#koth

1 messages ยท Page 1 of 1 (latest)

karmic beacon
#

anyone want to do a koth

#

it starts in 14 minutes

karmic beacon
#

starts in 9 minutes

karmic beacon
#

strats in 24 minustes

karmic beacon
#

starts in 24 miutes

jovial field
#

got someone cheating

#

[ terra2 ~ ]# ssh terraminator@10.10.99.90 -p 1337
terraminator@10.10.99.90's password:
Welcome to Ubuntu 16.04.3 LTS (GNU/Linux 4.4.0-87-generic x86_64)

239 packages can be updated.
151 updates are security updates.

The programs included with the Ubuntu system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Ubuntu comes with ABSOLUTELY NO WARRANTY, to the extent permitted by
applicable law.

The programs included with the Ubuntu system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Ubuntu comes with ABSOLUTELY NO WARRANTY, to the extent permitted by
applicable law.

Last login: Fri Jul 22 14:27:03 2022 from 10.8.41.76
Connection to 10.10.99.90 closed.

#

oot@lion:/home# cd gloria/
root@lion:/home/gloria# ls
user.txt
root@lion:/home/gloria# catHangup
sh: 1: Cannot set tty process group (Inappropriate ioctl for device)
[1] + Hangup bash

bash

#

msf6 exploit(multi/http/nostromo_code_exec) > run

[] Started reverse TCP handler on 10.8.41.76:4444
[
] Running automatic check ("set AutoCheck false" to disable)
[-] Exploit aborted due to failure: unknown: Cannot reliably check exploitability. "set ForceExploit true" to override check result.
[*] Exploit completed, but no session was created.
msf6 exploit(multi/http/nostromo_code_exec) >

#

and the nostromo service on port 8080 isnt reachable

#

same thing with the gloria account

karmic beacon
#

Do you get points if you do koth?

#

starts in 24 min

karmic beacon
#

You can still join this one

#

there is 7 mintues left

#

We just need 5 more people for it to be full

#

3 minutes left

#

to join

#

2 minutes left to join

#

4 more people till 10 people

#

1 min left.. quick

inner nexus
karmic beacon
#

I see

#

thanks

inner nexus
#

also wanna join my koth tourney?

karmic beacon
#

sorry was doing a koth

inner nexus
#

the*

fossil pecan
karmic beacon
#

starts in 24 minutes

dusky spoke
#

What's the max players per lobby?

karmic beacon
#

starts in 11 mins

dusky spoke
sour vectorBOT
#

Gave +1 Rep to @karmic beacon

karmic beacon
#

you're welcome

#

starts in 3 mins

fossil pecan
karmic beacon
#

starts in 3m ins

swift laurel
#

Would anyone know whats going on here ?

proven garnet
#

Just cat it

naive goblet
#

could be a missing endline in the file... also generally you do not open ssh keys in text editors... though you tend to be able too

karmic beacon
swift laurel
stiff egret
#

So either text editor or file perms issue

naive goblet
#

someone set the perms to 000

muted cradle
#

What koth? How it works?

prisma roost
pearl gladeBOT
fossil pecan
#

anyone playing today?

haughty turtle
#

gg @fossil pecan

lime hollow
#

here goes my first!

lime hollow
#

i don't get it at ALL ๐Ÿ˜‚

#

is it me noobing hard or is something wrong?

fossil pecan
#

hogwarts is a hell of an intro box haha

lime hollow
#

yeah i can see that ๐Ÿ˜„

fossil pecan
#

gotta do full port scan

#

4 main ports are random high ports

lime hollow
#

already got them

fossil pecan
#

entrypoints are random each game on hogwarts (port numbers, passwords, etc)

lime hollow
#

discreetly hiding that whitespace decode tab

#

do you mind voice chat for a bit after it's done?

#

still trying to do "stuff" ๐Ÿ˜‚

fossil pecan
lime hollow
#

well

#

@fossil pecan congratz ^^

#

tough fight!

#

OMG!

#

hahahaha

fossil pecan
sour vectorBOT
#

Gave +1 Rep to @lime hollow

fossil pecan
#

I can jump in voice soon if you still want

lime hollow
#

yeah of course

#

jsut found a flag

quiet schooner
steep agate
#

lol

gritty stirrup
inner nexus
#

Ooga wooga Dorito choosa

random trellis
inner nexus
quiet schooner
inner nexus
quiet schooner
inner nexus
#

Have you ever had it

quiet schooner
inner nexus
#

It was not really spamming I was telling ramgharia I want Doritos

uneven sedge
#

Doing so in particularly poor taste

inner nexus
#

Can I make a Dorito themed koth box?

#

Oh wait should I ask that in support

uneven sedge
#

Don't think it'll get accepted

inner nexus
#

Fsfs

random trellis
#

@stiff egret @quiet schooner @nova tide i have a humble request that if deleting /sbin/nologin from KOTH Machine is not allowed then please add it in rules.....
I mean what will be the fun of playing if no one will be able to login, when i tell anyone to stop doing this they says its not written anywhere in rules that you cant delete /sbin/nologin

quiet schooner
#

I'm not responsible for koth in any way.

