#koth
1 messages Β· Page 50 of 1
but this time it didnt go as default machine goes
even gev was sus of that
thats why
and no one had the shell other than me and gev and tanya
thats why
whatever
π
sorry for toxicity
@fair adder can you message in #talk-with-us-no-threading? I have muted you and will unmute you once we have talked π
starts in 3 minutes
Smart move.
gg
Damnit, I joined in late
me 2, first time getting panda as well
haha yeah
so many flags
you guys were good tho
Public random starts in 20
starts in 5 minss
joined, I accidentally got decaf today so I'll be off game rn
if you're having a hard time finding flags:
|| find / -size 33c -exec grep -lP [a-f0-9]{32} {} \; 2>/dev/null ||
Assuming no one has done anything like the yotf root flag π€·ββοΈ
hasn't done YotF
Oh, I split it up over about six lines
oh
And changed the order around
That also assumes that the flag will be a 32 character hash
As opposed to, uh, any other number
very much, but the current machine's fortuna which, afaik, only uses 32 hex
Oh, I split it up over about six lines
@terse willow this is why no one likes you
wait they're md5s?
Yur
Often
That's usually how they're made
or you just do like me and mash on your keyboard for a bit
I tend to use sha256, technically
alias flag-gen="echo THM{\$(head /dev/urandom | sha256sum | base64 | head -c 32)}"
ooh, kk sorry was searching them in hashkiller.io
ngl it would've been pretty cool had they actually meant anything
Still waiting for someone to find the two I have hidden in my boxes which actually do mean something π
Which boxes you talking about?
@terse willow
π π π π π π π π π π π π π π π π π π π π π
Still waiting for someone to find the two I have hidden in my boxes
which actually do mean something π
π π π π π π π π π π π π π π π π π π π π π
starts in 7 minutes
moved /root to /root2 and made my own /root, turns out that doesn't work either though the implications of having king move and not update... π
epochfluffu right?
gg
starts in 24 minutes
gg
gg
https://tryhackme.com/games/koth/join/e3a26d206c4dd1903ba98461
@sudden tendon @safe crescent @fair adder Do join if you guys are free
I've finished up for the day getting late
get your own binary of chattr on the box and change it to a non-obvious name π
symlink the old version of chattr or rename it to keep people busy
ooh first time getting this box
glhf
ooh first time getting this box
@gentle hatch second time in a day for me
π I installed a really cool backdoor if anyone can manage to find it
machine is dead, reset
monster did you disable ssh before?
i had to re-enable it to get it up before, im gonna report this
pretty weird that web-services are down and ssh isn't working yet you're getting king lol
pls reset
monster did you disable ssh before?
@gentle hatch no dude I thought you did lol
I thought you closed all the ports damnn
the IP address on my browser didnt update after the reset lmfao, apologies
lol it's okay
good game!
i know! i've never seen a game that close lol, I've never beat you until now haha
π π’ It's my birthday and I wanted to win so bad but still couldn't lol
It hurts dude
π¦ happy birthday!
Thanks dudeπ₯°
why do you guys keep resetting?
Hey guys, weβve been fairly lenient on the resets. please donβt abuse this feature, and turn this into a problem. Thanks!
why do you guys keep resetting?
@gentle hatch bc one of us wants a chance at becoming king
@gentle hatch others want a chance
thats not going to help if I already know the method to get root lol
I know to get root and become king you've just locked us out lol! Yes I uderstand thats the point
i just chattrd king.txt no big secret
I know i cant un chatterd it
@Droogy#0282bc one of us wants a chance at becoming king
@obsidian zinc That's not the purpose of KoTH. If one way you know is patched its better to find other possible ways in. instead of spamming reset.
maybe i hid chattr π
I know i cant un chatterd it
@obsidian zinc So its time to useman chattr??
Also you can always get your own chattr binary on the system.
With a different name, hide it in a different place?
Also you can always get your own chattr binary on the system.
@nova tide did not know that
Thanks
same directory just different name if thats okay?
Google: busy box binaries
@nova tide thanks. I appreciate the tip. @gentle hatch did you kick me out lol
no sir I did kill a shell like 10 mintues before but only bc someone killed mine >.<
hmm @gentle hatch I cant get into the machine. Technically im a ma'am
apologies
@gentle hatch all good
i swapped ports on some services
i just left a cool backdoor on the regular http server if someone can find it (no foolin i promise)
@gentle hatch hmmm okay
https://tryhackme.com/games/koth/join/2b05b6fb21566b2aff4431d1 if anyone wants to join
Thanks for the link @obsidian zinc
you are welcome @sudden tendon π
π€ 
Is anyone doing "King of the Hill"?
