#site-bugs

1 messages ยท Page 15 of 1

spiral flame
#

Just ask

#

It's probably not a bug if you just don't know how to solve it

exotic shard
#

ok im on the secound part of it and the Invoke Expresion command doesnt execute a script i tried provided line also a few othe variants of Invoke Expresion command with empty output

spiral flame
#

You're probably doing something wrong

undone quarry
#

Hi, in RP: PS Empire, Task 3, Question 7, the correct answer is ServerVersion, however the server header option is now Headers. Might have been changed recently.

spiral flame
#

@undone quarry Known issue

tender nimbus
#

Hi ,in the room: Anthem, when i go to /authors/jane-doe/ i get an internal server error. Is this intentional?

#

Runtime error*

spiral flame
#

@rare swallow fix yo box

rare swallow
#

lol what?

#

i made sure that i added 404 redirects

tender nimbus
#

here

rare swallow
#

so everything should be pointing to the main page if it tries accessing something that is not there

#

here where

tender nimbus
#

Sooooo... My anthem box just shut itself down...

median sapphire
#

Yeah, it's a known bug

spiral flame
#

@tender nimbus After an hour?

tender nimbus
#

i think so yes, i added time so i dont know exact

spiral flame
#

Yeah so adding an hour doesn't work for some reason

#

It's the same bug that hackpark has

median sapphire
#

๐Ÿค”

ebon oyster
#

i was 7th person completing peak hill.. Now i saw the scoreboard my number went to 9th. why?

short jackal
#

if your score is the same as other user's then the places are randomized

#

the speed doesn't count if you didn't get first blood on any task

ebon oyster
#

no ๐Ÿ˜ฆ all our scores will be same

#

yeah got it thanks.. lol

placid shard
#

Account lockout timer not cleared on password reset

spiral flame
#

@placid shard It's 5 minutes.

#

And you can get around it.

#

Very easily.

median dome
#

Not sure if this goes here or not but the mobile version of conversations doesn't conform to the phone view width

#

When in portrait

spiral flame
#

THM mobile is uh

#

Yeah nah

median dome
#

I mean yeah not to actually do boxes but I like checking some things on it

cinder crow
#

One of my tasks inside of my room has zero questions inside of the actual room but from my management side I see the questions Ive added its been updated, saved,reloaded its been like that for a day or two dont know whats going on with it

covert kernel
#

i cant log in anymore

#

i get "Cross Site Request Forgery Attempt.."

#

i disabled all extensions and im using firefox latest stable version

autumn wave
#

Can you log in from a private browser window or a different browser like Chrome to confirm?

mild maple
#

I've somehow managed to join the Linux Challenges room even though I'm not a subscriber, and there doesn't seem to be a way for me to leave the room. Is this a bug?

#

^^ it wont let me do any tasks in the room, just shows the screen telling me to subscribe... i was just wondering how to leave the room since theres no way for me to make any progress on it unless I subscribe (yes, im stingy and organized and i dont wanna be in a room if i cant do anything on it lol)

spiral flame
spiral flame
#

@oak cove upvote the thing to get it fixed sooner so I can complain at skidy with more weight

distant marsh
#

Can confirm @mild maple 's above issue, also happening for me

mortal dirge
#

Hey In the steganography crash course Theres a bug

#

I need to dm someone

#

any mods can help me ?

median sapphire
#

@mortal dirge There is no need to dm anyone, what bug have you found?

mortal dirge
#

like I found a url

#

but it is wrong

median sapphire
#

@mortal dirge Please post the link to the room

mortal dirge
#

in this go to exam2

median sapphire
#

Which task?

mortal dirge
#

I got this

#

but the url is wrong

median sapphire
#

@mortal dirge Remove that image as it is a spoiler, the url is working

spiral flame
#

@mortal dirge It's likely that you transcribed it wrong

#

It's not a bug

#

Check for characters that look similar.

#

Closed: Not a bug.

mortal dirge
#

I need help solving that

#

where can I ask

spiral flame
bitter meadow
#

for some reason I can't connect to the website in Advent of cyber

#

I did with everyrooms find

spiral flame
bitter meadow
#

I think it's a bug tho idk

spiral flame
#

@bitter meadow It's not.

covert kernel
#

there's a bug/typo in the androidhacking101 room instruction, who should i inform?

spiral flame
#

The creator @covert kernel

covert kernel
#

oh ok, thanks

spiral flame
#

Just tag them here @covert kernel

covert kernel
#

ok

#

A bug/typo in androidhacking101 room instruction. The instruction at [Task 5] Reversing -> search for apk d file.apk , it should be apktool d file.pak @warped osprey

knotty ruin
#

Hello, is flag11 (alias command in .bashrc) missing in Linux Challenges? I'm stuck on this.

spiral flame
#

It's not missing

#

There are more places it could be stored, or you might be looking as the wrong user

warped osprey
#

A bug/typo in androidhacking101 room instruction. The instruction at [Task 5] Reversing -> search for apk d file.apk , it should be apktool d file.pak @warped osprey
@covert kernel fixed, thanks

short jackal
#

Not sure why but the python-pickle badge didn't get added to my account after finishing peakhill

frosty cape
#

I updated your profile to include it.

#

I made a mistake when assigning the badge, I fixed this yesterday:)

short jackal
#

thanks :)

frosty cape
#

Also

#

At a 30 day streak

#

You can't lose that

#

Daymn

short jackal
#

i'll still do two tasks a day from the walkthrough rooms kek

#

gotta set a record

frosty cape
#

Oh wow, I mean, at least it's causing you to keep coming back

median sapphire
#

You made the platform too addictive ๐Ÿ˜›

short jackal
#

I still have some other rooms to do so it's not like i wouldn't :)

frosty cape
#

Mission Accomplished

#

Yeah thats fair.

short jackal
#

mostly BoF, asm or windows related Kappa

orchid hazel
spiral flame
#

@orchid hazel You're in /home/shiba1

#

The binary is in /home/shiba2

orchid hazel
#

damnit

#

thx

spiral flame
#

No skip steps

covert kernel
spiral flame
#

@sly raft also room icon pls?

sullen vessel
#

hum i'm also missing the "python pickling" badge, am i doing something wrong?

frosty cape
#

Whats your THM username?

sullen vessel
#

swapgs

spiral flame
#

This uh

sullen vessel
#

same, but it was fixed after a cache flush :)

spiral flame
#

Ok the bar is still taller than I feel it should be

sullen vessel
#

step 2 of JoyStick is (really too much) shortcutable, is it intended? it's supposed to be a hard room ๐Ÿ‘€

distant marsh
#

Hey, not sure about this but i've just seen my streak go down from 4 to 3 after completing a room (Anthem, fyi)

#

nevermind, fixed itself as soon as i wrote this message

spiral flame
#

Streaks are buggy

distant marsh
#

.<

spiral flame
#

They're being fixed

fiery kayak
#

Hello, I just joined TryHackMe and i wanted to subscribe to get a kali machine directly in your network, but i can't pay with paypal at the moment

potent epoch
#

I've got the same problem as @fiery kayak

#

Error 502, bad gateway

serene bone
#

+1 Same issue! 502 Bad gateway when try to buy using Paypal!

sly raft
#

We're looking into that issue now - in the mean time, please use a monthly subscription โ™ฅ๏ธ

potent epoch
#

It works again, thanks

fiery kayak
#

@potent epoch I'm still getting a 502

potent epoch
#

That's weird, my Paypal has been processed and I am currently subscribed

#

Paypal payment*

sly raft
#

We'll have it fixed fully by the end of the day @fiery kayak

#

if you can, use the monthly subscription for now

fiery kayak
#

i don't have a credit/debit card. It's fine I'll just do it tomorrow

mint creek
#

There is issue in Daily Bugle, where in after some time CMS stops responding even after spawning a new machine, issue persist.

