#koth

1 messages · Page 39 of 1

dreamy wasp
#

I don't know if the other guys were in the Discord before, the ping might have fallen on deaf ears

#

I'm here in here now though 😛

vagrant gull
#

How'd all you lot get in? All the same way? @dreamy wasp @sudden condor

nova tide
#

if anyone starts another game.. just ping me or send me invite link

tepid hornet
#

sure

nova tide
stiff egret
#

No one joining in 😕

patent forge
fair adder
sturdy plank
#

koth??

nova tide
#

koth??
@sturdy plank in an hour or so

patent forge
sturdy plank
#

@sturdy plank in an hour or so
@nova tide about 15 min to start koth

#

if u want join me click on mentats link

#

we are in same koth match

#

@nova tide but dont forget a thing im noob xD

nova tide
#

just dont do:
rm -rf /usr/bin/* KEKWLUL

sturdy plank
#

sure

stiff egret
#

sh: "rm" command not found

sturdy plank
#

how about bash @stiff egret

#

or rbash kekw

stiff egret
#

rm $(which rm)

nova tide
#

hello @fair adder

fair adder
#

Ah hi

#

Wassup

#

I saw you in dc's Livestream

nova tide
#

yo

fair adder
#

How you doin

#

Aye wait I've played against you once in koth

nova tide
#

i'm doing fine, wbu?

#

Aye wait I've played against you once in koth
@fair adder ayee really??

fair adder
#

Yeah

#

I remember you

#

You're from India from India right?

gusty cradle
#

🤔

fair adder
#

Hello dark lord

nova tide
#

You're from India from India right?
@fair adder Pakistan

fair adder
#

Ohh

#

Ok

#

I probably forgot

nova tide
#

I remember you
kekw

nova tide
#

random game starting in 3 minutes

late stratus
nova tide
#

@late stratus that's a spectator link

late stratus
fair adder
#

@patent forge not you again

patent forge
#

at least i'm famous ❤️

#

I'm proud of myself

fair adder
#

indeed you are ahahaha

#

i alredy see my self losing

#

smh

nova tide
#

And i am about to sleep 🥱

fair adder
#

that means i have a little bit of chance to win

#

smh

#

nwm i don't

#

i never did fortune

#

like not even intial access

nova tide
#

Well now is your chance then

fair adder
#

@mellow bough its not something that i can discuss openly in chat rooms can i message you in private?

mellow bough
#

We're currently doing a press release so now is really not the time

fair adder
#

Understood. Sorry for pinging you and good luck with press release.

patent forge
#

@fair adder didn't patched anything

fair adder
#

@patent forge bruh my internet died for a little bit sry

#

can you give me invite again ?

patent forge
stiff egret
#

M joining

patent forge
#

nothing patched 🙂

quiet schooner
#

@fair adder If you need a moderator, I'm around. What's up?

fair adder
#

@quiet schooner can i message you on private?

quiet schooner
#

If you could give me a loose idea what it's about, that'd be great

#

If not, I guess

fair adder
#

No problem, at my college i started teaching hacking for beginners course, so i wanted to use one of KotH machines, i don't want to post more here because its sensitive matter and i don't want to spam chat.

quiet schooner
#

hackers and food are both available as standalone rooms, so I'd push you towards those two

#

The other KoTH boxes are not, so probably not easy to use those

fair adder
#

I see, general idea was to one KotH machine, make private game and have team red infiltrate machine vs blue team patch it. So standalone rooms can't help me here.

#

@patent forge okay here i come

#

Thank you for answer and have a pleasant day/night! 😁

quiet schooner
#

I see, general idea was to one KotH machine, make private game and have team red infiltrate machine vs blue team patch it. So standalone rooms can't help me here.
@fair adder You can all access the one machine if you deploy it. The king service on port 9999 is a web server that prints the contents of the king file, so you can automate polling that quite easily for attack vs defense

fair adder
#

@quiet schooner I see thank you very much for this helpful information.

quiet schooner
#

You're welcome, I hope teaching with this goes well for you!

fair adder
#

i liturally don't know what to do

#

i give up

stiff egret
#

lmao

patent forge
#

@fair adder gobuster

#

rpcbind

stiff egret
#

nmap

fair adder
#

i did

#

and i got the b64 thing

#

i decode it

#

its not wokring

stiff egret
#

b64 of a file elf.

patent forge
#

@stiff egret you broke king 😦

stiff egret
#

🤨

#

You sure?

patent forge
#

i think that your "history" were spamming empty lines into king

#

i had to setup a loop to write anything

#

but it wasn't writing "holmes", that's the point

stiff egret
#

Lemme check

patent forge
#

you had to kill that script, isn't it?

quiet ore
patent forge
#

doing that again btw

#

there is something spamming " " inside king

stiff egret
#

What did you do?

patent forge
#

for what? 😉

#

no really, for what? haha

stiff egret
#

lmao its over

#

I still have a shell

patent forge
#

yep, the reverse one?

#

MY PSPY 😠

stiff egret
#

maybe

#

/bin/psss

#

lmao

patent forge
#

nonononononono

stiff egret
#

yee I remember

#

Tho, you should've used rm and not mv

#

if you know you know

patent forge
#

i don't like removing stuff

#

expecially if i can spam with stderr ❤️

stiff egret
#

either way, you renamed it and left it in same place

#

no point 🤷‍♂️

patent forge
#

no point?

#

does making an "auto-chattr" actually have one?

stiff egret
#

huh?

patent forge
#

your "immutable" script or something

#

under the boot/nano/.../ folder

stiff egret
#

Ah, that is not for what you are thinking.

patent forge
#

really?

stiff egret
#

Yee.

#

You shouldve copied it to your local

hardy jungle
#

That's called a red herring

patent forge
#

so what was that about? 🥕

stiff egret
#

Had some fun stuff in some of them.

patent forge
#

yes i should

stiff egret
#

That's called a red herring
@hardy jungle wdym

hardy jungle
#

@stiff egret I was guessing you do what I do but you don't

#

I leave red herrings around

stiff egret
#

Nope, pretty sure not.

hardy jungle
#

Fair enough

stiff egret
#

Nice terminal btw.

