#koth

1 messages ยท Page 45 of 1

vocal shell
#

send again to me too

boreal flare
#

Not doing that mistake again :P

vocal shell
#

someone should make a persistence room for linux

stiff egret
#

King of the hill

vocal shell
#

lul no

stiff egret
#

That's 10+ machines for you

gusty cradle
#

PayloadAllTheThings has everything you need

vocal shell
#

luv u ma1ware

#

koth is being mean

#

i cant ping

boreal flare
#

Lub blobheart

#

i cant ping
@vocal shell that's prolly smokecode

stiff egret
#

I can confirm again, ping is working.

gusty cradle
vocal shell
#

are koth staff able to see what people do on the machines

#

also thank you ma1ware

boreal flare
#

Malware blobheart

vocal shell
#

dont steal my trix

#

or ill uh steal yours blobknife

#

ill steal yours regardless

#

heheehehehe mwahahahahha

raven halo
#

lolol

vocal shell
#

is that ur doing smokecode

raven halo
vocal shell
#

ok but my thing wasn't THAT bad

#

you could still ping

raven halo
#

i cant change the king.txt ๐Ÿ˜ฆ

vocal shell
#

lsattr /root/king.txt

#

+ia is prolly on it

#

immutable

#

someone reset machine

#

so i can maybe ping

#

and clutch up

stiff egret
#

Ping is working fine, for 3 other players.

raven halo
#

it is on it but i cant chattr -i king.txt

stiff egret
#

You need to debug your VPN.~~ @polar light~~ @vocal shell

raven halo
#

lol

#

apt install e2fsprogs
tells me to install that

#

everytime i do chattr

stiff egret
#

Because someone deleted chattr from the box.

vocal shell
#

that's not true

gusty cradle
#

Statically compiled binaries are a thing

vocal shell
#

busybox has lots of buttons which one do i click for chattr

stiff egret
#

The one named chattr (?)

vocal shell
#

but there are several

#

ok i cant ping this box lol i tried downloading my vpn 3 times and i checked my internet (works) i can ping 10.10.10.10 but not the koth box ยฏ_(ใƒ„)_/ยฏ

#

good bye

gusty cradle
#

Maybe someone used an iptables rule to drop all pings?

stiff egret
#

but the box is fine and responding to pings.

vocal shell
#

i think so ma1ware

#

responding to your pings

gusty cradle
#

Did you try scanning with nmap?

#

With -Pn

vocal shell
#

i didnt bother

#

if i cant ping the machine, nmap wont work

gusty cradle
#

Incorrect

vocal shell
#

ok so i scan the machine and then i cant access it

gusty cradle
#

You can still access it

vocal shell
#

how

stiff egret
#

echo port and access ports are different

gusty cradle
#

Someone was most likely dropping icmp packets

#

This does not mean the machine isn't working

vocal shell
#

is that ok

gusty cradle
#

Windows by default drops all icmp echo requests

vocal shell
#

it ~is~ a linux box

gusty cradle
#

I'm aware, but it's very easy to implement it on a Linux box as well

#

Yeah, go ahead

stiff egret
#

Can confirm, there are no iptables rules defined in this box atm.

vocal shell
#

ok so not iptables what about ufw ignore im tired

gusty cradle
#

ufw is a front-end for iptables

raven halo
#

GG HOLMS, dont think anyone is getting king.txt

#

ive tried but dont know how even tho im root

#

i suck

stiff egret
#

We are all here to learn. :)

raven halo
#

yeah im trying to google if there are workarounds if chattr is not on the box

#

nothing so far

stiff egret
#

You can upload your own chattr to box.

#

This has been mentioned before a lot.

raven halo
#

i have tried that as well

#

but couldnt get it to run in /usr/bin

#

chmod +x it too

stiff egret
#

Um, I am assuming the most possible scenario here, I think you uploaded the chattr binary from your own box. You need to upload a static binary.

raven halo
#

oh

#

where do you get it from

#

found some on github

#

thanks

raven halo
#

thanks heaps

#

hopefully i can use this in my arsenal next time

stiff egret
#

:)

terse willow
#

I mean, just upload busybox

#

You get the lot in one ๐Ÿ˜

raven halo
#

Thank you

nova tide
#

I mean, just upload busybox
@terse willow Stop sharing my strats blobknife

terse willow
#

๐Ÿคทโ€โ™‚๏ธ

ruby arch
ruby arch
scenic rune
#

Hi

nova tide
#

Hye animewave

ruby arch
#

Anyone wanna play koth?

#

Ping me if anyone's up for a koth

runic quail
#

Naughty teach me your tricks. ๐Ÿฅบ

nova tide
#

wait for a week? ๐Ÿ˜›

runic quail
#

Sure.

nova tide
#

blog post will be coming soon.

#

also maybe i can stream in an hour or so if i wont fall asleep or play Siege

runic quail
#

Can you share your blog?

#

also maybe i can stream in an hour or so if i wont fall asleep or play Siege
Ping me if you are available.

nova tide
runic quail
#

Okay, looking forward to it.

sly turret
#

if anyone want to join

ruby arch
#

Still 23 mins to start guys join in!

vocal shell
#

koth anyone?

fierce summit
#

can anyone tell me how many peoples can be in a KOTH?

winged charm
#

@fierce summit 10

fierce summit
#

oh ty

vocal shell
acoustic rover
#

How can i get the users password? All I got is the ssh priv key and im in logged in as the user. any suggestions?

#

(not root)

stiff egret
#

User passwords are not stored in plaintext in Linux.
Most you can do is priv esc to root and get the users hash, and break it. Try to

#

If you got the ssh Priv key, that means it was intended that you Priv esc using only that.

stiff egret
#

Um. Please either mark it as spoiler or delete the message, as that is a spoiler for others.

