#room-bugs

1 messages · Page 1 of 1 (latest)

raw bison
#

If you count the number of asterisks, you should be able to see that it's not matching with the amount of the answer you are trying, thus it can't be the right answer and seems to be not a bug

livid escarpBOT
#

Gave +1 Rep to @raw bison

frail zephyr
#

i cannot execute the command, what can i do?

median coral
frail zephyr
#

this is attack box

#

i cannot come out of root

median coral
#

just adduser then

hazy tiger
# frail zephyr i cannot come out of root

Running databases and database control scripts as root is a generally a bad idea, and I don't see us supporting that use-case. You can switch to a non-root user by using su - USER, run the script, and then return to root by exiting the less-privileged shell.

hazy tiger
#

Also @frail zephyr Have you tried just running msfconsole?

#

The database should already be initilised

#

Actually, you shouldn't be initialising the database at all

frail zephyr
#

leave i booted into kali , its running fine😇

hazy tiger
#

Here's a post made by CMNatic 2 years ago:

TLDR: You should not initialise the Metasploit database yourself (i.e. through msfdb init) as you would on your own install of Kali because this has been fully automated and fixed on the TryHackMe AttackBox. The task in the Metasploit room instructing you to do so has now been changed to reflect this (:

dusky junco
#

Thanks Habba(:

#

Jabba

hazy tiger
#

Habba Habba 😏

frail zephyr
#

how to cat flag.txt ? any idea?

quaint sparrow
#

Try more

frail zephyr
#

thnx

ashen pewter
#

The first answer should be wrong. Or maybe i am god?

frail zephyr
#

k

frail zephyr
#

3rd question , there is spelling mistake , it shoud be rustscan

dusky junco
frail zephyr
storm orchid
#

In the "Content Discovery" room, Task 9, I misspelled the answer to the question, but it still marked it as completed.

oak umbra
#

in the content discovery room when Iaunch the machine it does not connect on port 80 .. it keeps complaining "Error response Error code: 405"

oak umbra
#

I do see the port is open and the process is up but the website is not served tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN 1473/python

quaint sparrow
#

It's not asking for the port number

#

It's asking for WHAT is running on the highest port.

frail zephyr
#

My bad apache is right

quaint sparrow
#

Now it's best you delete these pics so you're not ruining flags for others.

frail zephyr
#

Done

quaint sparrow
#

@raw bison still around?

raw bison
#

@chrome drum Please do not send invites to random discord servers in here, make sure your account has not been compromised

quaint sparrow
rotund burrow
peak carbon
#

Hello everyone sorry for bothering you all but I have been dealing with this for quite sometimes now, mostly when playing ctf do you all encounter instances where you can see an ftp running with anonymous login while scanning but try to ftp into it but get login failed ? Most time I try to terminate and restart the machine and sometime I have to do that more than 4 times before I’m able to login finally, I’m I missing anything or why is that happening, and yes you might want to ask if the server is up and the answer is yes cause I try to ping .

frail zephyr
#

can anyone share link of stenography room , i am not able to find it😅

nimble gyro
#

I know this is not a big issue. Just wanted to let you know. In Windows Fundamentals 3 Task 7 the answer should be Trusted Platform Module but while writing i miss the T of Trusted in the answer but answer still got accepted.

rugged canyon
livid escarpBOT
#

Gave +1 Rep to @nimble gyro

rugged canyon
#

GG robocop

silk eagle
soft terrace
silk eagle
soft terrace
eternal summit
#

Same as typically you can't have spaces before or after your username

humble briar
#

Hi! Don't know if this was already reported, but on Searchlight - IMINT challenge (https://tryhackme.com/room/searchlightosint), the answer format for the question "What is their phone number?"on Task 5 is incorrect. lightsaberpepe (not a bug, just a formatting thing)

quaint sparrow
quaint sparrow
humble briar
#

Yes it is. I'm talking about the mask in the input.

#

It was showing that it should have a blank space in the answer, but there is not.

frail zephyr
#

its weird i am not able to connect to internet with attackbox

flint folio
#

there is a bug in the owasptop10 room, task 25, second question. it says to alter the value of a cookie to 'admin' to be able to enter the admin dashboard and get the flag, but it's possible to enter in the admin just by putting the '/admin' at the url. it doesn't need to change the cookie value

eternal summit
frail zephyr
#

then tmr

half solstice
#

tryhackme.com/room/metasploitexploitation#
In task 3, "Different from regular Metasploit usage, once Metasploit is launched with a database, the help command, you will show the Database Backends Commands menu." It should say -
the help command will show you

solemn sinew
proper meadow
glad badger
livid escarpBOT
#

Gave +1 Rep to @proper meadow

proper meadow
#

😁

glad badger
proper meadow
#

@glad badger Working, thank you!

livid escarpBOT
#

Gave +1 Rep to @glad badger

soft terrace
soft terrace
quaint sparrow
# soft terrace

Yeah, the room has been made private as it may:
Be getting fixed
Too old so it's been retired.

#

Tl;DR, it's not a bug, it's intentional.

soft terrace
#

Thought it might be a old room which got removed. That's why i mentioned it 👌🏽

quaint sparrow
#

Probably best mentioning where you found it.

soft terrace
#

You can read it above

#

With Room, Task etc

quaint sparrow
glad badger
livid escarpBOT
#

Gave +1 Rep to @soft terrace

quaint sparrow
#

@eternal summit

eternal summit
#

-ban @drowsy karma -ddays 1 Secure your account and appeal this ban by emailing bans@tryhackme.com

livid escarpBOT
#

🔨 Banned Ramzan#4526 indefinitely

outer folio
eternal summit
#

Who says those are the same box?

rugged canyon
#

this is not a bug.... the target machine is a different one compared to the image example... the example is there to teach you what to look for... which is something different on the target machine

rugged canyon
#

no problem

chilly crest
#

@gleaming shadow snorlax

solemn sinew
solemn sinew
median coral
#

@gleaming shadow

eternal summit
#

-ban @wispy bramble -ddays 1 Nitro phishing. Secure your account and then appeal this ban by emailing bans@tryhackme.com

livid escarpBOT
#

🔨 Banned Weber#4717 indefinitely

median coral
#

@gleaming shadow

#

@raw bison

raw bison
#

-ban 797851105857765397 -ddays 1 Malicious discord server invites. If account was compromised, change password and add 2FA, then appeal by emailing bans@tryhackme.com

livid escarpBOT
#

🔨 Banned ! L ?#3107 indefinitely

gleaming shadow
#

thanks @raw bison

livid escarpBOT
#

Gave +1 Rep to @raw bison

dusky junco
livid escarpBOT
#

🔨 Banned Stormgod_Zephyrus1603#7904 indefinitely

late pebble
#

Hello, before the , it will be 6 char and after the , it will be 5 char for the answers

eternal summit
livid escarpBOT
#

🔨 Banned aeropop#1919 indefinitely

rugged canyon
#

@queen sphinx ⬆️

eternal summit
livid escarpBOT
#

🔨 Banned aryan7tiwary#7946 indefinitely

rugged canyon
#

maybe it starts from the bottom of the channels list

#

as #voice-chat tends to get the message a few sec before room bugs

eternal summit
#

There's an invite that links to this channel

orchid beacon
#

In the Windows Fundamentals 2 room the question requesting the name of the hidden share answer is sh4r3dF0Ld3r. According to Microsoft documentation a hidden share name requires a $ at the end of the name. So the correct answer should be sh4r3dF0Ld3r$. Is this something that can be fixed?

eternal summit
#

Did you refresh the page to see what the actual stored answer is?

#

Either way, if $ is just an indicator that it's hidden them couldn't you argue it's not part of the name?

orchid beacon
eternal summit
#

Yes but you could argue...

#

But please see my other point about refreshing the page.

orchid beacon
eternal summit
#

Answer tolerance.

rugged canyon
#

the correct answer acording to shadows refersh for said question is without the $

eternal summit
#

It loads the answer from the database, rather than displaying the answer it accepted from you

#

There is tolerance on answers

#

And does the room accept the answer with a dollar sign?

rugged canyon
orchid beacon
eternal summit
#

Is not a hidden share?

