TryHackMe! Skynet - Wildcard Injection

  Рет қаралды 109,658

John Hammond

John Hammond

3 жыл бұрын

Come play the GuidePoint Security CTF! go.guidepointsecurity.com/202...
For more content, subscribe on Twitch! / johnhammond010
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
PayPal: paypal.me/johnhammond010
E-mail: johnhammond010@gmail.com
Discord: johnhammond.org/discord
Twitter: / _johnhammond
GitHub: github.com/JohnHammond

Пікірлер: 251
@jonny-mp3
@jonny-mp3 3 жыл бұрын
That python bruteforcer is a lifesaver
@eXfilPr4tik
@eXfilPr4tik 3 жыл бұрын
True
@PreetisKitchenltr
@PreetisKitchenltr 3 жыл бұрын
Not Working For Me... Another Room By The Way...
@nullpwn
@nullpwn 3 жыл бұрын
john: makes a py script out of nothing in less than 2 minutes me on google: "how to declare a variable"
@eXfilPr4tik
@eXfilPr4tik 3 жыл бұрын
True XD
@praisong7475
@praisong7475 3 жыл бұрын
Learn python. It'll be worth it and fun to play with
@raihanrabbani386
@raihanrabbani386 3 жыл бұрын
yeah its straight tho!
@jozef187
@jozef187 3 жыл бұрын
😂😂
@LuisAlberto-si9hn
@LuisAlberto-si9hn 3 жыл бұрын
True that AHAHHAHA
@Mosern1977
@Mosern1977 3 жыл бұрын
As a developer - very interesting to see your approach to finding weaknesses. I can sort of see the fun in this kind of activity, the lure of the dark side :)
@Urzgag
@Urzgag 3 жыл бұрын
Nice vid John :) Btw : The "balls have zero to me" stuff was from an experiment, letting 2 AIs talk to each other with a set alphabet but no actual grammatical rules. After a while, they just came up with their own way of communicating :D
@stevenhernandez3243
@stevenhernandez3243 3 жыл бұрын
love the content and the way you explain everything so thoroughly! id also much rather see you walk through a script like that than if you didnt
@oaklyfoundation
@oaklyfoundation 3 жыл бұрын
This is why i like John more then ipsec, this is more learning then walkthrough
@mikee.
@mikee. 3 жыл бұрын
That tar exploit is INSANE, how have I *never* heard of "the * exploit"??
@compromyse
@compromyse 3 жыл бұрын
RIP all terminator references.
@Deathfreeze14
@Deathfreeze14 3 жыл бұрын
John, I must say please do more of these vids are awesome and the talking through your process is exceptional
@takeiteasyeh
@takeiteasyeh 3 жыл бұрын
heretic, not confirming with ls after mkdir.
@osamaamarneh5762
@osamaamarneh5762 3 жыл бұрын
Lmfao
@_caracalla_
@_caracalla_ 3 жыл бұрын
thats true lol
@meercat1880
@meercat1880 Жыл бұрын
i have never had an original experience huh
@jeffthechef69
@jeffthechef69 11 ай бұрын
Nope
@alexclarke6839
@alexclarke6839 3 жыл бұрын
Hey John, been loving how much detail you go into when doing these videos. Keep up the great content!
@aspxDEFINED
@aspxDEFINED 3 жыл бұрын
This was incredible. Thanks for the content John!
@karangadhave9002
@karangadhave9002 3 жыл бұрын
Learnt a lot through this live walkthrough, well narrated and explained. The best part is the way you put out your way of approaching the next possibility, that definitely helped me in knowing how to process my thoughts during a CTF
@meeDamian
@meeDamian 2 жыл бұрын
This is probably the most educational video on the topic I've ever seen, and I've seen a lot. Amazing.
@salimzavedkarim230
@salimzavedkarim230 Жыл бұрын
Been loathing reading all those articles about wildcard injection.... Thanks for the video man :)
@durzua05
@durzua05 3 жыл бұрын
Holyyyy that curl to python requests and the bruter you wrote just blew my mind. Good stuff John I really love your videos.
@christianmanalaysay
@christianmanalaysay 2 жыл бұрын
wow... exploiting the tar wildcard to set the SUID bit on /bin/bash is so freaking smart and cool man, I was stunned by how amazing that was. I'm trying to better myself at pentesting and John, you are teaching me amazing things! Thank you so much!
@AhmedMohamed-kn9sf
@AhmedMohamed-kn9sf 4 ай бұрын
I wanted it for 1 time and will be watching it for a few more times to note all the things taught here. Thank you so much for your efforts. I do respect you and your talent. 😇
@Child0ne
@Child0ne 2 жыл бұрын
this video was awesome! i learned Sooooo much! thank you so much john, your the man brother!
