#koth

1 messages · Page 52 of 1

weary axle
#

says 4 flags. i get 2

opal pond
weary axle
#

where r they hidden

opal pond
#

Starts in 16 mins

#

where r they hidden
@weary axle which room

weary axle
#

any

#

production currently

#

im root

opal pond
#

Use find

#

You’ll prolly get an error

#

Right V

#

?

#

On that room

weary axle
#

what?

opal pond
#

Can you use find

weary axle
#

i cant find more than 2

opal pond
#

Or so u get permission denied

weary axle
#

no

#

can u tell wher can i find dlags

#

flags

#

unable to find

opal pond
#

For whatever reason i got an error everytime i ran find and i had to fix it

#

Anyways

#

U can find 3 flags using fins

#

Find

weary axle
#

yea

#

in which 2 r same

opal pond
#

There are 2 more I believe

#

Search in users home dirs

weary axle
#

i got 1 more

opal pond
#

I deleted since it was a spoil

#

Thats all i can remember rn

weary axle
#

@sacred comet

#

u ther>

opal pond
frank oracle
#

Am done, ill be joining

opal pond
#

2 mins

frank oracle
#

Am here , lemme read rules real quick

weary axle
#

@sacred comet

#

where u found 4th flag pls tell

sacred comet
#

4th?

#

find / -name flag.txt 2>>/dev/null

weary axle
#

only 3

#

i get only 3

#

how 4

#

@stiff egret

#

can i ask u?

#

can u tell where is the 4th flag for productio

stiff egret
#

Um that's not something me or anyone else would tell, they are hidden and you have to find them, it only fun that way.

weary axle
#

im tired findind...played production for 10+ times

#

still coudnt find 4th

frank oracle
#

Um when you get root, try find / "flag*.txt" 2>/dev/null

#

Boy i dont like this machine

#

🤣

opal pond
#

U playing hackers ?

weary axle
#

no

#

pproduction

opal pond
#

No u mate
@frank oracle

#

Not*

weary axle
#

2 wins in a row wow

timber pelican
opal pond
#

My game finishes in 27 i’ll join then if u still playing

timber pelican
#

Aight then I'll delay it

#

I invalidated the link. 30 mins until start ok for u?

frank oracle
#

Did u patched the ||backdoor||? @opal pond

opal pond
#

Did u patched the ||backdoor||? @opal pond
@frank oracle nah

#

Didn’t patch anything tbh

#

Well except for the way i got in

#

I invalidated the link. 30 mins until start ok for u?
@timber pelican yes

timber pelican
opal pond
#

If anyones playing hackers with me check robots.txt for a hint

timber pelican
opal pond
#

Alright

frank oracle
#

Dang

#

I botched this one huh

opal pond
#

Did u get in via production

#

Or was that someone else

frank oracle
#

production, i was trying through g something guy but hydra was taking too long

opal pond
#

Ggs anyways

weary axle
#

BRO CAN U TELL WHERE TO ||FIND 4 FLAGS||

#

||I FOUND ONLY 3||

#

||find / -name flag.txt 2>>/dev/null|| this shows 3.....the 4th one is missing

opal pond
#

Maybe its not flag.txt ?

weary axle
#

what can it be

#

iwant to ask where can i find?

opal pond
#

Hidden files ?

weary axle
#

i was really upset

#

10+ times stil couldnt find

opal pond
#

Btw are u sure there are 4 flags ?

weary axle
#

when u hover above it it says 4 right

#

the submission area

#

of flafs

opal pond
#

Ok

weary axle
#

can u tell where are all 4?

#

with loc

#

i know 3 but still pls

opal pond
#

Starts in 10

#

i know 3 but still pls
@weary axle checking my note i only have 3 flags cant help there sorry

weary axle
#

anyone else pls

#

where can i find the 4th one

#

pls tell

dull geode
#

!dark

pearl gladeBOT
#
DarkStar7471
*ahem* Can help you?
dull geode
#

!dark

pearl gladeBOT
#
DarkStar7471
Peace, dudes.
sacred comet
opal pond
sacred comet
#

😐

teal root
#

lmao

teal root
#

can anyone kill the strace command for me, I seem to stuck here 😦

sacred comet
#

everything patched

#

i cant get the shellll']

teal root
#

yes ik, I just run command for fun and I got stucked f

#

I patched it

sacred comet
#

😦

opal pond
#

Someone just straight up deleted the whole code for port 3000 lol

#

Welp the disabled telnet too

teal root
#

I straight up lock myself out by running random command 😦

frank oracle
#

I really need to know how to patch stuff

sacred comet
opal pond
dull geode
#

24 mins

north stag
#

can someone open a "hackers" room so i can test my aproach (I was playing that room but the game ended while I was testing it 😦 )

terse willow
#

James was kind enough to release the box standalone

north stag
#

ohhhh!!!!!!!!!!!!!!!

#

THANKS!

terse willow
#

Yw

dull geode
#

how do we get permissions for using chattr in linux

#

cause

sacred comet
#

sed

#

😐

dull geode
#

I even being root doesn't give the permissions for chattr🙁🙁

#

hey I just wanna say to those people who are in the room with me pls don't reset just because you can't find passwords that's just so much rude and coward of you to do that

#

pls

#

it hurts🙁

#

and yeh is it allowed to change the flags??(I hope not)🙂🙂

stiff egret
#

oh god when will people start reading rules.

#

No, you cannot change flags. Also give the rules a read?

#

Maybe this blog as well?

north stag
livid ginkgo
#

lol whoever is on panda right now good ljob killing literally everything because you cant get king

#

n0beard

#

@harsh obsidian this you?

