#koth
1 messages Β· Page 23 of 1
no one was streaming our koth though
it was john hammond
doing his stream that i was watching while waiting for the koth to start
btw mysql was the way you guys were getting in after ssh and ftp closed?
Also was it you who got into my shell? @fair adder
Gotta learn that as well...
The winner is always the one with higher privs thats all im saying
Are the KOTH systems going to be retired as new ones come online? If so, are they going to have a room created?
what?
Also was it you who got into my shell? @fair adder
Gotta learn that as well...
@nova tide That's something I, also, need to get better at
anything i say can be used against me lol
@fair adder lol
@nova tide That's something I, also, need to get better at
@harsh obsidian before today i didnt even knew that was a thing xD
idk if that was anonymous or mydonut but he just came into my shell and started typing: i am in your shell xD
lmfao
its always fun to take over someones shell
i was like wtf XD so just killed that connection and made a new one.. not sure if he came in others as well or not π
That was me
Noice.. Well hopefully will be able to go against all of you one day and give you a tough time
Maybe
maybe
GG till the next time
What ?
i bet 20 on you lol
@primal stag There will be a way to replay them after they're retired. The exact mechanism is being discussed.
and so i lost the 20
@quiet schooner Cool, thanks!
Who is playing?
Doh, need to bring my a game!
very nice
Send a spectator link
Nice donut
Love the nyancat ?
Pretty neat
Nice
yeah I think myDonut won this
Definitely
He patched everything
hmm
Yeah he won
There should be a rule that you cant play the koth in a public match more than once or something... because I had someone get root in like 2 mins
gg
Yeah there needs to been a lot more boxes
I finally found another login rsa but I don't have enough time to get the password
nice
gg @rancid pewter
@rancid pewter gg man
Gg
@winter nest you up for another game?
Sure
Its late here so I might be a little slow
All good
damn, I just shut down my vm...
If its a machine I've done then ill probs hop off
Alright
Of course
I thought you cant shut all services down....
@fair adder can confirm
@quiet schooner
There's an email address on the website to report KoTH rule breaks
Ok thank you

hangman
or I just put the telnet starwars on for them
asciiquarium or fortune | cowsaw could be some decent alternatives
aafire 
Exploit.JO is cheating in the current game too!!!
@fair adder can confirm
@winter nest
He closed all the ports.
Except 9999
Ban hammer?
What does that mean?
Banning them
@plain salmon I think that's allowed, you can close ports just not the flag service
Woah really?! How will we exploit then? The game is useless now.
It's a firewall restriction @stable narwhal
The boxes have several ways in
It's a firewall restriction @stable narwhal
@fair adder that's not allowed but are you sure?
@stable narwhal you need to keep at least one way to get in
and blocking all ports except 9999 blocks all of them
I'm sure
Okay help me out, how can i get in now? π€£
@plain salmon did you try -p- tho?
^
@plain salmon did you try -p- tho?
@grand ember Let me try that thing.
Firewall styles attack isn't allowed so would need to be confirmed
oof joined this game
@forest bloom how did you close the ports?
aah i can't leave D:
I've ran "nmap -Pn -PU -p- <ip>" in my game with the guy and all were closed
What box?
Panda
Panda here too
No clue if this has anything to do with it but panda is vulnerable to some dos attacks
Yeah thatβs not right
What isn't?
Send an email to koth@tryhackme.com with that guys details and the match id and someone will take a look into the logs
Yup, doing that right away.
