#room-ideas

1 messages ยท Page 8 of 1

orchid elm
#

@native raptor Does the RAM allocated to the virtual box machine submitted as ova affect the speed of same machine when deployed on tryhackme

somber crow
#

No

orchid elm
#

I wonder why my room is slow

native raptor
#

Unless the admins have set it to be higher

orchid elm
#

Just one more quick question, how many days does it take for a submitted room to go public?

native raptor
sullen jay
#

hey, guys!
A few rooms about hacking aws, azure and google cloud would be a good one!
The same to defense side

icy trellis
#

Would you be able to explain what you mean?

#

Seems very targeted hahah

severe scroll
#

Had an idea of a room, but not sure I could make it myself atm as I'm not able to set up VMs as don't have my own PC. Might be a good idea though, who should I send it to?

severe scroll
#

The idea I had was a misconfigured cloud storage site, and I could work on it at some point in the future?

karmic ember
#

I'd second anything related to cloud security. The AWS security specialty was pretty underwhelming

sullen jay
native raptor
#

Only problem with that is convincing AWS to play ball

sullen jay
karmic ember
#

I could see it being an entire path, tbh. Not just a room

native raptor
#

(If AWS allowed it)

karmic ember
#

right

#

cloud misconfiguration is huge

#

learning how to do that right would be a big gain

native raptor
#

They have their own cyber workshops. I suspect they would be less than happy about us taking an account and letting people go nuts with it

#

Especially given once they've compromised it, they're free to run up big bills

#

We would need Amazon actively backing it with at least one (or preferably lots) of practice accounts

karmic ember
#

perhaps look into how A Cloud Guru does it- they have aws account sandboxes

sullen jay
#

yeah, they have a cool sandboxes. But, when it comes to teaching ways to compromise aws services, i don't think that would be a problem. Checkpoint has launched a series of tutorials with this theme

sudden garnet
#

something that can be used for an aws room ^^

karmic ember
#

I've got a few AWS certs and would be willing to assist with creating some AWS content. I'm not at a point where I could do it solo, though.

sullen jay
ripe cape
last mirage
#

I have a room idea to develop, whom shd i approach to discuss?

severe scroll
#

Yes, same here. I have what I think is s good room idea, I need to know where to discuss it.

native raptor
severe scroll
#

Thanks @native raptor ๐Ÿ˜€

marble currentBOT
#

Gave +1 Rep to @native raptor

native raptor
#

@merry coyote as a general rule, randomly pinging the big guys isn't going to do much other than annoy them ๐Ÿ˜†
Anirudh has already been added into #creators-lounge where they have already asked about their room idea and been responded to by THM room testers (who are generally best equipped to discuss what kind of thing is likely to get through the submission process) :)

dense acorn
#

I HAVE BEEN SUMMONED

#

You're welcome to chat with me about room ideas, but some of the other head-honchos might be a much better person to bounce ideas around with.

pastel tulip
#

WhiteKnife was here

graceful kayak
#

Hi. I want to make a suggestion for future rooms/networks. Some networks use a ring topology with a token to verify which endpoint has the data to transmit it, and it would be cool to have that within a segment of a network, even if so just to learn how to work with not so common topologies. Not sure if this sounds silly, but it's just an idea.

native raptor
vestal bear
#

hello, em, id like to make a room, that inside of it, has secretly a code for another room, that can only be accessed with it. is it a good idea? or is it fine if i try making it??

#

or possible even

somber crow
#

Possible yes

vestal bear
#

okay

#

@somber crow should i set autologin = true for my vm?

somber crow
#

Won't matter

vestal bear
#

thx

somber crow
#

@burnt plume Hiya, if you're the creator of the tshark room please reach out to me

vestal bear
#

@native raptor i dont think ill be able to make a rpi room

#

for thm

#

cuz with 1G of ram, ist been like 15 mins just for the ubuntu to boot.

somber crow
#

Did you use Ubuntu desktop?

vestal bear
#

w minimal installation

#

yup

somber crow
#

Don't.

vestal bear
#

cuz qemu needs graphics

somber crow
#

I don't think it does.

vestal bear
#

o really?

#

holly molly

#

what a fool i am

#

XDD
kekw

#

thank you @somber crow

marble currentBOT
#

Gave +1 Rep to @somber crow

somber crow
#

Good luck!

vestal bear
#

yey

vestal bear
vestal bear
#

this tut is saving me

somber crow
#

As a warning, I don't think KVM will work?

vestal bear
#

Idk

#

Im gonna follow the tut

#

If it works

#

Im fine with it

#

Else

#

Investigate more

#

Just trial and error

#

ยฏ_(ใƒ„)_/ยฏ

somber crow
#

because nested virtualisation won't work?

vestal bear
#

idk, i dont know nothing about AWS

#

:)))

#

ok, my ubuntu is installed and up-to-date

#

is moment to run this

#

well, make qemu installation and setup

#

and then install rapberry os (no desktop env)

#

and anyways, if it work on my laptop, i thing it will work on AWS, cuz im running an ubuntu vm, and inside of it the rpi os

#

and once i saw the tech specs of a vm, and the processor used for it, was a 2Ghz base freq

#

soo, technically, it should run a little more faster on AWS

#

i think so

#

@somber crow

somber crow
#

Yeah, but make sure you're not using nested virtualisation

vestal bear
#

actually, idk much about nested virtualisation. if i see something like that, ill try using another method

#

ok, downloading lite rpios

vestal bear
#

@somber crow i got bad and good news, bad one it didnt worked with the last page i sent u. good one is that i found one that actually is making the same as i

somber crow
#

Yea, the KVM part won't work

vestal bear
#

actually it failed with the networks

#

i think that the vm and the network setup with virsh made conflict

#

but anyways

#

the bad thing, is that ill need to use an older raspberry pi os flavour

somber crow
vestal bear
#

yup

#

i hope this 2cond way will work

#

LOL

#

the password for the ubu user almost got filtered

#

XD

vestal bear
#

yo @somber crow you wont believe me, i think that the raspbian os link was a fake and had virus too, cuz when i was extracting, it took many minutes, and then ended saying that there was no space left on disk, even it said the file to be 1,5 Gb weight

#

ill try using the latest raspberry pi os lite

#

idk

ripe cape
#

i dont think aws supports nested vms, period.

native raptor
#

It does -- it's just crazy expensive

ripe cape
#

proxmox on aws go brr

ripe cape
#

holey beep

#

xD

near wave
#

hy

#

can anyone givea hint about Year of the Jellyfish where is id i dont get it

dry mesa
visual bronze
#

warum geht der server nicht ?

#

Website*

ripe cape
#

english plz ๐Ÿ‘€

icy trellis
visual bronze
#

ok, thx

hot bolt
#

Hi, would anyone be intrested in a box about prototype pollution

#

i was planning on making one but i wanna see if people would be intrested

ripe cape
#

prototype pollution?

hot bolt
#

exactlyy

#

not many people know about it

karmic ember
#

I would absolutely be interested in this

#

is it JS only?

