#site-bugs
1 messages Β· Page 10 of 1
When i login sometimes its just redirecting me to /notifications/get page w
That's been fixed, patch is being pushed soon iirc @trail egret
π
Thanks for pointing that out! I'll fix it now! @rose kettle
@rugged ermine https://tryhackme.com/room/bpvolatility#
wat
Microsoft Window's
Fair enough.. :D
so basicly I reinstalled my OS
and I didn't forget to reinstall OpenVPN too
but whenever I deploy a machine it instantly times it out and terminates it
the menu is still there and it will go <ip> 00:0-9/-37 etc add more time terminate
As in deploying a machine on THM via the "Deploy" button on the website?
Is there any room in particular, or are you finding that across all rooms? I've been able to deploy all afternoon
Well hello there
we meet again haha
Mhm, sounds more like an issue on your side of things. Sorry to bounce you around, but shall we move to #site-support and investigate?
no probie
thank you!
Another one of my rooms too π @torn wedge
re-occuring theme here @covert kernel π
;)
Hi everyone, can someone help me? Idk if this is the right channel to ask something haha
sounds like it's either #site-support or #room-help you're after :)
Okay thank you
@covert kernel Wrong channel
Hi, Glitch on windows server 2016, hhupd.exe
If that's the web browsers not showing up
It's intended
Fixing it is part of the challenge
@orchid remnant tnx
s
what does it say after you run the binary?
Segmentation fault (core dumped)
sorry i'm quite new to this, so i'm probably the the wrong channell
please ignore my message
it's okay @deft pawn happens to the best of us
XSS-Playground- advises that you don't need the VPN but it seems to provide you with a private IP address
@frosty cape shouldn't it be like.
- Your rank
- You are ranked
Nah this works grammar wise
"you are rank number 22" is correct English c:
Mhm
For it to be "You are ranked", it would have to read "You are ranked 22nd"
is it me or the VM's are so slow
i got good connection but it keeps getting disconnected
@velvet siren probably just you, but this is a #site-support issue
ok, i just subscribed, my bad
hi
@icy tendon Wrong chat
Hi guys can anyone help me with the room hydra?
@covert flint Also wrong chat
@spiral flame sorry buddy
Hello.. I'm again in introtox8664 room..
i want to tell a typo at task 4.
"Run the command: px @rbp-04x" instead of "px @rbp-0x4"
I think it's not a big deal, but it's takes me a lot of re-reading to understand, due I'm new at dissasambling...also it's no a bad idea to add a picture of the output of the command, 'cause in this part we need to learn how to read that output. (where the value 4 is)
Hi all, total newbie. having issue with the beginner 'learn Linux' task getting putty to run. keeps giving me network error when I try to run shiba1@10.10.87.26...? any ideas. appreciate it
@timid arrow are you connected to the vpn
ahh no... sorry must have missed that
Do you know how to do that?
No, a vpn is a virtual private network
It allows you to access all of thm's machines
People on windows use openvpn gui
legend
Then on THM
You go to Access
Download you're configuration file
And import it into openvpn
Then hit connect and you're good :)
cheers pal
@timid arrow np, if you need any more help with the vpn ask in #site-support as this channel is for bugs
great thanks
Not sure if a bug, but in room/rppsempire task5 #8, since we are attacking a windows machine I think the correct module should be powershell/trollsploit/thunderstruck instead of python/trollsploit/osx/thunderstruck
Also in the same room in task3 #7 In newer versions of Empire (Im on 3.1.2) the option "serverVersion" is now called "headers"
Hello
I'm new to the site and to hacking..... I was wondering where to start, I have done a few assigments on overthewire.org - bandit but that's it.
Not in #site-bugs π
Switch over to #general, I'll point you in the right direction there π
https://tryhackme.com/room/sqli
some of the mesage boxes arent showing up
TryHackMe is an online platform for learning and teaching cyber security.
Helo
Hello .In the rpnmap room i trried to scan with the SYN TCP but the output is : all the 1000 ports are filtered (even with the ACK TCP scan )
Are you VPN'd?
yes but i'm using windows 10 with the openvpn
Nmap on windows with the VPN has been dodgy for some people
Maybe try running as an administrator?
This isn't a bug
ok thnks
can someone help me on a question in the metasploit room?
#room-help my friend @lean shale π
Hi everyone. I am new in discord as well as this forum. Hope you'll help me like your friend.
