#koth
1 messages Β· Page 26 of 1
Nice hahah
btw did you have a script that rewrites king.txt?
i've noticed that the king.txt would constantly be blank and then populated with your name
but couldn't find a cron
Not really a script, it was a binary
he chattr it correct?
Don't need cron to run a script on a loop, you can just have a delayed loop
I need to put GCC on the box one day
ye, thats a fair point kris
yea even with the pasta hint still got nothing π
Having while loops in your bash can be killed with your bash instance, mine stays up even after I get kicked of the box
@quiet schooner on food?
just waiting for more than 0 people to join my koth
Though actually it's easier with nobody except me, nevermind
@sudden axle I made Hackers and Food
@stable horizon Im here B)
i compiled a c file on the box
Dang.
with no problem
Food definitely has gcc
GCC would make it more spicy for Dan
ah interesting
Oh I know why
Dan, so do you
It also has kernel headers kekw
@stable horizon I'm not gonna do a 1v1 sorry bud
@weary kindle OpenSTMPD
who's up for a koth?
me
anybody awake and down to play koth?
@spare scroll Yeah, I joined π
thanksπ
Yay, we got spacejam
seems like a cool box
is it normal for koth machines to stay active after koth is over?
Hackers got fixed yet or not?
Hackers has been patched if that's what you mean @nova tide π
Hackers has been patched if that's what you mean @nova tide π
@brazen cloud nah, last night there was no port 80 π
Oh that's interesting - has the port moved perhaps?
no, Ninja closed it while fixing the instaroot π
I broke the webserver patching the instaroot
^^^
ohk
admin for fortune?
chattr on king file is legit right?
3 mins left
hi
Can anyone please clear this, I am having a fight with someone over this.
chattr on king file is legit right?
@stiff egret
I tried making them see sense. A screenshot from official MOD would help
I am on the side saying chattr and changing the password of users are allowed.
That'll do, Thanks
@stiff egret
The underlying policy with patching is "Would it impact legitimate users of the box?"
Like if you take down a webserver, that's a no go
Killing services that could be avoided... No go
if only people start reading the rules before playing the game instead..
world would become a great place
Scripts that automatically hack and/or harden the machine are forbidden
So no metasploit?
You're allowed msf
Anyone up for a game?
https://tryhackme.com/games/koth/join/ac3783852876864c677383c2
Starts in 15 min
@blissful frigate this is the sort of thing that's banned
@quiet schooner msf being msfvenom?
msf being metasploit framework
that, given you are on shrek./ Will auto harden donkey and also give root callback
within the first 3 seconds of ssh being open
Root callback?
You gain root shell instantly
you sure? ^
not really
maybe port 5000 but I dont really get how to patch it without dropping the service
π
We killing shells already bois?
@hasty narwhal u here?
LOL reset? when i opened terminal it said session closed
i left the game thought its GG
π
You patched shrek, donkey, and puss, no shit there is a reset
You added a second account so you could reset the box by yourself? That's just sad
Is this even allowed?
@somber agate You are allowed to patch all the vulns
yeah but adding a second account to control the resets
I'd ban them, that should be against the ToS
@lusty portal Opinion?
I can't imagine that that is allowed
I'm quiting this game, I don't like this
Now, every time I get root and he can't access the king.txt anymore he just resets and tries to lock me out
Everytime? i did once coz i had no idea there was a reset
coz when i got back you were already king your root account was in etc/passwd
changed passwords for all
so i wanted a reset as well
Is that a reason to cheat a reset?
Reset is meant for when someone breaks the box
Or cheats.
Not because someone patched it
i patched everything in the first time
was in VC in General
and all of a sudden theres a reset
well as the Ninja said reset is for breaking the box that i didnt
so you reset it
then i reset
and now you reseted once more but i still got root
It wasn't just me who reset it, but it was just you who reset it
But whatever, if you want to cheat like that, sure go ahead but I'm not playing against you anymore
@terse willow, if you don't mind, what's your opinion on banning them for breaking what probably should be in the ToS in the first place?
