#koth

1 messages · Page 41 of 1

stiff egret
#

I wonder too..

tame veldt
#

Btw is there any other way to get a shell?

#

Is that Holmes guy the same?

#

Coz his tty session doesn't show up> Btw is there any other way to get a shell?
@tame veldt

stiff egret
#

Yeah. most probably

#

also, I haven't patched any passwords yet/

fair adder
tame veldt
#

Omg no wonder the writeup ain't helping anymore😂

stiff egret
#

Whoever you are, you are breaking the king file.

tame veldt
#

King changed again

fickle hare
#

does anyone wanna voice chat?

stiff egret
#

eh, broken mic, sed

fickle hare
#

f

#

anyone else? ca3rus

fair adder
#

Can't today. Wife has meetings and we're both WFH right now.

fickle hare
#

btw, what was the original password to the ssh and how did you come across it?

#

rip

tame veldt
#

Is that Holmes guy here?

#

Telnet gave you pass

#

In Caesar cipher

#

Or smth like that

fickle hare
#

huh? hahahaha

#

Telnet

#

wtf

stiff egret
#

LMAO

fickle hare
#

XD

stiff egret
fickle hare
#

hahahahha

#

bruh, dis sh!t not fair

tame veldt
#

Wow

#

How you make it unchangeable bro..can you teach me?

stiff egret
#

you can just read about chattr binary.

#

It's used to make files immutable.

#

Usually, whoever uses it, deletes the binary from the system.

west heath
#

||Does every room send out the wall message about "cheesing" when using chattr?||

stiff egret
#

||Ah. no, IIRC, its only production room.||

west heath
#

||lol, first time using yesterday and I got that warning||

stiff egret
#

LMAO, Its more of a kick from machine than a warning

fickle hare
#

hey, whats the best nmap search to do when you first get the machine ip?

stiff egret
#
  1. there's this tool by one of our mods(bee), rustscan, It's just too fast. Try using that.
fickle hare
#

oooh cool

stiff egret
#

TBH, That tool is legendary.

tame veldt
#

Usually, whoever uses it, deletes the binary from the system.
@stiff egret oooo....

stiff egret
#

I mean, port 22 shows up almost right on the second when you click on enter. (if you use rustscan)

#

@stiff egret oooo....
@tame veldt um, they mostly move it out of PATH. so they can use it later/

fickle hare
stiff egret
#

shi* fast is the word I would use.

tame veldt
#

@tame veldt um, they mostly move it out of PATH. so they can use it later/
@stiff egret then how to find the binary?

fickle hare
#

wait im braindead

#

what was the line to install from github

stiff egret
#

You can't, you can upload your own chattr binary

#

ah, @fickle hare use the pre compiled binary

#

it's way easier that way..

fickle hare
#

wait

#

i gotta download the files?

tame veldt
#

Ohhh..thank for the information...🥰

fickle hare
#

like click on it

stiff egret
#

huh?

fickle hare
#

¯_(ツ)_/¯

stiff egret
#

wdym?

fickle hare
#

idfk

fickle hare
#

Download the .deb file from the releases page:

run the command dpkg -i on the file

stiff egret
#

ah, not that.

fickle hare
#

then what

#

2 min 😬

stiff egret
fickle hare
#

i download that?

stiff egret
#

Yes, and chmod +x rustscan

#

that should do ¯_(ツ)_/¯

tame veldt
#

You are a legend man...> Yes, and chmod +x rustscan
@stiff egret

fickle hare
#

alright

stiff egret
#

umm.. no

fickle hare
#

but when i run it, i get no feedback

stiff egret
#

johnsmile <-- this is a legend (imo)

#

This is what you should be getting.

fickle hare
#

i dont

tame veldt
#

:johnsmile: <-- this is a legend
@stiff egret is that Mr John Hammond?

stiff egret
#

Yeah

fickle hare
#

u supposed to use mysql on this?

stiff egret
#

🤷‍♂️ beeeeeeeeeee help

fickle hare
#

¯_(ツ)_/¯

stiff egret
#

I am not gunna tag a mod

fickle hare
stiff egret
#

A rumour is bee banned someone named elf when they tagged.

tame veldt
#

Is everyone here this old?> Can't today. Wife has meetings and we're both WFH right now.
@fair adder

#

No offense dude ...just curious

stiff egret
#

**!**me

fair adder
#

lolol

wary jolt
#

u supposed to use mysql on this?
@fickle hare the github repo has a guide how to compile it.

tame veldt
#

Am I the only one that is 20 here??

