#koth

1 messages ยท Page 12 of 1

light flame
#

And you keep the rootkit for yourself haha๐Ÿ˜‚

civic vortex
#

yup ive played koth for 1+ year, reported some players but only got replied by bots too
But i don't think it's because they don't care, it's just that mod resources are limited, they need to focus on other places

steep agate
#

sup

fossil helm
civic vortex
civic vortex
fossil helm
#

Nay or Yay?
Nay lol

civic vortex
#

๐Ÿ‘Œ

fossil helm
#

Salute to the fallen soldier @opaque gull that being cooked by Ch1 now

#

Lmfao

light flame
#

๐Ÿซก

civic vortex
#

we call those players "rookie killer" in games

opaque gull
#

bruh, i cant finish h1 easy medium hard

civic vortex
#

ive played many games until i solve them

#

first time

opaque gull
#

ill watch some videos

fossil helm
#

Also serv1 and 2

#

3 ways just pick

opaque gull
opaque gull
#

sorry im really bad, i need to watch videos lol

fossil helm
#

If you played with that Gladiuz i forgot his user God rank

#

Dont do ssh useless find another exploit lol

#

I forgot to screenshot ssh was error something "dangerous" thing lol i encountered him twice

rare pelican
steep agate
#

h1 medium

#

h1 medium is really cool, I don't know who created this box, but it's good

#

there should be more AD machines, that would be cool

opaque gull
sour vectorBOT
#

Gave +1 Rep to @steep agate (current: #115 - 65)

opaque gull
#

i just need now to learn hard, lion machines, also food, theres still good videos on youtube

#

offically im addicted now to KOTH

steep agate
opaque gull
#

private with friends same you skills would be more fun

#

your*

steep agate
opaque gull
#

good luck with that

steep agate
fossil helm
#

Im planning to make youtube on it but not now lol maybe next month

fossil helm
fossil helm
#

Just let them sleep we need to be good first in koth before they go back and play koth lol

opaque gull
fossil helm
opaque gull
light flame
#

I've beaten people with much higher levels in KOTH

#

easily

fossil helm
fossil helm
light flame
#

*of my rootkit

fossil helm
#

Unless you're in my threath list ๐Ÿ˜‚

broken pilot
opaque gull
#

any tips for h1 hard machine ? i tried to search on youtube but very long video

rare pelican
velvet vapor
#

Is this even possible?
Sum of first hacked time and remaining time is greater than 1 hr

jagged willow
#

@fossil helm

#

help

#

I am trying to do SQL injection in admin/login.php but its not working

#

how did you log in as admin?

fossil helm
jagged willow
#

Thanks

honest beacon
#

sorry @civic vortex just reseted mistakenly ๐Ÿ˜…

sleek tundra
#

Do games usually expire as soon as they're scheduled to start?

ember raft
#

Yeah, You have to wait a bit to get machine IP

sleek tundra
#

That was a little weird ๐Ÿ˜‚ okay thanks for letting me know

#

I think I saw you in one of the lobbies

ember raft
#

I wanted to play it after a long time but I guess I will not enjoy it

sleek tundra
#

Oh good it started

rare pelican
#

again i found a guy using ur kingkit @light flame

fossil helm
#

Damn tryhackme lol

#

Im about to finish their pentest path with just 3% unfinish in web fundamentals

fossil helm
#

Now suddenly added web app pentesting

fossil helm
# rare pelican sad

Yeah i guess i will be having more days and time doing pentest path + playing koth lol

leaden basin
#

Ya it's been a long time since playing so trying diff rootkit and also didn't care much about obfuscate stringing.

#

And what are new techniques going nowadays like i know the syscall one, interact is the one mount think.

#

@fossil helm you have ch1 rootkit sample ? Or know what he uses I just don't know about his rootkit ?

fossil helm
#

I forgot to save jt

#

It

#

Try to scroll up you will see it

fossil helm
leaden basin
#

No worries i ask matheuz

fossil helm
leaden basin
#

i use to have f11snip's king rootkit that the og one

fossil helm
#

Maybe i will cry a lot ๐Ÿ˜†

#

I used to cried on ch1 rootkit month ago bro lol but now how koth works its all about advance techniques and forensics also you need to be fast

leaden basin
#

I talked to him; he will be back soon.

leaden basin
rare pelican
remote rain
#

@honest beacon

hot perch
#

is this normal on koth games?

chattr -i
Command Executed
___
.'o O'-._
/ O o_.-| /O_.-' O | | o o .-
jgs |o O_.-'
'--`

No cheese strats!

civic vortex
fossil helm
fossil helm
#

Just delete chattr and use your own lol

hot perch
#

So i have to copy it to the /usr/bin folder?

#

Just that?

stiff egret
# hot perch Just that?

its an executable binary, you can run it from anywhere. Why put it in path where everyone can use it

stiff egret
hot perch
hot perch
#

@fossil helm is the machine not working or smth?

#

i'm foint

stiff egret
remote rain
#

anyone playing koth?

fossil helm
#

But i encountered that to that Gladiuz username twice.
God rank. in fireworks and food machine so i know i will not use ssh if that guy appears again.

fossil helm
#

@fallen palm man

#

I understand that you want to win but patch the machine only

#

Not deleting the domain lol

#

Now i will not give you a chance to step in the machine the next game i see your username ๐Ÿ˜‚

#

@fallen palm

#

Reset for what?

