#room-bugs

1 messages · Page 5 of 1

lyric crag
#

Ohh, I didn't know that. That's ok

#

thanks for the response 🙏

#

Would you like me to delete my msg or leave it as it is?

eternal summit
lyric crag
#

Alright, thanks for the quick response

wheat fractal
#

Running into issues following this room's instructions:
https://tryhackme.com/room/windows10privesc
In Task 11, it tells me to do

git clone https://github.com/Tib3rius/creddump7
pip3 install pycrypto
python3 creddump7/pwdump.py SYSTEM SAM

I did a bit of research and had to use pycryptodome instead of pycrypto, ran into some compatibility issues with the old package

keen sluice
#

I have the same problem. The flag.txt from the Administrators Documents folder is missing.

dusky junco
#

Hey 🙂 I'm taking a look into this @unreal bough @keen sluice

unreal bough
#

Oh it's not just me, thanks for conforming Ethlaron.

unreal bough
livid escarpBOT
#

Gave +1 Rep to @dusky junco

dusky junco
#

Update: this is resolved now. If you terminate and re-deploy the machine in task 2, you'll be good to go 🙂 sorry, I'll admit that I missed this when creating the new machine. cc @unreal bough @keen sluice

keen sluice
unreal bough
#

I think you are meant to launch vel and it will show you wants in the ADS, normal files have an ADS stream.

unreal bough
livid escarpBOT
#

Gave +1 Rep to @dusky junco

dusky junco
marsh mortar
#

Is there a bug in the Nessus tool room? Anytime I try to scan the active machine IP address, no vulnerabilities are detected. Kind of frustrating

zenith flume
#

Red Team Capstone Challenge - .89 is no longer reachable from attackbox

chrome sequoia
#

Hello, I have asked several times without an answer... I am on the machine Jumpbox, I tried with attackbox, kali web machine, and my own browser. In all cases I can't connect to port 80, do you also have the issue?

Thank you.

https://tryhackme.com/room/jumpbox

shell mauve
shell mauve
#

Well, find a solution, but differs from hints in text.. different image?

clear mango
#

Good evening please, I need help, my AttackBox Machine on Tryhackme has been black for a long time and prevents me from working. Has anyone ever encountered this error?

twin tapir
#

It may have been released long enough for the local cache to clear. If I understand the original post correctly

shell mauve
silk ferry
#

Thanks!

livid escarpBOT
#

Gave +1 Rep to @dusky junco

agile sequoia
#

Why do so many rooms have technical or content problems which stop learners in their tracks?

eternal summit
#

That's one example, and I completed it without that knowledge.
That's also an ancient room.
If you have any more examples, please do post them here.

agile sequoia
#

There's a bug in the kill chain question where one answer is absent so you can't complete the challenge

agile sequoia
#

Can we get this fixed? Observe how there are 6 answers on the left but recon is missing on the right so you can't actually answer the questions to proceed.

hazy tiger
marble gust
#

Certificate for this image in the OSI model room expired

placid abyss
#

Can you check if you can access Imgur

marble gust
#

imgur loads fine

lunar turret
#

Howdy. For the BreachingAD room (https://tryhackme.com/room/breachingad), I'm having some DNS problems. I configured DNS as instructed on both my AttackBox and my Kali VM (VPN'd in). It appears that the DNS service is either off, or malfunctioning on the THMDC machine:

┌──(kali㉿kali)-[~]
└─$ nslookup thmdc.za.tryhackme.com
;; communications error to 10.200.26.101#53: timed out
;; communications error to 10.200.26.101#53: timed out
;; communications error to 10.200.26.101#53: timed out
Server:         1.1.1.1
Address:        1.1.1.1#53

I configured Kali to use Cloudflare as a fallback. See screenshot for my network settings.

rugged canyon
#

aaah this problem again but this time not for shadow

lunar turret
#

oh this is a thing that happens a lot?

rugged canyon
#

well apparently

#

shadow "fixed" it by making it so they joined another subnet

rugged canyon
lunar turret
#

ahhhhhhhhhh

eternal summit
lunar turret
rugged canyon
#

welp not much shadow can do then

lunar turret
#

shadow is just fine. will contact THM support for helo

hazy tiger
lunar turret
#

Oh! Okay, awesome. Thanks Janna

#

*Jabba

#

*Jason dammit autocorrect

#

I did the things Shadow mentioned:

  • left room
  • took 20 minute break
  • regen'd network-specific OVPN configuration
  • redid OVPN config on Kali box
  • reconnected

Now I have two problems. Firstly, I still can't resolve DNS for the AD controller. Secondly, the OVPN config is incorrect on my Kali machine. And a new AttackBox container did not start the VPN automagically.

#

This is what I see when I try to connect using both the AttackBox and my Kali box:

2023-05-28 21:02:44 Using peer cipher 'AES-256-CBC'
2023-05-28 21:02:44 Error: problem with tun vs. tap setting
2023-05-28 21:02:44 Exiting due to fatal error
wispy geode
#

This about breaching AD?

#

Edit your ovpn file and change dev breachad to dev tun

#

@lunar turret

lunar turret
#

@wispy geode Got it, great success, thank you very much. That worked and I'm unblocked.

livid escarpBOT
#

Gave +1 Rep to @wispy geode

lunar turret
#

How do I give you Rep?

wispy geode
#

Awesome

#

The bot gives rep when you mention or reply to someone and say thank you, thanks, thnx

#

It's nice fake internet points 😁

lunar turret
#

I love it. It's like Reddit karma but better honk

glossy thorn
#

hello, I cannot access the machine in the linux fundamentals 1 room:

#

I should be able to access it directly from my browser and don't need anything like a vm or the attackbox

rugged canyon
#

oh we got another one that has this problem

#

it is kinda rare but they are probably still investigating what is causing it

#

@hazy tiger are you busy or could you look into the above.... it is the white screen split view again

hazy tiger
#

I think the devs are asleep

glossy thorn
#

ping says the host is up, but using the ip adress in the browser returns: unable to connect

#

after the nmap scan; using ssh with tryhackme and tryhackme works as alternative ^^

rancid spire
agile sequoia
hazy tiger
sleek mulch
#

bit of a issue not sure if its a bug or just fix it with a refresh but im in a system trying to scp a file to my home system problem is it asks for a password looked on the info tab and the password is N/A on my machine so kind of hit a road block here

hazy tiger
rocky badge
#

Hi guys and ladies. It seems to me like a bug in room Blue (which is Eternalblue practice room on Offencive Pentesting path). The third question on screen has the answer || RHOST || which is obvious but wrong.

stiff compass
#

guys in apache log file poisoing attack : box Archangel:

im uable to get the php code execute and get result. any one wants to help?

quaint sparrow
rocky badge
quaint sparrow
rocky badge
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

placid abyss
#

Yeah answer tolerance should have picked that up

glossy thorn
glossy thorn
rough trout
#

Hey there, attempting metasploitexploitation room using attackbox, keep getting issues when running modules: not sure how to work around it

this also: Error: 10.10.114.136: LoadError cannot load such file -- active_record/associations/has_many_association

sharp grotto
#

Hello, the registry explorer won’t start on machine of #Unattended room. It remains in state where it says starting. I aborted after about 15 minuten. VM also seems very slow.

lethal dagger
#

Hi there, anyone facing the connection issue to CapStone?

near aspen
#

Hi there, I saw that one of the questions on burp-suite basics may be outdated, because i just downloaded a new version and there is no sub-tab for 4 letters in user options

copper tide
#

Hello, the room:

Digital Forensics Case B4DM755

You have incorrect text in the following item:

Including hidden files, how many files are currently stored on the flash drive?

It should be fixed to:

Excluding hidden files, how many files are currently stored on the flash drive?

#

@proud carbon

proud carbon
# copper tide Hello, the room: Digital Forensics Case B4DM755 You have incorrect text in the...

Hello @copper tide,

Thank you for carefully examining the details in Digital Forensics Case B4DM755 😄

The original phrasing is intentional. The question was written as "Including hidden files, how many files are currently stored on the flash drive?" because it considers the hidden files.

There are two hidden files on the flash drive, which total eight files when added to the six visible files prior disk imaging and recovery of the deleted files.

However, I understand how this can cause some confusion.

Thank you for your observation, and we highly appreciate your help in maintaining the accuracy of our materials ghostblobgib

livid escarpBOT
#

Gave +1 Rep to @copper tide

cosmic ocean
#

hello guys and ladies i think i have a problems with some rooms especially older ones i don't some kinda of adblocker or firewall blocking but it seems that pictures are not loading so is anyone else experiencing this problem

cosmic ocean
quaint sparrow
cosmic ocean
quaint sparrow
cosmic ocean
eternal summit
static turtle
#

In the SOC Level 1 Path - under Yara, Task 8, I run the command that it tells me too, and it says "system seems to be clean", but yet all the questions are asking "what yara rule did it match on", "what does Loki classigy this file as" etc.

dreamy condor
#

Hey I'm having a problem with the Post-Exploitation Basics room, when I try import the .json files into BloodHound it is telling me Bad .json file

wooden talon
#

Can someone help me with these questions? I'm not sure what I'm doing wrong. I've checked walkthroughs, and they all seem to use the same command.