Hey! @covert kernel, come join us in #general / #thm-community-media though
Ok. CMNatic. Thanks.
Whats the time since boot?
4-5 mins
Whats the IP
Hold up I just deployed it again
If it happens again, give me the IP plz
10.10.249.161
Yeah it happened again
yh
It should have enough resources to boot quicker.
Don't terminate, let me investigate:)
ok
ok thanks
Hi i am new here and i am facing an extremely beginner problem
sorry should i put that hash in my line of msg
go over to #room-help and ask there
just put room name, question and task
Thanks alot
hey sorry guys if this is a stupid question, how do I make the vm's "less laggy"? does paying subscription make it smoother?
Which VM are you referring to? @frail slate
Subscription gives your VMs more resources
im currently doing learn linux room and there is a very slight lag when typing. might just be me being picky though haha
@spiral flame Yeah thanks. just wanted know.
how very slight? It might just be because you're far away from the VM
that could be your connection yeah
hello im stuck in day 10 can anyone help
metasploit seems to run exploit but no seession
or atleast can anyone tell me where i can get help
Is the RP:Nessus room bugged? It's not accepting my answer for #7 and I'm pretty sure it's correct. Unless this is better for the rooms-help menu?
@hazy jolt DM me your answer, Nessus is uh
Yea
nessus keeps changing version detection week by week it seems
Ah
@atomic prism What's up?
something about my account
That'll be a @frosty cape problem then
@frosty cape
Give him a minute π
He'll get back to you here, I'm sure. If it needs a DM then he'll offer that, but please don't go breaking rule 1 for it π
okay thank you for your help
Np
@atomic prism you got locked out?
yea some login problems nd man i been working hard for the account
@frosty cape yea i got some problems with that , can i have a private chat please.
i don't like talking about creds in here
sure m not doing that
Can you please email support@tryhackme.com
With your username & email
And I will investigate
okay thank you
but can we go private to explain one more thing or i should send it with mail
All within the email if possible
if its hard to explain, then sure DM
otherwise please email:)
if you send it now, 2 mins + time taken to investigate the issue
okay m working on it
@rugged ermine -- is there supposed to be a VM for RP: tmux?
DVWA is attached, but I'm not actually finding any reference to it in the room.
There is not
I use that VM as an example for if we wanted to scan and change tabs
if I'm remembering correctly
Ah, fair enough π
So has the one on socials I think
The new one seems to work
That one is outdated definitely
Not sure when it was last changed
Maybe a tryhackme.com/discord link that you can then use to forward on to the discord link?
^ yeah thats a good idea
So has the one on socials I think
@worthy stag nope the one on socials works
Meh didnβt need a ping
sorry it was the quote
@marble sparrow Wrong chat.
The search bug still exists, if you start typing before the rooms load it seems to break search until you reload
tried chrome and FF
Have replicated that on ff
The search bug still exists, if you start typing before the rooms load it seems to break search until you reload
@spiral flame In hacktivities or my rooms?
Ill fix:)
Hi has anyone done the Linux Challenge Flag 17? Been stuck on this one and the answer from the write up doesn't seem to align with the task given
@frail slate I'll look at it tomorrow. It's almost 4am - off to bed π΄
Just a heads up, I completed the HA Joker CTF but I sort of cheated at the end. The lxc container disappeared for no apparent reason after I ran the list command. I knew what I had to do from researching but no clue why it happened and didn't want to start over again.
The room was created by ki11switch
quick question how can I open the machine on a mack , I'm connected to tryhackme.com through open vpn already
timezone problem i think
@covert kernel being fixed today:)
cool
how am i supposed to access the shadow file if the user in challenge 4 (Advent of Cyber) hasn't got the permission?
@carmine vortex donβt ask in every channel if you donβt get a response be patient
I am stuck on Intro to Malware Analysis
room - malwareanalysisprimer
Task 14 > #3 Output the strings using Sysinternals "strings" tool.
What is the last string outputted ?
@jaunty mantle #room-help
Good Afternoon. Appears as though I've been charged twice this afternoon, any else have same issue and could admin take a look?
@frosty cape
@simple lava I did as well today.
Skidy is around, he'll sort it for you I'm sure
hi, could it be a bug, or i have to find a workaround for this? thank in advance!
