#koth-voice-chat
1 messages Β· Page 6 of 1
I'm gonna join
with an idiot @surreal elm
Hey let's go to a different discord server
invite link?
Sure
Anyone got tips on H1:meduim?
thats sad
I keep getting stuck at port 81 and not knowing the rdp password.
send flag pls
@arctic wharf sorry to ping you
hmm
metl just use the while command then you don't need to make a script. For example: while :; do echo metl > /root/king.txt; chattr +ai /root/king.txt; sleep 0.2; done 2> /dev/null &.
this will also run it in the background
I cannot confirm if that flag is valid, but, please avoid posting flags in public chats.
@surreal elm ^^
me neither it's a hard box
Still, Again, don't post flags, regardless they are valid or not. Also, please ping koth-staff for stuff related to King of the Hill. Or in general, pinging mods who have online status is usually a good idea. @vapid storm
Indeed
rly ;-; treeent
Its normal. Your not allowed to view other users home directories as a normal user
than someone changed the permission which is not allowed btw
yha...
that's intended ig...if i remember correctly
you can still get root
ik , i get root
treeent... u win Nice !
@rocky jewel !!
you are in rbash and not in bash. the difference between these two is that rbash is a restricted shell
also you can get out of rbash
hi
I am coughing more than I am talking
You guys already in a game?
I see Alex playing Hogwarts
3 minutes to gooooo
lol
H1:easyπ
LOL
I thought it would be hard or medium
Ok no while loops
Oh I got access, but got late for a while. Did you patch that serv3?
yeah, I wasted quite some time on it
lol
yes?
Uh lemme check
No, nothing unusual
yeah is my connection
no it was rosedrop
oh ok
yeah
long time ago
lol using pwncat, nice idea
those bits in lsattr arent real
that's just file system breaking
-suiad won't work
uh, I am not watching your stream.
yeah, no while loops
that's the file system breaking and adding multiple attribute bits on the file
my code is hammering the file. VERY badly
@ruby pier ig you found his script long time ago
which?
am not sure though
Here's a free hint so you don't waste your time
I did this cp /bin/bash /var/.history/.../vim/./shell
i knew this
Holmes the output of lsattr? is that random?
arey I told you, those bits/flags on king file mean nothing
yeah
because the code I am running is writing in king file with 300+ threads
so lsattr get's confused as hell
fsck? no
yeah xD
You are using bash to write in the file
I am using C
destroying that tty21 file was a smart move
I don't have a pts
the one that you just killed was pspy

/etc/thread
that's pspy
uh, I got root from that sudo NOPASSWD
systemctl restartServer
that's what I used to get root
then planted backdoors
that is one of the scripts
1?
I want to, but I gotta go, will play later :)
How the hell you don't have a pts
Sure
@scenic vine I was telling him to do linux fundamentals
send your tryhackme id
@scenic vine I didnt got tryhackme premium am I good for koth?
I can make a room
cooooooooooooooool
First time playing koth
sure! sure!
@vapid storm private shoulbe be good think so
whats this .
?
@vestal anchor don't reset the machine randomly
Yeah my bad. I completely forgot this machine has all the ports very randomly So I though something was wrong.
can I still join ?
yes
wait comming
GG i had no backdoors
GG
@ruby pier bro i need some help in ctf can u help me
GG @vestal anchor
oh ok
nooo its windows
OMG windows again
I wanna say 'why you guys hate windows so much' but same mate, same. 

There are 2 windows machine on KOTH
1 easy and 1 medium 
Which one you find easy?
Offline

that windows machine you can pwn it in 5 minutes
if you are speed running ;))
Yeah it was medium

