#site-support

1 messages · Page 278 of 1

nocturne orbit
#

Hmm. Thx. Didn’t think of that. If I’m ever able to get back to trying this room, I’ll keep that in mind. TY

little moss
#

Is there a way to filter the box search via OS?

#

Im trying to get a list of all Windows machines

nocturne orbit
#

So, not trying to be a pain, but if we have an issue, like I cannot get the victim to terminate, is there any path to support?

nocturne orbit
#

So, I’m working the Relevant Pen Test Challenge room. The VM dies after around an hour. Which I can manage. But my Active Machine show time left, but the machine doesn’t respond. So, try to terminate. Pop up says terminated, but when I try to start up a new VM, pop up claims I have an active machine, which shows in the browser. Browser refresh, clear cache, reboot my PC, nothing works. I guess I can wait out the ticker, 54m left, but it’s kinda inconvenient

crystal marlin
nocturne orbit
#

TY. Gave that a shot. VM is still hung. AttackBox did terminate, as expected. I’ll wait out the timer. TY for the advice, most appreciated!

lone stone
#

would anyone be able to help me with retrieving my 2020 advent of cyber completion certificate?

celest wadi
lone stone
#

no i dont

#

i dont even see a button on the 2020 one to retrieve it

magic void
#

can anyone point me towards attacktive directory support?

mellow oriole
#

I'm having an issue with getting OpenVpn to connect. Is that something I can get help with here?

mellow oriole
#

Tue May 10 13:47:11 2022 TCP: connect to [AF_INET]192.168.29.191:443 failed: Connection refused
Tue May 10 13:47:11 2022 SIGUSR1[connection failed(soft),init_instance] received, process restarting

  • Get the above error when attempting to use the product. Ensured firewall rules allow for TCP on 443 and UDP on 1194
eager fulcrum
mellow oriole
eager fulcrum
#

Yes

#

!docs vpn

sharp bisonBOT
#
TryHackMe
That topic does not exist!

Use !docs to list all of the available topics.

eager fulcrum
#

Oh it's just !vpn

eager fulcrum
mellow oriole
#

@gray loom Yes

#

worth@worth-Legion-S7-15ACH6:~$ ls -lpah /home/worth/twenger128.ovpn
ls: cannot access '/home/worth/twenger128.ovpn': No such file or directory

#

Okay, I might be a little brain damaged

#

How can I find the path then?

#

When using nautilus that's the path I take

#

It is in downloads as well

#

What's the path for downloads? I can't seem to get the terminal to access it

#

worth@worth-Legion-S7-15ACH6:~$ sudo -s
root@worth-Legion-S7-15ACH6:/home/worth# cd /downloads
bash: cd: /downloads: No such file or directory
root@worth-Legion-S7-15ACH6:/home/worth# ls /downloads
ls: cannot access '/downloads': No such file or directory
root@worth-Legion-S7-15ACH6:/home/worth#

#

worth@worth-Legion-S7-15ACH6:~/Downloads$ sudo openvpn /home/worth/Downloads/twenger128.ovpn
Options error: In [CMD-LINE]:1: Error opening configuration file: /home/worth/Downloads/twenger128.ovpn
Use --help for more information.
worth@worth-Legion-S7-15ACH6:~/Downloads$

#

It's in my downloads folder, and in my home folder. Both paths end up with the same result. I doubt it's a location problem

broken bear
#

This sounds like a permissions issue. openvpn has a verbosity flag doesn't it?

mellow oriole
#

The path is: /home/worth for the one in the home folder and /home/worth/Downloads for the one in the downloads folder

mellow oriole
#

Thank you for the effort! Didn't realize the config file was capitalized haha. Up and running

atomic escarp
#

getting this bug now while doing the same room 😅

karmic bough
#

Gracias, Thanks really function

scenic torrentBOT
#

Gave +1 Rep to @cursive sapphire

upbeat heron
#

Hi All, Is it illegal to stream the premium version of tryhackme content on twitch? TY!

finite aurora
#

I don't think so
Have seen some of them doing the same on YT

bronze vale
#

Hey,

If you have emailed within the past two days and have not received a response, please be patient:)

There is a small delay in answering emails but you should receive a response within 24 hours of this message.

Really sorry and thank you for your patience

naive dust
#

Any one know how to solve Sub-process /use/bin/dpkg returned an error code (1) on kali

#

yes but no solution about it

rocky valve
#

Hello. I think that some boxes were reset for me or something along those lines.
In the complete beginners path there are the burpsuite box and the metasploit boxes unmarked for me. But I still got the badges to "proof" that I already did those.

#

Thanks. That makes sense. 🙂

soft nymph
#

so i changed my email address to new one, on try hack me and currently this account is with the new email but i can't verify myself with the token anymore with this new account and to be noted i was already verified with my previous discord account, which i sadly unable to delete cause i am locked out of my Gaccount cause i lost my 2FA key and there are no other option available . So is there any way i can verify myself with this new account ?

weary spindle
soft nymph
weary spindle
#

Probably best pinging.

soft nymph
soft nymph
scenic torrentBOT
#

Gave +1 Rep to @weary spindle

cinder quest
#

OWASP Juice shop flag is not seen as correct

#

that error is there as a result of me trying to essentially brute force the flag to see if it had too many characters or what

#

i went here to verify and it still not working

#

the flag doesnt work on any of the other answers either

#

what the heck

#

ahh i see i got the answer now

jaunty lichen
#

Hi everyone
Plz help me
My try hack me room ip is not pingging.
Host seems Down..

carmine vector
#

Hey guys it seems like I`m on the root user instead of TryHackMe (the normal user according to the vid/ screenshots) and i cant find the right files, (Linux Fundamentals Part 1 - Task 5)

weary spindle
carmine vector
#

discord is not letting me to attach a screenshot :/

weary spindle
#

!docs verify

sharp bisonBOT
weary spindle
#

You need to verify.

carmine vector
weary spindle
#

You're root.

#

Now type ls

carmine vector
#

okay

weary spindle
#

Did you click that button?

carmine vector
#

yes

#

should i use the VPN option instead of the attackbox?

weary spindle
#

Are you sure you pressed the "start machine" and not "Start attackbox"

carmine vector
#

oh, nvm im blind

#

thx guys

royal acorn
#

Does anyone know why I'm getting this error?

#

from the blackarch repo

#

with the pacman packet manager

#

the .zip was created from osx

#

Ok, thank you.

marsh patrol
#

After my PC went to sleep, I am getting this error when I access the machine. "Unable to Connect". Both machines have more time. When I tried clicking "add more time", I get the yellow error in the top right that says Uh-oh! A problem occurred. Please try again later.

#

I tried that already.

#

On both my local Firefox browser and the tryhackme browser.

#

That refreshes the tryhackme browser, but it still gives the same error.

#

I can do a regular refresh on my local browser, but the Ctrl+F5 command will only go to the tryhackme browser.

#

Even logging in with a different browser does not work. I guess I will just terminate it.

slim lava
#

i'm in the Content Discovery room > Task 12
and none of the three automation tools (ffuf, dirb or gobuster) are working

sharp bisonBOT
naive dust
#

Hello got a questin on room Vulnversity task 4, i have to use burps intruder to sniper attack with 5 file extensions and only phtml is the right one but my burp suite shows all are legit https://i.imgur.com/HmbrQ3z.png

#

how would i know that phtml is the right one?

#

oh thank you yes, i havent checked the responses

scenic torrentBOT
#

Gave +1 Rep to @gray loom

sharp bisonBOT
winter star
#

when using openvpn to connect to room sites, is it supposed to be slow or have i might have done something wrong?

sharp bisonBOT
winter star
#

it says config not loaded but im connected to it now

#

with the correct path

#

ah nvm i got it

#

WOW so much better, thank you so much

scenic torrentBOT
#

Gave +1 Rep to @gray loom

slim lava
#

i just did but cant paste the screenshot

#

yes

slim lava
#

no

#

yes

slim lava
deft hedge
#

@foggy rover i need help...tried terminating a box...i refresh the page and it pops back up...disconnected from the only instance of my vpn...says im still connected????