I've been working on dev stuff. What's the issue?
Someone used a second account to be able to reset a koth box by themself
That does strike me as being somewhat unfair.
It's the site, so that's Skidy's remit.
@lusty portal, if you get a sec, what say you?
(Might be worth explicitly making that clear in the rules, if it's something to be avoided)
I meant from the discord, but the site would be convenient too
Not much point in banning someone from Discord if it's a site rule that was broken π€·ββοΈ
Fair fair
Still better than having somebody who's just going to cheat in the community though
@stable horizon Even if the user was banned from the site, as you've witnessed. He has a second account.
I feel like doing it in order to progress the game isnt necessarily bad like one time I accidently DoS a machine... oops but the game just couldnt go on because there werent enough reset votes so I think in that case it shouldnt be bannable but if youre doing it to get an unfair advantage thats when it should be against the rules I think it should be up to the discretion of the moderator of the game
The way to handle the situation, in my opinion, is to state the rules to him.
He claims he didn't know he was breaking them.
I don't think he should be banned, but I do think this should be very much against the rules
Totally agree with that ^
Very unfair.
Throw it in #544951750801752079 and maybe they will add it as a rule!
It's exploiting the system
Skidy is likely to make a rule for that
Seeing as I found a way to exploit the system and that became a rule
I pinged Skidy -- with any luck he'll get back when he gets a second π
π
@stiff egret Did you get that exploit working?
Reset is meant for when someone breaks the box
@quiet schooner Yeah I agree, I'll add the KoTH rule to 'One user per game (no alt accounts)' and 'Only reset if the box is broken'
@stiff egret Did you get that exploit working?
@quiet schooner Well, I think I should DM you about that.
@stiff egret Go ahead
@quiet schooner Yeah I agree, I'll add the KoTH rule to 'One user per game (no alt accounts)' and 'Only reset if the box is broken'
Thanks
I wanna know which exploit you guys are talking about π₯Ί
@quiet schooner So in a koth game, if a box has been fully patched, the game is just over?
Otherwise the game is just over after 5 min if someone has already done the box before (which is very likely)
The chances of that'll become less and less frequent as the pool expands
Besides resetting the box in that case will only extend the game by 5 minutes
@lusty portal
Why ping Skidy?
@stable horizon ?
Anyone playing?
Might've not noticed your ping
π
@quiet schooner while fixing instantroot did you made some changes to the way to get into production?
oh thats what i wanted to ask ^
That was never the intended
I still have a script that gets me fast root, but it's not instant any more
well idk the way about instant root but thats the way i got production
Well congratulations, that makes you a hacker π @nova tide
That was an unintentional vuln
feature not a bug ^^
I wouldn't have fixed it if it didn't make it instantly rootable
so thats what you added?
if (token === undefined || token === "")
Somebody needs to make a list of common linux processes, and you can compare it against the output of PS to see if somebody could be running a looped script to erase king.txt and put their name in it
i think token ==="" wasnt there before?
@nova tide It was
ohk
Somebody needs to make a list of common linux processes, and you can compare it against the output of PS to see if somebody could be running a looped script to erase king.txt and put their name in it
@stable horizon peeps have that,(including me) but 1. no one uses it unless its pro game, its like one time thing, you use it once, everyone know what it is. So unless its a some sort of prized game, peeps dont use their best.
right right
π
[STATUS] 41.39 tries/min, 1283 tries in 00:31h, 14343116 to do in 5776:01h, 4 active
RIP
20 minutes left lol still cant get anything π
RIP
||@quiet schooner What if the autogen picked the last password of rockyou?||
It won't
It better not lol, imagine someone getting the pass at 58 minutes lol
Yeah, it's pretty easy to restrict, don't you worry
Go faster with more threads
4 aint enough?
