#koth
1 messages Β· Page 73 of 1
yea hey, i just want to have fun
You set it yourself in your profile
Near the bottom i think
It's mostly just a guide afaik
So can set it whatever you want
Cool
Np
some people are cheating like in the first 2 minutes they have 4 flags
Pretty easy to remember where to go on most boxes, that's not too crazy
King and all flags in 10-30s is probably autopwn lol
After playing a few times
And flags don't change π
@fossil pecan shall weπΉ
π
you join?
im still afk on the phone
still have like 5-6 min, right?
oh dang u already king
lol
i'll be right there π
yeah
get here quick!!!

π
and you kept sending nyancat my way
π β€οΈ
I think I'll stream the next one (or two ... or three π )
https://f11snipe.live
annoying bosses are online
?
lol he's just joking around
haha who did the nyan cat thing gj
π β€οΈ
Hit me up as well if you guys play another game
starts in 23min
that is a long time
this one is already going ... i'll pause my king if you wanna jump in
well good things take time to get build
how much time in the game?
oh im in that game didnt even notice
14, 22min left
okay lets goooo
so can be taken if in 6min π
ah, this was a new way to get in, had it in notes, tried it for the first time
king isn't showing up ?
whawt
okay got it
Hey
@stiff egret how are you bro?
Hi, I am great,. just chilling, how are you?
I was doing some tests, weekdays it's complicated for me to play CTF because I get very busy, school, work, gym, course, etc.
@fossil pecan you on the game or left?
but i am fine
yes, understandable, I can relate with that
basically you run a command in another terminal
Yeah., I assumed
π€£
I was addicted to koth, now there are more people addicted
been there, done that
a friend of the team that I participate, is creating a tool that you can do this, only much more improved
yeah
the thing is, the tool is awesome, but if you have to transfer it over to target machine to run, then it means it will be in the hands of opponents too
and they can reverse it/ find a way to block it
yes this is true, but if this is to happen, it would be cool to put it in a directory that almost no one accesses
Nice snag! I stepped away for a few, but was kinda cheering for your comeback π
you know you can really monitor files coming in and executing, I mean the people who are able to do that would be less, but it is def findable if the person is monitoring the traffic
I was thinking about it, there was no resistence at all
manipulating bytes of a file
I assume all regular footholds were blocked already
idk, i don't usually block anything
generally the passwords were changed so
pspy does it
^
that much I checked, then went with one very unusual method, I've had it noted down but haven't used that in ages
if yall wanna chill hope in vc (my mic broken)
I'm broadcasting my screen
Testing bypass in XDR
and edr
and listening to some rave electronics
I can come join in a few
ok nice
Close game π
haha you good mate
damn
Hey guys i would like to try koth for the first time , any beginner here would like to create a game ?
You can join any online public game. Game will start if there are atleast 2 people available in the lobby.
Here is the link for a game that will start in 20 minutes: https://tryhackme.com/games/koth/join/7823293fddfd816a6d04cb96
Moreover, i recommend reading the rules and blogpost about KoTH.
!docs koth
Awesome i will have a read ! Cheers !!
haha gj whoever got in first
GG!
haha i restarted sshd cuz i saw that too
still not working?
i can ssh ...
π€·ββοΈ
@steep agate ^
π
yeah
the windows machines of koth is very fun
ya I need to keep working on those haha
getting alittle better, but still feel so lost on windows cmd/pwsh π
I understand
@night sierra nice game π
hey Snipe
how's it going today?
good boss, how about you?
doing well!
getting workday going, playing a lil koth on the side lol π
what are you up to?
just busy with some work, I'll play later on.
@fossil pecan are you in a game at the moment?
in 2 π
another starts in 5min
haha I'll hop in one of them
36min left of lion:
https://tryhackme.com/games/koth/join/5b532dc7d1f5ecbb79e4a97d
empty scores sofar
I'm on lion haha
Oh my
@fossil pecan i thought you'd be a king by now
I'm just chilling and coaching today π
I'm AFK now haha
Coming back now
Are you in?
yea I am still looking for a way in on that mysql
i found LFI on http 5555 π
nice
king has been unlocked π
haha
you were still finishing the other one
I'm trying to find a way to get into ssh, because I hit a dead point with the web server
Here's a fitting riddle for this box....
The way to SSH is thru FTP π
thought about π
Im trying to figure out how to access FTP if port 21 is closed ?
@swift laurel need to scan more ports ... 22 + 9999 and 4 more open ports π
food game starting now
https://tryhackme.com/games/koth/join/c97e1ba03722994e64b37e84
ooo
hackers
kinda fun one
gotta brute force all entries i think ...
after some initial recon***
Good morning all !!
great game! π
!docs verify
Sweet!
ya
Gg
Good morning everyone !
hey guys, anyone wanna play?
you still playing scully?
let's create a game, if there's no public ones
ok
GG @fossil pecan
Ya! That was a good one π
anyone up for koth? https://tryhackme.com/games/koth/join/b4edde2395cf4edfd8b6f453
yup
i think it is a problem with ssh
i found the user and password but doesnt work
@jovial field
i dont think so
are you sure ?
oh really ?
maybe
hmma
did you change the password ? :)))
@jovial field after this match, you will want to play another match ?
yes
why?
ok
then just lookup some services
you could for example try to bruteforce the ftp service with the given users like tyche
or amechania
Anyone playing rn?
YES
anyone playin?
Hi
hey! how's it going?
just hanging out, getting ready for work ... and playing a couple koth games π
you playing?
At the moment, no
@fossil pecan did you find any flag?
in the Shrek machine(koth)
i can't find any flag inside the /home directory
is it kind of cheating????
it is not named user.txt then???
Ya each user should have one
^
Try looking inside each user directory, you might find some.
I did that
who's online
ya! in queue, next in 17min here
https://tryhackme.com/games/koth/join/137642dbfb6dabb751999315
Ayy i am travelling, but let's see as long as the laptop battery lives imma attack that king.txt!
See you in terminal! (:
yay!
You in game? @fossil pecan
oh ya, just watching π
doing some enum + recon
@stiff egret getting some fun things setup π
Ay man
Just left the box, dropped the king setup and laptop is on 50 %
So saving some battery now
ππ it'll be fun, tho it only sends revs to my box, so unless you reverse it and change the IP, it's gonna make me king and send me shells everytime you use it π
Damn, gg @fossil pecan that was one hell of a game
that was awesome! was sweating haha
I swear my co travellers think I was hacking something illegal, it's 2 AM here and I am in a public bus

