#koth
1 messages Β· Page 66 of 1
alright, why not
how does it work, btw, do I need an attackbox, my kali VM or is it another thing entirely
just like any other box on thm as far as I'm aware
so whatever you normally use
i like using my own kali machine π
you could probably end this and set up a new room to start in 10 mins?
idk
okay sending now
Don't forget to leave the other game @
5 mins!
get your machines ready!!! wahooo XDD
I found the freaking flag but not sure how to decode it!!!!
i already tried base64
Duuuuude
you already found the flag
was it the one i postd???
yep, one sec
how did you decode it?
Use this tool to identify, detect, and analyze hashes online
saving this
Yo i found this
Let's not post most of the flag though, Roki
Dude you found the second flag???
i'm using metasploit to log into the apache server
not working out for me
I didn't think of trying that
i don't think it works
happy to hint at what I did if you want
Yes please !
after the game if you will ?
i'm still trying to figure out how to freaking bruteforce the loging directory
and/or ssh into the apache server
I've taken some some basic notes so I can recap
I don't think one can ssh into a server?
are all of the flags encrypted???
I'm so jealous π¦
no idea how to do that or to even find out that there is a shell
oh, there's a guide
but hey i found a flag !! maybe two
awesome
very close game
you blocked echo, huh?
no
good game tho, a minute longer and you'd have it with the 5 flags I would think
yeah yeah
good on you for at least finding one flag
this was nerve-wracking π
So
where is the 5th flag tho
There were 6 on the box I think
how the f*** did guys root?
what methods did you use??
i was trying to use the metasploit /tomcat/upload bypass
and it didn't work?
I just typed sudo -l and it showed me what I can run as sudo
I brute-forced shifu's password with hydra
found other credentials too, but those didn't get me anywhere
i saw the hint !!
shifu eats noodles lmao
that was the username huh ???
yeah, along with po, which I found with wpscan
I also used wordpress to get in
see i was close
no, hydra gave another password
yeah, found those two with gobuster, and then ran wpscan to find credentials
Then i found this
I bruteforced po's password on the wordpress site, then gave myself a reverse shell using the plugins
did anyone do anything with this? if so waht did you guys end up exploiting on ?
ooh that's cool
That is very cool
I got po's password too, but I didn't find where to log in
it's almost always /path/wp-login.php
yes i found this
oooh
but some reason it wouldn't let me acces it
I didn't, I killed the gobuster scan early by accident and didn't bother with it again
the dns wasn't configured correctly, so you needed to add it to your /etc/hosts
I learned that one from the wreath network, and I was able to access the full website
what you mean overwrite the sub domains
oh, I thought it was fine since I could open the site in the first place
you mean like this echo "10.10.92.30 overwrite.uploadvulns.thm shell.uploadvulns.thm java.uploadvulns.thm annex.uploadvulns.thm magic.uploadvulns.thm jewel.uploadvulns.thm" | sudo tee -a /etc/hosts
that's one way of doing it yeah
what did you do btw, echo stopped working for me and i couldn't put my name in king.txt, vim worked, but I have no idea how to use it, so I couldn't save
echo was working fine for me
so that's how it works?
you need to put your name inside the king.txt?
yep
that is sickkk
echo "name" > king.txt
LOL
but it didn't work after a point
I just ran a loop as a background job to echo my name into the file every 0.1 seconds
what the flying fuck
I don't know bash scripting that well, I just saw John Hammond do it once and I literally opened up the video I saw him do it in for the syntax
dude we were playing with freaking thanos
that's super cool
I know some python and kotlin, but not enough to do anything with it
so how would i have been able to kill that loop?
jobs should give you a list of background jobs that are running
it's clearly a service/process running no?
ohhh okay
so something like pkill or killall
didn't even occur to me
pretty much
that was like the one trick I had going into this lol
very nice
the best trick of us all
you went in
balancing patching, persistence, and looking for flags is so hard
I kept killing your shells because I literally had no idea what else to do lol
multi tasking at it's finest
LOL
I got like a few flags with just one command as root
I had no clue where else you guys were getting in
how would u do this ??
that's in the guide
find / -name flag.txt
there were none
did you remove chattr when you got root or was that just not on the box?
