#koth
1 messages ยท Page 1 of 1 (latest)
it starts in 14 minutes
starts in 9 minutes
strats in 24 minustes
starts in 24 miutes
got someone cheating
[ terra2 ~ ]# ssh terraminator@10.10.99.90 -p 1337
terraminator@10.10.99.90's password:
Welcome to Ubuntu 16.04.3 LTS (GNU/Linux 4.4.0-87-generic x86_64)
- Documentation: https://help.ubuntu.com
- Management: https://landscape.canonical.com
- Support: https://ubuntu.com/advantage
239 packages can be updated.
151 updates are security updates.
The programs included with the Ubuntu system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.
Ubuntu comes with ABSOLUTELY NO WARRANTY, to the extent permitted by
applicable law.
The programs included with the Ubuntu system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.
Ubuntu comes with ABSOLUTELY NO WARRANTY, to the extent permitted by
applicable law.
Last login: Fri Jul 22 14:27:03 2022 from 10.8.41.76
Connection to 10.10.99.90 closed.
oot@lion:/home# cd gloria/
root@lion:/home/gloria# ls
user.txt
root@lion:/home/gloria# catHangup
sh: 1: Cannot set tty process group (Inappropriate ioctl for device)
[1] + Hangup bash
bash
msf6 exploit(multi/http/nostromo_code_exec) > run
[] Started reverse TCP handler on 10.8.41.76:4444
[] Running automatic check ("set AutoCheck false" to disable)
[-] Exploit aborted due to failure: unknown: Cannot reliably check exploitability. "set ForceExploit true" to override check result.
[*] Exploit completed, but no session was created.
msf6 exploit(multi/http/nostromo_code_exec) >
and the nostromo service on port 8080 isnt reachable
[ terra2 ~/Desktop/koth/lion ]# ssh -i gloria.rsa gloria@10.10.99.90 -p 1337
Enter passphrase for key 'gloria.rsa':
Welcome to Ubuntu 16.04.3 LTS (GNU/Linux 4.4.0-87-generic x86_64)
- Documentation: https://help.ubuntu.com
- Management: https://landscape.canonical.com
- Support: https://ubuntu.com/advantage
239 packages can be updated.
151 updates are security updates.
Last login: Fri Jul 22 14:13:13 2022 from 10.18.20.108
Connection to 10.10.99.90 closed.
same thing with the gloria account
Do you get points if you do koth?
starts in 24 min
You can still join this one
there is 7 mintues left
We just need 5 more people for it to be full
3 minutes left
to join
2 minutes left to join
4 more people till 10 people
1 min left.. quick
I think you used to get points for putting in flags but idk anymore because it seems like a really easy way to farm
also wanna join my koth tourney?
sure
sorry was doing a koth
Streaming live matches to practice for tournament! Hogwarts is next, come say hi! ๐
https://youtu.be/PRXopkVxKhY
King of the Hill - Lion
Practice game on lion for KoTH tourny
starts in 24 minutes
What's the max players per lobby?
Thank you
Gave +1 Rep to @karmic beacon
you're welcome
starts in 3 mins
next game in 23min
https://tryhackme.com/games/koth/join/c9bbc845c2584205258894f8
starts in 3m ins
Just cat it
could be a missing endline in the file... also generally you do not open ssh keys in text editors... though you tend to be able too
Yeah i know you dont have to open them you still are suppose to be able too , I dont understand how out of sudden any RSA files doesnt work
So either text editor or file perms issue
someone set the perms to 000
What koth? How it works?
!docs koth
anyone playing today?
here goes my first!
i don't get it at ALL ๐
is it me noobing hard or is something wrong?
hogwarts is a hell of an intro box haha
yeah i can see that ๐
already got them
entrypoints are random each game on hogwarts (port numbers, passwords, etc)
discreetly hiding that whitespace decode tab
do you mind voice chat for a bit after it's done?
still trying to do "stuff" ๐
sure!
Haha, thanks!
Gave +1 Rep to @lime hollow
I can jump in voice soon if you still want
@steep agate #thm-community-media preferably
lol
This is "Tryhackme:koth H1:Easy Walk through" by kitaka joseph on Vimeo, the home for high quality videos and the people who love them.
Ooga wooga Dorito choosa
which language is this bro?
Da language of da Dorito muncher
What
Dori cheese ooga wooga nacho booga
What the hell are you talking about?
I want Doritos dinamita chili limon
Have you ever had it
Why are you spamming about it in the #koth channel?
It was not really spamming I was telling ramgharia I want Doritos
Doing so in particularly poor taste
Don't think it'll get accepted
Fsfs
@stiff egret @quiet schooner @nova tide i have a humble request that if deleting /sbin/nologin from KOTH Machine is not allowed then please add it in rules.....
I mean what will be the fun of playing if no one will be able to login, when i tell anyone to stop doing this they says its not written anywhere in rules that you cant delete /sbin/nologin
I'm not responsible for koth in any way.