#

Also you're just restating your point every time...

orchid beacon
orchid beacon
eternal summit
orchid beacon
eternal summit
orchid beacon
eternal summit
#

-mute @orchid beacon Please adjust your attitude in this discord. Your attitude towards volunteers here is not acceptable

livid escarpBOT
#

🔇 Muted Sm1ley#8105 for 1 day

hazy tiger
eternal summit
livid escarpBOT
#

🔨 Banned Khalid.#8605 indefinitely

glad badger
willow wave
#

Hi, seems there's a bug in Zeek room

#

fatal error when trying to investigate TASK-5 http.pcap

#

same when trying to investigate the ftp.pcap

#

Zeek signatures topic

tame karma
#

In the new Follina room, I had the room open for like 20 mins. Defender popped up because it detected two infected files on the desktop. The two files are for the task.

tropic flameBOT
worldly thistle
#

@tropic flame the Brainstorm room seems to be broken

worldly thistle
#

the Brainstrom room seems to be broken !! can anyone help me out ??

eternal summit
misty cave
orchid beacon
#

Verify what?

orchid beacon
#

Thank you

livid escarpBOT
#

Gave +1 Rep to @vital vine

glad badger
# orchid beacon

I see what you mean now. The share is not hidden, but the folder that is shared is a hidden folder. 🙂 I'll ask the content developer about this. Perhaps the question to ask is: What is the name of the hidden folder that is shared?

glad badger
# orchid beacon

The question has been updated. Thank you for reporting this. 🙂

livid escarpBOT
#

Gave +1 Rep to @orchid beacon

wheat fractal
#

I think there is a small typo in room CTF Collection Vol. 2 in Easter 15 hint

livid escarpBOT
#

Gave +1 Rep to @glad badger

tame karma
sinful crystal
#

Not sure if this is the right channel to report this but I made a typo in the room "fileinc" yet the answer was accepted.

eternal summit
sinful crystal
#

Alright 🙂

raw bison
#

It says "does not have the format" ?

median coral
solemn sinew
#

omfg

#

sorry guys

misty cave
strong kelp
glad badger
livid escarpBOT
#

Gave +1 Rep to @strong kelp

strong kelp
#

in some of them was fixed. I only realized it was unintended after i checked the writeups

stoic vigil
#

Hello hello,
Been doing the https://tryhackme.com/room/postexploit room and got to the part of bloodhound enumeration. When i load the sharphound zip into Bloodhound however, i get a bad Json message.
My college had the same experience, is this a shortcoming on our end or a bug?

rugged canyon
stoic vigil
rugged canyon
stoic vigil
#

I see, I hope a staff member sees this 😇

rugged canyon
#

think the attackbox might still work if you use that though

stoic vigil
rugged canyon
#

oh okay then that is kinda bad

#

yeah setting up your own virtual machine with bloodhound and trying multiple versions will take a while

shrewd quiver
#

Hi, I was doing windows internals room in which windows api room was linked for further information, however when I open that it says private room. Is there someway this room can be brought back together? Thanks!

rugged canyon
shrewd quiver
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

no idea

#

still the link to that room should probably not be there before the room is done

shrewd quiver
#

Also, as a suggestion, could in development rooms could be marked as such?

rugged canyon
#

¯_(ツ)_/¯

#

shadow is not thm staff so they can do very little about this

shrewd quiver
shrewd quiver
#

Thanks for the help though

rugged canyon
#

no problem

#

lets hope someone from thm staff sees this and can make changes

rugged canyon
livid escarpBOT
#

Gave +1 Rep to @shrewd quiver

stoic vigil
glad badger
stoic vigil
glad badger
stoic vigil
livid escarpBOT
#

Gave +1 Rep to @glad badger

proper harness
#

Not sure if it's an error but in this question (Windows fundamentals 3 task 5 about firewalls) the question ask for profile (in the text of the task too ) but the hint and the answer are with network instead of profile

eternal summit
proper harness
#

ty

stoic vigil
#

So about the Post-Exploitation Room, Sharphound is version3 and Bloodhound on attackbox is 4. The shortest path for me, was downloading the Bloodhound 3.5 Verison from official GitHub and run it straight after unzipping with Bloodhound --No-Sandbox.

thick hound
#

Hii, I think I found a bug in "Burp Suite: The Basics" Task 2. But it could occur in other tasks as well... When I answer the questions it only checks for the first 20 characters of the answer...

slim loom
#

I'm typing in the correct answer for the File Inclusion room, Task 5, Question 1, but I get no response from the site at all when clicking submit. I'm completely confused as to why?

rugged canyon
#

then hit ctrl + F5

#

then try again

#

happens sometimes that the pages stop responding to answers of questions

#

dunno why

slim loom
#

Still not giving a response. I tried restarting the room as well... Funny thing is, when I take my answer out and click Submit then the page responds as incorrect

slim loom
fleet scarab
#

I have been trying to get to the target host from my kali attack box for OWASP Top 10 Task 7 and while I was able to get to the hosted evilshell page when I try to browse to port 8888 I get an unable to connect error. I tried this from my raspberry pi connected with openvpn and ran into the same error

#

Don't know if I am just missing something, screwing something up, or if there really is something bugged

eternal summit
muted nimbus
#

In the OWASP top 10 room, in task 14 about XXE, there is an error with formatting. the room is meant to highlight a word with the code tags but highlights the wrong one.

#

In the last point on the list, the word "element" is highlighted, when the preceding word "body" should be highlighted

glad badger
livid escarpBOT
#

Gave +1 Rep to @muted nimbus

muted nimbus
livid escarpBOT
#

Gave +1 Rep to @vital vine

misty cave
#

I'm having a look at it 🙂

misty cave
#

Muiri's added the following 🙂 @slender gulch thanks for bringing it up

livid escarpBOT
#

Gave +1 Rep to @vital vine

misty cave
#

Ok robocop, i'll be back in like, 5 minutes 😄 you both deserve rep

livid escarpBOT
#

Gave +1 Rep to @misty cave

keen shore
#

Hello, furthernmap room's task 14 has a bug, the server does not let me scan its ports; it works with neither of sN, sF, sX flags
nmap's error:

Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.12 seconds
quaint sparrow
#

Did you add -Pn?

obsidian kiln
#

The note from Nmap quite literally also provides the solution

keen shore
#

@quaint sparrow @obsidian kiln Thanks for the responses, I was using the -Pn flag inappropriately.

livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

quaint bone
#

Hopefully an admin sees this and can update the room but I was going through the post-exploitation basics room (https://tryhackme.com/room/postexploit) and SharpHound is older than the bloodhound version that you're instructed to install. Can someone please update the bloodhound install instructions to download from here instead of through apt? This version worked great. https://github.com/BloodHoundAD/BloodHound/releases/tag/3.0.5

GitHub

This release fixes compatiblity with Neo4j 4.1 and fixes several bugs

Updated search query to be significantly faster
Fixed some prebuilt queries and renamed others
Populate raw query when using t...

raw bison
#

-ban 830080738913157140 -ddays 1 Nitro scam link. If account was compromised, change password and add 2FA, then appeal by emailing bans@tryhackme.com

livid escarpBOT
#

🔨 Banned Kuv32#8778 indefinitely

lyric walrus
#

Hello

#

i wanted to report that musicalstego room cannot be completed as the github page you need to access no longer exists

misty cave
tame karma
#

Hello, there is a typo in the Intro to Anti-Virus room. In Task 7, under C# Fingerprints, there is a sentence that starts with "Then, if it complied correctly..." It should be compiled, not complied.

wheat fractal
#

room " Linux PrivEsc " ssh to machine dont work

#

i terminate the machine re open it and same problem , i even killed openvpn and connected again and still

#

nmap machine ssh working on port 22 just to triple check everything

wheat fractal
peak carbon
#

Hello everyone sorry for bothering but have had instances where I Inputted the correct answer but it the website won’t pass it as correct check online to see if I’m wrong but to find out I’m not, have anyone here experience any thing similar ? Please ?

median coral
peak carbon
#

Okay sir @median coral

eternal summit
woeful cliff
rugged canyon
#

oh huh so it still links to that room even though it was made private over 6 months ago???

rugged canyon
#

shadow can do nothing about it as they are not thm staff but yeah weird it is still linked

woeful cliff
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
glad badger
glad badger
livid escarpBOT
#

Gave +1 Rep to @woeful cliff

woeful cliff
livid escarpBOT
#

Gave +1 Rep to @glad badger

rugged canyon
livid escarpBOT
#

Gave +1 Rep to @eternal summit

old birch
#

Hi, new here & working in the Vulnversity room. Where do I locate the ip add for the nmap scan. The only one I can find is for my Kali machine after my machine in step 1.

peak carbon
#

Hello everyone, I’m trying to work on THM from my own personal virtual box but I’m not able to ping or even scan my victim IP? Is there something I’m missing or THM IP”s just don’t work with any other machine apart from THM machine ?

quaint sparrow
#

Are you on VPN?

wary iris
#

Under the hacktivities?page=v3&tab=practice page for Pentesting Tools it isn't giving the green check marks for the completed rooms.

quaint sparrow
#

And the new ones don't count towards the badge yet.

wary iris
#

Ok like the Metasploit modules I have completed all those and received my badge

rotund birch
#

Hello! In this room: https://tryhackme.com/room/linuxagency I can just use pwnkit and bypass all the other lateral privilege escalations

quaint sparrow
rotund birch
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

marsh gazelle
#

Hi, I think I found a mistake in the Osquery room

#

the "correct" answer that I had to type in Task 5 is "select username from users where username like '%en';"

#

but I tried the same thing on the attached machine with the only difference being '%or' instead of '%en'

#

and I retrieved the "Administrator" username, therefore this syntax does not limit the username to 3 characters long as the question demands

#

I did achieve the wanted result tho with adding "and length(name) = 3" to the query

