#koth
1 messages ยท Page 34 of 1
Good luck doing that with no internet
oh
You need to understand the vulns
A lot of the KoTH boxes have custom code
Normally you can remove the vulns from that
Or replace the service with something functionally equivalent but not vulnerable
Eg there's a webserver with RCE? Replace it with a python webserver that serves the pages just the same
if u replace it
Languages like PHP are interpreted
Not compiled
Some boxes have the sourcecode for the services on there.
ohhh
if we apply a patch that doesnt work
like the
service wont start
we just undo it and thats fine right
Then you're in trouble ๐
ye
@errant yarrow are u in the KOTH???
starting in 5 minutes
public game
oeps
you are late
sorry was an accident
Hey! Anyone down to play koth in public? Nobody is playing rn :c
@worthy isle i would love to but rn busy with friends
Np ๐
@sturdy plankyes
anyone wanna play koth public?
i wanna try it out for the first time
:DDD
@worthy isle
Im doing a private game finally
ooh ok
But u can join
Itโs on another discord server tho, I can send you the link in dm if u donโt mind
@scarlet pike wanna join?
sure
Cool

@fair adder OP pls nerf

who is that b14ckdz ?? in koth
gg
how many ways in to shrek?
how many ways in to shrek?
@fair adder atleast 4 that i know of
When are we getting a new room?
its been like 10min and the machine is still on
@fair adder after reset machine stays up for an hour
O.o
When are we getting a new room?
@tardy gull Cryclic working on a new windows machine for koth i think
Oh boy. Windows is fun.
Whats with everyone going THM's Official? @nova tide xD
I am one more Offical user away from changing my nickname too ๐
Disclaimer: Not official.
xD
Pretty cool way to look official tho lol
Any mod I can DM about something? (Probably important(?)) (Its about site)
Iโve never done a KOTH but always have wanted to. Any tips?
There's a tips section on the KoTH page. ๐
Probably a spoiler TIP for KoTH @fair adder ||TIP: Always rename/remove chattr binary.||
your goal is to write your username on king.txt xD
Initially, yes, but once someone is IN the box, the goal is to maintain your username in king.txt. As long as its in there, you are winning.
Your goal is to root it and prevent others from rooting, correct?
@fair adder
xD
start in 17 min
@stiff egret Yeah, someone on one of the machines left some executables and I took advantage to download them
chattr was one but can't remember the others
๐
Unless snaps are removed, ubuntu machines will have a chattr in a snap
@quiet schooner I thought that was coincidental!
I think it's the core snap that's used in the installer
intended?
Snapd is annoying, I've started removing it
@quiet schooner true that tho
You can just copy an ubuntu chattr binary over though, about as easily
I mean, it's not unintended?
@quiet schooner I mean, I thought creater would remove those purposely
I mean, some do, some don't
Snapd takes up like 80mb or something so I purge it
As well as LXD to avoid that privesc
start in 9 min
urghhh playing KOTH against @livid dagger is so depressing.... 15 mins in and the machine is completely patched....
sorry, Fortune is pretty easy
I only patched one entrance though
there are 2-3 other ways that I know of
I think I might request a staggered start feature.... the more points you have the later you start... I need at least a 10 min head start on you! :p
do you think that would be fun! ๐
maybe hehe
make me have a stress attack
you have a chance
I have not done this one LION
Initially, yes, but once someone is IN the box, the goal is to maintain your username in king.txt. As long as its in there, you are winning.
@fair adder
@๐๐ป.๐๐ธ๐ต๐ถ๐ฎ๐ผ#0980 thanks for the answer. Is king.txt allowed to be moved around?
@stiff egret
Sorry it didnโt ping you
@fair adder No, if you move it you will break the king service and no one will get king points
Okay, thatโs why itโs worth asking. So I canโt affect the txt file at all besides editing it
So I can edit the attributes
Immutable
Thatโs what I was hinting on lol
I mean, there's not a rule against it and it won't break anything
It's included as a "people often do this" on the website
Okay, so itโs basically outsmarting people while on a time constraint
Boot them out the box, patch the box, sit back and relax
I have an idea but it will be a huge spoiler if I send it here, mind if I DM?
is it against the rules to run a command that writes on the opposite users terminal?