#

Could it also be done with python? If so, I'd absolutely love to see that done

native raptor
hot bolt
#

soo it would be easier for me to implement kekw

hot bolt
karmic ember
#

I am a JS idiot, so I can't be helpful there. but could maybe help with the python side of. I'm nowhere near a python expert though

hot bolt
#

i mean would always be nicee to see the python aspect of it as well

#

but from what i know its mainly JS

#

but this would also make me research so preety hype

karmic ember
#

dooo ittttt

#

are you thinking walkthrough or challenge? or both?

hot bolt
#

maybe a bit of both would be nicee you knoww

#

frist a little theory and then a full challenge evil

karmic ember
#

me likey ๐Ÿ™‚

sudden garnet
unique maple
#

I am stuck in safezone room. I did login as admin and tried to inject a php for RCE but nothing after cmd command runs and can not get a reverse shell. Any help would be appreciated.

somber crow
subtle grove
#

hi

empty urchin
#

I am currently working on my first room, Layer 2 Security Attacks, however I can't seem to find a way to include pictures from my own device but rather it's asking for a URL of the image; is there a way to include them from my own device or not? If not, can anyone name me a server that will keep pictures and not delete them, rather for free?

somber crow
#

imgur, GitHub

empty urchin
#

@somber crow thanks ๐Ÿ‘

marble currentBOT
#

Gave +1 Rep to @somber crow

frozen tangle
#

I would really like more rooms oriented for different certifications like eJPT, CEH and more.

fading oak
#

there are many rooms that cover that, or are you looking at a path like the Pentest+ one

sleek elbow
#

the big issue with that is that a lot of these things are trademarked, CompTIA specifically partnered with THM to make that iirc

#

like, iirc the Offensive Pentesting path use to be the OSCP path

frozen tangle
#

Oh okay, I was thinking of rooms that are kinda specialized to teach you the skills and help you prepare for certain certifications.

sleek elbow
#

also a thing with CEH is they teach a lot of proprietary windows software that literally no one in the world has ever used for some reason

karmic ember
#

like what?

sleek elbow
#

Internet Worm Maker Thing was by far the most entertaining

ripe cape
#

that one is nice

primal marsh
#

hey

orchid elm
#

Hi, I uploaded 3 rooms, i got update on 1 but other 2 are still showing "submitted". It's been 15 days

ripe cape
#

@orchid elm if you want them to be reviewed, switch the slider to "Public"

#

:)

orchid elm
#

Already did they are in "sumbitted" stage from past 15 days

ripe cape
#

ah then you gotta wait until a tester picks it up

native raptor
#

@orchid elm I'm only seeing two in the queue (one from 8 days ago, the other from 12). I'll see if we can get someone on them ๐Ÿ™‚

cedar echo
#

the testers are (almost) all volunteers

orchid elm
grave zinc
#

I don`t if this room for that...but do you can upload the video in the room metasploit again but with subtitles English?

glad depot
#

I got inspired by muiri's year of the jellyfish where there was a non intended way of getting foothold by reinstalling the application and wiping the data to create a new user (the intended way was an unauthenticated rce).
Would it be a worthwhile idea for a room to make multiple ways of getting a shell but if you brick the box or do permanent damage, then something happens like the flags get removed or the machine locks itself down? That's because during a pentest you want to avoid those kind of things as much as possible and i can't find a room with that concept in the list

sand rapids
#

Anyone having idea of creating a room in thm in the topic of "how to create ransomware or botnet"

coral ravine
sand rapids
coral ravine
#

How would it be used ethically though and what will people learn from it?

somber crow
#

I don't really seem a way of doing that ethically.
You could approach botnets and Ransomware from a blue team perspective sure, but I don't think you could teach it on any way that resembles ethical.

native raptor
oak finch
shut aurora
#

Hey are there any rooms totally focused on APIs and all , like from basics usage to exploitation and all?

somber crow
#

No, but I have one half written up

shut aurora
#

Planning to make it public anytime soon?

karmic raven
shut aurora
#

Or are there any other resources where I can learn about API vulnerabilities and exploitation?

paper shale
#

@shut aurora I think DVWS can help you

glad depot
paper shale
#

Damm Vulnerable Web Service

shut aurora
marble currentBOT
#

Gave +1 Rep to @paper shale

glad depot
karmic raven
#

just seems arbitrary to me but akkoShrug

somber crow
glad depot
#

I don't want to find a winner, i want to make people learn

#

And i think that after a box like this the concept of not destroying your client's application will at least be somewhere in their mind

karmic raven
#

from experience people wont really learn theyll just think its a bug get annoyed, spam the help channels, reset the room, do it again then learn nothing

#

I could be wrong

#

but that has been my experience with similar ideas

glad depot
velvet vigil
#

I think THM should implement of no boot machines system, as it'll be rude of me to say that this idea clicked my mind after what I saw on HTB that usually we don't have to start the machine and wait for to boot up but just click on start instance or something like that and you're provided with IP addr, but i think this will save much time because non-subscribers only have 1 hour after machine is deployed and some machine did take upto 5min or so ๐Ÿ™‚

ripe cape
#

@velvet vigil i believe that in htb, they're shared instances that are running 24/7

somber crow
#

That'd require sharing instances

ripe cape
#

you just join it

#

oh lul

somber crow
#

Unless you get VIP+ on HTB, you share instances.
With VIP+, you need to spin up the machine yourself

ripe cape
#

^^

#

on thm, each person gets its own machine

#

thats why theres boot time

velvet vigil
#

sorry, fool of me, i'm not a VIP+ member of HTB

native raptor
#

Yeah, the big advantage of THM is the instances aren't shared ๐Ÿ˜„

tacit anvil
#

teach me how to hack

#

lamo there is like 200-300 ppl here and i gst ignored

#

by 200 ppl lol

sleek elbow
cedar echo
velvet vigil
#

yes but i can't do that, I'm a non-sub noob :))

frozen tangle
atomic copper
#

There is no SQLi room in any of the paths!? concernedhex

sour zodiac
#

ok got a room idea that i think hasnt been done before,smb and ftp port open, smb access isn't allowed but can be gained: enum4linux scan will bring back 2 users, one of them will be bruteforceable, bruteforce smb and you are greetedby a txt file, saying that tom's credentials are extremely weak, this leads to yet another bruteforce, which gives us ftp access to tom, we are then given the credentials to the web app which is running on port 80, we log in, but now we are stuck as there is no visible way to gain foothold, but in the webapp source, we are left with a note that says that the admin is checking in every 2 minutes, xss????? yes! xss! we use session hijacking to gain access to admin account on the webapp which leads us to an upload page, we'll need to bypass a few upload filters untill we can upload a webshell, now we have foothold, getting root will take a bit of time for everyone since it is a kernel exploit, you are free to use whatever kernel exploit available

native raptor
sour zodiac
#

ah

native raptor
#

Keep at it though! See if you can find another way to disclose creds

gritty blade
gloomy trail
#

any moderator online

native raptor
#

?

gloomy trail
#

cani dm you for my throwback badge

native raptor
#

Aye, go for it

gloomy trail
#

done

karmic ember
#

Here's a weird idea: what about a room where the instructions/questions are encoded in some way, and part of the challenge is figuring out what is being asked

karmic raven
karmic ember
#

Not impossible. You'd have to provide some hints or something along the way

#

more of a scavenger hunt

somber crow
karmic ember
#

oh. Sorry, I misunderstood

#

but yeah, if it's been done, then ๐Ÿคทโ€โ™‚๏ธ

graceful crane
#

Hi y'all! I am thinking about developing an "Intro to Pwntools" box. I've been trying to learn Binary Exploit, and a lot of CTF players have told me that pwntools is a big deal. I was wondering if anybody had any input as to what they would like to see from it. I'm thinking checksec, cyclic, the binary packing functions, and networking functions. They have a shellcode generator, but I think msfvenom is better, although maybe that's worth mentioning too. Anyway, any feedback is appreciated. Thanks!

sleek elbow
#

@final sun might be able to provide some input ^

final sun
#

Got you, Spooks!

final sun
graceful crane
marble currentBOT
#

Gave +1 Rep to @final sun

tacit anvil
#

I think I have an idea of room idea, any recommendations for where I can share and improve ideas?

clear scaffold
#

ur idea doesn't matter

#

defently not here

#

b

#

because its not named "room-ideas"

icy trellis
icy trellis
somber crow
clear scaffold
#

na, I meant he asks where to share ideas on the channel where he needs to share ideas

#

everything I said was sarcastcly

clear scaffold
#

but, I am used to being rude

#

because I have never been in a nice community

icy trellis
#

Thereโ€™s always time to change, just please keep your comments to yourself if theyโ€™re not nice or vaguely sarcastic :)

cedar echo
clear scaffold
cedar echo
#

see, that can be taken the wrong way very easily ๐Ÿ™‚

#

also not everyone here is a native English speaker, so the subtle cues to a sarcastic remark are oft totally lost

cedar echo
clear scaffold
#

thanks

cedar echo
clear scaffold
#

aight sorry!

tacit anvil
#

beginner ROP room?

dawn onyx
#

More Ghidra walkthrough rooms?