Just join a public game it will toss you in a match thatβs getting ready to start, you can then share the link here and invite people to join
Is it necessary to have something installed to solve King of the Hill challenges?
kali should be all that is necessary
I don't know why I could not solve any challenge
I don't know why I could not solve any challenge
@crisp needle the machine was patchedπ
So did I have to find the password of that machine?
Each machine is different
So did I have to find the password of that machine?
@crisp needle find vulnerabilities on the machine to exploit
if anyone want to play
I am in, but I don't know if I will score
Yes, cannot access the website by IP address
did you started your openvpn
Does not work
Yes, cannot access the website by IP address
@crisp needle Nto all of them run webservers
Do I need to hack the target machine?
!docs koth
anyone on the box rn ?
I am trying
try to search for a password and a username
Can you show how you managed to become King and how you found easy flags?
ur free to patch but if you wanna have a gentleman's agreement to not kill shells I'll take it
either or tho I dont really mind play however you want π i dont kill shells anyway unless someone starts with me lol
What does killing shells mean?
kill -9 <PID of shell>
ll
kicks you off the machine
kk no shell killing
And how to get an easy flag?
if you get a foothold check user directories
no foothold, check webapp
thats basically it
sometimes an anon ftp server
ahhhhhhhhhhhhhhhhhhhhh
i hate offline
but we
I guess that for koth, it cannot be streamed
Yeah
is anyone already inside
i dont like windows
I use dual boot
yeah i just gotta brush up on my persistence techniques for windows, its a pain tho for sure
at least theres only like a 1/10 chance of getting Offline
at least I found where some ssh passwords are hiding c:
GG
another one ? but pls not windows
im down send link
oo haven't done this one
Me too
starts in 10
i play one more then finally go to gym π
yes sir then i cleared permissions on it
very rarely you have to utilize capabilities for KotH if ever
k
i think there was a suid binary left in there the whole game tho
hopefully you guys didnt get stuck in that python sandbox lol
yeah I removed SUID permissions on vim which got me in initially
lol
I briefly made bash a suid to privesc some redundant shells but that was just like a minute
i was searching for getting root
if I have seen the vim getting root would be easy
then
i dont get it when i search for suid file i get a list ... than i check with ls -la ... but when i want to use it with sudo -u root it says i have no permission
anyone wana hop in the public lobby
you're attempting to execute a command as a lower-privileged user as root which is a big no-no
run whoami
if ur not root then you can't execute a command as root
and if ur not given permissions in the sudoers file then you also can't execute commands as other users
so when my user is not in the sudoers file i cant use Suid binarys
How you are so fast? You became king within 3 minutes.
i literally just did this box last game π
you can @sly turret but double check if SUID bit is set on binary
You just closed every thing in the box..
Now everyone is sitting. hahaha
naw there is still a route
webapp will definitely take a bit of effort now tho
pkexec is not SUID exploitable
yeah ok but its suid so i should be able to run it as root right ?
yeah there is a input field with get parameter.
But I am not able to do anything with that.
not unless you are in sudoers file with permissions to execute files as root
there are some vulnerable processes running tho
you can still submit on webapp, intercept in burp and figure out how to make a submit request
ok let me check.
just think about how php forms process input
you added droogy is the best in that request.. hahaha

i got kicked out a few minutes ago something may have been patched :/
May be because you are king from starting of the game.. π
gg guys
gg everyone!
you were great man @gentle hatch
ahh tysm it was a little unfair since I just did this box before this game but always fun playing with ya π
This was my first time on this box....I was a little cluelessπ but it was fun
should I extend the time.
eh its offline no one is gonna wanna play this anyway
try -Pn
no i mean like the box name lol
i am just practising on AD pls I wanna try on this.I chose this box specifically.
After this we will play it normal way
i dont mind playing this im just saying most people avoid it lol
hey How do u got in?
complete this room and you'll get all the practice you need π https://tryhackme.com/room/blue
Didnt thought it would be vulnerable to blue.I was thinking of GPP aka MS14-025 but sysvol was inaccessible.
starts in 12
Can someone stream how to play once the game is finished?
