#koth
1 messages ยท Page 49 of 1
anyone getting trash?
yes, just bec you cant get into the machine doesnt mean the machine needs to be reset. i am just saying
Can someone share link to watch game?
yes bec this machine do this
thats why i resetted
you need scan again
no this machine close the port generally you need scan again and found new ports
now i am scanning every port in 1-9999
yes -p- parameter is good
add --max-retries as you have limited time
done
is the ressurection stone the password of root ??
BTW rustscan is nice for quick scanning
is the ressurection stone the password of root ??
@fair adder @hushed palm
cause i got the ressurection stone
I've learnt the hard way that boxes may have services that aren't on right at the start or something and that it's always good to scan again 5-10 min after starting
this one closes ports
I use rustscan and get open ports seconds after starting the scan begins and get details <1 min later
first it had 22 , 9999 , 9220
How much time left?
Ok
i dont change anything you can try
i do first "nmap -T4 -vv -p- <ip>" scan and after "nmap -A -p <ports> <ip>" it is work good
all port
65535 port scan itakes soma time but it have -vv parameter thats mean you can see found ports
ok
obviously this is hogwarts machine
and the real hogwartsz was hidden
so this machine will also be hidden
i am stupid
@hushed palm did you know that we are playing together for several days ??
I found p139,445 on the first scan
before i entered this server
@fair adder yes i know i see you
BTW is ro0t here?
How did you keep killing my pty?
Thinking back, I should have used while with chattr on root.txt...
I found someone with linpeas & some repo for privesc and just deleted them
@hushed palm man that message of "this is how legends win" was awesome , but it annoyed me , cause it crashed my computer whenever you did it
but it was cool tho
BTW, for those of you struggling with the long time it takes to nmap all the ports, I use rustscan which returns all the open ports in a few seconds
ok
actually i didnt write it, in that game i use a while script for write my name in king.txt and i left root, the other guy didnt find the script and he write it ๐
yeah I didn't notice when I lost king
so who broadcasted that message ??
what message?
asking Gev
I just tried dumping /dev/urandom on a random pts
SoWhat. broadcasted that message and he broke the terminal several times
Yeah I lost my terminal several times
Wait are we all talking about Tyler? I didn't notice a reset at all
SoWhat. broadcasted that message and he broke the terminal several times
@hushed palm actually that crashed my computer
oh
even more ANNOYING
Are we allowed to write script that automatically write to file every minute or every 2 minutes?
yes
@fair adder do you find the other ports?
Many of us use while [ 1 ]; do echo USERNAME > /root/king.txt; done
add in chattr for more king time
man
once more than one user has root, it's just a race condition with while on king
@marsh perch you can find this scripts in ps and you can kill so this need be allowed
Yeh I used once
@fair adder 
and named linpeas.sh

@hushed palm i thought that once i am root , i will make 5 more directories identical to /root and then see what happens to other players
lol xd
If you watch JohnHammond do KOTH, you'll see some fun ways players mess with others and how while is inevitable
@hushed palm i thought that once i am root , i will make 5 more directories identical to /root and then see what happens to other players
@fair adder this is very good xd
Tyler? TBH now that I know the solutions everything is super simple
I know only 1 route though
I used SSH as narrator
someone apparently got in as the other user
yes and he was kill all suid files too this is very bad
I kept getting kicked out but the routes in were untouched so I kept coming back
if i meet sowhat again
BTW where do KOTH boxes come from? I'd like to practice some.
i will try hackin to his machine and formatting it
raging
still the nmap scan going on
waiting for it to finish
do you use -vv parameter?
nah
oh
it is verbose
ok
writeing found ports in same time
you dont need wait for finsh scan
for being rude
How long till the machine finishes?
15 mins
16m
Okki ping me for the next one
If you guys are playing next then I will also join
I haven't slept and it's 5 AM, same here
nice
anyways
it ended
join
Which one is it?
change start time
it is a public one
ok
join
15 mins
i think we can wait 15 mins
Ok
https://tryhackme.com/games/koth/join/867b391ef68b9def6373e83c
@boreal flare @fair adder
already here, thanks gev!
