#koth

1 messages ยท Page 68 of 1

static plover
#

machine is ultimate slow

#

my internet is good

#

when pinging box

#

ping is over 1k

stiff egret
#

That also happens when someone is running recon scripts, like linPEAS.

#

Also, if you have root, patch the machines and keep the 'noobs' out.

#

If you run scripts like, pspy, the machine goes extremely slow, it is possible someone is running that.

#

There are a lot of examples for this, running hydra at max threads also makes the machines slow

#

Rustscan can crash machines

static plover
#

ohh then

#

im alone on machine

#

probably

#

hydra

#

enumerating

stiff egret
#

Can you DM me the IP of machine?

static plover
#

sure

#

one sec

#

again

#

machine is very slow

stiff egret
#

Can confirm, machine is alright.

fair adder
#

Guys, how do you do that? Within 15 minutes, ๐Ÿ˜„

#

Got my first 15 points and i'm just good to go to the shower by now. So exiting ๐Ÿ˜„

blissful flare
#

๐Ÿฅฒ

#

its all about how many times you have played a machines

#

thats why we are waiting for new machines

nova tide
fair adder
#

I still need to rely to much on my notes atm

static plover
#

-bash: king.txt: Operation not permitted
on koth

#

no one is in the shell

#

lol

nova tide
stiff egret
#

I TEXTED YOU WE COULD'VE FINISHED THOSE LAST WEEKEND!

nova tide
fair adder
#

H1: Hard is hard. Can't privilege escalate ๐Ÿ˜•

fathom lotus
#

jesus finally finished complete begginner

#

beginner

blissful flare
#

koth brke again??

#

broke

#

31656

stiff egret
#

lemme check

blissful flare
#

๐Ÿ˜‰

stiff egret
blissful flare
#

is it all right?

stiff egret
#

And it is proved

#

BROKEN

#

~~@lusty portal Hey, Same issue with website not picking up king from port 9999. ~~ Apologies for the ping, everything is OK.

#

IP: 10.10.81.198
Match ID: 31656

blissful flare
#

ok

stiff egret
#

On second thoughts, Hold on.

blissful flare
#

compensation will be 10 wins direct

stiff egret
#

your name is wrong

blissful flare
#

on scoreboard

stiff egret
#

Wrong spelling facepalm

blissful flare
#

oh sry

#

didnt saw

#

corrected

#

and the koth is working

#

sorry @stiff egret

stiff egret
#

OP KEKW

blissful flare
#

it

stiff egret
blissful flare
stiff egret
#

Don't blame me if I take the king now

blissful flare
#

is it

#

like we should do

#

do it

#

we ont patch anything here ok @stiff egret

stiff egret
#

I have no idea, have you patched it?

placid fable
#

Mr. Holmes got in with the patches ๐Ÿ˜†

stiff egret
#

hmm ok, sorry, not sorry

blissful flare
#

hahah

blissful flare
stiff egret
#

Mate, what did you do

blissful flare
#

nothing

#

maybe a nmap scan would help you

stiff egret
#

hahah

#

guessed that

blissful flare
#

no rev shells

stiff egret
#

I don't make the rules

#

damn I am getting rusty, been a long time I played KoTH

blissful flare
#

maybe

#

GG bw

#

btw

stiff egret
#

GG

blissful flare
#

If only if

stiff egret
#

Nice game lol, also cut that sir facepalm

blissful flare
#

I could get a follow back on ista

stiff egret
#

lol

blissful flare
#

๐Ÿ˜ข

#

same name on inta also

#

๐Ÿ™‚

stiff egret
#

done (:

blissful flare
#

thanks

mellow hornet
#

join us plzhttps://tryhackme.com/games/koth/join/2e5ff0012e8103bf26cea346

fathom lotus
#

join up

upper marlin
#

can you get the machine which is not currently in machine pool?

nova tide
upper marlin
#

Ok. I thought you only get from pool. No problem.

fair adder
#

anyone for koth? 31975

tawdry burrow
#

Hey guys. If i'm playing a koth and even with a players name in king.txt the points aren't getting added. is there anything i can do?

fair adder
#

Hello, i wanted to know if somebody would like to guide me for my first koth tomorow

#

because of even if i did a lot of ctf i never do a koth

fair adder
stiff egret
#

Click on that button

#

and you can see the pinned msgs, that are/were found useful.

fair adder
#

Ok thanks you very much

upper marlin
#

There is something wrong with my game. I have my username in king.txt but on leaderboard it is not giving point

#

this is game. IP: 10.10.117.60

#

It is showing the username on port 9999

#

@stiff egret any help?

tawdry burrow
upper marlin
#

This needs to be fixed. You can just win by flags.

fair adder
#

were could we find flag? Only the root flag?

#

because i don't find any user flags

tawdry burrow
#

Has anyone from staff confirmed it's an issue they know about?!

stiff egret
#

Although, it is a common issue sometimes, but please make sure you are entering the exact username in that file

upper marlin
#

Yeah. I rechecked it so many times

stiff egret
upper marlin
#

Also confirmed that the 9999 port was also showing the perect username.

upper marlin
stiff egret
#

Ah. Then it can the the site issue, I can't raise it now that the game is over. But I'll keep an eye around (:

upper marlin
marsh falcon
fair adder
#

okay

#

ty

upper marlin
upper marlin
#

@stiff egret it is happening again

stiff egret
#

Can you send you the IP in DM?

