#koth

1 messages ยท Page 65 of 1

latent osprey
#

The loop I m using is one liner

static aspen
#

ahh smort

latent osprey
#

How did you hacked the machine??

static aspen
#

the attack.sh was a script to gain a root shell

#

and all i did was manipulate the ports to find creds

latent osprey
#

Which vulnerability did you used??

#

Demm pwfeedback

static aspen
#

nvm not that one whoops wrong one

latent osprey
#

Woah! I don't know about this

#

Cool thanks

static aspen
#

lmfao you removed sudo noice

latent osprey
#

Hi

#

You know

#

The exploit you used from saleem rashid

static aspen
#

yeah

latent osprey
#

It is a not a local exploit

static aspen
#

yeah i realised that

latent osprey
#

You can use it directly to go to root

#

Yeah! I was confused for a bit

#

I thought you shared another exploit

static aspen
#

i was stupid lol

latent osprey
#

Umm! Naah

#

I just learned about chattr from you lol

static aspen
#

๐Ÿ˜†

#

it took me a while to even remember the chattr syntax

latent osprey
#

Lol! I just deleted chattr

static aspen
#

yeah i saw you deleted chattr and sudo, smort moves

latent osprey
#

And then downloaded it again to unset king.txt

latent osprey
#

Then again deleted chattr NotLikeThis NotLikeThis NotLikeThis

#

I was like wtf am I doing

#

Bro but it was amazing thanksblobheart blobheart

static aspen
#

np โค๏ธ

#

do you see the messages when i use wall?

latent osprey
#

Yess

static aspen
#

hahaha

latent osprey
#

I was thinking that what is this ! I saw that for the first time lol

#

I was killing your shells

#

Umm! Were they getting killed on your side??

static aspen
#

nah

#

i have a stable one now

latent osprey
static aspen
#

with ssh

latent osprey
#

Demm

static aspen
#

i found pasta's creds

latent osprey
#

I was wasting my time lol pepehands pepehands

latent osprey
#

Ooo I haven't saw that

#

But that's great ๐Ÿ”ฅ๐Ÿ”ฅ

static aspen
#

the "pneumonoultramicroscopicsilicovolcanoconiosis" or the binwalk stuff kekw

latent osprey
#

Okay the loop!

static aspen
latent osprey
#

While true; do echo playgue > king.txt ; sleep 1;done

Credits as usual @Lammm#7495

static aspen
#

is that it

latent osprey
#

Yeah

static aspen
#

wow, in a .sh file or command line?

errant marten
#

you need "do"

latent osprey
latent osprey
#

It will run in bg

static aspen
#

ahh smort big brain

errant marten
#

to run a while loop in bg just add &

#

exp

latent osprey
#

Yup! Otherwise this will not let you do anything on that terminal

errant marten
#

while true; do echo "1trick" > king.txt; sleep .1; done &

dull jacinth
#

whos xxx

#

two words i can say to him

latent osprey
#

Lol

#

I will reach master today

gentle hatch
#

you can also use the watch command, watch -n 0.1 echo "king" > king.txt

dull jacinth
#

/usr/bin/chattr +i king.txt

gentle hatch
#

takes up your terminal but if you're doing a loop race not really much else to do

errant marten
#

loops are for noobs

latent osprey
latent osprey
errant marten
#

its a binary

dull jacinth
latent osprey
latent osprey
dull jacinth
#

he needs to be banned

#

from tryhackme

latent osprey
#

Why?

static aspen
dull jacinth
#

Well first of all he isnt playing koth by the rules

latent osprey
#

Yeah I saw he just won a match

gentle hatch
#

message support with the game ID and proof

dull jacinth
#

yes ill screen shot

latent osprey
#

What did he do?

static aspen
#

ahh im guessing he did something like the dreaded rm -rf command

dull jacinth
#

for now lets just not mention stuff about this

#

we might alarm the guy

latent osprey
latent osprey
static aspen
#

the only things i think you can delete/fix are suid's sudo perms and chattr

#

and small vulns

dull jacinth
#

all i know is you patch the vulns and dont remove anything

gentle hatch
#

can't delete binaries afaik

dull jacinth
#

not sure but as long as it doesnt break the game

static aspen
gentle hatch
#

big reason I stopped playing is one or two idiots always ruining every game

errant marten
#

You can del chattr

gentle hatch
#

if someone brings it in you can delete it

errant marten
#

look at the rules!

#

it even says you can

#

only chattr

static aspen
#

btw gg

dull jacinth
#

nice

#

im quite familiar with esox

#

i think ive played with him before

latent osprey
sour vectorBOT
#

Gave +1 Rep to @static aspen

latent osprey
stiff egret
#

Please keep it PG13.

