#room-bugs

1 messages Β· Page 20 of 1

oak mica
#

good luck! also just a general tip, maybe default to the room-hints or room-help for a while, sometimes things that seem buggy are intentional!

#

(also ensure you read the entire documentation in case you miss a step and look like a goose honkpeace )

tribal pagoda
#

Ok, thanks for the tips, yes, pretty new to THM. I found that sometimes you need to type singular/plural correctly to get it right, things to pay attention to.

#

got it now πŸ™‚

obsidian flame
twin bay
obsidian kiln
#

@twin bay It's a caching thing. They didn't actually get the blood points -- they were just the tester for that room. The graphs aren't resetting properly

twin bay
#

I was wondering how they managed to root the box in 6 minutes πŸ™‚

agile void
#

Hello, I had a problem in blue room , I found all flags but when i submit them it says they are wrong

#

any suggestions?

hazy tiger
#

Screenshot?

agile void
#

sure

hazy tiger
#

You need to verify to post images btw

#

!docs verify

tropic flameBOT
agile void
#

the flag is in the screenshot

#

can i share it?

oak mica
#

considering it doesn't work its probably not correct, so maybe spoiler it and share it πŸ™‚

obsidian kiln
#

Yes, we can delete it after πŸ™‚

agile void
#

ok

#

!docs verify

tropic flameBOT
verbal sedge
#

Follow the steps in that link ^

oak mica
#

well, you are correct you need to copy the flag{} parts too

#

(most CTF's and flags on THM will have similar structures)

agile void
#

I tried wwith {

hazy tiger
#

Use the TryHackMe answer formatting as a hint on how your answer should look.

#

Symbols will show up in the answer format.

agile void
#

i tried with spaces too

hazy tiger
#

Look at the answer format.

#

Remove your answer.

#

It should say "Answer format: [symbols]"

agile void
#

Got it

#

thanks πŸ™‚

hazy tiger
#

Happy hacking!

somber vessel
#

I think this room is bugged https://tryhackme.com/room/uploadvulns. I'm on Task 11 I tried accessing my uploaded payload through the ||admin|| page and it always returns "Module not found", despite going back one directory level ../dir/file.extension

austere ore
#

https://tryhackme.com/room/uploadvulns this machine worked fine few hours ago, now it crashes instantly or almost instantly once you start running a gobuster attack on it, even with 2 threads or something pitiful like that. Few hours ago it could handle 200 threads just fine

#

I have rebooted that machine 4 times now, to no avail. Reconnected to THM network via Openvpn, cleaned my host file 4 times, nothing is running except openvpn and gobuster. No burpsuite, no proxy no nothing

warm maple
#

hey, I think there https://tryhackme.com/room/linuxprivesc in "Weak File Permissions - Readable /etc/shadow " is a problem. Root user password *321 cracked by john and accepted pass is different *123 yell_cat

warm maple
eternal summit
#

Okay

#

Often people report answer tolerance as a room bug

warm maple
#

I can show images, can I pm?

warm maple
eternal summit
#

It's not

#

But refreshing was a way to check

light harbor
#

In "CC: Pen Testing"
One question is for the flag to make a ping scan with nmap.
But "-sP" is not accepted

obsidian kiln
#

-sP has been deprecated for years -- how old is your nmap?

light harbor
#

v 7.91

#

Its still in the man page

obsidian kiln
#

That's latest. It should be in the man page as an aside saying that older versions of nmap still use this

light harbor
#

Googled it. Search in man page of nmap does not show a hit for "-sn".

obsidian kiln
#

That is the latest version of the man page

light harbor
#

I see. My version is from 2019. Doesnt get man pages update, when using "apt upgrade"? Im confused.

obsidian kiln
#

They should get updated, yes

light harbor
# obsidian kiln

Yes. this one is not in my man pages. Okay, will have to check, why they did not update.
Thanks for your help.

obsidian kiln
#

How odd. Np πŸ‘

deep cedar
#

whut ?

eternal summit
#

Answer tolerance

deep cedar
blissful lotus
#

In room "Cyber Scotland 2021 " task #4 doesn't work (used site repairshop.sbrp is not available)
What can i do with that?

obsidian kiln
glad plume
obsidian kiln
#

@twin tapir room go borky

eternal summit
#

I was doing that during the week

#

Was working fine

glad plume
#

It'll maybe be usable for ~30min to an hour but then disappears from downlaods folder

#

happened two or three times already

glad plume
#

mimikatz will exit and not in downloads folder anymore

twin tapir
#

That’s usually because you did something defender didn’t like and it turned back on Real Time Protection because #windows

sharp wave
#

so they hydra part in hackpark
task2 - the command they give you doesnt work and to fix it to make it work you have to change it entirely to where what the room gives you it hurts you more than it helps

mighty crescent
#

I am in remux the termux room i choose wrong answers on purpose but it marks it as correct then refreshing page changing my answers to correct one

gleaming shadow
#

Answer tolerance maybe?

#

How far off the correct response were you?

hazy tiger
#

It's 100% answer tolerance.

twin bay
wanton tide
#

In the powershell room, Task 4 Question "How many ports are listed as listening" the machines says 22 but the correct answer is 20

twin bay
#

Works when I remote in

#

Task 4 Question "What is the path of the scheduled task called new-sched-task?" Answer is \, they want /

somber vessel
desert plover
#

Hello, Can someone help me with a room that i do? The room is Linux Agency

eternal summit
#

This channel is for reporting bugs with rooms

glad badger
twin bay
crimson maple
#

Learning Linux Part 1 room issue: Start machine button starts the attack box rather then starting the machine. Plus, the attack machine is blocked. Part 2 room is working without issues.

eternal summit
#

Didn't start the attackbox for me, just didn't provide the in-browser access like it should

#

Ok, it did. Just took an extra minute

crimson maple
#

Weird.. that’s didn’t happen for me

eternal summit
#

I'd argue the bug here is a site bug - It didn't show the in browser access until I clicked a button along the top

crimson maple
#

Okay, I’ll try again. Thanks @eternal summit

twin bay
#

https://tryhackme.com/room/zer0logon

  • Task 3 - On line 9, we supply the the DC_Handle - Only 1 the should be there
  • Task 3 - As expected, most of the field nmes -> field names
  • Task 3 - about sloting it into the PoC -> slotting
  • Task 3 - save you the painsteaking effort -> painstaking
  • Task 3 - The hint for the first question refers to Task 2, Figure 3 - Task 2 - Impacket Installation has no figures
twin tapir
#

@viral cobalt fix it fix it fix it

calm kernel
#

hi
I am on OWASP Top10
and machine is very slow
when I use a command it lasts 2 min loading and finally cannot laod
then I refresh it loads and executes the command instantly
I don't knopw why it happens I have good connection

eternal summit
#

What box? There's like 9 in that room

calm kernel
#

Task 5

#

but I've done another web-based machine before and it's the same

#

it's so slow

glad badger
crimson maple
glad badger
eternal summit
#

You gotta click another button first

glad badger
#

Is it Learning Linux 1? I will try it and see if I can reproduce the problem.

eternal summit
#

I've also pinged skidy somewhere to see if it's intended

glad badger
#

Mine worked. That's strange.

eternal summit
#

Just the button to show split view

#

Like that

#

I don't know if that applies to fresh accounts

glad badger
#

I'm now adding the AttackBox. It will show the selector at the bottom between the two.

eternal summit
#

But I'd class this as a bug for this room for sure, seeing as it's confusing if you are expecting a machine to appear.

glad badger
#

When you hit the Show Split View, is the instance still deployed, or does it redeploy?

#

I exited Split View, and it still shows the VM's active machine information.

eternal summit
#

Yeah, it shows it. I just doesn't provide access

#

Remember, this is a lot of people's first room with in browser access

#

So if you need to do something special (click the Show Split View) button, it should be listed.

glad badger
#

Beyond the blue button Show Split View ?

eternal summit
#

What do you mean?

glad badger
#

I thought the appearance of the Show Split View button is pretty clear to get back to the split-view.

eternal summit
#

And it's not "getting back" if it never enters split view to start with

#

it never enters split view if you weren't in split view previously (Eg with the attackbox, or another room)

#

I click deploy, it does not enter split view.

glad badger
#

You'll probably have to video that one πŸ˜„ It worked for me. πŸ˜„

eternal summit
#

This is because I previously exited split view on another session/room etc

glad badger
#

Okay now I see the issue. It's a room-state problem. Question is how often that would occur.

eternal summit
#

Enough to cause confusion

#

It happened to someone earlier, it happened to me

glad badger
#

When a room deploys it should reset whatever value determines show split view

eternal summit
#

It's a deviation from the expected behaviour, and it's something that new users are more likely to hit than experienced users given how often In Browser access to target VMs is used.

glad badger
#

That should probably solve it.

