#koth
1 messages ยท Page 68 of 1
That also happens when someone is running recon scripts, like linPEAS.
Also, if you have root, patch the machines and keep the 'noobs' out.
If you run scripts like, pspy, the machine goes extremely slow, it is possible someone is running that.
There are a lot of examples for this, running hydra at max threads also makes the machines slow
Rustscan can crash machines
Can you DM me the IP of machine?
Can confirm, machine is alright.
Guys, how do you do that? Within 15 minutes, ๐
Got my first 15 points and i'm just good to go to the shower by now. So exiting ๐
๐ฅฒ
its all about how many times you have played a machines
thats why we are waiting for new machines
@stiff egret
Yes, I only started with koth since yesterday. But at the same time, i'm a noob and still have tons of things to learn.
I still need to rely to much on my notes atm
They might not have a tty session
ok breathing in before I break the PG13 rule.
I TEXTED YOU WE COULD'VE FINISHED THOSE LAST WEEKEND!
i told you i am free at night
H1: Hard is hard. Can't privilege escalate ๐
koth brke again??
broke
31656
lemme check
๐

is it all right?
And it is proved
BROKEN
~~@lusty portal Hey, Same issue with website not picking up king from port 9999. ~~ Apologies for the ping, everything is OK.
IP: 10.10.81.198
Match ID: 31656
ok
On second thoughts, Hold on.
compensation will be 10 wins direct
your name is wrong
on scoreboard
OP 
Ofc!
from where could I
Don't blame me if I take the king now
๐ข
is it
like we should do
do it
we ont patch anything here ok @stiff egret
I have no idea, have you patched it?
Mr. Holmes got in with the patches ๐
hahah
no but another guy did think so
Mate, what did you do
what?
nothing
maybe a nmap scan would help you
no rev shells
nah
maybe
GG bw
btw
GG
If only if
Nice game lol, also cut that sir 
I could get a follow back on ista
lol
done (:
thanks
join us plzhttps://tryhackme.com/games/koth/join/2e5ff0012e8103bf26cea346
join up
can you get the machine which is not currently in machine pool?
Yes, you can. Either be in public match or start a private one.
There are more machines in the pool but it only shows 10 most recent released on the page.
Ok. I thought you only get from pool. No problem.
anyone for koth? 31975
Hey guys. If i'm playing a koth and even with a players name in king.txt the points aren't getting added. is there anything i can do?
Hello, i wanted to know if somebody would like to guide me for my first koth tomorow
because of even if i did a lot of ctf i never do a koth
Check pins ๐
What do you mean by pins?
Click on that button
and you can see the pinned msgs, that are/were found useful.
-- If anyone wants to learn/Guidance about KoTH, they can always check out this blog post:
https://blog.tryhackme.com/guide-to-king-of-the-hill/
Ok thanks you very much
There is something wrong with my game. I have my username in king.txt but on leaderboard it is not giving point
this is game. IP: 10.10.117.60
It is showing the username on port 9999
@stiff egret any help?
I've heard people are having this problem too. I experienced it last night for myself
This needs to be fixed. You can just win by flags.
Has anyone from staff confirmed it's an issue they know about?!
Sorry for late reply, timezones thing, and about that issue
Although, it is a common issue sometimes, but please make sure you are entering the exact username in that file
Yeah. I rechecked it so many times
It was a known issue sometime back, but I haven't seen it raised recently
Also confirmed that the 9999 port was also showing the perect username.
No need to be sorry. It's sunday morning. No one likes working on sunday morning even in India.
Ah. Then it can the the site issue, I can't raise it now that the game is over. But I'll keep an eye around (:
Yeah. Also it was windows machine(H1:medium). If that has something to do with this.
Some are well hidden, some are on the home directory of users. But i think its different from box to box
Some are in ascii art formate too. Good luck about those.
@stiff egret it is happening again
Can you send you the IP in DM?
@quiet schooner If you are around, can you give this food box a look? (ref to ss)
I'm doing pwk so not really around for THM
Are you sure that's the service name?
ah, ok
try koth.service
That's what it is, iirc.
My local files say koth rather than king
No on that too
Oh, yes, that could be it
entirely possible that someone removed it though
I am gonna try in one more game and see if issue persists or not!
