#koth

1 messages ยท Page 30 of 1

livid mountain
#

lol

fair adder
#

lmao

rancid pewter
#

I wont use rootkit this time

livid mountain
#

o we get more flags now?

#

or no

fair adder
#

are flags randomly generated? I would assume so

livid mountain
#

can't resubmit - ok

fair adder
#

alright boys the grind begins

livid mountain
#

how is the king txt file write protected from root anyway

rancid pewter
#

chattr

dapper escarp
#

Chattr

#

The beautiful of making a file immutable

livid mountain
#

mmh

#

hmmmm

#

two new tricks learned ๐Ÿ˜„

#

I can't even kill -9 your stuff

#

๐Ÿ˜ข

#

Eh

#

GG @rancid pewter

quiet schooner
#

myDonuts has a rootkit ๐Ÿ˜‰

rancid pewter
#

GG

#

I might have overkilled KoTH

weary kindle
#

can't wait for the rkit meta

livid mountain
#

might xD

#

I'm so sad my awesome script didn't work

#

i made the perfect meme script last night

#

wanted to try it

#

but for some reason I got a "file not found" error

#

it's complicated....

#

๐Ÿ˜‚

rancid pewter
#

It in which language ?

livid mountain
#

bash

#

was just a simple shell script that wasn't too noisy and had had some tricks to hide itself

#

maybe the tricks fails

#

works on my pc LUL

full grove
rancid pewter
#

@livid mountain Would love to see that script in action

livid mountain
#

it's more simple than it sounds really

#

it's a trick i heard about in Darknet Diaries LOL

#

always wanted to try it

rancid pewter
#

Seem really interesting

livid mountain
#

want a peek?

#

You're gonna spot it and mitigate anyway so I don't mind sharing hahaha

rancid pewter
#

Yeah DM me

carmine hemlock
sullen hound
#

anyone playing koth

#

if not join here

last ether
#

Good game @sullen hound ๐Ÿ˜…

sullen hound
#

yeah

last ether
#

๐Ÿ˜…

#

Man you are good

sullen hound
#

yah

last ether
#

Though you kept kicking me out

#

Look whose the king

#

๐Ÿคฃ

sullen hound
#

I know who is it

#

I am learning some languages

last ether
#

Me too

#

Me too

sullen hound
#

And That might help me keep the king

last ether
#

It looks like you already memorized all the boxes

#

And That might help me keep the king
@sullen hound
Sure

#

I'm just a beginner too

sullen hound
#

I put 24 hrs to KOTH

last ether
#

Nice bro

#

Why NSA?

#

Why the name

sullen hound
#

You know why the name

last ether
#

No I don't

#

That's the reason I'm asking

#

Do you work for the NSA?๐Ÿ˜…

gray warren
#

Look out the window, if you see a black van with antennas you have your answer ๐Ÿคฃ

last ether
#

๐Ÿ˜…

jagged oyster
#

just started with koth, is there only user.txt and root.txt flags or are there more? or does it depend on the box

quiet schooner
#

@jagged oyster For SpaceJam, I think there's only user and root

#

For other boxes, there's 6-10 flags around the box

jagged oyster
#

okay that explains it, doing spacejam atm

quiet schooner
#

If you hover over the label for flag submission, you can see the number of flags

jagged oyster
#

been looking for more for like 40min now, facepalm ๐Ÿ˜„

#

aah okay, thanks!

sullen hound
#

anyone playing koth

jagged oyster
#

hm, getting 404 when trying to join a koth im participating in

sullen hound
#

which koth

jagged oyster
#

clicking on the link gives me 404, dunno why

sullen hound
#

that happened with me too

lusty portal
#

can you give me the link please?

quiet schooner
#

oooh a fix

sullen hound
#

i think

#

yes it is 404

lusty portal
#

Game 3307 does not exist

#

Can you please refresh your page and copy/paste the link

#

Is it the same?

jagged oyster
#

3305 is the one giving me 404

#

wait, im in now

#

weird stuff

lusty portal
#

Yeah, I'm looking into it

#

Very weird

sullen hound
#

anyone playing koth

#

join here start in 10 minutes

twin rapids
#

ahh too late ;D

sullen hound
#

yeah

sullen hound
#

anyone

spare scroll
#

is it any flags that is encoded?

slate crow
#

reset pls

#

reset panda

#

@sullen hound can you press reset ?

sullen hound
#

why

slate crow
#

cuz it's heavily patched, lol

#

let's play...

sullen hound
#

i patched it

#

if you beg

slate crow
#

lol

#

where's the fair play

sullen hound
#

then ok

#

its fair play

#

@slate crow

#

Patching is Allowed

fair adder
#

lol

slate crow
#

this guy's scared cuz he got only one way in

#

lmao

spare scroll
#

lol

slate crow
#

reset again bois

twin rapids
#

why spam reset xD

spare scroll
#

why tho, if he can patch it in five min we have lost, if he cant why reset?

sullen hound
#

i reseted it 3 times

#

now you cant get it its not my problem my mate

spare scroll
#

yea, but gg @sullen hound

#

was the file on port 80 a flag?

sullen hound
#

umm

#

in koth telling others in spoiling the box

#

so sorry

slate crow
#

what happened ?

#

you fallin ?

spare scroll
#

ohh, i didnt know

rugged pumice
#

lol there are a lot of new rooms added
to the koth games
haven't been active in a while ๐Ÿ˜ฎ

twin rapids
#

ahh a fly

spare scroll
#

dayum u are clutching tho

slate crow
#

beg me now

#

@sullen hound

twin rapids
#

bruh

gusty cradle
#

lol there are a lot of new rooms added
to the koth games
haven't been active in a while ๐Ÿ˜ฎ
@rugged pumice Yuck, that fly ๐Ÿคข

slate crow
#

if you beg
@sullen hound payback

sullen hound
#

@slate crow see who is winning

quiet schooner
#

What box?

spare scroll
#

panda

quiet schooner
#

Nice

spare scroll
#

yea

slate crow
#

he lost his only way in

#

lmao

quiet schooner
#

So yes, you lost your only way in

twin rapids
#

man i didn't find any way in

spare scroll
#

@twin rapids same lol

quiet schooner
#

Lost = forget

#

You can no longer use it.

