#site-bugs

1 messages · Page 27 of 1

marsh mango
#

its 30th sep right?

#

today

#

oh okay its next year

rigid mauve
#

hello everyone ! I've got a problem to connect via openvpn... (TLS Handshake Fail) Am i the only one ?

fair moon
#

thanks for reporting this. i've let the dev team know of is this issue

patent garnetBOT
#

Gave +1 Rep to @wise maple

spark gull
#

hello, here to report a bug

#

i won my first king of the hill match but the game doesnt show up in the completed games

#

and i did not get the badge for winning

#

thee game started at 18.30 circa and ended one hour later

near fjord
#

Hello, I was attempting to regenerate my ovpn config file for US-East-Regular-1, however after regenerating the file and downloading it the file was empty. Using the same process for US-West-Regular-1 seems to work fine.

vivid hinge
#

yeah i am having weird vpn problems too. this is a new one for me :
└──╼ #openvpn /home/user/Downloads/snoopbobb.ovpn
2021-10-01 05:23:35 DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-256-CBC' to --data-ciphers or change --cipher 'AES-256-CBC' to --data-ciphers-fallback 'AES-256-CBC' to silence this warning.
2021-10-01 05:23:35 OpenVPN 2.5.1 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Apr 28 2021
2021-10-01 05:23:35 library versions: OpenSSL 1.1.1k 25 Mar 2021, LZO 2.10
2021-10-01 05:23:35 OpenSSL: error:0909006C:PEM routines:get_name:no start line
2021-10-01 05:23:35 OpenSSL: error:140AD009:SSL routines:SSL_CTX_use_certificate_file:PEM lib
2021-10-01 05:23:35 Cannot load inline certificate file
2021-10-01 05:23:35 Exiting due to fatal error

rich berry
#

When we open a split windows as attackbox , copying from any room to attackbox is not possible. Is it a way to do it ?

leaden valley
covert kernel
#

on my profile page, it shows that I am currently charged £8.00

the currency should be in USD right? it reflects in USD for my receipt

near fjord
#

@vivid hinge I was getting that same error with my original ovpn config file, which is why I was trying to regenerate it...I just tried again on the US-East-Regular-1 and the file has some content, but looks like it's missing the content between the <cert></cert> block

rigid mauve
serene bone
#

Weird message comes up after any room's feedback submitted.

Steps:

  1. Submit flags/answers & complete any room, a pop up will appear with "Congratulations", at bottom of it, there's a "Leave Feedback" button, Click on It, Fill ur Feedback and Submit it.
  2. Now go to "My Rooms" by hovering mouse on ur Profile Pic, Or... Visit: tryhackme.com/rooms
  3. You'll see a weird message with "Thank you for your feedback! If you have anything else to add ever, write it here!" but there's no option to write further feedback.

It's Weird to see "If you have anything else to add ever, write it here" without any "write here" textbox or button.

vagrant citrus
#

Learning scheduler is still broken ??

idle shell
#

I don't know how but when I go to My Rooms page, I have all these rooms (100+) I did not join. Is anyone else experiencing this?

stuck horizon
#

Do the staff take bug reports from here or not? I have my one posted above and sent an email and a DM, no reply to anything?

brave reef
stuck horizon
#

Hey, I didn't see anything? Yes, no problem

rose lintel
#

@orchid remnant I can not verify own.Why I cant send msg to bot

brave reef
#

Have you enabled mutual DMs?

tropic maple
#

not sure if it's a bug or it's actually behaving as it should, but I've discovered an interesting behavior about badges.
completing the last room of any THM module rewards a badge to the user without considering if user has completed all of Module's rooms .

my logic says a user must only be rewarded a badge if he/she have completed all Module's tasks.

#

you can test it on the latest released module (intro to web hacking):

by completing only the command injection room you can get the badge

lament geyser
tropic maple
lament geyser
trim cradle
#

@lament geyser There seems to be another problem , recently i changed to my university email on tryhackme hoping to get a discount on premium but it still shows $10 a month. My university email does have a domain of .edu.pk so according to tryhackme policies , i am qualified for discount.

upbeat sonnet
#

hi, the country monthly ranking seems broken. For this month it says that I am supposed to be #31 right now for Denmark, but my username is not in the list of top50 at all

upbeat sonnet
#

after another room it looks like this:

#

so #12 vs #14

lament geyser
# upbeat sonnet so #12 vs #14

There are three users with 104 points, so there are 3 users with a ranking of 12. In the list those three users are listed 12 to 14 (even though they have the same amount of points). 🙂

upbeat sonnet
#

ahh did not even look at the points as they are not saying much tbh (getting 100points never means getting a 100points added to that score)

honest swan
#

@lament geyser I reported something to support@tryhackme.com a few days ago. No updates, etc yet.
Any Leads ?

young quiver
#

there's still the bug where whenever you finish answering all the questions and get the finished message you cant turn off the machine unless you refresh xD

#

Its like that ever since I started thm lmao

leaden valley
young quiver
leaden valley
#

It meas that overlay isn't being removed or disabled by the Javascript

spiral flame
slate kite
#

Was looking through some of the series when I saw this

#

It's a little misleading tbh

fair moon
patent garnetBOT
#

Gave +1 Rep to @slate kite

fair moon
#

it was acknowledged and should be fixed this week 🙂

orchid remnant
fair moon
floral egret
#

Hi, I am facing some problem regarding subscription. If I can get any help

#

actually I was tryinh to have a monthly subscription, but the transaction is not going through the paypal. So i can;t understand if its the problem from paypal's side or tryhackme's side

pearl nebula
#

I was trying to update my level here on discord, and the bot said me I was already up-to-date. In fact, i'm now level 7...

pearl nebula
#

🤦‍♂️

#

Sorry

brave reef
#

Not a problem!

maiden crown
#

hello here !

i face a strange problem, i got my account on tryhackme totally reset.
i got a subscription, i have done some challenge, but today when i'm connect i see nothing !
someone can help me ?

young quiver
#

not really a site bug but the bot said Im not subbed in the rank command

young quiver
#

@ebon oyster I think your'e the one to tell this to xD

brave reef
#

Bot has been broken for a while:)

#

!rank doesn’t work too

young quiver
#

oh oops

brave reef
#

Sorry i meant

#

Rank doesn’t work properly too

#

Hors is fixing it slowly

young quiver
#

best way of fixing things xD

#

he better get paid by the hour and not monthly HAHAHA

topaz venture
#

Hors is just very busy

pearl nebula
#

When i'm trying to add the static widget of my thm account on my github profile, Camo.usergithubusercontent.com (camo) returns an error : Non-Image content-type returned.... I contacted github and they say that the application/octet-stream isn't supported by camo. They highly recommend you to change the content-type of your images to image/png. Is this planned?

cinder crow
covert vine
orchid remnant
#

@frosty cape that might be something to look into? 🙂
TL;DR: The profile badges in S3 have a MIME of application/octet-stream, which prevents them from being embedded. It sounds like it's possible to change, which might be worth doing if so?

covert vine
#

POC to set header on AWS S3 Here a bot can edit or when the backend generate it it can be update at the time of first upload.

gleaming spruce
#

Not sure how big of a bug it is, but /usr/sbin isn't in the kali attackbox's path

#

Pretty annoying when a pre-launch installed binary isn't in path

brave reef
#

Kali isn’t support by us anymore @gleaming spruce :)

#

Or maintained I might add

spiral flame
gleaming spruce
#

Mb

fast root
#

Hey is there anyway to change the country of the account ?

frosty cape
patent garnetBOT
#

Gave +1 Rep to @orchid remnant

covert vine
low knot
#

the pentester badge doesnt work

#

ive activated and have the lucky badge again

lament geyser
lament geyser
low knot
#

I was control f5ing to hard refresh the page, not sure if that does it. I’m AFK now but will check tomorrow

lament geyser
#

I just checked your profile, it shows it correctly now. 🙂

lament geyser
patent garnetBOT
#

Gave +1 Rep to @low knot

low knot
#

No worries 🙂 thanks

rose lintel
#

.

covert kernel
#

The Leaderboard Ranking of KOTH is showing different result on every refresh...
Sometimes my Country Specific Rank is > All Countries Rank

#

These are the results of consecutive refresh

cinder crow
#

Doesn’t seem to be random so I assume that’s intended but I’m also not sure why it does that

covert kernel
covert kernel
#

Issue on IDOR, Task 7

Key-word detection says IDs is the same as IDS for Intrusion detection system in its description box
Got told to post it here after posting it in #room-bugs

lament geyser
patent garnetBOT
#

Gave +1 Rep to @rotund light

covert kernel
mild breach
covert kernel
#

Would make sense

lament geyser
brave reef
#

A toggle for room developers would be awesome

sharp cloud
#

can be sitebug, in some path, as free user see cooming soon?