#

Or reset it on terminate.

north gyro
#

Waste water valve, or separator valve, cant make up my mind

#

hint contradicts the task

hardy dragon
#

I am playing startup ctf on tryhackme but when i found suspicious.pcapng and i tried "file " command to check type of content but it shows me empty

zealous vortex
#

I'm in the ccpentesting room, and there's a minor bug in the answer acceptance on gobuster question 5: how to specify username. It allows "-u", when really the arg is "-U", and -u specifies the target url.

#

same for the next one, regarding password (-P) allowing -p whch is proxy

eternal summit
#

That's more of a platform bug TBH

#

Room creators get precisely 0 control over the answer tolerance

zealous vortex
#

ah. So Perhaps not an easy fix, then. I noticed a while ago that answer comparisons seem to be case insensitive, which usually doesn't matter, but this is the first time I've noticed that it's actually meaningful (but again, minor)

mystic ruin
#

In the Attacking ICS Plant #2 (Attacking ICS 2h) Room there is a Hint in the second flag. Specifically, it says "Open the feed pump, the outlet valve and the separator vessel valve while keeping the waste water valve closed." but the task is about letting the oil flow ONLY through the water valve.

The Hint should be corrected to this "Open the feed pump, the outlet valve and the waste water valve while keeping the separator vessel valve closed."

dusky junco
lunar vortex
#

For the Intro to x86-64 room, the R2 VM has no login information or rdp access

lunar vortex
#

Ah.

eternal summit
lunar vortex
#

Yeah sorry I was only looking in the task with the machine

dusky junco
#

For anyone who had issues with https://tryhackme.com/room/enterprise: We've doubled the resources that it deploys with for all users so it should be much more smoother. We increased the resources before the room was deployed but there was a bug on the back-end where it didn't exactly apply these (:

twin bay
rose aspen
#

nmap xmas scan. Free room, free machine, scan takes longer than free availability.

eternal summit
#

wat

north gyro
#

is the pastebin link broken in KaffeeSec - SoMeSINT or am i just doing it wrong?

dusky junco
#

It should be updated @north gyro you may have to refresh the room /re-deploy the box...but I'm working very closely w/ the creator on this to get it resolved over the next day or so

north gyro
#

thanks, just glad I'm not doing the same thing over and over expecting a different result

north gyro
#

its fine, just needed to try harder

dusky junco
#

Ah no worries

#

sometimes a bit of a fresh air/a break does wonders

#

Appreciate you reaching out though

nimble osprey
twin bay
#

https://tryhackme.com/room/sysmon -> Configuration preferences will vary depending on what SOC team so prepare to be flexible when monitoring. prepare to be flexible when monitoring. - Duplicated sentence.

dusky junco
soft terrace
loud breach
soft terrace
#

if so why is characters written correctly at the beginning happyPanda @loud breach

soft terrace
#

Don't worry. Me too

nimble osprey
dusky junco
#

New users will be signed up to the one that the data/results shows as the most useful but that's good to know @nimble osprey

loud breach
#

I think there is a port mistake on this part.
It's work on port 5001. isn't it?
somesint room

twin bay
twin bay
#

You spelled it Charachters twice πŸ™‚

undone drift
#

Room: HackPark
Task 3

I guess that "undefined" is not intended, right? 🀭

eternal summit
#

That's probably not so good...

wheat fractal
#

wait how'd i get pinged

eternal summit
#

-undelete -a

livid escarpBOT
#

Up to 10 last deleted messages (last hour or 12 hours for premium):

none...

eternal summit
#

@wheat fractal I saw someone ghostping you but I can't say who because no logs

timid imp
#

I can't use the exploit of ||icecast|| in the ice room. I have installed on my host machine(windows) and on my vm kali linux and both don't work and my anti virus turned off. is there a other way to get ||reverce shell||?

eternal summit
#

Check your firewall. Make sure the VPN is running directly in the kali VM.

#

There's no other way, because the room is designed to showcase that vulnerability

timid imp
#

OkΓ©

civic brook
#

spelling mistake in Password Security, ripes should have an 'n' in it

glad badger
civic brook
#

today

#

sorry hadn't refreshed it since yesterday, guess it got fixed

glad badger
#

No worries. I fixed it yesterday. πŸ™‚

civic brook
#

I got very stuck on that

glad badger
#

But now the room solution has to come fruition πŸ™‚

soft iron
#

Hello, simple url mistake on a link in the OWASPTop10 room on task 26, the link is pointing to ".../myprofile." instead of ".../myprofile" if ever you think it is worth fixing as it is a "reward" page

eternal summit
#

A screenshot describing where would go a long way

soft iron
dusky junco
#

Oh ofc that's my section of the room LMAO

soft iron
#

lol

dusky junco
#

A patched box is soonℒ️ for that ty for the reminder but bare with

#

Updated -- please refresh (:

soft iron
#

np, is it ok if to tell you guys here if there are minor things like these?

dusky junco
#

Please do (:

#

Appreciate you taking the time to do so!

soft iron
#

okidookee

twin tapir
#

new room - pyLon, Image seems odd

#

Also just overall odd wording / grammatical errors

#

@north gyro I think this is you?

#

source code is also on your GitHub which Im not sure is an issue or not?

north gyro
twin tapir
#

ah no, you can change anything about a room at any time: In the queue, ready to be public, or public

north gyro
#

the github is fine, I dont think it will lead to any hints though.

#

but at least you know what youre up against

#

well someone has solved it, did i expect anyone else to be the first, no

dusky junco
#

https://tryhackme.com/room/pylonzf has been made private and locked for the time being. Working w/ the creator to get this out back into the public ASAP (: If you catch wind of people having the "This room has been locked" this is why. Apologies for the inconvenience this causes.

raven plover
#

minor thing in somesint, task 3:
Here is a guide on google dorking does not link anywhere

north gyro
eternal summit
obsidian kiln
#

At least with you it's always the testers telling you to fix stuff

glad badger
eternal summit
#

Again, if you break stuff we'll complain at you and try to get it fixed

#

or in some cases, the room will just be made private till it's fixed

north gyro
glad badger
sonic willow
#

can room testers see changes? sort of like a version control type thing?

eternal summit
#

Unfortunately no

glad badger
soft iron
#

Phrasing mistake on OWASPTop10 Task 30; See yellow marker

glad badger
north gyro
#

ISO27001 room
Grammatical issue

topaz thorn
#

That's a private room atm

#

They're recently trying to fix it up

north gyro
#

it came up when i went to learn

#

is that a bug

obsidian kiln
#

It was set to public quietly the other day πŸ™‚

vast harbor
#

from intro to research

#

that switch is for saving a file not opening one

somber vessel
#

Task 12 in room https://tryhackme.com/room/wireshark instructions are outdated. Latest version of Wireshark isn't showing SSL on its list of Protocols, instead you can now find the RSA setting on the TLS

#

I'm using the Wireshark on Kali 2021.1 btw

obsidian kiln
#

Not in the Kali version it ain't

undone drift
#

Room: Game Zone
Task 3.

I think is missing a to from there 🀭

twin bay
#

This is further shown in Task 3 when they say This is where GPG comes in. GPG is actually directly based off of the OpenPGP standard.

novel fog
#

Guys I just wanted to say the room Internal is broken... something is wrong with it.... you can't access the WP Login for example

#

I woud send screens but I can't for some reason

eternal summit
#

It's not broken

novel fog
#

3 hours wasted... whatever

eternal summit
#

You probably just need to add something to /etc/hosts

#

!docs verify

tropic flameBOT
eternal summit
#

Follow that link to be able to post images.

obsidian kiln
#

Did you read this?

novel fog
#

ahhhhhhhhh ffs i didn't

#

well now i feel stupid and that cost me 3 hours so ..... yay

obsidian kiln
#

Always read the instructions πŸ™‚

novel fog
#

lmao

#

ok well thanks for the help

obsidian kiln
#

Np! Happy hacking πŸ˜„

novel fog
#

πŸ™‚

raven plover
twin bay
ember mulch
#

there is a bug in the room i am in

topaz thorn
ember mulch
#

network services

#

enumerating ftp

eternal summit
#

Why do you think there's a bug?

ember mulch
#

asks how many ports are open and there is only 1 open

eternal summit
#

Scan again after like 5-10 minutes.

ember mulch
#

ive already scanned like twice

eternal summit
#

...

ember mulch
#

this shouldnt be happening

eternal summit
#

There is FTP and HTTP running, HTTP just takes a while to start

ember mulch
#

that shouldnt be happening

eternal summit
#

It's a known issue. It's not a big problem, and I also told you the fix for it yesterday I'm 90% sure.

ember mulch
#

i know that, but still how am i suppose to learn properly when the boxes i am attacking aren't even giving me the correct info?

eternal summit
#

They are. It just takes time to boot.