#

@hardy jungle

#

Anyone playing one more?

hardy jungle
#

@stiff egret why thank you!

molten oyster
languid ermine
#

hey, i've never played a KOTH before but ive been really wanting to, any advice on starting out or something of the sort?

unique crescent
#

Anyone want to play KOTH?

stiff egret
#

hey, i've never played a KOTH before but ive been really wanting to, any advice on starting out or something of the sort?
@languid ermine imo try playing on the koth machines that have been converted to normal boxes, like "food" or "hackers "
That'll give you an idea about how good you are and how much you need to improve. :)

stiff egret
#

KoTH anyone?

#

random, public, in 23 minutes,

patent forge
nova tide
#

Starting in how much time? Lemme turn on my pc

latent quest
#

@nova tide I can when I got a better idea. Probably going to be around 1900 utc on Saturday. 🤔 Not 100% sure though. Depends on how studies go.

nova tide
#

Twitch username plzz

latent quest
#

You just want to see what I am doing. 🧐

nova tide
#

You just want to see what I am doing. 🧐
@latent quest maybe

latent quest
#

maybe Absolutely.

nova tide
#

Waiting for the stream

grand ember
#

i love the 57391 on the end kekw

nova tide
#

When your name is taken kekw

#

i love the 57391 on the end kekw
But you don't really have to worry 😂

#

🤔
I (sometimes) stream cybersecurity related content. I'm a fan of Wargames, CTFs, and Boot2Root style challenges so those will probably be around and maybe some other stuff.

latent quest
#

When your name is taken kekw
@nova tide It's a very sad day. 😆

nova tide
#

Btw isn't there a rule for no personal advertisementkekw

latent quest
#

You asked for it. blobfingerguns

nova tide
#

Noone gonna believe you kekw

latent quest
#

💀 Dirty, underhanded, tactics on the part of Naughty. The name is well deserved.

languid ermine
#

@languid ermine imo try playing on the koth machines that have been converted to normal boxes, like "food" or "hackers "
That'll give you an idea about how good you are and how much you need to improve. :)
@stiff egret thanks bro, ill do that now

nova tide
#

no one playing today?

patent forge
#

👀

grand ember
#

👀

nova tide
#

public game starting in 20 minutes ^^

patent forge
#

actually i have to fix my pc first 😦

#

it's not letting me win koths with @nova tide

#

i'm adding some rgbs to make it gaming faster

nova tide
#

🤔

patent forge
#

actually i really need to "fix" my pc

languid ermine
#

i'm adding some rgbs to make it gaming faster
@patent forge yeah bro take advantage of the extra 15 fps per rgb strip

patent forge
#

@nova tide can i believe that?

nova tide
#

what?

patent forge
#

are you playing?

nova tide
#

i was doing the new room that came last night after joining two KoTH games at a time 🤷‍♂️

#

just saw you got king so came back

patent forge
#

ggs, i'm out

nova tide
#

🤷‍♂️

late stratus
#

hi all... some advice please. Playing Koth we both have root and trying to write to king.txt.. we can set up scripts which spam the king file but whats the best way to find and kill the opponents script?

quiet schooner
#

ps

late stratus
#

Yea but that's every process.. how do i know which is writing to King.txt

weak matrix
#

maybe narrow down results.

quiet schooner
#

lsof

vagrant gull
#

What's the most efficient way to stop opponents from editing the file?

quiet schooner
#

Kick them off the box and patch it

vagrant gull
#

Welp

#

Ok

serene bay
#

Cut their fingers✂️

vagrant gull
#

Bruh

brazen cloud
#

It'd work shrugs

#

(only if you get every digit though)

patent forge
#

guys i have a problem

#

i have literally printed the string 2>/dev/null into my brain

#

maybe i should stop playing koth for 1 day or 2 🤣

dusty canyon
#

lol

#

yo mentats i remember u from the king of the hill games

patent forge
#

@dusty canyon yeah i played a lot of them lol

sturdy plank
#

@autumn solar reset machine when there was no-problem

#

is he against rule??

stiff egret
#

There are no solid rules around that yet, so he can reset the machine (I think )

nova tide
#

is he against rule??
@sturdy plank why not read the rules yourself?? 🤷‍♂️

sturdy plank
#

there is nothing write about that

#

but want to be sure @nova tide

patent forge
#

@low mango changed password?

low mango
#

no

#

We will, we will rock youblobfingerguns

patent forge
#

yeah i'm using it

#

i started at 50:00 lol

low mango
#

lol

low mango
patent forge
#

ggs

#

**don't touch my crons 😠 😠 😠 😠 😠

low mango
#

gg

sturdy plank
hallow torrent
#

.

quiet schooner
hallow torrent
#

opps

dusty canyon
#

Lol

fallen socket
#

Lol
@dusty canyon hey that was nice

dusty canyon
#

Yooooo

#

Wassup my guy

#

Ty u too

fallen socket
#

How did you made the king.txt file automaticly change to your name? 😄

#

crontab?

dusty canyon
#

Oh lmao nah dude im just here clickin away

#

I was literally just typing nano jondoe and saving that

#

Constantly

#

My fingers hurt

fallen socket
#

xDDD

dusty canyon
#

Lmaoaoaoaoaoaowoa

fallen socket
#

hahaha but it worked for you

dusty canyon
#

Lol yeyeye ty

fallen socket
#

you are new here?

dusty canyon
#

Yeye pretty new

#

I used to do hackthebox

#

Its hard af

fallen socket
#

yes, i tried that a few months ago

#

tryhackme is much more guided

dusty canyon
#

Lol yyeyee

#

I wonder what happens if all 3 players are in the king.txt

fallen socket
#

hmm good question

dusty canyon
#

Hehe

quiet schooner
#

I wonder what happens if all 3 players are in the king.txt
@dusty canyon None of them get points

dusty canyon
#

Oh dangit

quiet schooner
#

It has to be just the username, nothing else, exactly as it appears on THM

dusty canyon
#

Ahh ight ight

#

Ty

fallen socket
#

makes sende

#

sense*

dusty canyon
#

Lmaooaoaoa

fallen socket
#

i kicked you out of your ssh session, did that work?

