#voice-chat

1 messages ยท Page 6 of 1

plucky vault
#

@forest python hehe

forest python
#

@plucky vault By a while, I mean literally forever

#

Till the end of rockyou

plucky vault
#

yah i found monitor

forest python
#

JFC learn how to name variables

plucky vault
#

nope this is just to tilt you lmfao

forest python
#

Borders on rule 4 there

#

@plucky vault learn how to use curl

#

@plucky vault Also remember I can ban you from the room

#

So super rule 4

plucky vault
#

wdym

#

im just getting root

livid crag
#

then learn to use curl

forest python
#

@plucky vault ip a s

#

No sudo required

#

Try harder

#

Run less code as root

#

Don't abuse sudo

plucky vault
#

okay

forest python
#

@plucky vault That's literally the easiest thing to fix

#

Applies to 90% of rev shells on THM

#

90-100%

plucky vault
#

okay

#

hang on please

forest python
#

@plucky vault You really don't need to other than patching it

#

That go is just the source code for the webserver

#

It's uh

#

not compileable on the box

plucky vault
#

yah yah hang on

forest python
#

@plucky vault reverse shell use sudo into google

#

Rule 13

plucky vault
#

yeah im doing that rn

livid crag
#

im sur you are

forest python
#

Do some research

#

I know you only have 1 screen @plucky vault

plucky vault
#

wdym only 1 screen

forest python
#

You keep trying to use sudo

#

You need to fix your rev shell

plucky vault
#

aaa

#

john hammon's tool

#

idk how its called

forest python
#

No

#

Just some basic research

#

omg

#

@plucky vault learn how to google

#

I literally told you what to search

full sapphire
#

Uh, yeah, yelling at Google ain't gonna help xD

plucky vault
#

yes yes google help me

forest python
#

You know

#

Googling what I told you to google might help

#

Learning what a reverse shell is isn't likely to

plucky vault
#

okay i stop trol

forest python
#

@plucky vault reverse shell use sudo into google
@forest python

plucky vault
#

i just did

#

SMH

#

okay stop reading my mind

forest python
#

You went on the first result which wasn't relevant

#

Nice

livid crag
#

James, relax. It's funnier without him knowing he's not looking at the right thing

plucky vault
#

ikr

forest python
#

It's infuriating because food is so easy

#

And this fix is so easy

plucky vault
#

its not easy at all

forest python
#

It's something you should instinctively know how to fix

plucky vault
#

no i will bully

#

xD

forest python
#

Those quotes aren't real quotes

#

They're fancy format quotes

#

Welcome to ubuntu 1804

plucky vault
#

yeah im aware

#

hang on im using google

#

with all my power

forest python
#

The fix is really really obvious from what you're being told

#

You don't have a real shell

#

You need a real shell

#

There's a bunch of ways

plucky vault
#

im thinking

#

hang on

forest python
#

The python one is one of them

plucky vault
#

i know

forest python
#

You just skipped it when python2 wasn't installed

plucky vault
#

and im trying

#

but

#

there is not python

forest python
#

There is python

plucky vault
#

smh

#

hang on

forest python
#

It tells you python is installed

#

You just need to actually try

#

Think about it

#

be smarter

plucky vault
#

ok

#

hang on

forest python
#

It worked

#

Now keep working

#

I gotta eat in a bit

#

@plucky vault You upgraded your shell already

#

You're not spawning nested shells within shells

#

try actually using the shell you have

plucky vault
#

you go eat

#

i will figure this out

forest python
#

@plucky vault You don't have the password, so running commands as sudo aint gonna work

plucky vault
#

ooo

forest python
#

If you can run any commands with sudo without a password, sudo -l won't require a password

plucky vault
#

then i have to get sudo without being sudo

forest python
#

*root

plucky vault
#

superuser ๐Ÿ™‚

forest python
#

*root

wise mortar
#

*root

plucky vault
#

administrator xD

forest python
#

Just plain wrong

#

@plucky vault Don't just click the first result

plucky vault
#

yeah i just discovered that

forest python
#

It says abusing sudo rights

#

Read the title

#

@plucky vault You need to understand that before you attempt to use it

plucky vault
#
root       725  0.0  2.0 185948 20204 ?        Ssl  19:20   0:00 /usr/bin/python3 /usr/share/unattended-upgrades/unattended-upgrade-shutdown --wait-for-signal```
#

bingo

forest python
#

No

#

Not at all

#

You found something that runs by default on ubuntu as root

#

Well done.

#

@plucky vault You need to understand what you're doing

#

And I can promise you, you don't

#

If you just throw commands at it with no logical process and no thought, that's what makes a skiddy

#

Skiddies don't try to understand

#

hackers understand.

plucky vault
#

i try to understand

#

if python is runed by root

#

and if i type

#

whoami

#

then

forest python
#

No, you don't understand

plucky vault
#

it should give me root

forest python
#

Someone else is running a process

#

You can't touch that process

plucky vault
#

alr alr

#

give me like

#

idk

#

hang on

#

im trying to get an idea

#

of what to do

forest python
#

I keep posting privesc cheatsheets

plucky vault
#

didn't you say thats skidy?

forest python
#

@plucky vault No?

