#koth

1 messages ยท Page 17 of 1

weary kindle
#

@somber dust what's the hostname of your current game box? I'm curious

somber dust
#

How do I go about finding it? :p

#

It just says thm-prod

#

Seems like a generic hostname

weary kindle
#

AH

#

You got mine then skidy

#

What's it like?

somber dust
#

Ah nice! You made the box?

#

Really enjoyed it

glossy vessel
#

GG @weary kindle

weary kindle
#

GG

glossy vessel
#

also, is killing someone's process considered attacking others?

weary kindle
#

No

glossy vessel
#

i did not do that, cuz was unsure

ember agate
#

is it ok to kill other players shells?

glossy vessel
#

alright

rigid raptor
#

just not attack their actual machines

terse willow
#

@ember agate yes

weary kindle
#

Any lobbies going?

terse willow
#

So long as you don't aim for their computer

rigid raptor
#

I'd like to join one, even if I expect to lose horribly :p

terse willow
#

Eh, I'll 1v1 pars later to test it out

ember agate
#

ok, thanks everyone for a game, i will take a break and try to build some notes

gusty cradle
#

Are we allowed to create crons that inserts the name into king.txt every minute?

ember agate
#

i think all is allowed except specified

terse willow
#

Yes, although watch out for giving people ideas ๐Ÿ˜›

ember agate
#

like fw rules and killing services

gusty cradle
#

I'm gonna go create a cron

ember agate
#

and i would keep all of these secret haha

weary kindle
#

I wanna get Prod

brazen cloud
#

How do we leave KOTH lobbies?

gusty cradle
#

Cron's done

#

@brazen cloud You dont

#

I joined mine by accident as well

brazen cloud
#

Joined dan's by accident thought it was a spectator link

mortal latch
#

same

terse willow
#

Well

#

Now you're getting thrashed ๐Ÿ˜†

rigid raptor
#

the link should probably have a confirm thing

brazen cloud
#

I can't set aside 45 mins

#

yikes

terse willow
#

You throw it in ideas @rigid raptor -- I'll copy it to submissions

void rivet
#

@weary kindle nice box

rigid raptor
#

I'll copy you to submissions, muriburi

brazen cloud
#

Have fun practicing @weary kindle

#

sorry lad my bad

rigid raptor
#

so it's just gonna be me and dan? lmao, by the time I get in, Dan'll be ready to kick me out

brazen cloud
#

I suppose

terse willow
#

Especially if he gets his own box...

weary kindle
#

@dapper escarp you up for it?

brazen cloud
#

I've taken a seat that I didn't want / cant

gusty cradle
mortal latch
#

:/

gusty cradle
#

Just 10 more minutes, go get user

#

Run gobuster, nmap and anything you can think of

mortal latch
#

i did it

gusty cradle
#

That's a spoiler

mortal latch
#

oh sry

gusty cradle
#

It's fine

meager cloak
#

Wanna really troll people: Set the start time of the room for as long as possible, then watch people drop into public games they have to wait hours for without the ability to leave them.

mortal latch
#

lul

torpid notch
#

you sir are evil

glass wave
#

is it okay to change passwords and ssh keys?

meager cloak
#

Yep

weary kindle
#

30 secs

void rivet
#

Ffs who set it to 1hr

weary kindle
#

3 more spots avail

rigid raptor
#

it's just gonna be you and me, dan. I fear for my life.

meager cloak
#

I'm in

rigid raptor
#

ooh nice

meager cloak
#

I warn you, I'm not gonna be actively getting root, just need ever-changin rooms to test and develop my new tool against

rigid raptor
#

lmao, dan is king already

void rivet
#

how tf

#

xD

weary kindle
#

I remember this box

void rivet
#

oof

#

im out of my depth here xD

gusty cradle
#

I won!

torpid notch
#

gg @gusty cradle

gusty cradle
#

Thanks!

void rivet
#

i was well out of my depth

#

nice malware

mortal latch
#

gg @gusty cradle

gusty cradle
#

Thanks!

mortal latch
#

:)

dapper escarp
#

Need to pull myself out of bed and jump on this

terse willow
#

Same ^^

#

Well, I need to pull myself out of bed and document some code, but wth ๐Ÿคทโ€โ™‚๏ธ

torpid notch
#

I just realized that I had found 2 flags already :/

meager cloak
#

I've suddenly realized a flaw with people just automating root after hitting boxes enough

torpid notch
#

I didn't know they had a different encoding

meager cloak
#

Perhaps implementing a way to randomize access points would be a good idea

#

ssh-keys / password / parameter changes on deployment

terse willow
#

^^

#

Stick that over in ideas. I'll put it into submissions

meager cloak
#
| /index.php source code:
|_SherlockSec
|_http-majordomo2-dir-traversal: ERROR: Script execution failed (use -d to debug)
|_http-passwd: ERROR: Script execution failed (use -d to debug)
| http-phpmyadmin-dir-traversal: 
|   VULNERABLE:
|   phpMyAdmin grab_globals.lib.php subform Parameter Traversal Local File Inclusion
|     State: UNKNOWN (unable to test)
|     IDs:  CVE:CVE-2005-3299
|       PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.
|       
|     Disclosure date: 2005-10-nil
|     Extra information:
|       ../../../../../etc/passwd :
|   SherlockSec
#

Something tells me ShelockSec is in there ๐Ÿ˜‚

void rivet
#

XD

torpid notch
#

he coming

void rivet
#

I quit after he got king in 1min

#

๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚

weary kindle
#

Port 3000 is juicy skidy

#

And now it's gone

vernal gust
meager cloak
#

Damn

weary kindle
#

@lusty portal can we have shorter waiting times for KOTH? Like a 5 minute wait option or something

#

15 mins is too long imo

lusty portal
#

Yeet, let me add that in

#

Im changing how public games are joined, as there are so many lobbies with just 1 user in it.

