#koth
1 messages Β· Page 60 of 1
he called u slow ;-;
@ebon heron tell me when you play more .
oh , dang . π
message me when you want to see something which is patched
i will make it normal . π
probably , i am home alone . i am playing since 13 hours
ok i will text you
you playing one more ?
Intended
I would have thought after the first few times you'd stop because you realise your token is bad...
i mean i still dont know how did it happen
because juz before this , i got the shell , it was working
same problem
It's one user account, there can only be one session
oh thats why
7 minutes
please read the rules . before reporting π
You can always put your own binaries on to the system. chattr is the most common one of those ^
wraith , chmod too was working fine .
@dapper yew I don't think u cheated
Gg
pl tell how did i cheat
π π
do you think anyone cheated?
No
why was there a lot of swearing in the box regarding reports and stuff
was it you or the other guy
No it was not me
10 mins
lol @obtuse heart
While true:do echo wraith0p > /root/king.txt ; cat /root/king.txt ;done &
Does it remove anything?
No i think
Wait ill break my loop
I can 't even cd in home π
see the margine 
This is my first time playing koth
I have one issue
I can't able to connect or nmap scan with the ip provided for me
Are you connected to the thm vpn? I can communicate with the IP
When I tried to connect it says exiting due to fatal error
But, when I refreshed the page it tells that I was connected
Looks like a vpn issue
Yeah, it tells the same again
Exiting due to fatal error
Can I share the screen shot here?
Yap
Okay
Sorry, I will ask in #site-support
@delicate cedar can I DM you?
Sure
π¦
hi
yea i m not able to hack tyler machine
in koth
Uh, enumerate harder, try more methods, endpoints. You'll get it, it's a fairly easy machine.
wait see this
can you pls tell how can i find where my upload is saved on the server?
it had a upload directory
but i can't find where it is
i upload a php reverse shell
but can't locate it to run
;-;
hello sir? @stiff egret
- No need of sir,
- Have you solved other easy/medium boxes on tryhackme? KoTH is not for beginners.
yes i have solved some
Give this a read, might be of some help.
i tried ssh, mysql, smbmap, client shares,
wait ill see
@stiff egret do you know how to do this π ?
to find where the upload is located
after uploading the php
You find the uploads directory by enumerating more, I can't spoil KoTH machines here, the best option you have that I'd suggest is try out more easy/medium boxes on site, and revisit KoTH
so upload and uploads directory is different :0
interesting
i forgot this one lol
machine ded
ill try again
xD
Good luck :)
it's fun to play private koth w/yourself lol
π
there are other people talking in general so i don't want to disturb them
btw your binary named myfoot was breaking the machine
yea i removed it
while i was going to check it you removed it
π they are the names of the people
@blissful kettle first time seeing you in koth 
I never really play it everytime I join it I have to end up leaving 
everyone prepping for the tourney
hey holmes , i aint able to stream in koth . can you pl figure it out π
looking into it
did you find the issue ? π
Muiri and Dark both are offline atm, and IIRC they are they ones with perms to edit channel perms.
DW I'll ping them once they come online. :)
okay sure π
@dapper yew I think you can stream now, give it a try?
oh ok
@patent badger reading rules would be really helpful before playing koth π
I'm going the long way round WP for the win 
oh i got foothold with that too π
Too bad it's so slow
once someone fires up pspy / their king hammer, the machine slows down
Reee I should play koth more
It's fun ngl
Because I have no idea what i'm doing most the time lmao
just kick em off
From what i've seen all I see is Donut catching people in Tetris

don't elevate your reverse shell and you are tetris-free
he can only make you play tetris if you have a tty.
I just accidentally lost my shell by doing ^c when trying to get into king.txt 
If you are new to koth reading the blogpost will be really helpful
Yea i've read it
all binaries gone
Nope id is gone
no i mean listing stuff in a dir ? how to do that
echo *
works
there are still some system binaries that cannot be removed
after 5 mins
Heads up, I have them too
I keep asking dark to remove them from me though
you opened yourself to pings now
Only from you π

