#room-bugs

1 messages · Page 23 of 1

white osprey
#

Also shouldn't Task 5 "How many CIS controls exist?" be 18? The answer required is 20 although that was the formerly SANS top controls. (Or did i read it wrong)

young flower
glad badger
#

Fixed. Thank you for reporting. 🙂

livid escarpBOT
#

Gave +1 Rep to @untold mural

glad badger
#

It's on the list. 🙂

#

Fixed. Thank you for reporting. 🙂

livid escarpBOT
#

Gave +1 Rep to @white osprey

white osprey
#

Think there was a pin about boxes closing/times not being accurate. Here's one that it just happened for me on. - https://tryhackme.com/room/overpass3hosting

eternal summit
#

That will be a site bug

#

That's not a Windows machine so the licensing doesn't get in the way.

untold mural
#

Intro to IoT Pentesting : Task 3 , Don't think the Machine IP: MACHINE_IP is displaying properly

viral cobalt
#

the machine is deployed, right?

untold mural
#

yeah it is, Its just a display issue with js I assume its suppose to display the box ip

#

refreshed a few times and its still there, could be my browser I guess

#

(the box works fine)

viral cobalt
#

it's likely the room author implemented it incorrectly

obsidian kiln
#

^^^^
You often have to jump through hoops to get that working

twin bay
glad badger
livid escarpBOT
#

Gave +1 Rep to @twin bay

tiny ginkgo
#

Probably a silly question... Why does the splunk room contain ssh credentials to the machine? We don't need to access the machine via ssh for any of the tasks. After accessing the machine, I see that it only contains the dataset for the BOTSv1 in the home folder, which might be a reason for providing ssh access but a link to the dataset in already provided in one of the initial task descriptions.... ..?

pulsar sphinx
#

Im on thm's learning path "PreSecurity" currently in a room called "Extending Your Network", i've got the flag to get but I cant seem to make the simulation work (task 6), its asking for a TCP packet and when I change it, its still stuck on ARP

stiff notch
#

Hi! 🙂 I've found room bug-typo, it's "bu" instead "by, and it's "age" instead of "page"
• Found this is Cross-Site Scripting (Task 9 - Protection Methods & Other Exploits)

untold mural
#

Room: CC-Pentesting, Task : 9 typo

#

Linux strength training task 7

#

Linux strength training task 8

glad badger
livid escarpBOT
#

Gave +1 Rep to @stiff notch

glad badger
livid escarpBOT
#

Gave +1 Rep to @untold mural

untold mural
#

thanks you da best QA man

scenic dune
#

In the Wireshark room on task 12, the steps for importing the decryption key are now outdated

#

the steps are essentially the same except the dropdown under protocol you have to select TLS now rather than SSL

pulsar sphinx
chilly crag
#

Pre security - OSI model - layer 6 - task 3. I don't think it should accept a typo as the right answer? 😄

young flower
eternal summit
#

That's just answer tolerance

#

Room creators have no control over it

chilly crag
#

Ah ok

#

Thanks for clearing that up 🙂

gleaming shadow
#

Yeah if your answer is off by less than 10% or so it'll accept it

#

You can refresh the page to get the intended answer

inner violet
exotic remnant
dusky junco
livid escarpBOT
#

Gave +1 Rep to @exotic remnant

tulip solstice
#

Hi, I can't access Holo anymore (could yesterday) :
I only completed the first few acknowledge tasks and came back to it today

obsidian kiln
#

Uh, @viral cobalt?

glad badger
tulip solstice
livid escarpBOT
#

Gave +1 Rep to @glad badger

viral cobalt
#

@lucid oasis @tiny dragon might be able to help, i don't believe we have access to see anything related to banning/unbanning users related to rooms? I don't see any banned users on the room management end

lucid oasis
viral cobalt
obsidian kiln
#

(It is -- just looked it up via the tokens)

lucid oasis
#

I've unbanned him from the Holo room - We're soon to be starting to move THM over to React, once that happens it'll be easier for us to commit to adding in other room management features where you can unban.

obsidian kiln
#

Network management console? 😆

lucid oasis
obsidian kiln
#

Hehe, I know -- no rush 😄

viral cobalt
#

gib network management console

#

Muiri and I want beta

obsidian kiln
#

One of those things that's useful, but non-essential 🙂

lucid oasis
#

When its sort-of in beta, you guys will be the first to get access:)

obsidian kiln
#

Awesome 😁
Thank you 🙂

viral cobalt
#

@tulip solstice ^^^^ btw

twin bay
#

https://tryhackme.com/room/forensics
Task 2 -> "There are many suspicious open port" -> ports
Task 3 -> "In lats task" -> In the last task, "some IOC's. you" -> "You"

Several other grammatical errors that I'm sure someone going through will discover 🙂

twin tapir
#

heck

obsidian kiln
upper kiln
#

Is there a reason for duplicating this?

glad badger
livid escarpBOT
#

Gave +1 Rep to @upper kiln

eternal summit
eternal summit
#

Do switches actually break this down? No.
The answer also doesn't line up. Packet switching isn't breaking them down, it's getting them to the right place.
Intro To LAN

#

OSI model room seems to disagree with The Internet™️

dusky junco
#

It's the layer where the actual encryption itself happens because presentation is where data is formatted, etc

#

I'll make that clearer

#

It's very interchangable between the two depending on what function of TLS you're looking at as per RFC 5246

white osprey
#

room - howwebsiteswork | task 5 | Problem - Shouldn't this be "CTRL"?

eternal summit
#

Extending your network, the room should probably cover the default drop rule at the bottom? Maybe the fact that the tables are read top to bottom with a default rule?

#

DNS In Detail, Stand should be lower case s.

#

Task 5, should be What's

dusky junco
dusky junco
#

Updated. It'll take a little bit to reflect on the site (caching, etc)

white osprey
#

@dusky junco Yeah task 4, my bad. Super!

dusky junco
livid escarpBOT
#

Gave +1 Rep to @white osprey

dusky junco
cloud hemlock
#

MAC Address solution with only 1 d

#

instead of 2

dusky junco
#

If you refresh the page,you'll see that the answer gets replaced with the actual answer -- i.e. there'll be two d's (:

cloud hemlock
#

OK thx 🙂

dusky junco
#

👍 😄

onyx shard
#

An answer in linux fundamental room 1 that shouldn't have worked

#

hold on getting pic

eternal summit
#

That's answer tolerance

onyx shard
#

Ah, sorry for my overzealousness

untold mural
#

Windows fundamentals 1 : task 7, takes improper answer

dusky junco
untold mural
#

gotcha

viral cobalt
#

i wish we could have a floating message about answer tolerance

sonic willow
#

i think this alert should include due to answer tolerance with maybe a little i to hover to get information about answer tolerance is, if the answer was accepted because of that

winged wraith
eternal summit
#

I think I raised this.
It's also not sha512 either. It's sha512crypt which uses sha512 but it's not sha512.

winged wraith
#

Alright, thank you 👍

eternal summit
#

@dusky junco Once you're caught up on pings ^^

wild saffron
#

its not a big deal but it redirects to an undefined page. room:tickets1

winged wraith
untold mural
#

Room: Shodan, Task: 1 ping is invisible

livid escarpBOT
#

Gave +1 Rep to @wild saffron

dusky junco
untold mural
#

Room: Shodan, Task: 6 Text is on the page twice

eternal summit
#

@green steppe ^

untold mural
#

Room : Remux The Tmux Task : 2 , accept needs to be except

viral ingot
#

On intro to LAN - The arp protocol:

#

How does ARP Work?

Each device within a network has a ledger to store information on, which is called a cache. In the context of the ARP protocol, this cache stores the identifiers of other devices on the network.

In order to map these two identifiers together (IP address and MAC address), the ARP protocol sents two types of messages:

#

sents should be sends

livid escarpBOT
#

Gave +1 Rep to @scenic dune

green steppe
livid escarpBOT
#

Gave +1 Rep to @eternal summit

dapper abyss
#

I can't connect to the ssh

#

I tried but can't connecing

#

Room-linux privesc

#

Also same problem in wreath can't connect to ssh

crimson atlas
#

@thick junco
Thanks for writing down the blaster bug. I was having some issues also in the last step and couldn't figure it out.

livid escarpBOT
#

Gave +1 Rep to @thick junco

dusk matrix
#

in all time

eternal summit
#

Site bug, known issue.

glad badger
livid escarpBOT
#

Gave +1 Rep to @viral ingot

white osprey
#

Minor room bug with formatting in powershell room task 5

zealous schooner
#

Hi guys, I don't know if its a bug or not but in Basic Pentesting room when i ssh'ed as jan I could just do vim /home/kay/pass.bak and read the file. I don't know how this worked as I did not had read permissions.

tiny ginkgo
#

If I'm able to break a room/lab purposely by tampering with how it is implemented, should I report it?

