#koth
1 messages Β· Page 25 of 1
@fair adder yea not having much luck π
Game N.o 1799,1801,1802,1803 All Tyler Lmao
oooof
1800 didnt started or that would have been also tyler
@fair adder share invite link?
@novel grotto ^^^
im in 1801 mate . its ongoing. not sure can u invite whilst going?
alr wonna play after you eat
okay just tag me so i know
ok
gg well atleast i got some points. not bad for a complete guess mess
ok
@nova tide are you guys in game?
Im in bed lmfao
@nova tide are you guys in game?
@near sphinx completed. Wanna start new one? @fair adder
@near sphinx playing alone?
currently in game right now
yeah me too
ahan
Just got the new machine(Fortune)!
Enjoy π
@terse willow I have foothold but still no flag, interesting box so far
Hehe, wait until you play it again before you say that...
That box will never be the same twice..
You can autopwn it -- I've got one for it, just to see if I could do it. Not that I would ever use it
But it won't be easy. The passwords and keys all autogen, as does the easiest privesc
Make them all like this!
Hopefully flag autogen will be implemented site side soon asw
@stiff egret Hehe, soon
I've challenged myself for my next one
I want to be able to upload a script to an empty box
And autogen everything other than the flags
(Unless the site support for autogenned flags is out by then)
@full grove what was that script you used for the AD Forest?
badblood
BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world....
BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world....
Ah
@terse willow So will the vulnerabilities be different each time?
In Fortune?
Only one of the privescs (the easiest one)
The one I've got planned it'll be a little more diverse
(I.e. it'll be different each time, but still selected from a pool of possible vulnerabilities)
But full autogens are something that Dan is working on, so I'll leave that to him
@stiff egret the next KoTH box also has randomised passwords etc.
@stiff egret the next KoTH box also has randomised passwords etc.
@quiet schooner I am loving it more and more every second!
I doubt random passwords and flags would change anything, a good auto-pwn could still manage to work.
I made flag randomization with KoTH as a test bed, more so wanting it to be a sitewide rollout
So normal rooms also having random flags
π€
KoTH also needs it, but it should be an easy port
When playing a koth game today someone made it so that noone could change the king.txt file is this considered against the rules?
Its just using the chattr binary, look into it
When playing a koth game today someone made it so that noone could change the king.txt file is this considered against the rules?
@winged charm happened with me as well when i started koth as a newbie, you gotta look up for chattr and how to get binaries from your machine to the other one
I will didnt know you could do that ill look into it thanks
is there going to be a new competition this month?
come come babies
@primal stag
Well that's a bug
yeah ik π
here if anybody wants to play
gg @primal stag https://tryhackme.com/games/koth/1861
i hadn't played fortune before. that's a fun box
gg
@primal stag You played fortune?
Yea, I got distracted with something else π
this is gonna take forever
sup bois
sup?
im xal3xhx
haha
ive been having hella bad connection for some reason so this will be interesting
I hope this is fortune, never got it once
this is my my first real attempt, so ive never gotten any π
Nice @stiff egret
Thanks, Took hell of a time
I thought I had it locked down pretty well π
Oh man, I almost lost hope
@here anyone want to play agsint the new room?
You can't use that tag
Well, it looks like it worked.
It didn't mention anyone.
Eh, oh well. Got a game going up.
I don't care. It won't fire if noone else joins.
probabbly the same knowledge you are using to vulnerable CTF boxes
but right now public boxes is hard to play because machines are known to many
if you have a friends or others who have not played, it will be most interesting to play with them
There are a bunch of new machines
So actually itβs a great time to jump on
A lot of more experienced users got bored so itβs quite fair
go ez on me @primal stag
any clues on where to look for flags in koth! (in general)
most likely every user (may) have one and root have one
and find the remaining on the machine
you can use find command grep or any other possible ones or look into the machine on your own
I haven't blocked the way in, no need to reset!
i don't know that!
You could have asked π
In π
in, but only if it's a good one
KOTH boxes are like dogs, they're all good boys!
Nice @brave pilot
Ok, how'd you f' up the kingserver?