#

don't think so xD

dusty canyon
#

Lmaooo nah man

#

Gg dude

fallen socket
#

xD

dusty canyon
#

Lmao that was a good game

#

These king of the hill games are fun

fallen socket
#

they are! hehe

dusty canyon
#

Hehehe loll

fallen socket
#

next time i beat you haha

dusty canyon
#

Lmaoaoaoaoa ight bet bet

fallen socket
#

😄

dusty canyon
#

:D))

fallen socket
#

i wonder if the other koth machines are more difficult

quiet schooner
#

There's a range of difficulties

fallen socket
#

The production machine is a easy one?

quiet schooner
#

One of the easier ones, yeah

fallen socket
#

Ahh okay

#

But it seems, that defending your place in the king.txt is much more difficult than actually hack the machine

quiet schooner
#

Best way is patch all the vulns and kick everyone out

fallen socket
#

Is there a specific workaround for kicking everyone out. I tried it by killing the process of the other SSH session and the "who"-command only showed my session. But @dusty canyon was still in it

dusty canyon
#

Lmao i have no idea

quiet schooner
#

ps aux | grep pts or something

dusty canyon
#

Ah nice nice

fallen socket
#

Nice ty

slate crow
#

Is there a specific workaround for kicking everyone out. I tried it by killing the process of the other SSH session and the "who"-command only showed my session. But @dusty canyon was still in it
@fallen socket pkill -KILL -u user1 user2 user3

#

@fallen socket pkill -KILL -u user1 user2 user3
@slate crow killall -9 sh

#

keep in mind that you need to upload the killall binary from your local machine

low mango
low mango
#

@dav02 nice game

dusty canyon
#

Ty @slate crow

raven vine
#

Is 8658 room members are there

nova tide
sturdy plank
#

koth??

#

start in 22min

low mango
stiff egret
#

How much time is it starting in?

low mango
#

17 min

#

17m 42s

stiff egret
#

Thanks for the precise time xD I might join, if I could overcome my lazyness of getting up and starting my laptop

low mango
#

Good luck with overcoming laziness, buddy.

sturdy plank
#

guys please reset

#

i f*cked machine

#

@low mango

low mango
#

ok

#

@sturdy plank Fastest via ssh login in the wild west😆

sturdy plank
#

😆

nova tide
#

How to patch a box? Patch everything
chmod 700 /usr/bin/* noice kekw

#

🤦‍♂️

grand ember
#

I mean, it's working

stiff egret
#

sshh Don't tell everyone

grand ember
#

Don't you SSH me rageW

stiff egret
#

I'll ssh-keygen you

nova tide
#

Added to my notes kekw 🤷‍♂️

stiff egret
#

!clear 5

#

Damnit

nova tide
#

Also to get on recent games give 1m king to someone else kekw

#

Damn i'm learning new things today

stiff egret
#

chmod 700 $(which chmod)

#

Endgame

nova tide
#

you mean rm

stiff egret
#

stop spilling everything NAUGHTY!!

nova tide
#

😄 😛

#

Secret giving away free 1m king to others to get on recent games kekww 🤦‍♂️

stiff egret
#

Lmao how is he king?

#

Edit: how you are not?

nova tide
#

He's pro

stiff egret
#

xD

sturdy plank
#

🥳

nova tide
#

Edit: how you are not?
@stiff egret i just woke up.. and joined a game.. got root, didn't set any persistence. he killed my shell and chmod everything KEKWLUL

stiff egret
#

😂😂😂

nova tide
sturdy plank
#

@stiff egret i just woke up.. and joined a game.. got root, didn't set any persistence. he killed my shell and chmod everything :KEKWLUL:
@nova tide as ur chance ur shell was in game about 30min

nova tide
#

rbash shell with no other binary than pwd and echo?? Damn why didn't i privesc 🤔

stiff egret
sturdy plank
nova tide
#

🤦‍♂️

sturdy plank
#

LOL

stiff egret
#

Make a private game of hackers 😂😂😂😂😂 kekw

nova tide
#

he wont get a chance to use chmod in that 🤷‍♂️

stiff egret
#

😂😂😂😂😂 IKR

nova tide
#

pretty sure not even initial access either

stiff egret
#

Lol I haven't even changed that payload yet, it sends one rev to your ip too Lmao

nova tide
#

🤣

stiff egret
#

Imagine we both in same game and one of us gets free rev root

sturdy plank
#

@nova tide i did wrong

#

i think we need reset

nova tide
#

🤷‍♂️

sturdy plank
#

i killed my self LOL

#

also i change permission before i kill my self

#

people are sleeping

#

???

#

why they dont vote for reset

#

while PrivEsc way closed by me

#

i think we need to play another match @nova tide

#

because people are sleeping

nova tide
#

i just got root 🤷‍♂️

sturdy plank
#

huh??

#

how??

#

there is no-way

nova tide
sturdy plank
#

lol

nova tide
#

so you just patched every way you know and kicked yourself out?

#

including most of the binaries as well

sturdy plank
#

the problem is i dont change permission of /bin/* files

#

i just did it for /usr/bin/*

nova tide
#

that's not how you patch stuff 🤷‍♂️

#

Blue team..

#

google it?

#

why not just patch the privescs?

sturdy plank
#

no the problem is i dont have time to change permission of /bin/* because i kill my self before do it

nova tide
#

why are you so afraid from people using cd ??

