Hacking a Docker Container Registry

Поділитися
Вставка
  • Опубліковано 20 жов 2024
  • jh.live/chaing... || Scale securely with minimal, hardened, and 0 CVE container images to run your workloads with Chainguard! jh.live/chaing...
    Learn Cybersecurity - Name Your Price Training with John Hammond: nameyourpricet...
    Learn Coding: jh.live/codecr...
    WATCH MORE:
    Dark Web & Cybercrime Investigations: • Tracking Cybercrime on...
    Malware & Hacker Tradecraft: • Malware Analysis & Thr...
    📧JOIN MY NEWSLETTER ➡ jh.live/email
    🙏SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware
    🔥UA-cam ALGORITHM ➡ Like, Comment, & Subscribe!

КОМЕНТАРІ • 29

  • @_JohnHammond
    @_JohnHammond  2 місяці тому +31

    I should have done a better job emphasizing that this trick worked without any credentials or existing account, so it is "pre-authentication privilege escalation" (I showed it at the end, but wish I stated that earlier) 🔥PS, check out Chainguard! jh.live/chainguard

    • @_JohnHammond
      @_JohnHammond  2 місяці тому +3

      ​@@thenextbigthing8998 Thank you! I am planning to get back to livestreaming after DEFCON, hopefully in the next two weeks 😊

    • @Capt.Startrk
      @Capt.Startrk 2 місяці тому +1

      Hi @_JohnHammond can you please do a video on the hack that happened on crypto exchange Wazirx in India?

    • @malemmutum5049
      @malemmutum5049 2 місяці тому

      @@Capt.Startrk that would be nice!

    • @khadidiatouloucar3454
      @khadidiatouloucar3454 2 місяці тому

      Hht​@@thenextbigthing8998tt😢

  • @Jimzeel
    @Jimzeel 2 місяці тому +11

    It's these kind of walkthroughs that makes following you worth it. A clear, simple example of a known vulnerability and how to exploit is really usefull and worthwhile to watch when learning cybersecurity.

  • @cinderwolf32
    @cinderwolf32 2 місяці тому +32

    It's maybe an unusual way of doing things, but when I write Go API code I like to define a separate object for the API and DB object, and translate between the two in whatever code a given request is dispatched to. This forces me to consciously acknowledge each field that I'm letting through in both directions, and helps prevent both dirty data getting into the DB like here and also data leakage at the cost of additional verbosity.

    • @fraznofire2508
      @fraznofire2508 2 місяці тому +4

      That’s the correct way to do it, I believe they’re called a “data transfer object” where you define specific properties you want accessible/editable via your API and don’t include properties that shouldn’t be accessible outside of your own code

  • @simshady
    @simshady 2 місяці тому +8

    That's why one should use dedicated DTOs ;)

  • @Carambolero
    @Carambolero 2 місяці тому +1

    Finally a good content.

  • @valorsec
    @valorsec 2 місяці тому +1

    Can we have something about Browser Extensions acting as Infostealers ?

  • @mmkvhornet7522
    @mmkvhornet7522 2 місяці тому +1

    Great Video !

  • @Alain9-1
    @Alain9-1 2 місяці тому

    Thank you

  • @mrr0b0t-s6i
    @mrr0b0t-s6i 2 місяці тому

    Can you explain to us the road map for learning ethical hacking?

  • @ranacreed7671
    @ranacreed7671 2 місяці тому +1

    Ty master

  • @APTsec
    @APTsec 2 місяці тому

    Cool.

  • @noxious6725
    @noxious6725 2 місяці тому

    looking like vCenter ☠

  • @an3ssh
    @an3ssh 2 місяці тому +1

    this video: LGTM

  • @fadiallo1
    @fadiallo1 2 місяці тому +1

    Docker Container ?
    Again ?
    Help

  • @brownpaperbagyea
    @brownpaperbagyea 2 місяці тому

    🐐👑JOHN 🐹HAMMOND 👑🐐

  • @sunniglory514
    @sunniglory514 2 місяці тому +1

    💚

  • @AdamAdam-dn4st
    @AdamAdam-dn4st 2 місяці тому +1

    HoW tO hAcK a PdoCkEr cOmmtainer by me

  • @carsonjamesiv2512
    @carsonjamesiv2512 2 місяці тому +1

    YEAH,😀🎉

  • @rzvthepsycho69420
    @rzvthepsycho69420 2 місяці тому +2

    12 views blud fell off

    • @ODUyoutube
      @ODUyoutube 2 місяці тому

      What you mean blud

    • @TallShawnNetwork
      @TallShawnNetwork 2 місяці тому

      @@ODUyoutubesilly n-word ish

    • @slybandit8117
      @slybandit8117 2 місяці тому

      He just posted it when you viewed it. There are almost 5k views now. Yea, also “blud” WHAT??!!