#

@acoustic rover

acoustic rover
#

alrighty thanks! will do!

cerulean sparrow
#

join link for this ??

stiff egret
#

Click on options on the upper right corner.

#

There is an invite link.

#

@serene bay

cerulean sparrow
#

there is no options thing

stiff egret
#

The game is already running. You can only get join link if you are in the lobby.

#

You can ping those who are in room to get the link.

#

@raven halo

cerulean sparrow
#

@raven halo link please

nova tide
#

Alexa wants to join but too tired today darkchamp

cerulean sparrow
#

:/

#

dam

thin gyro
#

guys can someone tell me please how we are 5 in koth , the machine is not responding at all and still someone got 4 flags? how ?

#

this is a public room FYI

short tusk
#

<@&756155733468512386>

#

Sorry just really wanted a reason to ping the role

winged charm
#

gr

short tusk
#

But for real

#

You should probably get on that

thin gyro
#

is he cheating ?

short tusk
#

What's the join link

#

Or spectate link idk

thin gyro
low mango
#

@thin gyro Check your VPN connection. The flags can be found in various directories on the server. Just enumeration and fix vulnerabilities

thin gyro
#

my vpn is up and running

#

no probs with my vpn

stiff egret
#

guys can someone tell me please how we are 5 in koth , the machine is not responding at all and still someone got 4 flags? how ?
@thin gyro Since flags are static, chance s are he had the flags stored from previous games.

low mango
#

I am root

thin gyro
#

lol

#

I dont think he is cheating..

#

there is no point to hack the machine if he already done that

stiff egret
#

Hacking is only one part.

#

You need to persist your presence in the machine. While others try to kick you out.

thin gyro
#

yeah i know that. thanks

stiff egret
#

(if it does any good, there's a new KoTH room being released, today probably)

thin gyro
#

I'm connected to the vpn, to be sure I started another machine on the hacktivites. I can ping to the machine. probably a network problem with this specifiec machine

#

thanks for helping

stiff egret
#

Is that a windows machine?

low mango
#

@thin gyro If you think that the problem is in the server, then we can reset server

thin gyro
#

its ok mate

#

thanks

stiff egret
#

Yes, well, the vote system is there for this point only. If you think box is actually broken, you can vote.

thin gyro
#

ill win the next one ๐Ÿ™‚

stiff egret
#

That's the spirit ๐Ÿ™‚

thin gyro
#

btw , great job guys

#

great site

stiff egret
low mango
#

@thin gyro Have you checked anonymous login via ftp?

gusty cradle
#

Sorry just really wanted a reason to ping the role
@short tusk angrycooctus angrycooctus angrycooctus

short tusk
#

Malware you shouldโ€™ve been here smh

#

There was an issue

gusty cradle
#

What was the issue? ๐Ÿง

#

@short tusk

short tusk
#

A user was accusing another user of cheating as they couldnโ€™t access the machine, yet the other user had submitted flags

gusty cradle
#

Did the accusation have any logical foundation to it? Or was it just a simple case of since I can't hack it, the machine is either broken or the other person is cheating?

low mango
#

@gusty cradle I wasn't cheating. I was getting flags on the path to root.

#

I also fixed vulnerabilities on the server in order to be the king of the hill longer.

gusty cradle
#

Noted.

#

If anyone suspects that someone is cheating in a KoTH match, please email: koth@tryhackme.com.

stiff egret
#

It's resolved I think.

#

Also, Mods, I think the above msg should be pinned here.

gusty cradle
#

We should get pin permissions as well in this channel since we're supposed to moderate

stiff egret
#

@quiet schooner

quiet schooner
#

I can't

#

I don't think

gusty cradle
#

Also, Mods, I think the above msg should be pinned here.

#

Yeah, I'll bother Dark about the other thing, can you pin this message please: #koth message

#

@quiet schooner

#

I think he went to sleep ๐Ÿ˜ฆ

#

Well animewave

quiet schooner
#

I'm here I'm just not at home

vocal shell
vocal shell
#

did you guys give up

#

the people in my game

raven halo
#

lol

#

you delete ls and chmod

rancid pewter
#

Hello

winged charm
#

Hey Donut

#

you delete ls and chmod
@raven halo ?

rancid pewter
#

Someone up for a koth ?

raven halo
#

i was talking to August

#

i cant cat ls chmod etc

winged charm
#

could you show a screenshot?

raven halo
vocal shell
#

i didn't delete them

#

staff you may check

raven halo
#

๐Ÿ™‚

#

ok

rancid pewter
#

Send invite link

winged charm
#

did you make them unavailable?

vocal shell
#

nope

winged charm
#

๐Ÿคทโ€โ™‚๏ธ ok

raven halo
#

maybe i just need to try harder

#

anyway gg

vocal shell
#

i think it's going to be hard to priv esc

winged charm
#

I love how 3 of the avatars are people in hoodies

raven halo
#

sure..

vocal shell
#

did you root it @raven halo

raven halo
#

yes

#

i left anyway, not playing anymore

vocal shell
#

oh did you just || gdb ||

pure hazel
#

hi guys

#

im new here

raven halo
#

Hi there

vocal shell
#

smokecode answer ^^

raven halo
#

I dont want to spoil for others

vocal shell
#

dm me then

cerulean sparrow
#

starts in 19 mins

cerulean sparrow
#

@south herald looks like only both of us !

vocal shell
#

i will join

#

let me boot up machine

cerulean sparrow
#

ok

vocal shell
#

how's everyone doing

cerulean sparrow
#

maaaaaan

#

@vocal shell what ??!!!!

vocal shell
#

that's my fault i did that on accident

cerulean sparrow
#

ok

#

fix it now !!!

vocal shell
#

i uh

#

um

#

reset

#

fatal error

stiff egret
#

Also, @vocal shell , This is 2nd time I have noticed you doing that.
Changing the permissions of entire webserver directory essentially kills the service and should not be done.

