#koth-voice-chat
1 messages ยท Page 5 of 1
Then you can mail. And if possible use some screenshots as proof.
Might be
From which port you are connected to the machine?
What is this about?
but they wont show from the 5000 port .py backdoor either
- I got the point,
- Avoid the spoilers
- Yeah from what I remember, that was a chroot backdoor, it's not of much use tho.
but they wont show from the 5000 port .py backdoor either lol
๐ค
it was deleted, believe me
At this point, screenshots are really helpful
yeah, that's good, standard procedure.
anyone up for KOTH?
hi
Hey
i just joined my first random koth
Anyone for KOTH ?
7 mins
Herro?
when did that koth game start
i hear a lot of echo on stream
If the goal of koth is blocking all port or disabling all service
Congratulations you won
5 minutes
hi
wag1
i think all of us in koth should go in koth vc?
k
ill be there in 3-4min
If you think someone was breaking rules you can mail at koth@tryhackme.com
15 mins
koth?
yes
5 minutes
cool , okay
20 minutes
7 minutes
25 minutes
25 minutes
sad @twin urchin
๐ฆ
haha
cmon boiis show us some good match
i want to see real 1337 hacking stuff
bro what do ya expect ๐ ,its just 2 people . naughtys gonna beat us like ooooff
๐ฆ
dont patch pl !
snipers prep going hard
yeye
@plush plover u too join bru
maybe next round
okey
@cerulean wing ^
thnx
@slow star cya

https://tryhackme.com/games/koth/join/a83f5624271a91e626bd5f71
Koth starting in 10-15 minutes
Machine: Hogwarts
I wish I could join... I have no more time for the attackbox today and I'm not a high enough lvl bc I have limited time
you can connect to the vpn with your own kali machine .
!vpn
@twin urchin can i dm you
yep
good
for what ?๐
๐ koth
can you send the link if you can i need to do a room 
i dint understand
that rust
7 minutes left
well!
same
hhahahahaha
well, lets try this out once again...
dang
<.<
\O/
koth anyone?
lol imma be vibin all day in koth vc cuz i got no life XD
lol what happened
hello
Anyone playing rn? Link a invite?
52 minutes left
nothing is patched so far
is that my github I see there @twin urchin 
randomly bookmarked the writeups 
let's move over to koth vc
ah nah , he tells some cool tricks . 
join koth vc if you are playing koth
yup
lol the cool tricks one is private repo

whatever
i dont know how to use it ; have tried a lot
00:17 - Why I like Tmux
01:20 - Creating Tmux Session
01:45 - Bash: Ctrl + R - Recursive Search
02:02 - Tmux: Prefix Key (default Ctrl+B)
02:05 - Tmux: New Window - Prefix c
02:07 - Tmux: Switch Window - Prefix #
02:36 - My Tmux Config
02:50 - Demo of "nested tmux"
04:00 - Tmux: Rename Window - Prefix ,
04:20 - Tmux: Send/Join Pane Prefix [s|j]
...
smh my own stream is not loading for me 
@neon river i dont see it too .
once you start using tmux, there is no going back
not visible to me either
what you mean >/
what is tmux...forgive my ignorance
you mean to tell like tmux is love or something .
?
yeah
terminal multiplexer iirc
aww , let me actually use it then .
something like this
uh both tabbed and splitted
ok
you can join in last 5 minutes before the game ends and i have patched every possible foothold,removed all of the binaries,removed all users, closed ssh,removed all services except king service. Then you are welcome to join in.
smh i was playing on the wrong machine for this much time
lmao I saw that login on gibson I was like this is panda, why is he in hackers
BRO YOU ALL ARE SO GOOD!!!
naught , can you confirm is ssh is all good , its throwing errors
working fine for me
i removed your ssh key
but i sshed to shifu , it doesnt work
you changed password for shifu?
hmm
not giving any errors for me.
my vpn is all good tho
yupp working fine for me
okay , it seemed to work now but password changed
, i got no way in
i mean there are still 2-3 more ways in except ssh password
uh , there is but very long and annoying 
won't take more than 2 minutes ๐คทโโ๏ธ
im ready
How about a terminator??
No
any one wanna play koth ?
sure when im done with the one im doing
alright dm me when u wanna do
k
6min
Anyone for koth?
sure
Okk wait a minute
its spectating link
2 min left if anyone wants to join
@sinful vessel are you playing?
No, I cant figure it out :\
That's what i thought
hey guys if you played koth today ping me i would like to spectate
@marsh ivy can you put it on voice cht
what?
