#room-bugs

1 messages · Page 29 of 1

obsidian kiln
#

That room is deprecated, so yes, it is working with an outdated version of metasploit 🙂

polar flare
kindred hull
#

Pyramid of Pain Task 3: Is this supposed to say "adversary"?

#

Also, same room, task 5, I think the last two questions in that task were copied and pasted incorrectly? The both ask for the document name even though one is asking for the dropped binary, and the other is asking for the document

torpid otter
#

Windows Internals: In Task 7 there is maybe a bug I execute the inject-poc.exe and get a flag but the answer is everytime wrong ?

#

Or did I do something wrong ?

mint drift
#

Hello every one, i blocked on the Linux PrivEsc room on the Task 9, cronjob related task, it's seems like cron don't execute the scripts ..
https://tryhackme.com/room/linprivesc

mint drift
#

can i dm someone ? will i waiting for responses, i found out an other way to get the flag, and that not the purpose of the task 9 .. so i don't know if i'm going wrong here

dense garnet
solar drum
#

@queen sphinx

dusky junco
#

-ban 371488617949822978 -ddays 1 Game scam campaign

livid escarpBOT
#

🔨 Banned Yun#4421 indefinitely

surreal siren
#

So Im in the Buffer Overflow room and I'm pretty sure I have the right answer for Task 10 but the answer checker says its wrong. mona gives me this "\x00\x04\x3e\xe1"

#

nevermind

dusk veldt
#

There is an issue in task 8

#

Nax ctf medium

#

What is the full path for the exploitation module ?

#

I have submitted ans { exploit/Linux/http/nagios_xi_authenticated_rce }

lone viper
#

Same for Task 4 - Question 2

median coral
#

@dusk veldt

dusk veldt
livid escarpBOT
#

Gave +1 Rep to @median coral

muted mist
#

I'm currently doing the Post exploitation room and I'm not even able to complete one entire task as the Box keeps reconnecting every minute or the other. I'm using Remmina for RDP Access. Can someone help me out on this?

foggy cargo
#

My problem is not for a specific room...but i think it's ok to mention it. I've experienced the same problem with other PCs too. So, I usually extend my time when a deployed machine starts. And after about 1 hour...i get a notification that the machine is terminated(It's not actually terminated). But there's still 1 hour left? When i refresh the page the machine options show but it's kinda annoying.

eternal summit
foggy cargo
#

Oh

#

Why does that happen tho?

eternal summit
#

It's a bug, a programming error.

fading warren
#

Don't know if it's a bug, but in the kibana room (https://tryhackme.com/room/kiba) if I leave my reverse shell and try to launch it back from the web interface, it doesn't give me back the reverse shell and I need to reload the room.

split pier
#

Good morning everyone,
I was going through the Linux Fundamentals 2 room in TryHackMe https://tryhackme.com/room/linuxfundamentalspart2 and I noticed under Permissions 101 there is this Comment of switching User, which I think it has come there by some error as in the YouTube Video that is linked, there is a Diagram of permissions, can any one look into that?

#

Screenshot of the Video

astral anvil
#

Happens a fair bit and very little will be done about it

modern raven
#

The image in the video would make more sense at that point, because it goes over the permissions and that part explains permissions, switching users comes later in that task and has the same picture again on how to switch to user2

modern raven
wheat fractal
#

@dusky junco @eternal summit

honest oak
#

hi, i can't access the chajoh user in the Osiris room can someone check if is a bug or not??

dusky junco
#

Also good morning

wheat fractal
dusky junco
#

Ah cool cool

#

Wasn’t sure if that was the one that fluff got or not

#

Thanks for the ping!

honest oak
#

the chajoh user did not appear when i run 'net user' as authority\system

#

I do everything exactly the same as the writeups to get the third flag and the last step is to login as chajoh and get the flag

median coral
#

@dense garnet sounds like you had the same issue as this person ^

dense garnet
median coral
#

👀

honest oak
# dense garnet Already helped him in DMs yesterday.

yes you help me get the tool i need for the room but i haven't realized i can't login as that user, i did try and fail but i thought i was being dumb and sorry for the late response, if it's late night your timezone sorry for bothering

dense garnet
honest oak
dense garnet
honest oak
#

I finished about 90% just need to login as chajoh and get the flag

dense garnet
dense garnet
honest oak
dense garnet
#

you are SYSTEM

honest oak
#

after that i have to login as chajoh to open keepass without the password

dense garnet
honest oak
#

yeah i just want to finish the WindCorp Series

honest oak
livid escarpBOT
#

Gave +1 Rep to @dense garnet

mental compass
mental compass
honest oak
pearl socket
#

Hi
The Yara room -> https://tryhackme.com/room/yara
Task 6
6.3. Combining keywords
In this example where $txt_file = ".txt", it checks the string inside the file not the extension, and I tried it in practice to make sure, and yes it is not working with file extension it works with only the text inside.

vocal ginkgo
eternal summit
#

It should give up and use a backup font

vocal ginkgo
livid escarpBOT
#

Gave +1 Rep to @eternal summit

brittle crypt
#

Month later, same issue.

knotty elm
#

Just going backwards and refreshing my mind on a few topics and noticed that the IntroToNetworking - WHOIS question about Facebook is out of date; "Which city is the registrant based in?". Based on the current whois it does not work.

obsidian kiln
#

Pretty sure it tells you to switch domain

eternal summit
obsidian kiln
eternal summit
knotty elm
#

Im big enough to apologize for misreading. There's no need for snark.

eternal summit
knotty elm
#

Understood

obsidian kiln
knotty elm
#

All good.

#

Thanks for the info, I will make sure to read the question thoroughly next time I have one I feel is possibly a bug.

short dragon
#

hey room cross site scripting Task7 level 2 doesn't work i think script is never launch, it's normal ?

pearl chasm
#

In the " Hands-On Lab " section in this room: https://tryhackme.com/room/activedirectorybasics there is a link to a powerview cheat sheet. However this is the cheat sheet for PowerView 3.0. And the powerview version in the room is 2.0 so none of the commands in the cheat sheet work.

The current link: https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993 (these commands do not work in the room)
The link (I think) it should be: https://gist.github.com/HarmJ0y/3328d954607d71362e3c (these commands do work in the room)

hexed wagon
#

on this lesson: https://tryhackme.com/room/authenticationbypass, in Task 2 "Username enumeration", when they start explaining what the flags mean, when they get to -d there is one typo. "The -d argument specifies the data that we are going to send. In our example, we have the fields username, email, password and cpassword. " cpassword -> password

grave grove
glad badger
plucky void
#

Room - intro to pwntools: ASLR is enabled, is it intentional?

teal basalt
#

IIRC, you should be able to run a script with sudo
Check sudo -l 🤔

livid escarpBOT
#

Gave +1 Rep to @teal basalt

modern raven
#

In hacking with powershell https://tryhackme.com/room/powershell task 4 What is the path of the scheduled task called new-sched-task? The accepted answer is / when the path is actually \

cobalt ivy
#

I am currently working on Compia Pentest+ > Nmap and on task 14 I had to actually scan the first 10000 ports on target as 5000 didn't show any ports.
Just thought I should mention it here.

blissful vector
#

OWASP juice room... not sure why I'm not getting any flags for successful xss Task 7. Tried all three. Got the first two to work but not the third (I think? I mean... maybe not sure about the third one)

#

what I mean is. no popping flags for 7.1 and 7.2 tasks even if successful. 7.3 questionable cause not sure I did it right

#

❤️

wheat fractal
#

Hi, i think there is a bug in task 4 exploiting SMB of room Network services. I can't access doing smbclient //[IP]/profiles, they ask me for a password. Or there should be no password. I am stuck and i don't understand why it doesn't work so i think it is a bug

dense garnet
teal basalt
#

1-5000 isn't first 10000 ports👀

cobalt ivy
cobalt ivy
dense garnet
cobalt ivy
dense garnet
#

@queen sphinx @gleaming shadow

eternal summit
#

-ban @wheat fractal -ddays 1 Game phishing. Secure your account and then appeal this ban by emailing bans@tryhackme.com.