sullen hound
#

i will try hard

#

to remember it

quiet schooner
slate crow
#

you lost bruda

#

just accept the loss

#

@sullen hound

twin rapids
#

lul

quiet schooner
#

You're still taking the L

twin rapids
#

why u playin 2

slate crow
#

hahahahahahah

#

ya mad bro ?

quiet schooner
#

@sullen hound really? Remember when elf rekt you?

slate crow
#

ahahahahahahha

#

this guy's hilarious

quiet schooner
#

You got beaten

slate crow
#

use google

#

lmao

quiet schooner
#

By elf and me

fair adder
#

@rugged pumice the pic is named muha ๐Ÿ˜‚

#

yes me and James __Beat you __

#

@sullen hound james came in last minute and still had more points then you ๐Ÿ˜‚

quiet schooner
#

Elf, just how bad are you at KoTH?

fair adder
#

im like solid bad ๐Ÿ˜†

quiet schooner
#

I'm in CoD MW

twin rapids
fair adder
#

me is located in assembly rn

#

me and elf64 chillin

slate crow
#

gg bois

#

@maiden wasp gg

sullen hound
#

create a private machine panda

#

and DM me

#

I need to know what i forgot

fair adder
#

i mean sure

#

there i sent it to you

slate crow
#

indians of NSA

#

lmao

raven harness
slate crow
#

nah, ain't got no time for ya mad ass rn, workin' on other stuff

quiet schooner
#

People can be busy

slate crow
#

ye

#

me rn

ocean granite
#

@sullen hound you even playing?

#

koth

#

the game you joined

#

alright

#

man how did you get the username?

#

can i pm?

#

personal message

mint cargo
#

@sullen hound do we have any more vulns that aren't patched? i joined like after 35mins

#

okay np

carmine hemlock
#

Seems like clirimfurriku patched everything

#

but idk if theres still smth. on port 80

#

nice

mint cargo
#

lol gg

carmine hemlock
#

yeah, had a pretty big lead from the start, already knew the box ^^

#

port 3000 on that box is just OP

mint cargo
#

yeah there was a 3000 nodejs running.. was it in the box from the start or someone started it?

quiet schooner
#

It's there from the start

carmine hemlock
#

yup

mint cargo
#

i was using it for the rev shell and someone killed it lol

#

i literally JUST entered the rev shell command

carmine hemlock
#

yeah, you arent allowed to kill services but idk how I'd patch a service like that anyways, thats how its supposed to work

quiet schooner
#

You can patch the service on 3000

mint cargo
#

yeah u can edit the index.js maybe

carmine hemlock
#

Don't we take away the functionality of that service then?

#

isnt that its only purpose xD

mint cargo
#

or run it not under root

quiet schooner
#

@carmine hemlock That's fine. You're not impacting the functionality of the service for a genuine, non hacker user.

#

@sullen hound I refuse to answer your rules questions for several reasons

mint cargo
#

lol

quiet schooner
#

Mostly the fact that you should have read and understood them by now

#

Considering you CONSTANTLY ask.

carmine hemlock
#

Well then, gtg to bed now, was a good match!

covert basin
#

@sullen hound can i discuss a topic with you, plz?

#

DM?

harsh obsidian
nova tide
#

Join if you want some urandom on screen ๐Ÿ˜‚^^

green zenith
nova tide
#

Killua in KOTH?

green zenith
#

lol

green zenith
#

@sullen hound can you reset the machine plz

#

?

#

can't access the machine

#

๐Ÿ˜ฆ

#

even can't ping it

#

bro I know how to ping it

weak haven
#

vpn connected?

weak haven
#

i have a question about panda, can i dm someone?
it is regarding a initial access method

brittle flicker
#

who's koth?

#

everyone keeps talking about him

#

is he loki's brother?

delicate vine
#

KOTH = King Of The Hill

brittle flicker
#

nah

#

who is koth

#

stop lying

delicate vine
brittle flicker
#

that isn't koth

#

i've never been to that site

#

but who's koth

#

Is he the creator of that site?

#

stop messing with me

#

that's edited with the html

#

silly

delicate vine
brittle flicker
#

see?

#

liars

fossil jackal
#

xD

latent crest
#

anyone playing ?

weary marten
#

joining link?

viscid girder
civic oracle
#

Hey ya

spare scroll
#

ahhhh i just wasted 20 min on a brain lag

civic oracle
#

Restart the machine man

#

RESET!

spare scroll
#

ait

civic oracle
#

They guy just replaced the webapp

#

this shouldn't be allowed IMO

spare scroll
#

hahahaha lmao

civic oracle
#

The rest are not even on the chat

#

sad kek

quiet schooner
#

@civic oracle Why not?

#

If it's a valid patch that wouldn't affect genuine users, why wouldn't you allow that?

civic oracle
#

If he just replaces the entire code with "abc" text file

#

that beats the purpose

#

It does affect all users

#

The app is completely broken

quiet schooner
#

That affects the availability

civic oracle
#

Yep it does

quiet schooner
#

Check the rules, but that sounds like it could be a rule break

#

Yep rule 2

#

Nice and clear

terse willow
#

Are they?

civic oracle
#

Yeah I was playing

#

7 mins to end and completely locked out ๐Ÿ˜„

viscid girder
#

๐Ÿ˜„

#

lionaneesh was fun

civic oracle
#

Yeah man ๐Ÿ˜ฆ gg

#

I created so many different users to maintain access

#

that wall trick you did ruined my life ๐Ÿ˜ฆ

#

๐Ÿ˜„

#

whats some bullshit

#

ah

quiet schooner
#

So easy to patch

#

Please avoid spoiling the boxes though @viscid girder

viscid girder
#

okay sorry

quiet schooner
#

Have fun trying

#

That's a spectator link

civic oracle
#

You guys wanna join the voice channel ๐Ÿ˜„

minor urchin
#

i cant join VC cus im in the livingroom

viscid girder
#

did you already htaccess the upload NSA?

viscid girder
#

who has close ssh on 1337?

#

cheeky

fossil jackal
#

hi

civic oracle
#

Damn man

minor urchin
#

gg bois my laptop is gonna die now

civic oracle
#

He has denied login of every user on ssh

#

now we are completely locked out man

#

fuckkkk

#

Web vuln is patched as well

quiet schooner
#

3+ ways on every box

#

Wat

civic oracle
#

My bad. I am abusing myself. Like in awe! fuckkk!