#

Didn't change creds or patch

#

Come inside

remote rain
#

lets play koth

frank oracle
leaden basin
#

Talking about other platforms in chat or voice chat might get you banned be careful .

steep agate
#

I enjoy playing htb battlegrounds, server siege or cyber mayhem

frank oracle
#

The game started 3 minutes ago... bro how are you king already?

#

@stiff egret - Might require your insights here ?

steep agate
# frank oracle

Get root on the machine as quickly as possible and run this sudo sysctl -w kernel.modules_disabled=1

frank oracle
#

lmao this guy closed all ports.

steep agate
#

His rootkit makes a hook in sysctl, i think

#

if you try to load another LKM after it loads your own, you will not be able to use insmod for example, to load lkm

frank oracle
#

My guy

#

this person, got root literally 3 mins in game.

steep agate
frank oracle
#

it was.

steep agate
#

it gets root about 8 or 5 seconds after the machine starts

steep agate
frank oracle
#

ok

steep agate
# frank oracle ok

If you use common resources like chattr, chmod, etc., you won't win this match or you won't become king

#

already notified in advance

frank oracle
#

Are you in my game?

steep agate
frank oracle
#

ok. So you dont know whats happening in my game.

#

So maybe just - let me ask staff about whats up

steep agate
#

You are a new player, you have a lot to learn

frank oracle
#

I am definately not.

steep agate
#

strange, I never played against you

#

I mean, if you were a slightly older player you would know

steep agate
#

this is one of the things that happens when you play with a player that also uses a rootkit

#

if you don't know

#

anyway, good luck xD

fossil helm
fossil helm
#

๐Ÿ˜‚

fossil helm
steep agate
#

I was trying to explain this to @frank oracle but he wanted to be ignorant to someone who knows more than him, lol

fossil helm
#

@frank oracle is that you Rodrous?

steep agate
steep agate
fossil helm
#

Takes me a week to analyze it to my brain how koth works ๐Ÿคฃ

fossil helm
steep agate
#

You don't even need to compile it inside the machine, as it has already compiled the rootkit, so just be quick and load it

fossil helm
fossil helm
sour vectorBOT
#

Gave +1 Rep to @steep agate (current: #112 - 66)

steep agate
#

Anyway, I don't intend to play koth again, I think I already said this here once, but only when I have new machines or f11snipe does a live stream

fossil helm
fossil helm
steep agate
#

I think most of the players I played with stopped playing too

fossil helm
steep agate
#

yeah

fallen palm
#

@knotty mica I uploaded a easy boot2root room few weeks back on thm, how can i collaborate that room with you guys and make it public or something..??

near lily
fallen palm
#

How much time it usually takes to be approved.?

near lily
#

As long as it takes, usually.

fallen palm
#

๐Ÿซ 

#

That's my first room,so no idea about the publication time

steep agate
steep agate
#

and on hackthebox it took about 6 months for my box to be released

steep agate
#

yea

fallen palm
#

I see

#

You wanna try my room.?

#

It's pretty easy though

steep agate
#

You will have to be very patient until it is released

steep agate
fallen palm
steep agate
#

nice

fallen palm
steep agate
rare pelican
#

you will get the flag if you bypass first rootkit user space user.txt second root.txt after lkm

#

best for beginners to learn abt rootkits

#

blobfingerguns created by me

fossil helm
#

ldd /_/

rare pelican
#

no for lkm hehe

#

ldd not works for lkm

#

ldd used to list dependcies

#

try my room bro

#

there is intresting vuln. in web also

fossil helm
#

It works on user.txt

rare pelican
#

see code

rare pelican
#

try room u will get to know abt php filter chain

fossil helm
#

just transferred my vms and linux in my pc been doing thm in an old hdd laptop for about 3months that lagged always oftentimes hinders me in koth and thm paths lol

#

@rare pelican i feel the power surging in my hands been so long didnt use the pc lmfao

rare pelican
#

nice

#

why these people spamming reset alot

fossil helm
rare pelican
#

skids

rare pelican
#

NotLikeThis he be like

fossil helm
#

how to retrieve my 76 streaks lol
i did just rest like 1day and half damn
fr

rare pelican
#

i also used to do this alot lol XD

fossil helm
rare pelican
#

got to support page

near lily
rare pelican
#

type of you will get a small circle in dashboard were u have to click to contact for streak recovery

near lily
#

Ah, it's the same thing, if staff don't answer it, it gets E-mailed anyway

rare pelican
#

it works bro i tried many times when i lost my streaks XD

near lily
#

No worries sister, I know it works.

wise blade
jagged willow
#

@fossil helm

#

how do you get points without flags

#

your graph keeps increasing (more than 6 times)

#

and also what is becoming king?

wise blade
# jagged willow how do you get points without flags

You gain points when you're King, I think every minute or so you gain some points. Becoming king is where you add your TryHackMe username in the /root directory, there is a file called king and you insert your name there.

fossil helm
#

good start to learn koth the rest is your own research keep learning

jagged willow
bitter agate
#

anyone koth ??

