#koth

1 messages Β· Page 29 of 1

valid light
#

yep

#

need 1 more to hit reset

#

@sullen hound can you press reset lol

sullen hound
#

ok

#

who closed port 9001

#

everyone Who closed the port 9001 port

#

if i am not wrong that was against the rules

valid light
#

wasn't me

#

lol

weary kindle
#

Is this for prod?

valid light
#

mech keeps kicking me out !!

#

yeah prod

weary kindle
#

As the maker of that room, closing 9001 is allowed

valid light
#

imma reset again

sullen hound
#

who said

#

there is a patch

#

available

gusty cradle
#

@sullen hound Dan created Production

valid light
#

Dan let's reset :D

weary kindle
#

It literally says "backdoor", it's not a real world system critical service

sullen hound
#

but theres a patch of it

#

it can patch it

spark anchor
#

@weary kindle What does id_rsa.pub mean

#

What is .pub

sullen hound
#

without removing port the port

spark anchor
#

They require password to login right?

gusty cradle
#

@spark anchor Public key

sullen hound
#

try googling

spark anchor
#

@gusty cradle Anyone can login with that?

gusty cradle
#

No

valid light
#

@spark anchor Public key

spark anchor
#

I tried googling but could not find much

#

Public key requires pass.

valid light
#

you can authenticate with a private key provided the public key is in authorized_keys

weary kindle
#

@sullen hound if you were a sysadmin performing an internal audit, would you leave a service with the banner "Skidy's Secret Backdoor" ?

sullen hound
#

yes

#

but with something else

valid light
#

no it requires pass because someone removed it from authorized_keys

weary kindle
#

Then you wouldn't make it past your probation

gusty cradle
#

@spark anchor You can't login with the public key, the private key(id_rsa) is the one you're looking for

raven harness
#

there is a room for ssh i guess @spark anchor

spark anchor
#

@gusty cradle I did try with id_rsa private key. It requires pass too.

#

😭

sullen hound
#

@weary kindle even though we can change the password

raven harness
#

make sure perm is right

sullen hound
#

of Ashu

spark anchor
#

They are sir @raven harness

#

Only readable by Root

sullen hound
#

i m talking of the machine

gusty cradle
#

@spark anchor Is it encrypted? Did you set the permission to 600? Did you put your public key into authorized_keys?

spark anchor
#

I set the permission but

raven harness
#

??

spark anchor
#

But dont know about the rest

#

only if anyone could guide me

gusty cradle
#

@spark anchor Google can guide you πŸ™‚

spark anchor
#

Hm. I need to know more about SSH & authorized keys

#

Like you said, putting public key in authorized keys

valid light
#

i honestly don't know how to work around the patches anymore

#

whoever locked me out can you put my public key back in there LOL lemme find the flags and i'll leave you alone

#

@viscid girder PLEASE

sullen hound
#

just do one thing reset

#

it will be ok

#

but be fast

viscid girder
#

fun πŸ™‚

valid light
#

i already reset lmao

#

i just wanna hunt the flags, i only found 2 XD

sullen hound
#

last vote remaining

spark anchor
#

Why resetting again & again?

sullen hound
#

machine not respondin

spark anchor
#

What does ashu@ubuntu at the end of .pub mean?

gusty cradle
#

It means that the key belongs to ashu on a machine which has the hostname of ubuntu.

spark anchor
#

Yes finnaly

#

ea got it @gusty cradle

#

THanks

#

LOL

#

Someone messing with me

sullen hound
#

me too

spark anchor
#

Can you @gusty cradle tell me that how can someone type in my terminal "logout" ?

sullen hound
#

one thing left was privilege escalation of it

#

anyone know how it is done of production machine

gusty cradle
#

@spark anchor Please stop pinging me and google your questions, I'm in the middle of coding something πŸ™‚

unkempt pagoda
#

Are you playing two koths at the same time @sullen hound ?

spark anchor
#

Ah srry

sullen hound
#

yeah

#

i won 1

unkempt pagoda
#

Youre not winning this one πŸ™‚

sullen hound
#

yes because thats new to me

unkempt pagoda
#

You had a root shell though

#

within a minute

icy cave
#

🀣

sullen hound
#

im in

#

but dont know how to escalte privileges

unkempt pagoda
#

i think i patched them all by now

#

Swapped the rce from root user to the bunny user

spark anchor
#

why lphout againa nd agqain

sullen hound
#

hey there is not a single RCE vulnerability in the machine

spark anchor
#

WHO SET THE PASSWORD?

sullen hound
#

not be overefficient

spark anchor
#

Yea @sullen hound

unkempt pagoda
#

On spacejam?

#

Or on production

sullen hound
#

production

spark anchor
#

Yes

unkempt pagoda
#

nah i was talking about spacejam

spark anchor
#

Getting logout again and gaggin

sullen hound
#

i m not in spacejam

unkempt pagoda
#

πŸ€·πŸ»β€β™‚οΈ

sullen hound
#

i am not able to browse the websit

#

whats happening

spark anchor
#

Ys

#

same here

unkempt pagoda
#

Oh rip tryhackme

#

Ssl error

spark anchor
#

SSL_ERROR_NO_CYPHER_OVERLAP

sullen hound
#

what could that be

#

according to my knowledge somone messled with the cypher

unkempt pagoda
#

TLS handshake failing

sullen hound
#

yeah

#

theres something fishy going inside it

#

hey

#

but the virtual machines did not terminated

#

anyone online

#

it has shifted from https to http

#

whats happening does someone know

#

@terse willow can you help me with this

terse willow
#

Hm?

spark anchor
#

THM Hacked lol

sullen hound
#

i thought i was kicked out

#

as a hacker

spark anchor
#

@terse willow You came right when he called. Wow!

