Windows Shellbags & UHARC Compression: TryHackMe! AoC Day 8 "Santa's Bag of Toys"

Поділитися
Вставка
  • Опубліковано 12 січ 2025

КОМЕНТАРІ • 162

  • @Jikenda
    @Jikenda 3 роки тому +76

    John is a national cyber-teaching treasure.. this guy can make the most complex things much more understandable and he is the most welcoming guy in a very niche community. Best dude on the interwebs today by far!! 💯

  • @Insomnia_2311
    @Insomnia_2311 3 роки тому +33

    I've remembered a quote what a twitch streamer said yesterday: " Don't compare yourself with others, compare yourself to yourself from yesterday" and I've definetly learned a little bit today here. Thanks John and THM

    • @TRD_Mike
      @TRD_Mike 3 роки тому

      Wow that's an incredibly simple yet powerful statement. I'm going to have to remember that. Do you remember what streamer said that, they sound like someone I'd enjoy watching.

    • @Insomnia_2311
      @Insomnia_2311 3 роки тому

      @@TRD_Mike He made the official video of day 9 walkthrough on THM :)

    • @TheEggroll4321
      @TheEggroll4321 3 роки тому

      @@TRD_Mike Jordan Peterson is famous for saying that. He has a lot of little knowledge nuggets

  • @VidathD
    @VidathD 3 роки тому +42

    After all that beginner web stuff, this feels like a huge leap in difficulty (in a good way). Nice to see blueteam content!

  • @devermis2803
    @devermis2803 3 роки тому +4

    I can always count on you for giving us those christmas & good vibes and most especially, knowledge!!!!!

  • @thibdeved
    @thibdeved 3 роки тому +1

    Great day and perfect walkthrough video! I spend a really nice couple of hours solving it and watched the walkthrough after every few tasks done by myself. All the instructors for this event are great but you're by far my favorite and was so happy to see it was you today!
    The way you teach is incredible! I didn't feel like it was almost one hour video, and you're super understandable even for a non-english native! Keep the good work :)

  • @epicmotivevideo
    @epicmotivevideo 3 роки тому

    Thank you! I really enjoy your videos and I love that I am being introduced to other pros and their channels with the other Advent days.

  • @Colaholiker
    @Colaholiker 3 роки тому +3

    I don't think the time stamps in the PowerShell logs are like Unix time stamps, The very first one reads as 20211128153516, which looks a lot like November 28, 2021 15:35:16 (or 35 minutes and 16 seconds past 3 pm for those whose clocks only have 12 hours on them). So while the last digit increases every second, it's not really a second count. ;-)
    This was a really interesting day on AoC, even though I really struggled to get things working (on a technical level, not when it comes to understanding it). I first tried the browser version, but on my setup (inside my Kali VM that I use for TryHackMe running on Linux Mint) it was unusably slow, despite my PC normally not being on the slow side. So I tried getting RDP working (I know this is seamless in Windows, but I don't have a Windows machine at home anymore), which took a lot of tinkering to get the resolution usable (a 640x480 desktop on a 4k montor isn't exactly usable), and it was still painfully slow, but solvable.
    Big thanks to John and all the other fine folks behind AoC
    BTW: Great storytelling 🙂

  • @JRaiKetchum134
    @JRaiKetchum134 3 роки тому +4

    When I saw that you made this one, I went “Oh no. This is gonna be hard! I remember watching him make Peak Hill!” XD It was a lot of fun! I’m enjoying doing the Advent of Cyber 3 as a beginner from watching your videos for the past few months.
    Thanks John!!

  • @TRD_Mike
    @TRD_Mike 3 роки тому

    Hey John, another great video, and I learned a ton! I also want to say thanks for "Resetting Progress" and clearing all the answers out in the room before recording the video. I can't fault others for not doing it, but I find it really distracting when the answers are already populated, because I don't want to spoil it for myself, and then I have to concentrate on actively not looking at the answers lol. Anyway thanks again.

  • @Stephanus21
    @Stephanus21 3 роки тому

    Mr John you sir are amazing , thank you for teaching us , always makes it so easy to learn from you .