Panda relies and web/ssh
I may start installing an snmp back foot into boxes and closing all tcp
Think people having to exploit udp would throw them
As most forget it exists
That'd be pretty interesting
May do something in the future
What happened?
oh
Waiting for players
aah in koth 0X1 scares me
hey so i made a thing and if anyone wants to test it/use it it's here :D
https://hacks.computer/kothoverlay/?id=(GAME_ID)
made with stolen css
@dapper escarp how did ur OSCP go
Please if anyone is ever free to tell me how can i wget a command and use it mention me here..
i am trying:
python -m SimpleHTTPServer
wget <myip>:8000/c<ommand>
then chmod +x <command>
tried using ./<command>
<command>
nothing seems to work
the command needs to be statically linked (the libs need to be inside the binary), the libs can differ between systems so it may not work
it is.. inside /usr/bin
and it most likely gets the libraries from /lib or /usr/lib which probably won't be the same on other systems
find/compile a statically linked one
can you describe that a bit more plz
i am getting it from my /usr/bin and putting it in /usr/bin of the box
yes, but it usually won't work because the library files differ between the systems which may cause problems
if you want a binary file that will work no matter the system libs you need a statically compiled one (the binary has the required libraries inside)
how could i find that?
maybe there are some precompiled ones somewhere, idk
lost two koth just because i cant seem to use chattr.. last night against mydonut and one just right now.
had all ways patched, had root and just couldnt change king file
lel
aah cant wait for 20 minutes.. will play after fasting
ok
@fair adder how long till it starts
60 sec @void rivet
what box is it
food
lol no point playing if someone is just gonna mass kick from ssh
@pure beacon
@fair adder no point playin hes just mass closing sessions
kinda cheap to store passwords
lol, dont need to store them. Easy to find
@void rivet There is nothing wrong in storing passwords.
Just 

The KoTH challenges should implement a process that random generates the password each time it boots.
i know the method
how are others suppose to learn??
if they just get kicked from the box every 2 seconds
like i understand if ur learning how to defend
I wont boot you, my bad. Join, i havent patched anything.
Yes that
like i understand if ur learning how to defend
@void rivet
I run no scripts, and i never patch.
well, this game i actually patched my entry
i can fix it if you want to but were not using the same exploit
The KoTH challenges should implement a process that random generates the password each time it boots.
@winter nest flag / credential randomness is in the works - hopefully you'll start to see these sort of behaviours (amongst other fun things) within the next set of rotation or so!
into root
@brazen cloud Thats great to hear!
The pools are rapidly expanding, I mean it grew from like 3 boxes to 7 within not even weeks so...
But yeah there's some fun things in pipeline for it all π
Any thing you can hint to us? @brazen cloud
Hopefully sooner then later, I don't know enough to give an exact time stamp
I think randomness is the biggest changer, the other stuff is just little things to keep you busy :))
Chattr should also be taken completely off the Linux Machines
No
I feel like its caused more harm than good to the platfrom
apex u wanna play??
I think the better question is why should it be banned? It's an essential part of the patching process.
^^
@pure beacon really dude
so you are the one restricting people from accessing the machine thru ssh
Ok. Someone gets root and the first thing they do is chattr the king file then either delete the chattr binary or move it where it cant be found. Now when I come along I have to have a precompiled binary ready to match that specific machine and if not then I guess i'm outta luck? @gusty cradle


Sounds like you already know how to fix that problem. @winter nest
@winter nest Statically linked chattr binary
^^^
How so @gusty cradle ? I copy the binary from my kali machine? Nope
^
I know how to move the file.... thats not the issue
Its the binary itself. Once I bring the binary over it wont work because it isn't precompiled for that system.
@fair adder @gusty cradle
Statically compiled binaries are designed to just be able to be put onto any system
^
cant use any cheese strats on prod can u xD all my scripts have got me kicked of the box XD

@gusty cradle May I message you or @fair adder
grrrrrr @weary kindle
xD
luckily i completely locked it all of
before i got booted
xD
now i know that @pure beacon is the dirtiest player out there
yep lol
but in his defence
he is probs learning how to defend
which is fair enough
end of the day, i kinda over reacted, this is to help u learn shit
and if he is trying to learn to defend
then fair enough
its not fair if hes breaking the ToS
oh is he??
