#site-bugs
1 messages Β· Page 23 of 1
@reef anvil is this a site or room bug? Typically you will get room bugs resolved faster here
site bug, its a top 10 vuln, not sure if its still valid as I haven't tried it in 2 weeks π€·
Have you seen the bug bounty docs?
Yep! I submitted the details as requested
Great
Has this happened to anyone?

Hello guys, need help, I found some hard-coded cryptographic keys in an target what to do with that, it looks something like this
private static final byte[] 7r38r = {12, 74, 81, -80, 32, 101, -47, 72, 117, -14, 0, -49, 70, 25, -12, 54};
!rank
@dull kite This channel is for reporting TryHackMe platform bugs
Oops, I'm sorry
Messages working? Everytime i try to send a message this happens, logged out and back in and it still doesn't work, tried with an user that i wanted to message, then with this alt account that i have
yeah so remove a character off the end
And use the dropdown, otherwise it won't work
It's a weird system IMO
Yeah, it would be nice to have an option of sending messages when you visit someones profile IMO
it's not a bug..just a typo...Room Hardening Basics Part 2 / Task 9 ---Chapter 3 Quiz --- / question: (Yey/Ney) - GPG is based off of the OpenGPG standard (Answer is Yey). Should say OpenPGP. Room's creator Nameless0ne . Btw, cool room π
@median dome
Lol thanks for the heads up
no problem..really well presented rooms...I appreciate the time and effort..just this tiny bit π
@median dome Also Task#14 should be in Task#2 place..just following the order π
Yeah man it's on the list haha. Been busy with this new position
Found a bug when viewing my rooms and selecting the box to filter completed
Here is an image from the console:
unable to remove bad machines
what do you mean? You canβt just delete them?
I have found probably the most important bug ever: The z-index on the .ribbon class in ribbons.css should be a lower number, so the user's dropdown can actually overlay it (a z-index of 2 instead of 100 works)
This is what it should look like
This is what it looks like
Oh, we know. That's a classic one that's been brought up hundreds of times for months. At this point we just kinda accept it π
But... I have a fix! :p
I am new on this, but i was trying to start the COMPLETE BEGINNER path, and the rooms are loading all time, not being able to do it: any idea?
Not a major bug but still a bug (I typed helo instead of hello and it said it was corect (this "bug" may be intentinial))
Ahh okay π
If you refresh, it will show the correct answer
cheers
hi I'm blocked in chargement page for the room "What the shell" it 's normal ?
Profile/My Rooms the filter completed isn't working at the moment
[10:26 PM]
and when i navigate in the same options to the last page. the numbers to navigate the pages are gone and you are stuck.
[10:26 PM]
hope this helps to get it fixed
[10:26 PM]
cheers
Same issue for me at the moment...
These never load no matter what I do.
Its on the paths page after I click this (trying to get to 100%)
Its making me redo the linux walkthrough. It says it gives this badge. I have this badge. I have also done the other 3 linux rooms.
On the Linux Fundamantals Part 3 room, Task 7 asks you to create a directory containing a file in order to run a binary. However, on the current version of the VM, the directory and file have already been created. Possibly just not wiped when re-creating the VMs?
The VMs weren't recreated
It's just a bug that Paradox hasn't fixed, it's been like that forever.
Gotcha. I don't remember it from when I did the Linux Fundamentals room before, but it's been a while. Thanks!
On THM, the instances don't get reset. They're lost forever when they're terminated. When you click deploy, it spawns a VM from the template VM.
Yeah, I just figured maybe someone was testing the template and didn't wipe that directory
That's not really possible
Gotcha
Whenever I click on the "Hint" button, there is no popup, but the page behaves like there is cause I can't move the page anymore unless I click anywhere else on the screen (The Hint Popup is supposed to closed too by doing this)
So is it possible that these is a hint popup, but I just can't see it for some reason
I think that is the case, cause I also can't see popups when the answer is submit I right/wrong. I am using Firefox
https://tryhackme.com/hacktivities?tab=series - The mouse hover icon on the image of the series implies it can be clicked, when in fact it cannot
Updated locally, will be updated when we next push.
Fixed locally, will be live when we next push.
Mind clearing your browsers cache?
Which room is this in? Let me check with FireFox (mind sending over the verison of FF that you're using too?)
Mind refreshing your cache?
That is an impressive number of replies π
Still doesnt load them
Was on a role
What browser & verison are you using?
Can you screenshot your console output too please?
(F12 -> Console tab on the Paths page)
Browser: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:83.0) Gecko/20100101 Firefox/83.0
I'll take a deeper look into that tomorrow, thanks for sending it over.
Yup
Thanks for the reply. This is unfortunately not room specific for me but happening in every room. FF Version : 83.0 64-Bit Windows which is marked as the latest update
Sweet, thanks
Am getting"google block ip... When am using theHarvester
Undefined text where deploy/download button is supposed to be
Edit: Intro to Networking room (https://tryhackme.com/room/introtonetworking)
which room is this?
I've asked Muir to add the VM back to the task, not sure what is was originally called.
π€ that's interesting
Okay π
Thanks for reporting:)
The complete beginner path is still showing the old version for me. /hacktivities is updated, but /paths isn't. I tried clearing cache, no luck.
VM browser is the old version, Host is the new.
i can't copy things from Active Machine. When i click mouse 2 autopasted active machine's terminal area
what should i do ?
k also appears in /paths
hey
I can't access the website
it just keeps throwing hcaptchas at me
no way to do anything
You often need to solve a couple
There's a thing for reducing the amount posted in #resources
last time I solved 10+
so idk but it seems quite weird to have to solve 10+ captchas without even seeing the website despite being logged in...
could you do some server side magic there?
Nope, because I'm a discord moderator
:C
The tradeoff here is 10-100 people have to solve a lot of captchas, or the site might get attacked and become inaccessible for everyone
Try the thing posted in #resources
not rly a bug but more an annoyance. When you hover on your profile pic and go down to click on any of the options you have to down quite fast otherwise the drop down disappears. Would be nice if the dropdown faded out a little slower and then if you hover on the fading dropdown it still shows π
it could be a simple css transition between 100% and 0% opacity π
I've installed this fancy addon and tried again... nothing, just endless captchas
this doesn't make any sense
tbh I'd guess I'm either stuck in some weird loop or my ip is part of a banned range...
could someone please have a look at this?