Hey guys send me spectator link if you are playing
They are in the study room not in koth
Ah okok
Hi
I have rooted the hard host completely
but flags are missing
can I get a hand please? @spiral karma
same
patch coming in just two mins (: waiting for containers to rebuild
screenshot me proof @swift ravine
patch is on site -- refresh page & redeploy
yea
@dawn sentinel
it took me like
3 hours
to get foothold
it was hard ๐ซ
yea
@dawn sentinel how to put the magic bytes in a php
can you write it here
ghex
This is a list of file signatures, data used to identify or verify the content of a file. Such signatures are also known as magic numbers or Magic Bytes.
Many file formats are not intended to be read as text. If such a file is accidentally viewed as a text file, its contents will be unintelligible. However, sometimes the file signature can be re...
how do i use powershell in terminal
wait , i have an idea
tell me how to use powershell in term
<?php echo system([$_GET['cmd']) ?>
You can get a rev shell from a other port
This is the easy one right?
Hmm I am doing it now
Check port 81
Did you finished hard one?
This one is sql I think
Id = 2
Is your ip
What are you talking about @noble solstice
Never mind
Yep,
Nice
Okay lol
Oh okay
koth anyone?
let's play
20m
oh
hey guys
hey
happy @neon river
yas
hey there... can anybody be kind enough to share the directory in which uploaded files are stored... without deleting mine?
/tmp, /dev/shm/
I mean the shrek machine's /upload directory
they are usually stored in the current directory you are in. Also you can use -o or -O to specify the file path in curl and wget respectively.
/tmp and /dev/shm are the most common directories where every user can write in.
no idea, either way,
i was just confirming if there was slow mode enabled. wasn't able to send my 2nd text while i pressed enter twice
Oh yeah, no idea why but that happened with me too
the classic discord shake, when you can't send the msg
Just a general question... Can a person create koth boxes instead of normal rooms?
on thm
yeah
Well I think I know a way how to get that koth winner badge ๐
they are just a pain to make because they require 4 times the normal box's work
LMFAOOO
@neon river THIS IS THEY WAY
Hmm, will c bout it 
free #1 lol
Nehh, I am just free tonight... It's firday night yo 
today is saturday uh ?
in about 39 minutes eh
Lol, atleast I didn't tag anyone 
what , LOL
^^
btw, is there a way to solve these koth rooms as a normal boxes? Like just for practice and experiment around... irl... it's just messed up for me rn
food and hackers
Yeaa, I did hackers... what about the rest of 8 boxes?
I don't know what to say... But GENIUS
sudo apt install python3-pip
KOTH is up in 4 minutes if anyone is down
that's a spectators link
come play
24m
Auxiliary aborted due to failure: bad-config: Password cracking is not available without an active database connection.
anyone koth?
20m
@pale mountain Would you like to elaborate?
@brittle swan can u give a hint
have you check the web server?
yea
there is a command injection on the web server or you can enumerate the kerberos service
@brittle swan i am enumurating kerberos service , can u give a little hint for cmd injection
@summer venture hi
hi
@neon river invite?
gg ;-;
oh you made that one?
in /dev/shm/.../?
i removed it when i found ๐
@lone nova gg bro good koth
Gg yes it was
you make on script to auto set your nick in king??
Yes
wow
very nice bro
well thought out
i removed your ssh access and restarted the process
Oh
.ssh Am I right?
Yes
I used only msfconsole
using metasploit
ye
Gg
Tommorow
Bye
@lone nova gg
Where were u?
idk, I got lost in this
Oh
how did you break in?
I got cred from ftp
the ftp port was closed to me
I think you were in docker
how do i join the voice channel?
okay done
i had to verify using the discord token from my THM profile, for anyone curious..
@crimson sluice yo we just played a koth and I have a question for you, can I DM ? ๐
what is koth?
!docs koth
Give it a read
Anyone here?
yes
!docs koth

-ban @twin urchin Selling OSCP materials, incredibly illegal
๐จ Banned 5 N | P 3 R#8081 indefinitely
Wait.....isn't that the free pentesting with kali book?
Or am I crazy
damn
nope, pwk PDF is named that afaik.
Ya, just looked it up, you're totally right\
Then what the heck is that free book called then
intro to kali maybe
Hi @floral jackal,
The guy DMed me with details saying this was a misunderstanding, the videos were from a (public) YT channel containing the owner's content and not OSCP's.
Do you mind taking it up with him in DM (if possible)? he's kinda sad.
Yes, even I spoke to him. those videos are from a YouTube channel, Sad guy
He's asleep right now.
Appeals go to jon@tryhackme.com
I obviously cant speak for him, however, the evidence that was gathered was convincing enough to warrant a ban and a report to OffSec
Hmm, yeah, it felt like that to me too. I've DMed him the email address. Thanks!
-warn @calm scaffold Defense and apologetic behavior towards those having committed known illegal actions, especially those within the THM discord. Final warning.