But that sounds like a denial of service which is explicitly against the rules
You do not need to spell out what's against the rules, otherwise you'd have to enumerate every binary you're allowed or not allowed to delete.
true its like common sense that we are breaking rules and deleting nologin is just like breaking the machine
If people are breaking the rules, report them. Don't try and argue with them.
i reported once more than a week ago but got no response
If you didn't get any response, it's likely that we weren't able to take much action on the reported user, likely because of lack of enough evidence.
Ninja said everything needed for this, there's a reason you are supposed to be intermediate on THM to start KoTH. I don't see what part of 'dont delete system binaries' wasn't clear enough.
sorry i am not so good in english so can you please just tell me that deleting /sbin/nologin is allowed or not
Deleting /sbin/nologin is not allowed.
thanks
yess i sent only 2 screenshots, i can understand
@steep agate are you able to do something else then spamming /dev/urandom ???
and are you able to try to get root? I'm watching you...
I'll stop laughing sending urandom, and I'll be watching the logs, good luck!
very good friend, that's where you had to get root, just look at the dmesg ๐คฃ
dmesg
or
cat /var/log/kern.log | grep diamorphine
the @fossil pecan has a rootkit based on diamorphine with a sigkill different from the default, his is more appealing because the sigkill to hide the process and return the process is different
I still gave the tip of the logs ๐
30 minutes have passed, you can stay in the king, thanks for the match, you played well!
you too
Actually never heard of diamorphine until i saw someone else try to use it in a KoTH games haha... It is similar tho, even got some new ideas and tricks from learning how diamorphine works ๐
xcellerator too
It's always good to learn new things!
LEARN ALL THE THINGS! ๐
๐
here's the xcellerator blog series i found, learned all my rootkit stuffs starting with this ๐
https://xcellerator.github.io/posts/linux_rootkits_01
Learning about Linux rootkits is a great way to learn more about how the kernel works. Whatโs great about it is that, unless you really understand what the kernel is doing, your rootkit is unlikely to work, so it serves as a fantasic verifier.
In the FreeBSD world, you can find Joseph Kongโs amazing book Designing BSD Rootkits. It was written in...
linux hidden process is really cool
xcellerator ๐ป
utmp
just the tip?
Please come in lets play: https://tryhackme.com/games/koth/51628
why? what happened?
@steep agate is it even possible to bruteforce ashus backdoor?
I tried it 30 minutes with rockyou.txt and still no hit
you sure the other players did not patch it by changing the password???
I've never tested bruteforce itself on the ashu user, because it's almost impossible for someone who already has access to the machine not to have changed the users' password, but I believe so bro, then I can test it for you if you want
i mean service on port 9002 was shut down and the password of the ashu user changed
so i thought this is the only way left
not played koth so dunno ยฏ_(ใ)_/ยฏ
actually there are two backdoors on port 9001 and 9002
lol
there's a backdoor that the shell is limited, I confess that at first I racked my brains to know how it works, but then it's ok
yeah i know but after two minutes the connection got refused
oh I don't know what happened, I just know that there are two backdoors, and one has to have the password
All good
if I'm not mistaken it's "yourmom" something
?
the password
ok thank you for the hint
xD
lul this massco99 killed every service but is still loosing because he cant break the king.txt
lmao true, yesterday he removed gloria's flag in lion machine and left the file name with name "THIS IS MASCCO's DANGEROUS FLAG DONT TOUCH IT"๐คฃ
Dangerous people playing koth bruh
@radiant sun check this guy bro
going to report him
i have screen recorded too
he still lost the match
using while loop to attack other users is not allowed right?
That spam echo thing he doing I donโt think thatโs rule breaking
But if heโs using while on killing sessions or ssh service lol that surely is
in second pic we can see that he deleted nologin too
he deleted nologin
Mattheu is in another dimension ๐
i playing lol
WTF ๐คฃ ๐คฃ ๐คฃ ๐คฃ ๐คฃ ๐คฃ
he came to my DM, giving rage saying that I play koth for a long time and that I'm dehumilde and don't help anyone, and that their friends get mad because when they play with me they never win
@random trellis
but then I talked to him, and everything was fine.
he already did the same thing to me, deleted nologin
he was in my dm too, xposed named player was using your script of king.sh that just add chattr and remove it from /usr/bin, and the pwnzy said he is cheating he using any script of king.sh๐คฃ
๐คฃ
Well, Welcome here guys
nice match @random trellis, many things learned ๐
yess 1=1๐
๐คฃ
lmao, P.S. this game is just 100% fun. I am on a new laptop and have absolutely no proper workspace setup for any competition
i playing lol
which game is this?
I am basically trying to understand how to continue using windows on my laptop and not break it.
we are in trouble now๐ฅฒ
league of legends
I don't think so, I am awfully out of my general workspace, with no idea how this will work out. New laptop, new VM, just notes, all shortcuts gone
still (:
i will try my best if i not gone kicked๐คฃ
I will consider it a win if I am able to even get a root shell today ngl.
lmao, with no shortcuts and keybinds, it is hard enough already, I am sure as hell not playing windows, in which I am as bad as I am in french.
ps I have no idea about french.
wait
yeah
windows I left
@steep agate i was thinking for xfreerdp and you patched that too๐คฃ
it's very hard to play lol and koth at the same time but i try ๐คฃ
๐คฃ
Is this legal to to do
he said the same thing to me
๐i never play dirty.