Endless captchas
Help
Not a bug and check #resources
I mean it kinda is a bug
When I wanna go a to the path's main page I'm currently enrolled in by clicking on learn and the the name of the path it always leads to the path's enrolment page
Hello There, While running through introtonetworking there was a question that requested an IP address of a host, however the host only replied back with an IPV6 address and the answer is looking for an ipv4 address. I'm not sure if it was a "trick" by designed just wanted to point it out!
Try specifying -4 in the command @ember harness
Thanks a ton!
it is a bug
It's fixed anyway
new user... cant ssh into my first machine, It is deployed, i am connected to vpn, i am using format ssh user@host, the error I receive is Permission denied (publickey).
I never get the option to enter my password ...
#room-help :)
ah noted..
"My Rooms" section is completely broken. When trying to search I get an error, when clicking on any number of the pagination buttons, it will either show an empty page or only lists a few rooms but no longer any pagination buttons. Tested with latest FF and Chrome on Mac OSX and Windows (3 different combinations in total)
hi!, believe I've found a few bugs in the catregex room (I think it has to do with the way submit evaluates, and regex probably). Which is the right channel / propper way to report it?
@earnest igloo I think you need to report that in #room-bugs
#room-bugs would be suitable for those.
I think it's been mentioned here a couple of times already, but the "!verify" command doesnt seem to work with the bot right now
ahh thanks
Hi, I have a bug in my account I'm level 0x8 but in the dashboard page it says that the next level is 0x6 while it should say next level 0x9
Is THM website down?
seems down
Hi, on NetworkServices 2 i've got already finished task but i didnt touch them .. .and there are no questions on bottom of them
[edit]
title nfs2
@covert kernel Can you try leaving and joining the room again please
it doesnt help
@frosty cape Sorry for pinging you. This issue seems to have appeared again. User has left and rejoined the room, still there. Would you be able to offer some assistance please :)
How are you leaving the room? Using the leave option in the room?
there is only leave path button, i tried to 'join room' on other section and it works there but this one is witout questions...only task 1 and 2 had something to 'click' and 'submit'
on ttop its 100% but in whole category its not
Ah so you need to leave the room (not the pathway), if you click inside the room, go to the green options button and click leave, then rejoin, it will fix your issue.
No worries:) Happy Hacking
Thanks Skidy β€οΈ
Access Desktop in -5952s
"Filter completed" under https://tryhackme.com/rooms hasn't been working lately. I trusted all URLs in noscript & tried clearing cookies and session data but didn't change anything.
couldn't log in... the website told me about some cross site forgery, idk what that means
also I have to solve like 50 captchas, that's just paranoid
One other thing is happening though it is expected but weird at the same time.
- open aoc2
- wait for a while (i don't know maybe half hour or something)
- click any completed button for question.
- it will give u 503 cause of cloudflare
- refresh, it will go to /404.
open AOC2 again
happened to me twice already. The 503 is expected but getting 404 was not.
this should really be reworded to Only subscribers can access this room. As some rooms ie. Wireshark dont even have VMs
@frosty cape? ^^
Can you try refresh your cache please?
It'll be fixed in a code push we'll do on Sunday
i did that still same thing brother @frosty cape
tried different browser, tried on mobile
if that info helps
π
Im having this same issue @native marsh @frosty cape . I just signed up today
hi
i got the same issue also here. i also signed up today
It'll be fixed in a code push we'll do on Sunday
As he said above
i don't know how but my wifi went off for a split second and i
kept spammnig the submit button and now 1 flag counted as 3 flags and this stays the same even if i refresh the page.
I have the same issue in the Complete Beginner path, Iβll wait for the fix this sunday βπ»
I don't know if this counts as a bug but I think it's wrong
on Series -> Breaking windows Throwback is marked as "free" which is not. hope this helped
im sure this has been said a million times already
but i wish when i renew the box it doesnt tell me minutes later that its expired and remove the menu to terminate it later
because its still running, and im still using it
its been reported several times over, its because the room itself is for free users and not a vip exclusive.
U r correct. Breaking windows is not free.
How many of those are XSS alerts ?
Mhm -- not what the question was asking π
no one saw this :p
RiP me
So hey the day 9 task can be seen on advert to cyber
hmm this is all i can see (unless it's being fixed):
I think there was an issue with the scheduler or something. I saw someone saying that they had day 7 already.
Well, if someone completes tasks before they are released, they might risk getting disqualified altogether. Think about it. π
Safest is to report task scheduler issues to staff. π₯³
In the room https://tryhackme.com/room/introtonetworking there is this question under task4. Which layer of the TCP/IP model handles the functionality of the OSI network layer? I dont know I've just read the CCNP material so what do I know about networking. However, since almost all study material and google results showes another name, perhaps that should be accepted as well.
Very very annoying
@lean wind and what other name is that?
Bear in mind that comes largely from the CCNA study material
anyone know why these arenβt loading
been like that for over 2 weeks now
they said they was going to fix it on sunday
gues they didnt
@mystic marsh
i got same problem and others do to
hope it gets a fix soon
yah
if you login through the vnc while the vnc is visible, you get graphical issues
no not login ion thru vnc
tried on my mobile still same problem
tried different browsers to
This is a different thing
I'm not sure
@mystic marsh can you try refresh your cache π
@mystic marsh would you mind DMing me an screenshot of what the output in the developer's console looks like pls? π
whom?
this is what mine comes up with
ok thank you - i'll investigate π
So.. I seem to have both a 7 day streak and a 8 day streak, but no badge π
under your user go to Badges
you should also get an email when they are awarded
Is there some delay between getting 7 days and actually getting the badge?
one of the THM admins may have to check, I know sometimes there is a little delay
@sly raft you able to look into this? π
I'm not sure but I think I just bugged the whole 1 hour a day AttackBox thing.
Well it seems to have disconnected me now.
But I saw the timer jump from 4 minutes (which I had left in reality) to 33 to 0-2m etc.
But it went okay just a weird visual thing
I did not miss a day and it's showing 1 instead of 85 or something!
Can someone help me getting back my streak!?π©
The heatmap and streak don't measure the same activities
I'm sorry, I didn't get you!
Streak is based on questions answered
The heatmap, which you've pictured, tracks other details like machine deploys
You can have a heatmap with no gaps and still have 0 streak
They track different things
and I've been answering everyday and still lost my streak?
