#site-bugs
1 messages · Page 21 of 1
you took the little that sundae gave you to work with and made it actually effective
I'm re-opening ticket because the response was canned: associate did not understand that the spelling of "Go Fish" was wrong and they spelled it like "mahjong", whatever that is.
Please submit a ticket via the support page:
https://admin.tryhackme.com/ticket/complain_about_paradox/
Working fine for me 🤷♂️
Report submitted successfully on Pars!! Admins please take action
*muir
You both need professional help
👀
On the on-web VM "TryHackMe", when we do System > Administration > Users and group, the window pop up but is constantly loading and we can't interact with it anymore
@orchid remnant u broke it
That bit was Skidy
true
Looking Glass is missing here, from my THM profile
I think it only shows a fixed number of rooms?
That's your punishment for making so many rooms 
Ah, seemingly all room lists/general list share the same backend, that would settle why KoTH machine pool table/list also shows only 10 rooms.
Task 23 OWASP Top 10 [ Grammar ]
https://i.imgur.com/jb3EZwQ.png
Am I supposed to be able to see the whole /16? Nmap done: 65536 IP addresses (692 hosts up)
I guess it doesn't matter since it's not persistent
Nevermind
On the "My Rooms" page, the full page listing UI is shown when only a limited amount of pages are possible
@orchid remnant Attack VM has hashcat but a) It's an ancient version... We're on version 6
and b) No working OpenCL so you can't use hashcat properly
Sorry for this Muir, but me like password cracking
Hey, I pushed against adding it 😆
It was on the list of tools, so it got added, but I did say that there was no point in putting it on.
@orchid remnant The issue is, both Hashcat and John aren't properly functional
Nothing I can do about the repos -- that's the most up to date version on 18.04
Meh, fine, I'll take a look at it in a bit

In the empire room some answers are not possible with the latest version of empire
I found by downloading older releases
It's on Dark's list
Darks list:
- Make new rooms
- Administer Discord
- Fix Blue /s
- Fix Empire
I’ve talked to dark about redoing it I may pick it up and redo it once I’m done with my other projects
New Rooms on the dashboard doesn't seem to be in sync with releases; should be showing Spring, Relevant and Internal atm.
Those rooms haven't had their release dates reset properly so they don't show up as new
Room: XSS | Task: 3 | Question: 5 |
https://i.imgur.com/6Ovt3gW.png
this new request will includes a victims cookie...
streak on Dashboard still broken?
(Dashboard not counting KoTH flags submission for streak)
Actually, that XSS room as a few grammatical errors.
(Dashboard not counting KoTH flags submission for streak)
hi everyone did you ever had this bug ? In room "Learn Linux" you can't respond to an answer because fields are not shown ?
I pinged you in #site-support :)
@ruby dawn yup dude .. I'm here for the same reason
Infact on my profile it shows more rooms than I am actually in ..
ok thanks guys
Hello
Another chart bug - The line at the top doesn't start from 0
He’s just so good he starts with the points
I joined git happens earlier, and now i'm not in the room, when i go to my rooms it is there but i cant deploy the machine nor answer the question in the room
oh, so i send an email to someone?
Huh, ok, was it something you did or?
i used burp to edit a request to leave the room
because it didnt had the option to leave
There's a snippet pinned in #resources for future reference
ok 😄
hello all...any resources for git happens room....i found it but dont know what to do with it
@loud latch Hi. That doesn't seem to be a bug. We also politely ask that you respect the fact that it's a newly released challenge room, and as such please don't ask for hints yet.
!rule 13
Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.
Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.
my bad dude
No problem
anybody done with relevant room ?
Doesn't belong here
@lucid crane yeah, that's a no thank you. Including in DMs. Please see rules one and three
!rule 1
Rule 1: No unsolicited direct messages (DMs) to other members of the discord. This includes staff. Verify that the member you are messaging is ok with you sending them DMs. The only exception to this rule is if a situation warrants the involvement of a moderator in order to handle something such as harassment or a situation where another member of the discord has made you feel uncomfortable.
!rule 3
Rule 3: No excessive self promotion. Linking to another discord server is strictly prohibited, just don't turn it into advertising.
streak on Dashboard still broken?
@fresh tide happens to me. I recon it's a timezone issue
idk if its the right place but in AD basics i cant find the cheatsheet (i guess is not uploaded)
/activedirectorybasics is the room
task 8
Mhm yup, I can't seem to see it either. @cinder crow could you take a look when you get a chance pretty please? :3
checking now
oh I may now why.... Will might have taken it down now that they stopped supporting powerview
Can't see mention of a cheatsheet in any of the tasks aside from Task 8 where it says you can use the one provided ^^ unless it's on the box that you need to deploy?
?? where did the cheatsheet go?
i think it would be in the task cause in some part of the text says "use the following cheatsheet" like if there is an hiperlink
It somehow got removed but I replaced it
thanks
Thanks @cinder crow ❤️
Can you double check the streak count on your profile? It's in the same section as your general activity. That's supposed to be the most reliable record from what I recall
IMO Streaks are a bit broken rn. I lost mine of 9 days because of some weird reason that I don't know. (9, it's not much but it's honest work. xD)
IMO Streaks are a bit broken rn. I lost mine of 9 days because of some weird reason that I don't know. (9, it's not much but it's honest work. xD)
@brittle juniper They are very broken
Bee you didn't change your name today smh 👀
hi
a friend is doing "learn linux" room and the as not acces the the qestions, is this normal or is a bug?
@quaint wasp what is his username on THM
Hello. I propably found a bug.
Machine is jack.
I tried use a exploit:
unix/webapp/wp_admin_shell_upload
and i have a problem with credentials
[] Started reverse TCP handler on 192.168.40.128:4444
[] Authenticating with WordPress using wendy:changelater...
[-] Exploit aborted due to failure: no-access: Failed to authenticate with WordPress
what is wrong?