I think that would count as hacking other players
Which is against the rules
It seems only thing you can do is mess with the machine itself
It doesn't count as attacking other players
because their terminal sessions exist on the KoTH box
ok
wow the king.txt is locked down well in this current game... hmmmmm
Probably a spoiler tip ||lsattr /root/king.txt ||
couldnt get "that" executable to work...
tried uploading but wouldnt run... couldnt download... zzzzzz
so, who is using an autoexploiter for root?
gloria@lion:/tmp$ ls ls bash: /bin/ls: No such file or directory gloria@lion:/tmp$ ./cve ./cve [.] [.] t(-_-t) exploit for counterfeit grsec kernels such as KSPP and linux-hardened t(-_-t) [.] [.] ** This vulnerability cannot be exploited at all on authentic grsecurity kernel ** [.] [*] creating bpf map [*] sneaking evil bpf past the verifier [*] creating socketpair() [*] attaching bpf backdoor to socket [*] skbuff => ffff88003cbfcb00 [*] Leaking sock struct from ffff88003b675c00 [*] Sock->sk_rcvtimeo at offset 472 [*] Cred structure at ffff88003a1d6480 [*] UID from cred structure: 1002, matches the current: 1002 [*] hammering cred structure at ffff88003a1d6480 [*] credentials patched, launching shell... [!] exec No such file or directory gloria@lion:/tmp$ ls ls bash: /bin/ls: No such file or directory gloria@lion:/tmp$
isn't that kind of against the rules?
oh.... is it?? its a vulnerability???
not saying it's wrong I didn't know it was a vuln but if it gives you root privs, I thought it might be like against the rules because it works like an autoscript
oh....
also, earlier who shutdown the port 1337?
It's not against the rules though
haha I though that was you!!! your normal trick ๐
hahaah... the last game you closed 22!!
Writing a script specific to the box that will hack the box when you should be doing it manually is against the rules
no I didn't
Moving services is allowed but poor defence
@late stratus there you go! Mod just answered my question
that one is on exploit-db
Grabbing someone's exploit for a CVE is just fine
That'd be a nightmare otherwise
so then this ^^ vuln would it be considered auto-"hack" or not. I'm just curious to know because in that case, I would have used it also
Im confused too
ok. Well, I have the cve downloaded for next time ๐
haha you dont need anyhelp!!! (ps you owe me one ๐
I'm such a novice... just trying to learn as fast as I can
well, you learned that one fast!
also, FYI, I had not done that one ๐ it was fun though
sooo.... how was the king.txt locked down?? it was empty half the game and I couldnt chattr it..
not sure
I saw you had a script that looped your name into it but when I did it, nothing happened
king was empty after my .sh ran
there was a koth binary running but strings gave me nothing
yeah, don't ever delete it
There's a KoTH service running on 9999
The code for the KoTH service running on most of the boxes is open source
oh is it called koth?
It's a systemd service called koth
Yeah and the binary should be called koth
You're not allowed to mess with that service
oh crap.... sorry!! i might have screwed it... I was furiously trying to get king... apologies....
the king.txt file was still blank...
looool now I know why I couldn't add my name haha
well, actuall that service and the .txt don't have much in common only that the service reads the content from the file
basically I guess?
the file was still locked down somehow
you might have locked it somehow?
did someone screw with the "echo" binary??
so that it doesnt echo to king? that would be a sweet mod
echo to everything else so looks normal
or whoever this is (https://tryhackme.com/p/b14ckdz) is the one that was messing with the machine
because also, I notiched that lot's of things broke when I was in it
I have to go. Be back later
yep lots of normal services were borked
boutta try my first king of the hill against one other person ๐ช https://www.tryhackme.com/games/koth/6201
in 3 mins if anyone's trying to get an easy W
Is it ok to turn off ftp anonymous login?
