#koth
1 messages ยท Page 48 of 1
Epic
offline's easy tho
yea that's the problem
i mean , all of them are ez
I know that

i did every box at least 10 times
Nicee

No scripts at all 
~~Who'll you complain to? ~~

๐

i cant find the sixth flag on tyler
anyone knows where is it?
i've checked everything

=[
very very rare
is it allowed to kill shells or change user passwords or these kind of things?
Yeah,
kill shells too?
Yep
Regarding?
am having problem with my ssh. cant continue.
works for me
With love, XOXO @flint cloud

@terse willow
@terse willow
this is our chance CRy
also in #thm-community-media
@quiet schooner
pleasee
Sorry 
did you delete some files that privesc depends on?
No, I haven't patched a thing
maybe the other guy not you
anyway I banned
but I forgot to add a ban reaso Nas I am literally on a date
pls don't tell Dark 
Nice time to kill the wifi
just being a spectator hehehe!!!!
lol
@barren stream Only CM's and mods have access to that channel ๐
Muirrrrrrrrr
No, designers do too

Literally, it's only CM's and mods
that's it
Yep
wow
yea >> and >
I just saw

yeah
i voted


@fair adder Please reset, someone broke the machine
reset please
I'd say, The cat is very loyal. @flint cloud
Ayo but the N-No scripts rule? 
Um, I didn't use any scripts
did you put in the while a command we cant change the perms of king.txt?
RESETT
did you put in the while a command we cant change the perms of king.txt?
@sharp parrot try harder!!!!
-.-
Someone broke the machine 
one more vote to reset pls

for the love of god
blame Y3VsdAo=
Why would someone use such a horrible name 
WHATT
how am i root and cant change shrek's passwd
or change perms of king.txt
how do you that
well im still a beginner so good game
you are a king but holmes @stiff egret is coming to kick you lol
well im still a beginner so good game
@sharp parrot GG man,
its really fun but u guys are good i need more ppl at my level
You got in crossfire b/w me and cultholmes
lol
Yes
yo they patched everything or i am dumb?
Noice urandome missile go brrr
i cannot get back in
I didn't patch anything
who did ayo
I didn't patch anything
@stiff egret Holmes never patch, he is damn good to kick you out again.
Nice color theme
and you borked it 
your shell you mean?

after the game someone should help me fix my ssh
Not able to ssh to another computer, but can ping it?
damn bruh i cannot get back in
after the game someone should help me fix my ssh
Not able to ssh to another computer, but can ping it?
@fair adder maybe pass is wrong or has changed
damn bruh i cannot get back in
@fair adder there are multiple footholds in every machine
So -U its patched?
@fair adder maybe pass is wrong or has changed
@sharp parrot i check that also and login with the right credentials
So -U its patched?
@flint cloud huh?
That's the problem of knowing one way in , if you aren't fast enough then--
to whoever sending those walls, I am not the one who patched
That's the problem of knowing one way in , if you aren't fast enough then--
@flint cloud i was root on the box lmao
Everyone was 
is it allowed to kill shells?
yeaaaaa
Yeah
kill id?
kill -id-?
-______________________________-

man kill Give this a quick read @sharp parrot
kill -id-?
@sharp parrot I would show you , let me in
nope lol
@sharp parrot I would show you , let me in
@flint cloud

man killGive this a quick read @sharp parrot
@stiff egret real man doesnt read instructions