#

(threat-and-vulnerability-management) Misp room (there is free, but not work)

#

same situation
security-operations-and-monitoring btsuricata room ; btgraylog room ; btopenedr room

#

same situaction
threat-emulation module ...btatomicredteam room

scarlet forge
#

I was doing the 'Intro to Web Hacking' module, since it's a part of the JPT path for the current event that's running, and coming to the end of the module, I had one room left, the SQLi room. Yet, the system auto awarded me the badge for completing the 'Intro to Web Hacking' module, and I haven't done the final course yet. Just figured I'd let someone know. I'm sure it's probably because the SQLi room is newer than the others or something and the system doesn't know to include it in the requirements. Maybe someone can look into it when they have a chance.

torpid cradle
#

on the badge script

#

it still says lucky

#

not pentester

brave reef
#

Hah that’s funny

#

I know why that’s happening

#

@topaz venture could you drop a message in slack? ^^

frozen ocean
#

My badges got reset a few days ago and I put in a ticket on the site, but didn't hear anything back It says I've only got a 6 day streak, but if you look back over my past week I never missed a day. Is there any way to get my badges restored?

spiral flame
patent garnetBOT
#

Gave +1 Rep to @spiral flame

patent helm
#

Once a learning path is completed, the certificate of completion outputs the username instead of the full name. I have emailed support@tryhackme.com to have it changed to my full name but no reply yet.

patent helm
#

@knotty acorn

orchid remnant
# patent helm <@!404824509925949480>

Pinging random members of staff isn't going to get you very far -- especially given the person you pinged is a content dev with no control over the actual site.

#

Emailing support was the correct thing to do, although I don't believe it's possible to change the name on a certificate that has already been generated at this time.

brave reef
#

That is accurate^^

#

I cannot update the name on your certificate.

patent helm
#

Sorry, just saw them in the "Staff" category and did not feel like scrolling down to find the correct person to ping.

#

that is very unfortunate though.

rose sequoia
#

Allo mates, found a bug. If you claim the 1 day streak freeze prize and then unlock the 7 days streak freeze prize they are not cumulative and the 7 day wipes out the 1 day.... This is a notably sucky user experience.

peak flint
#

Fix please sudo baron in Room Internal

spiral flame
peak flint
wise vigil
#

i upload .ova its blocked at 39% for 2h why ?

edgy pike
reef sky
#

Hi there. I was working through the “Introduction to Web Hacking” and finished all of the modules except for the last one, “SQL Injection”. However, I was awarded the “Intro to Web Hacking” badge after completing “Command Injection”. Wanted to pass that along as I assume you would want all modules done for that badge.

lament geyser
reef sky
dusky wadi
#

Hello Team
Do you accept the security vulnerabilities associated with TLS ?
Knowing that it is considered : CWE 200 Exposure of Sensitive Information to an Unauthorized Actor!

dusky wadi
patent garnetBOT
#

Gave +1 Rep to @orchid remnant

tropic maple
#

redeeming a 7/1 day streak freeze prize causes user's subscription renew date to freeze too.

#

my subscription was supposed to be expired on 24/10/2021, i redeemed a 7 day streak ticket on24/10/2021 and I'm still a subscriber (26/10/2021).

#

I believe that's the reason why I'm still a subscribed user.

frank hawk
#

Seems to be some issues with guacamole in a room im currently in, loosing network connectivity and shit all the time, just wanted to let you know.

gleaming spruce
#

Rather a discord bug; I can't see the 0xD channels because of the pentester role replacing it

#

can't y'all change the way the bot uses the special roles? For example keep the standard role when setting a special role

#

(although I'm pretty sure the bot uses the API or whatever to pull levels from the website, so that'll be fun)

spiral flame
dusky plinth
#

Hey guys I saw a recent video where a researcher discusses how VPN users can attack other VPN users because there is no ACL to stop them from doing that. Is this being addressed? According to the researcher this issue has been reported multiple times to THM.

spiral flame
#

If you're connecting insecure systems to a network full of hackers, there's a problem

#

Also, there'd be nothing to stop them pivoting via the target machines seeing as you need to be able to reach them.

#

You should take steps to secure your system before connecting it to an insecure network.

dusky plinth
#

Well I know that, but shouldn't the platform take the necessary measures to reduce that risk? Other platforms do implement some type of ACL to protect their users. A paid learning platform shouldn't be the equivalent to the wild wild west

#

A lot of users are relatively new to Cybersecurity and don't know the basics of securing their system. The platform should do its best to protect these users and it does not seem to be the case.

celest crater
dusky plinth
patent garnetBOT
#

Gave +1 Rep to @celest crater

orchid remnant
halcyon sedge
orchid remnant
#

Put simply, to prevent users from connecting to each other in a network, you need to drop routes to each device. Easiest way to do that is subnetting, but that poses a huge problem to implement

dusky plinth
halcyon sedge
#

for example, in hack the box, hacking another user is not as easy as it is in tryhackme

brave reef
#

Yeah but it's still possible

orchid remnant
#

Each VPN server is already routed to prevent you from connecting to devices in other subnets (e.g. 10.11 can't connect to 10.9), but, whilst you could, theoretically block off 10.9.0.2 from connecting to 10.9.0.3, you can't stop 10.9.0.2 from connecting to 10.10.10.2, as that's a target machine, or stop 10.10.10.2 from connecting back, as that would stop any reverse shells, etc

brave reef
#

You're also warned when you sign up to HTB, or at least you were when I signed up.

dusky plinth
#

This is a VPN network, actually by default most if not all VPN servers don't allow this user to user communications, also known as U-Turn by default

orchid remnant
#

In other words, no matter what you do, it will always be possible to attack others, because the only way to prevent it destroys the functionality of the site

orchid remnant
#

That happens to have an OpenVPN server in it

halcyon sedge
brave reef
#

How would you know?

dusky plinth
kind scroll
hazy stratus
#

tl:dr any level of protection you put in place is moot

#

anyway you look at it, there is a direct path to another real person

orchid remnant
#

That said, as Spooky says, it's all a bit moot when you can just get around it anyway

#

By design there has to be routing between users and vulnerable servers 🤷‍♂️

hazy stratus
#

if you're genuinely concerned about a user compromising you, use the Kali VM or Attack Box VM.

orchid remnant
#

(Which is what new users are advised to do anyway)

dusky plinth
#

It's risk reduction, that's what Cybersecurity is all about. You can never be 100% secure but you can apply controls to reduce that risk. And again if other platforms have implemented it why not THM?

orchid remnant
#

True enough. I've pinged CMN to get him to look into that aspect 🙂

dusky plinth
#

Thank you. Much appreciated 🙌🏾👍🏾

orchid remnant
#

Having said which, that particular control is really not going to do a whole lot 🤷‍♂️
Worth having in place, but A) everyone in the network is a hacker -- if they're good enough to have a hope of compromising you then they can sure as hell pivot, and B) We already give people AttackBoxes on the 10.10.x.x subnet, which removes pivoting from the equation completely 🤷‍♂️

#

(Same applies to the HTB Pwn box for that last point, I believe. No idea what they do for VPN controls)

hazy stratus
#

afaik AWS won't let you implementing a "ap isolation" esq feature tbh

orchid remnant
celest crater
spiral flame
merry pawn
#

all about that subject, sounds weird to me, "we can't avoid that risk, if we implement a solution the platform will not work, we are not as bad as it looks". i like the platform but the risk is enought to think on it.

halcyon sedge
#

I don't understand why you still make it so easy for anyone with bad intentions to attack members of your platform.

brittle trout
#

you are teaching people how to do pentesting and secure their things but you do not secure yours

lament geyser
#

In AWS, Network ACL is defined by subnet, Security Group is defined per instance. 🙂

dusk marlin
#

This guy made a big mess, but yeah, I know we have to secure our own machines but we as a costumer need a secured place

dusk marlin
#

I trust this platform, and prove me wrong

halcyon sedge
#

but, probably all this is not a new notice for you

halcyon sedge
lament geyser
#

Please note that this channel is to report site bugs. So if you have concrete examples of issues, please let us know. 🙂

dusk marlin
celest crater
hazy stratus
#

I believe Tim knows. He means of any more issues

orchid remnant
bleak wraith
#

Things always can be better. We have faith in you THM. We love you, and we want to stay here. If technically don't have a general solution, consider a ROOM to teach how to protect our VM to avoid instrusions.

dusk marlin
#

@bleak wraith 👍🏽 best words ever

steady dew
# spiral flame If you're connecting insecure systems to a network full of hackers, there's a pr...