#

Doing stuff without understanding is.

plucky vault
#

exactly

forest python
#

It's a really easy box.

#

Using the privesc cheatsheet is not skiddy

plucky vault
#

smh im bad at privesc idk what do you expect

forest python
#

Then don't say either box is easy

plucky vault
#

for the record i didn't play food like seriously ever and that /monitor is like lucky hit

#

hackers is easy box ok ?

forest python
#

Don't say something's easy without actually knowing

#

Hackers isn't easy

#

You haven't completed it

plucky vault
#

okay i won't give up actually

#

i will complete both

#

hang on

#

like 5 sec

#

let me just get an idea

forest python
#

@plucky vault I'm gonna eat

#

Don't forget to extend the box

plucky vault
#

okay

forest python
#

@plucky vault aaaaaaaaa

#

@plucky vault You can generate SSH keys and use those to get a better shell btw

#

Nice trick

#

But it won't help you there

plucky vault
#

reee

#

idk what todo

forest python
plucky vault
#

bra

#

im busy rn for walkthrought

forest python
#

Learn what you're doing reee

plucky vault
#

finding anything that ends with .sh in the folder

forest python
#

You're just throwing stuff into find

#

find . -iname ".sh" will find files called exactly .sh

plucky vault
#

oh

#

can you give me / but reversed

forest python
#

A backslash?

plucky vault
#

cuz idk where its located i had to switch to other keyboard accedently spilled booster on it

forest python
#

It's a key

#

get a new keyboard

plucky vault
#

yah well James im not made of money yk

forest python
#

If you weren't in serbia, I'd post you one smh

tame ether
#

well noone is made of money

plucky vault
#

no tnx lol ๐Ÿ˜‚

#

can someone give me that key

#

/ but reversed

#

like its looking at oposite side

#

2 late

#

i found it

#

\

forest python
#
import strings
print(strings.symbols)```
#

You know

#

"*.sh" works

#

But you're not looking strategically

plucky vault
#

why doesn't (\w).sh work

#

its liturally doing what i want it to do

forest python
#

There's no .sh files there

#

So you get no results

plucky vault
#

oh

#

okay good

#

now i know command works

forest python
#

You can search from /

plucky vault
#

lol

forest python
#

it might not

#

Whatever you're doing, whatever it's being interpreted as, there's no results

plucky vault
#

i can see that

#

ok

#

i forgot

#

i know i don't know how to set permissions

forest python
#

Doesn't matter

plucky vault
#

its wrong

#

i also know that

#

!

forest python
#

@plucky vault Cheater.

plucky vault
#

why

#

did

#

you

#

do that?

forest python
#

Write it up?

#

Because I'm allowed to

plucky vault
#

its hurting my heart that i can't look at it rn lmfao

#

aa give me little hint ; (

#

tiny tiny hint

forest python
#

The little hint is stop just runnign every single command you know

#

Have a strategy

#

A method

#

Use your brain

plucky vault
#

aa me no brain

#

oky its stratechy time

#

im dumb

tawny oak
#

All the Best Elf ๐Ÿฅฐ

plucky vault
#

i hate privesc

forest python
#

Believe me

#

This is an easy one

#

There's a bunch of ways

plucky vault
#

i liturally feel like world's dumbest guy rn

forest python
#

Now stop saying that either box is easy

plucky vault
#

im not going to do that

#

this box is way harder

tawny oak
#

you can do it Elf!

forest python
#

You can't privesc hackers either

#

You can't say either is easy

plucky vault
#

no

#

this one is hard

#

other one is easy peasy

tame ether
#

what box is this?

plucky vault
#

food

tawny oak
#

Food CTF

forest python
#

@plucky vault No. You haven't privesc'd either

#

You got a shell really fast, in the hardest way on FoodCTF

plucky vault
#

wdym hardest way

#

its liturally easyest way ever

#

it says : ping:

