#koth

1 messages Β· Page 63 of 1

fair adder
#

30 seconds

#

πŸ™‚

#

@harsh obsidian well played

brave kettle
#

ive never played a koth is it fun

harsh obsidian
harsh obsidian
brave kettle
#

i worry im not good enough yet

harsh obsidian
brave kettle
#

yes i recently started the complete beginner path and im now on the owasp top 10. i find all this really fun and interesting.

#

i think i might try a koth match sometime soon

fair adder
#

the thing is most people who play already know how to get in the machines and privesc so i would say try some machines in private with a dummy account of yours so you learn

#

or try to get as much help as you can

#

like aboodking helped me

#

now i can beat his ass anytime

#

🐣

#

@ebon heron right?

ebon heron
#

😭😭😭😒yesss

brave kettle
nova tide
#

!docs koth

pearl gladeBOT
brave kettle
nova tide
#

There is also an awesome blog post in there πŸ˜„ Go through that it would be super useful

last ether
#

8 mins

dapper yew
#

after a month

last ether
#

15 mins

gloomy estuary
#

gogo

last ether
#

10 mins

wild escarp
#

any body up for the game

fair adder
#

it's all about skils men u can see that..

nova tide
#

Yes it is.

#

!docs koth

pearl gladeBOT
nova tide
#

Give it and rules a read if you are new to KoTH

gentle hatch
#

hey @nova tide and @stiff egret I've been making a script with Koth in mind, basically a very basic blue team framework - check whose logged in and for how long, hash common directories and poll for changes. not intended to do anything active, won't harden anything but strictly monitor certain things that defenders should check for. just wondering if that would be allowed in koth?

nova tide
#

Sounds good to me πŸ€” . As long as its not breaking anything πŸ˜„

gentle hatch
#

cool, ill share obv when I'm done, I'm hoping it can help people like me who were once clueless about what to check for once you have king

stiff egret
#

Agreed, as long as it's only a monitor, it's fine. :)

terse willow
#

How about we don't call people out in public for perceived offences @fair adder. If you have a problem with someone's conduct in KoTH, speak with one of the KoTH staff please :)

fair adder
#

k ;s

vocal shell
#

what are some of the low hanging fruit to secure a koth box and really lock it down from others?

quiet schooner
#

Weak passwords, straightforward RCE vulns

last ether
#

Anyone up for a game?

#

20 mins

marsh sierra
#

Is using while :; do chattr -ia /root/king.txt; echo USER > /root/king.txt; chattr +ia /root/king.txt; done allowed?

last ether
#

Yep

candid geode
#

I usually add a sleep in there.

fair adder
stiff egret
#

Break it down and read.
Also, that command is not correct. There is no file given to chattr to change the attribute of.
It is an infinite loop to lock down king file.

stiff egret
marsh sierra
#

This Command Will Infinitely Make King.txt writable, Write Your Username And Make It Inwritable

#

Anyone Up For A Game??

#

Starts In 3 Minutes

last ether
#

5 minutes

sour swallow
#

Heyy, anyone down for a KOTH tomorrow night (West European time)?

fair adder
#

no

fair adder
fair adder
#

no no u

sour swallow
sinful berry
#

that is portuguese ?

sour swallow
#

Yeah :) but i made a mistake, I'm actually in UTC +1 (France) . Anyway I'm free tonight if anyone wants to join a beginner KOTH, probably after 20h00.

harsh obsidian
gentle hatch
#

so I actually have a pretty basic beta version done if you like Ill push it at lunch

#

its nothing fancy, hashes a baseline of files in the popular directories (/var, /home, /root, /etc/, /bin), and after you have the baseline you run the tool to check if any files have been added or changed

#

and another feature will show you new logins via w

#

i've been trying to think of any other features to add, I've been looking at mirroring a given users TTY but its a real PITA to do properly

last ether
stiff egret
#

Yeah, tho as droogy said, it's a PITA to do that, it'll be interesting to see how you are going for it. I can make PRs once you push it on GitHub :)

gentle hatch
#

appreciate that, my wishlist is to set this script up as a C2, drop the agent on the box somewhere and issue commands remotely but figured I'll make the agent good first πŸ˜›

#

adding/testing one more quick feature and I'm gonna push it

urban vortex
#

πŸ™‚

#

@grim narwhal

gentle hatch
#

okay guys, my shell script is all set, I made this mostly with KoTH in mind to help people think a little more defensively and not just run a script to echo your name into king πŸ˜„

#

so please offer some feedback; features you'd like, you hate it, you love it, whatever

quiet schooner
#

I think that's a really good idea, and I agree that people need to start patching vulns smh

gentle hatch
#

agreed! i think the biggest problem is people literally do not know how to patch, what to look at and too busy wrestling for king

nova tide
gentle hatch
#

ah good point, I forgot people hang out there

#

done, cheers!

