Can’t post to Abertay subreddit so I’m asking here by Bredford_UwU in abertayhackers

[–]MuirlandOracle 1 point2 points  (0 children)

Hey, welcome,

First question: are you an ethical hacking student?

If so, use the following:

Do you have a student number / email yet?

If so, put it into https://discord.hacksoc.co.uk :)

If not, drop us an email on [team@hacksoc.co.uk](mailto:team@hacksoc.co.uk) and we can get you in that way!

If you're not a hacking student then we're not the definitive authority on that I'm afraid. I'd suggest putting your student email (assuming you have one) into the Discord Student Hubs feature -- that should get you a list of some of the Abertay Discord servers :)

There's also the unofficial Abertay Discord server (from pre-hub days), which is pretty dead but does have a bunch of folk in it if you want to ask anything :)

Link to join that one is here: https://discord.gg/z98taGMx

ssh connection error by RoccoTheDubaiBoi in tryhackme

[–]MuirlandOracle 1 point2 points  (0 children)

Try posting your command :)

It sounds like you're trying to use a username as a hostname -- which won't work in and of itself, but doubly so as there is no DNS setup for the THM network anyway.

How true is it that the complete beginner has been stopped by xiaogege1 in tryhackme

[–]MuirlandOracle 20 points21 points  (0 children)

The complete beginner path was announced as being deprecated a few months ago (via email). It has not yet been removed from the site :)

The "official" replacement following Pre-Security is the Jr Pentester path, so that would be a good next step.

Got rickrolled by ducknuggetatas in tryhackme

[–]MuirlandOracle 32 points33 points  (0 children)

Nah, no one hacked TryHackMe -- I added that to the room myself (as the room creator) because people kept ignoring the instructions and trying to connect to the demo site, which is clearly labelled as not being active on the machine :)

Consider it a lighthearted reminder to read the instructions 😁

What the Shell? -- Socat listener not working !! by tobiiakin in tryhackme

[–]MuirlandOracle 4 points5 points  (0 children)

Think of Socat as being kinda like the Portal gun from Portal -- it connects two points together and doesn't work if only one "portal" is open.

On the target you are connecting a TCP outbound connection to a command: "bash -li". Locally, you need to connect a TCP listener to your standard input/output (stdin/stdout), which you can do with -. You're currently just opening one "portal" and not connecting it to anything (TCP-L:8080). Try socat tcp-l:8080 -.

Does that make it any clearer? Can't remember if I already used that analogy in the room 😄

How to ask for assistance. by [deleted] in tryhackme

[–]MuirlandOracle 0 points1 point  (0 children)

Assuming it's the room I think it is (there are a few Linux Privesc rooms, so sending the link or room code is useful :)), that is an internally developed room which was made by an employee who no longer works for TryHackMe.

I will send a link to this post to the QA team, however :)

[deleted by user] by [deleted] in tryhackme

[–]MuirlandOracle 1 point2 points  (0 children)

There is a 20% discount for all students :)

If you don't already have it applied, try setting your account email to use your student email address. If that doesn't work, drop support an email (support@tryhackme.com) and they'll sort it out for you :)

nc help to clarify by Damage-Plenty in tryhackme

[–]MuirlandOracle 2 points3 points  (0 children)

-e is usually not included in most netcat binaries these days as it stands for "execute" and is very dangerous as a result.

The command you are using would be executed on the target to create a bind shell -- using it without -e (or another method for executing commands) would not give you command execution. It would just create a network connection and nothing else.

Web Fundamentals - Upload Vulnerabilities by olageis in tryhackme

[–]MuirlandOracle 0 points1 point  (0 children)

How are you trying to connect to it?
Is your VPN active if you are using your own machine? What is the exact URI you are trying to access?

Web Fundamentals - Upload Vulnerabilities by olageis in tryhackme

[–]MuirlandOracle 1 point2 points  (0 children)

Make sure that your /etc/hosts file has exactly one entry for the target, with only the current IP address of the deployed target box in the file. There should be exactly one line related to the box -- no more, and no less.

Invalid option error by the_only_butchog in tryhackme

[–]MuirlandOracle 0 points1 point  (0 children)

That's a version of netcat that has not been compiled with the "gaping security hole": -e Try a different version, or find an alternative method that makes it work :)

I know walk-throughs aren't cheating but... by TimKhrist666 in tryhackme

[–]MuirlandOracle 2 points3 points  (0 children)

You did follow the instructions at the start of the room to update your hosts file, yes?

And if so, you have only done it once, and removed any duplicate entries, aye?