The problem is that this is a learning platform and most users do not know how to protect themselves against these attacks, at least at the beginning.
In fact they are likely to start with insecure machines.
On the other hand, non-premium users can access premium machines with the same VPN simply by having the machine's IP.
Your argument is disproved, the THM system is poorly implemented and must be fixed, both for the sake of its users and for the sake of the company itself.
If I am going to get a driver's license, I hope that the driving school does not set traps along the way, excusing itself by saying that there are accidents on the road...

spiral flame
#

Systems like Kali are secure out of the box.

steady dew
spiral flame
cerulean vine
#

what was the command on linux to check what network listening services you have running???

lament geyser
#

One last reminder, that this channel is to report site bugs, it's not a channel for general discussion or opinions. Thank you for your understanding. 🙂

bleak wraith
merry pawn
#

they wont to fix it, its very clearly along the reading, they will update the terms and condition and done, "the user has the responsability to not be hacked on his platform".

merry pawn
#

maybe, i like to call it, prediction.

spiral flame
#

Let the site staff do site staff stuff

#

Stop trying to stir trouble here.

copper mauve
#

why did i lost my streak?

#

I even had a 1 Day Streak Freeze from the last action I never used....

steady dew
#

There is an error on the page
https://tryhackme.com/about

Since what is said there is not true, the bugs are reported as the big problem of the VPN and far from proving it, they try to make it look like it is the user's fault for not knowing how to protect himself.
So the text "by constantly speaking to them and taking any actions with their best interest at heart" is wrong.

Will you change it? or is it also the user's problem?

orchid remnant
#

Rhetorical question: the answer is one, and that was actually because the user had downloaded malware from a shady video site and had nothing to do with their VPN connectivity.

#

Believe it or not, this is not actually the problem you think it is. You are significantly more likely to get hacked by connecting to public wifi.

steady dew
orchid remnant
#

That and, as James said above: Kali, out of the box, is actually highly secure.

steady dew
#

I have not given my opinion 🙂 I have reported a typing error of the we

orchid remnant
orchid remnant
steady dew
#

I am not trying to make fun of the platform or be mean, even though I may have hurt feelings when writing, which I am sorry for.
I am aware of the effort involved in a platform like THM, but if it is known it is because of all the users who make use of it.
And I put myself in the shoes of the most novice users and the risk involved, not every initiated person uses kali.
In fact it is quite probable that young and initiated people start from windows machines.

I think the least the users deserve is the status of this report and the changes to apply.
Let's work to make the network more secure, that's what it's all about.

brittle trout
orchid remnant
#

It's basic networking -- of course it's known 😆
It's not something that needs "fixed" because nothing is actually broken.
If anything changes it will be an extra layer that gets added in to perform more isolation -- although I suspect AWS VPCs will make that difficult.

#

Again, there is no more danger than connecting to your local coffee shop wifi, or even to your corporate or school network (you never know who's there, right?)
In many ways there's less, as you should be connecting with a VM which will usually be secure off the shelf.

steady dew
#

I doubt that in my trusted coffee shop as many simultaneous hackers are connected as in THM... so the risk is not the same.
And obviously it must be known by the staff this vulnerability, but you assume that when you connect on a learning platform on cybersecurity these types of holes will be plugged and it is logical that they should be.

orchid remnant
#

I've made a thread for this -- please put your full concerns in there and we can discuss them without taking up this chat :)

orchid remnant
#

If anyone else has any concerns on this issue, please let me know and you can put them in there too

orchid remnant
#

How about now?

brittle trout
#

same thing

orchid remnant
#

Should be sorted :)

covert kernel
#

add please 😄, interesting stuff

hazy stratus
#

if they violate the code of conduct, report it under Section 9.1

blissful pecan
#

Is this the right place to discuss/report a potential vulnerability with the THM site? I did report via "Give Feedback" a few days ago but perhaps Discord is better.

brave reef
covert kernel
#

When you change your password in THM doesn't logout other active sessions automatically, implementing this would be good. (idk if this goes here)

orchid remnant
covert kernel
#

Thx

bitter crag
#

i got scared btw

#

not even sure if i got the tickets

hardy nexus
#

right now

orchid remnant
#

Uh

#

@frosty cape, if you're awake, why is the ticket redemption telling people that their accounts are being deleted?

#

I'd imagine that the event is over if it's on BST, but, uh

hardy nexus
#

I get that message but they gave me the ticket

scarlet creek
#

Jaysus I just got the same notification after finishing an nmap room, my palms got sweaty, mom's spaghetti etc. 😬

frosty cape
#

I will fix it for the next ticket promotion event - thanks for letting me know

orchid remnant
#

Aha, fair. Yeah, seems to be scaring a few people 😆

covert kernel
#

Question: I received the title of pentester. Then the TryHackMe bot set the title. I fell out of the advanced chat room. Can you change that?

orchid remnant
#

Short answer: no

#

Long answer: it will disappear soon giving you access back

covert kernel
#

thx. :)

hollow monolith
#

I'm not sure if this is considered a bug. I've had this happen on a frequent basis; I've clicked "Add 1 Hour," and it only works once. If the timing is close to expire and I try again and it doesn't work, and the room became expired.

glass slate
#

I need to report a bug

rigid bronze
#

Hi ya'll . I need your help . The machine on "Subdomain Enumeration" is not starting . The ip address is not populating here 👉 (http://machine_ip/ ) How do I resolve this ?

lapis nimbus
#

Has anyone managed to find a solution for the connection problem with Task 6 in Linux PrivEsc room in Junior Pentest path? Actually I've just tested all the task's 6 through 12 and have a connection error with all of them.

lament geyser
patent garnetBOT
#

Gave +1 Rep to @lament geyser

surreal niche
#

TryHackMe staff, The vm's are running really slow, to the point of being unusable, Please add more resources. Thanks

mild breach
#

not really a bug but the inconsistency between left-aligned and center-aligned is bugging me

zinc orchid
#

I uploaded a machine , and after trying to test it . I'v figured out that i have to make some changes.
But i can't delete the VM and re-upload it again.
What can i do ?

topaz venture
zinc orchid
keen edge
#

I'm not sure if this is a room bug or site bug,. There are instances when clicking on a task and the page refreshes.

mild breach
#

had that when checking for writeups too ^

young quiver
#

this is at the bottom of the new room

young quiver
#

for the room that came out today

mild breach
#

that's when the room was created, they all are like that

vital plover
#

Hi there 🙂
It is not possible for me to swith tabs in any given room..
No matter if I click on "Scoreboard" or any other tab, nothing changes..

vital plover
mellow basin
#

Same here.

quartz whale
#

I have this issue too. I noticed that appears only after i start a machine or the attack box

soft nebula
#

Congraulations on completing the Pentest+ pathway!
I found a typo on congratulation message when finished the pentest+ pathway

wooden plank
#

During the last few days, sometimes the page will refresh when I try to click on a new task tab, or the page will refresh when I click on the "writeups" button. Sometimes it refreshes everytime I click on "writeups." Anyone else having this issue?

vital plover
wheat heron
#

It happens both with the last version of Firefox and Chromium.

#

So same issue and behavior confirmed by at least 7 persons here.

#

@orchid remnant It's been at least 2 days this systematically reproducible platform-wide impacting everyone is happening. Could you alert the tech guys maintaining the platform please 🙂

orchid remnant
#

@remote laurel fix site pls

wheat heron
#

Temporary workaround:

Execute manually some steps of this function: https://assets.tryhackme.com/js/rooms/public/logic.js?v=3.11

function initWriteupClickModal() {
  const _0x22be06 = document['querySelector']('#writeups-simple');
  _0x22be06['style']['display'] = 'inline-block',
  _0x22be06['addEventListener']('click', function () {
    modalFooter['innerHTML'] = '',
    writeupFormEl['style']['marginTop'] = 0,
    modalTitle['innerHTML'] = '<i class="fas fa-pen-alt"></i> Writeups',
    modalBody['innerHTML'] = getWriteupListHTML(roomDataGlobal['writeups']);
    if (!addWriteupBtnClicked) modalFooter['innerHTML'] = '<button onclick="showWriteupForm(this)" type="button" class="btn btn-xs btn-secondary mb-2">Add Writeup</button>';
    modalFooter['appendChild'](writeupFormEl),
    $('#modal') ['modal']('handleUpdate'),
    $('#modal') ['modal']('show');
  });
}
#

Eg. in the JS console:

modalBody['innerHTML'] = getWriteupListHTML(roomDataGlobal['writeups']);
$('#modal') ['modal']('handleUpdate');
$('#modal') ['modal']('show');
#

This will show the Write-up modal.

