#koth-voice-chat
1 messages · Page 3 of 1
20 mins
Who wanna join a quick KotH challenge?
me
Let's go
!docs verify
GG to 4cid for the Panda challenge
If you're here, feel free to tell me how did you privesc'd the box
anyone doing a koth right now?
I just was
It was my first time, I didn't even know how to interact with the private IP until 30 minutes in
Anyone want to play?
What terminal are you using?
fish
I customized a little the settings that xct uses
Thanks!
xD
Anyone wants to play?
https://tryhackme.com/games/koth/77761
I wanted to replay this machine, i will be glad if someone could join
I wanted to play Hackers machine, thanks for helping though
Gave +1 Rep to @slim surge
want to host a private one ill join
any
any leads ?
there's a way in on 80
okay
Hello
Looking for a game if anyone is interested
@slim surge gg locking down h1 medium
@slim surge dont beat us to bad 🤣
ill make it fun 
hope its a linux box cuz i dont know windows very well
🤞 yea me either
can you join vc after so we can talk about the box when it is over
i would but im bout to head to bed, gotta work in am
I made a script to detect those players before joining matches,
if anyone is interested, please PM me and improve the tool together
Not too sure about the rules for koth, so I'll cc @neon river
thanks, i'll be glad to know
Gave +1 Rep to @wooden garden
I don’t think spamming pty sessions would be against the rules to report a player I mean it’s basically the same as https://tryhackme.com/room/redisl33t you could always just use -T flag when connecting through ssh to prevent someone spamming your pts. Or connect to machine without ssh and just don’t stabilize your shell . We have a few tips and tricks to help maneuver in an unstablized shell and edit files using sed.
Feel free to dm if you want I can share some of those tricks with you
I see, thanks a lot for the info
Gave +1 Rep to @slim surge
No problem
i3wm
cool thx
Are you bravosec?
Hi
Are you playing koth now?
yea
how minutes left or just started
@sinful nest did you clsoe all ports
?
I'm the one asking
you were the one who killed the machine lol @compact pagoda
no
send me your terminal output
yes
right hahahaha, lol
@sinful nest Are you on sftp
ah ?
no
btw @compact pagoda this box doens't have connect from external internet
I'm not with hidden processes and not using rootkit 😄
?? @compact pagoda
No, I seeing where you are by deleting files
I ? wtf 🤣
Last thing, don't blame me for the things you do like breaking the box in this game, that's not cool, own up to your mistakes 😉
I swear I didn't do anything during mid game. I just deleted files at the last 2 minutes
I just saw the nyan cat, and closed my terminal
Also, @sinful nest do you ln -s /dev/null .bash_history
ya
why ?
I was trying to see who enters directory using that. It works usualyl
ah ??
Also were you on no tty?
@sinful nest You are using rootkit
systemd?
no
I can't edit king.txt you are not using a loop I assume?
neither
Something to do with this ```type=SERVICE_START msg=audit(1691375918.470:3819): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=kothh comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
< type=SERVICE_STOP msg=audit(1691375918.471:3820): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=kothh comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
< type=SERVICE_START msg=audit(1691375918.471:3821): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=kothh comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
< type=SERVICE_STOP msg=audit(1691375918.673:3822): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=kothh comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed'
< type=SERVICE_START msg=audit(1691375923.720:3823): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=kothh comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
< type=SERVICE_STOP msg=audit(1691375923.721:3824): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=kothh comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
< type=SERVICE_START msg=audit(1691375923.721:3825): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=kothh comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
< type=SERVICE_STOP msg=audit(1691375923.922:3826): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=kothh comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=?
wrong?
Not this? Intercept Syscall Write from /root/king.txt.
This technique is very advanced using LKM ( Loadable Kernel Module) that is, at the kernel/ring0 level, me and F11snipe use it, basically if you try to put your nickname in king.txt, nothing will happen and the nickname of who is using the intercept syscall write will remain, as this file is being intercepted.
Also your ip? 10.14.39.200
Were you using the syscall write thing
I saw ip from crontab
cool
?
