#site-bugs
1 messages Β· Page 7 of 1
Well I think the start of level13 is 100k
The right side just hasn't updated since I got into level12.
Whats your username on THM @glass kindle ?
It's haruue @frosty cape
we seeing double now π
@frosty cape the l and the 1 are the same for 0xD, whereas in Haruue's screenshot they are clearly 2 different letters π
unless i'm level 113
No, I meant the "l" in level is the same as the "1" π
it says "leve113"
whereas in @glass kindle 's screenshot, level is not spelt with a 1 π
Oh yeah!
I'll add a space π
and change that
Thanks good spot btw
@rare swallow Fixing that bug too
@vocal raptor Its the way your font is showing on your browser
They're very very slightly different
@glass kindle @rare swallow Both your identified bugs have been fixed.
Thanks again everyone for reporting bugs!
π
I'm not a subscriber, earlier this year i joined these two rooms but i cant leave them now
The latest day in Advent challenge has a root flag which is useless
color.txt
us-city.txt
country.txt```
can't access those links
the pastebins links are not loading
room password cracking
those seem like very normal wordlists you can find on github, can you search for them? π
i cant imagine any of them are longer than rockyou haha
Cache perhaps? Doesn't load for me or downforeveryoneorjustme.com
yeah its probably cached
@rugged ermine So... the root flag on Retro is actually root.txt.txt
I feel betrayed because that caused me 10x more pain that it should have
LOL
I didn't even notice that when i did it
that's amazing and it better not be a bug
Oh that's a typo haha
lol
whoopsie lol Β―_(γ)_/Β―
@tribal knoll In RunC escape, the images aren't loading for me
Also @frosty cape that VM needs some more resources imo, logging in takes a while
I don't know if this really a bug.
but earlier today i opened cyberadvant room on firefox on my both host and vm, after I finished the challenge, I noticed my rank points.
after couple of hours I realized that the room still opened on my host browser, I submitted the challenge solution again on my host (I donβt know why O.o), then my points updated with the latter (I lost some points).
@earnest brook if you can load a website from a room on your browser after you have terminated the machine, it could be loading from cache. although I didn't understand exactly what happened with your points. can you elaborate a little?
@fading laurel what im trying to say is that i opened cyberadvant room on my host firefox to see today's tasks while my vm booting
after my vm started i opened the room on vm without closing the room or firfox on my host
after finishing the challenge on my vm, i looked at my points, it was ~(10160), after ~2hrs i closed my vm, to see that the room still open on my host's browser, i submitted the solutions again, then reload the page, lloking at my points it was ~(10070)
if I submitted the solution earlier, any submission came later should not be accepted, right?
I can't answer that, you'll have to wait for one of the admins to see it. I just chipped in to tell you about browser cache to eliminate that
idk if i'm in the right place, but the title of Task 23 in CC: Pen Testing is "privilege esalation".
it seems that the images are broken in: https://tryhackme.com/room/runcescape
TryHackMe is a platform for learning and teaching cyber security.
Ih
Uh
Ohno
That bad, but I can't fix until tomorrow
Never not using Imgur again
Litterally use imgur for all room pics
I cut a corner
Never cut corners
Ah
That's why
My sharex server provider had a drive failure
So data loss happened
@covert kernel will hate me π
CC: Pen Testing Task 3 #6 there is no text in the question
@cloud tundra whats the task called
Netcat
The issue has been fixed
however i've completed the room. and i loved it.
:)
Every time I forget to select a room, while making a task, it disables the button and does not enable it when I select a room
I end up having to delete the disabled='' from the html element
Not sure if it's a bug, but in the room Ice on Task 5 #2 it says:
In order to interact with lsass we need to be 'living in' a process that is the same architecture as the lsass service (x64 in the case of this machine) and a process that has the same permissions as lsass.
But Ice is x86
I might just be misunderstanding this though
Ah okay, thanks @covert kernel will fix that soon
@chilly seal is it not x86-64?
Bug: when you complete a room, the creator adds a new task, you haven't completed the room until all tasks are done but under "my rooms" and "hacktivities" both show as completed
Yeah, I could reset the 'complete' room - not sure if I can see this as a bug hm
But yeah I guess it is
Thanks for pointing this out mind
The links on the bottom, specifically goals, do not show up when logged in. Not sure whether this is a bug or needs to be a suggestion but please add a link to /goals in the side panel so that it's accessible to users who are logged in.
when searching for the advent calendar no results are showing when looking for the following
but if you look for christmas or cyber it shows up
@rugged ermine then you should look at implementing advance search: normal search to look for room names, advanced for tags, created date, etc. That will come in handy one day
not sure htb has something like that, so the more features we have the more you can showcase/advertise the platform
This is the input you are about to create:
TryHackMe Kali Box
THM Kali Boxes are lagging
-- Created by: Ashu
Issue has been created by @sly raft!
@sly raft you might want to add that the kali box sometimes gets the caps lock stuck for no reason and i can't find a way to remove so i have to hold down shift
Room = powershell: Task 3, Question 3 - answer is not correct for the machine's current state
actually scratch that...wrong window
but the powershell room could use more than 512MB RAM
minor bug
This is the input you are about to create:
Hacktivities Pagination
Pagination doesn't update when changing filters on the Hacktivities page
-- Created by: Ashu
Issue has been created by @sly raft!