I thought that was when looking for suid files
if you're not root, i mean
i also wanted to use metasploit since it hides me from you guys even more
it doesnt' include that python3 importty
it wasn't on the box, I tried the trick after you send the guide for persistence
ah
when you guys do the ps -aef --forest you can see what the attacker did
but clearly i wasn't able to root so i coudln't do this
I don't know what that is π
metasploit kinda slow considering how these boxes are made
I think you maybe jumped the gun with metasploit, yeah, the way I got in was super simple
I was surprised
if you ran ps -aef --forest you could of seen the background/service of that loop An00b did and killed it
that's neat
I'm taking notes π
Guess I'm playing this a lot more now
saaame
4:44
I felt so slow getting in though that I feel if anyone that was actually good at this would crush me
oh yeah, I would definitely be crushed too
same ! i thought everything was going to crash on me like last time
thankfully it was pretty fast this time
better to try and stick around people our level
i'm reading that now on the koth guid π
there's also a room for it on tryhackme
uses Rust instead of whatever nmap does
rustscan builds on nmap, so it's not an entirely different thing
whew
I'll make sure to install it and do the room
wonder if there was anything one could do with those samba shares
i think there is an smb exploit
I was trying to, but I couldn't figure out what was going on with that binary
using metasploit
I tried too, but I've only done something with it once or twice
I think enum4linux and some nmap scripts can deal with that
nmap can be used at a very high potential i haven't really unlocked yet
nmap cookbook is a book on my list
It was kind of funny finding things that I knew could be exploited, I just didn't know how to do them
same, really π I know it can be done, just definitely not how
there were like only 1 or two vectors i seen after running nmap
then 2 more when i ran gobuster
like the /cgi-bin/ directory defo had something to it
I've just never done something with that
did you find this with nikto?
found it with gobuster
I forgot to try nikto
I almost never use nikto, and I don't know if that's good or bad
It's just slooooooow
I had some time to chill and try stuff before you got in and looped me away
see ya
You trying to play another game here soon?
let's!
I'd try and play more often now that I have finally seen what it's like
I'm likely to be here, you can ping me
i'm going to freshin up on my skills and finish reading this blog then go to store to get some groceries !!
Thank you, i will ping !
Gave +1 Rep to @somber marsh
great!
It wasnβt chattr, just a loop written in bash
but this was done to the root/king.txt file no?
Yeah, I would give you the one liner, but I honestly think itβs to your benefit to learn bash scripting, so the pseudo code is
while(true)
echo <name> > /root/king.txt
sleep(0.1)
Wow man
Thank you @wind fjord
UGh i got so much too learn!!!!
chattr just changes permissions, in a sense, so putting that in a loop wouldnβt really help as much as other things would, especially when that binary is one that gets manipulated a lot
Np, just programming fundamentals
Note that you still need to go out and translate what I wrote into the syntax for bash
Because what I wrote will not work verbatim
good to note thank you!.
Gave +1 Rep to @wind fjord
thank you, I think I figured it out
Gave +1 Rep to @wind fjord
Are you guys ready for another koth game lol?
I am, just don't pick windows π
probably
Hey, anyone for koth?
I was doing koth and one person delete chattr binary now how can I get it again?
I tried getting it from my own pc but it is getting error
- Read the blog in pins
- You can download static chattr binary and use it.
Thanks
yes
Ok, nice
this is gonna be taken up for controversies, but
yes
- You know there are other ways to get a shell?
- You know you can noprofile your way in the box to not let bashrc load
- You do realise that validating tricks here will essentially make them public knowledge and mostly useless bc everyone will know?
well, i delete them π
So how can we learn all these things? Then
Read the blog in pins
watch John Hammond videos
watch Optional's videos
Try the tricks on public/generally released KoTH machines, like food and hackers.
Hmm! I will definitely do this thanks ππ
very excited to see some more boxes
@lilac basin why you always nyancat
only one time
Stop giving out spoilers
the moment of true @nova tide
koth game anyone?
starting in 10 minutes:
https://tryhackme.com/games/koth/join/e945bd4bb1ccb06a573f66ef
Ayooo is the machine up ??
okay this machine is explicitly complicated
only 2 ports to work with and gobuster aint returning squat
use -p-
I ran this command now map -F -sC -sV -T4 -sU 10.10.68.56
i didn't even include the -p-
that checks 1000 ports
oh crap
lol who reset the box??
not I
i was wondering the same
i had to redo my entire nmap
and recon
i found these pages which i thought was funny
Well too much for playing two games at a time i guess π
didn't knew when it got reset.. and someone was continuously killing my shell π
I think that was non1mous
i saw he was admin when i went over to the 9999/admin page
Nobody submitted a flag lol
i was trying to get the flags
anybody want to play rn?