stiff egret
#

Same. :)

barren stream
#

wassup

tame veldt
#

Then you're totally a legend man...I don't know shit about these things..😅

wary jolt
#

Im 16 NotLikeThis

stiff egret
#

@fickle hare here you have the CREATOR (bee)

barren stream
#

yes

#

hello

tame veldt
#

Im 16 NotLikeThis
@wary jolt omg

fickle hare
#

hello

wary jolt
#

Ask away while bee is here

fickle hare
#

creator of mysql or rustscan

stiff egret
#

advantages of having the tool creator in same server

barren stream
#

rustscan

#

i mean

#

mysql

fickle hare
#

xd

barren stream
#

i dont write bad software

stiff egret
#

lmao

barren stream
#

so thats not me

stiff egret
wary jolt
flint cloud
fickle hare
#

aight, imma not getting any output when writing chmod +x rustscan

tame veldt
#

Ask away while bee is here
@wary jolt So mr/ms bee can you give some pro tips..😅

barren stream
#

yup thats normal behaviour of chmod

flint cloud
#

Peter Griffins here to explain the joke

stiff egret
#

I mean, port 22 shows up almost right on the second when you click on enter. (if you use rustscan)
@stiff egret this is true

barren stream
#

StegKracken on  cpp [$!] 
➜ chmod +x a.out        

StegKracken on  cpp [$!] 
➜ ```
wary jolt
#

@wary jolt So mr/ms bee can you give some pro tips..😅
@tame veldt on what? I aint no pro XDD

barren stream
#

@wary jolt So mr/ms bee can you give some pro tips..😅
@tame veldt on what?

tame veldt
#

Hacking stuff as a whole..😅..I'm kinda super new to this stuff

flint cloud
#

@wary jolt So mr/ms bee can you give some pro tips..😅
@tame veldt so you asked the other person and mentioned the other

tame veldt
#

Sorry 😅

fickle hare
barren stream
#

yup thats normal behaviour

stiff egret
#

./ ?

barren stream
#

yup

wary jolt
#

Hacking is a broad topic

barren stream
#

mr holmes is right 🙂

#

Hacking stuff as a whole..😅..I'm kinda super new to this stuff
@tame veldt tryhackme.com is pretty good i've heard

wary jolt
#

./rustscan

stiff egret
#

@tame veldt tryhackme.com is pretty good i've heard
@barren stream i've heard that too

fickle hare
stiff egret
#

what a coincidence

barren stream
#

if you're using the pre-compiled version of RustScan on Linux, and you chmod +x rustscan you have to run the file with ./rustscan

wary jolt
#

I just experienced it so I can vouch for THM

barren stream
#

Is that the same directory as the RustScan binary is in?

#

I would use the .deb installer personally

fickle hare
#

eeeeeeeeeeeeeeeee

#

ops

barren stream
#

The Linux binary is because James bullied me into making it....

fickle hare
barren stream
#

if you use the binary you'd have to alias it to that exact location

#

hahaha yesss

#

🥳

stiff egret
#

I dunno it (deb) crashed on me, I don't remember the error but it did i swear (kali linux)

fickle hare
#

🥳

wary jolt
#

Add it now to /usr/bin or somewhere thats in the path

barren stream
#

I dunno it (deb) crashed on me, I don't remember the error but it did i swear (kali linux)
@stiff egret ehhh i cant test on deb, and our docker tests are passing 😉 so to me it works 😉 😜

wary jolt
#

So you can call it

tame veldt
#

@tame veldt tryhackme.com is pretty good i've heard
@barren stream So are there some specific rooms to go through?

stiff egret
#

it works on my system

#

LMAO

barren stream
#

@barren stream So are there some specific rooms to go through?
@tame veldt There's paths on tryhackme that guide you through it 🙂

tame veldt
#

I mean in a specific order*

barren stream
#

do the begginger path

#

ah

#

you're not subbed

#

1 sec

tame veldt
#

@tame veldt There's paths on tryhackme that guide you through it 🙂
@barren stream I'm kinda short on money atm..😅😂

barren stream
flint cloud
#

I made the docker image work by giving it net admin privileges and configuring openvpn inside the image kekw

barren stream
#

free path for ya

#

I made STEGOsaurus don't do it

tame veldt
#

Thanks dude...you guys truly are amazing and super helpful

wary jolt
#

VulnUniversity is a good room to start with

tame veldt
#

🥰🥰

stiff egret
fickle hare
#

wtf. i ran rustscan, got a port, then searched it and its food

#

oh wait, the machine we're hacking is food 🤦‍♂️

wary jolt
stiff egret
#

the machine name is below the IP I think or the counter

flint cloud
#

Nitro flex holmes

fickle hare
#

yeah

stiff egret
#

johnsmile I KNOW! @flint cloud

flint cloud
stiff egret
#

I told naughty that once I get this nitro, I'll spam him everyday

#

Lemme grab the ss

#

LMAO

flint cloud
stiff egret
#

(I mean he flexed so... )

fickle hare
#

but now im stuck. I have pic of food. I have port 22(ssh). and a twisted brain

stiff egret
#

but now im stuck. I have pic of food. I have port 22(ssh). and a twisted brain
@fickle hare very dangerous combination

wary jolt
stiff egret
#

!dark

pearl gladeBOT
#
DarkStar7471
*sigh* What do you want.
fickle hare
#

what now xd

wary jolt
#

Enumerate more

stiff egret
#

um, the game ended....

wary jolt
stiff egret
#

about 20 minutes ago...

