#koth
1 messages ยท Page 45 of 1
Not doing that mistake again :P
someone should make a persistence room for linux
King of the hill
lul no
That's 10+ machines for you
PayloadAllTheThings has everything you need
I can confirm again, ping is working.
https://github.com/swisskyrepo/PayloadsAllTheThings collection of cheatsheets for basically everything
Malware 
dont steal my trix
or ill uh steal yours 
ill steal yours regardless
heheehehehe mwahahahahha
lolol
is that ur doing smokecode

i cant change the king.txt ๐ฆ
lsattr /root/king.txt
+ia is prolly on it
immutable
someone reset machine
so i can maybe ping
and clutch up
Ping is working fine, for 3 other players.
it is on it but i cant chattr -i king.txt
You need to debug your VPN.~~ @polar light~~ @vocal shell
Because someone deleted chattr from the box.
that's not true
Statically compiled binaries are a thing
busybox has lots of buttons which one do i click for chattr
The one named chattr (?)
but there are several
ok i cant ping this box lol i tried downloading my vpn 3 times and i checked my internet (works) i can ping 10.10.10.10 but not the koth box ยฏ_(ใ)_/ยฏ
good bye
Maybe someone used an iptables rule to drop all pings?
but the box is fine and responding to pings.
Incorrect
ok so i scan the machine and then i cant access it
You can still access it
how
echo port and access ports are different
Someone was most likely dropping icmp packets
This does not mean the machine isn't working
is that ok
Windows by default drops all icmp echo requests
it ~is~ a linux box
I'm aware, but it's very easy to implement it on a Linux box as well
Yeah, go ahead
Can confirm, there are no iptables rules defined in this box atm.
ok so not iptables what about ufw ignore im tired
ufw is a front-end for iptables
GG HOLMS, dont think anyone is getting king.txt
ive tried but dont know how even tho im root
i suck
We are all here to learn. :)
yeah im trying to google if there are workarounds if chattr is not on the box
nothing so far
Um, I am assuming the most possible scenario here, I think you uploaded the chattr binary from your own box. You need to upload a static binary.
:)
Thank you
I mean, just upload busybox
@terse willow Stop sharing my strats
๐คทโโ๏ธ
TryHackMe is high bruh (jk just a glitch i guess)
Hi
Hye 
Naughty teach me your tricks. ๐ฅบ
wait for a week? ๐
Sure.
blog post will be coming soon.
also maybe i can stream in an hour or so if i wont fall asleep or play Siege
Can you share your blog?
also maybe i can stream in an hour or so if i wont fall asleep or play Siege
Ping me if you are available.
Official THM blog post.. it will be posted in #announcements
Okay, looking forward to it.
if anyone want to join
Still 23 mins to start guys join in!
koth anyone?
can anyone tell me how many peoples can be in a KOTH?
@fierce summit 10
oh ty
How can i get the users password? All I got is the ssh priv key and im in logged in as the user. any suggestions?
(not root)
User passwords are not stored in plaintext in Linux.
Most you can do is priv esc to root and get the users hash, and break it. Try to
If you got the ssh Priv key, that means it was intended that you Priv esc using only that.
Um. Please either mark it as spoiler or delete the message, as that is a spoiler for others.
@acoustic rover
alrighty thanks! will do!
join link for this ??
there is no options thing
The game is already running. You can only get join link if you are in the lobby.
You can ping those who are in room to get the link.
@raven halo
@raven halo link please
Alexa wants to join but too tired today 
guys can someone tell me please how we are 5 in koth , the machine is not responding at all and still someone got 4 flags? how ?
this is a public room FYI
gr
is he cheating ?
@thin gyro Check your VPN connection. The flags can be found in various directories on the server. Just enumeration and fix vulnerabilities
guys can someone tell me please how we are 5 in koth , the machine is not responding at all and still someone got 4 flags? how ?
@thin gyro Since flags are static, chance s are he had the flags stored from previous games.
I am root
lol
I dont think he is cheating..
there is no point to hack the machine if he already done that
Hacking is only one part.
