#room-bugs

1 messages · Page 18 of 1

obsidian kiln
#

Perfect

wheat fractal
#

?

gleaming shadow
#

is it normal that the flags don't work as passwords for the named users on linuxagency?

obsidian kiln
#

Honestly? No clue.
That's usually a routing thing, but given it's just AJAX that isn't working (i.e. you can access the site normally), it's unlikely to be at that level

wheat fractal
violet mason
#

cannot su into dalia's account with her flag in linuxagency room, bug or am I missing something?
restarted machine and the same problem

faint vault
#

Linum: Local Enum - Every time I get a reverse shell it works for around 2 minutes then dies and wont allow me to spawn another one. have had to terminate the box and redo

tall pivot
gleaming shadow
#

have you tried refreshing?

tall pivot
#

Yes, so many time

#

I'm afraid I destroyed something, before it worked and I did something and it did not work. LOL

main iris
#

hello ,everyone,the room Linux Agency,task 4,i got dalia's flag ,but i can't use the flag auth...why?

#

but the task 4 dalia's flag answer is corret

grim yoke
#

It's intended

#

I think

main iris
#

what?

main iris
#

haha ,i got it.thanks

glad badger
#

su dalia from viktor is not the intended path in the Linux Agency room. 🙂 @main iris

arctic bison
#

jabba

unkempt horizon
#

Hello, I'm working my way on the complete beginner learning path. But lastly, any room mark complete at 100% doesn't appear on my dashboard. Do you know how to fix that ?

eternal summit
unkempt horizon
#

Can you tell me a little bit more ?

eternal summit
burnt shell
unkempt horizon
eternal summit
#

I don't know. I didn't change it. I'm just a discord moderator.

#

It will be changing soonish

gleaming shadow
unkempt horizon
#

Ok then I'll continue walking on the path

tall pivot
faint vault
#

doing the linux priv esc room and on my 3rd reset in less than 10 minutes. I'm not bashing because im really enjoying THM, but this has been happening far to often in a lot of rooms , very frustrating.

eternal summit
#

I put the odds at about 90% that it's your VPN

small briar
#

Hi team, having a strange issue with the nmap room when attempting the practical. It looks like I'm not getting a target machine IP

untold pike
#

Hello, dear thm team.
I have a bug on this room: https://tryhackme.com/room/ccghidra
Task 4, second and third questions:

What is the first variable set to in the main function?
What is the first variable set to, in the function "fn1"?
I found 2 variables on main function (but no one have length equal 2 symbols) and no one on fn1. This method just returns nothing (see on the attached screen).

untold pike
small briar
eternal summit
faint vault
small briar
eternal summit
#

You did not deploy the VM

#

That's the attackbox.

#

Go to like... Task 1? And click deploy

small briar
eternal summit
#

If you ever see MACHINE_IP check that you've deployed the machine

opal ingot
hazy tiger
#

That's very vague.
How do you know you cannot ssh?
Is there an error?
What error?
Can you provide screenshots?
Have you checked any writeups to make sure you are doing it right?

eternal summit
hazy tiger
#

Hm their message was deleted.

sonic estuary
#

incorrect username, should be lower case for A

icy elbow
#

Hmm.. I'm trying to do https://tryhackme.com/room/corp and it seems to be uncooperative. When I click the start menu nothing happens no-matter how long I wait. I reset the machine and tested again. Same behavior. Anyone experiencing the same issue?

#

I've also noticed a bunch of other issues mentioned here

eternal summit
#

Yeah, it needs some fixes but I think the creator has been super busy

icy elbow
#

understood 🙂

#

I'll see if I can bend it to my will until that happens I guess 😄

#

should be a nice challenge I suppose

icy elbow
#

Finished anyways. Done.

tall pivot
obsidian kiln
obsidian kiln
#

That's your IP address -- what's the IP address of the box?

tall pivot
obsidian kiln
#

It matters because it means I can check it

tall pivot
#

Ok sorry

obsidian kiln
#

Can you show me the developer console please?

tall pivot
#

LOL it's work now sorry for disturbance

obsidian kiln
#

Fair enough 👍

#

Happy hacking 😄

tall pivot
#

Thx😋

karmic slate
#

@next bluff
This room has lots of great information. The problem ive found though is task 3 it approaches it from back to front. So it got me to add a load of paths to the website before adding the function that they are direction to. I had the website running and then once i start adding things to it, and it was coming up like python errors. I spent a while researching and resolving this which i managed to do. After finding the fix ive moved on to the next parts of the task while are the things that i found to resolve the issues i was getting. An easy fix you be tell people at the start of the task to turn the server off and or they could re-position the order of the information.

oblique hemlock
#

@green steppe if i'm not mistaken, you are the creator of the Rust room. In Task 4, there is this minor styling issue. This should be all included as a code block instead of only the first line. In the same task, there is 3 places where this is incorrectly styled.

white meteor
#

Hi, the room windowseventlogs has some issues with detailed questions about numbers of logs in the event viewer section i have deployed the room multiple times but never get the right number of log entries

autumn turret
eternal summit
autumn turret
#

Thx

slate parrot
#

The Shodan room could do with font normalisation, and also, in Task 7, the content before the image has been repeated twice @green steppe

oblique hemlock
#

any chance you figured it out? Me and another person are stuck on that one as well

modest jewel
#

I think there might be an issue with the "Sysinternals" room in the Cyber defence path.

#

I'm having trouble with the "sysinternals" room - getting task3 getting "Sysinternals live" to work - I set the path of the sysinternals and got webclient running - it doesn't seem to save the "turn network discovery on" settings.

north gyro
agile junco
#

Can you all help me solve linux agency i think it is have some problems I trying tu su to mission1 by entering mission1 flag but it is showing me authentication failure. Please someone please check

north gyro
#

yeah, i mentioned it in this room, but didn't take it any further, i don't like having unfinished rooms also

gleaming shadow
agile junco
#

Okay i'll try again. Thank you.

remote hamlet
#

Wireshark room > Task 4 > Opening Paragraph: Horrific grammar

obsidian kiln
#

@twin tapir

#

Fix

twin tapir
#

yo I’m aware of the grammar I just followed darks template don’t blame me blame me dark

#

Oh godI

#

I must’ve been super tired writing that

gleaming shadow
#

hmm, Lian_Yu seems to include a youtube video which is no longer avaiable (account terminated), is it required to continue the room?

#

doesn't appear to, ok

waxen wigeon
#

Is there a specific format to report a "bug" in a room?

#

Nothing major, just an invalid href= link in a recent room, felt I should do my part and report it. Not sure how to contact the room owner though?

obsidian kiln
waxen wigeon
obsidian kiln
#

That room is private

waxen wigeon
#

Well I just finished it?

obsidian kiln
#

Where did you get the link to join it from?

#

Once you're in it doesn't show you the status

waxen wigeon
#

The href for linking antifa.com to Russia, is invalid

obsidian kiln
#

That room is slated for release on the 21st of February

#

@plucky nimbus you missed a dead link in it btw ^^

#

@waxen wigeon Where did you find the join link for that room?

#

I'm assuming someone leaked it somewhere?

waxen wigeon
#

I'm assuming so as well

obsidian kiln
#

Well, it's all gonna be reset on the 21st anyway, so tough luck to anyone who did it early 🤷‍♂️

waxen wigeon
#

So I'm assuming points don't count after it's reset?

topaz thorn
#

You don't get any as it's private anyway

waxen wigeon
#

Good to know, thank you. Honestly didn't even know it was private

obsidian kiln
#

Might just leave it then, given it's a walkthrough anyway

#

Oh, no, it's a challenge

glad badger
waxen wigeon
waxen wigeon
wheat fractal
#

anyone else have issues with hackpark, seems to lag and not work properly

#

ive had no issues with any rooms thus far

plucky nimbus
green steppe
#

ahhh nice

#

i changed their username

#

so cute to see them living up to their name hahahah

atomic briar
#

Been trying to complete Windows PrivEsc for like 2 weeks now :L
On task 7 the reverse shell doesn't execute. I'm logged in as admin, I've tried the entire process multiple times now. Does anyone have any idea why it doesn't run? @slate parrot sorry to ping you but did you ever find a solution?

slate parrot
atomic briar
slate parrot
#

The room creator was super helpful, worth pinging them.

remote hamlet
main iris
#

flag is mission1{....}

topaz thorn
sharp void
#

SQL Injection Lab where I am facing this issue. Is there any issues regarding the update challenge?

