#koth
1 messages Β· Page 62 of 1
:sed
smh, the machine was fine. Useless reset
Did someone just do something to my ssh?
who reset just now
obv not me
this is insane
SMH, Damnit, I am not playing. Go win.
There was no need of reset, either time.
2 Resets back to back. And another on way with 1/3 resets done.
LOL
π€£
I hit the reset only once during the entire duration
And that was when I couldnt ping the machine in the vvery beginning
GG
i hit the rest when you said , waiting for the last reset .
didnt want to keep you waiting . π₯Ί
lol , someone pushed reset just now at the last minute
Remove?

first idea out of the oldest book
if you give them something to kill, they won't look anywhere else
so you see the /var/.history/shell running
you kill it and keep looking at it
no but i actually saw it running
that was me
ah
used this ^
sure
gg to my KOTH group, fun box
You script it? π
Ofc
general question about koth machines, are all initial entry points also possible privesc points? or are some not just possible to privesc from?
uh, all accounts have a privesc
well
I don't know about www-data, but there's usually a global privesc for all accounts
e.g. SUID binaries
It varies from machine to machine. Some footholds require you to pivot to another user and then get a priv esc to root.
anyone up for a game
?
chattr?
anyone up for a game?
That awkward moment when youβre mid-game and a power outage hits
happens to me before 5 seconds when games about to start
Lol

https://tryhackme.com/games/koth/join/19d33dd8ea91ef57f49c3f14
https://tryhackme.com/games/koth/19718
KOTH anyone ?
My VM is taking forever to update
ay just for fun match :)
Sure u go π
i wish its a hoth box
I didn't even got time to solve the medium box π
i solved it yeatrday ; lucky
if its medium , i wont stream
cuz its a secret trick π
i dont wanna spoil it
I am in the middle of a koth game right now, and can't use my VM. This is scary.
@dapper yew you have all flags?
yep
create a backdoor user
yea i forgot to do that
I got my VM working again:
https://tryhackme.com/games/koth/join/a99e884ee6e7430e5a1e7b26
and add in sudoers file
why need to add in sudoers while you add it as a root user?
someone changes the password for the user and it's their backdoor now π
true
3 minutes.

https://tryhackme.com/games/koth/19778 voicechat ?
Anyone Koth in Hoth , Ping me π
clearly not stream sniping abood
your watching my stream , i can see it
what have you done to the box
bruh . i mean something else
bro , theres no else in the box
thats why you werent getting points
why would i tell you
but you do somthing
bro , just see you dont have points
you messed up with systemd and koth.service
theres no king
.
i cant change your name
can you tell me
nah bro
okk i will discover
π
yup gg
π
why thanks ?
im in an empty koth game starting in about 10 minutes, does anyone wanna join? https://tryhackme.com/games/koth/join/1becf0c5d39a29d7e685c221
its my second time so no guarantee ill be any competition lol
anyone want to come school me in my first KOTH?
https://tryhackme.com/games/koth/join/782470e1ef0cc839b4674f82
@wispy sequoia wp bro sorry i didn't see it was your first game
@fair adder np, yeah a bit hard for me to fully grasp the concept of KOTH Iβm a beginner still lol
we were all beginners at some point
oops
my super beginner has joined 
well this is taking quite a while isnt it
it's interesting to do, especially with it being my first time
what are you trying rn?
ftp exploitation
have u found the flag?
nop this is my first ever KOTH I don't know where to look at all π€£ I did find accounts though
I just did general -A -p 1-1000, is there a dif with the -sV?
eh i dont think -A is a good idea in koth
it takes so long
and the output of it isnt that relevant
i usually do this - -sV -vvv
after rust
you can run -F first too
then scan again the ports it found with more info
check ftp, what does it allow?
so that's what flags look like
have u used hydra?
yeah, that's what I was using to fetch the credentials
where did u try?
one of the accounts obtained from the ftp notes
nice bro
i misstyped the username
in hydra
its been running for 20+ min
thats convenient
well I'm not getting further in 4 minutes, that was a sweet KOTH
pretty cool introduction to it
up for another one?