hahaha
@stiff egret i'm having so much fun with these koth games! ... i know it's kinda taboo haha, but about new boxes ... i have a lot of fun + cool ideas, and would love to chat with someone about possibly helping to build out some new koth boxes in my spare time π
are you the person for me to talk to? if not, can you point me in the right direction? β€οΈ
Generally Skidy would be the person to go to for that. There are 4 indev boxes with me, but I am just not able to cut out time to QA test them and push to Skidy
shoot a msg to them, obv rule of thumb ask for DM first.
reset
pls
broken
u sure ?
Starting in a minute
Starting in 20 minutes, depending on how fast people join in so
15 minutes out, gods it takes forever to start.
π
ayy, gonna be fun!
lemme see if @placid fable is up, π
Not the saturday morning I wanted, but gotta say this is hopefully gonna be fun, as long as it isn't Hogwarts./ or windows in general

lol
β οΈ
O.o
man I am not on system, just about to get back, went to get waterbottle
looks like holmes brought the same kit as last time π
reverse and it;s yours (:
i''ve already got a copy π .. but building my own too π
shell killer?
haha ya just any stable ones at least
nice but you didn't change the ssh password,
just logged back in
kick the people out and close the doors too
im just observing

10.17.1.8 who is this guy, just killed his shell

lool
nice, who's done this neat trick?
was testing something for king, now lagging soo hard most cmds hang forever lol ...
yep, people spawning a bunch of processes trying to overwrite the king file
damn, machine is hella slow
Holmes is legendary I couldnβt even touch king.txt
One hell of a Saturday Morning (: β€οΈ
Bro dass meπ
Was hella fun π€© ππΌ
def π
Oh, sorry. Have been busy lately.
Moreover, I haven't played any KoTH for a while, so hands aren't prepared well enough to go against Holmesπ
I wonder if it worked correctly. Like me and you having the same terminal window size (rows, columns) or else it would just show glitchy
It used to work perfectly for me, maybe we do have the same terminal sizes π
Maybe, oh I could have read your size first. stty -F /path/to/tty is it?π€
Anyway, it was fun π
Hasn't Mathew updated his?
Ahem, more boxes..ahem Holmes and Naughty

HMU if anyone plays in a while
hmu
https://tryhackme.com/games/koth/join/9557fef9d09499392000bf13
Starting in 21, depending on when you join in.
it's gonna be a bloodbath
I don't know who JohnHelarry is, but I do feel bad for them.
power went out here, so I'm out too
ah shit, tc.
welllll, I have mobile data tho
another match then?
Hogwarts or Windows and I click on leave game button
it's just dumb to try to fight with a knife if you don't know which side is blade
lol I told you, Hogwarts for unfair advantage
and windows because I believe KoTH is for when you know your way around the machine well enough to defend it. And I simply am not that good at windows. So
.
well, how are you gonna get with windows if you straight up give all the time
exactly, so when I said KoTH is for advanced level, that means I am learning on basic level, I just haven't reached the point yet.
I don't believe in the way of jumping in the river and learning while drowning
so I'd rather learn first which side is blade.
(though I must admit I learned linux that way only)

just jump into it, most that happens is we laught at your inadequesies

and mattew is king already
fair enough, I think I will at one point, and now that I will have more time to work on my skillls from this week, I will be able to jump in.
They are good at it. And, well, clearly better at windows than I am. GG
I mean, you guys have done more than 200 games, it should be easy at that point
Man, it's been over 2 years, since KoTH was launched.
Very few of the people who were there when it was launched are here anymore, or even play KoTH anymore.

it is, very.
keeping in mind that for more than one year, there was just one machine with Windows OS in pool.
maybe cuz the're more resource heavy to run and not that popular either
Yes, plus devving a windows machine is comparatively not very dev friendly. At least for KoTH. Where we have to add 4:4 foothold:privesc in the machine.
lol
prolly should've left and kept my dignity
Personally speaking, attacking and gaining admin in windows is not an issue for me, it is the defending in Windows where I lack behind.
That is also, generally, the area which requires a better understanding of the OS to gain expertise in.
well, I've got a user shell so π€
ay, best of luck! (:
Anyone playing?
6 in queue here
game in 5min
^
Ty for the ping. My vm decided to nuke itself and Iβm to lazy to reimage it so imma sit this one out
tag me if any match about to start, wanna do a game
starting in 5 minutes
**!**me
what a game! good one for me to end on haha , need to sleep π
Is it allowed to forward the traffic on the Box from Port 9999 aka. The koth service to an own service and send the own name?
You are not allowed to interfere with the KoTH service
ok
Also specified in the rules, i would recommend reading rules as well:
Yeah i know i thought it could be allowed because you are not actually touching the service
....
anyone up for koth? https://tryhackme.com/games/koth/join/21c4fb5dd923e4823f2fbc70
(ca. 24min)
im baaaaaaaaaaaaaaaaaaaaaaack
hell
any play
windows is pretty cool, on windows i like to test AV/EDR/XDR, it's a really cool subject
.ps1 scripts, powershell tricks
Hello
Hello
@fossil pecan ESEY
would it be unfair to change an ssh password for user in koth
its fair

