#koth-voice-chat
1 messages Β· Page 7 of 1
now
ok
which state >
sure
wht cant join voice
!docs verify
ty mane
nice
KOTH anyone??
I can go for a koth
we doing koth?
ill do koth
Which machine?
Don't have mic
@vague shore I am so sorry, my electricity went off and my laptop doesnt have much charge in it
I might not be able to connect
@vague shore I can play now
koth anyone??
play now?
lessss gooo
come vc then
are u able to hear me or not ?
no
nmap -sCV -T4 $ip
@twin hare
gcc ./donut.c -o k
There was someone around this server that once had issues with installing Qtile.
I finally found a way out, if you're seeing this.
starting in 5 min
starting in 10 mins
@rotund thicket is it good to have in here
How does one get perms to join the Koth vc?
U have to verify with the tryhackme bot
i keep getting I'm sorry but I couldn't find the specified token!
even though i am sure im copying it correctly
Ah. I forgot to say that bot is broken or not working rn it's a known issue π
lol nice, how do i get the subscriber role and verified other way
I belive bot is only the way to get em
π time to wait for them to fix it i guess
!docs verify
Most likely the chattr binary. You can read more about some tricks in the blog post linked here:
!docs koth
@eager umbra ^
Oh sorry wrong ping
well yes but I did actually nuke the binary, really I moved it elsewhere
You used it. I used it then removed it :)
I ended up just downlaoding it from my machine then π
use lsattr king.txt you can see the flags set on the file.
toward the end I used cron for the last bit of points
Yeah everyone started compiling it and using it
You were triggering everyone by moving stuff and killing shells lmao
1 person moved /bin/ls
I did π
I'd join vc but the bot isn't fixed yet so I can't π
@eager umbra when you say "compile" you mean chmod +x right?
i mean compiling from source
....not downloading it from their own machine?
Get chattr.c (chattr source code) > Compile it with gcc on attacker machine for target > Upload to target > Profit
hmm how is that different from what I did? I took chatter from my machine and put it on the target then chmod +x and done
if it works, it works
6 mins
https://tryhackme.com/games/koth/join/779061e13ab15ccbb81d656e
7 min virulent vices, board the train whilst you still have time π©
@crimson ingot it doesn't work
Probably best right-click banning those ones
https://tryhackme.com/games/koth/28873
let's join
I'm in
can't join voice chat though
Alg
Your loss
It'll be cause you're not verified, Use the verify bot first
who wants to play a koth?
Where is the king of hill voice chat ?
nice koth guys ahah
hi
hello
Hi, I have joined one private KOTH and i can't even ping
Time left is 35 mins
and decreasing
anyone wannna play koth please??
connect to openvpn haha
Couldn't it be a Windows machine?π€
OpenVPN is cross-platform
hey ! do someone have a little hint for the H1:Hard machine ? it's been the third time i'm playing on it but i found nothing
That's... not what they were suggesting...
Windows firewall blocks ICMP Echo by default -- they were suggesting that the target might be Windows
Thats what I thought but it didnt make sense in context to me
So I responded as is
Who knows what Sebin is going through... unless you do
If it is known Sebin knows that level detail, then I get it... however, I don't know Sebin, and it is quite a broad inference to assume he knows that without knowing him... he could just have connection issues with the VPN for all I know, and perhaps others were trying to help him with that who only knew Linux. I also don't know infloop.
No issues, I should have been more verbose π
20 mins
King of the hill
Anyone
17 m
Can anyone help in php to gif payload creation
I tried everything, conversion etc , nothing works
shouldnΒ΄t the ip be $ip = '10.10.2.15'?
what do you need?
it's pretty easy this payload
you just need to put it in a web server file upload and execute it
Yeah, pretty easy, was having some troubles in conversion from php to gif
It only allows jpg /gif uploads
It depends on how the web server validates your upload. Thereβs a whole room on doing this on THM.
There can be mainly two forms of verifications.
- Client side
- Server side
You can obviously control Client-side verifications.
And try to trick or exploit any Server-side verifications by using any information that is already available.
If you wanted to disguise a PHP file as a GIF or JPEG for a very simple file type check.
Then copy first 16-32 bytes (magic bytes) from a valid file of the required type and put them at the top of your target file.
Or you can manually do so by searching for various magic bytes online.
There can be multiple possible ways, like modifying image metadata and adding some PHP code into it.
