#koth

1 messages Β· Page 71 of 1

graceful bear
#

i gave up long time ago

#

lmao

brittle ether
#

Same

steep agate
#

I think this is you

graceful bear
steep agate
#

if he was a sysadmin he would certainly use an iptables, but it's forbidden in koth 🀣

plush kiln
#

Hehehe

lilac idol
#

can you give me a tip

#

so i can get a flag bro

brittle ether
#

I guess he is dead

#

He won’t give a tip

lilac idol
#

is this a flag or what

graceful bear
#

i also saw that

#

decoding it looks like a password

#

but unfortunately it's not a flag

lilac idol
#

it was a hash

#

now what

#

this is the password

#

736872656o6973616s6r696s6r

#

lets try it

steep agate
brittle ether
#

@steep agate u broke the shreck machine

steep agate
#

nor the failures in the web applications I corrected

lilac idol
#

do we use metasploit to exploit apache tomcat on port 8080

steep agate
#

I wanted to test something but I don't think it's possible in koth, it's kind of a shell breaker, when the person doesn't hide their pts, you break their shell, you can't even exit

steep agate
lilac idol
#

only 11 minutes left

steep agate
lilac idol
#

youre a pro

#

i lost

steep agate
#

that nothing, I'm just a koth user, like many others hahaha

graceful bear
#

πŸ‘€

brittle ether
steep agate
#

@brittle lotus restarting 4/5 times

#

🀣

brittle lotus
#

Hi

#

I don't play anymore. The service was not available.

steep agate
#

lol, the only thing i did was remove the id_rsa from gloria you were using to connect over ssh

brittle lotus
#

Is this new game? "Restart"

steep agate
brittle lotus
#

5?

steep agate
#

3/4

brittle lotus
#

No

#

I didn't even play

#

I connect only once

steep agate
#

10.10.205.113
10.10.114.192
10.10.216.181
10.10.187.175

#

4 restarts

brittle lotus
#

What is that?

steep agate
#

I thought they were trolling the game, if I patched the gloria user, 3 people were already clicking on reset, lol, I just thought it was funny

brittle lotus
#

After that I started playing. 🀣

steep agate
#

🀣

brittle lotus
#

And next game I just join

#

And logout...

steep agate
#

when I was going to score out of nowhere I saw about 3 people clicking on restart, then I: WTF WHAT'S HAPPENING, and I kept laughing

#

🀣

brittle lotus
#

Not the first time.

steep agate
#

yeah

brittle lotus
#

I am going to sleep. It's too late for me.

#

See you

steep agate
#

beauty, we are together flint, if you need we are there

#

@brittle lotus see you later

edgy knoll
#

all the criminal bosses are offline lol

#

lemme steal wins

#

@steep agate yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy

edgy knoll
steep agate
#

relax, I'm not even going to play, I'm just going to get root, if you want you can stay in king there

steep agate
# edgy knoll oh ohk

actually I'm going to stay in the king for 1 minute, I'm going to record the "demo" of something I intend to release

#

But don't worry, after I record, I take my nick from the king and leave the machine, for you to play

edgy knoll
#

finally someone with heart lol πŸ˜‚

#

you guys keep beating the machine you've already played over and over

steep agate
# edgy knoll you guys keep beating the machine you've already played over and over

actually, I think everyone here plays for fun, including me, koth is good because you train your "blue team" side, and it's good to do research related to defenses on linux machines, attack your opponent on the machine without using urandom, or things like that, defend your king, modifying attributes, learning to fix simple flaws like a command injection, an lfi, a file upload , among others, anyway, as far as I know, everyone plays for fun, including me too

#

sorry, my english is very bad hahahaha

edgy knoll
edgy knoll
steep agate
#

but chattr is not the only way to protect your king, actually chattr is one of them, but there are several

steep agate
edgy knoll
edgy knoll
steep agate
#

any ideas to "neutralize" chattr ?

edgy knoll
#

yup

#

tried changing the root folder name to root2 once

steep agate
#

if anyone used chattr +i, to change attributes, just use -i, to remove attributes and put your name there

edgy knoll
#

to mess with the/root/king.txt algorithm i think

steep agate
steep agate
edgy knoll
#

hackers damn

#

am doommed

#

keep forgetting to open attackbox early

steep agate
#

now I'm out of the machine, good game

edgy knoll
#

yup am king thanks muahhhhhhhhhhhhhhhh

steep agate
#

we are together, if you need help, or anything like that just call me

#

πŸ˜ƒ

edgy knoll
#

yup also look at my keepsake

#

i beat a God πŸ˜‚

#

joy

#

dont come back oh am kidding lol πŸƒβ€β™‚οΈ πŸ’¨

#

joking/kidding

steep agate
fossil pecan
steep agate
#

@fossil pecan I also need to update my github, from tricks to koth, I will add more things too, add more things to defend linux machines, windows too, teach how to patch for example in a file upload, lfi, command injection, etc.