#

everything is shut down and secretary isnt on the boxc

harsh obsidian
#

I haven't killed anything

livid ginkgo
#

i cant get onto ssh or wordpress

harsh obsidian
#

But ssh is no longer available. did you switch the port?

livid ginkgo
#

i didnt

harsh obsidian
#

oh damn, reset?

livid ginkgo
#

im now kicked off the box

#

ssh is completely down

#

same as port 80

#

ill find another way in

harsh obsidian
#

that's odd. i voted reset if it's kicked us both out and off

opal pond
#

Three more players

#

Starts in 14 mins

#

4 more players*

sacred comet
#

-_-

weary axle
#

i watching ipl

#

wait why did i join the game

opal pond
#

@stiff egret help lol

stiff egret
#

LoL why do you need help with, I can see your name getting in the file every once in a while

#

just try hard whatever you are doing

opal pond
#

Where should i put the binary I downloaded for busybox to use it

stiff egret
#

Anywhere (?)

opal pond
#

Nah i meant with this

sacred comet
#

/tmp ?

#

or /usr/bin

opal pond
#

I put it in bin didn’t find tge applet ?

#

The*

stiff egret
#

wget <LINK> -O /tmp/secret; chmod +x /tmp/secret;
Run using /tmp/./secret

#

Also you should do more boxes that involve linux, to get a hang of this.

#

Why the reset lol.

#

SMH

crisp needle
#

Anyone keen for a game of KOTH in roughy 2 hours?

opal pond
#

@Mr.Holmes#0001 😒

#

Why 😦

stiff egret
#

what?

opal pond
#

Urandom

stiff egret
#

I didn't do that, lol, I am not even active in machine

opal pond
#

Only u and me where in the box tho

stiff egret
#

NO, I can see 2 other IPs inside the box

opal pond
#

Im pretty sure they’re not root thi

weary axle
#

woah today is ipl final

#

and i didnt know

opal pond
#

Its aight imma come back in again ig lol

sacred comet
#

wew

stiff egret
#

OH I see that person running urandom

#

Want me to kill it?

sacred comet
#

kill process_id

opal pond
#

Idk its up to u the games already finished ggs 🙂

weary axle
#

what is that?

sacred comet
#

flag

#

0day wale room ka 😄

stiff egret
#

Dont do that?

weary axle
#

wait homes u didnt search any flag

sacred comet
#

lets do a KOTH?

stiff egret
#

Nope, I don't need to, Going for king is faster way to win.

weary axle
#

watching ipl?

sacred comet
#

watching ipl?
@weary axle dek raha tha 90% use ho gaya ab 😄

weary axle
#

wait why does my hydra take hell time to bruteforce?

opal pond
#

Nope, I don't need to, Going for king is faster way to win.
@Mr.Holmes#0001 > wget <LINK> -O /tmp/secret; chmod +x /tmp/secret;
Run using /tmp/./secret
@Mr.Holmes#0001 should i run the binary itself or with busybox ?

weary axle
#

took 30+ min once still didnt complete

opal pond
#

wait why does my hydra take hell time to bruteforce?
@weary axle cuz the passwords changed

sacred comet
#

wait why does my hydra take hell time to bruteforce?
@weary axle -t 64

#

took 30+ min once still didnt complete
@weary axle Threads badhake k use kiya karo

#

@weary axle cuz the passwords changed
@opal pond yeah thats the reason

#

-_-

#

service ssh stop 😦

opal pond
#

Busybox f’ed me on this one

#

Ggs

stiff egret
#

You don't need busybox, just upload individual chattr binary 🤷‍♂️

opal pond
#

You don't need busybox, just upload individual chattr binary 🤷‍♂️
@Mr.Holmes#0001 downloaded for the link in your blog ?

quiet schooner
#

@sacred comet Please keep all conversation in English only

sacred comet
#

-_- ok

weary axle
#

@weary axle cuz the passwords changed
@opal pond ikt

#

@weary axle -t 64
@sacred comet i used it

#

@weary axle Threads badhake k use kiya karo
@sacred comet ok

sacred comet
#

i am not a slave of you so i will use whatever i want

#

english hindi whatever

opal pond
#

Bruh :/

sacred comet
#

or make a new serve'r

weary axle
#

shd make a language channel

#

lol

mellow bough
#

Enjoy the ban for the casual racism in hindi there bud

gusty cradle
dull geode
#

lmao

#

these people have a nice sense of humor😂😂

#

or make a new serve'r
@Mr . R c#4194 .

#

17 mins

dull geode
#

hi @gloomy estuary

gloomy estuary
#

hi

#

is king

#

@dull geode tell me what you did at king.txt

dull geode
#

lol

#

after the room

#

OK?

gloomy estuary
#

ok

dull geode
#

yeh sure

#

why not

gloomy estuary
#

if you can't find another flag, i already won

dull geode
#

nice

#

well

#

11 mins are enough to reverse the game bruh

#

gg

gloomy estuary
#

it is not enough

#

I have 34 minutes of king

dull geode
#

nice

#

lol

#

I was away

gloomy estuary
#

good game

dull geode
#

yeh

#

gg

#

aah you left the machine?

#

gg bruh @gloomy estuary
yeh you were right ya won

gloomy estuary
#

lol, now tell me what you did on king.txt

fair adder
terse willow
#

What

#

In God's name

#

Is that 😆

dusty canyon
#

God

gloomy estuary
#

@spring hamlet ?

weary axle
#

Enjoy the ban for the casual racism in hindi there bud
@mellow bough wait how racism?

quiet schooner
#

Wasn't you, don't worry. It was the person who was banned. @weary axle

weary axle
#

but why banned him?

