#koth

1 messages ยท Page 43 of 1

vocal shell
#

oHHHH

quiet schooner
#

Have you read the rules koth rules? @vocal shell

vocal shell
#

YEAH

#

But UHHH

#

WAAT

stiff egret
#

His every sentance says otherwise @quiet schooner

dusty canyon
#

id like to try out sshpry it seems fun

vocal shell
#

So you're telling me if MySQL is on a box running as root

#

That I can not kill it

dusty canyon
#

um

vocal shell
#

Because of KoTH rules

#

Darn

quiet schooner
#

Not in KoTH.

stiff egret
#

You can patch it.

vocal shell
#

Patch MySQL

quiet schooner
#

You're in the KoTH channel

stiff egret
#

ยฏ\_(ใƒ„)_/ยฏ

vocal shell
#

But then like

#

UDF?

#

Priv Esc?

quiet schooner
#

That's if it's set up incorrectly

vocal shell
#

So like in the config file

#

It will have the root user running

#

Change that?

quiet schooner
#

You're allowed to patch.

#

You're not allowed to just kill a service blindly

vocal shell
#

What if it's like

#

Something else

#

Wait

#

I want to give an example

quiet schooner
#

You're still asking about your CDC? Please use #general

stiff egret
#

What's that?

vocal shell
#

Cyber Defense Competition

stiff egret
#

Ah.

#

OK.

vocal shell
#

No but I mean like things can be applied from both KoTH and CDC

dusty canyon
#

i now have a moral dilemma against fish shell

#

i dont know whether to use it or not im scared

vocal shell
#

Anyways ok I have to go

dusty canyon
#

yea sure it looked cool

vocal shell
#

I'll KoTH up later

dusty canyon
#

but im still scared of it

#

cool cya man

vocal shell
#

Cya!

stiff egret
#

i now have a moral dilemma against fish shell
@dusty canyon once you set it up correctly, it's very time saving and useful.

dusty canyon
#

"user friendly" they say

#

yea i guess

#

i kinda use guake rn cuz its easier ima use it with fish

stiff egret
#

be warned, fish does not support one liners a lot.

dusty canyon
#

um what

stiff egret
#

It's got its own small changes in syntax.

#

Like while and for loops.

#

Read on it, you'll know.

dusty canyon
#

uh ohhh stinkyy

stiff egret
#

Also, imma go sleep before Ninja points us to #general

dusty canyon
#

lmao ight cool cool

vocal shell
hasty quest
#

hi

boreal flare
#

Hello!

nova tide
#

Hye

potent oyster
#

Hey

vocal shell
#

Joined ๐Ÿ˜‰

vocal shell
#

@potent oyster are you on the koth above??

vocal shell
#

@boreal flare did you try the box above ^ ;))

hasty quest
#

hi

#

i need help

short tusk
#

With what

hasty quest
#

how can play

#

koth

#

have any kinds of video r txt

#

abut koth

#

?

short tusk
#

Uhhh ill leave this for the KOTH players to explain

vocal shell
#

Yes

#

Google TryHackMe KoTH and read rules

stiff egret
#

You should just check pinned msgs, @hasty quest

hasty quest
#

@stiff egret thanks

stiff egret
#

:))

vocal shell
#

@stiff egret hop on this

#

if you like

stiff egret
#

You really want me to join?

vocal shell
#

it's carnage

#

no i don't

stiff egret
#

Alright :))

vocal shell
#

join when i patch it

#

;))

stiff egret
boreal flare
#

hey mr holmes

stiff egret
#

Hey @boreal flare

#

Sup?

#

join when i patch it
@vocal shell booting my VM

boreal flare
#

nothing much...just solving jacob the boss

#

i had a question for you..

stiff egret
#

Sure shoot!

boreal flare
#

yesterday you said that you would've been on a different level if you had thm earlier

#

so if u dont mind answering where did you start?

stiff egret
#

start from here, and complete everything..

vocal shell
#

OK NAH IMA LEAVE @stiff egret

#

I GOTS STUFF TO DO

stiff egret
#

so if u dont mind answering where did you start?
@boreal flare um linux privesc I think

#

OK NAH IMA LEAVE @stiff egret
@vocal shell sed

vocal shell
#

sad!

stiff egret
#

I booted up my VM for you!

vocal shell
#

sad!

boreal flare
#

@boreal flare um linux privesc I think
@stiff egret ahh..

vocal shell
#

NEXT TIME

stiff egret
#

anyhoo, now that it's running, I'll play some anyway

hasty quest
#

I

boreal flare
#

@boreal flare did you try the box above ^ ;))
@vocal shell nahh dude..was just spectating

nova tide
#

ping me if someone is playing koth (except holmes/myDonut)

nova tide
#

i had my mid terms since this morning and people were playing and spamming invites after every 30 minutes.. and now i'm free where all those guys went? cri

stiff egret
#

ping me if someone is playing koth (except holmes/myDonut)
@nova tide its official, we 3 avoid each other

#

i had my mid terms since this morning and people were playing and spamming invites after every 30 minutes.. and now i'm free where all those guys went? cri
@nova tide bery sed

nova tide
#

myDonut don't.. he have asked me everytime he plays.. but i don't want to reveal my secret techniques that i have gathered after losing that many matches against him yet kekw

#

waiting for a big moment

stiff egret
#

tru

#

we avoid him lol

#

avoid isnt the right word

nova tide
#

I can play against him anytime he wants. coz i am free now, from exams.. pretty sure i know all of his techniques and got counters for each except rootkit.. but now even have a method to get around that as well ๐Ÿคซ

stiff egret
#

sssssh

#

delete that

nova tide
stiff egret
#

beeeeeeeeeeeeeeeeeeeeeeeeeeeee

#

lots of lob

#

you submitted it!!!

nova tide
#

Finally its in there

stiff egret
#

ABOUT TIME!