VIM room
@rare swallow ?
Just an empty question with no answer @delicate dragon
Which room?
TryHackMe is a platform for learning and teaching cyber security.
@delicate dragon this one
Strange
on task 2
I think day 17 on the 25daysofchristmas challenge has a bug. I manually tried all the 30 passwords and still did not get in.
Im new to this and teally want to learn is there anyone who has time to chat wity me ti helo me through allnof this
@still bison Read through the accompanying material
But also not here
Try the CyberAdvent challenges
@cloud tundra is it really in the 900k rangd, I've been at this for 4 hours now
@tired solar the best option is to find the flag in another way
@tired solar known issue for that room
Yea just should be fixed
Not likely to happen with a lot of these
I should not spend more than 20min brute forcing
Yep. It's a known issue though. Best way is to move on to the SSH and then find it from there
Sorting by newest in Hacktivities should sort by release date
hello, I have a learning path on 100% and nothing happens. I cannot see other learning paths (if there).
Should I "leave path" ?
You have to leave the path in order to see the others
ah ok π
Hey! I have issues with FTP on ctf100. This is the 4th time this exact same FTP issue has happened, Ashu said it might be because of my IP address (during cyber advent). This is the 5th time I haven't been able to do something because of my IP address. (The extra time was that CTF100 wouldn't recognise my IP address). Can whatever bug this is be fixed please? π For FTP, I cannot do anything at all related to FTP on some rooms. I get "500 Illegal PORT command." on every command. Per cyber advent, I have tried wget, file browser, internet browser, and ftp. It's definitely not because I don't know how it works. Pls fix :(((
PS: I can replicate this on 4 devices, on entirely different networks, with new VPN configs, and a brand new install of Kali. I'm 100% sure this isn't happening because I don't know how something works, I'm 100% sure this is a genuine bug that other people have faced too
My THM IP address doesn't ever change, so the bug will always be the same ^^
1 other person had that issue.
If you create a new account on TryHackMe and use that VPN does that experience the same issue as this will be a different IP
You don't have to create a new account. You can regenerate your VPN package in "access" tab
I've had at least 2 people DM me with the same problem. And regenerating a new VPN does not change anything, as your THM IP address will always be the exact same. A new account will fix this issue, as your IP address will have changed π
however the idea of creating new accounts until I win the IP address lottery sucks
What would be ideal is dynamic IP addresses, so I can just reconnect my VPN until I eventually do win the TryHackMe IP Address Lottery β’οΈ
Yeah, regenerating your config file won't change your IP address. Your account is normally linked to an addrese
Is this something you want to change? Not sure why you would need your connection IP address changed mind?
Aha win TryHackMe up address lottery
Lel
Fyi, this year we will have quality control in rooms
To mitigate bugs :9
Might be because of your IP address? I think it's because of the box if you've tried with diffetent OpenVPN config files
I'll take a look anyhow :)
This text is a little misleading, as you need to be a sub to do anything in the room? (Not just to deploy VMs in there)
That's discords fault
oh ... i say delete the #648878292551598080 since it doesn't work anyways and then reimplement it when they get the bug fixed. After a quick google search i found this https://help.mee6.xyz/en/article/welcome-messages-1y1t3dx/. TLDR You could disable to welcome messages and enable a private direct message on login.
Mistake in Fowsniff CTF
Username is different to one it says to use
It says to use the sender of one email, but actually it's the sender of the other
@frosty cape
There seems to be an issue with uploading files
My files stay at 100% and then hang for a couple minutes and say an error has occurred
Still broken for me
ah well that kinda sucks
guess we'll just have to wait until tomorrow when it hopefully get's fixed
You can't login with your username anymore. Only with your email.
However it still says you can login with username / email.
I think I complained about this a while back
Ahh, I'll test the VM upload issue!
Found the issue, I am uploading the fixed code
Weirdly enough I left a vm uploading overnight shortly after saying that and it was successful
@worthy stag how big was your vm? i was having issues with 10GB ova
@frosty cape I still cant upload any files :(
Wait
Development console
It stays at 100% and does nothing but the material is there
Yea its still hanging at 100
But I can download the material from my page
It just finished and said "An error occurred"
This is the input you are about to create:
UI Upload Bug
Hangs at 100%/throws error even when material is uploaded
-- Created by: Ashu
Issue has been created by @sly raft!
I think this may have something to do with the recent update where subscriber machines have better specs
Oof, CPU is 2.3GHz and RAM is 4GB
Also that should NOT say "memory"
Skidy, I'm VERY disappointed
(only mostly joking)
Hm - I will look into this, perhaps the "subscriber" resource tag is overriding the original VM specified resources. Will take a look this evening
retro box privesc method not working please help
@patent wedge not a bug, intended issue that there's a fix for. Look around in #room-help and #650425164894568455
^ not a bug its a feature
retro privesc not working
i inistialised the google chrome and ie
and even changed default browser many times
trying to force the link to open in ie
It does work. Youβre just having the same issue I had
so what u did to fix ?