#

@quiet schooner If you are around, can you give this food box a look? (ref to ss)

quiet schooner
stiff egret
quiet schooner
#

Are you sure that's the service name?

stiff egret
quiet schooner
#

try koth.service

stiff egret
quiet schooner
#

My local files say koth rather than king

stiff egret
stiff egret
quiet schooner
#

entirely possible that someone removed it though

stiff egret
#

nvm

#

thanks, got it, I missed that

#

it was koth.

upper marlin
#

I am gonna try in one more game and see if issue persists or not!

#

And the service is running too.

stiff egret
#

I've reported this to admins, it's a site issue. And should get fixed soon. (:

upper marlin
#

ok. Because I can confirm that this is issue because in next match I have same issue.

upper marlin
nova tide
#

No need. It's been reported to admins they will look into it.

upper marlin
#

ok. Good luck with the bug finding.

fair adder
#

well i don't find the 6th flag but i win !

gritty cedar
lapis folio
#

well ..

steep agate
#

but apparently they've already solved

#

sometimes king.txt points don't count

steep agate
#

On the machine now now you tasted your own poison hahahahahaha @lapis folio

lapis folio
#

well i don't want a king ...

steep agate
#

neither do I, for me to score the flags is fine ๐Ÿ˜‚

lapis folio
#

of course ...

#

ohh yeah i'm stupid loser ok ... u want to say like that to me i know :) no problem ... i'm just play it for fun

steep agate
#

????? Lol

#

I'm just playing for fun too lol

#

but if you think, that's fine, life goes on. now i have to finish some things, goodbye xD

lapis folio
#

well ... good luck

fair adder
#

Hello, i have a question, what could i do when the other players always disconnect me and lock my connection?

stiff egret
#

they don't 'lock' your connection, they just kick you out of the machine, what you can do in this is find other ways to get in the machine, think like a mercenary and try to find ways to hide your connection better once inside the machine.

fair adder
#

well i guess he won so, i will try to find something ๐Ÿ˜‰

stiff egret
#

For e.g. Once you get a reverse shell, don't stablise it, because that allocates you a tty, and that makes you more visible.

fair adder
#

ok

#

but hard t find when you know only one way on windows machines ๐Ÿ˜ข

stiff egret
#

In every machine, there are minimum 3 ways to get inside, you just have to ....

#

!dark

pearl gladeBOT
#
DarkStar7471
*ahem* Can help you?
stiff egret
#

nvm

fair adder
#

i know ๐Ÿ˜‰

#

i just don't know how

stiff egret
blissful flare
#

!dark

pearl gladeBOT
#
DarkStar7471
Because I said so.
steep agate
#

yo

upper marlin
#

@stiff egret It is happening again. King is not being counted.

steep agate
#

@upper marlin this king not counting error is showing up every week

stiff egret
#

Is the game on?

upper marlin
#

yes

stiff egret
#

DM me the box IP

upper marlin
#

You want creds?

stiff egret
#

I've pinged skidy regarding this. Hopefully this will be resolved. He did fix it last time, this is weird.

upper marlin
#

yes. that's why I am reporting again. It happened in morning too but I had a placement meeting so I couldn't report in time.

#

@stiff egret Is it possible that this is user issue? can you please join the game and try your username ?

upper marlin
#

how to contact your competitor in koth? If you have their network IP?

steep agate
upper marlin
#

Yeah. But someone was bruteforcing ssh logon. I just wanted to tell them to stop as it was worthless.

steep agate
#

I understood

fair adder
#

hey, do you know were i could find some doc about windows defense?

cerulean willow
#

People who do a lot of KOTH beware this person keeps the flags!

fair adder
fair adder
# cerulean willow

This Mrapdoul user (https://tryhackme.com/p/Mrapdoul) indeed seems to cheat over and over again. Plays 2 KoTH at the same time. Like ATM of writing this. Takes immediately control of the box, shut down services... Feels like he has nothing else to do as just cheating and misunderstanding what real ego is...

cerulean willow
fair adder
#

That script kiddy should be banned, that's my opinion

#

This is not playing anymore, what he does

cerulean willow
quiet schooner
pallid karma
#

mm.. does winning without king (only flags) count?

#

i won my first game tonight but it doesnt show up in the completed koth rooms and i didnt get my badge

#

the odd thing is that the game doesnt seem to have been completed

steep agate
pallid karma
#

so no king no victory

#

even though i had the most point i did not win?

#

๐Ÿ˜ฆ

steep agate
#

it doesn't matter if you score all the flags, if you don't stay on the king during the game until the end you don't win the match, but you scored the flags

steep agate
pallid karma
#

i mean i had the most points

#

no one became king

#

but i had the most fags

steep agate
#

well, if you scored higher than everyone else in the room you participated in, you won

pallid karma
#

that whaat i thought

quiet schooner
#

But if the match didn't end, that's a bug - #site-bugs

pallid karma
#

the match ended

#

i won

#

but the game doesnt show up in the completed games

quiet schooner
#

Report it as a site bug

pallid karma
#

thannk you ๐Ÿ™‚

#

will do

steep agate
nova tide
#

If there wasn't anyone else with king points it won't show up in recent games but that doesn't mean it doesn't count.

pallid karma
#

mmm

#

@nova tide is there a win cout?

nova tide
nova tide
pallid karma
#

i won with points

nova tide
#

then it would have given you +1 for your leaderboard.

pallid karma
#

it does

#

thanks

#

should i report the fact that i did not receive the badge?

steep agate
#

I think you only get the badge when you win with king points

pallid karma
#

ok

nova tide
#

I'm not sure how long it takes to award the badge. I would recommend waiting for sometime, if it's not still added then you can email and support will add it manually. Don't forget to attach the game url.

pallid karma
#

how can i recover it?

nova tide
pallid karma
#

the game url?