Your LHOST is wrong
ah thanks
Is Macka23
Okay someone will fix it soon
It's a known bug, Ashu will sort it soon.
aah ok ^^ thx
still the same
something is wrong with wordpress auth but login and password is ok
it's not a bug with THM
I'd recommend heading over to #room-help probably
Hi, I am not able to access the questions in room "Learn linux". It is all green but say 0%. My username in THM is okolsen
Leave and rejoin the room
ok..working now..Thanks a lot 👍
Hi there, can I please get the ”Learn Linux” room questions activated
usr: stonestepper
leave the room and join it again
Got it. -thx
H3LP all the windows 0r M0st oF the windows machines auto die after an hour regardless of how long they are extended. Been a issue for months...
Its something theyre already aware of and working to fix
how many people are working on it @cinder crow ?
the admins
can anyone give them a hand?
Nope
D:
Have to report this room
Task 3 question 2
CMN is working on updating that room already 🙂
How would I update REMnux? According cheatsheet should be ||remnux update||
But is not, is there another cheatsheet or something? Even the ******** *** doesnt match
upgrade updates all the tools and adds new one. update updates your existing packages. There is another command that updates and upgrades renmux in one go. If only you had actually searched on the internet
Hey, this was closed. The room is being updated by cmn. Please don't add more fuel to the fire here, there's already too much frustration
I'm just answering 🤔 his question
Am I supposed to know beforehand what questions to answer and what to not
Hey I think there's an issue with 'Learn Linux' room. Every task are already green and there is no progress bar. Even if you complete the room the progress is still 0%. Is anyone facing the same issue?
I've used the room for almost 3 days and it's still the same.
Leave the room and rejoin @true wind there was a bit of a bug with it to say the least. That should have you sorted afterwich 👍
Hi! I'm having some trouble with the PostExploit box. When i SSH into the machine the box drops the connection after a minute or two. The box also does not respond to pings either. After a while it comes back up and as soon as i have a connection, it disconnects again after a minute or so.
Things i tried:
Using different distro and PC
Checking if own packages are up to date
Waiting 10 minutes from boot
It won't respond to pings because it's a windows box
It might be your vpn if you keep disconnecting but idk it could be that it just loses a connection after everywhile sometimes that does happen
for me anyway
Ive been in this for a few hours now and i also switched THM servers. But no luck so far.
the pings isn't a bug but I think when I did that I had the same problem so it might just be the box itself
Well i do receive ICMP replies, and when i do. I can connect to SSH. When pings fail, so does SSH.
Maybe try RDP
Guess well have to wait for an admin :-)
Ye, same issue tho. Gonna retry that again.
Thank you so far :)
Is there anyone to whom i can ping except skidy?
With regards to?
Bug
👀
If it's a security bug, drop an email to support@tryhackme.com and any of the admins can read it
If it's a room thing we can fix it in here 🙂
Ohh cool. Thanks
I'm still confused in those mails when to use which. If someone can clearify that and pin it somewhere?
hello@tryhackme.com
support@tryhackme.com```
info I have no idea
support is for things that have gone wrong
education is if you're a teacher and want to buy in bulk
hello is basically everything else
I'd assume info would be for promotional stuff
Honestly @fresh tide, that's the first time I've seen that email recommended. Bugs are meant to be support@tryhackme.com, iirc. Might be hello
I'd suspect it's just a wrong email
Either way, it all ends up in the same place 🤷♂️
Okay 👌
It is showing the image for mv instead of cp [Learn Linux]
@covert kernel fix pls
It's been reported way too many times
Intended 🤷♂️
As they both do almost the same thing. Just replace mv with cp.
*sigh* Para, fix or I'm going through your rooms and randomly adding in "Paradox is an idiot" in random places
admin abuse reeee
Hah, I wish
#site-bugs have more bug reports for learn linux room than whole thm reports 
maybe?
Asking me? 👀
You or Szy
If one of you has the time to go and replicate that screenshot properly, I'd be grateful
I got nothing to do really. So I'm free
Otherwise we're waiting for Para to get off his rear end
Szy if you can do it? I'm on my phone atm
sure
Thanks Szy ♥️
colors might be bit off tho 
You mean you don't use cmd.exe? 
that'd require me to install putty 
Ach, sod it, that will annoy me, I'll do it myself -- shouldn't take long 😆
i'm pulling it rn
You can shop out the cursor
Hi! I'm having some trouble with the PostExploit box. When i SSH into the machine the box drops the connection after a minute or two. The box also does not respond to pings either. After a while it comes back up and as soon as i have a connection, it disconnects again after a minute or so.
@covert kernel Upping
Sounds like a VPN issue rather than a bug to me.
"vnc.tryhackme.tech unexpectedly closed the connection."
"vnc.tryhackme.tech unexpectedly closed the connection."
@solemn bobcat What do you mean? You deploy a machine, try to control it in the browser but it shows an error?
Hey the Powershell room VM appears to be missing cmdlets. I'm on the enumeration section and don't even have the Get-LocalUser cmdlet
Have rebooted with no success, btw
https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.localaccounts/?view=powershell-5.1 It's part of the module, so maybe try loading that?
Also, you're in a 32bit powershell on a 64bit system
cool thx
@covert kernel Upping
@covert kernel try logout from the PC and re login . It definitely works. I too faced the same issue.
Anthem goes offline sometimes when i open this dir ||/umbraco||
is this a bug or what?
this site it's not working googledorking.cmnatic.co.uk
Are you using the other website to check it’s score?
Hi. I got flag 7 in Linux challenges task 2 but it says I’m wrong
I’m not sure why.
Room: /vulnersity
Task 4
Awkward transition on Task 4 as if the sentence was cut short.
`To gain remote access to this machine, follow the
Edit the php-reverse-shell.php file and edit the ip to be your tun0 ip (you can get this by going to your access page on TryHackMe and using your internal ip).`
Secondly with the part included in the quote, referencing the access page seems to be iffy. Perhaps providing minor instruction on using ip address to grab your tun0 IP?
Throwback task 6: wrong picture for ||Get-NetDomainController||
Will update that in a bit ^
@thin forge the access page does reliably give you your tun0 IP. Just not whether you're actually connected.
That's interesting
I think it makes no sense. But I guess it would depending on how the access page determines how you're connected.