Reset the room after an attempt
Then try again. I havenβt got it working as gave up wasting time on it but it is still working as a number of people have tested it
oh okay ill try
If you get incredibly stuck and understand specifically what I'm teaching here I can also just give you the flag
The main goal here is that exploits are not consistent in real life and this one, while mostly consistent, takes some trial and error. That's why it was optional in the event
tried reset the box many times ... even with ur solution still didnt work
and i rly want to submit and go the next machine
much thnx @rugged ermine what next machine do u recommend ?
Have you done Blue and Ice?
not yet
i'll start it now
but when i think of blue always i think of eternal blue
hi ! cannot connect to rdp host on retro room
@everyone
@fervent gust Yeah I need to fix that, added to my list, thanks for repoting
ctfcollectionvol1 -> A sounding QR @tawdry totem
ooof
loool
Hah
DarkStar @frosty cape Make the room tags standard... example... there are four reverse engineering rooms on thm ... The tags are "reverseengineering", "Reverse Engineering", & "reverse engineering" so the search does not always work correctly... crossposting this in #522158404614225920
I don't know if it is an actual bug or if I don't understand the score "system" I finished the room https://tryhackme.com/room/metasploit and I only won 314 (the first two tasks are showed on the chart). Is it because the room is very old or is it an actual bug? Thank you in advance for your answer.
TryHackMe is a platform for learning and teaching cyber security.
You tried refreshing that bad boy
Yes, I refreshed and logged off but it didn't change
@plush tapir Its most likely because I changed how many points you get per question, before that others got much more.
Seems like @raw karma BOT isn't accepting !verfiy command!
Maybe because it's !verify and done via dms
@remote laurel
I'll check
Yeah, I'm wired into my own thing atm
Weird stuff, I restarted the bot
@wise epoch retry now? It seems to be fine
I think something crashed the bot, I gotta investigate this
Not working @remote laurel
Yeah I see that
It's weird
What's your rank?
It seems to be crashing only for u
weird, I'll check
@remote laurel 0xD
Seems odd to me - BUG HERE as well!
TryHackMe is a platform for learning and teaching cyber security.
TASK4 - Q4
@frosty cape Ok, it just looks weird that only the first tasks are displayed on the chart.
Well, not for me. I've finished the room and only the first ones are displayed here
give it some time
I will, hope it will get fixed ^^ Thanks
@plush tapir Which room for you?
@frosty cape https://tryhackme.com/room/metasploit
TryHackMe is a platform for learning and teaching cyber security.
ctfcollectionvol1 : A sounding QR
Hello,
I have a problem with time settings I guess.
When I deploy any room+extend with 1h,
It appears "vm expiring soon" and "vm expired".
Do you compare the time with the time on my PC? Because that seems to be the problem
Yes please
For all that are wondering, that bug has now been fixed.
Yeah, its annoying, but learnt something new tho
I'm mildly interested if you have a TL;DR of the issue
Yeah sure,it was pretty simple, my server returns a date (in the timezone its in), just had a function that converts to local timezone, updated the code client side. Not that complicated, but learnt about JS local time conversion.
Much appreciated 
no worries, if it effected you
It must have others too
So
Thank you for letting me know
Np :)
So in summary, JS doing JS things?
yup
Hi
(that doesn't go here)
@tribal creek Sounding QR patched, sorry
Does google actually properly index THM's writeups section? Doing SEO on my site and wondering if that's why I see no links
Dorks is google's exploit/hacking database, not SEO related
I assume you have search console etc set up for tryhackme?
Not sure if it's a bug or just slow notifications or something, but was just informed today that NinjaJc01 "has released a new walkthrough room, Wifi Hacking 101". The room's been out for 13 days now though
Yep, I got one via email. It's because it was reapproved @ocean reef
^
Was it removed and re-added or something?
Nope, rooms now require approval and mine came out just before. I think it was approved now and technically re released? @ocean reef
Oh gotcha, guess that means weβll be getting those notifications for all the older rooms too?
Only a few, it's just because of some minor updates that were made
Some of my rooms popped up like that since I made them cloneable
I think search is broken
Oof
Search for metasploit brings up my room
I updated the search yesterday - Ah you're talking about SEO?
yeah if a room is re-released, it will notify you π
@frosty cape nope, talking about room search
Searched metasploit
First few are relevant
Yeah thats right π
Rest are not
Next page
I only get 1 page
omg
Its really broken on FireFox
But searching Metsploit on FireFox gives me the same
Cross browser testing!
Thanks
Haha
Browser compatibility is a fun game.
Let's hope no one opens it on safari
Only supported in FireFox 68
Hi, the notification section doesn't quite sit properly when screen size is smaller (e.g. split screen) . Currently on a 13 inch display, with firefox split to the left half of screen.
That's an oof
Thanks! π
@covert kernel Ah really?
What seems to be the problem?
Just gets stuck?
Or it says Error?
@frosty cape yeah just immediate error
What does your console error say?
Bad request
What should I try?
Hmm, can you upload it to Google Drive
I will download it and upload it
I have not had any problems
So its a really weird bug
I will add it to my to-do list tho
Thanks for reporting it
ty x
<3 @frosty cape
for webappsec , is this by default or a bug happening when creating the user
Weird, no machine has been updated
So you're probably looking at the wrong place? Not sure though, I didn't make that room
|it happens when i press on create user ||
Isn't that LFI vulnerability?
