#koth

1 messages Β· Page 2 of 1

dry fossil
#

I'm not going to be going again, it's getting late

valid cairn
#

its never too late

#

jk jk have a good night!

dry fossil
#

I just want to know how the king.txt was protected, I had root most of the time but couldn't even change permissions of the text file or update it

#

Am also happy I technically found both ways onto the machine

valid cairn
fossil pecan
#

ssh was stopped, i restarted a few min ago πŸ˜„

dry fossil
#

ahh, will have to find the last one

fossil pecan
#

3+ on each machine

dry fossil
#

but how was the king protected?

#

was the entire dir chattr +i or something

valid cairn
dry fossil
#

it seemed like I couldn't modify or view anything in the dir

valid cairn
#

you will see eventually lol

dry fossil
#

I did that for the king but not the dir

#

I forgot to but I've turned off my vm now

fossil pecan
#

many ways to protect, you mentioned the big ones

dry fossil
#

was it chattr +i'd?

valid cairn
#

lets play again 9 tails!

dry fossil
#

πŸ˜†

#

nah, I've got a mate who wants to play some jackbox I think

#

maybe tomorrow

valid cairn
#

sure

fossil pecan
#

but as the guru koth dude says...

eventually, protecting king.txt is irrelevant
dry fossil
#

I'm going to do some research tomorrow because I have found that some other good ways of preventing writing are to bind it or use an LD_PRELOAD

#

and I might be able to write a few scripts to play with

fossil pecan
#

rarely use ssh during koth, but I do my best to keep it up and running for others πŸ˜›

dry fossil
#

Have any of you found a use for the telnet?

#

I presume that's the third way in

plush moss
#

it was not my intention to forego ssh...^^

dry fossil
#

ah I see, I looked at a walkthrough and I understand why I was getting odd symbols now, makes sense

#

I was using netcat but really needed to use telnet

#

I now understand the direction I would have gone using that to get in

magic owl
#

asd

valid cairn
#

crazy match with yall

#

GG!

dry fossil
#

gg

plush moss
#

gg

steep agate
#

your agent is very OP

#

kingmakers, rootkits, scripts to protect king, using while, oneline, etc, doesn't even come close against your fullsnipe agent, and really very OP

#

🀣

umbral narwhal
#

weeeee

umbral narwhal
#

GG @ jassim15

valid cairn
#

GG bro!

dry fossil
#

@valid cairn what've you done to sudo?

valid cairn
#

I did nothing to sudo

#

I only fixed the vuln for the Tar

dry fossil
#

the sudoers file is fucked then

valid cairn
dry fossil
#

not even root can use sudo :/

#

yeah

#

I can't use chattr except with pkexec and I don't have the root password to do that

valid cairn
dry fossil
#

ah

valid cairn
#

you gotta download the binary on your host os and upload it using python3 server

#

then use it to your own will

#

let the game end and ask me for the password You will be suprised lol

dry fossil
#

try ls /root

#

πŸ™‚

valid cairn
#

lol

#

lemme check tho

dry fossil
#

I figured out how to hide the actual root dir

#

you won bc you got in way before me haha but that was good fun

#

am going to take a break for a bit and will be on later

#

managed to change the root password also

valid cairn
#

very fun

#

same here lol

#

btw the password was uhh ||Burr#4312||

dry fossil
#

Ahh nice

#

That's why I couldn't crack it

valid cairn
#

lol

#

true

dry fossil
#

I did manage to change it though bc I copied the ssh keys from donkey to root, sshed in using them and then using the amended sudoers file managed to change the password without entering a password

radiant sun
#

hello peeps

plush moss
#

hei

fossil pecan
#

who's up for some koth today?

valid cairn
valid cairn
#

GG! @fossil pecan @tight harness

haughty turtle
#

how to get good with kothcri

valid cairn
#

Over time you will remember the way to get it

haughty turtle
valid cairn
haughty turtle
valid cairn
#

altho I couldnt figure out who to remove the permission with that

haughty turtle
#

i wanna know like advance techniques that can as a backdoor

valid cairn
valid cairn
haughty turtle
sour vectorBOT
#

Gave +1 Rep to @valid cairn

valid cairn
haughty turtle
#

and beside loop, what can u do to protect king?

#

or get king back when someone running loop

fossil pecan
#

many ways to king & backdoors ... I was thinking of hosting "Q & A" or "AMA" stream sometime soon, and can help answer questions & solve problems for anyone who's interested

valid cairn
#

Your eternal rival lol

feral urchin
#

its Tetsu

#

how are you

valid cairn
#

Tetsu ?? can it be??

#

is it really you??

feral urchin
valid cairn
#

you tell me

feral urchin
#

i dont know you

#

just i did many KOTH against F11 and it was fun

valid cairn
feral urchin
#

or i just dont remember

valid cairn
#

Bro it was a joke

feral urchin
#

i know

dry fossil
#

how many flags are there in fortuna?

#

got six so far

feral urchin
#

8 for each koth i think

dry fossil
#

not sure where the last 2 are

#

found 3 in different games and three in files called flag

valid cairn
#

Why is some one changing the flags in kOTH match?

naive goblet
#

oooh that is evil..... and probably not allowed

dry fossil
#

found them all

#

I've not touched them

valid cairn
#

look at this

dry fossil
#

It's not allowed

valid cairn
#

idk who is doing this?

dry fossil
#

looks shifted

#

that's not been changed

#

which one is that?

quiet schooner
#

Pretty sure that's just how it is

valid cairn
quiet schooner
#

Deleted because spoiler

dry fossil
#

that's normal, I've done lion

#

It's meant to be like that

valid cairn
dry fossil
valid cairn
#

and its wrogn answer

valid cairn
dry fossil
#

what error?