sour swallow
#

There is also an FAQ at the bottom of the page

bitter agate
#

I scan ip but which ?

broken pilot
jagged willow
#

@broken pilot

#

how?

broken pilot
#

edit the motd

jagged willow
#

did you use the bash exploit to elevate privileges

jagged willow
broken pilot
#

message of the day

broken pilot
jagged willow
broken pilot
broken pilot
jagged willow
broken pilot
#

id

jagged willow
#

how do you even disable that?

broken pilot
#

type id whats the output

jagged willow
broken pilot
jagged willow
#

thats what I was doing

#

the suid is blocked

broken pilot
#

/bin/bash -p

jagged willow
#

thanks

#

im king!!!

broken pilot
#

i just did a chattr lock on king

odd quiver
#

@fossil helm ay u the guy who was on top this month on koth

#

im ur biggest fan

#

will u become my mentor? wut

fossil helm
fossil helm
#

This might help you as a beginner guide

whole crystal
odd quiver
odd quiver
#

@fossil helm please help me with john

#

its not working!!!

fossil helm
#

@odd quiver you need to do xwiki to get into foothold

faint heath
#

Can someone please mentor me in koth I'm new

#

I'm very willing to learn anything

#

I do 100+ events per day

#

(Sometimes)

nova tide
#

@alpine quarry Refer to the following in order to send a message in this channel ^

#

Also for any koth related queries you may check the pinned messages like the following

fossil helm
#

I am thrilled to see blackdevil playing it's my firstime to see him play so im excited

#

but that idiot just ruined the game shutting it down lmfao

#

1 min king time

#

@nova tide he is been doing it since the day he played koth lol

#

Ik that can be disable shutdown reset poweroff command inside the machine but there are machines that it will not work

#

now he suddenly disappeared and didnt join the next game lol

#

He maybe filled with joy and partying announcing it to his neighbors kekw

#

my bruh used autopawn in food just to shutdown machine kekw

broken pilot
fossil helm
#

its just that i didnt expect it a while ago

#

because im waiting for devil

fossil helm
#

i even won against ch1 because of him bc ik he will shutdown the machine so expecting all will reset and it would be a good race to ch1

fossil helm
fossil helm
#

@leaden basin reset and bait me

#

i aint gonna buy that lol

#

good night guys im tired

broken pilot
#

See all the new active players and organize a big tournament soon.

fossil helm
broken pilot
# fossil helm team vs team?

We can try this... I was speaking to f11 and matheuz about this before and I think I know a way we can achieve this and make it fair for both teams.

fossil helm
broken pilot
#

The thing is one team would need to start a private match with their team mates and the "host"... Maybe 5-10 minutes to patch then we release the IP to the other team and how they score would be to put the "host" name as king .... Whoever has less time with the host name as king would win since they defended their machine the best ๐Ÿคท๐Ÿผโ€โ™‚๏ธ or maybe the other way around I don't know yet I'll have to think about it more

#

That way both teams could have a random machine, not know which machine they were Targeting, have to do some enumeration to know which machine they are playing etc... will make it a little bit harder.

#

We would need a host / referee that would be in both games I think f11 would be up for being the ref ๐Ÿคท๐Ÿผโ€โ™‚๏ธ i will talk with him soon and see if he would be interested in streaming this as well

fossil helm
broken pilot
fossil helm
broken pilot
#

We may even do another tournament but with no rootkits ๐Ÿ˜‰ make it fair for everyone playing, gives everyone a chance to win

fossil helm
broken pilot
fossil helm
broken pilot
broken pilot
#

After awhile it gets boring playing against ppl that can't beat you... Sure you rack up points but you are no longer learning

broken pilot
fossil helm
broken pilot
#

I'm also partly responsible for ch1's rootkit being so strong because I helped him find those bypasses so he could fix the holes

broken pilot
fossil helm
#

sudo lessecho USERNAME > /root/king.txt
sudo dd if=/dev/zero of=/dev/shm/root_f bs=1000 count=100
sudo mkfs.ext3 /dev/shm/root_f
sudo mkdir /dev/shm/sqashfs
sudo mount -o loop /dev/shm/root_f /dev/shm/sqashfs/
sudo chmod -R 777 /dev/shm/sqashfs/
sudo lessecho USERNAME > /dev/shm/sqashfs/king.txt
sudo mount -o ro,remount /dev/shm/sqashfs
sudo mount -o bind /dev/shm/sqashfs/king.txt /root/king.txt
sudo rm -rf /dev/shm/root_f

#

i bypass his rootkit

#

but they reseted the machine

#

after that he patched his rootkit lol

#

that time i dont have any idea who ch1 is

#

and he is using rootkit

#

i dont have idea i just follow what i read from mtz lmfao

broken pilot
broken pilot
fossil helm
#

i tried to experiment a own defense but @rare pelican just managed to bypassed it i thought it was already good because i used it frequently and win a lot lol he just saw what i did there i just pointing it in a folder and fire a loop lmfao

timber vale
fossil helm
#

@light flame

fossil helm
timber vale
broken pilot
#

@timber vale ๐Ÿ˜ข

#

๐Ÿคฃ, we WILL play again....