  • @Florian.Dalwigk
    @Florian.Dalwigk 3 роки тому

    I really enjoyed this special of yours! Great job and thank you, John! :)

  • @jeanpc9174
    @jeanpc9174 3 роки тому

    Im Newbie in this world and I am fascinated with all this material. Thanks THM TEAM!

  • @infosecafterdark-ds9
    @infosecafterdark-ds9 3 роки тому

    Great challenge, and great explanation! I ended up not needing the video for most of it, but you got me started, clarified things that I was confused about, and added additional insight into the material. Thanks for doing this!

  • @firstnamelastname5751
    @firstnamelastname5751 3 роки тому +1

    46:34
    “So Santa’s bag of toys has been FULL ON compromised”
    I laughed harder than I should have 🤣

  • @yahyatareen4944
    @yahyatareen4944 3 роки тому

    this topic was so unique everything was unique to me did it in 2 hours by myself except for 2 questions i was stuck at for a long time...it was really interesting ...i am out of words ...i cant explain but it was so refreshing man ....HATS OFF TO YOU JOHN!!!

  • @Supamario1111
    @Supamario1111 3 роки тому

    i love your teaching and the way you explain things,within two days of watching!!

  • @williamlong5899
    @williamlong5899 3 роки тому

    Awesome walkthrough John. Thank you for the guidance. I am new to cybersecurity and learned a lot of new content from this walkthrough. Thank you.

  • @vfryhn2
    @vfryhn2 3 роки тому

    I totally learned a lot I had never heard about UHA files nor shellbags, it was amazing and definitively got me wanting to learn more about these topics

  • @MrDiaz22
    @MrDiaz22 3 роки тому

    Thanks John for another awesome video, I appreciate the time you take to explain shortly different terms and acronyms, it really helps refreshing them, Loved the whole Web Exploitation week, let’s get some more networking and blue team content!!

  • @susananthony2084
    @susananthony2084 3 роки тому

    It was lots of fun! Have to watch it again as there were a lot of new things for me! Thank you for the video, John...Merry Christmas ☃❄⛄

  • @danom8ga
    @danom8ga 3 роки тому

    I thoroughly enjoyed this exercise John. You are dynamic speaker/teacher and you now have a subscriber and I'll look you on other social media platforms so I can learn from your great content!

  • @sayakarar
    @sayakarar 3 роки тому

    This special task was totally worth the wait. Got to learn much new things and got great exposures to tools and techniques. Loved it!!

  • @DIS_IZ_JOSH
    @DIS_IZ_JOSH 3 роки тому

    John, youre an awesome teacher, i love all your videos and im so glad THM partnered with you to run some of these advent of cyber events. keep up the amazing work! i hope to someday become as knowledgeable as you are in this field.

  • @Testuser0101
    @Testuser0101 3 роки тому

    Thanks for making the questions and explanations.

  • @raymondschuiling76
    @raymondschuiling76 3 роки тому

    Thnx for this nice and well structured challenge and video! Learned some stuff I didn't knew.

  • @davidraymond7420
    @davidraymond7420 3 роки тому

    Good one. I will read more on ShellBag for the future. Thanks John.

  • @TheMattharris61
    @TheMattharris61 3 роки тому

    Thanks John, always easy to follow along and great content from you and THM!

  • @themagus363
    @themagus363 3 роки тому

    Loved it!! Loads of fun and learnt a lot. Thanks John!

  • @jackfull9972
    @jackfull9972 3 роки тому

    Great room John. Really appreciated that you included some Easter eggs like 'shellbags' and 'lolbins' for beginners like myself to look more into!

  • @estelleferre
    @estelleferre 3 роки тому

    Thank you John. You helped me understand so many new notion.

  • @hax4coffee
    @hax4coffee 3 роки тому

    Awesome job as always! Thanks for all your hard work! Merry Christmas!

  • @PaulWilliamGeorge
    @PaulWilliamGeorge 3 роки тому

    "I love ya. I'll see ya in the next video." What a great way to end a fantastic day of cyber!

  • @Lodinn
    @Lodinn 3 роки тому +1

    51:11 Note that UHARC GUI actually tells you the file count right below the file list, no extraction necessary :p

  • @MauriceSamulski
    @MauriceSamulski 3 роки тому

    This was awesome, learned a lot about something I have not seen before: shell bags.

