#koth
1 messages ยท Page 42 of 1
you didn't learn anything then ๐
~~kali-undercover ~~
ok will be back in 15
just jokes
kk be safe
https://tryhackme.com/games/koth/9828 the next one (in 23 minutes for anyone who wants to join)
or if you're a subscriber drop a game that'll boot faster :))
People can't join this game, even if they want to. This is a spectate link
how can i fix it
Post the invite link
got it
awww noooo naughty's in the koth ๐
gonna go out with friends to eat something
take care
@vocal shell koth?
ok sure..!
!rank
Someone to play koth?
Post the invite link, I might join :)
Okay
anyone to join ??
starts in 20 minutes
!rank Psi.505
!rank
!rank
Anyone wanna pwn a noob in 30ish mins?
Why everyone is spamming bot commands in #koth but not in #bot-commands ??

can't come up with a witty quote
โOne can never have enough socks.โ -Albus Dumbledore
Headmaster to rescue.
starting in 1 min, join ๐
ggs, did anyone esc from production user?
if anyone wants to join
is it just me
or the ip doesnt work?
nvm
its laggy af for me
now its frozen and i cant ping it
ha dont worry it lagged a bit for me to in the begging
no i mean it works
for 5 minutes
and then it gets frozen
over and over again like that
gg guys
24 min
H
waddup
im down for da koth ๐
Here with you Augustus
Nice :))
gonna give it the college try ha
What's that mean
just try and make some points no guarantees
my vpn isnt connecting ๐
hah good start!
ohh your image is messed up..
dang
thats crazy bud are you in vmware or virtualbox?
damn and I'm stuck over here lol
FIXED IT
nice!
downloading a new vpn
you got this
nice you must have figured how to to turn in that flag
lol
gotta figure out this wp and cant lol
not great lol
wpscan borking
if you wanna stick around after an possibly go over this I'd appericate it
tomcat
how far along are you
basically passwords ruined this for me
which users did you try
for which wp or tomcat?
either
shot you a dm
can someone start a private koth so it can start faster?
public for now
Ok I can't sleep now. Time to play some koth then ๐คทโโ๏ธ
how do i upgrade da shell
what the fawk
@nova tide
i'm like in but i can't upgrade
my shell
i have a user shell
which python3
that should be working
Also i don't remember this being a cronjob.. who added this?? ๐ค
*/1 * * * * /usr/bin/find / -name "chattr" -exec rm -rf {} \;
@stiff egret ^^^
in lion
can't be me ๐
ok wait so why cant i run the kernel exploit
like its in /tmp
someone made a sudoers error
like in syntax
๐คทโโ๏ธ
also try python3 to upgrade your shell instead of /bin/bash ??
gloria
im gloria
Hye gloria i'm Naughty
i did
python3 -c 'import pty;pty.spawn("/bin/bash")'
exactly what i typed just now
try again? ๐ค

