#koth

1 messages ยท Page 49 of 1

fair adder
#

everything like that

silk needle
#

anyone getting trash?

fair adder
#

nah

#

@hushed palm any hints for me ??

#

please

hushed palm
#

yes, just bec you cant get into the machine doesnt mean the machine needs to be reset. i am just saying

fair adder
#

man

#

the ports were geting closed

#

thats abnormal

marsh perch
#

Can someone share link to watch game?

hushed palm
#

yes bec this machine do this

fair adder
#

thats why i resetted

hushed palm
#

you need scan again

fair adder
#

ok

#

literally

hushed palm
#

no this machine close the port generally you need scan again and found new ports

fair adder
#

now i am scanning every port in 1-9999

hushed palm
#

yes -p- parameter is good

fair adder
#

yeah

#

nmap -p 1-9999 10.10.206.5

#

@hushed palm just out of curiocity

marsh perch
#

add --max-retries as you have limited time

silk needle
#

done

fair adder
#

is the ressurection stone the password of root ??

silk needle
#

BTW rustscan is nice for quick scanning

fair adder
#

is the ressurection stone the password of root ??
@fair adder @hushed palm

#

cause i got the ressurection stone

silk needle
#

I've learnt the hard way that boxes may have services that aren't on right at the start or something and that it's always good to scan again 5-10 min after starting

fair adder
#

this one closes ports

silk needle
#

I use rustscan and get open ports seconds after starting the scan begins and get details <1 min later

fair adder
#

first it had 22 , 9999 , 9220

marsh perch
#

How much time left?

fair adder
#

half an hour

#

man

#

this is taking long

marsh perch
#

Ok

fair adder
#

man

#

i am giving up

hushed palm
#

i dont change anything you can try

fair adder
#

is this a joke ??

#

man

#

there are only 2 ports open

#

22 , 9999

hushed palm
#

no many more

#

use -p-

fair adder
#

lets try

#

i generally use -A

#

cause it tells me if there are any tricks

hushed palm
#

i do first "nmap -T4 -vv -p- <ip>" scan and after "nmap -A -p <ports> <ip>" it is work good

fair adder
#

ohh

#

nicee

#

what does -p- mean ??

hushed palm
#

all port

fair adder
#

are you kidding me ??

#

it takes 30 mins for me to scan 1-9999

#

nvm

#

i will try

hushed palm
#

65535 port scan itakes soma time but it have -vv parameter thats mean you can see found ports

fair adder
#

ok

#

obviously this is hogwarts machine

#

and the real hogwartsz was hidden

#

so this machine will also be hidden

#

i am stupid

#

@hushed palm did you know that we are playing together for several days ??

silk needle
#

I found p139,445 on the first scan

fair adder
#

before i entered this server

hushed palm
#

@fair adder yes i know i see you

silk needle
#

BTW is ro0t here?

#

How did you keep killing my pty?

#

Thinking back, I should have used while with chattr on root.txt...

#

I found someone with linpeas & some repo for privesc and just deleted them

fair adder
#

@hushed palm man that message of "this is how legends win" was awesome , but it annoyed me , cause it crashed my computer whenever you did it

#

but it was cool tho

silk needle
#

BTW, for those of you struggling with the long time it takes to nmap all the ports, I use rustscan which returns all the open ports in a few seconds

fair adder
#

ok

hushed palm
#

actually i didnt write it, in that game i use a while script for write my name in king.txt and i left root, the other guy didnt find the script and he write it ๐Ÿ˜„

silk needle
#

yeah I didn't notice when I lost king

fair adder
#

so who broadcasted that message ??

silk needle
#

what message?

fair adder
#

asking Gev

silk needle
#

I just tried dumping /dev/urandom on a random pts

hushed palm
#

SoWhat. broadcasted that message and he broke the terminal several times

fair adder
#

yeah

#

thats why i had to reset

silk needle
#

Yeah I lost my terminal several times

#

Wait are we all talking about Tyler? I didn't notice a reset at all

fair adder
#

SoWhat. broadcasted that message and he broke the terminal several times
@hushed palm actually that crashed my computer

hushed palm
#

oh

fair adder
#

even more ANNOYING

marsh perch
#

Are we allowed to write script that automatically write to file every minute or every 2 minutes?

silk needle
#

yes

fair adder
#

its simple

#

in c

hushed palm
#

@fair adder do you find the other ports?

