HackTheBox - Help

Поділитися
Вставка
  • Опубліковано 2 гру 2024

КОМЕНТАРІ • 74

  • @c1ph3rpunk
    @c1ph3rpunk 5 років тому +11

    Dude, your HTB walkthroughs are seriously the best around. As a blue-team side person I find almost immediate REAL WORLD TTP’s in here that I can immediately take back to my SIEM.

    • @ippsec
      @ippsec  5 років тому +6

      Awesome to hear the videos have helped your organizations defensive posture! You are definitely doing Blue Teaming well, keep it up.

  • @imoshtokill
    @imoshtokill 5 років тому +17

    I've learned more from your videos than any of the paid resources out there. This was the first box I managed to get without help, and it was neat watching how you went about it. I also love when you show multiple ways of getting in. Thanks for all these great videos!

    • @Calm_Energy
      @Calm_Energy 5 років тому +2

      Congratz on your first solo box! It's a feeling like no other.

  • @davyrogersuk
    @davyrogersuk 5 років тому +18

    The bash history password was the wrong case (we all know what it like to leave Caps Lock on)... switch it around and you have root.. although it’s always nice to see the other routes.... Once again, Great video!

    • @xFolkLorex
      @xFolkLorex 5 років тому +2

      ^ this

    • @danieleantolini2839
      @danieleantolini2839 5 років тому

      When I found the bash history password I tried immediately with Caps Lock on!!!! LOL :D

  • @JuanBotes
    @JuanBotes 4 роки тому

    you make awesome videos, you speak clearly, direct no scratching around in os and settings that is not related, i am still a complete rookie in pentest and use your videos to learn, and i love your indexing below each video so professional and easy to use. sorry my currency is bit flat but will contribue to your fund someday. keep videos coming please.

  • @saketsourav1202
    @saketsourav1202 5 років тому

    Massive respect to you for these videos ...i did the unintended route without using time.

  • @anthirian
    @anthirian 5 років тому +2

    The privesc didn’t even require a kernel exploit. The password you showed in the .bash_history file was actually a really big hint. It was capitalized wrong, so it simulated a CAPS lock being active. If you were to type it instead of copy-pasting and inverted the case, you could escalate to root.

  • @dxsp1d3r
    @dxsp1d3r 5 років тому +26

    I changed my Kali time to server time from settings menu
    😝😝

  • @Crysal
    @Crysal 5 років тому +1

    I've seen a bunch of people doing the split terminal like at 5:49. How do you do that?

  • @yojomojo
    @yojomojo 5 років тому

    ahh thank you! Ive been stuck on trying to figure out how to query the json page and I often see this same page on other boxes and google didnt make much sense to me, learned a lot on this one.

  • @humanflybzzz4568
    @humanflybzzz4568 5 років тому

    Thanks for the content, as i am prepping for OSCP, I find this invaluable. Love from Serbia

  • @hipn0099
    @hipn0099 5 років тому

    For the time exploit for user shell i just changed my date & time to be same as the box and it worked fine, also changed the time to wait for the file detection just in case. Overall great box !

  • @jacquesmit502
    @jacquesmit502 5 років тому

    Was a really fun box, keen to see how other people managed to get in

  • @kaosneverdied9457
    @kaosneverdied9457 5 років тому

    Thanks for making such a really instructive video! I have one question: at around 21:12 you say for ground with 'fg n', although this does not appear on the console line. When I try to use this I seemed to get each line tabbed. eg when I hit return on a command my shell has moved roughly one tab place away from its place on the above line. Thus a few returns in and my cursor is at the other edge of the screen. Have I misheard what you said and if so what should I be typing?

    • @ippsec
      @ippsec  5 років тому +1

      Fg

    • @kaosneverdied9457
      @kaosneverdied9457 5 років тому

      @@ippsec thank you! that's made things so much better :)

  • @zapherion4154
    @zapherion4154 5 років тому +2

    I manually changed my machine to match the servers time. Still need to learn some python I see :) Good vid like always.

    • @jimcolabuchanan6579
      @jimcolabuchanan6579 5 років тому

      Me too. I think I used "curl -v" to get the server time. I remember, I was able to use introspection in graphql to find some creds that allowed be to log into the help app, that gave me a time zone. But the time in the app had nothing to do with the server time. Rabbit hole, But I learned so much about data leakage.

    • @dxsp1d3r
      @dxsp1d3r 5 років тому +1

      I did the same thing but I got the timezone from GitHub I guess😂😂 didn't figured out that curl and burp can give you that as well

  • @vonniehudson
    @vonniehudson 5 років тому +5

    Haven’t even watched but thumbed it up anyway because I know it’s gonna be legit. Wish I could double subscribe

  • @Anbualex
    @Anbualex 5 років тому +1

    I been waiting for this, never figured this out

  • @mr.fakeman4718
    @mr.fakeman4718 5 років тому +1

    Server time! Ahh, now I know what I missed. At least I have learnt something new.

  • @TsukiCTF
    @TsukiCTF 5 років тому +1

    Congratz to 40000 subs!!

  • @omartito754
    @omartito754 5 років тому +5

    how the HELL is this supposed to be an EASY BOX! >.