wait i killed 2 shells was it yours?
beginners do
my shell got spammed
cat /dev/urandom?
is it just spam and you entered it to my shell?
im not angry lol im having fun i just want to learn new things
lmao
but you know what user are you so why not eliminate the others?
what stops people from just killing all tcp connections to other players?
yea ik
what stops people from just killing all tcp connections to other players?
@fair adder rules
but i thought killing is allowed
It is
wait so I get to flood shells but not kill sockets?
ss -tvp4
what is that
gets all socket connections and assoc. processes
not your IP? kill the proc
fair point
it's not truly a game w/o an opponent to fight against
ohhhhhh
alright i think im done for today i got 2nd place i dont think anyone will take that from me in this challenge
gg yall
Its over?
no
Yes time to figyht
@stiff egret do you use c script to log your name to king.txt?
dont kill me 
I'll be down for a sesh later, never tried KotH though
@stiff egret do you use c script to log your name to king.txt?
@sharp parrot um, I can, but mostly it depends
I'll be down for a sesh later, never tried KotH though
@fair adder It's fun
wha-
You gotta be kidding me
inb4 "patched"
ssh != sshd
@stiff egret dont let anyone get to king.txt ok?
im at king.txt lmao
I'll try my best
i love this emoji lol
Doesnt eveyone know all the boxes because theres only a bunch of them?
I just started playing last night
@nova stream its new for me too
me too
im at king.txt lmao
@fair adder
When my vm broke down first game lol
lol
I gotta switch off virtual box its absolute garbage
But it lets you take snapshots for free
uses VM
also uses vim
how do I exit?
Depends on how you use it, been using it for about a year now, no probs so far
I gotta switch off virtual box its absolute garbage
@nova stream
Every other week that I start my vm it wont boot
And then after an hour after I kill the process it bugs out
check settings if you set it correctly and gave it enough power
alright i gtg @stiff egret stick to king.txt
yay im 2nd place
You guys aren't playing?
nb
๐๐๐
Who am I trolling then
You guys aren't playing?
@flint cloud i got nothing else to do ill go jog a bit
i got all the flags i could find
Aight holmes told me 
am i cool now ?

**!**cool
you a Impasta
which desktop environment do you guys use ?
Unity ๐ค
why that resolution tho ?
who fork bombed the box lol
Unity ๐ค
@gusty cradle it's awesomeWM
They won't/ can't do that again
they might have crashed their own shell trying to spam someone else ? maybe?
@flint cloud that was me
Welcome to haxoring classes 101 by holmes: don't start a loop you can't kill



=]

ya ingles tresh

huh, didn't some dev. a /bin/sh less shell a while back?
someone wanna play nother koth? this was kinda boring ngl
did i wrote fine ?
@severe yoke
@stiff egret 
xDDD
someone wanna play nother koth? this was kinda boring ngl
@fair adder i would, but im still pretty noob :))
someone wanna play nother koth? this was kinda boring ngl
@fair adder if you want me in, then tag me ๐
@sharp parrot how did u got the sixth flag
@fair adder
Find it
starts in 5 mins
F
=[
wtf
@flint cloud sup? playing?
yo guys if ya come at koth i'll give free pizza
@fair adder If that's a lie, I'll be mad
nah u good bro
โค๏ธ
...
again tyler
si tu viens pas je vais te nique
@fair adder Keep it in english please
(I should delete that)



Do share their reply ๐คฃ
back, joining
Ima have to record it tomorrow
Big F

well, if its useful for your conscience, im here while i should be doing some large homework too


kalm
Yeah 
Sleeping lol
xd
what is SMH ? (srry, english isn`t my mother language)
It's short for, 'shaking my head'
aaamm
Shaking my hips like Shakira
nice
Ima fight you reg from tomorrow smhead @stiff egret
huh excuses

@stiff egret ez
I can edit that sudoers you know
that's how i got root
lol
meanwhile: oh neat jmx has notes
@stiff egret u son of a
@stiff egret u need to learn me how to do dat
i'm dumb as hell
no bruh fr now
i can't chown i can't do anything =[
huh? Why?
Yep, I thought you knew that already.
tfw metasploit doesn't work and the poc you're trying to use refers to a defunct web resource
Yep, I thought you knew that already.
@stiff egret the problem is
that the box
huh?
tfw metasploit doesn't work and the poc you're trying to use refers to a defunct web resource
@fair adder
(you can upload your own)
CVE : CVE-2010-0738right?
@fair adder which box?
tyler? . _.'
ah THAT exploit
oof
As I said, there are multiple methods to get in a box, ๐คทโโ๏ธ
you can try other footholds
true, found stuff in smb so that's a step in the right direction, though to what idk
symbol lookup error: ./chattr: undefined symbol: fsetproject
wat
i found sqli in https://plmb.ro/ which is the police site of romania lmao
lemme see what they have in there , time for proxychains yey
symbol lookup error: ./chattr: undefined symbol: fsetproject
@fair adder wrong binary maybe
=[
I don't trust proxychains tbh, it's no garentuee your requests get sent through it
at least that's what I saw w/ firefox
I don't trust proxychains tbh, it's no garentuee your requests get sent through it
@fair adder r u sure bout' that
probably a dumb application of it
iirc it just sets proxy env variables no?
hm
i got bored of koth , enough for today
maybe i'll go on htb , crack my head at those rooms
gg, got a flag at least. win for me (../)/
gg