Yep, since it's trying to open a stream. It definitely looks like LFI
@tribal creek
@frosty cape ignore previous bug reports, it wasnt a bug with the site I was just being stupid
Consistently getting a false positive CSRF warning when logging into the website on phone. Those are the same details I use on desktop with no problems.
Would you mind trying with another browser?
I've tested it and it seems to work for me - what is the one you're currently using?
Firefox just now. Will do π
Yep, looks like it's just Firefox. I've got it working in Brave, Opera, Duckduckgo and the 1password inbuilt browser.
Hm okay thanks
I will take a look and see if I can source the issue
What version of FireFox?
If the app details are to be believed, 68.4.1
Thank you
Weird, I haven't had that issue on Firefox mobile
Not sure if it's been suggested yet, but might we be able to update the pre-loaded Kali image or does it break something?
Its been suggested and is planned to be implemented soon @abstract bolt
@covert kernel thank you π
I've just developed a list of things I hit on when I start the box up
Going through ctf100 and I'm on Flag 56. Not sure if anyone else had this issue but ||secret.zip is an empty file for me||
On that note, I noticed that unzipping the ||429E.zip|| gives me ||need PK compat. v5.1 (can do v4.6)||. Going to do some digging but that may be my issue
Doesn't seem like it
Found my issue for anyone that may have something similar happen. ||It's not super obvious that the password from zip2john 429E.zip > hash; john hash results in a password that needs to be used to actually unzip the files. My machine did not run john properly with just "john hash" so I noticed that there is a password in one of the screenshots in teh write-up that is used here. After running 7z x 429E.zip, it prompted for a password which I then entered. This then put data in the files in Moreflag||
i think that's the point of @tawdry totem work
I'd agree if his write-up followed that extra information, mine was more of an issue with my machine not cracking passwords like it should. I blame the hardware on that point though
yeah, you should ask in the rooms help
because it seems like it was designed to be that way, imo
But it wasn't an issue of not knowing what to do
i understand that
It was a bug, but not on the room's end
did you use your own box?
For...
the task itself
Yes
Yeah, I got it all figured out. But going through all these CTFs and awesome rooms here I've realized that Parrot OS on a MacBook 2012 doesn't tend to crack hashes or passwords very well π
Not with that attitude
@rugged ermine @frosty cape for the love of all that is my ocd can you please align the email change button next to the email.
laptop
I will fix that ya
thnks my ocd thanks your great skill
Fixed locally, will be pushed inthe next update
click the "here" link? I should've highlighted
Hopefully it's not my end. Networks been weird today. Dead link is the least of my worries, you've got a great thing going on with the site. Can't wait to get into it.
@frosty cape how am I supposed to connect to https://tryhackme.com/room/introtox8664 ?
TryHackMe is a platform for learning and teaching cyber security.
@tribal knoll ```The username of the machine attached to the next task is tryhackme and the password is reismyfavl33t. To access the machine, SSH into it on port 22.
Here are a few things to note before beginning the room:```
it was in the intro
there is a user with 533572 points with 0 room solved, is it some testing or bug?
user testeptional.
Yeah that's Optional breaking THM @rotund wasp
@frosty cape I think you've been made aware of the exploit
@spiral flame thank you!
@frosty cape It was a PoC, pretty sure it was the private rooms exploit.
Thanks to @tribal knoll and @worthy stag for reporting this problem, I have rectified the issue and rolled back the users points.
Its also worth noting, I am rewarding both Sherlock and Optional for reporting this, rather than exploiting it to get #1 on the leaderboards (not that he needs it at place #2).
Thanks to everyone who points it out too. I can't trust any of you ey π
check again
we're back up
Just uploaded patch for THM
that's good, but when can we buy swag ?
So it will go down for 5 seconds
i want some stickers and a tshirt ;-;
So, I am going to do a "Level based shop" at 25k users.
What are we at now?
14.5k
xD
8cm*6cm ish
try turning it off and on again
I'm probably getting a defcon one otherwise
awww
6x8cm is smol
I'll make a bunch of cool merch, but at 25k users.
do the initial members ge something special ;-----;
Are we getting new levels soon?
loooool
I might add in 7 new levels
if that's the case we can't downgrade to get all ;-;
redo levels and put cool badges on the profile
borders i want to say
Oh right, around your avatar?

yeah, like, cool flex
but idk, might not be the best thing
you're the smart guy here, come up with something 1337
That would be awesome, I mean borders
Yiss. Anything to flex better
But i still don't agree with level based market @frosty cape . The people that higher levels won't be able to purchase the stuff they might like from lower levels
What about the ability of converting points into store currency to buy cool merch and we pay delivery?
?
High ranks will get access to more merch
Oh
I was thinking it's limited to the level
For level x you get 3 items and then when you progress you don't get access to those anymore you get a different set
Nah, so if you're level 1, you can get all basic & level 1 merch, level 2 gets you all of level 1, and the basic
hello. I can't access Attacktive Directory challange. When i click deploy, it doesn't deploy and give IP info. Instead Deploy button still lit when i refresh the page.
hmm, I think I might know why that is
I may need to re-create the VM for the box if it's true
white coloured font mr robot ?
i didnt figure out the white font hint mr robot ?
is the musicalstego still working? The link I got says the file is deleted
musicalstego works fine (just checked)
indeed, thanks
the hint for task 4.4 here is looking a bit odd
TryHackMe is a platform for learning and teaching cyber security.