alex pls change passwd back.
btw how did you know it so quicly?
to be honest I have no idea how to exploit this.
I see .bash_history is a SUID file but what do I do with it?
I have no idea which machine you are doing, but if that file is SUID and you can edit it, then you can just change it to a bash script to give you shell
π€·ββοΈ
nothing you can do afaik then
which machine is this?
panda
user?
shifu
Someone trolling you maybe. Not sure, but I don't remember seeing this in panda
π€
@neon river you online? remember something like this?
I don't ^
i removed both suid files
and i don t know why
it s showing him that
was || and ||
what is that output of?
Its from linpeas
Did you checked it with ls -l
removed suid files or removed the suid bit from those? π
I think someone made the whole folder suid 
I think so but I really have to go now thanks for the help tough
suid bit
@vestal anchor
I left you a way
for root
I already left because I had to go to my grandma but I will beat you next time (:
hehe will see =))))
I can play again in an hour
How are you always that fast. My rustscan wouldn't even display the ssh port until a few seconds ago
I'm giving up. I can't find any other exploits
My computer is to slow for this box. rustscan doesn't show anthing only port 22 and 9999.
eys
yes*
rustscan -a ip
only this
and then will show u the ports open
wait i will do something π
I did that but my pc is just very slow
alex what wrong?
also doing king of the hill with alex
?
no sry not you
@upper fog this is the moment of true
yep this is the only way
I hate this machine
=)))
im running 96 tries per min
π€ π
you push the threads too much, you essentially kill your chance of getting connections.
your own threads makes the machine unavailable.
i reduced the threads now
really doesn't matter what system I have. Only 3 variables here, wordlist, threads and the victim machine.
i m asking did you changed the pass for the user ?:)) to know if i m doing this for nothing :))
Oh no no, I didn't change anything
thank youu :))
π
Whoever's look reverse shell that was on 1234 , if you are confused why it isn't working anymore, please DM π
sure
moral of the story Dont use generic reverse shells

join this koth
damn that's one hell of a conversation going in there 

I went as fast as I could and still way to late.
tbh, I was probably the last one to get in the machine.
I got in serv3 first, but the priv esc was already patched.
So I tried to get in from another way. Hence the last. But surprised to see it unpatched though.
yes =)))
Same I can't find any privesc

Did you guys tried looking for SUID binaries?
i can't reach the machine for some reason
I'm trying but it has been loading for a while now
@vapid storm the machine is on
try the command again
The game is still up?
Spectators link?
Oh okay
No that one ended, I just checked
this is the one that's going on rn
Thanks
Gave +1 Rep to @upper fog
8Ball <What-to-ask:Text>
Invalid arguments provided: Not enough arguments passed
-8ball is robocop dumb bot?
No
-8ball are you a dumb bot?
No
-8ball you sure?
Yes
yeah
Yeah
You really submit flags?
I have root shell, so I don't know if the footholds are still active
I can π€·ββοΈ If needed be,. but usually king points are enough.
that's one hell of a location to hide stuff

What was it tho? you were using -p with it, was it a bash copy?
yeah
I hate hogwarts. My scans are always to slow.
11min
GG alex
gg
@violet heron
@plain valley whats up
@spiral meadow got root
Can't join vc rn my class is going on
trying to break
Great
its a public key
@pastel sierra hola
Any active games?
@sudden palm
shhh dont invite nonimous
@inland rivet go to the webpage


@thick socket why not check first index.php
With that
Base64 convert?
You're in that directory
Check Laravel structure on chrome
Coz he already has the password in his notes
Yes I've
I gave you something to read
You're on a right path

Btw there are around 4 ways to get in and Priv esc
As the name suggests H1:hard
I'll go off to bed... exams starting from tomorrow
Oof annoying exams
what is the machine ?
yea if it s still killing shells you can t do anything only if you are doing so fast
yeah i get the root he kills the shell
you need like this if he didn't patched anything
tty
pkill bash
ps aux | grep tty
that s how you can kill his shell too
i mean this is a fast method
but yea it s not nice to kill shells
like rq i get root in 10
he kills me in less than 10
sec
rare cases i get root
yeah
how does one change the permission to king.txt that root can't even edit it?
π
I was shut out!
there is a way.
yeah im watching your stream now π
ait the pressure is on
man chattr
Naughty im your biggest fan π΅π°

