HackTheBox! Magic - SQL injection, Magic Bytes & Setuid

Поділитися
Вставка
  • Опубліковано 19 лис 2024

КОМЕНТАРІ • 75

  • @vell0cet517
    @vell0cet517 4 роки тому +50

    “Wrestling with the machine” is good. The best part of your videos is seeing your thought process including how you adjust to obstacles.

  • @texastitan6567
    @texastitan6567 4 роки тому +26

    Sometimes i forget you already know how to complete the box and you know what this stuff is. You deserve an Oscar my friend.

  • @tibofordeyn1529
    @tibofordeyn1529 3 роки тому

    So crazy how I watched this video a few months back not understanding anything of what you’re doing, and now I’m almost able to do it myself

  • @watisonik
    @watisonik 4 роки тому

    I always enjoy your videos John. Thanks for taking us through your thought process. I'm not a "programmer" yet but I learnt something basic from watching your show, you always seems to put the structures first very quickly then customize it to suit the mission. Very nice. Lots to learn and I know your channel will be a major influence to my goal of becoming a pro.

  • @liamlouw4643
    @liamlouw4643 4 роки тому +2

    I've said it once and I'll say it again, so extremely happy these videos are back! Really missed them so much! Would also love a live stream of your attempt at a room!

  • @AKPA10
    @AKPA10 4 роки тому +14

    Make a video pentesting and creating the report simultaneously as you do in certifications or real life pentests.

  • @alzothunder5391
    @alzothunder5391 4 роки тому

    Fantastic video John! I agree with some of the others, "wrestling with the machine" is where the golden bits come from imo. Seeing how you pivot and adapt to obstacles, plus just your thought process in general, is probably the most valuable take away!

  • @BrunoBsso
    @BrunoBsso 4 роки тому +2

    Excellent. Even if you know what he's doing or not, even if you can follow his commands or not, even if you already did something similar in a HTB or THM or CTF. Excellent explanation step by step. I've been following your content for a while already, and this one was just on point both in quality and complexity. Keep the freaking awesome job you're doing. Thanks a lot for sharing.

  • @alexpearce3083
    @alexpearce3083 4 роки тому +1

    you did some blue magic with your eyes

  • @TheReck12
    @TheReck12 3 роки тому +2

    This was a simple box?? Man I have a lot to learn.

  • @edoardottt
    @edoardottt 4 роки тому +1

    Thanks John

  • @eklypzn
    @eklypzn 4 роки тому

    Nice to see an HTB on here. Gonna compare notes with Ippsec after this. See if you guys fry an egg the same way.

  • @cuttlefishn.w.2705
    @cuttlefishn.w.2705 3 роки тому

    When looking for obscure executables/commands on a system, wouldn't it be better to use whereis instead of which?

  • @eXfilPr4tik
    @eXfilPr4tik 4 роки тому +6

    LOVE FROM NEPAL @John Hammond

    • @suvidsinghal1365
      @suvidsinghal1365 4 роки тому +1

      Nepal n00b... First fix your government and Oli (Hate from India!)

  • @EB5005
    @EB5005 4 роки тому +2

    33:58 is why I prefer THM over HTB lol

  • @achuthvp5257
    @achuthvp5257 4 роки тому

    John and his fancy smancy shells

  • @HerbertEduardoFernandezTamayo
    @HerbertEduardoFernandezTamayo 3 роки тому

    awesome video, I've learned a lot, thank you so much

  • @jaganathanp2636
    @jaganathanp2636 4 роки тому +1

    That's awesome htb ctf keep doing more videos

  • @cooliceman0001
    @cooliceman0001 3 роки тому

    I really enjoyed your video! Thank you

  • @CODESEC
    @CODESEC 4 роки тому

    Your The Best Teacher Hakcer...

  • @aakashgautam3851
    @aakashgautam3851 4 роки тому +1

    Love from India 😍😎

  • @orgozlan323
    @orgozlan323 4 роки тому

    amazing. thank you !

  • @lazarep1
    @lazarep1 4 роки тому

    why do you never use burpsuite?i feel like it would have been easier to do this in burp

  • @OMER3-1-3
    @OMER3-1-3 2 роки тому

    Amazing 👏👏

  • @younesmohssen8158
    @younesmohssen8158 4 роки тому +1

    I kind of suck at priv esc. So here’s a question. In the /bin/sysinfo, couldnt he run /bin/sysinfo -p to become root?

    • @yixunnnn
      @yixunnnn 4 роки тому +1

      he could run sysinfo as root, but only that program as root

    • @younesmohssen8158
      @younesmohssen8158 4 роки тому

      @@yixunnnn ohhh I see i see. I thought he could maybe run the /bin/sysinfo -p to keep his privileges as root

  • @thehackinglabllc
    @thehackinglabllc 4 роки тому

    Excellent video!

  • @livemzgttv
    @livemzgttv 4 роки тому

    I hate to ask but would you do a basic command video and how to use them

  • @brettnieman3453
    @brettnieman3453 4 роки тому +4

    Hey John, any specific reason you always include quotes around your url arguments? Had issues in the past?

    • @_JohnHammond
      @_JohnHammond  4 роки тому +4

      I guess just habit -- I think I like to have it "explicit" so when I can and I do as a reflex, I'll try to put quotes around things. :) Thanks for watching!

