#koth

1 messages ยท Page 19 of 1

rigid raptor
#

actually, fifo is first in first out

terse willow
#

You may be right...

#

Thanks

#

Me being an idiot

rigid raptor
#

on contrast to LIFO, which would be a stack rather that a queue/pipe as FIFO is

void rivet
#

so i run that script and use netcat to listen to the port??

quiet schooner
terse willow
#

Anyway -- the shell is sent via netcat. The stuff that's sent back gets output into the FIFO, thus forming a full circle

void rivet
#

i got locked out anyway

terse willow
#

Yeah, I knew you were right as soon as you said that James ๐Ÿ˜†
It did feel a little off

void rivet
#

Meshal locked me out

#

xD

#

closed ssh

terse willow
#

That's a really good trick to remember either way @void rivet

void rivet
#

yh thanks for that

terse willow
#

Because you can almost guarantee that it will work, as long as netcat is installed

steep raptor
terse willow
#

It's easier to do mkfifo <file> rather than mknod <file> p though

void rivet
#

Meshal has locked up the ssh aha

#

time to go to a enw game

rigid raptor
#

you mean they closed the port?

void rivet
#

yh

#

thats what i mean

rigid raptor
#

I think that might be against the rules

quiet schooner
#

It is

void rivet
#

ooof

quiet schooner
#

That's a DoS of a service

void rivet
#

ooof

#

well

rigid raptor
#

I mean, that's not usually how that term is used, but not wrong for the literal meaning

void rivet
#

yh aha i shouldve just said closed the port

rigid raptor
#

oh, no no, I meant DoS :p

void rivet
#

oh haha

rigid raptor
#

that's usually when you flood something, but what James said is not technically wrong

quiet schooner
#

@rigid raptor Service was denied

#

C I A

#

A was impacted

rigid raptor
#

still not how it's usually used

quiet schooner
#

DoS isn't a flood

#

You can DoS by crashing servers

void rivet
#

so this guy broke the rules

quiet schooner
#

Possibly

rigid raptor
#

probably

void rivet
#

oof

rugged pumice
#

big OOF

#

๐Ÿคž hopefully he does not get in this 1 ;dd

void rivet
#

hopefully

dapper escarp
#

so I assume you've got your autopwn setup? @rugged pumice

rugged pumice
#

no, i don't know to how create them

full grove
#

bash is easy

#

wym

#

you literally just chain commands

rugged pumice
#

i've never scripted/coded in bash, don't know the syntax

rigid raptor
#

bash is easy once it clicks

#

but until then it's black magic

#

keep practicing

full grove
#

sshpass -p password ssh user@box;ssh-keygen;echo oldpass\nnewpass\nnewpass\n|passwd

#

ez

#

there isn't really any syntax

rigid raptor
#

there's plenty of syntax

full grove
#

its basically chaining one liners for koth

#

no real syntax

rigid raptor
#

all the syntax

void rivet
#

@meager cloak same box 3 times in a row

rugged pumice
#

ok that is all i can do on that box ;/

void rivet
#

i legit quit

#

idk what to do there

lusty portal
#

Which machine is it

rugged pumice
#

michael jordan ๐Ÿ˜„

rigid raptor
#

spacejam ;)

lusty portal
#

Eyy

void rivet
#

i ahvent even got creds or a flag for spacejam before

#

tried it 2 times

rigid raptor
#

is that your box, Skidy?

lusty portal
#

Nope:) Shrek is a box I designed, but it was created by Zayotic

#

SpaceJam was created by Zayotic too

rigid raptor
#

Right :p

rugged pumice
#

i got you parallex

#

he stole it ๐Ÿ˜ฎ

void rivet
#

@rugged pumice what u mean aha

#

haha

rugged pumice
#

i put your name in the king.txt file ๐Ÿ˜„

void rivet
#

xD

rugged pumice
#

be he is fighting back

void rivet
#

haha

#

ill send u a script

#

hang on

rugged pumice
#

i have 1

void rivet
#

ah ok

#

@rugged pumice ur holding it of though ๐Ÿ™‚

rugged pumice
#

he is doing something ;Z

void rivet
#

oof

#

i need to learn how to do this box

rugged pumice
#

got it back ๐Ÿ˜›

void rivet
#

aha yesss

#

still got 50mins

#

hehe

rugged pumice
#

this is the easiest box to get king in

#

but now what ;///

void rivet
#

well its easy if u know how to aha

fair adder
#

someone up for a koth?

rugged pumice
#

sowwy

fair adder
#

dude wtf this worked until the koth started

rugged pumice
#

restart it :?

fair adder
#

i did

#

i regened my keys also

quiet schooner
#

@fair adder Control C, reconnect

fair adder
#

had to reboot for it to work

cobalt jackal
#

starts in 20

rugged pumice
ember agate
#

i feel like i found a way how that root shell could be used next time

gusty cradle
rugged pumice
#

wow just found out there is 2 PROD rooms, 1 good, 1 broken ๐Ÿ˜

weary kindle
#

Huh?

quiet schooner
#

Lmao

gusty cradle
#

Or maybe that was food?

quiet schooner
#

If Dan didn't do it, it probably wasn't patched

rugged pumice
#

70% of my time i was trying to figure out what room is it... I know all 5 rooms and this didn't look like 1 of them

quiet schooner
#

Food was patched like 24 hours ago @gusty cradle

gusty cradle
#

^

#

Yeah, you mentioned it to me once

quiet schooner
#

But only a lil bit

weary kindle
#

Yeah, not a fan of patching boxes mid rotation skidy

#

So I can guarantee that Prod has not changed

rugged pumice
#

i'm talking about production room
there is a normal good version
and there is the "broken" version
no?

weary kindle
#

I don't think so?

