#koth
1 messages Β· Page 32 of 1
DM the bot
@terse willow thanks
@fair adder yeah
There should be a Discord token on your profile page
Send the bot !verify token
Using your token instead of "token"
Anyone want to play carnage ?
yeah
yeah im up for it.. still havent found a way in on port 80
@fair adder we'll be playing it soon with elf and badtaste
Ok Iβd like to poke at it if yβall need a player
sure
okay
@fair adder @fair adder @wild needle i'll dm you the invite link if you're all ok with that :)
im ok with that π
the game starts in 15 minutes
Yup
@grand ember yep
Reverify with the bot
i go voice chat @fair adder @grand ember
me no mic lol
maybe tonight i will talk in like a few hours
wall "John Hammond I am coming for you"
let me connect to the VPN first
wall "cj folow tha damn train"
how do i level up ? just complete more rooms?
win KOTH?
@fair adder Get points in rooms
Elf, you find that illusive KOTH yet?
Dang I am in rabbit hole on carnage
wiz... send me an invite in your game
glad to help gently nudge you
I'll make a game in a sec
@grand ember so you subbed anyway π
subbed again today
β€οΈ
just got my allowance 
someone my friends DM me about tyler please
@fair adder what you want to know?
umm why?
echo "Naughty" > king.txt
contents are correct
cat king.txt ?
wizkid
is your name same on THM as well?
yup
check now it should be working..
echo wizkid > king.txt
@fair adder you missed thm in your name there ^
Its case sensitive as well
try going to <Tyler IP>:9999 what it shows there?
if it contains your name you will start getting points
so the king.txt should exist, if you had to create it either someone deleted it or you're doing omething wrong
im the only one on the box
if its blank page that means your name isnt in king.txt


THM needs a theme song like offsec
@fair adder #544951750801752079 π
Imagine Dark BeatBoxing 
THM is the place to be
ippsec and hammond all be
thm for life
super nintendo - sega genesis - i could never imagine a platform like this
15 mins
holly man the top of the leaderboard is here @fair adder ahahah

@grand ember dude go easy on us
dw, probably won't get too far if this isn't carnage
btw it is a big success, you are doing a lot in your 17's
tf is that
nah
i'm doing recon for future games rn
so no really agressive plays except for killing shells from time to time
aa pls no π¦
was it you who got a pasta shell?
you can still get in as pasta
just created bread
lol don't destroy shell

bruh he keeps killing it π
that was rude

changing the pass
I didn't
Basic defence
i'm jsut sitting as root looking through the files
ninja got me out of my terminal to look at discord so i got back to killing shells 
you are not human lol
Wowowo gj you just crashed my pc
no way you can think that fast there are two ways 1 you are not human 2 you did this room 10023039845984 times
i did it literally once
Have you rooted hackers yet?
I am new on koth
@quiet schooner havent played it last time got 4 flags
I haven't got a single flag out of hacker sso far
@grand ember wow you wrecked my pc
LOL
Im legit gonna continue from phone and change my pc to old one cuz this one is tilting me 2 much SMH
Killing your shell = false Lol
@grand ember good luck findin all ahahaha
flags?
yeah
did you delete one of them? 
Flags for Food are easy π
Removing and moving flags is not okay @lone gorge
@grand ember bro I disconnected
And thats rule breaking

I got 3 before szymex crashed my pc...
I have all the flags for Food stored π
@gusty cradle i just save paths for flags 
7/8 flags 
go ahead
The last flag is a pain to find π
grep is taking it's sweet time
can't we finish the room earlier aahhaa
bro as I say cats are alien
and you are the prove of it π
@gusty cradle which one was supposed to be the hard one 
It's a little more difficult than the others, through grep does wonders π
we are in Koth-1
grep did its magic in seconds when i used it on dirs and not on /
what box was that?