orchid remnant
#

@mint creek issues can't persist between redeploys -- the redeployed version is completely reset. The issue will have to be something on your own computer; my bet would be the VPN connection

weak rune
#

Network issue

#

the machine is not responding

#

tried regenerating vpn

#

Room: hackpark

rare swallow
#

windows machines don't respond to ICMP ping by default @weak rune

#

use -Pn in your nmap scan

mighty night
#

@rare swallow He wrote that by accident.

weak rune
#

Not ping it was a mistake

#

I can't access the webpage or anything whatsoever

rare swallow
#

is it after an hour?

weak rune
#

I tried to restart the machine

#

is it after an hour?
@rare swallow Yeah I think

#

But I added time to it

#

And also I restarted it

opal parcel
#

its the same for me too

rare swallow
#

yeah, the box crashes after an hour

#

same goes to Anthem

median sapphire
#

HackPark is pretty unstable from what I've heard

opal parcel
#

yea that should be fixed its very annoying to do everything from beggining

rare swallow
#

it's going to be easier if you take notes

median sapphire
#

Write an autopwn to do it for you ๐Ÿคท

opal parcel
#

or it can be used as a method to practice

rare swallow
#

that, plus notes taking is an important skill to have

median sapphire
#

^ Notes are very important

weak rune
#

yeah, the box crashes after an hour
@rare swallow Shouldn't launching a new machine fix that?

#

I launched a new machine it is the same

median sapphire
#

Give it 5 minutes to boot up properly

mighty night
#

Even if we extent the time to 2 hours, the machine crashes when the time remaining is 1 Hour.

opal parcel
#

no launching a new machine fixes it but you lose all your progress

rare swallow
#

yup

#

it's a buggy bug with those rooms

unborn hornet
#

hi all

median sapphire
#

@unborn hornet Do you have a bug to report?

#

Please remember that this channel is only for reporting bugs.

shrewd horizon
#

Yo. I clicked a link to another room when I was in the room "Blue". Before my webpage loaded the link, I clicked the "Terminate" button for the remote machine. What I was greeted with was a "500" error.

lyric crown
#

#ultratech1
#5 The software using the port 8080 is a REST api, how many of its routes are used by the web application?

i thing the port in question is wrong...

jagged reef
#

Saving a room in the room management panel whilst it's loading changes the name & description to "Loading..." and resets all the other options to their default(?) state

#

should probably not let people save rooms if they're still pulling the data :p

worthy stag
#

/releases not updated

patent depot
#

Hello, I am just getting started on TryHackMe. It seems that the virtual machines that are deployed are blocking both my pings and nmap scans. I have seen similar posts online but no resolution. Does anyone have any suggestions? (Yes, my OpenVPN is connected)

spiral flame
wispy yacht
#

The streaks thing reset even after I submitted multiple questions, I'm not really too worried about it as my streak was only at 4 but I don't want someone else losing a bigger streak

#

If I just did something wrong let me know and I'll delete this message

spiral flame
#

@wispy yacht We know the streaks are broken, they are being fixed.

wispy yacht
#

@spiral flame sounds good, didn't know if it was known and didn't wanna see someone lose a streak and flip out or something

inland granite
#

@rugged ermine on the Blaster room, just a note, a modern windows 10 machine can no longer connect over RDP without the error: "The function requested is not supported...This could be due to CredSSP encryption oracle remediation"

#

the short term fix for that is to disable the protection via gpedit. this article had details: https://www.itechtics.com/solved-authentication-error-function-requested-is-not-supported/

After the May 2018 update to Windows 10, most of the users who use Remote Desktop function are facing RDP authentication error, function requested is not supported issue where they get the following error while logging in to a remote computer via RDP. We provide 4 solutions to...

rugged ermine
#

Are you using Remmina?

inland granite
#

windows 10 msrtc

rugged ermine
#

Use Remmina instead

#

It's more flexible about that

#

And I quite literally cannot patch that machine without breaking it

#

Albeit I'm fixing a different issue with the browser later

inland granite
#

ok cool. i solved it anyway ๐Ÿ™‚ its just the note for the specific task says on windows use rdp

rugged ermine
#

I'll adjust that now โค๏ธ

spiral flame
#

I will check it

rugged ermine
#

adjusted

inland granite
#

noice

covert kernel
#

Does anyone encounter problems with RDP in Corp room? It keeps on disconnecting and I wonder if problems with logging as admin on the box (surely with correct creds) are not caused by some problem with the machine ๐Ÿค”

spiral flame
#

Also the browser history isn't there for me @rugged ermine

rugged ermine
#

I'm aware of that and fixing it.

spiral flame
#

Cool

inland granite
#

yeah the browser history i guessed past due to doing 25 days a week ago ๐Ÿ™‚

#

sorry forgot to mention it

rugged ermine
#

Adjusted that now

#

I'm fixing the flag now and I'll reupload it in a few

spiral flame
#

@rugged ermine โค๏ธ

rugged ermine
#

Currently working on this fun project but I figured I might as well get that knocked out so it can be uploading in the background

autumn wave
#

@rugged ermine

rugged ermine
#

xD

hazy stratus
#

ThErEs A rEpO fOr ThAt

rugged ermine
#

Would you like me to link to your repo in the room?

#

@hazy stratus

hazy stratus
#

nah

#

there's a million completed scripts out there already :p

autumn wave
#

You can link mine though. ๐Ÿ™‚

#

I'll add my Python stuff if you want.

rugged ermine
#

Go for it! I can link it in my putting everything together step

#

โค๏ธ

autumn wave
#

Ok, I have everything in that link above.

rugged ermine
#

Schweeeet, thank you for putting that all together!

autumn wave
#

Sorry, changed the name.

rugged ermine
#

I'm going to add it as a reference for a complete and working script in the putting it all together section just in case people get stuck

autumn wave
#

Okie doke

rugged ermine
#

I'll link your twitter and THM profile as well on that

#

Blaster is fixed @inland granite @spiral flame

spiral flame
#

Sweet

#

That txt.txt hit me on retro

rugged ermine
#

haha I adjusted that as well

celest bronze
#

Easy to figure out that it was a typo

#

Just a heads up

spiral flame
#

@celest bronze That was caught and fixed

#

IIRC the password for that is broken anyway

#

But really, skidy should copy the standalone hydra VM onto advent of cyber for that task

celest bronze
#

Fixed?

#

I just ran into it 10 mins ago @spiral flame

spiral flame
#

@celest bronze For the standalone hydra

#

Or maybe that's where it was broken as well

celest bronze
#

Oh understood

spiral flame
#

IDK, the VM needs other fixes

pseudo ruin
#

I tried creating a new room, but unfortunately I can't upload any files. Is this a known problem? Clicking the Reset Upload button does nothing.

urban flame
#

Clicked on Hacktivities, filtered by completed then refreshed and the filter button doesn't work

spiral flame
#

@urban flame normally means you filtered before the page loaded

urban flame
#

Ah probably the refresh then

spiral flame
#

I think this has been reported a couple times with the different filter functions

#

And still happens

sly raft
#

@pseudo ruin if you log in and out it should fix it

autumn wave
#

Password policy on Corp needs to be addressed. Administrator password now requires reset before you are able to be logged on to the account.

pseudo ruin
#

@sly raft Tried it thrice and no changes. It still says that an upload is ongoing.

sly raft
#

what's your THM username?

pseudo ruin
#

it's svennergr

mortal kayak
#

Bugs in room Learn Linux.
The passwords of the shiba* user are readable
The shiba4 user's home directory already has all the files and directories needed to complete the challenge

spiral flame
#

@mortal kayak Not a bug

#

Well, not really a bug

#

They're not all readable

mortal kayak
spiral flame
#

@mortal kayak I mean it's still not really a bug

#

@covert kernel you could fix this though, seeing as you already have suid in place for reading them

mortal kayak
#

@spiral flame Okay! But they sure can be a easy cheat route XD
Also please look into the shiba4 user's home directory. That already has all the directories and files needed for the challenge

spiral flame
#

@mortal kayak We know about that one

#

Also, you're only cheating yourself

mortal kayak
#

I just pointed out only ๐Ÿคทโ€โ™‚๏ธ

covert kernel
#

room/completebeginner doesnt show as completed even if completed

#

been like this for a week

spiral flame
#

@covert kernel Check through it, make sure every question is complete.

covert kernel
#

did like 100 times

#

not the first time i report this

#

it even says 100%

#

no challs left to do

celest bronze
#

@rugged ermine Task 5 Question 8 of Empire is no longer the same answer.

