#pt1

1 messages ยท Page 4 of 1

thin kraken
#

imho, no.

copper cove
#

what else should I cover first?

thin kraken
copper cove
#

and i think there were some others that got removed

thin kraken
#

i found a really neat list the other day. hang on

copper cove
#

like an entire portion of the exam is AD and I don't see anything for AD in the prep materials except maybe this one

thin kraken
#

Web: Pickle Rick, Billing, Rabbit Store, Silver Platter, AVenger
Network: Blue, Net Sec Challenge, Stealth, Loopback, Linux LPE, Windows LPE
AD: Reset, Ledger, K2, AD: Authenticated Enumeration

Those rooms. Apparently. (I did those, and that still wasn't enough) .

copper cove
#

thanks!

copper cove
#

the exam is not proctored right?

#

how long did it take yall, the full 48 hrs?

copper cove
#

like can we consult thm curriculum during the exam

thin kraken
thin kraken
copper cove
thin kraken
#

eh. PT1 isn't my vibe.

#

The pentesting stuff i'm good at isn't represented in PT1.

#

binary RE, AWS / Azure compromises, etc.

copper cove
#

i'm dissapointed there's no linux section

thin kraken
#

there's linux challenges

#

ish.

#

but there's definitely, imho, a heavy windows bias.

#

also another thing that annoyed me tbh.

#

I'm of the age/experience/belief that windows is basically shite.

#

and not suitable for a server or desktop in a corporate/hosting/enterprise environment.

#

esp now that microsoft have linux toolchains for .net applications

copper cove
#

everything is unnecessarily more complicated than on linux

thin kraken
#

I've had jobs where the whole basis has been "get us the F off of windows because the license costs are killing us"

#

and it's acceptable to replace their AD with a RHEL box with 389 server or openldap and freeradius and replace their Panasonic PBX with Asterisk or Freeswitch, and take this company that are spending Tens of Thousands of Pounds a month on licenses for software and hardware, and switch them over to linux and unixes and stuff.

#

i worked for a while for a company who had like 600 windows desktops
to run Putty
to connect to a mainframe environment

#

That was it.. Their sole reason for having 600 licensed windowses
was to connect to something running AIX.

elder python
#

@ebon creek

vagrant lynx
#

you shld pm him, pasting the request here is the same as leaking exam.

#

you should remove it

indigo marlin
#

Passed it ๐Ÿ™ˆ

ebon creek
gritty lanternBOT
#
TryHackMe's Email

TryHackMe's support email address.

ebon creek
keen sleet
indigo marlin
hollow valley
#

me too

i get Your session has expired

The SDK token provided in this verification process has expired. Please go back and try again.

sleek maple
#

For the web app section

keen sleet
#

Please do not mention any kind of attack and we require not to discuss the exam during your exam period.

#

Everything is on the website. If you don't find what you're looking for, then maybe it's because it shouldn't be here / doesn't exist.

sleek maple
#

Sry

wheat glen
#

guys is there some kind of free practice test for pt1 or eJPTv2? id like to practice for these exams

keen sleet
#

No.

wheat glen
#

๐Ÿ˜”

grizzled torrent
# wheat glen ๐Ÿ˜”

You're given two attempts though so you can use your first attempt to get familiar with the exam env. Its just a bonus if your pass it in the first attempt

sleek maple
#

During my exam the VPN server went down and I lost a lot of hours before support saw my ticket and I was able to regain access could I have another retake or at least a discount on buying a retake I was very disappointed by the whole ordeal

vivid oak
#

Hey all! I am getting session expired during ID verification, is there any fix for this? I tried reaching out to support on the site but it seems like they may be busy. ๐Ÿ™‚

slim matrix
#

Hi, if there had faced same issue when clicked the start exam button like this
"Exam is under going maintenance, try again on an hour"

#

Well it's already 5 hour, so i can't start the exam

keen sleet
keen sleet
slim matrix
#

i had a screenshot of it, but i can't upload it here maybe from the channel settings

#

ohh my bad

#

i need verification first

lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #30 - 334)

ebon creek
slim matrix
north plank
#

Going to finally start mine tomorrow - every day keep putting it off!

vivid oak
#

If we are having an issue with the PT1 is the structured process to reach out to the support@tryhackme.com email address or is there a more timely place we can reach out to support for exam issues?

keen sleet
vivid oak
lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #30 - 335)

vivid oak
quiet ember
#

Anyone know how long the provisioning of the test should take? I have been waiting ~20 minutes:

vivid oak
quiet ember
vivid oak
vast flax
#

Can I check in today and start the exam later on?

quiet ember
# vast flax Can I check in today and start the exam later on?

Yes, it looks like you can totally do that. Once you check in it gives you a video to watch then you can start the environment. It appears that once the environment actually starts, the countdown starts. So you can checkin then leave and come back to it when you are ready.

vast flax
lime fulcrumBOT
#

Gave +1 Rep to @quiet ember (current: #2012 - 2)

vivid oak
quiet ember
#

No, I closed out, sent the email and waiting for a response

vivid oak
tall shoal
#

.

copper cove
#

does a reset in pt1 mean a penalty?

#

i hit reset thinking it wouldn't deduct anything but it said "your reset has been counted" or something similar which is ominous

ebon creek
gritty lanternBOT
coral bone
#

hello, one question... is the AD portion of the training material enought to pass the exam?

balmy canopy
#

I hope so, because I just finished the last challenge room (K2) and there was a lot to learn in K2, Ledger and AVenger, almost too much ๐Ÿ˜„

#

Probably need to go through them again before I take the exam

copper cove
#

soo who's idea was it to put partial flags in PT1 ๐Ÿ˜ญ

#

do i get half credit for half the flag

copper cove
#

annnd 90 mins later i found the other half ๐Ÿ˜ฎโ€๐Ÿ’จ

vagrant lynx
#

I didn't see this when I am doing the exam.

copper cove
vagrant lynx
#

I alway thought the partial point is that you found a vulnerability but you can exploit it but it came with no flag.

copper cove
#

WAYYY too close for comfort wow

snow radish
#

When I try to do the check in for PT1 I get this error from onfido (Your verification is expired)
Is there a way to restart the check in process?

ebon creek
ebon creek
gritty lanternBOT
#
TryHackMe's Email

TryHackMe's support email address.

vivid oak
#

Thank you for this! This was one of the best pieces of advice after I failed my first attempt. I adopted this mindset, signed up for PortSwigger academy and did a bunch of their labs. Got it on my 2nd attempt! ๐Ÿ™

lime fulcrumBOT
#

Gave +1 Rep to @safe musk (current: #32 - 324)

last plank
#

Hello everyone, I am currently preparing the exam and I would like to know if the report submitting is included in the 48h or we have a bit more time ?

copper cove
#

48hrs total

midnight sonnet
#

solving on ad-dc suddenly network cut I reset the machine still the same coolguy

copper cove
lime fulcrumBOT
#

โž• Gave the role PT1 to mr_mph

golden leaf
#

What if I don't meet this requirement? @ebon creek

ebon creek
serene nymph
#

Hello, just passed, can I get the role please?

lime fulcrumBOT
#

โž• Gave the role PT1 to flo2699

vast flax
#

It is ok to wait an hour for this?

round wagon
#

I'm experiencing the same issue.
I've been waiting for over an hour, but it still hasn't started.

I contacted support, but they are outside of business hours, so I haven't received a reply.

vast flax
#

Have you tried refreshing?

round wagon
#

Yes, I tried reloading the page and clearing the cache.
also tried it on both Chrome and Edge.โ€ฆ

vast flax
#

Returning to the previous step and forth won't get it started either

#

๐Ÿ˜ช

light token
#

There were a couple of reports earlier in the week

#

Im planning on taking days off to take the exam...this doesnt inspire that much confidence

pseudo bramble
#

when writting the summary in the reports of the exam we have to follow the summary structure that says in the reporting module? overview, results, impact, remediation?

ebon creek
midnight vale
#

Hello guys, can someone tell me I got a voucher via a giveaway from TryHackMe . Does that mean there are two attempts, or is it only one attempt?

vast flax
#

You have two attempts

midnight vale
lime fulcrumBOT
#

Gave +1 Rep to @vast flax (current: #3067 - 1)

tulip quest
#

test

#

Hmm oh I have to ask for a role

#

I passed

#

Decent exam was fun.