Yeah, if it was over 24 hours since you last answered a question
If you answer at 11am one day, then 1pm the next, you lose your streak
ohhh damn.
Lost 85 day streak. hurts af!
Was planning to post 100 day streak on socials in few days, lmao!
Sedlyf
Anyways thanks man.
In /christmas it's supposed to say "accessible" instead of "accessable"
I just got the badge!
hey, idk how often you guys get ddosed but I think the cloudflare setting may be a bit paranoid. It takes me between 5-30 minutes to load the site and even then I usually get logged out somehow...
Additional 5 seconds before the page loads is imo way better than solving captchas at every visit like it was set before.
The logging out never happened to me since the setting was turned on, maybe your browser is clearing the sessions somehow?
any news on this?
@native marsh @mystic marsh try again and let me know π
try refresh the cache please? π
i tried fixing something so hopefully it'll work now!
still the sameπ’
latest chrome
Hey guys in the introtosearch room on task 2 the 5th question on the $6$ hash it doesnt allow the answer if there is no blank space at the end
@native marsh I have the same problem. I reported it in #site-support
yeah its been like this for 3 weeks now almost
we'll be pushing a fix for this today/tomorrow π
@sly raft thank you
is this tryhackme channel?
guys i need to cancel my subscription for this monthy and get refund
@vocal raptor
I have no sympathy π€·ββοΈ Bee signed up for it π
But yeah, that's probably better anyway
bee said not to ping them on the discord with support issues dork
alright , will try this
Email support@tryhackme.com @candid geyser
thanks guys
I know, but I'm a sadistic git
I can't cancel subs anyway
but bee can forward it to the right person
Bee will redirect your email to someone who can cancel subs
the notification for KoTH has some funky grammar
@frosty cape
appreciate you guys sorting this out!!
friend with myself π https://cdn.discordapp.com/attachments/770580957253337098/786673332241694750/unknown.png
Why is that a bug? Loving yourself is the key to happiness
You're not meant to be able to
As soon as you have one friend added, you'll see yourself in the list anyway. π
Updated locally, update will be live later this week.
typo on /room/completebeginner "On the contrary, it's how actually learn to solve the problem."
@sleek scroll That's in a room, #room-bugs
whoops sorry
@sly raft thank you for fixing the problem
Got this weird room when connecting today, i believe it was a room recently created that probably has been removed ?
cc: @frosty cape
Fixed locally, will push later next week to roll it out side-wide.
Looks like trying to change task when you've just opened the room manage page seems to tell you that you haven't saved it when you have
Looks like the images on this blog post are missing:
https://blog.tryhackme.com/year-of-the-fox-official-write-up/
TryHackMe Challenge Link: https://tryhackme.com/yotf
Year of the Fox is the second box in what is now my New Year series of challenge
boxes. Following on from Year of the Rabbit, t...
@orchid remnant u broke it
Eh? I haven't done anything with that
Oh damn it all
404
Yeah, gimme a sec
The rewrite messed up with the update earlier so I disabled it
Gimme a sec
Thanks!
Fixed
Hai i cant see my ranking from country
i can't even pick a country from profile
it used to be there...is there any obvs change on that?
Or does it pick up vpn automatically cus it looks like.....previously it didn't
@visual cliff which country filter you are trying?
It's giving me UK.... cus vpn is connected to the UK
It wasn't this way previously
Oh they removed the country changing option??
I'm not sure about that ^^ wasn't active since last two months.
use burp
ayyy
self friending, also not a bug but a feature request, a way to remove friends π
Also not 100% a bug but I feel like using your Real Name in requests isn't such a good idea
Considering most people only added it for the certificates
potential bug. everytime i click off screen it pops back up
I can not edit any of my own created rooms anymore. Everytime I hit save it only says: Uh-oh! Something went wrong, try again later.
and everytime I select a task, a popup comes saying: You have not saved the task you were working on
I have a potential bug in the Windows PrivEsc room. The command 'sc qc "service name"' only works when written as 'sc.exe qc "service name"'.
Not a huge issue, but kind of annoying if you don't really know why it's happening.
Less of a bug and more of an issue with the room instructions.
hi
@frosty cape ^
Fixed, thanks for reporting:)
port 1337 
Hello thm. I noticed that my country changed. I don't know why. Could you please take a look at this issue
Also one of my friends also noticed same thing
There is a bug for the deployment of machine. Machine is deployed but after certain seconds it says ur machine is expiring soon but when I refresh the page it is not so. Please look into the issue
Hi, in "What the Shell?" room, it seems even though you have 2h timer on windows machine, it expires after 1 hour. @spiral flame suggested this is site bug in regards to machine, hence here it goes π
It's a bug with all windows machines on the site
I can apply a licensing fix lemme find the creator
Ok, i did not understood, anyway at least right channel now
It's okay thanks for reporting (:
!
when mentioning potential bugs, it's best to include as much information as you can, in this case it would probably be wise to give your thm username, the original country, the country is was changed to and when you noticed this
is this some kind of bug .. as i entered the answer in between the gap i jus inserted number and it got accepted ..how when this actual answer has 3 letter
is this bug ?
Nope it's not a bug
When you respond correctly, press the button and immediately add a character. Thats what happened, it counted the one in the box when u pressed the button
@K4oS#8387 @π
°π
²6π
²00π
Ώπ4#8396
By the time you update the answer locally, the correct answer has already been sent off to the server in an AJAX request. You aren't actually changing anything other than your local copy of the answer. Refresh the page and you'll see that it goes away
@wintry solstice
yea got it
Hi y'all, is there any way to use the internal messaging system , do we have to add people first before sending message ?
Nope, you don't
Type most of their name, and use the dropdown to complete it otherwise it doesn't work
Thanks for help π
Hi,I am from India will cybersecurity job demand consist in 2025,I'm going to complete my degree on 2025,will I get job after getting my certificates in this field?
it depends on what you know.
my try hack me account country changed, after i received update timezone email. My thm account https://tryhackme.com/p/moe1n1
My real location is IRAQ but now it changed to Ukraine
i'm not part of the thm team, but hopefully when one of the staff check this now they will have the information needed :)
Okay thanks
Email us! π
Sent one concerning same issue π
dunno if it's a bug or not, but I get the vm expiry warning even after I've terminated the VM
Hiiiii what room is this for please?