@random trellis i want to practice KoTH with you, Is it possible? btw i am a script kiddie
1min
I'm online a lot, and have been helping lots of people practice recently... DM me anytime if you want to chat, or play practice game(s) sometime ๐
@fossil pecan is good and knows more than me, you can do with him bro sorry, i am busy in some works these days
come in guys https://tryhackme.com/games/koth/51904
lol @TheJinn007
Dang lol
deleted /usr/bin/w and left his chattr in /root
I am telling you dangerous hackers started joining KoTh๐ฅฒ

lol bro๐ jinn bruh
lmao
You know deleting netstat comes under system binaries? @fossil pecan
?
I don't delete things ๐
only 3 of us in machine, h00dy didn't, and nor did I.
@stiff egret FYI - netstat is not included on the panda machine by default ๐ ๐
just checked brand new game
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
which netstat
which: no netstat in (/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin)
I defo forgot that then. My bad
GG @radiant sun @stiff egret - was fun to watch ๐
25 min
10 min to start
upload busybox and use that for ls???
uh oh someone broke the machine
You made a typo
should work
come in lets play guys https://tryhackme.com/games/koth/51974
I AM TRASH LOL
someone must have loaded a rootkit
terraminator
I'm serv3 lets fucking goooooo
yea
managed to get serv3 and a flag. Couldn't escalate privs. Like my 2nd game though so I'm happy I got points lol
also managed to find admin admin credentials and a cookie. tried ssh but didn't really have much of a clue where to go from there
there is a login panel at port 8000 somewhere, the credentials you found will work there
but you have to find that panel๐
and also these entrances will get patched if u playing against these good players
i dont even change passwords bro๐ฅฒ , i start playing after 10 mins when i play with new KOTH players
yea bro fair play i know but it takes too long for me to just get in haha
im learning
and once im root i have no idea what to patch and how to patch those
@steep agate that pwnzy guy came in my chats and started giving rage that because of you my frnds stopped playing KOTH, because last month you played 8hrs a day and i win because i cheat....
Well i never kicked someone, never changed password, i mostly plays after 10 mins of starting, how much more fair i can play now๐ฅฒ
how you get root, that is what to patch
how about patching the way we get in?
yess you can do that but make sure you dont break the machine๐
if i get in with ssh, i just change the machine pub to my pub
but patching like sql and web, i have no experience at all
for that you need to edit little bit source codes in /var/www/html
ahh thank you so i need to review my coding skill again lol
Gave +1 Rep to @random trellis
i love windows rooms ๐
that guy is crazy in the head, out of nowhere he started to rage, and if I play for a long time what does he have to do with my life? this guy is crazy๐
i have no idea how to get start with it but im learning about it
he said he will come back with some hard scripts again
and this was his hard script
๐คฃ
๐
seems like only ssh and king service is left.
Game ID?
i'm out of the room already sorry can't get it
That's alright, in case you get into such situation, feel free to report this, this is just dirty gaming and rule breaking in a happy mix.
yes that one
ah, it's the same user, the problem right now is, there are a lot of other users in the same game, I can't really point it to one user.
@nova tide wasn't there more reports on the same guy?
they changed the port to 55333 but i think you guys reset the game afterwards?
one more question just in general, when the koth box is really slow, what might cause that? is it my own vm or the box cuz when i practice in private game, sometimes it just really slow to load any web
yep i did see 55333
i pressed reset but only 2 votes so i just left it
Generally, it's the VPN, but if there are players with experience in the box, it is likely that they are running pspy inside. Slow machine is a telltale sign of that script.
but what if i just practice alone with my alt account? sometimes it also slow
So, try the pings on any other machine in tryhackme, and if that is all okay, then it's pspy or someone hammering the machine with some or the other bruteforcing tool.
so i think it's just my VPN issue
Yes, then it is your VPN.
thanks for the info
Gave +1 Rep to @stiff egret
i just practice alone for now
Rule of thumb, give it 2-3 minutes to boot up, I know that Hogwarts and almost all windows machines are slow to boot.
yes thank you for telling
Or you can delete the webpage.... They r both the same ๐
this massco guy plays very dirty bro, just because he dont know how to remove chattr
deleting web page is not allowed i think, so its batter to patch it๐
thats one thing about him.
Same thing happen to me also bro he completely removed the web page when I was playing with him
he did it to me too but lost anyway because he wasnt able to see that he hasnt any write perms on king.txt
@radiant sun did you really have to do that?๐
yea you just messed up with my shell haha
yea thats me
i thought it was spidey bruh lol
๐ญ
the fastest way to patch web lol
but its not allowed
@radiant sun @crimson light ๐ stop it guys
hehe
you dont wanna give me a chance haha
Yoo
What's the difference?... Both ways are meant to keep others out ๐
yea but deleting the web page is against the rules
Yea yea..... I knoww .... rules, rules, rules
lol if i try to join a public game it errors out and says Uh-oh, this page has been lost in the matrix.
and it shows object object dont know what this is
but if you are found breaking rules you could be banned?