SSH doesn't like lots of threads tho
4 is the recommended for SSH as some distros have brute force protection
whats the limit for threads?
nice edit
Well they weren't specific
The limit is "Turn it up until you start getting issues"
imma start from the opposite end.. keep turning it down until you stop getting issues
Imma watch the movie Hackers tonight. Recon level 9999.
It's a good movie
It containts the password for root
You not dumped shadow yet?
It containts the password for root
@nova tide Reported for spreading life threating rumours.
Did
but was facing issues to use hashcat
i think i shared a screenshot here somewhere
@nova tide Not an error
It would have attempted to crack the passwords
Why the flags are not autogen randoms?
Then you're doing something wrong
now using -t50
[STATUS] 757.86 tries/min, 5305 tries in 00:07h, 14339102 to do in 315:21h, 50 active
imma watch TCM till then
LOL, only 50?
Nahamsec*
I thought your plan was to start from last value π
kinda sucks that i am not really good enough do play koth cuz it is really fun π
gg @pure beacon @stable horizon @distant flint
except not really because i did basically nothing and instead blew $10
except not really because i did basically nothing and instead blew $10
@stable horizon What do you mean did nothing?
I did nothing
@stable horizon How did your initial nmap go?
Did my initial scan and got ssh and abyss, only exploits I could fine were to send a payload over to the server but that required local input
And the only abyss web server exploits I found that I could use were for overflowing the buffer and crashing the server
Next time you play Food, check out what's on the higher ports.....I always check non-standard ports in a browser and manually with telnet. You get a lot of weird and good stuff there....
Probably, my network is really bad so it takes about 30 minutes to scan more than 10000 unfortunately
It definitely shouldn't take that long. What command are you using?
I always use sV and O for service versions and OS detection
Do the RP: Nmap room ( https://tryhackme.com/room/rpnmap )
And then watch "Advanced nmap with Viss" on Hak5 ( https://www.youtube.com/watch?v=7XMIFTRiAGA )
Between the two, it should give you a great, fast, default nmap to run...
Dan Tentler joins us to share some tips about NMap and Mass Scan!
https://phobos.io/
https://twitter.com/viss
-----β-----β-----β-----β-----β-----β-----β-----β-----β-----β
Shop β http://www.hakshop.com
Subscribe β http://www.youtube.com/hak5
RSS Feeds β https://www.hak5.org/...
Kali on an eHDD
Kali on an eHDD
@stable horizon That's surprising. I run kali in a VM and it's speed is pretty damn good.
Kali in a VM works fine for me
Really it's my internet, it's pretty crap (1 MB/s)
Really it's my internet, it's pretty crap (1 MB/s)
@stable horizon Even that low, you should be okay with just nmap..... hmmmmmm....
They sold my desk, but I would move it back otherwise
And yes, for some reason I really am using an eHDD
Can you run VirtualBox on your machine?
On my actual Hard Drive? I mean yeah
On your laptop/desktop
The transfer speed isn't an issue though, this is actually much better than the Hard Drive I have in my system
can anybody give me a hint for fortune?
can anybody give me a hint for fortune?
@spare scroll I haven't yet played Fortune, sorry
okay, thanks anyway π
Itβs against the spirit of the competition regardless
ahh allright
Itβs against the spirit of the competition regardless
@brazen cloud Hints to get someone on the right road I think are good, we're all here to learn / practice / have fun. But to flat out give an answer or a command, definitely not okay.
i am not looking for a writeup but a hint cuz it have been 30 minutes and i got nothing
Absolutely :)
@brazen cloud Hints to get someone on the right road I think are good, we're all here to learn / practice / have fun. But to flat out give an answer or a command, definitely not okay.
@harsh obsidian Absolutely π
I haven't touched a koth box since beta test oof
@harsh obsidian sorry for destroying your shell, couldnt find your script

Finally Hackers in a public game:
https://tryhackme.com/games/koth/2269
Guys how do you stop people from accessing the ssh when your in
Passwords
Or keys
Ye if you change it the people who are already in stay in
So how do you get rid of them
Kill them.
