#koth-voice-chat

1 messages Β· Page 2 of 1

reef canopy
#

I would lose connection to the VM every few minutes for about a minute at a time.

#

No error.

#

People kicked me out a couple times too haha

#

I think it's either my computer or my Internet

slim surge
#

@reef canopy have you tried regenerating a new openvpn config file.

reef canopy
#

I haven't. I'll try that today.

zinc totem
#

You might also need to killall openvpn too

#

I always do it for sanity check

reef canopy
#

Thanks for that tip too!

reef canopy
#

So, seems to be working on my desktop just fine! It was still connected to the VPN when I unlocked it... I think @zinc totem might be right about the multiple OpenVPN connections. Or it's just a weird problem with my laptop

austere ice
#

UNO and F11snipe why do kill the machine

sinful olive
#

look in #koth seems like the root user got deleted

austere ice
sinful olive
#

i am pretty sure f11snipe is not the one who did this

austere ice
ivory shore
#

was UN0, i was first to vote reset πŸ˜›

#

stole king after he killed machine, hopefully he'll learn a lesson eventually πŸ€”

austere ice
sly wadi
#

what happened guys

vapid storm
#

10 min

modest magnet
#

anyone in a pub room, im in with 2ppl are you in here

#

im in voice

ivory shore
sand anvil
#

@ivory shore

#

can you reconnect back to ssh? πŸ™‚

ivory shore
sand anvil
#

I asked because I kicked you from the session :)))

ivory shore
#

I usually don't use ssh or stable shells at all πŸ˜‰

#

oh but we're on hogwarts box now haha ... it's the only linux machine i think requires ssh entrypoint πŸ€”

#

"See you on the box!" πŸ˜„

sand anvil
#

but I changed :)))

ivory shore
#

i saw

sand anvil
#

I was nnyaned :)))

ivory shore
#

😘

sand anvil
#

wtf

#

Why I cant access king.txt

#

I mean, Im root

#

@ivory shore Can you teach me please

#

damn, do you changed the vim with nano kekw

ivory shore
sand anvil
#

one question

ivory shore
#

throws me off everytime haha

sand anvil
#

how If Im root I cant chmod or other commends?

#

I mean, even though Im root I cant have acces to some commands

#

for example now I cant edit king.txt

#

why?

#

Im root

ivory shore
#

chattr ? I also used ||a mount trick earlier|| (can check my YT, one of my recent vids went over it πŸ˜‰ )
https://f11snipe.live

sand anvil
#

Ok you used chatter, but why I cant use chattr to :))

ivory shore
#

i have quite a few king tricks haha ... my best one makes chattr irrelevant πŸ˜›

sand anvil
#

lol

#

and can you explain me what is the diff betwen chattr and chmod

ivory shore
sand anvil
#

aha ok

#

so, you say that the trick is presented on your youtube channel

ivory shore
#

ls -al will show all files and perms (from chmod)

lsattr will show all attributes on files (from chattr)

ivory shore
#

still gotta make more content! haha

sand anvil
#

very nice

#

so youre a nice hacker :))

#

I still need to learn

#

I think you probably have more experience

ivory shore
# sand anvil I think you probably have more experience

I have tons of "blue team" type experience haha, been doing systems/software engineering for a long time, but only tinkering in hacking until a few months ago (and I fell in love with KoTH haha)

So I still have lots to learn (especially for windows lol) ... but I know way too much about linux systems from sysadmin POV πŸ˜„

sand anvil
ivory shore
#

that looks good! I'm weird and prefer man page and textbook/whitepaper/RFC reading, stack overflow helps daily too πŸ˜† ... I can share more, but it's such a wide subject, best to start getting into more specific resources to learn what you want/need

here's a good blog series, learned everything I know about rootkits going through this (best with more advanced linux/system knowledge & experience in C)
https://xcellerator.github.io/posts/linux_rootkits_01/

sand anvil
#

thx

#

@ivory shore the nyancat troll image script is created by you or is from the room?

ivory shore
modest magnet
#

GG MatheuZSec

i couldn't get anything

#

I think that i needed to find something on the 8888 port with werkzeug

#

but i have no idea

lone shadow
#

@ivory shore any ideas on this koth?

raven valley
#

@ocean trellis Did you patch neville password?

dire fulcrum
#

ooh sorry seing this kinda late @raven valley

#

yeah but i returned the default pass after setting myself up:)

#

@proud frigate I've got issues , cant enter a new koth game, keeps saying un defined 😦

raven valley
#

cause I wasn't able to connect at all

#

and this hackers machine there is something wrong with it

#

I think

dire fulcrum
#

nope

#

just think deep πŸ™‚

dire fulcrum
dire fulcrum
raven valley
raven valley
raven valley
sly wadi
slim surge
#

@vapid storm u in h1medium?

vapid storm
#

ok no prob

#

sent me the link

slim surge
vapid storm
#

i have prob with my vpn

slim surge
#

we can run another one just let me know.. have you killed all previous openvpn connections

raven valley
slim surge
#

@raven valley you sent spectator link its the other link you want to send

raven valley
#

@slim surge

#

Aren't you already playing in the h1-medium?

slim surge
#

yea

#

i can play both

raven valley
#

Alright XD

slim surge
#

sometimes 3 at once

raven valley
#

Go easy on me

#

How do you manage though?

slim surge
#

ill be able to see once you put your name in king.txt and i can switch terminal tabs in order to take it over

#

like now hahah

#

😜

raven valley
#

I know for sure you didn't mess with port 3000 right?