#

and that was incorrect as my answer wasn't accepted

#

any thoughts?

placid abyss
#

And actully do it the way that was intended by the room author

misty cave
marsh gazelle
#

yea but it also says "where the username is 3 characters long"

quaint sparrow
quaint sparrow
marsh gazelle
#

and now it shows that my answer really was with '_en'

#

is there any chance it altered my answer after accepting it or am I tripping?

misty cave
#

(no point saving and loading all the almost there but not quite long answers)

marsh gazelle
#

Oh that's cool, even though I still disagree with it but I guess that's up to the room creator

#

thanks 🙂

wheat fractal
wise abyss
#

In the section What the Shell? under *msfvenom *of the Complete Beginner learning path there is a link to the welcome room (https://tryhackme.com/room/welcome). However the room is private. I am guessing that the room has been replaced by a newer room and the link needs to be updated.

wheat fractal
twin bay
#

Room: androidhacking101
Task: 3

The typo is literally underlined in the screenshot

#

Might need a minor grammar pass as well (Following screenshot from Task 4)

glad badger
livid escarpBOT
#

Gave +1 Rep to @winter turret

amber valley
#

So Im trying to do the PenTesting Tools series but the Metasploit and Burp Suite rooms aren’t being cleared after i finished them

#

has anyone else had this problem or am I just being dumb about it

rugged canyon
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

no problem

ancient bramble
wheat fractal
#

I can't ping any of the entries in my /etc/hosts file (except for the localhost) someone please helpp.

wheat fractal
eternal summit
#

This isn't a room bug

wheat fractal
eternal summit
wheat fractal
livid escarpBOT
#

Gave +1 Rep to @eternal summit

wheat fractal
#

Hi I am in OWASP Juice Shop task 7 q 3 I have completed the URL, refresh the page and I don't get any alert saying XSS. I don't understand what's wrong... Please some help
Is it a bug?

silver dust
livid escarpBOT
#

Gave +1 Rep to @silver dust

silver dust
#

👍

umbral basin
#

In the Splunk 101 room, for Task 6 Sigma Rules, I had an issue with apostraphe and quotes at the end of the first question, and the github repo .yml changed for the second question, event ID was removed in commit history, and splunk query translation changes. Used a walkthrough for the second question.

rocky osprey
#

In the Wireshark 101 room, Task 12 HTTPS Traffic in Practical HTTPS Packet Analysis there is a line - "Let's take a closer look at one of the encrypted requests: Packet 11."
when i opened packet 11 i noticed the photo is not same as the packet details.
The photo in the room is Packet 36.
i think that should be fixed.

tough saddle
#

the machine doesn't have msfvenom like it should

#

on Task 10

tough saddle
#

and also apparently john isn't install either

#

jtr

solemn sinew
tough saddle
#

ah mb i'm just an idiot

solemn sinew
#

and what task that john isn't install?

wheat fractal
#

Feel like there is a bug or outdated answer in the room: Passive Reconnaissance, task 6 question 3. The question is:

Based on Shodan.io, what is the 3rd most common port used for nginx?

The answer found at shodan is not the correct answer

#

You can see that the 3rd most common port is 5000, but this is not valid.

quaint sparrow
#

That's because it's still working from apache search.

flint folio
#

the OWASP Juice Shop, task 8 questions are completely bugged. the flags doesn't appear even when clicking in the panels in the "score-board"

#

even deleting cookies and site data can't make the flags appear

flint folio
#

is there a way to see the flags?

#

seems the only way to get the flags is terminating the attack box and target machines after each solved question

sinful crystal
#

in the room attacktivedirectory at task 4 i can't get it to work, even if I follow a writeup to the letter. using the list of usernames I get 0 matches

quaint sparrow
sinful crystal
#

The list of usernames found in the room. I found that there are two versions on GitHub, neither worked

rotund burrow
#

In the Burp Suite: The Basics room there is a link in Task 10 to the portswinger cert that doesn't work, the old one from the old burp suite room works. I hope i'm not wrong and they are different certs but if possible maybe somebody could check.

https://tryhackme.com/room/burpsuitebasics

This is the link from the new room:
http://burp/cert

And this is from the old one that works:
http://localhost:8080

tulip basalt
#

dunno if this is technically a bug or not?
LST Room V2 VM
-Task 3 Question 3 has a different answer than the ``** ** ***** ********` would lead to believe, intentional misdirection?

#

Hmm. Indeed. ok fair enough, thanks

livid escarpBOT
#

Gave +1 Rep to @vital vine

faint pumice
#

Hey folks I'm on the first tutorial https://tryhackme.com/room/tutorial# and there is no ipaddress anywhere on this page that produces any http response as far as I can see. No red box at the top for example. The IP of my 'attack box' is not the IP its looking for and If I press start machine it only starts hte attack box but if i press it again it says I can only have a maximum of 3 machines open

#

How do I close/shutdown machines that I'm not using ?

#

Thanks for the help @vital vine

livid escarpBOT
#

Gave +1 Rep to @vital vine

obsidian kiln
#

Bear in mind that the URL http://burp is (obviously) not gonna work if you're not connected to the proxy...

rotund burrow
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

rotund burrow
#

The link from the old room works but only if you are connected to the vpn and with burpsuite open, the new one doesn't load the page regardless of the vpn and burp being open...

obsidian kiln
rotund burrow
rotund burrow
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

obsidian kiln
#

Np 🙂
The http://burp shortcut can only work if the proxy is capturing your traffic. Accessing it directly is a lot less clean, but obviously works

rotund burrow
#

It actually specifies in Task 9 also all these steps that i didn't notice until now, i've finished the old room and got used to that

rotund burrow
tame karma
#

In SSDLC, Task 4, there is a minor typo. The post says "GDRP." It should say "GDPR"

misty cave
#

Fixed, nice catch, that got past a lot of us 😄

hazy tiger
#

-ban 797435969996587030 -ddays 1 nitro scam

livid escarpBOT
#

🔨 Banned Tonymontana#4963 indefinitely

stoic vigil
#

Hello hello my dears,

So I just completed the CompTIA Pentest+ path and upon completion you get a voucher of 10%, that is stated to be valid until end of 2021. Just thought I'd let you know.

misty cave
stoic vigil
#

I still have the student offer, but I thought I Would let you know the text is wrong 😄

wet fable
#

anyone know why this happens on annie V2 room?

#

Just closes again instantly

#

ofc with my own shellcode + ip

misty cave
#

Looks to have a msfvenom shellcode in it.

misty cave
wet fable
#

But I'll try

misty cave
wheat fractal
#

this may be a site bug, idrk

misty cave
# wheat fractal

Looks like that room was retired, I'll remove the link, thanks

livid escarpBOT
#

Gave +1 Rep to @midnight sand

wheat fractal
misty cave
# wheat fractal Ohh, why do rooms retire?

Generally because they're old 😅 but it can also be because the content is outdated, doesn't match quality guidelines, and is unpopular. It may also be because a newer version is more applicable

plucky cave
glad badger
#

I ran nikto -h TARGET_IP and nikto -h TARGET_IP -p 8080 -Display 2 and did not crash so far. 🙂

winged hearth
#

hi guys !
just a thing about this room : https://tryhackme.com/room/rpnessusredux
it seems that from the last nessus version, the plugin id for the question What is the plugin id of the plugin that determines the HTTP server type and version? have changed . I'm right ?

#

i'm running nessus 10.3.0

plucky cave
#

The icy MP responses stop

flint folio
#

in the Web Enumeration room, in the last task (task 13 - conclusion), there is a room called RPWebScanning that was made private, so we cannot access it, but it's still recommended and there is a link to the room

plucky cave
#

...again with a new instance

eternal summit
#

!vpnscript

tropic flameBOT
plucky cave
#

nope ... just the single THM vpn connected

#

The rest of web enumeration and the vm's worked absolutely fine

glad badger
plucky cave
livid escarpBOT
#

Gave +1 Rep to @glad badger

solemn sinew
#

@eternal summit if u still around

eternal summit
#

-ban @nocturne needle -ddays 1 Nitro phishing. Secure your account and then appeal this ban by emailling bans@tryhackme.com

livid escarpBOT
#

🔨 Banned vn._creations#4353 indefinitely

eternal summit
#

@solemn sinew Thank you

livid escarpBOT
#

Gave +1 Rep to @solemn sinew

onyx tangle
#

hi

#

the is a room bug in try hack me linux fundamentals part 1

rapid lodge
#

im busy with uploadvulns and on magic.uploadvulns.thm i get internal server error 500, i tried many different things and i can't seem to complete it. i started googling and found some other people who finished it it followed 2 different people there solution step by step multiple times and it doesnt work. the times i don't receive the 500 error it still say submit=failure

misty cave
rapid lodge
livid escarpBOT
#

Gave +1 Rep to @misty cave

rapid lodge
#

im trying to do the pickle rick challenge room but i have tried on 4 different machine's by now and time and time again i lose connection to the server, even my active webpage which i was not even browsing atm just had the page open dissapeared. my gobuster scan worked a few minutes but same time my page dissapeared it started timeout exceeded retreiving headers. im pretty sure the problems ain't on my end. i really want to complete this today since its the last challenge for your certificate

quaint sparrow
rapid lodge
#

im on a vm as always

quaint sparrow
#

Type ip a

#

And count the number of tun* you have.

rapid lodge
quaint sparrow
#

Then type

#

sudo killall openvpn

quaint sparrow
#

Then do Ip a again.

rapid lodge
#

i restored back 1 vpn gimme a minute to see if the error persists

quaint sparrow
#

It shouldn't do.

rapid lodge
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

quaint sparrow
#

Happy hacking!

opaque wharf
#

good news guys i solved the big mystery

opaque wharf
#

wdym

eternal summit
#

It's not... You just need to add it to your hosts file.