@hazy stratus I have the same issue with the Attacktive Directory room, btw
hello there
am having some issues with task 4 in https://tryhackme.com/room/introtox8664
TryHackMe is a platform for learning and teaching cyber security.
i'm pretty sure the answer to #1 is 60 but it not correct and idk why
but also im big noob so it prob that
you might have more luck in #room-help
cool will do
@mossy willow Ah yes, I need to fix that bug
The answer format just tells you what the answer looks like
To get the formatting correct
I clarified it in general @frosty cape, I believe hes got it now
Thanks Paradox π
:)
Just a heads up that musicalstego's #4 accepts incorrect answers which messes with following tasks.
Didn't see a @pcmhdhp otherwise I'd ping the room creator
#2 on Steel Mountain.. I m going crazy, tried all I could think of and would appreciate a hint, assuming its not broken π
@arctic jolt #room-help
ty
evening
Good evening @covert kernel
π
@covert kernel does thou wish to report a bug
No I was having troubke cracking this password taking to long haha
Ab
Ah
If thou wishes for help #room-help is always avaliable :)
Hello. I cant deploy room in Attacktive Directory. It just wont boot up.
What do you mean? @rotund wasp - when you click deploy, does it just hang, do you get a machine IP?
@frosty cape . when i click deploy it just dont give me IP address, also if I refresh the page 'Deploy' buttom is still lit. When i click nothing same thing. I just subscribed thought maybe it will fix it π
I think I saw someone post about this before but this is the hint for Task 4 #4 on webappsec101.
Fixing tonight when back home thanks:)
This occurs for quite a few rooms with special characters in the hints
@frosty cape I have an idea as to why that might be, if it's the case you'll need to spin up a windows box for me
how can access OWASP Juice Shop after Doploy π©
@solar vapor Near the top of the room, there will be a box with a 10.10.x.x IP address. Connect to the THM VPN and then you can use that IP address in a browser etc
Where?
when use ip in browser
Head over to #site-support
@ocean reef that bug has been fixed
Kenobi room, question how much ports are open. The answer expects to run nmap without any args and not nmap -p-. If you do so there are more open ports
Ran nmap -sC-sV <ip> and it worked
@worthy stag yes. Thats what I am saying. If you omit p, it takes the default value (top ports). If you use -p- you scan all ports.
The questions asks how many ports are opened. It should ask how many are opened in a default nmap scan.
idk if it's a bug, but the linuxctf room has a mispelled file name and has the x-flag set but it's not an executable file
stealthcopterctfprimer1 Networking#8 has probably a bug: ||flag says spaces but solution requires _||
HA Joker CTF Task#18 command should print images, but doesn't
Can confirm, but it's intermittent
After a redeploy I had the images there
I think messing about with LXD might cause them to go missing
i just redeployed, same result, idk, will try again later
@olive drum Your Tor room - it's spelt "Tor", when I wrote a chapter of my book on Tor they got very (and I mean, overly aggressively) angry about it. While Tor acts as a privacy network now, its original purpose was for the use of "secure communication" and was created by the US Naval Research Labs for this purpose, released in public a few years later. Might be worth talking about bridge relays too (prevents censorship of Tor. As it is entirely open source you can block all known nodes (since Tor is not a fully P2P network, it has some centralised service name resolution servers (about 7 of them to be exact) and these contain the list of every known Tor node)).
For pentesting, Tor does not make at any point any way to hide you from the fact you are using Tor. To find out if someone is using Tor, you basically just need to ask them (its a bit more complicated, but the Tor devs have made it explicitly clear that they do not want to hide people using Tor
"makes all Tor users look the same." this is by far the most important aspect of Tor, and one that not many people understand. I like this!
"looking to hide their IP address" yes, assuming that you are connecting to a safe guard node (which you can prove)
other than that, great room π
@vocal raptor There's a nice talk on it, there are private bridges that you can ask for
Which is how a lot of tor in china works
yes, i know :p you have to email using a yahoo email address too
to get them
or some wweird russian one iirc?
my uni has blocked tor
like completely
i have to use a vpn > tor if i want to use tor :p
sucks so much
i had an assignment on Tor, and i couldnt even access the website to read the white paper
its even more annoying because i live in uni halls and they don't block porn, gambling, nazi websites or the likes but do block Tor
((in fact tor is the only one they have blocked that i have found so far))
Oh really?
Yea
Can shoot over a DM if you want
I think it's a little more srs than I thought but not too bad
@frosty cape
its my first time using it
and firefox is telling me that it's having trouble connecting
I know my openVPN is good
and so is my IP
is anyone else having these issues?
OpenVPN room, go try it @tawny halo
?
It might be that the VM doesn't run a webserver. Or doesn't on port 80. Or it hasn't started yet. Many reasons
There's a room for getting everything working and making sure it's all good
I'm using the webgramming room
The OpenVPN room.
TryHackMe is a platform for learning and teaching cyber security.