#

but how do you bypass chattr?

iron lion
slim surge
#

lol was no loop running

iron lion
#

oh then it is easier

raven valley
#

It seems everyone who plays koth has their own rootkit/backdoor XD

#

I need to learn stuff like that

slim surge
#

watching 9999 on my terminal so i can see when you put your name into king and i switched it back before min was up

iron lion
#

if trapnat only ran chattr once you can just run the reverse command to remove the immutability and then change king

slim surge
#

hahah didnt even run chattr yet

#

and havent patched anything.....

#

all you have to do is echo "Chosey" > /root/king.txt

raven valley
#

Yeah I know

#

but you will keep on changing it lol

slim surge
#

do it...

#

thats how you learn tho

raven valley
#

Do what?

slim surge
#

you already took king

raven valley
#

That's not the problem lol

#

I took king yes

#

persisted as king no

slim surge
#

you know how to lock king?

raven valley
#

Nope

#

chattr I think

#

I used the wrong command and deleted the chattr binary

#

so no way of locking now

slim surge
#

your gonna need it now to unlock it...

iron lion
#

or just upload busybox in some hidden folder

raven valley
#

XDD

slim surge
#

lol

#

had too

raven valley
#

You gotta teach me

slim surge
#

lol

raven valley
#

Did it work on you XD

slim surge
#

yea

#

its still running ima kill it now

raven valley
#

I killed it already lol

#

anyways

#

how did you get root?

#

matter of fact how did you get bunny?

slim surge
#

i cracked her hash using john

#

im trap now lol

raven valley
#

where did you find her hash lol

slim surge
#

/etc/shadow

raven valley
#

tried that without the a

raven valley
#

damn so you had append mode only on it too

#

what are other ways better than chattr that could be "less detected"

#

cause

#

Idk

#

but it feels like chattr is so known

slim surge
#

you could mount root

#

here cp -r /root to a folder somewhere

#

lets just say /tmp/...

raven valley
#

and then mount root to somewhere else?

#

that makes the folder read only

#

until someone finds that folder right?

#

can't you just use the find command on the king.txt?

slim surge
#

watch... you have king now ill show you what it looks like

#

cd to root and ls -la

#

try to write to king

raven valley
#

oh

slim surge
#

to umount it umount -l /root

#

now write your name to king

raven valley
#

didn't you mount /tmp/... to /root?

#

shouldn't stuff in /tmp/... be read only on /root?

#

or did you create a new folder?

slim surge
#

nope i made a differnet folder with just king.txt inside

raven valley
#

oh

slim surge
#

if your trying to be sneaky you can copy all of root and then mount it and it would have all files that was in root so its not so noticable

raven valley
#

I'm sorry but what exactly did that do again?

slim surge
#

ok if your running it .. its going to copy all file of root to /tmp/...

raven valley
slim surge
#

yea

raven valley
slim surge
#

dont need to know which folder is mounted

#

then second part will mount /tmp/... to root

raven valley
#

I played vs someone before who made the king.txt hidden while not having a . in front of it and being able to cat it

#

do you manage to know how he did it

#

but that one had my name how was your name in /root/king.txt then?

slim surge
#

lol you see how even tho you have your name in king its still showing mine

raven valley
slim surge
#

thats a nice little trick

raven valley
#

true

#

how did you find bunny hash though?

#

did you access the machine first?

slim surge
#

cat /etc/shadow

raven valley
#

Yeah I know I meant how did you get into the machine

#

to get the hash

slim surge
#

couldve got in on 3000 before you patched.....

raven valley
#

Well after I patched you still got in

slim surge
#

lol i kno...

#

cat /etc/shadow and save to some notes... try to crack some hashes...

raven valley
#

Oh they don't change?

#

I thought they change every match

slim surge
#

some games passwords change, some dont... take notes on everything

raven valley
#

Gg

slim surge
#

gg

raven valley
#

Thanks btw def learnt alot from you today

slim surge
#

hope you learned something new... tipsfedora

raven valley
#

Unfortunately I got an exam in 7 hours so I gotta get some rest

#

I'm looking forward to playing with you more though when you are free

slim surge
#

ok just hit me up

raven valley
#

Shouldn't every machine have multiple ways in?

slim surge
#

yea they do.. at least 3 or 4 ways in

#

some are more sneakier than others

raven valley
slim surge
#

i got in with bunny.. you got in 3000.. you can get in with jordan..