You are from pakistan, right?
Lemme invite you to a server that you will love
@everyone sto resetting the machine please!
jeeeez
that's, uh, an interesting name.
the wall thing with the chattr is interesting though XD
interesting and dangerous
anyone still doing koth?
@inland rivet I guess that tab won't work
thanks! @vapid storm
reset machine?
You created a symbolic-link? Didn't you?
Or it was done by someone else?
by accident xd
bro, what happened with the machine?
@inland rivet
um reset the machine??
This happened
we need 1 more person
@timid hare you dont have access to /root?
nvm you have
lmao plz reset the machine guys D:
this machine is a mess
@timid hare why is the king not changing xD?
yo 1trick are u good at blue teaming?
i wanna play public since it gives you a win
but, if the backdoor is something advance i wont probably find it like i said im only medium good
π
Feel free to join us!
@upper fog haha you made an script or so?
Gg
kinda
@neon river please do a live stream! would love to watch
Already streaming but in a super secret discord
Can I please get the invite?
That server don't exist
lmao
@neon river Thanks for blocking everything....
Gave +1 Rep to @neon river
huh?
you want to access root directory as gloria?
what that have to do anything with me?
Take a look at your screenshot?
and stop deleting your messages π€¦ββοΈ
@nimble relic
-warn @dapper jewel Let's get off politics
β Warned DrLiMengYan1#7369
hey everyone
what can i do if someone spammed the wall and kept sending broadcasts??
shell with no tty won't get those wall messages, you can also disable wall messages by using mesg n
if a root is spamming the wall mesg n is useless at this point
I have been looking in to this but couldn't find any way to get/spawn a non tty shell.
Keep it to english please
These are insults.
Yeah I just google translated.
Hey guys can anyone help me out on how can I change apache2 servers 401 page ?
what is koth?
king of the hill
sure I'm in a game now.
13min
yes, Its going to be interesting.
yay
I gues I won
yah
lmao
but there is like 1 maybe 2 ways to get into space-jam I think, so I get it.
yes but space-jam is the oldest box I think and I never found more than 2 ways in.
ohhh
Is this a game?
yes its called king of the hill https://tryhackme.com/games/koth
any hint
Who's on koth rn?
someone online on koth?
idk
@inland rivet can you send me your killallssh script?
yeah i saw that
LMAO
LOL
BRUHHHH
yeah it is π€£
lol exactly
@amber geyser hi
the php code looks something like this:
if(isset($_GET['cmd'])) {
$cmd = $_GET['cmd'];
system($cmd);
}
@rough moon
@vapid storm you guys playing koth? π
no
!docs koth
thanks
Gave +1 Rep to @neon river
Ya got u
join if interested
hi @pine vessel
zup! @pine vessel
sry bro i cant, im signing off now π¦ ima go to sleep
good night
hey i cant talk in vc, its locked. how do i solve this?
!docs verify
Anyone wants to play ?
@raven flareplay what
mao
hey, how do I join to voice chat?
Follow these instructions and you'll be verified
@chilly notch thanks!
Gave +1 Rep to @chilly notch
helo
hi
Hi
hi
hi
@formal void i can't see your stream. It's still loading.
@formal voidyou can use ctrl + cursor to jump your cursor either right or left on text. It's a fast way
/usr/share/seclists/Discovery/
go from here
/usr/share/seclists/Usernames/top-usernames-shortlist.txt
24 mins

