#koth

1 messages · Page 54 of 1

stiff egret
#

In a public game, strictly no, but in private games, players do all kinds of experiments, from testing their loops to practising how to spam others, 🤷‍♂️ the person who makes the room and invites others to it is responsible for this,

fair adder
#

Well, thank you @stiff egret

#

I hope you enjoyed the game anyway @opal pond, and i hope you will find better partners for your future games.

#

I was respectful with you from beginning to end.

opal pond
#

I hope you enjoyed the game anyway @opal pond, and i hope you will find better partners for your future games.
@fair adder yea same for both parts

#

I was respectful with you from beginning to end.
@fair adder so was i ?!

fair adder
#

A little bit less respectful than me when you write but it's okay 🙂

terse willow
#

@fair adder

#

<@&756155733468512386>

terse willow
#

There you go 😄

fair adder
#

thanks

stiff egret
#

/tenor whyy

terse willow
#

Because I felt like it

fair adder
#

its something like "you dont have a stable country"

#

google translate kinda lacking ngl

stiff egret
short tusk
#

Mr.Holmes

#

It’s an actual issue this time lmao

winged charm
#

@short tusk it’s fine I got it

short tusk
#

Cry ❤️

fair adder
winged charm
#

@fair adder can I get the game id please

fair adder
#

its @austere frigate

#

he is the one getting these messages

winged charm
#

I need the game id

winged charm
austere frigate
winged charm
#

@austere frigate can you send me the game id?

austere frigate
winged charm
#

Thank you

austere frigate
#

I thank you

winged charm
#

@austere frigate dm me please

winged charm
austere frigate
#

yes

#

it's me

winged charm
#

can you dm me 🙂

austere frigate
#

sure

nimble dew
terse willow
#

Right, but you did send it. Let's not start this up again please

nimble dew
#

I didn't send that message ..

#

Anyway ok

terse willow
#

@winged charm this is your job 🤷‍♂️

nimble dew
#

it was probably the other guy who was on the ssh

winged charm
#

@nimble dew please you admitted to it in my dms. Currently it’s a 24 hour ban please don’t make it longer

nimble dew
#

Ok ok nevermind

#

I'm sorry for everything I said

wraith geyser
nova tide
#

Koth-staff is back?
Do i need to mute the server again? kekw

winged charm
#

I think only for muiri

terse willow
#

Only for muiri when he decides to switch it back on for five seconds

jolly hornet
#

im speak spanish

#

15 mins and start the game

#

machine: windows 7

sick turtle
#

Get 'em

#

Starts in 1 min

#

Carnage is kinda hard

weary axle
#

no

#

its not

pale helm
green axle
#

Who sends a link for a koth?

terse willow
crisp needle
#

Is anyone keen for a game of KOTH tonight?

stiff egret
#

Ping me if it's not Hogwarts 😄

sick turtle
#

Or carnage

nova tide
#

Or windows

warm nova
#

Anyone knew to king of the hill? I wouldn't mind playing but with someone new like myself

autumn pawn
#

I know i don't have the level lmao. Would love to once i'm a bit more experienced

opal pond
#

Im down to play

#

Its not my first time tho

opal hull
#

r u guys ready

#

i want to play koth to

valid flume
#

@warm nova me

sharp salmon
#

im down for koth

valid flume
#

im gonna make a game

crisp needle
#

@stiff egret Are you ok for a King of the Hill in 30 mins?

crisp needle
stiff egret
opal hull
#

bro i'm sleeping gn8 have a blast - from India

warm nova
#

Sorry I went afk had to get back to work

topaz spruce
#

Hey! I want to play koh vs a friend we are both in the room and after the timer runs out we have no IP adress displayed only "EXPIRED" and status: Scheduled

#

did we miss something?

stiff egret
#

You can refresh the page, that should do it.

topaz spruce
#

still the same

stiff egret
#

Can you share the game ID or invite link?

topaz spruce
#

you got a message

stiff egret
#

Usually I'd say refrain from DMs, but I'll investigate the issue anyhow

#

Gimme a sec

topaz spruce
#

alright

stiff egret
#

Um, when did you start it? From what I can see it was started on 21:17 EU, and it's 23:36 right now, if I am not wrong, it ended about almost an hour ago?

topaz spruce
#

its 22:38 now in my time zone we started it at 22:12 with a 5minutes timer

#

sound like a timezone problem

stiff egret
#

mhmm, could be, still something's is def wrong,

primal shoal
#

👀❔

nimble dew
fair adder
#

||rot13|| @broken berry

lusty portal
nimble dew
#

Ok, thanks

pseudo horizon
#

.

stiff egret
#

Please don't post flags openly, use ||<spoiler>|| if you want to post something specific,
Regarding your issue, some flags are purposely encoded in basic encodings like base64/ROT13 etc as a part of challenge from the room creator. What you are seeing is an example of this.

stiff egret
#

👍

sour zealot
#

20 min

lilac pollen
#

hey guys, how can i be eligible to play koth? cuz whenever i try to join a public math it says : Uh-oh! Only intermediate and advanced experienced leveled users can play King of the Hill.