Carnage i think
xD
No it was Shrek I think
koth? start in 13min https://tryhackme.com/games/koth/join/00d532da882d82a82f91ac4b
why the box is sooooooo slow?
cant even ping it
I have no clue whats going on in this game ^^^^
toooooooo slooooow
lol
33 packets transmitted, 0 received, 100% packet loss, time 32776ms
@severe orchid you doing something?
is there supposed to be only one flag in the fortune machine?
@severe orchid there are 8
btw did you deleted all website data?
no
i have no fokin clue whats wrong
after every 10-15 seconds i cant access the box
404 page on site
yeah someone broke it
see your king time is not increasing either
i am in machine and its not even changing king
...
nvm
....
can you ping the machine @severe orchid
?
29 packets transmitted, 0 received, 100% packet loss, time 28661ms
@severe orchid can you vote reset? box is broken.. as its not even changing the king for half an hour
welp the box is broken.. peace out
idk who did this though ^ Well not like anyone gonna check it anyways
why is my king time not increasing?
Well only you and i were in the machine. so one of us must have broken the machine and i am pretty sure thats not me
hi, is the fi** up***d the right path on carnage?
https://tryhackme.com/games/koth/join/36c29d7cdf7e05222f0ad3f2
Koth if any of yall are up for it
starts in 5
rooted in 5
Anyone wants to join
Starts in 8 mins
@nova tide oooo 0xD
π
eh you will wreck me
Only if its food π
@nova tide who
@nova tide no, who is a command
tty?
to check your pts is tty, with who i can check others
π
Aaah Nice Try Naughty Boi, Next TIme :P @nova tide fixed it?
umm Maybe? π
Well i only know 2 ways in.. If you can find other possible ways you can easily get in
i can't im legit angry trying to fix gobuster..
what are you doing with gobuster elf?
anyone for public room?
so i finally managed to extract the wordlist from hackers... if anyone else has, feel free to dm.. my method was very messy and gross..
wut? O.o
on reset no .16 and it takes roughly 10secs to get passwd
^
I would like to know the conclusion if he found the wordlist or not ^^
if its possible imma start working on that too
@nova tide Found one of several
ohkkk
well its better to start finding the way for root shell instead of wordlist
@tardy gull @latent crest when you cant get in you dont have to reset the box as its already working, not broken just patched
oof


autopwn scripts not cool mate
@tardy gull there are machines that can be rooted under a minute
although it took me 2 to add my name in king π
@nova tide I get into wordpess Dashbord....am I in the right path ?
yeah ^
I don't understand what I do in the Dashbord can I ask for any hint or something like that ?
Should I use a PHP reverse shell from Pentest Monkey ?
Most likely you are supposed to find where you can add your own commands.. and get a reverse shell from there
thanks man !
It's a fairly standard wordpress thing
hey am I on the right way with ftp bruteforce (with rockyou.txt)?
autopwn scripts not cool mate
@tardy gull Meh, autopwn isn't a problem - it just means that the box makers need to try harder to make them not work with OOTB tools. Same as port scanning was harder before nmap etc.
@jovial moat No, that's wrong
Autopwn scripts are banned, explcitly
They do have to be tailored to the box.
meh
They'll earn you a KoTH ban.
The rarest badge on the platform.
Not really
Man I joined this game 20 Min after start and no other one has voted for reset π
go go go
Heck yeah I am root π easy
Ah my worst enemy
socket.error: [Errno 111] Connection refused
darnit i forgot to start the listener again ._.
15 mins remaining
@grand ember no mann damnn
well just do not screw my pc too π
OKΔ° π
he said he was going to damn liar
:C
:3
I'm also wrapping up RP: Burp
did i win yet
yikes, didn't get my ssh key in
@lone gorge I might actually win this if I don't let you in anymore 
π’ please don't kick me
you got it π
you kicked me from the limited shell? lmao
π sorry I had to otherwise you would beat me up
bro you won again you are an aliennnn

don't waste your time here tell us how to get to different universes π
it's only possible if you're a cat
π
I think you might actually win
if i can count in the end i'll have around 450 points
and you have 510
yeah if you don't find other flags π
there are only 4
REALLY ??
yeah
omg I can not believe I did it
I will ss this bro that's historical to me after the things you have done yesterday
naaah, i didn't do much yesterday
limited root shell was open
and skidy's backdoor was open
i made a revshell file from skidy because it doesn't have the limits
and executed it from the root shell
i see you in ftp lol
ahaha just lookin around
well how did you send and execute the reverse shell
hey Nighty remember me from that koth earlier
so you connect to the skidy backdoor and print lines to a file with a short path like /tmp/a
@terse topaz what is your thm name ?