#

I'm not 100% sure what you mean here

gusty cradle
#

@rugged pumice We're currently doing Food

rugged pumice
#

||GOOD 1||

#

bad 1

weary kindle
#

Different boxes

#

2nd is Patched Food

quiet schooner
#

Don't post spoilers too

rugged pumice
#

my b

#

im so confused lolll

gusty cradle
#

@quiet schooner You made the 8th flag too hard to find, I found all except that one

quiet schooner
#

@gusty cradle if it's the one I think it is, it's worth a bunch

#

And I really like where I hid it

gusty cradle
#

Guess, I'll have to try harder

rugged pumice
#

out of curiosity, why was the food room patch :?

quiet schooner
#

@rugged pumice I messed up one of the routes by mixing up 2 commands, and I patched something else too to make it a beter box

gusty cradle
#

@quiet schooner Are there other ways to get foothold on Food? Or is there only one?

quiet schooner
#

There's 4

rugged pumice
#

4 ๐Ÿ˜ฎ

gusty cradle
#

๐Ÿ‘€

#

Someone patched the first one

quiet schooner
gusty cradle
#

Yep

steep raptor
#

professor can you help me
professor "try harder"

rugged pumice
#

james,I have a question about the patched food room, can I pm you because it my question has a potential spoiler ;?

quiet schooner
#

Yes @rugged pumice but I can't promise I will answer

lusty portal
#

you can now see which machine users are playing

rugged pumice
#

cheers

steep raptor
#

wait it tells you the name of the machine now?

lusty portal
#

Yes:)

steep raptor
#

what's the point of nmap?

lusty portal
#

You're currently playing spacejam

#

I mean, if you have not played it?

steep raptor
#

I have played all of them already

#

ready for new ones

#

and the windows one

lusty portal
#

Coming next week

#

But machnes will be rotated every month

steep raptor
#

what are you thoughts on the change with food?

lusty portal
#

Ya good:)

rugged pumice
#

@steep raptor do you like the new website?

steep raptor
#

the form at the bottom isn't working REEEEEE

lusty portal
#

The flag form?

rugged pumice
#

๐Ÿ˜„

steep raptor
#

no @rugged pumice koth box webpage

quiet schooner
#

@steep raptor You enjoying the food patch?

rugged pumice
#

flag submiting box?

lusty portal
#

Daymn

#

Changing the website to 666

rugged pumice
#

๐Ÿ˜›

steep raptor
#

@quiet schooner yes and no

#

at least you fixed that image lol

quiet schooner
#

@steep raptor The patched route is still easy, just not as easy

rugged pumice
#

James, patching food, does the host monitoring thingy needs to work? or can I just โŒ it

#

๐Ÿ˜ฎ skidy

#

i closed the only way in I know

lusty portal
#

I noticed:)

rugged pumice
#

there is more than 1 way in ?

steep raptor
#

@rugged pumice he removed that because that is what everyone was using

#

not sure if it's still there

quiet schooner
#

@rugged pumice Breaking the service counts as a DoS to me

lusty portal
#

@rugged pumice he removed that because that is what everyone was using
@steep raptor There is another website running

steep raptor
#

what if you made the service filtered?

dapper escarp
#

James

#

please stop

#

you're going to hurt yourself

#

with statements like that

steep raptor
#

@lusty portal i know where that is

rugged pumice
#

James, the service is also 'sort of' a ||backdoor/shell/exploitable/thingy||

lusty portal
#

@rugged pumice I legit cant see how you're connected to the box

#

Am I overlooking something?

rugged pumice
#

im long gone, you kick me out ๐Ÿ˜ž

quiet schooner
#

lol

lusty portal
#

Ah, I run a few commands without even looking who is connected first

#

So might have got you on my first hit

rugged pumice
#

truuu

quiet schooner
#

I didn't realise skidy was playing

#

he has the writeup for the boxes

lusty portal
#

Yeah there is that

quiet schooner
#

call him out for cheating now

rugged pumice
#

๐Ÿ˜ฎ

lusty portal
#

I really need a box where I can say I dont have the writeup, because I'd love to play legit

#

with people

dapper escarp
#

@lusty portal I can give you delusion without a writeup?

lusty portal
#

Is this a KoTH box?

#

I thought it was for a room

dapper escarp
#

it could be

weary kindle
#

just wait for my project to be done

dapper escarp
#

Just need to rename to Asylum

quiet schooner
#

@lusty portal Remember your reviewers can review in theory

weary kindle
#

Then no-one will have a writeup skidy

lusty portal
#

Ashu is creating a new KoTH machine, so will have someone else review.

#

And have him not send the writeup in the chat to whoever makes it

rugged pumice
#

skidy there is no way that there is another of getting into the box apart from ||(1 x 1500) x 2||

lusty portal
#

skidy there is no way that there is another of getting into the box apart from ||(1 x 1500) x 2||
@rugged pumice There are many ways to get in, not just port 3000

#

3 other initial access methods

#

All KoTH machines have at least 3 initial access vectors

rugged pumice
#

without creds? ๐Ÿค”

quiet schooner
#

You on Shrek now?

lusty portal
#

By exploiting vulns

rugged pumice
#

oo ok,

lusty portal
#

๐Ÿ™‚

rugged pumice
#

its the michael jordan aka 666

quiet schooner
#

Ah, Spacejam

#

lmao 3000

rugged pumice
#

there is also a way to patch that without completely killing it,right?

quiet schooner
#

You might need to restart it, but you can patch it I bet

gusty cradle
distant zealot
#

Hi Guys

rugged pumice
#

hell0

distant zealot
#

machine need reset!

#

vote for reset please

rugged pumice
#

@gusty cradle

gusty cradle
#

Reset is not needed

distant zealot
#

ssh key changed

weary kindle
#

yea no that would be intentional

#

Not reset worthy

#

Nice try tho skidy

distant zealot
#

you must change vote reset to maximum

#

5 people in room and 1 left , 3/4 voted !

gusty cradle
#

Fine, I clicked reset,happy?

rugged pumice
#

"I CAN'T WAIT until randomization of ssh keys, passwords, etc comes in place"

gusty cradle
#

@rugged pumice Such enthusiasm! ๐Ÿ˜

rugged pumice
#

bro I googled 'enthusiasm', and still don't understand what you are trying to say ๐Ÿ˜„

gusty cradle
rugged pumice
#

i did just that, but still did not understand it

gusty cradle
#

I want to get shrek or food so I can use my autopwn

#

I need to test it out

steep raptor
#

go again?

gusty cradle
#

๐Ÿ˜…

steep raptor
#

kind of burned out from KOTH already

#

until the comp

quartz gale
#

hi

#

how its koth, any good for beginners or not recommended?

