#koth
1 messages Β· Page 61 of 1
can't gotta sleep, 2:15 AM here :(
you are lucky this time
i am , not him
30 seconds , holmes , my fingers !!!!π
all the best
whats wrong ?
you are fast
my fingers are frozen here ;
its snowing out side
i am surviving on heat of laptop

π
π
Which machine is this?
food
ah, nice, all the best π Imma go sleep.
have a nice dreams
have cold dreams
π
we need good players https://tryhackme.com/games/koth/join/fcbb652db217d35694a2b2e0
like sniper
π bro food has sl installed , dang .
if its hogwarts , i am exiting . i havent even solved it once
i mean i never got the chance to play it
i was trying to find how to solve
but i cant find anything
i didnt undersatnd
understand*
sniper are you using split screen?
nope.
The typing banana is classic.
Yea π
How did I never see that?!
You mean you never mistyped ls? π
ππ James , you created food box uh? Or you modified it?
Apparently not on food
I created it
Hackers and Food
that's some big haxor sign
Lol
food says sl not found π¦
no, i ....... account for that
π€
okay, not accounting for that it works and that's awesome!

Is anyone else experiencing long machine boot time at the beginning of games? Sometimes, machines like Hogwarts and Offline takes about 15-25 minutes to fully become available.
Offline is windows machine, hence slow boot times
regarding Hogwarts, it's different, so it's not actually booting slow, but the port scanner that you are using is dropping packets to speed up the scanning
to check if it's booted, always scan for port 22.
if that's open, then chances are everythingis
Yeah, that makes sense, thanks.
that is specifically for Hogwarts, and not a general advice
koth someone?
@stiff egret just a reminder regarding the hacker of the hill , any updates ?
I got the info, just confirming rn with skidy If I can post that here.
π π
@dapper yew Just confirmed with skidy, there is a detailed post to be released soon. If there's nothing by tomorrow, I'll post the info here. :)
thanks holmes π
gib labyrinth
i don't believe you anymore.
me too
you are getting lazy day by day.
me too

What should I do if someone kills the services on all ports?
Any suggestions?
Report them
How do I do that?
Check the pins
Alright, thanks.
I didnt kill the services by the way
π
Just playing the same way you do
@candid geode
Then what did you do the ssh service?
It is available
I can't even scan for it.
And there are many other ways to get onto the machine
Send them the room id if you think I am not following rules
The website backdoor is also down.
That was just working for me
Spectate link?
Really, it'll be a lot helpful if you'll just upload the game ID here
Removing that whole folder doesn't count as patching.
I was getting kicked out in nano seconds
right , that happens with me too . he uploads a kill script when hes in .
So I actually just copied the index.html from the parent directory into the backdoor folder
can you share the joining link
Here is a match.
wow this is about to end 
I don't think the match has even started yet.
Here's a free advise/method I use in these scenarios:
You send commands using this method, you won't have a Process ID, so you can't be killed.
It works well.... until they delete the .ssh.
Or password.
π€£ π€£ π€£ π€£
Hello everyone loves to play on TryHackMe especially KoTH, I just played KoTH but there are some tricks that I don't know yet like what is using urandom for? and how do i do that?
Players usually output the contents urandom into some else's screen.
cat /dev/urandom > /dev/pts/<number>
means it will pop up random characters that fill people's terminal screens? and how to find the number of pts?
You can google details about that, but for a start, you can find the PTS by typing, who command.
Nice, thanks for help! @stiff egret @candid geode
but how to prevent such urandom attacks?
login with command ssh -t?
As I said, research, google around. There's also a blog on tryhackme related to this.
okok thanks before
5 minutes.
Post the invite link, no one can join with this link
holmes dada
Sorry, I used the wrong one.
kill him
not playing lol,
How long left til starts?
I could extend it, if you want.
Nah it's fine
oof Offline
never done this one before
Now have to wait a bit cause Windows 
Yea I just cba now I setup my vm then closed it
Too hot in my room for me to concentrate 
Wait, you are king now, when did you come in?
haxor
how
lmao really?
Yea
Well your king again well that was weird
Have I found a secret way to win KOTH π
lmao
Unless you changed my name and are tricking us 
The flags are so easy to find on offline.
icacls?
I never tried it though.