#

no the problem is i dont have time to change permission of /bin/* because i kill my self before do it
@sturdy plank i'm saying that's not how you patch the box 🤦‍♂️

sturdy plank
#

ok

nova tide
#

removing every possible binary for the users is not called patching

#

patch privescs

#

patch the ways they are getting in from

sturdy plank
#

i know what u say

#

||/etc/sudoers||

nova tide
#

that's not the only thing

#

i said the same thing in last game

#

but you still tried doing the same method again

sturdy plank
#

know that but changing /etc/sudoers and chmoding will close PrivEsc part

#

im sure

nova tide
#

if i have my backdoor in all i have to do is kill your shell then even you won't be able to get back in as you have removed everything for other users.. so what's the point of playing KoTH like that?

#

know that but changing /etc/sudoers and chmoding will close PrivEsc part
@sturdy plank chmoding everything is not patching dudeeee

sturdy plank
#

yes it is

nova tide
#

🤦‍♂️

sturdy plank
#

also i forgot to say killing shell

nova tide
#

aaah i can't explain it to you.

sturdy plank
#

LOL

nova tide
#

my Bad sorry

#

have fun using chmod on every possible binary on the machine and learning your blue team ways

#

peace

sturdy plank
#

not ur bad that my problem that i cant understand all things

#

have fun using chmod on every possible binary on the machine and learning your blue team ways
@nova tide LOL, OK

#

anyway i'm not good at blue team, i'm better in red team @nova tide

nova tide
#

then why not learn to do that?

sturdy plank
#

because i dont need it

#

we just use it for koth

#

i dont want to be in blue team for CTF

nova tide
#

we don't need blue team skills?

#

ok

#

sorry to waste your time...

#

plz spend your time playing koth by chmod every damn thing on the box

sturdy plank
#

we just need some of the skills of that team

nova tide
#

you just locked your self out doing that

sturdy plank
#

sorry to waste your time...
@nova tide sorry me, thx for ur help man

#

plz spend your time playing koth by chmod every damn thing on the box
@nova tide LOL

low mango
#

It looks like rce exploit to nostromo 1.9.6 doesn't work :/

tepid hornet
#

@nova tide It's like arguing with a rock kekw

nova tide
#

@nova tide It's like arguing with a rock kekw
@tepid hornet yeah totally felt that

tepid hornet
#

Kali Linux copy pasterino skidy rock

serene bay
sturdy plank
#

who mentioned me??

serene bay
#

@sturdy plank why leave the game ?

sturdy plank
#

my friend need help for running kali on vm

serene bay
#

dude

#

one game

#

against you chmoding everything please 🙏

final nest
#

🤣

gusty cradle
#

Just remove chmod from the box

stiff egret
#

sssh

sturdy plank
#

against you chmoding everything please 🙏
@serene bay LOL

final nest
#

alias chmod ='exit'

sturdy plank
#

Just remove chmod from the box
@gusty cradle i will do that again by downloading chmod LOL

serene bay
#

@sturdy plank 1 game senpai 🙏

stiff egret
#

LMAO

sturdy plank
#

ok i joined again

final nest
#

🤣

serene bay
#

Arigato Have Fun

final nest
#

Which box is it?

gusty cradle
#

@gusty cradle i will do that again by downloading chmod LOL
@sturdy plank Delete all ways to transfer files 🙂

stiff egret
#

sssssssssssssshhhhhhhhhhhhhhhhh

serene bay
#

just bork the box ffs

sturdy plank
#

alias chmod ='exit'
@final nest wont work

#

try on ur shell

final nest
#

Ok

sturdy plank
#

u will see that it wont work

serene bay
stiff egret
#

echo "export chmod='exit'" >> ~/.bashrc

low mango
#

alias chmod='exit' will work

stiff egret
#

I think that one works too

sturdy plank
#

echo "export chmod='exit'" >> ~/.bashrc
@stiff egret it may work

stiff egret
#

may?

sturdy plank
#

alias chmod='exit' will work
@low mango try it on ur shell

low mango
#

ok

sturdy plank
#

u will see what will happen

#

may?
@stiff egret i didnt try that

stiff egret
#

hmm.

sturdy plank
#

but any-way i will spawn shell then do that for see if u guys trap me or not LOL

stiff egret
#

🤨

low mango
#

@sturdy plank Yea, this is not working

stiff egret
sturdy plank
#

i'm sure i will lose because u guys will trap me LOL

low mango
#

echo "export chmod='exit'" >> ~/.bashrc
@stiff egret nice trap lol

low mango
#

this is working

sturdy plank
#

@stiff egret u really delete chmod and ps ??

stiff egret
#

maybe | maybe not

sturdy plank
#

lol

sturdy plank
#

nice game but i needed to go

#

any-way bye guys

stiff egret
#

cya

#

GG

sturdy plank
#

yay gg

#

next time i will download ps and chmod in my PC

#

LOL

stiff egret
#

lol

#

I dont delete.

#

mv holds way more power then rm

fair adder
#

yay gg
@sturdy plank stop

#

its not funny

#

thats against the rules, you cant just chmod everything on the box and call that blue team

sturdy plank
#

LOL

#

LMAO

#

@quiet schooner sorry for mention can i ask a question about koth??

#

mv holds way more power then rm
@stiff egret ok LOL

fair adder
#

a

patent forge
#

@sturdy plank you are a bit aggressive in koths actually lol

sturdy plank
#

LMAO

patent forge
#

dude

#

you set a script which closes all pts in one game 🤣

#

that's not patching

#

always remember that a system may need to keep alive while blue teaming

#

and services should work as they properly should.