#

@fossil helm let me try to bypass the kit you are using, jump in one of these games

#
fossil helm
#

Mostly i dont use rk

#

I just used it when i know someone has it and in the lobby also

#

Or someone that i know has good forensic

broken pilot
#

i want you to use it though so i can see if i can beat it

fossil helm
#

My ch1 memories before when i cried a lot ๐Ÿคฃ๐Ÿฅฒ

fossil helm
#

Does anyone here bother to make yt video in H1hard machine.
I noticed that a lot of players can't get foothold or root access to that machine.
I'm planning to make by this month after i finish this thm pentest/red paths.
I will do the same to the only 1 write up of h1hard machine that i found.
Xxe inject & docker container escape.

rare pelican
fossil helm
#

Or you will just let me? Since it is my first yt vid i wonder what it looks like lol ๐Ÿ˜†

lavish brook
#

Hey Thinktwice...

#

Hello KOTH players,
I Am facing a problem, as a root user i tried chattr, chmod, umount...echo taking input but not reflecting in king.txt

I am a noob in koth game.

#

I want to learn..
Please refer something, so that i can learn

fossil helm
lavish brook
#

If someone change port, how can I find the that port again?

fossil helm
lavish brook
#

Not found anything interesting

#

Oh you are king in this server

#

Where i am playing

#

Hey teach me how can i enter

#

@fossil helm

fossil helm
#

Machine has been reset you can now proceed

lavish brook
#

Hey KOTH pro players,
when someone run while loop for king.txt, how can I break it?

broken pilot
light rampart
#

Hi guys i am new in koth

#

How to win against @timber vale he is not giving any chance to other players

fossil helm
#

For now don't play to win, play to learn explore the 13 machines take good notes

prime hull
#

Hello! So my skills aren't quite well yet, and I wanted to ask should I try to play koth without much skills, or I gotta have solid understanding of things?

#

The thing is, I have never played koth before, and to be honest I don't even know what it is about, can't seem to find tutorial videos or something

violet zealot
violet zealot
lavish brook
#

Hello KOTH player,
can anyone explain what it means?
sudo: PERM_ROOT: setresuid(0, -1, -1): Operation not permitted

light flame
broken pilot
prime hull
#

Thanks you all for answering - @broken pilot , @violet zealot !

sour vectorBOT
#

Gave +1 Rep to @broken pilot (current: #82 - 89)

prime hull
#

I am going to check on those videosupvote

civic vortex
#

Write your ssh public key to the user's .ssh/authorized_keys, then connect with SSH to get proper shell

#

Example scenario :

broken pilot
#

If KOTH ever comes out of beta we could really use a in game chat for the players who are not in the discord server... So we could at least tell them to reset the machine when it does this..

broken pilot
sonic belfry
sour vectorBOT
#

Gave +1 Rep to @broken pilot (current: #82 - 90)

fossil helm
versed tiger
#

hi

stiff egret
#

Hi

copper lion
#

hey guys, i was wondedring if loading LKM or eBPF programs, after being root, was allowed ?

light flame
#

And quite some players already use rootkits.

steep agate
#

I mean, if you want to load LKM, you'll have to be quick, because @timber vale rootkit also intercepts the use of sysctl/insmod so it's as if your LKM was sent to /dev/null

steep agate
versed tiger
#

3 players obviously know all flows and hack every machine within 1min

#

ah ok i didn't catch earlier i can play alone in private room...

#

anyway thx

#

no it doesn't work...

#

Status: Completed
(Insufficient Players)

fossil helm
#

I'm almost done in thm pentester path 61% to their new path web pentest. While doing koth ๐Ÿ˜…

versed tiger
#

competing w no competition

fossil helm
#

I wonder if Offensive sec path is still relevant at this year?

#

I saw some rooms are 2 yrs ago

#

I want to learn basic and fundamentals from their platform before i move to other platform

fossil helm
broken pilot
timber vale
fair adder
broken pilot
#

Thing is, I'm not creating rootkits to bypass rootkits... I'm doing it manually attacking the logic behind the rootkits... So once you realize what commands I'm running then you just hook those and I find something else ๐Ÿ˜œ

fossil helm
broken pilot
broken pilot
#

But these other ones I'm still holding on to haven't been yet...

broken pilot
fossil helm
#

Like alias ln=

broken pilot
#

Well I mean some players might complain, I guess it all depends on who you are playing against

broken pilot
fossil helm
#

by encountering that i learned on their techniques

broken pilot
broken pilot
fossil helm
# broken pilot No no no lol I'm taking my spot back soon ๐Ÿคฃ

Anyone can take my spot also i feel like i dont deserve that ๐Ÿคฃ
If OG's and other good players are active doing koth then they can just beamed me on that spot. I dont have plans also to replace bravo ik how skilled he is so i dont deserve to be in 4th also ๐Ÿ˜†

#

It's just that i have time doing koth these past months next year will be lessen like play a few in sat sun only ๐Ÿ˜†

broken pilot
fossil helm
broken pilot
#

It makes it more fun when you have multiple players able to get on the machine at the same time....

