#koth

1 messages · Page 51 of 1

weary axle
#

-bash: king.txt: cannot overwrite existing file

#

now i get this

fair adder
#

xD

weary axle
#

tell me what to do

#

@fair adder

#

u the gr8

#

ig

quiet schooner
#

did you mean busybox?
@fair adder I mean a static binary

#

However you choose to source one

weary axle
#

i quit

#

@velvet nexus

fair adder
#

The machine did not have the chattr, for some reason

quiet schooner
#

It's not always present

fair adder
#

i know

quiet schooner
#

And it can be removed

fair adder
#

Sure

quiet schooner
#

That's something a lot of people do so it's not that surprising

weary axle
#

@quiet schooner @fair adder can u help?

quiet schooner
#

??

weary axle
#

what shd i run?

#

cannot create king.txt: Permission denied

#

chattr -i not workin

fair adder
#

Upload your own chattr binarie

weary axle
#

i run still same problem

#

how?

quiet schooner
#

how?
@weary axle Blog post!

fair adder
#

SCP, Netcat...

weary axle
#

didnt use any

fair adder
#

@weary axle Blog post!
@quiet schooner Maybe you could just stop saying that and send the link

weary axle
#

for making

#

actually

quiet schooner
#

I'm a firm believer in finding the resources yourself

weary axle
#

-___-

quiet schooner
#

part of research

fair adder
#

I'm a firm believer in finding the resources yourself
@quiet schooner So, Why do you keep saying "blog post!"

weary axle
#

someone reset machiene

quiet schooner
#

because it's all covered in the blog post that you should read

fair adder
#

'-'

weary axle
#

whichhhhh

fair adder
weary axle
#

this

quiet schooner
#

See, research

weary axle
#

i read

fair adder
#

See, research
@quiet schooner I already read that

#

I'm trying to help someone

quiet schooner
#

Yeah, it covers static binaries

#

That's the whole point we're making here

weary axle
#

now i m king for next 20 min

#

but udbhav was 30 mu

#

shit

#

@velvet nexus

#

now which command

velvet nexus
#

i am still the king bro

weary axle
#

i was for 5 min

#

seriuosly which commands are u using for blocking me?

velvet nexus
#

now which command
@weary axle chattr -i king.txt && echo Udbhav > king.txt

weary axle
#

i did it indivi but not happeneing

velvet nexus
#

i am used the same command bro

weary axle
#

im real begginer

#

our 3rd participant

#

got root once

#

king

#

but i put my uname

velvet nexus
#

bro now i cant get the king

weary axle
#

no im spamming that commmand like mad

#

so thatswhy

stiff egret
#

You can make loops you know.

weary axle
#

how?

stiff egret
#

man while

#

In your terminal

weary axle
#

then

stiff egret
#

Then read what's on screen, you'll know.

weary axle
#

no manula entry for while

stiff egret
#

👀

#

You can google, 'Loops in bash'

weary axle
#

shit i lost a easy game

velvet nexus
#

thanks for the help @stiff egret

weary axle
#

bro did u loop??

velvet nexus
#

yes

weary axle
#

ik

#

iki

#

i knew it

#

cause i ws spammin and still u were root

#

king

#

gg

#

bye

velvet nexus
#

i used when homes told me

weary axle
#

now have to study

velvet nexus
#

ok bro

stiff egret
#

:))

summer star
#

What level do you have to be to play if you’re using a fresh account

quiet schooner
#

0

#

You need to set your experience level in your profiel

crisp needle
#

Anyone interested for a game of KOTH?

winged charm
#

What’s a KoTH mate

#

Apparently I’m a KoTH Staff or something

#

Don’t know what that means

stiff egret
#

Cry is losing it.

#

It's official

nova tide
#

who unmuted cry??

stiff egret
#

Question of the month

opal pond
#

Can you execute a script in smbclient ???

#

Talking about the Offline machine

opal pond
#

Any newbies wanna join ? Im not good

#

Starts in 15 mins

fair adder
#

@harsh obsidian Raaaaaaage 😄

fair adder
#

How tf do you flood my terminal like that? 😦

harsh obsidian
#

Lol, it took a lot of work to figure out, I'm not gonna lie

fair adder
#

that sucks.. really

harsh obsidian
#

Are you getting the quotes now?

fair adder
#

now i got slowly imcoming strings

#

yeah 😄

#

not what i wanted 😄

harsh obsidian
#

Not gonna lie, that's my favorite one.

fair adder
#

i hate it atm 😉

harsh obsidian
#

Lemme see if it'll let me stop them; sometimes it will, sometimes it won't

fair adder
#

how did you do this?

harsh obsidian
#

a whole lot of work with the echo command

fair adder
#

thats a really good tactic to stop everybody else

harsh obsidian
#

did that work to stop the movie quotes?

fair adder
#

yes. they stopped

harsh obsidian
#

sweet

fair adder
#

hm 😄

harsh obsidian
#

shouldn't be any random flood either

fair adder
#

terminal is useless now

#

nothing works

#

anyway. you won this one.