#

liturally the name it self is saying that you can use that to get reverse shell

#

SMH

forest python
#

I can implement that securely

#

No

#

Ping is a standard network utility

plucky vault
#

mhm

#

tell that to params ๐Ÿ™‚

forest python
#

Not for reverse shells

#

It was designed to be hacked that way

#

That was the hardest access route on that box

#

All of the others are crazy easy in comparison

tame ether
#

If that's the hardest way then what are the others kekw

plucky vault
#

how is that hardest access root idk

tame ether
#

I need to check these koth boxes

forest python
#

Waht

plucky vault
#

smh even szymex understands me

tame ether
#

it's not root

forest python
#

Rooting the box is also insanely easy

#

You just don't know what you're doing

plucky vault
#

i highly doubt its easy

forest python
#

You're running random commands

plucky vault
#

no im not

tame ether
#

smh even szymex understands me
@plucky vault wat

forest python
#

You don't have any method

plucky vault
#

wdym method

forest python
#

A plan

#

A process

#

Rather than just trying random stuff

plucky vault
#

yah nobody needs a plan you make it on the way

#

first get in and then get a plan

tame ether
#

๐Ÿ˜Ÿ

forest python
#

@plucky vault No, there are logical things to do when looking for a privesc

tame ether
#

@plucky vault now you're just wasting time kekw

tawny oak
#

u tried scripts? like linpeas? it will MAY speed up

plucky vault
#

okay

#

so now

#

i know how to build a time

#

so my priority is to get a root

forest python
#

Please actually complete the box

#

Before you say it's easy

plucky vault
#

no no

#

its easy

#

then

#

food

forest python
#

You haven't completed it

plucky vault
#

yah well im doing it rn

forest python
#

You can't root either

tame ether
forest python
#

For both of them, it's hard for you

plucky vault
#

first proof

forest python
#

The proof is you're failing right now.

plucky vault
#

no im not

#

im just

#

taking some time

forest python
#

Hard stuck.

plucky vault
#

thats not a fail

forest python
#

Without a strategy

plucky vault
#

yeah something like that

forest python
#

No idea of what to try

plucky vault
#

but not a fail

forest python
#

Hackers is harder

#

You haven't finished either

#

Your opinion is not valid

plucky vault
#

yah well not yet

#

but soon

tame ether
#

also why are you using vscode as your terminal thonk

plucky vault
#

cuz i can't do full screen share idk why

#

like when i want to share full screen

#

look

tame ether
#

ah, probably still not fixed on some distros

#

it's an electron bug iirc

plucky vault
#

im gonna be swtiching to windows 7 soon tho

tame ether
#

it had a problem with full-screen screensharing on linux

forest python
#

Windows 7 is EoL

plucky vault
#

windows 10*-

#

anyway back to other thing

tame ether
#

Mind DMing me the IP? I'm curious if I can get root before you do kekw

#

never did food so it's new to me :)

plucky vault
#

there i sent you

tame ether
#

got it ๐Ÿ‘

plucky vault
#

wait i forgot i alredy have reverse shell

tame ether
#

oof dark

plucky vault
#

im here

#

okay

#

wait

tame ether
#

why do i have you dark on 50% Kappa

plucky vault
#

idk can i ask this but can this be a little bit simpler

#

aaaa about that

#

sry i didn't know

#

yes yes i know i wasn't aware im sorry

#

i was warned by 3 mods about that

#

i deleted it 2

#

when james explain it to me

#

okay it won't happen again

#

ree i give up

#

james can i look at writeup ๐Ÿ˜‚

forest python
#

@plucky vault If you admit you lied

#

Hackers is not easier

#

And you shouldn't make statements like that without having actually done the box.

plucky vault
#

but im elf thats what elfs do

#

hang on

#

i actually have an idea

forest python
#

You don't have to talk bull

plucky vault
#

so i will admit but i will complete hackers just to try

#

i think its the same method

forest python
#

Good luck rooting it

#

Same method as what?

plucky vault
#

idk

#

like

#

its the same method

forest python
#

What is?

plucky vault
#

hang on

forest python
#

You're saying words with no meaning

plucky vault
#

i admit i lied

#

now watch

#

wait what

forest python
#

@plucky vault Privescs are different by user.

#

Try to understand the process for finding the privescs

#

Otherwise you're just being a skiddy and copy/pasting from the writeup

plucky vault
#

so basicly i needed a script

forest python
#

No

#

The script is one of many many exploits

plucky vault
#

oh

forest python
#

And you'd need to find the thing you exploit first

plucky vault
#

MHM

forest python
#

And then research that program

plucky vault
#

yah yah whatever i backoff my word cuz i thought its some geniues way but turns out it was just a cve and its just bad... and then im skid. ๐Ÿคฏ

forest python
#

There's more methods

plucky vault
#

also involving scripts

forest python
#

But you skipped all the enumeration in the writeup

plucky vault
#

yes cuz i done it in front of you

#

liturally

forest python
#

All of the "looking for ways to root the box"

#

enumeration doesn't stop when you get a shell

#

You immediately should be starting to look for ways to get more privs

plucky vault
#

hm

#

okay how do i leave a room

forest python
#

Read the writeup, work out how I found each vuln

tame ether
#

oof

#

jsut got user :C

plucky vault
#

wait you were actually playing ?

#

bruh this is like dissapointment for me and learned new stuff

tame ether
#

yeah

forest python
#

The privescs section @plucky vault

#

Read

#

looking for suid etc is what you should be doing

tame ether
#

I did like 3 koth games before two of which were with my friend and we both didn't get too far DogKek

forest python
#

Suid, sudo -l, look for passwords, use that resource

tame ether
#

rage foodctf room sub only

plucky vault
#

im reading

forest python
#

@tame ether Wait really?

