TryHackMe! [Web Vulnerabilities] Local File Inclusion

Поділитися
Вставка
  • Опубліковано 4 лис 2024
  • If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
    E-mail: johnhammond010@gmail.com
    PayPal: paypal.me/johnh...
    GitHub: github.com/Joh...
    Site: www.johnhammond...
    Twitter: / _johnhammond

КОМЕНТАРІ • 108

  • @MrTheMemes
    @MrTheMemes 4 роки тому +45

    Thanks John! I'm a newbie out here in the world of cybersecurity, your videos are helping me out A LOT. Keep it up man!

    • @_JohnHammond
      @_JohnHammond  4 роки тому +10

      Very happy to hear that, thank you so much! And thanks for watching!

    • @naifal-anazi4525
      @naifal-anazi4525 4 роки тому +1

      @@_JohnHammond that's true

  • @sechvnnull1524
    @sechvnnull1524 4 роки тому +6

    Fantastic job! Every thing that you do start to finish is vitally important. Your doing much more than simply giving answers to rooms; You are teaching your thought process and a general outline one should take each and every time. Repetition is a great teacher and having a structured strategy to follow is what it takes to succeed. So just wanted to encourage you and thank you for your hard work and time!

  • @Sandesh98147
    @Sandesh98147 4 роки тому +8

    Youre not losing quality and anytime you feel like it, you can always slow down the video upload freq. Im sure a lot of us will understand. You do amazing work and I dont want you to get burned out by it.

  • @jd-raymaker
    @jd-raymaker 4 роки тому +38

    tip on socat if you don't want to bind or reverse the connection:
    sudo socat STDIN EXEC:/bin/bash

    • @_JohnHammond
      @_JohnHammond  4 роки тому +14

      Oooh! That is AWESOME! That's not even in GTFOBins, you should definitely submit a pull request! And thanks for watching!

    • @jd-raymaker
      @jd-raymaker 4 роки тому +9

      @@_JohnHammond pull request submitted :)

    • @abdullahyasin3055
      @abdullahyasin3055 3 роки тому +1

      Great man i did using your trick and its included in gtfobins rn :)

    • @YousufKhan-pe9wy
      @YousufKhan-pe9wy 3 роки тому

      @@_JohnHammond nice wabsite i love yiu

  • @spigels4532
    @spigels4532 4 роки тому +3

    Hey man, I'm new to your channel but wow, have been loving your content! I've learnt more just watching and listening to you than I have picked up in years. Thanks! and I'll see you around.

  • @mcvaluemenu
    @mcvaluemenu 2 роки тому

    this video is a life saver. sometimes THM doesnt have things portrayed thats easy for me to understand. you have helped a lot.

  • @HabibsWorld96
    @HabibsWorld96 3 роки тому

    Thanks & respect John! I'm a newbie from Bangladesh💓💓

  • @tanawatmunmueang7924
    @tanawatmunmueang7924 3 роки тому

    I used to watch your videos when I was 14, learning how to making games in python. Now I am in uni and here you are with your amazing videos. Thank you!!!

  • @FernandoGonzalez-kc2vl
    @FernandoGonzalez-kc2vl 4 роки тому

    Ok im addicted to this channel. Good work ! Greetings from Argentina

  • @mattstorr
    @mattstorr 3 роки тому +1

    I know this is an older video, but the difference between this and your latest ones is that you take more time in the later ones. You zoomed through this at such a pace, wildly alt-tabbing between pages that it was (at times) difficult to follow. I found myself having to constantly stop the video and try to work things out by looking at the image rather than listening to your voice. Still, learnt something I didnt know, so keep up the great work :-)

  • @jamesfinlay1364
    @jamesfinlay1364 3 роки тому

    Keep up the great work man. I just subscribed to tryhackme with 0 experience and I’m loving the website.

  • @johnhack67
    @johnhack67 2 роки тому

    Hey John. Fantastic work mate.

  • @tristankeller7875
    @tristankeller7875 4 роки тому

    John "HAMMER-TIME" Hammond!!! Luv ur stuff! lol n applause! tnx 1000 for entertaining with your amazing skills!!