livid escarpBOT
#

🔨 Banned mk16#4352 indefinitely

gleaming shadow
#

looks like James got it

eternal summit
#

@dense garnet got em

dense garnet
grim turret
#

Hi, im having trouble answering the first question in task 5 of File Inclusion Local File Inclusion - LFI #2, the "correct answer button" is not working, is it working for some of you? i would like to know if im the one getting error or the room has bugs, thanks for the help

wheat fractal
cobalt ivy
dense garnet
blissful vector
#

Really looking forward to 100% juice room (not just the tasks). Tested and xss still down :3 uh… no rush.. just excited

woeful warren
#

Anyone else not seing any outcome of the data collection in the redline room? Have tried several times, from scratch, but it never generates the .mans :)

wind sedge
#

Evening! Having trouble with Investigating Windows #3, at the last module in the stack question. I'm entering the good value (<********) but it doesn't seems to work. 😦

median coral
wind sedge
#

yep

#

i checked for encoding, copy paste from procmon, changed machine in case something was wrong

#

no bueno

wind sedge
#

seven characters, in between a < and >

median coral
#

tried switching browsers .etc.?

wind sedge
#

yep

#

even tried.. edge.

median coral
#

then, it might be a room bug, cause it accepts for me

#

can you provide a clearer gif?

eternal summit
wind sedge
#

Uh Oh! Your Answer if Incorrect

wind sedge
median coral
wind sedge
#

making another one right now

median coral
#

prolly best to hide the other answers, I guess

wind sedge
#

should be clearer/hidden other answers

median coral
#

that's the wrong question,

wind sedge
#

arf, deleted the wrong div

median coral
#

cc @hazy hinge "Investigating windows 3", 3rd question from the end, correct answer is not supported for some reason

wind sedge
#

i have to get my kids off daycare now. but ping me if you need anything else and i'll come back to you whenever i get back on my pc

gaunt wadi
#

25daysofchristmas (advent of cyber 1 2019) Day 9 requests asks to connect to 10.10.169.100 port 3000

#

port is filtered and cannot access, can ping the ip though

dense garnet
#

Took me like 12hrs overall

median coral
dense garnet
eternal summit
#

@wheat fractal Are you ok?

wheat fractal
#

yeah, sorry, is there requirements on posting bugs?

eternal summit
#

Make sure it's actually a bug first, preferably by checking in #room-help that it's not user error
Then post enough detail about it

wheat fractal
#

Yeah, some experienced people checked and told that it's a bug

#

https://tryhackme.com/room/rpwebscanning

Task 3 - Question 8 (4 from bottom):
Featured in various rooms on TryHackMe, Cross-Site Scripting is a vicious attack that is becoming ever more common on the open web. What Alert does ZAP produce to let us know that this site is vulnerable to XSS? Note, there are often a couple warnings produced for this, look for one more so directly related to the web client.

Looks like new OWASP Zap versions can't find XSS vulnerability.
1 -> It should have "Web Browser XSS Protection Not Enabled" alert.
2 -> But it doesn't.

eternal summit
#

That room is no longer maintained

wheat fractal
eternal summit
#

Really you can't

wheat fractal
#

ok

shrewd shell
#

In room
https://tryhackme.com/room/windowseventlogs

task4 : question 3
they mention to check the example 7 ,
but in the website (https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.diagnostics/Get-WinEvent?view=powershell-7.1) its example 8 .

lime furnace
#

/room/linuxstrengthtraining

dusky junco
#

@glad badger one for y'all ^ (:

lone viper
#

Can't get a response back using nc OR 10.10.10.100 on task 8 of Cross Site Scripting room.

glad badger
blissful vector
#

Ok got the reason the OWASP juice xss wasn’t popping.. very specific quotations are needed.. so even if xss successful, have to use the walkthrough quotes.. :3 I’m just happy it works now lol

rotund lava
#

Currently working through the "Buffer Overflow Prep" room. I noticed the target machine count down timer isn't working correctly. The hour portion of the timer doesn't count down.

lime furnace
median coral
wind sedge
#

make sense :/

#

Thanks for the followup!

merry delta
#

Hello guys, i have a bug during on my exploit (with metasploit) on BLUE room, same error with after reboot VM target

median coral
#

!dark

tropic flameBOT
#
DarkStar7471
Very carefully, next question.
median coral
#

if you can show your errors or show options in #room-help someone will help :)

merry delta
#

Oh okay thanks for you return, and last question sorry how have you role ?

tropic flameBOT
merry delta
#

Thanks a lot 🙂
Have a nice day guys

median coral
#

🙂

wheat fractal
#

Knowing Blue, they might not have set the lhost.

median coral
#

most likely

median coral
#

uhh, @queen sphinx

queen sphinx
median coral
#

thought the bot deleted the messages automatically 🤔

#

when the're banned i.e.,

#

Oh, it's a -dday 1 difference, delete previous days messages, nice

dusky junco
#

-ban 832622412403179551 -ddays 1 no thanks. Sharing discord scam URLs. Ban appealrs are bans@tryhackme.com

livid escarpBOT
#

🔨 Banned mrjan#5445 indefinitely

median coral
wind sedge
livid escarpBOT
#

Gave +1 Rep to @median coral

clear summit
wheat fractal
dense garnet
#

I really think there should be a typo room, cause most bugs reported are just typos and could crowd up the channel and get actual bugs unnoticed.

obsidian kiln
#

Actual bugs get forwarded straight into a separate channel for QA

civic vector
#

Where should I report errors in rooms? It's a slight text error but confuses the student

dense garnet
obsidian kiln
#

That's already what happens 😆

dense garnet
dense garnet
#

Go to the hacker101 CTF thing and on top there should be a flag checker

#

And I’m pretty sure the Hard challenge is impossible, but I got it in a cheeky way, I managed to escape the docker containers and get to the host, and after that I just logged in to the docker containers from the host and got the flags haha

unreal bough
#

In the room Active Reconnaissance https://tryhackme.com/room/activerecon subroom Telnet. I tried running this on a up to date Kali Linux OS. I follow the instructions to connect to port 80 of the server instance with telnet with the commands: telnet 10.10.242.116 80 then I tried to get the banner with GET / HTTP/1.1 the response I get is that the server pauses for a minute and then closes. I have provided a picture of what the server response with below.

modern raven
unreal bough
#

I don't know if it's meant to time me out as fast as it does but I have about 3 seconds before it times out

modern raven
#

It's not suppose to stay open long, but also what is that ip you are connecting, because that doesn't look like thm machine ip? And maybe it would be better to move to the room help instead

unreal bough
livid escarpBOT
#

Gave +1 Rep to @modern raven

glad badger
#

We're looking into this. 🙂

glad badger
#

Room has been made private. 🙂

livid escarpBOT
#

Gave +1 Rep to @glad badger

proud turret
#

Anyone else having an issue with the OWASP Juice Shop Room, Task 7 Question 2 'Perform persistent xss'?

blissful vector
#

I got the answer :3

#

So don’t type it.. copy the task fed insert

proud turret
#

using the box or openvpn?

blissful vector
#

Because the ‘ is different

proud turret
#

I know

#

I tweeked it and got the XSS to be persistent, but no flag

blissful vector
#

They specifically want the slanted ‘ not just a typed one. Oh ok you know haha that’s what was not working for me

#

Yeah it wouldn’t give me the flag if I typed the xss myself even if xss worked.