#

what rank do i need to be?

teal root
#

you can change your user level to intermediate or advanced in the profile setting

#

the rank is not affected

lilac pollen
#

ah alright, thanks a lot man 😄

teal root
#

👍

green axle
#

Koth ?

coral spire
#

anyone for koth?

quiet schooner
#

Go into your THM profile

#

And change it

nova tide
#

ez

dense compass
#

King of the hills

hard stone
#

Is the rule: "6. No attacking other users" meant to prohibit killing processes or doing stuff like $ cat /dev/urandom > /dev/pts/1 ?

stiff egret
#

No, It means attacking the real machines of other users. You can do anything on remote box, (the visible IP on the koth game) as long as it abide by the rules.
But not the machines of other users. @hard stone

hard stone
#

Sure not attacking their machines was clear from the beginning 😉

stiff egret
#

Glad you cleared the confusion beforehand, because attacking other users is prohibited site wide. So breaking that one would've resulted in a site ban. (IIRC)

fair adder
#

hey

wraith geyser
#

15 min

primal shoal
quiet schooner
#

@broken berry Please don't post discord invite links, thank you

broken berry
#

sorry wrong channel

gaunt timber
#

i am beginners just want to learn Metasploit , i try tryhackme Metasploit room but it doesn't work for me plzz help

quiet schooner
#

#infosec-general is for infosec discussions that aren't requests for help with a specific THM room

#

@gaunt timber ^

gaunt timber
#

okk @alpine mango sorry I don't know that

weary axle
#

we can use scripts to keep our name in king.txt right

#

like a while loop

stiff egret
#

Yes you can. @weary axle

weary axle
#

the guy im playing with is saying it aint allowed..that is hardening the file and all...so just for confirmation i asked 🙂 thankyou for u reply

stiff egret
#

NP, you can also tell them to give the blog a read, the rules on site are described a bit more in the blog for easier understanding.

#

Pinned messages for the reference :)

spark forge
#

Dea

fair adder
#

Hey all

fair adder
#

iamjezz are you here?

#

@fair adder iamjezz

#

/koth/14728 is resetting

fair adder
#

short question. Is there any reason why I will get lion 4 times in a row?

broken berry
fair adder
#

good to know

hearty wing
#

will there be more machines in koth

#

okay looking forward to it

#

and also why is koth vc locked

stiff egret
#

@hearty wing that's probably because you are not verified.

hearty wing
#

Okay

hearty wing
#

How do i get verified

dense compass
#

Take your token from your profile and send message to the bot (tryhackme bot)

#

The message should be in format
!verify <token>

hearty wing
#

OK thx

nova tide
terse willow
#

Oh, I'm sorry -- was that not meant to be teased?

#

I was under the impression we were drumming up interest @nova tide

nova tide
#

Not yet

terse willow
#

Whoops

nova tide
#

No point deleting that now 😂

rotund topaz
#

anyone feeling up to a casual koth and vc?

tiny loom
stiff egret
tiny loom
#

ahh yeah

#

I'm always a bit paranoid when I python -m SimpleHTTPServer to ferry something over, that someone else also uses the open port 😄

winged charm
stiff egret
tiny loom
#

yeah that's what I meant

#

someone could just try random ips and find my httpserver

winged charm
tiny loom
#

popup? 😄

#

i guess i see it in the http server log

stiff egret
#

The python server shows every ping

stiff egret
winged charm
#

The other thing is you have to know what files you have in order to get from that open port and there’s not really any way that I know of to enumerate that

tiny loom
#

linpeas.sh seems like a safe choice

winged charm
#

Wait I’m being dense you can just get it from the GUI

#

nvm

#

anyways yes it’s a thing that can happen but there’s no real need to worry

stiff egret
tiny loom
#

anyways, the questions I actually wanted to ask:
-how did you get your various roles
-what is koth hacking? 😄

winged charm
#

I hang out with too many scots and brits alright bugger off

#

Being 1337
king of the hill it’s a competition with 10 people all hacking one machine

stiff egret
tiny loom
#

oki

#

how do i get the roles?

stiff egret
#

!verify <discord token from tryhackme profile> send this to tryhackme bot

native shore
#

brute forces taking so long 😩

broken berry
#

this box takes so long

#

i've never been able to finish it

nova tide
#

||-t 64||

native shore
#

I'm using that flag

broken berry
nova tide
#

Hackers can be rooted in less than 10 seconds

#

with brute force ^

native shore
#

Even with rockyou.txt?

nova tide
#

yeah

broken berry
native shore
#

nvm, i got access to the pass

broken berry
nova tide
#

Better luck next time

native shore
#

I was wrong, but my hydra finished right at the end is what i mean :/

#

that was fun

opal pond
#

Yea its a known bug

stiff egret
#

Yeah that's a known bug. I thought that was fixed, @lusty portal ?

terse willow
#

@winged charm warn someone

#

Actually

#

Try to use 8ball

winged charm
#

nah brah

#

dark said he’ll spank me

nova tide
#

-8ball can we access you?

#

Muriiiiiiiiiii

terse willow
#

There we go

#

Problem with being a member of the KoTH staff

#

@nova tide Try it now please?