sullen hound
#

i may tell all the information that i received

#

it is working on tor

terse willow
#

Sounds like the site is being upgraded. I know Skidy was intending to implement Cloudflare sometime this week

#

If it's an error with the TLS, that might be it

sullen hound
#

@terse willow Are you sure its being upgraded

gusty cradle
#

@sullen hound Yes, the admin's are aware of the issue and are working on it

sullen hound
#

@gusty cradle I was able to access the website with tor network

#

if that was upgrade then i also should not reach it with even tor

gusty cradle
#

@sullen hound The website is back up

terse willow
#

It was transferring the SSL certificate

#

Chances are that TOR just ignored that

sullen hound
#

no it isn't

#

Dear @terse willow Remember Tor Browser never ignores such small things due to high privacy

#

website not coming up on my side

brazen cloud
#

If it’s transferring to cloudflare then DNS will play a part in it - due to how tor works would explain why it might work on there and not in your browser

gusty cradle
#

"dear"

terse willow
#

....
You have no idea what TOR does, do you?...

brazen cloud
#

Nothing to be done by any one then just waiting

weary kindle
#

high privacy
ah yes, the browser made by the CIA is known for it's high privacy, never mind the fact you can de-anon anyone if you control an exit node

gusty cradle
#

^

sullen hound
#

yes thats true

#

but even if you are in a network of somebody such as wifi without the control of tor exit nodes you may see his all traffic

#

Ok Tor also stopped

#

@weary kindle I dont think Tor Browser is made by CIA

weary kindle
sullen hound
#

working again

quiet schooner
#

@sullen hound if you control the WiFi network, you can't see the traffic through tor.

teal raptor
#

🀩

sullen hound
#

@quiet schooner if the victim is in the same network then why cant we see the traffic going through the tor

quiet schooner
#

Because it's encrypted?

#

Because HTTPS traffic is always encrypted, that's what the S means?

sullen hound
#

i know thats encrypted

quiet schooner
#

It's not suddenly decrypted if you're on the same WiFi network

sullen hound
#

i know that

#

but the router is the main thing from where the traffic is going to and coming from

grand ember
#

but it's still encrypted

quiet schooner
#

It's encrypted between your device and the webserver you're talking to.

#

It might be encrypted again between your device and the router.

sullen hound
#

Ok the purpose of my sayiing was that if the person gets hold of the router he will be able to see all of the traffic

#

in my sense

quiet schooner
#

No.

#

They can't.

#

It's still encrypted.

viscid girder
#

anyone got a game going>?

gusty cradle
#

@sullen hound How the traffic is still encrypted? Explain your "logic".

quiet schooner
#

If you're going to make a statement related to cybersec in a cybersec discord, you'd better make it correct otherwise someone will call you out.

sullen hound
#

sorry i have to go but i will continue back

quiet schooner
#

Happy to cite my sources.

sullen hound
#

@fair adder

#

you said to come to koth i am waiting

#

come on

#

quick 5 minutes remainin

fair adder
#

what room ?

sullen hound
#

in the link

#

3 minutes remaining

quiet schooner
#

No point if the game is over

sullen hound
#

what

quiet schooner
#

If there's 3 mins left in the match

fair adder
#

it starts in 3 m

sullen hound
#

no 3 minutes to start

#

yeah

#

@fair adder if i weren't hacking multiple machines at a time the bug wouldn't be reported

quiet schooner
#

wat

#

the bug was reported long ago

brazen cloud
#

why try hard multiple koth lobbies

fair adder
#

what bug

#

sm

#

smh

sullen hound
#

hey the machine is space jam

fair adder
#

idk that room

#

oky i guess i will learn on the way

#

SMH

sullen hound
#

if i am right thats a vuln

quiet schooner
#

You're not

#

Please don't try to spoil boxes.

fair adder
#

bruh even if you were why are you telling that thats liturally spoiler

last ether
#

When do new koth boxes get released?

weary kindle
#

When they are ready

last ether
#

So there is no kind of schedule and stuff?

#

Cool

sullen hound
#

i am king @fair adder

#

without even spoiling

#

i am not a spoiler nor a cheater how many times i have to tell you

brazen cloud
#

You literally spoiled what needed to be done on the box in here

sullen hound
#

what did i done

#

then how can i spoiled it

weary kindle
#

You're playing prod right?

sullen hound
#

no space jam

fair adder
#

i not even turned the port 3000 port off
@sullen hound you liturally just spoiled again

weary kindle
#

Regardless, you were asking for help with Prod priv esc earlier: this will help

pkill -9 -t $(tty | sed 's/^.....//')
sullen hound
#

is this privilege escaltion

weary kindle
#

yeah

gusty cradle
#

πŸ‘€

sullen hound
#

@fair adder I didn't spoiled the box and if i did give me proof of it

weary kindle
#

Either that or run

sudo /usr/bin/chattr -i /root/king.txt
brazen cloud
#

Either the message was deleted by your or a moderator @sullen hound

fair adder
#

you said you didn't turn off port 3000 and that port has ||vuln||

sullen hound
#

wait a second if the port 3000 is off i don't turn it off

#

don't blame me all the time

fair adder
#

SMH

sullen hound
#

what do you mean by SMH

#

@brazen cloud there are two identical flags in space jam

icy cave
gusty cradle
#

@sullen hound It's not a bug

brazen cloud
#

Deleting because of spoilers.

gusty cradle
#

There are only two flags on Spacejam(root and user flag)

sullen hound
#

oh

quiet schooner
#

@icy cave imagine thinking KoTH boxes have internet

sullen hound
#

yeah

icy cave
#

i know 🀣

brazen cloud
#

You can report bugs without spoiling @sullen hound and as @gusty cradle said, that's not a bug irrespective.

fair adder
#

@sullen hound you spoiled 3 times in less then 15 minutes πŸ˜‚

sullen hound
#

what did i spoiled

#

just tell me the message

fair adder
#

lol they deleted

sullen hound
#

ok

#

ok i understood what i spoiled

#

the locations of flags

#

am i right

brazen cloud
#

Amongst things.

