#room-bugs

1 messages Β· Page 25 of 1

wheat fractal
#

Can the mods/admins not update someone else created room?

obsidian kiln
#

Admins yes, and a few of the rest of us, but it's not very polite

wheat fractal
#

Looking at the profile of "stuxnet", creator of NAX room, seems (s)he is not active on the THM anymore

#

BTW, how is possible to reach level 998? And having finished only 52 rooms, being ranked at 5076. Only 5 badges... I have better scores and I'm only at level 12 πŸ˜„

obsidian kiln
#

0 = Admin
997 = Staff
998 = Contributor
999 = Bug Hunter

#

1337 = Lucky

wheat fractal
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

wheat fractal
#

Shoot, I will never reach lever 14 πŸ˜„

obsidian kiln
#

You will if more levels are added πŸ€·β€β™‚οΈ

noble urchin
obsidian kiln
#

@dusky junco ^^ :)

noble urchin
#

Thanks πŸ˜„

dusky junco
#

this could be a problem as the VM is Windows 7

twin tapir
sour sequoia
#

こんばんわ from Jp.

I was doing "vulnversity" room. https://tryhackme.com/room/vulnversity

I could not upload rev php file to server on task4.
I selected a phtml file and submitted but it didn't finish uploading and then web browser showed error.

If you have the same problem and solved that, please tell me any advise.

tough holly
#

Something is wrong with this room

#

I'm on day 1 and cannot get it to work

eternal summit
#

Give it a bit longer to boot too.

tough holly
#

Ah gotcha, okay thank you. I didn't know about the #site-support room. It finally booted for me, it was just strange. I pay for the subscription and I've never had a room take that long to boot before so I thought maybe something was wrong with it since it's an old room πŸ˜† πŸ˜… but maybe the load is heavy this morning or something, thank you @eternal summit

livid escarpBOT
#

Gave +1 Rep to @eternal summit

eternal summit
#

It's a heavy webapp for some reason

tough holly
#

🧐 Interesting, good to know about how to VM's work though. I bet you're right, the webapp is probably heavier than I realized

eternal summit
#

Also I'd recommend not immediately assuming it's broken, usually rooms aren't and it's either user error or it just needs longer to boot.

#

Some rooms might even take 10 minutes to start fully

tough holly
#

No problem 😁 this is a website about hacking and figuring out bugs, so I thought maybe I found one somehow πŸ˜† I love THM and I've literally been using it every day for nearly 3 months, so when I thought I found a bug, I felt like I was being helpful to report it. I'll not do that in the future though if it's a big deal

teal basalt
tough holly
#

So I figured that is to be expected, that's just when I go grab my coffee lol 😎

modest mica
#

In burp suit room it says https://tryhackme.com/room/rpburpsuite
"For some additional practice on using Intruder, check out the older Learn Burp Suite room here on TryHackMe" the link doesn't work just points to this room has been made private

rotund lava
#

Thanks Muiri!!

livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

rotund lava
#

Thanks. I figured it was something like that.

fading idol
#

The course is no longer available on udemy, TCM has moved it to his website

#

you might wanna fix this

twin tapir
#

Where is this? You gave no context

cosmic plover
#

Room USTOUN
Fucking room, not fuction!
Port 1433 closed

#

5 Restart and not function

ebon otter
#

i think question 2 in task7 in owaspjuiceshop room is broken, or a least nee dsome updating, as burp made some change to the program which removed the "header" tab, so figure out where else you need to go to change what you need is not easymesnodding

latent meadow
viral cobalt
cosmic plover
livid escarpBOT
#

Gave +1 Rep to @viral cobalt

agile sequoia
#

So, I'm VPN-ed in but can't connect to their target box with any tool. Can't proceed with training like this.

#

Not even complete ARP cache entry for target at 10.10.10.2

teal basalt
agile sequoia
#

Then it says to browse around docs but 10.10.10.2 isn’t reachable.

muted charm
#

I noticed there is an error with Linux fundamentals part 3, task 4. I noticed it says to start the python module "http.server". But there is no python module named that. I think what it's supposed to say is "SimpleHTTPServer" ? > python -m SimpleHTTPServer 8000

teal basalt
eternal summit
modest mica
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

muted charm
livid escarpBOT
#

Gave +1 Rep to @teal basalt

agile sequoia
#

good morning!

ebon otter
#

not sure if PEBKAC, but in the "Authenticate" i deploy the room VM and i can ping it, but when i try to go to the IP using FF, it says it's "unable to connect"redpanda_thinking

agile sequoia
#

maybe it's blocking your source IP and you must pivot from another computer.

ebon otter
agile sequoia
#

oh, so you could reach it before?

ebon otter
agile sequoia
#

oic. wish I could help then.

ebon otter
agile sequoia
#

ok

agile sequoia
#

nope

#

it's still a problem with the page

#

it's like they forgot to stand up the .2 system to query with smbclient or other tools

eternal summit
eternal summit
ebon otter
formal kraken
#

is the machine in Post-Exploitation Basics buggy? cause powershell is not recognizing any of the commands

agile sequoia
#

smbclient //10.10.10.2/secret -U suit -p 445 (That last -p 445 is the port)

#

hint: smb

eternal summit
#

You are not told to use that IP. Do not use that IP, it is the wrong IP.

agile sequoia
#

I'm just reading the instructions. First it says 'suit' as the user, then to try Anonymous to see if it's permitted.

eternal summit
#

Deploy the target machine and use the IP of that target machine

agile sequoia
#

Maybe, but it says to browse around the target computer to see if anon is allowed. how am I misreading that?

eternal summit
#

Because you are assuming that it means 10.10.10.2

#

10.10.10.2 is nothing more than an example IP.

agile sequoia
#

so what are we supposed to be targeting if not .2?

eternal summit
#

I recommend you walk backwards and get more familiar with how tryhackme works.
Machines aren't shared, you need to deploy them yourself.

eternal summit
hazy tiger
#

@agile sequoia I responded to you over email about this.. right?

agile sequoia
#

Hey, i recog your handle. yes. got your note. didn't clarify the situation

#

The sentence says "look around for any interesting documents " using smbclient as anon. What system are they talking about if it's not the .2 they just mentioned?

eternal summit
#

You seem intent on ignoring any advice we try to give you.
Please actually take into account what we're saying, otherwise there's genuinely zero chance that you'll get 10.10.10.2 working.
Asking for help and then point-blank ignoring it is just plain rude.

agile sequoia
#

My question isn't being answered in a way that matches the problem I'm seeing on the site.

eternal summit
#

-warn @agile sequoia Please follow Rule 18 - You're point-blank ignoring the advice you're getting from both THM support and volunteers.

livid escarpBOT
#

⚠ Warned GregM#4160

agile sequoia
#

lovely. well-done.

#

nm. bye

eternal summit
#

-mute @agile sequoia Please follow Rule 18 - You're point-blank ignoring the advice you're getting from both THM support and volunteers. Don't be rude to people trying to help you. The problem won't get solved if you ignore everyone that tries to help you.

livid escarpBOT
#

πŸ”‡ Muted GregM#4160 for 1 day

placid trellis
#

I cant seem to find the issue, so I am placing it here as a possible bug.

In the Ice room, I am able to exploit Icecast and get onto the system. But when I do, the process is running as x86, which the answer calls for x64. Once I launch the exploit suggester, it launches for only x86 based systems. I receive only one hit back and it is not the correct answer as it is not looking for the right architecture. Is there something that I am doing wrong, or is there a bug in the setup of this machine?

teal basalt
placid trellis
#

Let me give that a shot

#

Thanks!

placid trellis
livid escarpBOT
#

Gave +1 Rep to @teal basalt

teal basalt
#

Try the same archmigrate stuff with this command manually

placid trellis
placid trellis
#

I have a x64 meterpreter, but the local_exploit_suggester is only giving one result

teal basalt
#

Migrated to a x86 process?

placid trellis
#

No. I had an x86 process, and migrated to x64 as that is what the room calls for. But when I did that, I am still not getting the results from the local_exploit_suggester to answer the questions

teal basalt
#

IIRC, the local_exploit_suggester uses current context to use the available exploits
So if your current process is x86, it would test exploits for that
Similar for x64

placid trellis
#

Yeah, thats what I hoped would fix the issue when I migrated

#

I ran it before under the x86 context and only 1 exploit was shown, and its not the correct one.

#

This is the only one that shows up: "exploit/windows/local/ms10_092_schelevator: The target appears to be vulnerable."

#

meterpreter > run post/multi/recon/local_exploit_suggester

[] 10.10.x.x - Collecting local exploits for x86/windows...
[
] 10.10.x.x - 4 exploit checks are being tried...
[+] 10.10.x.x - exploit/windows/local/ms10_092_schelevator: The target appears to be vulnerable.

#

That is the command and output

teal basalt
#

Alright, I will have to test myself.
I don't remember that roomπŸ˜…

placid trellis
#

lol, no worries

#

I really appreciate all the help

#

I am stuck good

#

I wish I could post screenshots here

teal basalt
#

You can

#

!docs verify

tropic flameBOT
placid trellis
#

Well, another thing that worked!

#

Thanks!

teal basalt
#

Is your metasploit-framework up to date?πŸ˜…

placid trellis
#

Yeah, I even did a dist upgrade as well

#

Try again

#

The process is x86

#

You sent me on another path I am trying

#

I just ran "searchsploit -u" to see if that helps

#

Will update when done

placid trellis
#

No dice. Same result after the update.

tribal oasis
#

Throwback task 15 instructions are out of date.