It comes installed.
yes
im trying to figure
out how it works
yeah i found it
to lock file
cacls <Folder Path> /P everyone:n
to lock folder
cacls <File Path> /P everyone:n
I tried it and it also works.
to lock file
icacls "C:\Users\Administrator\king-server\king.txt" /deny everyone:(DE,WD,AD)
I did this.
More windows boxes.
change passwords π€·ββοΈ
Task manager > users > disconnect.
ohh thanks jiakang
#koth message omg that picture -- the background has the grids on it ewwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww
Wait I'll delete that before I create even more work for myself
Oh no 
I have created an issue that wasn't an issue
I am guessing your response is restricted due to PG13 policy of this server
I'll add that line to my resume
@terse willow ^^ #764491023127674910
anyone wanting to play ?
I can actually play one game. π€
uh , till when you awake ?
this long
1-1:30 hours . lets just wait for 30 mins . if more joins , let's play . 2-4 people is not fun .
agreed
if anyone down to play , please message here π
ye, same here
I really need to improve it generally
feel like koths are a good way of doing that
not much in koth for windows, only one machine at the moment.
you make it sounds like there's plans for more π
I don't wanna leak too much, but if I am right, there will be more machines before feb ends.
huh?
who won
as expected
there's nothing this man doesn't win 
I literally had no idea
did you do the room ?
Which room?
The great escape
Nice!
It's actually an interesting machine, you don't/cant' get a shell except in the last part when AFTER you become root
Wait, so you get root before you get a shell?
yeah, the only shell you get in the end, it's of root
That's awesome!
and it was a pain, because I didn't know that
so I tried every damn reverse shell there is to get a shell
@stiff egret you could use the ||api|| to get a shell btw
||the 8080 api was running the commands in the internal docker||
sure, if you can send me the commands, I'd love to test them out
what about the ||docker daemon on 2375||
that is after you get root
||oh, what I did was, ran the docker priv esc command directly on that port, so the shell I got was root mounted shell||
ahh right, yeah
so you basically just ignored getting a shell
that's what I did as well
uh, I don't think I can join, about to shut everything down, done for today
yeah, once I realised that this is it
oh yeah, def, didn't try that, but it is clearly possible
you needed the docker *container name as well
I can get the exact command for you if you want it?
you needed the host in there as well I believe
yeah, ofc
but yeah, it was pretty basic docker escape
I think it's common to use an exposed docker socket to do it
so I had never done it with the daemon before which was cool
yeah, exactly, escaping was easy, but getting to the point where you can see what you need to escape was hard
I've been testing that out recently for the new box so actually used that a week ago
hence it clicked
you'll see, one of these days, I'll make enough coffee to last me for 24 hours, and next day new machine will be released
well, maybe not for someone who's operating on you 
I want to play, if you still wanted to.
Here is a link.
Gosh, I didn't realized you joined.
Here's another match.
https://tryhackme.com/games/koth/join/8cd6c0064322e323628e324c
ah I'll probably sleep soon
I just wanted to make sure it wasn't just you playing
try reclaim it
Alright then.
oucchh windowsπ©
Spectator link?
@nova tide totally not stream sniping
if you go on your stream and see which people are watching, i am not one of them
(Also, if you are streaming KOTH, you should be in the KOTH VC)
i have seen your persistence backdoor a thousand time already
if you remember i stopped it once before
Also watching THM's kid stream not yours
that's the most common back door π€·ββοΈ
@nova tide did you ever get that rootkit up and running
i don't have rootkits.
There's a 65536 port for the koth-leads
never needed one
stop telling everyone my secrets.
holmes π
πππ
now they know how i have root shell that fast.
Hey @dapper yew
but they don't have that superVPN that can open port 65536
but the password for root is in rockyou so they might be able to bruteforce it
@candid geode you know you're not allowed to kill ssh altogether, right?
I didn't kill ssh.
someone sure did
I also can't seem to use it as well.
Just use a reverse shell and hope no one kills it. That is what I am doing.
Nevermind, someone closed the port.
I think this is the problem.
Someone messed up with stuff, report and reset.
spacejam?
Yeah, the machine where everyone goes crazy.
Ah it's the || chroot||
someone did mess up with the service though
who is Jack Napier
Random guy on Koth.
Hey! Iβm new to koth, so have me excused if I do something weird. Having fun so far tho!