#

ip= 10.10.208.197

#

it wont shutdown

#

@torn citrus can you raise this to someone who'll reply?

weary spindle
deft hedge
#
<state>: "fulfilled"
<value>: undefined```
#

thats the response

weary spindle
#

Check now if the machine is still up.

deft hedge
#

apparently

weary spindle
#

You can do that by visting https://tryhackme.com/api/vm/running

deft hedge
#
roomId    "relevant"
expires    "2022-05-12T01:05:30.690Z"
created    "2022-05-11T21:05:30.691Z"
internalIP    "10.10.208.197"
instanceId    "i-039d372ed6ba0688a"
title    "Relevant"
timeInSeconds    5466.713
remote    
active    false
waitTime    null```
weary spindle
#

Ah, I can't help then, the command I gave you should shut down all machines.

#

Maybe best reporting this to site bugs.

rocky galleon
#

hello. i am trying to follow the labs with my own kali 2022.1 via a vpn. whenever i enter john or hydra on the terminal, i get a "segmentation fault". any thoughts?

jade fiber
#

Hello all, Im having a issue submitting a answer. network services task 7 telnet question 2 i got the welcome msg. i have tried a million times to submit it, but it keeps telling me that its wrong. i finished the section and all other answers submitted fine. am i missing something here?

jaunty lichen
lost birch
#

Hi im having an issue connecting openvpn server on kali linux on a fresh install, do i have to change any setting for it to work ??

crystal marlin
#

Show a screenshot of your openvpn output when trying to connect pls @lost birch @jaunty lichen

jaunty lichen
crystal marlin
#

!docs verify

sharp bisonBOT
jaunty lichen
crystal marlin
# jaunty lichen

I thought you are having issue with connecting to the tryhackme vpn ?

#

But the screenshot you posted is about an nmap scan?

jaunty lichen
#

Ip is not pingging

crystal marlin
#

Can you do curl 10.10.10.10/whoami and let me know if you get a reply with your tun0 IP ?

jaunty lichen
crystal marlin
jaunty lichen
jaunty lichen
crystal marlin
#

So just stick with what nmap is telling you: If it is really up, but blocking our ping probes, try -Pn

jaunty lichen
#

When I use -Pn
Then
All 1000 scanned ports on ip is ignored status

crystal marlin
jaunty lichen
#

Okay

crystal marlin
# jaunty lichen Okay

Actually it should find open ports by default too I just saw, so show me a screenshot of your nmap command and the output pls

jaunty lichen
#

Now it is pingging

#

I don't know how it is pingging..

crystal marlin
#

Show a screenshot pls, that way things are much easier

jaunty lichen
crystal marlin
jaunty lichen
#

Vulnversity

crystal marlin
# jaunty lichen Vulnversity

Ok, well then there might have been a different issue previously, like the machine was expired, or you haven't given the machine enough time to fully boot, etc. But at least it seems to work now, right ?

jaunty lichen
#

Okay thank you sir

eager fulcrum
candid warren
#

Good morning. I’m having trouble breaking into another system with IP address using nmap. It’s a task in the try hack me website. “The lazy admin”. Any help anyone?

eager fulcrum
jovial mango
jade fiber
wind juniper
#

#site-support hello - what is the best way to contact support and check if a subscription can be transferred to a new account?

sharp bisonBOT
jade fiber
#

Cannot for the life of me get the site to accept it. Verified it’s correct format and correct answer with several ppl now.

weary spindle
#

||SKIDY'S BACKDOOR.|| try that @jade fiber

feral bobcat
#

┌──(kali㉿kali)-[~]
└─$ sudo apt update
Get:1 http://kali.download/kali kali-rolling InRelease [30.6 kB]
Get:2 http://kali.download/kali kali-rolling/main amd64 Packages [18.2 MB]
Get:3 http://kali.download/kali kali-rolling/main amd64 Contents (deb) [42.0 MB]
Get:4 http://kali.download/kali kali-rolling/contrib amd64 Packages [114 kB]
Get:5 http://kali.download/kali kali-rolling/contrib amd64 Contents (deb) [155 kB]
Get:6 http://kali.download/kali kali-rolling/non-free amd64 Packages [214 kB]
Fetched 60.8 MB in 5s (13.0 MB/s)
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
1015 packages can be upgraded. Run 'apt list --upgradable' to see them.

┌──(kali㉿kali)-[~]
└─$ sudo apt upgrade
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Calculating upgrade... Done
Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.
The following information may help to resolve the situation:

The following packages have unmet dependencies:
libwacom9 : Depends: libwacom-common (= 2.2.0-1) but 1.12-1 is to be installed
E: Broken packages

#

can someone please help me, i can never upgrade my stuff

#

so sometimes my stuff doesnt work

jade fiber
left obsidian
#

I am trying to download the OpenVPN files, but..

#

ah nvm, apparently that's why there's a regenerate button

weary spindle
#

I tried it on both my VM and attackbox incase it was a bug.

But my answer was correct both times.

left obsidian
#

hmm

#

I did the

sudo openvpn user.ovpn
weary spindle
left obsidian
#

but still!

weary spindle
#

Does your script command look like this?

left obsidian
#

like this>?

weary spindle
#

Then you're connected, just minimise that window.

#

In a new terminal, type curl 10.10.10.10/whoami or ip a s

left obsidian
#

can I use the same user.ovpn everytime, or should I generate a new one every time

left obsidian
#

wait is it ok if I say it orr?

weary spindle
#

You're connected.

left obsidian
#

also shouldn't this change orr

weary spindle
#

As I said above, that is not 100% accurate.

#

I'm sure if you refresh it though it will be green

left obsidian
#

ooh alright, so the kali machine I am using on my VB is the machine I will be using to solve the attack boxes is right?

weary spindle
#

Yeah 🙂

left obsidian
weary spindle
#

Then the only IP you'll need to interact with is this one

left obsidian
#

I can do THM without a time limmit right?

weary spindle
#

Only that one.

#

You can add hours though,

#

I'm not sure if it's 6 hours or 4.

left obsidian
#

just to double check, once I close the terminal the tryhackme openvpn session is gone right?

weary spindle
#

Yup

#

If you want to end it do so with Ctrl + C

left obsidian
#

TryFlagMe time to hack cya!

#

thanks @weary spindle

scenic torrentBOT
#

Gave +1 Rep to @weary spindle

weary spindle
#

Happy Hacking!

weary spindle
# jade fiber Tried both

Interesting.

I reset my progress in the room, attempting each input 3 times.

Your one: didn't work.
Attackbox: worked
Vm: worked.

jade fiber
#

hmmm... ]

#

I guess i will reset and try again.

#

it randomly worked this time... Same answer. but it took it. lol

winter star
#

is there a way i can donwload the wordlist so i dont have to keep opening my attack box?

#

im on the authentication bypass room and im needing the seclists/usernames/names list

#

but is there a way i can just download all of them to just host them on my own vm

#

oop. no i havent lol. i thought it was something specifically in the attack box

eager needle
#

I tried buying 8£ premium for a month with paypal but got an error and im from germany

sharp bisonBOT
eager needle
#

Ill try that, thx

final coral
#

I'm trying to do the new learning path introduction to cyber security and I can't use the browser in the atack box, anyone know what to do?

zealous yoke
#

Hey 👋 what room is it that you're trying to access? You're a subscriber (according to your profile), so your attackbox will have internet access

true nest
#

I didn't know that last part, thanks. I use a VPS tho

zealous yoke
#

It's worth noting that not every machine on THM will be running a web server. And if it is running a web server, it's not always on port 80 (so your browser won't load it by just specifying the IP address, you have to provide the port number which is often apart of the challenge)

final coral
#

I just started it so it's called hacking your first machine

true nest
#

What happens when you launch the AttackBox in your browser specifically?

#

Typically you use the in browser AttackBox/Kali to attack the THM boxes

final coral
zealous yoke
#

The web page should load fine straight away if you're using the machine that you deploy in Task 1 (like so:)

Could you send a screenshot of what you see please?