I'm not able to yet, but stuff like that sounds within the realm of patching
no idea
But you're the official tomato! If you don't know, who will?
If you're on hackers, there's a much much much better patch
I'm sure there's a million better things than what i htink of
I don't even know if this other person is playing...
still fun tho
hmm, i'm so conflicted on what's over the line, even if i'm not really playing against someone...
youโre pretty much good to patch any and everything except for the king service on port 9999 as long as you donโt make the service unavailable. A general rule that Iโve heard referred to is as long as the box stays that a regular user with good intentions can use it as intended than it is fine and is within the rules. @livid palm
mind if i ask a specific example?
Website with an RCE command injection vuln
Good patch? Replace the webserver with a python http.server
lol
Still usable, but no vuln
does it serve the same content?
anyway, this is a service that executes stuff as root but with a char limit
shorten the limit? Turn it off? What's the potential "good intention" that a user would need that for. I'm 100% overthinking for this round, like i said
decrease char limit to one char? Change it to a useless user?
I mean I think you can justify disabling that
and I'm sure this comes up all the time
thanks for the input ppl
woohoo first W :king:
16mins left
Naughty please go easy on us
Why people left?
yeah sure you can DM me ๐
9min left
wanna play anyone?
my first koth btw
how long does it have left?
prob over now
@livid dagger in your website link to your THM account is 404 page
spectate link?
@stiff egret ^^
btw nice name xD
ikr! ๐
spectate link?
@stiff egret i think the game is over though
this is one that is running atm
https://tryhackme.com/games/koth/6226
awesome
here is another game starting in7 minutes:
https://tryhackme.com/games/koth/join/e00ce2d7014d6dc23ecdc51e
bummer got some issues to resolve, will join you guys later
LOL
F
Will update it on github lol
i want to see it in action
@nova tide I'll screenshare lol, I aint gonna show that in public stream ๐
Hey, currently playing KOTH on game 6226, just saying, if the other players are seeing this, closing SSH is illegal XD
Hey, currently playing KOTH on game 6226, just saying, if the other players are seeing this, closing SSH is illegal XD
@worthy isle LOL
It isnt.
Huh?
closing port is. but not if you replace it with some other port
You can patch any service, and that includes closing it, IF its un-patchable (is that a word?)
Yeah but they haven't replaced
They have killed the port
But the box has reset now so it's ok
@nova tide Probably because of a name change I did. Not everything has been updated yet
I just checked it and it works fine
Oh, I see what you meant. The link at the bottom. Not the link in the widget
fixed
now its working xD
well it was a fun game with you.. my electricity went off and just came back
the one mistake you did was you were writing your name after my name in king.txt
so none of us will get points
you have to replace mine and enter yours
well i was trying something new out.. if i was using the old method you wouldn't be able to append either
chattr is the binary that makes the file non-writeable/editable
i like your trick, added to my arsenal ๐
so chattr is built in binary inside the box?
dangit im sweating, glad it ends xD
๐
How can we report or where can we report if something illegal in koth happened?
Check the rules on the page
do koth private games have a player limit?
10 is the player limit for koth
thanks!
Thanks!
How many games of KOTH do you have to win to get badge
I got a badge after one win
I won one and I didn't get badge
is there only 3 ways to user and 2 to root in lion?
don't know
anyone want to play koth??
In a min
in 5 minutes
Starting in 12 minutes
@oak jacinth Everyone just left us :(
I ended up not bothering, got caught up with some school work lol
LOL
Me too
Anyone on Shrek just now?
i am hosting a game starts in 22
need some people
game starting in 3m!
start in 10 min
I'll be posting the invite link at around 5:30 PM BST :) , if you have any questions please don't hesitate to DM
Awesome:)

is having a bash loop to kill shells legal for koth
also @latent shell how many people per team
@scarlet pike Qualifying match (i.e. today), will be of solo players type.
oh
is having a bash loop to kill shells legal for koth
@scarlet pike Dirty trick, but yeah, legal. (As far as I know.)