void rivet
#

can u make an option so we can leave a scheduled game aswell lol

lusty portal
#

Yes

ember agate
#

probabbly can add something like ready button where everyone can vote to start

void rivet
#

thanks

#

cause i keep joining games with sherlock and he gets king in like 5 mins xD he 2 gud 4 me

#

im a big scrub me

dapper escarp
#

hes taken notes on all box entry points

weary kindle
#

one more spot

ember agate
#

seems like you can go to his stream and just check what he is doing

#

and do the same :b

void rivet
#

but then thats just cheatin

#

but the rate hes gettin these flags hes definitley done this before

#

this box

#

haha

vernal gust
void rivet
#

this is why a leave function would be nice

ember agate
#

i played that box with him before

quiet schooner
#

"localhost:1337" dammit skidy

ember agate
#

first time he was like 10 times slower ๐Ÿ˜„

lusty portal
#

I maybe looking at other data whilst people are playing

#

Im adding a leave button now

void rivet
#

thanks

vernal gust
#

i'm a noob, so plz take it easy on me ;-;

lusty portal
#

Opinions on only allow 1 users to enter 1 lobby at a time?

weary kindle
#

Pls no

lusty portal
#

I've seen so many lobbies with 1 user in

ember agate
#

someone just have to get in to root and take his king off

weary kindle
#

Some of these boxes are done with so quickly

vernal gust
#

then you have dan autoscripting koths

ember agate
#

he is not hardening machine so there is still the same way in anyway

void rivet
#

guessin u have done this box before haha?

vernal gust
#

i'm just throwing it in haha

#

I haven't

#

didn't even look at the streams, so i'm a newb to the whole concept

weary kindle
#

I did this one about 30 mins ago

ember agate
#

and seems like i can take ip from his stream

vernal gust
#

i like it hard on me

weary kindle
#

Still fresh

lusty portal
#

and seems like i can take ip from his stream
@ember agate Its on the same network

#

So yeah you could

meager cloak
#

Damn son

#

Almost king

vernal gust
#

my kali box died

weary kindle
#

@quiet schooner is Food yours?

quiet schooner
#

@weary kindle ...why do you ask?

weary kindle
#

Tis' a good room

#

/ box

quiet schooner
#

โค๏ธ

lusty portal
#

Im changing how public rooms are made to make it easier for groups of people to join. New code push coming in 1 hour

ember agate
#

@weary kindle, did you delete charattr binary in 10.10.69.129?

weary kindle
#

No?

quiet schooner
#

@weary kindle I hope the evil bits weren't too evil

vernal gust
#

damn lol

#

4 flags in 10 minutes

ember agate
#

it randomly works not

quiet schooner
#

?

weary kindle
#

24 is my box

#

so

vernal gust
#

balanced

rugged pumice
#

๐Ÿ˜

#

ohh wow

quiet schooner
#

@weary kindle I'm interested how much of the box you've discovered

weary kindle
#

6/8 flags so far

quiet schooner
#

I'm interested more about which paths you took

rugged pumice
#

@weary kindle did you leave something open?

weary kindle
#

Which box

rugged pumice
#

24

weary kindle
#

Everything is still open

rugged pumice
#

what user did you use to log with SSH ;/

weary kindle
#

ashu

void rivet
#

i done htat box

#

got so close to getting king

#

then timer ran out

#

big oof

vernal gust
#

i think in need to get some understanding of key formats loool

ember agate
#

what players can do if someone just puts shile loop with a line that changes king.txt?

dapper escarp
#

kill the process

weary kindle
#

@lusty portal trying to join a public game results in a 404

ember agate
#

we can't because while will put it up again

dapper escarp
#

you kill the process it terminates

ember agate
#

i know what killall is

quiet schooner
#

man kill

terse willow
#

@ember agate not if you stop the program. Killing it does the same kinda thing as Ctrl + C

ember agate
#

i can't even kill parent bash

terse willow
#

But from another TTY

ember agate
#

there is no tty

dapper escarp
#

koth isn't a game mode we help with

#

the idea is independent research

quiet schooner
#

You can stop dan from winning, but you need to google harder

vernal gust
#

stahp killing my sessions

ember agate
#

and if parent for that while is games binary?

weary kindle
#

object Object

void rivet
#

O_o

lusty portal
#

How Sherlock? What steps?

weary kindle
#

I just went to games/koth

quiet schooner
#

@ember agate You need to do your own research

rigid raptor
#

object Object is my favorite band

ember agate
#

sorry for questioning here

terse willow
#

Hehe, remember that Koth is direct competition. We like helping with questions that can't be googled when it's a learning environment. Koth? Koth is war ๐Ÿ˜†

vernal gust
#

how to damn use vim

weary kindle
#

any games goin'?

vernal gust
#

how many flags are there?

#

4?

weary kindle
#

Hover over the flag icon

#

It'll tell you

vernal gust
#

oh, yeah. right

#

thanks for the room though

#

really good learning curve

weary kindle
#

tyty

#

Did you run chattr?

vernal gust
#

damn u

dapper escarp
#

๐Ÿ˜‚

vernal gust
#

and the koth script

#

killed my terminals

weary kindle
#

smh

#

Insufficient players

ember agate
#

we can try

lusty portal
#

Daymn

ember agate
#

which game are you in?

#

i don't want to open any game link because of that auto join ๐Ÿ˜„

#

if i will open wrong one i will have to play multiple ones at the same time

weary kindle
dapper escarp
turbid plaza
#

Public join @dapper escarp ?

dapper escarp
#

yeah

#

should join you in

weary kindle
#

@dapper escarp you hopping in vc?

dapper escarp
#

ready to get stomped by Dan as I imagine he's done the entire pool

weary kindle
#

I have

dapper escarp
#

just waiting for stream to start

turbid plaza
#

looks like Im gonna lose

dapper escarp
#

same tbh

#

Dan has home field advantage

flint oriole
#

Are there going to be koth games all day?

weary kindle
#

yes

flint oriole
#

Awesome.

quiet schooner
#

@flint oriole You can also start your own

flint oriole
#

I might have missed it but what's the user limit, if any?

quiet schooner
#

6 per session @flint oriole

flint oriole
#

oh

lusty portal
#

@weary kindle Dominating the recent game board, however looks like game 21 SuitGuy will win

dapper escarp
#

@lusty portal does the king service require sudo?