#

Also, the machine that you deploy from a task in a room is not the attackbox. The attackbox is a specific machine provided by thm (and isn't the machine that you're meant to hack in a room)

broken bear
final coral
zealous yoke
#

Ah that's really interesting actually

zealous yoke
#

I'm not sure why the VM launches that as a page. It should open directly to the website (though I do see possibly why). Can you open http://fakebank.com in the browser please?

#

@final coral ^

final coral
#

Oh, that loaded

zealous yoke
#

brilliant. That URL (http://fakebank.com) is what you're supposed to be attacking/visiting. I think I know why that issue that you're having is occurring. I'll pass this along to the right channel

final coral
#

Thanks

worn vapor
#

Can anyone help me with the attack box?
It disconnects every 5 seconds, had the issue in multiple rooms

tawny vigil
#

I'm working on a html website
and im trying to bypass this

#

anyone got any ideas?

jovial mango
tawny vigil
#

no its my website for school

#

sorry i don think this is the right palce to post it

#

loloolo

fast jewel
#

hello all

#

i have a concern on some of the questions being asked in room Introduction to Network

#

is it the right place to post 🙂

lost carbon
#

I got my progress reset back to 1 even though I have been doing these rooms every single day .

weary spindle
#

!email

sharp bisonBOT
lost carbon
celest wadi
weary spindle
#

Depends.

I E-mailed yesterday afternoon and got a reply last night.

#

Like previously said, > 7 day(s) E-mail a follow up, just be polite.

crystal marlin
#

Add -oHostKeyAlgorithms=+ssh-rsa to your ssh command

scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

lofty hinge
#

Hello. Is it possible to unlink or relink my discord account? Joined THM in 2020 but after some inactivity on the platform decided to delete that account. I am back with a new one now but i cannot link it to my discord account as it appears its still linked to that deleted account.

plush bay
lofty hinge
scenic torrentBOT
#

Gave +1 Rep to @plush bay

lofty hinge
#

i'm in no rush

plush bay
#

know for a fact that muiri can do it but they seem busy right now

stuck hearth
#

Is anyone available?

crystal marlin
tacit ice
#

Hello, could you please fix the logic of the last answer submission of the "Walking An Application" room? I've submitted the correct flag but it keeps telling me it's incorrect.

#

The status updating of the Pentesting Tools series dashboard also seems to be broken as well once I've completed the "Metasploit: Introduction" room but I do not see a green checkbox next to it.

scarlet vessel
undone mulch
#

Im working on Linux PrivEsc room and im getting this error when trying to ssh into the box
Unable to negotiate with port 22: no matching host key type found. Their offer: ssh-rsa,ssh-dss

wheat wagon
tacit ice
#

It’s not a flag submission issue as the “Metasploit: Introduction” status shows up as 100% complete, but not in the the Pentesting Tools (learning path) dashboard.

tacit ice
tacit ice
crystal marlin
sour prairie
#

yo guys im insyalling windows dual boot besides my linux, has anyone ever faced this problem?

eager fulcrum
#

@red swan @sour prairie This channel is for directly tryhackme related tech support like site and VPN issues

red swan
#

i have seen many times how people here helped each other solve problems not related to thm. but ok.

eager fulcrum
light vale
lost carbon
#

In the windows privilege escalation room , everytime I try to connect to the RDP , it keeps rejecting my connection

crystal marlin
lost carbon
#

the target machine IP

crystal marlin
lost carbon
#

I thought it was the attacking machine

#

nm you are right

#

i did an ipconfig

crystal marlin
lost carbon
#

They are not set up like the linux machines on thm

crystal marlin
lost carbon
#

I mean you had to ssh into the Target IP whereas I don't do it for this room

crystal marlin
glossy kernel
#

Good day, I cant seem to proceed , when it comes to the second part, the machine is lagging

scarlet vessel
glossy kernel
scarlet vessel
scenic torrentBOT
#

Gave +1 Rep to @scarlet vessel

scarlet vessel
#

Just realised this is Tech support, my bad. if you need any more help with the rooms just go to #room-help or #room-hints 👍

quick reef
#

i have got issue when i submitted answer "walking an application" room, task 6 developer tools - network
i found proper flag but i have got msg "your answer is incorrect" Can someone help me?

rotund tusk
#

I got a new discord account and I cant verify my token because its already in use the bot says, could anyone help me?

long slate
#

Hello, I'm not able to login into the THM website, I got the msg "Captcha test has failed" but no captcha is loading on the login page.

vale musk
#

Is there a place on discord to report issues with the THM Business part of the site?

plush bay
crystal marlin
#

!email

sharp bisonBOT
vale musk
#

yeah I'll reach out to my contact then, but not in the weekend 🙂

tall canopy
#

I have question about payment of vip status. Who can i ask in direct?

eager fulcrum
scenic torrentBOT
#

Gave +1 Rep to @eager fulcrum

rotund tusk
#

any mods online to help me with my issue regarding the discord token?

#

need it removed from my old account and linked to this account xD

celest wadi
celest wadi
#

if that's in the complete beginner path, then you're being redirected to the newer rooms and the old ones show up as incompleted, think it's a known bug 🤷‍♂️

#

join old private rooms and finish 'em

crystal marlin
#

You can not fix that, you will have to wait until they replace the old rooms from that series

tough reef
#

Is it still possible to reset my streak?

crystal marlin
tough reef
#

No, I just couldn't make any challenge in the last 24h, so it went to 0 😦

#

I saw in a reddit post it was possible, but the post is from 1 or 2 years ago

crystal marlin
tough reef
#

Thank you, yeah, I just lost it about 6h ago or so

gleaming current
#

Can anyone help answer some questions about using egrep?

#

I'm trying to display words in a text file that don't contain any one character from a set. [iet]

#

I want to display all of the words that don't contain the letters, not remove all of the lines that contain these letters

crisp tinsel
#

My streak reset after 9. Today should be 10. I had answered a question yesterday. I actually answered two.

light vale
onyx bluff
#

hi everyone! how can I bruteforce a wordpress login page from a local dictionary file? what type of tool can I use?

jovial mango
jovial mango
jagged radish
#

trying to 'rdesktop' into the windowsprivesc room in jr pentest path, and im getting the following

naive dust
#

Hi,
When i extend my TryHackMe with an hour, it keeps just closing the machine after an hour.
The one hour extension does not work.

#

its very annoying for taking breaks in between

celest wadi
naive dust
#

oh okay

naive dust
#

I have a question related to John the Ripper. I have succesfully installed john-jumbo via brew (because MacOs). I am able to use John, however it seems for me that unshadow is not included. It is not recognized as a cmd (with the correct options/arguments). Any idea what possibly could be wrong?

naive dust
#

Unshadow is part of the John-jumbo build. The issue is solved. I have raised a question in github (openwall/john), and the answer is that unshadow is not included in the default search path, so i needed it to run with the full path instead: /opt/homebrew/Cellar/john-jumbo/1.9.0/share/john/unshadow......

eager fulcrum
crisp tinsel
light vale
crisp tinsel
light vale
#

I suggest you wait until tomorrow and see if the problem will solve by itself just like mine did or if it doesn't and you lose the streak by any chance, you can email the thm support and ask them nicely to give you the streak back, these are the only 2 things you can do

mild fiber
#

Using running nmap from my Kali VM returns "host seems to be down." Running it on the AttackBox works. I'm connected via OpenVPN on my VM. I tried connecting to it on my host machine instead, but same issue. I've tried reconfiguring my OVPN file, but same issue. I can ping the target, but nmap always says host is down. I found a thread on the forums where people report the same issue, but there doesn't seem to be a concrete solution.

eager fulcrum
plush bay
hushed ferry
#

I always have issues with reverse shells and callbacks in general. Issue is with my Kali box when I vpn into do rooms. I dont have issues with the THM attack box.