#

i mean, the game ended and i closed the tab after it was saying i won

nova tide
pallid karma
#

how the hell did you..?

#

lol

#

got it ๐Ÿ™‚

#

thaks

steep agate
pallid karma
#

i'll play again to win it with king

nova tide
#

GLHF

pallid karma
#

thanks ๐Ÿ™‚

ebon lichen
fair adder
#

Hi guys :)

steep agate
fair adder
#

@steep agate I saw your video on YouTube for koth

#

It's nice man,I like it

steep agate
#

Thank you very much!! :)

fair adder
#

Hello, do you know where I could learn how to defend windows machines? Like auto RDP disconnection for all the others account etc ...

stray wraith
#

@fair adder

#

have mercy me noobkekw

fair adder
#

oh i will play agains't you UwU

stray wraith
fair adder
#

good luk so ๐Ÿ˜‰

stray wraith
nova tide
fair adder
#

gg @stray wraith

#

i surrend myself

stray wraith
#

1 reset left

#

dunno king time is not updating

#

@fair adder ||check out port runnin mysql||

fair adder
#

yep

#

i know their is a db

#

but i would like to know how do you patch the vim privesc fail

stray wraith
#

uhuh

steep agate
nova tide
#

you can DM

steep agate
fair adder
#

ty

stray wraith
#

||use vim to modify /etc/passwd for root || @fair adder

sour vectorBOT
#

Gave +1 Rep to @stray wraith

steep agate
#

@stray wraith @fair adder what box?

fair adder
#

food

steep agate
#

oh, is easy

#

nice

stray wraith
#

root is a bit tricky

#

but rest is easy

steep agate
steep agate
stray wraith
#

๐Ÿ‘€

#

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.

#

ooooh this is sick

steep agate
#

Yes ๐Ÿ˜…

terse willow
#

Enjoy

stray wraith
#

: 0

#

gg @fair adder

fair adder
#

ty ๐Ÿ™‚

#

but without your hint about root passwd i don't won

stray wraith
#

ong i forgot about that image

#

good game bro

fair adder
#

ty

#

was funny when you kick me x)

steep agate
#

a very interesting machine is also carnage, its root is amazing

steep agate
stray wraith
#

i had to google how to do that

#

i keep forgetting

#

gotta play more often

#

๐Ÿ‘€

#

send again

fair adder
#

king is borken again

fair adder
stray wraith
#

Yea king is broken most of the times when i play

nova tide
nova tide
fair adder
#

all the games i did today

#

and i can't sry because i dont screenshot ip

placid fable
quiet schooner
#

history | grep 10.10

nova tide
steep agate
stray wraith
#

Lmao nice timing

steep agate
# fair adder how could i do this?

just adjust the crontab to kill the other opponent's session, but I don't know if it's against rules so I don't support you doing this

stray wraith
#

Thank you

steep agate
#

xD

stray wraith
#

โญ'ed

fair adder
stiff egret
fair adder
#

Ok ty ๐Ÿ˜Š

steep agate
#

I don't understand, why sometimes king.txt dots don't work?

nova tide
steep agate
stiff egret
short tusk
#

Hey!

If you're having issues with KoTH and the king.txt does not seem to be working,
please ping me or any of the KoTH Staff with the Machine IP.

Do this while the game is still active so that we can review the machine:)

stray wraith
#

@stiff egret ๐Ÿ‘‹

stiff egret
steep agate
#

there could be a reward system for the world's top 10 koth, that's my opinion and I think it would be cool

steep agate
#

king's points are not counting

#

IP machine - 10.10.105.2

#

help me please

fair adder
#

is it alowed to don't do recon on a room we already did? like folowing our old notes?รน

stiff egret
#

"don't" ? Why? Recon is not a rule, it's a choice, if you want to, because it's usually needed. If you don't need it, fewel free to skip it

fair adder
#

because it's a big disadvantage for those who have to do scans

#

so i wanted to know if we don't need to do it every games

stiff egret
#

Not a rule, No.

fair adder
#

ok

steep agate
#

recon is a fundamental part, and it is very important to know how to do a good recon.

fair adder
fair adder
#

i guess i will

steep agate
#

It's much faster than nmap

fair adder
#

ok

fair adder
naive goblet
#

is rustscan that much faster then -T5 nmap????

fair adder
#

i think yes

naive goblet
#

well guess it is up to try it and time them to find out.... then again with the right flags for nmap you should be able to rival the rustscan speed ยฏ_(ใƒ„)_/ยฏ

steep agate
stiff egret
#

Alone, Rustscan can go as high as all ports in one sec I think, it will probably push the target machine to 95%+ usage, but it can get you all ports very very fast.