Nah it s ok
anyone available for a KOTH?
It says there are only two flags. But I think there is an elite in the game. Is that a bug or what?π
It's a known bug, I'll keep an eye on the user, being first time, I am presuming it happened accidentally, it repeats, then the user is getting a warning.
Please ping anyone in koth-staff if you see the same user doing this again :)
Hey abood
π uh hey abood
google can help more then I can, Also I am half asleep
kaz any ideas?
Nice little chat we had
Busy box is just an executable that provides for other binaries
Of course
anyone else having issues getting on to THM or is it my local network acting up?
no one joined ^^ one , i am going AFK π
anyone who knows how to fix this? The game is done now, but would like to know how to write into the king file for my next game.
smells like chattr to me :(
there is a machine
sorry box
to echo your name to king
not > >>
echo vistimalik >> king.txt
i dont remember the machine
i dont remember
Read the blog post. Check pinned messages
thanks, i think it's the noclobber, cuz tried chattr and it that didn't work
They might be running chattr in a loop.
ANYONE WANNA PLAY KOTH?
sure
Hehe join
i mean
i am doing this for the first time
so idk if you have to make a room or something i guess you can just join the public room
@nova tide
Just join the public game.
Also for more info about koth read the koth docs and blogpost
I am already in a public room
!docs koth
@nova tide i am that deku773
Oof it is all well and good but how tf are we gonna protect the machine xD
- PG13
- Read the blog post/docs.
okay
can we encrypt the main king.txt after adding our name?
As long as the file is readable, you can do anything with it.
Ohh okay
you mean i can hide it and do whatever i want the user just have to find it right?
NO, the name and location of file should remain '/root/king.txt'
ugh okay then
Please do read the rules before you start
??
i can't even get the reverse shell
i mean
you got into the pc right
how did you even did that
i cant even get a little of command execution xD
well amma noob
he is streaming in #koth-voice-chat @broken jackal
@stiff egret Can I dm you?
Sure
sorry i was in vc, didn't saw your messages here
yup
@nova tide what was the last root pass you put .
You need to figure that out on your own π
ayy , cmon games over . π¦
Can't really tell you, i'm used to use that in every game π€·ββοΈ
it's not like he can crosscheck 
oh right
i tried like 40-50 passwords , manual brruteforcing with brain
it cant be 
i was trying to change back that to the old shifu password π€·ββοΈ
ah ,
i know, Naughty is lying, correct password is 'tryhackme123'
but whatever you tried to replace it with something very small
oh ya i dint try this
i was sticking behind his name
stop telling everyone my secrets 
now we might even post the correct password and you won't know @dapper yew

He's already making a wordlist of every word you are typing atm
lmao
ofcourse you are not, you are 0x5
i dint mean that . its a password for something . π get hints .
π€·ββοΈ
@nova tide oof you are soooooo good in this how did tou learnt?
OwO okay
It's going to be a crazy battle, so many players.
And imagine that being space jam.
I am in class.
π₯
The machine is tyler, great.
Who removed the narrator user in https://tryhackme.com/games/koth/19188 ?
@candid geode you can still get king
not me
I havent set up any persistence
The whole directory is gone, alongside with the flags.
Or is it just me?
Wait, nevermind, I can see it now.
Make sure you are not in chroot
spectator link ? match seems smoking .
I made sure that, not sure what was the issue.
^
i dont understand why half of them go AFK ,
Other commitments? π€·ββοΈ
another game ? now ! vm booting .
New match here:
https://tryhackme.com/games/koth/join/5be736d396fcc4747d2f50fb
put a spectator link , i will join at last if more people are there.
It's starting in like 1:30 minutes
oh , i will join next one . i am setting up tmux .
Here's the next one:
https://tryhackme.com/games/koth/join/0dcc09e8103512543b4ace31
Ok
@candid geode did you just patch that ?
Patch what?
i just found something amazing
,thanks for patching everything .
Howdy?
?
Did you see the message?
uh no , i am not even there on the box .
Oh okay, nevermind.
whoevers in my game , whats with the resets .
someone for koth
is deleting users at koth legal?