If only I were ever found
good luck.
๐ Just kidding... I know and I respect the rules
Just don't add me in your wanted list
Working fine for me... Sometimes error occurs when you try to join 3 or 4 machines at a time
i was having same issue in FF, i cleared cache and restarted browser and now i can ๐คทโโ๏ธ ๐
thank you this worked
Gave +1 Rep to @fossil pecan
Yeah I realized this late. TY for the help guys
Gave +1 Rep to @random trellis
you realise that sounds so ... interesting.
Next game 20min
https://tryhackme.com/games/koth/join/6ec9b69523484b57e6a12a48
@fossil pecan is giving me a hard time at koth
โค๏ธ
can anyone give me a hint of where the 8th flag of panda? i can't never find it. is it in source code?
I can give you hint,
It's in the box somewhere 
very informative
spare me don't send me urandom 
who?
๐yea I know who is it
the only way that i know to get root is patched now im playing with PATH thing but don't know how lol
finally holy
what is king.txtecho?

anyway thanks guy for sparing me
gg im satisfy now
haha
i was not that bro, i got king at starting and then started playing after about 10 mins
@haughty turtle this is all i was doing
king.txtecho made by me by mistake ๐คฃ you can see upward
u not dong a while loop?
i know somebody was doing a while loop cuz right after i put my name it changed instantly
i know, even my king timer stopped for 4 times
i never use any loop bro
i dont do that๐ , i just kicked someone who logged in through port 9001
nothing more
and i did
echo "root ALL=(ALL:ALL) ALL" > /etc/sudoers
i dont think its cheating
these are backdoors
think it's not as well
do u have any demonstration of those cuz i never get it to load
nc ip 9001
oh thank you ill try that when i practice alone hehe
Gave +1 Rep to @random trellis
but i get random room cuz im not subscriber
i just patched sudoers๐คทโโ๏ธ , its not against rules
u spared me that time or u didn't see my ssh key?
i dont know what you trying to say because i m not so good in english , but if you are saying why i did this.. then there was one more way to get root
ohh i understood now, i havnt seen your ssh key bro, as i told you i was just doing king at that time nothing more
yea i put my ssh key in one of the home directory
and i got root by using path exploit thing
cool, so you left your ssh key in skidy right?๐
nice that was the way i was talking about to get root ๐
there something hidden thing, change your path and you can get root
that's me
i didnt wanna say it haha
for w in {1..10}; do cat /dev/urandom > /dev/pts/$w; done
yup thats exactly you
I see that there are links to a panda.thm site... are these links broken or is there a way to access them?
Something else supposed to be there someone remove it and replace it with panda.thm
oh ok
i was not talking about you bro, it was someone who had reverse shell with with python and if i am not wrong you got reverse shell with bash๐
i saw that but havnt killed your process
@cobalt mountain stop doing reset spams
What about you? What have you done stop calling me ๐
just killed your pts
why dont you try tdurden user
you changed password of narrator, so i logged in through tdurden and i also changed all passwords
@random trellis this guy again? ๐
@cobalt mountain you like to send urandom to your friend's terminal, right? ๐
if I do the same to you, I'm sure you never play koth again
๐
Show me that ๐๐
I don't even need it, this is script kiddie stuff ๐
When I see the mentalities of some, my self-esteem increases
that's good bro, you need to grow up
for those of you who need to play urandom on the little friend's terminal, which can only be accessed via id_rsa and id_rsa.pub, you really need to grow up
yea
๐
CLOSE, SO CLOSE @fossil pecan , nice match
๐คฃ๐คฃ
๐ ๐ฅ
14min next game here
https://tryhackme.com/games/koth/join/963957b074fd482dfa9379bd
more games going on today ๐
if someone has premium and could create a private match for me please write to me. I have to prepare for the match against Matheuz.
against the top 1
Heyy
Hello guys, I'm new in koth game and I was wondering what do you think is the best way to learn (in particular the defence)
Just Play and you will See tactics of other Players. If you do this for some time you figure out tactics yourself
https://github.com/MatheuZSecurity/Koth-TryHackMe-Tricks
Metheu has this github
@radiant sun hey, can i hit you up?๐
yeah
I can do this! I would like to get some practice in the rooms too
you are a good opponent on windows machines, congratulations
Oh no koth windows
i wonder is tryhackme koth is anything like hackthebox's battlegrounds
coming from htb
Enjoy
Heeeeeellooo, who's Jinux, I have some question about the game we've been playing ๐
Nevermind, I found a tutorial... I'm a dumb ass who overthink :/
Thank you! Offline is my JAM!! You're still one opponent I can't seem to beat though!
Gave +1 Rep to @steep agate
Did someone encode the first flag on Panda?? Pretty sure it didn't use to be like that.. ๐ค
๐คฃ
you and me give a good fight for king on windows machines, you play well!
How come the ssh password in the Food mysql database isn't working
Hello? anyone?๐ ๐
someone might have changed the password.