#

But that sounds like a denial of service which is explicitly against the rules

#

You do not need to spell out what's against the rules, otherwise you'd have to enumerate every binary you're allowed or not allowed to delete.

random trellis
quiet schooner
#

If people are breaking the rules, report them. Don't try and argue with them.

random trellis
#

i reported once more than a week ago but got no response

stiff egret
#

If you didn't get any response, it's likely that we weren't able to take much action on the reported user, likely because of lack of enough evidence.

stiff egret
random trellis
stiff egret
#

Deleting /sbin/nologin is not allowed.

random trellis
#

thanks

random trellis
jovial field
#

@steep agate are you able to do something else then spamming /dev/urandom ???

steep agate
#

I'll stop laughing sending urandom, and I'll be watching the logs, good luck!

jovial field
#

lol now just pkill?

#

i see

steep agate
#

๐Ÿคฃ

#

what an angry guy in a game

jovial field
#

lul got root with your diamorphine

#

xD

steep agate
#

dmesg

#

or

#

cat /var/log/kern.log | grep diamorphine

#

the @fossil pecan has a rootkit based on diamorphine with a sigkill different from the default, his is more appealing because the sigkill to hide the process and return the process is different

steep agate
#

30 minutes have passed, you can stay in the king, thanks for the match, you played well!

jovial field
#

you too

fossil pecan
steep agate
#

It's always good to learn new things!

fossil pecan
#

LEARN ALL THE THINGS! ๐Ÿ˜›

steep agate
fossil pecan
#

here's the xcellerator blog series i found, learned all my rootkit stuffs starting with this ๐Ÿ‘
https://xcellerator.github.io/posts/linux_rootkits_01

steep agate
#

linux hidden process is really cool

radiant sun
fossil pecan
cinder apex
cursive ether
leaden knoll
#

TheMeme

#

You played dirty

random trellis
quartz thistle
#

@leaden knoll you pulled up

jovial field
#

@steep agate is it even possible to bruteforce ashus backdoor?

#

I tried it 30 minutes with rockyou.txt and still no hit

naive goblet
#

you sure the other players did not patch it by changing the password???

steep agate
jovial field
#

so i thought this is the only way left

naive goblet
#

not played koth so dunno ยฏ_(ใƒ„)_/ยฏ

steep agate
jovial field
#

yes port 9002 down

#

and i tried to bruteforce 9001

steep agate
#

there's a backdoor that the shell is limited, I confess that at first I racked my brains to know how it works, but then it's ok

jovial field
#

yeah i know but after two minutes the connection got refused

steep agate
#

oh I don't know what happened, I just know that there are two backdoors, and one has to have the password

jovial field
#

All good

steep agate
#

if I'm not mistaken it's "yourmom" something

jovial field
#

?

steep agate
#

the password

jovial field
#

ok thank you for the hint

steep agate
#

xD

jovial field
#

lul this massco99 killed every service but is still loosing because he cant break the king.txt

dry fossil
random trellis
radiant sun
#

Dangerous people playing koth bruh

random trellis
#

@radiant sun check this guy bro

#

going to report him

#

i have screen recorded too

#

he still lost the match

#

using while loop to attack other users is not allowed right?

radiant sun
#

That spam echo thing he doing I donโ€™t think thatโ€™s rule breaking

#

But if heโ€™s using while on killing sessions or ssh service lol that surely is

random trellis
#

he deleted nologin

radiant sun
#

Mattheu is in another dimension ๐Ÿ˜‚

steep agate
steep agate
steep agate
#

he came to my DM, giving rage saying that I play koth for a long time and that I'm dehumilde and don't help anyone, and that their friends get mad because when they play with me they never win

#

@random trellis

#

but then I talked to him, and everything was fine.

#

he already did the same thing to me, deleted nologin

random trellis
steep agate
#

๐Ÿคฃ

vapid condor
#

Well, Welcome here guys

cinder apex
vapid condor
#

How are we suppost to do something against this guy

cinder apex
#

yes

#

he is very good

vapid condor
#

what yes

#

Well I see

#

but

plain badge
#

nice match @random trellis, many things learned ๐Ÿ˜‚

random trellis
random trellis
stiff egret
#

lmao, P.S. this game is just 100% fun. I am on a new laptop and have absolutely no proper workspace setup for any competition

steep agate
#

i playing lol

random trellis
stiff egret
#

I am basically trying to understand how to continue using windows on my laptop and not break it.

random trellis
steep agate
stiff egret
radiant sun
#

still (:

random trellis
#

i will try my best if i not gone kicked๐Ÿคฃ

stiff egret
#

I will consider it a win if I am able to even get a root shell today ngl.

#

lmao, with no shortcuts and keybinds, it is hard enough already, I am sure as hell not playing windows, in which I am as bad as I am in french.

#

ps I have no idea about french.

