Tier 1: HackTheBox Starting Point - 6 Machines - Full Walkthrough (beginner friendly)

Поділитися
Вставка
  • Опубліковано 7 лис 2024

КОМЕНТАРІ • 104

  • @uv8575
    @uv8575 2 роки тому +7

    I read walk-throughs either when get stuck for a while or after the challenge, and your videos are explaining better + I get more tips on other tools/techniques.
    This will be my way moving forward: starting point box -> walk-through -> your video

  • @_CryptoCat
    @_CryptoCat  2 роки тому +6

    Since making this video, new machines have been added to the Tier 1 Starting Point, here's those videos:
    Responder: ua-cam.com/video/R8GOLiKIA1k/v-deo.html
    Bike: ua-cam.com/video/_JUakU4qGug/v-deo.html

  • @kttoc6260
    @kttoc6260 2 роки тому +2

    Explain very clear, before thinking for a long time, see your video be suddenly enlightened

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      awww that's great! thanks mate 🥰

  • @AbdelrahmanMostafa-wi1io
    @AbdelrahmanMostafa-wi1io Місяць тому +1

    I noticed you heart almost every comment in this video, so I just wanted to say I really appreciate your content

  • @BOMBPHONICS
    @BOMBPHONICS Рік тому +1

    THANK YOU! super new yet still completed that module on HTB but didn't yet understand what was happening. Definitely subscribing!

  • @chelrob2
    @chelrob2 Рік тому +1

    You make very difficult subject very approachable and fun. Thank you sir

  • @Hckr-ei2xj
    @Hckr-ei2xj Рік тому +1

    well taught and easy to follow these tutorials. thanks

  • @Suviiii69
    @Suviiii69 Рік тому +2

    ❤️❤️❤️really helpful thanyouu 🍃❤️

  • @Phantomroot-b2m
    @Phantomroot-b2m 4 місяці тому +2

    I learned much in this video

  • @stig7160
    @stig7160 Рік тому +2

    For pennyworth I didn't get hydra to work for bruteforcing as it didn't detect the "Invalid username or password" text, but using burp suite intruder with cluster bomb attack I managed to bruteforce the jenkins credentials pretty quickly.

  • @AidinNaserifard
    @AidinNaserifard 2 роки тому +3

    Congrats bro👍

  • @shba9300
    @shba9300 Рік тому +1

    omg i'm really overthinking this because i saw " Message signing enabled but not required " i thought it was smb relay attack so i used responder and waited for hours to get a hash but it was simply blank password? why is that this is really frustrating!!
    thanks for your content though, very helpful.

  • @patrikhruby1697
    @patrikhruby1697 Рік тому +1

    CryptoCat is the God. Bless You!

  • @the_snow9068
    @the_snow9068 2 роки тому +3

    How did you make gobuster showing wordlists as you type it in the terminal, i mean you wrote gobuster dir -w /usr/share/wordlists/ and it brang you the options like api_routes.txt and dibuster/ right in the terminal, because whenever i type gobuster dir -w /usr/share/wordlists/ it tells me that i didn't mention url, i know that u need to mention it so it works, but i don't want to loose time searching wordlists manually in filesystem and have them just like you (coming as i write the line to activate gobuster).
    Time stamp is 36:00 , crocodile machine.
    If you would help, it would be awesome.

    • @_CryptoCat
      @_CryptoCat  2 роки тому +1

      If you hit the tab key it should autocomplete, so hit it twice to bring up possible options. Really saves time!

  • @S2eedGH
    @S2eedGH 2 роки тому +3

    really perfect ! may I ask how did you link the folder to Github repo to get latest version of the tool ?

    • @_CryptoCat
      @_CryptoCat  2 роки тому +1

      Thanks mate 🥰 Is this for the PayloadsAllTheThings repo? You could just clone it to the desktop but I cloned it somewhere else then just created a shortcut (symlink) to it on the Desktop. I then use a simple script to recursively update all git repos periodically (although there's numerous AUR solutions available).

    • @S2eedGH
      @S2eedGH 2 роки тому +1

      @@_CryptoCat thx for replay, what I'm looking for is how to update all repos that I cloned before and stay up to date

    • @_CryptoCat
      @_CryptoCat  2 роки тому +1

      @@S2eedGH Ah OK yep, I use a script like this: gist.github.com/douglas/1287372
      I just run every few days from my home directory and it recusively updates all the repos 😀

    • @S2eedGH
      @S2eedGH 2 роки тому +1

      @@_CryptoCat Thanks for your effort man, keep going good work we learned a lot from you

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      @@S2eedGH Np! Great to hear, ty 🥰

  • @_techwaves
    @_techwaves 2 роки тому +4

    Great video man! I learned a lot of new things 💙

  • @Deadian781
    @Deadian781 10 місяців тому +1

    admin'# with a random password worked for me

    • @_CryptoCat
      @_CryptoCat  10 місяців тому

      Nice! Love the username 😉

  • @MarioLoco03
    @MarioLoco03 2 роки тому +4

    In Pennyworth, searching for the default password seemed like a misdirection on part by HTB. I found no such list related to jenkins. Only the file location for an "initial password" and it was not even close to what was on the list of default PWs provided by HTB.

