#koth

1 messages ยท Page 28 of 1

quiet schooner
#

Just drop the link

#

Not the join link

stable horizon
#

*not another way

sullen hound
#

hey what happened discuss with let it settle in a peaceful way

#

let me know what wrong have i done

quiet schooner
#

@sullen hound You're not allowed to close services unless there's no other way to patch them

#

Please read the KoTH rules

sullen hound
#

ok thanks for that

fair adder
#

was a damn good match though

#

i thought zero was gonna have you

stable horizon
#

Get him outta here

#

nobody uses windows looking for an invulnerable system

terse willow
#

That is enough @sullen hound
No masquerading as intelligence agencies please.
Also dangerously close to Rule 9

quartz gale
#

ban him

terse willow
#

Sure

#

Rule 9

stable horizon
#

Yes but you should at least read the rules before saying anything

#

Nobody's going to want to play with the person who cheated

quiet schooner
#

Closing ports is against the rules

#

Breaking the rules for an unfair advantage is cheating

#

wat

#

Modifying flags is also against the rules

#

I didn't say that you did

icy cave
#

they flags on lion arent a straight copy paste .. they need editing...

#

no one messed with the flags they worked for everyone else

quiet schooner
#

You're acting awfully defensive for someone who claims not to have broken rules.

#

I suggest you stop digging the hole and move on.

stable horizon
#

I don't even understand what you're asking

terse willow
#

I agree with James. Probably best stop digging here...

stable horizon
#

Has the report been filed?

quiet schooner
#

I think mango sent the email

fossil ledge
#

who made Panda?

full grove
#

hmm

#

I think that'd be Zay?

fossil ledge
#

can't find him, should I report only to him if I rooted?

quiet schooner
#

@fossil ledge You're meant to root the boxes. You don't have to report it

fossil ledge
#

ok

#

actually I didn't know how to do it, if I should report to the machine's owner, or if it's automatic

#

so just asking ๐Ÿ™‚

quiet schooner
#

@fossil ledge You're not meant to report it?

#

At all?

fossil ledge
#

I was just asking, didn't know. Thanks!

fair adder
#

@quiet schooner I have further gone into the I hate you hackers box deep hole of resentment... good for you sir!

quiet schooner
#

It's designed to be hard

#

In order to exploit, you need to understand the vulns

#

Have fun

fair adder
#

Can I quickly dm?

umbral dawn
#

any koth?

quiet schooner
#

@fair adder I might not answer your questions, but you can ask

severe orchid
harsh obsidian
#

Any koth going? I have a thing I want to test; don't care about flags or king

fossil jackal
#

go?

#

xD

sullen hound
#

hey does changing password is against the rules

gusty cradle
#

Changing passwords is allowed

sullen hound
#

thanks about it

#

is changing permissions of file allowd

#

allowed

brazen cloud
#

Yes

sullen hound
#

and using scripts that saves time

dapper escarp
#

Only way to maintain king is scripting

#

Usually anyway

sullen hound
#

is it allowed

dapper escarp
#

Yes ๐Ÿ˜‚

sullen hound
#

Thanks for your Time @dapper escarp

gusty cradle
#

and using scripts that saves time
@sullen hound Do you mean scripts that automatically pwn the box?

sullen hound
#

no

#

scripts that changes the king after it is changed by another

gusty cradle
#

Those are allowed

mint cargo
#

i have a question, if someone is doing the while loop to put his name into king.txt how to stop it?

sullen hound
#

can i answer this @gusty cradle

gusty cradle
#

Sure ๐Ÿ™‚

dapper escarp
#

Nuke their loops

mint cargo
#

yeah but how to? i did some ps -aux and killed the ssh shells but the loop didn't seem to stop @dapper escarp

sullen hound
#

try ps -ef

#

and find suspicious scripts

#

and kill them

fossil jackal
#

@dapper escarp vim .bashrc ; parrot xD that's so cool bro

sullen hound
#

thats to some extent for cutom commands

mint cargo
#

and kill them
@sullen hound will do that in next koth thanks

sullen hound
#

no Problem

weary marten
#

trying hard @sullen hound ?

sullen hound
#

try harder

weary marten
#

xD

sullen hound
#

now theres no chance you will be in

weary marten
#

i m in but not root ๐Ÿ˜ฆ

sullen hound
#

and you can not be root

#

so whats the password

weary marten
#

lol

sullen hound
#

come change your king

#

why dont you

#

๐Ÿ˜†

weary marten
#

coz m gonna win

#

see scoreboard

#

why do hard work ?

#

when u can sit and relax

#

well ggwp

sullen hound
#

well thats true to some extent

#

if i wasn't busy you would not win

#

that you know very clearly

weary marten
#

ohhh

#

okay

last ether
#

Guys I need a hint for hackers room

weary marten
#

me too xD

last ether
#

๐Ÿ˜…

#

Anybody?

sullen hound
#

dont sham just ask

warm chasm
#

Reset

quiet schooner
#

Hackers was designed to be hard.

fossil jackal
#

hihi

quiet schooner
#

You need to try and understand what the vulns for escalation are.

#

Don't spoil the box.

warm chasm
#

sorry

#

But you should reset it now

last ether
#

What??