Corp room
Sorted, weird payment dup bug. Fixed now.
I'm curious how many it affected
sorry it wasnt a bug, explorer exe, and runas from cmd did not work, but found another solution!:)
@frosty cape do we get refunded for the double payment or what?
new to discord , how do i add this seerver to my pc discord?
Add it to the user that you use to log into discord on your pc, then log in on the pc
also, next time ask in #site-support ;)
k , thanx and sorry :0
No worries
@crystal escarp all dup payments were refunded yes
Thanks
Have a small remark concerning blue box
our latest push may have messed a few things up
We're fixing currently
Development build works
Gotta love errors that only happen in prod
Read the last couple messages, @covert kernel :)
I doubt it'll take that long, but sure ;)
@frosty cape seems like it's fixed now. At least the issue I had.
Great response time.
ty, lots of problems you dont see still going on:)
So stay tuned
The load balancer gave me some unexpected problems
Tsk. Too many things pushed all at once :D
π
Hey in the linuxctf room for flag 17 it says you have to login to alice's account but || you can literally just cat the file without login into her account|| idk if it was ment this way but it doesn't seem so to me
Could you link the room?
yup that one
I suppose that's a bug, yes. A minor one, but a bug none the less
well, discoverer :p
well its easy solve just chmod the file to not give perms to everyone
not I am exterminator
Unlikely to get fixed though
Figures
true, its rly small bug
@frosty cape This one is on you
Nah, that room has just been broken for a while...
Bunch of stuff that needs fixed in it
I vote that it gets replaced with ZTH Linux in paths etc
Agreed
Skidys pushing a fix for that soon
alrighty
After he fixes the last push...
I assume the broken push had the fix in it
Presumably
What is a push if it doesn't fix a bug from the previous push
A push that breaks everything else?
a broken push :^)
not a push of code, I'd say.
What's a push if it doesn't create 10 new bugs?
Where else would you push too
what, push to prod? I don't use git.
thm-prod π
test in prod
This might no longer be a #site-bugs conversation..
debug in prod. Users can handle a little extra info
404 alternatives branches then "master" kekw
...mmmmaybe, Muri
Just have one of your files have a hidden rce
So you can debug while others are using the site
And boot 0day in case he finds it...
Haha
@visual oasis do you still get a broken expiry time?
maybe in 20 minutes again but not rn
I refreshed
but that image was posted as soon as I got the bug
had the same thing @visual oasis but I just had to refresh
ye same
its an easy fix wityhout any real consequences but still looks kinda funny
Also, I am pretty sure its caused by an overflow (where a number becomes to small or to large vcausing it to flip to the opposite side)
@worthy stag after awhile it will fix itself
Still a bug regardless
also wasn't me I always report on behalf of anyone who is with the university of Portsmouth
Kali room on google chrome
@worthy stag oooff
I can't replicate that error, its not based on timezones anymore
So confusing how its that large
is there a reason all these font sizes are different
or am I losing my vision
or both
Hey, I've got stucked in
RP: Metasploit Task 5. Can anyone help me, please?
@white sapphire #room-help
Hello
Learn Linux machine on firefox
mghrba finma mchaw nl9ahom haha
will fix today :))
hey guys, im trying to get the student discount, i used my student email but i still get the normal price
Official documentation site for TryHackMe
thanks! ill read it
what is it then?
@alumnos.upm.es
yeah, that's an interesting email address haha
but in spain all the universities use that format
yeah, TryHackMe started in UK so it covers most of the uk uni email addresses
it's quite hard to build a comprehensive list when you don't have requirements
right..
but yeah, just drop them an email
Cool! thanks!
they should be able to sort it out
Maybe they should verify you have github student pack, something like that
@frosty cape are you planning to add more university domains to the student discount?
maybe just verify it login in with github, just dropping some ideas
if you have ideas feel free to drop them in the #544951750801752079
or spotify π€£
if you have ideas feel free to drop them in the #544951750801752079
@rare swallow wi'll do!
you can't really verify that with spotify
you get the discount but it doesn't say anything about the status of you student
on spotify?
every year you need to verify it
lol, i haven't been asked to and yes i am a student
oh, i havent been on github as student for a year, only spotify
yeah, both of them don't check me up for whatever reason π also we are moving away from the purpose of the room
π im going to write the email
perfecto @woven iron ! Happy hacking! you can still use the free rooms until you get your subscription
Thanks! take care!
you too, cheers
I'm following a walk-through of advent of cyber and the cookie manipulation doesn't work can any-one help me
Leaving a room should terminate all deployed machines
@undone parrot make sure you don't have a 7 in your fixed value. If you haven't got that far, go to #room-help
the new survey appears restricted
or click the link again if that doesn't work
uhhh
is missing the sidebar on articles now, is this quite literally a feature or a bug?