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      Yeh same, I couldn't find the list they were referring to 😆

  • @mariusohnenamen5366
    @mariusohnenamen5366 8 місяців тому +1

    Thank you so much for your videos.

  • @madanybah8635
    @madanybah8635 2 роки тому +3

    Thank you very much for this video, I learned a lot

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      Great to hear! thanks 🥰

  • @丁泽楠
    @丁泽楠 Рік тому +1

    In the pennyworth video, you can get the version information of Jenkins by visiting /oops or /error.

  • @joshuafeldman3762
    @joshuafeldman3762 Місяць тому +2

    if u have an error on sequel mysql -h 10.129.60.3 -u root -p --skip-ssl do that

  • @ibrahimusman-v9m
    @ibrahimusman-v9m Рік тому +1

    what edition of parrot os should i use for the academy, is it the security or home edition?

    • @_CryptoCat
      @_CryptoCat  Рік тому

      Go with the security edition! It comes with a lot of pentesting tools. If you install the home edition it's OK too, you'll just have to install/configure more apps as you go.

  • @malcolmbulls6741
    @malcolmbulls6741 2 роки тому +3

    Can you do a update of this video I cant find a tut for Responder machine anywhere it must be new cuz nobody has it on youtube Or just a seperate tut just for responder its after Crocodile now not ignition. At least in my HTB it is.

    • @_CryptoCat
      @_CryptoCat  2 роки тому +1

      Wow, that was a fast request, Responder was just released today! 😂 I'll have a video up for it at the start of next week 😉

  • @iEv0lv3_
    @iEv0lv3_ 2 роки тому +3

    Show how to solve the new registration method. It's been updated since all posted tuts

    • @_CryptoCat
      @_CryptoCat  2 роки тому +3

      interesting, thanks for the tip! if it's allowed by HTB's strict walkthrough policy i'll definitely cover it 😊

    • @iEv0lv3_
      @iEv0lv3_ 2 роки тому +1

      @@_CryptoCat awesome

  • @k.o.o.p.a.
    @k.o.o.p.a. 2 роки тому +3

    Whats subl? How do i make a file that sqlmap accepts

    • @_CryptoCat
      @_CryptoCat  2 роки тому +1

      subl is Sublime text editor: www.sublimetext.com, but you can use any text editor. Just copy and paste the request from burp suite or firefox dev tools into your text file and pass to SQLMap with the -r flag 😉

  • @scwyldspirit
    @scwyldspirit 2 роки тому +2

    So I have a question about two of the Academy machines that I am having trouble with. In the Getting Started and Web Request modules if I try and run a ping on the box I get nothing back. Do I need to add the entry to the etc/hosts file?

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      You won't need to add to the hosts file if you're accessing by IP address (not domain name). Double check your VPN connectivity; I haven't tried academy but presumably it uses a different config to HTB starting point. If you can't get it working, check the forum or discord for more help: discord.gg/hackthebox

    • @scwyldspirit
      @scwyldspirit 2 роки тому +1

      @@_CryptoCat Yep I was able to gain access and solve the challenge

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      @@scwyldspirit Great! 😊

  • @Alex-vi6iz
    @Alex-vi6iz 5 місяців тому +1

    hi sorry to comment on an old video, but I spent like 3 hours trying to brute force the login page with hydra and ffuf on Pennyworth 😂, only to realize now after watching the vid, it is not possible in the traditional way. May I ask in this case if it would be possible to somehow brute force the login using another way ? Couldn't really find much online for this

    • @_CryptoCat
      @_CryptoCat  5 місяців тому +1

      Hmmm been a while since I looked at it but does this help? cloud.hacktricks.xyz/pentesting-ci-cd/jenkins-security#bruteforce

    • @Alex-vi6iz
      @Alex-vi6iz 5 місяців тому

      @@_CryptoCat really missed this one, I should check out hacktricks more often, many thanks

  • @pavi013
    @pavi013 5 місяців тому +1

    Appointment was little bit confusing, but it was easy when i got it.