#

Whatever the 10th flag was is kinda going to bug me though

lime fulcrumBOT
#

โž• Gave the role PT1 to spooonge

keen sleet
midnight sonnet
#

How come that the AI missed to score my net pen flag in the user. I'm sure that I included it on the report and also I put it in the flag slot so my. 8/10 became 7/10 flags and I failed I did do proper reporting in detailed. Nevertheless I will not report on mail support cuz I have a friend who encountered same issue as me no score in the flag he reported it but took 2 weeks for the answer and a insurance of 'reassisment' so nevermind.
I'll comeback stronger on the second attempt next time.

keen sleet
#

The flag is static grading, AI has nothing to do with it.

#

The AI only grades the big text fields where you can type freely, nothing else like the CVSS, Vuln ID or flags.

kindred oasis
#

anyone has tips for the web app portion? just failed my first attempt cuz of the web

midnight sonnet
keen sleet
#

I'm talking about "Save" button under the exact section for the flag, not the save button for the entire part (Such as Web, AD or NetSec)

midnight sonnet
unborn glacier
#

Hey everyone, just passed PT1 ๐Ÿ™‚ How can I have the role? Thanks

keen sleet
lime fulcrumBOT
#

โž• Gave the role PT1 to azkrath

frozen minnow
#

For the next attempt, I'm going to write EVERYTHING in the report. I'm prepared, but I wouldn't want them to steal the flag again...

#

Do you know if screenshots can be uploaded to the report? Or is that not possible?

keen sleet
# frozen minnow Do you know if screenshots can be uploaded to the report? Or is that not possibl...
  • Screenshots are not possible.
  • Stealing flags is not possible. You're saying an automated robot that compares chains of strings decided to go AI-Mode and stole your flag?That is not possible.

The possible causes - based on other users who contacted support thinking their flags were stolen or graded 0 by AI - turned out to be:

  • User mistakes (e.g. an extra space, an extra digit, or not clicking both save buttons)
balmy canopy
#

Perhaps it would be good for both exam takers and THM if there was a format validation on the flags?

fierce wagon
#

HELP!! Hey everyone, any particular resource that should be completed in any case to pass PT1 ? Open to suggestions !!

vagrant lynx
distant trout
frozen minnow
#

I know these automated systems rely on string comparisons and strict validations, but I also know from my experience working with AI and automation that these systems are not infallible. AI can make mistakes too, and when it does, it directly and frustratingly impacts the user experience

#

Moreover, I'm not the only one this happened to. Several other users have reported the same issue here on Discord entering the correct flag and still receiving a 0 from the system. This further supports the idea that the issue isn't necessarily on the user's side and deserves a closer review

midnight sonnet
# frozen minnow Bro, the same thing happened to me as you. I got 8/10 flags and one flag gave me...

I'm not sure what happened. As far as I know, I double-checked each flag. I submitted a report as the exam requires. Perhaps the AI is in a beta or trial mode or some glitch don't know. I can't complain since it was a free voucher. I will retake the exam and focus on passing. I read some of negative feedback on that AI grading so next time I'm aware and fully do a super 31337 hacker mans report.

frozen minnow
slow cypress
#

do we get free months of THM if we buy pt1?

drifting kayak
slow cypress
#

How do we claimed it

#

I dont get the free months

drifting kayak
pliant bear
upper osprey
#

did any1 take the PT1 certification is it tough?

pliant bear
tight violet
tight violet
#

@keen sleet Can you hook me up with the role?

snow radish
#

Should confidential information such as passwords be included into the report when I describe the attack path?

topaz oyster
#

Hi, I'm taking the PT1 exam. After restarting the network, I canโ€™t connect to any network in AttackBox and therefore canโ€™t complete any of the tasks...I can't create a ticket because of the chatbot on THM

pliant bear
topaz oyster
keen sleet
snow radish
topaz oyster
# keen sleet Check pinned message.

If I was working on a machine and after a reboot it stopped working and none of the machines respond to nmap -Pn or ping this clearly isnโ€™t an issue with my enumeration or actions taken

topaz oyster
#

I use attackBox Eu-Vip-2

topaz oyster
keen sleet
#

Oh then probably support is your only option.

gritty lanternBOT
#
TryHackMe's Email

TryHackMe's support email address.

kindred oasis
#

hi im in an exam now and im experiencing issues with the infrastructure but the report an issue button is not working

#

what should i do next?

gritty lanternBOT
#

@kindred oasis

TryHackMe's Email

TryHackMe's support email address.

autumn cobalt
#

hi guys, beside the recommend room is there another room we can practice for the exam?

autumn cobalt
fading prawn
#

Iโ€™m little more than 24hrs in the exam and trying many possible exploits that is aimed to where I believe itโ€™s located but so far only completed the AD section of the examโ€ฆ Banging my head for a good minute now ๐Ÿ˜…

vagrant lynx
#

One question, if after 2 week (10 working days) and still did not get back the result for manual review, should I send a email to support and ask them?

quick zephyr
#

Hi there

somber onyx
#

Hey can i ask one thing can i swap with pt1 and sal1

fading prawn
#

alright serious question, how do i receive the webapp flag after I know for a fact I found the vuln

kindred oasis
#

hi mods i just passed the exam how can i get the role?

light token
#

I think @keen sleet mentioned that on his guide

fading prawn
#

from what I'm getting at from taking the exam, you really do need a little more knowledge that what is provided in the recommended learning path

lime fulcrumBOT
#

Gave +1 Rep to @light token (current: #1228 - 4)

light token
#

I havent taken it yet...web part is scaring me lol

fading prawn
#

ive actually been going back at it as little reference and I must be missing something. both the Web fundamentals as well as the jr penetration tester paster I have been using quite a bit for reference but i feel the web fundamentals are very much just the very very basics and yes hence fundamentals but makes me question just a little if you truly need to go a step further and complete the Web application pentesting path as well which is not in the recommend learning path

balmy canopy
# fading prawn ive actually been going back at it as little reference and I must be missing som...

I haven't tried the exam yet, but one thing that also worries me is that you probably need experience doing the techniques described in the recommended learning. If you just go through the rooms once, you might have seen the knowledge that are required, but you haven't developed the "sixth sense" or "hacker mindset" that you need to quickly understand what you should try at certain points.

I can feel this when I am doing, especially random medium challenge rooms, that I need to be exposed to more variants on how to enumerate or how to think about exploiting a vulnerability. So even though I have done all recommended learning, I still think I need to do more, before trying the PT1 exam.

The WebApp Pentest path gives you more experience, but perhaps you need to learn a lot of techniques that will not be used in this exam. But it is probably useful anyway. PT1 shouldn't be the last certification, it's just the beginning ๐Ÿ™‚

kindred oasis
gritty lanternBOT
kindred oasis
cunning wedge
#

Hello ,Iโ€™m trying to set a deadline for learning and taking the pT1 exam what would the time frame would you suggest?

snow radish
#

If I put the vulnerability type wrong but everything else is right (included flag, report, reproduction steps) do I get the points or will it be discarded?

keen sleet
#

Or not since the flag doesn't match the vuln ID.

knotty sigil
#

Hey i think the pt1 machine im doing is broken i guess, anyone i should contact, i dont wanna reset as i think i'd have to do all the expoits again to get the new flags

snow radish
#

You can reset the machine, the flags will remain the same

#

I'm on my second attempt and reset the machine several times, but the flags are the same

keen sleet
#

Multiple resets will hurt the exam more than it will help. 20 is a LOT.

#

support@tryhackme.com - they do not work on week-ends.

vast flax
#

My network turned off out of the blue

#

How much time should I wait to have it turned on again?