The timer still goes down after terminating or adding time
This has been reported tons but never addressed
Tricky to reproduce as people tend to not leave the room open after terminating the machine
But yeah refreshing the page refreshes the timer properly as well
Hello
How can i change country location? At profile
email support@tryhackme.com
I emailed them but not answered ...
Give them a chance to respond
It's a small team for a lot of users, be patient :)
@arctic shuttle please do not be rude.
When?
I am not rude its joke:)
(Top tip: Jokes are meant to be funny)
Its not funny for you not means its bad joke:)
I don't hear anyone else laughing either π€·ββοΈ
Because we type text
Doesnβt prompt a cocky response.
Eh ... π
I think I did not receive the badge regarding the hacking streak
I think it is related to the timezone bug I had yesterday
My streak got manually reset but the server did not notice it, apparently
Okey, thanks!
uh guys, tryhackme keeps me in this cloudflare "Checking your browser before accessing tryhackme.com" loop
its been doing this for 5 minutes now
5mins? Seems like a long time. Have you refreshed the page?
Take about 5 or 6 seconds for me.
I'm also having this issue. It's going infinitely.
What helps is going in private window which suggests it's having to with cookies and such
If you deploy a machine and change browser tabs it takes twice the time to deploy
tested it on chrome and this doesn't happen, seems like it only happens in firefox
Don't now if this is the correct place, technically does not seem so, let me know if there's a better place for this. Just wanted to report that im experiencing considerable performance problems on the new room "Intro to ISAC"
@cinder crow
@sly raft can I get a bump on it
yess just bumped π
DASHBOARD/ACTUAL LEVEL of profile dont match with PUBLIC PROFILE LEVEL on THM website
Looks fine here
How do you mean?
I know some people don't realise that the level on the bottom right says 'Next Level'
π ryt
My deploy AttackBox button seems broken since today, tried other devices and web-browsers with no extensions
Im trying to upload a gif showcasing it but im having a little trouble give me a sec.
If there's something else meanwhile i can get to help, let me know.
hi guys i face problem with iron corp room i checked everything and my vpn is working i can access other machines but ironcorp machine is not accessible ... i deployed the machine 5 times but nothing work
@dawn cargo #site-support
can you submit this bug? room linuxctf : once the room is 100% completed, it won't mark the room as completed.
Hi! From the looks of it, launching the AttackBox or Kali instance does not work while in a room.
Debugged a little and found that launching via the button via Opera does not work. Launching via Edge does work however. Opera did work as of yesterday.
Edge
Opera
You can see the interaction button is different between Opera and Edge. Funny thing: I can launch the attackbox via Edge while keeping the screen in Opera open. Opera opens the Attackbox and i can continue via Opera. How 'bout dat!
Hey! @covert kernel This is a good point. We're (skidy) are aware and are working on a fix for this. Certainly interesting that it works on Opera okay -- do you have any errors in your browser's console when trying to launch between the two browsers?
Thanks!
I think in Opera the selector (Linux OR Attackbox) is working properly. The element next to it (launching the application) is missing/not loaded via Opera.
Using Edge to start the instance, i can work in Opera just fine.
Here's some screens:
Console Edge
Console Opera
View in Edge
View in Opera
@topaz venture
@covert kernel This is absolutely golden. Thank you so much for taking the time to replicate this for us
Hello
I think i have encountered something in Advent of Cyber2 Task 22
After entering the correct answer at the end of the answer i added an extra character and it's accepted as correct answer
:p
wasup
oh xD, i am dumb
I think there is a bug in the second room of the calendar...anyone noticed?
@odd tulip and what bug is that?
I logged to the upload page without using the given ID
What was the assignment for that task?
In day 2 you exercise for a revert shell, you have to find a way to log in the upload page. I learned about the syntax ex: ? cake=piece
"Please perform a security audit on the new server and make sure it's unhackable!"
That was the assignment
There's more than one vulnerability in that application -- it's an easter egg, not a bug π
So, well done finding it. Only heard about three people who have so far
There are a couple more as well, see if you can find them
I'll go back to it! Thanks for your time
Np!
@topaz venture Today i noticed the 'Start Attackbox'-element is back in Opera again!
Keep getting an issue, deployed VM closes after 2 hours even if extend time was requested and accepted (the timer says 1:4:00 - after 1:54:00 uptime, and the left 1 hour should be the extend time) but it closes in 4 minutes, notifying me that time has expired.
Is it just giving you a notification or is it actually closing?
Actually closing
Second time today, first when i took a lunch break and now for dinner π
wait, the VM is still active - just web-interface is belly-up and I'm unable to terminate-it now π
and again, sorry for the fragmentation.
After a reload of the page the vm menu appears
Yeah itβs just how the site handles timers
you only need to refresh the page and itβs still there
hey i cannot access deployed rdp server through remmina. i connect through openvpn. day23
error message: lost connection or can't connect to rdp server
Hello,
@minor vessel Hi
Greetings, i want to know after going for monthly subscription,after completing the time of subscription does they cut money frequently for the next month without interference of user
Not a bug but yes, if you donβt cancel it they will continue to take your money
If you pay via card, not via PayPal
In the room manage page (tryhackme.com/room/manage/my_room_name) if you press "Room making tutorial" it will blur the screen but nothing pops up. Tested on "Chromium Version 87.0.4280.88 (Developer Build) Fedora Project (64-bit)" and "Firefox 84.0 20201217094327 fedora"
hey people!
I came across two typos in one of THM's blog. Will this classify as a bug?
If yes, to whom should I approach to fix it?
Alright
in this one https://blog.tryhackme.com/100k/, under the heading "The 100k Mini-CTF", the second word "celebreate" should be "celebrate".
Also, for the same 100k snippet topic article in https://blog.tryhackme.com/, the writeup's sentences at the end is missing a fullstop after "timeline" and the spelling of "celebreate" needs to be changed.
the snippet needs some formatting too at the end maybe?
Hey, this popped up when I searched the room in google and wanted to ask if this site belongs to THM, as it doesn't have an SSL certificate.
I don't think that belongs to TryHackMe, so you better avoid that
Thanks, just thought it's better for you guys to know about it π
@frosty cape does that IP mean anything to you? ^^
Probably one of our servers that got indexed before I setup the custom whitelisting. Its not publicly accessible:)
The cert is issued to tryhackme.com by Lets Encrypt Authority x3 and the page returns a 403
@fierce tartan This isn't a bug.