WHERE ARE THE SHELLS GOING
you running those from rce?
or from a shell?
shell
do you see gloria@lion on your screen?
yes
then that's you somewhat upgraded shell
python3 -c "import pty;pty.spawn('/bin/bash')"
ctrl+z
stty raw -echo
fg
<enter enter enter>
export TERM=xterm```
sure
i can make any box you want
hackers?
bet
starting in 5 minutes hackers ^^
connection reset
you are using previously saved id_rsa?
how you are trying to ssh in?
just normall
using an old password?
i used the one i bruteforced rn
which user
campbell
it's rcampbell
try to ssh in then?
kk
how come for like ftp
i get permission denied for getting the files
get <file>
idk
how did you get in so fast
you gotta figure out on your own
me and naughty were on this box when it first came out lol thats how
i'm in for like 5 minutes already ๐คทโโ๏ธ
I just dont have my stuff saved so I have to get it all back lmao
looong time @raw bear
I had to upgrade my computer @nova tide so its definitely been a while.. lol I finally got my stuff and now i have an actual VM lol
nice
thats cool lol
i can type in #voice-chat
i hate you
what did you patch @nova tide
i didnt change the root ssh key :/
i should've kicked you out when i was root
but i was scared to see what would happen if i did
you can still do it
there's nothing patched rn
not sure if you could have found me though
i was in like 6-7 minutes before you not sure if patching would do anything ๐คทโโ๏ธ
i think:
which one
i use killall /bin/bash you will be kicked.. so any of those two you are it will kick you out
no
how come
mine is also not a tty
for production
try do it
i cant privesc
because i deleted python ๐ฎ
why would you delete python?? ๐คฆโโ๏ธ
SO OTHERS COULDnT
chmod ??
yeah i should've
i learned
i got root
relativelyfast
like i couldve
kicked you out
i saw you
...
you never kicked me out ๐คทโโ๏ธ
yeah i didnt want to piss you off
because i don't know what tricks you got
yeah i'm going to improve
GL
so you did killall right?
thx
my production machine is gone
but my other rcampbell is still up
coz you said just to kick you out from prod
i can kick from rcampbell as well if you want?
ping me if anyone wants to play more
I have to grind some more before playing KOTH
I'm not at that level yet
@nova tide how'd you root so fast
How come KoTH in morning today @nova tide
@stiff egret ^^^
@nova tide ah, I don't remember this cron being there either...
so just joined koth
Um, not gonna be very useful anyway, people don't store their chattrs with original name ๐คทโโ๏ธ
then i checked the time it was 07:30am
@nova tide LOL
not all the people Lakshman 
@raw bear @vocal shell you guys left?
game?
i joined the game but i didnt want to boot up kali
...
oh that game
yeah
i didnt know how to leave
lol xD
ok how do you get king but not all the flags ._.
you don't need flags after you own king file
Dunno why people don't understand that.
Morning Guys.. ๐
Morning
anyone?
Starts in 20m
I got the same thing @cerulean sparrow
No such file or directory error
Okay so this is pretty bad
sorry
I wonder what the guy did
I can't do anything at all this is amazing
I can do /bin/ls -alh
@cerulean sparrow any luck?
the box reset
we have like 40 more minutes
oh nvm
2 mins
that guy did some thing crazy
what's his username
he made the box unusable lol
@boreal flareayush
oops
not lost sorry i mean @gritty hollow
oh fuck
how many PEOPLE ARE ON HERE
SORRY
xD
yeah
i didnt do anything
i was afk
I wonder if it was SuitGuy messing with everyone ๐
I used this
16109/tcp open unknown syn-ack
port
I found image
download it
I wonder if it was SuitGuy messing with everyone ๐
@vocal shell He's someone from the higher ranks
maybe he was
and steghide extract
yeah so he is extra smart
then found creds for the other ssh
one more?
how wait so 16109 there was a port running
yes one more
is anyone subscribed so it can load faster
yeah that's why they're so good
wanna play private game guys?
join
ok
how'd you do that ๐ฎ
lost ??
yeah
you were the king ?
yeahh
you could do /bin/ls, /bin/cat, /bin/ps
nahh
O.O
how are you even supposed to
I'm stupid
know that
I didn't know that before
you could do /bin/ls, /bin/cat, /bin/ps
@vocal shell when u can do this and not just from any directory
that means the path is messed up
but then that's a valid trick
owww
if like someone doesn't know
sorry
like i didn't know!
??
tty
how like an ss?
yeah like ss it
gone xD
@gusty cradle starting in a minute
did you patch?
public match
nope
@nova tide Not now ๐ but later today 
the pros are here
how come i can't ssh in
ping me whenever you play
@nova tide can you ping the box
i'm booting up my vm
your vpn is working right?
@nova tide can you ping the box
@vocal shell
๐
i just got in and someone urandom me
i cant type in my shell
i cant do anything
@vocal shell you got king for 4 minutes still saying that?
im frozen again
after that i cant do anything
i cant type i cant
naughty do be kicking my ass ๐
whyy
always when i need to type most
i cant even ping the machine lmao
that binary is defected lmao
that seems like your problem
i think someone changed shell to rbash for shifu
not me i can't type
also i can't seem to change password for shifu for some reason
i have like a gazillion shells
but i cant type in any of them
how did you chattr king.txt
chattr isnt on the box
did you make shifu have a key
you're mean @nova tide
I COULDNT EVEN TPYE
I WATCHED MY BELOVED SHELLS DIE
You can upload your own chattr


how to get out of nyancat
Than its Naughty trolling with you, he wouldve named it something normal otherwise
i was so close to beating naughty
๐
i was gonna persist
i cant ping machine
is messed up


now my parents think weird things of me when they see nyancat going across my laptop

you cant get out of that
ope
it's impossible?
woah that is such a neat trick holy dude image blue teamers using that against red teamers in a CDC
that's what i'm going to figure out
because if they can't ssh in bruh there's no way they're going to get in
and kill your services
i mean if i change the password for shifu it's the same thing
what do you mean
you are only trying shifu ssh
then you are doing it wrong
i was using pkill..silly me
btw there are still some processes that kill -9can't kill
btw there are still some processes that
kill -9can't kill
@nova tide Thanks for the info
are there any methods to find out hidden shells?
does ps aux | grep pts show all of them ?
maybe
yeah
if you can find that
find what :)?
my PID
isnt it 11575?
no
its for the process ps aux | grep pts
that would automatically stop after a split second
try w
so how can one kill ur shell?
try top
by trying harder
@nova tide
netstat -antp
last?
you can try out those on your own
what else can you do
nothing special
no idea whats that
checking logs?
never had to check it
um how would i find you then


dude
you do know that i can't simply tell you the way to kill my shells?
Good luck
No
LMAOOOOO
WHAT
This chat is turning out to be more fun than Instagram feed.
Is anyone playing KoTH ?
Or y'all had enough of ๐
come DM i have something for you holmes
Interesting
dreams babe
ok twice here as well
ok
anyone up for a game?
2 min
imma head out to eat something
Naughty plays koth too much.
Naughty plays koth too much.
@native plume play koth with me
Check pinned message
... thanks !!! ๐
@pearl pelican B3nder do you have an tryhackme account
... sorry i wasn't watching the chat ... yes i have one ...
I need some players
yo
@sinful field i'm connected ๐
nice im ready
๐ฑ
Anyone up for KOTH?
Complete noob here
starts in 6
You are already king
yeah bt cant ping the box rn
anyone
for koh
You are not allowed to turn off ssh. (afaik)
people sometimes change ports.. That's allowed. Watchout for that.
Join in people! Starting in 4 minutes.
:))
offline.. Leaving.
Run EB