#

You removed the hint๐Ÿ˜…

warm chasm
#

It was more a spoiler

last ether
#

I'll keep trying

warm chasm
#

But check out ftp

last ether
#

I just need a nudge

#

I did

severe orchid
fleet apex
#

Why doesn't the King Update? I wrote my username in the King.txt, but it did not update yet. Do I need to do anything besides that?

severe orchid
#

try removing the file and do echo "yourusername" > king.txt

lusty portal
#

Is it your THM Username?

fleet apex
#

I did.

try removing the file and do echo "yourusername" > king.txt

#

Is it your THM Username?
@lusty portal Yeah even casesensitive

#

Sorry for the ping lul

lusty portal
#

Are you nxXLeoXxOne?

fleet apex
#

Nope

lusty portal
#

Whats your THM username, let me take a look.

fleet apex
#

Painforpay

lusty portal
#

There is 2 usernames in the file

#

Painforpay AND nxXLeoXxOne

#

It just needs to be your username

fleet apex
#

yeah thanks

lusty portal
#

If you read the king.txt's file contents, there are 2 usernames in there.

#

No problem.

fleet apex
#

I just saw it

#

Thank you! it that all?

lusty portal
#

Yup - add just your username in there, and it will recognise you as being the King ๐Ÿ‘‘

fleet apex
#

Okay!

severe orchid
#

why does every command as food user in food koth say not found

#

is this intentional?

quiet schooner
#

@severe orchid do some research

#

Shell is a long hanging fruit

severe orchid
#

oh, thanks

#

got it, thanks

#

is shell hikjacking allowed for defence in koth?

quiet schooner
#

Read the rules

#

If it's not against the rules, then by definition it's allowed

severe orchid
#

ok

unkempt pagoda
#

Did you change permission of a flag @severe orchid ?

severe orchid
#

no

unkempt pagoda
#

๐Ÿค”

quiet schooner
#

One of them on food isn't readable by the owner

severe orchid
#

but if there is a problem, you can reset the box

quiet schooner
#

If you're the owner, you can change permissions though

unkempt pagoda
#

Doesnt allow me to change perms

quiet schooner
#

Idk, might be immutable

severe orchid
#

try getting root

#

then read it

hollow stone
#

shouldn't be needed unless it's a root flag

warm hull
quiet schooner
#

@hollow stone or immutable qnd not readable by the owner

carmine hemlock
#

it didnt show the machine name in last 60s too (im in that same koth)

warm hull
#

yeah

hollow stone
#

@quiet schooner are there such flags in koth though?

quiet schooner
#

Only if I made a mistake ๐Ÿ‘€

severe orchid
sullen hound
unkempt pagoda
#

Why cant i write my username to king.txt :/

#

It just stays empty

severe orchid
#

is xxe the right path for panda koth

unkempt pagoda
#

Are flags regenerated or are they always the same?

nova tide
#

Always the same

#

i think they may change that in the future

fleet apex
#

Is it intentional that the Wordpress on panda bugs out? the Stylesheet points to panda.thm, all redirects do aswell

unkempt pagoda
#

You should add the it in your hosts file

mint cargo
#

and adding ip to hosts is easier overall as well. I always add it

weary marten
#

wtf the game is over but i m still in the box xD

spark anchor
#

@weary marten What is this name ? lol

weary marten
#

do you have problem with my name ?

spark anchor
#

@weary marten No sir, I was just asking.

whole path
hollow stone
#

@weary marten it's a known bug, koth machines stay active for a full hour after a reset

whole path
#

why does the wpscan not work

glossy vessel
#

where?

whole path
#

i think its called panda

spark anchor
#

Is it a wordpress website?

whole path
#

no results are returning

glossy vessel
#

you need to add the domain to /etc/hosts

whole path
#

yeahh

glossy vessel
#

so you can scan it

whole path
#

ooh okay thank you

sullen hound
#

hey whats app @hollow stone

hollow stone
#

@sullen hound did you do something to make the machine unreachable? can't even nmap it

sullen hound
#

didn't you accepted defeat

#

no

#

i did't

#

its on my side

#

too

#

what happened

#

it nots working here

hollow stone
#

no idea, just lost connection at one point

sullen hound
#

yeah

#

what a great machine

#

and a great match

#

don't you thing

#

think

hollow stone
#

meh, i prefer playing ones i haven't seen before and looking for the flags

#

this kind of scenario is kinda silly

sullen hound
#

i have played it

#

patched it

#

and see i shall won it

#

I won

hollow stone
#

right, gg

sullen hound
#

the machine is now up

hollow stone
#

i'm not sure chmoding king.txt to 000 is legal, i think the service needs it to work properly

#

not sure

sullen hound
#

thats legal i asked the admins

hollow stone
#

k, good to know

sullen hound
#

the service was working properly

#

thorough

#

it doesn't depends on it

#

as you we cant shutdown the machine

#

because the machine is truely owned

#

by tryhackme

full grove
#

illegal

#

lol

sullen hound
#

no i asked it

#

that was legal

full grove
#

the language you used there is a little uh

#

odd

#

kek

quiet schooner
#

chmod'ing to 000 is a terrible strategy

sullen hound
#

but he still can edit the file

quiet schooner
#

It shouldn't break the king service, but I don't think you'll get the points

#

wat

#

Yeah you just chmod it back

#

But it's a really bad strategy

#

Learn to defend

hollow stone
#

the points were working all the time tho

#

but yeah, it is terrible

full grove
#

chmod 004 4head

quiet schooner
#

write only filesystem best filesystem

sullen hound
#

hmm

full grove
#

that feeling

#

when you're just waiting for a package

sullen hound
#

nope

#

what do you think @quiet schooner is it legal though

#

chmod 000

#

am i roght

#

sorry right

full grove
#

you're going to get arrested if you 000 it

quiet schooner
#

I told you yesterday to read the rules.