#

finally a leaderboard where szy won't be on top

gusty cradle
#

๐Ÿ‘€

silver lance
#

Anyone wants to join?

grand ember
#

paste the link instead of sending a pic

#

really unlikely someone will type the link letter by letter

silver lance
#

3 mins to join

wheat ravine
#

anyone up for KOTH

nova tide
#

yeah?

stiff egret
#

eh

nova tide
wheat ravine
nova tide
ruby arch
#

Hop in guys!

#

7mins to go

stiff egret
#

uh uh @nova tide

stiff egret
#

you leaving?

#

or me?

#

we will just make a deadlock

nova tide
#

i mean it's the same thing.. you play or i ๐Ÿคทโ€โ™‚๏ธ

stiff egret
#

yeah

#

lol

#

we even know where we gunna hide our binaries

nova tide
#

if someone beats one of use then he probably have beaten both of us? kekw ๐Ÿค”

stiff egret
#

true LMAO

#

most probably

#

but non of us gonna use the nuclear missle so

nova tide
#

๐Ÿคซ

#

stop telling everyone that we got nuclear power atm ๐Ÿคซ

stiff egret
#

WE GOT NUCLEAR POWER

#

!

nova tide
#

@stiff egret why are you not playing?

stiff egret
#

waiting

#

in uid 0

#

ยฏ_(ใƒ„)_/ยฏ

#

there

cunning wraith
#

guys how u doin'?

#

this tryhackme platform is damn amazing
thank u guys
thank u sooo much for ur great job

stiff egret
#

@nova tide

severe yoke
#

F

stiff egret
#

Not kidding

severe yoke
#

ok

stiff egret
#

It's a player, with name everyone

severe yoke
#

Lol

#

i scared my self

#

xDDD

stiff egret
#

He was playing just now, so I tagged him

severe yoke
#

ok ok

stiff egret
severe yoke
#

hello, i would like to play a koth, its my first time on it, somebody that would like to play ??

#

lol

#

f : Uh-oh! Only intermediate and advanced experienced leveled users can play King of the Hill.

#

whyyy!!

#

@stiff egret which level should i have to play it ?

keen forum
#

You can change that in your profile

severe yoke
#

aaaa

#

xDD

#

that one

keen forum
#

profile -> about you

severe yoke
#

yes yes

#

now i remember

#

thx

#

xd

west sky
#

yo guys

#

lets do a koth

dusty canyon
#

Yes absolutely

#

When i get home

#

So like 2 hours

acoustic rover
#

Yea I would like to do on too some day THOUGH right now I'm noob. That's the only problem i see.

fair adder
#

so we doin da koth or na

stiff egret
#

๐Ÿ‘€ You in Arch Gang?

fair adder
stiff egret
#

Verified, welcome to the gang.

fair adder
#

thanks kind sir

stiff egret
#

(if that was not sarcasm/joke) no need of sir

tepid hornet
#

Is that pfetch ?

hallow torrent
#

starts in one hour
anyone can join regardless of skill level

stiff egret
#

Why private?

hallow torrent
#

to set the one hour time

fair adder
#

yes @tepid hornet

hallow torrent
#

lets do a koth
@west sky
When i get home
@dusty canyon
Yea I would like to do on too some day THOUGH right now I'm noob. That's the only problem i see.
@acoustic rover
wanna join?

acoustic rover
#

wanna get in voice?

hallow torrent
#

no
don't have any device for input

acoustic rover
#

ah ok

acoustic rover
#

Why is port 65432 open and googling it gives me info that its a trojan????

fair adder
#

homie got a backdoor

acoustic rover
#

ah ok

#

yea i fucking quit this shit. its just too hard

#

i have no clue

#

shrek just getting me more upset

lapis arch
#

lol, thats common @acoustic rover

#

do more rooms and you will get the hang of it

acoustic rover
#

they are exactly my rank and just got 250 points

#

thats just hilarious

#

i got exactly 0

#

i found a priv key

lapis arch
#

rank means nothing

acoustic rover
#

i dont even know what it is for

#

not for ssh

#

not for ftp

lapis arch
#

so, you need more study

#

so your mind can be expanded

acoustic rover
#

theres that one port open called abyss

#

but researching it shows me some exploit tho nothing even slightly usefull

#

theres a file upload

lapis arch
#

there's some ports in KOTH that are just endless holes

acoustic rover
#

i uploaded a reverse shell but i dont even know where it drops

lapis arch
#

thats a step, next step would be figure out where it went

#

Or just attack another service/port/vuln

acoustic rover
#

yea. and i looked and looked and looked

#

i used gobuster. no chance to find any upload folder

lapis arch
#

thats the hacker job.... infinite research ๐Ÿ˜†

acoustic rover
#

yea. but theres nowhere to drop in

lapis arch
#

there's some guides on internet for shrek

#

you can see where you could attack

acoustic rover
#

i dont even want to anymore

lapis arch
#

you got persist man!

acoustic rover
#

im sitting here for fucking an hour trying to find anything and finish the koth with 0 points

#

thats just so demotivating

lapis arch
#

I know you can get pissed, and frustated.... but thats what it is

#

you gotta love the PROCESS not the results.

