#koth
1 messages Β· Page 29 of 1
ok
who closed port 9001
everyone Who closed the port 9001 port
if i am not wrong that was against the rules
Is this for prod?
As the maker of that room, closing 9001 is allowed
imma reset again
@sullen hound Dan created Production
Dan let's reset :D
It literally says "backdoor", it's not a real world system critical service
without removing port the port
They require password to login right?
@spark anchor Public key
try googling
@gusty cradle Anyone can login with that?
No
@spark anchor Public key
you can authenticate with a private key provided the public key is in authorized_keys
@sullen hound if you were a sysadmin performing an internal audit, would you leave a service with the banner "Skidy's Secret Backdoor" ?
no it requires pass because someone removed it from authorized_keys
Then you wouldn't make it past your probation
@spark anchor You can't login with the public key, the private key(id_rsa) is the one you're looking for
there is a room for ssh i guess @spark anchor
@weary kindle even though we can change the password
make sure perm is right
of Ashu
i m talking of the machine
@spark anchor Is it encrypted? Did you set the permission to 600? Did you put your public key into authorized_keys?
I set the permission but
??
@spark anchor Google can guide you π
Hm. I need to know more about SSH & authorized keys
Like you said, putting public key in authorized keys
i honestly don't know how to work around the patches anymore
whoever locked me out can you put my public key back in there LOL lemme find the flags and i'll leave you alone
@viscid girder PLEASE
fun π
last vote remaining
Why resetting again & again?
machine not respondin
What does ashu@ubuntu at the end of .pub mean?
It means that the key belongs to ashu on a machine which has the hostname of ubuntu.
me too
Can you @gusty cradle tell me that how can someone type in my terminal "logout" ?
one thing left was privilege escalation of it
anyone know how it is done of production machine
@spark anchor Please stop pinging me and google your questions, I'm in the middle of coding something π
Are you playing two koths at the same time @sullen hound ?
Ah srry
yes because thats new to me
π€£
i think i patched them all by now
Swapped the rce from root user to the bunny user
why lphout againa nd agqain
hey there is not a single RCE vulnerability in the machine
WHO SET THE PASSWORD?
not be overefficient
Yea @sullen hound
production
Yes
nah i was talking about spacejam
Getting logout again and gaggin
i m not in spacejam
SSL_ERROR_NO_CYPHER_OVERLAP
TLS handshake failing
yeah
theres something fishy going inside it
hey
but the virtual machines did not terminated
anyone online
it has shifted from https to http
whats happening does someone know
@terse willow can you help me with this
Hm?
THM Hacked lol
@terse willow You came right when he called. Wow!
Sounds like the site is being upgraded. I know Skidy was intending to implement Cloudflare sometime this week
If it's an error with the TLS, that might be it
@terse willow Are you sure its being upgraded
@sullen hound Yes, the admin's are aware of the issue and are working on it
@gusty cradle I was able to access the website with tor network
if that was upgrade then i also should not reach it with even tor
@sullen hound The website is back up
no it isn't
Dear @terse willow Remember Tor Browser never ignores such small things due to high privacy
website not coming up on my side
If itβs transferring to cloudflare then DNS will play a part in it - due to how tor works would explain why it might work on there and not in your browser
"dear"
....
You have no idea what TOR does, do you?...
Nothing to be done by any one then just waiting
high privacy
ah yes, the browser made by the CIA is known for it's high privacy, never mind the fact you can de-anon anyone if you control an exit node
^
yes thats true
but even if you are in a network of somebody such as wifi without the control of tor exit nodes you may see his all traffic
Ok Tor also stopped
@weary kindle I dont think Tor Browser is made by CIA
Literally the first result.
working again
@sullen hound if you control the WiFi network, you can't see the traffic through tor.
π€©
@quiet schooner if the victim is in the same network then why cant we see the traffic going through the tor
Because it's encrypted?
Because HTTPS traffic is always encrypted, that's what the S means?
i know thats encrypted
It's not suddenly decrypted if you're on the same WiFi network
i know that
but the router is the main thing from where the traffic is going to and coming from
but it's still encrypted
It's encrypted between your device and the webserver you're talking to.
It might be encrypted again between your device and the router.
