#koth

1 messages ยท Page 34 of 1

scarlet pike
#

how do u guys usually find patches

#

is it usually just

#

updating the package

quiet schooner
#

Good luck doing that with no internet

scarlet pike
#

oh

quiet schooner
#

You need to understand the vulns

#

A lot of the KoTH boxes have custom code

#

Normally you can remove the vulns from that

#

Or replace the service with something functionally equivalent but not vulnerable

scarlet pike
#

ohh

#

so u can stop the original service

quiet schooner
#

Eg there's a webserver with RCE? Replace it with a python webserver that serves the pages just the same

scarlet pike
#

if u replace it

quiet schooner
#

Well

#

I'm not 100% on that

#

But I'd count it as a patch

scarlet pike
#

ok

#

how would u get access to the

#

custom code

#

to remove the vulns

quiet schooner
#

Languages like PHP are interpreted

#

Not compiled

#

Some boxes have the sourcecode for the services on there.

scarlet pike
#

ohhh

#

if we apply a patch that doesnt work

#

like the

#

service wont start

#

we just undo it and thats fine right

quiet schooner
#

Then you're in trouble ๐Ÿ˜‰

scarlet pike
#

not counted as taking it offline

#

oh rip

quiet schooner
#

But sure

#

Just be sensible

#

Follow the spirit of the rules

scarlet pike
#

ye

sturdy plank
#

@errant yarrow are u in the KOTH???

nova tide
#

starting in 5 minutes

#

public game

keen raven
#

oeps

nova tide
#

you are late

keen raven
#

sorry was an accident

worthy isle
#

Hey! Anyone down to play koth in public? Nobody is playing rn :c

nova tide
#

@worthy isle i would love to but rn busy with friends

worthy isle
#

Np ๐Ÿ™‚

errant yarrow
#

@sturdy plankyes

scarlet pike
#

anyone wanna play koth public?

#

i wanna try it out for the first time

#

:DDD

#

@worthy isle

worthy isle
#

Im doing a private game finally

scarlet pike
#

ooh ok

worthy isle
#

But u can join

#

Itโ€™s on another discord server tho, I can send you the link in dm if u donโ€™t mind

#

@scarlet pike wanna join?

scarlet pike
#

sure

worthy isle
#

Cool

fair adder
wary jolt
#

upvote
@fair adder OP pls nerf

fair adder
fair adder
fair adder
nova tide
fair adder
nova tide
#

who is that b14ckdz ?? in koth

nova tide
#

gg

fair adder
#

how many ways in to shrek?

nova tide
#

how many ways in to shrek?
@fair adder atleast 4 that i know of

tardy gull
#

When are we getting a new room?

fair adder
#

its been like 10min and the machine is still on

#

10min after game finished

nova tide
#

its been like 10min and the machine is still on
@fair adder after reset machine stays up for an hour

fair adder
#

O.o

nova tide
#

When are we getting a new room?
@tardy gull Cryclic working on a new windows machine for koth i think

latent quest
#

yell_cat Oh boy. Windows is fun.

stiff egret
#

Whats with everyone going THM's Official? @nova tide xD

nova tide
#

We are the officials โค๏ธ

#

xD

#

szy and will started this

stiff egret
#

I am one more Offical user away from changing my nickname too ๐Ÿ˜‚

quiet schooner
#

Disclaimer: Not official.

stiff egret
#

xD

#

Pretty cool way to look official tho lol

#

Any mod I can DM about something? (Probably important(?)) (Its about site)

fair adder
#

Iโ€™ve never done a KOTH but always have wanted to. Any tips?

gusty cradle
#

There's a tips section on the KoTH page. ๐Ÿ™‚

stiff egret
#

Probably a spoiler TIP for KoTH @fair adder ||TIP: Always rename/remove chattr binary.||

fair adder
#

Awesome, thanks

#

Your goal is to root it and prevent others from rooting, correct?

weary marten
#

your goal is to write your username on king.txt xD

stiff egret
#

Initially, yes, but once someone is IN the box, the goal is to maintain your username in king.txt. As long as its in there, you are winning.

Your goal is to root it and prevent others from rooting, correct?
@fair adder

fair adder
#

I just remove chattr

#

hate it

stiff egret
#

xD

sturdy plank
#

start in 17 min

livid dagger
#

@stiff egret Yeah, someone on one of the machines left some executables and I took advantage to download them

#

chattr was one but can't remember the others

quiet schooner
#

Pro tip

#

Unless snaps are removed, ubuntu machines will have a chattr in a snap

gusty cradle
#

๐Ÿ‘€

quiet schooner
#

find / -iname "chattr" 2>/dev/null

#

Add it to path or alias

stiff egret
#

Unless snaps are removed, ubuntu machines will have a chattr in a snap
@quiet schooner I thought that was coincidental!

quiet schooner
#

I think it's the core snap that's used in the installer

stiff egret
#

intended?

quiet schooner
#

Snapd is annoying, I've started removing it

#

I mean, it's not unintended?

stiff egret
#

Snapd is annoying, I've started removing it
@quiet schooner true that tho

quiet schooner
#

You can just copy an ubuntu chattr binary over though, about as easily

stiff egret
#

I mean, it's not unintended?
@quiet schooner I mean, I thought creater would remove those purposely

quiet schooner
#

I mean, some do, some don't

#

Snapd takes up like 80mb or something so I purge it

#

As well as LXD to avoid that privesc

sturdy plank
#

start in 9 min

late stratus
#

urghhh playing KOTH against @livid dagger is so depressing.... 15 mins in and the machine is completely patched....

livid dagger
#

sorry, Fortune is pretty easy

#

I only patched one entrance though

#

there are 2-3 other ways that I know of

late stratus
#

I think I might request a staggered start feature.... the more points you have the later you start... I need at least a 10 min head start on you! :p

livid dagger
#

so no, not completely patched ๐Ÿ˜‰

#

hahahaa

late stratus
#

do you think that would be fun! ๐Ÿ˜‰

livid dagger
#

maybe hehe

#

make me have a stress attack

#

you have a chance

#

I have not done this one LION

livid dagger
#

you just screwed up

#

whoever did that

fair adder
#

Initially, yes, but once someone is IN the box, the goal is to maintain your username in king.txt. As long as its in there, you are winning.
@fair adder
@๐“œ๐“ป.๐“—๐“ธ๐“ต๐“ถ๐“ฎ๐“ผ#0980 thanks for the answer. Is king.txt allowed to be moved around?

