#koth

1 messages Β· Page 50 of 1

fair adder
#

i will get root

#

but this time it didnt go as default machine goes

#

even gev was sus of that

#

thats why

#

and no one had the shell other than me and gev and tanya

#

thats why

turbid narwhal
#

idk i just did reset two times thats it

#

nothin else

#

i dont even know how to

fair adder
#

anyways

#

i am sorry

turbid narwhal
#

whatever

fair adder
#

😭

#

sorry for toxicity

barren stream
sudden tendon
#

starts in 3 minutes

stiff egret
#

Smart move.

sudden tendon
#

smart indeed

#

gg guys

gentle hatch
#

gg

stiff egret
#

Damnit, I joined in late

gentle hatch
#

me 2, first time getting panda as well

sudden tendon
#

haha yeah

gentle hatch
#

so many flags

sudden tendon
#

you guys were good tho

boreal flare
#

Public random starts in 20

sly turret
turbid narwhal
#

.....

#

starts in 4

turbid narwhal
#

starts in 5 minss

dreamy rune
fair adder
#

joined, I accidentally got decaf today so I'll be off game rn

fair adder
#

if you're having a hard time finding flags:
|| find / -size 33c -exec grep -lP [a-f0-9]{32} {} \; 2>/dev/null ||

terse willow
#

Assuming no one has done anything like the yotf root flag πŸ€·β€β™‚οΈ

fair adder
#

hasn't done YotF

terse willow
#

Oh, I split it up over about six lines

fair adder
#

oh

terse willow
#

And changed the order around

#

That also assumes that the flag will be a 32 character hash

#

As opposed to, uh, any other number

fair adder
#

very much, but the current machine's fortuna which, afaik, only uses 32 hex

winged charm
#

Oh, I split it up over about six lines
@terse willow this is why no one likes you

terse willow
#

Yeah, Fortune uses THM{MD5} iirc

#

Might even have just been MD5

fair adder
#

wait they're md5s?

winged charm
#

Yur

quiet schooner
#

Often

terse willow
#

That's usually how they're made

winged charm
#

or you just do like me and mash on your keyboard for a bit

terse willow
#

I tend to use sha256, technically

#
alias flag-gen="echo THM{\$(head /dev/urandom | sha256sum | base64 | head -c 32)}"
fair adder
#

ngl it would've been pretty cool had they actually meant anything

terse willow
#

Still waiting for someone to find the two I have hidden in my boxes which actually do mean something πŸ‘€

stiff egret
#

Which boxes you talking about?

#

@terse willow

#

πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€

Still waiting for someone to find the two I have hidden in my boxes
which actually do mean something πŸ‘€
πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€ πŸ‘€

sudden tendon
#

starts in 7 minutes

sudden tendon
fair adder
#

quick anyone know how to chattr w/o the chattr binary? πŸ‘€

fair adder
#

moved /root to /root2 and made my own /root, turns out that doesn't work either though the implications of having king move and not update... πŸ‘€

sudden tendon
#

epochfluffu right?

#

gg

#

starts in 24 minutes

fair adder
#

gg

safe crescent
#

gg

sudden tendon
safe crescent
#

I've finished up for the day getting late

fair adder
#

trying to figure out how to bypass chattr camping along with other stuff

#

busy rn

gentle hatch
#

get your own binary of chattr on the box and change it to a non-obvious name πŸ™‚

#

symlink the old version of chattr or rename it to keep people busy

#

ooh first time getting this box

#

glhf

sudden tendon
#

ooh first time getting this box
@gentle hatch second time in a day for me

gentle hatch
#

πŸ˜› I installed a really cool backdoor if anyone can manage to find it

#

machine is dead, reset

#

monster did you disable ssh before?

#

i had to re-enable it to get it up before, im gonna report this

#

pretty weird that web-services are down and ssh isn't working yet you're getting king lol

#

pls reset

sudden tendon
#

monster did you disable ssh before?
@gentle hatch no dude I thought you did lol

#

I thought you closed all the ports damnn

gentle hatch
#

the IP address on my browser didnt update after the reset lmfao, apologies

sudden tendon
#

lol it's okay

gentle hatch
#

good game!

sudden tendon
#

Good game guys

#

@gentle hatch Damn dude!One minute 😦

gentle hatch
#

i know! i've never seen a game that close lol, I've never beat you until now haha

sudden tendon
#

πŸ˜… 😒 It's my birthday and I wanted to win so bad but still couldn't lol

#

It hurts dude

gentle hatch
#

😦 happy birthday!

sudden tendon
#

Thanks dudeπŸ₯°

fair adder
gentle hatch
#

why do you guys keep resetting?

winged charm
#

Hey guys, we’ve been fairly lenient on the resets. please don’t abuse this feature, and turn this into a problem. Thanks!

obsidian zinc
#

why do you guys keep resetting?
@gentle hatch bc one of us wants a chance at becoming king

#

@gentle hatch others want a chance

gentle hatch
#

thats not going to help if I already know the method to get root lol

obsidian zinc
#

I know to get root and become king you've just locked us out lol! Yes I uderstand thats the point

gentle hatch
#

i just chattrd king.txt no big secret

obsidian zinc
#

I know i cant un chatterd it

nova tide
#

@Droogy#0282 bc one of us wants a chance at becoming king
@obsidian zinc That's not the purpose of KoTH. If one way you know is patched its better to find other possible ways in. instead of spamming reset.

gentle hatch
#

maybe i hid chattr πŸ™‚

nova tide
#

I know i cant un chatterd it
@obsidian zinc So its time to use man chattr??

#

Also you can always get your own chattr binary on the system.