#

not you

quiet schooner
#

@sullen hound Do you have a complaint to make?

#

The rules are PG13.

#

Single fbomb is "fine"

#

Excessive swearing is not

last ether
#

Too long the wait is bro

#

I'm going to watch a movie

#

And my time zone is different

#

Another time

#

Peace

gusty cradle
#

You sue them, because your NSA ๐Ÿ˜„

exotic quiver
#

What level do you need to be in order to play KOTH?

raven harness
exotic quiver
#

I always get the message Only intermediate and advanced experienced leveled users can play King of the Hill., anyone know something about this?

raven harness
#

go to profile and change

exotic quiver
#

Ah, thanks. I forgot that was a thing ๐Ÿ˜‚

gilded prism
#

aren't autopwn scripts banned?

brazen cloud
#

Ya huh

gilded prism
#

pretty sure someone in my game used one.

#

within like 5 seconds all acc passwords are changed.

#

it's you xD

brazen cloud
#

NSA

gilded prism
#

it's been 8 mins buddy

brazen cloud
#

You've been king 6 minutes

#

And Ryan is not

gilded prism
#

so within the minute we got on you got root and changed all passwords

#

k buddy

gusty cradle
#

What machine is it?

gilded prism
#

you can't patch everything

#

food

brazen cloud
#

There's no way to verify other then by the admins reviewing the logs. Send the url to koth@tryhackme.com

gilded prism
#

will do

gusty cradle
#

It's easy to root food ๐Ÿ™‚
But if you want to report them do as CMNatic says

gilded prism
#

this room has been out a long time buddy. there's nothing in the rules about me knowing flags from a previous session. They have already said that they look to refresh at some point. The fact is it's impossible for anyone else to do anything when within a minute you've gotten root, changed all the passwords and kicked everyone out.

#

you cannot patch everything. you have to leave one open

#

read the rules

#

before you play

#

ty

#

also i have a second game open which was also food which i was root on. stop whining.

#

if you have to use autpwn just to feel good about yourself then go ahead. you're not learning anything being a sore winner.

terse willow
#

Patching all vulnerabilities is fine. Doing it with a script, less so

quiet schooner
#

@gilded prism You don't have to leave any vulns open

#

wat

#

yes you can

gilded prism
#

sorry but can we go back a couple messages. he legit complained about storing flags right. So if this is the case he's on in 1 minute. then that's storing creds xD

terse willow
#

@gilded prism drop an email to koth@tryhackme.com with the game number. The logs can prove if it's an autopwn or not

gilded prism
#

done it

brazen cloud
#

^

terse willow
#

As for storing flags and creds, it's a bit of a dick move. It spoils the game for other people

brazen cloud
#

There is no party other then the admins who can verify the logs

terse willow
#

Not much we can do about it yet though

gilded prism
#

i'll just mute and block the childish kid. Imagine this platform is to learn and have fun and you got guys like him lol

quiet schooner
#

Be the better person here, best move @gilded prism

brazen cloud
#

Hey, we can keep it civil though.

quiet schooner
#

@sullen hound You've had warnings before. Be very careful.

#

Do you?

gusty cradle
#

James isn't a therapist ๐Ÿ˜›

terse willow
#

That's enough. Innocent until proven guilty and all. The admins will check the logs -- if there's an issue here then they will sort it.

#

Otherwise, there is no fault

quiet schooner
#

Under rules 2 and 4, please move on.

#

Nothing to see here.

#

Talk to a mod if you have a complaint.

terse willow
#

What's the complaint then?

gilded prism
#

?

quiet schooner
#

@gilded prism Please make sure that you respect rule 1.

#

Issue dealt with

#

Please move on

gilded prism
#

please don't make stuff up. i'm done here

quiet schooner
#

If you have an issue with how I handled that, please take it up with @terse willow

terse willow
#

Ta James... ๐Ÿ˜†

fair adder
#

Anyone looking ot get into some KOTH

brittle flicker
#

Whoโ€™s Koth?

gusty cradle
#

@brittle flicker An AI from Mars ๐Ÿ™‚

#

@sullen hound I'm joking ๐Ÿ˜›

fair adder
#

yup, thats exactly what i thought. leaving this game.. no time for pwnscript players

#

good luck to the rest of them. thought i would give him another chance

#

63 seconds and all passwords reset and 2 of 3 enterances are patched

#

no human types that fast. good day. you are blocked

terse willow
#

@sullen hound this sounds suspiciously like another altercation, about half an hour from the last one...
You've had a fair few warnings now

fair adder
#

all reminds me of hte convo that James had in here the other day about trust

quiet schooner
#

For those playing along at home, that was a ban.

exotic quiver
#

typing so fast you can reset all passwords and patch 2 entrances in like a minute. seems legit

fair adder
#

i don't want the kid banned. just want someone to talk some sense into him. this is a platform for fun, learning, and growth.

terse willow
#

Don't worry -- kid's been a pain to quite a few people, for quite some time; despite being told not to quite a few times

fair adder
#

can't fix stupid.

#

but you can make it hurt

stiff egret
#

loool, he's banned?

warm chasm
#

OK now that it's reset I know for sure. He also killed the blog for no reason

fair adder
#

he didn't patch the phpshell yet

stiff egret
#

LMAO0, btw can someone explain me how monthly leaderboards work? is it the right channel for that?

quiet schooner
stiff egret
#

heading that way..............

carmine hemlock
#

Is chattr +i king.txt; rm -rf /usr/bin/chattr allowed? Someone did that in a match today...

gusty cradle
#

Yeah, it's allowed.

carmine hemlock
#

it's pretty stupid tbh

gusty cradle
#

You can transfer a statically compiled chattr binary to the box to counter it

carmine hemlock
#

Searched for smth like that in the heat of the moment and didnt find any, guess I'm gonna look for it now / make it for myself. Thanks for that tip

quiet schooner
#

There are chattr binaries in snaps

#

For some reason

carmine hemlock
#

It was a centos box, tried to reinstall e2fsprogs but it had too many dependencies to download

quiet schooner
#

@carmine hemlock The VMs don't have internet access, so you won't be able to install packages

carmine hemlock
#

I downloaded them to my box, transfered to target box w/ wget and python simplehttpserver and then rpm -ivh

