#room-bugs

1 messages · Page 31 of 1

eternal summit
#

It's the worst solution possible to the problem of obsoleting rooms and a lot of people have had a lot of problems with it

misty cave
#

No reply? (Fixed)

quaint sparrow
misty cave
eternal summit
#

-ban 457592536244944896 -ddays 1 Nitro phishing

livid escarpBOT
#

🔨 Banned 457592536244944896 indefinitely

wheat fractal
#

Hi there, I was looking for my error in the networkservices2 room Task 3 because I couldn't reach ssh connexion, then I checked again the username and it might have an answer issue (well, I admit, I didn't see first that I wrote the wrong answer and it had nevertheless been accepted) : || The right username is cappucino with only one c isn't it ?||

rugged canyon
#

that is answer tolerances

#

if you referesh the page it will show the correct answer now

#

@wheat fractal ⬆️

wheat fractal
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

no problem

junior shore
#

Room :Linux PrivEsc Task 12 Capstone challenge not working

junior shore
#

When you the green start machine button it does not load.

#

no issues with the other tasks

#

just that one

#

tried that already. This is a task that I did a month back and it did this

#

Machine wont load whatsoever. If the other tasks loads the machine there is clearly something wrong with that task machine

#

"Connected to Tryhackme Remote. Waiting for response" If you read the forum page. People get the same sort of issue.

#

IP shows up but machine on the right hand side does not

#

If I can click the machines on the other tasks and they load up perfectly, its something wrong on THM side.

#

it is on split view

junior shore
#

If you can let me know if you get the same issue.

tropic flameBOT
junior shore
#

hmm idk then

dusky junco
junior shore
#

Maybe its an issue for free users I am assuming

junior shore
dusky junco
#

IK, but machines for subscribers will deploy with more resources, so it might be that we need to increase the minimums for free users.

Could you deploy the machine in that task and give me the IP address please? I can check on our end what it deploys with

junior shore
#

Yeah sure give me a sec

dusky junco
#

ty(:

junior shore
dusky junco
#

that looks like exactly what the issue is. I'll raise this to get it sorted 👍 unfortunately it's under the THM admin account, so I'll need to forward it onto the owners to get it sorted (:

junior shore
#

No worries thanks

dusky junco
#

-ban 532930515662012417 -ddays 1 Nitro scam/phish. You're 0x5....Secure you're account by resetting your pass and enabling 2FA. Appeal the ban at bans@tryhackme.com

livid escarpBOT
#

🔨 Banned diko#9968 indefinitely

dusky junco
#

ugh ick

#

I used you're not your and it's on record now

leaden kayak
junior shore
storm holly
eternal summit
storm holly
#

just seems like bad practice even it might be a lower scope issue

eternal summit
#

What do you mean by lower scope?

storm holly
#

the likelihood of someone reading https urls going through your computer

eternal summit
#

No idea what you're trying to say.

#

But refer to point b

spare terrace
#

i think @storm holly is talking about a man in the middle attack

eternal summit
near kelp
#

Hey guys, in room OWASP Top 10, XSS section (Task 20), if you change “XSS Playground” using <script>document.getElementById(“thm-title”).innerHTML = “I am hacker”</script> you aren’t getting the flag. I was a bit confused so had to look in the hints and it only worked with the recommended command. Idk if this is considered a bug just wanted to let you know

median coral
rugged canyon
#

Left Double Quotation Mark
double turned comma quotation mark
vs
Quotation Mark

near kelp
median coral
#

well, best to use the right quotes for future payloads and stuff then fingerguns

near kelp
#

sure, I just wanted to let you guys know that the text has changed on the website but I didn't get the flag:)

primal zodiac
#

bug on lazyadmin room is still there

#

so it seems that the article that its supposed to lead you to has changed its hostname