[Room: Common Linux Privesc]- [Task 9 ]-[Question] Now we're inside tmp, let's create an imitation executable. The format for what we want to do is: echo "[whatever command we want to run]" > [name of the executable we're imitating]

What would the command look like to open a bash shell, writing to a file with the name of the executable we're imitating

My awnser : echo “/bin/bash” > ls

But i still get (Uh-oh! Your answer is incorrect). Even after looking in mutiples walkthroughs

barren fulcrum
#

I used this command as room taught to me: Get-ChildItem -Hidden -Path C:\Users\kkidd\Desktop\

barren fulcrum
oblique mantle
eternal summit
#

MACHINE_IP is automatically replaced when you deploy it

oblique mantle
#

thx

proud yoke
#

Would you help me solve this problem?
Room is private

If this is an error on our behalf. Please contact us.
"

rugged canyon
# proud yoke room Volatility

mean the room is either very old and outdated
or broken
or getting updated
it also means you probably won't get access to it unless it gets made public again which does not happen supper often
if you can tell where you got linked to it,,,, the link to it will probably get removed to avoid same confusion for others

rugged canyon
#

¯_(ツ)_/¯

proud yoke
#

¯_(ツ)_/¯

#

🙂

rugged canyon
#

weird yeah seems shadow can access it and it is not private for shadow

proud yoke
#

hmmmm

#

thank you

rugged canyon
#

guess it is up to someone else to confirm what is happening here

proud yoke
#

so we will wait 🙂

quaint sparrow
rugged canyon
#

would be the room link

glad badger
quaint sparrow
#

I can access the link.

rugged canyon
#

guess there might have been an old version that got marked as private but a new one that works then maybe

sharp stump
runic nimbus
eternal summit
livid escarpBOT
#

Gave +1 Rep to @eternal summit

barren fulcrum
#

Hello everyone!
I am in Windows Priv Esc room
I didn't understand this, What is "thmservice" in this command?
In real world how do I know what should I type after "accesschk64.exe -qlc" command
I mean How this rooms creator know that "thmservice"

wispy geode
#

You'd also have to upload any tools to the machine yourself

barren fulcrum
eternal summit
barren fulcrum
nimble patio
#

Velociraptor room -> Task 4 -> Question 2

The answer for the question "How many files were uploaded?" is supposedly 20.

But the number that I'm actually getting from Velociraptor's output is 19

rugged canyon
#

full of broken imgur image links now due to imgur removing images not linked to any accounts

raw bison
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

no problem fontaene

barren fulcrum
#

It should be bug!
This is from "Windos priv esc" room task 7 Abusing Vulnerable Software
I did everything one by one as room.
Here you can see use "pwnd" part of administrator group, but when I type it credentials it doesn't work
I think it is bug or something other

woeful lava
barren fulcrum
craggy laurel
barren fulcrum
crisp widget
#

Hello ! I have issue with the room "Hacking with powershell" - Task 3 - Question 3 (How many cmdlets...). I've run the right command which gives me a certain number which is not validated, I've searched some walktroughts and videos which gave another number but it's still not validated. 😕

prisma bronze
#

should be "its"

#

in task 3, don't capitalise this

#

same task, should be "accessed"

#

this sentence is hard to comprehend, my suggestion: 'The reason for the above three different "find" commands (potentially) returning the same result is that "perm" parameter affects the way "find" works. This is confirmed by the screenshot of the command's manual as seen below:" or something

#

Same task. Other than the comma being unaesthetic, the second clause is ... not good. Suggestion: "This allows for an interesting privilege escalation path, which we will examine in more detail in task 6."

#

same task, ||3.4.0|| is also installed on the target machine

#

same task, should be "seems"

#

should be "few of them, rather"

#

should be "while keeping in mind that"

placid abyss
#

I'd argue that a simple as would be a better replacement

#

Otherwise it's a bit too wordy imo

placid abyss
placid abyss
#

Why?

eternal summit
#

Than

prisma bronze
# placid abyss Why?

"Then" is an adverb that refers to a specific time in the past or future. For example: "I went to the store, and then I went home."
"Than" is a conjunction used to compare two things. For example: "I am taller than my brother."

placid abyss
#

Oh I thought you were talking about my whole suggestion

#

Yup, my bad :)

junior shore
#

Not really a bug but was not sure which other chat to put this in but the room called "Carnage" question : "
What is the domain name for the first IP address of the Cobalt Strike server? You may use VirusTotal to confirm if it's the Cobalt Strike server (check the Community tab)." The answer given for this is the 2nd IP address that is accepted as the correct answer not first. So there is an error in the question wording and the correct answer should be the domain name of the first IP address not the 2nd.

crisp widget
restive sparrow
#

Task4 above

#

here's I am meant to scroll through the text, until unless one hovers, one can't notice even, its just there

#

multi lines could be easily paragrahed, I don't understand why this sliding thing happened.

#

out of nowhere, 9 is highlighted, among every other subtopic?!

#

I am afraid if this content was just copy pasted, who is that "he" being referred there?

hazy tiger
#

@muted musk I believe this is your room?

white jewel
#

snort challenege room task 2 - seq# of packet 62 and ttl for packet 65 dont seem to be right. snorts output makes it seem obvious but it's wrong.

#

and isnt the syntax on the output $sourceip -> $destip? either im wrong (more likely lol) or the answer for the last part of task 2 is backwards?

muted musk
#

Yes it is
I´m sorry i need to improve my english
Any recomendations about what should i write there?

bleak valley
#

is there anyone having problem with OWASP Top 10 - 2021 machine?

#

the index page is just loading

#

it seems not only this room the other rooms are the same

#

is there high load on the rooms or something!!??

hazy tiger
#

If it’s happening on other rooms, then it’s probably not a bug #site-support

pliant zodiac
agile mason
#

in task 3

placid abyss
eternal summit
agile mason
livid escarpBOT
#

Gave +1 Rep to @eternal summit

eternal summit
#

Deprecated, not just old.

glad badger
livid escarpBOT
#

Gave +1 Rep to @agile mason

barren fulcrum
#

There is bug from "DNS Manipulation" room. Because python code works well in my linux machine after transferrring those codes. But it doesn't work from attackbox (I installed all modules and requirements)

lunar fractal
#

Hey, ftp isn't working for me on the Brainstorm room. I can login into it anonymously but it doesn't list directories or files. It's probably extremely slow.
can anyone share the dll file and the chatserver.exe file? I would greatly appreciate any help

umbral mesa
#

I am doing the room GitHappens, and when I download the repository files with the git-dumper tool, it doesn't download the commit files. any idea why? #githappens

icy tendon
#

Within Phishing Analysis Tools : Task 7 Phishing Case 1, on the last question, you are asked to find the shortened URL and then defang it. I chose CyberChef to Extract the URLS from the .eml file and got 2 shortened URLS which are slightly different than what the answer is.

gilded ice
#

I cant seem to post pictures yet

#

it resolved itself after reloading the page 5 times, not sure if browser or server issue.

quaint sparrow
#

Possibly.

#

If you want to upload screenshots, you'll need to verify your account.

#

!docs verify

tropic flameBOT
gilded ice
#

!docs verify

tropic flameBOT
rain swallow
#

Hello, the Pyramid of Pain practical (task 9) seems to be broken. Whatever order you put the answers in comes out wrong. Luckily you don't need to complete that part to finish the task, but it should still confirm your answer.

hazy tiger
#

cc @dusky junco

quaint sparrow
#

It's not broken.

#

Not for me anyway

civic carbon
#

Trying to do the Redline room, following the directions preciesly, and none of the analysis files are forming/importing correctly.

deep pasture
#

Hello @tropic flame I'm facing issues for months now trying to work on the OpenCTI room. The OpenCTI instance is totally unreachable. Many users are facing this problem and it's really impacting for my work. Could you please see what's going on ? Appreciated : https://tryhackme.com/room/opencti

hazy tiger
#

@glad badger This machine often takes a long time to start up. I think it says 5/10 minutes but I had to wait a little longer (subscriber) for it to start.

Possibly add a message in the room to say it may take 15 minutes to start up?

deep pasture
#

Thanks a lot @hazy tiger but in fact I've been waiting for almost half an hour and nothing

livid escarpBOT
#

Gave +1 Rep to @hazy tiger

deep pasture
#

(I have a subscriber access)

junior shore
#

smart grotto room not working. One of the steps is to modify the etc/hosts file to make it show 10.10.21.99 development.smag.thm then save it then when you browse in the url bar to that it should pop up but its not

hazy tiger
rugged dawn
#

In the "Introduction to DevSecOps" room the static site is missing for me. It is also not showing as that little icon in the task section.

deep pasture
quaint sparrow
deep pasture
#

I do, but what else I can do.... 😒

hazy tiger
small flame
fading sinew
#

what the heck with breaching active directory room?

#

why I can't launch the network?

#

So, I don't have buttons to activate, or stop the network and also don't have information about network status?
for example, in enumerating active directory room i have all this things

smoky cosmos
#

Blaster machine is not working according to the walkthrough!

storm tiger
#

up

tired halo
#

lately the rooms links on advent of Cyber 3 (2021) dont open up a working link take day 5 task 10 doesnt allow me to use the link to open up the page

tawny osprey
#

In burp suite - intruder the question for task 7 is wrong (?) in the attack box, burp suite's intruder pitchfork has a max of 5 payload sets but the answer is 20. Is the burp version outdated on attack box that causes this discrepency?

foggy sparrow
#

is Zeek Scripts not working for others? facing syntax error from a newly launch machine

root@ip-10-10-119-111:/home/ubuntu/Desktop/Exercise-Files/TASK-7/101# zeek -C -r sample.pcap -s 101.zeek
error: Error in signature (./101.zeek:1): syntax error

root@ip-10-10-119-111:/home/ubuntu/Desktop/Exercise-Files/TASK-7/101# cat 101.zeek
event zeek_init()
{
print ("Started Zeek!");
}
event zeek_done()
{
print ("Stopped Zeek!");
}

deft olive
#

hi guys do you happen to know why we can't use nmap function in vm's ?

misty dew
#

what error do you get?

wicked remnant
# fading sinew what the heck with breaching active directory room?

this is my second attempt to do the room after giving up a few weeks ago due to the same issue. The attackbox never connects to the network for me like it's supposed to. I've started and restarted and restarted the attackbox, left the room, re-joined, repeated... arggh.

glad badger
hazy tiger
wicked remnant
quaint sparrow
#

Look at the top right, what is the network state?

