#koth
1 messages ยท Page 20 of 1
not my first time
Man try harder, but a lot of my stuff is timing out
i am
!multivpn
Type ps aux | grep openvpn into your terminal and press enter
If there's more than one line (and the second doesn't have "grep" in it), do the following steps
Type killall openvpn into your terminal and press enter
Start the VPN with sudo openvpn <path-to-config>
Well, getting in again
did u patched something already ?
@desert kernel Nope
Nah @dapper escarp s
I have patched some things
yea im not in optional ones
@here intrested come and join me
not me
Blind RCE, perfect
its not
coz with burp i see it
ok
now i cant read the flag
while im that user did u changed that ? ๐
which flag?
bread
bread rce should lead to a shell
I didn't touch the flags
wp
first time i played this machine
good luck
waiting on nmap :/
heheh
have you guys already mooed today
๐
haha
copy cat
ok now it requires suddenly a password
Maybe because someone patched it
its a ssh key
Yes, if you remove the key then it goes to password auth
thats allowed ?
I mean it's not DoS
It's a valid patch
@desert kernel You can find that out with some forensics


https://tryhackme.com/games/koth/291 best koth game in a long time
https://tryhackme.com/games/koth/291 best koth game in a long time
@dapper escarp Oo, what made it a good game?
No constant shell deaths and people were fighting to maintain king
Eyy
Any other techniques used to keep yourself as king?
Just porting in some other chattr binaries and hiding them
food has chattr on there without it being borked
Eyy:)
some spicy one liners coming in
Gotta work on using files over nc tbh
as someone at one point just removed the chmod binary
I'd just base64 it, copy it over, debase64
just use wget
or python web server
or curl -o
Some point during next week we will ask how to make KoTH better too. So keep notes on what makes a good game / what to add
PogChamp IRL
kekw
F
nice lobby system
Tyler I reeee
Oo he is playing without streaming
shrek I cri
Did I really win AGAIN
pikachu acts surprised meme
Expecting oreo to do some spicy stuff and win tbh
reset ?
why lol
hard box that few can root
nope
if it was that easy
i wouldnt be in that shell
eveything longer then 13 chars gets segfaulted
Falcon just comes in and claps some cheeks
Rather than random, I might rotate each machine. (Tyler -> Food etc..) or ensure the same doesn't come up again (right after the previous game)
I think he wants Tyler again ๐
I dont seem to be getting points for having my name in king.txt
any thoughts or am i stupid?
@versed oxide Make sure it's an exact copy and paste of your username
like, just the Plensu part, or the rank and stuff included?
Nah, just the Plensu part
yea its in there
So I would put in MuirlandOracle -- no extra spaces or information
Are you showing up as the King in the stats page?
nope
Uh, chances are that someone is overwriting the file then
What's the machine IP?
There is no king in the file
hmm. ive been tricked then i guess
Quite possibly
The machine will be broadcasting the current King on port 9999
Nothing's coming up from that IP
can i dm a question then just to verify there isnt an issue?
Yeah, go for it
and not possibly post anything i shouldnt
Agh. Freaking Tyler.
is it bug in king.txt ? some times it got empty and no one can write on it , i have permission and no got error
๐
@distant zealot Have you messed something with /bin/bash? Maybe that's the problem.
you deleted it ?
i think you did , i can't write to king
but i didn't any error for writing
@quiet schooner told That'll be someone intentionally doing it ๐
Only we two are active on Box lol
i cannot pty to /bin/bash, Maybe that messed with port 9999
maybe
I cannot ping the box lol
lol broke the box
reset lol
Connection Refused , i thinks it again TOS ๐
I did not did anything lol
you did ๐
just did killall -u root
Even I cannot get into the box
My while loop for king.txt is helping me
@glass flare That's a DoS
What's DOS?
@quiet schooner yes he did
killall -u root just kills all the users i think ๐ค
๐คฆ
๐
Read the rules, probably not allowed
I don't know that, Sorry!
