#koth
1 messages · Page 51 of 1
xD
did you mean busybox?
@fair adder I mean a static binary
However you choose to source one
The machine did not have the chattr, for some reason
It's not always present
i know
And it can be removed
Sure
That's something a lot of people do so it's not that surprising
@quiet schooner @fair adder can u help?
??
Upload your own chattr binarie
how?
@weary axle Blog post!
SCP, Netcat...
didnt use any
@weary axle Blog post!
@quiet schooner Maybe you could just stop saying that and send the link
I'm a firm believer in finding the resources yourself
-___-
part of research
I'm a firm believer in finding the resources yourself
@quiet schooner So, Why do you keep saying "blog post!"
someone reset machiene
because it's all covered in the blog post that you should read
'-'
whichhhhh
this
See, research
i read
now i m king for next 20 min
but udbhav was 30 mu
shit
@velvet nexus
now which command
i am still the king bro
now which command
@weary axle chattr -i king.txt && echo Udbhav > king.txt
i did it indivi but not happeneing
i am used the same command bro
bro now i cant get the king
You can make loops you know.
how?
then
Then read what's on screen, you'll know.
no manula entry for while
shit i lost a easy game
thanks for the help @stiff egret
bro did u loop??
yes
i used when homes told me
now have to study
ok bro
:))
What level do you have to be to play if you’re using a fresh account
Anyone interested for a game of KOTH?
What’s a KoTH mate
Apparently I’m a KoTH Staff or something
Don’t know what that means
who unmuted cry??
Question of the month
Any newbies wanna join ? Im not good
Starts in 15 mins
@harsh obsidian Raaaaaaage 😄
How tf do you flood my terminal like that? 😦
Lol, it took a lot of work to figure out, I'm not gonna lie
that sucks.. really
Are you getting the quotes now?
Not gonna lie, that's my favorite one.
i hate it atm 😉
Lemme see if it'll let me stop them; sometimes it will, sometimes it won't
how did you do this?
a whole lot of work with the echo command
thats a really good tactic to stop everybody else
did that work to stop the movie quotes?
yes. they stopped
sweet
hm 😄
shouldn't be any random flood either
terminal is useless now
nothing works
anyway. you won this one.
and i cant figure out how this backdoor works
Talking port ||9001|| ?
So I've looked at the code and got ||the password|| but I've never got it to work. From what others have told me, it's a troll from the room creator
oh man... what a bummer
I'm off the box altogether if you still need to play around and learn / search
but according to the code it shoult work
Which room are you guys doing
production
Ah ok gl
but according to the code it shoult work
@fair adder Agreed. It confuses the shit out of me. I have a thought, but I'm too lazy to track it down and see if it works...
theres nothing more to do... n0beard rocked it
@fair adder Thanks!
At first I thought i could win it
At first I thought i could win it
@fair adder You had it for a bit. And I wasn't sure that I'd be able to get on the box and get King....
My method (at least for KotH), is take how I got on the box and remove that avenue. And just work that one avenue at a time.
Yeah, did that in the beginning
but after the first or second reset i wasnt able to do so
you were faster i think
I try and chain commands together as much as possible to max the speed
For example, did you know that the ssh command in Linux has a -t option?
You definitely should. It's helped me A LOT
@opal pond i'm in the room to make sure you can play, but i don't know if i'm gonna be able to play or not (meeting)
@opal pond i'm in the room to make sure you can play, but i don't know if i'm gonna be able to play or not (meeting)
@harsh obsidian thx
@opal pond i'm in the room to make sure you can play, but i don't know if i'm gonna be able to play or not (meeting)
@harsh obsidian gg :c which path did you take ?
i started with netcat
i connected and grabbed king only because no one was king, but i didn't do anything that would've kept me king or patched access.
I didn’t know where both of the upload pages put the payload Tried that 2018 and 2019 cve on librenms with anonymous login no luck. Found one flag in smb and a alert.txt that had I believe a password in it but I didn’t know what the password was for
How did you get 1 flag?
anyone want to play
Yes im not good tho it’ll be my third game
How did you get 1 flag?
@crisp needle I have all of the flags for that box in my notes, i only bothered to submit the one
@crisp needle I have all of the flags for that box in my notes, i only bothered to submit the one
@harsh obsidian whats up with that alert txt ?? The “intresting” password ?
no re use of password or flags pls .. play fair
@harsh obsidian whats up with that alert txt ?? The “intresting” password ?
@opal pond I don't remember anything about alert.txt....
no reuse of password or flags pls .. plaz fair
@sly turret this is literally my 3rd game i dunnu anything about the boxes
@opal pond I don't remember anything about alert.txt....