fossil pecan
#

nice, i'm excited to learn more, i'll be publishing some of my tools and stuff also ... linux only tho, i still need to learn windows πŸ˜› ... haven't used windows much since 2008-2010 lol

steep agate
#

I must have been 5/6 years old at that time

#

🀣

fossil pecan
#

πŸ˜›

#

was my first college job as win sysadmin for uni ... but i ended up rebuilding most on linux

#

fuk IIS and all that old ASP crap

steep agate
#

damn, that's cool, very good

steep agate
#

so cool

#

@fossil pecan

#

I'll post it later today on my github

fossil pecan
#

nice

steep agate
fossil pecan
#

coming from system/devops engineer, it's really hard for me to not make (or try to) "autopwn" scripts haha ... I'm obsessed with scripts & automation

fossil pecan
steep agate
#

hahahaha, I wanted to take LPIC in the future

fossil pecan
#

LPIC?

steep agate
#

yeah

#

"Linux Professional Institute Certification"

fossil pecan
#

ah nice

#

i'm terrible with terms & acronyms haha ... but i know most of the fundamentals πŸ˜›

steep agate
#

hahahaha it's part

fossil pecan
#

i can't "remember" or "memorize" anything ... but i'm addicted to "understanding" everything

steep agate
#

I understand, how cool

steep agate
fossil pecan
#

haha ya maybe ... i'm a late bloomer πŸ‘΄

steep agate
#

I turn 17y this month

fossil pecan
#

nice, i'm 32 in august

#

πŸ˜›

steep agate
#

as I imagined, double

fossil pecan
#

almost dbl haha

steep agate
#

🀣

steep agate
#

well, the chat was good, I'll have to leave, and later I'll come back and I'll post it on github, see you later xD

naive cradle
#

Anyone up for some koth?

fossil pecan
#

starting up (beginner friendly) koth game(s), getting ready in the KOTH voice channel πŸ˜„

naive cradle
#

ok

fossil pecan
fossil pecan
#

@steep agate i'm trying windows koth "offline" ... i'm on the box, found a flag ... found king.txt, and put my name in there .. not king tho? haha idk windows for shit

#

my name is in king.txt ... am i missing something on windows?

#

haha found a bunch more flags

#

no clue if/how king works on windows

edgy knoll
#

helo snipe

edgy knoll
#

@brittle lotus look at my other keepsake

fossil pecan
#

@brittle lotus well played

#

I need to learn some more of those tricks haha

#

Just know mostly sysadmin things 😜

edgy knoll
#

lol

#

is amtheu online

edgy knoll
#

@steep agate

fossil pecan
#

@brittle lotus that really was awesome, haha you stumped me on a few things πŸ˜› ... GL on the rest of your games, i gotta go sleep haha

brittle lotus
brittle lotus
brittle lotus
brittle lotus
fossil pecan
brittle lotus
edgy knoll
#

last minute lol

brittle lotus
edgy knoll
#

sorry he gave me the match to play it he would've killed me if I lost

prisma roost
#

"badass are coming soon" πŸ‘€

edgy knoll
steep agate
steep agate
#

whats up

steep agate
#

and that's it, then you put your name on the king i, it's very easy hehehe, neutralized 😎 πŸ‘

#

using this here in koth would be OP, but I think it's forbidden 🀣

steep agate
edgy knoll
#

the last time we wanted to do a reset loop

#

against you

#

you added your dummy account

steep agate
# edgy knoll you added your dummy account

lol it was not my account, i called a friend of mine to play too, since everyone was together against me in loop, he plays koth sometimeso, g3n is good, i think he knows more than me

steep agate
#

he plays sometimes, but this birdhead never plays with me 😦

edgy knoll
steep agate
edgy knoll
#

we play together I'm commanding his moves he's typing lol

steep agate
edgy knoll
#

my wpm is as fast as my username

steep agate
#

for me you can take me out of king at will, i just want to train my skills with linux defense in koth

steep agate
edgy knoll
#

You really sound like a od πŸ˜‚ lol

ask and it shall be given unto u

steep agate
steep agate
edgy knoll
#

wish me luck i'm facing a god

#

lol food the creds are in my head\

steep agate
#

the battlegrounds hackthebox level is very good, it doesn't have so many entrypoints, it's fun, but too bad you can only play 2x a month, and practice is unlimited

edgy knoll
#

lol

#

i want to report someone

steep agate
#

but KoTh is a good place to train your skills with linux defense, but not only like koth, there are other labs to train too, skills with linux, sysadmin, and etc, for example, iptables cannot be used, which certainly a sysadmin would use, it's much smaller, but fun

edgy knoll
#

this guy cheats more than you lol @steep agate

prisma roost
# edgy knoll

he could've just emptied the path export PATH='' not necessarily cheating

edgy knoll
prisma roost
steep agate
#

just remove the id_rsa key that no one else tries to own the machine kkk.