#

I need help with Throwback and I'm not sure if it's a technical error. Please help me in channel #743859653343182930

ebon otter
#

seems there's also are issues in general with the "forced browsing" tasks in the "zthweb2" room as when i got to the [IP]:80 and login with the creds given in the task, i am forwarded to [IP]/note.php?note=1 while in the tasak screenshots it shows localhost/noot/note.txt,

i assumed localhostwas used when creating the room before importing everything over to THM, and normally you only need to replace localhost with [IP], to get it to work, but when i try do that by going to [IP]/noot/note.txt i just get a "Not Found" error from the php serviceredpanda_thinking

eternal summit
wheat fractal
#

Hi there, I want to report a bug, a flaw into the flaw on the authenticate room https://tryhackme.com/room/authenticate πŸ˜„ Tried to follow Task 4 JSON Web Token, the exorcise to get "Welcome user2: guest2". So the one before to play with the admin token, but I already got the admin flag.
(Don't ask me to much, because I don't understand this part very well. Confusing, even more with this bug πŸ˜› )

#

I copy pasted that encoded "eyJ0eXAiOiJKV1QiLCJhbGciOiJOT05FIn0K.eyJleHAiOjE1ODY3MDUyOTUsImlhdCI6MTU4NjcwNDk5NSwibmJmIjoxNTg2NzA0OTk1LCJpZGVudGl0eSI6MH0K." as given on that room and have put that into the cookie with the devs tools. But I bet this is not supposed to give me the admin flag straight away. As I should have created (encoded) a new token. Or did I miss something?

#

Or is that flaw so simple like that as I pasted that in the cookie array at position 0 ?

eternal summit
wheat fractal
#

I have no idea if it's a bug, I finished that Task 4, but to easy I think, as if I understood correctly, I should have created an new JSON token, modify the payload and set it to user id 0, which I did not do. I only copy pasted that encoded token as for the example for user2. But that gave me the admin flag on the run, which is not supposed to happen I think

#

I think i should have modified that payload
{"exp":1586620929,"iat":1586620629,"nbf":1586620629,"identity":2} to {"exp":1586620929,"iat":1586620629,"nbf":1586620629,"identity":0}

#

Or the room has an unknown spoiler?? that part: eyJ0eXAiOiJKV1QiLCJhbGciOiJOT05FIn0K.eyJleHAiOjE1ODY3MDUyOTUsImlhdCI6MTU4NjcwNDk5NSwibmJmIjoxNTg2NzA0OTk1LCJpZGVudGl0eSI6MH0K.

#

Let me check

#

Okay, spoiler alert into that room πŸ˜› decoded that second part of that toke (with https://www.base64decode.org/) and indeed it's already set to userid 0

#

I confirm, it's a bug (spoiler) into the room

#

Since we placed the alg value to None we don't have to add a 3rd part or the encrypted value so we can just put a dot(.) after 2nd part and leave it like that. So the final string would look like:
eyJ0eXAiOiJKV1QiLCJhbGciOiJOT05FIn0K.eyJleHAiOjE1ODY3MDUyOTUsImlhdCI6MTU4NjcwNDk5NSwibmJmIjoxNTg2NzA0OTk1LCJpZGVudGl0eSI6MH0K.

#

That's what is noted into the room

#

Shoot, forget to copy one paragraph before the above one: "Notice how we changed the value of identity from 1 to 2."

#

To resume, the eyJ0eXAiOiJKV1QiLCJhbGciOiJOT05FIn0K.eyJleHAiOjE1ODY3MDUyOTUsImlhdCI6MTU4NjcwNDk5NSwibmJmIjoxNTg2NzA0OTk1LCJpZGVudGl0eSI6MH0K. is supposed to be for userid 2 while it is already for userid 0

#

Or the question should be modified "Use the same method to find identity of admin user and retrieve the flag?"

#

Because the job is already done

wheat fractal
eternal summit
wheat fractal
#

Well I understand, but that give an extra security flaw you mean?

eternal summit
#

No

eternal summit
# wheat fractal I have no idea about what you are talking about. I'm a noob πŸ˜‰

JSON Web Token (JWT, pronounced , same as the word "jot") is a proposed Internet standard for creating data with optional signature and/or optional encryption whose payload holds JSON that asserts some number of claims. The tokens are signed either using a private secret or a public/private key.
For example, a server could generate a token that ...

wheat fractal
eternal summit
#

spoilers are not bugs

wheat fractal
#

Because his so said token for user2 (this one from the room:
eyJleHAiOjE1ODY3MDUyOTUsImlhdCI6MTU4NjcwNDk5NSwibmJmIjoxNTg2NzA0OTk1LCJpZGVudGl0eSI6MH0K)

Is actually for userid 0

#

Decoding it and it confirmed it is {"exp":1586705295,"iat":1586704995,"nbf":1586704995,"identity":0}

eternal summit
#

Ok, that's a bug.
You stating it here could be considered a spoiler, but it's not a spoiler to have the token in the room be incorrect.

wheat fractal
#

identity 0

eternal summit
#

They're also all expired but eh.

wheat fractal
#

Well, that token is supposed to be the exercise for user2, which we actually not get, we directly get the admin flag

eternal summit
#

Yeah. It's a bug.
You've now reported it.

wheat fractal
#

Don't feel offended or so please. Peace & Love...
I try to explain with my bad English that there's something not right, or not clear at all in that room

#

With that token i'm supposed to reach:

Now open the developer's tools in your browser and edit the stored cookie of the website to this new one and then just press the Go button and you'll notice that it will prompt "Welcome user2: guest2".

But I get the admin flag like show in the screenshot

median snow
#

@hazy hinge - There is a bug in Mitre room. Where in TASK 5 - Shield Active Defense.

#

Question :
Explore DTE0011, what is the ID where a defender can plant artifacts on a system to make it look like a virtual machine to the adversary
Answer : DUC0234 is correct answer

#

But it is not accepting it.

#

[DUC0234 A defender can plant files, registry entries, software, processes, etc. to make a system look like a VM when it is not.]

#

Thanks @hazy hinge for creating Mitre Room. I thoroughly enjoyed and learned a lot .. It was great experience in total πŸ™‚ Kudos to you and tryhackme Team

livid escarpBOT
#

Gave +1 Rep to @hazy hinge

twin bay
#

Room: Android Hacking 101

I think this screenshot speaks for itself πŸ™‚

twin tapir
#

@dry blade

wheat fractal
#

Hi there, there's some little typo in the title/description of the XXE room https://tryhackme.com/room/xxe
Quoting it: "This room aims at providing the basic introduction to XML External entity(XXE vulnerability."

wise spear
eternal summit
wise spear
eternal summit
#

What is your VM IP?

eternal summit
woeful wave
novel dock
#

format error in the room Agent Sudo Task 5

eternal summit
#

Eh, not really if you take it less literally

fading idol
#

You might want to change this now, because it's been a long time since msf6 has been out

eternal summit
fading idol
eternal summit
#

The whole room needs updating but it's hardly a bug

old nymph
#

Hey, I think that I have found a bug,
In the room "Network Services" on task 4 it takes a wrong input as correct answer ( i did two "//" instead of one ) πŸ˜„

glad badger
old nymph
#

ah okay, nvm then πŸ™‚

floral widget
#

So, I might have found a bug, but I havent been able to verify it because 1) I cant find anybody on the same subnet of wreath as me and 2) I dont have the time to replicate it for the next 2 weeks. Basically the 2 times that I accidentally let the timer run out on wreath it does not allow me back in. Even after you start up the boxes and wait 5-10 mins they just never respond. I can reach the .250 ( VPN server ) but everything else is down.

#

Is there anybody that could verify this?

modest mica
#

In OWASP juice shop task 8 there is no image only a border

floral widget
past orchid
#

Room [Windows PrivEsc v1.0]: Having trouble with task 1 and 2 (today only, was working fine yesterday) from my parrot OS onto the windows VM. Can see my reverse shell binary on the network share from the Windows box, but cannot copy over, greeted with "Access denied" and sometimes "the specified network name is no longer available".
Tried troubleshooting by using the THM attack box, but the file directory does not exist for: /usr/share/doc/python3-impacket/examples/smbserver.py to host an SMB share. (potentially 2 seperate issues here)

past orchid
#

installed impacket on the attackbox, and managed a reverse shell, so it must be an issue with my parrot OS, not sure what it could be

supple plover
#

I think I might have found a bug in the Blaster room. We're apparently supposed to be looking at browser history, but it's empty except for the one file I viewed today.

dense garnet
#

In the Investigating Windows Room the last login date for "John" seems to be a big buggy, I copied it straight from the machine and it seems to not work.

eternal summit
dense garnet
#

Isn't the format on the machine same as the one on the room?

eternal summit
#

Locales can be different, it might do some weird autodetection, I can't answer that

dense garnet
#

Ight I'll try

hazy hinge
agile sequoia
#

Ok. anyhow, the telnet exploit training page has a bug in the msfvenom syntax so it doesn't work. any idea who we can get to fix that? Can't proceed as is.

agile sequoia
#

I tried -arch and -platform but no variation seems to work. States Error: The selected platform is incompatible with the payload

eternal summit
#

Screenshots.

agile sequoia
#

msfvenom command missing -arch and -platform but no variation of what I've tried works.

eternal summit
#

It doesn't need them

#

It works as it is.

agile sequoia
#

hmm. those errors we get aren't stop conditions to you?

eternal summit
#

Clearly not.

#

They're informational, telling you that it's selecting them automatically based on the payload

hazy tiger
#

Usually errors stop the program from functioning, whereas this is just output/ wanrings*:)

agile sequoia
#

I may not be smart enough for this stuff. 0_o

hazy tiger
#

Not with that mindset!
It's difficult to get started with, just make sure to read everything clearly and google things you don't understand and you'll be fine:)

eternal summit
#

Something that a LOT of people seem to struggle with at the start is knowing the difference between something being broken and a small mistake they're making.
That difference is very important.
99.9% of the time, the content isn't broken.

agile sequoia
#

ok man. Sorry for the head glitch two days ago. Had jumped back into the training and forgot the target VM IP was at the start of the sub-module.