vocal shell
#

agreed, i wanted to do something else

stiff egret
#

Focus on twice

vocal shell
#

i'm learning

stiff egret
#

This is the second time. Anyway. That being said, just don't do this again.

vocal shell
#

okie dokie sir

stiff egret
#

SMH no need of sir.

vocal shell
#

psi did you patch already

#

@stiff egret are you logging my commands ๐Ÿ™„

stiff egret
#

No. But server is.

boreal flare
stiff egret
#

ยฏ\_(ใƒ„)_/ยฏ

vocal shell
#

that's kinda what i mean

#

are you reading them..

stiff egret
#

No

vocal shell
#

i see someone on the box ;))

vocal shell
#

karios :ooo

cerulean sparrow
#

checkmate

vocal shell
#

oh ur still playing? i left

#

lmao

#

HGAHAHA

#

i thought u gave up

cerulean sparrow
#

doesn't matter

#

I won

#

I do never give up

vocal shell
#

you lost

#

good game

main cobalt
#

Hi.. I am new here.

#

Can someone please give me some basic idea.. about how do we play this?

raven halo
#

If you're familiar with CTFs, its basically the same methodology coming in. However when you have root, you have to do your best to hold that position by patching the ways that you came in

#

DM me @main cobalt if you want to chat more or do a session together

main cobalt
#

Yeah I'm familiar with CTFs

#

Yup I'll DM

swift fossil
#

anyone is up

acoustic rover
#

@swift fossil please reset i just joined

acoustic rover
#

So. @native plume or literally any mod. @cerulean sparrow just did something weird.I dont even know if he hacked the machine but he instantly went to 8 flags. This seems kind of off.

#

(oh. and the machine was offline while that happened by a reset)

native plume
#

I am sorry @acoustic rover but you have to contact koth mods, I guess.

#

But that sounds like autopwn.

#

I'll let Skidy know.

acoustic rover
#

perfect thanks

native plume
#

Or any admin.

barren stream
#

<@&756155733468512386> ๐Ÿ˜‰

brazen cloud
#

Having a look at what I can see from here

acoustic rover
swift fossil
#

join me

acoustic rover
#

i just made up a game @swift fossil

swift fossil
#

machine type

acoustic rover
#

wanna talk while the koth?

swift fossil
#

ok

#

come

acoustic rover
#

where

#

im in KOTH vc

swift fossil
#

ok brother

#

wait i cant talk

#

i ll be with you

main cobalt
#

I'm also in

winged charm
#

Ooooo

#

Do I get to do things

acoustic rover
#

yes

brazen cloud
cerulean sparrow
#

guys do you hear me ?

acoustic rover
#

no

cerulean sparrow
#

I don't know wht is the problem

acoustic rover
#

@rancid pewter wanna join vc too?

rancid pewter
#

English is not my primary language so my speaking is really bad

main cobalt
#

Can't turn on mic ๐Ÿ˜ฆ

#

Hey @rancid pewter I'm kinda new to this, can I dm you to get some help for starting up?

#

Or anyone else currently in the room?

winged charm
#

@cerulean sparrow what you did wasnโ€™t necessarily against the rules but a little suspicious. Try not saving flags and make the game fun for everybody?

cerulean sparrow
#

XD

#

what ?

#

everyone does this

#

as you said >> "wasnโ€™t necessarily against the rules"

terse willow
#

I mean, who are you really cheating here?

winged charm
#

^

cerulean sparrow
#

no one cheated guys

#

calm down

terse willow
#

It's an underhanded trick designed to give yourself an advantage. In short, it's currently not against the rules, but morally speaking it's not exactly the characteristic of a nice person. ๐Ÿคทโ€โ™‚๏ธ

cerulean sparrow
#

I'll say it again "Everyone do it"

#

the ones that played against me

terse willow
#

Then everyone is equally morally decrepit. It's a good way of turning new players away, that's for sure.

cerulean sparrow
#

ok understood

#

never do it again

#

I promise

terse willow
#

We'll try to get autogens implemented ASAP, until then, just yell at people who do ๐Ÿ™‚

cerulean sparrow
#

ok

gusty cradle
#

๐Ÿง

fair adder
#

alright

boreal flare
#

Sorry man....gtg!

#

Will play next time

cerulean sparrow
#

@rancid pewter that was hard

#

i was trying openssl

#

but i ran out of time

nova tide
#

the ones that played against me
@cerulean sparrow i will try to play against you some day soon ๐Ÿ™‚

tepid hornet
#

Wrong channel

#

-_-

gusty cradle
#

๐Ÿง

tepid hornet
#

xD someone deleted their messages

acoustic rover
#

does anyone know whether Dark is from germany or not?

quiet schooner
winged charm
#

whaaaaat

stiff egret
#

Ah, another flag hoarding issue.

cerulean sparrow
#

@cerulean sparrow i will try to play against you some day soon ๐Ÿ™‚
@nova tide You already did before

nova tide
#

i don't remember ๐Ÿค”

#

Did i submitted already saved flags?

cerulean sparrow
#

@nova tide If you're the one who become king first then don't submit flags, I think yes you did that before

cerulean maple
#

Anyone up for KoTH ?

ruby arch
#

KoTH anyone?

swift fossil
#

whos up for a koth

#

Join Fast

iron sable
#

@south herald is that u on KoTH 10558 ?

south herald
#

yeah

iron sable
#

so u think getting all the flags in 3 seconds(as u already played that box), and filling out all thos holes, is the purpuss of the game ?

south herald
#

i have been playing this machine in the past, but that's not the reason why i get those flags fo fast

fair adder
#

@south herald that's not an explanation

south herald
#

what holes then?