Anyone have any insight on this?

crystal marlin
hushed ferry
#

what should I install to be able to access the ufw command?

ip a s/ifconfig shows lo, eth0, and tun0

#

nvm

#

ufw inactive

crystal marlin
hushed ferry
crystal marlin
hushed ferry
#

It is. Oracle virtual box

#

should I be bridged?

crystal marlin
hushed ferry
#

norde is installed but not currently active

#

Thought that might be causing it so I disabled it

broken bear
hushed ferry
#

I am wrong, still bridged

broken bear
#

If you are running the scan from your VM, you don't need to have a bridge adapter.

hushed ferry
#

putting it back into NAT doesnt seem like it fixed it.

crystal marlin
hushed ferry
#

Ive been able to ssh in to target machines I believe.

crystal marlin
#

Either way, try sudo ip link set dev tun0 mtu 1200 to see if that changes anything, if it doesn't just put it back to 1500

hushed ferry
crystal marlin
hushed ferry
#

yeah. I didnt stop the NC, but I did reupload the file

crystal marlin
#

Could you double check if your tun0 IP that you see when you do ip a s matches the IP in your payload?

hushed ferry
crystal marlin
hushed ferry
#

At the end of the day, I can just use the THM attack box but I am at the point where I want to get my personal box working the way it should.

crystal marlin
hushed ferry
#

success

crystal marlin
hushed ferry
crystal marlin
hushed ferry
#

"
Now we know what extension we can use for our payload we can progress.

We are going to use a PHP reverse shell as our payload. A reverse shell works by being called on the remote host and forcing this host to make a connection to you. So you'll listen for incoming connections, upload and have your shell executed which will beacon out to you to control!

Download the following reverse PHP shell here.

To gain remote access to this machine, follow these steps:

Edit the php-reverse-shell.php file and edit the ip to be your tun0 ip (you can get this by going to http://10.10.10.10 in the browser of your TryHackMe connected device).

Rename this file to php-reverse-shell.phtml

We're now going to listen to incoming connections using netcat. Run the following command: nc -lvnp 1234

Upload your shell and navigate to http://<ip>:3333/internal/uploads/php-reverse-shell.phtml - This will execute your payload

You should see a connection on your netcat session"

crystal marlin
#

?

hushed ferry
#

oh

#

It seems I have forgotten I vital step

crystal marlin
#

A very vital step, yes.

#

I wonder how you could get it working on the attackbox

hushed ferry
#

That wasnt with this task

#

It was with call backs from Metasplot and listeners

#

or reverse shells with metasplot

#

Let me make sure I have the file named correctly

#

Okay still dont have a call back but I did have some action on my openVPN terminal

#

top line is the initialization from when I connected

#

other lines just came through as I executed the reverse shell

crystal marlin
#

Try setting the mtu to 1200 again

hushed ferry
#

That did it

#

Would you mind explaining why reducing the maximum transmission unit size would fix it?

#

I dont learn anything(except to make sure I am following the steps) if I dont know why 1200 solved it vs 1500.

crystal marlin
hushed ferry
#

You are appreciated.

Thanks for being patient and taking the time to help me out!

hushed ferry
crystal marlin
hushed ferry
#

got it... so when I killed tun1 then closed out of openVPN.... I would have been leaving tun0 still so when reopening openVPN, just made tun1. Makes sense

mild fiber
#

Thank you for mentioning the multiple tun interfaces. I killed them and it works now.

ripe vapor
#

hello 🙂
I have a problem on hololive network, I can't ping the first computer (10.200.109.33) from openvpn or from the attacker box, same error.

split cradle
#

Hello, I have a question regarding my internet speed on my Linux, I have a fast internet but that isn't the same with my Linux, it has like 200kbps or less most of the time. Is there any way to unlock the speed to match my wifi speed ?thanks

ripe vapor
#

yes, I already did it

#

through my kali personnal machine

#

even through the kali box on the holo network, it didn't work 😦

#

yep, I have a "Network state : Running" on the top right

#

I already click on Start and the network uptime is abour a hour

topaz lion
#

I have a problem, everytime I try to ssh the machine it tells me the password incorrect

#

< ssh tryhackme@machine_ip with password=tryhackme >

#

I tried both opvpn & attackbox with the same result

sharp bisonBOT
topaz lion
#

I have a problem, everytime I try to ssh the machine it tells me the password incorrect. I tried thm attackbox & opvpn with no result
< ssh tryhackme@machine_ip with password=tryhackme >

#

one second I will send a fresh screenshot

#

Network Services

#

what the machine IP for in this room?

#

so in the following tasks I don't need to connect to any other machines? only use attackbox?

#

how to connect without ssh?

#

in task 4 the IP I shall use the attackbox ip or the machine?

#

sorry because I'm little confused

#

I used the target machine

subtle geyser
#

I'm having an issue with my attack box, the attack box doesn't seem to have access to the internet, it doesn't connect to google, and when I tried to ping google's main DNS server it didn't reply

#

No

foggy rapids
#

ssh sammie@10.10.254.1
The authenticity of host '10.10.254.1 (10.10.254.1)' can't be established.
ECDSA key fingerprint is SHA256:Jvnoj8A2m8+s3iRKJjURJPQHKly9KkY+ZKdKYF6oFhA.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added '10.10.254.1' (ECDSA) to the list of known hosts.
sammie@10.10.254.1's password:
Permission denied, please try again.

#

why permision denied

#

I DID AS YOU SAID

subtle geyser
#

is it something new?

foggy rapids
#

yes

sharp bisonBOT
foggy rapids
#

!docs verify

sharp bisonBOT
foggy rapids
#

!docs verify

sharp bisonBOT
foggy rapids
#

ok gotcha

#

i entered the correct IP and it worked. many thanks to you 🙂

foggy rapids
#

How am i supposed to find the password of johnny ?

#

Based on the top 7 passwords, let’s try to find Johnny’s password. What is the password for the user johnny? WHAT ARE TOP 7PASSWORDS ?

#

what

#

so where is that task about top 7 passwords ? I DONT SEE IT

#

thanks

compact island
#

Good morning. I'm piloting TryHackMe with a few students using the free accounts at the suggestion of a TryHackMe sales rep, but we are unable to complete the free Content Discovery room because the Attack Box is unable to access the Acme IT Support target machine. Are we doing something wrong? Thank you!

sharp bisonBOT
compact island
#

Absolutely.

tawdry orbit
#

The link to navigate is in Task 2. 🙂

compact island
#

Thank you both... that makes perfect sense. Looks like we're back in business.

spark schooner
#

i need help man

deep spire
spark schooner
#

in this room

#

in this qus.

#

i have right flag

#

but when i submited

#

they show this is wrong flag

#

now what can i do?

#

@deep spire

crystal marlin
merry hill
#

I want to buy for 3 months but not getting options to change months on subscription page
its either 1 month or anual plan

crystal marlin
merry hill
#

but on the student discount page its given that if I buy for 3 months i will get a month free

#

so how can i avail that offer

crystal marlin
merry hill
scarlet vessel
merry hill
#

ok so should i go for it

#

and buy a one month subscription

crystal marlin
crystal marlin
#

Use '

spark schooner
#

copy past sir 🙂

crystal marlin
quiet wyvern
#

hi guys! I'm trying to do the owasp juice shop room on THM, but when I connect to the vpn I can only ping the target IP, when I enter the address into the browser the page doesn't load... can anyone help me with this?

#

same thing 😦

#

the host connects directly to the internet

#

magic happened lol

#

it works now

#

thanks

#

nope, the taget was up for a while, I already connected to it from an attackbox to check if the target is okay, and it worked just fine that way

#

idk why it didn't load but it's fine now 😄

naive dust
#

I'm really new to this. I'm trying the following on my AttackBox but it doesn't do anything? Have just forgot everything I learnt in the last few days?

ssh tryhackme@10.10.42.79

#

now it's just timed out?

#

I'm sure it worked before

sharp bisonBOT
naive dust
#

I was going to but cant see where. I assumed maybe cos I was new?