^^
just a fyi I've only participated in one other KotH so it's likely I won't get in easily ๐
im in as well ๐
๐
thats the reason i cant find any public matched when i didnt came in this server
everyone here plays private matches
its good i came here
how do you get this tags of god and etc
??
sorry was trying to search for the command
!level
nope, well it's down to participation
if you complete rooms you get XP, that XP translates to levels
ok
thanks
Good Luck people
What's your name @boreal flare in Koth?
lostayush
Ok
my vpn doesn't work 
which both ??
Oh wow Gev got king
yeah
check open ports
samba just have flag
Yes
what else remains ??
wanna try a reverse shell on 8009 ??
that might be the way
feels bad, I literally can't install mysql tools
sad
what ??
king changed
i am a fool if i still cant catch the vuln
I am also not able to find anything
what if there is a free telnet nologin connection at a random port ??
ok
either i am stupid
or this machine is hard
ohhhhhh
3306
shit
yo
hi
4 koth in a row wtf
yeah
ur playing?
yeah
mysql -u root -h 10.10.7.63 -p
Enter password:
ERROR 1130 (HY000): Host 'ip-10-13-5-13.eu-west-1.compute.internal' is not allowed to connect to this MariaDB server
@marsh perch any lead ??
wut id?
@hushed palm Any nudge?
if you're looking for a foothold, idk, but points-wise there's easy flags posted about
try looking at SMB and gobuster
this windows machine is fcing hard wtf
I tried smb
While discussing the game is what actually makes it more fun, just try not to disclose/spoil machine related stuff, :)
You can always use ||<spoiler>|| to mark it as spoiler.
ok
Not finding anything
we are stupid i think
Are you sure there is nothing on ||8080||
yeah
Because that application has larger attack surface
it is the ||web configuring ||
if we find cred then we can get reverse shell
I still don't understand meaning of flag and ||robots.txt||
is there any ||default username of password|| of that ??
that application ??
thanks for the php upload, I didn't have one on hand :3
lol
what is goin on ???
While discussing the game is what actually makes it more fun, just try not to disclose/spoil machine related stuff, :)
You can always use ||<spoiler>|| to mark it as spoiler.
@stiff egret <spoiler>
๐ฉ
||webserver||
lol
55007
what ??
webserver is running on various ports
Then try port forward tech :
And scan once again nmap
@stiff egret <spoiler>
@covert vale huh?
a lot of rabbit holes
webserver is running on various ports
you asked for a nudge and i gave it to you .. rest is upto you ๐
Ok
no
well i'm not and i dont think gev is patching either
ok
areeeeee yr
i dont know anything abt it
this is hard
not patching either, tfw your binaries don't work smh
literally i am stupid
i am the stupidiest
of this discord group
this is your first KotH, it's not easy y'know
i am playing contantly doing koths from past 3 days
my service for people
PORT STATE SERVICE REASON
22/tcp open ssh syn-ack
53/tcp open domain syn-ack
80/tcp open http syn-ack
139/tcp open netbios-ssn syn-ack
445/tcp open microsoft-ds syn-ack
1337/tcp open waste syn-ack
3306/tcp open mysql syn-ack
8009/tcp open ajp13 syn-ack
8080/tcp open http-proxy syn-ack
8734/tcp filtered unknown no-response
9999/tcp open abyss syn-ack
"waste " lmfao
oh man
11007/tcp filtered unknown no-response
15170/tcp filtered unknown no-response
15300/tcp filtered unknown no-response
19494/tcp filtered unknown no-response
20822/tcp filtered unknown no-response
22344/tcp filtered unknown no-response
26045/tcp filtered unknown no-response
29613/tcp filtered unknown no-response
36627/tcp filtered unknown no-response
40354/tcp filtered unknown no-response
45816/tcp filtered unknown no-response
48064/tcp filtered unknown no-response
49929/tcp filtered unknown no-response
53431/tcp filtered unknown no-response
53803/tcp filtered unknown no-response
53954/tcp filtered unknown no-response
56537/tcp filtered unknown no-response
61757/tcp filtered unknown no-response
this is what i have
ahsgdjhasgdjhasgdjasd
what ??