I'd play yeah
5 mins
perfect
this is a weird box
yeah, I've almost exhausted everything I can think of
I think something finally worked, hmm
it's literally my second game π
same
i still don't know how to kill shells
shells on client or server?
How did you manage to get shell?
ps aux | grep pts
kil -9 <pid>
nothing more I can do in this game
thank you
Gave +1 Rep to @nova tide
found some weird output in the scan that looked like a hash to me, turned out it's base64 encoded with credentials
that is also how I got in
couldn't find any other way
welcome to the world of enumeration
gotta research how to bypass whatever you did to the king.txt
Wow
There were a couple of other ways I found, but using those credentials was the easiest way
I need upgrade my nmap skillz
There was lfi and a nfs share, I was just struggling to use them the way I wanted
I switched to rustscan as per advice here and in the guide
scanned all ports in seconds
yeah I found the mounted share, but didn't really know what to do with it
For some reason showmount just wasn't working? I haven't exploited/read enough nfs-stuff to know where to go
I was able to patch 1 vulnerability, which is better than last time, so I'm happy with myself
I do not know how to patch things so π
I have the basics down, so I can probably get in, get root and then I'm lost
I know you did something with chattr, so I removed the bits that you used and then hid the chattr binary
so I would either have to find it or upload my own?
yep
best place to start (after finding a way to persist) is to close up how you got in
although I couldn't find how to close up the port I used
I believe we're allowed to change passwords, but I feel like that would be kinda mean especially when we're not super experienced
I tried to change root's password so I can log in directly but I screwed that up somehow
I'd say it's fair considering there's always 3+ ways to get in
considering I found only one, I'd have been locked out π
fair enough
still have no idea what that first page did, never got around to looking at the php code
didn't see anything there
found another page with an image, but steghide wanted a passphrase
yep
in the mantra of offensive security, try harder
o7
I would, but there are huge gaps in my knowledge, started with this only 2 weeks ago
well... you're passing everyone that didn't start. so keep pushing my friend
thank you, I will, trying to do and learn something every single day
Gave +1 Rep to @blazing bane
i have seen shells that doesnt have pts
you gonna kill the shell with pid anyways.
How to report someone in koth guys??
If you suspect a player of cheating or rule-breaking, email koth@tryhackme.com with the game id (shown in url) and players username if possible. We can investigate..
Hey if player g0dmax55 here i would like to say ur a dirty player and i already reported u to koth@tryhackme.com good luck in cheating again
@cold token what kind of action did he do?
we have seen some players scanning other users
Wasn't that reported by blackmetvl
@tidal juniper he waited the king file to give him more 10 points so now he got more points and kept resting the machine every second so its impossible to connect to it again no ssh no ftp nothing at all and this is considered as a dirty cheating and unacceptable
Number of players playing that game?
Its only me and him thats why he can always reset it
Yup then it's a reportable thing
Dw support staff is too nice... they'll take the proper decision if any rule is offended
I just sent an email i think thats enough
Please send an email to the koth@tryhackme.com with relevant screenshots and information.
@stiff egret i did but without screenshots
@stiff egret all informations needed was sent today
NP, Please send screenshots afterwards, that shouldn't be an issue, Add game ID/link, the player you think was cheating, why you think they were cheating.
Stuff like that. Not limited to, that's just an example
@stiff egret info sent was
Game id
Player's username
Report reason
I didn't send a screenshot cause it wont be useful at all to see the ip it will look normal
Alright, great, someone will reach out to you or some action will be taken.
Holmes can I dm?π¬
Sure, though my replies can be a bit delayed :)
@sour zealot dude what the h3ck lmao i thought it ended and opened it from my phone now it counts that i lost the gameππ
everbody can join
when does it start
definitely got stuck on the previous one
isn't there supposed to be a flag in the flag directory at least
idk but I get it because space-jam has like 2 ways to get in I think.
no idea, but I couldn't do anything
any room that would help me understand what the way is there?
thanks, I'll definitely practice those
Gave +1 Rep to @wind furnace
Happy hacking
I guess I got really lucky the first two times I played with simple machines
Any beginner interested in playing koth with me for practice
@ashen parrot still up?