#

as I think I somehow broke it

lusty portal
#

Ooo

dapper escarp
#

by deleting sudoers

lusty portal
#

Which box?

#

oof

dapper escarp
#

shrek

lusty portal
#

I will investigate, just pushing some new KOTH changes

quiet schooner
#

My version of the king service shouldn't require sudo as it runs as a service

#

But that's a Zayotic one

lusty portal
#

@dapper escarp

#

You need your name as a capital

#

Otherwise it wont find you

dapper escarp
#

damn it

#

the bloody cap

#

when can I has lower case

lusty portal
#

sorry just saw that in my logs

#

And thought

#

Wait a sec

dapper escarp
#

lmao

#

I didn't even realise

lusty portal
#

username change coming soon:)

dapper escarp
#

pls papi I beg

#

I beg

quiet schooner
#

skidy please

#

just make him happy

#

robo3t that db and change it for him

lusty portal
#

Its done, just needs user input and limiting to changing once a month (and testing)

dapper escarp
#

You know you've hardened the box enough when you hear "Why is there a parrot"

turbid plaza
mellow bough
#

I was pinged?

neon sleet
#

My apologies

#

It was me

#

I didn't see you were streaming

mellow bough
#

oh you're good

#

I'm just chillin

neon sleet
#

Can I DM you, quick question.

#

Don't want to spoil it

mellow bough
#

about KOTH?

neon sleet
#

Yes

mellow bough
#

Maybe, it might be better to DM the individual box creators though lol

neon sleet
#

Who made Shrek?

mellow bough
#

Zay

neon sleet
#

Thank you

#

I'll speak with him later.

mellow bough
#

sounds good!

azure kite
#

@lusty portal is that you?

lusty portal
#

Sorry, I moved over to a dev environment now. Removed myself:)

meager cloak
ember agate
#

ooh, no

#

i joined randomly again

#

but seems like i was able to leave

lusty portal
#

@meager cloak Not sure if you're aware, but you're making a private lobby, if you join a public lobby, others will join organically ๐Ÿ™‚

#

And you can invite friends

rugged pumice
#

Hey Skidy, there should be an option that allows to ban players from joining so I can ban 'sherlock' ๐Ÿ™‚

meager cloak
#

I only have Create private game and Join public game

mellow bough
brazen cloud
#

can we make that site-wide thanks

dapper escarp
#

@mellow bough can you give us like 3 koth voice channels

low whale
#

are you playing 3 boxes at the same time LOL

dapper escarp
#

no

#

just spammed in vite

flint oriole
#

He's a god he can do it.

weary kindle
#

I was earlier tho

#

@lusty portal change the reset votes needed from 4 to 66%?

lusty portal
#

@lusty portal change the reset votes needed from 4 to 66%?
@weary kindle Ah yes, forgot about this. Will work on that early next week

dapper escarp
#

yeah 4 people to reset in a 4 person lobby ๐Ÿ˜‚

quiet schooner
#

Also how does that work with 1v1s?

lusty portal
#

^ Ah good shout

#

I didn't think of that

#

I might make the min of resets needed 2

dapper escarp
#

that's abusable

lusty portal
#

min number of resets needed 2 for 1v1;s

weary kindle
#

66% doesn't trigger in a 1v1 smh

lusty portal
#

e.g.
2 person lobby = 2 resets
3 person lobby = 2 resets
4 person lobby = 3 resets
5 person lobby = 3 resets
6 person lobby = 4 resets

mellow bough
#

I added two more voips

dapper escarp
#

Skidy is this game mode sub only?

quiet schooner
#

yes

dapper escarp
#

Seeing people without sub in a lobby

weary kindle
#

66% fixes this issue

quiet schooner
#

Interesting

dapper escarp
#

Might be a sub but because they haven't done any rooms it doesn't show the banner

lusty portal
#

Skidy is this game mode sub only?
@dapper escarp KoTH is sub-only yeah

#

Might be a sub but because they haven't done any rooms it doesn't show the banner
Huh?

#

Seeing people without sub in a lobby
@dapper escarp Wait

#

Wot

dapper escarp
#

!rank myalt

pearl gladeBOT
#
TryHackMe
!rank

The Matrix is real

Username:

myalt

Rank:

16611

Points:

0

Subscribed?

No!

dapper escarp
lusty portal
#

you know what I forgot to do

quiet schooner
#

lmao

lusty portal
#

Add the if statement to stop non-subscribers

dapper escarp
#

Well played Skidy

quiet schooner
#

f2p trial

lusty portal
#

Add the if statement to stop non-subscribers
@lusty portal nevermind, its there

#

But I see my issue

#

there are 2 ways to join

#

through invite link, and through the button

neon sleet
#

Can't connect

lusty portal
#

Well played Skidy
@dapper escarp Fixed, thank you for reporting that.

#

Opinions on showing the VM title along with the IP when games are played?

stark fox
#

Hi does the king of the hill is for everyone or subscribed users inly

mortal latch
#

subscribed

#

only

stark fox
#

Even the private rooms

mortal latch
#

i dont know but i think even private rooms

terse willow
#

Yes -- all Koth is subscriber only

stark fox
#

Oh okay

narrow parrot
#

do Koth game give xp?

terse willow
#

Ooh, good question

#

@lusty portal -- points for Koth?

lusty portal
#

Points for KOTH, but doesnt go towards your THM score:)

terse willow
#

Is that profile points, or just game poitns?