#

I'm assuming an update with Empire.

spiral flame
#

@celest bronze bunch of them have changed

celest bronze
#

Do you mind helping me out?

#

I'm Googling with no success.

spiral flame
#

Not at my PC rn, will take a look once I've sorted takeout

celest bronze
#

Nevermind

#

I found it in the Writeup

median sapphire
#

And I was just about to give you a hint ๐Ÿ˜›

worthy stag
#

dogcat removed from the releases page? @frosty cape

rugged ermine
#

I have to adjust Empire. That's my next project

frosty cape
#

Unless jammy did it, I didnt

spiral flame
#

It doesn't show up for me

#

Room is still public

#

Bug replicated @frosty cape

frosty cape
#

It's a tag

#

That makes it display

spiral flame
#

@frosty cape So do you add those tags, or do the creators?

pseudo ruin
#

@sly raft upload is still broken for me btw.

sly raft
#

mind if i DM @pseudo ruin ?

soft tusk
#

I'm new to this, can anyone help me. I'm a fast learner, I might be of any use in future

spiral flame
pseudo ruin
#

mind if i DM @pseudo ruin ?
@sly raft sure, no problem

urban flame
#

Authenticate was made private then public again, I now cannot rejoin as I am already in that room, could an admin fix that please?

#

Assuming that's to do with room instances with the same name, a user joined the previous instance without overwriting current status

pseudo ruin
#

mind if i DM @pseudo ruin ?
@sly raft after an other reset it's working now!

obsidian sundial
#

my streak reset to zero from 6 days on my 7th day (today)

orchid remnant
#

Yeah, let's just say streaks are buggy...

#

They're being fixed, but ignore 'em for now

frosty cape
#

my streak reset to zero from 6 days on my 7th day (today)
@obsidian sundial Whats your username?

obsidian sundial
#

@frosty cape sloshy

frosty cape
#

@frosty cape sloshy
@obsidian sundial Your streak is still in tact and hasn't been reset to 0? Where did you see this occur?

obsidian sundial
#

strangely it says 5 now after refreshing the page multiple times. should say 7 i believe but either way as long as the backend is working im good. Not super important its just cool to get the badges and eventually the 5% off

urban flame
#

Another bug with streaks, I answered a question and my timer reset back to 23hrs but the daily count didn't increase - another thing to consider about streaks ๐Ÿ™‚

frosty cape
#

^ Yeah it will, your streak only increases every 24 since answering your first question.

E.g. You can your first question at 3pm, (so you have 24h to answer again), if you re-answer 2 hours later (at 5pm) you will have 24 hours again to answer, but your streak will increase in 22 hours time (from 3pm, not 5). - Hope that made sense.

#

@frosty cape
@obsidian sundial https://tryhackme.com/p/sloshy Your profile says 7. I think the issue is with the date/time - What timezone are you?

fresh lynx
#

Can I suggest koth invite links don't automagically add you to the event? I just wanted to open it, but got added to the event which was a surprise.

topaz venture
#

That's the point of the links

#

you can join a spectator link to watch the game without joining

#

or the on-going public lobbies are on the koth page ๐Ÿ™‚

orchid remnant
#

Can I suggest koth invite links don't automagically add you to the event? I just wanted to open it, but got added to the event which was a surprise.
@fresh lynx That said, I've added it to the #641405480547385354 channel

fresh lynx
#

@topaz venture I didn't realise i was clicking a join link, and without confirmation i was in. If i hide this behind a bit.ly link?

topaz venture
#

Yeah I understand

#

Hindsight, it's caught me out a few times haha

fresh lynx
#

It also meant i joined a game that started 10 minutes earier and had to try ultra hard to catch up (I did ๐Ÿ˜„ ).

strong pumice
#

Went to the upload page and got this, even if I click reset it still give me this message.

spiral flame
#

Log out and back in @strong pumice

strong pumice
#

Okay, just done that, same issue.

#

I'll try clear browser data and see if that sorts it, Edit, it fixed it. disregard ๐Ÿ˜„

frosty cape
#

@spiral flame What Kali machine was that in the bug-submissions? The one deployed from the in-browser page?

spiral flame
#

Optimised

frosty cape
#

Or from another task in /room/kali

spiral flame
#

I haven't checked the others

frosty cape
#

Ah ok

#

Thanks

spiral flame
#

But I'd recommend checking the others as people have complained

frosty cape
#

Yeah I will, Im at home atm, so don't have full access to everything.

ebon oyster
#

so. one thing I noticed in the hacktivities page when u select a type.. click on a challenge and do back. the type remains unchanged but the result reverts to the original no-filter kinda set. So u have to select a different type then your preferred type.

jagged reef
#

not really a bug, but maybe the avatar upload file size should be restricted?

#

it just took me 45 seconds to load the dogcat management panel because 2 people who wrote writeups for it have like 15 mb gif avatars set

#

or maybe at least slap a loading="lazy" on them

runic marsh
#

Just auto resize after uploading

strong carbon
#

Why is the server getting 503?

#

and now i got a 504

#

interesting

#

Cloud is not on scale

#

to many users

#

Is anyone getting the same troubleshooting?

spiral flame
#

Have some patience

#

Let skidy fix it

strong carbon
#

It happens several times in the week

#

Im getting disappointed and doesnt want to learn

strong carbon
frosty cape
#

Im getting disappointed and doesnt want to learn
@strong carbon Sorry about that! We've identified the issue and have fixed it - We're working really hard to ensure things are running smoothly. Happy Hacking.

obsidian sundial
#

^ Yeah it will, your streak only increases every 24 since answering your first question.

E.g. You can your first question at 3pm, (so you have 24h to answer again), if you re-answer 2 hours later (at 5pm) you will have 24 hours again to answer, but your streak will increase in 22 hours time (from 3pm, not 5). -
Hope that made sense.
@frosty cape

I was thinking this right before I opened up discord a moment ago. lol thanks I got my 7 streak when I logged in around 10 last night utc-6

spiral flame
#

Hackpark died after 30mins, webapp no longer responds. Due to the stability issues and it not extending, should it really be a part of the Offensive Pentesting path?

autumn wave
#

The entire path needs adjusted. Is this a singular issue? I've not experienced it personally but can check if you want/need.

spiral flame
#

@autumn wave I redeployed and it seems... fine? But it definitely has stability issues and that's been reported A LOT

autumn wave
#

I've only ever noticed the issue where it dies at 58 minutes after time is added.

pseudo ruin
#

Log out and back in @strong pumice
@spiral flame @sly raft btw, upload bug is back for me. relog didn't work. using another browser didn't work as well.

strong pumice
#

btw, upload bug is back for me. relog didn't work. using another browser didn't work as well.
@pseudo ruin Try clearing all browser data for both browsers. Also probably best not to ping Mod's or Admins, see #rules 1

frosty cape
#

Hackpark died after 30mins, webapp no longer responds. Due to the stability issues and it not extending, should it really be a part of the Offensive Pentesting path?
@spiral flame This is weird and I am not sure whats causing the issue - I deployed and extended is > 1h and it was fine. So its very strange.

