TryHackMe! Wonderland - Python Module Manipulation & Capabilities

Поділитися
Вставка
  • Опубліковано 17 вер 2024
  • Hang with our community on Discord! johnhammond.or...
    If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
    E-mail: johnhammond010@gmail.com
    PayPal: paypal.me/johnh...
    GitHub: github.com/Joh...
    Site: www.johnhammond...
    Twitter: / _johnhammond

КОМЕНТАРІ • 63

  • @dsyncd555
    @dsyncd555 4 роки тому +8

    Between these videos and THM, I've learned so much over the past 8 months.

  • @claymoody
    @claymoody 4 роки тому +2

    This was really good. When I did this room earlier this week I thought it would be a good one for you to make a video for. Great minds and what not!!

  • @jasonmikinskiwallet4308
    @jasonmikinskiwallet4308 4 роки тому +7

    Dang I'm so far from getting that level. Hard work mien!

  • @JayPJC
    @JayPJC 4 роки тому +14

    Hey John. Do you have plans to make a Video on hosting your own CTF, Joepardy and A&D? I would really like that

  • @roquellucerop6898
    @roquellucerop6898 4 роки тому +1

    Great work John, as usual! Thanks for these videos, not only quite educative but also super entertaining. Any suggestion about good resources about Python for cyber security, it's obvious you love it :)

    • @anujpatel1654
      @anujpatel1654 4 роки тому

      i have a course of python for pentesters if you want

  • @majinroot
    @majinroot Рік тому

    Thank You Mr. Sheeran for taking time away from your music to be "John Hammond"😉

  • @rajith8973
    @rajith8973 4 роки тому

    Outro is dope like closing with the hand and music

  • @shijothomas5811
    @shijothomas5811 4 роки тому +1

    Realy helpful and u r doing a great job

  • @Roberto-fz4jm
    @Roberto-fz4jm 2 роки тому

    awesome

  • @thefaker136
    @thefaker136 4 роки тому +1

    Great!

  • @bruh_5555
    @bruh_5555 4 роки тому +3

    Hey John!! I love your videos and would you advise me to choose between learning binary hacking or web exploitation

    • @_JohnHammond
      @_JohnHammond  4 роки тому +4

      Which are you more interested in? :)

    • @bruh_5555
      @bruh_5555 4 роки тому +1

      @@_JohnHammond both xD

    • @s1ked_416
      @s1ked_416 11 місяців тому

      lol you answered your own question @@bruh_5555

  • @dom1310df
    @dom1310df 4 роки тому +4

    I might make my scripts exit by printing "Segmentation fault (core dumped)" just for the LOLs

  • @MsNecroth
    @MsNecroth 4 роки тому +2

    I am a little bit confused on a part and would appreciate some help and answers: the teaParty binary in the rabbit home directory has the sticky bits set and is also owned by root. my question is, why do we get shell as hatter and not root if the binary has SUID set? what commands can we use to check what is going on?

    • @jonathanlein7699
      @jonathanlein7699 4 роки тому

      Inside the teaParty binary the id used is 1003 corresponding to hatter instead of id 0 for root when calling setuid and setgid. I used IDA freeware to view the function calls and see the parameters used.

    • @MsNecroth
      @MsNecroth 4 роки тому

      @@jonathanlein7699 thank you, it makes sense now! it's very weird (at least to me) to have SUID set on the binary and then also have setuid/setgid inside as well. thanks for the help

  • @asadparkar2968
    @asadparkar2968 Рік тому

    Thanks a lot for an amazing explanation !

  • @emmanuelatala4043
    @emmanuelatala4043 4 роки тому

    Keep up the great content!

  • @g0w1h4m
    @g0w1h4m 4 роки тому

    Peculiar

  • @lenierortiz8498
    @lenierortiz8498 4 роки тому +1

    Hey john. Do you have plans on making a video explaining how you setted up the poor mans pentester?

  • @mr_ehmed
    @mr_ehmed 4 роки тому

    You are love man 100% quality content in free ❤

  • @surferbum618
    @surferbum618 4 роки тому

    Thx John!

  • @ac3mcl0ud90
    @ac3mcl0ud90 3 роки тому

    11:07 which font? Thank you and have a great day. The font looks pleasant to read.

  • @tekken-pakistan2718
    @tekken-pakistan2718 4 роки тому +2

    09:50 the juicy stuff

  • @gokulkarthik9790
    @gokulkarthik9790 4 роки тому +2

    I have a few questions....
    1.Whats the difference between bash and bash -p?
    2.When u ran teaparty,shouldn't u have become root and not hatter as the owner of the file is root?

    • @MRGolum
      @MRGolum 4 роки тому +1

      The -p option changes the output format to that specified by POSIX. When the shell is in posix mode, it does not recognize time as a reserved word if the next token begins with a `-'.