#

wait

#

yeah

#

windows I left

random trellis
#

@steep agate i was thinking for xfreerdp and you patched that too๐Ÿคฃ

steep agate
#

it's very hard to play lol and koth at the same time but i try ๐Ÿคฃ

karmic beacon
cinder apex
#

Is this legal to to do

jovial field
#

no this was me testing my rootkit sorry

#

just vote to reset the machine

radiant sun
cursive ether
cursive ether
jovial field
#

anyone up for koth?

fluid merlin
#

@random trellis i want to practice KoTH with you, Is it possible? btw i am a script kiddie

shadow pivot
#

1min

fossil pecan
random trellis
cinder apex
steep agate
#

lol @TheJinn007

marble turtle
#

Dang lol

random trellis
haughty turtle
stiff egret
#

lmao

stiff egret
#

You know deleting netstat comes under system binaries? @fossil pecan

fossil pecan
#

I don't delete things ๐Ÿ˜œ

stiff egret
#

only 3 of us in machine, h00dy didn't, and nor did I.

fossil pecan
#

๐Ÿคทโ€โ™‚๏ธ

#

I'm just here to hangout, I'm working - can't really play haha

fossil pecan
#

just checked brand new game

export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
which netstat
which: no netstat in (/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin)
stiff egret
#

I defo forgot that then. My bad

fossil pecan
#

GG @radiant sun @stiff egret - was fun to watch ๐Ÿ˜„

shadow pivot
#

25 min

#

10 min to start

jovial field
radiant sun
#

what's up

#

who's this

naive goblet
#

upload busybox and use that for ls???

radiant sun
naive goblet
#

uh oh someone broke the machine

quiet schooner
jovial field
cinder apex
marble turtle
#

I AM TRASH LOL

steep agate
radiant sun
#

terraminator

marble turtle
#

I'm serv3 lets fucking goooooo

steep agate
marble turtle
#

managed to get serv3 and a flag. Couldn't escalate privs. Like my 2nd game though so I'm happy I got points lol

#

also managed to find admin admin credentials and a cookie. tried ssh but didn't really have much of a clue where to go from there

random trellis
#

but you have to find that panel๐Ÿ˜‰

haughty turtle
#

and also these entrances will get patched if u playing against these good playerskekw

random trellis
haughty turtle
#

yea bro fair play i know but it takes too long for me to just get in haha

#

im learning

#

and once im root i have no idea what to patch and how to patch those

random trellis
#

@steep agate that pwnzy guy came in my chats and started giving rage that because of you my frnds stopped playing KOTH, because last month you played 8hrs a day and i win because i cheat....

Well i never kicked someone, never changed password, i mostly plays after 10 mins of starting, how much more fair i can play now๐Ÿฅฒ

random trellis
haughty turtle
#

how about patching the way we get in?

random trellis
haughty turtle
#

if i get in with ssh, i just change the machine pub to my pub

#

but patching like sql and web, i have no experience at all

random trellis
haughty turtle
sour vectorBOT
#

Gave +1 Rep to @random trellis

haughty turtle
#

for now i just do linux koth

#

for window i just leave the roomkekw

random trellis
steep agate
haughty turtle
random trellis
#

and this was his hard script

#

๐Ÿคฃ

steep agate
haughty turtle
#

what do to again this? one guy has root and close all the port except 9999?

nova tide
haughty turtle
#

can't ssh either

#

any other entrance?

stiff egret
#

Game ID?

haughty turtle
#

i'm out of the room already sorry can't get it

willow raptor
stiff egret
#

That's alright, in case you get into such situation, feel free to report this, this is just dirty gaming and rule breaking in a happy mix.

haughty turtle
#

yes that one

stiff egret
#

ah, it's the same user, the problem right now is, there are a lot of other users in the same game, I can't really point it to one user.
@nova tide wasn't there more reports on the same guy?

nova tide
haughty turtle
#

one more question just in general, when the koth box is really slow, what might cause that? is it my own vm or the box cuz when i practice in private game, sometimes it just really slow to load any web

haughty turtle
#

i pressed reset but only 2 votes so i just left it

stiff egret
#

Generally, it's the VPN, but if there are players with experience in the box, it is likely that they are running pspy inside. Slow machine is a telltale sign of that script.

haughty turtle
stiff egret
#

So, try the pings on any other machine in tryhackme, and if that is all okay, then it's pspy or someone hammering the machine with some or the other bruteforcing tool.

haughty turtle
#

so i think it's just my VPN issue

haughty turtle
sour vectorBOT
#

Gave +1 Rep to @stiff egret

haughty turtle
#

i just practice alone for now

stiff egret
#

Rule of thumb, give it 2-3 minutes to boot up, I know that Hogwarts and almost all windows machines are slow to boot.

haughty turtle
#

yes thank you for tellingblobfingerguns

urban bloom
random trellis
random trellis
cursive ether
fluid merlin
jovial field
#

he did it to me too but lost anyway because he wasnt able to see that he hasnt any write perms on king.txt

cursive ether
#

@radiant sun did you really have to do that?๐Ÿ˜‚

radiant sun
#

hehe

#

you in match?

cursive ether
radiant sun
#

which one are you?

#

THe meme?

cursive ether
radiant sun
#

i thought it was spidey bruh lol

cursive ether
haughty turtle
cursive ether
cursive ether
#

@radiant sun @crimson light ๐Ÿ˜‚ stop it guys

radiant sun
#

hehe

cursive ether
gritty stirrup
#

Yoo

urban bloom
cursive ether
urban bloom
jovial field
#

lol if i try to join a public game it errors out and says Uh-oh, this page has been lost in the matrix.

