#koth
1 messages ยท Page 59 of 1
ye, persistence should always be first call before deleting other people's shells
i was about to chattr king.txt and chattr binary
I presume you got in through the ssh key on the webserver
and i got killed
ye, I regenerated them
i removed em
n authoratized_keys
ye haha
i change root pwd
everytime
but now i forgot
and i make python script
to spam
wall
ye
phew
hahaha ye
it basically writes
100 wall commands in second
you can't even see ps -aux output
surely you could just do pkill -9 -t python or something
or killall python
is the new sudo patched on the boxes?
No.
Whoever was that, you just killed the machine.
That is very much against the rules.
You don't know me enough to know when I am angry.
I was simply stating the fact that someone was breaking the rules and that this game is reported.
havent even gotten root since i got booted off the first time
๐ heh good job there @quick terrace getting those flags fast, my first koth, kind of chaotic, need a good process ๐
how do you break the rules? Was it me xD
What do you mean?
read the rules on site, they state the things you can NOT do in a public game.
Yeah, i saw someone spamming cheese strats, no idea what that is ๐
NP
ty @leaden kernel figured someone was gonna boot my ass out of there fairly quick
Ah, guess i'll have to read them, just thought of the obvious ones, not try to probe people and escape vms, kind of that variety.
You should read the rules before starting it. ๐คทโโ๏ธ Standard stuff.
"No attacking other users." that one is kind of loosely defined ๐
It's just that ๐
well ggs everyone back to class
Where is this?
What is "King of the Hill"?
It is outdated. apparently
Seems like it yes
Well well, might have broken one rule there well harmless imo, wont happen again, "its only game"
Harmless to kill the box entirely?
Well it goes up again ๐
I mean, as long as you don't do it again no one can fault you really
Actually, not to step on anyone's toes, but they can
Yeah well, was a shitty action, gotta admit that, and im sorry, read the rules now ๐
Gotta say the urandom redirecting to pts:es and terminal crashing, i guess that is common eh? ๐ almost more annoying than a few seconds of downtime
It is not same for all boxes, the boxes that have randomisation will not work after reboot.
Awh crap, well what is done is done ๐
Yea should probably have read the rules ๐คฆโโ๏ธ
I'll take a ban if it comes to that, probably re-register anyway ๐
You realise that site ban evasion is uh... Very much frowned upon.
It's not much of a ban evasion if i'm not trying to evade it and even re-subscribe. What kind of punishment would that be if users wouldn't be able to mend for their wrongdoings ๐
It's generally just a firm warning for first timers. IIRC.
If you're given a site ban and you open a new account, that's ban evasion.
Most likely but anyways, im fine with loosing my points
Okay profitable ban evasion then
How about you just drop this and not break rules in future? saying in your benefit mate.
I'm not arguing ๐ yeah i've already said i wont, by the way the instance restarted several times, i only quickly rebooted it immidately almost by reflex when i saw the command injection in the python script ๐
Creating another account to avoid a ban is ban evasion. I don't know why that's up for debate at all.
Ban evasion is also a community ban.
Okay fine, then i'll just leave then if it comes to that.
Let's avoid getting the ban in the first place.
I'd prefer that, sorry about that stupid mistake. Should have known better ๐
(Just for the record, ban evasion on the site is slightly different to ban evasion on Discord. Ban evasion on the site means that you're technically breaking the law by "using a computer system without permission" -- and could be fined accordingly. Criminal records are not fun if you want to work in cyber, especially if it's for a cybercrime)
Regardless, all cleared up now
It's handled now, but essentially by banning an account the admins would be stating that they do not want this person to be allowed to use their systems. If the person then proceeds to make another account to circumvent the ban, they are using the systems unauthorised, which makes them criminally liable.