And the service is running too.
I've reported this to admins, it's a site issue. And should get fixed soon. (:
ok. Because I can confirm that this is issue because in next match I have same issue.
Have reported already in #koth-staff
should I send the info on this?
No need. It's been reported to admins they will look into it.
ok. Good luck with the bug finding.
well ..
yesterday if you put your nick in king.txt , it wasn't counting points
but apparently they've already solved
sometimes king.txt points don't count
On the machine now now you tasted your own poison hahahahahaha @lapis folio
well i don't want a king ...
neither do I, for me to score the flags is fine ๐
of course ...
ohh yeah i'm stupid loser ok ... u want to say like that to me i know :) no problem ... i'm just play it for fun
????? Lol
I'm just playing for fun too lol
but if you think, that's fine, life goes on. now i have to finish some things, goodbye xD
well ... good luck
Hello, i have a question, what could i do when the other players always disconnect me and lock my connection?
they don't 'lock' your connection, they just kick you out of the machine, what you can do in this is find other ways to get in the machine, think like a mercenary and try to find ways to hide your connection better once inside the machine.
well i guess he won so, i will try to find something ๐
For e.g. Once you get a reverse shell, don't stablise it, because that allocates you a tty, and that makes you more visible.
In every machine, there are minimum 3 ways to get inside, you just have to ....


!dark
nvm

!dark
yo
@stiff egret It is happening again. King is not being counted.
@upper marlin this king not counting error is showing up every week
Is the game on?
yes
DM me the box IP
You want creds?
I've pinged skidy regarding this. Hopefully this will be resolved. He did fix it last time, this is weird.
yes. that's why I am reporting again. It happened in morning too but I had a placement meeting so I couldn't report in time.
@stiff egret Is it possible that this is user issue? can you please join the game and try your username ?
https://tryhackme.com/games/koth/join/ef0d3d4c73f37e7c5446d70f this is invitation link
how to contact your competitor in koth? If you have their network IP?
if you are on the same machine as you logged into ssh, you can type: wall yourmessage
Yeah. But someone was bruteforcing ssh logon. I just wanted to tell them to stop as it was worthless.
I understood
hey, do you know were i could find some doc about windows defense?
These KOTH games start to be stupid like hell when peoples shut down services instead of fixing it... https://tryhackme.com/games/koth/32284
This Mrapdoul user (https://tryhackme.com/p/Mrapdoul) indeed seems to cheat over and over again. Plays 2 KoTH at the same time. Like ATM of writing this. Takes immediately control of the box, shut down services... Feels like he has nothing else to do as just cheating and misunderstanding what real ego is...
You saw it pitiful this kind of person
Just an idiot who think is smart
That script kiddy should be banned, that's my opinion
This is not playing anymore, what he does
I totally agree with you
The rules say where to handle this
mm.. does winning without king (only flags) count?
i won my first game tonight but it doesnt show up in the completed koth rooms and i didnt get my badge
the odd thing is that the game doesnt seem to have been completed
victory only counts if you stay longer in the king
it doesn't matter if you score all the flags, if you don't stay on the king during the game until the end you don't win the match, but you scored the flags
yes if you have more points you win
well, if you scored higher than everyone else in the room you participated in, you won
that whaat i thought
But if the match didn't end, that's a bug - #site-bugs
This.
Report it as a site bug
I understand
not a bug. it won't show up in recent games because only king changes once or more counts to be shown. otherwise it will add up in your win count.
If there wasn't anyone else with king points it won't show up in recent games but that doesn't mean it doesn't count.
if you win with 0 points/win by default that's the win that won't count.
on the leaderboard.
i won with points
then it would have given you +1 for your leaderboard.
I think you only get the badge when you win with king points
ok
I'm not sure how long it takes to award the badge. I would recommend waiting for sometime, if it's not still added then you can email and support will add it manually. Don't forget to attach the game url.
how can i recover it?