#

sqlite_version() is reflected instead of showing the data base version.

neon compass
#

Network Services 2 - Task 9 (Enumerating MySQL). The last question but one says that you should run the default "select module()" command. The default is "select version()" and that is what the question wants as an answer.

sterile crater
sterile crater
#

sure

gleaming shadow
#

oh got that too but I was doing it wrong

#

probably missed some punctuation somewhere

tight relic
trail bramble
#

Room:Core Windows Processes, Task2.

This should be written wmic process

#

@tight relic Hi✨

tight relic
#

Hi

glad badger
trail bramble
wild bramble
#

it has some minor spelling mistakes.

eternal summit
#

That is not a public room yet

wild bramble
#

it is

#

i just accessed i it rn

eternal summit
#

It is NOT a public room yet.

eternal summit
#

It's not even readied. Talk to the creator.

wild bramble
#

i dont know the creator 😦

#

ok sry 😦 .. i will ask yall be4 posting a question

eternal summit
wild bramble
eternal summit
#

They're probably the creator then.

#

Yeah they are quite clearly the creator based on what they said.

spring haven
#

mhm

obsidian kiln
#

@eternal summit if there is still a link in Darksec I'll delete it. Where is/was it?

thin salmon
#

Hello, I wasn't sure where to post this but in the John the ripper room in task 6, the /etc/shadow file available for download is different than the one provided

fading warren
#

In OWASP Juice Shop task1 there is a repetition. I'm not sure if it was done on purpose.
You will find these in all types in all types of web applications

wheat fractal
#

@topaz thorn Hi there
excuse me to interrupt you
i found a very little problem with site's coding which i though it would be useful to aware you about that

topaz thorn
#

I'm not site staff I can't fix that

eternal summit
#

What room?

wheat fractal
#

Nmap room

#

Task 5

eternal summit
#

@obsidian kiln did you break it?

wheat fractal
#

thank you for your attentions

obsidian kiln
#

The heck happened there

#

Looks fine to me?

#

@wheat fractal Try a hard refresh? (Ctrl + F5)

#

It's showing up fine on my screen

wheat fractal
#

let me check it again@obsidian kiln

eternal summit
#

It's probably your screen width?

wheat fractal
obsidian kiln
#

Even with a much smaller screen width I am not getting that James

#

Just goes off the screen

wheat fractal
#

@obsidian kiln that is wrong room :))

obsidian kiln
#

That is seriously weird

wheat fractal
obsidian kiln
#

Further nmap

#

Yep, that's what I'm looking at

#

Task 5

wheat fractal
#

heeemmmm i even cleaned the cash

#

i dont know really

#

i just though it might be useful to aware you about that @obsidian kiln

obsidian kiln
#

That image shouldn't be nearly that big anyway. The heck happened there

obsidian flame
obsidian kiln
#

Hm, that's a good shout actually

#

@wheat fractal Do you have any plugins that affect stuff on the screen?

obsidian flame
#

^ worth trying incognito with no plugins to see if it's fixed afterwards

wheat fractal
#

tha's all i have on Firefox the last update

obsidian kiln
#

My firefox is one behind. Trying it now

obsidian flame
#

i got firefox, can give it a go

obsidian kiln
#

Yeah, it's still Ok for me in updated firefox. That is very odd

#

You able to show me the CSS styles for the image in inspect element @wheat fractal?

obsidian flame
#

yup still fine

wheat fractal
#

which part

obsidian kiln
#

Select specifically the image, then it should be over on the right hand side

wheat fractal
#

image is selected

obsidian kiln
#

Mind doing a hard refresh and see if that fixes it?

wheat fractal
#

if that helps you yes sure @obsidian kiln

obsidian kiln
#

I mean at this point I'm just debugging -- I don't have a clue why it's doing that given I can't replicate

wheat fractal
#

wondering what was the problem

obsidian kiln
#

Well then.
It'll be to do with a fix I implemented when the editor changed at the start of December. I had to make it really wacky html in order to style the image

#

That didn't hold over well when the editor changed back

wheat fractal
#

okay thank you for your efforts

obsidian kiln
#

Np!

wheat fractal
#

i would be a good ....idea to put on a announce to tell everyone refresh their cash

#

yeap

#

seems you did a major change

trail bramble
wheat fractal
#

@trail bramble did it twice

#

it seems my ISP filtered the server where is imagase are stored

#

cause i can get them if i run VPN

#

the question is WHY!>

trail bramble
#

? Are you connecting from some restricted network?

Then, it's not THM problem. You should say the network admin.

wheat fractal
obsidian kiln
#

Those are on imgur

wheat fractal
eternal summit
wheat fractal
#

@eternal summit thanks for the help

#

at least that gave a clue about who's responsible for that

versed inlet
obsidian kiln
#

@versed inlet the video walkthrough?

versed inlet
#

yep

obsidian kiln
#

The box hasn't changed since the video was recorded, so it can't have gone wrong

versed inlet
#

i dunno what else to say

#

im not getting the reverse shell

obsidian kiln
#

Try redeploying?

versed inlet
#

ive been on it for the entire day

obsidian kiln
#

Oh, actually.

versed inlet
#

redeployed like 3-5 times

obsidian kiln
#

What's the IP?

versed inlet
#

one sec

#

10.10.31.155

obsidian kiln
#

Lemme check it

versed inlet
#

k thanks

#

you are free to look at the payloads i aleardy uploaded aswell

obsidian kiln
#

That's what I'm doing 😁

#

Did you get a shell back there?

versed inlet
#

what do you mean

#

i put the payload on the server but i couldnt get a shell

obsidian kiln
#

I assume you have a listener up?

versed inlet
#

yep i did

obsidian kiln
#

Because that's running just fine

versed inlet
#

wait what

obsidian kiln
#

Did you get a shell back?

versed inlet
#

no

obsidian kiln
#

Hm

#

10.9.255.254 your IP, yes?

versed inlet
#

yep

obsidian kiln
#

Listener on port 1234?

versed inlet
#

yep

obsidian kiln
#

Are you using Kali?

versed inlet
#

yep

#

ill even go ahead and try attackbox rn

#

one min

#

yep doesnt work with attackbox aswell

#

just FYI , the command im listening with is :nc -nlvp 1234

obsidian kiln
#

That's definitely working at my end

versed inlet
#

=/

wheat fractal
#

Hi guys, have a bug when trying to do Overpass on attackbox, do not want to comment too much includes spoliers.

versed inlet
#

so i dont know what to do man

#

i did the exact same

eternal summit
#

You can't use the in browser access

obsidian kiln
#

You're entering ../content/ZIE.jpg into the admin page, yes?

versed inlet
#

yes

#

exactly

obsidian kiln
#

Could you fullscreen your attackbox and send me the URL please?

wheat fractal
eternal summit
#

Yep.

wheat fractal
#

Thanks glad you are aware 😄

#

I found out by trying to kill the service and yeeted my session 😄

eternal summit
#

It never used to be an issue then the attackbox changed

#

You can use SSH or RDP or VNC just fine

lost stag
#

It appears to be something wrong in the Windows Event Logs room, task 2. I'm providing the right answer, but it isn't correct..

lost stag
#

It also appears that "What are the total number of events?" question isn't correct. Maybe i'm doing something wrong, but i don't think so.

#

I can't even interpret the questions in the rest of the room. It's asking for definitions, and when i read the exact definitions from Microsoft's web site it's not possible to give any answer or understand how it should look like..

eternal summit
#

They're different tho

eternal summit
#

Yes, that's meant to happen

#

It's an rbash for a reason

gleaming shadow
#

possible bug on the bash scripting walkthrough, task 5, Q3, answer takes "" as quotes, while the walkthrough uses ''. Intentional or not?

obsidian flame
#
The commands you are allowed to use in this room are:

cat
tac
head
tail
xxd
base64
find
grep
echo
xargs
hexeditor
tar
gzip
7zip
binwalk
Bear in mind, commands such as cd are not allowed.
#

oh yeah, there is no python import function btw as everything is symlinked to the user, nice try kekw there is a privesc with nothing to gain if you wanna find it

north bay
#

Hi all, I am on the Network Discovery room (Telnet). The nmap scan that is advised takes a long time... Is this normal?

wheat fractal
#

Hello Guys, can anyone help me resolve something with the WebAppSec 101 room from THM website?