iron sable
#

i have been playing this machine in the past, but that's not the reason why i get those flags fo fast
@south herald oh god, this is why i ||fucking|| hate those KoTH machines, im out

#

lah yn3l tabon mok fhad sba7 3sbti zaml boya

south herald
#

care to tell me what i done wrong?

fair adder
#

never mind

brazen cloud
#

I'm taking a look into what I can see regards to 10558

iron sable
#

naah @brazen cloud dont' bother its all good.

brazen cloud
#

We're looking into overhauling the KoTH boxes for automated healthchecks of things that are against the rules amongst other things

#

As long as there's no complaints, it's still good for us to have a look at to begin to build a picture of how koth matches operate day-to-day

stiff egret
#

Makes sense.

swift fossil
#

guyz

#

join

nova tide
mint cargo
#

y did u have to screenshot pepehands

nova tide
#

i'm keeping evidence now

#

you can't ghost ping me anymore

mint cargo
#

i will ghost ping and delete so fast that ur screenshot software wont be able to capture it.

nova tide
#

try me

mint cargo
#

pfft lol

stiff egret
#

Lmao

#

Nailed it

gusty cradle
#

๐Ÿ™‚

gusty cradle
#

New KoTH box dropping soonโ„ข๏ธ ๐Ÿ˜‰

stiff egret
#

For once, once, this soon is actually soon!

grand ember
#

noice

barren stream
#

KoTH staff, what colour do you want the KoTH flair to be on Reddit?

short tusk
#

red

barren stream
#

@stiff egret @nova tide from the top of my head

#

i dont wanna ping all koth staff ๐Ÿ˜›

stiff egret
#

Do we get options?

barren stream
#

yes

#

16 million colours

#

to be precise

#

any colour at all

#

i'm choosing colours not Dark so it can be literally anything ๐Ÿ˜›

stiff egret
#

I'd say, neonish-cyanmaybe?

barren stream
#

We already have that

#

๐Ÿ˜ฆ

#

1 sec

#

all current colours

#

i cant fix the font colour on new room as i am adding KoTH rn ๐Ÿ˜ฆ

stiff egret
#

:(( Um you choice then! blobheart

barren stream
#

I went with gold :))

#

@stiff egret Do you answer questions about KoTH as part of being KoTH staff?

stiff egret
#

Yes.

barren stream
#

So your remit extends past the Discord, which means if we get KoTH questions on Reddit it is KoTH staff's job to answer them? Sooo do you peeps want a user flair for KoTH staff on the subreddit? You won't get mod or anything, just a shiny badge to let people know you are KoTH staff ๐Ÿ™‚

#

Same goes for Forum (maybe, not forum staff) ๐Ÿ˜›

stiff egret
#

Confirming..

barren stream
#

Might be best to ask Dark?

stiff egret
#

Yep, That's what I just did.

barren stream
#

Ah great ๐Ÿ˜„

final nest
#

anyone wanna try hogwarts ?

stiff egret
#

You can directly ping him ๐Ÿ˜„ It'll be faster.

barren stream
#

@mellow bough Am I right in thinking that because KoTH staff deal with KoTH, and support / questions for KoTh does not exist solely on the Discord, I can give them a badge / flair on Reddit since their role as KoTh staff also applies to the subreddit? Same for forum too, if KoTH questions pop up?

#

Their role as KoTH Staff is not Discord specific but applies to all discussions on KoTH, regardless of platform*?

mellow bough
#

Since it's a role that I'm letting grow naturally, sure

barren stream
#

oooh~~~

#

@stiff egret do you mind asking everyone in KoTH staff for their Reddit usernames, and let them know I'll assign them a fancy Reddit KoTH user flair so people know they are KoTH staff? ๐Ÿ™‚

stiff egret
#

Will do and update you, I think most of them are offline atm.

mellow bough
#

Give me a moment, I'll post a list of the staff for you in the subreddit staff chat

dusty canyon
#

New koth machine??

stiff egret
#

Yes

dusty canyon
#

OOoOooooh

stiff egret
dusty canyon
slate crow
#

new koth machine?

#

noice, lets hope flags change

#

as well as creds

quiet schooner
#

That would be a platform feature, and is still pending

terse willow
#

The creds do change in Hogwarts though

#

~~Given I helped with the damn autogen ๐Ÿ˜† ~~

stiff egret
#

The creds do change in Hogwarts though
@terse willow not only creds

terse willow
#

Did you get that working in the end??

#

Perfect ๐Ÿ˜

stiff egret
#

Yep! That last command worked!

quiet schooner
#

Is it like the staircases in Hogwarts?

stiff egret
#

OH JAMES

#

YOU ARE THE ONLY ONE WHO GOT IT

quiet schooner
#

โค๏ธ

stiff egret
#

I TOLD A LOT OF THEM THAT THEY ARE LIKE STAIRS

#

But smh

#

I take it you will understand HP references in the box

#

There are a lot

fair adder
#

.... what a goofy box it is

#

can i send you a ping mr @stiff egret in a bit. wanted to ask about something on the box

#

correction. later... i am still poking aroudn at a few other things

stiff egret
#

Sure :)

thick coyote
#

anyone hogwart? >.<

vocal shell
near sphinx
#

ive just done hogward, anyone found all flags? im missing one

#

i found one but it says "wrong flag". it looks legit tho

stiff egret
#

ive just done hogward, anyone found all flags? im missing one
@near sphinx um. Its released yesterday, give it some time

#

i found one but it says "wrong flag". it looks legit tho
@near sphinx strange. ๐Ÿค”

final nest
#

ive just done hogward, anyone found all flags? im missing one
@near sphinx flags not naned flags

#

๐Ÿท

serene bay
#

Great Box @stiff egret ๐Ÿฅณ

stiff egret
vocal shell
#

do passwords not work for Food box lmao

#

koth staff do passwords reset for the food box

near sphinx
#

for which user? @vocal shell

vocal shell
#

any

#

i changed creds for every single user including root yet pts/5 got root upon login maybe ssh key?