fair adder
#

nah

#

its still searching

silk needle
#

Many of us use while [ 1 ]; do echo USERNAME > /root/king.txt; done

marsh perch
#

Ok

#

You can also write in bash

#

I wasn't sure if we are allowed or not

silk needle
#

add in chattr for more king time

fair adder
#

man

silk needle
#

once more than one user has root, it's just a race condition with while on king

hushed palm
#

@marsh perch you can find this scripts in ps and you can kill so this need be allowed

marsh perch
#

Yeh I used once

versed estuary
#

@fair adder blobheart

marsh perch
versed estuary
fair adder
#

@hushed palm i thought that once i am root , i will make 5 more directories identical to /root and then see what happens to other players

hushed palm
#

lol xd

silk needle
#

If you watch JohnHammond do KOTH, you'll see some fun ways players mess with others and how while is inevitable

hushed palm
#

@hushed palm i thought that once i am root , i will make 5 more directories identical to /root and then see what happens to other players
@fair adder this is very good xd

marsh perch
#

king time is very less

#

Is it difficult machine guys?

fair adder
#

it will be very awesome

#

but i didnt get root access

silk needle
#

Tyler? TBH now that I know the solutions everything is super simple

#

I know only 1 route though

#

I used SSH as narrator

fair adder
#

@hushed palm sowhat annoyed me sooooo much

#

that in 1 match

silk needle
#

someone apparently got in as the other user

fair adder
#

i got root

#

and killed ports

#

and changed the password of root

#

and ssh into it

hushed palm
#

yes and he was kill all suid files too this is very bad

silk needle
#

I kept getting kicked out but the routes in were untouched so I kept coming back

fair adder
#

and kill the gateway i got

#

yeah

silk needle
#

I used a SUID for root

#

didn't get nuked

fair adder
#

if i meet sowhat again

silk needle
#

BTW where do KOTH boxes come from? I'd like to practice some.

fair adder
#

i will try hackin to his machine and formatting it

#

raging

#

still the nmap scan going on

#

waiting for it to finish

hushed palm
#

do you use -vv parameter?

fair adder
#

nah

hushed palm
#

oh

fair adder
#

i dont even know what that does

#

what does it do ??

hushed palm
#

it is verbose

fair adder
#

ok

hushed palm
#

writeing found ports in same time

fair adder
#

i know what it means

#

sorry

hushed palm
#

you dont need wait for finsh scan

fair adder
#

for being rude

boreal flare
#

How long till the machine finishes?

fair adder
#

15 mins

hushed palm
#

16m

boreal flare
#

Okki ping me for the next one

fair adder
#

okie

#

waiting for the nmap scan

#

why nmap is soooooooo slow

marsh perch
#

If you guys are playing next then I will also join

fair adder
#

I haven't slept and it's 5 AM, same here

hushed palm
#

nice

fair adder
#

anyways

#

it ended

#

join

boreal flare
#

Which one is it?

marsh perch
#

change start time

fair adder
#

it is a public one

marsh perch
#

let's play private so we can start early

#

use random

fair adder
#

ok

#

join

#

15 mins

#

i think we can wait 15 mins

marsh perch
#

Ok

hushed palm
fair adder
#

already here, thanks gev!

hushed palm
#

^^

fair adder
#

just a fyi I've only participated in one other KotH so it's likely I won't get in easily ๐Ÿ‘€

boreal flare
#

im in as well ๐Ÿ˜„

marsh perch
#

๐Ÿ™‚

fair adder
#

thats the reason i cant find any public matched when i didnt came in this server

#

everyone here plays private matches

#

its good i came here

#

how do you get this tags of god and etc

#

??

#

sorry was trying to search for the command

#

!level

#

nope, well it's down to participation

#

if you complete rooms you get XP, that XP translates to levels

#

ok

#

thanks

boreal flare
#

Good Luck people

marsh perch
#

What's your name @boreal flare in Koth?

boreal flare
#

lostayush

marsh perch
#

Ok

boreal flare
#

my vpn doesn't work cri

fair adder
#

what ??

#

my nmap scan also didnt finish till now

#

@hushed palm salute to you

marsh perch
#

Not sure where to look

#

both apps has larger attack surface

fair adder
#

which both ??

marsh perch
#

Oh wow Gev got king

fair adder
#

yeah

marsh perch
#

check open ports

fair adder
#

samba is of no use

#

139 , 445 - trash

hushed palm
#

samba just have flag

fair adder
#

80 - contains a clue

#

22 - access point

#

8080 - invulnerable

#

thats it

marsh perch
#

8009

#

may be

fair adder
#

but it resets connection everytime we try to connect

#

i am quick at info

marsh perch
#

Yes

fair adder
#

what else remains ??

#

wanna try a reverse shell on 8009 ??

#

that might be the way

#

feels bad, I literally can't install mysql tools

#

sad

#

what ??

#

king changed

#

i am a fool if i still cant catch the vuln

marsh perch
#

I am also not able to find anything

fair adder
#

what if there is a free telnet nologin connection at a random port ??