#

just to learn something and have some fun

#

not to win

#

im too n00b

steep raptor
quartz gale
#

ur rank god

#

i am joke here

steep raptor
#

i don't have to play lol

quartz gale
#

๐Ÿ˜†

steep raptor
#

we can just talk

quartz gale
#

yeah thats the reason why I'm here

#

to chill

#

and maybe learn from better players

steep raptor
#

hold on

#

mic

#

needs to be plugged in

gusty cradle
#

I'm hoping it's shrek

#

Or maybe Tyler, I have not done that one

gusty cradle
#

Alright, which one of you deleted /etc/passwd ๐Ÿ˜ 

steep raptor
#

ya doing ok

gusty cradle
#

Someone also broke the privesc

rugged pumice
#

what privesc?

steep raptor
#

join the chat lets talk about it

gusty cradle
#

I think they deleted the vulnerable binary all together

steep raptor
#

im still on the box

#

but unable to do anything because passwd is somehow missing

gusty cradle
#

Were you the one that stopped ssh? ๐Ÿ˜„

#

Yeah someone deleted it

steep raptor
#

no?

gusty cradle
#

@rugged pumice Were you the one that did it?

steep raptor
#

no

gusty cradle
#

?

rugged pumice
#

sorry I was a bad admin

gusty cradle
#

Autopwn mode on

#

We got shrek!

dapper escarp
#

anyone playing any games?

rugged pumice
dapper escarp
#

tarasz your alt?

#

โค๏ธ

#

@rugged pumice you wiped the flags out?

#

/home/donkey/flag.txt empty

rugged pumice
#

what flags:?

#

no

dapper escarp
#

oh I see what you did

rugged pumice
#

i f9888ked up at the beginning and now can't log in

dapper escarp
#

A nasty autopwn that smells like man

gusty cradle
#

flags are empty

dapper escarp
#

cat was removed

#

they aren't empty

jolly parcel
#

are you sure?

dapper escarp
#

use less

gusty cradle
#

An alternative for cat works

dapper escarp
#

it shows

jolly parcel
#

which flag is empty?

#

all flags are there

gusty cradle
#

@jolly parcel Ignore me

jolly parcel
#

lol ok

gusty cradle
#

cat wasn't working so used an alternative

#

You disabled passwd?

jolly parcel
#

no

#

i don't have own autopwn script, just know the way to root

dapper escarp
#

You rooted and hardened in under a minute ๐Ÿ˜‚

#

Even my autopwn didn't work that fast

jolly parcel
#

my autopwn keeps failing everytime and i don't have a chance to work on it

#

i have scripts for persistence

#

not for root

dapper escarp
#

pretty much the same thing ๐Ÿ˜‚

#

Root pwning is the tricky step usually

jolly parcel
#

and then i manually patch all privescs i know

#

so maybe i missed something there and there is still a way to get root

#

like someone did on the last game

#

and removed passwd -_-

gusty cradle
#

@jolly parcel Did you remove /etc/sudoers again?

jolly parcel
#

yep

steep raptor
#

ya D:

jolly parcel
#

it's very easy to gain some persistence in a few mins, i am working right on a way to get good persistence without modifying or deleting most of the things on the box

gusty cradle
#

Who did the spam?

jolly parcel
#

not me

gusty cradle
#

It's @dapper escarp

weary kindle
#

get /dev/urandom'ed

gusty cradle
#

I have control of the shrek, he has donkey, you have root

weary kindle
#

Just be glad he doesn't have the parrot ready kekw

dapper escarp
#

You guys enjoying the linpeas wall?

#

thought you'd like some priv esc tips

gusty cradle
#

@dapper escarp You're evil

dapper escarp
#

keep killing my connection

gusty cradle
#

@jolly parcel Close ssh ๐Ÿ˜†

jolly parcel
#

rm /etc/passwd

#

easy win

gusty cradle
#

rm -rf /* -- more easy win

jolly parcel
#

DOS

#

deleting flags

#

etc

steep raptor
#

does removing passwd and shadow count as a DOS?

#

hope so that sucked

gusty cradle
#

Stop with /dev/urandom

dapper escarp
#

aint me anymore

jolly parcel
#

๐Ÿ™‚

weary kindle
#

all you need is 2 commands

#

who and pkill

jolly parcel
#

i am almost sure there is another way to privesc

#

that i haven't patched

dapper escarp
#

Well Puss is locked entirely

#

Shrek has been gimped as his only way is in ssh

gusty cradle
#

I'm shrek

#

Hehe

jolly parcel
#

@gusty cradle have your autopwn script worked?

gusty cradle
#

Didn't get time to check it out, let me see

#

Nope, it required sudo

#

Which you deleted

jolly parcel
#

well, we can restart

#

so you can check

#

1 vote left

gusty cradle
#

Who shut down ssh?

jolly parcel
#

congrats to someone

gusty cradle
#

sudo: no tty present and no askpass program specified

#

It returns this error

weary kindle
#

spawn a pty session?

jolly parcel
#

btw, are the flags rotated each game?

weary kindle
#

Soonโ„ข๏ธ

dapper escarp
#

wait ssh actaully went down?

gusty cradle
#

I think that was when the box restarted

dapper escarp
#

Kill my session

#

I kill your sanity

jolly parcel
#

how are you doing there?

gusty cradle
#

I need to go to sleep, see you guys tomorrow!

steep raptor
#

night @gusty cradle

dapper escarp
#

gnight mate

dapper escarp
#

anyone doing lobbies without auto?

