#koth
1 messages Β· Page 58 of 1
but you got me before
i can do ramen not even pasta
not even food to
you won
gg
.
i only got 4 flag
GG
GG to you
i managed somehow to kick out everyone with a self written script at one moment and i got king 5m at the end because of that
but it didnt work on every process
so it was a loss of time
what script?
what did it do?
....
i look at the rules before
spamming killing shells?
no
just a killing shells one time
only one time
i saw that spamming is illegal
so i didnt do with spamming
because i got disconnected at a moment π€£
but it was a fun game
the script said if this process is caused by an another host but no me disconnect it without spamming
just a killing shell once
....
that's what it means.
no it didnt spam kill
that's not the issue here
not at all
if its not your shell, kill it.
so if anyone else gets a shell they will be kicked out immediately.
no
its juste if another person is in root priv
it just shut the session and the man can reconnect
without any problem
it just run once
just to do gain a little bit more time in king
but anyone can reconnect
and kick my shell out too
(that's what happened)
so if its illegal to just kill a shell once tell me i will not do it next time
and i apologie if its illegal
This is a fun game, so avoid using scripts like that, from what you are saying, using that script can be borderline allowed, (but I can't say anything solid since haven't seen it yet. But most probably it will break the rules)
So please keep the game fun :))
i understand thanks you
i apologies by the fact thats its borderline legal
you just brightened my questioning about that method of making it more simple
i will not replicate this in the next koth game i will make
Great :)) All the best for your next game
thanks man hf too
wanna some guy come here?
u still doing koth?
k
sure
Anyone up for KoTH ?
Already in
Nice
Anyone wanna play
I'm playing
How long toll it starts ?
20m, I just create it
@opal pond Is that you on the box?
im talking bout wget, nano, (somethngs wrong with vi to cant save anything) and ...
vim=nano, nano=vim
As i told you, i'm not removing any binaries, just moving it
and that's the binary that u upload
find / -name wget doesnt give me anything and i dont assume u expect me to guess its name if u changed it and removed it from PATH
not the system binary
find recently modified file
Of course i changed it to another name, but instead of guessing it's name you can find recently modified or etc
Can I move king.txt from root dir?
Do not attack, modify or stop the service(king/KoTH service) on 9999 (this includes a 'KoTH' binary placed by default in /root and things like changing service locations.)
Actually can @stiff egret or @nova tide Verify this please
Giving the chat a read...
- Which machine is it?
- That's equivalent as either way others can't find them.
For reference, I was referring to this message and this one:
#koth message
#general message
One of which was posted in #general
Moving binaries from the path is the same thing, and that's not allowed, except for 2 cases, 1. Chattr binary and 2. In Hogwarts machine, names of nano and vim are interchanged by default.
No ofc you cannot, if you haven't read the rules, I'd advise you to give them a read first in case you end up breaking any.
Thanks for catching that, I was not on the system :))
No problemo 
Not really remember it, last I play with naughty he moved or remove some binary so I thought moving it is legal
Think about it, what's the difference bw moving and removing if it's not in path and not everyone can use it?
The rules says to try to patch, while keeping the machine as close to original state as possible.
No issues, just don't do that again in public games and we are good. :)
Okay
public game in 13 minutes
pass for hackers machine are changed everytime ?
yup
nmap finally finished scanning
the guy in this game >>?
holmes , is removing binaries allowed ?
^^
Jusr said that.
π₯΅
Please, please please give the rules a read if you have any doubts.
I have no issues if you ask again, clearing the confusion is better than breaking the rule and getting banned.
a guy named "fan" removed it
@runic shoal
what
nothing chattr
theres no wget , chattr , nano stuff
Not all machines have chattr
another reset
srsly ?
wtf
i am done , lol
wtf man, reset again -_-
Reset 3 times, lol
smh
not all machines have chattr, i just login into reset machine and i can't use chattr
for yout information
Yβall good?
You can add your binaries on to thw system if you want
That is fine. But what about the people who reset the box for no reasons. I played a game in which the box was reset for about 6-7 times for no reason
Then you report it to us
Good rules! It was the best to play fair @stiff egret
@half notch good luck boy
(bonne chance)
i cannot connect to pasta
changing password is legal ?
yup
i didnt know ...
kick with pkill is legal ?