#

so instead of basic-cms

#

its now sweetrice.xyz

#

this is where its supposed to take you

obtuse pebble
#

I'm doing the Lian_Yu box and I'm unsure if this is a bug but the youtube video doesn't work. This may be purposeful but I'm unsure

quick violet
median coral
obtuse pebble
obtuse pebble
median coral
#

I completed it without it,

obtuse pebble
livid escarpBOT
#

Gave +1 Rep to @median coral

median coral
#

probably was a rick roll or something

obtuse pebble
cedar meteor
wheat fractal
#

Splunk 2 Task6 Q4 won't accept my answer which I have confirmed elsewhere is correct. It is probably because it contains characters not on the English keyboard but I can't see any way to work around that

eternal summit
junior shore
#

Bypassing UAC task 3 does not work

chilly pasture
cedar meteor
digital mural
#

Hi everyone. I am working on the Kubernetes Chall TDI 2020 room and I am having trouble connecting to the Kubernetes server. When I run the command that is listed under the Hint, I see the version information for kubectl, but then I get the message "The connection to the server <IP>:6443 was refused - did you specify the right host or port?" I have downloaded the config file, I can ping the machine, but when I run rustscan I can only see port 22. I have tried respawning the machine and waiting ten minutes and I still get the same error. Is it me or the room?

median coral
#

that room has been dead for a year or so

#

search up in this channel

#

it's amazing that it's still public tho, a completely borked room just laying out there with zero support

#

¯_(ツ)_/¯

quick violet
#

@misty cave

median coral
#

they can't fix it, it's up to the room creator who can't be reached

quick violet
#

they can remove it

median coral
misty cave
quick violet
#

yup

median coral
#

yes

digital mural
livid escarpBOT
#

Gave +1 Rep to @median coral

median coral
misty cave
#

Is it part of any modules or anything? Will making it private break anything?

digital mural
median coral
#

it looks like a standalone room, no rooms have mentioned it afaik

#

it was one of the last rooms I did

quick violet
#

The Diana Initiative 2020 CTF

misty cave
#

@median coral @quick violet Kubernetes Chall Room is now private.

quick violet
#

perfect

frigid plover
#

Is there plans for a function to suggest changes to tasks text, styling changes, etc?

swift lava
#

Hello
I am doing Phishing room from initial access module
There seems to be some error in gophish installation in the room because vendor.min.js scripts is getting blocked
In firefox I got : Loading failed for the <script> with source “https://LAB_IP.p.thmlabs.com:8443/js/dist/vendor.min.js”.
In chromium(kali) : GET https://LAB_IP.p.thmlabs.com:8443/js/dist/vendor.min.js net::ERR_INCOMPLETE_CHUNKED_ENCODING 200 (OK)

Due to blocking of this script I cannot do anything because jQuery is blocked everywhere (eg : Uncaught ReferenceError: $ is not defined
at sending_profiles.min.js:1:5681)
What can I do?
I disabled all firefox tracker blocking features, chromium installation is brand new but still results are same

plush depot
#

Hi guys, I'm new to TryHackMe, I just started to complete a couple of Cyber Security courses, for some reason I can't complete one of them (Encryption - Cryopto 101) : there is the following question:
Who is TryHackMe's HTTPS certificate issued by? It says that the answer should be: ** I can't complete it, I tried all the different combos with C, but still not working. but I'm not sure if is a bug or the answer is different from what the question is asking. The first thing that came up when I was following the instructions on the Task 8, was CloudFlare, but it is longer than 2 slots. Does anyone know what should I do to complete this course?

rotund burrow
eternal summit
#

This is not a bug.

plush depot
#

Ah ok thanks,

dull hornet
#

Hello, in the junior penetration tester learning path room nmap post port scans there is a huge contradiction.

#

The upper text is clearly wrong and it is also clear writer is contradicting with himself in the next paragraph.

#

First it says you cannot use -sV flag within Syn Stealth scan (which is completely wrong) and than in the next paragraph he gives an completely different example where -sV flag is used with -sS.

eternal summit
#

It runs then sequentially, so perhaps it mostly needs clarification?

dull hornet
#

can you please be more clear I am not a native speaker

eternal summit
dull hornet
#

okay thank you

eternal summit
#

So they are sort of incompatible, but not for practical purposes

finite bison
vagrant tangle
#

Hey. is this a Bug, or I missing something?
I've Finished the Burp Suite : The Basic, but I cant complete the Pentesting Tools Series.