#

ok

#

either i am stupid

#

or this machine is hard

#

ohhhhhh

#

3306

#

shit

blazing jackal
#

yo

fair adder
#

hi

blazing jackal
#

4 koth in a row wtf

fair adder
#

yeah

blazing jackal
#

ur playing?

fair adder
#

yeah

marsh perch
#

mysql -u root -h 10.10.7.63 -p
Enter password:
ERROR 1130 (HY000): Host 'ip-10-13-5-13.eu-west-1.compute.internal' is not allowed to connect to this MariaDB server

fair adder
#

@marsh perch any lead ??

marsh perch
#

No

#

remote connection is not allowed

blazing jackal
#

wut id?

marsh perch
#

@hushed palm Any nudge?

fair adder
#

if you're looking for a foothold, idk, but points-wise there's easy flags posted about

#

try looking at SMB and gobuster

blazing jackal
#

this windows machine is fcing hard wtf

fair adder
#

but man

#

nvm

#

this is confusing

#

ehh

#

how do you even connect to a samba server ??

marsh perch
#

I tried smb

fair adder
#

ok

#

i am stupif

#

I tried smb
@marsh perch you tryin confuse me ??

stiff egret
#

While discussing the game is what actually makes it more fun, just try not to disclose/spoil machine related stuff, :)
You can always use ||<spoiler>|| to mark it as spoiler.

fair adder
#

ok

marsh perch
#

Not finding anything

fair adder
#

we are stupid i think

marsh perch
#

Are you sure there is nothing on ||8080||

fair adder
#

yeah

marsh perch
#

Because that application has larger attack surface

fair adder
#

it is the ||web configuring ||

marsh perch
#

if we find cred then we can get reverse shell

#

I still don't understand meaning of flag and ||robots.txt||

fair adder
#

is there any ||default username of password|| of that ??

#

that application ??

#

thanks for the php upload, I didn't have one on hand :3

boreal flare
#

lol

fair adder
#

what is goin on ???

covert vale
#

While discussing the game is what actually makes it more fun, just try not to disclose/spoil machine related stuff, :)
You can always use ||<spoiler>|| to mark it as spoiler.
@stiff egret <spoiler>

marsh perch
#

Any nudge @boreal flare

#

at least which port

covert vale
#

๐Ÿ’ฉ

boreal flare
#

||webserver||

marsh perch
#

lol

covert vale
#

55007

fair adder
#

what ??

marsh perch
#

webserver is running on various ports

fair adder
#

1337 port is open

#

letsss goooooo

covert vale
#

Then try port forward tech :
And scan once again nmap

fair adder
#

yessssss

#

ok

#

1337 is nginx

stiff egret
#

@stiff egret <spoiler>
@covert vale huh?

marsh perch
#

a lot of rabbit holes

boreal flare
#

webserver is running on various ports
you asked for a nudge and i gave it to you .. rest is upto you ๐Ÿ™‚

marsh perch
#

Ok

fair adder
#

@marsh perch any leads ??

#

i think they are patching it

marsh perch
#

no

boreal flare
#

well i'm not and i dont think gev is patching either

fair adder
#

ok

#

areeeeee yr

#

i dont know anything abt it

#

this is hard

#

not patching either, tfw your binaries don't work smh

#

literally i am stupid

#

i am the stupidiest

#

of this discord group

#

this is your first KotH, it's not easy y'know

#

i am playing contantly doing koths from past 3 days

#

my service for people

#

PORT STATE SERVICE REASON
22/tcp open ssh syn-ack
53/tcp open domain syn-ack
80/tcp open http syn-ack
139/tcp open netbios-ssn syn-ack
445/tcp open microsoft-ds syn-ack
1337/tcp open waste syn-ack
3306/tcp open mysql syn-ack
8009/tcp open ajp13 syn-ack
8080/tcp open http-proxy syn-ack
8734/tcp filtered unknown no-response
9999/tcp open abyss syn-ack

#

"waste " lmfao

marsh perch
#

oh man

fair adder
#

i have even more

#

want it ??

marsh perch
#

not sure

#

Unable to find anything

fair adder
#

11007/tcp filtered unknown no-response
15170/tcp filtered unknown no-response
15300/tcp filtered unknown no-response
19494/tcp filtered unknown no-response
20822/tcp filtered unknown no-response
22344/tcp filtered unknown no-response
26045/tcp filtered unknown no-response
29613/tcp filtered unknown no-response
36627/tcp filtered unknown no-response
40354/tcp filtered unknown no-response
45816/tcp filtered unknown no-response
48064/tcp filtered unknown no-response
49929/tcp filtered unknown no-response
53431/tcp filtered unknown no-response
53803/tcp filtered unknown no-response
53954/tcp filtered unknown no-response
56537/tcp filtered unknown no-response
61757/tcp filtered unknown no-response

#

this is what i have

#

ahsgdjhasgdjhasgdjasd

#

what ??

