#koth

1 messages Β· Page 11 of 1

fair adder
#

a begineer question what does that windows machine means ?

fossil helm
#

inside

#

com

#

come

fair adder
#

@fossil helm come

#

koth

#

voice chat

fossil helm
#

no im on the bed now with my xD

#

cant make noise

fossil helm
#

im there

fair adder
#

I started just now

#

reading writeups

fossil helm
#

yeah i gain a lot of knowledge in koth too it's my 2 weeks of playing koth i will just try to get 101 wins then stop for a month or 2 months cuz i will do some quest after

fossil helm
honest beacon
honest beacon
#

@civic vortex sh-4.2# sudo systemctl restart sshd
Error: No space left on device
Warning: sshd.service changed on disk. Run 'systemctl daemon-reload' to reload units.

#

i have faced this first time.What's that ?

civic vortex
#

just try systemctl daemon-reload

honest beacon
civic vortex
honest beacon
#

and playing with opponents not with machines

#

🀣

civic vortex
#

yeah I dont like to just load my stuff and set king, then go another game

honest beacon
#

you came using tigress ?

#

@civic vortex

#

root 2105 0.0 0.2 156700 5572 ? Ss 03:28 0:00 sshd: tigress [priv]
tigress 2123 0.0 0.1 157028 2768 ? S 03:28 0:00 _ sshd: tigress@notty what that mean ?

#

tigress@notty ?

civic vortex
#

maybe some leftover connection

honest beacon
civic vortex
honest beacon
#

ooh -T or -t ?

#

so we can't identify by who command

civic vortex
honest beacon
sour vectorBOT
#

Gave +1 Rep to @civic vortex (current: #491 - 10)

honest beacon
#

By the way i know you always inside machine

#

πŸ˜†πŸ˜†

#

Just waiting someone to do first move

fossil helm
#

Im done see u nextime lol

#

In 2weeks of playing koth i enjoyed it

#

So this is ctf i am curious about atleast i have now ideas

#

Thanks to those people i dmed when i need a explanation the community is helpful also giving some motivations 😁

honest beacon
fair adder
honest beacon
#

@civic vortex who are they ?

#

they play bulklyπŸ˜†

civic vortex
honest beacon
#

first time i have seen a lobby full of players

honest beacon
#

and they all left on last 30 seconds and joins another game in 30 seconds 🀣

civic vortex
#

But I guess its a fake account too

honest beacon
#

And on tyler machine they own machine and closed all ports only 9999 port is open and we can't reset becouse we need 5 accounts to be reset for resetting machine and i thought there are only 4 players that plays game and in lobby there are 10 🀣

#

and now king is Travix

civic vortex
#

yup some Anti-societies want to win games with fake account

honest beacon
#

but he is afraiding from you brother @civic vortex 🀣🀣

civic vortex
#

what a weirdo

honest beacon
#

by the way i have copied link to gane too

#

and there are only 2 peoples there you and he but there are 6 accounts 🀣

#

i think we should fight he has 5 accounts so we also need 3 more accounts we both teams will controll game

civic vortex
#

Im just gonna watch what hes doing

honest beacon
#

it will be equally

civic vortex
#

ik but I dont want to spam reset against him

#

waste of time

honest beacon
#

so you are making a honeypot for that bee πŸ™ƒ

fossil helm
#

Imagine he put so much effort just to win lol bet he is using firefox extension multi container so its easy to setup if you really want

#

But he solved boxes in each accnt because its all the same 0x4 level

honest beacon
#

noone paid here for solving games

honest beacon
#

@civic vortex I saw you firs time resetting machine 😁

#

is there no way other than ssh for shrek ?

civic vortex
honest beacon
#

I closed the doors for you

#

but you just break the door😁

civic vortex
#

πŸ’€

#

ok it crashed again

honest beacon
#

I just play from 5 hours.So i just go .Bye brother

steep agate
honest beacon
#

Not closing the port brother

#

It's just like riddle

#

🀣🀣

civic vortex
honest beacon
#

Don't go on words.Feel them

civic vortex
#

its an old machine anyways

honest beacon
#

i just closed all windows

#

except discord

civic vortex
#

πŸ‘Œ

honest beacon
#

you can reset again

civic vortex
#

no big deals

honest beacon
#

yeah

#

But, it's working on my side

#

I'm able to ping that machine

honest beacon
#

or problem nly from your side

civic vortex
#

maybe my persistence script confilcts with your actions

honest beacon
#

how even it's possible

#

maybe your vpn freezing that time ?

civic vortex
#

welp it only happens on shrek and hogwarts constantly, not my VPN issue

honest beacon
#

Anyway leave it I have to go for dinner>Bye

civic vortex
#

lmao @alpine quarry rebooting machine again, havent seen him for a long time

fossil helm
#

When you're all sleep hehe

civic vortex
fossil helm
#

Lol

#

Anyways i watched masco's youtube before when i was new playing koth he is good

civic vortex
fossil helm
#

Fireworks so weird box but its challenging

near lily
#

Fireworks changes.

steep agate
# near lily Fireworks changes.