#

it was supposed to be a warn imo

#

cause u cant ban someone who is speaking in their language...for 3, 4, msgs

quiet schooner
#

The racist messages were deleted.

weary axle
#

what were his racist msgs?||angrez?||

#

asking dont ban me

quiet schooner
#

If you're their friend and they're trying to appeal, they need to email jon@tryhackme.com

weary axle
#

im nor his frnds nor i know him

quiet schooner
#

We're not likely to share their racist messages again, seeing as they were racist.

weary axle
#

ook

#

sry

nova tide
#

HACKERC aren't we the only two people in the game? You don't really have to reset it though 🤷‍♂️

pearl crane
#

@nova tide pls tell me hackerc isnt that good, i dont even know what im going to use to attack the computer, i thought there would be more than 2 people. i was hopeing to defend

#

hoping*

nova tide
#

idk he didn't really did anything in game, he just reset once and didn't even try to get king and joined next game

pearl crane
#

do you have any advice?

nova tide
#

read the blog post?

#

and you are good to go.

pearl crane
#

k

fair adder
#

good morning. Anyone willing to koth with me?

weary axle
#

me fine

north stag
#

25 min

weary axle
#

@fair adder

fair adder
#

thanks

opal pond
#

Anyone wanna olay

#

Play*

dull geode
#

yeh wait

north stag
#

@dull geode how the hell did you exploit this fckng machineeeee

#

ughhh

dull geode
#

lol

north stag
#

im so lost

dull geode
#

well

#

I'll tellya

north stag
#

im in the smb

dull geode
#

but that zovatuuuuu

north stag
#

after 🙂

dull geode
#

changed the freaking flags

north stag
#

man, i dont eve care

dull geode
#

he the hell

north stag
#

just wanna learn this thing

dull geode
#

changed the freaking flags after submitting them

north stag
#

thats against the rules btw

dull geode
#

pls see

#

yeh that's what I'm saying

north stag
#

:/

opal pond
#

Yall in a game ?

north stag
#

yup

dull geode
#

pls see after this koth admins

north stag
#

is this machine avaliable off koth?

opal pond
#

is this machine avaliable off koth?
@north stag which one

dull geode
#

offline

hushed nebula
#

is there a way i can watch you guys do stuff cause like im new and can barely use friggen nmap lmao

north stag
#

offline
@dull geode .

opal pond
#

No

north stag
#

shttt

opal pond
#

is there a way i can watch you guys do stuff cause like im new and can barely use friggen nmap lmao
@hushed nebula Youtube

hushed nebula
#

ah yes ok InDeEd

opal pond
#

John hammond and optional

dull geode
#

is there any Koth admins?

#

here rn

north stag
#

@dull geode after the koth ends can you join vc?

dull geode
#

umm

#

IDK

north stag
#

😦

winged charm
#

@dull geode yes, why

dull geode
#

someone changed the flags in the offline machine after submitting them

winged charm
#

What’s the game id

dull geode
#

13229

#

his name is

#

zovuutavuu

winged charm
#

do you have any evidence that the flags were changed

dull geode
#

umm like how?

winged charm
#

like screenshots, anything

#

if the games over there’s not a lot we can do

dull geode
#

OK

#

nvm

#

thanks

winged charm
#

If it happens again just let us know with some evidence and we can take care of it

dull geode
#

OK

#

sure

weary axle
#

anyone koth/

fair adder
#

3min

weary axle
#

k th

#

wow prism is also there means i will lose

#

why is ssh port closed?

#

why u closed ssh port is it allowed?

#

is changing ssh allowed?

north stag
#

mods ...

weary axle
#

Not shown: 994 closed ports
PORT STATE SERVICE
21/tcp open ftp
80/tcp open http
3306/tcp open mysql
8009/tcp open ajp13
8080/tcp open http-proxy
9999/tcp open abyss

quiet schooner
#

mods ...
@north stag Not mods, koth-staff.

winged charm
#

game id

weary axle
#

of who?

winged charm
#

Are you guys playing the game or separate?

weary axle
#

its seperat

#

i m playing shrek

#

he is production ig

winged charm
#

send me yours as well

weary axle
#

how?

#

@winged charm

fair adder
#

why u closed ssh port is it allowed?
@weary axle I just changed the port lol

weary axle
#

and how u do that?

fair adder
#

'-' /etc/ssh/sshd_config?

harsh obsidian
#

and how u do that?
@weary axle google

fair adder
#

@weary axle google
@harsh obsidian xD

weary axle
#

i m asking a dumb qs

#

which port

#

@fair adder

fair adder
#

rustscan -a $IP

#

lol

winged charm
#

Spectator link

fair adder
#

Are you lazy?

weary axle
#

actually

#

just had dinner

stiff egret
#

mods ...
@north stag Pretty sure you are typing it wrong

#

IIRC, user is skidy

weary axle
stiff egret
#

not skiddy

harsh obsidian
#

which port
@weary axle Rerun nmap and you'll see

weary axle
#

didnt

#

still didnt

fair adder
harsh obsidian
#

are you scanning top 1000 or all ports?