#

or else change the user ssh password

#

I always try to get shell in different ways, for example I found a new one, with a recent cve

prisma roost
#

if it's pwnkit, it's overrated, if I play I always do chmod -s $(which pkexec)

steep agate
#

but it's ok, you can team up against me, resets, do what you want, I play 4fun XD

prisma roost
#

also, congrats on the top 1 position in koth πŸ₯³

edgy knoll
brazen cloud
steep agate
sour vectorBOT
#

Gave +1 Rep to @prisma roost

steep agate
#

in my github/ytb channel

lilac idol
lilac idol
fair meteor
fair meteor
summer needle
#

hey i'm pretty new can i do the koth one day?

lilac idol
edgy knoll
#

hello

#

buddy

edgy knoll
edgy knoll
#

brah this dude lol

lilac idol
edgy knoll
#

lol

#

pray although i only fear 3 people

#

matt mug flint

lilac idol
#

yeah im right here

edgy knoll
#

and @fair adder he's been offline since idk y

fair adder
#

what

lilac idol
#

yeah you have to take notes

edgy knoll
fair adder
lilac idol
fair adder
#

Hii

edgy knoll
#

havent seen you in a while

fair adder
#

just i am not doing koth

#

busy with my work

lilac idol
#

are you a pentester

fair adder
#

yes Red Teamer

lilac idol
#

nice

edgy knoll
#

oh my buddy use to say if it's windows @fair adder will win lol

fair adder
#

ya

edgy knoll
#

my laptop is dead

#

am switching to the slow as hell one

lilac idol
#

i hate the windows machines

fair adder
edgy knoll
#

good luck @sinful moat

lilac idol
#

were already in a game Niko

#

you would beat us anyway

fair adder
#

ok

lilac idol
#

hahah

fair adder
#

tell me when you start new game

lilac idol
edgy knoll
lilac idol
fair adder
fair adder
#

i did't see it lol

lilac idol
#

in order to be the best you have to beat the best

fair adder
#

LoL Yes

#

Beat @steep agate

lilac idol
#

i have tried lol he is good

fair adder
#

No I don't like this box

edgy knoll
#

lol its not windows

fair adder
#

yes 😭

edgy knoll
#

i came in late lol

#

no hope for me

lilac idol
edgy knoll
#

mr niko is in there

fair adder
#

yes

lilac idol
#

Niko why havent you got in yet

fair adder
#

i am in other game

#

i am not playing that game

lilac idol
#

why

lilac idol
fair adder
#

no

#

i did't do any thing in hacker box

edgy knoll
#

i took the whole thing down

lilac idol
#

you did

edgy knoll
#

yup

#

try another way

edgy knoll
lilac idol
#

i have to log off my mac

#

and use kali

#

i try to use my mac with homebrew run into problems

edgy knoll
#

i didnt see this one that's why tho

fair adder
#

πŸ™‚

edgy knoll
#

if it's windows i cant even dream of winning

fair adder
#

πŸ₯²

edgy knoll
fair adder
#

Yes πŸ™‚

potent parcel
#

welcome to the second round

edgy knoll
fair adder
#

Xd

edgy knoll
#

play with you next time lol battery low

#

@fair meteor i beat your idol πŸ˜‚

edgy knoll
#

lol

fair adder
#

bye bro

fair meteor
unborn anchor
steep agate
#

whats up?

#

sorry i was sleeping i just woke up

fair adder
#

Ohk

#

@steep agate one Guy was telling that to be best you have beat the best.

#

so i tell him beat you.

lilac idol
#

are you guys playing still

fair adder
#

no

summer needle
# fair meteor Yeah

for sure just looking for some people to play with. I still wanna knock out a couple more rooms before I try KOTH

fair meteor
#

@summer needle U should KOTH is kinda more of like been fast

steep agate
edgy knoll
#

@steep agate damn i need your writeup

#

koth

#

please

steep agate
edgy knoll
#

github

fair meteor
steep agate
fair meteor
#

Thanks

fair meteor
#

The kinda situation am in now is complex

#

I got root for 10sec😭

#

@steep agate U killed my shell

#

whhhhhhhhhhhhhhhhyyyyyyyyyyyy

steep agate
#

lol

fair meteor
#

I really don't know how to use vim fast

#

I was like shit "pressing delete key"

