#room-bugs

1 messages ยท Page 11 of 1

clear talon
#

working for me as well thank you

steel escarp
#

idk if this was on purpose or not but in burp suite: repeater i believe that the task 8 query it gives you should be "0 UNION SELECT ALL notes,null,null,null,null FROM people WHERE id = 1" and not "ALL SELECT". at least on mine "ALL SELECT" did return anything

swift quiver
dusk rose
#

There is a typo in SSRF room task 2. Payload ending should be &=x rather than &x=

rotund raptor
quaint sparrow
vagrant moat
#

Is ubunutu 24.04.1 is the latest version

spare mirage
golden roost
#

pushing the "copy" in Read Team OPSEC room copies text "flag" instead of the actual flag.

heavy jacinth
#

Hey! I'm having an issue with the gobuster:the basics room

I followed the steps and the DNS is pointing to the machine ip and I still can't run scans or connect to the www.offensivetools.thm for completing the tasks

I did run the "sudo systemctl restart systemd-resolved" command

#

Connecting via browser shows this

unborn pulsar
heavy jacinth
#

Nope but I can give that a shot and see if that works

#

Yeah that worked

unborn pulsar
heavy jacinth
#

I see, that makes sense
the task here says that we should add it there, so i assume that there was a mistake with it?

unborn pulsar
livid escarpBOT
#

Gave +1 Rep to @unborn pulsar (current: #12 - 736)

heavy jacinth
#

I ran into another issue with the room
I tried different wordlists and still only found 2 subdomains
and the answer 2 is incorrect

I looked up a write up and they ran the same command and got 4 subdomains, i wonder if it comes back to that dns issue that I was running into?

spare mirage
heavy jacinth
livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #5 - 1743)

wraith obsidian
livid escarpBOT
#

Gave +1 Rep to @golden roost (current: #1672 - 2)

stiff coral
#

I'm on the Gotta Catch'em All! room and i had to look up what to do. The writeup says that there should be a username:password in the web page source. I can't find it. I can only see a :

spare mirage
stiff coral
#

it's the default apache page. I can't find anything else with gobuster. On the writeup screenshot you can also see a part of the default apache page

stiff coral
#

there is no app. Only the default apache page

spare mirage
stiff coral
#

no only 80 and 22 where open. Writeup also says port 80

spare mirage
stiff coral
#

oh i got it. the user and password where in between the <>

slender sun
#

Hey so I'm having a issue with Linux fundamentals part 3 whenever I try to SSH into the target machine it says the credentials listed are incorrect, the username works but for some reason the password Doesn't I'm missing something?

heavy jacinth
slender sun
#

sure one sec

heavy jacinth
slender sun
#

@heavy jacinth Here are the screenshots the IP address username and password were pasted from the clipboard

#

one sec

#

For some reason I can't upload a screenshot to this discord server is there a verification I'm missing

slender sun
#

@heavy jacinth Here are The screenshot again the username and password were copied and pasted

spare mirage
#

Reverse those two ๐Ÿ™‚

heavy jacinth
#

the command is wrong yeah

#

it's tryhackme@10.10.191.171

slender sun
#

My dyslexia got me ๐Ÿ˜‚

heavy jacinth
#

happens to the best of us lol

stone goblet
#

In the room Friday Overtime, the date in the last question needs to be updated.

radiant bane
#

Is this the right place to post if you find some faulty things regarding tryhackme rooms or would you recommend another better way?

sick kestrel
#

https://tryhackme.com/r/room/monikerlink

small error for room directions: it is listed to change the "...Moniker Link (line #12)..." but the correct line to change is on Line #18 (ATTACKER_MACHINE) of the exploit.py script

  • additionally in the script the placeholder is spelled wrong (MAILSVER) and is on line #32.

this was a cool room btw, cheers

TryHackMe

Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View.

storm canopy
#

Hello, all the machines I'm trying doesn't load or load but doesn't render, is this a known issue the support is working in now?

quaint sparrow
bronze vigil
#

why i cant send pictures guys

quaint sparrow
#

Need to verify

last loomBOT
stone goblet
#

The question is "What is the SHA1 hash of the spyagent family spyware hosted on the same IP targeting Android devices on November 16, 2022?" The date I found it referring to is October 27th 2024.

idle python
short pebble
#

Here are my screenshots as well:

short pebble
#

Also, this did not work for me after I just did it

#

Yea just to be clear, I get that we can hack our way around it as far as the room goes. we can add to the hosts file, we can specificy the IP addr in the command, but this is not what this room is supposed to be about for gobuster.

#

It also is on a track for newer people who will NOT know what to do when the instructions don't list it, additionally, it makes a very clear statement on NOT scanning by IP because you are making the scope to broad in this specific exercise as it says that the target server is running multiple sites, as well as multiple vhosts

#

it also specifically asks that you make this DNS change, so that in the network you can resolve locally and complete the questions its asking

#

by domain name mind you, not IP

#

Thats why its being listed as a "bug" I would say it would be logical that this room needs to be thought about in the lense of a newer person given where it is on the track.

#

and potentially re-worked

#

I feel like this will just lead to people looking at writeups to get past it without learning the lessons its teaching

spare mirage
#

@short pebble @heavy jacinth Yeah a lot of users seems to report the same problem recently . I tried to add domain to /etc/hosts and add -r <target-machine-IP> to the gobuster command and it seems to fix the problem ๐Ÿ™‚ . -r is used to specify a DNS server manually .

short pebble
#

Like it's not an issue for you or me it's an issue when it comes to clarity and instructions is all. I have a newer friend who is coming up behind me, and I already know he's going to get lost right here lol.

#

Which means many people will. I get they need to think ourside the box, and thats part of the hacker mentallity that needs to be learned, but the objective in this room isn't nessecarily to do that as opposed to following implicit instructions for a specific outcome.

#

I think I see whats going on here, this system uses netplan

#

So its using netplan, and has us edit resolvd, these are not jiving

#

Like I am done harping on this, just know that this system also has netplan and loads that config as well, also, if we are going to need to add the host to the /etc/hosts file we should include that in the instructions for the sake of clarity for newer people. This definitly seems like an oversight and is an easy enough fix to just edit the room and include those instructions.

#

Also list the -r flag and its uses and why it would be needed.

obsidian garnet
#

Hi. I need some help if someone have time. Its networking concepts task 7 attachbox. Doesnt matter what machine i try to reach with telnet it unable to connect

#

Could someone check if the vm is good or can someone send me the exact,working command i should run?

#

Also how can i open a ticket if i already have one active? I found like 3bug since i started

obsidian garnet
#

Telnet 10.10.1.5 7

#

I also tried it with Machine_id and ip-10-10-1-5

quaint sparrow
obsidian garnet
#

The ip of machone and the flag

quaint sparrow
#

Can you copy and paste the question?

obsidian garnet
#

Yes.but i dont want the answers,i would like to try out telnet. I would like to use the roon as intended

#

I know i can get the answers online

obsidian garnet
#

Use telnet to connect to the web server on MACHINE_IP. What is the name and version of the http server?

radiant slate
#

Hello, so I had already posted this yesterday, but I think it was the wrong channel, since I think it is actually a bug. In The VM in Room "Active Directory Basics". (but it's probably doing this on every room)

This is what happen when I hold down the ( Key.

**It's only happen when I use RDP **on a VM in THM. otherwise the key works perfectly

#

(i have an AZERTY keybord)

obsidian garnet
quaint sparrow
quaint sparrow
obsidian garnet
#

I see but the task before the question is to use telnet to connect to three different port on the machine and use telnet with these services.but it seems these services either doesnt work or they are unreachable

obsidian garnet
quaint sparrow
obsidian garnet
#

Yeah

quaint sparrow
#

Then yes.

obsidian garnet
#

They should say you have only one start and not 1 hour...

quaint sparrow
#

Well, it's both.

last loomBOT
obsidian garnet
#

It should say so. I wanted to subscribe but i am not going to pay for one year when i see bugs everywhere

quaint sparrow
#

Out of the bugs you've posted, it wasn't a bug.

Which other bugs did you find?

quaint sparrow
obsidian garnet
#

Also i dont see the split screen togle anywhere

#

Oh i see it now that it should be a 2 machine operation this time.i am sorry

#

But they should still state that i have one attachbox start/day

obsidian garnet
#

Networking concepts

#

Oh sorry.the wrong question rooms?

#

Let me see...

#

Sorry.i need to work now.but there were miltiple in the cyber security path before the network part

livid escarpBOT
#

Gave +1 Rep to @idle python (current: #2550 - 1)

obsidian garnet
# quaint sparrow Which room is this?