XD
No that was serious
ty
gg @nova tide :D
Writeup @nova tide
?
@harsh obsidian sorry for destroying your shell, couldnt find your script
@pure beacon No worries. I'm glad I was able to hide it well. Mind if I DM you?
Writeup @nova tide
@proud moon whatup?
gl @distant flint
gg @nova tide :D
@onyx spade well i had to leave for fasting, i had the password for one user at that time. GG though
Hey...could you give me a walkthrough of the challenge...I'm still a newbie at this @nova tide
thats against the rules @proud moon
Ok
Writeups are not against the rules
is not? @quiet schooner
Read the rules.
oh ok well then
To combat the NMAP lag, I suppose I could technically use a Kali Box on the site
While, funnily enough, using Kali at the same time
Oh come on Westar, I was distracted
Nothing is patched, and I'll keep it that way
Fun, but doesn't that take the fun of the sense of risk from the other players?
Eh, I'll just go grab my Kali box's IP and SSH into that so I can get to work
Is there any way of accessing it other than the room?
I don't get what you mean
On what part
But I don't like patching vulns, come join me on my box and let me have some fun with your pts
Like the first and last sentence?
I don't care if you patch or not, I was joking.
But outside of the Kali room, is there an easy way to deploy the box?
Deploy what box?
Oh, uhm idk, I don't use that
It's in the kali room
That's how you deploy VMs on THM
VMs belong to rooms or KoTH
Right right but I was just checking if there were any other way of deploying it so I didn't need to go there
No?
hm ok
That reminds me, I need to try something next time I play KoTH
What html page are you getting?
Literally every html page just says Westar in the source
Well, every page I pulled with the spider
Are you scanning port 9999?
Because that is the port how thm knows who is king, that has my name because I'm currently king. There is no vuln there
There might be a vuln, I wrote the code for at least 3 of the boxes in rotation (for the king server) and we all know how that goes
oh boi
If there is, the code is open source so you aint gonna gain anything by directory bruteforcing it
Where can I find that?
Well in all fairness, I'm dumb
@somber agate Open source, written by me. Should be enough for you to find it
Extra hint, which you can get from the box
It's go
Aight, got it
Can you immediately win KotH by shutting off all the services running on the ports, and killing all the processes of users on the server?
hmm mmm m i wonder who posted that
Hey...could you give me a walkthrough of the challenge...I'm still a newbie at this @nova tide
@proud moon
Now I do the most fun part
Sitting in agony waiting for the server to start
6 minutes in, still broken
Restarting fixed
Anybody got some good stories?
i would recommend watching Hackers 1995 movie in the mean time
Maybe rewatch Wargames
Dont tell anyone but it contains the password for root π€«
Hmm
I probably chose the wrong username
But it's not like there's an easy way to enumerate usernames
well you got two of em that would be enough.
I have none of them, I just found the login and presumed the username was admin
you ran nmap scan right?
Yeah, everything closed
What the? Only 1000 scanned? Shit I forgot to put in the -p-
also put -A or -sC and -sV if you like
just for reference there's nothing else on higher ports so 1000 are enough
Remind me the tmux shortcut for copy mode
<prefix> + [
Got it
Somehow my first scan completely missed the important ports
Oh
That's useful
Well back to waiting for hydra with a new user
To be frank I could probably use a much smaller wordlist than rockyou
@brave pilot @stable horizon Good luck
didn't get to read it
ha
π
@quiet schooner Can I DM?
Sure
π
@nova tide if you have valorant installed. Exit vanguard and it will work again
Ah, my favourite kernel level malware anticheat
Had no issues like those. No i dont have valorant @dapper escarp and i tried opening and closing it multiple times times still didn't workded @fair adder . Idk what was the issue, just restarted the pc and it worked
@stable horizon Good luck. Good idea.