#

If the boxes had internet access it wouldnt have been that hard

#

(I downloaded the raw rpm files to my box)

exotic quiver
carmine hemlock
#

lmao

gusty cradle
#

Wasn't NSA banned?

carmine hemlock
#

from discord yeah

grand ember
#

discord only i think

gusty cradle
#

Dark mentioned about him being banned from site check the secret chat

grand ember
#

don't leak secret messages 11!!1!11!1!11!1!!111

terse willow
#

He was banned from the site. But he asked really nicely and got that one lifted on the condition of behaving absolutely perfectly...

exotic quiver
#

pretty sure it was just someone memeing ๐Ÿ˜‚

carmine hemlock
#

appearently not

mellow bough
#

I'm looking into this

#

I'm very displeased to say the least

gilded prism
#

Glad to see some action was taken. It wasnโ€™t fun to have fake reports against me earlier. At least heโ€™s been dealt with. Thanks staff, super job!

dapper escarp
rancid pewter
#

GG

warm chasm
#

GG

mellow bough
#

The ban on NSA has been lifted for the time being

mint cargo
#

lol just watching optionals' final match, Dark ur commentary was hilarious ๐Ÿ˜†

brittle flicker
#

Whoโ€™s koth again?

terse willow
#

I pity anyone called koth

#

So, hopefully, no one

brittle flicker
#

Koth must be very popular

#

Heโ€™s even got his own channel

quiet schooner
#

@brittle flicker Hank Hill.

brittle flicker
#

silly

#

that's not Koth

fair adder
#

hanKot Hill

viscid girder
brittle flicker
#

^-^

floral kernel
#

^_^

severe orchid
exotic quiver
exotic quiver
#

is it normal on Production and Food that the king.txt file is always truncated and pretty much can't be edited? or is this a trick ppl use or smth?

quiet schooner
#

It's something people do

royal pilot
livid ginkgo
#

I had a thing earlier where someone nerfed the king file to make it totally unwriteable. On production. Kinda want it to happen again so I can work out how to fix lol

royal pilot
#

Sure thing

#

Probably you're talking about chattr

#

Hop in

brittle flicker
#

heck

#

I keep missing him. I wanna meet Koth

exotic quiver
#

I had a thing earlier where someone nerfed the king file to make it totally unwriteable. On production. Kinda want it to happen again so I can work out how to fix lol
@livid ginkgo pretty sure we were in the same game although i thought it was just the two of us actively playing. the exact same thing happened to me on Food, not quite sure what it was either tbh

livid ginkgo
#

I think it was... all I did was run a while loop. I got the notification ||when someone used chattr|| so maybe they just used that then left? Those other two didnโ€™t do much... wonder if people are trolling... autopwn and troll.

#

I wonโ€™t lie I thought it was you who did that which is why I kicked you off the box lol. I wouldnโ€™t play that dirty normally.

exotic quiver
#

๐Ÿ˜‚

#

ye i have no idea either, i looked through processes multiple times, didn't really see any other activity or could find anything that could've possibly keep the king file from being truncated

livid ginkgo
#

Same here...

exotic quiver
#

i looked at it with tail for a bit and pretty much just a very quick spam of

watchdog2000
tail: file truncated
#

or smth along the lines

livid ginkgo
#

I was so confused why I couldnโ€™t write to the file because I monitored processes like crazy, thinking there was a battle of the while loops between mine and a blanking one

#

Yes occasionally I kept trying different methods of getting the king back.

exotic quiver
#

eventually i just tried to throw as many while loops at it as i could with my name, but no luck in beating the truncating really

livid ginkgo
#

I used nano. Vim. Deleting the file. Echoing to the file. Using a while loop and echoing. Nothing worked lol.

exotic quiver
#

same lmao

#

I honestly feel like it might've been a bug tbh. I'll send an email to the koth address with the two game IDs that it happened in for me

livid ginkgo
#

Possibly Yeahh if itโ€™s happened twice now.

nova tide
#

can you share the game id here?

#

i dont think there would be any bug

exotic quiver
#

3467 - Production
3469 - Food

quiet schooner
#

@exotic quiver People have rootkits

nova tide
#

3467 - Production
3469 - Food
@exotic quiver umm what was the issue again?

#

just checked the games i dont think anyone of those would have root kits

exotic quiver
#

Essentially the king.txt was constantly being truncated instantly after something was written into it

nova tide
#

myDonut is the only one with rootkits i know of. (May be Westar as well)

quiet schooner
#

Nah

#

More people than that

#

@exotic quiver Someone has a script probably

exotic quiver
#

It's weird tho, cause why would they do it if they're not even participating for points

quiet schooner
#

@exotic quiver For fun? To test it?

nova tide
#

*troll

livid ginkgo
#

Do you get points for KOTH games?

hollow stone
#

someone ban optional, he's deleting flags in koth

gusty cradle
#

@hollow stone Really?

hollow stone
#

it was an accident tho, but he did delete it ๐Ÿ™‚

exotic quiver
#

he echo'd his name into root.txt instead of king.txt ๐Ÿ˜‚

weary kindle
#

the flag has already been reverted, put down your pitchforks

twin rapids
#

lul

quiet schooner
#

LMAO

exotic quiver
#

tbf, relatable tho. i did the exact same thing on accident earlier

quiet schooner
#

It's not deleting if it was recovered

#

And tbf it's concerningly easy to do

twin rapids
#

Dalist snuck into da game ;p

exotic quiver
#

yeah, i had to sit there for 5 minutes wondering why i wasnt recognised as the king even tho i echo'd my name

#

then realised i typed root.txt instead of king.txt facepalm

twin rapids
#

F

hollow stone
#

he also killed ssh smh

twin rapids
#

sabotage!!

harsh obsidian
#

@JohnHammond#6971 is kickin a$$ in KotH right now.

mint cargo
#

Hey did u guys see the stream? john/optional/superhero

twin rapids
#

jup

mint cargo
#

they are pitching ideas for THM

#

They are trying to take in more people and do like tournaments!