#

That you have already been warned about.

sullen hound
#

@fair adder I am waiting for you to gain access

#

no i wasn't warned about spoilers

#

and didn't know it was one

fair adder
#

bruh im playing this room for the first time

sullen hound
#

oh

#

lame execuse

#

@fair adder

#

hey rm that file is out of rules and terrible

#

replace rm with removing

#

i think so

brazen cloud
#

mhm?

sullen hound
#

am i right @brazen cloud

brazen cloud
#

You'll have to give more context @sullen hound

sullen hound
#

It is out of Rules to remove or deleted the king.txt and root.txt file

quiet schooner
#

remove = delete

#

You can delete king.txt

gusty cradle
#

^

sullen hound
#

really

quiet schooner
#

Yes?

#

Read the rules

#

I keep telling you to

#

You've been reported for breaking them already

last ether
#

πŸ˜…

sullen hound
#

i read it but there's nothing like king.txt

quiet schooner
#

Then why do you think it's against the rules?

#

Don't make claims unless you can justify them

dapper escarp
#

@sullen hound you seem to have an issue with reading rules

sullen hound
#

okπŸ₯Ί

last ether
#

Now go read the rules and be back bro

dapper escarp
#

It is out of Rules to remove or deleted the king.txt and root.txt file
@sullen hound root.txt is a flag right? So no you can’t delete.

sullen hound
#

@fair adder said he was trying

#

then he removed the message

last ether
#

So you read the rules now? @sullen hound

sullen hound
#

i already read them

last ether
#

Oh good

quiet schooner
#

You need to understand

#

Just reading is not good enough

sullen hound
#

yeah

quiet schooner
#

You keep asking

#

So I don't think you've understood them

dapper escarp
#

The rules are clear cut. If you’d read them you would know you can’t mess with those files

sullen hound
#

now i do know them

fair adder
#

@sullen hound its not removed its moved

dapper escarp
#

@fair adder you can’t move flag locations

sullen hound
#

you typed remove

brittle merlin
#

Just to get it clear, is it allowed to change perm of king.txt to 000?

fair adder
#

oof

#

okay i will get it back

sullen hound
#

@fair adder

fair adder
#

the f did you do to chattr @sullen hound

gusty cradle
#

@brittle merlin That's a stupid strategy, but you're allowed.

sullen hound
#

thats disbale

fair adder
#

there its back @dapper escarp i just moved root to /home/

dapper escarp
#

...

sullen hound
#

sorry disabled

last ether
#

You can do anything to king.txt just not the flags

brittle merlin
#

Ah, I don't do that. But I have seen it many times. Don't know how to bypass that tho

fair adder
#

xD won't happen again

dapper escarp
#

While I’m here @fair adder reread the rules before you get banned from the game mode

fair adder
#

okay

spark anchor
#

The guy who does not sound like human.

sullen hound
#

whom

#

me or @fair adder

spark anchor
#

You need to see general chat to understand this.

fair adder
#

rule 7 is my favorite ... Scripts that automatically hack and/or harden the machine are forbidden

brazen cloud
#

My favourite rule is all of them

fair adder
#

@dapper escarp i reread them 2 times

sullen hound
#

and I 15 times

brazen cloud
#

Considering you moved a flag @fair adder

quiet schooner
#

You need to understand
@quiet schooner

spark anchor
#

@sullen hound and still not following them.

brazen cloud
#

I'd go through them again

sullen hound
#

i am just talking

fair adder
#

i was about to type i will go throught them 1 more time πŸ˜‚

sullen hound
#

and did followed the rules

#

then how are you saying @spark anchor

#

for GOD sake please blaming me everyone who says i am autopwning

grand ember
spark anchor
#

@grand ember There we go

fair adder
#

LOL

last ether
#

Man give the kid a break @spark anchor 🀣

spark anchor
#

Ah.. Man @sullen hound Sorry, I am just going way too far.

#

That wasn't the right attitude.

brazen cloud
#

Thank you, it can be kept civil.

spark anchor
#

Yup.

#

I love National Security Agency.

sullen hound
#

Here you Go

#

@fair adder Again comes the NSA

fair adder
#

what

spark anchor
#

@sullen hound πŸ’Œ

sullen hound
#

who want to play another koth

spark anchor
#

@sullen hound You are the best

sullen hound
#

i appreciate your love

#

but it is better for both of us to focus on tryhackme

#

in the best interests of both of us

spark anchor
#

Yes

sullen hound
spark anchor
#

I am sorry for my previous behavior. I don't know what happened to me

sullen hound
#

remember I have a big heart to deal

#

So NO PROBLEM

spark anchor
#

WDYM big heart to deal.

sullen hound
#

just understand Big Heart

#

that I forgives everyone

spark anchor
#

πŸ™‚

fair adder
#

he also has big brain πŸ˜„

spark anchor
#

Yes

sullen hound
#

challenge game is mine

#

now

dapper escarp
quiet schooner
#

Spec link?

fair adder
#

bruh why you bully you put challenge game even last game

spark anchor
#

:optional:

sullen hound
spark anchor
#

uf

sullen hound
#

hey im in

#

controlling two mcahines

#

machines

fair adder
#

hey im gonna go to the store πŸ˜„

sullen hound
#

no problem

#

the machine is mine

#

got 1st flag

spark anchor
#

MYSQL explit?