#

He's gonna get in back soon

#

And before i know boom i saw a broadcasted message saying bye

#

I then knew that was the end

#

Besides hw did u do that

steep agate
#

```kill ps aux|grep sshd|grep pts|awk '{print $2}';echo "bye";

#

😎 πŸ‘

#

well I'm going to bypass the XDR, good game bro, if you need just give me a touch here @fair meteor

steep agate
lilac idol
lilac idol
#

too easy boys

naive cradle
#

big dub

fair meteor
fair meteor
#

@near lily lol lets play

jovial field
#

(starts in ca. 20min)

fair adder
#

for sure

#

ima join hold o

#

on

jovial field
#

nice

lilac idol
lilac idol
#

invite

fair meteor
#

Join up y'all

#

@steep agate Whhhhhhhhhhhhhyyyyyyyyyyyyyyyyyyyyy

stiff egret
#

can I join? πŸ‘€

fair meteor
#

Yeah\

#

1min remaining be fast

stiff egret
#

ah, I'll pass then. Have fun y'all πŸ˜„

#

Just got back home, setting up everything now. Gonna take a while.

#

I thought it'll be standard 25 mins wait

fair meteor
stiff egret
#

ah niceeee

#

have fun blobfingerguns

fair meteor
dry fossil
#

@lilac idol Yh I didn't touch perms in /tmp

lilac idol
#

you did what to get root

dry fossil
#

Idk about that, I was careful not to mess with file perms because I didn't want to break a rule by accident

#

one sec

dry fossil
lilac idol
#

i thought you did

dry fossil
#

Using the bobba user

lilac idol
fair meteor
dry fossil
#

but I didn't change perms, I used find . -exec /bin/sh \; -quit

#

yeah

lilac idol
#

but how did you privesc

dry fossil
#

that was the privesc

lilac idol
#

from duku

fair meteor
#

nope bobba

dry fossil
#

Oh the password for bobba was in the db

lilac idol
#

i was trying to privesc from duku

dry fossil
#

and so I used python to create a shell and used that with su -l bobba and the password I found to get in

lilac idol
#

with this

fair meteor
#

strings web.db

lilac idol
dry fossil
#

Yeah that was the issue, duku had no suid bit executables

#

whereas bobba did

fair meteor
dry fossil
#

yeah

lilac idol
#

you found it in the database

dry fossil
#

Yeah

lilac idol
#

bobba

dry fossil
#

I used netcat to get it off the server

#

and then read it from kali

lilac idol
#

DB browser

dry fossil
#

Yep

fair meteor
lilac idol
#

lets play again

dry fossil
#

I'll play shortly, need a piss 🀣

fair meteor
lilac idol
#

scan every port

#

it could be on a random port

fair meteor
fair meteor
lilac idol
#

someone can change it

#

once they get root access

#

to a random port

lilac idol
steep agate
dry fossil
#

I tried hogwarts and failed miserably

#

although I was distracted as I was helping mates with their course work

#

That was my second time on carnage though

steep agate
dry fossil
fair meteor
steep agate
fair meteor
#

Yeah

dry fossil
#

Just because I tried it with nc and it didn't seem to complain but for some reason when I used the ftp client it complained

lilac idol
#

yeah if you play someone who plays this a lot then good luck

#

they already know every machine

fair meteor
dry fossil
#

and I couldn't be bothered figuring it out because I was distracted

lilac idol
#

-p-

dry fossil
fair meteor
dry fossil
steep agate
#

very OP lol

dry fossil
#

and then for particular versions manually do an nmap service version scan on those ports

#

I found that ideal

lilac idol
fair meteor
fair meteor
lilac idol
#

yeah use rustscan

dry fossil
#

fucking vm copy isn't shared

#

I forget that

steep agate
# fair meteor U're hiding ur pts right?

yes, I like to do a lot of research involving linux, and I test sometimes not always on koth, I play koth for that, and for the fun too ahueaheha, to see people trying to root/shell

dry fossil
#

is the room I'm in

lilac idol
#

yeah

fair meteor
#

So is it going to be on github

near lily
prisma roost
steep agate
#

πŸ‘€

steep agate
lilac idol
#

such as what

steep agate
# lilac idol such as what

one of them is you run a command in some other terminal, you make the person unable to exit the machine, you lock him in a restricted shell, and so on, there are several things

fair meteor
lilac idol
#

mathew said this is old but i havent seen one better than this https://noxtal.com/cheatsheets/2020/08/08/ultimate-koth-defense-guide/#remove-user-from-sudoers

steep agate
fair meteor
#

y'all should enjoy the game

#

my laptop battery is almost dead

dry fossil
#

I have no clue with this one icl

lilac idol
#

UEsDBAoACQAAAJadq1RMPeimHwAAABMAAAAJABwAY3JlZHMudHh0VVQJAAMcBHxiHAR8YnV4CwAB
BAAAAAAEAAAAANsLE1t+lexRf5gWwdTJB0nMZHLf++BKaOdVpGT2HuFQSwcITD3oph8AAAATAAAA
UEsBAh4DCgAJAAAAlp2rVEw96KYfAAAAEwAAAAkAGAAAAAAAAQAAAKSBAAAAAGNyZWRzLnR4dFVU
BQADHAR8YnV4CwABBAAAAAAEAAAAAFBLBQYAAAAAAQABAE8AAAByAAAAAAA=

dry fossil
#

I found that and have no clue what to do with it

lilac idol
#

i found this on port 3333

dry fossil
#

I presumed it was b64 but it's not