sour swallow
quiet schooner
#

Maybe watch for new network connections outbound?

gentle hatch
#

very good ideas thank you, network connection module to create some attribution is next on my list

fair adder
gentle hatch
#

okay got the outbound connection module sorted πŸ˜„

fair adder
#

hello 🐣

pastel forum
#

how can start koth?

nova tide
#

moreover read the docs for koth

#

!docs koth

pearl gladeBOT
nova tide
pastel forum
#

Thanks

grim narwhal
#

1 min

fair adder
#

helo 🐣

sour swallow
fair adder
#

oke

fair adder
#

🐣

opal dove
#

@gritty tapir try get the ip of the user using w

gritty tapir
#

Its just avobe you

quiet schooner
fair adder
#

@gritty tapir are you serious? lol

#

youre funny bro

opal dove
fair adder
#

i dont know, why would i care if i dont use any scripts whatsoever

dapper yew
opal dove
opal dove
#

we can start at the very basics?

dapper yew
#

sure sure .

dapper yew
opal dove
#

gimme a second

fair adder
#

helo 🐣

pure beacon
#

Anyone else expirienced this bug? Can't view the ip, or name of the box. Any solutions?

nova tide
#

and it's been a long time. Haven't seen you around πŸ˜„ animewave

#

Last we spoke was 10 months ago xD

lethal mural
small axle
#

who is playing?

#

join this

#

4 min left

#

why someone disabled private key access

#

@matheuw

quiet schooner
#

Patching

small axle
#

isnt it against the rules

#

F

ebon heron
nova tide
fair adder
#

helo 🐣

#

any game?

lethal mural
lethal mural
fair adder
#

helo 🐣

fair adder
#

please come play πŸ™‚

fair adder
#

boring

fair adder
#

hey everyone can i play king og the hill with anyone please

#

???

#

if yes please join with me here

#

@fair adder

#

wanna play

#

no

#

can i join you please

#

@fair adder

#

?

#

im not playing bro

#

oh ok sorry to ask

tame veldt
#

anyone for koth ?

#

@fair adder

fair adder
#

@tame veldt thank you so so so much

fair adder
#

gtg to bed good bye everyone

last ether
#

8 mins

#

Been a while

last ether
#

Does anyone know why my king time is not getting updated?

fair adder
#

53 seconds kek

last ether
#

Not 53 seconds buddy

#

It's 12:53

#

πŸ˜…

fair adder
#

🐣 come play please 🐣

fair adder
midnight meadow
#

I can't find king.txt file in Hogwarts machine

#

How I be the king so πŸ™„

fair adder
#

i think its another file

#

the name is headmaster i think

delicate cedar
midnight meadow
midnight meadow
#

πŸ™„

vocal shell
#

Does anyone wanna play KoTH?

fair adder
#

send location

vocal shell
#

@fair adder

delicate cedar
vocal shell
#

sorry, i wanted to start it faster

fair adder
#

i thought too

#

i dont understand why im not king tho

#

its been some time my name is in there

#

ok i guess

midnight meadow
fair adder
#

well im also having some problems with this

#

king.txt exists and my name's been in there for 10 min but nothing happened

delicate cedar
midnight meadow
last ether
#

But it was the h1-hard machine

midnight meadow
last ether
#

Yeah it is

#

The docker room can you help you with it

midnight meadow
#

Thank you

last ether
#

No problem

#

Have fun πŸ˜„

midnight meadow
#

πŸ˜„

stiff egret
last ether
#

There is something wrong with the king service in koth

#

It is not updating king time

midnight meadow
midnight meadow
stiff egret
#

That happens when someone is hammering the file too much.

#

For example, someone ran a loop to empty the file and add their name, and it's too fast, then the file would look empty to the king service.

last ether
stiff egret
#

πŸ€” If that happens again, can you ping me before the game ends?

last ether
#

Ok

#

I will do that next time

stiff egret
#

@last ether The issue could be with site this time, another user also reported same issue with an active game, I was able to take a look and report it to skidy, if this is a persistent issue, hopefully, it'll be resolved soon. :)

last ether
#

Cool. Thanks 😊

rain cairn
#

someone KOTH ?

fair adder
#

4 min

fair adder
wispy sequoia
#

@fair adder GG, atleast I got on the board this time with a flag! πŸ˜›

fair adder
#

did you figure out how to get access?

wispy sequoia
#

No I didn't, im guessing one of the ways in via smbclient? Or possibly brute forcing the login page with hydra?

fair adder
#

can i dm?

wispy sequoia
#

Yeah of course

unreal jasper
#

yo

#

koth anyone?