#

I'm so close it's actually kinda painful

#

literally (figuratively) root

#

EUID rn

#

i am just chillin out

boreal flare
#

i saw someone got root

fair adder
#

cause i have nothin in mind now

marsh perch
#

didn't get single flag

fair adder
#

me too

#

yeah but I have no idea how to stablize this foothold

#

man

#

i need to study

#

computers and tryhackme

#

this is very hard

#

@boreal flare can i get a writeup ??

boreal flare
#

i haven't made one

marsh perch
#

I found user for ||WP||

boreal flare
fair adder
#

please

#

help

#

me

#

i

#

am

#

losin

marsh perch
#

I also need help

fair adder
#

and

#

i

#

cant

#

learn

#

anything

#

๐Ÿ˜ญ

boreal flare
#

try doing some basic boxes first

#

koth is intermediate level

fair adder
#

like ??

marsh perch
#

Problem is rabbit holes

boreal flare
#

am not saying that i am but ... knowing some stuff beforehand works wonders

#

like learn linux

#

easy ctfs

marsh perch
#

I was able to get shells in 3-5 minutes for Koth

fair adder
#

i know linux

#

i compete in easy ctfs

boreal flare
#

and maybe watch some videos

fair adder
#

i did a buffer overflow

boreal flare
#

how are you still 0x1?

marsh perch
#

I don't like submitting answers to THM questions

fair adder
#

and i host my own irc server , ftp server

marsh perch
#

specially for Metasploit

#

I avoid using metasploit

fair adder
#

bruh

#

and i do everything

boreal flare
#

wut ?

fair adder
#

you own an irc, ftp, how are you 0x1?

boreal flare
#

why not submit answers lmao

fair adder
#

but i cant do a || fucking || box

boreal flare
#

PG13 pls

fair adder
#

i am useles

marsh perch
#

It happens @fair adder

#

No need to demotivate yourself

short tusk
#

pg13 means minimal swearing @boreal flare

marsh perch
#

Not all boxes are same

boreal flare
#

uhh .. ok

fair adder
#

i even complted 1 box

boreal flare
#

have you got a scraper for pg13 i wonder jabba kekw

fair adder
#

that spacejam one

#

and that fortune one

#

i completed all those machines

#

and still

#

STILL

marsh perch
#

Alright guys few seconds

boreal flare
#

oh .. dont worry you'll get there

hushed palm
#

wp guys

fair adder
#

i am a stupid person

marsh perch
#

then may be we can ask someone

boreal flare
#

GG people

fair adder
#

g

#

g

#

you're not dumb for not knowing how to hack

#

it's a diff. skill set entirely

#

i am dumb

boreal flare
#

exactly

fair adder
#

i think

#

even @boreal flare says i am dumb

#

man

marsh perch
#

Guys can I get help now

fair adder
#

๐Ÿ˜ญ

boreal flare
#

oh i wasn't

fair adder
#

gg

boreal flare
#

i was agreeing with "brackets" lmao

fair adder
#

RESPECT - 10000000

#

I never really made a name so I just stuck w/ it

#

i hope there is a spacejam machine next ime

#

anyway how did you guys move from EUID to UID?

#

I tried setting up ssh for root ๐Ÿ‘€

#

didn't work, still asked for pass

#

@fair adder how did you get a shell ??

#

am I allowed to say?

#

dm me

#

next koth please

boreal flare
#

do you guys wanna play hogwarts ?

fair adder
#

sounds neat, I'll try

marsh perch
#

Oh man

#

I feel very bad. I ignored that

boreal flare
fair adder
#

i want to play hogwarts

boreal flare
#

starts in 5

#

hogwarts

boreal flare
#

brackets are you epoch ?

fair adder
#

ye

marsh perch
#

Which machine is this?

#

random?

fair adder
#

is it allowed to say illegal stuff here ??

#

i wanna confess something

boreal flare
#

the machine is hogwarts

#

and yes you're not allowed to say illegeal things here

fair adder
#

||i leaked among us pc version for free and i talked with lawyers and its completely legal to use , this is what i wanna confess , i think it is not illegal , above message is just a jk , lmao ||

#

i hope you understand

#

I mean, you need to login to actually use it

boreal flare
#

Lol

fair adder
#

oh :v

#

I mean, you need to login to actually use it
@fair adder nah

#

box is up

#

its just a exe file

boreal flare
#

I don't have rustscan installed lmao

fair adder
#

is rustscan actually that much better?

boreal flare
#

Well it is for initial enumeration

#

But the results are not consistent

fair adder
#

better or worse than nmaps?

boreal flare
#

Nmap is good

#

But takes too much time

fair adder
#

huh

boreal flare
#

Rust scan is just fast

#

And it invokes nmap on the ports that it finds

fair adder
#

nmap has config files that I'd imagine you'd be able to implement into rustscan

#

though, as an official patch nmap probably wouldn't like it

boreal flare
#

Som many f ing typos

fair adder
#

can i post the free version here ??

#

or its not allowed ??