#

and it shows object object dont know what this is

nova tide
urban bloom
nova tide
urban bloom
#

๐Ÿ˜ Just kidding... I know and I respect the rules

urban bloom
urban bloom
# jovial field

Working fine for me... Sometimes error occurs when you try to join 3 or 4 machines at a time

fossil pecan
sour vectorBOT
#

Gave +1 Rep to @fossil pecan

marble turtle
sour vectorBOT
#

Gave +1 Rep to @random trellis

stiff egret
fossil pecan
sleek ocean
#

@fossil pecan is giving me a hard time at koth

fossil pecan
#

โค๏ธ

steep agate
haughty turtle
#

can anyone give me a hint of where the 8th flag of panda? i can't never find it. is it in source code?

near lily
haughty turtle
#

spare me don't send me urandom kekw

haughty turtle
#

one of them i don't know

#

let them challenge im just gonna mind my learning here

cursive ether
haughty turtle
#

the only way that i know to get root is patched now im playing with PATH thing but don't know how lol

#

finally holy

#

what is king.txtecho?

#

anyway thanks guy for sparing me

#

gg im satisfy now

cursive ether
#

haha

random trellis
#

@haughty turtle this is all i was doing

#

king.txtecho made by me by mistake ๐Ÿคฃ you can see upward

haughty turtle
#

u not dong a while loop?

random trellis
#

hahahha no

#

i was just changing king at last secs

haughty turtle
#

i know somebody was doing a while loop cuz right after i put my name it changed instantly

random trellis
#

i never use any loop bro

haughty turtle
#

at least no dirty play that time

#

i got only 2 urandom

#

๐Ÿ˜‚

random trellis
#

nothing more

haughty turtle
#

ohh btw what that port 9001 9002 do

#

my web keep loading forever

random trellis
#

and i did

echo "root ALL=(ALL:ALL) ALL" > /etc/sudoers

i dont think its cheating

random trellis
haughty turtle
haughty turtle
sour vectorBOT
#

Gave +1 Rep to @random trellis

haughty turtle
#

but i get random room cuz im not subscriber

random trellis
haughty turtle
#

u spared me that time or u didn't see my ssh key?

random trellis
random trellis
haughty turtle
#

and i got root by using path exploit thing

random trellis
haughty turtle
#

yes haha

#

the only way i know to get in

random trellis
#

there something hidden thing, change your path and you can get root

haughty turtle
#

i see something name hidden in tmp

#

but i get root with homework

radiant sun
cursive ether
radiant sun
cursive ether
#

yup thats exactly you

cursive ether
manic atlas
#

I see that there are links to a panda.thm site... are these links broken or is there a way to access them?

cursive ether
gritty stirrup
manic atlas
#

oh ok

cursive ether
random trellis
#

i was not talking about you bro, it was someone who had reverse shell with with python and if i am not wrong you got reverse shell with bash๐Ÿ˜…

#

i saw that but havnt killed your process

whole whale
random trellis
#

@cobalt mountain stop doing reset spams

cobalt mountain
#

What about you? What have you done stop calling me ๐Ÿ˜

random trellis
#

why dont you try tdurden user

#

you changed password of narrator, so i logged in through tdurden and i also changed all passwords

plain badge
#

@random trellis this guy again? ๐Ÿ˜‚

plain badge
#

@cobalt mountain you like to send urandom to your friend's terminal, right? ๐Ÿ˜‚

#

if I do the same to you, I'm sure you never play koth again

#

๐Ÿ™‚

cobalt mountain
#

Show me that ๐Ÿ˜‚๐Ÿ˜‚

plain badge
#

I don't even need it, this is script kiddie stuff ๐Ÿ˜

cobalt mountain
#

When I see the mentalities of some, my self-esteem increases

plain badge
#

that's good bro, you need to grow up

#

for those of you who need to play urandom on the little friend's terminal, which can only be accessed via id_rsa and id_rsa.pub, you really need to grow up

cobalt mountain
#

yea

steep agate
plain badge
#

CLOSE, SO CLOSE @fossil pecan , nice match

cursive ether
fossil pecan
#

Next up @fair meteor VS @steep agate !

Come watch and hang out!

https://F11snipe.live

random trellis
edgy knoll
#

We've forgotten about this thm server it's been so long ๐Ÿ˜‚

#

We've migrated

fossil pecan
fossil pecan
jovial field
#

if someone has premium and could create a private match for me please write to me. I have to prepare for the match against Matheuz.

haughty turtle
#

creepypog against the top 1

karmic beacon
fair adder
#

Hello guys, I'm new in koth game and I was wondering what do you think is the best way to learn (in particular the defence)

jovial field
haughty turtle
radiant sun
radiant sun
cursive ether
#

@radiant sun hey, can i hit you up?๐Ÿ˜‚

radiant sun
#

yeah

half quartz
steep agate
sleek ocean
#

Oh no koth windows

#

i wonder is tryhackme koth is anything like hackthebox's battlegrounds

#

coming from htb

radiant sun
plush venture
#

Heeeeeellooo, who's Jinux, I have some question about the game we've been playing ๐Ÿ™‚

plush venture
#

Nevermind, I found a tutorial... I'm a dumb ass who overthink :/

half quartz
sour vectorBOT
#

Gave +1 Rep to @steep agate

half quartz
#

Did someone encode the first flag on Panda?? Pretty sure it didn't use to be like that.. ๐Ÿค”

steep agate
#

you and me give a good fight for king on windows machines, you play well!