#

The static labs are not actual machines and just a mimic... Is that correct?

obsidian kiln
tiny ginkgo
obsidian kiln
#

Yep, exactly 🙂

#

It's just a static site

tiny ginkgo
#

Umm... Look at that... I'm able to render the dashboard inside a static lab by removing a regex validation from the javascript file... Can it be considered as a bug?

#

I was trying command injection... but lateron I realised that it isn't a real machine 😛 Still.... There may be possibilities of finding an XSS i guess..

viral cobalt
#

just remember, if you're going for a bug, it should try to be as low interaction as possible

#

a lot of places won't accept reflected xss because there isn't often valid security concerns because of certain technologies like csrf tokens, cors, etc

fluid depot
#

Having issues connecting to the box on /linuxfundamentalspart1, anyone else having this problem?

eternal summit
#

Click reconnect

fluid depot
#

Didn't work but after the 4th restart ive got a command line

fluid depot
livid escarpBOT
#

Gave +1 Rep to @eternal summit

restive quartz
#

@fluid depot I was having the same issue on the windows fundamental. It would drop connection every 15 seconds and was hard to get things done. I terminated and rebooted the box about 3 times and it finally seemed stable enough to allow me to do the task

fluid depot
hearty meteor
#

On the "PRE SECURITY" Learning path the "HTTP in detail" room on task 2. This question only accepted length spelled as lengt for me.

eternal summit
#

That's just answer tolerance.

hearty meteor
livid escarpBOT
#

Gave +1 Rep to @eternal summit

nova nymph
#

in the "Introductory Resarching" task 3, Vulnerability searching. The last question ask: "which CVE you would use to exploit a 2020 (as in the year) buffer overflow in the sudo program." But CVE database does not have the correct answer labeled as 2020, but 2019.
Either I don't understand the phrasing of the question or should it say 2019 instead of 2020?

eternal summit
#

No, it should not

#

It was made public in 2020, but the CVE was allocated etc in 2019

nova nymph
#

Just to clarify, I have the right answer, I was just confused that the CVE said 2019 🙂

keen dome
#

Hi there. Possible misspelling in "Extend your network" -> Task 2. Isn't this supposed to be "ascending" order ?

livid escarpBOT
#

Gave +1 Rep to @eternal summit

warm isle
#

so in DNS in Detail room (refreshing and going over basic things is great) task 2 question 3 -> What is the maximum length of a Domain name? the accepted answer 253 is wrong, becouse it actually is 252 (even text says ...maximum length must be kept below 253...)

eternal summit
warm isle
#

ok, so the text is missleading, my bad

glad badger
livid escarpBOT
#

Gave +1 Rep to @warm isle

wise fossil
#

windows fundamental part 2
I think the image here is missing
in task 7 cmd one

civic brook
#

Missing a space after .NET on Holo Task 5

twin tapir
#

@viral cobalt mwah

lapis briar
#

I think that Linux Fundamentals 2 is partially broken, Filesystem Interaction Continued wants me to check tryhackme's home directory, however, the attackbox is logged in as root and no tryhackme user exists

eternal summit
willow topaz
#

I don't know if its intentional but on the room HackPark if you run PowerUp.ps1 or winpeas you get the credential of the admin (default credential), when you are supposed to exploit a binary

cloud herald
#

HackPark is broken, it initially let me navigate to the login portal using my web browser, but it just started to no longer respond to anything on port 80. I tried terminating and then restarting the server and while it has a new IP, but it is still showing the same behavior.

#

Re-nmap scanning now shows port 80 as filtered.

willow topaz
# twin bay Then... ?

it gives you the default credential of the admin account and its getting around most of the suppose way of the privilege escalation specified in the guide

glacial plank
#

In Steel Mountain there is a root.txt flag but nowhere to submit it

eternal summit
#

@glacial plank

#

Task 3. Last question.

glacial plank
#

oh duh lol,

#

I forgot I submitted it already after doing the metasploit version, just did it without metasploit and thought the flags would be different

eternal summit
#

It's the same box

wheat fractal
thorny fjord
#

hi team

#

Room: web osint Task 2... question 5...This does not seem to be correct...Guess the answer needs to be revised.

hardy latch
#

Hi team🙂 I have problem with access to "Learn Rust" room... After entering the room, I can only see a "spinning circle". The problem occurs on different browsers, computers. I can access to other rooms without any problem.

white osprey
#

Hi, following the wireshark room (https://tryhackme.com/room/wireshark), it looks like this needs updating or needs a disclaimer for the version of wireshark. In task 12 HTTPS we are asked to use an RSA key to decrypt the data. It specifies to use SSL for this however wireshark removed this option from the protocols menu and we should now use TLS option. Might be worth either adding some more notes to that section or specifying to use an older version of wireshark. Room created by Cryillic

twin tapir
#

If I change this bs one more time I’m going to liberate wireshark

#

it’s gone back and forth more times than I can count

eternal summit
#

It's been TLS for a long time...

twin tapir
#

I had it at TLS first then people complained so I set it to SSL then people complained so I set it back to TLS and then finally back to SSL

low depot
#

I can not ssh into a server with the username and password is something wrong with the box?

#

I’m in common Linux privsec

#

Can somebody help me? I want to ssh into the attack box

eternal summit
zealous vortex
tiny ginkgo
fringe cape
#

This is a bug I guess Room : introtolan ; need proper validation of the string

eternal summit
#

That's answer tolerance.

fringe cape
#

Like the probability

eternal summit
#

A roughly 10% tolerance of incorrect or missing characters.

fringe cape
#

okie thenks @eternal summit

willow topaz
trail crane
#

Doing RBurpSuite room, and Task11 seems out of place.

#

It mentions a "Score board" that was supposedly previously used, but there's no previous task that mentions a scoreboard.

#

Wondering if Task 11 was pasted from a different room?

thorny fjord
nimble elk
#

i got a bug do i have to post it here

white osprey
#

if it's a room bug, yes. @nimble elk

lapis briar
livid escarpBOT
#

Gave +1 Rep to @eternal summit

jolly minnow
#

upload vunerabilites room have issues I cant load the page for whatever reason

untold mural
#

network services 2 task 8, needs commas

#

network services 2 task 9, "that you have it Metasploit installed"

muted swift
livid escarpBOT
#

Gave +1 Rep to @fluid depot

tiny ginkgo
pliant mantle
#

Hi Ross, Did you ever figure out how to get the images? I am having the same exact issue. Downloaded the .txt no problem, but images are stuck/empty.

glad badger
livid escarpBOT
#

Gave +1 Rep to @untold mural

glad badger
dense pelican
#

Hi, I think I've got a problem

#

Impossible to see the tasks

#

on Basic Pentesting Room

hazy tiger
#

Hey! Press options -> leave room, then rejoin it @dense pelican

dense pelican
#

I try

#

Nice it's ok for me now

#

Thank you @hazy tiger

livid escarpBOT
#

Gave +1 Rep to @hazy tiger

untold mural
#

Windows fundamentals 3 , task 5, T isn't italicized

chrome yacht
#

Typo in the tmux room "Last but now least" should be "Last but not least"; the last question

rugged marlin
#

I have a problem with cc: pen testing room. Task 8, Q7. The command for exploiting is either run or exploit isnt it or am I thinking it wrong?

#

I was reading it wrong. I got it.

west depot
#

Room:- Steel Mountain
Task - 3
What is the name of the name of the service which shows up as an unquoted service path vulnerability?

#

double print the name of

shut laurel
#

Room : Introductory Researching
Task - 3
If you wanted to exploit a 2020 buffer overflow in the sudo program, which cve would you use ?