Official documentation site for TryHackMe
If not, I'll raise it in the GitHub
@near mason has just seen this, think he is on it
Okay no worries, cheers @frosty cape (and Matt, don't want to un-necessarily ping)
@topaz venture @frosty cape all fixed...will add cypress tests to aid in preventing regressions like that future
Top man @near mason !
Hey, I've found interesting feature on https://tryhackme.com/room/blue machine timer
after adding 1h it just dissapeared
we'll be pushing a fix for this
I'd would not say this is a bug but https://tryhackme.com/getting-started gives me a 404 when I click the link to figure out how to connect to the network
!vpn is the new one fo rit
@wind tree where are you seeing the getting-started link?
ROOM : https://tryhackme.com/room/25daysofchristmas#
[Task 8] [Day 3] Evil Elf
i am trying to download this network capture file, but it's too slow and it will cancel itself... Failed - Network error.
my internet is fine and i have already tried to download it from different browser,
The problem comes from me or it's a bug ?
I use a VPN and it's fine i got it, thank you @olive drum
please help with this Who is the employee of the month?
room: steel mountain
@pale remnant Wrong chat. #room-hints and there's a hint on the question
the "your" on https://tryhackme.com/room/zthlinux
It's not a bug it's a feature @lofty mason
xddddd
FIX IT
@covert kernel Fix it or I get skidy to ban you. Typos are no longer allowed in rooms as an official note
Typos and bad grammar will get a room rejected
Any issue.
@covert kernel typos and grammar issues come first.
Man's got his priorities straight! ^^
You ever heard of Lord Timothy Dexter @spiral flame
He wrote a book which people critzed for being filled with grammar mistakes
So he released a second edition
On the last page of the second edition he put a bunch of commas, apostrophes and other various punctuation marks
And said "put them where they belong yourself"
@covert kernel just you're
I know I know I'm fixing it
ahh okie
In burp v2020.1 intruder module, a . in a payload will be escaped, which means that the list in https://tryhackme.com/room/vulnversity task 3 q3 doesn't work. You can easily get around it, but it may be worth updating the text, as the room's supposed to be introductory material
In addition to the above, in task4q5 i believe the correct answer does not match the reality on the vm. The 4-letter answer which I'm not going to say is not what appears in whoami or id after the reverse shell is started. Instead you get the user, www-data.
@spiral flame sorry bud my fault i was using the wrong name π π π€£
hello guys, would you help me with a problemm
Sounds like #room-help, @lofty tree :) Not a bug.
ty
in plethora ctf i can register in juice shop, the register button doesn't work
@covert kernel 1) Wrong channel
2) The entire server is full of hackers...
What are you after?
@orchid remnant pls hak fac3b00k
NASA html hacking 101 π
@orchid remnant I am after a professional hacker
@covert kernel Hi, please read rule 9 and stop asking. We don't do that here.
This isn't the channel, and that's unlikely
true
wtf where do I read the rule
For some reason, when I went to a room with an invalid code without being signed in, I got redirected to Why Subscribe. Subscribing wouldn't have fixed the 404
Changing the filter on the hacktivities while in a page greater than the filtered results breaks the numbering of the pages
Intro to x86-64 what is the ssh password
@pure holly Wrong chat. Read the task
@spiral flame ive read it
@pure holly 100% you haven't, I just found it immediately
Guys which is the cheapest usb adapter for Kali Linux
@covert kernel That's gonna depend on your area -- try researching it
Also, not #site-bugs π
sorry lol
Hello i cant downlow the pcap file from day 3 of advent cyber room eny help ?
#site-support @unborn arch
Sorry im new
@ornate moss run nmap as admin
@red kayak Its a bug with the add time feature. Might be a timezone issue π
@ornate moss That shouldn't be an issue anymre
It should update
Does any error message appear when you click it?