#

this box is so weird

#

nah

boreal flare
#

No dont

#

Unless you wanna get banned

fair adder
#

i am gonna speedrun now

#

to root of the box

boreal flare
#

Well good luck

fair adder
#

oh no it's potter triva

#

yeah

#

ressurection stone

#

neville

#

thanos

#

voldemort

boreal flare
#

somethings wrong with the box i think

fair adder
#

etc

#

thanos

#

somethings wrong with the box i think
@boreal flare nah

#

ah yes my favourite character

#

do you know harry potter didnt kill voldemort

#

I never saw it tbh

#

actually when thanos snapped

#

that time voldemort died

boreal flare
#

wtf is going on

fair adder
#

nothin

#

just distracting you

#

so that i get time for scanning the machine

boreal flare
#

when i type || ls || it says illegal port command

fair adder
#

yes it is

#

wait I just get an empty directory

#

cause you didnt use -A

#

nah

#

wait that's a thing?

boreal flare
#

wait I just get an empty directory
@fair adder how ?

#

can i dm you brackets ?

fair adder
#

i have the whole pathway to machine's root

#

"directory" meaning the login place itself xp

#

its my time now

#

aka I got into an empty FTP

#

there is nothing like that

#

aka I got into an empty FTP
@fair adder wait that ??

#

yeah

#

there are 5 ftp in this machine

#

what

#

only 1 contains the pass

#

sadly

#

yes it is

#

???

#

yes

#

its true

narrow fern
#

Are u sure?

fair adder
#

yeah

#

cmon man

#

i did that machine 5 times

boreal flare
#

i'm so sad rn

fair adder
#

@boreal flare if I didn't answer then yea, you can dm

boreal flare
#

i wont play on fresh installs

fair adder
#

it's just all harry potter triva ๐Ÿ˜ญ

#

@fair adder can you tell me the port of that ftp server ??

#

i will help you

#

surely i will help

#

port ??

narrow fern
#

Port: 69

fair adder
#

cmon

#

thats false

narrow fern
#

Maybe it's 22.

#

try that

fair adder
#

nah

#

its the ssh server

boreal flare
#

lol'

marsh perch
#

How to ignore unsafe port error

nova tide
#

hogwarts?

marsh perch
#

Yes

fair adder
#

you're running HTTPS on a HTTP server lol

nova tide
#

How to ignore unsafe port error
you gotta use google for that.. would be faster and more helpful.

fair adder
#

It's the hogwarts box, I haven't enum'd any HTTPS

#

cmon

marsh perch
#

getting for windows

fair adder
#

i have everything

#

pass and user

#

but i have to find ssh port man

#

i got a shell

#

BOOM

boreal flare
#

noice

#

good luck with getting king tho

#

๐Ÿ˜›

fair adder
#

i get a flag and i win

#

what ??

#

shit

#

tfw john says: No password hashes loaded (see FAQ)

boreal flare
#

mind sharing an ss ?

#

maybe better if dm

fair adder
#

ss?

boreal flare
#

screenshot

fair adder
#

probably not rn

boreal flare
#

okay

fair adder
#

@boreal flare any clues ??

#

please

boreal flare
#

you are on the box right

fair adder
#

yeah

boreal flare
#

what more clues do you need ?

fair adder
#

why doesn't zydra have a requirements.txt file

boreal flare
#

hide that prolly

#

@fair adder

fair adder
#

ok

boreal flare
#

try enumerating

fair adder
#

how ??

boreal flare
#

find sgid and suid files

#

try sudo -l

fair adder
#

ok

#

ok

#

nothin

#

sudo -l doesnt work

boreal flare
#

ok.. maybe

fair adder
#

there are no suid binarues

#

linenum doesnt work

#

wdym?

fair adder
#

chmod +x linenum.sh

#

there is no script like linenum

boreal flare
#

you haven't uploaded it ?

fair adder
#

nah

#

. _.'

#

how to upload it ??

#

I uploaded it last KotH to /tmp

#

fire up a http server or send it via nc

marsh perch
#

||Resurrection stone||

fair adder
#

thanks a ton

marsh perch
#

Stucked here

fair adder
#

if we're doing another KotH can it not be happy potter themed?

#

@boreal flare any hints

#

which doesnt include that i already know

marsh perch
#

Yes

boreal flare
#

any more would be like giving you the answer

fair adder
#

man please

#

YES I GOT ZYDRA TO WORK

#

atleast upload the linenum for me

boreal flare
#

lol

fair adder
#

i dont know how to upload

marsh perch
#

ujse nc

boreal flare
#

that i can

marsh perch
#

*use nc

fair adder
#

i forgot scp

marsh perch
#

or http server

fair adder
#

am i a fool to you

marsh perch
#

Help me to get shell lol

#

I will upload all scripts for you

fair adder
#

man

boreal flare
#

ahh i see what the problem is

fair adder
#

i give up

boreal flare
#

i cant upload either

fair adder
#

this is shit

#

i give up

#

technically i get 10 points cause i got a foothold

#

i cant upload either
@boreal flare any hints ??