Ok the purpose of my sayiing was that if the person gets hold of the router he will be able to see all of the traffic
in my sense
anyone got a game going>?
@sullen hound How the traffic is still encrypted? Explain your "logic".
If you're going to make a statement related to cybersec in a cybersec discord, you'd better make it correct otherwise someone will call you out.
sorry i have to go but i will continue back
@fair adder
you said to come to koth i am waiting
come on
quick 5 minutes remainin
what room ?
No point if the game is over
what
If there's 3 mins left in the match
it starts in 3 m
no 3 minutes to start
yeah
@fair adder if i weren't hacking multiple machines at a time the bug wouldn't be reported
why try hard multiple koth lobbies
hey the machine is space jam
if i am right thats a vuln
bruh even if you were why are you telling that thats liturally spoiler
When do new koth boxes get released?
When they are ready
i am king @fair adder
without even spoiling
i am not a spoiler nor a cheater how many times i have to tell you
You literally spoiled what needed to be done on the box in here
You're playing prod right?
no space jam
i not even turned the port 3000 port off
@sullen hound you liturally just spoiled again
Regardless, you were asking for help with Prod priv esc earlier: this will help
pkill -9 -t $(tty | sed 's/^.....//')
is this privilege escaltion
yeah
π
@fair adder I didn't spoiled the box and if i did give me proof of it
Either that or run
sudo /usr/bin/chattr -i /root/king.txt
Either the message was deleted by your or a moderator @sullen hound
you said you didn't turn off port 3000 and that port has ||vuln||
wait a second if the port 3000 is off i don't turn it off
don't blame me all the time
SMH
lol pts/1 00:00:00 wget https://cdn.discordapp.com/attachments/554713196804440101/710172199985610812/chattr
@sullen hound It's not a bug
Deleting because of spoilers.
There are only two flags on Spacejam(root and user flag)
oh
@icy cave imagine thinking KoTH boxes have internet
yeah
i know π€£
You can report bugs without spoiling @sullen hound and as @gusty cradle said, that's not a bug irrespective.
@sullen hound you spoiled 3 times in less then 15 minutes π
lol they deleted
@fair adder I am waiting for you to gain access
no i wasn't warned about spoilers
and didn't know it was one
bruh im playing this room for the first time
oh
lame execuse
@fair adder
hey rm that file is out of rules and terrible
replace rm with removing
i think so
mhm?
am i right @brazen cloud
You'll have to give more context @sullen hound
It is out of Rules to remove or deleted the king.txt and root.txt file
^
really
Yes?
Read the rules
I keep telling you to
You've been reported for breaking them already
π
i read it but there's nothing like king.txt
Then why do you think it's against the rules?
Don't make claims unless you can justify them
@sullen hound you seem to have an issue with reading rules
okπ₯Ί
Now go read the rules and be back bro
It is out of Rules to remove or deleted the king.txt and root.txt file
@sullen hound root.txt is a flag right? So no you canβt delete.
So you read the rules now? @sullen hound
i already read them
Oh good
yeah
The rules are clear cut. If youβd read them you would know you canβt mess with those files
now i do know them
@sullen hound its not removed its moved
@fair adder you canβt move flag locations
you typed remove
Just to get it clear, is it allowed to change perm of king.txt to 000?
@fair adder
the f did you do to chattr @sullen hound
@brittle merlin That's a stupid strategy, but you're allowed.
thats disbale
there its back @dapper escarp i just moved root to /home/
...
sorry disabled
You can do anything to king.txt just not the flags
Ah, I don't do that. But I have seen it many times. Don't know how to bypass that tho
xD won't happen again
While Iβm here @fair adder reread the rules before you get banned from the game mode
okay
The guy who does not sound like human.
You need to see general chat to understand this.
rule 7 is my favorite ... Scripts that automatically hack and/or harden the machine are forbidden
My favourite rule is all of them
@dapper escarp i reread them 2 times
and I 15 times
Considering you moved a flag @fair adder
You need to understand
@quiet schooner
@sullen hound and still not following them.
I'd go through them again
i am just talking
i was about to type i will go throught them 1 more time π
and did followed the rules
then how are you saying @spark anchor
for GOD sake please blaming me everyone who says i am autopwning

@grand ember There we go
LOL
Man give the kid a break @spark anchor π€£
Ah.. Man @sullen hound Sorry, I am just going way too far.