fickle hare
#

its another game lol

stiff egret
#

wai- what IP you scanning

fickle hare
#

43 min left

stiff egret
#

OH LOL

fickle hare
#

XD

stiff egret
#

uh uh, my bad I asked for IP, Don't leak it here

wary jolt
#

Ah delete delete

fickle hare
#

nothing to see here

wary jolt
stiff egret
#

I am john snowv2, I saw nothing

fickle hare
#

but

#

how

#

why

#

where

stiff egret
wary jolt
#

Dont leak the room IP unless you wanted to be trolled

fickle hare
#

XD

#

well imma not win anyways

wary jolt
#

Its part of the game

#

But be sure to improve

fickle hare
#

1 flag has been found

#

thats it lmao

stiff egret
#

The game doesn't end there

fickle hare
#

yeah yeah ik

#

but i dont know how to proceed

stiff egret
#

imo, you should always go for root first

#

if you are root, you can get other flags in a matter of seconds.

wary jolt
#

Proper enumeration and google-fu is the key

fickle hare
#

if imma ssh into that machine, is all i need to write ssh *UnknownIPThatHasNotBeenPostedHere*?

wary jolt
#

Ssh user@ip

stiff egret
#

and add a -i id_rsa if you have rsa keys

fickle hare
#
  1. is the user the thm machine?
#
  1. wtf is rsa key
stiff egret
#

user is the name of user you are logging in as

#

depends on machine

wary jolt
#

User is the user you wanted to access in the machine through ssh.

fickle hare
#

bruh

#

how do i know that

wary jolt
#

Enumeration

#

XD

fickle hare
#

idfk what that means

#

XD

stiff egret
#

I was literally typing that @wary jolt

fickle hare
#

my brain has failures

#

errors

#

h e l p

stiff egret
#

You should watch John's or optional's YT

wary jolt
#

Do more THM rooms and come back to koth

stiff egret
#

that'll give you an idea of it

fickle hare
#

ive watched johns and hes a bloody god

#

he is speed

stiff egret
fickle hare
#

my mind is too slow to process

#

yeah yeah

#

ik

stiff egret
#

speed 0.25x

fickle hare
#

speed 0.01x

#

^

tame veldt
#

speed 0.01x
@fickle hare same bro..😝

fickle hare
#

could you perhaps give me a clue (not enumeration please, i will litteraly shut down my computer and cry)

stiff egret
#

umm, there's a public GitHub... which is technically a cheat sheet of KoTH boxes...

wary jolt
#

If you want to practice that room, you can access it in rooms.

stiff egret
#

umm, there's a public GitHub... which is technically a cheat sheet of KoTH boxes...
@stiff egret Avoid that if you can, it's a spoiler of all machines

tame veldt
#

Which distro you use @stiff egret

stiff egret
#

Which distro you use @stiff egret
@tame veldt ^^^^^

#

What is your guess?

tame veldt
#

Arch ?😅

stiff egret
#

kekw yeah

wary jolt
tame veldt
stiff egret
#

No one got root yet.

#

Starting in 2 minutes

fair adder
#

I stepped into a room to practice some stuff I didn't understand. Back now!

stiff egret
#

:) It's still 45 mins to end, you can join in.!

#

Oh, you are already in the room

fair adder
#

In now. As soon as my terminal reboots. It was a bit messy after the room.

stiff egret
#

noice

tame veldt
#

linpeas takes a long time to run?..or is it just for me?

stiff egret
#

what do you mean by long time?

#

um, It's a long code, gives out a lot of stuff 🤷‍♂️

tame veldt
#

It's been stuck for like 3-4 minutes

stiff egret
#

oh you killed it

tame veldt
#

How?..I don't understand..

stiff egret
#

never mind, I was able to see your ./linp running, but then it disappeared, so I said, 'you killed it'

tame veldt
#

Ohh..

#

I tried killing your processes but u were already root😅

stiff egret
#

Which process?

tame veldt
#

Tty

stiff egret
#

yeah, which tty? I mean.

#

nvm

fair adder
#

I bogged my machine down trying to play catch-up anidab

stiff egret
tame veldt
#

Tty process 0 and 1

#

nvm
@stiff egret I don't totally understand what you're asking..😅

stiff egret
#

0 isn't mine

tame veldt
#

Ohh

stiff egret
#

oh nvm= short for nevermind :)

tame veldt
#

😅😅sorry again...

#

I don't know a lot of stuff

#

😅😂

stiff egret
#

Yeah NP,

#

Tty process 0 and 1
@tame veldt ||tty 0 is actually a method to privesc in this machine ||

tame veldt
#

Ohhh...

#

I'm no more playing...have assignments to do😅

stiff egret
#

oh. OK johnsmile

fickle hare
#

is it a total of 1 hour the game runs?

stiff egret
#

yeah

fickle hare
#

damn

tacit siren
#

anyone up ?

brittle flicker
#

Did I miss Koth again? I keep missing him!!!

#

!honk

pearl gladeBOT
#
TryHackMe
***HONK HONK HONK***
brittle flicker
#

PLEASE PING ME WHEN KOTH COMES BACK, I'VE NEVER MET HIM!!!!!

tacit siren
#

11 mins to go

brittle flicker
#

;-; Koth sounds like such a cool guy

tacit siren
#

Yeah actually..its sounds like a wwe wrestler 😛

stiff egret
tacit siren
west heath
#

Just to be clear on the rules, it is ok to patch vulnerabilities in the game, correct?

stiff egret
#

Yeah..

