#pre-security-legacy-path

1 messages · Page 2 of 1

tacit condor
#

Hi, I had a doubt regarding the https://tryhackme.com/room/packetsframes Room.

I have a conceptual question here.

In the First Task, there is some information mentioned as follows:


This process is called encapsulation which we discussed in room 3: the OSI model. At this stage, it's safe to assume that when we are talking about anything IP addresses, we are talking about packets. When the encapsulating information is stripped away, we're talking about the frame itself.```

I'm confused regarding the analogies being given.

If we put an envelope within an envelope. wouldn't that be the same as a Network Layer **Packet** inside a Data Link **Frame**?
The analogy seems to mention the opposite.

Secondly - in the last line - it mentions that stripping the encapsulating information away means we're talking about the frame?
Shouldn't that be the packet instead?
thorny mulch
#

generally i think every protocol in different layers has it's information and it adds this is as envlope so when passes lower layers like network layer it will add another envelope

hidden snow
#

Hey guys i'm on the Windows active directory basics room and i'm blocked on a very simple thing its dumb i know but honestly i don't know what to do when they say i have to connect to an account via RDP.

potent wedge
#

install remmina
use remmina to connect to ip with default rdp port and credentials
????
profit

hidden snow
#

So my question is : Do i need to use OpenVPN to connect to the THM.local domain for access to the "philip" account ?

#

Oh okayyy

potent wedge
#

on your kali linux vm

hidden snow
#

yeah i will do that

#

so little recap: boot my kali vm + install remmina (rdp client i guess) + connect to thm vpn + and then connect via ad credentials

#

well okay thanks for the help shadow !

potent wedge
#

yuup that is the path to do it

#

and no problem

clever elbow
#

Hi, friends. I am having issues with the "Linux Fundamentals Part 1" room, or rather, with the virtual machine. My username is "root" instead of "TryHackMe" and it seems I have different folders/files to what the room apparently expect me to have. Could someone help me? I am not sure whether I should have done something differently or it's simply bugged.

spice leaf
#

you don't need the AttackBox for now

clever elbow
somber currentBOT
#

Gave +1 Rep to @spice leaf

wet plank
#

Hi, I've been working through the pre-security pathway but I have come up against a problem. On Windows Fundamentals 1 and 2 I cannot get the machine to connect. The machine loads and the screen turns blue as it appears to connect to the Windows machine before switching and presenting me with the following message. "The TryHackMe remote server is not currently reachable. Please check your network and try again". It attempts to reconnect but the issue repeats. I have tried switching off and on my VPN to see if this is the issue, I have ensured all previous machines are closed but unfortunately the issue persists. If anyone has any suggestions I would be greatly appreciative. Thank you.

north phoenix
#

Hello everyone, I am on the Pre Security path >> Linux Fundamentals >> Part 2 >> Permissions 101, and when I try to find the answer to the 1st question "On the deployable machine, who is the owner of "important" ?", I can't find any "important" file/dir. Neither can I answer the following questions because there no "user2" when trying to switch user with sudo command. I don't know if I was expected to do that I didn't or is this part bugged ? Thanks for your help !

potent wedge
#

the machine you are currently interacting with is most likely the attackbox

#

you need to interact with the target machine

#

which you connect to using ssh

#

the instructions is in task 2

north phoenix
somber currentBOT
#

Gave +1 Rep to @potent wedge

potent wedge
#

no problem

north phoenix
#

Hello everyone, I am on the Pre Security path >> Linux Fundamentals >> Part 3 >> Task 4, I already deploy the machine, connected to the target machine and I launched the Python3's "HTTPServer". BUT when I use the following command "wget http://10.10.27.194:8000/.flag.txt" to download the file as asked, nothing happens. Did I miss something ?

tight ingot
north phoenix
tight ingot
tight ingot
north phoenix
tight ingot
#

Can you take a screenshot of the window?

north phoenix
north phoenix
tight ingot
north phoenix
tight ingot
north phoenix
somber currentBOT
#

Gave +1 Rep to @tight ingot

tight ingot
#

No problem!

Common mistake.

Happy hacking

north phoenix
#

I know it seems obvious for the insiders but not really obvious for those starting like me

tight ingot
#

The screenshots are what help me tell the difference.

analog girder
#

hello

#

is there need to know how to programm well

#

I just have basic knowledge of javascript

#

is it good for me to jump in THM pathways ?

potent wedge
analog girder
#

man I targetting for the oscp and pentesting

#

is there any need for it in the way ?

potent wedge
#

well buffer overflow exploitation is one of the areas where scripting in python or ruby will help a lot

analog girder
#

ehat about the AD

#

cause I think OSCP has deleted the bufferOverflow part in the exam

potent wedge
#

active directory is mostly graphical but commands for powershell

analog girder
#

so learning the windows administration is a must

#

so I didnt waste my time the last 3 months

#

?

potent wedge
#

yeah if you are going to mess with active directory

analog girder
#

so do u suggest me getting toward the THM pathways righ away

#

I have basic linux knowledge with a CCNA cert and knowledge about windows admin

#

?

potent wedge
#

yeah go for it but you might need not just tryhackme but some other sources for information too

analog girder
#

such us ?

potent wedge
potent wedge
analog girder
#

man do u fell me here

#

I know there is a lot of it in intternet

#

but what should know first

#

and what do i let it for advanced leels

#

levels

potent wedge
analog girder
#

thanks a lot

#

thank for your time

potent wedge
#

you're welcome

wicked garden
#

Hi guys, I'm new to this major I need to start from the scratch, but I don't know how

oak storm
#

Do this path

fathom gust
#

If I'm new not only to Hacking, but also IT, where do I start? I'm just fresh right out of collage

oak storm
fathom gust
oak storm
fathom gust
#

I want to get into hacking but I have no IT knowledge pretty much

oak storm
#

For penetration testing the oscp is the golden standard for entry level, pentest+ is good too and cheper but less marketable

fathom gust
#

Red teaming and working in the gov is what interests me

oak storm
#

Then check what certs job in the government requires

green rock
#

HELLO

#

What layers of the OSI model do firewalls operate at?

#

When i Type the answer Layer 2,Layer 3 as shown in the answer syntax i still get an error

#

can someone help me

#

?

spice leaf
green rock
#

ok

#

Thank you i got the right answer

gentle pilot
tight ingot
gentle pilot
#

omg, lol. thank you.

fluid talon
#

yay I finished this part wope wope

marsh veldt
#

nice

green rock
#

hello

#

i'm trying to start the HTTPserver with the Python 3 but after launhing the command i get no return such as 127.0.0.1 - - [04/May/2021/14:26:09] "GET /file HTTP/1.1" 200 - my cursor is still blanking as you can see in the screenshot, as if the syste is waiting for input command

green rock
#

hello

#

that's fine

#

i found it

#

thank you !

gentle pilot
mystic geyser
potent wedge
gloomy needle
#

Quick question for linux. I seemed to have lost the initial part to linux commands (tryhackme@linux1:~$).

If you lose it, how do you go about getting it back? Forgive my random jarble on it. Just trying to learn it haha.

wide arch
gloomy needle
somber currentBOT
#

Gave +1 Rep to @wide arch

marsh veldt
mental scaffold
marsh veldt
#

thanks

mental scaffold
#

When did you start doing this

marsh veldt
#

yesterday

#

well no today

#

just very early 12pm lol

mental scaffold
#

And you finished it so fast

marsh veldt
#

yeah the course was pretty easy for me

#

i liked it

mental scaffold
#

Nice

marsh veldt
#

lets goo

sand sonnet
marsh veldt
mental scaffold
#

Two certs in a day

umbral wraith
#

hii
I'm still stuck on the same problem of that wordlist in jr penetration walkthrough
user@rain berry$ ffuf -w /usr/share/wordlists/SecLists/Usernames/Names/names.txt -X POST -d "username=FUZZ&email=x&password=x&cpassword=x" -H "Content-Type: application/x-www-form-urlencoded" -u http://<ip address>/customers/signup -mr "username already exists"
this is the command which is mention in the walkthrough of authentication bypass
i have download the file of username.txt from the link you provided and modified the above command by changing the -w (location of my file)
then when i run the command it shows the output came when we run "ffuf -h" with a encountered error message of >> stat <location of file> "no such file or directory "
please help me out

oak storm
umbral wraith
#

yes

uncut swift
#

hii, im stuck on the windows fundamentals room. part two, task 2: q1 and 3. really don't see the answer

noble lodge
#

Hello, I am a total novice in Cybersecurity, what to do?

oak storm
mental scaffold
uncut swift
#

yeah i got it! Thanks

mental scaffold
elfin rover
mental scaffold
jade river
#

Why

#

The hell do you need my phone number and full name?