Tasaddar
then chmod +x it from skidy
and from the limited root shell you just run /tmp/a
and it runs
@terse topaz your rank is god ?
no I was rank 4 I just ranked up to 5
hah okay yeah I guess I do
that game
lol yall done reset the machine while I was getting food
lol I got root very fast
how do you become labeled as a bug hunter?
find 3+ critical bugs on the site
lol
sleep man π
hii
the hackers machine is a tough one for me, not alot going on on the web side, cant find known exploits that work etheir, not sure if someone patch it already
@lavish mantle on hackers, web has a thing going for it... there is a basic way that I used to get into the box that is just going through enumeration checklist... and idk if they are patched or not cuz I am not in game with u π
yeah i searched for what i could, all i was able to find was one flag, and a "spoiler" that mentioned something about keeping pws secure
i couldn't find alot on the services versions etc to exploit
i did try all pws on all users, on all the services i found
they are random, so it can be bottom of rockyou... just gotta wait it out...
also always doing more enumeration cant hurt
so you connect to the skidy backdoor and print lines to a file with a short path like /tmp/a
@grand ember how did you print it in one single line? echo would take more letters, and i cant seem to figure out the way from cat(concatenate)
@nova tide on 9001 you don't need to worry about line length, you set up the file 4here and run from the root one
Oh, didnt thought about that..
Also afaik you cannot output chars with cat, only files
gg
Anyone want to play Tyler or carnage ?
starting in 5 minutes
@gleaming flint gg π
gg
u get a user shell?
ah nice
escalated privileges
Nice, It was a awesome game
https://tryhackme.com/games/koth/join/51a754134df02737c5ad05b9 anyone want to play Production?
nah I already did production
letsgo babiii
whats it gonnna beeee
space jam?
ah shit.. the 1 windows box π Offline
guys cmon
I am bored
@burnt depot how did you get in as fed ahahaha
did you guys give up ?
you get the password right away
just a matter of guessing accts based on character names
i got a meterpreter shell on there finally
but then kept getting disconnected. i figured that was you π
offline 
i literally tried to exec anything with zcron but it wasn't working 
Are there any good write ups or THM rooms that help with KOTH defense ? How to maintain king, how to properly use chattr etc ?
theres so many easier ways to priv esc
just shut everything down xD
@fair adder Find the privescs and entry points, patch them, remain king.
turn everything off change all passwords and sit there drinking a cup of tea laughing at everyone below you
@burnt depot I changed the password then kicked you you were user fed π
is another koth starting?
yuupppp
BET
hope it aint the windows machine because I have nearly no practice hacking a windows machine xD
I am good at windows machines π
oop whelp xD
someone should live stream it
you can if ya join
@terse topaz you have 10/9 chance dont worry
i dont know that much to participate in koth
@fair adder I do but in another dc
I hope it aint one I already done or it will be boring
could you maybe let me watch?
@fair adder https://tryhackme.com/games/koth/4382
viewer lin
k
thank you
15 minutes remaining
you adn your hacker rank xD
0x2 
that made me wanna die
my python kept failing
hey Nightly do you do hacking outside of THM
@terse topaz Remember that killing services when you don't have to is banned
You can patch almost all the vulns
lol I know
If I really want I can grab my old scripts I had for securing a linux machine
wait is banning your IP from the machine banned xD
Using scripts to harden the box is also banned
oof
so for koth everyone is connected to the same box?
