HackTheBox Zipping

Поділитися
Вставка
  • Опубліковано 1 гру 2024

КОМЕНТАРІ • 29

  • @Cd6A0B
    @Cd6A0B 10 місяців тому +1

    Nice! I really like the second unintended method because it shows whoever discovered this, knew how the code works in deep depth and how to exploit it. That's something I need to get good at!

    • @ippsec
      @ippsec  10 місяців тому +2

      Haha nope didn't really know the code in depth. Had looked in depth after finding it, null bytes is something I try a lot and when it didn't throw an error at upload, but the file never existed. Started debugging it and discovered what happened.

  • @utkarshagrawal6060
    @utkarshagrawal6060 10 місяців тому

    Amazing. Always great to see ippsec video

  • @mohammadhosein6847
    @mohammadhosein6847 10 місяців тому

    I always learn sth new by watching you videos.TY

  • @xrunner55
    @xrunner55 10 місяців тому

    I remember popping this box. Figuring out the proper formatting for the file extension bypass was a pain. Trying all of them and also figuring out how to format it was educational. Once I got a foothold with that, it was a lot easier.

  • @anonymouspotato6017
    @anonymouspotato6017 10 місяців тому +1

    Great video! I actually have a few questions about the machine. There're actually two files that we can perform SQLi : product.php as shown in the video and cart.php at product_id parameter. However, we cannot write files with cart.php and I couldn't figure out why.
    Also for the lfi part, we can't include the file if the php file was written to /tmp directory. I was able to perform it on my machine but the machine didn't like /tmp.

    • @ippsec
      @ippsec  10 місяців тому +2

      /tmp is a dangerous directory because of SystemD PrivateTmp. MySQL and Apache have different tmp directories.

  • @Yoyo-qn4mv
    @Yoyo-qn4mv 10 місяців тому

    Learned so much from this one :) Tnq sir

  • @AUBCodeII
    @AUBCodeII 10 місяців тому +29

    You can't spell Zipping without Ipp

  • @stefan.b7812
    @stefan.b7812 10 місяців тому

    It is really hard to see urls and payloads on browser address bar. Can you zoom a little when working on address bar? Thanx in advance.

  • @0xmoriarty36
    @0xmoriarty36 10 місяців тому +2

    Keep it up

  • @atnguyenthanh5410
    @atnguyenthanh5410 2 місяці тому

    Bro that's insane

  • @HackerBabaOfficial
    @HackerBabaOfficial 10 місяців тому

    Can you kindly tell which keyboard you are using ?

    • @ippsec
      @ippsec  10 місяців тому

      Ducky Zero with cherry mx reds.

  • @perfectshow-bx1ov
    @perfectshow-bx1ov 10 місяців тому +1

    Sir I have many issue's on bookworm machine please could you help me to solve it 😉

    • @trustedsecurity6039
      @trustedsecurity6039 10 місяців тому +2

      There is tons of discord server where people do box together or help others people ;) That's also why i find the ranking a bit useless for most people, i interviewed a guy who was 48 or 58 on the ranking but didnt answer basic web question like what is a SSRF, didnt know what Magic bytes are...

    • @perfectshow-bx1ov
      @perfectshow-bx1ov 10 місяців тому +1

      @@trustedsecurity6039 thanks for your suggestion thanks a lot 🫡

  • @tg7943
    @tg7943 10 місяців тому

    Push!

  • @y.vinitsky6452
    @y.vinitsky6452 10 місяців тому

    Yay

  • @riezzo1350
    @riezzo1350 10 місяців тому

    i REALLY struggled with this one

  • @0x2e2e2f
    @0x2e2e2f 10 місяців тому

    Hi guys, beginner quest here, I should avoid use Ubuntu as main operating system ? Ippsec uses windows ?

    • @younests.1824
      @younests.1824 10 місяців тому +3

      Ippsec uses Parrot OS - HackTheBox Edition

    • @0x2e2e2f
      @0x2e2e2f 10 місяців тому

      @@younests.1824 vm or main host ?

  • @sand3epyadav
    @sand3epyadav 10 місяців тому

    Miss you sir , plz repying

  • @0xUnixy
    @0xUnixy 10 місяців тому

    قولها تاني كدا يحب

  • @houssam3078
    @houssam3078 10 місяців тому +2

    I hate watching your videos. I try hard to be on your level but I can't. You make things look easy, I'm thinking of staying away from this field

  • @felixkiprop48
    @felixkiprop48 10 місяців тому

    peace