#

Ah, thanks ๐Ÿ˜„

#

So no, Koth games do not give points to your profile @narrow parrot

narrow parrot
#

okay thx โค๏ธ

brazen cloud
#

Opinions on showing the VM title along with the IP when games are played?
@lusty portal I'd vote no because in the long run, people cough can just associate vm titles and adjust accordingly before enumerating from the get-go

#

Imho I think it's best that as little information about the box is given in that regard

void rivet
#

@lusty portal yesss show VM titles

#

Would be good

quiet schooner
#

@brazen cloud or script the exploitation based on VM type

#

However, you can fingerprint which box it is with nmap

void rivet
#

Either way in the first 2 mins of doing a box u cna tell if its one u have done already

quiet schooner
#

if ports=this/that/theOther then box = shrek etc

void rivet
#

So might aswell

#

Add the title

brazen cloud
#

that's what how I meant

#

Yeah I mean it's trivial in that regard I suppose

#

what's the first two minutes in a 45 minute game I suppose

quiet schooner
#

There's 65535 ports that you can use

#

If you have 3 open ports, that's an insane number of possible open ports

fair adder
#

65535 ports on the box 65535 ports

#

You take one down

#

Scan it around

quiet schooner
#

Fingerprint easy

fair adder
#

65534 ports on the box

quiet schooner
#

paradox is now nmap

brazen cloud
#

"is" implies that he "wasn't"

fair adder
#

Yws

#

Yes

terse willow
#

Oof

#

Just had a horrible Koth box idea..

fair adder
#

All 65535 ports open? @terse willow

terse willow
#

Maybe...

fair adder
#

It's already a thing

terse willow
#

Damn

fair adder
#

A really evil idea is just to have everything done through udp

terse willow
#

Meh, I'll keep it for a normal box then

#

Ooh, that could be fun too

fair adder
#

No one gives a duck about udp

vagrant monolith
steep raptor
#

is there only one user flag

#

between more than one /home user?

quiet schooner
#

Why don't you find out?

steep raptor
#

reading the flag on spacejam /home user1 and user2

#

are the same

#

user.txt

#

@quiet schooner

quiet schooner
#

Ok?

steep raptor
#

I already did

#

was just wondering if it was a mistake or not

#

?

#

@quiet schooner

quiet schooner
#

I didn't create it

steep raptor
#

both user's have the same string

#

got it

vagrant monolith
#

1 spot left

dapper escarp
#

So the question is, who is meshal

meager cloak
#

Mr steal yo woman

vagrant monolith
#

Woooo optional you are keeping the castle locked tight

#

hahah

dapper escarp
#

Woooo optional you are keeping the castle locked tight
@vagrant monolith I saw you trying to drop your name using cmd=

vagrant monolith
#

You closed 3000?

dapper escarp
#

โค๏ธ

#

There are other ways in

#

@vagrant monolith There are other ways in, I just patched that one service

vagrant monolith
#

I'm coming ๐Ÿ˜‰

dapper escarp
#

gl

fair adder
#

optional man holly ... I can't get in. Nice job

dapper escarp
#

I'll apologise now aha

#

even if you did you'd have to change king which isn't easy :p

vagrant monolith
#

Yea great job

#

Seeing you've hide so many shells across the box now

#

haha

#

Learned a lot

#

This game mode is addicting af

dapper escarp
#

true

#

persistence is key ๐Ÿ˜„

#

did any of you experience a shell die?

fair adder
#

Yea I got in for some time but after a while I think you kicked me and yea I only got 2 flags. I am not that experienced but

vagrant monolith
#

I had that once at least

#

But I must've kicked you also once?

#

I did kick myself once as well, that was fun

fair adder
#

Nice

dapper escarp
#

Yeah I think my shell died and one of you kept removing my www webshell to get back in

keen vine
#

lets go boyss

#

3 min tell my first koth

turbid plaza
#

@fair adder espaรฑol?

mortal axle
#

Just played KOTH, It was awesome ๐Ÿ”ฅ

lusty portal
#

Who did you okay with?

vocal basin
#

Can't see a button to exit from a koth, bytw won my first koth. It was awesome

cunning mulch
#

Just had my first KOTH game as well, gotta say, its awesome, one of the most fun CTF types i have tried
Keep up the good work!

mortal axle
#

Who did you okay with?
@lusty portal with fellas I met through the "looking-for-group" channel ๐Ÿ™‚

lusty portal
#

Awesome:)

steep raptor
vernal gust
#

is that James' doing?

quiet schooner
#

Nope @vernal gust

#

But you played yourself @steep raptor

vernal gust
#

yup

dapper escarp
#

Lmao

#

That wall broadcast tho

full grove
#

so fun fact, theres an option to execute commands on ssh login

#

I highly suggest knocking .bashrc out

steep raptor
#

did you remove someones path @full grove

full grove
#

hm?

#

lmao thats not my doing

quiet schooner
#

@steep raptor no spoil

steep raptor
#

oh sorry

#

wanted to know if it was him

quiet schooner
#

Intentionally a pain in the ass

full grove
meager cloak
#

export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin should fix you issues

full grove
#

james you beautiful boy

steep raptor
#

just did export PATH=$PATH:/usr/bin

#

close enough

full grove
steep raptor
#

wp wp

meager cloak
#

Ayyy

full grove
#

well done on the box James

steep raptor
#

REEEEE your wall rick rool

full grove
#

ssh user@box -t "rm ~/.bashrc"

#

ez bypass

steep raptor
#

pepe energy to the maX

#

question the game has ended but the box is still active

dapper escarp
#

@lusty portal one of the games isn't showing in most recent

full grove
#

yeah, thats how it is for a bit

lusty portal
#

@lusty portal one of the games isn't showing in most recent
@dapper escarp It only based on certain conditions, .e.g. if just 1 person gets points, it wont

dapper escarp
#

or is most recent randomly selected?