  • @peepers46
    @peepers46 3 роки тому

    Thanks for a great walkthrough John...LOVE your content

  • @SilviuPricope
    @SilviuPricope 3 роки тому

    Great stuff! As usually... of course!
    I am glad I had solved this Day 8 before I watched this video. I don't like spoilers... :D

  • @xQused
    @xQused 3 роки тому

    this is defently my first time with blue team and RDP. great for me as i am a begginer. thank you so much.

  • @y.vinitsky6452
    @y.vinitsky6452 3 роки тому +1

    thank you for putting this together. I never did any blue team stuff before. the attackbox was unuasble i logged in with windows rdp connect instead. My only gripe is the base64 encoded dat file was very hard to copy with such a slow machine

    • @joet2303
      @joet2303 3 роки тому

      Agreed. So much new knowledge for me but the hardest part was trying to copy/paste the encoded dat file while on the analysis machine.
      Obviously nothing to do with John’s fantastic work but I wanted to scream during that step, lol.

  • @mrnord1989
    @mrnord1989 3 роки тому

    This was super fun, the walktrough was super clear and easy to follow. Completed like 99% of this by my own. Just had to use the video for one of the questions :D Still a noob, but thanks for creating this. Keep up the good work :)

    • @Colaholiker
      @Colaholiker 3 роки тому

      I only had technical difficulties and made it rhough it on my own... but afterwards I had to watch the video, just for John's additional explanations.

  • @demetrioxray
    @demetrioxray 3 роки тому

    Fantastic and very creative! Have had a great time learning! Ty so much!
    :))))

  • @glasses1866
    @glasses1866 3 роки тому

    You make learning fun with your explanations. God bless you!

  • @naeem8434
    @naeem8434 3 роки тому

    Truly Amazing and feeling interesting to go along with you in this year in Advert of cyber 3

  • @VidathD
    @VidathD 3 роки тому +3

    26:22 That looks more like the time in YYYYMMDDHHMMSS

    • @_JohnHammond
      @_JohnHammond  3 роки тому +2

      Ah! You are totally right! That is not Unix time, my mistake!!

  • @valuial8691
    @valuial8691 3 роки тому

    Great video and nicely explained how everything works.
    As for possible flag submissions:
    you could have put a flag as one of the toys in that bag. nothing to hash, just read that one files contents to get your flag.

  • @crystalulloa3281
    @crystalulloa3281 3 роки тому

    Royally enjoyed this walk thru, thank you!!!!

  • @amx2311
    @amx2311 3 роки тому

    This, like your other content, honestly was a lot of fun to watch (though I must confess I watched it at 1.5 speed).

  • @m4rt_
    @m4rt_ 3 роки тому

    6:50 ... you could have right clicked on the wallpaper/desktop and hovered over view and made the icons larger

  • @Raviraj-el7ue
    @Raviraj-el7ue 3 роки тому

    Sir, you bring something innovative and unique everytime and you carved it fantastically in your all videos. This TryHackMe's Advent of Cyber Day 8 was fantastic and was interesting to get introduction to ShellBags Explorer and UHA Compressed Archive. I hope I will get more content related to blue teaming and red teaming in future from you,sir. I will be glad and amaze to watch those videos.

  • @dayjovi9880
    @dayjovi9880 3 роки тому

    Oh, Networking tasks are on the way. Thanks for revealing :)

  • @kartibok001
    @kartibok001 3 роки тому

    Another great visual write up and challenge!!

  • @breakingmhet8078
    @breakingmhet8078 3 роки тому

    Amazing content as always John! This AoC is AMAZING!

  • @HoermalzuichbinderB
    @HoermalzuichbinderB 2 роки тому

    44:00 Shows the total numer right away in the Log

  • @rrsmb7136
    @rrsmb7136 3 роки тому +1

    Great video John, my feedback to you is that as a beginner, i found it a little hard to keep track, if you do another AoC activity i will suggest easier stuff for us beginners. Good Hollidays to everybody

  • @jean-jacquescueff1488
    @jean-jacquescueff1488 3 роки тому

    Thank you John, you saved Christmas !