#

with the ssh?

#

Password was changed, you had to find another way in

#

was hoping you'd find a way in and try and fight for the king, had a little trick up my sleeve

naive goblet
#

is the trick named shadow???

dry fossil
#

Nope, if I told yous it'd spoil the fun haha

#

but seeing as I've had a chance to play about I've managed to prove that it works as intended

#

Even if you were to have root it'd stump you unless you figured it out haha

dry fossil
#

sound, this one ends in about 5 min

#

gorgeous

#

gg lads

stiff egret
dry fossil
#

Oh shit thanks

#

+rep @stiff egret

sour vectorBOT
#

Gave +1 Rep to @stiff egret

fossil pecan
valid cairn
#

+rep @valid cairn HMMM DOESNT WORK

valid cairn
#

even after overwriting its content and shredding it

#

doesnt change lol

dry fossil
#

I believe f11 made a rootkit sort of thing

#

probably uses ld_preload to prevent writing to king.txt

dry fossil
#

we do a little control f and bam

#
#

very cool that you did make a custom rootkit tbf, I want to do that soon

fossil pecan
#

πŸ˜„

steep agate
#

hiiiiiiiiiii guys

fossil pecan
dry fossil
sour vectorBOT
#

Gave +1 Rep to @fossil pecan

dry fossil
fossil pecan
#

linux* lol

dry fossil
#

what are the main ones used by koth now? 20.04.4 and 16.04.4?

fossil pecan
#

mostly 16 & 18, only 1/2 20+ i think

#

and 3 rhel/centos

#

and 1 debian8

#

something like that

#

uname -r to check each kernel version, and then need to find same/compatible VM (usually) to build with those exact header versions πŸ˜›

dense sigil
#

nice

wary adder
#

Vagrant is always convenient too tho, esp with the synced folder ability

haughty turtle
valid cairn
valid cairn
haughty turtle
dry fossil
#

@fossil pecan started that work on the rootkit πŸ˜„

#

Got a setroot successfully working and have started assembling a list of functions I'll implement when I get a chance

stiff egret
#

Unpopular opinion
backdoors >>>>> rootkits.

dry fossil
#

well a rootkit can have a backdoor can't it 😎

#

a backdoor can't have a rootkit so it is an unpopular opinion kekw

stiff egret
#

I was planning on not saying this, but ....

#

what if upcoming boxes are docker based.

dry fossil
#

Then you design the rootkit to escape containers :p

stiff egret
#

I meant only based off dockers. i.e. the whole game is supposed to be in dockers only.

dry fossil
#

I thought docker does use a kernel but that it's very cut down?

stiff egret
#

I don't remember seeing anything where you can use a rootkit in docker without privileged mode being on.
I can be wrong or limited by my knowledge though.

dry fossil
#

I imagine there's probably a way

stiff egret
#

@brazen cloud Tagging you here for the discussion, respond when you have time. You are my go to person with peak level docker knowledge.

dry fossil
#

I hate docker everytime I've used it I've struggled

stiff egret
#

tl;dr docker based rootkits exists?

dry fossil
#

They certainly do if it's privileged as you've said but I'm not sure about otherwise as privileged containers can load modules into the host kernel

stiff egret
#

I absolutely love them, I am sucker for managed storages and the whole container logic gives off a very 'managed' vibe.

dry fossil
#

This being said it's not unlikely that someone has found ways of doing it as it depends how poorly the docker instance is set up

stiff egret
#

Keeping in mind, if we are to launch any box that is to be played in docker only, then it will be stress/security tested to ensure stability of the game. So the possibility of hacking that docker itself is bleak, that being said, attacking the host docker will be most likely off the limits and appended into rules.

dry fossil
#

oh for sure but in the meantime I get to play around with a homebrew rootkit

stiff egret
#

That, is a very fruitful journey.

dry fossil
#

it is indeed, just added the code to hide itself while loaded in

stiff egret
#

All the best for the rest of it.

dry fossil
#

Thanks πŸ™‚

haughty turtle
#

@fossil pecan when did u join the game, huh?pepega

#

i don't remember seeing u in the first 20 min of the game

#

am i tripping?fawaz

fossil pecan
haughty turtle
#

btw it's GG from here cuz i have no idea how to get king back

fossil pecan
haughty turtle
#

hope to see u do koth on stream some day

#

maybe explaining some manual enum

jovial field
stiff egret
valid cairn
stiff egret
#

Heavy machines, hard to moderate, slow to start, πŸ€·β€β™‚οΈ though depends in the end on the machine.

valid cairn
#

btw you and naughty have a great guide on koth machines!

valid cairn
wind fjord
#

imagine new boxes kekw

valid cairn
#

OH shit Naughty Joined πŸ’€

nova tide
#

Just gonna watch πŸ˜„

#

@valid cairn wanna join vc?

valid cairn
#

lol cause parents are around

#

and I dont wanna show them my discord and spicy memes i Have on it πŸ”₯

nova tide
#

you can screenshare and i could watch πŸ˜„

valid cairn
#

sure

valid cairn
#

already inside the machine

#

escalating priveleges

nova tide
#

nice

#

i just booted vm xD

valid cairn
#

ahh shit I gotta secure it lmao

#

@nova tide sorry I gotta stop streaming the ports etc

#

lol

nova tide
#

oh i already have backdoor and root shell so doesn't really matter xD
Just wanted to see your tricks and see if i could recommend something.

valid cairn
#

good job lol

#

and you kicked me out of the machine πŸ‘

#

|| @nova tide || you gone now?

nova tide
#

no still there

valid cairn
#

do you have permenant root access to the machines?