What was he doing?
preventing access thru ssh
Probably shutting down services
like i cant even connect to host but i can ping it
You can shut services
preventing access thru ssh
@fair adder
Just have to leave other ways in
You need to keep all production services running
thats not what the ToS says
We'll be clarifying rules in a bit
Shutting down services is against the rules @stable narwhal
Ah I thought it was just the king service that was restricted as long as you left another way in
he knows i'll beat him if didnt shut down ssh
The disrespect
saucy
instead of shutting it down, just set it to another binary lel
The d i s r e s p e c t
Regardless, we'll be clarifying the total verbiage around this
I see it going down like this @void rivet
If I win I keep my name, if I lose I ban you and keep my name 
we shall have an option to restrict users like @pure beacon to play with certain users due to his lack of knowledge of KOTH ToS
ooof
When should we expect to hear something @mellow bough
Oofy
soon TM
So never^
People are also creating scripts to hack the machines faster...
autopwn
lol
i want to make one for prod but i dont want @weary kindle to hurt me
Maybe just before you join your first koth game, have a mandatory ToS pop-up @mellow bough
People are also creating scripts to hack the machines faster...
@winter nest This won't be so much an issue in our new releases of KoTH (some changes are being made to the game-mode).
And keep the rules up top instead of on bottom
its not against ToS to use your own scripts
OOOOOOOo That would be lovely
Unfortunately
But it's impossible to detect anyway
as long you dont restrict or shut down service like @pure beacon is doing then you should be good
9002 was made to be scripted btw
If you suspect breaking of the ToS, email koth@tryhackme.com with the match id and player username(s) is always the best for the time being!
we shall have like a voting system once someone is in a party to play koth and the players who gets more kick votes then duhh they get kicked
Mhm I don't think necessary
^
well if we know he gonna cheat and ruin the fun for everyone then why not?
Because than that player.may not be able to find a game again
Like skidy suggested and I mentioned, there's some pretty good changes coming to koth where scripting and just rooting the box instantly will be much much harder to do
:^
It's also real BM'ing which is just toxic
Maybe Add a chat box, like twitch one, where players could talk, So atleast they can all agree if they want to reset the machine.
Also what is kinda annoying in KoTH if we are talking feedback.... If there is 3 people in a match and one person gets root and they block all the ports or do something against ToS then the vote to reset should be 2/2
It's best to let the admins investigate issues regarding rule breaking rather then just exiling members
The point is that is should change based on the amount of users
I think that's better left to the staff to make those decisions, not players that can abuse it
^
The vote change is coming iirc
There's a thing called beta written near King Of The Hill. Cool down.
Koth is still a new thing so π lots of stuff in the works for it!
Yeah I know
well koth is going to get slammed with a lot of cheaters so
all im saying for cheaters that break the ToS should have a system where if they cheat then they get restrict
not banned
well koth is going to get slammed with a lot of cheaters so
@fair adder We hopefully have a system that will reduce this. I'll write a post to let you all know whats changing with KoTH.
@fair adder We hopefully have a system that will reduce this. I'll write a post to let you all know whats changing with KoTH.
@lusty portal ETA?
@stiff egret no rush
Thanks for the feedback though.
all we can do is report the user and thats it
and obviously koth prime, thm needs to make money π°
Yeah the feed back is nice
but thats not gonna stop the cheaters from creating new accounts
they dont care about trust
Anti-cheat is incredibly hard to implement on a KOTH box tho
look at @pure beacon
and obviously koth prime, thm needs to make money π°
@grand ember We're making KoTH free to play.. forever

YAAAAY THIS IS AWESOME
nice
@lusty portal, what happens if a box is sent a shutdown signal? Does it reset?

@grand ember We're making KoTH free to play.. forever
@lusty portal You kidding right?
oh boy
Nope:)
ig its over for the learners out there
π₯³
@lusty portal, what happens if a box is sent a shutdown signal? Does it reset?
@terse willow Do you mean when a machine is reset?
Koth was always intended to be a subscriber service
One of the few marketing points of subscribing was koth
@terse willow Do you mean when a machine is reset?
@lusty portal As in, if we were to set up monitoring as a process on the box that tells the box to reboot if something is switched off, or something doesn't look right -- would the reboot make it reset, or would it mess everything up?