#

didnt
@weary axle have you done the nmap room?

winged charm
#

!docs koth

pearl gladeBOT
winged charm
tepid hornet
#

Something similar is already pinned @winged charm

fair adder
#

Someone deleted root.txt and it wasn't me -;

weary axle
#

i quit already

brazen cloud
#

That's out of date now (or the docs.tryhackme.com as a whole is anyway) @tepid hornet good idea, I'll unpin that

fair adder
#

GG @weary axle

weary axle
#

i didnt play lol

fair adder
#

Hello, i'm new here !

harsh obsidian
#

Hello, i'm new here !
@fair adder Welcome!

fair adder
#

Thanks !

opal pond
#

Anyone up for a game

nova tide
#

IIRC, user is skidy
@stiff egret he corrected it in next line

stiff egret
#

Yeah, Saw it

nova tide
#

someone edited the flag so now you have to ban em

hot bloom
#

@stiff egret Quite a game! 🙂

stiff egret
#

sure was

hot bloom
#

20 king changes lol

nova tide
#

Room Tester 👀

sly turret
#

@stiff egret oh nooo 😄

#

oh its windows

stiff egret
#

I left :) no windows

sly turret
#

-.-

#

me 2

#

i will start another one

opal pond
#

i will start another one
@sly turret when does it start

sly turret
#

5 in

#

min

#

3*

opal pond
#

Can’t make it :c

sly turret
#

😦 i have to go to work in 1 h so cant wait but we can play tomorrow if you want

opal pond
#

Its ok,yea let’s do it tomorrow GL

sly turret
#

@stiff egret go crazy if you want 😄 i try my best

stiff egret
#

ayy, :)

unborn wigeon
#

@tender salmon

#

am fzin

#

@spring hamlet

spring hamlet
#

?

unborn wigeon
#

You not is this player of koth?

sly turret
#

did you create a while loop with chattr ?

unborn wigeon
#

i no

sly turret
#

no i mean holmes

spring hamlet
#

Honestly forgot I was even in it

#

also never done this KOTH

sly turret
#

@stiff egret what did you do 😄 i am root but i cant remove chattr i from the file ...

stiff egret
#

I looped it?

sly turret
#

i have my own chattr on the boox but it wont remove

#

aaa ok

#

hmm

#

ok i dont know how to find the loop and kill it so i think its game over

short tusk
#

!rule 9

pearl gladeBOT
#

Rule 9: No discussion of illegal/unethical topics or actions.

terse willow
#

@fair adder Nope

#

No illegal activity please

#

-warn @fair adder Rule 9 -- asking for help hacking a minecraft server

sour vectorBOT
#

⚠ Warned bang bang bang bang#2181

sly turret
#

@stiff egret hmm ok can you give me a hint how i can find the loop and kill it ?

#

for the next game 😄

stiff egret
#

You can't, all you can do is make another loop faster than the one I am using

sly turret
#

aa ok

glass bane
#

Hello

hardy jungle
#

warnings

sour vectorBOT
#
Warnings - User : 106802244329955328

Total : 0

No Warnings

hardy jungle
#

Oh good

winged charm
#

Interesting

#

-warn @hardy jungle insubordination

sour vectorBOT
#

⚠ Warned 🅷🄴🆇🅲🄷🄰🄾🆂#1337

winged charm
#

@terse willow

#

I did a thing

hardy jungle
#

Oh

winged charm
#

muiri

hardy jungle
#

Erm

winged charm
#

muiri

hardy jungle
#

MUIR

sudden badge
winged charm
#

I did a thing

hardy jungle
#

MUIR BOT IS BROKEN

winged charm
#

@mellow bough I did a thing

#

please fix

short tusk
#

@terse willow

#

Fix

hardy jungle
#

MUIR CODE RED

barren oar
#

anyone played the "Hogwarts" room

unborn wigeon
#

hello

#

anyone played the "Hogwarts" room
@barren oar i

#

I am playing

barren oar
#

have you any progress with that

terse willow
#

That'll be in the console which I can't access

barren oar
#

That'll be in the console which I can't access
@terse willow what console...?

terse willow
#

The yagpdb console

#

I'm replying to all the pings

#

@winged charm try doing it now?

barren oar
#

I'm replying to all the pings
@terse willow ohh alright

spring hamlet
#

anyone played the "Hogwarts" room
@barren oar Yeah I got no where with it

barren oar
#

@barren oar Yeah I got no where with it
@spring hamlet same here bro

spring hamlet
#

Took me til like half way through to even realise that port 22 wasn't SSH (my fault for not reading nmap) and I couldn't access the website at all

fair adder
#

The SSH port was dynamic and port 22 is bait

spring hamlet
#

oh fair

winged charm
#

-mute @hardy jungle

sour vectorBOT
#

Unable to run the command: The Mute command requires the Kick Members permission in this channel or additional roles set up by admins, you don't have it. (if you do contact bot support)

winged charm
#

-warn @hardy jungle

sour vectorBOT
#
Warn <User:Mention/ID> <Reason:Text>

Invalid arguments provided: Not enough arguments passed

winged charm
#

-warn @hardy jungle being wide

sour vectorBOT
#

Unable to run the command: The Warn command requires the Manage Messages permission in this channel or additional roles set up by admins, you don't have it. (if you do contact bot support)

winged charm
#

@terse willow you take away the manage perms though

terse willow
#

Yeah

#

Need to speak to Dark about which of those things is more important

stiff egret
#

Oh god what did you do Cry, that made them took our manage perms away?

winged charm
#

hackers gotta hack ya know

gloomy estuary
hot bloom
harsh obsidian
hot bloom
#

Haha @harsh obsidian , I'm kinda working too.. we'll see how it goes

harsh obsidian
#

I kind of hope it's Hogwarts because I haven't done that box yet. And with work, I can start a bit of enumeration without feeling like i need to dedicate myself to the box.

hot bloom
#

Hogwarts would be cool, I had it once, but I didn't get far

#

How often do new boxes get rotated in/out?

harsh obsidian
#

They show up periodically; i haven't seen any rotate out yet.

hot bloom
#

Ugh, that windows box

harsh obsidian
#

Yeah, it was a pain in the ass to figure out. it took me a good three or four rounds before i got it. but once you have the method as root, it's insanely easy to repeat

fair adder
#

anyone wanna do a koth?

cerulean maple
#

Yes

fair adder
#

join up koth vc

#

only if ya want

hot bloom
#

TFW finally figure out hogwarts and someone changed the password already 😦

quiet schooner
#

That's ok, the box changes every time

hot bloom
#

Well, the current one doesn't work lol

#

¯_(ツ)_/¯

hot bloom
#

Lame

winter mauve
#

anyone for koth ?

weary axle
#

im fine

#

cam cycling 4 5 kms.....and frnds tyre got punchured

gaunt oar
#

.

weary axle
#

anyone for koth

fair adder
#

good morning @here

#

What is allowed in koth and what not? Is changing passwords, deleting keys, changing permissons on binary allowed or not?