median tapir
#

How come the ssh password in the Food mysql database isn't working

#

Hello? anyone?๐Ÿ‘‹ ๐Ÿ‘€

nova tide
half quartz
sour vectorBOT
#

Gave +1 Rep to @steep agate

steep agate
craggy jasper
#

@random trellis I have a question regarding the box we are currently on. Mind sending me a DM?

random trellis
#

are you talking about hackers machine @craggy jasper ??

craggy jasper
#

Yes that one

#

Just wanted to know if my vector would have been correct and you just already patched it

random trellis
#

i patched it

#

now there were entry points open but you cant get root

random trellis
craggy jasper
#

Trying to use a combination of
usernames -> derived from the staff page and thier general username schema
passwords -> mentioned in the note

On a login portal I found

#

But no cigar ๐Ÿ™‚

random trellis
#

which are given in notes

craggy jasper
#

Trying not to get too specific on this channel to not spoil the fun for others

craggy jasper
#

Also tried boolean based blind sqli on the login form without success

random trellis
craggy jasper
#

yes

random trellis
#

you need to brute force it

craggy jasper
#

._. ok thnx

random trellis
craggy jasper
#

Hahaha ok will give it another long look ๐Ÿ˜‰

Sadly, no matter what vpn endpoint I use, I do not get a connection stable enough for login bruteforcing. Dunno if thats me or THM has some sort of issue rn.

#

ยฏ_(ใƒ„)_/ยฏ

random trellis
craggy jasper
#

No worries. I am not in a hurry ๐Ÿ™‚

#

Oh damn... face -> table.

It's a routing issue. Dockers default network adress space is colliding with THMs...

I knew it was me ๐Ÿ™ƒ

stiff egret
#

That's a first

jovial field
#

anyone up for koth?

jovial field
half quartz
#

Hahah somebody's trolling me @random trellis ๐Ÿ˜‚

random trellis
haughty turtle
#

how to u make that ascii art? is it pure coding or there is any generator?

random trellis
haughty turtle
sour vectorBOT
#

Gave +1 Rep to @random trellis

steep agate
#

good morning

plush venture
#

Hello @random trellis, I saw you many time on some koth rooms, I'm wondering if there's some rabbit hole on koth rooms, or maybe they are some entry point that I don't search enough for ๐Ÿ™‚

Like in the Shrek one, there is at least 4 or 5 way to get in, right ?

random trellis
plush venture
#

Thank you @random trellis

sour vectorBOT
#

Gave +1 Rep to @random trellis

quiet schooner
steep agate
#

right

gritty stirrup
#

Hey

#

Who wants to play an koth

unborn heath
#

any hints for Hogwarts KOTH?

near lily
#

Cast a spell.

celest salmon
#

@steep agate Are you playing 2 games at the same time?

celest salmon
#

Was just wondering, really cool

steep agate
#

It's totally possible to play 2 or 3 koth games, you get king in a game and then enter another game

steep agate
celest salmon
#

Just amazes me how good you are at this, lol

cursive ether
random trellis
#

@fair meteor why are you stopping KOTH services again and again

#

I am screen recording this time and if i found you doing this once again going to send it to KOTH staff

fair meteor
#

alright

#

@random trellis im not stopping again

#

i see u got through using tomcat nice

half quartz
valid cairn
valid cairn
steep agate
valid cairn
valid cairn
# steep agate xD

we have a one year age gap so I really look up to you!
I even got a samurai animated banner after looking at your phoenix

#

SO thank you for motivating me!

steep agate
steep agate
steep agate
steep agate
valid cairn
#

I should choose a new one too

#

can I take your old one?

#

@steep agate

#

if its a yes please dm me the GIF

half quartz
#

@steep agate officially over 1000 games won!! CONGRATS!!!

narrow tiger
#

@random trellis hey

random trellis
narrow tiger
#

How did you change port 9999 to ur name

narrow tiger
random trellis
narrow tiger
#

Where

#

Directly in terminal

#

I have no access currently

#

I can't even login in ssh

random trellis
narrow tiger
#

Ya

#

Thats y i can see ur changes

random trellis
#

which machine?

#

i havnt changed anything

narrow tiger
#

Space jam

random trellis
#

ohh space jam

narrow tiger
#

U found 2 flags

random trellis
#

i did king from command injection and added chattr to king and removed chatttr from /usr/bin

#

nothing more

narrow tiger
#

I didn't understand that

random trellis
#

i can only say you that keep trying machine is very easy

narrow tiger
#

K

random trellis
steep agate
steep agate
sour vectorBOT
#

Gave +1 Rep to @half quartz

valid cairn
sour vectorBOT
#

Gave +1 Rep to @steep agate

cedar cipher
steep agate
plain badge
half quartz
#

Hey Heyy KOTH players! I see @random trellis has officially hit over 500 wins!! It's turning into quite the celebratory week- Good Job Guys!!! ๐Ÿ‘ ๐Ÿ† ๐Ÿฅ‡

sour vectorBOT
#

Gave +1 Rep to @half quartz

narrow tiger
#

@random trellis

random trellis
pearl crane
#

i think the machine is broken, isnt hogwarts supposed to have a http server on 22?