#

It sounds like you didn't read the rules.

#

I am now telling you again. Read the rules.

sullen hound
#

tell me the link

quiet schooner
#

It's on the KoTH page.

#

You were reported for breaking the rules

#

And told to read them

#

And you haven't

#

I suggest that you do.

sullen hound
#

i read them

quiet schooner
#

Then you shouldn't have to ask.

sullen hound
#

i didnt break any rule

#

you could challenge me

#

how is chmod 000 is against the rules

quiet schooner
#

Read the rules

sullen hound
#

which rule

quiet schooner
#

You're not understanding something

sullen hound
#

i am

#

which rule to read 1.2.3.4.5.6.7

#

which one

quiet schooner
#

All of them

#

Read them

sullen hound
#

i read them all

#

theres not chmod at all in them

#

and neither i kept the users hardening it

#

it was working all the time

#

neither i stopped a service

#

however i changed passwords which aren't against the rules

#

neither i made the machine unavailable

#

neither i modify/deleted the flag

#

neither i attacked any other user

full grove
#

then you didn't break the rules

#

like James said before, you're just using a really bad tactic

#

like

#

stupid bad

#

like

quiet schooner
#

I never said you were breaking a rule.

full grove
#

rm -rf king.txt bad

quiet schooner
#

I just told you to read them

sullen hound
#

ok i have read them

quiet schooner
#

If you don't know if something's against the rules, you don't know the rules

sullen hound
#

but just tell me one thing yes/no

#

is chmoding against the rules

full grove
#

you can tell yourself that

#

you know the answer to that

#

you read the rules

#

and you said:

theres not chmod at all in them
@sullen hound

sullen hound
#

then i can tell it is allowed

quiet schooner
#

Just remember, you're known here for breaking rules after yesterday.

dapper escarp
#

Koth rules are massively down to interpretation

sullen hound
#

yes i am known

dapper escarp
#

Eg killing someoneโ€™s shell could be deemed as attacking other users

sullen hound
#

i have been killed many times

#

by other users

#

they seemed to attck me

quiet schooner
#

It's over bois, we killed the NSA

dapper escarp
#

Itโ€™s an example as to how people view them differently

warm chasm
#

Yeah what's up with killing pts'

quiet schooner
#

You're allowed.

full grove
#

yep

gusty cradle
#

^

full grove
#

establish RCE

quiet schooner
#

But it's a bad strategy

#

Patch vulns

#

Don't have to worry about people getting king if they can't get into the box and can't escalate

dapper escarp
#

Itโ€™s a fallback for when youโ€™ve patched most ways in

#

Iโ€™m working on something thatโ€™ll allow me to add other vulnerable ways in but allow@me to patch known ways

sullen hound
#

please remove the video N3ko its slowing my computer

dapper escarp
#

๐Ÿ˜‚๐Ÿ˜‚

spark anchor
#

๐Ÿ˜‚๐Ÿ˜‚

sullen hound
#

yes it is

latent quest
#

@dapper escarp That sounds interesting.

unkempt pagoda
#

Isnt that just a backdoor?

dapper escarp
#

??

spark anchor
#

I don't know why but I laughed.

dapper escarp
#

Not a back door

unkempt pagoda
#

Youre adding a vulnerabilty only you know?

dapper escarp
#

For example. Oh this website has a luck feature (weโ€™ll use fortune as example) replace the website with a site vulnerable to something like csrf

spark anchor
#

@dapper escarp Give me that .gif I just cannot stop looking at it ๐Ÿ˜†

dapper escarp
#

Youre adding a vulnerabilty only you know?
@unkempt pagoda promotes dynamic exploitation

#

If I ever get my idea working for a koth box itโ€™ll confuse a lot of people

unkempt pagoda
#

Ohh you actually want other people to use it aswell

sullen hound
#

@quiet schooner you told me that i have been known about the report yesterday sent and i know i am aware of it thats the reason why i am asking you everytime for rules

dapper escarp
#

Yeah. Patches donโ€™t have to be just remove vulnerability

quiet schooner
#

@sullen hound If you read the rules, and take maybe 1 minute to try and understand them, you would not have to ask.

dapper escarp
#

Why not make it interesting and leave my own ways in for others to find

unkempt pagoda
#

That's pretty cool

sullen hound
#

yeah

hollow stone
#

anyone know if koth boxes are chosen randomly or is there some weird algo that makes me always play the same ones?

#

like me specifically

quiet schooner
#

They're random in public games

unkempt pagoda
#

You can select either a random box or a specific box when you start a game

quiet schooner
#

Due to the nature of randomness, there's a chance you get the same box a few times in a row

#

As the pool grows, that chance goes down sharply

sullen hound
#

i agree with @quiet schooner

quiet schooner
#

wat

sullen hound
#

nothing

quiet schooner
#

Then why say anything?