#

firewall ,changing flags and disable services is a no-go, right?

stiff egret
#

Try reading rules on the koth homepage, and/or maybe give the pins on this channel a look. @fair adder

fair adder
#

@stiff egret I did this before asking the question 🙂

lavish elm
#

anyone koth?

#

@weary axle

stiff egret
#

@stiff egret I did this before asking the question 🙂
@fair adder Everything you asked about is either in the blog or on the rules section of koth page, I don't understand why you'll ask the same thing if it is already there in the site/blog.

opal pond
#

anyone koth?
@lavish elm u still playing?

fair adder
#

@stiff egret

#

ok, forget my question.

weary axle
#

yea im playing

#

@lavish elm

#

send link

#

@lavish elm
u there?

#

@opal pond

#

wanna play

opal pond
#

wanna play
@weary axle gimme a sec to boot up my stuff

#

Send links

weary axle
#

send anyone

#

anymore people?

teal root
#

me

weary axle
#

5 min game starting

#

sending link

opal pond
#

Im in a game

weary axle
#

which can u send me link

opal pond
weary axle
#

@opal pond

#

kk

#

clear

weary axle
#

what ports can i change ssh to?

#

why is the machine going offline so many times

opal pond
#

Nothings wrong with the machine

#

Its not going offline ?!

#

me
@teal root u still playing?

weary axle
#

it went so many time

#

and pls teach me how to patch vulns

#

u can dm me

#

@opal pond

opal pond
#

and pls teach me how to patch vulns
@weary axle each vuln obviously has its own patch but for koth I mostly patch suids and capabilities, edit sudoers and etc to prevent privilege escalation

weary axle
#

and how?

#

and is there a way to overcome those?

opal pond
#

Well to change suids and capabilities u obviously gotta be root so if ur not already no

#

Same goes for sudoers file

weary axle
#

i was root then machine went offline then i lost connection 3 4 times

opal pond
#

Machine never went offline

#

Its probably your internet

weary axle
#

and can u tell me what are the things except chattr and onemore was there

#

na it is strong

#

vpn also good

#

connected

#

did reconnect again and again

opal pond
#

Well the machine never went offline for me

weary axle
#

clobber and chattr

#

can u tell me why cant i access files even when i m root?

#

cause chattr -i king.txt didnt do

opal pond
#

Well on this box if u use chattr it’ll close ur ssh or any other connection since its a cheese start

#

Strat *

#

So thats probably why u got disconnected

#

The machine didn’t went offline

weary axle
#

wait meaning?

#

how will it go offline?

#

why?

opal pond
#

It won’t go offline

#

If u use chattr

#

It will close ur ssh connection for example

weary axle
#

ok i was disconnected

#

but why?

#

yea it did

#

like ssh terminal hanged

opal pond
#

Cuz they don’t want u to use it since its a cheese strat

#

On that box specifically

weary axle
#

means i shd use chattr

#

so whats r the other commands i can use?

opal pond
#

I used it but since I already had a backdoor I gained a foothold again

weary axle
#

wait how did u do from a backdoor?

#

can u explain me in dm it would br better to remeber

opal pond
#

There are tons of easy backdoors to implement on koth boxes i’ll leave that to u to figure out 😉

weary axle
#

which room in thm would u suggest me to take for tthat?

stiff egret
#

The box is made such that if you use chattr, then it will kick you out.

#

That's what was happening to you apparently

cerulean maple
#

Are you guys talking about Fortune ?

weary axle
#

yes just got to know

#

production

opal pond
#

Are you guys talking about Fortune ?
@cerulean maple production

cerulean maple
#

Oh

opal pond
#

Well on this box if u use chattr it’ll close ur ssh or any other connection since its a cheese start
@ion.know#3578 .

cerulean maple
#

But when I put my chattr binary it still didn't worked gave me some symlink error

weary axle
#

wait but how and what should i search for backdooring cause i dont know much in it and happy to learn

opal pond
#

wait but how and what should i search for backdooring cause i dont know much in it and happy to learn
@weary axle for example the easiest way is to add a user for yourself with privileges

weary axle
#

idk how

opal pond
#

Look it up

stiff egret
#

But when I put my chattr binary it still didn't worked gave me some symlink error
@cerulean maple google around for static binaries, you must've uploaded a dynamic binary

weary axle
#

im like new to this field and want to learn in it

#

so would love to get some one helping 🙂

opal pond
#

@cerulean maple google around for static binaries, you must've uploaded a dynamic binary
@Mr.Holmes#0001 hey if someone uses a loop is there anyway for me to overcome that ? Like if it sleeps every 0.1 for example a chattr loop or echo loop

#

Like can i kill it in anyways ?

stiff egret
#

You can't kill the loop, because it's hard to find the pid of it, since in all listings it'll show up as bash.

#

So/but you can error it out

opal pond
#

Does that kill it ?

stiff egret
#

For example, say someone is running the loop using printf, then you know the printf is a part of it, if you remove printf, it'll error out

cerulean maple
#

But can find the process in /proc/pts/pts- number to kill that process ?