#

With a different name, hide it in a different place?

obsidian zinc
#

Also you can always get your own chattr binary on the system.
@nova tide did not know that

#

Thanks

gentle hatch
#

same directory just different name if thats okay?

nova tide
#

Google: busy box binaries

obsidian zinc
#

@nova tide thanks. I appreciate the tip. @gentle hatch did you kick me out lol

gentle hatch
#

no sir I did kill a shell like 10 mintues before but only bc someone killed mine >.<

obsidian zinc
#

hmm @gentle hatch I cant get into the machine. Technically im a ma'am

gentle hatch
#

apologies

obsidian zinc
#

@gentle hatch all good

gentle hatch
#

i swapped ports on some services

#

i just left a cool backdoor on the regular http server if someone can find it (no foolin i promise)

obsidian zinc
#

@gentle hatch hmmm okay

dreamy rune
obsidian zinc
sudden tendon
#

Thanks for the link @obsidian zinc

obsidian zinc
#

you are welcome @sudden tendon πŸ˜„

sudden tendon
#

🀘 skidy

gaunt cradle
crisp needle
#

Is anyone doing "King of the Hill"?

winged charm
#

Just join a public game it will toss you in a match that’s getting ready to start, you can then share the link here and invite people to join

crisp needle
crisp needle
#

Is it necessary to have something installed to solve King of the Hill challenges?

winged charm
#

kali should be all that is necessary

crisp needle
#

I don't know why I could not solve any challenge

quiet schooner
#

Someone might have patched them

#

try the standalone KoTH boxes first

tepid berry
#

I don't know why I could not solve any challenge
@crisp needle the machine was patchedπŸ˜‰

crisp needle
#

So did I have to find the password of that machine?

quiet schooner
#

Each machine is different

tepid berry
#

So did I have to find the password of that machine?
@crisp needle find vulnerabilities on the machine to exploit

sly turret
#

if anyone want to play

crisp needle
#

I am in, but I don't know if I will score

sly turret
#

same πŸ˜„

#

u need some help ?

crisp needle
#

Yes, cannot access the website by IP address

sly turret
#

did you started your openvpn

crisp needle
#

Does not work

quiet schooner
#

Yes, cannot access the website by IP address
@crisp needle Nto all of them run webservers

crisp needle
#

Do I need to hack the target machine?

runic quail
#

!docs koth

pearl gladeBOT
crisp needle
#

!docs koth

#

Bex is king now

sly turret
#

anyone on the box rn ?

crisp needle
#

I am trying

sly turret
#

try to search for a password and a username

verbal comet
crisp needle
#

Can you show how you managed to become King and how you found easy flags?

sly turret
#

PM me

#

@gentle hatch we play with killing shells and patching ?

gentle hatch
#

ur free to patch but if you wanna have a gentleman's agreement to not kill shells I'll take it

#

either or tho I dont really mind play however you want πŸ™‚ i dont kill shells anyway unless someone starts with me lol

crisp needle
#

What does killing shells mean?

gentle hatch
#

kill -9 <PID of shell>

sly turret
#

ll

gentle hatch
#

kicks you off the machine

sly turret
#

kk no shell killing

crisp needle
#

And how to get an easy flag?

gentle hatch
#

if you get a foothold check user directories

#

no foothold, check webapp

#

thats basically it

#

sometimes an anon ftp server

#

ahhhhhhhhhhhhhhhhhhhhh

#

i hate offline

#

but we

sly turret
#

uff rip

#

i dont know any windows commands

verbal comet
#

Probably it will be linux machine.

#

Lol

crisp needle
#

I guess that for koth, it cannot be streamed

gentle hatch
#

it can be

#

reset? its being pretty slow

verbal comet
#

Yeah

sly turret
#

is anyone already inside

gentle hatch
#

i was briefly

#

been running the known exploit for about 20+ and its not budging lol

sly turret
#

i dont like windows

crisp needle
#

I use dual boot

gentle hatch
#

yeah i just gotta brush up on my persistence techniques for windows, its a pain tho for sure

#

at least theres only like a 1/10 chance of getting Offline

#

at least I found where some ssh passwords are hiding c:

#

GG

sly turret
#

another one ? but pls not windows

gentle hatch
#

im down send link

sly turret
verbal comet
#

No windows pls

#

This time.

gentle hatch
#

oo haven't done this one

verbal comet
#

Me too

sudden tendon
#

starts in 10

gentle hatch
#

i play one more then finally go to gym πŸ™‚

sly turret
#

how did you get root a suid file ?

#

or something with capabilitys

gentle hatch
#

yes sir then i cleared permissions on it

#

very rarely you have to utilize capabilities for KotH if ever

sly turret
#

k

gentle hatch
#

i think there was a suid binary left in there the whole game tho

#

hopefully you guys didnt get stuck in that python sandbox lol

verbal comet
#

i got the rev shell through .py

#

but the exploit was not working

gentle hatch
#

did you try running a C file?

#

i saw some segfaults

verbal comet
#

no on port 8080 there was .py

#

upload option

#

who did u got the root

gentle hatch
#

oh yeah i patched that πŸ™‚

#

only text files allowed

verbal comet
#

I am asking for root

#

i checked all suid but..

gentle hatch
#

yeah I removed SUID permissions on vim which got me in initially

verbal comet
#

lol

gentle hatch
#

I briefly made bash a suid to privesc some redundant shells but that was just like a minute

verbal comet
#

i was searching for getting root

#

if I have seen the vim getting root would be easy

#

then

sly turret
#

i dont get it when i search for suid file i get a list ... than i check with ls -la ... but when i want to use it with sudo -u root it says i have no permission

clear pawn
#

anyone wana hop in the public lobby

gentle hatch
#

you're attempting to execute a command as a lower-privileged user as root which is a big no-no

#

run whoami

#

if ur not root then you can't execute a command as root

#

and if ur not given permissions in the sudoers file then you also can't execute commands as other users

sly turret
#

so when my user is not in the sudoers file i cant use Suid binarys

sweet spade
#

How you are so fast? You became king within 3 minutes.

gentle hatch
#

i literally just did this box last game πŸ˜›

#

you can @sly turret but double check if SUID bit is set on binary

sly turret
#

/usr/bin/pkexec

#

it is set there

sweet spade
#

You just closed every thing in the box..

