HackTheBox - Manager

Поділитися
Вставка
  • Опубліковано 2 січ 2025

КОМЕНТАРІ • 29

  • @Ms.Robot.
    @Ms.Robot. 9 місяців тому +7

    Five years now and still waiting for someone to do write-ups this good. 🏆

  • @apkanalyze3623
    @apkanalyze3623 9 місяців тому +1

    Teşekkürler.

  • @osmandagdelen9575
    @osmandagdelen9575 9 місяців тому +3

    It's nice to see different perspectives

  • @MrFingenn
    @MrFingenn 9 місяців тому +4

    Weird, my scans didin't show the same opened ports. There was no 389 and 636 ports, I had 3268 and 3269. I still have the 2 nmap files of my scans 2 weeks ago. I guess this is why C****y failed. I have not saved my scan yesterday but I'm sure that 389 and 636 were not opened. If you go in Github issues of the tool used for PrivEsc someone was asking for a new feature to specify on command line the port LDAP is listening (hard coded in tools), explaining a use case of HTb Box not listening on default ports : I think I was not the only one with the same problem

    • @dadamnmayne
      @dadamnmayne 9 місяців тому +2

      Both ldap ports for me are filtered too.

  • @TShad0w-Sec
    @TShad0w-Sec 9 місяців тому +1

    Hey IppSec, could you in one of the boxes, also show the usage of Sliver C2 just as you did for Powershell Empire and Merlin back in the day? I would really appreciate it.

  • @TShad0w-Sec
    @TShad0w-Sec 9 місяців тому +1

    Hey IppSec, Could you show the usage of Sliver C2 in one the boxes, like you did for Powershell Empire and Merlin back in the day? I would really appreciate it.

    • @Strategic.
      @Strategic. 7 місяців тому

      On what box he did that ?

  • @0xanupam
    @0xanupam 9 місяців тому +1

    please make a playlist of that htb videos where i can watch only bugbounty/websec related boxes

  • @mayukhghara6991
    @mayukhghara6991 9 місяців тому +1

    Got access denied trying to issue certificate. help me

    • @0xalam
      @0xalam 8 місяців тому

      After sometime access is reset.

  • @RahulSharma-gf6pw
    @RahulSharma-gf6pw 9 місяців тому +1

    You are a legend 😊

  • @logiciananimal
    @logiciananimal 9 місяців тому +2

    I've always wondered why System can log in at all. I should see how that works sometime. Any thoughts?

    • @charlesnathansmith
      @charlesnathansmith 23 дні тому

      Psexec doesn't authenticate as system. It authenticates as an admin and then uploads a service to run as local system and pop a shell
      That's why there's a dcomexec, wmiexec, etc. They just abuse different RPC features to get code execution

    • @logiciananimal
      @logiciananimal 22 дні тому

      @@charlesnathansmith Interesting. I hadn't noticed that.

  • @y4s3rj4m4l-ik8mz
    @y4s3rj4m4l-ik8mz 9 місяців тому +1

    thanks bro very good and perfect

  • @SplitUnknown
    @SplitUnknown 9 місяців тому +2

    Thank you sir♥️🙏

  • @zyanzyan6300
    @zyanzyan6300 9 місяців тому +1

    hello sir,I want to ask some questions?
    can bug bounty useful in 2024 and the future?
    Because I feel the security of modern technology is very safe and security jobs can be rare in the future.
    I want your answer sir.

  • @unmuktyatree8200
    @unmuktyatree8200 2 місяці тому

    wonderful work

  • @jaylal4899
    @jaylal4899 8 місяців тому

    is it necessary to do a virtual hosts enumeration when we can do a dns zone transfer with the box? I would expect all the virtual hosts to be in the response of the zone transfer.

  • @tg7943
    @tg7943 9 місяців тому +1

    Push!

  • @whilykitt
    @whilykitt 9 місяців тому +1

    Why do you spoil the box at teh start of the video?

  • @AUBCodeII
    @AUBCodeII 9 місяців тому +5

    Hey Ipp-san, let's binge watch Dragon Ball Z in honor of Mr. Akira Toriyama

    • @ippsec
      @ippsec  9 місяців тому +24

      I’m not sure what would take longer, a spirit bomb or nmap

  • @Chris-oe1ru
    @Chris-oe1ru 9 місяців тому +1

    nice

  • @sotecluxan4221
    @sotecluxan4221 9 місяців тому +1