@vapid storm Enjoy your king time, im out 🤣
🤣 thanks
Gave +1 Rep to @restive kelp
Curious tho as im new to KOTH - so king time is what gives you points the most after flags?
i think yeah.. im new too 😄
And you disabled write access to the king.txt file even if im root? 😂
Got you ✌️
👍
Probably a chattr lock.. google about chattr
Yes did my research on the whole KOTH dynamic - thank you
Gave +1 Rep to @slim surge
If you need some tips and tricks feel free to dm
if someone want to join I'm here for some KOTH
https://tryhackme.com/games/koth/join/02b48410b6162e639b8308a0
jump on frens
@steel dirge .. aint it taking forever for the ftp bruteforcing?
no its anonymus login
yeah anonymous login initially, but for the user mcgrawford we need to bruteforce right?
Yes Rage, if you free for now, we can join ?
join
are you means KotH ?
I am here
username ?
ben.mert
awesome !
where is the king.txt in "medium" machine?
I believe it’s in c:\
whos in this game with me
need to configure sound settings
@tall knoll https://tryhackme.com/games/koth/80128
@tall knoll 10.10.249.62
@tall knoll https://education.github.com/pack
any !
later
@violet meteor
gg
does anyone tell me the right way to approach a koth challenge ?
uwu
Hey can you change your username please? We have a pretty strict no politics rule in this server
Changed it for them. 🙂
hey, can you verify me? i cant talk in #koth
no worries, you got it 🙂 you're verified now
!docs verify
Hi :3
Hi
wanna play koth?
3 min
Not for now, but thanks for asking and have fun or enjoy.
ok uwu
Okey
Ohayo
Hola!
can i join the general room ?
Yes, of course.
the voice is locked
You need to do verify
ok
someone teach me how to play koth
How to change my username on koth?
You need to change your username on your account.
Hey yall!
Here’s some good videos to learn from https://m.youtube.com/watch?v=wIDdrY-opPU
Playing KoTH and building cool tools & scripts!
Hi all
Hi all!
i like to see when people play koth its the best way to learn seeing others play. seeing how they approach things that a great way to learn
Hii
Check out #koth-voice-chat message
suggest me appropriate linux for pentest which won't crash every other week and which is stable os
Exactly, it is the Debian and Slackware
Should be any Linux os all you need is the tools… or you could use something like blackarch, kali, parrot, etc…
hello
Hello!
Hi
who's trevohack?
Hi!
Hey!
Me
hi
Hi!
hi all i broke my shell using while[ 1 ] loop how i can take it back?
Yeses
I wonder this too!
hi
Hi!
how are you?
Fine, you ?
fine thanks, what are you doing?
Gave +1 Rep to @untold quiver
Just thm path 🙂 you ?
chilling with a easy thm ctf
Yes, in same way. 🙂
yeah
Hello
Hi!
Hey, what’s your usernames on thm?
Hey, is same.
wanna play koth
Ya
No thanks, not right now.
Gave +1 Rep to @wanton sandal
Ya!
somebody wants to play koth?
quite
Hmm
hello everyone here i am trying to educate people about patching the system vuln in KOTH game my network are not work well today so also my vpn work slowly thus why i take long time to get into the game sometimes i reset a machine twice. Sorry for that but my advise is that don't delete web folder go and correct the vuln code from that web files and fix it to do that is just like delete the website because of bugs that not true our goals is to learn how to fix that vuln not to shutdown server or delete the web folder thanks and sorry for everybody i bothered @austere ice
Okey
<
Hi everyone~ There have person want to play KOTH after 7min
O
@ivory shore GG's you won off of 5 pts just realized i won. anyways ggs
ggs
somebody used iptables to block me lol
yes
@winter mauve This you? https://imgur.com/a/ex7RJa3, https://pastebin.com/Eaif4zzS
thx. keep up the good work. just don't screw up the box lol
Oh shit did I
kinda need /etc/passwd
Very true lol, I have no idea what to do, to patch vuln's
What chmod did u do to make king.txt xrwxxxxxxx
chmod 600?
i didn't chmod it. google chattr.
aren't you the same person redirecting tcp traffic on port 9999 to your ip and port for king?
a misunderstanding of the rules on my part 😁 . I didn't prevent everyone else from accessing the box.
anyone down for some koth?