Now everyone is sitting. hahaha

gentle hatch
#

naw there is still a route

#

webapp will definitely take a bit of effort now tho

#

pkexec is not SUID exploitable

sly turret
#

yeah ok but its suid so i should be able to run it as root right ?

sweet spade
#

yeah there is a input field with get parameter.
But I am not able to do anything with that.

gentle hatch
#

not unless you are in sudoers file with permissions to execute files as root

#

there are some vulnerable processes running tho

#

you can still submit on webapp, intercept in burp and figure out how to make a submit request

sweet spade
#

ok let me check.

gentle hatch
#

just think about how php forms process input

sweet spade
#

you added droogy is the best in that request.. hahaha

gentle hatch
sweet spade
#

Nothing is working..

#

I tried.

gentle hatch
#

i got kicked out a few minutes ago something may have been patched :/

sweet spade
#

May be because you are king from starting of the game.. πŸ˜…

sudden tendon
#

gg guys

gentle hatch
#

gg everyone!

sudden tendon
#

you were great man @gentle hatch

gentle hatch
#

ahh tysm it was a little unfair since I just did this box before this game but always fun playing with ya πŸ™‚

sudden tendon
#

This was my first time on this box....I was a little cluelessπŸ˜… but it was fun

verbal comet
#

should I extend the time.

gentle hatch
#

eh its offline no one is gonna wanna play this anyway

verbal comet
#

try -Pn

gentle hatch
#

no i mean like the box name lol

verbal comet
#

i am just practising on AD pls I wanna try on this.I chose this box specifically.

#

After this we will play it normal way

gentle hatch
#

i dont mind playing this im just saying most people avoid it lol

verbal comet
#

machine is on reset

#

is the machine dead.

gentle hatch
#

stop resetting lmao

#

windows takes a while to come up like 2-5 minutes

verbal comet
#

ok I got that

#

I will wait

verbal comet
#

hey How do u got in?

gentle hatch
verbal comet
#

Didnt thought it would be vulnerable to blue.I was thinking of GPP aka MS14-025 but sysvol was inaccessible.

sudden tendon
#

starts in 12

crisp needle
#

Can someone stream how to play once the game is finished?

quiet schooner
#

There are writeups for 2 of the KoTH boxes, on the standalone rooms

#

I recommend getting some practice on those ones

crisp needle
#

I already know that I will end up with 0 flags

quiet schooner
#

Yeah, so practice

crisp needle
winged charm
#

yes, the box is booting that's normal, you're not a subscriber so you're getting a sample of the attackbox. If you want to use the attackbox more you need to subscribe

crisp needle
#

The issue is that I don't know how to use that AttackBox to achieve anything

quiet schooner
#

It's basically the same as Kali

#

Have you completed many rooms on THM?

crisp needle
#

M0N573R777, can you tell how to got the flags?

quiet schooner
#

There's a very important lesson here.
You need to learn the skills. Just having instructions to get the flags probably won't help much. I really really recommend completing some rooms before starting KoTH

stiff egret
#

if once I bypass by lazy-ness threshold, I'll complete the blog

crisp needle
quiet schooner
#

Yes, that's a list of all the public rooms

crisp needle
#

The issue is that I do not even know where are the relevant files and scripts when I open a new AttackMachine like this

quiet schooner
#

It's basically Kali.

#

Everything is linked with shortcuts too. You need to practice to get familiar.

#

There's no way around it, you need to put the work in and practice.

fair adder
clear pawn
#

someone sent me a message directly to my shell once I got root

#

how did you do that?

stiff egret
#

wall

#

echo

#

many methods.

teal raptor
#

echo "msg" > /dev/pts/$

clear pawn
#

ooo I know it wasn't with wall because it was "cleaner"

#

maybe it was the echo method

#

that's pretty cool

stiff egret
#
  1. that was me
  2. I used wall
  3. you should give man wall a read.
nova tide
#

@stiff egret Stop playing koth behind my back kekw

stiff egret
#

believe it or not I started this game on my phone

nova tide
#

Can you use kali browser from phone?? πŸ‘€
If yes i can play 2-3 games during my office hours

stiff egret
#

I started kalibrowser and logged in using ssh on my phone's termux

#

:smort:

clear pawn
#

@stiff egret will do, ill now annoy all the other KOTH participants with wall

#

hehe

winter mauve
stiff egret
#

It's either that the game actually doesn't exist or Site was going through some troubles few minutes ago, maybe it is because of that. Either way, You can re-join a new game. πŸ€·β€β™‚οΈ

winter mauve
#

humm ok must leave this one before creating a new one i guess

clear pawn
#

im waiting in the new public lobby rn

stiff egret
#

πŸ‘

winter mauve
#

seems ok now ^^

stiff egret
#

@terse willow Can I DM? Just one or 2 questions

#

(wrong channel btw uh uh)

terse willow
#

Aye, go for it @stiff egret

clear pawn
#

I was trying to brute force the "Hacker" machine's users for over 40min, what was I doing wrong?

#

is there another trick to it?

quiet schooner
#

@clear pawn someone might have patched it.

clear pawn
#

ah true

#

nifty

gentle hatch
#

if u were in the same KOTH game as me for that I think it was broken, I looked at a writeup after to make sure I wasn't crazy and I did everything right but got a foothold on the wrong user

#

no one got root

#

but maybe they updated the box idk

polar summit
#

anybody up for KOTH

crisp needle
#

Who is keen for a KOTH game later in the day?

verbal comet
#

Lets have a koth.

