#koth

1 messages · Page 6 of 1

jovial field
#

@civic vortex

civic vortex
#

weird, it's still 2 ports open only

#

I'll just reset

#

sry

#

Since i'm kinda new to koth

#

May I ask, will setting passwordauthentication to no be against the rules?

jovial field
#

The machine should not be made unavailable (shutdown/reboot, firewall/iptables rules to stop all communication, all services terminated, machine botching etc).
Only stop a service if it can't be patched any other way. Services should remain available for “genuine users of the box” if at all possible. Changing ports of services is allowed. (Try to keep the machines in as original state as possible.)

jovial field
#

so the answer depends on the machine

civic vortex
sour vectorBOT
#

Gave +1 Rep to @jovial field

rose nimbus
#

Hey Gray, this is the THM server, please keep it on topic of THM 🙂

rose nimbus
#

no worries, thanks

fair adder
#

hello, anyone want to play "king of the hill" game?

fair adder
obsidian lark
#

in 30 mins

#

or in 15 mins

fair adder
#

halilovic

#

can you add me?

fair adder
obsidian lark
#

sryy I had some work

lucid salmon
#

lol its alive yet

obsidian lark
#

Hey, can anyone access the THM website? or is it just me

slender frost
#

There is a problem with the KOTH offline

#

There is my username on the king.txt on C:\Users\Administrator\king-server\king.txt

#

But in the platform I'm not king

broken pilot
#

Did you make the file hidden??

#

Try attrib -h king.txt @slender frost

fair adder
#

What is chattr?

broken pilot
naive stag
drifting sapphire
#

Ayo @lament drift Imma need to speak with you

#

please

lament drift
#

Sure dm

unborn atlas
#

hello, is koth available for free users? asking for a school event

naive goblet
#

though you can't make private games or choose what target machine gets selected then

stiff egret
spark monolith
#

RustScan is good for koth too?

naive goblet
#

and generally you can make nmap just as fast as rustscan if you want to

sour vectorBOT
#

Gave +1 Rep to @naive goblet

spark monolith
#

When you guys do koth things you make nmap runs based on wich machine you are or you pick some based command like -sV -sC

#

Or its case-by-case?

broken pilot
#

Gotta get used to seeing my name in green now 😢😢I liked the red.... but I do get access to advanced chat now…

spark monolith
#

Btw how this tags works? like red teamer and 0xD

broken pilot
#

Red teamer was a role given during the launch of the red team pathway .. the 0x roles are based off how many points you have. You get points by completing rooms and solving challenges .. this next upcoming event might have a new role associated with it also.. I think they did away with the red teamer role so more people would participate in this new event… just guessing tho..

unborn atlas
sour vectorBOT
#

Gave +1 Rep to @naive goblet

unborn atlas
remote cosmos
#

can koth be played using thekali on the website

broken pilot
drifting sapphire
sly gazelle
#

can anyone tell me the how to find out the right way to approaching a koth challenge?

fair adder
obsidian lark
sly gazelle
#

what do you mean by ofc?

obsidian lark
sly gazelle
#

okay that's obvious

obsidian lark
#

yeah

#

maybe

sly gazelle
#

BTW Thank You for your suggestion...

#

can you suggest me some additional resources to learn more?

#

if you know some?

obsidian lark
#

yeah first of all play every box by yourself and have a rough idea about each box's vulnerabilities. For king persistence you can check out Matheuz's koth repo https://github.com/MatheuZSecurity/Koth-TryHackMe-Tricks or after understanding how the game works it's easy to build up your own king defense tricks

GitHub

Koth - TryHackMe Tricks. Contribute to MatheuZSecurity/Koth-TryHackMe-Tricks development by creating an account on GitHub.

sly gazelle
#

Thanks a lot...

obsidian lark
#

Your Welcome!

broken pilot
celest bronze
#

omg. I give up on this KOTH. I'm able to get a reverse shell for a few seconds and then it crashes. I finally found another reverse shell that doesn't crash yet I'm stuck trapped in the web folder and it's insanely slow. Arg

celest bronze
#

The rules mention don't delete any system binaries except for chattr. Does that mean we are allowed to literally delete /usr/bin/chattr ?

celest bronze
#

@broken pilot thanks. What about changing the permissions of /root/king.txt. The rules say don't change for flags but not sure if that applies to king.txt or not. I know Im allowed to use chattr

sour vectorBOT
#

Gave +1 Rep to @broken pilot

celest bronze
#

oh nice

steep agate
#

👀

fossil pecan
hoary wren
#

im gonna suck but ill try

obsidian lark
river oracle
#

ight this is gonna be my first game how do i play

eternal nebula
#

yoo guys

#

so i gained access to the system and rooted but how do people make the king.txt file uneditable 🥲

#

is it something related chattr binary on linux? perhaps if anyone could send me some reading material on how i can perform that

radiant sun
steep agate
visual geyser
#

alright @vestal saddle good luck

vestal saddle
visual geyser
#

thanks

crisp rapids
#

It's not giving me the shell come on

#

-_-

steep agate
crisp rapids
radiant sun
vocal python
#

I'm bad at defense. :/

steep agate
#

but i change again

steep agate
vocal python
#

That's the plan. Still managed to win tho.

brittle flicker
#

Man! This Koth guy seems popular >:3

fair adder
vocal python
#

Aren't automatic tools against the rules? Seems to be a lot of that being done.

crisp rapids
#

Scripts that automatically hack(autopwns) and/or harden the machine are forbidden

#

NMAP isn't one of them If you meant it

vocal python
vestal saddle
#

Kicking off users is allowed

vocal python
#

I've been approaching these the wrong way then lol

fair adder
#

its allowed but some players dont like it

#

they prefer to have a root shell x shell

#

about me? If it's in the game, you must use it

vocal python
#

I can certainly see how some wouldn't like it. but if it's allowed. as the saying goes. git gud, dont git mad lol.

vocal python
#

turning off ssh is lame. back to watching tv. blatant rule breaking

vocal python
steep agate
#

this fun

short tusk
fair adder
#

it wanst me, it was massco99

#

i hate when this guy resets the match to get king or just drops down the services

fair adder
obsidian lark
#

yeah i've seen him doing it multiple times

broken pilot
#

Another good tip is create a backdoor that doesn’t require ssh to gain root shell then it doesn’t matter if ssh works or not

vestal saddle
#

i patched the privesc to root and forgot to setup persistence , now i am myself not root lol

vestal saddle
#

@fair adder did you used chattr on itself?

fair adder
vestal saddle
#

Couldn't find a way around it

#

Tried uploading a different one but failed

obsidian lark
#

Aye koth buds

obsidian lark
steep agate
obsidian lark
steep agate
#

I release the rest of the pending functions quickly, I already have process injection, pam and ld_preload rootkit practically ready

obsidian lark
#

Glad to hear!