@terse topaz I just do it for fun in THM
oh lol
do not get baned bro π¬
lol
another warrior has joined
oooo they bigger than you in numbers
my money is on nighty
dont let me down
gotta admit I dont like this one because it is such an easy foothold.
foothold meaning you can stay king easily?
can become king and stay easily
ah
@terse topaz by saving how to do all the rooms or lookin wlakthroughs π
lol no this room is very straight forward. xD its too easy
yeah when you look at walkthrough one time and saving it π
I did not xD I did this one yesterday and I remember what I did from then. get into the machine in 2 steps. then root in another 2
then patch that vulnerability xD
hmm though tell you what I dont like how this machine also keeps a log file and appends your Virtual IP address to it lol.
unfortunately I dont rank up from doing these though
nice
is dmc3 in the chat?
ya but appears offline
they did great last game heh
twice as many as everyone else
Ya, he did
I was using the the file upload, but I moved to the HR login. I found a few users that worked. I was hoping for a use for the cookies or something, but couldnt get it to work.
which box?
B)
the resume upload, i'm not sure... but i got the other one
imma start working on LFI/RCE stuff before i attempt that room again
other what?
oh, the docs one
There are multiple upload forms π
i need to get a script for automating 80 and a creds grabber for 81 as i don't like to save stuff and get privesc for bobba
@burnt depot random or a specific one?
I cant get past duku
carnage
lemme boot up my vm
lets go!
damn it already started
@grand ember you are just shooting off π
can someone send me the link to spectate
wait, you did or did someone else
i did lmao
you can get in as yoda but no privesc
if you somehow manage to get in as bobba/duku you can privesc
i am yet to patch this
Jeez, 7 flags. Thatβs the most Iβve seen someone get so far
you can get 2/3 flags easily rn
how did you get in as yoda? I have been stuck at duku for the last 5 games
Feels good xD
patched duku B)
I see that
ok, i reverted bobba's password
if you can privesc via that then congratz
cuz i don't know how yet
I see home/yoda/link
@burnt depot did you figure out how to get to yoda or bobba?
not directly... only cuz i got to the filesystem
duku was the easiest way in for me so far π
same
what was it?
π
lol
this is so duuuuumb
meaning i am dumb
but i couldn't know until i got a binary on the box
found a nice place with precompiled static binaries
did you block the privesc path u took?
from duku? yes
yoda also patched
only way in is via bobba
but i think i know how to patch that
ok patched 

nice
ok patched
Angry noot noises
everybody is welcomed
Nighty != Naughty
shttt
Ik
and my vpn doesn't want to connect
you always bored
i'm bored
@grand ember rooted hackers yet?
didn't get any chance so far
last time tho π
I wanna find that insta root that James always brags about π
well, i did get a chance but didn't root it lol
@grand ember don't get nasty boi
https://tryhackme.com/games/koth/join/44e7b83a21311b9d917e8b22
@lone gorge which room
Box*
@nova tide IDK yet
download it back bro
i'm doing it rn
come onnnnnn, my ovpn file is expired or smth
Reinstall windows, worked for me
imagine using windows
the key is missing the certificate+private key when I compare it with a key from my alt
they say anonymous is back because of that cop and also my friends instas got hacked
ugh, i'll need to work off a regular server for this game
I'll miss my old IP 
fortune 
never touched it
GG
VIP server?
yea
can you reconnect?
Regular one is working fine for me.
yeah
anyone can connect ?
to what?
ssh
umm i am in through ssh
wait? why reset?
ok i am literally not getting why are you even resetting the box?
and why 2 votes at once?
Can you send me the spectate link
Anyone wants to join
?
It's in 8 mins
is it allowed to change sudo rights?
Yes, you're allowed.
okay great
Yes, you're allowed to kill shells
Yay
go in koth-1 voice
who want to play koth in 10 minute ?
@jovial field come to my game there is more ppl
i just did read the above
@fair adder inb4 production again
ah k
ok im in
@exotic quiver putting it into gif?
first extension that came to mind, just trying stuff atm
did it work ...
did someone just kill ssh in our box lmao
who killed ssh
lmk in DMs if you wanna know how i got it done @fair adder
okay
i donno
F
Yeah the others left
anyone know what you're supposed to do with the overly limited shell?