Hey guys is anybody experiencing 'Submit' button not working when trying to submit an answer, if I try refreshing I frequently get 404 error (this happens generally in any room AFAIK)
I've got video recorded when this came up if you want me to throw it right here
@covert kernel I suspect it's two things you are experiencing. One is an expired csrf token which prevents the submit button from working and the other one is cloudflare's anti attack mechanisms that use POST requests to access the page which then makes the client think it should make a POST request too after a refresh which results in a 404 because a route like that doesn't actually exist
@short jackal What do you mean expired, this happens quite frequently.
So imo it can either be an expired csrf token which usually happens after like an hour from what I remember or cloudflare playing with you and not passing your requests through.
Haven't experienced anything abnormal with the platform recently so my bet would be on one of those.
You are probably right about the cloudflare thing, but I've got to say token expiration happened like 2,3 times in less than a hour.
Already asked on #general with no answer.
Skynet - Scoreboard shows 90 points for me after three completed tasks. optional apparently completed all tasks and only got 40.
Bug or am I missing something?
if I remember correctly the room was previously set as a walkthrough room which meant people would only get 8 points per question but now it's apparently a challenge one which gives 30 points per q.
As I said in general -- Don't compare your points to others.
Well, its part of the game, isn't it? And how to score points is not transparent enough IMHO
But bow I know, it is not a bug and I will stop worrying
Thanks!
Earning points shows your experience on the platform. While you can consider learning a game, comparing points is not apart of that game. Many changes and variables come into the platforms levels and points, in which can often lead to users getting more or less points depending.
There's a point re-calculation looming to make the site more competitive in some regards (:
but yes
the focus is very very very much the educational element
Hello there my streak are disappeared unfortunately when I opened the TryHackme page @topaz venture
howdyy, give support@tryhackme.com an email @quick cloak
w/ your THM username and explain your case there (:
I have edited that
It's all detailed in the FAQ
No
It genuinely is tho
It says vague things about dependencies on age of room, difficulty, etc. It is not explained how exactly. And even if, you won't be able to see how many points you would get, if you answer a question
Really dont want to argue. IMHO the faq does not explain much, definitely not enough
Ok, but it literally says how it works. 25% less for walkthrough rooms, 30pts/q most of the time on challenges
Ok, 25% of how many points?
When get points reduced exactly?
Wat
Never mind. Let's not argue
It's not arguing. It's explaining what's written there.
I recommend you read it for yourself
Done so several times
Take Skynet as an example. How is an enduser supposed to know how many points will be awarded?
Is it a challenge or a walkthrough?
If challenge, 30pts for each question that requires an answer
If walkthrough, 8pts for each question that requires an answer
Points should not be your focus.
Exactly! Back to learning and hacking now
Dunno if it's a big or the VM being weird, but copy paste towards the attack box is a bit broken
Points are also cut to 25% for older rooms
Nope.
25% on a walkthrough
And less points from the room go to your monthly score if they're older
Well I did an older room today and got a quarter the points
Walkthrough questions are worth 25% of challenge questions
It was a ctf room
What room?
Binex
Then you didn't get 25% of the points
Notice the +25 pts etc
Yes
And the bold text stating a different number
The bonus points were reduced
This is not because it's an older room
It's because the bonus points were excessive and were reduced
Ah probably
Ah didn't notice the discrepency
Math works out, carry on then
The copy paste towards the attack box is still a bit annoying though unless I missed something else
The sidebar copy/paste?
Even copy paste from another browser tab to the VM. It might be a Firefox thing though
The sidebar copy paste only grabs things from within the vm
Ah yep the site needs clipboard access
Except firefox doesn't let you grant that
Ah either I missed a permission or Firefox isn't happy
Ok that's fair
Will try with chrome another time
Hey, just noticed an issue with a deployed machine :
I extend its duration by one hour (total was 1h13min) and when it reached the 1h mark, it closed as if I hadn't extended the duration
correction : After refreshing the page, it seems that the machine is still up, but the pop-up appeared as if it ended.
Hiiiii sorry about that. What room was this for please?
2 bugs to report.
-
when i open room, and let's say i open the dev console it weirdly flickers. And can be seen in the network tab that the css/js files are reloading in an infinite loop.
-
I get notification randomly if I run a box and it expires. Even if I click close on the notification (or don't) it shows another another notification maybe after 2-3hrs. This happens in a loop. probably the intervalID in expire.js is not being cleared properly maybe putting the clearInterval as a first statement of activateTerminateAlert would solve the issue? π
From leggy, with luv

bobloblbaw tell leggy i miss him
wait, leggy left?
Leggy left about a month ago ~ish
I recive an 404 error when switching to EU-Regular-1 and trying to download the configuration file and I can not connect to EU- Regular-2 over OpenVPN. I can connect to the US-East-Regular-1 no problem. As for the EU-Regular-2 I get a KEEPALIVE_TIMEOUT and a CONNECTION_TIMEOUT error. If need bee I have a copy of the log file for my attempt to connect to EU-Regular-2. Don't know if this is report worthy since I am weary new here.
Regenerate, wait 60 seconds, redownload
Still did not work I got the same error for EU-Regular-2 and I still get a 404 not found when i try to download the EU-Regular-1 configuration file
Though US-East-Regular-1 works just fine
I mean, not a bug at all, i think the vast majority of us won't see it, but wanted to let know of that typo (fundamentals)
Hey, sorry I missed your question. It was for the nmap room (https://tryhackme.com/room/furthernmap)
@glass void I'm having the same issue
@covert kernel just switch to the US East it is the only one that works for me
Hi all! I have some issue with Attacktive Directory room. When I submit answer in question "What method allowed us to dump NTDS.DIT?", I get message, that is wrong, but I know that my answer is right. Anybody help me pls.
@tardy stratus This isn't a bug. #room-help
thnx
Something buggy in one of the tasks in the OWASP Top 10 room. Task 29, the components with known vulnerabilities lab. Once the machine is deployed and I've navigated to the web app, everything works fine on initial load. But if I go anywhere on the site, the database breaks, and I get the error "Can't connect database No such file or directory". This also keeps the intended exploit from running and providing a shell. Redeploying is the only way I can find to fix the database. I've successfully completed the task, just wanted to pass the bug along.