!docs koth
I mean
Itβs not expressly stated
You should really look at other options as there are far better options
gg @lilac basin
ahahha
I'd assume no, as that disrupts the normal operation of the server
Might need a referee on that though
bruh when i was connected to ftp i tried to switch dir with cd .. but it remained the same so i was blocked ahahhaha
lol
anyone koth ?
uh , if you told a bit earlier , i wouldnt have started room 
If you have folks in your room, I'll just leave this one. it's just me
lets play once i do this room @harsh obsidian will ping you π
Okay. There's 17 minutes until this KotH kicks off
anyone up for a game?
can i dm you?
ofc
is redirecting traffic from port 9999 allowed ? its not mentioned in the rules .
Port 9999 is out of scope, means nothing related to 9999 should be messed with
...
is it on?
Hell yeah!!
I feel like they are harder than the old ones.
Been trying to find a flag this morning π¦
I finally found a flag after 40 minutes of going around the box.
Yep, looks like I've a lot to learn
I found several ways of entering the box.
which one?
i was in the box the entire time ._. i didn't find a way to privesc or find any flag
what did you grep
grep -R "THM{" /var/www
The flag was in www.
|| did you see the txt file on how to privesc ||
What txt file?
|| i think it was like topsecretprivescmethod.txt ||
it was gibberish for me like unicode characters
i spent 50 minutes just trying to privesc
Can't even get a shell 
lol
Public game starts in 15: https://tryhackme.com/games/koth/join/59b7db5bfec642f57faba3f8
A quick question, H1 Easy is part of the KOTH? i.e. other users may mess up configuration?
has anyone managed to get all eight flags on panda?
naughty , he has 7 . ( stored in the cherry tree )
Grep the whole machine.
tried that. it takes longer to do than the hour we get
you really cant search for flags in panda , you dont know its name , also it doesnt have any "THM" as prefix .
yeah, i tried it with regex, but still takes too long
i wish we could exclude the stuff . like we know that the flag isnt in x directory , then it would be much easier
Is here the correct place to chat about Hacker of the Hill?
@harsh obsidian did i kick u out ?
I haven't found another way on that box so i'm gonna head to another while i think of other ways

Joined π
sweet
it's a lot of fun. can be frustrating as you look for initial footholds. just make sure you enumerate subdirectories and look at versions and look at ALL ports. just make sure you leave port 9999 alone always
im doing space jam and patched it by changing port to start again i did node server.js but it doesntl let me use the terminal
how to i fix that?
#room-help/hints
Is there a new koth machine called "tyler"???
i just subscribed yesterday and saw that in the koth section......
Tyler is there from the beginning.
The table size on site can only latest 10 values, hence tyler isn't visible there.
https://tryhackme.com/games/koth/19371 is not working well
only 2 open ports
22 and 9999
ik
If port 22 is open, that means the machine is perfectly fine.
there should be port 21 and port 80 opened
No
i did -p- at first
there is no port 21 open on the machine.
:) No probs
Join the koth starting in 9 minutes
Usually sending the invite link here is helpful.
It'll be my first koth, kinda excited
Ah, all the best :)
Has anyone figured out and managed to root the 3 machines yet?
I don't think so.
Easy is rootable
I only entered one flag is that normal?
Hey, It's a known bug.
someone start wall loop
is there like a partiucalr container for breaking out and getting root . in the hard box .
I have a question. Are the machines from https://tryhackme.com/room/hackerofthehill , the same machines Koth used?
yea
Ah, thanks.
Yeah, I found multiple ways of getting inside, but havenβt a way to gain root access.
avoid spoilers mates
Anyone up for a game in 5 mins!
Private or public?
Public
π
All of my backdoors will break if one day THM decided to tell everyone to regenerate their vpn configs
π€£
ah damn

@stiff egret Is there a difference between the hoth challenge box and the koth one?
no
oh
Why are we resetting?
Def not me
one less l in kill
π
what is core.d?
π€
Frustration
yeah guessed that much
:))
ah damn
that was so so close
I was AFK dmanit
Are you still in the machine?
Lol
I was, but went to do some work
ay it was a fun match
also, you can add -ia in one argument
Ah
doing that in 2 commands slows it down
π€£
rooting the hard one is pretty hard , tho i have a nice ssh shell
@stiff egret is it completely docker based and requires a docker privsc , ?
ah nice
I honestly have no idea, I am aiming to solve it first.
aiming to solve what ? the hard one ?
yeah
whered you reach
the windows one?
mhm
no
eh, I am very bad at windows, been practicing windows hacking from last week,
btw , are these machines gonna remain forever in koth ?
yeah
yeah, they are permanent addition to pool, asleast as far as I know
i am excited for first koth in these boxes . πΆ
just played one in h1-easy
oh . there are many ways in that box !