near sphinx
#

nah, you forgot to patch one more vulnerable service in there

vocal shell
#

i wasn't trying to patch

#

the services

#

i thought you guys gave up

#

LOL i didn't harden

#

the box

near sphinx
#

haha not really,we got in through there.

thick coyote
#

hahaha

vocal shell
#

got in through where

thick coyote
#

now im stuck

vocal shell
#

i have a few guesses

#

there a ton of ways in

near sphinx
#

through high ports web server

vocal shell
#

kk i have to plug my laptop in charge

near sphinx
#

sure mate

vocal shell
#

passwords didnt work tho

#

im salty

near sphinx
#

it should work, pasta should work

vocal shell
#

grrr

near sphinx
#

dang thats close

vocal shell
#

what's close

#

yeah i know

#

my vm even shut off

#

kk i go eat

thick coyote
#

i can't even got inside already haha

#

ctrl C kill me haha

stiff egret
#

koth staff do passwords reset for the food box
@vocal shell food is a static box, passwords remain same, until you change them.

#

ยฏ\_(ใƒ„)_/ยฏ

near sphinx
#

GGs

vocal shell
#

how gg?

#

did it end?

near sphinx
#

not yet, you can ssh now through pasta

nova tide
#

koth staff do passwords reset for the food box
๐Ÿคฆโ€โ™‚๏ธ

vocal shell
#

well you guys were discussing it

runic quail
#

Naughty, gib writeup.

nova tide
#

Soonโ„ข๏ธ

runic quail
nova tide
#

just doing uni stuff nowdays

stiff egret
#

well you guys were discussing it
@vocal shell it was about other box

vocal shell
#

@near sphinx reset?

near sphinx
#

sure why not

vocal shell
#

where are the flags ๐Ÿ˜ฆ

near sphinx
#

u play dirty ay @vocal shell haha

#

but nice

vocal shell
#

i didnt kick u out

#

my other user got kicked out too

near sphinx
#

all binaries are symlinked to /dev/null apparently

vocal shell
#

really

#

neat

stiff egret
#

Share the spectator link?

near sphinx
vocal shell
#

i need one flag

#

bruh

near sphinx
#

GG my guy, h0j3n will win

thick coyote
#

1 more minute haha

stiff egret
#

all binaries are symlinked to /dev/null apparently
@near sphinx not on my machine atm. Still public reminder, this is NOT allowed.

vocal shell
#

@thick coyote gib one flag

#

๐Ÿ˜

near sphinx
#

this shouldnt be allowed right? @stiff egret

vocal shell
#

that's actually the way the box is

#

i'm pretty sure

#

gg @thick coyote

stiff egret
#

He did echo the PATH, @vocal shell

vocal shell
#

what does that mean

#

what do you mean by that

stiff egret
#

That means the intended hurdle you are referring to is already passed.
Binaries are messed up with, and yes, that's not allowed.

vocal shell
#

this is the food box

#

that's how it is for users?

stiff egret
#

Look carefully in the screenshot.

vocal shell
#

he deleted it

stiff egret
#

DM me that? @near sphinx

near sphinx
#

im afraid it willspoil the box

vocal shell
#

what can cause that?

#

i'm still on the box

near sphinx
#

i'm still on the box
@vocal shell u mean still have a session?

vocal shell
#

yeah i do

near sphinx
#

the box has ended like 5 minutes ago @vocal shell

#

thats weird

#

why are u inside /bin folder tho ahaha kidding my dude xD

stiff egret
#

Known bug, on reset, box expiration time also resets, hence box runs for 1 hour. Though game ends.

vocal shell
#

im inside /bin to check to see if i messed something up on accident

#

because i want to make sure that i'm playing within the rules

#

@thick coyote how'd u get all 8 flags blobknife

near sphinx
#

grep + regex will do the trick

vocal shell
#

i tried that

#

am i doing it wrong

near sphinx
#

i cant tell. GG augustus. Lets play again sometimes. we can share knowledge and tricks blobheart

vocal shell
#

gg @near sphinx ๐Ÿ™‚

nova tide
#

im inside /bin to check to see if i messed something up on accident
@vocal shell you have been using accident for quite some time now

vocal shell
#

poor guy :[ he keeps resetting because i keep kicking him out

#

i feel like it's someones alt

vocal shell
stiff egret
#

Mind sharing the spec link?

vocal shell
vocal shell
#

how's everyone doing

#

who's that person sshing in

#

@stiff egret r u watching or something lol

stiff egret
#

No. I am not in game.

vocal shell
#

how did three people agree on resetting

#

all my work just gone

vocal shell
#

gg

#

@stiff egret has anyone ever got 60 minutes king time?

stiff egret
#

I mean, that would technically be a proof of autopwn.

#

ยฏ\_(ใƒ„)_/ยฏ

#

Though it is possible. I don't remember any match with that stat.

gusty cradle
#

but that was around the time that no one except me and a few others had completely pwned tyler

vocal shell
#

every single time on this box?

stiff egret
#

every single time on this box?
@vocal shell ?

vocal shell
#

can't change any users' password

gusty cradle
#

Are you root?

vocal shell
#

O

gusty cradle
#

Since, only root can specify usernames in the passwd command

vocal shell
#

LOL wait

stiff egret
#

euid

vocal shell
#

mhm

#

fixed it thank you :)!

stiff egret
#

ยฏ_(ใƒ„)_/ยฏ

vocal shell
#

i think i can get 59 minutes as king >:)

stiff egret
#

You can't on Hogwarts.

nova tide
#

@gusty cradle my max time is 58 blobknife

vocal shell
#

6 more minutes and i hold record blobknife

#

@nova tide

nova tide
#

I don't think you can get 59

vocal shell
#

why not blobknife

nova tide
#

Not possible?

vocal shell
#

o

#

are you certain

#

i almost got 60/60 blobknife

trail burrow
#

another one?

vocal shell
#

i can't, playing among us

patent forge
#

@nova tide next step is being king for the whole game

nova tide
#

๐Ÿคทโ€โ™‚๏ธ

boreal flare
#

i almost got 60/60 blobknife
@vocal shell autopwn to the limit.. ๐Ÿ‘€

stiff egret
#

There are 3-4 players I know of, who can get 700 + more than maximum possible points.