#

or do you get a new one everytime?

nova tide
#

Still have that initial shell and a backdoor.

valid cairn
#

KOTH lead mod perms go brr

#

Naughty is dominating the game

#

I hope my nmap scan with -p- and -T5 finishes before the game ends

stiff egret
#

@nova tide kekw

valid cairn
stiff egret
#

I should mention that it is a joke and we don't get AWS Shell access.

valid cairn
#

ik naughty told me that

stiff egret
#

That's what someone with aws shell access would say.

#

Okay I am messing with ya lol

valid cairn
#

I can get access but developing custom rootkits for it etc seems really excessive tbh

stiff egret
#

Totally agreed.

valid cairn
#

the other a freind of mine was telling me in the dms that he spent idk hours trying to make a custom rootkit that gives prevents the file from being changed

stiff egret
#

Don't take me wrong, it is really good for the researching and learning part, but other than that, it's a complete overkill for KoTH.

#

Atleast KoTH as of from TryHackMe.

valid cairn
#

ik lol but its like a requirement if you wanna play with the top players

stiff egret
#

πŸ€·β€β™‚οΈ I don't know what top players you are referring to, but it's really a game of a good script to write your name in king, and your speed / skill to point and shoot at people in the game.

#

chattr, echo, ps, kill, rm. (insmod) this should cover most of it.

valid cairn
#

you and naugthy

#

all of you are top players

stiff egret
#

πŸ€·β€β™‚οΈ as flattering as it is, if you are monitoring processes really well, you can basically kick off anyone from the game.

valid cairn
#

you can hide your processes

#

by embedding them cant you?

stiff egret
#

Some have overhyped hiding process.

#

Boy am I dropping truth bombs today

#

lol

valid cairn
#

i think and naughty should make a room called playing koth

stiff egret
# valid cairn by embedding them cant you?

get in the machine faster, monitor the processes, you can see what they are doing, undo their shit, and kick them off. Preferably in the same command, they won't know what hit em.

stiff egret
#

put a temporary chattr on basic files, essentially freezing the machine for the starting few minutes of the game to give you breathing space.

#

passwd, shadow, authorized_hosts, ssh config, id_rsa etc etc

#

rephrasing, by freezing the machine, I do not mean hanging it, but keeping it in same condition, so you have more time to setup your defences. Meanwhile everyone else will be confused why their one liners to setup backdoors aren't working.

valid cairn
#

thanks for the great tips my guy!

steep agate
#

hii guys πŸ˜‰

valid cairn
#

I had to leave home to get some supplies

#

sorry I left the game lmao

steep agate
#

no problem bro

#

xD

stiff egret
#

Hm, that is a nice one. Can be basically based off the blog that was shared earlier here.

wary adder
#

I'm not an expert on the subject by any means, but I'll probably start on that so that I myself can learn, then have someone like f11snipe look it over and correct me

radiant sun
#

yo

rugged leaf
#

why do i feel like the machines in KOTH are not being updated?

nova tide
#

because they are not? πŸ˜„

valid cairn
#

dear koth players

#

why are you not talking here?

stiff egret
#

πŸ‘‹

radiant sun
nova tide
valid cairn
wary adder
#

kek

magic maple
#

hello guys, i hav a problem. How can i protect king.txt :<

stiff egret
#

castle.

magic maple
nova tide
#

ehm ehm CASTLE

nova tide
stiff egret
#

Self plug, but you can read the blog in the pinned msgs to get more information about how to protect the king file.

rugged leaf
nova tide
rugged leaf
#

Looking forward to the Reveal...

stiff egret
steep agate
magic maple
fading moat
latent osprey
# stiff egret πŸ‘‹

Hey Holmes...
Earlier you were having a portfolio website.... Can you send the link please

stiff egret
latent osprey
stiff egret
#

Ah, yes, damn when did you see it, I removed it like 1.5 yrs ago

latent osprey
#

Then i Might have seen that 2years ago vent

#

But can you specially tell me the technologies you used in creating that website?

I really want to make something like that

stiff egret
#

I was a really dumb dev back then, so I just really did it in css lol

latent osprey
#

Whaat???

stiff egret
#

It was all just html and css. handmade

latent osprey
#

Seriously

#

That was really good website

#

How can someone make something like that in css and html

stiff egret
#

ngl I ask myself that, I don't know if I can make that rn if I wanted to lol

#

But ye, I think it's on my GitHub if you'll search for css maybe

latent osprey
#

Oh okay let Me look for it

#

Thanks

stiff egret
latent osprey
#

Hah thanks blobheart blobfingerguns

steep agate
rose nimbus
#

very cool!

rose nimbus
stiff egret
fair adder
echo helm
#

1 minute left ^^

fair adder
#

dammit

#

i'm installing rustcsan

echo helm
#

haha

#

just saw we will be playing offline

#

to bad haha

#

will be hard tbh, complety new for me

haughty turtle
#

ahh window one

fair adder
#

yeah that's a different game. the one i started starts in 16 ins

#

mins

#

i gave myself some time so i can install some tools.

steep agate
echo helm
#

@haughty turtle Bout to pass tbh πŸ˜„

haughty turtle
echo helm
#

Really really no idea how to start here

#

Haha, sameee xD

#

Shall we join @steep agate

#

Even tho I feel bad for fs5150. but I really have to learn before attacking windows servers

#

Only found a password

steep agate
echo helm
#

fs5150 just pwned it xD

echo helm
echo helm
steep agate
echo helm
#

Not ur nickname?

echo helm
#

yup, thats exactly the one im in

#

starting in 35 secs

dry fossil
#

rootkitted? @steep agate

steep agate
#

and I didn't fix the path to root either

dry fossil
#

I tried chmod and chattr and set noclobber

#

did you replace chattr?

steep agate
dry fossil
#

what'd you do?