So the king service is messed up, I tried to fix it... should probably reset this box.
@fair adder @novel grotto @brave pilot ?
ty
gg!
@primal stag gg, i had to step away part of the way though :(


@primal stag: really? all flags + rooting a koth box in less than 1 minute? do you have any reason why we should not report you? :v
haha no messing about
@primal stag Autopwn scripts are banned, if you're found to have used a script, you'll be banned from playing (we have our own internal logs we can check).
π
can you invite friends to play a private koth game, even if they arent subscribed?
Yes:)
oh
Its free to play
lets go
Glad to see the new update and plenty of new boxes now to play with!
@lusty portal can I PM you?
@lusty portal can I PM you?
@primal stag Yes please
Glad to see the new update and plenty of new boxes now to play with!
@nimble tangle We're releasing 4-5 new machines every month:)
@lusty portal Nice! I'll have to get back into it a bit more
https://tryhackme.com/games/koth/join/e2559774f044bffcbba067aa
9 minutes to go!
@primal stag naughtyyyy
@void rivet but i thought i was naughty π’
when it gonna update? the invite links still make you join the game even after completed
share invite link here?
I'll play π
hello there
gg
gg indeed π
gg bois
Anyone want to play Hackers?
Can anyone please clarify Point number 6 in KOTH rules?
We are in same machine when in same lobby, So I don't understand.
OHK
Their machine as in their main pc?
As in the machine they're connected to the VPN with.
As in the machine they're connected to the VPN with.
@quiet schooner Ah,Okayyy. UNDERSTOOD.
I'll play @fair adder
okay
koth
here
koth
I've got some practicing to go before I can do any good in a koth π half the time I forget the syntax for the tools I'm using
Step 1: Get root
Step 2: Take notes, and repeat.
Step 3: Write a script.
yeah, skip step 3
I need to find a group, because I'll definitely learn some tips & tricks if possible π.
@primal stag jeez this room is hard
It took me a few tries to get it
@fair adder What box?
It's a good one, I like to battle over king on windows π
i truly don't understand the room
Machine: Offline
@primal stag You played hackers yet?
Not yet..
wow you wrrecked it
It's still wide open.
fr i was expecting easyer room π
curl: (7) Failed to connect to 10.10.80.239 port 9999: Connection refused something's up with this room now :(
I can't even ping the server any longer.
Offline?
Someone popped EB on it I bet
EB?
haha,
Eternal blue(screen)
you too @fair adder
did you figure it out from your terminal session?
i see you got malwarebytes on there, nice
Thats what is calling the bluescreen.
π€£ Are you lot adding anti-virus to the Windows machines to keep people out?
@terse willow It comes with MB
Ah, fair enough. Whole different world
Interesting technique to consider....
that would be lol
Muirland if someone added mb onto the box, all the fucking power to them lmao
Did wonder π
@full grove Thought it already had it?
it does lol
Sure, Poker?
I've never tried it so I'd be down π as long as you go easy
Muri is Saw
(These, for the record, are not randomly picked -- take the hints wisely)
You should see Monkshood James...
It's shaping up really evilly
Chess seems a little unrelated
does someone wanna do a "learning" koth with me? I'd like to give it a go to see how it is and how I'd do. I can join voice chat so if I have any questions I can ask π
Nice
I would appreciate it though so I could leave and join you.
or neo you could join too and we can hop in VC
i have a invitation Link I think
@fair adder
I can't join VC right now but you can definitely dm me
any tips on space jam
I have few questions about koth rules
for "7. Scripts that automatically hack and/or harden the machine are forbidden" - What if i will create some kind of rootkit which will maintain my access in system, its including to this rule ?
What about killing other users process (reverse shells, scripts) ?
Changing for example address,port for service is legal ?
What about automated script which will overwirte king.txt with my username ?
What about chaning permission with chattr ?
What about chaning programs names (for example chaning bash name) ?