#

ofc no one is rispetting this "rule", and that makes games so lazy sometimes

terse willow
#

Yeah, let's not be shutting services down please 🙂

patent forge
#

@terse willow i'm talking about "hidden-rules"

terse willow
#

Hidden rules?

patent forge
#

like of course you can patch an lfi removing the call, right? (for example)

terse willow
#

Removing bad code is fine, yes

patent forge
#

yes but what i'm trying to say is that in real blue teaming situation, you have to fix that code

#

not removing that

fresh jungle
#

gg condor777

patent forge
#

and i think that would be great if everyone played like that

terse willow
#

It would

#

In fairness, removing it temporarily whilst you fixed it would make sense

patent forge
#

oh of course

stiff egret
#

It's a fine balance of patching and leaving enough to let others enjoy too.

grand ember
#

or creating other ways in :)

stiff egret
#

Like if I patch, I make sure there is atleast one way to bypass that patch

patent forge
#

@grand ember that's the point

grand ember
#

so people need to put some effort to get back in

stiff egret
#

Yeah, as I said, Its not a fight if the ring is empty

patent forge
#

or just make the (example) LFI harder to exploit

grand ember
#

ye

patent forge
#

there are several ways to enjoy a koth

stiff egret
#

minor things like, blowing echo, but leaving printf

patent forge
#

ofc not talking about competitive stuff

stiff egret
#

So others have a chance

patent forge
#

move chattr but not after having used that 😡

stiff egret
#

lmao, use the new location in loop

patent forge
#

or just install yours

stiff egret
#

🤷‍♂️

#

blow wget

patent forge
#

🤷

#

aliases are fun

#

concatenating them is a pretty || dick || move

stiff egret
patent forge
#

yeah like

#

pkill = "/bin/pkill" you know

stiff egret
#

echo "export ls='revshell; /usr/bin/ls'" >> ~/.bashrc

#

one of my favs

patent forge
#

oh wel

#

does it actually spawns a rev every ls?

stiff egret
#

they kick you, and you wait for them to do ls

#

but selecting which rev shell to use is the tricky part

patent forge
#

yeah got it

stiff egret
#

not all of them work

patent forge
#

also faked system crons

#

doing cp of bash and stuff

patent forge
#

anyone up for a koth?

dusty canyon
#

Yo whats up @patent forge

#

Hey um is it illegal to move king.txt to koth

#

I accidentally did that

#

And i cant get it back

quiet schooner
#

Have you read the rules?

dusty canyon
#

Ummmmmmm

#

Yes i have

quiet schooner
#

Then you should know the answer to that.
Also, unless you start attacking other players then it's not illegal. It might be against the KOTH rules, but the police aren't going to beat down your door.

dusty canyon
#

Ah whew

#

Tyty

gusty cradle
#

🚓

dusty canyon
#

Nono

#

No need for that

gusty cradle
#

🚨

dusty canyon
#

Stop that

hardy jungle
#

No u

#

👮

dusty canyon
#

Incorrect

#

Listen im 18 let me in

serene bay
#

Nope Only Weebs Allowed

serene bay
#

wtf closed ssh

#

um where can I report ?

stiff egret
#

Police station

serene bay
#

closed ssh and port 3000 lmao on space jam

quiet schooner
#

@serene bay The rules let you know where to report it 🙂

stark fox
#

Nope Only Weebs Allowed
@serene bay
Did I hear weebs I am in

hardy jungle
#

@stark fox not tonight mate.

serene bay
#

@stark fox We gotta take over SuitGuy

#

#WaifusFor2020

stark fox
#

Ah cool

#

Take him

serene bay
#

who is this kiwi guy in KOTH rn with me ?

hardy jungle
#

Your both barred sorry. 0day be the only one worth voting for

serene bay
#

no way we weebs have equal rights too

quiet schooner
sturdy plank
#

If i chnage permission of binaries i will against rule???????????????

tepid hornet
#

@nova tide kekw

serene bay
#

you mean chmoding every fuckin binary ?

#

then i'll say you're not supposed to play KOTH like that

nova tide
#

you mean chmoding every fuckin binary ?
@serene bay rm -rf $(which chmod) and his patching methods are gone.. kekw

serene bay
#

@nova tide Even better rm everything in /usr/bin

nova tide
#

i mean that's the patching method some people like and idk why 🤷‍♂️

hazy zodiac
#

Listen im 18 let me in
@dusty canyon two more years and u are a bumer

fair adder
stiff egret
#

@serene bay rm -rf $(which chmod) and his patching methods are gone.. kekw
@nova tide all of the patching methods prolly

nova tide
#

@fair adder maybe?

fair adder
#

Yeah

nova tide
#

yeah i did

#

ashu and skidy

dense junco
#

Hi can anyone teach me / send me resources on how to play koth. Am a beginner and I want to learn. Thank u

#

Food or shrek

#

Got it

#

But am wondering how to prevent other from coming in.

#

Like I can get into the machine. But how to secure the machine?

#

That's y I want someone to show me

nova tide
#

KoTH machines are meant to be a challenge.. So i don't think any gonna teach you how to root any of these. what you can do is do the easier ones on your own. Start from Shrek or Food.
There are already official writeups for Food and Hackers in Hacktivitites by James

dense junco
#

K I'll see thx

nova tide
#

Like I can get into the machine. But how to secure the machine?
@dense junco Patch the ways you got in from, set your methods to get back in. Check /etc/sudoers file it have anything in that. change passwords, remove ssh keys. and look for other ways people are getting in from. Kick other guys out

dense junco
#

Ohhh

stiff egret
#

John Hammond on YouTube
Optional on twitch

dense junco
#

Yes I watch him

stiff egret
#

Their content is legit good.

dense junco
#

Yep

stiff egret
#

They have enough content on YT/TWITCH to get you started in KoTH.
But as naughty said, it's a competitive thing, you only learn when you play against real peeps

nova tide
#

uhmm to watch optional's previous videos i think you need to sub 🤔

stiff egret
#

Yee

#

Sadly yeah

dense junco
#

No no he posts on yt also

serene bay
#

@stiff egret ahem saar are you official detective?☺️

nova tide
#

he have a few videos free on Youtube. you can JohnHammond on youtube

#

Or can always find your ways on your own

stiff egret
#

There's a rumour that you only start learning when you see Nyancat on your terminal
Prolly true

dense junco
#

Hmm thxx

nova tide
#

Self Learning > watching others

serene bay
#

I heard there is a guy who has github explaining koth in really good way 😁

stiff egret
#

@stiff egret ahem saar are you official detective?☺️
@serene bay lmao

serene bay
#

ig it's called holmes-py

stiff egret
#

There is no explanation there

#

Only methods

#

Tbh, very poor GitHub 😂😂

serene bay
#

I hope I Get to meet that guy once

stiff egret
#

Lmaoo

nova tide
#

I can write KoTH writeup on THM blog.. imma ask skidy if he allows that

serene bay
#

You're going to take someone jobs @nova tide

stiff egret
#

Damn noice, tho do they allow that?