#

@minor perch

#

Why do you need my private info for signup stuff

stark rain
#

?

tight ingot
marsh veldt
#

,

fathom gust
#

Anyone has the liat of paths to follow from the easiest one

#

?

oak storm
potent wedge
#

the optional ones are optional due to not teaching a lot of new concepts if you do the previous paths but are still worth looking into

fathom gust
#

I see, good to know

marsh veldt
#

what's pentest+

#

that's the

#

comptia thing?

oak storm
# marsh veldt what's pentest+

It is a certification, you take a test that is held by CompTIA and if you pass you get te certification, useful for job hunting, especially government jobs.

oak storm
jaunty patio
#

we do need a bash scripting if we planning to do pentest path ?

#

or in general in ethical hacking i mean

potent wedge
jaunty patio
#

ah okay its just a plus thanks!

potent wedge
jaunty patio
#

yeah it was on my learning list anyway thanks for time :))

dusky glen
#

I’m at Linux fundamentals Part 3 task 8, there’s no apache2 in /var/log?

#

I tried looking in both Linux machine and attack box

rain berryBOT
dusky glen
#

Ah okay! I got it now. Thank you

somber currentBOT
#

Gave +1 Rep to @trail flame

dusky glen
#

Stupid me haha sorry

rough crest
#

Hey guys I am stuck in the intro to offensive security first task itself even though I transfered money when I submit the transfered amount it is coming the answer is incorrect

#

Please someone help me

tight ingot
rough crest
somber currentBOT
#

Gave +1 Rep to @tight ingot

eager oar
#

Been connecting via kali VM and openVPN. Getting in to some windows things and wondering which RDP client are people using to connect to windows machines from within their kali VM?

potent wedge
#

remmina is easier for most people as it is a graphical application

#

xfreerdp is a terminal based rdp client where you need to specify everything in the command

eager oar
#

@potent wedge - I appreciate you!

#

follow up looks like xfreerdp comes with the current kali release so thats a win

glossy plank
#

Hi everyone. After leaning ccna and operating systems what should I learn else?

marsh veldt
somber currentBOT
#

Gave +1 Rep to @potent wedge

potent wedge
#

you're welcome

marsh veldt
somber currentBOT
#

Gave +1 Rep to @mystic arch

grim igloo
#

Hi guys, I'm new to cyber security and I want to learn more about it can you guys help me with some resources or how I should plan to learn, I'm starting with the free version of THM so is it beneficial or I've to get the pro one

rain berryBOT
spice leaf
#

You can follow this guide of free rooms for beginners

fringe pelican
#

When doing the Windows Fundamentals part 1 I get the same issue as with the Linux Fundamentals part 1. Launching the machine and only getting a white screen

potent wedge
# fringe pelican

@bitter dome wants the ip of the target machine and wants to look into this

#

if jabba is still up that is... he might have headed to bed

fringe pelican
#

sent it to you in a dm 🙂

potent wedge
#

oh sorry shadow can't do anything about it... this is jabba:s realm of having to look into problems and fix them

fringe pelican
#

haha that's fine. If he's still up he can contact me 😉

distant karma
fringe pelican
#

I did, in fact for the entire windows fundamentals i had white screen machines. Tried different browsers, no extensions, …

The attackbox itself works fine; it’s just those linux fundamentals and windows fundamentals machines I’m having trouble with

tight ingot
dark merlin
#

Im having a hard time understanding what account status means on the 4th question of the Windows Fundamentals 1 :: Task 6

#

If anyone know what it means, I'll appreciate if you share it

#

nvm just got it

tight ingot
#

It could be for a different room, 🙂 could you please delete this flag though. 🙂

cerulean tartan
#

Absolutely! That was my first thought. I was just super curious. Thanks again.

atomic hinge
# tacit condor Hi, I had a doubt regarding the https://tryhackme.com/room/packetsframes Room. ...

Hi, I have the same problem. 've been looking at various sources and I think it says the opposite here. When we encapsulate, then we put Packet envelope in the Frame envelope. But the tryhackme rooms say otherwise. And in decapsulation the Frame envelope should be first and the Packet envelope is inside.
I noticed the same problem further, in the Extending Your Network class.
Task 5:
Take, for example, a layer 2 switch in the diagram below. These switches will forward frames (**remember these are no longer packets as the IP protocol has been stripped**) onto the connected devices using their MAC address.
I think IP isn't stripped from Frame as frame is first in the process of decapsulation.

Can someone explain how this is not an error? The explanation @thorny mulch did not solve this for me.

proven quarry
#

linux fundamentals part 3, i use "python3 -m http.server" than i cant do anything else

#

and I can't get the .flag.txt file

tight ingot
proven quarry
#

so i should use 127.0.0.1?

#

it's saying connection refused

#

I've solved it, need to relog again with the provided credentials...

marsh veldt
#

does anyone know how to use gobuster

tight ingot
#

Isn't it

gobuster *flag* -u *url* -w path/to/wordlist.txt

#

Obvious for dir you replace flag with dir

marsh veldt
#

understood

#

I was in pre security first module

#

The gobuster command was: gobuster -u <url> -w wordlist.txt dir

#

What was the use of dir in this

bitter dome
rough ingot
#

On the next level pre-security! I hope I do well on this course, good luck to anyone who is already on it you rock!

rough ingot
#

Done

tardy egret
#

Hello, can anyone help? Does anyone know why I can't access the learning path? is it now not accessible?

tribal falcon
#

The Windows fundamentals 1 box doesn’t seem to be working for me. Launching it yields Connection does not exist

gaunt hull
#

or just read contents

quartz mulch
#

hello I am getting the following when trying to access the lab machine for the linux fundamentals -1 class I get a connection error, the requested connection does not exist
can anyone please suggest how can i access the lab

alpine venture
#

Confirming, that I also got the same error message when trying to connect to that machine.

alpine venture
opaque hazel
#

How to get started into bug bounty?

#

For beginners guide??

#

Pls anyone help me

meager cipher
#

@opaque hazel If youre a beginner, I wouldnt worry about bug bounties right now

fathom gust
wraith edge
#

Started this pathway. I am curious to hear from other people, do workplace people acknowledge certifications or skills from THM?

Was just wondering if anybody ever got picked up by doing these courses?

obtuse saffron
#

just started today hi everyone

tight ingot
somber currentBOT
#

Gave +1 Rep to @tight ingot

limber ingot
#

Started this pathway today and I learned a lot

#

The networking and intro to LAN helped a lot compared to other resources I was using to learn networking fundamentals

merry reef
#

Hi, folks, is there someone knows the answer for the 3rd question of 3rd task on the Intro to Digital Forensics plz. I am not looking for answer just want to complete it. I think there is bug, actual answer that maps shows it does not match with designated answer.

brave cobalt
#

On which part are you having a challenge?

merry reef
#

3 rd part

#

finding the location of kidnapper

brave cobalt
#

What command did you use against the image?

merry reef
#

no it is not about image

#

I solved all questions related to image

#

it is about where the image has been taken

#

physical location of the image

#

using exiftool

#

on that task 1st question is who is the author. found it.

#

2 nd location of image taken, not found

#

3 rd model name of camera, found

brave cobalt
#

Aahh... got it.

