#koth
1 messages · Page 41 of 1
Btw is there any other way to get a shell?
Is that Holmes guy the same?
Coz his tty session doesn't show up> Btw is there any other way to get a shell?
@tame veldt
https://tryhackme.com/games/koth/join/3afe3d8e6ef0de9f59fcba1a
22 minutes until this one start ^
Omg no wonder the writeup ain't helping anymore😂
Sorry dude time to go> https://tryhackme.com/games/koth/join/3afe3d8e6ef0de9f59fcba1a
22 minutes until this one start ^
@fair adder
King changed again
does anyone wanna voice chat?
eh, broken mic, sed
Can't today. Wife has meetings and we're both WFH right now.
LMAO
XD
you can just read about chattr binary.
It's used to make files immutable.
Usually, whoever uses it, deletes the binary from the system.
||Does every room send out the wall message about "cheesing" when using chattr?||
||Ah. no, IIRC, its only production room.||
||lol, first time using yesterday and I got that warning||
LMAO, Its more of a kick from machine than a warning
hey, whats the best nmap search to do when you first get the machine ip?
- there's this tool by one of our mods(bee),
rustscan, It's just too fast. Try using that.
oooh cool
TBH, That tool is legendary.
Usually, whoever uses it, deletes the binary from the system.
@stiff egret oooo....
I mean, port 22 shows up almost right on the second when you click on enter. (if you use rustscan)
@stiff egret oooo....
@tame veldt um, they mostly move it out of PATH. so they can use it later/
XD
shi* fast is the word I would use.
@tame veldt um, they mostly move it out of PATH. so they can use it later/
@stiff egret then how to find the binary?
You can't, you can upload your own chattr binary
ah, @fickle hare use the pre compiled binary
it's way easier that way..
Ohhh..thank for the information...🥰
like click on it
huh?
¯_(ツ)_/¯
wdym?
idfk
Download the .deb file from the releases page:
run the command dpkg -i on the file
ah, not that.
i download that?
You are a legend man...> Yes, and chmod +x rustscan
@stiff egret
alright
umm.. no
but when i run it, i get no feedback
i dont
:johnsmile: <-- this is a legend
@stiff egret is that Mr John Hammond?
Yeah
u supposed to use mysql on this?
🤷♂️ beeeeeeeeeee help
¯_(ツ)_/¯

A rumour is bee banned someone named elf when they tagged.
Is everyone here this old?> Can't today. Wife has meetings and we're both WFH right now.
@fair adder
No offense dude ...just curious
**!**me
lolol
u supposed to use mysql on this?
@fickle hare the github repo has a guide how to compile it.
Am I the only one that is 20 here??
Same. :)
wassup
Then you're totally a legend man...I don't know shit about these things..😅
Im 16 
@fickle hare here you have the CREATOR (bee)
Im 16
@wary jolt omg
Ask away while bee is here
creator of mysql or rustscan
advantages of having the tool creator in same server
xd
i dont write bad software
lmao