#

@dull jacinth

fair adder
#

@stiff egret check dm again pliz? :))

#

if u free

stiff egret
#

I just woke up, will get on the system in about 2 hours.

unreal jasper
#

yo, koth anyone?

latent osprey
#

Hi join 20MIN remaining

#

@unreal jasper

strange escarp
#

join it starts in 15 min

#

easy machines only

latent osprey
strange escarp
#

its over

latent osprey
#

Lol how

strange escarp
#

insufficient

latent osprey
#

Ook

strange escarp
#

players

#

if u wanna play i will create another one

#

will uplay

latent osprey
#

Yup

#

Which Macchine?

strange escarp
#

ok gonna create an random easy

#

is it ok with u

#

u there

latent osprey
#

Yes

#

I m herr

strange escarp
#

starts in 5 min

#

rq

latent osprey
#

Join koth vc

strange escarp
#

a min

dull jacinth
#

I forgot

strange escarp
stiff egret
sour zealot
latent osprey
sour zealot
unreal jasper
latent osprey
#

Koth anyone

novel galleon
#

hi

fair adder
#

@latent osprey send link

novel galleon
#

okay

#

this is already intimedating

#

is it like singleplayer?

fair adder
#

yes it is singleplayer

novel galleon
#

you got to defend it yourself?

#

damn

#

oaky

fair adder
#

correct ๐Ÿ˜„

novel galleon
#

i dont know blue team shit

#

but sure lets go

fair adder
#

not like that

#

you attack and then defend

#

@latent osprey ill make actually

latent osprey
#

Are you making

#

Or should I make??

#

@fair adder

novel galleon
#

how good do you have to be

latent osprey
#

Ook making

fair adder
#

i was making

novel galleon
#

good luck guys

fair adder
novel galleon
fair adder
#

good luck

latent osprey
#

Ook joining

novel galleon
fair adder
#

oh gotta change your dificulty

novel galleon
#

oh

#

where

#

settings?

fair adder
#

go to setttings

#

yes

#

then join again when your done

novel galleon
#

okay how do i join now

latent osprey
#

Join

fair adder
novel galleon
#

okayy

#

joined

#

now what

fair adder
#

we wait for game to start :)

novel galleon
#

okay

strange escarp
#

๐Ÿ˜‰

novel galleon
#

what should i know

latent osprey
#

@strange escarp join

strange escarp
#

done

fair adder
#

eyyyyyy

latent osprey
#

Woah

#

Gonna be a gg

novel galleon
#

what should we try to do

novel galleon
fair adder
#

try to get in the machine before anyone else

#

and make sure they dont get in

novel galleon
#

VC?

fair adder
#

i mean i wont talk but sure

#

you can screenshare

strange escarp
#

i only know how to hack but idk how to stop imao

novel galleon
#

i dont know anything lmfao

fair adder
strange escarp
#

yeha

fair adder
#

"how to kick people out of my ssh session"

novel galleon
#

so

strange escarp
#

haha

novel galleon
#

will the box start off with any vulns?

fair adder
#

of course

strange escarp
#

they have 3 to 4 or more

#

vulns

novel galleon
#

and then

#

you have to log in

fair adder
#

yes

novel galleon
#

and patch those vulns

#

right?

fair adder
#

but get flags

novel galleon
#

and flags will be anyhwere

#

correct?

fair adder
#

yes you can look around

#

could be in ..

strange escarp
#

whats the machine lvl

#

@latent osprey

fair adder
#

i think we gotta wait

strange escarp
#

curosity

#

im gonna wear my hoodie wojak_pepe_hoodie

fair adder
latent osprey
strange escarp
#

oh ig ur the authon of the game

fair adder
#

nah i am but we cant see yet

#

when game starts then we can

strange escarp
#

ok

fair adder
#

please dont be a windows machine kek

strange escarp
#

haha

#

yea

novel galleon
#

okay

#

idk what im doing

#

but im doing sometihng

strange escarp
#

haha

novel galleon
#

OMGGGG OH GOD

#

IDK WTF IS GOING ON

#

WHAT DID YOU GUYS PULL ME INTO LMFAO

fair adder
#

i know what i need to do

novel galleon
#

good for you,hacker

fair adder
#

gonna do it on my kali vm though

novel galleon
#

๐Ÿ˜ญ

fair adder
#

what are you on?

novel galleon
#

sshed kali vm

fair adder
#

you got ssh?

novel galleon
#

what?