#

I've been making a ctf

lucid salmon
#

@quanvivc123

river oracle
#

Idk who tf bravosec is but ima catch you soon

obsidian lark
civic vortex
#

lol

civic vortex
#

I got banned from cloudflare

#

Cuz I was trying to send this

#

Guys you can try it

#

NjE0NzQ2NkE2MTMzNTI2RjVBNTc0QTc2NjU0MTNEM0QwQQo=

#

4E6A45304E7A51324E6B45324D544D7A4E544932526A56424E546330515463324E6A55304D544E454D30517751513D3D0A

steep agate
#

if you get king, 3 resets

#

lmao hahahahah

civic vortex
steep agate
obsidian lark
#

for no reason

#

dunno why

civic vortex
#

not only tryhackme but also discord banned that word

obsidian lark
#

yeah

civic vortex
#

6147466A6133526F5A574A7665413D3D0A

#

6147466A6133526F5A574A7665413D3D0A

timber crest
charred hare
#

its not banning that word lol

#

there was a discord outage to do with cloudflare

#

nothing at all to do with whatever context you sent

obsidian lark
#

@floral swan good game bro

#

i was on a call want a rematch?

cobalt flower
#

is there a way to check your world ranking at KOTH?

#

im #1 at my country leaderboards pfff

lavish haven
#

select "all countries" instead of your country

civic vortex
fair adder
#

i will never be the best of my country aff

keen sun
fair adder
#

i know every single entrypoint on this machine

keen sun
#

damn, im still new tbh i keep getting upto ssh into ramen ls grab the flags on priv esc using GNU Screen -4.5.0 i cant seem to do it you got any ideas?

keen sun
keen sun
#

5 minutes till start

obsidian lark
eager cape
#

Evening guys. Whats the best way to get into KOTH? Just find a team and go in? Is there matchmaking?

obsidian lark
fair adder
frank kraken
lavish sigil
frank kraken
#

@lavish sigil I know i'm struggling to win

river oracle
#

Aye hop on someone lets hack

stable field
#

anyone is playing

fallen trout
#

game starts soon

fair adder
#

Simply the best pokemon trainer!

Just captured a rare Fire/Hacker type pokemon!

cloud badge
#

play?

boreal crane
#

Yessir

vestal saddle
#

is it possible for a machine to be first hacked at 14secs of starting without automation?

obsidian lark
leaden torrent
steep agate
#

@karmic gyro lmao

#

Using redirects incoming TCP traffic on port 9999 to IP address 10.2.66.237 on port 45999.

short tusk
#

@karmic gyro If you block access to the king service, your access to King of The Hill will be removed. This is your only warning

river oracle
#

Koth game starting in 10

obsidian lark
steep dove
#

@fossil pecan heya it's me MeNub from recent koth, haha fun game but i wanted to know what did you do to king.txt i couldnt get the permission on it tsk tsk

fossil pecan
steep dove
fair adder
#

locking with chattr and later rm -rf /usr/bin/chattr

#

👁️

fair adder
#

I decorated it

#

So, it's possible

#

39 secs

#

old ss btw

naive goblet
#

yeah just throw busybox on the machine and hide it well

#

tada most utils available

fair adder
short tusk
nova tide
fair adder
#

pi

vestal saddle
obsidian lark
radiant sun
steep agate
#

your command failed against my chattr haha

radiant sun
#

you could've just echoed anything and append to it lol

#

it would've worked not a big deal

radiant sun
#

dude, it varies it was in my old notes, in my wsl size of chattr is way less

#

its just a find command Lol why you stressing

steep agate
#

ah?

#

I'm just showing that it didn't work for me, lol

radiant sun
#

cuz size of your chattr might be diff.

#

the size in the command ig is of busybox chattr

steep agate
#

yes, just know the size of the chattr

radiant sun
steep agate
#

the size of my chattr is bigger

radiant sun
#

yuh u used -static

steep agate
#

This happens because I used -static , so obviously the size of my chattr will be bigger

steep agate
#

If you modify some things in chattr, the file size will also become larger

proud moth
#

@fair adder its a easy one bruh. you can get king. try harder.

#

damn congrats for king @fair adder

fair adder
#

🙂

#

thx

ancient salmon
#

hello guys

i want to ask if tryhackme plans to add new machines to koth ? since all linux machines are vulnerable to PwnKit ( or most of them )

obsidian lark
steep agate
#

and certainly, if they gave more value to koth, it would become the best game mode, it has been in beta for almost 4 years or less, many players including me have already offered to create koth machines without asking for any money in return, just because I liked the game mode and it didn't do anything

#

There could be an update for koth, it would be interesting and certainly many would want to play again, create new techniques, produce content in koth, and as the game mode is "hacker vs hackers", it would be the most popular and certainly many people to play ctf on tryhackme

radiant sun
#

@rancid inlet

stiff egret
#

?

radiant sun
stiff egret
#

I really hope it's not your script @radiant sun

radiant sun
#

Haha Nope

stiff egret
#

Whoever's it is, will either get a warning, or a ban.

buoyant hare
#

I think you meant to tag sum else? blobfingerguns

stiff egret
#

@obsidian lark

obsidian lark
stiff egret
#

Aye

unborn latch
#

Hey Guys

#

Anyone interested for koth

knotty micaBOT
#
Mr.Holmes
Leaderboard Position

163924

Username
Points

2720

Subscribed?