It's the same thing as sites that have a "You must be 18 or over" notice on them
If you click past the notice but you aren't actually over 18 then you're accessing a computer system without authorisation and could be prosecuted for it
Right, so it's technically a criminal act, huh, the more you know
Technically. I've never heard of anyone being prosecuted for it, but companies would be well within their rights to
Neither will you be, i seriously doubt a company would spend time and resources on petty cases like that, if its a re-occuring event that's making the company loose money, its a different thing.
Perhaps to set an example in an odd case ๐
With that said it doesnt make it right, so theres no confusion here ๐
anyone still playing?
I mean, it's a criminal case, not a civil one. The company doesn't lose money from it -- all they do is phone the police and pass along the information they have on you ๐คทโโ๏ธ
Regardless, you are correct to say that doesn't make it right and leave it there ๐
https://tryhackme.com/games/koth/join/a00e3fb640400c94ffb3099e 10min @nova tide
did naughty play ? who won ! the link doesnt open me on any page .
unfortunately Naughty didn't join in
saw the link late
Hop in, public room, starting in 13 minutes
@stiff egret sorry i had tg, my food coming in a sec ๐ฆ
NP :)))
hey @stiff egret , whats up
Hey (:
Perhaps not related to this channel, but has anyone used kvm switches? Thinking of setting up a dedicated box for these challenges, i dont feel like sitting in a VM doing these challenges, and dont want to use my main box either.
you can use attackbox
Thats like sitting in a VM that has been placed in a bowl of oatmeal, it's great and all but id rather not use the browser either ๐
Using a KVM switch would be kinda nice, beeing able to switch my keyboard/mouse and monitors to second computer.
Yea i'll ask there instead ๐ thanks
@runic shoal you need to verify with the bot to text in this channel.(Check the pins)
I'm here, thankyou for your help @nova tide
@nova tide do you use tmux ?
yeah
@nova tide koth ?
already in a game.
tell me once its over . ping me
join the next one
How large is the pool of machines in koth? I've played two koths, it was the same challenge. Nevermind, it says it on the page, so 10.
@nova tide box getting hamered

so messed up , oof ๐จ
what are the top ps
huh ?
top processes
i dont know . i dont even have a shell . someone kicked me and keys throwing error now
what error?
anyone in my game?
it asks for password . tho everythings set up correctly
@raw wigeon reset machine plz
oh now i see why the box is laggy
is this game working for anyone else
now i got the ports
vm
nvm
k
did you just close port 22?
no?
seems like it
No port 22 ^
you are the only person root though ๐
weird
If p0isson is telling the truth, I redirected someone to your emails who had a similar issue, they could not provide proof that the other user closed 22 but it was closed, Naughty.
@stiff egret ^
it can't go down unless someone does something..
but nvrmnd the game is over, GG
gg i guess
are you here?
20 mins
@delicate cedar I give you the victory, I will sleep
Hmm
gg
I'm nervous
First time we play against
Well, you did wrecked my team on htb battlegrounds haha
Alright you found out my little trick to block the king file now time for some chattr
Your lucky that I dont have my rootkit anymore
Time to pull of the big script let me introduce you to king-brute 50 thread in 4 process so 200 thread constantly writing my name in king.txt
The box are gonna be destroyed
No way just doing a cat of king.txt take like 5 sec to return nothing
It's hanging here
Box is not slow for me except when interacting with the king file
it takes about 4 sec to just cat or cd
hold up
pts/8 ?
Ohh that why it wasnt working
still not working
I'm gonna do some improvement ๐
Your king has came back after a long gone to win another game ๐คด
You shall join ?
?! What happened to your root kit?!
Whats the difference of rxvt and xterm? Can you explain to me
Ty I will check it
1 minute , pub
ah , windows ๐ฆ
Is it allowed if you have rooted the machine to disable ssh? So that nobody can ssh into the machine?
||you can change the ssh port , not just remove it :)||
Check dm
You should really read the rules, before you break one of them and get a warn/ban.
Yeah I read it, but my English is not very good. I didn't see it. So that why I am asking
Ok, just to clear the confusion, please do not stop services that are patchable, the aim is to patch the machines.
holmes , you down for a game ?