Yes
@nova tide can i talk to you in dms?
Sure
Any beginner interested in playing koth with me for practice
@ashen parrot ye
helo π£
people are already in here

@olive echo wanna join
@olive echo
hi
go easy
have you ever beat naughty @fair adder @fair adder
no
im too slow
go easy
i only have time for one hackthebox machine a week
im too rusty now
are you a skid now
yes
it will be windows machine
?
what
why reset
i didnt vote but my reverse shell wasn't working so i rage quit
:))))
another reset?
@fair adder @wind fjord the machine broken or what??
All the shells are deleted in a second
i am deleting them
I just assumed someone patched the file upload
:))
yep
i left
But the first time u didnt have time to
idk if blackmetal patched it in the VERY beggining but reverse shell upload didnt work
it was like 3 min in
Yea exactly
so i don't think he patched it at the time
box was just plain broken
anyway idk why reset the machine tho
there are other ways in
there's another file upload
in another port
thats what i did
||port 83||
@fair adder we thought it was broken thats it
@fair adder idk this machine so gg anyways
yeah this is the one machine i can't do
i love this one
why would you want to just kill all shells in loop?
how that would be blue teaming?
deleting files != patching....

Please refrain from doing that in the future.
You can simply just edit the code.
deleting files from the webserver would be the same as making that service unavailable.
That you can do.
sorry for being unclear :)))
no
evan plays koth
@fair adder come play koth with dop4
please?
OH MY GOD
what do i pay you for
if you are still looking for someone to play with i can join in π
Hello
Stop terrorising people smh
if anyone interested
join
But i just wanted to play ππ
@fair adder
i surrender
pls stop
okay π₯°
Wish i knew how to play koth
@fair adder
no
MFSOO YOUR PFP
im sad
tried to go for blood on the new htb machine but had problems with the vpn for almost 10 minutes 
ended up 64th
@fair adder your fault
yeah i actually have root access to your vpn
i kicked you off a lot
i knewu it
No that's allowed
i dont know much
If I wrote a script to always throw that on you, maybe then it's illegal
But I didn't
I will tell you now, no cap, I did not camp and try to keep springing it on you
Well i shud say, you shud focus on defense and not trashing shells of ppl.
I just made my shell give me revshell every 10 sec, so you're actually doing good by not making my shell die.
I was
So if you trash my one shell, i get another
I was trying to patch the file upload vulnerability, and I removed the private key that was just out there
Focus on patching up things.
actually you didn't it worked till the end.π
you see the key word is tried
I was going to do that, but nano wasn't on the box, and neither was busybox, so I was trying to learn vim to fix the file upload, then take care of the ssh stuff
So as you already knew, i got with user || shrek ||, Hence, I didn't use the file upload vulnerability
his || private keys ||were hanging in random file.
yeah
I get that I probably should have regened the ssh keys and then taken care of the file upload.
yeah it would have fixed everything.
I just wanted to patch the file upload first for learning purposes, but I understand your point
I was trying for the kernel exploit.. I don't know why it didn't work
Nonetheless , well played.
well played to you too
The wall would have gotten me had I not known how to deal with that
Can I play King of the hill without being level 9?
You can even play at level 1. The least thing you need is to set your experience level to intermediate/advanced in your profile.
Ok, thanks
good luck, have fun.
That's pretty cool π
You say that, but honestly, I'd be quite happy throwing that at an attacker IRL π
Hitting someone with a nyancat in koth does feel very good
24 mins
ok
π£
@wind fjord i use arch
@wind fjord u want to play without killing shells?
sure
ok
nyancat allowed or no?
thats ok
cool
rip
I just got in the box
ok
really sorry to do this, but something just came up so I'm going to have to leave the game
gg though, you did nice for not having hydra at first
gg
Whatβs alacritty btw?
Neat
@fair adder
what is nyancat ?
I mean is there a tool called nyancat
but thats just a meme tool how is it useful in koth ?
upload nyancat on the target and you can do something like ./nyancat > /dev/pts/<number>
Add & to run it in the background
It is usefull because it basically kills there shell but in a fun way.
Gave +1 Rep to @sour zealot
hi, simple question, when a new koth is released the first person to finish it gets more points? like for being the first one?
oh sorry, i mean CTF? like the new "Thats the ticket"
Well, this channel is for KoTH.