#

-8ball

sour vectorBOT
#
8Ball <What to ask:Text>

Invalid arguments provided: Not enough arguments passed

terse willow
#

-warnings @nova tide

sour vectorBOT
#
Warnings - User : 267010557889085440

Total : 1

#21888748: 16 Nov 20 22:41 UTC - By: MuirlandOracle#2721 (650476435269484549)
Reason: Attempting to get @stiff egret in trouble

logs: link

stiff egret
#

oh boi kekw

terse willow
#

Or you @stiff egret

#

Just try using 8ball?

#

Then try using warnings?

stiff egret
#

-8ball

sour vectorBOT
#
8Ball <What to ask:Text>

Invalid arguments provided: Not enough arguments passed

terse willow
#

Bingo

stiff egret
#

-warnings @nova tide

terse willow
#

Try it on Cry

#

I just temporarily removed his KoTH mod

stiff egret
#

-warnings @winged charm

#

sed

terse willow
#

Try -warn @winged charm Being a goober?

stiff egret
#

testing in prod

#

:kew

terse willow
#

Mhm. Always

#

I'm confident though

stiff egret
#

-warn @winged charm Being a goober?

terse willow
#

Perfect

stiff egret
#

ah dang

terse willow
#

Can you delete messages in here?

stiff egret
#

did it work?

terse willow
#

Like, Cry swearing?

#

Nope

#

Well

#

It worked

#

It didn't warn him, so it worked

stiff egret
#

ooo

terse willow
#

Ok, so you can delete messages, but can't use the bot

winged charm
#

we have no powers

terse willow
#

You don't

#

I yoinked your KoTH mod

#

Also

#

Warn @winged charm swearing. Again

#

-warn @winged charm Swearing. Again

winged charm
#

Oh bugger off

sour vectorBOT
#

⚠ Warned Cryillic#6015

winged charm
#

communists is not swearing

#

dawg what

terse willow
#

Oh, no, that was for the assholes

winged charm
#

This is mod abuse

terse willow
#

Mhm

#

Better believe it

#

Right, you should have powers in here, but no ability to use the bot, other than 8ball

winged charm
#

Do I have powers outside of here for the bot

#

This is oppression

terse willow
#

No, you don't

#

But you didn't anyway

primal shoal
broken loom
fair adder
quiet schooner
#

@winged charm

winged charm
#

dang it

#

@broken berry whats the game id?

quiet schooner
#

@broken berry There are slurs there. Please remove them or mark them as a spoiler at the very least.

winged charm
#

do you have any ideas of who it is?

broken berry
quiet schooner
#

@winged charm Plz grab images now, I'm gonna delete them

broken berry
#

i don't know for sure

winged charm
#

I already did

quiet schooner
#

Cool deleting now

winged charm
#

@broken berry theres too many users on there all in the same position I cant make an informed decision on who it is. If you can find any other information of who it is please let us know

broken berry
nova tide
deft cliff
#

Ooops clicked without knowing what I'm doing 🙂

nova tide
#

you can leave if you want

dusty canyon
#

Who made all of the previous koth machines?

cerulean sparrow
quiet schooner
#

I made Hackers and Food

#

Muir made fortune

#

Holmes made hogwarts

dusty canyon
#

Ah alr ty

crude zodiac
#

oops didnt mean to join

fair adder
#

its always better to remember to put your name in king.txt, if you are root 🙂

viral stirrup
stiff egret
#

:)

viral stirrup
#

I'll give it a try though

#

There's always time for learning something new 😄

stiff egret
nova tide
#

@fair adder @hazy geode @pablocordova which one of removed/chmod all of the binares?

primal shoal
fair adder
#

Uhh so what do I do?

#

and ye I read the blog post

stiff egret
#

The post literally tells you what to do.

stiff egret
fair adder
#

NVM, I get it, it's just it requires ya to have lot's of knowledge about other tools

#

Wish there would be hints at least lol

stiff egret
#

:) there are loads of rooms on THM to solve & learn from, give them a try

fair adder
#

yea sad thing is I barley understand the basics

#

I did the first basic linux room, and doing advent of cyber

stiff egret
fair adder
#

Yea I'll probably start that once advert of cyber is done

white wolf
hazy geode
#

hello

winged charm
#

-warn @kindred stump yeet

#

-8ball

sour vectorBOT
#
8Ball <What to ask:Text>

Invalid arguments provided: Not enough arguments passed

winged charm
#

this is nonsense

terse willow
#

It basically ignores anyone who isn't a mod

#

For everything other than -8ball

winged charm
#

damn it muiri

#

why cant yall just let me be with my powers

terse willow
#

I separated the overrides out into two separate categories -- one for mods, one for everyone else

#

Hey, you still have manage messages!

winged charm
#

I cant threaten dark with revolution now

terse willow
#

You couldn't anyway

#

He still has manual mute powers

#

Even if the bot breaks, you can mute you with two key presses

#

And ban you just as easily

winged charm
#

he would then have to deal with the like 10 other servers Im in with him

#

@terse willow no exit clause brah

terse willow
#

Nah, this is the one he cares about @winged charm

#

Doesn't matter if private servers get messed up

#

Here, it's an issue

delicate cedar
delicate cedar
short tusk
#

I’m not sure if KOTH rules but I’ll boop the staff

#

@winged charm @stiff egret

stiff egret
#

Taking a look

#

~~Can you tell me which is your username?~~Or better, get verified on discord here. That way we can tell who is who.