steep raptor
#

we are kind of already in the middle of one

#

@dapper escarp

long kiln
#

what is koth? ghostblobgib

tawdry agate
#

King of the Hill ๐Ÿ™‚

stable narwhal
dapper escarp
#

why dev null it

#

when you can replace it with terminal parrot dark

stable narwhal
#

Ffs what is with you and terminal parrot haha

#

It's a brilliant troll tbf

dapper escarp
#

my new favourite thing is creating ssh spam sessions to wall other peoples terminals

stable narwhal
#

That was great

dapper escarp
#

praise while :; loops

stable narwhal
#

Need a cowsay displaying "you just got trolled"

#

In-line bash FTW

dapper escarp
#

Man the things you can do with one line of bash is disgusting

stable narwhal
#

why dev null it
@dapper escarp could replace it to echo "Meow"

#

Agreed, who doesn't love a cheeky bash one liner

dapper escarp
#

I might just spam it with links to my youtube or twitch ๐Ÿ˜‚

stable narwhal
#

That's a decent way to plug

dapper escarp
#

Gotta take all the opportunities to plug

stable narwhal
#

Or rick roll

sonic atlas
#

lol optional always a troll

dapper escarp
#

You know if you don't get troll stuff like that, I'm trying hard to win

#

as I usually plant stuff like that around to stop people, if it seeks you out then I'm trolling

stable narwhal
#

I think the biggest trolls in KOTH are the Ox1s that just autopwn

dapper escarp
#

too many autopwn ruining the gamemode tho

#

Just gets boring, oh look you autopwn, looks like I need to use my autopwn and lose any enjoyment

sonic atlas
#

yeah I don't get that takes all the fun out of it

stable narwhal
#

Writing an autopwn is more entertaining than using the autopwn

dapper escarp
#

^^

#

Hard agree

#

I did it as a laugh

#

like on space jam, you can harden the box and gain persistence with one curl command which is hilarious

#

Shrek is equally as easy to get root callback and t hen have it execute a bin script on nc

#

I haven't had food or production more than once since KOTH released

#

only shrek/spacejam

stable narwhal
#

Think I may start playing KOTH when the new rotation happens

dapper escarp
#

^^

#

Yeah I don't think I'll be playing much unless it's private lobbies with people who won't autopwn

#

as it just gets boring else

stable narwhal
#

People have also played the boxes too much so they instantly know what to do regardless of autopwn, starting late in KOTH is pointless

dapper escarp
#

I dunno

#

A lot of people don't explore past the initial exploit path they find

#

so the harder ways in are rarely patched

sonic atlas
#

once there loads of boxs that should change

dapper escarp
#

Once I get the motivation to develop a koth box it should be interesting

#

more than 2/3 users

#

pivoting and multiple priv escs etc

#

users having only one way into them kinda limits it heavily

stable narwhal
#

That could be interesting

dapper escarp
#

oh look shrek needs an id rsa, better regen the keys

#

rip shrek

#

Oh puss uses telnet. Better shut that off, F for puss

#

better echo a passwd for donkey. Box dead

#

gg no re

stable narwhal
#

Random passwords and flags each game would help, I wonder if you could have a rotation of locations as well, change the paths to flags

dapper escarp
#

I mean in theory it's possible, a nightmare to implement random paths

#

I just think the complexity of boxes needs to be increased a bit

#

as they are too easy to autopwn

#

If all the boxes were like Tyler for example

#

that would be a good time to be alive

stable narwhal
#

Yeah, people say Tyler is harder than the rest of the current boxes

dapper escarp
#

Tyler is much harder

#

I've only had it once

#

maybe twice at most

#

still haven't rooted it

stable narwhal
#

Any idea if the KOTH boxes will be made into challenge rooms once retired?

dapper escarp
#

Think there is the idea of having a retired pool

#

idk if they will make them into rooms or just keep it as a pool

#

would need Ben or Ashu to clarify

stable narwhal
#

Ah okay, either or would be decent

dapper escarp
#

retired pool would be nice as it would give people who wanna stream it a chance to have a koth experience without spoiling active rooms

lusty portal
#

Random everytime

stable narwhal
lusty portal
#

Its possible to get that working

#

Would be very very fun

dapper escarp
#

^^

void rivet
#

^^

brazen cloud
#

We've setup SecGen for use in our CTF's here - very doable, also very good content wise!

weary kindle
#

Hey I'm working on that, it just takes time

lusty portal
#

People I have not seen before are playing

#

Why not join them

rigid raptor
#

That's a lot of new names

gusty cradle
#

@rigid raptor Join or no ๐Ÿฐ

rigid raptor
#

I already did, you bulli

gusty cradle
#

๐Ÿ˜

lusty portal
#

@rigid raptor is playing ๐Ÿ˜ฎ

#

This is new

#

I really hope this box isn't Tyler

#

That wouldn't be fun for anyone

rigid raptor
#

hahaha

#

I played once before. Got my butt handed to me.

#

I'll likely not do very good, but oh well~

#

it'll be fun

lusty portal
#

Got to be in it to win it

#

What was the last machine you played?

rigid raptor
#

spacejam

lusty portal
#

SpaceJam?

#

Ah yes

rigid raptor
#

i couldn't find any damn way in

lusty portal
#

Thats a nice one to start off with TBH

rigid raptor
#

haha, in that case i'm really gonna get it

#

oh

lusty portal
#

Oopps

rigid raptor
#

hahahaha

lusty portal
#

Unless someone closed a port to help you get in

gusty cradle
#

I hope it's shrek ๐Ÿ˜„

#

or Food

rigid raptor
#

I hope it's ๐Ÿฐ

lusty portal
rigid raptor
#

yupp

#

uh, I should probably connect to the vpn now

gusty cradle
#

@rigid raptor Held og lykke, ignore my pathetic Danish. ๐Ÿ˜„

rigid raptor
#

tak tak

gusty cradle
#

Du er velkommen

#

We got tyler ๐Ÿ˜ข

dapper escarp
#

F

lusty portal
#

Oof

#

Unlucky

#

Well, GG game over

gusty cradle
#

I got one flag

#

Time to found seven more ๐Ÿ˜ข

rigid raptor
#

I think I found something, but I need to research it first

#

did you just put me as king, @gusty cradle ? lol

#

cause I didn't

gusty cradle
#

Nah, I just came back I've been gone for last 10 minutes

rigid raptor
#

hahah alright

gusty cradle
#

@rugged pumice They are the one doing it

rigid raptor
#

ah, looks like the winner is giving everyone a few points xD

gusty cradle
#

Yeah

rigid raptor
#

hehehe

rugged pumice
#

๐Ÿ˜

rigid raptor
#

cute

dapper escarp
#

Also means that the leaderboard will be made public as there are multiple king changes