thorny thicket
#

bug i have that in some modules too

elder hound
#

not sure if this should be a bug or if it's better suited as feedback, but i just finished up the OverlayFS - CVE-2021-3493 room and had a miserable time copy/pasting the exploit.c program into the console window.
for whatever reason, the exploitable VM opens as its own frame within the browser window (rather than having a separate AttackBox like most of the others), and it doesn't include the clipboard option that the AttackBox has. copy-pasting the code via CTRL+V or CTRL+SHIFT+V doesn't work, and pasting it via the Edit menu > Paste command in the browser either results in the code pasting without line breaks (Firefox) or not pasting at all (Chrome). the VM is also cut off from the global internet so I can't just upload the code elsewhere and wget it.
only good option i found in the end was connecting via openvpn/sshing from my own computer, which eventually worked fine but was a pain vs. the usual browser-based approach. not sure if the room is still actively maintained but it might be worthwhile to just have the exploit.c flie sitting in the home directory of the VM itself - not really much relevant to be learned in the copy/pasting step, only frustration.

eternal summit
#

I can look at dropping the exploit on there though

#

The room isn't actively maintained as there isn't anything to actively maintain, but if I still have the file locally I can try to upload it again with the exploit this time

misty cave
hazy tiger
#

-ban 690953769445359718 -ddays 1 nitro scam

livid escarpBOT
#

🔨 Banned math#7570 indefinitely

elder hound
#

thanks james/robert! didnt mean to come off so salty in retrospect, hope the feedback helps others in the long run

eternal summit
#

-ban @rough stratus -ddays 1 Crypto nonsense referral scam

livid escarpBOT
#

🔨 Banned Echidna#8607 indefinitely

eternal summit
#

Type faster, Omega

icy elbow
#

I slowed down the moment I saw your name 😄

#

thanks james

#

also thanks lassi

pallid grove
#

Hi, probably you have a little mistake on the room MITRE task 7, when you add new question,
the question is:
Examine the emulation plan for Sandworm. What webshell is used for Scenario 1? Check MITRE ATT&CK for the Software ID for the webshell. What is the id? (format: webshell,id)
I think I found the answer but you want 5 letters and I think you except to get 7 letters

leaden kayak
leaden kayak
hot spear
#

Machine Mr. Robot CTF Key 2 keeps saying incorrect. but if I "cat key-2-of-3.txt" and copy and paste it, doesn't work. Any suggestions?

quaint sparrow
hot spear
#

Copy and pasted from terminal. Even tried eyeballing it and just type it out character by character

quaint sparrow
#

Yeah, there is another step you need to do with it.

#

Not that one.

#

The other file,

cursive magnet
#

I think there might be a bug with https://tryhackme.com/room/linprivesc task 11 when executing c code to spawn a root shell it errors with /home/ubuntu/sharedfolder/nfs: /lib/x86_64-linux-gnu/libc.so.6: version 'GLIBC_2.34' not found (required by ./home/ubuntu/sharedfolder/nfs)

#

been stuck with it a while and finally went through some of the writeups, who all do the same method I tried with success, so maybe somethings been updated and it broke?

cursive magnet
#

it doesn't

#

I tried that

cursive magnet
#

yep, from what I understand its caused by being compiled on a different system, but with gcc not available on the victim machine, I'm not sure what the solution is other than installing different VM's and hoping I get lucky?

misty gull
#

Or use Bloodhound < 4.0.3 (could be a documentation-only fix 🤔 )

obsidian kiln
rotund burrow
#

@gleaming shadow

naive tapir
#

hi, just something I noticed in the room DNS in detail. The last question, it should "whats the record for website.thm?" not www.website.thm, querying www returns an error and www can have a different record than naked domain

rugged canyon
#

@queen sphinx ⬆️

proper sentinel
rotund burrow
raw bison
#

Did you read the hint?
The flag is not directly in the comment, but a way to get to the flag.

tribal shale
#

linux agency mission24 there's no flag. its missing or someone removed it.

#

in the .viminfo file; cross-referenced and checked via some walkthroughs.. yep can confirm it's gone

modest fossil
#

Mitre room, task 3 question 4 "What are the data sources for Detection? (format: source1,source2,...)" has been broken since it was updated on July 1, 2022. It will not accept any input.

misty cave
tawny haven
#

The living of the land room is dead for me (The remote desktop server has denied access to this connection. If you require access, please ask your system administrator to grant your account access, or check your system settings.)

modest fossil
modest fossil
modest fossil
# modest fossil Any update on when this will be fixed? I have finished this room except for thi...