This one isn't about rules
All machines have same number of flags ? If no how i can check that I got all flags ?
the machines have different numbers of flags @jovial dune . When you hover over the flag icon next to the flag submisison box, it tells you the number of flags on the box
unofficially, it seems like rootkits for persistence, killing other user processes and automating overriding king.txt is ok
- Rootkits, we have no official stance on yet. I know one person in particular is working on one lol
- Traditionally, that's been okay
- the goal is to patch the vulnerabilities, if you want to take the security through obscurity method, I'm sure that's fine as long as the services remain up.
- That's fine
- That's fine
- I'd stray away from stuff like shells because that may be considered a dos, but cat and other binaries, traditionally that's been okay. Just remember to not turn the box into a DoS state
wait, so it's ok to move sshd to a different port?
as long as the service is online, I see no issue with it
I'd run it by higher powers to verify, but I think it's a fair mitigation method seeing as all someone needs to do is re-nmap the box
So no closing ports? not even a single like ssh,ftp,mysql etc?
iirc the only time its acceptable is if the service cannot be patched
i.e. Limited shell in Prod
what about space jam 3000?
change the variable
ohk
make people fuzz for it
or if you really wanted to be evil
drop someone into a container lol
start a honeypot on 22 
still trying to learn mysql so can get in or patch it
btw we can run simple bash/python scripts right? like on king.txt?
yes
no autopwn,no closing services thats all the new rules, right?
while True:
do echo "Naughty" > /root/king.txt
done
^^ yup
100% okay
chattr...
go for it
yeah one more thing once i deleted check.sh( i think that was the name) from shrek that wont let anybody ssh in into shrek even using key or the pass and even delays the time to ssh in with donkey as well.
or should i simply rewrite it instead of deleting it?
Not sure what check.sh does tbh
basically
if you're making a service inaccessible to anyone
it's a no-no
@gusty cradle this is what i deleted that wouldn't let you ssh in that day
if you can access it, then you're fine
because with ssh you can do some super strict filtering and that's fine
@nova tide I see, I was wondering why I couldn't ssh in π€
well it just stops the person using the id_rsa that they received
Also couldn't ssh in as donkey
well i changed the pass for donkey, not sure if there was any other way in
tomcat
I thought you got www-data?
but thats all i did that was causing all the issue with ssh, so wanted to make sure if its against the rules
I see no issue with ssh-keygen and rm -f ~/.ssh/authorized_keys
that's basically the same effect
same with changing password
anybody down to play in 2h?
the new "Hackers" box
in ^
@glossy vessel i like your pfp
axaxaxa
axaxaxa
@fair adder what's that?
its hahaha but not english version
https://tryhackme.com/games/koth/join/876963f540debe6adb7d9019
join in 5 more minutes to go
What box did you get?
and im stuck
Hackers
@nova tide @fair adder Drop me a spec link?
I made hackers, no point in me playing it 
Cheers
oh ok
Starting in about 5 mins if anyone wants to join: https://tryhackme.com/games/koth/join/7278b3cd35d383879e0ede74
Hey @quiet schooner I think I found a flag, Its not correct tho. Can I DM?
@stiff egret For Hackers?
Yes.
Uh sure
See if skidy entered it wrong
@lusty portal You missed a flag from Hackers I think
Flag matches my doc
do not DDOS users !
I somewhat doubt it's a DDoS
send urandom in sessions is DDoS
No, it is not.
DDoS is multi-source attack
Attack other users is legal ?
in case if you don't make the machine unavailable for them
The session is on the victim machine
Westar was here π
TTY flooding isn't even DOS, let alone DDOS
hello there
ohk, will try to find that out
GG all, i am in the machine still can't find a way to privesc
will try to play this one again
No root, perfect
anyone wants to play again? Hackers?
@nova tide Did you get user?
yeah
Nice.
starting in 15 minutes: Hackers
https://tryhackme.com/games/koth/join/e259fdd2fa75dabcefe8312d
imma get something to eat till then
@nova tide Drop me a spec link once it's going
I don't know if anyone has rooted hackers yet
really?
i don't think any one else is coming so i will join from my other account and try rooting it my self
there were some redirects but i only found one of those.