#

Sorry then I guess you have a different issue than I did. I had to literally copy it over to the attack box to make sure the character ascii was what they wanted

proud turret
#

How did you make that character?

blissful vector
#

I copied it CTRL+C

#

Didn’t bother looking up the hex

proud turret
#

lol

#

k

blissful vector
#

Or the ascii code. Just copy… as if you don’t know what you’re doing and copying every fed code they give

proud turret
#

You used the Attack Box?

blissful vector
#

Pretend you can’t type :3

#

Yeah

#

This happens in some ctfs when they save to things like Word.. the program is “smart” and will recode your character

proud turret
#

Ok, I am trying it now thanks

blissful vector
#

Np! Hope it works out

#

A way to fix this I think is to redo the answer accept to multiple quote types… but not sure how difficult it would be :<

proud turret
blissful vector
#

Ohhh interesting :3

proud turret
blissful vector
livid escarpBOT
#

Gave +1 Rep to @eternal summit

blissful vector
eternal summit
teal basalt
#

@MuirlandOracle#2721 have a look ^

obsidian kiln
wheat fractal
#

Who did you get to proof read it? kekw

sonic willow
#

tbf reading in your head those types of mistakes are very hard to spot

obsidian kiln
#

Tbf, it hasn't officially gone through QA yet -- Skidy wanted it pushed out ASAP, so I was kinda doing it blind

#

Just got Robert to unofficially take a look at it. In fairness to him, task 2 didn't exist last night

wheat fractal
#

I was joking,

glad badger
glad badger
#

The real attainable metric of course had to come from NASA, with sneaky language: Faster, Better, Cheaper. The wording shows more attainable measures in that it focuses on improving all three simultaneously, instead of demanding all three at the max from the start. 😎

main elbow
#

Wonderland stops responding to anything every 3 minutes. I tried restarting the machine nothing changed.

eternal summit
main elbow
#

i realized there was two instances of openvpn (username).ovpn that was probably the reason

obsidian kiln
#

Yeah, that would do it 🙂

misty cave
balmy cobalt
#

... I'm an idiot, I just saw what went wrong 😄

teal basalt
#

The command output given in the room may be an example. And you are tryhackme user in your screenshot, so it's home directory is /home/tryhackme and not /home/ubuntu (it could be this, but it isn't)

balmy cobalt
#

Yeah, i just noticed. Guess I'll complete this room and go to bed.

mossy basin
#

Hello. I recently finished ZTH: Web 2 on the web fundamentals path. I was having a hard time finishing section 2 forced browsing automatic exploitation as wfuzz was throwing errors at me left and right even after installing and reinstalling it.

#

Anyways

#

This was the error that it was throwing at me
I had to manually nano into the wfuzz and change this

#

I changed the interpreter from python3 to python2 and it worked. Just a heads up as it was frustrating as I thought I was doing something wrong for a long time.

#

Moreover, this isn't really a bug but something that took me a long time to realise as I was already frustrated from wfuzz not working. When I use the machine IP address and go to the website in task 6 the pictures in the task are a bit misguiding as paradox(the room creator) uses the directory localhost/noot/note.txt to retrieve the txt file and they have to change the user to admin to get the flag. Although in the actual attackbox when typed IPADDRESS/admin/note.txt it redirects to a 404 page not found. Instead its goes through a GET request note.php?note=1 for noot and ?note=0 for admin. This is important as in the next task, task 7 when using wfuzz I thought I had to enumerate the numbers and got very confused as I was not getting anything back. Instead I had to use the MACHINEIP:81:/FUZZ/note.txt. I honestly am not sure if I'm just stupid or overacting but yea Its just something that confused me a lot as the pictures on the tasks were diffrent than what I had to do on my own attackbox. 🙂 sorry for the rant

jade flax
#

Yup, yet another room expecting incorrect answers. This one has been sitting for over 7 months since it was first called out @hazy hinge

dry epoch
#

I believe I found a bug in the Linux PrivEsc room Task 11 machine. After I compiler my code and I try to run it on the target machine I get a
"/lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by "
Error. I did a little googling and it seems to be an issue with the version of compiler I used on my machine and the target machine.

wheat fractal
#

the button to submit is missing from the redteam opsec room task 2 for me

glad badger
# wheat fractal

There's no button to submit, as soon as you have selected the correct items, the flag will appear. 🙂

mossy basin
#

OWASP Juice Shop in task four the provided location of best1050.txt is not in usr/share/passwords but in another directory.

zenith mortar
#

room: https://tryhackme.com/room/tshark

Task 3 question 4 & 5:
accepted string
MZWGCZ33ORUDC427NFZV65QBOVTWQX3XNF2GQMDVG5PXI43IGRZGWIL5 <- correect string

but actually decoding it in base32 return
flag{th1s_is_v.ugh_with0u7_tsh4rk!} <- is incorrect flag

wheat fractal
#

The flag is ||flag{th1s_is_tough_with0u7_tsh4rk!}||

#

No, they're not, lol

#

The string should be MZWGCZ33ORUDC427NFZV65DPOVTWQX3XNF2GQMDVG5PXI43IGRZGWIL5

zenith mortar
#

tshark -r dnsexfil.pcap | awk -F . '{print $8}' | awk '{print $9}' | tr -d '\n'

onyx glen
#

m,

wheat fractal
#

linux privesc room, task 10, user can't actually touch files in /home/user

#

workaround is to sudo nano, place a # and save file as required names

glad badger
livid escarpBOT
#

Gave +1 Rep to @inner dagger

eternal summit
#

-ban @rich bear -ddays 1 Github "NFT generator" phishing scam

livid escarpBOT
#

🔨 Banned ilanik#3664 indefinitely

wheat fractal
#

room/rpnessusredux: "Scanning!", "What Apache HTTP Server Version is reported by Nessus?" - expects 2.4.99 (which doesn't exist), the target VM reports Apache 2.4.25 (Debian) which can be seen both in Nessus and by manually connecting to port 80 and checling.

rugged canyon
obsidian kiln
rugged canyon
#

yuup sorry

#

missed that before shadow posted theirs.... hopefully shadow gave some more details that were helpful... if not feel free to remove

lavish zenith
#

@analog moth hello, in the room "file inclusion", the image descriptions could be corrected. It refers to the get command as the file name

eternal summit
lavish zenith
eternal summit
#

That's also a file name. But it's the the file you're requesting from the web server. It's a parameter for the php code that you're asking the server to run by requesting get.php

sly dock
#

in room/packetsframes where it comes to task 3, there is a closing conversation part, and Alice is using FIN/ACK to initiate closing the conversation, then bob replies with FIN/ACK and finally Alice with ACK... this is different than the description in step 2 where closing connection is starter with FIN, then replied with FIN/ACK and closed with ACK

lavish zenith
sly dock
#

solid evidence, forgot to verify myself earlier so I could post it

wheat fractal
#

Room nmap04 task 3, OS detection doesn't work for me if I follow the instruction "nmap -O TARGETIP". I have to add -sV to get OS detection working.

wheat fractal
valid chasm
#

A typo in room "dirtypipe", Generating a SHA412Crypt Hash should be Generating a SHA512Crypt Hash (in the terminal window title)

eternal summit
#

@obsidian kiln kekww you need more sleep I swear

obsidian kiln
#

I'm genuinely surprised there weren't more kekw

eternal summit
#

Exactly

obsidian kiln
#

Fixed. Thanks @valid chasm ♥️

livid escarpBOT
#

Gave +1 Rep to @valid chasm

valid chasm
#

Thanks @obsidian kiln

livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

dense garnet
valid chasm
#

Umm.. I dont think so :) just a few i think

vapid bison
#

linuxfundamentalspart2, is there a fix for this?
terminal says "incorrect password"

eternal summit
burnt axle
obsidian kiln
#

-ban @barren laurel -ddays 1 Nitro Scam -- compromised account

livid escarpBOT
#

🔨 Banned (っ◔◡◔)っ ♥ littlemarmaid ♥#6700 indefinitely

vagrant void
#

path was /usr/share/seclists/Usernames/top-usernames-shortlist.txt

took me waaaaay too long to figure that out

median coral
vagrant void
#

shouldn't it mention that then?

median coral
#

it's kinda assumed , I guess but yeh

#

¯_(ツ)_/¯

rough holly
#

i have a bug.

sonic willow
rough holly
#

just a bug or two

#

maybe a bed bugger.

sonic willow
rough holly
#

just a bug.

#

maybe a bit of lolling.

#

trolling ofc

eternal summit
hazy tiger
#

@gleaming shadow @icy elbow

gleaming shadow
#

Ugh, ok

#

-ban 375945273379258368 -ddays 1 it appears your account is compromised by a nitro scam, please change your password and add mfa before appealing at bans@tryhackme.com

livid escarpBOT
#

🔨 Banned Virtu#9780 indefinitely

muted bobcat
#

Hi !
In the Linux Fundamental 2 learning program, I am root in the attackbox.
Is it normal ?

muted bobcat
livid escarpBOT
#

Gave +1 Rep to @median coral

muted bobcat
median coral
median coral
#

then that's the attackbox, you're supposed to be root on it

muted bobcat
#

But I can acess to /Rooms folder, and I've no correct file to answer questions

median coral
muted bobcat
#

OKi, sorry for the inconvenience 😉

brave zenith
median coral
#

navigating to that might give you the flag

modern raven
median coral
brave zenith
#

I finished the room but its a bug

strong kelp
#

Still in the same room in task 8. this part is hard to read.