The answer is CVE-2019-18634

So the question should be 2019 buffer overflow not 2020 buffer overflow

eternal summit
#

It should not. It was disclosed publicly in 2020 @shut laurel

shut laurel
#

Okay got it @eternal summit

silk plover
#

There is a bug in the OSQuery room. Task 5, the only question is as follows: What is the query to show the username field from the users table where the username is 3 characters long and ends with 'en'? (use single quotes in your answer)

This is the answer it accepts, which is clearly wrong:

#

Answer should be this or something very similar: SELECT username FROM users WHERE Length(username)>=3 AND username LIKE '%en';

silk plover
#

not by that much

topaz thorn
#

Refresh and it will correct the answer

silk plover
#

it didnt btw

#

the asterisks were exactly the length of the accepted answer. if you look, the accepted answer has nothing in it at all about the length of the username

torn flame
#

During presecurity path sometimes I had option to terminate from UI of the room but it did not actually shutdown machines even though I was able to start more instances (multiple running in the same time)

#

fixing this could save few $$

eternal summit
#

Are they machines, or are they the little web labs?

#

Little web labs aren't terminable, and they don't cost much at all to run because they're just webpages

torn flame
#

machines, windows machines are last I done and had 2 running

#

well, at least that what I thought - maybe I confused and both of my RDP sessions were connected to the same machine

eternal summit
#

I think there have been some bugs terminating machines lately

dapper abyss
#

I can't add the reverse shell in WordPress 404 template
Room -internal

#

Its says the error just bottom of the blue update file button

wheat fractal
#

Hey guys, I'm getting all kinds of weirdness in my attackbox. nmap is misbehaving it seems. I did 2 nmap -A with 1 returning 2 different outcomes. 1 seems to be an Android phone with port 999 and 9999 open. The next scan reveals the proper ports.

#

Want to share pic, but can't for some reason?

obsidian kiln
#

!docs verify

tropic flameBOT
wheat fractal
#

😁

dapper abyss
obsidian kiln
#

The box creator has locked down the file system so that www-data can't write into the wordpress plugins or themes directory

dapper abyss
#

But i can upload the rev shell via attackbox🙄

obsidian kiln
#

Oh?

dapper abyss
#

I tried with ubuntu and kali those have same error
But in attackbox i can upload the file but i didn't get the net cat

obsidian kiln
#

You've confirmed that it's uploaded? Because that really isn't how it works

dapper abyss
#

In daily buggle room i have the same problem but it will fix via attackbox

dapper abyss
obsidian kiln
#

The box is set to stop you from uploading stuff in Wordpress, so I have no idea what's going on with the attackbox

dapper abyss
obsidian kiln
#

Are you uploading a plugin or a theme

#

A theme should work, a plugin will not

dapper abyss
#

They don't got any error msg like the screenshot

dapper abyss
dapper abyss
obsidian kiln
#

Theme, from the screenshot. Okay, well, that should work for this one. Wrong box.

#

I would suggest researching that error message. The box does work

dapper abyss
#

So what will i do

eternal summit
#

@obsidian kiln That's sounding like the MTU issue to me, if blank works but a file with content doesn't

obsidian kiln
#

Then again, could still be MTU if the request is too large

eternal summit
#

Oh, maybe not then? If it POSTs the whole content then it's worth a go

obsidian kiln
#

Aye

dense mural
#

this is probably just me being an idiot but on the XSS room, when I copy/paste the XSS Key-Logger into the Stored XSS comment field, it crashes the box.

#

but not if I remove the comments.

#

and even when I do that, i see nothing new show up in the 10.10.x.x/logs page

hardy igloo
#

So in OWASP Juice Shop, I succeed in changing Jim's password, log in as Jim, and am greeted with a happy green "You successfully solved a challenge: Login Jim (Log in with Jim's user account.)", followed in the next line by a little checkered flag, next to about 40 hexdigits, and a copy button. I press the copy button, and paste it into the blank for question 2 of task 4, and am rewarded with "Uh-oh! Your answer is incorrect."

Where am I supposed to go from here? Interesting. I now see that a green box had previously appeared out of the displayed area of the web page when I initially succeeded in changing the password. So I've received credit for question 2 of task 4. Still dunno where the 40 hex digits that appeared when I logged in as jim go.

gleaming shadow
#

Should be on the scoreboard

remote hamlet
#

@dusky junco In the red bubble, "build" should be "built".

#

What is Networking: Task 3

lost heart
#

On Advent of Cyber 1 2019 Day 9, I am not getting any response from 10.10.169.100:3000. I have tried both on the AttackBox and VPN.

eternal summit
#

#room-help would be the appropriate place. This isn't a bug, you just haven't mounted the folder yet.

iron sparrow
vast cypress
#

Could it be worth changing now that? Seeing as we have Throwback that uses that(I think)?

vast cypress
#

Defender also seems to yeet Mimikatz.exe after you use it

balmy pivot
#

In CC:Pen Testing, Task 18 there seems to be a bug on the attackbox where sqlmap -u ip --forms --dump returns <blank> for database entries? I ran the same command on a virtual machine with Kali and did not get <blank> and instead got the flag

eternal summit
#

Yep, CMNatic is aware. Sqlmap needs updating

misty cave
obsidian kiln
misty cave
#

Soy Idiota

misty cave
outer pollen
#

In Windows Event Logs: misspelled answer accepted.

I had 2 typos, fixed 1 and submitted before noticing second, but my answer accepted.

Final input for task 3 question 2:

Read events from an event log, log file or using structed query.

hazy tiger
#

This is called answer tolerance.
If your answer is about 95% correct, it will be accepted.

This does mean that you can sometimes get away with typos or incorrect symbols in answers. @outer pollen :)

cosmic nacelle
#

anyone here

#

?

west depot
#

Yes

cosmic nacelle
#

where are u from brother ?

west depot
west depot
#

For?

cosmic nacelle
west depot
cosmic nacelle
west depot
#

Mods purge this convo if u mind it 😄

ionic mulch
#

I don't know if this is a bug but I've just tried to continue with a room that I was working through and when I try and answer a question I'm getting the message "To access material, start machines and answer questions login" even though I'm logged in. Any thing I can do?

eternal summit
#

#room-bugs is more for bugs with the content in rooms or the VMs rather than site issues

ionic mulch
eternal summit
#

Certainly a bug tho

lethal wraith
#

Is osquery bugged? It's not accepting the schema for win_event_log_data

lethal wraith
#

@eternal summit

eternal summit
# lethal wraith <@252418040388517888>

I'm not THM staff. I didn't make the room. I have not completed the room.
Don't just ping me to report bugs, you're pinging 100% the wrong person, and just report it as a bug here if you think it's bugged.

lethal wraith
#

Oh sorry

wheat fractal
#

don't think so, did you wait enough time in order to load the extension correctly ?

#

should return Done StartDriver

soft terrace
meager lance
#

I`ve a trivial typo in Linux Function Hooking by whokilleddb

#

Learn about function hooking in lLnux and have fun hooking functions

#

cancel, my chat was so far behind its already been reported

muted nimbus
#

In the "Intro to x86-64" (https://tryhackme.com/room/introtox8664), in the crackme1, where you are supposed to find the password in a binary, which is intended to be ||"127.0.0.1"||, you can also submit ||" . "|| instead

placid abyss
glad badger
livid escarpBOT
#

Gave +1 Rep to @soft terrace

high vapor
#

I was going through linux fundamentals part 3 and it seems there's a typo in task 5

#

shouldn't "systems" be "systemd"?

#

Great series btw, everything is explained very clearly

glad badger
livid escarpBOT
#

Gave +1 Rep to @high vapor

high vapor
#

np <:)

past moon
#

I guess someone from THM Team fixed it

#

Thanks xD

outer pollen
hazy tiger
#

That’s not the reason for it at all lmao

marsh summit
#

At this point I'm gonna put this in here, I'm working through https://tryhackme.com/room/introtoisac at the moment, Task 5 says to create a free ThreatConnect account. It looks like they've removed the option to do that now. Had to check the wayback machine to make sure I wasn't going insane.

ocean oasis
#

jokervm: task 1, question 6 typo

glad badger
twin tapir
#

Ew, it seems like they’re going platform based now

#

I still managed to get into my account which means they haven’t taken it away completely. I’ll take a look when I can

glad badger
acoustic hamlet
#

In task 14

dry rain
#

Working on "Hacker of the hill" submitting the Medium flags at hackerone, it keeps telling me those have already been submitted. I'm very sure I have not.

void vortex
#

"that" what? the suspense is killing me.