There will be a good reason for subscribing:) More info to follow
There already are good reasons for subscribing
oh yeah
then there will be mroe
there is but y'know what I mean π
@lusty portal As in, if we were to set up monitoring as a process on the box that tells the box to reboot if something is switched off, or something doesn't look right -- would the reboot make it reset, or would it mess everything up?
@terse willow No, we terminate the machine, then redeploy it from the base-image. You could include measures to help stop it happening, but if you're root, its very difficult to stop
@lusty portal I was thinking, if the website had a capability to receive an "Ok" message from the box, it could be reset automatically. As in, the box checks itself every minute to make sure that no rules have been broken. If something is wrong (or if the process is killed) the box gets reset
Other than heavily abstracting the box across several docker containers, you can't have anti-cheat running on a box where you're supposed to get root. Hell, there's not even fully defined rules yet, so I have no idea why you keep banging on about cheaters. I'm willing to be that these so called "cheaters" you're coming across just know their defense, same reason as to why when someone closes off all the easy vulns everyone cries and resets
I mean, it's already watching out for the king.txt, would it be so difficult to implement?
@lusty portal I was thinking, if the website had a capability to receive an "Ok" message from the box, it could be reset automatically. As in, the box checks itself every minute to make sure that no rules have been broken. If something is wrong (or if the process is killed) the box gets reset
@terse willow Like The services in A/D matches.
I mean, it's already watching out for the king.txt, would it be so difficult to implement?
@terse willow I can implement it box side if Skidy can implement it server side
@weary kindle I mean, I'm pretty sure you're not supposed to be compromising the services on the box, although I do otherwise agree
It just can't be 100% trusted
Mhm -- it would be really easy to implement box side
@winter nest This won't be so much an issue in our new releases of KoTH (some changes are being made to the game-mode).
@lusty portal Challenge accepted.
I'm not sure how you would get around it, to be honest. If it was working on the same principles as OTPs, you couldn't really replace the process, and shutting it down would mean a reset anyway π€·ββοΈ
Interrupting the checks and still convincing the process to send out the "Ok" message would be interesting
Although I daresay someone might figure out a way
It's not something that's 100% achievable unless there's a hypervisor, and that's a challenge in of it's self with AWS
Seeing as instances that support nested virtualization are 10x the price
AWS is half the fun 
True, there would definitely be more efficient ways of doing it than "in-box"
what do you mean shut down service @fair adder
But there's no reason a process on the machine couldn't be checking to ensure that it's getting the right output for open ports, for example
Or checking to see that essential processes haven't been killed
maybe some cut-down autopwns just to check the entrypoints each few minutes?
defo don't see why a "health check" isn't possible I mean - there's literal systems for it so...
but as Dan said, it can't be 100% trusted if it's in-box
Agreed. I mean, I don't even see it being totally necessary, but it might help π€·ββοΈ
if server-side done that sort of health checking it'll be a lot more authentic
I think a robust anti-cheat system would need dedicated, THM owned infrastructure to work properly, and that's a bad move for them to work towards
10000%
AWS is at least 25% of THM's success I'd say
will get very expensive at that too
There's a reason HTB charges what they do for their pro labs
^^
@fair adder Why are you saying im in breach of TOS? i read the rules and i abide by them
Guess who's finally upgrading to pro on Thursday!
Feelin targeted today 
π§

I havent even shut down ssh? wtf
these accusations man
The rules doesnt even specify that i cant shutdown services? not that i do
The machine should not be made unavailable (shutdown, firewall rules to stop all communication, all services terminated, machine botching etc..)
The machine should not be made unavailable, which i havent done
ive never messed with the firewall
i have never stopped ALL services, yes i have deleted some authorized_keys files, and kicked a few shells, but that isnt against the rules
@lilac lantern you done that too mee so wym?
oofff
you're a n00b so wym
come on bois
This is just getting petty now haha
^
Bordering Rule 2 and 4 tbf
We good, he's in discord with me.
Ah fairs
But the rules are not specifying what can and cannot be done
thats how we fk around @stable narwhal
@pure beacon sure we'll see about that once they see the logs
Admin can check logs
At this point you all are just playing sematics.....