No

knotty micaBOT
#
MatheuZSec
Leaderboard Position

237

Username
Points

78530

Subscribed?

Yes

#
h00dy
Leaderboard Position

2370

Username
Points

36985

Subscribed?

No

radiant sun
#

hey @steep agate , sup br

steep agate
#

sup

radiant sun
#

how you doing?

steep agate
#

good and you?

radiant sun
knotty micaBOT
#
SESUAV
Leaderboard Position

627

Username
Points

59695

Subscribed?

No

unborn latch
#

Anyone free

knotty micaBOT
#
foxieon
Leaderboard Position

13990

Username
Points

17741

Subscribed?

No

stiff egret
knotty micaBOT
#
jitender
Leaderboard Position

1247363

Username
Points

0

Subscribed?

No

knotty micaBOT
#
SalDvD
Leaderboard Position

2250

Username
Points

37730

Subscribed?

Yes

blazing hawk
#

guys any one to play

blazing hawk
#

yes

bronze root
#

Hey guys me and a couple of friends who are novices with Linux are thinking of trying a KofTH. But it’s saying I can’t bc I’m not intermediate. How can we all play?

short tusk
timber crest
#

Is koth hard? i don't quite understand it. will each person get a VM they have to protect and attack with or is everyone attacking one VM and adding their name to the sudoers file?

proven junco
timber crest
#

Where is this information? i looked around the website but couldn't seach it up or find it ? :/

proven junco
timber crest
#

sry for asking dumb questions 😅

fair adder
#

anyone wanna do a koth rn???

wild carbon
#

anyone wanna play a round of KOTH rn?

full bobcat
#

@steep agate Hi my Friend

steep agate
cold bronze
#

Anyone wanna chill and play some koth?

fair adder
#

anyone down to do some koth??

swift laurel
#

Hey guys !

cold bronze
final onyxBOT
#

There are no URLs in that message.

cold bronze
#

damn

jovial field
#

@dumbsheet

#

@slywooper

radiant sun
#

sup @jovial field

jovial field
#

idk me and SIxCode wanted to play a game and these two seemingly bots joined and began to spam reset the machine

radiant sun
#

lol

violet mesa
#

Hey, I just finished the junior pentest path. I am looking to do some koth to practice. Idealy not too competitive. Maybe cooperative ? with people of my lvl

blazing jewel
broken pilot
keen remnant
#

are rootkits cool in koth?

steep agate
# keen remnant are rootkits cool in koth?

yes, but most machines have the older kernel, and some machines do not have gcc or make installed, apart from other libs and dependencies that need to be included and compatibility...

#

but it is possible to use rootkits in koth, and with that you have advantages

keen remnant
steep agate
#

When you compile an LKM rootkit, it generates the ".ko" (kernel object) that can only be used in that exact version of the kernel on which it was compiled

#

Oh, unless you want to use user-land rookits

#

it will be less headache

keen remnant
#

I made ld_preload rootkit my only problem is libc version

#

i think

#

should probably look into lkm rootkits sounds interesting

violet mesa
blazing jewel
violet mesa
#

16h Eastern Standard Time

blazing jewel
#

Might be too early for me, I'll ping you if I'm around at that time tho.

broken pilot
violet mesa
#

As late as possible for me is fine. I hade a big day, need a nap

broken pilot
violet mesa
#

sorry, I think I will cancel for tooday.

golden basin
#

Are the machines running painfully slow today?

blazing jewel
#

Christmas traffic blobfingerguns

subtle python
#

wassup, anyone wanna koth?

violet mesa
#

I'm down

frank kraken
#

.

rain dew
#

KOTH is an exciting game but there are some idiots who uses automated scripts to take over the server within less than a minut and the support is dead.
I suggest renaming the game to king of the kid scripts 👍🏻

short tusk
steep agate
steep agate
steep agate
violet mesa
#

I nerver did any machine. Are there any other first timer ?

autumn narwhal
#

anyone in here

broken pilot
indigo cave
#

hey, anyone wanna do a koth

#

H1:Hard

obsidian lark
violet mesa
#

I'm down to find people who whant to make a gentleman agreement to play for fun with an agreed set of rules.

broken pilot
#

whoever wants to join, starts in 15 mins

broken pilot
violet mesa
#

Give me 30min and i'm here

steep agate
#

This is sad and a shame, because Koth is very famous, many players play it, and the lobby is sometimes full, with so many players playing it.

#

And there simply isn't any kind of rework, update or any information about any possible future update of Koth... I will always be willing to create machines for Koth, and I won't ask for anything in return because I like the style of play... Hacker x hacker

violet mesa
broken pilot
steep agate
#

I think we'll always get the same answer

#

I have no idea why THM doesn't pay attention to KoTH... But surely with more attention and love, it will become much superior to battlegrounds

#

because there are enough players to play koth, there is already a koth community where people love the style of play, THM just needs to pay attention to koth and it will certainly become much better and superior

broken pilot
#

never know tho.... maybe they get tired of hearing us and end up giving it a chance. or maybe we come up with some ideas for KOTH to generate some kind of revenue for thm and maybe they'll take it into consideration.

steep agate
#

I offer to make a machine without getting anything in return, no money, I wanted to do it just because I like the koth style of play

steep agate
#

many of my friends don't play koth because the machines are the same and tryhackme never supports updates