Does Fireworks have that mechanism for automatically generating boxes with different paths? I think this functionality is in business right?

near lily
steep agate
#

Oh i understand

steep agate
#

better than chrome

fossil helm
#

Let's do this k2

steep agate
fossil helm
#

Yeah yeah also pyrat

#

Looks like people are busy over there

ancient cliff
#

bro is just farming here

stiff egret
civic vortex
#

it gains the feeling of power and to be in control πŸ’ͺ

honest beacon
ancient cliff
sour vectorBOT
#

Gave +1 Rep to @honest beacon (current: #1494 - 2)

ancient cliff
#

i had root for 20 sec i guess πŸ™‚

#

now im learning to draw filesystems to read-only faster than my gun πŸ˜„

honest beacon
#

yeah you are right brother

#

but , at first i just try to solve and patch the machine fully like changing ports and so many things and created so many thinhs.But, for now i just have 1 script that kills tty sessions amd you can always bypass it using ssh -T username@ip and as all know i don't use LKM's so if someone is inside machine so he can beat me.But,i think this help them to learn a lot when play against me .I just give them chance i use chattr only to protect king nowadays.So if someone just use walkthroughs can't understand concept untill they face some problems.If someone though someone is killing my shell everytime so that person has to think that he also can kill his shell or try to find another way to bypass it.So,it's just helping them. To understand how rhings are working

#

i remember when someone has change password for a user.so i decided to learn that thig.how to change passwd.someone change pkrts so i just make script to change port and i just understand concepts by playing that onlu

#

by the way i'm not spamming games brother.So i play upto 20-25 games everyday.so i will think about others and will join only 5-10 games a day and try to keep machine as natural as possible

#

Ot was earlier when i think about leaderboard.But now i don't play for leaderboard.Just play to learn.But, sorry if you think i'm spamming.

#

And also thanks for it.

#

But do you know a thing.If i stop myself for joining that games.Lobby will be closed due to insufficient players 🀣Becouse everyone know if i will be inactive then other person come and join every gane

#

so nothing will change in my openion

#

but, thanks for realising me that,From tomorrow ownwords i just join maximum 10 games a day insted of 25-30

honest beacon
fossil helm
#

Solve thm boxes guys

#

Thm will not listen to your rants πŸ˜†

#

If you paid come and join me solve this new box K2 im almost drained and 24hrs solving but im on my way to finish

fossil helm
#

I saw you when i was new here in koth channel. We had the same rants before but dont be discourage just play and learn they will get tired so that hours you will practice and enhance your skills.

fossil helm
#

@fair adder also we're the same before i also get pissed off. Like what the heck is this guys is like a bots. I tell you, you will not be as good as them but you will learn pretty soon some techniques that you can use.

sour vectorBOT
#

Gave +1 Rep to @fossil helm (current: #2255 - 1)

fossil helm
#

Well, just wait until they make the all the machines like fireworks machine so that would be interesting and fun to play. THM koth is still beta but no offense their beta takes years πŸ« πŸ˜…

steep agate
#

Take the chance to play against players using rootkits to learn more (if you want) πŸ˜„

#

It's good when you play against good players, you try harder, and you learn more things by researching

honest beacon
#

did you play against me ?

#

I never used rootkits

#

i just use chattr at maximum protection for king.txt

#

and sometimes i just don't use it too πŸ˜…

#

But, if you think why always my terminal got killed.So you will grow πŸ˜…This happened to me earlier but then i realise how to play against it.So now.Untill corona comes we don't know how to face this situation.So, belive me if you really wanna face this and doing some great thing.You have to face a lot things and find other ways rather than blaming.I know you are right brother.KOTH should be improved and having some restriction too.But, we have to play as it is becouse, it doesn't give restrictions.So we have to face this to become good.Noone knows me before 40 days and even Thinktwice is new.But we both have same concept Learn by fun.So we just learn new things everyday rather than blaming anyone πŸ˜…

#

But, if everyone is not using rootkist.Then it should be improved 🀣Becouse in my openion rootkit's seems cheating in my openion.According to me we just habe to patch machine not making machine ours by rootkit 🀣But, still who cares Tryhavkme never reads feedbacks 🀣So we have to play as it is πŸ™ƒ

steep agate
honest beacon
#

joint victory of all 5 is 136 victories and all other player have 20 victoriesπŸ˜…

#

and this data is of only 4 days

#

So just think how annoying is this for new users

#

even they scared of joining public games

#

there should be a limit

#

in my openion

near lily
honest beacon
# near lily <#757261859270426745>

i have tell them so many suggestion at that place before 30 days.But, i thenk either they don't have time or they really doesn't care about it.

#

if you are a moderator please checkout my suggestions and think about it.The thing you think it has to be change just change or other than that leave it.

fossil helm
#

In the world of kung fu, speed determines the winner - Bruce Lee
πŸ˜†

#

@honest beacon you know it

#

Maybe when THM koth was new to the public i saw videos and streams 2 years ago yeah they enumerate and aim for flags so enjoyable to watch.
But now. What bruce lee said is applicable to that ctf koth πŸ˜†

honest beacon
#

But, in both cases nothing will change untill Tryhackme Mod team don't do anything

inland falcon
#

πŸ‘‹

steep agate
#

like this

#

I just wouldn't share it because I think it would be a mistake to do so with his rootkit in the koth chat, but I did a good analysis out of curiosity.

obsidian lark
honest beacon
#

She : How much you can do for me?

#

He:I can own 10 account for wictory 🀣

#

Travix : My efforts for winning.Created 10 accounts but, just a bit late so only joins 7 accounts 🀣.

#

ThinkTwice : I'm lone wolf

#

πŸ˜‚πŸ˜‚

sonic atlas
#

why you guys use more than one account just play the game the way its ment to be played

steep agate
fossil helm
#

yeah we talked about that that guy a while ago lol

fossil helm
#

but he didnt

#

lol

fossil helm
#

@honest beacon

#

travis vs you lol

honest beacon
honest beacon
#

So should we start a campain for making gane better ?

#

like creating #koth-Campain etc

#

If everyone raise voice we wil won.