That wasn't the right attitude.
Thank you, it can be kept civil.
what
@sullen hound π
who want to play another koth
@sullen hound You are the best
i appreciate your love
but it is better for both of us to focus on tryhackme
in the best interests of both of us
Yes
@fair adder join the game https://tryhackme.com/games/koth/join/b4eaf4d626753933b079518a
I am sorry for my previous behavior. I don't know what happened to me
WDYM big heart to deal.
π
he also has big brain π
Yes

Spec link?
bruh why you bully you put challenge game even last game
:optional:
uf
hey im gonna go to the store π
Hint?
@spark anchor FoodCTF is all about enumeration
Ok
and the machine is mine
nope
π
eh running nmap scan
execuses
im kinda taking time
no problem take time
enum4linux says "
Use of uninitialized value $global_workgroup in concatenation (.) or string at ./enum4linux.pl line 437.
". This error is bugging me from days. Searched Internet but no help
same as here
I get that when smb is not on a domain
but remember it only works if you have port 445 open
@sullen hound removed the page on higher port?
which page
oh you didn't
which page tell me
who is kiransau?
idk
Hey, @quiet schooner Why you joined.. NOO
damn you patched it @sullen hound
we are dead if you joined
hahahaa
Oh really?
yes i did
Rules being broken?
patching isn't against the rules
yah i know
Yes it isn't
no it isn't patching is part of blue team @spark anchor
I didnt say that you did
@sullen hound next room production i create π
I was asking Ninj
jk i don't want to pick a room im 2 dumb
https://tryhackme.com/games/koth/join/e9d26d125ebc8979ebfd37df here the one starting in 11 min
now again hacking 3 machines at a time
Bye
me going
I should do THM boxes. I dont have standard in front of you guys π¦
i just started doing few 2 :jo:
@fair adder you know python
who are monitors called
ohh i can't access to port 22
on which machine
food
link
you are a king there
@sullen hound you done fortune before/
He's in your lobby NSA
3085
SSH is still open
might be mine creds are worng
yeah
many things are still not patched xD
@quiet schooner but i don't know how...xD
na its fortune
There's a few games going on
@quiet schooner yes
@fair adder whats your username on tryhackme
@sullen hound slavkosmith
reset the fortuna
@sullen hound nice lol
so are you karma
Eh, don't worry, she might reset herself π€·ββοΈ
@sullen hound What's wrong with it?
password changed
but i saw many people do so
Resets are for if the box is completely broken
Or because someone has broken the rules
If you harden the box, that's allowed
oh
They're not for if someone has hardened the box and you're throwing a hissy fit at not being able to get in
That's just good strategy from your opponent
If you harden the box, that's allowed
@quiet schooner what is this ? lol
i just changed the password and pached some vulns
That is allowed
Shutting services off is not
As long as the box is still functioning, there is no reason to reset
Even if no one else can get in
Especially if no one else can get in -- requesting a reset then is just poor showmanship
so what we do now ?xD
If it's the machine that James hardened
Then you sit and wait for the clock to go down
new koth who's in
What box, how long?
in 5 minutes
here is the link as koth is 60 minutes long
are you in james
is there a 4th way in to food?
is there possible to change ssh password for food without login ?
i mean right before now i was able to login but now i m getting permission denied..
i sounda like a weird for you ...
@raven harness The box ended?
But if someone roots it, you can change the password
is there possible to change ssh password for food without login ?
i mean right before now i was able to login but now i m getting permission denied..
i sounda like a weird for you ...
@raven harness nope
@quiet schooner where are writeups for KOTH Machines
@sullen hound They don't exist for most of them
which ones exists
@quiet schooner I would change the pw if i got access into the server
but i cannot login into the server even i have got creds i m sure that are valid
@sullen hound That's on you to research
@raven harness Yeah, so someone else probably changed it
I changed the creds sry
You're allowed @warm chasm
can i post writeups ?
@sullen hound Remember, relying on writeups is cheap
@weary marten read the rules.
so it means no further access into that server @quiet schooner
yeah
@raven harness No?