aight, imma not getting any output when writing chmod +x rustscan
Ask away while bee is here
@wary jolt So mr/ms bee can you give some pro tips..😅
yup thats normal behaviour of chmod
Peter Griffins here to explain the joke
I mean, port 22 shows up almost right on the second when you click on enter. (if you use rustscan)
@stiff egret this is true
StegKracken on cpp [$!]
➜ chmod +x a.out
StegKracken on cpp [$!]
➜ ```
@wary jolt So mr/ms bee can you give some pro tips..😅
@tame veldt on what? I aint no pro XDD
@wary jolt So mr/ms bee can you give some pro tips..😅
@tame veldt on what?
Hacking stuff as a whole..😅..I'm kinda super new to this stuff
@wary jolt So mr/ms bee can you give some pro tips..😅
@tame veldt so you asked the other person and mentioned the other
Sorry 😅
yup thats normal behaviour
./ ?
yup
Hacking is a broad topic
mr holmes is right 🙂
Hacking stuff as a whole..😅..I'm kinda super new to this stuff
@tame veldt tryhackme.com is pretty good i've heard
./rustscan
@tame veldt tryhackme.com is pretty good i've heard
@barren stream i've heard that too
what a coincidence
if you're using the pre-compiled version of RustScan on Linux, and you chmod +x rustscan you have to run the file with ./rustscan
I just experienced it so I can vouch for THM
Is that the same directory as the RustScan binary is in?
I would use the .deb installer personally
The Linux binary is because James bullied me into making it....
if you use the binary you'd have to alias it to that exact location
hahaha yesss
🥳
I dunno it (deb) crashed on me, I don't remember the error but it did i swear (kali linux)
🥳
Add it now to /usr/bin or somewhere thats in the path
I dunno it (deb) crashed on me, I don't remember the error but it did i swear (kali linux)
@stiff egret ehhh i cant test on deb, and our docker tests are passing 😉 so to me it works 😉 😜
So you can call it
@tame veldt tryhackme.com is pretty good i've heard
@barren stream So are there some specific rooms to go through?
@barren stream So are there some specific rooms to go through?
@tame veldt There's paths on tryhackme that guide you through it 🙂
I mean in a specific order*
@tame veldt There's paths on tryhackme that guide you through it 🙂
@barren stream I'm kinda short on money atm..😅😂
I made the docker image work by giving it net admin privileges and configuring openvpn inside the image 
Thanks dude...you guys truly are amazing and super helpful
VulnUniversity is a good room to start with
🥰🥰

wtf. i ran rustscan, got a port, then searched it and its food
oh wait, the machine we're hacking is food 🤦♂️

Nitro flex holmes
yeah
I KNOW! @flint cloud


I told naughty that once I get this nitro, I'll spam him everyday
Lemme grab the ss
LMAO

(I mean he flexed so... )
but now im stuck. I have pic of food. I have port 22(ssh). and a twisted brain
but now im stuck. I have pic of food. I have port 22(ssh). and a twisted brain
@fickle hare very dangerous combination

!dark
what now xd
Enumerate more
um, the game ended....

about 20 minutes ago...
its another game lol
wai- what IP you scanning
43 min left
OH LOL
XD
uh uh, my bad I asked for IP, Don't leak it here
Ah delete delete
nothing to see here

I am john snowv2, I saw nothing
Dont leak the room IP unless you wanted to be trolled
The game doesn't end there
imo, you should always go for root first
if you are root, you can get other flags in a matter of seconds.
Proper enumeration and google-fu is the key

if imma ssh into that machine, is all i need to write ssh *UnknownIPThatHasNotBeenPostedHere*?
Ssh user@ip
and add a -i id_rsa if you have rsa keys
User is the user you wanted to access in the machine through ssh.
I was literally typing that @wary jolt
You should watch John's or optional's YT
Do more THM rooms and come back to koth
that'll give you an idea of it
could you perhaps give me a clue (not enumeration please, i will litteraly shut down my computer and cry)
umm, there's a public GitHub... which is technically a cheat sheet of KoTH boxes...
If you want to practice that room, you can access it in rooms.
umm, there's a public GitHub... which is technically a cheat sheet of KoTH boxes...
@stiff egret Avoid that if you can, it's a spoiler of all machines
Which distro you use @stiff egret
Arch ?😅
yeah


No one got root yet.
Starting in 2 minutes
I stepped into a room to practice some stuff I didn't understand. Back now!
In now. As soon as my terminal reboots. It was a bit messy after the room.
noice
linpeas takes a long time to run?..or is it just for me?
It's been stuck for like 3-4 minutes
oh you killed it
How?..I don't understand..
never mind, I was able to see your ./linp running, but then it disappeared, so I said, 'you killed it'
Tty
I bogged my machine down trying to play catch-up 