Is this the first time you used an emoji?
Could you perhaps do anything more fun except constantly killing shell if you're here π
I mean it's not the best tactic
but i was winning like 100 pts diff 3 mins left
and is it illegal i dont think so
this is my tactic myabe you have another tactic
You could patch the box, then kill shells just once to get everyone out
i already got full control with 6 backdoors
So patch it
Prevent people from getting in
Don't need backdoors if you gen SSH keys and patch all the things
for the next time
Nah @ebon heron different game π
Somehow i am unable to remove file attributes, need to study some i think ..
25 min
20 mins

cuz im at koth now
when i coonect the box
he kill so fast
is there is a command to kill ip when get connected
nvm guys
The kill command relates to processes and jobs. So you can't kill an ip, but you can block it in a firewall rule. Probably not something that is allowed anyway in KotH, but that would be my learning lesson on that. π
how to install chattr
That's the best one can do in their first game π
10 minutes .
i know
get on the next game
wait . let me understand how you did this
everythings patched in this box . @delicate cedar
hmm, I'm still have access
i guess i joined late but no problem, 5 mins left, will you guys playing again ???
leave that box π€£
give me root access
Oh, I thought you were talking the last game
yea you can join the game running and the next one too
nay , the production
Is it really has been patched?
yea check it .
i joined like 20 mins late .
||no sudos or suids to exploit left . :/||
admin
Are you already on the box?
ooops was there any other ??
joined this one
btw found nothing
We are in the same game
did you use the id_rsa?
yes i got connection reset
The ssh key not working or something else?
gosh . what is that .so file . π°
nooooooo........ at the last moment i start understanding things and room gets over
c++ will give you a hard time to see what is doing
Please avoid posting spoilers in chat. (I've deleted your msgs that were spoiling the box.)
anyone koth ?
spectator link?
there ya go
another one ?
Whoever is in my game, king file is broken, someone is using rookie hammer on it.
i already gave a reset
the points are just bouncing , smh
my king time was only counted for 6 mins .
so the king file has been empty for 37 minutes , MATH
Whats your point?
i mean who was the king for 37 minutes
No one, the file was broken, hence empty.
yea thats what
is there suppose to be a king.txt in hogwarts box
It's not there by default. You need to create one.
In /root/
Also avoid screenshots that are showing flags.
k sorry
what level do you have to be to join a public koth lobby
Intermediate
how do you get to intermediate
Go to your profile and change your level
@nova tide if you are on machine, can you post a screenshot? M on phone
go to your profile -> About you tab -> scroll to the bottom and change your experience level
Thanks!
https://tryhackme.com/games/koth/join/a83f5624271a91e626bd5f71
Koth starting in 10-15 minutes
Machine: Hogwarts
Huh?
nothing
the question is, why are you restarting ssh.
I didn't use that one anymore
but, again, why were you restarting ssh in that one?
It's not reqd, it makes the code redundant.
Spectator link ΒΏ
Score.?
Ah, forgot to submit flag -_-
Had to submit them, was afk for 15 minutes in the start of game
Yeah, didn't see you in early game
I actually forgot that I started the game, and went to make coffee, π
Pro move