#

Integer overflow?

sullen hound
#

got second

#

i again said if i tell you that will be called a spoiler

spark anchor
#

Hint?

quiet schooner
#

@spark anchor FoodCTF is all about enumeration

spark anchor
#

Ok

fair adder
#

ok im back

#

i wasn't running this time @glossy vessel

sullen hound
#

and the machine is mine

fair adder
#

cool

#

anything else ?

sullen hound
#

nope

fair adder
#

πŸ˜†

sullen hound
#

why dont you get in to

#

no execues

fair adder
#

eh running nmap scan

sullen hound
#

execuses

fair adder
#

im kinda taking time

sullen hound
#

no problem take time

spark anchor
#

enum4linux says "
Use of uninitialized value $global_workgroup in concatenation (.) or string at ./enum4linux.pl line 437.
". This error is bugging me from days. Searched Internet but no help

sullen hound
#

same as here

unkempt pagoda
#

I get that when smb is not on a domain

sullen hound
#

but remember it only works if you have port 445 open

fair adder
#

@sullen hound removed the page on higher port?

sullen hound
#

which page

fair adder
#

oh you didn't

sullen hound
#

which page tell me

spark anchor
#

who is kiransau?

sullen hound
#

idk

spark anchor
#

Hey, @quiet schooner Why you joined.. NOO

quiet schooner
#

taking a look

#

There's a lot of rule break allegations being thrown around

fair adder
#

damn you patched it @sullen hound

spark anchor
#

we are dead if you joined

sullen hound
#

hahahaa

spark anchor
#

Oh really?

sullen hound
#

yes i did

spark anchor
#

Rules being broken?

fair adder
#

you are so evil lol

#

pathed the other entery as well ?

sullen hound
#

patching isn't against the rules

fair adder
#

yah i know

spark anchor
#

Yes it isn't

fair adder
#

no it isn't patching is part of blue team @spark anchor

sullen hound
#

then how are you saying that i broke rules

#

@spark anchor

spark anchor
#

I didnt say that you did

fair adder
#

@sullen hound next room production i create πŸ˜›

spark anchor
#

I was asking Ninj

sullen hound
#

hahah

#

oh

#

dont forget to tag their names at end

fair adder
#

jk i don't want to pick a room im 2 dumb

sullen hound
#

now again hacking 3 machines at a time

fair adder
#

but you are organisation

#

so you can't complain about it hehe πŸ˜›

spark anchor
#

Bye

#

me going

#

I should do THM boxes. I dont have standard in front of you guys 😦

fair adder
#

i just started doing few 2 :jo:

sullen hound
#

@fair adder you know python

full grove
#

yis

#

new monitors will be here on Thursday ^-^

fair adder
#

@sullen hound yah

#

a lil bit lol

sullen hound
#

who are monitors called

raven harness
#

ohh i can't access to port 22

sullen hound
#

on which machine

raven harness
#

food

sullen hound
#

link

raven harness
#

you are a king there

fair adder
#

@sullen hound you done fortune before/

sullen hound
#

to some extent

#

room number

#

@raven harness

brazen cloud
#

He's in your lobby NSA

raven harness
#

3085

sullen hound
#

ok i will see it

#

meaning @fair adder

#

now the king is slaksosmith

fair adder
#

im not

#

karma is

sullen hound
#

see it

#

no in food machine

quiet schooner
#

SSH is still open

raven harness
#

might be mine creds are worng

sullen hound
#

yeah

quiet schooner
#

@raven harness You're allowed to change passwords

#

@fair adder Can I dm?

weary marten
#

many things are still not patched xD

raven harness
#

@quiet schooner but i don't know how...xD

quiet schooner
#

@raven harness Find out

#

@weary marten On food? Nah

weary marten
#

na its fortune

quiet schooner
#

There's a few games going on

fair adder
#

@quiet schooner yes

sullen hound
#

@fair adder whats your username on tryhackme

quiet schooner
#

@sullen hound slavkosmith

sullen hound
#

oh

#

ok

#

reset the fortuna

weary marten
#

reset the fortuna
@sullen hound nice lol

sullen hound
#

so are you karma

terse willow
#

Eh, don't worry, she might reset herself πŸ€·β€β™‚οΈ

sullen hound
#

ok

#

one vote pending

#

@fair adder reset the fortuna

terse willow
#

@sullen hound What's wrong with it?

sullen hound
#

password changed

terse willow
#

Eh?

#

That's not a reason to reset...

#

Password changing is allowed

sullen hound
#

but i saw many people do so

terse willow
#

Resets are for if the box is completely broken

#

Or because someone has broken the rules

quiet schooner
#

If you harden the box, that's allowed

sullen hound
#

oh

terse willow
#

They're not for if someone has hardened the box and you're throwing a hissy fit at not being able to get in

#

That's just good strategy from your opponent

weary marten
#

If you harden the box, that's allowed
@quiet schooner what is this ? lol

quiet schooner
#

Patching vulns

#

Changing passwords

#

That's not a reason for a reset

terse willow
#

Regenning SSH keys

#

Removing vulnerable code

#

Stuff that removes vulnerabilities

weary marten
#

i just changed the password and pached some vulns

terse willow
#

That is allowed

#

Shutting services off is not

#

As long as the box is still functioning, there is no reason to reset

#

Even if no one else can get in

#

Especially if no one else can get in -- requesting a reset then is just poor showmanship

sullen hound
#

oh

#

okh

#

won't do it again

weary marten
#

so what we do now ?xD

terse willow
#

If it's the machine that James hardened

#

Then you sit and wait for the clock to go down

sullen hound
#

new koth who's in

quiet schooner
#

What box, how long?

sullen hound
#

in 5 minutes

#

here is the link as koth is 60 minutes long

#

are you in james

icy cave
#

is there a 4th way in to food?

weary marten
#

lol there are 4?