#

I have some issue with the Authentication section.
How can I know username of a logged on user? from question: What is the username of a logged on user?

#

Should I handle the new cookie value to doing that?
Please, any help will be apreciate! 🙂

north bay
#

Can anyone help with super long nmap scan times?

obsidian flame
north bay
#

Enumerating Telnet in the Network Services room

obsidian flame
#

add -T4 at the end of the command to speed it up

#

nmap -A -p- -T4 IP

#

that should fix the issue with the script taking way too long 🙂

north bay
#

I get "Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn"

#

and then if i use -Pn it takes a long time

eternal summit
#

Sounds like you're not properly connected to the VPN

north bay
#

The browser says I am connected

obsidian flame
#

as james advised let's move the discussion to tech-support

jovial crest
#

Hello i have problem with this room

#

When i load this and login to ssh and want to set a breakpoint it gives me this error Cannot place a breakpoint on 0x5589ce52e637 unmapped memory.See e? dbg.bpinmaps

#

So i cant continue

oblique hemlock
#

@sleek jay Task 3 /tmuxremux, should be most instead of must. Great room by the way! (sorry for tagging you as it was not clear who's the creator, you or Oreo and i couldn't find a user called Oreo on the server)

sleek jay
#

It’s @tardy lynx room

civic brook
#

@oblique hemlock , you can often just put the room and issue; it will usually get re-directed to the right sources at that point

craggy solar
glad badger
#

Let me check @craggy solar

craggy solar
#

okay

glad badger
craggy solar
#

okay

hazy tiger
#

Have you left and rejoined the room?

#

Sometimes rooms say they have been completed but a quick leave and rejoin updates it.

craggy solar
#

okay, i don't remember joining this room and mostly when i join a room i complete it until it is really hard so i keep it for later

#

if i join now my previous answers will be shown right?

hazy tiger
#

Yes.

glad badger
#

Right now you're not showing as joined, so please re-join the room and see what happens.

craggy solar
#

okay i will join and check

hazy tiger
#

But there was a minor bug a while ago wherein rooms had issues with tasks, Skidy advised everyone to leave and join the room if this were the case.

craggy solar
#

okay my bad i have answered few questions sorry i will investigate properly next time before submitting again sorry

hazy tiger
#

I think I know your issue.

#

If I recall correctly, the empire room was updated? This means that all new tasks were not completed.

#

So you may have completed the room but as the room was re-created, all the new tasks were marked as uncompleted and old tasks stayed.

craggy solar
#

okay i will keep that in mind thank you so much for your help

calm kestrel
#

kk sorry

livid rune
eternal summit
#

@dusky junco this is on your list right?

gleaming shadow
#

I think windows boxes have a bug there that's slowly being fixed

compact shoal
limber plaza
#

hey found wrong input validation on bash scripting room in 2 questions its marking the wrong answers as right

eternal summit
limber plaza
#

can i dm you the screen shot?

eternal summit
#

Are there over 10% incorrect characters? @limber plaza

limber plaza
#

No, NM its just an answer tolerance 😅

oblique hemlock
#

there is a room (Content Security Policy) that multiple people are stuck on, it got reported tons of times that it needs internet connection to be done, but got said that it doesn't every time this was brought up. I just asked the room-maker and they confirmed that it needs internet access. They said it needs an admin to do so because room-creators can't enable internet access on their own anymore. Which admin can i tag?

obsidian kiln
#

@dusky junco is this within your powers?

spare fox
#

Hey, I have a question / report for windows10privesc, "Task 8" => "HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer" Does not exist, so the readme is not in sync with the machine. "Task 10" flat out doesn't work for me, tried to restart the vm multiple times, the script just says there are no credentials stored. Is it just me ?

spare fox
dusky junco
obsidian kiln
#

Well damn

odd shadow
#

OWASP Top 10 room, task 16 last answer. I got the private key but I think it's not accepting the right answer.
I put in the first 18 characters, ||MIIEoglBAAKCAQEA7|| and it doesn't accept.
#room-help message

oblique hemlock
oblique hemlock
#

did you type it over?

odd shadow
#

yeah I did, let me recheck.

#

are those ls or is

#

lmao

oblique hemlock
#

haha that is where the problem is indeed, try the different combinations i would say 😄

odd shadow
#

Got it, thanks.

spare fox
twin tapir
#

Just shouldn’t even use creddump7 at all should be using impacket. I personally hate the fact that it teaches creddump7

obsidian kiln
#

Ah, @twin tapir Just who I wanted to see

#

Speaking of impacket

#

It's being weird

twin tapir
#

god damn it muiri

#

you’re dummy self already dmed me once go and shoot

wise shard
#

anonymous room is not working as intended , not getting a reverse shell

#

can someone shed some light on this

spare fox
#

@twin tapir yeah. My point is, the rooms need overall revamp because it is highly unstable / inconsistent between 2 instances and is outdated

civic brook
#

GraphQL Task 4 seems to be giving me a wrong answer although I have checked my formatting a few times

oblique hemlock
#

did you copy and paste this answer? It seems like the double quotes are messed up. That happens sometimes when you copy and paste

civic brook
#

hmm weird, even when I typed it correctly I was getting the same error, but some how changes the quotes around worked this time

glad badger
civic brook
#

thanks @glad badger that makes sense now

fringe geyser
#

room ice contains a link to the room rpnmap which has been yoinked a while back

#

task2, question 2

tight relic
dusky junco
trail bramble
#

Room: Authenticate, Task 4(JSON Web Token)

This is not "edit the stored cookie", but "edit the stored Local Storage".

trail bramble
# obsidian flame that is a cookie ....

? My understanding is :

Am I not correct?

obsidian flame
#

Partially, but also if you search on google: where are JWT stored you get this:

trail bramble
#

Uh, I know that.

But I post #room-bugs . [Authenticate] room's app set JWT to Local Storage.
Therefore I point out the document has a bug. That's all.

eternal meteor
#

There's an issue in the Yara room - specifically the Loki task. When trying to scan file 2 it's showing an error with one of the yara rules and no scan results are coming through. I'm unable to complete the tasks

glad badger
sharp imp
#

Steel Mountain: Page instructs you to download PowerUp, it doesn't point out that it's included in Kali already ( /usr/share/windows-resources/powersploit/Privesc/PowerUp.ps1 ), not sure about AttackBox

obsidian kiln
#

@dusky junco ^^

glad badger
#

PowerUp.ps1 is not on the AttackBox. Although Empire/Starkiller will include it if I remember correctly.

tight relic
#

learncyberin25days - Task 16/Day 14: scylla.sh is down (gone ?) so the "Has rudolph been pwned? What password of his appeared in a breach?" question can't be solved

sonic willow
#

pretty sure it's scylla.so now, and it looks like the dev's fixing it now (saw them say this in another server)

tight relic
#

cool

dusky junco
#

Ah yeah I updated that in aoc2 but didn’t think about that room

#

I’ll update it when I get to my work laptop (:

gleaming shadow
#

Don't know if it's just me but Scylla.so doesn't work either

tight relic
#

nor me

twin tapir
#

Scylla often gets taken down either because of maintenance happening or he’s been under some attacks and companies going after him recently

foggy fable
#

did anyone run into a issue in Common Linux Privesc room task 4 question 6. When I submit the answer It pops a error undefined!!!

fleet pasture
#

hello, in the linux fundamentals 3 there is a bug in task nr 5 on the second question

#

when you answer it, the answer changes from "FIND" to "FINDE"

#

do only i have this bug?

vast cypress
#

Just tried that, didn't happen to me. Try refreshing

gaunt idol
#

i dont know if this is the right room for this but i cant ssh into the thm machines, ssh is working on other websites and im connected in the thm network.

obsidian flame
gaunt idol
#

its the final task on CC: Pen Testing

#

and linux strength training isnt working as well

obsidian flame
#

odd, what error are you receiving

gaunt idol
#

time out

#

ssh: connect to host 10.10.39.126 port 22: Connection timed out

obsidian flame
#

Odd. You are connected to the VPN, right?

gaunt idol
obsidian flame
#

Hmm. Haven't come across that as of now. I would suggest regenerating the VPN config

gaunt idol
#

already tried

obsidian flame
#

Not sure if anyone else has more experience. @eternal summit do you happen to know a solution for SSH not working even after VPN config regen?

tight relic
obsidian flame
#

hmm, that might be it, try doing the ssh connection with -vv

#

you can then force the protocol the connection should use

gaunt idol
#

ok i will try

fleet pasture
#

@dusky junco are you there?