I'm so close it's actually kinda painful
literally (figuratively) root
EUID rn
i am just chillin out
i saw someone got root
cause i have nothin in mind now
didn't get single flag
me too
yeah but I have no idea how to stablize this foothold
man
i need to study
computers and tryhackme
this is very hard
@boreal flare can i get a writeup ??
i haven't made one
I found user for ||WP||

I also need help
like ??
Problem is rabbit holes
am not saying that i am but ... knowing some stuff beforehand works wonders
like learn linux
easy ctfs
I was able to get shells in 3-5 minutes for Koth
and maybe watch some videos
i did a buffer overflow
how are you still 0x1?
I don't like submitting answers to THM questions
and i host my own irc server , ftp server
wut ?
you own an irc, ftp, how are you 0x1?
why not submit answers lmao
but i cant do a || fucking || box
PG13 pls
i am useles
pg13 means minimal swearing @boreal flare
Not all boxes are same
uhh .. ok
i even complted 1 box
have you got a scraper for pg13 i wonder jabba 
that spacejam one
and that fortune one
i completed all those machines
and still
STILL
Alright guys few seconds
oh .. dont worry you'll get there
wp guys
i am a stupid person
then may be we can ask someone
GG people
g
g
you're not dumb for not knowing how to hack
it's a diff. skill set entirely
i am dumb
exactly
Guys can I get help now
๐ญ
oh i wasn't
gg
i was agreeing with "brackets" lmao
RESPECT - 10000000
I never really made a name so I just stuck w/ it
i hope there is a spacejam machine next ime
anyway how did you guys move from EUID to UID?
I tried setting up ssh for root ๐
didn't work, still asked for pass
@fair adder how did you get a shell ??
am I allowed to say?
dm me
next koth please
do you guys wanna play hogwarts ?
sounds neat, I'll try
i want to play hogwarts
brackets are you epoch ?
ye
||i leaked among us pc version for free and i talked with lawyers and its completely legal to use , this is what i wanna confess , i think it is not illegal , above message is just a jk , lmao ||
i hope you understand
I mean, you need to login to actually use it
Lol
oh :v
I mean, you need to login to actually use it
@fair adder nah
box is up
its just a exe file
I don't have rustscan installed lmao
is rustscan actually that much better?
better or worse than nmaps?
huh
nmap has config files that I'd imagine you'd be able to implement into rustscan
though, as an official patch nmap probably wouldn't like it
Som many f ing typos
can i post the free version here ??
or its not allowed ??
this box is so weird
nah
Well good luck
somethings wrong with the box i think
etc
thanos
somethings wrong with the box i think
@boreal flare nah
ah yes my favourite character
do you know harry potter didnt kill voldemort
I never saw it tbh
actually when thanos snapped
that time voldemort died
when i type || ls || it says illegal port command
yes it is
wait I just get an empty directory
cause you didnt use -A
nah
wait that's a thing?
i have the whole pathway to machine's root
"directory" meaning the login place itself xp
its my time now
aka I got into an empty FTP
there is nothing like that
aka I got into an empty FTP
@fair adder wait that ??
yeah
there are 5 ftp in this machine
what
only 1 contains the pass
sadly
yes it is
???
yes
its true
Are u sure?
i'm so sad rn
@boreal flare if I didn't answer then yea, you can dm
i wont play on fresh installs
it's just all harry potter triva ๐ญ
@fair adder can you tell me the port of that ftp server ??
i will help you
surely i will help
port ??
Port: 69
lol'
How to ignore unsafe port error
hogwarts?