Tty process 0 and 1
nvm
@stiff egret I don't totally understand what you're asking..😅
0 isn't mine
Ohh
oh nvm= short for nevermind :)
Yeah NP,
Tty process 0 and 1
@tame veldt ||tty 0 is actually a method to privesc in this machine ||
oh. OK 
is it a total of 1 hour the game runs?
yeah
damn
anyone up ?
PLEASE PING ME WHEN KOTH COMES BACK, I'VE NEVER MET HIM!!!!!
11 mins to go
;-; Koth sounds like such a cool guy
Yeah actually..its sounds like a wwe wrestler 😛

Just to be clear on the rules, it is ok to patch vulnerabilities in the game, correct?
Ok, just didn't want to be seen as an ass for doing so
attack and defend, got it!
Um, Patching is the aim, but to keep the game interesting and possible, you should really not patch everything...
haha, I left the other accounts alone
Also, I think the resets change the password for the user every time @fickle hare you need to redo the steps to get the creds again
Which box is it?
||Fortune||
yeah ik
ah 

@left kraken Hi
@flint oriole hello
Anyone want to play koth soon?
@flint oriole yea, i saw that, also we're in the same country
you can enter into the voice channel
I mean probabil ca da.
Are you here @wheat ravine @delicate blaze
Hello
hey
Will you enter koth?
m very new to attack defence wana play one
Do you want play? @delicate blaze
Like solve ctf
lets make a private n there will play
my subscription is over :"(
@steel hornet @wheat ravine Let's do it, I'll learn something new
my subscription is over :"(
@steel hornet I don't have a subscription
You can make private rooms without subscription.
you just can't select which machine to launch.
join this room
My virtual computer has been deleted. Sorry if I join the next hand, will it be a problem?
I need to install again
from ur system??? or what
Hmm.
cant find anyone to KOTH with
👀
👀
👀
cultholmes playing KoTH 
Man I am leaving the game
Wha-?
🤣
I won't patch!
Promise!
Yea aight
is the machine slow, or just me?
@stiff egret I dunno, are you slow?
m growing old. sighs
count me in.
gonna play private or public??
public?
Joined. :)
👀
i give up maan
ayy we are here to learn ❤️
Anyone up for a koth?
Gobuster might give some flags..
If the machine supports http that is..
Gobuster might give some flags..
@tame veldt flag locations*
alright thx
😀
😎
Is it cool if I join? I promise I won't be as cocky today
👍👍> Is it cool if I join? I promise I won't be as cocky today
@west heath
I've got samba, but the creds I found don't work anywhere
rip
Which box is it?
oooooooooooooooooooooooooof
yeahhh
windows is not my strong point
^
my comments on this machine are restricted because of PG13 of this channel
lmao
ha
not even the backdoor works
yes, but it does not connect
my comments on this machine are restricted because of PG13 of this channel
@stiff egret 😂

which machine?
offline
Yeah..
um... the machine is actually very easy.. and a very common vulnerability .
I'm new to winpeas so maybe I missed sth
It'll be a spoiler.
it is taking eternity to exploit ** wink
true 😉
It'll be a spoiler.
@stiff egret Then don't..😀
it is taking eternity to exploit ** wink
@west heath Couldn't have put it better myself. @tame veldt that's a hint ^^^
Ahhh..I think I get it now
I've run it 5 times already with nothing
Exploit completed but no session was created😭
f
Do anybody know how to pass space jam box
Terminator crashed just like my brain 🤯
@visual pelican try using the room-help room - nevermind, just realized it is part of koth.
IGNORE ME
good job @tame veldt
It seems impossible
@visual pelican space jam is one of the easiest ones.
Um, you have a shell or still tryin to find foothold?
yeah still searchin'
weird then, because you cannot miss that port..
ah sorry
Is someone king already?
interesting
however it's hard because I need to use ASCII character since I don't have that symbol in my keyboard
It's frustrating
@nova tide I'm planning to be on in about an hour and a half.