Searchskills:
Task2:asking about snake oil,it should be in cryptography
And netstat i dont think it should be in search skills
Task3:what does the linux command ss stand for? Its not about search engines

quaint sparrow
quaint sparrow
obsidian garnet
#

So you are saying these questions are on the right place?

#

Okay.i think it is missleading but then its not a bug

obsidian garnet
#

Now i have to wait a day because i wanted to be nice and stopped it when something disturbed me. Its prety irritsting

rugged canyon
#

remmina and xfreerdp can inject the correct keyboard layout after you login

livid escarpBOT
#

Gave +1 Rep to @rugged canyon (current: #3 - 2041)

obsidian garnet
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow (current: #1 - 3186)

quaint sparrow
short pebble
sick bough
#

Happy new year everyone! I am just starting out on TryHack Me, and I am having trouble in PreSecurity. The Split Screen will not load. I don't normally use discord, so i cannot figure out how to upload an image, but here is the text:

#

I was using TryHackMe on Google Chrome on a 2011 Imac, and then I tried Safari, and TryHackMe would not even load. I have a 2012 Macbook I will try later and see if that fixes the issue. How do I upload screenshots? Whiteboard won't let me launch it, and Im guessing I am not allowed to use outside links?

vernal pulsar
#

Hello! I have a room+attack-box-bug ๐Ÿ™‚ It is in task 4 of the last room of the Complete Beginner course, Steel Mountain, https://tryhackme.com/r/room/steelmountain
It asks you to use CVE-2014-6287 (https://www.exploit-db.com/exploits/39161) which needs a webserver to be opened on the attack box on port 80. However the attack box already uses port 80, making it impossible to complete the room without using VNC. Would it be possible to add some explanation to the task showing how to adapt the CVE script to look for the nc.exe on a different port please?

idle python
#

In Cyber Kill Chain (r/room/cyberkillchainzmt), task 2, is Email harvesting supposed to be this small? phishing attack is also bold but has the same font size as the rest of the paragraph.

idle python
#

Also found these on task 6 and task 10 in the same room, in case this is a bug.

undone lotus
#

Hello! I am new here and I do not understand how to fix this problem. Can someone tell me how I can terminate the running machine or if I can connect to the already running machine?

quaint sparrow
quaint sparrow
undone lotus
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow (current: #1 - 3196)

wheat fractal
pastel reef
#

Advent of Cyber Day 22 "Join Lab" gives this page

spare mirage
pastel reef
#

Any way I could be notified when it's fixed it's one of the last 3 labs I need to do for the certification

wraith ginkgo
#

Linux Privilege Escalation - NFS. Instuction is to compile with gcc.

quaint sparrow
wheat fractal
#

/r/room/howwebsiteswork

dry sierra
#

Hey, there seems to be a bug in room metasploit: exploitation - task 6 - on the machine "MetasploitMSFVENOM". Every time I leave it (switch to show THM AttackBox UI) and later come back to it the state has been reset to the initial state with default user Murphy. This happens also when I have a root session running and have started the elf for the exploit. If I leave the machine terminal window it soon resets and stops whatever was started. It would seem this makes it impossible to get a meterpreter session to run another exploit against for the hashdump as it automatically disconnects whenever the machine is reset to its initial state.

bleak depot
#

I have a problem with the soc simulator. I completed it correctly, 'Victory! Security breach prevented!', but I didn't receive any points or badge. Has anyone experienced something similar or knows how to fix it? Btw I earned 535 points in total.

idle python
#

Dark mode bug in room Common Attacks, task 2, same details issues also exists in task 5, task 6, and task 9.

zealous cypress
#

Hey any fix for the submit button working at all on a particular room (netsec challenge) ive got the answer in there and it wont submit at all or respond in any way, the attack box is working fine. Also I am able to enter answers into the text field well outside their normal formats.
ive tried refreshing clearing browser cache and running in both fire fox and chrome

zealous cypress
#

never mind gotter done

stone goblet
#

Windows Forensics 2, Task 5, Question 4 asks: "What program was used to open C:\Users\THM-4n6\Desktop\KAPE\KAPE\ChangeLog.txt?"
The path should be: "C:\Users\THM-4n6\Desktop\KAPE\ChangeLog.txt"

austere crystal
#

Hey there, im having some trouble joining the room "Breaching Active Directory"

#

I cannot join it, it doesn't matter I recharge the webpage, I log off and log in, it doesn't matter

#

It doesn't let me join the room

spare mirage
austere crystal
#

Nope but its a free room

spare mirage
austere crystal
#

How can I know that

spare mirage
# austere crystal for real?

Yes , if you aren't premium user you need a 7-day streak to enter networks ๐Ÿ™‚ . It is stated on the room info card ๐Ÿ™‚

austere crystal
#

I don't see that its needed a 7 day streak

#

this is the room

austere crystal
#

holy fuck, what a shitty mechanism

#

well, thanks anyway

hazy tiger
#

Oh, they left ๐Ÿคทโ€โ™‚๏ธ

weak dew
#

The answer field has 1 character less than the answer, and the room cannot be finished:

#

Networking Secure Protocols - Task 8

idle python
weak dew
#

@idle python yeah the "P" is missing, but I do not have enough character space in the answer field.

idle python
weak dew
#

@idle python there seems to be, I cannot add more than the pre-set number of characters. Nine characters are the limit for this answer (not including the brackets):

idle python
#

Or url decode the entire string.

heavy jacinth
#

you can use cyber chef if that helps to decode it

weak dew
#

@heavy jacinth the correct answer is THM{BB8WM6P} if I am not mistaken?
I've watched a tutorial just to check and the guy there entered "THM{BB8WM6P}" and it was correct as seen here:

heavy jacinth
#

so you have to shift it by another letter

#

THM{B8WM6P}

weak dew
#

In his video that is 1month old, there is a different template for the answer. Here is how it looks like:

heavy jacinth
#

Is the right answer

weak dew
#

for me, this is how it looks like and the brackets are pre-set:

#

so I can only input 3 characters before the brackets, and 6 within the brackets.

idle python
heavy jacinth
#

Yeap, @weak dew look at this output from Cyberchef

weak dew
#

Strange that it worked for him, the answer should be incorrect. Thanks again for the help @heavy jacinth @idle python !

livid escarpBOT
#

Gave +1 Rep to @heavy jacinth (current: #1681 - 2)

heavy jacinth
fossil tulip
heavy jacinth
# fossil tulip

Maybe I'm losing it but can you be specific what room? There's Cryptograph Basics, Public Key Cryptography Basics, Introduction to Cryptography and many more

#

and a screenshot would help a lot too

fossil tulip
#

Oh of course wait

fossil tulip
heavy jacinth
fossil tulip
#

Ok

#

The certificate section of the public key cryptography basics room seems to be broken

last loomBOT
lament linden
#

Someone is having trouble in the Wreath room? I click on "enter room" and nothing happens

spare mirage
spare mirage
hearty epoch
livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #5 - 1802)

idle python
visual flicker
#

Ive been stuck on this for a bit now....Lateral Movement and Pivoting room. task 1 has you input this into the terminal. BUT when that happens, I get the error message.....so what am I not doing correctly and how does this get resolved?

spare mirage
visual flicker
# spare mirage Try to add domains to /etc/hosts

the issue is when I type the command...I get the "failed to resolve interface" for lateralmovement. The instructions they give in this particular exercise are pretty vauge, which doesnt help

wide solar
#

Hi - I'm having issues with room Snort Challenge - The Basics. Trying to submit answers for Writing IDS Rules (HTTP) - when I click 'Submit', nothing happens. I first encountered this on 03/01 and since then have not been able to proceed any furhter in completing the exercises in this room

spare mirage
wide solar
livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #5 - 1821)

spare mirage
wide solar
#

Use the given pcap file.

Write a single rule to detect "all TCP port 80 traffic" packets in the given pcap file.

What is the number of detected packets?

Note: You must answer this question correctly before answering the rest of the questions in this task.

Answer: 328

still kelp
#

is there a bug at introductory networking room, i didnt solve before today but still i cant get points when i solve tasks

#

i checked again and again

spare mirage
spare mirage
still kelp
spare mirage
still kelp
#

thats why i asked, it should be in real-time but didnt

#

did i get banned or something? why that happens?

#

enlighten me

spare mirage
still kelp
spare mirage
#

Can you try to restart your browser ?

spare mirage
wide solar
spare mirage
wide solar
#

sure

spare mirage
wide solar
#

definitely no proxy or VPN on

spare mirage
still kelp
#

you believe me now?

spare mirage
#

If you restart the room you won't get the points again ๐Ÿ™‚ .