#

Thats the purpose of it.

west heath
#

Ok, just didn't want to be seen as an ass for doing so

stiff egret
west heath
#

attack and defend, got it!

fickle hare
#

James

#

u too good

#

wtf

#

cant even ssh into it without u changing the pass

#

wait

stiff egret
#

Um, Patching is the aim, but to keep the game interesting and possible, you should really not patch everything...

west heath
#

haha, I left the other accounts alone

#

Also, I think the resets change the password for the user every time @fickle hare you need to redo the steps to get the creds again

stiff egret
#

Which box is it?

west heath
#

||Fortune||

fickle hare
#

yeah ik

stiff egret
#

ah kekw

fickle hare
left kraken
flint oriole
#

@left kraken Hi

left kraken
#

@flint oriole hello

zealous saddle
#

Anyone want to play koth soon?

left kraken
#

yea im here

#

just pm me

flint oriole
#

we're in the same koth and wanted to say hi.

#

🤠

left kraken
#

@flint oriole yea, i saw that, also we're in the same country

#

you can enter into the voice channel

flint oriole
#

I mean probabil ca da.

steel hornet
#

Are you here @wheat ravine @delicate blaze

delicate blaze
#

Hello

wheat ravine
#

hey

steel hornet
#

Will you enter koth?

wheat ravine
#

m very new to attack defence wana play one

steel hornet
#

Do you want play? @delicate blaze

delicate blaze
#

Yes

#

Is my first time, I'm not sure how

steel hornet
#

Like solve ctf

wheat ravine
#

are u in ??/

#

who is jondoe

steel hornet
#

Nope

#

Why did you get out channel bro

wheat ravine
#

lets make a private n there will play

steel hornet
#

my subscription is over :"(

delicate blaze
#

@steel hornet @wheat ravine Let's do it, I'll learn something new

#

my subscription is over :"(
@steel hornet I don't have a subscription

stiff egret
#

You can make private rooms without subscription.

#

you just can't select which machine to launch.

wheat ravine
#

join this room

steel hornet
#

My virtual computer has been deleted. Sorry if I join the next hand, will it be a problem?

#

I need to install again

wheat ravine
#

from ur system??? or what

flint oriole
#

Hmm.

lusty ginkgo
#

cant find anyone to KOTH with

nova tide
#

👀

flint cloud
flint oriole
#

👀

flint cloud
#

👀

stiff egret
#

cultholmes playing KoTH johncool

flint cloud
#

Man I am leaving the game

stiff egret
#

Wha-?

flint cloud
#

🤣

stiff egret
#

I won't patch!
Promise!

flint cloud
#

Yea aight

stiff egret
#

is the machine slow, or just me?

terse willow
#

@stiff egret I dunno, are you slow?

stiff egret
#

m growing old. sighs

wheat ravine
#

anybody up for koth

#

??

stiff egret
#

count me in.

wheat ravine
#

gonna play private or public??

stiff egret
#

public?

wheat ravine
stiff egret
#

Joined. :)

hallow torrent
stiff egret
#

👀

wheat ravine
#

i give up maan

stiff egret
#

ayy we are here to learn ❤️

fair adder
tame veldt
#

Anyone up for a koth?

fickle hare
#

yeah 🙂

#

are there any flags outside of the machine user? if u understand me

tame veldt
#

Gobuster might give some flags..

#

If the machine supports http that is..

#

Gobuster might give some flags..
@tame veldt flag locations*

fickle hare
#

alright thx

tame veldt
#

😀

fickle hare
#

😎

west heath
#

Is it cool if I join? I promise I won't be as cocky today

fickle hare
#

Lmao

#

I mean, it's fine for me

tame veldt
#

👍👍> Is it cool if I join? I promise I won't be as cocky today
@west heath

fickle hare
#

Bro, this machine hard

#

no points

west heath
#

I've got samba, but the creds I found don't work anywhere

fickle hare
#

rip

stiff egret
#

Which box is it?

fickle hare
#

my metasploit exploit isnt working :((

#

offline

stiff egret
#

oooooooooooooooooooooooooof

fickle hare
#

yeahhh

west heath
#

windows is not my strong point

fickle hare
#

^

stiff egret
#

my comments on this machine are restricted because of PG13 of this channel

fickle hare
#

lmao

west heath
#

ha

fickle hare
#

like wtf

#

these many ports

west heath
#

not even the backdoor works

fickle hare
#

rip

#

there are even more ports than i listed

#

:((

west heath
#

yes, but it does not connect

tame veldt
#

my comments on this machine are restricted because of PG13 of this channel
@stiff egret 😂

fickle hare
#

oh wtf. u got 2 flags

#

like boom

tame veldt
#

Yeah I had shell

#

Was trying privesc

#

Any hints on how to privesc?