#

@stiff egret

#

Sorry it didnโ€™t ping you

quiet schooner
#

@fair adder No, if you move it you will break the king service and no one will get king points

fair adder
#

Okay, thatโ€™s why itโ€™s worth asking. So I canโ€™t affect the txt file at all besides editing it

quiet schooner
#

Have a look at file attributes

#

You can make it unwritable, which is very common

fair adder
#

So I can edit the attributes

quiet schooner
#

Immutable

fair adder
#

Thatโ€™s what I was hinting on lol

quiet schooner
#

I mean, there's not a rule against it and it won't break anything

#

It's included as a "people often do this" on the website

fair adder
#

Okay, so itโ€™s basically outsmarting people while on a time constraint

quiet schooner
#

Boot them out the box, patch the box, sit back and relax

fair adder
#

I have an idea but it will be a huge spoiler if I send it here, mind if I DM?

livid dagger
#

is it against the rules to run a command that writes on the opposite users terminal?

fair adder
#

I think that would count as hacking other players

#

Which is against the rules

#

It seems only thing you can do is mess with the machine itself

quiet schooner
#

It doesn't count as attacking other players

#

because their terminal sessions exist on the KoTH box

livid dagger
#

ok

late stratus
#

wow the king.txt is locked down well in this current game... hmmmmm

stiff egret
#

Probably a spoiler tip ||lsattr /root/king.txt ||

late stratus
#

couldnt get "that" executable to work...

#

tried uploading but wouldnt run... couldnt download... zzzzzz

livid dagger
#

so, who is using an autoexploiter for root?

#

gloria@lion:/tmp$ ls ls bash: /bin/ls: No such file or directory gloria@lion:/tmp$ ./cve ./cve [.] [.] t(-_-t) exploit for counterfeit grsec kernels such as KSPP and linux-hardened t(-_-t) [.] [.] ** This vulnerability cannot be exploited at all on authentic grsecurity kernel ** [.] [*] creating bpf map [*] sneaking evil bpf past the verifier [*] creating socketpair() [*] attaching bpf backdoor to socket [*] skbuff => ffff88003cbfcb00 [*] Leaking sock struct from ffff88003b675c00 [*] Sock->sk_rcvtimeo at offset 472 [*] Cred structure at ffff88003a1d6480 [*] UID from cred structure: 1002, matches the current: 1002 [*] hammering cred structure at ffff88003a1d6480 [*] credentials patched, launching shell... [!] exec No such file or directory gloria@lion:/tmp$ ls ls bash: /bin/ls: No such file or directory gloria@lion:/tmp$

late stratus
#

I was

#

googled the kernel and hey presto

livid dagger
#

isn't that kind of against the rules?

late stratus
#

oh.... is it?? its a vulnerability???

livid dagger
#

not saying it's wrong I didn't know it was a vuln but if it gives you root privs, I thought it might be like against the rules because it works like an autoscript

late stratus
#

oh....

livid dagger
#

also, earlier who shutdown the port 1337?

quiet schooner
#

It's not against the rules though

late stratus
#

haha I though that was you!!! your normal trick ๐Ÿ˜‰

livid dagger
#

I don't do that sh*t

#

I just change permissions for users

#

not ports

late stratus
#

hahaah... the last game you closed 22!!

quiet schooner
#

Writing a script specific to the box that will hack the box when you should be doing it manually is against the rules

livid dagger
#

no I didn't

quiet schooner
#

Moving services is allowed but poor defence

late stratus
#

oh... ok

#

sorry!

livid dagger
#

@late stratus there you go! Mod just answered my question

late stratus
#

that one is on exploit-db

quiet schooner
#

Grabbing someone's exploit for a CVE is just fine

#

That'd be a nightmare otherwise

livid dagger
#

so then this ^^ vuln would it be considered auto-"hack" or not. I'm just curious to know because in that case, I would have used it also

late stratus
#

Im confused too

quiet schooner
#

You're grabbing an exploit for a vuln

#

That's perfectly fine

late stratus
#

(y)

#

๐Ÿ‘

livid dagger
#

ok. Well, I have the cve downloaded for next time ๐Ÿ™‚

late stratus
#

haha you dont need anyhelp!!! (ps you owe me one ๐Ÿ˜‰

livid dagger
#

so now, JRo, you still need hacking lessons from me after that DM?

#

hahaha

late stratus
#

I'm such a novice... just trying to learn as fast as I can

livid dagger
#

well, you learned that one fast!

#

also, FYI, I had not done that one ๐Ÿ˜‰ it was fun though

late stratus
#

sooo.... how was the king.txt locked down?? it was empty half the game and I couldnt chattr it..

livid dagger
#

not sure

#

I saw you had a script that looped your name into it but when I did it, nothing happened

#

king was empty after my .sh ran

late stratus
#

there was a koth binary running but strings gave me nothing

livid dagger
#

yeah, don't ever delete it

quiet schooner
#

There's a KoTH service running on 9999

#

The code for the KoTH service running on most of the boxes is open source

late stratus
#

oh is it called koth?

quiet schooner
#

It's a systemd service called koth

#

Yeah and the binary should be called koth

#

You're not allowed to mess with that service

late stratus
#

oh crap.... sorry!! i might have screwed it... I was furiously trying to get king... apologies....

#

the king.txt file was still blank...

livid dagger
#

looool now I know why I couldn't add my name haha

#

well, actuall that service and the .txt don't have much in common only that the service reads the content from the file

late stratus
#

so that file is just a reader though

#

yea exactly

livid dagger
#

basically I guess?

late stratus
#

the file was still locked down somehow

livid dagger
#

you might have locked it somehow?

late stratus
#

did someone screw with the "echo" binary??

#

so that it doesnt echo to king? that would be a sweet mod

#

echo to everything else so looks normal

livid dagger
#

because also, I notiched that lot's of things broke when I was in it

#

I have to go. Be back later

late stratus
#

yep lots of normal services were borked

livid palm
#

in 3 mins if anyone's trying to get an easy W

sudden beacon
#

yoooo

#

iโ€™d love to play with you but iโ€™m in bed now :((

livid palm
#

arent you in the uk?