#

or it's encoded or something

lilac idol
#

it could be encoded multiple times

#

in different encodings

#

i tried anonymous ftp

dry fossil
#

yeah that didn't work for me

lilac idol
#

MatheuZSec

fair meteor
#

that is base64 encoded format

#

decode it

lilac idol
#

i found mathew name on port 9999

#

hahah

fair meteor
#

it will have credentials to login as fortuna

lilac idol
#

PK
οΏ½ ���–«TL=è¦οΏ½οΏ½οΏ½οΏ½οΏ½οΏ½ οΏ½οΏ½creds.txtUT οΏ½|b|bux οΏ½οΏ½οΏ½οΏ½οΏ½οΏ½οΏ½οΏ½οΏ½Γ› [~•ìQ˜ÁÔÉIÌdrßûàJhΓ§UΒ€dΓΆΓ‘PKL=è¦οΏ½οΏ½οΏ½οΏ½οΏ½οΏ½PK
οΏ½ ���–«TL=è¦οΏ½οΏ½οΏ½οΏ½οΏ½οΏ½ οΏ½οΏ½οΏ½οΏ½οΏ½οΏ½���€����creds.txtUTοΏ½|bux οΏ½οΏ½οΏ½οΏ½οΏ½οΏ½οΏ½οΏ½οΏ½PKοΏ½οΏ½οΏ½οΏ½οΏ½οΏ½OοΏ½οΏ½οΏ½rοΏ½οΏ½οΏ½οΏ½οΏ½

#

it says creds.txt

fair meteor
lilac idol
#

it put a password on the zip

dry fossil
lilac idol
#

when i downloaded it

dry fossil
#

oh that would make more sense

#

it's a zip rip

fair meteor
#

yeah

dry fossil
#

I got the creds

fair meteor
#

zip2john application.zip > hash

#

john -w=/usr/share/wordlists/rockyou.txt hash

#

then get the cred

lilac idol
#

he already got all 7 flags

#

and probably changed the password

dry fossil
#

the login isn't working for ftp

fair meteor
fair meteor
dry fossil
#

I tried that but I'll try again ig

lilac idol
#

he probably changed the password

fair meteor
lilac idol
#

by now

fair meteor
#

lol Thats the first thing to do

steep agate
#

πŸ‘€

dry fossil
#

yeah ssh is patched along with ftp

lilac idol
#

yeah

#

were done for

fair meteor
dry fossil
#

yeah we're already locked out

fair meteor
#

lol

#

be familiar with linux according to matthew

dry fossil
#

Unfortunately the only alternative is trying to find a vuln in the webpage

#

which is unlikely

#

or those "random" ports anyway

near lily
#

I might play Koth. πŸ€”

dry fossil
#

the ports are locked off

lilac idol
#

search Apache/2.4.29 vulnerabilities

dry fossil
#

there's not much for it really

lilac idol
#

even if you get in he will kill the shell right away

steep agate
dry fossil
#

Have you left anything open? 😭

lilac idol
#

try to inject something on port 80 website

#

i think thats the last thing open

steep agate
dry fossil
#

Anything left vulnerable at all?

lilac idol
sour vectorBOT
#

Gave +1 Rep to @steep agate

dry fossil
#

Just wondering whether to bother trying still for now or wait till the next game

lilac idol
#

port 80 http webserver

#

is vulnerable

near lily
lilac idol
steep agate
#

good for today enough koth, thanks guys, it was a great game!

#

fortuna password : loveitachi

#

I put this password now, if you still want to play

#

@lilac idol@dry fossil

dry fossil
#

I figured out an entry point anyway

#

I'm working on another entry point

lilac idol
#

did you view creds.txt

dry fossil
#

yeah

#

I've not managed to get in but I'd found an ssh key in a file share

lilac idol
#

do you want to play again

dry fossil
#

can do

lilac idol
lilac idol
dry fossil
#

the file share is stuck mounted

#

ffs

#

Imma head off for now actually, am quite tired, will be on tomorrow tho

manic palm
#

Do the machines change? Like can't you just automate it once you've already done it?

wind fjord
#

I think Hackers and maybe like 1 or 2 other machines have dynamic flags and passwords so you can’t exactly script those ones as easily, but yeah

manic palm
#

Ah okay

#

But once you know initial access, you basically are just racing

wind fjord
#

Autopwns aren’t allowed because of the rules in place, but there’s nothing else stopping you other than being reported by other players and an honor code πŸ€·β€β™‚οΈ

manic palm
#

Makes sense

wind fjord
#

Most of the action for people who play this a lot is being on the box and reacting to other people’s defenses/trolls/traps quickly enough

steep agate
fossil pecan
# manic palm Makes sense

You playing KoTH? I'm finishing work and eating dinner, probably gonna get back on THM for a while if you're still around 😁

stiff egret
quiet schooner
edgy knoll
#

its pretty lively today

edgy knoll
dry fossil
#

How many flags are there in carnage?

dry fossil
#

I've got 7 so far, I'm assuming that's all of them

#

@broken loom GG

strong spear
fossil pecan
#

@graceful bear GG! almost caught up haha, just found 2nd flag as game was ending πŸ˜› ... only 2 on that box? probably more just harder to find?

graceful bear
#

That was a good game!!!

#

yeah only 2 flags x)

fossil pecan
#

haha ok

#

anyone have join link for current public game on "food" box?

dry fossil
#

just seen it's ending in 3 minutes tho

fossil pecan
#

all good, it put me into another food game πŸ˜›

dry fossil
#

good stuff

#

lmk how many flags you manage to get, I found 6

fossil pecan
#

same

dry fossil
#

got 7 on carnage

fossil pecan
#

nice

#

i don't think ive found more than 6 on any yet haha

fossil pecan
#

haven't seen any activity from the others playing in this game 😦

