#koth

1 messages · Page 40 of 1

lapis arch
#

Im in Shark

#

GLHF!

stiff egret
#

How much time is remaining?

lapis arch
#

30min @stiff egret

stiff egret
#

ah too late prolly

stiff egret
#

@autumn iron You aren't playing?

cinder vigil
#

We just finished the koth we were playing

autumn iron
#

nope 😅

cinder vigil
#

idk if he went for another one

stiff egret
#

nope 😅
@autumn iron thought so after I saw the scoreboard

lapis arch
fair adder
#

hey guyss i need help

#

is this the right place to ask help?

quiet schooner
#

Probably not

nova tide
#

Depends about what you need help.

hardy jungle
fair adder
#

oh okay thanks

native saffron
#

Hey , I’ve never played played koth , can someone explain what are the rules / what we’re supposed to do ?

quiet schooner
#

Both of those are explained on the page for KoTH 🙂

serene bay
#

@quiet schooner Pin this maybe ?

vagrant gull
#

Yes

serene bay
#

I've never seen so many upvotes in my life 👀

stiff egret
#

I'd say that he is sleeping, but he's probably watching. Like always.

serene bay
#

Just like God is watching us from his humble abode 🦩

stiff egret
#

imagine believing in God.

gusty cradle
barren stream
nova tide
#

I'd say that he is sleeping, but he's probably watching. Like always.
@stiff egret just woke up kekw

serene bay
#

We were talking about god@nova tide

stiff egret
#

I was talking about Ninja

lapis arch
mint cargo
#

what is the box?

stiff egret
#

No Idea, Anyone playing?

#

Join in, Starting in 6 minutes, Random, Public.

lapis arch
#

I will join late, whatever lol

stiff egret
#

And I left because no one was active lmao

lapis arch
#

hahaha

stiff egret
#

Are you playing it rn? In the same game?

#

@lapis arch

lapis arch
#

TRYING TO DO SOMETHIN

#

will try a flag at least lol

stiff egret
#

I guess its in #room-help where you should say this

frozen lily
#

Thx, sorry

stiff egret
#

Ping me if anyone is playing :))

fair adder
runic vigil
#

i'll try why not

cobalt jackal
#

anyone wanna do some koth?

runic vigil
#

ey talio ii'm doing rn

cobalt jackal
#

can we reset?

#

wtf happened?

runic vigil
#

idk :(

#

it was weird

cobalt jackal
#

one of you did something funny and broke the machine

runic vigil
#

well whatever it was near finishing anyway

cobalt jackal
#

yeah that's the weird part about it

#

join a new public one

lapis arch
#

im here from a koth, if anyone wants it, ping me here

glacial mantle
#

anyone here for koth?

vocal shell
#

What are some dirty tricks to do in a KOTH game? I know a very popular one (courtesy of John Hammond) is concatenating /dev/urandom into someone’s shell

stiff egret
#

aliases.

#

editing bashrc

#

There are a lot of things you can do, easiest way to know is by getting hit by them.

vocal shell
#

There are a lot of things you can do, easiest way to know is by getting hit by them.
Do you know of how I can find/make these tricks on my own? Would you happen to know if there is a GitHub or an article on some tricks?

gusty cradle
#

Alias nano to vim! blobknife

vocal shell
#

Mwhahaha that’s evil. Isn’t there a way to remove all aliases though? I cant recall the exact command, but I’d just do that.

gusty cradle
#

Yeah, there's the unalias command

#

You could also try symlinking them

vocal shell
#

Question, say you infect a binary such as /bin/echo, how would one find the infected binary 😮

gusty cradle
#

What do you mean by infect? If you mean modifying it to introduce a backdoor, that might work

vocal shell
#

Yes that’s precisely what I am thinking

gusty cradle
#

You'll have to compile from source

#

You could also use an LKM rootkit

vocal shell
#

and then each time someone tries to remove it there is a grep command searching for it and adds it back

gusty cradle
vocal shell
#

Ahh so you’d compare that with the echo binary?

gusty cradle
#

Hmm?

#

Wait? Is that even the source code for echo? 🤔

vocal shell
#

I don’t think so

#

But just for detecting an infected binary I’m not sure what would be the right thing to do

gusty cradle
#

I mean the binary would be compiled so it would be really difficult to detect 🤔

vocal shell
#

Wait

gusty cradle
#

Unless you get the source of the original binary and compare it 🤔

vocal shell
#

What if you copied the contents of the binary to another binary you made yourself

#

Ones infected the other isn’t

#

So to the user it looks like nothing is wrong

gusty cradle
#

Binaries are compiled, so you would have to copy the source code

vocal shell
#

🤔 You’re right

#

Hmmm

#

I’m confuzzled now

gusty cradle
#

I doubt anyone has enough time to RE a common linux binary, KoTH's only last for an hour

vocal shell
#

Ahh you’re right

gusty cradle
#

So the chances of anyone noticing it is very small

vocal shell
#

Hmm

#

Yes I agree

#

Ok so in general if you’re doing a blue/red exercise like KOTH I’ve noticed that people like: ps aux | grep pts

#

and then kill other people’s shells

#

Is there a way that perhaps you make a script that whitelists your shell and kills everyone with a different pts? Or maybe if you’re like evil evil, catting /dev/urandom in a loop endlessly into someone else’s shell

#

What are the ways someone can stop the /dev/urandom trick

gusty cradle
#

mesg n might block it

stiff egret
#

I just run a while loop for mesg, just in case some else reverts that.