@raven harness @warm chasm You are allowed to patch every vuln. You're encouraged.
When I play, I patch every vuln.
No I was just saying that they should still be looking
ok thanks
@quiet schooner Why dont add the points to public profile
Stop tagging me every time you have a question
according to my knowledge the First KOTH Game was play on march6
And?
and now its getting popular and popular
so why dont add its point to public profile
will there be also like tournament in future?π
You missed one
There might be another
I think there was like $100USD at stake over it?
ohhhh
was it live where non player could also spectate them?Like gaming tournament
Some were livestreamed
Join me as I compete in the final of the TryHackMe King of the hill tournament. This game was extremely fun as we were playing against winners from each heat on the latest and hardest Windows box in the box pool!
Check out TryHackMe here:
https://tryhackme.com
Check out my s...
small question, i think i missed a bit of background knowledge, why is the box called offline and are all the usernames names of offlinetv? i think i missed a thing or two
yeah, i get that haha
but is there a special reason why they chose offlinetv?
Ah cool!
the requirement for the box was
- Theme it
- Include X number of vectors
Super cool!
- make it fun
i would love to try it one day but yeah hahaha experience
I think there was like $100USD at stake over it?
150$
Starts in 20 min: https://tryhackme.com/games/koth/join/c0a67a5990704d0a608c87a2
@gleaming reef Noob
@gleaming reef Why reset the box from the beginning?
@lilac topaz you can reset
press reset π
@lilac topaz happy?
Thank u
@gleaming reef Thank for the fight π
how the hell could u reset reboot the box!! π€·ββοΈ
reset? what you mean?
Reboot π
but i couldn't write, i need 10 more minutes
I still wonder how that black magic works π you must have placed a backdoor somewhere
could not find it.
or the box had one in the first place π
hehe
@harsh obsidian you too
@harsh obsidian you too
@warm chasm question: I've been working on a thing. did you start getting hackers quotes on your terminals?
Yeah it was super annoying. Nicely done
Thanks. I've been busting my hump on that one. The nice thing, though, is it only displays. It doesn't actually insert in to your commands.
Yeah I realised. It was very disruptive nonetheless
https://tryhackme.com/games/koth/join/c9a776b3b714f708cc0ae716
Space Jam in 3 minutes
join here 5 minutes remaining
join fast
2 minutes remaining
How so? @fair adder
chat log says otherwise
you violated rules on me, then you did the same thing a day later
i will find a different game
what exactly did he violate?
i didn't
Closing services
banhammer
it was done only one time
See how easily trust is violated?
and I never did it again
and here you are trying to deny the whole thing. uncool bro. i will find others to play with
Once you breach someone's trust, it's hard or impossible to earn it back.
enjoy the evening
It only takes one time for a lot of things - trust is a good example of such
@quiet schooner i didn't have a play
THM staff must make rootkits, to ban users on malicious actions: like iptables, firewall-cmd, ufw, systemctl, service
@sullen hound wat
hey i didn't play for a while
@floral kernel Some of those aren't against the rules
like?
You can restart a service or patch it by replacing it with one that works
EG webserver with a vuln? Kill it, replace with python server on the same port
That's why it's against the rules to not replace
blue team > red team, change my mind π
once means always
You broke the rules that time when you broke the rules
You answered your own question
@quiet schooner but didn't broke them after it
Ok, but that doesn't restore people's trust in you
This seems like an abhorrently reoccurring conversation
@sullen hound https://en.wikipedia.org/wiki/Trust_(social_science)
In a social context, trust has several connotations. Definitions of trust typically refer to a situation characterized by the following aspects: one party (trustor) is willing to rely on the actions of another party (trustee); the situation is directed to the future. In additi...
and I don't close services after my 1st mistake
Don't expect everyone to trust you.
Ok, great.
That's not going to restore the trust you violated
I recommend you accept that, and move on
Arguing it with me is pointless
I shall try my best to keep my 1st mistake my last mistake
It's something about people you will just have to understand. Once you break someone's trust, they won't trust you easily.