Sure. I was about to start anyway.
cool , just put the link .
It's shady portion. I'd say don' t do it. You can patch the machine in other ways.
Kick the users off the machine, change the password, regenerate ssh keys. Stuff like that.
Ah ok Ty for everything
NP
https://tryhackme.com/games/koth/join/17890a7dc0c73f8e5bc6c67d
Public game, starting in 15 minutes.
the max guys allowed is 10 right ?
Yeah, 10 Tops
Spread the link around, ๐คทโโ๏ธ More might join, It's also a timezone thing.
big portion of those who play is sleeping rn.
i will put the link in general ๐ ?
๐คทโโ๏ธ uh, don't
really ? oh . welll here its a good time
Which country you are in?
INDIA ๐ , haryana
Oh great, same here. ๐
noice.
Good luck.
hammered ๐ถ
๐ what can I say, I love sending wall messages
whose pts 10 ๐
LMAO what did you do?
let go ๐
๐
just see the shells my god
pkill cat To diffuse the urandom missile
which one ?
accidentally used the default chattr
how is this happening ? the king file
no i dont mean hammering .
i am removing all attrtibutes. but as soon as i write my name , they come again
that's just loops, loops are obviously faster than you typing manually.
I think we should reset the machine, considering the code I just ran, eh, kinda broke the machine.
holmes lol
holmes lol
holmes lol
ban holmes
If anyone suspects that someone is cheating in a KoTH match, please email: koth@tryhackme.com.
Please include your game ID, username, username of the player you think is cheating, what they did / any evidence you have of them cheating
stop using my tricks on me
ban holmes
no holmes here, wrong room, go away
lol
Third koth, third Production haha wtf i should go buy a lottery ticket
Did you bork the machine @stiff egret ? ๐
Nevermind, got slow there for a minute ๐
๐คทโโ๏ธ
wha-?
๐ป
@stiff egret i am getting error . i am not able to join any game
site under maintainence ?
Refreshing should do it.
got it , thankie ๐
Yeah, I got that too.
King was only locked with chattr @stiff egret no extra protection mechanism in place? ๐
Been told again and again, flag hoarding is a thing and players do that, but that doesn't mean autopwn script.
Flag hoarding is only possible because flags are static, not for long.
Aren't you supposed to take the flags again once you've completed the machine once?
๐คทโโ๏ธ can't leak the secret
Flags remain same, so players reuse the ones they got last time.
Ah, thats what you mean, yea thats a flaw ๐
But passwords and rsa keys are changed from boot to boot ?
no i dint
i have the flags with me !
i know this is wrong but then what about the people who get king in 10 seconds . cant help , sorry
not on all boxes, but the newer ones, like Hackers, fortune or Hogwarts change.
kk my bad
Sweet, would be awesome to see the setup behind this infrastructure, just recently startled to fiddle with Terraform and Esxi myself.
At least for hackers and fortune, it's just a reboot cron bash script
As long as it does the job, startup scripts are fine ๐
Same thing in hogwarts, just a little longer as it's randomizes pretty much most of the stuff
Cool, theres no way to develop these koth machines as it is for regular rooms ? (As a regular user)
What do you mean?
May be i misunderstood it, perhaps they are user submitted? The koth machines.
Oh yeah, anyone can make them, they just gotta be koth machines, so essentially, 4 times the normal machine, (4 footholds, 4 priv escs)
Ah yeah, i need to learn how to read, says it quite clear on the develop rooms section ๐
alright , its no fun being alone in the box , username you guys should know and the password that i have changed is " pandaismyfavouriteanimal " .
for who?
ssh
which user
username you should know
ur lying
tell me lol
mhmm
oof
am i allow to remove pty ?
are you pubg?
yes
lol , my fingers broken after this rose
nice you was fast
did you actually guess the root pass or what
i tried to bruteforce shifu, but you already changed lol
i see , what did i miss patching
yep , gg rose
want the scripts?
nah , copied all , thanks ๐
ive got better ones lol
ok
is streaming KOTH allowed ?