#

can you tell me towards the end?

steep agate
dry fossil
#

I mean there has to be a reason I can't set ownership or write to it after chmodding etc.

fair adder
#

@haughty turtle did you change the ssh login password of webmaster lol?

haughty turtle
#

i don't even know ssh password

echo helm
#

VC for a sec? @steep agate @haughty turtle

#

gg btw

#

@fair adder

fair adder
#

Gg TryFlagMe

#

I found the ssh username just couldn't get hydra to work

#

To Brute Force the pas

echo helm
#

I got a php reverse shell but couldnt get my script to work

#

Voicechat guys?

#

Really curious what your approaches where

haughty turtle
#

i get rev shell as serv3 and get root by crontab

#

the only thing i changed was the directory in crontab: backups to ok kekw

echo helm
#

Yup, thats why it didn't worked I guess. Isn't that even against the rules? ^-^ @haughty turtle

#

@haughty turtle Or am I misinterpreting.
I revshelled trough php but where stuck then since the crontab wasnt working anymore... rly sad :c was wondering, what I was doing wrong tbh

haughty turtle
#

it should be considered as patch

dry fossil
misty jewel
#

anyone actively in public looking for a game?

misty elk
#

After adding attributes

steep agate
dry fossil
#

either replaced the chattr binary with one that didn't allow it or flocked it or something

wind fjord
#

big brain idea is to leave a fake chattr binary on the system that just kills your shell

#

or a backdoored chattr binary that runs shellcode or something like that

fossil pecan
wind fjord
#

It’s been a while since I’ve touched any of the KOTH boxes so I probably don’t remember

radiant sun
#

😌homie told me once .. respect ♾️

jovial field
#

other big brain move is to recompile the chattr binary with a delay of 1sec

stiff egret
#

that's what I've been doing for a long time initially -

jovial field
#

or you alias chattr to echo your name into king.txt

tranquil pewter
#

GG @ samarrajsingh

#

Sorry to whoever @me I haven't been on discord a good while. πŸ˜…

unborn ice
#

any one know how to fix this problem ?

i got this while using chattr

stiff egret
#

Use static binary.

median sinew
#

can you join

ionic wagon
dry fossil
#

Man flock

ionic wagon
#

Thanks I’ll check it when I get home

mental birch
#

hello

#

first try

#

anyone down for some koth

#

@fair adder hi , wanna play some koth ?

fair adder
#

After work around 6pm maybe ?

naive goblet
# mental birch ahh ?

in your profile on the about you part there is a bit where you can change to allow you to play koth

#

this thingy:

mental birch
mental birch
mental birch
sour vectorBOT
#

Gave +1 Rep to @naive goblet

naive goblet
#

Β―_(ツ)_/Β―

mental birch
#

So koth is only for subscribers right ? Even if it was public game ?

fair adder
#

So you'll likely be asleep !! Lol

naive goblet
#

nah think it is for everyone if it is public games

#

just you can't choose the target koth machine if you do unsubscribed thingy

mental birch
#

Oh great that mean when inferno subscription is over ,he can still play koth with roki this weekend

mental birch
mental birch
#

Wait I need my own vm ?

#

Game already started

#

Eh what on earth made me get into something that I got no clue about

jovial field
#

feel free to ask me if you have any questions

mental birch
#

Thank you πŸ™

jovial field
#

you are welcome

mental birch
#

@jovial field hello
I took a look at the rules ,points ,etc...

Questions:
1-Should I have my own Linux and then connect using the open VPN, or do I get an attackbox ?

2-"How to play" number 3 says "hack into the machine which is related to my question upvote

3-number 5 says "patch the machine vulnerabilities to maintain your access " which i don't know how ? And does that mean if I don't I could be kicked of the game ?

jovial field
#
  1. Yes you should use your own linux machine but in theory you can use an attackbox spawned on another box. 2. you should scan the machine for vulnerabilities and gain access to the machine. After that other players will try to kick you from the machine so you will need to find tactics to prevent them of that. 3. To hold your place on king.txt you can patch the vulnerabilities you used to gain access and search for even more, so other players wont even get into the machine. An other way to protect king.txt would be using tools such as chattr
mental birch
jovial field
#

i mean you could do some rooms of the beginners path to get used to tools like nmap, nikto, gobuster etc. while you are doing that you will also learn things about linux.

mental birch
#

I looked into YouTube and what I saw was looking advance for me and couldn't find anything for tutorial

sour vectorBOT
#

Gave +1 Rep to @jovial field

versed notch
#

Hi I’m looking to get into this but I’m not quite sure where to look to learn skills to do thisπŸ˜‚πŸ˜‚ Does anyone have any suggestions?πŸ˜‚

radiant sun
#

You can Practice in these two rooms 🐣

versed notch
sour vectorBOT
#

Gave +1 Rep to @radiant sun

primal fog
#

Hi guys! I'm looking for someone for hacking together. Is there anyone?

mental birch
#

I wish but not ready yet 😩

primal fog
#

I or you?

mental birch
#

Me ,im not ready yet

primal fog
#

What is your level?

mental birch
#

0x6

#

But still need to practice on the tools

jovial field
fossil pecan
#

how's everyone been? had to rebuild my rig and take a break for a bit haha, but I'll be back to play more soon! πŸ˜„

haughty turtle
fossil pecan
haughty turtle
mental birch
boreal pewter
#

Well I tried , VJ99. I know it's something to do with abusing the .jpg upload but I'm a bit rusty lol.

