#site-support
1 messages ยท Page 263 of 1
after you install the dmg, you should be able to import the ovpn (config) file by downloading the config file from your profile's access page.
https://tryhackme.com/access
i have to intsall the .dmg file from openvpn's website
Correct.
i cant access the website, tried 3 different browsers and i also cleared my local dns catche
Oh, I misunderstood what site wasn't working. That's bizarre. It's definitely up.
its not working for me at all
I'll grab a copy and throw it on googledrive.
used 3 different browsers, cleared my dns catche and cleared browsing cookies and data, refreshed and its not working
thank you.
Gave +1 Rep to @grand perch
what a legend @grand perch
Thanks ๐
Just took me a minute to understand which site won't load ๐
Uploading to drive now. Will be a few minutes. (Rural internet)
Does anyone know if the tickets will come back in to play, or will they be removed from you profile?
hey
LOL of course the weather decides to mess with my Internet today.
https://drive.google.com/file/d/1k7MC7FA_6BXXXBcDWy5pzoyIfwjFaML4/view?usp=sharing
Finally done the upload. G'luck.
thank you, is this for macos?
Gave +1 Rep to @grand perch
Yep, that's the DMG for Mac.
Yep.
when i finish some free rooms will i gain a room level like 0x4?
I'm running through a bunch of free rooms before I upgrade to paid account.
ugh. i wish i got a voutcher lol
It'd be nice ๐
But either way, once the holiday bank-account settles down, I'll be looking to throw money at THM, they deserve my support.
You get points by answering questions, regardless of free or subscriber only room. The more points you have the higher your lvl gets
@grand perch thanks so much, i downloaded openvpn now i need to import my openvpn thb configuration file.
thanks for the help.
Hi, on this room https://tryhackme.com/room/webenumerationv2 the second question of Task 9 is wrong there is a new version of the theme
Glad I was able.
Hello I have a friendly question: I just bought a one year membership and it said I would have 2 months free, but it says my subscription will renew after one year only. Is this normal?
I think it's a wording issue.
I read that to mean that the savings by purchasing a year, over month-by-month is equal to 2 months free.
I could be wrong though, I haven't bought my membership yet.
Oooh I see. Any staff member would like to confirm @grand perch 's answer if possible?
DUMP, I didn't find solution for this.
Wait a bit and try refreshing the page, if that doesn't solve it you might try to restart the target machine
Hi, any way to programatically open the chrome console?
thanks, it worked.
Gave +1 Rep to @crystal marlin
Do you mean with a python program or something like that? I'm a bit confused
Hmm, for webpages you can just call the chrome program directly followed by url... but that doesn't seem to work for chrome://preferences
Might need to do some sort of sendkeys: CTRL+L, chrome://preferences after chrome has launched.
I think [Severity 8] Insecure Deserialization - Code Execution from "OWASP Top 10" is broken. I tried multiple reverse shells with base64 and they didn't work and the link to the github gist is not available anymore. I don't want to type the whole python code but it basically does base64 encode. Room: https://tryhackme.com/room/owasptop10#
So did you only base64 encode them then instead of using the provided code ?
Yes, is that wrong? I looked like it and the link was broken to copy and paste it.
Ye, only base64 encoding the payload won't work.
Go to the github page and click on the revisions tab, scroll down a bit and you can copy paste the code. It's not meant to be like that, but at least you can find it there.
Thanks
Gave +1 Rep to @crystal marlin
When I start my VPN on kali, I get: sitnl_send: rtnl: generic error (-101): Network is unreachable
Is this a problem?
Does tryhackme give any real support? I emailed support and got no response. (this is not a rant)
If you verify your thm profile in discord you are able to send screenshots, I would suggest you send a screenshot of your openvpn output when trying to connect
Switched VPN to get it working
Okay then I guess it's solved, anyways, if you have any upcoming issues, there is a guide on how to verify
!docs verify
any one know how to install msfvenom?
What operating system are you on ?
kali
It should be preinstalled in kali already
If you enter msfconsole does that work ?
no
Strange.
Then do sudo apt install metasploit-framework
Happy New Year, I need some help, the Linux Fundamentals part 3 [Start Machine] button isn't working or rather the room "says" it's running but is no where to be seen. The Attackbox is fine but isn't used in this room. Whats the or is there a fix?
Refreshing the page might do the work or exit and again enter the room
hey can anyone tell me how can i know if my vm is in nat mode or bridged mode
and how can i change it to bridged mode
OWASP top 10 ask for pickle hacking tool but I don't understand how to install it I mean I have try to do sudo apt install pickle and it said it don't find the repertory to download it may I have help with this ? plz
you might it find owasp tools on github
but how I install it ?
pretty sure you will find the steps how to download it in there
But I mean it said to copy past but how I paste the file in 3 diffenrent file cause there is 3 file but in the same folder ?
OH GOD I'M A STUPID DUMP there was a download Zip in the corner of github...
Don't know if this is the correct place. Mod able to reach out to me about a CC transaction that I didn't authorize. (Rather than just disputing it with the CC company)
When I connect to the openvpn and start hacking the box after some time I cannot even ping for a while and after a while the connection continues. And also there are no errors in the terminal where I connected openvpn.
It works fine with HTB and eJPT boxes
Solved it meanwhile or you still need help ?
I think so, I ran ps aux | grep openvpn and removed the unwanted stuff...
hey im doing the brainstorm room
im testing the program on my local windows 7 vm
whenever i try to fuzz
in the terminal it shows something like this
as if the connection was terminated right after i connected with the fuzzer
i turned off windows firewall
i dont know what im doing wrong
Ask in #room-help or #room-hints .
Im not getting the IPS to the machines i start :S it stops at 0
Refresh mostly works
found the problem now, i had tryhack me open on my windows machine upstairs... the ip showed there but not on my linux one... closed the one on windows fixed it..
@celest wadi tyfor the answer anyway ๐
It looks like Throwback 10.200.3.x is broken and needs a reset. Any one able to give it a pick and reset please
Not sure if this is the right channel but I can't pay for my premium membership. When selecting paypal nothin happens (i logon to paypal, go through the steps and nothin) and when i select a CC The windows spits "chargebee is not defined" . Is this something on my end?
Do you mean VM?
You don't have to?
im already connected to openvpn for thm
If you load up your own VM and use the openvpn there is no need for the attackbox.
what about it in my host macos?
Are you using the windows gui?
the macos gui
you're on a mac?
mhm
Are you able to download virtualbox on a mac?
i already have it lol
i have kali linux installed too
Then download the openvpn script on Kali and sudo it.
okay
You know how, right?