Don't run commands if you don't know what they'll do.
now what happen to this completion ?
๐คทโโ๏ธ
if you have to run a command without knowing what it does, it has to be rm -rf / --no-preserve-root on your own system.
sudo rm -rf /* --no-preserve-root, there is an asterisk there ๐ฐ
๐
naah, -r makes it recursive, not the wildcard
Poor VM
hmm
Nope
@quiet schooner Does the asterisk make any difference?
Breadth explained it
I have even tested it on my own box, and re-installed my kali
The difference is shell globbing
oh, so that's what it's called.
It's really useful to learn
it's awesome
Globbing will bite you otherwise
Ah, thank you for informing me, now I will tell people to run rm -rf / --no-preserve-root on their system ๐
lol
... yes. A very important correction :p
@glass flare You aren't the only one. I did a command john typed in stream and accidentally got me banned via a box. :/
it's a big oof
not doing that again for sure
in KOTH it is allowed to deny ssh access for others?
Like adapting the authorized_keys file?
seems like deleting /etc/passwd is allowed, so, sure?
thats the thing, I am never sure what is allowed and what is going too far
yeah, machine botching is kinda vague
and No attacking other users means their systems on the VPN, or their sessions on the box?
seems like killing user processes is ok though
@fair adder depends, you can't kill the services running on the box, only patch
So can we use iptables to only allow my connection for ssh?
firewall rules to stop all communication makes me think not
one probably can't set invalid static routes for the other users too
can one remove the php file with a command injection vuln, or is it expected that the php file is modified so escapeshellcmd() and escapeshellargs() are used instead?
I think you're expected to patch it
Like editing the authorized_keys file
Just quick public service announcement
If you are on a spacejam lobby and someone closes port 3000.
DON'T
RESTART THE BOX
FIND THE OTHER WAYS IN
Why is the host in KOTH so often down for me :/
wdym?
when I try to ping it, or connected via ssh/telnet etc I often get host unreachable/down
sometimes the machine take a long time to boot up
maybe your vpn?
its only on KOTH
and it also kicks you out of everything every 5 minutes?
maybe it gets reset
it does not
its sad that I cannot get a good experience with it this way ๐ฆ Was yesterday and Today with Space Jam and also with Production once
My VM is not even on :dddd
If you are on a spacejam lobby and someone closes port 3000.
@dapper escarp Can you close ports? If so how many?
I believe the only port you can't close is 9999
3000 thousand is a good port if you look hard enough ๐
666 you've done spacejam enough to know
I know, but does that count as a backdoor of some sort because it can be exploit ;/d
spicy meatball game?
why is it taking so long to boot a machine?
37 minutes left and the machine doesn't load up
is it a windows machine?
oh KOTH game machines. Don't know then
did someone grab king and DoS it, @cobalt jackal? Or did it just never boot?
What's the match id?
I'll try again later maybe, if I'm up for it
c:
join in kill of hill with me
Someone broke ssh
Not only ssh a few other services as well.....
@quiet schooner Just wanted to tell you someone broke your machine and pretty much broke all ports, probably used iptables to only allows his ip via ssh
I know, but are we allowed to do the iptables thing?
You're not allowed to do that but it's a free week so if they get banned they'll just come back
You just report the person who did it to
koth@tryhackme.com
and it can be investigated
I might do that but since KoTH is free for a week, they would probably make a new account and start playing again
I might still win, since I still have more points I won
@lusty portal any chance you can reset game 388
think we have an afk in the lobby and I may have borked it
Oh really? Booked the lobby?
Not at my pc atm
Did you sort it?
Ping Ashu if not:)
It's done
anyone free to join in, just practicing for the competition
@woeful sundial I was randomly checking your profile and I see this xD
?
Mwahahah. Thanks so much!