anyone down for koth
Public starting in 23

oh wow lets play
Why

theres no fun playing then . he just kicks no matter what happens 
@harsh obsidian rm the link bro . 
or wait nvm . just put the link , sad people 
@green axle did you create the skynet room
damnn . my machine was stuck . i couldnt play
Not too late to jump in
why reset ,
good question
wdym π€£
We said not to kill, it's a few minutes and there is already a king
so fight to get king and take it away
why the ... do you keep resetting the box?>
Please don't reset
@green axle are you the creator of skynet room ? π
Who resets the machine?
No
I retire from this game
your a subscriber . create a hackers box . no deafult kings . π
what
I play in the next round
ok i am leaving the box
It is now 11th reset r we playing game of resets?
The worst thing is that they reset it and the password does not work
exactly
thats why i had doubt that if someone was actually changing the password or the password i have is wrong
yeah that was some bs
@dapper yew king? Wtf
No i retire
i really forgot
@green axle playing ?
what , bro you playing ? @green axle
password changed
oh lmao . i thought you quit
π€
π
where else to write
Done
okay .
Password changed
password changed for what ?
You can still get there
get where
To king
are there plans to patch Baron Samedit on some of the machines
I've found it's vulnerable on a couple
but I imagine it would be a lot of work to patch them
so I don't know if that's feasible or not
There is an overhaul pending from a long time now, but I don't see that happening anytime very soon.
but soonβ’οΈ
right, so if it happens it'll come with the big overhaul which I've heard whispers about π
Some of the creators who made the machines have left, so it'll be hard to patch them
yeah, most probably that one.
the bug's gonna be there until one from team takes a little too much caffeine one day and go on an upgrade spree
Ah right
well if you point me in the direction of the right person's donate a coffee, I'll see what I can do
π€£
I mean, is there a reason for it to be patched in KoTH?
Because you can patch it yourself if you're king
that too ^
we can treat it as by default vuln for now as well π€·ββοΈ
More paths, good thing IMO
agreed
You just gotta stop them from getting the shell, patch the footholds and done
if there's 2/3 methods in, it can be very demoralising when you have a foothold if you know the methods have been patched
so more is better :)
IIRC mostly all creators left some ways in that aren't discovered yet
this sound like some god ancient mystery 
π
There's one in Fortune that I've yet to hear anyone use
for foothold or privesc?
Foothold
I am CURIOUS NOW
@stiff egret wanna try find it with me?
I think I know that one, just checked my notes,
@terse willow Can I DM?
I HAVE TO CONFIRM IT NOW
then sure
I've heard if you ping him enough times
I'll die of suspense
uh there's a button that pops up when you right click anyones name and you are lead mod
Wanna guess it? Starts with 'B' and 3 chars long
for legal reasons, that's a joke people

mhm you are getting there

I am pretty damnnnnnn sure this is the one
but I need the confirmation god!
please give a vague hint , curiousity here as well π€ , even i think i know it π€« (not sure)
I need to confirm with Muiri that IF what I know is right or not
fine then shall i confirm " what i know" with you then ? 
Sure
i will dm later with ss π
@delicate cedar when did you get 0xD
I don't know if I'm just being blind
but weren't you like 0xA the other day
Hmm, not remember exactly
0xE when tho
he's going at such a rate
0xF is probably not too far away
@proud trout @delicate cedar can you do the koth and voice call?
i'm big noob but I did say I'd try it when I got 0xB so why not
umm, I'm a quite guy
no one in voice not gonna be alone in there >.>
Go for it
Ah damn I checked for Panda, just reread the chats and realised it's for fortune. Will DM you when I find that one remaining foothold
@delicate cedar add a ; clear; after sleep in that loop
Oh, okay
gg!
@stiff egret time for fortune then? ;)
Sure
I'm pretty sure the other folks on this box aren't actually playing....
Public starts in 12: https://tryhackme.com/games/koth/join/711ec26a59ab90e39529ca59
All the best
this one
^
woah
you left this match right ? π₯Ί i was with full prepartion
Uh, today was busy, some problem to resolve every 20 minutes or so, joined and left many games
lol, been there
That was slick; you bypassed chattr somehow
No, I used a normal root pty
someone was doing this, +10 for effort
Someone was killing my shells hella fast
Oh I know, I had to move pkill binary for a minute
that crashed the loop
then placed it back
lmfao
lmfao
what is this?
Private or public?
someone uploading deb files in the machine to install π
oh what is your THM username?
aboodking
ah ok
im new to thm
All the best :)
im trying to get better
That's the goal
That is what this platform is all about. And thank $Diety for it!
Gonna be tough competition in the event ngl
yeah, that's why I got surprised
Yea especially with some hackerone people coming over gonna be challenging
^^^ I hear the boxes are very very web based, so bug bounty experience will surely be of great help
holmes is this right?::while [ 1 ]; chattr -i /root/king.txt; echo aboodking > /root/king.txt; chattr +i /root/king.txt; done
Yeah, but if someone removes that chattr, your shell will be ruined
add error handling, smthn like 2>/dev/null
https://tryhackme.com/games/koth/join/f16a17c63dbc5fa3679540d2
https://tryhackme.com/games/koth/18704
3 minutes, 4 slots hop in
oh what is with the system
all machines in last 5 matches had been either tyler or space
space jam again??
yeah
smh
this is like the easiest machine in the entire pool
wow that was fast patch
that's the fastest patch i think i've ever seen.....
no, it was just slow to come up
Wasn't expecting both user to have the same flag π
lol
π
spectator link ?
hot game π€£
yeah no idea how n0beard is taking king from time to time
Oh no
also, for those who are starting new matches
lol
That makes the machine slow iirc
I am sorry before hand
no, use it with proper arguments
shhhhhhh
wrong link
if you join from public game, you'll end up on that one
yea i am joining next pub game
the thing is that i forget about it and start doing some room
no idea who was that but you killed my backdoor
damn man, nice spotting, whoever is that killing shells
Really, pkill is not the way.
killing shells is so annoying
I'm just trying to figure out how to get king π
10 minutes . pUbLiC
so so so annoying, easy bypass is finding some method to hide your pty
yo what did you guys do to that innocent file
Honestly I have no idea how I am king rn
Reee
I stopped my codes for king file, no idea how I am king lmaoo
I mistyped it 
I was like wait a minute