#

I Googled for || 'find location coordinates' || instead of using Google Maps as it gives out an error.

merry reef
#

so u got the street name?

brave cobalt
#

Yes

#

If you still can't make it work, dm me.

merry reef
#

I got it, but not solving that)))

#

how many letter does it consists I mean just first part?

brave cobalt
#

Or simply, you can find a site that lets you find a place by putting in the coordinates - lattitude and longitude.

merry reef
#

I usually use it with cereal))thanks anyway

brave cobalt
warm nymph
merry reef
#

@warm nymph, yes , I did, but it did not work by doing what it says on instruction. I found it somewhere else.

primal abyss
#

i am here: Windows Fundamentals 2 task 2: What is the name of the service that lists Systems Internals as the manufacturer? i did kind of look after everything, but i could not find anything that's alike the answer (answer format: 10). and this: Whom is the Windows license registered to? that's the second question from the same task in the same windows fundamentals 2, and I don't know how to learn that either. pls help
https://tryhackme.com/room/windowsfundamentals2x0x

cloud ridge
#

what learning path did you guys take after this one?

#

and what made you decide to take that

potent wedge
cloud ridge
somber currentBOT
#

Gave +1 Rep to @potent wedge

olive arch
#

hi guys when i prompt ($python3 -m http.server) in dployable machine and launch the command (Serving HTTP on 0.0.0.0 port 8000 (http://0.0.0.0:8000/) ...) then it stops in this line icant type commands anymore pls help

tight ingot
somber currentBOT
#

Gave +1 Rep to @tight ingot

olive arch
#

there is a problem in linux fundem3 task6 when i type crontabs -e it gives me "@reboot /var/opt/processes.sh" can someone help me

olive arch
# spice leaf so what's the issue?

normally when i enter in nano i should see the cron task to know when it will launched but i only see in the first line "@reboot /var/opt/processes.sh"

spice leaf
#

yes, and that is exactly what you should be seeing here

#

it tells you when it will launch

olive arch
spice leaf
#

the date isn't known in this case

olive arch
#

i answed 0 but its false

spice leaf
#

it is false, yes

mellow plinth
#

Can't progress through the Windows Funamentals 1 room because I can't get the "Attack Box" to connect, Hoping someone here could help me out.

long kindle
mellow plinth
long kindle
# mellow plinth No, I gave up.

I'm checking it out now and it looks like you're not using the AttackBox in this scenario, I think you're just exploring a W10 VM

#

First task allows you to RDP into the VM but I see nothing related to the AttackBox here, besides having the option to launch it

mellow plinth
somber currentBOT
#

Gave +1 Rep to @long kindle

oak escarp
#

hey, I am doing Linux Fundamental.Part 3 Room. There I need to ssh to a remote machine with proveded credentioals. But each time I put a password, I get a response "Permission denied, please try later". Meantime I double checked the password is correct. Any tips, mates? What did I wrong?

tight ingot
#

Probably use the the wrong ip.

Did you start the machine on task 1/3?

clear tundra
oak escarp
somber currentBOT
#

Gave +1 Rep to @clear tundra

tight ingot
#

If you look at the crontab through crontab -l it shows you at the bottom when it will run?

clear tundra
#

I mean a lot of the rooms don't explain everything, a big part of it is researching which is explained in the section before the room.
reading relevant books, or searching for relevant information after doing a room has been a big part of helping to learn IMO, especially the networking rooms.

most IT jobs are just about how well you can google

EDIT: I was thinking about the section in the complete beginner pathway for that researching comment, my b.

dapper finch
#

If i have learned Pre Security,what step shou i do?

short shadow
sand sedge
#

Hello there, a little bit stuck with introduction to linux. can someone help pleasse?

sand sedge
#

nvm... i'm a dumbass...

marsh veldt
#

im supposed to pay for this to unlock the room right?

potent wedge
marsh veldt
#

like the important ones

potent wedge
#

if you can't afford a subscription to tryhackme you could wait for the next community giveaway of vouchers

somber currentBOT
#

Gave +1 Rep to @potent wedge

potent wedge
marsh veldt
#

ill just do the free ones for now and then do the paid ones later

#

when i probably win one

#

that works right?

potent wedge
#

yuup that works just fine

marsh veldt
#

great

#

thanks alot <3

#

take care and be safe

trim dagger
#

Hi All. I am currently going through Linux Fundamentals 3, but I can't figure out if this is supposed to happen in the terminal. When I go to start the webserver using the python3 command, I receive the following which appears to be correct. But then the command line essentially disappears. Anyone have any idea how to get it back or what I may be doing incorrectly?

#

Tryhackme@linux3:~$ python3 -m http.server
Serving HTTP on 0.0.0.0 port 8000 (http://0.0.0.0:8000/). . .

trim dagger
#

I found the answer. That was step 1 (as others have pointed out). Step 2 is to open up a new terminal window for the AttackBox and use the wget function from there. Since you have turned the VM into a web server using the python3 command, the AttackBox and VM can communicate and you will receive the file.

tight ingot
#

But check out the syntax of the file.

fathom cargo
#

so am i

#

i'm also new to kali

#

it's been like 15 days from download

#

what book would any person recommend to read that tells us a lot about hacking and about kali linux

#

the most im

#

i mean

#

if anyone lnows let me know

snow crypt
spark rain
fossil hound
#

Hi, i'm on Linux Fundamental 3. I have a problem with the question 3 in Task 4. I can't seem to download the .flag.txt file as it keeps saying Error 404: File Not Found

spark rain
honest basin
#

Hi can someone please help me, I'm on take 6 practical network simulator and for some reason my network log isn't loading and it won't let me finish

wary lily
#

Actually I guess you are seeing as though you had no problem with Task 3...

ebon cape
#

I has a question

#

Pre security pathway using the attack box for windows ad started both machines trying to rdp and it was giving me a cant connect error

#

Do I need to use openvpn through the attack box aswell?

tight ingot
#

No.

#

Which room?

ebon cape
#

Windows fundamentals my bad

tight ingot
#

You don't need to RDP in?

#

That machine boots up a split screen machine.

ebon cape
#

Okay so I’m not crazy and but I was like hmm

tight ingot
#

have you booted up an attackbox?

#

And pressed the green start machine button on task 1?

ebon cape
#

I attempted rdp in the target machine for fundamentals 1 and it said can’t connect after accepting the certificate

tight ingot
#

Strange

#

If you click here you should switch machines if both are open

ebon cape
#

Yea I think it’s user error but same thing happened to someone else

#

Or maybe u don’t even need it for the fundamentals

tight ingot
#

you dont need to rdp in

ebon cape
#

Okay cool! Thx I was overthinking it

tight ingot
honest basin
somber currentBOT
#

Gave +1 Rep to @wary lily

bright drift
#

Finished this room.

low oar
#

Hey im having an issue ob the linux fundamentals part3

low oar
#

when running wget in it it continually loads then just connection timeout

spark rain
#

The instructions aren't super clear if you have no idea wtf you're doing (aka me when I did this room, took me awhile to figure it out 😅😅)

tight ingot
#

They literally tell you to use the attackbox.

spark rain
# tight ingot How are they not clear?

Well, considering this is the second time in a row that someone has asked this recently, I don't think I'm the only one who was confused. I think it would be more clear if it said to use two tabs in the terminal. For folks that are new and still getting used to the interface "use the attackbox" is still confusing.

#

Also it's kind of rude to be snippy about someone being confused on a site that's for beginners - nobody needs to be made to feel stupid around here, that's the opposite of what the site is trying to do.

tight ingot
#

I wasn't being rude.

slow folio
#

excuse me why can't i use the windows virtual machine in pre security pathway? i get this message:

"CONNECTION ERROR
The TryHackMe remote server is not currently reachable. Please check your network and try again"

fierce zinc
#

are you using OpenVPN or attack box?

slow folio
fierce zinc
#

did you tried switch the thm server?

#

on network

slow folio
fierce zinc
#

I guess its on profile picture and network

abstract sparrow
#

Do you guys take notes when doing rooms? Specifically this one because I feel like it has a lot of reading compared to some others.

spice leaf
abstract sparrow
#

I take mine in google docs and summarise it

#

I was wondering how everyone else does it

stark rain
#

taking nnotes is byg time yes

#

all the way

spice leaf
abstract sparrow
#

notion and obsidian appear very similar in design, obsidian looks like vs code to me.

#

What makes it good in your opinion?

spice leaf
# abstract sparrow What makes it good in your opinion?

The notes are stored in markdown files, which if needed can be opened in any text editor.