#

oh ok that makes sense

#

in other words, I need to let someone take king.txt xfor a second

quiet schooner
#

@full grove Did you enjoy the box?

full grove
#

good box

quiet schooner
#

Any feedback, DM is open

full grove
#

i really need to start tearing the boxes apart after easy initial entry

#

kinda like shrek

dapper escarp
#

I Love shrek

#

James' your box is really nice tbh

full grove
#

i found how i could potentially gain entry as a different user with the ability to read files

dapper escarp
#

even if I only found one foothold

meager cloak
#

Shrek is a ballache

lusty portal
#

in other words, I need to let someone take king.txt xfor a second
@dapper escarp ahaha inb4 you change king.txt to someone elses username

dapper escarp
#

Oh damn

#

that's a shout

full grove
#

i gotta work on Windows KOTH tho

quiet schooner
#

Again, any feedback please DM

full grove
#

that might be up next

steep raptor
#

@full grove real talk need to work on my windows skills

full grove
#

i think i can bang it out in a few hours

#

im just tryna think if i wanna take the Mr Robot approach to it

quiet schooner
#

no life, tonnes of drugs?

meager cloak
#

^

#

Great suggestion

#

10/10 would recommend

quiet schooner
#

Stay safe, kids

steep raptor
#

so coffee

dapper escarp
#

coffcoaine

lusty portal
#

What do we think about the public games? I think some people are entering games and not playing (because it starts in 20 minutes). Was thinking of perhaps a ready up type system or something?

dapper escarp
#

That would be pretty sick

#

I've done a couple of public games and they have had two idle

lusty portal
#

I was thinking:

If 3 or more people are in a game (no time limit), they can ready up. If they fail to ready up, they get removed.

#

Something along those lines

turbid plaza
stable narwhal
#

@lusty portal That's some CSGO thinking

#

Ready-up feature would be good

lusty portal
#

Yeah, I think i tmight be the way to go

#

Just need to test which is the best way

quiet schooner
#

Damn game 69 has passed

#

@fair adder @terse willow what box did you get?

lusty portal
#

Damn game 69 has passed
@quiet schooner Game 1337 is going to be big ๐Ÿ™‚

quiet schooner
#

I give it 2 weeks

lusty portal
#

If people keep just creating private games and sit in it by themselves yeah syre

#

I plan on fixing that

fair adder
#

our record is 1-1 @terse willow

#

we settle this at high noon tommorow

terse willow
#

Yours @quiet schooner

#

And it is great

lusty portal
#

We already have 30 people for the competition for KoTH

terse willow
#

I've just thrashed pars with it ๐Ÿ˜†

keen vine
#

i was playing koth earlier but now its saying i have to be a subscriber im sslty

fair adder
#

pshhh

#

if I recall

#

I thrased you game 1

terse willow
#

You did...

#

Does this mean we're not allowed 1v1 @lusty portal?

#

Because honestly it's great fun

fair adder
#

if you dont allow 1v1's we riot

lusty portal
#

No I mean, people are sitting by themselves

#

Like just 1 user

fair adder
#

oh

terse willow
#

Uh...

lusty portal
#

With no-one

fair adder
#

yeah thats a no

terse willow
#

That doesn't seem fair

lusty portal
#

I made it so games dont start with 1 user in them

terse willow
#

Sounds good

fair adder
#

so high noon tommorow @terse willow

#

?

terse willow
#

Depends whether I get the rest of this code documented before 5AM ๐Ÿ˜†

#

But quite possibly

#

Who's noon?

fair adder
#

oh that was more of a showman thing

terse willow
#

Haha

fair adder
#

high noon showdown

#

you know

terse willow
#

This brick wall is still killing me by the way

#

I dislike it

fair adder
#

we can do it whenever tommorow

terse willow
#

I very dislike it

fair adder
#

yeah im notgonna use that in future games

#

it ruins the fun

terse willow
#

Literally sitting here killing off processes looking for it ๐Ÿ˜†

fair adder
#

its not running anymore ORacle

#

๐Ÿ˜

#

the process is already dead

terse willow
#

Oh, I promise you

#

The process is alive and well...

fair adder
#

then just

#

reboot the box

terse willow
#

Nah

#

I've got a workaround

#

Sitting with a fully fledged root shell

quiet schooner
#

@terse willow @fair adder plz dm feedback

fair adder
#

On the bix

#

Box

quiet schooner
#

I have an idea for a theme for the next one

vernal gust
#

shrektangular?

#

shreked republic?

fair adder
#

Shrek box was fun

vernal gust
#

i didn't do it yet :c

quiet schooner
#

Yes box feedback

fair adder
#

Although I didn't like the path I took

#

Whatever box this was, was also fine

quiet schooner
#

@fair adder was it food themed?

fair adder
#

It was bot

#

Not

#

Actually

#

Yes it was

steep raptor
#

whoops

#

sorry

#

wp wp @meager cloak

#

ok how does the king.txt work for points?

quiet schooner
#

Every minute, the content is checked

#

The king gets points

meager cloak
#

GG guy's

steep raptor
#

GG

turbid plaza
#

gg

neon sleet
#

gg

#

It was a battle of the while loops

#

and I lost

meager cloak
vocal basin
#

Gg

steep raptor
#

only if i was any better. GG @meager cloak

runic river
#

Is there a wait before you can play another koth or can you just keep going game to game ?

neon sleet
#

No wait, other than for the game to start.

dapper escarp
#

Anyone want to 1v1 on shrek?

turbid plaza
#

If you wanna loose ๐Ÿ˜›

dapper escarp
#

you wanna say that to my one liner that instantly gives root and hardens?