#

John the Ripper - Task 4

white osprey
#

Task 5 on ffuf room isn't detecting some of the machineip inputs.

viral cobalt
white osprey
#

The second/third is the same as the one further down.

viral cobalt
#

if you refresh the page, does that fix it?

white osprey
#

nope

viral cobalt
#

MACHINE_IP man, lemme tell ya, it's a curse

#

no blessings here kekw

white osprey
#

i blame Noraj tbh

cursive laurel
#

john the ripper module has problems with ssh2john and rar2john

#

can execute from opt/john/fodler via .py execution, but comes off as "command not found otherwise"

#

and this is via attackbox - should of been more clear

#

also I think there is a small notational error in /introtolan

#

What technology do Switches use to break large pieces of data into smaller, more manageable packets? - the answer that makes it correct, I dont think is factually correct

keen forge
#

I've also had issues with rar2john in the AttackBox

eternal summit
#

It's just not in PATH. Not overly a bug.

cursive laurel
#

true, but not overly default, either. When you are going through the flow of instructions, and zip2john works...than seuddenly rar2john/ssh2john doesn't...it can give off a false impression that the user is doing something wrong or incorrect (which wouln't be true). There is no notation to indicate otherwise and had to figure it out outside of instructions. Just saying, could casue frustration for newer, less experienced members.

marsh summit
proud kernel
#

Anyone else having trouble with the upload vulns sites? They're pretty unstable

#

Sometimes it will continue nicely for a bit then crash again

crimson plume
#

In holo network, srv02 is no longer domain joined, few reports are there in holo-network channel

obsidian kiln
proud kernel
obsidian kiln
upper kiln
#

@glad badger repeated word.

eternal summit
#

@past moon

past moon
#

On it

#

Fixed it :D

#

Thanks man :D

#

Also

#

Splunk3 task 7 Question 3

#

I guess there'll be no hoth

#

@hazy hinge

remote hamlet
#

@dusky junco I know it is adam's room but I can't seem to tag him.
DNS in Detail - Task 4 - Final paragraph:

This value is a number represented in seconds that the response should be saved for locally until you have to look it up again.
Should either swap for and locally around, or remove for.

zealous vortex
#

or surround locally with ( )

glad badger
#

Grammarly's response after I changed it to that "You must have been practicing!" 😆

zealous vortex
#

Since some people are non-native speakers, it might be easier to break it up into two sentences.
Something like:
This value determines how long the response will be saved in the local cache. The value is in seconds.
or:
The value's unit is seconds
The value is time (in seconds). (parentheses can be removed if that is clearer to more people).
The unit for this value is: seconds.

#

I'm just thinking that a google translate on a complex sentence will be more confusing 🤷‍♂️

acoustic hamlet
#

Anyone here who can help me with correctly creating an OVA ?

eternal summit
#

Not really a bug

woeful jewel
#

In room upload vulnerablities task 7, when i try to foward a request using burpsuite into the java.uploadvulns.thm it just keep loading until it eventually said "Failed to connect to java.uploadvulns.thm:80". My connection is fine bc i tried it on a different website and they responded, i got another request. It seems like the machine didn't catch the forwaded request from burpsuite

cursive laurel
#

Ive had a few glitches with bthat task as well. Better to terminate the machine and restart it

austere ore
#

Something wrong with room Archangel. I cannot get the log file showing. I've followed many different walkthroughs, the path traversal that works for them doesnt do anything on my machine

austere ore
#

looking at the history of Archangel complaints this isnt anything new it seems. Something is fked with that room

#

just gonna move on until its fixed

vast cypress
eternal summit
#

Refresh the page

deft garnet
#

i have tried it in differnet days

#

it looks like issue is just for me

acoustic hamlet
#

The rpmetsploit room Task7 has a bug. Maybe its a MSF5 MSF6 incompatibility... But below task does not work anymore

#

rpmetasploit room (typo)

#

Although google will get you there

iron dagger
#

"John The Ripper" room. Task8. Section about custom rules. I think there is a typo in the code example: cAz"[0-9] [!£$%@]" produces Polopassword1 !. Code should be cAz"[0-9][!£$%@]" to give Polopassword1 ! (without space)

trail torrent
#

Having issues with internal, i cant connect to the domain with with my browser and even a curl is taking long

eternal summit
#

Did you add it to /etc/hosts? Has it been over an hour since you deployed it?

#

Has it worked previously?

trail torrent
#

First time on this box in particular, I edited the host file when I got the IP and I even waited the 5 mins to let the machine start up

#

and I can ping the box, just cant load the web page and everything but nmap and curl is timing out

eternal summit
trail torrent
#

MTU ?

#

nvm I had my host VPN on

#

thanks again

acoustic hamlet
#

In the room linuxfundamentals part1 Task 5... The number of directories and files don't match with the machine deployed

#

snap was added later.

runic belfry
#

In the room "Blaster "

Task 3 , Browser History was Deleted ! so i can't get CVE number

** restarted machine many times but the results are same **

jade plinth
echo epoch
#

getting erros when doing the SudoVulns room. Ive tried all combonations for -u

stiff notch
#

Hi! I have tried to use the exact information given but the output is still error, may i know is it my issue or could it be room bug?

• OWASP's Juice Shop - Task 5 - Question 2

wheat fractal
obsidian kiln
#

Read the instructions. That isn't a bug.

exotic herald
#

Room: Burp Suite
Task: 9
Bug: Clicking "Download Task Files" dropps the connection to the THM AttackBox

eternal summit
#

Lmao. Sounds more like a site bug?

exotic herald
#

Room: Burp Suite
Task: 9
Bug: "For some additional practice on using Intruder, check out the older Learn Burp Suite room here on TryHackMe" -> the linked Room is Private

exotic herald
obsidian kiln
#

The Burpsuite room is getting a revamp anyway 🙂

twin tapir
#

wasnt that room a revamp of the other room kekw

glad badger
#

Revamp imminent™️

dusky junco
dull orbit
#

dear all, I think there is a bug in the "Cross-site Scripting" room on task 8: i got all the "Hello" alerts but got only the first answer

#

thank you all.

stiff notch
livid escarpBOT
#

Gave +1 Rep to @urban zealot

mighty nimbus
sonic willow
#

time for cry to change it back :)

eternal summit
#

It's needed to change to TLS all the way through

#

Smart way would just be putting "click on TLS (SSL in older versions)"

obsidian kiln
#

I am sick of Cry not fixing that smh. Added

eternal summit
#

Muir>>>Cry

twin tapir
#

Thanks bb

#

it’s honestly something I’ve made a note to fix a million times then get caught up with other things and forget

obsidian kiln
#

Riiiiiiiiiiiiiiiiiight

wheat fractal
#

No ssh login dude

#

:/

obsidian kiln
wheat fractal
obsidian kiln
#

Can't you?

#

There's an in-browser machine

wheat fractal
#

lol

#

Thx

obsidian kiln
#

Np 🙂

merry thorn
#

it does not matter but its good to keep everything as perfect as possible

twin tapir
#

@viral cobalt fix it fix it fix it

viral cobalt
#

i dont know you

twin tapir
viral cobalt
#

throwback? whats that?

twin tapir
#

@obsidian kiln youre my witness I get his cut

viral cobalt
#

i dont know of any cut

stiff notch
#

Hi guys! I'm not sure whether is this bug or what because the flag did not come out after I've successfully done what was being told in the task

• OWASP Juice Shop - Task 7
• Question #2: Perform a persistent XSS!

[Note: I have restarted and retry from scratch and it still appears like this without flag]
• I saw some comments in reddit to stop burp suite then try again and it still doesn't work.

eternal summit
#

This channel is for bugs with tryhackme rooms.
That's not a tryhackme room. @wheat fractal

wheat fractal
#

my bad

#

i will dm

astral anvil
#

@viral cobalt one for you in holo?

viral cobalt
#

nope

#

those are for Cry

astral anvil
#

Also maybe missing a space up here

#

@twin tapir okie one for you it seems kekw

twin tapir
#

Fixed

exotic herald
#

Room: Cross-site Scripting
Task: 8 Filter Evasion: The word hello is filtered, bypass it.
Problem: Only one solution seems to be excepted?
How to reproduce: <p onmouseover="alert('Hel' + 'lo')">Hover me</p>
Error Description: Provided line solves the requested task but does not provide the flag.