I got the Mitre Room Task 3, Question 4 finally to work. There is a typo on the answer. The format expected is ASTERISKS, ASTERISKS, ASTERISKS. The answer was accepted in this format: ASTERISKS,ASTERISKS,ASTERISKS. I had to remove the trailing space after the comma on each component of the answer. All other questions with multiple components have a trailing space after the comma. This is a bugged input and needs to be fixed.

misty cave
modest fossil
misty cave
modest fossil
misty cave
# modest fossil I tried this on Google Chome and Edge on my Mint Linux Desktop and my Windows 11...

That's not correct. I've just gone through and had a look, as I'm perfectly happy to change formatting where it is inconsistent and a change makes sense. But, the very next question does not have a space after the comma, neither does Q3 in Task 7, (Q5 in Task 8 does, but that's to facilitate direct copy paste from source material) so, 3/4 of the questions that have a comma in that room follow the same format, and the only exception has a good reason. (missed Q5 in Task 7, also no spaces after a comma)

#

If you can show me a screenshot of it displaying differently in another browser, i'll look into that, but i don't believe it's an answer format issue currently.

modest fossil
misty cave
# modest fossil The next room I do that has a answer with multiple components separated with com...

But that'll be a different room 😄 doesn't mean it's a bug in that one. Different THM rooms aren't necessarily consistent in answer format, as content developers change, they could be in-house or community, and QA'd by different people. While we have guidelines, they aren't as strict as dictating whether or not there are spaces in an answer format, especially when there's a format string there that shows no spaces

modest fossil
#

Yeah, here's an example from the Zero Logon room. The accepted answer components are accepted with a trailing space after the commas. This is most likely as it's correct written style to use a trailing space after commas. One, Two, Three, etc...

misty cave
modest fossil
#

What you did here should keep this from being an issue again. Thanx.

misty cave
wicked igloo
#

Hi, not sure if its me or the room, in Authentication Bypass room, Cookie Tampering challenge, when i write curl command on the attackbox it start remplacing my syntax and even the ip of my machine, and if i write it again after this little bug, it don't work. i had to open in widescreen my shell so it don't glitch and can get the flag (tryed to refresh my page, restart my attackbox but still)

soft terrace
#

Room: https://tryhackme.com/room/linuxprivescarena
Issue: unable to ssh the normal way ( ssh TCM@Target-IP)
In order to ssh into the machine you need to use ssh -oHostKeyAlgorithms=+ssh-dss TCM@Target-IP

(found at https://askubuntu.com/questions/836048/ssh-returns-no-matching-host-key-type-found-their-offer-ssh-dss )

eternal summit
#

This is a quirk of the algorithm being deprecated, you'll see this in the real world

soft terrace
#

Agree. Still wanted to let the people know if they're looking for it

median coral
hazy tiger
#

cc @remote hamlet

dusky junco
remote hamlet
old sandal
#

"range: 10.11.12.15-20 will scan 6 IP addresses: 10.11.12.15, 10.11.12.13.16,… and 10.11.12.13.20"

#

the last two should 10.11.12.16,… and 10.11.12.20?

dense garnet
glad badger
livid escarpBOT
#

Gave +1 Rep to @old sandal

tawny haven
#

The Living Off the Land Room is still unaccessible through rdp !

heavy galleon
#

Holo network 10.200.110.30 L-SRV01 not letting you login to admin page. Worked earlier and now frozen when trying to login..

mighty quail
#

Hi does anyone know in the fortress box are we supposed to be able to access /data cause the flags are all in there

radiant gate
#

in overpass room Cookies.set("SessionToken","") is not working for me in /admin.html

#

is this a bug for me or anything else?

eternal summit
#

Please read several writeups before reporting it as a bug, the room hasn't changed

soft terrace
misty cave
past sonnet
#

Probably burp suite logo!

raw bison
misty cave
# past sonnet Probably burp suite logo!

Could you upload the image to the room? That is if they allow use of their images by other people. We may need to check/provide accreditation, depending on what Usage Rights it's under

misty cave
past sonnet
#

Stole it from medium in someone else's article

#

Can remove if you want

glad badger
livid escarpBOT
#

Gave +1 Rep to @eternal summit

past sonnet
tame karma
#

In Wireshark: The Basics, there is a typo in Task 5. Right at the beginning it says "Similar to "Appy as Filter"". It should say "Apply"

brazen zephyr
#

i think this is a typo?