#

@delicate cedar

delicate cedar
#

@stiff egret Done verified

stiff egret
#

Just saw the details, for now, it clearly looks like someone is controlling the resets using alt accounts, that is currently a bit shady because we kind of allow alt accounts in game.

delicate cedar
stiff egret
#

Agreed. I hope we can find some middle ground for this, I've pinged admins as well.

winged charm
#

What the heck

#

it’s too early for that

stiff egret
#

What the heck what the heck @winged charm

broken berry
#

Is it illegal to steal files from my machine via the python server I put up to send exploits to the target machine?

stiff egret
#

Yeah, but you can see the ip of users if they try to connect to your actual machine, you see them, you report them with screenshots.

dense compass
#

Anyone want to play?

#

Koth

hearty wing
#

idk not rn

lilac topaz
#

Awesome

delicate cedar
jovial phoenix
#

aww ok

patent forge
#

how can we be surprised of someone downloading data from our host in a KOTH? we should be "hackers"...

viral stirrup
patent forge
#

@viral stirrup yep, I know that and i totally agree as we are in a educational environment

#

but ehy, data is data, and security should be our main focus

#

I think it's correct to report, but not beeing surprised

viral stirrup
patent forge
#

also for "educational" reasons, getting the exploits from another player, can be useful to understand what he is doing and rush to patch

#

long story short, don't touch other people's stuff, but at the same time don't be superficial with your data @broken berry

stiff egret
patent forge
#

@stiff egret i know, rules are rules and i don't do that, i was just referring to an hypotetical scenario

#

concept is pretty much the same as using stuff like pspy etc to track other players activities

stiff egret
#

Yeah, I got that, I personally just start a spy to see what others are downloading and download them from the vuln machine

patent forge
#

can wireshark be a way?

stiff egret
#

Overkill

patent forge
#

following the stream of a nc shell could be interesting...

#

never done that on koth

stiff egret
#

It could be, but yeah, for a 1 hr game, it's too much, you have to defend and attack as well.

patent forge
#

next time playing with @nova tide i'm preparing macros just to pop up wireshark and sniff only.

viral stirrup
#

lol

stiff egret
#

LMAO, try xte, the thing is epic.

#

I've like 20 scripts to do specific stuff with xte

patent forge
#

the java text editor?

stiff egret
#

Uh uh, linux package

viral stirrup
#

xautomation

patent forge
#

lol

#

i'm so much skiddie that i looked for "XTE github" straight on google

stiff egret
#

😂😂😂😂

#

We all do that,

patent forge
#

i got more tools from koth players than everything else

stiff egret
#

LoL

viral stirrup
#

@stiff egret what else is up your sleeve?

stiff egret
#

Play a game and find out

pallid cosmos
#

i got oofed

pallid cosmos
#

@sacred schooner aint easy

#

i see

#

trying to gobuster my way

#

gobuster is not de wae

#

yeet

#

lol

#

mamadgholi speedy boi

#

lol

#

man howtohack

#

i am lost

#

did you even find a page?

#

what tool did you use?

#

ah i see

#

9999?

#

anyways i started blasting

#

ye

#

i am depressed now

#

need to learn more

#

ye i remember now...

#

should do that always if there is nothing interesting

viral stirrup
#

guys use rustscan to scan ports 100x faster than nmap

pallid cosmos
#

is it louder?

viral stirrup
#

also the port 9999 is for the KOTH flag service and you shouldn't exploit that

pallid cosmos
#

ah

#

looks hella fast

viral stirrup
#

sure np 🙂

viral stirrup
pallid cosmos
#

thanks

hearty wing
#

You should make a attack defense type game as well

pallid cosmos
#

Blue Red Teaming?

stiff egret
steel hornet
#

Starts after 10 minutes

#

Last 3 min

uncut basin
#

;

hazy geode
#

.

austere frigate
#

pls🥺

gloomy estuary
#

Any recruiting teams? or would anyone like to create one?

delicate cedar
nova tide
stiff egret
#

IIRC, it's to be fixed issue, where the invite links will expire after the game starts, but for now, yep they work

fair adder
#

Hey there. I am in a koth and we had two or there resets already. Looks some old accounts are used to reset the session

#

koth is running id 15268

stiff egret
#

Giving it a look rn :))

fair adder
#

bruh i don't even remember joining that room 🤔

#

i was playing koth with friends today tho

tall cove
#

Quit braggin'

fair adder
#

come at me

#

your favorite elf

fair adder
rancid pewter
#

Haha, I'll take that as a compliment.

fair adder
#

it was 😂

#

you are really good

rancid pewter
#

Lost my rootkit, all of my notes and I don't remember most of the box. That a pretty big advantage for you if you want to play against me.