@stable horizon i see you had about as much luck as i did π¦
If I were on a desktop if would be easier
probably, this way seems awkward
Some of the pages when curled were throwing errors, so I'll do another box when I get back
Oh yeah, is there any hint I can get for Hackers?
I just want to know if the goal of the unspecific form is brute force or if it's another method
That there is
But I didn't want to say it was a hidden page on the site, so I was unspecific
I have the usernames, but do I need to brute force the password or is there another way
I just wanted a yes or no answer
@stable horizon Key part of hacking is trying things and seeing if they work
I'd rather not keep trying things that are never going to work
Thatβs literally part of the process.
That's fair
I spent each of my last sessions in Hackers with hydra, and it never finds anything with most ||common password lists||
So maybe look elsewhere. If brute force isnβt your way in, maybe thereβs something else.
Or use a better wordlist
And make sure you have the usernames correct
Different services often use completely separate login systems
No reason that a valid system user is a valid website user
LDAP is hard, but that's a way that you could sync the two login sets
I'll just put up a private server and keep working
Oh crap you're right, I've been using a user I grabbed from a different server, I'll try it on the server I grabbed it from in the first place
Damn I'm an idiot
https://tryhackme.com/games/koth/2301 First Lion game:)
Good luck, but I have no doubt you'll do good
Am I allowed to make a second account so I can have a practice KotH game?
Or is that against the rules
@lusty portal Was there a final policy on this?
I know you can't use it as an unfair advantage like how Naughty rigged a reset
But I'm just practicing for when it's time for an actual game
Yeah that's why I'm asking skidy
Right right
w00t, it's Lion time! (Please be nice @somber agate )
I have a feeling the decision was that it's not, because it gives people a chance to practice/write autpwns in a zero-risk environment
@terse willow however now foodctf exists as a standalone for writeups
'tis true, but so far it's the only one
That's fair, I'll go see if I can grab somebody to join it for me
Is that allowed? Is the issue in having an alt or is it in practicing?
James makes a valid point in saying that write-ups are allowed now, so, good question.
My personal opinion would be that neither are particularly fair (especially given that the skills can be learnt on boxes that you won't be in competition over), but if one of the admins says otherwise then that's what goes
@terse willow We haven't had an official judgement
Exactly so ^^
@somber agate, that's not nice...
how often will it be added new machines to koth?
every month maybe?
There should be new additions to the pool each month
Although it looks like they're also being released throughout just now
The push for us to make them is certainly at the end of each month, ready for the next one
ahh, great!
Time to roll my roulette dice and see if I get the right machine so I can test out my idea
Lovely -- we have an official judgement π
On which part
@stable horizon Two accounts
Sweet
inflate those sign up numbers
ah yes nothing like more user data
I may have found an issue with the Lion box
Who do I need to contact
@quiet schooner ?
Can I dm you about it, to see if it is intentional?
gg!
@somber agate I know nothing about that box
@harsh obsidian GG!
Aight, I'd like to talk with someone about it, I found an instaroot
@lusty portal Who made this one?
holy crap i finally got a flag
holy crap i finally got a flag
@stable horizon Congrats!
@stable horizon Ayyy gj!
I was kind of hoping the password for donkey in shrek would be the same as the Shrek box from HTB
Nah different box
lol
Yeah ik but it would've been a good callback
@somber agate Join public KOTH I need a revenge
Read the rules and it says how to report
Email koth@tryhackme.com for reports
Email koth@tryhackme.com with the Username and your game id π (in the url)
And preferably read the rules ^^
@rancid pewter Nah, I'm done with koth for today lmao π
@lusty portal Who made this one?