#

lmao plz sleep

fair adder
#

Iโ€™m about to sleep as well, sorry

#

I havenโ€™t done any koth games yet

livid palm
#

Is it ok to turn off ftp anonymous login?

#

I'm not able to yet, but stuff like that sounds within the realm of patching

hazy zodiac
#

no idea

livid palm
#

But you're the official tomato! If you don't know, who will?

quiet schooner
#

If you're on hackers, there's a much much much better patch

livid palm
#

I'm sure there's a million better things than what i htink of

#

I don't even know if this other person is playing...

#

still fun tho

#

hmm, i'm so conflicted on what's over the line, even if i'm not really playing against someone...

winged charm
#

youโ€™re pretty much good to patch any and everything except for the king service on port 9999 as long as you donโ€™t make the service unavailable. A general rule that Iโ€™ve heard referred to is as long as the box stays that a regular user with good intentions can use it as intended than it is fine and is within the rules. @livid palm

livid palm
#

mind if i ask a specific example?

quiet schooner
#

Website with an RCE command injection vuln

#

Good patch? Replace the webserver with a python http.server

livid palm
#

lol

quiet schooner
#

Still usable, but no vuln

livid palm
#

does it serve the same content?

#

anyway, this is a service that executes stuff as root but with a char limit

#

shorten the limit? Turn it off? What's the potential "good intention" that a user would need that for. I'm 100% overthinking for this round, like i said

quiet schooner
#

decrease char limit to one char? Change it to a useless user?

#

I mean I think you can justify disabling that

livid palm
#

and I'm sure this comes up all the time

#

thanks for the input ppl

#

woohoo first W :king:

autumn iron
#

16mins left

vital shadow
#

Naughty please go easy on us

nova tide
#

Why people left?

vital shadow
#

I dont know

#

Would you mind Being DMed?

nova tide
#

yeah sure you can DM me ๐Ÿ™‚

sturdy plank
#

9min left

sharp harness
#

wanna play anyone?

#

my first koth btw

livid dagger
#

how long does it have left?

nova tide
#

prob over now

livid dagger
#

yeah

#

didn't realize time

#

haha

stiff egret
#

spectate link?

#

๐Ÿ˜‰

#

๐Ÿ˜†

nova tide
#

@livid dagger in your website link to your THM account is 404 page

stiff egret
#

spectate link?
@stiff egret ^^

nova tide
#

btw nice name xD

stiff egret
#

ikr! ๐Ÿ˜‚

nova tide
#

spectate link?
@stiff egret i think the game is over though

stiff egret
#

awesome

nova tide
stiff egret
#

bummer got some issues to resolve, will join you guys later

#

LOL

#

F

#

Will update it on github lol

nova tide
#

i want to see it in action

stiff egret
#

i want to see it in action
@nova tide I'll screenshare lol, I aint gonna show that in public stream ๐Ÿ˜‚

worthy isle
#

Hey, currently playing KOTH on game 6226, just saying, if the other players are seeing this, closing SSH is illegal XD

stiff egret
#

Hey, currently playing KOTH on game 6226, just saying, if the other players are seeing this, closing SSH is illegal XD
@worthy isle LOL

#

It isnt.

worthy isle
#

Huh?

nova tide
#

closing port is. but not if you replace it with some other port

stiff egret
#

You can patch any service, and that includes closing it, IF its un-patchable (is that a word?)

worthy isle
#

Yeah but they haven't replaced

#

They have killed the port

#

But the box has reset now so it's ok

terse willow
#

@stiff egret SSH is patchable.

#

Move it, but don't close it.

livid dagger
#

@nova tide Probably because of a name change I did. Not everything has been updated yet

#

I just checked it and it works fine

#

Oh, I see what you meant. The link at the bottom. Not the link in the widget

nova tide
#

๐Ÿ‘

#

yeah the badge works fine but the link not

livid dagger
#

fixed

nova tide
#

sorry voting reset because i think i broke the box

#

(although i am king)

near sphinx
#

now its working xD

nova tide
#

@near sphinx is that in you koth game

#

oh ok

near sphinx
#

yes man thats me

#

GG

nova tide
#

well it was a fun game with you.. my electricity went off and just came back

#

the one mistake you did was you were writing your name after my name in king.txt

#

so none of us will get points

#

you have to replace mine and enter yours

near sphinx
#

great game

#

how to replace the text if we can only append? i wonder

nova tide
#

well i was trying something new out.. if i was using the old method you wouldn't be able to append either

#

chattr is the binary that makes the file non-writeable/editable

near sphinx
#

i like your trick, added to my arsenal ๐Ÿ˜†

#

so chattr is built in binary inside the box?

#

dangit im sweating, glad it ends xD

nova tide
#

๐Ÿ˜„

wary jolt
#

How can we report or where can we report if something illegal in koth happened?

quiet schooner
#

Check the rules on the page

nova tide
coral sage
#

do koth private games have a player limit?

nova tide
#

10 is the player limit for koth

coral sage
#

thanks!

wary jolt
#

Thanks!blobfingerguns

oak jacinth
#

How many games of KOTH do you have to win to get badge

livid palm
#

I got a badge after one win

oak jacinth
#

I won one and I didn't get badge

fair adder
#

is there only 3 ways to user and 2 to root in lion?

livid dagger
#

don't know

sturdy plank
#

anyone want to play koth??

oak jacinth
#

In a min

thick coyote
#

in 5 minutes

warm trellis
#

Starting in 12 minutes

oak jacinth
#

Well played @warm trellis

#

Good game

#

In recent KOTH game

warm trellis
#

@oak jacinth Everyone just left us :(

oak jacinth
#

yeah. not sure why

#

you still doing the CHallenge @warm trellis

warm trellis
#

I ended up not bothering, got caught up with some school work lol

oak jacinth
#

fair enough

#

I just did it for the fun

#

we will have to play again soon

fair adder
stiff egret
#

ETA?