#

In the same task is this blank part:

lyric walrus
#

guys, this room is showing earned point when submitting flags but give 0 point on the total user score

#

do someone know if this is intended?

glad badger
lyric walrus
#

😦

#

why is it not public?

#

:((((

#

so another 500 point that i will never be able to do...

eternal summit
median coral
#

Good to know, thanks :)

bright portal
#

hey guys, really not sure if this is a bug or not.
I'm currently doing the XSS room (/room/xssgi) and I'm unable to get Task 8 to complete. I can verify I am getting my own call-back onto a python http server, however I'm not able to get the staff-session cookie that should theoretically be generated by the room.

I initially wasn't able to get my own session cookie until after I disabled the mixed content blocking in Firefox. I'm wondering if this is potentially a bug with the room, or if I'm just missing something lol.

bright portal
#

Already gave that a shot, I've tried using nc, python http.server, and the THM request catcher with a fresh machine booted up. None of these methods appear to be working.

silk python
#

Hey guys, I've just finished the Mindgames room (https://tryhackme.com/room/mindgames) and was able to root it via a totally different path as all the writeups are suggesting. So I'm not sure if it's intended that the box is also vulnerable for ||a 2021 CVE|| local privesc ?

real juniper
#

Hey uh, the https://tryhackme.com/room/internal machine is vulnerable to cve_2021_4032 and you can use the metasploit module cve_2021_4032_pwnkit_lpe_pkexec for instant privesc from www-data to root 😛

twilit bane
#

how 'bout that

dense garnet
manic atlas
#

?

lyric walrus
#

@silk python hello Kr1ss,

eternal summit
#

It's near impossible to update the boxes on THM without direct involvement from the THM staff, as a creator, so the only option is to reupload an updated copy. That kinda sucks, time and testing wise.

lyric walrus
#

well imo it's good@eternal summit, having old machines vulnerable to newer exploit feels more "real" and lets us test newly released cves

hazy tiger
lyric walrus
#

true@hazy tiger but still, a machine that was hard to hack irl 1 year ago but that hasnt been patched for log4shell and pwnkit is now an easy target isn't it?

#

the game on tryhackme is not fair and we know it, a lot of old machines are now retired

hazy tiger
#

Still not a learning opportunity 🙂

lyric walrus
#

it is

#

it only depends on how you approach it

#

people can still go out there and copy the flag froma walkthrough

#

it is up to you if you want to learn

hazy tiger
#

If we have dedicated rooms with those exploits, walkthrough and a challenge, you have room to practice.

Not limiting yourself to just TryHackMe, you should hopefully come across the exploits you learn about on here on other sites and you can expand your practical knowledge.

If it hasn’t been patched and you’re using the unpatched insta-root exploit, you’re not only cheating yourself but you’re not actually helping yourself in the real world.

Just because something has a probability of occurring, doesn’t mean that it is likely to occur.

#

Not having that option really helps motivate

lyric walrus
#

true, but what is thm going to do? patch all 500+ machines ?

#

i guess not

#

so, cheater will cheat

#

as we always see

#

(take a look at monthly hacker, most of them are 1-30 days accounts making 800+ events a day

hazy tiger
#

And most of them get their accounts reset

lyric walrus
#

well

#

first guy in switzerland is still first with 67k points

#

even though he surely cheated a lot

hazy tiger
#

I’m sorry, I’m looking for your report of them in the inbox

#

Don’t see it anywhere

#

Don’t complain if you’re not going to at least attempt to prevent

#

Even a message in the Discord is enough for one of the staff members to pick it up

lyric walrus
#

i mean, first i did not know you could report people, as i see it since i've been here (almost 2 years)

#

and second, you can see it in the monthly leaderbord

#

but ok

#

what does it look like?

hazy tiger
lyric walrus
#

well, i'd like to report this guy then

hazy tiger
#

Country leaderboards aren't monitored, only global.
You cannot get badges from country leaderboards, only the global one

lyric walrus
#

multiple occasions of 500+ events a day and on date 07 february 2022 he made 700+ events

hazy tiger
lyric walrus
#

i'll do so, thanks

hazy tiger
merry chasm
#

incorrect site version reported on the Pentest+ nessus room

#

both curl and nessus return 2.4.25, but the correct answer is apparently 2.4.99

#

sounds like this room is generally outdated and the scanning part is mostly broken, no?

split herald
#

hello on the Introductory Researching task 2 question 3 i know the answer but it keeps telling me i am wrong

#

can i write spoilers?

#

o ok ill do some more research sorry thanks for the time

#

o haha gee wizz

rugged canyon
#

break it ( https://tryhackme.com/room/breakit ) task 3: question 1: 2D 37 2B 19 31 99 31 B3 B2 AB A5 18 32 37 20 B3 B2 AC 2D 1A 31 B4 A1 3A A4 A3 9C B4 AD 36 AC 9E turn into this when using cyberchef with bitshifts and things:

#

which is not valid base64 but it is supposed to be

#

already solved it by trial and error with another tool but feel like this hex input is somehow wrong

glad badger
eternal summit
#

-ban @minor stump -ddays 1 NFT Game scam. Secure your account and appeal this ban by emailing bans@tryhackme.com

livid escarpBOT
#

🔨 Banned ~Jay~#9908 indefinitely

eternal summit
#

-ban @wheat fractal -ddays 1 Nitro Scam.

livid escarpBOT
#

🔨 Banned Tejaswi Pednekar#3832 indefinitely

lyric walrus
#

@glad badgeryeah, that's exactly what i was saying.

wheat fractal
#

https://tryhackme.com/room/intro2windows task 3, image explaining LDAP procedure, the text says "Lightweight Directory Authentication Protocol (LDAP)" but the acronym stands for Lightweight Directory Access Protocol

#

Do you guys even want these type of reports in here or is there a ticket system?

obsidian kiln
#

Here is perfect, thank you ♥️

wheat fractal
#

Ok I'll keep them coming when I see then 😉

obsidian kiln
#

@dusky junco one for you ^^^ :)

fading barn
#

got problem connecting on the Upload vuln Room. I did the modifications in the /etc/hosts but the website still telling me I didn't

fading barn
#

and I can't connect to the Linux Priv Esc Machine

#

ssh says it refuses the connection

loud veldt
#

hi - im in the Hydra room. I run hydra on the web host and got 16 correct user/pass combos. However, when I try to logon to retrieve the flag, it says they are incorrect

lyric walrus
#

@loud veldt can you paste your command?

#

when you get multiple logins it usually means you did something wrong and hydra interpret response as good while it's not.

median coral
lyric walrus
#

oh

median coral
lyric walrus
#

sorry

#

😉

median coral
#

🙂

fading barn
#

@vital vineyep

tropic flameBOT
sterile valley
#

Nice to meet you

uneven niche
#

Registrant Country has changed too. It's not Panama anymore it's Iceland

sterile valley
#

I don't quite understand what you're saying

uneven niche
#

If you lookup whois information it's different from what the information is given

sterile valley
#

Where are you from?

uneven niche
#

It's a room challenge.

uneven niche
sterile valley
#

@uneven nicheok thank you

livid escarpBOT
#

Gave +1 Rep to @uneven niche

dusk olive
#

I’m currently stuck with an Error I’m receiving in the Network Services course task 3.. I’m receiving the following..
(Error NT_STATUS_HOST_UNREACHABLE..

dusk olive
#

From the attack box when I perform the smbclient command

tropic flameBOT
dusk olive
teal basalt
# dusk olive

It might not be 10.10.10.2, if that's what you used from the given command shown in the room

#

Replace it with the MACHINE_IP of the deployed machine

dusk olive
livid escarpBOT
#

Gave +1 Rep to @teal basalt

vapid tendon
#

hello, im doing overpass3.. i obtained the foothold into the first shell.
i dont understand why my shell is not interactive

#

there are no way to stabilize it

#

any ideas?

#

okay, solved.. sorry for the mistake.

winged wave
#

In the room encryptioncrypto101, Task 8, don't you need to update the answer to the site certificate issuer question ? (I don't know if I should post here or in another place)

red haven
#

Hello Community,
I have a Problem in the room "lunix fundamentals part3".
There is the task to look inside the logs of apache2 to find out a few informations.
But unfortunately there simply aren't log-files for apache2.
I started the attackbox (deployable linux machine) and want to fullfill that to accomplish that course.