#

i have a small question for you 🙂

gaunt idol
#

expecting SSH2_MSG_KEX_ECDH_REPLY

eternal summit
#

@obsidian flame MTU fix

obsidian flame
grim yoke
#

room tmux last task , submitting the partial answer worked , and after refreshing it is displaying the full answer , don't know if it is a bug or not , just sharing it here !

civic brook
#

there is some answer tolerance for questions

grim yoke
#

okay 🙂

remote hamlet
#

Room: rrootme > Task 2 > Question 2: "What version of Apache are running" - should be "What version of Apache is running".

tiny ginkgo
compact shoal
#

No offense to the classic passwd's room owner, but... SPOILER AHEAD.
||I was 1 ltrace command away, in knowing the username|| It took me hardly 3-4 mins to solve this challenge 😉

uneven vault
#

Hi

#

is there anyone finished the Sysinternals room ?

#

i got stuck on this Q

#

There is a txt file on the desktop named file.txt. What is the text within the ADS?

#

the answer which i'm getting has deffrent format

tiny ginkgo
dusky junco
# oblique hemlock Any update on this?

Hey! Yeah apologies. So it's something that we can do (in terms of giving it internet access) as long as it isn't vulnerable -- which it doesn't look like it is.

However there's a few things with it and I've reached out to the creator yesterday and I'm waiting to hear back from him (:

narrow carbon
#

VulnVersity is down, anyone else or is it just me?

hazy tiger
#

Why do you think it is down?

narrow carbon
# hazy tiger Why do you think it is down?

I rebooted my machine twice, still can't connect to it, can't scan it, can't do anything with it. I don't think it's on my end since I've just done another room that functioned well.

hazy tiger
#

Are you connected to the VPN?

narrow carbon
#

Yes i am

hazy tiger
#

And you have tried to perform an nmap scan?

oblique hemlock
narrow carbon
#

The nmap scan functionned

#

but I can't use gobuster, it prompts me to a "no access" error

hazy tiger
#

Are you specifying the correct webserver port?

narrow carbon
#

and I can't browse to it

#

I am

hazy tiger
#

http://machine_ip:[webserver_port]

narrow carbon
#

I'll try again but I d on't think this is the problem

hazy tiger
#

Can you supply the command you were using?

narrow carbon
#

gobuster dir -u http://10.10.183.107:3333/ -w SecLists/Discovery/Web-Content/directory-list-2.3-small.txt

hazy tiger
#

Are you able to directly to go the webserver?

#

(typing the url into your browser)

narrow carbon
#

Well I wasn't until now, but it seems to be working as of 10 seconds ago

narrow carbon
hazy tiger
#

Yes:)

#

Jabba the Magician.

narrow carbon
#

Thanks 🙂

thorn cloud
obsidian kiln
#

Although I agree, it's not very well worded

thorn cloud
#

I agree not a big thing skidy but may be this will create less confusion of that else getting understood as something else XD

proper jasper
#

ok i was running a VPN at the same time, turned it off and now it works

thick stone
#

Hey, i am doing the Linux Challenges room. Is it possible, that there is a typo at flag 14? so this is the task: Where on the file system are logs typically stored? Find flag 14. and in the correct folder there is a document called flagtourteen. Is that just to prevent searching for it or is this a typo?

thick stone
#

2

glad badger
#

Room name? That's a retired room.

thick stone
#

Its Linux Challenges in the Linux Fundamentals module

glad badger
#

Could be either a typo or intended name obfuscation.

thick stone
#

i just wanted to proof. Thanks

fluid summit
#

Task 6 Day 4 : the word list at /opt/AoC-2020/Day-4/wordlist seems to be missing...attackbox ip:10.10.227.114

hazy tiger
#

What is missing exactly?

cobalt otter
#

nvm, my bad!

#

sorry, I was looking at it late yesterday and my eyes must have gone funny lol

cobalt otter
#

actually, I realized my error, there are pictures cropped too tight, I just posted the wrong one, as I said, it was late yesterday when I made the note. So this is the linux modules room, task 8

#

the top picture is supposed to show an xargs command, but it's unfortunately somewhere off to the right, it's referred to in the text below though, the next one similarly is supposed to be showing the use of a variable argVar but that too is not to be seen

glad badger
cobalt otter
glad badger
untold pike
#

Hello!
For this room https://tryhackme.com/room/linuxmodules
for the Task 7 That's what she sed and question What pattern did you use to reach that answer string? the correct answer doesn't work. I got with my command the answer for the previous question and my command have the same format as the "answer format" but it doesn't work.

compact shoal
untold pike
compact shoal
ancient token
topaz thorn
#

Refresh that’s answer tolerance

midnight hollow
#

Wtf

viral cobalt
#

dark reader plugins @midnight hollow

midnight hollow
viral folio
#

For room https://tryhackme.com/room/rpwebscanning , Task 3 Zip ZAP! question This website doesn't force a secure connection by default and ZAP isn't pleased with it. Which related cookie is ZAP upset about? and the answer to it is httponly.

I think it gives false impression. For cookies to be sent over a secure connection flag secure is used.

ancient token
slim raft
#

is this where i can ask about why my completed rooms arent updating??

eternal summit
#

In Network Services 2, Task 6, there's a question telling us to set the threads to 16. This won't do anything as it's max 1 thread per RHOST. @cinder bone

cinder bone
#

Thank you @eternal summit I'll change that 🙂

eternal summit
#

Also, for Task 9, Metasploit changed the default SQL @cinder bone

#

Wait, no

#

It needs to be set as select version() so it's just an error in the room

cinder bone
eternal summit
eternal summit
#

@dusky junco Task 5 Mitre, this should be plural not possessive.

#

Last question task 5

eternal summit
eternal summit
#

Yep, I just flagged this and it should be fixed soon

#

Like a few messages above

#

With the creator

molten pagoda
#

Oh lol

#

When it rains it pours.

#

You are onto it James apologies

#

Am enjoying the changes to the beginner path tho! 🙂

#

Nice excuse to go back over it.

floral quail
sturdy lake
#

It seems that there is something off about 'SSH' connection in the 'EasyCTF' room, It doesn't work.

coral shell
#

It seems that there is something off about 'SSH' connection in the 'enpass' room, It doesn't work.

eternal summit
#

It was tested and it's definitely working

coral shell
#

thanks

celest sphinx
#

hi everybody (new to the server and quite new to THM in general); I have a smallish problem in the "Blue" room, namely:

  • the exploit works in the provided attack box (metasploit version: 5.0.101-dev)
  • the exploit fails reliably on a new Kali (metasploit version: 6.0.29-dev)
    is this a funky bug?
    (it also does not matter whether I'm trying the exploit with the default meterpeter shell or the reverse_tcp shell as given by the room, same results on the respective VMs)
frank ibex
#

Hi,

I think there is a bug in this room:
https://tryhackme.com/room/sustah

It's related to the root privilege escalation step:

Note: I tried to re-deploy the machine to confirm that.