btw our koth machine is taking too long to load
I don't why that happens I can't even ping it
I've been using the kali room, and it seems to work better since I have a pretty bad connection
does anyone have some linux detection evasion resources? it would make koth a bit easier if the entire world couldn't see that I have a shell login
one of the main ways to find someone is by finding the tty they have
if you run /bin/bash for example
you will suddenly have a massive target on your back
or get slapped with a wall of urandom
Brimstone, you seem to be in pretty much every cybersec discord I'm in.
yo this vpn issue is really getting on my nerves
I regend, changed the servers still nothing
how long have you had VPN issues
had issues like 3 weeks ago
@cobalt jackal not sure if you are getting the same problem. Where your scan just fail because they can't see the rhost machine reeE
anyone available to play !
yes
guys joing the KOTH-1 voice channel if you're in the koth lobby. That's why it was made lol
yup
For KOTH do you get a openvpn config to connect to to hit the targets?
Okay, I just got my a$$ handed to me on KotH. Has anyone played Space Jam yet?
@glass flare that was a painful KotH for me. Mind if I ask you some questions?
Spacejam is a relatively easy one lol
find / -perm -u=s -type f 2>/dev/null
king.txt deleted ?
gg
https://tryhackme.com/games/koth/join/8aa3676a7b8ac8fcba0e2dfa
@cobalt jackal its still making on click to join the game even though it ended hours ago?
@wicked tangle Removed you from Monday's competition game
As you're already in another
whats is monday competition game ?
@lusty portal why??
You're already in another game:)
Which One I confused
Tuesday's game:)
Why is that
๐
Are you able to play Tuesday?
Great thanks:)
Pleasure @lusty portal
@gloomy shale bella!
finalmente italiani๐
Hi there.
Kingofthehill starting in 15 minutes: https://tryhackme.com/games/koth/498 feel free to join.
Hi @devout gulch !
hi
@devout gulch gg on food man
thanks
@lusty portal is everything on for next week? "KOTH competition"
cleaned out that email can you please send another one sorry
@woeful sundial did you kill me 
F
i was so close to a flag too
ahaha
@devout gulch @hot remnant do you see the box up?
nope
Well we don't seem to have enough people even playing to reset the box... ๐คฃ ๐คฃ ๐คฃ
if peach answers we should
shoot me inv link, I'll join if you need a reset ๐
huh, one can join games in progress, that's intersting
How do I join the KOTH competition
The link that I received in the email is for the logo competition
If anyone still wants to join, the link is here:
Well we don't seem to have enough people even playing to reset the box... ๐คฃ ๐คฃ ๐คฃ
@woeful sundial I'll update it so the number of resets are based on users playing:)
Wait is John playing koth again? I need to queue up and snipe him again ๐ค
is anybody going to stream the competition?
you are playing vs him
why are you not taking part?
I don't fancy taking part in a "who has the better autopwn" comp
I thought these were different boxes?
it looks like the box is still up after https://tryhackme.com/games/koth/498
that seems odd
did the reset confuse something?
It will be up for 2-3 mins after
ah, ok
skidy fix it so save yourself some AWS credit
boldly assumes skidy has credit and not debt to AWS
i even forgot how i got to skidy account
fml
i did it because i got the flag but i forgot to note how 
the box from 498 is still up it seems
i might have reboot it during the match, might be the cause ? ๐
after the reboot at ~45 minutes in?
nope, it got reset a couple of times after my reboot
If anyone still wants to join, the link is here:
@low whale Thank you!
@lusty portal not to be a jerk, but the box from game 498 is still up. i just want to let you know this looks like a problem
it's been nice, i've had more time to figure out how onushin horked it
i should have removed my scripts from tmp ๐
where are they, i'll remove them for you
:)
i guess, since the box is still up, you can remove them yourself
@lusty portal how do you guys shutdown boxes on timeout? hope it doesn't involve ssh
@devout gulch They're AWS instances. They can be shut down from the backend without actually touching the services on the box
Like pressing the power button on a computer
Expires in 1 minute apparently
Hmm
Should have expired way sooner
Its dead now
@fair adder Thanks for letting me know, will investigate
oooooo
If you reset the box
It adds an hour to the start time
Thats annoying
Dammit skidy
Need to still keep the old expire date
Well, that'll save your kidneys
lol mystery solved ๐
@lusty portal i love a good mystery, a mystery with an ending
What's the bug bounty on here? ๐
Isn't there meant to be at least 1 way kept open for KOTH?