#

But keep a shell open, and well, kill -9 $(pgrep cat)

terse willow
#

Please try to keep it PG13 @serene bay 🙂
If you've got a complaint, please feel free to send it in an email to koth@tryhackme.com along with the game ID. They are monitored, and can be checked 🙂

stiff egret
#

Ghost pings.

nova tide
#

YEAH

stiff egret
#

I'll report, @serene bay

serene bay
#

👀

stiff egret
#

Spamming in multiple servers

serene bay
#

that was on other 👀

stiff egret
#

I'll let this one pass

serene bay
#

🙏

gusty cradle
#

I saw that 👀

serene bay
#

Ahem I'll shall let this one pass too

stiff egret
#

LMAO Just saw that you are awasthi, lmao, I actually got offended

#

nvm, I take back my msgs,

tepid hornet
#

what's awasthi 🤔

stiff egret
#

I'll spam you back in every. single. channel

#

what's awasthi 🤔
@tepid hornet friend

tepid hornet
#

In Japanese I presume ?

serene bay
#

@tepid hornet Please don't translate

tepid hornet
#

wut kekw

stiff egret
#

Lmao, Awasthi is a last name

#

lmao

#

Its P.J. Awasthi

serene bay
#

That's it

#

Time to call God

carmine hemlock
royal cliff
#

I am down

#

Kind of curious if it's me or the attack host, can't get any ssh connection... getting key mismatch

nova tide
#

key mismatch and connection failed are two different things 🤷‍♂️

royal cliff
#

It was a algorithm mismatch

#

fixed it... now I understand why things arent working

nova tide
#

Nice

carmine hemlock
#

rip didnt get the user passwords this time, I think I set my hydra to a bit too many threads there, gg!

royal cliff
#

I hear you...

patent forge
frigid owl
#

@patent forge you got on there quick, it was me that kept knocking you off the file even though I couldn't write on it myself 😛

dusty canyon
#

Holy shit i hate tyler

obsidian dagger
#

hahah yeah that librenms is such a pain in the ass

#

the exploit is on metsploit right?

dusty canyon
#

Umm wait for tyler?

#

Oh damn were in the same game dude

#

Im jondoe

#

Also its the smb thing

#

I just did smbget cuz my smbclient was buggy

obsidian dagger
#

hahaha yeah maybey where in the same game, man tbh this game I gave up like some time ago I'm like in Europe and I'm so tierd so I can't focus anymore

dusty canyon
#

Oh dang man get sum sleep

#

What time is it for u?

patent forge
#

@frigid owl sorry dude I left the game after getting king sadcooctus

frigid owl
#

@patent forge i don't blame you lol, it seems like the only real feasible avenue onto it got nixed

hallow torrent
#

can i team up and play king of thee hill ??
??????
is there a option for it?

#

@quiet schooner

quiet schooner
#

Why tag me?

hallow torrent
#

cuz u r the mod?

quiet schooner
#

???

hallow torrent
#

can i team up and play king of thee hill ??
is there a option for it?

quiet schooner
#

I don't know, can you find one?

hallow torrent
#

no

quiet schooner
#

Then... Perhaps it's a no.

#

No need to tag me. Just be patient and wait for an answer.

hallow torrent
#

ok

nova tide
vocal shell
#

Question, how often do KOTH games occur?

nova tide
#

or you can share invite link here and whoever wants they can join in

vocal shell
#

Awesome, thanks!

grand ember
#

@hallow torrent you can team up but having it done is up to you

left folio
#

koth

lusty crown
#

hey

left folio
#

anyone join

#

game starts in 8min

tepid hornet
#

You got it blobknife

fair adder
#

please remove me from game, i accidentally clicked

tepid hornet
#

xD it's already over

lusty crown
#

hey

tepid hornet
#

Hi

lapis arch
#

hellow

nova tide
#

You got it blobknife
@tepid hornet play with me blobknife

tepid hornet
left folio
#

i lost connection @tepid hornet last match

tepid hornet
#

Unfortunate

left folio
#

coming in ?

#

7mins left

#

@nova tide play

tepid hornet
#

I'll pass

#

@nova tide is always ready to play

left folio
#

k

nova tide
#

playing minecraft with friends

left folio
#

k

serene bay
#

@left folio i'm in

left folio
#

yes

serene bay
#

@left folio playing ?

lapis arch
#

Anyone wants some koth?! Can i Use @here here? lol

gusty cradle
lapis arch
#

no for koth, here, both, or any?

nova tide
left folio
#

@serene bay hi i have a question

serene bay
#

Yep ?

left folio
#

im unable to connect ssh is it box or something wrong ?

serene bay
#

😉

#

nmap again

left folio
#

i did

serene bay
#

maybe i changed ports

left folio
#

are you sure its working ?

#

did u restart ssh after changing port ?

serene bay
#

try higher ports @left folio

left folio
#

PORT STATE SERVICE REASON
80/tcp open http syn-ack
139/tcp open netbios-ssn syn-ack
445/tcp open microsoft-ds syn-ack
3306/tcp open mysql syn-ack
8080/tcp open http-proxy syn-ack

#

nmap -p- 10.10.144.114 -^C -T5 --max-retries 0

serene bay
#

missed some more higher ports

left folio
#

k another one ?

frigid owl
#

gg @nova tide

nova tide
#

Nice one

#

but i left after taking king

#

playing siege rn

frigid owl
#

cool

quiet schooner
#

Haha thinking the chattr binary in path is the only one on the box

nova tide
#

i mean it was in /usr/bin/

frigid owl
#

no it wasnt

nova tide
#

(not with chattr name)

frigid owl
#

that's true, but i searched all paths

quiet schooner
#

snap

terse willow
#

perl

#

python

frigid owl
#

thanks for the food for thought

stiff egret
#

If someone start KoTH, ping me, I need a break.