#

If you have nothing to say, say nothing.

sullen hound
#

i am just saying that you are saying right

quiet schooner
#

There are better ways to do that than tagging a mod

sullen hound
#

ok thanks for that

cobalt jackal
#

yoo

#

server is really gettin populated

#

be messing me SHELLS!!WHEREDIDMYSHELLGOOOOO

gusty cradle
#

What?

cobalt jackal
#

2500 users

quiet schooner
#

@cobalt jackal There's a reason that there's a bunch of different VPN servers

cobalt jackal
#

you know, it gets annoying when it's this slow cause now I can't even ping the box

quiet schooner
#

@cobalt jackal That's a broken VPN

cobalt jackal
#

yup, regenerated it

#

not my fault

unkempt pagoda
#

Even killing my telnet connection eh

icy cave
#

im scheduled in a koth game but cant load the page i get 404... anyone in there that can send me the game no.?

cobalt jackal
#

@sullen hound @slate crow

#

wanna reset?

sullen hound
#

i cant access the page how can i reset

cobalt jackal
#

what page?

#

oh nvm

#

oof

sullen hound
#

it might 3015

cobalt jackal
#

yeah it's too slow, I had to use the browser kali

sullen hound
#

3 minutes have gone no changes

slate crow
#

it's been a long day boys

cobalt jackal
#

welp

#

that's a gg

#

yeah there's no way you guys can get to root unless you reset

umbral dawn
#

any koth?

slate crow
#

I'm actually tryna learn, can you guys give me a hint where can I search for the way in ?

umbral dawn
cobalt jackal
#

@slate crow nmap

quiet schooner
#

@slate crow KoTH isn't the best place to learn how to access

cobalt jackal
#

yeah

slate crow
#

no actually I know how to do the enumeration stuff

#

I'm tryna find out the way you got in ๐Ÿ˜„

#

SMB ?

gusty cradle
#

@slate crow Then enumerate the machine, I'm sure you'll find some ways in

cobalt jackal
#

can't tell you mate, just look at your nmap

slate crow
#

aight

cobalt jackal
#

but there's no point in getting to root, I removed certain aspects of some files

#

unless you find a way then that's up to you

quiet schooner
#

chattr -i king.txt

#

Might have to copy over a chattr binary

warm chasm
#

no cheesy strats

cobalt jackal
#

@quiet schooner could have done that too :3

#

@warm chasm what constitutes a cheesy strat apart from the rules for koth?

warm chasm
#

@cobalt jackal No I attemted to us chattr and got kicked out by the script replacing the chattr binary

#

And it said to me no cheesy strats

cobalt jackal
#

ohh hehe

#

that's on you

warm chasm
#

I wasn't implying

#

yeah

cobalt jackal
#

you can do other stuff though :3

#

@sullen hound @slate crow gg boys

dapper escarp
#

Oh thatโ€™s production right?

cobalt jackal
#

yeah

slate crow
#

lol

#

I was in another room

#

lmao

#

I wasn't even in your room xD

#

I was playing another public KOTH while talking to you ROFL

cobalt jackal
#

wdym? I see you on the scoreboard

#

did you leave?

slate crow
#

ye I just saw it lol

#

at my notifications

#

I wasn't even in your room

cobalt jackal
#

lol

slate crow
#

I joined your KOTH accidentally

#

anyway gg

#

xD

cobalt jackal
#

lmao gg mate

umbral dawn
#

any1 koth?

sullen hound
#

im in

unkempt pagoda
#

Well thats against the rules:

telnet: Unable to connect to remote host: Connection refused
#

Someone closed ssh

sullen hound
#

no no one did

#

i can still connect

unkempt pagoda
#

Im not in the same game as you

sullen hound
#

oh sorry

#

its mean that it wasn't me

#

thank god

terse willow
#

@unkempt pagoda Given that shutting services isn't allowed, if you know who it is, drop an email to koth@tryhackme.com

#

Actually, do that either way -- send them the game ID (at the end of the URL)

#

The admins can check the logs

quiet schooner
#

moving services isn't against the rules

unkempt pagoda
#

Hmm

#

Connection refused would suggest its blocked though right?

sullen hound
#

I think @unkempt pagoda it might be available on some other prot

#

port

unkempt pagoda
#

Game ended now, so no way to check anymore

#

I'll send an email anyway

#

Thanks

sullen hound
#

No Problem

terse willow
#

@unkempt pagoda Yeah, still give them the game number
They should have the logs

unkempt pagoda
#

Alright thanks Muirland ๐Ÿ™‚

sullen hound
#

hey wanted to join

stable horizon
#

joined just as you got king

sullen hound
#

yeah

hidden pier
#

is 8080 down?

sullen hound
#

yes

#

who did

#

should be present over here

#

thats out of rules

hidden pier
#

Now both 80 and 8080 are down, guys I understand you might be trying to patch vulnerable services, but shutting down services is not allowed.

quiet schooner
#

@hidden pier It is allowed, if there's no other way to patch them.

sullen hound
#

@quiet schooner there is a way to patch 80 port

#

but they didn't do it

quiet schooner
#

Ok, I wasn't saying they did

#

I'm not in your game.