#

on my kali?

strange escarp
#

willl be a good place

#

for disss

novel galleon
#

yeah

fair adder
#

god damn

#

ok im gonna get something now i think

latent osprey
ashen parrot
#

Any Beginner who is interested in playing koth for practice with me

nova tide
#

me animewave

unkempt moss
#

if any beginner wanna do koth for practicing DM me or ping me

strange escarp
#

@latent osprey

#

ping me back when ur in

latent osprey
#

Hi

strange escarp
#

hlo gonna have my lunch

#

2:30 or 2 oclock

#

fine with u

#

,?

ashen parrot
#

Any Beginner who is interested in playing koth for practice with me

unkempt moss
#

let do it, after I done eating

spark rock
#

Pretty new to all this stuff, what's the best way to get to know the basics of KOTH. From a complete beginner standpoint.

gentle hatch
#

just start playing and you'll learn, there's a group that regularly plays in voice chat you can always hop into and will give you some tips

spark rock
#

Got it, thanks ๐Ÿ‘

unkempt moss
#

why koth not currently work?

stiff egret
#

Be a little more specific?

unkempt moss
unkempt moss
stiff egret
#

It is repetitive or happened for just one match?

unkempt moss
#

it been like this for almost 2 hours now

stiff egret
#

cc: @lusty portal
This same issue keeps popping up everytime there are some issues with site. I am guessing this has something to do with earlier problems today?

wide gate
#

why always the same people play koth?

#

i don't know what mean cheating and how far we can go with the machine!

nova tide
wide gate
nova tide
#

!docs koth

pearl gladeBOT
nova tide
#

it would be super helpful for you as well. There's also a blog post linked you can read that too.

wide gate
sour vectorBOT
#

Gave +1 Rep to @nova tide

nova tide
wide gate
#

and why always the same people

#

around 4 or 5 persons always winning

#

When I see their accounts, I lose hope in the game

nova tide
#

There are multiple vulnerable services running that you can explore. Try patching the one you got in through and after that explore the box a bit and see if you can find anything.

wide gate
#

thank u by the way for your time

latent osprey
#

@lilac basin

#

Send me the link

#

Ookk np

opal dove
#

the current meta for the game is to learn the machine, then quickly get your scripts on the machine before anyone else

#

I'd focus against trying to win initially, although it seems counter intuitive

#

if you want to learn patching, don't run offensive scripts, just try learn what the web applications etc. are doing

#

and how you can patch that

#

if you run offensive scripts it can piss people off and they start killing shells :(

wide gate
#

i found that koth isn't good for learning . it's just let u type quick and race the time. but the same web app and the same vuln no thing new .

quiet schooner
#

Try hogwarts then

ashen parrot
#

Any beginner who wants to play koth with us for practice

strange escarp
#

Hey @ashen parrot

#

U here

#

Ping me back when u want to play

ashen parrot
#

Please tell me how to kill other people's terminal in koth

strange escarp
stiff egret
#

If you google about it, you can find way faster and way better ways to do this.

ashen parrot
#

Any tips and tricks to defend in koth

lilac basin
#

dont kill shells, dont run while loops.

quiet schooner
#

Killing shells isn't a great defense. Patching vulns will do much better.

dapper escarp
#

Persistence -> Patch -> Purge

  • Set up your persistence so you can get back in with ease.
  • Patch the systems vulns so you can prevent others getting in.
  • Purge those who may have gotten in
quiet schooner
#

I'd also break down patch a little further: If people can get in but can't get root then that's a little less serious than if they can get root and kick you out

lilac basin
#

patch comes before persistence

quiet schooner
#

Eh, not much point patching if someone then locks you out, means you can't get back in

lilac basin
#

but if you path before someone else get root you will remain the only one that obtain root priv

#

instead if you dont patch and someone becomes root he can kick you off and remove your persistence

#

also he can kick you off before you get persistence

ashen parrot
quiet schooner
#

I'm not saying don't do it

ashen parrot
#

but how to do it

quiet schooner
#

You've been told what to research

ashen parrot
#

kill -9 PID

#

?

fair adder
ashen parrot
#

but when i do ps -a

#

i find only two-three process

fair adder
#

That's how I learned and is the best way

lilac basin
ashen parrot
#

ps -aux

lilac basin
#

use this that looks better

strange escarp
#

hey

#

can we make infinite no of broadcast msg using any script

lilac basin
#

"no of broascast" is the message?

strange escarp
#

like this

#

i cant stop that

strange escarp
lilac basin
#

oh this is done with wall

strange escarp
#

haaha there is no remedy right then

lilac basin
#

yeah cuz i think it is a while loop

fair adder
#

I think there is...Muiri said in general that this could be escaped..I don't know how coz wasn't able to understand that properly what solution he said

strange escarp
#

i think my team mates are making use of koth writeups and getting root in less that 10 min psyduck

#

and making this nonsence

ashen parrot
#

someone is doing infinite infinite loops in koth

#

how to stop it

#

plz tell me now

strange escarp
#

ur friends are doig it bro

#

i have noting to do with that

fair adder
stiff egret
#

mesg n

#

This will stop wall msgs on your Pty.