#

Are you able to leave the room and re-join?

covert crystal
#

Just bumping this to the top. Issue still exists. User options "Misc" sub-tab no longer exists.

prisma bronze
#

https://tryhackme.com/room/linprivesc in Task 7 for the find command, the 0 before the suid bit is unnecessary. it doesn't cause any harm for it to be there but it's best to remove it from there to avoid any confusion for newbies

prisma bronze
#

also the machines in this room so far have failed to create a home folder for the karen user

prisma bronze
hazy tiger
#

Hm weird

prisma bronze
hazy tiger
prisma bronze
# hazy tiger Yes, not sure if it was updated or not.

I believe the whole room should be looked over and overhauled a bit. I pointed out earlier in this chat the various grammatical mistakes and occasionally hard to understand phrasings in it. I'm not saying that it's a bad room, it does teach what it wants to, but it doesn't feel that it lives up to the standards of the rest of the site. For example https://tryhackme.com/room/linuxprivesc does a much better job at explaining this stuff, but it has less practicals. Maybe combing the two together might be a good idea to end up with something that's worthy of being on a learning path.

hazy tiger
#

It is an very old community room

slim niche
#

How many cmdlets are installed on the system(only cmdlets, not functions and aliases)? is there a solution for this

marsh hatch
#

In the SOC 1 path --> Cyber Defense Framework section will not show completion. It keeps showing I have 97% complete and missing one question in the Mitre Room. But I have completed it 100%! It's really frustrating how many bugs and errors are on this site!

inland trail
weary urchin
#

https://tryhackme.com/room/burpsuiterepeater - The id we're pointed at, nr 2, is not the CEO, who's got id 1. So if you get the notes for id 2 it's empty. For 1 there's the flag. FYI @hazy tiger . Btw it might be start to change it to two so people don't just get the first one 😉

hazy tiger
weary urchin
#

Thought I'd report room bugs without sending them there. Which is better?

hazy tiger
#

Ah, yes, I remember you:)
For streaming, recording or general site queries, I’m okay with being pinged (within reason)

For room bugs, you’re free to post them here or create a ticket through the site, but I don’t directly handle them. Feel free to post them here and they will be picked up by the content engineers, QA or (if I’m around) me

weary urchin
#

Ok, thanks Jason ❤️ Sorry for the ping 🙂

hazy tiger
#

No harm down :)

willow pumice
#

So I am doing the basic static analysis room, and couldn't get the other browsers to open, so I used google chrome. It said it needed to unlock the profile. I did and a bunch of tab were already open trying to load

Did it maybe not clear from the last person, or something else?

#

slow as all get out too, though that may come with the territory

rancid drum
#

https://tryhackme.com/room/burpsuitebasics - The Active Machine with the name "Bastion v1.5" spins up but never responds to http requests so the tasks cannot be repeated. I have tried this using different browsers on different networks three different times today. The http never gives a response.

rancid drum
quaint sparrow
#

Are you waiting 5- 10 minutes?

quaint sparrow
eternal summit
rancid drum
rancid drum
rancid drum
quaint sparrow
rancid drum
quaint sparrow
#

It works for me.

#

Do you have any errors on your VPN output?

rancid drum
#

I am properly connected. In your first screenshot you were not connected to VPN.

quaint sparrow
#

Yes I was.

#

If you look in the top right hand corner, you can see my tun0.

rancid drum
#

can we go to a VC?

quaint sparrow
#

No.

rancid drum
#

So I may share screen?

quaint sparrow
#

!docs verify

tropic flameBOT
quaint sparrow
#

If you verify you can send screenshots,

And since this isn't a bug, but a connection issue, we should move to #site-support

rancid drum
#

"Works for me" does not really prove anything.

#

ugh

#

this is annoying.

quaint sparrow
#

It proves it works, and it's not a fault with THM.

So it must be something on your end.

#

A since you won't verify your THM with Discord, you can't attach screenshots.

#

And you can't join the VC because you're also not verified...

rancid drum
weary urchin
#

"Bug" or rather a needed update. All the burp intro rooms are for an older version of burp before the settings where separate.

At one point I found the answer to a question by looking at a screenshot in the room but at another one I had to start the attackbox that uses the older version. A bit of a hickup if you're using a vm & vpn but not a big one. I can imagine a true newbie might give up though ❤️

I understand you would have to update the attackbox to fix this but why not let us learn on the current versions of software instead of older versions.

Thanks! 🙂

hazy tiger
rough trout
#

https://tryhackme.com/room/wazuhct - Room has very confusing wording, Task 7 is particularly a nightmare. There are also some odd screenshots such as: The one that says to select rule but is highlighting "Administration", there's really no point to draw extra attention to the Administration section, would be better if the red box was around "Rule".

Also randomly has a question:
Ensure that you are logged in to the Wazuh management server on 10.10.229.53
But my other questions:
Ensure that you are logged in to the Wazuh management server on 10.10.186.32

I haven't restarted the room, nor the box, so not sure why it's asking me to go to another IP (it doesn't work), nor does it give me login creds for the new IP it wants me to connect to. I am connected to 10.10.186.32 Wazuh.

Overall the room is very easy and doesn't require much to deduce the answers but it's kind of a headache to read if you're actually trying to get the information and not just speed run the room.

magic bone
#

I tried both rdp and ssh and creds didnt work. I never use the split view unless necessary, which in this case may be. But I am going to try yours and the others suggestion on changing the password in split. Cheers.

granite veldt
#

Just use the Split View, I think that’s what I had to do. Iirc I manually enabled ssh just to have an easier time lol

#

I will agree this room is very vague on these bits

magic bone
#

Right? Great material but a bit vague at times.

granite veldt
#

Yeah depends on the author/creator tbh

craggy sun
#

Looks like this is still an issue

hazy tiger
somber parcel
#

hey , i have a problem with the Overpass2 room

#

what i can see is just a loading screen

willow pumice
willow pumice
#

also for some reason the internet is not working in the VM

weary urchin
#

The OWASP Juice room also have old Burp stuff FYI

#

https://tryhackme.com/room/uploadvulns in the Complete Beginner path. In task 1 you're asked to start the machine and to add an entry to the hosts file, then in task 2, you're told you need to do two other rooms first. Might be a good idea to just swap there two around. The suggested rooms are 13 & 15 task long and seem learning intense, so if you havn't done them they'll take quite some time 🙂

quaint sparrow
rugged ravine
#

Hello, i think i noticed something wrong in this room : https://tryhackme.com/room/linprivesc
Task 5, we are supposed to use an exploit from CVE : https://www.exploit-db.com/exploits/37292

But when i try, i have this error message on the remote machine : ./exploit: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./exploit)

I tried a few exploit but all of them looks to use C libraries. When i take a look in the writeup. Everything looks fine for the person who try.

supple crescent
weary urchin
# quaint sparrow This isn't really a bug. But are the two rooms in question before the room in a...

Not a coding bug but a logic one 😉 No, they are required for the room but not in the path. This is the case for other rooms too, like the one before, the OWASP juice shop. It requires Burpsuite Repeater that's not in the path (but we find this out right at the top of the room!!) (I ended up doing all the burp rooms while I were at it.) I don't mind doing extra rooms since my goal is learning, but since the path is Complete beginner all pre recs should really be in there 🙂 ❤️

If certain rooms, or the knowledge you gain in them, are required for a room, it would be great to place this info in the first task ❤️

placid abyss
placid abyss
#

But, as scrubz said, techincally not a bug

quaint sparrow
placid abyss
#

Depends what you'd classify as a bug :P

#

Doesn't hurt to post it here though

rugged canyon
#

yeah junior pentester path has burp suite rooms in it but they are after some of the rooms where you more or less need to have burp knowledge to pass through it

weary urchin
hazy tiger
#

@placid abyss @quaint sparrow Suggestions/ feedback are also welcome here regarding rooms

hazy tiger
#

thanks @weary urchin 🙌

livid escarpBOT
#

Gave +1 Rep to @weary urchin

livid escarpBOT
#

Gave +1 Rep to @hazy tiger

weary urchin
#

Thanks @hazy tiger

livid escarpBOT
#

Gave +1 Rep to @hazy tiger

weary urchin
#

Thanks @placid abyss

rugged ravine
livid escarpBOT
#

Gave +1 Rep to @supple crescent

wheat fractal
#

Did somebody completed the Aurora EDR room recently? I am unable to complete the scenario as there are no other logs generated than errors and informations about a licencing expired issue:

no valid license file found 
   Module: Aurora-Agent 
   Licensepath: C:\Program Files\Aurora-Agent 

License file found 
   Module: Aurora-Agent 
   Owner: xxxxx Aurora Agent (xxxxxx @ tryhackme.com) 
   Reason: license expired 
   Valid: false 
   Valid-From: 2022/06/05 
   Valid-To: 2023/06/13 
supple crescent
wheat fractal
livid escarpBOT
#

Gave +1 Rep to @supple crescent

karmic hornet
#

Hi can someone please help me, I'm on take 6 practical network simulator and for some reason my network log isn't loading and it won't let me finish because for some reason its not taking my packet

half solstice
#

In the velociraptor room, it seems like there is a typo in the image. It shows the command being issued from program files, and it really should be issued from program files\velociraptor.

stuck estuary
#

Bug on Burp Suite: The Basics section: Options. Question: 3.
Question:
In which base category can you find the "Updates" sub-category, which controls the Burp Suite update behaviour?
Answer should be: Misc.
But answer format is: *****

#

How should I pass this?

vivid sigil
#

Hi I am doing the room “OWASP Top 10 - 2021” Task 10. After I spin up the Attack Box I cannot see anything running on port 82

whole fulcrum
#

Hello.