sullen hound
#

so they broke the rules

#

didn't they

viscid girder
#

sorry NSA i will up the service

quiet schooner
#

@sullen hound If you have to ask, you're not familiar enough with the rules.

hidden pier
#

That's subjective tbh. There might be a way that they don't know about

@hidden pier It is allowed, if there's no other way to patch them.
@quiet schooner

quiet schooner
#

Since the machines don't have internet, the only way to patch some vulns is to close the service.

viscid girder
#

i ahve patched port 80 :p

sullen hound
#

you again turned the port 8080 port off

viscid girder
#

no its there

#

ctive Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 0.0.0.0:3306 0.0.0.0:* LISTEN 992/mysqld
tcp 0 0 0.0.0.0:8080 0.0.0.0:* LISTEN 8059/nhttpd
tcp 0 0 0.0.0.0:5555 0.0.0.0:* LISTEN 7889/nginx -g daemo
tcp 0 0 0.0.0.0:1337 0.0.0.0:* LISTEN 6411/sshd

sullen hound
#

now restarted it

#

didn't you

viscid girder
#

no i never shutdown 8080 lol

sullen hound
#

@hidden pier reset the machine to gain access

#

who shutted down port 1337

#

there was ssh running on it

viscid girder
#

yeah i can't get in

hidden pier
#

wasn't me. I think the machine was reset right before the game ends

#

GGs guys, it was fun

viscid girder
#

yeah gg

#

what could you exploit on port 8080?

hidden pier
#

will dm to not spoil it for others

sullen hound
#

why not start a new game

#

come and join me

#

5 min remaining

viscid girder
#

cool might not be able to stay for the whole but eh

sullen hound
#

eh play fair

#

at any cost

#

@viscid girder If I am not wrong you are new to Linux

#

aren't you

viscid girder
#

no why>

sullen hound
#

the patching skills showed

#

Machine Panda

#

30s

viscid girder
#

fair enuff

sullen hound
#

what

viscid girder
#

i got to learn more tbh

sullen hound
#

me too

#

remember learning never ends till death

viscid girder
#

sorry i can't finish this game

lilac topaz
#

๐Ÿ˜„

sullen hound
#

hey reset the machine

#

@lilac topaz @viscid girder reset the machine theres a problem

icy cave
severe orchid
sullen hound
fair adder
gusty cradle
#

@fair adder Is the script on your github? ๐Ÿ™‚

fair adder
#

it will be

#

but its made to work only on windows

gusty cradle
#

SMB can be made to run on Linux, but mostly Windows machines use SMB

fair adder
#

i mean i can import platform and make it run on linux if you want ๐Ÿคทโ€โ™‚๏ธ

gusty cradle
#

Nah, I just want to review the code ๐Ÿ˜„

glossy vessel
#

^

fair adder
#

sure when its done ๐Ÿ˜†

fair adder
#

@sullen hound can you do nmap scan for me cuz i deleted nmap i forgot on what port is smb

sullen hound
#

remember my friend smb is always on 445 port

#

im in

fair adder
#

oof ty

sullen hound
#

what

fair adder
#
C:\Windows\system32>net view \\10.10.176.20
System error 53 has occurred.

The network path was not found.


C:\Windows\system32>```
#

i officialy hate windows

#

oh my

#

i forgot to turn openvpn on

sullen hound
#

haha

#

lol

#

sometimes i also do it

fair adder
#

there now it works from command line gotta make it work from python now

sullen hound
#

oh

#

does anyone know what is it -bash: /bin/chattr: Permission denied
and how to fix it

#

even as root

fair adder
#

i don't know

sullen hound
#

do you have no hint whats happening

fair adder
#

im having some errors rn

#

and im in class

#

lol

sullen hound
#

oh sry

fair adder
#

this kinda works but it doesn't at the same time tho

#

im doing multi tasking xD

sullen hound
#

hey @fair adder do you know where is king.txt

#

in Offline Machine

fair adder
#

yes

sullen hound
#

where

fair adder
#

when you do smb you can find it in directory named king

#

so try bash find / d -name "King" 2>/dev/null

sullen hound
#

i got it and also did echo NSA > king.txt and my name is there but not showing on website

fair adder
#

hm

#

hang on my teacher said something to me

#

okay im back

#

so im not sure but check /root/

sullen hound
#

hey im in windows

fair adder
#

oh

#

i forgot

sullen hound
#

even after typing echo NSA > king.txt, mY name is in there but not showing on the website

#

might be it has a bug

fair adder
#

yeah maybe idk

sullen hound
#

if thats a big i have faced it many times

#

sorry that bug not big

fair adder
#

xD

sullen hound
#

4 min remaining

#

hurry

fair adder
#

jeez its panda

sullen hound
#

@fair adder hey see i got all the flags in such few sec

fair adder
#

yah gj

#

i can't wait to show you what i made when its done

sullen hound
#

really

#

why dont show me a demo in DM

#

I wish I have a Fast Computer

#

my computer is a dumb slow with 2.4 Ghz Core 2 Duo and just 2 GB and 128 MB graphics card

fair adder
#

oof

#

wish i could help man ๐Ÿ˜ฆ

#

its done

#

i mean it works like i wanted it to

sullen hound
#

why dont you send me a demo or full version

fair adder
terse willow
#

i can't wait to show you what i made when its done
@fair adder if that's an autopwn, then no

latent crest
#

anyone playing koth ?