No I would add another hour but the box wont be active anymore
Ill try and re-produce it again
ty
hey, I noticed that I would need to generate a new config file in order to connect to the network. however after trying to load it I get the following
so it says that its failed
any ideas?
but it worked before all the time
no TAP adapters
"what do you mean you have to unclog the pipes? They worked just fine!" :p
Hi guys, i am following the linux tutorial, this question is not clear to me: How do you specify which shell is used when you login? Any ideas?
#room-help @brazen crystal
i got a technical issue with willow.
hello,on room tomghost ,i need to decrypt the pgp ,i already have the passphrase to decrypt it but when i do pgp --decrypt file.pgp it doesnt asks me for a passphrase to insert it gives me "no secret key " any ideas,i tryid googling first?
Wrong channel
ups
When I open up the learn Linux room in hacktivites it opens the room fine however when I open the learn Linux room in my rooms it shows the why subscribe page
@cinder crow there's multiple Linux rooms
zthlinux
Hi all
in task 26 basic linux: are there issues with the answer field when checking for the answers?
@cinder crow yeah it's possible your clicking on the other Linux rooms
@lunar sierra how so?
the questions are: What flag deletes every file in a directory and
How do you suppress all warning prompts
but when i provide the answer it says its wrong
spoiler tags?
||answer||
gotcha ||-r and -f||
jajajaj
lol
And messed up two answers?!
thats OK
dammit pars
I blame thm
every one makes mistakes
I didn't touch the answer field
jajajajaja
I'm curious what they got set too tho
What the fuck
Pars is the dev
Uh.....
jajajaja code mistake
I blame thm for that
@frosty cape?....
Answer fields getting swapped around?...
blame who?
TryHackMe
Mhm π
yup, up and functioning
hey
Hello, pictures are not uploaded in the training videos?
Ohh alright
i have having error while doing nmap scan , it is showing --Host seems down. If it is really up, but blocking our ping probes , what to do?
hmm, what box are you talking about?
i have kali linux
no, what host are you scanning
the Vulnversity one
you conected to the vpn?
did you add -Pn to your nmap scan?
yes , it is showing same
Nmap scan report for 10.10.188.178
Host is up.
All 1000 scanned ports on 10.10.188.178 are filtered
try -p-
can u write the full nmap line
man nmap - plus it's not a bug, you need to invest some time looking at the commands you need
you'll benefit out of it more than me providing you with the command
depends on the box, usually 2-3 minutes as it takes some time for the services to start, but max 5
give it a go ^^ but go for #room-help and #room-hints if you need more assistance, this is not a bug. i will give you a hand over there
okk , thank u
Hi, i have a problem. When i bought my subsciption TryHackMe took the money twice. I got -10usd and -10usd. Where i should report this thing to get return? Thank you
@frosty cape
That's a known bug, fixed it and pushing the code live on 30 mins
Please email me and I will refund
Ok, thank you. Should i include: numbers of my card or any other information?
I'm curious why it happened :)
π³
@covert kernel Not a bug
@covert kernel that isn't a bug
hello, i believe the timer on https://tryhackme.com/room/webgramming final task is broken
it wont reset when submitting a valid string
"stuck on [1585666876148] msec" -- that's equivalent to 50 years lol
Anyone help with this question pls !
Entering enough data to make the application crash!
@deep wind #room-help
thanks for that @olive drum
Oops I was backwards
@celest bronze no 0day it's not worth it
I didn't realize I was looking at earlier
I can't find the a.txt in the learning linux room. is that a bug?
probably not. Ask in #room-help if you need help
ty
Ok you're gonna have to be more specific. And probably the wrong chat
just my thoughts here. so i just did joystick. i figured it would be hard like real hard because the rating is red. all i did was something easy and i got both flags.. it was prob one of the most easy box ive done so far. i know thats not quite a "bug" but i think others might try it if they knew it was easy, just trying to help here thats all!
Probably not the intended method?
But I'd argue that's a box spoiler and shouldn't be posted @acoustic saddle
fixed it
Thanks
idk, all i know was when i got in, both flags were just there in different dirs , kinda surprised me ...
np
who broke the site?
Sit tight guys. Ashu and Skidy will be asleep
Just refresh -- it'll sort itself out
They'll fix it in the morning
kk
welcome to the Degen Sleep Squad
send him a ctftime inv 
Confirmed Sk1dy is a sentient AI. No one is capable to test a PR, merge and push to live whilst asleep
except from @tribal knoll who just doesn't sleep
ever.
can someone help me with my VPN, i am unable to do HackerPark
#room-help @rare swallow π
Are room creators supposed to still have "Known Issues" access on the website?