#

starting soon

brave drum
#

sure

#

2mins

unreal jasper
#

cool

#

^ 1 min til start

remote eagle
#

@unreal jasper link ?

unreal jasper
#

already started, we can do another after

#

if you wanna join late there ya go

remote eagle
#

that wasn't nice xd

brave drum
#

lmaoo

remote eagle
#

do you see me on the box now ? :p

fair adder
#

i joined too late 🐣

remote eagle
#

@brave drum do me a favor

#

and log off root

#

and log in again

#

real quick

#

before the box expires

brave drum
#

ye it kills my shell automaticall

#

which is kinda scummy

remote eagle
#

I think the message is hilarious lmao

#

you can use other shells

#

besides bash

#

to login

brave drum
#

which message?

remote eagle
#

logoff and login

#

and you'll see a messge

brave drum
#

gg

remote eagle
#

gg

unreal jasper
#

gg

#

join voice boys

#

another

remote eagle
#

I can't xd

#

maybe later

unreal jasper
#

another 1?

remote eagle
#

sorry, it's getting late for me

unreal jasper
#

lameeeeee

#

for anyone else wqho wants to plkay

#

^

#

5 mins

fair adder
#

8 min

unreal jasper
#

aight

#

voice?

#

@fair adder

fair adder
#

i can join but now turn on mic

#

not*

unreal jasper
#

@frigid current voice?

errant marten
#

anyone wanna play?

fair adder
brave drum
#

toxic xd

fair adder
#

he is running shell killing scripts πŸ™‚

quiet schooner
#

Not like that's against the rules tho

fair adder
dapper escarp
fair adder
fair adder
#

I !!!! Just made a bash script that automatically hacks in to the lion machine in koth but sadly I can't use it cause that would be cheating

#

And it adds my name to headmaster kings goodbyes ect.... and rooting the lame VM

stiff egret
#

Uh, you realise that's very much against the rules.

(Also, your name is supposed to be in king.txt and NOT in headmaster.txt)

brave drum
#

anyone 1v1 koth?

low mango
midnight meadow
#

I can't edit king.txt in carnage

#

😩

grand ember
#

:>

digital forge
#

:v

#

||there's one program missing||

fair adder
ebon heron
#

@midnight meadow at carnage you should do echo name >> king.txt

#

or one >

digital forge
#

double '>' appends

stiff egret
#

You simply have to add your name to king file. And there should be only one name. How you do it doesn't matter.

digital forge
#

Eg.
if you type

echo name > king.txt

then the king.txt file will be overwritten containing only name

stiff egret
#

Almost all languages can write to files. You can use any.
Python, c, c++, go, bash (mostly used)

digital forge
#

assuming the file is not empty and contains randomString
and when you type

echo name >> king.txt

then your file contents will be:

randomString
name```
nova tide
#

If you were to do lsattr king.txt in carnage machine, you can see a flag on it. That means you can only append to this file. Other than that you might want to use chattr binary.

#

man chattr would be helpful.
Also that is intended in carnage.

rocky viper
#

@gloomy estuary

gloomy estuary
#

go everyone

rocky viper
#

go

gloomy estuary
#

could have put 10 or 15 minutes

rocky viper
lethal mural
mortal iris
#

hi guys

#

i was playing king of the hill and i noticed that user king closed ssh then we restarted the machine but unfortunately he changed the password too

#

I have the proofs

short tusk
mortal iris
#

done ^^

ebon heron
nova tide
ebon heron
#

πŸ‘Œ

gloomy estuary
#

15 mins

#

go go go

vivid scaffold
stiff egret
#

Hope it's not windows or Hogwarts, I'll drop out in either of them. (I can play Hogwarts if no one in game got any problem with that :) )

plain tulip
#

10min

errant marten
#

5min

last ether
#

"Creator of the wizarding world"

stiff egret
last ether
#

Meant to be that

#

Sorry if it came out any other way πŸ˜…

stiff egret
#

πŸ˜† np

last ether
#

For the record, I love harry potter

stiff egret
#

Starting in 13 minutes, public.

#

5 minutes to goooo, hop in people!

errant marten
#

Im in πŸ™‚

stiff egret
#

Close call, 10 secs :)

errant marten
#

yee

stiff egret
#

All the best πŸ‘

errant marten
#

bruh i dont even have nmap scan for this machine

#

LOL

stiff egret
#

Ah damnit, I gotta go, deployed my code in the box. password for food user is rustscanisbetter all the best.

errant marten
#

Ahaha someone changed ramen password 😒

stiff egret
#

Well, I haven't defended anything, not on system anymore,. But the food's password is rustscanisbetter, so you can try to priv esc from that

errant marten
#

rustscanisbetter is not the password

#

Well, I tried my best but I was too slow both of the users i found "food" and "ramen" passwords were changed. Good luck with the rest of the game πŸ™‚

stiff egret
#

Ah, damnit, then, someone else must've changed the password.

charred hare
digital forge
pastel forum
#

how can play loth?