#

we*

opal pond
#

That’ll kill they’re whole shell I believe

cerulean maple
#

Then there is no way stop other users scripts if we do the same it would just keep writing both user's name and none of them would be getting points xD

stiff egret
#
  1. You can try to locate other users script, you locate it, you kill it.
  2. No, even if you both start the same script, it is highly unlikely that they'll be caught in deadlock, one of them would lock the file first and will win 🤷‍♂️
barren oar
#

Then there is no way stop other users scripts if we do the same it would just keep writing both user's name and none of them would be getting points xD
@cerulean maple ahahah like yesterday...xD

#
  1. You can try to locate other users script, you locate it, you kill it.
  2. No, even if you both start the same script, it is highly unlikely that they'll be caught in deadlock, one of them would lock the file first and will win 🤷‍♂️
    @stiff egret Really bro it did...😆
cerulean maple
#

@cerulean maple ahahah like yesterday...xD
@barren oar yes xDD

barren oar
#

actually you can find the loop and kill the whole process

stiff egret
#

finding is the hard part

barren oar
#

finding is the hard part
@stiff egret it's easy and you can try it

opal pond
#

Anyone wanna play

dull geode
#

That’ll kill they’re whole shell I believe
@opal pond can't we do that?

opal pond
#

Its allowed but shouldn’t be abused its not fun nor fair

weary axle
#

anyone ?

#

for>

#

koth?

stiff egret
#

@stiff egret it's easy and you can try it
@barren oar oh I meant it for as in general, those who know how to do it, can do it.

dull geode
#

Its allowed but shouldn’t be abused its not fun nor fair
@opal pond OK👍👍

barren oar
#

@barren oar oh I meant it for as in general, those who know how to do it, can do it.
@stiff egret hmm

fair adder
#

@barren oar nice loop - I cannot find it 🙂

barren oar
#

@barren oar nice loop - I cannot find it 🙂
@fair adder thanks for that

fair adder
#

that was fun

barren oar
#

that was fun
@fair adder indeed

weary axle
#

@barren oar what loop u using?

#

imagine someone typing manully for so long like up arrow enter

#

i did that for 1 hr

#

last game

#

sometime

barren oar
#

nice one by the way

#

@barren oar what loop u using?
@weary axle it was just a while loop with a twist

#

GG

weary axle
#

wait why did the ssh port close all of a sudden

#

oh game over

#

it was fun

barren oar
#

wait why did the ssh port close all of a sudden
@weary axle most fun i have till now playing KOTH

weary axle
#
/bin/sh: 1: cannot create ~/king.txt: Directory nonexistent
/bin/sh: 1: cannot create ~/king.txt~: Directory nonexistent
/bin/sh: 1: cannot create ~/king.txt~~: Directory nonexistent
/bin/sh: 1: cannot create ~/king.txt~~: Directory nonexistent
/bin/sh: 1: cannot create ~/king.txt: Directory nonexistent```
#

this error came and i was like what happend

#

then realized game over

#

i had like 4 shells open

#

3 ssh

#

1 root shell

#

like the #

barren oar
#

mine was 1 ssh and 1 root

fair adder
#

yeah that was funny

weary axle
#

and whenever u were closing ssh i could change passwd and easily go inside that was luck

#

i had changed the port of 3000 and i just forgotton it

#

just then u closed ssh and i was like done

#

gone

barren oar
#

yeah that was amazing one

weary axle
#

i remebered 65520

#

and tried and it worked

#

and got # agaon

#

and ssh 3 ports for cat king one for python run and one for writing

#

there were 3 king.txt

barren oar
#

i was trying 3000 but then it did not work then i just ran rustscan and 65520 pops up

weary axle
#

what while loop u used?

barren oar
#

there were 3 king.txt
@weary axle i know and i was doing king on all of those files

weary axle
#

same

#

when kiste was king for min i saw 2 king.txt when u came i saw 3

fair adder
#

I was searching for the loop alle the time

#

drove me crazy

barren oar
#

when kiste was king for min i saw 2 king.txt when u came i saw 3
@weary axle 😆

#

I was searching for the loop alle the time
@fair adder yeah that was neat

weary axle
#

bro y u used sleep? 0.1?

#

cant u do without it?

barren oar
#

bro y u used sleep? 0.1?
@weary axle i can but just to keep it clean

weary axle
#

i used like a simple while True

barren oar
#

are you guys stablizing your shell or not

fair adder
#

I did it and created a new user with uid=0

weary axle
#

||subprocess.call('echo {username} > king.txt', shell=True)||

#

I did it and created a new user with uid=0
@fair adder how?

fair adder
#

useradd -m <username>

#

passwd <username<

weary axle
#

but what will happen if u do that??

fair adder
#

and changed the uid and gid to 0

#

thats it

weary axle
#

username meaning what shd be there?

#

how to change uid and gid to 0

barren oar
#

ohh yeah can do that

fair adder
#

in my case it was

#

useradd -m kiste

barren oar
#

but i was using my script to stablize the shell

#

i also remove your acc from sudoers group by the way...:xD

weary axle
#

i never went to sudo

#

direct root

#

no user shells

fair adder
#

jepp via port 3000

weary axle
#

what r the user shell btw

#

i changed 3000 to a random number and forgot myself

#

then remebembered

#

65520

barren oar
#

i changed 3000 to a random number and forgot myself
@weary axle ahahahha

#

i just ran the rustscan again and find that one

weary axle
#

i was stuck 5 min on that

fair adder
#

I was wondering if it would be allowed to use hosts.deny

barren oar
#

i voted for the reset i was thinking that port is dead

weary axle
#

same when ssh was going so many times

#

u n me voted

#

other were doing nothin ig

fair adder
#

same when ssh was going so many times
@weary axle I killed your ssh and python sessions

weary axle
#

how?

harsh obsidian
#

lol

fair adder
#

I was root on the box

barren oar
#

@weary axle I killed your ssh and python sessions
@fair adder i know but i automated that with my script

weary axle
#

i was root all the time

barren oar
#

you can kill others tty sessions if you are root

weary axle
#

how?

fair adder
#

i did something like ps -ef | grep pts/1

#

kill the proccessnumber

weary axle
#

@barren oar come to dm

fair adder
#

cu

barren oar
#

i did something like ps -ef | grep pts/1
@fair adder you can do this >> ps aux | grep pts

weary axle
#

wanna play a koth sometime tom?