#

There's a certain factor for PORT CHECKING in rustscan, that simply can't match or is comparable to nmap. In any way.
Nmap is a very detailed tool for scanning, rustscan only lists out the open ports.

steep agate
#

on koth, rustcan helps a lot on some machines with high ssh ports

fair adder
#

i'm alone, did somebody want to play with me?

marsh falcon
#

have u gotten root @fair adder ? idk if its me but it looks like king isnt displaying

fair adder
#

kind don't work onProduction

marsh falcon
fair adder
#

lel

#

but who close all ports except 9999

marsh falcon
#

not me

#

probably the other guy

fair adder
#

fuck

#

how could we play now?

marsh falcon
#

port 9001 and 9002 are open

fair adder
#

yes

#

9999 also

#

dude ๐Ÿ˜ฆ

marsh falcon
#

well, the other guy closed it

#

for sure

fair adder
#

@stiff egret

#

it's probably babauca

#

@marsh falcon even if this it was a good game

marsh falcon
#

thats a bummer

fair adder
#

a noob

marsh falcon
#

that game was beginning to get intense

fair adder
#

@brittle galleon go read the rules

marsh falcon
#

constant disconnects between users ๐Ÿ˜†

fair adder
#

yes was fun

brittle galleon
#

?

#

he closed all ports

#

lel

fair adder
#

you close the ports

brittle galleon
#

:))

#

nop

fair adder
#

?

#

so who did that

brittle galleon
#

i didint

#

the other one

#

well i need to go

#

reset the room

marsh falcon
#

i didnt tho..

fair adder
#

i know syde i don't think he should do this

marsh falcon
#

i was busy disconnecting the others

fair adder
#

is it possible that a misconfiguration of the crontab close ports?

marsh falcon
#

and someone was constantly disconnecting me so it couldnt have been me

fair adder
#

i was trying to do this in the crontab

marsh falcon
#

yea i saw it

#

i had to move fast and removed the sh script on roots home directory

#

u shouldve hid it better ๐Ÿ‘€

fair adder
#

lel i can't experiment with you

marsh falcon
#

haha

#

that was fun tho, sucks that we lost access

placid fable
#

Oh hey guys๐Ÿ˜…

#

Is the game still running?

fair adder
#

yes

#

but we can't do anything

#

sad because i prepared everything

placid fable
#

I got access to it๐Ÿ˜‚

fair adder
#

?

#

like ssh?

#

port 22 not close for you

placid fable
#

Who's king?

placid fable
fair adder
#

i guess it's side

#

but i'm sad because i did something so he couldn't log back as root

#

and so i would be the king

#

but i can't connect ssh so he won

placid fable
#

I have restarted sshd for you๐Ÿ˜…

#

Port 22

fair adder
#

ty

placid fable
#

Looks like someone was trying to fix server.py script๐Ÿค”

#

/home/skidy/homework/server.py

fair adder
#

not me

fair adder
#

i know i put matieu in but don'tremeber of the rest

#

or mathieu

#

well i loose

#

gg everybody

placid fable
#

I don't know what to do, should I change password for you? Or is the game over?

fair adder
#

idk

#

it's mmy false i forgot my password

#

x)

#

don't worry @marsh falcon deserved the win

placid fable
#

Alright, next time try to check for services running on 9001 and 9002

fair adder
#

what are them?

placid fable
#

What exactly is running on these ports.

placid fable
fair adder
#

you don't want to tell me?

placid fable
#

May I DM?

fair adder
#

yes sure

#

the game is finished for me

marsh falcon
brittle galleon
# fair adder a noob

One of u closed the ports, I know for sure. I guess u played as a team against me. Its a individual game. Nab

fair adder
#

I don't close the ports,I don't touch the python server files

fair adder
#

If it was the case why should I kick him and why did he removed my file for kick all users

marsh falcon
#

the game is finished anyways, no need to get heated up

fair adder
#

Yes

fair adder
#

king don't work on offline

#

IP 10.10.146.18

short tusk
#

Could you elabroate?

fair adder
#

well we are on the file but it don't add king time

#

i'm on this file Users\Administrator\king-server\king.txt

#

also by the way if somebody know how to auto disconnect all user on windows server 2012 r2 could he send me ressources or teach me how because i don't find anithing on the pinned messages

#

or any other defense tips for windows machine

fair adder
steep agate
#

๐Ÿ˜‚ ๐Ÿ˜‚ ๐Ÿ˜‚

#

I hate this kind of people, who change the ssh port or close it, IN PUBLIC ROOM

fair adder
#

Me two

brittle galleon
terse fulcrum
#

Anyone give some hint on production KOH
Priv esc

#

I got only two flags also not rooted

#

Can someone help me

nova tide
terse fulcrum
#

yes but it is asking password again

#

rooted:)

fair adder
prime knoll
ebon lichen
#

@rancid pewter As per pinned message, letting you know the "king" status isn't being updated for game running on 10.10.197.148 Thanks!

sour vectorBOT
#

Gave +1 Rep to @rancid pewter

ebon lichen
#

@rancid pewter ๐Ÿ‘

nova tide
ebon lichen
nova tide
#

Until further notice i would suggest not to. Will be announced here when its fixed. Thanks for reporting though.

spice steppe
terse fulcrum
nova tide
#

@livid lava mind if i drop a dm?

wicked shard
#

Anyone up for a match?