#

Lemme change that

#

It shouldn't be since KoTH is free

tame ether
#

thx :)

plucky vault
#

can you explain this line ? find / -uid 0 -perm -4000 -type f 2>/dev/null

forest python
#

@tame ether it's not sub only

tame ether
#

manpage @plucky vault

plucky vault
#

yah good point

tame ether
#

oh wait

#

foodctf redirected me to sub but the room id is different, that's why

plucky vault
#

the vm one

#

vim*

#

is so good

forest python
#

@plucky vault But you need to know that it exists

#

The search for suid

plucky vault
#

yeah i just noted that

forest python
#

Part of the process of enumeration

#

Scripts like linpeas do it for you

#

Once you learn how to do it manually, then you can start using scripts

#

Then you understand what you're doing, and you're just using tools to speed up the process

plucky vault
#

can this one be done thorught browser

forest python
#

None of them can

#

You need a shell

plucky vault
#

yeah i understand that part

#

but can you like first download a file and then make a shell

forest python
#

@plucky vault wat

plucky vault
#

hang on let me start hackers

forest python
#

Have fun

plucky vault
#

let me test does this stuff work there

forest python
#

Hackers was designed to hurt optional

#

It was designed to be hard.

plucky vault
#

yah well let it be today i learned something new from you smh

forest python
#

@plucky vault If you post the link, don't be surprised when people join

plucky vault
#

i alredy did

forest python
#

Yeah

plucky vault
#

well i need people to join so i can play

forest python
#

It's competitive now

plucky vault
#

sounds good to me ๐Ÿ™‚

#

also do you like my new pfp on thm ๐Ÿ˜‚?

#

giving enemies that scary look

#

anyway brb i go make cigarete and go to wc

#

cuz this will be good

#

okay im back and ready

tame ether
#

found one privesc on food :)

midnight fern
#

@tame ether Unintended?

tame ether
#

nah, I'm doing it for the first time kekw

tawny oak
#

Bro. Food privsec done!

That was super easy bro๐Ÿ˜›

tame ether
#

yeah lul

tawny oak
#

And... Elf was stuck out into it.

#

๐Ÿ˜… ๐Ÿ˜‚

plucky vault
#

i hate privesc xD

tawny oak
#

It was literally sooo easy, and can be done in multiple ways

tame ether
#

one of them was literally the whole theme of another room

plucky vault
#

and james is alredy king

tawny oak
#

Which room bro? I'll play that too๐Ÿ˜›

plucky vault
#

nice james

#

meanwhile im still doing enumiration

forest python
#

I know the fast ways

#

Have fun

plucky vault
#

reee

#

james is 2 good to be true xD

forest python
#

Box hardened

plucky vault
#

wdym

forest python
#

@plucky vault I patched the vulnerabilities

plucky vault
#

smh

#

tbh im not suprised.

tame ether
#

kek

forest python
#

@plucky vault I can see what you're going

#

And you're grasping

plucky vault
#

wdym

forest python
#

I can see those POSTs

plucky vault
#

well stop looking at them

#

thats like evil

#

no no thats like next level of evil

#

im gonna draw graph level of evil just for you

forest python
#

What, logs?

#

Reading logs isn't evil

plucky vault
#

yes ๐Ÿ˜‚

forest python
#

Basic blue team

plucky vault
#

bruh for this 41 days i never saw you not being serious ๐Ÿ˜‚

forest python
#

You shit-talk my box, you get whooped

plucky vault
#

so this is your box

#

?

#

oh you ment food

#

no wonder you are so mad at me...

forest python
#

I made food and hackers

tame ether
#

ooh it's midnight already :))))

plucky vault
#

well this conv just lost it's point i guess

forest python
#

Try opening your backdoor

#

Your precious backdoor

#

Just view it

plucky vault
#

yummy

#

is it made of candy?

forest python
#

It's the best

plucky vault
#

HAHAHAHA\

plucky vault
#

oh no what will i do now

#

back there again lmfao

forest python
#

@tame ether As I said, patched the whole box

#

Reload that page?

tame ether
#

ik that it "redirects" me lol

forest python
#

Whatever you're gobusting for

plucky vault
#

check my screen

#

really good

tame ether
#

imma go do very secure protocol from hackback2

forest python
#

@plucky vault You can't gain access now

#

Unless you're me.