#

send help

lapis arch
#

still there @stiff egret ?

#

I've just leved! Now I'm ready for Koth, lol

stiff egret
#

yee

#

Send the link, I'll join

lapis arch
#

ok one sec

nova tide
#

👀

stiff egret
#

Naughty if you join, then its a deadlock most prolly

lapis arch
#

anyone for koth? @stiff egret

#

We are at 3 already !

warped hearth
#

what is koth

blissful kettle
#

king of the hill

warped hearth
#

oh ok

lapis arch
#

hey jondoe

#

i think you've erased flag contents!

dusty canyon
#

I didnt

fair adder
obsidian dagger
obsidian dagger
#

gg @long kiln!

#

dang hackers is really hard

#

how did you get a privesc? I tried litteraly everything 😄

long kiln
#

how did you get a privesc? I tried litteraly everything 😄
@obsidian dagger sudo -l -l

obsidian dagger
#

but it said that sudo -l like the user I had couldnt do anything as sudo

#

did you like lock it?

#

I did see that lxd was installed and thought abt exploiding it but didn't have time

stiff egret
#

Run LINPEAS.

vocal shell
#

anyone have some neat tricks like cat /dev/urandom into someone’s shell similar to this (aggressive defence)

stiff egret
left folio
stiff egret
#

Which box?

left folio
#

dont know

stiff egret
#

Time?

left folio
#

starts in 19mins

stiff egret
#

thm booting

left folio
#

yes

#

14 mins left

#

whoz homeless ?

stiff egret
#

LMAO

#

It's not homeless

#

I have a home

blissful kettle
stiff egret
left folio
#

@stiff egret whats yours ?

stiff egret
#

holmes

left folio
#

@stiff egret wopps i didnt read it lol

#

i misread holmes as homeless

stiff egret
#

Yeah NP kekw

left folio
#

whoz blackout ?

#

wow we have 5 users

stiff egret
#

Noice.

tepid hornet
blissful kettle
#

my vpn lost connection and logged me out 😢

stiff egret
#

👀

#

Someone ran some misconfigured loop that was borking the king file, So I had to kick y'all out.

#

:sed:

blissful kettle
#

I keep getting the warning error on the vpn but that doesn't stop the connection so idk what's happened

stiff egret
#

🤷‍♂️

blissful kettle
#

might have to regenrate

stiff egret
#

Yeah, that might solve the issue.

#

He had persistence..

left folio
#

lol u won

#

osm

stiff egret
#

:))

nova tide
#

staring in 8 minutes

dusty canyon
#

Lmao

rancid pewter
#

Hey

dusty canyon
#

Hey dude

#

Attrib -i is the command right?

rancid pewter
#

attrib -a

#

I think

dusty canyon
#

Idfk how to make it writable yea

#

Oof gj dude

#

Ggs ur fast

rancid pewter
#

attrib -R Actually

#

Wanna compete on linux ?

dusty canyon
#

Lmao yea sure bro

rancid pewter
#

Join the public game

dusty canyon
#

Ight ight

#

Go easy pls

#

Ah jeez naughties here too

rancid pewter
#

Wont use my rootkit then

dusty canyon
#

LMAO

#

Yes please

rancid pewter
#

Someone remove the /bin directory

dusty canyon
#

No idea who that was

#

Who did that

#

Not me

#

Anyways ggs you godly men

nova tide
#

i mean there are only 4 ppl in game 🤷‍♂️

dusty canyon
#

Lmao and 2 of them are gods

nova tide
#

(lvl is just a number)

dusty canyon
#

Lmao maybe

lapis arch
#

ping me if anyone wants to play

nova tide
#

@lapis arch

lapis arch
#

oh yea

#

create invite link send to me!

#

@nova tide

nova tide
#

just join a public game

#

and i will jump in

dusty canyon
#

Ight yea same

lapis arch
#

nice

#

5min to start!

#

hurry @nova tide

#

I think jondoe is there

dusty canyon
#

Lmaoo

stiff egret
#

LMAO spec link?

rancid pewter
stiff egret
#

oooooooooooooooooof

rancid pewter
stiff egret
dusty canyon
#

yo donut howwwww

#

its the chattr thing right?

rancid pewter
#

I havent use my rootkit

dusty canyon
#

yea yea ok you and ur kits of root

rancid pewter
#

Just have a C script constantly making the file immutable

dusty canyon
#

yea i was wondering

rancid pewter
#

And putting my name in it

dusty canyon
#

like damn it kept saying the file has changed since i last wrote it

rancid pewter
#

At 5 thread

dusty canyon
#

lmao dude thats sum big man energy

stiff egret
#

There's a hidden rule that rm -rf / is allowed.

dusty canyon
#

no way

#

whoops

rancid pewter
#

I got another script that can do 50 thread in 5 process so 200 thread total but it too fast

dusty canyon
#

yea ur gonna crash the box dude

stiff egret
#

not box, but that thing sometimes borks the king file.

nova tide
#

/bin/ gone again

dusty canyon
#

lmao yea sorry

#

i did rm -rf *

nova tide
#

sorry?

stiff egret
#

ooooooooooooof

nova tide
#

really??

dusty canyon
#

yea

#

my bad

nova tide
#

...