#

and i cant figure out how this backdoor works

harsh obsidian
#

Talking port ||9001|| ?

fair adder
#

yeah

#

got the pw, but cant make it work

harsh obsidian
#

So I've looked at the code and got ||the password|| but I've never got it to work. From what others have told me, it's a troll from the room creator

fair adder
#

oh man... what a bummer

harsh obsidian
#

I'm off the box altogether if you still need to play around and learn / search

fair adder
#

but according to the code it shoult work

opal pond
#

Which room are you guys doing

fair adder
#

production

opal pond
#

Ah ok gl

fair adder
#

theres nothing more to do... n0beard rocked it

#

but thanks anyway

harsh obsidian
#

but according to the code it shoult work
@fair adder Agreed. It confuses the shit out of me. I have a thought, but I'm too lazy to track it down and see if it works...

#

theres nothing more to do... n0beard rocked it
@fair adder Thanks!

fair adder
#

At first I thought i could win it

harsh obsidian
#

At first I thought i could win it
@fair adder You had it for a bit. And I wasn't sure that I'd be able to get on the box and get King....

fair adder
#

I need more practice in blue teaming 🙂

#

hardening a box is not my strength

harsh obsidian
#

My method (at least for KotH), is take how I got on the box and remove that avenue. And just work that one avenue at a time.

fair adder
#

Yeah, did that in the beginning

#

but after the first or second reset i wasnt able to do so

#

you were faster i think

harsh obsidian
#

I try and chain commands together as much as possible to max the speed

#

For example, did you know that the ssh command in Linux has a -t option?

fair adder
#

thats a good hint

#

erm.. no. let me look it up

harsh obsidian
#

You definitely should. It's helped me A LOT

fair adder
#

ah okay, but does it help in this machine? there is tty or not?

#

can i dm you?

harsh obsidian
#

Sure

#

I'm looking up the man page now to make sure I'm giving the right advice

opal pond
harsh obsidian
#

@opal pond i'm in the room to make sure you can play, but i don't know if i'm gonna be able to play or not (meeting)

opal pond
#

@opal pond i'm in the room to make sure you can play, but i don't know if i'm gonna be able to play or not (meeting)
@harsh obsidian thx

opal pond
#

@opal pond i'm in the room to make sure you can play, but i don't know if i'm gonna be able to play or not (meeting)
@harsh obsidian gg :c which path did you take ?

harsh obsidian
#

i started with netcat

#

i connected and grabbed king only because no one was king, but i didn't do anything that would've kept me king or patched access.

opal pond
#

I didn’t know where both of the upload pages put the payload Tried that 2018 and 2019 cve on librenms with anonymous login no luck. Found one flag in smb and a alert.txt that had I believe a password in it but I didn’t know what the password was for

crisp needle
#

How did you get 1 flag?

sly turret
#

anyone want to play

opal pond
#

Yes im not good tho it’ll be my third game

harsh obsidian
#

How did you get 1 flag?
@crisp needle I have all of the flags for that box in my notes, i only bothered to submit the one

sly turret
opal pond
#

@crisp needle I have all of the flags for that box in my notes, i only bothered to submit the one
@harsh obsidian whats up with that alert txt ?? The “intresting” password ?

sly turret
#

no re use of password or flags pls .. play fair

harsh obsidian
#

@harsh obsidian whats up with that alert txt ?? The “intresting” password ?
@opal pond I don't remember anything about alert.txt....

opal pond
#

no reuse of password or flags pls .. plaz fair
@sly turret this is literally my 3rd game i dunnu anything about the boxes

#

@opal pond I don't remember anything about alert.txt....
@harsh obsidian ok

sly turret
#

oh okay 😄

opal pond
#

Go easy on me 🙂

harsh obsidian
#

@opal pond always, always, always, scan all ports when doing nmap....to help speed it up (beyond using -T5), check out the video on youtube that shannon morse (aka snubbs) did with dan tentler (aka viss) on the hak5 channel....that helped me A LOT with scanning speed

sly turret
#

can i patch anything or should i help u a bit

#

@opal pond found a way in ?

opal pond
#

@opal pond found a way in ?
@sly turret tryna figure out what note has to offer

#

Brute forcing everything 😂

sly turret
#

... i shoved in another hint in the note ...

opal pond
#

@opal pond always, always, always, scan all ports when doing nmap....to help speed it up (beyond using -T5), check out the video on youtube that shannon morse (aka snubbs) did with dan tentler (aka viss) on the hak5 channel....that helped me A LOT with scanning speed
@harsh obsidian thx

#

... i shoved in another hint in the note ...
@sly turret i see that thx

#

... i shoved in another hint in the note ...
@sly turret still no luck

fair adder
fair adder
#

lol

#

Maybe I accidentally broke the machine xD

#

Can someone reset the machine?

wraith geyser
#

i never deleted the flag

fair adder
#

...

#

Someone has deleted the flags

winged charm
#

Y’all good in here?

wraith geyser
#

reset?