#

@fair adder

fair adder
#

oh my god i forgot about the game lol

#

@stiff egret it started

stiff egret
#

LOL

celest pewter
#

Me too

rich nexus
#

Anyone on Shrek just now?

oak jacinth
#

Not atm

#

But might do it soon with friends

sinful field
#

i am hosting a game starts in 22

#

need some people

late stratus
#

game starting in 3m!

sinful field
#

just won koth by 8 flags

#

ballin

#

ggs

rapid kiln
#

NeoMakazo are u there

#

Join this voice

sturdy plank
#

start in 10 min

latent shell
#

I'll be posting the invite link at around 5:30 PM BST :) , if you have any questions please don't hesitate to DM

lusty portal
#

Awesome:)

latent shell
scarlet pike
#

is having a bash loop to kill shells legal for koth

#

also @latent shell how many people per team

stiff egret
#

@scarlet pike Qualifying match (i.e. today), will be of solo players type.

scarlet pike
#

oh

stiff egret
#

is having a bash loop to kill shells legal for koth
@scarlet pike Dirty trick, but yeah, legal. (As far as I know.)

scarlet pike
#

aight

#

wait then

#

is the finals solo

#

or teams

stiff egret
#

No, all matches from week 2 onwards, are team based.

scarlet pike
#

2?

#

3 u mean

#

2 is still qualifier

stiff egret
#

Oh yes, sorry, my bad. Guess I am missing a coffee.

scarlet pike
#

so

#

week 2 is still solo?

stiff egret
#

I'll just make sure. Gimme a minute.

#

Yes. Matches in Week 2 are also solo. @scarlet pike

scarlet pike
#

oh ok

slate crow
serene bay
#

Guys the KoTH July Starts in 1:10 hour mins Be Prepared ๐Ÿ˜‹ All The Best

latent shell
#

2mins to go :3

#

Hello everyone,
Here are the links for our first match of this SECARMY KOTH July Event,Please DM me once you've successfully joined the lobby!
Invite Link: https://tryhackme.com/games/koth/join/0b8ad459070e24195f3435a0
Spectator Link: https://tryhackme.com/games/koth/6351

#

@lusty portal lobbies filled within 5 seconds 0_KEKLaugh

lusty portal
#

Eyy:)

#

Some really great players in that lobby

stiff egret
#

@lusty portal lobbies filled within 5 seconds :0_KEKLaugh:
@latent shell 5? I bet that was 2.

#

Some really great players in that lobby
Yeah, gonna be fun. We got some plans to, hopefully keep it as fair as we can.

latent shell
#

Those who have joined the KOTH lobby please do message me! :)

late stratus
#

anybody streaming this KOTH?

latent shell
#

yeah but its happening in our server :)

#

i mean just the scoreboard though

#

i have attached the spectator link :)

#

we will have a reset every 15 mins so in case something gets patched you can have a chance again

serene bay
#

Well the match is pretty tough by the looks of thing only 1 flag till now 9802_load_windows10

chilly shore
#

Room is full sad ._.

latent shell
#

another match of our first week happens tomorrow at the same time. You can try joining :)

late stratus
#

is it first come first served?

latent shell
#

yep

late stratus
#

it would be cool for this to be streamed...

serene bay
#

it's been streamed

#

you can check out Secarmy Discord servre @late stratus

latent shell
#

just the leaderboard tho :)

nova tide
#

I wasnt even root yet and there was 2nd reset. The ip is not even up and ppl are voting for 3rd reset???

#

I am out ๐Ÿ™‚

wary jolt
#

Lol

nova tide
#

No point in playing a game like this

#

Koth is dying

gusty cradle
#

I haven't played KoTH in months

nova tide
#

well imma stop playing as well.
Till KOTH teams update comes up

mint cargo
#

uu naughty is saying this, that means serious

latent crest
fair adder
#

someone probably changed it

latent crest
#

oo is there any other way to get into the mechine ?

full grove
#

yes

quiet schooner
#

3-4 initial access, 3-4 privescs. Or more.

grand ember
#

on production there weren't that many afaik

#

the routes overlapped

fair adder
#

szyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy

serene bay
scarlet pike
#

is there any way to get past excessive shell killing

#

if they do nothing but watch ps aux and kill shells within seconds

#

is there anything u can do

#

cuz that seems like a very braindead but scarily effective defense

stiff egret
#

@scarlet pike well, make a one liner urandom missile, and send it as soon as you get in the box. They will kick you but in a few secs that missile will hit. And next time you connect, they won't be in the box.

scarlet pike
#

ohh

#

what if they have it on a loop

stiff egret
#

@scarlet pike Also, you can try to make a loop with sshpass , to send missiles in loop.

scarlet pike
#

as a background job

stiff egret
#

Well, this is how you can kill background loops. ( Be it kill loops or king writing loops )

killall bash
killall sh
#

@scarlet pike

scarlet pike
#

ohhh

#

ye i use those to kill king loops

#

so u would go in and killall bash

#

then go in again and missle them

#

and then u can get in

stiff egret
#

Yes, so In the one-liner when you add urandom missile, add these too.

scarlet pike
#

ohhh

stiff egret
#

@scarlet pike yeah.

scarlet pike
#

makes sense, thanks

stiff egret
#

โœŒ๏ธ

scarlet pike
#

i find it hard to believe there isnt a foolproof defense

#

that doesnt require firewalls or DoS

#

or closing ports

stiff egret
#

@scarlet pike There are, some evil tricks.

scarlet pike
#

like what ๐Ÿ‘€

stiff egret
#

Like once you are sure that you have a backdoor setup, then you can just silently add a ; or any random character to /etc/sudoers.
That will almost destroy all Priv Esc from sudo.

scarlet pike
#

ye

#

but is there a way to like

#

stop all incoming shells

#

completely

#

that isnt beatable

stiff egret
#

That's just superman defences, and no point playing a game in that if there is no fight.

scarlet pike
#

ohh

#

supermans are banned right

stiff egret
#

Like the fun in KoTH is the fight part.

#

supermans are banned right
@scarlet pike yep, most of them.

scarlet pike
#

cuz i thought they just said no closing ports or services

#

and no firewall

#

so couldnt u make a superman defence that didnt include those things

#

and it would be legal

stiff egret
#

There's this another dirty/smart method to stop writing in King.txt

scarlet pike
#

other than chattr?

stiff egret
#

chattr +a king.txt

scarlet pike
#

oh

#

but isnt chattr well known by now

stiff egret
#

So even if people make it mutable

scarlet pike
#

its even in the

stiff egret
#

They can edit it.

scarlet pike
#

ohh

stiff egret
#

Yeah, everyone tries to do this,
chattr -i king.txt

#

But since the file is append only

scarlet pike
#

but they can lsatte

#

lsattr

#

and find the a

#

oof

stiff egret
#

They can not WRITE in the file, but APPEND.