#

Same goes for the last question "<p ononmouseovermouseover="confirm('Hel' + 'lo')">Hover me</p>" this will solve the task but wont retrieve the flag 😄

#

Room: Cross-site Scripting
Task: 9
Problem: 2 Images References seem to be broken

past moon
#

From Holo

twin tapir
#

Fixed

wheat fractal
cedar shale
#

Blaster, task 3, no history in ie.

exotic remnant
#

Room: Osquery
Task 4: Schema Documentation
Problem: I'm not sure if this was intentional or not, but the task makes a point to tell the user the current version at time of writing was 4.7.0, but the answers were from version 4.6.0

cursive echo
#

Room: https://tryhackme.com/room/rpmetasploit
Task 7: Makin' Cisco Pround
Problem: In the walk through we're asked to use run autoroute -h however when running the command

meterpreter > run autoroute -h
[!] Meterpreter scripts are deprecated. Try post/multi/manage/autoroute.
[!] Example: run post/multi/manage/autoroute OPTION=value [...]
[-] Could not execute autoroute: ArgumentError wrong number of arguments (given 2, expected 0..1)

The script it suggests running cannot be run with the -h switch.

metasploit v6.0.48-dev

wheat fractal
#

"The Cod Caper" -- Tasks 8 and 9 result in a seg fault (as expected) but a permission denied to read the file. I followed the instructions to the letter (I think), and also followed a couple of walk-throughs, but I still could persuade it to output the contents of the file.
Bug?

scenic dune
#

Not sure this is a bug but in the room "Buffer Overflow Prep" the exact same steps that work perfectly first time on the attackbox do not work from a personal kali vm through openvpn even with the connection verified etc

eternal summit
#

Probably python 2/3 issues

gleaming shadow
#

I think the code for that is designed around python2. It's fairly trivial to translate it to py3 syntax though

sick hull
#

Task 7 of Windows Fundamentals 2

"In the above image, the line within the red box shows us an example syntax for the command.

The structure tells us the netstat command can be run alone or with parameters, such as -a, -b, -e, etc. "

it does not contain any image of netstat, even though it was mentioned as per line above.

eternal summit
#

That's just answer tolerance, try reloading the page.

hot flame
#

Hi! Rust room not working for me. It freezes at loading 😦

carmine urchin
#

In find command explanation instead of directory name here wrongly specified file name.

vague garnet
#

What is Networking / Identifying Devices on a Network lab doesn't show a flag. What to do?

lost plume
#

I'm having an issue on the What is Networking? room. I cannot seem to get the flag to show up, no matter what i do. I have removed ad block and tried different browsers. here is a video of me trying to get the flag.

lost plume
#

thanks for the heads up, i'll keep that in mind for the future

astral anvil
#

Is the THM Request catcher borked?

proper jasper
#

the new room, rocket... the web server crashes and stops loading whenever you fuzz it. im not going with too many threads either (10). I think this needs more resources with the vast number of services its running because you need to fuzz for the room but you cant because the server stops responding and the room just dies. and whgen you do get to use services they run super slow too.

eternal summit
#

cc @glad badger I think this is your domain now?

proper jasper
#

my shell keeps dying also - this is a big issue i think

hollow grove
#

https://tryhackme.com/room/webosint last question in TASK 2 is outdated, writeups have different answers than the actual domain info now ( correct answer is Panama, actual answer now is Iceland )

near flint
#

On Extending Your Network, task 2, first question my answer differ from the ones shown in the tutorial, but both are correct.

distant mauve
#

I'm having an issue with the "Upload Vulnerabilities" room. The specified link is not working (http(s)://overwrite.uploadvulns.thm).

swift hearth
proud kernel
#

run autoroute -h does not work anymore in msf6

gleaming shadow
#

Apparently if you leave it alone for a bit it comes back

proper jasper
#

Yeah I’ve rooted it now

#

Just painfully slow

obsidian kiln
proper jasper
#

My shells and SSH have about a minute of uptime for 2 mins of downtime so I have to plan and execute the plan fast

gleaming shadow
#

That's odd, I didn't have that kind of issue

proper jasper
#

Maybe it’s been given more resources now to mitigate

flint eagle
#

On the Alfred room, the .ps1 code snippit provided does not work

eternal summit
#

Check what you're hosting, as in the file and make sure it doesn't 404

limpid frigate
#

is there a problem with the rust room cant join it

#

it just loads for ever

eternal summit
#

It's a site bug.

limpid frigate
#

any way i can reach the room

eternal summit
#

Not until the site bug is fixed

limpid frigate
#

f no problme

astral anvil
#

Question 8 on Nax, the exploit it expects has had a name change within metasploit so is no longer correct

twin tapir
#

hmm, pretty sure stuxnet isnt here anymore

#

@obsidian kiln bb

obsidian kiln
#

Stuxnet is still here

twin tapir
#

Oh, weird. They weren’t showing up under my @ but when I search their user it shows up

karmic blade
#

Hello all. Task 7 on OWASP Top 10 is telling me to go to http://<box IP>:8888 but it's refusing connections there.

#

Restarting the room machine fixed it. Odd.

zenith fox
#

hello for the wireshark room in the http traffic section it asks me to print the entire uri request for packet 18. ive tried it a bunch of times and it has not worked if anybody can help me

#

the answer it says even on wiresharks website is not correct

#

jsut seeing if someone can pm the correct uri

white osprey
obsidian kiln
#

Oh Lord that is an old room

#

@glad badger one for you

white osprey
#

nvm

#

the owner put a comment in a hint.

#

just have to go to a github for it now

glad badger
#

Musical Stego, that's not music to my ears. 😄

twin tapir
#

It’s there but you haven’t given me enough information to really help

gleaming shadow
#

audio stego is always painful

meager depot
#

Is there a chance I could send screenshots? It'd make this easier

gleaming shadow
#

you can verify

#

!docs verify

tropic flameBOT
meager depot
#

Cheers

gleaming shadow
#

should be able to post screencaps now

meager depot
#

Was just triple checking to make sure it wasn't something a misunderstanding on my part, and upon having done that posting screenshots would be overkill.

I can post details if asked for them, but, suffice it to say "Linux Fundamentals Part 1" is completely broken. It leads to a generic AttackBox instance instead of what I assume once was a room-specific box, making the room impossible to pass on your own.

gleaming shadow
#

are you clicking the big green button in the task?

#

and not the one labelled "Start Attackbox"

meager depot
#

It's blue for me, but yes

gleaming shadow
#

this one

meager depot
#

So much for triple checking. I can see the machine name changed, I'm sure it'll work. Thanks

gleaming shadow
#

Start Attackbox will start the attackbox

#

that thing may need to be renamed tbh, you aren't the only one to get confused

meager depot
#

I just didn't know there were more instances of boxes, and assumed it was the same machine since it was in the same room.

gleaming shadow
#

yeah it's tricky.

#

generally the target vms are the big green button 🙂

meager depot
#

Don't you worry, I won't forget :D

glad badger
#

Start Machine change to Start TargetBox might be good for that green button. 😄

#

Answer tolerance. Refresh the page.

#

It accepts your answer when it is slightly off, in your case 1 character.

chrome yacht
#

In the Linux function hooking room there is a small typo in task 7, the last bullet point says “And lot more” but it should say “And a lot more” :) I’m on mobile so can’t send a screenshot of it unfortunately

true moon
#

I Got the same issue. Any solution?

carmine urchin
#

How do we insert (before the cursor) however the answer is small i. Mistakenly typed Capital I even though the solution got accepted. I found most of it ignore case sensitive. Could you please look at it?

#

@glad badger

tired hull
#

@true moon yeah I think I figured it out. The boxes on thm don't have any internet access, I guess for security reasons , so therefore my understanding is that the room explains all the ways you can use those Sysinternals apps whether from the internet or locally. This part is actually explaining how to access those apps if you were using your own machine ( which as internet connection ) . Then, because we are doing the room connecting to a thm windows machine , we have to use those Sysinternals from the local folder C:\sysinternals . That's my conclusion , maybe I'm wrong

true moon
tired hull
#

No, expect if you would try it from your own windows machine , you know what I mean ?

true moon
livid escarpBOT
#

Gave +1 Rep to @tired hull

tired hull
#

@true moon right on

carmine urchin
#

How do we write the file, but don't exit?

For this question even though the answer is correct but it is not accepting the solution

eternal summit
#

Not a bug

#

Check the answer format

weary sentinel
#

Hi guys,
I've been trying to defeat the room "for business reasons" but every time I try to upload my exploit as a plugin or page, it says there's been an error with the machine.