@quiet schooner I designed, Zayotic madr
@somber agate DM me:)
Might be a little slow at replying, at my parents:)
Will be back at it tomorrow
Fortune private game as don't wanna see Prod again https://tryhackme.com/games/koth/join/b473d445848c9e312f567bf0
14 minutes eta
GG
Has anyone found the eighth flag on Panda? This is driving me nuts
That last flag has evaded me since the first time I did that box
That being said I couldn't find the 7th flagthat time π
lol
@humble breach gg
@floral kernel well done! that was my first game ever... i got gloria first lol
i was so close with the upload form
But did you use auto script to put your name in the king.txt ??
Hunting the king hhhhhh
then getting forbidden and yall were way ahead lol
@humble breach local one liner
It is
It is allowed
It's my first time on try hack me
Welcome π
omg what have you done to the poor cms
If anyone wants to check out Lion:
https://tryhackme.com/games/koth/join/655cc35bab0173cd399fb65f
Just watched somebody play LION, I got some learning to do!! LOL
lion is easy
for some yes for some that are noobs (ME) no not yet
Kinda lost past User
On Hackers
Any tips? I'm currently grabbing PEAS
Shoot, times up
I'm lost
@fair adder Who made Hackers?
Ah
why?
He better not find himself in a dark alley
I see
Right, @crude meadow?
Is it hard
No it shut off when we were figuring it out
@quiet schooner
What do
@quiet schooner Can I DM you with pained noises of a request for help?
@fair adder Do you have any experience with this box? I seriously need just a tiny hint
Nope@stable horizon
Thanks for considering
@stable horizon you'll only get generic help, like everyone else does
is it possible to play by myself at koth?
it is required to have 2 or more players to start the game
however Skidy has said that having an alt to play private games is allowed.
@quiet schooner thanks man for the i nfo, going create my alt account
Down for development?
Ah, ok. Ty
To be fair I only really need generic help
Well, go ahead then
Before I go, what do you define as generic help
Ah okay
Yeah I don't really need help like that, I'm kinda just confused what I can use with an elevated ||openssl||
I'm aware
That's the hardest privesc on the box.
I know about the reverse shell, but when running under sudo it only gives me the user?
Yeah, you need to break down that command from GTFOBins
You call /bin/sh as your user, and just use the binary for IO
@stable horizon GTFOBins isn't that helpful for this, and that was intentional.
You need somewhere between a little and a lot more knowledge to use it (compared to what GTFOBins gives you)
Hi xD
??
yayy i did it
i got into the other account in hackers
Now just pivot to root somehow
any starting point tips?
have anyone rooted Tyler? i have a question
@floral kernel what's up? no spoilers
@fair adder can I PM?
sure
we need another reset req on https://tryhackme.com/games/koth/2402
pls guys :3
sry xD
here it is
and thanks in advance
Wait, i thought closing port isn't allowed???
sure isn't allowed
so why is port 3000 closed in this game?
i voted for the reset ,but someone else also joined in
Done
3000 can be easily fixed without a reset, I'm pretty sure
how ?
It's nodejs IIRC
okeh how
You have to understand the vuln
the whole point of that service is RCE. how do you "patch" that? changing the parameter name isn't a patch because it doesn't close the vulnerability. can that just return "This service is disabled" and never execute client input?
well that went horribly π€£
@fair adder Remove the RCE, leave the port open
Service is then patched, but still running
ok, so just always return "This service is disabled" or something
I mean it removes the vuln
Site is ded
@quiet schooner thanks, i'll do that next time
@stable horizon It's evaluated every minute
Been about 7 minutes
the last game that i joined had the same issue, i ran my bash loop but it didn't changed king
even only my name was in king.txt
its working in a private game but not sure why wasn't working in last game ^^^
yay
I broke my reverse shell, rip
oh god, it's Chara
How many flags does every box have?
someone will play koth soon ?
@jovial dune i'm in the public one that starts in 3 minutes
oh poo, it's the windows one, i know next to nothing about that π¦
ee windows
@hollow stone DM me an invite
i really hope someone is messing with my remote desktop session and the connection isn't supposed to be this wonky...
well, this was the most annoying experience ever π¦
Are people allowed to delete basic files? Like sudo and find and ls?