Never the less, as its been reported as unstable, I'll take a more detailed look into it. Added to my to-do list as medium priority.

pseudo ruin
#

@pseudo ruin Try clearing all browser data for both browsers. Also probably best not to ping Mod's or Admins, see #rules 1
@strong pumice Tried that and it didn't lead to any success me. I pinged them because of previous conversation about that bug.

olive drum
sly raft
#

@pseudo ruin mind checking if the upload works? :)
made a small change

mighty night
#

Can I DM you @sly raft ? It's important.

sly raft
#

what's it about?

mighty night
#

Weakness in THM website.

sly raft
mighty night
#

With full explanation.

pseudo ruin
#

@pseudo ruin mind checking if the upload works? :)
made a small change
@sly raft Looks like it's working. Couldn't reproduce the bug for now. Thanks for the fix!

sly raft
#

give me a shout if it breaks haha ๐Ÿ™‚

#

@mighty night mind forwarding it again - I can't see any recent emails about bugs ๐Ÿ™‚

mighty night
#

Okay!

#

Forwarded!

strong pumice
#

Getting this error when I'm trying to upload a Ova, I have tried clearing data, and a different browsers. Not sure if it's a me problem or THM problem.

olive drum
#

log out -> log in

#

seems like you are 'already uploading' something

strong pumice
#

Have done, same issue.

sly raft
#

give me one sec :))

#

try again now pls?

strong pumice
#

Fixed, thank you ๐Ÿ™‚

sturdy fern
#

Anyone else notice inconsistencies with the streak counter? Today mine was at 4, and the prompt said to complete a question within 16h to keep the streak going. I completed a question and the streak count went to 5, then I continued to answer questions and about an hour later the streak counter is at 0. Am I doing something wrong?

spiral flame
#

@sturdy fern It's being fixed.

orchid remnant
#

Let's just say that you'd probably be best ignoring it for the time being

#

Should be fixed soon ๐Ÿ™‚

sturdy fern
#

Okay cool, I thought for a second that the streak counter was a challenge itself

#

Was about to start reverse engineering it

orchid remnant
#

Haha

#

Might as well be -- the upload page is

hard horizon
#

Anyone else notice inconsistencies with the streak counter? Today mine was at 4, and the prompt said to complete a question within 16h to keep the streak going. I completed a question and the streak count went to 5, then I continued to answer questions and about an hour later the streak counter is at 0. Am I doing something wrong?
@sturdy fern yup same here but i will ignore as said by @orchid remnant

frosty cape
rare swallow
#

not a mistake, feature

hallow hamlet
#

Guys why does servers ain't working ?

fresh tide
#

Guys why does servers ain't working ?
@hallow hamlet THM website?

hallow hamlet
#

@fresh tide yes I am connected but I can not nmap or ping the machine

fresh tide
#

which room?

hallow hamlet
#

tony the tiger

hazy stratus
#

is it a windows box?

hallow hamlet
#

IDK

#

says java tho

hazy stratus
#

have you tried adding -Pn to your nmap scan?

hallow hamlet
#

yes I did nmap -Pn -sS -sV

#

even -p-

hazy stratus
#

how long ago did you deploy the machine?

hallow hamlet
#

5 mins

hazy stratus
#

give it a few more and see if theres any differences

hallow hamlet
#

it also happened in an other room yesterday it was fixed after an hour

#

@hazy stratus okay,

hazy stratus
#

this might be something @frosty cape and or @sly raft will need to look into

topaz venture
#

Just throwing my hat into the ring, can you try switching VPN servers?

#

Tony the Tiger takes a hot few minutes to setup but should be responding to pings after 3 or so minutes at least

hallow hamlet
#

@topaz venture I am tryin thompson machine

#

now same problem

#

and I restarted my service

topaz venture
#

Best thing I can recommend is switching servers and regenerating your config, importing that and seeing if that helps @hallow hamlet

hallow hamlet
#

I fixed the problem brother. I changed my server location to us west

#

thanks for contacting back

topaz venture
#

Good stuff ๐Ÿ™‚ happy hacking

lunar pine
#

@hazy stratus hey I'm suffering from an irritating bug for the last few days. Can you help me? It's in the "Advent of Christmas" room on day 11. Whenever I connect to the FTP server and send an ls or dir command, it says "500 illegal PORT command". Can't even go into passive mode because of an "invalid pasv_addr" error. Very irritating. Already tried to switch servers, both AUS and EU 1 have the same problem.

median sapphire
#

There's no need to ping a mod.

#

Try using ftp -p <ip>

lunar pine
#

@hazy stratus hey I'm suffering from an irritating bug for the last few days. Can you help me? It's in the "Advent of Christmas" room on day 11. Whenever I connect to the FTP server and send an ls or dir command, it says "500 illegal PORT command". Can't even go into passive mode because of an "invalid pasv_addr" error. Very irritating. Already tried to switch servers, both AUS and EU 1 have the same problem.
@median sapphire Can't even go into passive mode because of an "invalid pasv_addr" error.

ornate moss
#

Upon further investigation it was my dns blocking maxcdn.bootstrapcdn.com

spiral flame
#

@lunar pine run your VPN on the same machine you're connection to FTP from. This means if you're using a VM, connect from the VM not the host.

strong pumice
#

I think I have found a points bug, I don't want to just blurt it out though. Anybody I can DM? It may already be known, just wanna make sure

spiral flame
#

Report it to Skidy

strong pumice
#

Will he mind If I just DM him or is there a proper procedure?

spiral flame
#

@frosty cape is around rn so if you give him a little while I'm sure he can answer that

strong pumice
#

Okay cool cool cool cool cool

ebon oyster
#

hey..
so while the hacktivities page loads, if you click Filter Completed as expected it doesn't work. But even after everything is loaded if you uncheck and check that checkbox again it throws the same .length of undefined error.

#

Also, if I want to contribute on fixing these bugs can I do that anywhere?

spiral flame
#

THM is closed source

#

You can contribute to the docs, but not thm

#

By reporting them, you're helping

ebon oyster
#

cool thanks

frosty cape
#

I think I have found a points bug, I don't want to just blurt it out though. Anybody I can DM? It may already be known, just wanna make sure
@strong pumice Hi there, DM me please.

ebon oyster
#

one more thing.. so i have currently 3803 points. And I joined THM in this month 18th I think. So in the leaderboard of the month I can see people with <3800 points but not me.

is it because I have not yet completed my 1month?

short jackal
ebon oyster
#

ah! sorry

short jackal
#

:)

lunar pine
#

@lunar pine run your VPN on the same machine you're connection to FTP from. This means if you're using a VM, connect from the VM not the host.
@spiral flame doing exactly that bro i'm not really new to THM

spiral flame
#

I never said you were

lunar pine
spiral flame
#

You backgrounded FTP

lunar pine
#

this is what i see

spiral flame
#

It's already using that port so you can't rebind

#

You're repeatedly backgrounding it

#

Don't do that

#

Control Z is not undo

lunar pine
#

so i should kill ftp and retry?

median sapphire
#

Kill all of the ftp processes and retry.

lunar pine
#

can anyone of you please verify whether it is a problem with the box?

spiral flame
#

ps aux

#

sudo killall ftp

#

It's not a problem with the box, it worked for me

lunar pine
#

root@kali:~# ps aux | grep ftp
root 5616 0.0 0.0 6148 956 pts/1 S+ 21:26 0:00 grep ftp
root@kali:~# killall ftp
ftp: no process found

trim yoke
#

Iam in the Vulnversity room but if i type in the ip in google he says "This site can't be reached". Is it a problem with the box or did i make a mistake

spiral flame
#

You made a mistake.

jade beacon
#

For the RP:Metasploit room, Task 7, #1, the command that we are told to use is depricated (per meterpreter output). Recommand updating it to use the non-depricated command ||run post/multi/manage/autoroute SUBNET=172.18.1.0 NETMASK=255.255.255.0 ACTION=ADD||.

ember goblet
#

idk why it wouldn't accept this answer

fresh tide
#

@ember goblet which room?

ember goblet
#

cc;pentesting

fresh tide
#

did you try using double quotes? @ember goblet

ember goblet
#

i tried and it works

#

but it took some time haha

fresh tide
#

10/9 flags while i only submitted 9 flags.
The possible reason i could think of is: i think my left mouse click double clicks most of the time so it may have submitted a flag twice while clicking the submit button.
So spamming the Submit button or using any of the techinal ways could count the same flag twice or more times
https://tryhackme.com/games/koth/3936

spiral flame
#

@frosty cape skidaddle, we found a race condition point dupe bug in KoTH

#

Naughty and I

#

Got a PoC too

spiral flame
frosty cape
#

Nice, mind writing it up and sending it to me?