#

So, the network turned itself again but I can't reach the machines of my Assessment

keen sleet
#

Probably go for a reset. If you respected the RoE and have problems contact support.

knotty sigil
#

how to submit a vuln without a flag

#

with a fake flag yeah ?

keen sleet
coral bone
#

One question โ€ฆ. I m doing the exam โ€ฆ but is it possible to use images in the report or we must use only text to explain How we exploited vulns?

muted rover
#

PT1 - Im probably no where near ready to take it yet ...
But was thinking on the buy now and train up for it then take it scenario to make use of a discount voucher
On checking the FAQ says exam expiry should give up to 12 months to train BUT could be different if using a voucher and to check the terms of the voucher

The voucher is just a link though - there dont seem to be any terms anywhere with the voucher
Does anyone know if I will I get 12 months from date of purchase to train up first with this voucher ?

coral bone
warm beacon
#

just literally a couple hours ago

coral bone
#

Is 8 flag enough to pass ? I m missing 2 web flags:(

keen sleet
still halo
#

@novel coral @keen sleet @ebon creek I am taking my exam in the web part while exploiting a vulnerability i got the flag paramater with flag value:Placeholder flag what should be done now kindly help

still halo
#

Sure

keen sleet
vast flax
#

Yes, somehow it didn't happen when I tried another way

#

Only 1 flag remaining, I'm getting cooked for good

keen sleet
#

Good, it worked out in the end. Not sure why the network behaved that way. Did you respect the RoE?

coral bone
#

Ah sorry passing is 75%

#

Ok it is borderline

#

I remembered 70%

keen sleet
#

Actually, depends on the section. A flag in web is 40 points. In NetSec is 36 and in AD is 74.

#

So a total of 452 points for flags only, not 780.

coral bone
#

In ad for 2 hosts compromises you get 220

#

So 2 flags 110 each

#

20 for the report on that sections

#

I m reading the scoring system

#

Maybe they changed valuation criteria ?

tired grove
#

Hey guys, can you guys tell us what is really not allowed in the exam? Is it just AI that is prohibited?

wooden jackal
lime fulcrumBOT
#

Gave +1 Rep to @wooden jackal (current: #1057 - 5)

keen sleet
#

AD Section: {2 Flags - 220 points}

  • You have a perfect overall summary. (20 points)
  • You got both flags. (74 each)
  • You have a perfect report description on the AI's judgement.
  • You have perfect remediation action based on the AI's judgement.
cinder patrol
#

how many flags are there in PT1? 12?

#

The exam consists of 3 sections right each section contain 4 flags?

cinder patrol
lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #30 - 349)

vast flax
#

If I submit a report for a specific section, the exam ends?

keen sleet
#

Make sure you have all the exam done before submitting entire sections. That's if you want to stay on the safe side.

vast flax
#

I passed

#

Nonetheless, I also have to inform that AI tore some points out even if I reviewed my reports

midnight sonnet
#

Passed ๐Ÿ˜ช ๐Ÿ˜ƒ

keen sleet
lime fulcrumBOT
#

โž• Gave the role PT1 to putty_killa

midnight sonnet
keen sleet
#

No, there's a half flag system.

midnight sonnet
fading prawn
#

Would anyone be willing to share any extra rooms that would possibly help with the network and web portions of the test. I took the test once but I feel like Iโ€™m truly missing a technique on some findings that arenโ€™t fully working. Iโ€™m looking for more training outside the recommended path that I need to be looking at. Any help would be greatly appreciated

vast flax
fading prawn
#

Thank you @vast flax

lime fulcrumBOT
#

Gave +1 Rep to @vast flax (current: #2026 - 2)

fading prawn
#

Any other information or tips would be helpful as well

warm beacon
#

Does anyone think taking the web app pentesting learning path is worth it? I read somewhere where they said to do it

ebon creek
warm beacon
lime fulcrumBOT
#

Gave +1 Rep to @ebon creek (current: #1 - 5799)

hollow wagon
#

I passed yesterday. Overall it's a good exam (if you don't think about the unrealistic user simulation) and definitely provides more value than eJPT. Can't say about other certs (PJPT, PNPT, etc.) though because I haven't taken them.

keen sleet
#

BTW, we don't really allow discussing the exam, and specially once you're doing it. If you have bugs etc. you should contact the support team, but discussing the exam overall is not allowed.

ebon creek
ebon creek
balmy canopy
# ebon creek Well web app vulns are a big part of the exam I would definiteltly recommend you...

My thought was that Web App Pentest path covers topics that are not relevant to PT1. Of course good to know them, but I think as a newbie (as me) that the topics in Jr Pen Test and Web Fundamentals are a lot to ingest on their own. And instead try to reinforce the knowledge by doing the rooms in Recommended Learning several times or finding similar topics on other platforms. Is it a mistake from TryHackMe not having the Web App Pentest path as recommended learning?

amber parcel
#

Hi, I have a quick question: Does the network reset during the exam change all flags, or does it just reset the lab to its initial status?

prime reef
#

Should I achieve the pass mark in each section of the exam? or it's enough to reach the scoring pass of 750?

ebon creek
vagrant lynx
#

@keen sleet after sending for manual review, i passed, can give me the role when you are available. thanks

vagrant lynx
lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #29 - 353)

lapis wedge
keen sleet
stray skiff
#

hello, I am trying to start my exam but there is an error that says token expired and I am unable to check-in and continue further. Is there anyone who can help me with this issue? I wrote a ticket 3 days ago but there is still no answer and my voucher soon expires. What should I do?

keen sleet
prime reef
#

When should I start the second attempt after the retake is available?

mighty nimbus
#

Hii

idle hornet
#

I'm have mailed the support on the 25th July regarding pt 1 manual check and no response in return yet ๐Ÿซฉit's been more than 2 weeks. What should I do.

keen sleet
idle hornet
#

Thanks, Please do it ๐Ÿ˜ธ

coarse lake
#

Dumb question, but guess I should ask.
I got the voucher to take the PT1 for free, which expired by the end of Aug.
I just failed the exam, and I'm aware of the retake option. Does the retake option also expire at end of Aug?

stray skiff
keen sleet
stray skiff
lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #29 - 354)

sour iron
#

Is it still possible to get a free PT1 voucher by any chance?๐Ÿฅฒ๐Ÿฅฒ

fading prawn
#

currently on my second attempt. Results so far, I completed the Network portion and AD portion except for the report writing so far and I definitely would agree the WebApp portion is the most difficult of the three sections. I have enumerated and tried many exploits upon the webpage but only received 1 flag. Still have a good amount of time I just cant pin point exactly what I'm missing. Those that are prepping, really strengthen your webApp skills for sure. This coming from a person that holds a PWPA

prime reef
#

Does anyone have tips and recommended rooms and paths for the web app portion of the exam? just failed my first attempt cuz of the web

ebon creek
prime reef
lime fulcrumBOT
#

Gave +1 Rep to @ebon creek (current: #1 - 5818)

ebon creek
lime fulcrumBOT
#

Gave +1 Rep to @ebon creek (current: #1 - 5819)

keen sleet
#

Or did you buy it?

cinder patrol
#

to pass how many flag needed?

errant zephyr
#

hey I want to know that PT1 exam ID verification needs web camera?

keen sleet
#

You can also do it on a phone.

keen sleet
hollow wagon
# cinder patrol to pass how many flag needed?

The main factor is whether the AI grader like your report. I would say 9/10 flags with a "good" report should be safe, but if you get 8 flags with a "great" report (in the AI's point of view), maybe you can also pass with that.

jovial vapor
#

Hello, I have a doubt regarding the reporting. If I chained x vulnerabilities to get a flag, which vuln should I report? The most consequential one?

cinder patrol
#

if i passed the PT1 am i eligible to use my retake?

tame flower
#

Is there any mod or team member that can help me with the xss poc? Returns xss failed

vast flax
tame flower
keen sleet
#

Self DOM XSS doesn't count.

tame flower
#

Makes sense but there is no information regarding that

#

Thanks

keen sleet
#

It's pretty obvious IMO. A self dom XSS isn't a vulnerability, it's like opening the console and changing stuff on the website client-side and claiming it has been hacked.

fading prawn
#

Unfortunately the second time around I still wasnโ€™t able to pass due to web app section, however I did do better than my first attempt overall on the test. Funny enough I was able to even find a flag and finish finding report on the test literally 2 minutes left on the clock.
Recommendations for those studying, do the โ€œWeb Application Fundamentalsโ€ and the โ€œWeb application Pentestingโ€ rooms as I did catch myself referring back to each one trying to fish out nudges/help

cinder patrol
#

how can we get physical certificate?