From memory it just regexes the list of usernames that the OpenVPN server gives it
Essentially the OpenVPN servers do reliably give your IP because it's linked to your account and relatively unchanging, but handing the dynamic user list over is more of a problem. That's my understanding anyway, from what the admins have let slip
Alfred Task 1, questions 1: The answer you have as correct is wrong. That is, if you only submit the amount of TCP ports open, it is 'correct' but there are UDP too, which you don't seem to have taken into account
@orchid remnant It doesn't show your IP unless it thinks you're connected
If it doesn't think you're connected
Bearing in mind that it's broken and nearly always thinks you're connected
Then you have bigger problems
It's often the other way around
Damn
Would you like to type up something really quickly about grabbing your IP from your tool in the OpenVPN machine James?
I can throw it in
Or is that already covered in the welcome room?
Sure, it's going to be up 24/7 and it's got a catchy IP.
http://10.10.10.10/whoami can be used in scripts
I’ll check it out here in a bit after I wake up
hey guys, just got a 30 day streak but a badge doesn't show up - am I missing something?
It can take upto 24 hours on 30th day for the badge ( if there's any)
I got mine after completing a room the next day so that’s when you might get it
"Room making tutorial" button in the manage room page only makes my page darker
@orchid remnant After checking the changes you made, it looks great!
I think referencing 10.10.10.10 and instructing someone to do that might be easier and less confusing than telling them to use ip addr
That was my thought
still has da problem of needing to logout because it thinks i'm uploading
I get this too
Hi
Hi
Hi
how do i change my username or delete my account in tryhackme?
Email support@tryhackme.com
If you’re deleting your account to change your username it’ll be the same time as changing the username since they both go to the same email
So id recommend just waiting for them to reply
For the former
so changing the username is possible?
yes
thanks 😉
welcc, asking nicely always helps too! pro tip, it helps a lot with social engineering too 
Social engineers are just people who have learned the word please
i cant change the official writeup of my room
its a onedrive link
it looks like
wait
it actually saved it
but it still gave me the notification
Bugs alert:
While loading my rooms page when the Room /myrooms call is not yet completed and i press filter completed it throws error (which is not an error per say but null case handling would be useful)
But weirdly, even after the response of myrooms the filter completed doesn't work. And still shows Uncaught TypeError: Cannot read property 'length' of undefined.
I get it for the initial one, but latter one seems like a bug.

That's a bit of a bug when you start filtering i.e. Filter Completed before the whole list loads @cosmic imp if you were to refresh and let it load it should display okay (:
Or hyou may have joined a room that became private i.e welcome to tryhackme room
hey guys I got a problem... for 2 days some rooms are being disconnected and I don't know why
I ping them but sometimes it's working and sometimes it doesn't
There are some rooms that dont respond to ping
yes I know but I mean when I ping them in a first time it respond and after few minutes the room doesn't respond... like if the room has been disconnected
That's probably not a bug and probably a VPN issue?
yes maybe but my vpn is still connected
That doesn't fix all VPN problems.
Hello,'Rooms In' on my dashboard is incorrect
@cosmic imp I have the same issue and haven't gotten a reply either 😦
Mine appears off by two now as well 😫
omg what is that name
🤔
▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓ you clearly call him/her/they/it this
There's something funny about it being Szy and finding that
@short jackal stop breaking the rooms 
@covert kernel already mentioned to skidy and it'll probably be resolved soon™
BugHunter for a reason 🤔
szy special flags

Ma1ware please. I've found SO many. mostly paradoxs' rooms
haha grammar go brrrrrr
Forum Sort By option is broken. When you select Top and then Newest . it won't show you the newest posts.
Theseus doesn't appear on the new-rooms API - https://tryhackme.com/api/new-rooms
It will fix this for every room
Aaah - Awesome 🙂
Leader board for "Australian - All Time" works and I am showing up there but "Australian - Monthly", as can be seen, shows at the top that I am #11 but I don't show up in the list.
Am I supposed to see this on a fresh machine? Why is there user data from someone else?
That’ll be history of commands that were run when the box was being setup (:
Doesn’t look like bash history was cleared when the AMI was made
Is that supposed to be happening?
It’s not supposed to be there, but there’s nothing revealing in it / any actions from another THM user
They’re just the commands from when the admins were setting it up to deploy onto THM, usually it gets cleared but I guess it was missed this time (:
I see. Thanks for the insight!
A long tiem ago I joined the linux challenegs room when it was free
now the room became a paid one
but there is no mroe button I can't unjoin it
👀
Nice workaround, it worked, but a proper buton woudl be nice.
It tells you exactly what to run
That’s not what it tells you to do
gem install bundler:1.17.3
sinks away into hedges
come out of hedges youngling
I am new, trying to start the Kali Machine and I keep getting an authentication error, any help?
Could you screenshot it? 🙂
Misti I responded
Select another machine e.g if you’re using attack box, switch to normal kali. Then boot it up and once it’s loaded terminate it and boot the original one again
anybody run into any issue where you completed a few rooms a few days ago, and now it doesn't show you completed them?
Check if there are new tasks in the room
nothing new, looks like it just reset the progress I had on the room
just gonna do em again eventually, more practice
Uhm … how does one change one's location?
Selecting the correct one from the dropdown doesn't seem to update the profile, at least the change does not seem to persist.
Also: Negative ages are totally a thing in the profile 😄
What about it
Im trying to ansewr the very last two questions ... well i got the last question by working around my issue but for the question: Which group has a capital "V" in the group name? im trying to use powerview .. specifically Get-DomainGroupMember -Identity "Domain Admins" -Recurse but the powerview script doesnt appear to include this funcationlity
Use the cheat sheet
I am, that command is from teh cheat sheet
Get-DomainGroup -MemberIdentity Admin2
Why are you trying to find members of a group?
that command is supposed to "# get all the groups a user is effectively a member of, 'recursing up' using tokenGroups"
which for the question ... what group has a capital V .. seems like what im looking for
show me all the groups that admin2 is in, ok.. now Administrator... ok now etc etc
why not just list groups why are you trying to list groups that a member specifically is in.