Did someone of you faced the same issue or can help me somehow?
Would appreciate every help and thanks in previous!

modern raven
#

There is the green start machine button and credentials in task 2

red haven
livid escarpBOT
#

Gave +1 Rep to @modern raven

wheat cradle
#

Hacking With PowerShell - Title PowerShell Scripting: Task 3, Question 1, the file is actually called interesting-file.txt.txt

median coral
#

@dusky junco

dusky junco
#

-ban @digital folio —ddays 1 some sort of scam

#

-ban @digital folio ddays 1 some sort of scam

livid escarpBOT
#

🔨 Banned alemagno71#6653 indefinitely

#

🔨 Banned 823910237664706640 indefinitely

dusky junco
#

ty @median coral

livid escarpBOT
#

Gave +1 Rep to @median coral

eternal summit
#

I've just checked and the answer hasn't changed

winged wave
#

My antivirus editor replaced the certificate by its own kekw

#

So in fact, the answer was good 😄

eternal summit
winged wave
#

my bad :p

eternal summit
tribal plover
#

Hi I'm trying to connect to the Intro x86-64 room for about an hour or so, I restarted the machine five or six times but could only ssh into it once and the connection died after approximately 2 minutes, then I'm getting timeouts again. I'm connected and can access other sites so its probably not an issue on my side...

#

just now I was connected and again it died..

#

"connection closed by remote host"

slim shard
#

Super minor grammatical correction in the Burp Suite (rpburpsuite) room: Task 12 asks the following question:

Which extension allows us** too** bookmark various requests?
It should say "to" instead of "too."

wanton elk
#

Hey! I was working through the 'Encryption - Crypto 101' room, and I found an outdated answer on Task 8:
Question is "Who is TryHackMe's HTTPS certificate issued by?"
Old Answer: ||R3||
New Answer: ||E1||

rugged canyon
#

and it has been checked by a lot of people and confirmed in #room-hints

#

shadow gets the same result on both their phone and ubuntu laptop both of which can be reasonably without doubt not have been man in the middled

wanton elk
#

Thank you @rugged canyon !

livid escarpBOT
#

Gave +1 Rep to @rugged canyon

eternal summit
#

They're changing it but it's not consistent yet @wanton elk @rugged canyon

rugged canyon
#

ah okay then

wanton elk
#

Got it, Thank you @eternal summit

rugged canyon
#

guess it will be figured out over the next few days then

livid escarpBOT
#

Gave +1 Rep to @trail marten

eternal summit
#

-ban @obsidian spruce -ddays 1 Game scam. Please secure your account and then appeal by emailing bans@tryhackme.com

#

@obsidian kiln Bot is on strike

livid escarpBOT
#

🔨 Banned TanjirouKun#1424 indefinitely

astral anvil
#

This is just wrong, might be worth updating

crisp cloak
#

Hi there

#

regarding
Buffer Overflow Prep room

#

i have tried several days and times to connect to the machine but seems there is a connectivity issue. Even if RDP succeeds, after a few minutes it disconnects....

obsidian kiln
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

crisp cloak
#

Rebooted kali so far so good

slow frigate
#

Anyhelp on Room- Corp https://tryhackme.com/room/corp . Task3, Cant access the net to get kerb file so I rdpd to machine, created the file and ran in colors folder but get no answer, ie command does not give results

eternal summit
wraith shuttle
#

in the Network Services room, task 7 (exploiting telnet)

for the question: What would the command look like for the listening port we selected in our payload?

It took the answer ||nc -lvp -4444|| but the actual answer is ||nc -lvp 4444||

this is such a small typo i wasnt sure if it was worth reporting, but here u go

rugged canyon
wraith shuttle
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

also if you refresh the page after submitting an answer that it accepts it changes it to the real correct answer

wheat fractal
livid escarpBOT
#

Gave +1 Rep to @half quarry

median coral
#

the tolerance is the same (95%)

wheat fractal
median coral
#

for longer answers, you have more room for error

#

that is, with 30 characters one or two can be wrong

#

with 5 characters every one has to be correct

wheat fractal
#

😄

wheat fractal
#

Ah, cause you can't.

#

Good to know Zeesh, good to know.

obsidian kiln
#

Also, where did you get 95% from? 😆

wheat fractal
median coral
median coral
wheat fractal
median coral
wheat fractal
wheat fractal
#

Did ya?

median coral
obsidian kiln
native plank
#

I have the same issue... ||I have changed the source of netcat and compiled both 32bit and 64bit exe files. Both versions show up clean on virustotal but every payload seems to fail. I can execute a ping from the txt file and see the request hitting to my machine, if I tcpdump tun0 for icmp traffic.|| Did you get anywhere with this @dense garnet ?

native plank
livid escarpBOT
#

Gave +1 Rep to @dense garnet

restive narwhal
misty cave
compact shard
#

Hi I have a problem. My room is BufferOverflow prep. I am not able to connect to win 7 vm using rdp.

dense garnet
hazy tiger
#

Hi Muir

obsidian kiln
#

-ban @dreamy tusk -ddays Game scam -- compromised account

livid escarpBOT
#
Ban <User:Mention/ID> [Reason:Text]

[-d d:Duration - Duration]
[-ddays ddays:Whole number - Delete Days]

Invalid arguments provided: "Game" is not a whole number
obsidian kiln
#

Oh, oops

#

-ban @dreamy tusk -ddays 1 Game scam -- compromised account

livid escarpBOT
#

🔨 Banned Scooby#8556 indefinitely

calm estuary
#

Hello, both me and a colleague are having trouble accessing certain features within Smag Grotto

#

trying to access the admin.php, and it keeps hanging

wheat fractal
clear dune
#

Hello, I am in room Sysmon, when I start the machine and use Attackbox. It keeps opening Kali and not Window

eternal summit
#

That's for the attackbox

#

The target machine, Windows, won't use that button

#

It will use the button in the tasks

fleet rampart
jaunty thunder
#

i'm sorry, i have a question about the machine Gallery.... I try all the exploit but all failed... And i read all the walktgough and i set all correctly but i can't get root ... Maybe there is a bug?

fleet rampart
fleet rampart
#

huh, the more you know

#

meant 20.04, mb

#

and my machine

hearty mountain
#

Does anyone have a bug with the MITRE room? I started the room two weeks ago. I came back to finish it and every link in the Task 5 redirect me to https://engage.mitre.org/ ...

glad badger
livid escarpBOT
#

Gave +1 Rep to @hearty mountain

dense garnet
wheat fractal
#

On the REmux The Tmux room, task 4, i answered wrong on the first question(typed ctrl b , instead of ctrl b c) and it got accepted, when entering the second command which is "ctrl b ," i noticed this, refreshed the page and now it displays correctly so no issue in the end, just wanted to notify this

#

Same happened with the last 2 questions on task 4, it happens with this format i think

#

just entered ctrl or shift and added an 'a' and it got accepted, after refresh it corrects itselfs, don't know what's happening here

rugged canyon
#

might also be because of screen cmd key using a

wintry marsh
raw bison
#

You sure you are using the right pcap file? I just downloaded it and it matches

spiral sedge
spiral sedge
sturdy bridge
#

not sure if its a bug or not but on the room brainstorm, it says the answer 6 ports open but im only seeing 2 and from a quick search write ups say 2/3 aswell ?

muted swallow
#

Please can someone assist to decode this ID please. Source ID is 10ef60f0-3c9f-4b45-8e15-08da1318f608

eternal summit
#

@muted swallow is this a bug with a tryhackme room?

muted swallow
eternal summit
muted swallow
#

Noted. Can you help me to decode it please.

eternal summit
eternal summit
#

-ban @honest moon -ddays 1 Your account has been compromised and is being used to send phishing scams. Please secure your account and then appeal this ban by emailing bans@tryhackme.com

livid escarpBOT
#

🔨 Banned FiReKill#0201 indefinitely

full knot
livid escarpBOT
#

Gave +1 Rep to @dense garnet

swift badge
#

Hey, im trying to start https://tryhackme.com/room/introtox8664# however when i start the R2 VM for the first task, i dont get any User/pass info, so i'm unable to ssh to the vm through the vpn. Am i missing something?

swift badge
livid escarpBOT
#

Gave +1 Rep to @eternal summit

eternal summit
obsidian kiln
swift badge
#

Ill certainly do that now 🙂

sleek cliff
#

Room: https://tryhackme.com/room/webosint has 2 questions under "Task 2" which is no longer accurate/or has been changed ever since the creation of the room

These are:

  1. What is the first nameserver listed for the site?
  2. What country is listed for the registrant?

I have not looked at the other tasks yet, so there might be some old stuff in them too

rotund burrow
#

@gleaming shadow @queen sphinx @obsidian kiln

obsidian kiln
#

-ban @ember yew -ddays 1 Compromised account posting nitro scams. Please email bans@tryhackme.com when you have this fixed 🙂

livid escarpBOT
#

🔨 Banned Kracken#8538 indefinitely

obsidian kiln
#

Ta @rotund burrow 🙂

untold pollen
#

https://tryhackme.com/room/pythonbasics, section "Introduction to Functions":

To get the flag, one has to output the value calculated, but it's not mentioned in the instructions. Only "output a message to alert you (via a print statement)."

lone gazelle
#

Problem with Windows Fundamentals 3, Task 5. Had to check a write up, and it looks like the question had change but the answer didnt.