Thanks, it's definitely quite a battle!! ๐
Gave +1 Rep to @steep agate
yea!! ๐
@random trellis I have a question regarding the box we are currently on. Mind sending me a DM?
which machine?
are you talking about hackers machine @craggy jasper ??
Yes that one
Just wanted to know if my vector would have been correct and you just already patched it
what you got in the machine?? i mean how you were trying to do it?
Trying to use a combination of
usernames -> derived from the staff page and thier general username schema
passwords -> mentioned in the note
On a login portal I found
But no cigar ๐
that passwords dont work
which are given in notes
Trying not to get too specific on this channel to not spoil the fun for others
okk np bro
Also tried boolean based blind sqli on the login form without success
are you talking about /backdoor?
yes
you need to brute force it
._. ok thnx
there is one more easy way to do that machine, you will underdtand if you readed the note carefully๐
Hahaha ok will give it another long look ๐
Sadly, no matter what vpn endpoint I use, I do not get a connection stable enough for login bruteforcing. Dunno if thats me or THM has some sort of issue rn.
ยฏ_(ใ)_/ยฏ
sorry, i really dont know about this that why is this happening to you๐
No worries. I am not in a hurry ๐
Oh damn... face -> table.
It's a routing issue. Dockers default network adress space is colliding with THMs...
I knew it was me ๐
That's a first
anyone up for koth?
Hahah somebody's trolling me @random trellis ๐
๐ ๐คฃ it was my first time when i sent ascii to anyone
how to u make that ascii art? is it pure coding or there is any generator?
there are many online tools
thank you
Gave +1 Rep to @random trellis
MATTN plays an exclusive 60 minute DJ set for the Top 100 DJs virtual festival
If you can afford it, please consider donating - https://www.justgiving.com/fundraising/top100djs2020
The Top 100 DJs Virtual festival series, taking place every Saturday and Sunday from 18th July through to 19th September, will be broadcast across DJ Magโs global...
good morning
Hello @random trellis, I saw you many time on some koth rooms, I'm wondering if there's some rabbit hole on koth rooms, or maybe they are some entry point that I don't search enough for ๐
Like in the Shrek one, there is at least 4 or 5 way to get in, right ?
yess every machine has multiple entry points
Thank you @random trellis
Gave +1 Rep to @random trellis
#876804968731009055, not really suited for here
right
any hints for Hogwarts KOTH?
Cast a spell.
@steep agate Are you playing 2 games at the same time?
yes
why ?
Was just wondering, really cool
It's totally possible to play 2 or 3 koth games, you get king in a game and then enter another game
xD
Just amazes me how good you are at this, lol
@fair meteor why are you stopping KOTH services again and again
I am screen recording this time and if i found you doing this once again going to send it to KOTH staff
alright
@random trellis im not stopping again
i see u got through using tomcat nice
use a faster scanner than nmap (like rustscan) and scan all ports
dont give up, keep looking
he is really good once I spent 40 minutes getting king then he kicks me out of the machine lol!
at the end of the match, with a few minutes to go, I kicked you out of the machine ๐คฃ
i remember but I will come back stronger the next time I meet you !!! ๐ฅ
xD
we have a one year age gap so I really look up to you!
I even got a samurai animated banner after looking at your phoenix
SO thank you for motivating me!
I don't think age matters much, what really matters is the time you spent studying certain subjects
this phoenix gif I've been thinking about changing ๐คฃ
I am happy with that ๐
I think I'll put this one
good choice!
I should choose a new one too
can I take your old one?
@steep agate
if its a yes please dm me the GIF
@steep agate officially over 1000 games won!! CONGRATS!!!
@random trellis hey
hey
How did you change port 9999 to ur name
Help ur noob opponent sweat_smile
echo "RamghariaSaab" > /root/king.txt
Where
Directly in terminal
I have no access currently
I can't even login in ssh
are we in same machine rn?
Space jam
ohh space jam
U found 2 flags
i did king from command injection and added chattr to king and removed chatttr from /usr/bin
nothing more
I didn't understand that
i can only say you that keep trying machine is very easy
K
hint:- scan all ports there is a backdoor somewhere
yea
GGGGG ๐ , thanks ๐
Gave +1 Rep to @half quartz
thanks lol.
can you dm me?
Gave +1 Rep to @steep agate
Oh, you're samurai too?)
Samurai gangster's ๐
Hey Heyy KOTH players! I see @random trellis has officially hit over 500 wins!! It's turning into quite the celebratory week- Good Job Guys!!! ๐ ๐ ๐ฅ
thanks ๐
Gave +1 Rep to @half quartz
@random trellis
yess
i think the machine is broken, isnt hogwarts supposed to have a http server on 22?
@tranquil pewter can you reset? im 90% sure its broken
22 is ssh by default
https://tryhackme.com/games/koth/53003
All the ports are close and can't be scanned
The ports are higher in the list, give the scans some time to finish
Ofc it is. ๐ Shush
The machine is sometimes slow.