  • @Siik94Skillz
    @Siik94Skillz 5 років тому +13

    if this is 'easy', then I first of all still have a long way to go, second I need to watch the insane ones

  • @ashleypursell9702
    @ashleypursell9702 2 роки тому

    idk why but never thought to intercept a request from burp to find out what time a server is running thats clever

  • @brettnieman3453
    @brettnieman3453 5 років тому

    Great video as always! Thanks so much.

  • @enyconkali898
    @enyconkali898 5 років тому

    Hey can someone tell me how his "burp-addon" which is shown top right in his mozilla is called? Cant find it

    • @ippsec
      @ippsec  5 років тому +1

      Foxy Proxy

  • @aidenpierce5397
    @aidenpierce5397 4 роки тому

    my terminal will get stucked when I typed "stty raw -echo".How?

    • @nicolaikraus558
      @nicolaikraus558 3 роки тому

      I guess because you didnt enter python -c 'import pty;pty.spawn("/bin/bash")' on the remote machine

  • @itzkoushik3233
    @itzkoushik3233 3 роки тому

    my fav "the way to abuse this"

  • @aloodunayo1427
    @aloodunayo1427 5 років тому

    Love the intended way

  • @akramjabi3949
    @akramjabi3949 5 років тому +1

    this is a thank you comment

  • @kvancaydn231
    @kvancaydn231 5 років тому

    I have a dumb question. How can he divide terminal in kali :)

  • @nelson1587
    @nelson1587 4 роки тому

    30:25 Copy and paste it into a browser's address bar

  • @sidds020
    @sidds020 5 років тому

    I am so furious with myself. After getting the user shell 1st thing that came to my mind was to maybe look for a kernel exploit as it was an old box. Don't know why I started to try everything else but to search for a kernel exploit as I completely forgot about it. Got so close at getting root. For the user shell, maybe I was lucky I did not face the server time issue and the exploit script worked without modifying anything.

  • @jtsperry96
    @jtsperry96 5 років тому +4

    Priv esc s-nail??? Cve-2017-5899 anyone else do this?

    • @sidds020
      @sidds020 5 років тому

      Tried it.. didn't work for me..

    • @ThaEzioAuditore
      @ThaEzioAuditore 3 роки тому +1

      Yup ! I did. Worked like a charm

  • @mrjoa96
    @mrjoa96 5 років тому

    Timezones shouldn't matter, because unix timestamps are universal and not timezone-dependent.

  • @aslam271976
    @aslam271976 5 років тому

    I think the current epoch time is constant all around the world. There is not need of conversion. What you can do is change the timezone of the system to whatever you want and check the epoch time.

    • @ippsec
      @ippsec  5 років тому +2

      The server time stamp isn’t in epoch - so you need to handle time zones, I may of explained it poorly.

  • @Dkaldkh
    @Dkaldkh 5 років тому

    I didn't even change the time on my machine or mess with it at all but it still worked. Not sure why that is.

    • @ippsec
      @ippsec  5 років тому +1

      If you tried it enough. Your time was off. Or other people uploaded script, you may just get lucky and hit a correct hash

  • @cymtrickofficial6023
    @cymtrickofficial6023 5 років тому

    yo that's dope

  • @5t3f4nh4k1
    @5t3f4nh4k1 Рік тому

    @5:29 laudanum is opium ;]

  • @ashishpatil1085
    @ashishpatil1085 5 років тому +1

    I guess the intended way was to get creds from graphql then use them to login and then change timezone on box then run the exploit, I missed the header though and banged my head lol

    • @jimcolabuchanan6579
      @jimcolabuchanan6579 5 років тому

      Yea, I assumed that was a rabbit hole. I tried this and the time I found there did not work. I ended up using curl -v instead to get the server time.

    • @ashishpatil1085
      @ashishpatil1085 5 років тому +2

      @@jimcolabuchanan6579 I guess the creater forgot to remove the time header in the server

  • @rven5768
    @rven5768 5 років тому +1

    You could've added the continue keyword after the print to speed up the script. Anyway, great video.

  • @elliotalderson4467
    @elliotalderson4467 5 років тому

    Failed to open normal output file nmap/help.nmap for writing
    QUITTING! 🙁🙁

    • @ippsec
      @ippsec  5 років тому +1

      Probably need to create the directory

    • @elliotalderson4467
      @elliotalderson4467 5 років тому

      @@ippsec thank u very much sir ♥️
      Keep going

  • @dxsp1d3r
    @dxsp1d3r 5 років тому

    I was shouting you forgot the and 😂

  • @Corp_E
    @Corp_E День тому

    this IS NOT an easy box. the difficulty ratings are seriously upsetting. They destroy confidence.

  • @striple765
    @striple765 5 років тому +1

    First !

  • @MethodicalGaming
    @MethodicalGaming Рік тому

    I guess these videos are for people that are familiar with all the commands? You very rarely explain why you are doing a command you are doing

    • @ippsec
      @ippsec  Рік тому +1

      Watch the older videos, try my first one like popcorn.

    • @MethodicalGaming
      @MethodicalGaming Рік тому

      @@ippsec Ill have a look, thanks

  • @coolsticks99
    @coolsticks99 5 років тому

    I hated this box