YOU SURE???
I think so?
@lusty portal can you confirm?
Well that doesn't necessarily mean that the kind of behaviour should spill into here as @stable narwhal suggested imho
YOU'RE ALLBITCHING ABOUT BEING PATCHED
Admin can inspect logs of the games yes
Grow up π
If you wanna be fair why not keep the service running but change the port number....
and absolutely do
O_o
@winter nest Thats meaner lol
Not really
That's enough from the lot of you. Tone it back please π
Keep it civil my dudes.
@lilac lantern can I quickly remind you of the PG-13 rule
Thanks for the reminder
oooo
can i remind u all that im eating a original curry pot noodle rn
Sounds nice tbh
That sounds delightful
it is
Indeed
it really is
I have a strongbow dark fruits
solid pot noodle choice
thats what she said
i got a full cupboard of pot noodle
Ayyyy
i never remember
π
π€¦
hahaaa
Can the 3 of you make a private chat to have your little spat please?
Nah I'm good
ok everyone thats here what box was the first hardest you've ever encountered?
when is the next new box coming out
food
@stable narwhal was that a box?
i mean, imma say pain cause i havent tried pain yt
Pain is easy
KOTH specific or in THM?
Multimaster from HackTheBox was pretty difficult to solve
koth I would assume
koth specific
Multimaster from HTB was pretty hard
@gusty cradle what she said
Oi
@lilac lantern :mad:
@lilac lantern again PG-13
^^
What. How is that not pg-13
Put it this way, would you say it to a school teacher?
ye
I've had kids younger than 12 saying the F bomb mate
ok guys only boxes that you've already done on KOTH only
yes I have
100%
from hardest to easiest
"that's what she said" is obviously an intended innuendo
ok maybe the other way:
should you say this to a teacher
No nsfw references @lilac lantern
Okokok bbz
"that's what she said" is obviously an intended innuendo
@stable narwhal pg 13 pls
I'm sorry β€οΈ
Or innuendos
I've had kids younger than 12 saying the F bomb mate
@lilac lantern That is not the point. We know children swear a lot
ffs
Language dude.
^
^
for free souls
I haven't sworn π
It's just stirring the pot at this point...
JESUS
ok name your boxes from easy to hard everyone
damn do emojis count towards pg-13?

change subject now
^^
Need more windows ones
New Koth boxes will be out at the start of the month
for sure
tomorrow
@fair adder where did you hear that
in my dreams
lmao Para
Not with that attitude
It might be now he said it
Not with that attitude
@fair adder That;s just antagonising
Wait, we're releasing them tomorrow?
Stop
Koth boxes will likely come out the first week of May
I best get started then 
I mean, that should be one of them at 20% conversion.
@weary kindle hehe
Shoulda been called Jammy @terse willow
Not exactly ready to come out yet π
I still need to make my windows box
it should of been called @lilac lantern
quick Optional's asleep release koth boxes 
quick Optional's asleep release koth boxes
@brazen cloud Finally get the upper-hand
@brazen cloud optional keeps one eye open and never sleeps
@brazen cloud Nah check the mentors lounge
He has koth notification hard wired into his alarm
LMAO
or it should of been called @pure beacon
brain-koth interface 
@fair adder dude stop antagonising...
π
Then everyone here is in dire danger of getting a mute...
Dispel the tension, put a filter in between brain and keyboard. Don't send anything that's likely to annoy or antagonise people
It's really that simple
@fair adder a community mentor, and ones who recommendation I will fully take if he says to mute/ban you
just a THM user mate
That, for the record, is a prime example of antagonistic
Enough @lilac lantern
That's a warning now -- you've been told a few times
You would be wise to quit while your ahead @lilac lantern
So I'm not entitled to an opinion anymore? Man this place was cool at the start of the year.
For those that I have offended I am sorry, but if you can't take a little light hearted banter then I do apologise.
Reasonable enough?
You could litterally not do a simple apology without adding a snarky remark
sighs
And for those that have an issue, please.. Do join voice channel.
they dont want your apology
Enough!