Haha lol itโs not ssh on 22 in hogwarts

you are with me
I saw, best of luck
thanks,you too
thanks
Gave +1 Rep to @wary citrus
that was fast
It always is
I'd say this is best answered by staff or you can appeal the ban on website. I am not sure how much I am supposed to disclose here. And for you reputation, you won't want me doing that either.
cc: @short tusk
You were banned for purchasing and redeeming fraudulent cards.
-ban 899296404906868766 Site banned for redeeming fraudulent vouchers.
๐จ Banned RamghariaSaab#9825 indefinitely
Who's up for some games today? Excited to get back into it ๐
who is up for a koth?
wanna play koth anyone?
My man went from top top 10 koth to ban...
that is why we must do stuff with honesty!
i second this
hella
@fossil pecan ๐
Haha not me, forgot i joined a game lol
sorry bro
Hey, everyone.From which point on would you recommend me to try out koth? Like, are there also easier ones, where you battle against not so experienced players or how does it work?
any players with any level can join public room
there are some good players even on level one
i recommend you taking notes because you will have it easier when you know the machines
the machines wont be changed anyways xD
wtf Spidey?
Oh god that is one example of failed reverse shell loop


@stiff egret I'm crazy yk, is it allowed to upload custom jumpscare html?
As long as you don't disrupt the main webpage.
Generally it's allowed to upload anything, but the rule of thumb, don't remove services that can be otherwise patched without affecting their functionality.
Afterall that's what you do in real world scenarios.
someone might have changed the port
@MIDHUNGRAJ
guy called MIDHUNGRAJ
he is fking disabled every port
i was first get into shell
took root
he was edit king.txt
and removed everything from /usr/bin
wtf guys
The rules state how to report people
What did he even use the fraudulent cards on? Subscription?
or vouchers
sneaky way to fake emoji/emotes right there
Anything to save money from discord nitro
anyone wanna do a private koth with me?
if anyone does, dm me
Do any KOTH players here have their OSCP certification?
Hello. I want to team up with two friends and do challenges and got recommended this here Koth from #subscriber - Wondering if anyone can explain how this works.
We are 3 people and will all be subscribers.
hey! ๐ - koth is pretty fun, can join public (matchmaking) games, or create your own private game/room (invite only). You should be able to pick any box as a subscriber for practice
https://tryhackme.com/games/koth
outlines & rules/faq's ^ here are pretty good, I've been playing a ton of koth last few months (a bit of a break past couple weeks tho haha) ... I'd be happy to help answer any questions, or even jump in VC to chat sometime, let me know ๐
Awesome man, thank you so much. If I have any questions I'll be in touch ๐ โค๏ธ
Is It Allow To Stop SSH Service in KOTH ?
You can change the port but not stop the service itself.
@nova tide but some one is doing it there is no ssh on this ip I Scan All Port No SSH Find But In Start There was a ssh open
You know how to report them ๐
Who's up for some KoTH today?
What time you thinking? I haven't done much but if there's a decent group doing it, I'd be happy to jump in
I'll be online in a little bit, but I'm around and available to play for a while. Happy to do private games also, if you want to learn/practice ๐
^ if you wanna join
@fossil pecan what's the code for this one?
Not sure what you mean... Next game is in 10 min
i was looking at the wrong one, no worries
Can jump in current lobby from the KoTH homepage for public matches
Or can do private ones for practice
๐คฆโโ๏ธ
hahahah
next 23min lol
You must be close, you get it in the next 5 min, you win ๐
*and hold the rest of the game,i probably won't be back, hoping this next game is Linux lol
or i'll just skip flags ๐
bruh moment
i was out here doing something wild
and u could literally eternalblue the whole time
weeeeird, king isn't changing even though I've changed the file
gg
Hmm
Interesting
anyone up for some koth?
I still don't know much Windows haha, but something similar happened to me using a rev shell on windows, it had to do with encoding/formatting, looked fine from my end, but you can see who is current King by hitting port 9999 (same for every box)
curl $VMIP:9999
Mine showed up with broken characters and lots of extra spaces lol
But worked fine using normal SSH Shell ๐คทโโ๏ธ๐
is this the thing that u use to show king's name on your stream?
Yup ๐
anyone wann ctf
sure
either one, you choose! the Hogwarts box on koth is acting funky for me today
we can do normal if you like
I got decimated last time I did koth
@fossil pecan had a great time playing with you and dang You are seriously skilled!
anyone up for a koth? https://tryhackme.com/games/koth/join/d9889696311abae75c13cb97
Me there.
wtf '-'

How do I play king of the hill?
TryHackMe Support Center helps you to find FAQ, how-to guides and step-by-step tutorials.
thank you
Gave +1 Rep to @nova tide

how do i play
TryHackMe Support Center helps you to find FAQ, how-to guides and step-by-step tutorials.
okay
Anyone keen for a game?
where's king.txt in hogwarts machine ?๐คจ
I think you're supposed to create your own king.txt.
yeah thanks i did that
call_cmd "echo '[USERNAME]' > king.txt "
call_cmd "chattr +i king.txt"
while [[ $(cat /root/king.txt) != "[usernameHere]" ]]; do chattr -i king.txt;echo "[usernamehere]" >> /root/king.txt; chattr +i king.txt; done```
Would this actually work?
is this bash script? what does that call_cmd do?