  • @aryanpatel2188
    @aryanpatel2188 2 роки тому +2

    Fast make video in tier 2......love your work......from india ❣️

    • @aryanpatel2188
      @aryanpatel2188 2 роки тому +1

      What's your qualifications....?
      And what you work as any company....?
      How many years you had in enter security analyst ....?
      Plz answer this question

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      thanks mate 🥰 will try and get the tier 2 done next week 😉

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      so many questions 😆 most of my qualifications/experience is listed on my linkedin - www.linkedin.com/in/cryptocat

  • @Andrew-bs7xx
    @Andrew-bs7xx 2 роки тому +2

    I beleive the question "what symbol do we use to comment out parts of the code?" is referring to bash.

    • @_CryptoCat
      @_CryptoCat  2 роки тому +1

      I can't remember the question you are referring to but you're right, '#' is used for single-line comments in bash. It's also used for many others, e.g. python, perl, SQL 🙂

  • @khurrammobiles
    @khurrammobiles 2 роки тому +2

    Thanks you sir, your video helping me a lot..
    Unfortunately sir, I'm facing some problem
    When i execute the command "nmap -p- -sV ip" so it's took a lot of time, upto hours

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      Could be connectivity issues. If everything is OK with your network, try resetting the box and if that fails, change the VPN server (redownload connection pack).

    • @khurrammobiles
      @khurrammobiles 2 роки тому +1

      @@_CryptoCat thanks you.. my problem solved by adding" -T4 "

  • @Starmanfansunofficial
    @Starmanfansunofficial 2 роки тому +2

    thanks!

  • @junaidjaved4792
    @junaidjaved4792 2 роки тому +3

    Perfecttttt

  • @DigitalGhost0
    @DigitalGhost0 2 роки тому +2

    nice video

  • @localhost4356
    @localhost4356 2 роки тому +2

    Nice

  • @devmelonroblox
    @devmelonroblox 2 роки тому +2

    Task 4 is incorrect for me..

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      Task 4 on which machine? 😆 Can you give me timestamp and a bit more info?

  • @naifalthbaiti4921
    @naifalthbaiti4921 2 роки тому +2

    great

  • @BassemInJapan
    @BassemInJapan 10 місяців тому +1

    gg

  • @DamienThorn5175
    @DamienThorn5175 2 роки тому +2

    No Bike machine :(

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      Oh damn, I missed the new machine release! When I've got some time I'll re-sub to the VIP and make a walkthrough 😅

    • @DamienThorn5175
      @DamienThorn5175 2 роки тому +1

      @@_CryptoCat thx mate

  • @minhquan4115
    @minhquan4115 Рік тому +1

    why can't i access the url?

    • @_CryptoCat
      @_CryptoCat  Рік тому

      What error do you get? Check VPN connection? Reset box?

  • @CaraVermelha33
    @CaraVermelha33 2 роки тому +2

    I pass hour on submit flag and the thing was on my face

  • @tristan3006
    @tristan3006 2 роки тому +2

    good content, but the hackthebox vpn are just so broken and they just don't work

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      Free or VIP? 🤔🤑

    • @tristan3006
      @tristan3006 2 роки тому +1

      @@_CryptoCat I think it was VIP

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      @@tristan3006 Oh OK, maybe try changing servers (although might be only one for starting point). I've had problems with free VPN in the past, less so with VIP.

    • @tristan3006
      @tristan3006 2 роки тому +1

      @@_CryptoCat Thx yeah there was a little problem but I tried again and it worked

  • @kaiahnung8326
    @kaiahnung8326 2 роки тому +2

    unfortunately i cant connect to the mariadb.
    mysql -u root -h 10.129.84.254
    errormessage: ERROR 2002 (HY000): Can't connect to server on '10.129.84.254' (115)
    i can connect to my local server with
    mysql -u root
    so how can i connect to the target mariadb?

    • @_CryptoCat
      @_CryptoCat  2 роки тому

      Double check steps in video / official PDF walkthrough. If that fails, check the hackthebox discord and/or forum for support 😉

  • @gigabitestudios
    @gigabitestudios 2 роки тому +3

    if you did
    sudo mysql -h $IP
    it would show you the version

  • @wikeff
    @wikeff Рік тому +2

    woaw, in Appointment I just put login admin and password: aa' OR 1=1 --

    • @_CryptoCat
      @_CryptoCat  Рік тому +1

      nice! there's a few ways to do it 😊

    • @beyrin2024
      @beyrin2024 Рік тому +1

      I guess, they changed it again and for me it didn't work. But it works with # as comment symbol. a' or 1=1#

    • @wikeff
      @wikeff Рік тому

      @@beyrin2024 Try to put a space bar after the -- and see if it works :) >a' OR 1=1 -- <
      But yeah, they might have changed it! Nice workouround