#

Blow lsattr.

scarlet pike
#

oh

#

epic

stiff egret
#

ikr

scarlet pike
#

i mean they could bring an lsattr and chattr binary

#

but thats just tedious

#

lel

stiff egret
#

Or things like this
mv /bin/echo /bin/.myname && cp /bin/true /bin/echo

scarlet pike
#

ye ye

#

ivee heard about binary moving

#

is there a complete set of static linux binaries i can get somewhere

stiff egret
#

That will also make while loops useless. Since most of them just try to echo things.

scarlet pike
#

to upload if its gone

#

cuz i know theres a static chattr binary

stiff egret
#

Yeah.

latent shell
#

2 hours to go for the second match of week 1 for the SECARMY KoTH July Event. I will be sharing the link here at 10:00 PM IST or 5:30 PM BST

nova tide
#

@latent shell will it be posted here first or in your server?

latent shell
#

We'll be posting it on both the servers at the same time and if not there would be a 1-2 second difference

scarlet pike
#

koth anyone?

#

public game

nova tide
#

aah its going to take 18 minutes.. i will have to prep for the compeitition so imma leave

scarlet pike
#

oh rip

#

oh yeah the competition

#

shit i wanna try tday but i feel im gna die

#

do they do the usual boxes

#

or are there special boxes or smth

#

or is it just a normal game

nova tide
#

well the difficult part is to get in more than getting king ๐Ÿ˜„

latent shell
#

Hello everyone,
Here are the links for our second match of this SECARMY KOTH July Event,Please DM me once you've successfully joined the lobby!
Invite Link: https://tryhackme.com/games/koth/join/02c6ea99c3ef27254ac57090
Spectator Link: https://tryhackme.com/games/koth/6403

#

those who joined today please ping / DM me

livid dagger
#

how the f*ck in less than 10 minutes you get access and root to the machine hackers? The most difficult one there is

quiet schooner
#

You can do it in under a minute easily

short tusk
#

Funny joke kekw

livid dagger
#

well, more than 1 minute

short tusk
#

Practice makes perfect

livid dagger
#

because you have to run the nmap scan and then, you can see where the way to get in is

#

then, the time to bruteforce the credentials

short tusk
#

Use efficient nmap Scans

#

Whilst the nmap scan isn runni ng see what you can find

livid dagger
#

umm,,, I do

short tusk
#

If thereโ€™s a website run a gobuster Scan, guess some directories

quiet schooner
#

well, more than 1 minute
@livid dagger I can do it in a minute

late stratus
#

I was playing this KOTH and you def need prior knowledge to root the macine in minutes...

quiet schooner
#

Yes

#

But you can do it in under a minute

livid dagger
#

I can to if you know already what you are looking for

late stratus
#

a true competition would be a new VM no one has seen before...

#

yea exactly but only if you know what you are looking for .... I know 2 ways into the machine... and 1 way to privesc

livid dagger
#

no, the thing would be that the requirement is to generate new credentials (passwords not usernames) for everytime a machine resets

late stratus
#

ok so its a game for whoever can type the fastest! lol

quiet schooner
#

no, the thing would be that the requirement is to generate new credentials (passwords not usernames) for everytime a machine resets
@livid dagger This is implemented on some boxes

#

Fortune was the first, closely followed by hackers

sturdy plank
#

because you have to run the nmap scan and then, you can see where the way to get in is
@livid dagger
this guys dont scan because they knew all vuln before

sonic belfry
#

Do a blind KotH, meaning players don't know which machine is the target.

livid dagger
#

that would be even better

#

not putting what name of the game would probably make it more difficult

#

for if anyone has saved data like ssh logins, id_rsa or whatever

quiet schooner
#

Except you can find that information more or less instantly on nmap

#

That's why it was added

stiff egret
#

I don't think KoTH is for beginners.
Goal is to root a box in a race within 1 hour.
You need some prior knowledge for that.

#

That was for those who are saying you need to know the machine beforehand.

#

Do a blind KotH, meaning players don't know which machine is the target.
@sonic belfry that's definitely worth a upvote.

nova tide
#

in koth not all the ways are closed 90% of the time... even in todays competition there was one way to get root available for whole 1hour that no one patched.

#

Also it was a fun KoTH match after sooo long... Thanks to the Event Organizers โค๏ธ

livid dagger
#

why is this happening?

#

root@gibson:~# cat king.txt
root@gibson:~# echo Th3J0k3r >> king.txt
root@gibson:~# cat king.txt
root@gibson:~#

gusty cradle
#

Looks like someone is overwriting your file

livid dagger
#

but no one is in that's the thing

#

now I go to the thm koth site game and see this

#

and in the terminal, I see this still

#

root@gibson:~# ls -l
total 6420
-rw-r----- 1 root root 0 Jul 5 18:33 king.txt
-rwxr-xr-x 1 root root 6566663 Apr 30 00:59 koth
root@gibson:~# cat king.txt
root@gibson:~#

#

WTF?!

quiet schooner
#

lsattr king,txt

livid dagger
#

root@gibson:~# lsattr king.txt
--------------e--- king.txt
root@gibson:

#

not familiar with that command thouhg

quiet schooner
#

Someone's just overwriting it then

#

File attributes, google_it

#

There's a nice wikipedia page on it

livid dagger
#

looking at it now

#

I figured out a way to do it

#

ok, I thought I did but nope

#

oh well, gotta read the wiki

#

BTW, the file I was trying to append my name to, I found out it was the wrong file where you were supposed to put your name

#

maybe

quiet schooner
#

/root/king.txt

livid dagger
#

so I wanted to ask, can the king.txt file be in a /home/<blah blah>/king.txt ?