Because, uh, I apparently do not
^ it's moved to under manage rooms π
i love this site... vpn is working but accessing machine "ignite" keeps timing out... I have VIP, is there a plan to speed up connect times?
As in, should I still be able to open an issue for someone else's room Ashu?
(zthlinux in this case)
@orchid remnant VIP will not effect the speed of connection/reliability will it?
It affects deployed machines -- gives them more power and speeds them up
Chances are that you've got more than one VPN open
no you shouldn't @orchid remnant
Ah, thanks Ashu π
Thank you!!! will test.. im sure thats the issue though... i was having issues with vpn initially
I've just found out on accident that one of the links under https://tryhackme.com/goals to one of the rooms is no longer working. In the fun category the Basic Steganography entry links to https://tryhackme.com/room/basicsteganography but there is only an error page there. I think https://tryhackme.com/room/basicsteganographyal would be the correct link.
@frosty cape -- any chance of you taking a look at the backend for 25daysofchristmas? Got a flag that I've confirmed to be correct (i.e. identical to my completed answer) that isn't being accepted. It's not got whitespace at either side. TryHackMe username is opkoli123
Discord Tag: @random lily
@frosty cape @sly raft i completed all flags on jurassic park machine however flag1 i cannot submit due to it saying its wrong
and it has to be the correct one
i can provide more info in DM
would redeploying a machine help ?
Hello. On Basic Steganography room, I can't submit the flag for challenge 3
same case of the jurassic park problem
This appears to be a recurring problem
Hopefully the admins have seen the pings and are working on it
I wonder if it's a platform issue or a room issue?
Koth page FAQs. 1v1's should read 1v1s as it's not a contraction and it doesn't show ownership
Hi
I found a bug in one of the rooms https://tryhackme.com/room/googledorking# task3 question 3
That's a me! What's up?
https://app.neilpatel.com/en/seo_analyzer/site_audit?domain=blog.cmnatic.co.uk&view=all reports a score of ||81||
Haha that's great I didn't expect an answer so quick
I thought this could crop up. Bare with me for one second if you may!
I don't think this is a good question as the result may vary depending if you make changes to your site or they update the seotool
Can you also put your answer in spoiler tags please by using || ||
We'll move out of here and maybe towards #522158404614225920 as there's no bug as it is - however I agree with your comments
@topaz venture how do I do the spoiler tags part
:^
modify your message and put what you said after I said "That's a me!" into those spoiler tags please
Gotcha
thanks!! - I'll catcha in #522158404614225920 π
What is the "correct" answer? so that I can complete the room and don't have to try all possible answers XD
Yes of course
for anyone looking back at this: no bug, no issue - contacted them to try and replicate issue. All is good :^
hello guya
Do you have a bug to report @oak hare ?
Unless you're about to report a bug, #general or #thm-community-media is probably better suited
It's a windows box
It ignores Ping requests
yes
and Yeah #room-help π
thank
very very minor bug on Task 23 in the ccpentesting room - the link to LinEnum has a left parentheses as part of the link. This will take an unsuspecting user to a 404 on github. pls disregard if this has been raised already. thx.
@covert kernel...
whistles
@frosty cape @Ashu i completed all flags on jurassic park machine however flag1 i cannot submit due to it saying its wrong
and it has to be the correct one
i can provide more info in DM
did u guys see this
They'll get to it. It's 3am british time now @mellow sorrel
Hello, on the hackpark room on task 4 #3 it is asking for the abnormal service running and I found it and its not accepting it
Can we get some further clarification / testing as towards Task 22 of AoC - Specifically Hydra for "mollys web password"
Had it come up on #room-help and the right steps produces the right answer (or at least it was when I completed the room on the day) but the flag isn't being accepted.
