#koth
1 messages ยท Page 44 of 1
Although, there were king changes for "production" yesterday
i had the same issue yesterday with panda box
Mhm yeah I've just started a private match to test a theory
ahh..
Could you DM me the IP address of the box please?
sure one sec..
Thanks ๐
Anyone up for a koth?
Joined in :)
Hello mr holmes!
Hey!
How are you doing ?
Sure shoot!
Thanks!
So i tried creating the binaries..just like yours and they dont seem to work
which language have you used ?
I made in c and python, which binary were you trying to make?
DM me, they are a bit of spoilers.
okay..
anyone to play
?
Count me in!
done
urgh offline
This is hard...
no offence to the creator, but I hate this box
(offline)
(probably because I don't know windows
)
Well you're king..and you say u dont know windows...(maybe that's what humility is)
well getting to admin account is skill itself
this box is eternally slowwwwwww
i have tried that multiple times..(earlier..not now)
i never seem to get it to work
its 1/4 chance
ahh..
i'll try again maybe i'll get a shell
its 1/4 chance
that's why it took you 10 mins to get king..(i get it now)
that's why it took you 10 mins to get king..(i get it now)
@boreal flare exactly
after 4 minutes, you can't beat me in this box
I'll be king for 31 minutes
GG
aren't you going to submit the flags?
Since he is king, I gotta submit them at the last moment, that'll put me on top
Sure
This is an unknown place for me, I don't have any idea of windows commands, at all
tactical win
dam it

I were so close
-_-

F
Tho it was fun, I was googling every command 
Dude I was trying to make while loop and realised I don't know shit in windows
ยฏ_(ใ)_/ยฏ
fight me in linux 
I was soooooooo clooooooose as hell
50 pts
fight me in linux
@stiff egret maybe tomorrow
Yeah Gotta sleep, It's 3:30 AM here
lol
1:59
and you can't exit it 
anyone want to join: https://tryhackme.com/games/koth/join/491bb8f053cae2f29ad45ff6
anyone playing Koth
Anyone wanna join in?
starts in 10 min
Is there a room you knit easily?
@cerulean sparrow how can i join
claick
by clicking on the link mate
@cerulean sparrow how can i join
@fair adder
am in and who are my team mates or against each other
F
xD
my terminal right now
if you're not the one dev randoming people then who is
people want to know!!
who was the one urandoming everyone
dunno
join
atleast not publicly
found the binary
starts in 5 min
no, you'll just do that again lol
im trying to reverse it so i know what to do next time
xD..so youre scared
ahh...
/usr/bin/cmatrix
in that case...i'll improve myself too!
lol
gg @cerulean sparrow
XD
another day
2 years of batch scripting are worthy ๐
why dont you search for flags ??
ok
Hop in
Ping me @stiff egret if u play another:)
happens to the best of us mate

Hope it gets better and i beat u in the next game ๐
I made extra strong coffee today, in hopes that I'll be on system for about 7-8 more hours
Now I have no internet and no sleep
I got my net back, ping me if anyone plays!
not you
Fun match vibes exit, its offline
Gonna be good
xD
can i have the spectator link?
Yep
not this one lmao
This is cheating...xD

I hate this damn exploit
there's an option to leave the room
I used that option
can't time be less
there's an option to leave the room
I used that option
i thought that you were in the game..lol..i left too ๐
That'll be a private game, (for less time)
just when 10s were left
That'll be a private game, (for less time)
@stiff egret how
how did someone already alter the king.txt file?
no me
are the ||creds|| even right for the ||remote desktop|| that you find in ||samba||?
yeah and that's a spoiler.
I have tried this room twice using that with no luck. Either i'm slow or not reading them right
something to do with ||tazers||?
That would be nice, but I think the creator should fix them too. I think that would save me an eternity...
Who is deleting flags?
In which machine?
offline
yeah i know. nostalgia hit me like drugs lol
what is this?
- That's not me.
- You removed all binaries.
no
not me
i dont delete anything
nvrmnd.. someone moved most of the binaries.. not sure moved or deleted..
someone removed most of the binaries before i got root
reset if you want
@true needle The moves you did are, well, very dumb.
i swear i didn't move anything
Removing binaries is not the way to win.
i said i did not
most of the binaries were already removed before i get root
if it was not you it could be someone from those other two
whoever was using nyancat or urandom on my shells
GG man. No point trying in a box with almost all binaries gone.
spam killing shells is allowed?
removing all binaries is allowed?
i mean you play "Among us" and you still can't find the imposter?


you me-er with f
LOL That was fun
๐
๐
planning to move to Italy next year
You serious?
yeah
ayyy all the best!
planning it out with friends. we all gonna move together.. its not even that much expensive and scholarships and all that stuff
looks nice
planning to do Masters in Cyber Security from there. and study for certs meanwhile
damn man, noice,
we all talked with a guy who do this kind of stuff. he said it gonna cost you 5 lac for first year(fees+visa)
for now we are 80% sure to move to only. lets see how it goes.. have like a year to plan things out
what is this?
@true needle try to add 2>/dev/null
KOTH is hard...