Not sure about that either ๐
the game url?
i mean, the game ended and i closed the tab after it was saying i won
Here you go: https://tryhackme.com/games/koth/32295
๐
i'll play again to win it with king
GLHF
thanks ๐
It's getting late, for me at least, anyone up for a final one? https://tryhackme.com/games/koth/join/479be9e3d1ed9076730e0422
Hi guys :)
hi
Thank you very much!! :)
Hello, do you know where I could learn how to defend windows machines? Like auto RDP disconnection for all the others account etc ...
oh i will play agains't you UwU

good luk so ๐

Oh KoTH video? Can i get a link too?
1 reset left
dunno king time is not updating
@fair adder ||check out port runnin mysql||
yep
i know their is a db
but i would like to know how do you patch the vim privesc fail
uhuh
do you want the link to my video? sorry i didn't understand very well i'm using the translator because i'm brazilian ๐
send me your video link. 
you can DM
or can share in #thm-community-media if it's totally a THM content ๐ค
chmod 755 /usr/bin/vim
ty
okay
||use vim to modify /etc/passwd for root || @fair adder
nice trick ty
Gave +1 Rep to @stray wraith
@stray wraith @fair adder what box?
food

there are several ways to get root on this machine, even with that CVE-2021-3493
๐
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.
ooooh this is sick
Yes ๐
Enjoy
a very interesting machine is also carnage, its root is amazing
you can set crontab to kick people off the machine too

i had to google how to do that
i keep forgetting
gotta play more often
๐
send again
how could i do this?
king is borken again
sure play with me it's borring when you're not here
send ip
^
You must have used the IP in some command
export IP=""?
history | grep 10.10
i was asking for the ip if the machine was currently active and i could check it myslef.
my github :)
just adjust the crontab to kill the other opponent's session, but I don't know if it's against rules so I don't support you doing this
Thank you
xD
โญ'ed
Do you have a tuto or a doc so I can learn how to do this
John's videos, Optional's Videos and there's also a blog in pinned messages.
Ok ty ๐
It's down right now
I don't understand, why sometimes king.txt dots don't work?
elaborate?
king points bug again
?
jabba, imma just point them now to you
Hey!
If you're having issues with KoTH and the king.txt does not seem to be working,
please ping me or any of the KoTH Staff with the Machine IP.
Do this while the game is still active so that we can review the machine:)
@stiff egret ๐
๐
there could be a reward system for the world's top 10 koth, that's my opinion and I think it would be cool
king's points are not counting
IP machine - 10.10.105.2
help me please
^^
is it alowed to don't do recon on a room we already did? like folowing our old notes?รน
"don't" ? Why? Recon is not a rule, it's a choice, if you want to, because it's usually needed. If you don't need it, fewel free to skip it
because it's a big disadvantage for those who have to do scans
so i wanted to know if we don't need to do it every games
Not a rule, No.
ok
recon is a fundamental part, and it is very important to know how to do a good recon.
yes but i don't even finish my nmap scan that somebody rooted the machine
Use rustscan bro
i guess i will
It's much faster than nmap
ok
hell yea much faster
is rustscan that much faster then -T5 nmap????
i think yes
well guess it is up to try it and time them to find out.... then again with the right flags for nmap you should be able to rival the rustscan speed ยฏ_(ใ)_/ยฏ
xD
Yes
Rustscan and nmap works together, rustscan gets you the open ports, faster than nmap can and then pipes them to nmap, that way nmap can finish up the overall scan faster.
Alone, Rustscan can go as high as all ports in one sec I think, it will probably push the target machine to 95%+ usage, but it can get you all ports very very fast.
There's a certain factor for PORT CHECKING in rustscan, that simply can't match or is comparable to nmap. In any way.
Nmap is a very detailed tool for scanning, rustscan only lists out the open ports.
Yes
on koth, rustcan helps a lot on some machines with high ssh ports
i'm alone, did somebody want to play with me?
have u gotten root @fair adder ? idk if its me but it looks like king isnt displaying
kind don't work onProduction
disconnect.sh ๐
port 9001 and 9002 are open
@stiff egret
it's probably babauca
@marsh falcon even if this it was a good game
thats a bummer
a noob
that game was beginning to get intense
@brittle galleon go read the rules
constant disconnects between users ๐
yes was fun
you close the ports
i didnt tho..
i know syde i don't think he should do this
i was busy disconnecting the others
is it possible that a misconfiguration of the crontab close ports?
and someone was constantly disconnecting me so it couldnt have been me
it's me UwU
i was trying to do this in the crontab
yea i saw it
i had to move fast and removed the sh script on roots home directory
u shouldve hid it better ๐
lel i can't experiment with you
I got access to it๐
Who's king?