tacit anvil
#

A room that showcases all the owasp top 10, without any help

Like you need to apply all of owasp top 10 skills to root

native raptor
native raptor
#

Not at all ๐Ÿ˜„

crude current
#

I don't much about the resources required to host a VM in a cloud though I know there are some dangers involved in hosting VMs created by others on your network.
Further, I also don't know whether THM will look up into setting up resources that are different then the 'ROOM environment'.
Having said all of the above, I suggest that THM should have a option of practicing 'all' machines available at VulnHUB, just like on the pattern of offensive security PG-Play and Practice.

native raptor
#

I suspect offsec would have a problem with that @crude current, given they own vulnhub and proving grounds.

crude current
somber crow
#

Further, I also don't know whether THM will look up into setting up resources that are different then the 'ROOM environment'. Can I ask what you mean by this? The room format is used to collect the tasks and resources dedicated around a specific topic.

native raptor
#

Same as here -- many THM machines are community made

crude current
somber crow
#

Ok, please explain how and the value it confers over a room format that we have atm?

native raptor
#

Heck, there are a fair few cross-overs, but those are always either uploaded by the creator, or uploaded with the permission of the creator. We don't have the right to take those VMs without the owners' permission

somber crow
#

Muir that's not what creative license means I saw that

native raptor
#

Also remember that PG and THM are two different companies. No point in stealing each other's formats ๐Ÿคทโ€โ™‚๏ธ

native raptor
crude current
somber crow
#

Ok, but there's no point in change for the sake of change. Especially when that change is ripped from another platform.

native raptor
#

Well, that's fine. If you like the PG format, use PG. It's a good idea to use lots of different resources anyway

crude current
somber crow
#

What format are you describing? This is something I've asked a few times but you haven't answered.

crude current
somber crow
#

Ok, you can switch on a machine and try to root it on THM too.

crude current
#

I understand.. but there are lists available for VulnHub machines.. like priviliage esclaation, abusing sudo rights.. web things.. I hope you get an idea..

somber crow
#

Are these lists a part of the platform, or from people on other sites?

#

Because you can already search by tag on tryhackme to find rooms similar to how you're describing

crude current
# somber crow Are these lists a part of the platform, or from people on other sites?

These are just machines mostly submitted by people... I don't know they are part of any platform. Offsec PG play gives you the option of hosting some of the machines.
VulnHub machines have been categorized in various lists, which I think you all are well ware of, for example, https://github.com/Ignitetechnologies/Linux-Privilege-Escalation

GitHub

This cheatsheet is aimed at the OSCP aspirants to help them understand the various methods of Escalating Privilege on Linux based Machines and CTFs with examples. - Ignitetechnologies/Linux-Privile...

somber crow
#

I wasn't asking about the machines

#

The lists are not a part of the platform, so there's nothing stopping you writing your own lists for THM.

crude current
#

the problem is with hosting

#

like the offsec allows you to host some of them in their PG play

somber crow
#

That's because offsec owns vulnhub.

crude current
#

but machines are submitted by community

#

I dont know the licence under which users submit

#

but It THM should be allowd to host them

#

and given the fact that the machines can be downloaded by any one and is free to host at his private network... OFFsec should not have any problem with THM doing it over the internet

somber crow
#

Not really.

#

THM are making money off it

crude current
#

The money charged by offsec for their PG play is, I think, for hosting... not the machines

somber crow
#

Commercial use is usually not allowed

crude current
#

money is not being charged for setting up machines.. but the hosting

somber crow
#

There's a huge amount of content submitted to THM and a huge amount released. I don't see why you would need to steal vulnhub machines for kt.

crude current
#

I respect the content and I like it as well though I am too little to appreciate it fully but I liked the idea of offsec pg play and I thought It would be a good one if such things existed in THM along with all other room.

somber crow
#

Check out the policy here.

#

THM taking machines from vulnhub to directly compete with proving grounds is not a good faith effort. It's not very respectful of interlectual property either.

crude current
# somber crow How is this related?

IF xyz is open source whose commerical use is prohibited, though every body can use it... If I set up a virtual lab of linux machines over the internet, where I let users practice that xyz, would It be bad/unethical or not violating the agreeemnt.

#

if charge people to cover my hosting costs

somber crow
#

I'm not a lawyer and I'm not here to answer your legal questions

crude current
#

this was not a question

somber crow
#

Especially if they're wholly unrelated to the purpose of this channel.

crude current
#

it was just a food for thought

#

thanks for your time

somber crow
#

Creators are free to submit their vulnhub boxes here.

#

THM will not accept boxes submitted by people that aren't the creator. I don't think "permission from the creator" is enough anymore either but I may be wrong there.

waxen silo
#

Idea: All links provided in tasks should open in a new tab

karmic raven
waxen silo
#

Atleast in nmap room task 12 the link opened in the same window...not in a new tab

native raptor
#

That's something that's wrong with your browser if it's opening in the same tab

somber crow
#

It's also an option for room creators, we get a checkbox/dropdown to decide if it opens in a new tab etc

gritty blade
#

more rooms like CCT2019 please... that was a fun room

cunning thunder
solar whale
#

@waxen silo use the scroll wheel click / CTRL + click (i guess) / cmd + click

gritty blade
waxen silo
sour zodiac
#

to all my room creator friends, please create a python exploit scripting room that just practices exploit scripting using python

somber crow
#

There's already an intro to exploit development room?

sleek elbow
#

also worth noting

#

BoF rooms

sour zodiac
#

bof rooms are great practice for python scripting

#

but it would be great to have a room that focused on making python scripts that focused on web stuff

karmic ember
# hot bolt Hi, would anyone be intrested in a box about prototype pollution

I just saw this, which might also be relevant/helpful/interesting https://www.youtube.com/watch?v=tyL3Ouais1c

Seriously, isn't Snyk SUPER COOL? Check it out! https://snyk.co/johnhammond
Exploit Goof, the vulnerable web app! https://github.com/snyk/goof

00:07 - BlitzProp HackTheBox Cyber Apocalypse CTF challenge Intro
01:00 - What is snyk?
02:36 - Snyk can be FREE!
03:34 - Connecting Snyk to Github
04:54 - Discovering Goof, the Vulnerable Web App
07:28...

โ–ถ Play video
tulip tangle
#

netcat walkthrough eyes_blur

sudden garnet
frank kayak
#

For the defensive path, I'm missing one big thing that is abused allot lately. M365 forwarding rules and mail forms (like ruler does). And I would like a small introduction to protect.office.com

The same is applicable to an exchange server as lots of high impact exploits lately have to do with Exchange Web Access.

So I think it would help if some of those things are highlighted in the defensive path as it's a good attack vector that is widely being abused. Same with and explanation of dkim dmarc and spf. For exchange and perhaps also exim mailservers.

karmic raven
frank kayak
# karmic raven Those are very hard to emulate

Hope some of the room builders are up for a challenge... No one told me the ideas had to be easy to implement btw.

But they are very popular attack vectors lately and also very much in the news and spotlights.

I think that even an European government body got hacked because they where 2 months late with patching Exchange server last month.

native raptor
karmic raven
#

Itโ€™s just not feasible

frank kayak
#

Exchange requires allot of memory to start indeed. The exchange database is like 2 gb out of the box already.

#

For dns you can use something obscure like 127.254.254.1

#

But an explanation about spf dkim and dmarc doesn't hurt in a room with examples of phishing it would prevent as the initial attack vector is somewhat mitigated.

#

Although I do think most of the people here would rather test out the poc codes for the exchange server owa vulnerability ๐Ÿคฃ

karmic raven
frank kayak
#

I don't specialise in aws. ๐Ÿคฃ but do you want a room where you have to execute the poc code against exchange or rather some spf dkim and dmarc? I can take a look in a few minutes if it's doable for me.

sleek elbow
#

it's not feasible.

#

with the amount of resources required for a single box, it only will work for networks... and even then, it'll barely work for networks

#

the exchange server will need more than 8gb of ram and 4 cores

frank kayak
#

I'll give it a shot though, what networking is required for a VMWare Workstation image for a room upload?