There are writeups for 2 of the KoTH boxes, on the standalone rooms
I recommend getting some practice on those ones
I already know that I will end up with 0 flags
Yeah, so practice
yes, the box is booting that's normal, you're not a subscriber so you're getting a sample of the attackbox. If you want to use the attackbox more you need to subscribe
The issue is that I don't know how to use that AttackBox to achieve anything
M0N573R777, can you tell how to got the flags?
There's a very important lesson here.
You need to learn the skills. Just having instructions to get the flags probably won't help much. I really really recommend completing some rooms before starting KoTH
if once I bypass by lazy-ness threshold, I'll complete the blog
Do you mean there? https://tryhackme.com/hacktivities
Yes, that's a list of all the public rooms
The issue is that I do not even know where are the relevant files and scripts when I open a new AttackMachine like this
It's basically Kali.
Everything is linked with shortcuts too. You need to practice to get familiar.
There's no way around it, you need to put the work in and practice.
echo "msg" > /dev/pts/$
ooo I know it wasn't with wall because it was "cleaner"
maybe it was the echo method
that's pretty cool
- that was me
- I used wall
- you should give
man walla read.
@stiff egret Stop playing koth behind my back 
Can you use kali browser from phone?? π
If yes i can play 2-3 games during my office hours
Hello there :), i just start a a new public KOT and i had only 404 error when i try to access the page of the session :/ any issue ?https://tryhackme.com/games/koth/12114
It's either that the game actually doesn't exist or Site was going through some troubles few minutes ago, maybe it is because of that. Either way, You can re-join a new game. π€·ββοΈ
humm ok must leave this one before creating a new one i guess
im waiting in the new public lobby rn
π
seems ok now ^^
Aye, go for it @stiff egret
I was trying to brute force the "Hacker" machine's users for over 40min, what was I doing wrong?
is there another trick to it?
@clear pawn someone might have patched it.
if u were in the same KOTH game as me for that I think it was broken, I looked at a writeup after to make sure I wasn't crazy and I did everything right but got a foothold on the wrong user
no one got root
but maybe they updated the box idk
anybody up for KOTH
Who is keen for a KOTH game later in the day?
Lets have a koth.
Whose ready?
first KOTH win!
Nice
Which machine ?
gg
sorry but yes π
wp π
No spoil
i just gotta learn how to avoid getting nyancatted, not sure where to start with that
luckily i had persistence but still
@quiet schooner deleted the messages
The IP address of the target is not given?
GG!
starts in 12
gg π
lol gg dude
boring
@cerulean sparrow want me to join?
I swear no one playing koth knows how to set up persistence
wasnt there just a room on persistence geez

starts in 22
how do you guys brute force hacker so fast
custom wordlists or using -t 64
hmmm custom wordlists ey?
im using rockyou and it's gotten me no where hehe what wordlist are you using?
the one i made for hackers.
alright
rockyou would be enough though
but would take a little bit of more time
just use -t 64
Gg
how much knowledge need to play koth ? is it for intermediate players ?
..
Try Playing a game
yep..
9 min
https://tryhackme.com/games/koth/join/71159ad527aef89b845d96c4
@hushed palm why so pro man .. i got one flag only ooof
@hushed palm why so pro man .. i got one flag only ooof
@grand hamlet keep trying there are multiple vulnerabilities
@grand hamlet keep trying there are multiple vulnerabilities
@hushed palm yep i saw ..
300 points htf...
I mma out π
@hushed palm you do bughunting?
no i dont
okk
r
anyone wana play?
public game in 10 mins β€οΈ https://tryhackme.com/games/koth/join/7ede72152cf63d14f687d496
Anyone keen for a game of koth?
Yeah!I'm bored
Make an invite
starts in 24
EXPIRED
start in 3 mins boys
machine offline
<windows machine>
mm
pl
how's everything going?
im hanging out in public lobby trying to get a game going
If you post an invite link, I'll join. Probably won't play as I'm working on another room, but I'll join so you don't get the game cancelled.
wow thanks, link above
that's just the spectator link, I need the invite link
In the lobby, on the top right, click options. Copy and paste the Invitation Link
No, spectator link only allows user to see scoreboard, whereas to actually play in the game, you need invite link.
start in 5 mins
mmm
Make sure you scan for, and look at, all ports. Especially "non-standard" ones........
how could symlinks be used in red v blue environment (ex : koth)
22 mins
how could symlinks be used in red v blue environment (ex : koth)
@vocal shell #infosec-general
Hey, someone up for koth? Will be an easy one, its my firs ttime π
Hey, someone up for koth? Will be an easy one, its my firs ttime π
@fair adder Oh man one hour too late.. π
Yeah, unfortunately
Got time for another round?