The original question asked the type of network it would be called, but now its asking for the type of firewall profile. Putting in the correct firewall profile is incorrect.

||Should be "public profile" not "public network"||

eternal summit
#

-ban @narrow oracle -ddays 1 Compromised account posting nitro scams. Please email bans@tryhackme.com when you have this fixed 🙂

livid escarpBOT
#

🔨 Banned KIIIRA#2618 indefinitely

onyx lodge
eternal summit
#

Oh, no they're google. Not sure why they're broken but they're be broken for everyone cc @glad badger

wheat fractal
#

Softlock on Linux Fundamentals Part 1 (impossible to complete)

Task 4 and 5 is impossible to complete. (I sent feedback on Task4)

Task4 question:
What is the username of who you're logged in as on your deployed Linux machine?

ANS: tryhackme

However, the machine I logged in is defaulted ROOT. (I guessed the flag!!)

eternal summit
median coral
wheat fractal
#

Ya I did thanks!! Machine is in task3!!

dense garnet
#

@gleaming shadow @icy elbow

gleaming shadow
#

-ban 922530431017037904 -ddays 1 Your account has been compromised by a nitro scam, please change your passwords and add mfa before emailing bans@tryhackme.com to get the ban revoked.

livid escarpBOT
#

🔨 Banned where is my son !#6150 indefinitely

gleaming shadow
#

I really should macro that message'

rotund burrow
gleaming shadow
#

Most yes but they're getting creative

rotund burrow
#

yeah true

shrewd tangle
errant lotus
#

There is prob a bug on room Linux PrivESC

on task 1 you need to connect to a ssh server but its not connecting it says this:** Unable to negotiate with 10.10.105.206 port 22: no matching host key type found. Their offer: ssh-rsa,ssh-dss**. i asked in Room-help somebody tried it too but it didn't work for him eather

eternal summit
eternal summit
livid escarpBOT
#

Gave +1 Rep to @shrewd tangle

eternal summit
#

Done

split basalt
eternal summit
#

@obsidian kiln

obsidian kiln
#

-ban @clever relic -ddays 1 Nitro Scam

livid escarpBOT
#

🔨 Banned 3N354#0718 indefinitely

obsidian kiln
#

Remind me why you couldn't do that? 😆

eternal summit
obsidian kiln
#

It amazes me that you think I'm sober smh

uncut bramble
#

I am trying to do the WebOSINT room but I am at Task 2 - It seems the details I pull out do not match what they are asking for.. Has anyone ran into this?

uncut bramble
#

Yep it seems the domain name details have changed and are no longer valid for the tasks.

wheat fractal
#

@eternal summit How did you learn to be so good at hacking?

#

Dm me if you don’t want to publicly say

hot barn
quaint sparrow
quaint sparrow
#

So whatever your word list is being used has api in the list.

hot barn
quaint sparrow
hot barn
#

Let me check

#

1,585,853 bytes

quaint sparrow
#

Yeah, the one you have is bigger than the one on the attackbox.

hot barn
#

Alright, all good then 🙂

quaint sparrow
#

So it will more than likely have api in the word list.

blissful epoch
#

I think Linux Fundamentals Part 3 might be broken.
Under Processes 101 it asks you to find a flag among processes running on the deployed instance.
I followed the video exactly, connecting to the instance via attack box and trying both "ps aux" and "ps aux | less" but still couldn't find the flag. Had to copy it off the video...

eternal summit
#

It'll also depend on the width of your terminal iirc, especially if you use unfiltered outputs

blissful epoch
#

it found a tryhackme+ process but i dont see the flag, no matter how wide i make the terminal (and rerun the command)

eternal summit
#

What did you grep for?

blissful epoch
#

tried thm then THM then THM{PROCESSES}

#

ps aux | grep thm

#

like that ^

#

no " or anything

eternal summit
#

What user is your SSH session running as? What's the hostname of the box you're interacting with?

#

It may help to verify to provide this info, so you can send a screenshot

#

!docs verify

tropic flameBOT
blissful epoch
eternal summit
#

Ok, verify with the bot and send a screenshot please

#

You can verify by following the steps in the link just above

blissful epoch
eternal summit
#

Have you tried terminating and deploying the box again?

blissful epoch
#

i closed and opened the terminal and reconnected to the instance, but i haven't tried terminating yet, wanted to check here in case i did something wrong before i go having to wait for it to load up again

#

ill go ahead and terminate now then

eternal summit
blissful epoch
#

ok i see

#

but to clarify, in this case i wasnt right?

eternal summit
#

¯_(ツ)_/¯

blissful epoch
#

ok restarted it and connected with ssh
I should try
ps aux | grep thm
?

#

well that gives same output as screenshot, no flag in sight

eternal summit
#

I'm starting the machine up

blissful epoch
#

i did just ps aux

#

this time i found it

plain crescent
#

https://tryhackme.com/room/osqueryf8 <-- In Task 8 the number of features has changed since the room was published. It also looks like the referenced plugin "polylogyx" has been deprecated .

#

I had to go look at the readme history and find the year old documentation to answer the question correctly.

#

||Its currently 25 but the correct answer is 23||

eternal summit
#

-ban @lunar wadi -ddays 1 Nitro phishing. Please secure your account and then appeal this ban by emailing bans@tryhackme.com

livid escarpBOT
#

🔨 Banned Hsehwag#9276 indefinitely

placid thistle
worldly trellis
#

I just wanted to report this room still has a bug

#

Theres a youtube video out there and it seems Im not the only one who has had this same bug. Also there needs to be a note to use HTTPS not http. There is no warning about that here

quaint sparrow
#

The room isn't bugged, the cookie catcher is borked.

#

You can catch the cookie using NC.

worldly trellis
#

damn lol

#

I kept only getting my own cookies

quaint sparrow
#

Try using nc

#

What is your payload?

somber roost
#

nc from attack box worked for me after trying via vpn a few times with same issue (only my cookie)

worldly trellis
#

I basically starting my own python web server

#

that ip is my vm's IP address

quaint sparrow
#

Are you using the attackbox?

#

No, you're own VM.

worldly trellis
#

Nope I am using a vm

quaint sparrow
#

Try using a different port.