No, all matches from week 2 onwards, are team based.
Oh yes, sorry, my bad. Guess I am missing a coffee.
I'll just make sure. Gimme a minute.
Yes. Matches in Week 2 are also solo. @scarlet pike
oh ok
Guys the KoTH July Starts in 1:10 hour mins Be Prepared ๐ All The Best
2mins to go :3
Hello everyone,
Here are the links for our first match of this SECARMY KOTH July Event,Please DM me once you've successfully joined the lobby!
Invite Link: https://tryhackme.com/games/koth/join/0b8ad459070e24195f3435a0
Spectator Link: https://tryhackme.com/games/koth/6351
@lusty portal lobbies filled within 5 seconds 
@lusty portal lobbies filled within 5 seconds :0_KEKLaugh:
@latent shell 5? I bet that was 2.
Some really great players in that lobby
Yeah, gonna be fun. We got some plans to, hopefully keep it as fair as we can.
Those who have joined the KOTH lobby please do message me! :)
anybody streaming this KOTH?
yeah but its happening in our server :)
i mean just the scoreboard though
i have attached the spectator link :)
we will have a reset every 15 mins so in case something gets patched you can have a chance again
Well the match is pretty tough by the looks of thing only 1 flag till now 
Room is full sad ._.
another match of our first week happens tomorrow at the same time. You can try joining :)
is it first come first served?
yep
it would be cool for this to be streamed...
just the leaderboard tho :)
I wasnt even root yet and there was 2nd reset. The ip is not even up and ppl are voting for 3rd reset???
I am out ๐
Lol
I haven't played KoTH in months
well imma stop playing as well.
Till KOTH teams update comes up
uu naughty is saying this, that means serious
any hint on Production ? It'll be very helpfull
someone probably changed it
oo is there any other way to get into the mechine ?
yes
3-4 initial access, 3-4 privescs. Or more.
szyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy

is there any way to get past excessive shell killing
if they do nothing but watch ps aux and kill shells within seconds
is there anything u can do
cuz that seems like a very braindead but scarily effective defense
@scarlet pike well, make a one liner urandom missile, and send it as soon as you get in the box. They will kick you but in a few secs that missile will hit. And next time you connect, they won't be in the box.
@scarlet pike Also, you can try to make a loop with sshpass , to send missiles in loop.
as a background job
Well, this is how you can kill background loops. ( Be it kill loops or king writing loops )
killall bash
killall sh
@scarlet pike
ohhh
ye i use those to kill king loops
so u would go in and killall bash
then go in again and missle them
and then u can get in
Yes, so In the one-liner when you add urandom missile, add these too.
ohhh
@scarlet pike yeah.
makes sense, thanks
โ๏ธ
i find it hard to believe there isnt a foolproof defense
that doesnt require firewalls or DoS
or closing ports
@scarlet pike There are, some evil tricks.
like what ๐
Like once you are sure that you have a backdoor setup, then you can just silently add a ; or any random character to /etc/sudoers.
That will almost destroy all Priv Esc from sudo.
ye
but is there a way to like
stop all incoming shells
completely
that isnt beatable
That's just superman defences, and no point playing a game in that if there is no fight.
Like the fun in KoTH is the fight part.
supermans are banned right
@scarlet pike yep, most of them.
cuz i thought they just said no closing ports or services
and no firewall
so couldnt u make a superman defence that didnt include those things
and it would be legal
There's this another dirty/smart method to stop writing in King.txt
other than chattr?
chattr +a king.txt
So even if people make it mutable
its even in the
They can edit it.
ohh
Yeah, everyone tries to do this,
chattr -i king.txt
But since the file is append only
ikr
Or things like this
mv /bin/echo /bin/.myname && cp /bin/true /bin/echo
ye ye
ivee heard about binary moving
is there a complete set of static linux binaries i can get somewhere
That will also make while loops useless. Since most of them just try to echo things.