#

koth is very famous, many people like this style, if you pay more attention, it will definitely become much superior

broken pilot
#

maybe even something like new machines for subscribed players.. I mean we could hype it up with tournaments and other events around koth. that might drive more people to want to play also

steep agate
#

we just need a chance

#

yes that is also a great idea

#

but without a doubt I would definitely make a new koth machine, and certainly other players who love the game style would do the same thing

broken pilot
#

we could always just make some private ones lol ... and test them with certain players. Once its gets perfected then maybe we can turn it in and 🤞 it gets reviewed

steep agate
#

many famous people have already played koth and they all loved it, including john hammond, maybe if there was a new update, or something like that, if THM paid more attention to KoTH and so on... People would come back and play KoTH again (even so, MANY people play koth daily) and creating new content, new techniques, etc... would be really cool.

broken pilot
#

1 person spin up the box and share the ip between the players while we test...

steep agate
#

This spin box idea, I liked it hahaha

violet mesa
#

Ready

steep agate
#

that's a cool ideia lol

#

as if it were a random spin box

steep agate
violet mesa
#

Damn

#

Only intermediate and advanced experienced leveled users can play King of the Hill.

broken pilot
violet mesa
#

I'm lvl 9

steep agate
#

is the recommended level to play koth

#

intermediate

broken pilot
violet mesa
#

ah tanks

broken pilot
#

np

violet mesa
#

Want to go voice chat

steep agate
#

just wait, wait and wait...

broken pilot
steep agate
#

yeah lol

#

hahaha

broken pilot
broken pilot
violet mesa
#

Sure

broken pilot
#

are you ready now? if so i can set the game to start in 5 mins?

violet mesa
#

I am ready

#

I see you are already in a game that is about to end

#

no rush but I am ready when you are

broken pilot
#

are you connected to the vpn? and i forgot im not subscribed so i cant chose the boxes lol my bad

#

ill start a new public game

violet mesa
#

I am connected to the vpn

#

I am subscribed I can make the room

#

Here is the link

broken pilot
violet mesa
#

I dont mind

broken pilot
#

ok, i'll wait until you put your name into king.txt before i start to take king. I will step up the techniques every time you manage to take back king, to make it fun 😉

violet mesa
#

I foud a support page prety sure I can inject a payload there

pulsar carbon
#

test

#

@steep agate sup

#

im trying to take over the machine

violet mesa
#

For ssh bruteforce wich methode do you prefere ?

#

I was going to go with metasploit auxiliary/scanner/ssh/ssh_login

#

But I heard you can also use hydra ?

#

I have only use hydra on login form is there also a syntax for ssh ?
If yes that its would be way quicker then going trouh al the steppes of metasploit.
Or do you use an other methode ?

jovial field
#

but for koth usually you don't need to bruteforce

blazing jewel
#

A great instructor once told me "SSH is generally not the way" blobfingerguns

brittle flicker
#

This koth guy sure is popular!

blazing jewel
brittle flicker
blazing jewel
steep agate
#

🧐

pulsar carbon
#

Same lol

#

I’m confused lol

brittle flicker
pulsar carbon
#

Oh yes lol

pulsar carbon
#

man i can't tell if someone is patching carnage

#

😔

brittle flicker
#

are you feeling better?

pulsar carbon
#

Hmmmm

broken pilot
#

no one has scored king points in 12 hrs?... or the past 62 games ? blobhuh

young bramble
#

I guess the koth service is down. no one can set king since 12 hours ago...The games start normally but they are not registered. I've tried this also in private games. The same issue. If you write your name in king.txt, it gets ignored 🙂

broken pilot
#

challenge accepted lol

steep agate
young bramble
#

only flags points are counted 🙂

steep agate
#

I was looking, port 9999 is working normally, but the king's points don't count on the THM platform

#

Maybe it's a bug on the thm website

broken pilot
#

i think its on the scoring side like reading 9999 because koth service running and reporting the name on port 9999

young bramble
#

there is no connection on 9999. so I guess the backend machine where koth service is hosted is down

broken pilot
#

anybody tell em about it yet?

steep agate
#

It's been like this for more than 10 hours

young bramble
#

just filled a feedback form

broken pilot
#

@short tusk sorry for the ping but are you guys aware of this already? ^^

short tusk
#

Let me check 👍

#

Is this in every room or just one? @broken pilot @young bramble @steep agate

broken pilot
#

every game

short tusk
#

Okay thanks

broken pilot
#

no problem

young bramble
#

every koth game, including private ones

steep agate
#

last king

short tusk
#

I’ve reported the issue, sorry for the inconvenience:)

broken pilot
#

Ty

short tusk
#

We're investigating the KoTH issues,
Sorry for the inconvenience

short tusk
#

This issue has been resolved, thank you for your patience

pulsar carbon
#

thank you

swift pollen
#

hi

proud moth
#

@alpine quarry

? grow up bruh.

#

play the game not the reset game. !!

short tusk
proud moth
short tusk
#

You still have to let people be able to access the box

proud moth
#

i left the id_rsa and all other way to get in into the box as it is. Xd.

#

i just patched priv.

short tusk
#

Mhhm but you can't just deny them access to root, you didn't do that right?

proud moth
#

whats the point of patching the foothold aswell.

short tusk
#

What do you mean by you patched 'priv'?

proud moth
proud moth
short tusk
fair adder
#

Amateurs I’ll be hopping on the battle ground later today ;3

steep agate
proud moth
proud moth
steep agate
fair adder
#

You can dm me whenever you wanna play been looking for a bud to do battle grounds or koth with been years the group of people I used to play with every day just went their own ways

peak peak
#

i'm a beginner and i wanna try some KOTH, but i tried it once and had a big issue

#

I was completely clueless on what I could do to breach the machine, and at the end of it there wasn't any sort of feedback to help me see what I did wrong

#

It was a while back and I don't remember what all I tried on the machine

#

What tips could you give a beginner before they go to KOTH

upper marlin
fair adder
#

Lots of enumeration

fair adder
steep agate
#

WHAT? HAHAHAHAHAHA

naive goblet
#

duplicating matheuz bug

#

we now have two matheuz

steep agate
#

+1 KoTH bugs

#

hahahhaahh

steep agate
compact prism
#

The only one who actually can compete with @steep agate is @steep agate 🙌

dapper vigil
#

don't be a skid

sour vectorBOT
#

Gave +1 Rep to @compact prism (current: #1964 - 1)

solemn socket
#

@steep agate How do you persistence? pspy didn’t find anything useful.

steep agate
#

Did you mean persistence?

solemn socket
#

yes

steep agate
#

Oh yes, it's my persistence, you can find one of them using pspy yes...