just ordered some food.. will be here just let me know when it's about to start
Alrighty.
Maybe your sleep deprivation can give me an edge. 🤔
lmao
@nova tide why are u playing koth at 6AM
idk
what's his stream
@nova tide you didn't tell me 😞
Can any one tell me where I can get chattr binary..I've been looking for it on Google with no success
I want to keep a copy for myself
Thanx🙏
:))
wait are those safe @stiff egret ? how can i know/check? md5? sha?
sure, shoot :)
22 minutes. Public game
Oh nice
Good luck @stiff egret
You too!
Chattr removed?

oof
but whatever I did can be undone, I made sure there is atleast one method to do that.
and chmod isn't the only thing that can make files executable
What about backdoors?
what about them?
idk
You turned my strategy against me
cat /dev/random
Oh that was you ?
I thought it was the other guy
I call them urandom missiles. 😉
It's fun, playing with this guy, lostayush, he just doesn't give up!
yea
ah, he is breaking the king file
adding his name in it.
I have to kill you now lostayush
I am sorry for that.
It's fun, playing with this guy, lostayush, he just doesn't give up!
@stiff egret thanks man...it means so much to me hearing from you
hi dude
@stiff egret thanks man...it means so much to me hearing from you
@boreal flare ayyy you were good, others just give up
i was spamming you the whole time
@boreal flare didn't receive a single msg
thanks dude..

sure
Yes, let's do it
just plz dont make it public the waiting time's...way too much
he was on 0 I think.
@stiff egret Thats is true
um, If we all join at the same moment, I think It'll be 5 minutes
ohhk..that works
Join, 3 players already in game
i'm in

can i ask..why do u prefer arch ?
It's just personal preference, I like the AUR. Plus been using it so long that can't think of switching.
Package installation is just too good in arch than others.
again personal preference
Tho I am playing on Kali VM
ohh..
Base OS is Arch, koth is in kali VM
Speaking honestly i am new to linux and pwn and everything i use your writeups to get into the machine...😆
So dont expect much from me
One minute left, get ready guys
Same man..🥰
wth where is chmod 😆
I was watching that exp
I knew this msg was coming
there are other methods to make a file executable. 😉
😆 😆
Maybe it's some kind of kernel exploit?
its from ur giude xD
Yeah realized that, that's why the size was too big.
still lokkin for ways to make it excecutable
@boreal flare this is chmod
wth ssh down as well?
no, ssh it works
ah, its too 1337 for users. 😉
@boreal flare add -p 1337
oops
also, how to make a file executable without chmod @boreal flare
looks like chattr deleted again
um, chattr was never on the box
okaay
can i not execute binaries from other places🧐
chmod recovered
If your binary is dynamically linked, you cannot.
Hence upload the binaries that are static.
yeah, then you can use it
@boreal flare @stiff egret gg
@boreal flare @stiff egret gg
@low mango GG. ! :))
I was making some tea. Today turned out to be a KoTH day LMAO.
Oooohh...I missed a good one
Well, I am playing today, ping me if anyone wanna play 
Not at the moment..maybe around 8?
I'll be around hopefully, 👍
🔥
@stiff egret Koth?
sure
13 minutes to goo
LOL I forgot
XD
how come the loops aren't working now..xD
😆 😆
@stiff egret even after killing your processes why isnt it working ?
which process did you kill?
your ... folders
i saw pspys logs
should've deleted that pspys when I saw it
xD
so why cant i edit now?
can i know how u did it?
the pspys?
yeah
that was easy, cat /dev/urandom > /dev/pts/NUMBER & I checked which tty your script was outputting to, and destoryed that tty
the script itself is so heavy that it just lagged and crashed
i ran it on 2 terminals
ooooh
starts in 6
:HyperThinkRotate: well, I only killed one
@stiff egret i tried downloading your kit
but python wasnt there
so :sigh
no curl no wget -_-
there are still soo many ways to transfer files/binaries
can iget an eg?
huh?
I didn't remove any of those binaries
no curl no wget -_-
@boreal flare are you sure?
No. just checked, both are present.