wispy sequoia
#

@brave drum GG mano cant seem to find a way in πŸ˜›

brave drum
#

gg

wispy sequoia
#

I liked your message you left behind πŸ˜„

ebon heron
#

loth

#

Meaning of loth in English

loth
adjective formal (also loth)
UK /lΙ™ΚŠΞΈ/ US /loʊθ/
be loth to do sth

to be unwilling to do something:
I'm loth to spend it all at once.
Synonyms
averseindisposed (NOT WILLING) formalunwilling
Thesaurus: synonyms, antonyms, and examples
not wanting to do something
unwillingShe was unwilling to hand over the money.
lothI was loath to spend all the money at once.
balkThe MP balked at a proposal to raise council tax.
reluctantI was reluctant to leave because I was having such a good time.
disinclinedI am disinclined to take on the extra work without more pay.
See more results Β»
SMART Vocabulary: related words and phrases
(Definition of loath from the Cambridge Advanced Learner's Dictionary & Thesaurus Β© Cambridge University Press)
loth | AMERICAN DICTIONARY
loth
adjective [ + to infinitive ]
US /loʊθ, loʊð/

unwilling; reluctant:
She’d be loath to admit it, but she doesn’t really like opera.
(Definition of loath from the Cambridge Academic Content Dictionary Β© Cambridge University Press)
EXAMPLES of loth
loth
Most governments are loath to increase water prices for fear of political retribution from an active farm lobby.
From the Cambridge English Corpus
In fact habaneros are generally loath to own up to being especuladores (' speculators ').
From the Cambridge English Corpus

#

i think he mean this

stiff egret
#

H
o
p

i
n

p
e
o
p
l
e

#

ohk @last ether the game is on

last ether
#

πŸ˜…

#

Its probably gonna be off for me

#

🀣

stiff egret
#

?

#

ah lol got it

#

shrek LMFAO

last ether
#

🀣

stiff egret
#

PS I don't need a shell to run commands anymore, you can kill them as much as you want

stiff egret
#

apparently my script isn't clearing the file correctly, or you are writing in a weird way

last ether
#

I love being weird

#

πŸ˜…

stiff egret
#

πŸ˜†

stiff egret
#

the machine is on my side

last ether
stiff egret
#

lol yeah

last ether
#

My side now

#

😜

stiff egret
#

Can I DM?

last ether
#

Yeah bro

#

Sure

#

You dont have to ask we've been dming before too

candid geode
#

I thought the TryHackMe bot was typing, but it was Holmes.

stiff egret
candid geode
fair adder
#

hey im new to koth[been 3 days]

#

even when i get root i cant set my name on king

#

/bin/sh: 23: cannot create king.txt: Permission denied

#

i get this

stiff egret
#

Read about chattr binary

fair adder
#

i tried that and it says chattr not installed

stiff egret
#

usually any player who uses it, deletes it afterwards.

fair adder
#

so i cant do anything now?

#

any tips ?

stiff egret
#

Upload your own chattr binary

fair adder
#

do i install it ?

stiff egret
#

Download from busybox binaries.

leaden kernel
#

"You are allowed to use rootkits. But as implied by rules, while planting rootkits, make sure you do not break the machine or make it unusable for everyone but you." πŸ€”

stiff egret
#

what is confusing in that?

leaden kernel
#

I have a slight memory someone broke a machine doing that πŸ™‚

#

might be wrong though πŸ™‚

stiff egret
dry wigeon
#

I broke machines on htb

stiff egret
#

...

leaden kernel
#

Remember something you said @stiff egret "Oops i think my code broke the machine" πŸ™‚

#

Might be wrong whatever πŸ™‚

stiff egret
#

that was during a friendly match, and that wasn't any rootkit. Regardless, if hackers are hacking and fighting in a machine, things are bound to go wrong. The rule is to prevent someone trying something they don't know properly about.

dry wigeon
#

I had an issue on htb TBH

leaden kernel
#

Ahh i see πŸ™‚

dry wigeon
#

Not thm

#

I'm dumdum

stiff egret
#

re. when I broke the machine, I referred to the king file crashing because the code writing in it too fast.

leaden kernel
#

Ah right, that was the issue, i remember now πŸ™‚

#

Very nice post @stiff egret , should start using rustscan.. πŸ™‚

stiff egret
#

thanks :)
Rustscan is just so fast that it should be illegal.

leaden kernel
#

Is like nmap obsolete nowadays or is the usecase for rustscan narrow ?

stiff egret
#

imo, rustscan isn't something you can use in real world, (unless you tune it down using config file)
But in practice env like THM, it's just way better then nmap alone.

leaden kernel
#

Oh, its noisy ?

stiff egret
#

πŸ€·β€β™‚οΈ you can't scan 64k ports without being noisy in less then (what was it?) a minute?

leaden kernel
#

Haha yeah πŸ™‚ thats very true

#

ahh, i love rust and cargo, such a well made language and package manager

#

dont know why i suspected the build process would crash, im too familiar with nodejs

stiff egret
#

I build it for the first time, after that, i've been downloading the pre-compiled versions.