No, something else
i guess it's side
but i'm sad because i did something so he couldn't log back as root
and so i would be the king
but i can't connect ssh so he won
ty
Looks like someone was trying to fix server.py script๐ค
/home/skidy/homework/server.py
not me
i forget the password lol
i know i put matieu in but don'tremeber of the rest
or mathieu
well i loose
gg everybody
I don't know what to do, should I change password for you? Or is the game over?
idk
it's mmy false i forgot my password
x)
don't worry @marsh falcon deserved the win
Alright, next time try to check for services running on 9001 and 9002
what are them?
What exactly is running on these ports.
Check it next time you get access to the box
you don't want to tell me?
ok
It won't be fun that way.
But I could
May I DM?
not me as well i kept getting disconnected
One of u closed the ports, I know for sure. I guess u played as a team against me. Its a individual game. Nab
I don't close the ports,I don't touch the python server files
You think we are cheating?
If it was the case why should I kick him and why did he removed my file for kick all users
we weren't teaming. we we're going up against each other
the game is finished anyways, no need to get heated up
Yes
Could you elabroate?
well we are on the file but it don't add king time
i'm on this file Users\Administrator\king-server\king.txt
also by the way if somebody know how to auto disconnect all user on windows server 2012 r2 could he send me ressources or teach me how because i don't find anithing on the pinned messages
or any other defense tips for windows machine
start in 20m come play and have fun ๐ https://tryhackme.com/games/koth/join/cab7b98ef86ef06f95a840a2
Script kiddie
๐ ๐ ๐
I hate this kind of people, who change the ssh port or close it, IN PUBLIC ROOM
Me two
It doesn't matter, I had to go anyway
Anyone give some hint on production KOH
Priv esc
I got only two flags also not rooted
Can someone help me
Have you tried checking ||sudo -l||
If you can't use sudo l try find...
@rancid pewter As per pinned message, letting you know the "king" status isn't being updated for game running on 10.10.197.148 Thanks!
Gave +1 Rep to @rancid pewter
@rancid pewter ๐
known issue and have been reported to admins. They will look into it.
Just to be sure, do you want us to continue to report the issue (when it occurs)?
Until further notice i would suggest not to. Will be announced here when its fixed. Thanks for reporting though.
@livid lava mind if i drop a dm?
Anyone up for a match?

cool
We can play if you want to.
But rn lunch break from work so gonna grab something to eat
oh ok
You are going to have a hard time๐
yeah i know man , I am playing against a oscp certified ๐
KoTH lead > OSCP
Remember that OSCP is still entry level ๐
๐
Just don't play against an OSCE3
ok
but OSEE is fine 
OSEE isn't useful in a pool of mainly Linux machines with a fast-paced game environment ๐
Actually, tbf, that applies to OSCE3 as well ๐คทโโ๏ธ
nah just drop a kernel 0day 
@nova tide When I click "Join a public game" on the KotH landing page, it returns Uh-oh! undefined. Any idea what might be causing that?
Are you using bitdefender or any in-browser anti virus?
Nope, and currently successfully enrolled in two other games. So it worked fine, say 15 mins ago.
You can't join more than 2 public games at once.
Ah, thanks. That makes sense. Appreciate the feedback.
Gave +1 Rep to @nova tide
That link works fine. Guess I should dial it down a bit ๐
You can join public games through invite link though.
Thanks! Clear. ๐
why did the hacker machine take so much time to bruteforce
i guess you should use passwords hight on the rockyou wordlist because we only have one hour to root the machine
It uses passwords high on rockyou. AND it is made with one hour thing keeping in mind. The machine is bruteforce-able in a fairly good amount of time. If it is taking you too long, highly likely that you may be doing something wrong.