New challenge rooms will usually have blood points enabled. That's an extra 50 points per question for the first person to answer it.
yep, i messed up the categories, thought it was koth π .
also Thanks!
Gave +1 Rep to @quiet schooner
@short tusk this is the link and then my username is β0xEvanβ
U canβt join in a game that is already finished
look at #site-bugs
i was just showing jabba the game link because he asked for it
I need the game link, not the join link :p
how do i find that
Yes?
The link with the game ID at the end is the game link.
Usually the one in address bar.
The one that is being shared above, with the word join in the URL is the join link.
@tall cove
Hah! I was too slow
(2 monitors and I am on my 4th coffee for tonight)
ty for game β€οΈ
@lilac basin thanks for the koth, that was my first time and I had no idea what to expect. More work to be done!!!
Gave +1 Rep to @lilac basin
Since there can be multiple KOTH games happening at the same time, does everyone hop on the same KOTH voice channel?
There are many people now days who are playing together and join vc regularly. and some prefer not to join. its all their preferences.
found every flag but still don't know how to use busybox correctly ;-;
Literally just found the link to all of the busybox binaries 
wp @lilac basin
Hi
ahaa
Ayooooo
Yow
here you go
Nicee
starts in 5
kk
i dont have kali machine im on windows rn can I use attackbox
Noice
get you machines ready π π₯³
You need to share the invitation link, this is the spectator link
i thought i did
how do I use attackbox
Ah dang,
how do I use attackbox there isnt any option
Only intermediate players can join
change this in settings
ok2
go to profile and click about you
and scroll down
1 minute 3 seconds and my attackbox is starting
Okay I'm in
18 secs for me ?
your time is faster lol
It's starting soon
yeah i found richard as the username
nice
without using gobuster or nothing lol
nice2
there's a funny youtube video on this challenge lmao
got one flag
fuck
next time ill come with kali in vm
attackbox is slow
i'm literally installing all the tools again since i had to restart my machines a few days ago
And I found something strange
not sure if these are false positives
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: 12345
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: 123456
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: dutchess
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: password
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: 123456789
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: iloveyou
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: 1234567
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: abc123
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: princess
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: rockyou
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: nicole
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: babygirl
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: daniel
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: 12345678
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: lovely
[80][http-post-form] host: 10.10.160.164 login: gcrawford password: monkey
Haha
i gtg
Where you going?
to my mom`s room
Still play koth?
ill play in some time
Ok
super freaking slow lol
Haha
how did you find this?
Anyone up?
Who is playing https://tryhackme.com/games/koth/26467 with me?
kex_exchange_identification: Connection closed by remote host
stuck here dont know what to do
Reconnect.
No, the ssh.
this is likely because of the bruteforcing that's on going on the machine.
http and ssh both running on port 22 :
Which machine?
hogwarts
OH, that, uh. is intended.
:0
-p-
Hi
Question about koth
In rule 8 it says we cannot change execute permissions of system binaries
Does this also mean we cannot remove setuid permissions?
Pretty sure that rule is mostly to prevent people from just doing something like chmod 700 /usr/bin as root, because this would mean absolutely no one can use the system except for root, which is wrong
If something has suid perms that creates a way to get to root, you can and should change that
Yes, there is a fine difference between patching and destroying the machine.
Thanks
Gave +1 Rep to @wind fjord
it was quite interesting for me first time this kind of game. Totally incompetent in many areas, but windows in particular, I am curios if it was @hasty cradle who killed my shells π
Always upload more than 1 shell
Anyone up for match?!
no
lMAO
Man H1 is dumb
Man specify which h1
Hard.
H1 hard is anything but dumb
adam wants to know your location
π
Just delete your IP address and all is fine. π
shutdown ur pc forever 
koth join fast
I cant get last flag from space jam room
Can anyone give me hint how to get flag from king.txt?
You don't get a flag from that file
If you are playing first time it's good to read the rules and also the blog post. King file is the file that gives +10 points every minute to the person who have their name in the file.
!docs koth
Okay thanks
Gave +1 Rep to @nova tide
@deep crag just ping @nova tide or @stiff egret here
i got footage of a guy in koth sending me in a loop f israel
can i dm you?
absolutely
@delicate moon Please avoid spoilers.
Oh sorry just saw no one got on
goddamn hilarious

Does anyone want to go to the KOTH?
how to leave
you can't leave a koth game once it's started
oo
it's mistake
you can't?