i hate carnage!
I am finally in but cant escalate to root
π¦
This will literally take two or more matches until i master this machine
@tranquil pewter
anyone wanna play koth? starting soon
you left?
no, i got beat by you xD
anyone wanna play a game?
π€
@cursive ether
alright joining now
ok
3 more minutes to go
GG
was a bit late
but finally rooted carnage
@steep agate you have a shell?
no
that's not how you patch lmao
I just fixed the backdoor, removed the .ssh, changed the passwords, and patched port 3000
π€·ββοΈ
counts as machine broken. If you wanna reset or just stay alone in machine where whole sytem is chmod.
huh?
just no simple command injection, backdoor port, remove .ssh keys, and change passwords
We are literally discussing it in koth staff who broke the rules and asking you as only you seem to have the shell..
smh
oh
but it wasn't me, if you want I'll send you more evidence
enjoy the free win. Just patch the things the way they are supposed to be. Whole system have already been chmod.
nah its fine
GG's
there was someone using while with pts kill, but I ended these processes
i have that in koth staff π
mind wanna check the permissions on bash binary?
someone must have changed the apache settings
yes
I have a clear conscience, it wasn't me
and I wasn't even supposed to be in this match, I joined for fun
^
as well ? I'm using google translate, did you mean
you mean to put things back?
lol
just went into the backdoor that no one had fixed, got the id_rsa from bunny, escalated privileges, kikei all shells, fixed port 3000 first, then the backdoor, then removed the .ssh keys and changed the passwords as shown in my screenshots terminal
If anyone else sees someone breaking rules again like happened in this game please report at koth@tryhackme.com
- chmod whole machine
- closing ports (61432)
lol, so backdoors can't be fixed?
Alright, not what I expected to read on a Sunday morning one hour after I woke up.
So, MatheuZ, clearly there is a communication gap here as you mentioned using gtranslate. That is fair.
About the rules, someone, broke the machine, by essentially braking chmod permissions in it for almost everything.
And the person with the active shell is bound to be blamed.
You do not kill a service to fix it.
yes someone broke but it wasn't me, i entered the shell later
I don't understand what is the hype of winning a game, it's about enjoying it. Whoever it is in the game right now and is breaking the rules.
I'd suggest please read the rules first, because for precaution, we will send out a warning to all users in this game. Please be aware of what you(all users in the game ) do when you are playing a public match.
I was in a DM with the @random trellis
if you want I can show you more evidence, I really wasn't the one who took the permissions from port 80
I do not have a shell and nor am I on my system right now to monitor anything. I am just saying as a general precautionary measure to you all that please read the rules, understand the difference between patching and basically breaking the machine.
This is supposed to be a stimulated environment for how you tackle real life attacks, and killing all pts is just a dumb and the type of move that will get you kicked out of a job in industry.
As I said, I am not on system right now to actually verify any evidence. Thank you for cooperation.
Gave +1 Rep to @steep agate
Public game starting in 19 minutes:
https://tryhackme.com/games/koth/join/ddb43ca006e4b22d7ad6092a
kill process and pts itself is stupid, when you hide in the machine, or you already have rootkit + persistence and you already have your C2 prepared, but since it's koth, the goal is to stay in king
Posting this again here, so incase someone can't find the rules page, can read these here and ask if you have any doubts.
right, I have a clear conscience, if I need it I'm willing to help with anything π
COUGH COUGH @random trellis - remember what I said the other day about chmod -R / ?? ... ya, not a good result π
I mean how hard can it be to understand rule 8?
I just won the match out of honesty... but I understand anyway, you guys are employees and you do a great job, that's right! good work, thanks but still, thanks for the game, space jam is really an interesting machine
have a great morning/afternoon/evening, if you need anything you can call me π
Edit: not employees, just volunteers. Again I am guessing that is another gtranslate gimmick.