If you see that as snarky then that's your misinterpretation
Please just ban him already....
Done.
Not too sure if this is a message for #544951750801752079, from the previous convo someone mentioned about learning and getting started with KOTH, would it be beneficial to have KOTH categories such as New/Chilled -> Experienced/Go Hard - Similar to profile levels
I think there was talk about that @stable narwhal
I would agree for that
Yeah I remember talks about it - scaling with your profile level but wasn't quite sure where it ended up. Definitely a nice idea!
But how would one define easy etc?
Different people are good with different styles of hacking
I for instance hate WEB.
Most of the time, I don't think Profile Ranks correlate to KOTH ability, it may be nice to have for new-comers to have an enjoyable environment to get comfortable with new boxes etc...
Easy attack vectors with clear path to execution
I think you'd find that'd create more subcategories than anything
compared to harder boxes that are more obscure to root
Easy attack vectors with clear path to execution
@dapper escarp This and other players
binex to get root 
Isn/t that what private rooms are for?
Most of the time, I don't think Profile Ranks correlate to KOTH ability, it may be nice to have for new-comers to have an enjoyable environment to get comfortable with new boxes etc...
@stable narwhal
request that newbies join a private game etc?
But even newbies on THM could be pen testers in real life so
Heap overflow for foothold and root π
It's hard to differentiate between the skill levels.
But even newbies on THM could be pen testers in real life so
@lilac lantern "I don't think Profile Ranks correlate to KOTH ability"
Heap overflow for foothold and root π
@gusty cradle Nah, heap overflow for foothold and n-day exploit for root.
Heap overflow for foothold and root π
@gusty cradle who hurt you?
π
You have a sick sense of humor but I like that about you @gusty cradle
lol
Egghunter, @dapper escarp will love it...
@lilac lantern "I don't think Profile Ranks correlate to KOTH ability"
@stable narwhal Slightly snarky but I'll let it pass. But doesn't that dismiss the whole KOTH subject?
@gusty cradle is a madlad
You have no idea whoo you're up against
Mhm yeah I somewhat agree
It's not wrong
just die
@dapper escarp Didn't you said "They're not that bad" few days ago lol.
the statement holds a lot of weight, no one knows how they will react when suddenly they are being shell killed or spawned into a terminal parrot
I know for a fact if I join a room with @dapper escarp I'm leaving
It's a fine mix between being put up against someone whose better then you, then someone whose waaaaaaay better
ayye @dapper escarp wassupp
You have no idea whoo you're up against
@lilac lantern Why I put it here first for discussion rather straight to Ideas
heap exploits are horrible
I agree.
The thing is, now people are making automated scripts
for these rooms
So that';s you screwed anyway
You don't learn if you're against people of the same skill, but also don't learn if you're against someone who can root it in 5 because they're just very good
agreed
I mean
Heap overflow on windows box @dapper escarp
How do you define the fine line?
I get called out for scripting when I don't use them
and usually have proof of that xD
Just memorise the box
^^
And do what you need.
:nice @dapper escarp yes that was me my Bad GG 
Certainly worth a discussion as @stable narwhal suggested. Perhaps it'll sort itself out kinda once the new features are being implemented
We do, so we know how to get king asap
OR those that watch peoples streams know the rooms
So newbies technically but are fully aware of the entry points
@brazen cloud whoo, basically suggesting it because that's how I feel when playing lmao
I'm working on a new implementation with random everything, it just takes a lot of time to develop alongside everything else
yeah totally! @stable narwhal
Plus Runescape has cost me at least 5 days in the past week

Oh god still on that RS hype π
people who watch my streams don't know the rooms
never left π
they just know my preferred exploit path
people who watch my streams don't know the rooms
@dapper escarp Can confirm haha
Man I talked to you guys like january you were hard on that hype
we don't watch the streams for koth/boxes, we just bully him 
which is usually ssh through a memorised password into a low hanging priv esc
Hype train stops for no man nor woman
@dapper escarp Can confirm haha
@stable narwhal I could search the stream right now and learn the way in
I mean at this point I don't play koth as the only boxes that interest me are offline and tyler
I'm there for the poki dono's
Learn a way in
You'd be hard pushed, again I only get shrek/space jam on stream
then watch 4 other people
It's just my 2 cents is all guys
or in the chance I recognise someone who autopwns I whip out my pwn
Bearing in mind we put about 3-5 initials in each box and most people only ever use one
yeah totally @lilac lantern π valid points nontheless!