nova tide
wicked shard
#

cool

nova tide
#

But rn lunch break from work so gonna grab something to eat

wicked shard
#

oh ok

placid fable
wicked shard
#

yeah i know man , I am playing against a oscp certified ๐Ÿ™‚

nova tide
#

KoTH lead > OSCP

terse willow
wicked shard
#

๐Ÿ™‚

terse willow
#

Just don't play against an OSCE3

wicked shard
#

ok

dapper escarp
terse willow
#

Actually, tbf, that applies to OSCE3 as well ๐Ÿคทโ€โ™‚๏ธ

dapper escarp
#

nah just drop a kernel 0day kekw

ebon lichen
#

@nova tide When I click "Join a public game" on the KotH landing page, it returns Uh-oh! undefined. Any idea what might be causing that?

short tusk
ebon lichen
nova tide
ebon lichen
sour vectorBOT
#

Gave +1 Rep to @nova tide

ebon lichen
nova tide
#

You can join public games through invite link though.

ebon lichen
fair adder
#

why did the hacker machine take so much time to bruteforce

#

i guess you should use passwords hight on the rockyou wordlist because we only have one hour to root the machine

stiff egret
#

It uses passwords high on rockyou. AND it is made with one hour thing keeping in mind. The machine is bruteforce-able in a fairly good amount of time. If it is taking you too long, highly likely that you may be doing something wrong.

fair adder
#

๐Ÿค”

#

maybe

#

but i guess my command is good

#

hydra -l gcrawford -P /home/nk0/wordlists/rockyou.txt ftp://IP -t 64

stiff egret
#

I can only speculate, there is also the factor of other players bruting the machine, resulting in machine being super slow with all those threads.

fair adder
#

sure

stiff egret
#

hm, that command looks find iirc.

fair adder
#

12minuts...

#

and my opponent is already in

#

even ssh is long...

#

[STATUS] 1257.43 tries/min, 8802 tries in 00:07h, 14335725 to do in 190:01h, 64 active

#

but if it was high, why should i get 8802 tries?

stiff egret
#

Ping me the machine IP in DM please.

fair adder
#

i did it

#

ftp```[STATUS] 964.67 tries/min, 14470 tries in 00:15h, 14330057 to do in 247:35h, 64 active

#

and ssh```[STATUS] 26.29 tries/min, 184 tries in 00:07h, 14344214 to do in 9095:04h, 4 active

stiff egret
#

I mean you realise that it is possible that your opponent might have changed the passwords?

fair adder
#

i don't think he did it

#

because with the time he should already be root

#

i think he just bruteforce the ssh credentials

#

but not the ftp

#

i think he change the ssh but not the ftp

stiff egret
#

Can confirm the ssh password is not changed. I just ran the bruteforce, and logged in.

fair adder
#

wait

#

you bruteforce in 1m

stiff egret
#

Yes.

fair adder
#

what's wrong with me?

stiff egret
#

that's what I said to my therapist.

#

jokes aside, your VPN connection could be dropping

fair adder
#

oh

#

how could i fix that

stiff egret
#

Bruteforcing FTP now

fair adder
#

i do

#

it's bruteforcing

#
Hydra v9.2 (c) 2021 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2021-10-06 15:57:39
[WARNING] Restorefile (you have 10 seconds to abort... (use option -I to skip waiting)) from a previous session found, to prevent overwriting, ./hydra.restore
[DATA] max 64 tasks per 1 server, overall 64 tasks, 14344398 login tries (l:1/p:14344398), ~224132 tries per task
[DATA] attacking ftp://10.10.94.76:21/
[STATUS] 257.00 tries/min, 257 tries in 00:01h, 14344230 to do in 930:15h, 64 active
[STATUS] 385.67 tries/min, 1157 tries in 00:03h, 14343370 to do in 619:52h, 64 active

#

i don't have the password

#

did i use the wrong command?

stiff egret
#

Interesting, now from what I think, there's a possibility that ftp password is changed, I am running the same command, and it isn't picking it up.

#

And overall machine is fine, as I was able to bruteforce hydra at double the rate I bruted ftp at.

fair adder
#

ok

#

but ssh bruteforce don't work too for me

stiff egret
#

That's weird, because I can tell you, the current password is as high in the wordlist as <300.

fair adder
#

i don't know why it don't work for me ๐Ÿ˜ฆ

#

well i will do another machine

stiff egret
#

Maybe check / regen your VPN.

#

That usually is the evergreen cure to these issues.

fair adder
#

ok

fair adder
#

@stiff egret one player changed the content of the flags

#

ip: 10.10.44.166

#

and flag is the flag4.txt in root dir

#

here are the palyers

#

and i suspect nerdrobot

#

because he get the root flag

short tusk
#

Boop @nova tide, if you're around

fair adder
#

it's useless to play against this type of palyers

short tusk
#

I'm not 200% sure how to check who's done what.
I presume it may be the user who has the most flags but until Naughty or Homles come online there's not much I can do.

fair adder
#

no problems

#

but he need to know the rules because it's not allowed

nova tide
fair adder
#

because he don't deserve to win

nova tide
#

Let me see

fair adder
#

ty ๐Ÿ™‚

prime knoll
nova tide
#

That's a spectators link

prime knoll
#

sorry idk

gloomy estuary
quiet schooner
fair adder
#

Yes

#

But when the password isn't changed

tribal elk
fair adder
#

?

tribal elk
sour vectorBOT
#

Gave +1 Rep to @nova tide

tribal elk
wicked shard
#

anyone up for a match?

dapper plume
#

are all koth machines have 3 flags ?

nova tide
dapper plume
#

thanks

nova tide
#

You can see the total flags by hovering your cursor to the flag icon near flags submission box.

fair adder
#

anyone wants to join me at some koth?

fair adder
#

hello

#

i have an issue while i'm trying to connect on ssh to the machines

#

i get this error message```Permission denied, please try again.