Adding some stuff to the file name, f.e. if the server is checking the second element in the filename after spliting it using ., then you may want to add some. in the filename.
There is <input accept="..."...>, you can change that or modify it using Burpsuite for example.
anyone koth ?
I'm here
nice
Anyone else here?
Anybody down?
You need to verify yourself first, here you go
!docs verify
how?
!docs verify
sanks
DerSchleimi, how are you getting flags if the machine is not responding? π
Oh! You were patching all the services after stopping them all at once.
At least, echo YOUR_USERNAME > /root/king.txt π
If that happens again ping me.
WDYM?
One of my opponent in my last KoTH game stopped all of the services to fix them (I think, because the web server was restarted after 5-10 minutes).
But no other service. At the time we had 2/3 reset requests and then he perhaps made the reset request and everything was resolvedπ
Is there anything wrong?
I did follow the rulesπ
I meant stopping services is against the rules. That's not how you patch stuff. If you see someone breaking rules feel free to ping me i will look into it π
Ok, I will report it from next timeπ
Well, we can surely systemctl restart SERVICE once we have patched it properly. Right?
Or service SERVICE restartπ
This one is confusing
Also, there is one /home/USERNAME/main (golang binary)
I did kill it's process as I couldn't recompile the main.go file after fixing the issue ||shell service||
Sorry, if that is against the rulesπ
Yeah
anyone???
.
@bleak condor where are you from? π if i may ask..
Danmark
aah okay.
y'all can join this koth match if anyone wants to play ^
@granite scarab @slender bobcat
@clear topaz ^
join this
@clear topaz can we vote reset? someone broke the machine
Sorry, I didn't see this till now.
what happened? https://tryhackme.com/games/koth/30999
did anyone get anything fro 10.10.121.243
anyone want's to play a koth?
-warn @pulsar jungle I'm sure you're frustrated but that's not appropriate in the slightest. Be nice.
β Warned slashr#4327
Why when im brute force'ing Hackers KOTH it takes sooooo much time? I see some people getting already root access when I can't even get my credentials right
You can try increasing threads?
Tried and its alright with 40 but if I try like 64 it gives me error that there is too many connections from my IP address. When I looked up writeup for Hackers I see that other easily can work with 64 threads
please
ill be so happe
π

any one join only 1 minuute left
remmina client in linux
@ember torrent
xfreerdp
@ember torrent
xfreerdp /u:username /p:password /v:IP
@ember torrent rdesktop
anyone up..?
Why mr.0x is winner without submitting flags..?
Perhaps because they got King points
I didn't get it
There are two types of points
- By submitting Flags
- By becoming King for at least a minute
!docs koth
How he will be king without getting shell access
Just asking I am new to KOH
How can you be sure they didn't get a shell?
You need to have a shell with root to become King
If he have root shell he will submit flags right..?
It is upto them to find and submit flagsπ
hey
hellooo

i found a veeeery long flag in one of the king of the hill challenges
when i submitted it it said incorrect though it was the one
It could be encrypted or make sure if it's 32 character flag and you are copy pasting it correctly.
Doesn't seem to be a flag. Which machine though?
Carnage(Linux)
Lion (Linux)
Panda(Linux)
Shrek(Linux)
Tyler(Linux)
@hybrid harness
smbclient: Can't load /etc/samba/smb.conf - run testparm to debug it
sudo smbclient -L \\10.10.135.39\public
sudo smbclient -L \\\\10.10.135.39\\public
smbclient \\10.10.135.39\public -u anonymous
smbget -U anonymous smb://10.10.135.39//public//flag.txt
narrator
e a
cmon Zeshan1234.. no scripts to stay in king.txt please
It might be a spin loop
while [ 1 ]; do
# chattr -
echo ... > king.txt
# chattr +
done
... (as far as i know that wasn't allowed no? or is it)
You are allowed to modify the chattr binary. Replace it with the one that writes your username to king.txt
You can find one on GitHubπ€
So a script that automatically updates king.txt does not conflict with rule 7?
IIRC, there isn't any rule to prevent use of a while loop to update king.txtπ
aye
That is a different rule.
Updating king.txt isn't considered as autopwn or machine hardening
regarding king of The Hill. Machine: Hackers . Did someone try scanning the staff images?
maybe there could be potential hidden data embeded.