#

(me, naughty, James, maybe szy)

blissful kettle
#

Szy is always first in rooms so I think he would

stiff egret
#

I meant more than maximum possible

boreal flare
#

Well if you're the smartest one in the class then you're in the wrong class... @vocal shell

vocal shell
#

i'm not the smartest one in the class

boreal flare
#

(me, naughty, James, maybe szy)
These are pros and that's a different story..

stiff egret
#

There are 3-4 players I know of, who can get 700 + more than maximum possible points.
@stiff egret ^

vocal shell
#

._.

#

those guys are really talented people i'm not there yet

#

what do you mean by more than maximum possible points?

stiff egret
#

More than maximum possible points.
I meant exactly that.

vocal shell
#

on a koth box?

stiff egret
#

Yep

#

;)

vocal shell
#

if no flags and just king 600 is max score then

#

how can you go above 600

boreal flare
#

I've been trying all day to get Hogwarts....but never got it cri

stiff egret
#

I've been trying all day to get Hogwarts....but never got it cri
@boreal flare All the best!

boreal flare
#

Thanks! (I probably need it)

#

Congo to you Mr Holmes

vocal shell
#

gib secwet on how getting more points in koth box blobknife

boreal flare
#

It's your first box if I'm not mistaken?

stiff egret
#

Yep

#

More in production

vocal shell
#

what does that even mean

#

only the elite can destroy everyone

tame veldt
#

Anyone for koth?

boreal flare
#

Well not me

#

ask Augustus

#

@vocal shell

wicked tartan
#

Anyone solve sixes vulnhub?

winged charm
#

@wicked tartan this is for the king of the hill game mode in tryhackme please take that to #general

wicked tartan
#

Sorry

fair adder
#

Anybody solved hogwarts

boreal flare
#

Nope dude

#

been trying to get into that room for whole day..but no luck

fair adder
#

Me too

boreal flare
winged charm
#

beg holmes for the secret haxs

stiff egret
boreal flare
#

first need to get the on box tho..

stiff egret
#

TryHarder wrong
Bribe the creator right

noble flicker
#

hogwarts; what a machine! It's my first koth machine in the thm and no one could find a single flag .. but wow .. learned a lot

cerulean maple
#

@noble flicker Really ? Can't wait to try it

swift fossil
#

guyz

#

anyone up for a koth

cerulean maple
#

@swift fossil Maybe later

swift fossil
#

ah

#

lets play a simple one

cerulean maple
#

Ok I'm coming

swift fossil
#

thanks

fair adder
#

anyone to play koth

final nest
#

. ใ€€ใ€€ใ€€ใ€‚ใ€€ใ€€ใ€€ใ€€โ€ขใ€€ ใ€€๏พŸใ€€ใ€€ใ€‚ ใ€€ใ€€.

.ใ€€ใ€€ใ€€ ใ€€ใ€€.ใ€€ใ€€ใ€€ใ€€ใ€€ใ€‚ใ€€ใ€€ ใ€‚ใ€€.

.ใ€€ใ€€ ใ€‚ใ€€ใ€€ใ€€ใ€€ใ€€ เถž ใ€‚ . ใ€€ใ€€ โ€ข ใ€€ใ€€ใ€€ใ€€โ€ข

@stiff egret was The Impostor.

'ใ€€ใ€€ใ€€ 0 Impostor remains ใ€€ ใ€€ใ€€ใ€‚

๏พŸใ€€ใ€€ใ€€.ใ€€ใ€€ใ€€. ,ใ€€ใ€€ใ€€ใ€€.ใ€€ .

#

@nova tide check this lol

#

TryHarder :wrong:
Bribe the creator :right:
@stiff egret that's y ๐Ÿคฃ๐Ÿคฃ๐Ÿคฃ

winged charm
#

@vocal shell can you dm me when you get a chance ๐Ÿ™‚

grand ember
#

i have 6/7 flags on hogwarts

#

cant' find the last one lol

stiff egret
#

Send your GameID

grand ember
#

found it, i still have a question about a specific file tho

stiff egret
#

Interesting..

loud stone
lucid quail
#

They vote to reset the machine

#

To stop u

winged charm
#

@lucid quail who?

fair adder
stiff egret
#

They vote to reset the machine
@lucid quail Nothing much can be done about that, It is a gentlemen's game.

lucid quail
#

@stiff egret I know but Iโ€™m just saying that some players are idiots. They donโ€™t respect others

stiff egret
#

Leave some vulns unpatched, and kick them when they get in. This will keep them from resetting

winged charm
#

@lucid quail if it continues to happen and heโ€™s purposefully doing it let one of the koth staff know and weโ€™ll look into it

fair adder
#

new koth box
anyone wanna run it and have a go?

nova tide
#

Aah resets.. good old days pepehands

cerulean maple
#

@fair adder Yeah let's do it

south herald
#

this new koth room is the best so far

#

good job ๐Ÿ’ฏ

light breach
pearl pelican
light breach
#

@fair adder what is the name of the new one?

blissful kettle
#

Hogwarts

chilly sandal
#

Anyone down?

left yoke
#

Hiii

nova tide
#

hye

cerulean maple
#

Yo

vagrant gull
trail burrow
calm briar
#

one dude , changed all the 8 flags

stiff egret
#

Game ID?