I'm in a public room right now π Starts in 25 minutes
It's my second time ever
Think it could be fun
have you done https://tryhackme.com/room/ctfcollectionvol2 ?
Yeah why? π
The webpage is killing me π
Haha yeah when I opened it the first time I was like: Oh my...
yeah... Is there an option to stop gifs repeating?
There must be
unfortunately i cant voice chat actually π¦ Would be fun
yep looking good
Got two yeah π
Where exactly?
got a ||base64 string which should be a pkzip|| file. but i dont know how to get this file
Please avoid spoilers.
Use ||spoiler|| if necessary
Hope thats better
You can DM me if you want. Then we don't have to spam the chat here π
anyone up for koth ?
At the moment there is a scheduled one open: https://tryhackme.com/games/koth/join/7645b32109206ff0b3e20be1
starts in 17m
Who is modifying the flag in ||/home/ashu|| and deleting the ||server1.py|| in ||/home/skidy||? 
... yeah rude π¦
i found something in server1 but i cleared my terminal and cant remember
Maybe its part of harden the vm -.-
Modifying flags and deleting files are both against the rules
That happend here π¦
Email koth@tryhackme.com with the game ID π
Game ID is the number in the URL, right?
@potent oyster do you know who deleted the file?
anyone up for a match?
starts in 8 minutes
who fork bombed
idk
whaaaaat
@wraith geyser did you delete the flags of fortune?

@wraith geyser did you delete the flags of fortune?
@gloomy estuary i have the same question
i didnt delete the flags
they were all named flag not flag.txt
thats for the 1st 3
idk about the other 4
@fair adder @gloomy estuary
I don't want to know if they were renamed, just if it was you or not
whatever, just want to know who deleted it. Missing flags and some users in / home
all right, bro. I already played this room, and I remember having 2 more users on / home. Someone deleted
[root@tyler narrator]# cd /root
[root@tyler ~]# id
uid=0(root) gid=0(root) groups=0(root)
[root@tyler ~]# ls -la
total 7432
dr-xr-x---. 4 root root 221 Mar 27 2020 .
dr-xr-xr-x. 18 root root 272 Mar 25 2020 ..
lrwxrwxrwx 1 root root 9 Mar 19 2020 .bash_history -> /dev/null
-rw-r--r--. 1 root root 18 Dec 28 2013 .bash_logout
-rw-r--r--. 1 root root 176 Dec 28 2013 .bash_profile
-rw-r--r--. 1 root root 176 Dec 28 2013 .bashrc
drwx------ 4 root root 33 Mar 26 2020 .cache
-rw-r--r--. 1 root root 100 Dec 28 2013 .cshrc
drwxr----- 3 root root 19 Mar 25 2020 .pki
-rw-r--r--. 1 root root 129 Dec 28 2013 .tcshrc
-rw------- 1 root root 0 Mar 27 2020 .viminfo
-rw-------. 1 root root 1418 Mar 19 2020 anaconda-ks.cfg
-rw------- 1 root root 6 Oct 28 03:05 king.txt
-rwx------ 1 root root 7576048 Mar 26 2020 koth
-rw------- 1 root root 33 Mar 26 2020 root.txt
[root@tyler ~]# echo "itspossible9" >> king.txt
bash: king.txt: Permission denied
Why I can't write to king.txt file
cat /usr/bin/chattr
cat: /usr/bin/chattr: No such file or directory
Where is chattr binary?
locate chattr
someone prob deleted it lul
its not always on the system. people upload it from their machine and rename it
ye
Oh I see
you can upload the one from your machine and run it
What's the user of that binary though?
try checking out busybox binaries
you have to be root to use chattr
I was root
well what do you mean with "What's the user of that binary"?
Google chattr
in this case the "immutable" attribute is being set
Oh I see
or just man chattr on your local machine.