You need to persist your presence in the machine. While others try to kick you out.
yeah i know that. thanks
(if it does any good, there's a new KoTH room being released, today probably)
I'm connected to the vpn, to be sure I started another machine on the hacktivites. I can ping to the machine. probably a network problem with this specifiec machine
thanks for helping
Is that a windows machine?
@thin gyro If you think that the problem is in the server, then we can reset server
Yes, well, the vote system is there for this point only. If you think box is actually broken, you can vote.
ill win the next one ๐
That's the spirit ๐
I am simply koth staff.
Not site. #522158404614225920 :)
@thin gyro Have you checked anonymous login via ftp?
Sorry just really wanted a reason to ping the role
@short tusk![]()
![]()
A user was accusing another user of cheating as they couldnโt access the machine, yet the other user had submitted flags
Did the accusation have any logical foundation to it? Or was it just a simple case of since I can't hack it, the machine is either broken or the other person is cheating?
@gusty cradle I wasn't cheating. I was getting flags on the path to root.
I also fixed vulnerabilities on the server in order to be the king of the hill longer.
Noted.
If anyone suspects that someone is cheating in a KoTH match, please email: koth@tryhackme.com.
We should get pin permissions as well in this channel since we're supposed to moderate
@quiet schooner
Also, Mods, I think the above msg should be pinned here.
Yeah, I'll bother Dark about the other thing, can you pin this message please: #koth message
@quiet schooner
I think he went to sleep ๐ฆ
Well 
I'm here I'm just not at home
Hello
Someone up for a koth ?
could you show a screenshot?
Send invite link
did you make them unavailable?
nope
๐คทโโ๏ธ ok
i think it's going to be hard to priv esc
I love how 3 of the avatars are people in hoodies
sure..
did you root it @raven halo
oh did you just || gdb ||
Hi there
smokecode answer ^^
I dont want to spoil for others
dm me then
starts in 19 mins
@south herald looks like only both of us !
ok
how's everyone doing
that's my fault i did that on accident
Also, @vocal shell , This is 2nd time I have noticed you doing that.
Changing the permissions of entire webserver directory essentially kills the service and should not be done.
agreed, i wanted to do something else
Focus on twice
i'm learning
This is the second time. Anyway. That being said, just don't do this again.
okie dokie sir
SMH no need of sir.
No. But server is.

ยฏ\_(ใ)_/ยฏ
No
i see someone on the box ;))
karios :ooo
checkmate
Hi.. I am new here.
Can someone please give me some basic idea.. about how do we play this?
If you're familiar with CTFs, its basically the same methodology coming in. However when you have root, you have to do your best to hold that position by patching the ways that you came in
DM me @main cobalt if you want to chat more or do a session together
anyone is up
@swift fossil please reset i just joined
So. @native plume or literally any mod. @cerulean sparrow just did something weird.I dont even know if he hacked the machine but he instantly went to 8 flags. This seems kind of off.
Game link is https://tryhackme.com/games/koth/10515
(oh. and the machine was offline while that happened by a reset)
I am sorry @acoustic rover but you have to contact koth mods, I guess.
But that sounds like autopwn.
I'll let Skidy know.
perfect thanks
Or any admin.
<@&756155733468512386> ๐
Having a look at what I can see from here
https://tryhackme.com/games/koth/join/e3486ebf41094465a8082fbd if someone wants to play
join me
i just made up a game @swift fossil
machine type
wanna talk while the koth?
I'm also in
yes
#koth-staff @winged charm (:
guys do you hear me ?
no
I don't know wht is the problem
@rancid pewter wanna join vc too?
English is not my primary language so my speaking is really bad
Can't turn on mic ๐ฆ
Hey @rancid pewter I'm kinda new to this, can I dm you to get some help for starting up?
Or anyone else currently in the room?
@cerulean sparrow what you did wasnโt necessarily against the rules but a little suspicious. Try not saving flags and make the game fun for everybody?
XD
what ?
everyone does this
as you said >> "wasnโt necessarily against the rules"
I mean, who are you really cheating here?
^
It's an underhanded trick designed to give yourself an advantage. In short, it's currently not against the rules, but morally speaking it's not exactly the characteristic of a nice person. ๐คทโโ๏ธ
Then everyone is equally morally decrepit. It's a good way of turning new players away, that's for sure.