#

Thanks though. see yas

teal basalt
meager wigeon
#

owasptop10 task 14 under breaking down how the DTD validates the XML, !element body: defines the 'body' element to be of type '#PCDATA'
'element' is highlighted when 'body' body should be highlighted like the terms above
not really a bug, but just a typo?

placid trellis
#

I am still struggling with the ICE room.

#

Here is a screenshot with the local_exploit_suggester

#

I only get one hit

#

And it is being run as an x86

#

I have migrated to a x64 meterpreter as well, still the same thing - only one result

#

Is it a "bug" that this is running as x86 or am I doing something wrong?

twin bay
#

Well - It is an x86 binary (Seeing as how it's in C:\Program Files (x86)\)

#

So it'd stand to reason that escalating through it would give you an x86 shell

wheat fractal
#

Not sure if this qualifies as a bug but I would like to share a problem I experienced and how I solved it.

In the room "Common Linux Privesc" I couldn't get the LinEnum script to run neither on the remote machine nor my local machine using the script in task 4 using wget https://github.com/rebootuser/LinEnum/blob/master/LinEnum.sh

I kept getting this error:

user3@polobox:~$ ./LinEnum.sh
./LinEnum.sh: line 7: syntax error near unexpected token newline' ./LinEnum.sh: line 7: <!DOCTYPE html>'
user3@polobox:~$

I found this comment by @plucky ginkgo

27/07/2021
@snow ravine ,These are the commands:
root@kali:~/Downloads/linenum# git clone https://github.com/rebootuser/LinEnum.git

This solved my issue and I was able to run the LinEnum.sh on my local machine and on the remote machine.

user3@polobox:~$ ./LinEnum.sh > output_LinEnum.txt
user3@polobox:~$

teal basalt
#

This one https://raw.githubusercontent.com/rebootuser/LinEnum/master/LinEnum.sh

wheat fractal
livid escarpBOT
#

Gave +1 Rep to @plucky ginkgo

wheat fractal
pearl socket
#

In the room https://tryhackme.com/room/rpmetasploit
In the task 7
In the question 2
"Additionally, we can start a socks5 proxy server out of this session. Background our current meterpreter session and run the command search server/socks5. What is the full path to the socks5 auxiliary module?"

There is no ||auxiliary/server/socks5 || in metasploit anymore
There is auxiliary/server/socks_proxy now
Maybe this should be changed ?

livid escarpBOT
#

Gave +1 Rep to @hazy hinge

versed yoke
#

Not a bug per se but rather outdated instructions provided at the beginning of the Volatility room. It says that the tool can be installed via 'apt-get install volatility'. Well, it apparently can't be installed like this anymore so I figured I'd report it in case you think it's worth updating the copy. Edit: obviously apologies if this should've been posted in #site-bugs, I only noticed it after posting it here.

eternal summit
sand dome
placid trellis
placid trellis
#

Im not sure it is a bug, so much it is an issue with the room now. I am moving this to there.

hazy elk
#

In the Windows Event Logs room, task 4 question 4:

Execute the command from Example 8. Use Microsoft-Windows-PowerShell as the log provider. How many event ids are displayed for this event provider?

the website answer is ###, which is the results from running the command with '(Command).count or 'Command | measure' but not the actual number of events, these include whitespace at the end of the list of results and the lines at the beginning of the results with formatting info. actual answer is ###-4.
Discovered this before learning about the .count and | measure by running the command with 'Command > events.txt' and opening in notepad which shows the line count.

fast prawn
#

I think this is a bug

#

the module corresponds to the CVE asked earlier

#
#

task 1 q 8

#

even after copying the answer from a writeup, it doesn't work

#

checked 6 of them and none work

teal basalt
uncut wagon
#

Room: https://tryhackme.com/room/osqueryf8
Task: 4 (Schema Documentation)

All questions refer to the documentation here: https://osquery.io/schema/4.7.0/ (version 4.7.0)

Questions/Issues:
Q. How many tables are there for this version of Osquery?
=> System Expects: 266
=> Documentation Says: 271
Q. How many of the tables for this version are compatible with Windows?
=> System Expects: 96
=> Documentation Says: 98
Q. How many tables are compatible with Linux?
=> System Expects: 155
=> Documentation Says: 156

Is it possible the documentation has changed since the room was created?

white widget
#

Room: Sakura
Task: 2 TIP-OFF

Accepts partially wrong answer. Answer should be: "Sak**<snip>" but accepts "ak<snip>**"

(Also have screenshot)

obsidian kiln
white widget
obsidian kiln
#

Np πŸ™‚

runic ravine
#

Hi! I also have this problem, it was not solved?

teal barn
dusky oriole
#

room: YARA, https://tryhackme.com/room/yara
Task 6, 6,2 conditions. There
I tested locally and on the in-browser VM. the syntax in the picture using a $ instead of '#' causes YARA to fail. it should be #{variable_name}

$hello_world <= 10

checking 3.x and 4.x documentation, the syntax does not match the image in the room. Not sure if this is a typo or deprecated usage. https://yara.readthedocs.io/en/v3.4.0/writingrules.html#conditions

The number of occurrences of each string is represented by a variable whose name is the string identifier but with a # character in place of the $ character.

woeful plover
#

Hey, is there a bug in wonderland?

eternal summit
#

I mean there might be, but it certainly won't affect your ability to complete the box

#

I haven't modified the room

woeful plover
#

Then maybe i am badly stuck at priv escalation part πŸ˜“

dusky oriole
zinc dove
#

@dusky junco I appear to be having the same issue, in the same room as this message was discussing #room-bugs message

Every time I go to extend the session, it just goes poof

#

IP I was using is 10.10.78.110 and i think it was at 56 minutes remaining when i extended it

dry blade
ancient relic
lucid bough
#

In the room Linux Fundamentals2 on the snipet example "Using ls to view hidden folders" it seems to be missing the -a argument
tryhackme@linux2:~$ ls .hiddenfolder folder1 tryhackme@linux2:~$

civic ibex
#

do we report typos here?

viral cobalt
#

rumor has it @glad badger is the typo-fixer πŸ‘€

glad badger
#

World famous typo fixer. 128 tpm. πŸ₯³

granite glen
#

having problems with the first question of the How websites work room. the answer should be Front End but it say incorrect

eternal summit
#

The video is incorrect

granite glen
#

ohhh

#

ok

zinc dove
#

Still having the same problem as i was last night with relevant, where it seems like it's dying after an hour

eternal summit
#

It's been reported, the correct people have been made aware

zinc dove
#

ok, I saw a thing yesterday from like January where... someone said he thought he had fixed it

granite glen
#

@eternal summit done thanks

livid escarpBOT
#

Gave +1 Rep to @eternal summit

zinc dove
#

Thanks as always

zinc dove
#

Is the fact that the machine seems to hang fairly frequently for a few minutes related to that @eternal summit ?

eternal summit
#

That... that will not be

zinc dove
#

is it a known thing? I'm running gobuster, and every time i start getting time outs, pings also start failing, but eventually it comes back

eternal summit
zinc dove
#

default i think it's 10

#

but it's been happening with every enum i do

eternal summit
#

That's not so normal. @dusky junco can you check the resources on Relevant please?

zinc dove
#

Here's what i'm seeing: First failure on gobuster: [ERROR] 2021/09/24 19:05:56 Context deadline exceeded or io timeout

Running a ping test in another terminal, on a 10 second interval:

[1632524744.848828] 64 bytes from 10.10.46.91: icmp_seq=8 ttl=125 time=86.0 ms
[1632524877.678213] 64 bytes from 10.10.46.91: icmp_seq=21 ttl=125 time=86.1 ms
[1632524887.687245] 64 bytes from 10.10.46.91: icmp_seq=22 ttl=125 time=85.0 ms
eternal summit
#

I had some issues but nowhere near that bad

zinc dove
#

notice it halts for ~100 seconds, from 4733 to 4877

dense pelican
#

Hi, I think I have an issue with the Alfred Room

#

There is an admin available ?

#

Ok I was stuck on the Task2 with the : Start-Process "shell-name.exe"

#

It was executed on the server but the revershell don't connect

#

So, my solution was to just enter : shell-name.exe

#

And it connect to the reverseshell

#

I don't know if you want to correct the instructions :). Have a nive day πŸ˜‰

obtuse musk
obtuse musk
charred summit
#

Also in the Metasploit exploitation room, there isn't a download button to get the wordlist if you're using your own box. (Task 1)

vague salmon
#

I am working on Metasploit: Exploitation room Task: 2 , try to find an smb user password but given password file (/usr/share/wordlists/MetasploitRoom/MetasploitWordlist.txt) is unable to find password, how can I go on, trying another password file like rockyou.txt ??
Besides, it states that "please download the wordlist by clicking the Download Task Files button to the right" , good! but where is this button I could not find ??

severe ravine
charred summit
vague salmon
#

@severe ravine same issue for me, like @charred summit stated.

obtuse musk
#

got the wordlist, too. But the password for penny still isn't there..

vague salmon
#

you are right

obtuse musk
#

NOW IT WORKED!!!!! lol

simple citrus
#

same problem with the password for user penny

#

oh what

simple citrus
obtuse musk
#

download the file from task 1, upper right corner πŸ™‚

#

Thanks @severe ravine πŸ™‚

livid escarpBOT
#

Gave +1 Rep to @severe ravine

simple citrus
#

Thx @obtuse musk

livid escarpBOT
#

Gave +1 Rep to @obtuse musk

charred summit
#

All reappeared, plus wordlist with an extra line! πŸ˜‚ Thanks for sorting that πŸ‘

obtuse musk
vague salmon
#

Gave +1 Rep to @obtuse musk

#

Gave +1 Rep to @severe ravine

obtuse musk
#

are you using Metasploit?