#

i only know two

raven harness
#

is there possible to change ssh password for food without login ?
i mean right before now i was able to login but now i m getting permission denied..
i sounda like a weird for you ...

quiet schooner
#

@raven harness The box ended?

#

But if someone roots it, you can change the password

weary marten
#

is there possible to change ssh password for food without login ?
i mean right before now i was able to login but now i m getting permission denied..
i sounda like a weird for you ...
@raven harness nope

sullen hound
#

@quiet schooner where are writeups for KOTH Machines

quiet schooner
#

@sullen hound They don't exist for most of them

sullen hound
#

which ones exists

raven harness
#

@quiet schooner I would change the pw if i got access into the server
but i cannot login into the server even i have got creds i m sure that are valid

quiet schooner
#

@sullen hound That's on you to research

sullen hound
#

oh

#

ok

quiet schooner
#

@raven harness Yeah, so someone else probably changed it

warm chasm
#

I changed the creds sry

quiet schooner
#

You're allowed @warm chasm

weary marten
#

can i post writeups ?

quiet schooner
#

@sullen hound Remember, relying on writeups is cheap

#

@weary marten read the rules.

warm chasm
#

Yeah I know

#

But there are remaining vulns

raven harness
#

so it means no further access into that server @quiet schooner

sullen hound
#

yeah

quiet schooner
#

@raven harness No?

#

@raven harness @warm chasm You are allowed to patch every vuln. You're encouraged.

#

When I play, I patch every vuln.

warm chasm
#

No I was just saying that they should still be looking

raven harness
#

ok thanks

sullen hound
#

@quiet schooner Why dont add the points to public profile

quiet schooner
#

Stop tagging me every time you have a question

sullen hound
#

according to my knowledge the First KOTH Game was play on march6

quiet schooner
#

And?

sullen hound
#

and now its getting popular and popular

#

so why dont add its point to public profile

quiet schooner
#

because that's exploitable

#

Skidy has said why, many times

raven harness
#

will there be also like tournament in future?πŸ˜‚

quiet schooner
#

You missed one

#

There might be another

#

I think there was like $100USD at stake over it?

raven harness
#

ohhhh
was it live where non player could also spectate them?Like gaming tournament

quiet schooner
#

Some were livestreamed

quick flax
#

small question, i think i missed a bit of background knowledge, why is the box called offline and are all the usernames names of offlinetv? i think i missed a thing or two

quiet schooner
#

@quick flax Themed.

#

FoodCTF is food themed

quick flax
#

yeah, i get that haha

quiet schooner
#

Hackers is themed from the 1995 movie hackers

#

So what's the question?

quick flax
#

but is there a special reason why they chose offlinetv?

quiet schooner
#

@full grove is a big fan

#

Creator of the box chooses the theme

quick flax
#

Ah cool!

full grove
#

the requirement for the box was

  • Theme it
  • Include X number of vectors
quick flax
#

Super cool!

quiet schooner
#
  • make it fun
quick flax
#

i would love to try it one day but yeah hahaha experience

nova tide
#

I think there was like $100USD at stake over it?
150$

unkempt pagoda
harsh obsidian
lilac topaz
#

@gleaming reef Noob

gleaming reef
#

?

#

@lilac topaz ?

lilac topaz
#

@gleaming reef Why reset the box from the beginning?

gleaming reef
#

@lilac topaz you can reset

lilac topaz
#

press reset πŸ˜‰

gleaming reef
#

@lilac topaz happy?

lilac topaz
#

Thank u

lilac topaz
#

@gleaming reef Thank for the fight πŸ˜‰

#

how the hell could u reset reboot the box!! πŸ€·β€β™‚οΈ

gleaming reef
#

reset? what you mean?

lilac topaz
#

Reboot πŸ˜„

gleaming reef
#

reboot

#

hahaha black magic

lilac topaz
#

You did it as root

#

You even remove king.txt πŸ˜›

#

Thats some πŸ•΅οΈ magic

gleaming reef
#

but i couldn't write, i need 10 more minutes

lilac topaz
#

I still wonder how that black magic works πŸ™‚ you must have placed a backdoor somewhere

#

could not find it.

gleaming reef
#

or the box had one in the first place πŸ™‚

lilac topaz
#

hehe

harsh obsidian
#

gg

#

@warm chasm nicely played

warm chasm
#

@harsh obsidian you too

harsh obsidian
#

@harsh obsidian you too
@warm chasm question: I've been working on a thing. did you start getting hackers quotes on your terminals?

warm chasm
#

Yeah it was super annoying. Nicely done

harsh obsidian
#

Thanks. I've been busting my hump on that one. The nice thing, though, is it only displays. It doesn't actually insert in to your commands.

warm chasm
#

Yeah I realised. It was very disruptive nonetheless

floral kernel
sullen hound
#

join here 5 minutes remaining

#

join fast

#

2 minutes remaining

fair adder
#

Good luck, i am out

#

don't play with someone who doesn't follow rules

sullen hound
#

i follow rules

#

you can ask anyone

#

even james

brazen cloud
#

How so? @fair adder

fair adder
#

chat log says otherwise

#

you violated rules on me, then you did the same thing a day later

#

i will find a different game

floral kernel
#

what exactly did he violate?

sullen hound
#

i didn't

quiet schooner
#

Closing services

floral kernel
#

banhammer

sullen hound
#

it was done only one time

fair adder
#

they told you to read the rules 30 hours ago

#

you didnd

quiet schooner
#

See how easily trust is violated?

sullen hound
#

and I never did it again

fair adder
#

and here you are trying to deny the whole thing. uncool bro. i will find others to play with

quiet schooner
#

Once you breach someone's trust, it's hard or impossible to earn it back.