#

script for setup persistence/backdoor

#

but other than that, I don't think pspy will catch the rest

solemn socket
compact prism
#

@proud moth @civic vortex really? who created the second account to impersonate me?SureBruh

civic vortex
compact prism
proud moth
#

i was gone after c:\ shares was disabled. lol.

tepid anvil
#

Every KOTH game I've seen has that same scoreboard lmao

#

One person gets in at ~10m or less then just maintains dominance

tepid anvil
#

Also I'd 100% be the flat line at the bottom NotLikeThis

fossil pecan
blazing hawk
obsidian lark
violet zealot
#

@steep agate got nyaned

white forge
#

man spent the whole time on hackers room trying to crack the password in hydra

fossil pecan
upper shell
#

@matheuz did u do reset?

#

@steep agate

steep agate
#

why?

upper shell
#

Oh no I thought maybe it was you, because most you need like 5 minuts to get inside the machine

#

most times*

steep agate
upper shell
#

Did u patch file upload..?

steep agate
#

but I don't know who clicked reset, if it wasn't you, maybe it was that other player

steep agate
upper shell
#

Oh huh

steep agate
#

I don't usually give patches, only with certain people...

upper shell
#

Oh yep now I see that you're on the machine

mystic granite
#

anyone up for a KOTH?

timber vale
#

hello guys does any one know how to get a nyancat executable binary to use in koth because im using mac m2 so my processor architecture is arm64

#

@steep agate how to do your nyan thing

steep agate
proud moth
#

dear thm staff where i can report bugs ?

#

Its a serious one.

willow raptor
proud moth
#

its a bug in koth.

#

not in room.

willow raptor
proud moth
sour vectorBOT
#

Gave +1 Rep to @willow raptor (current: #7 - 787)

willow raptor
#

sounds good, happy to help

white forge
#

how can we tell if every possible vulnerability was patched

#

theres literally no other way into the machine

#

tried AJP, the ssh key, file uploads,ftp,etc..

timber vale
#

@steep agate how you run ncat to anyone who run chattr even if he downloading it and running it in any other dir how did you do that ?

jovial field
jovial field
#

and you can find it by a hash of the content or the filename

jovial field
#

or even just some unique symbol in the file

#

therefore it doesnt matter where you put you chattr because he can still find it

#

you would either need to obfuscate the binary and randomize the filename or just use the syscalls for setting the immutable bit for ext filesystems

#

but you shouldnt reuse filenames or binaries as if he finds them once by chance he can certainly track them down after that fast

#

this still doesnt make it impossible to track your chattr binary but at least a bit harder

proud moth
timber vale
fair adder
#

will try it

wind kite
#

Do I need my own VM to participate in KOTH?

fossil pecan
wind kite
#

yeah it did, thanks

trail iris
karmic rover
autumn drum
#

.

autumn drum
#

Somebody wanna play?

steep agate
timber vale
proud moth
#

@lavish crystal here

@steep moss bro dont shutdown the box. !!

#

that's not how we play koth. Xd.

young bramble
#

Yes, ShaRif. If you read the rules, the first one tells you not to do a reboot/shutdown

fair adder
#

@steep agate the koth you just played (offline) did u get in with the CVE-2002-2443

copper olive
#

Is the best way to play koth is to jump right in with the knowledge you know?

fair adder
#

thats what i did

neon sluice
#

Might have to try that out

open lion
#

where is naughty and holmes

ember peak
#

RIP me gg @steep agate

obsidian lark
civic vortex
#

@steep moss nice one, no one reported you?

steep agate
#

LOL, is it a kid? 😂

civic vortex
steep agate
#

Anyway, I don't think there is any more staff or anyone to report to, the report email takes a while to be responded to and most of the time it doesn't result in anything other than an alert and even once it receives an alert it continues to do the same

civic vortex
#

yeah I'll just ignore him for now, he cant win even with "try hard"

short tusk
sour vectorBOT
#

Gave +1 Rep to @short tusk (current: #6 - 1162)

late lagoon
#

...

trail iris
#

How you can be king event nmap and gobuster not completed to scan ???
Lot of 0xG0D do C2 for pawned server ... it's will not interesting for play anymore...

#

for me the mission is to check vuln for that room and the bonus to be king.
Why not you @lavish crystal vs @steep agate vs @steep moss to play, and let the other's play farewell

civic vortex
#

@dire shell thanks for helping me secure the king JoyFacepalm

sour vectorBOT
#

Gave +1 Rep to @dire shell (current: #2001 - 1)

stiff egret
violet zealot
steep agate
steep agate
steep agate
#

the main objective is to defend the king, so some players use advanced resources to defend

trail iris
#

the nmap does not give the result yet but the machine was pawned.

steep agate
#

There are few players I have observed that use autopwn

#

But the real challenge is defending the king, you learn a lot of new things from other players and by researching too...

#

It was thanks to koth that I became very interested in rootkits

trail iris
#

Yups. i know THM from watching John Hammond Play Koth on YT. and that's cool for me as a noob

steep agate
#

If it's like John's video, I think for beginners it would be cool to play private games with friends first, and then play in public to get used to it.

trail iris
#

4 minutes to run

#

Let's play farewell

violet zealot
trail iris
#

or C2 Server

violet zealot
#

wait what?

#

i don't see how u can use a c2 on thm

short tusk
#

It is against the rules and will result in a ban.

violet zealot
#

what's happening with koth machines?

