HackTheBox - Perfection

  Рет қаралды 12,664

IppSec

IppSec

Күн бұрын

00:00 - Introduction
00:50 - Start of nmap
02:50 - Discovering the Weighted Grade Calculator which we will exploit
04:50 - Using FFUF to enumerate all bad characters and discovering we can't send any symbols
07:10 - Quick bash one liner with JQ to URL Encode each line of our wordlist
09:30 - Discovering a New Line character breaks the search for Bad Characters, then getting a shell on the box
14:40 - Shell returned, looking at the source code and seeing the "Bad Character" filter was really a regex whitelist
18:50 - Discovering mail that says the password format in the database
21:50 - Using hashcat Bruteforce mode to crack the password

Пікірлер: 31
@AUBCodeII
@AUBCodeII 24 күн бұрын
Babe, wake up, new IppSec video dropped
@o3tg2w35t
@o3tg2w35t 17 күн бұрын
I learned pen-testing largely from these videos. Three years ago, I got my first pentesting job and somehow promptly forgot all about IppSec. Until today. It's such a great feeling, to know that all my studies paid off. I can finally understand the full content of these videos! Yipee!!
@NatteeSetobol
@NatteeSetobol 18 күн бұрын
I didn't know you could brute force with hashcat like that. I always learn something new!!
@juandelpuerto5711
@juandelpuerto5711 24 күн бұрын
Thanks, as always your explanations are gold!
@Ms.Robot.
@Ms.Robot. 23 күн бұрын
❤🎉 another sweet drop from the Wizard of the Matrix.
@bread_girl_jane
@bread_girl_jane 20 күн бұрын
ippsec you’re one of my heroes but the way you pronounce ubuntu kills me lmao
@StefanŁukasik-m3k
@StefanŁukasik-m3k 24 күн бұрын
Solid as usual
@activ3Port
@activ3Port 24 күн бұрын
the GOAT
@kingzedge
@kingzedge 14 күн бұрын
Aside from HTB and TryHackMe, what tools should I be playing around with on my computer in order to break into Cyber? I have a few ideas: Kali Linux, Linux GUI, Windows command prompt. What else should I download?
@InsanexBrain
@InsanexBrain 12 күн бұрын
thanks! great video as always
@felixkiprop48
@felixkiprop48 22 күн бұрын
Let's rock❤
@Martin-Pentest
@Martin-Pentest 23 күн бұрын
Hey Ippsec i have a question that i guess is unrelated to this particular video but i know your the man to ask.. so i'm trying to figure out why if i type echo "password" | md5sum the output or string is totally different to the string i would get on say md5 hash generator online? Maybe i am being stupid but i guess i won't know if i don't ask.
@ippsec
@ippsec 23 күн бұрын
Without a -n, echo is putting a line break in.
@Martin-Pentest
@Martin-Pentest 23 күн бұрын
@@ippsec Well now i feel stupid aha.. problem solved. Thanks for the reply ipp your a legend 👌
@sh22xpr
@sh22xpr 21 күн бұрын
I assume hashcat checks file each iteration instead of remembering it's content
@raphaelriera-v3b
@raphaelriera-v3b 22 күн бұрын
hey my burpsuite browser can't connect to the website
@abdirahmann
@abdirahmann 24 күн бұрын
good vid
@mohammadhosein6847
@mohammadhosein6847 23 күн бұрын
you are so amazing
@ManuGram
@ManuGram 24 күн бұрын
Really great content,i just wanna ask if you could do more mobile app hacking
@alanbusque6645
@alanbusque6645 24 күн бұрын
Thanks
@nicollasalcantara6907
@nicollasalcantara6907 15 күн бұрын
My reverse shell is not working lol
@_Mann_Kasodariya
@_Mann_Kasodariya 13 күн бұрын
can you make video about how can you have option to which search engines do waan search for it or give me name of softwer so i can to. if anyone know in chat will you help me into this 3>.
@seM1c0l0n
@seM1c0l0n 22 күн бұрын
ffuf supports OS commands to encode input
@tg7943
@tg7943 11 күн бұрын
Push!
@j0hnc0nn0r-sec
@j0hnc0nn0r-sec 11 күн бұрын
Hard to tell he ever had a speech impediment now
@admiralbaty
@admiralbaty 24 күн бұрын
semicolon ; Colon :
@amieemaya9472
@amieemaya9472 23 күн бұрын
Lulz
@Blomma761
@Blomma761 24 күн бұрын
First
@redxroomie
@redxroomie 24 күн бұрын
Lol
@boogieman97
@boogieman97 18 күн бұрын
Hey Ippsec, yesterday I got a new VIP sub for HackTheBox for a year. Haven't done any of the Sherlocks earlier until today. I really liked the LockPick3 Sherlock! Have you done that one yourself already ?
HackTheBox - Jab
40:07
IppSec
Рет қаралды 9 М.
HackTheBox - Crafty
26:17
IppSec
Рет қаралды 11 М.
ПРОВЕРИЛ АРБУЗЫ #shorts
00:34
Паша Осадчий
Рет қаралды 7 МЛН
A little girl was shy at her first ballet lesson #shorts
00:35
Fabiosa Animated
Рет қаралды 13 МЛН
HackTheBox - Sau
16:21
IppSec
Рет қаралды 14 М.
HackTheBox - Busqueda
29:53
IppSec
Рет қаралды 18 М.
HackTheBox - Office
1:16:05
IppSec
Рет қаралды 11 М.
Where People Go When They Want to Hack You
34:40
CyberNews
Рет қаралды 1,4 МЛН
How to OVER Engineer a Website // What is a Tech Stack?
11:20
Fireship
Рет қаралды 2,3 МЛН
HackTheBox - CozyHosting
37:18
IppSec
Рет қаралды 12 М.
HackTheBox - Broker
29:03
IppSec
Рет қаралды 25 М.
Nature's Incredible ROTATING MOTOR (It’s Electric!) - Smarter Every Day 300
29:37
HackTheBox   RegistryTwo
2:06:46
IppSec
Рет қаралды 11 М.
ПРОВЕРИЛ АРБУЗЫ #shorts
00:34
Паша Осадчий
Рет қаралды 7 МЛН