#

If not then you are just wasting hours playing by yourself lol...

fossil helm
#

I just echoed my user w/o defense then leave ๐Ÿฅฒ๐Ÿ˜…

#

@broken pilot i know you can just beamed me in linux but in windows if we had a chance to play in same match in windows can you test my defense there

broken pilot
fossil helm
#

Hopefully they will add more windows in koth add 3 so that will be 15 machines ๐Ÿ˜

broken pilot
#

I mean I know some things in windows but I'm more comfortable with Linux..

fossil helm
broken pilot
broken pilot
# steep agate ad is life

I've been waiting for you to show me some tricks bro ๐Ÿ˜‚. I keep putting it off from learning... I think I'm going to make it my mission for 2025 to become good at windows lol.

#

Especially since the majority of companies use windows and AD.. I can do some basic stuff but not fast at all ๐Ÿ˜‚. I've been learning a little powershell here and there, need to create some good notes though

steep agate
fossil helm
broken pilot
fossil helm
# steep agate ad is life

I also learned that AD are used by the 90%+ of large corps, companies, orgs ๐Ÿ˜ญ
I need to be a AD specialist ๐Ÿ˜†๐Ÿ”ฅ

broken pilot
fossil helm
steep agate
steep agate
#

Most of the time there will be some EDR solution

#

in machines

steep agate
#

I was talking to some people who have been working on this for a few days, it's really cool, they deal with a lot of malware for Linux, Yara rules, etc.

#

but there aren't many job openings, it's a very specific niche

steep agate
#

I recently took the CRTA, now I intend to try to take the CRTP

hoary mulch
#

Random 221321 you in here?

#

My attack box timed out ahha

hoary mulch
white breach
#

I had a bug with KOTH while playing with a friend, i got access to the VM and put my name in the file (forgot the name of the file) but it didn't give me any points and it was my friend who was gettings points

limber rune
#

this is why i don't hack anymore, too many sweats like dompriv

leaden basin
#

they don't know how to play fair

limber rune
#

lmao yeah

#

oh wow you have king

leaden basin
limber rune
#

oh what

#

damn

leaden basin
#

@limber rune

limber rune
#

oh ok

acoustic drum
#

nothing working for me ffs ha

limber rune
#

yeah same

leaden basin
#

vote reset

acoustic drum
#

done

leaden basin
#

still need 2 more

acoustic drum
#

make sure u beat him niko

leaden basin
#

if the box don't get reset i win anyway

acoustic drum
#

good ha

leaden basin
#

but its not about the win its about fair play

acoustic drum
#

nah thats right but at least he dont get the points

leaden basin
#

ya

opaque gull
#

why do you reset the machine everytime

opaque gull
steep agate
#

CRTA is so easy

opaque gull
#

just started with the lab

tight inlet
#

@faint path did the box just not work the entire 2nd half for you as well?

steep agate
fossil helm
steep agate
fossil helm
#

Thm went off ๐Ÿ“ด

fossil helm
#

That promo 10$?

#

I just want to open thm to put a flag in web pentest flag and sleep so my streak will stay but it's down

#

Alright its back

fossil helm
#

It's nice to see a lot of players are playing koth now

#

@timber vale just continue to be inactive ๐Ÿคฃ

#

@south pulsar

#

Why you leave

steep agate
fossil helm
#

I see cyberwarfare

steep agate
#

yeah

#

CyberWarfare

fossil helm
fossil helm
# steep agate yeah

Nah doesn't matter to that "industry recognize" the important is the knowledge that we will gain ๐Ÿ˜

#

Give me the coupon ๐Ÿ˜ญ๐Ÿคก

steep agate
fossil helm
#

@steep agate how many days you studied the course

steep agate
steep agate
#

I used one but apparently the other doesn't work

chrome bloom
#

hello everyone, nice to meet you. I was wondering if anyone had any problems with the production koth machine? When i use ftp to get id_rsa it just hangs. However, im able to get the other files like authorize_keys and flag.txt. Maybe im doing soemthing wrong? Any help is much appreciated!

#

i can see it says permission denied if using ftp -d "ip"

ruby osprey
opaque gull
#

and then asked me for the coupon

opaque gull
ruby osprey
fossil helm
#

Who else uses autopawns here

#

Lets play now

#

I will try to match your autopawns with just my bare hands

#

I had a list of usernames using autopawns

#

Why you guys are so desperate huh ๐Ÿ˜‚

fossil helm
radiant sun
stiff egret
fossil helm
#

Imagine they're already had shell and will just do root while other players are just on their way to get foothold it's clearly unfair

#

๐Ÿ˜‚

stiff egret
fossil helm
rare pelican
opaque gull
#

kinda boring when you use auto the machine, enless if you can break his defense lol, thats why i switch to ctf and study for certifications

fossil helm
# opaque gull kinda boring when you use auto the machine, enless if you can break his defense ...

