HTB Cyber Apocalypse - cURL As a Service

  Рет қаралды 37,251

John Hammond

John Hammond

3 жыл бұрын

Moving your first steps into hacking? Start from HTB Academy: bit.ly/3vuWp08
Hungry for more hacking training? Join Hack The Box now: bit.ly/331nQCl
For more content, subscribe on Twitch! / johnhammond010
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
PayPal: paypal.me/johnhammond010
E-mail: johnhammond010@gmail.com
Discord: johnhammond.org/discord
Twitter: / _johnhammond
GitHub: github.com/JohnHammond

Пікірлер: 103
@NateRoberts
@NateRoberts 3 жыл бұрын
You say “you talked too much” but for a beginner your deep dives/verbosity definitely help someone like me. So it’s greatly appreciated, thanks so much for the content.
@jwoo13
@jwoo13 3 жыл бұрын
I really appreciate you "thinking out loud" as to what you're doing at each step; it helps a lot of us learn as that fits our learning style.
@vanshajdhar9223
@vanshajdhar9223 3 жыл бұрын
Yes I agree
@mjtonyfire
@mjtonyfire 3 жыл бұрын
John, man... Do NOT stop being verbose. Your train of thought whilst solving a problem is INVALUABLE. I don't think there's another youtuber out there that gives us this fine grain critical thinking regards hacking/CTF/stuff. I'll watch one of your vids from start to finish the first time, then I'll be going slower through the next play through, taking notes, following along... This is the best way to learn. Keep going. You've just earned another patreon. Thanks man.
@Zygorg
@Zygorg 3 жыл бұрын
Yes
@YeffRamos
@YeffRamos 3 жыл бұрын
love how descriptive and verbose these are actually... even if we use curl every day it's nice to see somebody go in-depth with it.
@tsustyle6263
@tsustyle6263 3 жыл бұрын
I've said this before and I'm going to say it again. I learn more in 30 minutes watching John's videos than I do in 3 hours with any other teaching medium. Incredible job as always. Thank you.
@lepsycho3691
@lepsycho3691 3 жыл бұрын
I really like to hear your thought process, it gives me a lot of insights on how to approach a challenge like this!
@theITGuy-no3nt
@theITGuy-no3nt 3 жыл бұрын
@johnhammond Sorry for the second comment, but this is like the 10th time I have heard you apologize for being verbose in explanation, video length, or for "fumbling" through a challenge. I can not state strongly enough that those things are *precisely* why I watch your videos, and I feel that I am not alone. I do not give a fetid pair of dingo's kidneys about the a-b-c steps of solving any particular challenge; it is the thought process that leads to the solution that interests me. I enjoy watching you beat your head against walls, as would anyone who ever pounded a keyboard in fury whilst screaming "What the *actual* $%@# ?" Keep it up. What you are doing works.
@hayaanrizvi
@hayaanrizvi 3 жыл бұрын
Exactly, couldn't have said it better myself
@theITGuy-no3nt
@theITGuy-no3nt 3 жыл бұрын
@@hayaanrizvi Thanks
@saidjuma1433
@saidjuma1433 3 жыл бұрын
I always learn something new when i see a upload from you. Keep up the good work my mans
@yoshi5113
@yoshi5113 3 жыл бұрын
I love how the way you explain the tricks, thanks a lot John, Love from Indonesia.
@steps0x029a
@steps0x029a 3 жыл бұрын
Love the talking-to-yourself and thinking-out-load approach, it really helps with understanding the process!
@nikkittb
@nikkittb 2 жыл бұрын
I really like how you took the time to explain all the steps you took here John! Even explaining the little things, like what ngrok does and how you spin it up! Loving the content man!
@kylejessup5740
@kylejessup5740 3 жыл бұрын
Happy to see some Cyber Apocalypse videos, I'm a beginner at this stuff and only found a few flags in this CTF. I will definitely watch more.
@peterchari3839
@peterchari3839 3 жыл бұрын
Great walk through video. Clear explanation. Its very easy to follow.
@jimpowers4463
@jimpowers4463 3 жыл бұрын
Great video, so awesome that HTB spun up the game for you to make these videos for us.
@nouriyacine8823
@nouriyacine8823 3 жыл бұрын
I loved CTF games because of you dear . Can't stop learning more abd more all thee day. Thanks so much for everything you share with us.
@JimmyGeschwind
@JimmyGeschwind 3 жыл бұрын
I like that you go through and show the whole process and not just jump on the solution. I feel that I learn more from that approach. Keep it up!