#

maybe it's from my config or bad version but it's a bit borring cause i can't play

#

do you have any idea of were the problem could come from?

nova tide
#

Are you able to do other rooms?

fair adder
fair adder
#

@nova tide i guess the problem is for every rooms

#

not only koth

#
Unable to negotiate with 10.10.113.87 port 22: no matching host key type found. Their offer: ssh-rsa,ssh-dss
nova tide
nova tide
fair adder
fair adder
nova tide
#

๐Ÿคทโ€โ™‚๏ธ

fair adder
#

should i reinstall arch just for this problem?

#

on the doc i only find for creating a server using openssh

nova tide
fair adder
#

good idea i will wait for help there

fair adder
#

too late

#

:/

fair adder
#

is it allowed to play with two accounts to try defense?

#

like i defend with my first account and then attack with the secound

#

when i'm alone in the lobby

terse willow
#

Only in private games

fair adder
#

ok

#

ty

terse willow
#

Np ๐Ÿ™‚

fair adder
#

3 times it's h1 easy lel

nova tide
#

But is it easy though?

fair adder
#

Anyone lead an in-person KoTH event?

weary axle
stiff egret
fair adder
fallow heart
fair adder
# stiff egret Elaborate?

Iโ€™d like to put on a KoTH event at work for all our new SOC analysts to get them excited to learn more. But Iโ€™ve never lead a KoTH, let alone in person. Looking for tips to make non-red people interested in learning how to do basic PenTesting and then compete

stiff egret
#

100%

fair adder
#

Okay! Thanks. I Havnt touched THM since the Christmas event but want to get back into it and thought this would be the best jump start

fair adder
fair adder
#

Everytime my brute forces attacks don't work on the hackers machine but work on simple rooms like hydra etc... idk why but it's sad because I can't do this room

quiet schooner
#

Usually means your syntax is off.

#

Hydra's also not great for HTTP

fair adder
#

I'm talking about ftp and the syntax is perfect I verify with writeups and with Mr Holmes or Naughty73

quiet schooner
fair adder
#

Weird

quiet schooner
#

GPU doesn't matter in the slightest

#

It's a network bruteforce.

fair adder
#

i have a good connection as well

#

what is wrong with this command?

#

their already in...

#

is it too bad to be win?

short tusk
#

Sample command: hydra -t <threads> -l <username> -P /path/to/password.lst <machine_ip> ftp

fair adder
#

for me it's a good connection

fair adder
#

but mein seems to work too

#

on other rooms

#

do you have a recommandation about the number of thread?

short tusk
#

No more than 16 imo

fair adder
#

ok

short tusk
#

You have to remember, it's not about how fast your computer and network is, it's about the machine you're attacking too.

fair adder
#

yes

#

maybe that's becausei was sending too many requests

fallow heart
#

@fair adder did you close some ports?

fair adder
#

@fair adder staffs idk if i close all ports

#

idk

#

maybe

fallow heart
#

you did i think ^^ we did a reset

fair adder
#

like i wrote a script to disconnect users

fair adder
#

i'm sorry

fallow heart
#

np

fair adder
#

wasn't my intention

#

@fallow heart reset only reboot?

#

don't will delete my defense?

#

i think the ports still close

#

did a staff could turn them back on please? i'm really sorry

#

i wanted to kill user connections every 5secs not services

fallow heart
#

no it's back to normal now

fair adder
#

nice

wind fjord
fair adder
#

we can disconnect ssh connection, it's a part of the game

wind fjord
#

It's okay to disconnect people every once in a while, but writing a script to do that every 5 seconds is defo pushing it in my opinion

fair adder
#

oh idk maybe

#

well it's not write in the rules

wind fjord
#

I'm not KOTH staff, so do as you want, just giving you a heads up

fair adder
#

well let's ask them

fallow heart
wind fjord
fair adder
#

for me it's ok

#

like i could do it without scripts

#

just using who every sec

#

like i did before

#

but i thoug that automatisation was better

#

idea

fallow heart
#

as far as i can see you are alone on the box anyway, im still trying on initial access ๐Ÿ˜„

fair adder
#

gl ๐Ÿ˜‰

#

i don't really defend

#

(because i forget my password)

#

oh no reset removed my chattr patch

nova tide
# fair adder i wanted to kill user connections every 5secs not services

Won't that be a better idea to just patch the way they are getting in from? Defending comes in blue teaming and I don't see how killing every other connection would be counted as blue teaming. Let's say you are in a real world scenario and you have just kicked out every employee from the system rather than patching one simple ssh key.

mortal trail
#

king of the hill H1:Hard is so difficult

#

any hints

#

an an entry path?

fair adder
#

because their is also reverse shell not only ssh

fair adder
#

i have a question, how did jceggink could edit king.txt file even if he was edited using chattr and the chattr binary replaced by something who do that