Yeah.
2 hours to go for the second match of week 1 for the SECARMY KoTH July Event. I will be sharing the link here at 10:00 PM IST or 5:30 PM BST
@latent shell will it be posted here first or in your server?
We'll be posting it on both the servers at the same time and if not there would be a 1-2 second difference
koth anyone?
public game
aah its going to take 18 minutes.. i will have to prep for the compeitition so imma leave
oh rip
oh yeah the competition
shit i wanna try tday but i feel im gna die
do they do the usual boxes
or are there special boxes or smth
or is it just a normal game
well the difficult part is to get in more than getting king ๐
Hello everyone,
Here are the links for our second match of this SECARMY KOTH July Event,Please DM me once you've successfully joined the lobby!
Invite Link: https://tryhackme.com/games/koth/join/02c6ea99c3ef27254ac57090
Spectator Link: https://tryhackme.com/games/koth/6403
those who joined today please ping / DM me
how the f*ck in less than 10 minutes you get access and root to the machine hackers? The most difficult one there is
You can do it in under a minute easily
Funny joke 
well, more than 1 minute
Practice makes perfect
because you have to run the nmap scan and then, you can see where the way to get in is
then, the time to bruteforce the credentials
umm,,, I do
If thereโs a website run a gobuster Scan, guess some directories
well, more than 1 minute
@livid dagger I can do it in a minute
I was playing this KOTH and you def need prior knowledge to root the macine in minutes...
I can to if you know already what you are looking for
a true competition would be a new VM no one has seen before...
yea exactly but only if you know what you are looking for .... I know 2 ways into the machine... and 1 way to privesc
no, the thing would be that the requirement is to generate new credentials (passwords not usernames) for everytime a machine resets
ok so its a game for whoever can type the fastest! lol
no, the thing would be that the requirement is to generate new credentials (passwords not usernames) for everytime a machine resets
@livid dagger This is implemented on some boxes
Fortune was the first, closely followed by hackers
because you have to run the nmap scan and then, you can see where the way to get in is
@livid dagger
this guys dont scan because they knew all vuln before
Do a blind KotH, meaning players don't know which machine is the target.
that would be even better
not putting what name of the game would probably make it more difficult
for if anyone has saved data like ssh logins, id_rsa or whatever
Except you can find that information more or less instantly on nmap
That's why it was added
I don't think KoTH is for beginners.
Goal is to root a box in a race within 1 hour.
You need some prior knowledge for that.
That was for those who are saying you need to know the machine beforehand.
Do a blind KotH, meaning players don't know which machine is the target.
@sonic belfry that's definitely worth a upvote.
in koth not all the ways are closed 90% of the time... even in todays competition there was one way to get root available for whole 1hour that no one patched.
Also it was a fun KoTH match after sooo long... Thanks to the Event Organizers โค๏ธ
why is this happening?
root@gibson:~# cat king.txt
root@gibson:~# echo Th3J0k3r >> king.txt
root@gibson:~# cat king.txt
root@gibson:~#
Looks like someone is overwriting your file
but no one is in that's the thing
now I go to the thm koth site game and see this
and in the terminal, I see this still
root@gibson:~# ls -l
total 6420
-rw-r----- 1 root root 0 Jul 5 18:33 king.txt
-rwxr-xr-x 1 root root 6566663 Apr 30 00:59 koth
root@gibson:~# cat king.txt
root@gibson:~#
WTF?!
lsattr king,txt
root@gibson:~# lsattr king.txt
--------------e--- king.txt
root@gibson:
not familiar with that command thouhg
Someone's just overwriting it then
File attributes, 
There's a nice wikipedia page on it
looking at it now
I figured out a way to do it
ok, I thought I did but nope
oh well, gotta read the wiki
BTW, the file I was trying to append my name to, I found out it was the wrong file where you were supposed to put your name
maybe
/root/king.txt
so I wanted to ask, can the king.txt file be in a /home/<blah blah>/king.txt ?
because in the challenge above, that was the case
I believe
so then that was a rabbit hole then I guess
well, not literally but in a way it was because it would make you think that
IDK, I just happen to see a king.txt file in a users home directory
and when I appened my name to it, it stayed
so then that was a rabbit hole then I guess
@livid dagger Someone trolled you.