raven harness
#

join public program

latent crest
#

ok

fair adder
#

@terse willow its really not lol

terse willow
#

Good

fair adder
#

Its made to flex with those formated strings

sullen hound
#

who's playing koth

fair adder
#

Me not

sullen hound
#

ok

#

@latent crest are you here

latent crest
#

yeah

sullen hound
#

why not start a koth that will start after 5 min

latent crest
#

I'm not a subscribed member

sullen hound
#

no problem

#

i will do it for you

#

oh

#

do you know how to leave a koth

latent crest
#

Options --> Leave Games

sullen hound
#

join quick

#

@latent crest ready to play

#

i am going to win

latent crest
#

I'm in....I'm a noob so probably I need your hint

sullen hound
#

@remote sparrow is also in

#

in koth hint is not allowed

#

im in

latent crest
#

I don't know how to exploit MySQL so you gizz have a good time

sullen hound
#

is that ok

spark anchor
#

Great! ๐Ÿคฃ

sullen hound
#

i can't see a sad face thats why i posted

spark anchor
#

To make sure he gets sad huh?

sullen hound
#

no he will became happy if he knows

latent crest
#

let me learn about it then I'll join that machine @sullen hound can I ask for some resource ?

sullen hound
#

@spark anchor can i give him resources

spark anchor
#

@sullen hound I dont know.

sullen hound
#

to learn

spark anchor
#

Ofcourse.

sullen hound
#

@latent crest just learn primer series you will know what i am talking abou

#

everything is in that course

#

and try watching live players stream

fair adder
#

uh guys

spark anchor
#

WHAT! ELF

fair adder
#

what is the http port

spark anchor
#

How did you get here?

fair adder
#

i don't have nmap so i can't scan lol

spark anchor
#

80

fair adder
#

its not 80

#

other one

spark anchor
#

HTTPS: - 443

sullen hound
#

remember @fair adder port 80 is for http and 443 is for https

fair adder
#

@sullen hound no i mean in the koth you guys are doing

sullen hound
#

oh

fair adder
#

i forgot on what port is http

spark anchor
#

lol

fair adder
#

its not standard 80

#

i mean it is

#

but there is also 1 more

spark anchor
#

Complete the question xD

fair adder
#

eh... i go install nmap

#

SMH

sullen hound
#

theres http on it

spark anchor
#

Default http 80 & https is 443

sullen hound
#

no http on it

fair adder
#

no

sullen hound
#

theres no http on it

fair adder
#

im not talking about default @spark anchor

#

there is one more port i don't remember which one

#

smh

spark anchor
#

@fair adder Ok I got you.

sullen hound
#

which port

fair adder
#

hang on let me just install nmap i will run the scan

#

there ya go

quick flax
#

is koth a good way to learn? when you get down the basics?

fair adder
#

wait whaa

#

james is patched it ?

spark anchor
#

@quick flax Never tried it.

#

I will today.

quick flax
#

nicee

sullen hound
#

join me at

spark anchor
#

@sullen hound New Koth Game?

fair adder
#

what room ?

sullen hound
#

yeah in 5 to 7 minutes

#

just join quickly

fair adder
#

smh i don't even have gobuster

spark anchor
#

I have never tried Koth @sullen hound

quick flax
#

i will try koth later on today after work

fair adder
#

well there i joined

sullen hound
#

no you did't

spark anchor
#

@sullen hound What do we need to do?

sullen hound
#

for what

fair adder
sullen hound
#

oh

#

okk

spark anchor
#

That Profile picture lol

sullen hound
#

9 players in action

spark anchor
#

What do we need to do lol?

#

I joined it

fair adder
#

you need to have most points

sullen hound
#

for what @spark anchor

#

yes and the king

spark anchor
#

Yes for the Koth

quick flax
#

get access to the machine and find flags/make yourself king

fair adder
#

don't expect much from me ๐Ÿ™‚

spark anchor
#

I mean how can we win in this game?

#

Same here @fair adder

sullen hound
#

after 60 minutes you win

quick flax
#

xD

sullen hound
#

with the highest points

fair adder
#

idk im not on linux for now

spark anchor
#

I have heard we need to change a file to be king?

sullen hound
#

no

fair adder
#

gonna buy my self laptop on 25th may

spark anchor
#

You sure?

fair adder
#

it will be my new cyber weapon

sullen hound
#

LOL

#

he joking

spark anchor
#

Hack NASA with it

sullen hound
#

just type username in king.txt

spark anchor
#

Ohhh Ok @sullen hound Thanks.

fair adder
#

jk jk

spark anchor
#

I dont even know if I can lol

sullen hound
#

i think @spark anchor is new to linux

#

totally new

fair adder
#

reee what room is it?