I also cannot activate the plugins due to the same error

I believe I'm doing it correctly and that the problem is with the machine and not myself

bright sorrel
foggy island
#

How Websites Work - HTML Injection -> I input the HTML code (correctly) for the site, but I do not get a flag.

#

The link appears and when I inspect it, it is showing correctly. I'm not sure why the flag isn't appearing (Chrome v92.0.4515.111)

grave meadow
#

Hey guys, I am running PowerUp.ps1 on the "Steel Mountain" room and am getting errors. Anyone run into this issue?

swift hearth
tiny ginkgo
#

Room: https://tryhackme.com/room/learnowaspzap
Task: 5

Without importing ZAP Certificates, ZAP is unable to handle simultaneous Web request forwarding and intercepting. Do not skip this step.

upvote False information. The Zap root CA certificate is used to encrypt and decrypt the ssl traffic from and to our browsers. Therefore it will only be required for https websites.

tiny ginkgo
obtuse musk
#

https://tryhackme.com/room/nax
The answer to question 8 has changed as the module in metasploit is now named slightly different.

thick stone
#

Hey there, I am doing the Steelmountain Room. Unlikly there is no possibility for me to run the process to get a reverse shell. I have tried with 3 different writeups and my own kali Box. Is there a Bug?

crimson gust
swift hearth
swift hearth
# crimson gust Nope how can i do that ?

The way I did it is in chrome you can right click on the target site, and 'view frame source', and in the window that opens remove 'view-source:' from the URL. Maybe there is a more elegant way but it works 🙂

crimson gust
livid escarpBOT
#

Gave +1 Rep to @swift hearth

crimson gust
#

It doesn't work for me 🤔

wheat fractal
eternal summit
#

1111 1111 1111 1111

#

What's that in base10?

wheat fractal
#

65 536

eternal summit
#

Nearly.

wheat fractal
#

*5

eternal summit
#

Last bit is 1, so it's odd for certain

#

So you need 17 bits to store 65536

wheat fractal
#

neat

#

my bad

eternal summit
#

Everything clear there now?

wheat fractal
#

yeah no worries i should have double check before sending my message

eternal summit
#

Okay sweet, happy hacking

abstract timber
#

hey are you guys having issues with rooms right now ? like starting a room and not being able to access the webapp , that kind of stuff ?

#

like I can access 10.10.10.10 fine

#

but when I deploy a machine , for some rooms it works fine , for others nada

red marsh
#

I think the correct formatting for this:

#

Should actually be 0 */12 * * * cp -R <et cetera>

#

The slash means "increment." Without the slash, maybe this will just execute every 24 hours at 12pm.

tranquil fossil
fading warren
tiny ginkgo
languid moth
twin tapir
#

I believe the solution to that problem was to go to the network simulator URL itself

mortal lily
#

I can't get the hackpark web page to load (it just says Loading Tasks... with a spinny wheel) . I have tried from several different browsers and even different machines (both Windows and Linux). Is this room broken for everyone, or is there just something wrong with my profile?

frozen hornet
#

Hi guys, I am not sure if there is a problem with the room or the my vpn or something else, I ll just post it here.

#

On room metasploit, I keep getting the following error

#

Do you thing it's something on my part?

vagrant breach
#

Hi guys, I've started the Linux fundamentals part and started an Ubuntu. For some reason it is just very different from what I'm seeing here and from the videos. For example, my Ubuntu is showing root instead of tryhackme as a user. Also I don't find any folders like the ones from the video. I ended up typing the answers from the video because my terminal does not seem to be the same as what it is supposed to be. What am I doing wrong? I am using the attackbox

frozen hornet
#

Did you try changing users or moving to the user directory?

vagrant breach
#

Yes

#

I've found nothing I could recognize

#

When I use whoami it returned root. Also the default location does not have folder 1, 2,3 or 4. It has Documents, and some other folders.

#

Maybe I started it wrong. I'll try again later

#

Ty

civic brook
#

you need to deploy the machine for the room, it is different than the attack box

lusty basin
#

Network services, Task 4: When command smbclient is run, I get an error, 'WARNING: The "syslog" option is deprecated'

eternal summit
#

Not a bug with the room
Will not stop you from being able to complete the room either.
@lusty basin

dusky aurora
#

(Moved from #site-support)
Having issues with the new NIS Cloud Funcdamentals room. Task 2, question 4...about the NGFW layers. There seems to be an issue with the format of the answer.

lusty basin
livid escarpBOT
#

Gave +1 Rep to @eternal summit

eternal summit
#

It's something with the attackbox, rather than the room

#

It's also just a warning, not an error

lusty basin
#

I see, I'm new to linux and cyber sec, not very familiar yet.

#

Good to know though :)

red marsh
red marsh
#

This is seems wrong:

#

John will complain that there is no such format. Also you can see from the man page that an NT format does not exist.

#

The correct answer, I assume, would be LM.

#

That said, I couldn't ge tthe password out of john for whatever reason. It was easy to crack with hashcat though.

red marsh
#

^ On second thought, maybe I'm missing a package or something. The tutorials are mentioning other formats that john doesn't recognize.

eternal summit
wind plover
#

Hi, not to sure if this is the right channel or not. Working back through BOF prep room in prep for OSCP next week. For some weird reason im experiencing something weird with mona. Despite knowing the bad chars already from my prior attempts mona doesn’t ever return “Unmodified”. I’ve tried this on a few overflow examples to test and they are all the same.

swift hearth
#

https://tryhackme.com/room/owasptop10 task 26 mentions "First, we need to set up a netcat listener on our Kali. If you are a subscriber, you can control your own in-browser TryHackMe Kali Machine." but I don't think our attackbox is (still?) Kali, that paragraph might need an update.

alpine tangle
#

Buffer Overflow Prep, Mona isnt in c: any more. Cant seem to find the bytearray.bin now. Have been working on this the last few days, overflow 1 and 2 went smooth yesterday, working on 3 now, and I cant do the !mona compare because the path is wrong now. Doin a search on the c drive I cant seem to find the mona folder now o.O

#

I said "now" way too many times..

#

Im a dumby, forgot to make a working folder..

wind plover
alpine tangle
#

Dont get rid of eery bad char, only the ones that have another behind it in chronological order. They arent all bad, the first one is causing the second one to be bad

#

off to an appt, hope that helps!

wind plover
# alpine tangle Dont get rid of eery bad char, only the ones that have another behind it in chro...

Yeah yeah, I get that. I’m rerunning through the room. I’ve already been through it before. But for some odd reason when I compare the esp with the byte array it never returns unmodified despite eliminating all bad chars. Assume your not having that issue. I’ve just spun up the browser box and I’m still getting the same issue. Might be an issue with my process however, followed the tutorial to the letter

vagrant sedge
#

just wanted to say that this is written 2 times by mistake

#

(on holo)

placid abyss
#

@vagrant sedge

cursive echo
#

Not so much a bug but just a missing word in the question:
Room https://tryhackme.com/room/tokyoghoul666
Task 4 question 1, text is missing a word but could also just be simplified to

What did the message say?

There are other issues with the presentation of this room I.e. The hint text for Task 4 question 1

wheat fractal
#

In the 'Introductory Networking' room, Task 7 (last question) is out of date and the answer sought is no long available (Tech Admin email address - has changed in WHOIS reality!) Impossible to find in current records.

eternal summit
wheat fractal
#

@eternal summit Yup, from FB to MS.

abstract timber
#

Hey , in the basic pen testing room , when you do ssh into it , the ssh crashes on any major output , like if I cat a long file , so just a report

rough imp
#

Has anyone encountered a bug in the "What is networking room"?