I recommend you accept that, and move on
@quiet schooner
Ok
Please don't bring it up again, this is a formal warning under Rule 2 @sullen hound
π
@floral kernel Atleast you could play koth with me or you couldn't
im playing brotha
what it is
ha?
what do you mean by brotha
brother/fella
Ok
yes, you changed user's password so im locked out
lets do another game
sure
can you give me some minutes
finish the game first
@floral kernel There's other ways to get in when someone changes a password
yeah ik
@quiet schooner what are they
found 3 ways till now
is there any rule of thumb, like every box has X user ways and Y root ways?
3-4 minimum
i see
okhh
just give me round about ten minutes @floral kernel we will continue a game
or start another koth
just give me round about ten minutes @floral kernel we will continue a game
@sullen hound to dump the db? π
any1 using Arch-based distro, here?
sure
come on my friend lets do it
Mind if I join you?
word, thanks
@harsh obsidian you can say anything to me I shall never mind
@stable horizon Hey, don't start that again
Ok
is my donut here
Just wanted to compile my rootkit on the box but the kernel headers are not installed
Yeah sure
ayeee my boyy killing it again @rancid pewter
Yeah mate, made a rootkit to be sure to win every game
I'm impressed. I'm busting my ass to figure out how to take king back and I've got nothing
yea well it takes years of experience lol
Im not on the box anymore
Something you have going still keeps you as king
Yeah you know I got a little script that run 50 thread in 5 process so 200 thread constantly brute forcing the king.txt
NICE!!
Yeah you know I got a little script that run 50 thread in 5 process so 200 thread constantly brute forcing the king.txt
@rancid pewter compiled binary or bash / python /etc?
C
So compiled binary
I got a rootkit ready too just need to compiler it for specific kernel version
A game starts in 15 minutes: https://tryhackme.com/games/koth/join/b7a844c4560c639e2c6ae76b
@harsh obsidian Having some problem getting king, this time it a rootkit
I think our respective methods are fighting eachother so hard that the system can't find a king lol. neither of us have gone up in points in a couple of minutes
And I think my method over tasked the system. Gonna have to adjust it...
I think you made a fork bomb or something can connect to ssh
I'll vote a reset
You might want to verify your script seem like a fork bomb
It's looking fine on my connections. I'll nerf it a bit next time I run it; I'm not trying to kill the box
I gave another reset vote; I won't run that one again until I figure out wtf
Funny little thing that sometimes works against newbies:
echo -n "I" > /dev/pts/3;sleep 1;echo -n " am" > /dev/pts/3;sleep 1;echo -n " in" > /dev/pts/3;sleep 1;echo -n " your" > /dev/pts/3; sleep 1; echo -n " shell" > /dev/pts/3;
I've got something like that but every 4 seconds kicks another quote from hackers to someone's shell
myDonut used that once against me and i totally fell for that
I got some technique to write on someone else shell but I cant see anything
lmfao
I got some technique to write on someone else shell but I cant see anything
@rancid pewter oh i thought that's what you did
exec >/dev/pts/PTS NUMBER 0>&1
@rancid pewter I've been looking in to that myself....is that how you get tetris going?
Or nyan
Nope I got a C script to run on other tty
Won't this work?
./nyan > /dev/pts/n.o ?
Yes but with my tetris script I wont get key input
Gotta work on that then ^^
Btw the way you write on someone's shell, it wont run that written data,right?
So how's that different from the one that i mentioned
Yes with exec you can run command
Oh
But you cant see anything and it will kill your terminal when the people exit
I think @sullen hound left us to our devices....
Won't this work?
./nyan > /dev/pts/n.o?
@nova tide One of my recent favorites is: echo "Ah ah ah you didnt say the magic word" >> /dev/pts/$x
yeah
@nova tide One of my recent favorites is: echo "Ah ah ah you didnt say the magic word" >> /dev/pts/$x
@harsh obsidian yeah i have seen that π
Or just aliases to a simple file or may be urandom
And make ppl rage
I figured a nice little Jurassic Park reference could be a bit of fun
I like a lovely little rickroll in the JS
Or just aliases to a simple file or may be urandom
@nova tide I love aliases. I only use that when I'm in the mood to be a super dick
I like a lovely little rickroll in the JS
@quiet schooner That's a GREAT idea!