@harsh obsidian ok
oh okay 😄
Go easy on me 🙂
@opal pond always, always, always, scan all ports when doing nmap....to help speed it up (beyond using -T5), check out the video on youtube that shannon morse (aka snubbs) did with dan tentler (aka viss) on the hak5 channel....that helped me A LOT with scanning speed
@opal pond found a way in ?
@sly turret tryna figure out what note has to offer
Brute forcing everything 😂
... i shoved in another hint in the note ...
@opal pond always, always, always, scan all ports when doing nmap....to help speed it up (beyond using -T5), check out the video on youtube that shannon morse (aka snubbs) did with dan tentler (aka viss) on the hak5 channel....that helped me A LOT with scanning speed
@harsh obsidian thx
... i shoved in another hint in the note ...
@sly turret i see that thx
... i shoved in another hint in the note ...
@sly turret still no luck
i never deleted the flag
Y’all good in here?
can you send over the game id?
Reset if it happens again send an email to koth@tryhackme.com or contact a KoTH Staff (I am one)
yea
why reset
gg
... i shoved in another hint in the note ...
@sly turret ahhh, Hackers is a great box. Mind DM’ing me the note / hint you slipped in there?
@fair adder u won each game like pls teach me sone tricks
@opal pond please don't just dump spoilers for the boxes here. They were asking what the other user added.
@opal pond please don't just dump spoilers for the boxes here. They were asking what the other user added.
@quiet schooner sorry my bad
anyone up for a match?
Yez
S
Yea im not that good neither
Its a public game and a God player is in sooo if yall wanna make a private send links
Starts in 2 mins
Anyone wanna play ?
Anyone for a game of KOTH?
public one in 5 mins 🙂 https://tryhackme.com/games/koth/join/25beb13da96497057c1df022
20 min
gg hmmm how'd you break the root limited shell?
@wraith geyser was it using path manipulation?
bruh
why isn't it accepting the flags 😦
yo wtf
why the fuck is the flag
the base64
?
gg
@wraith geyser Please don't spoil the boxes like that
starts in 2 minutes
Are hogwarts machine bug?
what do you mean?


i would say enumerate harder
I found a .zip and cracked it
Docker
lol
hey
I'm a bog noob
can anyone pls help me with this
you can ofcourse be at first
I just need to learn
how it is done
https://tryhackme.com/games/koth/join/4977b3db840dbb0fd680c958
@dull geode U still on?
okkk
me too
goodluck
anyone got privesc??
join me fellow newbies
anyone got privesc??
@dull geode nah.was trying a c exploit hthough
@dull geode nah.was trying a c exploit hthough
@chrome blade how the heck did goku got first
lol I submitted the flag first
lol
well
this was nice as a first timer
and what was with that base64 string in the home page
?
@chrome blade how the heck did goku got first
lol I submitted the flag first
@dull geode i forgot to start my vpn and was wondering why nmap is not working lol
and what was with that base64 string in the home page
@dull geode private key
i was searching for a username then though about shrek
It was written on the tryhack me page at the starting(shrek)
@dull geode my bad but it was fun man
but I'm talking about the base64 string on the index.html page that was commented
lol
well
yeh
@dull geode my bad but it was fun man
@chrome blade
but I'm talking about the base64 string on the index.html page that was commented
@dull geode lol i missed it I guess
OH
i uploaded a php reverse shell on port 80
Watch the spoilers please.
but when i tried to run it under uploads/rev.php it said file not found
Watch the spoilers please.
@stiff egret srry
didn't it supported only jpg and png?
you didn't ssh into shrek?
@dull geode i did ofcource thats how i find ythe first plag
well
didn't it supported only jpg and png?
@dull geode there is a trick i saw it in ippsec videos!
i ll tell
@dull geode there is a trick i saw it in ippsec videos!
@chrome blade what was that?
OK
were you goku?? @chrome blade
na i m drunkenstein
oh OK
@chrome blade what was that?
@dull geode ||GIF8;||appent it at the start of php file
was it easy?
@dull geode i think yeah ran out of time thoug
was it easy?
@dull geode then upload with .php extension it will work!
rev.GIF8.php?(just guessed)(I have no idea)
na
yes
would love to paly mor koth in future @dull geode
@chrome blade yeh me too
well
We will tho
you can send invitation links tho
PM me 🙂🙂
We will tho
@dull geode I have sent a friend request
Do you know how to patch vulnerabilties in koth?
Do you know how to patch vulnerabilties in koth?
@chrome blade nope
I'm new in these things
@chrome blade nope
@dull geode me too
King of the Hill
How long till it starts ?