2 Minutes to start if someone wants to join in??
LMAO
π π


I liturally hate you !!
Bruh i thought nobody is playing so just captured one flag and left
Didnt know naughty will strike again
That's definitely a 
then
It really doesnt have anything to do with that lmfao
i think i "may be" able to root it in this try
If you kept going, trying harder, you might have got more flags
Nah the point it i thougt everyone was afk
So it was on purpose 1 flag
@nova tide lets play together that room later
i am playing rn
gg
@nova tide If you had a flag that wouldn't submit last time, that's now fixed
Ninja someone got king
Oooh spicy
π
GG's ^^^
β€οΈ
space jam
What machine do you think is the hardest for root in KOTH ?
offline?
because it's windows π ??
I'd personally say tyler but that's only because I haven't got user on it. I've got an instant path to root once I get user
bro @floral kernel i keep looseing connection is that your or is all my stuffs F, (not shell, i cant even view the website)
PG13 please π
hahah the censorship
π
@floral kernel this is a learning environment -- i.e. there might be younger students, or indeed teachers around
We'd like to keep it a respectful place for them
Where can I read the rules for koth, please?
@floral kernel For the discord or KoTH?
for koth, i read them right now thanks
i thought that patching vulnerabilities = no gaps π my bad
thanks for clarifying
You're allowed to patch all vulns
IRL if you are in that kind of situation the first thing to do is to close the service, but nvm, we are playing here we have to follow the rules. π
bro @floral kernel i keep looseing connection is that your or is all my stuffs F, (not shell, i cant even view the website)
@coral maple to be honest, i closed the apache2 service for a moment to test my webshell, if it's sending packets to port 80
alright np!
alright np!
@coral maple this game is fun btw π
secrets π€«
and i think me loosing connection is partly my end as well, been having trouble past few days
i'm too lucky that my neighbor has the wifi password same as the ssid π
lmao
alright i think you got this one in the bag, connection keeps dying π¦ gonna have to fix that
thing is my internet is perfect so its just vpn
gg
@floral kernel feel free to DM me, I created the machine
n3ko-chan thans
@somber agate can i dm you? correct me if i am wrong somewhere in hydra command
You playin hackers?
You can DM me
Yo, can I dm you aswell
I won't spoil it but I can fix your syntax
Something is not right here
Sure.
I have next question for rules
Changing user password is permitted ?
Yes.
@jovial dune from my understanding that falls under patching which is actually recommended to do
I'm stumpt on this fortune one. I dont get it at all π
I'd like another round of hackers, I got root but would like to find another way
Anyone down for a private hackers game?
is hackers a semi easy one?
dang and your lvl 9, I'd probably never get it then
here here
very cool invite
come play with me for extra brain cells
lol will it make me better? π I definitely need brain cells but I don't wanna keep getting stuck.
no no this game will legit give you brain cells
can I leave an active koth?
yes yes
Hello from the other side
Did you manage to do it, naughty?
you can leave the one that is not started yet. but after the clock hits 0 you can't leave
oh hey @nova tide
naughtt
just ate for the fast and got back
oh damn I think im screwed...
ah heck he joined
lol gl all around though ofc
jk i love to play vs u
alr alr haha
Thanks π
baaaaahaaa
imma try hackers after this game in private one...
Yeah I got ti
@nova tide wonna play together ?
sure
@nova tide could I join to get some experience on the box?
sure, will share the invite link here as well
awesome thanks π
lmao Fortune
imma make Hackers lobby instead, haven't played it either
if someone wants to join in into hackers:
https://tryhackme.com/games/koth/join/8f63b239d001b3d04189a3d2
4 minutes^
lol its raining here just got back, and there are multiple ppl now in game lol
1-(555)-HydraFixer here, what's your problem?
That's the best link for anything hydra http
HTTP is the only one that's difficult with Hydra normally
ok its raining heavily outside... electricity may turn off at any moment
Can we reset the box I did a little error
No I have overwritten shadow
gg
imma watch the movie then
damn that box is hard
Which box?
hackers
Hackers again
lets go again
I wouldn't say it's hard
Is there only one way ?
re
Koth boxes always have at least 4 ways
so hackers have 3?
has anyone gotten root yet?
yea
one guy so far
did he?