#

i think someone killed every network service

winged charm
#

can you send over the game id?

wraith geyser
winged charm
#

Reset if it happens again send an email to koth@tryhackme.com or contact a KoTH Staff (I am one)

wraith geyser
#

waiting for the last vote

#

oh wait it changed a lready

fair adder
#

yea

wraith geyser
#

why reset

fair adder
#

I have the same question

#

lol

#

Why did you deleted the xargs? xD

wraith geyser
#

I didnt

#

I moved it to /usr/bin/su

fair adder
#

xD

#

GG @wraith geyser

wraith geyser
#

gg

fair adder
harsh obsidian
#

... i shoved in another hint in the note ...
@sly turret ahhh, Hackers is a great box. Mind DM’ing me the note / hint you slipped in there?

weary axle
#

@fair adder u won each game like pls teach me sone tricks

quiet schooner
#

@opal pond please don't just dump spoilers for the boxes here. They were asking what the other user added.

opal pond
#

@opal pond please don't just dump spoilers for the boxes here. They were asking what the other user added.
@quiet schooner sorry my bad

chrome blade
#

anyone up for a match?

tranquil hare
#

hey

#

anyone want to playy??

opal pond
#

Yez

#

S

#

Yea im not that good neither

#

Its a public game and a God player is in sooo if yall wanna make a private send links

opal pond
#

Starts in 2 mins

opal pond
#

Anyone wanna play ?

crisp needle
#

Anyone for a game of KOTH?

patent forge
wraith geyser
#

20 min

upbeat widget
#

gg hmmm how'd you break the root limited shell?

#

@wraith geyser was it using path manipulation?

wraith geyser
#

bruh

#

why isn't it accepting the flags 😦

#

yo wtf

#

why the fuck is the flag

#

the base64

upbeat widget
#

?

wraith geyser
#

gg

fair adder
quiet schooner
#

@wraith geyser Please don't spoil the boxes like that

sudden tendon
#

starts in 2 minutes

fair adder
#

Are hogwarts machine bug?

nova tide
#

what do you mean?

fair adder
#

idk, i cannot find any flag

#

Any user

nova tide
fair adder
#

xD

nova tide
#

i would say enumerate harder

fair adder
#

I found a .zip and cracked it

nova tide
#

Docker

fair adder
#

lol

dull geode
#

hey

#

I'm a bog noob

#

can anyone pls help me with this

#

you can ofcourse be at first

#

I just need to learn

#

how it is done

chrome blade
dull geode
#

yeh

#

it has started

#

not this one

#

wait

#

let me share

chrome blade
#

okkk

dull geode
chrome blade
#

I have neveer played a koth before

#

I m hopping in!

dull geode
#

me too

chrome blade
#

goodluck

dull geode
#

anyone got privesc??

woven orbit
#

join me fellow newbies

chrome blade
#

anyone got privesc??
@dull geode nah.was trying a c exploit hthough

dull geode
#

@dull geode nah.was trying a c exploit hthough
@chrome blade how the heck did goku got first
lol I submitted the flag first

#

lol

#

well

#

this was nice as a first timer

#

and what was with that base64 string in the home page

#

?

chrome blade
#

@chrome blade how the heck did goku got first
lol I submitted the flag first
@dull geode i forgot to start my vpn and was wondering why nmap is not working lol

#

and what was with that base64 string in the home page
@dull geode private key

dull geode
#

lmao

#

@dull geode private key
@chrome blade no

#

that was on a different page

chrome blade
#

i was searching for a username then though about shrek

dull geode
#

yeh

#

It was written on the tryhack me page at the starting(shrek)kekw

chrome blade
#

It was written on the tryhack me page at the starting(shrek)kekw
@dull geode my bad but it was fun man

dull geode
#

but I'm talking about the base64 string on the index.html page that was commented

#

lol

#

well

#

yeh

@dull geode my bad but it was fun man
@chrome blade

chrome blade
#

but I'm talking about the base64 string on the index.html page that was commented
@dull geode lol i missed it I guess

dull geode
#

OH

chrome blade
#

i uploaded a php reverse shell on port 80

stiff egret
#

Watch the spoilers please.

dull geode
#

lol what??

#

you didn't ssh into shrek?

chrome blade
#

but when i tried to run it under uploads/rev.php it said file not found

#

Watch the spoilers please.
@stiff egret srry

dull geode
#

didn't it supported only jpg and png?

chrome blade
#

you didn't ssh into shrek?
@dull geode i did ofcource thats how i find ythe first plag

dull geode
#

well

chrome blade
#

didn't it supported only jpg and png?
@dull geode there is a trick i saw it in ippsec videos!

dull geode
#

then I have to learn

#

lol

chrome blade
#

i ll tell

dull geode
#

@dull geode there is a trick i saw it in ippsec videos!
@chrome blade what was that?

#

OK

#

were you goku?? @chrome blade

chrome blade
#

na i m drunkenstein

dull geode
#

oh OK

chrome blade
#

@chrome blade what was that?
@dull geode ||GIF8;||appent it at the start of php file

dull geode
#

was it easy?

#

OHHHHH

#

like this

chrome blade
#

was it easy?
@dull geode i think yeah ran out of time thoug

#

was it easy?
@dull geode then upload with .php extension it will work!

dull geode
#

rev.GIF8.php?(just guessed)(I have no idea)

chrome blade
#

na

dull geode
#

OH inside the file

#

?

chrome blade
#

yes

dull geode
#

OH I get it now

#

thanks

chrome blade
#

but i couldnt execute it lol

dull geode
#

oh

#

well

#

it would have been worth a try tho

#

lol

chrome blade
#

it works most of the time😉

#

would love to paly mor koth in future @dull geode

dull geode
#

would love to paly mor koth in future @dull geode
@chrome blade yeh me too

#

well

#

We will tho

#

you can send invitation links tho

#

PM me 🙂🙂

chrome blade
#

We will tho
@dull geode I have sent a friend request

#

Do you know how to patch vulnerabilties in koth?

dull geode
#

Do you know how to patch vulnerabilties in koth?
@chrome blade nope

#

I'm new in these things

chrome blade
#

@chrome blade nope
@dull geode me too

dull geode
#

loo

#

lol

fair adder
#

great guy!!! @woven orbit

#

how its going?