i used chmod -R a+x /root just because the root folder was locked and i thought a+x is used to permissions
i havnt closed any port, i tried to login with 61432 port but @steep agate fixed it
and the pkill i used just because someone removed command injection from port 3000
@nova tide also sent me nyncat and breaked my shell in KOTH whats about that
is it not against rules?
@random trellis
Give the rules a read. Breaking shell/killing shell is not against the rules. But setting a while loop to do that is just. Well.
i am sorry for that, i used while loop but that gave me an error, i havnt cheated trust me, even i was asking matheu that command injection is closed and there was port 61432 that is not working
so i quit the game
see this bro
As I said before, since we do not have any enough evidence against anyone, we just warned everyone in that game for rule check. Other than that, all the best for future games and just keep an eye out for rules.
It's a game in the end and playing by the rules is the only way it can be entertaining.
I mean imagine if no one can get a shell at all, then what's the fun in that?
okk bro i was just gone afraid to get my account banned
the port 3000 I had fixed, the port that had a backdoor too, but someone had used chmod on port 80 and no one knows until now
there were several "whiles" of kill pts running in the background
That, I know, were from RamghariaSaab.
About chmod, we have no clue who did that, tho F11 did pointed out that RamghariaSaab had a conversation about that.
This chapter is closed now.
the chmod f11snipe was talking about, that was a match betwee us when f11snipe locked the king i used chmod -R a+x /root; chmod -R a+x /root/king.txt, and then i asked f11snipe about it and he told me that it doesnt unlock it , it will break it
Use chattr
@stiff egret how to take action against someone who resets the machine for no reason
after no one can take it king or they can't get access after fixing the box they just click reset, don't test other methods to gain access... π€£
true
Honest answer, there's no action against dumbess in rules.
It's just that people are dumb and irritating who doesn't value the game who go ahead and reset uselessly. Best case, stop playing with them. If they spamming a lot, then report with game IDs and whatever evidence you can gather on koth@tryhackme.com
okk bro thanks
Gave +1 Rep to @stiff egret
did someone delete the user folders out of the home dir?
there is only the folder i created left
i guess we should reset the machine
WTF
nearly 30 mins of king that is a huge amount of time to be king
probably have done the box before if they can do it that quickly
I don't think you noticed, I'm not even in the game, I joined as a spectator and I can see the IP of the machine
oh haha
π€£ π€£ Wtf brrrooo
now wonder if that is a bug
too π
could always send it as a report in #site-bugs if it is
or even if it is not and see what the response is
hey everyone, does anyone know how I can spectate KOTH games? the THM link just takes me to the game page. (unless that's considered the spectating?)
oh nvm it says there's a spectator link to share hmm...
Some people join koth-vc while playing KoTH and some also like to screenshare so others can learn/see what they are doing. Other than that there isn't much of a spectating option on site except for viewing the scoreboard.
ooo okay ty! will check that out
Ik f11snipe would play in vc now there isnβt many people that join vc for koth tho
it happened with me too 2 days ago, I was spectating @tranquil pewter match of offline machine and was able to see the machine i.p π€£
WTFFFFF π€£ π€£
You should have hopped on. See if taking King would get you listed. Haha
i tried it once in a private match, but it doesnt work
I see. That's cool to know. Haha
It's an active and already reported bug on the site that reveals the IP of the game you are spectating.
Asked in #general a few days back, but it got buried before I could get an answer
Considering playing some KoTH with friends, suggestion on the easiest KoTH box to start with (since we haven't worked the whole defending side yet)?
Spacejam (the easiest out of the following), Panda & Food is pretty nice to play. Food is also available as a room on THM, so you can get some practice in
Shrek too, I think.
I need to get onto KoTH myself πͺ I haven't played it outside of the internal beta testing & with colleagues once or twice