#

Whose ready?

silent pebble
#

first KOTH win!

dusty canyon
#

Nice

cerulean sparrow
#

boring

cerulean maple
#

Which machine ?

sly turret
sly turret
#

gg

hushed palm
#

yes it was in

#

you could guess it was too easy

sly turret
#

omg

#

no

hushed palm
#

sorry but yes πŸ˜„

sly turret
#

shit

#

ok next time i will get it πŸ˜„ still much to learn

hushed palm
#

wp πŸ™‚

quiet schooner
#

No spoil

gentle hatch
#

i just gotta learn how to avoid getting nyancatted, not sure where to start with that

#

luckily i had persistence but still

sly turret
#

@quiet schooner deleted the messages

crisp needle
crisp needle
#

The IP address of the target is not given?

gentle hatch
#

GG!

sudden tendon
#

starts in 12

gentle hatch
#

gg πŸ˜„

sudden tendon
#

lol gg dude

nova tide
#

boring
@cerulean sparrow want me to join?

sly turret
#

:D:D dude

#

what is this

#

... killing shells sucks

#

ok im out

winged charm
#

I swear no one playing koth knows how to set up persistence

#

wasnt there just a room on persistence geez

stiff egret
sudden tendon
#

starts in 22

clear pawn
#

how do you guys brute force hacker so fast

hushed palm
#

[STATUS] 76.00 tries/min

#

lol

#

probably i cant finish in 60 min

nova tide
#

custom wordlists or using -t 64

clear pawn
#

hmmm custom wordlists ey?

#

im using rockyou and it's gotten me no where hehe what wordlist are you using?

nova tide
#

the one i made for hackers.

clear pawn
#

alright

nova tide
#

rockyou would be enough though

#

but would take a little bit of more time

#

just use -t 64

crisp needle
crisp needle
#

Gg

grand hamlet
#

how much knowledge need to play koth ? is it for intermediate players ?

grand hamlet
#

..

tepid hornet
#

Try Playing a game

grand hamlet
#

yep..

hushed palm
#

9 min

grand hamlet
hushed palm
#

@hushed palm why so pro man .. i got one flag only ooof
@grand hamlet keep trying there are multiple vulnerabilities

grand hamlet
#

@grand hamlet keep trying there are multiple vulnerabilities
@hushed palm yep i saw ..

#

300 points htf...

#

I mma out πŸ˜‚

grand hamlet
#

@hushed palm you do bughunting?

hushed palm
#

no i dont

grand hamlet
#

okk

silk needle
delicate walrus
#

r

silk needle
clear pawn
#

anyone wana play?

patent forge
crisp needle
#

Anyone keen for a game of koth?

sudden tendon
#

Yeah!I'm bored

crisp needle
#

Make an invite

sudden tendon
#

starts in 24

jolly hornet
#

EXPIRED

#

start in 3 mins boys

#

machine offline

#

<windows machine>

#

mm

#

pl

harsh obsidian
#

how's everything going?

clear pawn
#

im hanging out in public lobby trying to get a game going

harsh obsidian
#

If you post an invite link, I'll join. Probably won't play as I'm working on another room, but I'll join so you don't get the game cancelled.

clear pawn
#

wow thanks, link above

harsh obsidian
#

that's just the spectator link, I need the invite link

clear pawn
#

im not sure what you mean

#

if you click it you will be in the lobby

harsh obsidian
#

In the lobby, on the top right, click options. Copy and paste the Invitation Link

clear pawn
#

o sweet

#

both links do the same thing though

#

don't they?

stiff egret
#

No, spectator link only allows user to see scoreboard, whereas to actually play in the game, you need invite link.

jolly hornet
jolly hornet
#

start in 5 mins

#

mmm

harsh obsidian
#

Make sure you scan for, and look at, all ports. Especially "non-standard" ones........

vocal shell
#

how could symlinks be used in red v blue environment (ex : koth)

hushed palm
#

22 mins

quiet schooner
#

how could symlinks be used in red v blue environment (ex : koth)
@vocal shell #infosec-general

fair adder
#

Hey, someone up for koth? Will be an easy one, its my firs ttime πŸ˜„

tribal wren
#

Hey, someone up for koth? Will be an easy one, its my firs ttime πŸ˜„
@fair adder Oh man one hour too late.. πŸ˜›

fair adder
#

Yeah, unfortunately

tribal wren
#

Got time for another round?

#

I'm in a public room right now πŸ™‚ Starts in 25 minutes

fair adder
#

Let's try...

#

Never did this before

tribal wren
#

It's my second time ever

fair adder
#

Think it could be fun

tribal wren
#

Yeah why? πŸ™‚

fair adder
#

The webpage is killing me πŸ˜„

tribal wren
#

Haha yeah when I opened it the first time I was like: Oh my...

fair adder
#

yeah... Is there an option to stop gifs repeating?

tribal wren
#

There must be

fair adder
#

unfortunately i cant voice chat actually 😦 Would be fun

tribal wren
#

Yeah no problem. Maybe another time

#

Is it just me or did the machine just die?

fair adder
#

its alive for me

#

does it work again?

tribal wren
#

yep looking good

fair adder
#

got something, but dont know how to use it 😦

#

Wah, you got the first flag already?

tribal wren
#

Got two yeah πŸ˜„

fair adder
#

😦

#

im stuck...

tribal wren
#

Where exactly?

fair adder
#

got a ||base64 string which should be a pkzip|| file. but i dont know how to get this file

stiff egret
#

Please avoid spoilers.
Use ||spoiler|| if necessary

fair adder
#

Hope thats better

tribal wren
#

You can DM me if you want. Then we don't have to spam the chat here πŸ˜‰

mossy token
#

anyone up for koth ?

fair adder
#

starts in 17m

fair adder
#

Who is modifying the flag in ||/home/ashu|| and deleting the ||server1.py|| in ||/home/skidy||? sadcooctus

sly turret
#

... yeah rude 😦

#

i found something in server1 but i cleared my terminal and cant remember

fair adder
#

Maybe its part of harden the vm -.-

sly turret
#

yeah mayve

#

ftp is closed too i think

terse willow
#

Modifying flags and deleting files are both against the rules

fair adder
#

That happend here 😦

terse willow
fair adder
#

Game ID is the number in the URL, right?

fair adder
#

@potent oyster do you know who deleted the file?

wraith geyser
#

anyone up for a match?