#

I just tried alone everytime reported them.mailed them.But, who cares

#

Anyone is with me ?

steep agate
#

And the summary of what some of the functions do

obsidian lark
steep agate
#

I talked to a few people, and for other players with common techniques, I think it would be cool to let others know what they are dealing with, even if they don't know how to create rootkits

obsidian lark
steep agate
#

Do you think I should delete the kernel object and just leave the txt?

obsidian lark
#

exactly u leaked his kit πŸ˜‚

obsidian lark
steep agate
#

sure

steep agate
obsidian lark
#

if everyone has lkms koth will be a game of speed

steep agate
#

This happens with other players too, in fact, it doesn't change anything

#

at least I'm trying to make the game more balanced, at least so other players know what they're dealing with and make their techniques stronger

obsidian lark
#

still players use basic tricks mostly, if everyone gets the power of lkms its no fun anymore

steep agate
#

well, I used LKM but mine was easily broken by many players

steep agate
obsidian lark
steep agate
#

well, players who use LKM are already at an advantage, so I don't see a problem balancing that

honest beacon
#

That's why i never use LKM's

obsidian lark
honest beacon
#

And I don't play KOTH

#

like that

steep agate
obsidian lark
#

i've spent months writing my kit for koth... and whats the point if someone else copies my code lol

honest beacon
steep agate
obsidian lark
honest beacon
#

but the point is that is LKM legal ? I think it's chitting.We don't have to change anything means removing or adding binaries except chattr.So how LKM's are legal for KOTH ?

obsidian lark
steep agate
honest beacon
steep agate
#

Yes, but the rules don't say they are prohibited, that's the point

steep agate
honest beacon
#

No it shouldn't be allowed in my openion

steep agate
#

That's why koth is only for intermediate level players and above

#

not for beginners

obsidian lark
#

lol fr

steep agate
#

I mean, for you to play Koth your account needs to be as an intermediary

honest beacon
steep agate
#

Yes, I also agree with that, creating a rootkit is difficult even for those who know C

#

That's why I thought it would be cool to at least show what the rootkit does, so other players know what they're dealing with, to make it more balanced.

honest beacon
#

But, if rootkit is not allowed.Then the game will be more interactive.

steep agate
#

it will definitely be more interactive, the point I want to make is that it is not in the rules that it is prohibited, but on the other hand, playing against good players like ch1, and others who have rootkits is good because you can research and understand more

#

search for other sides of breaking a rootkit, @broken pilot is one of them, the guy breaks rootkits out there 🀣

#

Anyway, I think that's it, at least to make it a little more balanced, giving at least the minimum chance against common players

broken pilot
#

Here's my perspective on this, lkm's are very op and they force you to learn something new. I enjoy the challenge of trying to figure out a way to bypass them manually. But I can also see the perspective of newer players also, it tends to be a little unfair if you spam every game with a lkm.... Sure use a lkm for experienced players, but there's really no need for a lkm when you could beat the player with a simple chattr lock... 59 mins king for most games played using a rootkit does not show skill, in fact I believe that if rootkits were disabled for newer machines then some players wouldn't be able to farm the wins anymore and actually make it a fair fight... It would actually make koth more fun if it was a fair fight. Sure in the wild there are no rules like what koth has in place and you would need to know how to protect against lkm's or at least know how to detect them. At some point hooking everything that could potentially bypass a lkm for KOTH could be a little unfair and players may resort to playing dirty or breaking the rules...

fossil helm
#

Damn i sleep about 24hrs

#

And i read it all

#

But ch1 is hard to defeat in speed

#

He setup everything just like 2 click and boom

gritty linden
fossil helm
steep agate
# gritty linden

Oh yes, ch1 I had dropped this LKM once in one of my last games on a machine to test if it worked, but in the end it just broke the machine so I left it aside πŸ˜„

steep agate
fossil helm
steep agate
fossil helm
#

He is just here reading

#

I call him mah G

gritty linden
#

thats how koth is really equalized

#

just plug your username there

fossil helm
#

Fr

#

Anyways i will still use what my source made because he explained it to me what i need to know

steep agate
#

Ch1 uses autopwn, every game he spends 59 minutes in the game, so if you enter before him, and disable module loading, he won't be able to beat you

fossil helm
#

And he is.....

#

@light flame

steep agate
#

arnout is good

#

i really like him

#

best ring3 rootkit dev

#

in my opinion

rare pelican
steep agate
#

Yes, it is so low that it uses autopwn to load modules πŸ˜„

#

not skill issue

rare pelican
steep agate
#

just skids

steep agate
#

@obsidian lark is good too making ring3 rootkits

rare pelican
#

all in one xd

steep agate
#

well, if you combine it with sshpass and add all the commands you can even

rare pelican
#

i also started my rootkit you already know XD @steep agate

steep agate
#

Oh nice!

rare pelican
#

but not that much good at hiding process

steep agate
#

I'm helping a friend of mine's snapekit to make it more stealthy

fossil helm
rare pelican
steep agate
#

Maybe I'll do some ring3 rootkit projects for Windows, although I've been really enjoying seeing content about BYOVD in the last few days

#

vulnerable driver

fossil helm
steep agate
#

ring3

#

From what I saw, it was incredible

steep agate
rare pelican
#

kekw got 600 points in only 21 min in a machine lol

rare pelican
fossil helm
steep agate
#

Windows is very good, I like it, exploring AD is very cool too

#

Speaking of AD, I'm getting ready for CRTP

rare pelican
steep agate
rare pelican
steep agate
#

sure

rare pelican
#

how my friend got an free thm premium wtf

fossil helm
steep agate
#

I really like it, I passed the CRTO using cobalt strike, full lateral movement, and common AD exploitation techniques

fossil helm
#

Took me 24hrs to that thm new K2

#

But i admit i read write ups started in middle camp

steep agate
#

bloodhound is very good, it's a shame that a red ops, or in real life, makes a lot of noise, the SOC will clearly notice, and will take away your access/network πŸ˜…

#

but it's cool to train and learn

#

about AD, you would learn a lot in vulnlab

near lily
#

This chat is veering off the channel topic...

steep agate
#

Oh, okay, sure

fossil helm
#

Anyways go back to KOTH

steep agate
#

Of course, well, my old code is there, I used it in my last game to see if it worked, but from what I remember some things were breaking, if you want feel free to study it πŸ˜„