#

added to /etc/hosts but can't nmap on it

violet zealot
short tusk
#

more specific tools

violet zealot
#

bruh

steep agate
# violet zealot what do u mean by autopwn ?

in short, a script that explores the machine without having to do anything, just execute, and it already gives you access to the machine with root, and automatically fixes the machine's vulnerabilities

#

and this results in ban

violet zealot
#

is it just me?

steep agate
violet zealot
#

yeah but why is it blocking without it?

steep agate
#

idk

violet zealot
#

kk

violet zealot
#

autopwn is okey, but the others?

#

i don't want to be banned for doing something fishy

steep agate
violet zealot
#

what it means "harden the machine" ?

steep agate
#

make the system more "secure"

violet zealot
#

oh okey

#

tf is going on

steep agate
violet zealot
#

im giving up i just can't interact with the machine

trail iris
#

GG

trail iris
steep agate
#

gg

violet zealot
#

any idea on why i couldn't interact with the box?

#

is it happening sometimes for u too or im just cursed?

steep agate
#

especially for koth and especially on some machines, I recommend you use rustscan, it's much faster

violet zealot
#

i did see it on some ctf writeups but never tried it

#

but if nmap can't ping the machine i guess it would be the same for rustscan?

steep agate
#

well, I like to use rustscan in CTF's

trail iris
#

Hei ... are you patch the vuln?

steep agate
violet zealot
#

from wich level we can play koth?

#

my mate wants to play but it says "only intermediate and advanced experienced level players can access"

violet zealot
#

yup just found it thx

steep agate
#

you can go to "Experience Level" and change

trail iris
#

are you loop script?

#

GG bro nice game

steep agate
#

it's my custom rootkit/LKM

#

gg

violet zealot
#

i can't believe it

#

im in a private game and gaine, can't even interact with the machine

#

i can't nmap nor ssh on it

#

nothing

steep agate
#

maybe problem with your vpn

violet zealot
#

am i dumb or?

#

pretty sure it's a private key file 🤡

violet zealot
#

Okey just to be sure : am i allowed to use scripts to patch vulns?

#

Not autopwn or anything else, i gain access normally but use scripts to patch vulns

violet zealot
#

is it normal if i get disconnected from a user shell?

#

i was looking for flags and got disconnected from shell, im trying to get back on it but nothing...

#

i guess it's time to sleep...

terse willow
#

You're missing a bunch of newlines there

violet zealot
#

i didn't really used it so i was referring to a writeup on htb

late lagoon
#

Mk0, if the file is encrypted, do you need to break a pw to decrypt it? Maybe ssh2john on the hash and then supply a wordlist?

terse willow
# violet zealot really?! like what?

Try creating an encrypted RSA key yourself and see what the format should be. You can then compare that with the one you have there. Should be pretty easy to fix after that.

terse willow
late lagoon
#

Ahh I didn't see that that far back

violet zealot
#

@steep agate can u explain?

#

20 seconds?

steep agate
violet zealot
#

flags or root?

steep agate
#

detail: when I entered the machine you were already rooted and using /boot/koth.sh to protect king, so I just used my LKM and became king

violet zealot
#

idk whats the meaning of "firsthacked"

#

but i was not root

#

i was in fact in a bash somthing

#

but not root

#

idk very well of koth

steep agate
#

3 minutes after you haha

violet zealot
#

yep shrek flag

#

bruh i thought it means king

steep agate
#

you were supposed to be king at 20:22, but when I loaded my LKM, I was the king

#

hehe

violet zealot
#

oh i didn't think of that this way

#

i thought u became king in 20sec 🤡

steep agate
violet zealot
#

im reading ur github repo

#

i didn't think they were so mystical techniques to defend

violet zealot
#

im so lost on windows NotLikeThis

violet zealot
#

Fortune box is broken (for me) because i got the creds and can't ssh with it

#

Or maybe im doing something wrong but i extracted the creds.txt file 3 times to be sure i got the right password, used it on ssh and got it wrong...

terse willow
#

I built that machine years ago. The autogen has never failed before. Chances of it spontaneously starting to fail now are slim

violet zealot
#

At that time I was the only one on the shell, that's why I forgot about this idea

#

But yeah I thought about it at first cuz I do it too 👀

steep agate
violet zealot
terse willow
#

Well now that's interesting chceyes

#

If that happens again, do us a favour and grab both the hash from /etc/shadow and the plaintext credential for me please?
There's nothing I can do to amend the machine unfortunately, but might be able to figure out if there's an issue technically

violet zealot
#

(btw are u planning on adding new machines for koth?)

#

@terse willow sorry in advance for the ping

terse willow
violet zealot
#

Okey np thank u

steep agate
terse willow
#

The project was effectively abandoned years ago.
Again, whether that's still the case or not, I couldn't comment

steep agate
#

But I still hope that one day we will have new machines 🙏

fair adder
#

anyone wanna do koth with me?

violet zealot
#

if i get root, patch the vuln, change root password and protect the king (delete chattr etc...), except for lkm how can someone get the king back?

stiff egret
violet zealot
#

What kind of persistence? I don't really see how am I supposed to do that on a koth machine. And I don't understand the "faster write" part

stiff egret
#

About faster write, that basically comes down to the efficiency and speed of the method you are using to write into the king file. For e.g., There could be better ways, but in most cases, running a python script to open the king file and writing your name into it would be slower than say, a compiled C binary that does the same thing.

violet zealot
# stiff egret You should read on persistence. Basically, if someone got in first, and setup s...

Yeah i know about persistence, just wondering about this case because im pretty sure i got in first and in the rules it says no script for autopwn... persistence is okey? And the machine ip reset every time so i guess a persistence can't be on the machine everytime, but maybe im wrong im still learning koth (i do pentest but never did this kind of things). Idk if im clear because english is not my native language, im doing my best 🙂

And for the faster write part, i recently wrote a custom shell script to write my name in king.txt, chattr and remove its binary and then whange passwords. But if im the first to get in, except for lkm (i have to look into that its pretty cool) i don't full understand how some people keep getting access despite my defense 🫠

#

The case im talking about is i got access to root and became king, waited for like 10mins and then the king changed, i couldn't write in it (permission denied) and then i got kicked out of my shell and couldn't get back in

stiff egret
#

Okay, so one thing at a time.