#

Or is it just spamming submit for a flag?

spiral flame
#

@frosty cape tiny bit more more than that

#

Can I DM?

frosty cape
#

Yeah

spiral flame
#

@covert kernel Once you've slept, there seems to be random, empty code blocks in ccr2

median sapphire
#

Alfred is not showing as completed for me, I've checked the room for any additional tasks, but there seem to be none, I've also tried leaving the room and joining again, but Alfred still shows as uncompleted.

jade solar
#

Not really a /bug/ so to speak but whenever i copy IP from here, an extra space gets added to the start of it.

#

is it just me ?

spiral flame
#

I haven't had that issue

jade solar
#

Okay then

topaz venture
#

I get that as well. It seems to be browser specific I think?

#

Curious to see others thoughts

#

These days I just type out the IP address

rare swallow
#

i doubleclick on the ip, it will just select the ip

orchid remnant
#

Pretty sure it's browser specific that one

oak marten
#

'i doubleclick on the ip, it will just select the ip'

#

DIdnt you want to double click the ip

spiral flame
#

@oak marten ????

tired obsidian
#

Please please, remove already completed rooms from suggested

spiral flame
#

@tired obsidian Closed, not a bug

tired obsidian
#

There's nowhere else to request it

spiral flame
#

Pick one

tired obsidian
#

...fair

fresh tide
#

Not really a /bug/ so to speak but whenever i copy IP from here, an extra space gets added to the start of it.
it happens even with me... using firefox in kali.. a lot of people have already mentioned this earlier

acoustic saddle
#

i believe at least for me i needed to install neo4j server for bloodhound to work.... idk if its just me but ya without neo4j the server would not start

celest bronze
#

Been paying attention to the hours that I do challenges, and my streak just reset to zero. Was so close to a 30 day streak ๐Ÿ˜ฆ

rare swallow
#

not anymore

#

i mean, i have 7 days and it shows as 1

proud pilot
#

Failed to deamonise connection timed out in Vulnversity

spiral flame
#

@proud pilot #room-help this is a "you" problem not a bug

rare swallow
#

wrong channel for that

cinder crow
#

@acoustic saddle neo4j is installed with bloodhound if you follow the directions in the room all you have to do to setup neo4j up is to run neo4j console and follow the instructions that come with it

frosty cape
#

Been paying attention to the hours that I do challenges, and my streak just reset to zero. Was so close to a 30 day streak ๐Ÿ˜ฆ
@celest bronze Hm, it doesn't use your yearly activity, but if you answered a question 24 hours before your last one (or played a KoTH game).

#

How long did it say you had left?

#

When you covered over your 'Streak' sidebar?

celest bronze
#

Honestly Iโ€™m not 100% sure, I know I was super close and I do at least 1-3 rooms a day on THM. Iโ€™ll pay closer attention to the hours, thank you @frosty cape

frosty cape
#

I gave you your streak back.

#

I think I need to be a little more lenient on the streaks?

spiral flame
#

Wait, did you fix it randomly clearing streaks?

frosty cape
#

Huh

spiral flame
#

They were buggy

#

Like horrendously

frosty cape
#

It should be fixed now (I think).

celest bronze
#

Thank you!

#

I could have sworn I answered in the time frame!

#

So this means, if I don't answer at least 1 question in 11 hours. I lose it again?

#

Because if that's the case, I am very sure I did that.

sullen vessel
#

cc @final fox :)

orchid remnant
#

Uh, yeah @frosty cape?

#

Might wanna check the leaderboards...

#

The bug Dan found, or a similar one, may still be in play...

sullen vessel
#

@frosty cape / @celest bronze: same issue with streaks here. I completed a room this afternoon and now it still tells me "you have two hours left to answer".

covert kernel
#

He has 2 completed rooms

#

It's possible he made a room on alt account with a bunch of questions

#

And spam completed it

orchid remnant
#

Also possible that this is an actual bug which has already been responsibly disclosed ๐Ÿคทโ€โ™‚๏ธ

#

Just worth bringing it to Skidy's attention, methinks

covert kernel
#

We can hope

sullen vessel
#

and now I solved a question and the streak in my sidebar went from 5 to 4, and it tells me I have 22 hours left to answer (why not 24?). Outside the timezone bugs, issues are still present. I'll create a test account and try to summarize everything.

final fox
#

i just made room with a lot of tasks

#

and solved it

#

lol

sullen vessel
#

nice :)

orchid remnant
#

Guess what Pars

#

You were right...

final fox
#

im friend with szymex

#

so i think

#

he wont mind

#

xD

#

i mean

#

till someone wont reset

#

my points

orchid remnant
#

@frosty cape plz fix?

spiral flame
#

I maintain

#

Only approved rooms should grant points

orchid remnant
#

^^

spiral flame
#

Even if approved != public

orchid remnant
#

Or admin approved private rooms

#

That ^^

#

Also solves the problem of us getting points while testing...

final fox
#

and room should be "reapproved" after adding task

#

coz it would be still possible

#

to spam adding tasks and solving it

orchid remnant
#

That's the job of the tester to notice -- we wouldn't accept a room if it wasn't genuine content, even now

#

If tasks are being added randomly, we have the option to pull it

frosty cape
#

i just made room with a lot of tasks
@final fox You mean you just made a private room with lots of tasks?

#

Hm, from now on (until I push my latest code base), all private room points don't go towards your main account score.

spiral flame
#

Then I can just create a room on my alt

icy orbit
spiral flame
#

Accounts are cheap

#

AKA free

frosty cape
#

Then I can just create a room on my alt
@spiral flame You need to make the room public tho?

#

Which goes through room reviewers

final fox
#

yeah

spiral flame
#

all private room points don't go towards your main account score I think I misunderstood this

final fox
#

private room

spiral flame
#

I think I misunderstood main as room creator

#

Also my poor hackback2 points

frosty cape
#

private room
@final fox Ok ty, I reset your score/level back to 0.

#

and now I solved a question and the streak in my sidebar went from 5 to 4, and it tells me I have 22 hours left to answer (why not 24?). Outside the timezone bugs, issues are still present. I'll create a test account and try to summarize everything.
@sullen vessel Oh really? Can you check using your /p/<username> (public profile)?

spiral flame
final fox
#

๐Ÿ‘

#

im still 0xG0D here

#

xD

orchid remnant
#

Ta for the reminder...

frosty cape
#

ahahah

orchid remnant
#

๐Ÿ˜

#

(That would probably have slipped past if you hadn't brought it up ๐Ÿคฃ)

final fox
#

lol

orchid remnant
#

Don't worry

#

You might have just accidentally become an admin...