#

there might be another way also .. still enumerating all the machines to find all the ways in

raven valley
#

yes but you need to have hacked it before to get in bunny or jordan I think XD

slim surge
#

lol yea i dumped all /etc/shadows into some notes to see which ones i could crack...

raven valley
slim surge
#

i dont patch the machines cuz i like trying to fight for king.

ivory shore
wicked rapids
#

i never played this

#

anyone who wants to play @ me

#

or dm me

untold needle
#

@ MatheuZ. GG

#

Hahaha

velvet rune
#

im new to KoTH this is my first game

icy swallow
#

i am new to this so you will obv win

#

after that

#

can you tell me what u did

#

or what u tried

#

@slim surge

#

ty in advance

#

❀️

slim surge
#

i dont know much about windows... we could run another one and you can practice if you want

slim surge
#

just create a private game with any box you want to practice on and send me the link ill join

icy swallow
#

ok ty

#

i cant ssh anything

#

i made sure i am connected to the config vpn

#

i can ping the machine and scan it with nmap

#

but i cant ssh to it whatever what

slim surge
#

like i said i dont know much about the windows boxes but i havent changed anyhing

icy swallow
#

its not just this one

#

any game i join

#

i run into the same problem

ivory shore
icy swallow
#

It's not bad creds when I enter the command it just keeps blinking until it says connection closed by host

ivory shore
#

Hmmm, ya sounds like VPN, network, firewall issue πŸ€”

raven valley
raven valley
#

@slim surge fgs

forest raptor
#

I'm lost lol.

raven valley
#

@slim surge Did you patch the cron?

#

why is it not working lol

slim surge
#

nope

raven valley
#

lol

slim surge
#

/bin/bash -p

raven valley
#

why-

#

Is this already there or did you enable it?

slim surge
#

i enabled it in the cron

#

along with a rev shell lol

forest raptor
#

I gave up lol. πŸ€¦β€β™‚οΈ

slim surge
#

did you run a namp scan?

raven valley
#

Why is my revshell not working then?

forest raptor
slim surge
#

did you find anything interesting on any of the ports

sharp olive
#

@oak coral why you delete flag?

#

it is forbidden to remove the flags

oak coral
#

i didnt

#

lmao

sharp olive
#

no xD you delete the flag

oak coral
#

no i did not ;)))

#

there s a way to get it back

#

my tty was getting spammed at first too

sharp olive
oak coral
#

nope this guy has king

#

he broke it

#

all commands are like gone now

sharp olive
oak coral
#

yep all commands are gone

#

shits not fun im leaving

sharp olive
#

it is normally forbidden

oak coral
#

isnt that against the rules anyway ?

sharp olive
#

yes

#

he can't do this

oak coral
#

well i hope the mods of koth do something

sharp olive
#

he close the port 9999

#

but its forbidden

oak coral
sharp olive
oak coral
sinful olive
#

gg @slim surge i was litterally pasting the last flag last second but included the cat command into my clipboard

slim surge
#

GG @sinful olive

clear turret
#

is there anyone who want to play koth with me?

rigid ember
#

@reef wadi

rigid ember
#

ifconfig

slim surge
#

GG Hack.You

vapid storm
vapid storm
tribal beacon
#

3

slim surge
#

starts in 15min

grizzled hinge
#

@slim surgehop in vc

slim surge
#

wassup

#

naw i didnt patch anything

#

join that other game lol

#

yea

#

im on production

#

lol

#

try port 80

#

yea u can still join it

#

ohhh your on production strive?

#

here easy entry

#

wassup

#

theres a spare in /tmp @short elbow

#

ssh -i id_rsa

#

yea you can kick ppl

#

go ahead

#

ill be back

#

here you can have king back lol

#

ftp

grizzled hinge
slim surge
#

nope

#

wassup

#

magic

grizzled hinge
#

so you nmaped it . figured out ssh and ftp is there. grabbed the id_rsa from ftp. sshed into it then naviagted till you fouind skidys folder then got the first flag

#

then what

slim surge
#

google

#

ight im out

#

✌️

grizzled hinge
#

System info

OS:

IP:

Hostname

DNS:

Web-Technology:

Programming language and frameworks:

Web server software:

Database software:?

SSH Server ?

Mail Server?