#

@strange escarp

strange escarp
#

Oh thanks

#

Noted

strange escarp
sour vectorBOT
#

Gave +1 Rep to @lapis linden

strange escarp
#

+rep @stiff egret

#

What

#

Not working

#

Cool down ig

stiff egret
#

dumb bot I tell you, dumb bot.

strange escarp
opal dove
#

+rep @stiff egret

sour vectorBOT
#

Gave +1 Rep to @stiff egret

opal dove
#

there we go

#

I got your back

stiff egret
#

lol thanks

#

that doesn't change the fact that you dumb @sour vector

nova tide
sour zealot
lilac basin
fair adder
#

koth game tonight at 5PM pst time be there or be square

modest rock
fair adder
modest rock
fair adder
modest rock
#

that gives me time to organise a koth folder together

fair adder
#

here we go

fair adder
#

Actually nikto started to return some results but gobuster i keep getting errors

stiff egret
#

Which machine is it?

fair adder
#

h1: easy

stiff egret
#

๐Ÿค” I don't think directory brute force will work on that one.

fair adder
#

i know where one flag is but i can't get to it

modest rock
fair adder
#

nmap is taking for ever !

modest rock
#

ooh yh i feel ya xd

fair adder
#

I know thers a flag in here !!!

#

I'm going to run burp

#

Now burpsuite if frozen smh

modest rock
#

ugh i can't even ls properly smh

fair adder
#

burpsuite completely broke my machine

#

it's subzero frozen

stiff egret
#

just burpsuite being burpsuite

fair adder
#

i can't see the uploads button to upload my .php shell!!

#

all i see is the browser button fml

stiff egret
#

you don't need burpsuite to get a shell from that foothold

fair adder
#

webshell????

#

here we go

modest rock
#

my netcat is broken it won't connect with the webshell lol

stiff egret
#

You sure you are calling it back right?

#

try curl localhost:<PORT IN REVSHELL> on your machine with nc open, to see if the netcat is dead or you are doing something wrong

#

if netcat catches the connection, then you are calling the php/jpg file wrong on the webpage.

fair adder
#

restarting my entire machine FML

fair adder
#

I can't seem to upload a php file without having to use burp

stiff egret
#

||extensions matter|| that's all I can say

fair adder
#

Dudes i'm so freaking close !! smh

#

i can't get this stupid webshell to work ๐Ÿ˜ซ

#

i upload the .php rev shell and i navigate to /uploads/webshell.php?cmd=whoami

#

and nothing ๐Ÿ˜ฆ

fair adder
#

I was just about to use pentestmonkey and start up nc

#

I couldn't get webshell.php to work ๐Ÿ˜ฆ

modest rock
#

same XD

fair adder
modest rock
#

jup i uploaded an embedded jpg

fair adder
#

I kept using .php extension are you kidding me.

#

How many directories did you find ?

modest rock
#

aaah that's unfortunate

#

not a whole lot

#

i stopped gobusting midway when i saw the ticket page

fair adder
#

did you manage to rev shell?

modest rock
#

i tried curling but it got a connection but then dropped if i hit enter

fair adder
stiff egret
fair adder
stiff egret
#

Honest advise, do watch his Bsides Nova KoTH video, it's 3 hours long or something I think. Not sure, but I watched it on 0.25x to see what they were doing and it's awesome

fair adder
stiff egret
#

Totally worth it

fair adder
#

I love this !!!

#

anyone wanna do koth

fair adder
fair adder
fair adder
stiff egret
#

I can play one too if you send the invite link

fair adder
#

hmm thinkies

#

XD

stiff egret
fair adder
#

after metasploit is done installing on wsl, i'll send invite link @stiff egret

#

Burpsuite froze my machine

stiff egret
#

What are your specs? @fair adder

fair adder
#

we're gettiing there

#

You guys started already?

#

nope just installing my metasploit

fair adder
#

when I found the service it was running

stiff egret
fair adder
#

Super glitchy

#

Burpsuite froze and i had to restart my entire machine

#

nothing was clicking or running

stiff egret
#

๐Ÿค” I've used i5 2nd gen with 8 gigs for 1 year, it was smooth af and I usually had a kali VM , discord, Firefox, notion open at almost all the time

fair adder
#

I had Burpsuite, NMAP, gobuster, nikto running and boom it just froze/crashed

stiff egret
#

You on SSD?

fair adder
fair adder
stiff egret
#

then I'd say use linux in dual boot or as main OS

fair adder
#

instead of windows?