#

Because most of the times you simply wont hack things ๐Ÿ™‚

acoustic rover
#

i found this NzM2ODcyNjU2bzY5NzM2MTZzNnI2OTZzNnI= but i dont even know what it is. i suspected base64 but that just gives me some weird string which doesnt work ass passwords, nor anything else

#

What do i have the process for if i dont have a result??

lapis arch
#

the process make you more experienced....

acoustic rover
#

i would be ok with just finding ONE flag

lapis arch
#

you can discover a new tech...technique....

acoustic rover
#

but hell no

lapis arch
#

man, i've done like 20 koths and won like 3....

#

in 10 of that I did not find anything. but thats Ok

acoustic rover
#

reading the comment <!-- shrek is like an onion --> just gets me so upset

#

yea ok. but i found alot of shit though nothing is of use

#

i got a priv key. what did i use it for? nothing cuz thres nothing to use it

lapis arch
#

I recommend you taking a little break ๐Ÿ˜›

stiff egret
#

Hey people! Seems like I missed the game!

acoustic rover
#

hm

#

ok. he patched the ssh priv key

#

thanks

#

im done

#

bye

lapis arch
#

bye man, good luck, peace

ruby arch
#

Anyone up for a Koth?

fair adder
#

Me!

ruby arch
#

Lets do it bruh

fair adder
#

This one is interesting...

nova tide
#

theres that one port open called abyss
@acoustic rover that would surely be 9999 port running the king service.. if you look at the rules no exploiting that one.

acoustic rover
#

Though it was running abyss something. That's what it told me.

hardy jungle
#

Read the rules.

#

Says what it is, and you can't attack it

chilly sandal
#

@hallow torrent you joined me

#

๐Ÿ˜‚ I'm not that great

#

Im in VC if you wanna join ๐Ÿ˜„

hallow torrent
vast perch
#

Im really struggling getting into koth and I really want to but im struggling

hallow torrent
#

Im in VC if you wanna join ๐Ÿ˜„
@chilly sandal i dont have a n input device

#

whoo are u talking to?

#

lol

#

wannaa joinn /?

in koth

#

ok

vast perch
#

Anyone have any tips

chilly sandal
#

for?

hallow torrent
vast perch
#

Or maybe have a koth team I can join to maybe learn some?

chilly sandal
hallow torrent
#

thx

#

i am iin

vast perch
#

?

hallow torrent
#

i mean the link lol

#

Or maybe have a koth team I can join to maybe learn some?
@vast perch search internet for koth
walk-throughs

vast perch
#

Oh maybe thats not a bad idea

hallow torrent
#

yea

#

lol

#

abyss

quiet schooner
#

It's not abyss.

hallow torrent
#

me neither
i haven't played "hackers" machine before

quiet schooner
#

It has writeups

#

But 9999 on all KoTH boxes is the KoTH service which is out of scope.

hallow torrent
#

ok

quiet schooner
#

It's also open source.

hallow torrent
#

It has writeups
@quiet schooner where?

quiet schooner
#

You can find them with less than 10 minutes of looking

#

So I won't link you

hallow torrent
#

ok

#

r u in?>

#

ur in ssh??

#

how?

#

ok

quiet schooner
#

I'm not playing.

chilly sandal
#

were talking

#

he doesn't have input atm

#

we're in VC

hallow torrent
#

lol

#

i don't have experience with hydraa

#

ok

#

wwhat?

#

ok
try ur best kid

#

ok np
i will reset then

#

done

#

ll

#

lol

#

it needs time to start

#

r u in?

#

what happen to hydra?

#

i m talking bout u
r u in?

#

no i wont

#

just askingg

#

lol

#

no iam nt

#

i nmapng for other way in
except hydra

#

ok

#

got sudo?

#

11 min left

#

wwhat>?/

#

login as anonymouse

#

ohh

#

i got thiss

#

Skiddies keep out.
Any unauthorised access will be forwarded straight to Richard McGill FBI and you WILL be arrested.

  • plague
#

lol

#

yeaa

#

lol

#

1 min left

vocal shell
#

waait what

#

i wanted to join and surprise

#

aww

chilly sandal
#

lol

vocal shell
#

now it looks like i lost xD

#

new game in 5 minutes

hallow torrent
chilly sandal
#

Aug if you can we're in VC

vocal shell
#

i dont have an input device

#

soz

#

@hallow torrent join da koth

#

1 min left

#

i made it private so it'd load faster

hallow torrent
#

got it

chilly sandal
#

anyone make progrss ๐Ÿ˜‚

vocal shell
#

yessir

chilly sandal
#

with ssh to fortune?

vocal shell
#

hmm??

lusty crown
#

anyone up for koth now?

#

how long since the game started?

chilly sandal
#

still 49 mins left

vocal shell
#

like 5 minutes?

#

o

#

yeah that

#

did someone patch?

chilly sandal
#

not unless you did

vocal shell
#

waaaa

#

@lusty crown did you?

chilly sandal
#

no he just joined

lusty crown
#

i'm in the game

vocal shell
#

i have creds for the

#

whaaaa

#

and then it wont lemme ssh

chilly sandal
#

you changed the ssh key!? bully

vast perch
#

Anyone maybe wanna walk through a koth with me sometime? Im pretty beginner and kinda want some help learning

vocal shell
#

i didnt change the ssh key!

chilly sandal
#

hmm

vocal shell
#

im on

#

i havent patched

#

i dont wanna patch

#

๐Ÿ˜‰

#

ouch

#

whoever /dev/urandom'd me

chilly sandal
#

I had to I'm sorry

vocal shell
#

must've felt good

chilly sandal
#

a little but I needed to have control ๐Ÿ˜‚

#

would you like me to kill the urandom?

vocal shell
#

did you change the password

chilly sandal
#

maybe

vocal shell
#

nah you don't have to do anything

#

why are you guys resetting ever other second?