@livid dagger its better to use
echo Th3J0k3r > king.txt
instead of echo Th3J0k3r >> king.txt
As there are other players as well who will be writing their names in and if you append your name it will be like:
cat king.txt
Naughty Th3J0k3r
So none of you will be getting any points
yeah, I did that @nova tide
but there is another box that if you do >> instead of > it will put your name since > wouldn't work
maybe because of permissions but I'm not familiar witht that
@livid dagger most likely because someone must have done chattr +a king.txt if you were to lsattr king.txt you can see whats going on.
Try reading more about chattr binary
so if you want to add your name using > so you need to use chattr -a king.txt and then echo 'Naughty' > king.txt
in koth not all the ways are closed 90% of the time... even in todays competition there was one way to get root available for whole 1hour that no one patched.
@nova tide whatโs way to get root?
get rev shell >> privesc ??
โprivescโ โ suid ?
Suid is one of many many many ways you might be able to privesc
Any1 up for a game?
i'm game! joined!
ok
https://tryhackme.com/games/koth/join/53d8c3e75d4bfed81ddf1e43
@deep jolt 6 mins to go guys
Aw damn Iโd join but I donโt like KOTH
you have
16 minutes to think about it
we can vc if you want
uh oh
I spoke to soon
of all the people to join
HA
do you know who he is
I believe you can beat them
he looks slightly intimidating
No I do not but I know who the NSA are so..
Spam vs. US Gov.
should be a pushover
oh no
it's a windows machine
OH NO
ABORT ABORT
no website
trying to exploit the smb now
just no practice on windows
not gonna end well
it alway's like this 
Iirc the only windows koth box is offline?
Still yet to give it a go, lemme know how you cope with it
Iirc the only windows koth box is offline?
@warm trellis it's literally as the name goes, offline
I get the concept and it's nice, but windows in general is too slow. Plus there is always someone trying eternal blue on windows. So that ruins the fun.
Yeah, i saw optional give it a go and it didn't look too fun lmao
Plus there is always someone trying eternal blue on windows. So that ruins the fun.
@stiff egret
purely hypothetically
what's wrong with running eternal blue on windows..
if you run the wrong one you blue screen the box and it wonโt go back up unless you reset it from thm 
someone wanna join ?
no, lol
feel sorry for Snowden
gg bois
@teal field gg
nicely done
mve was gaining
omg
wanna vc
i joined with 20 seconds left ๐
I beat mr snowden at least
didn't even get to boot my laptop up lmao
rip 
lmfao
I think Dalist kept booting me off
no it wasn't me, lol
I was tryna find the last flag ๐
nice, I got 3 in the end
how did you get footholds on the other two accounts
could only see the file upload
yeah
there's the default privesc iirc
what was the duku privesc
nothing in sudoers
so I died
not getting linpeas in there
wait, how do you get verified here ๐
you have to tell me how to privesc
then you get it automatically
the bot messaged you what you needed to do at the start btw
hmm can't remember
I wanna know the footholds for the other web ones
I was poking around in /var/www/html and saw something about isset($SESSION)
so didn't know if that was included
lemme check my notes
isn't carnage the box which has root running on a tmux session?
yeah, @rotund topaz i'm 99% sure the priv esc for carnage is through a tmux exploit
Alright, thanks mate
I'll look into it
I really need to start making better notes
@alpine yoke stop wiping the board ๐
@rotund topaz Oh, man. I just got the pass with hydra and then block all the ports and change the flags ๐
@rotund topaz Oh, man. I just got the pass with hydra and then block all the ports and change the flags ๐
@alpine yoke everything you mentioned is against the rules.
