#site-support

1 messages · Page 276 of 1

waxen dock
#

What's it doing?

weary spindle
#

Eh?

#

Do you mean "Not that it changed anything" ?

waxen dock
#

although I was not trying to access one

weary spindle
#

^

waxen dock
#

I'll look it up, thanks!

#

So if I get it correctly the MTU of tun0 in my VM was incorrectly set because of my personal VPN?

tough linden
#

Hey Lassi,

Quick update I re-did the blind XSS but i used the AttackBox instead of my Kali desktop. and within 20 seconds the cookie was there.

I've successfully completed the room.

Thanks for the assistance you offered.

scenic torrentBOT
#

Gave +1 Rep to @gray loom

tough linden
#

Appears so, funny enough everything else worked through my desktop. After I got the cookie I saved it to a text file then spun up an http server on the attack box and had no issues with wget to download it to my kali desktop.

hallow hill
#

Try
$ mkdir /tmp/mount
$ sudo mount -t nfs ip_addr:home /tmp/mount -nolock
$ cd /tmp/mount/desired_dir

#

home being the share

gentle hatch
#

Hi everyone, I have immigrated to Portugal, how do I change my country on my profile?

#

Thank you sorted

scenic torrentBOT
#

Gave +1 Rep to @gray loom

unborn sun
#

Hi, I use openVPN to connect to the TryHackme VMs. All is fine. But now I was asked in "OWASP Top 10" to get my TryHackMe VPN IP from the Access Page (https://tryhackme.com/access). When I check this page it shows me: connected - a red x. And Internal Virtual IP Address: 0.0.0.0. Shouldn't be there a green tick and an IP number? I guess I need this number for completing this task: [Severity 8] Insecure Deserialization - Code Execution. Again, the openVPN connection works correct while checking the access page. Edit: I guess I found the answer elsewhere: "You should use your tun0 interface address". However, is it correct that the 0.0.0.0 is shown on the access page?

unique flume
#

is there a way to disable pop-up with connection instructions every time i start vm?

unique flume
weary spindle
unique flume
#

im

weary spindle
#

can you send a s/shot of the full pop up?

unique flume
#

thats all of it actually

crystal marlin
# unique flume im

There is no sub role on your discord profile, so you sure you are sub ?

unique flume
#

yeah.. but so you could also see it I verified with bot again

chilly hamlet
#

Burpsuit does not open
I checked my java

#

used command apt install default-jdk

#

still Burpsuit does not open

placid mango
minor wave
#

hey guys any reason a regex does not work with grep -o but works perfectly on a regex testing site?
I am trying to use: [^\s/]*\.js(?!\S) to extract all js files from an apachelog
works fine on regexr.com but on kali I get 0 results using: cat access_log.txt | grep -o '[^\s/]*\.js(?!\S)' and my test cases are from that file
so its the same format

wheat wagon
#

Try running grep with the -E flag.

minor wave
#

and any regex online tester i try it works

#

so its weird

#

maybe its the regex language

#

okay so figured it out

#

regex in grep uses Golang

#

so the correct regex is: [^\s/]*\.js[^\S]

earnest tree
#

Random question (maybe wrong channel, in this case sorry for the spam): in some cases I would like to re-complete a room more than once (concrete example: after ca. half year as a refresher). "Reset room progress" works as it should, however on the rooms overview page the room retains the green checkmark ✅ in the top-right corner. Is this known/expected or a bug for me?

weary spindle
#

I think it just acknowledges that you have still completed the room before.

hollow wharf
#

I am having problems exploiting the "ice" room, is this an appropiate channel to ask about it?

sharp bisonBOT
hollow wharf
#

Okay, so, pretty much the metaexploit module exploit/windows/http/icecast_header is not working for me, and ends the exploit on "Exploit completed, but no session was created." I verified I have conectivity with the vuln machine but is still not working, Here are the options im using and the conectivity test:

#

This is the error I'm getting now, I already tried to restart the vuln machine, and before the "Rex::ConnectionRefused" wasn't there, but the result was the same

#

Yes, it's just another terminal, although, any other idea to confirm conectivity?

#

Indeed

#

Thanks a lot ^^

#

sure, go ahead!

#

hahahahah okay then I'll do that hahah

#

Dang, okay so I did that, the new Vuln machine IP is 10.10.48.189 but now I'm back to where I originally started:

#

Although, the service is open now

#

So strange tho.... Maybe i have to update/re-install msfconsole?

light vale
#

Doesn't the task tell you to run it with run -j ?

#

Not with exploit

hollow wharf
hollow wharf
#

me right now:

#

Im rebooting my VM, let's see if that works

light vale
#

No no, i had the same problem

#

What task is that?

hollow wharf
light vale
#

Ohh sorry i thought it was from the Metasploit room

#

But whatever i guess it's the same thing because i had the same problem

#

It's from metasploit unfortunately from one of it's updates

#

I use a prebuild kali image that comes with mfs6 don't know what version.

#

When i updated Kali it updated the mfs6 also to another version can't remember the exact number. And had this problem and tried with the guys everything still didn't work

#

The only thing that worked was to "install" the prebuild kali image again and tried without updating it first, and it worked

hollow wharf
#

So, if I understood correctly, you are saying I have to use an old version of msfconsole to exploit this vuln? 🤔

light vale
#

yes

hollow wharf
light vale
#

I mean that worked for me 😄

#

Sorry i don't want to mislead you

hollow wharf
#

🤣

light vale
#

Well yeah, the version was fucked up but i guess it's something different here

hollow wharf
#

Im updating msfconsole with apt install metasploit-framework, so I pray this time it works

#

My new ver, let's see if it works now

#

Maybe I should get a new kali vm i guess :_C

#

I could also stream my display if you guys want to give it a try to solve this but I have no idea what's going wrong right now

#

Also, this my OS:

#

Not really no

#

Already executed it but no verbose response, what does it do?

light vale
#

maybe it's a stupid question but do you think this could be caused by not running msfconsole with sudo permissions?

#

great, cos i've read somewhere that this could cause some problems, especially with some ports

#

ohh yeah true

hollow wharf
#

altho not true, i was logged with root :C

light vale
willow timber
#

Ok, so how can i check if my ssh port is open @naive dust

willow timber
#

ok i´ll try that, but i´ll be away for a moment

#

i´ll write you if i have any news

naive dust
willow timber
weary spindle
#

The ssh port for the room their doing should be open.

willow timber
willow timber
#

code 101

weary spindle
#

Did you keep your vpn opened and minimised?

willow timber
weary spindle
#

Show me a screenshot of your ssh attempt and machine timer.

weary spindle
#

Is the network unreachable your vpn?

willow timber
#

i think so

weary spindle
#

That's why it won't work.

#

Is that the same ssh attempt as earlier?

willow timber
#

yes

willow timber
weary spindle
willow timber
#

yes

halcyon mist
#

need help setting up docker. im following the docs and added the repository to sources. is the link outdated or am i missing something.

night zenith
#

Hello I need a help about Wazuh room I can't access to wazuh server from linux machine specifically from Firefox and I got this error (Firefox can’t establish a connection to the server at ..) , the first time I could access but now I can't. please I need to solve this problem 🥲

shadow burrow
#

Anyone else intermittently losing connection to the THM VPN? Every few minutes I lose connection to the lab and if I wait long enough openvpn will timeout and reconnect. Then another few minutes later I drop again. I know my connection's good because pings to the VPN server keep coming back uninterrupted.

#

no consumer VPN or anything, though I did bump my MTU down just in case (to no effect)

wanton flicker
#

Hi all, my laptop suddenly cannot connect to internet on host&guest OS and VMware network adapter is still turned on even VMware is turned off ...... I can connect internet through my phone tethering on host and guest OS, but cannot only through my wifi🥲 Do anyone know how to fix it? There's no problem with wifi, I can connect internet using wifi with my phone.