#

That way somebody could just restart the same room over and over again and build up points ๐Ÿ˜‰

still kelp
#

i know that

#

thats my first time

#

thats why i report this bug

#

i didnt solve that room before

#

i showed at first, didnt you watch??

#

i proved at the begining

#

i proved with "not completed" filter

spare mirage
#

Anyway if you think there's problem with your points , try to reach out to support ๐Ÿ™‚

last loomBOT
#
TryHackMe's Email

TryHackMe's support email address.

spare mirage
# wide solar

๐Ÿ˜ญ . Do you have browser extensions or ad-blocker ? If so , try to disable them ๐Ÿ™‚

wide solar
spare mirage
spare mirage
wide solar
#

yes - i've tried this on different PCs

spare mirage
#

Can you try to connect to a different network ?

#

I'm running out of ideas what's going on here ๐Ÿคฃ

wraith obsidian
#

@wide solar @spare mirage - Strange. Is this the correct summary of the issue:

  • only on the some questions in the room "Snort Challenge - The Basics", not others rooms/questions
  • Not VPN, no browser Add ins
  • incognito mode other browsers, other machines, reboot all tested and show the same issue,
  • Reset room progress and retry - same?
  • Issue is either no visual response or a error "An unknown error has occurred"
spare mirage
livid escarpBOT
#

Gave +1 Rep to @wraith obsidian (current: #630 - 8)

spare mirage
#

@wide solar Can you try to restart room progress or to leave and re-join the room again ๐Ÿ™‚ .

junior shore
#

not sure whether this is a room bug or not but the room Allsigns2pwnage keeps disconnecting every 30-45 min. Its a premium room, so a bit disappointed really.

#

I am using attack the box as well

wide solar
#

@spare mirage @wraith obsidian - room reset and same issue persists

spare mirage
wide solar
spare mirage
wide solar
# spare mirage Yes

done - rejoined, completed the Introduction Task 1, moved onto Task 2 and same issue

spare mirage
#

Go to Task 8 and try to complete question in Task 8

wide solar
#

not sure if this feedback helps but it seems to be isolated to this room , other rooms work fine

spare mirage
wide solar
spare mirage
wide solar
#

here is an example from a different room - this works fine

wraith obsidian
#

Sending you DM to get your THM username @wide solar

wraith obsidian
livid escarpBOT
#

Gave +1 Rep to @nocturne gulch (current: #1684 - 2)

sick kestrel
#

I think there is an issue in the metasploit: exploitation room, specifically regarding OpenVPN connections. on task 6 which requires the use of a staged rev_tcp exploit. I have confirmed that hosts, and ports are set correctly, and matching payloads are loaded to the listener. I've also tried alternative staged exploits and un-staged exploits with the same relatable issue.
For staged exploits the the listener acknowledges connection and begins [*] Sending stage (1017704 bytes) to 10.10.x.x but hangs and is stuck for more than 10 minutes.
For un-staged exploits its hangs at 0% during the wget call to the http server on attack device.

ssh to the exploit box also does not work over the openvpn connection.

just confirmed copied all steps from the attack box and it worked

viscid veldt
#

hello, in aoc 2024 task 22 - azure everyone can join? i get 500 error ..

spare mirage
#

Probably something on THM side

viscid veldt
#

Ok thanks for reply

vague hawk
#

Hey there guys I am trying to access the upload vulnerabilities webpages but it won't reach the them on my own computer or the attack box at all even with accessing my /etc/hosts files and inputting the required information

pastel burrow
#

I have an issue with the room Snort Challenge the basics Task 2. The right answer isn't accepted to the question. What is the destination address of packet 64? can you guys help?

shadow prairie
obsidian kiln
shadow prairie
obsidian kiln
#

The domain

shadow prairie
#

oh no I got redirected automatically

#

Thought that was by some dns server

obsidian kiln
#

... Why would a DNS server redirect you from an IP to a domain?

shadow prairie
#

oh, right

obsidian kiln
#

And how would DNS work in a lab environment where the same box can be deployed multiple times?

shadow prairie
#

I'm pretty new, my bad.

obsidian kiln
#

(tbf, I actually can think of a way to do that, but it's not something I've ever seen in practice kekw )

#

All good

shadow prairie
#

So what's the reason for doing that?

#

And why does the browser automatically turn that IP into a domain?

grave zinc
obsidian kiln
#

... and now I wanna go code a DNS server

obsidian kiln
shadow prairie
#

Adding the domain to a hosts file

obsidian kiln
obsidian kiln
shadow prairie
obsidian kiln
#

i.e., you need to access it via that vhost

obsidian kiln
shadow prairie
obsidian kiln
#

It's a common thing. A web server can host multiple apps. It needs a way to distinguish between them.
That gets more complex when we start adding in load balancers, gateways, other reverse proxies, etc.

#

The other reason is for TLS. The certificate must match the domain name. Redirecting clients means they don't get TLS errors.

shadow prairie
#

Thanks @obsidian kiln

livid escarpBOT
#

Gave +1 Rep to @obsidian kiln (current: #10 - 815)

obsidian kiln
#

Np ๐Ÿ™‚

storm ember
#

hi

#

having a little issue here

spare mirage
# storm ember hi

Are you sure that you're using the right machine ๐Ÿ™‚ ? Each Task in this room has a different machine attached to it .

storm ember
#

Yes I did, was able to compile it from attacker machine, thanks

sick kestrel
#

OWASP Top 10 - 2021 Room's box keeps terminating after only a few minutes

spare mirage
storm ember
#

@spare mirage I am using my real machine for my tryhackme tasks, because my PC doesn't support virtualization, so I partitioned it instead. So what are some of the cons of using my real machine for hacking. And how can I manage it to be on a safer side.

spare mirage
storm ember
#

@spare mirage was just curious to know if there are things I could do to still use it in a more safer way.

spare mirage
storm ember
storm ember
#

Hp Pavilion G6

spare mirage
#

Evem some old Pentium 4's support virtualization , you should be good ๐Ÿ˜„

storm ember
spare mirage
storm ember
spare mirage
storm ember
cobalt lily
#

I try to use Telnet but the system tell me that the connession is closed by foreign host

spare mirage
cobalt lily
#

When I try it tell me that there is a network problemi

#

And I canโ€™t give you the screenshot

#

I try again

#

No it doesnโ€™t work

cobalt lily
spare mirage
#

GET / HTTP/1.1

#

Host: telnet

#

Hit enter twice ๐Ÿ™‚

cobalt lily
#

I type get but the response is this

spare mirage
#

And there's a space in the first command GET / HTTP/1.1

cobalt lily
#

How do I Connect via Telnet?

hexed thistle
#

You have done that step (in recent the image sent)

spare mirage
cobalt lily
hexed thistle
#

You may need a host section too

#

Read the task, it probably says

cobalt lily
#

The task tell me to use Telnet the ip and the port

spare mirage
#

Host: telnet

#

Then hit enter twice

cobalt lily
#

Also Get? So I type get but if I type get and press enter it give me the same problem. How can I type the get Line and the host Line?

cobalt lily
#

Ok by typing get and also host?

spare mirage
cobalt lily
#

Ok

#

I try

#

No it doesnโ€™t work

#

Dunno maybe Iโ€™m missing something iโ€™ll try later

bold summit
#

Hi, not sure if this belongs here but here we go:
iโ€™m currently doing day 5 of AOC and I have to use burp to analyse the requests. When burp is intercepting a request and I click forward to go through, the attack box starts to freeze. I then waited for a couple of minutes and now the attack box completely shut down.

Is it a problem due to the free attack box capacity (which i understood is less powerfull than the one for the subscribers) or would this be an issue from my computer ?

spare mirage
bold summit
#

To be more precise, it froze when I pressed Forward after doing the request on the website

spare mirage
bold summit
#

Ok thank you.

