TryHackMe! Skynet - Wildcard Injection
Вставка
- Опубліковано 4 вер 2024
- Come play the GuidePoint Security CTF! go.guidepoints...
For more content, subscribe on Twitch! / johnhammond010
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
PayPal: paypal.me/john...
E-mail: johnhammond010@gmail.com
Discord: johnhammond.or...
Twitter: / _johnhammond
GitHub: github.com/Joh...
That python bruteforcer is a lifesaver
True
Not Working For Me... Another Room By The Way...
Nice vid John :)
Btw : The "balls have zero to me" stuff was from an experiment, letting 2 AIs talk to each other with a set alphabet but no actual grammatical rules.
After a while, they just came up with their own way of communicating :D
As a developer - very interesting to see your approach to finding weaknesses. I can sort of see the fun in this kind of activity, the lure of the dark side :)
love the content and the way you explain everything so thoroughly! id also much rather see you walk through a script like that than if you didnt
john: makes a py script out of nothing in less than 2 minutes
me on google: "how to declare a variable"
True XD
Learn python. It'll be worth it and fun to play with
yeah its straight tho!
😂😂
True that AHAHHAHA
heretic, not confirming with ls after mkdir.
Lmfao
thats true lol
i have never had an original experience huh
Nope
RIP all terminator references.
wow... exploiting the tar wildcard to set the SUID bit on /bin/bash is so freaking smart and cool man, I was stunned by how amazing that was. I'm trying to better myself at pentesting and John, you are teaching me amazing things! Thank you so much!
That tar exploit is INSANE, how have I *never* heard of "the * exploit"??
Learnt a lot through this live walkthrough, well narrated and explained.
The best part is the way you put out your way of approaching the next possibility, that definitely helped me in knowing how to process my thoughts during a CTF
this video was awesome! i learned Sooooo much! thank you so much john, your the man brother!
Love this approach John. Its raw, honest and not contrived (i.e. doesnt come over as you've already completed it and are now just going back through the motions!). Its far more enjoyable to listen to your thought process this way, and you still seem to manage to keep things easy to understand. Nice work :-) Subbed.
And thanks for introducing me to Terminator. Its my new favourite 'tmux' alternative :-) Now to work out what distro you are using...... ;)
Sir u really are a very humble person ❤️❤️
Ah Skynet. One of the best loved THM rooms, I believe. Out of curiosity, I just looked at the conclusion in my own notes and it says "probably my favorite ctf to date." :)
Been loathing reading all those articles about wildcard injection....
Thanks for the video man :)
curl to python... :O
how did i not know about this, where has this been my whole life!?
I was literally sitting here and saying "bro ... that would helped me so many times" xD
Holyyyy that curl to python requests and the bruter you wrote just blew my mind. Good stuff John I really love your videos.
I was as excited as you are when you privilege escalated. This is simply amazing.
John please stop apologizing for doing exactly what we need (going into detail about how you as a pentester would approach this) Its exactly why I love this channel.. its not generic like the others. So please stop and carry on.
I wanted it for 1 time and will be watching it for a few more times to note all the things taught here. Thank you so much for your efforts. I do respect you and your talent. 😇
John, I must say please do more of these vids are awesome and the talking through your process is exceptional
I don’t know what is going on but this seems interesting haha
You should learn python it’s fun
@@brian3947 I’ve learnt python but this is not just python haha. It’s also bout networking and managing file stuff
*John:* "Oh, we have a personal SMB share named milesdyson, that seems random."
*Me:* Wait... does John not realize who Miles Dyson was in the Terminator universe?
*John (5 mins later):* "I actually haven't seen the Terminator movies."
*Me:* ...aha, well that explains that.
please always go off on tangents like the python one in this video, if anything..... go on to do a video about the tangent and go off into a tangent in that video and then do a video of that tangent and so on and so on, your videos quite literally pushed me in the direction of doing my (now a year in) degree in cybersecurity and the tryhack me rooms, you sir are a legend , thank you for your work
dude, you rock! This was awesome. when I saw the bash-4.3# i was like 😁😁😁
super creative privelage escalation john! amazing content please keep it coming!
Had a great time watch you work your magic. Im still learning and watching your videos really helps! Thanks john
Amazing videos with great explanations to beginners instead of just cruising through all the answers without explaining the reasoning behind anything.
This is probably the most educational video on the topic I've ever seen, and I've seen a lot. Amazing.
Just found your channel and subscribed. Awesome videos and explanations
Thanks for this I was having trouble with the tar wildcard portion!