Because by listing groups that a member is in youre not going to find the answer
searching that cheat sheet to try and find something applicable
well i solved it, but what i needed wasnt on that cheat sheet
a cheat sheet usually isn’t designed to hold everything needed it gives you a base to work off of and maybe a few off the wall commands that aren’t easy to just guess. There are two ways in that cheat sheet that allow you to find the groups as well as with a tiny bit of guess work or research find that get-domaingroup is what you want
the only solution for it would be for me to make my own cheat sheet however Will has already made an amazing cheat sheet as one of the creators of power view and an amazing hacker
the get-domaingroup is not the option i used to solve it
👀
Does anyone else face cmd freezing issue. I have okayish internet connection but my terminal freezes on alot of boxes. Also if one some box port 80 is open accessing the website is one hell of a task. I have tried restarting openvpn and changing the server.
https://tryhackme.com/leaderboards something is up with Monthly Leaderboard
Hey! I think there is a potential bug in the leaderboard section
These are the monthy standings
These are the all time standings
Where is the bug?
@topaz venture Was taking a look at tonythetiger ( https://tryhackme.com/room/tonythetiger ) again, its been a while since I've completed it and I found that the link to your blog in task 5 is broken( https://blog.cmnatic.co.uk/posts/exploiting-a-java-de-serialisation-attack-on-windows-demo/ )
No CSS on the old one? 👀
I'm moving everything
the only problem with using a static site gen :\ you're a bit screwed if you gotta change anything
CSS should load on that now tho
if not, have fun 
oh hang on I got the posts mixed up
Lesson in tryhackme doesn't see pictures
...
Now thats fixed ahaha
Lesson in tryhackme doesn't see pictures
@covert kernel I have already told you what the problem likely is. This is not a bug.
Yeah, just saw it, thanks CMN
@topaz venture bana mı gülüyon yarramm
🧐
ne var len
Please keep it in english
I'm going to take a very big assumption that wasn't offensive. English please.
It's offensive from what I gather
bakarız
@spiral flame Press on the correction and you'll see the meaning
@covert kernel English.
But I have told you the issue
And it is not a bug
Please go back to #general
@covert kernel Final warning. English only.
ı am TURK ı no spek engılsh
This is an english discord.
Are you sure your suggestion will work?
Sorted @median sapphire 👍
@topaz venture Now you sort it! 🤣
I tried to reference that damn post in my exam and couldn't find it!
@spiral flame You're your man, brother. it worked thx
🧐
@median sapphire ?
Where is the bug?
@fair cypress On the leaderboards page. You can see for yourself
This is the bug - Before today(3pm as I was aware) the leaderboards looked fine. Now what happens is, if you make points, the monthly standings reflect the worldwide standings which should not be the case.
With the Kali inbrowser machine, there a problem with metasploit, you have to uninstall it and reinstall it before you can run any metasploit commands.
Do you by any chance have a picture/copy of the error? 😅
I can get it for you
Was it this by any chance?
Yeah
@fair moon @frail vessel I'm not sure which one of you found it first, but could you please retest the point duplication bug. If you manage to get it working again, please stop testing it and let me know.
Looks like Kali is gonna need a working snapshotting as well
@frosty cape Briskets was the first to notice it, I'll give it a test again now quick
@frosty cape Briskets was the first to notice it, I'll give it a test again now quick
@frail vessel sounds good. i'm sure suitguy mastered the art lol. i just wanna put it out there i didn't do it on my main! 😄
Yes please
Also with the Kali Box, Im not sure if this is because of the developers of kali or the snapshot of the image, but when you highlight the url in the Url bar, you cannot delete it and instead it copys it to your clipboard
Actually @frail vessel, if you have not been given the extra points then it'll be ok.
Your monthly/overall points should have only increased by 1 instance of answering it correctly.
The fix to get metasploit up and running on the kali box is just updating ruby and installing gems but
but
No idea why it's broke as of like an hour ago
this problem has happened since the new kali was updated
i just forgot to say anything
for both problems
!rank
Yeah the repos for Kali have been a state
!rank
!rank
Wait the race condition was successful?
It did multiple submissions but my points only went up once
You're welcome my dude
Just pushed a patched version of the Kali box @sterile shadow (: metasploit is fixed amongst a few other updates
Thank you. 👍
@olive drum task 8 question 1 encorrect flag -r but no request file
Isn't url -u
my vids on tryhackme go for 4 seconds than stop for 1 minute, it's also happening for others in america, not just me
The videos are going to be moved to a CDN (at the moment they’re served from an s3 bucket in Ireland) which’ll resolve this
Not sure when that’s being done, but it’s been noted (:
It would be great if the video could float down the page as you worked on tasks
Just while we're talking about that, I know it's not really a bug
Well I'm out of try for today 🙂
this a bug? Seen it in a few rooms
@frosty cape could I im about a finding?
🥩
this a bug? Seen it in a few rooms
@rugged spindle Which room is this in? I fixed this, so it might be from an old issue.
Old KoTH machine doesn't die after reset
I can still get rev shells back from it.
(IF it shows dead to users, then its prolly depleting resources, because I setup a loop to send me rev shells and even after the reset, its sending them)
hello, i found a bug of the Tryhackme Discord's bot, it happened that i made "!docs room-notes" and it gave me the tryhackme level's page 😦 #bot-commands
idk if it applies or happens with another ones, but i found that one
it's known and it's being fixed
ok ok
ah
and in the Tryhackme Level's page, is missing the "bug hunter" level
:))
or that one isnt obtainable ??
it isn't obtainable by normal means so idk about that
I have a problem with my account i think , i joined about 92 room and completed 90 but it know shows that i have completed 80 , so i checked it but it's 90 . any one had this before?
92 rooms shitttt i just started htb getting bored😆
Same problem with me
@old rampart i send them an email last night but no response until know , did you do any thing or you just think they are going to fix it soon?
am i being really stupid or have the links for rooms on the manage rooms page broke? they go to the actual room rather than /room/manage ?