how?
?
Ah, that means, the PATH is not configured properly,
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
do that ^ or use absolute paths.
you my friend are a lifesaver

sure 😄
gg
gg
should i boost serrerver?
yuhhh
epic
pog
wait people who have nitro can speak messages
look
speak messages is only more vulneerable for malicious code man discord got holes in 300 ways
@fair adder
...wat
Too 1337 for me to understand.
if you get paid for searching a vulnerbility in discord i would be compition of bill gates right now make billions hahah
...

I mean, https://discord.com/security
🙂
join meh
@vocal shell you sent spec link
joined
6 more minutes maybe it'll speed up if you join idk this is my second koth
YAY
awesome 😎
also I don't know these boxes
so don't make fun
:[
haven't played since 1 month
good I have a chance 😅

SON OF A GUN
lmao
FIREFOX IS NOT RESPONDING

I THOUGHT
OK
Ok
I got the id_rsa but
you were already king
and when i tried using it
it didnt owrk
so i thought you switched the key
anyone on?
nope
you didnt takeover king ?
LMAO
OMG
i echo'd the wrong name
I did
echo EmperorAugusts
instead of EmperorAugustus

25 to go
im in 😎
@serene bay how'd you get root so fast on the box we just did
/robots.txt and then found that dir for the id_rsa
how'd you priv esc so quickly

ugh
OH OH
How'd you do the terminal trick?
Dancing ASCII Parrot
@serene bay did I kick you out at least once?
where was it 😏
my ssh2john is bugging
@boreal flare how da fawk u get in
the id_rsa is BUGGIN
File "ssh2john.py", line 208, in <module>
read_private_key(filename)
File "ssh2john.py", line 105, in read_private_key
while (lines[end].strip() != '-----END ' + tag + ' PRIVATE KEY-----') and (end < len(lines)):
IndexError: list index out of range
help
Goooooood nooooon people!
which box?

well remove the new line from the end of rsa key
and don't use metasploit
these should be the morals for life
pls pin
xD
modssssssssssssss
@boreal flare how da fawk u get in
@vocal shell i've played it many times
good noon mr holmes
😆
xD i left it like that
James is probably sleeping
tag da mods
Y
backme up on this #koth message
@boreal flare did you patch everything
these 2 msgs should be pinned
i see someone on pts/2
@boreal flare did you patch everything
@vocal shell patched nothing
did you change id_rsa
True but that's what I'd call common knowledge
bro how can i not get gloria's password 😠
did you change id_rsa
@vocal shell yeah
augustus@parrot was it ?🤔
nope not me
im on kali
SIKE
im on arch
ARCH FTW
no but i have no idea what to do now ._.
Sorry 😛
no i mean
should i tell u password for gloria ?
um. there are multiple methods to get in as you know..
w
who
thanks
ps aux | grep pts
ssssssssshhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh
kill -9 $(tty)
xD...i wont kill
im not even on
that other guy dropped missiles on me so had to kill him
could you see me with that
u have to be on the machine for that :P
could you see me with that
@vocal shell
ps aux | grep bash
Or
ps aux | grep py
gg !
I LEARNED A LOT
by not getting in
it's hilarious
wait so @boreal flare
did you know that i was user alex?
can we play after 15 mins?
when ?
did you see me
@vocal shell
earlier in the game or towards the end
near the last 10 minutes
and i'm going to develop a strategy
@vocal shell oooh...sounds SPOOKY
near the last 10 minutes
@vocal shell nope couldnt see you
spoooky watch out LOST
@vocal shell i'm getting scared alright.... xD
because i tried to pretend to be you
time ?🤔
@boreal flare you did the box before 😠