Just checking, lol.
How are you getting on?
Is it possible to have more than 4 people in a team ?
Not sure.
If not, why ๐
I'm not part of a team, have you tried adding x number of users.
I am having some issues with the HackPark uploading a file in File Manager in the admin portal
Yes, so basically my friend tries to join in and is prompted something about already having 4 members inside the team
i think it has something to do with my kali instance, it works from the attackbox, continuing ๐
@naive dust
I think that's your answer.
i am connected
Yup.
thanks for helping, i appreciate it @naive dust
Gave +1 Rep to @lament valve
Yes, but what is this limit for ? it makes no sense ๐
Np.
Np
I can't say I know anything about the teams section, I don't use it.
same login tho
how can i access the tryhackme terminal?
@naive dust
use the machine ip.
What room are you doing?
Also on Kali go to 10.10.10.10
linux fundementals
Which part?
it showed me a flag and my vpn/tryhackme ip for the machine
i think first
which task?
5
Did you deploy the machine?
attackbox?
Good!
Gave +1 Rep to @lament valve
can you reset your attackbox?
You can get a fresh one by terminating it and deploying it again.
If that's what you mean by reset.
oh ok
so if I delete a file i can stop the maschine and start it again and then the file is back?
ok, thx for help
Gave +1 Rep to @eager fulcrum
hey guys i got 404 when downloading hololive ovpn file
can anyone help with the issue
Follow the instructions from the below link see if it helps
#site-support message
already done all of that
Hmm odd
I've misread i thought it was the normal openvpn config file.. Maybe somebody else will be able to help when they see your issue, let's wait a bit ๐
ok thanks
I want to download OpenVPN for mac OS. the link not working
Have you installed virtualbox, or are you just using the one for Macos?
did you mean VM ware?
yes I have it
but I want to try it on my mac
I haven't used a mac before.
Try this room.
I get a 404 when trying to download a holo vpn file.. I've tried regenerating
Seems like it's just Holo because Wreath works fine
I followed Jabba's instructions (logging in and out and regenerating) and it's still not working... I can't switch VPN servers because there's only one for Holo 
Hi guys
room overpass final flag.
We need start a server on attackbox with port 80 for target machine can download a file in crontabs. But port 80 is used on attack-box
We can't change crontab file, it's owned by root and we are trying escalate
I don't know ask this problem in tech or help room
hmmm
I did it tks ๐
you should be able to close the program that uses port 80 on the attackbox but dunno how viable that is
well shadow just used their local machine for that room so obviously never got hit with this problem
same here
well, local VM-ish
bump
anybody here is mobaxterm?
Before I subscribe to Premium, is it possible to change my username on my TryHackMe account?
Contact support.
lol I used to some years ago
Hello Team I am new to THM , I am trying to solve Authentication Bypass.
when i try to open the page http://10.10.97.140/customers/signup it shows Error code 405
Solved it meanwhile ?
Hi, is the Room "Blue" broken for anyone else? It just loads endlessly, when I try to access it.
Does that also happen with https://tryhackme.com/room/rpmetasploit ?
yes
Are you using a private vpn ?
yes, is that blocking it?
Most likely it's filtering out a certain js file if I remember correctly, so take a look in that direction
alright, thanks!
Gave +1 Rep to @crystal marlin
Hey, Anybody please help me with the Linux Privilege Escalation Room https://tryhackme.com/room/linprivesc
I am not getting the reverse shell of the cronjob room Task 9
probably you made a mistake in the steps provided
try doing the steps again as the're pretty self explanatory
done the same way but which IP should I use in the reverse shell script?
your own tun0 ip
tried, not getting
Check the permissions of the file that's getting executed by cron. Also, I would suggest using #room-help for room related questions, but I'm not a mod or something so it's still up to you ๐
okay okay
hey. Is it possible to exploit "blue" box with msf eternalblue exploit? Tried numerous times and it keeps failing
I should've say "is it possible on free plan" ๐
First time aim trying to use Metasploit with my kali machine instead of the browser one. Getting FAIL after Triggering free of corrupted buffer.
Extra information:
ROOM: Metasploit:introduction
Pinging the target works fine
Doing the exploit with browser vm works fine
When i use VIP-1 VPN i cant even ping, but im using VIP-2 and that one works
Im using the ip on top right (green box) as LHOST, target ip as RHOSTS, RPORT 445 and LPORT 4444, Payload windows/x64/meterpreter/reverse_tcp
Already tried to restart vpn session and restart metasploit terminal to redo everything. Iยดm guessing there is something super simple that iยดm missing since im now that experienced at this. ^^
Hi,
I can't connect to THM using openvpn and I can't seem to know why.
So basically, I'm on arch (kernel version: 5.15.11-arch2-1)
I installed openvpn using pacman and openvpn --version gives the following output:
OpenVPN 2.5.5 [git:makepkg/869f194c23ae93c4+] x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Dec 15 2021
library versions: OpenSSL 1.1.1m 14 Dec 2021, LZO 2.10
Originally developed by James Yonan
Copyright (C) 2002-2021 OpenVPN Inc <sales@openvpn.net>
Compile time defines:
I downloaded the last version of my openvpn configuration
Thanks in advance for any help
The IP on the top right of THM could be different to your vpn IP. So rather check the tun0 interface with ip a s and take the IP from there.
Show the output of openvpn when you try to connect to the thm vpn
Sry @naive dust ๐
You might want to verify first in order to be able to send screenshots in here.
!docs verify
This exploit can fail several times, so make sure you are using the correct LHOST, also you might want to try restarting the target machine if it keeps failing after 2 - 3 attempts.
already tried restarting it once, but gonna give it another try. Thanks
@crystal marlin Same fail , but ima try to reset everything and try this before im starting to ask for more solutions, maby after all theese tries there is something in the backround failing :p
It says Initialization Sequence Completed so it seems you are succesfully connected. So I'm not sure why you think you can't connect ?
Well because on this page https://tryhackme.com/access I have a red cross on the connected line instead of a green tick
The access page is not reliable to verify if you are connect via openvpn. To verify if you are succesfully connected either open 10.10.10.10 in your browser or try curl 10.10.10.10/whoami in your terminal (where the curl command should reply with your vpn IP)
Ok thanks I didn't know that I just read what was written directly on the website
Ok it works thanks
Hey guys, I'm confused about those streaks for everyday tasks. I answered questions everyday in December/21 and now I'm with only one day streak. When the year changes, those badges are reseted?