oh
i understand
π
π
π
hello, the hogwarts machine does not have king.txt?
blame @stiff egret π
of course
I saw that I didn't have king.txt, so I created one, is it against the rules? I can correct
No, it is okay to create /root/king.txt in Hogwarts.
As by default, there isn't one in there.
I understand, it makes sense. "Feature" π
Thanks, I was afraid to break some rule as I couldn't find a king.txt. Thank you anyway
Lol guys be hitting reset without any reason
they dont try to find any new way and just hit reset π€£
hahahaha thanks bro
Gave +1 Rep to @radiant sun
anyone want to do a KOTH? im new to those kind of games and want to try it out
Yea kk
i want to report a child
koth@tryhackme.com :)
be sure to include proof, screenshots etc.,
okay
lol bro you were the one messing up with ssh conf file
@radiant sun is absloutely right
we have proof @edgy knoll
you messed with sshd_config
If you have proof, submit it to the Staff and leave it to them.
Not that I'm a mod or anything.
wtf bro
why there is no SSH in this machine
which machine is that
lol, lion
?
lion
why would you send that audio message
because im angry asf
then who deleted half of sshd_config data
who are you talking about
oh, okay sorry then bro my bad we misunderstood
@random trellis really reporting while i didnt even play
nah i reported
did i win
nah
did i even play
idk
okay calm down, i'll take back the report
is not on attackbox
next time actually check I'm sure there were other guys in the game why think it's me
and I didn't win
no comments
π
@radiant sun reporting
not me
sorry bro @edgy knoll
while i was busy with you
now we have too many proofs we can report him
yea seeing the other guy is lvl 3 i didn't thought he could change the conf file too
but who knows you made him king, just saying no offenseπ
so , im not reporting anyone right now
but i'll make sure to collect every proof from next time
yeah you know i was level 1 too right
when i started beating up losers ;like u
same here, changing ports are allowed but stopping services is cringe
π
they reset dummy
Bye i'm going to spam resets
they started it π₯±
Tracklist: http://1001.tl/2360fxj9
Live Today, Love Tomorrow, Unite Forever,...
www.tomorrowland.com
anyone to play ?
`
π€
wait
less gooo
If anyone starts any match and need a player, ping me too. Around here for a while
If Mr. Holmes joins, it becomes King of the Holmes π
Hi.
@random trellis you're very good man
Hi.
Hi
but i lostπ₯²
i had all flags, but havnt submitted because i knew that i am going to lost this match nowπ€£
even so, that was close π
we will see now
Alright done with it people @nova tide @prisma roost @near lily
Give em kids permission to tag and watch them go berserk