#

Enjoy @vital plover @wooden plank @quartz whale @mellow basin @young quiver

remote laurel
#

This has all been reported and we're looking into it. Thank you all for your reports! <3

patent garnetBOT
#

Gave +1 Rep to @wheat heron

frosty cape
patent garnetBOT
#

Gave +1 Rep to @wheat heron

vital plover
#

Thanks @frosty cape

patent garnetBOT
#

Gave +1 Rep to @frosty cape

mild breach
wheat heron
patent garnetBOT
#

Gave +1 Rep to @frosty cape

wheat heron
hollow mesa
#

Hello there, im having an issue where i want to reset the password. I don't receive the reset password's mail (i checked everything) and still got the message 'email already taken' if i try to sign up again. What can i do ? Rip for this email adress ? thx 👍

hollow monolith
mild breach
hollow monolith
mild breach
hollow monolith
patent garnetBOT
#

Gave +1 Rep to @mild breach

mild breach
#

hehe i'm not staff, i just wanna make sure it's not user error before things are potentially escalated to the admins/staff 😅 glad it's fine for you now

next crypt
#

Was idly playing with the button and learned that the Scheduler seems like it thinks things will take years and years.
Example:
Jr Penetration Tester Pathway: ~56 hours
If I set the scheduler to 56 hrs/week, It thinks I should be done by the 5th of June.
Counting from the max 168 hrs, 18 Jan 2022 (Presumably?)
I think it assumes that at 1 hr/week I should be done sometime in 30 July 2028, unless the smaller numbers are skipping whole years.

grim lotus
#

Does anyone have an idea why the skills matrix is not visible in my dashboard? I have tried different browsers but I cannot see the skills matrix anywhere (Firefox, Edge, Brave). Would love to see it to keep track of my progress.

covert kernel
#

Hi. Please can you repare the room "zero logon". I am trying to access it it is not possible. The page is broken AGAIN. It does not load.

normal juniper
#

small type-o: underlined should be "changed" not "changes"

dusk crane
#

My user name not showing up in the country leaderboards ?

gentle raven
#

this is not where I live

zinc orchid
#

@gentle raven change the flag by clicking on it

gentle raven
#

Did

#

It keeps changing back lol

spiral flame
#

It's a bug and has been acknowledged by site staff

stiff tiger
patent garnetBOT
#

Gave +1 Rep to @zinc orchid

sleek canopy
#

Typo in the msg after submitting "About me" details. Horay Hooray

worn thistle
#

When I start any room site give me same ip all times (its down )

#

It says I have running machine , but its not true

#

regenerating vpn didnt help

#

I cannot terminate "running " room

#

Its ok now

spiral flame
covert kernel
#

Hi guys! I'm having troubles with the leaderboard. I'm supposed to be at rank 40 something in Argentina leaderboard but I'm not, I have 14604 points

worn thistle
spiral flame
#

You need to be using the IP listed under Active Machine Information, that's the target machine

torpid cradle
#

the site timer is off by about an hour

cerulean vine
#

and it could not be messed up timezone thingies then???

wraith copper
#

hello, when i connect to oscp overflow with fuzzer.py, it straightly show could not connect to the target? why ?

flint turret
#

@frosty cape

Can the username on THM be made case - insensitive?
It doesn't seem to be a good idea to use the same username with different case

vital plover
#

Hi there 🙂
At my Public Profile, in front of the Yearly Activity Tab, the "M" of Mon and "W" of Wed are cut off on the left side. This is NOT browser dependent.

mild breach
flint turret
brave reef
#

Case sensitive usernames are much better imo and they allow for more availability in usernames

#

As well as that, case insensitive usernames means that all usernames are in lowercase but personally I like my username to have a capital letter

#

Furthermore there’s literally no reason why it’s a bad idea for people to have similar names but with different cases.

There’s more than one person called “John Smith” in the world, it’s your job to let your employer know which John Smith you are

#

And finally, if you sign up with “Jacob” but then you use your username as “jacob” then that’s your fault for typing a different name to what you signed up with

#

Thank you for coming to my Ted talk

flint turret
brave reef
#

As someone in infosec, you should be trained to spot scams

#

It’s like “stean.community” instead of “steam.community”

flint turret
#

But in terms of another person's perspective, for a scenario like picking the profile link during a call, the user must define each letter as capital or small right ?

I just xprnced it a few hours before. For a 5 letter username, he was coming up with a sentence

brave reef
#

As the manager of the inbox, I experience it all the time. I think it could be made clearer from sign up that usernames will be case sensitive but even in other games and platforms I’ll tell my friends the same case as how I signed up and how it appears on the leaderboards

cosmic drift
#

Hi, I have an issue I want to let the devs know

There's a bug with the leaderboards in which it locates me as someone from Afghanistan when I am really someone from Chile, the issue being that the whole leaderboard bugs out because of it, placing me in last place when in reality I should be way higher in my own country's score considering how many rooms I have completed. Please fix it! I really want to compare my score with people from my own country.

zenith belfry
#

Hi support, I'd like to ask for help, just noticed that my country profile changed upon checking the leaderboards.

zenith belfry
alpine halo
#

My country too changed

#

it's still in Afghanisthan

#

I can't change it

prime oak
#

is the site forgetting our old inputs? i partially did a room yesterday(tor room) and today some of the answers were gone, I re-entered the answer and clicked submit.

#

faced this in another room yesterday as well.

covert junco
#

It shouldn't have accepted

#

Obviously answer is this:

orchid remnant
barren ridge
#

Hello! I'm pretty new to the site (and this Discord) and wanted to submit a problem I've been having recently. I'm working through the "Complete Beginner" path and have found on a few occasions that when my deployed machine is nearing the termination time, I'll extend it and still get the notifications that it'll be expiring soon. Then, after a few minutes, I get the notification that it's expired and regardless of the time left on the machine, it'll terminate. This isn't a huge problem, but a mild annoyance.

vital plover
halcyon sphinx
#

Hello! i have was intented to buy 1 month subscription but by mistake bought 15 months.... Could any one help me on how to get refund... $150 is a huge amount for me

halcyon sphinx
#

Thank you

zenith belfry
round wind
#

Hello I am having an issue with the country, it shows am in afghanisthan when infact am not

topaz venture
keen marten
#

i cant use the hint button

#

in any room basicly

#

and in my browser it throws up errors

#

like this

#

each time i press the hint

#

am i doing smth wrong?

#

or is this a bug

spiral flame
#

That image is very truncated

turbid heart
#

I think there is a bug that occurs when you update your profile info, my country on tryhackme was originally Ireland, after adding some info about myself it changed my profiles country to Afghanistan. I have tried changing it back but it doesn't save to Ireland, but instead reverts back to Afghanistan

#

im on the afghan leaderboards, used to be on Irelands'

#

+353 is Ireland prefix

covert kernel
patent garnetBOT
#

Gave +1 Rep to @waxen quarry

covert kernel
#

anytime

patent garnetBOT
#

Gave +1 Rep to @waxen quarry

covert kernel
#

Anytime

eternal scaffold
#

Is there someone I can speak to regarding my thm 30day streak? I seem to have lost it at one point but I made sure I was on it everyday.

eternal scaffold
patent garnetBOT
#

Gave +1 Rep to @mild breach

covert vine
# frosty cape Thanks for letting me know - I've fixed this in dev, will be live in the next fe...

Sorry for directly replying

The static badges are now embedded in GitHub and work fine. But are not updated when you regenerate the badges. WHY? because GitHub need a new header as Cache-Control If there is no Cache-Control header GitHub doesn't update it. So please add a Cache-Control to some realistic value like 1 day or 12 hours or no-cache
IF you set it to no-cache It will cost you (tryhackme) money. Setting to real value like 1 day will costs GitHub bandwidth.