I think someone just said the same thing in tech support so although you’re stupid I don’t think you are in this case
am i being really stupid or have the links for rooms on the
manage roomspage broke? they go to the actual room rather than/room/manage?
@mild breach This should be fixed now, sorry about that.
yep fixed now thanks :)
Using the !rank command with the bot, if you add a # whatever you type after it (as long as the username before it is on the THM website) it will ignore and thus you can get strange names through the bot:
gib jabba BugHunter 
I wish
not that smart
!rank Heiss#DoesThisWork.WhoMadeThis...
😎
Gooooood thing that didn't work
If it had, that would be the second time this month I've made the Bot ping everyone
I mean you can use the bot to ghost ping right?
In what sense?
I thought it wouldn’t ignore the whole message
The bot ignores symbols
So adding a symbol after the correct username means it passed whatever to the output
If it had, that would be the second time this month I've made the Bot ping everyone
@orchid remnant Ah, you only have that in certain channels?
See here’s another symbol that works
@orchid remnant Ah, you only have that in certain channels?
@spiral flame Only in #733142795325538356
Ah yep
I'm dying that this is a thing. Luckily it did get its perms removed. https://cdn.discordapp.com/attachments/559443389058252800/751956419091103794/unknown.png
Room OWASP Top 10, Task 21 #2: seems that there is a bug.
@umbral grotto go to /, then follow the link
@umbral grotto go to /, then follow the link
@spiral flame Solved.
It's a pain, I know
Well, its a good workaround. Thanks. 🙂
I managed to get a wrong answer to be accepted by pressing enter then accidentally adding a period after. The delay allowed the answer to be accepted and also to lock in the mistake.
Answer tolerance is beautiful
Well that's taking it impressively far
lmao
joining an old game that never started because of insufficient players is marked as completed and shows the last player joined as the winner:
https://tryhackme.com/games/koth/9829
I think there is a bug with number of rooms enrolled (and completed)... Or maybe I am counting something wrong
wdym?
It's known @eternal cove 🙂
Skidy's fixing
I can see I have joined 66 rooms... That's the same number of rooms it shows on my profile... Also on my profile it shows I've completed 54 rooms... So technically 66-54= 12 rooms I have not solved... But in my rooms I can see I the number of rooms that I have not completed are only 4
maybe you left some of them ¯_(ツ)_/¯
I don't think so@short jackal😅
As far as I can remember till date I've left at max 2 or 3 rooms
@orchid remnant is it the same issue I described?
@covert kernel
@spiral flame
@covert kernel zthlinux
@pine quiver i just wanted to be included
@pine quiver I'll include you
I'm not sure if this is a bug
It is indeed
That
tneeds to be capitalized
@sick coral You're going to find that anything done by Pars, has plenty of grammatical errors.
I'm trying to point things out as I go 😅
I just don't play often 🙈
But I did finish that box
Room
Whatever
:D
Progress ! 😄
If you see the room is by Pars and he's messed up somewhere, just DM him "uh oh".
lmao
The one i'm working on now is made by DarkStar7471 so 🤷♀️
make sure you report all of those, hehe
shouldn't be 100% since i have one task left
supposed to be Math.floor not Math.round
Talking about progress:
The level progress bar on the dashboard is pretty broken: The width of the actual bar (in the style attribute) is too wide to reflect the progress in the current level, while the aria-valuenow attribute seems to be stuck at 25, which makes the accessibility extremely confusing.
:/
well I need help with my certificate, I requested it, but it's already about hour and still nothing comes up, only "please wait..." message
I have no idea how long you're supposed to wait, but I would imagine it'd be instant 😦
@tawny raven this ThrowBack? 🙂
yes
Feel free to DM me with a copy of your certificate and I can give you the role in here @tawny raven 🙂
Or if you don't want to show your real name, just DM me your TryHackMe username and we can sort it out that way 😄
@orchid remnant That's not the issue
They don't have a cert
As in, they requested it and it wasn't given
They've waited 2+ hours now 😦
idk how long you're meant to wait 😦
Should have the badge
Yeah, I pinged Skidy in #749634929129685022
ahhh
Not really a bug, but a misleading hint. Room "25daysofchristmas", task 22. The hint suggests the password is within the first 30 elements of the rockyou.txt set. It is not the case (roughly in the 90k range).
Yep it's broken
The standalone is fixed
Someone just needs to copy the VM from the standalone room over
👀
hey, so it seems like there is some problem with smbclient on both linux and thmAttack machines:
is that IP hosting an SMB server?
has anyone noticed in Access machine it never loads your IP and status?
also cant get to the openvpn page
so normally it loads the data without a problem
but i noticed that some of the users actually have a invalid vpn server set or smth and it makes the details api route hang
what's the 404?

@short jackal 404 is just when I try to download my openvpn config file
what's the vpn server you have currently selected?
ah i see it in the screenshot above
@short jackal dw its was me being a dumb as I didnt realise you had to select a server before it shows you its status 🤦♂️
😄
@pine quiver yup, it's the "Relevant" room
@verbal igloo vpn connected?
ssh on the virtual machine
is openvpn on the vm?
not sure, but i cant really connect to it through vpn
my ISP blocked the ports OpenVPN uses
Oh, okay :)
Or forward slashes if you don't want weird excessive backslashes
yup, it works, thanks a lot 🙂 also, "/" > "\"
That doesn't concern THM 🤷♂️
hey, I'm currently doing the "Internal" room, where everytime I try to login to the wordpress, the machine's IP gets translated to "http://internal.thm/"
that's because virtual hosts are a thing
add that to your /etc/hosts
and it'll work without a problem
oh, thanks 🙂 i knew that there is a hosts file in windows, but couldnt find it in linux
has anyone noticed in Access machine it never loads your IP and status?
@barren gazelle Change VPN servers and try again
I think it's a bug but this score is block for 3 days now
I didn't earn points or experience
while I'm answering questions
are the questions empty or do they require an answer?