#

starts in 8 minutes

wraith geyser
#

who fork bombed

fair adder
#

idk

winged charm
#

whaaaaat

fair adder
#

lmao what a dick

#

fork bombing a koth

gloomy estuary
#

@wraith geyser did you delete the flags of fortune?

hazy zodiac
fair adder
#

@wraith geyser did you delete the flags of fortune?
@gloomy estuary i have the same question

wraith geyser
#

i didnt delete the flags

#

they were all named flag not flag.txt

#

thats for the 1st 3

#

idk about the other 4

#

@fair adder @gloomy estuary

gloomy estuary
#

I don't want to know if they were renamed, just if it was you or not

#

whatever, just want to know who deleted it. Missing flags and some users in / home

wraith geyser
#

no like

#

that was the original name

#

I saw 4 users in home last time I checked

gloomy estuary
#

all right, bro. I already played this room, and I remember having 2 more users on / home. Someone deleted

marsh perch
#

[root@tyler narrator]# cd /root
[root@tyler ~]# id
uid=0(root) gid=0(root) groups=0(root)
[root@tyler ~]# ls -la
total 7432
dr-xr-x---. 4 root root 221 Mar 27 2020 .
dr-xr-xr-x. 18 root root 272 Mar 25 2020 ..
lrwxrwxrwx 1 root root 9 Mar 19 2020 .bash_history -> /dev/null
-rw-r--r--. 1 root root 18 Dec 28 2013 .bash_logout
-rw-r--r--. 1 root root 176 Dec 28 2013 .bash_profile
-rw-r--r--. 1 root root 176 Dec 28 2013 .bashrc
drwx------ 4 root root 33 Mar 26 2020 .cache
-rw-r--r--. 1 root root 100 Dec 28 2013 .cshrc
drwxr----- 3 root root 19 Mar 25 2020 .pki
-rw-r--r--. 1 root root 129 Dec 28 2013 .tcshrc
-rw------- 1 root root 0 Mar 27 2020 .viminfo
-rw-------. 1 root root 1418 Mar 19 2020 anaconda-ks.cfg
-rw------- 1 root root 6 Oct 28 03:05 king.txt
-rwx------ 1 root root 7576048 Mar 26 2020 koth
-rw------- 1 root root 33 Mar 26 2020 root.txt
[root@tyler ~]# echo "itspossible9" >> king.txt
bash: king.txt: Permission denied

#

Why I can't write to king.txt file

nova tide
#

try reading about chattr binary

#

lsattr king.txt

marsh perch
#

cat /usr/bin/chattr
cat: /usr/bin/chattr: No such file or directory

#

Where is chattr binary?

#

locate chattr

mystic talon
#

someone prob deleted it lul

nova tide
#

its not always on the system. people upload it from their machine and rename it

mystic talon
#

ye

marsh perch
#

Oh I see

mystic talon
#

you can upload the one from your machine and run it

marsh perch
#

What's the user of that binary though?

nova tide
#

try checking out busybox binaries

mystic talon
#

you have to be root to use chattr

marsh perch
#

I was root

mystic talon
#

well what do you mean with "What's the user of that binary"?

marsh perch
#

My bad

#

*use

mystic talon
#

oh

#

you can set some attributes for files

cerulean maple
#

Google chattr

mystic talon
#

in this case the "immutable" attribute is being set

marsh perch
#

Oh I see

nova tide
#

or just man chattr on your local machine.

cerulean maple
#

Hmmm

marsh perch
#

Thank you all

cerulean maple
#

Now become king ❀️

marsh perch
#

lol I ran out of time

cerulean maple
#

oh xD

marsh perch
#

Rank User Country Flags King Time Points
1

pr1sm

6    54m    680

2

itspossible9

5    0m    115

3

mechboy

1    0m    15
cerulean maple
#

Anyways you learned something

marsh perch
#

Yes

cerulean maple
#

that's all that matters

fair adder
#

how does KOTH even work in terms of hacking!

#

?*

fair adder
crisp needle
weary axle
#

are the koth machines down?

#

ote: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.03 seconds

#

its been 5 minutes

#

offline

tribal wren
#

Happened to me yesterday. Had to restart the VM...

fair adder
#

Is it allowed in koth to remove entries from /etc/sudoers and alter entries in /etc/passwd? Asking for a friend πŸ˜„

terse willow
#

As long as the functionality remains the same @fair adder

#

For example, if the permission in sudoers is for vim, you could change it to sudoedit over a specific file

#

Or set the target of a sudo command to something totally useless and very specific

fair adder
#

Changing the login from /bin/bash to /bin/rbash seems not really to be the same, right?

terse willow
#

I mean, technically throwing someone into a restricted shell isn't really changing the functionality. In the real world that's a protective measure πŸ€·β€β™‚οΈ

#

It's also not impossible to escape something like rbash

fair adder
#

Okay. So I'm my friend is safe there.. But what about deleting lines from /etc/sudoers?

terse willow
#

If the user is meant to be able to change stuff with sudoers then that functionality should remain -- unless it's a very stupid security hole

fair adder
#

user could execute find with root perms... I think this is a security hole.

terse willow
#

I would say try not to delete them, but if the line is something like: user ALL=(ALL:ALL) systemctl you could change it so they could only change something specific

#

Em, yeah, Ok, with something like find, given the exec, I think you'd probably be justified in removing that one

#

But ideally replace it with something equivalent, without the hole

fair adder
#

okay, Im trying to do that.