  • @mouadbousbaa7387
    @mouadbousbaa7387 4 роки тому

    awesome

  • @theprimecoder4981
    @theprimecoder4981 4 роки тому

    I have been trying to use the ovpn in Kali but it gives me openssl error

  • @0xshaheen
    @0xshaheen 4 роки тому +1

    I love your content

  • @zacharyfoster6089
    @zacharyfoster6089 3 роки тому

    "lets not waste any time..." (proceeds to waste everyone's time)

  • @rishi905
    @rishi905 4 роки тому

    really awesome man👌👌👏👏

  • @rajith8973
    @rajith8973 4 роки тому +1

    Make some king of the hill tricks like persistence or killing others shell

  • @CreativeJE
    @CreativeJE 4 роки тому

    Please can you do same with NodeJS

  • @MrPaddy35
    @MrPaddy35 4 роки тому

    its a great video but i did not understand how we go from open, create same file with gets us root shell and then root not showing anything , ending was very confusing

    • @nohandle13
      @nohandle13 4 роки тому +1

      The binary that he ran had a SUID bit, meaning that you run it with the privilages of the creator, being root. (Someone please correct me if I'm wrong.)
      Since the binary (sysinfo) included a popen(lshw, blabla) command, he made a bash (or shell? Don't remember) script that he then added to his path, thus prioritizing it over others. By adding the -p to bash, he keeps the euid (effective user id provided by SUID --> he is now root) in the new instance!
      But, there was no output, so he cleverly added a sticky bit to bash in general. So when he ran it again, he kept his root euid.
      Hope this makes some sense. And if anyone finds mistakes, feel free to correct me!

    • @MrPaddy35
      @MrPaddy35 4 роки тому +1

      @@nohandle13 Thanks alot for the explanation, Really appreciate that

    • @nohandle13
      @nohandle13 4 роки тому

      @@MrPaddy35 no problem! Glad to help :)

  • @imhassan9119
    @imhassan9119 4 роки тому

    why do double extensions bypass the file type filter?

    • @timeisdemise8318
      @timeisdemise8318 4 роки тому

      What bypasses the filter is the last extension (png in .php.png), in addition to the PNG magic bytes.

  • @Wizatek
    @Wizatek 3 роки тому

    Reminds me of the .asp;.png thing from iis6

  • @isectech
    @isectech 4 роки тому

    Hey John what kind of terminal you use ?

    • @arsen3223
      @arsen3223 4 роки тому

      It's called Terminator

  • @somebodystealsmyname
    @somebodystealsmyname 4 роки тому +1

    Just a guess, but I think the reason you did not get output from your `/bin/bash -p` was, that popen was not connected to stdout or that it does not return anything to stdout until it exits.

    • @willyt3hwhale
      @willyt3hwhale 4 роки тому

      The last remark is correct. It will output to stdout once bash exits, so if he would have scrolled up to the beginning of the output he would've spotted the output of his commands.

  • @techchannel3107
    @techchannel3107 3 роки тому

    I Think your eye is happening something

  • @cyberwar2214
    @cyberwar2214 4 роки тому

    Hey very good...but you some take a rest because of your eyes be really red😘❤🧡💛💚💙💜🖤🤍

  • @PremkumarD
    @PremkumarD 4 роки тому

    playing @ 0.75x speed

  • @LegacyVision.
    @LegacyVision. 4 роки тому

    pwncat is trying to do helpful things but stability suffers, cant wait till it gets more stable, will be perfect.

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Рік тому

    Ok easy to task websites 👍

  • @MTS_IT
    @MTS_IT 4 роки тому

    so, a hot woman next to me in a gym (threadmill) - why are you watching that man??? LOL

  • @dieterbeckers8819
    @dieterbeckers8819 3 роки тому +1

    He's like a budget Ed Sheeran with hacking skills :P

  • @BEYBLADETHENEWGEEKS
    @BEYBLADETHENEWGEEKS 4 роки тому

    Man why don't you make a video on your os you are using for pentesting

  • @omeritachiquita
    @omeritachiquita 3 роки тому

    🤼‍♀️

  • @LinuxJedi
    @LinuxJedi 3 роки тому

    meta data smart one exif that shit

  • @Hackedpw
    @Hackedpw 4 роки тому

    K

  • @vamsikolati
    @vamsikolati 4 роки тому

    Hey John please continue making htb machine videos after they get retired

  • @wecksell
    @wecksell 4 роки тому

    Python3: bytes.fromhex(”0a0a0a”)

  • @georgehammond867
    @georgehammond867 4 роки тому

    you are over working ...take it easy

  • @inx1819
    @inx1819 4 роки тому +1

    J I F F S

  • @Dionny
    @Dionny 4 роки тому +1

    This is Oscar level acting

  • @ACHV_MN
    @ACHV_MN 4 роки тому

    Awesomely amazing video, Sir! I’m learning a lot from you side by side with tryhackme and other informational videos! Keep up the great work!

    • @ACHV_MN
      @ACHV_MN 4 роки тому +1

      Have you thought of creating content walking through specific tools/ strategies you include in the videos? Maybe quick articles or links to videos where you go over items like pwncat, stabilizing shells, SUID exploitation, etc.

  • @Batuhanea
    @Batuhanea 4 роки тому

    I love watching these videos but I can't even create a basic page with HTML. I literally have no idea what you are doing

  • @sempaidesu
    @sempaidesu 4 роки тому

    You look so tired .. take a rest bro ...

    • @_DeProgrammer
      @_DeProgrammer 4 роки тому

      You look like an idiot. take a dirt nap.

  • @quickz1306
    @quickz1306 4 роки тому

    nerd

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Рік тому

    Blind to work hoto pasbloo