Setting Cache-Control to a age require to add time as cache-control: max-age=120
else Cache-Control: no-cache
More info about cache control header from morzilla docs - https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control

Further evidence how and why issue happened- https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/about-anonymized-urls

TL;DR - static badges doesn't update automatically embed on github. Require a header name Cache-Control set to a real value or no-cache (can be set using metadate)

The Cache-Control HTTP header field holds directives (instructions) — in both requests and responses — that control caching in browsers and shared caches (e.g. Proxies, CDNs).

covert vine
drowsy lynx
#

My student email is not recognised, the site is displaying the same 10$/month, what should I do?
Edit: Emailed already.

dapper pike
#

okey generating certificate, for advent 2020 generate certificate for aoc 2021, proudly achieved 😄

surreal tiger
#

Hi

orchid remnant
# surreal tiger Hi

Could you please not post "Hi" in half a dozen different channels -- especially not channels that have a specific use? 🙂
Drop into #general if you want to chat

#

Make that a dozen. Jesus that is spammy

surreal tiger
#

It said that i needed to do this for verification

#

Sorry

spiral flame
surreal tiger
#

The website or so I thought

spiral flame
#

If something said you need to spam something, it needs to be changed

surreal tiger
#

Turns out i got trolled

#

Sorry about that

lavish oasis
#

I am facing an issue where I am unable to change the country option in my profile

#

When I update it, it says that it has been updated but as a soon as I refresh the page. There is no change.

fringe folio
#

Which is the latest version of Windows Server? Answer: Windows Server 2019 is wrong

mild breach
fringe folio
vocal badger
#

Hi , I have a problem with my account in tryhackme . After I cancel my subscription , my region has been changed to afghanistan , I tried to change it but after when I go to my profile it shows my region afghanistan again . I had typed my phone number too , there was not any problem when I had premium . Please help me to fix this problem.

zinc lichen
vocal badger
patent garnetBOT
#

Gave +1 Rep to @zinc lichen

marsh geode
#

hi guys. on my public profile it shows a ukraine flag when actually i dont live there. is there a way that i can change it? i didnt find any option on my profile settings and the above link with update timezone redirects me to my dashboard

vital plover
marsh geode
#

tried that already nothing changed

vital plover
marsh geode
#

no problem thanks though 🙂

cerulean vine
#

contacting the support email might help too

#

!email

raw karmaBOT
marsh geode
#

ye i will try that thanks

cerulean vine
#

good luck

harsh vessel
ebon belfry
topaz venture
spiral flame
vague fossil
#

@covert kernel yo can you dm

harsh vessel
patent garnetBOT
#

Gave +1 Rep to @zinc lichen

deft terrace
#

Can somebody help me with Road?>

spiral flame
covert kernel
spiral flame
covert kernel
dark herald
#

There is a problem with the pre security certificate

#

The certificate doesnt have a picure of the course i finished or any information of what course i bypassed

native fjord
#

i subscribed to premium with Paypal.
I got transaction email from Paypal and Premium activate email from THM.
But my account still has not Premium features.
Pls help me

orchid remnant
#

Some rooms do not give points

#

15 + 0 == 15 🤷‍♂️

#

Potentially

#

What room is it @sharp gyro?

#

Correct -- it's only viewable through the management page

#

The site isn't really about the points

spiral flame
#

I asked Skidy if the +50 etc applied when it was set to zero pts/q and it doesn't

orchid remnant
spiral flame
orchid remnant
#

That's still a thing?

spiral flame
strong dust
#

i've seen today people sharing their badges with broken icons

civic mango
#

Hi the code AoC**** for 20% discount is shown as "Invalid Coupon Code". I want to subscribe for annual subscription. What is the email for support?

orchid remnant
#

!email

raw karmaBOT
covert kernel
#

Hi, I've been trying (several times) to change my country from Afghanistan to France (since I'm french 😅 ) but the change doesn't work

storm meadow
#

Hey THM-Guys,

i had recently struggle with removing friends, since scrolling down made that remove (x) function wander even more down the page without being able to reach it with my mouse cause it was leaving the intended container for it.

I also found a little workaround to it. still, you may want to have a look at it, i noticed this happens to everyone i talked to about that "wonky" remove friends feature on the site.

what i tried in the first place:

  • resizing the browser window
  • using different browsers
    • ff, edge, chrome
      -having no addons running at all

what actually got me to the remove friend function:

  • aiming to othe "friends-block" function in devtools
    • unchecking "max-height" setting.
    • unchecking "overflow-y" setting.
paper girder
#

Hey guys @small forge @twin oyster , I think there's an issue in the answering of the 4th last question of the Room Carnage

storm meadow
paper girder
#

👍@storm meadow

covert kernel
#

Hello, recently I've noticed that the country affiliated with my profile has 1) changed for no reason and 2) can't be change back (bug?).
For days, I've tried so far to change it to something else, but it always reset to "Afghanistan" (after a refresh or checking on my public profile).

Is this issue known ?
How can it be fix ?

elder sky
elder sky
#

I dont know if you can see the content, so I paste it here.

Hey there!
With our new API changes, our "update-timezone" URL has been moved.

To update the timezone/ country flag on your account to your current location, disable any incognito browser sessions/ VPN connections and click this link:

https://tryhackme.com/api/user/update-timezone

You do not see anything happen, but it should take you straight to your dashboard -- this means it has worked.

marsh geode
#

anyone knows if the broken badge icons are gonna be fixed?

exotic kernel
#

mini bug with leader board not updating when changing countries

topaz venture
celest edge
hollow cosmos
#

hi

covert kernel
patent garnetBOT
#

Gave +1 Rep to @celest edge

stray torrent
orchid remnant
#

Keep reading the questions

#

Also, @cinder crow, put a goddamn warning in the question

paper iris
#

Hi guys, on my profile its showing that I'm from Afganistan, while I'm sitting in Scotland 😄 I tried to put my number with +44 but it doesn't help. Now I sent !rank command to tryhackmeBOT and he said that I'm not subscribed, but I'm 😄 Do you know how to change country origin ?

paper iris
patent garnetBOT
#

Gave +1 Rep to @orchid remnant

cinder crow
#

it lets you register

#

and there is a hint

worn thistle
#

no terminate button in ustoun room 😭 just cannot restart machine

rough void
#

Someone to speak privately about a problem?

round silo
#

hi everyone

tranquil briar
#

cookies are the biggest scam

#

they trolled me

orchid remnant
tranquil briar
#

nah

orchid remnant
#

(In other words, can we get a little more information on that?)

tranquil briar
#

I'm good

#

oh

tranquil briar
#

I couldn't figure that out

orchid remnant
#

That doesn't sound like a troll to me

tranquil briar
#

Why not? So you're saying it was done on purpose?

orchid remnant
#

No. A badly developed application perhaps (cc @cinder crow), but not a troll

#

Unfortunately for you, you'll see many of those IRL

#

Initiative will take you a long way

tranquil briar
#

bruh

cinder crow
tranquil briar
#

It was my stupidity for not being able to figure out such a simple thing. Sorry for bothering

tranquil briar
#

I am now watchin John Hammond's video, he had the same problem as me lol

lost glacier
#

Why cost the premium after login 1,5€ more? Without 6€. With Login 7,5€, newsletter (aoc2021) 4,8€

obsidian timber
#

Hi, is there a problem with email ? Didn't receive any email like password reset / subscription confirm

manic peak
obsidian timber
#

Yes

#

ofc

manic peak
#

maybe it will take some time, maybe wait a few minutes and see if it shows up.

obsidian timber
#

more than 1 day ?

manic peak
#

for me it comes instantly, maybe if you have multiple emails you could try to search through their inboxes and see which ones have gotten emails from TryHackMe and try that one (that's what I did when I forgot what email I used for TryHackMe).

spiral flame
leaden bridge
#

hi am facing a problem in THM website

#

the problem is when i update my profile !! when i set the country and submit everything and it tell me "Thank you. Your details have been recorded"

#

after that when i reload the page it reset the country to afghanistan flag

leaden bridge
#

thank you i fixed it

pine swallow
#

No problem

devout sundial
wheat heron
#

the link href is https://docs.tryhackme.com/docs/room-creation/the-review-process%22 the extra double quote is breaking the link

orchid remnant
wheat heron
#

Idk, ask UsN, it's him who reported it, but I guess from google results

dull heath
#

if i start a machine, then after 55 minutes or so i go ahead and add more time. after 5 minutes has passed (the original time limit ends) i get a message about the box time has run out and the box shutdown (even though i just added 1 hour and the box is still live)

#

and the information about the box disappears because the time ran out

spiral flame
dull heath
#

also for rooms with more than 1 machine to run. if i complete a machine and terminate it within 60 minutes then start another machine. after 50 minutes i will get a message about time running out then the message about time being out and machine stopped. Even though I already terminated the machine and started a new one

devout sundial
gentle raven
#

Hint for Question 1-Day 7 of AoC shows the flag for the question

celest edge
#

that was supposed to go in the answer field I think

gentle raven
sly lily
#

Day 7 AoC attached VM unusable and unstable as of 9:00 AM EST today.

wraith moss
#

Day 3 AoC Attackbox/Room is unstable and crashing as of right now 😦

forest kayak
#

First question of Day 3 AoC indicates http://MACHINE_IP instead of the ip.

spiral flame
forest kayak
#

okey, thanks, sorry for that

marsh crescent
#

There is a bug with changing country in number phone (Profile > About you) - when selecting a country and giving phone number (or leaving empty phone number with just selected country) it gives back to the first option (Afghanistan) after refreshing page (but number phone is saved).

patent garnetBOT
#

Gave +1 Rep to @waxen quarry

covert kernel
#

Anytime

lunar galleon
#

is this a bug?