@rancid pewter are you on the box with me?
@fair adder There's definitely a security bug bounty for THM
@flat remnant You're allowed to patch them, but the services can't be stopped
Not with that attitude
You can check by hovering over the flag icon on the flag submission box
closing one port is allowed right?
Generally the accepted guideline is don't shut anything down
As long as there's an entry point you're fine.
^
someone for a question on shrek ?
@rancid pewter is that you in the koth game?
yeah
nice job
Yep, you were really fast
You did a nice job too
how many flags are in food total?
8
@late quest Impressive
today it took me a whole hour to do nothing on food machine
food is one of the easiest
@late quest I think we all do that sometimes, just spent 20m to do a simple SQLi
Watch the spoilers
Sorry
I only have 7 flags, still need to find the last one on Food
what are the hardest machines?
Tyler
one of the ports on tyler is slow as dirt
i got all the flags on that too
Can people in king of the hill just drop down a service?
no
Oreo?
closing the port isn't allowed only patching it but leaving the service open
done with that game
started 30 mins late whoops
that's right I'm Oreo
@steep raptor if you leave other ways in
along with "reset" this needs a "change the box"
With the tag 0xD and god i thought we had lost in the beginning
I deem closing port 3000 patching on space jam
Not really
People only know 3000
If you spend time finding the other two ways in youโre golden
๐๐๐

But even getting King or root flag becomes hard after few minutes because people make it harder
Gotta be fast
Stupid question but how do i connect to an host with a key file?
ssh -i private_ssh_key username@rhost
Nah
the public ssh-key is the one that goes in the authorized_hosts file
If That's what you are asking
@late quest Oh yep thank you
OSCP guy in the background "Try Harder harder.."
Curious to see shrek and finish priv esc on production
Wish You could choose the machine
Hi, I signed up for koth, but I can't participate that day... but I couldn't find where to cancel
does anyone know?
or I don't need to cancel?

@lusty portal
If editing is possible I'd like to tweak mine a bit as well. I looked at my calendar after signing up. 

lol, thank god im not in this 1, tar๐โโ๏ธ autopwn
or I don't need to cancel?
@agile oak please let me know: ben@tryhackme.com
anyone up for koth ?
koth is addicting
haha @gusty cradle patched the privesc even?
@vagrant monolith Yep
Nice
๐
koth is addicting
@vagrant monolith https://tryhackme.com/games/koth/556
The King is catching up:)
haha
I was a bit lucky; @gusty cradle learned me a new trick ๐
im so bad at patching up and disrupting others 
@vagrant monolith ?
I joined another game @gusty cradle and got Tyler again
๐
And you happen to just teach me the hard way you can also just patch the privesc
๐
can i learn it too? ๐
Me too btw @late quest , I'm to focussed on myself
i need to find shrek and production
Yea, those are nice too. I like all the boxes actually
there should be an option to leave for a limited time if you join a ongoing match ๐
@vagrant monolith do you want a tip for the 6th flag ๐
Ohh yeah sure
oh cmon
someone deleted everything in the box
can someone join to reset the box really quick?
they removed the whole cms lol
@late quest do you know who exactly did that?
i was so happy i finally got shrek for the first time
ruined 
@low whale can you do anything?
what exactly do you need?
do you know who exactly?
and by deleted, you mean literally deleted the files?
they could have edited the web server to not show the routes to those pages
would that be against the rules aswell? but ye iirc it was 404 errors on all those resources
Yall would hate doing food with me. First thing that happens is the user pasta gets kill all and user deleted
@late quest mind sending us an email at koth@tryhackme.com
with the game ID and the user you think is doign it
yeah i think it also counted a flag twice
Thought it was koth@pearl glade for complaints?
yess it is @dapper escarp ๐
Hi evryone,
In https://tryhackme.com/games/koth/576 someone killed SSH & HTTPD
my guess is it's the current king, that previously deleted everything in /var/www/
@young walrus yeah this was just submitted by @late quest ^^
@glossy vessel that's sad..
i know, behaviour like that is not tolerated :(
Lol
Hi evryone,
In https://tryhackme.com/games/koth/576 someone killed SSH & HTTPD
@young walrus
Is it a level 1?