Is that against and rules? Because somebody just did
That's fine
@stable horizon You can get them back if you're smart about it
Kris
Kros
I'm just gunna point this out here. You can get static binaries for all of those
try harder
stop moaning
good night
@stable horizon Also if that's foodctf, there's a good chance that that was just the way the box was designed
Low hanging fruit, designed to be annoying to use
I mean it isn't too hard, just gotta add /usr/bin to path
Are you still getting the wall @stable horizon?
@stable horizon Pls remove image and report pts/1 to koth@tryhackme.com
I was going to try for the IP, but yeah, just report pts/1 and maybe the time stamp?
@terse willow I mean tracing it to the IP is better
@stable horizon But pls remove image
@stable horizon Could you send an invite to that box please?
Sry
@terse willow hmu if you need creds, I got root creds for it
I was literally about to do that James π
KING OF THE HILL JUST LEVELED TF UP
oh my god this hurts me
why is the shell always slowly deteriorating, first no backspace then no cursor
now not even a username
at least it was fun
for a few seconds
Thanks for reporting the behaviour of that certain spoil sport.
my eyes are very pain from trying to read the screen
Yeah...No place for toxicity like that...
No just the bad deterioration of the UI
lol joined this game a little late
https://tryhackme.com/games/koth/join/108698be79fab246b64ff0c6
@burnt depot gl
make it seem so simple but then... wtf
well then i guess im a little not great lol
@stable horizon you only found one route
but learning is fun
And it took you a loooong time to find it
Yeah until someone patches it. Which you can do super fast.
aaaaand times up
gg π
man i feel like i was so close to something, but no dice
that was fun
i just found a login and then time ended lol
gl @burnt depot ghannett hopefully hackers comes back up; I've got a LOT of work to do on there... π¦
agreed. gl 2 all
@harsh obsidian with the skyrocketing score lol
@weak haven lol. I keep my notes so I don't make the same mistakes again. I finally found the final flag though, than $diety!
- thank $diety
i just dont see my way in yet. more minimal that the others i've done so far
i just dont see my way in yet. more minimal that the others i've done so far
@burnt depot Ports 15065 and 16109 have http servers. dirb works well here....
;p ok.. nice
yah gotta work on my sql stuff a ton lol
gg all!
i think im addicted lol
So easy
@stable horizon which way you found? through which user i mean
For?
hackers
Anyone trying https://tryhackme.com/games/koth/2477
@brittle merlin not right now, but I got that one a few days ago, seemed harder than the other ones I tried
I get redirected to panda.thm and it doesn't seem to load up.
got valid creds for user but it doesn't let me log in
did you add it to your host
in /etc/hosts?
ye
nope, can you tell me how?
just opening the file and copying what the examples there are doing should work
I tried, doesn't work. Tried reconnecting to the vpn as well
Saving panda.thm to your known hosts doesn't work?
let me try again
I think the actual web page that displays that hostname is supposed to stay as such
Yeah what do I add there? The entire url to the page or just the IP?
IP usually
Yeah, it worked. Thanks
Hi @somber agate may i ask some question for box hacker?
you can ask me
can someone give me a nudge on spacejam? now on my 4th go and still no shell.. dont think i understand nodejs correctly
@high anvil Ye you can DM me if still needed
Too bad James isn't here, that would be great
@stable horizon Can i dm you?
Sure
@stable horizon may i pm you with a question regarding koth hackers ( 2nd user) machine ?
hii

Yes
@willow silo Can I join your game?
so many places to put files... but where do they gooo lol
any1 got a game going i can join? 25min wait
any1 got a game going i can join? 25min wait
@pure beacon Got about 17 minutes remaining on the clock
https://tryhackme.com/games/koth/join/c75e3a184f2a77ab1514bbc7
Starting in 24 minutes:
Starting in 7 minutes:
https://tryhackme.com/games/koth/join/e84d954c3520d9b3f8439336
I've reported it in bug submissions
well ill take the win
Thats odd, i didnt see anyone else in the room at all
I literally clicked a link once and was granted a KOTH win. Never played a match in my life.