#

lol

#

hehuuehe

#

wp

eternal garden
#

King of the Hill

dull geode
opal pond
#

How long till it starts ?

crisp needle
#

I was wondering the same question

opal pond
sudden tendon
opal pond
#

@opal pond starts in 4
@ms.geeky#2472 already in

sudden tendon
#

haha I know it's for others

opal pond
#

Ah k

sudden tendon
#

okay!

opal pond
#

okay!
@ms.geeky#2472 did u change the pass ?!

dull geode
#

@sudden tendon have you done this before too?

opal pond
#

Can we reset ?

dull geode
#

yeh

opal pond
#

No re use of flags plz

dull geode
#

I'm doing this first time

opal pond
#

Its my second time but im not using any old flags

#

Thats not fun

nova tide
#

Can we reset ?
@opal pond why?

sudden tendon
#

@sudden tendon did u change the pass ?!
@opal pond yeah man

opal pond
#

The passwd for the user who had weak pass was changed

dull geode
#

someone has did this before and just doing it with us

nova tide
#

The passwd for the user who had weak pass was changed
@opal pond So you want to reset just because of that??

opal pond
#

I mean

#

Ok lets not reset

#

🤷🏻‍♂️

dull geode
#

So you want to reset just because of that??
@nova tide someone had done this before so what's the point for the newcomers?

nova tide
#

There must be more ways for foothold/privesc. Why not try looking for those instead?

dull geode
#

should they just sit back??

#

there's a point for doing

nova tide
#

for newcomers?? i would suggest don't play if you are a newcomer. KoTH is for beginner level players for a reason. If you want to reset just because you can't ssh in using the one weak password you found then you need more time doing rooms instead of playing KoTH

dull geode
#

newcomers in KOTH bro

#

there was a submit of flag right away when the machine started

nova tide
#

should they just sit back??
@dull geode That's the whole point for koth. There are more than one way to get in. So instead of sitting back and waiting for someone to reset the box for you why not start looking for other ways in

dull geode
#

there was a submit of flag right away when the machine started
@dull geode .

nova tide
#

That's their mindset. but it's not impossible to find all of the flags that quick.

dull geode
#

That's their mindset. but it's not impossible to find all of the flags that quick.
@nova tide that's what I'm saying they had the flag beforehand

nova tide
#

okay, so you have an hour to find them. Good luck

dull geode
#

lol

#

it has already been wasted

nova tide
#

how??

#

there are no blood points for flags...

dull geode
#

leave it

#

nvm

nova tide
#

and they are not allowed to delete the flags either.. If you can find you way in then you can get those flags 🤷‍♂️

#

Its up to you what you do.

opal pond
#

Ohhh now u wannaaa reset huh

#

Lol

#

What happened the password lol

dull geode
#

idk

opal pond
#

Lets not reset for a sec

#

Whos playing rn ??

dull geode
#

I didn't

#

me

opal pond
#

@sudden tendon u still playing

dull geode
#

who's unknown?

opal pond
#

Me

dull geode
#

oh

#

lol

#

nice

opal pond
#

Welp ssh is not a way in no more rip

sudden tendon
#

@sudden tendon u still playing
@opal pond lol just found the ssh creds I guess Yes

#

who's unknown?
@dull geode got no idea

opal pond
#

@opal pond lol just found the ssh creds I guess Yes
@ms.geeky#2472 u in rn ?

#

@dull geode got no idea
@ms.geeky#2472 thats me

sudden tendon
#

don't kick me out tho :/

#

damn it you ppl!Seriously!?

dull geode
#

what happend?

sudden tendon
#

they reset the machine yet again

#

:/

winged charm
#

yall good in here?

opal pond
#

Yessir

#

they reset the machine yet again
@ms.geeky#2472 ggs

sudden tendon
#

yall good in here?
@winged charm Yeah dude!thanks for askin'

#

@sudden tendon ggs
@opal pond Oof thanks man!You too

opal pond
#

Damnn as soon as i get root

#

Times out

#

Lol

#

Ggs

sudden tendon
#

lol guess I was lucky.....

opal pond
#

Nah no luck

#

Anyways

#

Im in a public lobby with 2 other pll

#

Ppl

#

3 other pol

#

Ppl*

sudden tendon
#

haha

opal pond
#

Join if yall want

sudden tendon
#

link?

opal pond
#

No re use of old flags plz

dull geode
#

pls

#

OK @sudden tendon ??
pls bro/sis

sudden tendon
#

lol will try

dull geode
#

are you ppl able to run simple commands like ls and cd?? on the machine

dull geode
#

lol

#

hey just for info
someone removed the files from tmp directory in food machine in the KOTH

quiet schooner
#

Is that a problem?