As far as I know, there is no way to fully remove your account from a game while it is active. You can always close the tab and just not play, but the "Leave Game" button that shows up under options before the game starts is not there after the IP shows up.
I wonder if that's an unintentional design flaw, and that you could still leave using the API, or it's deliberate
You cannot, the API doesn't work after the game starts.
damn, so it's intentional :(
koth be a commitment lol
It's mostly for logging and things like that (:
We need to know who was where and when - doing what, etc
mv vm decided the crash the moment I found an vulnerability 
xd
Hello, how long does it takes to get the badge after you won a KOTH?
It should be immediate. I am really not very aware of that timing. DW you will get a badge. The max time it can take is 24 hrs.
okay thx cuz i won yesterday night so it's still less than 24 hours
:) Feel free to ping here tomorrow if you don't get one by then :)
anyone up?
Depends :)
For a KoTH match? Probably no
For some Tip regarding KoTH? Yes
For some doubt regarding KoTH? Yes
Hence, depends
koth match
guess I answered it π
I see
np
@sour gale
i'm in
refresh
yep
not bad for a koth setup is it?
i never played koth how can i ? should i polish my skills before playing?
lessssssssssssss go https://tryhackme.com/games/koth/join/00efc9c69fea7a0e95d822a5
Anyone up for a KoTH?
If you can solve easy/medium boxes on tryhackme, you can hack your way in KoTH, although to maintain persistence, you might wanna give some resources a look.
There are some in the pinned chats/
ohh that will be fun thanksπ
anyone want to join a KoTH mainly to help me on gettin started?
anyone want to do some KOTH
@dense rivet here
I'll do koth when I'll be able to do koth βοΈ
Does anyone know how to figure out topSecretPrivescMethod on H1 easy?
That's my backdoor to get into the box for modifications π€·ββοΈ
Good luck figuring it out -- it's not possible
Ohhhh haha thanks!
12 mins
Anyone ready for the play?
Hello guys. Anyone ready to play KOTH
All the best!
Did you started?
Please dm me @primal scaffold , so that I will be notified
I am sorry I cant rn , ill start on 7pm gmt +3
Oh.. it will be night for me bro. Then we will plan some other time
Which box?
Linux or Windows?
Oh... Random
Ok I will join. But if windows I can't do, because I don't know exploitation of Windows machine
same bruh
All the best to you too
Who created this? Either you or someone else?
the guy with username PKVIRUS
If he is a subscriber I guess he know what machine is this
yup, i think he knows
Yes
btw i'm already in a match
In the last one minute the name will be revealed so that we can decide to stay or leave
Oh.. nice
will it cause any problem ?
You are far away from the remaining bro, so I guess you will be winner
So you can start new match no issues
then ok
Thank you. Wish you the same π
never played this machine before
me too
you got the flag :0
yes i'm in the box now
check port 8888
Thanks for the hint
Anything useful?
this one will give you footholt
edit: foothold
not the endpoint apps is showing not found
It's not correct to chat here, shall I dm you
π
As far as there are no spoilers u can talk here and #koth-voice-chat
What do yall think "Luck is a parameter for everything, command it" means?
π
Totally not trying to get help for a specific machine
It's the parameter that goes in the url to take your input
Ohhhh like in the URL
I was tryna put it through burpsuit
burpsuite
There's only 10m left and literally no one has gotten into this machine yet
Fortune is a funny machine
Was I supposed to be able to run actual linux commands through the luck parameter?
That machine is so confusing
There's a lot of RNG built into it if that's the route you wanted to try
I think the luck parameter is a 1 in 3 to work, the page on port 80 has a 1 in 65535 chance to give you a shell, etc

1 in 20, actually
The luck parameter is either 1 in 8, or 1 in 12
Can't remember what I set that one to
Port 80 is definitely 1 in 20 though
It's been a while since I went through the box. I just assumed port 80 was like a roulette of every single port.
Nah, you tell it what port you want a shell on
Although I'm pretty sure when I looked at the php for the luck parameter it was a 1 in 3, but I can believe 1 in 8
I think 1 in 65535 would be really funny though
Oh, different page
Yeah, that's a much better chance, if and when it decides to stop insulting you
1 in 65535 would be hilarious, but I wasn't allowed to go nuts on it
It is called Fortune