In this room: https://tryhackme.com/room/furthernmap, task 14 (Practical):

The first question: Does the target <ip here> respond to ICMP (ping) requests (Y/N)?
The answer is Yes, when I do (nmap -sn <ip here>) from the attackbox against the targeted machine I get "Host is up" back and when I submit "Y" it says it's wrong and only takes "N" for the right answer.

rugged canyon
whole fulcrum
rugged canyon
#

yeah because that is how the target machine used to work and doubt that should have changed

whole fulcrum
#

So in this case the answer validation is not correct, right? just making sure I'm learning correctly and not missing anything

real mauve
#

Hello 👋.

I have a Issue in this room: https://tryhackme.com/room/bashscripting

the problem being: some of the questions/tasks are completely unrelated to the information above.
For example in task 4 (parameters), there is no piece of information related to the task "How can we get the number of arguments supplied to a script?"

raw bison
livid escarpBOT
#

Gave +1 Rep to @half solstice

raw bison
half solstice
#

In the velociraptor room, Task 6 question 3, the question reads,
What is followed by the WHERE keyword?
It should say something like, "What follows the WHERE keyword?"

whole fulcrum
livid escarpBOT
#

Gave +1 Rep to @raw bison

fair zealot
calm frigateBOT
#

Done!

supple crescent
real mauve
livid escarpBOT
#

Gave +1 Rep to @supple crescent

split marsh
north snow
raw bison
livid escarpBOT
#

Gave +1 Rep to @split marsh

frosty lance
#

Heyho, in the "Attacking ICS Plant #1" room, the answer to the second question in Task 2 is missing a ')'

burnt sparrow
#

Hello Red Team OPSEC task has 7 problems. The site does not working. Answer 45231. Don't submit

void ibex
#

Red Team - Sandbox evasion Task 4 - section Taking a nap.
This section discusses adding a sleep delay to the dropper.ccp main function as a way to evade short running sandbox's however the displayed code snip refers to code for checking the host is a windows DC from a later section "Querying Network information"

quaint sparrow
#

45231 won't work, but 4 5 * * * will.

muted lynx
#

What am I supposed to do here? At a certain point, the room stopped working, and even terminating it would do nothing as a page refresh would show it was still there. And this shows I cannot even wait for it to die 😦
It's not the browser either, I have two THM sessions on two devices on two different networks and they both show this "error"...

#

well, as I posted this the room died. It's not the first time this has happened, however, and for this room only (for now)

robust turtle
rain swallow
#

Room: Threat Intelligence Tools - https://tryhackme.com/room/threatinteltools#

Task 5 - Phishtool

Question 4: What is the Originating IP address? Defang the IP address.

Question 5: How many hops did the email go through to get to the recipient?

It is not explained within this task nor is it obvious how to answer either of these questions.

The task also doesn't make use of Phishtool at all with the attached machine, which is odd. It's like an entirely different task/questions.

#

Task 6 - Cisco Talos Intelligence

Similar issues as well. Doesn't seem very clear as to how to actually proceed with the task. It says you need to download a file, but that file is existent on the virtual machine, so are we to download it to our computer from there? Or do we log on to the phishing tool from the VM? It's extremely slow and clunky trying to do that, so it's a bit odd still.

#

Same with the rest of the tasks pretty much. For example, Task 7 scenario 1, how are we supposed to figure that out? It's not explained in the task or the room.

#

Doesn't explain how to find the hash in order to use the cisco tool to answer the question etc.

#

overall an extremely frustrating room and the tryhackme forum seems to have the same feelings

sudden sable
#

guys I've noticed that the deploy room for the room I'm doing is gone? anyone who experienced this?

rugged canyon
#

ditto seems there is no machine to launch in said room

#

something has gone wrong somewhere

raw bison
livid escarpBOT
#

Gave +1 Rep to @sudden sable

outer root
#

Hello,
I’m having issues configuring dns and connecting to domain.
Even after setting dns with systemd-resolve conmand , nothing works. This is for lateral movement network
Please Advice

fast pier
#

Hello! I have been trying to finish the room https://tryhackme.com/room/breachingad for a few days, but it is impossible to ping the main DC, and the reset button doesn’t seem to be working either
Thanks for reading my message 🙂

quaint sparrow
fast pier
visual nest
#

Hi, I am trying to start with https://tryhackme.com/room/breachingad as well - I tried both via openvpn and attackbox but have had no luck in setting up the DNS (on both openvpn/attackbox) and cannot really start the room. I raised a bug ticket ID #8833

wheat fractal
#

In the "Hacking with PowerShell" room I think the machine is different.

bright flax
quaint sparrow
visual nest
#

@quaint sparrow yes - I tried that - in summary put in nameserver 10.200.20.101 (the IP of THMDC) - when using openvpn and my own kali vm - and tried to run the command as per room page on attackbox - but still no joy

#

@Scrubz - I just noticed (sorry first time in discord ... been busy going through the paths) the breaching-ad network chat above - saw your discussions, will try that (leave room, wait 5 and retry - hopefully getting another subnet) - I did try leaving but joined in less than 5 I think

#

@Scrubz - it worked! 😮

quaint sparrow
wheat fractal
quaint sparrow
wheat fractal
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

quaint sparrow
ivory rover
#

For Advent of Cyber 2022, task 13 (Smart Contracts), one of the solidity files doesn't compile in Remix, even with the specified compiler version.

#

If anyone knows how to fix, please let me know. Thanks!

rugged canyon
#

weird... wonder what changed to make that happen

#

anyways if you can read smart contract code or code in general you can use that to get the flag

#

@ivory rover ⬆️

livid escarpBOT
#

Gave +1 Rep to @rugged canyon

tacit kettle
#

Hi i found out a writing error in a room

rugged canyon
#

and yes this is the place to report it

tacit kettle
wheat fractal
#

Hi there o/
@quaint sparrow @wheat fractal @bright flax
I've noticed this bug too in "Hacking with Powershell" room, is it confirmed that there's something wrong with the VM ? 🙂

quaint sparrow
#

I had a look last night but was unsure what I was looking for, I can have another look later and try and help. (I'm not staff)

wheat fractal
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

dusky junco
quaint sparrow
#

Ah, Ben's on the case 😀

wheat fractal
livid escarpBOT
#

Gave +1 Rep to @dusky junco

dusky junco
# wheat fractal Perfect, thanks to both of you 👍

Hey 👋 just to follow up. I've made some changes to the VM. I'm just testing it now, but the VM should reflect the expected answers fine now. I've also added some guidance especially to Task 3 Q#3 re. the cmdlets - there're numerous ways to measure how many cmdlets are installed but they provide different amounts based upon your query. I've added a hint to this question to make it a bit clearer on exactly what the answer is looking for (i.e. the question is expecting you to follow the format of the room i.e. Verb-Noun | module-module. You could, for example, use Get-command | measure which technically is correct (though gives a different output), but it isn't the approach that you're taught in the room. If that makes sense?

#

cc @quaint sparrow

quaint sparrow
livid escarpBOT
#

Gave +1 Rep to @dusky junco

tiny breach
#

Anyone doing the Virtualization and Containers room? I think task 5's question is bugged.

wheat fractal
livid escarpBOT
#

Gave +1 Rep to @dusky junco

static igloo
tiny breach
tiny breach
quaint sparrow
#

Some people have finished the room

quaint sparrow
#

RE Task 5 being bugged, I just done it, it's straight forward, and only took 5 min(s)

placid abyss
#

Can't say the same sadly

#

Doesn't accept the correct answer

quaint sparrow
#

I just went to the ||machine_ip:5000||

placid abyss
quaint sparrow
#

What if you curl?

placid abyss
#

No, they physically do not show

#

If I type in _ it doesn't show up

#

It's nothing to do with the specific command being ran, more the actull interface

tiny breach
#

I curled it too, maybe that was my problem 😄

placid abyss
#

If your using the split view, the underscores wont show up - no command you use

livid escarpBOT
#

Gave +1 Rep to @placid abyss

raw bison
# placid abyss

Seems to be just a "visual bug", as copy pasting seems to pick up on the underscore.
We added a little note to the room.

pure lion
burnt geyser
#

Hi, I am trying to access machine in splunk201 room(uncident handling with splunk) using attackbox and getting 502 badgateway error. Is there a fix?

static grotto
#

Hi there. WindowsEventLogs room > Task 5 > Question 2: Answer includes the query for "SubjectUserName", but then when the next question asks how many results were from that query, the actual XPath would have been using the TargetUserName, which results in two. So just a bit of incorrectness in Answer #2 if I'm correct.

torn tangle
#

I need help. I have been connecting with openvpn but when I'm trying to open a ACMI site with my virtual ip address the page is still loading

oblique spindle
deft sluice
#

i am getting remote server issues as well

weary urchin
#

https://tryhackme.com/room/webenumerationv2 Task 6
Q: There are some virtual hosts running on this server. What are they?
The command learnt in the information section gives output 1 which is quite confuzzling for a newbie ❤️
After googling I found that adding --append-domain gave the correct result

sharp citrus
dusky junco
weary urchin
livid escarpBOT
#

Gave +1 Rep to @dusky junco

weary urchin
#

Fyi on this and other rooms btw. Most rooms use the path SecLists while it's all lower case on my kali vm. I checked the attack box and it has the pascal case one. I guess kali is the odd one out since the git proj is called SecLists so if you clone that's the name you get too. Maybe not something that would make a noob stumble but maybe worth mentioning somewhere?

ashen pewter
#

just started Local File Inclusion and im getting an error msg 502 -> Bad gateway when i just started the machine

#

waited for 2 mins

#

Forget what i said....it fixed it self

#

its fixed now

dusky junco
ashen pewter
livid escarpBOT
#

Gave +1 Rep to @dusky junco

hidden turtle
#

Did you ever figure this out? I am having the same issue.