Make sure you do not kill the service that's running with that user, for e.g. if a user is the owner of a web-server, and you pkill that user, then the web-server will die too. And now that is against the rules.
so i can kill user but not service with running user ?
what ? i not kill user in this game, but i just asking because someone kick me from service
50 min 4 flags and you are king oh yeah
Rules
ok, don't kick anything
this make me confused, if i play this game, and someone kick me
i just know flow this machine and i'm saved with command find
I learned the flow machine and was helped by memorizing a few commands
thanks for ur attention, please correct me if i'm wrong...
I don't have to see anything here talk to the staff I know
Thanks for ur attention and time π
π
thanks for help me ...
I just wanted to know the correct rules, and was confused by some of the things players did
so i say many thanks for you bro,,,
Totally possible π€·ββοΈ
ja
@runic shoal good luck, have fun.
It was the hogwarts machine bro that machine is not simple, also you have to list a lot
i mean i see Fan in alot of games i playim guessing he has played each machines before multiple time so he is experienced so it wouldnt be suprising that he can do that
who tf changed the password at the machine?
Iβm not in that game, but changing passwords is authorized
yes i know
Read the rules before using that language.
Are we no longer allowed to change passwords?
Read the rules before using that language.*
I'm on phone and just woke up π
Lol. Hopefully you slept well
oh man, sorry, thank you. ;3
an user, from koth, is allowed to change the name of directory root in .root?
or change the name?
No. as it might will mess up the king service
@runic shoal π
i leave, so have fun @fair adder
ty π
hey everyone, im in a koth lobby with one other guy. Is there any sort of chat for the lobby on the website?
@nova tide Not sure what's going on here but ^^
Nope there isn't any only here
Not atm but in the future there might be.
ahhh ok thx
You can always use wall
if both of you are in the machine ^
or DM them on site if they won't mind.
The game hasnt started yet and its supposed to be my first koth π
Well GLHF
thank you π
@nova tide
π
so?
LOL
it is allowed
would recommend reading the docs for koth and blog post if you are new to koth
check the pins ^
its ok.
Just give that a read:
https://blog.tryhackme.com/guide-to-king-of-the-hill/
Yeah that's totally ok
As long as you are not breaking the rules you don't have to worry about anything π
@obtuse heart feel free to @ me here π
For the machine you just need some basic enumeration to do.
Try running linenum/linpeas and see if something pops up.
Check for some suid binaries, if something comes up in that?
@nova tide thanks bro
Purplerose?
?
Why did u move wget?
Holmes said no moving or remove binary
then how comes i cant use cat ?
I'm not renaming anything
I'm not doing anything other than keep my username in king.txt
u changed cat
weird
Put wget back pls
Yes
Idk, I'm not doing anything to system binary
@idle harness You should probably report it, maybe they can check the box
Nope, I didn't
As I told you, probably should report it and see what's what
sorry for ping but how do you get a terminal on android??
I'm using termux and chroot to arch arm
i always thought you needed a linux custom rom
ohh thanks for the info i might try it out
Np
stell , you playing ?
Sure
anyone can join , 5 minutes
@delicate cedar link expired πΏ
I thought that was this one
yeah i juz found that out π
its fun in android noe ? no typo errors
If it's not hogwarts or fortune I'll play π
lol
public game in 10 minutes
hmm
the box wasnt responding ,
It's responding
hmm?
oof
@delicate cedar join next game
I give up on hackers haha
join next one
offline again
wanna exit ?
already did
@nova tide can you fire up fortune in private games?
π
oh ya same for me , 11 minutes for last hackers to finish
hmm
Any one able to join new public game?
Worked fine here
@delicate cedar playing ?
I'm doing some room first
send the link for next game @delicate cedar
@nova tide what happens to ssh service?
Public game
https://tryhackme.com/games/koth/17687
you sent the spectate link bruh
ok let me make this clear , removing chattr is allowed or not ?
its allowed
cool ok
howwwwwwwwwwwwwww in the worlddd
I give up
haha
Will you guys play another one ?
I AM UP
Okays
@nova tide You coming ?
nones playing spacejam ??