#

Also, Check pins.

calm briar
#

he probably didnt read the rules , please pardon him , just warn him

#

@stiff egret

stiff egret
#

mhm, You have any proofs that they changed the flags?
Is Diesel here?

#

Just send the data you have (username/ gameID ) to koth@tryhackme.com, Most probably, someone from the site will mail them a warning.

light breach
#

anyone awake? wanna play KOTH before i start class?

calm briar
#

mhm, You have any proofs that they changed the flags?
Is Diesel here?
@stiff egret he changed all to THM{diesel}

#

the cureent room , he edited sudoer file

#

and removed current user from sudoer

#

hes spoiling rooms

#

please attend to this, the room in not fun at all ,

boreal flare
#

the cureent room , he edited sudoer file
@calm briar
That is totally allowed

stiff egret
#

Editing flags in clearly Not allowed. Can you DM me the IP of room?

#

@calm briar

winged charm
#

@calm briar not much we can do about it right now, if youโ€™re still in the game or if you play another game with them take screenshots and show us exactly what is happening so we can come to a fair conclusion. editing flags is against the rules however editing the sudoers file is perfectly fine

calm briar
#

ok great, ill catch him next time and take screenshots, hes plays too dirty

#

Thanks for the help

tame veldt
#

@calm briar you guys aren't playing anymore ?

calm briar
#

we still palying

#

can anyone teach me how to corrupt other players shell

tame veldt
#

can i have the link?

calm briar
#

whenever im root, the other user , corrupt my shelland ick me out

#

@tame veldt

tame veldt
#

Thanks!

#

Just 1 min remaining ๐Ÿ˜ข

#

ping me if you guys play again

calm briar
#

ok, will share the link here

tame veldt
#

Cool

main verge
#

am here

winged charm
#

I need screenshots of the flags as well as the sudoers file

#

if you can get them

calm briar
#

@main verge @tame veldt ill start a room in 5 minutes , lets play

#

@tame veldt you seem like a pro!

tame veldt
#

Trust me i am not ๐Ÿ˜›

calm briar
#

Hello guys , Diesel PM me , he didnt know about the rules , So we are cool now ๐Ÿ™‚

short tusk
#

Should've read them before hand smh

calm briar
gusty cradle
#

@calm briar What is Diesel's discord?

dry dragon
#

@calm briar
Did u get answer for how to corrupt other players shell if so share it with me also pls

calm briar
#

@dry dragon ill share with you once he teachs me

dry dragon
#

@calm briar thnks that's goona help me a lot

cerulean maple
#

can anyone teach me how to corrupt other players shell
@calm briar I think this is how they do it
cat /dev/urandom > /dev/pts/pts-number 2>/dev/null , correct me if I'm wrong

light breach
#

Thats also a way to echo a message to then to troll lol i do that with my friend all the time xD

#

Echo "annoying txt here" | write username pts/#

cerulean maple
#

Nice xD

brittle flicker
#

heeeeeeeeeeeck

#

Did I miss Mr.Koth

#

everyone here keeps talking about him, but I never see him

#

how sad

stiff egret
#

I know their address!

brittle flicker
#

I heard Koth was a cool guy

#

no way!

#

tell me!

stiff egret
brittle flicker
#

.>

#

big sad

#

he's not here

stiff egret
#

You have to click on this button

brittle flicker
#

๐Ÿ˜ฆ

#

I'll wait for him to come home

stiff egret
brittle flicker
#

Danke Mr

stiff egret
#

Click on that button

#

You'll meet them

brittle flicker
#

D: biggest sad

winged charm
#

The heck

brittle flicker
#

I never get to see Koth

#

everyone streams koth

#

but I've seen his face

#

...when will my koth hubby come back from war?

winged charm
#

I think itโ€™s because your experience level set in your profile is too low iirc

stiff egret
#

Nailed it cry

#

Nailed it

winged charm
#

yo Iโ€™m very confused right now

dry dragon
#

@brittle flicker did u use inspect element to trick us๐Ÿ˜‚๐Ÿ˜‚

winged charm
#

goofy goober

brittle flicker
#

NO! KOTH JUST HATES ME, BRING BACK MY KIDS KOTH!!!

carmine gate
#

Anyone wanna do koth in about 20 minutes?

#

Waiting in a public lobby rn

main wolf
#

@carmine gate i am new to koth

#

i can join

#

can teach me?

carmine gate
#

Same. This'll be my first game

#

Not new to pentesting though

main wolf
#

hm

#

where should i join

#

oh only

#

intermediate and advanced user can join the game

carmine gate
#

Yeah. Feeling up to it?

#

Could possibly just co-op it for teamwork skills I suppose

main wolf
#

hmm

trail burrow
#

link?

main wolf
#

i think i need to beome intermdiate uesr to play

trail burrow
#

yes you should

carmine gate
#

Whoops, probably should have sent that

#

Thanks

trail burrow
#

im in

carmine gate
#

Nice

main wolf
dry dragon
#

Joined this game real late๐Ÿ˜‚๐Ÿ˜‚

calm briar
#

LOL

#

The KOTH was mad fun

dry dragon
calm briar
#

ME , B4SHBOUY , Diesel

#

fighting for king

#

@dry dragon how you doing bro

dry dragon
#

@calm briar fine

#

machine was so unresponsive

#

even though i got that exploit and ran it shell kept breaking

calm briar
#

yes

#

we were messing the shell

#

You understand @dry dragon

dry dragon
#

listen what was up with that anonymous ftp login

#

like how could someone have done it

calm briar
#

bashbuoy was killing the machine to retain king

dry dragon
#

ohh i c

calm briar
#

on the offline box ?

dry dragon
#

yes

#

there was anonymous ftp login

calm briar
#

I didnt try the enumerating ftp

#

just went straight for psexec

dry dragon
#

lol

#

it allowed ftp login but said like password is the e-mail username

calm briar
#

is anonymous login allowed?