#

@stiff egret

fickle hare
stiff egret
#

which machine?

fickle hare
#

offline

tame veldt
#

Yeah..

stiff egret
#

um... the machine is actually very easy.. and a very common vulnerability .

tame veldt
#

I'm new to winpeas so maybe I missed sth

stiff egret
#

It'll be a spoiler.

west heath
#

it is taking eternity to exploit ** wink

stiff egret
#

true 😉

tame veldt
#

It'll be a spoiler.
@stiff egret Then don't..😀

stiff egret
#

it is taking eternity to exploit ** wink
@west heath Couldn't have put it better myself. @tame veldt that's a hint ^^^

tame veldt
#

Ahhh..I think I get it now

west heath
#

I've run it 5 times already with nothing

tame veldt
#

Exploit completed but no session was created😭

fickle hare
#

f

visual pelican
#

Do anybody know how to pass space jam box

tame veldt
#

Terminator crashed just like my brain 🤯

west heath
#

@visual pelican try using the room-help room - nevermind, just realized it is part of koth.

IGNORE ME

visual pelican
#

It seems impossible

#

It is not a room it's for koth

west heath
#

good job @tame veldt

stiff egret
#

It seems impossible
@visual pelican space jam is one of the easiest ones.

visual pelican
#

what

#

i checked everything

#

dirs

#

ports

#

all of them are empty

stiff egret
#

Um, you have a shell or still tryin to find foothold?

visual pelican
#

yeah still searchin'

stiff egret
#

weird then, because you cannot miss that port..

visual pelican
#

but i checked every single thing

#

telnet ssh http 9999 3000

stiff egret
#

um, don't post that/

#

that's a spoiler

visual pelican
#

ah sorry

stiff egret
#

um. As I said before, I can post but that'll be a spoiler.
so, try harder

#

Enumerate each port

visual pelican
#

The problem is

#

all my team mates

#

are stucked

#

i guess we have to reset it tho

stiff egret
#

Is someone king already?

visual pelican
#

no

#

we didn't even get a shell

stiff egret
#

¯_(ツ)_/¯

#

check every port.

primal ether
#

interesting

#

however it's hard because I need to use ASCII character since I don't have that symbol in my keyboard

#

It's frustrating

latent quest
#

@nova tide I'm planning to be on in about an hour and a half.

nova tide
#

i'm awake for that

#

it's 03:49am and waiting for you

latent quest
nova tide
#

just ordered some food.. will be here just let me know when it's about to start

latent quest
#

Alrighty.

Maybe your sleep deprivation can give me an edge. 🤔

latent quest
#

@nova tide Getting started.

#

@grand ember Maybe you want to join KOTH?

grand ember
#

when 👀

#

cuuuuz i'm in the middle of a box rn kekw

latent quest
#

Game starting in 15 minutes?

#

You can handle two at once right?

grand ember
#

lmao

mint cargo
#

@nova tide why are u playing koth at 6AM

nova tide
#

idk

mint cargo
#

lmao

#

nightwolf is streaming lmao

vocal shell
#

what's his stream

mint cargo
#

oops wrong msg

vocal shell
#

aww he ended

#

ope i js checked now 😮

#

that's why lol my bad

stiff egret
#

@nova tide you didn't tell me 😞

tame veldt
#

Can any one tell me where I can get chattr binary..I've been looking for it on Google with no success

#

I want to keep a copy for myself

stiff egret
#

@tame veldt

tame veldt
#

Thanx🙏

stiff egret
#

:))

vocal shell
#

wait are those safe @stiff egret ? how can i know/check? md5? sha?

stiff egret
#

It's busybox's official.

#

You can always compile your own.

#

🤷‍♂️

vocal shell
#

okay can i dm you a private question

#

like pertaining to binaries in linux

stiff egret
#

sure, shoot :)

#

22 minutes. Public game

low mango
#

Oh nice

stiff egret
#

M doing some work atm, KoTH keeps me awake kekw

low mango
#

Good luck @stiff egret

stiff egret
#

You too!

low mango
#

Chattr removed?

stiff egret
#

ofc.

#

¯_(ツ)_/¯

low mango
stiff egret
#

Alright

#

restored

#

@low mango chattr is in place

low mango
#

haha

#

where is chmod?oof

stiff egret
#

void

low mango
#

oof

stiff egret
#

but whatever I did can be undone, I made sure there is atleast one method to do that.

#

and chmod isn't the only thing that can make files executable

low mango
#

What about backdoors?

stiff egret
#

what about them?

low mango
#

on 61432 and 3000 ports

#

You will fix them?

stiff egret
#

I haven't patched them 🤷‍♂️

#

no fun with a 100% patched box

#

lostayush is here?

low mango
#

idk

stiff egret
#

echo "stop catting urandom to innocent players -holmes" > /dev/pts/3

#

lmao

low mango
#

You turned my strategy against meyell_cat

stiff egret
#

🤣

#

wait, what was your strategy?

low mango
#

cat /dev/random

stiff egret
#

Oh that was you ?

#

I thought it was the other guy

#

I call them urandom missiles. 😉

#

It's fun, playing with this guy, lostayush, he just doesn't give up!

low mango
#

yea

stiff egret
#

ah, he is breaking the king file

#

adding his name in it.

#

I have to kill you now lostayush

#

I am sorry for that.

boreal flare
#

It's fun, playing with this guy, lostayush, he just doesn't give up!
@stiff egret thanks man...it means so much to me hearing from you

stiff egret
#

Ah we found lostayush!