#

2mins

short void
#

Does the 'hack with friends' feature let you collaborate on any room, or is it only for KOTH?

stiff egret
#

No, it's for KoTH only. @short void

#

(tho If you see it this way, all challenge rooms have scoreboards, so technically, you are hacking with friends whatever you hack on tryhackme :)) )

short void
#

@stiff egret Thanks for clarifying. I was actually hoping it could be used as a sort of co-op mode (as opposed to competitive race mode) in order to get some of my friends into hacking without them feeling lost. Maybe THM will add it in the future.

stiff egret
#

In case you are unaware, you can create private rooms, and invite only your friends in them, that way you can decide your own rules and speeds :)

broken loom
#

hlo

latent osprey
#

hi

#

anyone wants to play koth?

#

okay! i will wait

broken loom
#

lets roll

#

can someone tell me how to play koth???

#

thanks ...

latent osprey
#

how many times have you guys played ??

#

this is my second time

broken loom
#

first

latent osprey
#

noice

broken loom
#

why i cannot connect using creds.txt

broken berry
#

maybe someone changed the password?

broken loom
#

???

broken berry
broken loom
#

i don't know much but is this the way to patch ????

broken berry
#

i'm not actually sure its allowed but it can be considered as a patch

#

changing the password restricts other users from accessing the session

broken berry
#

but there's always an other way

quiet schooner
regal notch
#

any koth up ?

#

invites ?

fair adder
#

@regal notch just dont forget to paste 6 flags in 12 seconds after just freshly booted machine 🙂

#

u must be hella good

patent forge
#

@rancid pewter vc?

rancid pewter
#

My speaking english is really bad

regal notch
fair adder
#

Of course you can, but not 10 seconds after booted machine. I havent even finished my enumeration bro. 🙂

#

oh wow i didnt know you can find flags without shell

regal notch
#

I meant collecting it during the play not saving it Omg

regal notch
#

And I didn't submit it by 12 seconds,
I turned up king and then I started the submission of flags

Is 12s enough for to be the king? Don't need anything to find for privesc?

Yes it took time, several minutes. But how this guy is talking about seconds

formal gust
#

anyone who has played space jam, is it possible to like get an ssh session

dusty canyon
#

keygen

nova tide
#

This ^

delicate cedar
marsh perch
regal notch
marsh perch
#

@fair adder Can I DM?

fair adder
#

ure

#

sure

short tusk
stiff egret
#

Nothing we can do about that for now, skidy did say that he'll edit some rules for that, but nothing as of now.

short tusk
#

Rip

winged charm
fair adder
#

@lost compass can we reset the machine in koth?

lost compass
#

Hey sorry @fair adder i just saw your message

fair adder
#

Its okay

lost compass
#

Gg it was tight

latent osprey
#

Hey

#

Anyone up for koth?

pearl crane
#

im a noob pls dont tryhard me

fair adder
#

me too!

fair adder
#

i'm getting on my vpn, just one sec

fair adder
#

do i need to just click on the link or also open my vpn configuration file?

pearl crane
#

just click link

#

then you can get config

#

bruh i might need a new link

#

kk that one starts in 15 mins

fair adder
#

Noooooooooooo

#

Bruhhhhhhhhhh

#

I can't join you

#

😦

#

bryh

#

why

#

I am a noob

pearl crane
#

?

fair adder
#

need to be intermiidaiate

#

or expert

pearl crane
#

dude u can change in setting lol

fair adder
pearl crane
#

just go to settings and change it lol

fair adder
#

okay i need to be back!

#

how long you going be on here?

#

i'll be back in 40 mins need to go to store!!!@

#

brb

pearl crane
#

i have no life sooooo that should answer

#

@fair adder are u slavko?

fair adder
#

y

pearl crane
#

idk

#

just asking lol

#

yep u are

#

ight im bout to get completely dominated

torpid ridge
#

whats a koth and hows it work?

#

do all 10 ppl ssh into the same machine or something

terse willow
#

Hack their way in

#

But yes

#

Lots of people target the same box. The first person who gets in tries to keep the others out

torpid ridge
#

oh ok

#

how do ppl usually keep others out?

#

firewall rules?

#

oh theres flags too

terse willow
#

By patching the vulnerable stuff

#

Firewall rules are banned

trail hinge
#

think of it like blue teaming

#

you could keep everyone out by shutting down your servers

torpid ridge
#

interesting

trail hinge
#

but it's useless

#

the fun is finding the root cause and addressing it without interrupting service

torpid ridge
#

im assuming these services can all be patched and restarted without restarting the target machine then?

#

are all the machines the same? or randomized vulnerabilities per instance/game?

trail hinge
#

They maintain a pool of machines

torpid ridge
#

when it says new machines added every month, do they swap them out or straight up add new ones?

trail hinge
torpid ridge
#

i just found the page lol

trail hinge
#

Plus you can see some previous games

torpid ridge
#

is it possible to patch everything? or is it too much to do in an hour

trail hinge
#

So alternatively, If you are curious, JohnHammond has some videos of a playthrough if you wanna get a feel of how the game plays

torpid ridge
#

oh cool, thanks

torpid ridge
#

I love this guy, such friendly

grand ember
#

it's certainly doable in a match but i'd say only if you knew at least part of the machine before

torpid ridge
#

gotcha, thanks!

fair adder
#

hey koth stuff

#

is writing script to automate finding flags against rules?

terse willow
#

<@&756155733468512386>

winged charm
#

ree

terse willow
#

Boy asked you a question

winged charm
#

well

#

hmm

#

this is going to require an interesting interpretation of the rules

fair adder
#

so its against rules?