๐
@nova tide really? i was just trying to defend the machine. i'm begginer on THM. sorry for this, so
yeah, thx
that would explain why I was struggling to break in ๐
LOL
Anyone remember the file path for the Offline KoTH king file?
C:\Administrators\some folder\
Desktop?
@quiet schooner some custom directory on c:/users/administrator/
Welp that's not going in the documentation then
we need more windows boxes for koth here, that file path would be the standard then
You can set a standard with the existing box.
it's mostly the pioneer imo, it's a good filepath thou ๐
we need more windows boxes for koth here, that file path would be the standard then
@fading nymph please no.
Sounds like someone wants more windows content too
๐ Seriously, I am not good in windows, but in my opinion, KoTH is really, um, hard/(?) in windows.
I don't know if this is just me.
But if you connect to a user with RDP, no one else can connect then.
where's the meterpreter gang at ?
Key of the sentence being that.
thats why SSH, WinRM and others are open ๐
Welp that's not going in the documentation then
@quiet schooner c:/users/administrator/king-server/king.txt
pretty sure
James is sleeping
anyone up for a hack?
when i copy paste flag it dont work for me
@sturdy plank flags could also be encrypted
zzzzz... https://tryhackme.com/p/AsafDamn .. just reboots the machine every 2 mins after he goes ahead in points.... boring...
@late stratus There is a report email on the page
Please use that, rather than complaining here.
it was more of a warning for anyone else joining a game with this user...
Report them.
i think KOTH already have a rule about that tho
Show the number of times the box has been reset in a game of KoTH and add to the rules that it should only be reset if a rule has actually been broken
...Yes, that's what I was saying
But reboot != reset
Constant reboots is 100% a DoS
maybe maybe
I mean, it is.
add a automatic reset when the machine is broken
How would you detect the machine being broken?
and dont let players reset the machine
How would you detect the machine being broken?
@quiet schooner
or
Resets are not the problem here.
Restarts and resets are different things entirely.
oh
@sturdy plank flags could also be encrypted
@nova tide
no-one encode that because i can see {thm} in flag. the flag didnt encode by any-one
so please add a rule that dont reset the machine when paths are patch
we are two people in koth
A rule against abusing resets has already been asked for
ok
so please report a player n my game
Have you read the rules?
i read it about 3 weeks ago
Maybe a check script to keep checking if the flags are correct and in place, and if they are not then the script initiates reset?
@quiet schooner
yes but write it in #544951750801752079 @stiff egret
to do so the koth binary would need to have all the flags locations or to get the locations from somewhere which isn't ideal because the players are supposed to find them
another way would be to use an autopwn script from the thm side but still, that would lead to many false-positives just because the box was patched
if there are different ways you think it could check for that i'm all for it but it shouldn't make finding the flags easy nor result in any false-positives
so i think its better to use a input box in koth page that u input ur koth ID then will select options and will send report to mod of websites @grand ember
something like this would make reporting a lot easier but i'm sure it'd also produce a lot of false requests
but the creator can check what happend i think??
with koth it's not the creator that checks
because we use vpn and vpn can say what we do
yeah, admins can check the info they have on the game
so do i must to write it in #544951750801752079 ???
i guess you can post it there
sure
@runic compass are u afk??
gg @sullen hound lol
@sullen hound constantly resetting the instance to block me from getting points... shame on you :b
He got unbanned from discord? ๐
I think so?
@slate crow i was still on until i closed my own session xD
having to use diff shell because of ur "whatchu doing mate" spam xD
@slate crow check root
done with that one. i'll reset for you tho
who is this Strange270 with @last ether in koth rn?
btw you are practising for competition? ๐
Were am I in that game bro?