Hope you get it

stiff egret
#

These msgs, man.

#

I hope VJ99 gets it.

fossil pecan
fair adder
mental birch
#

Yeah same question

fossil pecan
mental birch
#

Wait stream through discord vc ?

fossil pecan
#

ya sometimes, but mainly stream on YT & twitch (YT primary for hacking content)

mental birch
#

Nice because I can't use discord vc its banned here

fossil pecan
#

I'm "F11snipe" pretty much everywhere, also have twitter, github and stuff πŸ˜„

#

don't have 100 subs for my "branded YT page" (yet) ... but this is easy redirect https://f11snipe.live

fair adder
#

@fossil pecan LOL Bro What's That I see something like yo**m*m 🀣

fossil pecan
#

hahahah, oh ya! it's a joke query param, to mess with their analytics/tracking

fair adder
#

Ya

fossil pecan
#

so they'll see visits to my page with source "your mom"

#

lots of eastereggs when i'm involved πŸ˜‰

fair adder
#

Yes

fair adder
#

@fossil pecan Its Was Really Good Game GG! i don't deserve the win.

fossil pecan
#

I just really like to try and tie points haha 😜

fair adder
#

Ya i know

fair adder
#

@fossil pecan Are You Using ChaShell ?

fossil pecan
fossil pecan
fair adder
#

Cuz I see dns over your ip so

upbeat bone
#

Anyone wanna play?

gritty stump
#

12m startin

fair adder
vital tide
primal fog
#

Hi guys, anyone for hacking?

#

To spent a little of time

#

spend*

fair adder
#

for ctfs

primal fog
#

Anyone for play?

vital tide
#

anyone else playing rn?

#

theres 4 other people in the game with me but idk if they active

#

im the only person whos submitting flags

fossil pecan
fair adder
#

@fossil pecan When you are Going to Stream?
Watting For It

steep agate
#

I wanted the f11 to come back with the streams

#

miss you

fair adder
#

Me To

vital tide
fossil pecan
vital tide
gritty stump
#

startin 15 min

harsh obsidian
harsh obsidian
#

^^^ 5 minutes

fair adder
#

@fossil pecan

#

Good Luck

vital tide
radiant sun
#

yo

paper iron
#

test

harsh obsidian
neon verge
#

anyone for a match in 5mins?

plain badge
#

@desert umbra could you stop resetting the machine and try other ways to get access to it? πŸ™‚

obsidian mesa
nova tide
#

well it's been two days now so πŸ˜„

fair adder
#

i know im a complete moron. I didn't see the date until i actually looked πŸ˜…

#

mind you i've been using two monitors now and i can barely see my laptop lmao

#

this is where i have discord on

#

i've said this before but i think it's time for me to take a break from discord..see you later naughty ! TryFlagMe

fair adder
# stiff egret Ctrl + '+'

Hello Mr.Holmes πŸ‘‹
Yep I had this on full zoom blast. Thankfully I have my eye exam coming up so I'll be getting glasses soon

stiff egret
fair adder
sour vectorBOT
#

Gave +1 Rep to @stiff egret

stiff egret
#

rep farming ftw

jovial field
sour vectorBOT
#

Gave +1 Rep to @stiff egret

steep agate
craggy spruce
#

why are people allowed to post the answers to koth online when the VMs are still the same after two years?

#

anyone playing Production now?

quiet schooner
craggy spruce
#

is port 9999 part of the infrastructure? It always comes up

quiet schooner
#

Yes.

quiet schooner
#

Please read the rules. Not following the rulss can get you banned

craggy spruce
#

so good to ignore port 9999?

quiet schooner
#

It's in the rules...

stiff egret
#

....

craggy spruce
#

Production was a fun machine

craggy spruce
#

someone just killed the services or banned my IP in KOTH game 58043

quiet schooner
craggy spruce
#

This makes me wonder how much hammering a box can take. 6 people all firing dirb and more...!

#

The VPN network is good

#

resilient

#

hi @steep agate , it's me vs you a lot!

craggy spruce
#

I bet you've played all the boxes

craggy spruce
craggy spruce
steep agate
craggy spruce
#

how did you lock king.txt ...

craggy spruce
#

@steep agate did you use chattr?

steep agate
steep agate
craggy spruce
#

I would definitely pay for this, can't believe it's free

#

The only problems are that there's no-one playing sometimes

stiff egret
craggy spruce
craggy spruce
#

koth offline

steep agate
steep agate
craggy spruce
#

do you change passwords or patch the vulnerabilities?

craggy spruce
#

great, just checking

steep agate
#

πŸ€”

craggy spruce
#

should king.txt be at C:\king.txt ?

steep agate
craggy spruce
#

where is it? πŸ˜„

steep agate
craggy spruce
#

thanks

craggy spruce
#

I think you kicked me out and changed the password

steep agate
craggy spruce
#

did you remove king.txt yourself or did I manage to write to it?

steep agate
#

there is not only one way

steep agate
#

sorry i forgot about the game

#

🀣

craggy spruce
steep agate
harsh obsidian
#

.@fallow hinge gg

harsh obsidian
#

. @fallow hinge got king at the end. nicely done.