  1. Persistence is okay, and in rules, it is actually part of the game.
  2. You have to setup persistence every time in a new machine, but it is irrelevant to the machine IP, for e.g. a script that in the background sends my IP a rev shell every 2 minutes, does not need the machine IP in it. This is a very basic example and probably won't work against advanced players.
  3. You need to understand that even if you delete the chattr file, people can upload their own under other names and use them instead.
#

Also, it's a competitive game, meaning people will continue to change the king file and you'll have to defend it every second, your script needs to hidden enough that others cant just kill the process from ps aux.

stiff egret
violet zealot
#

And didn't think about killing the process too

#

Thanks a lot for ur answers, i'll read some doc about it (and if u have some or advices for me my dm are open)

steep agate
#

maybe this repository will help you with koth

violet zealot
#

there is sooo much to understand and learn

violet zealot
#

I'm on Hogwarts and my nmap says ssh on port 7958 but i couldn't ssh on it

obsidian dagger
violet zealot
#

On windows machine where am i supposed to find or write the king file?

#

its been like 10-15mins im root but cant figure it out

#

and for some reason my shell died

violet zealot
#

wtf is that

#

nobody became king and i got all the flags in 1st

#

and he's using multiple accounts 🤡

short tusk
violet zealot
#

i didn't save it, can i find it somewhere?

short tusk
violet zealot
short tusk
violet zealot
#

yep

#

oh i think i got it

brazen cloud
steep agate
brazen cloud
#

Sure! I'll keep a note of your interest if we progress with anything. But yeah, not a definite 100%, or if so, when...but fingers crossed!

steep agate
#

I hope everything goes well, KoTH is loved by many players, but certainly many are already happy with this news including me, I will do what I can to help, if you need any help, you can count on me 🙂

violet zealot
#

Same here blobfingerguns

subtle python
short tusk
violet zealot
#

lmao i don't understand how the victory system works

short tusk
steep agate
# short tusk Looks like it's alphabetical

in fact it is not like that, for example, mk0 must have entered the match first, then mascoo, so the system counts the victory as whoever entered last, if no one marked any flag and no one was king, the system gives the victory to whoever entered Lastly, I watched this for a while

trail iris
violet zealot
#

im trying to write that too

#
Medium

Grabbing the Golden Ring-0

GitHub

Linux Kernel Hacking. Contribute to xcellerator/linux_kernel_hacking development by creating an account on GitHub.

trail iris
steep agate
honest flicker
#

@violet zealot gg man, nice new websites xd

honest flicker
#

was it telnet?

violet zealot
#

nope?

#

u mean the entry point?

honest flicker
#

yee

violet zealot
#

rce in cmd parameter

honest flicker
#

whaat? i thought i found all websites

#

well, enumeration is key i guess

violet zealot
#

i unpatched it, u can try again

honest flicker
#

oh so 3000 wasnt your custom port?

violet zealot
#

nope

honest flicker
#

ohhh, i didnt find it in my first scan

violet zealot
#

nodejs server running on port 3000

honest flicker
#

yep, found it in the second try

violet zealot
#

This guy is spamming reset NotLikeThis

violet zealot
#

@fossil pecan lkm script?

violet zealot
#

i knew it 👀

#

how am i supposed to counter it lmao

fossil pecan
violet zealot
sour vectorBOT
#

Gave +1 Rep to @fossil pecan (current: #100 - 63)

jovial field
#

gg

#

oh no gg doesn't give rep points anymore

north wolf
#

Playing koth for the first time!

steep agate
#

GG! @violet zealot

violet zealot
trail iris
steep agate
violet zealot
violet zealot
#

@steep agate if u and f11snipe use the lkm, can u bypass each other defense or it's the first root who wins?

#

wait u can play multiple games at the same time?!

steep agate
violet zealot
#

yup

steep agate
#

btw, and there are still compatibility issues with the kernel, as most koth machines have an older kernel... which causes a lot of conflict with different techniques

violet zealot
#

i wrote a script that could maybe do the job but actually trying to fix compiling issues NotLikeThis

indigo furnace
#

Good day everyone! How do I find KoTH players??

#

It's my first time even hearing about it and it seemed interesting

violet zealot
#

Just start a public game and wait, u will match someone

north wolf
#

won on 2nd attempt!

steep agate
# north wolf won on 2nd attempt!

Nice! I forgot (afk) I was at the match completely, I went out to shower and have dinner haha, I returned to the game with 4 minutes left

#

hehe

hallow tendon
#

i can type now 🥳

hallow tendon
#

you guys have access to the box?

north wolf
#

it isn't updating at all WTH!?

#

It's been like more than 5 min. 😐

#

still I could verify its my username and another minute passed away

#

this is cheating man 😩

naive goblet
#

did they kill the king checking service????

#

because if they did that is indeed cheating and against the rules

north wolf
#

and I cloudn't even find koth binary within /root

north wolf
north wolf
#

funny that its still my username lol

naive goblet
#

@short tusk seems someone needs checking in on following the rules about koth as they might have killed the king service

short tusk
#

You need to submit a ticket to customer service

north wolf
short tusk
#

Press the bubble in the bottom right corner and speak to the chat bot about reporting a user in KoTH

naive goblet
#

ah did not know the procedure

#

thanks jabba

north wolf
#

done, thanks

steep agate
#

check the mount command @north wolf

acoustic drum
#

anyone online wanna do koth?

north wolf
north wolf
obsidian lark
# north wolf

there’s a one liner to achieve “read only file system”

#

mount —bind -o ro /<location>/ /root/king.txt

jovial field
steep agate
# north wolf

Oh, you probably got this from my koth repository, or from @jovial field haha

#

this is very easy to undo

obsidian lark
north wolf
wintry needle
#

Hi I tried to do the kung fu panda KOTH, but im not sure of how I could get into the system.
I tried brute forcing the ssh for the password.
I tried looking for videos, but none of them showed good solutions.
Thank you.