dry fossil
#

Oooh, where was the 7th?

#

wait do you mean the one in /home/tryhackme

#

called flag7 or do you mean you found 7 overall (just checked and congrats on getting 7 I had no clue and used the find functions so I presume it was hidden inside a file or something)

fossil pecan
#

ya it was in a unique location

#

i found with global search from /

dry fossil
#

ahh fair enough, will get it next time

fair adder
#

i used to play with someone who would change the flags

fair meteor
#

Someone deleted binaries

lilac idol
#

is it illegal

#

to change the flags

lilac idol
fair meteor
#

yEAH

fair meteor
#

Then probably they will report u

#

???

lilac idol
#

oh okay

fair meteor
#

Nice

fossil pecan
#

Any games going on?

lilac idol
#

i read the rules

#

yeah we got a game

nova tide
fossil pecan
fair meteor
lilac idol
#

the game already started sorry

fair meteor
#

My wifi is down

fossil pecan
fair meteor
fossil pecan
lilac idol
#

i was in but he killed my shell or something

#

im locked up

#

this guy is cheating

#

bad

fair meteor
#

i did not kill ur shell

#

I removed the authorized keys

#

so u won't login with the id_rsa

lilac idol
#

idiot

fair meteor
lilac idol
#

you are cheating

#

you made my whole screen mess up

#

and made my terminal fcked up

fair meteor
fossil pecan
#

lol ya seems like someone tanked this sytem ... no user names for ids, and /etc/ssh is gone entirely πŸ€”

fair meteor
#

there's actually /etc/ssh

lilac idol
#

youre getting banned

fair meteor
fossil pecan
#

πŸ€·β€β™‚οΈ

fair meteor
#

U are root also

fair meteor
fossil pecan
lilac idol
#

it was

fair meteor
#

Then generate another id_rsa

fossil pecan
#

/etc/ssh is the entire sshd server config πŸ˜›

lilac idol
#

my terminal said 999+ things popping up

#

when i got root

fair meteor
fossil pecan
#

i got urandmed too lol

lilac idol
#

hes cheating

fossil pecan
#

part of the game

fair meteor
#

I just wanted to make it fun

fossil pecan
#

❀️

#

i dig it

lilac idol
#

im reporting you for messing my terminal up

fossil pecan
#

?

#

oh shit that other game started lol

#

forgot

lilac idol
fair meteor
strong spear
#

Finally, I'm become to winner of the KOTH.

fair meteor
#

Oh mug3 is there nvm

fossil pecan
#

someone fuked this box, or really fking with my sessions somehow lol

#
bash: /usr/bin/ls: No such file or directory
bash-4.2# id
id
bash: id: command not found
bash-4.2# echo $PATH
echo $PATH
/usr/local/bin:/usr/bin
bash-4.2# export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
bash-4.2# ls
ls
bash: ls: command not found
bash-4.2# sh
sh
bash: sh: command not found
bash-4.2# /bin/sh
/bin/sh
bash: /bin/sh: No such file or directory
bash-4.2# 
fair meteor
strong spear
#

but I didn't received KOTH winner badge. why?

fair meteor
strong spear
#

Yes

fair meteor
strong spear
#

H1:Hard

fair meteor
#

Am not sure u put ur name in king.txt

#

Did u do docker escape to get the main root

strong spear
#

I didn't access the got king.txt but I see this king.txt file.

fair meteor
#

U should have put ur name in king.txt file

#

Though u won

#

Cause u had much flags than ur opponent

graceful bear
#

lol @fossil pecan

#

what are you doing with my shell

fossil pecan
#

❀️

#

reset?

lilac idol
#

it made my computer lock up

quiet schooner
#

@lilac idol You were told where to take accusations of cheating.

fossil pecan
#

@graceful bear i wanna find those other 2 flags!! haha i'm only at 5 πŸ˜›

graceful bear
#

πŸ‘€

#

i wanna find the last flag lmao

fossil pecan
#

oh there's 8?

#

hhaha

#

i'm not looking hard enough

graceful bear
fossil pecan
#

we're getting record for king changes on the koth page game list πŸ˜„

fair meteor
fair meteor
quiet schooner
# fair meteor Okay

Spamming terminals isn't against the koth rules, they're just being a sore loser

fair meteor
#

Help!

#

My kali machine isn't connecting to the internet

#

So I have been using kali on thm

fair meteor
#

Anyone online

steep agate
#

lol

#

I have worse things than urandom, you won't even be able to get out of the shell, and that's not cheating either, it's part of the game, it's the same as spawning nyancat, it's not cheating lol

fair meteor
steep agate
#

I'm updating my koth tricks repository, it should be ready by 16/15/17

dry fossil
#

gonna have to work on the unprotect version 🀣

#

set +o noclobber and whatnot

#

new box To try, pretty happy for a first attempt

steep agate
#

🀣

steep agate
dry fossil
#

Fair enough πŸ˜„

#

How would you have gone about undoing chattr removal, just re-add a binary?

steep agate
#

yes, just add the chattr binary again

#

buuuuuuuuuuut

#

if you leave wget, curl, etc, and leave these binaries only for those who are root, your opponent will not be able to put chattr on the machine, nor any exploit to be able to escalate privileges, but there is a way to "neutralize" that, you can also do it upload binaries, exploits etc, using ssh