#

Thanks for the guidance

grand ember
#

It's also not impossible to escape something like rbash
@terse willow unless you screw something up when setting up the env for it πŸ‘€

terse willow
#

Heh

nova tide
#

Oh koth-staff can even remove lead mod's messages kekw

short tusk
#

You should be able to remove anyone’s, even admins

winged charm
#

Hold up fr

#

that’s mad

#

but only in here so big sad

#

Oh hold we can pin as well very cool Kanye

nova tide
#

@mint cargo come here now,i will show you my powers kekw

wraith geyser
crisp needle
nova tide
#

@wraith geyser that's a spectator link

clear pawn
#

anyone wana play?

#

10min

shy pasture
#

To Chmod93, of the koth : Good game ! You scared me, at the end ! πŸ™‚

mint cargo
#

@mint cargo come here now,i will show you my powers kekw
@nova tide NO

#

u bully me naughty 😦

fair adder
#

heyya

winged charm
#

Hey

nova tide
#

Heyy

cerulean maple
#

Heyyy

fair adder
#

yyeeh

nova tide
runic quail
#

Aye, thank you @nova tide and @stiff egret . blobheart

stiff egret
#

πŸ˜„

gentle hatch
#

So when are you guys going to make a blog post on your C2 infra and rootkits πŸ‘€

stiff egret
#

:never:

nova tide
#

^

gentle hatch
#

haha, great post tho btw, I saw a variation of that SSH trick in the operator's handbook except it also bypasses .bashrc and also hides from w and who

stiff egret
#

(we did leak about clobber)

gentle hatch
#

I just need to keep playing BG with ippsec, dude is always dropping nuggets like that

stiff egret
#

(only 20 kekw )

gentle hatch
#

I have a quick question about nyancat'ing someone, are you binding the service to a port or having nyancat run whenever a user runs what they think is a legitimate service?

#

I've tried playing around with it on a VM but couldn't really get it

nova tide
#

Don't stop any service.. for nyancat you can just run it on their tty

gentle hatch
#

ooo okay I was overthinking it I think ik what to do now

#

ty very much

nova tide
#

if you want to take it to next step try making them play tetris

spare crest
#

So when are you guys going to make a blog post on your C2 infra and rootkits πŸ‘€

Just look at the opensource Reptile (Kernel Module) or Vlany (ld-preload), are good for starting out.

dusty canyon
#

Oh man its ippsec

#

2020 is strange

weary axle
#

why is bryteforcing taking so long

#

for hackers machine

#

30 min still no luck

runic quail
#

Nice blog post @nova tide and @stiff egret, also nicely explained. I guess I can win some matches now. 😁

winged charm
#

@weary axle shouldn’t take more than 5 if it does youre doing something wrong

weary axle
#

it takes real long

winged charm
#

You sure someone hasn’t changed the password

#

the point of the game is to defend and attack

stiff egret
#

@weary axle Don't post spoilers without hiding them, also, the machines have multiple entry points, you can always let hydra do its thing while you try to search for more entrypoints,

weary axle
#

was that a spoiler??

#

and how to make text spoler?

#

You sure someone hasn’t changed the password
@winged charm me and my other account are playing.

#

no one else

stiff egret
#

||<spoiler>||

weary axle
#

||like this||

#

h

nova tide
#

IIspoilerII

velvet nexus
#

if anyone whats to join u can

#

only 1 min left

#

sorry guys started

harsh obsidian
sly turret
#

@gentle hatch did u killed ssh? or spawed the port ?

polar summit
sly turret
sly turret
#

@fair adder nyancat is not patching πŸ˜„

fair adder
#

@fair adder nyancat is not patching πŸ˜„
@sly turret xD

#

Are you sure?

sly turret
#

yes

#

πŸ˜„

fair adder
#

Did you have shell?

sly turret
#

not atm

fair adder
#

Okay

sly turret
#

zou changed the ssh port right ?

fair adder
#

zou changed the ssh port right ?
@sly turret Maybe xD

nova tide
sly turret
#

changed or killed πŸ€”

fair adder
#

changed or killed πŸ€”
@sly turret Nmap can answer your question

sly turret
#

you are cheaky πŸ˜„

#

i found it

fair adder
#

What "cheaky" means? ;-;

sly turret
#

u crashed the Box ?

fair adder
#

u crashed the Box ?
@sly turret Sorry, i was testing the iptables

sly turret
#

k

fair adder
#

Try again

terse willow
#

Use of iptables on the KoTH boxes is banned, iirc

#

No messing with the firewall

fair adder
#

Use of iptables on the KoTH boxes is banned, iirc
@terse willow lol

#

I didn't know, sorry @sly turret

sly turret
#

np

#

its private game so no one cares πŸ˜„

terse willow
#

If it's a private game, go nuts. Use your own rules 😁

quiet schooner
#

*within reason

#

Attacking other user's machines is still off limits, because that's illegal.

fair adder
#

Attacking other user's machines is still off limits, because that's illegal.
@quiet schooner The fun is play nyancat on other player's machines

quiet schooner
#

That's different

sly turret
#

@fair adder you need that rainbow parrot thing its 100x better than nyancat

fair adder
#

@fair adder you need that rainbow parrot thing its 100x better than nyancat
@sly turret xD i will try

#

@sly turret Did you see nyancat on your terminal?

sly turret
#

yeah

#

@fair adder can you teach me how you changed the port and the name

fair adder
#

/etc/ssh/sshd_config

#

@fair adder can you teach me how you changed the port and the name
@sly turret The name of what?

sly turret
#

before you changed it was named ssh on port 22 you changed the port and the name

fair adder
#

I just changed the port, maybe nmap identified it as another service

sly turret
#

aa ok

sly turret
sudden tendon
#

starts in 23 minutes

velvet nexus
#

starts in 18 mintues

weary axle
#

anybody for koth?

#

||chattr +i /root/king.txt|| whats the opposite for this command?

#

nvm found it

#

for anyone else

#

it is

#

||chattr -i /root/king.txt||

#

anybody playing koth after 5 10 min ???

cerulean maple
#

KoTH anyone ?

velvet nexus
#

starts in 20 mins

weary axle
#

join pls

patent forge
#

@hot bloom are u playing the koth?

hot bloom
#

Yep

patent forge
#

glhf πŸ™‚

hot bloom
#

Haha! Let's do it!

weary axle
#

anyone playing???