Solved:)

past wadi
#

hi

#

help need

tidal shore
past wadi
#

i am trying to verify but showing this error Sorry this token is already used by someone.

broken bear
past wadi
shadow burrow
tidal shore
#

lol

tidal shore
#

Don't forget that you disabled the adapter when you try to reconnect to VPN (you can toggle that back probably)

wanton flicker
tidal shore
#

It didn't create another virtual adapter? As far as I know it does have to route through one but I haven't worked on VPNs in a while and there could be some new method 😛

ebon birch
#

Is this cano tech support? Where is @near spruce ????

spark wadi
#

hello. i'm not sure if losing my login info falls under tech support, but it seems to be the best match. can i get help restoring my paid account here?

sharp bisonBOT
weary spindle
#

Contact support, they'll be able to help you.

spark wadi
#

@weary spindle awesome. thank you. i was looking all over the website for the contact email and never could find it.

scenic torrentBOT
#

Gave +1 Rep to @weary spindle

weary spindle
spark wadi
#

i don't have that email acout anymore. i signed up over the fall and just now have gotten time to begin using the account.

weary spindle
#

Oh, I see.

Well, support will sort you out with the right information.

spark wadi
warm condor
#

Hi, i made a new THM account a while ago and forgot to link it with the discord bot but it still has my old THM account linked to it.
What do I do?

weary spindle
#

You need a mod to remove the link on your discord account, then you can link the new one.

warm condor
#

oh, ok, how i make them remove it?

weary spindle
#

You don't make them, you just post "Can a mod please remove my token from account, I'd like to switch to my new THM account please."

warm condor
#

ahh ok

#

thank you!

crystal marlin
crystal marlin
warm condor
#

ooh

#

lel yess please

crystal marlin
stray cove
#

Yeah ok

stray cove
warm condor
scenic torrentBOT
#

Gave +1 Rep to @stray cove

solemn jetty
#

seems it's either hit or miss when the dogcat boots up

hollow wharf
#

@gray loom @light vale I did it!, and yeah, new Kali VM and everything on the first try, ty to both of u

light vale
# hollow wharf

glad you manage to fix it, i think it's something with an kali update that messes up mfs database or something, gonna have a task that i need to use it again and i've updated again let's see how it goes 😄

#

What's good with these prebuild kali images is that if you need a new one you can just set it up in a matter of minutes

#

I think i'm gonna keep one updated and one without any updates on it just for these kind of things

hollow wharf
#

Completely agree, I'm saving the OVA file if i need a fresh install

gleaming lynx
#

is there a trick to use the same openvpn file on two machines at the same time? I want to use tools like burp on my windows machine while i am using netcat on my raspberry pi4.

broken bear
#

Think about this a bit: is the IP address the same every time you connect with your THM OVPN profile?

gleaming lynx
#

I mean couldn't i set something like a switch to manage the traffic?

naive dust
#

uhm, hello there! I needed some help. My pc was infected by a ransomware called dmay. now all of my files are encrypted and it's asking for 980 dollars. Is there any way I can decrypt all of them. Please help

unique raft
#

I'm unable to login on thm site from my phone, but from others phone it's always working.
Everytime I try to login from my phone, I got error regarding wrong credentials. I tried changing from chrome to brave to edge but the story is same. Can anyone help me to understand this? Should I consider this DoS from tryhackme 🥲?

zealous yoke
#

check for auto-fill and things

#

also, no, that is not what a DoS is

unique raft
#

I've been trying these for whole week.

solemn elm
#

anyone know how to regain access to a already hacked ig accoutn

eager fulcrum
lapis brook
#

Metasploit room unable to load on the Complete Beginner Learning Path.

#

I did. I even tried different browseR. Logged in logged out. Same.

#

The console got a bunch of errors.

#

Done that yea.

#

It worked now. I changed vpn server. Appreciate the help!

signal nymph
#

A better way to import the PowerView:

  1. Rename-Item PowerView.ps1 PowerView.psm1
  2. Import-Module PowerView.psm1
  3. Now you can use the Get-Command to list all the imported functions:
    Get-Command -Module PowerView
  4. Then you can use Get-Help to output available flags for every function:
    Get-Help <function-name>
vestal glacier
#

From Egy-pt and cannot connect to the VPN, Tried all day long and different vpn clients but with no luck

#

have been trying proxies but no luck finding a good one too

vestal glacier
bronze vale
low robin
#

Hi I am doing my labs using attackbox. But it keep on disconnecting

#

Even though I am using subscription labs and facing this issues from couple of days.

scenic torrentBOT
#

Gave +1 Rep to @signal nymph

gritty lagoon
#

Is there any known issues with OpenVPN configuration pack for windows? It keeps telling me that the server could not find the download.

crystal marlin
gritty lagoon
#

Yes

crystal marlin
gritty lagoon
#

Awesome thanks

vestal glacier
scenic torrentBOT
#

Gave +1 Rep to @bronze vale

dire night
#

Hy

eager fulcrum
#

@dire night Now that's not very nice, is it?

bronze vale
vestal glacier
eager fulcrum
vestal glacier
#

👍

eager fulcrum
#

-warn @vestal glacier Stop asking how to bypass VPN restrictions in your country, this is illegal and will not be tolerated. This is your final warning, any further discussion or questions about bypassing restrictions will mean that you will be banned.

scenic torrentBOT
#

⚠ Warned Sharafantah#6384

vestal glacier
#

haha

twilit briar
#

Hello, I'm not sure if I can ask this question here...
Could someone help me out...
I wanted to change my username on my account?
How do I do it?

sharp bisonBOT
twilit briar
#

Thank you.

scenic torrentBOT
#

Gave +1 Rep to @gray loom

cinder thistle
#

Keep in mind that when I generated mine, it took ~5 minutes

sharp bisonBOT
#

Ok @pale crypt, you will now be notified of future announcements.

tight egret
#

How can i go to do cyber

pliant anvil
#

Hi There, when opening a Windows machine in the browser for the Splunk training, I see a blip of it spinning up and then just black screen. Anyone have that issue? Thanks!

verbal dagger
crystal marlin
mortal citrus
#

Been searching through old post to find the answer myself with no luck.

How does the streak timer work? 24 hours from what? Is it midnight GMT? I know it's not midnight my timezone

naive dust
#

salut y a t'il qlqn à qui je peux poser une question ?

drifting ravine
#

#site-support

I hope you find this well. I’m connected to vpn but for some reason I can’t connect to the tryhackme box via the browser. The machine im using is Kali Linux on a raspberry pi 4. Would you happen to have a solution?

sharp bisonBOT
drifting ravine
#

OWASP Top 10

#

I’m trying to do tasks 5 to 7 in browser

sour linden
#

hi. i have some issues with the VPN. after 30-60 seconds, i am getting disconnected. impossible to ping the target or anything.
i have this error :