#

Not used to aws or anything so I have to ask XD

sleek elbow
#

Microsoft recommends 128GB minimum

#

all networking is stripped out by aws

frank kayak
#

Cool ๐Ÿ™‚

somber crow
#

For exchange?

frank kayak
#

Exchange is MASSIVE...

somber crow
#

Something something upselling azure instances

sleek elbow
#

tl:dr not happening

frank kayak
#

Depends if you're an NGO or something you can buy Exchange for just like 100 dollars.

#

And each seat costs like 5 dollars XD

#

But believe me you don't want to know the retail price...

#

The funny thing is. I'm not worried about getting it slimmed down to an acceptable level of resources all that much if the installer isn't limiting me. I'm more afraid of failing to exploit it myself ๐Ÿคฃ

sleek elbow
#

the highest running resources machine is Osiris iirc with 1.5GB of ram lol

frank kayak
#

Here I was expecting 2 gb to be acceptable. I'll lower it down to 1 gb ๐Ÿคฃ

#

Keep forgetting that memory is among the most precious resource in the cloud ๐Ÿ˜ฉ

native raptor
#

Nah, 2Gb is fairly common

#

Osiris is on 4Gb, which is nuts

frank kayak
#

Well I said I would get it to 1 GB now, so I will try it... ๐Ÿ˜›

#

If it fails I'll make it a bit bigger. But at least I'll try

#

It's not like they'll try to login via RDP or something, at most they will just use the Hafnium attack to get a flag.

#

Must admit that I thought Exchange 2013 was a pain in the ass to install, but compared to 2016 and 2019 it was actually pretty easy DX

frank kayak
#

Small update got it running at 1.5gm memory and 2 cpu. Could drop the amount of. CPU down but would need to higher the amount of memory a little to make IIS stable ๐Ÿคฃ

sour zodiac
#

a wfuzz room would be rly good since thm only really focuses on gobuster which is quite limited

#

wfuzz is really useful for a lot of things

native raptor
#

Although I agree -- more on fuzzers would be good

modest trail
native raptor
#

Not to the best of my knowledge. I'm literally in the middle of asking Ashu if it would be a good idea to make one

icy trellis
#

Didn't Pars make one?

somber crow
#

A room about LXD. So that'd cover:

  • What is LXD, and how is it used
  • How to recognise that you're in an LXD container
  • Exploiting privileged containers, or the lxd group on the default user in Ubuntu
native raptor
#

Got the wrong room code

icy trellis
#

Ah shoot I completely missed your message, sorry ๐Ÿ˜…

whole isle
#

Hi guys, are there any rooms for CVE-2015-0235 Ghost Vulnerability

#

I'm very interested in that one

#

Or any idea where can I exploit it

tough pasture
#

can't see anything with a quick google, so if there's one on TryHackMe/other places, there's not a public writeup for it, it seems @whole isle

#

but, you could always try make a room for it ;)

sudden glade
#

There should be a security+ learning path

#

Since we made a deal with CompTIA for PenTest+ it is reasonable

#

Right?

rugged swan
#

can someone create a walkthrough room for ROP ?

tough pasture
rugged swan
#

yep @tough pasture

tough pasture
#

I don't know what the admin's views on binary exploitation are, as there's not been any done before focused on different types e.g. ret2libc or ROP like you said I don't think

rugged swan
#

Thanks @tough pasture

marble currentBOT
#

Gave +1 Rep to @tough pasture

sudden glade
#

Wouldnโ€™t a Python hacking room be good?

hushed urchin
#

he he

cedar echo
#

Hacking with python, or having a python application?

sudden glade
#

Hacking with Python

#

I think using it for web hacking or for general penetration testing

#

I also think there should be more WiFi and network hacking rooms

#

I just plow through CCNA for hours on end

#

Sorry wrong channel

cedar echo
#

but as python is a general purpose language, said scripts can be feasibly written in any language

sudden glade
#

Right but there should be rooms for the purpose to practice apply programming to hacking

#

Like writing attack scripts

#

It would be a good next step after getting basics

#

Or writing scripts to assist with regular kali tools to enhance skills

true hornet
#

Have a look into that :)

whole kayak
#

hello everyone

#

i had a wordlist of 15gb

#

tried to crack a wpa

#

with hashcat

tough pasture
#

riiight

#

Is that a statement or are you looking for help

valid pawn
ripe cape
#

:o

timid wing
#

Exchange server 0day go brrrrrrr

somber crow
orchid elm
#

Hi can I be added to creators lounge, wanted to check up on my submitted rooms...๐Ÿ˜ฌ

somber crow
#

It's a pity

timid wing
#

For real its a pretty important vuln to say the least up there with the recent sudo vuln and comparable to Eternal SMB vulns

somber crow
#

Hi I'm not really here rn

#

@icy trellis you're up

icy trellis
#

-arole 655956944929947656 creators-lounge

marble currentBOT
#

โž• Gave the role Creators-Lounge to cirius#4450

orchid elm
#

Thanks

wet trout
#

How about a room that shows you how to clean up your tracks, so you leave less IOC's? This may already be out there, but thought I would ask.

wet trout
#

LOL

icy trellis
#

@outer vapor Please do not post that command.

crude lotus
gloomy trail
#

can we get more room in the oscp path

#

like more ad rooms

somber crow
#

It's not the OSCP path

#

And OSCP doesn't cover AD, PWK covers AD but the exam doesn't yet

cunning thunder
next spindle
#

@icy trellis or @somber crow can added me to creators lounge?

native raptor
#

@next spindleDone

next spindle
#

Ty

bleak cargo
#

Could the windows privesc room be included in the complete beginner pathway along with the Linux privesc?

strange smelt
bleak cargo
#

Thanks guys and I just felt it would go along with the privilege escalation section as well

normal star
#

hi I have a small question.

#

i submitted a box, how long will it take to make it public :3 , this is my first time submitting a box so i have no experience :/ thats why i am asking.

somber crow
#

Walkthrough rooms will be released somewhat quickly at the moment.

normal star
marble currentBOT
#

Gave +1 Rep to @somber crow

native raptor
#

Just the length of the queue just now :)
They should hopefully be tested relatively quickly, although there's a bit of a backlog there too

sleek elbow
#

yeah, I submitted one of my boxes a couple weeks ago and it's been a minute since I've heard anything of it

cedar echo
#

werk werk

#

there's quite a few boxes that are ready with no release date set yet, I imagine the current backlog'll be at least a month

rose cradle
#

exciting times to be a consumer ๐Ÿ˜„

fluid sedge
#

It would be awesome to get a honeypot room

sleek elbow
#

as someone who works with enterprise grade honeypot software

#

it's cool!

#

but the whole point is to ensure you've got a good honeypot

#

and to have a good honeypot, you can't have an attacker know they're in a honeypot

tacit anvil
weary bloom
#

On the **Cyber Defense **learning path, under Threat Emulation, I think it would be appropriate to make Attacking Kerberos as first in the list then Attacktive Directory second.

I was struggling hard in trying to follow along Attacktive Directory. Often I would Google walkthroughs to figure out what actions were taken to get the answer as it wasn't giving you any tips or hints on what to run. I couldn't even get **Kerbrute **working. I was so frustrated that I rage quit that room and ventured on to the next room (Attacking Kerberos). I felt this room assumed you already had knowledge of the tools laid down for you.

Opening up Attacking Kerberos brought a breeze of fresh air. Not only did it provide you a good introduction to Kerberos, it even highlighted that you needed to edit the** /etc/hosts** file in order for your Kerbrute command to work. All of my questions that I posted in #room-help we're all in this room!!! A few examples are 1) modifying the hosts file and 2) Kerbrute installation.