Have you read the rules? @dapper yew
yes . it says it is allowed but then i am not able to do it in koth voice channel
wtf i can use ls
Still got the source code of it but I need to compile again for all kernel header and linux distro of KoTH box. Way too lazy too do it again.
Check your PATH or someone might have deleted binaries
port 22 isnt even open
Might have been changed port
Full nmap scan
k
https://twitter.com/RealTryHackMe/status/1357044988165685249
Is this challenge using a new machine?
Yeah
yep no ssh ports
Port 65531 actually
So the goal is to be the first 1-10 to solve the challenge?
idk how much i can spoil that ^ nvrmnd
Actually i never asked that ๐
I'm confused of how the invitation work
there will be 3 machines(easy/med/hard), and you can play one at a time.
Selecting the winners is on admins and others.
Let me confirm that for you.
Weird it working for me
Hmm, so it doesn't matter who first to solved the machine?
Try again I just restarted the ssh service
Yeah just checked there no iptables rule on the box
But yeah ls is missing on the box
i dont know whats happening tryhackme says im connected to the vpn but i still can ssh
Make sure you only have 1 instance of openvpn running. Also you could try starting THM room and see if you can access it to make sure the issue is with the VPN
i can ping the machine
I really have no idea sorry
my vpn is fine
Grr
Doesn't mean anything to me.
;-;
Don't complain if you're going to not take help.
what?
You said you had an issue, I offered a solution, in order to troubleshoot a problem you need to find the cause.
the solution u gave me wasnt the issue i had
What was the issue then?
And..?
wdym and?
i couldnt ssh into the box
that was the problem
i didnt know why it wasnt working because my vpn was working so why wasnt the ssh port working?
There are plenty reasons for not being able to ssh into a box.
How do you know your VPN was working?
Because you could ping?
i check on tryhackme and it has a tick and also i pinged and it was working and also i check the vpn it said it was initialized
Ignore the access page
surely if i can ping the box then my vpn is working
Not always.
thx anyway
Started yet?
4min
10 mins , pub
Is there a way to report players who are obviously not adhering to the rules of KOTH?
check pins .
thanks, will do
๐คทโโ๏ธ
the king file cant recognise the king anymore hahaha
It is, it's just when the site is reading the file, my name is in it/
when does the site read the file .
Every minute
The points increase every minute.
what if the points are same
Oh @stiff egret Can I DM a sec?
Sure :)
TIME ?
after 23 minutes
you sent the wrong link brotha @ebon heron
join this , 15 minutes
@stiff egret the banner is not getting displayed while sharing the koth link . everything alright ๐ ?
im coming
whats your name on site
aboodking
whats wrong . then
you have a lot of vpn connections running ig
you sure ? becuase when you have 2 that happens
i recommned you to just kill your vpn and connect . pc restarting and all not needed
just do pkill openvpn twice or thrice
ok
and connect again , everything should be fine
!multivpn
Make sure you have setup your VPN connection correctly https://tryhackme.com/room/openvpn
Type ps aux | grep openvpn into your terminal and press enter
If there's more than one line (that don't start with "grep" or sudo), do the following steps
Type sudo killall openvpn into your terminal and press enter
Start the VPN with sudo openvpn <path-to-config>
@ebon heron you able to come in ?
naughty , koth ?
see put the koth
umm 
i cant mention purplerOses's script everywhere , can i ? ๐คฃ
you up for koth ?