Some rooms don’t give points and questions without answers do not give points
yes but I mean I start a room 3 days ago "owasp juice shop"
it was giving points
but np
just a feedback 🙂
If it’s feedback why post it in bugs
ok then mb
Unless you’re actively doing challenge rooms then there’s no issue :)
well ty for information have a nice day
You can launch multiple machines if the rooms are private. I have 2 private rooms' machines running atm.
hello, i reached 7 days streak (it's showing 8 days on the left menu) but i didn't get the 7 days streak badge anyone knows why?
Wait another day it doesn’t appear straight away
oh, okay
Hello, I subscribed to Tryhackme last week and I have a little but annoying bug when I deploy a web browsed Kali. The problem is that when I select/highlight a text (for example on the firefox url), i cannot delete it by just pushing the backspace key. In fact, I have to put my cursor at the end of the URL and delete each letter one by one with the backspace.. Do you know where does it come from ?
(Firefox is just an example, I have this bug on all apps, like pycharm for example, where it is very annoying to remove line of code one by one....)
It's because you're using the web browser
sshing into it will fix the issue but I don't know of any other fix
ah damned..
Web browser is the purpose of subscribing ahah
(also the private rooms of course)
You can just backspace without highlighting it
@hallow pike I think I know what you mean, I've added it to my bug list, will fix in the next week or so.
Thanks Skidy
For the moment, as Jabba mentioned, use the backspace.
yes but when there is 300 chacracters for example in a script, you have to push the backspace key during 20 seconds lol
Skidy is RDP/VNC etc still open?
Thanks so much
Do the script on your home computer and paste it onto the machine 🤷♂️
I was very frustrated with that 😛
Skidy is RDP/VNC etc still open?
VNC is, not sure about RDP.
I was very frustrated with that 😛
@hallow pike Try VNCing in, perhaps
Do the script on your home computer and paste it onto the machine 🤷♂️
@brave reef Yes of course, but the problem doesn't occur only on script stuff 😛
Anyway, thanks a lot for your quick feedback ! 🙂
RDP is open on the attack machine (:
VNC uses the same xrdp server, so yeah, RDP is open 😁
@hallow pike bayou can also highlight it all and right click it and then click Cut
RDP or VNC should work better though
there is an issue in launching the attacking machine....its not getting launched
can anyone plz check and get it fixed
@tacit drift
Please go back to #site-support and wait for someone to help
Also, which one of you broke the top bar IP indicator? @topaz venture @orchid remnant
Bro
I realised this as like 20 mins ago
I think skidy/someones changed the instance that gets deployed on AWS
it's got the network card of a t3a instance
I just terminated it so RIP
Just get it to grab it from http://10.10.10.10/whoami
That one was all CMN 😁
Having said which, something funny is happening with that box. My tools keep disappearing from it too
it's ens5 now
Yeah the box is being a bit funky
Eh well yeah I've fixed it on this one
especially VNC
Rebooted this one, can't VNC into it through the browser but can RDP just fine
hey
what are these jitter effects on the web page?
are they supposed to appear ? :3

👀
Are any of your browser extensions interacting with the page?
I'm intensely staring at my page and do not see any jitters or flashing
I'd start with those. I see multiple extensions that could cause a problem, but it's hard to tell what is what with how small the rez is. I think the green swirl icon is Grammarly? I've always had weird problems with it and it de-stabilized my browser, personally.
I'm using grammarly :p, nothing
It has been way more intensive like 2-3 months ago
but it has been minimized with the time
and updates
Run THM in private mode or another mode that disables addons. Problem persists, keep troubleshooting.
It doesn't affect my experience
everything runs alright
I've always thought it has been something you guys created xD
to look cool
but looks like it's a bug or something :3
it only happens on thm
I've used THM on Firefox & Chrome on Debian as well as Chrome on W10 and I don't have issues.
not in any other page
it's got the network card of a t3a instance
@topaz venture Wow, can't get anything past you:)
I found this bug a few days ago: I have had completed the "Pentest Series" rooms before the "Series" update and I still don't have the badge.
It's known.
I completed both the overpass rooms but didn’t get the badge?
I believe that this is a known issue
There are prolly more coming in that series 🤷♂️
Is it a known bug for all the badges in the series
If you complete a room or series before the badge is added, you don't get the badge automatically
It's one badge per series
Yup, cause when the series released, I already had 4 of them completed. Haven't got a badge
Maybe add a claim button for the badge and then when it knows you've completed it will give you the badge
once you have claimed it
Just a suggestion that might help
hey, so I'm doing the Buffer Overflow Prep Room, and when fuzzing using the first script, it crashes after the first iteration and send an exception
I just got an email.
This seems … wrong.
I'm going to have to agree with you there. That's an interesting one.
This happened upon finishing the Looking Glass room. Kinda fitting, I guess 😄
Or is this even an easteregg 🧐
👀
Ah, the series badge also sorry for Looking Glass
Is there one for Looking Glass? If so, it doesn't appear on https://tryhackme.com/badges for me.
Ah, the series badge
also sorry for Looking Glass
@spiral flame Honestly, I love the SSH idea.
There's one for the Wonderland series
Did you complete Wonderland previously?
If not, I have an idea what it could be. I'll try to recreate it if you haven't completed Wonderland
Nope, I finished the Wonderland room before the looking glass one, but haven't done either beforehand.
Is the wonderland series badge maybe hidden in some way?
This would fit the undefined in the e-mail and also the fact that it doesn't show up in my badge list.
And it doesn't show up on my profile either: https://tryhackme.com/p/esclear
@frosty cape this is weird
If I can help with this in any way, feel free to send me a private message.
Welp, oof
same with breakingwindows
Lookingglass doesn't even have the "badgename" key
nvm that isn't necessary ignore me
so yeah wonderland and breakingwindows has empty "badgename"
I'll whack that into #685858111952781324
@frosty cape this is weird
@spiral flame @topaz venture That bug has been fixed in dev, will be pushed live today/tomorrow. Thanks for reporting (& thanks CMNatic for the screenshots with the badge name)
Sweet
Nice one 👍
On badges page: https://tryhackme.com/badges
I want to say Chev reported that, but it looks like it might have been a different page
Oof … docker containers within rooms seem to be unbearably slow.
The box seems to freeze completely and I am not even able to ping it at this point.