#

!docs

sharp bisonBOT
#
TryHackMe
Here are all of the possible topics!
!docs url

Visit the help site

!docs verify

Learn how to sync your THM profile to Discord

!docs student

Learn about our student discount programme

!docs levels

View all the TryHackMe levels & point requirements

!docs room-notes

Get started with making TryHackMe room

!docs room-review

Learn about the TryHackMe room review process

!docs api

Read about the TryHackMe API

!docs koth

How to play TryHackMe's King of the Hill (KoTH)

!docs free-path

What rooms should you do? A free guide for beginners

!docs bug-bounty

Learn about TryHackMe's Bug Bounty Programme!

naive dust
#

Nmap

#

I tried without ssh and didn't work. Hang on I'll go mess with it some more. Thanks for you help

#

I dunno. I'm totally stuck

#

I've read the whole thing up to task 12 and now I have no idea what I'm doing. It's like I've completely forgot all the linux stuff. Which is annoying cos I only finished it yesterday

#

ah. I think I got it

#

ok cool thanks. I solved the one I was stuck on. Now I'm trying to figure out the next one

scenic torrentBOT
#

Gave +1 Rep to @gray loom

turbid crystal
#

guys there are 2 nvcontainer.exe that is using my computer with different ips should i be worried

#

pls help

worthy kelp
#

I'm doing the Nessus room and stuck on task 4 (basic network scan). Nessus keeps coming back with no results. Nothing at all. But the questions clearly imply that there is supposed to be something to find. I've checked that I am doing it correctly and repeated it but I am completely stumped. Has this happened to anyone else?

light vale
#

And also be sure you entered the correct machine ip address that you need to scan

worthy kelp
scenic torrentBOT
#

Gave +1 Rep to @light vale

worthy kelp
worthy kelp
#

damn vulnerable web application

light vale
worthy kelp
#

the deployed vm

light vale
#

go to the discovery section and check scan all ports

#

and this doesn't work either, terminate the machine and start a new one, edit the scan and set the new ip address and try again

#

it's a simple task it should work without problems

worthy kelp
#

Yeah the WebApp scan failed too. I've definitely got a bug somewhere.

#

Thanks for your help!

light vale
worthy kelp
#

From my own windows machine

light vale
#

Ohh now i saw that it's not installed on the attackbox i forgot

worthy kelp
#

yeah they said it's too small for nessus

light vale
#

I would suggest installing a kali linux vm for tryhackme tasks it's really not recommended to use your own host, especially windows one if you ask me...

worthy kelp
#

yeah i tried to set up kali on aws the other day but couldn't get the gui config to work and gave up on it.

weary spindle
#

Nessus takes up 30GB of storage alone.

weary spindle
worthy kelp
#

just direct on my laptop

weary spindle
#

Have you used Kali before?

worthy kelp
#

yes

restive steeple
#

Hi!!, This is tushar and I have been facing a problem in login as it is denying my account but I have been continuously active on tryhackme for about 6 months, pls help

light vale
#

And try to let them know what error or issue you are encountering

restive steeple
#

gr8, thanks a lot

light vale
#

no worries

hot dune
#

Hello guys, does somebody know how long it takes to get an answer from the THM support?

light vale
hot dune
scenic torrentBOT
#

Gave +1 Rep to @light vale

hot dune
light vale
#

It's a reputation system when you tag somebody or reply to a message and say thank you it gives you +1 rep

hot dune
#

That sounds neat. What can you do with them and where do you see the amount?

light vale
deep spire
hot dune
#

ahhhh alright. Thank you two. 👌

light vale
#

no worries

plush bay
#

for it to give rep you can use either a reply with thank you in it or a ping with the thank you in it or a +rep @someone to give the rep point

#

and to view your rep it is -rep

hot dune
plush bay
#

there is also -toprep to view the leaderboard

hot dune
#

oh wow

sterile brook
#

where do I find my open attack boxes? I tried starting a new one and it says I can only have 3 open at a time but I dont know where they are

deep spire
#

if you want to look, look in your browser history at recent rooms

plush bay
#

should it not also be a show split view button to get into an already open attackbox???

sterile brook
#

thanks that worked

deep spire
weary spindle
fast urchin
#

My account was disabled for the last couple days and I do not why. Just prior @deep spire was helping me and he pointed out that discord was indicating I was spamming, but he did not know why. He said he hoped it would resolve soon, but it didn't and I my account was disabled. I was able to log back in today. I am using firefox rather than desktop because that was what I was using when the account was disabled.

weary spindle
fast urchin
#

Can anyone tell me why this might have occurred and how I might prevent it in the future? Also are there any moderators that could tell me if my account is still flagging as spam or not?

weary spindle
#

I doubt it will be if you're able to log in a browser.

deep spire
deep spire
fast urchin
#

Discord

deep spire
fast urchin
#

I'll try

deep spire
waxen harbor
#

Hello, What means the days left in Holo Room?

crystal marlin
celest wadi
weary spindle
weary spindle
# celest wadi Wat?

Can also be used to show you which machines you have running. == Doesn't that just list them tho

eager fulcrum
#

@fast urchin Did discord terminate your account?
You really should not be evading that termination, it's a violation of ToS and we should really ban you from the discord because of that.

fast urchin
eager fulcrum
fast urchin
# eager fulcrum <@929514768237215785> Did discord terminate your account? You really should not ...

I was unable to login with desktop, I could not message support because I had forgotten what email I had signed up for discord with (I use my cell # for logging in). So today I remembered what it was and decided to try logging in with it on firefox rather than desktop and it worked. Frankly, I am insulted that you would say that I am evading anything and I cannot fathom why discord is so touchy that it would have flagged me for spam

eager fulcrum
#

If this is the same account then it is fine

fast urchin
#

Oh, you were thinking that I created a new account because the other one was disabled? No, I am using the same one and just logged back in with firefox this morning and it worked. I thought you were saying I was deliberately evading by simply logging in with another browser. But again, frankly speaking, even IF I had created a new account, because my account was unfairly disabled for spam (which I have no idea why that would be) even if I HAD done that- why would you blame me for that??

eager fulcrum
#

Yes.

#

Evading a discord platform ban is a break of ToS, which we ban for here.

fast urchin
#

@eager fulcrum well I am glad that you guys have customer's backs that pay for your service when the platform you choose to host this service on decides to unfairly knock them off for no reason. Another reason I guess I need to get to the bottom of why my account was disabled in the first place.

eager fulcrum
#

Getting banned here doesn't get you banned on the site.

#

Official support is handled via email, rather than discord.

fast urchin
#

Well regardless there is no reason for my account to be disabled. I wouldn't just give up trying to do tryhackme because of something that isn't my fault. And without discord, I'd be completely lost @eager fulcrum

eager fulcrum
#

Ok, take it up with discord.

#

We've established that you're not evading a discord platform ban, the only problem here is the problem that you're deciding to create.

fast urchin
#

I have heard many stories of people being banned on discord for no reason. If I was to be one of those people, I would not just give up on this stuff. What do you mean "decided to create"?

eager fulcrum
#

We established that there is not a problem, you're deciding to continue.