#

I'm getting an error in the Snort room when trying to run traffic-generator.sh "Failed to execute child process "tcpreplay" (No such file or directory)

#

Never mind, figured it out seconds after posting. Needed to use sudo.

thorny mountain
#

hey guys, I'm doing overpass3 and up to the part where I use the user creds to log in via ftp, I'm then supposed to craft a php reverse shell and upload it to the server. every walkthrough i've followed through on allows the user to cd to backups and use the put command to upload their shell. I keep getting an error saying that it couldn't create the file. wondering if the room is bugged as every other video i've seen it's working fine.. they cd to backups, use put ~/Downloads/payload.sh.php and it uploads. cannot recreate on my end.

eternal summit
#

!docs verify

tropic flameBOT
uncut nymph
thorny mountain
eternal summit
thorny mountain
eternal summit
thorny mountain
eternal summit
#

Ahaha, no problem

thorny mountain
eternal summit
thorny mountain
eternal summit
thorny mountain
livid escarpBOT
#

Gave +1 Rep to @eternal summit

dark raptor
#

AWS Lambda
https://tryhackme.com/room/awslambda

TASK 5 Q1

Using the command "aws lambda get-policy --query Policy --output text --function-name <function arn from task 2>" retrieve the invocation policy for this sample function. What is the Action for the most permissive Statement?

Please Correct: <function arn from task 3>

glad badger
livid escarpBOT
#

Gave +1 Rep to @dark raptor

weak gate
#

the room exploiting active directory is currently not working

rugged canyon
wheat fractal
#

THM is not getting back to me via the ticket so I am gonna post it here, anyone encountering the same problem in the Linux Privilege Escalating room on the NFS priv escalation task?

Room URL
https://tryhackme.com/room/linprivesc

Task/question
Task 11 / Q: "Gain a root shell on the target system"

Description
When I compile the given nfs.c ($ cat nfs.c int main() { setgid(0); setuid(0); system("/bin/bash"); return 0; }) on my own machine and then mount it on the box and try to run it it gives me this error: $ ./nfs ./nfs: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./nfs). I am no expert in C but I am guessing this is happening because of compatibility issues. I also tried other bash shells such as wget https://github.com/polo-sec/writing/raw/master/Security%20Challenge%20Walkthroughs/Networks%202/bash and that did not work as well because of this error: $ ./bash -p ./bash: error while loading shared libraries: libtinfo.so.5: cannot open shared object file: No such file or directory , I tried both on my own machine with the same permissions and they worked.

Error message
lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found | ./bash: error while loading shared libraries: libtinfo.so.5: cannot open shared object file: No such file or directory

rugged canyon
#

the problems you are experencing has to do with version mismatchs and libraries being included meaning it will fail because of cross compilation or none static bianry bash version

wheat fractal
#

so you mean cp -p /bin/bash /NFS_SAHRE_FOLDER_PATH on the victim and then on my machine change the permissions of the copied file to be able to execute it as root as then try it like that, please correct me if i am wrong

rugged canyon
#

./bash -p to run it after you set the suid bit though

#

so it does not drop the root privs

wheat fractal
#

alr thank you

rugged canyon
#

no problem

#

recognise this problem happens a lot so have helped a lot of users with it

#

it is a good lesson to learn that cross compilation and none staic binaries being hard to use

hollow crescent
#

hi, i introduced some of my friends to thm, specifically the intro to lan room, and although without logging in it says the room is public, as soon as they login to a free account, it sends them to the subscription page

safe nymph
safe nymph
#

@tropic flame

hazy tiger
safe nymph
#

@tropic flame @hazy tiger support@tryhackme.com support@tryhackme.com
Yes we are on a business plan and have mailed this issue to the above-mentioned email 4 days prior, still no reply, If there is any other email that we can contact for faster support please suggest
Thank you.

livid escarpBOT
#

Gave +1 Rep to @hazy tiger

hazy tiger
safe nymph
#

@hazy tiger Please provide link where we can raise ticket Could not find it any where in website.

quaint sparrow
hazy tiger
#

Thanks Scrubz^

safe nymph
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

quaint sparrow
#

Where is this room found?

#

Yes, but where did you find the link?

#

It's a private room, so anyone who's given the link can access the room.

quaint sparrow
#

"outwith" is not a typo.

quaint sparrow
pine sandal
#

Hi, is there the right place to report a typo on a picture ?

#

In the room "DNS in detail" > Task 4 > Typo on the picture "Authoratative DNS Server"

pine sandal
#

👌🏻 , good to know for the future

vital zodiac
#

ROOM: Threat Intelligence for SOC
Task 2 | Question: Based on the set of IOCs, how many IOC hits were discovered in the logs?
According to the Kibana-Elastic virtual machine in the cloud it is showing 45 hits, however, the correct one is 48, I verified it by looking at the writeup on youtube. I put the dates requested by and with the list of ip's Room.

errant oasis
#

in the room "Windows PrivESc Arena" > task3 > there's a problem copying the malicious exe file from the linux VM to the windows VM .

torn yacht
#

hi, i think i found a security issue with a recent machine, I wrote to hello@tropic flame but I'm guessing that box isn't monitored over the weekend. Is there anyone with THM that I can report to?

placid abyss
#

The boxes are supposed to be vulnerable

#

What sort of issue are you talking about

torn yacht
#

obviously i know the boxes are supposed to be vulnerable. i think someone has left real-world credentials on a recent box.

placid abyss
#

hmm @dusky junco

raw crypt
#

3 months later and still not updated blobhuh

sinful crystal
#

😦

whole fulcrum
#

Hello.

I'm doing (Web Fundamentals - Introduction to web hacking) and I haven't finished the last part (SQL Injection) yet, but I received the badge for "Intro to web hacking"

noble oxide
#

This problem by @orchid schooner was never fixed

pine sandal
#

Get a bug on room SQL Injection > Task 5, I found the password, but the popup disappears without clicking on its "close" button and it does not show the flag (I have a screen if necessary)

sharp citrus
#

you have some sort of popup blocker or smth ?

pine sandal
#

ublock origin on my browser (test disabled and it's not better) + dns filter on my lan but it shouldn't interact with THM

sharp citrus
#

let me try run it and will let you know if is the same

pine sandal
#

👌🏻

sharp citrus
#

when ypu find martin password you get to 2nd tab right? then on top you need to have 1st flag

pine sandal
#

yeah ... -_-'

sharp citrus
#

helped ?

pine sandal
#

got stuck on this popup without reading the next page. It's time to take a break and have a coffee

#

thanks @sharp citrus

livid escarpBOT
#

Gave +1 Rep to @sharp citrus

sharp citrus
#

it can happen. take brake. and slow you self when learning. no need to speed-run things 🙂

pine sandal
#

just delete your screen, you have cc the answer on the left 😉

sharp citrus
livid escarpBOT
#

Gave +1 Rep to @pine sandal

wraith orchid
#

Then you can fix this and make the compiler happy by casting it:

rugged canyon
#

nice you seem to have provided a fix for your found bug so that it can be changed in the descripiton in the room

#

but yeah the challenge is solvable by actually reverse engineering the flag from the code

wraith orchid
#

Yea IK, can't keep secrets on chain, but unfortunatly doesn't let people do re-entrancy practically. If you guys wanted to implement a long term fix, you could copy the openzeppelin code add it to the zip and import it locally, therefor any future changes wont affect the room.

rugged canyon
#

shadow is just a room tester they don't have perms to change stuff in the room ¯_(ツ)_/¯

#

would point this towards @dusky junco or @glad badger for fixing

dusky junco
rugged canyon
#

carbon copies

hollow condor
#

hello everyone, this was taken from the Autopsy room , task number 7 "What self-assuring message did the 'Informant' write for himself on a Sticky Note? (no spaces)" when i enter the answer , it say it is incorrect , does anyone else experience this?

wispy geode
#

This isn't a room bug, it's for #room-help or #room-hints In any case, the error already tells you, id_rsa files require specific permissions to work, you can change file permissions with the chmod command. Google is your best friend this field, read up on what permissions are required

opaque pebble
#

This isn't actualy a room bug but more like a room creation thing. I want to upload a banner image to my room but, it only allows urls and my image is a local file. How can I use it?

opaque pebble
#

Using what service?

quaint sparrow
#

Google one?

opaque pebble
#

I tried hosting it on mega but seems THM can't find the file

blob:https://mega.nz/36dfd6d8-6473-4ed3-bfc4-63f8e5e4093a
slow sorrel
#

I was stuck with the same problem and disconnecting from the DB solved it for me

wheat fractal
#

hey guys i am trying to exploit the new room Red v5 https://tryhackme.com/room/redisl33t, I finished the first two tasks and I need to get root access now, for that you need to exploit the binary pkexec on /home/red/.git/pkexec because it has the setuid however for the exploit you need gcc to compile the code but the victim machine does not have it installed and when I try compiling it on my own machine and then uploading it I get this error:
/lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./exploit)
any solutions? or should I wait until it is fixed thanks in advance

rugged canyon
wheat fractal
#

even the one with python needs gcc a snip from the code:

    os.system("mkdir -p 'GCONV_PATH=.' pwnkit ; touch 'GCONV_PATH=./pwnkit'; chmod a+x 'GCONV_PATH=./pwnkit'")
    os.system("echo 'module UTF-8// PWNKIT// pwnkit 2' > pwnkit/gconv-modules")
    f=open("pwnkit/pwnkit.c","w") ; f.write(so) ;f.close()
    os.system("gcc pwnkit/pwnkit.c -o pwnkit/pwnkit.so -shared -fPIC")
    envi=[b"pwnkit", b"PATH=GCONV_PATH=.",b"CHARSET=PWNKIT",b"SHELL=pwnkit",None]
    env=(c_char_p * len(envi))() ;env[:]=envi
    libc = CDLL(find_library('c'))
    libc.execve(b'/usr/bin/pkexec',c_char_p(None) ,env)

main()```

I could not find any other exploits with the mentoned languages, i cannot run apt-install on the victim, and whats cross compiling
rugged canyon
wheat fractal
#

I think I found it trying it rn

wheat fractal
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

safe nymph
quaint sparrow
safe nymph
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

quaint sparrow
#

Just ask your question.

