TryHackMe! Overpass 2 Recovering from THE HACK

Поділитися
Вставка
  • Опубліковано 29 лис 2024

КОМЕНТАРІ • 76

  • @4ag2
    @4ag2 4 роки тому +23

    Ed Sheeran ah John the Ripper Hammond THANK YOU ! 💯🤟

  • @danwilliams6776
    @danwilliams6776 4 роки тому +10

    Loving this series, wish it was your first attempt live though, would be great to follow your thought process!

  • @chittodihoc
    @chittodihoc 4 роки тому +1

    the things i love in this series is i can see his thinking about something may be helpful at this situation.

  • @arghosinha1424
    @arghosinha1424 2 роки тому

    Thanks, really love the extra information that leakes during the whole processes

  • @wasima5933
    @wasima5933 4 роки тому +9

    loving the tryhackme content recently!

  • @tomjackson9420
    @tomjackson9420 4 роки тому +4

    You have a natural ability for teaching. Ever consider doing a noob course on Udemy or on here?

  • @elisehackmann-tf6xg
    @elisehackmann-tf6xg Рік тому

    thank you for the little push you gave me for the last part :) !

  • @mina_ashraf
    @mina_ashraf 4 роки тому +2

    Let the hunger games begin

  • @blessedfridayuyo4372
    @blessedfridayuyo4372 4 роки тому +1

    Hi John, thanks for the walk-through. Please, do you have a link to a documentation on the -p in the suid_bash command?

  • @andreaswahl6644
    @andreaswahl6644 4 роки тому +1

    Octothorp ,best word

  • @HowToEverything1
    @HowToEverything1 3 роки тому

    Octothorpe, understood man

  • @assassino689
    @assassino689 3 роки тому

    great walkthrough! thanks again!

  • @ITRIEDEL
    @ITRIEDEL 4 роки тому +2

    can someone elaborate on the -p argument? I literally cant find any more info on it? Does it stand for permissions? How does this relate to the PE here? Thanks

    • @ITRIEDEL
      @ITRIEDEL 4 роки тому +6

      found it.. .for anyone else.
      bash -c "help set"
      -p Turned on whenever the real and effective user ids do not match.
      Disables processing of the $ENV file and importing of shell
      functions. Turning this option off causes the effective uid and
      gid to be set to the real uid and gid.

    • @sourabhjoshi5877
      @sourabhjoshi5877 Рік тому

      Thank you so much was stuck at same point for so long

  • @decoder6878
    @decoder6878 3 роки тому

    Awesome video John (the) Hammond.🤓

  • @majidaveiro4493
    @majidaveiro4493 2 роки тому

    A living legend! Thanks a lot

  • @chinmaynangia4482
    @chinmaynangia4482 3 роки тому

    why was development folder not visible to us during the attacking ?

  • @jorisschepers85
    @jorisschepers85 4 роки тому

    Keep doing these. Thanks man

  • @hollywoodolq
    @hollywoodolq Рік тому

    i dont understand what the attacker did with the .overpass file? it outputs a string and after this he knows the user and password? i thougt it was maybe base64 enocoded but i was not able to decode this string to anything usable.

  • @kundananji1
    @kundananji1 4 роки тому

    Men, kinda miss the start . Therefore I will wait for a recording so I can follow well.@jjohn kudos for doing this box

  • @nareshg7292
    @nareshg7292 4 роки тому

    what terminal multiplexer do you use ?

  • @vargnaar
    @vargnaar 4 роки тому +1

    Cooctus Clan!

  • @cscogin22
    @cscogin22 4 роки тому

    Thanks brother for the great content.

  • @InspireQuests
    @InspireQuests Рік тому

    how do i know that why i used -p . or how do i know that i have to use -p without knowing whats inside the program

  • @johndavidbalgos4709
    @johndavidbalgos4709 4 роки тому

    hi, any documentation why you set the options "-p" when you run ./.suid_bash?

    • @gurkiratsingh5165
      @gurkiratsingh5165 4 роки тому +4

      It is actually given in the GTFOBins website look at the end of webpage
      gtfobins.github.io/gtfobins/bash/

    • @johndavidbalgos4709
      @johndavidbalgos4709 4 роки тому

      @@gurkiratsingh5165 thanks a lot

  • @craigmac7176
    @craigmac7176 4 роки тому

    Really loving the content!

  • @jb_lofi
    @jb_lofi 3 роки тому +1

    Looking at shibes. Like, Shiba Inus. It's what every self respecting person does on the internet.

  • @samlewis4195
    @samlewis4195 4 роки тому

    Dude I had user flag in about 30 minute of this thing the day it came out but then got stuck on priv esc as the hint had me thinking it had something to do with the ssh keys that were made. I finally had to step back and think, and then ran ls -a and felt so dumb.