Figured I'd share my experience as I don't want other people to go through the same hell as me.

somber crow
#

But also you absolutely need to supplement THM rooms with your own research

weary bloom
#

I figured since it's a Learning Path I'll have to take each room in order

#

Now I know it isn't the case. But would probably be best to just switch the order of the two rooms moving forward. Thanks for the link, I've submitted my Feedback.

somber crow
#

Who says that isn't the case?

tawdry ravine
#

is there an attack box that can be used to just generally mess around with and practice stuff learned in other rooms?

somber crow
#

Do you mean a target machine or what?

tawdry ravine
#

yea a target machine and attack box that's just for messing around on

#

with hidden stuff on

somber crow
#

There is not.

tawdry ravine
#

well that's my room idea. it has like very little information and questions are just get flag 1, get flag 2 etc. with increasing difficulty. and you just have to use what you learned from other rooms without any specific guidance.

karmic ember
#

the OWASP juice shop room and DVWA might be along the lines of what you're thinking

ripe cape
#

yeah ^^ although that it doesnt cover privesc that much, or not at all :)

tawdry ravine
#

I use metasploit sometimes but it's kind of hard to grapple with.

somber crow
#

Like any challenge room

native raptor
#

Do you mean more of a playground with different ways to do things, kinda like a KoTH machine @tawdry ravine?

sleek elbow
#

actually, I'm not busy for the rest of the week, I'll see if I can't push some buttons to make things happen

karmic raven
#

just kidding love you bb

ripe cape
tacit anvil
vital blaze
#

Hey guys I was thinking about creating a room on Function Hooking using LD_PRELOAD on linux. What do you all think ?

tough pasture
#

so it'd be hard finding a balance

vital blaze
#

Yeah some basic knowledge would be required but I will try to break it into parts with some hands-on

meager lodge
#

need help

#

stuck

vital blaze
#

With ?

meager lodge
#

Security Misconfiguration task in owasp top 10

#

I need to login a page

vital blaze
#

I guess you're in the wrong channel

meager lodge
#

oh

vital blaze
native raptor
clear garden
#

Does THM have rooms related with sigma rule?

karmic raven
warm spear
#

is there a Room for Azure platforms?

karmic raven
#

nope

#

nothing really cloud, most of us have deemed it too difficult/tedious to make a practical room on

cunning thunder
outer girder
#

Hi, I'm interested in making Incident Response and Digital Forensics related rooms. How do the Windows licensing work for creating Windows rooms?

somber crow
fluid sedge
#

Perhaps a Snort room?

sudden garnet
#

there's a suricata room in dev so i hope they can snort too

sour zodiac
#

Don't know if a room like this already exists, but this is the simplified idea: its as real as a ctf can get, kind of simulating a bug bounty, disallowing some attacks and allowing others, (web based challenge btw) foothold will be hell, exactly like a bug bounty, everything will be sanitized(but dont sanitize it too much, we want foothold to be possible kekw), the player will have to try multiple payloads in attempt to get a successful web attack, from there they get foothold bla bla bla, and the privesc extremely hard ;))

sudden garnet
#

isnโ€™t that pretty much every web based challenge box?

#

just a hard one it it needs filter evasion techniques

sour zodiac
#

more rooms on some filter evasion techniques would be very nice

spice frigate
#

If I completed a paid room, after my sub expires I should still have access to it.

#

Hope this becomes a thing

somber crow
#

This channel is more for suggesting new rooms to be made

tacit anvil
#

more rooms on underground yet very useful tools, things that arenโ€™t the mainstream or what everyone uses.. and a walkthrough on how to use them would be cool

native raptor
ripe cape
#

lol

native raptor
#

That is not how subscription models work I'm afraid

karmic ember
tacit anvil
karmic ember
#

this is all true. I meant that sarcastically

tacit anvil
#

yeah I get it

#

there should be a capture the cat room

#

you gotta hack into the machine and when you are root it has a cat picture with the name of the cat, and you gotta submit the name of the cat

tacit acorn
#

hey guys im not sure if there is a room for gaining access on Mac osx machies, if there is something like that could you please point to a similar room? And if not, that would be nice to have a room like that. I myself have not found much online about exploiting a mac osx, just food for thought

lunar plank
marble currentBOT
#

Gave +1 Rep to @tacit acorn

tacit acorn
marble currentBOT
#

Gave +1 Rep to @lunar plank

sleek elbow
#

still looks like they're at $1.20/hr per instance for a 24 hour-minimum lease ;-;

#

I wish apple would give in and allow virtualization on non Apple hardware

karmic raven
atomic glade
#

Ah, thanks just saw it and figured would throw it out

cunning thunder
cedar echo
#

Those are expensive ๐Ÿ™‚

cunning thunder
#

I think they're using Apple Mini's. Imagining this gigantic room with a cart full of mini apples. ๐Ÿ˜„

karmic ember
#

AWS also has a service for testing on various mobile devices. Soo yeah, they probably have an entire data center filled with macs and various cell phones and such

#

or multiple, because regions.

karmic ember
#

I guess macs can't dodge balls.

ripe cape
#

must hurt doe

#

a glass sharp thing

karmic ember
#

Possible idea: a room on recon-ng

#

(for the pen+ path)

karmic ember
#

Also, possibly more in-depth stuff on aircrack and ARP (again, for pen+)

uncut kelp
modest trail
#

@uncut kelp wrong channel but likely you've forgotten to import the module with something like Import-Module -Name Powerview.ps1

uncut kelp
marble currentBOT
#

Gave +1 Rep to @modest trail

sudden garnet
karmic ember
#

Probably just basic/general knowledge. The beginner and pen+ paths didn't really have any of that (unless I forgot it, which is possible).

somber crow
#

I've been contemplating a 102 room, if I can work out what content I want to include

foggy quest
#

is Ubuntu 20.04 not supported for machine submissions?

native raptor
#

AWS won't convert it

#

So, nope

foggy quest
#

damn thats so unfortunate

native raptor
#

It's annoying as heck

foggy quest
#

yeah tell me about it ๐Ÿ˜‚

native raptor
#

Nothing we can do about it until Amazon get their act together

#

We can deploy them in the cloud directly, but that requires either quasi-admin perms over the management console, or direct communication with an admin to co-ordinate deployment/cloning/etc

#

I've just built one for the new polkit vuln, for example, which required 20.04

#

But generally speaking, no, and it's very annoying

foggy quest
#

who can i speak to about? perhaps the route may sway them to say yes thinknow

modest trail
native raptor
#

Want to DM me the idea?
I can technically deploy one for you, although I can't move them between accounts (and the only way for me to attach it to the room directly would mean adding my name to it, which isn't fair on you) so you'd be better speaking to someone like CMNatic to co-ordinate it.
If you DM with what you're intending I can tell you if it's likely to get straight through testing though, which may be enough to sway 'em ๐Ÿ˜„

native raptor
karmic ember
tough pasture
native raptor
#

Ooh, apparently it might

#

But meh, I have a working copy in the room already ๐Ÿคทโ€โ™‚๏ธ

tough pasture
native raptor
#

Nope. 20.04

#

I can deploy them directly

tough pasture
#

ahh, got it

#

โœจ admin privileges โœจ right?

native raptor
#

Not an admin, but aye

tough pasture
dapper nymph
#

B

radiant swallow
#

polkit when

#

๐Ÿ‘€

somber crow
radiant swallow
native raptor
ripe cape
#

spoilers

native raptor
#

It's a walkthrough smh

karmic ember
#

I love walkthroughs ๐Ÿ™‚ blobheart

short jackal
#

Does anyone know what it would take to build a homemade virtual PC, without using a website that gives it to you, real code that you make

sudden garnet
#

que

radiant swallow
short jackal
#

Ok thank you

radiant swallow
native raptor
tacit acorn
ruby bloom
#

probably this idea has already been around here, but it would be nice to have a room with the objective of teaching how to make a writeup and/or mainly a report. The report is something important in our area and it is very difficult to find content on the internet that shows a good or at least standardized way of reporting. The room could simply work with simple vulnerabilities, focused only on teaching how to report them in a document

#

The Wreath room has a bit of a summary about it but it would be nice to have a room focused on that in more details.

native raptor
modest trail
# ruby bloom probably this idea has already been around here, but it would be nice to have a ...