Do you know if that issue is caused because of the limited power of the attackbox and would be fixed if I had a subscription or if it's caused by my PC not being powerful enough (it is a computer i use for gaming)

spare mirage
bold summit
spare mirage
livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #4 - 1863)

rough glade
#

In the "Search Skills" Room via Cyber Security 101 - Start Your Cyber Security Journey - Search Skills (Task 4) "What does BitDefenderFalx detect the file with the hash 2de70ca737c1f4602517c555ddd54165432cf231ffc0e21fb2e23b9dd14e7fb4 as?" The answer when scanned viva Virustotal is not the correct answer (I have found the answer) but the hash that is submitted gives a different result to the expected answer. The hint is Use virustotal.com but as explained the result is not correct? Am I missing something or is this answer not valid/need updating?

rough glade
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow (current: #1 - 3211)

slow imp
#

Hey , I've noticed that the dark mode isn't updating the font color for some of the texts in THM. how do I reach out to the team and let them know about this?

wraith creek
#

https://tryhackme.com/r/room/networkservices2

  • Task 3
    original: In order to do a more advanced enumeration of the NFS server, and shares- we're going to need a few tools.
    fixed: In order to do a more advanced enumeration of the NFS server, and shares, we're going to need a few tools.

also in the mounting NFS shares section theres a random line break after 'You can create'

  • Task 5
    this whole thing is a bit wonky so heres corrected

2. The process of sending mail can now begin. The client first submits the sender's and recipient's email addresses, the body of the email, and any attachments to the server.

3. The SMTP server then checks whether the domain name of the recipient and the sender is the same.

4. The SMTP server of the sender will make a connection to the recipient's SMTP server before relaying the email. If the recipient's server can't be accessed, or is not available, the e-mail gets put into an SMTP queue.

5. Then, the recipient's SMTP server will verify the incoming email. It does this by checking if the domain and user name have been recognised. The server will then forward the email to the POP or IMAP server, as shown in the diagram above.

6. The e-mail will then show up in the recipient's inbox.```
i saw more but it would be a lot of text
hazy tiger
wraith creek
#

oh true, i did not know if they were separate for a reason (first time on this topic)

wraith creek
#

https://tryhackme.com/r/room/owaspjuiceshop
using the site's dark mode makes some text hard to see
highlighted text also has this issue like in task 1, but in the opposite way since the highlighter yellow makes it hard to read the lightened text

TryHackMe

This room uses the Juice Shop vulnerable web application to learn how to identify and exploit common web application vulnerabilities.

#

(i meant to put this image)

sick kestrel
#

is this intentional in the hydra room? http responses are not notably different from incorrect and correct user/pass entries. confirmed the video walkthrough shows a different response code.

spare mirage
sick kestrel
sick kestrel
haughty shadow
#

What is the answer of the first exercise of the Junior Security Analyst Intro

#

?ยฟ

#

please help D:

lost path
#

On Extending Your Network, Task 6
On the first question I canโ€™t put in the THM{}. Iโ€™ve completed the simulator, it just says the answer is too short and to make sure I spelt it right

lost path
#

Still doesnโ€™t work

fathom ember
#

Room: File inclusion, task 5 question #2 Which function is causing the directory traversal in Lab #4?
Does not take answer file-get-contents but instead takes file_get_contents

short pebble
#

Linux Privilege Escalation Task 6:

Q: How would you use Nmap to spawn a root shell if your user had sudo rights on nmap?

#

I know how to do this already from my own real world experience, so I knew what it was looking for.

#

However, in that task, and the tasks before it. It doesn't go over this with the learner at all.

#

I think that it likely should or it's going to have to force a user to look up an answer and not learn anything.

#

Unless I am missing something?

spare mirage
quaint sparrow
short pebble
# quaint sparrow Wouldn't the user not learn something with some self-research?

I appreciate the platform and the value it brings, but Iโ€™ve noticed some areas for improvement that could enhance both the learning experience and the platformโ€™s overall credibility, especially considering it is a paid product.

From a learnerโ€™s perspective, itโ€™s important that lessons and exercises are structured in a way that provides all the necessary information to complete the tasks. Unless it is explicitly stated that the purpose of an exercise is to encourage research or exploration, the expectation is that the material will include everything required to succeed in the lesson. For paid content, learners expect a streamlined and comprehensive learning experience, and gaps in information can undermine the perceived value of the platform.

For instance, there have been cases where troubleshooting an issue, such as a DNS misconfiguration, required knowledge or commands that had not yet been introduced in the curriculum. This left learners relying on external โ€œtribal knowledgeโ€ or workarounds that didnโ€™t fully address the root of the problem. While independent research is an important skill, the platform should clearly indicate when such an approach is intended, or ensure that exercises are self-contained with the necessary resources and guidance.

From a business perspective, addressing these issues through more rigorous quality assurance and lesson design improvements would not only enhance the user experience but also strengthen the platformโ€™s reputation. As consumers, we want to feel we are getting value for our investment, and improving these aspects represents low-hanging fruit that could greatly benefit both the users and the company.

My challenge is determining where to submit this kind of feedback so that it can be reviewed in good faith by the appropriate team or room administrators. Iโ€™m sharing this feedback because I genuinely like the platform and want to see it succeed. However, as a professional in the field, I recognize that these gaps could lead others to question the credibility of the product if they go unaddressed.

My intention is not to criticize harshly but to contribute ideas that could improve the experience for everyone.

[Rewritten for clarity through ChatGPT so you donโ€™t have to dissect my ramblings]

unborn pulsar
quaint sparrow
short pebble
#

My point stands in general I think though I may have been incorrect in my assumption that particular room wasnโ€™t free itโ€™s still an over all experience that Iโ€™m referencing that I feel could be potentially improved upon.

quaint sparrow
#

That concerns me because I like the platform and if Iโ€™m able to see holes on a professional level that means that many people will as well and it tanks the products credibility when proper QA isnโ€™t considered on some of these lessons.

TryHackMe have a QA team in place to review all rooms before they're released.

But yeah, some of these rooms on the website require the user to have a look and research for themself, the greater majority of this field is self research, you'd get no where if you don't.

It's like being a Doctor, THM isn't the "We're going to teach you everythin you need to know"

quaint sparrow
#

It's not a new room.

#

Also the link is given for the user to use to research, for the answer

fervent token
#

Not sure if this is the correct channel but ... Phishing Analysis Fundamentals -> Task 4 -> "Review this Knowledge Base (KB) article from Media Temple on viewing the raw/full email headers in various email clients here. " The link behind "here" is dead.

split needle
#

Hello in:
Gobuster: The Basics
Task 2: Environment and Setup

The DNS configuration mentioned (upadate of /etc/systemd/resolved.conf) did not work on the Attackerbox I had to edit: /etc/resolv.conf
and change the var nameserver to my attckbox IP.

umbral girder
#

Hello, in room Snort Task 2, there are a couple of command lines examples that are not readable when the website is in dark mode, the font seems to not update to a lighter color.

halcyon widget
#

Hi , some rooms are not working, for ex. Snort challenges I can't click on submit to verify answers

#

Tried on other devices same

spare mirage
tropic flower
#

I discovered what I suspect is a bug in the Linux Privilege Escalation room, task 6 (Sudo). Given the task is about using sudo and other applications to run arbitrary commands, I suspect that the file "flag2.txt" should have a umask of 640 (o+rw, g+r, u-). Otherwise there's isn't any reason to use sudo at all--just a quick find command to locate the file and then running cat (or vim, or anything) as the normal user.

(Note: this is right after resetting the VM, I hadn't run anything else)

Coda: Same thing with task 8 (Capabilities)--the flag can be read without using the escalation.

steel escarp
#

the snort room the script is completely blacked out in the view

#

idk if its supposed to look like that or not, but i cant remember other boxes looking like that in other rooms

tropic flower
#

I think it's a bug with the dark mode, I noticed it on a couple other text boxes as well in a couple rooms. As a workaround, you can probably just highlight it until someone goes in and updates the dark mode CSS .

steel escarp
#

im using the lightmode for that exact reason

#

highlighting it fixed the problem and its there tho, just black font of a dark background

weak dew
#

is the introductory Hydra room meant to not give any points?