@mattstorr
@mattstorr 3 жыл бұрын
Love this approach John. Its raw, honest and not contrived (i.e. doesnt come over as you've already completed it and are now just going back through the motions!). Its far more enjoyable to listen to your thought process this way, and you still seem to manage to keep things easy to understand. Nice work :-) Subbed.
@mattstorr
@mattstorr 3 жыл бұрын
And thanks for introducing me to Terminator. Its my new favourite 'tmux' alternative :-) Now to work out what distro you are using...... ;)
@allesnikt
@allesnikt Жыл бұрын
Just found your channel and subscribed. Awesome videos and explanations
@uniquechannelnames
@uniquechannelnames 2 жыл бұрын
Thanks for this I was having trouble with the tar wildcard portion!
@TntTnt-oz7iv
@TntTnt-oz7iv 2 жыл бұрын
That was incredible thanks for your work
@johnmcconnell4030
@johnmcconnell4030 2 жыл бұрын
You are amazing! Thanks for the walk through!
@cooliceman0001
@cooliceman0001 3 жыл бұрын
Had a great time watch you work your magic. Im still learning and watching your videos really helps! Thanks john
@bryttontsai6068
@bryttontsai6068 3 жыл бұрын
Amazing videos with great explanations to beginners instead of just cruising through all the answers without explaining the reasoning behind anything.
@jocularich
@jocularich 2 жыл бұрын
this video inspired me more...thanks John
@jonathangorelik7849
@jonathangorelik7849 4 ай бұрын
super creative privelage escalation john! amazing content please keep it coming!
@shawn8163
@shawn8163 3 жыл бұрын
Great video like walk throughs to see your process.
@RycnGaming
@RycnGaming 3 жыл бұрын
Thank you very much for each video you upload. I am a cybersecurity student and always I get upset, I put one of your video and get motivated to keep on.. thank you 🙏
@SamerAlhasweh
@SamerAlhasweh Жыл бұрын
i enjoyed every single moment of this
@jeprox718
@jeprox718 3 жыл бұрын
CTFs are so fascinating ..enjoyable content! keep it coming!
@sylvesterrac3792
@sylvesterrac3792 3 жыл бұрын
Thanks John, I always learn something new
@sandipanmandal3830
@sandipanmandal3830 3 жыл бұрын
Sir u really are a very humble person ❤️❤️
@fangUwU
@fangUwU 3 жыл бұрын
you explain everything so simply ❤️ thanks bruhhh 😘😘
@hayaanrizvi
@hayaanrizvi 2 жыл бұрын
This was one of your best vids so far
@RedBlueLabs
@RedBlueLabs Жыл бұрын
I liked how you used curl to trigger the call back. I will start bringing that into my process
@bmbiz
@bmbiz 2 жыл бұрын
Ah Skynet. One of the best loved THM rooms, I believe. Out of curiosity, I just looked at the conclusion in my own notes and it says "probably my favorite ctf to date." :)
@gngn2973
@gngn2973 3 жыл бұрын
dude, you rock! This was awesome. when I saw the bash-4.3# i was like 😁😁😁
@shiralihusan9344
@shiralihusan9344 3 жыл бұрын
I was as excited as you are when you privilege escalated. This is simply amazing.
@bbowling619
@bbowling619 3 жыл бұрын
Omg. More content! My brain cant keep up. Its literally regurgitating info at this point but im plugged back in . Leggo peeps and thank you once again Mr John !
@testingme7936
@testingme7936 2 жыл бұрын
i learned a lot from your videos thanks
@tobiasgerber3546
@tobiasgerber3546 3 жыл бұрын
Good work. Well done. Learned a lot!
@vojislavpavkovs9124
@vojislavpavkovs9124 Жыл бұрын
Awesome! You are online person out there who cares to explain stuff! Love Your videos!
@osamaamarneh5762
@osamaamarneh5762 3 жыл бұрын
Thank you for an amazing informative educational video ❤️
@Zachucks
@Zachucks 3 жыл бұрын
curl to python... :O how did i not know about this, where has this been my whole life!?
@salatwurzel-4388
@salatwurzel-4388 3 жыл бұрын
I was literally sitting here and saying "bro ... that would helped me so many times" xD
@KevinMsyah
@KevinMsyah 3 жыл бұрын
Please keep making contents like this, we really enjoy watching your vids ,thankss
@rrd_webmania
@rrd_webmania Жыл бұрын
This video is my favorite so far
@playmaker1011
@playmaker1011 3 жыл бұрын
Simply a huge thanks ✊
@demonview6075
@demonview6075 5 күн бұрын
yo awesome vid, crystal clear thanks
@giuliano6535
@giuliano6535 3 жыл бұрын
Thanks for another fun and educational video boss!