fair adder
#

enjoy the evening

brazen cloud
#

It only takes one time for a lot of things - trust is a good example of such

sullen hound
#

@quiet schooner i didn't have a play

floral kernel
#

THM staff must make rootkits, to ban users on malicious actions: like iptables, firewall-cmd, ufw, systemctl, service

quiet schooner
#

@sullen hound wat

sullen hound
#

hey i didn't play for a while

quiet schooner
#

@floral kernel Some of those aren't against the rules

floral kernel
#

like?

quiet schooner
#

You can restart a service or patch it by replacing it with one that works

#

EG webserver with a vuln? Kill it, replace with python server on the same port

floral kernel
#

after the replace part is a dream

#

for many..

quiet schooner
#

That's why it's against the rules to not replace

floral kernel
#

blue team > red team, change my mind πŸ˜„

sullen hound
#

@quiet schooner when did i break the rules

#

i only broke it one time

floral kernel
#

once means always

quiet schooner
#

You broke the rules that time when you broke the rules

#

You answered your own question

sullen hound
#

@quiet schooner but didn't broke them after it

quiet schooner
#

Ok, but that doesn't restore people's trust in you

brazen cloud
#

This seems like an abhorrently reoccurring conversation

quiet schooner
sullen hound
#

i do play with the other members

#

they do trust me

quiet schooner
#

Ok

#

Good for you

sullen hound
#

and I don't close services after my 1st mistake

quiet schooner
#

Don't expect everyone to trust you.

#

Ok, great.

#

That's not going to restore the trust you violated

#

I recommend you accept that, and move on

#

Arguing it with me is pointless

sullen hound
#

I shall try my best to keep my 1st mistake my last mistake

quiet schooner
#

It's something about people you will just have to understand. Once you break someone's trust, they won't trust you easily.

sullen hound
#

Ok i agree with that

#

but this was a game

#

not a real life incident

quiet schooner
#

I recommend you accept that, and move on
@quiet schooner

sullen hound
#

Ok

quiet schooner
#

Please don't bring it up again, this is a formal warning under Rule 2 @sullen hound

sullen hound
#

Ok

#

I shall move on

#

Rule 2 of Koth

quiet schooner
#

No. Rule 2 of the discord. @sullen hound

#

Now.

sullen hound
#

got it rule 2 and reading others

#

Read all of Them Now I know them

brazen cloud
#

πŸ‘

sullen hound
#

@floral kernel Atleast you could play koth with me or you couldn't

floral kernel
#

im playing brotha

sullen hound
#

what it is

floral kernel
#

ha?

sullen hound
#

what do you mean by brotha

floral kernel
#

brother/fella

sullen hound
#

Ok

floral kernel
#

gg

#

first time doing this Fortuna machine

sullen hound
#

and you were in but now

#

out

#

am i right

floral kernel
#

yes, you changed user's password so im locked out

sullen hound
#

lets do another game

floral kernel
#

sure

sullen hound
#

can you give me some minutes

floral kernel
#

finish the game first

sullen hound
#

here you go you are the king happy

#

just give me some minutes

quiet schooner
#

@floral kernel There's other ways to get in when someone changes a password

floral kernel
#

yeah ik

sullen hound
#

@quiet schooner what are they

floral kernel
#

found 3 ways till now

quiet schooner
#

You're asking me to spoil a box?

#

I aint gonna spoil a box.

sullen hound
#

ok don't tell

#

i shall research it

#

but thanks for giving me a hint

floral kernel
#

is there any rule of thumb, like every box has X user ways and Y root ways?

quiet schooner
#

3-4 minimum

floral kernel
#

i see

sullen hound
#

okhh

#

just give me round about ten minutes @floral kernel we will continue a game

#

or start another koth

floral kernel
#

just give me round about ten minutes @floral kernel we will continue a game
@sullen hound to dump the db? πŸ˜‰

#

any1 using Arch-based distro, here?

sullen hound
#

are you ready

#

@floral kernel

floral kernel
#

sure

sullen hound
#

come on my friend lets do it

harsh obsidian
#

Mind if I join you?

sullen hound
#

no dear

#

its open for everyone

#

yes its panda

harsh obsidian
#

word, thanks

sullen hound
#

@harsh obsidian you can say anything to me I shall never mind

stable horizon
#

Hey it's that guy that cheats

#

Get outta here

quiet schooner
#

@stable horizon Hey, don't start that again

stable horizon
#

Ok

sullen hound
#

is my donut here

quiet schooner
#

πŸ₯―

#

that's a bagel

sullen hound
#

@quiet schooner Thanks

#

tasty

rancid pewter
#

Just wanted to compile my rootkit on the box but the kernel headers are not installed

#

Yeah sure

fair adder
#

ayeee my boyy killing it again @rancid pewter

rancid pewter
#

Yeah mate, made a rootkit to be sure to win every game

fair adder
#

ffs of course you did

#

you too smart for these games

harsh obsidian
#

I'm impressed. I'm busting my ass to figure out how to take king back and I've got nothing

fair adder
#

yea well it takes years of experience lol

rancid pewter
#

Im not on the box anymore

harsh obsidian
#

Something you have going still keeps you as king

rancid pewter
#

Yeah you know I got a little script that run 50 thread in 5 process so 200 thread constantly brute forcing the king.txt

harsh obsidian
#

NICE!!

#

Yeah you know I got a little script that run 50 thread in 5 process so 200 thread constantly brute forcing the king.txt
@rancid pewter compiled binary or bash / python /etc?

rancid pewter
#

C

quiet schooner
#

So compiled binary

rancid pewter
#

I got a rootkit ready too just need to compiler it for specific kernel version

harsh obsidian
#

very nice!