#

hydra didn't work for me either. Try metasploit πŸ˜‰

livid escarpBOT
#

Gave +1 Rep to @obtuse musk

obtuse musk
#

yep, it was lolol πŸ™‚

#

No worries πŸ™‚

brave notch
#

@severe ravine thanks for fixing the issue dg, gg

livid escarpBOT
#

Gave +1 Rep to @severe ravine

wheat fractal
#

Okay, I'm doing more of Metasploit:Exploitation, and there is a task that involves generating reverse_shell.elf , Unfortunately I get Segmentation Fault when executing it

proper meadow
#

Hey this room has a bug, the wordlist provided has not the right password..

#

This is the room

molten surge
#

Wordlist was recently updated

#

Try download a fresh copy

wintry gull
#

I report that a month ago nothing have change

graceful aspen
#

Hello, I've a bug in this room
https://tryhackme.com/room/introtoshells
At Task 7 we learn about socat encrypted shells, and to do it we need socat on the target and our attack machine. So they suggest to save a pre-compiled binary of socat and host it on a python server then wget it on the target.
We must use OPENSSL args on both sides to succeed in connecting. But the pre-compiled binary linked in the room is not compiled with OPENSSL, and therefore can't be used to complete the connection.

eternal summit
#

@obsidian kiln this one's for you

alpine tangle
#

Linux Fundamentals 2 https://tryhackme.com/room/linuxfundamentalspart2

Task 5: Although intimidating, these three columns are very important in determining certain characteristics of a file or folder and whether or not we have access to it. A file or folder can have a couple of characteristics that determine both what it is that and who we can do with it as -- such as the following:

Read
Write
Execute 

The diagram below is a great representation of how these permissions can be translated.

#

There is no diagram

lone wind
#

rejetto http file server on steel mountain doesnt show up in any scans

#

the two servers are other ones

stuck stirrup
stuck stirrup
dusky junco
livid escarpBOT
#

Gave +1 Rep to @stuck stirrup

dusky junco
#

+rep @alpine tangle

#

ree

wheat fractal
#

hello

#

the order of the tasks for this room is weird

#

i guess it's an error

bronze wren
#

Intro to Windows > Task 6
When RDP'ing into the AD machine, Im brought right to a your password is expired and must be changed screen.
Attempting to change the password disconnects you from the RDP session. This does not happen in the walkthrough.

teal basalt
alpine tangle
#

THM laggy, or is it me? Doing Linux 3, the ssh connection keeps dieing on me. Did rooms 1 and 2 with no problem

bronze wren
#

The credentials provided are Administrator:Tryhackme123! no space anymore.

eternal summit
#

What RDP client are you using?

bronze wren
#

Remmina

eternal summit
#

Try a couple different ones

#

Xfreerdp works decently, as does rdesktop

#

If you can use the official Microsoft one on your OS, use that

bronze wren
#

Sure, but if the password change prompt is coming from the Windows machine, I'm not sure how changing the client would help.

#

Can't even connect with rdesktop

#
Failed to initialize NLA, do you have correct Kerberos TGT initialized ?
Failed to connect, CredSSP required by server (check if server has disabled old TLS versions, if yes use -V option).
eternal summit
#

RDP when it's not a Windows official MS client and official Windows RDP server is a mess

bronze wren
#

Native windows RDP connects but same pwd change msg

teal basalt
bronze wren
#

So to recap:
Remmina - Connect, pwd must be changed
Rdesktop - No connection at all
Native RDP- Connect, pwd must be changed

eternal summit
#

But you should be able to go through with the change.

bronze wren
#

I get disconnected from the RDP session

#

just get booted out

alpine tangle
#

@dusky junco

linux 3

only manual instructions, doesnt explain automation. Doesnt take much leg work to figure out its the enable option. Not even really a bug, idk... lol... Instructions say itll go over manual then automated, but doesnt. shrug Leaving this here just in case lol

carmine urchin
#

In Filter Evasion Challenge 3 where Hello is filtered, I used <img src="" onerror="alert(String.fromCharCode(72, 101, 108, 108, 111))"> and got alert Hello but there is no flag received after it.
Kamalakannan D
β€”

Again for challenge 4 <img src=q onclick="alert(String.fromCharCode(72, 101, 108, 108, 111))"> this payload prompts Hello
But I didn't receive any flag

raw bison
gaunt lake
#

Hi everyone, on https://tryhackme.com/room/malmalintroductory in Task 14 answer 2 might be wrong. Once I checked the MD5 file with virustotal, I received that the hash is not malicious, as I put "Nay" as an answer I have got "Wrong Answer"...

misty cave
civic ibex
#

In the OWASP Top 10 room, task 26, the link doesn't go to a python script, it goes to a bunch of json.

#

this page

eternal summit
#

You shouldn't be doing any rounding

alpine tangle
#

Im just making a python script.

Math must be a use it or lose it thing xD

kind fern
#

In Linux Fundamentals Part 2, Task 5, paragraph 3, the wording seems off.

A file or folder can have a couple of characteristics that determine both what it is that and who we can do with it as -- such as the following:

ancient quail
#

hello is there any bug in metasploit exploitation room

lone wind
#

on windows basics 1, you can’t connect the Remote Desktop

floral garnet
#

In Overpass 2 I submitted a wrong flag and it accepted it as right.

Not sure if that's suppose to happen but I figured I'd pass it off anyway.

hazy tiger
#

Answer tolerance

#

95% correct, the answer box will accept it

#

Refresh and it will update

pseudo wyvern
eternal summit
stuck stirrup
stuck stirrup
copper python
#

They all refer to mysql service however the port is closed when I port scan the machine

gusty halo
#

In Retro i am getting an error(12004 Winhttp internal error) when i try to transfer files to the target machine using Certutil or Invoke WebRequest.

The same command seems to work for others when i tried checking out writeups.Tried Resetting the machine multiple times but nothing seems to work.

signal tundra
#
#

This links don't come up for me

upper sparrow
#

this is written really poorly and confusingly: ```Kerberos Tickets Overview -

The main ticket that you will see is a ticket-granting ticket these can come in various forms such as a .kirbi for Rubeus .ccache for Impacket. The main ticket that you will see is a .kirbi ticket. A ticket is typically base64 encoded and can be used for various attacks. The ticket-granting ticket is only used with the KDC in order to get service tickets. Once you give the TGT the server then gets the User details, session key, and then encrypts the ticket with the service account NTLM hash. Your TGT then gives the encrypted timestamp, session key, and the encrypted TGT. The KDC will then authenticate the TGT and give back a service ticket for the requested service. A normal TGT will only work with that given service account that is connected to it however a KRBTGT allows you to get any service ticket that you want allowing you to access anything on the domain that you want.```

astral anvil
# upper sparrow this is written really poorly and confusingly: ```Kerberos Tickets Overview - ...

Maybe a suggested update? Thoughts

The main ticket that you will see is a ticket-granting ticket (TGT) these may come in a variety of forms such as a .kirbi for Rubeus or .ccache for Impacket. The main ticket that you will see is a .kirbi. A ticket is typically base64 encoded and can be utilised for various attacks. The TGT is only used with the Key Distribution Center (KDC) in order to get service tickets. Once you give the TGT to the server it will then get the Users details, session key, before encrypting the ticket with the service account NTLM hash. Your TGT then provides the encrypted timestamp, session key, and the encrypted TGT to the KDC which will then authenticate the TGT and give back a service ticket for the requested service. A normal TGT will only work with the connected service account. However, a KRBTGT allows you to get any service ticket allowing you access to anything on the domain.
upper sparrow
#

better, but still misses some punctuation

astral anvil
#

I’ll take that as didn’t throw thru grammarly πŸ˜‚

spark apex
#

Room - Corp
Task 4
Hyperlink not available

vague salmon
#

Task 5 Creating queries: question "What is the query to show the username field from the users table where the username is 3 characters long and ends with 'en'? " must 'em'

#

There is no use in the table ending with %en

true karma
#

Hey, I'm doing Advent of Cyber1 Day9. But I can't access 10.10.196.100:3000 is this normal?

stuck stirrup
livid escarpBOT
#

Gave +1 Rep to @spark apex

stuck stirrup
vague salmon
#

change question OR change DB

stuck stirrup
wheat fractal
#

Hi there, In the meterpreter room (https://tryhackme.com/room/meterpreter) a typo in the hint of Task 5 of the question "Where is the "secrets.txt" file located?" The hint say: "You can use any of these commands: search -f *.txt search -f secrets.txt.txt" (mention of double txt)

eternal summit
wheat fractal
#

Got my answer already: No files matching your search were found.