#

if this happens that will be so awesome! And they will try to make koth boxes as well

twin rapids
#

sounds great

nova tide
#

i am up to play some tetris in those tournaments

#

anyone playing carnage?

nova tide
#

umm anyone knows who that Shikra guy is? in ktoh atm

exotic quiver
#

pretty sure i've seen his name a few times in earlier games, but thats about it

nova tide
#

@sacred viper sorry for ping but just wanted to say Eid Mubarak boi

magic gorge
#

@nova tide - I'm in this koth game, and i'm wondering if something is going on...

#

/root/king.txt isn't matching the service

nova tide
#

No idea what that means ^

gusty cradle
#

Webpage updates after one minute

magic gorge
#

the service on 9999 was showing Shikra's username, regardless of what was in /root/king.txt

quiet schooner
#

Thonk

magic gorge
#

and my name appeared to be in there for a long time

quiet schooner
#

Sounds like they might have broken the rules and interfered with the service on 9999

magic gorge
#

but it might have just been changing last minute

quiet schooner
#

netstat -tulpn see what's listening on 9999

magic gorge
#

not sure, my shells got borked now

quiet schooner
#

What box is it?

magic gorge
#

netstat wasn't on the box

#

tyler

quiet schooner
#

I can't help then

magic gorge
#

i'm not 100% sure though, i could be mistaken here

sacred viper
#

@nova tide Thanks Bro! Eid Mubarak to you as well!

nova tide
#

Khair Mubarik

sacred viper
#

@nova tide What's up with Shikra? that'e me!

magic gorge
#

things seemed weird

#

my shell was getting borked though, so i'm not sure

nova tide
#

just saw the Pakistani flag sooo was just curious

magic gorge
#

i might have fallen for a troll of yours

sacred viper
#

Shikra is me, I just can't change my username on thm

quiet schooner
#

*yet

#

You will soon

sacred viper
#

but i dont think we are in the same game

nova tide
#

yeah i just found your discord name by search

sacred viper
#

Thanks @quiet schooner, skidy said this exact same thing almot 8 monts ago ๐Ÿ™‚

nova tide
#

saw recent game running and saw your name

quiet schooner
#

@sacred viper It's implemented on the backend, just needs to be added to the profile page

sacred viper
#

Oh great, But my username on thm is already gone ๐Ÿ˜ญ

magic gorge
#

well played - absolutely destroyed me

#

i was riskyflea in that game

#

i was confused because from my shell my username was showing up in the king file for a few mins in a row, but the 9999 service was showing yours. I think I fell for a troll from the box or another player though

sacred viper
#

i don't think i even used port 9999

#

i stared with port 8080 to get a shell

quiet schooner
#

You don't interact with 9999

#

9999 is how TryHackMe knows who's king

magic gorge
#

port 9999 is what the tryhackme uses

sacred viper
#

Ahhh! Gothca ๐Ÿ™‚

magic gorge
#

i got nowhere with 8080

#

managed to get through 80

#

found one way up to root from there, but it wasn't a fun shell, and it went after a while

sacred viper
#

Oh! how did you manage through port 80

#

by /upload

magic gorge
#

i think i might have managed to kill my own root in a panic ๐Ÿ˜„

sacred viper
#

ha ha ha ๐Ÿ™‚

magic gorge
#

we allowed to give solutions in this discord?

#

as in give specifics of how we did it

quiet schooner
#

No spoilers

sacred viper
#

not sure, @quiet schooner can answers

#

oh okay! Thanks Ninja!

magic gorge
#

shame, i kinda want to know how you got in through 8080

#

i found a login page and couldn't see a simple way past it

#

dammit, i just realised the troll i fell for...

#

the name of a particular file just dawned on me ๐Ÿ˜„

nova tide
#

shame, i kinda want to know how you got in through 8080
@magic gorge try harder

gusty cradle
magic gorge
#

๐Ÿ˜„

#

i thought i was sitting with name in the king file, so stopped trying harder

#

i was wrong

sacred viper
#

๐Ÿ˜€

nova tide
#

well its always best to set persistence

#

^^^ doesn't matter if you are king or not it always helps you win the late game

magic gorge
#

i had persistent access to the troll

#

i can't really say any more without it being a spoiler i guess

#

i definitely need more practice at this

nova tide
#

Good Luck

magic gorge
#

thanks

jovial moat
#

anyone here currently playing?

sacred viper
#

Not me!

magic gorge
#

i am

jovial moat
#

Are we allowed to attack other players?

magic gorge
#

not their machines

jovial moat
#

I see...

magic gorge
#

the rule "No attacking other users" seems vague now i read it again to be fair

jovial moat
#

Yeah

magic gorge
#

that's how i read it the first time

#

what does "attacking" mean?

jovial moat
#

I've avoiding being mean to others

quiet schooner
#

@magic gorge Killing shells fine

jovial moat
#

well smashing my pty seems pretty attacking

quiet schooner
#

Scanning their machines? Nope

magic gorge
#

yeah, i killed shells and catted /dev/urandom to his pts for a while

#

was assuming that was fine

#

sorry if i've misunderstood that

quiet schooner
#

That's fine

magic gorge
#

i'm pulling my hair out here trying to work out that permission you've set on that file though

quiet schooner
#

That's not their machine, that's their shell on the KoTH machine

#

@magic gorge lsattr

magic gorge
#

aaaah

#

cheers

jovial moat
#

Is anyone else playing??

magic gorge
#

my poor backdoor user ๐Ÿ˜ข

jovial moat
#

huh?

magic gorge
#

the password for a backdoor user i added no longer works

#

or i can't copy and paste

jovial moat
#

yeah, sorry about that

magic gorge
#

the latter is likely

jovial moat
#

you can come back in, scotty / foo

#

@magic gorge ^^

magic gorge
#

๐Ÿ˜„

#

think it's a bit too late now

#

don't suppose you fancy giving his sudo rights back? ๐Ÿ˜›

jovial moat
#

Organisation policy forbids it

magic gorge
#

How quickly do change requests get processed?

jovial moat
#

Raise a Service Now ticket

#

You have sudo back

magic gorge
#

i'm scared to use it

#

worried it'll pop up into powershell or something

fair adder
jovial moat
#

hahaha

magic gorge
#

root@spacejam:/root# tail king.txt
Daviey
root@spacejam:/root# cat king.txt
cat: king.txt: Permission denied
root@spacejam:/root#