velvet nexus
quiet schooner
#

It shouldn't be.

velvet nexus
#

4 mins left

dull geode
#

IDK

#

cause I can't 'ls' into any directory

quiet schooner
#

If it's a problem, report it. If it's not a problem, then why mention it?

dull geode
#

I dont know if it was done

quiet schooner
#

If you're in ||telnet|| then that's intended.

dull geode
#

while creating the machine

#

no

#

not even in ssh

quiet schooner
#

so report it if you need to ¯_(ツ)_/¯

#

There's procedure for this

dull geode
#

OK

#

nvm

#

I found a way

sudden tendon
#

cool

#

GG guys!

dull geode
#

gg

velvet nexus
#

hi guys

#

has anyone tried the hogworts room in KOTH

cerulean maple
#

I tried it and cried xDD

velvet nexus
#

😳

#

20 minutes left

weary axle
#

sry

#

cant join

velvet nexus
#

y

weary axle
#

gt sleep

velvet nexus
#

ok

weary axle
#

its 10 right?

velvet nexus
#

yeah

weary axle
#

so i hve to

#

3 min still

velvet nexus
#

ok bro

weary axle
#

i hv to do hw

#

will u do tom after 2 sometime??

#

@velvet nexus

velvet nexus
#

what?

#

ok bro do ur hw

weary axle
#

histry

#

and it is headache

#

lol

#

gn

velvet nexus
#

ook

#

gn

opal pond
#

U still in ?

opal pond
opal pond
opal pond
#

If anyones playing with me in this room check robots.txt a put a hint ther 😉

gloomy estuary
#

12mn

fair adder
patent forge
weary axle
#

@patent forge

#

are u pro?

patent forge
#

what do you mean with pro? 😆

weary axle
#

r u begginer inter or pro

patent forge
#

pretty much beginner, but played a lot of koths

weary axle
#

me played less koths

#

wait shit i m not in linux

#

in windows curretnly

#

will do after a hr

#

next koth

#

u fine @patent forge

#

and i need help in koths

#

@patent forge

#

are u playing

patent forge
#

yes

#

@weary axle are you?

weary axle
#

which command u used?

#

chattr y u removed?

#

@patent forge

#

@patent forge

patent forge
#

not removed

#

@weary axle i'm out, don't wanna waste my time patching stuff to get a reset.

opal pond
#

Anyone up for a game or two

weary axle
#

@weary axle i'm out, don't wanna waste my time patching stuff to get a reset.
@patent forge really?

sly turret
#

@patent forge have a question ... you deleted or changed chattr ... is it possible to upload busybox and run chatter from there ?

gloomy estuary
dull geode
#

lol who changed the website on panda?

#

is it allowed?

#

to change the website

#

at least keep the image same bro

#

@gloomy estuary

gloomy estuary
#

I just put a message, it's nothing that will disrupt the game

#

there was an image of the furious 5

#

nothing much, just put a message

dull geode
#

well

#

the message seem to remove the image

#

yeh

#

there was an image of the furious 5
@gloomy estuary and that's not there anymore

gloomy estuary
#

look now

#

everything ok now?

dull geode
#

yeh gg

opal pond
#

Anyone wanna play in like 15 min

dull geode
#

gg @gloomy estuary

gloomy estuary
#

hehe

dull geode
#

Anyone wanna play in like 15 min
@opal pond yeh

#

cmon

#

send the link

opal pond
#

Lemme turn my stuff on

#

Join a public game and send a link

#

Till i get my stuff together

dull geode
#

well

sudden tendon
#

starts in 17 minutes

cerulean maple
#

Has it started already ?

opal pond
#

??

#

Has it ?

sudden tendon
#

Yeah but do join

opal pond
#

Im in

sudden tendon
#

Great!

opal pond
#

Ohh its hogwarts

#

Jesus

sudden tendon
#

lol

opal pond
#

A whole maze

sudden tendon
#

I got no idea what to do

opal pond
#

Same

sudden tendon
#

Ahh I see done this before?

opal pond
#

Not me

#

But lemme tell you its a whole maze

sudden tendon
#

lol I can see that from the nmap scan

opal pond
#

Wait till you actually go to the ports

sudden tendon
#

okayy

cerulean maple
#

hahah not hogwarts anything but that xD

opal pond
#

Ikr

sudden tendon
#

you guys got anything?

opal pond
#

Lol

#

Nah i gave up already

sudden tendon
#

lol I'm supposed to be sleeping....thought of having some fun instead only to experience this

opal pond
#

I heard the priv esc on it is pretty easy

#

But actually getting a foothold on the box ..

#

Its beyond me

sudden tendon
#

I found something but no idea what that is

#

I will dm you

opal pond
#

Ok

crisp needle
sudden tendon
#

no dude why?

crisp needle
#

I missed

sudden tendon
#

oh okay ok

opal pond
#

oh okay ok
@ms.geeky#2472 u having fun ?

sudden tendon
#

Yeahh for sure

#

thanks for the game

opal pond
#

Anyone up for a game ?

idle siren
#

Anyone wanna come?