#

for example this

#

... i can't make it spoiler

#

can i upload it on dm?

terse willow
#

Just upload it smh

fair adder
#

okay

terse willow
#

We can delete it after

fair adder
#
import re
import os
regex_pattern = r"(^thm{.*}|thm{[a-f0-9]{32}}|[a-f0-9]{32})" 
text = ''
os.system("find / -type f 2>/dev/null >> file_names")
with open('file_names','r') as f: 
    for files in f.readlines():
        files = files.strip("\n")
        try:
            with open(f'{files}','r',encoding='ISO-8859-1') as r:
                for lines in r.readlines():
                    text += lines
                resault = re.findall(regex_pattern,text)
                if(len(resault) == 1):
                    print(f"{resault[0]} - {files}")
                text = ''
        except Exception as f:
            print(f)
os.system("rm file_names")
print("done")```
terse willow
#

Well

#

That's gonna crash the boxes

winged charm
#

Ok Im going with an its within the rules assuming it is only looking for flags if any of the other koth staff disagree we can discuss in #koth-staff

terse willow
#

Like. Immediately

#

You're indexing every file on the system and dumping it into a text file

winged charm
#

haha

#

its much easier to find flags than that

terse willow
#

I can do it in a oneliner

winged charm
#

straight up just do a locate flag I gurantee youll find plenty

terse willow
#

In native bash

fair adder
winged charm
#

the command really wouldnt be that hard

trail hinge
#

grep -R my dude

terse willow
#

^^^

fair adder
terse willow
#

It'll work the same way as your program

trail hinge
#

either way

fair adder
#

it wont

#

u guys are up?

trail hinge
#

you are essentially just benchmarking disk io

fair adder
#

this thing will find every md5 hash 2

#

oh my

terse willow
#

Either way you're looking at regex

#

The same regex for either command

fair adder
#

i have an idea

terse willow
#

Oh God

fair adder
#

you are right

terse willow
#

This never ends well

fair adder
#

that would kill a box cuz im indexing files to one file right?

#

why not make it opet what i supply as argument 🤔

terse willow
#

Eh?

fair adder
#

yeah that should work

#

so like then i can

#

find / -type f 2>/dev/null | python3 main.py

trail hinge
#

find / -type -f 2>/dev/null -print0 | xargs -0 egrep '(^thm{.*}|thm{[a-f0-9]{32}}|[a-f0-9]{32})'

#

would probably be significantly faster

#

and won't fork a bunch of pids

#

one pid

fair adder
#

thats evil

#

why 😭

terse willow
fair adder
#

i had so much fun writing that script

#

now there is no point to it 😭

terse willow
#

I'm sorry Elf

#

But there never was kekw

trail hinge
#

honestly

fair adder
#

i will use it anyway tho blobknife

trail hinge
#

i just couldn't in good conscience watch you do that to a server

terse willow
terse willow
#

If you dos the server deliberately, we're banning you from everything

fair adder
#

i will use this thing

terse willow
#

Good Elf

fair adder
#

elf don't be bad guy

terse willow
#

See?