#

I really hope that's fixed...

final fox
#

yeah

#

i saw that

#

XD

#

ADM1N

#

rank

frosty cape
#

I really hope that's fixed...
@orchid remnant It is and it was just the level displayed

#

No roles and/or permissions were attached

#

Its just a level number

orchid remnant
#

Hehe, fair enough ๐Ÿ˜

sullen vessel
#

@frosty cape : ok, the streak count on public profile is right, it's only wrong in the sidebar

frosty cape
#

ooo

#

oka

#

Let me look into that now

#

I have data to work with

#

Whats your THM username?

sullen vessel
#

and now I see that I have 23 hours to answer, it increased :P

#

swapgs

frosty cape
#

oh, so its fixed?

sullen vessel
#

i'll let you know

frosty cape
#

You need to refresh your page to see your streak time left:)

sullen vessel
#

yep, i did it multiple times

frosty cape
#

Ah no, it is bugged

#

Let me see why

sullen vessel
#

it's also weird that i have events the last 25 days but only a streak of 5 days, i guess i got tricked by the 22 hours time window

frosty cape
#

Oo, I found the bug

spiral flame
#

Oooh

#

Bug report?

twilit brook
#

should wrong answers or answers that need to be updated be posted in bugs?

orchid remnant
#

Yep

twilit brook
#

im doing the beginner path:
RP: Nessus
[Task 4] Scanning!
#9 it asked what web server type and version

When i did the scan on the deployed machine for this section i get Apache/2.4.7
but it says that is wrong and has an indication of: **/..

cinder crow
#

Offensive Pentesting Path - Proving It - Game Zone description contradicts itself I believe it should say no SQLMap - Initially exploit this machine via SQLi and reveal a hidden service using an SSH tunnel. Try not to use any tools for this one (no SQLi or Metasploit).

orchid remnant
#

@rugged ermine might need looked into?

#

@cinder crow That, uh, might need changed

#

I'll take a look ๐Ÿ™‚

#

@cinder crow Where's the contradiction?

cinder crow
#

(no SQLi or Metasploit) you need to use SQLi but not with SQLmap like in the room

orchid remnant
#

There's an SQLmap task?

cinder crow
#

yes however the room says use SQLi as an exploit then says no SQLi so I am assuming thatโ€™s intended to say no SQLmap

#

path not room sorry

orchid remnant
#

Aaah

#

that explains it

#

Yeah, can't edit that one I'm afraid ๐Ÿ˜ข

twilit brook
#

so what should i do?

cinder crow
#

Wait for dark to fix

twilit brook
#

ok thanks

ember goblet
#

idk why they both gets accepte

tired obsidian
#

@twilit brook He won't fix it for a bit, I'll tell you the answers when you come back on

#

Why do you think they're wrong?

ember goblet
#

one is "not accessed" within the last 10 days

#

means the window is 10+ days to the past

#

the other one is "within the last 2 hours"

#

yet they accept the same flag

#

-120 or -19

#

*-10

spiral flame
#

Press refresh

#

See if it changes

tired obsidian
#

Yeah James is right

#

That usually fixes it

#

You are correct though, it should be +10

spiral flame
#

If it changes, then there's answer tolerance

ember goblet
#

it does
but what does >answer tolerance mean

spiral flame
#

There's some tolerance on the answers that you give

#

A small amount of the answer doesn't have to match

ember goblet
#

but why do we have this feature though

#

doesn't it mean it's more likely to goad the user into wrong knowledge

spiral flame
#

Take it up with Skidy

#

We've asked for more control over it, as room creators

tired obsidian
#

Answer tolerance is dumb

#

On the same question I missed quotes and it said it was wrong, even though it would work without them

spiral flame
#

I've also asked skidy to effectively refresh that field on submit+correct answer

fresh tide
#

@spiral flame please DM me when you come online, i think i have found another use of our bug ๐Ÿ˜„ (Points abuse in simple rooms) or should i share with someone here?

short jackal
#

For bugs it's best to contact admins I think

fresh tide
#

For bugs it's best to contact admins I think
@short jackal skidy already knows about that one.

#

But i think James only told him about KOTH but it also works in other rooms as well

frosty cape
#

Its because of the extra points you got the user and root.

#

I need to recalculate points and include extra points.

fresh tide
#

I just did retro room on that account but instead of 690 total points i got 1380

hollow quiver
#

https://tryhackme.com/room/zthlinux > Task 25 > "Recall that ls allows shows us our username twice in one of it's fields." > Remove allows. Not much of a bug. Sorry if this is the wrong channel.

rose shell
#

@rugged ermine @frosty cape

#

a moment?

rugged ermine
#

?

rose shell
rugged ermine
#

OOF

rose shell
#

or is it intended?

hazy stratus
#

LOL

topaz venture
#

LMAOO

rugged ermine
#

@frosty cape send halp, we gotta updoot that and add more to the rotation

rose shell
#

oof

rugged ermine
#

We totally need to add FLYNN LIVES

hazy stratus
#

it's gonna be like the Minecraft title screen

topaz venture
#

'Leeerrrroy Jeenkinnnns...',
wait wha

rugged ermine
#

We should grab one of the MC title screen texts that is more iconic

hazy stratus
#

"Hack The Who?"

spiral flame
#

Hack the WHO? Not again

rugged ermine
#

I'mma veto that

rose shell
spiral flame
#

It's just hard to see it

orchid remnant
#

@wanton copper It should be working. The LFI won't give you a shell, as I assume the writeups will have showed you

spiral flame
#

Lmao I think they realised a mistake, ok

orchid remnant
#

It's just a matter of reading through

#

Aha ๐Ÿ˜

wanton copper
#

read more of the walkthrough it points to a dif port after the same issue as me

#

odd as that port isnt the vuln app

spiral flame
#

That port just serves the logs

#

Not exactly realistic, but it's useful here

olive drum
#

Authenticate room broken? says I have already joined it or banned

#

log out -> log in did not help

wanton copper
#

@spiral flame I went through it at the start and discounted it - buzzer went on the cooker so ran out of time to chat and finish it lol

covert kernel
#

Hi, i want to know what login and password i need to entre to connect on webbrowser machine (kali)

orchid remnant
#

It should be written in the room @covert kernel

#

Is the in-browser not working?

covert kernel
spiral flame
#

Terminate and redeploy @covert kernel

#

Bug is being fixed this week

covert kernel
#

Ok thanks @spiral flame

#

I will do that

hallow hamlet
#

hey people I had 6 days streak at tryhackme .com I finished room today as well buut now it is gone

frosty cape
#

Yes look
@covert kernel This is being fixed, scaling our in-browser functionality once and for all has been a task and a half! Almost there with it.

orchid remnant
#

Which room @covert kernel?

spiral flame
#

Terminate and redeploy

jagged garden
#

hello friends! i'm having trouble with Common Linux Privesc- Task 4 #6. when i enter in my answer I get "Uh oh! undefined". Screenshot also has the browser console (per #room-help advice)

spiral flame
#

Unlikely to get fixed

#

But ok

#

I can't report it unfortunately

#

@covert kernel DM me a screenshot of show databases; in mysql

#

It's a database name

#

The name of a database

#

mysql can have several databases

spiral flame
covert kernel
spiral flame
#

@olive drum

olive drum
#

my bad, iโ€™ll fix soon

spiral flame
sudden flint
#

thanks!

covert kernel
#

SystemScheduler.exe tooo ๐Ÿ˜ฆ

#

is my last task in HackPark box

spiral flame
#

@covert kernel That's not the name of the service

#

To be fair, the answer it's looking for is actually incorrect as well

covert kernel
#

so it is another name? i found this at last on the video

#

i must search about another one? or?

spiral flame
#

A service is a separate construct to an exe

#

exe is a file

covert kernel
#

and SystemScheduler?

spiral flame
#

sc query

#

That lists your services

covert kernel
#

in windows shell or meterpreter?

spiral flame
#

You need to put .exe on the end of the correct service which isn't actually correct

#

It's a windows command, and this is changing to #room-help

covert kernel
#

thank you! now i now.. but i don't spoiling ๐Ÿ™‚

#

know*

tired obsidian
#

After the enumeration of user accounts is finished, we can attempt to abuse a feature Kerberos within Kerberos with an attack method called ASREPRoasting.