latent crest
#

echo <Username> /root/king/txt

spark anchor
#

2 weeks experience only @sullen hound

#

echo <Username> /root/king/txt
@latent crest I know the command, but not the way to get in the system

fair adder
#

@latent crest echo <name> > /root/king.txt

sullen hound
#

no i have greater experience

weary marten
#

echo <Username> /root/king/txt
@latent crest ahh thanks man

sullen hound
#

thats not that way

quick flax
#

@latent crest I know the command, but not the way to get in the system
@spark anchor thats the fun part to find out

spark anchor
#

I think king.txt instead of "/"

latent crest
#

I know the command, but not the way to get in the system
@spark anchor same ๐Ÿ˜„

sullen hound
#

thats echo $USERNAME > king.txt

weary marten
#

offline wtf

fair adder
#

yah i kinda missed

#

my keyboard is small ๐Ÿ™‚

#

jeez its offline...

sullen hound
#

yes i gonna win at any cost

#

see you there

spark anchor
#

Machine is offline lol

fair adder
#

well gl guys ๐Ÿ˜‰

spark anchor
#

LOL OFFLINE

sullen hound
#

passwords will change

spark anchor
#

GLGLGL

#

Get ready to lose still

weary marten
#

leave xD

sullen hound
#

if all are afraid of Offline why not join another

spark anchor
#

LOL

#

It is offline sir

sullen hound
#

no it is online poing it

#

ping it

#

now

weary marten
#

new game?

sullen hound
#

everyone

weary marten
#

no its offline

sullen hound
#

it isn't

#

its new one

weary marten
#

i dont trust you

#

you are nsa

sullen hound
#

ok dont trust me

#

when i said trust me

#

others are enough to trust me

#

get in there everyone new gamehttps://tryhackme.com/games/koth/join/cc262c9dcdca342de2378678

fair adder
#

bruh

#

can you make more koths?

sullen hound
#

yeah why not

fair adder
#

no ๐Ÿ˜ญ

sullen hound
#

what happened

fair adder
#

what room is that one

#

panda

#

LOL

sullen hound
#

thats no room thats private game

fair adder
#

i don't have any enumiration tools except nmap

sullen hound
#

here

fair adder
#

i can't play it lol

sullen hound
#

who is here to challenge me

#

is that ok

spark anchor
#

New room again?

#

What are you doing?

fair adder
#

this is making me laugh

spark anchor
#

haha

#

I laughed

sullen hound
#

no one in there

#

whom i am with playing

fair adder
#

im in there

sullen hound
#

but you are not ready

fair adder
#

oh and one more guy

#

i can't play anyway

#

im just watching you guys ๐Ÿ™‚

sullen hound
#

then see take the machine

spark anchor
#

@sullen hound Mme coming4

#

startting in 1 hour?

pliant sigil
sullen hound
#

no it has already start @spark anchor

spark anchor
#

ARRGH NOOO

#

I WAS CONFUSED

sullen hound
#

and as always i am king

#

and all vulnerabilities patched

spark anchor
#

You have played this.

#

That is why you know how to get into this.

#

We are new.

sullen hound
#

๐Ÿ˜ญ

fair adder
#

stacking up on streak? @sullen hound

sullen hound
#

no one here to play with fairlt

#

yes i am on a streak

fair adder
#

wonna play vs me on production?

sullen hound
#

vhy not

fair adder
#

okay

#

when i get back to debian then we play

sullen hound
#

uh

#

when

fair adder
#

i can barely do anything with this windows smh

sullen hound
#

today or any other day

#

do you have windows

fair adder
#

yah im on windows

#

parrot security maybe..

#

hang on

#

im looking at distors olol

sullen hound
#

hmm

#

which windows

spark anchor
#

I hate you NSA

fair adder
#

im on windows 10

sullen hound
#

great is it fully patched

fair adder
#

cent os

#

looks

#

good

spark anchor
#

@sullen hound Hey, Why ? ๐Ÿ˜ญ

#

๐Ÿ˜ญ

#

๐Ÿ˜ญ

#

๐Ÿ˜ญ

#

Let us play!

#

It is my first time

sullen hound
#

why not

#

play

spark anchor
#

Haha

#

nice joke

#

Play

sullen hound
#

i didn't odered you to leave or don't play

#

everything is yours

spark anchor
#

You patched it ๐Ÿ˜ญ

sullen hound
#

yeah

#

being fastest

spark anchor
#

guide me what to do

sullen hound
#

sorry guides not working here

#

thinking wisely might work

#

and i am opening one vulnerability

#

now think wisely and act wisely

valid light
#

@sullen hound are you in a koth with me (?)

#

i'm in a public game and no one is doing anything i think (?) :(

sullen hound
#

give me link i will see

valid light
#

i think everyone else is afk or something

latent crest
#

where should I need to focus Samba or tomcat @sullen hound

valid light
#

i don't want an uncontested blue ribbon D:

#

@latent crest which box are we talking about? they both sound intersting services to take a look at

latent crest
#

@valid light Panda

spark anchor
#

@valid light These guys are beating me ๐Ÿ˜ญ

#

๐Ÿ˜ญ

valid light
#

@spark anchor oh no :(

#

i'm sad that no one is beating me in this public game

spark anchor
#

That NSA guy is playing for a long time.

#

And today Is my first day in KOTH

valid light
#

aww man, i'm sure you can do it!

spark anchor
#

He knows the machine's vuln's.