#

what time is at ur place @barren oar

barren oar
#

there were some other tricks but i was struggling with finding all the flags

#

wanna play a koth sometime tom?
@weary axle yup

weary axle
#

gn

#

im going to sleep

barren oar
#

gn

gn
@weary axle

weary axle
#

what time at ur place?

barren oar
#

its 9:40 pm

weary axle
#

ah k gn

barren oar
#

bye

opal pond
#

Anyone wanna play

harsh obsidian
#

Anyone wanna play
@opal pond i can do a light game. i'm only half paying attention to this meeting

opal pond
#

Send me a link for like 10 mins

#

In 10 mins*

harsh obsidian
#

k

opal pond
#

Im in a game that starts in 13 min want me to send the link ? > k
@harsh obsidian

barren oar
#

Im in a game that starts in 13 min want me to send the link ? > k
@harsh obsidian
@opal pond are you in game

opal pond
#

Yea

#

Starts in 7

barren oar
opal pond
#

Ok who evers doings that don’t u think that’s enough?

#

U did that to three of my shells

#

Bruh this was my 4th shell

#

How many times are u gonna kill my shells ?

fair adder
#

xD

#

GG

torpid fern
#

@opal pond picardia

fair adder
barren oar
#

@opal pond :picardia:
@torpid fern nice one

torpid fern
#

xD

barren oar
#

my freaking ssh dies

opal pond
#

U guys friends or something?

#

With the other lvl 1

barren oar
#

who

opal pond
#

Not u

#

Parism

#

xD
@torpid fern this guy

barren oar
#

ok

fair adder
#

Parism, wtf lol

opal pond
#

And the other lvl 1

#

Parism, wtf lol
@fair adder whatever the name was ion know

fair adder
#

The last game was not enough for me to play

#

So, now i will play

opal pond
#

Every time i got a the box all three of u were on it

#

🧐🤨

fair adder
#

lol

opal pond
#

Suspicious

torpid fern
#

tryhackme for me just and good koth

fair adder
#

Suspicious
@opal pond Yea i think so

#

Did you create a script to put your nick in king.txt?

opal pond
#

Yea a loop

#

Sounds like yall made a script to get root on the whole box lol :/

fair adder
#

lol I don't found that

torpid fern
#

I also created one in shell script

fair adder
#

Nice

opal pond
#

Eh off to studying again

cerulean maple
#

Why reset ??

#

Lol @fair adder if you can't get in you'll just reset the machine , smooth move

fair adder
#

'-'

#

Shutup

nova tide
#

@cerulean maple you creating a room?

cerulean maple
#

Yeah I'm planning to

#

Shutup
@fair adder XDDDD

fair adder
#

xD

nova tide
#

Yeah I'm planning to
@cerulean maple you got creators-lounge role before creating a room?

cerulean maple
#

I asked a mod that I'm working on a room so would it be a good room then he gave me permissions to talk over on that channel

fair adder
#

Why i cannot get root with SUID 😞

cerulean maple
#

Okay I have made it easy for you now xD

fair adder
#

More easy than sudo su?

#

xD

cerulean maple
#

I would just say that you can own the box with ashu 😄

fair adder
#

lol

#

Wtf delete the flags isn't against the rules?

cerulean maple
#

Who deleted flags ?

fair adder
#

Idk, someone

cerulean maple
#

Bro flags are there xD

fair adder
#

Are you sure?

cerulean maple
#

Yeah your right

#

someone deleted ashu 's flag

fair adder
#

Yea, i think so

cerulean maple
#

Emergency any KoTH staff? Someone is messing with the flags xD

#

@fair adder Did you got root ?

fair adder
#

No

#

I'm trying to get root

nova tide
#

Ashu had a flag?

#

wasn't that root,skidy and ftp and one more?

fair adder
cerulean maple
#

root didn't have a flag

fair adder
#

That's an older pic

cerulean maple
#

ashu , ftp , skidy and one more loaction was having flag( ^)

nova tide
#

welp

#

report it to koth@tryhackme.com with Game id

fair adder
#

Shit, i lost my shell xD

#

GG @cerulean maple

cerulean maple
#

GG bois

#

Shit, i lost my shell xD
@fair adder I didn't kill anyone's shell XD

fair adder
#

@fair adder I didn't kill anyone's shell XD
@cerulean maple lol xD

cerulean maple
#

Which machine you want to play if your up for KoTH ?

fair adder
#

The machine hackers is cool

cerulean maple
fair adder
#

Rules: the first one who get shell, lose

cerulean maple
#

XDDDDDDD

#

Okay !

unborn wigeon
#

@cerulean maple did you delete the flags? mainly from ashu /? who deleted ssh? that's against the rules!

#

Rules: the first one who get shell, lose
@fair adder huahahahahahhah

#

i go to lose

cerulean maple
#

What no I didn't delete those flags

#

I even made it easier for you guys

#

Why would I delete the flags

#

I gave ashu all the privileges so you all could get root xD

unborn wigeon
#

you delete yes!

cerulean maple
#

Wow !

barren oar
#

you delete yes!
@unborn wigeon are you really gonna do this man...