#

The THM labs address is totally different...

opaque wharf
#

i remember one of these room i solved like that

#

hold on im gonna try that

eternal summit
opaque wharf
#

can i upload image here

opaque wharf
livid escarpBOT
#

Gave +1 Rep to @eternal summit

opaque wharf
#

i dunno how but mines works too 😄

wheat fractal
#

hello, the room Crash Course Pentesting is not free anymore i think can anyone confirm it for me please.

opaque wharf
wheat fractal
#

it does not work

wheat fractal
#

yes

quaint sparrow
#

The room is private on purpose.

quaint sparrow
# wheat fractal yes

The room has been marked retired.

You should post the room where you found link so site staff can remove it.

wheat fractal
#

okey

wheat fractal
eternal summit
wheat fractal
#

so I have to ask the permission of the one who created the room?

eternal summit
#

No, it's retired. There's plenty of content to replace it.

wheat fractal
#

I got a bug with vulnnet:roasted. Came back from lunch break and the vm is still up.

Terminating it and then refreshing the page will say its still up. No way to shut it down. Anyone knows a solution for this?

If u go to the url to see what active target vm's are running. It's says even i started it at 6 am. Seem's weird i started on this specific room at 10 am.

misty cave
livid escarpBOT
#

Gave +1 Rep to @misty cave

rugged canyon
#

which gives another ip as the answer

#

namely: ||10.10.57.178||

sonic willow
rugged canyon
#

oooh that is a good catch

sonic willow
#

looking at just the destination address, ||10.100.1.33|| is still more frequent than ||10.10.57.178|| though

rugged canyon
livid escarpBOT
#

Gave +1 Rep to @sonic willow

clever pecan
#

on my kali box it says

_─_ nslookup thmdc.za.tryhackme.com


;; Got recursion not available from 10.200.71.101, trying next server
Server:         1.1.1.1
Address:        1.1.1.1#53

** server can't find thmdc.za.tryhackme.com: NXDOMAIN

#

No

#

from attackbox

#

on the other hand i tested with breaching AD it is working just fine

#

ik first i tried it on my box then attackbox

#

it's been 4 hours but not enough votes so i can't reset it

#

okay thank you

candid garden
#

Dunno if this is intentional or not

rugged canyon
#

i.e you can typo the answer slightly on some tasks and it will get accepted as correct

candid garden
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

just reload the page and it will correct itself to the real answer

candid garden
#

I'm too tired to learn stuff rn so I m revising things I already know haha

rugged canyon
#

thats fair.... enjoy segmenting knowledge better into your brain

misty cave
quick depot
#

I found error in WbeOsint room of tryhackme

#

In it's second task 3rd question What is the first nameserver listed for the site?

#

I did whois and it showed me this

#

But this is wrong when we specify it as answer

#

when I looked walkthrough it showed me this

#

Now I would be finding whole day if I would had not watched walkthrough.

dusky junco
# quick depot

ahh yes this is a problem with the much older content on THM. I've updated the answer in the room so that it now expects || ns1.brainydns.com|| (: ty

livid escarpBOT
#

Gave +1 Rep to @quick depot

frigid plover
#

https://tryhackme.com/room/dailybugle
First question is "wrong"
If you copy paste the answer directly from the box, you get "Incorrect answer", you need to remove the - before it's excepted.

vague ruin
#

the site in the room upload vulnerabilities is not working

quaint sparrow
#

Did you add the site to your hosts file?

eternal summit
quaint sparrow
eternal summit
#

They weren't specific about what they needed. In this case, it's help rather than reporting a bug

quaint sparrow
#

Nah, that's true.

quick depot
#

we need to write answer and in it we will write liquid web, l.l.c

#

but when we do IP History it has record of liquid web it does not specify l.l.c

#

and in walkthrough it has l.l.c record

sonic willow
#

another reason why questions based on public information should be about the process rather than the answer

tame karma
livid escarpBOT
#

Gave +1 Rep to @misty cave

faint zodiac
#

A room / dependency probleem bug in easyctf : the required exploit script is a python2 script. Fixing and migrating the script is a bit out of scope for a easy room (in my eyes) and getting to run a python 2 script with python2 and pip2 etc is a sort of knowledge I wouldn't require for a easy room. Maybe add a little text blob explaining that python2 python3 part

misty cave
faint zodiac
#

Just bumped the difficulty a bit above beginners.

misty cave
faint zodiac
#

@misty cave thanks Also as a General Feedback from running a course with 30 students right now maybe having maybe a beginner tier or something like that where these kind of roadblocks are not there. Some easy rooms have a easy First exploit but a hard second stage.

livid escarpBOT
#

Gave +1 Rep to @misty cave

hazy tiger
#

-ban 740987583584010402 -ddays 1 scam

livid escarpBOT
#

🔨 Banned DarkHawk#4392 indefinitely

wheat fractal
#

oof

rapid lodge
#

hello again, im trying to complete eternalblue room and in the 2nd part i need to get the vulnerable exploit running. i tried a few times since it was telling me i probably need to restart my machine a few times. so i did but i keep restarting and the run/exploit cmd keeps failing. i even used the video to see if its correct what im doing. and it was correct. so now im clueless.

#

lhost is set

#

10.0.2.15

#

should it be my thm ip?

#

tyvm

fallen wraith
#

Re: #room-bugs message
The https://tryhackme.com/room/encryptioncrypto101 is still referring to the private room (CC Pentesting is the hyperlink to the private room)

Note: This room expects some familiarity with tools, and some research into how to use them yourself!
I recommend completing CC Pentesting first for some familiarity with John The Ripper.

misty cave
fallen wraith
misty cave
#

It's James' room, so figured I'd take a peek and it looks like he's not a fan of that room #room-bugs message

raw bison
#

-ban 850070964669775943 -ddays 1 Nitro scam link. If account was compromised, change password and add 2FA, then appeal by emailing bans@tryhackme.com

livid escarpBOT
#

🔨 Banned Massi#5183 indefinitely

tame karma
#

I know this is old, but the room is up!

quaint sparrow
brazen dagger
#

Just started TryHackMe and am on the Vulnversity box. Task 4 asks me to try upload a few filetypes to the server. It asks "what common extension seems to be blocked?" I just made new empty files and named them test.txt, test.exe, test.pdf, etc. All of them were disallowed it seems? I eventually found out the answer from the walkthrough, but when I tested it it gave me the same response as all the other types did. Anyone else had this happen?

eternal summit
#

It's "what common file type, which you'd want to upload to exploit the server, is blocked?" really

signal cairn
#

"Intro to ISAC" room Task 8. I got a Windows Activation Error when I RDP to the VM

livid escarpBOT
#

Gave +1 Rep to @signal cairn

uncut cairn
#

"Introduction to Web Hacking"
"Content Discovery"
Task 3 "Manual Discovery - Favicon"

All of this exercise has been updated except the answer that is asked to be provided.
The md5 hash value that we are given is d41d8cd98f00b204e9800998ecf8427e which is related to Zero byte favicon
The answer that is currently accepted is cgiirc

misty cave
uncut cairn
#

Oh my bad then, I'm going to retry

misty cave
uncut cairn
#

subscriber

misty cave
#

Ok, I'll put a note in there for that.

misty cave
uncut cairn
#

I did it again and you were right, I found the correct result. Do you want me to delete my messages?

misty cave
# uncut cairn I did it again and you were right, I found the correct result. Do you want me to...

Nah, it's all good, it means people who search can find the thing 🙂

I've added the following to the task Note: This curl will fail on the Attackbox if you are a free user, in which case you should use a VM for this. If your hash ends with 427e then your curl failed, and you may need to try it again. ( @vital vine that should cut down on how many of those questions need to be fielded 🙂 )

uncut cairn
#

Alright thank you

misty cave
#

i tried that, but my windows powershell Doesn't like making it a oneliner...

#

oooh, wget https://static-labs.tryhackme.cloud/sites/favicon/images/favicon.ico -UseBasicParsing -o favicon.ico ; Get-FileHash .\favicon.ico -Algorithm MD5 works

#

curl and wget are both just aliases for Invoke-WebRequest in PS

elfin field
#

Crack The Hash Level 2 is broken Haiti is a broken tool.