rigid raptor
#

hahaha

#

mmmh, I'm missing a few pieces to get in >.>

neon sleet
#

This is hilarious

#

King keeps changing

rigid raptor
#

666 is doing it

rugged pumice
#

i'm going afk, every 1 minute there is going to be a new king. so everybody is going to rotate. you can see the ps running on the box on the live stream

rigid raptor
#

pfffh

neon sleet
#

I didn't see the stream

#

one sec

#

That is great ๐Ÿ˜›

#

I was wondering how everyone had king time without flags.

#

On Tyler

rugged pumice
#

๐Ÿ˜„

rigid raptor
#

mmh, I found several approaches, but for all of them i'm lacking pieces

rugged pumice
#

hmm

rigid raptor
#

I bet i'm missing something super obvious

rugged pumice
#

if ma1ware is not in by now, there is something wrong

rigid raptor
#

I think they left cause of the box selection

rugged pumice
#

ohh ๐Ÿ˜„

gusty cradle
#

Nah, I'm here

rigid raptor
#

oh, right

gusty cradle
#

I just came back

rigid raptor
#

I'll piggyback my way in

gusty cradle
#

I have homework to do ๐Ÿ˜ข

rigid raptor
#

ew~

gusty cradle
#

Online school started again today

rigid raptor
#

I'm going to take a big nap

rugged pumice
#

so you do video chats or just online assignments ?

gusty cradle
#

@rugged pumice Online assignments they upload videos

rugged pumice
#

ohh

gusty cradle
#

I think I know what to exploit, but unfortunately it does not seem to be working right now, so I started doing homework

#

@rugged pumice gg

rugged pumice
#

gg

gusty cradle
#

You guys up for another?

rugged pumice
#

i gotta go to work in 30 minutes ;/

rigid raptor
#

I thought you had homework :p

gusty cradle
#

I completed it

rigid raptor
#

surely you can pwn us in less, 666 ;D

gusty cradle
#

English homework

rugged pumice
#

well, i'll skip it because I have to eat, watch couple of video, etc

#

it wouldn't be fun for you guys if i go there and patch it in 3 minutes; without autopwn ๐Ÿ˜‰

north cedar
#

Keep my name in your mind, I will wreck on KOTH comp day, not the good way, but the "check yoself before you wreck yoself" way

I will WRECK... (Myself) ๐Ÿ˜ซ

primal estuary
rugged pumice
#

@steep raptor shoot up link for koth if possible ๐Ÿ™‚

full grove
#

summon @dapper escarp and @weary kindle kekw

steep raptor
#

was getting food

#

how's everyone

rugged pumice
#

good n u?

steep raptor
#

im doing alright the covid-19 stay at home is kinda getting to me though

rugged pumice
#

staying at home is chill lol

steep raptor
#

@rugged pumice it was just when thing were really to start to come together, then covid-19. Oh well

#

nothing I can really do other than stay home as must as possible

#

@rugged pumice how was your last KOTH?

rugged pumice
#

the 30king changes game?

steep raptor
#

@rugged pumice the one you just posted in the KOTH chat

rugged pumice
#

ohh, it was 1v1, with my alt account ๐Ÿ˜„

steep raptor
#

oh

rugged pumice
#

i forgot about it and didnt play it

steep raptor
#

can't wait for the new KOTH machines to kick my butt

rugged pumice
#

same

#

u wanna play?

steep raptor
#

not right now still eating and creating more notes

rugged pumice
#

kk

steep raptor
#

@rugged pumice think it would be cool if someone was able to pop a shell with VBScripts on windows

rugged pumice
#

yep, I've been looking into windows privescs

steep raptor
#

what happens if the exploit blue screens the box and there are not enough people to reset it

#

would that be labeled as a DOS or admin failure to defend

rugged pumice
#

I checked my own windows to see if there was some privesc and I found 1 that allows any user on my pc to create another admin user :E

steep raptor
#

whops

rugged pumice
#

it wouldn't be DOS because it is not your fault that the machine crashed/couldn't handle a service properly ๐Ÿ˜‰

#

i wonder if we will be able to 'Remote Desktop' the windows machine ;o

steep raptor
#

@rugged pumice what do you use for remote desktop. There is a Linux tool I install on kali to do RDP from kali

#

as the client

rugged pumice
#

me too, but i forgot what was the name of the tool

steep raptor
#

remmina @rugged pumice or do you use something else?

rugged pumice
#

yes, i believe so

distant zealot
#

Yo

full grove
#

intentionally BSOD'ing the box would be more griefing than anything else

#

also doing that would be incredibly stupid as BSODing the box would prevent a person from becoming king -- they'd basically be relying on flags, which is a really bad strat

hidden island
#

Yo I'm in koth rn, need some peeps to join!

distant zealot
#

anybody for play ?

gusty cradle
#

We need a conformation button, before joining a koth match

hidden island
#

gg

gusty cradle
#

I joined last 15 minutes ๐Ÿ˜ข

hidden island
#

that was a fun box. I guess we're not allowed to talk about our solutions tho

#

i rly enjoyed it

#

went ahead and joined the next as well

lusty portal
gusty cradle
#

@lusty portal Are you playing?

lusty portal
#

I am not, have the writeups as someone said, so would be unfair.