Hmmm
Thank you all
Now become king β€οΈ
lol I ran out of time
oh xD
Rank User Country Flags King Time Points
1
pr1sm
6 54m 680
2
itspossible9
5 0m 115
3
mechboy
1 0m 15
Anyways you learned something
Yes
that's all that matters
Have a look here: https://tryhackme.com/games/koth
are the koth machines down?
ote: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.03 seconds
its been 5 minutes
offline
Happened to me yesterday. Had to restart the VM...
Is it allowed in koth to remove entries from /etc/sudoers and alter entries in /etc/passwd? Asking for a friend π
As long as the functionality remains the same @fair adder
For example, if the permission in sudoers is for vim, you could change it to sudoedit over a specific file
Or set the target of a sudo command to something totally useless and very specific
Changing the login from /bin/bash to /bin/rbash seems not really to be the same, right?
I mean, technically throwing someone into a restricted shell isn't really changing the functionality. In the real world that's a protective measure π€·ββοΈ
It's also not impossible to escape something like rbash
Okay. So I'm my friend is safe there.. But what about deleting lines from /etc/sudoers?
If the user is meant to be able to change stuff with sudoers then that functionality should remain -- unless it's a very stupid security hole
user could execute find with root perms... I think this is a security hole.
I would say try not to delete them, but if the line is something like: user ALL=(ALL:ALL) systemctl you could change it so they could only change something specific
Em, yeah, Ok, with something like find, given the exec, I think you'd probably be justified in removing that one
But ideally replace it with something equivalent, without the hole
It's also not impossible to escape something like rbash
@terse willow unless you screw something up when setting up the env for it π
Heh
Oh koth-staff can even remove lead mod's messages 
You should be able to remove anyoneβs, even admins
Hold up fr
thatβs mad
but only in here so big sad
Oh hold we can pin as well very cool Kanye
@mint cargo come here now,i will show you my powers 
https://tryhackme.com/games/koth/12502
https://tryhackme.com/games/koth/join/fa1bec2ba0621ff567cce66d
7 mins
@wraith geyser that's a spectator link
anyone wana play?
10min
To Chmod93, of the koth : Good game ! You scared me, at the end ! π
@mint cargo come here now,i will show you my powers
@nova tide NO
u bully me naughty π¦
heyya
Hey
Heyy
Heyyy
yyeeh
@runic quail #announcements
Aye, thank you @nova tide and @stiff egret . 
π
So when are you guys going to make a blog post on your C2 infra and rootkits π
:never:
^
haha, great post tho btw, I saw a variation of that SSH trick in the operator's handbook except it also bypasses .bashrc and also hides from w and who
(we did leak about clobber)
I just need to keep playing BG with ippsec, dude is always dropping nuggets like that
(only 20
)
I have a quick question about nyancat'ing someone, are you binding the service to a port or having nyancat run whenever a user runs what they think is a legitimate service?
I've tried playing around with it on a VM but couldn't really get it
Don't stop any service.. for nyancat you can just run it on their tty
if you want to take it to next step try making them play tetris
So when are you guys going to make a blog post on your C2 infra and rootkits π
Just look at the opensource Reptile (Kernel Module) or Vlany (ld-preload), are good for starting out.
Nice blog post @nova tide and @stiff egret, also nicely explained. I guess I can win some matches now. π
@weary axle shouldnβt take more than 5 if it does youre doing something wrong
it takes real long
You sure someone hasnβt changed the password
the point of the game is to defend and attack
@weary axle Don't post spoilers without hiding them, also, the machines have multiple entry points, you can always let hydra do its thing while you try to search for more entrypoints,
was that a spoiler??
and how to make text spoler?
You sure someone hasnβt changed the password
@winged charm me and my other account are playing.
no one else
||<spoiler>||
IIspoilerII
if anyone whats to join u can
only 1 min left
sorry guys started
https://tryhackme.com/games/koth/join/e163cbcf213020e8025d83ed
@velvet nexus Have you enumerated the box with nmap? Did you look at the results of default scripts and not just what port numbers are open?
@gentle hatch did u killed ssh? or spawed the port ?
https://tryhackme.com/games/koth/join/4370693c7f33727db7d040be
Beginner friendly not to much patching
@fair adder nyancat is not patching π
Did you have shell?
not atm
Okay
zou changed the ssh port right ?
zou changed the ssh port right ?