#

I put in the correct MAC address for Bob's computer but it wont progress the module

civic brook
#

what browser are you using

rough imp
#

chrome

civic brook
#

if you have firefox, it works there

rough imp
#

Thank you!

tiny ginkgo
thin tartan
#

on the team box, key won't work,

tiny ginkgo
alpine tangle
#

@wind plover I am doing overflow3 and having the same issue as now

#

you now**

#

@wind plover Sent you a friend request, pm me if youd like. We can work on it together, and not blow this room up Dx

stuck sun
#

Hello, im unable to terminate the machine in the windows fundamentals 1 room, when i click terminate it looks like it is off then i try to open another it says i have one open then i refresh the page and it is still active.

dreamy geyser
#

Did any experience a delay/lag when trying to load the cmd for tib3rius windows privesc course? My cmd won’t load and I’m connected to the vpn

plucky tree
#

Hello, the room Agent-sudo keeps on dying. Sometimes I can't ping it, sometimes its working. Can anyone help? Thanks!

viral cobalt
#

if so, restart your box and make sure you only have one openvpn instance running

plucky tree
#

Hi @viral cobalt, yes I'm always connected to the vpn. normal browsing seems to be fine, but the room machine does not respond sometimes. I already tried to restart the machine. Issue still persist

viral cobalt
#

yes, I'm aware your connected to the VPN. That symptom is common when you have multiple OpenVPN sessions running at once

plucky tree
#

my apologies, I misread. letme try that. thank you

elfin gust
#

Bug in Linux challenges, task 4, the cronjob isn’t there

teal onyx
#

In the Learning Cybersecurity room, the Bruteforce task says to use a 4 digit token but the instructions say to go from 1 to 10,000 which would be a five digit number. Should be from 0000 to 9999

gleaming shadow
tiny ginkgo
tiny ginkgo
copper yew
#

any devs here, there's something that could confuse a lot of ppl in tryhackme, On "How websites Work" The answer in the video is "front end", but it didn't work, but "client side" worked (might confuse some people, can yall change it) (dm for screenshot, it's not letting me post it

tiny ginkgo
tropic flameBOT
eternal summit
#

Given the answer is in the text, I feel like discouraging copying from the video in that way isn't exactly a problem

buoyant skiff
#

hello

#

I have one bug on TryHackMe Training

#

on quest

#

Deploy the interactive lab using the "View Site" button and spoof your MAC address to access the site. What is the flag?

buoyant skiff
#

help me pleaseee

placid abyss
#

?

#

What do you mean you can't answer it?

#

@buoyant skiff

#

Also be patient, we're all volunteers here

buoyant skiff
#

It is easy quest but It can't show me for answer

wheat fractal
#

You'll have the flag once you enter the correct MAC address

#

is it not working ?

timber wyvern
#

waiting on another nmap to confirm

#

can confirm port 1433 is not present

#

will move on but can staff have a look into this 😮

earnest oasis
earnest oasis
#

Seems like google chrome isn't really helpful with THM Rooms.
The alerts won't trigger and so therefore many roomy can't complete.
When using microsoft edge ( 🤮 ) the alerts will show up.
Damn it...

wheat fractal
#

I always use built-in Firefox when doing CTFs so yeah it is possible, I don't know thought

eternal summit
eternal summit
#

There's really not many.

earnest oasis
# eternal summit There's really not many.

https://tryhackme.com/room/httpindetail
https://tryhackme.com/room/extendingyournetwork
https://tryhackme.com/room/whatisnetworking

Those are the "beginner" rooms. So you are making life harder than it's currently is for them ? 😄

eternal summit
#

No. I'm doing nothing.

#

Chrome pushed an update that breaks some stuff.

#

It's documented here, reported a few times. It'll be fixed. It's three rooms out of over 400, less than 1%

earnest oasis
earnest oasis
eternal summit
#

Seriously. It's a brand new change to chrome that breaks stuff. It'll be fixed. You have to be patient.

west depot
#

yea

swift hearth
idle sun
#

https://tryhackme.com/room/networkservices
Last question in Task 4, it is impossible to connect to the host via ssh with the private key (it asks for a password, and yes, I used the -i flag and changed the file permissions to 600) I had tried everything, so I finally decided to find a Write up about this room and see what I was doing wrong, but everything I was doing was right, which means something is wrong.

eternal summit
#

No, it's definitely possible

idle sun
eternal summit
#

I'd recommend going to #room-help and providing screenshots

clever pecan
gleaming shadow
#

Hmm, did the juicy details room logs get updated or am I just being dumb? It's asking for the timestamp of the successful login, which is not the correct answer from the logs...

wheat fractal
#

Did you put Yay or Nay before the timestamp ?

gleaming shadow
#

yes

wheat fractal
#

And added +0000 at the end ?

gleaming shadow
#

the accepted answer is the end of the attack

wheat fractal
#

Can you write here the answer you tried ?

#

So I can compare with mine

gleaming shadow
#

Nay, 11/Apr/2021:09:15:03 +0000

wheat fractal
#

Oh ok I see, you got the right format

#

but

#

not the right time

gleaming shadow
#

this is wrong, as is:

Yay, 11/Apr/2021:09:15:03 +0000
Nay, 11/Apr/2021:09:20:43 +0000
Yay, 11/Apr/2021:09:20:43 +0000
#

oh frack there it is.

wheat fractal
#

Its something like 09:16:xx

gleaming shadow
#

hydra is dumb and I hate it

wheat fractal
#

Ahahaha yeah it can be pain in the ass sometime

gleaming shadow
#

cat access.log | grep 'login .*" 200' catches it

#

because http 1.0

wheat fractal
#

As you said Hydra is dumb ( and so its output ) so I've had been through the logs by myself

#

But nice you finally got it prayge

gleaming shadow
#

I'm not sure I understand the next one though

#

nm got it

wheat fractal
#

Hit me up if you need some extra help

gleaming shadow
#

it'll give the city as well

idle sun
livid escarpBOT
#

Gave +1 Rep to @eternal summit

vagrant sedge
#

there is no deploy button for the newest room

#

i refreshed the page on both my actual machine and the vm

glad badger
#

I'm not sure why that is happening. Thank you for reporting. It happens for Task 2 and 4.

livid escarpBOT
#

Gave +1 Rep to @thorn forge

glad badger
glad badger
misty cave
glad badger
livid escarpBOT
#

Gave +1 Rep to @tiny ginkgo

glad badger
glad badger
copper yew
#

ohh, thx

glad badger
civic brook
glad badger
civic brook
glad badger
#

Does it work in Google Chrome in a separate tab, as opposed to in a frame (what THM calls Split View)?

civic brook
#

not sure, I know in split it doesn't work. let me try

glad badger
#

Right click > View Frame Source

civic brook
glad badger
#

Now remove the view-source prefix and you'll get the page.

civic brook
#

works that way, just not in split. I will add it as a t-shoot note

glad badger
#

I see now why it is happening in split.

#

Basically it's a cross origin iframe validation that blocks it in split view: A different origin subframe tried to create a JavaScript dialog. This is no longer allowed and was blocked.

civic brook
#

I know it worked in the rooms when they were originally released, this issue is recent

glad badger
#

Yeah, it is a recent update to Google Chrome browser.

civic brook
#

it is the same with Edge, so it would be Chromium related

glad badger
#

I've forwarded the Chrome iframe situation to the content dev. 🙂

swift hearth
glad badger
civic brook
#

@glad badger can you check why CMSPIT isn't showing a deploy option

#

I figure it was there for testing

swift hearth
# glad badger HTTP ?

Tried both http and https. From one of my vps'es it shows some error on http and doens't connect at all on https. Body I get over http is <html> <head><title>Know what you are doing</title></head> <body> <pre> Seems you have nothing to do here, seriously... </pre> </body> </html>

swift hearth
#

but maybe thats because of the curl user-agent

#

perhaps they geo-restrict it

languid moth
languid moth
#

Okay so it seems like any room that uses popup windows doesnt work for me using chrome, it blocks the popups with the flags.

eternal summit
#

Yep, it's a change that recently happened in Chrome

glad badger
languid moth
#

Thanks but I just switched to firefox, much less workarounds.

frigid lintel
#

hey is the jenkins vm bugged? im unable to get the meterpreter reverse tcp payload to work at all, and i've tried all the ones for windows using the x86 arch and the encoder just like instructed, i've tried the regular shell as well as the powershell reverse tcp payloads, using the attack-box

eternal summit
wheat fractal
wheat fractal
#

Just want to report a typo in PoloMints' Network Services room (https://tryhackme.com/room/networkservices), task 9, in resources: As we're going to be logging in to an FTP server, we're going to need to make sure therre is an ftp client installed on the system. should be "there". Same paragraph: If you're bought to a prompt that says: "ftp>" should be "brought"
have a nice day CatThumbsUp

abstract holly
#

Nevermind 😛

eternal summit
abstract holly
#

Ah yes, thanks! Will keep that in mind fingerguns

glad badger
livid escarpBOT
#

Gave +1 Rep to @warm chasm

cosmic vine
#

This is more likely incompetence on my part (brand new to this) than a bug, but..... I'm working on T4 of "Network Services" and running the command: smbclient //10.10.245.19/profiles -U Anonymous -p 139. The question says to not supply a password, so when I'm prompted for a password in Linux i just press Enter. From there it says to type help for a list of possible commands and the action is not completed.