Let's roll
XD
well do it in the morning for sure
or later in the afternoon if your still up for it
im free right now if you area ready
starts in 10 mins
Okey
hi
anyone in here?
start in 12 min
10 min
Okey
Hi
koth anyone?
KOTH any1?
hi
hello
@sick panther 😦
@ivory shore what was ur pts i couldnt find it
I usually avoid using any pts or stable shells 😉
socat
@crimson notch
see this.
check your error.
btw im not root anymore.
all my processes were killed a while back.
ooow
were you btwist ?
yes
you are using netcat command wrong.
check that.
and you can't read /root/root.txt lol.
fr ?
yes.
hi
were you asking me.
the box easy was up when i was there. after i lost shells i was gone.
Hey. WhatsUp Guys..
Hi there
Hi KoTH player…
hi
Koth anyone?
Play some learn some
wow... windows box on koth is really goods
wasup
wtf
@candid fable Did u make the txt file?
yes 🙂 who else ?
GG
GG man
Somebody wanna play koth and vc?
@crimson notch how to posible this.
But I'm getting angry! 
you'v just changed the pass of shifu. ig there are many other routes to hop in.
how to change medium machine password.
do u need a openvpn to participate in koth if so where do i get the key?
There is no a special vpn file for koth as far as i know, i guess the general vpn file for thm is enough.
Someone is up for quick KOTH?
nice one @ionic junco
are u want to tell me how you change permission of king.txt so i cannot write on it ?
look like added user king are you ?
Chattr +i / -i king.txt ? it is does / doesn't work for you ?
Nice one ... file permission not changed, but it's my fault ... i write crontab to execute every minute but with wrong path 😅
* * * * * root echo "my username" > king.txt <== this should /root/king.txt
ок
Hei @wanton sandal where you put the chattr ?
i removed chattr
i use a custom binary
nice to play with you ...
gg
dm
Is it allowed to close the ssh port on a koth machine?
As long as there is another way onto the box
@flint ginkgo Okay for delete the chattr, but not the wget binary 😡
hi master @topaz ridge
did u have any clue on how to use the rsa keys?
i tried like 20 variations of 'ssh -i' and even just 'ssh production' but it said 10.10.27.182 closed on port 22
@vapid storm I don’t know, i was gone to eat. Do you want make a private game to test ?
uhh sure
u know my username?
I send you a pm
yup
hi
what's up
.
hi
hi
I would like buy tryhackme premium I need a body for discount if there is someone who would like to buy pls text me.
hi
What are your guys most sophisticated tools you made or used in koth?
hi
you cant on the website, but you can on discord
Thank you for your reply!
Which channel should I use?
you can use the KOTH vc
KOTH channel is locked.
Why is this?
have you enabled it in the id:customize @rain cliff ?
You need to be verified
/DOCS verify
@shy bough @forest laurel
Thanks! I verified !!
Gave +1 Rep to @shy bough (current: #2050 - 1)
How do I talk with my people in KOTH?
You need to be verified. /DOCS verify.
@gusty pebble
damn u can go support
@alpine pagoda GG D:
Gg
@sinful nest Did You Manage To Get Flags? 👀
yeah why?
You Didnt Submit? It Showed 0
yes, for me it is not necessary to submit flag, when you are in king
Wait, If Someone Becomes King You Can Become King By Using Stashed Flags?
yeah you can win, but this only works when you have more points than the person who has king, so you score the flags****
*takes notes*
no... you can still get points using flags if someone else is king tho.
Ah man... think i was too slow trying to get SSH
who's down for koth?
I play koth for the first time in months and someone decides to disable ssh smh
lol
lol
@dr0p
What a cheater
resetting machine since you where kicked out of the machine
@staff
You'll need to email support 🙂
never do anything
gg zzzzzz super dirty game
resets should be deleted
Played first KOTH ever and lost due to some minutes. Got root only after the challenge was over. Manual enumeration took time, linpeas was so fast. Bad luck (._.). Any suggestions to a new KOTH player?