yeaah
ah lol

:))

They're gone btw
LMAO
Banned for the black hat crap and multiple warnings they received
Multiple instances of vulgar language, black hat discussion regarding the website listed earlier in chat
ah, I thought mods let him pass, either way ๐คทโโ๏ธ
wait he was serious about hacking the romanian police?
yepperino, he was posting a bunch of sketchy crap
We don't really like even joking about black hat things here, gotta keep it legal
yeah, iirc the hacking community's already on thin ice w/ the discord admins given the nature of the server
We're educational
And we gotta keep it that way
We know some people are gonna be a-holes about that and it's just something we have to deal with on a case by case basis
yeah, iirc the hacking community's already on thin ice w/ the discord admins given the nature of the server
@fair adder Not really thin ice, but given we're partnered, it's in everyone's best interests to keep everything legal (not that it wasn't already)
how stupid, people like that end up in jail, not because of what they do but due to their big ego. either way white hat is the way up ๐ฏ
Yeah, IPs in web based services are kinda standard
For sure
All it takes is authority's to contact discord, get IP then contact VPN hope they have logs then gg gn
Although I'm not sure how the laws work in Romania
What if they use TOR?
ever tried making a discord account w/ a throw away email?
phone verif. instantly v-v
There are websites where you get a number and can get SMSs
hey guys can we move this to #infosec-general or #general as this is no longer related to koth
kk
Halo come to onlytanyaa room
anyone for koth?
Yeah me joined ur room CRASHVENDETTA
Halo come to onlytanyaa room
@covert vale ooohhh
Me noob first tym for this game
sameeeee
Hahah @turbid narwhal noice jk
honestly, ive played this only 4-5 before
youre already pro
youre already on lvl A chillllllll
im noob you dont have to try hard youre gonna win
i wont be able to find flagss chillll
I dont think so
Liar
im not lyin -_-
Who's that guy itspossible9
idk maybe a random player
game link?
be fast
My heart beating fast!!!
just booting up my vm
Lol GOD tier @nova tide
I'm also bruh!!!
alsoo, plss dont patch im tryin to learn stuffs and dont reset plssssss
another lvl d
shittttttttttttttttt
ill be the last
:)
is there any place where i can learn more about koth game?
can anyone do a writeup of this machine for me, i cant do anythin

Carnage machine going wrong
nyancat?
LMAOOOOO
@nova tide is rlyy prooo. hes a koth staff too, im pretty shocked
nyancat?
@turbid narwhal yeah
....
???
Are you doxxing Naughty? ๐ง
i mean i have all(most) of my socials connected to THM/discord, so you don't really have to post that here ๐คทโโ๏ธ
Are you doxxing Naughty? ๐ง
@gusty cradle wat? ๐

Are you doxxing Naughty? ๐ง
@gusty cradle next your turn?
I'm nub
well played
๐
Yeah my machine stucked while prev esc part
IM NOOB

Sed lyf

0 POINTSS LOL
Me also 0 points
unluqy
i gave up too early lol didnt try much
practice makes perfect
You were on last game right @covert vale ?
Yeah .my first match
Same here
Are you doxxing Naughty? ๐ง
@gusty cradle next your turn?
lmaooo you got scared @gusty cradle