There is no real standardised way of reporting as it differs between companies so would make it pretty difficult to create a room on. One repo I see being sent around quite commonly is this one: https://github.com/juliocesarfort/public-pentesting-reports
It might give some idea as to how they differ but also have similarities ๐Ÿ™‚

GitHub

Curated list of public penetration test reports released by several consulting firms and academic security groups - juliocesarfort/public-pentesting-reports

tacit anvil
#

It just occurred to me, do you need room reviewers/beta-testers ? If this is volunteer work and you could use more people in the pool I'd be happy to help. Would also force me to accelerate my learning plan ๐Ÿ™‚

tacit acorn
#

@somber crow yo any updates on the WiFi hacking 102?

graceful crane
#

Hello friends! I have been developing a room called "Intro to Pwntools" which is what it sounds like. I am hoping to make it public, although before I submit it for public consumption, I was hoping a few people might like to test drive it: https://tryhackme.com/room/introtopwntools

#

I would appreciate constructive feedback, presuming it is respectful. Thanks!

karmic raven
#

Nah itโ€™s not you just donโ€™t know how to access a non public released room

warm sand
turbid schooner
#

Hello, room "intro to networking" in the Complete beginner path.
It is stated in the task 7 WHOIS that whois might not be already installed on the attackbox machine (running apt-get install whois)
On my end traceroute (task 6) wasn't installed either, we could add a disclaimer on the previous task.
Love your work.

ripe lodge
#

๐Ÿ‘‹ HI

lucid quail
#

alpaca attack ๐Ÿ‘€ if possible

sudden garnet
#

doesnโ€™t that involve a mitm?

tacit anvil
#

Hi guys. When i expoit ip, with msfconsole, using ssh_enumers, it shows me "found'". no matter what user_list I provide. I think it havent be like so. where is a problem? I hope i explain myself right. learning...

#

holy, sorry for posting in wrong room

tacit anvil
rocky gazelle
#

-undelete

marble currentBOT
#

Up to 10 last deleted messages (last hour or 12 hours for premium):

none...

chilly kayak
#

I'm fumbling around with the inacave room (and enjoying it), I think I found shell code(lol). What if you all created a room to get more understanding of shell code?

tacit anvil
#

has any one done a room with the sudoedit -s '\' exploit?

somber crow
#

I think Muir did

crisp scaffold
#

Hello everybody. Are there any rooms yet or planned which may focus on OT or industrial security?
Also, can someone point me to the right direction where I can learn some techniques to fake CRCs?

fading oak
crisp scaffold
#

Thank you

nova kiln
#

Hello, I've been thinking of making a room based on python tool development that i'd like to make, is that something that's possible to make on TryHackMe?

native raptor
#

Would be up to @cunning thunder or @willow glade to decide whether that's something that's wanted for public release given there's already a Python room out and it's not a programming platform ๐Ÿ™‚

willow glade
# nova kiln Hello, I've been thinking of making a room based on python tool development that...

I agree with @native raptor. Having some level of programming competency is definitely helpful for hacking. However, I donโ€™t think it would be a good fit at the moment.

If you think the platform could benefit from a programming path or youโ€™d like to see more coding based content please feel free to leave site feedback. (All site feedback gets read! ๐Ÿ˜)

@cunning thunder, thoughts?

cunning thunder
burnt panther
#

@cunning thunder hello sir, i submitted a room on tryhackme..the room name is unworthy thor..i want to know how many days it takes to to open lab publicly.

sleek elbow
#

short answer: it could take a while
long answer: it depends how many rooms are in the queue, how difficult your room might be to test, how difficult other rooms in queue are, if a volunteer room tester vs thm employee has picked up testing, and how busy testers might be in any given week

restive swallow
clear jasper
#

Hi all,
[SOLVED]
in the task 10 of the "Network Services 2" module,
Do you have an idea why I have this error ?
Or do you have the same problem ?
I can connect me with mysql client at this database like the task 9, and the mysql_sql module works fine.

burnt panther
#

hey how i volunteer for room tester on thm ?

somber crow
#

You would need to be selected.

tacit anvil
#

how bout a room called "I use arch btw"

grim finch
#

@clear jasper Looks like you solved it but just incase i think this is to do with the version error. Drop down to msf5 and try ๐Ÿ™‚

somber crow
#

How is that a version error?

tacit acorn
#

room idea: Burp Suite 2.0 ?

#

after finishing the upload vulnerabilities room, which btw, @native raptor did an amazing job at, I think maybe being more familiarized in detail of using burp suite would help people complete rooms such as Muiri's, specifically the jewels task, easier. Idk what you guys think but thats what popped up in my head when I woke up

native raptor
#

Like the Burpsuite room?

tacit acorn
# native raptor Like the Burpsuite room?

I do @rocky gazelle did an amazing job at that room! When I got to your room last task I had no choice but to give in and watch your video and that cleared it up, I wasn't using burpsuite correctly from the start, thats how i got hung up! haha

sharp kindle
#

Hi Guys, is there a room for Report Generation in tryhackme.. if not, can anyone guide for the source to follow.

#

if it is something we are reporting for bug bounty..

clear jasper
graceful crane
tacit anvil
#

Hello Everyone, has anyone thought of making a room on Laravel Vulnerabilities?
I've been looking around for it but apparently it's not there.

and by searching it looks like there are many Laravel Vulnerabilities.

Thank you && Happy Hacking!!!

#

Look forward to hear from you folks.

icy trellis
#

Ohhh

#

If nobody takes this I might ๐Ÿ‘€

tacit anvil
fluid drift
#

who knows how to hack a webcam

somber crow
#

@fluid drift Why do you wanna do that?

fluid drift
somber crow
marble currentBOT
#

๐Ÿ”จ Banned montaibrah#6252 indefinitely

karmic raven
sleek elbow
karmic raven
gray blaze
#

Ulrich Boltaz:
Anyone completed kida room

I need help on gaining shell

somber crow
#

@gray blaze this channel is for suggesting new THM rooms, try #room-hints

sudden garnet
#

would rooms on enterprise level firewalls be doable? or would there be licensing issues

sleek elbow
#

it depends

sleek elbow
#

-warn @tacit anvil Your user account/token has been compromised. Your account is sending CS:GO scam messages. I'll be placing you on a 24 hour mute. Get this fixed.

marble currentBOT
#

โš  Warned CEEEEEJ#5011

sleek elbow
#

-mute @tacit anvil 24

marble currentBOT
#

๐Ÿ”‡ Muted CEEEEEJ#5011 for 24 minutes

sleek elbow
#

-mute @tacit anvil 24h

marble currentBOT
#

๐Ÿ”‡ Muted CEEEEEJ#5011 for 1 day

hybrid merlin
#

I realised we don't have a room on VLANs, either teaching the basics of them or compromising/hopping between them. I'll start research tonight. not sure if I'll need to make a network to do it or not.

fading oak
#

I think one of the newer rooms under Pre Security: Network Fundamentals does touch briefly on VLAN's and routing. You may want to coordinate with CMN on doing something further.

keen bone
#

a series of rooms about beginner intermediate advanced binary exploitation in linux and windows and room for kernel exploitation technique for both system i think it will be a good idea

cedar shuttle
#

there should be a path on grc (governance risk compliance )

native raptor
#

Apologies -- read that very wrong ๐Ÿ˜†

native raptor
#

Why not make one @wild burrow? ๐Ÿ™‚

#

I'm sure there was one actually

#

No idea what happened to it if there was

#

Doesn't seem to be there now

cedar echo
#

Is beef still relevant these days?

lament star
#

But never actually released it

sleek elbow
#

yeah

#

something about wanting a VM and him not wanting one or something

karmic raven
#

Itโ€™s just not worth the time IMO but I believe @feral reef said he would look into making some at one point

feral reef
modest trail
cedar echo
#

Oh my

marble currentBOT
#

Gave +1 Rep to @native raptor

tacit anvil
#

tryhackme should have a room where U have to socially engineer an ai, depicting a real social engineering attack

#

the ai can be an employee of an imaginary company

#

and once you are able to socially engineer the ai you are given the source code of a webserver and you have to hack into the webserver like a typical ctf

icy trellis
#

Technically Throwback, I guess?