@zenith trench How did you obtain access through the backdoor? I am currently trying to brute-force my way in. However, no success yet
me of course
Im not telling you xD
it's 8000
You already did this machine, isnt right?
yes
but i'm trying to patch this at 100%
Is my first Koth
I see
Jeez, I was too slow
Bro
do you want a premium voucher?
@vapid storm
oh ty so much
how could i activate it?
I cant see the code, but I sent
go to you profile, and the subscribe section in the right side
ok
there you put the code
enjoy
nothing, is just a gift for beating me XD
Dont worry, I like to learn by myself
no problem, if you need a teamate or learn more about koth call me
sure
Is that the channel
Can someone please tell me how to join a vc
@vapid storm We meet again xd
yes x)
good luck π
Same for you ^^
stop shuting my session down xD
x)
@untold trellis good luck
what are you guyz talking about ?
Koth games bro
ooh
hi guys
Hi
hey
Phishing alert(1) everyone
Hi
ironic
we meet again
yes π
π
All routes into the box are still wide open.
Having said that, might have removed shrek SSH keys. Let me see, if I could put those back...
Sorry, can't restore the original SSH keys for shrek, but as a teaser the SSH password is: pleaseletmein!. Good luck!
Thanks for sharing the link to the private game, apologies if I messed it up. Have a good weekend! (Mine starts now) π
Take it easy on me didakos & pythonista!
Heyyy
Actually read too late
some for king pf the hell
i can't connect
in ssh
what's wrong ?
ssh shifu@10.10.241.168
kex_exchange_identification: read: Connection reset by peer
Connection reset by 10.10.241.168 port 22
idk if it's me who did something wrong
well i vote to reset i hope the other will do thesame
Anyone doing KOTH?
?
Revenge face intensifies
oh ok
nice game @vapid storm!
π
ty π
was great
do you speak french by the way?
yes
nice me too
maybe we could do some stuff together when you want
sure π
first time on discord... why can't I write in the channel koth ?
can we PM on here ?
because you don't link you're account
do !verify to @proud frigate
@proud frigate
im MP
pm
got it...
π
let's talk on here another time, got to disconnect
are you here often ?
bye
A+
oui je suis plutot actif
j'essaye de faire un koth par jour
nice π je me reconnecte ptet ce soir
pour guarder ma place de top 2 ^^
ok
tien moi au jus
wow. joli!
moi je suis 1er (mais seulement du classement suisse π )
c'est pas mal, moi je suis meme pas le premier fr
1er execo seulement
une victoire alors π
exact
π
@vapid storm @vapid storm English only here.
sry
how do i join??
what ?
!docs verify
I don't defend this game π
I fucked up the machine sorry, could you vote to reset please @ocean olive @vapid stormrato @adining
etc...
I fucked up the machine sorry, could you vote to reset please @ocean olive @vapid stormrato @adining
etc...
@junior yoke GO AWAY!! IM SICK OF LOSING TO YOU Dx
@mossy pine Wow, such emotion! Do you want to compare notes on this one? Seems like it is just the two of us in this game. Ping me in DM if you want to discuss strategy.
lol
Im just now learning about chattr. Is that what you used to lock me outta king.txt? lol
you got messages turned off
Hi sorry about that. Tried to ping you as well and got the same message. I will add you as a friend.
Yup, chattr can be used to change attributes, and it is not always on the box. So, clever to keep a precompiled binary at the ready, so you can BYO.
Looks like you are not accepting new friend requests?
Fixt!
@mossy pine Thanks for the discussion in PM. KotH boxes are an awesome way to practise exploitation of a vulnerable box, establish persistence to ensure you can gain a stable shell and reconnect, and then search for and patch vulnerabilities (defend). I learn something new every time I play. Keep in touch and DM if you ever wish to discuss strategy π
Gave +1 Rep to @mossy pine
@junior yoke 100%, and thank you! Anyone trying to really learn this shit, follow this man. Many wonderful tips, and all round good dude!
Gave +1 Rep to @junior yoke
@gritty lance Go ez
Hey
hiya π
are u ready?
Just learned about Chattr. Thought Id be sneaky sneaky, and I get a pro π¦
NOT AT ALL! But GL! lol
relax π
π
Oh man lmfao
After this match, would you mind pointing me where I can learn this nyan cat thing xD
nvm!
ps
π
Pm me
Gave +1 Rep to @gritty lance
i am not sure where i can read the rules there
it seems only to be introduction and stuff
thx
If you scroll down a bit in FAQ section you can see the rules.
took me 5 minutes but okay?
bruh
Hi
.
he got really good notes on all the machines
he copy's and paste's commands from his notes
β
So youβre saying you donβt?
i make notes? yes.