#

Shoot: I should have removed the name of the secrets.txt (That's the answer: C:\Program Files (x86)\Windows Multimedia Platform)

wheat fractal
kindred hull
wheat fractal
#

You will not find that file with the hint given

burnt raven
burnt raven
eternal summit
#

@burnt raven 2.4.99 and 2.4.99 are the same?

burnt raven
burnt raven
livid escarpBOT
#

Gave +1 Rep to @eternal summit

hazy hinge
# vague salmon change question OR change DB

You are correct. There isn't a user that will be returned but the question is simply asking you to submit the query based on the question. The question is not asking for an actual user/username.

brave notch
faint ridge
wheat fractal
#

Hello everyone
I've got a problem with the network services room
I'm actually on task smb exploit and i have a problem with ssh login
I found the user name which is John and i downloaded his private ssh key on the smb server but when i'm trying to connect on the ssh server it tell me that the connection is bloqued
i augmented keys permissions by using chmod 600 id_rsa

eternal summit
stuck stirrup
livid escarpBOT
#

Gave +1 Rep to @ocean island

stuck stirrup
wheat fractal
livid escarpBOT
#

Gave +1 Rep to @eternal summit

boreal prism
#

Hi guys , room look to glass have bug of login with correct password

#

Ssh jabberwocky@roomip -p 22

#

Am using correct password (bewareThejabberwock) but not login , please fix as soon , am using my pc and tryhackme kali machine as invalid login

dusky junco
boreal prism
#

@eternal summit man fix your room as soon please

teal basalt
boreal prism
#

Yea

teal basalt
#

IIRC, the actual password is constructed as the combination of four random strings from a wordlist.
And the password is subject to change after multiple trialsπŸ€”

#

||bewareTheJabberwock|| isn't the password for SSHπŸ™‚

boreal prism
#

This right ? (bewareThejabberwock)

teal basalt
#

Verify it on the service from where you found it first

#

The one that saysπŸ€”
Enter secret:

boreal prism
#

Massage before decrypt is ('Awbw utqasmx, tuh tst zljxaa bdcij
Wph gjgl aoh zkuqsi zg ale hpie;
Bpe oqbzc nxyi tst iosszqdtz,
Eew ale xdte semja dbxxkhfe.
Jdbr tivtmi pw sxderpIoeKeudmgdstd)

boreal prism
obsidian kiln
eternal summit
obsidian kiln
#

That box hasn't changed since it was released.

eternal summit
boreal prism
eternal summit
#

Because you demanded that I fix an issue

#

And that I make it my priority

#

When you haven't checked writeups or done any of the background work to check if it's a bug

boreal prism
eternal summit
boreal prism
#

I don’t know , am asking for help

eternal summit
#

This is not a bug and I won't discuss it any further. Try harder. Use the appropriate help channels if you're stuck

boreal prism
eternal summit
#

-mute @boreal prism 20m Incredibly rude, demanding that a creator fixes their box when there's not a bug. Refusing to follow the standard help process.

livid escarpBOT
#

πŸ”‡ Muted resteex0#7293 for 20 minutes

boreal prism
#

@eternal summit why you muted me ? , am paid money for tryhackme for service not rude from you to me , am asking for helping and you getting angry why ? I don’t know .? Cannot working with customers please dont rude with us

#

I want real someone from technical support of tryhackme

hazy tiger
#

Hey @boreal prism
You requested someone from technical support? :)
What's your issue?

boreal prism
hazy tiger
#

I am technical support:)

boreal prism
hazy tiger
#

Hey!
I'm sorry you feel that way.
Discord moderators are volunteers, they are not TryHackMe employees.

Give me a moment to read your issue:)

boreal prism
#

Ok

hazy tiger
#

Hey, so it looks like you're missing a capital letter on the password, have you tried "bewareTheJabberwock"

#

Oh, whoops, sorry that's wrong.

boreal prism
hazy tiger
#

So, you were demanding that the room creator should fix their room.

It’s not acceptable behaviour to request someone to fix something, it comes across as rude.

boreal prism
hazy tiger
#

Ah, so, I see your issue.

#

The β€œpassword” you are using is actually the ||secret|| required to get the password.

The room isn’t broken at all:)
Have you checked the writeups on the room yet?

boreal prism
#

Because that am here for asking helping

hazy tiger
#

You didn’t ask for help.

boreal prism
#

@hazy tiger Man if I created room and someone having issue with my room , not shooting with him

hazy tiger
#

Look, you said

#

That’s very rude, especially as the room isn’t broken:)

boreal prism
hazy tiger
#

Please read writeups on the room to fix your problem, or ask for help in the help chats #room-help

boreal prism
#

Am asking with please

#

@hazy tiger listen this you replay to solved issue ?

#

The room not sams as god but can same as bugs , this my right to asking for helping

#

@hazy tiger you not fix my issue here

glad badger
boreal prism
# hazy tiger

@glad badger this not rude , but after that from your team is rude because am asking for help , and this not help , any room have bugs and you know that , why this guys angry ? I don’t know ? I see very simple issue , why all this of misunderstand

glad badger
boreal prism
#

But not valid login on my pc or machine of tryhackme

#

I spent one hour from my time to chatting bullshit , now am asking for help no clear technical answer to solving , someone not have meaning of word ( please ) and attack customers for nothing , customers enter here for looking solving issue but the replay out of the box , if real any one from tryhackme teams should be apologizing for me , this very deep disappointment of tryhackme teams here

gleaming shadow
#

Hey, please stop arguing as the room is not broken. The problem is user error; Read the existing writeups and figure out what you are doing wrong or I will ban you.

eternal summit
#

-mute @boreal prism 48h Incredibly rude to both a room creator and support staff. Continuing this behaviour after a 20min mute. Be polite, be respectful, and please stop when you're asked.
Your issue is entirely user error, and can be resolved easily by following the instructions provided to you but support staff.
If you continue being rude after this mute, you will be permanently banned.

livid escarpBOT
#

πŸ”‡ Muted resteex0#7293 for 2 days

wheat fractal
#

I think that this is more of a typo than a bug. I'm in the Metasploit room, task 2 Scanning. It says "Metasploit will scan port numbers from 1 to 1000" But when I open msfconsole and the module portscan/tcp it says "PORTS 1-10.000" by default and it also says 1-10.000 in the screenshot above the text in task 2 Scanning.

heavy spade
livid escarpBOT
#

πŸ”¨ Banned resteex0#7293 indefinitely

livid escarpBOT
#

Gave +1 Rep to @tiny sun

river stone
#

@vagrant light @idle plume I'm having what appears to be a serious issue on the final portion of Osiris. I just spent five hours on my livestream struggling with it. As I'm sure you remember, the final hurdle of this box involves rebuilding a DPAPI master key using the domain backup key on Ra. In the writeup, CQDPAPIBlobSearcher.exe is used and has the following output, screenshotted directly from the writeup:

#

This is a screenshot of running the same tool with the same arguments on Osiris, live right now:

#

notice that the "mkguid" in both is different. I believe this is the root of my issue.

#

The writeup asserts that mkguid "a773eede-71b6-4d66-b4b8-437e01749caa" is the correct Keepass one, and that guid is indeed present here that I can see but does not seem to be associated with anything.

#

Regardless, I have used CQMasterKeyAD.exe to rebuild BOTH master keys with both mkguids, and Keepass does not open.

#

Iive done this probably five or ssix times now. I've extracted the key from Ra using CQTools and using mimikatz. I've gone through this whole process multiple times and it does not work. Nothing ever works to get Keepass open.

#

I just walked through ALL of the steps in the walkthrough command by command copy/pasting where possible, and KEepass STILL does not open.

#

At this point I believe there is an issue with the machine. The mismatched mkguids seem to indicate that. Unless you have something I'm missing to point out?

quiet peak
#

hello, i am wondering if this is a bug: in overpass:

#

||i need to use port 80 to set up the reverse shell script as mentioned in the writeups, but port 80 is in use by websockify on the attackbox.||

#

why is this port in use on the attackbox? i feel like trying to reconfigure this would definitely break some proxying it's clearly using

#

i can't complete this on my locally virtualized parrot box either because the vpn isn't working according to the instructions πŸ₯²

vagrant light
# river stone At this point I believe there is an issue with the machine. The mismatched mkgui...

Hi. We did encounter exactly the same issue a couple of times a while ago, when doing a run-through. Reset the box and then it worked. Have no idea what makes this happen. The box-image is unchanged, so the problem cannot be there. It just seems to happen sometimes... Put as much as possible in the ducky-script. That way you will be at the right place only a couple of minutes, after a reset.

river stone
livid escarpBOT
#

Gave +1 Rep to @vagrant light

vagrant light
river stone
#

@vagrant light Nah I get it man, these are the eldritch dark magicks and you can only understand DPAPI so much ❀️

dense garnet
#

Network services 2, NFS, bug related to the bash file```./bash: error while loading shared libraries: libtinfo.so.6: cannot open shared object file: No such file or directory

#

I finally solved it using a sudo exploit

#

only CVE-2021-3156 worked for me

teal basalt
dense garnet
#

Oh oops

#

welp I already got the room lol

#

It was honestly way more fun having to find a different exploit myself xD

zenith rapids
#

#alfred There root flag is not in the "C:\Windows\System32\config" directory

#

#alfred in fact I am unable to locate it anywhere in the box

eternal summit
#

Otherwise Windows simply denies that the flag exists

obsidian kiln
#

That isn't a bug

lone wind
#

it isnt?

#

im sorry

obsidian kiln
#

No, it's you not knowing alternatives to DNS πŸ˜„
(That's your hint btw)

lone wind
#

hm

lone wind
hazy tiger
#

https://tryhackme.com/room/owaspjuiceshop
Task 4, Question 2 ( @dusky junco )

Bug/ Issue:
Typo, it should be "James", not "Jame"

Incorrect Sentence:
"Believe it or not, the reset password mechanism can also be exploited! When inputted into the email field in the Forgot Password page, Jim's security question is set to "Your eldest siblings middle name?". In Task 2, we found that Jim might have something to do with Star Trek. Googling "Jim Star Trek" gives us a wiki page for Jame T. Kirk from Star Trek."

Correct Sentence:
"Believe it or not, the reset password mechanism can also be exploited! When inputted into the email field in the Forgot Password page, Jim's security question is set to "Your eldest siblings middle name?". In Task 2, we found that Jim might have something to do with Star Trek. Googling "Jim Star Trek" gives us a wiki page for James T. Kirk from Star Trek."

Screenshot:

dawn iron
#

https://tryhackme.com/room/thefindcommand
Task 3, Question 8 (@frail vigil)

Find all files that were not accessed in the last 10 days with extension ".png"
(emphasis mine)

I made a mistake:
||find / -type f -atime -10 -name "*.png"||
This would find files that were, in fact, accessed in the last 10 days, but it was marked as correct.