  • @راميابراهيم-ز9ن
    @راميابراهيم-ز9ن 4 роки тому

    You're a king. Well played man!

  • @Gormlessostrich
    @Gormlessostrich 3 роки тому

    Thanks, John!

  • @realkiddshady
    @realkiddshady 4 роки тому

    Another great video John. Thank you.

  • @eklypzn
    @eklypzn 4 роки тому +6

    I wanna see John dance to his outro music

    • @_JohnHammond
      @_JohnHammond  4 роки тому +4

      Maybe in the 100k subscriber special? ;)
      Thanks so much for watching!

    • @chiragjogani3389
      @chiragjogani3389 4 роки тому

      John Hammond 100k subs done sir

    • @therenaissance8322
      @therenaissance8322 4 роки тому

      @@_JohnHammond you have more than 100K subs. When are you going to fulfill the promise?

    • @BrosBrainsBroke
      @BrosBrainsBroke 4 роки тому

      In @John Hammond's defence he did say maybe🤔🤔🤔😁

  • @kinjolnath
    @kinjolnath 4 роки тому +3

    Thanks John. Looking forward to more live streams (:

    • @_JohnHammond
      @_JohnHammond  4 роки тому +1

      Hoping to do more on the weekends! Thanks so much for watching!

  • @ghadeeralhayek4373
    @ghadeeralhayek4373 4 роки тому +3

    "i jest hate doing algorithms" we all do dud

  • @GuideYeti
    @GuideYeti 4 роки тому +1

    I LOVE THIS GUY

    • @_JohnHammond
      @_JohnHammond  4 роки тому

      I LOVE YOU TOO!
      Thanks so much for watching!

  • @viv_2489
    @viv_2489 3 роки тому

    You are awesome 😀

  • @sand3epyadav
    @sand3epyadav 3 роки тому

    You r my fav teacher

  • @khalidaldrouby719
    @khalidaldrouby719 4 роки тому +1

    Keep up the good work !

    • @_JohnHammond
      @_JohnHammond  4 роки тому +1

      More on the way! Thanks so much for watching!

  • @NieshaAdi-n1r
    @NieshaAdi-n1r Місяць тому

    Anderson Isle

  • @Child0ne
    @Child0ne 3 роки тому

    john can you make a video on setting up your terminals and all your shortcuts and keybinds you use to maneuve around quickly, you are the only person that rips around terminals seamlessly, i would love to learn how to do it like you

  • @CowperMoira-c4d
    @CowperMoira-c4d Місяць тому

    McKenzie Pines

  • @LoreneMoore-x2h
    @LoreneMoore-x2h Місяць тому

    Silas Forge

  • @neilthomas5026
    @neilthomas5026 4 роки тому

    Very cool as always :)

  • @haraprasadghosh6866
    @haraprasadghosh6866 3 роки тому

    Sir please explain the buffer overflow practical for the OSCP simple and easy techniques.

  • @shivangraina9698
    @shivangraina9698 4 роки тому

    Great video john..btw Can we do this challenge by tampering ssh log files to get rce?

  • @ChaoticVengace
    @ChaoticVengace 4 роки тому

    Hey John! Love the videos and the KOTH live streams. I'm still a beginner in this field and one of my biggest problems I think is taking good notes. I love that you write a README for every box you do, but am having trouble making my own without just trying to copy you. Could you possibly do a video on how to take proper notes and writing up a box? Or would you have any quick tips? Hope everything for you is well :)

  • @MatteoGariglio
    @MatteoGariglio 3 роки тому

    Hi John (from the future), I love watching/learning from your contents! What is the actual code inside the script: stabilize_shell3 ? Cheers

  • @claudiafischering901
    @claudiafischering901 3 роки тому

    Hey, I like your CTFs. I found it too, but you don't need a reverseshell. The Wbeservice run as root, so you can find the flags only by url. ^^ Funny. But never ever run a webservice as root. NO GO!