#

I'd recommend you contact discord support and stop messaging here.

fast urchin
#

What do you mean it is a problem that "your deciding to create"?

eager fulcrum
#

I believe I've made myself clear. Please stop here, and contact Discord support.

golden laurel
#

anyone can help with nessus ?

eager fulcrum
fast urchin
#

I already did send a message to support. I only remembered the email today. I don't want there to be any problems, I want everything squared away properly here because I very much need discord to learn this stuff. So when you say there is a problem, I want to know why @eager fulcrum but I have sent a message to support so hopefully that resolves everything

golden laurel
#

okay okay somewhere i can go @eager fulcrum

light vale
#

Choose one and post your question there, not in all 3 of them of course

eager fulcrum
#

(assuming it's related to the THM content on it)

tender cosmos
#

what is the monthly subscription fees of THM, coz i got invoice of 10 $ for my current month, but for the upcoming month its showing £10

eager fulcrum
#

It displays the wrong symbol

naive dust
#

Hello

#

I got hacked on tryhackme

#

I have no idea, but someone took over my account, and changed the password

#

I cannot access it

sharp bisonBOT
naive dust
#

Alright thanks

tender cosmos
scenic torrentBOT
#

Gave +1 Rep to @eager fulcrum

outer beacon
#

hello

#

really need help to fix this

crystal marlin
outer beacon
sly jacinth
#

File "/usr/lib/python3/dist-packages/ldap3/core/connection.py", line 1307, in start_tls
if self.server.tls.start_tls(self) and self.strategy.sync: # for asynchronous connections _start_tls is run by the strategy
File "/usr/lib/python3/dist-packages/ldap3/core/tls.py", line 277, in start_tls
raise LDAPStartTLSError(connection.last_error)
ldap3.core.exceptions.LDAPStartTLSError: startTLS failed - unavailable

onyx plume
#

Dude Holo is just unusable lol

#

I think there are just way too many people using it. web server on the first machine will just be unreachable despite the machine being aline

#

*alive

#

I'll probably just try and come back to it another time/day

abstract violet
sonic plinth
#

hello the room POLOTELNET does not open any port, please check it, thanks

crystal marlin
sonic plinth
#

yes, it is. I waited for about 10 minutes and used command "nmap -sT -sV -O -A" to scan

#

the result is "Host is up (0.0016s latency).
All 1000 scanned ports on ip-10-10-142-238.eu-west-1.compute.internal (10.10.142.238) are closed"

crystal marlin
sonic plinth
#

yes, because I think it is a TELNET room

crystal marlin
#

Also, the -A flag is pretty much an overkill, especially when doing an initial scan to look for open ports

crystal marlin
sonic plinth
#

thanks, I will try 65535 ports 🙂

timber pendant
#

Hello, is there a way to change the public IP of the attackbox? I want to sent packets to a remote server and make it look like they're being send from 2 different addresses.

timber pendant
stray cove
#

This can also be considered abuse of the attackbox

#

Use is monitored and you may risk getting site-banned

spark schooner
#

i need someon's help

#

anyone?

#

Hello, I'm having trouble with answering the last question in the room. I'm not sure why, but when I try to switch to the root account, I am unable to do so despite entering the correct password. When I try to switch to the root account, I keep getting the 'su: Authentication failure' message which indicates that I was not able to be authenticated. Could someone please let me know why this might be occurring?

golden isle
#

Hello, I'm a beginner and I need help setting up openvpn on my vm, anyone available?

crystal marlin
golden isle
#

its don't work for me

#

😢

crystal marlin
#

Best to verify and send a screenshot of what doesn't work

#

!docs verify

sharp bisonBOT
spark schooner
#

can i dm you?

crystal marlin
spark schooner
#

ok check

elder crag
#

I've been having issues connecting to the machines they take longer than normal to come up, and ssh into them isn't as responsive

#

and anytime i type ssh password it says connection closed by target ip

#

machine is capstone challenge under /room/linprivesc

crystal marlin
elder crag
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

elder crag
#

thanks

eager fulcrum
finite crow
#

I am trying to figure out why I cant get Firefox to load tryhackme, i can get it to load in chrome (which I don't want to use) but not in Firefox. It worked fine on my Linux machine but not on my windows desktop. I even created a Mozilla act ( I didn't want to do) to sync the settings from my Firefox browser to and the same results. Any help would be appreciated.

#

also seems to happen with a similar site and its just these 2 sites

crystal marlin
#

You'll have to verify first in order to be able to send screenshots

#

!docs verify

sharp bisonBOT
finite crow
crystal marlin
finite crow
crystal marlin
#

If you google "pr_end_of_file_error" you should come across a couple of things you could try

finite crow
#

I went to through and turned off proxy settings on network settings for my computer as well as FF, still will not connect, also tried the to change tracking settings in the config setting, not sure what to do, i can still use my laptop but would like the use of bigger screen when on the site

finite crow
#

i will look at it and see what i can do, im a privacy addict so i would rather use my FF browser, i changed my dns as well and nothing

finite crow
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

zealous yoke
finite crow
frigid scroll
#

looking for a pro at ssh tunnels to explain me some stuff, very quick

vapid gorge
#

Hi, I need some help. I'm in https://tryhackme.com/room/internal and try to go loggin page: http://<ip>/blog/wp-login.php. But page load very slowly. I try curl page and all ip go to http://internal.thm. My /etc/hosts don't have link like ip internal.thm. I try to restart compyter but not success. Do technical team help me?

finite aurora
vapid gorge
scenic torrentBOT
#

Gave +1 Rep to @finite aurora

jagged galleon
#

workoing on windows privilege escalation and trying to rdp to the windows machine, but getting an error
"Failed to connect , CREDSSP required by server"
this is the command i used rdesktop -u user -p Password1 x.x.x.x -g 60%
googled the error but not able to find the required answer to solve this issue
how to solve this issue?

honest scroll
#

Question, now a tech support one but a discord server one. How do you get the roles regarding certs?

weary spindle
jagged galleon
scenic torrentBOT
#

Gave +1 Rep to @eager fulcrum

vale terrace
#

Heyya can i get reset my discord token because my last discord just got deleted somehow !!!

#

@eager fulcrum buddy can you help me ??

vale terrace
eager fulcrum
#

-ban @vale terrace Evading a discord platform ban. This is a breach of Discord's terms of service.

scenic torrentBOT
#

🔨 Banned CyFuN#6277 indefinitely

naive dawn
#

does anyone know why evil-winrms download command isnt working for me? Says download successful but it hasnt transferred the file

inland knoll
#

So I deleted my old discord (to get away from some people). My account token is taken by that old account.

Tried to verify again but it's already been used. Not sure what to do other than deleting my THM and paying for a new subscription

broken bear
#

For deleted accounts, I think only @barren birch can do a lookup to remove that token.

inland knoll
#

I could ask him I suppose

barren birch
#

DM me the token please 🙂

inland knoll
#

Np

onyx plume
#

Anyone know why sometimes Holo will have totally different IP scheme? When it’s working properly and I can actually connect to it the L-SRV01 client will be like 10.200.111.33. Right now it’s showing 192.168.100.1 and I can’t ping it despite being on the attack machine. Obviously I’ve voted to reset it but that’s just a waiting game until enough people vote.

#

Yes the network diagram is displaying that as their IPs.

#

OHHH okay I’m following now. The diagram is changing as I work through the network

#

Yeah yeah I can reach L-SRV01 at 10.200.111.33 still. Thanks!

tawdry orbit
azure marsh
weary spindle
#

It's either being fixed or it's too old, sometimes the latter.

tawdry orbit
outer imp
#

hey guys can you help me fix subscription problem

#

when i do confirm credit card info they said (Your card issuer bank has declined this payment.Please contact your bank for support.)

sharp bisonBOT
outer imp
#

okey

#

already but no answer, i'll try again

#

yeaah sure 😉

bronze vale
#

No, don't email support

#

Read the error

#

It says contact your bank

outer imp
#

ERROR : Your card issuer bank has declined this payment.Please contact your bank for support.

outer imp
#

and no problem

bronze vale
#

We don't tell you to contact your bank because we want to send you on a goose chase 😁

#

We're telling you that you need to contact your bank because they're doing something to your payment.

storm jasper
#

Hello. I'm having a problem with Network Services, Enumerating Telnet room. The nmap scan is taking a very long time. I've done this twice, using different machines; same result. Is this room working correctly? The nmap scan is taking over 3 hours to complete. The previous room I did (Enumerating SMB) worked just fine. Help?

eager fulcrum
#

From the answer format, you know the port is a 4 digit port so between 1000 and 9999

#

Scan between those ports and you'll get it quickly

storm jasper
scenic torrentBOT
#

Gave +1 Rep to @eager fulcrum

plush bay
#

another tip is to mess with nmaps timing to scan more ports quicker but at a chance of false postives and false negatives