nova tide
#

imma ask

stiff egret
#

Yee

nova tide
#

You see that shiny role in my profile?

stiff egret
#

Damit

nova tide
serene bay
#

Flex

stiff egret
#

😂😂

#

Flex indeed

nova tide
dense junco
#

kekw
@nova tide ur discord Id is 9999 😂

#

So easy to remember

stiff egret
#

rich lad

serene bay
#

Money Money

nova tide
#

Win KoTH competitions 😛

stiff egret
#

I'll make a blog to make maggi

#

Hope they gime me that too

#

😂😂😂

nova tide
#

you can add your writeup for that if you ask bee

#

on his site

stiff egret
#

Um, my GitHub one?

nova tide
#

nah

#

bee have one site..

serene bay
#

Um Can we have a Waifu based koth box ?

nova tide
#

unOfficial THM Food writeups

stiff egret
#

😂😂😂😂😂😂

serene bay
#

I'd love to be the King

nova tide
#

but You are going to be the Queen

stiff egret
#

Oh no, better yet
How to make water.

nova tide
#

5 points for Queen 10 for king

serene bay
#

Nani ?

fair adder
#

For KoTH, are there any writeups out there?

#

This is my first time participating, so I feel a bit lost out there

#

this might seem like a stupid question

#

but are all these machines static? what I mean is feature-wise are there any changes between consecutive runs?

nova tide
#

only Fortune and Hackers are the ones with random passwords generated.
For others you can use your notes/passwords/sshkeys etc.

fair adder
#

So basically, I need to run multiple iterations on KoTH on every machine to get somewhere

nova tide
#

i mean you can play private games to practice..

#

i have seen people almost finding every possible way in for the machine in a couple of hours

fair adder
#

How long have you been pentesting?

#

I'm just curious

#

I hope me asking you this is not too unprofessional

#

I just completed my second room!

nova tide
#

How long have you been pentesting?
@fair adder Me?

fair adder
#

Yeah

low mango
#

Nice game

nova tide
#

pentesting??

#

i just play KoTH

#

and started doing THM rooms 3-4 months ago

#

nothing else

fair adder
#

Ahh ok

#

I just started in July

nova tide
#

noice

fair adder
#

Want to do this for my career

#

so all advice is welcome

nova tide
#

just go try hard on those boxes

#

rooms *

#

really worth the time

serene bay
#

really worth the time
@nova tide Can you iterate over it more ?

nova tide
#

Well i waste most of my time playing KoTH and doing nothing. so not the best guy to ask for advise kekw

serene bay
#

You can definitely 👋

serene bay
#

@nova tide go easy on me please in koth

nova tide
#

Easy? Whats dat? blobknife

#

you even changed your country to Japan lmao

serene bay
#

Power of True Weeb

#

now don't stalk me please

#

@nova tide imma leave now 😢

nova tide
#

no narrator password for you blobknife

serene bay
#

🍶

#

Yamete senpai

tepid hornet
#

He knows no one understands japenese

serene bay
#

Yare Yare

tepid hornet
#

😄

nova tide
#

i do 🤷‍♂️

tepid hornet
#

opening google translate

#

lie blobknife

nova tide
#

Yamete=stop it (not a reference from hentai)
Yare Yare is a reference from JoJo

serene bay
#

Sayanora Senpai

#

I'll go on other game then 😩

nova tide
#

lets reset?

#

imma go buy something to eat

#

for tonight

serene bay
#

Arigato @nova tide

stiff egret
#

Why thanks?

nova tide
#

i went out

#

btw i didn't voted reset

serene bay
#

Still Arigato ❤️

raven vine
#

@nova tide I am whoamiha3nain

nova tide
#

Ayeee ♥️

raven vine
#

♥️

vivid ridge
#

Hey what would be a good resource to learn how to play koth

quiet schooner
#

The standalone KoTH boxes, then some private games

vivid ridge
#

Ok thanks

nova tide
#

KoTH machines are meant to be a challenge.. So i don't think any gonna teach you how to root any of these. what you can do is do the easier ones on your own. Start from Shrek or Food.
There are already official writeups for Food and Hackers in Hacktivitites by James

quiet schooner
#

(And you can deploy them to play yourself with no friends and no subscription)

short tusk
#

Who needs friends anyway

gusty cradle
#

👀

tepid hornet
#

Not me

shell snow
#

How would you deploy the machines on your own? 🤔

short tusk
#

Subscribe

quiet schooner
shell snow
#

thanks 🙂 thought maybe you can deploy all of them

stiff egret
#

Anyone playing?

#

:(

short tusk
#

Subscribe
@short tusk Oh sorry I thought you meant play KOTH by yourself my b

late sundial
#

How to start with koth

#

pls guide me guys

stiff egret
late sundial
#

??

stiff egret
#

Um, this question have been asked a lot so I just pasted the reply links. :)

serene bay
#

Public Game Starts in 15

autumn iron
#

public game 22mins

short tusk
#

I might play a game in about an hour

autumn iron
#

no problem join the next game 😉

#

i would play multiple games today

stiff egret
#

O.o never seen jabba play

#

ping me too?

autumn iron
#

yup sure

nova tide
#

I might play a game in about an hour
@short tusk when you gonna play? I just woke up. Should i turn on my pc?

short tusk
#

Not yet haha, eating breakfast atm

nova tide
#

Subscribe
@short tusk even if you are not sub you can deploy random koth machine in private games

short tusk
#

Learn something new everyday ;)

stiff egret
#

@autumn iron GG awesome match, nice match after so long

nova tide
#

👀

autumn iron
#

thankyou 🙂

stiff egret
#

Had me struggle, alot

serene bay
#

which koth machine has kernel 3.8.X ?