Send the link
skyent wbu ?
na doing hackthebox
okay !
um . join this link , its a pub game in 24 mins
meanwhile , lets play a private game
oh no , i can just do 2 games at a time .
maybe you try sending the link
Joined
ok but 22 mins who will wait . meanwhile i am already in a game
just come in that
18 mins left for it to get over
someone said " na doing hackthebox" 
wow
Nothing is patched btw .
plz no kick
+1
yes okay ,
CAN I JOIN

fast rose
cuz i joned
yes why not
sniper
mean
we need connect to vpn
yea . too much importing stuff going on 
right
hehe , you just imported a hell lotta stuff and thats gonna cause me harm 
lel
who kicked
does that matter ? ๐
of course no
i love indian
people
iknow soome words
ke sahe bai
means how are you
i think
snipe are u pubgboy?
hehe , right . but i dont think the mods will allow us to talk here . you are welcome to DME me ๐
Keep it to english only @ebon heron
ok sir
doing what ? 
king.txt
its magic its magic 
you call me crook , ofc i wont 
gg anyway
can we delete useless stuff
systemctl restart sshd
u change ports?
what
i dint mess with anything
its fine
@nova tide Sorry for the ping , deleting useless stuff is fine ? (same error i got)
uuhm, I'm playing koth with someone and they're resetting the machine as much as they can
I don't have a proof of it so please join if you wanna see it
can someone check ? because as far as I know, doing so is against the rules
You can check the pins.write a mail. It helps bro.
try now, they might not be able to reset now
i think it's not supposted to remove flags if there are any of them there
it's against the rules
now I can't even write to /root/king.txt after you joined lol
did you do any trick ?
you or flowito I guess
i just joined so they can't reset.
oooooooh
how does that work tho ?
nvm I'm dumb
the game froze for some reason
I've bee a king for while
and it still says 18 minutes
the points also froze
anyone up for koth?
koth ?

rose you wana play ?
actually . let some more people come . 2 is not fun .
5 minutes , public , many people are there .
i am root but still cant write my name to king
goood
weird
yes
is this some sort of error in carnage machine or its made like that
no one is king.
sky .
even couldnt get king right ?
but you got the flags lmao
That default on Carnage. You might want to learn what is chattr.
Been having that same issue lol
Same.lol
@fervent reef was thtat u lol
lol
gg
intended
๐ first time I played carnage.

Anyone for KOTH ?
24 minutes , public .
i dont mind giving the changed password for the user . feel free to ask
wow
you do that always . dont you 
meanie
wait . wow for what
yestarday , you were king . i was struglling to get shell . you killed me brutly
i was tryna patch the way u got in
nay , other than that , you killed me everytime
no .
why
idk . ๐คฃ
?
i knew only 1 way in this machine . i want to know more ways
u scared ?
i think ur scared to count to 30secs
๐ sure
first thing - never buy any of these 'i think ur scared to count to 30secs'
why would i do that
bc it gives free cookies
haha i hate cookies
it gives milk?
i dont like that either
ah ur so scared u start spamming
well i beat u lol
well done
i just wanted to kill ur shell then leave
oh , cool
have fun isolating in the box
finde, lets do this . you come in the machine and no killing shells
only defending without killing
how bout that ?
do u even know how to kill peoples shells without using my script?
so now what
which one ?
what is it?
send me
koth!
come play!
Public game if anyone is down: https://tryhackme.com/games/koth/join/b5fa68112cdb366a53f01045
Joined 
killing shells isn't allowed? That seem to happen in every single koth ๐
what are you talking about ?
ok i got your question now
umm
. we were just doing deals because it was getting boring . both of us were kicking each other out . so we decided not to

1 minute , public
Ahhhh i see, spicing it up! ๐ thanks for the answer
hehe , you free to play now ?
Sorry, gonna make some dinner ๐ im up for it later though!
sure ๐ , just ping me
21 mins , public . hop in
17 minutes
Oh right, the anti-swear bot ๐ that was a shi**y koth ๐
lol
Each typo on the VM is like a cog breaking in the head ๐ need a dedicated box for this stuff heh
-warn @leaden kernel Please don't evade the swear filter
Or don't
-warn 210470799394471936 Please don't evade the swear filter
โ Warned frazzet#0608
There we go
15 mins
yo . get in . no fun being alone
so , doesnt matter , does it ? ๐ ๐
how tf are you 0x2
dont judge anyone ! ๐
@fair adder language(PG13).