proud gale
#

I am going to be taking the PT1 soon, is there any tools that are prohibited on the exam? The exam FAQ page seems pretty empty

#

Also for AD do we expect it to be blind or assumed breach?

stray skiff
#

hello, I am on my first attempt on my pt1 exam but having really big issue. Cannot connect to ANY target. I tried kali linux and the attack box but the results are the same. This is the output of the commands ip route | grep 10.200
10.200.48.0/24 via 10.50.46.1 dev lateralmovement metric 1000
10.200.150.0/24 via 10.50.46.1 dev lateralmovement
root@ip-10-10-187-231:~# nmap -Pn -p- --min-rate 2000 10.200.150.100
Starting Nmap 7.80 ( https://nmap.org ) at 2025-08-16 09:52 BST
Nmap scan report for trybankme.thm (10.200.150.100)
Host is up.
All 65535 scanned ports on trybankme.thm (10.200.150.100) are filtered

Nmap done: 1 IP address (1 host up) scanned in 67.06 seconds tried to restart the network but again, it is not working. Please, help me. My time is running and I do not want to fail also the network says it is offline when I move from the dashboard and the machine. What should I do?

snow stone
#

Hello yall,

Got the voucher for PT1 and I'm going to tackle the first try this weekend. From what I've heard the exam is pretty stable, but I want to ask if you experienced any issues with the environment and what will you recommend to use - the AttackBox or my own VM?

cinder patrol
#

ofc VM

signal steppe
#

hey guuys, i just submitted the pt1 exam and im really confused about the points that were taken from me by the AI, is is possible to ask for a manual revision or smth?

snow stone
#

from what I've read it is possible, make a ticket and explain them your concerns

vagrant lynx
signal steppe
#

got 8 flags score 731, plus one vuln that i described but got no points out of it

vagrant lynx
vagrant lynx
#

By that time, it might be too close to the expire date.

signal steppe
#

yeah i want to try, do i create a ticket or send a email?

vagrant lynx
signal steppe
#

ok, thks so much

harsh quest
#

got stuck on the web, 1 vuln left

shut mesa
#

hi

cloud tree
#

Hello, when I go to check in for the exam, it says that my verification has expired. Does anyone know how I can fix this problem?

stray skiff
#

Hello, had the same problem here. Write a ticket to the support. They will reset it

cloud tree
#

thanks

lone wraith
#

any updates on physical certs or the special package for the first 100 to pass?

light token
#

Whats the cooldown period if we fail ?

keen sleet
fast veldt
#

Anyone

#

Online

keen sleet
fast veldt
#

Is pt1 internationally recognized?

#

Like compTIA or ceh

keen sleet
#

No.

proud gale
#

I'm experiencing a bunch of network timeouts on both the vpn and the attackbox.... is there a way to get support

proud gale
#

This is actually ridiculous how bad the exam network isโ€ฆ I cannot connect to any machine anymore

proud gale
#

also getting a lot of issues where after I take a screenshot the attackerbox just won't take inputs or defaults to holding command... this is actually a horrible exam experience

#

@keen sleet or @ebon creek any advice, this is actually impossible to work with now. My attackbox won't let me type or select, it has alt held down and won't let me do anything

plush solstice
#

Chat, I'm cooked, solved AD and network in 4 hours, spent the next 20 hours doing web only to find 1 flag... 20 hours left, hopefully a brain blast kicks in psyDuck I CAN DO THIS

proud gale
#

atleast your machines work lmao

shut mesa
#

My name has been printed incorrectly on the certificate in PT1. Is it possible to get it corrected?

ebon creek
ebon creek
ebon creek
gritty lanternBOT
#
TryHackMe's Email

TryHackMe's support email address.

ebon creek
formal pumice
#

@whole beacon My Network Pentest reverse shell is really slow. Windows machine. Other labs just works fine

#

And yes, reseted it, regenerated config file, none of them didn't work. Same issue yesterday too.

proud gale
lime fulcrumBOT
#

Gave +1 Rep to @ebon creek (current: #1 - 5831)

proud gale
#

I haven't been able to access the web section at all for more than 10 minutes without the attack box freezing, network issues, lack of connecting to the vpn, etc

formal pumice
#

@ebon creek @rain raptor

#

I've only 5 hours left and have to travel in between too

ebon creek
proud gale
#

Yeah the network is cooked, idk why they have this exam out when it is so unstable

#

I have to reset the full network every ~10-15 minutes to make any progress

ebon creek
proud gale
#

The exam doesn't seem to work on weekends either ๐Ÿคท

little mica
#

@ebon creek if this is the case then what will happen if the attendee gets failed? Asking this out of curiosity. As I am writing a review on THM PT1 examination.

#

Shall the attendees not start the examination over the weekends?

ebon creek
gritty lanternBOT
#
TryHackMe's Email

TryHackMe's support email address.

little mica
#

@ebon creek Thanks a lot

lime fulcrumBOT
#

Gave +1 Rep to @ebon creek (current: #1 - 5832)

tight violet
#

Did they start shipping the physical certificates?

keen sleet
#

But it is known that the delivery of such stuff are very slow at THM. People have redeemed their prizes (On the profile tab) and haven't received anything for months. Disappointing, but that's how it is for now.

tight violet
#

True, it's not even limited to just the deliveries. I've been invited to meet with them twice and both times they've never shown up for the meeting.

stray skiff
#

Hello, I failed my exam. Since I won the voucher from the giveaway and the voucher was valid till 30 August, does anyone know since when my retake voucher is valid?

little mica
harsh quest
#

eeeh finally passed my PT1

hasty maple
plush solstice
#

I now have 2 flags on the WEB, 2 left and I'm done, WERE SO CLOSE BOIS

lusty bobcat
#

Let's go! Good luck peeps, I hope I will be doing it soon, too. Right now I don't feel even close to be ready

keen sleet
topaz oyster
#

If the machines or the network donโ€™t work during the exam, send them an email, they will compensate you with extra hours. I also couldnโ€™t get it running for about 2 hours, got frustrated, and left. When I came back, they had replied and added extra hours to my exam.

#

The network, by the way, seemed to start working on its own after about 3 hours.

gray tulip
#

Today I gave the PT1 exam. I submitted the actual flag, but they gave me 0 points even though the flag was completely correct.

#

Only 1 Points needed to pass

idle hornet
#

@keen sleet thanks for the escalation, cleared it ๐Ÿ˜

lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #29 - 357)

blissful cloak
#

Hello!

plush solstice
#

Ended up getting 3 of the flags on the web app, and I passed! The last vuln will haunt me for the rest of my days...

ebon creek
proud gale
#

So far even with all the network instability and reset every few minutes I managed to get:

  • 2.5 web flags
  • all four network flags
  • all ad flags
    Still got ~23 hours left but got to do all the reporting. Found plenty of vulns on the remainder of the web app just havenโ€™t gotten the full 3rd flag or a flag for some of the other vulns
#

Think Iโ€™m in a good spot assuming the network starts behaving

#

Still probably should get extra time since the infra is super unstable

#

I think Iโ€™m cooked since Iโ€™m about to be on an airplane in a couple hours but we will see

proud gale
#

For the reporting is there a style guide we should follow or any guidelines on things like writing from an agnostic threat assessor? For work we write โ€œthe offensive security team found Xโ€ฆโ€ but wanted to check as we are an individual

ebon creek
#

You will need to reach out to suppport on the email below

gritty lanternBOT
#
TryHackMe's Email

TryHackMe's support email address.

trim basalt
#

Hello, I have received the pt1 free voucher. The email states that I have until August 30th to take the exam, so can I start the exam on the 29th?

distant trout
#

This exam is crazy hard. It does not match the training provided by THM at all. Pretty upsetting honestly.

keen sleet
keen sleet
#

support@tryhackme.com

lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #29 - 358)

late linden
keen sleet
#

2-4 hours of overlap is the best you will get.

proud gale
#

Managed to pass the exam even will all the exam issues ๐Ÿ˜Ž

#

AI grader sucks lowkey tho

plush solstice
#

@keen sleet How do I get the PT1 role? I passed the exam recently!

ebon creek
#

@proud gale @plush solstice Congrats guys ๐Ÿ™‚ ๐Ÿš€ ๐Ÿ”ฅ

ebon creek
#

Shouldn't take more than a week

#

?