Yes
you're running HTTPS on a HTTP server lol
How to ignore unsafe port error
you gotta use google for that.. would be faster and more helpful.
getting for windows
i have everything
pass and user
but i have to find ssh port man
i got a shell
BOOM
i get a flag and i win
what ??
shit
tfw john says: No password hashes loaded (see FAQ)
ss?
screenshot
probably not rn
okay
you are on the box right
yeah
what more clues do you need ?
why doesn't zydra have a requirements.txt file
ok
try enumerating
how ??
ok.. maybe
you haven't uploaded it ?
nah
. _.'
how to upload it ??
I uploaded it last KotH to /tmp
fire up a http server or send it via nc
||Resurrection stone||
thanks a ton
Stucked here
if we're doing another KotH can it not be happy potter themed?
@boreal flare any hints
which doesnt include that i already know
Yes
any more would be like giving you the answer
lol
i dont know how to upload
ujse nc
that i can
*use nc
i forgot scp
or http server
am i a fool to you
man
ahh i see what the problem is
i give up
i cant upload either
this is shit
i give up
technically i get 10 points cause i got a foothold
i cant upload either
@boreal flare any hints ??
if not i give up
hop over to dms
nice
also found ftp
my vm died ๐ข
gg
GG people
i am sooooooooooooooooo angry at myself
lol I didn't check ftp properly
i will kill myself
I thought it's empty
fuck me
words
keep it PG13
kill me
you'll get muted, warned or banned if you keep it up btw
well i am ||13|| btw
XD
still, the rules do apply
lmfao
ok
had I had Zydra installed prior or if my John binary wasn't broken I might've gotten in sooner
||kill me and blast me off to venux ||
the connection man
reset guys
Nah there is another one
ok
But it seems gev patched that
15 Minutes
hybr3d are you here
hello ๐ ... how did you send messages to my terminal in the last Koth round?
holmes
Hey
Hey
whens this one starting?
5 Minutes
yup
I'll leave
lol
i figured out how to root it yesterday holmes!
@gentle hatch noice
Rooting hogwarts is ez, getting foothold is hard
I have no idea how to do this
Enumerate, Use tools like rustscan.
I found .... ports open
aaaaaaaaaaaaahhhhhhhhhhhhhh
if you guys can enumerate usernames and the ssh port I left a backdoor with a very easy password
nice! now try to ssh with that username
the pw is very short, less than 8 characters, should definitely be in a popular password cracking file
I am trying to ssh into it but it does not work
probably the wrong username, try to think of what usernames would most likely be on a harry potter themed box
ssh is on a weird port
make sure you know how to ssh on a different port
I found another potential username
starting in one minute
@nova tide did you patched something
gg
No
I had root but couldnt do much lmfao
i'm in 3 games rn.. not sure which one you talking about
ok so no one even got a shell yet on hogwarts.. why would reset it???
@nova tide good game
๐
my friend was deleting my shells
public game starting in 2 minutes
That's a spectator link, you have to share invite link
@nova tide
im in
hogwarts machine was ez, but privesc....
which user you used to privesc?
soo for now you only have a shell on it?
im in another game bruh. 16min to start
only remebering
i played with u
demoni386
He gonna leave now
meowless is really good
he is sus
sometimes he get king in 1 second
@blazing jackal Please keep it safe for work.
@quiet schooner sorry
@blazing jackal Please keep it safe for work.
@quiet schooner please
Also, they can't read your messages as they're banned here.
he was talking about doing illegal stuff in his country iirc
Plus the toxicity.
hmm, cringe
so i seriously doubt he plays koth clean, people seem to always complain about it, just plays like a jerk
Report them if so
want see he solve some HTB machine
freacrin hard
btw if anyone wants to join, 9min https://tryhackme.com/games/koth/join/9534fe509c14e8ade41f5a6a
Can you guys please not spam reset??
okk soooo?
im sad
soo you spam reset?
isn't me
well someone is spamming the reset button just because they don't have ashu id_rsa access anymore..
bruh
yes
4 resets in 20 minutes......