craggy spruce
#

hi anyone playing Hogwarts with me

craggy spruce
#

hi anyone playing Offline with me

#

@netstalk33r @ncat

sour zealot
#

When will some new machines be added to koth?

jovial field
#

in an undefined amount of time

nova tide
#

Good question.

steep agate
#

more windows machines would be nice πŸ₯Ί

stiff egret
#

lmao

#

I wonder.

steep agate
craggy spruce
#

there aren't many koth players

fossil pecan
#

Don't get full 10/10 often tho

steep agate
#

16 min

harsh obsidian
#

I tried....no luck

craggy spruce
sour vectorBOT
#

Gave +1 Rep to @harsh obsidian

craggy spruce
#

how do people lock king.txt other than chattr?

jovial field
#

23min

craggy spruce
#

gg @harsh obsidian

#

@harsh obsidian did you harden or patch anything?

harsh obsidian
craggy spruce
#

cool thanks for not locking us out

#

have you solved the docx one? I have two users but not the docx one.

harsh obsidian
harsh obsidian
#

@craggy spruce I sent you a pm

craggy spruce
#

I'm amazed of all those players no-one else scored

craggy spruce
#

hello to anyone else playing carnage @MasterCynder @ATalkingSausage

sour zealot
#

Anyone know how to get custom name for busybox? Whenever i rename it it says applet not found

stiff egret
#

Um you can just download separate binaries?

#

Or compile your own - either way, you don't need to rely on in-box busybox. If someone messes with that, you'll never know.

sour zealot
#

Yeah but whenever i download the binary or compile it my self as soon as i change the file name it says: applet not found.

#

I know its possible but i dont know how

stiff egret
#

You realise that whatever applet you are using of busybox, can be compiled to run solo? e.g. chattr.

#

You don't really need the whole busybox package just to run chattr.

sour zealot
#

I know. I can rename busybox to chattr and it will work as only chattr or i can only compile chattr solo as you said but i just want the whole busybox package under a custom name.

quiet schooner
#

You might be able to rename it, but I suspect it'll try and use it's new name as the command

sour zealot
craggy spruce
#

is Tyler a bit broken for the upload one? It doesn't actually write the file you upload to disk?

sour zealot
sour zealot
craggy spruce
#

hi @sour zealot, really fun to play against you πŸ™‚

#

thank you for not locking us out

#

how are you locking king.txt?

#

oh I see

#

@sour zealot why can't I find your files? rootkit?

#

gg

sour zealot
#

gg

craggy spruce
#

please answer my questions πŸ˜„

sour zealot
craggy spruce
#

but I did a find for them

#

I don't see anything in /tmp now

sour zealot
#

what name did you put in the find because my files arent called busybox

craggy spruce
#

I'm looking in /tmp right now

sour zealot
#

yeah it was very weird. in one shell i had a different /tmp directory then in another shell

craggy spruce
#

interesting

sour zealot
#

no i never saw any of your command. were you hiding your shell or was it just me

fair adder
#

7 min

sour zealot
sour zealot
fringe valve
#

@fossil pecan Good game. I had no idea there was a 5th flag on the box.

craggy spruce
#

@fossil pecan please will you invite me to the current game?