#

Even Jovnn agrees

fair adder
#

yeah

#

Muir if u see him doing bad thing call me

#

i will punish him

terse willow
#

Nah, you're alright

#

I can just mute and/or ban

fair adder
#
[root@dhcppc3 elf]# find / -type -f 2>/dev/null | grep -E '(^thm{.*}|thm{[a-f0-9]{32}}|[a-f0-9]{32})'
[root@dhcppc3 elf]# find / -type -f 2>/dev/null -print0 | xargs -0 egrep '(^thm{.*}|thm{[a-f0-9]{32}}|[a-f0-9]{32})'
``` this not work
trail hinge
#

might need to mess with the regex

fair adder
trail hinge
#

also my typo with the -f

#

it works in spirit

#

the -print0 is important as it inlines the matches

fair adder
#

yeahhh @terse willow just gonna go and optimise my code so i don't dos a machine

trail hinge
#

it keeps everything in a single pid

#

keeps you from forking off an ungodly amount of processes

stiff egret
fair adder
# stiff egret Ok, though I agree that scripting to find flags is allowed, this script specific...

i came up with solution tho py import re import os import sys regex_pattern = r"(^thm{.*}|thm{[a-f0-9]{32}}|[a-f0-9]{32})" text = '' for strings in sys.stdin: strings = strings.strip("\n") with open(str(strings),'r',encoding='ISO-8859-1') as r: try: for lines in r.readlines(): text += lines resault = re.findall(regex_pattern,text) if(len(resault) == 1): print(f"{resault[0]} - {strings}") text = '' except Exception as f: print(f) print("done") do you think this is more stable?

#

cuz like then you are not making anything you are just opening files?

winged charm
#

that sounds horrible

#

youre trying to parse every file in the system

glad turtle
#

Starting in 4 mins, feel free to join

stiff egret
fair adder
#

most

#

but not all

latent osprey
#

Hi

#

Anyone for koth?

regal notch
#

koth koth koth kotheyyy

fair adder
#

Anyone wanna play ?, send link here..... @pearl crane

faint tinsel
#

hi

#

just turning machine on

fair adder
#

Send link please. Friendly reminder* I am noob

#

need to change my settings brb 🙂

faint tinsel
#

im a noob too no worrys tipsfedora

#

@fair adder link dm or here?

fair adder
#

here is fine 🙂

faint tinsel
#

here u go

#

im not polandese btw

#

3mins

fair adder
#

not sure what that means, but you're okay 🙂

#

Still working on my settings

faint tinsel
#

1 minute to start

#

oh it failed

#

@fair adder u can join now

fair adder
#

duude! my browser is supler slow!!

#

okay send link again

faint tinsel
fair adder
#

one sec my vpn is giving me problems

faint tinsel
#

you have 15 mins

#

ping me when you're here

fair adder
#

Not sure what's happening to my Parrot OS

#

My VM box isn't turning on bro. I can't play with you @faint tinsel

faint tinsel
#

no problem

#

check your settings

fair adder
#

I'm gonna have to fix this. I'll brb man 🤦

faint tinsel
#

ok np

pearl crane
#

last time i tried to download parrot it screwed me over

#

im sticking to kali lol

primal shoal
#

👀

fair adder
#

Okay, I have fixed my machine!

#

@faint tinsel @pearl crane You tryna play now?

faint tinsel
#

its 8am here not in pc rn

fair adder
#

8am?

#

Let me know when you can play 🙂

grand delta
#

can someone share spectate link while you guys play .......it might be helpful for others

fair adder
#

Anyone trying to play

#

send link here please 🙂

pearl crane
fair adder
#

Hell yeah!

#

still giving me the only intermidiate level @pearl crane

pearl crane
#

go to settings and change your level

fair adder
#

Ok, i will do this again

#

Hell yeah !

#

here we go !

#

LOL

#

first game ever !!!

pearl crane
#

gl

#

its pretty hard tbh

fair adder
#

gl!

pearl crane
#

if you cant do it look for a tutorial as last resort

fair adder
#

I have no idea what to do tbh lol

#

Okay

pearl crane
#

lol

fair adder
#

here we go!

#

what port do i use to connect to the ip address ??

pearl crane
#

u need to hack it

#

but dont disturb 9999

stiff egret
fair adder
#

Thank u!!

#

i need previlge escalation!!

quiet schooner
#

You're gonna want to do quite a few easy to medium CTFs first

fair adder
#

I need the the password lol!

#

I keep getting a connection refused when trying root into the ip address does this mean they have patched the vulnerability there?

#

And now my machine froze completl;y

fair adder
stiff egret
fair adder
#

keeps telling me TCP/IP fingerprrinter requires root previliges

#

i've even included the -Pn switch

#

just like nmap room taught me but no working

#

wow i needed to add the sudo!

dusk cave
#

So nice to see your enthusiasm 😄

fair adder
#

okay! i found port 22/80 and 23 open!

fair adder
#

i ran -T4 and -vv to get faster results but its still going super slow lol

dusk cave
#

-vv is making it more verbose

pastel sparrow
#

Hey anyone wants to play?

fair adder
#

I found a whole bunch of ports open and also a 139 open

#

isn't this hackable ?

dusk cave
#

this isnt coop 😄

fair adder
#

Man o man this is fun

dusk cave
#

did u manage?

fair adder
#

I need to learn how to use curl

#

i'm reading on one of the write ups that i need a listener also ?

#

so not sure what that is lol

#

Didn't realize how much of a noob i was

#

Looks like PKyahhh won

#

congrats bro!

pastel sparrow
#

Hey of anyone wants to play

dusk cave
tribal socket
#

come ^^

hoary lava
#

What rooms do you guys recommend before taking part in one of the koths?

quiet schooner
#

Try out Hackers and Food which are available outside of KoTH in standalone rooms

tribal socket
#

How many machines are available altogether?

grand ember
#

10, you have a list on the koth page

tribal socket
#

and shrek ?

quiet schooner
#

But it only lists the most recent 10

grand ember
#

oh well

tribal socket
#

how many are there in all?

pearl crane
pearl crane
#

while its scanning*

fair adder
#

I'm doing a couple more CTF's and finishing my "Complete Beginners" path before I do another one 🙂

tribal socket
#

lol

regal notch
#

@Mr.Holmes#3066
Redirecting traffic of port 9999 is restricted?