#

The kernel object of ch1 is also there, just throw it into ghidra and analyze the functions although I made a summary

fossil helm
#

If you guys had rootkits already be sure you're fast as ch1 or else a lot of players also are fast

#

In the world of kung fu , speed determines the winner. - Bruce lee
New motto of KOTH

steep agate
#

to be more balanced, of course, if ch1 loads his rootkit 25 seconds after the game loads it gets a little complicated so you have to be faster and disable LKM loading using `sudo sysctl -w kernel.modules_disabled=1

`

rare pelican
steep agate
rare pelican
#

he just enter into the machine & waits for approx 3 sec then he become king

steep agate
#

this is not skill

rare pelican
fossil helm
#

But ch1 is still the winner

#

Lol

#

Imagine that how fast he is

steep agate
#

there must be a command ready or a curl for that ||"backdoor" on port 3000||

rare pelican
#

kekw he telled me his wpm

#

wpm 92 acc 99%

steep agate
#

Anyway, if you disable kernel module loading, it won't be able to beat you without LKM

civic vortex
steep agate
#

Sure

#

Nah bro, it's not bad, from what I saw in the print it's really cool

civic vortex
#

the hooking method is bad

#

will see how you do it

steep agate
#

It will be ok, bugs can be fixed

#

okay

#

I have a friend who is very good with ring3 rootkit for windows, he developed one a while ago

civic vortex
steep agate
#

Hummm, okay

#

using the Detours lib helps a lot too

civic vortex
#

ahh actually mine uses the Detours lib too

steep agate
#

Nice, this lib is very good

fossil helm
#

I only use your tutorials in windows and i add some ideas to maintain my presence in the king but still not enough to those knowledgeable in windows machine

fossil helm
#

you and @steep agate are both hero of other people here

#

for a long time they rant about it lmfao

#

but ch1 is faster than brucelee then goodluck to those who will use kekw

#

there are only 4 machines you can beat him but he is not playing there also

steep agate
steep agate
fossil helm
rare pelican
civic vortex
#

tbh If someone released a koth LKM source code so that everyone no matter the skill level can use it, people will just autopwn every games in order to be the first to iimplant lol, good job @gritty linden or whoever you really are

civic vortex
fossil helm
civic vortex
#

πŸ‘Œ

fossil helm
# civic vortex πŸ‘Œ

but idk lol maybe and maybe its not him he said he will be having 10 games a day starting tomorrow

#

but weekends he will grind

#

mah G will be busy in school

civic vortex
fossil helm
civic vortex
#

nah it's boring for me

fossil helm
civic vortex
#

the biggest joy is to look at logs, but not much experienced players are playing recently

fossil helm
civic vortex
#

so that I can log their IP, username and behaviors in my DB

gritty linden
# gritty linden

jokes aside this lkm works just plug your name there and compile it it didnt even compile before but it got fixed πŸ‘
it also still needs some hooks cuz its bypassable you can see whats missing from this other rootkit and implement it

steep agate
#

is he

civic vortex
steep agate
steep agate
# civic vortex <:catok:981545140617347082>

I had already given you the sample without the anti reversing trick, you must have already looked deeper into the ch1 rootkit, in fact, it cannot create one for the current kernel

steep agate
steep agate
#

By the way, you use this code as much as you want, I'll even help make it stronger, I really don't care about koth anymore, if I can help people I'd be happy πŸ˜„

civic vortex
#

πŸ‘Œ

honest beacon
#

we have to tell them to change rules like limiting games per day upto 10 or like that how much wr want and if someone us joining anothwr game then. It souuldn't add in another game untill that game is over.

near lily
honest beacon
#

it has been a month but nobody reply

broken pilot
fossil helm
lyric geode
#

It should be played how it was designed to be just sayin'

fossil helm
lyric geode
#

when a newbie tries, ofc they gonna look at writeups.

fossil helm
lyric geode
#

It's happening same like htb bg, slowly fading away to improve it.

#

It's game and game should be fair.

fossil helm
lyric geode
#

Tiers for the users might help

#

Easy - Hard

#

So OGs can have fun with rootkits while newbies can work around to learn KoTH structure.

fossil helm
#

Or remove all the old machines disable loading rootkits.

lyric geode
#

Well, a lot learnt writing rootkits but still bad for the person who just started playing for the first time.

fossil helm
#

There will be a lot of changes should be done thm should think the pros and cons to make that koth fair

lyric geode
#

So fixing KoTH right now is kinda of a hard side.

#

As community also pushing rooms on to platform for public, it makes a lot harder to manage Stuff.

steep agate
#

for business , it doesn’t make sense

lyric geode
#

It doesn't give both user and platform much, other then user having fun (which not really) and platform having user base for KoTH.

steep agate
#

yeah

lyric geode
#

It's just a "feature"

vague wadi
#

It shouldn’t be allowed to give everyone a fair chance and not give anyone an auto win button

honest beacon
fossil helm
#

If your forensic skills is not good as @civic vortex then goodluck looking for rootkits like ch1 is using, Bravo did not learn it in just a month. For those beginners like me who will play koth just enjoy looking for flags and practice exploiting the machine or avoid playing koth until THM will do something about it. Better to pawn those boxes in CTF category or do a THM path. blobfingerguns blobfingerguns

civic vortex
fossil helm
#

For now there's nothing we can do the koth is being played in that way.