I left it
eek
can we upgrade sudo on all our koth machines please :)
Because couldn't get my name on king.txt ,it was setting the ia flags when I was removing them
i ve played many games , but i still dont know how to get the chattr file if its removed
like i could import it from my sys
but then how to use it is the prob
You have to upload a static chattr binary
then just use it like a normal binary
Which can be found on google
and how to do that
.
like you mean git for chattr and then executing it and stuff
You can upload that chattr binary from your machine after downloading it through wget or netcat after starting a python server on your machine
Yes
so i just write that in a editor and then give the permissions , then use it ? Right ? (compiling ) kk
fine
yes i have tried busybox ....
What do you mean?
why dont u see where he is doing that command
@grand delta holmes probably has his own chattr script
you need to find it
and remove that script
before it will work
Exactly
so basically what i did in this ss was right ?
Maybe
Wait what, I am not even playing today ππ
Yeah true
i save all the ss , for doubts ππ
this was like 2 weeks ago ig
Lmao, I am so surprised like wutπ€£
@cerulean maple You playing ?
Yes just getting my shell being terminated xD
You don't need to compile your own, you can download one from busybox and use it π€·ββοΈ
This one ^
umm , okay
Hmm, @stiff egret moving binary it's not allowed but naughty did it on my last game so I'm confused here
finally won 1 game after so long , oof
GG
Your history or other pts?
like i was typing w , who , ps aux | forest and stuff to see the people in the box but then one of them got to know about this
so how would he have done this
There's so many way to do that, maybe googling would help
hmm
Explain a bit?
Naughty moving system binary
we aren't allowed to rename binary files even though its in its path?
Just dont mess with system binaries, there are 2 instances where this is by default, 1. Hogwarts with vim and nano, and 2. Food with something that's a spoiler.
Other then that, don't.
Remember you are supposed to patch the machine, renaming system binaries is really not the way to do that.
@stiff egret can you explain wdym by "patching" ? what exactly comes under it ?
yo im in a koth with two other dudes, is one of them here?
type their usernames with @river lichen and check
doesnt seem like it π¦
Fixing anything that is broken and helping attackers gain shell, anything within the limits of rules.
cool
@stiff egret true ,but attackers gain shell through ports , so ig switching ports is allowed but closing port is not
wait you can switch ports?
someone said it before , you can move ports
Yeah, there are multiple blog ports on blog.tryhackme.com related to KoTH, give them a read, I think they cover mostly everything.
welp, doesnt matter anyways, were 3 ppl in this room and nobody managed to get access within the hour we had...
haha , which box
how do I know? lol
There is a name below IP address on the page
That word is usually the name of machine you faced.
too bad, its just over
still the name wont go , lmao
the best box is hogwarts bro , its too hard to get in
OH, well, that's one of the hard ones,
can I tell you what I tried doing or is it considered spoiler?
ik great
you know like , i have a writeup for every box but then hogwarts is like way too out bruh , its too hard for a writeup
||I found the /backdoor/shell/ prompt and figured if I make a cookie called SessionToken and fill the value with random chars it wont redirect me to the home page and I can stay ther||
||but I wasnt able to execute commands from ther||
No, because you aint authenticated
yea thats what it told me but I didnt find a way to authenticate
but was my general approach good/correct? π
nvm I just checked a writeup
thats so sad, I tried the same but with another username
well play another one then :)
idk man, im kinda tired now. that was exhausting π
also isnt koth kinda lame once you know all rooms?
I mean you can probably write a script to do get initial access...
.The fun is hacking against others in a race like environment
I mean if you do that you're breaking the rules
- That is actually against the rules, and some of the current boxes and all the newer ones are made in such a way that scripting them is reallly hard,
oh someone offered me a few, but I refused, so I thought it was ok to do that
Do give the rules a read before you play, so you don't end up with troubles :)
It seems Im really lost in terms of rule knowledge, youre probably right π
Edit: Rule 7, got it π
holmes when will new machines come
also can a non sub play a subscriber-machine joining by link ?
Oh there is one to be released (not mine) really really soon β’οΈ
Yeah ofc.
You mean in KoTH?
yea
Yeah, so if a subscriber creates a room, and shares the link, anyone can join in.
okay ..
https://tryhackme.com/games/koth/join/b43dbd6153240c2df2188a79
Hop in if anyone wants to play :)
Public match, starting in 23 minutes.
bruh
chattr?
yeah
Nope
ur not even on the box
Never take cookies from strangers.