#

It is for me lol

#

└──╼ $./haiti 741ebf5166b9ece4cca88a3868c44871e8370707cf19af3ceaa4a6fba006f224ae03f39153492853
Traceback (most recent call last):
2: from ./haiti:7:in <main>'
1: from /usr/lib/ruby/vendor_ruby/rubygems/core_ext/kernel_require.rb:85:in require'
/usr/lib/ruby/vendor_ruby/rubygems/core_ext/kernel_require.rb:85:in `require': cannot load such file -- haiti (LoadError)

#

Well....... it's not a user issue..... more like an issue with a poorly documented tool.

#

Huh......

#

How do you even install it......

#

lol

#

There is a binary file in there........

misty cave
#

Added the Powershell instructions

elfin field
#

Oh hahaha

livid escarpBOT
#

Gave +1 Rep to @misty cave

elfin field
#

I ran the gem install haiti-hash command wrong earlier

#

Thanks @vital vine

livid escarpBOT
#

Gave +1 Rep to @vital vine

misty cave
#

I wanted to make the powershell window a different colour, but couldn't find a room where someone did that...

#

I know i've seen it though

cinder moth
#

In the Metasploit:Exploitation room, my machine from task 6 always kind of resets when I switch back to my kali atack machine. All my previous commands are gone, my root and most importantly, my reverse shell is killed. But the file I downloaded to it stays.

raw bison
cinder moth
cinder moth
raw bison
elfin field
#

Hi all......

#

I think there is a bug with the Crack The Hash Level 2 room........

#

I'm working on task 5 question one and i get the following error after running the command in the instructions;

#

└──╼ $python3 wordlistctl.py fetch -l dogs -d
--==[ wordlistctl by blackarch.org ]==--

usage: wordlistctl fetch [-h] [-l WORDLIST [WORDLIST ...]]
[-g {usernames,passwords,discovery,fuzzing,misc} [{usernames,passwords,discovery,fuzzing,misc} ...]]
[-b BASEDIR] [-d] [-w WORKERS] [-u USERAGENT]
fetch_term
wordlistctl fetch: error: the following arguments are required: fetch_term

elfin field
#

That's exactly how the room instructs people to complete the question by entering this command;
└──╼ $python3 wordlistctl.py fetch -l dogs -d

#

Right.......

#

Well......

#

I guess the room instructions might benefit from being updated.

misty cave
elfin field
#

@misty cave No...... I'm not aware of what the correct command is right now i've switched to a different machine.

misty cave
elfin field
#

@misty cave Oh no that's alright..... So....... Is it your machine ?

misty cave
elfin field
#

@misty cave Oh i see......

#

+rep

livid escarpBOT
#

Gave +1 Rep to @misty cave

vital pilot
#

Not really a bug, rather a nuisance: introlan/task3 wants "adress" in 2 answers and "address" in the last answer. I was expecting it to be spelled consistently. The tasks use "address", as does the tooltip for ARP.

eternal summit
vital pilot
vital pilot
eternal summit
vital pilot
eternal summit
#

You can reset the whole room to answer again

#

Not much point though

hot spear
misty cave
smoky musk
#

frustrated with the file inclusion room. I already finished task two and was on three and I wasn’t getting the web server response I thought I should have gotten. I went back to step 2 and sure enough, it wasn't working now. Again, I already was able to close that step. Now, instead of getting /etc/paswwd I am getting an error page with an Apache response saying server is on 8080. Port 8080 isnt even open.

#

i let the room time out. came back and hour and a half later with a new target IP. Same bugs

#

Frustrated. I am just going to a different room. I guess I'll practice this at Portswigger academy.

rugged canyon
#

@hazy tiger ⬆️

hazy tiger
#

-ban 651696071382401024 -ddays 1 Scam

livid escarpBOT
#

🔨 Banned AP XD#3960 indefinitely

rugged canyon
#

thank you @hazy tiger

livid escarpBOT
#

Gave +1 Rep to @hazy tiger

brazen dagger
#

Task 14 asks "Does the target (10.10.92.96)respond to ICMP (ping) requests (Y/N)?"
It marks "N" as the correct answer

#

But nmap -sn 10.10.92.96 returns the following output:

Starting Nmap 7.60 ( https://nmap.org ) at 2022-08-29 02:14 BST
Nmap scan report for ip-10-10-92-96.eu-west-1.compute.internal (10.10.92.96)
Host is up (0.00011s latency).
MAC Address: 02:95:65:C5:F5:E7 (Unknown)
Nmap done: 1 IP address (1 host up) scanned in 0.26 seconds
#

I am a subscriber and am using the Attackbox, which has IP 10.10.154.135

brazen dagger
#

Oh my goodness I am a fool. Thank you

#

Out of interest, is nmap doing it with an ARP scan here?

dense garnet
thick stone
#

Hi, this isn't a bug but i think there is a little mistake in room "Protocols and Servers" Task 6.
The second question asks how many emails a user can download with IMAP. That do make sense, but as it is the pop3 task, I guess it should be pop3 insted of IMAP.

misty cave
misty cave
misty cave
earnest patio
sharp citrus
fluid pelican
misty cave
molten flare
#

https://tryhackme.com/room/uploadvulns - starting in task 5 (remote code execution) I'm having an issue where when I go to upload anything, be it a jpeg/png/shell/etc, it will show the file but when I hit the button to upload, nothing happens and it refreshes. I'll then check the /resources and it shows that nothing got uploaded. Thought it might have been me, so I skipped down to task 7 (bypassing client-side filtering) and ran into the same issue. It'll show that I either selected a png or not, but will never actually let it upload. I've tried using both Kali linux and attack box and both gave same issues. Also verified my /etc/hosts file was set up correctly per the instructions given.

misty cave
molten flare
misty cave
molten flare
flat socket
#

Thanks haha, I forgot about that

livid escarpBOT
#

Gave +1 Rep to @vital vine

dusky remnant
#

In Wireshark 101, Task 7, there is a grammatical error under ARP Traffic overview under the first image.

"The Opcode is short for operation code and will you tell you whether it is an ARP Request or Reply."

misty cave
livid escarpBOT
#

Gave +1 Rep to @dusky remnant

solemn sinew
#

Room: Year of the fox
Link: https://tryhackme.com/room/yotf
Issue: When I try to forward port 22 to other port to be accessible from outside (read multiple writeup and they use same method), I get this error
My Command: ./socat tcp-listen:1234,reuseaddr,fork tcp:localhost:22

I tried to download it from my machine but add the path but still doesn't work

tacit sky
#

Room: Sysinternals
Links: https://tryhackme.com/room/btsysinternalssg
Issue: Task 3 states that you should be able to change the advanced sharing settings so that you can access a network drive. However, the THM virtual machine has been configured to not allow this setting to be changed, meaning you cannot complete sections of this room

#

I have found numerous bugs within the SecOps and Monitoring section of Cyber Defense, I will document as many as I can remember

#

Room: Sysmon
Links: https://tryhackme.com/room/sysmon
Issue: From what I understand, the room is supposed to create a virtual machine which contains Sysmon and the configuration files. However, the the room instead creates a headless virtual machine which I have not been able to access using my OpenVPN client.

misty cave
tacit sky
#

I tried rdesktop which I have used during my university degree but that wouldnt connect. But I think rdesktop struggles to connect to THM virtual machines

misty cave
misty cave
tacit sky
#

I have used Remmina before, but my main issue was that the remote desktop was a small 4:3 interface, making it unusable. I'll try xfreerdp

misty cave
misty cave
livid escarpBOT
#

Gave +1 Rep to @tacit sky

primal shore
#

Room: OWASP Top 10
Link: https://tryhackme.com/room/owasptop10
Issue: Task 25 wants you to change the cookie value for "userType" from "user" to "admin" in order to access the /admin page on the website. However even without changing this value, the /admin page seems accessible

obsidian kiln
#

TL;DR: not a bug

solemn sinew
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

obsidian kiln
tacit sky
#

Room: Osquery
Link: https://tryhackme.com/room/osqueryf8
Issue: For task 3, the answers for the first 2 questions are out of date. I had to look up walkthroughs online to get these answers. Osquery has been updated a few times, so these answers will need updating. There are similar issues with Task 4 questions 3 thru 5

wheat fractal
#

hi there ! i got stuck in hydra lab because the site which gonna be cracked is not displaying