With a simple style sheet, I have like 9 different colours in order to colour-code my notes, there's a lot of useful plugins, you can link to other notes or headings within the same note.

Files are stored locally and not in the cloud, which on one hand means you're responsible for keeping your own backups, but on the other, it could potentially help with keeping notes confidential if the given employer allows usage of Obsidian. I like that you can nest folders as needed.

I really haven't used Notion much, but I've heard that the export function isn't great which would make migrating your notes harder.

warm epoch
spice leaf
somber currentBOT
#

Gave +1 Rep to @warm epoch

abstract sparrow
somber currentBOT
#

Gave +1 Rep to @spice leaf

abstract sparrow
#

notion blue screens my laptop anyway for some reason so I am more than happy to make the switch there

spice leaf
abstract sparrow
#

Thanks

undone cradle
#

Windows Fundamentals 1 task 6
What is the account status?

#

how can i find it i dont understand

#

nvm

spark rain
abstract sparrow
#

Nice

quartz vine
#

Finally reached 80% on this path! I think I'll be finishing this up today.

quartz vine
#

Completed the Pre-Security Path!

#

reach out if you need any assistance.

abstract sparrow
#

Congratulations

quartz vine
somber currentBOT
#

Gave +1 Rep to @abstract sparrow

marsh veldt
#

Windows Fundamentals 1 task 6
What is the account status?

When I click on properties of the accounts, there is absolutely nothing about account status

fathom gust
tight ingot
somber currentBOT
#

Gave +1 Rep to @fathom gust

marsh veldt
marsh veldt
brave plank
spice leaf
# brave plank Would you be willing to send these examples to me haha? Or just, how do u make t...

For the drop downs, basically you make a new folder, another below it and different notes in the folder, depending on your needs, you can nest folders as much as you want.

For the notes, warnings, etc., you can use the built-in callouts feature:

https://help.obsidian.md/Editing+and+formatting/Callouts

Or a plugin called Admonitions.

Obsidian Help

Use callouts to include additional content without breaking the flow of your notes. To create a callout, add [!info] to the first line of a blockquote, where info is the type identifier. The ty…

brave plank
#

Ahhh

#

Thanks!

frank cliff
#

hello guys, I'm learning Linux Fundamentals part 3 - Can NOT access the file "access.log" in /var/log to find out the IP address, answer for Q. Probably, I need root privilege, so I've tried sudo with "tryhackme" password, it doesn't work.

#

Can anyone help me, please?

tight ingot
#

Or are you trying on the attackbox?

frank cliff
#

I'm in ssh tryhackme

frank cliff
#

tryhackme@linux3:~$ cd /var/log/apache2/
tryhackme@linux3:/var/log/apache2$ ls
access.log error.log error.log.2.gz
access.log.1 error.log.1 other_vhosts_access.log
tryhackme@linux3:/var/log/apache2$ cat access.log
cat: access.log: Permission denied

#

this is what I've got

#

tried to sudo it:

#

tryhackme@linux3:/var/log/apache2$ sudo cat access.log
[sudo] password for tryhackme:
Sorry, try again.
[sudo] password for tryhackme:
tryhackme is not in the sudoers file. This incident will be reported.
tryhackme@linux3:/var/log/apache2$

frank cliff
#

ryhackme@linux3:~$ cd /var/log/apache2/
tryhackme@linux3:/var/log/apache2$ ls
access.log error.log error.log.2.gz
access.log.1 error.log.1 other_vhosts_access.log
tryhackme@linux3:/var/log/apache2$ cat access.log
cat: access.log: Permission denied

#

SERVER logs

sterile spade
#

you need to cat out the access.log to get the ip address yes, the first access.log you don't have permission for, however that's not the only access log in there that can help you find the ip address

strong lake
tiny acorn
#

hmmm

#

not sure why it wouldn't embed

sand ember
#

I didnt quite get it-

tiny acorn
#

so can a network address be any number?

#

for example, if a network address was 192.168.1.35, can a device connected to the network have a host address that's the same as the network address but the last octet is different? (such as 192.168.1.20 or 192.168.1.0 or 192.168.1.40 or 192.168.1.100 or 192.168.1.255)

brave cobalt
#

!docs verify

rain berryBOT
brave cobalt
#

Folks here won't simply click on links shared

brave cobalt
# tiny acorn for example, if a network address was 192.168.1.35, can a device connected to th...

It will depend on how the network is divided. You may need to look up subnetting for this. Also, the network address is always the first address in your network or subnet. In your sample, if the network address is 192.168.1.35, you cannot have a host address of 192.168.1.0 or 192.168.1.20 that is a part of that network. The subnet mask or CIDR notation will need to be considered here. Same goes with a host address that has a last octet of 255 as it will be the broadcast address for a network or subnet as the case may be.

somber currentBOT
#

Gave +1 Rep to @brave cobalt

violet ruin
#

! Verify

dreamy turtle
#

hey , i have an issue to respond to a question

#

i cant add screenshots i guess

#

it's the question "When will the crontab on the deployed instance (10.10.122.65) run?"
i am connected to the linux3 and used the command "crontab -l" but found no specific cron job entries

dreamy turtle
#

hm i used it and put it on a text file

#

I have to look for something ?

sand ember
#

ss means screenshot. i dont exactly remember the task and the context man

#

so i said a screenshot would be helpful

dreamy turtle
#

ah u mean screenshots xD

#

tried to restart and get new one,but still stuck

sand ember
#

crontab -l gives you that output?

dreamy turtle
#

yep

sand ember
#

the answer is literally in front of u

#

just look closely

#

at the output

dreamy turtle
#

on the second screenshot ?

sand ember
#

yes

dreamy turtle
#

tried reboot , startup

sand ember
#

try @frail swallow

dreamy turtle
sand ember
#

did u add @

dreamy turtle
#

omg

#

20 min of my life xD

sand ember
#

its okay happens to the best of us

dreamy turtle
#

thanks buddy

sand ember
#

Yw

potent wedge
#

haha yeah this happens a lot

sterile maple
#

the answer should be changed to "on reboot" tbh

hollow idol
#

Anyone can help me out here with the Windows Fundamentals Part 2 ?
i just don't get it

#

omg this is so ...
Fundamentals Part 2 Question 1 : ||PsShutdown||
Question 3 : ||C:\Windows\System32\control.exe /name Microsoft.Troubleshooting||

waxen gyro
#

I don't know how to check the account status in Windows Fundamentals Part 1, help?

tight ingot
#

Go to users and right click properties

waxen gyro
olive vortex
#

Hello
I have a problem with Pre Security path
How The Web Works
HTTP in detail
Whenever I try to view a tab, it shows either a "White page" or "Security error"
tried from Tor browser, Firefox, Chrome.
Any solution?

olive vortex
brave cobalt
glad bison
olive vortex
olive vortex
marsh veldt
#

Hey friends

#

Is there anyone going with this pathway ?

coarse oak
wanton flower
#

Hello Friends, What flag do you get when you ping 8.8.8.8?
What flag am i looking for exactly Because when i ping 8.8.8.8, i got a successful connection to the IP Address

tight ingot
wanton flower
somber currentBOT
#

Gave +1 Rep to @tight ingot

rose laurel
#

Can anyone help what is pre security pathway where should i get started ??

marsh veldt
worldly bolt
#

I'm up to subnetting and the example for host address confuses me. It says, Purpose: An IP address here is used to identify a device on the subnet, Explanation: For example, a device will have the network address of 192.168.1.1 and Example: 192.168.1.100

Why is the Explanation saying network address is 192.168.1.1? Wouldn't network addres be 192.168.1.0

worldly bolt
brave cobalt
#

!docs verify

rain berryBOT
brave cobalt
marsh veldt
#

Hi guys,

Where to get the credentials url for the Pre security certificate which is received from tryhackme, I need it to upload in LinkedIn.

Please guide me where to get that....

tight ingot
#

Credentials url?

brave cobalt
formal plover
#

Hello
I have a problem with task 3 (Enumerating SMB) from network services
When i do the nmap scan the attack box shows 5 open ports none of them is SMB

#

What could be the problem?

formal plover
#

There are six

#

I deployed the telnet machine and i still have the same issue

tight ingot
#

The machines are different.