    • @naomimendoza7164
      @naomimendoza7164 4 роки тому

      Hey, I got hacked on my business page and was confused but then I was referred to magicalhack on IG. He got my account recovered, I recommend him.

  • @D0w0ge
    @D0w0ge 4 роки тому

    Now that you are doing this tryhackme stuff, will you go back to doing some more CTF Challenges (harder ones, that take more than 5+ min to solve)

    • @_JohnHammond
      @_JohnHammond  4 роки тому

      What sort of challenges do you want to see?

    • @cimihan4816
      @cimihan4816 4 роки тому

      @@_JohnHammond why not RE chals?

  • @ARZ10198
    @ARZ10198 4 роки тому

    Whats the name of the outro song your using in your videos ?

    • @_JohnHammond
      @_JohnHammond  4 роки тому +1

      That is Lost Sky - Fearless

    • @ARZ10198
      @ARZ10198 4 роки тому

      @@_JohnHammond Thanks john , just had to comment something for UA-cam's algorithm xD

  • @samsb9468
    @samsb9468 4 роки тому

    hey !! wanna ask you something! can you bypass icloud authentification with these codes and stuff ???

    • @Reelix
      @Reelix 4 роки тому +1

      If he could, Apple would pay him about $250,000 to tell them how, in which case they'd patch it, and he wouldn't be able to anymore.

  • @AnirudraDiwakar
    @AnirudraDiwakar 4 роки тому +1

    Looking at shibes xD doge woof woof

  • @legndery
    @legndery 4 роки тому

    lol shibe = shiba Inu. A prevalent theme in THM mod group. Even they have a bot command for that. :-P

  • @unevenlab2277
    @unevenlab2277 2 роки тому +1

    Hi John thank you so much for your videos, you're doing a really great job and i really like how do you explain..... I was stopped in ssh login, I don't know why on my local machine I can't login cause I always had this massage: "Unable to negotiate with port 2222: no matching host key type found. Their offer: ssh-rsa", I was going crazy and I thought I was doing smth wrong at the end....but you confirmed in you video that my steps were right...so I used the online kali machine on THM and it works immediatly -.-" I can't really understand why I had this issue on my local vm... do you, or anybody else, have any idea (just for future situations)? thank you!!

    • @gtb7878
      @gtb7878 2 роки тому +2

      With the Option -oHostKeyAlgorithms=+ssh-rsa you can force to use the Algorithm the Server wants

    • @abdullahwebde692
      @abdullahwebde692 2 роки тому

      @@gtb7878 I have same Uneven problem and when I use this it work! , thanks

    • @gtb7878
      @gtb7878 2 роки тому

      @@abdullahwebde692 nice to hear it worked! :)

  • @pspwilliams
    @pspwilliams 3 роки тому

    Any advive to where to start on try hack me ?
    /

  • @sebastiantillmann1669
    @sebastiantillmann1669 4 роки тому +1

    octothorpe ?!?

  • @aldiyark1593
    @aldiyark1593 4 роки тому

    do your job mr.Algorithm thing)

  • @m_peter1514
    @m_peter1514 4 роки тому

    You r the best for ctf

  • @ca7986
    @ca7986 4 роки тому

    ❤️

  • @mattplaygamez
    @mattplaygamez 10 місяців тому

    Try Overpass 3

  • @carlossainz_55
    @carlossainz_55 4 роки тому

    Hello Everyone i am John Hammond and I am the Winner

  • @checknate8820
    @checknate8820 4 роки тому

    Try the Recovery Room. tryhackme.com/room/recovery

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Рік тому

    Reyal files this reyal files.🤝🙏🙏🔥retoo time 👀?.

  • @Hackedpw
    @Hackedpw 4 роки тому

    K

  • @360starcraft
    @360starcraft 4 роки тому

    Please stop presolving the rooms! I think it's much more interesting to see your struggles in real time (cutting if the struggles get too long) but I think it's far less fun watching you act it out. Thanks for taking some criticism, love your videos nonetheless!

    • @_JohnHammond
      @_JohnHammond  4 роки тому +4

      I think I will start to do this on Twitch or something, where I'll take a look at a box for the very first time on a stream, but UA-cam could be reserved for the proper walkthrough video. Do you think that works as a good mix?

    • @360starcraft
      @360starcraft 4 роки тому +1

      John Hammond That sounds like a good way to get both. I don’t know how often I’d be able to tune into the streams with work, but if you’re saving twitch vods I’d be sure to watch them.
      I think that seeing how you think about the rooms in real time is more beneficial to me personally than a walkthrough.

    • @tristanross9795
      @tristanross9795 4 роки тому

      @@_JohnHammond I would follow and subscribe to you live streaming on any platform for real-time solves.