#

Passwords were changed, backdoor was patched

plucky vault
#

but i don't want to be you

#

btw you are breaking rules right here @forest python

forest python
#

No, I am not

#

Tell me which rule I'm breaking

#

You're allowed to patch the box

tame ether
#

it's not completely blocked as he said it's possible to get in if you're him

plucky vault
#

you said i can't get access

tame ether
#

which means

forest python
#

You're allowed to change passwords

tame ether
#

you'd need to somehow impersonate gim

forest python
#

I haven't stopped services

tame ether
#

that's what I got from it thonk

forest python
#

@tame ether You'd just need to know my password

tame ether
#

optionalFTW kekw

plucky vault
#

thank god james evil level is raising

forest python
#

@plucky vault So again, what rule did I break?

plucky vault
#

it apears you didn't

forest python
#

๐Ÿ‘

tame ether
#

๐Ÿ‘‹

plucky vault
#

@forest python do you like logs ?

forest python
#

Post every second getting met with an error code? Nice.

#

have fun

plucky vault
#

every 1.5 btw

forest python
#

All you're doing is spamming one of several root shells that I have open

#

And your own

tame ether
#

@plucky vault there's no point in you streaming this

plucky vault
#

yah good idea

lofty moat
#

optionalFTW always works

#

even worked in last stream xD

tame ether
#

yeah r2 won't help you with apk

#

@plucky vault

plucky vault
#

but it says : explore apk

tame ether
#

what makes you think r2 will help you with that

#

apk is not a binary like exe/elf files are

forest python
#

@livid crag Hi, everyone's asleep so I'm being quiet

livid crag
#

No worries :)

plucky vault
#

yah

#

but idk how else to explore it

#

like run it ?

alpine ember
#

google?

forest python
#

apk reverse engineering into your favourite search engine

livid crag
tame ether
#

static analysis sections

forest python
#

@livid crag A wonderful bird is the pelican; His beak can hold more than his belican. He can hold in his beak Enough food for a week, Though Iโ€™m damned if I know how the helican! โ€”Dixon Lanier Merritt (often incorrectly ascribed to Ogden Nash)

livid crag
#

Lovely.

forest python
#

Some books there

#

Legally free

livid crag
#

I'm aware, thanks

plucky vault
#

so

#

i need to do that room ?

#

in order to complete borderlands?

tame ether
#

that room can point you in the right direction

#

at least for the apk part

#

you can omit that and do it afterwards

tame ether
#

;-;

plucky vault
#

yah no worry

#

haha

tame ether
#

maybe leave the apk alone and focus on the other flags

plucky vault
#

oh

#

okay

#

aa found something

#

i legit don't know what to do lol

tame ether
marble cape
#

Goodness, it's a party in chat

tame ether
#

join us

#

:)

marble cape
#

In a bit

#

Gimme about 50 minutes and I'll join if you guys are still there

plucky vault
#

pls no im dumbxD don't laugh

#

yoo i need to use my phone for this one?

tame ether
#

no

#

static analysis sections

plucky vault
#

smh

#

its not my fault

tame ether
#

well the fact you're addicted to smoking is most likely your fault thonk

plucky vault
#

lol

civic wedge
plucky vault
#

i don't know

tame ether
#

don't think so

plucky vault
#

๐Ÿ˜ญ

#

you left me

marble cape
#

rip voice chat

plucky vault
#

yah

#

im gonna stream racetrack since i didn't complete it

livid crag
#

HHAHAHAHAH

#

@wise mortar

wise mortar
#

AHHAAHHAA

livid crag
#

Come on, let's watch it and talk about how wrong he is

plucky vault
#

close what?

#

aa

#

xD

livid crag
#

ima like 70% done with initializing nessus

plucky vault
#

bruh its crashing

#

why.

#

@livid crag are you watching ?

#

smh no point on streaming to guys who are afk xD

civic wedge
#

bro

#

im sorry

#

im doing math hw, and i can't even help im trash.

livid crag
wise mortar
#

holy $&@! thats still going?

livid crag
#

It finished a few seconds later

#

I actually just finished it

#

Time to do BP

plucky vault
#

hey

#

yeah

#

gj on 0xA

#

now idk how to run it

midnight pier
#

hey can you help me?

livid crag
#

SUID you vegetable

plucky vault
#

aaaa

#

i can't use vim lol

livid crag
#

@plucky vault ||Vim was a glitch when they were trying to make the actual SUID exploit, it doesn't work even if you got an interactive shell||

plucky vault
#

smh

#

LOL

#

thats sad

#

F

#

holy

#

4000 not 400 xD

midnight pier
#

elf

#

Mon May 18 07:57:19 2020 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this

#

help me

plucky vault
#

idk

#

you didn't

midnight pier
#

openvpn error

plucky vault
#

messages me first and then says *im gonna block you

harsh needle
#

yo

#

lol

#

@robust zinc here

#

yea lol

#

are u hydra?

robust zinc
harsh needle
#

cri are u going to play KOTH?

robust zinc
#

No I just came into this channel to see what is going on

harsh needle
#

me too

robust zinc
#

I am not smart enough for KOTH yet

#

Haven't even got all the basic's down yet LOL

harsh needle
#

SAD

robust zinc
#

Very! LOL

harsh needle
#

LOL

#

GO SLEEP RIGHT NOW!!