You need to launch the correct machine for each task

brave cobalt
worldly bolt
somber currentBOT
#

Gave +1 Rep to @brave cobalt

worldly bolt
#

Issue shows up at Interacting With the Filesystem!

tight ingot
#

The screenshots are just examples.

worldly bolt
somber currentBOT
#

Gave +1 Rep to @tight ingot

tight ingot
worldly bolt
somber currentBOT
#

Gave +1 Rep to @tight ingot

formal plover
#

I'm doing an nmap scan on task 6 (enumerating telnet) but the remote host doesn't show any open ports and i re-scanned the host for port 23 and it tells me the port is closed

#

Any help?

brave cobalt
formal plover
#

Nmap --top-ports 1000 [ip]

brave cobalt
fringe pond
#

Hi Team,

When I click on the view site, it opens on the same browser window. The split option. But I want that to open in a new tab. Is there an option?

brave cobalt
fringe pond
#

Okay

formal plover
#

When i use metasploit on enumerating mysql it doesn't show me the right results

#

My RHOSTS, PASSWORD, USERNAME, RPORT are correct

#

It doesn't return any useful result

formal plover
#

Why does it return Access denied?

formal plover
#

I tried to use metasploit again to exploit mysql but it returned Access denied again

brave cobalt
formal plover
formal plover
#

All done 👍

lost oyster
#

Hi guys, im doing linux fundamentals 3 and using ps aux to find the weird file, I can see whoopsie, but i cant do anythin with it

quartz dock
formal plover
#

OWASP 10-2021
insecure design
I'm trying to find the password resitting bypass i tried to manipulate the url, i entered very long passwords and entered some shell commands but i didn't get any useful results

#

Any hint?

lost oyster
# quartz dock iirc you have to cat down into the file `cat ../../file`

I looked it up on youtube, there is supposed to be a flag in the file list, but it doesnt appear when i run the command, others have had this issue, and it is fixed with a reeboot, but alas i rebooted 5 times and it didnt fix the issue. i typed the flag in that i saw on YT and moved on , hopefully no more issues like this occur

lost oyster
#

all good, thanks for trying to help, I had already cat that file it was in wingding format

quartz dock
#

ah, yeah I think I was miss remembering rooms as well

lost oyster
#

i nano'd thinkng the flag was inside, but it's not

quartz dock
#

yeah I'd have to go back through the room I've forgotten

lost oyster
#

looking for the apache2 file for logs, But it doesnt exist

#

more issues with the linux fundmentals machine not havig the files required to finish the task

tight ingot
#

You'e in the wrong VM.

#

You need to SSH in to the machine.

lost oyster
#

i launch the box though

tight ingot
#

But you didn't SSH in to the user.

lost oyster
#

it said look on the deployable machine, so i didnt ssh in to the tryhack me box, but when i did, it still doesnt exist

#

thanks for your assistance in this matter however

tight ingot
#

cd /var/log

lost oyster
tight ingot
#

You didn't do the step previous.

lost oyster
#

what step previous?

#

ls? it only says task3

tight ingot
lost oyster
#

thanks , i had to cd in to the apache2 log, it would not produce it with the command

errant needle
#

hi,
i'm in the room "linux fondamental part2" and i try to connect the tryhackme account with ssh tryhackme@IP MACHINE but the pswrd tryhack don't work.
I've try a lot and i think it's a bug machine. Can I have help plz?
i've see in a forum a people have the same probleme than me

tight ingot
#

You're using the wrong ip.

#

You need to start the machine on task 2.

summer flame
#

Hi, I'm trying out to answer task3 of linuxfundpart3 / my trouble is that the attackbox logs me as root and there is no tryhackme user. I terminated all the machines I could have open before, logged out the website, loggedin again, and start the machine from task2 of linuxfundpart3 (as a solution given by Scrubz above) So, I saw the IP changed from before. But the new machine, with the new ip, still has the same trouble... could someone please help ? thanks

summer flame
tight ingot
#

Do you ssh in to it?

Can you verify and share screenshots?

#

!docs verify

rain berryBOT
summer flame
somber currentBOT
#

Gave +1 Rep to @tight ingot

potent vine
#

im doing packets and frames on network fundamentals and i cant understand this piece of info, if anyone could someone help me understand this if possible cause im abit lost on it

jovial palm
limpid oak
#

Hello. I am at Linux Fundamentals Part 3 and on Task4. While I run the the python3 webserver I can't execute the wget command. I have tried using the & command. I have tried open 2 different terminals., one that is running the webserver and the other that is running the wget command(which gives me 404 error). I have tried run the command under the web servers without prompt(which doesn't make any sense ofc).

thin yoke
# potent vine im doing packets and frames on network fundamentals and i cant understand this p...

Every packet has a sequence number so the computer knows the correct order of packets to construct the file/img/page etc properly. In the handshake phase it establishes that number. When it starts to send data it uses that number and every time it increase it . Actually in handshake phase syn/ack it should increase the ins +1 and in the last ack should increase 5000+1 ( probably it is a miss type from tryhackme) . Hope that helps ! Also dont forget google has lots of content about these.

dense orchid
#

Hello, I'm studying network fundamentals. Reading about packet and frames, in task 2, the article seems to confuse the TCP/IP model and the TCP protocol itself. Please correct me if I'm wrong, but what I understand is that the model is one thing and the protocols are another even though they have very similar names. If that's the case, I think there's room to go into more detail about the differences.

brave cobalt
dense orchid
#

[edited]
From the article (https://tryhackme.com/room/packetsframes, task 2):

TCP (or Transmission Control Protocol for short) is another one of these rules used in networking.

This protocol is very similar to the OSI model that we have previously discussed in room three of this module so far. The TCP/IP protocol consists of four layers and is arguably just a summarised version of the OSI model. These layers are:
Application
Transport
Internet
Network Interface

Very similar to how the OSI model works, information is added to each layer of the TCP model as the piece of data (or packet) traverses it. As you may recall, this process is known as encapsulation - where the reverse of this process is decapsulation.

One defining feature of TCP is that it is connection-based, which means that TCP must establish a connection between both a client and a device acting as a server before data is sent.
[...]"

Paragraph two, list and paragraph three are describing the protocol suite, while paragraphs surrounding it and the article main motive it to introduce the TCP protocol.

I thought this could lead to confusions without prior knowledge because their differences are not contrasted enough. Supplementing materials for the most part make sure to distinguish these.

tired hearth
# hollow idol Anyone can help me out here with the Windows Fundamentals Part 2 ? i just don't ...

Thanks, this helped me! Just wanted to add some non-answer help, for those looking to understand the answer a bit better, for whatever reason, I didnt really understand what was being asked for question 1, and got a bit intimidated by 3. 😅

To find the answer for question 1, go to service tab under system configuration, then look at the manufacturer column, this is where the answer will come from. You can either scroll until you file "system internals" or you can sort them until you see the answer.
For question 3, think back to previous room, windows 1, what system folders were talked about that were critical to funciton of machine? now, what program do we want to execute? so the first part is that directory and file, the second part is much more straight forward, what are we trying to do, and on what system?

topaz owl
#

What is the flag that you obtain by followin along For practical example of defense security

#

I’m stuck in that question I thought the answer was red

plain gull
brave cobalt
#

You can use resources outside of THM for the time being. Most of these are available in the Internet, but not in a gamified format. Still, it will be useful. Also, if you can wait it out or make use of the free path for now, THM usually offers a discount or promo around end of Novemeber or early December (during their Advent of Cyber event).

somber currentBOT
#

Gave +1 Rep to @brave cobalt

brave cobalt
#

There's also a free path.. let me look for it..

