HackTheBox - TwoMillion

Поділитися
Вставка
  • Опубліковано 21 січ 2025

КОМЕНТАРІ • 72

  • @Agr0dan
    @Agr0dan Рік тому +38

    I’m glad you said you had trouble solving the invite code back in the day because so did I lol

  • @ITSecurityLabs
    @ITSecurityLabs Рік тому +15

    I am not the only one who had to lookup the invite code! Great box, brings back memories for sure

  • @Myk4my
    @Myk4my Рік тому +4

    This was one of the best videos you made. I love seeing your methodology and problem-solving techniques in the face of the unknown, it gives me the strength to keep learning.
    Do more like this, please!

  • @joyemoticon
    @joyemoticon Рік тому +19

    The invite code thing is like looking at something you wrote when you were in high school. You remember that it really broke your brain when you did it initially, but all the experience you have gotten since then has made it beyond trivial.

  • @arenmanukyan8527
    @arenmanukyan8527 Рік тому +63

    I really don't understand how this machine is considered "Easy", and i'm terrified what will the "Medium" ones be...

    • @waybetter4462
      @waybetter4462 10 місяців тому +12

      Welcome to the Hackthebox community!❤😅

  • @deesick_
    @deesick_ 10 місяців тому +5

    This box is so intimidating. If this is considered easy then I'm scared of what's to come

  • @cloudliving447
    @cloudliving447 Рік тому +2

    this is a different level of amazing watching, after solving this - still learned a lot

  • @lool7922
    @lool7922 Рік тому +3

    Great work - waiting for the next one

  • @souleymaneadellah1176
    @souleymaneadellah1176 Рік тому +7

    An ippsec vid on a Wednesday? This feels like when GoT episodes gets leaked 😂

  • @dailyversesforgod
    @dailyversesforgod Рік тому +4

    Do you go through the boxes before filming or are you just naturally talented? :) great video as always

  • @lindacupples3381
    @lindacupples3381 Рік тому +2

    Hey Ippsec, I have a question regarding the regex in remove_special_characters. I have seen this regex used in many web applications, some as apart of ID sanitisation in dynamic queries. I got them impression from your video that it'd be possible to bypass this regex. Would it be possible to comment on it further? It might even be a good separate video. Thanks

  • @techtimefly
    @techtimefly 9 місяців тому +2

    Using JS-Beautify 1.15.1 and CyberChef, both seem to fail to de ofuscate the javascript min.js file

    • @colmcarroll3413
      @colmcarroll3413 8 місяців тому

      I had the same issue but ChatGPT worked for me

    • @DeonDatDeal
      @DeonDatDeal 7 днів тому

      for me too did you ever figure this out???

    • @PPHY_GLND
      @PPHY_GLND 7 днів тому

      ​@@DeonDatDealon js-beautify options make sure "Detect packers and obfuscators?(unsafe)" is selected as well as "Space before conditional..."

  • @herc
    @herc Рік тому +4

    I saw this machine getting released on HTB, now it's no longer present. Is it only for you to show us your approach to solving machine or?

  • @papacanfly5639
    @papacanfly5639 9 місяців тому +1

    Any idea where he uploaded the next part of the video "Beyond Root- Adding overlay FS"?

  • @jojobobbubble5688
    @jojobobbubble5688 Рік тому +1

    I love everything about this and can't wait for you to complete the cliffhanger!

    • @ippsec
      @ippsec  Рік тому +3

      It will be slightly longer than I expected, it's a lot more complicated than I expected. But I'll certainly put something out there soon as I can. You can see I created an issue on Linux Exploit Suggestors repo :)

  • @patrickFREE.
    @patrickFREE. Рік тому

    so do you use everytime put, if you want to update smth?

  • @joaobeja2076
    @joaobeja2076 11 місяців тому

    I didn't understand why we would need to add the hostname to the hosts file? And how do we get to that conclusion by entering to the website and getting the not found result? (I started HTB a few weeks ago, I'm still a noob, can someone explain me?)

    • @ippsec
      @ippsec  11 місяців тому +1

      When doing these types of CTF’s there is no DNS Server. Some websites do virtual host routing, which makes DNS important. Editing the host file mimics having a dns server. I don’t remember how this box leaked the hostname but I’m sure if you watch from nmap, it’s probably around there. Normally it’s ssl certificates

    • @joaobeja2076
      @joaobeja2076 11 місяців тому

      It was from nmap!
      Thanks for the help !!

  • @CyberCrusader-l3g
    @CyberCrusader-l3g Рік тому

    Hey man do you know why i cant i get "Server Not Found" when i try to load up the site on that machine?