#

i wondered if you'd modified cat

#

never wondered for long enough though i guess

quiet schooner
#

You know about tac?

magic gorge
#

not really

quiet schooner
#

tac is cat

#

but different

twin rapids
#

in reverse ๐Ÿ˜ฎ

quiet schooner
#

cat is for concatenation

#

tac concatenates the arguments in reverse order or something

magic gorge
#

reverse line order it seems

jovial moat
#

how many vulns do i need to patch??

quiet schooner
#

All of them really

magic gorge
#

yeah, i got root quickly this game, set up some persistence, and nobody else had done anything to i relaxed on patching. you saw first hand how that went

jovial moat
#

๐Ÿ˜†

magic gorge
#

tac real-king.txt

riskyflea

#

the one i'm still confused about is how the king file magically gets the immutible attribute on it when i try write to it

#

inotify involved somehow?

quiet schooner
#

Someone has a script probably

magic gorge
#

yeah, couldn't see the script is ps

#

it doesn't seem like a timing thing

#

@jovial moat - is that rs1 something that was on the system, or is it yours?

jovial moat
#

Yeah... some people are real b*stards

#

that is mine

livid ginkgo
#

ps aux May help. And โ€˜wโ€™

jovial moat
#

rs1 is just a reverse shell

livid ginkgo
#

Letโ€™s you see who is running processes. I had this happening earlier tho and couldnโ€™t find out what I needed to kill.

#

I didnโ€™t want to be an ass and boot people off every time they got back on

magic gorge
#

i always forgte about w

jovial moat
#

@magic gorge congrats on getting first blood. That was faaaast

magic gorge
#

congrats on the win. that was clinical once you got on

#

i saw the port i got in through, and new it's something i like to go straight for

#

i don't really get how aggressive to be to other players in these. I probably could have patches every vuln (or at least every obvious one) in the time i had as root, but that seems like it would just ruin the game

quiet schooner
#

Eh, I've locked players out for 58/60mins in a game before

jovial moat
#

Yeah.. I feel the same way, I mean - you just just wreck every pty that isnn't yours.

quiet schooner
#

Don't have to worry about wrecking a tty if they can't get a shell

jovial moat
#

chmod -x /bin/bash , nobody will be able to get a shell after me ๐Ÿ˜„

quiet schooner
#

I just close vulns and sit back

#

Put some rickrolls in the JS files

magic gorge
#

You could just script killing any new process, or any new process that is a shell of some kind

#

that could be a loop you paste in as soon as you get root

jovial moat
#

Ohhhhh that is a good call. I need to prepare some http redirects to rickroll if people try to use patched vulns.

magic gorge
#

Messing with user's deafult shells could be fun

exotic quiver
#

The thing with killing any new processes is that the machine wouldn't be usable anymore by "legitimate" users.

livid ginkgo
#

Rick rolls would be greatttt

#

Thereโ€™s so much potential to trolll people

#

Still allowing them access. But trolling. The occasional boot off is okay too.

exotic quiver
#

Would be especially great on Fortune with the randomness I think ๐Ÿ˜‚

livid ginkgo
#

Ahh you patch everything except the chancy one

#

Then wish them luck lol

exotic quiver
#

Tell them it's a 1 in 1000 chance to get a shell, but instead it's a 1 in 1000 chance to get rickrolled

quiet schooner
#

999/1000 rickroll, 1/1000 for a shell

livid ginkgo
#

Ha

magic gorge
#

Give them a shell on a different box

livid ginkgo
#

Now that

#

Hahaha

#

You set up your own little docker machine that they spawn into

#

And it even has a priv esc and king file

#

Damn thatโ€™s evillll

jovial moat
#

On it.

livid ginkgo
#

There must be a rule against that ๐Ÿ˜‚

magic gorge
#

This could backfire when they escape the docker container ๐Ÿ˜„

exotic quiver
#

I was just about to say that, just make them a small environment with a fake root user and king.txt

quiet schooner
#

I thought about adding that to a KoTH machine

exotic quiver
#

Make them scratch their heads on why it's not updating that they're the king

magic gorge
#

I think someone has done a less over the top version of that to me before

#

I realised after the game ended

jovial moat
#

HTB had a docker one where you had to bounce between containers.

magic gorge
#

was that the reddish machine from a while ago?

jovial moat
#

yeah, ~2 years ago it was live

magic gorge
#

I loved that one

jovial moat
#

Same

magic gorge
#

there's somehting really satisfying about jumping through loads of docker containers

jovial moat
#

Yeah, i felt the same way. Wasn't haaaaard... but felt rewarding.

#

Anyway, it is late in Britland, go to bed @magic gorge ๐Ÿ˜„

magic gorge
#

wow just realised how late it is

#

thanks mum!

exotic quiver
#

I mean, I feel that way already with just getting on a box, I can imagine how great it'd be to hop through multiple containers

jovial moat
#

@magic gorge Look forward to kicking your butt next time ๐Ÿ™‚

magic gorge
#

In fairness, it is slightly dissappointing to get a shell and have no user.txt

#

I'm patching everything next time

#

Adding a ticket system where you request shells

#

Well played though. I was in pain for the second half of that

exotic quiver
#

Would be great if you could pull that off without interference

#

Inb4 there's a vuln in your ticket system tho

magic gorge
#

I'll make a deliberately vulnerable one. Just patch all the box vulns and run my own ctf

#

Most of me is joking about this, but there's part of me that is really tempted....

fair adder
#

whoever made carnage.... wow

livid ginkgo
#

Is it good? Iโ€™m hoping to find it tomorrow to give it a go

fair adder
#

well i have bashed my face against my laptop for the past hour so....

livid ginkgo
#

Ah wow then... damn.