News Server: ?
Network File System?
Domain

USERS:

CREDENTIALS (ANY):

=========================================================================

Attack Vectors (To-Try List):

=========================================================================

NMAP RESULTS:

=========================================================================

Services Enumeration:

[+ Port enumeration/osint for all ports- further enumeration based on nmap/shodan]

Ie nc –nv portnumber

telnet IP portnumber

[ + NIKTO for web]

[ + WFUZZ/Feroxbuster/dirb web]

FILES: / (Web Root)

DIRECTORIES: / (Web Root)

=========================================================================

OTHER:

=========================================================================

Exploit :

Cves

=========================================================================

PRIV-ESC:

[+ enum4linux/winpeas/linpeas/evilwinrm]

=========================================================================

Take Away Concepts:

Scripts:

#

@zinc totem@vapid storm

lyric siren
#

Any contestants from the KOTH that finished 5mins ago (Machine: Food)?

static kayak
#

Hey @grizzled hinge
Do you remember who were there in today's voice chat

#

I by mistake cancelled his message request

#

Now I can't remember his name

#

Help me..

grizzled hinge
#

Unaware GU71 Kill Chain i think @static kayak

static kayak
#

Ha

#

GU71

#

Thanks bro

#

@grizzled hinge Thank you

brittle stirrupBOT
#

Gave +1 Rep to @grizzled hinge

static kayak
#

Ha

#

It's working

#

If you mention someone and say thank you the bot will give you one rep

#

Umm...

#

Strive can I get 1 rep back as payback

#

Just mention me and say thank you

grizzled hinge
#

@static kayak thank you

brittle stirrupBOT
#

Gave +1 Rep to @static kayak

grizzled hinge
#

just btw i dont think the rep points do much

static kayak
#

🀫

#

Ha

#

It's a point

slim surge
#

@static kayak you can also give rep points +rep

brittle stirrupBOT
#

Gave +1 Rep to @static kayak

slim surge
#

Hahaha

ivory shore
brittle stirrupBOT
#

Gave +1 Rep to @slim surge

slim surge
brittle stirrupBOT
#

Gave +1 Rep to @ivory shore

slim surge
#

Hahaha

#

Easy rep farming lol

sinful olive
brittle stirrupBOT
#

Gave +1 Rep to @slim surge

slim surge
brittle stirrupBOT
#

Gave +1 Rep to @sinful olive

past ember
#

y'all playing with free rep πŸ˜‚

ivory shore
brittle stirrupBOT
#

Gave +1 Rep to @past ember

past ember
#

πŸ˜‚

static kayak
#

@grizzled hinge +rep +rep

brittle stirrupBOT
#

Gave +1 Rep to @grizzled hinge

static kayak
#

πŸ˜…

untold needle
brittle stirrupBOT
#

Gave +1 Rep to @slim surge

slim surge
brittle stirrupBOT
#

Gave +1 Rep to @untold needle

sinful nest
#

+rep @brittle stirrup

frosty hedge
#

^^ @stoic quiver

stoic quiver
#

Please do not advertise unsanctioned giveaways in the discord

stoic quiver
slim surge
slim surge
#

@stoic quiver would it be ok to dm?

stoic quiver
slim surge
#

was wondering if the post was ok if it was changed to say tips and tricks instead of prizes...

#

just trying to get some more people playing

modest magnet
#

my nmap cans always stop at 99.75%!! what going on

neon river
#

Scan Harder

carmine mortar
#

Is it possible that someone just shut the ssh port down in production? It's either that or I'm filtered from ssh somehow

slim surge
#

@carmine mortar they might've changed the port.... did you try running another scan?

carmine mortar
#

I scanned a few more times but I don't remember other ports, might have missed them

atomic bramble
#

yo

ivory shore
fervent beacon
#

yall gave me that 1 min im appreciative KEKW

ivory shore
next forge
#

Hey guys! I’m new to the KOTH scene, this is my first game so be gentle lol

ivory shore
empty solar
latent bronze
faint reef
void monolith
#

Found my first flag but it won't submit 😭

#

Voice chat anyone?

ivory shore
proud frigateBOT
vapid storm
faint reef
empty solar
#

Hey @ivory shore πŸ˜„

fleet wren
#

gg @ivory shore

ivory shore
brittle stirrupBOT
#

Gave +1 Rep to @fleet wren

covert glacier
#

wow, its F11snipe

empty solar
#

haha πŸ™‚ @ivory shore

ivory shore
potent shoal
#

what is going on here

empty solar
#

Nothing, just a little bit of fun πŸ™‚

potent shoal
#

yes, you can't do anything without an ip haha

slim surge
#

@potent shoal might have to vote reset when that happens

#

Seen that happen a few times so far.. tried brute forcing flags to find out which box was running but that doesn’t work… only thing I’ve seen that works is resetting machine

potent shoal
#

yes quite possible, had also tried reset, but it was not voted on

languid peak
#

@potent shoal What is the entry point for running lab. I tried so much . Can you give a hint?

languid peak
#

yes

potent shoal
#

look at port 82^^

austere ice
potent shoal
austere ice
#

not a fair game

potent shoal
#

you ended up resetting it every 3 minutes ExcuseMeWtf

austere ice
potent shoal
#

because you couldn't get in after I changed the ssh password. for the same reason, I resetet

slim surge
#

There’s other ways to get on the machines besides ssh….

vital zinc
vital zinc
#

@ivory shore @slim surge well played!

karmic viper
#

having trouble decode the base64 found on 3333 anyone do it yet?