#

This is a known issue.

ember mulch
#

ok, as long as its known

#

and they are working on it

#

thanks

eternal summit
ember mulch
#

@eternal summit gotcha, thanks man

umbral oasis
#

ey guys, any idea?

#

im unable to se the website

atomic briar
umbral oasis
#

they say "It might take around 3 minutes to boot properly"

#

and doesn't work

atomic briar
#

I'm guessing you probably need to build the webapp in Django to gain access to it, not sure. Someone who's done that room can probably help you in #room-help

umbral oasis
#

i will ask there, thank you so much

atomic briar
#

https://tryhackme.com/room/tmuxremux
This room has tons of grammatical errors and a few spelling errors. They aren't major but they make the room harder to understand than it should be.
Since there's so much text I've put my corrections in a pastebin file. I only got through Task 2, I can fix the rest of the room if needed.
https://pastebin.com/trLdUCTU

zealous vortex
#

Minor typo in johntheripper0 room. Task 6 "there is a change" should be "chance"

glad badger
zealous vortex
#

no prob. I'm amazed how fast you guys are

strong kelp
# umbral oasis

The problem is here: -oN flag specifies the file you write to, but you put the IP

#

It sees the IP as the name of the file

undone drift
#

Room: Pen Testing
Task 16

Hehe, it doesn't look like it is case sensitive 🀭

hazy tiger
#

Hmm must be answer tolerance

undone drift
#

yeah, I figure that this is needed but mentioning "Case sensitive" has nothing to do with the answer, in this case. I thought the answer was intended to be case sensitive 🀭 that's why I reported it

wheat fractal
#

Hi guys, I'm having problems in Enterprise... can someone help?

eternal summit
#

This channel is for reporting bugs with rooms, not for asking for help.

astral jewel
astral jewel
eternal summit
#

I don't think you're meant to interact with the site.

#

It doesn't tell you to, it's applying theory

astral jewel
#

Yeahr, its only little bit thinking πŸ˜„ - Thy for help

glacial wind
#

I am trying to do a gobuster scan in https://tryhackme.com/room/rrootme but at the start I did the scan with too much threds so it crashed so I terminated this and tried to lower more and more the number of threds and every time it crashed I tried 5 and it crashed. what am I doing wrong?

turbid wing
#

I don't know whether to report this..
I'm doing metasploit room rn ...while looking for write-up provided by @Mr.Holmes#3066 it redirects to dashboard ...just want to clarify whether it's intended or mistakenly submitted ...

eternal summit
#

That was part of a CTF IIRC

turbid wing
#

To me?

eternal summit
#

Who else?

#

The title looks like a CTF flag, correct?

turbid wing
#

Yes

eternal summit
#

Exactly.

turbid wing
#

So it is not a problem ryt

obsidian kiln
#

@fossil relic Can I delete those now?

fossil relic
#

Which ones?

#

Oh that

#

IIRC Dark said he deleted them after the event

#

no idea how they are still there.

obsidian kiln
#

Gone now πŸ€·β€β™‚οΈ

signal ridge
#

Room: networkservices2
Task: 6
accepts wrong answer

topaz thorn
#

That's answer tolerance, refresh and it will give you the correct answer

signal ridge
#

strange, shouldn't it give an error saying wrong answer ?

obsidian kiln
#

No -- it's there to make sure you don't type out very long answers, make a typo, then have to do the whole thing again

signal ridge
#

cool, thanks

misty cave
#

@hazy tiger Hey, just did your History of Malware room, all good, except "PERVADE" becomes "PREVADE" in the last paragraph and question of the ANIMAL section

hazy tiger
#

Sorry? I'm not sure I understand what you mean πŸ˜„

misty cave
#

it's a typo is all, the R and E have swapped order πŸ™‚

hazy tiger
#

Whoops! Good spot 😁 Refresh and they should be updated, thanks :D

misty cave
#

Yup, all fixed πŸ™‚ my day job means I spot all of those little things.

fierce summit
#

Hello people I have a problem, my good answers are not counting at all πŸ˜„ my dashboard showing 0 answers today.

eternal summit
fierce summit
remote hamlet
#

@north gyro Grammatical discrepancies with the room information at the top.


Being able to analyse a file and determine its contents is important, once you extract the hidden file in the image there is further work to do.``` Has run-on sentences. 