#

If i werenโ€™t already in bed Iโ€™d boot my laptop and VM and give it a crack.

nova tide
#

Anyone playing koth or planning to stream in KOTH-STREAM?

livid ginkgo
#

I might play a game later on

burnt depot
#

i hope to get another go at Carnage tomorrow

fair adder
#

it's allowed to change the ssh creds ?

livid ginkgo
#

it is

fair adder
#

how should we know it then ?

livid ginkgo
#

as long as the service can be used by a user, its fine. so no shutting services down, but password changing, or taking malicious code out is fine

fair adder
#

hmm

livid ginkgo
#

the vulnerability is disclosed credentials/easy to crack creds. therefore to patch you change the password no?

fair adder
#

the creds stored in the mysql , and it's still the old one i used but no longer work

livid ginkgo
#

ok so someone changed the creds so you cant get in that way - thats allowed. you just need to find another way in, or see if they set the password to something brute forceable (liekly not though)

fair adder
#

Okay !

livid ginkgo
#

sucky! but yeahh

#

good luck!

icy cave
#

anyone wanna play carnage? starts in 5mins

livid ginkgo
#

damn misse dit

icy cave
#

still open @livid ginkgo

livid ginkgo
#

okay coming

#

joined ๐Ÿ™‚

finite turret
#

Darkbandit...

stiff egret
#

Can I have the spectator link?

#

@icy cave

icy cave
#

im failing miserably

stiff egret
#

Oh lol, I thought many peeps are in game

livid ginkgo
#

are you on th ebox?

#

im not lol

icy cave
#

nope

stiff egret
#

Actually m just too lazy rn to get up from bed and turn the sys on. Wanted to do this. Ah

livid ginkgo
#

man this is tough

livid ginkgo
#

another game starting in 2 mins

unkempt pagoda
frosty bolt
#

I jumped in and saw two 0x9 and noped tf out

unkempt pagoda
#

Meh, i'm 0x9 but wouldnt consider myself as good at all

brazen cloud
#

koth is a whole different ballgame ๐Ÿ™‚

#

You might surprise yourself @frosty bolt !

unkempt pagoda
#

I've lost to people with lower ranks

#

Ranks dont have to say anything

fair adder
jovial moat
#

๐Ÿ˜„

fair adder
#

don't worry im preety sure you can win me cuz im noob..

jovial moat
#

@unkempt pagoda Are you still playing?

unkempt pagoda
#

Uh yeah im in that game i posted

jovial moat
#

@unkempt pagoda Is that 3532?

unkempt pagoda
#

3533

jovial moat
#

@livid ginkgo GG.

livid ginkgo
#

it was indeed!

#

carnage is tough!

unkempt pagoda
#

People just resetting the box once you patch one of the vulns ๐Ÿ™‚

exotic quiver
lost olive
#

i'm in!

exotic quiver
#

Did someone really delete the ls binary? ohno

lost olive
#

more binaries are gone ...

exotic quiver
#

all of them are gone lmao

lost olive
#

looks like you win

exotic quiver
#

i feel like someone did a cheeky rm -rf /

#

the only folders left are /dev, /proc, /root, /run and /sys

lost olive
#

that's pretty nasty

exotic quiver
#

i voted for a reset

lost olive
#

yeah me too

quiet schooner
#

Report em

exotic quiver
#

yeah, will do

lost olive
#

a reset isn't in your best interest though. you're king atm

exotic quiver
#

true, but i dont wanna win like this

#

i play dirty, but not this dirty

quiet schooner
#

Pretty sure THM stops awarding points if the king service is broken

exotic quiver
#

the koth service still seems in tact

#

it's still reading the king.txt file fine and awarding points, yikes

#

pretty sure the koth service lives in the /sys folder, so yeah

lost olive
#

well that was the shortest koth i've ever played

exotic quiver
#

Yeah, this machine is quite easy to be fair

lost olive
#

true. this is my first time playing it and got root in < 5 minutes

#

and it has a nice surprise that kills your session ๐Ÿ™‚

exotic quiver
#

Does that binary really kill your session?

#

For me it never does, it just prints the cheesy strat text on wall but my session remains

lost olive
#

it's not a binary. it's a simple shell script

exotic quiver
#

ah, shame i cant look at it now ๐Ÿ˜‚

lost olive
#

hope someone else hits reset so we can continue

exotic quiver
#

nah, it's part of the machine

#

i have

lost olive
#

me too

#

it's 3/4 atm

exotic quiver
#

tho from the looks of it half of the game never even touched the machine anyway

unkempt pagoda
#

Well that guy 'patched' the machine

#

Yeah i did

exotic quiver
#

Reset is on 4/5 now, yikes

unkempt pagoda
#

Ssh is running but im getting kicked

exotic quiver
#

probably because it can't put you in the correct folder

unkempt pagoda
#

There is a mail address you can report him

exotic quiver
#

Yeah I'm aware, I've done that

unkempt pagoda
#

Ah good

exotic quiver
#

I feel like I made the dude ragequit or smth, lmao

burnt depot
slate crow
#

reset ?

#

once again ?

final nest
#

lol @exotic quiver man ur /dev/pts/5 right?

exotic quiver
#

maybe frogeyes

#

oh ffs

#

someone's spamming me with /dev/urandom, big oof

final nest
#

XD someone's broadcasting messages to my shell ๐Ÿ˜•

#

lol gg wid u guys

slate crow
#

gg boys

#

I was actually doing /dev/urandom on you duco

#

xD

#

you did really great tho

#

btw now everyone knows it once john hammond used it

#

xD

#

it's pretty crazy

icy cave
#

pretty easy to escape too

exotic quiver
#

When the machines have been around for a while it's pretty much just a game of cat and mouse really, I usually just upload a chattr binary and hide it somewhere with a name that fits with the folder contents

#

Would be nice if things such as passwords, ssh keys etc could be randomised per reset

slate crow
#

do you mind sharing the chattr binary ?

#

๐Ÿ˜„

exotic quiver
#

lookup busybox binaries

slate crow
#

ohh

#

thanks

icy cave
full grove
#

@exotic quiver thats a feature being worked on ^-^

exotic quiver
#

Ah nice

#

Just posted it in #544951750801752079, but good to know it's being worked on. I'm sure that will make things more fun ๐Ÿ™‚

full grove
#

agreed, password and flag randomization is probably the easiest of the set (for Linux anyways)

#

just head /dev/urandom for 16 lines then md5sum it

exotic quiver
#

Yeah I reckon it'd be a little harder with Windows, but probably doable nonetheless

full grove
#

dynamic ssh keygen shouldn't be too much of an issue either, it's just creating & testing the scripts

quiet schooner
#

The flag randomisation has to be implemented on the backend

#

Dan has a PoC, skidy needs to do it

weary kindle
#

yeah, the scripts are made already

#

they were made like 3 weeks ago

worldly igloo
#

is patching vulnerabilities like removing the vulnerable code in a web server or removing suid binaries allowed?

quiet schooner
#

@worldly igloo Have you read the rules?

worldly igloo
#

yeah

quiet schooner
#

I recommend reading the rules

#

They will answer that question

worldly igloo
#

well, i just wanted to know what includes in "patching vulnerabilities"

quiet schooner
#

Patching the vulnerabilities is included.