#

@haughty tendon good luck 🙂

opal pond
#

Anyone wanna come?
@idle siren did somebody straight up kill ssh ?

idle siren
#

U are in same room with me?

opal pond
#

How else would i know that 🙂

idle siren
#

I didnt kill it. I just tried to connect to it and then moved to sql

opal pond
#

Oh so the port changed huh

#

Nah nvm its still 22

#

I didnt kill it. I just tried to connect to it and then moved to sql
@idle siren u still playing?

idle siren
#

yeah, playing with the ssh

opal pond
#

Dm me if you want a hint

idle siren
#

okay.

opal pond
hot bloom
#

20 mins

weary axle
#

can i make a video of solving a koth

summer star
brazen cloud
#

You stream and post writeups on KoTH machines @weary axle

#

This extends to making a video (:

weary axle
#

what?

brazen cloud
#

You stream and post writeups on KoTH machines @weary axle
@brazen cloud

weary axle
#

idk how to make a writup

brazen cloud
#

Videos too

#

It's listed in the rules

weary axle
#

cant i make a video like start a private game and play

opal pond
#

Anyone up for a game

idle siren
fair adder
#

shadowgag

sudden tendon
#

starts in 2m

wraith geyser
#

23m

tall spoke
#

do you guys think it would be against the rules to change an id_rsa key in KOTH?

fair adder
#

10min...

terse willow
#

@tall spoke no, it's allowed 🙂

sly turret
#

@tall spoke dont remove files dont shutdown services ... change password (rsa keys) and change service ports are allowed ...

quiet schooner
#

"removing files" is a bit of a vague one tbh, you can remove files and it still be perfectly fine rules wise

tranquil hare
#

starts in 19 minutes from now

dull geode
#

16 mins

#

can we move files?

velvet nexus
#

15 mins left

sly turret
#

"removing files" is a bit of a vague one tbh, you can remove files and it still be perfectly fine rules wise
@NinjaJc01#7746 ok removing flags 😂

opal pond
#

Anyone wanna play

scarlet fog
#

yo

sly turret
#

"removing files" is a bit of a vague one tbh, you can remove files and it still be perfectly fine rules wise
@NinjaJc01#7746 ok removing flags 😂

opal pond
#

Anyone?

harsh obsidian
#

.

opal pond
#

؟

#

.
@harsh obsidian down to play ?

harsh obsidian
#

Halfway playing a match now while at work. If you just need a player in the room so you can practice, I've got you.

opal pond
#

Nah thx though

harsh obsidian
#

No worries

hot bloom
#

@harsh obsidian did you move on to a different game?

harsh obsidian
#

@harsh obsidian did you move on to a different game?
@hot bloom Ish. i'm at work right now and got pulled in to meetings and whatnot

hot bloom
#

Ah, bummer

#

Also, double bummer for working on a Saturday

harsh obsidian
#

meh, such is life

#

@hot bloom i'm surprised you didn't finish off the flags

hot bloom
#

I couldn't find them all lol

#

I was trying to figure out how to mess with ioctl flags without chattr

#

Since it wasn't on the box

quiet schooner
#

You can always pull across a static binary with a different name

#

I think you can also do it with python

hot bloom
#

Also, was distracted by the news

#

Biden won

#

I think you can also do it with python
@quiet schooner Yeah, found a couple options

harsh obsidian
#

@quiet schooner Yeah, found a couple options
@hot bloom can you PM some of those resources so i can learn as well, please?

hot bloom
#

Sure

dull geode
#

24 mins

#

anyone?

#

22 mins

dull geode
#

6 mins

fair adder
#

I have a question, if default user have sudo perms. Is it by the rules that i edit sudoers file and remove user from sudoers ?

dull geode
#

no

#

you can

#

remove the user/users

#

from sudoers

#

@opal pond lol you ofcourse are a good in this than me lol
I tried so hard to retain king lmao

fair adder
#

thank you

dull geode
#

gg

sudden tendon
#

starts in 1 min

opal pond
#

I’ll be playing in 15 mins

sudden tendon
#

great!will be waiting to have fun w/ you

opal pond
#

Hey

#

Wanna “have fun” with me ? Lol

sudden tendon
#

hahaha yeah

#

it's boring playing without someone you know

opal pond
#

Im in a public game with another dude

#

Join if u want

#

Starts in 19 mins tho

sudden tendon
#

Okay!I will join....thanks

opal pond
#

Okay!I will join....thanks
@ms.geeky#2472 want me to send you the link ?

sudden tendon
#

that will be very helpful

opal pond
sudden tendon
#

joined!

dull geode
#

24 mins

opal pond
#

Anyone wanna play

dull geode
#

yep

opal pond
#

Starts in 14 min

#

Mins

pine flint
#

What’s a Koth?

dull geode
#

king of the hill lol

pine flint
#

Well, I know what the thing means

#

But what do you do in it

dull geode
#

you hack a machine

#

capture flags

#

and

#

escalate your privileges

#

and

#

try to retain your name in the king.txt file

pine flint
#

1 machine for all or 1 for each

dull geode
#

1 for all

#

1 for 10 to be precise

pine flint
#

damm

#

that’s hard ig

dull geode
#

umm

#

well practice makes a man perfect

#

lol

pine flint
#

right

opal pond
#

umm
@dull geode where did u go

dull geode
#

my machine died lol

#

and I have to take food lol

#

so I don't think I'll play today

dull geode
#

2 mins

opal pond
opal pond
#

Starts in 5 mins

opal pond
#

Its a public game btw

#

Its back again nvm

#

Can you do that ? Deleting the file than creating it again to put ur name in it ?

stiff egret
#

It isn't supposed to be deleted.

opal pond
#

I think someone did tho

stiff egret
#

Pretty sure it's in the rules.