๐
chmod -x $(which chmod)
anyone around? I am down to try again ๐
@fair agate
join that one it loads in 5 minutes (faster than 20)
Thanks!
I am in bro!
https://tryhackme.com/games/koth/join/aa0927509fb06ea29b61f766
@vocal shell can anyone help me on how to get the first flag cos i dig up but couldnt find any
is anyone on the box rn?
yes
nope
hmm
I am still working on getting the first flag...
how do you get root but not the first flag
I do not have root
this is my second time doing this one, and I got a webshell ๐
i found flags but i can't read them
same
wow i spent an hour and i didnt even root it lmao
i couldn't, there is only one way
o lmao
this guy
inputs all his flags
ogey...
only gets 4 flags
Which box?
Sorry haha i just patch one way the most common one using tmux
And i had other flags but had to go xD
@vocal shell dm me
Tbh i dont know but there are always more than one way in koth
dm me
@grand ember teach me too
@nova tide you wish 

@nova tide How did project defence go? 
they said 4 practicals are not enough.. add more

How many machines are in koth
count the amount on the right
that's the current rotation
I thought Szy shared a KOTH match link.
Anyone up for a koth rn?
@stiff egret You are learning Tex formats? What does your template look like
Very f'ed up.
learning is not the right word
struggling and failing very miserably should cover that.
can we go to PM?
or go to a channel othe than koth
What tek engine/ui you are you trying (echo? )
I installed tex dependencies to my system and now using vscode to compile
can we go to PM?
@inland sluice nothing much to talk about, I have almost given up on it.
do you have a pretty resume in word format already?
Or no pretty resume at all. just a bunch of gobblygook
LIke, are you just working on converting to tex, or writing something completely from scratch w/ a completely alien method
LIke, are you just working on converting to tex, or writing something completely from scratch w/ a completely alien method
@inland sluice yee, trying to make a good looking one in an entirely new method
I supported our researches tex needs for ... 12 of my 14 yrs i worked there
I already have a resume in docs template. but wanted to make one in tex
I am very new to this, started trying it a month back when CMN posted about it in resources.
May i suggest you try a different tex environment, something with more wysiwyg results
oh, ๐ค
try like overleaf
its like you are having to create two things simultaneously, both of which will have to be nearly perfect if you are not to end up discouraged
like rolling two dice, and if you don tget a perfect 6-6 .. you get frustrated
Oh
does that make sense?
If this advice helps, create a redacted template, one without company/personal names, but duties/skills intact! would love to see it
Sure, Can I ping you If I make something and need some help on it? (regarding tex)
Who want to do a KOTH ? Like right now
i say exploded, but i smacked w/ an aluminum ladder, and it did what you woudl expect ap iece of cheap glass w/ a metal screw going through the middle of it to do
@inland sluice u h uh, Take care โ๏ธ
This is my first game on tyler
same
Am in! xD
all the bestโ๏ธ
@ruby arch please don't dump spoilers in here
ight sorry for that
@stiff egret How goes your online tex experience
In a A/D CTF atm. Gonna try it later tonight ๐
attack/defend? team vs team or something?
Yeah, internal CTF b/w teams
give em hell, ๐
An online platform for learning and teaching cyber security, all through your browser.
anyone free to join ?
isn't this considered attacking somebodys shell?
@livid dagger There's not a rule against attacking someone's shell
well, attacking user I meant
because it blocked my terminal
I'm not mad
I actually think it's hilarious what it's doing
and whatever it did, it actuall f*ucked up my terminal literally
well, attacking user I meant
@livid dagger It's not. The shell exists entirely on the KoTH box and doesn't affect their machine
They're not attacking your machine, it's not against the rules.
Also, no need to swear. At all. Trying to censor it doesn't change that.
mk
..lol...!
sorry mate
isn't this against rules?
i get instantly disconnected
not complaining just asking :))
Have you read the rules?
scroll down a bit and read the rules:
https://tryhackme.com/games/koth
I recommend reading the rules.
It's not a DoS against the machine
The machine remains fully functional.
No service is denied.
ahh..ok sorry about that..
allright, we gotta come up with a plan here... two v one??