2022-04-25 16:51:47 TLS Error: Unroutable control packet received from [AF_INET]18.202.129.195:1194 (si=3 op=P_CONTROL_V1)
2022-04-25 16:51:52 TLS Error: Unroutable control packet received from [AF_INET]18.202.129.195:1194 (si=3 op=P_CONTROL_V1)
2022-04-25 16:52:00 TLS Error: Unroutable control packet received from [AF_INET]18.202.129.195:1194 (si=3 op=P_CONTROL_V1)
2022-04-25 16:53:39 [server] Inactivity timeout (--ping-restart), restarting
2022-04-25 16:53:39 SIGUSR1[soft,ping-restart] received, process restarting
2022-04-25 16:53:39 Restart pause, 5 second(s)
2022-04-25 16:53:44 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2022-04-25 16:53:44 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2022-04-25 16:53:44 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.129.195:1194
2022-04-25 16:53:44 Socket Buffers: R=[212992->212992] S=[212992->212992]
2022-04-25 16:53:44 UDP link local: (not bound)
2022-04-25 16:53:44 UDP link remote: [AF_INET]18.202.129.195:1194
2022-04-25 16:53:44 TLS: Initial packet from [AF_INET]18.202.129.195:1194, sid=04fb4970 343dd8ef
2022-04-25 16:53:44 VERIFY OK: depth=1, CN=ChangeMe
2022-04-25 16:53:44 VERIFY KU OK
2022-04-25 16:53:44 Validating certificate extended key usage
2022-04-25 16:53:44 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2022-04-25 16:53:44 VERIFY EKU OK
2022-04-25 16:53:44 VERIFY OK: depth=0, CN=server
2022-04-25 16:53:44 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, 2048 bit RSA
2022-04-25 16:53:44 [server] Peer Connection Initiated with [AF_INET]18.202.129.195:1194
2022-04-25 16:53:45 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)

drifting ravine
#

Yes it does

#

Okay

#

Understand @gray loom

#

Understood

#

@gray loom it works

#

@gray loom

#

doing it now @gray loom

#

and that is when I will put the machine's IP into the browser right?

#

all fixed!!

#

Thanks @gray loom

scenic torrentBOT
#

Gave +1 Rep to @gray loom

drifting ravine
#

I’m having the same problem with task 7 on OWASP Top 10

astral cape
#

@drifting ravine can you verify vpn connection on the machine browser visiting THM access page? (sry for redundant msg :P)
https://tryhackme.com/access

drifting ravine
#

Yup

astral cape
#

interesting, not sure without more involved debugging ... i would try curl connect (same HTTP GET req from command line) ... then it could be browser issue

drifting ravine
#

Same as this @astral cape

#

?

astral cape
#

that just pings THM server to check VPN status, not the actual vm you're trying to hit

#

could just see response codes using:

curl -IL http://VM_IP:VM_PORT
#

replace VM_IP and VM_PORT with the middle of the url

mortal citrus
#

I keep losing my streak. Does a streak day start at midnight my time zone or a specific one? GMT?

drifting ravine
#

@gray loom on it

#

@gray loom and wait another 5 minutes?

#

it works now

#

thanks

naive dust
#

Hello

#

i found bug in tryhackme, where i send it

weary spindle
#

!docs bug-bounty

sharp bisonBOT
unique oak
#

help I cannot get past part 1 ( literally lol)

unique oak
naive dust
#

Thanks

shy cloak
#

How can I exclude size on dirbuster?

nocturne blade
#

forgot what e-mail I used for register, and cannot recover only by nickname

#

is there anyway ?#note checked all e-mails, found nothing by that nick

weary spindle
#

if you remember your username, or have the card details/paypal used to buy a if you ever did then contact support

#

!email

sharp bisonBOT
naive dust
#

Hi

#

I'm not able to access practice urls in my simulated machine can someone help

crystal marlin
#

!docs verify

sharp bisonBOT
vapid pagoda
#

Hi i started using THM yesterday. Its pretty cool. However I cant seem to get connected to the vpn. My terminal says i am connected but THM webpage says otherwise. Any help? 🙂

weary spindle
#

As I answered in general, the webpage can be buggy when you are connected.

ip a s if you have one tun# you should be ok.
10.10.10.10/curl should give you the THM IP.
If you visit 10.10.10.10 in a web browser, it should give you a connection verified.

#

Once it says "Initializing complete" just minimise that window.

vapid pagoda
#

Ty ^^

robust pollen
#

Anything wrong woth holo booted off and unable to get back on. Reconnected the VPN still the same.

silk marsh
#

Anyone has a good resource to study and practice SQLI?

crystal marlin
silk marsh
quick stag
hollow wharf
#

I need help the machines i start on vulnversity room dont seem to boot up properly and i already terminated the vm 1 time and it didnt work, any ideas?

kind ruin
#

Wait longer

sharp bisonBOT
kind ruin
#

Is your vpn properly connected

hollow wharf
#

ow wait

#

maybe not

#

reboot?

#

or . . .?

#

❤️

#

is that normal?

#

no i didnt

#

only by openvpn [file]

crystal marlin
#

Give it a minute before doing ip a s

hollow wharf
#

ow, thanks

#

it just dissapeared

#

Now i can connect and do the nmap scan properly

#

ty guyz 😄

onyx raven
#

hi

#

can some one help me hack a game please

hollow wharf
onyx raven
#

who i am not a fool nice girl

eager fulcrum
simple sky
#

what game?

eager fulcrum
#

-ban @onyx raven Asking for help game hacking. This is against the rules here. Ban appeals are by email: bans@tryhackme.com

eager fulcrum
scenic torrentBOT
#

🔨 Banned Jerom#1132 indefinitely

simple sky
craggy quarry
#

It says Wrong Answer Thou

crystal marlin
silent egret
#

@grizzled halo Whenever I try to do a reverse shell, netcat won't respond. At first I thought this was an issue with the .ovpn file so I re-download but the problem still persists.

grizzled halo
#

That's still too vague. How are you trying to get a shell, what is the payload, and why was your first thought the VPN file if everything else was working?

astral cape
naive dust
#

Hello everyone... Not really sure where to ask but what are the benefits if any of using my own vm or thm one? How do i use my own vm in rooms? Will centos do the job?

grizzled halo
#

I think this channel is for tech support, not VM advice

silent egret
naive dust
#

Ok thanks buddy!

scenic torrentBOT
#

Gave +1 Rep to @gray loom

amber jackal
#

to change the profile avatar picture, what format should the image file be? I've tried png, jpg, and gif and they all give me the same error that I need to select an image file to upload my avatar. tia

tight viper
amber jackal
#

haven't tried from a different browser, will give that a whirl.

tight viper
#

That's odd, tried logging out and back in. Maybe even using a different browser?

#

What is the current browser you have been trying?

tight viper
#

See if another browser will work, if not log out and back in.

amber jackal
amber jackal
#

just trying to use the same vaultboy image that Discord just let me upload with no issue.

tight viper
#

Might have to be something a staff member would look into. Could be an account issue, not quite sure.

#

Unless, try doing a different image and see if you are able to upload.

amber jackal
#

will try that

#

new image did the trick, guess it just didn't like that one for whatever reason

tight viper
#

Just find an alternative photo with vaultboy and you'll be all good 😄

amber jackal
#

yep, I'm good. thx for your help

naive dust
#

I have a old 21 inch Samsung TV how can I connect it to my pc as dual monitors?

tight viper
unkempt nest
#

Hi, anyone facing the "cannot accessing your paypal account" problem while trying to subscribe with paypal?

sullen vapor
#

Help me, im new to this and i cant figure this out
"What is the syntax to ping 10.10.10.10?"

celest wadi
#

Same on Windows and linux

sullen vapor
#

Ohh, thanks!

sullen vapor
#

Need help again lol
"What is the verb given to the job that Routers perform?"

weary spindle
#

routeers

sullen vapor
#

Huh

turbid ferry
weary spindle
#

Will give you a clue, didn't want to completely spoil it.