@sly turret Maybe xD
If anyone wants to learn/Guidance about KoTH, they can always check out this blog post:
https://blog.tryhackme.com/guide-to-king-of-the-hill/
changed or killed π€
If anyone wants to learn/Guidance about KoTH, they can always check out this blog post:
https://blog.tryhackme.com/guide-to-king-of-the-hill/
@nova tide Nice!
changed or killed π€
@sly turret Nmap can answer your question
What "cheaky" means? ;-;
u crashed the Box ?
u crashed the Box ?
@sly turret Sorry, i was testing the iptables
k
Try again
Use of iptables on the KoTH boxes is banned, iirc
@terse willow lol
I didn't know, sorry @sly turret
If it's a private game, go nuts. Use your own rules π
*within reason
Attacking other user's machines is still off limits, because that's illegal.
Attacking other user's machines is still off limits, because that's illegal.
@quiet schooner The fun is play nyancat on other player's machines
That's different
@fair adder you need that rainbow parrot thing its 100x better than nyancat
@fair adder you need that rainbow parrot thing its 100x better than nyancat
@sly turret xD i will try
@sly turret Did you see nyancat on your terminal?
/etc/ssh/sshd_config
@fair adder can you teach me how you changed the port and the name
@sly turret The name of what?
before you changed it was named ssh on port 22 you changed the port and the name
I just changed the port, maybe nmap identified it as another service
aa ok
starts in 23 minutes
starts in 18 mintues
anybody for koth?
||chattr +i /root/king.txt|| whats the opposite for this command?
nvm found it
for anyone else
it is
||chattr -i /root/king.txt||
anybody playing koth after 5 10 min ???
KoTH anyone ?
Starts in 5min , machine is Hogwarts
https://tryhackme.com/games/koth/join/444d4e32736773b621cd6d3b
starts in 20 mins
join pls
@hot bloom are u playing the koth?
Yep
glhf π
Haha! Let's do it!
hello guys
@patent forge did you give up?
Can someone help with the hogwards KOTH?
I am stuck at a certain point
It would realy help a lot
if you're having trouble just create a private game for it and lab it out
its not a very difficult box, just unique
Thats what i did with a friend of mine
We are stuck on the login page
And we have 24 minutes left
So if you can hint me anything please do
theres a much easier way that doesn't involve any web-hacking
make sure you enumerate all ports properly
did you interact with every single port you found from your scan?
the only thing I can say is that it's a very basic service
there's no need you'll get it π
Someone already playing?
Anyone up for KoTH, ping me too! It's weekend! KoTH night!
In 5mins , Machine : Hogwarts
https://tryhackme.com/games/koth/join/f545421f30c4a6e73cf22a97
@stiff egret Do you want to play too ?
@latent shell it's like your wish come true
lol
@stiff egret Do you want to play too ?
@cerulean maple If you don't have any problem with that
No problem at all , but for a fact I know that I'm going to lose xD
2 min remaining
@latent shell
yaas
hop in
joined
@nova tide I don't think you'll play? (don't it's for fun and we both fight)
me ready 
Oh umair form secarmy how are you
ayy i am good hbu
Fine !
i can't talk on the voice sorry
hop in the game just started
Yes game just started
In 5mins , Machine : Hogwarts
https://tryhackme.com/games/koth/join/f545421f30c4a6e73cf22a97
@cerulean maple this?
yes
I'm playing siege for now
Oh
NOICE
nice port list you got there π€£
hogwarts?
yes
you are not allowed to play it
Ik, but umair insisted
good luck to him then
no i didn't , he is abusing us with his machine
FFS
hogwarts i have already played that machine before
lies on the top of lies on the top of lies
xD
LOL
will you guys play another box after this
sure
Private, random, 5 minutes
that's better
lol
@nova tide

damn 1 vote to reset the machine
becuase you patched everything
what, no
becuase you patched everything
@noble wren uhmm do you even know the rules??
I did this while sharing screen, I didn't patch one thing
Yeah, tho I haven't patched, but patching is not against the rules, it is actually the purpose of this
@nova tide lol then what is the purpose of playing it

There's nothing patched.. you are not Trying hard enough
check the blog post/pin message if you want to know anything about KoTH
bruh you aren't even playing
But i know the rules and you should too
lol, you know?
um, What do you mean?