I had some weird experience also when a level auto pwnd the whole box in 2 secs
@vagrant monolith no, it's BlackMrx that is playing dirty
i think its lvl 2
sorry guys ๐
that's me
i was just messing around
@late quest @young walrus @vagrant monolith ๐
sorry guys
you should have read rules beforehand
is disabling SSH and HTTPD against the rules ??
@fair adder patching is ok, removing everything is not
then i saw resets and went for SSH and HTTPD disabling
ah i didn't really read the rules !
sorry
anyway i have a game that starts Friday if anyone would like to join
this time i'm gonna play fair
@fair adder You have to keep services running.
^
There's nothing saying you cant enable certain security features in ssh's config ๐
@fair adder thanks for being honest though, you saved me some time having to investigate the machine to find out who was messing around.
i have a question
if you mess up with the ssh private key is it alright ?
why is it always tyler
regening keys is okay
@fair adder I feel ya on that one, we had atleast 2 hours of Production last night
yeah, regenning keys is good. its a method of mitigating an exposed private key
result for
nmap -T4 -sS -A 10.10.141.112
Is Pain supposed to be active? I retrieved a file containing a flag yet the site says there's no flags to collect on the box?
was it from the http?
Nope
oh
The site also says there are no flags to collect. I also got a password but it doesn't work for the given user (That doesn't really mean anything as it could just be a file that exists etc. but yeah) starting to get a bit stumped for ideas at this point
User is implied within the file
well the ones i tried didnt work
that's against the rules
xb8 Idk how you've claimed 5 flags when there's only 4 on the box???
@late quest ^
That's super weird
So my mouse slipped and I might have accidentally joined the above linked game by @spice elm
i already sent an email to koth@pearl glade about it
Colio
Hmm
Is there any way to leave a KOTH game?
Options, top right
There isn't an option to leave?
Someone needs a reminder about Rule 3
he means in a game that already started
https://tryhackme.com/games/koth/598 saving koth id for mods so they can check out the flag this
Yeah this round has been slightly borked as someone was playing with the koth binary and it's stopped recording points
@nimble tangle If you find out who, I think skidy was explicitly banning messing with the service on 9999
Unfortunately the only thing we have to know it was happening was the commands used were in .bash_history and by that point I think most of us were root
looks like you are killing it ๐
Hello
how can u add name in king.txt i am trying for 40 min
deletes ur .vim file
pls tell
chattr
@rancid pewter Something wrong with your submission? :3
Gg
@rancid pewter <3
@lusty portal bby is it too late to sign up to the koth tourny ๐
Optional is scary lol
optional is terrifying
You have nothing to fear but fear itself
doubt
@lusty portal bby is it too late to sign up to the koth tourny ๐
@dapper escarp Nope, can I put you in the wednesday game if you want?
lol, optional vs sherlock, that would be tense to watch
what time?
@dapper escarp Can I be a pain and ask you shoot an email over to ben@tryhackme.com - On my laptop downstairs. It will respond me, unless you wanna ping me later
Yeah no problem man, will send one in a sec
I wonder how many people who are in the 267 forgot they had a comp today ๐
anyone streaming ?
i don't think so
you can watch it live here but thats about it
quick, already 6 flags: o
@rancid pewter God ur scary
Why
ur fast as hell
Ohh yeah
i want your king.c :)
You wont get it
worth asking :)
Yeah
Yes gimmi ur king
Soo good luck I am all setup
lol
tf happened
anyone getting a connection from tyler?