#

But Ainut is right, that is where that type of question would go.

sullen vapor
#

Oh so the questions on the web is like a room? Didnt notice that, but thanks!

weary spindle
eager fulcrum
celest wadi
light nacelle
#

Hi

#

How to start

#

?

wheat wagon
light nacelle
#

k

unkempt nest
unkempt nest
#

got it, thanks!

scenic torrentBOT
#

Gave +1 Rep to @gray loom

drifting ravine
#

#site-support I am currently having a problem SSHing into the current room i am working on. I did turn on my vpn and I have my VPN IP address logged. However when I try to SSH in my terminal , I always get a "Permission Denied, please try again" as the output. The room I am working on is the Sudo Security Bypass room . I appreciate any help.

eager fulcrum
drifting ravine
#

@eager fulcrum the credentials I am trying are from what I use to login into my THM dashboard.

eager fulcrum
#

Don't do that!

jovial mango
eager fulcrum
#

Never enter your THM password anywhere other than the THM website login!

weary spindle
#

I'd change your THM password.

eager fulcrum
weary spindle
eager fulcrum
#

It was transmitted encrypted over SSH, the VM won't be exfiltrating them

drifting ravine
eager fulcrum
#

Have a read through the text

#

If you are having trouble with something on THM, step 1 should be re-reading the task text

jovial mango
weary spindle
#

Or on a completely different task from the deploy task.

drifting ravine
#

thanks everyone!

#

Now what would I do with the password then?

#

Should I change it ?

#

for my dashboard

#

understood but for my dashboard login

weary spindle
#

You should be fine

drifting ravine
#

understood, thank you

#

I am in

naive dust
#

Hello, It is any way to download a suscription bill to justify suscription with my company?

drifting ravine
#

#site-support I am trying to ssh into Polkit v1.2 room's box but I get a connection refused. The command inputted into the terminal was ssh tryhackme@10.10.14.219 - p 2222 but still received a connection refusal. Any help would be appreciated!

wheat wagon
drifting ravine
wheat wagon
drifting ravine
wheat wagon
#

You sure the ip address is correct and the machine is running?

drifting ravine
#

yes

wheat wagon
#

Are you able to ping it?

drifting ravine
#

no

#

nothing from the ping scan

wheat wagon
#

You are connected to the VPN?

drifting ravine
#

yes

#

could it be i didn't terminate another machine from prior?

wheat wagon
#

I dont think that should be a problem.

drifting ravine
#

no my internet went out i gotta fix it

#

yes I could now

#

now what?

drifting ravine
#

lassi I am on a room and figured that issue prior out

#

@gray loom when i try to ssh into my machines IP on port 2222 i receive a unable to negotiate with IP no matching host key type found. Their offer: ssh-rsa"

#

Overpass 2 - Hacked

#

Task 3 - Get Back In!

pale crypt
#

Hello there! I keep getting this error Unable to negotiate with 10.10.157.63 port 22: no matching host key type found. Their offer: ssh-rsa,ssh-dss when trying to ssh into Linux PrivEsc machine. Does someone know how can I fix it ? I tried to reboot my machine, the THM machine, ssh service ... ^^

celest wadi
pale crypt
#

Awesome, ty ! ^^

scenic torrentBOT
#

Gave +1 Rep to @gray loom

neon remnant
#

Good evening people, I could use some help.
I am struggling with my new mobile system (a macbook air m1). I want to hammer on some boxes with that machine but I kinda don't want to install a VM as all the tools I need seem to work just fine.

Problem:
I can't access any webpage from a machine. If I am trying to do so, it would just load to the end of time and won't respond.

I know that kind of misbehaving from my kali working station and changing the MTU to 1200 did the trick for me.

I tried to do the same on macos but It is limited to a minimum of 1280 and that didn't seem to work.

And yes ...

  • I tried to ping the machine -> works fine
  • I reloaded and replaced the openvpn file a few times
  • I tried to use the openvpn GUI thing
leaden bolt
#

Good afternoon all. Is it possible to change my username so that I can add a more professional name to the certs earned from the learning paths? Le Prawn will probably raise some questions in a corporate environment 😋

sharp bisonBOT
neon wigeon
#

Burp Suite Repeater I think is a completely different version of Burp. I cant view the inspector, plus following each step, even watching tutorials Im unable to get the flag in task 6 ;/ I dont see any raw data, adn followed maybe 3 different tutorials to a tee. Has anyone been able to get it to work? Im using Kali in the browser

sharp bisonBOT
neon wigeon
#

thank you! I'll try attackbox then and see if it works on there. I wish i knew their Kali was outdated. I spent a good 2 hours redoing this lab trying to figure it out lol

scenic torrentBOT
#

Gave +1 Rep to @gray loom

neon wigeon
#

yeah I figured it would too. Its the first time I ran into the problem. Burp couldnt (made sure intercept was on/off at right times) render the page in the repeater and the raw data wouldn't give the flag (Edit: Got the flag in attackbox)

leaden bolt
#

Thank you very much!

scenic torrentBOT
#

Gave +1 Rep to @gray loom

naive dust
#
  • Deleted -
heavy crypt
#

Hi I was wondering what's going on with the Web Fundamentals room, it keeps redirection to HTTP in Detail when I open it and I cannot complete the room due to that.

undone rock
#

same prblem here

#

except for me intro2windows reddirect to windowsfundamental

glass rapids
#

Hi I accidentally entered the wrong cvv when paying, the charge is pending but will be denied later. How do I repay?

Also I was working on burp suite. In the lesson it was basic installation and then some juice shop tasks.

Today it's called something different "burp suite basics" and all my progress. I checked all other burp rooms and while some are similar, none are the room I was working in.
Has there been an update?.

celest wadi
#

!email

sharp bisonBOT
celest wadi
#

And yes, the old burpsuite rooms were deprecated AFAIK, and replaced with newer up to date content

glass rapids
#

@celest wadi ah okay thank you... Especially for the burp suite info.
I was mad!

I also went to the thm payment page, updated my card so hopefully that works. I still have vip access so all good so far.
Thank again for your help!

scenic torrentBOT
#

Gave +1 Rep to @celest wadi

hexed summit
#

did the Metasploit room just update?

hot charm
#

Hi everyone,

silk marsh
#

Hey, does a GET request can delete something?

hot charm
#

I am having an issue with machines web pages, they wouldn't load in browser. I can ping the machines and scan them using nmap but web pages are not loading.

hot charm
#

the web page keeps loading but nothing opens

silk marsh
#

Do you have Burp opened?

hot charm
#

no

silk marsh
#

Any proxy in use?

hot charm
#

no proxies, i am only connected to thm's VPN

silk marsh
hot charm
#

same issue

placid mango
#

Which room?

hot charm
#

all machines on the web hacking fundamentals module, but right now i am on the OWASP top 10 room

placid mango
hot charm
#

yes, it gives me my ip address assigned to tun0 interface

placid mango
#

Okay, so which task from owasp room you are doing?

#

Also, verify with bot so you can send screenshots.

#

!docs verify

sharp bisonBOT
hot charm
#

Task 5: Command Injection Practical

placid mango
#

Show screenshot of ip a command and another screenshot of what happens when you visit the url given in tasks.

hot charm
placid mango
#

Have you tried any different browser?

hot charm
#

i have tried brave browser and chromium on burp

#

but same issue

placid mango
#

What happens when you use curl command to that url?

hot charm
#

it responds !!

#

other machines in the same module (web hacking fundamentals) won't respond anything even when using curl

placid mango
# hot charm

That's strange... Looks like a browser to me. Try installing chromium. apt update && apt install chromium and see if it loads or not.

hot charm
#

i have installed brave browser and used it's default settings but nothing happened !