GG to whoever I just played.
10 mins
helo guys i am beginer at hacking can anyone teach me
@pine vessel
@pine vessel
Follow the learning path
@vagrant thicket can you teach me how to hack a win pc using kali
King of the Hill join fasthttps://tryhackme.com/games/koth/join/763d218da6e6b4490c9a4cf0
joined late lol
@uncut grove whatsup
not really
i have an exam in 10 mins
sorry
No worries i solved it!
Hi
when khoth new room will be start
when this koth will complete then play with me once again
Who's in for friendship and lot of conversations concerning about hacking
15 min
Wus up
Yes
Me,Me,Me ππππππ
Hello
Come friends gogogo
is the machine broken ?
i found rce on port 3000
but it gives error
i did machine_ip:3000?cmd=whoami
i think you missed /
π
ip:3000/?cmd=whoami
hey bro
hey
your streaming bro awsome
no iam not streaming
I did exactly that
And yeah, I talked to the other guy, he probably did the machine before too so he pwned and patched in less than a minute
1 min
hi
Can I join in
broke the tmux session oops
Iβd rather not with the unsolicited friend request
You can use lsattr <file> to see what chattr bits are on the file
In the mid to end of the game, I set up a one liner bash script to keep putting my name in the file
ahh ya dirty boi
I would have patched more stuff but then I accidentally broke my tmux session and forgot the whole point of tmux is being able to run multiple sessions
Or windows, or whatever theyβre called
I donβt like using tmux
me neither
unreal
me also want to play
some
hi @pine vessel
hi
hahaaa
@pine vessel join voice
Covid-19 = Certification Of Vaccination ID - 19 = (AI)
Sweet mother of God
What game? @spiral karma
Apex legends π
Woah smooth. I like your game play π
Hello @simple cobalt 
Nice to hear you talk π
:DDD
yea i did
hey
yohoo
test123
int main() { printf("Hello Everyone!"); return 0; }
int main()
{
cout << "halo" << endl;
return 0;
}
Anyone for a match ?
Sure!
Same here, it's my first one too
I haven't made any progress, is there a VPN we're supposed to connect to?
I've been running recon on the IP provided, and haven't been getting anything back
!docs koth
Give these a read. also the blog post linked int it. ^
Thanks!
12 mins
@spiral wolf No unsolicited DMs please
ok, I am sorry. I wanted to ask that could you start one more linux machine
Np, it's getting a little late where I'm at, so not right now probably
Ok
Could you please tell how you solved that like give a blueprint. I tried a lot but unable to get even 1 flag
Hogwarts is a funky box. I got in via ftp, where there's a password protected zip folder with neville's creds
Crack the password using john and zip2john, and then use linpeas to search for privesc
There's a whole lot of things in the box, and I'm sure other people don't want to be spoiled, but that was the route I took
It's not getting connected to ftp. How ever It connected via one port i didn;'t even remember the number, but it asked me name
Use anonymous login
I tried that but no use
The port was also above 1000
yes i guess something 1068 or something I am not sure
ftp <IP> <PORT>
Username: Anonymous
Password: <LEAVE EMPTY>
it happens
π
When you are free, please send me the invite link
but please select only linux, no windows
I am not a subscriber, so I can't select machine. It gives random
I usually post links to koth games I set up in the server anyway.
ok
Anyone ready to play KOTH?
ant one here join the game
I'm down
Sorry @rose sphinx for the flags kkkk
GL @vapid storm
anyone koth???
Sorry guys, cant really join right now! thx for the invite
Good lock
Machine lock...
whos down fo a koth?
Me
Who's beingd3v ?
Hey there!
Can someone help me with ||secrets.txt.enc|| file for KoTH Machine - Hogwarts?
someone killed the server
hello
I would like to join one, but its my first game
hope i am not too late. no issue i use to play koth the first time too
hi
hi
I u wanna play rn lemme know
I will play in 1 hour from now
Hi
i think we should make approintment to meet each other, since timezone is littlebit problem for us
yes
now ?
@fading river there's something on port 3333
nvm
is yoour phhp sseid smae
same as mine ?
Cookie: PHPSESSID=7t16859pha7ce6sfplpgtrt0je
what kind of encryption could it be ?
@deep ermine
nc port ?
on prot 3333
right ?
nah
i have no idea currently
a folder
but trying to figure it out
maybe try hydra for bruteforcing roll ?
maybe
did you figured out ?
nah
u ?
ok
i said its a netcat running
what is it ?
after decoding it , there is something for sure
can base64 be converted to image or something
woooo
@deep ermine
loooook
base64 to file
password needed
can you bruteforce it ??
will try
btw nfs look at that too
i have no idea what it is
noice
there;s file for ssh
nah
np
mine first
yes
i got hermes ssh key
nice
lmao
π
2049 isnt hermes ssh
then
idk
its not working
same
good
where is website hosted
game finished
but how am i winner
???????/
u got flag first
@fading river
u r winner

i am always free
π
also ready for today
i am completeing this one now
ok
want ot complete ?