#

Also the room clock is set to 0, although you have 2 minor challanges to complete:

idle python
#

Another dark mode issue, this time in room Network Services 2 (/r/room/networkservices2), task 6.

spare mirage
tidal venture
empty kernel
#

I got a issue with the machines, when ever i start them up they just turn darkblue...

rough glade
#

Windows Fundamentals 1 - Task 3 "The Desktop (GUI) - Question 3 "Besides Clock and Network, what other icon is visible in the Notification Area?" This question/answer is very poor and does not reference this anywhere within the room text/explanation. I think this may need some including in the room text as you need to go outside of the module/room to find the answer

quaint sparrow
spare mirage
rough glade
#

Thank you

wide pilot
#

For Task 5, Question 3 of https://tryhackme.com/room/enumerationpe. Hint says to use ||/opt/snmpcheck/snmpcheck.rb MACHINE_IP -c public | more||, but on AttackBox I just get this error:
```internal:/usr/local/rvm/rubies/ruby-3.0.0/lib/ruby/3.0.0/rubygems/core_ext/kernel_require.rb:85:in require': cannot load such file -- snmp (LoadError) from <internal:/usr/local/rvm/rubies/ruby-3.0.0/lib/ruby/3.0.0/rubygems/core_ext/kernel_require.rb>:85:in require'
from /opt/snmpcheck/snmpcheck.rb:47:in `<main>'

idle python
next kiln
#

Weird Question - i finished Investigating with Splunk challenge. Got info that i did 100% of the room, but on my dashboard i got only 50% of the challenge finished, dunno why. Anyone got a solution for it or something?

spare mirage
next kiln
#

did it already, reset my progress aswell

halcyon widget
warped vine
#

Just wanted to report that the images for What the Shell? are no longer loading. When loaded to a new window, I received: The image "https://i.imgur.com/rN7YkJJ.pngโ€ cannot be displayed because it contains errors. Same error for the other images.

idle python
radiant bane
#

In
https://tryhackme.com/r/room/burpsuiterepeater task 8 Extra-mile challenge
"""
As we know the table name and the number of rows, we can use a union query to select the column names for the people table from the columns table in the information_schema default database.
"""
belonging to a Union Select attack
would say this probably is not number of rows but rather number of columns ?

warm rampart
#

Hi! I am loving the dark mode so far.

I just encountered a dark mode issue in Wireshark: The Basics | Task 2 room. Although, in the same section, there is another table with perfect text contrast.

idle python
#

The "Pre-perquisites" (yes, it is misspelled in the room) for Intro to IR and IM (r/room/introtoirandim), task 1, doesn't lead to the Intro to Defensive Security room, the URL is wrong so it leads to room search instead. IDK is that room was removed, or renamed, but the closest matching room I found was Defensive Security Intro, r/room/defensivesecurityintro.

warm rampart
#

Same as before. #room-bugs message
Wireshark: The Basics | Task 2 - Colouring Packets Text is not readable.

spare mirage
halcyon widget
spare mirage
halcyon widget
#

And Snort Challenge - Live attacks , beginning works but it stops working from Task 2 , question : what is the used protocol/port in the attack?

#

Quite odd tbh

#

Only 2 rooms not working , the rest is fine for now

spare mirage
halcyon widget
#

Task 2

#

No question works when clicking on submit

#

Team needs to review the configuration or algorithm idk

#

Same for the rest

#

Other tasks

#

And the following room

spare mirage
#

Just to make sure

halcyon widget
#

Hey man 100% it's the site , not answers

#

For example, task 2 , first answer is 328

#

On snort challenge - the basics

#

Usually if i get a wrong answer id get a notification

#

Here the 2 rooms are just bugged

#

The submit buttons are simply unresponsive

spare mirage
idle python
#

Another issue in Intro to IR and IM (r/room/introtoirandim), task 5, I believe this should be a heading like Insufficient Determination of Incident Scope.

Don't mind the red color, I added that to highlight what should've been a heading. ๐Ÿ‘

tame aurora
#

The AD basic room Task 4 just denies Phillip of access in power shell even after delegation

#

I just do as admin

spare mirage
tame aurora
spare mirage
tame aurora
#

The picture is the bug showing how the delegation didnโ€™t work. I used admin then

obsidian flame
#

you need to have the right permissions to be able to perform password resets, you can't do it for a different user without those

lament forge
#

In the cryptography hashing basics room anyone know how to get a attackbox? The VM just loads a blank screen. It says I can SSH in but I have no option to start an attack box to do so.

spare mirage
dense tiger
#

for room nmap01, Task 4, second last question, the regex filter is buggy that simply accept computer as answer even though the correct answer is computer5. Tried reset progress and the bug is reproducible.

spare mirage
dense tiger
livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #4 - 1953)

spare mirage
# dense tiger Alright. But I do suggest make the verification filter stricter for this questio...

Well , yeah , you're right ๐Ÿ™‚ . Same happens in OSI room where it asks for a specific layer but since the logic works the way it works even if you input just layer it will accept the answer , instead of using the correct one, ex : layer 1 , layer 5 , etc. ๐Ÿ˜„ .But if the logic would look for a 100% match many users will probably become stuck with incorrect answers because of small typos and stuff , so I completely understand why this works the way it works ๐Ÿ˜„

dense tiger
#

the same room nmap01, task 7, question 1: "Which TCP ping scan does not require a privileged account?" the given answer is "tcp syn ping". However unprivileged user can use both SYN and ACK ping, just that they will fallback to Connect scan. This answer confuse me a lot, question 2 is similar too. Official documentation states the same thing too: "only the privileged user root is generally able to send and receive raw TCP packets. For unprivileged users, a workaround is automatically employed whereby the connect system call is initiated against each target port."

halcyon widget
#

Tried resetting and exiting but same thing

#

I'll send an email to support

spare mirage
halcyon widget
#

Forget it, you don't understand

#

Thanks for trying

spare mirage
halcyon widget
#

I explain that the problem is technical but you don't understand it

spare mirage
halcyon widget
#

Forget about that, when you answer a question in general and click on submit what do you get?

#

You get woop woop if you're correct, and a red message if incorrect

#

In the 2 rooms I mentioned none of that works

tough parcel
#

Hello discord mods.
I believe this hint should be for the second question check it our in Snort room Task 8

spare mirage
halcyon widget
#

I know man, I've just been telling that there are bugs in both rooms

#

I don't expect them to let me give wrong answers

spare mirage
idle python
#

Another dark mode issue, this time in Introduction to SIEM (r/room/introtosiem) on task 3, Log Sources and Log Ingestion. The logs are pretty much not visible on dark mode.

halcyon widget
livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #4 - 1968)

idle python
#

Small dark mode issue in Intro to Detection Engineering (r/room/introtodetectionengineering) task 6.

bold lodge
#

On https://tryhackme.com/r/room/pythonbasics im on task 7 Loops, and I got the flag: THM{LOOPS_WHILE_FOR} , but the flag says its incorrect when I enter it in, please help... ;-;

TryHackMe

Using a web-based code editor, learn the basics of Python and put your knowledge into practice by eventually coding a short Bitcoin investment project.

cobalt lily
#

I have this problema

spare mirage
# cobalt lily

You need to hit eneter twice after specifying the host header don't wait for a connection to time out

cobalt lily
#

Ok

#

Thanks it finally worked

spare mirage
cobalt lily
#

Now I have this problem

pliant mist
spare mirage
# cobalt lily

Make sure that you're using the correct machine ๐Ÿ˜‰

cobalt lily
#

I think the problem is with the server

#

Itโ€™s unusual maybe itโ€™s a bug

paper grotto
#

intro to lan's question's (What is the range of a section (octet) of a subnet mask?) answer; 0-225 or 0 to 225 gets the error message

cobalt lily
#

The target machine is alive

paper grotto
livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #4 - 1979)

pallid breach
#

Hello, guys. I have a big issue here. I'm trying to connect to OpenVPN, and it connects successfully, but it only works with the IP of the "OpenVPN room" to test if you are connected or not. Up until this point, there is no issue. The big and strange problem is that when I try to access the IP of any room except the "OpenVPN room," it keeps loading in the browser and I cannot access it. Any fix, please?

spare mirage
pallid breach
#

i tried and nothing happened

spare mirage
#

Maybe it doesn't have open web server or it is on non-standard port

pallid breach
#

owasp top 10 2021

spare mirage
pallid breach
#

so, what can i do

quaint sparrow
#

It has loads of webservers.

spare mirage
pallid breach
#

i will try that and let u know

#

ty bro

spare mirage
charred spoke
#

Anybody know how to connect correctly to the VM Machine from Intro to Malware Analysis Room through OpenVPN access.