I need to learn some more before digging into it
It would be pretty cool if we could actually see the people trying to break into the boxes when spectating, I initially clicked spectate then unintentionally joined the match so decided to give it a whiff
@fair adder thanks for all the help π I'll look into some more KOTH during the week once I finish my last modules in the beginner learning path
np ; )
is there any recommendations on things I should focus on for KOTH?
seems the most straightforward thing would be the pentesting path and/or security path to path all the vulnerabilities once inside
Pretty much.
Going for king is the way. You can get flags afterwards. But if you own the king, you own the game.
And, yeah, finding vulns from inside the machine is much easier, so find one easy way to get root, and then find other ways from the inside, incase someone patches the easy method.
Set some backdoors as soon as you get root.
Is koth not working for any of you?
It says I am currently in a game, but I can't really seem to participate.
Is this something to be worried about?
i got this
Yeah, very odd.
maybe just ping the staff , might help
KoTH staff do not deal with the site.
#site-bugs sounds like a better place for that?
close one
woah
last minute haha
What a comeback.
I mean, itβs space jam. The results are usually pretty unpredictable.
Two swedes playing koth atm, i'll be damned π
Rare breed
Be nice to the swedes @fair adder
https://tryhackme.com/games/koth/join/9fe118c98c277da4947ecde2
lvl:
intermediate
jo @fair adder killing shells is fun huh ?
ye
π
π£
u want to try the H1 hard box ?
hell no
Hey
yo
can anyone explain this:?
or why its happenining
you need to go to your profile
and change your 'skill' level
thank you so much bro
profile > about you > change lvl
; ')
im rank 1 koth
of the month
kekw
wow
biggest achievement of my life
whens the next koth?
oh no
guys anyone for a koth /
π
you guys rock!
Nice π
by mistake π
i dont know how tdurden was popping again and again
loop for ssh on tdurden ? Heard it the very first time π
i was preoccupied with so much other stuff that did not play koth for bout a week or so .
cuz of this , my first match 
second game , i was comfortable
And yet you were able to hold king for 3 mins π
haha 
@candid geode be gentle pls π£
Peace brother @dapper yew
@last ether may i dm π
Yeah sure
No patches then?
And its H1: Medium 
aah im not playing this one
Neither am I.
can you send thelink
I don't have it.
I didn't copy it to my clipboard when I left.
@fair adder do you have it ?
How did you get it?
Ah, that makes sense.
np
aaaah i hate this room
The "hackers" room?
yes
I nearly lost trying to get nyancat on the machine 
hahahaha
i dont like this room because my internet is so bad
so hydra takes so much time
Maybe you just need to try the correct wordlist
You can root the box within a minute
rockyou ftw
Sometimes it isn't your wordlist being bad. Sometimes the password gets changed.
Sometimes you need a subset of the primary reallly large wordlist
A very small subset
nice ty for the help @stiff egret @nova tide @candid geode
what wordlist to be used for hackers .
^
it takes hell lotta time
Well it's up to you to figure out what you can do about it π
(I can root hackers in less than 10 seconds)
but autopwns are not allowed 
you wanna play koth ?
so now focus on learning ?
OSCP
study ? study what . like cybersec ?
theres only one machine i can root in less than 10 seconds
my computer
and thats if i dont misstype my password
The only machine I can root in under 10 seconds is space jam 
all the machine are rootable in 10 seconds except hackers , hogwarts and h1:medium .
( according to me )
lol
Nevermind what I just said.
π
I didn't realize there was the word "except"
Hackers is rootable in 10 seconds if you know the secret
where have you hid it james . tell me tell me . just joking 
H1:medium too
I'm excluding the fact I know a password to an ALL ALL sudo user on it
If we knew what all of the root passwords are, we could root easily.
okay lemme do that box again . i am kind of hinted what to do
i know one boxes's root pass
but unfortunately no root login
does any machines have rootlogin enabled ?
Some do, but a lot don't.
5 mins
The machine is working perfectly fine
Don't understand why there are 2 resets already
Maybe because you have closed all the ports and entries to the machine :0
oh god do i have to enter in the game for this
Am not in game lmao, am just guessing, i quitted a while ago
hmm i cant seem to connect to the machine it says host is down is any 1 else getting it
nvm
Are you in my game?
vpn?
@fair adder I thought no killing shells...
hmm who said that?
