Hack The Box - Flight

Поділитися
Вставка
  • Опубліковано 6 лис 2024

КОМЕНТАРІ • 35

  • @BroodPitt
    @BroodPitt Рік тому +13

    Yes please make a video of a box rebuild! 👍

  • @null_1065
    @null_1065 Рік тому +8

    Thanks Ippsec

  • @aaronaguilar2238
    @aaronaguilar2238 2 місяці тому

    Very insightful box! Thank you!

  • @_hackwell
    @_hackwell Рік тому +12

    Hi! could you make a video about how you rebuild your box ? We all have our own way I guess

  • @fxs5501
    @fxs5501 2 місяці тому

    There is also a way to exploit the seprivilege with potato
    Good Video!

  • @KellenBegin
    @KellenBegin Рік тому +1

    great video, also a box rebuild video would be awesome

  • @haoming5630
    @haoming5630 Рік тому

    This is literally the besst machine so far

  • @sb77de
    @sb77de Рік тому +1

    that tmux situation got clearly out of hand at some point 😆

  • @gmabreak
    @gmabreak Рік тому

    the goat! :)

  • @stevejones371
    @stevejones371 Рік тому +2

    Around the 20 minute mark - my brain exploded. I'm starting to question whether or not IPPSec is human or not. Are you an AI bro?

  • @Naneto_00
    @Naneto_00 Рік тому

    Nice job

  • @sand3epyadav
    @sand3epyadav Рік тому

    I love ippsec

  • @yuyu-ce4fz
    @yuyu-ce4fz Рік тому

    Nice

  • @glens6145
    @glens6145 Рік тому +2

    The real curl binary now lives in Windows/System32 if that makes things easier. Not sure what version of Windows they started doing that with though

  • @lool7922
    @lool7922 Рік тому

    thanks

  • @RobertPodosek
    @RobertPodosek Рік тому

    What linux distro do you run for hacking? Kali?

  • @Lapatate-s1l
    @Lapatate-s1l 8 місяців тому

    Hi . Nice videos . I don’t understand how did u have an smb connection by manipulation de RFI url . What is happening on the url ip/please/subscribe . I didn’t understand this part of the video . The script only prints content of a file . Can you explain me please ? Thank you very much .

    • @splendorblackman2487
      @splendorblackman2487 6 місяців тому

      I believe we try to make a smb connection back to our attacker box, and when it tries to connect it gives the user name/hash and we capture the traffic with responder. Since the one trying to make the connection is a service (svc_apache) we get those credientials. As far as I am aware, AD stuff almost everything communicates with their user/hash combo

  • @lumikarhu
    @lumikarhu Рік тому

    thanks, i learned a lot, like uploading desktop.ini and catching the response but i'd be still stuck at the kerberos appool part. gotta try harder i guess. BTW please do a rebuild video!

  • @tg7943
    @tg7943 Рік тому

    Push!

  • @rmcmahon1000
    @rmcmahon1000 Рік тому

    Can someone please let me know why RunAsC is needed and can't just use PS credential Object?

    • @ryuzaki1705
      @ryuzaki1705 10 місяців тому +1

      Because PS credential object works when you have a real terminal so when you are connected throught ssh, rdp, ecc..
      If you are using meterpreter or another kind of reverse shell it will not work because is not "native"

  • @abyanhafiizh-3065
    @abyanhafiizh-3065 3 місяці тому

    what a brainfuck machine 🔥

  • @stackcanary3368
    @stackcanary3368 Рік тому

    Did you leak your public IP ?

  • @kazhiroma9736
    @kazhiroma9736 Рік тому

    Do you use a VPN to connect to HTB besides the VPN they provide to connect to it. Like one to hide public IP

  • @yuyu-ce4fz
    @yuyu-ce4fz Рік тому

    Can I use potato in iis priv?

  • @RajatSharma_1111
    @RajatSharma_1111 Рік тому

    Hi Ippsec, I am testing one box and ports that are open are 80, 443 and 3389. Port 80 and 443 opens the same web page and its a login screen. I have ran sqlmap, able to enumerate database name but not the tables. getting some errors. Bruteforced dirctories, but nothing interesting ad also ran bruteorce for 3389 but no luck
    Can you pleas perovide any inputs?

  • @EvaristeGwanulaga
    @EvaristeGwanulaga Місяць тому

    Do you have some minutes for me to talk to you about our lord and savior exegol?

  • @AUBCodeII
    @AUBCodeII Рік тому

    What's going on, my politically incorrect racial epithets, it's ya boy Ippsec

  • @flrn84791
    @flrn84791 Рік тому

    How was this box seriously rated as hard? 😂🙈