@eklypzn
@eklypzn 3 жыл бұрын
Solid video. I was like yelling at the screen early about the methods. I definitely had a few questions about source code answered for me and I'll probably end up referring to this video again.
@hjorturpalmipalsson4521
@hjorturpalmipalsson4521 3 жыл бұрын
Always fun to see different take on those challenges. I used the -o flag in curl, it allows us to output the content of the curl into a file. With that in mind, I just curled a webshell file and outputted it into the static js folder and then executed it via the browser.
@AustinReed1
@AustinReed1 Жыл бұрын
John I had to hop on here and leave a comment, you are great man keep up the good work, I just saw one of the CTF's you were in and it was obvious they were being assholes, muting you on purpose, being snide then dismissing you at the end was shitty and inexcusable. Good for you for taking the high road and being tactful during the whole event and never uttering a negative word about that guy. Keep up the awesome work, the world needs more people like you!
@asmedeus448
@asmedeus448 3 жыл бұрын
I learn something today. Thank you.
@Devinatron
@Devinatron 3 жыл бұрын
I feel dumb now seeing how simple it was. I got too far in the weeds during the event on this one, but I really appreciate the thinking out-loud! I'll get better at these, thanks for the awesome vid!
@mrbeancanman
@mrbeancanman 3 жыл бұрын
its definitely worth while! more of this please :D
@wilcosec
@wilcosec 3 жыл бұрын
This was a fun one! Thanks John!
@akay9030
@akay9030 3 жыл бұрын
Always wait for your videos...awesome work ..keep it up,plz upload ctf more often
@ez-it-solutions9128
@ez-it-solutions9128 3 жыл бұрын
It's very difficult to hit every audience and talent level but these are the kind of video's worth paying for! A shorter, summed up version that skips specific steps or lacks the long-winded explanations is what most video's provide - but you provide the most thorough and absolute content! Keep it coming - What you call long-form or verbose is what makes it easy for everyone to follow.
@atishkumarpradhan9759
@atishkumarpradhan9759 3 жыл бұрын
The thought process is really helpful brother :)
@shauncollins1280
@shauncollins1280 3 жыл бұрын
Love you man... Thank you so much 🙏
@THRE3KINGZStudios3kz
@THRE3KINGZStudios3kz 3 жыл бұрын
Ayo I seen you on a recommended vid by Joshua Fluke discussing Cyber Sec and I started off just like you mane I was into making video games and I started in unity and UE5, got my degree in CIS, and lately I’ve been sharpening my technical skills. I want to get the Cyber MOS in the Army and AF and since I recently graduated, like this week, I been putting together my resume and trying to soak in as much info as possible bc We really want this job you know! Well anyways it’s nice to find someone with some things in common and your vids are very informative!
@xBrownnyx
@xBrownnyx 3 жыл бұрын
It is worthwhile, thanks. Great video!
@TheDyscontinuum
@TheDyscontinuum 3 жыл бұрын
Much appreciated good sir
@_CryptoCat
@_CryptoCat 3 жыл бұрын
thats cool you got the -T flag to work! i was playing around with it for a while before eventually solving with file:/// 😀
@telnobynoyator_6183
@telnobynoyator_6183 2 жыл бұрын
I though of the same thing ! So file IS a solution...
@_d47_
@_d47_ 3 жыл бұрын
Thanks bro, i really like watch your videos
@petehinch3871
@petehinch3871 3 жыл бұрын
Love your Videos John
@adnentrimech7958
@adnentrimech7958 3 жыл бұрын
THANKS
@devil874
@devil874 3 жыл бұрын
oh thats nice i used: -o argument to uplaod a .php file that printed the flag its great i kinda allways learn something watching you
@LinuxSploitOfficial
@LinuxSploitOfficial 3 жыл бұрын
Amazing Thumbnail ♥️
@vellankiindeevar5530
@vellankiindeevar5530 3 жыл бұрын
Man your vids are so engaging
@talinross
@talinross 3 жыл бұрын
Best video ever !
@joehollon317
@joehollon317 3 жыл бұрын
Great vid
@ilyesdhiaeddine6610
@ilyesdhiaeddine6610 3 жыл бұрын
yes please keep this format
@nothingreallymatters7530
@nothingreallymatters7530 3 жыл бұрын
it's super worth it just beginner like me.
@mossdem
@mossdem 3 жыл бұрын
We know you wanna just release it now John…
@andydietz7434
@andydietz7434 3 жыл бұрын
Love the explanation and please don't think you are being "Long Winded". I agree with the others, that this is great explanations for beginners or just to understand what you are thinking!! Please keep it up and yes, we want more CTF writeup videos. Also what is the song that is in the end of the video, it is stuck in my head and I want to go find it so I can listen to it while work on my hacker skilz!!