Hey, here you will find several tips and tricks for koth, both for defense and attack: https://github.com/MatheuZSecurity/Koth-TryHackMe-Tricks
Thank you
Gave +1 Rep to @sinful nest (current: #133 - 51)
How can I join voice? :(
sorry I have no mic or headset
You need to verify yourself first
There are no URLs in that message.
testing
testing response
true
What... 0day on KOTH 🥳 ...
Would've been a good game to play... 😩 I missed it.. lol
This is priv match
Oh yea @slim surge, it was a priv match. 
Yea I figured it was, only see 0day and Simon. I could've still jumped in tho 😞... Maybe next time 😂
Yahh you can call me when you play
Sure, It was fun playing with you.

Ohh really 👽
Let's see ,
I will send you a join link here
let me finish the game. 
wait for 10 mins I guess.
5 minutes
@final acorn Make a fireworks private one.
❤️ 
yea win it 🎉
Bro i was so tired, can we play the next day please
why not, I'm not good at it. 😉 (don't root it).
Ohh okk
why not akhi, you still gonna win. 
Maybe maybe we wont know xD
;=;
im waiting to play my second KOTH... EVER. Like, im new to hacking and all and have practiced a bit and i did my first KOTH yesterday, and i looked at the recent matches today and the winner in all of them was Ch1. I join a match, im waiting for it to start, guess whoes there. Just me and Ch1. Ch1 seems proffessional, i am new o hacking...
I wonder who will win???? (Definitely not me 😅 )
(I bailed out, they patched everything too fast
i just did koth today and ch1 just pwned the root in 1 min i think he is using autopwn script ...
Yeah Idk but he’s top 6% he seems pretty good at it. Cheating in the game, but at least it would be good in the real world penetration tests
im in top 2% near of the top 1% and just to do a nmap scan on the machine take like 5 min for me, he don't need to enum the machine to pwn it x) or maybe he know all of the koth machine
Idk then, I’m quite new to it
^^
What do you do then? Nmap scan then what? I use tmux, and in split screen do nmap and gobuster and then while that’s going look at the webpage and use inspect element and then go off of what directories are shown in gobuster and ports open in nmap
after nmap if i see http i use dirsearch to enum dir , ffuf to enum subdomain , if there is login page default credential , sqli // if i see some service like ssh , sql i try some default credential like root:root , if i see a CMS on a webpage i search the version and if there is some CVE on it
Ah ok, what’s sqli?
SQL injection
when you send the request on a webpage the server will do a SQL request like
Select user from users_table where users_table.user = $USER and users_table.password = $PASS
in sql the comment is --
so you will put in login this ' OR 1=1 -- -
so the request will be like that :
Select user from users_table where User = '' OR 1=1 -- - ' = users_table.user and users_table.password = $PASS
- = users_table.user and $PASS=users_table.password will be in comment
so the requesti will be always true and you will get the admin sessions
you can do the complete begginer its a great path to learn the basics !
(I used to do a bit of programming in python, only basic stuff tho a few years ago so I can understand that relatively easily) the password check bit gets commented out so no password is required
y that the idea
Ah ok I’ll look into it, thanks for the help! 😁👍
Gave +1 Rep to @wanton pilot (current: #2182 - 1)
Pretty smart tbh, can’t get around the password, just disable it
he just pwned the machine in 1 min x)
Ohhh dang
Should probably report him.
I literally just stopped trying 20 mins into my match cus nothing worked as he had patched everything
You do realise that someo of the machines are pre-made images.
So if it's an older machine, they were already have auto-pwn stuff.
No, I didn’t realise, as I said before, I’m relatively new to this all
Yes but surely they’re not allowed to do that?
Y is not allowed
@wanton pilot do you want to do a KOTH with me sometime? It could be today, tonorrow, the nexct day. Just whenever. Priv message me whenever you want to and we will do one if I am available. (Remember im new to hacking lol and i want to do KOTH as i found it fun - i have only ever done 1 match - and think it will be great for me to learn.) im also doing old KOTH rooms on tryhackme
Yes if you want !