#

paradox @robust zinc

robust zinc
#

LMAO

harsh needle
#

@livid crag stealing?

#

what

#

me?

#

bruh

#

are u stupid?

robust zinc
#

maybe

#

๐Ÿ˜‚

harsh needle
#

lol

#

i'm talking to Sad Kris

hot sparrow
#

I have a question

#

how to get king in Windows Machine OFFLINE

fresh solar
#

...

quiet needle
hot sparrow
#

is try harder for me

fresh solar
#

Duh

quiet needle
#

Very much so @hot sparrow

hot sparrow
#

the KOTH page tells that your username should be in the file

#

and i have placed my username in that file

quiet needle
#

Correct

#

As with every other machine

hot sparrow
#

but king doesn't seems to change

quiet needle
#

how you do that though

hot sparrow
#

shall i write here

#

@quiet needle can i tell here what i did though

quiet needle
#

I'd rather not for the sake of competition

#

Are there any characters at the end of the entry in the file? E.g. white spaces, new lines?

hot sparrow
#

no

quiet needle
#

Another user might be overwriting the file then.

hot sparrow
#

no i was testing the same in with no user or a user who was offline

#

doesn't seems to work in OFFLINE Machine

#

while i play with other players they somehow managed theri username in that file

#

Dont Know Whats Happening

quiet needle
#

Right - so then you know it's working if other users can put their usernames into it

hot sparrow
#

yeah other players do

quiet needle
#

Exactly

hot sparrow
#

but why i can't

quiet needle
hot sparrow
#

i am doing the same as i do in linux

#

uh

quiet needle
#

That's a very broad statement

hot sparrow
#

ok

#

are here tornaments held too

quiet needle
#

Not necessarily tournaments as of yet, but we have a few popular livestreamers who host a private lobby

hot sparrow
#

ok

#

and can a non-subscribed user can take part in it

quiet needle
#

Koth is free to play

hot sparrow
#

okhh

#

Thanks for your Time @quiet needle

quiet needle
#

๐Ÿ‘

hot sparrow
#

one thing remaining

#

can i create a machine in koth

quiet needle
#

Machines for koth are made from people in the creators programme

#

get into that and you can pitch your idea ๐Ÿ™‚

hot sparrow
#

where is creators programme

quiet needle
#

Submit / publish a few rooms that go down well with the community and you'll be selected by the admins

hot sparrow
#

okhh

#

Thanks Again for your Time @quiet needle

quiet needle
#

๐Ÿ‘

lusty light
#

Bahahah I love the lolcat

buoyant lichen
#

huh let's see

marble cape
#

Man, it's party in there

tawny oak
#

took me whole hour too ๐Ÿ˜ธ

tawny oak
#

maybe helpful for elf: I watched John's Pingu room video today and found assembly, cyclic, binary things maybe... those value mean something related to that ๐Ÿค”

#

use nc on 7321

plucky vault
#

oh

#

ye ik

#

xD

#

i mean command

full sapphire
#

๐Ÿคฆโ€โ™‚๏ธ

tame ether
#

@tawny oak that's not useful if he didn't get the prev part

tawny oak
#

๐Ÿ˜› sry! but it may be helpful!

tame ether
#

unless someone got prev steps it's just misleading

plucky vault
#

yah im confused

#

wait i alredy know cirilic

#

i saw these alredy somewhere xD

#

i think im dumb?

tawny oak
#

U R DOING GREAT!

I'm here to cheer u up ๐Ÿป
U can do it Elf! U can do it

plucky vault
#

am i atleast in the right way o.O

tawny oak
#

(STILL MAYBE MISLEADING)
elf, I think (10% sure) i got clue,

someone gave hint to check discription of room, there is a PICKLE png image, and there is also a python module named pickle

#

was that helpful?

plucky vault
#

yes

#

i think

#

?

#

hehe

#

i know i can use that command but like sudo ifconfig tun0 seems easyer

#

idk why

forest python
#

@plucky vault Are you... trying to interact with a non-http service using requests?

plucky vault
#

thank you for explain lol

#

i liturally don't know what to do

#

ooo

#

thats it

marble cape
#

@naive nacelle I gave you the twitch streamer role. Do you do YouTube as well?

tawny oak
#

is stream down?
edit: I think Yes!

plucky vault
#

Yes

#

My pc died

#

5 min ๐Ÿ˜‚๐Ÿ˜‚

tawny oak
#

okie! but keep going bro โค๏ธ

plucky vault
#

Yah

#

okay im back

#

sorry for that guys my pc crashed

#

bruh i alredy did that room

tawny oak
#

Any hints or tricks u can recall from his video that he used completing it or anything that can be helpful (mislead + maybe time waste)

plucky vault
#

idk what to try

#

brb in 5 min

tawny oak
#

I think... It's all in our front, we just can't see them yet. There is no way John didn't just used Pickel for making this room. Something phishy is there... I'm also checking all related things right now.