#

i will try with chromium, give me a sec

#

i searched about this issue and found others having the same thing but i found no solutions for it

placid mango
#

Do you this problem with other rooms or only this room?

eager fulcrum
#

MTU issue

woven lantern
#

i'm having trouble with nmap room task 12 it's not accepting what i belive is the correct answer

#

sorry task 11

hot charm
woven lantern
#

with this question to be specific
What optional argument can the ftp-anon.nse script take?

placid mango
hot charm
eager fulcrum
#

Try the MTU fix.

hot charm
eager fulcrum
hot charm
woven lantern
#

@eager fulcrum tbh i can't find the hints in this room and i was suspecting an answer and after searching online for a while i found out that most ppl say that it is the correct one so now i'm pretty sure that the answer i'm typing is the correct one but it's still not working

eager fulcrum
hot charm
#

Thanks a lot i really appreciate it @eager fulcrum @placid mango

scenic torrentBOT
#

Gave +1 Rep to @eager fulcrum

neon remnant
eager fulcrum
#

You have the same problem as yourself?

neon remnant
#

yes.

silk marsh
#

Haha

neon remnant
#

No, I mean with the MTU fix

#

okay, found a fix for macOS user.
If you have the same problem try the following command:
sudo ifconfig utun10 mtu 1200

dapper holly
#

hello tryhackme, I made a small lapse in relation to my subscription on the platform, I forgot to cancel on the last day and the subscription was extended until the next month, the bank is now charging me and the problem is that I can not afford, can I get the refund?

crystal marlin
#

!email

sharp bisonBOT
dapper holly
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

quaint moss
#

can you change your username?

crystal marlin
quaint moss
#

Thanks

sterile gate
#

Hi guys, is't still posible to have the student discount in the vip subscription? And how can I get it?

weary spindle
#

!email

sharp bisonBOT
vestal glacier
#

Can I tunnel the vpn client file .ovpn through proxy? the proto udp doesn't accept the http/https/socks4 local proxies

#

I think it accepts the socks5 but how to do it if I am right?

coral pine
#

I was nearly finished my Complete Beginner cert and now it seems like all my Burpsuite rooms have reset on me.. Any reason this would happen?

coral pine
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

crystal marlin
coral pine
#

And they are all the same tasks in Burp Suite room

crystal marlin
coral pine
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

crystal marlin
coral pine
coral pine
# crystal marlin Ye they might be kind of similar, but definitely different.

Man, this kind of sucks. I know they are different rooms, but it is all the same stuff that was covered in the old rooms. I was nearly finished the cert before and now I have to do all of this again. The path shouldn't be changed for existing users. Can you please pass along my feedback as I never get responses on the site?

pale hamlet
#

Anyone here good with qBittorrent?

balmy osprey
#

after i ran a room when i look in my mac with ifconfig and i get gif0, stf0, api1 and so how can i disable it?

jovial mango
#

sudo ifconfig <controller name> down

tidal beacon
#

Hi guys,
I have an access issue and hope I can find a solution here.
I renewed my premium access since April 12 but I do not have premium access.
I wrote to support by email but no response yet.

crystal marlin
# coral pine Man, this kind of sucks. I know they are different rooms, but it is all the same...

Well, I don't know how they should change the path for existing users and for new users, the paths are the same for everyone. Also, learning is all about repetition, so I don't think it's that bad to do that room again.
Have you been at #feedback-and-ideas already to express that?
I understand, it's unfortunate that you have to do this room again, but at a certain point they had to remove outdated rooms with the new ones. If they would have done it 2 weeks later, maybe someone else would have been affected, so it's just kind of bad luck that it hit you 🙂

coral pine
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

maiden folio
#

Hi guys can i speak with a modo for a problem on my room? 🙂

placid mango
crystal marlin
maiden folio
simple sky
#

why? what is the problem?

crystal marlin
marsh shoal
#

I can't seem to find a way to copy into Windows machines, does anyone have an idea how to do that?

crystal marlin
#

And copy what?

marsh shoal
marsh shoal
maiden folio
#

I try to list the document on the machine with ls or dir and i got a NT_STATUS_UO_TIMEOUT listening *

simple sky
marsh shoal
crystal marlin
simple sky
simple sky
crystal marlin
marsh shoal
scenic torrentBOT
#

Gave +1 Rep to @simple sky

simple sky
marsh shoal
maiden folio
simple sky
#

send here

#

so other ppl can see it and help you if I can't

crystal marlin
#

!docs verify

sharp bisonBOT
maiden folio
crystal marlin
maiden folio
#

yep

crystal marlin
#

Also, please provide a screenshot of where you got the target machine IP from

crystal marlin
maiden folio
crystal marlin
maiden folio
crystal marlin
maiden folio
# crystal marlin Works just fine, could you check `ip a s` on your attacking machine and show me ...

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: enp4s0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc fq_codel state DOWN group default qlen 1000
link/ether 24:4b:fe:87:a2:fd brd ff:ff:ff:ff:ff:ff
3: wlp3s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
link/ether 70:66:55:f9:c8:23 brd ff:ff:ff:ff:ff:ff
inet 172.20.10.2/28 brd 172.20.10.15 scope global dynamic noprefixroute wlp3s0
valid_lft 77919sec preferred_lft 77919sec
inet6 2a01:cb1a:4055:3151:808e:ce9e:c286:4acd/64 scope global noprefixroute
valid_lft forever preferred_lft forever
inet6 fe80::a5d3:4a45:e9aa:9425/64 scope link noprefixroute
valid_lft forever preferred_lft forever

crystal marlin
maiden folio
#

i'm on my host machine

crystal marlin
maiden folio
#

i can't sen the entire response

#

too long ^^

crystal marlin
maiden folio
crystal marlin
maiden folio
#

nope

crystal marlin
maiden folio
crystal marlin
crystal marlin
maiden folio
#

But I don't understand why it wasn't working

#

x)

crystal marlin
# maiden folio But I don't understand why it wasn't working

As far as I understand, that might be an issue with encapsulation, so if there are a couple of devices in between you and the vpn server, the packets get too big, but I could misunderstand that, so don't take that as right. If anyone with better networking knowledge could correct me, that would be highly appreciated 😄

maiden folio
maiden folio
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

scenic torrentBOT
#

Gave +1 Rep to @placid mango

odd vine
#

@sharp bison you guys seem to have an issue with your payment system rejecting payments from UK cards. It seem related to SCA (Strong Customer Authentication)

#

buying vouchers with a card from the UK isn't possible, all cards are being rejected.

modest surge
#

Everytime I try and download my configuration file for accessing via openvpn I just get a 404?

modest surge
#

already done all that myself but I'll just wait some more ig

crystal marlin
modest surge
#

aand now it's working

modest surge
crystal marlin
humble fern
#

Hello, maybe someone can help me. I completed the burp modules, answered all question, everything is ticked with the green validation icon.
But in my dashboard it shows as not finished.

#

Someone already seen that before ?

#

All task ok

crystal marlin
# humble fern All task ok

You sure that's the same room? And not the Burp Suite: The basics since that's a different room then just Burp Suite (which got removed)

#

So I assume, if you click on Burp Suite it's redirecting you to Burp Suite: The basics

humble fern
#

I don’t know, I’ll try to check

#

At least I maybe have an answer

crystal marlin
odd vine
#

@crystal marlin can you assist with payment issues?

crystal marlin
#

!email

sharp bisonBOT
humble fern
#

But it’s directly from the path so it should be good ?

crystal marlin
humble fern
#

Ok it’s solved, I clicked on learn > seleted web fundamentals and it automatically updated the status

humble fern
#

Thanks for your help, it’s a weird bug 😂

crystal marlin
tawdry orbit
# humble fern

Looks like this is from the CompTIA Pentest+ learning path? The first module of that path has not been updated yet for Burp Suite and Metapsloit which redirect to newer rooms. 🙂

cunning chasm
#

Curious if someone could talk to me about some networking stuff to help me better understand some things going on with subnetting

weary spindle
#

Just ask away if you have any questions, a server with over 130000 users, someone will know the answer.

broken bear
knotty flicker
#

Hi there, my hacking streak counter just reset with the complete beginner path update just few days away to reach the 30 days badge. Any fix ?