#

This can keep you pre-occupied until the promo becomes available.

somber currentBOT
#

Gave +1 Rep to @brave cobalt

ruby ocean
#

Hello…
New to this board. But hopefully I can provide some valuable feedback. If you’re interested in continuing without “losing out” you can use skillsforall and they have a free Cisco basic networking course. You can jump into the OSI model section if you feel you have a good grasp on the previous modules. In addition, if you want to reinforce this, because I personally found the Cisco course slightly confusing, you can watch networking vids on YouTube from “practical networking” channel. IMO these should be enough to cover the same stuff and more as the THM modules.

somber currentBOT
#

Gave +1 Rep to @ruby ocean

ruby ocean
#

Don’t sweat it. It happens to the best of us. TBH I finished the Cisco course but didn’t really understand the OSI and TCP/IP concepts either. But once you see the visuals and also use the packet tracer labs. It’ll start to click better.

full thicket
#

hello, any tips on installing kerbrute

plain gull
tropic needle
#

Just wondering if anyone could tell me when to use a php reverse shell. What is a indicator when say using nmap or look at a website that someone would understand they need to use a php reverse shell when uploading a file

potent wedge
#

then again php is still the most common backend for websites so knowing how to exploit it is good as in most instances it is what is being used

tropic needle
potent wedge
#

yuups

#

and if it does nothing it is probably another way in

tropic needle
somber currentBOT
#

Gave +1 Rep to @potent wedge

young lakeBOT
#

Done!

pine shadow
#

for some reason the root.service file doesn't work... we are supposed to put the machine for the kali vm ip in htere right?

pine shadow
#

i got it to work... it was the priv esc room in the vulnuniversity

timid wolf
#

Finished 🎉🏁

timid wolf
lyric chasm
#

can someone help me

warped wind
#

You probably also shouldn't spam across multiple channels

#

Ah, looking at this further you are not asking for actual help... ah well

tawdry lion
#

yo guys is someone online i have a question

brave cobalt
meager beacon
#

I can access tryhackme with android. But in room Linux fundamental, I can't access my keyboard in virtual machine, I can't type any command.

analog badge
#

anyone have issue where when the split screen is a cmd there are no controls above the cmd screen? for instance what is networking/ task4/ view site, there should be controls above the cmd

meager beacon
brave cobalt
#

If I remember it correctly, you only need to run some commands in Split View screen

analog badge
somber currentBOT
#

Gave +1 Rep to @brave cobalt

brave cobalt
#

Is your browser up to date?

meager beacon
#

Ok, now my browser is updated.

meager beacon
somber currentBOT
#

Gave +1 Rep to @brave cobalt

ruby ocean
#

Hey yall. Quick question as I work my way through this pathway. But I’ve been wanting to ask how many of you successful learners are able to retain all this info. Do you all take notes? If so, how would you recommend this being done? Or do you just spend countless hours on thm and this help with retention?😅
Thank you in advance

warped wind
#

Taking notes and practicing what you learned are good ways to retain information or in the case of the notes you can reference it later even if you have since forgotten it. Notion and Obsidian are two popular note taking apps and as for how to take notes just do whatever you want, there is no given right way, if it works for you then it is your right way

ruby ocean
unborn pewter
#

Pen and paper 👍

west ether
#

What are good paths to do after this one

brave cobalt
unborn pewter
somber currentBOT
#

Gave +1 Rep to @brave cobalt

west ether
#

I do not understand crontabs at all, can someone help me

#

I posted in #room-help but I’ve hardly gotten any help

#

Trying to find the crontabs and find when they will run

ruby ocean
ruby ocean
west ether
#

I did that but I have no idea what to do with it

ruby ocean
#

Could you elaborate a little more on what you’re trying to do?

ruby ocean
west ether
#

“When will the crontab on the deployed instance run?”

west ether
ruby ocean
#

The asterisk value would correlate to everytime at boot. And the 12 would correct to every day at 12…

#

So everytime at book and at 12.. the system would perform the backup

west ether
#

Ok I somewhat get it now

ruby ocean
#

I encourage you to play around with it so you can better understand. It’s a little difficult to explain it. It’s one of those things you gotta play around with.

#

For example. Schedule a cronjob for 2 min later. Something easy like echo hello to a new file

#

Cronjobs are confusing and are one of those things you have to play around with to better grasp it. I didn’t want to give you answer as I thought it might not “help”. But it was at “@reboot”

west ether
#

Yeah I found that line several times I just didn’t get it

ruby ocean
#

Once you play around with it you’ll get a better idea of how it works. I was surprised at how confusing reading about it can seem. Hope this helped.

west ether
#

It did, thanks

west ether
#

just finished this path, gonna finish up intro to cyber sec and then do jr pentesting

unborn pewter
west ether
#

the linux section is fun

granite niche
#

Is the question Task 8 for Windows Fundamentals 3 still correct with the documentation? I'm quite certain I have the answer but it's not accepted and the asterisks are formatted differently as well. I don't want to spoil the answer lol

granite niche
#

The bitlocker task

#

I found the actual answer now, it isn't mentioned in that way in the documentation, not sure if that is what you're going for or that the Windows docs have changed

unborn pewter
outer field
#

One message removed from a suspended account.

#

One message removed from a suspended account.

unborn pewter
#

Write down your notes! 🙂

unborn pewter
#

Windows fundamentals.... i forgot how boring Windows actually is 😅

rugged ferry
#

Are you guys studying at Conestoga?

real zealot
#

hello

#

good day

#

I am doing the Pre-Security learning path

#

i'm on the first windows room but the VM machine won't connect

#

it keeps reconnecting

brave cobalt
#

You'll need to type /verify token <discord token found in your THM profile>.

real zealot
somber currentBOT
#

Gave +1 Rep to @brave cobalt

real zealot
real zealot
brave cobalt
#

Let me try and spin up that VM

real zealot
#

thank you

#

apparently all the windows vm are not loading for me

#

I tried the other 2 rooms as well, same thing

#

would it be a browser issue? I'm using chrome

brave cobalt
real zealot
#

mmmmm

brave cobalt
real zealot
#

which browser did you use?

#

if thats okay to share

brave cobalt
#

I'm using Firefox, but it seems to be a network connection from your end. To which VPN server are you connected to?

real zealot
#

i use nord. but even after disconnecting and trying it still doesn't work

#

also, i was using the VM, not the RDP

brave cobalt
real zealot
#

okay

#

retrying without plus with different browser

#

i think something is wrong with my computer. same issue

#

the linux boxes run fine, just the windows

brave cobalt
real zealot
#

Also restarted and the same issue. Also with a different browser

real zealot
#

so its definitely my computer, I used my phone which is also on vpn and it worked

#

so need to find out why my computer not allowing it

rose plank
#

yes

#

can you please tell what exactly i need to do for verifying myself 😅

#

@brave cobalt

trail plaza
#

Hi, is anyone else having issues with the VPN connection to tryhackme being very slow?

real zealot
rain karma
#

Is this room outdated?

#

currently logged in as root and it doesnt accept root as an answer

tight ingot
#

Nope, your answer is wrong.

You're in the wrong machine, did you deploy the machine on Task 1? 🙂

rain karma
#

upon checking theres only one machine for this room

tight ingot
#

Linux fundamental 1?

rain karma
#

@tight ingot hey you again, hello there

rain karma
tight ingot
#

Can you send a me a screwnshot of the row at the bottom of the attackbox?

rain karma
#

hold on

tight ingot
#

Can you click where it says "linuxfundem"

rain karma
#

oh my!

#

there you go, thanks @tight ingot creepypog

somber currentBOT
#

Gave +1 Rep to @tight ingot

tight ingot
rain karma
waxen charm
#

hello guys, first message on the discord for me, started out recently. did anyone beat the osi model split screen game in under 19 seconds ? "(Can you beat our staff high score of 19 seconds?)" personally got 22s seconds on the second try, might be something im missing, seemed like i was moving instantly...

tight ingot
#

Attempt number 3.

#

Last attempt 🙂 @waxen charm

waxen charm
#

oh wow

#

guess it's doable 😄

#

thanks

rain karma
#

How do I fix the already running instance of my attackbox. I cant deploy a new one. I already terminated it but still cant deploy a new one.

brave cobalt
rain karma
#

Why is it asking me to connect to myself? 10.10.84.81 is myself so why is it asking me to get a file on myself?

#

it says ensure that you are connected to the deployed instance 10.10.84.81 which is the (attackbox myself) and get some files on it? Get some files on myself?