I copy paste? no.
Lol thatβs a lie
don't see a reason to prove it to you π
I mean Iβve watched you play and do it but whatever dude suit yourself.
you believe whatever you want. but accusing someone of something without proof isn't a good thing.
Lol Iβm not the one acting defensive about anything, I was just simply telling him how you where able to do the machines so fast.
π€¦ββοΈ
Itβs ok dude do whatever you want.
I donβt understand why youβre denying it but whatever.
do whatever you like. but don't blame me for something without any proof.
not your bro. and please think before you talk about someone.
Yeah good notes help a lot.
Copy pasting commands help too lol
Don't be an ass. Respect people's preferences.
Yes sir!
Good evening. I am currently playing the Panda box on 10.10.119.120, it appears that none of the system binaries can be found, with the exception of the shell-builtin command. PATH variable appears fine, and printf '%s\n' * in / shows that e.g. /bin still exists. Any ideas?
I think I will start taking notes too in that case
reset the box, someone might be playing dirty.
When you do, save them! And next time you play the box youβll have the edge. π€π½
Nah, not a big fan of resets. I would rather find away around the issue, which I did. But still like to understand the issue better - and learn stuff.
Suit yourself. You havenβt played with someone thatβs erased the ssh keys yet I guess
They also rm -rf root sometimes.
π
I have played a fair amount of games π and removing or overwriting ssh keys is (in my opinion) a valid strat, but removing flags or system binaries isn't quite. There's usually 3-4 ways into the machine, so if the ssh keys are gone, find a new one, at least, that's my philosophy.
Depends on what machine youβre playing π₯Έ
Can't think of a box where the only route in is using ssh keys? You?
You know another way inside production? If you do let me know 
I am familiar with rule 1, but removing ssh keys doesn't make the box unavailable. It is still running perfectly fine.
Cool π
check ports 9001 and 9002
I will thank you π
Gave +1 Rep to @junior yoke
Im new to king of the hill games
But I see many players become king from the start
How does this happen?
anyone have good suggestions for username and passwords lists for the koth games?
Since most boxes are themed, some basic googling will get you places if you really want a user list. As for passwords, rockyou should have you covered if a login is meant to be bruteforced or cracked
@pastel sierra you there?
Wassssaaaappp
Watch
Itβs all open
why im not allowed to join any voice channel?
Did you verified?
Are you guys playing?
Someone is playing?
hlooo anyone like to play
@rustic shardDid you stop the PHP service on Port 3000?
@slender bobcat r u playing space jam?
what is space jame
Itβs a new box
alooooooo
do anyone wants to play a koth?
if u want, join here:
@pastel sierra grasshopper
Just won 3 Koth worth 600 points and only 36 points were added to my monthly score??
Someone please tell me something is wrong or I just drop whole
Completing rooms gets you a certain number of points. A breakdown of how questions are scored as follows:
KoTH points won't affect your monthly/general leaderboard
Thank you. So I wonder. How someone is able to earn about 2000 points on its monthly score in just 24hours? See Ireland monthly score please, have I been seconded just from a cheat? I've been doing everyday challenges and walkthroughs yet how is he/she gets over 2k points and over 200 in activities in just 24h? Please help
Gave +1 Rep to @neon river
the koth keeps failing.
Edit: it was from me
Nvm I had troubles with the VPN.
Hello Guys
I'm a beginner in this hacking stuff.
Can you please tell me the sources where I can learn all these sorts of things ?
I will be grateful π
how do u get into this room
Took me so long to find the king file on the windows box lol took at the flags first lol
what machine
There should be a cap on usage of the reset - I was in a koth game where someone resetted the machine every minute (disadvantage when you are only 2 in a koth game).
i need a link which directs another site, i remember something like "@" for it
lmao
yes, that's what l need
so, how can l do that?
anyone online in koth?
replace T with t, thats cuz I am not able to send the later one bcs discord sends it as example.com
what app r using for kali
like for opening kali
@visual obsidian
cant talk man mic not working
just type here
i cant here u
Just use VBox or VMware lol
i can't change my country in my try hack me profile
that link redirect me to dashbord
sry and thank u @neon river its work appreciate thank u
Gave +1 Rep to @neon river
Hi
https://tryhackme.com/games/koth/join/3f4101dd7942082ef5546c81
if anyone is down for the Hackers KOTH box; would be one of the few I haven't tried before π
Hi
Hi 2
Come let have fun KOTH
hloooo anyone playing koth??