I tried connecting with the credentials shown in the task instructions, but it wouldn't connect when I tried to connect through ssh with the command:
ssh ubuntu@<ip-address>
and input the pasword 123456 as shown.

Is there some other service I have to connect with?

spare mirage
wheat fractal
#

hi im new and i tried to connect on the vpn try hack me with open vpn but there is an error and i dont know how i can make for cancel her

#

2025-01-12 03:14:30 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2025-01-12 03:14:30 Note: cipher 'AES-256-CBC' in --data-ciphers is not supported by ovpn-dco, disabling data channel offload.

spare mirage
wheat fractal
#

i already do that

#

but in the EU 2 and 3 file there is nothing so i tried on 4 and its the only one who works

wheat fractal
#

open vpn is connected

spare mirage
# wheat fractal i have to connect my kali linux too ?

You should run VPN only only on your Kali VM if you want to use it . Don't run VPN on both Windows and VM at the same time . Sometimes those VPN server may be down for some reason ( maintenance,etc. ) , so that may be the reason why EU-4 is the only one working right now ๐Ÿ™‚

wheat fractal
#

this is not good ?

spare mirage
wheat fractal
#

i cant past screen shot

spare mirage
wheat fractal
spare mirage
wheat fractal
#

bcause now i have ubuntu kali and other on my computer

spare mirage
misty gull
#

๐Ÿ‘‹ Looks like the whois entry for the domain used in https://tryhackme.com/r/room/webosint has been updated; The phone number contained is not the once that T2:Q2 is expecting.

TryHackMe

Conducting basic open source intelligence research on a website

spare mirage
charred spoke
livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #4 - 1998)

fringe creek
#

on Vulnerability Scanner Overview room task 6, I can not seem to find any high severity vulnerability ๐Ÿ˜ฆ

fringe creek
#

TY

tame aurora
livid escarpBOT
#

Gave +1 Rep to @obsidian flame (current: #214 - 34)

obsidian flame
#

it could be installed on the host but not imported in that user session

tame aurora
tame aurora
#

Iโ€™m sorry about the eyesore

obsidian flame
# tame aurora This

no worries, what i am saying is to run as administrator, input Philip's credentials then run the module. I don't think you can run that module without your session being an elevated one. run as administrator is slightly different than asking you to run the command as the Administrator. would you like me to expand on it or did you get the gist

spare mirage
#

You will be able to upload images after you verify . Follow instructions from the link below ๐Ÿ™‚

brazen hedge
tame aurora
spare mirage
#

What's the problem in Task 5 ?

brazen hedge
spare mirage
# brazen hedge In fact there is no problem I'm an idiot

You're confusing me buddy ๐Ÿ˜„ . Open up the file the Task tells you to open . First line will tell you the log rotation frequency , 2nd line should tell you number of rotations . I can fire up the VM and provide with a screenshot if you need to ๐Ÿ™‚

brazen hedge
#

Yes it's ok I just understood I thought it was linked to an error but not at all it was just me

spare mirage
spare mirage
livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #4 - 2015)

stuck topaz
#

all done

stuck topaz
full sonnet
#

@spare mirage in the room Content Discovery in the junior penetration tester path Task number 9, the wayback machine url has changed since the last incident on internet archive, but the task still wants the old url.

spare mirage
#

Just copy that to answer box

full sonnet
#

oh sorry my bad

#

yeah i figured it out prom the new link on the website

spare mirage
full sonnet
#

thank you โค๏ธ

spare mirage
fierce kite
#

Hi, experiencing automatic VM termination (not attack box) (within 10- 15 minutes of deployment) multiple times. Room - windows incident surface

#

Additionally the Dashboard counter Continues but RDP fails, also the RDP screen shows shut down screen.

#

And for that reason reconnection also fails.

haughty hornet
#

I also had this happen twice last night. I was working on the silver platter room when it happened.

gloomy sphinx
#

Hi,
Could anyone help me with my copying issue?
I use THM attack machine for all my tasks but a lot of times I canโ€™t copy data/text from the attack machine to my host(mac). Itโ€™s really hard & non productive to type out file hashes ๐Ÿฅบ

Iโ€™m new to this all, kindly help me.
Example room - Wireshark: The Basics

gloomy sphinx
#

SUPER!!! Thanks KGB!

spare mirage
#

Don't say thanks to me , say thanks to @novel carbon ๐Ÿ˜„

livid escarpBOT
#

Gave +1 Rep to @novel carbon (current: #19 - 502)

novel carbon
spare mirage
livid escarpBOT
#

Gave +1 Rep to @novel carbon (current: #19 - 503)

junior shore
lone meadow
#

i was doing the "File Inclusion", on the 5th task, first question. i copy pasted a "wrong" (according to what i was getting "File Content Preview of ../../../../etc/passwd0x00") answer but it accepted it. idk how to explain it better without screenshots but i was not seeing /etc/passwd/ with the answer i gave lol

ocean quest
#

Hi,
I think that the Aurora EDR room is currently not working correctly. When i try to run the batch script to spawn the events, I get multiple errors and none of the events i need to complete the room. Checked videos for method and i end up with another result. Could i get some help with this please?

ivory osprey
#

Yes mate

#

You can get all the best guide you would be in need
@ocean quest

spare mirage
lone meadow
#

and /.

#

or maybe i did it wrong, w/e lol

silk valley
#

I think I can get you something else

spare mirage
real yoke
misty gull
spare mirage
serene kite
#

hi the view site button doesnt work

#

Failed to load resource: the server responded with a status of 429 ()

quaint sparrow
#

Which task, they all work for me, tried different browser, disable extentions?

serene kite
quaint sparrow
#

I'm using Firefox

serene kite
#

also*

quaint sparrow
#

Do you have av blocking?

serene kite
#

checked an acc with no extensions didnt work
checkd with edge browser didnt wrk
but with firefox it works

#

was using chrome browser

#

guess now llbe usin firefox)

#

thx for help

chrome pier
#

Hello Team

#

I have issue with room the machin is not starting

spare mirage
chrome pier
#

you mean on this one

spare mirage
chrome pier
#

504 Gateway Time-out

spare mirage
#

If the machine still doesn't start after 15min terminate that instance and start a new one ๐Ÿ™‚

chrome pier
#

same issue

quaint sparrow
chrome pier
#

i just open the link

#

the machine did not started

quaint sparrow
#

So what populated the IP?

chrome pier
#

I cliked on start machine an did not pop up nothing

quaint sparrow
#

Green start machine button, and NOT the attackbox?

chrome pier
#

yes

#

maybe I need to open the vpn

lucid peak
#

Donโ€™t you see in the left you have to wait for a bit.

chrome pier
#

nothing

#

I cannot attach the screen shots hear ?

spare mirage
chrome pier
#

I tried different Browsers same issue

lucid peak
#

Share the screenshots if you can

#

In dm

chrome pier
#

I open in Edge

#

now I am doing the task

jade spear
#

CI/CD and Build Security room isn't feasible with information given.
Do you know if an update will be carried out ?

wraith creek
rocky atlas
#

task 5 the answer on github wont even fit.

#

so i am incapable of completing the room

#

Match all lines that start with $, followed by any single digit,
followed by $, followed by one or more non-whitespace characters

#

^$\d$\S+

misty gull
spare mirage
haughty cipher
#

Hello everyone,
i currently try to solve the Lab Work in the "Incident Respone Fundamentals". Unfortunately the task site doesn't load in the wright way. Can somebody please help me?
Thanks ๐Ÿ™‚

#

is it possible to reset the site?

haughty cipher
quaint sparrow
haughty cipher
#

i only see the Katie Smith Email and nothing else

quaint sparrow
#

Maybe your page?

What are you browsing on?

haughty cipher
#

chrome, i will test it in a other browser

#

ah on firefox it works

#

Thank you for your quick help ๐Ÿ™‚

quaint sparrow
#

That's ok

#

If you click this (Right click) it will open it's own window.

haughty cipher
#

ah i see, thank you for the tip

steel sentinel
#

I think there's a bug in the room Incident Handling with Splunk. I'm in Weaponization Phase, i found the email address but it won't let me input it, there's a character missing in the answer. I've searched online for the answer and it's the same I found, but still it won't let me type it.

spare mirage
misty gull
white reef
#

Hello, I don't know if it is a bug or just I don't understand what I'm supposed to do, but I have a problem with Task 8 Challenge in Networking Secure Protocols on Cyber Security 101 Pathway. I did everything that is mentioned to do, loaded ssl-key.log and nothing changes in Wireshark. I spent about an hour looking at giberish packets. Then I surrendered and check out HINT, which pointed me to packet 366. And I carefully searched for any thm{} flag or password and haven't found. Uploading ssl-key.log whatever it should do - it doesn't

white reef
#

Now it's working as it should, I noticed the difference just after hitting OK this time

plucky stone
#

.