Find a way to make it less limited
Yes lmao
@fair adder how do you both come into the machine
im in bed lol
Me too
Is there any like beginner stuff for exploiting code?
https://tryhackme.com/games/koth/join/1f530db3f83e44cd9b78c990 if you wanna join
Starting in 8 mins
Nice tactic, man
anyone can point me in the right directon for /backdoor login page hackers koth machine ? for root@kali:~/thm# hydra -l production -P /usr/share/wordlists/rockyou.txt hackers_ip http-post-form "/login:username=^USER^&password=^PASS^:F=incorrect" -V
Hydra v8.6 (c) 2017 by van Hauser/THC - Please do not use in military or secret service organizations, or for illegal purposes., do i need to use hydra to solve this part?
i dont want to spoil much for you but you can use hydra with the right users/password file used to brute force.
https://tryhackme.com/games/koth/ @hoary vortex
King Of The Hill = koth
oh
Thanks @nova tide i Will look if i can find the right hydra command
https://tryhackme.com/games/koth/join/392cb49b0bb447db0680c4f4 come for a fun game
will jemad koth spielen?
(in 10min)
carnage is pretty okay, i learned much from it
Starting in two minutes: https://tryhackme.com/games/koth/join/5dc62bb22bbfbcaf2b06caa3
Has anyone got all eight flags on Fortune? I've got seven but am stuck on the final....
sh-4.2# passwd shifu
passwd: Only root can specify a user name.
sh-4.2# whoami
root
Starts in 24 minutes: https://tryhackme.com/games/koth/join/60d8a34479095fd8a568acf6
@fair adder gg. i can see with netstat that you're on the box, but for the life of me, i can't figure out how. well done.
@quiet schooner James, did my boy give you some juicy details in that private DM? @icy cave is on a mission to reverse your box. we spent DAYS looking at that thing
That was days ago
i been dealing with them riots.. busy bro
They also used the literal worst way to reverse it
thats part of the fun though. CTFs(in this case KOTH) have a path... but the cool thing is finding other thigs that the creator didn't necessarily want/expect
sure... and he and i have been working it. but damn if that box didn't piss us off (i know i specifically sent you some PMs about my processes) i am sure i am not the only one ... All said... BRO good box, hell good box to all the KOTH creaters
More CTFs coming.
@quiet schooner any chance that ther ecould be a blue /red on a multi box ...ala... more RL than just 199whatever hackers intro hacking scene ---- for a box?
instead of just 10 KOTH, 5 v 5 teams?
on a small cluster of comps
defend a few vulns on a cluster
teams can be interesting
maybe soonβ’
β’
i know that KOTH is in beta. and its honestly pretty f-ing cool ... good job for it.
@quiet schooner quick pm?
It's 3am
really really afast?
like just 2 lines?
only cuz your a box creator and @neon sleet isn't (as far as i know
take that as a yes....
β€οΈ
@fair adder just wait like, 8 hours?
i sent, and i am sorry and i know and yes... my wrist is slapped
that is so that others know not for you necessairly
-_-
shameless plug for those who are curious... these dudes(ladies) do some work...
https://tryhackme.com/faq
15 minutes to go: https://tryhackme.com/games/koth/join/09633f290d85971d1abdd880
Good game @harsh obsidian
gg!
S
@nova tide meant that doesn't mean you can't strategically abuse it
well its a 10/10 game and going to be reset 2nd time.. 4/5 votes
GG to whoever got root
GL as well
GG all
@fair adder try harder π
try what harder
4571 you lost in Tyler against Kaz_N3mz3r(DarkBandit)
imma play some sixsiege
4571 you lost in Tyler against Kaz_N3mz3r(DarkBandit)
@nova tide
We got some intense spectating going on hereπ
Man, I hope koth is doing alright. Has anyone heard from him?
ETA? @autumn iron
i didnt get you
I meant = how much time remaining to start?
8mins
oh boi, gonna be fun
yeah
no idea
@last ether is damn faast bro
π
π
dude you blew up wget
same
and me as a noob having no idea after submitting the single flag!