#

πŸ™‡

harsh obsidian
rancid pewter
#

@harsh obsidian Having some problem getting king, this time it a rootkit

harsh obsidian
#

I think our respective methods are fighting eachother so hard that the system can't find a king lol. neither of us have gone up in points in a couple of minutes

#

And I think my method over tasked the system. Gonna have to adjust it...

rancid pewter
#

I think you made a fork bomb or something can connect to ssh

harsh obsidian
#

I'll vote a reset

rancid pewter
#

You might want to verify your script seem like a fork bomb

harsh obsidian
#

It's looking fine on my connections. I'll nerf it a bit next time I run it; I'm not trying to kill the box

#

I gave another reset vote; I won't run that one again until I figure out wtf

nova tide
#

Funny little thing that sometimes works against newbies:
echo -n "I" > /dev/pts/3;sleep 1;echo -n " am" > /dev/pts/3;sleep 1;echo -n " in" > /dev/pts/3;sleep 1;echo -n " your" > /dev/pts/3; sleep 1; echo -n " shell" > /dev/pts/3;

harsh obsidian
#

I've got something like that but every 4 seconds kicks another quote from hackers to someone's shell

nova tide
#

myDonut used that once against me and i totally fell for that

rancid pewter
#

I got some technique to write on someone else shell but I cant see anything

harsh obsidian
#

lmfao

nova tide
#

I got some technique to write on someone else shell but I cant see anything
@rancid pewter oh i thought that's what you did

rancid pewter
#

Let me give my technique

#

exec >/dev/pts/PTS NUMBER 0>&1

harsh obsidian
#

exec >/dev/pts/PTS NUMBER 0>&1
@rancid pewter I've been looking in to that myself....is that how you get tetris going?

nova tide
#

Or nyan

rancid pewter
#

Nope I got a C script to run on other tty

nova tide
#

Won't this work?
./nyan > /dev/pts/n.o ?

rancid pewter
#

Yes but with my tetris script I wont get key input

nova tide
#

Gotta work on that then ^^

#

Btw the way you write on someone's shell, it wont run that written data,right?

#

So how's that different from the one that i mentioned

rancid pewter
#

Yes with exec you can run command

nova tide
#

Oh

rancid pewter
#

But you cant see anything and it will kill your terminal when the people exit

harsh obsidian
#

I think @sullen hound left us to our devices....

#

Won't this work?
./nyan > /dev/pts/n.o ?
@nova tide One of my recent favorites is: echo "Ah ah ah you didnt say the magic word" >> /dev/pts/$x

sullen hound
#

yeah

nova tide
#

@nova tide One of my recent favorites is: echo "Ah ah ah you didnt say the magic word" >> /dev/pts/$x
@harsh obsidian yeah i have seen that πŸ˜‚

#

Or just aliases to a simple file or may be urandom

#

And make ppl rage

harsh obsidian
#

I figured a nice little Jurassic Park reference could be a bit of fun

quiet schooner
#

I like a lovely little rickroll in the JS

harsh obsidian
#

Or just aliases to a simple file or may be urandom
@nova tide I love aliases. I only use that when I'm in the mood to be a super dick

#

I like a lovely little rickroll in the JS
@quiet schooner That's a GREAT idea!

nova tide
#

I like a lovely little rickroll in the JS
@quiet schooner i wish i could see you in action someday

quiet schooner
#

It's no fun to watch

#

I just patch the vulns and add rickrolls

nova tide
#

That's why i want to watch you in action

quiet schooner
#

When you made 20%+ of the boxes, there's a good chance you can patch the vulns after rooting it

harsh obsidian
#

Lol. watch a live stream somewhere

nova tide
#

Missed when you went against szymex

quiet schooner
harsh obsidian
#

Nice!

#

I've only been able to get a 59min king on one or two boxes

quiet schooner
#

Can't be dethroned if no one can get a shell.

nova tide
#

Well you can't just patch all of them at once

quiet schooner
#

You can patch hackers in under a minute

nova tide
#

Can't be dethroned if no one can get a shell.
@quiet schooner Hackers takes time

lusty portal
#

Oof, James pulling the big guns out

quiet schooner
#

Speed patching

#

I resisted the ALL ALL sudo creds I have for hackers and food. That's no fun.

grand ember
#

Missed when you went against szymex
@nova tide lol, me and koth aren't the best combo kekw

nova tide
#

Well it's just fun to watch you guys go against each other sometimes

#

Specially if someone is streaming and everyone is in voice channel

quiet schooner
#

There's exploits on hackers that only a few people have found

nova tide
#

I resisted the ALL ALL sudo creds I have for hackers and food. That's no fun.
@quiet schooner but still can't seem to get a shell on tyler, hmm

quiet schooner
#

I've played Tyler twice

#

That's all.

#

I have the privesc ready for it.

nova tide
#

If you guys plan to play again sometime i would love to watch instead of joining in

quiet schooner
#

I mostly show up in KoTH when people need to lose.

harsh obsidian
#

lol

stable horizon
#

That's fair

sullen hound
#

koth online

fair adder
#

cool koth game

#

@sullen hound did you path the box?