#

How to play
Join a lobby with up to 10 players
When everyone is ready, you'll get a machines IP address
Enumerate and hack into the machine
Add your TryHackMe username to /root/king.txt
Patch the machines vulnerabilities to maintain your access
The longer you're king, the more points you get
Hunt for flags around the system for extra points
After 60 minutes, the game ends

#

Rules
To prevent cheating and ensure this game is realistic, everyone must the follow the rules:

The machine should not be made unavailable (shutdown/reboot, firewall/iptables rules to stop all communication, all services terminated, machine botching etc).
Only stop a service if it can't be patched any other way. Services should remain available for β€œgenuine users of the box” if at all possible. Changing ports of services is allowed. (Try to keep the machines in as original state as possible.)
No modifying/removing flags or their permissions (if any flag is everyone readable, it should be left like that).
Do not attack, modify or stop the service(king/KoTH service) on 9999 (this includes a 'KoTH' binary placed by default in /root and things like changing service locations.)
Any sort of DoS against the machine.
No attacking other users (you have no reason to attempt any recon on any IP other than the one given to you on the game page).
Scripts that automatically hack(autopwns) and/or harden the machine are forbidden.
Do NOT delete system binaries (except chattr) or change executable permissions on them (or their directory).
Using alt/dummy accounts to control resets is not allowed.
Resets should only be used if the target has been broken or otherwise rendered unusable; resets shouldn't be used to prevent users from gaining access.
If one vulnerability is patch then don't spam resets, there are 4-5 methods to gain foothold in every machine.
Games are moderated, and failure to abide by the rules will result in a game and/or site ban.

steep agate
fossil helm
#

sheesh xD

steep agate
steep agate
near lily
fossil helm
fossil helm
#

If anyone of you who are willing to answer his curiosity NotLikeThis

lyric geode
#

πŸ‘€

steep agate
rare pelican
inland falcon
#

Question: I have stable connection in the beginning, but once a player gains acces to king.txt I start getting distruptions to my ssh connection (freezes). Is this not against the rules (blocking user with firewall or some other method)? πŸ€”

steep agate
inland falcon
fossil helm
fossil helm
near lily
fossil helm
fossil helm
#

related to koth

steep agate
#

but it could be at THM too, a room like that would be cool, I don't think there is one

fossil helm
honest beacon
steep agate
#

Most of what I see is just teaching how to use rkhunter and chkrootkit lol

honest beacon
sonic atlas
#

this ch1 guy never gives anyone a chance

fossil helm
#

You can play now i told him to sleep 😴 πŸ˜…

rare pelican
obsidian lark
steep agate
obsidian lark
steep agate
#

oh, okay i see now

obsidian lark
civic vortex
rare pelican
fossil helm
#

I have his picture

rare pelican
#

nah i havent

#

send me privately

fossil helm
#

I will send it here anyway

rare pelican
#

nag dont leak

fossil helm
#

I will leak

rare pelican
rare pelican
#

πŸ˜‚

frank oracle
#

cannot seem to join @hasty harness

#

can you reshare the link ?

plush jetty
#

Aww now I"m verified -- I didn't know how to get in here

fast galleon
#

You can find Ch1 in this group.
#koth-voice-chat

Ask him what tools he use in KOTH.
He was active till August.

steep agate
plush jetty
#

How we doing?

steep agate
#

just use sudo sysctl -w kernel.modules_disabled=1 very fast

frank oracle
#

oh we sucked lmao

steep agate
frank oracle
#

I

#

Need. Practice.

plush jetty
#

Potato, I used ms17_010_psexec on 445

fast galleon
steep agate
#

yeah

#

it does all this in a matter of 10 seconds or 20 as soon as the machine starts up, so you guys will really have to be the flash 🀣

frank oracle
#

Got credentials, didnt knew where i can spray them

plush jetty
#

I'm going to go out and try that way -- I am not as familiar with using LDAP

frank oracle
#

I need to read my ejpt material again sheesh

plush jetty
#

I'm taking it on Tuesday

#

hehe

frank oracle
#

Goodlucj

#

it will be fun !

fast galleon
plush jetty
#

Thanks! I'm nervous haha

steep agate
fast galleon
steep agate
fast galleon
plush jetty
frank oracle
#

No machine timed out

#

I would need to brush through the basics again, because omg

plush jetty
#

Who is Ch1?

#

He set the King almost immediately and I can't find anyway to modify the king.txt file -_-

fast galleon
steep agate
plush jetty
# steep agate

I'm not seasoned enough 😦 Am I able to stop this next time without tools like rhunter and chkrootkit?

steep agate
plush jetty
sour vectorBOT
#

Gave +1 Rep to @steep agate (current: #117 - 63)

steep agate
fossil helm
#

It's THM's fault and they didn't do anything on it

fossil helm
#

In koth only.

#

Do it as fast as you can 3 seconds 😁

#

If you cannot do that you have no chance against him in 6 machines

fossil helm
#

Just read the github of @steep agate a lot of tips there for koth that may lead you to win in koth

#

WITHOUT ch1 lill

#

Lol

#

And w/o @obsidian lark and @civic vortex πŸ˜…

fast galleon
fossil helm
fossil helm
gritty linden
#

still need some hooks but you can work with it

#

also some hooks there need to be fixed

swift laurel
#

@steep agate we need that rootkit room already buddy! I have a feeling it would be fire

stable wing
#

@swift laurel you are killing me mate
πŸ˜„

swift laurel
stable wing
#

this is exiting πŸ˜„

#

this was my 1st koth πŸ˜„

#

i did good right?

swift laurel
#

you sure did! Got king and everything. Doesn't get any better!

stable wing
#

πŸ˜„
I will be back. πŸ˜…

#

btw how did you kick me out?

swift laurel
#

I just killed your process when I noticed you robbed me of king lol

stable wing
#

and you changed the passwords. NotLikeThis

swift laurel
#

I removed the pub key from authorized_keys but didnt changed any password

stable wing
#

thanks for the explanation. πŸ™‚
learned a lot

swift laurel
#

my pleasure

stable wing
#

DM?

swift laurel
#

Feel free to do so!

violet zealot
#

But if ch1 does load his rootkit 10 seconds after machine starts, then he basically use autopwn?