#

Ah, you've spammed that in multiple channels..

#

Just be patient.

#

Well, 3 now.

#

Just one would have been great, no reason for the sarcastical tone, you're the one seeking help after all.

nimble locust
#

that attitude is really not appreciated megalodon

#

people are volunteering their time?

#

?

#

This server is English only

calm frigateBOT
#

:mute: _m3g4l0d0n#0 has been muted.

coarse spade
#

Hi. I think there's a task in the Unified Kill Chain room (https://tryhackme.com/room/unifiedkillchain) that needs to be updated. In Task 5 "Phase: In (Initial Foothold)", it mentions Unified Kill Chain's "Weaponization" phase. But a 2020 addendum on the bottom of page 6 of the Unified Kill Chain website's PDF (https://www.unifiedkillchain.com/assets/The-Unified-Kill-Chain.pdf) says "...Weaponization
was renamed to Resource Development following the addition of that tactic to MITRE ATT&CK™ in October 2020 (v8)".So I think maybe the reference to the "Weaponization" phase it should be updated to "Resource Development" and link to the MITRE Tactic TA004 (https://attack.mitre.org/tactics/TA0042/).

#

Hi. I think there's a mistake in the "Packets & Frames" room (https://tryhackme.com/room/packetsframes). In Task 4 "UDP/IP", it says that UDP headers have a "Time to Live (TTL)" header. But I think that's for IP headers, not UDP. I don't think UDP cares about TTL. I think it was in the table describing IP headers in the room's Task 1 " What are Packets and Frames?" and copied over.

radiant condor
#

Hi, I think I have found a discrepancy in the information provided for room: https://tryhackme.com/room/redteamengagements

Task 7, "When will the engagement end?". The resource plan provided shows a discrepancy between the ENGAGEMENT DATES: 10/12/21 - 11/12/21 and the actual dates used later such as Post-Exploitation and Persistence: 10/24/2021 - 11/14/2021

quaint sparrow
static grotto
#

Late reply, but I am having the same problem

short plover
#

Hello I think I found a bug. I am doing Network Services 2 im on task3 and I cannot get the folder of the remote IP and I have tried closing the VMs and starting new ones still not working

sharp citrus
#

is that target machine still active ?

sharp citrus
short plover
#

I just restarted it

#

and logout and logged back into my account

sharp citrus
#

let me know new ip so i can try mount it on my pc

short plover
#

10.10.75.142

sharp citrus
#

i created /tmp/dir and used thissudo mount -t nfs 10.10.234.189:home /tmp/dir/ -nolock

short plover
#

still nothing on my end

sharp citrus
#

use sudo

#

oh sry

rugged canyon
sharp citrus
#

sudo mount -t nfs 10.10.75.142:home /tmp/dir/ -nolock

rugged canyon
#

also important lesson.. why are you only checking for none hidden files and folder/directories

short plover
#

I know the ls command should show me the file... I normally use ls -la

rugged canyon
#

also another tip

#

don't be inside the same folder you are mounting to while mounting

#

as that can cause problems with it not updating until you leave or close that terminal

short plover
#

that worked

#

thank you

rugged canyon
#

nice now you are getting closer

short plover
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

no problem

craggy sun
weak kettle
#

Hi to all you cybersecurity enthusiasts, In some rooms, I found broken links. How and where should I submit them?

placid abyss
#

submit em here'

shell orchid
#

Hey y'all, I'm a bit new here first time posting anything here, and I'm not sure if this is a bug, but I revisited the blue room just for fun and I've somehow managed to create 282 active sessions

Yes, I followed the exact steps mentioned in the room. I'm curious as to why something like this would happen

PS: I've already completed the room before. I'm not looking for hints, or answers or such; just curious as to why these many sessions are created

#

Here's what I did

## Fire up msfconsole
## setg RHOSTS, LHOSTS, PAYLOAD, stuff like that

msf6> use exploit/windows/smb/ms17_010_eternalblue

msf6 exploit(windows/smb/ms17_010_eternalblue) > run
....
# Ctrl+Z
msf6 exploit(windows/smb/ms17_010_eternalblue) > use post/multi/manage/shell_to_meterpreter

msf6 post(multi/manage/shell_to_meterpreter) > set SESSION 1 set
 
msf6 post(multi/manage/shell_to_meterpreter) > run
## Get into the session, background it to do some other stuff locally on my machine (nothing that could affect this stuff). Hop back in, switched back to powershell and it somehow got fucked. Abort session and back to running the exploit again. 

That's when this happened. The second time running the exploit

steady basalt
#

Why are the actual results hidden?


[*] 10.10.53.17:25                    - Scanned 1 of 1 hosts (100 % complete)
[*] Auxiliary module execution completed```
shell orchid
#

And no, I'm quite positive that I did not omit anything important from the description

dull tendon
#

Hi, I'm not sure whether this is a room bug or a problem with my current working machine. When I'm working on https://tryhackme.com/room/windowslocalpersistence Task6, flag13 and added UserInitMprLogonScript value to the registry according to the instruction, I cannot get a reverse shell on my port. When I checked the registry with the command 'reg query "HKCU\Environment "/s', the item didn't appear. After I added it with the command in the shell, I could successfully get my reverse shell.

median jolt
wheat fractal
#

Room does not respond to nmblookup on VPN. Only on AttackBox.

hazy tiger
wheat fractal
#

everything works but the firewall seems to be blocking any form of enumeration

hazy tiger
#

@glad badger Do we know the room maintainer?

glad badger
hazy tiger
glad badger
#

Room magician @earnest patio could be good. 😄

hazy tiger
#

Munra is truly the magician

hazy tiger
# wheat fractal

Hey Munra 👋
For when you read this, any reason why the zer0logon room would be blocking VPN connections, but not the AttackBox?

weary urchin
#

room commonlinuxprivesc task 8, first q. Might be nice to add exiting vi after the exit there 😉

also task 6, q2 is a bit funny since it refers to "what you just read" and what type of privesc it is. What we read last was to su to another user. The answer is vertical since they mean the tasks goal... but maybe make the questions reference what's actually meant 😉 (sorry for nitpicking, bored in the countryside house without a good computer lol, even typing this on my phone since I don't want to bog down my crazy zzzlow laptop with discord :D)

dawn tapir
#

Hello guys why i can not connect to the room adresse ip i have all the things setting up i am in the owasp top 10 room in command injection challenge

raw bison
hazy tiger
raw bison
hazy tiger
#

I’m not sure I follow what you mean by network

#

Are you referring to the subnet?

raw bison
cosmic ocean
#

helo everyone i don't know if it is my browser or not but a while i am getting a problem with some rooms especially older ones, the problem is the image is not appearing and when i click the place of image it says the image couldn't be loaded do anyone getting that bug or i am the only one experiencing. it really makes me feel stress there is several important rooms to me have that bug

cosmic ocean
quaint sparrow
#

I don't think it's a bug if it's imgur, it could be removed/blocked by your ISP/Country

cosmic ocean
raw bison
calm frigateBOT
#

Done!

calm frigateBOT
zealous ferry
#

Hey guys anyone done Wonderland recently? I am stuck at last priv escalation

#
hatter@wonderland:~$ getcap -r / 2>/dev/null
/usr/bin/perl5.26.1 = cap_setuid+ep
/usr/bin/mtr-packet = cap_net_raw+ep
/usr/bin/perl = cap_setuid+ep
hatter@wonderland:~$ perl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec "/bin/sh";'
bash: /usr/bin/perl: Permission denied
hatter@wonderland:~$ /usr/bin/perl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec "/bin/sh";'
bash: /usr/bin/perl: Permission denied
#

even though perl binary has capabilities set with SUID why I am unable to get the root shell?

stuck peak
molten oriole
night lodge
swift hearth
earnest patio
earnest patio
# wheat fractal Room does not respond to nmblookup on VPN. Only on AttackBox.

This is because when connecting from the VPN, you are in a different network than the server. Windows will not answer (by default in recent versions) any NBSTAT request that comes from outside the local network. In case you are wondering how to obtain the name and domain of the server, you can also rely on RDP as it uses an SSL certificate with the full name/domain of the server as shown in the image (nmap should catch it with the -A option):

earnest patio
livid escarpBOT
#

Gave +1 Rep to @swift hearth

wheat fractal
livid escarpBOT
#

Gave +1 Rep to @earnest patio

earnest patio
#

I'll add a note on the room to clarify this a bit, though.

wheat fractal
#

It's funny how it's a security update from June 16, 2016 probably due to CVE-2016-3299

#

No idea that this was a function added

supple geyser
#

It's at Layer 4 - Transport

gloomy lake
stuck peak
quaint sparrow
#

Which room?