#

@tranquil pewter can you reset? im 90% sure its broken

haughty turtle
#

22 is ssh by default

pearl crane
#

its http on nmap, and curling it returns html

#

but firefox is blocking it right now

haughty turtle
stiff egret
#

The ports are higher in the list, give the scans some time to finish

stiff egret
#

The machine is sometimes slow.

radiant sun
wary citrus
random trellis
wary citrus
#

thanks,you too

random trellis
sour vectorBOT
#

Gave +1 Rep to @wary citrus

wary citrus
#

that was fast

radiant sun
random trellis
#

why?? ๐Ÿ˜ญ

#

@stiff egret @nova tide

stiff egret
#

I'd say this is best answered by staff or you can appeal the ban on website. I am not sure how much I am supposed to disclose here. And for you reputation, you won't want me doing that either.

cc: @short tusk

short tusk
#

-ban 899296404906868766 Site banned for redeeming fraudulent vouchers.

sour vectorBOT
#

๐Ÿ”จ Banned RamghariaSaab#9825 indefinitely

fossil pecan
#

Who's up for some games today? Excited to get back into it ๐Ÿ˜

jovial field
#

who is up for a koth?

cobalt mountain
#

GG

valid cairn
#

wanna play koth anyone?

valid cairn
#

that is why we must do stuff with honesty!

fiery sedge
fair adder
#

hella

prisma roost
#

@fossil pecan ๐Ÿ‘€

fossil pecan
#

Haha not me, forgot i joined a game lol

half quartz
static plover
#

sorry bro

stiff egret
#

I saw that when I goddamn woke up

fair adder
#

Hey, everyone.From which point on would you recommend me to try out koth? Like, are there also easier ones, where you battle against not so experienced players or how does it work?

haughty turtle
jovial field
#

i recommend you taking notes because you will have it easier when you know the machines

#

the machines wont be changed anyways xD

jovial field
stiff egret
#

Oh god that is one example of failed reverse shell loop

burnt geyser
burnt geyser
static plover
#

@stiff egret I'm crazy yk, is it allowed to upload custom jumpscare html?

stiff egret
#

As long as you don't disrupt the main webpage.
Generally it's allowed to upload anything, but the rule of thumb, don't remove services that can be otherwise patched without affecting their functionality.
Afterall that's what you do in real world scenarios.

static plover
#

Ohh okay

#

rn random guy disabled ssh port

#

thats forbbiden i guess

nova tide
static plover
#

no its not

#

i was do -p-

static plover
#

@MIDHUNGRAJ

#

guy called MIDHUNGRAJ

#

he is fking disabled every port

#

i was first get into shell

#

took root

#

he was edit king.txt

#

and removed everything from /usr/bin

#

wtf guys

quiet schooner
candid timber
candid timber
naive goblet
#

sneaky way to fake emoji/emotes right there

candid timber
fair adder
#

anyone wanna do a private koth with me?

#

if anyone does, dm me

half quartz
#

Do any KOTH players here have their OSCP certification?

forest plume
#

Hello. I want to team up with two friends and do challenges and got recommended this here Koth from #subscriber - Wondering if anyone can explain how this works.

We are 3 people and will all be subscribers.

fossil pecan
#

outlines & rules/faq's ^ here are pretty good, I've been playing a ton of koth last few months (a bit of a break past couple weeks tho haha) ... I'd be happy to help answer any questions, or even jump in VC to chat sometime, let me know ๐Ÿ˜„

forest plume
#

Awesome man, thank you so much. If I have any questions I'll be in touch ๐Ÿ™‚ โค๏ธ

fair adder
#

Is It Allow To Stop SSH Service in KOTH ?

nova tide
fair adder
#

@nova tide but some one is doing it there is no ssh on this ip I Scan All Port No SSH Find But In Start There was a ssh open

nova tide
fair adder
nova tide
#

!email

pearl gladeBOT
#
TryHackMe
Contact us for support, teaching enquires and more!
fossil pecan
#

Who's up for some KoTH today?

wary adder
fossil pecan
wary adder
#

@fossil pecan what's the code for this one?

fossil pecan
wary adder
fossil pecan
#

Can jump in current lobby from the KoTH homepage for public matches

#

Or can do private ones for practice

wary adder
#

oh freak, windows box

#

๐Ÿ’€

fossil pecan
#

๐Ÿคฆโ€โ™‚๏ธ

wary adder
#

hahahah

fossil pecan
#

next 23min lol

wary adder
#

Where tf is king.txt bro

#

๐Ÿ˜‚

#

you sly dawg

fossil pecan
#

You must be close, you get it in the next 5 min, you win ๐Ÿ˜

#

*and hold the rest of the game,i probably won't be back, hoping this next game is Linux lol

#

or i'll just skip flags ๐Ÿ˜‰

wary adder
#

bruh moment

#

i was out here doing something wild

#

and u could literally eternalblue the whole time

#

weeeeird, king isn't changing even though I've changed the file

#

gg

dense sigil
#

Hmm

#

Interesting

#

anyone up for some koth?