I liked how you used curl to trigger the call back. I will start bringing that into my process
It seems like I've found my new favourite channel
Thank you very much for each video you upload. I am a cybersecurity student and always I get upset, I put one of your video and get motivated to keep on.. thank you 🙏
Awesome! You are online person out there who cares to explain stuff! Love Your videos!
This video is my favorite so far
Hey John, been loving how much detail you go into when doing these videos. Keep up the great content!
i enjoyed every single moment of this
nothing better then this..john...explnation is wonderfull :)
The gibberish email was a reference to a Facebook research project where two AI supposed to talk to each other essentially descended into madness.
Creepy shit, did recognize it instantly :)
i learned a lot from your videos thanks
this video inspired me more...thanks John
This was incredible. Thanks for the content John!
This was so much fun!
Great video like walk throughs to see your process.
CTFs are so fascinating ..enjoyable content! keep it coming!
I can’t believe that I have seen a 1 hour video on UA-cam and want more
You are amazing! Thanks for the walk through!
LastPass better sponsor you now. Nice placement right there.
Can't tell how much I appreciate this was so confused at root privilege escalation lol
On the part where you used python to check for logins i'm pretty sure you could use a session to make it a lot faster. s = requests.Session() s.post(url)
The problem seems to be SquirrelMail taking time to process requests, setting up a session won't help with it
Omg. More content! My brain cant keep up. Its literally regurgitating info at this point but im plugged back in . Leggo peeps and thank you once again Mr John !
loved your bin bash suid. My lazy version is simply doing that to the /etc/passwd and login as root. Have all the info I need in a file that I just copy paste everytime! Nice and quick
I'm not gonna lie, I was super annoyed once I realized how much work had to be put in at the end lol. I thought I was a rockstar until it got to the cuppa part. Then getting that stable shell and actually figuring out what to do? Infuriating. Thank you for your time an mentorship doing rooms like this for us. I wish this was something I could do on my own, but maybe THM is designed just for walkthroughs just like this so we can learn.
that "what" at 18.30 has a separate fan base
Please keep making contents like this, we really enjoy watching your vids ,thankss
This was one of your best vids so far
that wildcard priv-esc is just super nice
Awesome video
that SUID trick was cool
Miles Dyson is the father of Skynet
That was incredible thanks for your work
Thanks John, I always learn something new
12:50 Very cool !
OMG!!! Skynet! Don't they eventually take over the world and cause its destruction that ends up with Arnold coming back from the future???
Oh. Got to the SquirrelMail bit and then realised :-( Doh!!
you explain everything so simply ❤️ thanks bruhhh 😘😘
great video and awesome explanation
yo awesome vid, crystal clear thanks
Thank you very much.
Excellent
Me sitting at home waiting for videos :- nothing happens for weeks.
Me travels for 5 days :- 2 videos posted 😂
Nice execution.
Awesome John Hammond but you let me down by not watching the terminator movie just kidding, if you do get the chance only watch 1 & 2 don't bother with the rest. lol
I wanted to scream at the screen: the CMS password was in that mail! :-D
But damn, what actually happened was much better.
Thank you!
Good work. Well done. Learned a lot!
really great live premiere and overall video!
Thanks for another fun and educational video boss!
John Hammond for president everyone!
When you got to that Miles Dyson Personal Page i was sure that the picture had steganography in it.. :D But where it continued were so much better
Thank you for an amazing informative educational video ❤️
so happy that ur channel exists
So awesome!
Very nice, thanks for showcasing your way of solving this room. I tried it this morning before I looked at your video. Since I cannot code in python I had a similar script as bash script, but never made it working because I forgot sending the hidden fields ..
I don't know if the room is an easy one, I was lost after finding the user.txt
Still a lot to learn I guess :)
Great content
Awesome video!
@John, thanks
So clear, so good!
Simply a huge thanks ✊
Hello John, could you do the Daily Bugle room on T.H.M.? I love the way you approach things and explain them.
4:13 suddenly I have a strange urge to hit the subscribe button
Extremly funny, thank you.
I love it! thank you.
Great content John, could tell you hadn’t watched the terminator movies once you seem to overlook the miles dyson reference. :-)
What sort of hardware and software setup would you recommend for a beginner?
Nice video. Learned a lot from that.
this took me like 5 hours before i looked at this for the tar wildcard thing
Sweet Video! Didn't understand 95%, but it looked cool :)
dude this is awesome!
so much fun
thank you very mush. this was helpfull