#

another thing for an "add-on" would be to remove the gcc or the lib that gcc uses, so your opponent won't be able to compile on the machine 🀣

dry fossil
#

Yh that being said, you could use a netcat output to file

steep agate
#

yeah

dry fossil
#

and if nc is removed or not present &> /dev/tcp/ip/port will work

steep agate
#

well i never tested removing netcat from koth machine, so i can't give you a certainty @dry fossil

dry fossil
#

yh however they shouldn't really be resetting the machine just because they can't get in

steep agate
#

but that's exactly what happens, for example

#

you couldn't enter the user who had that password, after that there are people who don't even try anymore, they just leave by clicking on reset and enter the next game, so I say you have to think how your enemy would make the machine, and the steps

dry fossil
#

Well yeah, ig, I just go to /games/koth and join another one that way if I'm locked out entirely

#

at least once I've tried finding a new entry point

steep agate
#

although, at most, there are 5/6 entry points on some machines, not all

#

I'm thinking of quitting koth, I've already reached my goal, and I had a lot of fun playing koth, met some brilliant people

graceful bear
fair meteor
#

lol its so addictive hahaha

dry fossil
#

🀣

manic palm
#

Do games run regularly or do I need to queue with people?

#

I might start this weekend lol. Intimidated but looks so fun

fossil pecan
# fair meteor lol its so addictive hahaha

haha i know, right?!? i'm still just getting familiar with all the koth stuff, can't wait to learn more πŸ˜„ ... i need serious help on windows lol, i had admin last windows box, but writing my name in king.txt ... never registered my as king 😦

#

idk shit about windows πŸ˜›

fossil pecan
cerulean summit
#

goodluck!

#

whos playing koth right now?

#

windows box ;-;-;-;

exotic glade
#

Anyone wanna play koth?

naive goblet
#

would play if shadow was not planning on sleeping soon thanks to it being past midnight

fair adder
#

This is probably an obvious question, but it's not obvious to me. Given the fact that everyone uses their own system to log into the same machine, are there any possible leaks of data or information that could occur?

jovial field
quiet schooner
exotic glade
dry fossil
#

@graceful bear gg, where was that 7th flag that u found, I found two entry points and got the flags in the home directories and iirc one from a db

graceful bear
#

the other is in an interesting directory in /etc

dry fossil
#

ahh

#

when you got root how'd you go about it? Did you escalate through neville using the ip suid?

#

That was my first way onto root but towards the end I found one file that led me to 3 other files and gave me access to a backdoor-esque thing

#

I did try and upload a reverse shell to the resume-upload and succeeded but it didn't seem to work, I also noticed wget and nc weren't working to connect to my webserver so I presume you set something up but that was good fun, first time on that one. I think I did fortuna twice and am still finding stuff on that. I want to try and find some new entry points on carnage as I've done that a few times now and I tried shrek the other day 🀣

graceful bear
#

it's always good to go through the machine after getting root..there's always some juicy stuff to find

dry fossil
#

yeah, I ended up sticking to the machine and not trying to do the webserver stuff, only reason I tried at first was to try and move across laterally to try and get a flag

steep agate
#

@graceful bear

graceful bear
steep agate
lilac idol
steep agate
edgy knoll
#

aiyo

random trellis
edgy knoll
#

we got history

random trellis
edgy knoll
#

I've been beating gods at level 1 i have alot of keepsakes

#

i want to add your name lol πŸ˜‚

random trellis
#

πŸ˜‚ πŸ˜‚

#

actually i am busy in my exams these days, so not playing koth

#

alot

edgy knoll
#

writing final year exams

#

also

random trellis
#

nice i got messages from many koth players and most of them were 15-16

#

and thats great lol

#

all of them were good in ctf

edgy knoll
edgy knoll
random trellis
#

when my exams were not started

#

i am 20 btw lol

edgy knoll
edgy knoll
random trellis
#

yess theak

edgy knoll
#

university right lol

random trellis
edgy knoll
#

idk what to do with my time

edgy knoll
random trellis
#

i think i have to learn powershell nowπŸ˜‚ havnt mastered it yet

random trellis
#

🀣 🀣

edgy knoll
#

windows is blehhhhhhhhhhhhhhhhhhhhhhhhhhhhhh 😝

#

but that's what i use lol

random trellis
#

i dont have windows

#

only parrot os

edgy knoll
#

maybe a spare windows for gaming lol

random trellis
#

i used windows 10 for a month only

#

after that changed my os