I'm playing
Who's playing Koth?
VOICE CHAT
i littarly got banned from a server cz i was talking about doge and admiring elon musk
lol
-ban @fleet imp -ddays 2 Joined to spam links/server links. Appeals are bans@tryhackme.com if you happen to not be a bod
π¨ Banned Guru_88#2690 indefinitely
Um
-reason 914838209924571156 Joined to spam links/server links. Appeals are bans@tryhackme.com if you happen to not be a bot
π
Is there a way to change your name in tryhackme? 
Wrong channel but :
@vapid storm π
@vapid storm π
I will play koth with the others, public room
so it's not funny, you restarted about 2 times
alias, public room counts as win, private does not count, I think
Sorry to be dumb.
Anyone know the windows login creds for KOTH
Am I supposed to hack those
?
which room ?? h1 medium ??
Yes
Yes windows h1 medium
Hack em
welcome everybody ....
Why can't I play koth and it shows me "You must have experience" and at the same time I see people playing and they don't have experience
You can change that from your profile > About You section
thanks . pro
Gave +1 Rep to @neon river
https://tryhackme.com/games/koth/join/9213fb6ccc39d2dec506a9e1
about to start koth in 20 min
Anyone up for a game??
game?
anybody up for a game?
hi gΓΊy
hi guys
i have some issues in kali-linux
wifite actually
can you guys help me

i play rainbow six on ps4
Who's trying to play?
i can join in if you want?
How long are you planning on being on?
whenever you want?
I have to do something real quick. I'll let you know whenever I'm done. If you still up for it we can go a round
starting in 2 minutes
https://tryhackme.com/games/koth/join/a839144a885b0e2f6ca79b36
Answer the questions below
What is the name of the career role that is legally employed to find vulnerabilities in applications?
pentester ?
penetration tester
2 words separately will be th correct answer
anyone down to KOTH
@lone kelp
I can't change king.txt
Operation permission denied? i am root user
Hi MrSynox, I'd recommend you check out chattr a pretty common strategy to prevent fellow competitors in KoTH from getting their name in.
oh thanks
Gave +1 Rep to @junior yoke
That was an interesting game, always nice when there's a bit of a battle for King. Thanks!
Gave +1 Rep to @lone kelp
i left the game after the reset :))
I see thereβs a koth about to startβ¦ anyone in here playing?
I was very surprised why 4 people voted to reset the machine. There was (at least) one active way into the machine and (at least) one route to root.
Yeah, Iβm in, but stepped away to get my kid a bottle
Thisβll be my first one
Is there supposed to be some sort of voice chat here?
it is
but u must get verify with ur discord token
dm the tryhackme bot
click Profile > Other. on the tryhackme website
u have there ur token
@mellow escarp
Ok thanks @lone kelp
Gave +1 Rep to @lone kelp
@junior yoke I was kinda lost after gaining a user shell while you were root. What methods do you lose to overthrow the king?
How could u see that @junior yoke?
Hi. Each KotH box has multiple footholds and different ways to escalate privileges, often at least 2-3. After getting onto the box I found most vulnerabilities were still unpatched.
Most common approach to slowdown other players from writing to the /root/king.txt is to make it immutable and remove/rename the binary used to do this. This can easily be undone, if you come prepared.
More sustainable is to create persistence (so you can back in), patch vulnerabilities (to prevent others from getting in) and finally "coax" others off the box π
How long does it take to get verified? I Dm the tryhackme bot and am still not verified?
I still can't get in those vc channels with a lock
did u used your token to get verified?
I dm my token to tryhackme bot
"You are weak" that's a bit mean @lone kelp
thanks it workedπ
Gave +1 Rep to @lone kelp
hello hackers
@lone kelp How do you put your certifications in your profile?