I know the attackbox already has a service running on port 8000

#

@gleaming shadow

worldly trellis
quaint sparrow
#

Try Changing the port to 9999

And using nc.

gleaming shadow
#

-ban 493027743802458112 -ddays 1 your account has been compromised by a nitro scam. Please change your passwords and add mfa before emailing bans@tryhackme.com

livid escarpBOT
#

🔨 Banned Whisper#9600 indefinitely

quaint sparrow
quaint sparrow
#

It worked?

worldly trellis
#

I didnt test it yet

#

earlier I gave up on it since I ttechnically made the exploit work

#

when I get thechance i might try it

#

I saw there was another solution sitting out there

dense garnet
#

I believe the new MISP room has a bugged VM attached.

glad badger
dense garnet
glad badger
dense garnet
glad badger
#

Aah, that would be another issue. Let me check.

glad badger
inland trail
wheat fractal
#

Linux fundamentals part 1 I am doing exactly what the guy in the video is doing but it is not working. Anyone able to jump in voicechat to troubleshoot this?

upbeat vector
#

There is bug in the room xssgi. No cookie is being sent to the attacker

boreal magnet
#

ans is wrong

dense garnet
livid escarpBOT
#

Gave +1 Rep to @inland trail

dense garnet
#

+rep @glad badger too haha

#

+rep @glad badger

#

okay I'll stop haha

#

sorry for the pings xD

obsidian kiln
# boreal magnet ans is wrong

Thank you for reporting.
Now could you please also tell us what room that is, what you think the answer should be, why you think it's wrong, and anything else that would make that report actionable? 🙂

boreal magnet
#

Oh it fixed thanks

quaint sparrow
rugged canyon
#

somehow it magically worked for shadow which feels like some amazing luck

charred geode
#

Hi guys,
I've a problem on the room ZTH: Obscure Web Vulns for the task 18, when I insert my payload the service crash suddenly and I've to reboot the machine... however it's a simple JWT
Am I the only one in this situation ?
Thx

upbeat vector
delicate vine
#

Good Day, I want to report a bug:

median coral
obsidian kiln
dusky junco
#

Para cutting corners? KEKW

#

I'll never forget that guy

#

Especially him and his box development mindset of "I'll never need to change this again so I'll just disable SSH"

obsidian kiln
#

TL;DR: I forgot the port knocking sequence to open it... 😂

#

Fortunately I keep good notes

dusky junco
fresh night
#

On net sec challenge how can I take the flag for the last question? I think i've tried everything and if I do a nmap scan at T5 the percentage doesn't even get up

#

I tried decoy, t1 , sF , sS , --mtu 8 and t0 nothing seems giving me anything

flat ibex
#

Hi, is the machine in "Exploit Vulnerabilities" room (/room/exploitingavulnerabilityv2) broken? I have started the machine but the web browser http://<given IP> does not open. Nmap port scan shows that port 80 is open and the room instruction says to wait minimum 5 minutes but it's been nearly 30 minutes and nothing is showing up. Is this an expected behaviour or is it a bug?

tropic flameBOT
obtuse mortar
#

!docs verify

tropic flameBOT
rugged canyon
flat ibex
#

ok, verified!

quaint sparrow
fresh night
#

I think the message was very clear

rugged canyon
fresh night
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

no problem

eternal summit
sharp crown
#

okay sorry

blissful vector
#

Phishing emails 4, Conclusion, has a link to incident response website however I don’t know if the link works anymore. I still guessed the framework and got it though.

noble edge
#

Hello, i'm trying the GhostCat room, i logged in as skyfck with ssh, and then tried to cat the tryhackme.asc file, downloading it with python, nc, scp or even reading it with less and none of them work. I also tried to Base64 encode it but the same problem occured. I guess the file is bugged.
One more thing to note is Hello, i'm trying the GhostCat room, i logged in as skyf
ck with ssh, and then tried to cat the tryhackme.asc file, downloading it with python, nc, scp or even reading it with less and none of them work. I also tried to Base64 encode it but the same problem occured. I guess the file is bugged.
One more thing to note is that i got this message on my openvpn connection : 2022-04-15 15:30:54 read UDP [EMSGSIZE Path-MTU=1442]: Message too long (code=90).
Not sure if that message is relevant since when i tried catting the file again it didn't show twice.

reef vapor
#

In the room Battery, it's possible to privesc to root with pwnkit. It seems like it shouldn't be possible because you are supposed to move laterally before getting to root.

eternal summit
reef vapor
#

Okay, thanks for the heads up

queen root
#

anyone knows if XSS room in the pentesting learning path is bugged or smthing?
Las question is not accepting my answer allthough i have the session id properly decoded

quaint sparrow
#

What is your answer?

#

There is a chance you have caught your own cookie, instead of the staff.

gleaming shadow
#

more than just a chance though

chilly pasture
#

Hi. I'm in the Sysmon room under Security Operations & Monitoring module. For Task 9 Detecting Evasion Techniques, there is no Event ID 15 inside the Hunting_ADS.evtx provided in the download files

tame karma
#

In Pyramid of Pain, task 9.... There doesn't appear to be any right answer. The instructions say "Once you are sure, submit your answer on the static site to retrieve a flag!"

But then you don't have to actually submit the flag. Is this room broken? Is there really no right answer? The instructions about capturing the flag should change if there is no flag.

quaint sparrow
quaint sparrow
median coral
quaint sparrow
median coral
warm finch
#

hey, bug in the room searchlightosint, the last task (#9) ||has a location that was closed...so searching it showed up something else instead of the correct answer. not sure if that was part of the task to looking up building history/changes or not||

quaint sparrow
#

What did you search for?

#

Use spoilers if you want?

warm finch
quaint sparrow
#

Yeah you can use double pipe to hide text ||like this||

warm finch
old acorn
#

Hey, guys. Have a question about brainstorm. I've done quite a few BOF now but on my win10 the offset is 3472 but the actual offset is different on the server (2012). which makes the whole room pointless

#

Can someone else take a look? Could be me missing something here

tame karma
eternal summit
#

-ban @wheat fractal -ddays 1 Nitro scam. Please secure your account and then email bans@tryhackme.com

#

@obsidian kiln fix yag

wheat fractal
#

can someone check: In the room 'Empire' I can't load the images in the Task 'Listeners' and the task 'stagers' I tried different browsers and devices, but still. Can someone else check?

#

this is the room

eternal summit
wheat fractal
#

oh, ok I was not aware

#

Is there a work around? I will look for a walkthrough, that has screenshots.

wheat fractal
#

the pictures are not absolutely necessary

#

and I found this video, where you can see them

hollow urchin
#

hey, on task4 of the linux3 room, I've created the server, transferred the file, opened it, the flag doesn't seem to be the right answer though.

quaint sparrow
#

What is the answer you get?

hollow urchin
quaint sparrow
hollow urchin
quaint sparrow
hollow urchin
quaint sparrow
#

Are you downloading .flag.txt?

hollow urchin
quaint sparrow
#

Hhmm, I'll boot it up

#

I done it and I got the right flag?

#

If you verify you can screenshots

#

!docs verify

tropic flameBOT
hollow urchin
#

Got it to work, i got a different flag this time, thank you

quaint sparrow
#

🙂 Excellent.

gray cairn
#

Hey guys, I have some trouble with the room RootMe. I can't upload anything. The server never answers to me when I'm trying to upload a file. I just get an error when I upload nothing.

summer cradle
#

I’m having trouble doing rootme, uploaded shells do not reach back. I have uploaded and made sure everything is how it should be.

eternal summit
summer cradle
#

Did

eternal summit
mossy basin
#

for Linux Pric Esc room the Sudo machine you can get the flag from flag2.txt by simply cat"ing the file using the user karen

#

there is no check for sudoers

#

Task 6* sorry

#

was that intentional or?

#

never mind you won't be able to see /etc/shadow for frank's hashed password unless you are sudo

mint torrent
#

Task 2 in Packet & Frames. When explaining SYN/ACK, it brings up the ISN. It should be Initial Sequence Number, but the page has it written as Initial Number Sequence.

split basalt
#

3rd question "Execute the command from Example 7. Instead of the string Policy search for PowerShell. What is the name of the 3rd log provider?" is actually referring to Example 8

#

and 4th question the same, it says Example 8 but looks like it should be 9

dusky junco
livid escarpBOT
#

Gave +1 Rep to @mint torrent

gray cairn
livid escarpBOT
#

Gave +1 Rep to @eternal summit

open otter
#

Anybody knows the correct answer to this in Room passwordattacks Task 4

#

don't know why this doesn't work

#

the result of the command seems fine to me

sonic willow
open otter
#

well looks like this works ||crunch 5 5 -t "THM^^" -o tryhackme.txt||

dusky junco
livid escarpBOT
#

🔨 Banned kiro6123#1921 indefinitely

worthy plank
#

Hello, I stumbled across an unintended path to root for the 'Internal' room (https://tryhackme.com/room/internal), this exploit completely bypasses the user portion of the box. Not sure if its been mentioned before, but I can provide screenshots to a staff member if they'd like. If you don't get to this tonight just send me a DM so I don't miss your message and I'll send the photos over

tame karma
#

In The Hive room, the URL is https://ip_address/index.html. The room doesn't load with https. I switched it to http and it worked fine. There are two references to the URL that should be updated.