turbid plaza
#

โ˜น๏ธ

#

you wanna say that to my one liner that instantly gives root and hardens?
@dapper escarp Iโ€™ll try to make my own one

dapper escarp
#

gl son

#

I believe

turbid plaza
#

Thanks dad

full grove
#

@sharp stirrup rip shrek

fair adder
#

So if we play koth and get shrek

full grove
#

your child has been massacred

fair adder
#

I guess we just

#

Lose

turbid plaza
#

@dapper escarp nice man๐Ÿ˜Š

dapper escarp
#

I won't spoil the behind the scenes of that script

#

@lusty portal dad are you proud of me

full grove
#

dont give him ideas

lusty portal
#

Thats scary

dapper escarp
#

1.5 boxes autopwned so far

#

just need to get Dans and James

quiet schooner
#

I'm interested once you get it for Food

dapper escarp
#

have shrek running with arg passing now too

#

pog

fair adder
#

Gonna need mutliple games to get low priv on @sharp stirrup's new box

#

So @sharp stirrupjust wins

steep raptor
#

can you be apart of more than one KOTH at a single time

quiet schooner
#

Yes

torpid notch
#

I forgot that the game had started @steep raptor

steep raptor
#

oh sorry

#

removed something already

#

you want some help

#

@torpid notch ?

torpid notch
#

yea I did the same box last night and I still cant get any of the flags

rugged pumice
#

Sherlock plays 7 KOTHs at a time accessgranted

narrow parrot
#

How difficult are Koths? If you would rate them? easy?medium?hard?

fair adder
#

They're easy boxes

#

They have to be since you have to get root, get points as king, and defend the boxes in 45 minutes

narrow parrot
#

@fair adder Okay thanks for the fast reply โค๏ธ

fair adder
#

<3

steep raptor
#

already ready for new machines

#

have only done food,spacejack,and shrek

#

never gotten tryler or production yet

quiet schooner
#

@steep raptor Did you get user on food?

steep raptor
#

i think sow

rugged pumice
steep raptor
#

why they oh

#

whoops missed ya

#

can't believe they already scripted the answers

#

that was fast

quiet schooner
#

@rugged pumice Haven't seen this box before

rugged pumice
#

same ;/

steep raptor
#

ncie new box woot

#

oh the same thing

#

again

quiet schooner
#

I'm in a rabbit hole

steep raptor
#

REEEEEE

rugged pumice
#

w0w

steep raptor
#

owo

rugged pumice
#

staring at a screen for 50 minutes,
clueless ;/

fair adder
#

if you wanna run another one when that one is done im more than down

quiet schooner
#

@weary kindle you were explicitly told not to

#

so.

#

Can you not?

dapper escarp
#

James

weary kindle
#

Mate

dapper escarp
#

are you taking the piss?

weary kindle
#

I'm playing monopoly

dapper escarp
#

pull that rod out of your ass

#

real quick

weary kindle
#

I joined as a meme

full grove
#

can confirm

rugged pumice
#

wow, good job James ;d

mellow bough
#

Please be polite my guys โค๏ธ

rugged pumice
weary kindle
#

I didn't mean to click that one smh

#

monopoly

fair adder
rugged pumice
#

i hope it's not the same box NotLikeThis

quiet schooner
#

@rugged pumice Since I'm the creator of this one, I'm patching only

rugged pumice
#

you created this 1 ๐Ÿ˜ฎ

#

does the ''Ping'' button do anything?

terse willow
#

Can't really give hints in Koth ๐Ÿ˜„

#

Gotta figure that one out

dapper escarp
#

I'll dump my auto scripts the last week of rotation

terse willow
#

Oof

quiet schooner
#

@rugged pumice I'm patching the box

rugged pumice
#

gg

quiet schooner
#

GG

torpid notch
#

gg @fair adder

fair adder
#

gg wp

cinder blade
#

any one from india

#

i cant buy subscription ...

#

card denied msg pop up after submitting setalis

#

pls help

glossy vessel
#

@cinder blade might be worth emailing support@tryhackme.com with your problem

#

also make sure that your card supports international purchases

ember agate
#

morning

#

anyone will be playing today?

glossy vessel
#

everyone :)

dapper escarp
#

I'm likely to play a little later

#

might nap soon

ember agate
#

in what time zones do you live?

glossy vessel
#

mostly UK

dapper escarp
#

think the majority are either uk (BST) or America (mixed)

distant zealot
#

in KOTH i must waiting someone join ?

glossy vessel
#

in public games, yes

#

if you create a private one, you have to share the link to it

distant zealot
#

i see , then if counter down competition not start while some one join right ?

glossy vessel
#

there must be >1 person to start

#

so 1 v 1 are possible

distant zealot
#

i see and when 1v1 start no any new user can join ?

glossy vessel
#

if the game is private and you send a link to someone

distant zealot
#

i mean in public

glossy vessel
#

then obviously only this person will have access to join

#

public games can be joined by anyone in a certain time frame (preparation time)

vagrant monolith
vagrant monolith
#

wow, fifth flag

#

love this game mode

#

lol - 7th, flags everywhere

lusty portal
#

love this game mode
@vagrant monolith amazing:)

#

To make public games better, what do we think about having public game start times longer, unless 2 or more people ready up?

ember agate
#

maybe you could make a ready button for admins so they can start a games without a timer

vagrant monolith
#

To make public games better, what do we think about having public game start times longer, unless 2 or more people ready up?
@lusty portal and when all ready reveal the ip

#

Yea

gusty cradle
#

Can we modify iptable rules?

turbid plaza
#

no I think

lusty portal
#

I guess, as along as the services are not effected and its not a stupid rule such as blocking every connection apart from your active one.