OH god that is a LOT of shells you have open
there isn't any
hey send the link when you play
root under 15mins
wow
Had to kill the spy.
i rlly dont understand how ur running that command
Which command?
surely ur getting the nyan cat 2?
?
um, no

π€·ββοΈ it was fun, really. GG.
also, you can simply do Ctrl +C to get out of cat
Surprised you didn't figure that out.
lets play holmes π
3 minutes to go
dont bully me for gods sake π¦
GL
I don't bully lol
ah sorry , not you . naughty does π¦
i hope this isnt hogwarts
me too
bruh , you created it . wth π
hence I can't play that π€·ββοΈ
policy ?
it's unfair advantage
nah, but it's not fun in it for me
stoks
hows cat not working
lmao, no, the file is actually empty
ah damnit, there are less resources allocated to this machine, so my code is apparently locking the file so hard that it's getting truncated before king service can read it
gimme a minute, if I can fix it then all good, otherwise we reset?
Pretty sure I fixed it
where did you find this? do you mind telling
Oh no
π
u never heard of monitoring?
@stiff egret you there ?
which
read about chattr
alright ty
sudo chattr +i /root/king.txt when you get root
What's your name on the site @quick terrace

How do you suppress all warning prompts??
??
Gg @almihiza
Well, I managed to get on to Hogwarts as N******, found a pdf-related thing, and then the match was over lol
My shell was killed
Is killing shell alowed?
yeah
Ok
Do you mean output from errors?
idea for koth what if you were able to choose what position you wanted to be in like blue and red. if you choose blue you have credentials to the box and you gotta secure it while red is tryna get into it? basically thereβs not much to change the blue team has to keep their king service/maybe other services up and the red has to get in and take them down?
From what I know, that is the defination related to attack-defence game type. And not KoTH, although you can start private games with friends, and make teams.
ah ok i just gotta find friends now 
wanna be friends?
sure! lol
xd
@cerulean maple playing ?
Joined other game
send link
@stiff egret why dont i see the machine name
Surprisingly, I have no idea.
Just pinged skidy about it, probably some bug
Starting another game in meantime
Starting a private room
Starts in 5 mins
@stiff egret yo will play ^^ this ?
Your SANKALSPINEY?
yes ?
Oh ok?
sorry it resetted
Idk why
yeah
hope it isnt hogwarts ..
GLHF
any one joining koth
Public or private?
ooh
what
no not to you
no one coming ??
ah, again I am hammering it too hard
Sorry mate, not playing private games rn.
oh ok
exactly π¦
oh oh
lemme stop that
LOL
stop the hammering , asap π
do a 100 thread gobuster on it
Oh no, we are talking about king.txt file
found your thing , holmes
oh fine
which thing
i am going to do the complete begginer path
holmes , this machine is to ohard to defend . time is required
Stopped the hammer
yes
no
Check again π
like literally i dint type that cat king.txt . i was just echoing
haha , noice .
what is happening π
here, bombarding your pspy
Did your pspy got hit?
kind of ,
the whole thing is spammed with /etc/killall
whose trying to spam me π€
yes, who is spamming you
THAT was not me
"backdoor"guy
π€ huh?
u can be in two games at once?
Yeah, 2 is the limit
is that tmux?
yeah
where u get the config files?
made them π€·ββοΈ
ofc
~/.tmux.conf
cba to do it tho
/root dir OP
π€·ββοΈ worth it for the productivity it comes with
bruh why did you post writeups of koths
Huh?
?
(deleted my link of tmux configs)
if those aren't trust issues, I don't know what are 
GG holmes
GG
Just in case if someone is wondering why they can't message in this channel anymore, they need to verify with the bot.
what happend @stiff egret π
π€ what do you mean?
if the points are not increasing, or the king file is empty, site shows the last king as king, but the player doesn't get any points.
?
No, the file is changing really fast.