Hope someone from the technical team will check it

gleaming shadow
#

according the creater that file is not in a standard location

eternal summit
celest sphinx
eternal summit
#

It should be your tun0 VPN IP

celest sphinx
#

could confirm it, LHOST was the NATted IP of the VM, setting it to the tun0 IP enabled the exploit 👍 learned something again, thank you coolguy

true dagger
#

Is there something wrong with the Inferno box ssh connects and kicks me out after 30 seconds while I'm looking through the box?
I tried terminating the room multiple times and restarting my vm

eternal summit
#

It was tested, and is working.

charred mulch
#

hello , im at the alfred room , im at the end of task2 , i succeeded to make my msfvenom file to run , but the msfconsole multi handler , gets stuck (pic will be sent on my next msg)

charred mulch
#

anyone?

maiden wigeon
maiden wigeon
#

But it also spits commands out by itself...such as "logout". I didnt type it, but it logged me out bc of it lol

#

With that said tho... once you have access to the box... priv-esc is too easy.. so if you still havent rooted the box.. dont overthink it

astral phoenix
#

try typing ls

glad badger
#

For those who reported room completions not showing as complete in the learning paths, that has now been fixed. 🙂 🥳 thm

trail bramble
twin bay
raw bison
fair jasper
#

Hi, I would like to know if someone is having problems with Inferno machine where once connected with ssh or revshell it keeps disconnecting. Is it this behaviour normal?

gray ridge
#

Yeah got the same problem... quite frustrating to be honest @fiery lark , was it intended?

eternal summit
fiery lark
#

it's not a bug

gray ridge
#

I see... more than inferno i'd call it annoying 😅

shy zenith
eternal summit
#

refresh

shy zenith
#

thx 🙂

sonic willow
#

state what the bug is

#

state which task and question it is too :)

fleet surge
#

these links in the OWASP Top 10 to the OpenVPN room are not working
just fyi

untold pike
#

Hm... Sorry, but after I submitted 4th and 5th answers, the second one accept right answer...

true dagger
rugged forum
#

In Advent of Cyber 2 Day 24 first question
Scan the machine. What ports are open?
i am getting result 80,65000
when i entered it is showing incorrect answer but it is the correct answer

solemn quiver
rugged forum
broken forum
#

In the room bashscripting (https://tryhackme.com/room/bashscripting), Task 6 - Conditionals, using the operator && with [ is not appropriate. It'll work but give an error saying missing ].
Using single brackets, the correct operator for and would be -a imo

Also, the msg variable was probably meant to be used in line 4 and 7? It's unused and could confuse first-time-learners maybe🤷‍♂️

harsh zephyr
#

I think that the whole construct is a little bit overcomplicated...a simple 'echo $msg > "$filename"' would do the same.

obsidian kiln
#

@steel monolith worth updating that. Get a tester to look at it again when you do though.

steel monolith
#

yep thanks for bringing that up taking a look now

glad badger
gleaming shadow
#

Yeah there's a particularly evil script in the root cron

#

It's possible to bypass though

wheat fractal
#

Bug in the box rick and morty

topaz thorn
wheat fractal
#

Dm

topaz thorn
#

No

#

say here

wheat fractal
#

U can have all flags just whis strings, cat is block but strings no its a bug no?

#

@topaz thorn

languid egret
#

In learn the linux fundamental part 1 - the room automotically completed the the task and no option to input answers

obsidian kiln
wheat fractal
#

...

gleaming shadow
#

You win!

#

Huzzah!

#

Closed: not a bug.

wheat fractal
#

Lol

wheat fractal
#

In The New Machine "The Great Escape" http server suddenly went down after few minutes , resetting the machine like twice and it's down .

#

NVM: it works now

gleaming shadow
#

The 503s are not a bug

wheat fractal
#

I think in the room (https://tryhackme.com/room/ccpentesting), it may have an issue at task 18 (Vulnerable Web Application) concerning the last question. I got the table with empty data, no flag.

Table: m**
[2 entries]
+---------+---------+
| m       | v       |
+---------+---------+
| <blank> | <blank> |
| <blank> | <blank> |
+---------+---------+

Database: t****
Table: l**
[1 entry]
+---------+---------+
| f       | v       |
+---------+---------+
| <blank> | <blank> |
+---------+---------+
eternal summit
#

It's an issue with sqlmap usually

wheat fractal
eternal summit
#

Don't use the attack box? Try cloning the python script from GitHub?

wheat fractal
shy zenith
#

Machine: Linux Modules
Task 8
Question 3
Says to use verbose flag but the correct answer is without it.

gleaming shadow
#

could be the answer tolerence acting up

#

what did you input?

shy zenith
#

ls | xargs -I word -n 1 sh -c "{ echo word >> shortrockyou; rm word }"

gleaming shadow
#

yeah probably the answer tolerance

#

did you try refreshing the page?

merry cape
#

did someone delete the proof.txt contents for the inferno machine or is it just me? I got root and was able to access the proof.txt flag but nothing was in it

thick acorn
#

in task 14 of room nmap the answer is showing that 3 ports are open or closed but it's not accepting as a correct answer

charred mulch
#

May I pm you? since we apparently live on different time zones?
Thank you

shy zenith
eternal summit
charred mulch
#

im still facing with a bug

eternal summit
thick acorn
eternal summit
thick acorn
#

ok I got it

lyric walrus
#

i would like to report a presumed bug: in crack the hashes box, task 1.4 the hint says "A lot of tools will attempt to identify this as bcrypt and, well, that's not exactly right. Bcrypt is often cited (at this time) as being very difficult to crack. Try some other formats that start with the letter b, you'll see them in the suggested hash types" but i got confirmation that it is in fact bcrypt and the hint may be revisited to say something like: "try filter your password list by lenght to shorten the cracking time"

eternal summit
#

Yeah it is literally bcrypt

#

The hint is 100% incorrect

lyric walrus
#

@eternal summit

#

It seems a bit odd but with 20cpus i cracked it in 1 day and 19hours using hashcat's -w 4 switch

static oracle
#

good day all, I'm doing the room encryption crypto 101, got to task 9 where it says I should deploy the room "Learn Linux" but it says the room is private. Anyone know if this is a bug? Is there a similar room I can launch to complete this task?

eternal summit
# static oracle good day all, I'm doing the room encryption crypto 101, got to task 9 where it s...
#

Learn Linux was split into the three Linux Fundamentals rooms

static oracle
#

when I click the link in crpto101 task 9 it still takes me to that page.

eternal summit
#

But it's fixed.

static oracle
#

oh nice ty ty

cosmic oracle
#

hey there i think i have found a bug. So i have finished the Introductory Networking a couple of days ago and everything is 100% done but it doesn't count as a room completed. I have tried and refreshed the site ofc but the problem has remained for a few days. its not a huge problem of course but it would be nice to get the room completed. Just wanted you guys to know 🙂 but anyway, thank you for an amazing site that i have learned so much on.

eternal summit
#

Because it no longer shows the checkmarks in learning paths

cosmic oracle
#

i dont know if it is a learning path. would you like screenshots?

eternal summit
#

!docs verify

tropic flameBOT
eternal summit
#

You'll need to do that first, but it'd help

cosmic oracle
#

okay imma do that brb

#

so there we go

eternal summit
#

There's still a question that you haven't checked off probably

cosmic oracle
#

i think that should be it? ive cp my discord token to the bot and it say "upp to date"

eternal summit
#

Yep

cosmic oracle
#

does it show now or still nothing? 😦

eternal summit
#

I can't check on the site, but are all the tasks in the room green?

cosmic oracle
#

yes

#

yes

eternal summit
cosmic oracle
#

thank you for the help ❤️

tiny ginkgo
topaz light
#

Share badge functionality not working.. any idea?

pure urchin
#

Hi, I'm working through the 25 Days of Cyber Security. On Day 6 it requires an answer to 'How many XSS alerts are in the scan'. I am sure I answered this correctly, but it doesn't accept answer. It says format is in the form of single digit, so I used the answer both in the tutorial (same as my answer) and then tried every single digit and none work. Is there a bug? While waiting right now I have just run through every single digit (0-9) and it's finally accepted an answer, but it's not the right answer (according to my results and the tutorial by DarkStar). It wouldn't accept any of these yesterday.

glad badger
#

The video tutorial provides the right answer to the question (Q5 in the current room, Q6 in the video), but the questions were re-arranged/changed since the video was recorded. @pure urchin

pure urchin
#

Thanks @glad badger . The answer it accepted as correct was not the same as the video / the actual correct answer (can I say what it accepted?).