๐ค
maybe
but i guess my command is good
hydra -l gcrawford -P /home/nk0/wordlists/rockyou.txt ftp://IP -t 64
I can only speculate, there is also the factor of other players bruting the machine, resulting in machine being super slow with all those threads.
sure
hm, that command looks find iirc.
12minuts...
and my opponent is already in
even ssh is long...
[STATUS] 1257.43 tries/min, 8802 tries in 00:07h, 14335725 to do in 190:01h, 64 active
but if it was high, why should i get 8802 tries?
Ping me the machine IP in DM please.
i did it
ftp```[STATUS] 964.67 tries/min, 14470 tries in 00:15h, 14330057 to do in 247:35h, 64 active
and ssh```[STATUS] 26.29 tries/min, 184 tries in 00:07h, 14344214 to do in 9095:04h, 4 active
I mean you realise that it is possible that your opponent might have changed the passwords?
i don't think he did it
because with the time he should already be root
i think he just bruteforce the ssh credentials
but not the ftp
i think he change the ssh but not the ftp
\
Can confirm the ssh password is not changed. I just ran the bruteforce, and logged in.
Yes.
what's wrong with me?
that's what I said to my therapist.
jokes aside, your VPN connection could be dropping
Bruteforcing FTP now
i do
it's bruteforcing
Hydra v9.2 (c) 2021 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).
Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2021-10-06 15:57:39
[WARNING] Restorefile (you have 10 seconds to abort... (use option -I to skip waiting)) from a previous session found, to prevent overwriting, ./hydra.restore
[DATA] max 64 tasks per 1 server, overall 64 tasks, 14344398 login tries (l:1/p:14344398), ~224132 tries per task
[DATA] attacking ftp://10.10.94.76:21/
[STATUS] 257.00 tries/min, 257 tries in 00:01h, 14344230 to do in 930:15h, 64 active
[STATUS] 385.67 tries/min, 1157 tries in 00:03h, 14343370 to do in 619:52h, 64 active
i don't have the password
did i use the wrong command?
Interesting, now from what I think, there's a possibility that ftp password is changed, I am running the same command, and it isn't picking it up.
And overall machine is fine, as I was able to bruteforce hydra at double the rate I bruted ftp at.
That's weird, because I can tell you, the current password is as high in the wordlist as <300.
ok
@stiff egret one player changed the content of the flags
ip: 10.10.44.166
and flag is the flag4.txt in root dir
here are the palyers
and i suspect nerdrobot
because he get the root flag
Boop @nova tide, if you're around
it's useless to play against this type of palyers
I'm not 200% sure how to check who's done what.
I presume it may be the user who has the most flags but until Naughty or Homles come online there's not much I can do.
Just came back from office ๐
because he don't deserve to win
Let me see
ty ๐
you need to share invite link for other people to join.
That's a spectators link
sorry idk
Bear in mind that if someone beats you and changes the password, you'll not find it
Is it only me who is seeing that a protocol is missing?.
hydra -l gcrawford -P /home/nk0/wordlists/rockyou.txt 10.10.94.76 -t 64 ftp
?
oops, sorry wrong room
ftp://<ip> works too
Thanks for letting me know. I didn't knew that.๐ @nova tide
Gave +1 Rep to @nova tide
anyone up for a match?
are all koth machines have 3 flags ?
different machines have different amount of flags.
thanks
You can see the total flags by hovering your cursor to the flag icon near flags submission box.
anyone wants to join me at some koth?
hello
i have an issue while i'm trying to connect on ssh to the machines
i get this error message```Permission denied, please try again.
maybe it's from my config or bad version but it's a bit borring cause i can't play
do you have any idea of were the problem could come from?
Are you able to do other rooms?
Uninstall arch easy 
i don't try rooms, but for koth i tryed to machines, hogward and fortune
@nova tide i guess the problem is for every rooms
not only koth
because i when i try to login in the Introduction To Honeypots machine i get this message
Unable to negotiate with 10.10.113.87 port 22: no matching host key type found. Their offer: ssh-rsa,ssh-dss
but i can connect on ```ssh demo@10.10.113.87 -p 1400
Because there isn't any ssh on 22 or not allowed?