I was wondering the same question
https://tryhackme.com/games/koth/join/9da27fab873ce013e54a2ea0
@opal pond starts in 4
@opal pond starts in 4
@ms.geeky#2472 already in
haha I know it's for others
Ah k
okay!
okay!
@ms.geeky#2472 did u change the pass ?!
@sudden tendon have you done this before too?
Can we reset ?
yeh
No re use of flags plz
I'm doing this first time
Can we reset ?
@opal pond why?
@sudden tendon did u change the pass ?!
@opal pond yeah man
The passwd for the user who had weak pass was changed
someone has did this before and just doing it with us
The passwd for the user who had weak pass was changed
@opal pond So you want to reset just because of that??
So you want to reset just because of that??
@nova tide someone had done this before so what's the point for the newcomers?
There must be more ways for foothold/privesc. Why not try looking for those instead?
for newcomers?? i would suggest don't play if you are a newcomer. KoTH is for beginner level players for a reason. If you want to reset just because you can't ssh in using the one weak password you found then you need more time doing rooms instead of playing KoTH
should they just sit back??
@dull geode That's the whole point for koth. There are more than one way to get in. So instead of sitting back and waiting for someone to reset the box for you why not start looking for other ways in
there was a submit of flag right away when the machine started
@dull geode .
That's their mindset. but it's not impossible to find all of the flags that quick.
That's their mindset. but it's not impossible to find all of the flags that quick.
@nova tide that's what I'm saying they had the flag beforehand
okay, so you have an hour to find them. Good luck
and they are not allowed to delete the flags either.. If you can find you way in then you can get those flags 🤷♂️
Its up to you what you do.
idk
@sudden tendon u still playing
who's unknown?
Me
Welp ssh is not a way in no more rip
@sudden tendon u still playing
@opal pond lol just found the ssh creds I guess Yes
who's unknown?
@dull geode got no idea
@opal pond lol just found the ssh creds I guess Yes
@ms.geeky#2472 u in rn ?
@dull geode got no idea
@ms.geeky#2472 thats me
what happend?
yall good in here?
yall good in here?
@winged charm Yeah dude!thanks for askin'
@sudden tendon ggs
@opal pond Oof thanks man!You too
lol guess I was lucky.....
Nah no luck
Anyways
Im in a public lobby with 2 other pll
Ppl
3 other pol
Ppl*
haha
Join if yall want
link?
No re use of old flags plz
lol will try
are you ppl able to run simple commands like ls and cd?? on the machine
lol
hey just for info
someone removed the files from tmp directory in food machine in the KOTH
Is that a problem?
It shouldn't be.
4 mins left
If it's a problem, report it. If it's not a problem, then why mention it?
I dont know if it was done
If you're in ||telnet|| then that's intended.
gg
I tried it and cried xDD
😳
20 minutes left
y
gt sleep
ok
its 10 right?
yeah
ok bro
U still in ?
If anyones playing with me in this room check robots.txt a put a hint ther 😉
12mn
https://tryhackme.com/games/koth/join/3acae1cc443e5f0149817202 ping me if playing 🙂
what do you mean with pro? 😆
r u begginer inter or pro
pretty much beginner, but played a lot of koths
me played less koths
wait shit i m not in linux
in windows curretnly
will do after a hr
next koth
u fine @patent forge
and i need help in koths
@patent forge
are u playing
not removed
@weary axle i'm out, don't wanna waste my time patching stuff to get a reset.
Anyone up for a game or two
@weary axle i'm out, don't wanna waste my time patching stuff to get a reset.
@patent forge really?
@patent forge have a question ... you deleted or changed chattr ... is it possible to upload busybox and run chatter from there ?
lol who changed the website on panda?
is it allowed?
to change the website
at least keep the image same bro
@gloomy estuary
I just put a message, it's nothing that will disrupt the game
there was an image of the furious 5
nothing much, just put a message
well
the message seem to remove the image
yeh
there was an image of the furious 5
@gloomy estuary and that's not there anymore
yeh gg
Anyone wanna play in like 15 min
gg @gloomy estuary
hehe
Lemme turn my stuff on
Join a public game and send a link
Till i get my stuff together
well
starts in 17 minutes
Has it started already ?
Yeah but do join
Im in
Great!
lol
A whole maze
I got no idea what to do
Same
Ahh I see done this before?
lol I can see that from the nmap scan
Wait till you actually go to the ports
okayy
hahah not hogwarts anything but that xD
Ikr
you guys got anything?
lol I'm supposed to be sleeping....thought of having some fun instead only to experience this
I heard the priv esc on it is pretty easy
But actually getting a foothold on the box ..