We'll try to get autogens implemented ASAP, until then, just yell at people who do ๐
ok
๐ง
alright
the ones that played against me
@cerulean sparrow i will try to play against you some day soon ๐
๐ง
xD someone deleted their messages
does anyone know whether Dark is from germany or not?

whaaaaat
Ah, another flag hoarding issue.
@cerulean sparrow i will try to play against you some day soon ๐
@nova tide You already did before
@nova tide If you're the one who become king first then don't submit flags, I think yes you did that before
Anyone up for KoTH ?
KoTH anyone?
whos up for a koth
Join Fast
@south herald is that u on KoTH 10558 ?
yeah
so u think getting all the flags in 3 seconds(as u already played that box), and filling out all thos holes, is the purpuss of the game ?
i have been playing this machine in the past, but that's not the reason why i get those flags fo fast
@south herald that's not an explanation
what holes then?
i have been playing this machine in the past, but that's not the reason why i get those flags fo fast
@south herald oh god, this is why i ||fucking|| hate those KoTH machines, im out
lah yn3l tabon mok fhad sba7 3sbti zaml boya
care to tell me what i done wrong?
never mind
I'm taking a look into what I can see regards to 10558
naah @brazen cloud dont' bother its all good.
We're looking into overhauling the KoTH boxes for automated healthchecks of things that are against the rules amongst other things
As long as there's no complaints, it's still good for us to have a look at to begin to build a picture of how koth matches operate day-to-day
Makes sense.
guyz
join
@mint cargo sure ๐
y did u have to screenshot 
i will ghost ping and delete so fast that ur screenshot software wont be able to capture it.
pfft lol
๐
New KoTH box dropping soonโข๏ธ ๐
For once, once, this soon is actually soon!
noice
KoTH staff, what colour do you want the KoTH flair to be on Reddit?
red
@stiff egret @nova tide from the top of my head
i dont wanna ping all koth staff ๐
Do we get options?
yes
16 million colours
to be precise
any colour at all
i'm choosing colours not Dark so it can be literally anything ๐
I'd say, neonish-cyanmaybe?
We already have that
๐ฆ
1 sec
all current colours
i cant fix the font colour on new room as i am adding KoTH rn ๐ฆ
:(( Um you choice then! 
I went with gold :))
@stiff egret Do you answer questions about KoTH as part of being KoTH staff?
Yes.
So your remit extends past the Discord, which means if we get KoTH questions on Reddit it is KoTH staff's job to answer them? Sooo do you peeps want a user flair for KoTH staff on the subreddit? You won't get mod or anything, just a shiny badge to let people know you are KoTH staff ๐
Same goes for Forum (maybe, not forum staff) ๐
Confirming..
Might be best to ask Dark?
Yep, That's what I just did.
Ah great ๐
anyone wanna try hogwarts ?
You can directly ping him ๐ It'll be faster.
@mellow bough Am I right in thinking that because KoTH staff deal with KoTH, and support / questions for KoTh does not exist solely on the Discord, I can give them a badge / flair on Reddit since their role as KoTh staff also applies to the subreddit? Same for forum too, if KoTH questions pop up?
Their role as KoTH Staff is not Discord specific but applies to all discussions on KoTH, regardless of platform*?
Since it's a role that I'm letting grow naturally, sure
oooh~~~
@stiff egret do you mind asking everyone in KoTH staff for their Reddit usernames, and let them know I'll assign them a fancy Reddit KoTH user flair so people know they are KoTH staff? ๐
Will do and update you, I think most of them are offline atm.
Give me a moment, I'll post a list of the staff for you in the subreddit staff chat
New koth machine??
Yes
OOoOooooh


That would be a platform feature, and is still pending
The creds do change in Hogwarts though
~~Given I helped with the damn autogen ๐ ~~
The creds do change in Hogwarts though
@terse willow not only creds
Yep! That last command worked!
Is it like the staircases in Hogwarts?