Thanks for suggesting that James
Idk ports etc for webgramming but iirc it's seperate challenges so it's unlikely to use standard ports.
hmm
the access page says I'm all good
but when I try to curl into my ip onto port 21001
it says access denied
rather connection refuse
wait wut
now its working
hmm
weird
actually
it seems like the connection keeps cutting
@frosty cape In our adventure to get me removed from /room/gamezone before I was subscribed, I think we broke it for now that I'm subscribed...
@vocal raptor Thanks for the information! Ye you right, obviously, Tor wouldnβt be so useful on the professional scale because even most of the websites nowadays can detect that you are using Tor and simply blacklist you.
@ocean reef You're now unbanned from the room π
lol
bug confirmed
π
@frosty cape the icons and names are the other way round π
TryHackMe is a platform for learning and teaching cyber security.
Fixed
Thanks for letting me know
cheerio
Potential bug in gamezone. On Task 4 #2, going through using john atm. Unzipped john and ran ||john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt --format=Raw-SHA256|| but getting ||Warning: invalid UTF-8 seen reading /usr/share/wordlists/rockyou.txt|| it then fails to find the password. Also had ||sqlmap attempts to crack the hash with /usr/share/wordlists/rockyou.txt which also failed||
Anyone able to test it? Using the kali VM for this
Invalid utf is a known thing
It's a bug with rockyou
But it worked for me, idk if that's the right format?
Try Crackstation
hi
@spiral flame Mind if I DM you about the rockyou stuff real quick?
For anyone that cares, apparently rockyou.txt.gz works with Hydra, though rockyou.txt.gz won't work with hashcat/john π
just tar -xvf rockyou.txt.gz done
works with everything after
but yeah hydra will take a txt.gz
Have something big that needs attention
like thic with three c's juicy
https://tryhackme.com/room/attacktivedirectory bug - VMs not booting
TryHackMe is a platform for learning and teaching cyber security.
@hazy stratus I'm assuming it's your room by the name?
^^ yeah
@frail vessel @worthy stag Thank you for finding and reporting the stored XSS vulnerability. This has now been fixed.
As a way to say thank you and be transparent to our community, I would like to publically award you a bug bounty for reporting this safely.
The entire site right now
Can you both email ben@tryhackme.com with your username's and method to pay you (PayPal address or debit/credit card)
The question is, do I get bug hunter yet? π’
TryHackMe is a platform for learning and teaching cyber security.
Congrats Optional β€οΈ
β€οΈ
Grats haha
At this point, I think I should be in #site-bugs . Alfred Task 3 #4 says to find root.txt in C:\Windows\System32\config\ however it doesn't exist.
Tried ||search -d C:\Windows\System32\config\ -r recurse -f root.txt as well as -f *.txt. Both find nothing.|| Lastly tried doing a recursive search from just C:\ and found nothing as well
@ocean reef ah, yes. I remember this.
I don't think you have permissions to view it without migrating process.
It's there.
@ocean reef yep, I remembered it
Well thank you for that, did not realize running as system in one process =/= same privs as system in another process
@ocean reef yep it's a bit weird
@tribal knoll rip the images in task 3 https://tryhackme.com/room/runcescape
TryHackMe is a platform for learning and teaching cyber security.
im having issues with the blue machine port 445 seems to be filtered
TryHackMe is a platform for learning and teaching cyber security.
just one question
why does such a room still exist?
Ah, in the past anyone could release a room without it being reviewed
Now that all public rooms are reviewed before going public
ah okay
nice
np :)
and another question, i see, i can leave rooms with "Options" on the top right
but i joined a random room and it appeared to be paid-only
and i can't leave it now, as i get redirected to /why-subscribe with 302 immediately
You couldn't have joined if you were't subscribed
weird
But that's a known thing that @frosty cape was meant to fix lol
You can join if you arenβt a sub @spiral flame just need the room code
@worthy stag but i can't leave it anymore?
Well that sounds like it needs fixing
Yeah I had this issue a while back
when creating a kali instance it hangs when i select UK keyboard
hello rowbot
Kali machine freezes when keyboard layout selected
Join random room, stop non-vip users joining vip rooms.
On my to-do list
<3
there are btw at least 2 buggy rooms, idk if there is some official bug tracker or something?
It's been discussed
When creating a task, if you don't assign to a room, click "create task" you get this error. If you then try to assign it to a room, it is impossible to click "create task"
Which I'm slightly salty that my 30 mins of work was deleted because I had to refresh the page as there was no way to click "create task" once you have selected a roon ;-;
My process for creating content involves typing it up elsewhere first
@vocal raptor I am so sorry about that! Putting that to the top of my to-do list
anyone else not seeing a way to enroll in the oscp path under tryhackme.com/paths?
i'm just seeing red/blue primer series like always
If you're already enrolled in the primer series then you won't be able to see any of the other paths. That might be it @tidal kiln?
yep, once i left i was able to see other paths
also on torforbeginners room, the onion site listed in #3.3 appears to be down
Vm's that I deploy seem to stop responding after 1 hour
edit: and shutdown
Re-opening the vm solves this issue
@tidal kiln people were reporting that, but at the same time other people reported it was ok
@ornate moss yes, intended behaviour. Unless you extend them, they die.
yea but it shoud expire 12 hours from when I launch it right?
if not then thats also a bug
@ornate moss you get an expiration time once you deploy. Itβs one hour and you can instantly extend for another hour.