dusty canyon
#

sorryryr

rancid pewter
#

And I got a rootkit that is just is unbeatable except by another rootkit

stiff egret
#

... kekw

dusty canyon
#

detective said it was ok

nova tide
#

and you did that in a game before as well

dusty canyon
#

that wasnt me

nova tide
#

in space jam

dusty canyon
#

no cap

nova tide
#

why ? 🤷‍♂️

dusty canyon
#

whahduduayu meana

nova tide
#

...

stiff egret
dusty canyon
#

LMAO

#

koth is fun

#

also i cant do anything now

rancid pewter
#

On which game ?

dusty canyon
#

space jam

#

the dumb one that i dont like

rancid pewter
#

Seem to be alright for me

dusty canyon
#

its hard

#

also the food box is bricked to we reset it?

rancid pewter
#

Yeah sure

stiff egret
#

iirc Space is the easiest ones out there.

dusty canyon
#

ight

#

no shh

#

its very difficult

stiff egret
#

checking notes

dusty canyon
#

lmaoo

#

...?

stiff egret
#

Just checked, Yeah, space is indeed one of the very easy ones, you didn't check your nmap correctly

dusty canyon
#

no waayy

#

yer johkin

stiff egret
#

You'll know when you root that, 😉

dusty canyon
#

lmao i did dude it took me like 20 min

#

fuckin curl commands are so sensitive

stiff egret
#

LOL whic-? wha-?

dusty canyon
#

also idk if this is how ur supposed to do it but i got a root shell from that

stiff egret
#

||which port you talking?||

quiet schooner
#

Spacejam is easy until someone patches the single vuln that people know

dusty canyon
#

bro i dont have my nmap i dont remmebr

#

yea

nova tide
dusty canyon
#

LMAAOO

#

ITS THAT CHATTR BOT MAN

stiff egret
#

-oN nmap_initial

dusty canyon
#

BRUH @rancid pewter

#

ah

rancid pewter
#

Yeah that me doing some typo

stiff egret
#

Ninja watching everything, as usual

dusty canyon
#

lmaoooo

stiff egret
#

from /etc/shadows

dusty canyon
#

yo i thought that the ~ thing was a chattr glitch

#

i was playing around with chattr before and the same thing happened when i tried to edit the file

#

the :wq! thing

rancid pewter
dusty canyon
#

ohhhh oby lets go

#

you better not use ur damn rootkit

stiff egret
#

The only way to beat mydonut is to not let him in the box.

dusty canyon
#

LMAO

#

tru tru

rancid pewter
#

Then join the game @stiff egret

dusty canyon
#

NOOO IT SPACE JAM AGAIN

gusty cradle
#

👀

dusty canyon
#

BRHHHH

stiff egret
#

Then join the game @stiff egret
@rancid pewter some other plans tonight kekw

pearl pasture
#

not jondoe again

gusty cradle
#

Space jam is literally the easiest box

dusty canyon
#

no

rancid pewter
#

Someone already removed the binary

dusty canyon
#

oh who

low mango
#

yea

#

I have the same problem

dusty canyon
#

yea

#

me too

#

i mean echo still works

rancid pewter
#

@stiff egret Come on only playing for 30 min

dusty canyon
#

kindaaa

#

yea ive never played with detective man

#

hey detective man play a koth game

stiff egret
#

LMAO 1. jondoe I am usually playing just not tonight
2. oi donut, ah man can't 😦

dusty canyon
#

ahhhhh lmao ight well say when ur playing

stiff egret
#

already running 2 days behind the schedule

dusty canyon
#

on what?

#

HOW

rancid pewter
#

Ok no problem hope to play against you soon

stiff egret
#

because I can't bypass my lazyness threshold

dusty canyon
#

oh wait was it reset

stiff egret
#

Ok no problem hope to play against you soon
@rancid pewter sure thing

#

TIP: spam reset and patch before mydonut can get in

#

bella ciao

dusty canyon
#

lmaooo

rancid pewter
#

Removing every binary from the box wont stop me I have my static shell

dusty canyon
#

@cobalt jackal ?

quiet schooner
#

Removing every binary from the box wont stop I have my static shell
@rancid pewter It also sounds like it'd impact legitimate users quite hard... Which sounds like it's against the rules

rancid pewter
#

I am not the one removing binary from the box

dusty canyon
#

huh?

#

my guy im not even playing

quiet schooner
#

@dusty canyon Please stop spamming cursewords in russian. This is an official warning.

dusty canyon
#

no dude this was literally before

#

look at the time stamps i didnt do this after you told me dude

quiet schooner
#

Just accept it and improve for the future, ezpz

dusty canyon
#

oof

#

.__.

rancid pewter
#

Anyway well played all

dusty canyon
#

yes yes

low mango
#

lol

#

I just noticed that the /bin folder has been deleted

lapis arch
#

p

#

wp

#

lol

fair adder
#

anyone want to play ?

nova tide
#

It also sounds like it'd impact legitimate users quite hard... Which sounds like it's against the rules
You talking about deleting binaries or his sash shell?

quiet schooner
#

Deleting /bin

nova tide
#

👍

obsidian dagger
#

if anyone is intrested

vocal shell
#

Are KoTHs recorded on your profile? Like how many you've entered in? Your W/L ratio or whatever?

left folio
#

anyone ready for koth now ?

stiff egret
#

Are KoTHs recorded on your profile? Like how many you've entered in? Your W/L ratio or whatever?
@vocal shell I don't think there's anything like that on site rn. Tho there's a tool out there that can calculate, but it's half broken

vocal shell
#

Awesome thanks!