sullen hound
#

which one

fair adder
#

Panda

sullen hound
#

why not

fair adder
#

lol

#

smh its my first time playing panda

nova tide
#

πŸ˜„

#

good luck with wordpress then

sullen hound
#

i done it too

fair adder
#

im stuck at wordpress rn

#

never used that stuff before

nova tide
#

Good luck with that

fair adder
#

xD

#

im so stuck

sullen hound
#

I have to go

#

will be back soon

fair adder
#

im gonna go complete few rooms

#

cuz koth isn't going to get my skill up if i don't know how to play it

nova tide
#

cough cough hmm

brazen cloud
#

maybe

#

but tryharder and it will x

sullen hound
#

anyone playing koth

fair adder
#

me no

sullen hound
#

why dont join here

fair adder
#

aaa you wil bullly me

#

but ok

sullen hound
#

hey @fair adder i Never bully anyone in my life

fair adder
#

it was a joke for you dominating on koth everytime

quiet schooner
#

Until they come up against someone who knows how to patch and how to defend

fair adder
#

and then they all lose

#

*including me

terse willow
fair adder
sullen hound
#

hey @fair adder leave that game

fair adder
#

ok

#

No place like 127.0.0.1

sullen hound
#

yeah

#

now get here fast

#

you got in

fair adder
#

yah

#

do you like my new pfp?

sullen hound
#

yeah seems nice

#

anyone playin koth

sullen hound
#

join here starting in 10 minutes

fair adder
#

pepega

quiet schooner
#

What box?

fair adder
#

Panda

quiet schooner
#

That guy doesn't patch anything other than changing passwords

stiff egret
#

lol

fair adder
#

lmfao

sullen hound
#

@fair adder what happened did i did something wrong

#

what happened

#

please remove the gif my computer stuck at such gifs

fair adder
#

wut

sullen hound
#

please remove that message my computer is getting slow and slow

#

the media message

fair adder
#

ah soz

sullen hound
#

thanks

#

hey @fair adder there is still a vulnerability open in that panda box

#

why not get in

fair adder
#

i cANT fIND

sullen hound
#

there is one

#

7 members all in line

#

now 8

#

1 minutes remaining

gusty cradle
#

Why?

quiet schooner
#

No, you don't

#

DM me.

sullen hound
#

ok

quiet schooner
#

Don't spoil the box

sullen hound
#

ok

raven harness
floral snow
#

Why can't be king of the game? I earned more flag than others but idk why the second player is choosed? πŸ€”

gusty cradle
#

@floral snow Did you enter your name in the king.txt file?

quiet schooner
#

@floral snow King doesn't mean first place

#

King is the name in the /root/king.txt file

floral snow
#

Wow!

#

Okay

quiet schooner
#

@floral snow Please read the rules, all the info is there

floral snow
#

Okay

floral snow
#

Please, how can I bypass "command redirection forbidden"?

livid mountain
#

anyone game?

#

@full grove come hack with meeee ❀️

fair adder
#

what is this machine lol

full grove
#

owo

fair adder
#

i swear its only a matter of time before birb gets king

#

wait

livid mountain
#

πŸ˜„

#

HI πŸ˜„

#

I'll give you a bit of time before I nuke the vulns though

#

I closed one only πŸ˜„

fair adder
#

what vulns lmfao. all i've got is a random decrypted b64 string and what I believe is an ssh key lol

#

i need to practice more

rancid pewter
#

Dont worry @livid mountain I will take back my place as king

livid mountain
#

@fair adder if it was easy to get and posed a threat to me, maybe that was it πŸ˜„

fair adder
#

XD

mellow bough
#

o/ birb

quiet schooner
#

@fair adder decoded base64 string

livid mountain
#

are we allowed to run scripts to maintain king ?

mellow bough
#

mhmm

livid mountain
#

not harden/attack

#

nice

mellow bough
#

You're allowed to go pretty crazy and use root kits if you'd like

fair adder
#

yes, decoded. It isn't a flag so /shrug

mellow bough
#

The primary goal is to provide an avenue for growth

#

and sometimes getting ya shit kicked from someone who runs a rootkit is best lol

livid mountain
#

ok

#

not sure if lag or messed up shell

mellow bough
#

Only real rules are no autopwn and you can only close off backdoors. Essential services have to stay up, you gotta patch 'em

#

Depending on the box, could be both lol

livid mountain
#

right right

#

and no iptables πŸ˜‚

mellow bough
#

That too xD

quiet schooner
#

Remember

#

Vulnerable web server? Replace with python http server

#

ez

unkempt pagoda
#

Would removing the vulnerable php code count as patching?

livid mountain
#

I guess you could patch the code ye

unkempt pagoda
#

But youre also removing "functionality"

#

πŸ€”

fair adder
#

I mean would it still work as intended

quiet schooner
#

@unkempt pagoda The test tends to be "Does it work for a genuine user?"

unkempt pagoda
#

Hmm

livid mountain
#

my king script is bored

#

@rancid pewter enjoy your points for now πŸ˜‚

fair adder
#

there should be code checks that run

#

πŸ€”

unkempt pagoda
#

Thanks for that tetris shell @rancid pewter :p

rancid pewter
#

No problem

livid mountain
#

lol

rancid pewter
#

Seem like my rootkit is working on every linux box

fair adder
#

Im reading a book on rootkits. Pretty interesting so far, but a lot of the asm stuff goes over my head

unkempt pagoda
#

Instant tetris on login :p

rancid pewter
#

I havent done any asm to make my rootkit @fair adder

fair adder
#

It's typically for making the super ring 0 kernel level kits πŸ˜„

#

and cryptors

#

do any of these koth boxes have steg on the images? I doubt it, but it be funny if one of them did lmao

unkempt pagoda
#

not sure

quiet schooner
#

They might

#

You gotta play them all

unkempt pagoda
#

So many images to check though

fair adder
#

but i havent slept in 30 hours 😫

#

would it be possible to go into a solo koth just to find vulns?

quiet schooner
#

There's a way

#

I won't tell you how

fair adder
#

:|

quiet schooner
#

You're a hacker

#

Figure it out

fair adder
#

fair lool

livid mountain
#

hahaha donut πŸ˜‚

#

touche

#

awww you even patched my entry

#

meanie

rancid pewter
#

What ?

livid mountain
#

OH

#

reset

#

k then

#

I thought you kicked me out