#

because in the challenge above, that was the case

#

I believe

quiet schooner
#

No

#

It is always (on linux boxes) /root/king.txt

livid dagger
#

so then that was a rabbit hole then I guess

#

well, not literally but in a way it was because it would make you think that

#

IDK, I just happen to see a king.txt file in a users home directory

#

and when I appened my name to it, it stayed

stiff egret
#

so then that was a rabbit hole then I guess
@livid dagger Someone trolled you.

nova tide
#

@livid dagger its better to use
echo Th3J0k3r > king.txt
instead of echo Th3J0k3r >> king.txt
As there are other players as well who will be writing their names in and if you append your name it will be like:
cat king.txt
Naughty Th3J0k3r
So none of you will be getting any points

livid dagger
#

yeah, I did that @nova tide

#

but there is another box that if you do >> instead of > it will put your name since > wouldn't work

#

maybe because of permissions but I'm not familiar witht that

nova tide
#

@livid dagger most likely because someone must have done chattr +a king.txt if you were to lsattr king.txt you can see whats going on.
Try reading more about chattr binary

#

so if you want to add your name using > so you need to use chattr -a king.txt and then echo 'Naughty' > king.txt

chilly shore
#

in koth not all the ways are closed 90% of the time... even in todays competition there was one way to get root available for whole 1hour that no one patched.
@nova tide whatโ€™s way to get root?

nova tide
#

get rev shell >> privesc ??

chilly shore
#

โ€œprivescโ€ โ‰ˆ suid ?

quiet schooner
#

Suid is one of many many many ways you might be able to privesc

deep jolt
#

Any1 up for a game?

wet pendant
#

i'm game! joined!

primal field
#

ok

deep jolt
rotund topaz
#

so lonely :((

short tusk
#

Aw damn Iโ€™d join but I donโ€™t like KOTH

rotund topaz
#

well

#

I'm not very good at it

#

so you could just breeze through if you want

short tusk
#

Hmmmm

#

Iโ€™ll think about it

rotund topaz
#

you have

#

16 minutes to think about it

#

we can vc if you want

#

uh oh

#

I spoke to soon

#

of all the people to join

short tusk
#

HA

rotund topaz
#

do you know who he is

short tusk
#

I believe you can beat them

rotund topaz
#

he looks slightly intimidating

short tusk
#

No I do not but I know who the NSA are so..

rotund topaz
#

Spam vs. US Gov.

#

should be a pushover

#

oh no

#

it's a windows machine

#

OH NO

#

ABORT ABORT

short tusk
#

Perform an nmap scan

#

Check for websites

#

use enum4linux

#

idk

rotund topaz
#

no website

#

trying to exploit the smb now

#

just no practice on windows

#

not gonna end well

serene bay
#

it alway's like this waifu

warm trellis
#

Iirc the only windows koth box is offline?

#

Still yet to give it a go, lemme know how you cope with it

stiff egret
#

Iirc the only windows koth box is offline?
@warm trellis it's literally as the name goes, offline
I get the concept and it's nice, but windows in general is too slow. Plus there is always someone trying eternal blue on windows. So that ruins the fun.

warm trellis
#

Yeah, i saw optional give it a go and it didn't look too fun lmao

rotund topaz
#

Plus there is always someone trying eternal blue on windows. So that ruins the fun.
@stiff egret blobcatsweatsip

#

purely hypothetically

#

what's wrong with running eternal blue on windows..

winged charm
#

if you run the wrong one you blue screen the box and it wonโ€™t go back up unless you reset it from thm kekw

rotund topaz
#

ah

#

I can see the attraction of it

teal field
slate crow
#

someone wanna join ?

rotund topaz
#

oh

#

joined by accident

#

nice

#

@slate crow I see we're against that NSA guy...

slate crow
#

lmfao

#

hahahahaha

#

indian version of Snowden

rotund topaz
#

did you patch the image upload thing

#

I swear

#

@slate crow daddy help

slate crow
#

no, lol

rotund topaz
#

:((

#

well

#

I'm beating NSA as of now at least

slate crow
#

feel sorry for Snowden

rotund topaz
#

eee

#

who keeps resetting

#

kinda annoying bro

#

@slate crow gg

slate crow
#

gg bois

rotund topaz
#

@teal field gg

slate crow
#

nicely done

rotund topaz
#

mve was gaining

warm trellis
#

omg

rotund topaz
#

wanna vc

warm trellis
#

i didn't even mean to join that guy

#

whoops

rotund topaz
#

yeah neither

#

but

#

once I was in

#

had to kinda play at least

warm trellis
#

i joined with 20 seconds left ๐Ÿ˜”

rotund topaz
#

I beat mr snowden at least

warm trellis
#

didn't even get to boot my laptop up lmao

rotund topaz
#

rip sadglas

slate crow
#

lmfao

rotund topaz
#

I think Dalist kept booting me off

slate crow
#

no it wasn't me, lol

rotund topaz
#

I was on duku all the time

#

oh rip

slate crow
#

I was tryna find the last flag ๐Ÿ™‚

rotund topaz
#

nice, I got 3 in the end

#

how did you get footholds on the other two accounts

#

could only see the file upload

slate crow
#

once you get root, you get everything

#

๐Ÿ˜„

rotund topaz
#

wait so from duku to root I guess

#

nice

slate crow
#

yeah

warm trellis
#

there's the default privesc iirc

rotund topaz
#

what was the duku privesc

#

nothing in sudoers

#

so I died

#

not getting linpeas in there

slate crow
#

wait, how do you get verified here ๐Ÿ˜„

rotund topaz
#

you have to tell me how to privesc

#

then you get it automatically

#

the bot messaged you what you needed to do at the start btw

warm trellis
#

errr

#

i can't remember off the top of my head, was it a binary priv esc?

rotund topaz
#

hmm can't remember

#

I wanna know the footholds for the other web ones

#

I was poking around in /var/www/html and saw something about isset($SESSION)

#

so didn't know if that was included

warm trellis
#

lemme check my notes

#

isn't carnage the box which has root running on a tmux session?