Someone come play KOTH
that's a spectator link, if you want people to join you need to share invite link that you can find in options from the top right side.
k
attila-21 you are killing the fun bro
hi all,
please could someone help me ? i wan to make a brute force attack using metaspoit to DVWA sytem login (http)? it is for educational reasons. i study the guide of rapid7 https://docs.rapid7.com/metasploit/bruteforce-attacks/ https://www.tutorialspoint.com/metasploit/metasploit_brute_force_attacks.htm, https://www.offensive-security.com/metasploit-unleashed/scanner-http-auxiliary-modules/ but i can't do it. Any help? I am a beginner.
the output error is concern the URI : " No URI found that asks for HTTP authentication"
i am using /auxiliary/scanner/http/http_login module. i am not sure if this module is the correct. has anyone tried it?
i dont use MSF for bruteforce http , i use hydra for http forms ,in case you want to try and check ,find this article from null-bytes explain it very well
https://null-byte.wonderhowto.com/how-to/hack-like-pro-crack-online-web-form-passwords-with-thc-hydra-burp-suite-0160643/
Welcome back, my hacker novitiates! In an earlier tutorial, I had introduced you to two essential tools for cracking online passwordsβTamper Data and THC-Hydra. In that guide, I promised to follow up with another tutorial on how to use THC-Hydra against web forms, so here we go. Although you can use Tamper Data for this purpose, I want to introd...
π
The case study is with metaspoloit. any help?
you heard of patator?
Just start playing KOTH, why would someone write a script to auto rotate king?
Do you mean a script to pwn the machine or a script to put their name as king?
It was a script that rotated the king between everyone in the lobby. It would put one username in king for 5 minutes and then change it to the next user
So by the end of the game it had like 40 king changes
The only use for it would seem to be either for fun or to get the most king changes in a game
There is a possibility two people running loops to get their names in king file. And these loops fighting each other for king that kept changing it every minute
Or just a crontab
gg @junior yoke
Thanks. Got to say, big admirer of that profile pic!
Gave +1 Rep to @rustic mortar
Just for sheer fun to make people wonder why they are king. While scans are running, add people that are in the channel to the loop, and once elevated, run the loop. Does not chattr or anything else. Just echos the next user in line to the file.
!docs koth
how do i get access to voice chat
you verify your discord with the @proud frigate bot using the following thingy:
!docs verify
ok
@junior yoke I have problems connecting to tryhackme servers
yo @thick socket
yoyo @timid hare
Thanks for connecting in DM. Awesome to make your acquaintance π
Gave +1 Rep to @steady ember
same like it continuosly ask for pass
does anyone want to play a game of koth?
haha thank you!
Gave +1 Rep to @junior yoke
ποΈ
has anyone come across BKR13 because I saw him a few times today and each time I want to play every service and port is shut down before I can break into a system and he disables ssh and the apache services. My question is if this is allowed on KOTH?
saw him before and he did the same thing
Yup,
He did the same with me .
BKR13 is in my koth lobby right now this should be fun.... do they really just shut down every service?
share invite link
it already started sorry
share it anways
so, does hermes_ssh work or you replaced it already @neon river
haven't done anything other than adding my name in king file
yeh I guess
anonymous ftp login didn't work actually so thought you'd turned it off
working fine for me
ah shit I only have the one(openvpn), filtering for players ips, that's a new one
and ports are closed or moved to higher port numbers π€·ββοΈ
I don't see ssh showing up at all lol
so I guess they really do be shutting every service down lol
@vapid storm ^
oh I see it now
vote reset, @vocal ginkgo @vapid storm
done
ah did you remove the chattr binary after changing the permission
this is really f**ing me up rn
add your own chattr binary?
too late now, been too long since I've played koth properly, no ordered files or binaries left 
Good Game @neon river had a lot of fun! thanks
Gave +1 Rep to @neon river
welp at least BKR13 didn't win
well, we kinda ganged up against him but he was also kinda cheating so no matter
trueπ I have to go complete some more rooms. I've really only done reversing and forensics... joined tryhackme to get into offensive and defensive security
if anyone sees them breaking rules again mention me or holmes or email at koth@tryhackme.com with enough proof.
cc: @vapid storm @vocal ginkgo
Sure!
What's the command to make king.txt unchangeable ?
chattr -i king.txt
And what's the command of like crontab to echo on king.txt every second?
crontab is too obvious imo(googleable anyways),
while :; do echo 'username' > /root/king.txt ; done make a script with this and run it in some obscure place like /var/lib/whatever
no, sorry, don't like random friend requests, but I can help here if you have further questions @zealous chasm
+i
what he said ^
Changing service ports are allowed right ?