stiff egret
#

:))

sudden condor
#

Hey guys

nova tide
#

I don't think there's anything like that on site rn. Tho there's a tool out there that can calculate, but it's half broken
half broken?? 👀

gusty cradle
#

👀

low mango
#

Hello guys

stiff egret
#

half broken?? 👀
@nova tide Haven't had the time to fix that capping issue 🤷‍♂️

nova tide
#

i thought that was THM blocking it 🤔

#

(too many requests)

stiff egret
#

Yeah, that's the capping thing. I think it can be fixed, but haven't tried it yet 😬

#

I was planning on making it so that it only needs to run once and save the data locally

nova tide
#

well it works in Kali browser though 🤷‍♂️

stiff egret
#

Yeah, that's why "Half broken"

#

😂

#

Weird tho, why external requests are getting firewalled as well as those which are on VPN, but not those from kali machine.

nova tide
#

coz kali is in the same network

stiff egret
#

So are the VPNs.

#

Kali is just another machine connected to thm using VPN.

hallow torrent
#

would it be legal if i edit server.js in spacejam for preventing command injection?

terse willow
#

If you're meaning editing a web file to remove the vulnerable code?

#

That is exactly what you're supposed to do

sturdy plank
#

guys in my koth match the players reset it when there was no-problem

#

and they reset about every minutes

#

is there anyway to warn them

hallow torrent
#

lol

quiet schooner
#

Not actually against the rules yet so no @sturdy plank

dusty canyon
#

@wicked viper pls stop resetting

cobalt jackal
fair adder
sturdy plank
#

ok thx for ur help @quiet schooner

rapid spire
#

Someone wants to play koth?

pearl pasture
#

oh hey @rapid spire XD

rapid spire
#

Hey

pearl pasture
#

good game 🙂

rapid spire
#

yes

#

gg

#

Are you aliceawoo?

pearl pasture
#

yeah

rapid spire
#

someone to play koth?

left folio
serene bay
#

Starts in 20

left folio
#

anyone ?

low mango
hallow torrent
#

would i be able to level up from the points i gain in koth?

royal cliff
hallow torrent
#

i joined

brazen cloud
#

At the moment you don't gain any points by participating in KoTH @hallow torrent

hallow torrent
#

why not?

#

at the moment i mean

brazen cloud
#

KoTH is completely seperate from the wider THM site as it stands. At most you can earn the "KoTH winner" badge for your profile

#

It's been requested, I think we're waiting for KoTH to expand a little bit more and for the teams part of THM to be overhauled (:

hallow torrent
#

ohh

stiff egret
hallow torrent
#

cuz its beta

lapis arch
#

anyone for a koth?

#

25 minutes to start

dusty canyon
#

oh nice

#

wait that was 2 hours ago

#

im smart

lapis arch
#

lol

tacit siren
#

Anyone is up for game ?

obsidian dagger
#

I'm down

#

send me a link ill join or you want me to create the game?

tacit siren
obsidian dagger
#

dope

#

@tacit siren can you hear me?

hallow torrent
fair adder
nova tide
#

Elf playing koth 👀

stiff egret
#

he disappears every time

hallow torrent
worldly beacon
#

has anyone done zth web 2

#

oh sorry wrong room lol

lapis arch
#

anyone up for a koth?

obsidian dagger
#

I'm down

#

@lapis arch

lapis arch
#

Ok then, I will create a room

#

@obsidian dagger

obsidian dagger
#

okay I'm joining

lapis arch
#

its ok to wait?

obsidian dagger
#

yeah nah it's chill

lapis arch
#

great see u soon

obsidian dagger
#

I'm quickly finishing a room while the game starts

lapis arch
#

me2

lapis arch
#

cool, we got 4 ppl lets go

#

good luck all

obsidian dagger
#

yeah im kinda hyped tbh

lapis arch
#

haha nmice

obsidian dagger
#

is the room down?

lapis arch
#

hmm not yet oi think

#

im on ssh

obsidian dagger
#

ha my basd my internet was acting up

lapis arch
#

lol damn

wary jolt
#

Good Gamenocooctus

lapis arch
#

haha gg

obsidian dagger
#

ha gg @wary jolt

#

hey the koth binary in the root folder is it yours ? @wary jolt

wary jolt
#

nope. That's the binary that authenticates with the king.txt

#

that's THM's property

obsidian dagger
#

haaa

#

okay I thought it was like a virus that someone put there

lapis arch
#

hahaha

#

does anyone know what does that 'img' executable do? lol

obsidian dagger
#

how did you lock people out from editing the king.txt file?

lapis arch
#

cttr?

wary jolt
#

by changing the change attributes

lapis arch
#

yea thats it

#

King.txt file locked? - A user might have used the chattr binary to stop even a root user editing the file. @obsidian dagger

obsidian dagger
#

dope I never seen that

#

pretty clever

wary jolt
#

always check for the file attributes tho

obsidian dagger
#

yeah ill do from know on

#

but I managed to like change the file to a symbolic link

#

to like /tmp/test

#

anc put my name in that

#

and yours like still appeared did you put like a process that overwrote me?