#

send a link plsss

#

lets play a private game with many people

hot bloom
weary axle
#

which machine is it??

#

@hot bloom

velvet nexus
#

hello guys

hot bloom
#

@patent forge did you give up?

compact hare
#

Can someone help with the hogwards KOTH?

#

I am stuck at a certain point

#

It would realy help a lot

gentle hatch
#

if you're having trouble just create a private game for it and lab it out

#

its not a very difficult box, just unique

compact hare
#

Thats what i did with a friend of mine

#

We are stuck on the login page

#

And we have 24 minutes left

#

So if you can hint me anything please do

gentle hatch
#

theres a much easier way that doesn't involve any web-hacking

#

make sure you enumerate all ports properly

compact hare
#

I did

#

What am i missing ?

gentle hatch
#

did you interact with every single port you found from your scan?

compact hare
#

Yeah

#

Can i dm you?

gentle hatch
#

the only thing I can say is that it's a very basic service

#

there's no need you'll get it πŸ™‚

compact hare
#

||vsftpd||

#

?

hot bloom
#

Someone already playing?

stiff egret
#

Anyone up for KoTH, ping me too! It's weekend! KoTH night!

cerulean maple
#

@stiff egret Do you want to play too ?

stiff egret
#

@latent shell it's like your wish come true

#

lol

#

@stiff egret Do you want to play too ?
@cerulean maple If you don't have any problem with that

cerulean maple
#

No problem at all , but for a fact I know that I'm going to lose xD

#

2 min remaining

stiff egret
#

@latent shell

latent shell
#

yaas

stiff egret
#

hop in

latent shell
#

joined

stiff egret
#

@nova tide I don't think you'll play? (don't it's for fun and we both fight)

latent shell
cerulean maple
#

Oh umair form secarmy how are you

latent shell
#

ayy i am good hbu

cerulean maple
#

Fine !

stiff egret
#

lol

#

I am booting my vm

#

@noble wren

noble wren
#

i can't talk on the voice sorry

stiff egret
#

hop in the game just started

cerulean maple
#

Yes game just started

noble wren
cerulean maple
#

yes

nova tide
#

I'm playing siege for now

cerulean maple
#

Oh

stiff egret
#

NOICE

latent shell
#

nice port list you got there 🀣

stiff egret
#

lol what

#

I swear I rooted it the intended way

#

that's why it took so long

nova tide
#

hogwarts?

stiff egret
#

yeah

cerulean maple
#

yes

nova tide
#

you are not allowed to play it

stiff egret
#

Ik, but umair insisted

nova tide
#

good luck to him then

latent shell
#

no i didn't , he is abusing us with his machine

stiff egret
#

lies

latent shell
#

FFS

noble wren
#

hogwarts i have already played that machine before

stiff egret
#

lies on the top of lies on the top of lies

latent shell
#

I USED CTRL + Z INSTEAD OF USING Z

#

oh god

stiff egret
#

LOL

#

honest to god, that's all I have done so far:

#
echo holmes >/root/king.txt
cerulean maple
#

xD

latent shell
#

lmao nah

#

lmfao

stiff egret
#

LOL

noble wren
#

will you guys play another box after this

stiff egret
#

sure

#

Private, random, 5 minutes

noble wren
#

that's better

stiff egret
#

even the shell says so

noble wren
#

lol

stiff egret
#

@nova tide

nova tide
noble wren
#

damn 1 vote to reset the machine

stiff egret
#

um, why do you want to reset?

#

I am in the machine, and I don't see anything wrong

noble wren
#

becuase you patched everything

stiff egret
#

what, no

nova tide
#

becuase you patched everything
@noble wren uhmm do you even know the rules??

stiff egret
#

I did this while sharing screen, I didn't patch one thing

nova tide
stiff egret
#

Yeah, tho I haven't patched, but patching is not against the rules, it is actually the purpose of this

noble wren
#

@nova tide lol then what is the purpose of playing it

nova tide
#

There's nothing patched.. you are not Trying hard enough

#

check the blog post/pin message if you want to know anything about KoTH

noble wren
#

bruh you aren't even playing

nova tide
#

But i know the rules and you should too

noble wren
stiff egret
#

um, What do you mean?

noble wren
#

nuh. it's for @nova tide

#

gg

stiff egret
#

GG
but just so you know,
Even tho I didn't patch anything on machine, as Naughty said, patching is one of the main purposes of this game, I didn't patch it so others can get a chance.

noble wren
#

yeah i was not doing it on the right way

#

there is noting patched

#

good night

stiff egret
#

GN

nova tide
#

nuh. it's for @nova tide
@noble wren you even have any idea what you are even saying? facepalm

#

GN

wraith geyser
#

22 min

opal crown
#

ive never done a KOTH before, i might be an easy opponent

#

nice and windows decided to reject my activation key right as soon as i joined

opal crown
#

i definitely need to hone my skills before doing one of these in the future

#

im not giving up but i definitely wont be winning this lul

wraith geyser
#

activiation key?

#

are you using a windows vm

wraith geyser
marsh perch
marsh perch
#

Hi @fair adder

fair adder
#

hi

marsh perch
#

Any hint for privesc?

fair adder
#

hmmm

#

Sometimes you can hijack somethings

marsh perch
#

tmux?

fair adder
#

idk xD

marsh perch
#

lol

#

I tried tmux earlier but it wasn't working

#

It says no session

fair adder
#

You'll have to find out

#

I tried tmiux earlier but it wasn't working
@marsh perch There are others ways

weary axle
#

pls join

marsh perch
#

I am not able to find anything on this box

#

@fair adder

#

I will appreciate if you can help little bit

fair adder
#

Do you have shell?

marsh perch
#

Yes

#

I am monitoring processes

#

for cronjobs

fair adder
#

Hmmmm....