plush bay
#

refresh the page

plush bay
knotty flicker
scenic torrentBOT
#

Gave +1 Rep to @plush bay

plush bay
#

no problem

empty stag
sharp bisonBOT
silver rapids
#

Question: is there an API I can use to create KOTH games? I see the requests being made, etc, but I still have to deal with recaptcha and cloudflare to script the creation of a room

tawdry elm
#

Hi peeps, got an issue, the dash is failing to progress even after completing the modules

tawdry elm
#

i redid the entire burp suite twice thinking that

#

every individual module is green and i get the fireworks at the end

worn aspen
#

Huh

#

is it a visual bug?

tawdry elm
#

very likely its just screwing my in progress dashboard and "continue learning"

#

if i hit continue learning it takes me back to the burp module

worn aspen
#

Try clicking on a new module

tawdry elm
#

logged out/in and on separate devices

worn aspen
#

maybe you finished the burp module and they want you to select a new one

tawdry elm
#

yup completed other modules as well

#

moved onto the next one metasploit and that did the same

worn aspen
#

What is the progress bar at?

tawdry elm
#

imgr links allowed?

worn aspen
#

idk

#

if not just dm

tawdry elm
worn aspen
#

Well that's certainly weird

#

and you said it's not letting you progress right?

tawdry elm
#

i can go manually select new modules but can't follow the path it sets out

worn aspen
#

Did you start any new modules?

tawdry elm
#

aye started new ones and completed them and earning levels just the dash is screwed for me and learning path

worn aspen
#

I've never dealt with this kind of issue, and I think it might just be save data, so try selecting the next path in your modules and going through them manually to "update" the save data.

tawdry elm
#

nods

elder forum
#

So I used the opvn like I was supposed to, but for some reason whenver I ping the target I get 100% packet loss

#

did I miss a step?

celest wadi
# elder forum

if you get your ip from
curl 10.10.10.10/whoami then you're connected :)

elder forum
#

I still have 100% packet loss

celest wadi
celest wadi
elder forum
#

oh bruh

#

yeah imu just dumb

#

how can u even disable that

celest wadi
naive dust
#

Anyone help me with attackbox.
It's too much slow, if I type or click anything it takes at least 15sec or more to work.

cursive sapphire
#

Its your network connection thats slow ig

naive dust
cursive sapphire
#

Well , it shouldn't lag for any other reason , certainly not for someone subscribed

naive dust
twin shale
#

hey

#

i completed the burp suite module

#

but it's not updating in the comptia pentest+ path

crystal marlin
#

You'll have to verify first to do so

#

!docs verify

sharp bisonBOT
twin shale
#

don't mind the link lel

#

it's not marked as done while i finished all the module

#

even this one

crystal marlin
#

If you could upload the actual screenshots directly in discord instead of somewhere else and post the link, that would be great, since I'm not too happy with opening unknown links, I can see enough from the preview, but just for further screenshots 😄

twin shale
#

you don't have to open the link just the image preview that discord send x)

#

but ok wait

crystal marlin
#

The Burp suite room is not the same as the Burp Suite: The basics

#

Ye, I just said I can see enough from the preview right now 😄

twin shale
#

yeah but i did all the the burp suite rooms x))

crystal marlin
#

The Burp Suite room got removed and replaced with Burp Suite: The basics so the room that's showing as not completed is a different one

twin shale
#

like all of them

#

oh

#

which one is it then

crystal marlin
# twin shale which one is it then

A removed one, if you click on that it's redirecting you to a different one, I'll report it so that it's getting changed in that path as well

twin shale
#

oh

#

so we can't get the pentest+ module done for now ?

#

since the room just doesn't exist ?

crystal marlin
twin shale
#

okok ^^

wary oyster
#

for some weird reason on my pc i cant verify the recaptcha

#

im using brave browser

#

no ad blocker or anything is on

#

nvm solved it, had to do with a vpn addon

naive dust
#

Hello

#

Can we remove the token from my discord account so I can re-verify it?

iron obsidian
#

hello, I'm on introtonetworking room, on "whois facebook.com" command I'm getting error of connect: network is unreachable

#

pls help

weary spindle
#

If you're a free user, you won't have an internet connection on the attackbox.

iron obsidian
#

do i have to be a subscriber to use whois

naive dust
#

you have to be a subscriber to make whois work. Without an internet neither it, nor traceroute will work

weary spindle
#

No.

#

Well.

#

Yes on the terminal.

#

But you could always use "Whois facebook.com" on google on your host machine.

naive dust
#

... wat

naive dust
#

interesting

iron obsidian
drowsy heart
#

root@ip-10-10-5-99:~# wfuzz -c -f out.txt -w '/root/Desktop/subdomains-top1million-20000.txt' --sc 200,202,204,301,307,403 http://FUZZ.nahamstore.thm

Warning: Pycurl is not compiled against Openssl. Wfuzz might not work correctly when fuzzing SSL sites. Check Wfuzz's documentation for more information.


  • Wfuzz 2.2.9 - The Web Fuzzer *

Target: http://FUZZ.nahamstore.thm/
Total requests: 19983

==================================================================
ID Response Lines Word Chars Payload

Fatal exception: Pycurl error 6: Could not resolve host: www.nahamstore.thm
root@ip-10-10-5-99:~#

#

I am getting an error when using wfuzz -- can't figure out why.

#

I added nahamstore.thm to etc/hosts

crystal marlin
drowsy heart
#

thanks for the help

wise flicker
drowsy heart
crystal marlin
#

If you verify you can send screenshots

#

!docs verify

sharp bisonBOT
drowsy heart
#

this is what it looks like on Kali, pycurl issue?

crystal marlin
# drowsy heart thnks

Is this the kali machine provided by thm or your own ?
In case it's the one by thm, I suggest you use the attackbox and try again.
Since that's a different error then you got previously.

drowsy heart
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

cinder thistle
#

I believe that you should be able to enumerate subdomains even from your own box

crystal marlin
cinder thistle
woeful nebula
#

Hi

#

How do I download certificated for old rooms/paths?

#

Let's say I want to download the certificate of Advent of Cyber 2021 because I lost it. How to I do it?

crystal marlin
woeful nebula
#

I can't see any certificate button

crystal marlin
woeful nebula
#

Yes I can see for 2021. Sorry, I meant I wanted to download for Advent of Cyber 2020. I can't see the button there anymore.

crystal marlin
woeful nebula
#

Oh. Is it same for other old rooms as well because I can't see for 2019 as well. I recently lost all the certificates from THM as they were in PNG format and my junk cleaner cleaned all the images from my file system. I forgot that I had certificates in PNG/JPEG as well.

#

Is there any way to download them? Can you please look into it and let me know or maybe perhaps ask any other mods who are maybe aware of it?

drowsy heart
#

I think this is the same error on the attack box. Just can't figure out how to run wfuzz :/

crystal marlin
drowsy heart
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

tidal shore
# iron obsidian traceroute works

Like completely or?
I assume the command itself should run but probes will just follow default route until (pretty shortly) somebody doesn't have a route out?

iron obsidian
tardy jewel
#

hi

#

i am new in this discord group

#

i have knowledg about computer things programing and stuf but i dont now phyton plz try to help me

crystal marlin
lofty gate
#

hello! I'm ripping through the "learning" tutorials... but am suddenly stopped by a never-ending spinning "loading" page. Nothing has changed on my end that I'm aware of. Is this a proper place to get help for this?

lofty gate
#

whoa! that did it. Can you tell me what this did? I guess it's a known issue?

lofty gate
#

thank you so much!