#

There is no machine that he can root in 10 seconds, the fastest machine to root is Tyler if I remember well because it's basically rce and oneliner privesc

fossil helm
#

THM just said the machines has 3-4 vulns

obsidian lark
violet zealot
violet zealot
fossil helm
violet zealot
violet zealot
#

But we are not talking about ports lol, I did all thm machines and exploited every vulns that they had, I remember which box was the fastest to access or root

#

So like I said, either he's using autopwn or boxes changed (or a recent exploit can root them all, like regreSSHion but I don't think so)

fossil helm
#

he is weak in 4 machines but idk if that is the term maybe if he will learn that 4 machines he will surely also win there

stable wing
#

i am relatively new to CTF and cyber security.
I just played KOTH and people seem to root the machine pretty quickly. while i am struggling to get a foothold.

is it just pure skill and practice or are there any tools/scripts? πŸ€”

civic vortex
#

After that, if you take good notes, you can just copy paste from your snippets

Because you dont want to do the same thing over again (Except copy pasting)

At this stage, the main thing to focus on is the techniques to defend king and remain persistence

civic vortex
#

Some people just copy commands from others' writeup and spam rootkits written by others without knowing how it works, which means they gain nothing but hollowness

stable wing
#

Thanks @civic vortex for the clarification. πŸ™‚
i was really puzzled how fast some players captured the king.
now, i know that I have to practice more.

sour vectorBOT
#

Gave +1 Rep to @civic vortex (current: #460 - 11)

civic vortex
#

Another guy who is breaking the rule lol

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

#

nvm he doesnt know the rules : V, but looking at rules is a must before doing anything in real life tho

fossil helm
#

Imagine doing that with @civic vortex in the line up

#

πŸ˜†

stable wing
#

😞

fossil helm
#

I keep researching, also i spent 1 week solving all the box before

#

The h1hard really gave me hardtime until now i can root it but it takes me time

stable wing
#

practice and research

fossil helm
#

I realized after all the loose the clue is just right in front of me reading the how to play

#

Same as other here im really pissed off to ch1 before

civic vortex
fossil helm
#

Imagine you doin enumeration then someone is the king already and you cannot do anything about it.

stable wing
#

i was playing the previous machine. suddenly machine returns 403 error. πŸ˜„

fossil helm
#

I talked to ch1 he also experienced same as us before wayback matheuz and others are playing. Until he did some steps to improved his playing lmfao πŸ˜‚ i can say he is not using autopawns or what but idk maybe who knows.
As far as i know he is just preparing everything

fossil helm
fossil helm
stable wing
#

i was able to capture the king in "production"
and I commented
#skidy ALL=(root) SETENV:NOPASSWD: /usr/bin/git *, /usr/bin/chattr

so other players can not gain root access as I did. thats not against the rules. right? πŸ˜„

fair adder
#

how do we get the solutions for the koth we played?

near lily
#

There is some "writeups" around github.

#

Nothing official from THM, as where would the fun in that be?

plush jetty
nova tide
true valve
#

Anybody up for KOTH?

#

no? That's fine.

split sable
#

I wanna start trying out KOTH what rooms should I do to get an idea of what to do after scanning the targets

#

Other than the obvious metasploit rooms, I’m looking for more techniques

true valve
fossil helm
#

im waiting for you to get the king. i am @civic vortex 2.0

#

jk lol

civic vortex
#

call me matheuz 2.0

fossil helm
true valve
#

good game

split sable
sour vectorBOT
#

Gave +1 Rep to @true valve (current: #696 - 6)

civic vortex
fossil helm
#

Im so poor in forensics im trying to read some articles from mtz's dc

obsidian lark
fossil helm
#

The heck this channel been hide

#

@civic vortex revenge time NotLikeThis

rare pelican
steep agate
swift laurel
sour vectorBOT
#

Gave +1 Rep to @steep agate (current: #118 - 64)

steep agate
steep agate
fossil helm
#

no rootkit okay pradayun for the win!

fossil helm
civic vortex
fossil helm
civic vortex
fossil helm
#

the kernel parameters defined in the specified configuration file will be applied immediately without requiring a reboot

#

@civic vortex did you just put Moetez name right?

fossil helm
#

w/o sudo sysctl -p

#

can still load rootkit

#

if im not mistaken

civic vortex
#

i tried it before, and it does block rootkit loading

fossil helm
#

i had this 4 lol

#

sudo sysctl -w kernel.modules_disabled=1
sudo sysctl -w kernel.randomize_va_space=2
sysctl kernel.ftrace_enabled=0
sudo sysctl -p

#

i just added ftrace when i read mtz article lol

fossil helm
#

others should execute these as fast as they can if they don't want their opponents to load rootkits

#

as far as i played koth i can say in current koth players there is no one using autopawns

#

at first i accused ch1 before but i found at that mah g is just preparing everything but yeah he uses rootkit lol

#

but not autopawn

ancient cliff
#

anyone wanna private koth without rootkit? the only defense rule is: only patch the flaws to get in

#

like "chill"

fossil helm
#

come hop into public

#

no one will use rootkit

ancient cliff
#

but you (?)

fossil helm
#

i will show you when im in the root that i executed these

fossil helm
#

or if youre the first

#

just do it

fossil helm
#

i didnt patch

#

im letting you in

fossil helm
#

nice g sir see ya later im gonna finish redteaming path before subs end in 31 lol

ancient cliff
#

lol

#

wp

#

im too slow 🐌

fossil helm
#

i slipt 2 times in the root part so i thought you were there already πŸ˜…

ancient cliff
#

its my 3rd koth, i dont know the box yet

#

you got root in 5 min

#

you guys dont even enumerate, you already know creds

fossil helm
fossil helm
#

Somehow it took me 1week to figure out h1hard machine

#

And i practice it lol

#

If thm will rebirth the koth then enumeration is the key again

ancient cliff
#

from my experience i know its possible to automate the process of creating vm with differents creds and (vulnerable)services... i know its possible but i have no clue how hard is it to implement that into koth

#

for now, if i want to try hard, i just have to copy paste all the writeups for the known rooms, and just speed run a rootkit into it