#

ahhhh i got it

slim surge
modern spire
#

Could someone put me through

#

It’s a different name when I cat king.txt from when I request it through 0.0.0.0:9999

#

I understand the service request for a certain file. But how does this work

sinful olive
modern spire
#

I don’t get it

#

Could you help me out here ?

#

there were two KOTH binaries and king files

#

@slim surge could I DM you?

slim surge
slim surge
slim surge
#

GG @drifting ridge @grave tulip

oak coral
#

@kindred dust do u want that win ?

#

im just messing with scripts , so i dont mind

kindred dust
#

Thank you bro but I leave the game a long time ago

#

@oak coral

oak coral
#

ah alr

#

yea np

slim surge
oak coral
slim surge
#

its ok @oak coral

vapid storm
#

hi

ivory shore
vapid storm
#

i'm in game already

#

@rocky carbon

ivory shore
#

Can join more if you want πŸ™‚

fierce oxide
#

Hi

#

This is me jacksparrow1998 on KOTH

vapid storm
#

ayo

#

who wanna play koth ?

ivory shore
grave tulip
#

same

slim surge
#

20 mins

fierce oxide
#

what you are getting blackdevil???

#

using cheap things to win the match

#

anyway you play alone. I am leaving/

austere ice
#

anyone online we can play fair game and share ideas???

ivory shore
fierce oxide
#

anyone

fierce oxide
#

portscan fails,...!!!!!

austere ice
grave tulip
# austere ice let's play

you are a script kiddie who compensates for not being able to hold on to king by shutting everything off. Try a level playing field sometime.

austere ice
austere ice
#

yourself on machine try to be a king everything is open but you can't because i know what i am doing

#

you have run this "#!/bin/bash

chroot centos_chroot /bin/bash -c "nc -nvlp 6555 -e /bin/bash" " i can see all your command /bin/bash /opt/scripts/chroot.sh

#

and i am told you first play a fair game and below is my command that warned you

#

echo "massco99 here please play a fair game if you kick me out you will never back again" > /dev/pts/1

#

we are here for learn bro not a war thus why i warned you to play a fair game. but sorry if i am cause trouble or bother you i am real sorry @grave tulip bro but i play a fair game

#

who is andremmsoares

slim surge
slim surge
eternal hound
#

yo hackers

#

anyone wanna join !!

slim surge
grave tulip
ivory shore
iron lion
#

'oly moly that is amazingly close

junior pollen
#

ji

#

hi

fierce oxide
#

its me jacksparrow1998

slim surge
potent shoal
#

maybe im lost, but why im not king in h1 hard? i insert my name, but i dont get king

grave tulip
potent shoal
brittle stirrupBOT
#

Gave +1 Rep to @grave tulip

grave tulip
potent shoal
grave tulip
potent shoal
brittle stirrupBOT
#

Gave +1 Rep to @grave tulip

slim surge
slim surge
full crow
#

Am i the only one with VPN issues?

#

after running a full system upgrade yesterday, i've been unable to connect

proud frigateBOT
iron lion
#

Try this and see if that fixes it

full crow
#

k

full crow
brittle stirrupBOT
#

Gave +1 Rep to @iron lion

iron lion
#

No problem

full crow
#

Shrek box keeps breaking

potent shoal
ivory shore
full crow
potent shoal
grave tulip
#

gg @fervent beacon

fervent beacon
slim surge
jade elm
#

@ivory shore u wanna join vc

ivory shore
ivory shore
fluid vapor
#

I enjoyed koth, I just started to game

ivory shore
median kettle
#

How do you fix the read-only file system error. I've tried remounting but it wouldn't work

ivory shore
slim surge
subtle laurel
#

is it allowed to remove the chattr command file?

neon river
subtle laurel
#

πŸ‘

sinful nest
silk patio
#

@slim surge you are a genius ❀️

slim surge
#

@silk patio tipsfedora

subtle laurel
#

when getting a root shell, can i kill the other users' sessions?

vapid storm
#

try to maintain your ethics

neon river
subtle laurel
#

ok thx

crimson ingot
# vapid storm try to maintain your ethics

What ethics? kekw
Rule of thumb: if it's a reasonable thing to do in enterprise, it's fine here

In enterprise if you notice a breach, you chuck 'em out and patch πŸ€·β€β™‚οΈ
You don't shut down services, or move things between ports, or delete the file system, or whatever other crap people seem to delight in doing to win these things though

crimson ingot
#

Then perhaps specify that πŸ€·β€β™‚οΈ
Poe's Law: Never assume that your words alone will be interpreted the way you intend them to be over the internet when there are no other indicators of intent

#

i.e. if you make a statement with no context, expect it to be taken literally

sinful nest
#

lmao

iron lion
#

so is it okay in enterprise to disable someones shell with the nyancat binary????

fallow hornet
crimson ingot
iron lion
#

yeah it sounds like a very rare enterprise application

north shadow
#

what can I do if a file has +ie attributes but I can't run chattr because it "isn't" installed on the system, but I know it is

iron lion
brittle stirrupBOT
#

Gave +1 Rep to @iron lion

iron lion
#

no problem... just know if your competitors finds that busybox binary they can remove it if they want

north shadow
#

how do I look for a busybox from a different user?