Its beyond me
Ok
https://tryhackme.com/games/koth/join/22fbbc300b22e5a56fca1bda
@sudden tendon
Is there another game of KOTH?
no dude why?
I missed
oh okay ok
oh okay ok
@ms.geeky#2472 u having fun ?
Anyone up for a game ?
Anyone wanna come?
@haughty tendon good luck 🙂
Anyone wanna come?
@idle siren did somebody straight up kill ssh ?
U are in same room with me?
How else would i know that 🙂
I didnt kill it. I just tried to connect to it and then moved to sql
Oh so the port changed huh
Nah nvm its still 22
I didnt kill it. I just tried to connect to it and then moved to sql
@idle siren u still playing?
yeah, playing with the ssh
Dm me if you want a hint
okay.
20 mins
can i make a video of solving a koth
You stream and post writeups on KoTH machines @weary axle
This extends to making a video (:
what?
You stream and post writeups on KoTH machines @weary axle
@brazen cloud
idk how to make a writup
cant i make a video like start a private game and play
Anyone up for a game
shadowgag
starts in 2m
23m
do you guys think it would be against the rules to change an id_rsa key in KOTH?
10min...
@tall spoke no, it's allowed 🙂
@tall spoke dont remove files dont shutdown services ... change password (rsa keys) and change service ports are allowed ...
"removing files" is a bit of a vague one tbh, you can remove files and it still be perfectly fine rules wise
starts in 19 minutes from now
16 mins
can we move files?
15 mins left
"removing files" is a bit of a vague one tbh, you can remove files and it still be perfectly fine rules wise
@NinjaJc01#7746 ok removing flags 😂
Anyone wanna play
yo
"removing files" is a bit of a vague one tbh, you can remove files and it still be perfectly fine rules wise
@NinjaJc01#7746 ok removing flags 😂
Anyone?
.
Halfway playing a match now while at work. If you just need a player in the room so you can practice, I've got you.
Nah thx though
No worries
@harsh obsidian did you move on to a different game?
@harsh obsidian did you move on to a different game?
@hot bloom Ish. i'm at work right now and got pulled in to meetings and whatnot
I couldn't find them all lol
I was trying to figure out how to mess with ioctl flags without chattr
Since it wasn't on the box
You can always pull across a static binary with a different name
I think you can also do it with python
Also, was distracted by the news
Biden won
I think you can also do it with python
@quiet schooner Yeah, found a couple options
@quiet schooner Yeah, found a couple options
@hot bloom can you PM some of those resources so i can learn as well, please?
Sure
24 mins
anyone?
22 mins
6 mins
I have a question, if default user have sudo perms. Is it by the rules that i edit sudoers file and remove user from sudoers ?
no
you can
remove the user/users
from sudoers
@opal pond lol you ofcourse are a good in this than me lol
I tried so hard to retain king lmao
thank you
gg
starts in 1 min
I’ll be playing in 15 mins
great!will be waiting to have fun w/ you
Okay!I will join....thanks
Okay!I will join....thanks
@ms.geeky#2472 want me to send you the link ?
that will be very helpful
joined!
24 mins
Anyone wanna play
yep
Starts in 14 min
Mins
What’s a Koth?
king of the hill lol
you hack a machine
capture flags
and
escalate your privileges
and
try to retain your name in the king.txt file
1 machine for all or 1 for each
right
umm
@dull geode where did u go
2 mins
Starts in 5 mins
Https://tryhackme.com/games/koth/13099
@ion.know#3578 Hey i think someone removed king.txt in my game ?!
Its a public game btw
Its back again nvm
Can you do that ? Deleting the file than creating it again to put ur name in it ?
It isn't supposed to be deleted.
I think someone did tho
Pretty sure it's in the rules.
When on earth will players start reading rules. URGHHHHH
I even did find / -name king.txt
As roo
Root*
And can someone tell me how many flags are on Tyler ?
They must've made a loop to delete and add new, but well, it will result in service not picking up the file and hence they will lose some points.
And can someone tell me how many flags are on Tyler ?
@opal pond Hover near the flag submission box, the flag icon should tell you how many are there.
The games finished can you tell ? Im tryna see if there is a bug
There are only 2.
Cuz sometimes when i quickly double click the submit button for the flags I believe sometimes it counts 2 flags
Not sure, but my notes says so.
There are only 2.
@Mr.Holmes#0001 i found 5 thi :/
I believe there is only 5
But i somehow submitted 6
Cuz sometimes when i quickly double click the submit button for the flags I believe sometimes it counts 2 flags
@ion.know#3578 .
