CUSTOM Java Deserialization Exploit - Serial Snyker

Поділитися
Вставка
  • Опубліковано 1 гру 2024

КОМЕНТАРІ • 43

  • @geroffmilan3328
    @geroffmilan3328 2 роки тому +7

    As an infrastructure red teamer, this topic is one I've never explored, but this vid has piqued my curiosity.
    Cheers.

  • @tyronemguni3895
    @tyronemguni3895 2 роки тому +5

    Finally, some code that I recognize but John doesn't lol. I feel proud rn

  • @zionstemple
    @zionstemple 2 роки тому +1

    Every time I watch John I learn something new. Love this channel.

  • @rayden4894
    @rayden4894 2 роки тому +5

    We need more videos like this John
    U are the best 🤜🤛

  • @fram1111
    @fram1111 2 роки тому +6

    Great video and thank you for dumbing it down and giving a good explanation of your approach. So glad your Java was rusty I learned more from your approach

  • @bmdyy
    @bmdyy 2 роки тому +9

    Thumbnail goes hard

  • @vivek-raman
    @vivek-raman 2 роки тому +5

    This was my first CTF, I got so close to cracking this. I got stuck on getting the reverse shell. Thanks for the video!

    • @lorenzocuttitta9474
      @lorenzocuttitta9474 2 роки тому

      where i can try ?

    • @vivek-raman
      @vivek-raman 2 роки тому +2

      @@lorenzocuttitta9474 I believe the docker images should be available to download from snyk

  • @somebodystealsmyname
    @somebodystealsmyname 2 роки тому +2

    While it is kind of funny seeing you struggling with Java, you did pulled yourself through. Great job!

  • @THRE3KINGZStudios3kz
    @THRE3KINGZStudios3kz 2 роки тому +2

    Learning so much from your channel! ❤

  • @officialexploitacademy
    @officialexploitacademy 2 роки тому

    Awesome content John, amazing content as usual!

  • @xAlbanianHackerx
    @xAlbanianHackerx 2 роки тому +1

    I think it would also be helpful if you discussed on how to mitigate this vulnerability. Thanks for the vid as usual!

  • @GJ22
    @GJ22 2 роки тому +3

    I do know java fairly well but this stuff still puzzles me. I still have a lot to learn

  • @vincenzosomma94
    @vincenzosomma94 2 роки тому

    You are a magician 🤯

  • @mrblok1992
    @mrblok1992 2 роки тому +1

    Most likely will refer to this video again. lol

  • @paul7408
    @paul7408 2 роки тому +1

    As someone who newer to pentest/'hacking' world but knows java well, I got a nice lil lol out of "idk what p-o-m.xml is.."

  • @srikeshmaharaj
    @srikeshmaharaj 2 роки тому

    Here's John!!

  • @ipb4isleep
    @ipb4isleep 2 роки тому +3

    19:22 why use {} on line 13?

    • @nordgaren2358
      @nordgaren2358 2 роки тому +3

      Because it's an array of that kind of object, you use the curly braces to make a new array containing the object, or objects seperated with a comma, in the curly braces.
      You could do this with numbers, too, in Java, I believe (same as C#. Not a java expert, sorry!).
      Integer[] intArray = {1,2,3,4,5};

    • @majoryoshi
      @majoryoshi 2 роки тому +3

      @@nordgaren2358 you’re right, initializing an array with {} creates an empty array of size 0

    • @nordgaren2358
      @nordgaren2358 2 роки тому

      @@majoryoshi ah, yes, you can make an empty array like that, too. Apparently in C#, you are supposee to use the generic Array.Empty. Idk if that is common in java or not, or if it matters THAT much. 😂

    • @kristiyangerasimov6708
      @kristiyangerasimov6708 2 роки тому +1

      @@nordgaren2358 there are helper methods to initialize an empty array in Java too, but there is no wrong way to do it :)

    • @majoryoshi
      @majoryoshi 2 роки тому +1

      @@nordgaren2358 I'm not the most experienced with Java admittedly so I can't speak to if initializing empty arrays is commonplace, especially given that they're a fixed size (as opposed to an ArrayList, which is akin to a list in Python). It's literally an array of length 0 with no way to add anything to it, taking up memory unnecessarily. Maybe it's reinitialized later on and I didn't cat it but still.

  • @lorenzocuttitta9474
    @lorenzocuttitta9474 2 роки тому

    where i can try this ?

  • @thinhle1611
    @thinhle1611 10 місяців тому

    can you share the source code ? I would like to download and try it by myself ?

  • @scavro
    @scavro 2 роки тому

    Great¡¡¡¡¡¡¡¡¡¡

  • @christophertharp7763
    @christophertharp7763 2 роки тому

    my brain exploded

  • @KingBowserLP
    @KingBowserLP 2 роки тому +1

    saddened to see the absolute mess from the snyk ctf 101 continued into the actual event. great video though!

    • @_JohnHammond
      @_JohnHammond  2 роки тому +4

      I hear there were some hiccups with the event itself and infrastructure. I might try and chat with them if there is anything more I can do to help for the future

  • @LinksTune
    @LinksTune 2 роки тому

    Lol, me to my code: “can’t find symbol… what are you talking about??”

  • @sburrato
    @sburrato 2 роки тому

    Hey jonh! I just need help, I installes blackeye on my kali VM but the link to send to the victing is invisible, I tried reinstalling blackeye and ngrok, but it still doesn't work. What should I do?

  • @joshuajamesmaul5433
    @joshuajamesmaul5433 2 роки тому

    hello sir, can you help me find a family member using her name on facebook only??

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Рік тому

    Who is the comment opening outside price files

  • @utensilapparatus8692
    @utensilapparatus8692 2 роки тому

    ☃️

  • @ahtungdihtung
    @ahtungdihtung 2 роки тому

    Does not make sense - still enjoy

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Рік тому

    Reg ryxein account

  • @sandra8139
    @sandra8139 2 роки тому

    Have you Court them doing in My identity you do don't forget to tell them it's out of Shoalhaven hards like the highest court's will get them what they deserve forever right

  • @serhanesaidi3140
    @serhanesaidi3140 2 роки тому +1

    First comment

  • @theWSt
    @theWSt Рік тому

    I'm a little dissapointed that you don't know Maven (pom.xml, mvnw) while knowing Java