@ajaymandal2560
@ajaymandal2560 3 жыл бұрын
Worth while ❤️👌
@morsi7842
@morsi7842 3 жыл бұрын
Big fan from Egypt, I really appreciate your work. Thank you for sharing such knowledge
@savoyblue777
@savoyblue777 3 жыл бұрын
If you don't mind John What terminal do use on your system? And thank you for all you do to help us all
@dedkeny
@dedkeny 3 жыл бұрын
Almighty Algo STUFF!!!!!!!!!
@THRE3KINGZStudios3kz
@THRE3KINGZStudios3kz 3 жыл бұрын
My twin and I are both in the military but not branched or have MOS yet and we were told we shouldn’t get our certs before going in just wait... I kinda wished I already gotten them trying to get at least our Sec+ first 😂😂😂
@bhagyalakshmi1053
@bhagyalakshmi1053 11 ай бұрын
Work full this one to track is a nice easy to work my headel jobs
@bhagyalakshmi1053
@bhagyalakshmi1053 Жыл бұрын
Nice 👍
@amine250
@amine250 3 жыл бұрын
That was a nice challenge
@JoPraveen
@JoPraveen 3 жыл бұрын
👏✨
@CyberSecForce
@CyberSecForce Жыл бұрын
Great
@BRYDN_NATHAN
@BRYDN_NATHAN 3 жыл бұрын
Thank you. KZfaq
@viv_2489
@viv_2489 3 жыл бұрын
Waiting for this
@jeffersonding5898
@jeffersonding5898 3 жыл бұрын
A great resource to use instead of reading through thousands of lines of manuals is GTFOBins. Has may important exploits and examples implemented already
@holigan5392
@holigan5392 3 жыл бұрын
Make a tutorial for black box pen testing
@avasonds
@avasonds 3 жыл бұрын
yo John your a beast I've been watching your videos, so when is the nsa hiring you?
@alexandrohdez3982
@alexandrohdez3982 Жыл бұрын
👏👏👏👏👏
@rebootlinux608
@rebootlinux608 3 жыл бұрын
I have a question do you use ubuntu on your hardware or as a virtual machine?
@telnobynoyator_6183
@telnobynoyator_6183 2 жыл бұрын
I immediately though of (and saw) the FILE protocol I wonder if that's going to be the answer
@jaopredoramires
@jaopredoramires 3 жыл бұрын
is this your `classic` ubuntu box? always wanted to know which version it is also, took me ages to figure out you were on XFCE
@ayush_panwar1
@ayush_panwar1 3 жыл бұрын
Another awesome video 👏👏 But we r hungry we need more ctfs and there are new KOTH machines out there we want a new KOTH VIDEO ALSO!!! WANT TO SEE PEOPLE Lynched by you 😆😅
@krish12180
@krish12180 3 жыл бұрын
Long form and verbose is the way to do this.
@learn_offsec
@learn_offsec 3 жыл бұрын
Can you please do videos for Cyber Security Germany challenge
@Minecodes
@Minecodes 3 жыл бұрын
Well, this is a nice challange, bu i missed it too XDD
@GodModeMaker
@GodModeMaker 3 жыл бұрын
I love Verbosity. Don't stop being Verbose. Ever. sudo johnhammond -vvvv
@logiciananimal
@logiciananimal 3 жыл бұрын
I think it is interesting to name a CTF game an "apocalypse", as that literally means something like an unveiling or uncovering.
@cocosloan3748
@cocosloan3748 3 жыл бұрын
You are fucking amazing John !
@tanrrivtko1249
@tanrrivtko1249 3 жыл бұрын
My head hurts.
@DHIRAL2908
@DHIRAL2908 3 жыл бұрын
Haha just when I saw the curl prompt, the first thing I would try will be file:///
@karthika3357
@karthika3357 3 жыл бұрын
What song play in outro?
@killerskincanoe
@killerskincanoe 3 жыл бұрын
Will there be a secret plz subscribe command? It's the main reason why I watch.
@danielma2824
@danielma2824 3 жыл бұрын
hello i have a problem in hack the box (challenge/ hardware) can you help me ??the file open .sal (the challengs Debugging Interface) can you me a tip
@tylersmith8245
@tylersmith8245 3 жыл бұрын
I love the deep dives. I'm a web application developer and have been watching your channel to get a better grasp on security, and by the end of each video my face is basically surprised_pikachu.gif
@annankazi6628
@annankazi6628 3 жыл бұрын
HEY SIR HOPE YOU'LL REPLY SIR HOW CAN I KNOW THAT SOMEONE HAS HACKED MY ANDROID?? PLZ REPLY ME SIR!!