When on earth will players start reading rules. URGHHHHH

opal pond
#

I even did find / -name king.txt

#

As roo

#

Root*

#

And can someone tell me how many flags are on Tyler ?

stiff egret
#

They must've made a loop to delete and add new, but well, it will result in service not picking up the file and hence they will lose some points.

#

And can someone tell me how many flags are on Tyler ?
@opal pond Hover near the flag submission box, the flag icon should tell you how many are there.

opal pond
#

The games finished can you tell ? Im tryna see if there is a bug

stiff egret
#

There are only 2.

opal pond
#

Cuz sometimes when i quickly double click the submit button for the flags I believe sometimes it counts 2 flags

stiff egret
#

Not sure, but my notes says so.

opal pond
#

There are only 2.
@Mr.Holmes#0001 i found 5 thi :/

#

I believe there is only 5

#

But i somehow submitted 6

#

Cuz sometimes when i quickly double click the submit button for the flags I believe sometimes it counts 2 flags
@ion.know#3578 .

stiff egret
#

That's a known bug.

opal pond
#

Oh

#

Thanks anyways

opal pond
#

That's a known bug.
@Mr.Holmes#0001 when will u add hogwarts to ur github :c that room confuses the f outta me

stiff egret
#

When new machine is released.

opal pond
#

Which I assume u can’t say when that happens ?

stiff egret
#

🤷‍♂️ :)

opal pond
#

Can you tell me if in the right direction? A little hint maybe ? Cuz i think i found some stuff

#

I’ll say one word and you tell me if im in right direction?

stiff egret
#

Maybe(?)

opal pond
#

Idk if its considered spoiling

#

I’ll delete right after i say it

stiff egret
#

I'll delete it if it is.

#

Well, that's one way to go

#

that one is pretty straight forward.

opal pond
#

Is it like the 3 thingys ?

stiff egret
#

Um, the 3 thingys are another way to go, these are not connected

opal pond
#

Am I missing something thats right under my nose ?

gusty cradle
#

👀

stiff egret
#

Just look carefully. at everything.
BTW have you rooted it?

opal pond
#

Nah not even close its beyond me

#

I just found this

#

These

#

I think ik some stuff bout the thing you deleted

#

Some ideas

#

But the others nah

stiff egret
#

Well, you can try again, check services on every port, there are some ports you might have missed, don't stick to one port. You can get shell from every foothold in less than 3 minutes, so if it takes you more than 10 minutes on any port, you are in the wrong direction.

opal pond
#

And the ports change everytime right ?

#

Or am I tripping

stiff egret
#

Yeah most of the stuff changes everytime

opal pond
#

Yea I figured

#

Wanna reset the box so we can give this guy another chance ?

#

(Koth)

stiff egret
#

uh, Oh, your call, I am not in the game.

#

🤷‍♂️

opal pond
#

Yea pls vote if ur on

stiff egret
#

aight

opal pond
#

Cuz i see him on the box assuming he’s still trying

stiff egret
#

OH I did got in for a sec, IIRC all privesc are gone

#

No point of trying.

opal pond
#

Fr ??

#

Oh my bad i though there where other ways

#

Yea lets reset

stiff egret
#

I checked 3 methods, all are dead

opal pond
#

They were all suid ?

#

Well and sudo

stiff egret
#

2 were suid

opal pond
#

Did u vote or no ??

stiff egret
#

Oh I did.

#

Pretty sure all others left

opal pond
#

Oh thats u on the box ?

stiff egret
#

um no

opal pond
#

I thought u weren’t playing

#

So someone is

stiff egret
#

Oh yes I am

#

hol on.

#

Yeah that was me.

opal pond
#

Yea probably everyone left anyways

stiff egret
#

my tmux was on, smh.

opal pond
#

Someone got kicked out cuz of chees starts and since i changed the ssh port they gave up

#

Ggs anyway

stiff egret
#

GG :)

fair adder
#

Hogwarts T T

#

guys

glossy sundial
#

What

hot bloom
weary axle
#

@hot bloom

#

can u start agai

hot bloom
#

Sure. Did you start one or should I?

weary axle
#

u can

#

5 min one

#

can u teach me but for some machines?

#

@hot bloom

hot bloom
#

Teach you what?

weary axle
#

like some machines are hard

#

for me

#

lion for example

#

i couldnt solve it

hot bloom
#

I haven't done that one

weary axle
#

o

#

link?

hot bloom
#

Someone already started a game..

weary axle
#

16

weary axle
#

@hot bloom did u remove chattr?

hot bloom
#

Nope

#

There wasn't one on the box

#

At least, not that I could find

weary axle
#

so which command u used?