โค๏ธ
I TOLD A LOT OF THEM THAT THEY ARE LIKE STAIRS
But smh
I take it you will understand HP references in the box
There are a lot
.... what a goofy box it is
can i send you a ping mr @stiff egret in a bit. wanted to ask about something on the box
correction. later... i am still poking aroudn at a few other things
Sure :)
anyone hogwart? >.<
ive just done hogward, anyone found all flags? im missing one
i found one but it says "wrong flag". it looks legit tho
ive just done hogward, anyone found all flags? im missing one
@near sphinx um. Its released yesterday, give it some time
i found one but it says "wrong flag". it looks legit tho
@near sphinx strange. ๐ค
ive just done hogward, anyone found all flags? im missing one
@near sphinx flags not naned flags
๐ท
Great Box @stiff egret ๐ฅณ

do passwords not work for Food box lmao
koth staff do passwords reset for the food box
for which user? @vocal shell
any
i changed creds for every single user including root yet pts/5 got root upon login maybe ssh key?
nah, you forgot to patch one more vulnerable service in there
i wasn't trying to patch
the services
i thought you guys gave up
LOL i didn't harden
the box
haha not really,we got in through there.
hahaha
got in through where
now im stuck
through high ports web server
kk i have to plug my laptop in charge
sure mate
it should work, pasta should work
grrr
dang thats close
koth staff do passwords reset for the food box
@vocal shell food is a static box, passwords remain same, until you change them.
ยฏ\_(ใ)_/ยฏ
GGs
not yet, you can ssh now through pasta
koth staff do passwords reset for the food box
๐คฆโโ๏ธ
well you guys were discussing it
Soonโข๏ธ

just doing uni stuff nowdays
well you guys were discussing it
@vocal shell it was about other box
@near sphinx reset?
sure why not
where are the flags ๐ฆ
all binaries are symlinked to /dev/null apparently
Share the spectator link?
GG my guy, h0j3n will win
1 more minute haha
all binaries are symlinked to /dev/null apparently
@near sphinx not on my machine atm. Still public reminder, this is NOT allowed.
this shouldnt be allowed right? @stiff egret
He did echo the PATH, @vocal shell
That means the intended hurdle you are referring to is already passed.
Binaries are messed up with, and yes, that's not allowed.
Look carefully in the screenshot.
he deleted it
DM me that? @near sphinx
im afraid it willspoil the box
i'm still on the box
@vocal shell u mean still have a session?
the box has ended like 5 minutes ago @vocal shell
thats weird
why are u inside /bin folder tho ahaha kidding my dude xD
Known bug, on reset, box expiration time also resets, hence box runs for 1 hour. Though game ends.
im inside /bin to check to see if i messed something up on accident
because i want to make sure that i'm playing within the rules
@thick coyote how'd u get all 8 flags 
grep + regex will do the trick
i cant tell. GG augustus. Lets play again sometimes. we can share knowledge and tricks 
gg @near sphinx ๐
im inside /bin to check to see if i messed something up on accident
@vocal shell you have been using accident for quite some time now

poor guy :[ he keeps resetting because i keep kicking him out
i feel like it's someones alt
Mind sharing the spec link?
how's everyone doing
who's that person sshing in
@stiff egret r u watching or something lol
No. I am not in game.
gg
@stiff egret has anyone ever got 60 minutes king time?
I mean, that would technically be a proof of autopwn.
ยฏ\_(ใ)_/ยฏ
Though it is possible. I don't remember any match with that stat.
My max was 57 minutes which I got once or twice.
https://media.discordapp.net/attachments/655499723050057731/700359905475035186/gg.png?width=958&height=642
but that was around the time that no one except me and a few others had completely pwned tyler
every single time on this box?
@vocal shell ?
can't change any users' password
Are you root?
O
Since, only root can specify usernames in the passwd command
euid
ยฏ_(ใ)_/ยฏ
i think i can get 59 minutes as king >:)
You can't on Hogwarts.
@gusty cradle my max time is 58 
I don't think you can get 59
why not 
Not possible?
another one?
i can't, playing among us
@nova tide next step is being king for the whole game
๐คทโโ๏ธ
i almost got 60/60
@vocal shell autopwn to the limit.. ๐
There are 3-4 players I know of, who can get 700 + more than maximum possible points.
(me, naughty, James, maybe szy)
Szy is always first in rooms so I think he would
I meant more than maximum possible
Well if you're the smartest one in the class then you're in the wrong class... @vocal shell
i'm not the smartest one in the class
(me, naughty, James, maybe szy)
These are pros and that's a different story..