#

idk

lament geyser
lunar galleon
#

huh

#

3020

#

i didn't really pay attention to the bar

#

but 3020 doesn't look correct

#

i leveled up yesterday

tough hinge
#

this link not working

spiral flame
tough hinge
#

ohhh

runic crag
#

hi

#

is there any problem in
https://tryhackme.com/room/adventofcyber3#
Task 14 [Day 9] Networking Where Is All This Data Going
What is the username and password used in the login page in the HTTP #2 - POST section?

#

i got username and password with dot between them like
McSkidy.Christmas2021!
and still wrong !!?

long osprey
#

Not really a bug just a typo but as you can see it says “beginner friendly security exercises VERY day”

spiral flame
spiral flame
serene quiver
serene quiver
#

hey, this might be asking just to ask, but there's a lot of grammatical errors in https://tryhackme.com/room/packetsframes, would you like me to send an email with everything?

pseudo zenith
#

it's really annoying

static cargo
#

Just had a machine stay up after refreshing the page after it should have expired. (Time remaining said something like "0-3m 0-15s" and didn't count down, and it was still reachable from the Try Hack Me AttackBox, which was also still up after it should have expired.)

#

Refreshing again fixed it, though.

keen lance
#

anyone have problems with the room Relevant? soon as i run gobuster even with a timeout etc. it goes for awhile 30 minutes or so? Then i get exceeded error. and i cant run gobuster after that. I also cant terminate the room and restart it? what gives?

coarse stratus
#

When you launch the attackbox you can reset the timer by clicking on THM AttackBox button next to the Machine Information one. I think that the machine would still expire when it should but i don't think the timer should be reset when refreshing the site or the attackbox.

dusky trout
celest edge
#

I feel that this button is poorly named...

sacred folio
#

Hi, I don't know if it is a bug or me who does not understand. The Leaderboards say I am no.42 and when I go at 42, I'm not there ...

slate nexus
#

hello , i can't enter acting with my machine

runic crag
#

in Kali Linux Box there is lag and very slow
my account is premium for 1 year

mild hemlock
#

Minor issue, static profile badge isn't generating the icons properly regardless of how many times its regenerated

torpid cradle
vast lodge
#

seems the time for the browser vm 's is broken as it keep resetting to 2hours left every time i switch vm's or just click on the vm name again as shown here:

https://imgur.com/a/gGyXYzz

covert kernel
#
tryhackme@linux3:~$ wget http://10.10.49.77:8000/.flag.txt
--2021-12-15 15:48:21--  http://10.10.49.77:8000/.flag.txt
Connecting to 10.10.49.77:8000... failed: Connection refused.
spiral flame
dull heath
#

dunno if this is intended behaviour but I have noticed this 3 times now. On occassion I willy copy / paste a flag to short. Like if the flag is THM{THIS_IS_A_FLAG} I will copy only like THM{THIS_IS_A_FL

#

the challenge accepts it cut off like that

covert vine
#

static badges are broken please fix it

timid ice
#

spelling error ig

#

is multitasking like this by design?

lament geyser
covert vine
#

Can you pls fix the static badge. It's broken for more than 2/3 week

fluid horizon
#

I cant terminate the machine and the hints won't alert any pop-up after few minutes

covert kernel
#

Hi, whenever I try to accept a friend request, I get an error 404... Any idea why ? Might be a bug ?

prisma blaze
#

I can't connect to openvpn it always said file corrupt

#

On my vm of course

spiral flame
forest dagger
#

Hello, I just completed the aoc room a couple minutes ago and still had my streak, then started another room and it went to 1

outer granite
#

I found a flag submission bug where it takes the answer as correct even when a character is missing. So far it has happened to me twice in AOC rooms

orchid remnant
outer granite
#

oh, didn't know that existed

orchid remnant
#

There's a slim margin of error that's accepted in case you make a typo copying a long command or flag

outer granite
#

Thanks for telling me :D

covert junco
#

Why does it say 5 learning paths ? Shouldn't it be 7

#

web, complete b, junior, comptia, offensive, defense, pre security

covert junco
sick fiber
#

Maybe it should be "Last 7 days" and not "this week" ?

upbeat pendant
#

My location is erroneously set to Afghanistan and I can’t change it 🤔

covert kernel
covert kernel
patent garnetBOT
#

Gave +1 Rep to @lament lodge

lapis heron
#

Is this normal?

lament geyser
patent garnetBOT
#

Gave +1 Rep to @lapis heron

patent garnetBOT
#

Gave +1 Rep to @lament geyser

gentle raven
lapis heron
gentle raven
#

nope

#

I know for sure that it isn't normal

lapis heron
#

Fr tho

covert kernel
zenith pendant
#

hmm

covert vine
#

please anyone can fix that static badge.... Pleaseeeeeeeee...... ITs stucked

oak ether
#

guys can someone help
on my about page the country keeps giving me Afghanistan and each time trying to change it to my country it doesn't change

oak ether
rare tree
#

close browser from process , try again , clear cookies , try again ..
i hope thats work for u

#

what os are you using ? are u inside the thm browser based instant ?

oak ether
#

i tried from windows and linux

#

chrome , opera and firefox

rare tree
#

check your network connection then , i think it is a network issue i guess

covert kernel
oak ether
patent garnetBOT
#

Gave +1 Rep to @waxen quarry

covert kernel
#

Np

frank linden
#

Not a site bug but related to discord, this @patent garnet cooldown is killing me, can't the time be reduced somewhat?

frank linden
#

Yes

covert junco
#

+1

covert kernel
#

Why would you like to reduce it though, I'm interested

frank linden
#

Thanks @spiral flame

patent garnetBOT
#

Gave +1 Rep to @spiral flame

frank linden
#

Thanks @covert kernel

covert kernel
#

I could say I understand but since reps are mostly meaningless I don't really see the point :p

spiral flame
#

The cooldown is in place for a reason.

covert kernel
#

& yeah it's to avoid rep abuse ig

frank linden
#

Yeh, I guess that makes sense

covert kernel
#

👀

frank linden
#

Let's see if it's over thanks @covert kernel

torpid hedge
#

Hii

#

I am new member

unborn stream
#

Please is this normal? my badge does not load properly even after regenerating it multiple times.

spiral flame
#

@torpid hedge Please do not spam.

covert kernel
gusty salmon
#

When are we going to get the list of winners for cyber advent 3 of thm?

#

They said it will be on the 27th december

pseudo zenith
#

small site bug

spiral flame
lyric lodge
#

Greetings support.
I must have changed my number 20 times already and it keeps on resetting and putting me in Afghanistan and without my number everytime I leave my profile page and come back

zinc lichen
orchid remnant
#

Hehe, niceeeee
Do us a favour and drop that one to support would ya?

#

Deleting it from here given it's falling into the range of security bugs but if you drop an email to support@tryhackme.com with it, they'll get back to you 🙂

native garnet
#

Any update on the Suricata room? Seems to still be in progress. 🙂 Thank you!

gray walrus
#

last time I checked 1/3 was 0.33..., not 0.32

#

also would be nice to have an indicator that the room is a subscription room before clicking on it

devout sundial
covert vine
civic current
#

-The rooms on the phishing module don't appear on the search tab. They are available only from the Learn tab.
-None of them add up to the total of completed rooms in your profile.
-No points were awarded for the tasks either.