Please don't reset now
kkkkkkkkkkk
wtf someone deactivated all the socks
ok i realllllyyyy don't wanna say something.. but please don't spam reset when one way is patched.. pleaseeeeeeeeeeeeeeeeeeeeeeeeeee
Bye
oh boy my favourite type of player, the type that weaponizes the reset button
they're probably worse than people who DoS HTB boxes
searchsploit apache
Anyone for koth?
Or I need to play w myself
hi
hi
anyone wanna play koth ??
xd
why you have to kill my terminal ??
@fair adder i am sorry i have 53m king time and i didnt want to lose this xd
i am here
how did you make this spoiler thing
|| <spoiler> ||
oh ok thank you
i am waiting for url
you used that zip to get root ??
ok
no i use a suid file: xargs
no
to log in
no i use a suid file: xargs
@hushed palm are you stupid ??
||fortuna was allowed to run any command with sudo ||
i said to log in i was use nfs and you ask that again and i think you asked for priv esc ๐
i got fortuna
i know in 3333 port
yes bec i was add all sudo priv for fortuna ๐
i still wonder why other people didnt get i ?
yes bec i was add all sudo priv for fortuna ๐
@hushed palm so you added sudo perms to fortuna ??
i think they gave up quickly
ok
yes bec no one come
yes but 5 minutes before ๐
yeah
anyways
i think pico binary was allowed to run as sudo
by default
Bella Ciao - ORIGINALE
i have my own shell
man
i am realy i didnt do this for you
you killed my terminal
we have 1 player too in here
someone resseted
yes
look at file sharing services
man
i got ASHU'S SHELL
how to get root ??
i mean
hints
i got 1 more point
yesssssssss boi
man
@hushed palm any hints to get the password of ashu ??
i am in ashu shell
you dont need any password
enter Ashu's password
then how would i know
ashu now have a password, did not exist before i was use that
shit
what now
no sudo
no enumeration
no root
@hushed palm now what ?
i should wait ??
what a game
yes
wtf???
you edited sudoer file
are you sure, i could use and i am too not root
idek how to
im just a beginner i dont even know how to
how did you get root then ??
tell me the steps
you did got root
and editted the /root/king.txt file
now tell me
how did you get root ??
@turbid narwhal care giving any answers ??
yeah sorry i wasnt here
i got ||id rsa from ftp anon login ||
then got into ashu
then sudo -l
and how did you get root ??
||sudo su skidy||
man
Umm better to tag those as spoilers
changed user
|| spoiler ||
thats what i did
dude yes this a way ๐ you can use || sudo su skidy and skidy have git for sudo||
there is more way
she used this
whats this?
i am sure
dude yes this a way ๐ you can use || sudo su skidy and skidy have git for sudo||
@hushed palm man the git was available for sudo
would you mind editing these to be spoilers
i got id rsa from ftp anon login
@turbid narwhal
in ashu shell also
would you mind editing these to be spoilers
@turbid narwhal
@boreal flare idk how to do that
how to edit spoiler
|| spoiler ||
..
@hushed palm who the heck changed the passwords then ??
and the sudoer file
??
its against rules i think
sudoer file was normal for me but dont hink its against the rules to change
ok
but ashu sudo required password
how the heck am i supposed to get password if i get the only id_rsa ??
idk u cant my friend didnt tell me that
someone changed the pass for sure
@fair adder umm..no you need to enumerate thoroughly
password can change you need to do hack
i didnt cause i dont know how to
how the heck am i supposed to get password if i get the only id_rsa ??
@fair adder ??
there is no possible way
@fair adder umm..no you need to enumerate thoroughly
.
@fair adder ??
@fair adder you need to learn that and not yell at people
ok
anyways
next koth
im not playin w you
why ??
obviously if you are root then you can do anything
thats why
just leave it
i wont blame again
sry
hmm next time maybe
no im tired, next time
ok
Lol
@boreal flare you ??
Umm.... Not me either
Nevermind