leaden kernel
#

Oh they had that available in their repo ?

stiff egret
#

yeah, check for releases.

leaden kernel
#

πŸ€¦β€β™‚οΈ

#

Well next time then πŸ™‚

stiff egret
#

πŸ˜„

leaden kernel
#

Ehm, 10k ports in 10 seconds wt

#

thats fast πŸ™‚

terse willow
#

Which, irl, is not a good thing

leaden kernel
remote wasp
weak crag
#

hey guys, is there a way to write to king.txt after someone use chattr +i?

nova tide
#

If you can't find any chattr binary on the system, upload yours.

weak crag
nova tide
#

Someone might be running chattr in a loop

weak crag
#

Is that permitted? run scripts in KOTH?

fair adder
#

yes you can

nova tide
#

Depends, if it's within the rules then yes.

candid geode
# weak crag Is that permitted? run scripts in KOTH?

I don’t think that counts as a script. A script would be, automatically uploading and executing the chattr binary every 10 seconds to a very secret directory and automatically removing files uploaded by other players to stop them from playing.

fair adder
#

gg

brave kettle
#

gg

brave drum
#

what?

spice verge
#

How am i making them unreadable?

brave drum
#

before u start making accustations actually show us proof because i know i didnt

spice verge
#

I'm not sure if i've done something wrong or not. How would i be able to make it unreadble?

#

Gain root access then

#

Well again.. I don't know how it's been made unreadble

brave drum
fair adder
#

🐣

stiff egret
# brave drum

lsattr shows attributes on the file, and there isn't any that shows the readability of it.

fair adder
#

helo 🐣

#

15 min

errant marten
brave kettle
#

gg

#

close one :D

errant marten
#

ahah GG!

brave kettle
#

i dont know how i pulled ahead in the last 30 secs

#

i got lucky and found a flag

errant marten
#

What user did you get root from

fair adder
#

bruh trully

#

why

#

did u do that

brave kettle
fair adder
#

😦

brave kettle
#

;D

#

you almost beat me

errant marten
#

bro i went with tyche and it was a headache

#

lol

fair adder
#

i was so dead when i saw /usr/bin/ALL

brave kettle
fair adder
brave kettle
errant marten
#

aha okay.

#

but ggwp

brave kettle
#

gg

errant marten
#

@brave kettle welcome and gl hf

brave kettle
#

gl hf :)

errant marten
#

I cant cat root.txt

brave kettle
#

that was my fault i accidentally messed it up sorry about that

#

you won anyways

errant marten
#

no

#

i still can lose someone download chattr

errant marten
#

ggwp

brave kettle
#

gg wp

spice steppe
limpid flume
#

Hello @cold hearth

cold hearth
#

Hi @limpid flume

#

good luck @limpid flume

limpid flume
#

Same

#

Food

limpid flume
#

Any luck @cold hearth

cold hearth
#

not realy and you XD

limpid flume
#

me too

cold hearth
#

next i will try nmap scripts for mysql

limpid flume
#

Let me try that too

cold hearth
#

me too

limpid flume
#

I think I found valid credentials @cold hearth

#

Yeah

limpid flume
#

You found it @cold hearth Finally lol

cold hearth
#

yes

#

but you are still winning gg

limpid flume
#

gg

tulip bough
#

wanna play some koth?

#

its sooo long ago i played to

cold hearth
#

in 30 min

brave drum
#

ill play if u want

limpid flume
#

@cold hearth I patched it thats why you can't find the flag (root flag)

tulip bough
#

Can you send an invite url

nova tide
tulip bough
#

Well joining midgame isnt a lot of fun xD

brave drum
#

especially when they have an auto kill shell script πŸ˜„

tulip bough
#

i dont know why my account is a intermediat user i dont even know how to run nmap

#

🀣

#

well i was pretty good a year ago but i havent done it in wayyy to long

cold hearth
tulip bough
#

Shall we do a voip call in the KOTH channel?

#

@cold hearth goodluck πŸ‘

cold hearth
#

@tulip bough goodluck too

remote wasp
#

good luck guys

tulip bough
#

i need it harder then anyone i guess

gloomy estuary
#

@remote wasp

#

haha

tulip bough
#

my brain lmao

remote wasp
#

heauehaeu

narrow warren
#

I like how nwkz does laugh

#

haueahuehuaehu

remote wasp
#

<3

tulip bough
#

is it normal that i only see port 22?

remote wasp
#

run nmap again

#

try enumerate the mysql port

tulip bough
#

@remote wasp goodluck again

#

xD

remote wasp
#

gl

tulip bough
#

@finite garden gl

finite garden
tulip bough
#

even tho you will beat me so badly xD

fair adder
#

can i have those shell killing scripts πŸ‘€

stiff egret
#

Those shell killing scripts are not allowed. Iirc (cc: @nova tide )

idle mulch
#

anyone free here ?