I think the only time people may have learnt a box is when I did panda for the first time
because I literally hunted for all possible ways in and their priv escs
I'm one of those, okay .. Good idea, but what about this, this and this etc. Always think outside the box (no pun intended)
I wish there was a way to submit boxes to be used in KoTH
There is....
@winter nest contact one of the admins
oof
I'm still working on my first box
I dont have a box ready, but would love to make one
'Serve me the shell
but my upload failed 4 times
So I gave up
Will re-do probably next month
New machine coming.
I assume if I make a box then I'll make mutliple initial entries and multiple priv esc.
yes
like 3 to 5?
If possible, multiple entries are the way forward
But, please make sure it's tested all the way then ask others to test too
Mine only has one way atm
Due to the nature of the exploit
I can't quite remember the stipulations for KOTH box development
If you remember send them to me
@winter nest At least 4 entry points, 4 privescs and 4 flags
Admins have to approve an initial plan for it
There's a lot more guidelines that help make it fun and replayable
poki worship koth room inc π
kekw
Wasn't that Pain?
@quiet schooner how so
give them an inch they'll take a mile
@winter nest avoiding passwords etc as once you've played the box you can record those for next timw
(Or autogen them -- which is what mine is doing)
Yeah I figured
he needs to make an entire room dedicated to her :Kappa:
@grand ember you best know when that dono goal hits we doing the "HELP POKI FIND HER FEET" room
for the memes
yeah lmao
@grand ember you best know when that dono goal hits we doing the "HELP POKI FIND HER FEET" room
@dapper escarp You need help haha
It's changed you
well you did this to chat and then chat did this to you 300 times
yeah I get shafted by it every stream now
Gesus is usually one of the first saying "poki"
KOTH stream tonight?
+1
:pokiW:
inoculation, not koth
keep going back and reediting it as I finish each box
it is inoculation before koth tbh
Oh of course, the report
If I get it done at around 7 I'll likely stream after
but won't be anything official
Ayy
might just chill and watch poki
it is inoculation before koth tbh
@dapper escarp A cheeky 60 points
Needs to be more
Could have a point multiplier per flag based on difficulty - Extra points work too
x1.5 medium x2.5 hard
Yeah something like that
would be hard to balance
and require striker reviews of rooms to determine difficulty
Also just using the bonus points system would do it
Also just using the bonus points system would do it
@quiet schooner not all harder rooms have extra points though
people vote for difficulty -> average difficulty * fixed point amount
my suggestion
Inoculation being the best example
Yeah but using the extra points system
Yeah, easiest way to do it
bonus points are a poorly implemented system
flat multipliers on difficulty would be easier implementation
Borderlands was ridiculous
optional how was ur OSCP
can you join and vote reset please?
they are trolling us lol
And by that you mean, what, exactly @vale summit?
we was just playing xD
Unless they're breaking the rules, that ain't enough for a reset
https://busybox.net/downloads/binaries/
@dapper escarp i have been looking for those for like 2 days now. Thanks
I gotchu
heres some more useful binaries as well!
Reset? and start again?
@lusty portal any idea when thm is gonna have merch??
i wanna buy some when i get paid aha
A swag shop is coming out soon @void rivet
Goood
reset? @stiff egret
m bad with panda
oh ok
this is my first machine of panda
if anyone of you knows about port 3306 and have spare time anytime teach me β€οΈ
The best friend after books is google.
~ Mr.Holmes
3306? That's a mysql port?
3306? That's a mysql port?
@dapper escarp No its where the webpages load π
3306 is default mysql and without looking at a scan would be a default guess
[pun was intended]
@nova tide https://tryhackme.com/room/25daysofchristmas
3306? That's a mysql port?