  • @sarahmaynard-murray4623
    @sarahmaynard-murray4623 3 роки тому

    Super fun challenge. Thanks for such a great explanation.

  • @Jack10Boom
    @Jack10Boom 3 роки тому

    Thank you John for posting this video. "Get started with Cyber Security in 25 Days - Learn the basics by doing a new, beginner friendly security challenge every day leading up to Christmas." I'm not looking for a career in cyber security, but I am interested in cyber security. I'm a basic beginner and it is refreshing to have some one 'hold my hand' while I do this. Thanks again.

  • @nft_explorer
    @nft_explorer 3 роки тому

    How did you select so fast with Shift on 27:00 . Can you explain in more details? thanks.

  • @dextrofy
    @dextrofy 3 роки тому

    This was awesome! Thanks John!

  • @vidhuran4414
    @vidhuran4414 3 роки тому +1

    Sir Please make more videos of this type , it seems to be useful to beginners !

  • @Mags0O7
    @Mags0O7 3 роки тому

    i love how you laughed at the evil content of bag of toys :) :) ye who comes up with this stuff . thanks again for a great video

  • @doubleg7064
    @doubleg7064 3 роки тому +1

    for anyone finding diffculties copying all the base64 encoded stuff try deleting all the stuff outside the begin certifcate and end certifcate and then select all and copy

  • @scottp8329
    @scottp8329 3 роки тому

    Spot on buddy as always explained everything easily liked it a lot.

  • @salmansajidkhan1077
    @salmansajidkhan1077 3 роки тому

    For those who are unable to decode the transcript file due to slowness or copy issue in browser....
    Tip :- Copy the whole transcript file and paste in new notepad file, remove contents before --- begin certificate --- and content after -------end certificate --- save file with any name and upload to cyberchef rather than pasting ......hope this help others.

  • @shadydealer1332
    @shadydealer1332 3 роки тому +1

    I tried using the web version of the machine, but for some reason it kept starting an ubuntu box. Ended up using RDP as suggested, but thought it might be useful feedback

  • @ibrahimiam
    @ibrahimiam 3 роки тому

    Wonderful series!! Thanks a lot.

  • @zenmoto369
    @zenmoto369 3 роки тому +4

    Great! Day 8, one the best so far, too bad the THM windows machine kept breaking :D

    • @thecreed5641
      @thecreed5641 3 роки тому

      now its not even opening and the new instruction is said to access with attack machine into rdp

    • @dfgd09
      @dfgd09 3 роки тому

      They are working on the network problems. Should be back to normal soon

  • @ahtungdihtung
    @ahtungdihtung 3 роки тому

    it may be small crowd, but hey! 6k views in 5hr for sybersec is hUUUUUge crowd.
    kinda want to bring a DJ and that is - John!
    awesome job on this one dude ;]

  • @tpavan
    @tpavan 3 роки тому

    Cute challenge, thanks for the walkthrough, sure easier than day 6 :-D

  • @aaaaaaaaaaaaaaaaaaaaaaaa997
    @aaaaaaaaaaaaaaaaaaaaaaaa997 3 роки тому

    Thank you for the great walkthrough.

  • @harmanjotsingh3135
    @harmanjotsingh3135 3 роки тому

    i dint wanna be the one who should asking the stuff out of topic or subject but was that a cop or ambulance at 11:05-11:12

  • @layeejoshi2737
    @layeejoshi2737 3 роки тому

    ​It was a lot of fun ! New flavor of challenge!!

  • @nilesh.k-v6s
    @nilesh.k-v6s 3 роки тому

    Shellbags was new for me. useful in Forensics, i'm guessing. just had a small reconnection in the middle, but overall awesome!

  • @tabandyfarm8103
    @tabandyfarm8103 3 роки тому

    Fantastic! Thank you I am learning so much! :)

  • @husseindhooma5816
    @husseindhooma5816 3 роки тому

    John thanks for an awesome video, you are a legend sir.

  • @jaspreetsingh9688
    @jaspreetsingh9688 3 роки тому +3

    Please make upcoming days video also because i like the way you teach

  • @feliper5265
    @feliper5265 3 роки тому

    That was really nice, Thank you !!