Rootkit is not prohibited it's there already because there are ways to bypass it but using autopawns + lkm or userland ( ring3 ) is a greedy and a thirst for wins ๐Ÿ˜†
My first 2weeks playing koth i spent time to the machines enumerating it all reading a lot of write ups and koth tips and tricks. After that i found a formula on how to play it it's 456 ๐Ÿ˜‚
Luckily i found some people like @rare pelican and @light flame who helped me understand what lkm's and userland.
Also i read what matheuz put in his channel about rootkits.

fossil helm
#

I do koth as a side quest only im aiming all the red and pentest path of thm before i move to other platform

#

Koth is 24mins queue in the lobby and 1hr to play. Dont let that time consumed you if you got the king then move into another tab.
Or if there's a good player that you cannot bypass his defense then let it be.

hidden breach
#

My goat

honest beacon
#

can someone tell me what's problem here

#

name on king.txt is "khanakay" and on port 9999 it shows "amansaini"

violet zealot
#

went from a 100 to 10?

steep agate
#

or else he just left his nickname in king.txt and when you visited port 9999 he changed his nickname in king

fossil helm
#

Cant load rk or userland in hogwarts

steep agate
fossil helm
#

Nah idk since i usually used manual defense unless the opponent has rk or userland

#

I see the dir there is no other txt been added

steep agate
fossil helm
#

Redirecting traffic from port 9999

steep agate
#

I've played Hogwarts enough times to know this

fossil helm
#

Or he can just hide the original king and link it the user that he adds

#

You can still change the king.txt

#

But he will be still the king

steep agate
fossil helm
#

I didn't try such tricks in hogwarts since it's sensitive machine a lot of people handle that machine wrong

#

They throw some code lines of to def the king right away that cause error in the king and cannot create king anymore lol

#

I encounter a lot of that before when i just let them get the king first

steep agate
#

and then there was no space to create anything

fossil helm
steep agate
rare pelican
#

in hogwarts

fossil helm
rare pelican
fossil helm
fossil helm
fickle steppe
leaden basin
#

apon joinning koth public match

#

Can any staff member check this?

near lily
leaden basin
fair adder
#

does koth vc be any active?

#

i wonder

#

bruh my friend is pissing me off

#

we in a private game but he's deleting flags

#

๐Ÿ˜ก

#

bro wana play games ima bout to scrape his python http server

brazen sluice
mystic oxide
#

Hello

mystic oxide
#

Well then @fossil helm , are you tired? ๐Ÿ˜‰

fossil helm
#

@mystic oxide i will just make it 1001 and stop playing for a moment im just making bravo as my shield for those aiming top 5 will face him first ๐Ÿ˜†

rare pelican
#

happy to see him

mystic oxide
#

MDR devilxuser

rare pelican
mystic oxide
#

nice game

#

kit ?

#

what kit are you talking about?

rare pelican
#

TryFlagMe nothing bro

#

nvm good game with you

mystic oxide
#

yes

slate bramble
#

any spectate links ? ๐Ÿ˜„

mystic oxide
#

why not participate directly?

blazing hawk
#

@fossil helm bro why r u shutting the box services u shoudnt be doing so
in the worst case change the port dont shut them thats dirty play

#

Been working on this machine and man itโ€™s pretty annoying finding auto scripts and random tools left in the userโ€™s home directory

fossil helm
#

Im not the only player lol

#

What match is that

blazing hawk
#

the carnage one

#

nvm

#

private

fossil helm
#

Alright who are the other players

#

There are players there that has history of breaking rules

#

I will not tell it's up to you to find out

blazing hawk
#

absolutely snn it was a game we had fun

#

gg

fossil helm
#

After getting king i dont do silly things and proceed reading paths in webapp pentest

#

So i dont care that much in the machine on what's going on ๐Ÿฅฒ

#

Not until someone will dmed me so i will look at the history or processess

fossil helm
#

You can mention him here he cant deny i saw it a while ago i just let him do that lol

blazing hawk
#

No need mate

mystic oxide
#

lol @Jaydeep.Shirsath it cuts the ssh connection

crisp edge
mystic oxide
#

yes yes

crisp edge
#

I don't able to connect back

mystic oxide
#

normal look @fossil helm

crisp edge
#

@mystic oxide I got ssh port 65535

mystic oxide
fossil helm
#

Just move to other game already

#

Stop using resets w/o valid reasons

civic vortex
#

This is tryhackme lol

fossil helm
short oriole
#

Do i need VPN to access the koth?

mystic oxide
#

yes

near lily
rare pelican
#

it been a long minute of expiration

fossil helm
#

Advance Happy New Year my THM friends, KoTH players and Everyone! ๐ŸŽ‡๐ŸŽ†๐ŸŽ‰

#

Cheers ๐Ÿฅ‚๐Ÿท

fair adder
rare pelican
#

That's why currently I am not playing

fair adder
#

like is there something wrong with server or what?

rare pelican
#

Don't know

fair adder
#

Same I will also then play later

rare pelican
#

Max reset happen or not?

#

Still ip not came?

fair adder
#

nope I think other players are not even watching

rare pelican
#

One reset need

#

1/2

fair adder
#

I clicked but its saying "You have already requested for a reset"

rare pelican
#

U can only reset it one time one player

fair adder
#

I left, today KOTH is not working

leaden basin
#

Happy new year guys

verbal garden
#

why koth is not working?