😂 i played 400 + games just im 9 level and i beat your a** doesnt mean i cheat level dont do anything in koth its experience
i was playing koth since i was level 1 which is almost one year ago and you just started i have keys for most machines and some machines just need a curl cmd if you dont know your way around a machine or those other noobs dont doest mean you accuse me of stuff
i never patch stuff no one can take king any way so i dont patch
I didn't ask you to justify yourself, but 59 min of root on a game of koth means that you legit rooted the machine in less than 1 min.
you guys should talk in the main koth channel so people can see your messages and i can see them too
It may look suspicious, but if it's legit, well done!
yeah i do that for most machines i save keys and i know easier ways on most machines
thanks
Gave +1 Rep to @wanton pilot (current: #1451 - 2)
you just need to save keys and experience with the machines
on the machines that i have played the root was easy just a cmd and the user was juste in sql database
what machine did we play?
yeah food you littraly need one curl cmd to get a foothold
y
for me it was juste sql database was accessible with root:root and there was a credential
and the root was only 1 cmd or smthg like that
yeah you get ramen i know ramen noodles is the best is also the pass
y
there is also an http port that have an image in that image there is creds hidden for pasta
the httpport just serves the image and you use binwalk on it to get the hidden data
i looked at my notes its port 16109 idk if that changes
ok your just a big tryharder x) sry i though your cheating
and there is a hidden api that let you execute stuff as bread with one curl cmd which is what i used 👍
okok
i saw this messages after alot of time not a lot of people talk here we have more discussions in the koth channel
https://discord.com/channels/521382216299839518/695343809726513292
okok
use rustscan instead
ffuf is the very fast you can also use it to enum dirs
i just discovered threader 3000 like 2 days ago is very fast to scan port too 🙂
Yeah I say the same, I was never accusing you @grand sparrow, just simply pointing out how it was suspicious, but as @wanton pilot says, if you didn’t cheat, then well done, that is some skill right there
In food? I tried that it never worked for me on the food box…
mysql -h ip -u root -p then type root
Dam, can you tell me?
I always did that. Ah well must have had a typo or something. I’ll try again soon
What’s the curl command to get the foothold
i will give you a hint its port 15065
Alright thx
use ffuf to get the the hidden dir then explore there to find the hidden api
What’s ffuf? Is it like go buster?
yeah but ffuf is a lot faster
And rusts can I’ve heard of but never used
Ok I’ll use that from now on
Guys I was practicing on the food koth room from the old rotations, is it the same as the koth room that’s in rotation right now?
Ahh ok. I’ll practice on that then so at least I’ll have 1 box that I know I can beat
Yes that’s the one
I’ve tried it but never got into the MySQL or anything, only did an nano
Nmap not nano
What’s the MySQL to get in and see the users that are like ramen and stuff
for mysql the username is root and the pass is root
just do mysql -h ip -u root -p then type the pass which is root
I could have sworn I tried that
Oh well I’ll message here in a bit when I try it and say if that worked or not
or you can go with the approach of the img and get pasta creds
i
You can do that? What image?
i think i remember you you played with me yesterday and you kept resetting cuz you thought i was patching but i didnt do it
img on port 16109 do curl ip:16109 --output img.jpg
I promise I have never clicked the reset button, although in the intermission I did keep leaving and then joining again hoping it would be a different match without you
Ok, what does the -O do?
maybe its not you then
Yeah I’ve NEVER clicked the button to reset the box
i meant --output curl doesnt save the response by default so you need to explicitly save it to some file
then use binwalk to get the creds
Ahh pls
Ok not please lol
Autocorrect
Il message here in a bit saying if any of this helped, which I think it will. Thanks for the help, sorry it seemed I thought you were cheating, I was just saying it seemed a bit suspicious. You’re very skilled.
ok. Im loading up the food koth room right now to try some of the stuff you told me
the room is ready, machine is strated, but im installing the stuff like rust and ffuf to try out. Ill add more time if i need. Im only doing it to try this all out
never got around to even trying the room as rust wont install
how do i install rust? also im busy now so i wont be able to do it anyways until later
install rustscan not rust for me it was just sudo apt update && apt install rustscan if this dont work and you have debian you download the latest .deb package from the the repo only and install it with dpkg -i packagename
I’ll try the first command but when I try the .deb file with dpkg -i it doesn’t work
when i do the first command it throws this error:
Error: The repository 'http://ftp.debian.org/debian stretch Release' does not have a Release file.