Not sure where you found 12 hours
It goes off your virtual machines time so chances are thatβs off
Intended behaviour is one hour
yea that is weird
I usually get about 300ms when pinging the vms so maybe that could be a factor
@ornate moss it just means the time it's displaying is in the wrong timezone
@frosty cape we got another timezone bug
Why is the leader board all screwed up. Completing rooms only changes the overall leaderboard. Not the leader board for the month?
@fossil haven monthly leaderboard is now only boxes released this month
@worthy stag how do you filter by month
That isn't a thing but is a great idea to add
@worthy stag it seems like the only way to know if they are in the current month is to click on them. The task will show the posted date.
Would be nice to have a filter option a user clicks on hacktivities though
mmmmmm
Have recommended in #544951750801752079 as it would make logical sense
the feature has only been configured this way since today so it's fresh so will require development
but will be better in the long run
@worthy stag just thought it was a bug because it seems like there isn't any docs for the leader board. Unless I'm blind. Will post there in the future for ideas
anyone having problems with the vpn?
Unroutable control packet received from [AF_INET]18.202.129.195:1194 (si=3 op=P_CONTROL_V1)
Sorted it over in #522158404614225920 @frosty cape. There were multiple VPN connections open simultaneously.
@frosty cape having trouble uploading a .jpg for a task, been trying for quite some time. Maybe 20 - 30 uploads attempted. I keep on getting "An error occured. Please refresh the page and try again."
its a 36kb .jpeg file
@vocal raptor why not host on imgur?
Because I really don't want Google to index it
Unless there's something on Imgur for that haha
actually wait i can just use github i guess
can always just title it something really obscure and it won't affect it
github works too but can be indexed if it becomes popular
yeah it'll still index π¦
maybe thm will accept a zip folder
Nope π¦ Maybe my uni is blocking uploading to thm or something
i cant upload anything at all π¦
VPN?
haha its ok π
and i did just try on a vpn
my uni blocks so much it wouldnt surprise me if they blocked uploading to thm
can't even access the tor white paper which is needed for an assignment ππ
@vocal raptor
Try upload again
Fixed it
omg lol
Deploy Kali machine at uni
Then you have no restrictions
starts typing essay in cherry tree
kali machine terminates
omegalul
When you click on order by, set to newest. click on a room, then press back button it is still "order by newest" however what is on the screen is the default most popular and you can no longer "order by" unless you refresh
can anyone help with an issue deploying my machine?
Sure, lets move over to #site-support
Is this abnormal or am I missing something?
Adding code snippets to a new room.
Yeah thats weord hm
I mean, definitely not a huge problem or anything, but slightly amusing nonetheless.
EDIT: nevermind π
Not a bug
Got another one, @frosty cape
Not sure precisely what caused it, although I could hazard a guess if pushed.
Wait, what room?
That's one I'm working on. Just a preview, but it's doing the same thing in the task editor
If you have an exploit for that sudo vuln, DM me
Not yet -- only the proof of concept, same as you. I saw the conversation you had in #room-ideas earlier. I'm writing up the theory just now, and testing the POC when I get access to VMware in a bit. Waiting for the exploit before submitting though.
If you find a working exploit, my DMs are open.
Likewise. It's a full root shell you're going for, yeah?
Command execution as root, via that vuln
Doesn't matter if it's full shell etc, you could pop a rev shell or something probably
Fair enough, sorry - misread what you said earlier!
Have you tried the POC by the way?
It's just a segfault
Just looked at the exploit-db entry: so it is.
Handy.
I'll keep an eye out for a working exploit. Let us know if you find one too
I'll keep looking
My mistake, being a tad blind. Could someone add a space between Level and the level number please?
Firefox CSS for dashboard is also off, looks somewhat different in Chrome
Cheers, for a second I thought the level said 110 and 111, would have been awesome to be that high haha
Aha, I'll change it
Hey guys
Seems to be a bug with the leaderboards. I thought they changed it so that the monthly leaderboard would only count points earned from rooms released during that month. The scores on the monthly leaderboard are much more than the total points you can earn from the rooms released this month so far. Unless that change has not been made.
Hi @flat maple read "How points work" https://tryhackme.com/faq
TryHackMe is a platform for learning and teaching cyber security.
Essentially, for the monthly leaderboard, you get points for new challenges 100%, old challenges 25%, new walkthroughs 25%
Hope that clears your question up
Hi @winged abyss π
Hi @frosty cape π
@frosty cape Thanks for the link, was missing the last part of the info about old rooms still counting but for 25%
Yeah, no worries
@sly raft
@topaz venture thanks for a wonderful room on Jupyter! I found a small mistake tho. It the room [Task 8] it says "navigate to task 8 directory", while on the server it appers to be named "task 7". It doesn't affect anything significantly, just a small typo
Thank you @olive drum! Slight oversight. I'm going over it all with a fresh pair of eyes π

Renamed all the directories to a much more logical sense, re-uploaded the VM and reflected these changes in the rooms' tasks. Thanks for spotting @olive drum o/
@covert kernel I believe you are the creator of customwordlists. I am having issues with getting results, not sure why, fcrackzip fails to find a password. zip2john gives an error. when trying to use unzip I get oot@kali:~/Downloads/Flags_Part1# unzip flag1.txt.zip
Archive: flag1.txt.zip
skipping: flag1.txt need PK compat. v5.1 (can do v4.6)
zip2john
ver 81.9 flag1.txt.zip/flag1.txt is not encrypted, or stored with non-handled compression type
DM me with more information @kind flint
@olive drum Onion link on 'TOR for beginners' down. Hope it getΒ΄s back up soon. Thanks!