#

Support is only available on the email below

gritty lanternBOT
#
TryHackMe's Email

TryHackMe's support email address.

late linden
rapid bolt
keen sleet
#

Flags are just basic string matching. There's very little place for error. It's most likely a user-induced error: an extra space, character, not saving the flags correctly, etc.

proud gale
#

How do we get the welcome kit once we received our pass?

keen sleet
cinder patrol
#

@keen sleet i've passed my pt1 i can see i can retake

if i retake and get failed i'll consider fail?

#

also how I can get physical certificate if you could tell

proud gale
# keen sleet The welcome kit?

Quote from the website: Step 3
Get certified and get hired!
Access your digital certificate, celebrate your achievement with a Credly digital badge, and receive a physical welcome kit.

keen sleet
#

You can either order it or get it alongside other goodies for free if you are in the first 100 to pass PT1.

#

We have been waiting for around 2.5 months so I wouldn't get your hopes up for now.

cinder patrol
keen sleet
woeful escarp
#

QQ: For the ones that have the opportunity to complete PT1 before August 31st by having a previous cert like OSCP, does it also include the premium 3 months of learning? If that's the case I've never had the premium activated on my account and was met with a paywall whenever I tried to visit the training/rooms.

vast flax
gritty trail
#

Hi guys, just why I can't reset the lab ? I asked to reset like some hours and go and still... not reset and can't click on the button agian :(.

gritty trail
#

Nvm finally reset I guess, rn I'm doing a break, I can click again on the button but yeah... +2h.

rancid ember
fiery juniper
#

How can we request the real certificate of pt1?

#

I want to buy it

keen sleet
#

You have been asked to wait at least a week, please stop pinging all the staff members. Manual PT1 reviews can take up to 14 days.

keen sleet
unreal frigate
#

Hi, I passed a few days back I just wanted to know. Has already 100 people passed? Is there any chance for winning the physical cert( it looks awesome by the way)

vagrant lynx
unreal frigate
#

There was a reward for first 100 people

vagrant lynx
#

oh really

#

lol

vagrant lynx
unreal frigate
#

๐Ÿ˜‘

#

I am literally asking that

vagrant lynx
#

/is there a api

#

i see

unreal frigate
#

Yeah

#

๐Ÿคฃ

#

PT1 is awesome probably best among the junior certs

vagrant lynx
#

exam i think is good for like tech interview

#

for job

#

but the AI grading system...

unreal frigate
#

I want PT2 to be on the level or above og PNPT/OSCP. Tryhackme is doing great

vagrant lynx
#

i have bad experience

unreal frigate
vagrant lynx
unreal frigate
#

The AI grading

vagrant lynx
#

maybe a CPE system to renew the cert

#

also

unreal frigate
#

Other than that.my experience was smooth. No disturbance of the exam environment

vagrant lynx
#

at least for my experience

lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #29 - 360)

junior drum
balmy canopy
#

@junior drum Not yet. I am doing a real pentesting assignment right now (my first!!!), so the study has been postponed a couple of weeks. My plan is to take the exam in October.

frosty stag
hollow wyvern
#

Hi in verification process error saying your session has expired

#

How to solve it

#

@lime fulcrum

woven night
#

Anybody know how to verify for PT1? Do I need a cam on my desktop computer?

hollow wyvern
tired ether
#

Hello! I received an exam voucher for PT1 during the promotion (that expires on 30th Aug). Does that include a free retake as well or just one attempt? Would appreciate if anyone knows, thanks.

woven night
woven night
broken copper
snow stone
#

ticket to the support is already submitted, but I wanted to check here if there is some faster way to resolve this problem.

found 2 vulns in the web part of the certificate, but seems that the script doesn't generate the flags correctly for the format the the report is expecting.. any thoughts on this?

woven night
snow stone
snow stone
#

any mod on here?

ebon creek
snow stone
bleak latch
#

hey, im getting

Your session has expired

The SDK token provided in this verification process has expired. Please go back and try again

during my check in process

#

what am i supposed to do

snow stone
bleak latch
#

nope

#

still the same issue

snow stone
#

the only time i got this is when i was too slow for the selfie, at which point you get this error?

bleak latch
#

as soon as i click check in

#

it shows up , by some onfido security

#

i am doing it on pc, should i try switching to my phone?

snow stone
#

yeah try with the phone - scan the qr code and do it from there

bleak latch
#

same thing on phone

#

as soon as i click next step after typing my real name, it shows me SDK token provided has expired

#

Ahh man i was planning on giving it today because university starts next week, and they arent gonna reply till monday probably

#

pain

snow stone
#

not sure then what to advise you, except to open a ticket to the support and wait for them or someone in here to answer with some resolution

bleak latch
#

yeah i sent a mail

bleak latch
#

nvm, they replied so fast it got fixed

snow stone
#

and i'm still waiting psyDuck

bleak latch
#

praying you get your reply soon my brother

#

all prayers your way

hybrid spoke
#

Anyone encounterd the "Answer is too short, ensure the answer follows this exact length:" while trynna submit a flag in the PT1, Report ?

#

It's expecting a format other then the flags given in Network section

snow stone
#

exaclty my problem

#

found 4 (for sure correct vulns) and the flag is not in the format it should be

hybrid spoke
#

I emailed the support still waiting for a response

snow stone
#

please ping me if they give you a solution as from 12 hours - the only thing i got is "reset" and then "all is good, don't reset much" - but all is not great cri

hybrid spoke
#

HAHAHAHAHAH aight will do

brave vault
#

anyone can help???

brave vault
#

i sent email to support but dont receive rely

vagrant lynx
brave vault
#

i can not connect to vpn

#

anyone can help me

late kettle
#

Hi! I'm currently taking the exam, and I can't ping the workstation IP but I can ping the DC IP, anyone can help?

autumn cobalt
#

Will the new exam environment be the same or different one if we take the second attempt?

hybrid spoke
#

any updates from ur side ?

snow stone
#

got little more than 20h myself but...

hybrid spoke
#

man I miss TCM's support!

heavy gyro
#

I have logged a ticket on a bug with the flag in my exam environment but have not receive a reply. Anyone knows how fast they would usually reply? Or if there is a support admin in the discord that would expedite or reach out to

heavy gyro
hybrid spoke
#

I'm talking to support rn they said the flags are expected to be uuid when i got them as a hash

#

so confusing

heavy gyro
#

Mine is not even in a uuid format which is what it is expecting sigh

hybrid spoke
#

they are currently investigating @heavy gyro @snow stone

snow stone
#

nice, love to hear this

heavy gyro
#

Hope they compensate some time loss xD

snow stone
hybrid spoke
heavy gyro
hybrid spoke
#

I'm on a chat, can't see a ticket number

snow stone
#

Ticket ID #28810105 if it will be easier

safe musk
#

As long as you have proof of your actual flag values in your exam, so screenshots of the flag with the date, a manual review would give you the points. It looks like the flag generation system decided to not generate UUID flags for the network portion for one or two of the exam attempts. The team is investigating why. But as long as you have proof, the manual review will award you the points for the flag values. That's why we have the manual review process. But it can take up to 2 weeks for a review.

hybrid spoke
#

I have the screenshots but without a date, that means what ?

safe musk
hybrid spoke
snow stone
hybrid spoke
#

๐Ÿ˜ฎ

safe musk
snow stone
#

I'm confused.. can you contact me in the ticket so you explain - as if they are correct then the report platform is broken

safe musk
# snow stone I'm confused.. can you contact me in the ticket so you explain - as if they are ...

Your message was: I got the problem in all 3 domains - Network, Web and AD

So what I did:

  • Authenticated into your control server
  • Checked your unique flags and verified that all of them are UUID, which they are
  • Authenticated into your webapp and confirmed that it populated the same UUID 4 flags, which it did
  • Authenticated into your netsec windows box and confirmed the user.txt flag is UUID, which it is
  • Authenticated into your AD WRK machine and confirmed the flag.txt is UUID, which it is

So I'm not sure how you got this non-UUID problem in all three domains? Unless you are facing a different problem that isn't related to this issue?

hybrid spoke
#

Maybe that's as of now, check his logs from when he typed the flag values to confirm

#

from my side I still have the same issue, tried to redo one machine and still getting flag as a hash format the same one i got in the beginning

safe musk
# hybrid spoke from my side I still have the same issue, tried to redo one machine and still ge...