Something like this reads better.
```This room contains steganography and may be difficult. If you are finding it difficult to overcome, read the hint for flag 1.

Being able to analyse a file and determine its contents is important. Once you extract the hidden file in the image, there will be further work to do.```
remote hamlet
#

<3

topaz flare
#

Room: John The Ripper
Task: 11
Instructs to use python3 to run ssh2john.py python3 /opt/john/ssh2john.py This throws an error with missing python modules.
python /opt/john/ssh2john.py However utilising python 2.7 instead works as intended

weary veldt
#

any known issues with 'what the shell'? room is just spinning when I try and load the page. thanks

obsidian kiln
#

@weary veldt that's a problem with your antivirus. Add an exclusion for the tryhackme.com domain

static holly
#

Hi guys
Is there any known problem for the room "Mal: Malware Introductory"?
I've logged in over RDP and I'm in the task folder (damn slow...) but when I look in the properties it shows no MD5 hash as it should
In a picture there are 3 hashes and I got none

pine nova
#

Hey hey! Wireshark 101 room - task 5 is saying to continue to task 5 not task 6 πŸ™‚

royal spruce
#

The HackPark room is blocked at this stage...keeping this loading state eternally

#

Can anybody fix the broken room?

potent wyvern
potent wyvern
#

I did what i needed to do, set the variable, but i can't execute shiba2 still

potent wyvern
#

I think it is, but if it is not I'll accept it

#

Maybe it is some problem in regard to the room + webattack?

eternal summit
#

It is not broken.

#

If you would like help with it, please use #room-help
Otherwise, provide some evidence that it's broken here.

potent wyvern
#

I'll do, i even ran the command in the hint, but nothing

#

Shiba2 won't execute

eternal summit
#

Screenshots. But seriously, the room isn't broken. Please move to #room-help if you'd like help.

potent wyvern
#

I re-did the same procedure, but now it worked

eternal summit
#

You can break the binary if you run a command that ends in >> $USER

potent wyvern
#

Ah, i see

#

Thanks you, thm staff the best & most prepared. Is there a badge for the "premium" users? my levels aren't counting up in discord too

eternal summit
#

Re-verify with the bot

#

I'm not THM staff, just a discord moderator

potent wyvern
#

It's okay. I'll re-verify then

grim python
#

In "corp" I am unable to log into the Administrator account using the password. I got the second to last answer right that asks for the password so it should be correct. Im trying to login like I did for the other account for task 3 which worked.

eternal summit
#

It's expired but you can definitely log in.

grim python
#

I checked the guide and tried copy pasting the command (subbing in the target ip) but its not working and Ive tried multiple times to login, copy pasting the password and typing the password.

eternal summit
#

Some RDP clients don't work well with it

grim python
#

It worked for the login for the earlier question

grim python
#

Its also the RDP client suggested by the attached writeup and pre installed on the attack box.

eternal summit
#

If you have a windows install anywhere, try the real MS rdp client

grim python
#

Same issue, can login as the other account but not the administrator

golden rivet
#

Just β€œalmost” finished this Room. Docker method worked perfect on my Kali VM. And I will try to use OpenVas more now to test as Nessus is not working good on my machine (takes forever to load plugins)

But I could not finish the room because first question on Task 7 is not accepting my answers. Funny because it accepted the scan end time which is right under the scan start time... any tips on why?

#

Oops forget about. Just noticed I was missing the comma. Rubber ducky effect. Tell someone your problem and then you find right away 🀣🀣

twin tapir
weary veldt
north gyro
#

Hi, my room pyLon is suffering an issue that i think is related to lack of resources for free users, but i cannot confirm it, is someone able to DM me in regards to this?

obsidian kiln
somber vessel
twin tapir
#

@somber vessel that might be intended? I’m not sure

twin tapir
north gyro
wheat fractal
#

Room: Network Services - Task 9. Question-1: How many ports are open on the target machine?. Issue: I found that the answer is ||2|| but my scan says it's not true

eternal summit
#

Wait like 10 minutes

#

It'll open another port.

proven prism
#

In Network Services 2, Task 6, answer 9, the suggested .txt file is not under the listed file path on the Attackbox. The file path should be "/usr/share/wordlists/SecLists/Usernames"

eternal summit
#

@dusky junco ^ seclists on the AB

dusky junco
#

Epic

eternal summit
#

No it's something you should fix lmao

dusky junco
#

Oh i know πŸ˜›

#

oh

wheat fractal
#

Does anyone knows if the HackPark room will be available again? I notice that it's still looping in a loading state.

eternal summit
#

Skidy is aware

#

it's a bug.

raven plover
eternal summit
#

Refresh

raven plover
#

that solved it, thanks!

wheat fractal
twin bay
#

https://tryhackme.com/room/malresearching - Task 4 - I've written more about how malware detects it is in a virtual environment and the possible routes it can take to escape on my blog. - The link takes you to https://oldblog.cmnatic.co.uk/posts/so-you-want-to-analyse-malware/ which is a 404 page (I suspect it should take you to blog, not oldblog)

misty girder
#

https://www.tryhackme.com/room/easyctf - Task 5 - I'm unable to run the Python command, it doesn't work, after 2 hours of searching, i've look at the writeups and made the exact same manipulations and i keep having the same message File

I'm running from the attack box

here is the message, unable to go further than this even with python 2 or 3

"46635.py", line 25
print "[+] Specify an url target"
^
SyntaxError: Missing parentheses in call to 'print'. Did you mean print("[+] Specify an url target")?

sonic willow
#

python3 won't give that error

#

what error are you getting when using python3?

misty girder
#

@sonic willow root@ip-10-10-125-37:~# python3 46635.py -u http://10.10.56.192/simple --crack -w /usr/share/wordlists/rockyou.txt

File "46635.py", line 25
print "[+] Specify an url target"
^
SyntaxError: Missing parentheses in call to 'print'. Did you mean print("[+] Specify an url target")?

#

the .py exploit i got it from the internet and from kali too

sonic willow
#

okay let's move over to #room-help, this isn't a bug with the room

wraith mortar
#

asking this for a friend: he's doing the nmap room and he keeps getting ports filtered especially on FTP. I try myself and I don't get this, I get the expected outcome. Any reason why his nmap scan is not working?
He's connected to VPN etc

eternal summit
wraith mortar
#

Thanks

#

If he extended the room it would be okay?

#

@eternal summit He did restart the room and it still wasn't working though?

eternal summit
eternal summit
wraith mortar
#

Okay, but I just found it weird how I launched the room up myself and it worked straight away. He restarted the room and ran the same command and it is filtered. Very strange I thought

twin bay
wheat fractal
prisma rune
#

https://tryhackme.com/room/yara
In Task 9 the Loki tool has to be used to can a file for vulnerability. Tried using the tool that is present in the VM that is provided in the question and something does not seem right. The tool throws errors

#

Tried running command with sudo as well. But still getting the same error

twin tapir
#

eh it’s just complaining about one line in a file it should be fine

tired thorn
#

the virtual machine in metasploit room (Windows Fundamentals module) is down

#

also the blue room

#

is it in maintenance?

#

out of service for any reason?

eternal summit
#

Room machines can't be down as they're not shared.
@lucid oasis people seem to have trouble deploying these VMs atm.

tired thorn
#

yesterday this VM worked

#

today is different

eternal summit
tired thorn
#

ty πŸ˜„

lucid oasis
lucid oasis
tired thorn
#

hi @lucid oasis πŸ˜„

eternal summit
#

People have been reporting that they don't get an IP

tired thorn
#

it show this message but it doesnt start

eternal summit
#

It displays 'starting machine' then just nothing

#

Yep

tired thorn
#

its the only module that it happens I think

#

I've tried networking fundamentals and is all good

eternal summit
#

Do you know if it happens on the furthernmap room?

tired thorn
#

it works in nmap

tiny dragon
#

should be ok now

#

let me know if they're any issues

echo vector
#

Hi guys, the hackpark room, it keeps loading and it is part of learn path
never finishes loading

tired thorn
wheat fractal
#

Hi, I found the last room flag "intro to x86-64", but when I try to put it in the replies it won't accept it. I also looked at a write-up that solved this room, because I thought I was wrong, but it solves it the same way. Can anyone help me?

topaz thorn
#

You have to do something with the last flag and you will get the right answer

wheat fractal
#

@topaz thorn ok, now it tell me Correct Password

#

but still, what i need to enter on the field

#

ok I'm stupid sorry

#

It works

topaz thorn
#

Not at all took me a while to realise as well what I did wrong with that room

wheat fractal
#

thank you, I needed to carefully re-watch the assembly code to understand the what I was doing wrong, it was a little frustrating but quite a lot of fun. I know that that's beginner stuff, but I had to start somewhereπŸ™ƒ πŸ™ƒ

supple trench
#

There has come new statistics regarding room yara, task 11 Valhalla, in the cyber defense learning path. the latest month overrules the intended month

supple trench
soft terrace
eternal summit
#

@wheat fractal please don't post accepted answers. ls -lah list with hidden files.

wheat fractal
#

sry, my bad. And thank you very much! @eternal summit

somber vessel
round mantle
#

what

rich cloak
#

Not really a bug but https://tryhackme.com/room/linux1 seems to be missing [Section 1: Using SSH] or something like that. Planning to use this in a ethical hacking class this summer with some student new to linux and this would def confuse them.