There are 3-4 players I know of, who can get
700 +more than maximum possible points.
@stiff egret ^
._.
those guys are really talented people i'm not there yet
what do you mean by more than maximum possible points?
More than maximum possible points.
I meant exactly that.
on a koth box?
I've been trying all day to get Hogwarts....but never got it 
I've been trying all day to get Hogwarts....but never got it
@boreal flare All the best!
gib secwet on how getting more points in koth box 
It's your first box if I'm not mistaken?
Anyone for koth?
Anyone solve sixes vulnhub?
@wicked tartan this is for the king of the hill game mode in tryhackme please take that to #general
Sorry
Anybody solved hogwarts
Me too

beg holmes for the secret haxs

first need to get the on box tho..
TryHarder 
Bribe the creator 
hogwarts; what a machine! It's my first koth machine in the thm and no one could find a single flag .. but wow .. learned a lot
@noble flicker Really ? Can't wait to try it
guyz
anyone up for a koth
@swift fossil Maybe later
Ok I'm coming
thanks
anyone to play koth
. ใใใใใใใใโขใ ใ๏พใใใ ใใ.
.ใใใ ใใ.ใใใใใใใใ ใใ.
.ใใ ใใใใใใ เถ ใ . ใใ โข ใใใใโข
@stiff egret was The Impostor.
'ใใใ 0 Impostor remains ใ ใใใ
๏พใใใ.ใใใ. ,ใใใใ.ใ .
@nova tide check this lol
TryHarder :wrong:
Bribe the creator :right:
@stiff egret that's y ๐คฃ๐คฃ๐คฃ
@vocal shell can you dm me when you get a chance ๐
Send your GameID
found it, i still have a question about a specific file tho
Interesting..
@lucid quail who?
They vote to reset the machine
@lucid quail Nothing much can be done about that, It is a gentlemen's game.
@winged charm
@stiff egret I know but Iโm just saying that some players are idiots. They donโt respect others
Leave some vulns unpatched, and kick them when they get in. This will keep them from resetting
@lucid quail if it continues to happen and heโs purposefully doing it let one of the koth staff know and weโll look into it
new koth box
anyone wanna run it and have a go?
Aah resets.. good old days 
@fair adder Yeah let's do it
game starts in like 20 mins if anyone wants to play https://tryhackme.com/games/koth/join/76bb7e9ebc7a9860300b1154
hi guys ... game start in abous 22 mins .. https://tryhackme.com/games/koth/join/988ac6ff9ca1a67b885b698b
@fair adder what is the name of the new one?
Hogwarts
Anyone down?
Hiii
hye
Yo
one dude , changed all the 8 flags
user pprofile : https://tryhackme.com/p/Diesel
he probably didnt read the rules , please pardon him , just warn him
@stiff egret
mhm, You have any proofs that they changed the flags?
Is Diesel here?
Just send the data you have (username/ gameID ) to koth@tryhackme.com, Most probably, someone from the site will mail them a warning.
anyone awake? wanna play KOTH before i start class?
mhm, You have any proofs that they changed the flags?
Is Diesel here?
@stiff egret he changed all to THM{diesel}
the cureent room , he edited sudoer file
and removed current user from sudoer
hes spoiling rooms
please attend to this, the room in not fun at all ,
cuurent room : https://tryhackme.com/games/koth/10760
the cureent room , he edited sudoer file
@calm briar
That is totally allowed
@calm briar not much we can do about it right now, if youโre still in the game or if you play another game with them take screenshots and show us exactly what is happening so we can come to a fair conclusion. editing flags is against the rules however editing the sudoers file is perfectly fine
ok great, ill catch him next time and take screenshots, hes plays too dirty
Thanks for the help
@calm briar you guys aren't playing anymore ?
can i have the link?
whenever im root, the other user , corrupt my shelland ick me out
@tame veldt
ok, will share the link here
Cool
am here
@main verge @tame veldt ill start a room in 5 minutes , lets play
@tame veldt you seem like a pro!
Trust me i am not ๐
Hello guys , Diesel PM me , he didnt know about the rules , So we are cool now ๐
Should've read them before hand smh
@calm briar What is Diesel's discord?