I reset the room and put in the correct answer, which was also accepted.
||find / -type f -atime +10 -name "*.png"||

It's a small thing, but I thought you'd want to know. Thank you!

livid escarpBOT
#

Gave +1 Rep to @frail vigil

upper condor
#

Having trouble with "Walking an application"

The question is what "What is the framework flag?" which I have found, and pasted it into the answer box. However it's saying that the answer is wrong. Just wondering if this has been happening to anyone else?

frail vigil
livid escarpBOT
#

Gave +1 Rep to @dawn iron

thin sleet
#

I think room: "Wgel CTF" might be bugged. I was able to get the ||id_rsa key|| and I'm trying to run ||"ssh -i ~/.ssh/id_rsa <login name>@<ip>"||.I am asked for a password still. I still have a lot to learn about hacking but I've checked a few walk-throughs and they seem to confirm I'm at the correct step. The users in the walkthrough also don't get asked for a password.

odd shadow
#

10.200.126.0/24 for holo is down 😦

#

tried waiting the time and restarting - no luck

rapid hawk
odd shadow
#

anyone in holo .126 subnet mind voting reset for me

#

Needs 3/5 more I can only do it every hour

marsh brook
#

#room-bugs In learning Path Cyber Defense, Threat and Vulnerability Management, Course Intro in ISAC: the strings.exe worked only after copying the file in C:\Windows\System32

astral anvil
#

Lockdown room has bug that even if you leave admin password blank it will override

river stone
#

@vagrant light @idle plume Update on the Osiris issues I reported a few days ago: on stream today I was finally finishing up the box and I determined specifically what is changing the guid for the Keepass DPAPI blob. Running Keepass before re-building the Master Key is what ruins it; it seems that Keepass tries to access the correct master key, fails, and then sets a different GUID on its encrypted blob, perhaps so it can try accessing it with that key as a fallback?

#

I'm not sure why it does this, but I did confirm it using mimikatz' dpapi::cred command on the ProtectedUserKey.bin file just before trying to open Keepass (unsuccessfully, because Charlotte's password has changed) and then just after, and the guids were different.

#

I don't know why Keepass does this, but it seems this is what is requiring a box reset.

rapid hawk
#

Just confirming, the id_rsa in that folder is the one you copied?

thin sleet
#

Yeah. I was sure to mv my host generated id_rsa into a hidden folder out of that dir.

rapid hawk
#

Ah ok. Just making sure. I haven't done that box yet, so I can't say for sure, but the id_rsa might require a password to use. The brother of a serial killer might be able to Crack it (don't wanna give away what to do if that is indeed the next step. You should get the reference, if not lmk)

thin sleet
#

Yeah I got it. I didn't think about that. Should have lol. I was just kinda stumped when the walkthrough snips didn't show the box asking for a pass.

rapid hawk
#

Yea. Again, idk, could be that it is bugged. I haven't done it yet, but thats what I'd do next

thin sleet
#

lmk if you too run into an issue when you get to it.

rapid hawk
#

Will do

vagrant light
livid escarpBOT
#

Gave +1 Rep to @river stone

proper moon
#

Not exactly a bug just that the directories in linux2 aren't the same as the questions. Just input the answer for the ASCII text question from the video because the directories didn't match.

eternal summit
livid escarpBOT
#

Gave +1 Rep to @river stone

frail halo
eternal summit
#

@obsidian kiln

obsidian kiln
#

Blugh

frail halo
obsidian kiln
#

Gotta take dog out, but will deal with that in a little bit

#

Ta for reporting πŸ™‚

dense garnet
#

the final XSS task doesn't seem to work

#

It isn't sending the requests back

#

anyone managed it?

proper jasper
brave notch
#

Just want to confirm that Task 8 from XSSGI - acmeitsupportv10 seems bugged with the provided payload. I suggest looking online for another payload (or craft another with your h4ck3r skillz) πŸ˜‰ Because it can work.

brave notch
#

@glad badger I tried both and it did not work. I changed the xss payload and then it worked for method1

#

||<img src=x onerror=this.src="http://<machine-ip>/?c="+document.cookie>||

rigid basalt
#

Can confirm above. was able to get a payload to trigger but method listed in room werent working. None the less still a great room.

river stone
# vagrant light Ahhh. Interesting. Thanks for clarifying what makes this happen! Btw. is your st...

@vagrant light It is! https://twitch.tv/alh4zr3d is the main page. The videos are here: https://www.twitch.tv/Alh4zr3d/videos. My Osiris run is spread over three separate streams; the first is this one: https://www.twitch.tv/videos/1160065874, the second is struggling with DPAPI and becoming frustrated: https://www.twitch.tv/videos/1163763875, and the third I just did yesterday and I finally finish it: https://www.twitch.tv/videos/1166580516

glad badger
vagrant light
vague salmon
#

Hi everybody! Is there any problem in room Cross-site Scripting? After trying to enter a payload site becomes inaccessible as displayed on the browser "Unable to connect" ??

#

or I do something wrong ?

vague salmon
#

ok , it s working now. It was probably temporary

thorny fjord
#

same here

#

same here

uncut wagon
twin bay
#

https://tryhackme.com/room/sqlinjectionlm

Changing the query to "LIMIT 1,1" forces the query to skip the first result, and then "LIMIT 2,1" returns the second result and so on. You need to remember the first number tells the database how many results you wish to skip, and the second number tells the database how many rows to return.
If the first number says how many you want to skip, and the second being how many rows you want to return, then 1,1 would be (Skip 1, take 1) giving you the second (Correct) but 2,1 should be (Skip 2, take 1) giving you the third result - Not the second

glad badger
glad badger
#

I've updated the question to reflect this: What is the flag after completing level two? (and moving to level 3) πŸ™‚ @uncut wagon

uncut wagon
livid escarpBOT
#

Gave +1 Rep to @glad badger

glad badger
vague salmon
#

Cross-site Scripting problem appeared again; in Task 7; copy and paste the code in the key logger and put it in the stored XXS, web site goes down? any idea ?

tough flax
#

Hello,
in uploadvulns room, websites don't work while I can connect to thm's servers without worries

eternal summit
#

What issue/error are you getting?

tough flax
#

When I try ping, I don't receive any response

spring mauve
#

Hi, I am working on the room "walking an application". I found 2 flags more, but I can't find questions regarding to more flags. Is it intentional? Thanks.

bleak beacon
#

hello, on Linux Fundamentals Part 1 task 5 third question "
What is the contents of this file?". the solution input accepted the last variable as 1 rather than !

signal citrus
#

yes, there are some that accept your input and mark it as correct answer even though you may have some typo @bleak beacon

frozen sun
#

Hello, the new honey-pot intro room has a broken question in Task6, question 1

#

When asking for the CPU type, it does not accept the output of lscpu or cat/proc/cpuinfo, although I see some similarity in the expected pattern of answer.

rapid hawk
slender grail
#

i think there is a bug in introduction to web hacking module. I didn't finish sqlinjection room but i received a badge for finishing introduction to web hacking module.

rapid hawk
#

Did you finish the last module of the room?

slender grail
#

last room in the module is sql injection.

rapid hawk
#

Yea. Thats a known issue.

frail halo
#

Does anyone know the user of "Polomints"? I'm hitting https://tryhackme.com/room/johntheripper0 Task 8 and the modifier "c - Capitalises the character positionally" should probably read "c capitalize" like the JTR wiki or "c - Capitalise the first letter"

rapid hawk
#

im confused as to what youre asking

frail halo
#

There's a line that's repeated in the room where the modifier 'c' is described twice.

#

The first time is "c - Capitalises the character positionally" which I think is a bit confusing.

#

and the second time "Capitalise the first letter - c" makes more sense.

#

It's only a typo, but I thought the place to report it was here.

#

Also, are custom rules called by --rule or --rules? looking briefly at the help line, I can't find --rule, but can find --rules.

rapid hawk
#

its not a typo. c capitalizes a character based on the position that you place the c in. since the rule it lists is cAz... c is the first position do it will capitalize the first letter

frail halo
#

so how do you capitalize other letters?

rapid hawk
#

move the c to a different place in the rule lo

#

lol

#

actually, nvm. i went back to look and i think you are correct

#

pretty sure it should say capitalize the first letter both times

frail halo
#

Thanks - know who we msg to change it?

rapid hawk
#

idk, it might not be a bug lol. im reading through the rules syntax rn. hold on

#

ok, i dont believe its a bug. sorry lol. someone can correct me if im wrong but i believe if you were to do Azc it would take the word, add whatever characters you say and then capitalize the last letter. or something like cat

#

that*

#

i believe it is positional

frail halo
#

Thx for checking it out.

wheat fractal
#

owasp top 10 task 7 site not working

pine lily
#

people have issues with masterminds room.

they expect ssh credentials to connect. and there is no explanation about how to connect to the box.
i saw similar rooms with vnc, split view pops up as soon as it's ready.

https://tryhackme.com/room/mastermindsxlq

wheat fractal
#

split view pops up as soon as it's ready

That's what happen with Masterminds aswell

#

( at least, in my case )

stuck stirrup
livid escarpBOT
#

Gave +1 Rep to @stuck stirrup

elder crane
#

hii i am not able to suport the metasploit exploit name in nax challenge it is showing uncorrect anwser but it is correct i have exploited the same vuln to get a shell

wheat fractal
#

Hello .. I am trying to solve the USTON machine. I have credentials for the SVC-Kerb user, but can't find a way to continue. I have seen that the MS-SQL port should be open, but no ... Is it possible that the machine is failing?

steel talon
glad badger
gritty mason
#

i have two bugs that i wanted to mention but scrolling up it seems im not the only one having issues with the xssgi staff cookie payload and also USTOUN not having sql running. Thank you THM Staff for your help, much appreciated

gritty mason
#

I was able to get the xssgi staff cookie to fire using the AttackBox but not through the openvpn but USTOUN is still a thorn in my side πŸ™‚

glad badger
livid escarpBOT
#

Gave +1 Rep to @steel talon

hazy tiger
#

https://tryhackme.com/room/introtolan ( @dusky junco )
Task 3 (at the top)
Bug type: Grammatical Error

Incorrect sentence: the ARP protocol or Address Resolution Protocol for short
What it should be: the Address Resolution Protocol protocol or ARP for short

Screenshot:

sonic willow
#

you sure jabba πŸ€”