stiff egret
#

I had arch as main OS and kali in VM. Did everything in vm,

fair adder
#

i wanna do that but i get errors on my computer downstair's i fully switched to ubutnu and it doesn't find my internet

stiff egret
#

Use this to make sure your main OS doesn't die bc of your VM

#

Execution cap

#

that way your main os will have 20% of the CPU even if all processors go 100% in VM

fair adder
stiff egret
#

๐Ÿคทโ€โ™‚๏ธ you can use regular Ubuntu as well

fair adder
#

in the one koth game john hammond did he had nothing installed

stiff egret
#

lol yeah, I remember

fair adder
#

I love my windows blobheart

#

i rememeber

#

yeah ๐Ÿคฃ

stiff egret
fair adder
#

Lol

stiff egret
fair adder
#

By far it's been a smooth ride so far except for today

#

don't know what happened

fair adder
stiff egret
# fair adder

yeah that's the one, at 0.25x feels like 3 hrs ๐Ÿ˜†

fair adder
#

LMAO

stiff egret
fair adder
#

Okay watching this now ๐Ÿ™‚

fair adder
stiff egret
#

wsl

fair adder
#

they say nmap is broken on wsl

stiff egret
#

I thought it were installing stuff in wsl

fair adder
#

oh i am

#

it's just they say wsl and nmap don't go hand and hand

stiff egret
fair adder
#

it's a cool thing :D

#

yeah lemme show you what happens on my wsl

stiff egret
#

Will give it a try someday.
You can't skip windows in corporate field.
It's a nightmare that's gonna come weather you like it or not

fair adder
stiff egret
#

sublime

fair adder
#

no way !

#

ugh

stiff egret
#

lol why?

fair adder
#

so nano < sublime ๐Ÿ˜ฆ

#

can i create .php with sublime?

stiff egret
#

kekw anything > nano

fair adder
#

Noooooooo

#

my mind has been changed ๐Ÿ˜ฆ

stiff egret
stiff egret
fair adder
#

๐Ÿคฃ

#

wonder what happpens when i use multiple flags ๐Ÿ˜ณ

stiff egret
#

try 2>/dev/null?

#

that should pipe away the errors

fair adder
#

tried that

#

and same thing but

#

noticed this at the top

#

i scrolled all the way back up

stiff egret
#

eh just use a VM

fair adder
#

fax

fair adder
#

look at all this shit john was running

#

what the flying hacker life is all this

#

lol

stiff egret
#

I watched this video so many times, I almost memorised it

fair adder
#

You are a true hacker

stiff egret
#

lol

fair adder
#

you have to multi task to work at mc donalds shit is hard

#

look at all those screens

stiff egret
#

yeah I get it

fair adder
#

It's like flying a plane

stiff egret
#

hence 0.25x

fair adder
#

he can almost be a damn pilot lol

stiff egret
fair adder
#

thank you @stiff egret

stiff egret
#

the bot sux anyway nvm ๐Ÿ˜„

fair adder
sour vectorBOT
#

Gave +1 Rep to @stiff egret

fair adder
#

Hopefully i don't get in trouble

#

But it was a really cool video you suggested so thank you for that

stiff egret
#

v4 sublime looks great by default

stiff egret
fair adder
#

And author/blogger XD

stiff egret
#

KoTH-lead is the lead of KoTH staff

fair adder
#

Lol you are amazing !

stiff egret
fair adder
# stiff egret ayyyy

Hey man you suggested such a great video actually... I now truly see what it means to "fly" using linux and your hacking skills. This is such a great vid

#

I also understand now why hackers like to have multiple screens

stiff egret
stiff egret
fair adder
iron cloud
#

Hey would anyone like to play KOTH? Cause I am really bored right now

fair adder
stiff egret
iron cloud
#

care to join? @fair adder

stiff egret
#

I've joined in, although I re-installed my VM so I might end up losing bad. but eh

fair adder
#

make it public so others can join

stiff egret
#

It's a public game, that's random box selection

iron cloud
#

Its a public server

#

I cant choose box

fair adder
#

you also have the option to create private

iron cloud
#

should I?

fair adder
#

No

iron cloud
#

K making

fair adder
#

make it public

iron cloud
#

ya we can play public

fair adder
#

i think there were others who wanted to play

#

boy i need to get my notes straight

iron cloud
#

VC?