#

I tried lookign for it but didnt see it

wary jolt
#

yeah I saw what you did there and removed the symlink and inserted my user again

obsidian dagger
#

hahaha

#

gg anyway 🙂

lapis arch
#

haha nice game guys

#

👏

wary jolt
#

good game. haven't played koth in months and the first game i got is fun XD

lapis arch
#

I was sure my flag would worth it

obsidian dagger
#

yeah I think that was the best game I had yet

lapis arch
#

hard to find good games like this, in these hours lol

thin fox
#

hello guys

#

wanna join?

obsidian dagger
#

hey

#

i'm down

little nebula
native saffron
#

Are we allowed to change the location / name of the king.txt ?

grand ember
#

no

nova tide
#

You can try but it won't work 🤷‍♂️

terse willow
#

Well, it'll work, but it'll break the whole thing

nova tide
#

(unless you edit the king service and that's against the rules)

grand ember
#

you shouldn't tamper with the king service

terse willow
#

It's also thoroughly against the rules

native saffron
#

I guess it’s a good thing I asked :’D to avoid getting into troubles

nova tide
#

You can't rm king.txt you can rename it but that won't work. As machine only gonna check for king.txt file.

#

You edit name for king file and someone makes a new file named king.txt
That new file will be the one used for king service not the one you edited

native saffron
#

Is there anything else I should know about this file ? Like tips or forbidden stuff

nova tide
#

chattr

#

Read about this binary. ^^

native saffron
#

I will ! Thanks

hallow torrent
obsidian dagger
#

gg guys

thin fox
#

gg

dense junco
#

Hi can anyone teach me to do koth?

nova tide
#

check pinned message

lapis arch
#

hey @dense junco , every machine is different, you need to practice thru rooms and try koth on your own

dense junco
#

aight

stiff egret
#

Have I seen you before?

nova tide
#

KoTH machines are meant to be a challenge.. So i don't think anyone gonna teach you how to root any of these. what you can do is do the easier ones on your own. Start from Shrek or Food.
There are already official writeups for Food and Hackers in Hacktivitites by James. Also try to do some easy level rooms before playing koth. As koth is meant to be intermediate level.

stiff egret
#

Your name looks familiar

lapis arch
#

@stiff egret u talking about Ninja? hahha

#

You are the detective, u should know XD

stiff egret
#

Consultant detective. I choose my clients. ;)

lapis arch
#

hohoho 😄

nova tide
rapid spire
#

oh no just dont use google

#

Use duck

stiff egret
#

👀

lapis arch
#

anyone for a koth?

lapis arch
thin fox
#

let's play koth?

obsidian dagger
#

gg guys

thin fox
#

gg

obsidian dagger
#

wanna do a rematch?

thin fox
#

let's go

obsidian dagger
#

@thin fox

thin fox
#

good game

obsidian dagger
#

gg

serene bay
#

@obsidian dagger up for game ?

obsidian dagger
#

ha maybey later rn I'm taking a break 🙂

#

srry

thin fox
obsidian dagger
#

@thin fox did the game glitch out?

thin fox
#

join me

#

xD

#

@obsidian dagger

obsidian dagger
#

ha ok wierd

obsidian dagger
#

you wanted to machine reset? @thin fox

thin fox
#

yeah pls bro

obsidian dagger
#

ha no worries

#

i just got like kicked of the box I was like wtf

thin fox
#

oh srry

#

well i'm ok

#

no need rest

obsidian dagger
#

gg @thin fox you deserved that win

thin fox
#

thz dude

obsidian dagger
#

ha no worries

lusty crown
hazy zodiac
#

@lusty crown what is the machine?

lusty crown
#

idk

hazy zodiac
#

oh

lusty crown
#

you will get the machine name after it starts right?

hazy zodiac
#

ye

lusty crown
#

there's still a lot of time left!

hazy zodiac
#

imma go cycling first

#

cya

lusty crown
#

lol

#

k

stiff egret
#

It's starting in?

lusty crown
#

20 min

stiff egret
#

Ah. Ok.

hazy zodiac
#

@stiff egret want to join?

stiff egret
#

(I avoid KoTH)

#

Also, nope, not @ home rn xD
Might join next game

grand ember
#

Kothhthhthth

hazy zodiac
#

oh okie

#

hai syz

stiff egret
#

Ththththhththt

grand ember
#

Hai

stiff egret
#

but if szy starts a python server on his root.

hazy zodiac
#

oh no

stiff egret
#

kekw :

#

szy your scripts pls

grand ember
#

There are no scripts

stiff egret
#

Then, it must be, .scripts

grand ember
#

There are only my fingers, if you want then just chop them off

hazy zodiac
#

👀

stiff egret
#

0.o

hazy zodiac
#

may i ask for your brain?

stiff egret
grand ember
#

It doesn't exist

hazy zodiac
#

👀

stiff egret
#

Ight, imma go, in a govt office trying to get some docs updated but these lazy app (with 2 s) people are gonna take forever

hallow torrent
lapis arch
#

im up!

viral lichen
#

lemme spectate

lapis arch
#

spectator

viral lichen
#

its early in the morning - I wont be able to see what you guys are doing exactly right?

lapis arch
#

yea

#

But i can stream to you if u want so

#

im not that good xD

viral lichen
#

That would be awesome 😄

lapis arch
#

sure i will dm u

viral lichen
#

its early in the morning - I wont be able to see what you guys are doing exactly right?
@viral lichen nvm its 2pm here.

lapis arch
#

lol

#

early for you xD

viral lichen
#

Heh yeah

obsidian dagger
#

Quick question, using some kind of home made root kit / creating my own malware for remote acess would that be considered cheating?

full grove
#

nope

#

people have done it before

obsidian dagger
#

cool thanks 🙂 👍

hallow torrent
#

how do i patch offline for blue??

lapis arch
#

what do you mean @hallow torrent ?

hallow torrent
#

what do you mean @hallow torrent ?
@lapis arch how do i patch eternal blue vuln in koth offline machine

tepid hornet
#

Try to patch the next best thing you can

dusty canyon
#

or you could just monitor powershell processes. ps powershell in meterpreter

#

also remember to use attrib +R

patent forge
#

private one starting in 15 mins

hasty quest
#

hi

lyric holly
#

hi

grand ember
#

Hey Jammy

low mango
#

Hi there

lusty crown
#

hey

low mango
hazy zodiac
#

@low mango start now?