#

dont be buzz kill

unborn wigeon
#

aff

barren oar
#

my ssh was not working the whole time that does not mean that i blame him

cerulean maple
#

@unborn wigeon I wasn't the only one with root privleges there were 7 people

#

So don't just start pointing fingers at someone

barren oar
#

you can report the game if you want

unborn wigeon
#

someone removed the ssh, but it wasn't me, i just took root at the end, i would be 2nd if the flags were not deleted; -;

barren oar
#

really

#

there are three routes to get the machine ssh is one of them

cerulean maple
#

@unborn wigeon Even ssh was failing you could have found the other way also it is not against the rules to patch ssh

barren oar
#

someone removed the ssh, but it wasn't me, i just took root at the end, i would be 2nd if the flags were not deleted; -;
@unborn wigeon did you find other 3 flags

quiet schooner
#

It's against the rules to close ssh, typically

#

Seeing as there are other ways to patch it

barren oar
#

you can change the port or play with creds

fair adder
#

Delete ssh keys is against the rules?

barren oar
#

deleting it is against the rules

opal pond
#

Delete ssh keys is against the rules?
@fair adder i don’t think so

fair adder
#

So, someone deleted the ssh keys

opal pond
#

Deleting id_rsa and authorized keys are not against the rules

#

I think

fair adder
#

Deleting id_rsa and authorized keys are not against the rules
@opal pond Idk

opal pond
#

James is typing

cerulean maple
#

Someone change the SSH port is against the rules ?

quiet schooner
#

If a private key is leaked, the first realworld step would be to remove the corresponding public key

opal pond
#

Someone change the SSH port is against the rules ?
@cerulean maple nah

fair adder
#

Someone change the SSH port is against the rules ?
@cerulean maple No ;-

opal pond
#

Y’all in a game ?

cerulean maple
fair adder
#

Did you get shell? @cerulean maple

cerulean maple
#

Nah XD

fair adder
#

XD

cerulean maple
#

@fair adder You ?

fair adder
#

I guess not

opal pond
cerulean maple
#

It is started

fair adder
#

@opal pond Has started

cerulean maple
#

45m are left for it to end

opal pond
#

Which room

fair adder
#

Hackers

cerulean maple
#

Hackers

opal pond
#

Noice

unborn wigeon
#

@fair adder you speaking english fluent?

fair adder
#

@fair adder you speaking english fluent?
@unborn wigeon lol, of course not

opal pond
#

Ay yall give me a head strat

#

Start

#

Lol

fair adder
#

Did you get shell? @opal pond

opal pond
#

Yea

#

Already patched tho 😦

#

Reset maybe ? 😄 i came in late

cerulean maple
#

Nah I think no one's in

opal pond
#

Im in

#

Someone is already root

cerulean maple
#

Oh XD

fair adder
#

You lose

#

xD

opal pond
#

Patched stuff

fair adder
#

Sorry, i patched it and killed my shell 😞

opal pond
#

Lol

fair adder
#

xD

boreal flare
#

Hey!

#

anyone up for a koth?

fair adder
#

So, if you want to find another way to privesc, i will be waiting

quiet schooner
#

Hackers has a writeup 👀

opal pond
#

So, if you want to find another way to privesc, i will be waiting
@fair adder thats what im doing rn

#

Hackers has a writeup 👀
@quiet schooner even better the box is offline

#

I mean outta koth

#

Thanks to u I believe?!

fair adder
#

Hackers has a writeup 👀
@quiet schooner Will not help xD

boreal flare
#

how much time is left ? @fair adder

opal pond
#

30 mins

boreal flare
#

ooh

opal pond
#

Feel free to join

#

We will reset

boreal flare
#

i'll join probably the next game

opal pond
#

Y’all wanna reset ?

fair adder
#

Wait, don't reset...

boreal flare
#

starts in 20

opal pond
#

Make it 28 so we can join

boreal flare
#

its public

opal pond
#

Wait, don't reset...
@fair adder why

fair adder
#

I'm looking for another way to privesc ;-;

opal pond
#

Yea im running linpeas not seeing anything

fair adder
#

So sad

#

Ok, reset if you want

opal pond
#

Already voted

#

Oh XD
@cerulean maple u wanna vote ?

cerulean maple
#

Voted !

boreal flare
#

@cerulean maple which room did you create ?

#

uhhh... hackers

opal pond
#

So sad
@fair adder idk want to read files tho lol

#

I don’t *

fair adder
#

You can create a revshell with that

#

I guess

opal pond
#

Not enough time eh

#

Gga

#

Ggs*

#

Btw with what script to u write in someones terminal ? > I guess
@fair adder

fair adder
#

Yea

#

Are you right

#

Someone playing in the public koth?

boreal flare
#

um.. no not this one

#

i had a new install .. configuring some stuff

cerulean maple
#

Someone playing in the public koth?
@fair adder Nah , gonna play tomorrow xD

#

GG btw 😄

fair adder
#

GG

boreal flare
#

arz are you not playing ?

barren oar
#

anyone wanna play KOTH

clear pawn
#

anyone wana play?

wraith geyser
#

anyone up for a match?

#

starts in 24

sudden tendon
#

U there hackermansam?

fair adder
#

lol i joined

static zephyr
#

@wraith geyser thx for posting I have been wanting to try one of these boxes

fair adder
#

dang i need lower peeps in this KOTH so i can get clap TwT

static zephyr
#

ehh im not that good I just have been practicing alot, Im just doing it for fun

fair adder
#

same it fun af

#

anyone wanna join KOTH vc?

static zephyr
#

I do want the real experience first than I would be down

fair adder
#

koolz

#

3 minutes left get ready bois XD

#

hints anyone

winged charm
#

hack gooder

static zephyr
#

@fair adder you ready/ wanna hop in channel??

fair adder
#

Cant sweepy maybe tomarrow ya can add me so we can do another KOTH togeather

static zephyr
#

np

dull geode