#

The rules tell you what you're not allowed to do.

lost olive
#

you can remove suid binaries, or patch the machine in other ways. You can't firewall the machine or make it unavailable in any other way.

#

the rules are pretty clear on that

worldly igloo
#

yeah

#

Thanks :D

quiet schooner
#

@worldly igloo Just remove the suid bit tho

worldly igloo
#

okay

final nest
#

is there any prob i get a 404 cannot join public games

hollow stone
#

yeah, the site is being sucky

final nest
#

lol y now xD

teal field
quiet schooner
#

The site is having trouble

teal field
#

Yeah, TryHackme is having trouble

final nest
#

Yea it's having some troubles ๐Ÿ˜

teal field
slate crow
#

is koth down ?

quiet schooner
#

THM is

slate crow
#

okay

teal field
#

How do you actually get a role on THM

livid ginkgo
#

You can sync your on site profile

slate crow
#

@quiet schooner actually THM is working, KOTH is the only thing which is not working on my side

livid ginkgo
#

You can get a discord token from your profile @teal field

slate crow
#

@quiet schooner actually THM is working, KOTH is the only thing which is not working on my side
is it because site is cached on the server side ?

quiet schooner
#

No idea

#

They're fixing stuff

slate crow
#

cool, let's hope for a new KOTH box

quiet schooner
#

Site doesn't go down for that

nova tide
#

cool, let's hope for a new KOTH box
@slate crow Carnage is already out

teal field
#

@livid ginkgo but where

nova tide
#

on your profile? ^

quiet schooner
#

@teal field On your profile on the site

#

Then DM it to the bot like !verify yourTokenGoesHere

nova tide
#

https://www.tryhackme.com/profile

#

in Other tab you can find your discord token

teal field
#

I have it. Where can I verify it?

quiet schooner
#

Then DM it to the bot like !verify yourTokenGoesHere
@quiet schooner

slate crow
#

let me know when KOTH is back pls

nova tide
#

its back @slate crow

slate crow
#

it's still giving me 404

nova tide
#

working fine for me

teal field
#

I think im to silly

slate crow
#

yeah, might take a while to update for me

final nest
#

Will it be up by today i meam koth?

quiet schooner
slate crow
#

yeah, prob. within 5 mins

#

will be up

quiet schooner
#

@final nest @slate crow Some games will be broken

#

it happens sometimes

slate crow
#

what do you mean by some games ?

final nest
#

So how long will it take for you guys to fully fix em

quiet schooner
#

@final nest Mods aren't the site creators

#

@slate crow /game/number

#

Like that

final nest
#

Yea it breaks for me

quiet schooner
#

I can view it tho

final nest
#

Lol i can view too sry

#

But joining a public game gives me 404

quiet schooner
#

@lusty portal If you can, the current active public game doesn't exist

nova tide
#

Last active game id was 3554

slate crow
#

yeah, new public games are broken

#

all of them redirect to 404

teal field
#

Now I have verify my token, but in my profile is no difference

nova tide
#

i think 3555 must be broken it may be automatically fixed within those 25 minutes waiting time or if an admin can just skip that game smh

teal field
#

Now I have verify my token, but in my profile is no difference
@teal field Where can i set my roll up

livid ginkgo
#

It says you are 0x06

teal field
#

ok . thanks

lusty portal
#

New games are fixed,I found the issue, will fix when I'm home tomorrow. Sorry about that:)

nova tide
lusty portal
#

Whats the id?

nova tide
#

ok joining public is fine now.

lusty portal
#

Yeah, there will have been a short delay in that working.

teal field
#

Yeah, it works now

nova tide
#

@stiff egret nah too tired to boot up my vm

stiff egret
#

lmao

gusty cradle
#

That 404 icon looks oddly familiar ๐Ÿ˜

slate crow
#

Public game still doesn't work

#

still redirecting me to 404

teal field
nova tide
#

ok it bugged out again..

teal field
#

would be coool

slate crow
#

๐Ÿ™‚

teal field
#

will someone join koth1

slate crow
#

sure

lost olive
#

what was that command agian to stop /dev/urandom from messing up your terminal?

mint cargo
#

mesg n

#

to make ur pty read-only

lost olive
#

hm, that doesn't work if someone is already messing with you, though

mint cargo
#

yeah saw that in john's video. it messes up the stdin i guess

lost olive
#

that reminds me to turn off the terminal bell

#

dripdripdripdripdripdripdripdripdrip

stiff egret
#

tyler retired?

nova tide
#

^^??

quiet schooner
#

@lusty portal tyler gone

nova tide
#

Ooh so that wasn't intentional

quiet schooner
#

Skidy didn't tell anyone if it was

#

Spacejam should be retired if any get retired IMO

stiff egret
#

ah true

lusty portal
#

No, the machine pool table list just shows 10 at a time:)

nova tide
#

Oh ok...

quiet schooner
#

@lusty portal Probably best to fix it then, if Tyler is still in there. Maybe a scroll bar or something?

leaden spoke
weak haven
#

I got king finally lol

#

even if it was for two minutes

leaden spoke
#

@rancid pewter did you remove everything?๐Ÿ˜†

rancid pewter
#

I didnt remove anything

#

Just messing up with people shell

leaden spoke
#

hahahaha

rancid pewter
#

What ?

#

There a bunch of way to bypass it and you can easily do 200 points to get your shell back

quiet schooner
#

@chrome pumice It's a DoS on your shell, not on the box or a service on the box.

leaden spoke
#

Hey GG @rancid pewter

rancid pewter
#

GG

leaden spoke
#

did anyone use the port 3000 script?