Haven't tried this room though.
it is
Then you might be doing something wrong idk. Can't understand much by just the info you are providing.
well idk what i do wrong it's the problem
๐คทโโ๏ธ
should i reinstall arch just for this problem?
on the doc i only find for creating a server using openssh
good idea i will wait for help there
do you want to play?
https://tryhackme.com/games/koth/join/cce6484017b97df27a5ed7d8
too late
:/
is it allowed to play with two accounts to try defense?
like i defend with my first account and then attack with the secound
when i'm alone in the lobby
Only in private games
Np ๐
3 times it's h1 easy lel
But is it easy though?
Anyone lead an in-person KoTH event?
๐ฏ
Elaborate?
Yes, I don't find all the differs way to enter in the machine
Iโd like to put on a KoTH event at work for all our new SOC analysts to get them excited to learn more. But Iโve never lead a KoTH, let alone in person. Looking for tips to make non-red people interested in learning how to do basic PenTesting and then compete
show them the video of John and this Koth launch
100%
Okay! Thanks. I Havnt touched THM since the Christmas event but want to get back into it and thought this would be the best jump start
Everytime my brute forces attacks don't work on the hackers machine but work on simple rooms like hydra etc... idk why but it's sad because I can't do this room
I'm talking about ftp and the syntax is perfect I verify with writeups and with Mr Holmes or Naughty73
Then someone is likely getting the password faster than you and immediately changing it
How,like the password is in the first 200 and I run as soon as the IP display and my config is a 1060
Weird
i have a good connection as well
what is wrong with this command?
their already in...
is it too bad to be win?
Sample command: hydra -t <threads> -l <username> -P /path/to/password.lst <machine_ip> ftp
for me it's a good connection
ok i will try next time like that
but mein seems to work too
on other rooms
do you have a recommandation about the number of thread?
No more than 16 imo
ok
You have to remember, it's not about how fast your computer and network is, it's about the machine you're attacking too.
@fair adder did you close some ports?
you did i think ^^ we did a reset
like i wrote a script to disconnect users
np
wasn't my intention
@fallow heart reset only reboot?
don't will delete my defense?
i think the ports still close
did a staff could turn them back on please? i'm really sorry
i wanted to kill user connections every 5secs not services
no it's back to normal now
nice
Not part of the game but I'm like 80% sure that breaks some kind of rule
disconnecting users is ok, but not services
we can disconnect ssh connection, it's a part of the game
It's okay to disconnect people every once in a while, but writing a script to do that every 5 seconds is defo pushing it in my opinion
I'm not KOTH staff, so do as you want, just giving you a heads up
well let's ask them
scripts that harden the machine are forbidden.. but i guess that can be interpreted in many ways
From the official blog here: https://blog.tryhackme.com/guide-to-king-of-the-hill/
for me it's ok
like i could do it without scripts
just using who every sec
like i did before
but i thoug that automatisation was better
idea
as far as i can see you are alone on the box anyway, im still trying on initial access ๐
gl ๐
i don't really defend
(because i forget my password)
oh no reset removed my chattr patch
Won't that be a better idea to just patch the way they are getting in from? Defending comes in blue teaming and I don't see how killing every other connection would be counted as blue teaming. Let's say you are in a real world scenario and you have just kicked out every employee from the system rather than patching one simple ssh key.
this is for fun when i patch everithing i found
because their is also reverse shell not only ssh
i have a question, how did jceggink could edit king.txt file even if he was edited using chattr and the chattr binary replaced by something who do that
# chattr +j king.txt
You are late
bye, Nekro
i would like to know how so i could learn more ๐
(tell me after the game if you see my msg)
๐
Bring your own chattr ๐
@ebon lichen did you shut down ssh? .. there are only three ports left open
You can still get in via the 15065
ik
Then let's privesc and restart SSH ๐
failing at the privesc from bread ๐
check /dev/shm, left you a present.
Hahaha, thx ๐
not fun when you are on the other end
What if the others can do and not me? I already was in the other side and now what it is. And as you can see i didn't win๐ it makes everything exciting and it's competition ๐
Their is always another way๐
That's what makes the diff you see, you can obviously do it without the script, but when you do that, i.e. run the commands every second, and realise that automation is not allowed, then you'll realise, sooner or later, that there gotta be a different way to keep them out.