chilly sandal
#

im not ๐Ÿ˜ข

#

its annoying lol

vocal shell
#

WHO RESEt

#

JUST BECAUSE I GOT ROOt

#

@hallow torrent and @lusty crown

chilly sandal
#

me that time bully kicking me out of foruna

vocal shell
#

why are you like this

lusty crown
#

bro i didn't do shit

vocal shell
#

if it resets again

lusty crown
#

who tf is resetting the box

vocal shell
#

i stg

#

IT TAKES 2 PEOPLE

#

it's REALLY ANNOYING

#

10 TIMES AT LEAST

#

YOU RESET

#

LMAO

lusty crown
#

bro i'm not doing anything

vocal shell
#

who changed the password

#

lmao

chilly sandal
#

ill put it back

#

lol

vocal shell
#

wow wha

#

we JUST RESET

#

and you're root

chilly sandal
#

its gonna me Augustus

#

I WILL RESET

vocal shell
#

dont fucking reset because you got kicked out

#

THIS SHOULD BE A FUCKING RULE

#

IM DONE

#

WITH YOU

#

WOW

#

RESETS AT LEAST 12 TIMES IN ONE GAME

#

go get your win

#

idgaf

grand ember
#

Yikes

blazing quiver
#

Mars? Is going on here?

#

Well that isn't what I wrote at all.

#

Whats going on here?

grand ember
#

Someone got salty because of constant resetting in a koth match

blazing quiver
#

Oh. So what does koth mean?

stiff egret
#

King of the hill.

blazing quiver
#

Ohhh okay.

#

What does resetting do?

stiff egret
#

Umm why don't you give koth page a read?

vocal shell
#

@grand ember how would you feel if someone reset 10+ times in one game? Once every time the machine boots? By 1:30 minute you get a new box

#

i was really mad

grand ember
#

I'm not saying you're wrong, i would be salty too

terse willow
#

smh. You step out of 6 hours. Jesus.
@vocal shell @lusty crown watch your language. You must have seen reminders that this is PG13 -- that string of profanities is totally inappropriate.

@chilly sandal adding you in here too:
Getting kicked out, or failing to get into the machine, is not a valid reason to reset the box. I don't know which of you was voting for it, but it sounds very much like you were instigating it, angelic. That is a rule that's been added in the development site, but has yet to be pushed to the production site that everyone sees. As it is, that kind of resetting I would argue does partially come under rule 5 related to DOSing the thing ๐Ÿคทโ€โ™‚๏ธ
The aim of the game is to be realistic. Changing SSH keys and passwords are fine. Kicking people out when you notice them is fine. TTY spamming is a low blow. Resetting is moronic. If you can't play properly, don't play at all. If you can't play calmly don't play at all. That goes for the lot of you.

lusty crown
#

got it!

#

sorry!

terse willow
#

@lusty portal any chance of getting that rule update pushed at some point? ๐Ÿ™‚

vocal shell
#

I apologize @terse willow I was frustrated at the time and I used vulgar language. It will not happen again

terse willow
#

Thank you ๐Ÿ™‚

lusty crown
#

there should actually be a new feature where we get to know who clicked the reset button!

full grove
lusty crown
#

okay

vocal shell
#

thank you @full grove

full grove
#

welcc

nova tide
#

THIS SHOULD BE A FUCKING RULE
@vocal shell it will be in the next update:
Reset the box only if its broken not when its patched.
Also check #641405480547385354 to upvote/downvote some of the ideas about KoTH

#

there should actually be a new feature where we get to know who clicked the reset button!
People are thinking/fighting over stuff that i fought for weeks ago ๐Ÿ˜‚๐Ÿ˜‚
Gib new rules blobknife

short tusk
#

I should get into KoTH

stiff egret
#

This is the best time jabba!!!

short tusk
#

I mean I should

#

But

#

eh

chilly sandal
#

@terse willow I stated that I never instigated it I only clicked reset when I borked something like no one being able to get to root. When I clicked reset it was for a valid reason and only when another had already voted to reset. I never reset JUST because I got knocked off the box as their are other ways in

west heath
#

@chilly sandal Are you in the current koth room with me?

chilly sandal
#

yes lol and I'm stuck ๐Ÿ˜‚ IDK where to go from here

#

@west heath

#

I got the rsa but it needs a pass IDK

#

Why? @west heath

west heath
#

no password required, make sure your permissions are correct 600 and you are using the -i option

chilly sandal
#

hmm I did ssh -i id_rsa Ashu@$IP and I made sure chmod +600 id_rsa so idk

west heath
#

ashu

#

note the lowercase

chilly sandal
#

lol

#

wow

#

still wants a pass so my loss ๐Ÿ˜‚

quiet schooner
#

Unix usernames are always lowercase

stiff egret
#

Someone changed the sshkeys then. @chilly sandal

west heath
#

not I

chilly sandal
#

ah I figured someone had to ๐Ÿ˜‚

west heath
#

no id's have been changed in this session.