Besides from that, it was a nice module.

spiral flame
cedar canyon
#

There is a bug with static profile badge icon: The rank, room and badges icons are not appearing

sudden scaffold
#

When I terminate a machine manually, the javascript on the page continues to operate. If it is the only machine on the page, I get expiration popups, which is only a minor annoyance. However, if the page has multiple machines, the false expiration of the previously terminated machine winds up hiding the header on the page that displays the IP address of my current machine and the terminate button. This really becomes a problem on pages that have multiple machines, such as AoC. I wound up having to refresh the AoC page after terminating a machine because my progress was stunted a bit.

lime belfry
spiral flame
lime belfry
#

Click the button, it confirms it is done, but wont allow me to open a new machine

#

It keeps telling me I still have a machine active.

spiral flame
#

That's likely a different bug then

simple vector
#

Hey, when I try to download my opvn file, I'm redirected to page 404.

sharp gyro
simple vector
#

Thx @sharp gyro for help !

patent garnetBOT
#

Gave +1 Rep to @sharp gyro

gleaming spruce
#

I get a 404 when trying to download a holo vpn file

#

I've tried regenerating

#

Seems like it's just holo

#

Wreath works fine

#

welp, I just read the messages above

#

welp, followed Jabba's instructions (logging in and out and regenerating) and it's still not working

#

I can't switch VPN servers because there's only one for Holo

stable pecan
#

pictures not loaded @ Network Services only

ionic palm
#

In Profile page, in the About tab, whenever i change the country flag and click on submit details i get a popup that the details have been recorded and then the flag changes. But when i refresh the page i get the old country instead of the new one. Its not a major issue in any way but its still an issue.

ionic palm
patent garnetBOT
#

Gave +1 Rep to @astral forge

scarlet creek
#

Not sure if this is a known issue but I see a bug in the monthly regional leaderboards; I'm listed as #6 up top but then on the list I'm #8.

I've seen a similar issue a few days ago where I was listed up top as #15 but then looking at the actual list, a different user was placed as #15 and I was actually nowhere to be found on that list.

Both issues were specific to the monthly leaderboard only.

#

screenshot for context

mild breach
#

@scarlet creek it’s because you 3 have the same amount of points

scarlet creek
pure nymph
#

So I subscribed a month ago (in a couple days is my payment date from what I remember)
The profile section on the website shows I'm not due to renew until 06/01/2022 though

pure nymph
#

Oh I'm an idiot! It's backwards xD

spiral flame
#

*Forwards

pure nymph
#

Today is 01/06/2022 xDD It throws me off all the time lol

#

Local formatting is just different

gray walrus
#

can't operate website (click links) while confetti is falling. seems like confetti is in the foreground.

covert kernel
#

I don't think that's a bug, it happens to everyone, unless it wasn't supposed to act that way

gray walrus
#

of course a bug can happen to everyone. since when is it a criteria that bugs only happen to some people?

#

either way it was annoying me

#

here is another one

orchid remnant
#

It annoying you doesn't mean that it wasn't intentional 😆

#

No idea if it was or wasn't though 🤷‍♂️

gray walrus
#

I've been solving rooms for the last 40 minutes

#

clock is in the top right corner

orchid remnant
#

Chances are that's time difference, but don't quote me on that. It's not midnight in UTC yet

#

Either way it should probably be in local time

gray walrus
#

it probably should

#

(but then you get other issues. good luck with that)

covert kernel
orchid remnant
#

Calm it 🙂
No issue

gray walrus
#

sorry I didn't mean to sound (look, read?) offensive. i probably could've worded it nicer.

timber hare
#

Hi! I have a class that is using the THM platform for some intro labs, however, we need to start using the OVPN app with the configuration files. Attempting to download the files, brings up the 404 page. Regenerating doesn't help with this. Any thoughts or a timeline on getting this corrected? Is there a different webpage for it? Thanks for any help!

spiral flame
patent garnetBOT
#

Gave +1 Rep to @spiral flame

marble comet
#

Hey, I cancelled my premium like 3 months ago because I didn’t have time to get on. I thought it would stop charging my card the month after I cancelled but it didn’t(I even logged on and I had no access to premium rooms or services, yet my card was still charged). So what I did after that was delete my account, I was still charged… What is even more strange is that it sends the invoice to an email which I have never created a THM account with.( I got two emails). I’ve emailed support but still no response. Help me please.

#

I wonder, if just by being here with the discord token of my old account makes it believe that I still have that account even if I deleted it ?

spice comet
#

hey guys

#

i am not able to purchase premium with paypal and i don't have credit card

#

i clicked on "paypal checkout"

#

then i went and clicked "agree and continue" in the paypal popup window that shows my debit card

#

after that popup closes and i am back to the main website.... there it now says

#

"pay $10 and subscribe" inside the modal and nothing happens

#

no amount was deducted from my account though. Any help?

#

i am from india

spice comet
#

@topaz venture @hazy stratus

hazy stratus
digital jungle
#

When I click Resume Learning (dashboard) -> nothing is happening (as work around I click on Learn , ...)

sharp gyro
balmy parcel
#

I am currently having problems with upload vulnerbilites rooom

#

the server seems to be very slow or some of websites are not responding

orchid remnant
balmy parcel
#

there are4

#

should I clear

orchid remnant
#

You should. That's where your problem is

#

There should only ever be one at a time

balmy parcel
#

ok thank you

orchid remnant
#

Np 🙂

mystic wigeon
#

why cant i access splunk url

upbeat sonnet
#

When completing the ComTIA pentest+ learning path you will get a discount code for the actual course....this code stopped working by the end of 2021.

lament geyser
patent garnetBOT
#

Gave +1 Rep to @upbeat sonnet

nova latch
#

Hey @raw karma, can't seem to load attackbox? I'm doing the intro to networking room where I need to the use the cmd line in Linux and can't get it to load. Just a heads up!

pine swallow
nova latch
#

not loading

#

at all

#

starts connection and then loads in perpetuity

pine swallow
#

I'm firing one up to check

nova latch
#

Naturally it works now, after a half hour of restarting and terminating etc

#

thanks for reachign out

pine swallow
#

Cool

dawn orchid
#

#rools

reef anvil
#

Tried 3 different browsers and tried my phone too but the captcha button is not showing so I can't login?

lament geyser
reef anvil
#

hmm no nothing like that, I checked DNS too and nothing there either, haven't made changes to my machine either and logged in a few days ago

lament geyser
#

Also check if you're blocking fonts.gstatic.com

reef anvil
runic crag
pine swallow
#

!rank @runic crag

#

Oof

reef anvil
lament geyser
burnt pond
#

Hello THM support, I just purchased a voucher and shared with someone. He is having issues using that. the error he is getting says 'invalid Voucher code'. We have double checked the code and its correct. Is there any issue on THM side? Should he try again after sometime?

burnt pond
orchid remnant
#

It needs to go into your profile page, under the subscribe section. There's a tab called "Redeem" with a box for it there :)

#

It doesn't go into the voucher code box of the subscription purchase page.

grand parcel
#

how can i access window VM in tryhackme?

burnt pond
patent garnetBOT
#

Gave +1 Rep to @orchid remnant

covert vine
#

static badges are cracked not rendered correctly from a long time. no way to fix.
at-least confirm it will fix or not. mods, staff (edited)

#

Just asking is there anychance it will be fixed as.. this is already 3 months pending

spiral flame
#

@peak shard This channel is for bugs on the tryhackme website.

stoic shore
drowsy lava
#

Seems lige the Subscribe Now buttons are out of service for Premium. Could you look into this?

spiral flame
drowsy lava
spiral flame
#

In chrome

drowsy lava
#

It won't open for me, i don't get it :/

drowsy lava
#

Worked on my laptop, problem solved 😛

verbal adder
#

How do I change issuing certificate to a real name instead of username for a learning path?

mild breach
#

if the certificate has already been generated, you cannot change the name on it. however, you can change your name at https://tryhackme.com/profile under the General tab in the Full Name input for future certificates

nocturne tundra
#

Hi there, i got some problem of connection when i'm trying to load some page. I'm using an openvpn connection to connect to THM, so i wonder if someone else got any problem too ?

lilac parcel
#

Can someone uses the "Subscribe" buttons on the "/why-subscribe" site? or do i need some more "out of the box thinking" to subscribe? :'D

spiral flame
brave reef
lilac parcel
#

When i press them i get an error in the console from brave

Failed to load resource: net::ERR_NAME_NOT_RESOLVED static.hotjar.com/c/hotjar-1950941.js?sv=6:1 
Failed to load resource: net::ERR_NAME_NOT_RESOLVED www.googletagmanager.com/gtag/js?id=UA-129037102-1:1 
Failed to load resource: net::ERR_NAME_NOT_RESOLVED chargebee.js:1 Uncaught ReferenceError: Chargebee is not defined
    at chargebeePremiumPlan (chargebee.js:1:56)
    at HTMLButtonElement.onclick (why-subscribe:161:109)```
#

I tryd to build the URL by myself but since i dont know my user id the maximum from the url i can build is:
https://tryhackme.com/premium-plan-charge/feedback/subscription?redirect=/payment/pending&t=premium-subscription&hpId=

also i do get the same problem on mutliple devices

brave reef
#

cc @frosty cape User cannot purchase from /why-subscribe, the above error appears^
James said they're not the first to report

spiral flame
lilac parcel
#

okay so im waiting for the Official support team for further informations & instructions right?

brave reef
#

For the moment, yes. Will need to see what’s causing the issue so you should hopefully be contacted soon/ it will be diagnosed.