Certainly weren't posed as guidelines to me, but fair π€·ββοΈ
I failed my privesc by completly overwriting the shadow file
F
i have no idea what that .sh file do
so we are basicly no lifing hackers ?
I am root in 10 min for sure
I didnt brute force ...
you got in through production or gcrawford?
@rancid pewter DM me
Why ?
Rooted
well done... im stuck lmao
this is the second time I got somewhere cool and just lost the ability to use my brain haha
Maybe it more simple than you think
.lock ?
GG
damn i finally made it in haha
im down, would be cool to learn more of it, can make one if u need
4m
donut boutta destory the box again π

lmao @vast kite me my first time on the box lmfao
lmao
As a note, Hackers is semi broken by AWS
It's still playable, but will be more replayable once patched
it was fun @quiet schooner first time I really tried doing this by myself, and I managed to get root after some looking around...
Try the other routes
will do for sure, its still pretty hard to even find half of the stuff butonce I find it I do pretty well...
22 minutes to go: https://tryhackme.com/games/koth/join/d92e82102a3c8fc35e2cafc9
LMFAO i just logged myself out of root after I patched my entrance... what a brain I have
https://tryhackme.com/games/koth/2005
https://tryhackme.com/games/koth/join/b344ccbec0daacec8af55cda
anyone playing?
3 minutes Hackers ^^^
are you still trying to root hackers? 
yeah production is easy
slept in the morning after getting productionm need to privesc still
mhm but itβs on gtfobins
it worked for you?
yeah
wait, what?
production has an easy priv esc
idk I canβt say without spoiling π
I'd love to play, but currently at work.. You got this man!
well so far i only know of 4 ppl who got root, including u,westar, mydonut and one more guy
@glossy vessel Can I dm you? Wondering how you did it
do you really want to know? π
Yes.
i think itβs better if you figure it out yourself
I already got root, I'm just wondering how you got it
oh oh alright
@fair adder gg
Hello from the other side 
Yo!
i got 6 flags and production so far.. and i think remaining will be in other 2 uers and one in root
getting production is easy... but cant figure out how to privsec.. everyone is saying it have an easy privesc
played Hackers like 4 times so far. almost there
got it once but left coz i wanted to play hackers
many people have rooted that so i dont think it will be that much difficult
but iwant root in this one xD
will try at night
found a couple of pirvesc methods for Hackers.. gotta try them later
i wonder if theres ever been 10/10 lobby in koth
this is the highest i have seen so far
i hope its Hackers
this is the highest i have seen so far
@nova tide True
I bet, Most of them are ultra pros with fake accounts.
well NaughtyHacker is mine not sure about others xD
Youuuuuuuuuuuuuuu π€£
how?
why the box is sooo slow?
Who is DontDothis? I just urandomed his shell
HMU if someone wants to play Hackers
want to ask a few questions about ssh keys, can i dm someone? so i wont end up messing up with my own pc instead
@nova tide Really depends on how advanced your question is, but DM me and I'll try my best hahah
game any one ?
@mystic quiver invite for koth?
@nova tide Sorry bro i didn't saw the message.It's over bro.
np
How to make sure someone is not using autopwn in koth?
You really canβt I guess? If they get king and all flags within a minute it canβt not be an autopwn, but otherwise.. idk
Nice, I think I know where to look, but just havenβt found it yet
So the rule saying: "No Autopwn" how that works?
@nova tide Skidy got logs
@somber agate Let me know if you find the instaroot, I'm gonna be patching it friday so you have until then
@nova tide https://tryhackme.com/games/koth/join/8781effc41a9fa704c74160e hackers? 15mins
always up for hackers β€οΈ
@nova tide @raw bear https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology and Resources/Linux - Privilege Escalation.md
Works on most boxes π
Thanks β€οΈ
I've posted in resources and all over the place a few times
π β€οΈ
i have got some what idea what mydonut did to get root but i cant completely follow the way.. found a few more things today gotta try those this time
lets see how it goes
imma grab some food brb in a minute
Hackers is designed so that you need to understand the steps that you're taking
I have my own way that has worked to get root, but I was gonna look into just looking for other ways to go about getting in...