fossil pecan
fossil pecan
craggy spruce
#
Opening backdoors ...
Monitoring ...
Cleanup ...
SNIPED (10s)
``` haha
craggy spruce
#

@fossil pecan did you give up?

#

you have hidden your processes

#

how!

fossil pecan
fringe valve
#

...

craggy spruce
#

hi

fringe valve
#

GG

craggy spruce
#

did you hack the score server or something

#

5 20m 420 vs 5 20m 290

fringe valve
#

I was thinking the same thing. is there a flag worth 200 points?

#

130*

naive goblet
#

the longer you are king the more points... so dunno anything else here

craggy spruce
#

we were king for the same amount of time

naive goblet
#

Β―_(ツ)_/Β―

fringe valve
#

I am not sure, but are different flags worth more points? Could it be possible F11snipes were worth more?

craggy spruce
#

@fossil pecan no progress on offline?

#

I'm sure I pwned it before but this time I couldn't work it out!

#

even if you don't play

fossil pecan
craggy spruce
fossil pecan
fossil pecan
steep agate
#

find / -name flag* -exec cat {} \; when I didn't know where the flags were on the machine. I always used this command haha

#

or grep -rli thm{ / 2>/dev/null

naive goblet
#

one of the koth boxes has "games" you can play which are binary files with flags as rewards for winning the games

steep agate
#

exactly

#

but it helps a lot of new koth players to look for the flags, just like it helped me in the beginning πŸ˜‰ @naive goblet

naive goblet
#

true did not claim said commands are useless just that there are now some koth targets that have more hidden flags that won't be as easy to access

harsh obsidian
harsh obsidian
#

Is anyone is down for a private game of H1: Medium? I have only one more flag to find.....

harsh obsidian
#

@fair adder hey man, do you have any idea where the sixth flag is? i'm losing my mind over here

harsh obsidian
#

I'll give it a shot, thank you

#

It still hasn't found the sixth flag. I'm good on the first five, but not the sixth

#

neither find nor findstr is working.......

fair adder
#

Don't know man

#

Where is the 6th flag

craggy spruce
#

@fossil pecan is it a rootkit you have or something part of linux?

sour zealot
broken pilot
harsh obsidian
median tapir
obsidian current
#

hi

#

check this out

stiff egret
#

What about it?

nova tide
fair adder
#

@verbal minnow

#

starting a machine

#

how many minutes ?

#

getting my machine ready

fair adder
#

looks like I won lol

#

insufficient players

#

i will use this time to install binwalk

craggy spruce
#

@bl4ckrabbit nice perseverance

sour zealot
craggy spruce
#

@sour zealot wrong link

sour zealot
craggy spruce
#

this is my first time playing H1: Easy

stiff egret
#

Have fun! @craggy spruce

craggy spruce
#

it's all over before it began

#

very easy web vuln

broken pilot
harsh obsidian
flint jacinth
#

Quick question about koth rules
am I allowed to play in the sudoers file to patch the way I PE the machine?
and change passwords/remove ssh keys

#

@steep agate Dude you are way much higher in level lol

misty elk
#

But you are not allowed to stop services or deleting the webpages, removing binaries

#

Except chattr, it can be removed

flint jacinth
#

alright

fossil pecan
#

gg @steep agate πŸ˜„

harsh obsidian
#

it's gonna come down to, quite literally, the last minute @fossil pecan

pearl pine
#

Hiii

#

Please tell me how to access a machine properly for koth

#

Can anyone help

fossil pecan
pearl pine
#

suppose i participate in a koth

#

there is an ip

#

say 10.10.183.139

#

now where to access that

#

i open a random attack box and try accessing it

#

but i don't think it works

fossil pecan
#

Attack box should work, better from VPN tho

pearl pine
#

I am opening an attackbox by going in a random tryhackme room and starting the attackbox

#

Will it still work !!

#

I'm a bit confused

fossil pecan
#

i'm not sure, i don't use attack box sorry .. i think they are on same vpn, did you try already and it didn't work?

pearl pine
#

Okay i'll try

misty elk
#

Download your openvpn from here

#

You can play with openvpn too

#

And if you don't know how to use open vpn here is the guide

steep agate
fossil pecan
harsh obsidian
#

nicely done @misty elk

harsh obsidian
#

c1nn3r, are you on here?

plain wagon
#

hi guys

#

i have a question

#

how to get intermediate?

nova tide
sour vectorBOT
#

Gave +1 Rep to @nova tide

orchid kelp
#

Hello!

fair adder
#

Yoyo

orchid kelp
#

Hello!

#

@sour vector ?

orchid kelp
#

gg

somber nimbus
jovial field
#

(24min)

median tapir
#

@steep agate How do you guys do that troll thing where you send ascii art over to someone's terminal in KoTH

nova tide
quick rapids
steep agate
#

I just saw the message now, sorry

broken pilot
#

Hahaha with goober dropping 8 flags right at the end.. will it be enough??

#

clutch move for the tie…

fringe valve
#

Haha I dropped them cause I knew i had no hope

broken pilot
#

Damn gg goober… with that last flag with 18 secs left

#

@fringe valve

#

Im bored at work watching koth games …. Hahahaha

fringe valve
#

Haha thanks.

#

It took me way too long to get on that box though haha

median tapir
#

By the way..how do i change my tryhackme username

naive goblet
median tapir
naive goblet
#

and also it might take a while before the email support gets to it as there is only one person handling said support email and they got a lot of emails to sort through

sour vectorBOT
#

Gave +1 Rep to @naive goblet

naive goblet
#

no problem

median tapir
#

quick question; besides editing the king.txt file, is there any other way to be king?

fossil pecan
quick terrace
#

uh is the lobby bugged for anyone else

nova tide
quick terrace
fossil pecan
#

ya same haha, we got all reset votes to get it going πŸ˜›

nova tide
#

aah that happens sometimes, iirc if you just hit refresh it would show up.
Not sure if that was the same bug in your case.

#

Did the machine show up as Machine Expired?

fossil pecan
#

no was empty on all loads refresh/fresh/new login

#

haha

quick terrace
#

didnt even appear in ongoing games

#

its good now tho

fossil pecan
#

ongoing matches only show if/when 1+ king minutes awarded .. i think πŸ€”

nova tide
#

Weird πŸ€”

fossil pecan
quick terrace
quick terrace
#

darn u

median tapir
#

Anyone know where the king file for the Medium machine is? I finally got admin priv but couldn't find it for the rest of the gameπŸ˜…

stiff egret
#

It should be in C:/Users/Administrator/koth/king.txt?

#

iirc.

median tapir
#

gg @steep agate πŸ˜ƒ

steep agate
median tapir
steep agate
median tapir
#

yh

steep agate
median tapir