๐คฃ
๐คฃ
aah ok
i just saw the Pakistani flag so just wanted to know. as he's ranked #3 on THM scoreboard in Pakistan
๐ค
after ma1ware and me though
At least he's winning ๐
well he's trying.. GL to him
You're in the match as well? ๐ค
he is good though
if i were @weary marten wouldn't be root for this long ๐
nah JK. ik you are good xD
na man me noob
ohh no, wheres my rootkit
starting in 9 minutes.. public game
https://tryhackme.com/games/koth/join/ce7889325f655be1f1477964
where is the stinking flags in panda xD
oh Strange also have 7 flags.. Can i claim that's my alt acount?
everyone afraid of you xD
12 minutes to go:
https://tryhackme.com/games/koth/join/19beca3ece631ca285f42b38
public game
12 minutes to go:
https://tryhackme.com/games/koth/join/19beca3ece631ca285f42b38
starting in 5 minutes
New KOTH Box any time soon!?
6mins left
@weary marten offline
windows aha! ๐ข
me too
create a new game
24min ๐ถ
did you ever solve offline
one time
how was it??
๐คทโโ๏ธ
lets wait for some time
ppl only koth when i am sleeping ? ๐ฆ
public game starts in 24 minutes:
https://tryhackme.com/games/koth/join/c27aa569928a5b56fa32377c
i went out for a few minutes.. whats that?
dont know about it
but its look like someone sending message from syslogd
maybe its for ur CPU
any one want to play koth??
Hey peeps join us today for the second weeks qualifers at 5:30 PM BST / 10:00 PM IST for the SECARMY KoTH JULY event.
Will share the link at 5:30 PM BST exactly
Ohhh a competition I might need to finish some game for it
Hey peeps join us today for the second weeks qualifers at 5:30 PM BST / 10:00 PM IST for the SECARMY KoTH JULY event.
@latent shell will drop the link in 7 mins
Hello everyone,
Here are the links for our first match of the second week of SECARMY KOTH July Event,Please DM me once you've successfully joined the lobby!
Invite Link: https://tryhackme.com/games/koth/join/5360d41a58847841e97a9dde
Spectator Link: https://tryhackme.com/games/koth/6744
2 Slots still left for the Event
@brazen cloud hey i need some help , can i DM?
sure thanks!
Should be good to go ๐
Ppl saw myDonut joining and now the lobby isn't even full even after 30 minutes in game ๐
Food
Production,Shrek
starts in 5
@rancid pewter you playing?
Eating my Oreo
lol
if you plan to play let me know we can reset.. as i have already patched everything
If deleting counts as patching
its the only box that i know how to properly play
have already lost in this one against you and westar before once
You deleted the /usr/bin I think
no
You deleted systemctl, wget, curl ?
no
You deleted systemctl, wget, curl ?
@rancid pewter they are still on the box
in /usr/bin
You modified the PATH or something ?
i did something that i want to do in finals
mostly to stop some rootkits.. i didnt delete any of those binaries though that i can confirm
Can we reset plz ?
Maybe I should start to kill people shell
lol
well its not against the rules... sooo?
after patch i have to kick you out smh if its by urandom or kill
before you could set some persistence
noice
But I dont know if it going to work since it a Centos box
if the kernel version is right then it should be fine
unless you're running ubuntu specific commands
its working
I know but I have made change on my Ubuntu box but forgot to change it on my Centos box so I only need to recompile it
You can do cat king.txt you will see my name but I wont be king
You can do cat king.txt you will see my name but I wont be king
@rancid pewter but why??? ๐
yeah you are in king file though
I just need to change an '=' to '<' in my rootkit
Donโt worry I am making some persistence that you wonโt be able to kill
But really well played
Thanks. Looking forward to play against you in the competition. If i didn't had my finals during the competition i may have made one myself
starts in 5 min
umm you pasted it twice

@gentle wedge which box
dont know which box
If there was a leaderboard for KoTH @nova tide would be #1 all I ever see you do is hang out in this channel and play KoTH
If there was a leaderboard for KoTH @nova tide would be #1 all I ever see you do is hang out in this channel and play KoTH
@barren stream only thing left is to start making rootkits now. That i will start working on after finals