#

And yes to confirm, Q5 in current room.

trail bramble
dusky junco
brazen gulch
obsidian flame
#

incorrect series mentioned in the first task of the new room:
Which ISO27000 families standard can be audited?

Plus it's incorrect as you can audit against multiple iso standards such as iso 9001 etc

#

Last question is singular. it's A || risk || based appraoch

topaz thorn
#

I’ll tell them to change it 🙂

obsidian flame
#

i am an ISO haha, so this things i know by heart

#

also if he want's a markdown of that i can give it to him of all the iso controls 🙂

topaz thorn
#

@muted musk ^^

obsidian flame
#

grammar

#

task 4 has like 5 different formats for the notes :c

#

grammar again

#

grammar

topaz thorn
#

I must have been tired to miss all of that

wheat fractal
#

"Go and read the ISO 27001 doc ;)" hints like this are very poor, please add a link to the documentation. When you want that the users learn to google, then build a "google" machine ...

midnight hollow
#

Exactly I have been confused in several questions since they are not well written

oblique hemlock
#

oooh there is an ISO room? imma go and do it e_e

gleaming shadow
#

That's the most excitement I've seen over an ISO standard in...ever

viral cobalt
#

+1

obsidian flame
sonic willow
#

task 4, the title "requirements" is also spelt wrong on the iso room

wheat fractal
#

@gleaming shadow ... sry, when the community not can say, the quality of this machine is very poor, than we can close THM ...

oblique hemlock
#

room: https://tryhackme.com/room/iso27001

Issues:
Task 1:
1- "JUST THE ISO 27001 CAN BE AUDITED". Wrong more ISOs can be used to audit against depending on the goals and the industry...etc.
2- first question says "What does ISO mean?", it should say what does it stand for. It doesn't mean anything, it is abbreviation.
3- "Which is the objective from an ISMS?", it should be What is the objective of an ISMS. The accepted risk is also questionable.
4-"Which ISO2700 families standard can be audited?", accepted answer is wrong
Task 2:
1- "Also exist two kind of audits methods", should There also exist or something else. This is wrong.
2- "This was not a 27001 room?". Was this not...
3- "but maybe you don't ever will have 27001 audits" ???
4- "Which organization release a guide for remote audits to help organizations in the pandemic" did release a guide?
Task 3:
1- " I going to " I am going to
2- "introduce you to different thing about an ISMS should have considerate when is going into development" ????
3- "he can delegate his responsibility " they can delegate their responsibility
4- "well, that service should be documented and be competent about security" Incorrect, you can still gain certificates without a third party is competent about security. It all depends about the scope of the audit
5- "What mathematical funcition can help to get integrity?" has nothing to do with ISOs but technically correct. And it is function
General
1- A huge part of the room is plagiarized, from this site for example: https://reciprocitylabs.com/resources/what-are-the-three-types-of-iso-audits/ .

the room has been taken down, i will stop with my feedback

gleaming shadow
#

Eh?

gleaming shadow
wheat fractal
#

"That's the most excitement I've seen over an ISO standard in...ever" <- this was a reaction to your post

obsidian flame
#

that doesn't mean he is the creator of the room, lol

wheat fractal
#

i know

gleaming shadow
#

Oh I was reacting to @oblique hemlock

#

Who was like oooh ISO!

wheat fractal
#

but it sounds like, he disrespect the feedback

gleaming shadow
#

Oh it's probably legit

#

ISO standards are generally dry reads

obsidian flame
#

can be fun if you present them well

gleaming shadow
#

Haha perhaps

obsidian flame
#

and if you have a good internal/external auditor

#

i've been doing for over a year now for the place i work for, a part of my role is to be the ISO (information security officer) so it can be fun and games and looking ahead

#

but there is also the dull paperwork, policies and stuff that goes into it

dusky junco
#

Hey all (: thanks for reporting the errors you've found with the ISO room. We've pulled it from being public to work with the creator and to get reviewed

oblique hemlock
#

Thanks for doing so 🙂

dusky junco
#

Yeah, once you have joined it you will still be able to see the room

#

It's just no one who hasn't already joined it can't now

gleaming shadow
#

Hope everything gets resolved!

slate parrot
#

I love the diversity of THM. But I wish there was a dedicated proof reading team that reviewed the editorial content of a THM room.

lost plume
#

I found a room question that is potentially expired today, not a bug though. It is in the Searchlight - IMINT room. The last question wants the user to find the hotel the friend is staying at. The hotel, since the room was published, has closed down and the building is going through renovations. Although the question is still solveable, it takes significatnly more work than i believe was intended.

slate parrot
#

A recently released room is an example of this — appreciate that the author is likely to speak English as a second or third language, but this is more reason to offer such a proof reading service.

topaz thorn
#

That's what the room testing team does, we can't make everything perfect, all we can do is give guidance towards the creator to help them avoid these mistakes, if we miss anything then report them here it's all human error there is no need for a proof reading team

slate parrot
slate parrot
sonic willow
#

i agree with snkhan, while room testers do a good job at making sure the room content is good, often some of the rooms as snkhan mentioned are structured weirdly/grammatical issues etc. and i think a proof reader who has access to modify the room to correct these (rather than asking the creator to) would be very beneficial to the quality

#

maybe something like

  • submit room for public release
  • room tester tests the room (for bugs or wrong information)
  • proof reader corrects any formatting issues / grammatical issues etc
  • normal release schedule
topaz thorn
#

That's exactly what the room tester does

slate parrot
topaz thorn
#

Yes I have it, it was tested

slate parrot
#

I’ve even volunteered to proof read in the past.

#

There are font issues in the very first paragraph, and grammatical issues throughout.

topaz thorn
#

Look it's going to be reviewed again

sonic willow
#

from what i've seen and heard, room testers let the creator know about the issues, but things such as grammatical and formatting are not going to get resolved if for example the creator's primary language isn't english

topaz thorn
#

When it's re-released it will be better

#

We can ensure you it will have less grammatical issues , I will say part of it is my fault due to me being the original tester and I may have overlooked a lot of certain things, so I can say I am to blame for a part of it due to me not re-checking clearly, so i'm sorry for the inconvenience this has caused

slate parrot
#

Thanks @topaz thorn, I hope the team can reconsider integrating a proof reading process as part of the excellent suggestion by @sonic willow

verbal sedge
slate parrot
#

I’ve sent this feedback (and countless others) via the feedback tool

topaz thorn
#

Yep, in the room docs review we have to ensure that grammar and spelling is correct, I can say that I should have checked better and will try to not make this mistake again, I must have been under stress when testing this room for it to be incorrect like this

slate parrot
#

No worries @topaz thorn thanks for all your support in room testing, and keeping the flow of machines coming to us 🥰

hazy tiger
#

snkhan, let's not be rude and move on. Please do not try to start any drama, site staff have been notified.

lost plume
#

Not trying to be bothersome, just want to check if anyone was able to see my above message

obsidian kiln
#

(For the record @slate parrot, I know for a fact that Skidy and Ashu read everything that goes through that form -- like, literally all of it)

lost plume
#

sorry for the late reply. it appears difficult to me since using the context clues from the video in the question make the answer very hard. Just searching key buildings nearby do not show the old hotel since it has gone so far removed in the search results. when going through the question, i had to eventually look up old shops in the vicinity to find the answer. not even the buildings directory listed the old hotel. the question is also not posed as a historical question but instead as if the hotel is supposed to still exist. I was only ever able to find the hotel directly if i already knew the name of it.

worn ember
slate parrot
oblique hemlock
#

i agree ^, i sent a suggestion in about supporting LaTeX because it would encourage people to add more theoretical information security content but I have never gotten a reply. So i just assumed they didn't like my idea, which is fine but would be nice to have it said explicitly.

gleaming shadow
#

LaTeX would be hard...