#

@storm jasper you could therefor use for example -T4 or -T5 to speed up the scan at a slight risk of it missing the open port or reporting some closed port as open

storm jasper
scenic torrentBOT
#

Gave +1 Rep to @plush bay

storm jasper
scenic torrentBOT
#

Gave +1 Rep to @plush bay

sudden heart
#

Hello sir , I need some help

crystal marlin
sudden heart
crystal marlin
#

So probably the best to reach out to that email

sudden heart
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

sudden heart
#

I told him to mail the issue

crystal marlin
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

serene raptor
#

hey, could plugins prevent the script from terminating the machines?
i posted it and the attackbox is not terminating

fetch('/api/vm/running')
  .then(r => r.json())
  .then(vms =>
    vms.forEach(vm =>
      fetch('/api/vm/terminate', {
        method: 'POST',
        body: JSON.stringify({ code: vm.roomId }),
        headers: {
          'csrf-token': csrfToken,
          'Content-Type': 'application/json'
        }
      })
    )
  )
#

nvm, i had to refresh the page lol

glad brook
#

hello! qq: how long does it take for a writeup to be reviewed, on average?

midnight haven
#

Hi! I cant deploy my machine "maximum 3 machines". Problem is that I only have 1 room open which I'm trying to start. Any suggestions?

midnight haven
light vale
#

This is where you have to paste it, hit Inspect and at the top you have Console

#

I mean at least this is how it normally looks, maybe share a screenshot if it's still not working

#

!docs verify

sharp bisonBOT
light vale
#

You need to do this before being allowed to share screenshots here

midnight haven
scenic torrentBOT
#

Gave +1 Rep to @light vale

light vale
muted oak
#

Hi, we created a room, but we are not sure how points works...we enable first blood, but some task didn't give them first blood points and others are in 0 points... do you know how it works?

plush bay
weary spindle
#

I think it is, since you don't have access to the #creators-lounge

bronze vale
naive dust
#

hi, now im a premium user on tryhackme

naive dust
tribal flume
#

is this the place to get support if we have the paid educational dashboard? having an issue with intro2windows05. booting the vm in task6 leads to a repeating login error.

#

I would email my rep but it's already the weekend where they are.

eager fulcrum
eager fulcrum
tribal flume
#

thanks for the heads up, take care.

muted oak
celest wadi
rotund tartan
#

hi guys, i think there is some issue with the room linuxprivesc, it will not allow me to access via ssh

#

can someone help me pls?

muted oak
celest wadi
sharp bisonBOT
tawdry orbit
coarse rivet
#

Hi, please I need help. My Attackbox is unable to load webpages. It keeps showing "Problem loading page" whenever i search for something on firefox. What do I do?

coarse rivet
#

Oh. I didn't know. So is there any way to complete the task?

#

I have to log into a page on attackbox to complete a session on tryhackme's pentesting path

#

Junior Penetration Tester Path - Content Discovery -Task 3: Manual Discovery-Fav Icon

coarse rivet
#

Thank you so much. It works.

scenic torrentBOT
#

Gave +1 Rep to @gray loom

hushed pivot
#

Good morning. Go to link for Sharing Badges doesn't seem to work

hushed pivot
#

ohh ok2x. thanks

scenic torrentBOT
#

Gave +1 Rep to @gray loom

desert oak
#

is there an option to delete workspace i created or get myself removed from the workspace? i tried changing email but still i am a member

lost birch
#

hi i cant connect with open vpn in the VM,

#

2022-05-21 01:17:55 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2022-05-21 01:17:55 DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-256-CBC' to --data-ciphers or change --cipher 'AES-256-CBC' to --data-ciphers-fallback 'AES-256-CBC' to silence this warning.
2022-05-21 01:17:55 OpenVPN 2.5.6 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Mar 20 2022
2022-05-21 01:17:55 library versions: OpenSSL 1.1.1m 14 Dec 2021, LZO 2.10
2022-05-21 01:17:55 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2022-05-21 01:17:55 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2022-05-21 01:17:55 TCP/UDP: Preserving recently used remote address: [AF_INET]34.253.19.14:1194
2022-05-21 01:17:55 Socket Buffers: R=[212992->212992] S=[212992->212992]
2022-05-21 01:17:55 UDP link local: (not bound)
2022-05-21 01:17:55 UDP link remote: [AF_INET]34.253.19.14:1194
2022-05-21 01:18:55 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2022-05-21 01:18:55 TLS Error: TLS handshake failed
2022-05-21 01:18:55 SIGUSR1[soft,tls-error] received, process restarting
2022-05-21 01:18:55 Restart pause, 5 second(s)

sudden heart
#

and how much time the team takes to resolve the issue...

naive dust
#

Hi, I have a strange bug with openvpn (on vip server) I am connected to thm I can nmap the targets, I can connect to 80 port but dont have the images and when I can I cant have a reverse shell with pentestmonkey PHP shell BUT I can have it with the AttackBox OoO on Skynet per example. Any1 got an idea? Thx

celest wadi
naive dust
#

checking

#

i'm connecting again to the box

#

but i got no firewall

#

(it's a Vmware box)

celest wadi
#

check if you're able to connect on the ports yourself, nc ip port

naive dust
#

hmm i see the images now and I can reverse shell

#

i have changed nothing ^^^

#

thx @celest wadi i'll check again if issues are coming !

scenic torrentBOT
#

Gave +1 Rep to @celest wadi

naive dust
#

have a good day

ashen crypt
#

is there a way to completely delete WSL from my machine ?
i went to settings >Apps> apps and features> searched for windows for linux bla bla bla> and uninstalled it but it doesnt seem to go away , pls any help would be appreciated

#

i know this isnt directly related to tryhackme but please, i really need help.

ashen crypt
#

i fixed it nvm

uneven folio
#

Hello guys have a problem with my Kali. I have no more storage for dpkg

eager fulcrum
# uneven folio

This channel is for directly tryhackme related tech support like site or VPN issues

compact orbit
#

whenever i start the attack box its showing "failed to connect to server"

#

In room "walking an application"

jaunty maple
#

tryhackme is not down ? I can't reach it

#

tryhackme is down ? I can't reach it*

eager fulcrum
quaint citrus
#

Hello, I'm trying to do the Plotted-TMS room but every 3 minutes everything crashed it is impossible to complete an nmap let alone a gobuster/nikto scan, it's been three days since I have noticed these kind of bugs/lags... on many rooms, It doesn't seem to be on my side as I can reach any other site including tryhackme's

#

Yup I have two, The tun1 was created when i did the wreath network, do you think i should set the tun1 link down ?

#

okay, I did 🙂

#

I will reboot the machine and get back to you if it's still laggy

#

It's the same gobuster dies after 40 seconds.. I'll try to regenerate my vpn config

#

When i vant to download my newly generate config file i get a 404

sharp bisonBOT
sudden heart
eager fulcrum
quaint citrus
#

Ok so here's what I did:

killall openvpn
ip link set tun1 down
generated new ovpn key to other eu serv
killed all tmux sessions
terminated my room
launched ovpn with new key
tested with Muirland scritps
It seems to be working

So the issue was that i add to tunX interface colliding which explained the working/not working 🙂 Thx for your help and have a good day

scenic torrentBOT
#

Gave +1 Rep to @gray loom

oak blade
#

Hi, team. Is it possible that the servers for "/room/fileinc" have had a change in their config? I'm consistently getting 502 (Bad Gateway) errors

crystal marlin
chilly copper
#

I'm having timeout problems in the LFI/RFI lab, can anyone help me? I have already generated a new openvpn access, restarted the machine, but it still occurs..

oak blade
#

And yes, I've tried numerous restarts (4 times, I think)

crystal marlin
oak blade
#

Sure, let me fire it up again. Couple of minutes

#

10.10.136.14

#

I can now see that it loads some content (the page name in the browser tab, but that's about it)

#

(And my browser allows sites to use JS)

crystal marlin
oak blade
#

On my own Windows client, yes. Which I have used succesfully for quite some rooms already. I'll try on another host, and see if the problem occurs there as well

crystal marlin
oak blade
#

Correct 🙂

#

Heh. Works fine on my Mac. Really strange stuff. Does this count as PEBKAC? 😄

crystal marlin
oak blade
#

I appreciate the help!