#

you see the pw in page source ?

#

the user should be offlineking

dry dragon
#

ohh for me on port 80 it didn't open up itself

#

was there a http server on port 80

calm briar
fair adder
#

Koth was fun

dry dragon
#

Is there anyone playing koth now??

fair adder
#

Not yet

dry dragon
#

already started though

fair adder
#

Hahaha

#

Am coming

cerulean sparrow
#

xD

cerulean sparrow
#

@muted forge XD

muted forge
#

@cerulean sparrow i relised it now ๐Ÿ˜ฆ

#

can you hacked it

cerulean sparrow
#

?

muted forge
#

koth

cerulean sparrow
#

I was in the machine since a long time

#

I wanted to encourage you

muted forge
#

ok

#

can you give me a small tio

cerulean sparrow
#

ok

muted forge
#

my internet is to bad http page isnt reloded yet

#

i scan with nmap,and gobuster now

#

machine dont return any response

cerulean sparrow
#

try the ip again

muted forge
#

ok

cerulean sparrow
#

chech it

#

if it's correct

muted forge
#

why is main page isnt loading

cerulean sparrow
#

restart openvpn

#

it happens sometimes

#

sudo killall openvpn

#

then start it again

muted forge
#

ok

cerulean sparrow
#

it works !

muted forge
#

it isnt work on my device

cerulean sparrow
#

I'll give you a hint

#

you need to find an open port

#

then do the rest

#

greater that 1000

muted forge
#

im i need to use -p-

cerulean sparrow
#

you can the get even the root flag from there

muted forge
#

where is the user fla

#

g

#

there is a directory called /flag but

#

in includes nothing on here

cerulean sparrow
#

yes

#

it contains nothing

muted forge
#

yes i found your port

cerulean sparrow
#

the cmd parameter is undefined

#

so you got this ?

#

message

muted forge
#

yes

#

en RCE

cerulean sparrow
#

ok do the rest

#

it's easy now

#

search for the message and do the rest stuff

#

you got it ?

muted forge
#

i dont know how to exploit it

#

ok

#

the big suprise

#

it isnt loading

#

heh i done it

light breach
#

oppss

dusky berry
brittle flicker
#

||koth looks like a cool guy :3||

dusky berry
#

Join in if any one would like to play skidy

carmine gate
#

Dang, bad timing for me. Let me know when you get another going

light breach
#

Makimg king flag hidden file isint against the rules right?

stiff egret
#

No, it is against the rules.

#

You cannot move or delete king.txt.

#

@light breach

#

Please give rules a read.

quiet schooner
#

It'll also stop the king service from working, so offers literally 0 advantage

#

Someone can just make a non hidden file

light breach
#

Not move same dir just .king.txt

#

I mean just rename it to .king not move it thats cheating

stiff egret
#

...

light breach
#

Honestly asking for a friend so i can tell him not to

winged charm
#

There are very specific things that need to happen with the file do not touch it except to put you name in

light breach
#

Okay thats what i thought

terse willow
#

Riiiiiiight ๐Ÿ˜†

#

@winged charm How's the Owl coming along?

winged charm
#

muir youโ€™re a mad man

light breach
#

Now that makes sense technically speaking. Because the script running uses king.txt file okay cool. Man such a rad concept

terse willow
#

๐Ÿ˜

#

And that is a medium Cry

#

You don't want to see the Linux ones

stiff egret
#

Owl ๐Ÿ‘€

terse willow
#

I've just planned out another Windows box though

#

Which might just involve Otters...

stiff egret
#

What..... are..... you.... guys.... talking .... about..... TELL....ME..!!

terse willow
#

I asked Cry to take a look at my first Windows box last night, Holmes

stiff egret
#

for koth?

terse willow
#

He's... uh... getting his arse handed to him

#

Nah

stiff egret
#

phew,

winged charm
#

Nooooo

#

I got a foothold

terse willow
#

Ey!

quiet schooner
winged charm
#

just in a completely different box

terse willow
#

๐Ÿคฃ

light breach
#

Wait is this an unreleased box we are talking about lol

stiff egret
#

๐Ÿ˜†

terse willow
#

It is

#

just in a completely different box
@winged charm The one that tried to attack the attackbox?

winged charm
#

Yep

terse willow
#

You got into it? ๐Ÿคฃ

stiff egret
#

Ninja

#

ban

winged charm
stiff egret
#

wohoooo

light breach
#

So who made carnage....?

#

Not asking for help just cant seem to figure it out lol nice work

light breach
mellow lodge
#

anyone active now

terse willow
#

@light breach Small warning -- there are currently 27824 people in here; all of whom would be alerted if that everyone ping had worked. Fortunately we're smart enough not to let people use it, but a little consideration maybe?

stiff egret
#

6 users increased in that much time. Noiceeee

raven halo
#

anyone wanna play koth

light breach
#

@raven halo still around?

raven halo
#

@light breach ill be back in an hour or so

raven halo
#

2 mins

light breach
#

hogwarts is the bane of my existence

#

shoot bro i am doing one now got 12 left

#

bed after this tho

raven halo
#

all good, this machine is hogwarts too - i did it yesterday and couldnt get anything

#

hopefully better thist ime

light breach
#

yeah its rough

dry dragon
#

random room public match u all are most welcome

#

20 mins to go

dry dragon
#

did someone stop ssh service

#

??

nova tide
#

Try doing:
nmap -A -p 22 <machine ip>

#

They may have changed the password or the port ๐Ÿคทโ€โ™‚๏ธ

dry dragon
#

no on line it runs on different port

#

*lion