eternal summit
#

You get a shell side by side in the room

misty cave
#

Hi @twin tapir, just done the wireshark room, and in Task 12 (HTTPS Traffic) the text says: "In order to load an RSA key navigate to Edit > Preferences > Protocols > SSL > [+], you will need to fill in the various sections on the menu with the following preferences".

it would seem that in Wireshark 3.4.4 (Latest version, was Pre-installed on my Kali) the workflow is different, and there is no SSL under the Protocols list. You can instead follow the same instructions, but enter the details in the "TLS" section of the Protocols.
e.g. "In some versions SSL is not in this list so we look for TLS instead, Edit > Preferences > Protocols > TLS > [+], you will need to fill in the various sections on the menu with the following preferences"

#

No SSL

eternal summit
#

It's kinda buggy: if you've fullscreened the attackbox from split screen before then it doesn't show up and you need to click a button along the top @rich cloak

eternal summit
# misty cave No SSL

Wireshark calls the protocol different things in different versions. If it was changed, you would get the other half of people complaining that they can't find it because it's under the wrong name.

misty cave
eternal summit
#

Maybe. That's up to Cry.

misty cave
#

Fair πŸ™‚

wheat fractal
#

HackPark is working fine again. Thank's for repairing it!

steady temple
#

There is a bug in CC Pentesting when you come to use meteaploit against the machine. The machine that's deployed is not listening on any ports and metaploit fails.

#

I spent some time thinking it was my metasploit but I have now successfully it against another machine, so I'm confident there is something wrong with that machine.

dense stag
steady temple
#

I suggest moving on. You don't need to have completed this step to do the rest of the room. I just wish I could mark the room as complete.

strong kelp
#

The part after . is it intended?

#

I mean, it does not make much sense

dense stag
steady temple
eternal summit
distant ice
tidal path
#

Hello, I am trying to join wreath room. I am not premium but apparently I should be able to access it with a 7 day streak?
I have a 7 day streak as you can see on the screenshot

obsidian kiln
#

There's something up with the streaks just now @tidal path. Check your profile page? I suspect it'll tell you 6 days

#

Yeah -- TL;DR: the one at the top is one day ahead

lost stag
#

Is there something wrong with the WebAppSec 101 room? When i start the machine the web server doesn't launch..
Tried to reset it without any luck. Port scan with nMap only reveals port 111 open.

undone drift
#

I know that 99% of the time, it is not a bug in the room but now I am pretty confused about this room.

Room: Brainstorm
First task.

I have run Threader3000 and nmap and I get 3 ports open. Apparently, this is not the answer. I am this dumb? What I am doing so wrong that I am only finding 3 ports?

#

I even got the root flag but I can't get over this question πŸ˜„

lost stag
#

Perhaps the room had services running in the past that is no longer running? Or that the answer simply is just set wrong..

undone drift
#

Yeah, I'm thinking about that too. That's why I am here 🀭 I suppose this is a bug

lost stag
#

According to writeups it shouldnt be more than these three.
It was easy to guess the answer though, even though that shouldnt be neccessary :p

strong kelp
#

I think it should be a picture in the background

hasty bison
glad badger
hasty bison
topaz thorn
#

Are you on about the linux privesc room?

hasty bison
topaz thorn
#

Never seen that one before

glad badger
#

Try /linuxprivesc

hasty bison
#

i have that room as well

#

does this mean the other room has been removed ?

glad badger
#

It looks like it, let me double check for you.

hasty bison
#

okay

glad badger
#

Yeah, that one looks like it is gone. There's also a second alternative: /linuxprivescarena

hasty bison
#

yeah i hv both of them

#

how do i quit the room if its removed ?

glad badger
#

Green Options button > Leave πŸ™‚

hasty bison
#

no i meant the one thats removed

#

all i see is that not found message

#

i also hv some rooms that i joined months ago and found out they arent free anymore, i cant quit them as well (there is no button)

glad badger
#

I think you can't leave a removed room, but there's no harm of it showing up in My rooms.

hasty bison
#

alrightt ill check it out

obsidian kiln
hasty bison
#

oh yeah ill give that a try as well, thank you

wheat fractal
#

Hello, I'm on room kafeesec , on task4, I have installed spiderfoot, but when trying a new scan I'm getting "Invalid target type" . I'm running kali linux just upgraded. Is this a known bug?

#

My bad, looks like the scan target needs to be set using quotes

severe monolith
#

In the room linuxmodules, on that's what she sed, the titles ("The purple gang" and "The green gang") are mixed up. NOT A BUG I guess, but a bit confusing

severe monolith
#

The purple gang has modes s and y

#

Shouldn't the green gang have those?

obsidian kiln
#

Oh, I getcha

#

Sorry -- was looking at the actual colours

#

Yep. @dusky junco

vast isle
#

Hi - Currently completing OWASP-Juice-Shop, and I'm not able to complete Task 6, Q3, remove 5* review, but when I complete the steps and get onto the page, I'm not able to see any 5*, ony 4 and below.

I've terminated the box twice, but it appears the same. At this moment, I'm not able to complete Juice-Shop

compact shoal
coral shell
#

hi i have some problems with this room Memory Forensics when im tried to download the file i get failed i repeated 3 times get 300mb and i get failed

placid abyss
#

Do you have space on your harddrive for the file?

coral shell
#

yeah

#

i have 45 go

placid abyss
#

Have you tried using a download manager for downloading it?

coral shell
#

i dont have it

placid abyss
#

The issue might be your browser from which your downloading it from..?

#

Try using a download manager (you can just search on Google for one)

coral shell
#

yeah i know it but im using linux right now

#

thanks bty, i will try again

placid abyss
#

There are download managers for Linux..... @coral shell

coral shell
#

i didn't know, good

long flume
#

Somewhere between a bug and feedback: my VM for this room on the Complete Beginner path is suuuuuuper slow https://tryhackme.com/room/intro2windows

I've had periods where it seems unresponsive for a few minutes. Part of it requires setting up some users and then logging in and testing stuff, but it takes several minutes to get through the login flow. Looking at the task manager from the admin account in my RDP session, it's constantly sitting at 99% CPU and roughly 95% memory. I think the VM might just be spec'd too low? (I'm RDPing at 1024x768 resolution, if that's relevant)

#

(It also says "Windows License is expired" in the corner, IDK if that's relevant tho)

topaz edge
#

@tropic flame the room Kenobi doesn't work for me at all. I've been trying to work through it, and nothing I do works like the writeups I've read. help..?

eternal summit
#

That's the bot

dusky junco
reef vapor
#

Hey. "OWASP-Juice-Shop, Task 7, Perform a persistent XSS!" Doesn't return the flag for me
EDIT: It worked, I had alert('xss') instead of alert(xss)

indigo orchid
#

In room/volatility, when I submit correct answer to this question, it doesnt accept it and says incorrect.
What process can be considered suspicious in Case 001?
I'm unable to complete the room. Just that one question remaining. Please help.

twin tapir
#

that room isnt even out yet

#

what

indigo orchid
#

i didnt even see how many days old that room was

#

but anyway, can you help with that issue? i can dm you what I think is the correct answer and you can let me know? @twin tapir

woeful cliff
#

Hi! It's not exactly a bug but it could save you some bandwidth/traffic fee. In this room: https://tryhackme.com/room/networkservices2 the Task 6 Enumerating SMTP
recommends to use: /usr/share/seclists/Usernames,
but in your attack box image it is here: /usr/share/wordlists/SecLists/Usernames
I guess many folks will just clone / download the git repo instead of using this local copy. I would modify the description.

eternal summit
#

Yeah, except the path provided is where it is installed in Kali

#

the attackbox should ideally be changed to match up cc @dusky junco

tired thorn
#

Hi

#

I think the VM of Attacktive directory is bugged

#

I did it yesterday and nmap showed the service of the VM

#

with open ports

#

I did it this morning too and it cant describe the service and the open ports changed

eternal summit
#

The VM won't have changed, most likely. Did you deploy a fresh machine? Using the IP you had before?

#

-sV and -A are redundant, -A does -sC -sV -O

tired thorn
#

this was yesterday

tired thorn
#

different open ports

tired thorn
# tired thorn

Is strange because the service that nmap says is running is Oracle VB not Windows

eternal summit
#

Looks just fine here

#

I blame your network

tired thorn
eternal summit
#

Certainly not an issue with the room

tired thorn
tired thorn
#

I dont know why its happening this to me

eternal summit
#

The room is working correctly

tired thorn
#

I am so stupid

#

I wasn't connected to the VPN facepalm

#

I don't know which device I was trying to hack 🀣

#

sorry If I was bothering you

twin bay
#

https://tryhackme.com/room/sqlilab - Task 9 - The URL does not include the port (5000). Task 10 has this set up correctly (Visibly anyways - The hyperlink location is still incorrect)

summer pond
dusky junco
wheat fractal
#

@everyone

remote creek
sudden basin
#

rust room didnt open

#

its just stuck at this

wheat fractal
#

dont know if it's quite correct place for it

#

this is correct answer , but it's not "restricting" ipv4 , it's 'forcing' to use ipv4

#

am i wrong ?

eternal summit
#

Your choices are 4 or 6

wheat fractal
#

yes

eternal summit
#

Restricting it to ipv4 means use ipv4 only

wheat fractal
#

ohh i see now

#

@eternal summit tanks πŸ™‚