#

yeah, @rotund topaz i'm 99% sure the priv esc for carnage is through a tmux exploit

rotund topaz
#

Alright, thanks mate

#

I'll look into it

#

I really need to start making better notes

rotund topaz
#

@alpine yoke stop wiping the board ๐Ÿ˜‚

alpine yoke
#

@rotund topaz Oh, man. I just got the pass with hydra and then block all the ports and change the flags ๐Ÿ˜…

nova tide
#

@rotund topaz Oh, man. I just got the pass with hydra and then block all the ports and change the flags ๐Ÿ˜…
@alpine yoke everything you mentioned is against the rules.

stiff egret
#

๐Ÿ˜†

alpine yoke
#

@nova tide really? i was just trying to defend the machine. i'm begginer on THM. sorry for this, so

nova tide
#

Read rules of KoTH

alpine yoke
#

yeah, thx

rotund topaz
#

that would explain why I was struggling to break in ๐Ÿ˜‚

livid dagger
#

LOL

quiet schooner
#

Anyone remember the file path for the Offline KoTH king file?

full grove
#

C:\Administrators\some folder\

quiet schooner
#

Desktop?

fading nymph
#

@quiet schooner some custom directory on c:/users/administrator/

quiet schooner
#

Welp that's not going in the documentation then

fading nymph
#

we need more windows boxes for koth here, that file path would be the standard then

quiet schooner
#

You can set a standard with the existing box.

fading nymph
#

it's mostly the pioneer imo, it's a good filepath thou ๐Ÿ˜„

stiff egret
#

we need more windows boxes for koth here, that file path would be the standard then
@fading nymph please no.

quiet schooner
#

Sounds like someone wants more windows content too

stiff egret
#

๐Ÿ˜‚ Seriously, I am not good in windows, but in my opinion, KoTH is really, um, hard/(?) in windows.
I don't know if this is just me.
But if you connect to a user with RDP, no one else can connect then.

slate crow
#

where's the meterpreter gang at ?

oak jacinth
#

Here

#

the offline room isn't that bad

stiff egret
#

Key of the sentence being that.

slate crow
full grove
#

thats why SSH, WinRM and others are open ๐Ÿ‘€

fair adder
#

Welp that's not going in the documentation then
@quiet schooner c:/users/administrator/king-server/king.txt

#

pretty sure

short tusk
#

James is sleeping

late stratus
#

anyone up for a hack?

sturdy plank
#

someone edit the flags

#

when i copy paste flag it dont work for me

late stratus
nova tide
#

when i copy paste flag it dont work for me
@sturdy plank flags could also be encrypted

late stratus
quiet schooner
#

@late stratus There is a report email on the page

#

Please use that, rather than complaining here.

late stratus
#

it was more of a warning for anyone else joining a game with this user...

quiet schooner
#

Report them.

hazy zodiac
#

i think KOTH already have a rule about that tho

#

Show the number of times the box has been reset in a game of KoTH and add to the rules that it should only be reset if a rule has actually been broken

quiet schooner
#

...Yes, that's what I was saying

#

But reboot != reset

#

Constant reboots is 100% a DoS

hazy zodiac
#

maybe maybe

quiet schooner
#

I mean, it is.

hazy zodiac
#

add a automatic reset when the machine is broken

quiet schooner
#

How would you detect the machine being broken?

hazy zodiac
#

and dont let players reset the machine

quiet schooner
#

How would you detect the machine being broken?
@quiet schooner

hazy zodiac
#

or

quiet schooner
#

Resets are not the problem here.

#

Restarts and resets are different things entirely.

hazy zodiac
#

oh

sturdy plank
#

@sturdy plank flags could also be encrypted
@nova tide
no-one encode that because i can see {thm} in flag. the flag didnt encode by any-one

sturdy plank
#

guys please delete reset machine

#

someone use reset when i be king

#

please

quiet schooner
#

Resets exist because people can break things

#

They're not likely to be removed

sturdy plank
#

so please add a rule that dont reset the machine when paths are patch

#

we are two people in koth

quiet schooner
#

A rule against abusing resets has already been asked for

sturdy plank
#

ok

#

so please report a player n my game

quiet schooner
#

Have you read the rules?

sturdy plank
#

i read it about 3 weeks ago

quiet schooner
#

Then you know that reports aren't done through discord.

#

Read the rules again.

sturdy plank
#

i didnt see any thing about reset machine at 3 week ago

#

ok

stiff egret
#

Maybe a check script to keep checking if the flags are correct and in place, and if they are not then the script initiates reset?
@quiet schooner

sturdy plank
grand ember
#

to do so the koth binary would need to have all the flags locations or to get the locations from somewhere which isn't ideal because the players are supposed to find them
another way would be to use an autopwn script from the thm side but still, that would lead to many false-positives just because the box was patched

if there are different ways you think it could check for that i'm all for it but it shouldn't make finding the flags easy nor result in any false-positives

sturdy plank
#

so i think its better to use a input box in koth page that u input ur koth ID then will select options and will send report to mod of websites @grand ember

grand ember
#

something like this would make reporting a lot easier but i'm sure it'd also produce a lot of false requests

sturdy plank
#

but the creator can check what happend i think??

grand ember
#

with koth it's not the creator that checks

sturdy plank
#

because we use vpn and vpn can say what we do

grand ember
#

yeah, admins can check the info they have on the game

sturdy plank
grand ember
#

i guess you can post it there

sturdy plank
#

ok

#

thx for ur help

#

another question i have from u, can i dm u??

grand ember
#

sure

sturdy plank
#

@runic compass are u afk??

fair adder
#

gg @sullen hound lol

fair adder
#

@sullen hound constantly resetting the instance to block me from getting points... shame on you :b

nova tide
#

He got unbanned from discord? ๐Ÿ‘€

grand ember
#

I think so?

slate crow
#

ryan are ya here ?

#

@cobalt flower let's reset the machine ๐Ÿ™‚

#

?

#

warned ya ๐Ÿ™‚

gilded prism
#

@slate crow i was still on until i closed my own session xD

#

having to use diff shell because of ur "whatchu doing mate" spam xD

#

@slate crow check root

slate crow
#

what root ?

#

@gilded prism let's get 4th flag dude

#

๐Ÿ˜„

#

@gilded prism reset

gilded prism
#

done with that one. i'll reset for you tho

slate crow
#

thanks bud

#

wanna do another one ?

autumn iron
nova tide
#

who is this Strange270 with @last ether in koth rn?