have you voted?
can I dm you?
lol why is this 2v1 ? xD
yes
xD
you can
bahahah
dm me if you want
almost*
GG all
GG!
hey naughty :)))
@nova tide is this your doing there was an error running your commandError: spawn /bin/sh ENOENT
yeah?
ope
for some reason i couldn't nano/vi
or like edit any files lmao
can i dm u rq
yeah
geegee naughty
Yep
did you just imagine that Bashert is not my alt?
time to call @true needle
2 minutes to start
hop in people (not you alexa/naughty)
Leaving
I was just sending another link
it's gonna be prolly 22 minutes
thats fine bruh (24 tbh) we can play tom
๐คทโโ๏ธ waiting for the update to get that start button
Dang cuz of joining a new room forgot to sumbit my flags in the room which was just a min to complete
and i have lost
Ah nvmnd it was fun
lol
Only one guy other than me was root
lost by 10 seconds
Gn man, cya tom
now 0m 38s
that guy was good
at least you won! can you tell how you patched it at least i can learn from that
@fair adder for which machine?
https://tryhackme.com/games/koth/join/f050290af4b5990462c12d6e ongoing game i've locked down the box you can't get in @ anyone
lol
i want to play another one i cant be n two and i dont want to lose any
how did you get the first flag
for which machine
that machine
how is that possible
i'm an Emperor
how can access File uploaded /images/?
how can access: navigate to the /images/ directory?
lol
that's how?
i can't find the sixth flag ๐ฆ
Not Found
The requested URL /images/ was not found on this server.
that means there's no images directory that is found on the server
but i was able to upload a shell
<!DOCTYPE html>
<html>
<body>
<div align="center">
<form action="" method="post" enctype="multipart/form-data">
<br>
<b>Select image : </b>
<input type="file" name="file" id="file" style="border: solid;">
<input type="submit" value="Submit" name="submit">
</form>
File uploaded /images/?</div>
</body>
</html>
on tyler?
is just a text output telling it was uploaded to </form>
File uploaded /images/?</div>
there's no way you're priv escing
i think it just ended
rip
who'd u log in as
did you just upload a reverse shell?
anyone playing koth tayler machine
Is there one running @fair adder
yes
anyone to help me navigat to this File uploaded /images/?
source code does not show anything
reset the time @raven halo
OMFG @snow isle gg we all lose
its lost if youre reffering to me
GG!
lol
im trying to reverse your nyancat and parrot
i see .bashrc
i cant have you coming into the box
im sorry
lol
public game starting in 12 minutes:
https://tryhackme.com/games/koth/join/e2a988d1e18660055b5264d4
i cant have you coming into the box
@raven halo lets learn together...howd you do that ?
dm me
killing ssh ?
nvrmnd can't play.. peace out
Join in if anyone's up for a koth
21 mins to start guys! join in if u can
Congratz Mr Holmes!
๐
for the KOTH staff role
ah That lol, ty :)
๐
i need to get a copy of all the binaries when playing with you xD
i'll host my bin with python server xD

lol that was a lot of writing



smh i'm on the box this time
well there's no find binary so it'll take time
I didn't blow it this time
ahh its just perm denied
ummm...dont know whats happening in that case
Oh, I think that is intended.
well cant change perm either
Are you root?
Ah, nice one
||cat evil_script.py||
@stiff egret this was such a waste of time xD
What were you trying to do in that?
i've successfully wasted 20 mins of my time..!
so far
did i skip the priv esc smh?
LOL no, I think there are 2 methods unpatched for priv esc. (atm)

GG!
GG
You sure it's ||(only)|| immutable?
xD
uh huh
Oh damn. How the hell did I lose my 12 day streak.
i tried real hard this time to get rid of some of your stuff
but do you still have some stashed away?
https://tenor.com/oxZC.gif
@stiff egret oops!!
i give up...can't surpass you in this life time
No pg13 rating to the face ๐

In case you downloaded my binaries, some of them are infected to send me rev shells. Don't run them on your system.
@boreal flare
xD
it's too late
i ran them like weeks ago
tried to learn rev engineering for that
but ....๐คฏ
One of these days, I'll plant a rm -rf / in one of the binaries. 

did i get even one of your shells?
um, right now?
yeah like in past 5 mins
I had no shell. I thought everyone left the game. So I closed my terminal
-_-
Um. Maybe bashert
I don't have ttys..
@ruby arch
ahh...i saw several backdoors in logs
what logs are you looking at
That wasnt me
i need a few hours im at work
ah, sadly our time zones doesn't match.