Cause your flags are not UUID. So they won't change. As mentioned in my previous message, there was an issue in your exam with the flag generation so it gave MD5 instead of UUID. But as long as you have proof that they are your flags then you will get your points.

What's I'm trying to say here is that user's shouldn't just automatically jump to the conclusion that everyone is facing the same exact issue.

hybrid spoke
#

And if the system is generating md5 instead of uuid would that be my issue ?

#

u said if that's the case i can provide screenshots

#

but that will take 2 weeks ?

#

2 weeks for verifying the flags that the system gave it to me wrong

#

and to get my cert

#

??

safe musk
hybrid spoke
#

issue fixed ig ?

#

just retested on the windows machine

safe musk
# hybrid spoke issue fixed ig ?

New values should have been pushed for both your Windows and Linux machine. So your two options is either just grab the four flags again and submit the correct ones. Or the manual review with the old flags

hybrid spoke
#

Flags grabbed

#

PT1 passed ๐ŸŽ‰

stray skiff
#

Hello, guys, is there a chance to extend my voucher? To be clear, I won it in the giveaway and failed the first attempt.

snow stone
tame spire
#

About to start the exam. With all the issues we keep hearing about, wish me good luck ๐Ÿคž๐Ÿผ

keen sleet
snow stone
#

they said my flags are not broken ๐Ÿคทโ€โ™‚๏ธ

frank falcon
#

I took an exam 8 days ago, and still generating correct flags for the Network Section is not working? I have a second attempt, valid to the end of month, but I'm scared to use it, if problems with flags still exist.

urban trench
#

anyone had problems when submitting the exam got 0 points in summary or something?

coral bone
#

is the flag problem resolved ? i m planning to use my retake

tough axle
#

Hey, everyone. I'm going to attempt PT1 exam in a day or two. Wanted to ask a few things before I attempted it.

-> I know the exam is 48 hrs long. Does that time include reporting or not?
-> If the 48 hours does include the reporting work, how long would it ideally take to get done with the reporting task?
-> Also, what will I need for verification process and how long does that take?
-> And, how soon can I reattempt the exam in case of failure in the 1st attempt ?

Thanks, and please wish me luck. I'm not too confident about the web-app part, but I hope I make it. Cheers ๐Ÿคž

keen sleet
deep turtle
#

Hi guys, I am having trouble with verification process

keen sleet
deep turtle
#

does it take a long time usually?

deep turtle
#

ah support will answer in 2 days , damn

tough axle
lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #29 - 365)

keen sleet
mental oar
#

Does PT1 include reverse engineering?

keen sleet
brave vault
#

i have question if i fail PT1 and do retake so i can do retake in next 12 moth. right?

noble glen
#

HI, guys, I do have problem in starting in the exam, the id verification URL does not work porperly, showing your SDK token expired, already drafted mail to support team but I think they replies on monday to friday.
Can anyone help me on this?

#

@novel coral @keen sleet @ebon creek

ebon creek
ebon creek
brave vault
#

right?

brave vault
#

yes thank you

noble glen
#

other than mailing them. is there any other ways to contact the support team?

noble sonnet
#

Hi. Iโ€™m currently taking the exam and the AD Workstation is down. I have reset the network over 6 times. Is it from THMโ€™s end or am I missing something?

brave vault
#

i have prolem with web PT1

#

I triggered xss sucess but when curl reponse is fail

snow stone
split folio
#

Hi Good Morning Everyone

#

Currently writing my PT1

#

i need some help

#

anyone currently writing it ?

kindred oasis
split folio
#

I'm not asking for answers

#

I'm asking for tips

raw jay
#

Hey I'm doing the pt1 now I am using attack box but can't seem to reach the trybankme ip i ping it it seems to be down I try to search the ip in a browser connection gets timed out anyone help

junior drum
#

make sure the file has a size (many have a 0kb size at first, had it this morning)

raw jay
junior drum
#

oh i dunno then sorry ๐Ÿ™

plush vector
plush vector
#

It will tell you what the issue is if you have any issues

brave vault
#

although web have vuln but i dont get any flag

raw jay
#

Is there anyone from try hackme that can help

raw jay
#

Anyone from tryhack me please help

junior drum
#

@raw jay better get a kali vm i think

#

it's the weekend, not sure they're working

raw jay
#

I downloaded the vpn file and tried to connect through that too using openvpn still cNt pin the target

#

I.p

junior drum
#

did you check the vpn file size?

#

too bad the report doesn't take markdown

bleak rampart
#

i am Facing issus on Verify your identity page

#

show error message
Your session has expired
The SDK token provided in this verification process has expired. Please go back and try again.

what to do Guys?

raw jay
#

Can't even reach the target i.p what exam is this

bleak rampart
#

I Mailed , But No responce Get

sturdy saffron
#

My PT1 voucher expires Aug 31. If I start my first attempt on Aug 25 (ends Aug 27), and then do the retake on Aug 30 after the 72h wait, will both attempts still count even though the retake runs past the expiry?

desert terrace
#

hello, i was wondering
do the flags reset also if i reset the network during the exam?

junior drum
#

I wonder how many started the exam and thought "I don't have what it takes"

strange ermine
#

If I submit my first flag will it grade my reporting on it or does it only get scored at the end?

junior drum
#

scoring is done at the end

bleak rampart
#

In the PT1 exam, Iโ€™m facing issues on the โ€˜Verify Your Identityโ€™ page. What should I d0 ?

#

Error Msg
Your session has expired
The SDK token provided in this verification process has expired. Please go back and try again.

bleak rampart
#

I tried, logout and again login, i used diff bowers also

#

Please help me

keen sleet
broken perch
bleak rampart
broken perch
#

Yup same here, I emailed support, logged out, cleared my browser history and cache and getting the same issue too

keen sleet
#

It's the weekend; people don't work on the weekend.

#

No reply before Tuesday. Monday is a bank holiday as well.

visual hazel
#

Hi, is there any support for pt1 ?

#

NetSec servers are constantly going offline

junior drum
#

AD servers are slow as hell too

sick python
#

Probs gonna give up on this exam... the environment simply won't stay up :/

#

Restarted 3 times, and half the machines are bricked. Hope support can supply something when they're back online.

final vine
#

is it normal if I just shut down my pc ?

midnight vale
#

hello can someone help me how i can get fast support from thm team , i am facing technical issues in exam

snow stone
midnight vale
#

fixed

junior drum
#

erm... my flag changed as i was doing the assessement (and now it's not in the right format anymore) Oo did it happen to someone else?

junior drum
junior drum
#

Well i'm amidst my exam and tbh, i find it quite frustrating that :

  • networks are unstable as hell (resetting the netsec again cause the machine isn't responding anymore... again and for no reasons)
  • flags are not fixed
  • report is buggy and the formatting is quite difficult
  • reports are definitly missing pictures
  • AD is slow
  • verification process buggy (i think that might be the most documented thing around)

I get that it's nice to have a 48hours format exam as many others, but at the least it would be awesome to provide a fully functioning environment or at least stable ... it really feels like juggling with machetes, porcelain and a drunk sailor here to keep it all working at once

dawn estuary
#

I exploited about 14hrs ago only to start reporting and now i'm seeing that the flag was not correct( was changed from the initial one๐Ÿ˜’๐Ÿ˜ญ) i had to exploit it all over again i hope it won't invalidate all my flags, exploting all 3 labs all over won't be nice

dawn estuary
sonic orbit
#

URGENT - any mods available to help with flag submission for PT1 exam?

#

The flag from my windows netsec machine bears no resemblance to the correct format.

junior drum
junior drum
sonic orbit
dawn estuary
#

I almost submited a user flag as root flag because of this stress lmao

plush vector
dawn estuary
#

It's the same for AD too c'mon guys ๐Ÿ˜ญ

sonic orbit
#

reset and it's now giving me an MD5 - this is ridiculous

versed python
#

The SDK token provided in this verification process has expired. Please go back and try again.