sonic tapir
#

What's up with learn rust room? I see multiple people, including me can't load it.

frank creek
#

Exact same issue. It actually gives me 2 flags, which are not the right ones

undone drift
#

that tag, winpea it should be winPEAS

civic brook
#

not sure if the answer is off or if there is something wrong with Volatility, correct answer keeps getting a incorrect

hazy tiger
#

Try a cache refresh

civic brook
#

still getting the incorrect

hazy tiger
#

Hol' up

#

@twin tapir plss help

left tendon
#

yeah broken for me too. should be right as it matches the process id

twin tapir
#

I blame volatility

obsidian kiln
#

Go fix

left tendon
#

yuuusss fixed. sweet sweet green completed. thanks @twin tapir

last roost
#

Anyone else having problems with their AttackBox just shutting down? I've been trying to finish Blue for several hours now because my AttackBox keeps shutting down mid-exploit.

civic brook
#

room is good, thanks for the good room Cry

dawn rover
left tendon
#

it loads when i try it @dawn rover did you add it to your hosts file?

dawn rover
#

yes I did at the start of the room

#

wait I'll restart my machine and try again

#

It loads now , God I totally forgot about the hosts file

#

thanks @left tendon

analog zephyr
verbal sedge
analog zephyr
#

or any different way of accessing it for now?

verbal sedge
#

they will fix it whenever they can. I have no info regarding that.

analog zephyr
#

Thank you

twin bay
grim harness
eternal summit
#

@obsidian kiln fixitfixit

#

Or wait

#

Maybe don't, I don't know what CMN is doing lately

glad badger
grim harness
grim harness
# sonic willow i don't see a `+s` on task 4?

"Now, we're going to add the SUID bit permission to the bash executable we just copied to the share using "sudo chmod +[permission] bash". What letter do we use to set the SUID bit set using chmod?"

#

the answer to that question is a one letter answer, and it only accepts the s

#

yet if instead of +s the +sx is used, the assignment works, not if you use only +s

sonic willow
#

it seems fine to me, the binary should already be executable and hence have the x flag, but i'll spin the room up now and check for you

oak mica
#

I think it's to do with setting +s over-rides it being executable (+x) but i'm not 100% the "man ls" page for this is how I worked it out when I was confusing myself with it on a challenge in the past

#

's'
If the setuid or setgid bit and the corresponding executable bit are both set.

'S'
If the setuid or setgid bit is set but the corresponding executable bit is not set.

sonic willow
#

yeah i'm not sure what is being asked

eternal summit
#

The issue is that it was not executable before

#

Suid does not overwrite the executable permission, suid is an additional digit, you could use chmod 477

grim harness
eternal summit
grim harness
#

i've tried the whole thing twice, but it wasn't executable initially, apparently

paper basin
#

https://tryhackme.com/room/openvas

Not quite a bug I don't think but when using the attack box for this room, Docker would not start without me running the following commands:

systemctl unmask docker.service
systemctl unmask docker.socket

I can then run the Docker service via "systemctl start docker.service"

#

Might be worth noting?

frozen pier
#

I joined the new volatility room when it first came, didn't answer anything; today I can't go in , It says me I have to buy a subscription, but I don't have any, AND the worst thing I even can't leave the room, it just stands in My Rooms

#

Can someone help?

glad badger
obsidian flame
#

Hey @glad badger is it possible for you to relink that to the split version of zthlinux or even to the module?

eternal summit
#

I think CMN is doing something about the foundwtional Linux content this week

obsidian flame
#

Oki dokes, good to know

glad badger
woeful cliff
#

Dear Team, I'm practicing with this room: https://tryhackme.com/room/wireshark .
-Task 12 HTTPS traffic mentions Packet 11 while the picture is about Packet 36.
-"navigate to Edit > Preferences > Protocols > SSL > [+]" this option is now called TLS in WireShark.

left tendon
#

for reference, attack 5 and 6 require that the room machine have internet access

#

(which it doesnt πŸ™‚ )

north gyro
grim harness
#

@heavy spade my just updated msf6 cannot seems to find anything called socks5

obsidian kiln
#

Ooookay, and why do you need to ping an admin for that? @grim harness

grim harness
#

Ooh since it was his room, I thought it might make sense to do so. Sorry.

obsidian kiln
#

I have a feeling MSF changed the syntax. Try anything that looks like socks_proxy and set it to socks5 in there

grim harness
twin tapir
obsidian flame
#

but that may be a solid 4 months ago

hardy jungle
#

keeps loading

glad badger
#

Which room linked to /zthlinux? @hardy jungle

woeful cliff
hardy jungle
woeful cliff
hardy jungle
#

Well i think learn linux box just learns you things like cd and cat and ls and all the standard things

gleaming shadow
#

hey, for attackingics2, the second flag doesn't seem to work

#

will try reseting the box

#

and that somehow worked, probably a glitch in the matrix with the visuals

verbal sedge
gleaming shadow
#

410 is a rare code indeed

blazing raven
#

Hey, i think the ustoun box needs a resource boost it takes like 40 mins for the intended port to show up (Free users) the service is really slow too, since the Windows machines are up for like an hour or so its gonna make it hell for users to root the machine.
I completed the box last night trying to make the video walkthrough and its making it hell for me and i know a lot of people are stuck too probs because of that so thats why im asking, thanks.

mental bough
#

Having a problem in linuxstrengthtraining - the final flag won't get accepted.
There seems to be an extra character after the left curl bracket ({*******} dunno if that'll show in discord).
I've tried brute-forcing that last character, which naturally isn't reflected in the flag within the box, but I've had no luck.

#

Right curl bracket*

glad badger
mental bough
#

Thank you!

grim yoke
neat magnet
#

In the yara room the answer to Back to Valhalla, inspect the Info for this rule. Under Statistics what was the highest rule match per month in the last 2 years? (YYYY/M) has to be updated

proud pagoda
#

Room: https://tryhackme.com/room/uploadvulns
Task: 5
Bug: in the screenshot of the gobuster command, the mode "dir" is written without the -m switch (maybe in the previous version was a command?)

eternal summit
#

Your gobuster is outdated, by quite a long way.

#

3.0 released in June 2019.

proud pagoda
#

oh wow my bad then, thought so cause I had just installed it, better like this then, no bug

pearl oriole
eternal summit
#

Nope.

pearl oriole
#

Ty

frigid plover
zealous vortex
#

Minor typo in room "intro2windows", task 4, under disk cleanup: "just adding up to the computer disk space"

#

shortly below that, under "command-line tools" it says windows comes with 2, but actually lists 3.

spare idol
#

I am having a problem open vulnersity website I just says and error message and I am using openvpn and are a free to play

eternal summit
#

It doesn't run a webserver on port 80

#

Follow the instructions in the room

spare idol
#

I can try again or else I am gonna show a screenshot off it

sonic willow
#

aside from the first question in task 1, and task 4, every question is missing a question mark

twin bay
real snow
#

AllSignsPoint2Pwnage is the slowest room on THM I think. Unstable as well.

obtuse adder
#

This box (AllSignsPoint2Pwnage) should be deleted or fixed because it is OMEGA unstable and it dies after 30 min for no fucking reason.

austere kernel
#
└─$ ssh -i id_rsa kenobi@10.10.78.26                                        1 β¨―
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@         WARNING: UNPROTECTED PRIVATE KEY FILE!          @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0644 for 'id_rsa' are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key "id_rsa": bad permissions
kenobi@10.10.78.26's password: 
#

I can't use the private key in Kenobi

hazy tiger
#

Try chmod 600 id_rsa

#

Then re-run ssh.

austere kernel
#

I tried, doesn't work.

hazy tiger
#

Any errors?

austere kernel
#
β”Œβ”€β”€(kaliγ‰Ώkali)-[/mnt/kenobiNFS/tmp]
└─$ sudo chmod 600 id_rsa                                                 130 β¨―
chmod: changing permissions of 'id_rsa': Read-only file system
                                                                                
β”Œβ”€β”€(kaliγ‰Ώkali)-[/mnt/kenobiNFS/tmp]
└─$ ssh -i id_rsa kenobi@10.10.78.26                                        1 β¨―
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@         WARNING: UNPROTECTED PRIVATE KEY FILE!          @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0644 for 'id_rsa' are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key "id_rsa": bad permissions
kenobi@10.10.78.26's password: 
#

It stays perm 0644

hazy tiger
#

uhh wut

austere kernel
#

Have the feeling I'm either really stupid orr...

#

I can try moving the key out of the mount 2 my desktop?

hazy tiger
#

Oh

#

Yes, move it to your home machine πŸ˜„

austere kernel
#

Thank God, I am so smart.

hazy tiger
#

Haha, yeah you are!

glad badger
glad badger
storm flax
#

If I am doing a room and it asks a question which the answer is a domain name, but the domain name is now different to what the answer is, where would I go to get this fixed/updated?

The current answer to the question is a redirect to a different domain.

sonic willow
storm flax
sonic willow
# storm flax yes

okay, so the usual way is to just put the room name, task and question here and explain what's wrong, but i'll let dark know since i've seen this mentioned a few times

#

@heavy spade any chance you could update the last question on task 2 in the splunk room please?
https://tryhackme.com/room/bpsplunk
the current answer still works, but it redirects to a new subdomain (community), people have said it's hard to find by googling

storm flax
eternal summit
storm flax
eternal summit