#

glad to know it wasn't just me. thanks again, Scrubz

iron schooner
#

My Attackbox on tryhackme keeps disconnecting while i use it. Does anyone know why?

bleak tusk
#

Can anyone help me iam in OWASP top 10 room To complete the questions below, navigate to http://MACHINE_IP/evilshell.php. I changed the machine ip to START MACHINE IP. Eventhough it shows "This site can’t be reached" 0.0.0.0 took too long to respond. 0.0.0.0 is the START MACHINE IP ADDRESS.

neat lark
#

hello, need support with failed payment recognition

weary spindle
#

!email

sharp bisonBOT
static brook
#

Hi There, currently working with authentication bypass room in Jr Pentester Pathway, for some reason I am unable to type in "" (double quotes and single) in the terminal, I searched online and discovered it to be a regional language setting issue, and the solution was to change the language preferences to English(US), but the Attackbox settings are set to English and English(UK) with English(us) greyed out. I can't completed any exercises as most requires the use of quotation marks in terminal commands. Please advise on a solution.

static brook
#

Never Mind, figured out

balmy osprey
#

after i ran one room my ifconfig have changed and now shows me wired staff

#

need help please

prisma palm
#

i m unable to connect to deployed machine via openvpn, help here for 'complete beginners room'

balmy osprey
#

gif0, stf0, anpi1, en3, ap1, awdl0, llw0, utun0

#

and more

#

I have done it and it’s stay the same

#

The pentesting

#

I used kali on my machine with openvpn

prisma palm
#

The file configuration file downloaded to be connected with openvpn is unable to connect, i changed the servers and the message displayed is "connection timedout"

#

I am connecting using windows with openvpn

#

okie thanks

prisma palm
#

getting the same result as when connecting using windows, and i changed to all the available configuration files. anything else you recommend ?

solar hearth
#

Can anyone explain me how this one is working? I did 1 question a day and my streak still resets.. Did i do smth wrong, or it's a bug in site?

zealous yoke
# solar hearth Can anyone explain me how this one is working? I did 1 question a day and my str...

You need to do one every 24 hours, it doesn't work on a day basis in that sense. Also, make sure you have your timezone set correctly in your profile (make sure you have no vpns running, the thm is okay):

https://tryhackme.com/api/user/update-timezone

It will redirect you to the /dashboard if it is successful

solar hearth
#

Thanks Ben, so to keep streak i must to do next task not later than 24h from last one.. Got it, thanks again (also idk if timezone had impact on that, but i opened that link too - it redirected me to dashboard, hope it would be ok now 🙂 )

zealous yoke
#

There is a bit of a bug where your profile get set to Afghanistan by default, so you'd be following their day/night cycle which could be very different for when you're likely to be answering questions based on w/e your actual timezone is (:

#

but that link updates it once and for all unless you visit it again from another country etc

#

so to keep streak i must to do next task not later than 24h from last one
yup precisely (:

#

For example, you'll loose a streak if you do a question at 1PM, then do another question at 3PM the next day. It's "the next day" but it's not within 24 hours of your last question

balmy osprey
zealous yoke
# balmy osprey Someone can help me please?

It looks like they're all apple mac interfaces. How are you running the network adapter on your Kali VM? Is it bridged? Are you running ifconfig on your mac by accident?

As long as it's working, and you see tun0 it should be fine. The THM VPN won't create network interfaces other than the tun0 (which is OpenVPN)

balmy osprey
zealous yoke
#

I have no idea, and I don't think you're supposed to delete the interfaces. They may be made by the hypervisor/mac os to support the virtual machine https://superuser.com/questions/267660/can-someone-please-explain-ifconfig-output-in-mac-os-x

zealous yoke
#

No idea then, just apple shenanigans maybe. If you can browse the web, and your THM vpn works then I wouldn't worry tbh

#

Not really much more we can do here

balmy osprey
#

👍🏻

toxic quail
#

hi guys i have an arduino attiny85 and i am having some code errors can anyone help me

near coral
#

Wrapped up the burp course all the checks are green but the pentest path still shows it incomplete? Any way to make it check again or something?

mortal yoke
#

I need the close all session of my account in all device, How can I do?

gleaming current
#

Can I ask some basic questions about Vim here?

stray wadi
#

I am not able to connect to OpenVPN. I tried everything but still I am not able to connect.

#

It's just stuck on this forever

shy cloak
#

first time I've encountered this "Uh-oh! You can only deploy a maximum of 3 machines at a time." any help 🙂

prisma stirrup
candid geode
#

hi guys, i need some help, it happened when i went to install the kali linux iso for dual boot and it happens that my computer recognized some things as a virus. It's normal?

true nest
#

I mean Kali ISO may show up as malicious but that’s a bit overkill. If you got the Kali ISO from their official site, and heck even checked hashes with their published ones, then it’s fine

candid geode
#

it was from their original website

true nest
#

I wouldn’t worry much about it, but remember that Kali should not be permanently installed as an often used OS, with always root you need to be very careful about when you deploy it

#

Dual boot isn’t the best idea for Kali, a live USB is more than enough

#

personally I just install the tools myself in my own Arch install but yeah that’s not so quick heh

gaunt pier
#

Or a virtual machine

gaunt pier
true nest
#

yeah I shouldn’t have mentioned it lol, just my solution

#

do not recommend Arch for beginners

gaunt pier
#

Oracle VBox

true nest
#

heh, Player or Workstation Pro

gaunt pier
#

And deploy the ISO on it

candid geode
gaunt pier
#

And enjoy the installation

gaunt pier
candid geode
#

4gb ram

gaunt pier
#

VM needs atleast 8gb ram

#

To run smoothly

broken bear
gaunt pier
#

8gb in host pc

#

Just upgrade ur RAM

#

Add another 4gb and it will start working smoothly

candid geode
#

I used dual boot a while ago but it never happened, maybe it's because of windows defender

gaunt pier
true nest
#

Defender can't read Linux ext4 filesystems, wouldn't have been a factor

candid geode
#

Kali linux 2022.1 changelog

true nest
#

Don't dual boot Kali, VM or live USB

#

I have a virtual private server for pentesting but that's more advanced

gaunt pier
#

Windows is troublesome OS if u want to dual boot

#

Really really troublesome

true nest
#

Windows first then Linux, but yeah there's a lot that can go wrong

candid geode
#

when I used avast this never happened

true nest
#

I mean technically Kali ISO is malicious

#

Makes sense for it to be detected

#

Just check hash and you're fine

candid geode
#

I used wsl2 but I didn't like it very much so I removed it

true nest
#

WSL has extremely limited networking capabilities anyways

#

VMs or live USB is a better solution

gaunt pier
#

Or a AWS Cloud Server

broken bear
true nest
#

Yeah just even then, won’t do Kali properly. I do think it’s in the MS Store lol

spark spoke
#

Hi @fallen cave

#

So towards the problem i had

fallen cave
#

Yes

fallen cave
spark spoke
# fallen cave Can you tell me what is wrong from the beginning

I had a problem with Oracle VM so before I uninstalled Oracle VM, I copy pasted the whole Kali Folder under Program Files -> Oracle where the Kali Linux folder was located onto my seperate external hard drive. It's been like 4-5 months and I have reinstalle back Oracle VM. My question is can I paste back the Kali Linux folder which was located in Program Files -> Oracle back there now ?

fallen cave
#

Later stuffs please DM me

spark spoke
#

ok

remote vault
#

hello can anybody tell me how can i use my discord token

crystal marlin
sharp bisonBOT
weary spindle
spark spoke
scenic torrentBOT
#

Gave +1 Rep to @weary spindle

dawn shuttle
#

Hey i installed the java-11-openjdk package on fedora but ghidra says it can't find it and neither can I tbh

******************************************************************
JDK 11+ (64-bit) could not be found and must be manually chosen!
******************************************************************
Enter path to JDK home directory (ENTER for dialog): 
Opening selection dialog...