You can't just copy/paste from GTFObins
@raw bear no changing anything
naw I wasnt planning on it, but I am getting root
imma try to hack this badboy today
@nova tide yeah, im root
yeah, i just took it
@rugged portal U livestreaming koth??
is it ok to change passwords in koth ?
That's been answered many times @spring trail
thanx
It was a yes.
But if there's a guy named "Naughty" in game you are supposed to send that new password to him, so he can make sure nothing is wrong with the machine.
definetly nope
sad noot noises
Anyone KOTH?
i still have to massage my Dad's right arm will play after that.
btw play hackers with me? π @stiff egret
You mustve gotten root on that
You say that
He knows my way in
It's designed to be harder
Well, not harder. You just have to actually understand a little more
it wasnt that way for me? i just had to keep looking through what I knew already
I can share my notes with u ninja if u want
yO @raw bear @stiff egret
yo
yo
So no closing ports and no spamming kill shells
no defences but kill shells are allowed
No Spamming
maybe π
lul
(Pretty sure there's no rule against that)
(i know)
oh great a box i dont know at all π
I freaking manually typed the commands
well i dont want to fight with you yet still looking for persistence on this
so i can get back in any how
so you are not allowed to open ports?
are you?
uh? Well I havent closed or changed any ports.
no i am asking
if you can open a port that wasnt open by default? π
if anyone can answer that? ^^^
I think you can, Since you cant kill main services, you can always shift them to the ports down the list, like 40923 etc
lets suppose i was supposed to open a port so i can set my way in from that port? is that allowed?
take ssh as an example
Thats backdoor, I'd say thats allowed, but still depends on Mods/Admins.
thanks, took me a while
well i almost finished my late night dinner
gg @stiff egret @nova tide I do enjoy a good KOTH battle!
Same here,
Hackers?
im down
@raw bear but you have to find the other way in
I gotta get some sleep now lol
I am
No im going to look into it
Need to get a new mouse after lock down.. this one just double clickes 8/10 times
dang, i have gaming peripherals so mine are pretty good
well its Logitech G102 i believe
G502 is pretty good its lasted me a while and was relatively cheap
yeah that one is around the same price like this one but i like this one more
i play sixsiege on this one instead of that. tried that i kept on clicking those extra DPI buttons right next to the left click
I turn them off, i only use 400 dpi
lets remake and set timer to 5 minutes
which games you play?
i play Sixsiege,Dota 2,Fortnite,Tekken 7 and GTA V
Clash of clans also if that counts
yeah i have played some apex as well.. a few of my friends still play it, i was somewhere lvl on 35 i think
Can i join?
@rancid pewter @somber agate Thanks for reporting and helping me diagnose that
Sorry myDonuts for patching the other vuln you found, it was too powerful π
Yeah sure
@somber agate I can discuss it if you want too, I have the code
Fortune machine is too hard π i can't
Ach, Fortune is a kitten.
You can literally get from nothing up to root by pure luck.
Admin/Mod for Fortune? I may have something you wanna patch.
@terse willow you're up
@stiff egret yep, feel free to DM π
guys, how many flags are on fortune machine? i dunno if i found all of them
@sudden axle fortune has 8
thx
mouse over the flag icon next to the submission box to double check
@quiet schooner the number of flags needs to be more visible
@fair adder #522158404614225920 or #544951750801752079 if you have an idea of how it should be done
@sudden axle What box?
fortune
Ah nice
just finished it
lol I never even got 1 flag in fortune, I fixed my kali box so ima be messing around with koth's later today taking notes of everything for future reference
if you are a beginner it's kind of expected
but dw, you will learn with time
are the rooms equally difficult @quiet schooner ?