#

@low mango

#

I had to spam on terminals

#

LMAO

boreal flare
#

helloo...!skidy

#

i was spamming you the whole time

low mango
#

hi dude

stiff egret
#

@stiff egret thanks man...it means so much to me hearing from you
@boreal flare ayyy you were good, others just give up

#

i was spamming you the whole time
@boreal flare didn't receive a single msg

boreal flare
#

thanks dude..

gusty cradle
boreal flare
#

you were at dev/pts/0 right?

#

or pts/3

#

i sent messages to both of them

stiff egret
#

Nope, I got no pts kekw

#

laf3r here must be getting them

#

he was on 0 I think.

boreal flare
#

maybe...

#

i killed that several times😆

stiff egret
#

Wanna play again?

boreal flare
#

sure

low mango
#

Yes, let's do it

boreal flare
#

just plz dont make it public the waiting time's...way too much

low mango
#

he was on 0 I think.
@stiff egret Thats is true

stiff egret
#

um, If we all join at the same moment, I think It'll be 5 minutes

boreal flare
#

ohhk..that works

stiff egret
#

Join, 3 players already in game

boreal flare
#

i'm in

stiff egret
boreal flare
#

can i ask..why do u prefer arch ?

stiff egret
#

It's just personal preference, I like the AUR. Plus been using it so long that can't think of switching.
Package installation is just too good in arch than others.
again personal preference

#

Tho I am playing on Kali VM

boreal flare
#

ohh..

stiff egret
#

Base OS is Arch, koth is in kali VM

boreal flare
#

Speaking honestly i am new to linux and pwn and everything i use your writeups to get into the machine...😆
So dont expect much from me

stiff egret
#

Tho you were defending well.

boreal flare
#

thats a little trick i learnt from THE John

#

from his videos

stiff egret
#

Ah,

#

Well here to learn ❤️

low mango
#

One minute left, get ready guys

boreal flare
#

Same man..🥰

stiff egret
#

chattr blown already?

boreal flare
#

wth where is chmod 😆

stiff egret
#

I was watching that exp

#

I knew this msg was coming

#

there are other methods to make a file executable. 😉

boreal flare
#

😆 😆

stiff egret
#

what is that btw

#

I am looking through strings, And I have not seen this one before

low mango
#

Maybe it's some kind of kernel exploit?

stiff egret
#

Ah, I forgot

#

LMAO

#

Its that exploit.

boreal flare
#

its from ur giude xD

stiff egret
#

Yeah realized that, that's why the size was too big.

boreal flare
#

still lokkin for ways to make it excecutableoof

low mango
#

@boreal flare this is chmod

boreal flare
#

wth ssh down as well?

low mango
#

no, ssh it works

boreal flare
stiff egret
#

ah, its too 1337 for users. 😉

low mango
#

@boreal flare add -p 1337

boreal flare
#

oops

stiff egret
#

also, how to make a file executable without chmod @boreal flare

low mango
#

looks like chattr deleted again

stiff egret
#

um, chattr was never on the box

low mango
#

okaay

boreal flare
#

can i not execute binaries from other places🧐

low mango
#

chmod recovered

stiff egret
#

If your binary is dynamically linked, you cannot.
Hence upload the binaries that are static.

boreal flare
#

i downloaded it from busy box

#

so i reckon it should be static ?

stiff egret
#

yeah, then you can use it

low mango
#

chattr recovered

#

but to late

boreal flare
#

yeah i transferred it to bin

#

well played mr holmes

low mango
#

@boreal flare @stiff egret gg

boreal flare
#

i wasnt any competition....but i'll try to be next time 🙂

#

gg man

stiff egret
#

@boreal flare @stiff egret gg
@low mango GG. ! :))

#

I was making some tea. Today turned out to be a KoTH day LMAO.

tame veldt
#

Oooohh...I missed a good one

stiff egret
#

Well, I am playing today, ping me if anyone wanna play blobfingerguns

tame veldt
#

Not at the moment..maybe around 8?

stiff egret
#

I'll be around hopefully, 👍

tame veldt
#

🔥

boreal flare
#

@stiff egret Koth?

stiff egret
#

sure

boreal flare
stiff egret
#

13 minutes to goo

fickle hare
#

1 minute

#

woooo

stiff egret
#

LOL I forgot

fickle hare
#

XD

boreal flare
#

how come the loops aren't working now..xD

stiff egret
#

🤣

#

I was away, solving other box. Just saw the screen, pspys

boreal flare
#

😆 😆

boreal flare
#

@stiff egret even after killing your processes why isnt it working ?

stiff egret
#

which process did you kill?

boreal flare
#

your ... folders

stiff egret
#

OK, that was impressive.

#

I was not expecting you to find them

#

How did you do it?

boreal flare
#

find command

#

and pspys

stiff egret
#

ah, which filename I leaked

#

?