#

i checked my proxy and the firewall but i didn't find anything

#

need help please

raw bison
wheat fractal
#

i will try it thanks anyway

tacit sky
#

Room: Osquery
Link: https://tryhackme.com/room/osqueryf8
Issue: Task 9 requires you to load an extension called "plgx_win_extension.ext.exe". When you use the recommended command, the extension cannot load because the "Extension binary doesn't exist"
Command from room: osqueryi --allow-unsafe --extension "C:\Program Files\osquery\extensions\osq-ext-bin\plgx_win_extension.ext.exe"
Error being thrown: Extension binary doesn't exist in: /home/tryhackme/C:\Program Files\osquery\extensions\osq-ext-bin\plgx_win_extension.ext.exe

twilit fjord
rugged canyon
twilit fjord
rugged canyon
#

you should leave the port as 50001 or it won't work

#

i.e the port variable in the script needs to be 50001 but the port in the shell code should be the correct port for your msfvenom and handler

twilit fjord
#

as i sad there wouldnt be a callback i allso checked some writeups in case i messed it up but they did the same

rugged canyon
#

heavily doubt the room just broke on itself

#

so try and make a new shellcode and replace it again

twilit fjord
#

yeah whatever others in the forum have the same problem

#

so i just do another room

#

my usual schedule if i get into issues is: do i think i did it right => restart the box => not working => rethink what i did => no solution => restart vm => still not working check forum or writeup. thats what i do before even think of reporting.

rugged canyon
#

yeah wait a sec... going to test it themselves to see if it is broken or just some weirdness with the script for you

twilit fjord
#

thx

rugged canyon
#

works for shadow weirdly enoughs

#
$ nc -lnvp 1234
Listening on 0.0.0.0 1234
Connection received on 10.10.31.198 57690
whoami
annie
id 
uid=1000(annie) gid=1000(annie) groups=1000(annie),24(cdrom),27(sudo),30(dip),46(plugdev),111(lpadmin),112(sambashare)
twilit fjord
#

mmm k

#

thx for the help

#

i try run it from attack box maybe

rugged canyon
#

good luck and hope you can fix it somehow

twilit fjord
#

there are other rooms to have fun with if not

rugged canyon
#

true

#

or if you don't mind shadow can give you the ssh key file and you step up from there

vital pilot
#

linuxfundamentalspart3 / task6

Crontab is one of the processes that is started during boot, which is responsible for facilitating and managing cron jobs.

shouldn't this read as "Cron is one of the processes that is started"? At least, the service is called cron.service. The process also is "cron"

#

linuxfundamentalspart3 / task7

When developers wish to submit software to the community, they will submit it to an "apt" repository.
How about
"to a repository. For Ubuntu (and other Debian based systems) this will be an "apt" repository.

Am I overly pedantic? Is this something to be requested somewhere else or should I just keep ignoring this stuff because you people are getting enough of such requests?

eternal summit
vital pilot
#

Ah, ok. I'll keep this in mind.

twilit fjord
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

no problem

vital pilot
# eternal summit It's beginner content so this might make it more confusing than it already is

Hmm....task 7 also gives some strange instructions which are confusing, at least to me.
It talks about using add-apt-repository to add a new repository,

Let's walk through adding and removing a repository using the add-apt-repository command we illustrated above.

but goes on manually creating and editing a list file.
In the end, it wants to remove the package (sublime in the example) but now uses add-apt-repository to remove a completely unrelated repo (with placeholder syntax) and then removing the package itself.

Is there a way this can be streamlined/cleaned up?

eternal summit
#

It's not something I should be pinged for, discord mods are not site staff

vital pilot
#

Understood.

#

Moving this stuff to the feedback form.

misty cave
misty cave
misty cave
# tacit sky Room: Osquery Link: https://tryhackme.com/room/osqueryf8 Issue: For task 3, the ...

There's no problem with this. I suspect you either haven't launched the machine attached to the room, or have made some other error which you should be able to troubleshoot. I'm going to assume your other bugs for this room also aren't valid.

Please make sure to take these basic troubleshooting steps before jumping to assuming it's a room-bug. In future can you submit screenshots of the issue, and what you've done to try and verify it?

misty cave
#

+rep @vital pilot

livid escarpBOT
#

Gave +1 Rep to @vital pilot

gleaming latch
lavish skiff
#

Adventifcyber2 day 2... without any value for /?id= You can still upload files.

tacit sky
livid escarpBOT
#

Gave +1 Rep to @thick stone

misty cave
livid escarpBOT
#

Gave +1 Rep to @gleaming latch

gleaming latch
lofty delta
#

Hey guys, I'm facing the same problem with room networkservices as this : #room-bugs message

What's the usual way to forward issues to the room creator ?

quaint sparrow
lofty delta
#

Just terminated the machine and started the machine related to task 9, same ftpfinal name

quaint sparrow
#

Ok, let's move over to #room-help as this isn't a bug.

lofty delta
#

How is it not a bug when the answer for question 1 of task 9 is not in line with the results of the scan ? I did find the right answer but it doesn't match the scan results.

quaint sparrow
#

Easy.

#

There is more than one port open on the machine.

lofty delta
#

I don't want to put too much publicly, can I reach out privately ?

quaint sparrow
#

No, public is fine.

misty cave
misty cave
#

@raw bison

raw bison
#

Thanks, just forgot the ddays 1 for that one 🙂

misty cave
livid escarpBOT
#

Gave +1 Rep to @raw bison

quaint sparrow
#

@hazy tiger

eternal summit
#

-ban @rich igloo -ddays 1 Nitro phishing. Please secure your account and then appeal by emailling bans@tryhackme.com

livid escarpBOT
#

🔨 Banned Renren1503#5020 indefinitely

smoky musk
#

I'm doing the RA 2 room and I can not for the life of me to get internal dns resolution working.

wanton oyster
#

Hi, im think there is a mistake in the room of Python Basics: https://tryhackme.com/room/pythonbasics, there is an 'elif' where there should be an 'else'.

hazy tiger
#

Lmao how was that missed

rugged canyon
#

good catch

north folio
sharp citrus
north folio
#

you rock man!

#

thanks

sharp citrus
#

glad to help

broken tiger
#

I'm not sure this is a bug.
In the File Inclusion room Lab #1 does not care which directory layer you use. It always returns the preview content of /etc/passwdas if it's already at the top layer and not at /var/www/html

eternal summit
#

In summary, not a bug

misty cave
livid escarpBOT
#

Gave +1 Rep to @wanton oyster

twin bay
#

Has it above as well

south pebble
#

there's a bug in the answer for the user in task3, 4th answer, of this room https://tryhackme.com/room/networkservices2
it accepted the correct italian word "cappuccino" but the actual user is "cappucino"
I realised after trying several times to ssh into the machine with the wrong username, and I kept referencing the previous answer I gave thinking I was using the correct name

#

oh i didn't know there was any, yea i see the answer has been corrected

tender barn
#

Hi, i facing some trouble with connect to RDP in room Relevant , if this behavior is expected?

#
➜ xfreerdp /u:user /p:pass /v:10.10.213.51:3389
[19:53:16:400] [52494:52495] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[19:53:16:400] [52494:52495] [WARN][com.freerdp.crypto] - CN = Relevant
[19:53:16:401] [52494:52495] [ERROR][com.freerdp.crypto] - @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
[19:53:16:401] [52494:52495] [ERROR][com.freerdp.crypto] - @           WARNING: CERTIFICATE NAME MISMATCH!           @
[19:53:16:401] [52494:52495] [ERROR][com.freerdp.crypto] - @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
[19:53:16:401] [52494:52495] [ERROR][com.freerdp.crypto] - The hostname used for this connection (10.10.213.51:3389) 
[19:53:16:401] [52494:52495] [ERROR][com.freerdp.crypto] - does not match the name given in the certificate:
[19:53:16:401] [52494:52495] [ERROR][com.freerdp.crypto] - Common Name (CN):
[19:53:16:401] [52494:52495] [ERROR][com.freerdp.crypto] -      Relevant
[19:53:16:401] [52494:52495] [ERROR][com.freerdp.crypto] - A valid certificate for the wrong name should NOT be trusted!
Certificate details for 10.10.213.51:3389 (RDP-Server):
        Common Name: Relevant
        Subject:     CN = Relevant
        Issuer:      CN = Relevant
        Thumbprint:  3e:14:a6:a5:5d:ee:bd:65:da:b3:c2:8a:24:3c:15:0c:95:f7:1d:2b:ba:c0:00:08:7b:32:c6:da:98:66:ac:5e
The above X.509 certificate could not be verified, possibly because you do not have
the CA certificate in your certificate store, or the certificate has expired.
Please look at the OpenSSL documentation on how to add a private CA to the store.
Do you trust the above certificate? (Y/T/N) Y

#

[19:53:21:393] [52494:52495] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 104: Connection reset by peer
[19:53:21:393] [52494:52495] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[19:53:24:068] [52494:52495] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 104: Connection reset by peer
[19:53:24:069] [52494:52495] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[19:53:24:069] [52494:52495] [ERROR][com.freerdp.core] - freerdp_post_connect failed
livid escarpBOT
#

Gave +1 Rep to @twin bay

iron furnace
#

Sup fam

misty cave
misty cave
livid escarpBOT
#

Gave +1 Rep to @misty cave

celest igloo
#

I don’t know if it qualifies as a Bug, it’s more a clarification… in the room “Linux PrivEsc” of the #878393611929129000 when I tried to connect with my kali pc via vpn I received the message

“Unable to negotiate with <IP> port 22: no matching how to key type found. Their offer: ssh-rsa, ssh-dss”.