#

i wouldb suggest ygetting rid of the and prot9ocol

#

qait no chaning the sentence to the Addres Reaoltuon Protocl or ARP for ahort

#

sory for the typos

north gyro
#

Room: Passive Reconnaissance
Task 6 Question 1 is confusing, perhaps Which country in the world has the second most apache servers?

hollow star
livid escarpBOT
#

Gave +1 Rep to @north gyro

fading idol
#

Task 35 Wreath, I think it should be spelled as order

craggy igloo
#

Linux Fundamentals Part 1
Task 4
Question 2

I started a Machine and used the AttackBox option.
Opening the terminal and using the command whoami, the returned user is root.
However the question expects the tryhackme user.

fading idol
#

You should have a comma instead of a full stop.

dusky junco
craggy igloo
livid escarpBOT
#

Gave +1 Rep to @dusky junco

vague salmon
#

Room steelmountain , in Task 3; I got an error after PowerUp.ps1 script , any advice ?

wheat fractal
lone wind
#

the Yara room is pretty much broken, you cant correctly install the tool due to bugs and issues

hazy tiger
#

Room link, task, screenshots, explanation

void vortex
#

New Room: Net Sec Challenge. https://tryhackme.com/room/netsecchallenge
Is the chance of being detected supposed to increase while nothing is happening? You can just watch it increase to 100% without initiating a scan.

glad badger
void vortex
#

Thank you.

lyric walrus
#

Regarding the netsecchallenge room

#

It seems it doesnt give points

#

@glad badger Is That Intended? I see point being Made in the room (30 points per answer) but they dont add up to my global score

glad badger
lyric walrus
#

:(

#

@glad badger they'll eventually are up once released?

#

Or are they lost points if i do it Now?

#

Also, it seems i experience the same issue as @void vortex

#

No matter what the scan is or of i dont scan at all, the counter Will still go up no flag appears after the scan is complete

void vortex
#

I was just going to wait until they created a discord room to discuss it there. It's apparently intended. I didn't mean to jump the gun on a room that wasn't released yet.

glad badger
#

And think about which scan "uses the least" when it comes to being identifiable when it sends probe packets. πŸ˜„

lyric walrus
#

Ok, but the point is that the counter goes up even of i dont scan it , 1 minute is enough to go to 50%. It my scan takes more than 1 minute the counter would go over 50%

#

Ill try

vague salmon
#

Room steelmountain , in Task 3; I got an error after PowerUp.ps1 script , any advice ?
PS > . .\PowerUp.ps1

jovial karma
#

hello i am trying to solve a room called upload vulnerabilities, in the last i am needed to do client side filtering but when i click response to server it doesn't shows me the request the name of page is /assets/js/upload.js

#

instead its showing me this

#

pls ping me

alpine spindle
#

hello i am trying to solve a room called upload vulnerabilities, in the last i am needed to do client side filtering but when i click response to server it doesn't shows me the request the name of page is /assets/js/upload.js
instead its showing me this

jovial karma
#

i think the rooms is buged

#

@dusky junco

vague salmon
rapid hawk
# jovial karma

Burp suite dosent intercept external Javascriot files by default. Theres a setting somewhere to enable it, I don't remember where tho

eternal summit
#

-warn @alpine spindle Stop copying user's messages and sending them again. It's spam.

livid escarpBOT
#

⚠ Warned sensenboy#7203

frozen sun
#

Hi! The new user room Challenge on Network Services has a bug for me, where the % chance of being detected goes up while not running any scan whatsoever

#

I have confirmed this with another user

frozen sun
#

Or is stuck hard fast at 0% and doesn’t work (the button to rest count also doesn’t tripped a pop up) with my local VM(latest kali)

wheat fractal
#

although i have the issue of not being able to run a scan stealthy enough to not hit 100%

#

actually, i just ran the machine and got 68% instantly - no scans. maybe it is a bug

sinful rivet
#

The windows10privesc machine is shutting down well before expiration, and the stopped machine isn't reflected in the UI. It's been frustrating me because i couldn't figure out what was happening, I saw the actual shutdown process this time though. The UI shows 56m 11s left and a machine IP - so I've been thinking i had an active machine and was experience network issues. when in reality the machine is shut down 😦

gleaming shadow
#

@dusky junco that one might need licensing

sinful rivet
#

It is expired. I thought they only shutdown once every 24 hours though. Thanks for checking it.

kind fern
#

In the room Sysinternals, Task 1, Question 1, I think the year is wrong per the wiki.

gritty moth
#

linux fundamentals part 2, task 5 and task 6 have a couple screenshots / paragraphs in the wrong place

livid escarpBOT
#

Gave +1 Rep to @gritty moth

kind fern
frozen sun
wheat fractal
#

Yeah that's why I was after some info on the IDS. It's scan scope obviously goes beyond just the packets sent in nmap scans.

upper pumice
#

Hello, I have a problem : Room Burpsuite, Task 9, last question i can't submit the answer : it says undefined

vague salmon
#

Room Alfred , I am on Task 1, whateever way I tried nothing worked on sudo nc -nlvp 4448 screen remains unchanged, I am able to see the script Invoke-PowerShellTcp.ps1 when I check the browser access as IP.. I use └─$ /home/kali/.local/bin/updog -p 80 for my web server. I got stuck , any advice will be appreciated !

#

I suspect the script Invoke-PowerShellTcp.ps1

#

?

rapid hawk
#

What your asking is not very clear. Could you please clarify what you're stuck on?

#

Screen shots will also help us to figure it out quicker

eternal summit
#

Also this should really be in #room-help unless you're certain it's a bug.

rapid hawk
#

Oops Lol. I wasn't paying attention to the room

olive mulch
#

gatekeeper isnt working

#

i cant connect to the service with python and i need add -nv to connect with nc

eternal summit
olive mulch
#

i cant connect with gatekeeper service with my python script

#

is not my firsts buffer overflow room and i didnt got any problem

clever wadi
#

Redline VMs are missing the IOCs were supposed to find

sleek goblet
#

there is a bug in the room tmuxremux in task 5 (bug: question has been repeated)

wheat fractal
#

FFUF: is missing the favicon.ico on my try last night. not sure if this is known

wheat fractal
#

also the about.php is missing as well. room seems to be broken

sonic willow
sonic willow
obsidian kiln
#

There's a trick to it though 😁

wheat fractal
kind fern
#

Sysmon room - Task 6 - Hunting-LSASS.evtx is missing from the Practice folder.

wanton prawn
#

Hey guys, Im stuck on a room called internal, and im not sure if this is bug or anything, but what i have tried to do was to login to the wordpress and then this happens to it (The username and password are correct)

#

When you click the password you will be redirected to this domain:

obsidian kiln
wanton prawn
#

i did tho, and i saw the writeups for this room because i was stuck on this, they all did what i did tho but for some reason i cant access the website

#

what do you suggest i should do?

obsidian kiln
#

Read the task information

wanton prawn
#

ohh right got it! thanks tho!

obsidian kiln
#

Np

wheat fractal
obsidian kiln
#

Pardon?

astral anvil
#

rip hackback events

wheat fractal
#

pickle rick writeup on wrong room

#

nevermind, task 17 is pickle rick

obsidian kiln
#

Uh huh

urban mural
#

bof1 room has some typos and errors that make a complex topic even more annoying to start in :/ and as a result, the actual correct answer for task 4 is considered wrong because the author didn't proofread.

wheat fractal
#

Django room: Website won't load and ssh is timing out. restarting the machine won't help. vpn connection is working.

thick stone
#

Hi, this isn't a direct Bug, but is it possible that the red marked part should say "How to test for Stored XSS"?

exotic mason
stuck stirrup
livid escarpBOT
#

Gave +1 Rep to @sonic willow

stuck stirrup
frail halo
#

task 6: scripting

#

The answer is actually wrong - there are 11 ports 130-140 inclusive, the answer is not actually 11.

bitter zinc
#

Room https://tryhackme.com/room/rrootme
Probably a non issue, but in /var/www/html there is a website.zip file which is a replica of the website, in the panel folder and in index.php there is an old flag from hackIT in there

bleak glade
#

In NetworkServices Room, Task-6 Telnet Deployed machine doesn't give any ports as open!
I m using nmap <ipaddress>

eager quartz
#

Even after several restarts I cannot connect to the Kubernetes cluster (e.g. "The connection to the server 10.10.224.50:6443 was refused"). I can ping the server but port 6443 is never open. Am I doing something wrong or is there a technical issue?

eternal summit
#

This is not a bug, you're just not looking in the right place. I think the room tells you to scan all ports?

bleak glade
#

Ok thank you Ninja

north gyro
obsidian kiln
#

@glad badger another one for you ^^ :)

silk trellis
#

Hello, we have problems on the room Linux PrivEsc ( Linprivec), Task 6 :

subtle harbor
#

Room Linux PrivEsc (linprivesc), Task 10 Q1:
root@ip-10-10-245-47:/# echo $PATH
/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/usr/local/games:/snap/bin
No odd path found in PATH matching given pattern.
expected answer: ||/home/matt||

eternal summit
subtle harbor
#

$PATH in original shell

shadow snow
#

find / -writable 2>/dev/null

keen niche
eternal summit
#

I didn't say they weren't, they provided more evidence

narrow mountain
#

Hi, I'm in the room https://tryhackme.com/room/django Task 5. I've started the machine and try to browse the IP from the machine with my AttackBox and get the error message "DisallowedHost at / - Invalid HTTP_HOST Header: 'IP from the started Box'. You may need to add 'IP from the started Box' to ALLOWED_HOSTS." I'm pretty sure it isn't part of the challenge.