#

just checked

chilly sandal
#

hmm oh well my vm hates me then

west heath
#

try ./id_rsa

chilly sandal
#

bad perms still wants pass and id_rsa would say the same

west heath
stiff egret
chilly sandal
#

Im in but I can't do nothing now ๐Ÿ˜‚

stiff egret
#

ยฏ\_(ใƒ„)_/ยฏ

west heath
#

You're in

stiff egret
#

KoTH boxes are easier to solve than normal ones. Because they are made in such a way that they are solvable in less than 1 hour.

west heath
#

Start poking around. What can this user do?

stiff egret
#

Which user do you have?

chilly sandal
#

ashu I can't do much apparently

west heath
#

Who else is a user

stiff egret
#

there's always a method to privesc ยฏ\_(ใƒ„)_/ยฏ

chilly sandal
#

I see I just cant spell for crap

stiff egret
chilly sandal
#

@west heath I appreciate all the help you gave me for that box. I didn't realize I had capitalized Ashu by mistake. and fighting you for king was entertaining ๐Ÿ˜‚

west heath
#

cronjobs for the win

chilly sandal
#

ah see IDk cronjobs but I was trying to do a while loop for chattr and echoing

west heath
#

More things to learn. Luckily you are in the right place to do so. THM is an awesome platform to develop your skill set

chilly sandal
#

I fully agree with that

#

@west heath we meet again ๐Ÿ˜‚

west heath
#

haha, well look at that

chilly sandal
#

how unfortunate for me ๐Ÿ˜‚

#

nah its a good learning experience and thats what I came here for

west heath
#

I keep getting the "Production" room, If I do, I will bounce. Really hoping for "Offline" to try some Windows hacking

chilly sandal
#

I can manage with linux boxes but Windows IDK if I can do that

west heath
#

Just another learning opportunity

chilly sandal
#

right

#

what os are you using kali?

west heath
#

Nah, basic ubuntu. I have just acquired all of the tools I needed as I've gone along.

chilly sandal
#

same

west heath
#

Kali is cool and all, but it is for those who know their tools already. Like I said, THM is a great place to learn those tools and then adopt kali when you are ready

chilly sandal
#

I love arch so I may move to black arch or just arch with black arch tools

west heath
#

there you go

chilly sandal
#

my first linux distro I used was ubuntu for reinstalling windows then I really dove into it when I had a friend convince me to try Arch and I fell in love with it

west heath
#

Nice! I've tried mint, fedora, kali, and centos. For me, ubuntu just feels natural. Just my opinion though

chilly sandal
#

it does feel natural I can totally agree with you on that one!

#

its just so much simpler to install than arch too. Arch I gotta do everything myself which is fun when I'm not feeling lazy ๐Ÿ˜„

#

and I don't have metasploit fun

#

I got it just in time ๐Ÿ˜‚

west heath
#

you don't use or don't have metasploit?

chilly sandal
#

I didn't have it I forgot to grab it

west heath
#

gotcha, it is useful, but knda defeats the purpose of learning how to hack if you are using an automated tool

chilly sandal
#

true but learning to use tools can speed up the process. I am interested in trying to do it without metasploit

#

is your ubuntu the host or guest? I have a vm so

#

next question is does core count increase the speed of some of the stuff we have to do?

west heath
#

I've upgraded it to host from windows 7. (old computer from yesteryear), although vms are very handy for trying out different distros

#

it can. especially for brute forcing and john the ripper / hashcat challenges

nova tide
#

Today i had a dream that there are new KoTH rules and KoTH networks ๐Ÿฅบ

stiff egret
#

bery bery sed

brave yarrow
#

anyone in for koth?

stiff egret
#

count me in

brave yarrow
#

oh sr you still on?

#

@stiff egret

stiff egret
#

Can't play now :( gonna sleep now, its 4AM here

brave yarrow
#

๐Ÿ˜ฆ mb tmr

stiff egret
#

maybe :)

west sky
#

if anyone wanna play koth with me, it starts in 3 minutes

brave yarrow
#

sr i was late

vast perch
#

Anyone wanna walk through a koth later tonight

vast perch
#

Im trying to learn some and want to know if anyone wants to teach a bit

brave yarrow
#

@vast perch i'm in if you want but in like 3 hours cs i have to study

lusty crown
#

20 min as of now

raven halo
#

anyone around for koth

raven halo
#

anyone wanna do koth

hallow torrent
#

yeaa

hallow torrent
hallow torrent
hallow torrent
grand ember
#

someone was playing with bashrc i presume

stark fox
#

someone made recovery 2 kekw

boreal flare
#

xD
y am i getting this everytime i connect to ssh?
@hallow torrent

vivid ridge
#

I was all caught in nmap scans

#

never found other ports till 15 min before end

#

plus nostromo exploit got patched

#

that was the only thing I was able to find and that also got closed within seconds

hallow torrent
#

nostrom sn't patchhed

vivid ridge
#

connection closed that was the error I was getting

#

but it was working a min before that

slate crow
slate crow
#

ay bois

#

watchu doin?

honest sandal
#

malik got dc'ed

#

and i'm trying..

boreal flare
#

umm...can anyone help me..i have a situation...

#

how can i privesc from here ?

#

what am i doing wrong ?

blissful kettle
#

Try check GTFO bins on how to escalate

boreal flare
#

Tried that

#

but it didnt work either

nova tide
#

how can i privesc from here ?
@boreal flare try entering full path:
sudo /bin/nano /home/gcrawford/bussiness.txt

boreal flare
#

tried that too

#

but it somehow downgraded my shell

#

this happened after executing that

ruby arch
#

Anyone up for a koth bois?

west sky
#

@ruby arch i join

ruby arch
#

Lets do it marco

west sky
#

yes

west sky
#

@ruby arch sorry my kali crashed

#

are you deathsniper?

ruby arch
#

I am not even playing rn ๐Ÿ˜‚ sorry guys i had to go out will be home by next game

#

no i am GragTung

west sky
#

oh lol

#

me too

ruby arch
#

Hahaha

west sky
#

my kali crashed it was good game tho

ruby arch
#

Did the patch the machine up?