GG
but just so you know,
Even tho I didn't patch anything on machine, as Naughty said, patching is one of the main purposes of this game, I didn't patch it so others can get a chance.
GN
nuh. it's for @nova tide
@noble wren you even have any idea what you are even saying?
GN
22 min
ive never done a KOTH before, i might be an easy opponent
nice and windows decided to reject my activation key right as soon as i joined
i definitely need to hone my skills before doing one of these in the future
im not giving up but i definitely wont be winning this lul
Hi @fair adder
hi
Any hint for privesc?
tmux?
idk xD
You'll have to find out
I tried tmiux earlier but it wasn't working
@marsh perch There are others ways
pls join
I am not able to find anything on this box
@fair adder
I will appreciate if you can help little bit
Do you have shell?
Hmmmm....
I have patched the tmux EOP
So maybe you should take a look at the versions
lol
have you attempted to scour for a writeup
hey guys
when i do ||echo myuid > king.txt||
and do ||cat king.txt||
i dont see anything
but when i do the echo id thing the other persons id id coming
why isnt my id coming??
someone resteted the machine now it is working
idk why it didnt
can someone give some tips on hogwarts? lot of ports and harry potter quotes
can someone give some tips on hogwarts? lot of ports and harry potter quotes
@oak pawn find something to run sqli against
Usually I'd say enumerate harder, but It's sunday, so free hint: Check for services, one of them is very very common and that is the easiest way to get in the machine.
theres a writeup somewhere for it
Cry, what did you do with your PFP
doja-chan
youre the one who approved it...
ahaha
...
...
false
Haha
power abuse
Oh now I remember why I approved it
if theyre actually playing with others that defend well the writeups can become useless
plus it only shows one method
yerp
Once everyone is in machine, no point of writeup then
BTW is it ok to kick others out of koth boxes. Like use kill?
Or change password
That'll help a lot
If anyone suspects that someone is cheating in a KoTH match, please email: koth@tryhackme.com.
Please include your game ID, username, username of the player you think is cheating, what they did / any evidence you have of them cheating
What is "King of the Hill"?
If I started to play KOTH, I'd be reported 24/7 because I'm so 1337
OK one more pin and I'll report power abuse
Yeah, they all say that
Yeah Skidy banned me from playing so I can't prove it π€·ββοΈ
pinning pictures of my doja-chan
Sorry I was predicting the future
Yeah Skidy banned me from playing so I can't prove it π€·ββοΈ
@short tusk
lmao
anyone wana play?
https://tryhackme.com/games/koth/join/b748af93d9eb88a85611ed5d
23 mins
If anyone is interested
https://tryhackme.com/games/koth/join/73ba13f8b47a6cb0f1974cd6
24 mins
If anyone interested
15 min anyone pls
plssss
Take a look at gtfobins.github.io
but at which step did u do it??
Take a look at EOP tricks
starts in 20mins guys
xD
it is a public game bro
okay
pls tell me some tricks
which room
bro
if i know i will help you
9 mins left
@weary axle are you still in the game ?
ok bro sorry
np
@velvet nexus
which command did u run can u tell meπ
ik this sound like idiot
i will say you in the private chat
i just used the chattr +i
Maybe someone has deleted the chattr
but its opps is chattr -i
@weary axle is it even i don't this until now
cause i did it and still perm denied
but when i did echo it worked
--------------e-- ./flag4.txt -----a-------e-- ./king.txt -------------e-- ./koth
Maybe the machine is in trouble
Is clobbering disabled?
https://en.wikipedia.org/wiki/Clobbering
In software engineering, clobbering a file or computer memory is overwriting its contents. The Jargon File defines clobbering as
To overwrite, usually unintentionally: "I walked off the end of the array and clobbered the stack." Compare mung, scribble, trash, and smash the st...
Is clobbering disabled?
https://en.wikipedia.org/wiki/Clobbering
@quiet schooner No
In software engineering, clobbering a file or computer memory is overwriting its contents. The Jargon File defines clobbering as
To overwrite, usually unintentionally: "I walked off the end of the array and clobbered the stack." Compare mung, scribble, trash, and smash the st...
--------------e-- ./flag4.txt -----a-------e-- ./king.txt -------------e-- ./koth
@fair adder where u founf this
lsattr
Carnage
If only people would give the blog a read. smh.
'-'
Reset? xD
did you mean busybox?