#

I’ll let you know if I receive any updates

lilac parcel
#

I already wrote a mail to them, thank u guys for response :D

spiral flame
lilac parcel
#

😂 😂

lilac parcel
#

@brave reef im able to use the subscription buttons again^^

brave reef
#

Ah, cool. I was just about to respond to your email hah

lilac parcel
#

Ty for the fast responding! :3 have a nice evening :D

hollow ether
#

Hello, i have a wierd problem with my profile, I cannot change my country. If I change my phone number to my country it will change back to Afghanistan. i tried with country code and without, same problem.

desert reef
#

Hi, at the page https://tryhackme.com/room/bufferoverflowprep this command: /usr/share/metasploit-framework/tools/exploit/pattern_create.rb -l 600 doesn't work. The error is: bash: /usr/share/metasploit-framework/tools/exploit/pattern_create.rb: No such file or directory

#

maybe can i use /opt/metasploit-framework-5101/tools/exploit/pattern_create.rb?

brave reef
patent garnetBOT
#

Gave +1 Rep to @brave reef

pseudo relic
#

I'm not able to connect to vpn

#

After following steps it's still not showing connected tho on terminal it is

spiral flame
pseudo relic
#

Alright

frank linden
#

!dark

raw karmaBOT
#
DarkStar7471
Sir, this is a Denny's. Imma have to ask you stop.
burnt tiger
#

Hi

covert kernel
#

I can get on it.

brave reef
#

Can you verify and send that in the Discord, instead of as a link, please? 🙂

#

!docs verify

raw karmaBOT
formal finch
#

!rank

craggy jasper
#

Hello Hackers

strange gazelle
#

i cant sign in my account

#

i am logged in it on my pc but i cant log in my account at my handy

#

it says that my email or password are wrong but i changed it on my pc and it isnt wrong

orchid hatch
#

Hello friends, I want to work in the field of hacking and security. 1. Where do I start and what should I read? ۲. How long does it take to study? 3. How can I register on the Hakerone site?

final mountain
brazen sandal
#

morning, i found something a little buggy, not sure if it was already mentioned. when i click on develop > upload, the page says i'm already uploading and i should reset, but i never tried to upload anything. this only happens until i click the reset-button. if i log out and in, it shows again that i am currently uploading.
and there are two typos/missing spaces. one is in the message saying "... upload tocomplete. ..." and the other is in the button "ResetUpload". (and maybe some margin between the message and the button, but that's just some ui-thingy😅 )

#

and after reading the message, i think the last sentence seems to miss a "to" in "..., click reset your upload."

shadow hamlet
#

So I posted this in tech support as well and it could just be user error ig but Ive had this reoccurring problem within the tryhackme rooms. Firstly for some reason terminating machines within the rooms hasn't been working for example once I'm done completing a task I hit terminate machine at the top and the little green message comes up saying that the machine has been terminated but if I try to start up the next one it says that I still have one running and refreshing the page shows that the machine that was supposed to be terminated is still running. This makes rooms like OWASP top 10 or really any room that has multiple different machines very frustrating because I have to wait 2 hours between every task. Secondly whenever I have the attackbox or kali machine running whether its in split view or the separate full screen tab the hint button just stops working.

shadow hamlet
patent garnetBOT
#

Gave +1 Rep to @late wharf

delicate warren
#

I was wondering why the attackbox got to 2 hours every time I closed split screen and opened up again, then tried it 2 times in a row and ended up having NaNh NaNm and NaNs to the room

#

when refreshing the site the time comes back to normal, so nothing breaks

neat thorn
#

Hi I have 20950 points but I have not levelled up to 0xD

plain ridge
#

I've been doing the #CyberCrafted room but the machine site is not working for me it gave me "cybercrafted.thm’s DNS address could not be found. Diagnosing the problem." this error

drowsy crystal
sharp gyro
drowsy crystal
#

yes

lament geyser
brazen schooner
#

Hello everyone! How can I get back my monkey?

#

I was automatically charged 10 dollars for a subscription, but I did not buy it

#

@rugged ermine @frosty cape

sharp gyro
young quiver
topaz venture
#

Sent them onto the right direction ((: thanks all

swift topaz
#

I submitted a vulnerability 4 months ago and I have no reply till now

#

any update ??

swift topaz
#

@topaz venture ??

brave reef
swift topaz
#

but ask them to take them seriously..

finite sun
frank linden
lament geyser
brave reef
fluid echo
#

Throwback network - task 15, task 16 - missing pictures: "403. That’s an error.

Your client does not have permission to get URL /ap6zQ14qDzWF1HPb0CFYYSPJnQ49m7bMJnE5y_UPwO8fs0H4F5OREcr6Ps8d7DNJbEobEFEA6M8oPzIxKbRS0CfhChqG8s_UaQXioyPfgz283aH0A1uGZ0F1O4_3gxFkMXFGwJlD from this server. (Client IP address: x.x.x.x)

ACL Denied That’s all we know."

runic copper
#

Not sure if this is the right place for this but I have completed all of the Phishing module but have no badge

lament geyser
patent garnetBOT
#

Gave +1 Rep to @lament geyser

green frigate
#

where can i report a koth bug? Thanks.

young quiver
#

not really bug but fits here best, tryhackme monthly leaderboards top 12-17 have the same amount of points, are from the same country, and have the same amount of rooms overall complete (+-)

covert kernel
#

I started the Dear QA machine and the attack box, but target's ip didn't appear.. I lost a couple of minutes but nevermind. Then i hit refresh, and it was there 🙂 Maybe a bug..

elder trellis
#

Hello Team , a friend sent friend request but when I click on the "Accept friend request" ... i've obtanied the follow message error "Uh-oh, this page has been lost in the matrix." , can you help me? thank you.

young quiver
spiral flame
manic peak
#

So I was doing a room (linux privesc) and I extended the expire time, and when it was 1 hour and 10 minutes left or something (if i had not added the extra time it would have been just 10 minutes) it gave me a warning saying it will expire soon, then when it reached 1 hour (when the initial 2 hours had passed) it said that the timer had run out, and the machine information box was gone, then i refreshed the page and it was back.
I think the timer is a bit broken.

cerulean vine
#

it is indeed

#

it often states that time is running low or that the machine has expired if shadow don't refresh the page after terminating the machine

ruby lintel
#

Hey, I'm doing the throwback network, and a bunch of the images wont render.

#

Is there something I can do?

#

When I try to view the link for the image, I get this:

fluid echo
#

I have the same issue

deep wadi
#

Hi! Some time after finishing Pre-security path, my Packets & Frames room bugged. All the tasks doubled, but only one of each pair has questions in it. Path shows 95% completion now. I got my certificate 3 weeks ago, but I just saw the bug today. I'm not bothered much, just reporting this.

lament geyser
patent garnetBOT
#

Gave +1 Rep to @deep wadi

upper gate
#

Hello, I can't change the nationality flag on my profile! When you select the flag you want and click to change, the page is reloaded and nothing happens...

drowsy crystal
#

I think i got the web hacking badge unfairly?

short jackal
# drowsy crystal

It's very possible that you got it when the requirements were different and you met them. They aren't revoked when requirements are updated

spiral flame
covert kernel
#

Think it was the command injection room.

dark inlet
#

Has anyone had an issue with completing all the tasks in a room (100%) shows up, but it doesn't clear the module in the Learning Path?

#

Nvm, saw that this was brought up in #room-bugs - looks like others saw it too

frank linden
#

Not sure if this is a site bug or intended but you can join/view private rooms by simply replacing /room/<name> with /jr/<name

brave reef
#

@frank linden I deleted that, please don’t expose private room codes

frank linden
#

Apologies, forgot

frank linden
deep wadi
patent garnetBOT
#

Gave +1 Rep to @lament geyser

hoary tundra
#

hi "£" does this means "sterling" ?
After you subscribed the website it shows as it will renew as "£" instead of "$". I didn't get it

#

Also, when i complete something the pop-up message shown in the website. I can't click anything when the message is there. It lasts like 4-5 seconds and i am unable to click terminate the machine etc.

#

After it's gone, i can click whatever i want. It's kinda annoying and i wanted to write about it.

gentle raven
#

Is the point system broken?

silent shoal
#

hello I have a question related to my certificates. My name does not appear correctly. I think the issue is with the ' character in my last name. It causes the @#x27; Does anybody know how to fix this on the vertificates already awarded? Thanks

spiral flame
#

This may change in the future.