west sky
#

yeah

#

i made python bot to keep replacing the file with my name over and over

#

lol

ruby arch
#

Thats good haha

#

Just booted my VM up

#

Last 8mins remaining

hallow torrent
#

@ruby arch join thelast one

ruby arch
#

Sorry didnt see that before

#

Lets just wait for this one to start ๐Ÿ™‚

vocal shell
#

cant ping machine

nova tide
#

nice

vocal shell
#

@raven halo can u ping

#

i cant ping

#

how can u use the box lmao @raven halo

#

how did u get chattr on the box

#

dude if i could ping this box

#

gg no re

#

can u reset??

vocal shell
#

lhttps://tryhackme.com/games/koth/10137

#

5 minutes

nova tide
#

which machine?

vocal shell
#

its random

#

@nova tide

nova tide
#

You do realize that you are sharing spectator links not invite links?

vocal shell
#

oops

nova tide
#

I'm going to sleep. will play later maybe

vocal shell
vocal shell
#

AHH I KICKED MYSELF OUT

#

someone changed password for fortuna

#

loser

proper sundial
#

yeah loser

vocal shell
#

WOW

raven halo
#

Cant get in, someone changed the password or even delete the .ssh lol

vocal shell
#

no one did that

#

i did not do that

#

thats happening to my user as well

#

someones root rn

raven halo
#

gotta be another way in ๐Ÿ˜ฆ

vocal shell
#

there are like 4

#

maybe more

#

like 20

raven halo
#

lol

#

gg

vocal shell
#

gg

#

@vralparmar

#

did u ever get in

#

@raven halo

#

did u ever get in

raven halo
#

Nope

#

๐Ÿ˜ฆ

#

Was finding other ways

vocal shell
#

not once?

#

what was the hardest part

raven halo
#

Nope, not at all. SSH fortuna didnt work even after resetts

vocal shell
#

||i tried creating a user for persistence || and even that didnt work for ssh

raven halo
#

yeah. its a difficult box to get other footholds, I was trying other avenues. Website could be a possibility.. ๐Ÿ˜ฆ

vocal shell
#

starts in 3 minutes

#

i'm in

raven halo
#

amjazing wow

vocal shell
#

if you can't ssh in

#

it's because i changed your shells

#

ssh is still up

#

This account is currently not available. is what you'll get

raven halo
#

Ill find another way grr lol

vocal shell
#

if you can get in

#

i'll give you a cookie

#

i think someone is in

#

oMFG

#

nvm that was me

#

@raven halo

#

do you want a user shell

#

im so confident that you will not be able to priv esc

raven halo
#

wordpress is down lol

vocal shell
#

i didnt touch ๐Ÿ˜ฎ

#

down for me too

#

make sure its in your /etc/hosts

#

panda.thm

#

@raven halo shifu:bxN6DiMHXtmEnKbtUd3B4yLm0OMfAKXA9y4yJeN4HZMZc/7aB/fzJenxEBAS+ASFkXD3NYyCsbiOYhskMGk+0VScMlKKPe8YBUbCWuZDWE8fJmkaodnnkMUXYmHoXmsJ89LHoSrJzSnAzFMs4Vm5GFIPeVw5BIm2wfJKVXgzjQZIXo7Oz0AhMFAsowte2uhgHUWr64bXzLZDv4e0pmwzIK8W1WBm/wRE73P0Pkb6YA2mICBAiMkLW7HVjt9xvFhTMOuy

#

shifu's creds

raven halo
#

lol port 80 doesnt even work my god

#

im gonna cry

vocal shell
#

really!1

raven halo
#

lol

#

what did you do @polar light

vocal shell
#

just ssh in

#

I DONT KNOW LOL I THOUGHT

#

someone was logging in as po

#

and i killed the process

#

ok for now just ssh in as shifu with those creds

#

good luck priv escing! ๐Ÿ˜„

raven halo
#

is that the id_rsa

vocal shell
#

that's the password ;))

#

are you in

raven halo
#

wow

vocal shell
#

i just took whatever i could find

#

there's no way you're bruteforcing

#

in one hour

raven halo
#

i am

#

in

#

*hacker voice(

vocal shell
#

i'm in

#

you gotta say it in one line

#

i've hacked into the mainframe

raven halo
#

you restrict my access

#

and put a false flag

#

wow

#

im dyin

vocal shell
#

wait I DIDNT

#

WHERE

#

WHERE

#

show meh

#

i didnt create any flags

#

i did my best to restrict access ;))

raven halo
#

i know, im running linpeas on the mainframe

vocal shell
#

lemme know if you find anything ;))

#

anything happen to linpeas??

raven halo
#

cant find crap

#

i cant even wall

vocal shell
#

REALLY

#

OMG

raven halo
#

cant even cat /etc/passwd

#

lol wonderful

vocal shell
#

i know i chmod'd it

#

blue team ๐Ÿ˜Ž

raven halo
#

you're amazing

vocal shell
#

thank you

#

HAHA

#

i'm practicing

#

i think there's virtually no way to priv esc

raven halo
#

There isnt

#

GG man

vocal shell
#

ty ty

#

you still have 17 minutes

#

dont give up

#

@ challenger

raven halo
#

im giving up, i know there isnt much I can do

vocal shell
#

also u can ssh in

raven halo
#

GG

vocal shell
#

thank you ๐Ÿ˜‰

#

i haven't touched wordpress

#

maybe you can get in via there upload a reverse shell

raven halo
#

I cant get in at all

vocal shell
#

you can definitely get flags tho

raven halo
#

I need to learn how to tighten evenything up like you

vocal shell
#

๐Ÿ˜„

raven halo
#

restrict access in linux etc. really cool - is there anywhere I can read up on these sort of things?

vocal shell
#

CIS benchmarks, DISA STIG, blogs, youtube, twitter

raven halo
#

Ok

vocal shell
#

i know more defense than offense i'm a blue teamer

#

i just learned "hacking" like 3 weeks ago maybe

raven halo
#

Im thinking more of quick cheatsheet?

vocal shell
#

lol

#

oh

#

i know

#

BTFM

#

Blue Team Field Manual

#

google

raven halo
#

is this where you learned all these techniques?