Oh well 
bro why am i lagging so much wtf
Alright.
sorry im a dirty player
I think you are the first player that kills my shells at that rate 
Rematch? @fair adder
https://tryhackme.com/games/koth/join/aa4b2800e2b08da1b5ac8756

It's lion again.
didi he put that cat gif
jiakang wining as always
its ok now i know how he gets access so fast
@candid geode why killing shells man D:
Me? I am the one getting killed :/
You are still the king somehow.
yessir
i cant join rn
k
H1 Medium game, here is the invitation:
https://tryhackme.com/games/koth/join/2de21a25560973e80feea599
helo π£
https://tryhackme.com/games/koth/join/20f0ab4fae9ff3914abecf8b
https://tryhackme.com/games/koth/20049
Starting in about 15 minutes.
@candid geode hi
Hello.
3 minutes left.
It is the hackers machine.
no still bruting hydra
did u got
I think the password isn't in my wordlist. Gotta use a backup plan.
password doesnt seems in note
i think we need to use rockyou
you got it right?
Yes, went in through the backdoor
ooh nice
Check the main page. I left something for you.
ok
lol
Reload again.
i am joining ur party
jiakang changing web is illegal?
There wasn't anything useful to be honest.
It doesn't say it in the rules, but after if you modify the content and the machine becomes totally unavailable, then that would be illegal.
i mean if you change that contenet at backdoor
at hackers
its not illegal
cuz you are not deleting you are only closing roads
am i right
i need to read the rules
changing the content is ok but you can't delete it because then it would be pretty much the same as deleting a privesc vector binary instead of fixing its permissions or whatever
https://tryhackme.com/games/koth/join/6d1cc43a4b6132ae7a961982 starting in 10 min
Is the machine working?
Ah, I thought it's gonna be linux machine
Or is should I renew my vpn config?
it isnt working for me aswell
i hope its an easy one XD
i hope i dont get smashed
if i get 1 flag ill be happy
why we have so much cats at the chat
lmao
i need to be ca ttooo
ok now its good
Can anyone access the machine?
Oh it looks like it
Cause @delicate cedar is already king π€£
I realized I wasn't connected to my vpn π₯ 
my cat is better
i should stick to my courses XD
Strongly disagreeeπ€£
actullay we have same pp but the cats are diffrent
my cat try harder
your cat is playing minecraft
lol
Your cat is watching some NSFW content
I saw your profile picture before, but as a gif.
Yeh
@green axle gg?
Hmmm
What
No i'm still here
get king π ?
I can no longer since you gave him all the permits, but I still took away the position of king
π¬
;-;
How did you manage to stop my process?
gg
Koth on fire nowdays π
helo π£
https://tryhackme.com/games/koth/join/9fd4c6e761ac5517d30f8d47 anyone up for a game π£
Come over to the KOTH voice channel to chat as we hack π
How do I get ssh to start working again?
Someone in my game may have terminated the ssh service and I can't get it to working.
Ah, no wonder it wasn't working.
game id?
can you see who else is in the machine? their ip.
also screen shot for that cat killssh.sh file if possible.
use w to see their ip
I have their ip, but I can't find the killssh.sh.
It isn't in /var/src
They do have a lot of scripts in /var/src.
find / -name killssh.sh 2>/dev/null
I'll try that.
dm me their ip as well, screenshot if possible.
DM me the machine ip, i can try to check.
rip
well i didn't patch anything after getting in anyways
changed back the password for fortuna to the one you find in creds just in case if you had changed it
@graceful breach you can ask it here , people are helpful π
yo
can i report i player for reseting the machine without reason?
its not broken or anything but he keeps reseting it because i get root first
Not really against the rules.
rule 10 doesnt apply to this?
π€·ββοΈ

hello, any tips on offline windows machine?