#

at least in a web context

oblique hemlock
#

not really the point i'm making, but sure, even such a reply would suffice. In the content of "hey we saw your message, it is not gonna happen"

gleaming shadow
#

they probably get quite of bit, always hard to respond

oak mica
dusky junco
oak mica
#

nice work, thanks @dusky junco !

dark lion
eternal summit
#

Yep that's broken

#

@cinder bone did you change your username on github?

wheat fractal
#

is this room broken on task3? https://tryhackme.com/room/sqlilab
i cant extract columns from the table named "secrets"
payload is "',nickName=(SELECT group_concat(id "," author "," secret text || ":") from secrets),email='"

fresh agate
#

hi is "blue" broken or something m trying to run the "eternalblue" but it sad 'Connection reset by peer'

eternal summit
#

The room is not broken

#

Update your metasploit

fresh agate
#

i update it to 6.0.30 v

deft elm
#

On exploiting NFS just in case

wheat fractal
fresh agate
eternal summit
#

No it's fixed in msf6 now.

odd shadow
#

Task 3: Privilege escalation, shell never comes back it just hangs

#

for Alfred

mint harbor
topaz thorn
#

It works fine, others have completed the room

mossy zinc
#

hey guys, i'm the kiba room https://tryhackme.com/room/kiba and i'm unable to receive a shell, i read this https://beginninghacking.net/2020/08/28/try-hack-me-kiba-this-room-was-released-today-this-will-get-unlocked-after-3-days-otherwise-you-can-use-the-root-flag-to-unlock-it-thmp___s/ and followed what this writeups says but i'm still unable to receive the shell and gain a foothold into the machine

The skills to be tested and needed to solve this room are: rustscan, CVE, capabilities, privilege escalation, reverse-shell, and nc (netcat). This room was released today 8/28/2020, and I wanted to…

eternal summit
mossy zinc
#

alright i'll post this there

#

i tought it was a bug since following what was written in many writeups wasn't working

oblique hemlock
wheat fractal
#

Docker does not seem to able to start.

eternal summit
#

!docs verify

tropic flameBOT
wheat fractal
#

Is this intended for me?

eternal summit
#

Yes, because currently you can't embed images.

wheat fractal
#

I'm okay with that.

dusky junco
#

Your Docker daemon shutdown/started up too quickly after the changes

#

did you simply restart the service or stopped and started?

wheat fractal
#

I did wait more than a minute. Stopped and restarted it.

#

'Started it'.

dusky junco
#

Mhhm interesting

#

Only thing I can recommend is restarting your PC -- if not, use the attackbox (:

wheat fractal
#

I'm sorry, but this is the Attackbox ^_^

dusky junco
#

Oh it is?

#

That's not good ahah

#

Okay -- lemme take a look into that Coldlip

wheat fractal
#

Sure, thanks 🙂

#

What i tried:

  • Waiting 60+ seconds for startup
  • Reset both the room and Attackbox
  • Change the configuration from docker-rodeo.thm to docker.thm in both HOSTS and the configuration of Docker.
dusky junco
#

I just gotta catchup on a few things w/ work so it'll be ~20 mins before I can start investigating

dusky junco
wheat fractal
#

Sure, i'll just give this another try and see if i can start it with increasing delay, or debug it. Ill keep you posted 🙂

dusky junco
#

Appreciate that! I'll get to debugging it myself when I can (:

wheat fractal
#

@dusky junco I made a video which shows the bug, perhaps i can DM this to you?

dusky junco
#

Sure! I'll open my DM's (:

#

Should be good to send @wheat fractal

ruby swift
#

Hey, I'm trying to do The Great Escape box I have the backup api's location but when I'm trying to request it using the current active api (exactly like writeups and John's video showed) I dont get the 400 respcode.

I only get

An error occurred: api-dev-backup
                Response was:
                ---------------------------------------
                <-- -1 http://api-dev-backup:8080/exif?url=http://localhost
Response : 
Length : 0
Body : (empty)
Headers : (0)

I dont know what to do. I waited for the box after a redeploy for like 15min but it's still not working

gleaming shadow
#

we're looking into it, it seems to only affect the free tier for some reason

dusky junco
#

Hey all, for users who have had issues with https://tryhackme.com/room/thegreatescape we've increased the resources (doubled the amount of RAM) that the instance that you deploy has.

You'll need to terminate the instance that you've got running in the room currently and refresh the page to ensure the changes reflect for y'all (:

(Please remember to respect the rules regarding the non-disclosure of sharing hints/giving answers/asking for help)

Any further issues please let us know! ❤️

gleaming shadow
#

can confirm, boots up much faster

eternal summit
#

Answer tolerance, refresh.

jade raft
#

Not a bug but after chmod 544 .profile
Shouldn't be
-xr-r--r--
?

#

Task 15 Learning Linux Part 2

#

I'm talking about .profile permissions

gleaming shadow
#

you need +w to be able to redirect into the file

#

544 is an odd permission

#

more common are 644 (rw for owner, r for all others) or 755 (rwx for owner, rx for others)

civic brook
#

you could always go 777

gleaming shadow
#

777 is overkill and you know it

#

I'd treat that as a firable offense as well

civic brook
#

I have worked with a few people that have done that in their home

gleaming shadow
#

they are wrong

#

unless you want a security hole the size of an A380

#

or a 747

#

btw 747 is also a stupid permission, don't use that either

civic brook
#

C130

gleaming shadow
#

point stands

#

so what are you trying to do, @jade raft

#

ah I see,

#

permissions are generally displayed as rwx rwx rwx

#

the numbers in chmod are in octal (base 8)

#

if you translate to binary, 544 -> 101 100 100

#

meaning r-xr--r--

jade raft
# gleaming shadow you need +w to be able to redirect into the file

Y I mean that screen I posted is what they show on lesson..
I think there are something wrong after in the example the author use
chmod 544 .profile
In the line where u see the green .profile I think the permissions should be -xr-r-r-- and not -r-xr--r-- as appear in the screenshoot above

gleaming shadow
#

so r is the 4's place, w is the 2's place and x is the 1's place

#

naw the screenshot is correct

obsidian kiln
gleaming shadow
#

and the handy blog post with pictures 😛

muted skiff
#

Is room the great escape still broken? because it seems that docker daemon is down 😦

midnight hollow
#

Do you know in which port the Docker is running?

gleaming shadow
#

ah sorry, misread

midnight hollow
dark ferry
#

Internal pentesting room-bug

#

I'm trying to login into a site but i keep getting "hmm. We're having trouble finding that site"

#

It's a login page. I found it. But when i try to login to it ,it doesn't even show a wrong password error ,it simply redirects to we can't connect ro the server at internal.thm

#

After i click the login button it redirects to a dns "internal.thm"

#

It redirects from an IP address to dns

#

I tried to check what's the problem by intercepting with burp

#

Apparently there's a "redirect_to" command right after one clicks on login button

verbal sedge
dark ferry
#

Yes

#

I am @verbal sedge

verbal sedge
dark ferry
#

Yes

verbal sedge
#

working fine for me

dark ferry
#

Damn. Why isn't working for me .

verbal sedge
#

have you added internal.thm/blog in your /etc/hosts?

dark ferry
#

Yes

#

Lemme see

#

But i remember doing that

balmy kite
#

OWASP Top 10 - Task20 - Q5 Keep getting the same pop-ups the 2nd with the answer, but that is not accepted as an answer. Can't get anything else from it, so? Anybody have a suggestions?

cerulean inlet
#

@balmy kite you'll probably get better feedback in #room-help if you haven't posted there already

balmy kite
jade flax
#

I'm having issues on the Intro to Django room. Tried reaching out to the room creator but can't message unless I'm their friend and they aren't accepting any more requests. Anyone friends with @next bluff ?

hazy tiger
#

Swafox is unavailable at the moment. Please state your issue:)

jade flax
# hazy tiger Swafox is unavailable at the moment. Please state your issue:)

I was having issues with the lab and went to their GitHub where they listed exact code to make the lab work. I've used that code verbatim and am still having problems. The instructions state browsing to http://127.0.0.1:8000/Articles will show your app running. I get error 404. Same with 0.0.0.0:8000/Articles. Also in the instructions they show some code that will generate a "Hello World" upon visiting the URL that your app is at. Unfortunately they do not tell you where you're supposed to place this code to generate the response. Like I said, my code matches what they had posted on GitHub perfectly.