Man you are a smurf xD
ok sry
๐ง
Naughty stream sniping ๐
Not like you ๐

jk
i just joined the vc, not watching the stream btw
lemme pick up the order from downstairs brb
No one talking 
no mics gang xD
you can join in and start talking and others will as well then
what the hell
?
who changed pass and stuff , lol
lol
naughty speaks up ๐
i can talk when i need to xD
GG
๐naughty , out of a sudden how did you come
17 minutes late i think ๐ค
2 mins
passwd changed:(
i can change it back if you want, but would be a better idea to find the other possible ways ๐
anyone can take part uh ? @nova tide
i'm not sure yet about the details.
i dint understand that room you know .
i think its for limited people
@nova tide bro do you mind streaming ?
what you want to see?
woaha
wowww
direct root
i mean i have the same script .
i juz dont know how to terminate it
background it?
idk what is your backdoor.
@delicate cedar join the game .
๐ง
@delicate cedar i think we broke king file 
@fair adder tell me one thing . how does me hoarding the flags cheating . i mean isnt it allowed . tho its wrong .

It's more like the box getting hammered ๐
I can't even get in the box
why cant i change the root pass
xD
@delicate cedar can i dm?
whats happening the box , damn
Yap
@delicate cedar @nova tide the ssh service isnt working anymore . can you reset the box
no i just removed your ssh key
no , even the root login pas not working
you can't change the password either
and what about the root login ?
thru ssh
its enabled
but still i dont get in , i mean i dont get to type the pass
its stuck here from so long
someone moved systemctl?
uh , its not wokring
um ok
well you are the one who was editing ssh config anyways
i tried but i cant get reverse shell
but i dint do anything messy
just permitted the root login
thats all
i won , unbelivable LOL
RIP, I forgot to submit the flag
๐
flags don't really matter. If you have more king time it feels like a win anyways ๐
๐
๐คทโโ๏ธ
use -p-?
before you get frustrated and report people please confirm if you are right ๐
Always a good idea to run a full nmap scan ๐
i just did rustscan . oh shoot
anyway i dint report anyone .
but doesnt rustscan scan all ports by default
?
i asked in theris server . they said it does and thats why i switched to rust
i don't use rustscan
5 minutes
PRIVATE GAME
does the creds remain same in fortune machine ?
Nope, they didn't AFAIK
Speed can lead to inaccuracy. I believe Rustscan is meant to be accurate, but that isn't necessarily always going to be the case. You never know how the target will respond to being battered at high speed.
yea , will take care of it next time ๐
who are the guys from the panda koth rn ?
23 mins
you go hard on the koth, love to see it!
y do u change the ssh config ._.
can't thm staff make it illegal or something
-_-
i want it to be illegal ๐
what ? lol
changing ssh config
whats your point ?
by changing ssh config, you can't get into the system
expect reverse
shell
that can also be disabled somehow
um . see
disabling the ssh port is not allowed .
messing with sshd config if very well allowed
you can change the ports
๐

oh i got your point
your telling me ?
oh lol
yea i juzt created a script for rev shells . iam prepared kind of ๐
I'm too noob for koth ๐ญ soon tho! once I finish beginner path I'll try them out ๐
bro you are 0xA
your A wizard wdym ๐
bruh
i am noob . you both should teach me
i did almost every easy walkthrough available for free on thm and that got my wizard
i practice koth machines with my alt account ๐
lol
you are a smurf lol
๐ no
i will play with you ๐ . dm me anytime
yea cool
20 minutes
2
๐ why , what hhappened ?
yes
๐
GG all
well , its not finsihed yet actually
if you want to come in the box , dm me . i will tell password
๐ no worries
tell me password
7 minutes
Someone ghost pinged me? ๐
i did for asking link for that error of no space left on ssh
i scrolled up too much and found
๐
25 mins
i am playing continous koth since 12 hours

fun .