#

I can also post a screenshot with the IPs if this helps.

narrow mountain
#

It's the same with the "Web Kali Box", and remains even when I restart the CTF Machine.

wheat fractal
#

Bastion v1.5: machine won't load website on port 80 so Task 13 is unsolvable. Room name is Burp Suite: The Basics. Title of the machine is Bastion v1.5

wheat fractal
#

ok. i will dig into it again. nmap scan works. also the site on port 9999 is there

#

port 80 times out

#

ok so my protonvpn connection is somehow interfering with the local hosted websites on the THM machines. not sure why at the moment

eternal summit
#

VPN inside a VPN never goes well

wheat fractal
obtuse musk
#

Hi there πŸ™‚
Not sure if this is a room or a site bug, but I'm sure the tag "linux" at a room about Windows Privesc ist not correct..

obsidian kiln
wheat fractal
#

sry for the trouble

obsidian kiln
#

Np πŸ™‚

glad badger
livid escarpBOT
#

Gave +1 Rep to @obtuse musk

stuck stirrup
livid escarpBOT
#

Gave +1 Rep to @subtle harbor

vast cloak
#

At the Cross-site Scripting room in the new path , The machine in the last challenge (Practical Example (Blind XSS)) gives out a 504 and even after restarting it multiple times I am still unable to reconnect

lone wind
#

discord bot still has "You now have the lucky title! Congrats!"

#

not pentester

dusky junco
lone wind
#

bug hunter now?! 😏

dusky junco
#

hehehe that's only for 3x valid site bugs @lone wind πŸ˜„

dusky junco
#

No it's "bug" with the discord bot which is community managed technically

lone wind
#

oh

#

okay

dusky junco
#

yes bruvva sorry

obsidian kiln
#

Like, bugs that would get a bug bounty

dusky junco
#

yes hence valid site bugs

obsidian kiln
#

Yeah, but I can point to a dozen things that don't work on the site but that aren't security bugs πŸ˜†

dusky junco
#

oh well yeah

#

hopefully the context gave that away but good point πŸ˜„

river timber
#

Hey hey. I reported feedback on the site already but posting here too. In the β€˜Walking an Application’ room in the β€˜Developer Tools - Debugger’ section, it says that, β€œIn Firefox and Safari, this feature is called Debugger, but in Google Chrome, it’s called Sources.” I was using Safari 15.0 and at least in that version, Safari is also calling the feature β€˜Sources’.

nimble locust
#

not a bug but a small suggestion, in pentestingfundamentals task 2 it has the following texts in the 'hat category' tables:

These guys use their skills to benefit others often; however, they do not respect/follow the law or ethical standards at all times.

& 

These guys are criminals and often seek to damage organisations or gain some form of financial benefit at the cost of others. 

'guys' in this context is not really gender neutral like 'hey guys' I think?

#

the rest of the room avoids appointing gender very nicely πŸ˜„

obsidian kiln
#

Also very colloquial

dusky junco
livid escarpBOT
#

Gave +1 Rep to @nimble locust

nimble locust
livid escarpBOT
#

Gave +1 Rep to @dusky junco

dusky junco
#

I say "guys" very much collectively but of course that is not clear unless you know my colloquialisms πŸ˜„

nimble locust
#

It's obvious you put effort into it throughout the rest of the room :)blobheart I catch myself on this kind of language too sometimes, habits can be persistent haha

dusky junco
#

They certainly can hehe -- I do try my best for that. But yeah, no real excuse, thanks again for reporting ❀️ πŸ˜„

weak gate
#

sysinternals room can't turn on network discoveries. it simply remains set "turn off network discoveries" inNetwork sharing center > advanced sharing settings. DNS service is running and is on automatic but Function Discovery Resource Publication, SSDP Discovery, and UPnP Device Host are not. I turned them on and made mode on automatic and i resolved the problem. This was quite irritating ngl

lone wind
#

hey uh

#

btw

#

the pentester role replaces my level role

#

intended?

dusky junco
#

answered in #general but for others: yes it is intended

#

you will return to your old level after the event

fringe thistle
#

https://tryhackme.com/room/vulnerabilitycapstone, Task 2, Last Question, There are two exploits about remote code execution (at exploit db) and both of them give errors like traceback calls, I tried to fix python version but it seems like it's written in py2 because of raw_input and no () print command, but then urllib gave error, I have seen at stackoverflow that urllib seperated the lib to three main parts in py3 so I have changed the import command to something like this from urllib import parse and then used parse.quote rather than urllib.quote but then server refused to connect... @glad badger

heady pebble
#

Not a bug really, but I think there's an incorrect answer? In the Kenobi room, task 3, question 2. I believe the answer is supposed to be 3, but it says the correct answer is 4. Maybe I'm just not understanding the search results properly?

crimson apex
valid chasm
#

i am stuck too on task 9, linprivesc, seems to not run

#

maybe we are missing something?

supple plover
#

I guessed the answer for that one based on the directories present on the machine and the length of the answer.

#

But yes, the machine is not configured correctly.

lone wind
#

in most of the new rooms, MACHINE_IP is bugged and doesnt change after your machine is started

obsidian kiln
#

Or code blocks?

lone wind
obsidian kiln
#

Plain text not working is a concern

#

Example?

lone wind
#

Try ssh mark@machine_ip

#

but not in a code block

obsidian kiln
#

Which room...

raven turtle
obsidian kiln
#

Well that helps πŸ˜†

raven turtle
#

huh?

obsidian kiln
#

You answered the question

raven turtle
#

Oh, wasnt paying attention to the previous guy :)

obsidian kiln
#

Can you screenshot?

#

Can't seem to replicate

raven turtle
obsidian kiln
#

Hm. Which task is that?

raven turtle
#

task 8, same with task 7 though

#

previous rooms showed the ip with dashes though iirc

obsidian kiln
#

How odd

#

Worked for me

#

Huh

raven turtle
#

"works on my machine" :)

obsidian kiln
#

Yeah, but it clearly hasn't for you. How odd

raven turtle
#

oh even better, now it works for me too and i cant replicate it anymore

#

managed to replicate it again, repeated the same steps, cant replicate it anymore... ?????

#

figured out how to replicate it:
start machine 1 (task 7)
ip is shown with dashes
terminate machine 1, start machine 2 (task 8)
ip is shown with dots

obsidian kiln
#

Interesting

#

@lucid oasis that'll be a "you" thing

proper jasper
#

nevermind just realised it wants the dir not the full path

lucid oasis
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

pine lily
fast prawn
shy canopy
#

is nyone having any issues with the new path? i am in "walking a website" task 3. i have found a flag through default creds, but when i try to answer the question with the flag, its not being recognized....

vast cloak
#

At the Cross-site Scripting room in the new path , The machine in the last challenge (Practical Example (Blind XSS)) gives out a 504 and even after restarting it multiple times I am still unable to reconnect

shadow bison
#

Hi all , on the Jr Pen test path in the "Walking an application" task 3 "what is the framework flag" working ?

#

I think im putting in the right answer but it aint taking it πŸ˜„

rapid hawk
#

If it's not taking it you don't have the right answer

#

There's a flag you can find that isn't used till much later in the room

rapid hawk
#

No worries

sonic willow
obsidian kiln
#

Whilst we're at it, has that room been changed to not state that RFI is a relevant threat?

sonic willow
#

oh hello

obsidian kiln
#

Because last I saw, it failed absolutely miserably to mention that RFI hasn't been possible out of the box since 2014(?) and insinuates strongly that you don't need to go out of your way to explicitly make it unsafe.

#

Which is just blatantly misleading

sonic willow
#

yeah i remember in da oscp videos he mentioned you need to explicitly enable something in the php.ini i think for it to work

obsidian kiln
#

Mhm

#

I brought this up in room testers when it released

#

But nope. Still not fixed

#

πŸ€·β€β™‚οΈ

white grotto
#

Hey, In the new junior pentester path, there is 2 privesc rooms. The linux works really fine and the credentials are given in the room, but there is no user or password in the Windows room : https://tryhackme.com/room/winprivesc . Is this normal ? It seems rather complicated to get an entrypoint on this compared to its linux equivalent.

zealous magnet
#

Hello, I'm working on junior pentester path - walking an application room and I can't find the first flag (which is supposed to be in the comment section).

#

Ah i can't upload the screenshot

rapid hawk
#

So um, kind of a big bug I found with task 10 of the Linux privesc room...

#

The questions for that task are also wayyyyyyyy wayyyyy off from what the answers are. It asks for what the weird file in your PATH is when your PATH is the standard PATH. (The answer for this question is somehow|| /home/matt||). Then it asks what odd folder you have write access for, and somehow the answer is|| /home/murdoch|| even though you can't actually write ti that directory but rather a file within that directory

#

If I didn't look on the forum I would have absolutley no way of knowing how to answer those questions

obsidian kiln
#

@glad badger another one for you πŸ™‚

glad badger
livid escarpBOT
#

Gave +1 Rep to @rapid hawk

rapid hawk
#

Having another sleight issue, with task 11 in the same room. The code thats given for the exploit cannot be executed after compiling (at least, that's how it is for me) I copied it exactly, I tired making changes, been playing with it for an hour and it won't run no matter what I do

#
bash: ./exploit: cannot execute binary file: Exec format error
dense garnet
#

Dos2unix on the file

#

Nvm

obsidian kiln
dense garnet
#

It’s a binary lol

dense garnet
obsidian kiln
#

Yeaaaaaaaaap

dense garnet
#

Maybe try to compile it on the target machine?

rapid hawk
#

Lemme try that

dense garnet
#

Usually the rooms have no gcc tho

#

Did you download a precompiled version or did you compile it?

rapid hawk
#

I've exhausted my knowledge of C. I don't know what else to do with this one

dense garnet
#

Wait is it a file you made yourself?

#

What room is it?

rapid hawk
#

Task 11 of the Linux privesc room

#

The NFS one

dense garnet
#

Oh shoot I haven’t gotten around to that

rapid hawk
#

Ah

dense garnet
#

Is the exploit code from github?

#

Are both your system and the target system the same arch?

rapid hawk
dense garnet