i still dont understand that sh -c thing
?
that sh -c
no idea, but I am guessing something @harsh obsidian ran
I have nothing to do with that

honestly , i have seen that command a lot in my games , still dont know what is it
from the man page:
-c Read commands from the command_string operand instead of from the standard input. Special parameter 0 will be set from the command_name operand and the positional parameters ($1, $2, etc.) set from the remaining argument operands.
cleared that up
nice
I swear to god I have no idea why my name is in there
I just lost my shell and it it wouldn't let me in just to realise I didn't listen for it 
π€¦ββοΈ
been there
king file is actually free from any loops atm
prodigy1337x , you are no one to teach me about what is allowed or not . you have come to played . play and leave . and if you think i removed some binary , just report me . leaving warnings for me in the root folder isnt the way . and what writeup are you talking about . nothing of that even makes sense . i am sure you think nano is removed . which isnt there in the system by default , please get some life man
@stiff egret Heads up ^
Please try to keep a calm tone, if they don't know something or they are doing something that you don't like, you can report it as well, ranting here is not the way. Also, if it is Hogwarts, then yeah, nano is not there by default.
sorry if my behaviour was bad but when people put false allegations straight away calling me a 'cheater' , its hard to resist . he doesnt even know the stuff , and hes leaving warnings for me . wow
π€·ββοΈ Kick them off the machine
If you're not guilty then ignore and head forward .. Ranting won't help... Simple
i mean , i just thought bursting out once would help . Because this is not the first time i am experiencing this .
guys how to stop others loop process
ay holmes you wanna do a game today? @stiff egret
can't played a lot already, gottta sleep
ah fair enough mate, maybe tomorrow?
(~2AM here)
sure, I'll ping you when I play,
can try,
π
Still the tone you are using is not appropriate
@nova tide i apolozise again
-bash: /root/king.txt: Read-only file system any fixes
β
@rancid pewter
hmm
sounds
fishy to me
thanks mercury
I think you should fight him
π
whoever wins gets to keep the tetris game
that teteris game was good
did you complete it
no
It more like 200 points
hogwarts box is strange
I didn't get the issue here.
Delete what?
It is, but as I get further along I like it more
do a man fgets 
the thing is like the first warning in buffer overflows
then dont