#

is it only me, who's facing an issue?

fair adder
#

Happy new year Guysssss

fair adder
verbal garden
broken pilot
#

Happy new year

rare pelican
mystic oxide
#

Happy new year

fossil helm
#

After almost 4 months finally finished while playing koth ๐Ÿ˜†

#

Just a small rant to thm atleast add points to walkthroughs? Look if someone finishes those path they're still in Omni rank ๐Ÿ˜…

#

Also i have some ctf rooms not related to that paths

fossil helm
#

@short tusk

fossil helm
#

I mean if you finished those paths you should be atleast in

#

Wizzard rank

#

because the nose and the brain bleed is not that easy finishing those paths to someone a beginner like me kekw NotLikeThis

mystic oxide
fossil helm
fossil helm
fossil helm
# mystic oxide

I will also finish pentest+ and offsec since it was 45% and 71% after finishing that pentest paths.

fair adder
brittle flicker
#

Eheheh, this Koth guy seems popular :3

mystic oxide
#

yes

rare pelican
mystic oxide
rare pelican
#

no script

#

ask @fossil helm he knows me i dont use scripts to get root

#

i devlop that speed on my own not script dont blame me

mystic oxide
rare pelican
#

every player did that to save time

#

infact thinktwice bravo everyone alrdy save it to save time

mystic oxide
rare pelican
mystic oxide
mystic oxide
mystic oxide
rare pelican
mystic oxide
#

why are you trying to shutdown the machine?

#

316 shutdown

#

and make blocking rules in the firewall?

#

@rare pelican why : 250 ufw
251 iptables
252 iptables --show
253 iptables -h

rare pelican
#

ig maybe @fair adder

#

he is doing

#

i am not doing anything in the machine

fair adder
#

bro I am also not playing

rare pelican
#

i am in food

#

me too not playinh

fair adder
#

GHOST

mystic oxide
# fair adder GHOST

tryhackme rule number 1: The machine must not be made unavailable (shutdown/restart, firewall/iptables rules to stop all communication)

rare pelican
rare pelican
#

i am not in the machine tho

mystic oxide
fair adder
#

same here

rare pelican
#

lol

#

u checking ur own

mystic oxide
rare pelican
#

i didnt do ssomthing to iptables tho

mystic oxide
#

I don't even know how to use it

mystic oxide
rare pelican
mystic oxide
rare pelican
#

i am telling u again i didn't do anything

#

didnt touched the iptables thoo

mystic oxide
rare pelican
#

& ur checking ur own root history tho bro

mystic oxide
#

I'll come back later, good game

steep agate
#

๐Ÿ˜‚

#

Koth is funny

#

players do something wrong and then don't want to take the blame

leaden basin
#
 [BIN: /usr/sbin/service] service ssh stop 
 [BIN: /usr/bin/basename] basename /usr/sbin/service 
 [BIN: /usr/bin/basename] basename /usr/sbin/service 
 [BIN: /bin/systemctl] systemctl --quiet is-active multi-user.target 
 [BIN: /bin/sh] sh /bin/systemctl --quiet is-active multi-user.target 
 [BIN: /bin/sed] sed -ne s/\.socket\s*[a-z]*\s*$/.socket/p 
 [BIN: /bin/systemctl] systemctl list-unit-files --full --type=socket 
 [BIN: /bin/sh] sh /bin/systemctl list-unit-files --full --type=socket 
 [BIN: /usr/local/sbin/systemctl] systemctl stop ssh.service 
 [BIN: /usr/local/bin/systemctl] systemctl stop ssh.service 
 [BIN: /usr/sbin/systemctl] systemctl stop ssh.service 
 [BIN: /usr/bin/systemctl] systemctl stop ssh.service 
 [BIN: /sbin/systemctl] systemctl stop ssh.service 
 [BIN: /bin/systemctl] systemctl stop ssh.service 
 [BIN: /bin/sh] sh /bin/systemctl stop ssh.service

@mystic oxide you should not talk about rules first blame your self ๐Ÿคฃ

mystic oxide
#

??? lol I'm not even here

rare pelican
leaden basin
#

that have your name in ๐Ÿ˜‚

fair adder
rare pelican
trim patrol
#

New here. What can I do?

mystic oxide
fossil helm
#

What's the trouble here ๐Ÿ’€

#

Cant koth cant do thm rooms have a job maybe later lol

crisp edge
near lily
knotty micaBOT
#
TryHackMe's Email

TryHackMe's support email address.

leaden basin
#

15 min in the game and he reset like 8 times

rare pelican
#

In koth people reset for no reason ๐Ÿคฃ

magic oyster
#

There will be a game in 20 minutes, join us! It's going to be fun!

magic oyster
#

goodluck, fellows!

magic oyster
#

@fair adder nice game buddy

fair adder
#

Thx bro

magic oyster
#

gg

mystic oxide
#

@fossil helm nice game Offline

#

on the other hand on Production, your loop with chattr breaks the shell, so we can't do anything anymore

#

@fossil helm ha and you also deleted the entry for sh and bash, ha yes there it is sure that we can no longer do anything, it's a shame

fossil helm
mystic oxide
#

we can no longer access the box

fossil helm
#

someone just patched after killing shells lol

mystic oxide
#

in any case it seems to me that this is the very first time that I manage to finish a KOTH in front of you, but hey it was a windows box. In any case nice game

#

nice game on offline

#

but I still have to learn a lot under Linux, I'm not very good at the king under Linux, when you're there, well yes it's dead to win LOL

mystic oxide
sour vectorBOT
#

Gave +1 Rep to @fossil helm (current: #1030 - 4)

strange sigil
#

damn since when did koth get so tense lmao

mystic oxide
#

lol @fossil helm why all delete : [] Opening SVCManager on 10.10.146.61.....
[
] Stopping service gqKx.....
[] Removing service gqKx.....
[
] Removing file vOqiSOXH.exe.....