#

Should be After the enumeration of user accounts is finished, we can attempt to abuse a feature within Kerberos with an attack method called ASREPRoasting.

#

Task 5 description

spiral flame
#

@hazy stratus

rare swallow
#

new box font issues

spiral flame
#

Also, wasn't it meant to be a a challenge room tonight at 8pm?

rare swallow
spiral flame
#

@frosty cape release issues

sly raft
#

appears to be browser specific hm?

spiral flame
#

@sly raft Yeah that means there's a font set that shouldn't be set

#

Overriding the default for the questions

median sapphire
#

Happening to me as well, I'm using Chrome 83.0.4103.61

spiral flame
#

It's trying to use a font you don't have locally

#

And falling back to serif

rare swallow
median sapphire
#

It's trying to use Ubuntu Mono

spiral flame
#

This is a known issue

#

But shouldn't have happened IMO

hazy stratus
#

fixed

spiral flame
#

Still not showing up in hacktivities though

frosty cape
#

new box font issues
@rare swallow Check again please, this will be fixed when I move everything over to use MarkDown and not HTML

rare swallow
#

looks good @frosty cape

jagged garden
#

hello friends! i'm having trouble with Common Linux Privesc- Task 4 #6. when i enter in my answer I get "Uh oh! undefined". Screenshot also has the browser console (per #room-help advice)

sullen vessel
olive drum
#

yeah

sullen vessel
#

nice

strong pumice
#

He was rank 3 earlier ๐Ÿ˜‚

sullen vessel
#

i guess they will take the first rank the 31th :)

hallow hamlet
#

<@&568449888682246145> why does tryhackme deletes me streaks I had 6 yesterday and I have completed a machine but now it says that I have 0 streaks

orchid remnant
#

No need to ping the admins ๐Ÿ™‚

spiral flame
#

Streaks are being fixed.

hallow hamlet
#

I was going to get the badge ๐Ÿ˜ฆ

orchid remnant
#

Streaks are buggy as hell

#

They're being fixed

hallow hamlet
#

okay just please give them back ahaha ๐Ÿ˜„

sullen vessel
#

tl;dr it's because you have a delay of 24 hours hours max between each answer, it's not reinitialized at midnight

hallow hamlet
#

@sullen vessel it was only 10 hours ago

rare swallow
#

7 days streak badge doesn't show

spiral flame
#

So the points change hasn't gone through

#

Also, I have a 10 day streak according to the heatmap. Please can I get the badge for 7 days?

spiral flame
#

Refresh

short jackal
#

refreshed multiple times

spiral flame
#

I still cannot express how much I love that domain

short jackal
#

force-refreshed and went to other pages too, still shows 1h or 2h

#

and I really don't want to loose this streak

oak bridge
spiral flame
#

Yeah it's coming back

#

Skidy pushed some new code

oak bridge
#

OK, thank you!

#

Cleaning browser cache is solution, thx

tired obsidian
#

The file for Flag 56 in CTF100 is missing the data in it that would have the flag

#

Like, it should be an ascii file but it's just empty

#

Just restarted the box and it's still missing

short jackal
#

lemme check thonk

tired obsidian
short jackal
#

check the original zip ;)

tired obsidian
#

?

short jackal
#

check the 429E zip file

#

it's all good, you missed a step :)

tired obsidian
#

On Kali

#

And I have to decrypt GPG

spiral flame
#

@tired obsidian More context required

tired obsidian
#

The RDP window in the Kali room, the link is broken

#

As is the access in browser link, the hostname is set to undefined

spiral flame
#

Clear your browser cache

tired obsidian
#

Shift+Refresh -> Same issue

spiral flame
#

@tired obsidian That's not clear cache

tired obsidian
#

Clearing now

tired obsidian
#

Still broken

spiral flame
#

@frosty cape

tired obsidian
#

Powershell Hacking is broken, kicks me to the Remote Login screen on the inbrowser RDP

#

(bit better than just not loading the page in general)

#

I restarted the machine and it didn't fix it

spiral flame
#

@tired obsidian remote tryhackme login?

#

Ooof that was meant to be fixed I think

tired obsidian
#

Yeah it was fixed under kali, but this one is still broken

#

sub 120

#

114 rank, retiring for the night

median sapphire
tired obsidian
#

ope i thought i was there, sorry

exotic jacinth
#

I posted in #site-support but I believe there is something wrong with the Windows PrivEsc Arena room. I cannot log in as user, only as TCM. I cannot change user with runas /user:user cmd, I get a 1327 error: user account restricted even though I'm entering the correct password: password321. There was also no GUI way of changing user as far as I saw. I'm using remmina

frosty cape
#

ope i thought i was there, sorry
@tired obsidian yo, when you deploy an inbrowser machine, what are you seeing? What URL?

spiral flame
#

@jolly jetty you didn't perform a full scan

tired obsidian
#

@tired obsidian yo, when you deploy an inbrowser machine, what are you seeing? What URL?
@frosty cape Proper URL, but instead of tryhackme with its sub-domain it displays as undefined

jolly jetty
#

@spiral flame Which setting do I need to enable for full scan ? I was following all the settings given on the room section, so I thought I was

spiral flame
#

@jolly jetty I don't know without looking at nessus, but this isn't a bug. This is user error.

tired obsidian
#

well its not doing it anymore for some reason, ill keep you updated

#

Yeah it fixed itself ๐Ÿ™ƒ

jolly jetty
#

@spiral flame I think so, but since no one responses on those room help channels so I have try to post on other channel to make someone like you to notice that

spiral flame
#

@jolly jetty That's not how this works. It's not a bug, don't misuse the channels. There's a procedure for getting help if you don't get help in #room-help

jolly jetty
#

Okay then. I have removed those messages from this channel, and I have actually post it on channels #room-help and #692465827143876689 for hours, wish you or someone else can help me on my error over there

spiral flame
potent trellis
#

Room Tracking specifically

exotic jacinth
#

I posted in #site-support but I believe there is something wrong with the Windows PrivEsc Arena room. I cannot log in as user, only as TCM. I cannot change user with runas /user:user cmd, I get a 1327 error: user account restricted even though I'm entering the correct password: password321. There was also no GUI way of changing user as far as I saw. I'm using remmina

#

im still having this issue is anyone able to verify

#

i just changed the password and runas worked successfully

prime spindle
#

IP banned? why

spiral flame
#

@prime spindle ??

prime spindle
#

Can't view the site

spiral flame
#

Show us

prime spindle
spiral flame
#

Do you share your broadband with anyone?

prime spindle
#

nope

frosty cape
#

nope
@prime spindle Hm, we have no rules in place that would stop your access.

#

Are you using a VPN?

prime spindle
#

nope

frosty cape
#

DM me your IP, I'll have you unbanned.

urban flame
#

My streak counter just jumped from 14hrs to 1 randomly jumped to 2 hrs after answering a question and it won't increase now

spiral flame
#

@frosty cape Can I have my 11 day streak and the 7day badge please?

short jackal
#

it should reset in 1-2h to the normal count, i had the same problem yesterday @urban flame

urban flame
#

14 -> 1 ->2 ->1 -> 2 lol

short jackal
#

the script that calculates it clientside is weird af

urban flame
#

@frosty cape Can I have my 11 day streak and the 7day badge please?
@spiral flame If that's the case, same please as I'm on 18days now

#

If it resets again, I'm giving up for now

#

Answered 5 questions and it won't reset my countdown oof

short jackal
#

should go back to normal count in an hour or so

celest edge
#

is it a bug if you use an unintended path to solve the box?

spiral flame
#

Creator is probably interested

orchid remnant
#

@celest edge Which box?