Whoever's code dominates, the file shows that for a milli sec, then truncates and again.
ok
What is happening? When I try to see that scheduled game it gives 404 and I can't join to public game
Probably something to do with the DO problemes last night
I thought THM moved away from DO.
what is DO
Digital Ocean, a cloud provider
From what skidy said in #lounge yesterday, more like moving away
ah damnit, can't take ss, destroyed my config of window manager
why join gives 404 ?
Right now?
no idea
Are you in a match rn?
18m to start
Can you send me the spectators link?
Rip, I don't know if other player on this match can play it
is it 17832 ?
Probably
6 flags within seconds @stiff egret
any idea which are those fake one's
Hahaha
for me the flags should not be static and change their place
I believe he / she has saved flags
the flags dont change?
for 100% sure
user flags also deleted @stiff egret
Been told time and again, flag hoarding is not against the rules, it's bad, it's frowned upon, but not against the rules. Yet
Now, that is a problem, check pins :)
is there a chattr equivalent on windows?
attrib may be
Yeah
i tried attirb still getting access denied
He was π
is back
@stiff egret
No flag has been deleted.
They were all in place.
My friend who's a student and got premium for six months took ban unfairly after 3 days for that.
He asked for logs.
@mellow bough ^^^
Pisika was banned for ban evasion. If you have a problem with that, you can talk to me about it.
@fair adder
Meowless has a perma ban
@gloomy estuary what's going on with this?
and, again, who is meowless?
I'll have their ban repealed, however, this entire situation is under investigation.
he's going to come in now
and talk to him
and @gloomy estuary
how did you come to the conclusion that pisika is meowles?
Right now I've passed that along to other staff
That being said, when I initially looked at pisika's account, there was an inappropriate picture for their profile
That's also a site ban
what's not ok?
It's been removed in this case and I've asked Skidy to repeal the ban
Pictures of half naked people are not okay whatsoever.
man
yes?
we're a group of students, and my friend took over 3 days ban, and about pfp you could write to him or delete his pfp.
I'll be frank, I don't have time to do that and cannot easily removed profile pictures. That bit is on you
I'll repeal the ban but beyond that I do not frankly care as the individual in question is still in the wrong.
@mellow bough This account uses the same photo that meowless used on his Instagram, and right when he got access to the machine, there was a user named 'meowless' in the users directory
Aight, that's more than enough proof for me honestly
It can be him, it can't be either. I don't really care
Just, do you have anything to say to this?
I don't know what you're talking about, pisika is a friend of mine, alongside rs6, and we are a group of students in cyber sec, we're roommates and this is the first time we have an account on tryhackme, he bought 6 months of premium tryhackme content and after 3 days he gets banned with no reason, if the photo was a problem you could just ask him to change it or remove it.
And
for the time being, I'm going to have the ban still repealed
ok
but this is flat out problematic and suspicious as hell
I understand this may just be a huge misunderstanding and still am willing to treat it that way
In my honest opinion this looks like crap and smells like crap. And I don't know about y'all but if something usually looks and smells the part, it usually is crap
Please be on your best behavior to put all of this behind ya
Just, do you have anything to say to this?
@mellow bough I don't want my name associated with the 'pisika' user ban, I was just commenting that I thought he was the mewless. Do not ask for a ban on it. Feel free to do whatever you want.
I'd like to see the pfp of his instagram account.
@fair adder please back off from this. The situation is settled as is and please just be on your best behavior
ok
The ban should be repealed here in just a bit, just takes a bit to do that change
pisika has the same characteristics as meowless to get the flags very fast
one question, did you guys banned pisika just because someone said it was "meowles"? and who tf is meowles
look mates pisika ban has been repealed as we donβt have enough to go off of @fair adder dark already asked you to back off so just stay chill and play their ban has already been repealed
: )
why are you smiling?
It's forbidden?
@fair adder I understand your frustration here, just please drop it for now.
Skidy isn't back quite yet, it shouldn't be too much longer for the repeal
Just wait for a bit, we'll get ya taken care of
he's going to take unban or not?
Hi just,
Not to step in on Dark or anything but the right people will be informed when Skidy is available.
As well as that, I believe your friend will be informed on the situation also :)
But then
When will the machines generate random flags for each time a koth machine is started?