#

What's your syntax?

#

I know which one you're on now.

#

It is.

#

it deosn't ask for a different port, it's default.

#

So the port doesn't need to be mentioned.

#

But I can see what you mean.

#

If you remove the ||port|| completly, you'll get the correct answer.

#

Are you using ipaddress or 10.10.10.2 ?

#

It's not asking for the active machine ip.

#

Yes, but which IP?

the active machine ip, or the one in the question?

#

Incorrect ip.

#

Use the one in the question, it's the one it's asking for.

novel osprey
#

guys im trying to connect to a machine using an attackbox and it gives the error

#

permission denied

#

publickey

#

i've even tried using openvpn on different machines of my own and it still gives the same error

quaint sparrow
#

Which machine are you trying to connect to?

novel osprey
#

walking an application

#

this one

stuck peak
novel osprey
#

Ty anyways

quaint sparrow
stuck peak
livid escarpBOT
#

Gave +1 Rep to @stuck peak

rough abyss
#

In the Wireshark Room Task 4

#

I believe theres a word missing, it should be "traffic can [be] both the hard part as well as the fun part,"

#

🤓 ☝️

wheat fractal
#

np gimme a sec

leaden kayak
heavy ridge
#

In the Network Services room, there's a portion that involves enumerating SMB, using enum4linux. The issue is, there's a question that asks you to identify which OS the remote server is using and there doesn't appear to be a way to do that currently, as SMBclient has changed something that doesn't allow you to gather OS info anymore

brazen raven
#

Anyone, have some problems with openvpn connection with version 2.5.7 ?

#

when I try to made some scans with gobuster, or dirbuster, connection is down.

marsh hatch
#

I will tag onto @heavy ridge 's post. You simply cannot continue in the Network Services room Task 4. God, every room, there just had to be something that stops your progress. I've given up on THM support long ago. Hope someone have a fix. So annoying. 😡

quaint sparrow
#

What happens when you don't declare a port?

quaint sparrow
quaint sparrow
wheat fractal
#

hi guys, i have a little issue with agent sudo room; i found the ssh password, but noway to etablish a connection. (i look some writeup it worked without any strange option for other peoples.) any ideas ? thanks

#

my command is just "ssh user@host

quaint sparrow
#

Are you using user or the username ?

wheat fractal
#

the username

quaint sparrow
#

what's your ip?

wheat fractal
#

wont spoil ^

#

10.10.36.132

#

and i'm connected via thm vpn

quaint sparrow
#

Is your ssh not doing anything?

wheat fractal
#

nop just connection closed by 10.10.36.132 port 22

quaint sparrow
#

Interesting?

wheat fractal
quaint sparrow
#

Does it connect right away?

wheat fractal
#

nop no connection

#

but i can ping the serv and connect via ftp without issue

#

same for the http

quaint sparrow
#

sudo ip link set dev tun0 mtu 1200

Try running that command, then connect over ssh

#

(leave your THM vpn on)

wheat fractal
#

dude

#

udabest

#

thanks 😄

#

can u quickly explain this command ?

quaint sparrow
#

It lowers the packet size sent.

rugged canyon
#

set max transfer unit of the tun0 device( the openvpn connection device ) to 1200 meaning it lowers the max size of the packets meaning it sends packets more often and it helps get the packets to and from the target machine @wheat fractal

wheat fractal
#

oh okay, thanks for answer 🙂

rigid wyvern
#

Hi everyone, not sure if it's the right channel to ask, but I can't connect to my own (private for now) room:

  • Ubuntu VM with SSH and ping allowed, uploaded from VMware Workstation to Tryhackme.
  • Started the VM (Start Machine), and can neither ping nor SSH it (other public-room VMs work fine)
    I suspect that some network changes were malformed during THM VM export, but don't have a way to check.
    What can I do to debug the issue and connect to my VM? Thanks.
quaint sparrow
rigid wyvern
quaint sparrow
#

Yeah,it will locally.

But I think you need to give it the provisions for a free user, which is 516mb.

Is that right @dusky junco ?

stuck lion
#

Anyone is having issues with the Wreath sever for sshutle not working for gitserver pivoting section?

rigid wyvern
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

quaint sparrow
dusky junco
#

So networking (i.e. what adapter you use) won't have an impact. This essentially gets stripped during the conversion process and set to what is compatible for our infra. The only thing I can imagine networking wise is for example IPTables/UFW or similar firewalling. I.E. if you have specified that only x port can be accepted from y source. Or for example, setting up an application so that it is only accessible from 127.0.0.1 or a private IP address such as 192

It's more likely that the machine is struggling to start-up services. Uploaded VMs on THM have the following resources assigned by default (unless we configure differently on our end):

  1. 512mb RAM for free users
  2. 1GB RAM for subscribers

What sort of services/applications are you running on the VM? As a good debug method, try running the VM in your VMWare with 512mb RAM and see what happens:)

quaint sparrow
rigid wyvern
# dusky junco Hey 👋

Hi Ben, thanks for your answer.
There are indeed some task-related iptables rules, but only for a single task-related TCP port, nothing to do with rerouting, SSH, ICMP, or other services, can't imagine this being the cause. As for the resources - only Nginx and backend Python oneliner, tried running with 512mb and it works fine. Tried capturing traffic from AttackBox and no success, the VM does not answer at all.

livid escarpBOT
#

Gave +1 Rep to @dusky junco

wheat fractal
#

Hi! So, I would like to know if someone else is experiencing connections errors in the room Lateral Movement and Pivoting; After completing every necessary step to perform the lab, I cant even ping the Domain Controller or any other machine in the network, neither connect to the necessary domain(http://distributor.za.tryhackme.com/creds) to obtain the credentials to go further in the room;

acoustic knoll
#

Hi, got soms probs in Network Services 2. The machine accept the ssh, but then nothing happend. Checked it wit tcpdump and there is an error with the connection.

quaint sparrow
acoustic knoll
quaint sparrow
#

By bad.

#

You should be able to

#

Did you change the permission?

acoustic knoll
#

yes i did,

#

reset my vpn, its working now 🙂

quaint sparrow
#

Good good

tranquil egret
#

Hey

#

I think that was supposed to be search instead of run in the Ice room

cobalt sky
#

Hello, in ice room task 3 question4 was a link to a Private Room RP:Metasploit. And the Hint for Question 2 was not helpfull. I think the cvedetails site got an design update.

dusky junco
tranquil egret
dusky junco
#

The path to the module might be diffferent depending on msf version. What one are you using out of curiosity?

#

that room would've been written for msf5 at the time

#

and yup that would make sense if you search for exploit suggester your first result is likely going to be exploit suggester, so selecting 0 would make sense

tranquil egret
#

ye

dusky junco
#

so perhaps the bug is that the room needs to show the path for exploit suggester for msf6, but I'l have to load up kali later to see if it's changed or not

austere yacht
#

In task6 of the Content Discovery chapter, I got the answer but got an error when I entered it. The webpage returned me the message "THM Static Labs" and the answer required was {} I got an error no matter how I entered it. How can I solve this problem?

quaint sparrow
austere yacht
quaint sparrow
#

That's the wrong answer.

austere yacht
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

pearl ridge
#

Room "Nmap Advanced Port Scans" , task 5, first answer is not working:

#

Second answer is like the first one but with one added IP and the format works

sonic willow
#

i just read the man pages and your answer is wrong

pearl ridge
#

Thanks for making me feel bad, haha! Well let me double check then! Thanks @sonic willow

livid escarpBOT
#

Gave +1 Rep to @sonic willow

pearl ridge
#

I was confused between spoof and decoy, thanks @sonic willow

nocturne stratus
#

https://tryhackme.com/room/webenumerationv2 task 12 question 1 What is the name & version of the web server that Nikto has determined running on port 80? scan shows 2.4.29 but the answer was 2.4.7 ? had to consult a walkthrough to discover the answer was wrong

#

oh ffs nvm i was using the wpscan machine not the nikto one lol

#

total derp moment on my end disregard!

kind wren
#

I need help with the Linux Fundamentals Part 3 room, I tried to download .flag.txt on the AttackBox, but it just didn't download for some reason

quaint sparrow
kind wren
kind wren
kind wren
quaint sparrow
quaint sparrow
#

Ok, you'll need to wait until tomorrow, or subscribe.

But my point with the .flag.txt

The extention at the start is a . so that makes it a hidden file.

#

So you might have thought you weren't downloading, unless you add a flag to show hidden files.

kind wren
quaint sparrow
#

I'm sure Linux Fundementals 2 covered hidden files.

kind wren
quaint sparrow
#

Yes.

kind wren
#

wait, you can use -a with wget?

quaint sparrow
#

No

#

You'd used wget http://machine_ip:port/File

Then use ls -a to view the directory and include hidden files.

kind wren
#

like, nothing about .flag.txt there

#

oh well, I'll wait until tomorrow and see if I can download and/or see the file

quaint sparrow
#

Yup

polar summit
#

So, I'm doing Linux Fundamentals part 1 and I completed everything except for the grep command

#

it's not doing any commmands not even the help command

polar summit
#

nevermind I think it was a navigation error

wheat fractal
polar summit
#

but I watched the video and tried to finish part1 all the way through before giving the answer

#

I think something might be missing because certain files and folders were missing

wheat fractal
#

ok its up to you but dont do this

#

like it wont make you good in problem solving

polar summit
#

no but I had no choice for this one

wheat fractal
#

Just get the YT session for grep and get to it

polar summit
#

grep was not working with anyting I did

wheat fractal
polar summit
wheat fractal
polar summit
#

odly enough I could not find grep's git hub page either

#

I don't have a mic

wheat fractal
#

no problem ill guide you all though'

polar summit
#

also I gotta be in tutorials since that's the only one open to me

#

i think

deep turret
#
plain drift
#

This may be a repeat, but the following room seems dead:
https://tryhackme.com/room/islandorchestration

  1. started machine. Got an IP

  2. performed nmap scan (sS, sV, A), shows only port 22 open

  3. There is no official walkthrough but this (and others) https://www.youtube.com/watch?v=uzjgG6lTO_0 shows ports 22,80,8443 should be open

  4. When I scan I see only 22
    PORT STATE SERVICE VERSION
    22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
    80/tcp closed http
    8443/tcp closed https-alt

  5. the walkthrough also shows a webpage on the default port 80, which s not working

Seems busted.