๐
anyone up to play koth???
m comming
i started with with jacob but m here again
m that much noob that dont even get a single shell
anyway i tries my best
Anyone wanna join in?
https://tryhackme.com/games/koth/join/a26166890052578c9b69a321
beginner 1st KotH for me
ah ggs broh
You aren't playing?
You were in game?
Yeye im jondoe
Oh lol
Bord man
I didn't know!
LmOa

๐
Who keeps resetting
Lmao uea
I knew there was a reason for thay
I didn't see a thing/
Hehehhehe
anyone knows why chattr is disabled in the machine
Um, It's not, other's are just using it more than you ๐คทโโ๏ธ
well well i tried for the first time today
so i was going through that few minutes ago
Is the game over?
yeahabout to
1 minute left
m not aware about mitigation and all
anywhere i can find that
???
chattr -i file
?
Bottom of the page.
Give it a read
๐
heheheh
I submitted the flags when 30 seconds were remaining.
Lets go for another one guys!
Yeye sure
yeah i say that
Dope dope
saw*
Hm?
one more???? @stiff egret @dusty canyon
๐
Here...
This is public
23 minutes
Yea quite a bit
The wait never seems to end!
It's already 3:30 AM here
Yes hehe
Im watching john hammonds 7 hour throwback video
start a private game? 5 minutes?
Im watching john hammonds 7 hour throwback video
@dusty canyon I was watching planet of apes lol
ยฏ_(ใ)_/ยฏ
m starting my system again
lmaooo ight ight
U have like 3 mine homie
I won't
Same bro i feel ya ๐คฃ
lmAO
jk jk
iggght
Lmaoooo dont wooory ur fine
Its still starting dont if i'll be able to join you guys
Actually i tried making my own virtual machine but its hell lot of heavy
Try making one using vagrant.
It's a bit more managed
I am running one using that rn.
My ssh never works.... it stopped in last game also
Is it started
Heck, Even chmod is in place rn.
Shit
Is it started
@wheat ravine YEah
@ruby arch Dunno about ssh, I am inside and ssh is working on port 22
Oh yea idk
Nvrmnd my shell is stupid
Wait seriously.
Welp
Who removed ls.
Are you guys gonna start a new game after this
No idea
๐๐๐๐๐
Lmaoo idk
Reset, I am in vote. Someone destroyed the machine.
Lmao
Like python -m SimpleHTTPServer 80?
Boooo python3 better
yk what I mean
Probably its already there unless someone messes with it
Lmaoo
Wait is it the telnet shell
Cuz if it is u need to set the enviroment variable
No every box I go on chattr binary is not there
Ohk, Machine is not dead
For me itโs doesnโt seem to work
I was waiting on root for you guys
Oh youuu
et tu brute
I just exited my shell
LOL, Well I used absolute paths.
I am depressed
We all are. ๐ฆ
Welp ggs peeps imma go do homework now
And imma sleep. 
Oh okay guys seeya later lads.
Ight cya peeps
Sleep deprivation will catchup very soon
Well when do u join @stiff egret
I have insomnia, pretty badass
Well when do u join @stiff egret
@wheat ravine ?
@ruby arch u gonna sleep yet
Nope not yet
He is asking like whats ur regular time to play koth
Yeah๐ m very much poor in english still tries my best
Its fine bruh
Um whenever I am online(?)
๐ alright will stalk u on discord๐๐

@stiff egret you motherfricker i tried out that fish shell and i almost got locked out of my own machine
the thing had the fish in the /etc/shells
but it wasnt working
๐
and everytime it would just say hey this doesnt exist
so i had to modifyu that damn /etc/pam.d/chsh
you have no idea how long it took me to find it
to disable pam auth
i hate fish shell
never again
linux scary
Um. You know can just change the shell in /etc/passwd?
ommm wait no but the chsh thing
Also, I use fish for 12+ hours a day and it never failed me.
lmAO
chsh had a password lock on it
and i tried all my passwords
and it wouldnt work
so i panicked
dum shell
LOL
In ending of every line in passwd file, it define which shell the user can use.
thats a good idea
kill all root processes >:)
You can change that.
change what
kill all root processes >:)
@vocal shell not allowed.
really?
oh right /bin/bash
yea no im just stupid nvm
dont worry abt it shush
i remembered that dont worry
i knew that
100 percent knew that im so smart
really?
@vocal shell yeah. That will obviously kill all processes. Essentially killing the box down. Or equivalent.
There is a or to be a rule that you cannot kill services as long as there is a way to patch that