โ Warned Umar_0x01#0079
No, I was wrong, it's the syllabus file of PWK(OSCP) from offsec's site.
https://www.offensive-security.com/documentation/penetration-testing-with-kali.pdf
I highly suggest you quit commenting before you get yourself banned as well
i have heard u get banned from offsec if u find and use a pdf am i right?
@nocturne flower except in rare circumstances, yes
ah thanks ๐
hlo DarkBandit
2 seconds (: @stable oar
excieted to watch 1st KOTH
revshell
my first koth
Anyone wanna play KOTH?
gg @vernal basin
absolutely poggers
lmaoo
I guess its over
smart duddddde xD
u saw chattr ๐
I did
xd
and i tried copying mine but newer version
import ur own if the machine dont have
mine uses a different version of glibc i assume
i am new to hacking but if u wanna join koth then https://tryhackme.com/games/koth/join/140a5b62d0cf29f586ef3988
@everyone
Did you really expect that to work..?
i said the same thing and realized they left or were banned kekw
๐ค
lol
sharing the link in one of the channels would be enough ๐
This is just the spectator link
anyone up for some koth?
hello
how are you every one
?
my name is hallopino
i want to learn more about hacking
how can i do that ?
Hey if you check #start-here This will tell you where to start
thank you Blackout
koth anyone?
I don't think that matters
||#!/bin/bash while : do rm -rf /root/king.txt echo b4rt00 > /root/king.txt done||
anyone 1v1 koth?
I thought this was public game
@vapid storm join this one https://tryhackme.com/games/koth/join/e33fae71a900c145398f85a6
your supposed to patch not remove the way to privesc
breh
really
remove?
yes
tmux
thats the way to privesc
it was in the tmp dir you had to do "tmux -S default attach"
you removed it
-_- there's another, and I didn't remove that
I moved to another dir
I can move it back to default place if you want
Already put it on default location
Also, isn't that the purpose of patching? to remove privesc? 
yo where is the hidden king.txt lmfao
hidden king.txt?
nvm i tought i saw something
Well, GG
GG
dam bro we were fighting for that king the whole time XD
good game that was actually really enjoyable!
๐
lol did you get the cat thing on your terminal
yeah, a nyancat
Joining in
that room is new ?
yap
Stellarix, can you view my screen to help my ?
putz
@vapid storm use cyberchef for that flag
@rapid meteor that is so much RGB ๐
@vapid storm rot13
That one is rotated left
@vapid storm
See its ending with mht means thm. Just rotate all backwards
@vapid storm remove that ; after done and put & to background it
If you are saying something to me I can't hear you. I'm outside rn.
No handsfree
@dire tree what did u do to serv3 passwd file?
I didn't change anything
kk
Hahah what was that? ๐
The nyan?
Yeah ๐
rip
i would patch but im too lazy
I've given up anyway so
Reading a KOTH guide, since i didn't know how to counter ๐
hahahaha
hm
when I start to kill shell will not cry
@thick socket can't take it without getting in the way of others ?, I could kill you since the 2 min game ..., have good sense
i was patching
also did a wall telling that
so if you patch, you have to restart certain services
then i just changed the password of root as you did
to change the root password is to keep killing shells, and removing the web?
if you don't know how to play, don't enter the room
hi uwu
Do you get THM points for winning a KOTH game?
No points, but somehow you can earn daily streaks from it.
Well, like that, it can be exploited in some way, if there's no people in public rooms, a person can invite their friend, and make that their friend do not play the game, so he wins only.
I can't tell really, but I tried to describe it as much as I can
@everyone
did they just left after trying to ping everyone? 
They were banned
oh they spammed in every channel nvrmnd
What is inside the link though?
22/tcp open ssh
7258/tcp open unknown
7328/tcp open swx
9999/tcp open abyss
10191/tcp open unknown
49221/tcp open unknown
thx bro
enumerate the web?
Wa?
or services
there was no website or do you mean 9999
no nvm thats for koth im stupid
yeah
could you type?
I am here. I am also on the call
oh okay. Im not that good so it would not be interesting.
Im not sure about that.
it's an inside joke here (brazil). we fear the Indians on these pentest platforms
as well as Russians and Chinese
Oh, haha.
hey
sup
starting a bit late but i'll catch up :D
Damn you are good
@severe fossil you can't kill process
i didn't kill yours
nice to play with you
bcoz i remove po from passwd file ๐
fuck
we do hack yes
@vapid storm ssh with ashu user password is Kakima@123
how would that count as blue teaming? what's the point in doing that actually?
bro ahah i cant find the privesc bc you keep kicking me out
GG! Next time I will be faster
๐คฃ
sure
atleast i found a new way to get in the box
ahahaha 4 min left
can't expose it i think, but i can give hint. I used ftp
why?