#

Another small issue with the lab is that the code they have posted on GitHub is not exactly what they have you do in the lab. I've taken screenshots and notes on the differences if that would help.

obsidian kiln
#

!rule 1

tropic flameBOT
#

Rule 1: No unsolicited direct messages (DMs) or friend requests to other members of the discord without explicit permission. You may DM members of the moderation team without asking if you have an issue with another member in the Discord. The community manager (Dark) may be DM'd without restriction.

obsidian kiln
#

and all

jade flax
obsidian kiln
#

Preferably ping them in the server first

jade flax
lyric walrus
#

hello

#

here to report a bug

#

second question, how many ports open? the answer wants you to type 7, while with nmap -sV -p- -vv -A machineip i find 11

#

21,22,80,111,139,445,2049,37543,38199,40785,54805

#

either the question should ask only for ports under 1000

#

or the answer should be 11

#

imo

#

thank you!

harsh zephyr
#

I think its fine...Kenobi is a beginner room, so "nmap targetip" without any switches.

eternal summit
#

Nah it should say under 1000 if it means under 1000

#

No harm in making it clearer

gleaming shadow
#

I mean, it gives you the command to run in the hint

lyric walrus
#

i get it, but kenobi is also at the end of the complete noob series, so imo, after having run a shitton of nmap scripts you shouldnt just assume someone's gonna look at the hint

#

while in other rooms a lot of time it is said you should always look for higher ports

#

that's just my opinion but nothing wrong with a clearer explanation

hazy zenith
#

Having an issue in the enumerating telnet task. i've run nmap -T4 -p- <IP> as well as nmap -A -p8012 <IP> the answer after running should include the phrase Skidy's Backdoor. however I am just getting 8012/tcp open unknown. looking up online and it should include a lot more data ie. Skidy's Backdoorphrase. I have run on both the virtual box as well as the VPN.

eternal summit
#

It seems to only give the banner on first connect

hazy zenith
#

it seems that way. Reaching out to a friend in cyber world, he tried and had success getting all the fingerprint info running same commands. he also said that because of certain firewalls, connection, etc not enough info is collected from the scan to do OS detection.

#

clearly he is more well versed and I the beginner lol. any help with a workaround would be greatly appreciated

raw bison
#

I'm doing the tryhackme.com/room/windows10privesc Task 9

Unfortunately there is no password in the registry. This issue was reported several times in the past 2 month already, but it seems it's still not fixed? As it is part of the beginner path it is quite frustrating to not be able to do this task and complete the path.

oblique hemlock
glad badger
sonic willow
fading warren
#

In Investigating Windows room 5th question the answer format is said as
Answer format: username1, username2
But is
Answer format: username1 username2
(without the comma)

gleaming shadow
#

Answer tolerance?

eternal summit
#

Refresh the page @fading warren

fading warren
mint pivot
#

Hello! I noticed that the binary 'shiba2' in the Linux Fundamentals Part 2 room gives a seg fault upon execution. I think this is a bug? Unless I'm just doing something wrong (just running it like ./shiba2)

obsidian kiln
mint pivot
#

ahhhh haha okay got it. thanks!

rain bison
#

Hey

I’m on the easy challenge of the Hacker101 room and I managed to load once the support.php page on port 8002 but now I can’t ... is it normal ?

obsidian kiln
#

Could you send me the IP address via DM please?

rain bison
#

It loads forever and timeout

rain bison
obsidian kiln
#

Yes

gleaming shadow
#

it';s on 8001 no?

#

I'm assuming that it's normal that the button on the page for the server on port 8002 does nothing?

obsidian kiln
gleaming shadow
#

oh

#

that might explain why I'm not getting anything

obsidian kiln
#

Yeaaaaah

#

Htaccess is horrible

gleaming shadow
#

like anywhere

obsidian kiln
#

Oh, it was just 8002 that was acting up

gleaming shadow
#

ah

#

bugger

obsidian kiln
#

The other two are fine and have been from the start

gleaming shadow
#

ah

#

yeah ok, having the JS works better

gleaming shadow
#

I still can't see how to compromise 2 though...

vast cypress
#

(it is)

fallen pine
placid abyss
#

So apparently you "dont need to be connected to the network" to access this room, maybe this was a spelling mistake or something because I certainly cant access it without connecting to the VPN?

wheat fractal
#

Hello, I would say that here the author swapped P and NP in the this paragraph and it may be confusing for someone reading it! Am I right? We may fix it! https://tryhackme.com/room/johntheripper0

What makes Hashes secure?

Hashing algorithms are designed so that they only operate one way. This means that a calculated hash cannot be reversed using just the output given. This ties back to a fundamental mathematical problem known as the P vs NP relationship .

While this is an extremely interesting mathematical concept that proves fundamental to computing and cryptography I am in no way qualified to try and explain it in detail here; but abstractly it means that the algorithm to hash the value will be "NP" and can therefore be calculated reasonably. However an un-hashing algorithm would be "P" and intractable to solve- meaning that it cannot be computed in a reasonable time using standard computers.

eternal summit
placid abyss
#

Ah I see, no worries 🙂

torn tinsel
#

I think the WebOSINT room has an error. ..? The ICANN site doesn't list a registrant for the first site (like it does for, say, Google) and whois.domaintools.com lists an answer that's rejected.

sonic willow
#

https://tryhackme.com/room/intro2windows, task 4
it has a section on Registry Editor, then a section on Command-line tools, and then beck to more information on Registry Editor, should that not be moved up?

hollow pilot
#

My server keeps timing out learncyberin25days task 5

sharp wave
#

webosint - task2 - What is listed for the name of the registrant? -- i think this is a bug

#

if the answer used to be what its looking for, i think what it is now has .. changed.

inland scaffold
#

im trying to get the second task for the Rick and Morty CTF room, and i use all the options to display the second ingredient in /home/rick, and blocked, which is correct. I try to use the Less command and nothing appears at all. Is this correct?

obsidian kiln
inland scaffold
#

i was using a walkthrough and it worked like a charm for them

#

||cd /home/rick; less 'second ingredient'||

#

ty tho

oblique hemlock
#

Grammar in this sentence in the room LFI Basics

harsh pumice
#

it's which

oblique hemlock
#

@green steppe it seems like the shodan.io room's pictures and the linked blog post are not working anymore

gleaming shadow
#

JVM Reverse Engineering, task 5, the image is broken

balmy kite
eternal summit
#

It's not broken, it was tested and there have been 0 other compliants.

inland narwhal
#

Someone is having trouble accessing "Alfred room" ( path OSCP )? the room does not load

obsidian kiln
#

@balmy kite you need to figure out why it isn't working and modify the exploit

obsidian kiln
#

You can't just run an exploit and assume it will work

#

The room is not broken -- it just requires more thought than blindly throwing exploits at it

balmy kite
obsidian kiln
#

Keep trying -- you'll get it 🙂

balmy kite
#

Maybe, now busy with other rooms.

obsidian kiln
#

Focus on getting RCE first. Then worry about the shell

balmy kite
#

Yeah, the RCE indeed. I will give it another try, soon.

gleaming shadow
#

I had a fair amount of trouble with the RCE but the room does work

#

the classic examples you'll find probably won't work exactly as written

#

good hunting

jagged dove
#

The right answer is ||community.splunk.com|| currently the answer is ||answers.splunk.com|| which also redirects to ||community.splunk.com||

#

This is quite hard to find by googling so it may take the user to look into old posts before getting the current answer.

eager moon
oblique hemlock
eager moon
dusky junco
dusky junco
dark yarrow
#

I was solving this Bash Scripting room and found that this question is accepting this wrong answer. It's not a bug, just a slight error and couldn't find any related channel to post this so i am posting this here.
Thanks 🙂

compact crag
#

Hello, could anyone help on the OWASP juice shop room, task 7, question 2, I managed to get the xss executed on the last login page, but no flags displayed!

oblique hemlock
dark yarrow
#

Yeah just felt like i should inform 🙂

gleaming shadow
gleaming shadow
dark yarrow
#

Thanks @gleaming shadow

balmy kite