I'm currently doing a privilege escalation in ultratech1.
I've restarted the host machine before and it didn't help.
I'm currently waiting for the output of an ls from within the container for … about 15 minutes now I think.
Oh, something just happened 😮
Ah, it began to echo the commands typed before.
Sounds like it died. Doesn't sound like a platform but to me really?
It didn't die.
It is still doing things, I'm currently getting my directory listing…
Still doesn't sound like a platform bug? #room-bugs exists if it's a room bug
I don't know, I thought that this could be a resource allocation thing.
But I finally got the last flag, so I'm out of that machine 😄
You don't share VMs with anyone outside of Throwback or KoTH
I was thinking of the hypervisor, but as I don't know about the inner workings of THM, I can only guess about the source of the problem 🤷♂️
It's AWS
I think I found a platform bug, can I have a personal chat with thm cool guys? XD
If it is a security bug, email jon@tryhackme.com if it is anything else type it here :)
hello@raw karma, jabba?
If you would like to talk in private ask one of themoderators to dm
I got told jon for security issues?
#metordocswhen?
TryHackMe both encourages and rewards responsible security bug discovering and disclosing. Whilst we review every report on a case-by-case basis, we ask fo
support, interesting
Not sure whether its considered security tho, more like businness logic error maybe or sth similar
Yep, complicating it further. That's recently written so I'd assume that one
Awesome, thank you
Attack box THM IP is not showing up
I think @topaz venture is aware?
Yup ((:
The tier that the machines boot on AWS have changed so it broke the script again
Using James ’ 10.10.10.10 on next clone (:
I think there is a bug in the Streaks timing. I did a room yesterday and just id one today. I had a 27 day streak and now it just reset to 1!!!!
There's not, it's a 24 hour timer. When you answer a question, it resets that timer. If the timer hits 0, you lose your streak
Say you answer at 1pm Monday, and 2pm Tuesday, you lose your streak
I am an 0x8 but for some reason I only have the 0x1 role
You need to verify with the bot
If you don't have the "Verified" role, it won't update
As I have noted before, I can't change my country on my profile page.
There does not seem to be a request or websocket message happening when I change the country.
~~This is contrary to the note on the bottom of https://tryhackme.com/subscriptions.~~
Huh. It seems that one has to load stripe's javascript to change one's country. Is this really necessary?
noice
it seems the imgur for tmux's cheat sheet seems not to show for me, the page itself is blank maybe is on my end but i found it strange since some of the keys in the sheet due to the low quality are a bit hard to read since they are smaller
The new UI is looking good but doesn't save my input :(
Waited/reloaded/filled in the boxes again and when I click the update button everything goes blank or "Loading"
Sorry, found out the "Lock room" Button really locks the room down. Locked me out of editing it
Also. I banned myself
w8 where is my deploy button?
0-o
Because the whole room is broken, the vm got removed temporarily I guess
ah that explains
Uh...
Nope. Dang Ubuntu...
Just click "Don't show again" for now -- we'll get rid of the warning in a bit 🙂
hello i cant see an images in rooms even i use vpn (i also tried other vpns) whats wrong ?
the left one in opera with its vpn same room
Images should be visible without any VPN connection
idk also they re not visible in my casual connection
maybe because of my country
it was visible in 2019 kali, i install the new one which is 2020 because of i got some issues at 2019 version
now i cant see an images
king service is having issues l
w8 where is my deploy button?
@hard horizon Just give it an hour @hard horizon
Because the whole room is broken, the vm got removed temporarily I guess
@short jackalNo it isn't. Just a username had to be changed
It's uploading as we speak 😅 Online in a bit
The site doesn't appear to be querying the king service right. When curling the IP address of a machine, the username in /root/root.txt is inputted correctly, and is responded when CURL'd (see first screenshot)
However, this isn't reflected on the koth lobby nor the API (see the second screenshot)
user's kingTime is also 0
Even with 4 resets on the box. It seems to be having problems for other people too https://discordapp.com/channels/521382216299839518/559443389058252800/755025918510235739
I don't play koth and don't know any of the PoE's to test but
@frosty cape thoughts? It was working as of yesterday
user's kingTime is also 0
Let me take a look
Thanks!
The match ID for this specific test is 10209, but it seems to be happening across other matches too
Ah, I know the issue
There we go
All fixed.
It was a permission thing on our end.
Legend
@frosty portal @untold pewter The issue has now been resolved
Thanks for reporting, you too @prime rapids (although a bit more detail would of highlighted this sooner) 😄
i could have reported it with more details but there were chances that some other player have messed with it
Thanks!!
Ah for sure, I understand @prime rapids (: Sorry I missed your message, I would of asked you to DM just like I did with the other players
🙂
very very weird tho, been playing last night, didn't encounter any issues.
This probably popped up today.
@prime rapids @frozen timber @untold pewter apologies, I assumed it was just another deadlock issue.
no prob 🙂
No issues man..(bade bade shehron m choti chizein hoti rehti h)😂
When completing Simple CTF it doesn't appear to show as completed in the room list. There is also a duplicate of the room. However it's marked as completed on the room and user profile.
Hi, in nmap room, the hint of the question 4 of the task 3 is worng, at least nmap show me a version on the virtual machine that is not which the questions accept. Look it please.
It shows me a newer version.
#room-bugs for room bugs @wet sky
Sorry
I wanted to report that my subscription expired but I was still able to access/still enrolled in the learning path that I joined prior to the subscription expiration. IDK if that was intentional. I unenrolled in the path and tried to re-enroll and it did not let me enroll again (which it shouldnt)
@frosty cape just a heads up
I wanted to report that my subscription expired but I was still able to access/still enrolled in the learning path that I joined prior to the subscription expiration. IDK if that was intentional. I unenrolled in the path and tried to re-enroll and it did not let me enroll again (which it shouldnt)
@somber wraith Ah, thanks for letting me know. I wasn't aware of this:)
The poweshell command to run the powerup script doesnt work it just sit there and does nothing
someone might want to update that lesson so we can complete it .