#

Hello I need help, I am currently at Linux Fundamentals part 3 of pre security and it seems like my machine won't work, i entered the ip adress of the room but it seems like i cant enter my password for some reason i try typing but it wont type

hazy tiger
woven oak
#

Hello everyone I had a question what would yall do when you answer a question hit submit and it gives you an error or the submit bottom wonโ€™t work

odd thistle
#

holla

vivid lotus
#

in cyberlens i first did using vpn got an error so i tried it with attackbox and still the same issue

#

[] Started reverse TCP handler on 10.10.226.206:4444
[
] Uploading the MSI to C:\Users\CYBERL~1\AppData\Local\Temp\1\EkGWFYFXoMKS.msi ...
[] Executing MSI...
[
] Exploit completed, but no session was created.

#

i tried the manual method also using msfvenom but still the same issue

foggy bronze
#

Hello! I am currently at Linux Fundamentals 2 and here I should enter the password "tryhackme", but it always says "permission denied, please try again". How could I solve this?

mellow bolt
#

Also it's case sensitive, so if you're unintentionally capitalizing any letters, don't do that either.

foggy bronze
#

Thank you. My bad, I used the wrong IP.

frail berry
#

idk to report this to #room-bugs or #site-bugs but this color scheme in dark mode makes it hard to read. btw the room is the common attacks room

spare mirage
woven oak
#

Hello everyone I had a question what would yall do when you answer a question hit submit and it gives you an error or the submit bottom wonโ€™t work

mellow bolt
woven oak
#

But when I hit the submit button wouldnโ€™t it tell me Iโ€™m wrong

#

But your right thank you

rugged canyon
#

if it does not work after that it is check if the answer is correct

woven oak
#

Ok thank you

vivid lotus
#

Idk the names

spare mirage
vivid lotus
#

i also tried metasploit and did completely with it like how tyler the author of it did

#

but still i got the same issue

sterile bridge
#

ROM bug

vivid lotus
#

here i cant send i think

tulip cargo
#

in the room with burp suite : the basics, at the task 7 clicking on the last Burp Suite underlined before the questions, it shows a pop-up not in the right place ^^'

vivid lotus
livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #3 - 2149)

vivid lotus
#

i have uploaded the ss

spare mirage
vivid lotus
#

that also i did

#

i will see if i have ss

#

i dont have the ss of output

#

but the reciever was not able to recieve

#

both had same port numbers also

spare mirage
# vivid lotus

No , I haven't used rev shell payload , I used widnows/adduser payload to generate a .msi executable since we already have Install elevated priv as Cyberlens user

vivid lotus
#

ok

#

i saw in many writeups and videos they had refered this method so i used this

spare mirage
vivid lotus
#

ok

#

i thought there might some issue with the room

#

so i raised it here

#

thank you @spare mirage

livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #3 - 2150)

spare mirage
vivid lotus
#

ok then i will try different methods

spare mirage
# vivid lotus ok then i will try different methods

Try to consult with some write-up if you're stuck . I can confirm it that windows/adduser payload as .msi worked for me as a vector for privesc ๐Ÿ™‚ . Also , disclaimer, name of the privilege that our have isn't exactly Install elevated , I can't remember the exact name but it is something along those lines ๐Ÿ˜„ . Feel free to reach out later if you're going to try this vector maybe we can figure something out . Also , it's maybe better to continue this conversation in https://discord.com/channels/521382216299839518/522158539129618453 ๐Ÿ˜„ .

vivid lotus
#

ok will let u know in feb now preoccupied with studies

spare mirage
empty kernel
#

im not sure if im right, but in Active Directory Basics Task3 Question3 are the spaces missing....

rain horizon
misty sable
#

Hello, there is a "bug" on room Network Services 2 task 9. In this task you need to connect to a sql server, using a command, and you can't do that on the attackbox because it doesn't come with the default-mysql-client... and you can't install it either as a free user, because the attackbox doesn't have internet access.

cold fog
#

hello, pretty sure sessionmanagement room is bugged. after logging in with a newly created account on the webpage, I get 500 error and no session cookie

#

based on the room instructions, shouldn't behave this way. I am unable to complete the room

obsidian garnet
#

Hi. I have a problem in the windows command line room. certain keys (like h) dont work in the attachbox.what could be the problem? And i also cant connect to the severs from my pc

odd hearth
#

hi, in the room Enumerating Active Directory , the attack box setup for the vpn is wrong it's configured for the room before with the wrong ip. in ex: 10.200.148... instead of 10.200.33... dont worry i made it work, just for other.i changed the distant server adress.

gilded belfry
#

Snort Challenge - The Basics -> Task 8 -> Question 4: It asks to create a rule to detect packet payloads between 770 and 855 bytes, but the correct answer takes into account only packets with TCP payload. Shouldn't UDP also be taken into account with this phrasing? (basically I used "ip" in the protocol field of the rule but if I used "tcp" instead I would've gotten the correct answer)

livid escarpBOT
#

Gave +1 Rep to @hazy tiger (current: #6 - 1436)

neon echo
#

Guys, I can't connect the site to Kali Linux. Has anyone experienced the same problem before?๐Ÿ™‚

spare mirage
earnest jetty
quick blade
#

In "Web Enumeration" room (https://tryhackme.com/r/room/webenumerationv2) Task 12, Question 1, the expected answer appears to be to long. I'm supposed to use nikto to find out version of web server running on port 80, but version that I get and see in other people walkthroughs is "Apache/2.4.7" which is too short for the answer? I tried terminating and redeploying both target and attackbox, refreshing the page and copy-pasting answer from discord, even accessing it from my smartphone, but I get the same result.

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

viscid veldt
#

Hello everytime i try this room ate aoc 2023 task 17 i get this error i'm doing something wrong?

heady portal
#

Investigating Windows
https://tryhackme.com/r/room/investigatingwindows

Task 1
During the compromise, at what time did Windows first assign special privileges to a new logon?

Answer format: MM/DD/YYYY HH:MM:SS AM/PM


HH is not accepted as input. But it works with the format** H**:MM:SS

Solution:
Remove one "H" from the Answer format.
Resulting:
Answer format: MM/DD/YYYY H:MM:SS AM/PM

rain horizon
#

looks like a typo in wiresharkthebasics

pliant bluff
#

try running it with "python" instead of "python3"
had the same issue with missing modules. gave it a shot with just "python" and it worked.

fair wedge
#

In the "Nmap Basic Port Scans" room, on task 6 I am asked to run a UDP scan against a target VM. But the scan it tells me to run does not return any port numbers.

#

I had similar problems on some of the earlier tasks, but I was able to get around it by scanning all ports or restarting the target VM

fair wedge
#

It worked after trying the scan again a few minutes later!

spare mirage
sharp topaz
#

With the new dark mode, I found this.

#

On mobile browser.

fair wedge
livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #2 - 2255)

pine sigil
#

Networking Secure Protocols task number 8!!! The input field is not long enough to accept the answer. I am really certain I got the right answer from packet 366. Answer is THM{7BB8WM6P} but input is {***} 2 characters short. I tried copy and paste also.

idle python
pine sigil
livid escarpBOT
#

Gave +1 Rep to @idle python (current: #504 - 11)

idle python
pine sigil
shadow citrus
#

at wireshark:basic u need to highlight the words inorder to see it

stable harness
#

Hello insecurerandomness rooom task 5 is broken

#

How can I pass the task 5 if it is not working? I cannot get the answers to the questions?

idle python
ripe fable
#

Iโ€™ve been stuck on the Windows Fundamentals 1 room for a few days now because another user is connected to the remote computer. Is there a way around this or do I just need to keep trying?

sick kestrel
runic stag
#

I'm having the same issues, how will I do? I have terminated the machine and started it back but still the same thing
The answer keep showing as wrong

#

You rebooted your entire browser?

ripe fable
#

this is the error message i keep getting

sick kestrel
round ibex
#

hello i got an issue with an attackbox, everytime i try to netcat the Target IP Address it wont work at all i tried doing this on my VM and on the actual attackbox suscription and tells me it cannot (https) on my VM, and nothing on the actual attackbox no response.

spare mirage
round ibex
#

Am i doing this wrong lol i was following a walkthrough tutorial

#

sorry im a bit new on this

spare mirage
round ibex
spare mirage
round ibex
#

task 8

spare mirage
round ibex
#

i made sure to start the machine on that page

#

so not sure why lol

spare mirage
# round ibex

You need to run command from the 2nd terminal on vulnerable website and you should change IP in it to point to your AttackBox IP

round ibex
#

ok ill try this

round ibex
livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #2 - 2292)

wise hinge
spare mirage
wise hinge
#

It's calling api in a loop