I remember Muirl coming across this the other day I think
Found a bug in the XSS Room, Task 7. As soon as I copy (the unmodified version of) the script into the comment field and hit submit, the Webserver will crash. Machine is still answering to Ping but the Webserver is dead. So Task 7 kills it for some reason. Tested it 3 times now to be sure - it is reproduceable
where are you submitting theo output of your keylogger?
is the room badly configured, awnser output somwhere unusual, maybe it can cause the webapp to dc from the db or smthin from its connection to a backend, idk
is it possible to modify the location that a( webserver/server/anything that can connect) sends/receive requests aka trick the connection ?
you cold try uploading the output to the log folder if you are currently using an ncat listener
that's what i've personally done
@rare swallow I only copied the unmodified script, it should output the logged keys to the console
hmm, fairs
βlet l = ""; // Variable to store key-strokes in
βdocument.onkeypress = function (e) { // Event to listen for key presses
βββl += e.key; // If user types, log it to the l variable
βββconsole.log(l); // update this line to post to your own server
β}
</script> ```
just paste this into the comment field, hit submit and it is gone
did you add your own webserver there?
according to the last comment it says to post the stuff to yours
the comment says Now you have this script, can you adapt it and post it into the stored xss page. Then start typing on that page and see it appear on the logs page.
so you could set up a simple python server locally and add the ip of it to the console.log()
for testing it, it should work to log to the console and not crash the webserver. you would need to change it have it log to MACHINE_IP/logs/ - that is the challenge
yeah, well you need to adapt it
if I remove the console.log(l) part, the server does not crash. but still this is weird behavior
I deliberately wanted to see if in the developers console
I think you misunderstand, when you run console.log() what ever inside the parenthesis (a string) is logged to the console
in the example the value of the variable l
oh gotcha
sorry, wasn't following it correctly
let me try it out in a bit and i will get back to you @smoky vortex
βlet l = ""; // Variable to store key-strokes in
βdocument.onkeypress = function (e) { // Event to listen for key presses
βββl += e.key; // If user types, log it to the l variable
βββdocument.location='/log/'+l;
β}
</script> ``` tested it like this and it still crashes - seems that as soon as it tries to access whatever is stored in the variable will make the server crash
will look into it in a bit ^^, pinky promise
no problem, just wanted to report it as a bug. thanks
I think there is a bug with the pickle Rick room
@abstract dove mind elaborating a little?
I have been struggling with it for the last few days so I decided to search a walkthrough for a hint but I don't get any result when I use the same command as used in the walkthroug
Which command?
Because ls -la/home/rick wont give any results
ls -la /home/rick
Or
ls -la/home/rick
Both do not work
Can you screenshot what's happening for me? π
That's Ok π
@covert kernel 150% sure this should say "noot"
Critical bug ^ Take site down until fixed
Take pars down until it's fixed
Take pars down
take pars
pars cmere bb
@covert kernel
Fix
@spiral flame <3
Firefox on arch works fine too
nani?
Works just fine in kali
@fossil haven try just refreshing
@covert kernel that didn't work
Try a different browser
skidy tests in brave
oh
@fossil haven But it's bugged just for you, Control R
F5 doesn't work. Probably going to have to clear web cache or something
Hi everyone π Found a "Bug" on the Jurassic Park CTF. Flag1 is not working. anyone has a way how to get the flag accepted ?
hey
did u guys read the message i said about the "Jurassic park box "
i wanna complete it
hey @mellow sorrel you have the same problem like me, with flag1?
Please keep the language SFW
Have some patience, KOTH is happening first
yea sure
I've mentioned Skidy, I'm sure he's aware
I tagged him as well, so he's had a few notifications
Yeah, two of our guys are streaming it
where
As is John Hammond
is there a link somewhere ?
i have to workout first but maybe after π
ah right
thanks
ah
its not started yet
btw moving back to general π
- after clicking 'Back' in the browser, 'Filter Completed' checkbox doesn't do its job. (works when uncheck and check again)
2)When a machine expires, the page needs to be refreshed before it can be Deployed again.
Little bits but hope this is useful.
should be KOTH
Also, might be worth mentioning/detailing the rotation system that Dark brought up in this section
should be KOTH
@spiral flame Do I need to amend anything to the PR for the docs in relation?
Uh any uses of Koth should be KOTH
I thought the same imho
But wanted to keep the continuity of the contents of the site to the docs as much as I can
There are no public sessions running atm, not sure if that is a bug
@dreamy pelican Public sessions for KOTH?