π
that was fun π
Thats always my move
@last ether well i did that today against you as well. Could have done something about netcat as well
πππ
Once i used chmod 600 chmod as root and couldn't figure out how to undo that
You forgot scp though broπ
@last ether well that was after two resets, sooo
I was not in the game for the first reset bro
By the time I joined, you had already patched everythingπ
So I took advantage of the reset buttonπ
russian federation vs Amaricaaaa
@stable horizon this room is hard asf
not really
bro we tried this room 3 times and couldn't get any results π
which room? 
@grand ember hackers
@grand ember hackers bro do u know how to do it ?
nope
@rancid pewter brooo how did you get in
Brute Force
thats capp bro I been trying bruteforce for 3 days π
._.
whoever got into hackers i really want to know how i've tried everything xD
Hey
did u do it?
koth machine panda ????
machine does not start I guess
we reseted it several times but still
maybe it's just being sneaky π
nope bro it is panda
new room is ready my indian friends if you are here
nah, you just didn't re-verify
you need to re-verify with the bot to update roles here
π
done its upgraded
Naughty > Nighty
password changed! nice move
@nova tide if Nighty == 'ingame':
Naughty=False
print('don't even go there')
(-:
@autumn iron bro I made a user for u to get in username shark password is shark
@autumn iron how you liked the place π
π I left a file you to read π
haha go ahead!
OWNED by NIGHTY
Kral4 is your second account,right? Nighty
hi
whoever is on lion rn fck off for disabling the only vulnerability
That's allowed, and there will be several vulns.
didn't find any other
That's on you. There are at least four vulnerabilities per box, and at least four privescs.
One or two boxes have less, but that's the guide we follow when building them.
If you can only find one, that's your problem.
s
so someone is salty or so it seems, someone's ddosing the box
If you find out who it is, report them
it's ok, I reset the box
@mellow crag gg
@burnt depot nice work mate, was meant to be a private game, so didn't patch up behind me and then couldn't get back in haha, well done
Is "hacker" box possible? we have tried several times and only get 10 points haha. I just want to make sure it is not broken π
It's always possible, but yes
"try harder" then. Thank you π
@trim bloom hackers is designed to be hard.
There was one guy that asked a lot of questions regarding rules.. I don't see him here anymore.. i think it was nsa or something
There was one guy that asked a lot of questions regarding rules.. I don't see him here anymore.. i think it was nsa or something
@mint cargo Yeah he was NSA.
i thought his ban got unbanned
His site ban has been, yes
i finally figured out i think the last path in with @icy cave this morning. Now to find the last privesc.
Do anyone now how to use magic bytes to encode php as png or jpeg
Check in internet
I had
@teal field I've got a room coming out on this soon π
@teal field you can do it with echo and base64
Thanks, but I had found a way
exiftool -Comment='<?php system($_REQUEST['cmd']); ?>' test.png
broooo @teal field how many times you have done this room
yeah I know I have uploaded my rv shells
but you got in so freaking fast
I didn't see your files as well
but I haven't made any notes
how did you get in without uploading any files
I had uploaded a reverse shell
thats my one shell.gif.php
I have not changed the machine and am now going offline, so good luck
problem is servers are bad rn
gg @radiant raft
@fair adder those pesky creators cant make them too easy can they?
I cry on the inside when these things come out and feel sheepish after the ahah moment happens.
You do not want to know some of the stuff we have planned...
I have told James that i love and hate him for his KOTH boxes (and more recently about wonderland). Creators... great job to you all. i disticntly remember sending a message to one saying "i hate you, i hate your box... but damn was that fun and frustrating when i finally got through it)
Good job on sticking on with it (:
I try "advent on cyber" but when i deploy machine for first challenge, i cant enter to website.
i put ip adress of machine in firefox and i got "unable to connect"
but i can ping from terminal
ok now its works
just need to waint some time lol
@wary oxide This is the KoTH channel.
Hi there.
π
Not when it's like, really really easy
not 44 seconds easy