smart decision
2m
Wrong link, post the invite link.
sama here
plus my hands are cold so I won't play well 

i know how it feels when that happens .
my hands freeze when naughty , holmes and me are in the same match . i get frezzed 
lmao happens to me too

the first time i was streaming and naughty was in game . i shook so hard . that i had to call someone to hold me
and this was all before 1 min of the match started .
I can totally relate
anyone down for a koth ?
i think you break the box its not pinging
7 minutes left
@opal dove ^
my bad bro, I was asleep β€οΈ @delicate cedar
23min
@ebon heron you able to do a private one?
you don't have to play
I just want to set a tool up
start in 14 min π
I feel lonely
ok so there is nobody
i can join
im here
yee
i search a ctf or a challenge which brings in a lot of points you have 1?
how many?
year of the rabbit 310 points.
you need to have lvl 8
u2 π
i never do Lioness nice
24 mins
look king π
are you guys in tyler box?
no lion
lion is not hard that much
weldone
never done lion before
i think the hardest box is hogwarts
I have upload my reverse shell how use listener?
nc -lvp PORT
Okay
Just that?
I have nothing humm hum
listening on 0.0.0.0 on 1234
Its write that
I go page ip/upload/index.php/php-reverse-shell.php
But my console write nothing...
@errant marten
What is the problem
you need to find where it is stored
yes
Yeah i find
Its that
@errant marten but nothing...
I use port 1234 i change ?
enegity
i dont think that is weer stored
me either. :/
Euh okau
Okay
@ebon heron how do you revsere flags. I dont remeber π¦
reverse flags?

Listening on 0.0.0.0 1234
that is normal?
@ebon heron I found it out, it was echo "flag" | rev
enegity
yes
use this
10.10.10.165 hmmm
yes?
yes
the ip is http://10.10.101.138/
put the attack ip there
i do that
Is that a vuln in the box? @ebon heron
but nothing
1 min left π
Or something you added?
yes
WTF
Don't spoil the koth boxes @ebon heron
there are nothing
sorry
5 min
@fair adder GG
ahaha
I don't even have my own nitro LOL
enegity you need to learn bro
but when you play you learn
@ebon heron I'll check if i have enough time for one more round.
1 min left andrew
@ebon heron when i do ctf /koth i learn
many things
I can't anyways.
oh π¦
@fair adder Panda isn't soo hard if you have watch kong fu panda LOL
oh okay robots.txt 
@errant marten oh shiiiiiit
ban
you deserve a ban for this bad joke
it's the sentence
ahaha, I'm sorry.
yeah yeah lol
@ebon heron seriousss
155
pts
I didn't even make my nmap
keep calm
You already did it
do you want to come in
but i'm not well otherwise
dm?
Don't evade the swear bot. Quite simple.
anyone up for a koth?
13 mins
15 minutes
:p
did not take all the flags too quickly give me a chance lol
no site?
there is no site
no http port
Have you scanned?
Ah it's food this is an annoying one
lol
try again?
FYI I haven't done anything, just normal advice
Is this normal when sshing straight in?
yeah, it's an intended hurdle for food machine
^^
REEE
Did you check if it runs on a different port?
mind path blown
Not a bad idear π
also just basic stuff, give http://10.10.10.10 a look
9999 is the king service
hmmm
very funny google
they are no site in 22 and 3306
At this point I can only tell you to try harder
π
I will try to take a closer look at this port 3306
All the best :)
I would like to hear some tips about defensive techniques in Koth
Yeha fr me 2
There is, just you haven't looked hard enough
but for you it's too easy sherlock
lol π€·ββοΈ
hmmm
Try avoiding spoilers/screenshots
Yeah
yeah
sorry
np :)
did you got root
no just user
brb gonna go get my dinner
@fair adder are you in a game?
Read the blog if you haven't https://blog.tryhackme.com/guide-to-king-of-the-hill/
lol
same link π
its gona be hot game
I HOPE SO π¦
Ah damn, just turned my VM off