That's a known bug.
That's a known bug.
@Mr.Holmes#0001 when will u add hogwarts to ur github :c that room confuses the f outta me
When new machine is released.
Which I assume u can’t say when that happens ?
🤷♂️ :)
Can you tell me if in the right direction? A little hint maybe ? Cuz i think i found some stuff
I’ll say one word and you tell me if im in right direction?
Maybe(?)
I'll delete it if it is.
Well, that's one way to go
that one is pretty straight forward.
Is it like the 3 thingys ?
Um, the 3 thingys are another way to go, these are not connected
Am I missing something thats right under my nose ?
👀
Just look carefully. at everything.
BTW have you rooted it?
Nah not even close its beyond me
I just found this
These
I think ik some stuff bout the thing you deleted
Some ideas
But the others nah
Well, you can try again, check services on every port, there are some ports you might have missed, don't stick to one port. You can get shell from every foothold in less than 3 minutes, so if it takes you more than 10 minutes on any port, you are in the wrong direction.
Yeah most of the stuff changes everytime
Yea pls vote if ur on
aight
Cuz i see him on the box assuming he’s still trying
I checked 3 methods, all are dead
2 were suid
Did u vote or no ??
Oh thats u on the box ?
um no
Yea probably everyone left anyways
my tmux was on, smh.
Someone got kicked out cuz of chees starts and since i changed the ssh port they gave up
Ggs anyway
GG :)
What
https://tryhackme.com/games/koth/join/8686727c5df6806505487722 - 15 mins if anyone is interested
Sure. Did you start one or should I?
Teach you what?
I haven't done that one
Someone already started a game..
16
@hot bloom did u remove chattr?
Anyone wanna play ?
now?
anyone
anyone
@weary axle u up ?
yes cmon
let me start my machine
1 min
see
adjust your Firefox settings
All I know that it has rabbit holes 😄
and it is something idk
Isn't that what we call spoiling a box?
Thanks 😊
can i make a walkthrough?
Just hint would be fine but no need to explain the whole method
i always have habbit of explaining
Just hint would be fine but no need to explain the whole method
That was for talking here
And for walkthrough @stiff egret you ok with someone making public writeup for hogwarts?
You can make notes for yourself, were you asking to make it for someone else or just yourself?
like a post
And for walkthrough @stiff egret you ok with someone making public writeup for hogwarts?
i is asking.....................can i make a video rather??
cause i didnt find any
im bad at writing
There is already one writeup of Hogwarts public,
Also, I have no problem with anyone making writeups for it, but I'd suggest only show one method to root the box, not all of them.
can i mke a video?
@weary axle Sure :)
There is already one writeup of Hogwarts public,
@Mr.Holmes#0001 where ?
Didn’t u say you wouldn’t release write ups till the next box came out ?!
:google:
@Mr.Holmes#0001 nothing
lol holmes why reset?
aah I know
bruh
I changed all the passwords then someone reset the machine
then you became the king
I got in from that, tho pretty nice patches.
Reset is a necessary evil.
lol someone just removed simple commands
huh? I am in the box, lemme check
I can't do locate lmao
aah
https://github.com/holmes-py/koth-healthcheck
If you have root shell, you can use this to check if someone broke basic rules.
hey after this is over just tell me how did you remove the write permissions and chmod permissions
pls
man chmod
and what was that patch from which you broke in
@dull geode Uh, DM, It'll be a spoiler here.
Tho I'd say just look for yourself, you can find it. If I tell you then it won't be fun.
Might as well read writeups of all machines.
Starts in 6 mins
OMG holmes what the heck
how did you change the permissions for not changing any permissions lmao
OK I give up
I literally tried 15 things to change the permissions now you removed the reading perms too
yeh sorry I saw wrong lol
Join in if anyone wanna play.
🤔
ok gg holmes that was some nice game(definitely not nice of you😑)
GG :)
Hello thanks to whoever invited me to this server. Someone wants to play a 1v1 just for fun?
find me in voice
starts in 8 minutes
gg
Wow, that was a really fun game
hey
anyonw will play?
me
lets play again
depends
i m tired
just came from downstairs
but if machine is tough i will go
cause im sleepy
o man production
okk no prob
Anyone up for a game
I can play once i complete brute it
yeah
Aight lemme start up my stuff
I can play once i complete brute it
@frank oracle which part of it are at rb
Rn
I um, priv esc
That shouldn’t take long then
Depends on how fast linpeas work
You could priv esc without linpeas
Then run linpeas
Yeah
I can, but i choose not to
Ok u do u
I'll let ya know