  • @sudosuraj
    @sudosuraj 3 роки тому +2

    Let's open the bag of toys 😬😆❤️

  • @slbpriank91
    @slbpriank91 3 роки тому

    Thanks, i got to learn new things and it was fun :)

  • @jamesmaweu8957
    @jamesmaweu8957 3 роки тому

    Awesome, Learnt a lot today Thanks

  • @infoseckid
    @infoseckid 3 роки тому

    It was cool using Windows machine as the attackbox.

  • @1083916
    @1083916 3 роки тому

    Hi John.
    Thanks for putting this task together. It's been my favorite so far and i think it will still be when i finish all of them.
    One question though, would there be a way to use shellbags explorer if the actor didn't show the user.dat base64 code?

  • @gsound12
    @gsound12 3 роки тому

    Thank you man. This is amazing;)

  • @statesman2die4
    @statesman2die4 3 роки тому

    great stuff... just a thought, could have a flag file in the archive...

  • @sillymel
    @sillymel 3 роки тому

    (55:19) So, uh, you don't actually need to restore the files to see how many files were in the original Bag of Toys. I would have suggested putting a flag in one of the files you needed to recover as your final check.

    • @Colaholiker
      @Colaholiker 3 роки тому

      You still need the password to get the count. After that it is just extracting files from an archive, which isn't much different from any of the more common formats. So the challenging tasks are done by that point imho, the rest is no challenge for people who join the AoC. ;-)

    • @sillymel
      @sillymel 3 роки тому

      @@Colaholiker You do not, in fact, need the archive password to get the count. I posted a message in the Advent of Cyber 3 channel on the Try Hack Me Discord server about how to get the count without the archive password (trying to keep things vague here in case someone using the video as a walkthrough accidentally sees this comment before finishing).

    • @Colaholiker
      @Colaholiker 3 роки тому

      @@sillymel Okay, I didn't see it straight away. I'm not on Discord (I still somewhat have a normal live outrside the internet ;-) ), so I just do what John likes to do and press the "I believe" button. :)

  • @btboss123
    @btboss123 3 роки тому

    Great job thank you for the video appreciate it.

  • @GratuityMedia
    @GratuityMedia 3 роки тому

    camel case lol, I really liked it but my machine crashed constantly maybe too many hereos!

  • @federicoconoscenti6921
    @federicoconoscenti6921 3 роки тому

    loved this task John♥️

  • @slavomirjuriga9228
    @slavomirjuriga9228 3 роки тому

    This room was real fun :)

  • @edgarhernandez3430
    @edgarhernandez3430 3 роки тому

    Excited to be here for a live THM!!!

  • @nadiarusiecki5785
    @nadiarusiecki5785 3 роки тому +1

    That was amazing, it was like uncovering whole story, have you considered making games about hacking?

  • @petrspac5024
    @petrspac5024 3 роки тому

    Good job!! Thank you it was fun

  • @dalamar666
    @dalamar666 3 роки тому +1

    I am sorry John, but trying to use CyberChef in this VM is unusable. There is something baked in with the resolution of the firefox browser. I can scroll up and down but cannot see the top and cannot choose different options. I have restarted the VM multiple times and nothing.

  • @Carr7.0
    @Carr7.0 3 роки тому

    isn't it ctrl+scolling to get the other views? (for details)

  • @somepineaple572
    @somepineaple572 3 роки тому

    So is "disabling powershell" in windows like going onto a linux machine going "lets delete bash"

  • @custume
    @custume 3 роки тому

    good video, yeah the hash was a bad idea, good one

  • @fordorth
    @fordorth 3 роки тому

    I have a super very important pen testing question... I must have the answer...
    John how long does it take to do your hair in the morning? I must know!

  • @kumarniloy3893
    @kumarniloy3893 3 роки тому

    Answer me John , did you have fun making the third powershell transcript ?

  • @assassino689
    @assassino689 3 роки тому

    thanks man! great stuff!

  • @Asentinn
    @Asentinn 3 роки тому

    Yeah, that was a good one!

  • @jimlabilles
    @jimlabilles 3 роки тому

    have you ever thought about teaching in a university?
    you definitely have a great way of explaining things!