#

it could be any name right?

slim surge
crimson ingot
#

Or filehash if they've just grabbed a prebuilt one

vapid storm
#

@proven pollen

#

are you playing with me rn?

north shadow
#

I gained a rev-shell but sometimes it just does some strange things, like it have been hacked. And I can see what a player is typing without me having control over the shell. What does this happen? Can someone actually do that?

#

and when I stop the rev-shell, my own VM shell is bugged as well (I need to open a new one to use it properly)

iron lion
iron lion
crimson notch
#

hey can somebody help my on KOTH production machine. even after getting root i was unable to put my name in king.txt

sinful nest
brisk pelican
#

hi

crimson notch
#

CeloXSec is here ???

slim surge
edgy sky
#

Hello everyone,I am curious how can I get permission to join voice chat?

proud frigateBOT
iron lion
#

then follow the instructions in the link and you can join voice chat and post screenshots

edgy sky
#

thx!

iron lion
#

no problem

vapid storm
#

anybody in this game here?

slim surge
ivory shore
ashen roost
#

Does anyone want to join a team for hack-a-sat 4? Qualifiers are April 1st

zinc totem
#

What do you need to know for it

ashen roost
slim surge
vapid storm
#

who koth

#

rn

gleaming anvil
#

any one wanna do H1 linux ez

slim surge
#

20 mins

slim surge
tropic ridge
#

πŸ™‚

tropic ridge
#

wp

sly depot
#

hi

ivory shore
austere ice
#

hey bro share panda link game @ivory shore

soft beacon
#

@austere ice GG bro for the Koth of Shrek
Could you tell me please how did you exploit the machine plz?

austere ice
soft beacon
austere ice
soft beacon
#

we were in the Shrek KOTH

austere ice
#

then you will get "/Cpxtpt2hWCee9VFa.txt"

soft beacon
#

Same then I found a private key

#

Whose user was that private key?

#

shrek, puss, or donkey?

austere ice
soft beacon
#

oooh I see

#

I found shrek's password with Hydra lol

austere ice
#

but also you need to chmod 600 so as to have full read and write

soft beacon
#

Yeah I know

#

then how did you proceed?

#

To elevate your privileges to root

austere ice
#

i got the interesting result as /usr/bin/gdb

soft beacon
#

I found python using that

#

oooh

austere ice
#

go to gitfobins site and search gdb you will get sudo exploit

austere ice
soft beacon
#

oooh I see

#

I used python to spawn a root shell as well

#

I was root but I couldn't write to king.txt

#

weird

#

Did you change something by any chance?

austere ice
soft beacon
#

daaaaamn I knew it

austere ice
#

also i think f11snipe also do chattr the same

soft beacon
#

And from there, did you patch anything else?

#

just for curiosity

austere ice
#

yeah think was but its my tricks

soft beacon
#

Oh no problem

austere ice
soft beacon
#

where?

austere ice
soft beacon
#

oh yeah yeah take your time

#

let's talk later

austere ice
soft beacon
#

thanks man

#

I appreciate it

slim surge
#

20 mins

slim surge
#

20 mins

ivory shore
slim surge
#

20 mins

limber fractal
#

Ω‡Ψ§ΩŠ

brittle wasp
#

is there a vpn just for koth?

iron lion
brittle wasp
#

understoodpartyblob

#

@iron lion ty

brittle stirrupBOT
#

Gave +1 Rep to @iron lion

iron lion
#

no problem

brittle wasp
#

@brittle wasp ty

#

:3

#

why arent you guys in call :p

iron lion
#

mostly because shadow is getting ready to go sleeps

brittle wasp
#

ahh i see

slim surge
#

GLHF @brittle wasp

brittle wasp
#

heheh

#

glhf

slim surge
#

easy way in ssh Trap@<IP>

#

passwd:letmein

brittle wasp
#

ahh

#

ty

slim surge
hazy robin
#

Let's go

tight condor
#

anyone on here

ivory shore
slim surge
shadow rose
#

otherwise its gonna be me vs trapnatized

#

guess its just me and you again

rancid estuary
rough falcon
rough falcon
#

@sand hollow GG

sand hollow
slim surge
#

20 mins

rough falcon
rough falcon
slim surge
#

20 mins

slim surge
dire fulcrum
#

20mins

slim surge
still geode
#

15 mins private

sly wadi
#

@latent jay hey can you check the machine there was silverbullet76 in king but wasn't showing as king on scoreboard but when i did remount the root then few things stopped working can you check it once

vapid storm
#

An user has change the ssh key in the food machine it is legal ?