you won again bro, i came late too kingπ₯²
I was just wondering if it's ok to share your KoTH notes.
bro i almost lost π
Since you asked politely, what part of them?
Alright, imma public my backdoor system/payload gen thingy as soon as I get my next job

That will, also, almost break all public matches from thereafter tho
honestly, if it's public people will come up with fixes for it
It will either kill KoTH to boring level or will make it super exciting
like just find stuff it needs for basic functionally and make your own script to kill it
Yes
That's basically what me and Naughty did for hours to almost everything there is publicly for KoTH
Hmm this got exciting
Feeling like an iceberg, might hit a Titanic and public the notes tonight lol
@nova tide what say?
just pgrep -a sh | xargs kill

LoooooooL
I remember when I once posted that
And someone used it
And said
Burh it killed my own shell wtf

Someone asked for some tips on KoTH and I thought your github was simple enough for them to understand, and then build on their own.
Fair enough, that repo is history tbh, just direct methods to root of some machines.
It do, tho, gives them an idea about what they should do. But not much
Yeah, @random trellis I don't know what it was, but it seems to be working fine right now.
Just tried joining a game on phone
what's up peopless?!? anyone playing today?
i was gone afraid thought i am the only one getting 404 error
Gods I wish the cloudflare would let my bot go through, that way I'll be able to print out a leaderboard of who's spamming the matches with bots or alt accounts. And the frequency analysis will also tell a great deal about it.
smh
@grand ember how the hell
did you join the vc exact same second
szy#bot confirmed
i joined like a minute after you lol
@stiff egret i was outside and just came and saw you were in the match and kingπ₯² , I was trying for king but gone kickedπ€£
ohh so you changed port once again
ah, I am not in the game/VM/
i am going king rn with 30 mins timingπ
oh GG lol When you said you were kicked etc, I left the game thinking no one is playing anymore
I don't remember there being a flag on /flag
π€
there was i guess
I could be wrong tho, will have to check notes and I am off the desk now so
π lol
Example of overriding settings on a per-user basis
#Match User anoncvs
X11Forwarding no
AllowTcpForwarding no
PermitTTY no
ForceCommand cvs server
DenyUsers ftp
Port 65534
i found it so rejoined