Just saw the room-bug channel. If this needs to go in there instead let me know.
Preferably
will do π
@hazy stratus if i get redirected to 404 when i click on download my vpn config is that a bug?
I tried re logging in regenerating
Nothing works
@brazen grove please stop tagging random people and ask in #site-support
I am experiencing the same problem with other rooms. I will provide detail later, currently i can't.
I have not received the badge "hacker of the month" even though the global month leaderboard has been reset, does it take some time to receive it?
You were hacker of the month in your own country @indigo steppe -- not overall
I must inquire that this is not true, i was first with 8060 poitns aproximately
Spiffysec was second with 8032 points.
Last time you showed us a screenshot you were fourth (30th, iirc)
Indeed, but i played a lot recently, and i came up first
Yesterday i did a lot of events that lead me up to the first place
No database of the scores? I can provide photos, chat history, and such
i mean i dont have access to it
Okay, let me know if i can provide something
Hello, I would like to report that at https://tryhackme.com/room/commonlinuxprivesc there is a link to a now private room https://tryhackme.com/room/zthlinux
@covert kernel Can you post this in #room-bugs please?
ups, my bad, sure @spiral flame
using the code blocks when editing text in the task creator is kind of broken
il hihglight a section and press the code block and it will sosrt of not put it in and just make a blank box and not do it
i think its genrally when tehre is a space between 2 lines and you want the code block to surround all of them
This is why we write in HTML, or markdown in Notion and copy it in
Eventually when you make enough boxes and rooms you learn how to finesse the editor
we got a nicer one but it ended up coming with more problems than improvements
Eventually the editor will be a pleasure to use
There's written that your next rank will be Level 10. It's not a bug
Oooo srry
is this a bug or is the sorting of rankings a cron job that doesn't run 'often' ? it says 26 but im actually ranked 28th
Iβm presuming itβs because you and 6 other people have the exact same amount of points but your name starts with A automatically pushing you to the top
That or everyone has the same rank when they have the same points
Hey I have recently come across an account logged in in an attackbox which is not mine can anyone from the team check whether it is due to a bug
What do you mean? π
I use attack box for completing rooms
I think it was last month I opened firefox on the attack box and someone's not logged out properly so instead of login page I have landed in their dashboard
It only happenned once but I was sure someone's account wasn't logged outπ
Also in a browser based attack box if we navigate to any of the room the screen getting extremely small because of the splitview
it says I am level 13 but I don't get next level points
Thatβs cuz there is no next level
level 13 it the highest?
Youβre already god what more do you want from life
Think I should drop this here
Throughout advent, file uploads never work on my Kali VM
I would have to use my windows machine to do uploads instead
Sounds like a problem with your Kali VM there
Hi Guys, I'm trying to git clone Kerbrute tool
But mo Internet on the Host... what can I do?
??
You can ask the question in the right channel
Idk. I downloaded Parrot and uploads still don't seem to work
Wait. It's working
I had to change the network adapter from NAT to Bridged in Virtual Box
okay that's weird ,
PS - already completed alfred
@frosty cape layout a little buggered? between linux and koth?
also the icons are beautiful β€οΈ
tried clearing πͺ and cache but still not showing anything
ah there we go beautiful
@mild breach try now.
ah yeah all good now π
& really glad you like the new design:)
Not a bug, but I think it should be 1 event not events
The search algorithm could very much use work in this instance I was looking for the Windows Event Log room and it only picked up on the Windows keyword
i think this is a bit weird, how the openvpn says "Setup required" with a dash, and kali says "No setup required" with a tick
yeah. that one makes sense if you think about it, but it's very confusing at first. definitely not the best readability
yeah i get why a red dash is good for the free option (openvpn), to try and drive people for the paid option but yeah it reads a bit off
I also feel like i have not 'done' 2109 events this year.
I think its not 2021 but last 12 months progress.
I think so too ^_^
If I'm checking the monthly leaderboard for my country, it's telling me on top that I'm rank 27, but my username is not showing up in the list. It's even showing people with 0 points, from rank 25 - 50 ?
Which country
Austria
Username?
Fontaene
they should update pretty much immediately from what I understand
@lone grail you sure your country is set to Austria on your profile? The timezone fix link for streaks changes the country and it might not be accurate
@short jackal Well regarding to my public profile it is set to Austria, also if I go to the monthly leaderboard for Austria, on top of the page it's telling me I'm rank 27. If I'm going to a different country no rank is shown on top of the page. So yes, I'm pretty sure.
Hello, guys. I'm doing the tryouts
Now that I have the time, I can actually give it a good shot
I'm not doing too bad, but I have a question
For task 7. After I have downloaded the folder and unzipded it, I can't open any of the files.
They all have a .bad file extension
How do I open it?
If anyone can give me a pointer, I would appreciate it
#room-help if you need help or #room-hints
thanks, I'll check it out
Hey my subscription ended yesterday and i still can use the subscription only rooms.
I find a Bug on TryHackMe, where i can report this.?
What kind of bug? Visual bug, room or task bug, or security related?
Security related.
Drop an email to support@tryhackme.com π
I already do this, but i didn't get any response from support.
Bee seems to be away just now. Wonder why
@frosty cape are you able to take a look at this?
Security bug emailed in, but no response π
should I send the bug report on support?
!docs bug-bounty
Thanks.
Hey, DM me your email, I'll take a look
No picture for the Kali Machine room?
IIRC that room is totally deprecated, and you should be using my-machine instead
#introtowindows
unable to access introtowindows room
it says "Owner has made this room private"
any idea how can i access this room
@forest sluice the room code is intro2windows, https://tryhackme.com/room/intro2windows
Is it just me but when I loaded a new page of THM I got 503 errors and sometimes ssh errors ? it seems to have disappeared
Is anyone else seeing their connection status at the top as "get connected" even though they definitely are? I'm using openvpn, did a few hard refreshes, checked a few different rooms, even disconnected and reconnected, still nothing
Just me? cool
Weird bug: Incorrect badge count
My badge count says that I have 5 badges, but when I look at the badge pictures, there are only 4 of them.
I checked my email and I was awarded the "Webbed" badge twice, hence the incorrect count.
Also another possible bug?