Yes this is bash script, Iโve heard thereโs a function which I forgot to implement that runs the command ๐
put this #!/bin/bash on the top maybe
๐
@fossil pecan ๐
@fossil pecan what did you do to remove permissions of that file ๐ค
multiple chattr flags (more than +i can control write method/locks) ๐
lsattr
should show all attributes set
i actually moved chattr and still you changed attributes

always "BYOC" haha (bring your own chattr ๐ )
who TheLinuxBoy
bro yesterday you kept joining my games im getting oblitirated
how many games did u play yesterday
idk how u are level 9 and this good bro
do you do other stuff outside THM?
dunno TheLinuxBoy, mhmad727, F11snipe, Mathuez are so good that giving them more than 3 minutes can be lethal.
They are so quick with it that they even have kicked me out of a box in which I was root and tried the best to secure it
he doesn't focus on rank but he's better than what his rank is
they can just get king with ssh from their machine
lol
Ik but I believe that its proficency of doing playing KOTH machines repetively over and over again that makes them so good at it
is there any way someone could tell me how invite links are generated? OxSweat and some others got a project where they want to do private koth matches and send the invite link via a discord bot.
si
My level stalled out when i discovered KoTH a couple months ago lol
I can probably help you guys figure that out, I'll be online in a little while if you're around
I do my best to avoid ssh, trying to be extra sneaky ๐
can root user change other users ssh password/remove auth key? is it allowed?
ya would be considered a patch
oke
i heard your root kit thing is amazing but i can't never figure what it means haha
Heya dude, do you have any scripts I could incorporate into my day to day KOTH fails so I atleast have a chance against people that have been doing this type of stuff for a long time?
u should try to learn to do it manually first before u run any script without understanding about what it does
I do, its just quite annoying as while Im trying to learn how to I almost instantly get blocked off and its quite hard for my friends to form a decent koth timeline as we're all over the globe with little time able to do it unless its daft am for me
I'm happy to help answer any questions, and help develop some of your own... I'm working on polishing some of my tools + scripts to share on GitHub soon (ish haha)
u can practice with your alt account
I didnt know that was allowed lmao, didnt want to run the risk with staff but if your sure its good to go?
yea private match with your alt to practice
Mind if I dm?
won't harm anyone
Coolio
sure! I'm happy to host/join private matches anytime for practice also ๐
bro you sweatting KoTH
i play at night mostly and if i want to play a game and not get instantly oblitirated i need to play at the morning
when @fossil pecan and @steep agate not in your game
rn Matheu is in my game :(
lol
when @steep agate and myself both afk entire game lol ๐
i'll get it started ๐
ohhhh sorry I had forgotten about the game, I was playing LOL and answering some messages that I even forgot about the game ๐คฃ
Niceeโฆ Im tryna get into it
private game ?
nice graph there lol
Hey, did thm already start to randomize the koth flags or are they still the same for every room?
They are same for both KoTH and THM rooms. There might be randomized flags in future events.
Why dont they randomize it? There is always some one in koth copy pasting them
40 points off the maximum for this box
@fossil pecan Im slowly getting there xD
though being king for a longer time should give you more points then that???
10 points for each full 60 seconds
think the max point calculation is just from the flags and not counting king time
oh fair enough
its counting king and flags, maximum amount for SpaceJam is 670 points if you auto script it (and break rules) and miraculously get king the exact second you get the ip otherwise its 660.
The longer you have your TryHackMe Username in the /root/king.txt file, the more points you get. You obtain 10 points every full-minute you are the current "King". To obtain 10 points, you must be the current "King" for 60 seconds (1 full-minute). If you are only the king for 50 seconds, you will not be awarded the 10 points, nor will the person who was "King" for the remaining 10 seconds of that minute. - Taken from THM help page
I hope you see that using Auto pwning or generally using scripts that give you way too much power is not allowed here.
Yer Im saying the maximum possible theoretically is 670 but realistically itโs 660 provided there was no cheats involve. Im sorry if this got misinterpreted โค๏ธ
oh bad on my part lol
I wasnโt much better, I could have made it clearer. โค๏ธ
ez dw but I believe we need to have a more fair env but there are still people just so good at it that make you question your skill lol
cough @fossil pecan and @steep agate cough
Personally Iโve never done a public match yet as want to get my bearings and see whatโs going on with them all with friends before I subject myself to that torture.
Me and my friend did SpaceJam (The pic I sent earlier today) and Hogwarts and I personally disliked it as even with my privesc it was near impossible to secure root (The king.txt file was missing too).
its in ||tmp||
apart from that I think I have never won against these two
rn playing koth too lol
I kept looking in /root/ where I personally think it should be and itโs expected in most of the Koth guides and i ended up only getting 50 points the entire match while my friend was still running his Nmap full port scan by the end of it.
Cause I heard the ports are random on each machine compared to the others
Yea that is true
I see why they did it but even tho it still took me 20+ minutes to find the two ports I used to access Neville account
what ?