median coral
outer smelt
languid moth
#

on https://tryhackme.com/room/kenobi seems like the answer is wrong

modern raven
languid moth
#

Interesting, its a fresh machine with everything upgraded and updated

#

but thanks for pointing it out

quaint sparrow
#

Have you tried upgrading searchsploit manually then trying?

languid moth
#

unable to locate package, I guess this explains it

#

its not part of kali's repos but it comes with an old db pre installed

quaint sparrow
#

sudo apt update && sudo apt -y install exploitdb

obsidian kiln
languid moth
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

worthy plank
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

rugged canyon
#

@misty cave as we kinda discussed earlier yes day 9 of aoc 2019 is broken... could probably be fixed with a virtual machine to launch that does the same json sending of new urls to check... if you wonder what the old correct answer is it is ||sCrIPtKiDd|| and the chain starts on / and then moves to/f as seen in the task description

#

also it should end with a end part on the last thingy as also stated by the task description

blissful vector
#

Not really a bug, but I don’t think the directions for Game Zone room task 2 work for the login: ‘ or 1=1 —

blissful vector
#

Never mind disregard.. had to include the third dash lol

next galleon
#

On the Jr. Pentester Path, Room "Protocols and servers". The second question from task 6 should be in the task 7. It is about IMAP(task 7) which is not explained in task 6 (which is about Pop3)

reef vapor
#

Not sure if a bug: In room brainstorm I couldn't find more than 3 ports in enum but it had more ports than that

#

Yeah, used -p- and even --data-string to evade the firewall

#

I used Syn scan and null and xmas but all failed

median coral
reef vapor
#

Yeah I was just annoyed for the fact that there're ports I couldn't find😅 thanks anyways

median coral
#

yeh, you might get them with a udp scan, but I mean whats the point

#

¯_(ツ)_/¯

lavish mulch
#

25 Days Of Cyber Security Room
the quotation marks were by accident and the answer is still right ?XD

eternal summit
lavish mulch
#

oh

ashen sail
#

Room Nax question 8 about metasploit path has a bug. exploit/linux/http/nagios_xi_authenticated_rce is not registering as a correct answer. I wonder if i am answering it wrongly. i search all possible wirteups and answer is correct but not working on mine

median coral
ashen sail
livid escarpBOT
#

Gave +1 Rep to @median coral

barren topaz
#

Hey there, not sure if this is a room bug, or something on my end. I am in the Network Services room Task 4 Exploiting SMB. I am able to login successfully with smb client. However, when I 'ls' in my current directory i get a long pause, then an error: smb: > ls
NT_STATUS_IO_TIMEOUT listing *
I am using the *latestish kali os

#

a bit more info: I am unable to cd into any directory. hardly any commands work.

dusky junco
#

-ban 598524835718758400 -ddays 1 nitro scam

livid escarpBOT
#

🔨 Banned ! 𝘼𝙢𝙢𝙉𝙞𝙠𝙠𝙞#6912 indefinitely

dusky junco
#

ty @vital vine

livid escarpBOT
#

Gave +1 Rep to @vital vine

strong shard
#

In Metasploit room :
https://tryhackme.com/room/rpmetasploit
Task 7 Makin' Cisco Proud [second question]
the answer is : auxiliary/server/socks5
This auxiliary still exist in msf5 , I think it's removed in msf6 ?

obsidian kiln
strong shard
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

eternal summit
#

-ban @wheat fractal -ddays 1 Nitro phishing. Please secure your account and then appeal this ban by emailing bans@tryhackme.com

livid escarpBOT
#

🔨 Banned Rahul Maurya#8776 indefinitely

left tendon
#

i think the content security policy room is still broken - tasks 5 and 6 of the attack tasks require the box to have internet access

thorn jasper
#

Hello everyone,
Im stuck with Splunk201 room.

Under task three, the link won't open up in browser. I tried it multiple times. Any help would be appreciated in this regard.

Thanks.

heady pebble
#

The Mitre room needs a complete overhaul. The first couple tasks that require searching for answers are incredibly vague and don't teach anything except poking around the mitre site trying to find possible answers. One of the answers is literally just one of like 20 possible answers, with no way to know which is correct without trying all of them until it says you're correct.

The later rooms are completely useless as they are for Mitre Shield, which doesn't exist anymore. It has been replaced by Mitre Engage, and none of the links work because shield doesn't exist. The questions are also equally vague as before, so nobody can figure out the answers since the Mitre site is completely different from when the room was created.

In my searching for help in this room, I noticed that multiple other people have also pointed this out in other posts here on discord, but they all went completely unacknowledged. Hopefully someone will see this and do something about it. The Mitre rooms needs to be completely redone.

twilit forge
#

this jewel room is bugged again I believe. I know I am beating a dead horse, but I have started over 4 times already and followed the video step by step. I know the file uploads and I know what its called and how to access it. just keeps erroring out

eternal summit
twilit forge
eternal summit
#

Did you add the magic bytes to the start of the file?

twilit forge
#

Similar to someone else, enumeration reveals the file being present, but attempts to execute fail. Also, accessing the file directly give an error saying it can't be read, so that confirms it's there

#

Yes, the only way the file would upload

eternal summit
#

IIRC that's not the only way it will upload, and adding the magic bytes prevents it from uploading for that one.

#

Check the writeups

twilit forge
#

?

#

It wouldn't let me upload without the bytes being present iirc

#

I already shut my rig down, and I've got work in 4 his. I'll tackle it manaña and get back with results

#

But again, I was able to upload the file. It just won't execute

eternal summit
twilit forge
#

Okay well that changes things... I'll review thank you

#

This room is literally all that's in my way of the next rank

eternal summit
violet dune
#

On the Nessus room (https://tryhackme.com/room/rpnessusredux). Task 4, question 6: What Apache HTTP Server Version is reported by Nessus.

The correct answer is not accepted by TryHackMe. Upon Nessus scan finishing it returns the server version as 2.4.25 and is also confirmed by NMAP. Upon looking at a walkthrough I found that the answer is 2.4.99 which is not what these tools return as the server version.

obsidian kiln
# twilit forge Yes, the only way the file would upload

That's an important lesson in checking where the filters are... and that client side filters are trivial to bypass.

As alluded to in the room, NodeJS (unlike PHP) does not allow you to execute JS files if they aren't actually JS files

#

You need the correct magic number.

#

Also, how the heck did you follow the video and still have this issue?

quaint sparrow
#

That takes skill.

#

It's like falling up stairs.

rugged canyon
#

@misty cave seems day 14 of the aoc 2019 is broken because of no aws application on the attackbox that shadow could find

#

shadow used some curl trickery to get the data but the intended way from the document for that day is to use aws cli

rugged canyon
#

or maybe there is aws cli on the attackbox but shadow could not find it... but it would be weird for the attackbox to have it as after all it does not have an internet connection if you are not a subscriber

misty cave
rugged canyon
#

fair

#

shadow just don't feel like installing a lot of stuff for aws cli

#

luckly curl worked

glad badger
#

This is from Advent of Cyber 3 regarding aws cli: Please note: If you are on the TryHackMe free plan, the attack box does not have internet access and cannot reach AWS. You will need to install curl and the AWS CLI on your own machine in order to complete this challenge. Instructions for installing the AWS CLI are here: https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html

rugged canyon
#

thanks tim

shrewd mason
merry chasm
#

yeah I don't usually use nessus, still weird

glossy crane
#

Hi, in the room “Dogcat” the file backup.sh does not run every minute, therefore it is impossible to get the last flag. (I live in China , i use my own pc to connect to the machine through openvpn and i have amother vpn on the background so i can access tryhack me without any problems).

obsidian kiln
glossy crane
#

I know the second VPN can cause problems, but is the only way i have to access Tryhackme from China unfortunately. I am 100% the script is not running every minute on my system

#

but it might be a problem on my side, just raising awareness in case it has something to do with the platform

#

because all the video tutorial on the box seem to be fine, but they are quite old soooo just in case, I left it here in case anyone wanted to have a quick look at the box @obsidian kiln

glossy crane
#

lassi that is a really good point, i will try that today and i will try also to run it on a attack box instead of using my system... then i will report back

glossy crane