nova tide
#

You are not even allowed to touch that port.

quiet schooner
#

I'm proud to be the reason for that rule

quiet schooner
#

Like you can see who's king happily, right?

#

I have an idea for a mini project is all.

nova tide
#

🤷‍♂️

quiet schooner
#

Long as you can read from it, we good

hearty wing
#

anyone up for koth today

nova tide
#

Maybe later tonight

hearty wing
#

okay

#

I just want to try the panda machine out

nova tide
#

Okay

regal notch
#

🖐️

grand delta
#

you can join if interested

dusk cave
#

someone up for a game?

dusk cave
#

starting in 1 min

dusk cave
#

if i try to access the machine ip i get redirected to a website from another player is that allowed?

full grove
#

is the website malicious?

winged charm
dusk cave
winged charm
#

can you dm a screenshot to me

dusk cave
#

the game is over but i will check my history

winged charm
#

That doesn’t do any good

dusk cave
full grove
#

its a google site, so nah

tribal socket
#

lol

#

this is my friend this is his ctf correction site

#

@west zenith ^^

west zenith
#

hello

tribal socket
#

FORTUNE again lol

nova tide
tribal socket
#

readed 👍

nova tide
#

can someone share invite link for the game?

west zenith
#

the game is over

nova tide
#

still showing 31 minutes 🤔

#

but ok

west zenith
nova tide
west zenith
#

ok this one isn't corrupted

nova tide
#

No, i just want to play.

west zenith
#

😄

tribal socket
#

I am no longer available 😡

tribal socket
#

@west zenith are you afk?

quiet schooner
#

@tribal socket Please keep it to english only

tribal socket
#

🙂

plucky totem
#

come lets play

solemn dust
#

feeling kinda lonely here being the only guy in the lobby

nova tide
#

@regal notch editing the king service is not allowed.. you totally broke the rules by editing the service as well as stopping the king service..(Twice)

regal notch
#

The service was down before the reset, and i just held 3m till the first reset

#

And I wa toally got out of the box and stayed still and voted the reset

stiff egret
#

This is not the first time.

nova tide
#

you stopped king service, we reset. after 40 minutes into game. You edited king service and changed king.txt location to /opt/king.txt

regal notch
#

I didn't stopped it

stiff egret
#

Also, but this time I was watching Naughty's stream too

regal notch
#

yeah it was running

nova tide
regal notch
#

just moved it to another location,
rule siad editing or stopping

nova tide
#

editing

regal notch
#

was editing means moving it

stiff egret
#

That's not allowed.

regal notch
#

oops

#

So I'm getting a ban?

nova tide
#

I don't think so.

regal notch
#

Expecting the rule to be elaborated a bit more

stiff egret
#

I am not so sure about that.

regal notch
#

I was not clear about it
and few others even attacked my shell

#

Lemme see whats gonna happen.
Never gonna touch that hot thing again😅

winged charm
#

@regal notch Hey mate can you dm me?

feral niche
#

What to do with this binary file in smb@nova tide

nova tide
#

in Panda?

feral niche
#

Yes

nova tide
#

i don't remember if there was anything in smbshares

feral niche
#

Ok

nova tide
#

Also someone closed ssh service earlier.. That's not allowed.

winged charm
#

we love mystery binaries

#

run it and see

#

is it minecraft?

#

is it ransomware?

#

who knows

#

its like a mystery box

nova tide
#

Wow, people really like the quote "If i can't play, i wont let anyone else play"

winged charm
delicate cedar
#

Someone just keep spamming to kill shell

winged charm
#

@delicate cedar so they’re just killing your shell?

delicate cedar
#

yes

winged charm
#

That’s allowed

#

I honestly hate the fact that it’s allowed how to is but it is

delicate cedar
stiff egret
#

Then you patch the stuff 🤷‍♂️

delicate cedar
#

He's killing the shell

nova tide
#

Kill their shell, learn how you can hide yourself from tty sessions.

delicate cedar
#

Already know how to hide pid, The problem is he's killing my sessions like crazy

stiff egret
#

You need to hide your tty.

stiff egret
delicate cedar
#

Hmm, I thought remount the proc using hidepid option did the job

stiff egret
#

🤷‍♂️

nova tide
#

I tried using hidepid as well but it didn't work as i expected it to. 🤷‍♂️

delicate cedar
tribal socket
#

what command?

delicate cedar
#

ssh ... -T

nova tide
#

I don't want to get out of my bed and turn on my PC

stiff egret
#

Nvm that, it's windows

grand delta
#

anyone up for a game

#

?

grand delta
#

anyone up for a game >?? for a public game it literally takes 24 mins

urban violet
#

Is it illegal to modify /etc/ssh/sshd_config so that:
(a) SSH port is set to non-default, e.g. 2222
(b) a specific user is denied (with the DenyUser syntax)

stiff egret
#

Point a is allowed,
Point b is not.

#

@urban violet

winged charm
#

I mean

#

Is point b not though?

#

that’s never come up and the rules are still very vague

#

I’d say it would technically still be within the rules

stiff egret
#

No, making machine unavailable for/by users is/shouldn't be allowed.

grand delta
#

anyone up for a game

#

?

solemn dust
#

god i wish there would be a shoutbox in koth

delicate cedar
#

Man I wish there would be ranked system when user win they get point and lost point when losing

winged charm
solemn dust
#

@marsh perch you want to hop on the vc? im 0xMcshoothy

marsh perch
#

Hey how is it going man? @solemn dust

#

Not sure why ssh creds are not working. I am on my way to bruteforce ssh

#

if it's not working then I will try FTP

#

Oh I see

#

You also changed cred?

stiff egret
#

Avoid the spoilers please.

solemn dust
#

yeah sorry

stiff egret
#

Np :))

marsh perch
#

Apologies @stiff egret

simple bough
#

Hey

nova tide
#

Hi animewave

grand delta
#

sup

simple patio
#

who wants to join my public game?

broken jackal
#

@simple patio yay am in

simple patio
#

Yes, thanks

#

Don't expect much from me though