@calm briar
Did u get answer for how to corrupt other players shell if so share it with me also pls
@dry dragon ill share with you once he teachs me
@calm briar thnks that's goona help me a lot
can anyone teach me how to corrupt other players shell
@calm briar I think this is how they do it
cat /dev/urandom > /dev/pts/pts-number 2>/dev/null, correct me if I'm wrong
Thats also a way to echo a message to then to troll lol i do that with my friend all the time xD
Echo "annoying txt here" | write username pts/#
Nice xD
heeeeeeeeeeeck
Did I miss Mr.Koth
everyone here keeps talking about him, but I never see him
how sad
I know their address!
You have to click on this button
Danke Mr
The heck
I never get to see Koth
everyone streams koth
but I've seen his face
...when will my koth hubby come back from war?
I think itโs because your experience level set in your profile is too low iirc
yo Iโm very confused right now
@brittle flicker did u use inspect element to trick us๐๐
goofy goober
NO! KOTH JUST HATES ME, BRING BACK MY KIDS KOTH!!!
hmm
link?
i think i need to beome intermdiate uesr to play
yes you should
Whoops, probably should have sent that
Thanks
im in
Nice
Joined this game real late๐๐
@calm briar fine
machine was so unresponsive
even though i got that exploit and ran it shell kept breaking
bashbuoy was killing the machine to retain king
ohh i c
on the offline box ?
is anonymous login allowed?
you see the pw in page source ?
the user should be offlineking
Koth was fun
Is there anyone playing koth now??
Not yet
already started though
xD
@muted forge XD
?
koth
ok
my internet is to bad http page isnt reloded yet
i scan with nmap,and gobuster now
machine dont return any response
try the ip again
ok
why is main page isnt loading
restart openvpn
it happens sometimes
sudo killall openvpn
then start it again
ok
it works !
it isnt work on my device
I'll give you a hint
you need to find an open port
then do the rest
greater that 1000
im i need to use -p-
you can the get even the root flag from there
where is the user fla
g
there is a directory called /flag but
in includes nothing on here
yes i found your port
ok do the rest
it's easy now
search for the message and do the rest stuff
you got it ?
i dont know how to exploit it
ok
the big suprise
it isnt loading
heh i done it
oppss
||koth looks like a cool guy :3||
Join in if any one would like to play 
Dang, bad timing for me. Let me know when you get another going
Makimg king flag hidden file isint against the rules right?
No, it is against the rules.
You cannot move or delete king.txt.
@light breach
Please give rules a read.
It'll also stop the king service from working, so offers literally 0 advantage
Someone can just make a non hidden file
Not move same dir just .king.txt
I mean just rename it to .king not move it thats cheating
...
Honestly asking for a friend so i can tell him not to
There are very specific things that need to happen with the file do not touch it except to put you name in
Okay thats what i thought
muir youโre a mad man
Now that makes sense technically speaking. Because the script running uses king.txt file okay cool. Man such a rad concept
Owl ๐
I've just planned out another Windows box though
Which might just involve Otters...
What..... are..... you.... guys.... talking .... about..... TELL....ME..!!
I asked Cry to take a look at my first Windows box last night, Holmes
for koth?
phew,
Ey!
just in a completely different box
๐คฃ
Wait is this an unreleased box we are talking about lol
๐
It is
just in a completely different box
@winged charm The one that tried to attack the attackbox?
Yep
You got into it? ๐คฃ
wohoooo
So who made carnage....?
Not asking for help just cant seem to figure it out lol nice work
anyone active now
@light breach Small warning -- there are currently 27824 people in here; all of whom would be alerted if that everyone ping had worked. Fortunately we're smart enough not to let people use it, but a little consideration maybe?
6 users increased in that much time. Noiceeee
anyone wanna play koth
@raven halo still around?
@light breach ill be back in an hour or so
2 mins
hogwarts is the bane of my existence
shoot bro i am doing one now got 12 left
bed after this tho
all good, this machine is hogwarts too - i did it yesterday and couldnt get anything
hopefully better thist ime
yeah its rough
random room public match u all are most welcome
20 mins to go