#

I have patched the tmux EOP

#

So maybe you should take a look at the versions

marsh perch
#

I found some CVEs

#

but exploit is not working

fair adder
#

lol

dapper fern
#

Hi

#

Some help for Hogwarts machine

#

Any one help me.. I wil dm

winged charm
#

have you attempted to scour for a writeup

weary axle
#

hey guys

#

when i do ||echo myuid > king.txt||

#

and do ||cat king.txt||

#

i dont see anything

#

but when i do the echo id thing the other persons id id coming

#

why isnt my id coming??

#

someone resteted the machine now it is working

#

idk why it didnt

velvet nexus
oak pawn
#

can someone give some tips on hogwarts? lot of ports and harry potter quotes

bright panther
#

can someone give some tips on hogwarts? lot of ports and harry potter quotes
@oak pawn find something to run sqli against

stiff egret
#

Usually I'd say enumerate harder, but It's sunday, so free hint: Check for services, one of them is very very common and that is the easiest way to get in the machine.

winged charm
#

theres a writeup somewhere for it

stiff egret
#

Cry, what did you do with your PFP

winged charm
#

doja-chan

#

youre the one who approved it...

#

ahaha

#

...

stiff egret
#

...

winged charm
#

false

short tusk
#

Haha

stiff egret
#

power abuse

winged charm
#

I mean

#

the thing about koth writeups

stiff egret
#

Oh now I remember why I approved it

winged charm
#

if theyre actually playing with others that defend well the writeups can become useless

stiff egret
#

plus it only shows one method

winged charm
#

yerp

stiff egret
#

Once everyone is in machine, no point of writeup then

bright panther
#

BTW is it ok to kick others out of koth boxes. Like use kill?

stiff egret
#

Check pins

#

Give the blog a read

bright panther
#

Or change password

stiff egret
#

That'll help a lot

winged charm
winged charm
#

If anyone suspects that someone is cheating in a KoTH match, please email: koth@tryhackme.com.
Please include your game ID, username, username of the player you think is cheating, what they did / any evidence you have of them cheating

short tusk
#

If I started to play KOTH, I'd be reported 24/7 because I'm so 1337

stiff egret
#

OK one more pin and I'll report power abuse

winged charm
#

Im just updating the pins

#

for actual KoTH things

stiff egret
#

Yeah, they all say that

short tusk
#

Yeah Skidy banned me from playing so I can't prove it πŸ€·β€β™‚οΈ

winged charm
#

pinning pictures of my doja-chan

stiff egret
#

Oh Jabba that was for cry

#

but play with me and prove

short tusk
#

Sorry I was predicting the future

#

Yeah Skidy banned me from playing so I can't prove it πŸ€·β€β™‚οΈ
@short tusk

stiff egret
#

DAMN

short tusk
#

Haha

stiff egret
#

for good time

short tusk
#

lmao

clear pawn
#

anyone wana play?

crisp needle
crisp needle
weary axle
#

15 min anyone pls

#

plssss

fair adder
weary axle
#

@fair adder how did u privelege pls tell me

#

i wanna learn

fair adder
weary axle
#

but at which step did u do it??

fair adder
#

Take a look at EOP tricks

velvet nexus
#

starts in 20mins guys

weary axle
#

bro waitttt

#

im in another challenge

fair adder
#

xD

weary axle
#

will u start after like 30 min

#

pri1sm is not working in curretn game

velvet nexus
#

it is a public game bro

weary axle
#

i got a flag @fair adder

#

still stuck

fair adder
#

Nice

#

I will join now

velvet nexus
#

okay

weary axle
#

pls tell me some tricks

velvet nexus
#

which room

#

bro

#

if i know i will help you

#

9 mins left

#

@weary axle are you still in the game ?

weary axle
velvet nexus
#

ok bro sorry

weary axle
#

np

#

@velvet nexus

#

which command did u run can u tell meπŸ˜†

#

ik this sound like idiot

velvet nexus
#

i will say you in the private chat

weary axle
#

k

#

when ??

#

cause u did nice trick but now im stuck

velvet nexus
#

i just used the chattr +i

weary axle
#

but its opps is chattr -i

#

its not working

#

@velvet nexus

fair adder
#

Maybe someone has deleted the chattr

velvet nexus
#

but its opps is chattr -i
@weary axle is it even i don't this until now

weary axle
#

cause i did it and still perm denied

velvet nexus
#

but when i did echo it worked

fair adder
#

--------------e-- ./flag4.txt -----a-------e-- ./king.txt -------------e-- ./koth

#

Maybe the machine is in trouble

quiet schooner
#

In software engineering, clobbering a file or computer memory is overwriting its contents. The Jargon File defines clobbering as

To overwrite, usually unintentionally: "I walked off the end of the array and clobbered the stack." Compare mung, scribble, trash, and smash the st...

fair adder
#

Is clobbering disabled?
https://en.wikipedia.org/wiki/Clobbering
@quiet schooner No

In software engineering, clobbering a file or computer memory is overwriting its contents. The Jargon File defines clobbering as

To overwrite, usually unintentionally: "I walked off the end of the array and clobbered the stack." Compare mung, scribble, trash, and smash the st...

weary axle
#

--------------e-- ./flag4.txt -----a-------e-- ./king.txt -------------e-- ./koth
@fair adder where u founf this

fair adder
#

lsattr

weary axle
#

which machin

#

ur diff machine

fair adder
#

Carnage

stiff egret
#

If only people would give the blog a read. smh.

fair adder
#

'-'

weary axle
#

it is still perm denied

#

prism any insights?

fair adder
#

Reset? xD

weary axle
#

-__-

#

my head is confused

fair adder
#

So, i can't do anything

#

GG

quiet schooner
#

Grab a static one!

#

Blog post!

fair adder
#

did you mean busybox?