And get worse, because I have two "days streak freeze", one of "one day" and other of "seven days", I won these in the Pentest challenge deployed in October.
It seems I do not answered nothing yesterday, I'm not sure of it, but yet, I have those "days streak freeze", so it should "protect me" of a gap.
Hi I have a problem with the room 'File Inclusion'
hi why can't i access a machines webpage
i can nmap and ping the machine
gobuster works on it too
but i just can't display the webpage
i've typed http:// {machine_IP}:{port}
but the actual ip and port
openvpn is working and my ip is shown on the tryhackme website
oh and i can also see the for 10.10.10.10
sometimes it takes like 5 minutes for the machine to boot properly, but I don't know
took more than 10 minutes but its working now thanks
i should've been more patient
Hello Guys Happy New year!!
My Streak is getting reset again and again ( I solve questions twice a day ) I didnt noticed at first but when I came across it today it was 0 ( probably meant to be around 10) Can anyone guide me what's being wrong here?
did you solve the last question within 24 hours?
yes even within 12 hrs
anyways, you can reach out to support via mail and ask them to retrieve your streak kindly.
Is there any way to change my tryhackme handle?
hello, every-time I change the phone number on tryhackme, the country gets changed to Afghanistan, and that's not the where I live ๐ฆ any sloutions?
Is there anyway to unlink my old discord account from my THM account?
Good morning guys! I have a problem, I am working with Vulnversity and for some reason I can't see my machine deployed
any suggestions? thanks!
Hi can someone help me with a tech problem
If they know what it is, they might :)
I'm logging into this app Aftership and it keeps saying that it is sending me a confirmation email. But I havnet received one. I made sure its the right email and checked spam.
Is this related to THM?
THM?
Tryhackme
no its not but I thought you guys knew a lot about tech. I didn't know who else to go to
Get in touch with Aftership.
Hey guys, any ideia or instructions about it?
How can I connect to attack box using OpenVpn?
When I follow the first step
I go to a page which says "uh oh..."
You don't have to use the VPN to connect to the Attack Box. The AB is a browser-based instance accessible through, you guessed it, your web browser.
Unless you're already running, say, Kali in a VM and want to connect that VM to THM, you do not have to bother with the VPN.
Send a mail to hello@tryhackme.com.
Yeah, I am aware of how to use the browser version. I was curious to how I can use the OpenVpn to do the same. I already have Ubuntu running in VM
The VPN's used for connecting the VM to the THM network.
What's the exact error message you're getting when downloading your .openvpn file?
This is what I get when I click the download link
... Huh.
Lemme check...
@hexed dock
https://tryhackme.com/access?o=vpn
'ere, that should set you up right.
Okay, thank you so much!
Gave +1 Rep to @knotty halo
No problem at all, happy hackin'!
Wait, when I click "Download the configuration" button, I get redirected the the same error page
Maybe the link is broken?
Unlikely. Try regenerating, and then downloading the re-generated file.
Errrr...
That is interesting. Also, +1 on concisely providing a clear description of your error that quickly.
Thanks for assisting me. I hope the the problem is resolved ๐
I am having issues accessing the Throwback network from my VM. My vpn connection is working without an issue - I am able to ping my attackbox. I am not able to access any of the 3 beginning machines of Throwback from my VM through the vpn (ping or nmap scan). These machines are reachable through my attackbox, but I do not want to use this attackbox.
I have tried redownloading and regenerating my VPN. I have tried resetting the throwback network
I might be horribly mistaken, but isn't Throwback a Network? There should be an extra tab on the openvpn-generate site that allows you to set up access from your host to the Throwback net.
๐คฆโโ๏ธ thank you, i was so dumb and thought it relied on the regular vpn
Gave +1 Rep to @knotty halo
No problem at all. Happy hackin'!
howdy! does anyone know how long it takes for your level tag to update on discord after you level up on the platform
Screenshot for context
edit - nvm lol, it just updated 
@hexed dock did you try changing the server?
Btw, you can force it to update by just verifying again with the bot ๐
Hey. Just out of curiosity - I can't recall to myself, but I'm pretty sure last year (I mean 2020) after completing AoC2 one should be awarded a badge too, right?
what could be the reason why the badge has not been awarded after completing the room?
I feel like iv tried everything now. Still getting fail after triggering free of corrupted buffer when using metasploit with vpn. Pinging works fine, using my tun0
Could you verify your thm profile in order to be able to send screenshots, then send a screenshot of your exploit options ?
!docs verify
The following link||https://github.com/m00-git/LZKTB4ET|| from the Musical Stego room, does not work.
There we go, When i use the same settings on browser (exept for the LHOST) it works like a charm @crystal marlin
its not for a flag or anything, just wanna get everything to work so i dont stumble across some problem further ahead ๐
LHOST starts with 10.14 ? You sure that's your tun0 IP ?
If you enter ip a s do you only see a tun0 interface or any extra like tun1, tun2 etc ?
tun0 and tun1
Okay then that's already an issue. You are not using any other extra vpn beside the thm one, right ?
none active no, i downloaded VIP-1 that one did not work at all so i downloaded VIP-2 that one worked
Then do sudo killall openvpn then connect to the thm vpn again, wait a minute or so, do ip a s again to verify there is only a tun0 interface and not any extra like tun1, tun2 etc.
ye that leaves me with a tun0 only (i used ip addr del before)
If you do ps aux | grep openvpn what's the output of that?
EU-VIP-2 is open 3 times on root for some reason
It would be easier if I see a screenshot. But anyways, I highly suggest you do the steps I provided above
ye ima fix a screenshot (no disc on my kali machine) so it takes some time to send it :p
Ye I think there is no need for a screenshot then, save yourself the hustle, just follow the steps I provided above and you should be fine after that
i did those steps before i did the grep
and thats the output after
ip a s shows only a tun0 (exept for the standard connections above) and ps aux | grep openvpn shows this
Mh, not sure why there is 2 times a line with sudo, but regarding to the multivpn doc I assume that's fine.
So you might want to try the blue exploit again now, maybe restart the target machine also and give it about 10 minutes (might be a bit much, but to make sure it's fully up) before you run the exploit, also make sure you check the LHOST with your tun0 again.