#

sigh

median tapir
#

@broken pilot ggπŸ‘

steep agate
#

??

short tusk
#

@nova tide ?

short tusk
#

@orchid kelp You really thought you could delete this message?

#

@nova tide is this against the rules?

nova tide
#

After you chattr the binary you can't delete it.
Not against the rules.

steep agate
short tusk
#

Β―_(ツ)_/Β―

orchid kelp
#

what happened?

tranquil pewter
orchid kelp
#

@short tusk one bug in machine

#

@short tusk @nova tide
I didn't know but I was trying commands and there was no king.txt but when you are root you can create it again..

nova tide
orchid kelp
nova tide
half quartz
#

Is there anyway some of the staff/ more reputable members could help me?
I've been hacked and my devices will try to hack and take over anything else I connect to... so any KOTH games and lessons. Before I knew what was happening I noticed boxes were crashing and extra ports were open.
I was thinking of creating a private game, and inviting some of the top players/ staff to investigate and shut down the process ?

orchid kelp
orchid kelp
jovial field
short tusk
jovial field
# half quartz Is there anyway some of the staff/ more reputable members could help me? I've be...

maybe you should undermine your theory of being hacked by logging into an virtual box which is in a virtual network with your "hacked "machine and test (for example with tcpdump) what data is being sent. I mean if suddenly new ports are open on a koth machine it litterally means nothing. It could be that other players installed backdoors or the machine just took a bit of time to start up the services listening on the new ports.

nova tide
#

Hi @alpine quarry animewave

#

If you have any questions related koth you can always ask here or mail on koth@tryhackme.com
In your case deleting id_rsa shouldn't be an issue. πŸ™‚

quick rapids
#

Is BL4CKD3VIL#6424 here ??

serene crane
#

Who is rootpiebot?

quiet schooner
quick rapids
#

@quiet schooner DM ?

quiet schooner
quick rapids
teal oyster
#

Lol

serene crane
#

Im looking for F11snipe

#

@fossil pecan good game bro πŸ€ͺ

brittle flicker
#

Who is this Koth dude :3

stiff egret
#

And the milk is back lol

#

Long time no see @brittle flicker

teal oyster
#

@lavish crystal ??????

brittle flicker
#

I’m hoping this day finds you well :3 I’m thinking I’ll see this Koth guy after some practice on THM >;3

dusk cave
#

Game starting in 3 min

dusk cave
#

Someone up for koth?

#

yo just checked you on the leader board @fossil pecan you probably know all the flags and ways to get root on all the machines already:D

#

go easy on me

fossil pecan
dusk cave
#

ah yes

#

gl hf

teal oyster
#

@fossil pecan πŸ§‘β€πŸ¦―πŸ§‘β€πŸ¦―πŸ§‘β€πŸ¦―πŸ§‘β€πŸ¦―πŸ˜‚πŸ˜‚πŸ˜‚πŸ˜‚πŸ˜‚
Next match lolπŸ˜‚πŸ˜‚πŸ˜‚

teal oyster
#

@fossil pecan lol dude πŸ˜‚πŸ˜‚πŸ€πŸ€

grim moat
#

can anyone tell me what I'm doing wrong here while making ssh connection using SSH in Production KoTH. Even after supplying id_rsa file, password is being asked??

stiff egret
#

Someone could've changed the password.

broken pilot
#

@grim moat did you chmod 600 I’d_rsa ?

#
  • id_rsa
stiff egret
#

/ read only

broken pilot
#

No it doesn’t it shows 400

#

Id_rsa should be rw

stiff egret
#

I think it would work with r only. I could be wrong here though, never tried to compare these two.

broken pilot
#

yea I’ve never tried it with read only but thinking about it after I said it you might be right…

stiff egret
#

I mean it is on lesser permissions that minimum required, eh its complicated to phrase but yeah, iykyk

grim moat
#

tried all 400 600 700 still same

broken pilot
#

It could be they changed the sshd_config file to only allow passwords…

stiff egret
#
  1. Someone could've changed the passwords.
  2. What Trapnatized said
  3. You maybe have a newline in id_rsa key. Try with -vv to see if it is accepting key or not.
grim moat
#

Still same with rw

#

with -vv debug2: we sent a publickey packet, wait for reply
debug1: Authentications that can continue: publickey,password
debug2: we did not send a packet, disable method
debug1: Next authentication method: password
ashu@prod.thm's password:

broken pilot
#

Don’t know if you added your own ssh pub key in to authorized_keys .. but it could be permissions not set to 700 for .ssh and 600 for authorized_keys…

stiff egret
grim moat
broken pilot
#

Or they changed the public keys inside of authorized_keys and that’s why your id_rsa no longer works…

stiff egret
#

Plus, because the machines are not new, most of the older players know the machines, and know how to get in without even doing a nmap scan, as they have notes from the last time they did that machine.

broken pilot
#

I mean it all depends on who you are playing against too…. Cuz 10 mins could be plenty of time for them to change passwords, patch the vulnerabilities and add their own persistence…

stiff egret
#

We grow.

grim moat
#

Thanks for the info otherwise I'll be stuck at only one exploit forever thinking I was doing something wrong

stiff egret
#

There are mostly 3-4 ways to hack into every KoTH machine, so if one doesn't work out, you can start looking for others. There is a good chance that all might not be patched.

broken pilot
#

Agree’s with mr Holmes…

fossil pecan
lusty basin
#

Argh! Thought I was getting somewhere and now there's a king! πŸ˜‚ Lots of "Hello friend in my term" πŸ˜„

uneven whale
#

What's the fun about doing every koth machines a hundred times @fossil pecan ?

fossil pecan
uneven whale
#

Did you deleted the authorized_key file for user Ashu ? I wasn't able to ssh using his private key so I want to be sure that's not an issue on my virtual machine

#

@fossil pecan

fossil pecan
uneven whale
#

No that's fair game I should have done the same thing if I was connected first

uneven whale
fossil pecan
#

imo

uneven whale
fossil pecan
#

new password for ashu lemmeinpls πŸ˜›

uneven whale
fossil pecan
#

ya it's root vs root πŸ˜†

#

kindof is "unlimited", how root can you go?? lol

uneven whale
fossil pecan
#

ah, ya that's a tricky one haha

uneven whale
#

For an easy machine like it, 9001/9002 aren't obvious

broken pilot
#

GG @fossil pecan @lavish crystal @fair adder

#

motivation for me to get better

broken pilot
fair adder
broken pilot
#

GG @steep agate too fast bro..

steep agate
broken pilot
#

yea i gotta work on finding multiple ways in all the boxes...

broken pilot
#

@steep agate hahhaha that was funny. i was wondering why my chattr wasnt workind ....

#

*working

steep agate
broken pilot
#

hahahaha i thought that other other day when i killed your shell