#

I've also tested a lot of the machines

gusty cradle
#

๐Ÿ˜…

lusty portal
jolly parcel
#

8 now

brittle elk
#

sad me that i can't join

latent quest
gusty cradle
#

We're getting production

weary kindle
#

ooh

#

glhf

brittle elk
weary kindle
#

Change it in your profile settings

lusty portal
#

^ only if you're actually that level tho:)

latent quest
#

I'm going to check real quick...

dapper escarp
#

Iโ€™ve been summoned

lusty portal
#

RIP Tyler

#

Thoughts on removing Tyler until we have a better matching system in place?

weary kindle
#

Hell nah

latent quest
#

Plus. I don't know that better matchmaking would fix the issue looking at the ranks of the players.

dapper escarp
#

Donโ€™t do it

#

Tyler is the only room that provides any challenge at all

fair adder
#

Lol

lusty portal
#

King on Tyler

dapper escarp
#

pog

#

dpgg is insane

#

added to my dodge list

nova tide
#

why everyone is making new accounts to kick others ass? just come from your main

latent quest
#

^

dapper escarp
#

^

glass flare
weary kindle
#

I see you've gotten Food

lusty portal
#

inb4 people think its a problem with TryHackMe:)

glass flare
#

I am thinking, it's problem with Dan ๐Ÿค”

weary kindle
#

I'm not even playing KOTH atm ๐Ÿ˜…

#

I'm training my attack in OSRS

glass flare
#

๐Ÿ™‚

#

Food is really good, I am not finding any way to go through ๐Ÿ˜…

reef storm
#

@lusty portal @dapper escarp before that game, i had the same machine

manic palm
#

Is KOTH team based or is it just 6 person free for all

reef storm
#

free for all

manic palm
#

Is it diversified in skill/challenges? For example, my web is drastically better than binary exploitation

#

I saw in John Hammonds videos there were multiple ways in

#

Which is nice

reef storm
#

3rd time tyler in my room

#

are the rooms for koth generated every ~25 minutes?

glass flare
#

Any hint on FOOD Please ๐Ÿคฆ

terse willow
#

We can't give hints for active Koth boxes...
Kinda defeats the purpose, don't you think? ๐Ÿ˜›

reef storm
#

is there a possibility to lower the countdown when someone joins a room

distant zealot
#

im in ๐Ÿ™‚

nova tide
#

is anyone streaming koth?

rugged pumice
#

8 players :O, thats new

latent quest
#

@nova tide I don't believe that it's allowed.

rugged pumice
#

its allowed

#

for this 1

gusty cradle
#

^

nova tide
#

its allowed

#

even still watching 0ptional's previous video, also johnhammond have one on his channel

latent quest
#

Yeah. My understanding was the launch one was an exception. I could be wrong on that however.

gusty cradle
#

@rugged pumice Shrek autopwn on ๐Ÿ˜

weary kindle
#

Streaming the active pool is allowed for the first month

#

As soon as there is a retired pool, streamers have to switch to that

rugged pumice
#

@gusty cradle try it

gusty cradle
#

rooted

latent quest
#

@weary kindle Got it thank you!

rugged pumice
#

now what ? @gusty cradle

gusty cradle
#

What do you mean?

rugged pumice
#

still lurking i see, ok

gusty cradle
#

๐Ÿ˜†

glass flare
#

lol, your deleting flags @gusty cradle

rugged pumice
#

you can't do that

gusty cradle
#

No

#

I'm not

distant zealot
#

i can't see my uploaded file ?

gusty cradle
#

Some idiot deleted shrek's flag

distant zealot
#

i uplaoded but can't opened it not found

rugged pumice
#

wow

gusty cradle
#

@rugged pumice Tut, tut piping chattr to /dev/null

rugged pumice
#

not me

#

2/4 already lol

#

OK! im angry now

gusty cradle
#

๐Ÿ˜†

glass flare
#

Good defending, Not even letting me to be on box for atleast 1m lol

#

reset the box ๐Ÿคฆ

gusty cradle
#

๐Ÿ˜„

rugged pumice
#

how many times are you guys going to restart the box

#

the outcome is the same

gusty cradle
#

I win

distant zealot
#

gg

nova tide
#

gg

gusty cradle
#

I have not won yet

rugged pumice
#

why would you

gusty cradle
#

?

rugged pumice
#

I SEE U

gusty cradle
#

No, you don't I'm hidden

#

Just one more reset ๐Ÿ˜„

rugged pumice
#

๐Ÿ˜„ lol

quiet schooner
#

@rugged pumice ...are you on an 80s VT terminal?

rugged pumice
#

๐Ÿ˜„

#

is 1 of those retro terminals i have installed

#

i really like it

fair adder
#

Kind of reminds me of Fallout

glass flare
#

lol port 22 closed

gusty cradle
#

is ssh down?

#

@rugged pumice That's me

#

๐Ÿ˜

rugged pumice
#

shouldn't be

#

;/

gusty cradle
#

Guys reset

rugged pumice
#

i think its down for maintenance

gusty cradle
#

๐Ÿ˜„

rugged pumice
#

how many resets did they do so far ๐Ÿ˜„

gusty cradle
#

SSH is down...

#

๐Ÿ˜ 

rugged pumice
#

3 minutes ; no point of reset

#

its this time of year

gusty cradle
#

You keep stealing my root!

#

๐Ÿ˜„

rugged pumice
#

of course

#

and you keep logging in some how ๐Ÿ˜„

gusty cradle
#

I have a backdoor ๐Ÿ˜†

#

Good luck finding it ๐Ÿ˜†

rugged pumice
#

i can tell because i've secured some stuff

gusty cradle
#

@rugged pumice gg

#

I'll get you next time

#

๐Ÿ˜†

rugged pumice
#

๐Ÿ˜„

gusty cradle
#

At least I know my auto-pwn works

#

๐Ÿ˜„

fair adder
#

Just create a internal port loop on a local server on the machine

#

your not closing ports

#

just re-directing traffic ๐Ÿ˜‰

gusty cradle
#

You talking about ssh tunneling?

fair adder
#

y e s

gusty cradle
#

That will still leave ssh open

fair adder
#

Not if you re-direct any new connections that aren't your IP

gusty cradle
#

It's a good idea

fair adder
#

Thanks

gusty cradle
#

๐Ÿ‘

dapper escarp
#

Time for some koth

glass flare
#

Send me link, When your up. @dapper escarp

dapper escarp
#

Stream is up, starting properly in 5 minutes

lusty portal
#

Private game, nevermind

rugged pumice
#

let them play alone, they look like they are fresh ;D

dapper escarp
#

I have a new name in my game

#

huh?

lusty portal
#

Oo

dapper escarp
#

inb4 someoen autopwns

#

gunna scream if they do

lusty portal
#

@rugged pumice is in and has done every box (I think?)