  • @anujpatel1654
    @anujpatel1654 4 роки тому

    john i always press like button

  • @asepsayyad3118
    @asepsayyad3118 4 роки тому +1

    Hello sir !
    Will you please provide us the scripts that you used to find vuln in Linux box ...
    It will be great if you make a video on it !!!

  • @silent_flow
    @silent_flow 4 роки тому

    thanks ! please do more tryhackme in your channel.Love From IRAN

  • @hurleynukka3171
    @hurleynukka3171 4 роки тому

    What Linux OS do you use? Any you recommendations for a beginner Linux user?

  • @kr4k3nn
    @kr4k3nn 4 роки тому +1

    sir is there any specific reason why you use ubuntu instead of Kali or parrot which have already installed tools you needed?

    • @bruh_5555
      @bruh_5555 4 роки тому

      He finds kali overwhelming with so many tools and also Ubuntu has wider support base and softwares to do stuff like streaming and recording

    • @cotneit
      @cotneit 4 роки тому

      I assume this is the OS he daily drives. You're not supposed to run Kali as your main OS. Parrot is more suitable for that, but I assume he just likes Ubuntu and is used to it, and it's not like he has a problem installing things himself.
      Also, Parrot is the only OS I tried that just keeps hanging at random times on my laptop. Don't know if it's a common problem.
      If you ask me, Ubuntu is just the best distro out of the box (Though ram consumption with gnome is a bit too high compared to other desktop environments).

  • @MrDavidmcdonald
    @MrDavidmcdonald 4 роки тому

    Great video, too many adverts though :-(

  • @aashaykorani5180
    @aashaykorani5180 3 роки тому

    Hi John can you (or anyone else here) help me understand what does the -p flag do in /bin/bash -p command? 11:07

  • @honestsniping1
    @honestsniping1 4 роки тому +1

    can somebody explain 13:37?
    why can he abuse date?

    • @jacobsan
      @jacobsan 4 роки тому

      The script calls for a date module and he just creates his own with the same name so that instead of calling the real date it calls his malicious script

    • @honestsniping1
      @honestsniping1 4 роки тому

      @@jacobsan but this isnt a python modul, it is a bash command / bash programm...
      i mean i get the point, but if i create a bash script with the name "test" in my home dir and in the same dir i type in "test" then nothing would happen (i need to type in ./test odr bash test)...

  • @arshiyakhan6789
    @arshiyakhan6789 4 роки тому

    We want cyberstack challenges with python scripting please

  • @evildead7845
    @evildead7845 4 роки тому

    Hey If you dont mind can you make a tutorial on hershell ?

  • @checknate8820
    @checknate8820 4 роки тому

    How long did it take you to figure out the url was supposed to spell out rabbit? and why cant you grab the root.txt on you machine and switch the permissions on your end?

    • @bruh_5555
      @bruh_5555 4 роки тому

      Because the file is owned by root and linhz prevents you from accessing the file itself and you can only change the permissions of the file if you're the owner of the file or if you're root but in this case the file is owned by root so you have no luck in reading it because if you try to grab it, the program will have to read the file too so no luck

  • @jaywandery9269
    @jaywandery9269 11 місяців тому

    This room got me dizzy in the beginning

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Рік тому

    Numerical details explain master

  • @nullogs4468
    @nullogs4468 4 роки тому

    What are your certs on the wall behind you??

    • @_JohnHammond
      @_JohnHammond  4 роки тому

      Those are actually my girlfriend's degree and commission ahaha. Her desk is behind mine (all those Disney figures back there are hers too :)

  • @Hackedpw
    @Hackedpw 4 роки тому

    Okay

  • @anuradhalakruwan1918
    @anuradhalakruwan1918 4 роки тому +1

    John sar windows 10 use ethical hac***king course. 🕵️‍♂️🕵️‍♂️🕵️‍♂️🕵️‍♂️🕵️‍♂️

  • @victormontilla9968
    @victormontilla9968 4 роки тому

    Me gustaría aprender python

  • @igedesanjayaputravhyasa2756
    @igedesanjayaputravhyasa2756 7 місяців тому

    I was denied access when i try to enter root using the gtfo bin. Can anybody tell me where did i do wrong?

  • @arshiyakhan6789
    @arshiyakhan6789 4 роки тому

    We want cyberstack challenges with python scripting please

  • @arshiyakhan6789
    @arshiyakhan6789 4 роки тому

    We want cyberstack challenges with python scripting please

  • @arshiyakhan6789
    @arshiyakhan6789 4 роки тому

    We want cyberstack challenges with python scripting please

  • @arshiyakhan6789
    @arshiyakhan6789 4 роки тому

    We want cyberstack challenges with python scripting please

  • @arshiyakhan6789
    @arshiyakhan6789 4 роки тому

    We want cyberstack challenges with python scripting please

  • @arshiyakhan6789
    @arshiyakhan6789 4 роки тому

    We want cyberstack challenges with python scripting please