It is not down! working fine
Just try pressing Ctrl+L do build a new connection and youβll see it @fickle locust
Yeah working perfectly now, thanks! @olive drum
Np 
there is a badge for this section not listed , LINUX badge
It doesn't list any badges, those are seperate?
for example in this section i get burp badge
@deft jackal We're re-doing the beginner path, so ignore the badge bit for now
it is showing the new room twice
They're different rooms
@olive drum did wonder about that. It's because they're the same series. I think I'll change the colour in one of them
@orchid remnant Yeah different colours would be cool
There we go!
Perf
Oh it's not sorry, I competed your room then reset my progress
So it's displaying as a completed ueer
Interesting
i saw this today in my email when one of the guys i know left my team
should be "You lost a member"
Ahh good spot
I want to re-do teams at some point
I am not a fan of how its created on profiles
I want there to be a team panel
And there be a team leaderboard etc..
2020 Team Rebrand π
Yeah that would be great and maybe for now just up the amount of members we can have in a team lol its restrcted to four and there is 6 of us in total that wanna get in to a team together π thank you!
TMUX room just seen it says "up" rather than "us"
https://blog.tryhackme.com/company/hackback2019.html/ doesn't work @frosty cape
Oh right, where are you getting that link from?
hackback2019
Is that a bug? The user points > rank points. Guessing highest rank with points so it can't update any higher
Yeah it's not a bug. It'll just grow now @urban flame
Added an idea submission based on that post, could be something cool
Makes it more competitive
Updated, will be live soon
@frosty cape IΒ΄ve completed the blue machine and didnΒ΄t get the badge
@fickle locust that happens with some rooms, if you have completed the room before the badge was released, it won't update
@frosty cape, that's defo one to fix, especially as profile badges are a thing now π
Okay cheers
I think I'm missing 4 or 5 atm
Ill write a script to check every user this weekend π
a
Hi guys, I just want to ask you about room Blue.. There is not possible to run exploit ms17_010_eternalblue. Every try ends with
[+] 10.10.135.179:445 - ETERNALBLUE overwrite completed successfully (0xC000000D)!
[] 10.10.135.179:445 - Sending egg to corrupted connection.
[] 10.10.135.179:445 - Triggering free of corrupted buffer.
[-] 10.10.135.179:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.10.135.179:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=FAIL-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.10.135.179:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[*] Exploit completed, but no session was created.
Do you know how to configure vpn/metasploit to work this exploit?
@covert kernel Yeah it's a dodgy exploit
Try updating msf
Or the THM kali machine if you can
I went through 3 kali installs for it
Hi, this machine is not deploying right, it only says that it's deployed but it doesn't start, I've been waiting for an hour, I also tried yesterday
Hehe. All this time and that's still catching people out.
@kind compass it's working just fine. That machine blocks ICMP requests -- it's got a firewall on it.
Try adding -Pn to your nmap scan π
@orchid remnant Hahahaha OMG!!! I'll never forget this I promise, thank you
Hehe, You're welcome π
Now we know the request type and have a URL for the login form, we can get started brute-forcing an account.
Run the following command but fill in the blanks:
hydra -l <username> -P /usr/share/wordlists/<wordlist> <ip> http-post-form
Guess a username, choose a password wordlist and gain credentials to a user account!
thats not how you brute a website login from what i am seeing. it spits out 2 errors when done in exactly that format just wanted to post here
@acoustic saddle fill in the blanks and it should work
@acoustic saddle I'm heading into a lecture in about half an hour, but if you DM me with exactly what you're trying I'll give you a nudge in the right direction.
having trouble getting to websites in Kali VM tonight. can't apt install stuff, can't browse to google.com
anyone else?
the internet is disabled until tomorrow i think
ahh yes, turning off the ol' internet switch
I have this issues when use multi/http/struts2_content_type_ognl to exploit CVE-2017-5638
--->> [-] Exploit aborted due to failure: bad-config: Server returned HTTP 404, please double check TARGETURI
help me please
I set it TARGETURI /struts2-showcase/
Wrong chat, but loads of people are from UoP @timid locust
Which chat then?
Thanks
@frosty cape your THM emails are going to spam on Protonmail:
This email has failed its domain's authentication requirements. It may be spoofed or improperly forwarded!
"Learn more"
Specifically, Proton thinks you failed one of these:
(SPF, DKIM, or DMARC
really
Athays strange
**that's
will check it out later today - thanks for flagging it :)
Idk if its causing it cause protonmail lists 3 things it doesnt like about this email, but the email authentication stuff is in red so
As far as I know, we have our domain Auth done properly