Notice: Updating from such a repository can't be done securely, and is therefore disabled by default.
Notice: See apt-secure(8) manpage for repository creation and user configuration details.
also how do you make the command in the box there? its in a box in a way
sudo apt install rustscan
Error: Unable to locate package rustscan
sorry. i was a sleeping let me send you the github repo
get the debian package from there and install it
Yeah I have done that but how do I install the package? I’ve downloaded the .deb file from there already but when I do | sudo dpkg -i rustfile.deb |
When I do that command it throws the error.
Not the error in the message I just replied to from myself, but it throws an error
what error does it say?
dpkg -i ./rustfile.deb
or dpkg -i <full_path_to_the_file>
otherwise it will search rustfile.deb from online repo list
GAHHHHHH
Thank god your a life saver (o haven’t tried it yet, but that must have been what I was doing wrong, not doing the ./ )
Gave +1 Rep to @radiant quail (current: #759 - 5)
Makes sense tbh
Guys i got it working turns out mysystem runs arm64 not amd64 so the dpkg with t he .deb file thing
that didnt work so instead i got it working by asking chatgpt and it said to try the docker method and ave me the commands to do and it finally works everywhere. Before i got it to work but you had to go to the directory
it might affect the performance since docker is probably emulating x86 so what you could do is build rustcan from sources and this way you dont need docker
ah well, it’s the only way that worked for me
why is ch1 in every koth that i ever join?
https://tryhackme.com/games/koth/join/c756f101f884ce01c9ff7c47
anyone wanna join koth
starting in 8mins
@brazen hull
what is koth ?
osint 🥶🥶
Is there is a king of the hill easy mode
Why isn’t it giving us the target IP?
How can i get in the vc?
you're in my game rn right? do you see an ip?
no i dont
i was going to play but i left
sorry lad
yeah its taking a bit longer than usual i might just do my own
refresh the page maybe?
it never shows for me lol
i've been, but its stuck on "scheduled"
I had this issue before with koth, even starting my own
yeah same
who uses this room 😂 dont we have another one for koth
This is for the voice channel...
king of the hill
@wanton sandal is this you in the KotH game? 😅
which?
hackers box?
yes Hackers -- 132024
@wanton sandal we were in the same game couple of times now you always destroy me 🤣
hehe gg
ah yeah i played tht
how did you get in bro? 😅
brute forcing the weak password?
I tried but my hydra skills are not that good so far 🫣
i got in via the web vuln, n yes bruteforcing but i dont use hydra
Okay 👌🏻. gg man
i still have so much to learn.. 😅
gg, good luck
thanks friend
Gave +1 Rep to @winter gazelle (current: #2104 - 2)
@winter gazelle yo can u reset the machine
You are the next one i can't beat 😅
All good it just took little longer to start 😄
@glad bramble my skills are not enough to get root on this machine give me a hint how you got in 😅
I did already
I started 1 month ago 😅 i am still learning
www.tryhackme.com/games/koth132079 someone want to join?
try more everytime friend
🫡
Tenho Los Bro com tacos troco por uma lá grande
@glad bramble did you close ssh?
Or was there never a chance to connect via ssh? 🧐
Oh my bad forgott to chance from the standart port to the actual one 😅
@misty wharf gg
@winter gazelle game?
Yeah lets go
it wassnt me but I know how it work haha
What was happening?
login in ssh again then use -T flag haha
What you mean?
That shit scared the shit out of me
So you say someone saw my ssh login?
It only was in the ssh seasion so i should be save lol 😅 but scary
you'll learn that later but now try to learn how to hide haha
I only 2 months in 😅
I have to learn a lot more then that how i saw it 😂
So yoz say if i had use -t by login into ssh that would have not happend right? 😅
the -T yeah but I dunno what other players do if they can still throw some troll on you even if you use -T
Ok
u can still find the pid using ps auxf n kill the shell
Bro are you hunting me? 😂😂
!koth
The same here. Connected successfully to my VPN file config but ping target machine is timing out.
contact the tryhackme support
contact the tryhackme support maybe if enough people report they actually start to do something
I thought I was the only one
I should do that too
@winter gazelle you're killing it bro🔥🔥
haha thank you bro 🫡
Gave +1 Rep to @tropic mauve (current: #3535 - 1)
what happend ?