#

and in the writeup the machine has python3 installed but mine has it also installed but it doesnt work

#

room overpass 3

eternal summit
#

It might have python3, but it might not be in your $PATH.

#

If a write-up seems to be poor quality (ie wrong content) then stop using it

brazen zephyr
#

It has in /usr/bin/python3 but i cant upgrade my shell with it

brazen zephyr
eternal summit
#

Not a bug. Please post in #room-help if you're reading writeups and having issues. Please post to #room-bugs once you're sure it's a bug. @brazen zephyr

brazen zephyr
#

okay

strong kelp
strong breach
strong minnow
#

The answer is already listed "{{"

#

So like others question it has it hidden in these characters "**"

#

But it legit just said {{

#

And its the answer

#

Idk if its considered a bug

wheat fractal
minor latch
quaint sparrow
#

You get it from the website IIRC.

minor latch
minor latch
quaint sparrow
#

It's really just 4 extra characters, I think the only who can answer is possibly either @misty cave or James.

#

Possibly not a bug, maybe it's changed over time?

misty cave
quaint sparrow
misty cave
minor latch
#

Thanks guys for answering

eternal summit
#

@quaint sparrow @misty cave Your exact answer isn't saved, THM replaces it with the correct answer when you refresh the page

hoary fiber
#

Hello, I'm not sure if this is a bug or not, but I don't have the option to "Start", "Extend", or "Reset" on the exploitingad room. The network state is stuck on "Resetting" for days. This is the room: https://tryhackme.com/room/exploitingad

median coral
hoary fiber
livid escarpBOT
#

Gave +1 Rep to @median coral

eternal summit
#

-ban @harsh nova -ddays 1 Nitro phishing. Your account has been hacked and used to send nitro scams. Please secure your account and enable twofactor, then appeal this ban by emailing bans@tryhackme.com

livid escarpBOT
#

🔨 Banned static#8098 indefinitely

rapid wren
#

Has anyone had the same problem in the Burp Suite room- whenever I try to open the burp browser I am met with an error " Burp Browser Error - net .portswigger .devtools.client.p: Refusing to start browser as your current configuration does not support running without sandbox." How do I change this? WRONG SERVER! Sorry!

half solstice
#

In https://tryhackme.com/room/webenumerationv2, the write-up says Luckily, installing Go on Kali Linux does not require any installation of Go and does not carry with it a complicated install process. It should say "Gobuster".

quaint sparrow
#

It's probably a reference to that.

eternal summit
half solstice
eternal summit
#

First instance of "go" should read "gobuster"

quaint sparrow
#

Ah, I just thought it mean you didn't have to install "go"

eternal summit
#

That's what it means, but it doesn't say that

obsidian kiln
idle depot
#

Hello, I'm not sure if this is a bug or not, but in room "Network Services" task 9, when I nmap, i can only get port 21 open, but when i say there is only that port open i get that my answer is wrong. So after a google search i found that i was supposed to have port 80 open. I have already rebooted the machine a few times and can't get it open.

rugged canyon
#

oh yeah that one is unusually slow

half solstice
glad badger
livid escarpBOT
#

Gave +1 Rep to @half solstice

alpine rose
#

How the web works -> how websites work -> question "what term best describes the side your browser renders a website" answers supposed to be "front end" but it says that its incorrectly

quaint sparrow
#

"front end" is the wrong answer.

eternal summit
alpine rose
#

What is it supposed to be then

eternal summit
alpine rose
#

I did

#

Its the first question

eternal summit
alpine rose
#

It literally says 1. Front end (client-side) -the way your browser renders a website

#

It not front end, not client side

eternal summit
#

You're copying from the video. Don't do that. Content changes as it's corrected or updated.

alpine rose
#

Yes okay, but it asks what term best describes the side your browser renders a website

alpine rose
#

And the hint says "client side or server side"