#

i am getting this eror can someone let me know how to solve it

dawn estuary
#

Is the attack box down too ??

junior drum
versed python
#

The SDK token provided in this verification process has expired. Please go back and try again.
i am getting this eror can someone let me know how to solve it

anyone

vale granite
#

guys if i buy PT1 voucher do i get option to like set up date when i will do exam or does it starts in 3 months after i have bought voucher?

i am confused

desert terrace
#

you can choose whenever you want within a year, you don't have to set up a date prior to taking the exam

dawn estuary
#
dawn estuary
#

Thanks man ๐Ÿ’ช

dawn estuary
lime fulcrumBOT
#

Gave +1 Rep to @snow mango (current: #835 - 7)

tough axle
#

Quick question. Do you folks reckon I can pass the exam with 4 netsec flags, 2 AD flags and 2 webapp flags (assuming my report is decent) ?

sonic orbit
#

sounds possible IMO

vale granite
#

is this room enough knowledge for writing pentest reports

#

for pt1

remote portal
#

The onfido site isn't working for me. tried several browsers

grizzled torrent
keen sleet
strange ermine
#

I am worried my network flags are not the correct format. Should any flags read just plain text?

#

It does looks like its in the wrong format

#

What do I do in this case?

mighty mist
#

If i reset the exam environment should i resubmit the flags?

sonic orbit
strange ermine
sonic orbit
strange ermine
sonic orbit
junior drum
#

am i the only that have been cut from the network ?

#

is there an admin/mod that can help by any chance? i restarted the network, regenerated the vpn file and still nothing when i ping 10.10.10.10 i have a 100% packets lost whereas when i'm using the tryhackme general vpn file everything works fine ......

junior drum
#

any staff member please?

cloud tree
#

does anyone know if I reset the lab enviroment of the examen (PT1) the flags change?

junior drum
#

they do for some, and don't for others

full pivot
#

This test has been super buggy

#

Not a fan so far

cloud tree
#

I already exploited a vulnerability on the web app but I dont get any flag, does anyone know why?

junior drum
#

@plush vector sorry for pinging you, just to know if there's any support whatsoever or if I can just let it go, I've been out of the network for an hour, even the attack box is off of it and I have less than 10hours left, should I consider this failed ?

plush vector
junior drum
#

I don't recall tbh, I'm going to do it again

#

I've also regenerated the vpn file twice

plush vector
#

Try reset it, wait 10 mins and see if the attackbox will load back up

junior drum
#

Thx

#

still got nothing... i'm still out of the vpn connection, regenerated the vpn file, tried with the attackbox too...

coral bone
#

I do not know what to think โ€ฆ i m going to retry this exam because i failed with 729 โ€ฆ and i think that i mis a flag for a bug โ€ฆ. Hope the next try will be successfull

junior drum
#

@plush vector nothing at all ๐Ÿ™

#

made a support ticket, it's going to be a wrap for me and that really is frustrating all the network issues, vms, flag bugs...

plush vector
#

Try run tryconnectme on the attackbox

junior drum
#

used the thm-troubleshoot script

#

shutting down my vpn i'll try on the attackbox again

junior drum
#

ran the script twice

And on Discord, please provide the output from:
  /root/Desktop/NetworkConfigs/logs/pt1-network-3.log
root@ip-10-10-229-152:~# cat /root/Desktop/NetworkConfigs/logs/pt1-network-3.log
cat: /root/Desktop/NetworkConfigs/logs/pt1-network-3.log: No such file or directory
#

and even a third time ... still the same

full pivot
#

AD section is kicking my but

junior drum
#

At least you have access to it ๐Ÿ˜‚

warm sapphire
#

lol you asking for help on a certificate exam?

full pivot
#

I messaged you. the web was also broken for me

keen sleet
#

You don't give a shit you're cheating in an exam?

north plank
#

Has anybody found that a user flag is missing in the exam environment that is described in the rules of engagement / deliverables? thanks

torpid berry
#

Anyone knows the intended way to submit a partial flag, as described in the RoE? It implies that that's a possibility, but then validation on the report fields actively block submission until it matches the expected format (which is a full flag).

keen sleet
#

You cannot submit a partial one.

#

Basically, a partial flag awards you no points.

torpid berry
#

What about an identified vuln with no flag?

If you identify a vulnerability but are unable to fully exploit it to receive the flag value, you can submit the vulnerability without the flag for partial credit.
For the same validation reasons as with a partial flag, it's not totally clear how you could "submit it for partial credit"

final vine
#

Could we get the physical certification after passing the exam ?

glossy gulch
#

Hey, so, I found an XSS but i can't retrieve the flag, I've been stuck here for a few hours now

glossy gulch
keen sleet
keen sleet
keen sleet
lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #29 - 368)

sullen aspen
#

Hi guys can someone help me with the gatekeeper

glossy gulch
glossy gulch
#

thanks for the hint btw

glossy gulch
lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #29 - 369)

heavy gyro
#

Is it possible to ask for or get a manual review on the reporting aspects of the report? Like CVE, description etc.

torn girder
#

@keen sleet ib my man hahaha

junior drum
#

Tada!!! I officially failed PT1 for.... VPN connection not working on THM side yeeeeeeey ๐ŸŽ‰ ๐Ÿฅณ ๐ŸŽ‰ ๐Ÿฅณ ๐ŸŽ‰ ๐Ÿฅณ ๐ŸŽ‰ ๐Ÿฅณ

coral bone
#

Buggiest cert ever

coral bone
#

I m experiencing a bug in network session and i m not able to go on โ€ฆ any admin available ?

#

Also the โ€œ report issueโ€ button does not work

coral bone
#

Now i can access to a machine but there is no flag

languid shell
#

I took my first attempt 2 days back. I'm totally disappointed with your support. For the first 8 hours I couldn't reach the web server. Then for 4 hours its performance was poor and It became unresponsive. It hardly handled 3 parallel requests. Adding on to it, the attack box reset frequently without any notice and every progress was lost. I can't believe my efforts went in vain.

junior drum
#

i shot them a mail yesterday, maybe everyone that has had a bad experience should too

#

having the 14 last hours with not working vpn network for that kind of exam is totally insane

languid shell
junior drum
#

same ... guess i'm definitely going for CPTS then , got a retake but in the same conditions? no way on earth

elder nova
left helm
#

PT1 kicked my bug. Network wasn't bad, AD was alright but Web App I was pretty lost. Feels like a Bug Bounty cert.

junior drum
elder nova
keen sleet
junior drum
#

i mean read the room, i'm not the sole soul to be quite upset about PT1 here

keen sleet
#

'support@tryhackme.com' for the rest.

#

Without the quotation marks.

coral bone
#

I rebooted for the third time and i got the flags but i wasted lot of time

gritty trail
#

Question, I failed my first attempt but I will have to quickly make the second attempt soon otherwise I will not be able to pass it... I had contacted support with documents to discuss the problems I encountered when sending the report and the results. Can I make my second attempt at while they are looking about my documents or do I have to wait for a response?

dawn estuary
strange ermine
#

What is the physical welcome kit? Has anyone received it?

elder nova
#

probably the most annoying part is the web, i've finished everything else in 4 hours with the exception of web chevy

keen sleet
#

We don't really allow promotion in here.
If you want your article to be allowed to be published in here, please allow its access publicly and not to members-only.

keen sleet
gritty trail
# keen sleet Yeah you can.

Alright, thanks,because I reported two vulnerabilities without flags and I got 0 points, and that's how I lost quite a few points., is this normal or not?

lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #29 - 370)

keen sleet
gritty trail
#

But yet it says that we win points?

#

"partial points" or did I misunderstand something?

keen sleet
#

The only way to get points without finding a flag is if the vulnerability you found actually has a flag behind it but you weren't able to retrieve it.

#

You'll get partial points only in this case.

gritty trail
#

Ah okay.