Yeah! ty alot, hope it works ๐
im going for a fresh install of my OS now since nothing works :p
for some reason, everytime iยดm setting up the VPN it goes up on tun1. if i make tun0 DOWN everything works exept that iยดm getting fail when triggering free of corrupted buffer. so i think ยดv made something earlier that makes my tun0 occupied even if it has no ip :p
Mh, I'm not sure if a fresh install will change it. How do you disconnect the vpn connection when you want to shut it down ? Also, after connecting to the vpn, do you keep the terminal where you connected open ?
ye l keep it open allways (once i made it run in the backround) maby thats the problem ๐ฎ
iยดv just made ctrl+c when i end the connection
I would just restart your attacking machine. Then connect to the VPN again and keep the terminal running. If you want to shut down the connection press ctrl+c in that terminal. Don't run the VPN connection twice. There should be no need to run something like tun0 down or so.
And the blue exploit can fail several times, so if you was trying it 2 - 3 times and it fails, you might want to restart the target machine. Also you could try a different payload. So instead of meterpreter just a usual reverse shell. I think some people said they had more success with that, although I somewhat doubt that it makes a difference.
Is your attacking machine a VM ?
nah
K.
its a kali on its own hardware
Did you ever receive a reverse shell on that machine?
on the vm THM provides i recive a reverse shell with ease. but on my hardware i just get FAIL
but i can ping the target
Eternal blue doesn't work the majority of the time.
Muiri recommended to me auto blue
hmm ok, it works flawless on THM browser kali every time for some reason :p but maby there is nothing wrong with my vpn then XD
So then I would try to spin up a usual target machine, like linux fund 2, ssh into that machine and then try to run a simple payload to catch that in a nc listener on your attacking machine, to make sure your machine doesn't have any other issues that prevents receiving reverse shells
@naive dustty i will tty that one @crystal marlin ima try that aswell ๐
I did it. Thanks for your attention and time. ๐
Gave +1 Rep to @knotty halo
No problem at all!
hi, I have a problem with the Wreath room, the connection is too slow and disconnects every 10 seconds, is that ok???
thanks @celest wadi , sorry just saw there is Wreath-network room
Gave +1 Rep to @celest wadi
Could you share any error logs?
Try to check the pinned messages in this channel, there are a few workarounds
Can anyone please help me with this question?
All I want to do is create the groups first and then add the users as they come in.
Thank you in advance
Is the page for buying vouchers down or just me? Every time I try to buy vouchers this morning it times out and Cloudflare isn't happy. ๐ฆ Edit: Disregard, finally started working
Hi everyone, anyone know if I routed my traffic through tor can I still use openvpn to connect to tryhackme ?
Isn't tor for TCP protocol?
IIRC, there is some support or there was; using port 53 for UDP protocol
But it just did the DNS queries๐ค
TryHackMe's openvpn configuration uses UDP, right?
So it may not ve plausible๐
I'm not running a debian based linux distro and I'm trying to get matasploit installed, I run msfdb init and I get this
Traceback (most recent call last):
7: from ./msfdb:1079:in `<main>'
6: from ./msfdb:938:in `invoke_command'
5: from ./msfdb:201:in `init_db'
4: from /opt/metasploit-framework/lib/msfdb_helpers/pg_ctl.rb:25:in `init'
3: from /opt/metasploit-framework/lib/msfdb_helpers/pg_ctl.rb:105:in `create_db_users'
2: from /usr/lib64/ruby/gems/2.7.0/gems/pg-1.2.3/lib/pg.rb:58:in `connect'
1: from /usr/lib64/ruby/gems/2.7.0/gems/pg-1.2.3/lib/pg.rb:58:in `new'
/usr/lib64/ruby/gems/2.7.0/gems/pg-1.2.3/lib/pg.rb:58:in `initialize': could not connect to server: Connection refused (PG::ConnectionBad)
Is the server running on host "127.0.0.1" and accepting
TCP/IP connections on port 5433?
I just installed yesterday MS in Fedora with https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers
IIRC msfdb is how metasploit interfaces with a backing db. is there a config option prior to that point to pick where the db is and crededntials?
what distro are you running?
gentoo
I didn't get to choose it, but it seems to have been made in my home directory
$HOME/.msf4/db
the attackbox 1 hour limit ran out
apparently i can open the machine with the open vpn
how
https://tryhackme.com/room/openvpn @ashen crypt explains it in a simple manner
This goes back to having a VM with a Linux distro.
well i am connected
but , i cant access it
as in , no terminal
idk if u know what i mean
Iโm having issues on the room of owasptop10. Broken Authetication Practical I cannot obtain the flag for the user darren. Can someone help me?
if you are connect and you try in a web browser to access 10.10.10.10 what do you get
Thanks
..........................................
got that
so nothing that looks like this????
in here
it says im not connected to the network
but the access details say i am
if only shadow could remember the link to the troubleshoot script
i can see the page on 10.10.10.10
just like that
then you are technically connected to the vpn then.... so is it a special target machine you can't access???
yes i am connected
i cant see the terminal
thats what im saying
im doing linux fundamentals and i need the terminal
which one of the linux fundamentals and what task???
2
task 3
in task 2
it says to open teh machine
which i cant do
task 2'
are you on windows or a linux vm where you connected to the vpn???
because if windows you probably need to get something like putty setup to ssh
okay maybe you can just open powershell and then run: ssh tryhackme@yourMACHINE_IP and after that enter the password when it asks for it
the password is also tryhackme
silly question
wdym by my machine ip
the internal virtual ip adress?
nvmm
i understood
https://assets.tryhackme.com/additional/linux-fundamentals/part2/deploy1.png the one surrounded by the red box in this image but replace the numbers with what you see there
did you get it working then lucius???
you're welcome
thanks
yeah but they intend you to do it from the attackbox as that is easier for new people but this way works too
Is there anyway to unlink my old discord account from my THM account?
yes there is if you contact a moderator here and ask nicely... dunno exactly who of the moderators have the ability to do it but they probably can refer to each other to help with this
Ah okay thanks, should i dm them or?
Gave +1 Rep to @plush bay
nah pinging them in here is the better way as the rules state to not dm without asking first
Thank you
just do not spoil your token in here
they will probably ask you to dm them with more info but that comes then
@eager fulcrum Could you help?
๐
Please DM me your token
๐
Did Discord delete your account or did you?
Yeah i deleted it
Ok, try now
Nice it worked, thank you
Gave +1 Rep to @eager fulcrum
Hey is there a possibility to erase all my Progress? I Want to start completely over
You can reset each room.
yeah i know but i want to reset all. I mean Progress, badges and so on
That would be account deletion.
not sure if this is the right room, I installed the Docker of GVM and I had it working until my laptop unexpectedly reboot while it was running and now I get "Login failed. Waiting for OMP service to become available." I followed the instructions in the Greenbone room but I don't know much about Docker
I've restarted the container and "docker top openvas" seems to show it's running
or if this is just techsupport for THM itself I can try the cyber defense channel
No, you should still be able to login, double check your credntials.