That's the ladder of evolution from what I know.
Automation is not allowed?
I didn't knew sorry
Will read the rules again
Scripts that automatically hack(autopwns) and/or harden the machine are forbidden
It's not the same context
Like my script wasn't an autopwn
And I'm not sure that it harden the machine because I could do this my self really easyli
But if it's not allowed, no problems I don't will do it again ๐
I just need to know ๐
And if it is allowed should I respect a specific delay?
Ok, to be honest, it's really a grey side of things, it depends on the script, how and what it is doing.
EDIT: Automation to some extent is allowed, killing shells, hardening the machines using automation can be considered grey area, and in the end is a subject to Moderator's understanding.
cc: @nova tide any edits?
What is koth exactly? How friendly is it for beginners
You get a machine, 10 players also get the same target IP, all of you race to hack that machine and once you've hacked it, you race to defend it against the players who are still trying to get in. There are flags in the machine that you can find and submit to the main page, and there is a king.txt file, whoever adds their name in that file, gets 10 points per minute for the name being in it.
Disconnect user
Wait. 5 secs
Do it again
-> Patch the machine.
-> Disconnect User.
-> See them reconnect again?
-> Find their backdoors and disconnect again.
Won't that be a better approach?
This is for when I have to patch, like I'm trying to find backdoors, but if they prices and disconnects me I loose
It's not the only defense i use
- This is not defense.
- You need set your backdoors/persistence so you can get back in.
sure but i choose the users i kick
i guess i have to do private games to fully defend the machines
whose playing rn ? https://tryhackme.com/games/koth/32938
Got the Hard machine this time around ๐
@ebon lichenany hints on the H1:Hard machine?
There's an excellent room where you can practice all three Hacker of the Hill boxes, easy, medium and hard: https://tryhackme.com/room/hackerofthehill
Thanks mate
@quiet schooner
Anyone want to do some koth?
when you want ๐
Try the standalone room
Ok i will
could you send me the link please
because i don't find it
Standalone meaning not part of koth. Search "hackers"
oh yes thank you
well it don't work
i will try with -64
what is wrong with this command? hydra -t 64 -l gcrawford -P /home/nk0/wordlists/rockyou.txt 10.10.226.34 ftp
well it don't work with -64
Yikes, why 64
Because it's max and faster. But I used 16 first but did nothing
More doesn't always mean faster:)
i checked myself. the services are running perfectly fine. I'm not sure if the rockyou is updated as well with the latest kali release? the following password would be within a few hundred/thousand passwords but on bare metal latest kali machine it won't give you the password.
cc: @quiet schooner @stiff egret
That hash is gcrawford ftp hash btw ^
There's also other troll terminal?
BELLOOO ๐ wanna play anyone?
@wide horizon hi
check the 800 port
for a fair play
@wide horizon
I dont know the user of pythonista
I've been spending my time trying to bypass the upload filter, need to practice more
next time use the 8002, the lesson part
uploading files in koth is slow
and it costs you time
I've never done this box before, so I was just doing it for the challenge lol
Oh, is your first time?
I've already done this 2 times and it is in this room
there are a gift
hello, i don't know if it's normal, but i can't connect in ssh to the machine, like i were disconnected and when i try to connect i get this message:
ssh shifu@10.10.241.168
kex_exchange_identification: read: Connection reset by peer
Connection reset by 10.10.241.168 port 22
i just want to know if it's allowed by the rules or if it's just a problem from me
anyway, gg @eversingoob
**game link:**https://tryhackme.com/games/koth/33214
and by the way if it's allowed how to do this ๐
Maybe you broke it while doing chmod 777 on the entire server (for whatever reason..)?
lmao
@silk glade zzzzz
๐
why did not all the win count for the leaderboard?
like this one: https://tryhackme.com/games/koth/33243
and this one: https://tryhackme.com/games/koth/33242
didn't count
I just realized it
and the game i'm doing don't count...
i don't enderstand why :/
IIRC, The games with actual king changes are the only ones that are counted.
Any game with king time > 0.
cc: @nova tide
All games are counted. That page just shows the most recent ones with king changes.
The leaderboard.