Is that + or -
its 2:00am for you too, so you can understand @neon river
a simple - + mistake
+i makes it unchangeable
-i makes it changeable
yeh
Means if someone use +i for king.txt and someone else use -i , will he able to over write on it.
yes, but people remove the chattr binary before others can make king.txt changeable
so, you have to upload your own chattr binary or "recreate" the file
Ok this is new for me.
How we exactly suppose to create own chattr binary ?
Ok
or simply copy your own from /usr/bin/chattr if you're on linux
Thanks to make me rember the binary
Gave +1 Rep to @vocal ginkgo
That means there is no ultimate way to defend our name on king.txt
it's a ctf game after all, where patches exist exploits exist as well
you can find a static binary from busybox
Ok
There's one pinned message in #koth π
tried to upload my own chattr but it didn't work
chmod +x chattr
/usr/bin/chattr run that
lol
it's my chattr from kali /usr/bin
just like you told me yesterday to uplaod own chattr
Yeh, haven't tested it myself, try downloading it from busybox
ok hold on
is that this one ?
Yes, try it
you need static chattr binary. this one will work
Gave +1 Rep to @vocal ginkgo
π
which one will you suggest to defend name in king.txt
chattr or while loop
ideally, a mixture of both, so it echos the username, makes king.txt unchangeable, sleep for 2 sec, and repeat the process
what but if you make it chattr + i you might not able to overwrite it every couple of seconds using loop
something like
while :; do chattr -i king.txt; echo username > king.txt; sleep 2;chattr +i king.txt;done
that's the case if chattr exists on binaries
Perhaps sleep after chattr +i ... π
what he said ^^
we are deleting the chattr from binaries right ?
no, not in this case
Gave +1 Rep to @vocal ginkgo
just a general query;
what if we do like
while true; do wall texthere;done
this is probably broadcast the text and other's can't execute shell right
so will this violate any koth rules
or we can actually stop this broadcast ?
@vocal ginkgo
!docs koth
rules are there and for specific queries plz ask, koth mods or staff like "naughty" or "Mr.Homes"
@neon river
It doesn't really Break the rules but also not a good thing to do. You can bypass it by getting a non tty session
You can still execute commands even if they are spamming wall messages
ohh! , what's the command to spawn the non tty session ssh? @neon river
!docs koth
Hi guys, does this look familiar to anyone π
Nmap scan report for 10.10.49.2
Host is up, received conn-refused (0.15s latency).
Scanned at 2022-01-25 22:29:52 +03 for 0s
PORT STATE SERVICE REASON
9999/tcp open abyss syn-ack
23399/tcp open unknown syn-ack
was this the BKR13 user? thought they reported him
Back at it. He left port 9999 open this time π
So the king service would update when he replaced my name with his. Clever.
or incredibly dumb to resort to cheating π€·ββοΈ
let's ping @neon river to review this
don't say its not cheating
He has now taken port 23399 down as well, was trying to brute-force the ssh password:
Nmap scan report for 10.10.49.2
Host is up, received conn-refused (0.14s latency).
Scanned at 2022-01-25 22:36:53 +03 for 0s
PORT STATE SERVICE REASON
9999/tcp open abyss syn-ack
Email koth@tryhackme.com with screenshots
Well, all I have got is my rustscan outputs. That enough?
yep he's in a game with me rn and he's shut down all the ports except 9999
Latest game running, my first time attempting to compete and needlessly to say, I failed π
are we allowed to change a files permissions cause the guy im in a game with did that and i couldnt access the king.txt
you'll improve sooner or later
I'm only starting out in cyber, so I wasn't nearly as knowledgeable as I needed to be. So I know to keep studying and trying stuff out.
King.txt file locked? - A user might have used the chattr binary to stop even a root user editing the file.
They have been banned. Have fun now π
@junior yoke @vocal ginkgo @covert dawn
Good riddance

π
can you hear me .
why i cant join
you need to verify, follow this
!docs verify
!docs verify
How are there 100 reacts?
Because everyone wants to have fun π
it's cause there are a lot of scam bots that liked it haha
it's a part of a huge new scam
Hi quick question, are players allowed to take down a port?
Got a game where ssh seems to be closed.
its not allowed
Any other checks that I can do?
Thanks
Not sure if we are allowed to ask for help, if not please ignore
Just wanted to know if the above is a result of patching that was done by another player, and sort of what I could look at to learn more on it?
That's intended
Anyone else playing right now?
I'll play you
4 minutes left on wait https://tryhackme.com/games/koth/join/873842aab3567a39cf655ef5