#

What happened now Elf?๐Ÿ™

plucky vault
#

Aaa my pc crashed

#

....

#

I cant stream tonight 2 many technical issues smh...

#

Lmfao

tawny oak
#

Nothing's in here

plucky vault
#

Yeah im in bed just started watching ๐Ÿ˜‚ thanks for hints you are really awsome

#

@tawny oaknoted lol ๐Ÿ˜‚

livid crag
woeful rock
#

Kitten @wise mortar

plucky vault
#

@tawny oak xD

tawny oak
#

really sry elf, I was gone for lunch! but I recorded everything to watch later
and now.... I'm back!

#

so... did u tried passing whole 01010101 raw file for unpickling?
(most suspecious)

did u tried raw hex converted file to unpickle

plucky vault
#

hex?

#

hmm

tawny oak
#

maybe? we should try evreything na?

plucky vault
#

yah im doing that xD

tame ether
#

@plucky vault try re-decoding the 0/1 to the pickle file with this, I think you might have some bad chars inside:
cat creds | perl -lpe '$_=pack"B*",$_'>creds.pickle

plucky vault
#

this one works tho

tame ether
#

also don't use loops

#

when reading

plucky vault
#

wow

#

thank you xD

tame ether
#

told ya :)

tawny oak
#

๐Ÿ˜น hmmm... that was simple!

plucky vault
#

yep xD

#

but i will have to go soon ๐Ÿ˜ฆ

tawny oak
#

keeep doing, dont' waste itme

#

time

#

fazt

plucky vault
#

im eating lol xD

tawny oak
#

lol, then eat, don't stream! and peacefully go school!

plucky vault
#

no ๐Ÿ˜„

#

i go finish school stuff and then go back to completing this

tawny oak
#

noice!

plucky vault
#

fun fact: im eating pickles

tawny oak
#

๐Ÿ˜น lol, don't eat them! they r extremely difficult (in a way ๐Ÿ˜› )

plucky vault
#

they are cut idk how to explain xD

#

this needs some json

tawny oak
#

can't think (i do remember 1 thing, but let me find)

naive nacelle
#

@Dark Thank you! No youtube :)

tawny oak
plucky vault
#

maybe

tame ether
#

nope

plucky vault
#

my class starts in 6 minutes guys

#

i will see you in like 1 hour or maybe 1 and a half

tame ether
#

go to class :)

plucky vault
#

yes i go to class xD

tame ether
#

@plucky vault pls automate that, it'll be a good python excercise :)

plucky vault
#

lol

#

idk how to automate tuples xD

tame ether
#

tuple is a list

#

but can have different types

plucky vault
#

eh

#

i mean... it kinda works

#

xD

#

it just needs a little bit

#

of you know

#

fixing

#

xD

#

ooo i came up with a great idea

#

@tame ether ๐Ÿ˜„

tawny oak
#

what did I missed? ๐Ÿ˜›

plucky vault
#

xD

zenith cradle
#

high quality pickles :))

plucky vault
#

yes

zenith cradle
#

do we even allow copyrights here

#

?

#

xDD

plucky vault
#

who where

forest python
#

@plucky vault Netcat -e VERY VERY VERY rarely works

#

Don't trust it

#

@plucky vault nc -e only works for a certain version of netcat

#

On ubuntu, you will practically never have that version installed.

plucky vault
#

๐Ÿ˜ฆ

forest python
#

@plucky vault Learn how to use SSH keys.

#

They make upgrading the shell super easy if SSH is installed

plucky vault
#

ssh keys

#

hang on i heard of those

forest python
#

Yes, SSH keys.

#

@plucky vault Don't copy paste commands reee

#

Learn how to use.

#

man ssh-keygen @plucky vault on your host

#

I mean I have 3 commands saved that get you a better shell

plucky vault
#

you helped me ๐Ÿ˜‚

#

i think im gonna read the ssh-keygen

forest python
#

@plucky vault pwd

#

Find where you are first.

plucky vault
#

/home/dill i think

forest python
#

You think?

#

Find out for certain

#

Don't make assumptions

tawny oak
#

Mind: I need a better thing than ls -la ๐Ÿค”. I should Google it.

Elf: ls -la but BETTER.

plucky vault
#

im not in dill

forest python
#

believe me, you don't need to read much of the code

#

You have RCE

#

Use it.

zealous prism
#

Try to rub that Py script! it's may reverse a shell

#

use*

forest python
#

@plucky vault Why sudo ssh?