#

right ?

fossil helm
#

How you get in doesn't matter anymore

#

The clue is right on our face

light flame
ancient cliff
fossil helm
# fossil helm

My first 1st week in thm koth i was like enumerating and doing some hakkaman stuff on my keyboard i just figured out how to play it. That was also what the others and the retired players was doing.

ancient cliff
#

wp, i'll stick on solo learning for now, im too slow for thoses shenanigans blobheart

#

Maybe one day i'll tryhard koth

fossil helm
#

If you read the past messages here you see a lot of brucelee memes πŸ˜‚

#

@rare pelican πŸ˜†

fossil helm
# fossil helm

But still the essence if the game is to make you learn these advance stuff also in forensic side

#

My defense a while ago was just easy to @civic vortex

#

He always kick my ass also @obsidian lark

#

They had good forensic skills

ancient cliff
#

yeah i wish to learn that wisdom πŸ˜„

#

that why we all here after all

fossil helm
steep agate
#

Lucky for those who have already had the chance to play against those who use rootkits, and use this to their advantage to learn more about malware, forensics, etc.

fossil helm
#

Need to solidify the forensics and defensive in the king

#

If you play koth with the experienced players and you do enumeration etc nah you'll lose because they will jump straight in the king.
Now in the king is the real battle.

fossil helm
#

I did like this in my first days in koth because i feel like im super hakkaman but i always lose why i got many flags πŸ˜† later did i know that the video is 1yr ago and the new meta of playing is not that anymore πŸ˜†

#

#pentesting #ctf #hacking #metasploit #kalilinux #tryhackme #kingofthehill

Hey what’s up? In this video series, I tell the story of my first King of the Hill challenge on try hack me (koth).

πŸš€ πŸ”₯ Become a pentester
https://academy.thehackerish.com/p/from-zero-to-signing-your-first-ethical-hacker-job?utm_source=social&utm_medium=youtube&utm_ca...

β–Ά Play video
astral cargo
fossil helm
astral cargo
#

lmfao

#

yeah

fossil helm
#

sorry i just practicing to use it its for @civic vortex but he is so stealthy he is hard to find inside the machine 😭

civic vortex
fossil helm
rare pelican
fossil helm
rare pelican
sonic belfry
fossil helm
#

after the countdown of 1 minute before it starts

#

for 1 minute need to refresh 10x

steep agate
fossil helm
#

now still the same

steep agate
#

didn't start yesterday

fossil helm
steep agate
#

other players have already sent some reports about bugs in koth, and usually nothing happens

steep agate
fossil helm
#

the late comers will be able to join lol

#

because of that

#

you can leave also but you can still go back to the lobby like 1min

steep agate
steep agate
# fossil helm you mean by this? lol
                      ,____
                      |---.\
              ___     |    `                  __.....__
             / .-\  ./=                        .'         ':,
            |  |"|_/\/|                    /  __  _  __  \\
            ;  |-;| /_|                    | |_)) || |_))||
           / \_| |/ \ |                    | | \\ || |   ||       w00t w00t!@!@!@!
          /      \/\( |                    |             ||   _,
          |   /  |` ) |                   |  Sysadmin   ||.-(_{}
          /   \ _/    |                       |   DEAD      |/    `
         /--._/  \    |                 \\|       {}_)-,||
         `/|)    |    /                 \\;/,,;;;;;;;,\\|//,
           /     |   |                .;;;;;;;;;;;;;;;;,
         .'      |   |               \,;;;;;;;;;;;;;;;;,//
        /         \  |              \\;;;;;;;;;;;;;;;;,//
       (_.-.__.__./  /             ,\';;;;;;;;;;;;;;;;'
    ```
#

Nooo, the ascii was buggy here

stiff egret
astral cargo
astral cargo
#

it was another CTF

fossil helm
#

@mossy hearth

#

i saw what you did there but anyways good game

rare pelican
tough plover
#

can anyone hop on koth?

#

had a round with 4 people last night and someone disbabled ssh πŸ’€

#

still won cause that locked everyone out of the box and no one else voted for a reset

fossil helm
#

@civic vortex we are in the wrong channel lmfao

fossil helm
#

upon my forensic invistigation i found myself dumb cri kekw

#

it must be some super userland been used there? hmmm

fossil helm
civic vortex
#

nah

rare pelican
#

https://tryhackme.com/r/p/HckN1L this mf removes all the binaries from the machine

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

#

he is mf

#

kid

fossil helm
#

give them win so they will not do that lol

rare pelican
violet zealot
#

funny to see that nothing changed vent

fossil helm
#

@rare pelican come 2 games

civic vortex
#

He should put what he is capable of in koth in his profile too lol

fossil helm
civic vortex
fossil helm
#

He suddenly dmed me this πŸ₯²

#

I waited for him in spacejam 2 mins

#

The next game i didn't give him the chance lol

#

More than a year playing koth and was beamed many times by a 1 month old player

#

@rare pelican is a 15 yr old boy. He just said to a 15 yr old that he is playing koth for fun idk which of them are more mature in thinking lol

#

He is just afraid or dont want to lose the game. I lost so many times i just accepted it and didnt do any stupid things inside the machine.

civic vortex
#

Every time i lose, I make sure i take notes of how to fix the issue next time

#

that's what learning is

civic vortex
rare pelican
rare pelican
#

lol

rare pelican
#

revenge is revenge

fossil helm
#

@rare pelican

rare pelican
fallen palm
#

Imagine when someone loose and votes to reset the machine lol

#

Thatswhy koth isn't fun anymore.

rare pelican
#

kekw bro lol

fossil helm
#

That two pakistan flag

#

Same owner accnt spamming reset

rare pelican
#

hehe still i am the king

#

they are skid

fossil helm
#

Thm should limit the 1 reset per player only

rare pelican
#

lol

fossil helm
rare pelican
#

they just reset

fossil helm
#

No if you dethroned him in the king that is when he play stupid

rare pelican
#

lol but why do we care

#

game is game

#

fun is fun

fossil helm
rare pelican
#

just chill & learn

#

simple

fossil helm
#

Game is game and many cried lol

rare pelican
#

bcz they dont even bothr to try

frank oracle
#

ou someone rn in game?

fossil helm
marsh cobalt
#

Guys just a question for koth, how can I become king because I had most points And some other guy was king with less point

stiff egret
obsidian lark
#

Mr.Holmes, You have to get access to put your name in king.text, correct?

light flame
obsidian lark
#

Thanks Mr.Holmes

obsidian lark
#

Thinktwice how did you get the flags?

fossil helm
#

flag.txt root.txt user.txt just find it

fossil helm
# obsidian lark Thinktwice how did you get the flags?