@tshidiflo2226
@tshidiflo2226 2 жыл бұрын
John please stop apologizing for doing exactly what we need (going into detail about how you as a pentester would approach this) Its exactly why I love this channel.. its not generic like the others. So please stop and carry on.
@user-ii2hp9tp1z
@user-ii2hp9tp1z 3 жыл бұрын
that wildcard priv-esc is just super nice
@av9401
@av9401 2 жыл бұрын
Thank you!
@randompicks1328
@randompicks1328 3 жыл бұрын
Buddy you are the best I ever seen so far 😍😍😍
@DanielPizarro184
@DanielPizarro184 3 жыл бұрын
so happy that ur channel exists
@anonymoushackeromega6376
@anonymoushackeromega6376 2 жыл бұрын
nothing better then this..john...explnation is wonderfull :)
@lixanderguzman3305
@lixanderguzman3305 3 жыл бұрын
I don’t know what is going on but this seems interesting haha
@brian3947
@brian3947 3 жыл бұрын
You should learn python it’s fun
@lasergamer2869
@lasergamer2869 3 жыл бұрын
@@brian3947 I’ve learnt python but this is not just python haha. It’s also bout networking and managing file stuff
@marco.garofalo
@marco.garofalo 3 жыл бұрын
This was so much fun!
@WafflesASAP
@WafflesASAP 2 жыл бұрын
*John:* "Oh, we have a personal SMB share named milesdyson, that seems random." *Me:* Wait... does John not realize who Miles Dyson was in the Terminator universe? *John (5 mins later):* "I actually haven't seen the Terminator movies." *Me:* ...aha, well that explains that.
@squeelyinc
@squeelyinc 3 жыл бұрын
Great content John, could tell you hadn’t watched the terminator movies once you seem to overlook the miles dyson reference. :-) What sort of hardware and software setup would you recommend for a beginner?
@armandsriekstins7646
@armandsriekstins7646 3 жыл бұрын
It seems like I've found my new favourite channel
@martyn158
@martyn158 2 жыл бұрын
please always go off on tangents like the python one in this video, if anything..... go on to do a video about the tangent and go off into a tangent in that video and then do a video of that tangent and so on and so on, your videos quite literally pushed me in the direction of doing my (now a year in) degree in cybersecurity and the tryhack me rooms, you sir are a legend , thank you for your work
@spoonkrisp8776
@spoonkrisp8776 2 жыл бұрын
I can’t believe that I have seen a 1 hour video on KZfaq and want more
@iAshenBlade
@iAshenBlade 2 жыл бұрын
Can't tell how much I appreciate this was so confused at root privilege escalation lol
@gabrielex
@gabrielex 3 жыл бұрын
So clear, so good!
@johannespain7855
@johannespain7855 3 жыл бұрын
really great live premiere and overall video!
@MrPOWER6000
@MrPOWER6000 3 жыл бұрын
I love it! thank you.
@yusufbilalbatir5221
@yusufbilalbatir5221 3 жыл бұрын
Extremly funny, thank you.
@assassino689
@assassino689 2 жыл бұрын
thanks man!
@nuridincersaygili
@nuridincersaygili Жыл бұрын
Excellent
@dxnxz53
@dxnxz53 2 жыл бұрын
dude this is awesome!
@Z0nd4
@Z0nd4 2 жыл бұрын
Thank you very much.
@werskantti
@werskantti 3 жыл бұрын
When you got to that Miles Dyson Personal Page i was sure that the picture had steganography in it.. :D But where it continued were so much better
@leblanc666666
@leblanc666666 2 жыл бұрын
loved your bin bash suid. My lazy version is simply doing that to the /etc/passwd and login as root. Have all the info I need in a file that I just copy paste everytime! Nice and quick
@0xsudip892
@0xsudip892 3 жыл бұрын
Awesome as always
@benfelts70
@benfelts70 3 жыл бұрын
So awesome!
@master_of_bytes
@master_of_bytes 3 жыл бұрын
Nice video. Learned a lot from that.
@AA-fy7kn
@AA-fy7kn 3 жыл бұрын
Hello John, could you do the Daily Bugle room on T.H.M.? I love the way you approach things and explain them.
@John-hq9kx
@John-hq9kx 3 жыл бұрын
That was a very Interesting video, thank you for this amazing content ! 😁👍
@robertron5303
@robertron5303 3 жыл бұрын
Big ups! Great content 👍👍
@stefank2387
@stefank2387 2 жыл бұрын
Great content
@lioralalouf61
@lioralalouf61 Жыл бұрын
awsome work i love u so much
@stefan.krause
@stefan.krause 2 жыл бұрын
Very nice, thanks for showcasing your way of solving this room. I tried it this morning before I looked at your video. Since I cannot code in python I had a similar script as bash script, but never made it working because I forgot sending the hidden fields .. I don't know if the room is an easy one, I was lost after finding the user.txt Still a lot to learn I guess :)
@siddheshghag5889
@siddheshghag5889 3 жыл бұрын
Nice execution.