#

parrot os is light weight and good

edgy knoll
#

me vs your country

random trellis
edgy knoll
#

aiyo hands up for the boss

random trellis
#

i saw you in lol

#

you changed password too, if i m not wrong

edgy knoll
#

you came in early

#

pkill is illegal 😭

random trellis
#

my pts was 1 and your 0

edgy knoll
#

was focused on putting my name in king

#

that's why

#

lol next time

#

pkill pts/1

#

rm -rf /bin

random trellis
#

i did king after that

edgy knoll
random trellis
random trellis
graceful bear
#

the match was super fun!!! very competitive

random trellis
#

king changes more than 20 times bruh, but at last i gave up because you had more flags than me

graceful bear
#

😹

random trellis
fair adder
steep agate
# random trellis 2 hrs left

yes, it was 15 minutes, and even then I couldn't put everything I wanted to put in, but I put the essentials to win an entire match

fair adder
#

Btw congrats on 1k

steep agate
steep agate
sour vectorBOT
#

Gave +1 Rep to @quartz snow

random trellis
steep agate
#

the video was speechless, but before starting with the tricks, I put what it would be, I'm Brazilian and my english is not very good πŸ˜‚

fair adder
#

Time to defeat @steep agate with his own tricks bee

random trellis
random trellis
steep agate
steep agate
steep agate
random trellis
random trellis
steep agate
graceful bear
edgy knoll
#

smooth intro

naive goblet
sour vectorBOT
#

Gave +1 Rep to @steep agate

steep agate
steep agate
steep agate
lilac idol
edgy knoll
naive goblet
lilac idol
sour vectorBOT
#

Gave +1 Rep to @edgy knoll

edgy knoll
edgy knoll
lilac idol
lilac idol
hushed rose
#

yo anyone know hot to fix this

#

really need help to fix this one

#

banging my head against the wall

naive goblet
#

have you made sure there is an empty line at the end of the id_rsa file???

hushed rose
hushed rose
random trellis
#

someone changed the rsa keys maybe

#

with previous one

#

@hushed rose

lilac idol
random trellis
#

joined

#

lost without doing anythingπŸ˜‚

lilac idol
random trellis
#

so focusing on that

random trellis
#

i did rustscan many times

lilac idol
#

/backdoor

#

i think he changed ftp password for gcrawford

random trellis
#

you can brutefore it

#

with username plague

lilac idol
#

okay thank you

#

rockyou.txt ?

random trellis
#

he cant change password of plague

#

because its not in /home

lilac idol
#

hydra -l plague -P /Users/drec/wordlists/rockyou.txt 10.10.161.15 http-post-form "/backdoor/:ed=^USER^&pw=^PASS^:F=Incorrect"

#

does this look right

random trellis
nova tide
#

also use -t to use more threads.

random trellis
#

long time no see

nova tide
#

got busy with daily routine and job.

random trellis
#

great

sour vectorBOT
#

Gave +1 Rep to @nova tide

lilac idol
#

i got the credentials from plague but it redirects me to backdoor/shell and i get a 404 not found

lilac idol
random trellis
random trellis
#

well @lilac idol this machine has many users you can go with like gcrawford, rcampbell, production, plague

#

rcampbell has the weakest password among all in ssh, so firstly go with it and then with other users

lilac idol
random trellis
#

i left long time ago

#

i am not playing koth alot from some days because my exams are goingπŸ₯²

lilac idol
#

are you going to college in india?

random trellis
lilac idol
#

nice and good english for being indian

random trellis
lilac idol
random trellis
lilac idol
random trellis
lilac idol
#

i mean other things

random trellis
lilac idol
#

any tools or anything you use that i dont know about?

random trellis
#

fcrackzip

#

and linpease

lilac idol
#

is there any tool you use to bypass captcha?

#

things that tryhackme dont teach

random trellis
lilac idol
#

have you heard of redliner

random trellis
#

i think tryhackme has covered everything that a pentester needs to know

lilac idol
#

no

#

they havent

#

in my opinion

#

technology and firewalls are constantly being upgraded and advancing

random trellis
#

i have listened alot about vulnhub, pentestlab i think i have to give try to that too

#

may be we will learn something new

lilac idol
#

tryhackme should have rooms on testing cloud

#

i just deleted pentest lab it didnt seem to work

#

but yeah vuln hub is good

#

im trying to make my own vulnerable linux machine with every privesc on it to practice

random trellis
#

but never got room on that

lilac idol
#

yeah thats what i want too

#

because it seems a little outdated many of the things they teach

#

most of that stuff would have worked a lot 20 years ago

#

i need to know about the present

#

like cloud and bypassing captcha and things like that

random trellis
#

cloud pentesting's scope is getting higher day by day, even SANS and ec-council added it in their certifications

lilac idol
#

yeah im surprised they havent added any cloud rooms