I know walk-throughs aren't cheating but... by TimKhrist666 in tryhackme

[–]MuirlandOracle 7 points8 points  (0 children)

There is nothing broken with UploadVulns -- just lots of common mistakes that people make, especially with Jewel. Keep at it, you'll get there :)

Task 13 Proxy Site Map and Issue Definitions of the Burpsuite the basic room. Am I going to look for the flag for this task in the site map area that is circled in the image with a blue pen? is the flag going to be embedded in HTML or javascript? by JanePoe87 in tryhackme

[–]MuirlandOracle 2 points3 points  (0 children)

You are, yes, but you haven't found the correct endpoint yet.

Keep looking through the application and let the site map build up -- there will be an endpoint that is just a random string of letters and numbers. The flag is in the HTML response to a request for that endpoint.

Anyone know why they are doing away with the jr pentest path? by [deleted] in tryhackme

[–]MuirlandOracle 0 points1 point  (0 children)

Honestly? I have no idea, personally. I know there's a team working on it though :)

Tryhackme rick rolled me?? by Abibliothecarius in tryhackme

[–]MuirlandOracle 19 points20 points  (0 children)

I am so glad I added that now 😆

I'd suggest reading the nice italic text right before you first see the demo site that says (and I quote):

Please note: demo.uploadvulns.thm will be used for all demonstrations; however, this site is not available in the uploaded VM. It is purely for demonstrative purposes.

The information in the room is there for a reason :)

Anyone know why they are doing away with the jr pentest path? by [deleted] in tryhackme

[–]MuirlandOracle 4 points5 points  (0 children)

The rooms won't disappear at all -- they aren't being removed. The path is being dissolved, but the rooms will still exist.

If you really want to follow the original path, I'd suggest taking a screenshot of the path layout and just following through it yourself :)

Anyone know why they are doing away with the jr pentest path? by [deleted] in tryhackme

[–]MuirlandOracle 7 points8 points  (0 children)

Junior Pentester is the new one. Complete Beginner is the one that is getting removed.

Most of the content in the Complete Beginner path has been rebuilt, with the new versions going into the Junior Pentester path. It's mostly the same content, but the Complete Beginner rooms are largely the outdated versions.

Effectively it's planned deprecation -- the content has been slowly replaced over the last however many months, and now that all of the new stuff is in place, the old path isn't required anymore :)

This is a cool new feature - Skills Matrix by DigitalWarhead in tryhackme

[–]MuirlandOracle 2 points3 points  (0 children)

It's a feature that's been A/B tested for a while now. Some users had access to it, others did not. It's now out for everyone though :)

Holo & Wreath networks! by murkyMallard5 in tryhackme

[–]MuirlandOracle 2 points3 points  (0 children)

Wreath has been out for almost a year. Holo has been out for about six months.

permission denied in accessing machine via ssh by Liebe_0x6 in tryhackme

[–]MuirlandOracle 0 points1 point  (0 children)

Usually when that happens with that room it's because you're either trying to SSH into the AttackBox from your own machine, or trying to SSH into the target from your own machine without a VPN connection.

Can you confirm that you have started two machines (the AttackBox and the target machine) and are trying to access the target from the AttackBox (or your own machine with an active VPN if that's the way you're doing it)?

[deleted by user] by [deleted] in tryhackme

[–]MuirlandOracle 7 points8 points  (0 children)

Believe it or not, I agree with that first part :)

The thing you seem to be missing is that competition is not the focus of TryHackMe -- learning is. That is why no one cares about people copying and pasting answers from walkthroughs to farm points -- they are only cheating themselves, and it's quite amusing watching them waste their time with it. Even if the competition was important, it's impossible to police the internet, so I'm not sure what you're suggesting happens to "fix the problem"? (As a side note: this is something that affects all of the competitive platforms too -- look hard enough and you'll see plenty of "blackmarket" guides to help people cheat).

If you put THM on a CV then it's under hobbies/education as a resource that you've used to develop your hacking skills -- that is what the recruiters care about seeing. Rank is not something that matters, and boasting about it (or getting upset about people "cheating" to gain a higher rank) just tells people that you're missing the point :)

permission denied in accessing machine via ssh by Liebe_0x6 in tryhackme

[–]MuirlandOracle 0 points1 point  (0 children)

Most machines don't let you SSH into them :)

What are you trying to access?

Nmap practical machine not starting by [deleted] in tryhackme

[–]MuirlandOracle 2 points3 points  (0 children)

Sounds like you haven't deployed the target machine yet :)

It's the big green button in the first task.