#

or havent start yet

low mango
#

Not yet, it will start in 19 minutes

#

~18

hazy zodiac
#

oh okie

hasty quest
#

how can join

short tusk
#

click the link

hallow torrent
hallow torrent
#

who is up for koth ?
starts in 5min

fading anchor
#

anyone here?

tepid hornet
nova tide
#

Yo

dusty canyon
#

@fading anchor good game dude

fading anchor
#

gg

placid locust
#

hey ppl

thin fox
#

let's play?

lusty crown
#

@thin fox send the spectator link also

thin fox
#

here is invitation link

#

come and join

lusty crown
#

@thin fox stuck with some paperwork today! sorry! but i would love to just watch the game

placid locust
#

how to watch games live?

stiff egret
#

They aren't live, closest is, you can see the scoreboards.
Or if you know the player, you can ask them to get in a call and screenshare.
There are many videos online of events and matches. Which were live streamed.

#

@ myDonut live streams.

placid locust
#

thx

thin fox
carmine hemlock
thin fox
#

wanna reset?

lilac nymph
#

Does anyone know how to close an Instagram account
@lavish coral I don't think this is the right channel for these kind of questions.

blissful kettle
#

yea that belongs in #general and asking how to close an Instagram sounds kind of suspicious to me

terse willow
#

yea that belongs in #general and asking how to close an Instagram sounds kind of suspicious to me
@blissful kettle Why's it suspicious? (assuming it's their own)

blissful kettle
#

Idk it could be it's just suspicious when you haven't seen them before and they ask that if they elaborated more saying it's their own account then I wouldn't find it suspicious idk i'm just very wary of things

lilac nymph
#

@blissful kettle Why's it suspicious? (assuming it's their own)
@terse willow Nope, He wanted to close someone else's account, He DMed me asking for help.

lyric shuttle
#

anyone want to play?

terse willow
#

@can58#7239 This true?

#

Oh, he's already left

#

Meh, not getting back in then 🤷‍♂️

lilac nymph
#

Yup, think so

#

@can58#7239 This true?
@terse willow I think, he just somehow stumbled upon the TryHackMe website while searching for "How to close Instagram account of someone else"

blissful kettle
#

Yea that's why I thought it was suspicious I was like it's pretty straightforward on how to close your own

terse willow
#

Well, banned now anyway 🤷‍♂️

west sky
#

hello

#

i need help in koth shrek

dusty canyon
#

Enumerate the website harder

#

Theres smthn there

hallow torrent
#

starts in 5

hallow torrent
#

is ssh closed in lion ?

hallow torrent
astral mountain
nova tide
#

Soon it won't be fair. When they update KoTH rules.

#

Can you share spectator link?

astral mountain
nova tide
#

For some reason some people think they don't need blue teaming skills so instead of pstching the boz they chmod 700 or remove all of the binaries

#

It gotta be one of those two guys at the top

stiff egret
#

You can just do this as soon as you get in the box,
chattr +i /bin/*

#

I mean, temporary, but a fix, nonetheless.

nova tide
#

I mean if i get root before them there's no chance for noobs like those to remove any of the binaries 🤷‍♂️

stiff egret
#

LMAO true.

astral mountain
#

You can just do this as soon as you get in the box,
chattr +i /bin/*
@stiff egret thanks, will do

gusty cradle
#

👀

stiff egret
#

||Just don't do this on Production machine.||

#

Production as in the name of box.

nova tide
#

myDonut is typing 👀

rancid pewter
#

Hello some people want to play

nova tide
#

I wish i could 🤷‍♂️

#

But i have all of my things in the hostel

#

But the fan/air cooler wasn't working

#

So i came back to my friend's place

#

Hopefully that will be fixed in the morning

stiff egret
#

systemctl restart cooler

nova tide
#

But i need to privesc first

rancid pewter
#

@stiff egret Can you play ?

stiff egret
#

Nope :( on phone rn.

#

It's about 8 PM here. So very active family time.

rancid pewter
#

Ok yeah no problem

stiff egret
#

You playing tonight?

rancid pewter
#

Yeah if you are playing

#

It morning for me

stiff egret
#

I'll tag you if I start :))

rancid pewter
#

Alright Thanks

hallow torrent
#

sh-4.2# chattr +i king.txt
sh: /bin/chattr: Permission denied

#

why?

rancid pewter
#

You might want to download chattr from your box

hallow torrent
#

You might want to download chattr from your box
@rancid pewter how?

rancid pewter
#

Download a static version of chattr on your box and open a web server to download it from the KoTH box

hallow torrent
#

ok

hallow torrent
#

starts in 5

lapis arch
#

IM IN

hallow torrent
#

ok\

lapis arch
#

good luck!

steel tiger
#

why is it timer of my teammate increasing while my username is in king.txt

hallow torrent
#

vim's exception for editing in a remote shell??

steel tiger
#

sh-4.2# cat king.txt
powershot

lapis arch
#

gg well played everyone

astral mountain
#

well played

#

time to sleep

hallow torrent
#

starts in 2

hallow torrent
nova tide
#

why is it timer of my teammate increasing while my username is in king.txt
@steel tiger check <machine ip>:9999 on browser. Whoever have their name on that will be getting points. And make sure king file you are writing is /root/king.txt

low mango
#

Hey there

patent forge
#

@low mango sorry, i left, don't know how to work on windows machines..

low mango
#

@patent forge It's okay. Basically the same enumeration of ports and smb.

low mango
#

@patent forge gg

tame veldt
#

What's the deal with the offlinetv koth...I can't seem to get more than two flags..can anyone help?

fringe timber
#

is there a way I can spectate a koth when i am a beginner or do I have to be intermediate ?

tame veldt
#

Anyone up for koth?