#

Will be a race:)

glass flare
#

@lusty portal I want link to join ๐Ÿ˜‰

dapper escarp
#

just click join public

rugged pumice
#

true

dapper escarp
#

I don't plan on autoing anything today

glass flare
#

๐Ÿ‘

dapper escarp
#

so if someone auto pwn I just jump into next game

#

basically oh look king in under 2 minutes

#

out

lusty portal
#

If you can work out who it is, let me know.

fair adder
#

Congrats on that tense game guys, I was watching in the shadows!

rugged pumice
#

i don't have any autopwns, i don't find them fun

dapper escarp
#

you have enough alts so it's assumed you have them

#

just saying xD

rugged pumice
#

;]

weary kindle
#

@dapper escarp hop in mentor lounge big man skidy

dapper escarp
#

alts are only used to develop your knowledge/scripts

#

is usually my assumption

gusty cradle
#

I use my alt to develop autopwn

glass flare
#

seems 1hr is not enough to enumerate food ๐Ÿค”

rugged pumice
#

;/?

glass flare
#

got down into many rabbit holes....

quiet schooner
#

@glass flare 1hr is plenty for food

gusty cradle
#

I do need to verify my Food autopwn

quiet schooner
#

There are no rabbit holes.

gusty cradle
#

@glass flare Send an invite ๐Ÿ˜„

#

You are currently doing Food, right?

rugged pumice
#

its in public lobby

glass flare
#

Nop, I did it back...

gusty cradle
#

Has the match started?

rigid raptor
#

There are always rabbit holes, James. Especially if you make them yourself :p

rugged pumice
#

15 mins

gusty cradle
#

To start?

#

Or to end? ๐Ÿ˜†

rugged pumice
#

start

glass flare
#

I think, i enumerated food too much.

#

hitting everything hard without any success.

gusty cradle
#

There is no too much enumeration

quiet schooner
#

Don't hit things hard

#

Hit things smart

glass flare
#

๐Ÿ˜‚

#

๐Ÿ‘

weary kindle
lusty portal
weary kindle
#

Games with viewers

rugged pumice
#

play koth/275 or watch both streams ๐Ÿค”

lusty portal
#

how did I not get that rip

#

And thats awesome

#

When you do, I can put an announcement out

dapper escarp
#

Put it out whenever bby, hopefully can get some decent games without autopwning

weary kindle
#

I think we're both live now, so

rugged pumice
#

ima watch @dapper escarp and @weary kindle stream instead of playing

latent quest
#

Oh. That would be fun to watch. Definitely going to play some latter today.

rugged pumice
#

would be cool if you guys did squad stream ๐Ÿค”

weary kindle
#

not a clue how that works

rugged pumice
#

;/

weary kindle
#

plus chat says we need partner

distant zealot
#

why i can't change this file with root -rw-r--r-- 1 root root

nova tide
#

ok so flags wont change in koth hill, people save that and spam right after the room starts.. have already saved the passwords for all users as they have done the room before.
so whats fun in that??

rigid raptor
#

I assume that that's going to change in a coming version. This is the first version of KotH, after all. It was just released not more than a week ago

nova tide
#

yeah i did watched the beta stream but i am still wondering whats the fun in that??

ok so flags wont change in koth hill, people save that and spam right after the room starts.. have already saved the passwords for all users as they have done the room before.
so whats fun in that??

rigid raptor
#

you can choose not to play if the current version isn't enough for you, you know :)

nova tide
#

well thats one way to put that, Thanks!!! gotta stay put in the Quarantine then

rigid raptor
#

Keep it sleazy, mate :p

distant zealot
#

why i can't change this file with root -rw-r--r-- 1 root root

ionic yarrow
#

somebody is doing dos or ssh brute forcing or something now in koth and it's really sad ๐Ÿ˜ฆ Why ruin the game man

rigid raptor
#

What error are you getting, @distant zealot ?

distant zealot
#

@rigid raptor Permission denied

rigid raptor
#

@ionic yarrow I believe there's a report system for this on the game page

#

sounds like you don't actually have root, @distant zealot

ionic yarrow
#

Really where ??

distant zealot
#

uid=0(root) gid=0(root) groups=0(root)

#

is it possible someone change it ?

rigid raptor
#

I thought it was at the bottom of the page, but now I can't see it. Might not be visible to spectators

#

who knows, @distant zealot. It could be all sorts of interesting trickery. It all depends on the other players

distant zealot
#

@rancid pewter you did it ๐Ÿ™‚

rancid pewter
#

Yes

distant zealot
#

ah then game is over ๐Ÿ™‚

rigid raptor
#

hehehe :)

distant zealot
#

there is no way recover it ?

rancid pewter
#

Yes there one way

rigid raptor
#

Not if they patched it up correctly. But who knows, they may have missed something -- or left themselves a backdoor

rancid pewter
#

I have patched up nothing I just make the king.txt write protected

#

And now I simply mess with their terminal

rigid raptor
#

haha :p

distant zealot
#

what mean write protect ? mean root also can't write ?

rancid pewter
#

Yes

distant zealot
#

then there is no recovery ?

rancid pewter
#

I did the same with my ssh key on the box

#

Yeah you need to use a specific program

rigid raptor
#

haha

distant zealot
#

i see chattr ?

rancid pewter
#

Yup

distant zealot
#

good job

rancid pewter
#

I have moved it in the /opt folder if you to be king for the last minute

distant zealot
#

good

rigid raptor
#

what, you moved chattr?