#

Not much of an Ai though KEKWL

sleek elbow
icy trellis
#

Troooooo

#

"If email.has_attachment: email.attachment_run"

sleek elbow
#

actually, we did it a much worse better way

#

we used a mail commandlet to unpack executables from the emails, then shipped them off with SFTP which we then used SSH to run them kekw

karmic plume
#

I would put the idea of disable functions room

somber crow
#

Huh?

lament star
#

PHP disable_functions most likely

#

Or how to bypass them to be more precise.

tacit anvil
#

it will be more of a talking ai thing

#

where you have to convince the AI to give u the source code

#

or smth

#

and no it wont be if statements it will be a proper neural network

tacit anvil
#

whats that supposed to mean

karmic raven
#

kekw

#

He was making a joke about the Throwback AI

karmic raven
tacit anvil
#

hmm

#

it will be trained on my pc then i will export the keras model put it into an ubuntu server then upload it

karmic raven
#

If youโ€™re insane enough to do all that work go for it

tacit anvil
#

yep

sleek elbow
keen bone
#

windows driver and kernel exploitation it will be a nice idea for a room

somber crow
#

Covering?

tranquil marsh
#

Yeah like how to write a proper report

native raptor
# tranquil marsh Yeah like how to write a proper report

This keeps coming up, in here, so I really wish I had another answer, but report writing isn't something it's really possible to teach.
There are millions of ways to do it. Every company does it differently / has their own templates. I have an example at the end of Wreath, but that fits easily into a single task.

keen bone
#

i think it s a good idea to add a binary exploitation channel

native raptor
#

@keen bone why not a web channel? Or a forensics channel? Or a crypto channel?

#

(Genuinely asking -- if you have a justification for switching up the entire help structure in the server then we can look into it)

sudden garnet
#

i think maybe they meant room

keen bone
keen bone
marble currentBOT
#

Gave +1 Rep to @sudden garnet

keen bone
native raptor
karmic raven
#

tbh, in all the discords Iโ€™ve seen with dedicated security channels, they rarely get used and the conversation is very random. I think the channel structure here has created a balance middle ground with some channels I think could do with some leaning out but eh

keen bone
karmic raven
somber crow
#

That'd be way too many channels

keen bone
normal star
#

hey, i submitted a room. its been 1 month now i guess. what i suppose to do now :3

somber crow
#

You'll need to be patient. The room reviewers are all volunteers, and there's no fixed time

normal star
#

ohh cool! thats totally fine. generally how long will it take ?

#

this is my first room tbh; so i just dont have any idea ๐Ÿ˜… .

cunning thunder
# normal star this is my first room tbh; so i just dont have any idea ๐Ÿ˜… .

Hello, and thank you for submitting community content on the TryHackMe platform. ๐Ÿฅณ The room queue is pretty busy, so it's hard to say exactly when your room will be reviewed. As soon as a room tester starts reviewing your submission, the system will notify you. ๐Ÿ™‚

Here's more information regarding the Room Review Process:
https://help.tryhackme.com/room-creation/the-room-review-proccess

TryHackMe

What is Room Testing and Who Tests? TryHackMe uses a room review and testing process to keep content on the site accessible, consistent, and appropriate. R

marble currentBOT
#

Gave +1 Rep to @normal star

normal star
marble currentBOT
#

Gave +1 Rep to @cunning thunder

sudden obsidian
#

Can someone guide me on how to add colorful text in task title for creating a room?

native raptor
#

(It's really not hard though: good luck!)

lucid quail
#

๐Ÿ‘€

normal star
native raptor
normal star
#

calling a bug a feature XD typical programming things

native raptor
#

It's not a bug so much as the configuration allowing slightly more (harmless) things than were intended ๐Ÿคทโ€โ™‚๏ธ

normal star
#

hehe yeah i was just joking :3

native raptor
#

Or that, if you're lazy like Cry

karmic raven
#

I call it engineering

sudden garnet
#

i agree

#

i stole it from muir's room

native raptor
#

I call it theft and lack of ingenuity, but sure

native raptor
#

-clean 100 689000887041130517

topaz parcel
#

i have a question, it is possible to attach to tmux session after logging in which was previously created. But how will it be possible to keep that session running when we export the box to and upload it to thm room. Wouldn't that process just die when we turn off the box. Or is there a way to spin the session up when we boot up the box

tough pasture
#

@topaz parcel maybe something like this will help?

lament star
#

wouldn't recommend that as a privesc, it's way too common.

teal sapphire
topaz parcel
upbeat badge
#

Hi all, there is any material about how to make rooms/challenges?

lunar plank
#

!docs room-notes

soft hamletBOT
tacit anvil
#

did I just get ghost pinged again?

heavy hemlock
#

What do you think of a room adapted from the series the blacklist and the shadow broker group?!

undone mist
#

For Windows Fundamentals 3, for task 5 I'd suggest using just "xyz" instead of "xyz network" as the answer, because me and another dude spent some time confused after putting in "xyz profile" (same amount of letters as network) and it not working.

tacit anvil
#

Adding some WAF bypass in the web fundamentals

#

not only for XSS, but also for SQLi and general purpose API

plush galleon
#

In addition to the already existing "OWASP TOP 10" room, could we get an OWASP room that walks you through the manual testing HUD that Owasp provides?

placid pilot
#

In developing a room, is there any interest in a blackbox-room ?

native raptor
#

Wdym a blackbox-room @placid pilot?

#

(Because that describes most of the challenges on the site if you mean black box in the traditional sense)

placid pilot
#

I havent ventured into all parts of the site yet. But getting the answer to 1 question without any information is whats already on here?

native raptor
#

I mean, search the site for challenge boxes

#

Some of those are guided

#

Most are not

placid pilot
#

Ok cool. So I can upload some of mine ๐Ÿ™‚

native raptor
#

Most challenges are just like that

#

VM and a couple of flags ๐Ÿคทโ€โ™‚๏ธ

placid pilot
#

Shouldnt be easy to get them though

native raptor
#

I mean, that's from a hard ranked box

#

They go up to insane

#

I'd suggest maybe having a play with a few more of the features on the site before thinking about building stuff for it, just by-the-by ๐Ÿ™‚
Not least because we reject things that are too similar to other content. It helps to have a good basis in what's already there.

placid pilot
#

I get it. I'm just here to see if there's things I don't know yet. Paid for the premium rooms just to see whats there

#

I'll get in touch later when I've done a few CTFs

tacit anvil
#

DevOps Path would be really great

#

atleast i think

brave stream
#

@tacit anvil 100%. I'd love to see that.

tough pasture
#

A room on what firewalls are, and a brief introduction to setting up rules in Linux and maybe Windows?

native raptor
#

Think we've already got Linux covered in one of the Linux hardening rooms? IPtables anyway -- there are a lot of wrappers around it though.

#

Wreath does a tiny bit of firewall configuration with firewalld and netsh, although that could definitely be expanded on

sudden garnet
#

how many people actually configure host based firewalls though? maybe something like pfsense would be a lot more useful imo

somber crow
#

The content on firewalls in the new networking rooms has a lot of room for expansion for sure

placid pilot
#

Purely interest in hostbased firewalls? Or more into firewalls like pfsense or the commercial versions? Just curious where the interest lies

#

Does THM for example allow for 2 VMs be be spinned up: a firewall and a hackable VM (and your VPN or Attackbox). AFAIK there is only one box used in most rooms

tough pasture
#

I was actually thinking of primarily hostbased firewalls, and how they can be used for security when you're doing CTFs etc.

#

although it's a way smaller topic than commercial versions and it's uses in enterprise I guess

keen jetty
#

Would anyone be interested in a room on system hardening/ configuration?