I like a lovely little rickroll in the JS
@quiet schooner i wish i could see you in action someday
That's why i want to watch you in action
When you made 20%+ of the boxes, there's a good chance you can patch the vulns after rooting it
Lol. watch a live stream somewhere
Missed when you went against szymex
This is what happens
Can't be dethroned if no one can get a shell.
Well you can't just patch all of them at once
You can patch hackers in under a minute
Can't be dethroned if no one can get a shell.
@quiet schooner Hackers takes time
Oof, James pulling the big guns out
Speed patching
I resisted the ALL ALL sudo creds I have for hackers and food. That's no fun.
Missed when you went against szymex
@nova tide lol, me and koth aren't the best combo
Well it's just fun to watch you guys go against each other sometimes
Specially if someone is streaming and everyone is in voice channel
There's exploits on hackers that only a few people have found
I resisted the ALL ALL sudo creds I have for hackers and food. That's no fun.
@quiet schooner but still can't seem to get a shell on tyler, hmm
If you guys plan to play again sometime i would love to watch instead of joining in
I mostly show up in KoTH when people need to lose.
lol
That's fair
koth online
cool koth game
@sullen hound did you path the box?
which one
Panda
why not
i done it too
Good luck with that
im gonna go complete few rooms
cuz koth isn't going to get my skill up if i don't know how to play it
cough cough hmm
anyone playing koth
me no
why dont join here
hey @fair adder i Never bully anyone in my life
it was a joke for you dominating on koth everytime
Until they come up against someone who knows how to patch and how to defend
@fair adder see #544951750801752079...
hey @fair adder leave that game
and join here in 5 min https://tryhackme.com/games/koth/join/d1ad32a7d6cfd047a1d523fa
yeah seems nice
anyone playin koth
join here starting in 10 minutes
What box?
Panda
That guy doesn't patch anything other than changing passwords
lol
lmfao
@fair adder what happened did i did something wrong
what happened
please remove the gif my computer stuck at such gifs
wut
ah soz
thanks
hey @fair adder there is still a vulnerability open in that panda box
why not get in
i cANT fIND
there is one
7 members all in line
now 8
1 minutes remaining
Why?
ok
Don't spoil the box
ok
Why can't be king of the game? I earned more flag than others but idk why the second player is choosed? π€
@floral snow Did you enter your name in the king.txt file?
@floral snow King doesn't mean first place
King is the name in the /root/king.txt file
@floral snow Please read the rules, all the info is there
Okay
Please, how can I bypass "command redirection forbidden"?
anyone game?
7 mins 'til start: https://tryhackme.com/games/koth/join/08eb12d81c1a43632de0e704
@full grove come hack with meeee β€οΈ
what is this machine lol
owo
π
HI π
I'll give you a bit of time before I nuke the vulns though
I closed one only π
what vulns lmfao. all i've got is a random decrypted b64 string and what I believe is an ssh key lol
i need to practice more
Dont worry @livid mountain I will take back my place as king
@fair adder if it was easy to get and posed a threat to me, maybe that was it π
XD
o/ birb
@fair adder decoded base64 string
are we allowed to run scripts to maintain king ?
mhmm
You're allowed to go pretty crazy and use root kits if you'd like
yes, decoded. It isn't a flag so /shrug
The primary goal is to provide an avenue for growth
and sometimes getting ya shit kicked from someone who runs a rootkit is best lol
Only real rules are no autopwn and you can only close off backdoors. Essential services have to stay up, you gotta patch 'em
Depending on the box, could be both lol
That too xD
Would removing the vulnerable php code count as patching?
I guess you could patch the code ye
I mean would it still work as intended
@unkempt pagoda The test tends to be "Does it work for a genuine user?"
Hmm
Thanks for that tetris shell @rancid pewter :p
No problem
lol
Seem like my rootkit is working on every linux box
Im reading a book on rootkits. Pretty interesting so far, but a lot of the asm stuff goes over my head
Instant tetris on login :p
I havent done any asm to make my rootkit @fair adder
It's typically for making the super ring 0 kernel level kits π
and cryptors
do any of these koth boxes have steg on the images? I doubt it, but it be funny if one of them did lmao
not sure
So many images to check though
but i havent slept in 30 hours π«
would it be possible to go into a solo koth just to find vulns?
:|
fair lool
What ?


and it will x