#

btw you are practising for competition? ๐Ÿ˜„

last ether
#

Were am I in that game bro?

nova tide
#

ooh wait

#

my bad

#

wrong ping

last ether
#

๐Ÿคฃ

nova tide
#

@weary marten

#

was supposed to ping him

#

i am bad with names

last ether
#

๐Ÿคฃ

nova tide
weary marten
#

lol

#

idk who he is

nova tide
#

aah ok

#

i just saw the Pakistani flag so just wanted to know. as he's ranked #3 on THM scoreboard in Pakistan

gusty cradle
#

๐Ÿค”

nova tide
#

after ma1ware and me though

gusty cradle
#

At least he's winning ๐Ÿ™‚

nova tide
#

well he's trying.. GL to him

gusty cradle
#

You're in the match as well? ๐Ÿค”

nova tide
#

nah

#

i was doing a couple of easy boxes

weary marten
#

he is good though

nova tide
#

if i were @weary marten wouldn't be root for this long ๐Ÿ˜„

weary marten
#

ohh shit

#

PANIC

nova tide
#

nah JK. ik you are good xD

weary marten
#

na man me noob

nova tide
#

but you beat me

#

once

#

but that aint gonna happen again ๐Ÿ˜› (i hope)

weary marten
#

ohh no, wheres my rootkit

quiet schooner
nova tide
weary marten
#

where is the stinking flags in panda xD

nova tide
#

how many total flags were in panda?

#

i think i only have 7 of those

weary marten
#

8

#

i have 6

nova tide
#

oh Strange also have 7 flags.. Can i claim that's my alt acount?

weary marten
#

๐Ÿ‘€

#

na thats not you...for sure

nova tide
weary marten
#

everyone afraid of you xD

nova tide
#

public game

fair adder
#

New KOTH Box any time soon!?

autumn iron
#

6mins left

#

@weary marten offline

#

windows aha! ๐Ÿ˜ข

weary marten
#

i left

#

lol

autumn iron
#

me too

weary marten
#

create a new game

autumn iron
weary marten
#

24min ๐Ÿ˜ถ

autumn iron
#

did you ever solve offline

weary marten
#

one time

autumn iron
#

how was it??

weary marten
#

i would say medium

#

i hate windows btw

autumn iron
#

i hate it too

#

only 2??

weary marten
#

๐Ÿคทโ€โ™‚๏ธ

autumn iron
#

lets wait for some time

nova tide
#

ppl only koth when i am sleeping ? ๐Ÿ˜ฆ

nova tide
elfin charm
#

congratz @nova tide

#

๐Ÿ˜„

nova tide
sturdy plank
#

dont know about it

#

but its look like someone sending message from syslogd

#

maybe its for ur CPU

#

any one want to play koth??

latent shell
#

Will share the link at 5:30 PM BST exactly

autumn iron
fair adder
autumn iron
#

lol same

#

๐Ÿ˜†

rancid pewter
#

Ohhh a competition I might need to finish some game for it

latent shell
#

Hey peeps join us today for the second weeks qualifers at 5:30 PM BST / 10:00 PM IST for the SECARMY KoTH JULY event.
@latent shell will drop the link in 7 mins

#

Hello everyone,
Here are the links for our first match of the second week of SECARMY KOTH July Event,Please DM me once you've successfully joined the lobby!
Invite Link: https://tryhackme.com/games/koth/join/5360d41a58847841e97a9dde
Spectator Link: https://tryhackme.com/games/koth/6744

serene bay
#

2 Slots still left for the Event

latent shell
#

@brazen cloud hey i need some help , can i DM?

brazen cloud
#

Hey (: go for it

#

Uh lemme open DM's real quick

latent shell
#

sure thanks!

brazen cloud
#

Should be good to go ๐Ÿ‘

nova tide
#

Ppl saw myDonut joining and now the lobby isn't even full even after 30 minutes in game ๐Ÿ˜‚

blissful flower
#

can you suggest easy rooms other then panda?

#

koth room

quiet schooner
#

Food

nova tide
#

Production,Shrek

split stump
#

starts in 5

nova tide
#

@rancid pewter you playing?

rancid pewter
#

Eating my Oreo

nova tide
#

ohk

#

i was trying for no reason then xD

mint cargo
#

lol

nova tide
#

if you plan to play let me know we can reset.. as i have already patched everything

#

If deleting counts as patching

rancid pewter
#

Ok I am ready

#

@nova tide GG pretty sure you have patched all the box now

nova tide
#

its the only box that i know how to properly play

#

have already lost in this one against you and westar before once

rancid pewter
#

You deleted the /usr/bin I think

nova tide
#

no

rancid pewter
#

You deleted systemctl, wget, curl ?

nova tide
#

no

#

You deleted systemctl, wget, curl ?
@rancid pewter they are still on the box

#

in /usr/bin

rancid pewter
#

You modified the PATH or something ?

nova tide
#

i did something that i want to do in finals

#

mostly to stop some rootkits.. i didnt delete any of those binaries though that i can confirm

rancid pewter
#

Can we reset plz ?

nova tide
#

sure

#

even after reset its not kicking me out of the box

rancid pewter
#

Maybe I should start to kill people shell

grand ember
#

lol

nova tide
#

well its not against the rules... sooo?

#

after patch i have to kick you out smh if its by urandom or kill

#

before you could set some persistence

rancid pewter
#

Ok can you reset again ?

#

I got my rootkit on that time

nova tide
#

noice

rancid pewter
#

But I dont know if it going to work since it a Centos box

grand ember
#

if the kernel version is right then it should be fine

#

unless you're running ubuntu specific commands

nova tide
#

its working

rancid pewter
#

I know but I have made change on my Ubuntu box but forgot to change it on my Centos box so I only need to recompile it

#

You can do cat king.txt you will see my name but I wont be king

nova tide
#

You can do cat king.txt you will see my name but I wont be king
@rancid pewter but why??? ๐Ÿ‘€

#

yeah you are in king file though

rancid pewter
#

I just need to change an '=' to '<' in my rootkit

#

Donโ€™t worry I am making some persistence that you wonโ€™t be able to kill

#

But really well played

nova tide
#

Thanks. Looking forward to play against you in the competition. If i didn't had my finals during the competition i may have made one myself

elfin charm
fair adder
nova tide
gentle wedge
#

starts in 5 min

nova tide
#

umm you pasted it twice

gentle wedge
nova tide
#

@gentle wedge which box

gentle wedge
#

dont know which box

nova tide
#

oh random

#

ok

gentle wedge
#

i didnt subscribe

#

ya

barren stream
#

If there was a leaderboard for KoTH @nova tide would be #1 all I ever see you do is hang out in this channel and play KoTH

nova tide
#

If there was a leaderboard for KoTH @nova tide would be #1 all I ever see you do is hang out in this channel and play KoTH
@barren stream only thing left is to start making rootkits now. That i will start working on after finals