#

We cannot hack without this access

#

At the beginning we need to hack a mysql server for have the ssh key and after we need to use it but one of the other players has change this key.

#

And I have been kicked .

true stone
#

There are multiple footholds.

#

And yes, you can be kicked from an SSH session

#

welcome to KOTH

slim surge
#

15 mins

slim surge
trail wharf
#

3m

cerulean salmon
#

user giorgosR21 removed ssh server from machine, leaving the game unplayble for everyone

slim surge
#

There’s other ways in besides ssh πŸ€”

#

Also try running another port scan he may have just changed the port #

cerulean salmon
#

he didnt change port

#

depends on the machine

trail wharf
#

13m

slim surge
#

20 mins

nocturne pine
#

Hey everyone, is there a way around if someone makes the file king.txt immutable and deletes chattr?

ivory shore
tropic vale
#

hi

#

I am new in KOTh. will i win?

#

I am level 9.

iron lion
tropic vale
#

I got 3rd. Everytime i tried to get in. It was a dead end. I got 110 points. will this be added in my total xp?

grave raptor
#

I'm reading the instructions and there are a lot of rules. Who enforces the rules?

true stone
#

THM Staff, I believe Naughty and Holmes run the KOTH part (?)

grave raptor
#

Does that actually work?

ivory shore
ivory shore
thin fern
#

How can i get verified to access the voice chats ? I want to hear the voices of the people who are beating me up and restricting access at 11 minuts of the games :C xD (i am a noob)

slim surge
#

!docs verify

proud frigateBOT
thin fern
#

!docs verify

proud frigateBOT
thin fern
#

Oh thank you !

slim surge
#

No problem

slim surge
#

15 mins

remote oriole
#

!docs verify

proud frigateBOT
thin fern
#

17 min

winter vigil
#

!docs verify

proud frigateBOT
ripe oyster
#

!docs verify

proud frigateBOT
slim surge
slim surge
#

15 mins

slim surge
#

20 min

ivory shore
slim surge
#

10 mins

slim surge
slim surge
#

15 mins to joinhttps://tryhackme.com/games/koth/join/71f06550153f1169efa36569

slim surge
zinc storm
#

Hello

ivory shore
slim surge
#

10 mins

timber ocean
#

anyone home?

chrome cedar
#

@sinful nest

sinful nest
chrome cedar
sinful nest
chrome cedar
slim surge
#

20 mins

slim surge
#

20 mins

slim surge
proud frigateBOT
slim surge
#

10 mins

wanton bane
#

Hey

slim surge
#

20 mins

glacial cedar
#

!docs verify

proud frigateBOT
slim surge
#

15 mins

sinful nest
sleek sorrel
#

@sinful nest Hey man! Just hopped on the discord. Can I dm you to ask some questions?

coral holly
#

!docs verify

proud frigateBOT
vapid storm
#

guess we can chat in here @frigid trellis

#

to not fill up the general chat

frigid trellis
#

sure

#

my heart is rushing for no reason

#

thats funny

vapid storm
#

haha

#

I'm excited for it

#

first time

frigid trellis
#

same

vapid storm
#

I have no idea how to patch

frigid trellis
#

Hole idea is to prevent access to other users, patching requires research and can take some time.

#

Did you choose the machine or is it random?

vapid storm
#

I picked a random easy one

#

I think

#

"H1: Easy Linux"

frigid trellis
#

KING

vapid storm
#

damn haha I just barely realized that I had to add the different ports to the ip when I entered it in the web browser

frigid trellis
#

$IP:8002 has a php interpreter

#

immediate RCE

#

after that its just privesc

vapid storm
#

ah

frigid trellis
#

not sure if there is any more flags on the system besides root.txt

#

i've tried to find it without success

vapid storm
#

I just figured out the rce

frigid trellis
#

as i said, this page is a php interpreter, it will run any code you type into it. Rev shells included

vapid storm
#

yea I figured that

#

trying to escalate privs now

frigid trellis
#

good luck

#

ive patched the priv esc hehe

vapid storm
#

haha damn

#

I gotta hop off now

frigid trellis
#

it was fun

#

make sure we do this again sometime

vapid storm
#

yea once I have a little more time to try and actually finish it haha

#

was fun

stark ivy
stark ivy
#

Expired but didn't start?

stark ivy
#

@sleek sorrel You having as much trouble as me? XD

sleek sorrel
#

lol yeah

#

Are you rogue12?

stark ivy
#

It's my first koth and I'm dying of thirst while watching hex drown. XD

#

I am, yes. Nice to meet you.

sleek sorrel
#

Nice to meet you too!