there was flag at ip/flag that was double encrypted with hexadecimal and base 64
Sounds like you need to chat to Skidy
Neither of those are encryption
I am thinking of maybe getting one aws IP whitelisted if he will. Then can use that with openvpn
@fair meteor lol cant you play a fair match instead of kicking and resetting machine
π π
lol am serious
i know hw to do it but i tried it on production machine and i enter using skidy
@steep agate u removed that youtube content
but after getting root and i use chattr its saying
on kind of thing ion what it is
that is an intended troll
@stiff egret
jasper05 is closing services
several friends of mine are complaining about jasper05, because it is using autopwn, and it is closing the services
Do I report here?
Drop an email with whatever evidences you have, (from your friends as well) to koth@tryhackme.com
right
so we have something in the lines incase needed. Discord chats are not preferred way to report
I'll send
Thanks
ok, I'll send it to the email, it's not the first, second or third person who comes to my DM to complain about jasper, who is closing all services and using autopwn, deleting pages
report sent
lol he just killed ssh π€£
Now that I've gained access to the machine, I'll get more evidence and send you holmes
it actually stopped the ssh service π€£
more evidence about jasper5, sent by email sir holmes, now it is proven that he play dirty in koth xD
there are many players who are trying to report jasper5, yesterday in h1 easy he edited port 8002 webpage, but after that when i got root from port 8000 he stopped every service of the machine, i was getting only errors for opening webpages
yes, the same thing happened to me, he stops all services
chattr in production machine dont work, so i used my own chattr
@random trellis oh thanks so u uploaded it from ur machine
Gave +1 Rep to @random trellis
but when i do that it shows me error
i also tried using chmod +x chattr but still i keep getting error
@fair meteor download busy box chattr from here
https://busybox.net/downloads/binaries/1.31.0-i686-uclibc/
okay thanks
Is there anyone who would like to do a king of the hill H1:Easy ?
sure
here everything is normal bro, and I just killed the pts, when you entered the machine
hint:- in smbclient you will get password of another user
i hope you left tigress door for themπ€£
hahahah it's been open so far, but it only enters through the writeups path...
he*
relax buddy, it's just a game, why do you take it so seriously? i was playing watch dogs while i was playing this machine π€£
and I just fixed the .ssh and the shifu password, you didn't even try other methods to enter
and there's still another backdoor
are you seeing? that's why people get irritated, don't try another way to get into the machine, it's always the same....
I'm not even in the machine anymore, it's already gone, now I'm raising my C2
every machine have atleast 3 doors, and its written in the KOTH description too
yes, but many don't try any other way and come all irritated π€£
youtube videos machine koth... π
π₯²
@jovial field it was a good match in H1 easy
i hope you are not the one who clicked on reset when i fixed the crontabπ
yeah was afk after the middle of the match but was a good game
doing a new match now: https://tryhackme.com/games/koth/join/f4da8715441ea9bd7e173a1c
Helloπ
I'm up for an H1: easy koth
Whoever is playing Koth rn I'm so sorry for continously kicking you off π but it was so funny
@junior pulsar Bro I'm sorry ππ
No problem i do it sometimes XD 

ππOng
Ahh that's no fun
user infodarms.ch created a file king2.txt in /root with his nick. lmao π π π π
did it work???
no, I just thought it was funny
lol
π€£ π€£ π€£ π€£
Its funny but it also happens when we try to edit read-only file with vim, sometimes it creates a new file instead of editing itπ
@random trellis damn, are you in two koth and leading with 15 flags at the same time? Geez, nothing gets past some of you here π
is using hydra allowed for koth?
Yes, there are a few rooms where you need brute forcing.
Interesting, I thought brute forcing was a cheap tactic to get into a room. Are you sure you have to brute force to get those few rooms? I thought there is a way to get in every room through existing vulnerabilities or random clues.
There are multiple ways to get foothold and brute forcing passwords could be one as well.
I see. Thank you!
Gave +1 Rep to @nova tide
wtf, I'm not even in the game, why am i able to see the ip of the machine? π
This bug is reported and i thought its fixed now, but it is still hereπ
seems like someone might have deleted it.
@haughty turtle Please avoid posting direct solutions or spoilers in chat. (in this case, locations of all flags. )
sorry didn't know that
is it allowed to delete flag like that?
its not.
thank you good to know
Gave +1 Rep to @nova tide
@stiff egret why........your riddles hogwarts..........so hard to decrypt π
@random trellis π€£ π€£
π€£
@steep agate yesterday i did curl I.P:22 in hogwarts and found there is a webpage at port 22, but my browser was not allowing to access, was getting restrictionsπ₯²
and also found a sql vuln page, when i logged in it was all black screenπ€£
i think if i change my browser maybe next time i will understand them
this must be me for sure
and i need a hint why this password is wrong
because its changedπ , he changed it for sure