#

cause i couldnt edit

opal pond
#

Anyone wanna play ?

weary axle
#

now?

weary axle
#

anyone

opal pond
#

anyone
@weary axle u up ?

dull geode
#

yes cmon

#

let me start my machine

#

1 min

dull geode
winged charm
#

adjust your Firefox settings

opal pond
#

About::config

#

Said that like 100 times in general

dull geode
#

OK OK

#

thanks

#

does anybody have any idea for hogwarts machine??

cerulean maple
#

All I know that it has rabbit holes 😄

weary axle
#

and it is something idk

nova tide
#

Isn't that what we call spoiling a box?

weary axle
#

is it>

#

idk

#

deleting all just a min

nova tide
#

Thanks 😊

weary axle
#

can i make a walkthrough?

nova tide
#

Just hint would be fine but no need to explain the whole method

weary axle
#

i always have habbit of explaining

nova tide
#

Just hint would be fine but no need to explain the whole method
That was for talking here

#

And for walkthrough @stiff egret you ok with someone making public writeup for hogwarts?

weary axle
#

i m asking

#

idk how to make a website

nova tide
#

You can make notes for yourself, were you asking to make it for someone else or just yourself?

weary axle
#

like a post

nova tide
#

And for walkthrough @stiff egret you ok with someone making public writeup for hogwarts?

weary axle
#

i is asking.....................can i make a video rather??

#

cause i didnt find any

#

im bad at writing

stiff egret
#

There is already one writeup of Hogwarts public,

weary axle
#

is it?

#

can i mke a video?

stiff egret
#

Also, I have no problem with anyone making writeups for it, but I'd suggest only show one method to root the box, not all of them.

#

can i mke a video?
@weary axle Sure :)

opal pond
#

There is already one writeup of Hogwarts public,
@Mr.Holmes#0001 where ?

stiff egret
#

🤣

opal pond
#

Didn’t u say you wouldn’t release write ups till the next box came out ?!

#

:google:
@Mr.Holmes#0001 nothing

stiff egret
#

I didn't release any official writeup

#

It's from someone else.

dull geode
#

lol holmes why reset?

stiff egret
#

not me

#

I was king, why would I reset lol

dull geode
#

aah I know

#

bruh

#

I changed all the passwords then someone reset the machine

#

then you became the king

stiff egret
#

Yep, I saw that, almost everything was patched

#

(except one)

dull geode
#

lol

#

yeh

#

I'm still a learner

#

but

#

it's rude

#

to just

stiff egret
#

I got in from that, tho pretty nice patches.

dull geode
#

reset if you can't find passwords

#

thanks

stiff egret
#

Reset is a necessary evil.

dull geode
#

lol someone just removed simple commands

stiff egret
#

huh? I am in the box, lemme check

dull geode
#

lmaokekw

#

me too

#

I'm checking

stiff egret
#

Everything is alright

#

except nc binary, someone removed it

dull geode
#

I can't do locate lmao

stiff egret
dull geode
#

aah

stiff egret
dull geode
#

hey after this is over just tell me how did you remove the write permissions and chmod permissions

#

pls

stiff egret
#

man chmod

dull geode
#

and what was that patch from which you broke in

#

OK

stiff egret
#

and what was that patch from which you broke in
@dull geode Uh, DM, It'll be a spoiler here.
Tho I'd say just look for yourself, you can find it. If I tell you then it won't be fun.
Might as well read writeups of all machines.

dull geode
#

yeh not here

#

but after this

opal pond
#

Starts in 6 mins

dull geode
#

OMG holmes what the heck

#

how did you change the permissions for not changing any permissions lmao

#

OK I give up

#

I literally tried 15 things to change the permissions now you removed the reading perms too

stiff egret
#

Wai- wha- ?

#

No, I didn't do anything with read permissions.

dull geode
#

yeh sorry I saw wrong lol

stiff egret
#

Join in if anyone wanna play.

gusty cradle
#

🤔

dull geode
#

ok gg holmes that was some nice game(definitely not nice of you😑)

stiff egret
#

GG :)

timber pelican
#

Hello thanks to whoever invited me to this server. Someone wants to play a 1v1 just for fun?

timber pelican
#

find me in voice

fair adder
sudden tendon
#

starts in 8 minutes

hot bloom
wraith geyser
#

gg

hot bloom
#

Wow, that was a really fun game

sacred comet
#

hey

#

anyonw will play?

weary axle
#

me

sacred comet
#

come on

#

Game in 3 minutes

weary axle
#

nice game

#

first time 30+ min king

#

47 min

sacred comet
#

lets play again

weary axle
#

depends

#

i m tired

#

just came from downstairs

#

but if machine is tough i will go

#

cause im sleepy

#

o man production

sacred comet
#

okk no prob

opal pond
#

Anyone up for a game

frank oracle
#

I can play once i complete brute it

sacred comet
#

yeah

opal pond
#

Aight lemme start up my stuff

#

I can play once i complete brute it
@frank oracle which part of it are at rb

#

Rn

frank oracle
#

I um, priv esc

opal pond
#

That shouldn’t take long then

frank oracle
#

Depends on how fast linpeas work

opal pond
#

I think u could find some pretty good stuff manually

#

I always check manually

cerulean maple
#

You could priv esc without linpeas

opal pond
#

Then run linpeas

cerulean maple
#

Yeah

frank oracle
#

I can, but i choose not to

opal pond
#

Ok u do u

frank oracle
#

I'll let ya know

weary axle
#

why cant i find all the flags>

#

it says find 8 flags i fing 4