This could be a timezone issue, but on my dashboard, it says I answered 0 questions on the 12th, but 94 questions on the 13th. This is incorrect as all those questions were answered on the 12th (It's 12:23 AM on the 13th at the time of writing)
Hi ! Is anybody here who faces a bug with the vpn like me ?
What bug? @storm beacon
2021-01-13 09:24:27 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set. 2021-01-13 09:24:27 DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-256-CBC' to --data-ciphers or change --cipher 'AES-256-CBC' to --data-ciphers-fallback 'AES-256-CBC' to silence this warning. 2021-01-13 09:24:27 OpenVPN 2.5.0 [git:makepkg/a73072d8f780e888+] x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Nov 6 2020 2021-01-13 09:24:27 library versions: OpenSSL 1.1.1i 8 Dec 2020, LZO 2.10 2021-01-13 09:24:27 OpenSSL: error:0909006C:PEM routines:get_name:no start line 2021-01-13 09:24:27 OpenSSL: error:140AD009:SSL routines:SSL_CTX_use_certificate_file:PEM lib 2021-01-13 09:24:27 Cannot load inline certificate file 2021-01-13 09:24:27 Exiting due to fatal error @brave reef
feeling with ya, cant connect to vpn and cant open any machines ^^
Whoops
You have the same error ?
I posted it in the wrong section.
please try these steps:
β’ Press regenerate, wait 2 minutes and then try downloading again
β’ Change VPN server and try downloading again
β’ Log out of your account and log back in.
I tried all of these :/
You switched servers?
nah got a different one
Yup
Keep switching servers until you find a working one.
Ok I'll try thanks :
Kevin ?
Hm?
Im kinda new to this (just started yesterday) and my attackbox is not starting at all
just getting a pop up "Please wait, your machine is still loading.."
Screenshot the page please
Refresh your page
I did, even restarted my pc
and deleted all cookies etc.
trying to get a connection for the last 2 hours now :c kinda frustrating xD
One moment, I'm discussing it with site staff :)
thanks a lot :c
Hey Paul, whats your THM username?
Let me investigate why this is happening:)
thanks a lot β€οΈ
@brave reef I tried the US East server and it worked perfectly thanks
I dont know if its helping, I cant connect to openvpn either
Everything seems okay / working on my end.
Would you mind opening your development console (F12), going to the console tab and then attempting to start the AttackBox
Would you mind trying another browser?
sure
If it works in another browser, please let me know what version of Chrome that is
its still not working (I used firefox)
Do you get the same errors in your console?
no its a different one
something about "splitview" and "SameSite"
its written in german ^^
(version of Chrome is 87.0.4280.141 )
Hm, one last ask. Would you mind deploying the machine from here: https://tryhackme.com/my-machine
Does it properly deploy?
Oh right - so the splitscreen AttackBox worked for you yesterday?
nope same error
that tutorial is kinda hard tho haha
Nothing has changed on our end since yesterday - no new codepushes etc..
The only thing I can think of is your Anti-Virus is all of a sudden picking up the /deploy endpoint and blocking it.
Mind checking your AV?
If you're using Avast, there has been reports of that being the cause of this.
damn
yea ^^
thanks a lot its avast
im gonna try turning it off
could have thought of that
I used Avasts false positive form to have it looked into.
@crystal cobalt rather than turning off your AV, just add TryHackMe.com to the "exclusion list": https://support.avast.com/en-gb/article/168/
Although it is generally not recommended, you may want to exclude certain files, folders, or websites from scanning to speed up your scans or to avoid false positive detections. You can do this by adding individual files, entire folders, and websites to the exceptions list. Items on your except...
well ... its still not working haha
gonna turn it off completly, just to check if its working then
ok its working now, dont know why avast is not recognizing the given exclusion list.. gonna figure something out
thanks a lot β€οΈ
No worries, happy hacking:)
Thank you Skidy :)
Erm g'day, so I got logged out my THM account and erm I cant log back in because it says "recaptcha" failed but their is no recaptcha on the page.
Reloaded the page multiple times
(As you can see some of the assets / images haven't loaded either)
Hard refresh?
Yeah, I think I've found the cause
Something pointing to localhost:1337?
I had a NoScript exetsion which blocks the scripts, I've removed it but I think its still somehow disabling the scripts
Ah oof
Hi just wanted to show this little bug, when i resize the window to middle screen this one little bugger happens the dimensions are 768x974 --> 919 x 974 more or less, generally I think people take great pride in making this website look splendid. π
Its the dashboard page
Thanks, fixed this in locally, will be live later this week:)
CompTIA Pentest+ Pathway --- Shouldn't the rooms have check marks if they're complete? I could be 100% wrong but I've only just noticed this
just wish to say a massive thank you to the tryhackme team ,for not only making it a fun game like enviroment, but also for the fantastic content and tutorials you offer, I have learned so much over the past 12 months or so with THM.
introjsLogic.js:1 Uncaught TypeError: Cannot read property 'className' of null
at _0x7fde7b._introBeforeChangeCallback (introjsLogic.js:1)
at _0x7fde7b._0x3a31c9 (intro.js:1)
at _0x7fde7b._0x320577 (intro.js:1)
at _0x7fde7b.start (intro.js:1)
at startManageIntro (introjsLogic.js:1)
at HTMLButtonElement.onclick (curiosity:formatted:600)
bug with the room making tutorial button
the above is from the chromium js console
hi all I don't know if this is the right place to put this. I want to start the Cyber Defence path, but some rooms that I have already done are shown as incomplete
showing the first few rooms
as an example intro to networking is 100% complete
the path show 32% complete, but no completed rooms (only if I go into the room)
Same
Same, also cannot deploy the attack kerberos room
Which task is it meant to be attached to?
Task 1 I think
Probably a good 100$ in AWS charges lmao
And a cookie. πͺ
Same problem here with 'Attacking Kerberos' no deploy option
Having some serious issues with a basic eternal blue box. Actually all my boxes keep having very intermittent connectivity today. Are there issues?
I am subbed btw
@mental copper #site-support
thanks mate
I should get out of bed and fix that now....
This is more of a bug for the bot then the actual site, but the !docs api provides an invalid link. Where can I get the API docs for THM?