I'm all set, I just blew out the container since I wasn't very far along and now it's working
After alot of trial and error and a insane amount of help from fontaene iยดv figured out that there is nothing wrong with my vpn. But my machine cant make reverse shells. everything works amazing but as soon as i g2 create a reverse shell i get nothing. Any ideas what the issue can be? when listening with netcat its just silence on the machine but same thing on browser vm works fine. wont matter what way im trying to make the reverse shell.
EDIT: i dident realy figure it out myself he kinda said maby thats the problem :p so i cant take the cred for that eather hehe
Hey
All the rooms that i tried deploying goes down after 5 minutes from deploying
Can someone explain to me this please
Hey! As usual I start my vm, Openvpn and it starts like usual
But after booting up my machine on crackthehash2, I can't access it in my browser
waited 10mins, the machine boots up, i can ping and curl n stuff
but can't use firefox
I tried starting other rooms that holds a website like pickle rick ctf and it works just fine, I can access the website
There might an issue with the room or idk, I booted up multiple times with waiting 5-10minutes, no website
Seems I can access with only my windows and openvpn for windows, but on my linux I can access Pickle Rick and other ones as well, just not this one ๐ค
Not using burp proxies or anything, just openvpn launched in a term and firefox classic
Turns out at my 5th machine without doing anything this one works, different ip thought
Didn't worked: 10.10.234.190
So this room, right? https://tryhackme.com/room/crackthehashlevel2
indeed
Is that IP the current target machine IP? And if yes, can I try to access it ?
4 times it booted as 10.10.234.190 didn't worked, now i'm on 10.10.86.239 and it works
Alright, so you good now ?
yep, but still i don't understand why it didn't worked, could that be a pb with me or the machine?
because when it changed to 10.10.86.239 it works perfectly now
Not sure, is your linux a VM ? And if yes, you don't have openvpn running on your host (windows as you said?) and inside your VM simultaneously ?
not simultaneously, i tried my vm and my real os windows after shutting down the openvpn client
and also i tried re-generating the openvpn file, it did nothing (just trying because why not)
Did you try a different server?
Alright, ye then hard to tell why it wasn't working at first. Get back here if the issue comes back
i got able to access the one i couldn't with my linux vm, with windows and the openvpn windows client (it's down, the image is because the website is cached in my pc rn)
Can you access 10.10.10.10?
yes, i can access this, pickle rick ctf website, and other rooms with websites as well
i didn't booted up anything else that could influence the situation, just this terminal and this browser
Doesn't seem like a VPN issue since you can access other rooms just fine
Wait I'm confused now, is it working now or not ๐ ?
Might just be a problem with the room itself
yes, i'm just explaining more because he asked me if i could reach other rooms
Ah kk.
@cinder jackal Do you need help?
We may report this issue with 10.10.234.190 in #room-bugs ? (the one machine that doesn't show up)
Yeah, report it there
Well, tbh claiming that there is a room bug without being sure, doesn't sound reasonable, but feel free to do if you think so ๐
Hello, can u help me pls? When I go to /room/bashscripting but the Images could not be loaded, all other tasks was fine. I just tryd wget on Image URL (https://i.ibb.co/7W5mn0c/carbon-8.png) it says connection refused. There is my DNS and Proxy in my network but i dont believe thats the issue. Maybe it is a Server-Error but how can I readout the Error-Code ๐ ? My Firefox dont show it somehow... Is it only me having this problem, how can i fix it, or is it server-sided?
*When I go to /room/bashscripting the Images could not be loaded
Which task is it ?
Task2
Images loads fine for me. What browser are you on?
Firefox
So if you manually navigate to https://i.ibb.co/7W5mn0c/carbon-8.png it's also not showing it ?
Ye, could be. Try to check towards that direction.
that would be strange ...i did many other rooms with loaded Images. I'll check Query Log of PiHole w8
Definitely the pi hole.
ok yes it is the Pihile
*PiHole ...it loads Images when I disable it
Thank you for your Response
I love tryhackme โค๏ธ :3
My Pihole blocks over 9.000.000 Domains ...somehow https:// --> i.ibb.co <-- /7W5mn0c/carbon-8.png is part of it but why ๐คทโโ๏ธ
Figured it out meanwhile ? Missed that message. If you haven't solved it already. Try to check sudo ufw status
๐
hey can someone help me with a cmd in the terminal
i wanna replace a certain dll but im not sure how
how can I change the flag on my public profile? its showing US which is incorrect but I cant find an option to change it
does anybody have an idea what my issue setting up metasploit it, this is the traceback I get when I run msfdb init:
Traceback (most recent call last):
7: from ./msfdb:1079:in `<main>'
6: from ./msfdb:938:in `invoke_command'
5: from ./msfdb:201:in `init_db'
4: from /opt/metasploit-framework/lib/msfdb_helpers/pg_ctl.rb:25:in `init'
3: from /opt/metasploit-framework/lib/msfdb_helpers/pg_ctl.rb:105:in `create_db_users'
2: from /usr/lib64/ruby/gems/2.7.0/gems/pg-1.2.3/lib/pg.rb:58:in `connect'
1: from /usr/lib64/ruby/gems/2.7.0/gems/pg-1.2.3/lib/pg.rb:58:in `new'
/usr/lib64/ruby/gems/2.7.0/gems/pg-1.2.3/lib/pg.rb:58:in `initialize': could not connect to server: Connection refused (PG::ConnectionBad)
Is the server running on host "127.0.0.1" and accepting
TCP/IP connections on port 5433?
from my little bit of looking around, it seems to be something to do with credentials, but I can't figure it out
it did create a db directory for me in my home dir
it could also be a missing dependency, since I had to get mfs off of github
thank you
Gave +1 Rep to @crystal marlin
maybe missing permissions
Do you have postgresql started ?
I'm going to guess no
The you might try sudo systemctl start postgresql
shoot, I don't use systemd
I figured out how to do it for me, but now I'm running into other issues
* Directory not found: /var/lib/postgresql/13/data
* HINT: Ensure that DATA_DIR points to the right path.