@bbott-britishbroadcastingo535
@bbott-britishbroadcastingo535 3 жыл бұрын
I really think he should‘ve done „curl file:///flag“
@_JohnHammond
@_JohnHammond 3 жыл бұрын
I showcase that at the end of the video and explain that that is the best solution?
@sumedh1678
@sumedh1678 3 жыл бұрын
Doggo CTF Walkthrough, Please?
@FaZeInvite17
@FaZeInvite17 3 жыл бұрын
just for the yt algo :))
@worldaroundyou593
@worldaroundyou593 3 жыл бұрын
💻💣🛸
@tamilxctf4075
@tamilxctf4075 3 жыл бұрын
Human doing ctf 🤔..
@dobermanelliot8129
@dobermanelliot8129 3 жыл бұрын
keep great job John, dont stop beeing verbose, we love it! if u just come and write "okay its ease lets file:///flag" we would not watch it! cya ;)
@theITGuy-no3nt
@theITGuy-no3nt 3 жыл бұрын
I think most of us watch for the verbosity, John.
@Ca1vema
@Ca1vema 3 жыл бұрын
Can you actually put a video description in a description box? Not only ads? It’s there for a reason.
@debtlesspig7685
@debtlesspig7685 3 жыл бұрын
78mins tick tok
@kraemrz
@kraemrz 3 жыл бұрын
For yt algorithm
@joelpainchaud4887
@joelpainchaud4887 3 жыл бұрын
Algorithm token
@gauravbisht9622
@gauravbisht9622 3 жыл бұрын
ethical hacker ed sheeran lite 😂😂
@prabingurung4844
@prabingurung4844 3 жыл бұрын
hey John, what's going on ( ̄_, ̄ )
@alpacasecurity9915
@alpacasecurity9915 3 жыл бұрын
LOL I uploaded a webshell and then found the flag
@rajeshvayalar965
@rajeshvayalar965 3 жыл бұрын
മലയാളി ഇല്ല
@b0b2600
@b0b2600 3 жыл бұрын
Verbose is good. - v
@laurenzkaml3864
@laurenzkaml3864 3 жыл бұрын
I had a better solution. You can write a trace file of the request and then just access it like /trace.
@methuso
@methuso 3 жыл бұрын
yes. long and verbose... please :)
@himanishmandal9556
@himanishmandal9556 3 жыл бұрын
Sir, we do know you want to start right away. Why wait after all the channel does belong to you, does it not? Kindest of Regards, Himanish Mandal one of your fans. P. S - Don't find mistakes in my statement I am from India.
XML Object Exfiltration - HackTheBox Cyber Apocalypse CTF "E. Tree"
28:13
Cloudflare CDN CSP - XSS Bypass / HackTheBox Cyber Apocalypse CTF
40:49
ШЕЛБИЛАР | bayGUYS
24:45
bayGUYS
Рет қаралды 382 М.
Зу-зу Күлпәш. Стоп. (1-бөлім)
52:33
ASTANATV Movie
Рет қаралды 273 М.
ISSEI funny story😂😂😂Strange World | Pink with inoCat
00:36
ISSEI / いっせい
Рет қаралды 12 МЛН
TryHackMe! Tartarus - Website Password Bruteforcing
31:59
John Hammond
Рет қаралды 94 М.
SQLite Blind SQL Injection - HackTheBox Cyber Apocalypse CTF
35:25
John Hammond
Рет қаралды 70 М.
JSON Web Keys (JWK & JWT) - "Emergency" - HackTheBox Business CTF
29:09
Blind MongoDB NoSQL Injection - HackTheBox Cyber Apocalypse CTF
19:11
GoogleCTF - Cross-Site Scripting "Pasteurize"
29:21
John Hammond
Рет қаралды 96 М.
How I Passed the OSCP in 8 Hours (On My First Attempt!)
18:18
Tyler Ramsbey
Рет қаралды 79 М.
TryHackMe! Bypassing Upload Filters & DirtySock
53:38
John Hammond
Рет қаралды 67 М.
How to know if your PC is hacked? Suspicious Network Activity 101
10:19
The PC Security Channel
Рет қаралды 1 МЛН
ШЕЛБИЛАР | bayGUYS
24:45
bayGUYS
Рет қаралды 382 М.