!docs api
This month a gifted month subscription lapsed, and then I resubscribed on my own. Since then, I've been seeing some strange behavior on the site. First, the part that tells me my IP never changes from "Get Connected"
Next, the rooms I've completed in my path are showing as incomplete
Even though I just completed Network Services, and everything prior
Hi, anyone has been able to check this?
Same for me
Same for me here, also in the Web Fundamentals and Offensife Pentesting paths. I also tried leaving the path and enrolling again, logging-off and logging back on and using incognito mode, nothing worked
Not exactly a bug, just a typo 'too' should be 'to' (https://tryhackme.com/room/rpburpsuite) task 12 last line.
An online platform for learning and teaching cyber security, all through your browser.
Certain pihole adlists break the room search functionality. Disabling the below adlists allowed functionality to return.
https://s3.amazonaws.com/lists.disconnect.me/simple_ad.txt
https://s3.amazonaws.com/lists.disconnect.me/simple_tracking.txt
Well ... the start machine button in Attacking Kerberos is back ... glad you changed your pihole ... because i don't have one and where the heck would i have changed it the :D:D:D
thx for fixing the button
Hello, not sure this is the right channel but I joined the offensive pentesting path but is not tracking the progress
Yea doesnt seem to track under those pages
This is intended behavior for now. Will change in the near future after the next update.
I also had the same problem @lament geyser
@lament geyser thanks!
Hi all, I'm doing the MITRE room, I think's these questions are on the wrong order
Trying to download a certificate for completing offensive pentesting path and getting 200 response with a url in XHR request, but 403 to download the link within
same for other paths too
guess its just a kali linux firefox issue, worked on windows chrome
i got 87% on the web fundamentals path
although non of the rooms show as completed
when i click on them i can see that all the tasks are done
Path progress has been temporary disabled
ah, how come?
also, this isn't much of a bug i don't think, but i can't change my country?
For anyone asking about the Paths not tracking progress: it's intended functionality for now. They removed the ticks to prepare for changing codebase.
I have a problem with SSH connection on day 20 (task 25) in Advent of cyber 2, permission denied, bad password. Attackbox and openvpn same problem. i changed machine like 10 times, waited for more than 20 minutes each, every time the same problem
i try to solve the day 23 but cant able to connect
in the networkServices2 room this should be select version()
it is 6 for me in metasploit room task 5 but it says wrong answer
User error: read the question. It doesn't ask for the number.
I noticed one bug again that as my Advent of Cyber 2 room was completed when our event of Advent of Cyber 2 was going on and had ended on 25th December,2020 at that time why it was showing in my recently enrolled section in my dashboard now. I don't know whether it is a bug or not. Can you clarify @topaz venture whether it is a bug or not by taking your time man.
This has been resolved, thanks for reporting (:
AoC Day 6, actual number of types of XSS in OWASP ZAP automated scan and the video/room are in disagreement
Hey Born, this sounds like the normal behaviour of the "recently enrolled" section that you see on the dashboard there. To my understanding, the "recently enrolled" view shows the last four rooms that you have either deployed an instance or completed a question/task in.
Although the Advent of Cyber 2020 event ended on the 25th of December, users can still complete tasks throughout the rest of this year. So I would imagine you're seeing that room still as you haven't or completed a question/task in 4 different rooms since π
I had completed all the tasks at the time of Advent of Cyber 2 man
For example, this is what my recently enrolled looks like
Although I had to hide some rooms there as they're not out yet
For sure (: but have you completed tasks in 4 different rooms since then?
Yeah
It's ok man no worries for that
Oh right -- could you share a screenshot of your "recently enrolled" please? π
Ok
Now you can get the point what I am saying
I was doing the AOC 2 tasks everyday on the regular basis when the tasks were released everyday for the first 25 days of Christmas and I had a certificate of completion of AOC 2 too with me.
Okay awesome! Thanks!
Check if there's a bug or not
And if you were to enrol into another room would that change your display?
Yup
Recently I am doing the What The Shell? room now
That sounds like its normal behaviour
Do you have a few minutes for me to PM you please?
Is that okay? π
Yup it's ok
π
Pretty annoying bug , when extending time on rooms I click and extended it and it adds an hour but when it runs down and gets to the hour mark I then get the expired machine and it terminates .. grrrr
@unkempt jungle that's a bug with windows machines. List which ones that happens on and ping cmnatic.
done. got a failed request. added as friend and ill resend when accepted. Thanks
ping ?
ok kool, @topaz venture Hi , found a bug with burp suite room where the room expires even though its displaying there is still an hour left. Was advised to send u over a message after i posted in bugs. Thanks
simple ctf and advent of cyber already completed but showing on viewing filter completed option in my rooms
!docs student
also this is not a bug
yha i know iam really sorry
any hints on basic malware RE
Ask in #room-hints with the task youβre stuck on
Does coldbox work on windows I couldnt get ||the reverse shell working||
This doesn't sound like a site bug
ok sorry
just wondering.. the old badges(burped,wireshark) still seem to appear when sharing the room badges
I don't know if this was reported before but when I go to my profile to my badge, the page turns grey and doesn't work (stops responding)
Hi everyone, a streak that gets reset before midnight is a bug or tech support? I posted in the tech support channel and would not like to double post, so if it has to be here I'll delete from the other channel and put it here
Email support ^
Thanks Jabba! Will do π
Keep getting rooms shutting off at 1 hour to go, very frustrating!
@topaz venture one for you here π
I think I'm having the same issue as @unkempt jungle - machine still shows active, but anything sent to the target machine just kinda flops after being online an hour and still showing an hour remaining. Terminating the machine and restarting seems to resolve the issue.
Ah thanks!
Sorry I've been offline for the weekend and been hyper-focusing on getting THM stuff done today (hence the silence in the discord recently)
Defo sounds like a licensing thing thanks @orchid remnant. @unkempt jungle and @last sapphire apologies about that. At the moment it's a manual fix that I gotta do as Windows rooms crop up (and the process of applying the fix -> getting it to dev & testing -> then finally onto the THM site) is a bit long winded for obvious reasons
If you could pass along the room codes that you've had this issue with so far (and any further) I'll jot them down to tackle!
this sounds like something that should be automated
It's already scripted, but there are two problems:
A) You need admin creds for the box, which is tricky if it's a member of the community
B) It's a script that Skidy wrote and is (justifiably) very protective of -- we can't just distribute it and tell people to implement it themselves, and we have to ensure that it's not left on the box.