#

ah,damn

boreal flare
#

i saw pspys logs

stiff egret
#

should've deleted that pspys when I saw it

boreal flare
#

xD

stiff egret
#

lesson learned

#

LMAO

boreal flare
#

so why cant i edit now?

stiff egret
#

because I had more than one method writing in the file

boreal flare
#

i deleted two of them

#

u had even more?

stiff egret
#

well,

boreal flare
#

😅

#

no more pspys logs to look at..that things been stuck for like 10 mins

stiff egret
#

I did try to destroy its output

#

seemingly it worked

boreal flare
#

can i know how u did it?

stiff egret
#

the pspys?

boreal flare
#

yeah

stiff egret
#

that was easy, cat /dev/urandom > /dev/pts/NUMBER & I checked which tty your script was outputting to, and destoryed that tty

#

the script itself is so heavy that it just lagged and crashed

boreal flare
#

i ran it on 2 terminals

stiff egret
#

HyperThinkRotate well, I only killed one

#

other mustve crashed, the thing is very unstable

boreal flare
#

ooooh

#

starts in 6

#

:HyperThinkRotate: well, I only killed one
@stiff egret i tried downloading your kit

#

but python wasnt there

#

so :sigh

stiff egret
boreal flare
#

no curl no wget -_-

nova tide
#

there are still soo many ways to transfer files/binaries

boreal flare
#

can iget an eg?

stiff egret
#

huh?

#

I didn't remove any of those binaries

#

no curl no wget -_-
@boreal flare are you sure?

#

No. just checked, both are present.

boreal flare
#

blobhuh
how?

stiff egret
#

?

boreal flare
#

have a lookie

stiff egret
#

Ah, that means, the PATH is not configured properly,

#

export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin

#

do that ^ or use absolute paths.

boreal flare
#

you my friend are a lifesaver

stiff egret
boreal flare
#

gg man

#

will come up with something new tom 🙂

stiff egret
#

sure 😄

fallen birch
#

gg

dusty canyon
#

gg

stiff egret
#

I didn't play tho but

#

gg

#

ping me if anyone plays.

fair adder
#

should i boost serrerver?

#

yuhhh

#

epic

#

pog

#

wait people who have nitro can speak messages

stiff egret
#

huh, never tried that..

#

Why are our colors different

fair adder
#

look

fair adder
#

speak messages is only more vulneerable for malicious code man discord got holes in 300 ways

#

@fair adder

quiet schooner
#

...wat

stiff egret
#

Too 1337 for me to understand.

fair adder
#

if you get paid for searching a vulnerbility in discord i would be compition of bill gates right now make billions hahah

stiff egret
#

...

sonic gull
coral sage
vocal shell
#

🙂

#

join meh

serene bay
#

@vocal shell you sent spec link

vocal shell
#

OPE

#

sorry!

#

just click the public game

#

i'm there

serene bay
#

joined

vocal shell
#

6 more minutes maybe it'll speed up if you join idk this is my second koth

#

YAY

#

awesome 😎

#

also I don't know these boxes

#

so don't make fun

#

:[

serene bay
#

haven't played since 1 month

vocal shell
#

good I have a chance 😅

serene bay
#

me noob bro

#

you got every chance

vocal shell
#

ME bigger noob

#

I'm going to struggle

#

don't worry

serene bay
vocal shell
#

SON OF A GUN

serene bay
#

lmao

vocal shell
#

MY NMAP SCAN DIDNT EVEN RETURN

#

aND you gOT KING

serene bay
#

check index.html @vocal shell

vocal shell
#

FIREFOX IS NOT RESPONDING

serene bay
vocal shell
#

I THOUGHT

#

OK

#

Ok

#

I got the id_rsa but

#

you were already king

#

and when i tried using it

#

it didnt owrk

#

so i thought you switched the key

serene bay
#

i didnt patch ssh

#

you can ssh still

slim umbra
#

Check your vpn connection

#

then

vocal shell
#

i hate you @serene bay

#

LOL

serene bay
#

@vocal shell try now

#

have fun me going now @vocal shell

vocal shell
#

are you gone

#

what

#

NOO

chrome blade
#

anyone on?

dusty canyon
#

nope

vocal shell
#

yess im on

#

wanna play?

serene bay
#

you didnt takeover king ?

vocal shell
#

LMAO

#

OMG

#

i echo'd the wrong name

#

I did

#

echo EmperorAugusts

#

instead of EmperorAugustus

serene bay
vocal shell
#

you're not in rught

#

right

boreal flare
#

25 to go

vocal shell
#

im in 😎

vocal shell
#

@serene bay how'd you get root so fast on the box we just did

#

/robots.txt and then found that dir for the id_rsa

#

how'd you priv esc so quickly

serene bay
vocal shell
#

ugh

#

OH OH

#

How'd you do the terminal trick?