#

any idea ?

stiff egret
#

uname

serene bay
#

myname

patent forge
#

Hello everyone 👋🏻

low mango
#

Hi

#

@distant aspen hydra won't help you.

distant aspen
#

@low mango Forgot that was even running - kinda gave up when I saw that you were in the machine and anything which I thought might work seemed to have been changed to stop working.

#

@low mango Congrats on the win 🙂

low mango
#

Thanks tipsfedora

distant aspen
#

I'll give KOTH another go when I'm a little better/quicker.

low mango
#

Good luck

distant aspen
#

Thanks

patent forge
#

plis join

low mango
slate crow
#

lol, is koth still a thing? xD

low mango
#

koth has already started

serene bay
#

@slate crow Hello Sar

slate crow
#

what is a Sar?

#

Sarah?

fair adder
#

lol

stable glen
#

how do i get the directory?

fair adder
#

dirbuster or gobuster @stable glen

stiff egret
#

what is a Sar?
@slate crow slang for sir

low mango
#

dirbuster or gobuster @stable glen
@fair adder or ffuf

fair adder
#

@stable glen u will need a wordlist for gobuster um I think dirsearch has one preinstalled

stable glen
#

aight

#

ty @fair adder @fair adder

#

wiat how do i do it exactly

stiff egret
#

Just google for options of dirbuster or gobuster, If you are on kali/parrot, the wordlists are preinstalled I think. So, Just google (!)

stable glen
#

i have kali

stiff egret
#

Also, (not rude) but google replies faster then any of us, DMing it will be more helpful....

#

:))

fair adder
#

the wordlists are in dirbusters directory

stiff egret
#

Also, (not rude) but google replies faster then any of us, DMing it will be more helpful....
@stiff egret MODS, is it worthy of pin?

stable glen
quiet schooner
#

Try it

stable glen
#

try waht

#

i want the koth directroy

quiet schooner
#

wat

#

There is no koth directory

stable glen
#

bruh

#

look

quiet schooner
#

I'm looking

stable glen
stable glen
#

🐒

quiet schooner
#

Ok, have you done any of the beginner rooms on THM?

#

I recommend going to your dashboard and completing those first

stable glen
#

yep iv done 3

stiff egret
#

King of the hill is for intermediate level. (?)

stable glen
#

:/

quiet schooner
#

yep iv done 3
@stable glen Then you should know how linux works. And that koth is a folder john made on his own machine.

stable glen
#

hm i knew that...

quiet schooner
#

You know... I'm gonna go out on a limb here and say that's a lie.

fair adder
#

how'd you guess that one

vagrant gull
#

Thm's official sherlock up in here

olive vessel
#

Hey... Anyone please tell me what's KOTH... and what should I do when I get in there? Actually I'm new to THM ;(

dusty canyon
#

Its just king of the hill

#

U just need to go to ur profile

#

And change ur skill level to intermediate or above i think

#

Its pretty fun

#

Yo hollup

#

My guy ur omni stfu u aint new

vagrant gull
#

@olive vessel I don't think you're serious, but if you are then you're dumb as it's quite literally on the page as soon as you click on koth.

dusty canyon
#

@vagrant gull quickly retreat, we still have time to claim our dignity

#

Hes confuzzed us

inland sluice
#

Does gobuster/dirbuster accomodate stdin for the wordlist?

stiff egret
#

Thm's official sherlock up in here
@vagrant gull if you mean me, then unofficial

nova tide
#

👀

stiff egret
#

👀

sturdy plank
#

👀

flint ember
#

👀

nova tide
#

But can you do dis

quiet schooner
hardy jungle
stiff egret
#

Naughty flexing his custom emojis
Me screenshotting them and uploading them to tenor so I can flex back

nova tide
#

Well i only have 10 more days to spam them 🤷‍♂️

stiff egret
#

then you'll join the tenor family

#

xD

#

You flex anymore and I wont share those tenor links. Huh

vagrant gull
#

@stiff egret Oh shit that's a real thing!

stiff egret
#

Yee it is, I took to that mission personally after naughty spammed me with nitro emojis for 3 days.

vagrant gull
#

Ahahah

stiff egret
#

That's pepesaber

nova tide
#

Yee it is, I took to that mission personally after naughty spammed me with nitro emojis for 3 days.
@stiff egret demonrun partypussy parrot partyTroll nootnoot reegun

serene bay
#

@nova tide He takes things personally alot💁‍♂️

stiff egret
#

soon, I'll get that nitro, and you'll wake up to 100 nitro emojis everyday

nova tide
#

imma block you every night before going to bed kekw

stiff egret
#

I'll make a bot

#

just for this

serene bay
#

Sounds like Tsundere to me @nova tide

stiff egret
#

wha- ?

serene bay
#

Wait

#

Tsundere is a Japanese term for a character development process that depicts a person who is initially cold before gradually showing a warmer, friendlier side over time. The word is derived from the terms tsun tsun and dere dere.

stiff egret
#

👀 madeup words

serene bay
#

That's the truth

serene bay
#

Language of Kami 🥳

patent forge
carmine hemlock
#

@patent forge might wanna reset, accidentally overwrote the root flag instead of king.txt 🤦‍♂️

patent forge
#

i'm out @carmine hemlock

#

gg

carmine hemlock
#

gg, was quite a battle

patent forge
#

yep, but every time i set a "true" persistence the machine got reset

#

so it's kinda annoying 😦

carmine hemlock
#

to my knowledge it only got reset once didnt it?

patent forge
#

nope, i saw 2 resets

carmine hemlock
#

interesting, but the ip changes doesnt it?

patent forge
#

or maybe i'm wrong

#

yeah wait a sec

carmine hemlock
#

I'm still in with the same ip

patent forge
#

lol

carmine hemlock
#

just one reset lmao

patent forge
#

lol

#

typo in a payload

#

ggs

carmine hemlock
#

And pre- that reset i kinda had "persistence"
ggs lmao

fair adder
#

"i want to hold you like a switchblade" @carmine hemlock

carmine hemlock
#

lmao

lapis arch
#

starting one now!