#

Start the webserver of my own attackbox? Why? To get files on my self? I would understand if its asking me to start a webserver of a remote machine instead.

brave cobalt
#

How are you connecting to THM - via VM or Attackbox?

rain karma
#

10.10.84.81 is my attackbox

brave cobalt
brave cobalt
#

aaah.. that is not the Attackbox, but the target VM for the room.

rain karma
brave cobalt
#

You will have to use the Attackbox (by clicking on the blue Start Attackbox button that you can find on the top portion of your screen). You will then use it to connect to your target (after starting the HTTPServer module).

brave cobalt
#

Can you click on the Start Attackbox to see where it will re-direct you?

brave cobalt
rain karma
#

ahh I see it now

brave cobalt
#

That's it then.

rain karma
#

this is my own IP in which where I need to dump the files with

rain karma
somber currentBOT
#

Gave +1 Rep to @brave cobalt

brave cobalt
#

Glad I could help.

rain karma
#

could I start sending commands now or should I wait for it to finish serving? @brave cobalt

#

its not responding at all

brave cobalt
#

It only means it is now serving the file and can be fetched from the Attackbox via curl or wget

brave cobalt
brave cobalt
rain karma
#

there is no flag.txt on home dir of tryhackme attackbox

#

ah there is but its a hidden file

brave cobalt
#

And then type cd ~ to return to the tryhackme user's home directory

rain karma
#

okay hold on

brave cobalt
#

And then type ls -la to list all files in the current directory

rain karma
#

i need to be on the home directory of tryhackme and then run the httpserver right?

#

ahhhh

#

okay it should be not on /home dir

#

thats why it cant retrieve the file

#

hold on let me try

#

ah finally

#

thanks again @brave cobalt !

somber currentBOT
#

Gave +1 Rep to @brave cobalt

brave cobalt
rain karma
#

how do I determine if a process is "out of ordinary?" What is the indicator that it is an unusual process?

#

Also how do I view the flag of a process? Can I just cat command on a process?

brave cobalt
#

I vaguely remember this question as it is very tricky to answer if you have no idea. However, I would suggest to check the processes run by root.

rain karma
somber currentBOT
#

Gave +1 Rep to @brave cobalt

rain karma
#

@brave cobalt how do I output the flag out of a certain process?

#

@brave cobalt found it. I forgor to connect to the target attackbox kekwsanta

dry nest
#

Windows Fundamentals 2 > task 7:
For the ipconfig command, how do you show detailed information?

why does the answer has to be in capital letters? if you're looking it up with ipconfig /? you will see lowercase, only in the refered link the capital letters are used

tight ingot
#

There's a command you can use that Will display all inform

#

Informa

shrewd island
#

Yea there is a specific option you can use for more detailed ipconfig response 🙂

limber flintBOT
earnest crescent
potent wedge
earnest crescent
#

i want some guidence i am confused which path to follow

potent wedge
earnest crescent
potent wedge
#

yes ello ello shadow is shadow a person that refers to themselves in third person

earnest crescent
# potent wedge well shadows list there is going in the order shadow recommends to follow the pa...

If you want shadows recommendations it is in this order
⁠pre-security-pathway 
⁠introduction-to-cyber-security-… 
⁠junior-pentester-path 
⁠complete-beginner-path (optional)
⁠pentest-plus-path (optional)
⁠web-fundamentals-path 
⁠soc-level-1-path 
⁠offensive-pentesting-path 
⁠red-teaming-path 
⁠cyber-defense-path
[02:10]
the optional ones are optional due to not teaching a lot of new concepts if you do the previous paths but are still worth looking into have you updated the sequence of this path?

#

have you updated the sequence of this path?

earnest crescent
#

can you send the updated ones

#

as for now you are working professional or student

potent wedge
earnest crescent
potent wedge
earnest crescent
#

ok

potent wedge
#

if you wanna post pictures use the /verify token command

rose sable
#

I just started the advent of cyber as a beginner in this field and i hope it's very beginner friendly

gleaming idol
#

I set up the server using python3 -m http.server

#

Then I opened another terminal and I'm using wget http://ip:8000/.flag.txt and i'm connecting fine but it's saying that the file isn't found

#

any advice?

#

Nvm figured it out

#

So the issue was that i wasn't doing python3 -m http.server from the proper location. So when i connected, there was nothing to find

somber currentBOT
#

Gave +1 Rep to @potent wedge

potent wedge
#

no problem

timid oak
#

Hello everyone I'm new here fell free to talk with me.

misty drum
#

my pc help

twin hatch
#

Anybody doing advent of cyber 23 ...
I'm stuck in task day 10(yesterday)
While doing code execution I can get connected with http server... Tried my kali machine but no ... Even on attackbox....
Did follow the video also carefully.... please help anyone

brave cobalt
twin hatch
twin hatch
#

In attackbox

twin hatch
#

In attackbox

lost matrix
twin hatch
brave cobalt
twin hatch
brave cobalt
lost matrix
twin hatch
# brave cobalt

U know I gota split screen there and there isn't this option

twin hatch
#

It's working properly for a long time

lost matrix
# twin hatch Brave

Yeah, some users have reported Brave issues as well. I'd recommend to try it with Chrome or Firefox.

elder ravine
#

what brave works perfectly for me

#

jsut make sure to update it

marsh veldt
#

@twin hatch You can try by using crtl+insert & shift+insert for copy/paste respectively

marsh veldt
twin hatch
marsh veldt
#

Double right click on the uppermost icon and try to reach for preference

marsh veldt
twin hatch
edgy summit
#

Hello

rain karma
#

What does this even mean? The name of the service? The way it asks the question is quite confusing..

rain karma
ruby ocean
rain karma
#

Just pointing things out so that it can be eventually improve

ruby ocean
rain karma
fluid hill
#

pls helllp, linux fundamental part 3, for processes 101 it asked me to Locate the process that is running on the deployed instance (......). What flag is given? I ran the exact same code, but there is no flag after the command ps aux at all, I also did ps aux >> a and grep 'THM' a but there is still no flag....

potent wedge
#

if the later of course it will not find anything

potent wedge
#

ps aux | grep -i thm should probably work then

fluid hill
#

lemme try once again and i'll report if this time the flag occurs

potent wedge
#

the -i will help for no case senstivity

fluid hill
#

yeah, today it worked. I also tried the exact same thing from yesterday, and it also worked. I don't know if it was yesterday's target machine's problem, i was quite frustrated lol.

indigo sequoia
#

Hey hello hi, so I finished the intro to cybersec pathway and I'm about to finish the presecurity pathway(the free ones) and, I think "complete beginner" is the next pathway because it has those 2 as prerequisites, I was wondering if not doing the premium modules in the previous paths would have a heavy effect on me doing that pathway, and if there were any other alternatives I could find and do them

pliant dove
#

mostly you will need to go back to the prerequisites modules and have a look at them, but sometimes you dont even need it. Its enough just to look on google how to do this and that. if youre beginner, I suggest you to do them all of course. good luck !

cloud kestrel
#

Hi just Started out and wanted to know what would be the best Strategy to start.
a) do all the Info Modules, then progress to the easy ones, the Medium ones and so on or
b) follow the Pathways in a similar fashion

agile idol
indigo sequoia
somber currentBOT
#

Gave +1 Rep to @pliant dove

cloud kestrel
somber currentBOT
#

Gave +1 Rep to @agile idol

agile idol
#

I'll do jr pentest next

summer oracle
#

A very beginner question.
I'm going through network topologies and roles of switch/hub/repeater.

is the diff between switch and a hub can be looked as:
switch = star topology, thus no bottleneck?
hub = bus topology, thus more prone to "traffic jam"?

brave cobalt
summer oracle
somber currentBOT
#

Gave +1 Rep to @brave cobalt

brave cobalt
#

Glad I could help.

dusky ferry
#

hey

twin hatch
#

@dusky ferry hy

twin brook
#

Please can someone help me with how to solve the second hackme problems

brave cobalt
cloud kestrel
#

Hi. I'm having some trouble with the "Learn the Linux Fundamentals Part 3" room. The fourth Task requires you to deploy a Webserver on the Attack Machine and to download a file. As soon as i run the Command to deploy the Server i am unable to run further commands until i use Ctrl + C to stop the server. I am sure i am missing something but i cant find a solution in the room

tidal grove
#

@cloud kestrel You need to deploy the webserver on the machine you wish to download from, then use wget on the machine you wish to download to. You'll want to use two different terminals for that.