  • @ashaak1863
    @ashaak1863 4 роки тому

    Dude the shell stabilize script is awesome. Mind sharing? I always do it manually :D

  • @minecrero
    @minecrero 4 роки тому

    Hey John! while watching your video I noticed how you stabilized your shell. How do you do that? is it a precoded script of somesort?
    Great video btw, keep on the good work

    • @minecrero
      @minecrero 4 роки тому

      @Antony Niyazov I'm not sure I completely understand, but thank you, I will try it

  • @kairavb
    @kairavb 10 місяців тому

    I prefer quality

  • @HelloImCrimson
    @HelloImCrimson 4 роки тому

    Is there a video of you doing like a really really hard hack, the type that makes you think for a while? If not, make it lol :D

  • @zzsql
    @zzsql 3 роки тому +2

    This is really neat stuff but You blow through it so quickly, not explaining key elements that the viewers will learn less.
    As with 'Stabilize Shell" you did. No idea what you did there but it sounds important so I'll google it.
    We call them learning opportunities that you're missing.
    Otherwise, awesome.

  • @faruky9197
    @faruky9197 4 роки тому +1

    adamsın adam

  • @Mindflayer86
    @Mindflayer86 4 роки тому +3

    Why on earth are you taking notes? -You literally made a complete video about the entire process. xD

    • @ozgunozerk334
      @ozgunozerk334 4 роки тому

      He likes his stuff ordered, nice and clean maybe?

    • @megvmean
      @megvmean 3 роки тому

      You should always do this. It's good practice.

  • @westernvibes1267
    @westernvibes1267 4 роки тому +1

    Cool, how did you make that stabilize shell bash script tho?

    • @lordtony8276
      @lordtony8276 4 роки тому

      He's got a video on his channel that's called "poor man's pen testing" or something along those lines where he shows how to do that bit.

  • @HabibsWorld96
    @HabibsWorld96 3 роки тому

    at last part ,i heard a background music, tell me name plz😅

  • @PC-fe1pf
    @PC-fe1pf 4 роки тому

    Bro i have a question if you can answer it. Did you use xdotool for your shell stabilizer? If not how do you background the shell from a script?

  • @MrPiks0u
    @MrPiks0u 4 роки тому +1

    I tried to LFI user.txt and root.txt from the webpage.
    Both worked... because root is running flask

    • @_JohnHammond
      @_JohnHammond  4 роки тому

      AHAHAHA THAT is AWESOME, good call! I should have tried that! Thanks for watching!

  • @ozgunozerk334
    @ozgunozerk334 4 роки тому

    Hello John! Why the website did load after aggressive nmap command, and why did it not load before? Any ideas?

  • @d4rkytff114
    @d4rkytff114 2 роки тому

    What is the version of your ubunto OS

  • @reneshraghu3172
    @reneshraghu3172 4 роки тому

    nice bro

  • @jakemcneil9887
    @jakemcneil9887 4 роки тому

    What do you mean by stabilize the shell?

  • @davidmacon1138
    @davidmacon1138 Рік тому

    This is a video that ASSUMES a lot of those that view. Not a good resource for newbs

  • @CyberTron_SnakeTomahawk
    @CyberTron_SnakeTomahawk 4 роки тому +1

    Hey John this “stabilize_shell” do you use “rlwrap + netcat”?

    • @afetodefato1436
      @afetodefato1436 4 роки тому +1

      github.com/JohnHammond/poor-mans-pentest/blob/master/stabilize_shell.sh
      Look if it help you
      And he have video on youtube explain how it works too

    • @EndisuKKJJ
      @EndisuKKJJ Рік тому

      @@afetodefato1436 thanks 🦆🤝🏻🦆

  • @adhishrikothiyal.dreamz
    @adhishrikothiyal.dreamz Місяць тому

    Can anyone share link to this lab? I am unable to find it.

  • @learntechnos4629
    @learntechnos4629 4 роки тому

    I got problem in a site m working on. i can view all files in all directory, but cannot read. Can you help me on this?

  • @wize7475
    @wize7475 4 роки тому

    is it weird that I got into hacking like a week ago and Ive watched like 15 of your videos already?