#

not cool even the 2 boxes before this one, you delete all access to the box, luckily we were able to reset the box so that @leaden basin passes in front of you because otherwise no one can play anymore.

mystic oxide
#

lol like???

fossil helm
#

what? lol

#

food?

#

didnt even play after getting king lol

#

you guys just reset and i didnt care lol

mystic oxide
#

why on Linux VMs do you cut all access to the box, so it's unplayable

fossil helm
#

someone just killed shell ik who did it lol

mystic oxide
#

yes normal there is only that to do, you block everything

fossil helm
mystic oxide
fossil helm
#

youre a legend rank and you dont know what youre talking

#

lmfao

mystic oxide
#

but it's not necessarily against you, but it's a shame that you play like that, you block all access to the box

fossil helm
#

ask it to niko lmfao

#

before you reset the box nikko got the king from me

#

you blind?

#

he kicked you all ol

#

lol

#

sometimes use the logic why you went into that thm rank bro kol

#

lol

mystic oxide
#

yes yes if we had not reset the box, we could not do anything, so yes with @leaden basin we reset the box.

fossil helm
#

i didnt play in 3 resets

mystic oxide
#

I'm just asking you why you block all access to the box once you enter it? It's just a question

leaden basin
#

@fossil helm lol fix your lkm breaking the machine blameing other is easy

fossil helm
#

kekw he accuse me

#

i dint even play

#

lmfao

#

after i been kicked in the machine

leaden basin
#

Lol then does't mean you will accuse other lol

fossil helm
#

its like he accuse anshul a while back

#

but he doesnt know what he is accusing

mystic oxide
#

we just see that when you play, 10 seconds later the box becomes inaccessible that's all

fossil helm
#

you played to me a while ago

#

did you see that? lol

mystic oxide
#

block services and change all passwords, I'm just saying it's not very cool that's all

fossil helm
#

he didnt change passs

#

lmfao

#

anyways its hard to explain to you dont know that

#

i am also the victim of that killing shell a while ago so i didnt play after that

#

@mystic oxide next time be careful mentioning someone here lmfao

mystic oxide
#

?

fossil helm
#

if you dont know what are you talking lmfao

mystic oxide
#

lmfao ?

fossil helm
#

lmfao

#

he cried

#

he said "block all access"

#

no need because shell already killed in loop kekw

steep agate
#

try using a different process name

#

and so someone who doesn't know anything about Linux won't be able to kill your pid

fossil helm
#

I can escape with that loop also

fossil helm
fossil helm
#

@mystic oxide hows the windows machine

#

i am asking in a nice way

mystic oxide
steep agate
#

Windows is cool, you can play a lot with ACL/Attributes of a file in koth, you can also make a ring3 rootkit for Windows

#

It would be nice to have an AD machine with ADCS (Certificate Services), can be predicted many people abusing certificates for persistence

fossil helm
mystic oxide
fossil helm
steep agate
#

most people who play windows machines in koth (that's when I played, I stopped playing last year), just used loops with attrib and icacls

#

what is easy to bypass

fossil helm
steep agate
#

serious? interesting

fossil helm
#

i have my own in h1medium but in offline im trying to figure it out

steep agate
#

I thought no one would see my repo anymore

mystic oxide
fossil helm
mystic oxide
sour vectorBOT
#

Gave +1 Rep to @steep agate (current: #112 - 68)

mystic oxide
#

and I still have a lot to learn, but a little bit every day, slowly but surely lol

steep agate
#

yeah

fossil helm
mystic oxide
mystic oxide
#

*icacls

fossil helm
#

i can unlock it but yeah its ok to be in that way 1min king lol

mystic oxide
#

just with attrib, no problem for the king

fossil helm
#

@mystic oxide i unlocked it

#

just try

steep agate
#
:loop
icacls "king.txt" /grant:r *S-1-1-0:F & attrib -r -s -h "king.txt"
goto loop
#

problem solved

mystic oxide
#

I'm not in the box anymore

sour vectorBOT
#

Gave +1 Rep to @steep agate (current: #111 - 69)

fossil helm
steep agate
#

for block write in king.txt in all users

#

the only problem is that this will literally lock king.txt, and therefore you will not earn points every 1 minute

fossil helm
#

yeah

mystic oxide
#

I use this command myself
icacls "C:\Users\Administrator\king-server\king.txt" /deny everyone:(W,D)

steep agate
#

btw, it's worth mentioning that running loops like this can slow down the machine, just as running loops in bash on Linux can also slow down the machine a little.

#

but I don't think there's anything that could harm other players, it's just something to know

mystic oxide
fossil helm
#

try it in h1medium now

mystic oxide
#

directly from the meterpreter

fossil helm
#

so no one can exploit the offline using msfconsole

mystic oxide
#

ok nice

fossil helm
#

but i just let you in

mystic oxide
#

ok thanks

fossil helm
#

anyways this is good room in offsec pent @mystic oxide