celest edge
#

Basic Pentesting

orchid remnant
#

That's a THM one from memory

celest edge
#

I think the intended way to to grab the ssh key and use that to log in as the second user

orchid remnant
#

So they probably wouldn't be hugely interested

#

I've heard there's an unintended there before actually

#

Can't remember what it was, but it's come up

celest edge
#

though ||vim.basic|| is suid root and can read the flag

#

from the first user's account

orchid remnant
#

๐Ÿคฃ

#

I like that

#

Has to be Vim

celest edge
#

can also read the shadow file, but seeing the password, not patient enough to bruteforce it

orchid remnant
#

Yeah, you aren't bruteforcing that password

#

No need either, you can get full RCE with Vim on SUID

celest edge
#

normally yeah

#

could add myself to sudoers ๐Ÿ™‚

#

but if it's a known bug then that's fine

cinder crow
#

down votes count twice when upvoted the number goes up by 1 when downvoted the number goes up by two tested on multiple rooms

spiral flame
#

@cinder crow Yes that's not a bug

#

That's how maths works

#

Score = 5

#

Score +1 = 6

#

Score -1 = 4

#

Difference between upvoted and downvoted appears to be two

cinder crow
#

oh yeah haha wasnt even thinking about that oops

spiral flame
#

@cinder crow However, it is kind of a bug that we can't remove an upvote

cinder crow
#

that what I was thinking in terms of and wasnt even thinking about an upvote straight to a downvote

median dome
#

The 6 was me typing too fast but it still accepted it

spiral flame
#

@median dome yes, that plus answer tolerance

#

Refresh the page

#

Skidy needs to add a thing that sets the answer field immediately after it's marked correct

median dome
#

ah it changed back to 12345

modern pike
#

every pic in vulnversity is broken (not that its needed in my case)

fresh tide
#

every pic in vulnversity is broken (not that its needed in my case)
@modern pike on the webpage?

modern pike
#

on the answer submission screen

fresh tide
modern pike
#

must be me then

fresh tide
#

Not sure but may be try clearing cache and stuff?

#

or it could be just your browser? Try using a different browser or incognito mode?

modern pike
#

i fixed the problem, my laptops time and date is messed up and i have to manually fix it each time i boot up

undone nebula
#

So on Task #35 Question #3 of the Learn Linux room, not sure I understand why its not sudo with the list flag.

#

is there a bug?

hallow hamlet
#

hackbak2019 room does not accept the first flag

spiral flame
#

@undone nebula Just the flag

#

@hallow hamlet That room has a lot of tasks, you need to be more specific

undone nebula
#

ugh...

median sapphire
#

It's probably the first Jurassic Park flag

undone nebula
#

thank you

spiral flame
#

@undone nebula Answer format exists for a reason, use it.

covert kernel
#

Hi i am 14 is it late for me to learn hacking?

spiral flame
#

@covert kernel Wrong chat

hallow hamlet
#

@spiral flame I have found all but expect 1st flag I also found that one but does not accept

median sapphire
spiral flame
#

@hallow hamlet There's a LOT of tasks. Which one?

covert kernel
#

@median sapphire o sory i forgot to change chat๐Ÿ˜ฌ๐Ÿ˜

hallow hamlet
#

task4 question 5

median sapphire
#

That's broken unfortunately, I've already reported it to Dark ๐Ÿคท

hallow hamlet
#

I have just check walkthough even there it says the one I found is 1st flag

median sapphire
#

That task is broken....

short jackal
#

it had a different flag originally but the VM was switched to use the one from the standalone room

hallow hamlet
#

@short jackal so what now ๐Ÿ˜„

short jackal
#

nothing you can do tbh

hallow hamlet
#

did you get it?

#

I bet you did ๐Ÿ˜„

short jackal
#

i got it before it was switched

hallow hamlet
#

can you send that one pls

spiral flame
#

Be careful of rule 5

hallow hamlet
#

but the room is broken

#

I can not do anythig

short jackal
#

yeah not sure if I can share it

spiral flame
#

Trading flag1 that doesn't work for flag1 that does is OK, as long as @short jackal can verify the flag that odesn't work

hallow hamlet
#

@spiral flame you can check it yourself as well ๐Ÿ˜„ eveybody says it is broken

spiral flame
#

I can't check it

short jackal
#

me and ma1ware checked this like a week or two ago, the VMs were merged so the original flag is lost

spiral flame
#

Because I haven't completed it

hallow hamlet
#

me and ma1ware checked this like a week or two ago, the VMs were merged so the original flag is lost
.

short jackal
#

dm me the flag you got

spiral flame
#

basically, if szymex can confirm the flag you got should be correct, then I don't see the problem with them giving you the valid flag

hallow hamlet
#

yup thanks guys

median sapphire
#

@short jackal Me want's flag too ghostblobgib

short jackal
#

dm :)

covert kernel
spiral flame
covert kernel
#

ok

sly cedar
#

Is there a known bug with 'WebAppSec 101'? Cant seem to launch a box with the web application on port 80 or any other port ๐Ÿ˜ฎ

spiral flame
#

Connect to the VPN @sly cedar

sly cedar
#

I am connected & so does the website state, thanks for quick answer

#

there is some tcp port open on 111 tho

#

Hey actually nvm, it does work now, guess it wasnt done yet

#

.prune 3

spiral flame
#

There's not an issue with the room, it just takes time to boot

sly cedar
#

thank you for insane quick response :>

#

have a good one

hazy stratus
#

pls no self bot, violates discord ToS

ebon oyster
#

Hey so I thing we have a bug in the Authenticate box.
Basically
eyJ0eXAiOiJKV1QiLCJhbGciOiJOT05FIn0K
this works
but
eyJ0eXAiOiJKV1QiLCJhbGciOiJOT05FIn0 this will not.

The difference is a newline character. So basically {}\n is e30K and {} is e30=(which is e30 in jwt)

@hollow arch

rare swallow
final raft
#

Think Binex might be broken, repeatedly crashes after being up for about 3 minutes.

#

I've tried around 20 times

sullen vessel
#

The badge Monthly Hacker is not automatically awarded

short jackal
#

monthly one is, the 7 day one isn't

#

the streak counter on the sidebar is a bit off

sullen vessel
#

(i'm not talking of 1 month streak!)

short jackal
#

ah, the top 1 from monthly right?

sullen vessel
#

yep

fresh tide
#

i had 14h to answer to keep my streak, i answer a question then it started showing 1h to answer to keep your streak after reloading after few seconds its showing 2h O.o

short jackal
#

the timing on sidebar is off, should reset to normal hours in an hour or so

sick ferry
#

im having a issue connecting with my vpn it takes forever connecting

short jackal
#

There is an issue with the VIP server, I dm'd Skidy about it

sick ferry
#

@short jackal i figured that i even downloaded new ones and still cant connect

urban flame
#

i had 14h to answer to keep my streak, i answer a question then it started showing 1h to answer to keep your streak after reloading after few seconds its showing 2h O.o
@fresh tide Happened to me yesterday with the same numbers

urban flame
#

If a user is in a room which is made private, it kicks you from the room but THM isn't updated so the user status remains in the room and is then stuck, can't leave as you are not in a room but can't join as you are...

frosty cape
#

Ah thats weird

#

What room is that?

urban flame
#

Authenticate

orchid remnant
#

Ah, Skidy's already seen. Just typing it up to throw into submissions ๐Ÿ˜†

urban flame
#

schrodinger's CTF

frosty cape
#

i had 14h to answer to keep my streak, i answer a question then it started showing 1h to answer to keep your streak after reloading after few seconds its showing 2h O.o
@fresh tide what timezone are you in?

orchid remnant
#

Ooh, that sounds fun actually. Might make that...

strong pumice
#

Ooh, that sounds fun actually. Might make that...
@orchid remnant pls no

orchid remnant
urban flame
#

@fresh tide what timezone are you in?
@frosty cape Same here, don't think it's a timezone issue @frosty cape as going to assume we are on the same timezone

topaz venture
#

oh muirl why