cloud kestrel
#

Thank you very much. It's very logical in hindsight. Appreciate the Help :) Merry Christmas btw

tidal grove
#

@cloud kestrel You're very welcome. Merry Christmas to you.

crude prawn
#

hi

dusky galleon
tidal grove
dusky galleon
#

But the attackbox has a very limited timing of an hour for free subscribers like myself.

tight ingot
#

It's on the same network

#

Take screenshots and let's see your error.

dusky galleon
#

It's been resolved. I'm using the OVPN

cloud kestrel
#

Hello. Me again. I've run into another Problem with the "Learn the Linux Fundamentals Part 3" room. The sixth Task wants to know when the crontab on the deployed Instance will run. I figured out the answer(the First day of every Week at 5 am) but i can't, for the life of me figure out how to answer the question. It shows that the Answer is a seven letter Word but i don't know what it could be. The hint also doesn't help in that regard.

slate fractal
cloud kestrel
#

Oh right. completely forgot about that. Thank you so much :)

shut python
#

TCP seems like the agent at passport control. Confirming all your paperwork and visas are in order before letting you proceed. Which can be time consuming. And UDP seems like a catapult firing some data over a wall.

covert wedge
#

Hey, guys, can you please help me out here

Here is the link to the room
https://tryhackme.com/room/windowsfundamentals1xbx

The last question in the task 6, why the provided answer is correct, I can see on my windows VM machine that there is no tick next to account is disabled...

crimson fable
#

Hi guys ! I hope y'all are doing good

#

Can someone help please ?!! Out of all the tasks and rooms, I couldn't have imagined Being stuck with that one

#

The Last question of task 3 in the windows fundamental 1' room

hexed pewter
#

I feel like if I click that I'd get hacked

storm fiber
#

pre security contains some premium rooms ! couldn't i can learn them in fre ??

warped wind
undone bone
#

Hey guys, I was wondering if there's an online quiz I could take to make sure I have a good grasp of the pre-security material 🙂

twin hatch
brave cobalt
#

You can always go back to it anyway.

fallen sundial
tight ingot
fallen sundial
#

oh ok

#

now i am on network basics like packet and frames how should i learn it like there is alot to read,Should I clear my concept or learn it all?

brave cobalt
half chasm
#

Hola alguien me puede ayudar
[20:53]
plis estoy en la parte de Conceptos bases de windows , y no entiendo 2 preguntas

distant mauve
warped wind
#

Handwritten notes are certainly better for memeorization. Digital notes are great for searchability as well as the ability to embed screenshots, links, code snippets, etc into them though. A combination of both can work quite nicely at times. Personally I tend to be all digital nowadays, but back when I started out and was studying for network+ and security+ I found handwritten stuff quite helpful.

distant mauve
warped wind
# distant mauve would you say doing both the whole way is worth the time investment for learning...

Would be a major time investment to do it both ways for everything, not sure if it would be worth it. If you like handwritten right now then I think just doing that as you have been to start out with is nice. Once you feel more comfortable with things and are looking to build up a whole database of notes (as most people tend to do) then I would move to digital and maybe at that point you would put a briefer version of your handwritten notes in some digital application. Still though I cannot overstate the usefulness of having a massive searchable database of notes comprised of courses, syntax, tools, methodology, practice boxes that you have hacked, etc.

distant mauve
warped wind
#

I am using notion right now, which does have an application but I just use the website myself. I like notion because it is cloud synced, but there are tons of other options as well, Obsidian probably being the most popular choice.

#

Cherrytree which you said you had been using isn't a bad choice either, but just use whatever you like

distant mauve
somber currentBOT
#

Gave +1 Rep to @warped wind

quaint edge
sly spear
# distant mauve Thank you for the input, I marked them down for future reference.

In my opinion, hand written notes is probably ideal to start with, especially if your used to it. Generally hand written notes are better for memory recall as it requires more thought and motor function to write.

Transitioning to or noting some things digitally would work as well though, for example having digital notes of common protocols, port numbers of even things like class full IP architecture etc for quick search reference would be helpful.

Additionally you can look at items like remarkable if you wanted which is a digital hand writing tool. I haven't personally tried them but I know some people who swear by them.

#

Obsidian that Hiro mentioned I quite like, I find the feature set to be good.

distant mauve
sly spear
distant mauve
sly spear
#

👍

last ocean
#

Hello, I want to ask about the foregrounding and backgrounding because when I'm trying to write the commands as it was shown in the task it doesn't work.
What should I do?
Any help?

fathom vale
last ocean
#

@fathom vale
I'm doing this to background a command :

echo hello &

and then when I'm writing the command " fg " nothing appears in the foreground.

#

@fathom vale
And when I'm writing ctrl+Z , the command is not repeated

fathom vale
# last ocean <@1093437416578220062> And when I'm writing ctrl+Z , the command is not repeate...

It is normal that the command is not repeated when you press the keys ctrl+Z.
In the context of the Processes 101 task, there was a loop going on and printing over and over again the words: "This will keep looping until I stop it !". This was a script written prior. In the middle of the execution of this script, you want to free up your terminal and put this loop in pause, in the background. To do that, you can press the keys ctrl+Z. ctrl+Z does not repeat a command, it puts an executing process (here, the loop) in the background.

last ocean
#

@fathom vale
I got you

fathom vale
# last ocean <@1093437416578220062> I'm doing this to background a command : echo hello & ...

I just tried on two different machines. This is what I got when I use the command echo hello &

root@ip-10-10-255-85:~# echo "hello" &
[1] 2776
root@ip-10-10-255-85:~# hello
user@machine:~$ echo "hello" &
[1] 57618
hello
user@machine:~$             

So you can see none of these behaviours look like the typical "put this in the background, we will take it out later". I used fg on both machines afterwards and both processes were already done. The thing is, echo "hello" is such a simple and fast process, that it finishes even before the prompt returns. To try backgrounding and foregrounding with a command that takes longer, try using sleep 10 &.

last ocean
#

@fathom vale
What does the command "sleep" do

#

@fathom vale
When I wrote the commands I have the same results that you got but when I press fg command nothing appears that's because the echo is very simple and to quickly to be done

#

Right?

#

@fathom vale
Should I write the " sleep " command before or after the " fg " command

fathom vale
#

Like this: man <command_name>

#

Here is your answer : sleep - sleep for a specified number of seconds

fathom vale
fathom vale
#

What would happen if you use fg before having any process in the background ?

last ocean
somber currentBOT
#

Gave +1 Rep to @fathom vale (current: #1297 - 2)

fathom vale
last ocean
fathom vale
#

I tried and it gave this indeed

#

bash: fg: current: no such job

last ocean
sly spear
#

Is there a natural progression of pathways on tryhackem

#

For example where would one go once finishing pre security

#

And how does complete beginner differ to pre security

brave cobalt
brave cobalt
sly spear
#

Thanks for the information

#

I shall follow that recommendation 👍

quiet arch
#

In Linux fundamental 1 they said we can use grep to search entire content however when i tried to search content with machine ip it didnt search anything. Then i put THM instead of machine ip it searched. Qs is how we can search through grep in cfts in real life then?

brave cobalt
sly spear
#

So on Linux fundamental part 3 task 4 I am trying to run python3 -m http.server and then download the flag but for some reason it doesn't seem to work as displayed in the screenshots so I can't download the file via wget http://10.10.10.83:8000/.flag.txt

warped wind
sly spear
#

So from attackbox ssh'd onto the active machine, then ran it from there

#

ie just followed the information in the task as it is written

warped wind
#

Yeah so you run the http server from there, but then you run the wget command from the attackbox itself and not the SSH session. Is this what you are doing?

sly spear
#

Well i didn't get to the part where I run wget as when i do python3 -m http.server I get no feedback to say that the command has run, which I think I am meant to, at least it shows as much in the task screenshots

warped wind
#

Can you share a screenshot? The command isn't really supposed to give much in terms of output until you wget it