#

๐Ÿ˜ญ

valid light
#

which machine are you on

sullen hound
#

i said one vulnerability is still open

valid light
#

panda too?

sullen hound
#

@valid light give me your koth join link

valid light
spark anchor
#

Panda @valid light

valid light
#

@latent crest for Panda, you'll find something interesting in Samba

latent crest
#

thanks

sullen hound
#

@valid light If i am not wrong it is not allowed to give someone hint

valid light
#

oh, alright my bad

sullen hound
#

but to give someone learning resources

#

now listen

valid light
#

?

#

Are you NSA in my koth room LOL

sullen hound
#

@latent crest and @spark anchor if you want to get in offline machine

valid light
#

I assumed that's you

sullen hound
#

just make a virtual machine of your own nad try to hack it

#

if you succeded in hacking it then you would hack it

latent crest
#

Nope I'm good here

sullen hound
#

let me get into the machine

#

and then see

#

how its done

valid light
#

?

sullen hound
#

within seconds

valid light
#

which machine are y'all talking about

sullen hound
#

OFFLINE

valid light
#

i didn't patch anything

#

you can get in

#

i don't want to patch anything

sullen hound
#

why

valid light
#

it's not fun

#

no one's got any flags

sullen hound
#

now go and see the page and see how i am going on astreak one after another

#

1st flag

#

got

valid light
#

good for you

sullen hound
#

sec flag got

#

third got

spark anchor
#

Why do I think that @sullen hound you have stored flags in a notepad file? You got 3 flag within 10 seconds. Not possible.

#

@valid light Is it that easy?

sullen hound
#

because im the fastest in offline

#

4th one got

valid light
#

@spark anchor yep really easy

spark anchor
#

---___---

sullen hound
#

5th one got

#

only three remaining

#

someone messing with me

weary kindle
#

what a surprise

sullen hound
#

got another one

#

got another

valid light
#

LOL @weary kindle

sullen hound
#

got the last one

#

thats how game is played

#

now changing users password

weary kindle
#

So what you're telling me is KoTH is a game about bragging in as special discord channel? I've been playing wrong this whole time! ๐Ÿ˜ฒ

valid light
#

@sullen hound how do you have 9 flags? there's only supposed to be 8 (?)

sullen hound
#

i am also astonised

#

what happened

#

really what is that

valid light
#

LOL you tell me

sullen hound
#

might be that game error

#

or either i pasted other machine flag into it

#

in hurry

gusty cradle
#

So you store flags? ๐Ÿ™‚

weary kindle
#

So you just have a text file with all the flags then? kekw

sullen hound
#

no you can check

#

me

#

i was hacking two machines at a time

#

one was panda

#

and one food

#

and other this offline

terse willow
#

That's three...

gusty cradle
#

That's three machines

sullen hound
#

yeah

gusty cradle
#

@sullen hound You said you were hacking into two machines?

sullen hound
#

ok sry for that

weary kindle
#

Ah yes, the great gigabrain strategy of playing 3 games at once when you can only join 2 lobbies at a time

sullen hound
#

3 one ended

#

now how can i restart it @weary kindle

latent crest
#

wpscan --url 10.0.2.4 --wordlist /root/Desktop/rockyou.txt --username po is my command alright ?

valid light
#

seems right

sullen hound
#

dear that commands only work if there is a wordpress on that site and a login functionality enabled

valid light
#

@sullen hound btw did you think you kicked me out lol

#

you didn't

#

just saying

sullen hound
#

on which game

severe orchid
#

does anyone know how to priv esc in panda

#

i mean get shell from wordpress

#

as po

sullen hound
#

@weary kindle remember I can hack things very quickly but forget them within seconds

gusty cradle
#

...

valid light
#

bruh

#

offline lol

#

@severe orchid hmm i'd like to try tbh

sullen hound
#

dear while talking i changed all the password of the machines of offlines

valid light
#

you think i would let you take a shot at it without persistence

#

lol

sullen hound
#

in which machine tell me and link

valid light
#

lol doesn't matter

#

8mins to end

#

offline

spark anchor
#

-_-

#

I got 1 flag

#

lol

sullen hound
#

the thing I dont know is how to became king in Offline Maching

#

@spark anchor try more you will find all of them

valid light
#

@spark anchor Panda? how much longer is that room available for ?

sullen hound
#

round about 13 minutes

valid light
#

mm too short

#

lemme know if y'all playing another game

spark anchor
#

YESSSSSS !!!

#

I am getting sommething in me now

valid light
#

nice!

viscid girder
valid light
#

@viscid girder send invite link pleasee!

sullen hound
#

give us joining link

valid light
#

^

viscid girder
latent crest
sullen hound
#

im in

#

try wpscan -h

#

too see what argument are you passing wrong

#

i am going but will be back soon

weary kindle
latent crest
#

ok

fleet apex
#

The king file cant be altered. Any help? I have root

fair adder
#

@fleet apex what are you trying and what's the error?

fleet apex
#

I am trying "echo Painforpay > king.txt" but the contents dont get changed. I dont have an error

hollow stone
#

someone might be overwriting it, you're not the only person in the game

fleet apex
#

yeah, i think its a script

#

But how can i stop that?

hollow stone
#

find it and kill it i guess

valid light
#

i'm pretty sure someone removed and messed with the flag

#

lol

#

i voted to reset

spark anchor
#

๐Ÿ™‚

valid light
#

was it you XD

sullen hound
#

sorry im late

#

where

fleet apex
#

yeah

#

we've reset it