#

Starts in 8

stark fox
#

Japanese baburao
What an incredible combo
You have my respect

thin fox
thin fox
#

somenone join me pls

tame veldt
#

@stark fox 🙏🙏

#

Wanna join koth?

astral mountain
#

Hi, in koth what happen if two people login as root. How to make the other logout?

stiff egret
#

You kill their process ID.

astral mountain
#

How to know if I don't accidentally kill my ssh process id?

stiff egret
#

You make sure it's not your PID that you kill. 🤷‍♂️

astral mountain
#

So I might kill myself

stiff egret
#

tty use this command to see your tty, and don't kill the PID corresponding to that TTY.

astral mountain
#

alright, alright. that's new for me. Thanks a lot.

stiff egret
#

:)

summer dust
#

Add your TryHackMe username to /root/king.txt
Are you supposed to replace the username by yours or append it?

astral mountain
#

replace

stiff egret
#

Appending doesn't work. The king service only reads one line and it needs to be an exact match of your username.

vagrant ingot
#

never done koth before, total beginer, would I be too out of my depth trying it?

stiff egret
#

Um check out pins. 😁

vagrant ingot
#

ah, thanks 😄

hallow torrent
hallow torrent
#

5 min

fair adder
#

are they planning to add new boxes anytime soon?

runic quail
fair adder
#

Its been like 4 months at least without a new box

stiff egret
#

Yes, but IIRC, there are some boxes about to be launched. Soon ™️

fair adder
#

Guess its better than HTB. Seems like their KOTH is never coming out...

full grove
#

Cryillic has a new machine in dev afaik

#

its been on hold due to networks iirc

tacit siren
nova tide
#

Hello fellow with same name

stiff egret
#

LMAO what's going on with these changemes

hazy zodiac
#

Guess its better than HTB. Seems like their KOTH is never coming out...
@fair adder they are doing a thing like KoTH the name is HGB (hacking battle grounds)

potent oyster
hollow canyon
#

lol i feel so accomplished getting root on a ez room

nova tide
#

GG's

hasty quest
#

how can devloped tryhack room

stiff egret
#

There are videos on that, by Dark and John Hammond. Search YT.

hallow torrent
stiff egret
#

ooooooooof 17 minutes, I'll forget that I joined by then facepalm

potent oyster
tame veldt
#

Starts in 17

#

Anyone up for a game?

fickle hare
#

I am

stiff egret
#

started already?

fickle hare
#

nope

#

its been expired

stiff egret
#

No, It's up and running, I just joined.

fickle hare
#

wtf

#

xd

#

oh wait

#

Only intermediate and advanced experienced leveled users can play King of the Hill.

#

f

#

how do i become an intermediate

west heath
#

change that setting in your profile

stiff egret
#

(IF you know how to play, then you can just edit in settings.)

#

But that said, it is really for intermediate and advance level players, You'll have a hard time playing if you don't know it.

fickle hare
#

yeah. I just want to learn koth. I have never played it

stiff egret
#

Ah, then you should check pins on this channel. :)

fickle hare
#

yeah alright

#

But i've completed multiple rooms

#

but idk

#

¯_(ツ)_/¯

stiff egret
#

¯_(ツ)_/¯

fair adder
#

Hey I'm in that room! It's a tough one.

#

Kudos to whoever is killing it in there right now.

fickle hare
#

lol

stiff egret
#

What's your username?

#

@fair adder

fair adder
#

ca3rus

stiff egret
#

Oh got it.

fickle hare
#

why did it say holmes before on 10.10.174.177:9999? lmao

stiff egret
#

That is the port king service runs on

#

It tells the website who is king rn.

#

It reads from king.txt

#

Whoever that was, broke the king.txt

#

GG

tame veldt
#

When I have root access why cant I edit king file?

stiff egret
#

Because it is immutable. Read about chattr binary

tame veldt
#

How to undo that?

stiff egret
#

Because it is immutable. Read about chattr binary
@stiff egret ^^^ read

#

Usually, its, chattr -i filename

tame veldt
#

Which chattr does not give any response

stiff egret
#

Because it's not there/

tame veldt
#

It seemed to work for a second and then again the other guy was king

stiff egret
#

¯_(ツ)_/¯

tame veldt
#

😅

#

Sorry for being noob

stiff egret
#

ay, we are all here to learn. ❣️

tame veldt
#

Thanks for supporting 🥰❤️

stiff egret
#

lostayush is this guy here?

tame veldt
#

That's my brother..😅

stiff egret
#

He is playing good, really good. :)

tame veldt
#

He has some writeup for koth

#

That's why

stiff egret
#

github?

tame veldt
#

Yeah

#

He offered me too

#

But I declined

#

😅

stiff egret
#

ah

quiet schooner
#

github?
@stiff egret I wonder whose those are...

stiff egret