#

And also I had a vulnerability in my report and in the final results it changed the ID, was it the one I was supposed to put this one (from results) or is it a bug?

junior drum
lime fulcrumBOT
#

Gave +1 Rep to @dawn estuary (current: #3104 - 1)

dawn estuary
north plank
#

@junior drum you will get it next time- i am 24 hours in - 4 hours for network and ad total and 20 hours staring at burpsuite!

coral bone
#

I ve done AD and Networkโ€ฆ but web is killing me

#

8/10 but without another web i lo not pass

tulip violet
#

upvoteHey, I wanted to ask: if someone fails on the first attempt after starting the exam on the 30th, would they be allowed a second attempt?. Expiration date 31st Aug 2025.upvote

obtuse kite
#

There's 2 free attempts on the cert.

obtuse kite
tulip violet
obtuse kite
#

2025 or 2026? ๐Ÿ‘€

tulip violet
#

2025

#

haha !

obtuse kite
#

๐Ÿ’€

#

hahaha

#

Then you will have to buy it again or try to it before 31th. You have 6 days.

tulip violet
#

Haha ! Thanks Will spit blood now !

obtuse kite
#

Sure.

glossy gulch
#

How many flags do I need to pass?

obtuse kite
#

As much as requested. On each section.

glossy gulch
#

I have 6 out of 10 flags

obtuse kite
#

Has hecho AD?

glossy gulch
obtuse kite
#

AppSec/WebApp:
4 vulnerabilities and 4 flagsto submit.

NetSec
2 Hosts to compromise & 4 flags to submit.

Active Directory
2 Hosts to compromise & 2 flags to submit.

obtuse kite
obtuse kite
autumn cobalt
#

does 8 flag
web 2/4 network4/4 AD2/2 sufficeint to pass?

north plank
#

was trying to work this out myself!

#

18 hours to go!

glossy gulch
#

7 flags!!

#

I need 8 to pass right?

#

AppSec/WebApp:
I have 2/4

NetSec
I have 4/4

Active Directory
I have 1/2

coral bone
#

You need 9

#

I failed with 2 web 4 net and 2ad almost all points for report

#

One question if I found a vuln that does not Give flags can it be considered for partial points? It is a big vuln

glossy gulch
#

They are 10 in total

coral bone
#

But does not think it was intended

coral bone
glossy gulch
#

Is hard asf tbh

wide sigil
#

hey

gritty trail
#

You can loose a lot of points due to your report.

#

But if you did good, 8/10 flags is enough to pass.

autumn cobalt
lime fulcrumBOT
#

Gave +1 Rep to @gritty trail (current: #3105 - 1)

north plank
#

convinced that web app isn;t giving out the flags

coral bone
#

zamir8989 i took almost all reports point and not passed with 8

coral bone
#

i'm finding lots of vulns but no flags

keen sleet
lime fulcrumBOT
#

Gave +1 Rep to @keen sleet (current: #29 - 371)

full pivot
#

If you pass PT1 are you able to still re-take the exam with the retake? It looks like it will let you but I am not sure.

karmic bay
#

Even if the vulnerability has a major business impact, if it doesn't give a flag it apparently doesn't matter

glossy gulch
#

The AD is insane

coral bone
#

and they states that even if you do not get a flag they valuate a valid finding

tough axle
tulip violet
#

People VPN is Not working for PT1, What's wrong ?

tulip violet
#

because of WSL ?

glossy gulch
#

just a quick question, if I press the reset button... the flags change or something?

#

I only need 2 web vulns

#

but I think my web env is bugged or smth

ebon creek
tulip violet
#

Okay thanks

tulip violet
#

I already lost my 3 hours

coral bone
coral bone
#

is there someone who knows this ?

balmy pecan
#

Hey, Iโ€™m planning to go for the PT1. Iโ€™ve already done the Jr PT Path, the Web App Path, and quite a few challenges, but I noticed the cert also covers Active Directory skills. Since thatโ€™s not really in any of those paths and I donโ€™t have much experience with it, is AD knowledge a required prerequisite for PT1?

tulip violet
#

It's not even working on VM

#

I tried your official script as well.

#

Tried changing data to my mobile hotspot.

#

still not working.

#

Tried manually chaning mtu.

#

Attackbox is extremely slow.

#

Now What ? Just stare on the screen to fail ?

ebon creek
# tulip violet Sir ?

Sorry but I can't help you with that , you will have to reach out to support on the email below

gritty lanternBOT
#
TryHackMe's Email

TryHackMe's support email address.

ebon creek
tulip violet
#

**It's already been 1.5 hours since I have reported this issue **

tired ether
#

Hi everyone, just wanted some clarification around the report for the exam. We only have text boxes, so I guess screenshots can't be used. Are we supposed to include code/commands that we used? There's no markdown so I'm not sure.

lime fulcrumBOT
#

Gave +1 Rep to @ebon creek (current: #1 - 5875)

junior drum
rare ice
#

Hey, I have a quick question about the PT1 exam voucher. I won it in a giveaway for those that already are certified.

The exam voucher is valid until August 31st and includes one free retake. If I start the exam on August 31st (it's 48 hours), will I still be able to use the free retake afterwards?

tulip violet
junior drum
tulip violet
north plank
#

i wouldn't worry - have full working access and still siting on my chair with nothing working!

tulip violet
#

@normal wadi Do something for VPN !

sudden stag
#

@normal wadi @mighty crescent its been HOURS that my VPN wont connect and my cert time is being wasted

junior drum
#

Send a mail to support@tryhackme.com

sudden stag
lime fulcrumBOT
#

Gave +1 Rep to @junior drum (current: #2040 - 2)

sudden stag
#

turns out, the support is really shit and they wont even bother to take a look

north plank
#

sounds obvious, but you have tried regenerating the ovpn and making sure that you have killed any previous openvpn session : ps -awk |grep "openvpn" and then kill for the pid - also make sure your pc isn''t on same subnet as vpn ip address!

sudden stag
#

it doesnt make a difference

north plank
#

have you previously used thm's vpn servers for rooms / lab. Does this still work?

sudden stag
#

i have a streak of 229 days, i have encountered issues like these a hundred times

#

what i can NOT afford is to have my certification time wasted over some bullshit connection issue like this

junior drum
junior drum
coral bone
#

i'm also waiting for a response from support ... it is a paid cert

junior drum
vivid remnant
#

๐Ÿ™๐Ÿป๐Ÿ™๐Ÿป๐Ÿ™๐Ÿป

north plank
#

unsurprising - didnt pass!

#

amazed how many points i lost on reporting (even with 2 more web vulns don't think i would have passed!)

#

would have been better for tryhackme to have published an example report for each section for a "test machine" to show what was expected in the report.

#

So my official take is PT1 is officially harder then OSEP for me!

keen sleet
tired ether
coral bone
#

and in the passing criteria they states :

"For each of the vulnerabilities you find, we will score identification, classification,proof of exploitation and reporting separately."

#

"each of the vulns"

#

no to be polemic but it is strange that i need to guess if a vuln ( that is a vuln) will be considerated a vuln

#

and nobady has responded to my emails

keen sleet
keen sleet
vapid surge
#

N

keen sleet
keen sleet
#

Yes... for each of the vulns that have a flag....

#

Again, context is important.

coral bone
#

sure .. so here the context is that i m taking a 48 hour exam without support.. lots of people failed it for beeing without support ... and we paid

keen sleet
# coral bone yesterday morning

Well, obviously they're not going to answer then. Technically your ticket has been waiting for just a few hours since today is the first work day.

dry crater
#

First attempt I had 3/4 flags on the network part, but I still failed the cert.
Just retook it and failed againโ€ฆ this time the network section was brutal, only 1/4 flags. ๐Ÿ˜“

north plank
#

@dry crater sorry to hear that. Just failed myself on the web app side - got 4 network and 2ad flags but lost quite a few points om reporting

dry crater
#

Yeah this time the Windows part was insanely hard. I was completely lost and even tried asking AI for help but still couldnโ€™t get anywhere. Ended up spending almost a full day on it, really horrible experience

dry crater
torn girder
rare ice
#

Can i take the exam on the 31st? In my understanding it expires after the expiration date.

latent slate
#

Is it possible to skip retake time?

#

@ebon creek

ebon creek
latent slate
ebon creek
gritty lanternBOT
#
TryHackMe's Email

TryHackMe's support email address.

latent slate