#

Due this this reason my submit button isn't reaching to the actual endpoint and nothing happens?

#

FYI it's pulling cpu usage image of kali virtual machine which blocks other API request with Too Many Request error

spare mirage
wise hinge
cobalt lily
#

Strangely the system doesnโ€™t ask me the username and password

#

It put out this thing

#

Iโ€™m doing post Office protocol on protocol and servers

cobalt lily
#

KGB?

spare mirage
cobalt lily
#

Protocols and servers

spare mirage
cobalt lily
#

Post Office protocols (POP3)

spare mirage
# cobalt lily

You need to manually specifty username and password after connection

livid escarpBOT
#

Gave +1 Rep to @cobalt lily (current: #2609 - 1)

cobalt lily
#

Ok but it doesnโ€™t ask them to me

spare mirage
#

PASS D2xc9CgD

cobalt lily
#

Ok it doesnโ€™t ask them to me

#

Look at the photo

spare mirage
#

It shouldn't ask you

cobalt lily
#

Aaaah

#

K

spare mirage
cobalt lily
#

Thanks

#

No

#

I insert manually frank etc

#

But it doesnโ€™t work

spare mirage
cobalt lily
spare mirage
cobalt lily
#

As you see I type โ€œfrankโ€ but it simply doesnโ€™t work

spare mirage
cobalt lily
#

Ok I try

#

Thanks

#

And then I type Stat

#

And it tell me

#

Ok

#

It doesnโ€™t give me the information

spare mirage
cobalt lily
#

Ok

spare mirage
cobalt lily
#

I solved

spare mirage
shadow prairie
#

https://tryhackme.com/r/room/linprivesc
Task 3: I can't connect over sh, I'm using sudo ssh karen@<the machine's ip> and it just keeps loading. Yes, I can ping the box, Yes the vpn is setup, yes the interface is also shown in ifconfig.

TryHackMe

Learn the fundamentals of Linux privilege escalation. From enumeration to exploitation, get hands-on with over 8 different privilege escalation techniques.

shadow prairie
spare mirage
shadow prairie
#

kali

#

default config, but even without sudo it does this

#

openvpn

spare mirage
shadow prairie
shadow prairie
#

But yeah it's supposed to ask me for a fingerprint and then to provide a password but it doesn't even do that, fault might be on my end, i'm going to see if updating makes a difference.

spare mirage
shadow prairie
spare mirage
shadow prairie
spare mirage
shadow prairie
spare mirage
# shadow prairie

Hm , strange , can you access the machine in split-screen view on THM website

#

It should be accessible

shadow prairie
#

Thanks @spare mirage

livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #2 - 2300)

spare mirage
quaint sparrow
tulip furnace
#

https://tryhackme.com/r/room/breachingad
Task 1
Command "nslookup tryhackme.com <THM DC IP>" gives
";; communications error to <THM DC IP>#53: timed out".

"nslookup thmdc.za.tryhackme.com <THM DC IP>" is working.
I did "systemd-resolve --interface breachad --set-dns $THMDCIP --set-domain za.tryhackme.com" but
"nslookup thmdc.za.tryhackme.com" is not working as well. Thank you for help in advance!

TryHackMe

This network covers techniques and tools that can be used to acquire that first set of AD credentials that can then be used to enumerate AD.

quaint sparrow
tulip furnace
quaint sparrow
tulip furnace
quaint sparrow
tulip furnace
quaint sparrow
tulip furnace
quaint sparrow
tulip furnace
#

So now the room is locked?

quaint sparrow
#

No, you can use options to leave the room and get a different subnet after 15 mins

tulip furnace
#

Alright, I will try, thank you

shadow prairie
# quaint sparrow You still doing this?

Right now i'm using the box on the site but on the sudo privesc task it crashes when you do the gtfobins nano method...unfortunate, think i've had to restart 3 times now

cedar bane
#

Hello! Room Cyber Security 101 Networking Networking Core Protocols HTTP(S): Accessing the Web - the message I got was <html>
<head><title>400 Bad Request</title></head>
<body>
<center><h1>400 Bad Request</h1></center>
<hr><center>nginx/1.18.0 (Ubuntu)</center>
</body>
</html>
Connection closed by foreign host.

#

I rezolved the puzzle with the browser but I want to know if I did something wrong

spare mirage
ripe fable
sick kestrel
#

And which task

gilded vortex
#

In wreath machine, I am attempting to exploit the target but have been unsuccessful so far. I can ping the target, but I am unable to obtain a shell. Could you please assist me?

#

@spare mirage

spare mirage
cedar bane
spare mirage
# cedar bane

Your request has bad formatting and you're missing host header which is mandatory by HTTP/1.1 specification ๐Ÿ™‚

#

GET /flag.html HTTP/1.1 Host: telnet

#

Then hit enter twice

cedar bane
livid escarpBOT
#

Gave +1 Rep to @spare mirage (current: #2 - 2322)

calm lion
#

For the cyberchef basics room. The final anwser for task 5 practice, practice, practice. What is the URL encoded value of thm dot com/r/careers the anwser is returning errors. Even though I've encoded it correctly in Cyberchef.

calm lion
#

so i think the questions answer was supposed to be the encoded version, but the actual answer is the same link.

#

i feel like the room wanted the output answer, but instead the correct answer is the input value?

#

this is what it counts as the correct answer.

spare mirage
calm lion
#

yet its asking for the encoded version (output).

#

otherwise i completed the room without issue.

icy fog
#

In the XSS moudle from THM Junior Pentester, in the last challenge there is a little setting, which prevents us to complete if not using attackbox, since attackbox is insanely laggy would be nice if it was fixed. When you try to fetch it back to your IP you get the packet blocked and this is setting is doing it: Referrer Policy: strict-origin-when-cross-origin, if you do an SSRF combined with the XSS you can get a 302 response, however the session cookie returned is not the one it should return for the challenge to be completed ๐Ÿ˜ฆ

#

or am I just slow in the head?

loud heron
#

Room: Advanced ELK Queries
https://tryhackme.com/r/room/advancedelkqueries
Task 5, Question 1:
Including the misspellings, how many incidents has JLim handled where he misspelt the word โ€œtrueโ€?
The wording on this question is incorrect, it should say something to the effect of:
Including the misspellings, how many incidents has JLim handled where he included the word "true"?

Reasoning:
Mis-spellings only of the word "true" is single digits. Answer is 3 digits. Correct spellings of word "true" is 3 digits.
The question specifically asks ONLY for misspellings. Twice ^_^

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

ripe fable
spare mirage
sick kestrel
#

connecting to itself

ripe fable
#

so I dont need to login to anything?

#

gotcha mb

spare mirage
sick kestrel
ripe fable
#

ok that was my next question, sorry ab that

sick kestrel
stiff stag
#

I'm having issues with submitting an answer to a question in Investigating Windows; when I click "submit," absolutely nothing happens. not even an error.

#

tried in both Chrome & Edge, same issue

spare mirage
stiff stag
#

it's a question asking what time john last logged in, i follow the format, click submit and nothing happens

#

so i tried the next question and the same thing happens

#

sorry the room is called, Investigating Windows

dim atlas
teal patio
#

Hello I have seen several posts regarding issues with Aurora EDR room. Are you aware of issues and are working on them?

#

The script does not produce logs needed for tasks

#

I saw it being reported on 14 of january

long hatch
#

Hi, how can i report a bug in room?

spare mirage
long hatch
#

Lately I was doing new room Light. So when I'm sending my SQLi to find out what is the name of the table in the database I was using payload:
โ€˜ UNION SELECT name FROM sqlite_master WHERE type='table
I got a response "Ahh there is a word in there I don't like :("
Query should be corect but it did not worked. I tried other many different payloads and was going crazy. Finally I checked walkthroughs of it to find out that the working payload was:
' Union Select name FROM sqlite_master WHERE type='table
And the response was "Password: <name_of_table>"
I think that there is an error with the filter set before SQLi is being executed on the database. becasue if I use anything other then "UNION SELECT" or "union select" or mix of those, a SQLi is executed correctly. Doesn't matter how it is typed, it just cannot be written with all big or all small letters. It doesn't matter how I write other parts of the command like FROM and WHERE -> they can be any mix of big and small letters.
Going back, I think that this filter is looking for "UNION" or "union" or "SELECT" or "select" and it is sending mentioned response brefore my command can reach the database. Therefore, even though I was right I couldn't complete the task.

Maybe it should be like that, then please correct me. Could it be me that I did not though of that but I think something is not right there

#

Also,
If I would send just "UNION" or "union" or "SELECT" or "select" to the server I would get this repsonse: "Ahh there is a word in there I don't like :(".
Not even that my query is invalid (it would not fit the query on the database)

#

If I would send "unioN" or "Union" or "seleCT" or anything other then ("UNION" or "union" or "SELECT" or "select") I would get response: "Username not found." -> it is not registered by filter

long hatch
#

soo, is this a bug?

loud heron
quaint sparrow
#

Please don't cross post.

wheat fractal