@turbid narwhal Way more experienced people than you have tried and failed miserably, you can try but you'll fail just like the other 9-10 people that tried to find me.
๐
Get nyancated while playing with naughty 
Doxxing isn't allowed in this discord anyway, osint is but doxxing someone can get you in a lot of trouble.
@turbid narwhal I tired but I dont know how to play this game

koth anyone?
im comin
samee
Idk patching vulns
Way more experienced people than you have tried and failed miserably, you can try but you'll fail just like the other 9-10 people that tried to find me.
@gusty cradle i know about you
anyone got user?
Spectator link?
6 people wow..
Enumeration might help you?
?
||I think webservers had something||
||/webservers forbidden||
Hahahah
i got to login page with poetential pass and users but cant do anything
You already have 2 flags tho
@covert vale are you the root?
Yeah
Lol
Maybe someone killed the webservers?
im a beginner i want to be better
Sed lyf:
goku would be disappointed of you
Lol
Og LOL
plsssss
I just del some flags so dont try
i dont care about flags or winning i want to learn to be better

I just del some flags so dont try
@covert vale ok now that's against the rules
No its tmp u can get now
?
Flags r in the hidden table
Flags r in the hidden table
@covert vale try reading the rules for once
Ok everything I set back dont worry
bro have you done something?
||/backdoor|| dont work
i think thats just against the rules
EVEN WEB ITSELF IS FORBIDDEN WTF
then idk whats going on
Noice btw
17 min
@gusty cradle i know about you
@nova tide
The only thing you know is the country
and that's cuz your my friend

:blobyes:
@flint cloud
Hop in people
do we have some good write up for koth?
There's a repo on github ๐
I'm sure @stiff egret knows what I'm talking about ๐
Seeing as he made it
hes all set for his koth now๐
thank you ma1ware
!ban ma1 for posting spoiler links

๐๐
@flint cloud
@stiff egret is it still on?
let's create new
Yeaahh
yeah
what yeah @nova tide

let's create new
@stiff egret yeah
Which holmes will win
Lmaoooo

What are you hiding?
that is the smort question
Ima create the game
Exactly
Is that so
share the link, whoever is playing will join
Yes
He is also playing
@flint cloud I'm a normal person, so I like to sleep at 12:00 in the morning and not play KOTH

I am taking offence in that line
3 mins
what do you mean normal people doesn't play koth
@flint cloud I'm a normal person, so I like to sleep at 12:00 in the morning and not play KOTH
@tepid hornet What do you mean by normal person
which box is it?
I don't expect you to play fair, but eh
LMAO THE ORIGINAL HOLMES

All others are fake
Fight for the title

Hehe
@tepid hornet join
We are all holmes
What
Green is sus
Which green


Which green
@dusty canyon Boooth of you
Lmaoooo
NOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
wait did this tyler machine died?
no, he is playing dirty
wget gone
@tepid hornet removing binaries is not allowed, since it is a private game I am not saying anything
He is not playing
(Also kicking you now would be double the fun)
what do you mean normal people doesn't play koth
@stiff egret
A normal person prolly doesn't play koth at 12 in the midnight
@tepid hornet removing binaries is not allowed, since it is a private game I am not saying anything
@stiff egret bruh
I'm not even playing
You just woke me up from bed
well, if you can go back to your original names, I won't have trouble tagging you

Whos the original one now
@stiff egret
A normal person prolly doesn't play koth at 12 in the midnight
@turbid narwhal um koth is to be played at 12 midnight, and that is a rule

Who's the real Holmes? Prolly @stiff egret
You are in luck, bee is offline, (da best mod) they would've kicked you imposters
@tepid hornet
@nova tide
@turbid narwhal um koth is to be played at 12 midnight, and that is a rule
@stiff egret
Imma go to bed, also I don't wanna be the only noob here so I'd rather sleep
You are in luck, bee is offline, (da best mod) they would've kicked you imposters
@stiff egret
๐๐๐