#

??

fair adder
#

nah don't feel like talking rn

#

just hacking ๐Ÿ™‚

iron cloud
#

fine........ ๐Ÿ˜„

#

I just played one yesterday and GOSH I WAS supposed to be king, but the last moment, someone changed the permissions for king.txt ๐Ÿ˜ซ

fair adder
#

can't you chmod +x again?

iron cloud
fair adder
#

no?

iron cloud
fair adder
#

i never was in ?

fair adder
iron cloud
#

y werent? ๐Ÿ˜ž

iron cloud
#

I also guess he used chattr

stiff egret
#

immortal

iron cloud
fair adder
#

LMAO

#

that is elon musks laptop

stiff egret
#

my VM thinks I have a nuclear core attached to it ๐Ÿ˜†

fair adder
#

it would be crazy if tesla came out with their own laptop and cpu

iron cloud
fair adder
#

it would probably be a chargeless laptop

iron cloud
#

VC? Mr holmes? @stiff egret

stiff egret
iron cloud
fair adder
#

sickkkkkk

stiff egret
#

that's probably the lowest around here

delicate cedar
fair adder
stiff egret
#

yay is package manager/installer for arch.

#

equivalent of apt

fair adder
stiff egret
#

yep

fair adder
#

what!!!!!

stiff egret
#

fresh arch install

fair adder
#

he said he didn't use arch!??

#

wow

#

lol

stiff egret
#

[john@arch]

fair adder
#

I thought he used Ubuntu?

#

oh dang

stiff egret
#

uh, it varies

fair adder
#

he must of switched a long time ago

stiff egret
#

the video is of a long time ago

fair adder
#

yup

fair adder
iron cloud
#

I had a late start guys ๐Ÿ˜ฉ

#

had an urgent call

#

seems like @stiff egret king

stiff egret
#

dw nothing is patched

wind furnace
fair adder
#

so ya i'm wrong on that one

wind furnace
#

I wouldn't say completely wrong. Since you can install software with it blobfingerguns

fair adder
fair adder
fair adder
stiff egret
fair adder
#

LOL still playing

#

I see Mr.Holmes is king of course lmao

fair adder
stiff egret
#

sure np

iron cloud
#

hey holmes wt the hell did u do? the machines too slow man @stiff egret

stiff egret
iron cloud
#

can we reset it plzzz?????? Looks like nik isnt alive

stiff egret
#

Uh sure

#

one sec

iron cloud
#

fasttttt man only 20 min remaining

stiff egret
#

it's working fine

iron cloud
#

u know wt? never mind

fair adder
#

370 points ๐Ÿคฃ

stiff egret
#

I just got the rev shell back, the machine is OK

fair adder
#

@stiff egret after you get in and get root do you still give other people a chnace to try and at leas get something?

stiff egret
#

the machine is in the same condition, I only added my persistence

fair adder
#

that's just what i need

#

wanna play another one

stiff egret
#

Sure

fair adder
#

yay

#

just ping me when

stiff egret
#

Starting in 24 mins

iron cloud
stiff egret
#

Uh no I did not

iron cloud
#

and whats with the php? it just doesnt execute

#

first of all the machines all funky

#

can uuuuuu plzzzzz resettttttt

stiff egret
#

done

iron cloud
#

ladies and gentleman, we have a new king

#

Should have done this at first LOLLLL

#

lord I hate the machine..... its tooo funky

fair adder
stiff egret
#

No

iron cloud
#

u have to find other vulnsss

fair adder
#

why have i never thought of that ๐Ÿคฃ

fair adder
#

i coulda kept king all i had to do is change ssh password

stiff egret
#

You can change passwords, you can patch the machine

fair adder
#

it was the only room i ever got far on

iron cloud
#

๐Ÿ˜ญ

#

times over

stiff egret
#

yeah

#

GG

iron cloud
#

I had a late start ๐Ÿ˜ซ

fair adder
#

wanna join this one @iron cloud

iron cloud
#

hey holmes it was nice playing

iron cloud
fair adder
iron cloud
#

u wanna talk about it holmes?

#

how did ya gain access? Wordpress?

stiff egret
#

the password

iron cloud
#

for shifu

stiff egret
#

yeah

iron cloud
#

knew it

stiff egret
#

static machine, easiest way in

iron cloud
#

d u know wts with wordpress? I changed 404.php but I didnt get a callback

stiff egret
#

๐Ÿค”

iron cloud
#

ya I was wondering that

stiff egret
#

you replaced the 404 with pentestmonkey rev shell?

iron cloud
#

ya I did copy paste, changed ip and port

#

and the machine was tooo funky

#

even tred curl to trigger

stiff egret
#

Wordpress does that to machines

stiff egret
iron cloud
#

yaaa........ I had expertience with mr robot ctf

fair adder
#

Freaking dope

iron cloud
#

also u know wts with tomcat

fair adder
#

CONGRATZ ya'll

stiff egret
iron cloud
#

can ya please sent url? if u don mind?

stiff egret
#

I cannot spoil machines here, I can DM you if you want

iron cloud
fair adder
#

So by changing ssh password once you find the king.txt or root.txt flag you can stay king ??