rancid pewter
#

I moved the chattr binary

rigid raptor
#

hahahaha

#

that's absolutely hilarious

ionic yarrow
#

Did you guys had hard time logging in ssh ?

rancid pewter
#

Good job everyone nice game

distant zealot
#

gg

#

and if i upload new chattr binary i can change it right ?

rancid pewter
#

Yeah

distant zealot
#

haha good

rigid raptor
#

yeah, I was just thinking about keeping a stash of binaries for that sort of thing.

latent quest
#

Yeah. Going to play a bit and get a feel for what I'll find useful.

cobalt jackal
lusty portal
#

^ Lots of users

cobalt jackal
#

aye skidy?

lusty portal
#

heyo

cobalt jackal
#

when's the next set of boxes coming in?

lusty portal
#

End of the month

#

But 2 more are being added Monday

cobalt jackal
#

awesome

lusty portal
#

A new Windows/Linux box

cobalt jackal
#

windowspepehands

#

I can dig windows

dapper escarp
#

@lusty portal think someone just jumped on migrated to the king process

weary kindle
#

someone DoS'ed the 9999 port

lusty portal
#

Is it DoS'd or a mistake?

#

Hm

weary kindle
#

No king update for a while

dapper escarp
#

I mean king isn't updating

#

I have persistence on it

lusty portal
#

I will investigate AWS logs to see if I can catch anything, and then try match it to the virtual IP if I can

#

Just speeding up THM atm by rewriting queries/restructing database

cobalt jackal
#

I love how skidy is THE admin, but is 0x1

#

xD

#

much respectcat_ping

rugged pumice
cobalt jackal
nova tide
#

@lusty portal admin or not use commands in #bot-commands Thanks ๐Ÿ˜†

rugged pumice
dapper escarp
#

Lol

#

shocked you're not banned

rugged pumice
#

why ๐Ÿ˜„

reef storm
#

๐Ÿ˜‰

neon sleet
#

You broke one of the minimal rules that KOTH has.

rugged pumice
#

which is?

dapper escarp
#

what are you binding your boot process to?

#

Out of curiousity

glass flare
#

@lusty portal Hide all the box names, and don't atleast name the boxes, maybe hard to make autopwn keep secret.

reef storm
#

@dapper escarp @weary kindle please give us a chance ๐Ÿ™‚

dapper escarp
#

you rooted tyler

#

doubt we have a chance really

reef storm
#

as i said i played tyler today 4 times

#

and after the 2nd game i gave up, its not fun at all

quiet schooner
#

@glass flare you can immediately tell it based on your nmap scan

latent quest
#

I love how skidy is THE admin, but is 0x1
@cobalt jackal He went so far up the scale there was no where to go but loop back around. ๐Ÿ˜

quiet schooner
#

@reef storm Tyler is the most fun box for some people, they're different in difficulty by quite a bit

lusty portal
#

If game 279 isn't Tyler, winners gets a free sub? Make it a little interesting

vagrant monolith
#

I head the privesc of Tyler was patched or changed? I'm most likely wrong

dapper escarp
#

if game 279 is shrek I'm not playing koth anymore

lusty portal
#

^ nooooo

dapper escarp
#

I only seem to land in shrek/spacejam

lusty portal
#

Shrek for love and life

reef storm
#

no shrek

dapper escarp
#

autopwn boxes suck tbh ๐Ÿ˜‚

lusty portal
#

Ah yeah I saw that script

dapper escarp
#

Tyler is the only one that doesn't have auto to my knowledge

vagrant monolith
#

10 players?! wth

lusty portal
#

I increased it for next weeks competition

vagrant monolith
#

Nice haha

#

cool

lusty portal
#

Might decrease later

dapper escarp
#

New weeks comp new boxes or nah?

lusty portal
#

2 new boxes

dapper escarp
#

hows the bracket working for that?

lusty portal
#

After talking with Ashu, we couldn't have 5 new ones developed in time

reef storm
#

is there going to be any ad machines?

vagrant monolith
#

Ahh man, I might join in if I get the chance

lusty portal
#

And time to test them all

reef storm
#

if its tyler i'm not playing

dapper escarp
#

If there's two new boxes it depends on how the bracket works

vagrant monolith
#

Havnt played tyler yet @reef storm ?

reef storm
#

i had 4 times in a row

dapper escarp
#

If it's groups and winner of group goes into finals bracket

#

that's good

#

if not then it won't work as auto

#

get root > harden > autopwn written

quiet schooner
#

Tyler 4x in a row is like 0.16% chance

#

Crazy unlikely

dapper escarp
#

I'm here to say that the box selection isn't a mathematical chance

#

I've had shrek 5 times at this point

lusty portal
#

I promise its random

dapper escarp
#

only seen food and prod once

lusty portal
#

Food eyy - Going to be a good game

quiet schooner
#

Randomness is weird, but yeah I had tyler 3x in a row too

glass flare
#

Oh my food...

reef storm
#

gg guys, was fun

weary kindle
#

gg

nova tide
#

i think it was optional's stream where he said it would be fun if we have to play multiple machines at a time and hack both of them at the same time

#

as you have 2 boxes coming up may be try that?

dapper escarp
#

Guys on Food

#

just because you can't edit the king.txt file means reset

#

just means tryharder

stable narwhal
dapper escarp
#

Resetting because the binary is missing is just griefing

vagrant monolith
#

Ah box is slow ๐Ÿ˜ฆ

rigid raptor
vagrant monolith
#

So uhm, @dapper escarp I guess shrek closed up for today ๐Ÿ˜›

#

My first go at shrek, so had no idea about entry points

desert kernel
#

yo

#

why did it changed to 14 mins

#

it was first 7

#

lol when i refreshed it went back to 4 ๐Ÿ˜›

dapper escarp
#

So shrek still has a numebr of ways in โค๏ธ

#

Someone regenned shreks key

#

so idk about that one

fair adder
#

helping out..

dapper escarp
#

high ports

#

do a full port scan

#

donkey is also still a way in

desert kernel
#

@fair adder