@NimbleSF
@NimbleSF Жыл бұрын
I'm not gonna lie, I was super annoyed once I realized how much work had to be put in at the end lol. I thought I was a rockstar until it got to the cuppa part. Then getting that stable shell and actually figuring out what to do? Infuriating. Thank you for your time an mentorship doing rooms like this for us. I wish this was something I could do on my own, but maybe THM is designed just for walkthroughs just like this so we can learn.
@holabola9064
@holabola9064 2 жыл бұрын
Awesome video
@codermomo1792
@codermomo1792 4 ай бұрын
thank you very mush. this was helpfull
@yossig7316
@yossig7316 3 жыл бұрын
thank you, thank you, thank you!
@dannelson2590
@dannelson2590 3 жыл бұрын
Awesome video!
@mikes_.5_cent
@mikes_.5_cent 3 жыл бұрын
@John, thanks
@williamsys1504
@williamsys1504 3 жыл бұрын
Love the video!
@adminservice9459
@adminservice9459 3 жыл бұрын
John Hammond for president everyone!
@toolbgtools
@toolbgtools Жыл бұрын
that SUID trick was cool
@mr.holmes4149
@mr.holmes4149 3 жыл бұрын
Awesome vid! 👌
@yusif2233
@yusif2233 3 жыл бұрын
Yoo that's amazing
@bladesvlogs4965
@bladesvlogs4965 3 жыл бұрын
Sweet Video! Didn't understand 95%, but it looked cool :)
@JustSomeAussie1
@JustSomeAussie1 3 жыл бұрын
On the part where you used python to check for logins i'm pretty sure you could use a session to make it a lot faster. s = requests.Session() s.post(url)
@zig0to
@zig0to 3 жыл бұрын
The problem seems to be SquirrelMail taking time to process requests, setting up a session won't help with it
@Omar-gw8lt
@Omar-gw8lt 3 жыл бұрын
Awesome John Hammond but you let me down by not watching the terminator movie just kidding, if you do get the chance only watch 1 & 2 don't bother with the rest. lol
@wanishoaib_
@wanishoaib_ 3 жыл бұрын
Love ur vids
@jonasbadstubner2905
@jonasbadstubner2905 3 жыл бұрын
LastPass better sponsor you now. Nice placement right there.
Bruteforcing MFA & Fail2ban Manipulation - TryHackMe! (Biteme)
44:38
TryHackMe! Bypassing Upload Filters & DirtySock
53:38
John Hammond
Рет қаралды 67 М.
Godzilla Attacks Brawl Stars!!!
00:39
Brawl Stars
Рет қаралды 10 МЛН
The magical amulet of the cross! #clown #小丑 #shorts
00:54
好人小丑
Рет қаралды 21 МЛН
Useful Gadget for Smart Parents 🌟
00:29
Meow-some! Reacts
Рет қаралды 10 МЛН
Көтіңді қысып, ауылға қайт! | АСАУ | 2 серия
33:16
CVE-2021-44228 - Log4j - MINECRAFT VULNERABLE! (and SO MUCH MORE)
34:52
TARGETED Phishing - Fake Outlook Password Harvester
47:09
John Hammond
Рет қаралды 256 М.
Hack Smarter Security -- TryHackMe - [Official Walkthrough!]
1:14:11
Tyler Ramsbey
Рет қаралды 2,2 М.
Gitlab LFI to RCE - HackTheBox "Laboratory"
1:13:44
John Hammond
Рет қаралды 114 М.
Finding WEIRD Devices on the Public Internet
27:48
John Hammond
Рет қаралды 172 М.
He tried to hack me...
34:15
John Hammond
Рет қаралды 373 М.
Snip3 Crypter/RAT Loader - DcRat MALWARE ANALYSIS
1:42:04
John Hammond
Рет қаралды 493 М.
TryHackMe GAMING SERVER - LXD Privilege Escalation
34:50
John Hammond
Рет қаралды 162 М.
Binary Exploitation Deep Dive: Return to LIBC (with Matt)
2:12:41
John Hammond
Рет қаралды 184 М.
The Apex Legends Hacker: Destroyer2009
21:47
John Hammond
Рет қаралды 114 М.
Godzilla Attacks Brawl Stars!!!
00:39
Brawl Stars
Рет қаралды 10 МЛН