#

ok

vocal shell
#

Blue Team Field Manual filetype:pdf

#

no it's not

#

i actually discovered it like 2 years after

#

it has useful information

#

definitely go look at that

raven halo
#

Thanks - GG man, im off see ya

vocal shell
#

byee

vocal shell
#

how to patch windows/smb/ms17_010_psexec

nova tide
#

Google it

vocal shell
#

i did @nova tide i couldnt find anything

nova tide
vocal shell
#

you try do it

#

prove me wrong

terse willow
#

@vocal shell you can download hotfixes and install manually iirc

rapid spire
#

Someone for KoTH

terse willow
#

Go find the hotfix for MS17_010, download it, then just use it on Offline

vocal shell
#

thank you! any articles?

ruby arch
#

Wanna play a koth anyone?

stiff egret
#

Ping me if anyone plays !

ruby arch
stiff egret
#

Joined

hallow torrent
stiff egret
boreal flare
stiff egret
#

๐Ÿ‘€

boreal flare
#

Join this one too...well you can handle multiple boxes at once....

#

if you want to that is...

stiff egret
#

Joined ๐Ÿ˜‰

boreal flare
#

๐Ÿ™‚

#

omg holmes and naughty showdown is it ?

stiff egret
#

HuH? Where?

#

LOL m out then, kekw

#

no mood of deadlocks

nova tide
boreal flare
#

i should've kept quiet...lmao

stiff egret
#

LOL

#

our game would've been over in 20 secs regardless of box

#

either him or me ๐Ÿคทโ€โ™‚๏ธ

boreal flare
#

xD

stiff egret
boreal flare
#

i'm so bad with these php rev shells

nova tide
#

our game would've been over in 20 secs regardless of box
or both running for king

stiff egret
#

or both running for king
@nova tide we would've patched and kicked

boreal flare
#

why the hell is sudoers file empty

stiff egret
#

why the hell is sudoers file empty
@boreal flare **!**me

boreal flare
#

sorry..?

stiff egret
#

not me

boreal flare
#

ahh

#

well i was talking about the other box

stiff egret
#

I don't even remember which game I am in

hallow torrent
#

-bash: ls: No such file or directory

stiff egret
#

which box is it?

boreal flare
#

shrek

stiff egret
#

ยฏ_(ใƒ„)_/ยฏ

boreal flare
#

well naughty seems to be playing with me

stiff egret
boreal flare
#

mr naughty if you dont mind sharing how'd you do that ?

#

even pwncat wasn't working

#

had no options

nova tide
#

well naughty seems to be playing with me
@boreal flare well i wasn't playing until someone killed my shell kekw

#

-bash: ls: No such file or directory
@hallow torrent you are in my game?

boreal flare
#

๐Ÿ˜› sorry about that.... did you cat my shell?

#

i was trying to modify sudoers

#

and each f'in time someone would cat my shell

nova tide
#

who knows?

boreal flare
#

well...

#

whatever..

nova tide
#

you mean this?
echo -n "I" > /dev/pts/1;sleep 2;echo -n " am" > /dev/pts/1;sleep 2;echo -n " in" > /dev/pts/1;sleep 2;echo -n " your" > /dev/pts/1; sleep 2; echo -n " shell" > /dev/pts/1;

boreal flare
#

yea

#

so it was you

nova tide
#

also that parrot trick was cool

#

until i saw all of your binaries

boreal flare
#

thanks!

#

yeah..that was a mistake

#

did you change ch binary with nyancat ?

nova tide
#

??

boreal flare
#

how were all my shell showing nyancat?

hallow torrent
#

@hallow torrent you are in my game?
@nova tide yaaaa

nova tide
#

idk why you are facing that ls issue

boreal flare
#

there is an ss above

hallow torrent
#

ok

boreal flare
#

i thought that was you

nova tide
#

how were all my shell showing nyancat?
@boreal flare that was me

boreal flare
#

@boreal flare that was me
@nova tide thats wht i was asking..can you share how'd you do that?

nova tide
#

get the nyancat binary.. parrot would be cool too

hallow torrent
#

can NyanCat doo ths?

-bash: ls: No such file or directory

nova tide
#

and then do this:
nyancat > /dev/pts/<tty of the victim here>

boreal flare
#

ahh

#

i see

#

just like dev/urandom

nova tide
#

@boreal flare you changed ls ?

boreal flare
#

nope not me!

nova tide
#

someone added an alias for that

boreal flare
#

well..thanks for the valuable info

#

learned a lot today

#

thanks!

nova tide
unkempt oracle
#

how do you find out the tty?

ruby arch
#

Still 6 mins left to start

nova tide
#

how do you find out the tty?
@JonasM#1199 ps aux | grep pts or w for your's do tty

hallow torrent
#

ps aux | grep pts

unkempt oracle
#

ty

hallow torrent
nova tide
#

imma play some siege with friends now

hallow torrent
#

ok

boreal flare
#

I'll join after this game

hallow torrent
#

ok

hallow torrent
#

how do i gget in carnage |?

nova tide
#

there was a thing for that

#

i forgot the name

#

that was

#

(JK)

#

carnage is easy

#

finding creds is easy when you know the method

hallow torrent
#

whats the methode/?

nova tide
#

tryharder
That's where it comes in handy

hallow torrent
#

i amm bruteforing ssh with hydra

nova tide
#

Don't do that

hallow torrent
#

yea
i stoped

#

give mme some cllue

nova tide
#

check the available ports

#

try checking while file you can upload?