Any game won with points > 0(default win) is counted for the leaderboard.
ok ty
king.txt don't work on offline
echo nk0 > king.txt
type king.txt
nk0
@ebon lichen You're a ninja at these koth matches man!
Haha, that is very kind. Thanks! As mentioned in DM, take @woeful sundial advice and actually keep track of what you do each time you complete a room or play a KotH game. When you play the box again, keep adding to that readme.md and build on what you learned previously ๐
Gave +1 Rep to @median meadow
@ebon lichen Had a lot fun playing with and learning from you! People like you make this community amazing. Until next time my friend โ
๐ likewise!
H1 hard is Hard as fork
El chapo :0
๐
lel i just realized i'm in that game
it is pronounced k-o-t-a-h not koth 

Pardon?
Last I checked it is pronounced K-aw-th
@brazen cloud isn't it k'awh? for you?
never played koth before, i'm in the lobby but how do i connect
!docs KOTH
!docs koth
thx
koth game soon! getting my machine ready
installing the metapackages on my windows subsystem for linux kali
It's pronounced "cough"
kowth
Good evening, just realised I posted my query in the wrong room. I am currently playing the Panda box on 10.10.119.120, it appears that none of the system binaries can be found, with the exception of the shell-builtin command. PATH variable appears fine, and printf '%s\n' * in / shows that e.g. /bin still exists. Any ideas?
Makes navigating the box bit of a challenge, not impossible, but being limited to the shell-builtin commands makes collecting flags a bit of a pain.
cd /bin returns bash: cd: bin: No such file or directory, so I am starting to believe someone's changes permissions on /bin and possibly removed /usr/bin.
seems like some might have removed the binaries/folder itself.
unable to get a rev shell as there aren't any binaries in the system
mind telling me shifu password?
@ebon lichen
Don't know it, it has been changed, I am root now, but passwd no longer works, as the binary cannot be found.
you can use echo * instead of ls. see if there's anything left in /?
Yeah. printf '%s\n' * in / shows: [root@panda /]# printf '%s\n' * bin boot dev etc home lib lib64 media mnt opt proc root run sbin srv sys tmp usr var
cd bin ?
So the folder is there, but you cannot cd into it.
bash: cd: /bin: No such file or directory```
Do you know of a way to list folder permissions with just builtin shell commands?
Alas, nope.
bash: python: command not found
[root@panda /]# python3
bash: python3: command not found```
/bin/python or /usr/bin/python ?
seems like binaries gone. i couldn't confirm it though.
At least, I am still king ๐ [root@panda /]# printf "%s" "$(</root/king.txt)" jceggink
Thanks for the suggestions. I have seen this happen a couple of times before. No have way to circumnavigate it using builtin shell commands, but I guess it is not quite in line with rule 8. Anyway, thanks!
Gave +1 Rep to @nova tide
if you see something like that again you can mail at koth@tryhackme.com with the proof(some screenshots) and suspected players. Would be better if have their names/ip.
Ok. No biggie, though, found a way around the issue and learned something new about shell builtin commands - silver lining etc ๐
Hiii, anyone for any koth this afternoon?
I'm real begginer level but i wanna try
you're lucky that I don't have my notebook, I'm on a 2gb ram, pentium dual core computer and I'm not even at home hahahahaha but next time, when I win my notebook this month or the next, you'll have an opponent at your height hahahaha
@ebon lichen
Looking forward to it! Appreciate the competition ๐
hahaha I'm looking forward to this too!
seems like there are people playing and also in vc
#koth-voice-chat message
Tnks
hello
hello
anybody know the solution to this on production koth?
retry without the $IP like ashu@10.10.199.98
thanks it worked

Congrats ๐ฅณ
But just don't share flags in public ๐
Have fun 
ty
I've start a King of the hill
Come and challenge me: https://tryhackme.com/games/koth/join/7aa9f6cefa1f96431ea32948
Anybody?

gg @dim scroll @ebon lichen
@ebon lichen let me know if you plan to play another one ๐
Congrats! Enjoyed that one, was forced to explore new avenues, which is great and brings the challenge back. Much appreciated!
Currently in a game and 'Tyler' seems to be down - anyone else having this problem?
Yoyo