#

might play some koth together !

#

Starts in 10Mins

#

starts in 4

#

Starts in 1

drowsy vector
#

Anyone wanna invite me to a game of koth

fair adder
#

20 min

gloomy estuary
#

go go?

next swan
#

@gloomy estuary Feel free to join

fair adder
next swan
#

Sure!

gloomy estuary
#

@fair adder 0x8 hacker

#

take it easy

fair adder
#

my bad 🀣

next swan
#

Do you want to join into the voice chat during the game?

gloomy estuary
#

sure

#

join

gloomy estuary
#

yo @fair adder

#

@fair adder @next swan are you still playing?

fair adder
#

i closed my shit

gloomy estuary
#

lol

#

why?

#

I give up friends

#

it is already 3:50 am and I can't take any more sleep

#

@fair adder @next swan

#

good game

fair adder
#

good game man

gloomy estuary
#

another time we can play again with more people

next swan
#

good game guys

gloomy estuary
#

gg

unkempt adder
unkempt adder
#

@gloomy estuary take it easy please😩

#

oh you left

gloomy estuary
#

but I go out to play brawlhalla

#

lol

unkempt adder
#

oh please come back, i want to feel your gameplay

#

🀣

gloomy estuary
#

ok

unkempt adder
#

yh, today is my debut on KOTHπŸ˜‹

gloomy estuary
#

@unkempt adder

#

go

#

3mn

unkempt adder
#

ok

#

i think the link was for spectators

unkempt adder
#

let's goo

shadow pivot
#

starts in 15 min

#

5min

errant marten
#

bruh joined a game that already is in process.

errant marten
#

to be honest there should be a warning when you enter a game that is already in progress. Maybe something like this "this game is already started, do you wish to still continue?"

unkempt adder
#

upvote in 4 mins

unreal jasper
#

yo

#

anyone wanna start a game in like 5 mins?

remote wasp
gloomy estuary
#

lkajfhds

unkempt adder
pliant moon
#

.

next swan
lethal mural
#

18 minutes

errant marten
#

2min

#

GL HF

remote wasp
gloomy estuary
#

dr black

rapid crest
#

yes ?

gloomy estuary
#

good game

#

bro

rapid crest
#

y

#

I needed to eat during it

#

btw I should have made a loop to still be the king

gloomy estuary
#

lol

#

I was already doing one

rapid crest
#

didn't find your process 😦

gloomy estuary
#

lol

#

did you see my messages?

rapid crest
#

where ?

gloomy estuary
#

I created a loop by playing the command wall "message"

slim lake
rigid bone
#

hi

nova tide
remote wasp
gloomy estuary
#

@candid geode what?

slim lake
opal dove
#

anyone had much koth experience here?

stiff egret
#

Heyo, depends, what do you mean?

opal dove
#

I'm looking for a partner

fair adder
nova tide
short tusk
#

I need to play KoTH aaa

#

Soonℒ️

nova tide
#

Yes you should.. @ me whenever you play

remote wasp
short tusk
#

Ah, yes. Ping the top player to play KoTH πŸ€” πŸ˜„

short tusk
remote wasp
#

aehuaehauehaeu

#

ok

short tusk
#

Maybe on the weekend. :p

nova tide
terse willow
#

Maybe Tinder?

nova tide
terse willow
#

imagine using Tinder, ew

#

Talk about taking the romance out of dating

blissful kettle
#

Bumble ftw

terse willow
#

IRL ftw

nova tide
blissful kettle
#

Nah going pretty well

nova tide
#

I guess i need to swipe harder πŸ˜…

terse willow
#

I just can't imagine dating someone off the bat. Like, at least make friends with them first smh

snow tundra
#

Game starts in 5

remote wasp
#

'suntsam' breaking the machine

#

GNU nano 5.6.1 x Modified
nwkz@evilab~# whereis bash bash: /etc/bash.bashrc /usr/share/man/man1/bash.1.gz nwkz@evilab~# echo $PATH /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/usr/local/games:/snap/bin nwkz@evilab~# whereis ls ls: /usr/share/man/man1/ls.1.gz nwkz@evilab~# whereis chmod chmod: /usr/share/man/man2/chmod.2.gz /usr/share/man/man1/chmod.1.gz nwkz@evilab~# echo * .* kworker . .. -sniffer nwkz@evilab~# whereis echo echo: /usr/share/man/man1/echo.1.gz