#

Which is also not one of the answers

eternal summit
#

#room-hints
Get the answer right and you'll understand the answer and why this isn't a bug

strange parcel
#

Hi team, going through the python room (https://tryhackme.com/room/pythonbasics) and noticed a small typo in the sample code.
In the sample code in task 5, the last elif: should be an else:
The same typo appears in the sample code at the top of Task 6

open torrent
#

Hey, in the room command injection https://tryhackme.com/room/oscommandinjection there is an error in task 4, in the method filter_input we pass the FILTER_VALIDATE_NUMBER as an argument but it doesn't exist ( the correct one is FILTER_VALIDATE_INT )

wary solar
#

Hello guys, hope you're doing well. I have a matter with the Sysmon room: the sysmon machine starts, but never appears to work in. Even in trying the I.P adress, i have no results, so i can't make the work: https://tryhackme.com/room/sysmon
If someone can help me for that, thank you!

wary solar
wary solar
# quaint sparrow How are you logging in?

The machine starts well, we see the time remaining before expiry, but the windows environment does not appear, and when I type the ip address, it does not work either

strange parcel
#

Hello, I was trying to do the postexploit room (https://tryhackme.com/room/postexploit) and ran into trouble on Task3 - Bloodhound.
I downloaded loot.zip from the victim machine, but couldn't get bloodhound to load it
I saw some github issues that seemed to indicate there may be a mismatch in versions between sharphound and bloodhound. Im wondering if this room is a little old one of those tools was updated but not the other

sonic willow
half solstice
#

lowercase a.

red valley
#

Is anyone able to get task 10 done form the Throwback room? I can't seem to get a call back from the reverse shell

rugged canyon
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

no problem... and good luck with finding someone that can help and knows what the issue is

hazy tiger
#

-ban 647008787609157642 Nitro scam

livid escarpBOT
#

🔨 Banned satyam dave#7994 indefinitely

crystal verge
quaint sparrow
sand yew
#

In network services 2 nfs session (you can get root without exploiting the suid bits because the root pass is same as the username(easily guessable))

#

idk if this counts as a bug or not

wheat fractal
#

In agent sudo room getting veeery slow ftp speeds and a number of Authenticate/Decrypt packet error: packet HMAC authentication failed errors in the ovpn logs - am I supposed to be downloading the files?

wheat fractal
crystal verge
#

idk if it's fixed now

tame karma
#

In Wireshark Packet Operations, Task 4, under Comparison Operators, the operator for Not Equal is incorrect. It says ip.src == 10.10.10.100. It should be ip.src != 10.10.10.100

rotund burrow
#

@gleaming shadow

gleaming shadow
#

-ban 665506269922197527 -ddays 1 Please do not post invites to porn discords.

livid escarpBOT
#

🔨 Banned AggelosGalazios#0778 indefinitely

raw bison
#

@crude swan Please do not post random server invites in this discord.

crude swan
#

@raw bison not me i just chang my password

raw bison
crude swan
#

@raw bison yes my bad

livid escarpBOT
#

Gave +1 Rep to @tame karma

tame karma
livid escarpBOT
#

Gave +1 Rep to @misty cave

willow stag
#

hey, I am doing the Blaster room and I have noticed that the IE history is not present, I have used the write ups to bump past that question however I feel like someone needs to look into why the history is not being populated so others do not run into the same problem. Question 3.1 in the Blaster room, and this is what I see.

median coral
#

@gleaming shadow @raw bison

gleaming shadow
#

why is yag not killing those...

eternal summit
median coral
#

@gleaming shadow @raw bison

#

lmao, that's the same link too

gleaming shadow
#

-mute @viscid ivy Please don't post discord invite links.

livid escarpBOT
#

🔇 Muted Solid0x10#4408 for 1 day

gleaming shadow
raw bison
#

@topaz dock Please do not post discord server invites in here, make sure your account hasn't been compromised

topaz dock
#

It has

#

I am so very sorry

raw bison
astral talon
#

Hi .. I'm new here and I was doing Vulnversity.. but it seems to be broken..
I used -p- in nmap with-sV but it doesn't display the results for squid proxy .. at all..

eternal summit
astral talon
astral talon
#

uh oh.. such a silly mistake! I'm sorry ! Thanks for your help!

livid escarpBOT
#

Gave +1 Rep to @vital vine

astral talon
glacial hornet
#

In the Hydra room (https://tryhackme.com/room/hydra) in the section "Post Web Form" is something missing. The Hydra command is missing the "login" before :username.