Searching online I was able to find that I should edit the connection command to

ssh -oHostKeyAlgorithms=+ssh-dss user@IP

maybe this indication could be added to the room introduction when it states you should connect to THM VPN to access the VM

quick violet
misty cave
livid escarpBOT
#

Gave +1 Rep to @quick violet

misty cave
tacit sky
#

I am currently working through the splunk 2 room. Task 4 question 4 asks you to use a IP address found in question 2 to search for a URI path. The task suggests using the query index="botsv2" src_ip="IPADDR" and then using the Interesting Fields to filter for URL's. However, the IP address doesn't return any URI paths. Looking into it online, the IP given for question 3 is what the question is actually referring to

#

And this is the specific question

faint token
#

Hey possibly a bug possibly not, for the empline room I am experiencing the site either rejecting all requests after I attempt to enumerate it with Ferox, or occasionally the webserver completely going offline and just timing out to all requests

#

which lasted until I restarted the machine

#

it has happened a couple of times so far

wheat fractal
#

https://tryhackme.com/room/threatinteltools Task5 PhishTool is discussed and mentioned we are shown how to use it. however when loading our virtual machine we don't have that tool installed we have thunderbird mail installed. we have to manually count the hops but all info is there. Also Task 4: Feodo tracker is no longer an active website. Task 6: " Use the .eml file you’ve downloaded in the previous task, PhishTool, to answer the following questions." Typo instead of phishTool I think it meant Talos

wanton oyster
#

Hi, im not sure if there is an error in the second task's script of Python for pentesters. Is an 'f' where there sould be nothing.

#

The first sentence after de 'for sub in subdoms'

misty cave
faint token
#

Oddly enough after posting i also experienced where it would only reject me for certain pages if i stopped the scan early

quick violet
misty cave
quick violet
misty cave
wanton oyster
livid escarpBOT
#

Gave +1 Rep to @eternal summit

obsidian kiln
misty cave
sharp citrus
misty cave
livid escarpBOT
#

Gave +1 Rep to @sharp citrus

obsidian kiln
grizzled briar
#

In the room how websites work under task 2 the last question forgets to ask what the flag/text is.

wheat fractal
#

in the Empire room, Empire doesn't cleanly install on the attackbox using the existing instructions nor does it come preinstalled

sullen flame
#

In Windows Local Persistence, Task 2, last part.
When I change the RID of the user, the account breaks and the RDP session just flashes.
Connecting via WINRM does not work either.
I tried restarting the machine.
The administrator account does not work either after editing the SAM database.

livid escarpBOT
#

Gave +1 Rep to @grizzled briar

misty cave
sharp citrus
#

Not sure if is bug. In the https://tryhackme.com/room/redteamrecon in reacon-ng Task6. In the section Working with Installed Modules all the time we install/work with google_site_web module, and just one time there is line that say to load module that we installed viewdns_reverse_whois. and that is only time is mentioned. Even in demo video there is no part for that viewdns module?

misty cave
sharp citrus
#

is part 6. trough all part is talk of google_site_web. just one paragraph saysLet’s load the module that we installed earlier from the marketplace, modules load viewdns_reverse_whois And just in that paragraph is only time mentioned and we newer installed it as part of task. all the time before and after is just google_site_web module

raw bison
#

Since you already around @misty cave , another minor thing

https://tryhackme.com/room/opsec - Task 3

Who is the adversary is? Guess should be Who is the adversary?

misty cave
livid escarpBOT
#

Gave +1 Rep to @raw bison

candid garden
#

not as much a bug as a writing error
Webenum room / Gobuster 1.3 Practical

You will also need to add "webenum.thm" to your /etc/hosts file to start off with like so:

echo "MACHINE_IP webenum.thm" >> /etc/hosts
This results in the IP getting pasted at the end of /etc/hosts in space which is reserved for IPv6 hosts. That makes it so the domain doesn't get recognized.
(At least on my KaliVM, maybe on the web kali / attackbox it works alr)

naive agate
#

Trying to figure out if this is a bug or I'm doing something wrong. For the Password Attacks room, Task 4, Second Question to generate the list containing THM@!

#

i ran this and it generated it in a list, but it's not accepting it as an answer

misty cave
misty cave
naive agate
ruby olive
#

Splunk 2 room section 400 question 4 is bugged the file name in the answer is ||나는_데이비드를_사랑한다.hwp|| yet it refuses to accept the input......

dawn tapir
#

Hello guys
I face a problem to many times
the problem is when i enter a room most of them don't display the screenshots
This how it looks

misty cave
ruby olive
ruby olive
#

||\u1102\u1161\u1102\u1173\u11ab_\u1103\u1166\u110b\u1175\u1107\u1175\u1103\u1173\u1105\u1173\u11af_\u1109\u1161\u1105\u1161\u11bc\u1112\u1161\u11ab\u1103\u1161.hwp ||

misty cave
misty cave
ruby olive
misty cave
#

+rep @ruby olive for figuring that one out in DM's. Turns out Safari doesn't like the characterset. Hint updated 😄

livid escarpBOT
#

Gave +1 Rep to @ruby olive

ruby olive
#

Woot

rugged canyon
#

oh wow a rare instance of web browser engine causing problems

rugged canyon
#

https://tryhackme.com/room/networkservices2 task 4 explains for you to wget https://github.com/polo-sec/writing/blob/master/Security%20Challenge%20Walkthroughs/Networks%202/bash instead of wget https://github.com/polo-sec/writing/raw/master/Security%20Challenge%20Walkthroughs/Networks%202/bash the first one downloads the web page and not the binary.... the second one uses the raw data link and downloads the bash binary executable

bronze cave
#

And the lines literally right before that link are this:
If you want to download it via the command line, be careful not to download the github page instead of the raw script. You can use
I didn't realize the mistake until the last part of the task and had to restart with a new AttackBox because I somehow couldn't change the file on the target. Good thing @rugged canyon was around so at least I knew the room didn't take it's own advice. 😒

dusty zodiac
#

Runtime Detection Evasion - The room has to be terminated and reloaded for Task 6 to work

dusty zodiac
#

Also, Task 7, the link for the code snippet by BC-Security directs to a 404 page

uneven sonnet
#

at the start of task 4 in https://tryhackme.com/room/introtoc2, there should be a prompt to cd to the /opt folder before getting armitage, since this is where the rest of the commands refer to

ornate axle
#

Same problem. Figure it out?

raw bison
#

No need to ping staff right away, if you think something is a bug, just report it in here.
In fact, it turned out to be no bug 🙂

misty cave
misty cave
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

stoic vigil
#

In the Weaponization room, I can't seem to get cmd.exe to pop up like calc.exe when following the rooms outline. Anyone else had this issue?

#

(task 3)

ornate axle
livid escarpBOT
#

Gave +1 Rep to @raw bison

sinful crystal
#

Not strictly a bug but I noticed that the attackbox won't work as designed in the room "post-exploitation basics". The installed version of bloodhound won't read the zip from sharphound. I grabbed version 3.0.2 from GitHub and ran that instead, which works

oblique mural
#

Did you find a solution to this

signal citrus
#

OPSEC - Task 7 is very confusing . i think you need to be more clear in question what is needed and also the hint it self is confusing. e.x. no need to put "" 😵‍💫

quaint sparrow
#

They are redesigning that part.

signal citrus
rugged canyon
#

according to robert it is not getting fixed any time soon

sullen flame
#

Is Evading Logging and Monitoring, Task 10 bugged or am I doing something wrong?

#

I've followed the guide but it still says binary leaked..

sullen flame
#

now it just gets stuck like this:

misty cave
misty cave
quaint sparrow
#

When you least expect it 🙂

quaint sparrow
misty cave
quaint sparrow
misty cave
quaint sparrow
misty cave
quaint sparrow
wheat fractal
#

Task 4: We are told that we should see a data entry that will lead us to shadowban.eu however nothing pops up anymore and I was able to find the link from a right up and that link is dead so we end up with no way of finding the value of the search

misty cave
lime pumice
#

Not sure if this belongs here, but i'll give it a try.
In the Red Team Learning Path, in the Sandbox Evasion Room, Task 4. I guess there is the wrong code snippet within the text :). The first code snippet in this task should be a sleep function to evade sandbox, but it is a function which checks if the host is a domaincontroller. The same code snippet is used again at the end of the room. So i assume that there was just something mixed up?

peak mica
#

room "Python for Pentesters" is missing a txt file "subdomains.txt"

wet fable
sullen flame
weak gate
#

the machine of MALRemnuxv2 doesn't allow you to paste content

misty cave
weak gate
#

already tried and it is linux

#

it doesn't work even if i copy from the machine itself

thick stone
digital depot
#

Issues with getting the 'Site' on Task 7 to continue to the next question on the Red Team- OpSec Room. According to the Blogs seems to be a bunch of people having this issue.
https://tryhackme.com/room/opsec

eternal summit
#

-ban @noble karma -ddays 1 Game malware spam

livid escarpBOT
#

🔨 Banned Hullzy#7162 indefinitely

rotund burrow
#

I have a problem answering 2 questions from *Task 6 IOC Search Collector Analysis * from the *Redline * room. One of the questions is:
Provide the hash (SHA-256) for the file.