#

if not i give up

boreal flare
#

hop over to dms

fair adder
#

ok

#

got root

boreal flare
#

nice

marsh perch
#

also found ftp

boreal flare
#

my vm died ๐Ÿ˜ข

fair adder
#

gg

boreal flare
#

GG people

fair adder
#

i am sooooooooooooooooo angry at myself

marsh perch
#

lol I didn't check ftp properly

fair adder
#

i will kill myself

marsh perch
#

I thought it's empty

fair adder
#

fuck me

#

words

#

keep it PG13

#

kill me

#

you'll get muted, warned or banned if you keep it up btw

#

well i am ||13|| btw

#

XD

#

still, the rules do apply

#

lmfao

#

ok

#

had I had Zydra installed prior or if my John binary wasn't broken I might've gotten in sooner

#

||kill me and blast me off to venux ||

boreal flare
#

why ?

#

burying wont do ?

fair adder
#

no

#

i am deeserving of the last fragment of rock salt at venus

marsh perch
#

||sudo|| no longer works

#

there is no way other than that

#

@hushed palm

fair adder
#

the connection man

marsh perch
#

reset guys

fair adder
#

nah

#

the koth is over

marsh perch
#

Nah there is another one

fair adder
#

ok

marsh perch
fair adder
#

i am not playinh

#

bye

marsh perch
#

But it seems gev patched that

nova stream
#

15 Minutes

sly turret
#

hybr3d are you here

sly turret
#

hello ๐Ÿ˜„ ... how did you send messages to my terminal in the last Koth round?

stiff egret
stiff egret
limpid flume
#

holmes

stiff egret
#

Hey

limpid flume
#

Hey

gentle hatch
#

whens this one starting?

stiff egret
#

5 Minutes

limpid flume
#

yup

stiff egret
#

I'll leave

limpid flume
#

why

#

its about to start

gentle hatch
#

he made this lmao

#

i figured out how to root it yesterday holmes!

limpid flume
#

lol

stiff egret
#

i figured out how to root it yesterday holmes!
@gentle hatch noice

#

Rooting hogwarts is ez, getting foothold is hard

limpid flume
#

I have no idea how to do this

stiff egret
#

Enumerate, Use tools like rustscan.

limpid flume
#

I found .... ports open

gentle hatch
#

i finally figured out why i couldnt ssh into root too ๐Ÿ˜„

#

v sneaky

limpid flume
#

aaaaaaaaaaaaahhhhhhhhhhhhhh

gentle hatch
#

if you guys can enumerate usernames and the ssh port I left a backdoor with a very easy password

limpid flume
#

oh

#

I found a potential username

gentle hatch
#

nice! now try to ssh with that username

#

the pw is very short, less than 8 characters, should definitely be in a popular password cracking file

limpid flume
#

I am trying to ssh into it but it does not work

gentle hatch
#

probably the wrong username, try to think of what usernames would most likely be on a harry potter themed box

#

ssh is on a weird port

#

make sure you know how to ssh on a different port

limpid flume
#

I found another potential username

nova tide
#

starting in one minute

gentle hatch
#

hm havent done this one yet

#

glhf

sly turret
sly turret
#

@nova tide did you patched something

gentle hatch
#

gg

nova tide
#

No

gentle hatch
#

I had root but couldnt do much lmfao

nova tide
#

i'm in 3 games rn.. not sure which one you talking about

sly turret
#

ohh nvm ... im stupid :D:D

#

forget to write sudo before the command ๐Ÿ˜„

nova tide
#

ok so no one even got a shell yet on hogwarts.. why would reset it???

fair adder
#

@nova tide good game

nova tide
#

๐Ÿ™‚

fair adder
#

my friend was deleting my shells

nova tide
#

ooh

#

rip

fair adder
#

and I couldn't catch a flag

#

rip ๐Ÿ˜ž

#

someone deleted the end directory too i think

nova tide
#

public game starting in 2 minutes

nova tide
#

ok who is that meow guy again?

#

in my koth match

fair adder
nova tide
#

That's a spectator link, you have to share invite link

blazing jackal
#

@nova tide

#

im in

#

hogwarts machine was ez, but privesc....

nova tide
#

which user you used to privesc?

blazing jackal
#

sadsalkd only www

#

the default

#

of php webshell

#

idk how to escalate

nova tide
#

soo for now you only have a shell on it?

blazing jackal
#

im in another game bruh. 16min to start

#

only remebering

#

i played with u

#

demoni386

nova tide
#

ooh my bad i forgot

#

i was in like 3-4 games at the same time ๐Ÿ˜„

blazing jackal
#

fjksabhdjfbs

#

wtf meowless joined

#

shit

nova tide
#

He gonna leave now

fair adder
#

meowless is really good

gentle hatch
#

he is sus

fair adder
#

sometimes he get king in 1 second

quiet schooner
#

@blazing jackal Please keep it safe for work.

blazing jackal
#

@quiet schooner sorry

fair adder
#

@blazing jackal Please keep it safe for work.
@quiet schooner please

quiet schooner
#

Also, they can't read your messages as they're banned here.

blazing jackal
#

meowless is banned?