# chattr +j king.txt 
You are late
bye, Nekro

#

i would like to know how so i could learn more ๐Ÿ™‚

#

(tell me after the game if you see my msg)

ebon lichen
#

๐Ÿ™‚

fallow heart
#

Bring your own chattr ๐Ÿ˜‰

#

@ebon lichen did you shut down ssh? .. there are only three ports left open

ebon lichen
#

Nope, wasn't me

#

I got kicked out as well.

fallow heart
#

thats all i get

#

lets try a reset, someone killed ssh for good

ebon lichen
#

You can still get in via the 15065

fallow heart
#

ik

ebon lichen
#

Then let's privesc and restart SSH ๐Ÿ™‚

fallow heart
#

failing at the privesc from bread ๐Ÿ˜„

ebon lichen
fallow heart
#

Hahaha, thx ๐Ÿ˜„

nova tide
fair adder
#

Their is always another way๐Ÿ˜‰

stiff egret
# fair adder like i could do it without scripts

That's what makes the diff you see, you can obviously do it without the script, but when you do that, i.e. run the commands every second, and realise that automation is not allowed, then you'll realise, sooner or later, that there gotta be a different way to keep them out.
That's the ladder of evolution from what I know.

fair adder
#

I didn't knew sorry

#

Will read the rules again

#

Scripts that automatically hack(autopwns) and/or harden the machine are forbidden

#

It's not the same context

#

Like my script wasn't an autopwn

#

And I'm not sure that it harden the machine because I could do this my self really easyli

fair adder
#

But if it's not allowed, no problems I don't will do it again ๐Ÿ˜‰

#

I just need to know ๐Ÿ˜€

fair adder
#

And if it is allowed should I respect a specific delay?

stiff egret
#

Ok, to be honest, it's really a grey side of things, it depends on the script, how and what it is doing.

stiff egret
ionic wagon
#

What is koth exactly? How friendly is it for beginners

stiff egret
#

You get a machine, 10 players also get the same target IP, all of you race to hack that machine and once you've hacked it, you race to defend it against the players who are still trying to get in. There are flags in the machine that you can find and submit to the main page, and there is a king.txt file, whoever adds their name in that file, gets 10 points per minute for the name being in it.

fair adder
nova tide
#

-> Patch the machine.
-> Disconnect User.
-> See them reconnect again?
-> Find their backdoors and disconnect again.

Won't that be a better approach?

fair adder
#

It's not the only defense i use

nova tide
#
  1. This is not defense.
  2. You need set your backdoors/persistence so you can get back in.
fair adder
#

sure but i choose the users i kick

#

i guess i have to do private games to fully defend the machines

mortal trail
#

Got the Hard machine this time around ๐Ÿ™‚

mortal trail
#

@ebon lichenany hints on the H1:Hard machine?

ebon lichen
mortal trail
#

Thanks mate

stiff egret
#

@quiet schooner

fair adder
#

Anyone want to do some koth?

fair adder
#

Me

#

In a few hours if you want

fair adder
fair adder
#

hackers never want to get bruteforced ๐Ÿ˜ฆ

#

not a question of thread i think

quiet schooner
fair adder
#

Ok i will

fair adder
#

because i don't find it

quiet schooner
fair adder
#

oh yes thank you

#

well it don't work

#

i will try with -64

#

what is wrong with this command? hydra -t 64 -l gcrawford -P /home/nk0/wordlists/rockyou.txt 10.10.226.34 ftp

#

well it don't work with -64

short tusk
#

Yikes, why 64

fair adder
#

Because it's max and faster. But I used 16 first but did nothing

short tusk
#

More doesn't always mean faster:)

fair adder
#

16 don't work two

#

Should I try 1?

nova tide
#

That hash is gcrawford ftp hash btw ^

lucid salmon
#

Hey guys

#

which funny thins do you while are king

#

im so booored

lucid salmon
nova tide
#

/dev/urandom

#

also if you try a bit you can make people play tetris

iron cloud
#

BELLOOO ๐Ÿ˜„ wanna play anyone?

fair adder
lucid salmon
#

@wide horizon hi

#

check the 800 port

#

for a fair play

#

@wide horizon

#

I dont know the user of pythonista

wide horizon
#

I've been spending my time trying to bypass the upload filter, need to practice more

lucid salmon
#

uploading files in koth is slow

#

and it costs you time

wide horizon
#

I've never done this box before, so I was just doing it for the challenge lol

lucid salmon
#

Oh, is your first time?

I've already done this 2 times and it is in this room

lucid salmon
ebon heron
#

ooooo

#

i missed this place

fair adder
#

hello, i don't know if it's normal, but i can't connect in ssh to the machine, like i were disconnected and when i try to connect i get this message:

#

ssh shifu@10.10.241.168
kex_exchange_identification: read: Connection reset by peer
Connection reset by 10.10.241.168 port 22

#

i just want to know if it's allowed by the rules or if it's just a problem from me

#

anyway, gg @eversingoob

#

and by the way if it's allowed how to do this ๐Ÿ˜‰

fallow heart
#

Maybe you broke it while doing chmod 777 on the entire server (for whatever reason..)?

spring hamlet
#

lmao

lucid salmon
#

@silk glade zzzzz

fair adder
#

๐Ÿ™‚

fair adder
#

why did not all the win count for the leaderboard?

#

didn't count

#

I just realized it

fair adder
#

and the game i'm doing don't count...

#

i don't enderstand why :/

stiff egret
#

IIRC, The games with actual king changes are the only ones that are counted.
Any game with king time > 0.