rugged pumice
weary kindle
#

I feel attacked

#

I don't even have autopwn

#

Haven't had the chance to make my scripts yet

rugged pumice
#

but you can get King without scanning ๐Ÿ˜‰

weary kindle
#

not true

dapper escarp
#

How about instead of making a ban list. You make better scripts

#

As not gunna lie itโ€™s obnoxious seeing a big banned users thing

vernal gust
#

what's the fun in autopwn

terse willow
#

@dapper escarp In fairness, that script of yours for Shrek is lethal. Only way you're beating that is by making a more efficient one and I shouldn't think that's really the point of Koth ๐Ÿ˜†
Although the ban list doesn't really sit right, I agree

dapper escarp
#

I made the script as a challenge to myself

#

I donโ€™t use it

turbid plaza
#

Anyone up for a game?

terse willow
#

Well that's fine then isn't it? No point in banning at all then, is there

dapper escarp
#

Ah fyi I used to make htb autopwns but stopped. So the fact I have the chance to make some now makes me happy

turbid plaza
#

๐Ÿ™‚

dapper escarp
#

The only box id even consider running a pwn script on is Tyler as I have no clue how to get to root so would need to extra time

terse willow
#

@dapper escarp It's something I want to try, frankly. Gotta love some scripting. A one liner to automatically root a box just makes me so happy ๐Ÿ˜†

#

Although I would agree that doing it for anything other than the challenge is a low blow

#

Unless it's a 1v1 against @neon sleet -- then it's fair game ๐Ÿ˜›

dapper escarp
#

The script doesnโ€™t harden

#

It just gives a persistent path to root, so itโ€™s not as unfair as people think

#

There will still be other ways up

#

Gotta work on the harden script now

terse willow
#

Fair. That's another thing I really gotta learn

#

Oh, thanks for the reminder

#

Need to go find the wall binary

neon sleet
#

I have to play a few more times to get a feel for the multiple entry points.

dapper escarp
#

Wall should be in your default Linux installs

neon sleet
#

I got rekt yesterday.

terse willow
#

@dapper escarp Oh, it is -- /usr/bin. Just needed to find where it is so I can kill it as soon as I get into a box ๐Ÿ˜

neon sleet
#

You can just rename it

#

and still use it

terse willow
#

Why would I want to use it?

#

I'm after something far more devious ๐Ÿ˜

void rivet
#

@lusty portal u considered adding a chat box on koth? ik its a stupid idea but still

lusty portal
#

I was going to, but thought Discord would be best:)

#

I think I am going to improve public games joining first

void rivet
#

ah ok yh

vagrant monolith
#

What I miss is a way to see what kind of public game is created, open for me to join. As in the wait time on it. Perhaps a list of open public games? To see whoโ€™s in it

#

Iโ€™ll send it through feedback ๐Ÿ˜

lusty portal
#

Thanks, displaying public games onthe dashboard is a good idea for users to see

dapper escarp
#

Sees optional Dodges

void rivet
#

legit

#

if i see u or sherlock am dippin

mellow bough
#

Just wait until I start playin

#

I've seen Skidy hopping in which means it's totally fair game for me to start messing things up ๐Ÿ˜‰

steep raptor
#

but i love the rush of fighting my way back in @mellow bough after getting the boot

mellow bough
#

hehe

#

Honestly, these games are a rush and I love them

#

Even watching them is a blast

steep raptor
#

ya can't wait for windows machines to kick my butt

turbid plaza
#

@steep raptor think weโ€™ve got a problem on our koth๐Ÿ˜‚

steep raptor
#

no

#

there is something

#

i did to prevent you from writing your name

turbid plaza
#

Ou okay

steep raptor
#

can you figure it out?

dapper escarp
#

Chattr

steep raptor
#

NOPe

dapper escarp
#

Failing that just kill all bash sessions, if itโ€™s a script itโ€™ll kill it

steep raptor
#

how is everyone today?

turbid plaza
#

can you figure it out?
@steep raptor Nope,

steep raptor
#

well i know what i did but not sure how to enum for it

#

whooops

fair adder
#

Hi everyone ๐Ÿ™‚ someone knows when the next KOTH event will be?

lusty portal
#

We're running a KOTH competition next week

fair adder
#

Great ๐Ÿ™‚ is Hammond also on board? was fun watching him last time ๐Ÿ˜‰

void rivet
#

i will put money down on 2 people that i think will win

rigid raptor
#

I don't believe it'll be streamed or recorded at all. That was a once off.

#

probably dan or optional

void rivet
#

yep

#

lol

#

legit whenever i see them in a game cause they get king in like 5 mins

rigid raptor
#

to be fair, they know all the boxes now

void rivet
#

yh

rigid raptor
#

but there's no doubt they know what they're doing

turbid plaza
#

@steep raptor none of us cant get king isn't it?

steep raptor
#

that's right

#

how did that other guy figure it out

#

mmmm

turbid plaza
#

who?

steep raptor
#

oh figured it out

#

lol

#

can't find it with ps

#

REE

steep raptor
#

will retired KOTH boxes be setup as hacktivites. Would like to work on the services I don't understand without getting kicked out.

quiet schooner
#

They will be retired in a way that you can still play them, hopefully alone too

rigid raptor
#

hmm, if the boxes are retired, then on the last day, streamers should be allowed to stream the box

quiet schooner
#

For the last week, I think the policy was

rigid raptor
#

wow.

lusty portal
#

plz stop

#

Banned

rigid raptor
#

self botting gone wrong lol

steep raptor
#

what was that?

rigid raptor
#

also, that sounds cool, @quiet schooner

#

someone repeatedly posting "this [something] was not found" or something like that. I don't think I could paste and hit enter that fast

steep raptor
#

but why?

rigid raptor
#

people do weird poopy all the time.

jolly parcel
cunning mulch
#

@jolly parcel Can you access the box?

#

*oh nvm it responds now

dapper escarp
steep raptor
#

um whoops

dapper escarp
#

I swear no autopwn

glossy vessel
#

imagine using katana in KOTH

dapper escarp
#

katana doesn't work in koth ๐Ÿ˜‚

glossy vessel
dapper escarp
#

imagine people not joining this public game

somber agate
#

Would be sad

quiet schooner
#

FoodCTF has been patched. In summary, tryharder

lusty portal
#

We have over 50 people signed up for the KOTH competition

#

We might have to do games of 10 users per KOTH game

quiet schooner
#

What's the structure?