Not a valid JDK home directory. Missing bin directory!
Enter path to JDK home directory (ENTER for dialog): Opening selection dialog...
Not a valid JDK home directory. Missing bin directory!
Enter path to JDK home directory (ENTER for dialog): Opening selection dialog...
Not a valid JDK home directory. JDK is missing javac executable!

#

I entered a couple versions that i found in /usr/lib/jvm

manic wind
#

anyone know why im getting this

celest wadi
manic wind
#

download it again?

celest wadi
#

Yep

manic wind
#

1 sec

#

hmm I switched servers and it worked

#

thanks

celest wadi
#

🙂

weary spindle
#

Now that's not very friendly...

celest wadi
#

Fineeee...

soft dagger
#

this might be real obvious and im just not seing it but; search bar for the platform? ie i want to see a room on exchange_proxyshell_rce in metaplsoit - how can i search the website for rooms/tutroials on this?

plush bay
#

doubt it would get you exactly what you want in this use case though

prisma palm
soft dagger
scenic torrentBOT
#

Gave +1 Rep to @plush bay

prisma palm
plush bay
#

i.e clicking the learn button at the top of the page and then a bit down there is a search tab

prisma palm
#

can you help i am unable to connect to the machine via openvpn

#

yes done that

#

no

tidal shore
# prisma palm

That doesn't say much other than that it didn't work, try to add more verbose output (-vvv or whatever openvpn uses idk) or maybe check tcpdump -i eth0 host 3.7.33.194 etc

prisma palm
#

Okay shall try that

final garden
#

is there anything I can do to get my streak back?

plush bay
#

if we don't count the slow but efficient way of making a new streak

rain ridge
#

For some reason my openvpn isn't working anymore and get this error

#

Cipher negotiation is disabled since neither P2MP client nor server mode is enabled
Options error: You must define TUN/TAP device (--dev)

jovial mango
rain ridge
#

I'll try that again now

weary spindle
#

!vpnscript

sharp bisonBOT
weary spindle
#

Could also try that.

rain ridge
#

Never really had problems before until now. Got the VPN working and saying sequence complete but when I refresh the connection page and the website itself still says access machines

crystal marlin
celest wadi
rain ridge
radiant pike
#

yo guys im trying to connect to the vpn server but it's giving me a hell lot of errors

#

classic sudo openvpn username.ovpn doesnt work and it reports Cipher negotiation is disabled since neither P2MP client nor server mode is enabled Options error: You must define TUN/TAP device (--dev)

#

then i put --dev tun

#

but it says Options error: I'm trying to parse "Valeryum999.ovpn" as an --option parameter but I don't see a leading '--'

#

and now i'm stuck

crystal marlin
#

Also, have you altered your ovpn file in any way?

radiant pike
#

nope

#

how can i screenshot from linux?

#

i tried one last resource:

#

sudo openvpn --config ./Downloads/Valeryum999.ovpn --dev tun 2022-05-02 16:20:34 Cipher negotiation is disabled since neither P2MP client nor server mode is enabled 2022-05-02 16:20:34 OpenVPN 2.5.5 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Feb 21 2022 2022-05-02 16:20:34 library versions: OpenSSL 1.1.1n 15 Mar 2022, LZO 2.10 2022-05-02 16:20:34 ******* WARNING *******: All encryption and authentication features disabled -- All data will be tunnelled as clear text and will not be protected against man-in-the-middle changes. PLEASE DO RECONSIDER THIS CONFIGURATION! 2022-05-02 16:20:34 TUN/TAP device tun0 opened 2022-05-02 16:20:34 Could not determine IPv4/IPv6 protocol. Using AF_INET 2022-05-02 16:20:34 UDPv4 link local (bound): [AF_INET][undef]:1194 2022-05-02 16:20:34 UDPv4 link remote: [AF_UNSPEC]

#

but it never does anything

broken bear
#

Is linux a guest? Just use the host screenshot tool

radiant pike
#

where do i find this

broken bear
#

Is your linux install a VM or bare metal?

radiant pike
#

i'm in dual boot

#

bare metal i'd say

broken bear
#

So bare metal.

#

How are you connected? Wifi or wired?

radiant pike
#

wifi

broken bear
#

is your adapter fully supported by your distro?

radiant pike
#

uhm

#

i think so?

broken bear
#

Ok. What's the output of ip a

radiant pike
#

how would i be able to be online otherwise

#

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: wlan0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether 80:30:49:a5:5e:a1 brd ff:ff:ff:ff:ff:ff
inet 192.168.1.17/24 brd 192.168.1.255 scope global dynamic noprefixroute wlan0
valid_lft 21210sec preferred_lft 21210sec
inet6 fe80::8230:49ff:fea5:5ea1/64 scope link noprefixroute
valid_lft forever preferred_lft forever

broken bear
#

what distro are you using?

radiant pike
#

Linux 5.15.0-kali3-amd64

broken bear
#

is that the latest rolling release?

radiant pike
#

no i dont think so

#

but the thing is openvpn worked before

#

now i wanted to change servers

#

but it all messed up

broken bear
#

can you post the beginning of your ovpn file? first line through <ca>

#

the rest of the file should be certificate and keyinfo

radiant pike
#

lol it's empty

#

wtf

#

but it's empty

#

i'm using the EU-VIP-2 server

broken bear
#

regenerate the file and wait a minute or two before downloading

radiant pike
#

alright i'm trying

#

thank you for your time and help!

#

still empty

broken bear
#

Are you a paid subscriber?

radiant pike
#

yes

#

i just made the subscription

broken bear
#

It might take a few minutes for account changes to propogate through.

#

Can you generate a non-VIP config file?

radiant pike
#

it makes sense, i'll retry later then

radiant pike
broken bear
#

I think the next thing to do is email support

radiant pike
#

alright, i'm gonna retry in a couple of hours, if it doesn't work by then i'll write to email support

#

thank you regardless :D

cursive sapphire
#

What do you need help with?

broken bear
#

Don't spam multiple channels asking for help. Everyone is a volunteer, please ask your question in the appropriate room and wait patiently

prisma palm
scenic torrentBOT
#

Gave +1 Rep to @tidal shore

tidal shore
# prisma palm thank you so much for your input, fyi i am beginner level, so please bear with m...

for openvpn it looks like the verbosity is controlled this way:

--verb n
    Set output verbosity to n (default=1). Each level shows all info from the previous levels. Level 3 is recommended if you want a good summary of what's happening without being swamped by output.

    0 -- No output except fatal errors.
    1 to 4 -- Normal usage range.
    5 -- Output R and W characters to the console for each packet read and write, uppercase is used for TCP/UDP packets and lowercase is used for TUN/TAP packets.
    6 to 11 -- Debug info range (see errlevel.h for additional information on debug levels). 

(just experiment and see where more detailed/useful messages start to appear)

The tcpdump command is going to show all the packets that are passing through the 'eth0' network interface to/from the given host IP (may vary, check 'ifconfig')
(You can filter it further if needed but presumably there shouldn't be a lot of other unrelated traffic between your machine and the VPN gateway's public address)

The log so far tells us the TLS negotiation didn't happen and suggests checking network connectivity, and also says the TLS handshake failed (maybe it failed in and of itself for a separate reason, or maybe it just failed because it never got started at all?)
So this way you can see, is any packet at all sent to the VPN gateway? Does any reply come back? Does it stop early or is any clue visible in the contents of the packet, is the source/destination address or something else not as expected, etc. And overall you can get a lot of information about where exactly the failure is happening (in your computer or in someone else's, for one) and hopefully why

prisma palm
tidal shore
#

Do you get anything else if you add --verb 3 to the openvpn command? And then increasing the number by one at a time if it still doesn't have any more details about the TLS procedure?