Yessir
lmao I think i broke my conversation list after creating a convo with me and me π
messages:74 Uncaught (in promise) TypeError: Cannot read property 'userId' of undefined
at putUnseenFirst (messages:74)
at genGroupHtml (messages:74)
at Object.success (messages:74)
at u (jquery.min.js:2)
at Object.fireWith [as resolveWith] (jquery.min.js:2)
at k (jquery.min.js:2)
at XMLHttpRequest.<anonymous> (jquery.min.js:2)```
(this isn't for your bugs, this is for THM bugs)
My bad, this is on the thm conversation list
hey guys
<@&568449888682246145> may I pm one of you? i have a bug with the message system, a bigger one than the one I posted before
inb4 xss
nah :D
oh :p
didn't try that, i got sucked in to this thing
just hit it here in a code block
send an email to hello@tryhackme.com @short jackal
sent :)
Hey there I've never been able to submit this last answer on the RP: Nmap room. I don't know why but the button won't work for me
If you remove the answer, what does the answer format look like?
Answer format: ***
That's the right answer i think, but the button doesn't do anything ? no error or validation ?
yes -- does it actually say it's the wrong answer, or does it just not respond?
Nothing happens it just gives the button a green effect like I've clicked it
refresh the page
or full refresh, shift+f5 if it doesn't solve it
Still doesn't want to submit I think I remember having this problem months ago when I initially attempted the room
Could you check the browser console for any errors?
Yep wait there I just had one but pressed f5 I'll try and get it again but it said something like
tryhackme.com/api/rpnmap/answer 504 error
gateway timeout
What if you clear your cookies and login again?
use editthiscookies if you don't wanna clear all the cookies everywhere
just logout/login to clear thm cookies I think, rather than edit it
I still get 504 gateway time-out
It might still save a session cookie that isn't a remember me cookie -- that's how I'd do it
Alright
You said it also happened months ago, right? I signed up a few weeks ago, and have successesfully done this room. Something weird is going on
If I go to any other room though I can submit these. It's literally just that one answer in the Nmap room
maybe try another browser?
do try
but if I'm to wager a guess, I'm going to say that there's an invalid state on the specific answer for your user.
Doesn't want to work in firefox either
Figures
@frosty cape Something curious is going on here. I suspect one of the user-answers somehow got into an invalid state. When @sly nacelle tries to answer RP: Nmap Task 2 Question 15, https://tryhackme.com/room/rpnmap he gets an 504 -- gateway timed out. logout/login, cookie clear, browser change didn't help. Other questions work fine for @sly nacelle, and this question works fine for others. @sly nacelle report that they first attempted the question a few months back, and that the issue is still going on now.
By the way, @sly nacelle, if skidy investigates, he's probably gonna want your username on THM
Username: Alextibtab
Alextibtab, can you try leaving and re-joining the room?
The bug might have been caused by an update we pushed a few months ago
If that doens't work, I will take a look
Thanks Bread for explaining the problem too. Makes it way easier to read/understand whats going on.
@frosty cape I'm still getting the Gateway Time-out error
[Task 15] [Day 10] Metasploit-a-ho-ho-ho
Please help me. I can't find file "flag1". When i compromise the web server i search file "flag1" via command "find" find - name "flag1" but no results
- ROOM Advent of Cyber
Sounds like #room-help, @hushed basin
can't completeroom/25daysofchristmas
because [Task 22] #1 is bugged and does not accept the correct answer,
has the issue been fixed yet?
Use Hydra to bruteforce molly's web password. What is flag 1?
When I change filters the paginations at the bottom of the "hacktivities page" don't update
did you get molly's password?
@covert kernel It greys them out
@rare swallow We verified the flag was correct but the page wouldn't accept it
yea but you can't choose from the new pages
no, when you log in, it shows the flag1 but when I paste it in it does not work
@covert kernel If you filter, it has less. They're greyed out, disabled.
James any work around that? That is the last question I need to answer in order to complete the room?
@sharp ore I'm speaking to skidy
ok
yea
same bug it seems then
coz i cant submit flag1
funny when u rooted the machine submitted all flags, except 1
π
@mellow sorrel @sharp ore are you 100% sure its the right answer?
yup
Or does it not return any response when you input your answer?
Yes, I can see it on the screen
every writeup also says its the right one
*webpage
okay
Didn't you check it with someone too?
every other flag worked fine except flag1
yea i did
but he didnt recall correctly
yup with CM
Once you submit, what happens, it says congrats, but when you refresh is back to being unanswered?
Thanks, let me know shortly before