To answer the questions from this Task you need to Create a IOC file with the provided strings and a file size, and then create a new IOC report from that IOC file on an existing Redline Session found in C:\Users\Administrator\Documents\Analysis\Sessions\AnalysisSession1.

To answer this specific question the HINT says to Use the "Get-FileHash" command in PowerShell but how can you use it when the file doesn't exist/is not present in that location? Without the file you won't be able to answer the last 2 questions in the task....

old sandal
#

There are two different rooms both called Active Directory Basics, this might be a bit confusing.

sharp palm
# sinful crystal Not strictly a bug but I noticed that the attackbox won't work as designed in th...

I acknowledge the root problem of this one is being looked at. I will, however, post that I solved this problem (used my own Kali instead of the AttackBox) by transferring a copy of SharpHound.exe I had instead of using the provided SharpHound.ps1 pre-positioned on the Windows machine.

  1. locate SharpHound.exe will show you where on your Kali machine you might have it
  2. Then you can use python3 -m http.server to serve it up for download
  3. Download it via the browser or with PowerShell/cmd.exe and the certutils command.
grizzled briar
rugged canyon
jagged depot
grizzled briar
misty cave
rugged canyon
ornate axle
#

Good day @earnest patio, I would like to report an inaccuracy in the "RT path - Living off the Land" room. I have screenshots, if you would like them.

So, a 32-bit binary on a 64-bit system would live in "%windir%\SysWOW64\" and 64-bit binary on a 64-bit system would live in "%windir%\System32\ or in some cases just "%windir%".

The LOL room states the opposite

Hope this makes it into the "LOL" room. Cheers.

earnest patio
livid escarpBOT
#

Gave +1 Rep to @ornate axle

rugged canyon
#

hint on why that might be the case == you might have captured your own cookie by going on said ticket page

dry cliff
#

hello guys, sorry for writing but i got stuck on this https://tryhackme.com/room/relevant room. I upload my shell in the smb and call it. It arrives but there is no shell. My netcat connects but i dont get a shell. Any ideas? I gave up and followed the write up and i also tried to run exactly the same command to create my payload and it still doesn't return a shell. maybe a bug of the room?

#

i get no shell

rugged canyon
dry cliff
#

yep

#

not working

#

i am also now trying the eternal blue and man o man, the vm is breaking all the time. nothing is working as it should with this vm

#

i restarted the vm and tried again for the 10th time....

#

i got a shell back

#

literally did nothing different

#

i swear

#

i am mad that i got it now. wtf i dont know what is going on

wheat fractal
#

pretty sure there is a bug on the room Walking An Application / dev tools-Network

#

looks like the flag don't work

#

Could be a bait from the owners room but idk i'm pretty sure i have the good flag

#

yep I just found it mb

obtuse musk
#

Hi 🙂
In the new room "Cyber Kill Chain" (https://tryhackme.com/room/cyberkillchainzmt);
Task9 (Practice Analysis) I got the flag, but it is the wrong one. Nine characters short.
It is from an other room (https://tryhackme.com/room/redteamthreatintel; Task 7 - first answer...

dusky junco
modest locust
tropic flameBOT
native void
#

Trying to do task 6 in Metasploit Exploitation and all I'm getting is "cannot chdir to /home/murphy: No such file or directory found"

modern raven
rotund burrow
# modern raven Had today this same problem with Redline task 6 that the file doesn't exist on t...

Yeah you are right, i have the habit of getting stuck on a solution without trying to figure out a different method, for example entering the MD5 in Virus Total to get the SHA-256 and the name of the exe, i took the answer from a walkthrough instead and moved on 😄

But still, the hint is misleading since the file doesn't exist, it should say check Virus Total or whatever, in my opinion at least...

serene iron
#

Hi in the room REloaded there is a vocabulary mistake

#

it says "Which instruction did you modified?"

#

while it should be "Which instruction did you modify?"

rugged canyon
#

https://tryhackme.com/room/passwordattacks task 6 only question:
What would the syntax you would use to create a rule to produce the following: "S[Word]NN where N is Number and S is a symbol of !@?
should probably be:
What would the syntax you would use to create a rule to produce the following: S[Word]NN where N is Number and S is a symbol of !@?
i.e remove the extra double quote at the start as it just causes confusion

serene iron
#

What would the syntax you would use to create a rule to produce the following: S[Word]NN where N is Number and S is a symbol of !@ be?
doesn't the "be" need to be added to the end?

rugged canyon
#

¯_(ツ)_/¯

#

it is displayed in code block form so it is distinct enough without another double quote at the end

raw bison
rugged canyon
#

oh nice.... missed your report fontaene

#

then guess the team is aware now

raw bison
hazy tiger
#

-ban 889899039561228338 -ddays 1 nft scam

livid escarpBOT
#

🔨 Banned Kelvin Danso Helary#1638 indefinitely

nocturne stratus
regal moth
#

For LinuxFundamentalsPart3 idk if I'm just dumb on how I'm interpreting this but it says to start a process on boot to use
systemctl start apache2

#

and for the question asked about starting a process on boot startup the correct answer is enable

placid quail
#

good evening, i believe this is the correct place for this feedback. if not please let me know.
In the Red Team Recon room there is a minor typo here

eternal summit
#

The text is saying about starting it now

#

You need to use research, rather than copying from the text

glad badger
twin bay
placid abyss
#

I find that font very hard to read

visual leaf
#

Hello found a weird bug here

#

it accepted the word "topologyu"

#

room "intro to LAN" Introducing LAN topologies

raw bison
# visual leaf

Answer tolerance, refresh the page and it should show the correct one

visual leaf
#

ok

weak gate
#

i don't know if this could be considered as a bug but windows in windows persistence flag 6 asks u how u want to open the file and if u choose notepad (as a normal user would always do) it doesn't run the command and it doesn't give u the shell

#

there should be a way to avoid windows to ask for it...

weak gate
#

also wget doesn't function

twin tapir
twin tapir
weak gate
#

it doesn't load save the file tho

#

i know it's powershell

#

i tried with Invoke-WebRequest -Outfile and it worked

twin tapir
#

Yeah just add -Outfile to wget

#

It’s just an alias for Invoke-WebRequest

weak gate
#

oh thanks

midnight iron
#

Hello, I would like to ask dev if, for Investigating Windows room (https://tryhackme.com/room/investigatingwindows) you can reformulate better the question 11 "At what time did Windows first assign special privileges to a new logon?" because it is misleading and create misunderstanding. The question written in this way seems to ask to the user to get the first Special Logon event. In reality, the right answer is not the first Special Logon of Windows but the one near the time of compromise by the hacker. So, I dont know if it is wrong the question, or the expected answer. Thanks

graceful otter
pallid grove
#

Hi
I think you have problem with the machine on the room Zero logon(https://tryhackme.com/room/zer0logon)

I try to get the NTLM hash of administrator but all the time give me error, about I can`t use that I need to install lib and more.
and then, I was very tired and want to succeed the room so I just take the hash from Walkthrough.
So yay. I had the hash, I know the IP so lets to connect the machine
but then evil - winrm give me that:

vital pilot
#

introtonetworking, Task 5, Question 5: the answer should be -v , but -V is also accepted. -V would give the version information for ping, but we want verbose output, which is -v

rugged canyon
#

i.e it lets you typo the answer slightly but still accepts it as correct

#

if you reload the page it will correct itself

vital pilot
#

I guess there's no "require-strict" switch? ^^ .... yeah, I saw this several times and was lucky there's tolerance, but here I figured it would just be wrong in the sense, that the wrong answer would still work on ping. Never mind 🙂

nocturne stratus
ripe jetty
#

Hi, I subscribed today. In the linux fundamentals part 2 room, I'm trying to ssh into the machine. I'm entering the correct IP address and password as tryhackme. Still, it's giving permission denied.

#

As it is an old room, has anything changed?

tropic flameBOT
ashen obsidian
#

Simple CTF web servere not working

ashen obsidian
# ashen obsidian Simple CTF web servere not working

└─$ gobuster dir -u http://10.10.116.169/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt

Gobuster v3.1.0
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)

[+] Url: http://10.10.116.169/
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.1.0
[+] Timeout: 10s

2022/09/18 20:24:47 Starting gobuster in directory enumeration mode

Error: error on running gobuster: unable to connect to http://10.10.116.169/: Get "http://10.10.116.169/": context deadline exceeded (Client.Timeout exceeded while awaiting headers)

ashen obsidian
#

yes

#

└─$ ping 10.10.116.169
PING 10.10.116.169 (10.10.116.169) 56(84) bytes of data.
64 bytes from 10.10.116.169: icmp_seq=13 ttl=63 time=184 ms
64 bytes from 10.10.116.169: icmp_seq=14 ttl=63 time=116 ms

solemn sinew
#

weird that command is correct