iron cloud
fair adder
iron cloud
#

hey @stiff egret , honestly, u changed chattr permissions right? ๐Ÿ˜

stiff egret
#

Yeah, obv, that's how you stay king

iron cloud
fair adder
#

hmm lion

#

never done this

stiff egret
fair adder
#

ahh might need new vpn file

iron cloud
#

i am innnnnnn

fair adder
#

um i think i left

#

nvm all good

#

ok one of you patched ftp

stiff egret
#

not me

#

Time to start patching

#

get your persistence people, Patching starting in 3..2..1

iron cloud
#

someone used chattrrrrr

stiff egret
#

the question is where are you hiding that pspy @delicate cedar

iron cloud
#

whoooooo kicked my shelllllllllllllllllllllllll

#

lorddd

fair adder
#

am still not in anything

stiff egret
#

I am not sure if you can get in now

fair adder
#

lmao ๐Ÿคฃ

stiff egret
#

although you can still find the vuln

#

if you see the vuln and the exploit doesn't work

#

that's probably me being a mean person here

fair adder
#

i couldn't get into ftp in the beginning was it even possible

stiff egret
#

I honestly dont remember

delicate cedar
iron cloud
#

HEy wtff man...... the moment I echo to /root/king.txt, my shelll kicks offf

fair adder
#

๐Ÿคฃ

stiff egret
#

No idea what happened here, but someone messed up

iron cloud
#

did someone messed with tmux tooo varg

#

tis getting interestingggg

stiff egret
#

whoever planted that ssh backdoor, hats off. That was NEW

delicate cedar
#

What happened to ssh server?

stiff egret
#

Died bc of that preload rshell

#

that's my guess

#

I did kill some of it's processes, but that shouldn't take down the server

delicate cedar
#

Seems like no one trying to fix ssh server

stiff egret
delicate cedar
#

Just coming back up -_-

stiff egret
#

daemon and main both are on

#

You've won @delicate cedar resetting the machine now at 20 sec gap to extend it

delicate cedar
#

๐Ÿ˜‚

stiff egret
#

oh nvm gg

iron cloud
#

who the helll reset at last

#

๐Ÿ˜ต

stiff egret
#

It was fun lol

iron cloud
#

ya it wasssss

#

would be real fun if we were is VC

stiff egret
#

I don't know what were you doing with that preload in ssh

iron cloud
stiff egret
#

But that's something I haven't seen before

delicate cedar
#

My backdoor is only ssh ๐Ÿ˜ข

iron cloud
delicate cedar
#

I'm basically doomed when that messed up

stiff egret
#

But the game ended

stiff egret
iron cloud
#

gosh I have like 100s of tabs on chrome open here ๐Ÿคฃ

stiff egret
#

๐Ÿ˜‚

delicate cedar
#

Looks like rshell is messed up, time for write rk show his true power.

#

Also @stiff egret you didn't stripped ur binary

#

I can quickly reverse the content

iron cloud
#

hey...... does anyone know y I was kicked off while echo ying to king.txt

stiff egret
stiff egret
opal dove
#

stellarix got a new backdoor? ๐Ÿ‘€

stiff egret
#

Yep, most probably, can't say much until I see that binary

#

It's some sort injection in ssh process

#

Probably a custom reverse shell sending binary, hooked with ssh

opal dove
#

oo, that sounds very smart

stiff egret
#

Yeah

opal dove
#

Stellarix knows C? ๐Ÿ‘€

stiff egret
#

a pro

opal dove
#

I'll need to read up on that one

#

I haven't played against stella for a while

#

sounds like we need a game

olive flint
#

What is this channel never been here before

nova tide
olive flint
#

Oh... I'll take my leave then ๐Ÿ˜ข

nova tide
olive flint
#

nooooooooooop

ashen parrot
#

Any beginner interested in playing koth with me for practice

stiff egret
iron cloud
lavish rain
#

I mean i know what's going on, I also know the tools but I need to practice more

#

Anyone, wanna play koth?

deep crag
fair adder
#

already 3 of us in here

#

uh oh naughty joined kek

#

already lost

errant marten
#

9 people, its gonna be interesting

fair adder
#

make that 10

fair adder
#

did one of you patch the php reverse shell?

nova tide
#

GG all

pine dirge
#

got crushed ๐Ÿ˜›

#

i cracked the ssh passphrase but it wouldnt except it yell_cat

errant marten
errant marten
ashen parrot
#

Any beginner interested in playing koth with me for practice

fair adder
#

sure

#

nvm gotta go 2 bed

#

:(

stiff egret
#

I am deleting this msg, since it contains a spoiler for a fairly recent room, plus sharing spoiler information about koth rooms is not allowed.