I don't want to deal with someone getting 7 flags in 3 seconds
Not sure when that will happen but just go to king youβll win if you keep king for the game
Honestly, I play koth and I never called the king, I just care about getting access, root and get the flags
and for the fun of making fun of other players
very good
lol
@mellow bough Any news?
It's not your account, is it? IIRC, any/all updates are forwarded through email. @terse willow
Yeah, it will be handled by email if it's a site thing.
i think somethings wrong with this game
or im just wrong lol
Nothing is wrong, the box is made like that, try harder
ports started showing after a while
@fair adder gg
@stiff egret why is the machine so lagy?
No idea, you running pspy?
nope, is it my connexion or do you also have problem connecting to it?
no, it's smooth on my side, probably your VPN, are you using double VPN or something?
hmm nope but if it's on my side i'll check my network
Hop in people, public, starting in 17 minutes
"JustW" got banned for what?
It says why he got banned
Anyone who is banned, gets notified why so.
^
If they have a problem, they can sort it with Dark
If he want's to appeal the ban he can email jon@tryhackme.com. This isn't the forum to discuss bans
Okay, Thanks Sir.
I work for a living please don't call me sir xD (That's a fun little joke)
Ok Mr. :)))
Just to make this abundantly clear:
The people who have been recently banned were banned for a reason -- and a very serious one at that. If they want to appeal it then they can email. As Magna kindly provided, the address is jon@tryhackme.com.
I will not have any more discussion of it in here -- this is not the place for that kind of conflict. If you disagree with the bans then you can tell them to email. Disagree loudly around here, you can join them and appeal for yourself.
Hopefully that leaves no room for misinterpretation.
He did.
He did.. what?
He Sended a mail.
Wonderful. It can be handled there
As I said. There will be no further discussion of it in here
This is a public, learning environment. I do not have tolerance for people dragging conflict up
Ok, I understand. Thanks for your support.
Who got banned -_-
As muir stated above, this is not the place for discussion.
Which part of "no further discussion"...
Ok man it is not to discuss it is a simple question I do not think it is to start a discussion.
@delicate cedar Hello, congrats for your position in the KoTH leader board. It would be amazing to play a game against if you want ?
Sure, I'll @ you when I'm playing
We have got to change the colour of one of those ranks smh
So youβre a NCO, huh?
@rancid pewter
Hmm, ssh service seems broken
Nope, checked. Checking again
It says failed here, and ssh has no response
koth anyone?
sure
ok i joined a game but itβs gonna take 22 minutes how do we make it faster lol
we could do the private game thatβs gonna load in 5 minutes
ok
starts in 4 minutes
gl
i can't ping the box ._.
no me personally
sometimes i can ping the box and sometimes i can't. when i finally can and i get inside the machine suddenly i can't type anymore @stiff egret
i keep restarting my openvpn but nothing seems to work
Are you using multiple VPNs?
just openvpn
for e.g. some third party VPN on your host/ or from where you are getting the connection.
nope
Then either try regenning your VPN from /access, if the problem persists then head to, #site-support
:))
on each machines there are like 3-5 differents ways in getting in right?
Yeah
k
koth anyone?
Hop in, Public game, 12 minutes to start
@delicate cedar why did you left space jam?? well that one is easy
I'm changing my mind
Just curious you only play food,panda and offline?
Nope, if I'm playing with you guys I'm not gonna do it on phone, I was gonna turn on my pc but this is 4 am π
and i went tryhard for no reason 
@ me if you plan to play again.. its fun playing with you
π
dsdasd
15 mins
could i ask someone a question about carnage rq?
yeah haha i was wondering what happened @vocal shell
when is it starting?
1 mins
ah bummer, will join the next one, sys upgrade going on
ok
what kali version do ya use
Oh no, I am on arch
its either mobli or cryptomalware
and as far as i know you cannot remove these binaries , its just chattr
There are still lots of other ways to get your binaries on to the system
still , its not allowed is it
i just imported a lot of stuff using wget before you hopped in , maybe its the other guy
honestly it wasn't me, check with the other user
sure π , sorry for the trouble
no problem
Deleting is not allowed, but since it is deleted you can look for other ways to win this.
thankx naught , could you just ping the other guy about this .
gg @dapper yew
π»
π
@rancid pewter ;-;
Ready for some Tetris ?
oh my what have i got myself into

wdym?