@dapper escarp it is
@nova tide https://tryhackme.com/room/25daysofchristmas
@quiet schooner have that on pending.. doing koth since a couple of days.. started it and then paused
There's content in there for mysql
https://www.sololearn.com/Course/SQL/
using that as well
you shared that last night
oh ok
i will do that one for sure then.. after fasting
how do you guys go about getting the flags?
Good luck
Cheers pal, you too. Go easy on me π
Let me finish my new script ...
..
@lilac lantern Did it work ?
I cannot swear here.
#Leaving
gg wp
Mate everything is automated on scripts man what's the point π
What ?
You've used a script yeah?
Let me finish my new script ...
@rancid pewter I assume this message
π€
But to prank people it a script
You can get really fast on some KoTH boxes
I know, got all flags and king in 7 minutes π
wish I had a physical VM of kali
rather than teamviewerd on
or a physical kali machine lool
Considering I manage the devices.
that's even worse
Then you can get admin
Nope, not allowed to install any applications at all.
Use that work money, get yourself a cheap thinkpad or something
"Everything is temp" is just a metaphor for life.
ryzen 5 2600X, 32 gb ram etc etc
still not a good security practice to put VMs on your work laptop π
Therre is no VM on my work lapptop
it's just a statement not relating to you directly, i'm just saying it's not a good idea
Meh fair enough.
LOVE that you can start a new game before your other one ends.
Kinda funny π
You can play a few at once
^^
gg
Can't wait till the swagshop comes out
no one playing koth?
gg @harsh obsidian I fell asleep after like 20 minutes π
anyone up for a game
@void rivet You playing?
yh but im already in 2 game aha
haha
ill send u a message when im done
βοΈ
which box?
prod
i dont like doing it
cause ik it
and ik not to use any cheesy scripts on this box cause it just boots u out lol
i was trying somehow to find how it knows about cheese and disable that
im looking thorugh it now
completely locked hte machine off
so no one can get on it
so im just freely looking around
lol
i just took a look inside chattr, u can delete the text inside that kicks u out
yh exactly
im currently in 2 prod games
feels bad man
locked everyone out of both of them
lol
I get root, then set up a monitor system, so if I see really good players in lobby then I use defences, otherwise, most of the time, It's them trying to fight against my scripting skills.. @void rivet
aha yh
like i just got the box tyler
got king and completely locked the box
now i just sit back
wait for my next game
ππ
See, we are actually supposed to do that, but now it feels bad considering if others are tryin to learn.
but if u know how to do everything and ur locking the box for no reason
Actions Justified
then ur just saddddd
That's pointless
i probs use it 1 or 2 times, while im getting rid of keys and passwords
Lmao
xD
Did you got nyaned by myDonut?
i havent played with him yet
That was a hell of a close fight.
Beaware
If he's in lobby, shit's about to get real
No mercy
oh lol
Yeah
oof
No wifi since lockdown
Set it lower, I'll be able to watch next time, I said same to optional
@void rivet Serviceman won't come.
Sed_lyf
oof
im just happy my wifi is working
i have data
but that only goes so far
i got 25GB data
im just happy my wifi is working
@void rivet you should be
Bc I know how painful it is
Anyway, try setting the video quality to optional
Edit yes if that's the patch. Delete no. If it's food, that's a really terrible patch. @void rivet
almost done with all rooms except pain and production.. in pain just got 3 flags and in production tried alone game just got all flags couldnt privesc so gave up.
3 minutes left to start if someone wants to join in ^^^
pain it is ^^^
nice work @nova tide
i am late i was doing pain as well
xD
nice one changing lsattr
i wonder if its a while loop running thhat i cant seem to find
who is b3y0nd in my koth queue
@spice crown he is beyond your reach lmao
niceeeee
nice one changing lsattr
@nova tide didnt
i wonder if its a while loop running thhat i cant seem to find
@nova tide neither
well wasnt able to use it unless replaced it
nice idea btw
who have that python script running?
@nova tide Not me
come back?