I literally clicked a link once and was granted a KOTH win. Never played a match in my life.
@tacit vale Did you get the badge for winning?
I got it added to my streak, it was counted
I didn't get a badge. But got the win screen.
Odd
@tacit vale Seemed like it took a bit for it to show up for me. π€·ββοΈ
April 23rd. So I've given up hope on my unearned badge.
Ive won a koth match too and never got the badge
April 23rd. So I've given up home on my unearned badge.
@tacit vale ?
Ive won a koth match too and never got the badge
@winged charm That's surprising. If you have the game number, I'd suggest pinging one of the Admins....
Same happened to me, I presume you need your name in the file at the end and not just the highest point value
ah k
I have it, and I've only won a public KoTH
Contact skidy, he'll give you the badge
22 minutes until start: https://tryhackme.com/games/koth/join/7756a4a7a16ebaf888562ada
are there decoy king files?
lol, no. I haven't seen any decoys
gg to you too lo
lol
i tried to put my name in but it wouldn't update to the scoreboard
<evil grin>
i was so happy when i found it lol
then all of a sudden i read it again and @harsh obsidian is back in the damn file
lol. feel free to PM me as to how you got it. maybe we can talk a bit
oh god did you use chattr again
............................................................................................................................maybe
you'll quickly disband that team lol
i'm still learning my way around different techniques
@harsh obsidian you are evil
He is, but he's my fren
really cool game come play with me
I have a question for koth
Is it ok to edit the sshd_config file in any machine once you have root?
Or is that against the rules
Is it ok to edit the sshd_config file in any machine once you have root?
@last ether
I'm not terminating the service
Ok it's fine then
my personal opinion : its not
read the rules
making machine unavailable for others is against the rules
patching vulnerabilities or changing ssh port is fine
But there are other ways to get onto a machine?
There's always multiple
And I'm not terminating the ssh service
thatβs good
Only allowing certain users to log in
That's fine no
That is what security is after all. Isn't it?
That tooπ
so that getting user becomes fairly useless
But you never know when someone else finds something you haven't
yup, thatβs the point of the game
So the technique mentioned above is fine right?
anytime 
how many flag are there on spacejam?
if you still have the room up, mouse over the flag icon
the hover text will tell you the number
welp
if you wanna know how many flag total each box? just put your cursor mouse on "flag icon" beside flag submission. they will tell you how many flag that you need to obtain
Any hints on food?
@brittle merlin look for all open ports
and check if there are any interesting files on them
Any hints for hackers
Enumerate harder
I able to find only two flags lol
Should we actually watch the Hackers movie from 19s
i mean, you could just beat on the box, but you won't really appreciate the work that went into it
It's a KoTH box
It's designed to be beaten on
There's lots of doors
Find them, open them
Guys one question ....... Do every machine have more than one way to break in
i heard rumor that there's at least 4 ways to break in, on every machine
Ok....
@quiet schooner can i dm you?
Did space jam .... it seems really easyπ
@finite turret try Hackers next π
π
ugh... not looking forward to going head to head with you @nova tide
get spanked every time
i cri π’
well at least you showed some emotion!
I'll beat him for you
@stable horizon π
Send me an invite when have chance
@fair adder Keep it PG13 please π
Damnit is relatively PG13, but that's about the limit of it
btw what does chattr do? and how do you use it in koth?
@fair adder Probably a chattr on a loop
@fair adder chattr -i /path/to/file && rm /usr/bin/chattr
(i am not even root)
Yeah that's what n0beard tends to do to me
@fair adder
chattr -i /path/to/file && rm /usr/bin/chattr
@gusty cradle let him google?
β