* HINT: Or perhaps you need to create the database cluster:
* emerge --config dev-db/postgresql:13
* ERROR: postgresql-13 failed to start
I'll do some digging about
well I have no clue now
I got postgresql started, but I'm still getting the same issue
Mh, dunno, maybe someone else is more familiar with such things. But just setting up a virtual kali linux machine would be no option for you ? As lets say you fixed that issue, you might run into more issues for other tools you need.
uh
I am having other issues setting up a vm, I might just use the one provided on the website
even though I kinda hate that option
hey does anyone know where is the smbserver located in tryhackme attackbox
hello, is it possible to download the previous Advent of Cyber certificate? I can't find any download link
click on it
I mean the previous one, like Advent Cyber 2
I already finished it but there's no certificate button
Hello! I'd like to update my Discord token that is currently linked to my Discord account since I made a new account. The website says I have to contact a mod here so are there any mods that can help me? Thanks
@crystal marlin when doing sudo ufw status im getting Allow anywhere on all items on the list and those items are:
OpenSSH
80
443
8080
OpenSSH(v6)
80(v6)
443(v6)
8080(v6)
do i need to have the ports i wanna use for my serverse shells on this list ?
oh and its ACTIVE
yes, you need to have any ports you use for reverse shells open @tall ocean
i am trying to access the wreath network, lost access due to time, finishing my writeup/notes. when i try and download a new connection pack i get a 404 error.
i left the room and rejoined, and still 404 error on download attempt
i click here
i get this
@main iristy
I'm doing Upload vulnerability and I've follow all the instruction but I don't have access to the website overwrite.vulnerability.thm I don't understand I've done the command with the echo thing and it doesn't work
and when use the ip of the room they ask for using the url provided in the course
@plain gateat the start of that room i think you have a line you g2 write in terminal?
I've done it
the ''echo'' thing with the ''tee''
but firefox is always redirect me to google
and you changes the machine ip in the code right?
yes
simple question ik but its a misstake i could have done so i ask :p
im launching the room aswell to check it ouy
works like a charm for me
but i have to write http://<adress>
Oh probably that my error
if i dont write http:// its google
ok i'll try
It don't find the website now
I've restart the machine and undo the setting for changing it and now it say 502 bad gateway
used the command after restart?
yes
and you used the other command before exit the vm?
I've undo and remake the command
okok
yes
if you just use the ip on the machine you attack in the url then?
do you get a list of sites then?
How to change the country??
yes
VPN or proxies
Bro not like that... Changeing the country flag on tryhackme
then just copie the top one and use http://and.that.adress that does not work? :S
http is a bad gateway and https is not even able to reach the website
:S:S
maby restart the machine your attacking then
im using vpn and it works for me
I mean I use the VIP one
im using VIP-2
then im no help at all sadly, im just a noob that it worked for and tried to tell you how i did :p
no problem ๐
i just started it up, used the command, used ip in url, ctrl+v on the one i had to use and added http:// before i uset ctrl+v
It nice there is always somebody trying to help here ๐
g2g now but i wish you best of luck. try to use the browser vm and c if it works there?
then you atleast know if its your doing or if its your machine/vpn that fails
i'm gonna try on windows it's probably my kali VM who it an asshole xD
I don't remember how to speak english lol
Everyone here are volunteers,
Try downloading the vpn before you start the machine.
so email support?
Thats one option if this room doesn't help.
However, you mentioned you started the machine and then downloaded, have you tried regenerating a new configuration file and waiting 60 seconds?
no
Try that
And you still can't download a new configuration?
Strange, I just tried a download and it worked.
I know which one you're having trouble downloading.
๐
!vpnscript
Nope, that doesn't help.
This has happened to me in the past and I just regenerated a new vpn configuration and it worked,
thanks, im going to email support
Jabba will sort you out.
Did you try to regenerate and then wait 3 + mins before trying to download? Also have you tried to log out of your account and back in ?
So after figuring out that you have a firewall in place, did you manage to receive rev shells now ?
yes and yes, but ty
Gave +1 Rep to @crystal marlin
Hey is static now fixed??
Hi guys, about the prizes of the event Advent of Cyber, what's the difference from the list Burp Pro and BurpSuite?
It might be just my interpretation, but I think "Burp Pro" is a licence for the Burp Suite Professional edition and just "BurpSuite" is a voucher for the Burp Suite Certified Exam.
hi i can't background a shell is msfdb
when i presst ctrl+z it backgrounds msfconsole itself
google says i should make sh file wrapper that catches sigstop where msfconsole is located
how can i do this if its what i should do
You sure you are in a session/shell ?
Could you show a screenshot of being in such and press ctrl+z ?
i backgrounded using the background command and am upgrading to a meterpreter shell rn
okay
Mh, that doesn't look like you are in a session already. It seems the exploit is still running and you press ctrl+z
Okay, but that also doesn't look like it's back grounding the whole msfconsole? Not sure why it says suspended msfdb run, but you should be still in msfconsole? At least I can't see it in that screenshot that you aren't anymore.
Hello I'm having some issues when running nmap scans on the hack box. taking way longer than it should.
it shows that im back in root
What room, what task, what's the full nmap command ?
Okay, but without seeing it in a screenshot, it's hard to tell, so you shouldn't have cut the screenshot that small
Network services 2 nfs enumeration. nmap -A -p- IP address
if you want you can help troy first idm waiting
You shouldn't use -A if you are doing an initial scan on all ports, that's taking unnecessarily longer, beside that using the -A is barely appropriate
Mh, tbh, I never encountered that :/
was following the directions in the room, still shouldn't take nearly 40 minutes to
complete
It could, of course
yeah its unusual but google says to make a sh file wrapper but idk how to do that
Instead of doing that, did you try to upgrade metasploit already ?
no i'll do that
But to not face waiting 40 mins, I suggest you use sudo nmap -sS -T4 -vv -p- IP which should scan it way faster and the -T4 option should be fine to use for THM machines.
even running nmap without the -A just the -p- on one IP is not completing... just hangs, and time keeps going up.
Try the command I suggested and let me know if that's working better, if it will not, we can go from there.
I will try that
still hanging, but getting more information with the -vv
seems to hang around 25%+
I mean you still have to give it a couple of minutes
is it normal for even that scan to take more than 5 minutes?
I'm using the web based attack box.
It's 65k+ ports, so yes it could.
ok
perhaps that is something that could be mentioned as part of these exercises that ask you to perform nmap scans. I know I was not expecting these scans to be running for more than a few minutes
scan still running.
saying 4 minutes remaining...
Ye, but already sounds way faster then 40+ minutes, right ?