Original PoemsΒ©οΈ in there
π
what is this letter guy?
G .... The word will be Glad may be
or if it was two G's it would have been Good Game
its flag lol, in h1 easy machine.. Its written in asciiπ€£
i was also confused first time that what it is, so at last i got that its a flag
I see the first interaction with Hogwarts machine?
@stiff egret i get full black screen after login here in hogwarts
i did hogwarts many times with neville but just trying to understand other doorsπ
there is login.php so maybe i need to run sqlmap
I am just gonna say what's the first thing we do when we see a webpage.
i was confused why the word is Gad cuz i didn't know there is a " l "
@random trellis i was doing the spacejam with u, can u tell me how to write into that king.txt or u patched it already?
and do u know how to revert the patch like make it vulnerable again?
i made that file to read only
you can make it writable again after removing the attributes
thanks, got user hermoineπ
Gave +1 Rep to @stiff egret
but when i do ls -la i see that it rw and how do i make it writable again?
cuz when i do lsattr it has the --ia--
i added attributes with chattr lol, not with chmod
exactly i used chattr +ai /root/king.txt
hahaha yess
ahh i see cuz i read about that tip as well but when i do chattr -i /root/king.txt it said chattr not exist
so i assume it got removed
i don't know the way to download it back as well lol
i was trying to wget it but i don't much about the executable file
i did chmod +x chattr that i got from machine
and that's it, that's all I got i stuck there
do u have youtube bro?
i wanna learn about this koth
hahaha no i dont have sorry
u should have one hehe u're good
anyway thank you for answering
Gave +1 Rep to @random trellis
ill prob ask more in the future
you can use this chattr
fot KOTH
thank you i'll learn more about this
Gave +1 Rep to @random trellis
lol the trick you and cybersloth use for stopping all services for a while is really dirty
π€£ π€£
lmao resetted machine for no reason
nope
thats a private game tho
poβ1000:1000::/home/po:/sbin/nologin
shifuβ1001:1001::/home/shifu:/sbin/nologin
tigress1002:1002::/home/tigress:/sbin/nologin
turned to no login
yup
he told you lol
forwarded
thats not cheating lol
aint specified in the rules
lets leave it, it was private game
can you use the in-browser kali for the KOTH or do you need to use your own machine?
anyone
Where can i access the in-browser from the KOTH page? or do i need to start it in a different room?
yess i saw
yes
π₯² '
yes
I think it was
yes i know all hogwarts entry points
how many are there are? i know only 3
and here comes the mystery, i'll let you find out hehehe
π€£ alright
anyone here want to do a koth?
if anyone wants to do a koth right now here is the link to join
The riddles for me @stiff egret π
Anyone want to do a koth
Whoever is down for a koth tourney dm me
you can send invite link here
I dont think they will let me send a sever inv we aren't starting today it's once we get over 16 competitors
i can understand bro but koth lobby allows only 10 members to play
ik it'll mainly be 1v1s
ohh nice
yea because if its 10 players at once itll be pretty annoying to play ngl
π€£ no its fun, i won alot of matches with full lobby
competating alot of people at once is eally fun
ight bet maybe i can get like 20 then run two full lobbies then the two remaining 1v1?
sounds good
was also thinking of something like this : "2v2 and the goal is to be the only team on the box at time limit and the goal is to annoy and kick the other team off as much as possible to win"
kicking?? you can fix the machine to stop other people
π π
you nayaned yourselfπ€£ ??
of course! gotta test all my commands before i try them in game π
hi
@fossil pecan @steep agate bro @inner nexus wants to talk with you
where?
wanna join my koth tourney? ramghariasaab said you were good :)
yes i would love to participate
fs im gonna send you the server in dms if you don't mind
Right