No
FoodCTF is quite easy, production is too
Hackers is harder
Tyler is decently hard
...production is easy?... im screwed then π
and i guess there are multiple ways in
as it is in fortune
still dunno if web way is exploitable or nah
@nova tide send invite link
Public game I think
I'm watching along
i dont know why people think tyler is hard.. i mean i literally got root in the first try in a few minutes
it's fine go ahead and pick tyler
takes me 10 seconds
"First Try"
I haven't tried it much
god what have I signed up for, I am about to get my ass kicked by you so hard
takes me 10 seconds
@stiff egret then peeps start spamming ban button
like dude i manually typed the code, pardon lmao
or "Nice Scripts" xD
or "Nice Scripts" xD
@nova tide no scripts till i am in shell
there's a fine line behind good notes with a high wpm and an autopwn script
there's a fine line behind good notes with a high wpm and an autopwn script
@fair adder hear hear
Scripts to harden the box aren't allowed IIRC
Scripts to harden the box aren't allowed IIRC
@quiet schooner hear hear
thats what people say when you get root in seconds..<<<thats what i meant
Hackers had a lovely instaroot vuln
Single command, straight to root shell
That was fixed.
Hackers had a lovely instaroot vuln
damn it, cant get root on that one yet
Hackers is designed to be harder than Food
i still want to get in through production. Got only one way so far
Designed so there's a little research and direction
i still want to get in through production. Got only one way so far
@nova tide easier once you are inside
always easier to find vulns from the inside
not exactly
Designed so there's a little research and direction
@quiet schooner Yeah I figured, i was soo close to break my laptop when i found the exploit and couldnt complile it, if you know you know
@stiff egret DM, which exploit?
always easier to find vulns from the inside
@stiff egret well i am in production but cant privesc from that to root
@nova tide is there any ways left to get in?
well there are still 2 ways that i know of to get in
damn
that i have no idea how to patch xD
oh i think i patched one of those
lmao i have no idea how to find them so you should be good
i'm stuck after upload my file haha
is it allowed to quit? haha
never give up
thanks for the motivation but i dont think i will get anywhere in 40 min
It's also the first time I've been involved in this kind of challenges
kinda hard 4 me but easy 4 @nova tide

yea lmao we are getting a beating
@nova tide you blew up node?
Hackers ^^^
starting in 4 minutes
wont change or patch anything in this ^^^
@quiet schooner you made changes in hackers?
imma just eat,wait and look at my screen to finish its job
I guess I was too slow figuring out a way in
nmap will show you the way
btw who was the guy who set listener on tyler? and reconnecting to it?
me
guys, any hints for fortune?
Can't really help with Koth boxes I'm afraid
But speaking as the guy who made it
You don't need to be able to hack to do it
You can literally get to root on pure luck
for real?
Hackers is broken sorry
hello everyone, i am new here, do we get the private room links here for koth?, cuz no one joins the public rooms
@sonic pecan we are in the same game and it is like five ppl there
@spare scroll can i join midgame ?
you are in the game
no worries bro
@quiet schooner dynamic passwords on Fortune seems to work fine. I had different creds this time
@sudden axle Yeah
I hadn't tested it because it wasn't my box
@nova tide patch is coming btw
space jam is supposed to be easy right?
yes
yeah its either that or i have become ultra pro lmao
latter is not possible, so i figured π€£
@sudden axle Yep, my autogen script works fine -- I tested it earlier.
For some reason it's just Hackers that it's not working on. No idea why
@terse willow Hackers autogen was fixed
Webserver was broken but that's being sorted
Ooh, lovely π
AWS broke it
The webserver or the autogen?
Ah π
Fair enough
are people allowed to spam broadcasted messages?
Yes π
lol okay
And it's not a broadcast, that one was just for you π
geez Wes you took over the box so fast
I've done this box before, path to root is quite easy once you get the hang of it
i dont even have the first flag π
You'll get it, just try harder π
is their more than 1 way in? lol i'm pretty sure you patched the mysql thing, since I can't connect to it. π
@chilly sandal Foodctf?
ye
There's a bunch of ways in
gg
Lmao, someone threw me off aswell, so then I just start shooting you know
i threw you off hah