Yes does sound faster
Alright ๐ Some mentioned using -T4 --min-rate 10000 gave them the best results in speed/reliability, so I guess you have to play around a bit to find what's working best for you. It might also depend on the target machine you scan, some machines are getting scanned faster and some are slower.
did finally finish
thanks I will play around.
appreciate the help
that --min-rate really helped with the speed
Does type flag1.txt work?
Refer to #room-help ๐
Oops, try shell first to get a simple shell
Perhaps meterpreter doesn't have cat (see help)๐ค
Hey there ๐
I am quite new to the TryHackMe platform. Possibly I should send an email regarding my issue but I wanted to try it here first:
I would like to install the OpenVPN connection for VMs and want to download te configuration file for that, but when I click on the "Download my Configuration File" button, the next window shows a 404 error with the text "Uh-oh, this page has been lost in the matrix." I am in mid Europe. Does anyone have an idea what the problem is?
Thanks for any help beforehand ๐
Some other european servers work, but no clue what is wrong with the others
Try "more flag1.txt"
the file was overwritten and contained nothing inside so i terminated the machine started a new one and that worked
Ah, good good.
thank you tho
@crystal marlinwe will c now. disables the firewall and ran the exploit 2x fail this far
Are you still doing Blue?
and now the WIN came ๐ firewall was the problem XD thx alot for helping me solve this! damn the smile on my face now XD
@naive dustwell i tried blue now again after iยดv made alot of other stuff in between ๐ but now eternal blue worked like a charm !
Excellent!
Awesome, well done ๐
@crystal marlinwell it was all you :p
Nah, I just gave you hints, it's about not giving up until it works :=)
@crystal marlinwelll thx for all the hints then XD nice to not having to use the browser vpn now ๐
Gave +1 Rep to @crystal marlin
I lost my streak due to work purposes. I would be happy to get it back if possible, thanks
I thought pause streak was there... But u was wrong
Hello, I have an unusual problem. I'm a blind user of try hack me, and i have trouble solving puzzles which are at the end of each room. Now there's that one in that room where i'm learning about http, how websites work, etc, and i must solve that puzzle at the end to go further. This is the presecurity path. Is there any way to make these puzzles accessible for the screenreaders? Or atleast can i skip them somehow to continue learning? I'm stuck there like for 2 weeks and my subscription has renewed itself, but ii'm not able to go further because of these puzzles. Regards. Ah and sorry if i have posted it in the wrong channel.
@carmine wasp Are you needing help with a specific task in a room?
Well I rather meand to get some kind of a solution to skip these puzzles or atleast make them readable but i guess that won't help either because i must drag them with a mouse and i am not able to do that. I'm stuck here:
Click the "View Site" button on the right. Using everything you've learnt from the other modules, drag and drop the tiles into the correct order of how a request to a website works to reveal the flag.
This is task 4 in putting it all together room. I guess giving me the flag would work, but it's only a temporary solution and probably i'll have the same problem in next rooms
@Mods, I have a new Discord user (old ones were deleted by me) and I want to use the "Discord Token" again to verify my user in Discord account. Can some Mod unlink my old account please?
Hello guys, just a quick question. At Intro to x86-64, the attack box seems empty. Where can i find the binaries?
@main rain task 2 has an attached machine, you should see the binaries in that machine.
Is there anyway to change your tryhackme username?
Cheers!
When I try to visit the following URL in the Upload Vulnerabilities Room, in Task 5: Remote Code Execution, I just get Rick Rolled (goes to Rick Astley: Never Going to Give You Up, YouTube page) ๐ฆ
Because that's not an actual site for that task, it's just an example.
Oh hecc, you're right, I need to go to shell.uploadvulns.thm. Thank you
Gave +1 Rep to @crystal marlin
In Linux PrivEsc room task #10 there's no home directory for my current credential is it normal ?
Yes it is
thank you
i used my token in another discord account, how can i verify this account with the same token?
can someone please help me link my THM subscription to this discord account? ๐
i found the help thread on the site c: thank you
can i have a role of N+?
Hello! How do I change my country in my profile?
hello! - i'm not able to connect to try hack me network(vpn) - i have this problem since i reached to egypt only - before that when i was in india it's was all good - btw i have tried all the systems i have on mac on windwos on linux but still the same problem ? - anyone can help !!๐ซ
@earnest steppe i remember hearing "OpenVPN is blocked in Egypt" somewhere, but don't quote me on this.
so what should i do to be able to connect to their network and play again ?!
@earnest steppe I found this.
#site-support message
๐
Thank you! ๐
Gave +1 Rep to @lament trout
Yo! I have a question about ssh, i try to login with the public IP of my server (Ubuntu server 18.04), password is the right one but always says i have the wrong one, but when i try with my local ip, i can login without any problems, anyone have an idea why is that? Thanks!
the public ip is only for web browsing and other stuff I believe, for anything related to the actual system you'd need the private system ip
So if i want to ssh from my home to my server (which is at my workplace), what ip do i need? I have the 198.168.xxx.xxx but i think this one only work in the local network?
you'd have to do port forwarding in your router's settings to access it via the external IP
Ohhh shit yeah make sense, didn't think about that but totally make sense since the public ip is for the router if im right, thanks alot!
I am using an Attack Box and want to download the task files of a VIP room. How can I do that?
Can you post a link to that room?
Yes, of course: https://tryhackme.com/room/johntheripper0#
I need the binary file in Task 11
Hm. How did you do it till task 11?
Previous task files were text files, and I copy-pasted the contents into the Attack Box
Let me try...
I could use base64 to transfer the zip file to the attack box ๐
You could copy/paste that one also. But it's a bit tricky with SSH keys as a missing empty, last line can throw an error.
Hm.
I'll try it...
Sorry, it was actually task 9. However, base64 works perfectly.
BTW, you can also launch a http.server on your host and wget it from the AttackBox (you have to be connected to THM VPN). Just tried it out and works.
Thx. However, currently I am not using a host...
just wondering.. does tryhackme plans to make a python scripting room?
Like a tutorial?
There is a room with a few challenges: https://tryhackme.com/room/scripting
hehe nice, thanks for the share.. i guess i missed those! ๐
Gave +1 Rep to @lone karma
You can search for rooms. Go to "Learn" then "Search" and type "Python" or "Script" into the search bar.
Certain features on the THM website are just not so revealed or easy accessible...
I guess that's part of hacking :)
greattt!!.. ive been doing the learning paths mostly and there havent been much of python in those... the rooms for python seems to be damn nice...