#

cc: @nova tide

nova tide
stiff egret
#

The leaderboard.

fair adder
#

ok

#

so it count for the leaderboard?

#

enven if it's not desplayed

nova tide
#

Any game won with points > 0(default win) is counted for the leaderboard.

fair adder
#

ok ty

fair adder
#

king.txt don't work on offline

#

echo nk0 > king.txt

type king.txt
nk0

median meadow
#

@ebon lichen You're a ninja at these koth matches man!

ebon lichen
sour vectorBOT
#

Gave +1 Rep to @median meadow

median meadow
#

@ebon lichen Had a lot fun playing with and learning from you! People like you make this community amazing. Until next time my friend โœ‹

fair adder
lucid salmon
#

H1 hard is Hard as fork

fair adder
#

๐Ÿ‘€

fair adder
livid lava
#

lel i just realized i'm in that game

swift torrent
ebon lichen
prime knoll
primal scaffold
#

it is pronounced k-o-t-a-h not koth kekw

nova tide
terse willow
#

Last I checked it is pronounced K-aw-th

stiff egret
#

@brazen cloud isn't it k'awh? for you?

heavy abyss
#

never played koth before, i'm in the lobby but how do i connect

short tusk
#

!docs KOTH

pearl gladeBOT
#
TryHackMe
That topic does not exist!

Use !docs to list all of the available topics.

short tusk
#

!docs koth

pearl gladeBOT
heavy abyss
#

thx

fair adder
#

koth game soon! getting my machine ready

#

installing the metapackages on my windows subsystem for linux kali

fair adder
#

42%

#

machine almost ready

quiet schooner
stiff egret
#

@terse willow

#

want a free nitro Muiri?

weary axle
#

kowth

ebon lichen
#

Good evening, just realised I posted my query in the wrong room. I am currently playing the Panda box on 10.10.119.120, it appears that none of the system binaries can be found, with the exception of the shell-builtin command. PATH variable appears fine, and printf '%s\n' * in / shows that e.g. /bin still exists. Any ideas?

#

Makes navigating the box bit of a challenge, not impossible, but being limited to the shell-builtin commands makes collecting flags a bit of a pain.

#

cd /bin returns bash: cd: bin: No such file or directory, so I am starting to believe someone's changes permissions on /bin and possibly removed /usr/bin.

nova tide
#

seems like some might have removed the binaries/folder itself.

#

unable to get a rev shell as there aren't any binaries in the system

#

mind telling me shifu password?
@ebon lichen

ebon lichen
#

Don't know it, it has been changed, I am root now, but passwd no longer works, as the binary cannot be found.

nova tide
#

you can use echo * instead of ls. see if there's anything left in /?

ebon lichen
#

Yeah. printf '%s\n' * in / shows: [root@panda /]# printf '%s\n' * bin boot dev etc home lib lib64 media mnt opt proc root run sbin srv sys tmp usr var

nova tide
#

cd bin ?

ebon lichen
#

So the folder is there, but you cannot cd into it.

#
bash: cd: /bin: No such file or directory```
#

Do you know of a way to list folder permissions with just builtin shell commands?

nova tide
#

are you able to use python/python3?

#

can't test myself without any shell ๐Ÿ˜„

ebon lichen
#

Alas, nope.

#
bash: python: command not found
[root@panda /]# python3
bash: python3: command not found```
nova tide
#

/bin/python or /usr/bin/python ?

#

seems like binaries gone. i couldn't confirm it though.

ebon lichen
#

At least, I am still king ๐Ÿ˜‡ [root@panda /]# printf "%s" "$(</root/king.txt)" jceggink

nova tide
#

yeah the king service is still working

#

well the game is over. GG ๐Ÿ˜„

ebon lichen
# nova tide well the game is over. GG ๐Ÿ˜„

Thanks for the suggestions. I have seen this happen a couple of times before. No have way to circumnavigate it using builtin shell commands, but I guess it is not quite in line with rule 8. Anyway, thanks!

sour vectorBOT
#

Gave +1 Rep to @nova tide

nova tide
ebon lichen
graceful oriole
#

Hiii, anyone for any koth this afternoon?

#

I'm real begginer level but i wanna try

tardy pulsar
steep agate
#

you're lucky that I don't have my notebook, I'm on a 2gb ram, pentium dual core computer and I'm not even at home hahahahaha but next time, when I win my notebook this month or the next, you'll have an opponent at your height hahahaha

#

@ebon lichen

ebon lichen
steep agate
#

hahaha I'm looking forward to this too!

graceful oriole
#

hi

#

anyone for kot?

nova tide
graceful oriole
#

Tnks

fair adder
cerulean summit
#

hello

stiff egret
#

hello

fair adder
#

anybody know the solution to this on production koth?

#

retry without the $IP like ashu@10.10.199.98

#

thanks it worked

tardy pulsar
fair adder
#

getting better at koth

#

fastest ever flag ive gotten

nova tide
fair adder
#

oh sure

#

soz

nova tide
#

Have fun blobheart

fair adder
#

ty

dim scroll
dim scroll
#

Anybody?

nova tide
nova tide
#

gg @dim scroll @ebon lichen

#

@ebon lichen let me know if you plan to play another one ๐Ÿ™‚

ebon lichen
red marsh
#

Currently in a game and 'Tyler' seems to be down - anyone else having this problem?

fair adder
#

Yoyo