#

@sour zealot

latent osprey
#

@stiff egret hey! The ftp part always crashes in my pc in hackers machine can you tell me something I can do about it??

stiff egret
#

You must be doing something wrong

latent osprey
#

I do this

#

But still

#

I don't get any password match

#

And after sometime my pc crashes

stiff egret
#

I have no idea how that command can crash your PC

#

that's hydra running on 15 threads.

#

It's just not possible

latent osprey
#

It runs in my pc but after 10 to 15 it just stops

#

And nothing happens

#

Which word list should we use in KOTH??

stiff egret
#

@quiet schooner Got any ideas here? (You created hackers, you obv know more about it)

latent osprey
#

For password cracking

quiet schooner
#

Someone probably changed the password before you could get it

stiff egret
#

Context: They are running hydra on ftp with 15 threads

quiet schooner
#

Hydra should be happy with 64 threads

stiff egret
latent osprey
latent osprey
quiet schooner
#

It's designed to be a good few minutes

#

It's also dynamic

latent osprey
#

Ummm! It been 8k passworda but still I haven't got the password for ftp

stiff egret
#

You are either dropping packets or doing something wrong. It shouldn't take this long. And hackers machine is hard, intentionally.

latent osprey
#

@quiet schooner is there only one way to get in haxkers mahine?? Ftp only?

stiff egret
#

This has been said time and again, I repeat it,
All machines have multiple footholds and multiple priv esc points.
Usually more than 3 each.

nova tide
latent osprey
latent osprey
lavish rain
#

@ashen parrot I can. DM me

sour zealot
#

Let's say I have the commands 'expand' and 'less' as a setuid. Is there any other way to exploit this instead of reading /etc/shadow and cracking the password?

stiff egret
#

If there's an option to pop a shell using those binaries then you can do that, but usually less can only read and so can you.

sour zealot
#

ok thanks.

errant marten
lilac basin
frail ridge
#

remember that some machine does not change the password

#

you could quickly get in, get root and change passwords

lilac basin
#

never

frail ridge
#

i do

#

and i think thats legal rigtth?

lilac basin
#

yeah it is

frail ridge
#

it just not fair for entry person thats my point hehe

#

beacuse they get lost try to get in ๐Ÿ˜ฉ

lilac basin
#

yep

#

so dont change passwords

#

so everyone can get into

#

just think about becoming root

somber marsh
#

I think I'm nowhere near a point where I could play Koth, but could anyone give me a quick rundown on where I need to be to give it a try?

vast siren
quiet schooner
#

So actually hacking into the boxes, most are like an easy-medium level THM challenge room

#

Defending is a different matter

somber marsh
#

so would you recommend going through the defensive path first?

quiet schooner
#

I wouldn't say it'd help much

somber marsh
#

more independent learning is required perhaps

#

I'll probably steer clear for now, I'm barely any good at the offensive side as is

vast siren
#

@somber marsh I'm right there with you. Might try one just to see what it's like but I wouldn't have any expectation on my results

somber marsh
vast siren
#

Teamwork sounds more fun than competition at this point

somber marsh
#

sounds like a good time, I'm in

vast siren
#

I'd like to do more work on the beginner path first but let's keep in touch

somber marsh
#

yeah, I'm at the final room of the beginner path, but I kinda breezed through things, so I'd like to review some notes, reset a few rooms

gentle hatch
#

come hang in voice chat whenever you see people in there, lots of koth players friendly to new people hang out there (including me)

ashen parrot
#

Any beginner interested in playing koth with me for practice

sour zealot
#

Maybe It's just me but why does the 'food' machine not show up here?

stiff egret
#

Only most recent 10 machines show up in that table.

#

The remaining machines are still the part of pool, but the table is for only 10 machines.

lilac basin
#

@swift juncogue "Do NOT delete system binaries (except chattr)"

supple herald
stiff egret
#

As I said, they are the older machines, and the table only shows last/most recent 10 machines

#

Shrek was the first/second machine to be released I think

nova tide
#

@lilac basin can you share the game invite?

lilac basin
nova tide
#

Noice someone removed the binaries facepalm

lilac basin
#

yep

nova tide
#

Voted reset. Don't want free king points when there are no binaries

nova tide
#

@lilac basin what's the point of killing my shell 20+ times by now in less than 5 minutes when you can simply patch it?

lilac basin
#

you are running while loops

nova tide
#

Ok now you can try killing shells, no more loops so it won't matter.

lilac basin
#

why do u run scripts

nova tide
#

@lilac basin just @ me when you plan to play again..

lilac basin
#

i will go to bed now tomorrow i will play again

nova tide
lilac basin
#

sure

fair adder
#

Koth game anyone ????

wind fjord
#

first game of koth for me o7

fair adder
somber marsh
#

would like to, but I probably won't be able to do anything yet