Hint : ||its all metasploit ||
i'm curious how much koth is the same as real life hacking
Not really similar
Seeing as people won't be hacking the same stuff to try and boot you out at every turn
and run nyancat on your tty
ok reseting the machine without reason isnt against the rules, but this is getting so annoying...
if it is being abused it is actually against the rules and I suggest you report it here to the koth-staff or send an email to koth@tryhackme.com
(Naughty said otherwise above, but I'm inclined to agree with you on this one Cry)
Im just going off the rules but I really dont have any say here as Im no longer a staff member
π
Hellow guys , anyone knows how to execute our name to king.txt continously
thanks π
may i dm you? @graceful breach
(^v^)
sure
@fair adder u wanna split the king XD
im not getting any points while king ?
u are getting points if u becOme king
π¦
i win for 1 minute
oops
2
ill get that first win oneday
π£ you never won?
did u write a script to keep changing king.txt ?
oh
because im a complete newbie on windows
i tried changing it couple times i thought u wrote a script for a moment XD
lets hope for a linux machine
wait i have a question
did u get kicked out of ur session ?
previous ctf
coz i was trying something
yes
yeah i saw them both
how did you do that?
open task manager
users
u can see everyone connected to the pc
u can rightclick and signout
k
i dont understand why it showed "youre not part of admins group" everytime before it kicked me out tho
idk
i tried deleting ur user so when u use rdp it doesnt work
i also dont know if that worked
administrator?
no i hide it
hm
wait are u sure u deleted mine ?
because everytime i go to users to check for new ones
mine was still there
i ran net user juba /delete
and net user juba after
and it showed no user with that name
or smth like that
lol
but u still can delete it
i want to get better at shells but the room is very boring
not much activity more reading
im not subscribed ;s
@urban vortex not gonna get very far in this industry if you can't sit down and digest information, I'm afraid
i agree, its a habit that can be developed
i personally love to just read stuff
but feel the need to put it to practice after
@urban vortex good luck
u2 my friend
Hello guys is this legal?
[shrek@shrek ~]$ Connection to 10.10.246.114 closed by remote host.
Connection to 10.10.246.114 closed.
Guy just shuts down 22 port.
its okay to change port but not close it
im playing with you too did you check if he changed it to another port ?
@finite garden its open
yes Yes now π When he make 325 points and he is king for 20min
ofc he will open π
and its closed again π
PORT STATE SERVICE REASON
3306/tcp open mysql syn-ack ttl 63
8009/tcp open ajp13 syn-ack ttl 63
8080/tcp open http-proxy syn-ack ttl 63
9999/tcp open abyss syn-ack ttl 63
65432/tcp closed unknown reset ttl 63

Its ok π
Some people dont want to have fun playing koth π
i wont be lazy to report him π
yo anyone? https://tryhackme.com/games/koth/join/1054b342ae62720bd7019fcf 4 min
Check pins, you'll see a msg for how to report info.
Thanks i already did it π
Also, sometimes, some players shift the ssh to a v. higher port, like, 60000 or something.
Yes i know π but sometimes they just shut it down D: hahah
True that. Hence the report option.
big chance its the last port that random one but its close
i try but its not
cuz its close
Yes π so thats illegal stuff to doing on koth and i report that guy
https://tryhackme.com/games/koth/join/39688cc9dbac5ee39321c8da anyone? starting in 2 min
https://tryhackme.com/games/koth/join/1e560aff81d05b89c85d64ef starting in 8 min π£
https://tryhackme.com/games/koth/join/79901ad13fb824720fbb3477 starts in 2 min π£
come play π π£
nvm its h1:medium 
https://tryhackme.com/games/koth/join/087f6222795a32726b9885c1
I finally have time to play again. 
Voice chat?
Does running tmux on zsh make it crash on Kali?
Cause it just logged me out of my system π
Anybody else face this issue?
Nope
Are you the one logging in with Bobba?
I cant even ping the machine
10.10.237.81, it is up and running.
You forgot to blue the ip in other lines π
I was only blurring my ip
π€£
I know I am connected to the THM network because tun0ip gives me my ip address
yo anyone up for a game? https://tryhackme.com/games/koth/join/5374f358889434a03e918797
This game was terrible for me. Needed to enumerate the box again π. But these days everyone gets king in the blink of an eye π€
How long?
15 min
π π£
5 min to start π join pls π£
nice
i forget about the vpn once again
koth was kinda dead yesterday
i missed killing shells π
What do you mean by forgetting the vpn?
i forget to connect to the thm network
and i take a while to realize that
so i have a late start
Oh I've been there!