#

Dancing ASCII Parrot

#

@serene bay did I kick you out at least once?

serene bay
#

Bashrc

#

You kicked me once but I had backdoor

vocal shell
#

where was it 😏

vocal shell
#

my ssh2john is bugging

#

@boreal flare how da fawk u get in

#

the id_rsa is BUGGIN

#
  File "ssh2john.py", line 208, in <module>
    read_private_key(filename)
  File "ssh2john.py", line 105, in read_private_key
    while (lines[end].strip() != '-----END ' + tag + ' PRIVATE KEY-----') and (end < len(lines)):
IndexError: list index out of range
#

help

stiff egret
#

Goooooood nooooon people!

vocal shell
#

@stiff egret halp

#

idk how to crack the id_rsa

stiff egret
#

which box?

vocal shell
#

Lion 😦

#

i tried RCE

stiff egret
vocal shell
#

didnt work

stiff egret
#

well remove the new line from the end of rsa key

#

and don't use metasploit

#

these should be the morals for life

#

pls pin

boreal flare
#

xD

vocal shell
#

omg dude

#

im so dumb

stiff egret
#

modssssssssssssss

boreal flare
#

@boreal flare how da fawk u get in
@vocal shell i've played it many times

#

good noon mr holmes

stiff egret
#

pls James I know you are watching

#

pin

#

Hey @boreal flare

#

this close to taggin

boreal flare
#

😆

stiff egret
vocal shell
#

wait did id_rsa have NO PASSWORD

#

????

#

that's SO BULLSHIT

boreal flare
#

xD i left it like that

stiff egret
#

did it had private word in it?

#

szyyyyy

grand ember
#

James is probably sleeping

stiff egret
#

tag da mods

grand ember
#

Y

stiff egret
vocal shell
#

@boreal flare did you patch everything

stiff egret
#

these 2 msgs should be pinned

boreal flare
#

i see someone on pts/2

#

@boreal flare did you patch everything
@vocal shell patched nothing

vocal shell
#

did you change id_rsa

grand ember
#

True but that's what I'd call common knowledge

stiff egret
#

wellllllll not shredding hard disks is also common knowledge.....

#

e ...l......f..

vocal shell
#

bro how can i not get gloria's password 😠

boreal flare
#

did you change id_rsa
@vocal shell yeah

vocal shell
#

OHHH

#

wait

#

yeah i got nothing

boreal flare
#

augustus@parrot was it ?🤔

vocal shell
#

nope not me

#

im on kali

#

SIKE

#

im on arch

#

ARCH FTW

#

no but i have no idea what to do now ._.

boreal flare
#

Sorry 😛

vocal shell
#

no i mean

boreal flare
#

should i tell u password for gloria ?

vocal shell
#

NO

#

idk what im doing wrong

#

with this RCE

stiff egret
#

um. there are multiple methods to get in as you know..

vocal shell
#

dont tell me

#

im getting in

stiff egret
#

just deleted my kali vm, recreating with the latest image

#

2020.3 lets go zsh

boreal flare
#

umm... @stiff egret how can i see sessions that others are using

#

except tty

stiff egret
#

w

boreal flare
#

yeah i use that and no one else shows up

#

thats the only way?

stiff egret
#

who

boreal flare
#

thanks

nova tide
#

ps aux | grep pts

stiff egret
#

ssssssssshhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh

vocal shell
#

NO

#

DONT DO THAT

#

NO

#

DONT

#

DO IT

nova tide
#

kill -9 $(tty)

stiff egret
#

Yes,

#

That's a good one

vocal shell
#

STOP

#

DONT

#

TELL HIM

#

im not even on

boreal flare
#

xD...i wont kill

vocal shell
#

im not even on

boreal flare
#

that other guy dropped missiles on me so had to kill him

vocal shell
#

who was that

#

missiles :O?

boreal flare
#

random

#

orpheus

#

ps aux | grep pts
@nova tide thanks for the info man...:)

vocal shell
#

could you see me with that

boreal flare
#

nop

#

nope*

vocal shell
#

really

#

SNEAKY SNEAKY

#

HHAHAHAH

#

you can find me

boreal flare
#

u have to be on the machine for that :P

could you see me with that
@vocal shell

vocal shell
#

like 3 other ways

#

im on alright 🙂

nova tide
#

ps aux | grep bash
Or
ps aux | grep py

vocal shell
#

I GET A FLAG

#

RIGHT AS IT ENDS

#

OK LETS PLAY AGAIN

#

Good game!

boreal flare
#

gg !

vocal shell
#

I LEARNED A LOT

#

by not getting in

#

it's hilarious

#

wait so @boreal flare

#

did you know that i was user alex?

boreal flare
#

can we play after 15 mins?

vocal shell
#

did you see me

#

yeah the next game will prolly boot up by then

boreal flare
#

when ?

did you see me
@vocal shell

vocal shell
#

and i'm going to develop a strategy

#

you didnt?!?!

boreal flare
#

earlier in the game or towards the end

vocal shell
#

near the last 10 minutes

boreal flare
#

and i'm going to develop a strategy
@vocal shell oooh...sounds SPOOKY

vocal shell
#

I KNOW!!!

#

spooky

#

spoooky watch out LOST

#

ima come for you 😎

boreal flare
#

near the last 10 minutes
@vocal shell nope couldnt see you

vocal shell
#

ok good

#

that's really good

#

but it was really easy to find me

stiff egret
boreal flare
#

spoooky watch out LOST
@vocal shell i'm getting scared alright.... xD

vocal shell
#

because i tried to pretend to be you

stiff egret
#

nothing suspicious

#

just normal windows

boreal flare
#

time ?🤔

vocal shell
#

@boreal flare you did the box before 😠