#

SELinux, GPO, STIG, etc?

somber crow
#

You could go very in depth with SELinux IMO, especially doing hackery things while it's enabled

keen jetty
#

I'll see what I can put together ๐Ÿ™‚

atomic glade
#

CVE-2021-22555

#

New exploit?

karmic ember
placid pilot
#

I meant if it was possible to deploy a multi-vm room

cunning thunder
#

You can attach one VM to one task, but they are deployed separately and are not forming a deployed network (like wreath).

lapis wedge
#

how can i hack

#

my friend phone

true hornet
# lapis wedge how can i hack

First off that isn't what we do here and is 100% illegal
Secondly this is completely the wrong channel to ask that.

lapis wedge
#

So in which channel I would ask that

true hornet
#

See point 1

#

Also point 3 - Rule 9

fading nova
#

Someone, Please Help me with the rooms I do know nothing. As a beginner, I don't know from where should I start to learn cybersecurity. I want to subscript but I don't understand what benefits I will get by subscription.Someone, please help me๐Ÿ˜ฉ

gusty fulcrum
#

@fading nova If you subscribe you can do the pre-security and complete beginner path's. That will walk you through from knowing nothing to knowing quite a bit in a short period of time.

fading nova
fading nova
gusty fulcrum
cedar echo
placid pilot
cedar echo
#

Sorry on mobile don't always see everything

placid pilot
marble currentBOT
#

Gave +1 Rep to @gusty fulcrum

tranquil marsh
somber crow
#

Nope

#

In networks, they're handled separately. You don't deploy them.

placid pilot
somber crow
#

There's a huge cost issue from several machines, and beyond that there's the technology. Networks are shared environments because of this.

native raptor
#

They also require a lot of direct interaction with the admins to setup and manage them. Those guys are seriously busy these days

analog saddle
#

Has anyone ever thought about a programming path? That and a basic hardware/electronics path?

somber crow
#

Those are a little tenuous in terms of their links to cybersec

#

THM isn't a programming learning platform, there's lots of those already

native raptor
#

Aye, but they would ๐Ÿ˜†

placid pilot
somber crow
#

That won't overly help though

placid pilot
#

It does for setting up your own environment and testing

somber crow
#

Ok, but you'd be doing that entirely outside of the THM Networks environment

placid pilot
#

Well you can do it inside a vm

somber crow
#

Which is very different to standard THM rooms and, like Muir said, requires a lot of admin involvement.

somber crow
placid pilot
#

Networking

somber crow
#

Yeah, but that's not THM networks

somber crow
#

No.

placid pilot
somber crow
#

That's entirely wrong.

placid pilot
#

Because?

somber crow
#

Because that's not how it works?

#

It's not inside a VM

placid pilot
#

Yes it is. It's isolated networking

somber crow
#

You can make your own room with a single VM and containerised stuff. As long as you don't use nested virt then it'll be fine.
But that's NOT the THM netoworks feature.

#

Please understand the distinction.

placid pilot
#

I understand. I just explained it

#

Chill

native raptor
#

Docker / LXC networking, whilst simulated networking, isn't quite the same as a VPC on AWS ๐Ÿ™‚

placid pilot
#

I know. Like I do that stuff for work

somber crow
#

THM networks is a specific feature which requires a lot of admin involvement. You cannot develop for that, unless you're explicitly invited.

#

As I said, you can visualise a network and do containerisation if you want. That's not THM Networks

placid pilot
#

Ok you're really not reading what I'm saying

#

I'm out. Do what you want with my vm. I'm stopping my subscription

#

Not being taken seriously is a big mistake

somber crow
#

I'm not THM staff. We all do this on a voluntary basis, and we're lending the experience and understanding of the platform because we want to see good content created.

placid pilot
#

Doesn't change my opinion

lunar plank
#

Hii, if it helps, things like the THM networks (that you connect to and hack) is very complicated. Rooms like wreath, holo, etc are very individual in the sense that they the deployment process for these is so unique (i.e. we have to have vpn servers, and the network has to scale depending upon users) all of which is very costly

You're more then welcome (and encouraged) to submit a room that has an individual room though @placid pilot (:

#

You can use networking in single VM containers i.e. dockers but aye yeah, multiple machines/VMs per room is very specific

#

afaik we aren't looking to have anymore networks for a good amount of time afaik

analog saddle
somber crow
#

Those are scripting languages, with the intent of automating activities

#

THM isn't a programming platform, and the site staff have rejected a number of programming based rooms.

analog saddle
#

Not even introductory courses? It would make sense since some exploits are written in C. As well as some tools too. I think have some kind of primer or basic overview wouldnโ€™t be too far out of the realm.

somber crow
#

There are lots and lots of primer programming sites

analog saddle
#

Ok thanks

teal sapphire
karmic raven
#

That room has been updated

#

Itโ€™s been chilling in the release queue for months

teal sapphire
regal badger
#

Is there any mac os rooms or that not a thing?

somber crow
#

MacOS is incredibly expensive on AWS so not really feasible for rooms

teal mortar
#

Would love to see more blue team rooms in the future

sudden garnet
teal mortar
sudden garnet
#

i think they might be working on a blue team network, although i could be wrong

#

but if you guys arenโ€™t, i think that would be a really good idea, fully mimicking a soc ๐Ÿ‘€

tranquil marsh
#

Here is an idea... There is already a Security+ learning path, how about paths for other certifications? Like en eJPT path, that can act like a companion to the INE course.

#

Pentest+ path I mean

karmic raven
#

Itโ€™s in my opinion pretty much a one time thing but you could always put it in #feedback-and-ideas that would be a better place for it

cunning thunder
tacit anvil
#

a printnightmare room would be interesting

sleek elbow
#

same thing happened for Zero Logon

#

had to wait close to a month after release because we didn't want people running out and 0logoning DCs lel

slender turtle
#

I've done a few ctf's now and seen some challenges with recursive nested .zip files and noticed THM doesn't have any challenges related to that. maybe one where you write a simple bash script to solve?

tacit anvil
marble currentBOT
#

Gave +1 Rep to @sleek elbow

orchid cliff
#

Pls help with the answers

sleek elbow
#

don't seek help for school assignments here.

#

@orchid cliff

orchid cliff
#

Ok

#

Where can I get help then?

sleek elbow
#

Not in this discord.

#

we respect academic honesty here.

#

You can do the research for your own assignments yourself.

sacred yoke
#

A few ideas include:
The IT Crowd themed room :)

I figured if there was a Rick and Morty themed room, maybe there could be a Tuca & Vertie themed room.

clever compass
#

How about a room /thread with a Q&A on discord and THM rules for new comers ?

sleek elbow
clever compass
#

@sleek elbow Do you think I should ?

sleek elbow
#

it would probably be useful for the people who come in and say "what did", but probably not as a room

clever compass
#

Thanks! I will do ๐Ÿ™‚

rocky gazelle
clever compass
#

@rocky gazelle Hi Dark, It is to help understand the key points in the rules. There could be questions like 'If I do X, Y or Z - which rule am I breaking? Something like that.

rocky gazelle
#

Is there a specific rule you see this helping with? I'm not being critical, I just don't think the rules are too hard to understand. They're pointed out in our #start-here chat and have been worded/reworded for clarity

clever compass
#

Not at all! I am all good ๐Ÿ™‚ I just thought this exercise might help.

rocky gazelle
#

I do appreciate the suggestion, just want to make sure I understand the root of any issues :)

brave aspen
#

What about a room about how to use Scapy?

placid pilot
modest trail
#

It's not technically an 0 day anymore

teal sapphire
#

A tutorial room for Selenium Web-Browser Automation would be great๐Ÿ‘€

teal sapphire
cunning thunder
teal sapphire
#

Apart from it, if the webapplication is static in nature and depends entirely upon JS, it would be pretty hard to reverse-engineer it and automate any features in it using standard python libraries such as requests.

cedar echo
cedar echo
#

Puppeteer is also an alternative I've seen used in rooms

lusty quarry
#

Maybe a room that touches on use-after-free and other binary exploits

radiant swallow
#

Sequoia privesc CVE2021-33909

cedar echo
#

Are there any rooms touching SAML?

tranquil marsh
#

Has anyone asked for a room specifically covering directory enumeration, like dirb, dirbuster and gobuster? It's slightly touched on in the CC Pentest room, but I think a dedicated room would be awesome for beginners (since you need to know at least one of those three for Pickle Rick).

somber crow
#

CMN made one

#

Not sure if it came out

tranquil marsh
lunar plank
tranquil marsh