I canโt seem to get it working on my kali for some reason
how you using it?
Your just too good at KOTH, thatโs what we had previously said
send screen shots
oh, thank you ๐ฅฐ
Gave +1 Rep to @low dagger
Tried using their install guide and just canโt wrap my head around it. So I might try and compile it tomorrow as itโs nearly 1am my time
I really need to find good resources on chattr binary
โค๏ธ
maybe check the rustscan room
If king file doesn't exist, you can always create it again ๐ ... Some boxes like Hogwarts don't have one to start with
it might help with installation
did you get it from git hub?
Thatโs my favourite binary to use as unless you know what your looking for, itโs awkward as hell
Is it available for free users?
yuups
Was tryna do
ik bruh I cant understand how tho make it so immutable even after using chmod and chattr using -i command
guys, I recommend that you use rootkits, create your own scripts to protect only king.txt
any resources for that?
of rootkit you can base on diamorphine to be able to use it as studies and in the future create your own rootkit
shadow not trust themselves with rootkit stuffs
For me:
I ensure to run it where king.txt is:
(After putting name in king.txt)
chattr +i king.txt
If it ends up getting edited and chattr gets added
chattr -i king.txt
echo โ[Username]โ > king.txt
chattr +i king.txt
I would want to declare mathuez my koth rival but rn he is way too op
but not for long
I will come back stronger than ever!
sometimes doesnt work still
@jovial field @fossil pecan @radiant sun ! Nosferatuvjr#1091 is very good players too!!
gives permission denied even after:
using -i and -a on chattr,
changing permissions for chattr
doesnt make sense tho
In my CTF team (we ainโt the best but somehow we get top 10% at times?), theyโve said Iโm hands down the best in the team yet Iโm actually horrific at web pentesting and also AD (Im trying to learn AD first)
You running it as root?
root all the time
I can usually get root in machines in like 2-3 mins
but then I sped the rest of the time researching how to change file perms
Mhmโฆ try -R before the +/- i
for recursiveness?
It might be an idea
will try and let you know
for now I gotta play more koth lol
Lol, Ima unwind with YT and probs go sleep
what type of content do you watch?
Some times JohnHammond but commonly League as tryna learn that to play with my mates
League seems noice
but never played any Triple AAA title on pc ever
Yer, my college have an esports team on it. I got my pc mainly for gaming and started to do cybersec as that appealed to me
You will be a really cool hacker who games or a really cool gamer who hacks! ๐ ๐ฏ
Thatโs my goal ๐, work hard play hard
anyways you probs gotta go now so see ya! ๐
If Iโm free tomorrow or smth I might see if I can finally run a public match for fun
sure lets do a private one altho on some machines like H1 I suck
If you got premium sure, Im just poor rn ๐
same bruv!
#PoorManGang
Idk why but I made it so all my scripts need xte installed
weird
hi
the problem here is what happens if chattr gets replaced or deleted
and it is slow
True, in none of mine (admittedly private) chattr was deleted
in all of mine it was deleted or replaced lol
Yeah, that's usually the first step
To my understanding, what you wanna do is statically link a chattr binary so you can pull it up when you get access
@fossil pecan Good game brother!
oooh close to a tie
Yea ik
I lost at finding flags lol
I really tried hard but it has something to do with games
and I tried some but only found 1
What is the best distro for beginners ?
Couz when I first started I jumped to kali and things was bad felt dumb on multiple occasions
๐
Daym congrats
Pov:me one day :)
for ease of use for daily driving??? pop os or linux mint
for only using for hacking??? kali linux or parrot os
yeah do not recommend shadows use case though
as shadow has to install a lot of things from source or sometimes installing things using the default repos
So should I still go for kali but keep practicing ?
yeah would recommend a kali linux vm for all things tryhackme
Thanks
Gave +1 Rep to @naive goblet
it is kinda like having your own personal attackbox instance
hit cog button.... press reset room progress tada
Can't login due to me forgetting my password and no clue which email
I'm still searching for it though might be somewhere in my 2nd account pins
Yup gonna subscribe too
Ah last thing pls
What order should I be doing first
Someone said I should got for pre sec before beginner path
Offensive is far away 
if you feel like you absoulutely need to do complete beginner stick it after junior pentester
yeah
it is a lot harder then the others with previous knowledge
So this way I'm starting over , like 0 knowledge right ? Couz that's what I want
Thanks I appreciate the help
@naive goblet
Gave +1 Rep to @naive goblet
Ping for reps :)
I will :)
reps all over the place
Haha
hannah montana linux
I'll check it out thanks
Gave +1 Rep to @steep agate
@fossil pecan patch first king later nice haha
i got all these but can't do anything
yea and removed the perms to get root
well atleast now
and btw I closed your shell so sorry for that
ok
Hey did yall just close ssh?
I did a nmap scan with -p- couldnt find 1 port for ssh?
@fossil pecan How'd you protect the king file? I can't change perms or write to it?
I checked noclobber and immutability
root kit lol
@fossil pecan you in through ssh?
or something else? cause the ssh ports seem to be closed
it's completely patched