#

Yes

#

I told you to report it here.

storm flax
eternal summit
#

I understand. But prior to this, you asked in #site-support and you were told to report it here.

storm flax
eternal summit
#

Where would I go to report it?
#roombugs

ancient token
#

Hi, in the room https://tryhackme.com/room/catregex there is a mistake with one of the answers
Question: Match every possible IPv4 IP address (use metacharacters and groups)
Answer: (\d{1,3}.){3}\d{1,3}

I actually probe these because regular expression are interesting for me but this doesnt work, I build another synstaxis according theory and it works, not the rigth

#

So the error was my copy -paste? or is the wrong sintax

#

this one works too

zealous vortex
#

there are regex tester sits online, if that helps. That's usually what I do when building a regex. you can input various test inputs that should get accepted and rejected

ancient token
#

the room actually gives you a online site the explain the hole function

#

the point here is that i belied that the "rigth" answer is not the rigth answerπŸ˜…

tranquil vessel
late orchid
#

doing the dogs cat room right now and i think theirs a small issue that im not sure if its intended

#

the log that im getting from LFI is very very very long

obsidian kiln
#

The log will be different in each box @late orchid

#

Depending on what you did to it before getting the LFI

#

i.e. if you ran a directory fuzz on it, the log will be huge

late orchid
#

is the alert also intended? in burp it opens just find but in the browser i get spammed by alerts saying nice and vulnerable as well as a ton of blank ones

jade idol
#

In https://tryhackme.com/room/bufferoverflowprep on task 4 (OVERFLOW3 ), the questions are answerable and both EIP and Badchars can be obtained to complete the task, but when I try to go on to get shell I always fail. The payload will not generate with the confirmed badchard.

unique wigeon
#

Hello everyone, I have experienced this for almost 3 days every time I want to play in the GLITCH room, I have tried resetting the machine several times but the results are still the same

wheat fractal
#

https://tryhackme.com/room/dailybugle

Dumping the database in this room didn't work for me. Tried with SQLMap and Joomblah.py, sqlmap said that table '#__users' didn't exist (Also the majority of the "joomla" database couldn't be dumped) and joomblah gave me some error which I didn't save.

maiden spoke
#

@unique wigeon You need to wait for the web application to start. Give it a couple of minutes and the error will go away.

digital plume
#

the newest version of metasploit doesn't come with auxiliary/server/socks5 anymore. it has probably been renamed.
room is rpmetasploit

#
version
Framework: 6.0.39-dev-
Console  : 6.0.39-dev-
obsidian flame
late orchid
#

trying to solve the chocolate factory room now

#

and it says that on the server their is a missing python library

#

and in the script the encrypted message is missing the B'' part so theirs a error

digital plume
#

@obsidian flame the issue is that the answer required to complete the task doesn't show up anymore, not that I need a module that doesn't exist.
though I could guess the answer with the information provided without actually finding it through the provided command

obsidian flame
devout osprey
#

Solving Bolt room but port 8*** on http don't work and load indefinitely. My vpn is connected

remote hamlet
agile void
#

Hello guys , I have been stuck in this problem for a while now

#

when i enter a room and do an nmap scan port 80 shows its open

#

but when i try to access it on firefox it just keeps loading

sonic willow
#

@agile void what room is this happening on please? is your browser trying to redirect to https? is there something causing your browser to hang eg. burp?

eternal summit
agile void
#

yes kind of every room, some rooms work fine tho but most keeps loading

eternal summit
agile void
#

let me check

#

yea yea

#

it opens

#

very fast

#

most of rooms keeps loading then opens but after so much time idk why

eternal summit
#

Does it also show your VPN IP?

agile void
#

yes it shows it

eternal summit
#

Ok. Try the MTU fix pinned in #site-support but it's unlikely to help.

agile void
#

sure thanks

amber drum
#

Hi, recently I cant connect to THM's machine

#
ping 10.10.43.126                                                    2 β¨―
PING 10.10.43.126 (10.10.43.126) 56(84) bytes of data.
64 bytes from 10.10.43.126: icmp_seq=1 ttl=63 time=260 ms
64 bytes from 10.10.43.126: icmp_seq=2 ttl=63 time=278 ms
64 bytes from 10.10.43.126: icmp_seq=3 ttl=63 time=265 ms
64 bytes from 10.10.43.126: icmp_seq=4 ttl=63 time=252 ms
64 bytes from 10.10.43.126: icmp_seq=5 ttl=63 time=260 ms
64 bytes from 10.10.43.126: icmp_seq=6 ttl=63 time=249 ms
64 bytes from 10.10.43.126: icmp_seq=7 ttl=63 time=216 ms
64 bytes from 10.10.43.126: icmp_seq=8 ttl=63 time=257 ms
64 bytes from 10.10.43.126: icmp_seq=9 ttl=63 time=239 ms
64 bytes from 10.10.43.126: icmp_seq=10 ttl=63 time=218 ms
64 bytes from 10.10.43.126: icmp_seq=11 ttl=63 time=349 ms
64 bytes from 10.10.43.126: icmp_seq=12 ttl=63 time=260 ms
64 bytes from 10.10.43.126: icmp_seq=13 ttl=63 time=243 ms
64 bytes from 10.10.43.126: icmp_seq=14 ttl=63 time=224 ms
64 bytes from 10.10.43.126: icmp_seq=15 ttl=63 time=283 ms
64 bytes from 10.10.43.126: icmp_seq=16 ttl=63 time=264 ms
64 bytes from 10.10.43.126: icmp_seq=17 ttl=63 time=241 ms
64 bytes from 10.10.43.126: icmp_seq=18 ttl=63 time=225 ms
64 bytes from 10.10.43.126: icmp_seq=19 ttl=63 time=284 ms
64 bytes from 10.10.43.126: icmp_seq=20 ttl=63 time=259 ms
64 bytes from 10.10.43.126: icmp_seq=21 ttl=63 time=240 ms
64 bytes from 10.10.43.126: icmp_seq=22 ttl=63 time=222 ms
64 bytes from 10.10.43.126: icmp_seq=23 ttl=63 time=281 ms
#

i've tried connecting via ovenvpn also wouldnt help

summer hatch
#

hey, I have a problem with the "owasp top 10" room at severity 7
the second to last question and the last one, it doesn't want to accept the answers. it doesn't tell me if it's good or not, isn't that normal?

eternal summit
#

Check your antivirus

#

@summer hatch Usually it's antivirus blocking it

summer hatch
eternal summit
#

What antivirus is it?

#

Skidy has been working with them to eliminate the false positives

summer hatch
#

it's the basic antivirus, win def

eternal summit
#

That's weird

summer hatch
eternal summit
#

@lucid oasis this one's new, defender getting in the way now. This is probably more of an issue than avg/avast.

hazy tiger
#

Hmm that's interesting πŸ€”

tardy lynx
#

Corp room admin pw expired and changing it is a nightmare

glad badger
eternal summit
#

If you can type the password, like 5 minutes at most? Factoring in getting it wrong a couple times

tardy lynx
#

you have to type the original one in and copy and paste doesn't seem to work on remmina or xfreerdp

dry valley
#

yep

#

even with +clipboard

glad badger
#

Typing _QuejVudId6 as the password? It's 11 characters.

tardy lynx
glad badger
#

The new password requirement can be derived from that: 11 characters, 1 special character, 1 numerical, 3 Uppercase (probably the policy has 1 Uppercase).

tardy lynx
#

alright done

#

update if anyone needs to change windows password on remote windows machine but no gui net user username * is your friend

glad badger
#

With xfreerdp, try adding the /p at the end with no password specified, it should prompt in the CLI.

tardy lynx
lucid oasis
zealous vortex
#

Minor typo/run-on sentence. Room: activedirectorybasics, task 5. Should be a period between "...to and from each other <.> when attacking an Active Directory..."

dark raptor
#

STEEL MOUNTAIN ROOM: Anyone try this room lately using the path and tools laid out in the room? The procedure to overwrite the ASCService.exe file on the target w/the .exe file generated by msvenom and start a Netcat rev shell on my machine results in the screen-shot scenario below. With sc query, I can verify I am stopping the service before I execute the listener. When I sc start AdvancedSystemCareService9, it just times out. I have verified msfvenom created the correct .exe file for my tun0 ip and LPORT.

viral cobalt
dark raptor
#

Hey there-

#

I used -f exe (I copied the output in the room)

viral cobalt
#

try exe-service

#

it's designed for unquoted service paths afaik

#

and as a tip, you can use LHOST=tun0

dark raptor
#

oh very nice- I will try that- thank you. Else, I will do it manually with a Python script and server, OSCP style;)

viral cobalt
#

or whatever your thm vpn interface happens to be

#

and generating executables w/ msfvenom is fully in scope, you only have to worry about Meterpreter/msf exploits

dark raptor
#

yes I tried to rule out Meterpreter ip conflicts as it uses my tun0 to listen on this exploit, also uses my eth0 briefly to setup a server, then it stops the service. But as long as the ports are different, should be able to use the same ip addy right?

#

in other words, my netcat listener and meterpreter could both use my tun0 at the same time, because they are listening on different ports- am I correct?

viral cobalt
dark raptor
#

roger that! thanks again - back at it;)

#

btw- I am in awe of all your certs!!!! Mega Kudos to you!!πŸ’―

dark raptor
#

got root! that exe-service was totally it! thanks again- perhaps they should update that screen shot in the room?

wheat fractal
#

I can be wrong but I believe that the correct answer for the room hacking with powershell, Basic powershell commands, question 3 "how many cmdlets are installed on the system?", has changed...

#

On the box I found 6641 which is not the correct answer, I follow my method and then to be sure read a write up and with the method from it I still found 6641 and not the good answer the room requires.

elder aurora
#

after 15 minutes from boot is normal that port on 1433 on Ustoun room is still closed ? Also this box becomes unreachable after about 1 hour

#

took about 27 min T_T

viral cobalt
#

potentially needs the licensing fix?

eternal summit
#

And I can confirm the testing team is aware of the SQL issue

robust niche