violet zealot
#

if i remember correctly it's either an lfi or a rce

#

let me check my notes real quick

#

nvm it's related to wordpress, u have to find the right path, then bruteforce it with something like wpscan and then get a php reverse shell (dw u will find where)

wintry needle
#

oh ok. thank you.

trail iris
naive goblet
trail iris
naive goblet
#

yeah you can do a decently big amount of things in koth but some good rules are also established

craggy storm
#

@fossil pecan bro where was chattr

#

also how did you got root

fossil pecan
#

Feel free to DM me if you wanna chat more, can play practice matches sometime also if you're up for it

light relic
#

Good game @fossil pecan - I need to say that you locking king.txt in many ways was the hardest thing to deal with in this game

viscid torrent
#

whos the wise guy LOL

rose folio
#

Are you allowed to use chattr binary to lock the king.txt file? The rules say "Don't modify flags or their permissions" but under tips and tricks it says "King.txt file locked? - A user might have used the chattr binary to stop even a root user editing the file." implying that's not against the rules? So I'm not sure if that's allowed or not

viscid torrent
#

I think the king file is game, but flag.txt is not

#

thats how I have played anyway.

rose folio
#

Alright.

viscid torrent
#

chattr is also not in all the levels. if you are going to use it, bring your own binary

#

i need more practice. someone got me with a wall bomb lol.

rose folio
#

THought you're not allowed to attack other users

jovial field
#

you should not attack them on their own machines

rose folio
#

granted I am not sure how that's defined exactly, i.e. is it kosher/allowed to terminate their shell and boot them?

jovial field
viscid torrent
#

yeah, part of the game is yeeting the "bad actor" out of the system

rose folio
#

boot as in close the shell

#

so they get disconnected from the KOTH machine

jovial field
#

yes but you don't want to spam someone with killing shells (automated f.i.)

#

because this is just not fun to play with

rose folio
#

yeah ther'es a rule no automated scripts

#

I mean like using ps and kill to close their shell manually

jovial field
#

sure but don't spam kill every time you see someone enter the machine

#

Everyone should have a chance

#

This also applies to not patching the whole machine

#

leave at least one entry point

rose folio
#

eh, I thought patching the whole machine isn't against the rules,

jovial field
#

it isn't but this is just common sense

rose folio
#

For good sportsmanship/rule of fun, I agree though

jovial field
#

yeah

rose folio
#

I imagine finding a way to install/setup a backdoor is a smart choice because it'll make it harder for the other users to keep you out

jovial field
#

I mean you dont want to be completely dominated by someone like f11snipe or matheuz. And just like that let lower skill players play and learn

rose folio
#

Yep

jovial field
#

most players are doing exactly that

rose folio
#

I do wish you could do a practice run on a KOTH machine, like a match with just you so you can practice compromising the machine

jovial field
#

I think there are like one or two machines where you can do that

viscid torrent
#

matchmaking would be nice to. kinda sucks going in a room with someone who has done the room a billion times

jovial field
#

getting into the machine is easy especially if you have done it before

rose folio
#

Makes me wish procedurally generated VM's were a thing

jovial field
#

there are several sneaky tricks out there with different levels of complexity.

rose folio
#

so you could have randomized KOTH boxes so it's always a fresh experience

jovial field
#

but it is still easy

viscid torrent
#

hogwarts is weird lol...I was super high last night, and thought hogwarts was different the two times I plated it...nice to have confirmation lol

#

played*

viscid torrent
#

@fossil pecan am I barking up the wrong tree with trying to buffer overflow

steep agate
#

@viscid torrent check dm, pls if you can

jovial field
#

there is no koth machine that contains a buffer overflow i know of

viscid torrent
#

thanks terraminator

viscid torrent
#

@fossil pecan good game friend. you got me by 3 minutes I locked myself out of one of the vulns and can't find the other one.

elder rapids
#

Want to get into koths but dont know if Im high enough skill level. What do you recommend knowing for them? I've completed the intro to cyber security and the jr pen test learning paths as well as a variety of other rooms

viscid torrent
#

just jump in dude. you wont know unless you try it out

jovial field
#

yeah just have fun

viscid torrent
#

I thought I had @jovial field on that one...but nope

jovial field
#

xD

jovial field
green finch
#

and bro cheating and getting root shell and removing binaries like cd , ls ... looping a wall command ain't gonna make you nothing else than script baby @muted gyro

near lily
spark galleon
amber raven
#

anyone wants to play?

rose folio
#

Are we allowed to use TheFatRat to install a backdoor on the machine or is that too malware-y

short tusk
rose folio
#

Some sort of rootkit that puts in a backdoor,

#

description on github says "This tool compiles a malware with popular payload" so I don't really know what the heck it is

#

Seems like some tool that uses metasploit or something to create a rootkit/backdoor dunno if that would be too cheesy for KOTH. (mouse-related pun not intended). The "guide to koth" blog post at least mentions rootkits are allowed for persistance

rose folio
#

Upon further research it looks like it's mostly just a tool to automate MSFVenom to creat a backdoor, I believe which is part of Metasploit. Either way I thought I'd ask if something like that is allowed just to double check.

steep agate
#

You'd better use or create your own rootkit to stay hidden in the system

rose folio
#

Do players often use rootkits in KOTH?

steep agate
#

backdoor any user can take you down and leave your backdoor inoperable

steep agate
rose folio
#

I know like one tips for KOTH guide on github said something like "Rootkits are allowed but are considered unsporting, a good rootkit user is virtually impossible to stop once they set it" etc

steep agate
#

The use of backdoors/rootkits is allowed, as long as you do not break the machine or leave it inaccessible

rose folio
#

Yeah, I'm saying like a tips guide on github (an unofficial one) was saying they're unfun to play against and the author of the guide dislikes people who spam them on public games

steep agate
sour vectorBOT
#

Gave +1 Rep to @rose folio (current: #2040 - 1)