You need to have root access so you can find flags in other directories. Also there are 1 command to execute to have flags just search for what command is that. Some machines you can find flags on the website itself , in mysql etc.
In windows it just a 1 command you can have all flags already.

obsidian lark
#

Thinktwice, thanks for the info.

#

That all happends After you get initial access, initial access is my issue.

stiff egret
#

Challenge rooms*

obsidian lark
#

Mr,Homes, thank you for the advice.

winged grove
#

Hi !

short tusk
#

Probably consider how we word things, ey? @civic vortex
That message is not at all appropriate.

Please report all KoTH rule breakers to support@tryhackme.com and refrain from calling users names. This is your only warning, you may be removed if this happens again.

leaden basin
#

https://koth.guru/ Just in Case Someone Don't know!

F11snipe

Welcome to KoTH Guru! A fun companion app for King of the Hill on TryHackMe

fossil helm
#

Hello I'm late 🧐

steep agate
fossil helm
#

Srry if may sound rude but...

#

I guess thm should also practice answer some email/s

#

I did just skipped the most important part of red teaming the ad section because of the broken network

#

The reset has been spammed by other room that is same network with AD section

#

That is why players are more preferred rant here in dc more than in emails cuz the staffs are active here

#

If i report this guy on email will thm do an action to this?

#

Luckily just had 5 players he cannot do shit on resets

#

I gave them time to do the king so they will not complain.

velvet vapor
#

Bruhh whats the entry point for Hogwarts challenge its impossible not getting anywhere near

stiff egret
#

Incase you're aware about the Hogwarts castle Stairs in Harry Potter not needed for this, just side info.
The ports and services juggle. You might want to do through scans before you start testing.
I recommend rustscan to get ports and then do a -sCV to check what's running where.

fossil helm
#

He maybe referring to this match

#

I didn't change creds i just let them in cuz im testing some alternative defense in hogwarts

stiff egret
opaque gull
#

im here :p

twilit pawn
#

Thinktwice did you use mount in space jam?

fossil helm
twilit pawn
#

How did you do it? Can you teach me?

fossil helm
#

Are you surprised that i bypassed you 😁

#

My time was short cuz im reading web funda path a while ago lol

opaque gull
#

its fun to play with @fossil helm and @leaden basin , sometimes they let me to take the king but later they stole it easily lol

#

steal it from me*

twilit pawn
opaque gull
#

we need to learn how to bypass

twilit pawn
#

Yeah I didn't even know what to do

fossil helm
#

We're the same im new also.

spice mason
#

@fossil helm what did you do the the filesystem lol

spice mason
steep agate
#

umount -l /root/king.txt

spice mason
spice mason
steep agate
spice mason
steep agate
#

mount |grep proc

#

probably some script using while to mount (btw, this can end up breaking the machine on some occasions)

spice mason
#

Also you're MatheuZSecurity right? found your github through all this madness lol. great resource

sour vectorBOT
#

Gave +1 Rep to @spice mason (current: #2357 - 1)

fossil helm
#

It is just a 3 line command

#

I just found it in other players while looking at what they do then i just add something

civic coral
#

i just like placing some funni sliver implants and hide away after chattr'ing king

#

maybe some tty trolling sometimes

fossil helm
# twilit pawn Yeaaa

I did it also to glutto. I dont know what he is using it's some loop that is my first time to see

steep agate
civic coral
#

not hiding with mount, usually playing around with funni ttps i see in the wild

civic coral
#

nope, rootkits feel like (and probably are) cheating in koth

steep agate
#

because these are the two best known ways

#

you can try to do something like enter in ssh without tty, but even then you are easily discovered

civic coral
#

and to be fair most of what i see on the linux side at work is just RW deployment and exfil KEKW but have seen some silly persistence

fossil helm
#

But you cant do that to ch1 lol

#

Is like he is advance in 1 min lol

steep agate
#

It's a shame that practically the best players I've ever played against stopped playing, btw, it gets tiring at some point hehe

steep agate
civic coral
#

as a blue teamer I do want to do koth more just always forget

steep agate
#

hide this process

#

Furthermore, I have never seen anyone on Koth who could hide 100%, even from the userland, even in the "real world".

civic coral
#

hiding processes is fun, though i prefer beaconing services and have an idea for some .so hijacking shenanigans

steep agate
civic coral
#

true, still fun though echidsmile

light flame
opaque gull
#

now im playing with someone on production machine. everytime i be the king he reset the machine

#

is that legal ? game has 2 players only he did reset more than 2 times

obsidian lark
opaque gull
#

Artisan73

fossil helm
honest beacon
spice mason
#

bro closed ssh...

#

@honest beacon

honest beacon
#

nah bro

#

just change port

honest beacon
honest beacon
opaque gull
civic vortex
civic vortex
near lily
fossil helm
#

Damn i about to play but i saw the history and Mah G is there

#

Wait imma let him sleep so we can play lmfao 🀣

#

I got 10+ people dmed me on how to defend the king what did I do

#

Im so kind so i answered them all with @steep agate github on how to play koth as a start the rest is their own research