fossil pecan
#
curl $VMIP:9999
#

Mine showed up with broken characters and lots of extra spaces lol

#

But worked fine using normal SSH Shell ๐Ÿคทโ€โ™‚๏ธ๐Ÿ˜œ

haughty turtle
fossil pecan
#

Yup ๐Ÿ‘

fair adder
#

anyone wann ctf

remote pulsar
fair adder
#

alr

#

koth or normal

wary adder
#

bro im down for koth

#

i got smacked yesterday ๐Ÿชฆ

remote pulsar
remote pulsar
remote pulsar
fair adder
valid cairn
#

@fossil pecan had a great time playing with you and dang You are seriously skilled!

jovial field
steep agate
#

wtf '-'

haughty turtle
#

new place for king

steep agate
slim ledge
#

How do I play king of the hill?

nova tide
slim ledge
sour vectorBOT
#

Gave +1 Rep to @nova tide

dapper vigil
edgy knoll
#

how do i play

haughty turtle
rare warren
#

Anyone keen for a game?

unborn ice
#

where's king.txt in hogwarts machine ?๐Ÿคจ

lavish oyster
unborn ice
#

yeah thanks i did that

low dagger
#
call_cmd "echo '[USERNAME]' > king.txt "
call_cmd "chattr +i king.txt"

while [[ $(cat /root/king.txt) != "[usernameHere]" ]]; do chattr -i king.txt;echo "[usernamehere]" >> /root/king.txt; chattr +i king.txt; done```

Would this actually work?
haughty turtle
low dagger
haughty turtle
low dagger
valid cairn
unborn ice
#

@fossil pecan ๐Ÿ™‚

#

@fossil pecan what did you do to remove permissions of that file ๐Ÿค”

fossil pecan
#

multiple chattr flags (more than +i can control write method/locks) ๐Ÿ˜‰

#

lsattr

#

should show all attributes set

unborn ice
fossil pecan
#

always "BYOC" haha (bring your own chattr ๐Ÿ˜› )

dawn horizon
#

who TheLinuxBoy

high lark
#

how many games did u play yesterday

high lark
#

do you do other stuff outside THM?

valid cairn
#

They are so quick with it that they even have kicked me out of a box in which I was root and tried the best to secure it

haughty turtle
haughty turtle
valid cairn
#

Ik but I believe that its proficency of doing playing KOTH machines repetively over and over again that makes them so good at it

jovial field
#

is there any way someone could tell me how invite links are generated? OxSweat and some others got a project where they want to do private koth matches and send the invite link via a discord bot.

magic owl
#

si

fossil pecan
fossil pecan
fossil pecan
burnt glade
#

can root user change other users ssh password/remove auth key? is it allowed?

fossil pecan
#

ya would be considered a patch

burnt glade
#

oke

haughty turtle
low dagger
haughty turtle
low dagger
fossil pecan
#

I'm happy to help answer any questions, and help develop some of your own... I'm working on polishing some of my tools + scripts to share on GitHub soon (ish haha)

haughty turtle
low dagger
haughty turtle
haughty turtle
#

won't harm anyone

fossil pecan
high lark
#

when @fossil pecan and @steep agate not in your game

#

rn Matheu is in my game :(

steep agate
#

hii

#

i playing lol

steep agate
high lark
#

lol

fossil pecan
#

i'll get it started ๐Ÿ˜‰

steep agate
low dagger
fossil pecan
fossil pecan
#

next public, you're alreadyin ๐Ÿ˜„

#

GG last match btw ๐Ÿ˜›

haughty turtle
#

nice graph there lol

fair adder
#

Hey, did thm already start to randomize the koth flags or are they still the same for every room?

nova tide
fair adder
#

Why dont they randomize it? There is always some one in koth copy pasting them

low dagger
#

40 points off the maximum for this box

@fossil pecan Im slowly getting there xD

naive goblet
low dagger
naive goblet
#

think the max point calculation is just from the flags and not counting king time

naive goblet
low dagger
#

The longer you have your TryHackMe Username in the /root/king.txt file, the more points you get. You obtain 10 points every full-minute you are the current "King". To obtain 10 points, you must be the current "King" for 60 seconds (1 full-minute). If you are only the king for 50 seconds, you will not be awarded the 10 points, nor will the person who was "King" for the remaining 10 seconds of that minute. - Taken from THM help page

valid cairn
#

I hope you see that using Auto pwning or generally using scripts that give you way too much power is not allowed here.

low dagger
low dagger
valid cairn
low dagger
# valid cairn ez dw but I believe we need to have a more fair env but there are still people j...

cough @fossil pecan and @steep agate cough

Personally Iโ€™ve never done a public match yet as want to get my bearings and see whatโ€™s going on with them all with friends before I subject myself to that torture.

Me and my friend did SpaceJam (The pic I sent earlier today) and Hogwarts and I personally disliked it as even with my privesc it was near impossible to secure root (The king.txt file was missing too).

valid cairn
#

apart from that I think I have never won against these two

#

rn playing koth too lol

low dagger
# valid cairn its in ||tmp||

I kept looking in /root/ where I personally think it should be and itโ€™s expected in most of the Koth guides and i ended up only getting 50 points the entire match while my friend was still running his Nmap full port scan by the end of it.

#

Cause I heard the ports are random on each machine compared to the others

low dagger
valid cairn
#

try using rustscan

#

way faster.

low dagger
valid cairn
low dagger
valid cairn
#

send screen shots

steep agate
sour vectorBOT
#

Gave +1 Rep to @low dagger

low dagger
# valid cairn how you using it?