#

why?

gentle hatch
#

he was talking about doing illegal stuff in his country iirc

quiet schooner
#

Plus the toxicity.

blazing jackal
#

hmm, cringe

gentle hatch
#

so i seriously doubt he plays koth clean, people seem to always complain about it, just plays like a jerk

quiet schooner
#

Report them if so

blazing jackal
#

want see he solve some HTB machine

#

freacrin hard

nova tide
#

Can you guys please not spam reset??

blazing jackal
#

bruh

#

meowless regenerated ssh

#

@nova tide

nova tide
#

okk soooo?

blazing jackal
#

im sad

nova tide
#

soo you spam reset?

blazing jackal
#

nn

#

no

#

i aint reseted

fair adder
#

isn't me

nova tide
#

well someone is spamming the reset button just because they don't have ashu id_rsa access anymore..

blazing jackal
#

bruh

fair adder
#

yes

nova tide
#

4 resets in 20 minutes......

blazing jackal
#

somenone hacked me

#

i have been nyaned

nova tide
#

Please don't reset now

fair adder
#

kkkkkkkkkkk

blazing jackal
#

wtf someone deactivated all the socks

blazing jackal
#

gg

#

someone killed my ssh like 8900 times

nova tide
#

ok i realllllyyyy don't wanna say something.. but please don't spam reset when one way is patched.. pleaseeeeeeeeeeeeeeeeeeeeeeeeeee

#

Bye

fair adder
#

oh boy my favourite type of player, the type that weaponizes the reset button

#

they're probably worse than people who DoS HTB boxes

searchsploit apache

fair adder
turbid narwhal
#

Anyone for koth?

#

Or I need to play w myself

fair adder
#

hi

dreamy rune
#

hi

fair adder
#

anyone wanna play koth ??

dreamy rune
#

im in a game. Is going sooo slow

#

i cant even acces the webpage

fair adder
#

@hushed palm why

#

why you have to kill my terminal ??

#

i got root shell

#

hehehehehe

hushed palm
#

xd

fair adder
#

you failed at your work

#

yessssssssss

#

even tho i entered late

hushed palm
#

why you have to kill my terminal ??
@fair adder i am sorry i have 53m king time and i didnt want to lose this xd

fair adder
#

ok

#

its okay

#

next koth ??

hushed palm
#

i am here

fair adder
#

you used ||application.zip|| ??

#

to get root ??

hushed palm
#

how did you make this spoiler thing

fair adder
#

|| <spoiler> ||

hushed palm
#

i was use ||nfs||

#

ok xd

fair adder
#

| spoiler here |

#

like that

#

just || both side

hushed palm
#

oh ok thank you

fair adder
#

welcome

#

next koth ??

hushed palm
#

i am waiting for url

fair adder
#

you used that zip to get root ??

#

ok

hushed palm
#

no i use a suid file: xargs

fair adder
#

no

#

to log in

#

no i use a suid file: xargs
@hushed palm are you stupid ??

#

||fortuna was allowed to run any command with sudo ||

hushed palm
#

i said to log in i was use nfs and you ask that again and i think you asked for priv esc ๐Ÿ˜„

fair adder
#

i got fortuna

hushed palm
#

i was use nfs

#

i dont use fortuna

#

i use hermes user

fair adder
#

ohh

#

ok

#

actually i got the creds of fortuna in a zip file

hushed palm
#

i know in 3333 port

fair adder
#

yeah

#

it was easy

#

very easy

hushed palm
#

yes bec i was add all sudo priv for fortuna ๐Ÿ˜„

fair adder
#

i still wonder why other people didnt get i ?

#

yes bec i was add all sudo priv for fortuna ๐Ÿ˜„
@hushed palm so you added sudo perms to fortuna ??

hushed palm
#

i think they gave up quickly

fair adder
#

ok

hushed palm
#

yes bec no one come

fair adder
#

ohh

#

but i came then

#

and it became your mistake

#

hehehehe

#

๐Ÿ™‚

hushed palm
#

yes but 5 minutes before ๐Ÿ˜„

fair adder
#

yeah

#

anyways

#

i think pico binary was allowed to run as sudo

#

by default

#

Bella Ciao - ORIGINALE

fair adder
#

man

#

@hushed palm i got ashu's shell btw

#

why the heck you disconnected me

#

??

hushed palm
#

i have my own shell

fair adder
#

man

hushed palm
#

i am realy i didnt do this for you

fair adder
#

you killed my terminal

hushed palm
#

no i am not

#

i would say if i did

fair adder
#

and its not connecting

hushed palm
#

we have 1 player too in here

fair adder
#

someone resseted

hushed palm
#

yes

fair adder
#

i didnt know

#

any hints??

hushed palm
#

look at file sharing services

fair adder
#

man

#

i got ASHU'S SHELL

#

how to get root ??