#

or what you can do to login without password?

hallow torrent
#

ok

#

where do i get php-reverse-shell?

chilly sandal
#

google pentest monkey reverse shell

blissful kettle
#

or github

chilly sandal
#

I get mine from github

hallow torrent
#

would dixs be ok?

chilly sandal
#

yep

#

I use that one

blissful kettle
#

Pentest monkey seems to give warnings before proceeding no idea what happened to it

chilly sandal
#

I dont get any errors using pentest monkey stuff

quiet schooner
#

Google flagged the site because hacking tools

nova tide
hallow torrent
#

lol

chilly sandal
#

so do See Details and click ignore

stiff egret
#

well it contains reverse shells..

flint oriole
#

yeah

#

some windows antiviruses got triggered on a pdf with shell examples

terse willow
#

some windows antiviruses got triggered on a pdf with shell examples
@flint oriole In fairness, have you seen the tantrum Windows Defender throws if it finds a Kali ISO?

flint oriole
#

:> lmao no

terse willow
#

It's uh, amusing

quiet schooner
#

Interesting, doesn't pick them up here

terse willow
#

Odd. Thing almost gave me a heart attack when it started doing it with me and found 500 odd bits of malware that had suddenly infected my PC ๐Ÿ˜†
Until I noticed that the file paths for all of them were directly to the Kali ISO

sly turret
fair adder
raven halo
#

Have you guys had an issue where you are root. Echo your name in king.txt but it doesnt update the leader board?

#

I've had this happen to me twice already

#

I've reset the box as well

#

Is this a bug?

boreal flare
#

Yeah..it happened with me too..

stiff egret
#

Um. The King service reads the file every minute. You need to be king for 60 seconds to get your name in there.

#

Sometimes, the king.txt gets broken, but that should get fixed after reset.

raven halo
#

maybe creating a cron job to write username > king.txt doesnt update?

#

every minute**

#

probably why, yeah?

#

would deleting the king.txt and creating it again fix the issue?

stiff egret
#

It might. Unless some other player got some loops running.

boreal flare
#

Yesterday my name was in king file for the whole game but I had no king time

runic quail
#

Iirc you have to execute some binary after putting your name in king file.

raven halo
#

ive done that as well

#

I've also restarted the service manually and restarted it, nothing

#

just tested this now

#

:S

sterile viper
#

Have you guys had an issue where you are root. Echo your name in king.txt but it doesnt update the leader board?
@raven halo
yeah

#

i am having this bug

raven halo
#

@sterile viper Yeah sucks man, not sure how to fix it - I tried to restart the service as well as running the binary

#

Is there someone we can talk to, to fix it

sterile viper
#

yeah moderator maybe

stiff egret
#

@sterile viper Yeah sucks man, not sure how to fix it - I tried to restart the service as well as running the binary
@raven halo 1. You are not supposed to toggle with the King service. That is out of scope.

#
  1. As far as I know, I believe that someone in the game borked the king.txt file. And hence there must be some deadlock on it, because of which King service was not able to read it.
#

Iirc you have to execute some binary after putting your name in king file.
@runic quail No, you don't have to do anything like that, simply adding your name to king.txt is all you need.

sterile viper
#
  1. As far as I know, I believe that someone in the game borked the king.txt file. And hence there must be some deadlock on it, because of which King service was not able to read it.
    @stiff egret
    naaa
#

file is good

#

checked everything

stiff egret
#

Yeaaa, because you can't "see" deadlocks.

sterile viper
#

there must be a bug with king service

stiff egret
#

As much as I know, There is not.
You can read the code if you like.
It's a public repo by James.

raven halo
#

so how do you fix it? Ive been in a couple of games that happened like this

#

tbh, im only on try hack me for the koth, no other places have it as far as i know

stiff egret
#

You simply reset. (In worst case senario.)

raven halo
#

I've reset, still doesnt work - then what?

stiff egret
#

tbh, im only on try hack me for the koth, no other places have it as far as i know
@raven halo I am playing it from the time it was released and no, there is no such bug. Or if there is, then I don't know how I didn't encounter it.

#

I've reset, still doesnt work - then what?
@raven halo Think about it, reset is the nuclear option, if that doesn't work then you are doing something wrong.

raven halo
#

ok Thanks

stiff egret
#

Think about it like this, you have a phone, you can't get signal,
Reset is like buying a new phone.
If you can't get signal after reset then that means something is wrong from your side.

raven halo
#

Thanks man, i got it the first time lol

stiff egret
#

Thanks man, i got it the first time lol
@raven halo ๐Ÿ˜๐Ÿ‘

vast kite
boreal flare
#

My name's been on the king file for like 10 mins

#

but no king time

brazen cloud
#

Is port 9999/the king service runnig?

#

Also, ensure that there's no whitespace after your username like when you press the spacebar, etc

boreal flare
#

yes it is running.....and im echoing into the file so no scope for a space

#

same for the other guy with me

brazen cloud
#

Are you lostayush by any chance?

boreal flare
#

Yes!

#

is something the matter ...?

brazen cloud
#

Mhm I'm not sure, it might be worth voting to reset - It looks like you've got a username in the king file okay

#

the match is saying no one's been king yet

boreal flare
#

The machine's already been reset for 2 times