maybe it's me I'm gonna restart
I got stuff
what rank is required to play KOTH?
lol, finally got time to patch :3000 on spacejam
You can pwn space jam much easier than 3000
that's a KEKW right there hahahahahahaha
hello, there is a sql injection in that box or its just nmap false positive?
usually defeats the point of KOTH if ppl give you hints ๐
For some reason, dc is running an event. However, I can't join it
You might havce to change your experience level in your profile
hola!
i got 2nd flag u already got king
๐
1st time
sureeeee
yo!
i call bullshit
yea but on production
there is some limited shell
i tryed so much to break out of it
and i always get locked out of ssh
when i play koth
Again itโs not a forgiving game mode
Gotta be fast to get in through low hanging fruit
i was in
getting in is not the problem
its also not fair when u play against people who already rooted the box 10 times
Sounds like salt
Iโve played a decent amount of these boxes, yet I still get put down by people on their second time
It just depends on your own ability
its not salt
if you know the method how to get root etc and others dont
ofcourse you win
As @dapper escarp mentioned above, Try Harder
The Motto of OffSec
Repetition of a task can translate into proficiency at doing it.
Especially with KOTH - hopefully as more blue team content get's developed, it'll be easier to pickup skills like that ๐
Hell, I made Production and people still beat me on it
I think I could way to put it can be ""Keep Trying". If you don't get it keep looking. Find another way in. And root doesn't mean win. You can defiantly pick that up from snagging other flags and making life difficult for other peeps.
^^
I can echo that. Iโve played these rooms way too much and still get beaten
Usually by crisco as that user is insane
Like, I have the root password that no-one else has and I still get my ass handed to me
Itโs no different to playing csgo or something. You need to expect to lose before you get better
no
Just as an open air question, could I get banned from KOTH for spending my time on the box tripping others up?
And still lose when you are better. ๐คฃ
As long as you follow the rules @rancid cove
I don't think it's to far off from anything in life.
If you don't fail, how will you know what you need to get better at to not fail again?
They're the only stipulations - if you stick within them i.e. not turning services off then tripping others up is part of the gamemode ๐
Since we're using CSGO as an example, I always play games on the highest difficulty possible. I get murdered and frustrated, but it makes me better so that when I do win or finish the task, I know that I overcame the best it could throw at me and I (eventually) came out on top
Shade in all honesty it just sounds like youโre moaning because youโre being beaten
lol
its not that
when u play against people who know how to root the box, and they lock you out of ssh
well production is a box your not coming back on then
but dont worry i wont give up
i will keep trying
im just bad at blue team stuff ๐
if ssh is your only way in, you need to find more
also found some limited shell
you cant escape from
and some backdoor i dont know the pass off
Instead of spoiling the box, 

also
spoiling ?

you make alot of sense
not
Shade
?
Iโm gunna be brutally honest, you have a limited shell. You are limited to 11 chars plus enter
i know
You gave up
There's 4 ways of entry to all the boxes.
Chances are, if you found a a limited shell; there's a way to break out of it or use it for something else.
I haven't personally done that box.
No
lmao
Honestly, he hasn't told me a thing about it.
๐
The only other person that I've told how the 9002 shell works is sp00ky, and that's because he wrote the server script
You can either bruteforce or exfiltrate the pass via another access method
It's not too far down in rockyou tbf
weird
~30k
I could have put it at 1.3 mil, so
im already in
Oh new rotation is out?
@stable narwhal 2 new boxes
who is crisco
why ?
Because they know what they are doing and causes a challenge
guy got king for 36m already
dude
He is beatable
try harder is not gonna do anything
just saying that
im a beginner with koth
its just sounding arrogant
Like just because someone beat you, doesn't mean share it with the world
while i am
Try harder is a state of mind
@desert kernel what box is it anyway?
Both of you play nice
he obvs just knew the way to root
oh wait i think food is the easy root one
Lol if someone is scoring more goals in a football game is that cheating too?
yh ik aha
oh yea