    • @cristhianz91
      @cristhianz91 4 роки тому

      How is it going for you? Are you subscribed to try hack me?

    • @wize7475
      @wize7475 4 роки тому

      @@cristhianz91 Not yet. Right know Im just trying to understand the basics, learn about the tools etc. But I think its something I want to progress on. Watching John use the tools also gives me some understanding about them.

    • @owendmartin
      @owendmartin 4 роки тому

      You should also look at some of John's CTF (Capture the Flag) videos for good byte sized, digestible information. Also you can look up some well documented Archived CTFs (ie PICOCTF or one of google ones) to get some hands on practice. (shameless plug) Also check out his Discord. Lots of smart people there who are also interested in this sort of thing. ;)

  • @нинавасильева-щ3е
    @нинавасильева-щ3е 2 місяці тому

    01244 Wava Mountain

  • @TomMuller-t9f
    @TomMuller-t9f Місяць тому

    Thomas Brenda Garcia Dorothy Garcia Ruth

  • @data_eng_tuts
    @data_eng_tuts 4 роки тому

    I am facing the same issue while accessing the machine ip via Web browser. any suggestions.

  • @MOSTIE100
    @MOSTIE100 2 роки тому

    nice....

  • @samuelwittlinger7790
    @samuelwittlinger7790 4 роки тому

    Where can I find the script to stabilize the shell?

  • @petrovasyka8
    @petrovasyka8 3 роки тому

    Can we crack root hash from etc/shadow?

  • @saadhith
    @saadhith 4 роки тому

    I think it's low-key to ask this. But what is John's outro song name?

    • @_JohnHammond
      @_JohnHammond  4 роки тому +1

      That is Lost Sky - Fearless. The artist used to be called TULE, but you can them by "Lost Sky" now. Thanks so much for watching!

    • @saadhith
      @saadhith 4 роки тому

      @@_JohnHammond I'm seriously happy that u replied dude. U r doing a great work. Nvm those ip error , typos, and stuff like that. Its kinda a fun in this serious thing. Thanks a lot for the efforts u put in doing these vids to help beginners like us to learn new stuff. ❣️

  • @FranklinYvette
    @FranklinYvette Місяць тому

    Smith Jason Rodriguez Robert Taylor Jennifer

  • @surenavdalyan6036
    @surenavdalyan6036 4 роки тому

    Hey John , can you plz provide Stabilize_shell2.sh, Stabilize_shell3.sh ? how it is written?

  • @multifriendproduct
    @multifriendproduct 4 роки тому

    Link for stabilize shell script?

  • @ca7986
    @ca7986 4 роки тому

    ♥️

  • @HarringtonJim
    @HarringtonJim 2 місяці тому

    Clark Donna Lopez Larry Martin Kevin

  • @annafan83
    @annafan83 4 роки тому

    Moar!! :3

    • @_JohnHammond
      @_JohnHammond  4 роки тому +1

      More coming up! Each Tuesday and Thursday this month! Thanks so much for watching!

  • @NoyesBruce-k4n
    @NoyesBruce-k4n Місяць тому

    Williams Angela Thomas Sarah Johnson Amy

  • @rajeshwaris6663
    @rajeshwaris6663 4 роки тому

    which python or which python3

    • @_JohnHammond
      @_JohnHammond  4 роки тому

      Yup, I suck bahaha. I'll try and remember to go for that next time!

  • @dopy8418
    @dopy8418 4 роки тому

    Hey john, telling you as a i watch your videos a lot to learn. i watch them hitting pause and rewind constantly. You look kind of tired and indifferent on that one compared to earlier stuff. Careful with that. You might wanna do little less but keep’em motivated.

    • @_JohnHammond
      @_JohnHammond  4 роки тому +2

      Good to know, that is good feedback, thanks for letting me know. You can tell by the lighting and the colors in this video that it is pretty late at night, and there are even some flops in this video since I had some left over stuff from the other one. I'll try and do better to pace myself, especially the VM starting up and the OpenVPN nonsense. Thank you for the constructive criticism -- and thanks for watching!