#

Any issues with the new SSTI room ? Tried accessing the url yesterday couldnt connect, now 7 minutes after boot cant connect either.

#

Ignore that, im stupid πŸ˜„

eternal summit
#

@sonic willow worth adding a note that / will 404?

sonic willow
civic brook
#

new WebEnum room is kicking an answer error for WP theme, not sure if it's me or not

loud breach
true granite
#

AllSignsPoint2Pwnage seems to have something going on, after an hour it kicks you out even if you are a VIP and have 2 hours on the box. Not sure if that's been reported yet, but happened twice in a row.

obsidian kiln
#

That indicates that it's thrown its license and need to have it applied again πŸ™‚
It's a known issue

north gyro
#

being nitpicky Thankfully for us, WPScan should say Thankfully for us, nikto

vivid dagger
#

In Linux PrivEsc machine ssh is not working currently, yseterday too it was not working, also many of times the service starts after a delay of 5-6 mins. But right now after a delay of 10 mins also it is not working

echo shoal
#

Any help with knockd and ufw not working on thw thm machine i uploaded but is working fine on the machine i made

brazen gulch
#

Hey @dusky junco ! Thanks for making the Web Enumeration room.

Quick feedback: Task 4 first sentence refers to Dirbuster, which probably was meant to be Gobuster.

ο»Ώ"dir" Mode
Dirbuster has a "dir" mode that allows the user to enumerate website directories.

https://tryhackme.com/room/webenumerationv2

lethal haven
#

Hey @dusky junco Task 9 Question 2

WPScan says that this theme is out of date, what does it suggest is the number of the latest version?
which is ||2.0|| but it keep saying answer incorrect probably a bug

coral shell
dusky junco
dusky junco
dusky junco
coral shell
karmic wing
#

Hi @dusky junco, there a copy/paste issue on the Web Enumaration room (which I'm learning a lot from, btw). In the Nikto section, it talks about how WPScan is already installed.
"Installing Nikto

Thankfully for us, WPScan comes pre-installed on the latest versions of penetration testing systems such as Kali Linux and Parrot. If you are using an older version of Kali Linux (such as 2019) for example, Nikto is in the apt repository, so can be installed by a simple sudo apt update && sudo apt install nikto"

distant vine
#

Hi @dusky junco, in the Web Enumeration room, when I installed seclists it installed to /usr/share/seclists/ instead of /usr/share/wordlists/SecLists/ as mentioned as an example for running gobuster in dns and vhost modes (Task 4).

eternal summit
#

On Kali?

distant vine
eternal summit
#

I think one of those paths is for the attackbox

distant vine
#

Ok

ashen pewter
#

In the Network Services room while trying to use command smbclient (to log into annonymous of the machine). It sometimes works and sometimes not, and when it works it just crashes. says its a connection issue

#

What do i do?

rustic nebula
#

and try again'

ashen pewter
#

i did

#

didnt work

eternal summit
ashen pewter
#

o_connect: Connection to 10.10.218.111 failed (Error NT_STATUS_IO_TIMEOUT)

#

this is the error i recive

eternal summit
somber vessel
eternal summit
#

Yeah it has a licensing issue so it dies after an hour

somber vessel
#

ah, that explains it. Thanks James

compact shoal
#

Different ctf... I cracked the password for wp-login but it says incorrect... Any one with whom I can verify the password?? Coz username I got is corrwct...

compact shoal
#

I have found a lead... Trying that... Will update if I get in... Saying, "NOT A BUG"

topaz thorn
#

The room was tested

winged wraith
#

https://tryhackme.com/room/linux1
Section 1 is missing so that you can't know how to log in to the deployed machine, as far as I can see.
I recommended this to a couple of class mates who have to learn basic linux, that's when I noticed.

eternal summit
winged wraith
#

Oh, that's new, isn't it? My bad then. Very neat!

eternal summit
#

Not very new

winged wraith
#

Oh well

dusky junco
#

Different paths for different OS's

#

If a room is built around the use of the attackbox is easier to support etc (:

distant vine
#

Ok, thanks! πŸ˜„

dusky junco
#

Appreciate it πŸ˜„ I should maybe add something like "the path may be different if you are not using the attackbox" just to make it clearer (:

foggy bloom
#

Hello all! I am currently doing this room: https://tryhackme.com/room/attacktivedirectory and is it possible that the hash retrieved is not the right format? In Task 5, the question on hash type's answer seems to be different than the one retrieved

#

can I write spoilers here?

#

ok I just tried on local and the attackbox, maybe I'm just cursed with hash crackers -_-

marsh plinth
#

or what?

#

also can you tell me the syntax for hashcat or john your using?

eternal summit
#

They're not cracking the hash yet either

marsh plinth
#

ight

#

lemme check it

foggy bloom
#

The hash seems to be the wrong version or something, my knowledge here is limited

eternal summit
foggy bloom
rocky cloak
#

Panama is no longer correct answer

#

it should be Iceland, since mailing address for registrant is: Kalkofnsvegur 2, Reykjavik, Capital Region, 101, IS

zealous vortex
#

Not sure if this is a room bug. In room rpmetasploit, task 5, there's a question "what is the name of the column on the far left side...". The question below it says enter "use" plus the number from the previous question, but the previous question is asking for column name, not exploit number

#

Just below this, II think there might be a bug in the instructions. It says to switch back to the icecast exploit, and run it, but that doesn't have/retain the LHOST setting.

#

setting that gets me the meterpreter session, but the 'jobs' command shows nothing, both in and out of msf (separate shell window). So perhaps I'm doing something wrong, or perhaps these instructions need to be updated.

eternal summit
zealous vortex
#

in the meterpreter shell?

#

that gets me an 'unknown command' error. Running it in a kali shell window (not the one running msf) shows nada

#

the "use <number>" command is already done in the previous step, so I think the question specifically asking for it (with no entry for the field needed) might not be needed

eternal summit
zealous vortex
eternal summit
#

There's a few parts that need a revamp, but Dark's a busy guy

zealous vortex
#

fair enough :). Not complaining, just learning and making noob mistakes πŸ™‚

eternal summit
#

No, it does 100% need some things fixing

zealous vortex
#

Might just be that things changed since it was created πŸ€·β€β™‚οΈ

eternal summit
#

Some things, yeah.
Others were slightly off from the start.

zealous vortex
#

gotcha

#

well, thanks for the help (as always) !

#

you've given me some extra info/context that helps explain it

zealous vortex
#

same room, rpmetasploit, task 7, 2nd question. The 'search server/socks5' command returns nothing. Had to search for socks instead, and guess/reverse engineer the correct answer from the ones listed. I'm guessing the name just changed.

eternal summit
#

Yep, that's another thing that needs an update

zealous vortex
#

Thought so. Just figured I'd add it to the list if it wasn't already known

#

James, may I DM you?

eternal summit
zealous vortex
#

Wanted to volunteer to help fix some of the 'low hanging fruit'/easier type issues

eternal summit
#

That'd be something to talk to CMNatic or TimTaylor about

zealous vortex
#

Thanks. I'll try to catch them at some point

wheat fractal
#

Hi. The room 'network services' from the complete beginner course has a bug. Telnet does not always display the welcome message. Restarting he machine helps.

vague drift
#

Hi guys, don't know if this is a bug or by design, but when I launch the machine in the Hacking with Powershell room (https://tryhackme.com/room/powershell) it always launches the attackbox at the same time. I'm OK with that, but the problem is that this attackbox does not have a side panel that I can use to copy/paste into the machine. Is it possible to get that added? It would be a great help to me and I think probably to others as well. Screen shot of missing side panel:
https://i.imgur.com/uUDu1T8m.png

eternal summit
#

That is not the attackbox.

#

That is the target machine.

vague drift
#

ack! Gotcha...I get that now...any way though to get the side panel functionality?

eternal summit
#

Don't think so. I imagine you could RDP in.

vague drift
#

ok, thanks...

crude zinc
#

Hi everyone, I think I detected a bug in "Different CTF" room. As the room is under embarguo, can I DM someone to explain the bug ?

topaz thorn
#

You can dm me if you want, as I tested the room, but I didn't come across any bug with the room

crude zinc
#

I just wrote you

frigid plover
#

Typo in Steel Mountain - https://tryhackme.com/room/steelmountain
Take close attention to the CanRestart option that is set to true. What is the name of the name of the service which shows up as an unquoted service path vulnerability?
duplicate the name of

buoyant dock
proud pagoda
obsidian kiln
civic hornet
#

On Advent of Cyber 2, Task 6, the cookie generated from a capital-S username is accepted for the answer, but not as a valid session cookie on the actual machine
the cookie generated from a lowercase-s username works as a session cookie

#

I can't check if it would work as an accepted answer for the question because I've already answered it "correctly" using the other cookie

eternal summit
#

Refresh and it will replace it with the actual correct answer

#

THM's answer fields have some tolerance on them. Imagine how annoying it'd be to be 1char off on a 32char string that you had typed by hand.

civic hornet
#

I see. I guess this is just an edge case where it actually leads to confusion πŸ˜†

#

thank you for that clarification

glass folio
#

Typo's in the new Web enumeration room

oak mica
#

how is that wrong?

#

I can't see any typos

glass folio
#

The flags should start with -- , that is the case for all other examples commands

oak mica
#

oh true, i thought you mean the word was wrong

#

but it should be -- you are correct, or -U or -P

glass folio
#

Yeah