#

@brazen cloud @sly crown @still bramble @short tusk @sonic belfry

still bramble
#

Ouch

short tusk
#

Reeee

#

-warn @remote wasp Please do not mass ping TryHackMe Staff

sour vectorBOT
#

⚠ Warned eae filhão só nos compiuter#7310

nova tide
# remote wasp GNU nano 5.6.1 ...
  1. Try sending a screenshot, also it looks like your machine not the koth machine?
  2. Mention koth-staff for issues regarding koth not the THM staff.
  3. If you believe someone is breaking the rules, reports go to koth@tryhackme.com
royal pilot
candid geode
candid geode
gloomy estuary
#

nothing, I just wanted to know why you sent that emoji @candid geode

shadow pivot
#

10 min

#

3 min

fair adder
#

6min

opal dove
terse willow
#

You sure? πŸ‘€

gentle hatch
#

although its not that great for 1v1 stuff

remote wasp
opal dove
#

just to see how well it runs one of these days if you want?

shadow pivot
#

5 min

fallow heart
#

Just getting EXPIRED when we try to start 1v1 koth. Any idea what the issue is?

stiff egret
#

Tried hard refresh?
Ctrl + F5 on non-Mac systems.

#

Could be a cache issue.

fallow heart
#

Also tried to create a new match

stiff egret
#

Starting in 4 minutes.

fallow heart
#

huh, EXPIRED again

stiff egret
#

Yep, noted, pinging others now. Thanks for pointing it out. Should be fixed soon.

fallow heart
#

Alright, appreciate it, thanks

stiff egret
#

:)

final nest
#

@royal pilot this guy kek @stiff egret

stiff egret
final nest
#

Coolz

stiff egret
#

@fallow heart If you still want to play KoTH, the issue is resolved and KoTH is back and fun as ever.

#

Happy hacking!

fallow heart
#

Wohoo, thanksπŸ₯³

stiff egret
#

πŸ˜„

remote wasp
fair adder
slim lake
#

@flat pendant

junior rose
#

Anonyone up for KOTH !!??

idle mulch
#

if someones available,hop in

#

match in 3

#

match in 1

fair adder
#

any game starting soon?

fair adder
#

7 players

orchid sentinel
#

like fr you had 5 flags in the first 5 mins of the game

#

u ok man?

fair adder
#

Notes notes notes notes

orchid sentinel
#

and i cant get a shell!!!!!

#

it just hangs when i set up a nc listener

#

everyone in the current koth game pleeeeasseeeee reset the machine

#

we have 3/4 rn

fair adder
#

Reset only happens when the machine is broken

orchid sentinel
#

naa

nova tide
orchid sentinel
#

idk tho

#

it might not be

orchid sentinel
#

and ive done nothing wrong

#

it just hangs

orchid sentinel
#

something is definitely sus

orchid sentinel
#

thats cheating

nova tide
#

Then try other possible ways to get foothold. Resetting might not help.

fair adder
nova tide
orchid sentinel
#

there is no hacker in the world who does a koth and gets 5 flags in 5 minutes

#

its impossible

nova tide
#

I can get them under a minute. But that's not the issue here.

orchid sentinel
#

ok thats not the point

nova tide
orchid sentinel
nova tide
#

He might have done the machine before.

orchid sentinel
#

but thats not the point here

nova tide
orchid sentinel
#

i cant get a shell

fair adder
nova tide
#

So you can't get a shell means he is cheating?

orchid sentinel
#

no.

#

it does not mean he's cheating

#

there is nothing i am doing now that is wrong that should prevent me from getting a shell

#

its hanging

nova tide
orchid sentinel
#

ive done this koth game lots of times

nova tide
#

Then there are still different ways to get a shell. Well the machine got reset anyways good luck

fair adder
fair adder
vital tide
#

anyone want to play?

vital tide
#

no one?

fringe sigil
#

hey someone available to join the koth?

stiff egret
#

You need to share the invite link and NOT the spectator link, others can only join using invite link.

orchid sentinel
#

less goooo

#

join up

fair adder
#

helo 🐣

fair adder
#

that's fun playing with people who vote reset for no reason

#

🐣

orchid sentinel
#

wdym

fair adder
#

i didn't πŸ™‚ but ok

#

i mean if you wnat to reset it thats no problem

#

the outcome will be the same

#

again and again

#

did you even get access btw?

#

i havent seen anyone in the machine other than cleverrat

orchid sentinel
#

brother i couldnt even ssh into the machine because you have changed the contents of one of the files like sshhhhhhhhhhhhhhhhhhhh

#

i left the game anyway

fair adder
#

ok but that's not against the rules tho?

orchid sentinel
#

no way im playing against you again

fair adder
#

why?

orchid sentinel
#

apparently it is πŸ™‚

fair adder
#

removing the ssh key == rendering the machine unusable?

#

what?

orchid sentinel
orchid sentinel
#

therefore being unusable

fair adder
#

it's not the only way

#

you're just too lazy to look for another one

orchid sentinel
#

lmao this guy is a 🀑

stiff egret
fair adder
#

Guys let's chill out

fair adder
#

4-5 ways to get foothold

#

Oh...Holmes is here

#

don't spam resets

#

btw all it takes to find another way is take a look at port 8080

charred delta
#

And for what its worth I would love to do a CTF or KOTH soon. Never did one! Watched some guys do it live today and it looked pretty kool! Would love to learn methodologies and strategies! Expect questions from me in the future!

stiff egret
#

All the best!

charred delta
#

arigato!

fair adder
quiet schooner
#

@orchid sentinel ^

orchid sentinel
#

ok

frail ridge
#

Can i edit the passwd file to block any shell from new users?

nova tide
quiet schooner
#

@remote wasp We don't post that command here

bleak trail
#

Heeey !