Nice walkthrough though.

kind locust
#

Its not a bug, but there is a misstype on room commonlinuxprivesc on task 9 the hint on the question "Great! Now we've made our imitation..." Is written "e 'x' ecutable" on the hint

raw bison
livid escarpBOT
#

Gave +1 Rep to @deep turret

deep turret
#

oh nice my first rep 🥳

pearl ridge
#

Room: Protocols and Servers; Task 3: The target machine is not responding as expected. It disconnects upon typing the instructed commands from the task description

#

I cannot type "host: telnet" because it disconnets

#

I found a write-up and the steps are the same that I was trying to execute

sonic willow
#

it might be something to do with line breaks in your telnet client

chrome vigil
#

In netsec challenge, on vm, after performing the port scan it doesn't display port 10021. The same command executed on attack box shows the port. Don't know what causes this bug.

misty gull
cedar needle
#

.

merry juniper
#

Task n.5, there's a misspelling error, obfusticated instead of obfuscated

slow plinth
#

Typo in the DNS server diagram on the right side of Task 4 in DNSinDetail (https://tryhackme.com/room/dnsindetail). "Authoritative" is misspelled as "Authoratative". This may cause issues given it is a misspelling of one of the question answers.

granite veldt
#

Hello, I believe I’ve filed a report on this issue in the past but the OpenVAS room at (https://tryhackme.com/room/openvas) uses an outdated Docker container from 2017 which has several issues that require manual intervention to resolve.

I would highly recommend this room be updated to use the OpenVAS “Greenbone Community Containers” as this now has full feature parity with building from source, even if not claimed as “production ready”. This is a Docker Compose solution which I’ve found to be robust.

https://greenbone.github.io/docs/latest/22.4/container/index.html

#

I’m not sure if this is the example I found originally, but this details the multiple times you need to edit the 2017 container to update feed URLs and etc, these steps would be required to complete the room in 2023: https://systemweakness.com/openvas-docker-container-setup-working-2022-all-nvts-200fbcb8bd9f

Medium

I needed to scan a lot of IPs with OpenVAS for an assignment and it proved to be a very painful experience. I had some limitations, since I…

granite veldt
#

Followup, I’ve emailed THM support via the “Contact Us” page regarding this issue

coral thicket
fresh bay
#

i have a error displayed on my screen and can't figure how to remove it?

thmVNC encountered an error:

Uncaught SyntaxError: Function statements require a function name

It's a big red box in the middle of my attackbox. Any solutions?

median hinge
#

#room-bugs #site-bugs #site-support I've been in several rooms where my progress is not being saved. For example. 'Red Team Engagements' Task 6 has been completed, but the task will not show completed and if I refresh the page it will not save my progress. This has happened over the last few days as well. Any help is appreciated. Thanks!

tender axle
#

the breaching ad room seems to be bugged in a way that I cannot access the network. I am using a Kali VM and changed my /etc/resolv.conf file. I added the nameserver to the top of the list, which helped me in resolving the IP of pxeboot.za.tryhackme.com on the terminal, but whenever I enter the site on the browser it fails. I got we're having trouble finding that site error on the browser. I checked the braeaching AD chat room on discord and followed all the pinned steps. The third step about the nslookup tryhackme.com <THM DC IP> does not work and the only soultion that the moderator (I think) recommended is that to contact support, so here I am. Please let me know if this is a right channel for this or not ?

wheat fractal
#

not a bug, just a typo

Within the Holo Network, Task 15 Paragraph 1
Last sentence says: or not and anyway misconfigurations that might allow us to escape the container
Should be any and not anyway

wheat fractal
#

another typo within the Holo network

#

Task 18, 4th section up from the Answers section

giving use code execution. Find the command used below
should be giving us code execution

lofty cliff
#

when I enter to xss lab I get (privet room) why?

wheat fractal
quaint sparrow
quaint sparrow
#

!docs verify

tropic flameBOT
chrome vigil
#

typo in linprivesc: privilege escalation: PATH

last adder
#

Hi all - regarding OpenVAS - Option 1: Install from Kali/OpenVAS repositories - has anyone found a detailed guide - I have tried a few different ways to get it installed in a Kali Puple VM deployed on KVM but I am struggling as multiple errors come up

tender axle
quaint sparrow
tender axle
#

yes i tried that.

#

the bot gives me the following error

Your message could not be delivered. This is usually because you don't share a server with the recipient or the recipient is only accepting direct messages from friends. You can see the full list of reasons here: https://support.discord.com/hc/en-us/articles/360060145013

quaint sparrow
#

You're still not opening up your DM's.

#

Just to be sure, it's @tropic flame, right?

tender axle
#

yessss

#

i cannot upload my Screenshots here

quaint sparrow
#

I know, because you need to verify 😂

tender axle
#

Oh god I'm in a loop

#

To solve 1 problem, I gotta solve three more xD
me likey

#

The bot sends me the same message in the DM as well mate. Shoould I leave and rejoin the server?\

#

I gotta feeling that might just do the trick

#

but I dont wanna loose my previous chats as well 😦

#

@gleaming shadow can you look into this please?

#

@hazy tiger

gleaming shadow
tender axle
#

Is that something I'll have to do?

#

if yes how so?

gleaming shadow
#

this setting

tender axle
#

whoaa yup thanks a lot

gleaming shadow
#

you can close them back up afterwards

tender axle
#

Thanks man kudos to you

#

much appreciated ❤️

ornate solar
#

OWASP-Juice-Shop the flag associated with the bak file doesnt show up even i downloaded the bak file as it is mentioned and tried to clear the cookies but nothing works

wild geyser
fading path
lilac trellis
wheat fractal
#

https://tryhackme.com/room/netsecchallenge
Task: 8
Description: I dont know if im wrong about this so please let me know if i have got something wrong and i will edit/remove this message as quikly as possible, anyway in task 8 it provides a link to where you need to perform a nmap scan on the provided target ip although the answer could be done with -sN it could also be done with -sI although it did not give me the flag after i performed the scan with -sI.

candid scarab
ornate solar
candid scarab
#

Room Extending your network
The site in task 6 - Network Simulator isn't available anymore
It looks like the webpage at https://static-labs.tryhackme.cloud/sites/net-simulator/?config=introtonetworking might be having issues, or it may have moved permanently to a new web address.
https://tryhackme.com/room/extendingyournetwork

granite crest
#

Hey guys: I have submitted a ticket but did not know if I also need to post here as well: In Red Team engagement task 7 pulling up the website I get the following

#

Any ideas?

granite crest
#

Also it happened on Task 8 and Task 9. Luckily I found a walkthrough video on the room on youtube.

kind locust
#

Room activerecon task 2 has a broken link on the question

tired summit
#

hello, i'm in python basics room, and i couldn't access the site which provided to coding stuff, somehow it keeps direct me to https://static-labs.tryhackme.cloud/sites/programming/python/intro-to-python/ everytime i click on view site

livid escarpBOT
#

Gave +1 Rep to @lilac trellis

tired summit
#

i tried on the other room it has the same issue

raw bison
cyan plank
tired summit
cyan plank
#

Thankfully. I'm swimming along in the room now.

tired summit
#

yea, thank you admin

worldly tapir
#

hello! can i check the status of a network here with someone from thm?

#

room hololive. it seems that the address have changed, so now it does not allow yo to connect from vpn

lilac trellis
#

What is the first subdomain discovered? > Delta > Correct answer
But the first subdomain discovered is "api"

#

Command used: ffuf -v -w ~/Partage/namelist.txt -H "Host: FUZZ.acmeitsupport.thm" -u http://10.10.219.245 -fs 2395 -p 0.1

#

ffuf version: 2.0.0-dev

#

seclists/kali-rolling,now 2023.2-0kali1 all [installed]

quaint sparrow
lilac trellis
quaint sparrow
#

So you'll get the correct answer if you do this on the attackbox.

lilac trellis
#

yeah, that's what I thought

worldly tapir
#

hi @raw bison ! i don't know if i have a particular problem or if its a general problem in the "holo netwrok". this is the current state with ips assigned to the machines

#

the vpn is assigning me an address in another subnet and i can't communicate with the machines. i already tried the message pi in #holo-network to regenerate .ovpn

raw bison
worldly tapir
raw bison
worldly tapir
#

if you can see any general problem, it would be great for the network!. while, to give the systemtime, i'm going to leave the room now and re-enter tomorrow after more hours

raw bison
lilac trellis
#

I can't post a screen shot, but I have the following error
curl: (7) Failed to connect to 10.10.90.132 port 80: No route to host

#

I restarted the target machine and it works now.

blissful reef
#

when i click on active directory it shows me it's private

celest glen
#

are you signed in on your subscribed account?

blissful reef
#

can u plz delete it so they can investigate ?

celest glen
#

buddy

blissful reef
#

im talking about something else

celest glen
#

thats not the right one

#

?