stark ivy
#

I tried random ssh logins to kill time, lola and bugs are there

sleek sorrel
#

Haha for your first one H3x007 got king really fast. Odds are he patched a lot of the easy vulnerabilities

stark ivy
#

I was thinking the same. lol

sleek sorrel
#

I’d recommend looking at some write ups of the machines to help you learn how they work. You’ll run into the same machines if you keep trying and it’ll give you good practice!

stark ivy
#

Thanks for the tip! I was actually just looking up marvin quotes to try and guess the password XD

#

My money is on earthshatteringkaboom, or a version of it lol

sleek sorrel
#

I’ve either found the password will be in rockyou.txt, or will be in plaintext somewhere on the website (if the box has one) or through a vulnerable service (like Anonymous ftp login)

stark ivy
#

I noticed telnet was a thing. Maybe an exploit for it? It is notoriously vulnerable.

sleek sorrel
#

Perhaps. Part of the fun is researching vulnerabilities and testing them out!

stark ivy
#

GG, man. I'm looking forward to the next one. I have to run to town for a bit, but i'm going to keep joining them until I get a flag.

#

One flag will make me happy. Tomorrow will be two. XD

sleek sorrel
#

Gg! Just keep trying! It feels pretty good whenever you succeed for every step!

wanton sandal
#

Hi

sleek sorrel
#

@ivory shore Did you put my name back in king.txt?

ivory shore
sleek sorrel
#

haha wow I dont even know where to begin. Would it be too much to ask you to teach me your ways?πŸ˜‚

#

just found your webiste. youre a ninja. im gonna have fun learning xD

#

GG man, i think youre the real winner lol

serene goblet
#

@ivory shore Thanks, but what do you once you get root ?

brittle stirrupBOT
#

Gave +1 Rep to @ivory shore

slim surge
stark ivy
#

Rogue12 from TryHackMe here. Looking forward to playing. ^_^

stark ivy
#

Sorry!

slim surge
#

20 mins

slim surge
wanton sandal
#

hi

bitter willow
#

Yo

slim surge
#

Sup

slim surge
compact pagoda
#

@slim surge Execute tk?

slim surge
compact pagoda
#

The ... gave it away

slim surge
compact pagoda
#

what does m do?

slim surge
hazy plaza
#

@ivory shore any tips?

sinful nest
plain cape
#

GG @austere ice

austere ice
sinful nest
#

Hello everyone how are you? Hope well πŸ˜„ . Well, after 2 years, I finally updated my tryhackme koth tricks repository with new tricks, I hope you like it, anything I'm available to help πŸ™‚

topaz veldt
#

Hello I'm new here

#

What's koth

#

And how to access it

forest laurel
# topaz veldt Hello I'm new here

πŸ‘‹

hi new here (in.security)

KoTH is a pvp game on THM, you can access it by setting your profile as intermediate or higher.

#

!docs koth

proud frigateBOT
topaz veldt
#

When will it be conducted

#

Can we spectate players ?

forest laurel
#

You can view games by a scoreboard, but you can't watch other players unless they stream/record (which I don't know can be done)

topaz veldt
forest laurel
#

Random times through the day

topaz veldt
#

@forest laurel did you participated in any of these

forest laurel
topaz veldt
#

@forest laurel can I dm you

#

Just for some personal help

forest laurel
#

If you require help you can ask in the appropriate channels, there is no need for a DM.

topaz veldt
#

Yeah, great idea

swift crown
vapid storm
#

hey sanlake you here?

slim surge
slim surge
hollow zephyr
#

Hello everyone, join me if you like to play

hollow zephyr
#

would like rematch

vapid storm
hollow zephyr
#

I do not know i just join public

vapid storm
#

@wise mica bruu

#

are you blackdevil?

wise mica
#

no why

wise mica
vapid storm
sonic stump
#

@wise mica fontaene refered you to infosec-general, this chat is for koth. Please don't drop the same question in random places

wise mica
#

but he asked

sonic stump
#

no, you asked for help.

wise mica
#

yes cus he asked me somthing

#

nevermaind

sonic stump
#

please dont call me bro. You have to patiently wait until someone in infosec-general wants to help you

wise mica
#

ok

sonic stump
#

thank you

vapid storm
#

@sand hollow

#

Yo

worn cove
slim surge
#

20 mins

wanton sandal
slim surge
river pulsar
#

thats so hard

stark ivy
night hemlock
#

how does one get into the KOTH channels?

sonic stump
#

!docs verify

proud frigateBOT
night hemlock
brittle stirrupBOT
#

Gave +1 Rep to @sonic stump

night hemlock
#

dude

modern spire
#

!docs verify

proud frigateBOT
vapid storm
#

!docs verify

proud frigateBOT
vapid storm
#

Hi guys how do we register to enter the sounds

iron lion
night hemlock
#

gg to the kid who just beat me by 20 pts on offline, that was fun

proud frigateBOT
river pulsar
slim surge