  • @solcloud
    @solcloud Рік тому +1

    Nicely done, thank you 👍

  • @dharanisanjaiy
    @dharanisanjaiy Рік тому +3

    I really missed "We have alreadyyyy rannnn itt "

  • @rutherford5872
    @rutherford5872 Рік тому

    How do you display your own IP in your terminal prompt? Please let me know

  • @leakim4975
    @leakim4975 Рік тому +1

    Do you have more videos of solving boxes without previous experience with them?

    • @ippsec
      @ippsec  Рік тому

      Some of the Easy ones back in like 2021 probably. There was a time when I did them more blind, but I started reviewing boxes before they went live to players, so its hard to do a true blind play through.

    • @leakim4975
      @leakim4975 Рік тому

      @@ippsec Ok thanks. Love your content and Im always learning something new from every video! Keep doing your thing!

  • @gee5889
    @gee5889 Рік тому +1

    Which computer and software do you use

  • @Simply_facts...-----382
    @Simply_facts...-----382 Рік тому

    sir i am a free user of hack the box and i cant get the virtual machine in my windows for longer time is there any other option to get virtual machine for free inmy windows to work for the machines in hack the box sir

  • @255py8
    @255py8 Рік тому

    first time seeing that kracken
    what is it? a custom machine made by you or a new server to crack hashes?

    • @ippsec
      @ippsec  Рік тому

      Its just a box I have on my network.

  • @ruthlozanorodriguez207
    @ruthlozanorodriguez207 Рік тому +1

    Is it possible that you will solve the soccer box without using sqlmap? I've been really struggling with it, plus I think its a really interesting machine. Regards from Spain :)

    • @ippsec
      @ippsec  Рік тому

      Nope I’ll use sqlmap. There are videos where I do Boolean injection without it

    • @ruthlozanorodriguez207
      @ruthlozanorodriguez207 Рік тому

      @@ippsec Okay! Thanks eitherway for all the content you give us ☺

  • @james_nt
    @james_nt 9 місяців тому

    how to copy text from tmux & pasting outside tmux ?

    • @james_nt
      @james_nt 9 місяців тому

      for now my discovery is to used shift and select text I want to copy and right click to paste it. Wonder, how do you purely used command :)

    • @DeadDinosaur
      @DeadDinosaur 4 місяці тому

      tmux-yank plugin will do the trick!

  • @pabloalfaro2595
    @pabloalfaro2595 Рік тому

    Do you prefer ferobuster or gobuster?

  • @rockedwow7217
    @rockedwow7217 Рік тому

    why do we need a header? and why should the header be a cookie?

    • @ippsec
      @ippsec  Рік тому

      Helps if you put a timestamp of where your question is. I don't know exactly what you are asking

    • @rockedwow7217
      @rockedwow7217 Рік тому

      @@ippsec sorry about that. the time stamp is 17:17

    • @ne5i_
      @ne5i_ Рік тому

      It’s because it’s an authenticated endpoint - you need the Cookie header for an authenticated session

  • @amieemaya9472
    @amieemaya9472 Рік тому +2

    Wow thank u

  • @Ms.Robot.
    @Ms.Robot. Рік тому

    Oh no, my calendar must be two days off‼️😅

  • @stanislavsmetanin1307
    @stanislavsmetanin1307 Рік тому

    Bravo maestro)))

  • @daniyalhassan9672
    @daniyalhassan9672 Рік тому

    ssh kracken command not given output as how in video instead it gives failed to resolve hostname or Service anyone can help me with this

    • @ippsec
      @ippsec  Рік тому

      Kracken is a box on my network, you can run hashcat on your computer

  • @fpvpdu
    @fpvpdu 4 місяці тому

    11:10
    Fun fact: you can't check "Remember me" on this box 😆

  • @Macj707
    @Macj707 10 місяців тому

    CHEF CRISP WUZ HERE!

  • @tudasuda5501
    @tudasuda5501 Рік тому

    Thnx!

  • @tg7943
    @tg7943 Рік тому

    Push!

  • @AUBCodeII
    @AUBCodeII Рік тому +1

    Ipp, you should create a box called "Your mom"

  • @caothanh9768
    @caothanh9768 Рік тому +1

    Oops! Go back to the old school :v

  • @FMisi
    @FMisi Рік тому

    31:07 interesting..

  • @candyyyq
    @candyyyq 6 місяців тому

    Woah what is kracken??

  • @filmyguyyt
    @filmyguyyt Рік тому

    Hi!

  • @sotecluxan4221
    @sotecluxan4221 Рік тому

    AAA!

  • @e4stark
    @e4stark Рік тому

    mice

  • @ctf59
    @ctf59 Рік тому

    Wtf?))

  • @pauljones5620
    @pauljones5620 Рік тому

    I'd like to understand more how the command injection vulnerability works.

  • @triplem3224
    @triplem3224 Рік тому

    I don't know why this box is rated as "Easy" it's pretty far from it