#

i mean

#

hints

#

i got 1 more point

#

yesssssssss boi

#

man

#

@hushed palm any hints to get the password of ashu ??

#

i am in ashu shell

hushed palm
#

you dont need any password

fair adder
#

but for sudo man

#

i need password

hushed palm
#

sudo have NOPASSWD feature

#

just try sudo -l

fair adder
#

no

#

[sudo] password for ashu:

#

what now ??

short tusk
#

enter Ashu's password

fair adder
#

i dont have it

#

i am in its shell

short tusk
#

Well then you can't

#

No password, no sudo

fair adder
#

then how would i know

hushed palm
#

oh the other user do this

#

he use passwd command

fair adder
#

what ?

#

man

#

this is not fair

hushed palm
#

ashu now have a password, did not exist before i was use that

fair adder
#

shit

#

what now

#

no sudo

#

no enumeration

#

no root

#

@hushed palm now what ?

#

i should wait ??

hushed palm
#

what a game

fair adder
#

yeah

#

@hushed palm the shell communication is very confusing

hushed palm
#

yes

turbid narwhal
#

wtf???

fair adder
#

you edited sudoer file

hushed palm
#

are you sure, i could use and i am too not root

turbid narwhal
#

idek how to

fair adder
#

yes

#

i am sure

turbid narwhal
#

im just a beginner i dont even know how to

fair adder
#

how did you get root then ??

#

tell me the steps

#

you did got root

#

and editted the /root/king.txt file

#

now tell me

#

how did you get root ??

#

@turbid narwhal care giving any answers ??

turbid narwhal
#

yeah sorry i wasnt here

#

i got ||id rsa from ftp anon login ||

#

then got into ashu

#

then sudo -l

fair adder
#

and how did you get root ??

turbid narwhal
#

||sudo su skidy||

fair adder
#

man

boreal flare
#

Umm better to tag those as spoilers

turbid narwhal
#

changed user

fair adder
#

dont lie

#

dont lie

#

please

#

dont lie

#

thats not the way you get root

boreal flare
#

|| spoiler ||

turbid narwhal
#

thats what i did

fair adder
#

let me reverse search it

#

@turbid narwhal you cheater

hushed palm
#

dude yes this a way ๐Ÿ˜„ you can use || sudo su skidy and skidy have git for sudo||

#

there is more way

fair adder
#

she used this

turbid narwhal
#

whats this?

fair adder
#

i am sure

turbid narwhal
#

idk my friend taugh me this machine

#

idk what youre talkin bout

fair adder
#

dude yes this a way ๐Ÿ˜„ you can use || sudo su skidy and skidy have git for sudo||
@hushed palm man the git was available for sudo

boreal flare
#

would you mind editing these to be spoilers

i got id rsa from ftp anon login
@turbid narwhal

fair adder
#

in ashu shell also

turbid narwhal
#

would you mind editing these to be spoilers
@turbid narwhal
@boreal flare idk how to do that

#

how to edit spoiler

boreal flare
#

|| spoiler ||
..

fair adder
#

@hushed palm who the heck changed the passwords then ??

#

and the sudoer file

#

??

#

its against rules i think

hushed palm
#

sudoer file was normal for me but dont hink its against the rules to change

fair adder
#

ok

#

but ashu sudo required password

#

how the heck am i supposed to get password if i get the only id_rsa ??

turbid narwhal
#

idk u cant my friend didnt tell me that

fair adder
#

someone changed the pass for sure

#

anyways

boreal flare
#

someone changed the pass for sure
@fair adder umm..no you need to enumerate thoroughly

hushed palm
#

password can change you need to do hack

turbid narwhal
#

i didnt cause i dont know how to

fair adder
#

how the heck am i supposed to get password if i get the only id_rsa ??
@fair adder ??

#

there is no possible way

hushed palm
#

@fair adder umm..no you need to enumerate thoroughly
.

boreal flare
#

@fair adder ??
@fair adder you need to learn that and not yell at people

fair adder
#

ok

#

anyways

#

next koth

turbid narwhal
#

im not playin w you

fair adder
#

why ??

turbid narwhal
#

cause youre blamein me for sth i didnt do

#

im good on my own :)

fair adder
#

obviously if you are root then you can do anything

#

thats why

#

just leave it

#

i wont blame again

#

sry

turbid narwhal
#

hmm next time maybe

fair adder
#

ok

#

@hushed palm you coming ??

hushed palm
#

no im tired, next time

fair adder
#

ok

boreal flare
#

Lol

fair adder
#

@boreal flare you ??

boreal flare
#

Umm.... Not me either

fair adder
#

man i just asked man

#

where is the toxicity ??

boreal flare
#

Nevermind

fair adder
#

actually i did that machine 10 times

#

and i was sure that once this machine comes