#

starts in 1 minute

hollow galleon
#

Another one is starting in 18 minutes

lapis arch
#

Anyone willing to share KOTH process via discord?

hollow galleon
#

I'm brand new to it so I won't this time 😛

lapis arch
#

haha me too

hollow galleon
#

Join in the for the laugh, we'll struggle along together and see how we'll do

lapis arch
#

Where to join? @hollow galleon

hollow galleon
#

6 minutes until we start

lapis arch
#

Oh Im in

hollow galleon
#

Just make sure you've joined it

lapis arch
#

I am sure

hollow galleon
#

Ah yeah I see you now

lapis arch
#

Im the n33wbie of the room

#

😆

hollow galleon
#

Am I ok to DM you?

lapis arch
#

Sure mate

#

@stiff egret can I Dm you later? tks Sir

stiff egret
#
  1. No need for sir.
#
  1. ofc NP
west sky
#

Hello, are you allowed in koth to delete a flag file? like a flag in flag.txt, are you allowed to delete it when you gain access to the machine?

#

Thanks

stiff egret
#

Ok, I usually don't do this, But someone is editing names of flags.

#

Whoever you are, Please give Rules a look.

hollow galleon
#

I can't even get back into it after my connection dropped so definately wasn't me 😛

stiff egret
#

60% of the things you are doing are against the rules. (not to you @hollow galleon )

hollow galleon
#

I've had a lot of fun doing this, didn't have a huge idea on what I was doing but having competition added a cool side to it

stiff egret
#

Um, You are with the username kiwi?

hollow galleon
#

No I'm spl99 above you, I just changed my username in here to work with the tryhackme website

stiff egret
#

Ah, ok, nice.

#

GG

#

Whoever kiwi was, nice game man, You fought hard.

hollow galleon
#

It looked like a good fight in fairness

stiff egret
#

Yeah. One of the rare ones.

#

Most of the time people just put up superman defences and its no point to play after that. This one, non of us patched port <REDACTED>, and it was fun lol

hollow galleon
#

Thats awesone! Makes it more interesting that way I'd imagine

fair adder
#

what rooms do you have to have finished to play koth?

blissful kettle
#

To play KOTH you need to set your experience level to intermediate @fair adder

fair adder
#

yeah i understand, but whats the recommended like experience?

#

im unsure what intermediate is

stiff egret
#

um, imo, just try public KoTH rooms, like Food / hackers. And if you think you can handle then go for match with real players.

blissful kettle
#

Intermediate is that you have a basic understanding of security

west sky
#

oh ok, because I was playing with somebody, and he removed the flag

blissful kettle
#

That's allowed

west sky
#

it said thats not allowed in the rules

gusty cradle
#

It's not allowed

blissful kettle
#

oh crap i might have read that wrong

west sky
#

lol

#

he was a level 1 in disguise

gusty cradle
#

Level 1's are always the ones you need to watch out for

#

😄

west sky
#

yeah he was trolling

stiff egret
#

Petition to make Rules page the most underrated page of tryhackme.

blissful kettle
#

and the unverified

nova bramble
#

I have a thought for something to try on one of these koth boxes, but I’m unsure if it would be against the rules, is there a mod or admin I can DM to verify?

sudden badge
#

ask here

#

in the channel

lapis arch
lapis arch
#

Does sometime machines in KOTH takes a while to load?

quiet schooner
#

It probably doesn't respond to pings as it's windows

nova bramble
#

@sudden badge If you get on a Linux box, is it fine to do a for loop killing any process based on when it’s created?

#

Would stop any new connections and stuff to the box. Idk the format of KOTH on THM boxes so idk if that would break scoring checks

sudden badge
#

Oh, dont ask me i dont play koth, i Just told to ask in here lol

#

Someone will give theit opinion

quiet schooner
#

Sounds like it would impact legitimate users, so that's a bad @nova bramble

stiff egret
#

Imo, think about it like this, 'If someone hired you as red team incident response team, then will you do that on the main?'

#

'Making a loop to kill every new connection?'

quiet schooner
#

*blue team

stiff egret
#

I just follow this before I make any move in game. Simple.

#

Is it tho?

#

🤔

#

Incident response teams are blue?

quiet schooner
#

Yes

#

Red teams are attack

stiff egret
#

Ah well, my bad.

little nebula
lapis arch
#

@little nebula Hey can I DM you?

little nebula
#

Yeah

little nebula
low mango
#

Nice

vernal rock
#

hey lads

#

me and my friend are in a KOTH

#

and we are both pretty sucky at this

#

any advice on how we could start tying to find an explot?

#

So far we've ran dirbuster, nmap, and used burpsuite and have found nothing.

low mango
#

Enumeration is a key

#

@little nebula @fair adderot @Prasadbro gg

vernal rock
#

enumeration? such as in their database?

grand ember
#

Yup

vernal rock
#

how though?

#

how could I even find a database?

grand ember
#

Web apps maybe

vernal rock
#

erm

#

I'm quite new to this, could you maybe go more in depth please?

nova tide
#

I'm quite new to this, could you maybe go more in depth please?
@vernal rock KoTH machines are meant to be a challenge.. So i don't think anyone gonna teach you how to root any of these. what you can do is do the easier ones on your own. Start from Shrek or Food.
There are already official writeups for Food and Hackers in Hacktivitites by James. Also try to do some easy level rooms before playing koth. As koth is meant to be intermediate level.

stiff egret
#

MODS, Pin this? upvote

#

This is repeated so many times.

serene bay
#

stop spamming reset guys please 🙏

stiff egret
#

😂😂

#

sudo systemctl disable reset.service

lapis arch
autumn iron