3
its kinda hard to patch everything while playing koth
been working on a script to patch all 3 at once .
hmm, auto patched script
uh no , not exactly , it should be done manually , but yea its a script π
damn that hard box is hard
if it makes you feel better
in the hour that it was streamed when it first came out
I believe only naughty got a shell, and that was it
Uh, please read the rules.
Rule 7.
The current lion machine is up for like 30 seconds then go down for 30 seconds on repeat. Anyone else have that problem?
Vote for reset? If everyone/anyone else is also getting the same issue, then they'll vote in too.
If not, then you know it's probably not for all
Yeah, I'm the only one who voted for it so it might just be me.
Going home.. Won't be able to for the rest of the week.
Finally, I have properly rooted easy.
That took longer than I expected.

Sorry
didnt mean that in response to you
The flags are missing
So wanted to ask in here
yeah @mint girder I think szy had the same issue
Wrong emoji
is it hard
Hours, I guess.
I just started the medium one.
i rooted the hard one , finally
ayyy nice
@candid geode @dapper yew you down for a chill koth and vc?
haven't done one in a while
i am down , ofc , so happy π
yea .
@dapper yew ready when you are
we can always do a calm warmup
lets play hogwarts box
have you got vip?
uh no . i thought you had it ! lol
nah mine ran out :(
we can just start a couple and see if we get a good machine
one of the new ones or hogwarts
fine , but if its a medium box . i cant play , havent rooted it yet
yea np , lets root it
join vc :)
but , i dont really talk sorry . i will stream
koth anyone?
sure, but can only play for tops 10 minutes
ok
join the vc when ready or just ping me when your ready
Anyone up for a game?
Same one buddy π
Hey, closing ports is not allowed right ?
well done
There are so many ways of entering the Medium box.
IIRC there are 3 ways each machine (hackerone ones)
with all those writeups, koth is just who is reading the writeup faster, koth just has 0 fun
Yeah, some players just search for writeups online instead of doing the machine themselves.
There's a part, that says, defending the machine. You don't just have to hack, but patch too. I don't remember those writeups showing how to patch.
exactly, that sucks, if there would be new machines with 0 writeups on the web, that would be awesome
Really mate, did you see the announcement? There were 3 machines released in last 3 days.
im talking about the other ones
At the end of the day, people have notes on the machines. Writeups do more to level the playing field that they do to cheat.
You are in a game with me. I can assure you I rooted the machine myself and haven't patched much. Still got hope buddyπ
What machine is it?
Yep, that machine has lots of ways in.
All machines have a lot of ways in. Really it's the game of defending more then it is of hacking in. The machines are made in such a way that they are usually hack-able in 10-20 minutes.
wasnt talking about you
I was just giving you a chance to have fun. Cause you said KotH is 0 fun. π
thas true maybe you can get in but you cant defend
20 minutes before it begins.
Ok
I thought it was the one going on now
@candid geode good game bro!
Never played koth before, but I will join
My VM just froze. Maybe you might have a chance.
The machine got a reset.
3 minutes before it starts.
I will probably get destroyed.
Ah crap, it is the H1: Medium.
nonono
i havent solved this yet
Neither have I.
I havent solved it too
Gotta improvise.
wanna start another?
Yeah
EXITED OUT, sharing another link
Cool
how to exit
wait , i could submit 1 flag , i have it stored .
Easy win then.
nice
another reason to use clipmanager
How much time left for the game to start?
the helen user , i have it but its the backtothm
wish I could, but nope
get a shell, get one flag and get it over with
the foothold wasn't that hard IIRC
skidy said if you give him THM flags , he will give backTOthm flags , what if i give him backtothm flag π€¨
will i get back THM flag ? 
It is tyler again.
One Quick question
If one's get root access to the easy one and he changes the owner and group of that file...then there's no other way possible to get root
Am I right?
And changes the perms too
Most probably
Thanks
Did the machine just freeze?
I can't move.