Reset, someone deleted main binaries.
not the main ones

you are already out
Im in
๐
Reset, someone deleted main binaries.
@stiff egret told you
Ayo I didn't do this
(someone started deleting binaries, but a private game, who I am to say)

You changed sshd config
what no
Yes you did 
nope
someone did
๐ง
me too
Now you are using scripts
what? me? scripts? no never
Can See that 
aww
cant make your user?
UM, 1. I got no crons
2. yeah that's mine



I wanted to frame that
change the name back
and give your word you won't use names related to sherlock holmes

time
I am changing that
and?
I respect your wishes to die in honor

I played by the rules in first half
huh
Deleting binaries
that's not allowed
you couldve said who you gonna tell?
well,

Just don't do that again?
Removing binaries is eh poor defence
take ss to send you after they ban
oooof

I WON'T (terribly shaking )
(screams) DONT BAN ME
(screams again) PLEASEE
lol
I don't/can't ban
(I just you know report)


are you playing koth rn?
who?
you guys
I can join in if you like,
I deleted wget , curl , nc
@flint cloud only?
@stiff egret hey where did you find this ruleset? https://discordapp.com/channels/521382216299839518/695343809726513292/766376950238806076
It is an in-progress blog thats me and Naughty are writing. It is to be published sometime around next week. @gentle hatch
Oh awesome, I have a bunch of questions about best practices for playing koth I'm sure will be answered there ๐
Anyone wanna play koth?
23 Minutes, Public.
remind me to never play with meowless again lol
just spam killing shells kek
and editing sudoers file
impossible when the foothold on this machine is the sudoers file
theres another but whatevs
๐คทโโ๏ธ
impossible when the foothold on this machine is the sudoers file
@gentle hatch You're allowed to patch the machine, you know that right?
No rules about leaving one way in
I understand that just seems like poor sportsmanship is all
if the machine is fully patched then what is the point of playing lmao
To win.
You can always create a container to let them in to, give them false hope
Create a false king file etc
ig just really annoying when people spam wall and kill shells is all
mostly all of those methods have their patches, just research about them
I left that game before it started
starting in 5
wtf Meowless king in under 1 min lol
If it's suspicious, report it
wtf Meowless king in under 1 min lol
@sly turret whatโs the game id?
but its fair he let me in ... i think he dont patched anything
oh he kills shells -.-
ahh i dont care i lost but learned some new things ๐
anyone want to play another KotH
meowless is really good
@sly turret Only way to get your name in the king.txt was to reset the box. I only played for 2 minute to get my rootkit in. Anyway GG.
This man and his rootkit man istg i still have ptsd from the last time i played with him
good luck ๐
GG! Finally got root on Hogwarts lol
any one for a koth match ??
join join join
@versed estuary
here is the link
@fair adder thanks 
@fair adder ๐ฌ
hey
actually
the code is this
<!-- Begin
function popUp(URL)
{
day = new Date();
id = day.getTime();
eval("page" + id + " = window.open(URL, '" + id + "', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=550,height=600');");
}
// End -->
@runic quail
and the page variable is set to tyler.thm:8080
KOTH!
What are you trying to do with this?
You mean a subdomain ?
no
Quant's here. 
like
What's a subfolder
He mean directory I guess.
whenever the popup function i run
it pops the website
tyler.thm:8080
and it doesnt load for me
i cant even curl it
Have you added the website to your hosts file as DarkW suggested in #site-support
how to ??
i will google it
wait a min
but what ip to set it to
??
koth ip changes everytime
Use the one that is currently showing.
koth ip changes everytime
@fair adder Change it everytime the IP changes
You can just simple echo to the hosts file if you are on Linux
i know
It's a very ugly process for Windows
Host addresses$
2 127.0.0.1 localhost$
3 127.0.1.1 USSR$
4 ::1 localhost ip6-localhost ip6-loopback$
5 ff02::1 ip6-allnodes$
6 ff02::2 ip6-allrouters$
7 tyler.thm 10.10.172.5$
this is my file
@tepid hornet
what do you mean?