Tried using their install guide and just canโ€™t wrap my head around it. So I might try and compile it tomorrow as itโ€™s nearly 1am my time

valid cairn
#

I really need to find good resources on chattr binary

low dagger
naive goblet
#

maybe check the rustscan room

fossil pecan
naive goblet
#

it might help with installation

low dagger
low dagger
naive goblet
#

yuups

low dagger
naive goblet
valid cairn
steep agate
#

guys, I recommend that you use rootkits, create your own scripts to protect only king.txt

steep agate
naive goblet
#

shadow not trust themselves with rootkit stuffs

valid cairn
#

understaning root kits seems lit asf!

#

will check it out

low dagger
valid cairn
#

I would want to declare mathuez my koth rival but rn he is way too op

#

but not for long

#

I will come back stronger than ever!

steep agate
valid cairn
#

gives permission denied even after:
using -i and -a on chattr,
changing permissions for chattr

#

doesnt make sense tho

low dagger
#

In my CTF team (we ainโ€™t the best but somehow we get top 10% at times?), theyโ€™ve said Iโ€™m hands down the best in the team yet Iโ€™m actually horrific at web pentesting and also AD (Im trying to learn AD first)

valid cairn
#

I can usually get root in machines in like 2-3 mins

#

but then I sped the rest of the time researching how to change file perms

low dagger
valid cairn
low dagger
valid cairn
#

for now I gotta play more koth lol

low dagger
valid cairn
low dagger
valid cairn
#

but never played any Triple AAA title on pc ever

low dagger
valid cairn
low dagger
valid cairn
#

anyways you probs gotta go now so see ya! ๐Ÿ‘‹

valid cairn
#

good motive

low dagger
valid cairn
low dagger
valid cairn
low dagger
valid cairn
#

weird

magic owl
#

hi

jovial field
#

and it is slow

low dagger
jovial field
#

in all of mine it was deleted or replaced lol

wary adder
#

Yeah, that's usually the first step

#

To my understanding, what you wanna do is statically link a chattr binary so you can pull it up when you get access

valid cairn
#

@fossil pecan Good game brother!

naive goblet
#

oooh close to a tie

valid cairn
#

I lost at finding flags lol

#

I really tried hard but it has something to do with games

#

and I tried some but only found 1

mental birch
#

What is the best distro for beginners ?

#

Couz when I first started I jumped to kali and things was bad felt dumb on multiple occasions

#

๐Ÿ™‚

mental birch
#

Pov:me one day :)

naive goblet
#

for ease of use for daily driving??? pop os or linux mint
for only using for hacking??? kali linux or parrot os

mental birch
#

For THM :)

#

What do u use shadow?

#

Ubuntu right ?

naive goblet
#

yeah do not recommend shadows use case though

#

as shadow has to install a lot of things from source or sometimes installing things using the default repos

mental birch
#

So should I still go for kali but keep practicing ?

naive goblet
#

yeah would recommend a kali linux vm for all things tryhackme

sour vectorBOT
#

Gave +1 Rep to @naive goblet

naive goblet
#

it is kinda like having your own personal attackbox instance

mental birch
#

Alright ๐Ÿ‘

#

Btw shadow i can't keep my points and reset the rooms

naive goblet
#

hit cog button.... press reset room progress tada

mental birch
#

Can't login due to me forgetting my password and no clue which email

#

I'm still searching for it though might be somewhere in my 2nd account pins

naive goblet
#

oooh

#

yeah then maybe making a new account is easier

mental birch
#

Yup gonna subscribe too

#

Ah last thing pls

#

What order should I be doing first

#

Someone said I should got for pre sec before beginner path

mental birch
#

Offensive is far away Black_Movie_42

naive goblet
#

if you feel like you absoulutely need to do complete beginner stick it after junior pentester

#

yeah

#

it is a lot harder then the others with previous knowledge

mental birch
#

So this way I'm starting over , like 0 knowledge right ? Couz that's what I want

naive goblet
#

yuups

#

take plenty of notes

mental birch
#

Thanks I appreciate the help 864811785684385802 @naive goblet

sour vectorBOT
#

Gave +1 Rep to @naive goblet

mental birch
#

Ping for reps :)

mental birch
naive goblet
#

reps all over the place

mental birch
#

Haha

steep agate
mental birch
sour vectorBOT
#

Gave +1 Rep to @steep agate

haughty turtle
#

@fossil pecan patch first king later nice haha

#

i got all these but can't do anything

wary adder
#

i run all my assessments on a HM linux box

dry fossil
#

@valid cairn did u change the ssh password?

#

just curious

valid cairn
#

well atleast now

#

and btw I closed your shell so sorry for that

dry fossil
#

ok

valid cairn
#

Hey did yall just close ssh?

#

I did a nmap scan with -p- couldnt find 1 port for ssh?

dry fossil
#

@fossil pecan How'd you protect the king file? I can't change perms or write to it?

#

I checked noclobber and immutability

valid cairn
#

root kit lol

#

@fossil pecan you in through ssh?

#

or something else? cause the ssh ports seem to be closed

dry fossil
#

it's completely patched

valid cairn
#

ik lol

#

we can wait for this one to end!