Guys in the room https://tryhackme.com/room/introtox8664 binaries are missing from attack box, can you please check?
Pretty sure you're meant to do it on the deployed machine, not the attackbox.
Someone can help me to unlink my THM token from a removed Discord account, please?
Anyone getting errors SSH'ing from an attackbox to Linux VM, worked yesterday but today its failing - port 22: Connection timed out
both VMs are new
DM me your token
A followup question (being new to this site) does SSH always work, or does it depend on the room thaat you are in. I've found that SSH works in one room, but not in another (furthernmap) - thanks.
depends on the room.
Gave +1 Rep to @lament trout
Thanks, sounds like its by design then.
Where can I contact support to help me with a private issue?
email them, support@tryhackme.com
K thanks @upbeat bloom
Gave +1 Rep to @upbeat bloom
Can anyone help I'm new here , I have issues in my kali vm, I try update but it show me failed to fetch , I edit source file http to https , and change DHCP ip ,and vm network settings still the same problem
And I can ping kali.org also I change branches
Majorly source files are http not https
Futher if it shows failed to fetch there is error. Like IP unavailable ,,,etc
Thank you @eager fulcrum
Gave +1 Rep to @eager fulcrum
Hi all, I can't connect to the Wreath network via VirtualBox and OpenVPN, however, I can confirm I'm connected to THM via 10.10.10.10. Anyone else having issues?
Did you use the usual VPN config or did you download the one for wreath(which is not the same as the usual one)?
Yup, someone just pointed that out in the Wreath room, thx for the heads up!
Problem solved.
hi why can't i ping for example google.com
i can't really ping anything but thm machines
From which machine ?
So not the attackbox provided by thm ?
no no
Can you even open google or any other website in your VM ?
And if you turn off the vpn, does that change anything ?
nope
sorry my wifi just stopped working
so i canโt use the pc until it starts working again
Hola, I am trying to go through throwback but the pfsense firewall application is giving me a 504 error when trying to access, so I can't work through the course.
its back
anyone have a solution to the Error: error on parsing arguments: wordlist file "/usr/share/wordlist/dirbuster/directory-list-2.3-small.txt" does not exist: stat /usr/share/wordlist/dirbuster/directory-list-2.3-small.txt: no such file or directory
issue
Local VM or AttackBox?
attackbox
Link to room?
One sec. In the meantime you could search for that directory:
find / -type d -name wordlist 2>/dev/null
Small typo. wordlists and not wordlist @grand ore
Have fun.
thx
how to change information text in profile?
Hi im having trouble connecting to the network via openvpn. I've regenerated the ovpn file multiple times and switched between servers to no avail. Any assistance would be much appreciated! Thanks!
Can you post a screenshot of the terminal running OpenVPN?
sure
However it's better for you.
all signs point towards it working
but this never detects me as connected
nor can I ping any of the machines I start
Is this a local VM?
yes
Can you open a browser and go to 10.10.10.10? Do you see your IP at the bottom?
Yes, within the VM that OpenVPN is running
Does it show your IP? (bottom of 10.10.10.10)
yes
interestingly, it was working fine the other day, then all of a sudden I started having these issues
Great. So what makes you think you are not connected? I don't think that web page on tryhackme.com is always accurate.
If i do a room with a deployable machine, I cant ping it or interact at all with it
Can I try? Can you send me the link to the room you are talking about?
ok im so sorry to bother
i have no idea why or how
but the problem is gone...
as soon as I ask too ๐
thanks for the help, I appreciate it
No problem :))
Hello, sorry for bothering you again. But I've got stuck in the OWASP Top 10 room: https://tryhackme.com/room/owasptop10. The problem is Task 22, first question: I entered "<script>alert('Hello')</script>", but it told me that the answer is wrong. However, I tried some variations (double quotes, singles quotes, with and without semicolon), but always got the same answer.
The writeups where not helpful, either.
You sure you are talking about task 22 ? As task 22 is something else for me?
Sorry, I am talking about Task 20 (XSS)
The same applies to the next question asking for the machine IP address: <script>alert(window.location.hostname)</script> is marked as incorrect
And you are trying to put <script>alert('Hello')</script> as the answer ?
Yes, I did
You have to do these xss tasks on the target machines website and if you are doing it right you will receive a flag, which will then be the answer. So the answer is not the actual payload itself.
Thank you! But I executed this on the target machine, but I did not receive the flag.
Then you probably doing something wrong. If you think you are doing it right, maybe try to restart the target machine.
Ah! Okay, reading sometimes helps ๐ Now I understood that I am getting the answer from the machine...
Do you know the simplest provider/way where and how to setup a small website with only a box to write text and send it, then it would be stored in some database?
#infosec-general would be a better place for this.
ok thanks
Dears can anyone help me to change my country because when I changed it and get back again it shows me another country
Thanks a lot
there should be a pinned message having links to all FAQs here
502 Error on Burp Suite: The Basics
I didn't do anything, i just tried to connect with the link provided by the room
try refreshing now? it loads for me.
infinite loading
i'm refreshing since you posted your message
:/
it's ok now but it seems scripts are desactivated
are you using another vpn or something?
nop
Try to use https
try on your host machine maybe?
it is 
Rly, mh what about trying http then ?
it works on http now !
but it took time before charging and showing "DNS Probe finished domain"
maybe the server itself is suffering ?
Hey everyone, I have a feeling sqlmap is not able to find any websites through the ovpn network. I'm currently trying the Overpass room, and sqlmap keeps getting 404s
Command i'm using: sqlmap -u "http://10.10.228.16/admin" --data="username=admin&password=password" -dbs
Has anyone encountered this issue before?
Just fyi, I can actually get the website through a browser. So the my ovpn config should be working correctly
okay so im having some issues getting a windows vm on which i can get brainstorms exe to actually run anyone wanna recommend a specific vm. tried win 7 x86 same with win 8
Move it here @ashen crypt
alr
i started the attackbox
opened firefox there
and wrote the machine's ip
error 405 , doesnt work
Let me try it also.
What's the title next to the IP you are trying to connect to ?
You have to use the Active Machine Information not the one at the top, if that is the one you are using...
i am
as i do start machine
its telling me
you can only deploy 3 machines
idk what machine is open
ahbabhahhaha
is there a way to close all machines i mightve opened and forgot to terminate?
Click on the terminate button, the one in red
thsat i cant figure out
where
what browser control
as in how
do i do it
@crystal marlin
Open the dev tools in your browser and click on the "console" tab, then paste that code in there
๐
no worries

THM Staff???