Nah. You want to?
im donw
Anyone who wants to hop in
starting in 5 mins
If anyone is interested im in a public game feel free to hop in then
lolol
holmes
holmes sir
u gotta be cheating sir
how u getting flags bruh
ur not on
u just know where they are
I got them when I was on machine 10 minutes ago, when you hardcore patched it.
anyone looking to play?
Plus I think you did some borderline legal patches.
like what
I didn't get enough time, but I will log them next time.
bad
boi
there are 8 flags total
i still havent found the other 4
if i did i would've won, i had lots of time to
good game regardless
Indeed.
im confused as to what type of patching you think i did
Something around ssh.
that wouldn't be true i havent figured ssh out on the koth boxes
i didn't touch the ssh file
i actually thought you did something
because it wouldn't let me connect
but i think that was the time around the reset
I didn't get enough time, but I will log them next time.
@stiff egret ^^
ยฏ_(ใ)_/ยฏ
did i ever kill your shell
Nope.
ยฏ_(ใ)_/ยฏ
(I was king before reset for 28 mins. I am not that pro to get king without shell)

cries in 24 minutes
GG! good night dude
anyone want to play
join 
No I won't 

koth anyone?
sounds good
lets go
@raven halo
is that the spectator link
there we go
starts in 2 min
lol someone keeps on kicking me out
All KoTH machines will have at least 4 ways in @raven halo
i didn't change any password i get an authentication error
wait no way at least 4 ways!?
describe what you're trying to do
i haven't patched anything ๐
well maybe
Retype new UNIX password:
passwd: Authentication token manipulation error
passwd: password unchanged
rip
idunno how to fix?
Eh, someone could have done that purposely, it's a defence nonetheless.
i'm the only one on the box
(you can't see others, doesn't mean they aren't there.)
hermes ๐
i know
great
Ping me in next game. I'll join as well. :)
lol @polar light tell me not to cat the flag.txt then continue to change the password for hermes ๐ฆ
(wrong tag
)
sure..
if i could change passwords then uh game would be over
i haven't patched like anything lol
@vocal shell screenshot id?
sure
i fixed it btw
just now
alright people in koth only way in is via a reverse shell
Or wait until the autogen changes those passwords back
autogen :o?

How do you think the passwords change every game?
I put some fun tricks in that box, which is why we now have a bunch of scripted boxes
oh that's what you mean
Did you create it @terse willow
Fortune? Yes
ok
I only found 2
4 at the very least.
do you want a user @raven halo
its ok, no point
GG
trying to find out the other 3 footholds
im sure you can do something with port 80
๐ฆ
i have questions for you
when you got a shell how many seconds before i kicked you out
im sure you can do something with port 80
@raven halo a bunch of stuff
Changed some file permissions?
most certainly
Wunderbar
Wunderbar?
German for wonderful/excellent
GG
wait smokecode
you never answered my question
"when you got a shell how many seconds before i kicked you out"
hermes same thing kinda but a bit slower
i think because you knew I couldnt do anything because there wasnt any commands I could run
wait so when you got on
it didnt work afterwards when you kicked me out - yep
you couldn't run anything
correct
new game
interesting
^ new game for anyone im kinda tired but i wanna do one more
@stiff egret
Booting my VM.
๐ง
๐คจ
Screenshots are generally more helpful to explain your problem.
That is intentional on this box.
Actually it's not. It's a very common mistake people do on linux. You have to patch that bug and make it work.
i can't ping the box
ยฏ_(ใ)_/ยฏ
no it's not
VPN issues then
Koth-Staff is supposed to check on the people who are removing /usr/bin/* or chmod everything..
Also, don't leak your IP.
chattr is fine
Koth-Staff is supposed to check on the people who are removing
/usr/bin/*or chmod everything..
Uh huh...mr detective
PG-13
rated G for geveryone
just don't remove the binaries that are used to use the box?
Nope. Changed my payloads 2 days back. @boreal flare


๐ง
That means I can't do my stuff anymore?
Legit stuff
Like the ones I showed you
I forgot, send again? ๐
xD