#

That's a terrible idea

#

Stop running code as root when you don't need to

plucky vault
#

hm

#

okay

#

ty

forest python
#

@plucky vault Bad chmod command

#

chmod perms file

#

you put 2 perms

plucky vault
#

i forgot the command ๐Ÿ˜‚

forest python
#

you also forgot something

azure moss
#

Shake ur mouse in happiness

#

lad

plucky vault
#

wait i think i got it

forest python
#

I wonder what failed to decode base64 could mean

tawny oak
#

u nice giving hints Ninja blobfingerguns

Just saying... :smh:

forest python
#

I aint giving hints

#

He doesn't know what to do here

plucky vault
#

quite liturally don't know anything ๐Ÿ˜‚

#

okay im back

forest python
#

It's a farm

#

It aint gonna just run base64 encoded commands

tawny oak
#

OMG! ๐Ÿ˜น

plucky vault
#

carrots don't grow on hills

#

i think?

#

oo i got something

#

@west sphinx wow you are typing really fast ๐Ÿ˜‚

forest python
#

@plucky vault Read the room description

#

@plucky vault ls -lah in the folder of the exe and tell me what the file type is

#

also file is a great command

#

It's not a bash script, I'll tell you that

#

You didn't do that in the folder

plucky vault
#

okay

#

i think i got something

#

nope im stuck again

valid night
#

Still going with Peak Hill?

forest python
#

ls /opt/peakhillwhatever

#

@valid night Couple days now...

valid night
tawny oak
#

ninja, I got root

#

but i can't able to select root.txt, let me send u screenshot

tame ether
#

hehe

#

this is the best part

forest python
#

@tawny oak Yea, it sucks

tawny oak
#

hint?

#

plox

forest python
#

I think john intentionally made it harder

tawny oak
#

๐Ÿ˜›

tame ether
#

yeah

forest python
#

Honestly, it's the only non hidden file in the dir

#

Quick way to cat it

#

use bash stuff

tame ether
#

:)

tawny oak
#

๐Ÿ˜ธ okay!

#

@plucky vault SEE, even I got root! u can also do it!

ps: u actually taught me python and pickle little little bit to solve this room! and yeah BASE64 does work!

#

is there a stupid (blank space) before the file?

I think using / / / / / something can access it?

or is there something different? @forest python

forest python
#

@tawny oak If you understand

#

There's not a blank space

#

I tried cat " root.txt"

#

I think zero width chars

tawny oak
#

u can do it ELF!

plucky vault
#

wow well thats nice to know ๐Ÿ˜‚

tawny oak
#

keep up

plucky vault
#

but im still stuck lol

forest python
#

You were looking at the right things

plucky vault
#

hm

tawny oak
#

ninja, can i scp whole folder to my local system and just open it with gui

plucky vault
#

i don't remember what i was looking at ๐Ÿ˜‚

tawny oak
#

lol ELF!

forest python
#

@tawny oak Maybe

#

@plucky vault the article about depickling untrusted data

plucky vault
#

well now we lost it

#

cuz uh my pc crashed

forest python
#

This is why you don't use private mode

#

You're leaving tracks anyway with files

plucky vault
#

and now i forgot how to use tmux xD

forest python
#

I don't use tmux very often

tardy beacon
#

Good afternoon

plucky vault
#

gm @tardy beacon

fresh solar
#

Shows us the creds @plucky vault ๐Ÿ˜›

plucky vault
#

wdym

fresh solar
#

Your login creds to THM๐Ÿ™„

forest python
#

@plucky vault Why block hors?

#

Hors is lovely

plucky vault
#

i didn't block anybody?

forest python
#

Your screen shows you blocked Horshark

plucky vault
#

i did not know that xD

#

@tardy beacon sorry if i blocked you

azure moss
#

Straight in with the tag

plucky vault
#

no fr i didn't know i blocked hem

tardy beacon
#

Lmao no worries

plucky vault
#

sry again xD

tame ether
fresh solar
tardy beacon
#

Aye, no problem :)

#

Oh well I'm out to do some botdev

tame ether
#

:D

tardy beacon
#

See y'all later folks :)

plucky vault
#

well gl ๐Ÿ˜„

forest python
#

@west sphinx plz mute your mic if you're not talking

plucky vault
#

i liturally still don't understand

plucky vault
#

not yet :jo:

forest python
#

@plucky vault that looks promising

#

Although

#

print "something" might indicate something to you

tawny oak
#

@forest python room completed!

i just cat-ed whole folder

cat /*

๐Ÿ˜›
It was in my mind whole time, I just didn't tried it

#

thankz ELF! ninja, szymex, etc!!!

#

โค๏ธ

#

I'm still watching u elf! ๐Ÿ˜ƒ

plucky vault
#

gj

#

better then me lol

forest python
#

@tawny oak cat * is what I did

tawny oak
#

cat /root/*

#

yeah!

lean musk
#

this is riveting

plucky vault
#

i don't understand this

#

like at all

tawny oak
#

sudo /opt/....that stupid file

send commands in base64
that's all bro, u already reached there!

lean musk
#

legit is your monitor like 144p

plucky vault
#

no here let me show you my monitor

lean musk
#

fair enough

tame ether
#

omg

tawny oak
#

i think ELF is exuasted and can't think straight!
relax for min or two