Does it like automatically disconnect over time?
you always do it π€£
i reboot quite often tbh
my hardware is far from being good
lol
Oh, reboot. That makes sense.
same
if i use orange it will run faster
π₯
Players keep resetting the machine in my game. What should I do? 
send invite link here, i join so they might need more votes to reset
Someone is using this!
no wonder what people can do just to win .
As I said, please post the outputs of bothw and ps aux|grep ssh in one screenshot
That way I can confirm who is breaking the rules
@last ether maybe remove that script so that it doesnt pass on
@nova tide ^
KaliGhost always plays dirty. He was the one script-killing my space jam shells last time.
some people are playing to have fun other to kill shells.
Looking into it π
afk in koth lol
I found kalighost and his scripts again.
Hell, I managed to take him out before he got the time to run all of these.
killssh.sh just kills all ssh shells.
Anyone who wants to report someone, for running malicious script, please follow this:
-- w ; ps aux | grep <the script name you think is malicious>
So we can identify who is running the script.
In this case,
w ; ps aux | grep killssh
I waited for him to run his scripts, but he didn't this time.
Sometimes the w doesn't give any results
I do have the source code of the scripts, in which he has his ip and username.
Me too π
In those scenarios, it's really hard to identify without involving logs.
In that case, report whatever you get to the email provided in pins.
Hmm ok
I got this:
okay lets do this before blackmetal wakes up
https://tryhackme.com/games/koth/join/8cafbc31ca637fdd187c8c46 @fair adder @hazy zodiac
I always do:
ps -eaf --forest
the problem in that screenshot is that I cannot verify the pts from that screenshot on which the script was running.
10.4.23.250
lets play
Yeah, f is shorthand for --forest
how do i make a gif my pfp
can't be certain
come faster it starts in 2:30 min
on thm or discord?
aye
thm
les go
Yeah, but I will have to play another game with him, because this one has ended.
I don't know if you can anymore, it was once a bug.
You could once, but it was removed
i used it Β―_(γ)_/Β―
I also can't play today anymore, I got work to do.
been so long I've played.
Which box are you doing? π
shrek
Ahh I think I have flags stored somewhere 
heyyyyy π
remmeber that one time i gave you chips
it's not fair chuin is 0xD
me n00b
lets go
im scared for some reaosn π€£
don't forget to connect to openvpn
what how do i start
okay let me do that
okay what now
Scan the IP
enumerate for vulns
things that you do for regular boxes.
Bonus: Give the pinned article a read.
okay thank you so much
gosh this has to be easy
ikr
You can login using ssh via multiple ways
if you have the ssh key, you can use something like:
ssh -i sshkey username@IP
make sure you change key's permissions beforehand,
chmod 600 sshkey
If you are new to this, I'd suggest do give some easy/medium rooms a try once.
yeah, that's correct
someone closed my connection
is that a thing?
yes
it was chuin
okay that is so cool
i know he did it to me, but thats really cool
Yeah, this is a defense/attack game, people get in first, they patch, if someone has a shell, they kill the process ID.
Watch videos of John Hammond on KoTH.
He made some awesome content on YT
streamed a lot 5-6 months back if I am correct
bet thank you.
frick i cant get ssh
same bruh
he's good at this
imma exploit it
your good at this
u son of a
can you go against @fair adder ? chuin
imma exploit it u son of a
chuin
IM STUPIDEST PERSON EVER
almost
i only patched 2 stuff
Watch it
i cant upload reverse shell
Keep it PG13.
oh sorry
yes
then why u havent got shell yet lol
ok imma go sleep
im giving up
wat
can you go against @hazy zodiac in koth i wanna watch and see wh owins
ok
send location
smesh
me smesh chuinzer
LMAO
Private/Public?
Has anyone, in the history of Panda, managed to find all eight flags. I've got seven but for the love of life, the universe, and everything I can't find the eight daggone flag....
I'm starting to doubt it exists....
I got 7 as well but haven't tried to look for 8th.
who stole the 8th flag
Oh, I've been looking for that eighth. It feels like looking for the lost city of Atlantis
It is probably hidden deep inside the /dev/urandom file.
lmfao
helo
π£ come play
This is getting to be a good one!