viral bone
#

I encountered the same thing today. user2 and the tryhackmeuser have access to the same files. (Linux Fundamentals Part 2, Task 5)

eternal summit
#

Yep that's documented

agile sigil
#

Hi there

#

I was working on the Steal Mountain Room

#

and when I was trying to get an initial access

#

I used the metasploit module that was recommended to use

#

and i got this error

#

(can't upload pictures?)

swift hearth
#

!docs verify

tropic flameBOT
agile sigil
#

ok thanks

#

thank you sling

#

Does this need a manual intervention of the THM team (like a reset of the machine?)

swift hearth
#

No your instance is private to you, and you can just Terminate the machine and start it again if you feel like you want to reset its state.

agile sigil
#

Ok great imma do this thanks!

gleaming shadow
agile sigil
#

@swift hearth resetting the machine helped me realize a mistake on my side thanks!

livid escarpBOT
#

Gave +1 Rep to @swift hearth

worthy steeple
#

Room - Advent of Cyber 1 [2019]

Task 14 - [Day 9] Requests

Problem - The task states to access the web server on IP 10.10.169.100 (seems to be a hardcoded IP, versus the usual dynamic ones) at port 3000. IP is up but port 3000 is not up. None of the open ports are web-servers.

Things I've Tried - Ensured VPN connection is good. Cannot reset the box as it doesn't seems to be a "static" box.

wheat fractal
#

Hi everyone! Since yesterday it's almost impossible to work with hackpark. The access to the webserver, to the blogengine admin page everyhting is slow. The file manager does not load the page completely.... once I managed to get inside even to run a simple dir command sometimes takes ages to have a result. Is it possible to do something about this?? I spend more time reloading pages and commands than practicing on the box itself.

raw dune
#

Hello guys! Still no internet access on the vulnerable machines in CSP ROOM?

teal barn
#

It seems that we can't solve That's The Ticket https://tryhackme.com/room/thatstheticket because TryHackMe Request Catcher seems down (see <#site-bugs message>).
It looks like TryHackMe Request Catcher is the only allowed host because setting a listener on my machine I receive message from me but not from the admin.

#

@tepid moon can you confirms that?

vagrant sedge
#

The newest room (CMspit) is veeeery slow, i reseted the machine twice and the ||assets|| won't load even if i wait for 10 minutes i get a "System Error" ||i tried with 2 users, admin and skidy||

crimson iron
#

IDK if this is a bug or if this was intended, using sudo pkexec /bin/bash in Networking Services 2 gives you root access

#

sudo asks for password, i got the password wrong and it still gave me root access

eternal summit
crimson iron
#

The task3 VM, the final queston of task 4 is to give the root flag

deft garnet
#

ROOM - CMSpit
LINK - https://tryhackme.com/room/cmspit

ERROR TYPE - small typo

TASK - 1 QUESTION - 10.
Answer is in format of
"CVE-0000-00000"

BUt asnswer say CVE-0000-0000

#

slight mistake of one zero

eternal summit
#

That's a public IP, that's one of a very very very small number of systems with a public IP and Internet access.

#

It needs it as part of the room, for some arcane reason. Then Muir made it a bit more evil after it was required

#

Correct, you'll be scanning it over the internet

obsidian kiln
#

I need to make more public ones -- they threw people off so badly

#

How long has it been active for?

#

It's active

#

Just tried connecting

#

Screenshot the error?

#

Okay, read the error

#

What is it telling you

#

It's not saying that it can't connect

#

Check the URL -- that's all you're getting 😛

#

Faiiir. Yeah, all working as intended

#

That box is designed to throw you off balance

#

Depends on your ISP I'm afraid. Some don't care at all, others are very strict

#

I'd suggest erring on the side of caution

deft garnet
#

Thm is not a valid tld

#

Try editing etc/hosts if u want to use the website

worldly grotto
#

I think 5.1 in room/rpnessusredux changed with a latest version of nessus

wheat fractal
hazy tiger
#

It's a room loading but, I have reported to the site team and it should hopefully be fixed soon

wheat fractal
#

thanks! 🙂

west depot
#

i guess it was supposed to be its hard for me to cover all of them
room attacking kerberos
https://tryhackme.com/room/attackingkerberos

west depot
#

task-3

#

ig a user doesn't need to be there
above room Task - 5

obsidian kiln
#

They are both poorly written @west depot, but technically correct

#

There aren't any mistakes there, per se

#

That said, @twin tapir stick your Grammarly over that room -- see if it does a better job than you did smh

west depot
#

2nd one makes a sence bit now , but the first one?
That's should be like

The tool has way too many attacks and features , it's hard for me to cover all of them so I will be covering .......

Instead it has

The tool has way too many attacks and features for me to cover all of them so I will be covering......

west depot
#

My bad , there aren't any mistakes

obsidian kiln
#

Hehe, yeah. It's very badly written, but it's not actually inaccurate

west depot
#

Yes. umarucool

glad badger
swift hearth
twin tapir
gleaming stag
#

There seems to be an issue in the "Investigate Windows 3.x" room in which the info provided by the VM image is not the correct answer. For the question "What is the Parent PID for the above process?", the PID provided in the image is 616, but the correct answer is 620. We've had multiple people in my organization run into the same issue. Sometimes, terminating and restarting the machine fixes the issue, other times it doesn't. I apologize if this is a known issue... I tried searching the channel and didn't find anything. Thanks.

wheat fractal
livid escarpBOT
#

Gave +1 Rep to @hazy tiger

wheat fractal
#

Hum, strange, zerOlogon room again doesn't load. This room -> https://tryhackme.com/room/zer0logon But on my laptop I got RED FLAG notification of my antivirus that it blocked because of Python: CVE-2020-1472B [Expl] usage in that room

viral cobalt
#

lmao AVG blocked my POC. I feel so honored

#

@lucid oasis iirc you were the right person to reach out to about AV blocking rooms?

lucid oasis
livid escarpBOT
#

Gave +1 Rep to @ocean island

idle sun
harsh pumice
#

did you run a command that would never end (like ping with no limit)

#

because that's what killed it for me

idle sun
harsh pumice
#

yeah that's why

#

ping is still running

#

hanging it

#

so just reboot the box and it should be fine

idle sun
livid escarpBOT
#

Gave +1 Rep to @harsh pumice

idle sun
#

I still think it's a bug tho

harsh pumice
#

well it just can't run multiple commands

#

but yeah I could see it being a bit confusing

glad badger
gleaming stag
meager lance
#

@dusky junco MMA CMN -Task 6, Question 2 - needs Avast definition as correct answer , not Avast-mobile as stated

livid escarpBOT
#

Gave +1 Rep to @meager lance

slow mist
#

kerberos room no workie

slow mist
#

controller pings by hostname, has the list changed?

eternal summit
#

No.

glad badger
livid escarpBOT
#

Gave +1 Rep to @gleaming stag

kindred hull
#

The attacking kerberos room definitely needs a grammar review. Many missing commas, some needed parentheses, etc.

wheat fractal
#

Sorry if I am in the wrong channel, little typo in the Task #3 Q4 of Mobile Malware Analysis

#

( Or is it still grammarly correct ? I don't know correct me if needed )

dusky junco
#

No you're right (: I updated it a little while so you're probably still seeing the old hint 😄 thanks for reporting

#

@wheat fractal ^ 😄

wheat fractal
#

Oh okay that's what I thought at first, you're welcome CMN tipsfedora

#

+rep @dusky junco

livid escarpBOT
#

Gave +1 Rep to @dusky junco

hot flame
#

I don't know if it is a real bug or something changed but I am getting ridiculously low points answering rooms. I already tried with a lot of rooms, including really recent ones and I all get, max, is 2 points for answer

zenith warren
#

Not really a bug, more a suggestion. Memory Forensics task 3, q2. It asks "what did john write", instructions on the formatting of what was written could be clearer

gusty halo
#

facing the same error @wheat fractal

#

had Reset the machine but it shows 30mins left even if i refresh it and Reset progress