🤔
jk @neon river was first
@empty dragon
hacked
Man, you lot took forever to notice this new chat
I'll be honest, I subconsciously clicked
anyone playing koth
now more trashtalking 🙂
what is this
one more channel to ghost ping you
boooo
or the opposite?
You can't ping me if i leave the server 
Yoh
Good afternoon
0x9 lvl I'm not sure if your trolling
oh its krypto
make sure you are doing the download ON your attack machine
headphone charging right now. gimme bout 3 more mins
You guys are still trying to connect
ok
no ddos pls
HAHAH
anyone up for koth
lets give it a try
is that u sunkennunu
did u join
ye
wait after the timer it will give us a ip
yeah we havce to wait
k
fff i know this box
its easy only\
yes it is
just use basic ohk
yeah the box is up now
ye it is
just the basics nmap and msf
aynone knows how `to edit files in windows
goddamit i lost shelll
did u scan for scripts
yes
--script vuln
hmm
scan for all ports
for scripts
this is not good they should have given another box f
no i did it before thats why
aynone knows how `to edit files in windows
@fluid oxide Windows doesn't do CLI editing in the same way that Linux does. Copy the files up, or use echo
If you're lucky you get a modified shell. cmder, for example, will let you use vim
yeah then i used meterpreter to do that
in my first koth i was having just the nmap scan nthg else lol
i dont know wt to do next afte nmap scan
ig u got some vulns
type == echo
lol how many joined here
copy con == cat >
i dint change anything in box
Have mercy on us
search for that vuln in metasploit
yeah m17 and eternal blue are same
ehem, Don't spoil the boxes, (I keep repeating this 🤷♂️ )
Let others try, it's more fun that way. :)
look for ms17
@fluid oxide Never accused you of changing it, i said it COULD be patched, ialso said that EB is flakey, and sometimes even if you do it right, it wont work
bruh i am not that good maybe i just entered the box and dont know how to patch it
i am searching for patch it actailly
bois iam in
godddam howmany people here
i dint change any flags
or passwords
crap
juice do u know offline tv
noice!!!!!!!!!!!
ig ur thm username
^^
juice u need to keep the THM username in king.txt
not ur dc name
u got this booi
does anyone know how to patch this vuln
gg
WOOO
hmm
GG
WP
was fun
i killed shells
oh ye u killed mine
yeah he actaully kept the wrong name in king.txt
Again
hmm once i playd with this guys @empty canopy he was the king only after 5mins lol
xd
@fluid oxide ohh i remember
hmm yeah
@fluid oxide but this time im pretty busy i dont think i will be able to play neatly
glhf
nice
actaully i was also peeking that upload thing anf lfi
but cant find the file where it uploaded
there are so many distractions in this box
wtf
bro juice i think ur got shell
bro i am stuck in this /bin file
lol
yes
bro same sitaution stuck in /bin
and where the hell are files being uploaded
did someone closed ssh
oh crap
lol somone is killing shells iguess
f this bin
xd
selling at a low price
black friday occasion
@thick socket you know whom to dm
@peak gorge change the payload
wait how did u gethat shgell
python3 -c 'import pty; pty.spawn("/bin/bash")'
ohh shit i was using python2
but it doesnt work
@empty canopy how did u get that shell from nostromo/
nope
lol why would i
joking 😄
i would just hook into the kernel and make the processes hidden by default 
i don't really have anything to say rn


.
lol
whats up
@vapid storm hi
Hey man!
@stark seal
@vapid storm it is much simpler than all that you are doing
Is SSH key patched?
wordlist big.txt
@vapid storm http://10.10.39.138/_styles/?luck=id
there is also another more complicated way to get shell. The ssh shell
port 3333
@vapid storm
Thanks.
lol is that complicated
is a hidden file in base64
@vapid storm reverse shell in python
didn't need the burp suite
good game
yeah
spooky knowing that I'm being streamed
starts in 15 mins
whaa-
what are you doing behind my back??
@neat night
wait wrong holmes
@upper fog
you still have lots of winnings pending, remember? 😛