Resets should only be used if the target has been broken or otherwise rendered unusable; resets shouldn't be used to prevent users from gaining access.
ok
yes!did not get ssh
rescan? someone changed ssh port
aa
thanks for information
hi
Hello ๐
@charred patrol @whole locust
What y'all doing there? ๐
[redacted]
Yo
zz
@hexed crypt nice play
try now get a reverse shell
good luck
I'm leaving, see you later. we can play another koth later @civic cradle
I surrender
Hey
@dawn sentinel 
heh saw that
There goes one competitive team
naughty will have less competition

.
i dont kill services
bruh in my nmap scan there isn't any ssh port
gg
@dire tree nice to play with you
OSCP Voucher Giveaway!
TryHackMe will be releasing a challenge this Friday, including a giveaway for an OSCP voucher, generously donated by @q8fawazo! The winners will be announced on Discord, so make sure to pop in and meet everyone prior to starting!
https://t.co/FOrwCOzfMb
@pastel sierra that's for a file which is executable for ashu as root you can set the path variable as per your choice
hi
so for every command you run will look for file first in your folder
you can exploit that using export $PATH={whatever directory you wanna start from}:$PATH
read $PATH exploit
on google
.
xfreerdp /u:USERNAME /p:PASSWORD/cert:ignore /v:IPADDRESS
CACLS king.txt /e /p {Administrator}:{F}
what a great koth game
@versed sinew removed all the binaries
@harsh cedar please ban him
this isn't the first time he removes all the binaries
Hey @ruby pier If someone is breaking the KOTH rules, please report them to koth@tryhackme.com, with sufficient proof.
This means videos, images, or anything that proves they deleted the binaries.
If you cannot provide proof, we are unable to punish the user.
What?
@ruby pier if you have any issues regarding koth please ping koth staff as they are the ones supposed to deal with that.
Or other than that what jabba said.
If you are talking about a machine food with the user food and not able to run binaries then that is intended. Kindly stay calm
@lusty iron where you just in koth
i think he means nowak removing service binaries so no one can get in. he did to us a few times that other day. gets to root really quick then took down http and ssh so no body could get in. level 4 and hes doing around 34 to 126 events a day. first activity is 95 events on the 25th
not that events really matter but.
No ๐ค
I was playing koth w a guy named just like you is why I was asking
Did he win?
idk how
Clearly the name
Clearly
@ruby pier how are you doing this so quickly?
GG
Because not every flag has same points...points varies for which flag you submit...as far as I have read the koth docs
whats koth binary
i sent it again in koth room
I couldn't find the people in that room, at Discord
anyway.. do you want link?
easports its in the game
@halcyon rose http://IP:9090/linpeas.sh
You guys up for one more koth?
Am gonna join too...after completing the GoldenEye room
live in 3 minutes
@inland rivet
is this the link @ruby pier ??
yep
Dude stop killing shells
Dude atleast allow us to privesc if you can't
That's how Dirty you play koth?
awwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww
We can, @vapid storm
okay how do i start?
Register on the website
okay
is it safe to us my personality email?
@vapid storm Maybe #general Would be a better channel. This is usually a supplement channel to the KOTH voice chat.
okay
Any chance TryHackMe could feature global pricing? I haven't seen another site as big as THM that only uses ยฃ
Sorry IDK if you're doing Q&A right now
My bad, sorry wrong channel
@thick socket hop in
I didn't heard you
Come again
Most of us will be trying to patch ๐
Decode Base64 to file online using a free decoding tool
reset the machine
Why?
Will you all play one more koth?
14 mins
@thick socket @inland rivet hop in
Stellarix hop in
12 mins
๐
How many koth games have you played?
As I can see the overall leaderboard of koth
why Tyler Machine is so so so slow ?
can i dm?
Sure
hi
https://blog.tryhackme.com/guide-to-king-of-the-hill/ here is a guide for king of the hill
but if you're really new i suggest doing the tutorial rooms first
i been but been locked by the dumb paywall
but using there linux is not
then i suggest installing linux on a virtual machine
im on a chromebook
but cant enable linux
thou i use repl.it for my linux
;---------;
๐
I have never done this machine
For me its first time doing koth
@neon river ๐ค๐คhow many koth at a single time?
What's that falling characters?
cmatrix
when playing KOTH is it allowed to change password
because someone just kill my shell and change the password also
First time doing KOTH any tips? ๐
new koth
public
How to leave?
options and leave game
Thanks @inland rivet
!docs koth
There's also a blog post linked here ^
Give that a read as well.
!docs koth

Why can't i join this room?
i hate this day bcs i can t finish a koth machine because i need to leave ๐ข
we can play another day alex its cool
gg man
gg
@violet heron have you uploaded powershell?
Evilwinrm or xfreerdp @inland rivet
@inland rivet you've psexec.py?
Or
evil-winrm -i IP -u username -p password
13 minutes