#

if you want to join and come Discord :))

quiet schooner
#

-warn @remote wasp Repeatedly posting destructive commands, even after being asked not to. (rule 17)

sour vectorBOT
#

⚠ Warned nwkz#7310

fair adder
remote wasp
#

aheuaheuaheuheu

#

s0rry gr1ng0

vital tide
#

anyone down for KOTH

fair adder
#

send location

#

@vital tide

vital tide
#

1 sec

fair adder
#

oh i think i just joined it

vital tide
vital tide
fair adder
#

you playing another one?

vital tide
#

okok

#

ill start on this one

vital tide
fair adder
#

no

vital tide
#

okok ill just do this one then

fair adder
#

what are you trying

#

@vital tide

vital tide
#

im doing some stuff on the web server

fair adder
#

i see you two messing with port 80

#

i changed the password

#

to wordpress

vital tide
#

idk what the thing with the panda.thm thing is

#

in the robots directory

#

im still kind of a noob

fair adder
#

that means you should add panda.thm to you /etc/hosts

vital tide
#

oh

#

wait

#

port 8080

#

has tomcat

vital tide
fair adder
#

put 10.10.183.246 panda.thm in there

vital tide
#

oh okok

#

wait what does that do tho

fair adder
#

but you don't need this if you're not going for the wordpress foothold

vital tide
#

i might mess around with it

#

like this?

fair adder
#

yes

#

bro

#

i feel like i'm chilling in f'ing mars rn

#

432 Hz Destroy Unconscious Blockages & Fear, Binaural Beats

You can download this track with the title "432 Hz Destroy Unconscious Blockages" here:
Amazon: http://amzn.to/3bWrvHq
7 Digital: http://bit.ly/2THr1LK
or listen to it on:
Spotify: https://spoti.fi/2xubbvn
YouTube Music: http://bit.ly/2TUihRu
Deezer: http://bit.ly/3cRVVbG
Akazoo: htt...

β–Ά Play video
#

wtf

vital tide
#

lmao

vital tide
fair adder
#

yes

#

but as i said i changed password for the user

#

so there's no point

vital tide
#

why did I have to add the host then?

#

shoudnt I already be able to access the wordpress directory?

#

got a flag ajsdbasd

#

im tryna find some credentials and maybe get something through the mysql

fair adder
fair adder
#

so when you add it to /etc/hosts your browser sends the request with the host: panda.thm header

vital tide
#

thats the only thing close that I found so far

fair adder
#

i have no idea

vital tide
#

its just on the home page html code

#

its in a comment

#

hmmm maybe some stego on the image?

#

lemme just keep messing with the tomcat ajhsdbabd

fair adder
#

CVE-2019-0232 maybe

#

let me try it out in metasploit

#

didn't work

vital tide
#

yeaaa i was experimenting

vital tide
fair adder
#

nah i'm tired

vital tide
#

ah okok

#

sad

#

im trying stuff on the smb server

#

Known Usernames .. administrator, guest, krbtgt, domain admins, root, bin, none

#

anyone else want to play another one?

fair adder
slim lake
#

@fair adder

#

Reset please

vital tide
#

anyone wanna play?

#

bruh if this is a windows machine im acc dead

fair adder
#

@fair adder why you left

fair adder
vital tide
#

it will be funnnn

fair adder
#

ok and i'm gonna cry

#

why did you leave me evan

#

why did you do it

#

because i gotta install ram

#

ok

#

i download keyboard now

#

sudo apt-get install 16gb of ram

vital tide
#

only the best

fair adder
#

Subscribe to The Telegraph on YouTube β–Ί https://bit.ly/3idrdLH

Billionaire Elon Musk has unveiled a video showing a cyborg monkey playing the 1970s video game Pong entirely with its mind using brain implants.

The footage shows a nine-year-old macaque called Pager with a chip inserted on each side of his brain, created by Musk's AI company Ne...

β–Ά Play video
#

good luck @vital tide

vital tide
fair adder
#

h1: medium kekw

#

it hurts

#

god why

vital tide
#

BRUHHHH WHY IS IT WINDOWS

#

NAHJHHHHH

#

IMA BE DEAD

#

I CANT DO WINDOWS STUFF FOR MY LIFE

fair adder
#

pain.

#

oh

#

@vital tide are you playing?

vital tide
#

bruh I hate windows ajbsda

#

yea

fair adder
#

i found something

#

look port 80