#

I feel like 10 might not go so well

lusty portal
#

5 games, winner of each goes to the final

fair adder
#

James is right

lusty portal
#

Hmm

fair adder
#

25 member games

quiet schooner
#

Maybe bracket tourney?

lusty portal
#

10 member games

quiet schooner
#

Winner goes to next round, some rounds

fair adder
#

Nah the 10 member game idea seems fine

#

Koth isn't really designed for bracket tourneys

vernal gust
#

plus with just such a small pool of devices it makes it easy to autopwn

fair adder
#

@quiet schooneryou makea me so sad ;-;

#

@vernal gustexactly

#

That's why I didn't enter the competition

vernal gust
#

it's very frustrating

#

like Dan got root in 5 minutes

full grove
#

10 member games seem not fine

fair adder
#

I stand no chance at victory because there are people who have these scripts ready

vernal gust
#

while i struggled for 10 doing recon

full grove
#

how many days until the competition

vernal gust
#

1 week

fair adder
#

It's on the 13th iirc

#

So 1 w ek

#

Week

#

And in that time the scripts are gonna get better

#

@lusty portal is there any chance for competitions we can get competition specific boxes

#

Because certain people have a clear advantage since they've already done the boxes and built autopwn scripts

quiet schooner
#

Push it back a week maybe, use next month's boxes?

fair adder
#

But then people will have an advantage for next month

#

If we have boxes dedicated to competitions

#

Then there's no external advantage which can be used

#

Or gained

terse willow
#

Well boys? Looks like we're designing a tonne of competition boxes...

fair adder
#

Especially since you're offering money

#

There's gonna be people that make an alt account to do KOTH with

#

So they can get more time to analyze the boxes

quiet schooner
#

brb buying 5 subs to play KOTH and write autopwn

fair adder
#

There's way to many ways to cheat this imo

#

@quiet schooner you only need 1

lusty portal
#

We have a KOTH box unreleased (not yet made)

#

We might just that

fair adder
#

8 bucks for 150 seems like a good deal for me

lusty portal
#

And just stop streaming for it

quiet schooner
#

I think you'd need 2 KOTH boxes?

fair adder
#

3

quiet schooner
#

One for the quals, one for the final?

#

2 or 3

lusty portal
#

Ah yea

#

Good idea

fair adder
#

Depending on how many rounds you have

lusty portal
#

Maybe that Windows box will be ready? @full grove ๐Ÿ™‚ If not, I will get another one created

quiet schooner
#

quick someone send Spopy some redbull

full grove
#

ill make sure it is

fair adder
#

So just to be clear

quiet schooner
#

Windows for the final sounds fun

fair adder
#

In the future are we getting competition specific boxes @lusty portal

full grove
#

I was just thinking if we could fastrack a couple of boxes for the competition so we have some mystery boxes in the pool

lusty portal
#

I think @low whale is creating a spec for a new KOTH box

#

So we would have 3

fair adder
#

That's good

full grove
#

Good, its needed

fair adder
#

If you want me to do a koth box I can, im done with this zth room, I just need to send the vms to Ashu since I can't upload them on thm ;-;

full grove
#

;-;

#

ive got a lot of the construction on my box done

#

i just need to implement the fun portion

low whale
#

oh yeh looking forward to the windows box ๐Ÿ™‚

lusty portal
#

If you want me to do a koth box I can, im done with this zth room, I just need to send the vms to Ashu since I can't upload them on thm ;-;
@fair adder Thanks, Ill talk with Ashu and see where things are at:)

#

Might take you up onthat

low whale
#

will be a very good challenge ๐Ÿ™‚

lusty portal
#

i just need to implement the fun portion
@full grove Awesome!:D

fair adder
#

You'll have the Google drive links to the vms in an hour @low whale

#

My internet is a bit slow for uploading

low whale
#

no worries @fair adder ๐Ÿ™‚

full grove
#

vms

#

lul

low whale
#

just send it over when reaadyy

terse willow
#

He's done four for one room...

fair adder
#

I have 4

low whale
#

LOOL amazing

fair adder
#

CC pentesting had like 7

terse willow
#

Then there's me, looking at doing two for my SudoVulns room before it got split up, thinking that was way too untidy, and learning docker just to avoid it. Four is just *shiver*

#

I have no idea how you stand that Pars ๐Ÿ˜†

fair adder
#

It's my room style ๐Ÿ˜

terse willow
#

RIP Pars' internet...

fair adder
#

S*IT GOOGLE DRIVE

quiet schooner
#

Ran out of space?

fair adder
#

I have to repulosd one of them

quiet schooner
#

F

fair adder
#

Actually making a koth box with the web vulns I've done here would be great

void rivet
#

Any noobs like me up for a game of koth

steep raptor
#

been waiting in public all rest of the day

#

@void rivet join if you want

void rivet
#

@steep raptor I'm a noob lad

#

I'm new to all this

steep raptor
#

if you have another player i can see in lobby and watch

void rivet
#

Nah just me

steep raptor
#

well join if you want to

#

watch it be the machine that I have trouble with

#

can't play by myself already tired

void rivet
#

I'll join in a couple mins

#

Just doin somethin atm

steep raptor
#

whenever your ready

#

you're

void rivet
#

im in

#

jeez

#

ur gonna fuck me up

#

cba to wait 10mins ill make a game and inv u

quiet schooner
#

I'm down in a while if you want more competition

steep raptor
#

yikes

void rivet
#

u two are gonna fuk me up

quiet schooner
#

Please keep the language pg13

steep raptor
#

ninja is going to eat some oreo's

void rivet
#

ah sorry

#

my bad

quiet schooner
#

Just a byte @steep raptor