Thank you
[Task 3] Privilege Escalation
https://tryhackme.com/room/steelmountain
Would be best if you shared screenshots of your attempt so we can troubleshoot it. The tool works fine as far as I know.
Would be best if you shared screenshots of your attempt so we can troubleshoot it. The tool works fine as far as I know.
@autumn wave
Now it works. I am such a male karen. can I speak to your manager hahaha
thanks for the help
You’re welcome
@spiral flame @topaz venture That bug has been fixed in dev, will be pushed live today/tomorrow. Thanks for reporting (& thanks CMNatic for the screenshots with the badge name)
@frosty cape This issue with the missing badgenames isn't fixed yet, is it?
@deft tartan Not all series get badges.
Ah, I see, so there isn't a badge to be gained from the wonderland series?
No
Steel mountain (issues)
[Task 3] Privilege Escalation
Question 3
Upload your binary and replace the legitimate one. Then restart the program to get a shell as root.
There are two issues with this vm
- in the msfvenom it tell you to create a reverse tcp named Advance.exe but there no executable named like that in the IObit directory
the screenshot should be changed to ASCService.exe
PS > . .\PowerUp.ps1
PS > invoke-Allchecks
ServiceName : AdvancedSystemCareService9
Path : C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
ModifiablePath : @{ModifiablePath=C:; IdentityReference=BUILTIN\Users; Permissions=AppendData/AddSubdirectory}
StartName : LocalSystem
AbuseFunction : Write-ServiceBinary -Name 'AdvancedSystemCareService9' -Path <HijackPath>
CanRestart : True
Name : AdvancedSystemCareService9
Check : Unquoted Service Paths
- when you try to delete the file I get an error saying that I dont have enough rights(i tried use meterpreter, shell and powershell)
meterpreter > rm ASCService.exe
[-] stdapi_fs_delete_file: Operation failed: Access is denied.
also tried getsystem
so it looks like I have to escalate privs in order to be able to replace the Iobit file
Instead of replacing it just place it in the directory and try it
Thanks rad but I am just saying that the instructions should be updated
no worries man. thanks for the suggestion 🙂
This isn't a bug or an issue with the instructions.
There is no file that requires removal. Best recommendation is you research unquoted service paths a bit so you understand the mechanics of how they work. You aren't supposed to hijack or remove the ASCservice.exe.
is Throwback Network Labs stipe payment have issue ?
i see blank screen when hit buy with card
do you have any adblockers and/or use brave?
I have adblocker, should disabled it?
worth a shot -- also check dev console and see if there are any errors
I will thanks
Why do new rooms not showing in "hacktivities" when ordering based on "Newest"?
is it a bug or am I using it wrong?
its actually showing in terms of the time it was uploaded on THM not released.
shouldn't that actually be based on released?
Yes it's being changed
here is my console log for Buy ThrowHack netwrok with stripe checkout-a09f84d9f1f…b1ff93ccad7a34.js:1 Uncaught TypeError: e.supportedLocalesOf is not a function at checkout-a09f84d9f1f…b1ff93ccad7a34.js:1 at Array.every (<anonymous>) at checkout-a09f84d9f1f…b1ff93ccad7a34.js:1 at Fe (checkout-a09f84d9f1f…b1ff93ccad7a34.js:1) at checkout-a09f84d9f1f…b1ff93ccad7a34.js:1 at Object.dispatch (checkout-a09f84d9f1f…b1ff93ccad7a34.js:1) at Ai (checkout-a09f84d9f1f…b1ff93ccad7a34.js:1) at checkout-a09f84d9f1f…b1ff93ccad7a34.js:1 at Module.<anonymous> (checkout-a09f84d9f1f…b1ff93ccad7a34.js:1) at c (checkout-a09f84d9f1f…b1ff93ccad7a34.js:1) at Object.<anonymous> (checkout-a09f84d9f1f…b1ff93ccad7a34.js:1) at c (checkout-a09f84d9f1f…b1ff93ccad7a34.js:1) at checkout-a09f84d9f1f…b1ff93ccad7a34.js:1 at checkout-a09f84d9f1f…b1ff93ccad7a34.js:1 checkout-a09f84d9f1f…b1ff93ccad7a34.js:1 Uncaught (in promise) TypeError: e.supportedLocalesOf is not a function at checkout-a09f84d9f1f…b1ff93ccad7a34.js:1 at Array.every (<anonymous>) at checkout-a09f84d9f1f…b1ff93ccad7a34.js:1 at Fe (checkout-a09f84d9f1f…b1ff93ccad7a34.js:1) at checkout-a09f84d9f1f…b1ff93ccad7a34.js:1 at checkout-a09f84d9f1f…b1ff93ccad7a34.js:1 at dispatch (checkout-a09f84d9f1f…b1ff93ccad7a34.js:1) at checkout-a09f84d9f1f…b1ff93ccad7a34.js:1
when i switch to Firefox it fix
Do you have any browser extensions
Most of the time when I select something (double click on a word or just selecting it) and then press backspace it's not doing anything. I have to unselect it and remove it one by one. This is in Chrome and Opera. On both VMs. No I did not search for this on discord. If this has been reported multiple times why isn't it fixed already?
I also cant remove it by typing. No button works.
Download my configuration file on ACCESS throws an 404 error
happening if my VPN Server is EU-Regular-2
yeah have a problem with the vpn
VPN issues are @sly raft's domain if I recall
I've fixed it - but need to figure out what is at the root of the problem Thanks for reporting guys:)
It’s proper English the way it is
Uh, not sure about that Bob
Should be either "with" or preferably "against" in there
It's colloquially correct as is, but not proper English
yeee
I suppose I stand corrected
You do now 😁
Hiya, just spotted this guy, I thought I reported it 🙂
Fixed 🙂
You’re choosing the wrong exploit
You need to load number 2 but either way it works for other people
How so? Im in room eternalblue and task 2 question 2 is literally this answere
So if none of them load then restart the VM
And what did you mean by on Botha VMs @rugged spindle Attackbix and Kali?
Yeah
That's broken in Metasploit @rugged spindle @brave reef

No it isn't. Just a username had to be changed