#

I'll tinker a bit with the MTU

#

I've taken necessary precautions, but thanks!

cold basin
#

Hi, My verification on Discord is not working with the TryHackMe bot. :/

weary spindle
#

@barren birch I did ping Ben earlier but he must be busy.

The bot is running commands, but it's not verifying again.

cold basin
#

Okay, thanks for the information. I will try it later.

inland shell
#

I have been grinding everyday on tryhackme about 2 weeks after i bought the membership and i lost all my streaks because i couldn't work on my tryhackme studies because my power cut off for half the day 😦 . Is is possible to get my streaks back at where i was i think you all can see in the history that i have been grinding everyday

#

please tag me with a answer

crystal marlin
naive dust
#

what's up with thm and no 2fa?

bronze vale
#

Not really a tech support question is it? :)

naive dust
civic mist
#

Hi! I'm trying to work on BOF OSCP PREP on the website but i got some issues w the script & the server ashin@cyberfoxar:~$ nc 10.10.7.82 1337 Welcome to OSCP Vulnerable Server! Enter HELP for help. HELP Valid Commands: HELP OVERFLOW1 [value] OVERFLOW2 [value] OVERFLOW3 [value] OVERFLOW4 [value] OVERFLOW5 [value] OVERFLOW6 [value] OVERFLOW7 [value] OVERFLOW8 [value] OVERFLOW9 [value] OVERFLOW10 [value] EXIT OVERFLOW2 AAA OVERFLOW2 COMPLETE OVERFLOW10 AAAA OVERFLOW10 COMPLETE Any idea about wtf is happening?

rigid crystal
#

Hello, is anyone one to help me? I've been charged for THM premium all year but I've been busy. I came back to the site to start training again and my premium features are gone. Why?

sharp bisonBOT
rigid crystal
#

Will do

odd kelp
#

I can't verify my account

brave horizon
#

Hi I am having issues with the exercise practical Example (Blind XSS), O I can connect with the website so when I inserted the XSS is not connecting back to my web server, I have tested in my local machine (using tun0 address and it is working) I wonder if the script to read the support tickets it is running?

sterile brook
#

When I connect to a room through openvpn, the connection constantly keeps disconnecting and restarting. Is that normal? Seems like the attack box works way better.

gleaming current
#

Hi I have a question about the 'fg' command

#

I'm learning how to use this command this week in school and we're tasked with running a command in the background by appending it with "&" at the end and then bringing it back by using 'jobs' to find the job number and then use 'fg 1' (in this case 1 because there's only one job) to bring it back to the foreground

#

I am using WSL right now and I have Ubuntu and Kali. On my kali terminal, I cannot use "fg 1" to bring the job back to the foreground. I have to use "fg %1" to bring the job to the foreground on Kali. However, on Ubuntu I can use "fg 1" to bring the job back to the foreground.

#

Can anyone explain what's going on here and why the difference?

true nest
#

zsh is great for customization and some fantastic tab completion, you can even tab complete flags for most apps. nmap -P [tab] will show you a list of the available ping flags there

gleaming current
#

Yeah I love it. I am a little bit worried it's become a bit of a crutch though. I struggle sometimes when I use ubuntu to remember full commands and I'm usually very unsure when I type a command that doesn't become highlighted to indicate that it is indeed a real command lol.

#

Thanks for answering 🙂

true nest
#

One thing I think THM highights in its rooms are limited linux enviroments, sometimes you’re working with only sh in the target environment and do have to put your linux chops to the test a a bit more. zsh just makes things a bit more comfy in your attacker enviroment, but when you drop to no color, then you know it’s time to get real :p

#

making reverse shells more “pretty” and usable plays pretty big part with that stuff

gleaming current
#

Time to find out who's a real hacker... * puts on sunglasses* and who ain't

#

yeah I've definitely been there, finally getting a reverse shell and then you're like... oh shit none of the colors are there... what do I... do?

true nest
#

Yeah the real ouch is using arrow keys without rlwrap and such, "what the shell" room goes into this at length.

last hinge
#

after weeks i still cannot connect to virtual machines of tryhacmme

#

whyyy...???

#

cannot believe that i have subscribed to tryhackme when i cannot connect to vm

celest wadi
last hinge
#

that is so *** when i download openvpn file it is empty

#

nvm thanks

sharp bisonBOT
sterile brook
#

It says please enter the path to your config. Where is that?

crystal marlin
#

So either run the script inside the same directory where that config file is located, or just provide the path to it

sterile brook
#

I have both files in my downloads folder but its saying it cant find it

crystal marlin
#

!docs verify

sharp bisonBOT
wraith torrent
#

Hey so I am trying to connect to THM's network through OpenVPN using the config file I downloaded however it keeps throwing me an error

crystal marlin
#

!docs verify

sharp bisonBOT
wraith torrent
sterile brook
#

I verified but it didnt seem to do anything

wraith torrent
crystal marlin
scenic torrentBOT
#

Gave +1 Rep to @wraith torrent

crystal marlin
#

Ups, ez rep I guess 😄

wraith torrent
sterile brook
#

no reply, I did it 4 times

wraith torrent
#

^

crystal marlin
#

Well then send me the screenshot via DM guys

wraith torrent
#

Of the bot or of the problem?

crystal marlin
#

Of the problem

wraith torrent
#

Alright sounds good

sterile brook
crystal marlin
jade lotus
#

hi everyone, i have tried to be verified by tryhackme BOT but nothing comes back when i try to send my token throu !verify

crystal marlin
jade lotus
#

but until i am verified imma not be able to send screenshots of my problems

crystal marlin
jade lotus
#

thanks

west kelp
#

Hey, I'm trying to connect in the Bounty Hacker CTF via ftp, but it doesn't response when I do f.e. get or ls. It stucks at 229 Entering Extended Passive Mode . Any solution?

crystal marlin
west kelp
#

when you started writing I saw, I was in the false channel ^^

weary spindle
scenic torrentBOT
#

Gave +1 Rep to @gray loom

alpine mauve
#

is there any way to spawn windows attackbox on thm? I need to use the immunity debugger ._.

#

is there any way to overcome this? from what i understand the issue is my machine running 64bit while the app is not?

celest wadi
#

windows vms are resource heavy to setup locally sadge

alpine mauve
celest wadi
#

well, having vm's is nice anyways, also, I don't think you need to run the binary itself, it should run just fine in immunity by itself which is all you really need

eager fulcrum
zenith stirrup
#

I searched on google and could not find an answer so I am going to ask here. Is there a Ubuntu package that allows me to get access to this wifi adapter I have so that I can enable monitor mode on my laptop.

weary spindle
#

Can the Wi-Fi adapter go in monitor mode?

zenith stirrup
#

The one I got can yes

#

I can get you a link to the wifi adapter I got on amazon if you want to look at it.Tried that

#

Tried that

#

Didnt work

#

And that is for the built in wifi adaptor

#

Not a USB wifi adaptor

#

And my problem is that my laptop does not detect the wifi adaptor

#

Yes and no. I like to test anything I learn on Tryhackme on my personal laptop

#

So its not like I am reading a textbook

#

Ik there is an attackbox but It still feels confined to me

#

Thank you

blazing summit
#

Jr Pentester-Authentication-Task 3 appears to broken. The ffuf isnt finding any valid passwords

#

I've verified my input 30 times

blazing summit
#

Nvm, it doesnt clarify NOT to send the direct output > to a file but to instead save the names themselves.

supple charm
#

Noticed nmap version is a few versions behind current version. Can Tech Support update nmap version on the VMs ?

slim heath
#

Currently working with the Windows fundamentals rooms. How am I supposed to copy from the WIN machine into my THM browser?

#

Because it seems that the copy paste utility only work inside the attackbox

celest wadi
#

no

#

windows machines don't have that feature, that's only on the attackbox