HTB Cyber Apocalypse - cURL As a Service

  Рет қаралды 37,245

John Hammond

John Hammond

3 жыл бұрын

Moving your first steps into hacking? Start from HTB Academy: bit.ly/3vuWp08
Hungry for more hacking training? Join Hack The Box now: bit.ly/331nQCl
For more content, subscribe on Twitch! / johnhammond010
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
PayPal: paypal.me/johnhammond010
E-mail: johnhammond010@gmail.com
Discord: johnhammond.org/discord
Twitter: / _johnhammond
GitHub: github.com/JohnHammond

Пікірлер: 103
@NateRoberts
@NateRoberts 3 жыл бұрын
You say “you talked too much” but for a beginner your deep dives/verbosity definitely help someone like me. So it’s greatly appreciated, thanks so much for the content.
@jwoo13
@jwoo13 3 жыл бұрын
I really appreciate you "thinking out loud" as to what you're doing at each step; it helps a lot of us learn as that fits our learning style.
@vanshajdhar9223
@vanshajdhar9223 3 жыл бұрын
Yes I agree
@mjtonyfire
@mjtonyfire 3 жыл бұрын
John, man... Do NOT stop being verbose. Your train of thought whilst solving a problem is INVALUABLE. I don't think there's another youtuber out there that gives us this fine grain critical thinking regards hacking/CTF/stuff. I'll watch one of your vids from start to finish the first time, then I'll be going slower through the next play through, taking notes, following along... This is the best way to learn. Keep going. You've just earned another patreon. Thanks man.
@Zygorg
@Zygorg 3 жыл бұрын
Yes
@YeffRamos
@YeffRamos 3 жыл бұрын
love how descriptive and verbose these are actually... even if we use curl every day it's nice to see somebody go in-depth with it.
@lepsycho3691
@lepsycho3691 3 жыл бұрын
I really like to hear your thought process, it gives me a lot of insights on how to approach a challenge like this!
@steps0x029a
@steps0x029a 3 жыл бұрын
Love the talking-to-yourself and thinking-out-load approach, it really helps with understanding the process!
@tsustyle6263
@tsustyle6263 3 жыл бұрын
I've said this before and I'm going to say it again. I learn more in 30 minutes watching John's videos than I do in 3 hours with any other teaching medium. Incredible job as always. Thank you.
@nikkittb
@nikkittb 2 жыл бұрын
I really like how you took the time to explain all the steps you took here John! Even explaining the little things, like what ngrok does and how you spin it up! Loving the content man!
@JimmyGeschwind
@JimmyGeschwind 3 жыл бұрын
I like that you go through and show the whole process and not just jump on the solution. I feel that I learn more from that approach. Keep it up!
@saidjuma1433
@saidjuma1433 3 жыл бұрын
I always learn something new when i see a upload from you. Keep up the good work my mans
@yoshi5113
@yoshi5113 3 жыл бұрын
I love how the way you explain the tricks, thanks a lot John, Love from Indonesia.
@peterchari3839
@peterchari3839 3 жыл бұрын
Great walk through video. Clear explanation. Its very easy to follow.
@nouriyacine8823
@nouriyacine8823 3 жыл бұрын
I loved CTF games because of you dear . Can't stop learning more abd more all thee day. Thanks so much for everything you share with us.
@kylejessup5740
@kylejessup5740 3 жыл бұрын
Happy to see some Cyber Apocalypse videos, I'm a beginner at this stuff and only found a few flags in this CTF. I will definitely watch more.
@jimpowers4463
@jimpowers4463 3 жыл бұрын
Great video, so awesome that HTB spun up the game for you to make these videos for us.
@hjorturpalmipalsson4521
@hjorturpalmipalsson4521 3 жыл бұрын
Always fun to see different take on those challenges. I used the -o flag in curl, it allows us to output the content of the curl into a file. With that in mind, I just curled a webshell file and outputted it into the static js folder and then executed it via the browser.
@AustinReed1
@AustinReed1 Жыл бұрын
John I had to hop on here and leave a comment, you are great man keep up the good work, I just saw one of the CTF's you were in and it was obvious they were being assholes, muting you on purpose, being snide then dismissing you at the end was shitty and inexcusable. Good for you for taking the high road and being tactful during the whole event and never uttering a negative word about that guy. Keep up the awesome work, the world needs more people like you!
@shauncollins1280
@shauncollins1280 3 жыл бұрын
Love you man... Thank you so much 🙏
@ez-it-solutions9128
@ez-it-solutions9128 3 жыл бұрын
It's very difficult to hit every audience and talent level but these are the kind of video's worth paying for! A shorter, summed up version that skips specific steps or lacks the long-winded explanations is what most video's provide - but you provide the most thorough and absolute content! Keep it coming - What you call long-form or verbose is what makes it easy for everyone to follow.
@eklypzn
@eklypzn 3 жыл бұрын
Solid video. I was like yelling at the screen early about the methods. I definitely had a few questions about source code answered for me and I'll probably end up referring to this video again.
@wilcosec
@wilcosec 3 жыл бұрын
This was a fun one! Thanks John!
@xBrownnyx
@xBrownnyx 3 жыл бұрын
It is worthwhile, thanks. Great video!
@Devinatron
@Devinatron 3 жыл бұрын
I feel dumb now seeing how simple it was. I got too far in the weeds during the event on this one, but I really appreciate the thinking out-loud! I'll get better at these, thanks for the awesome vid!
@mrbeancanman
@mrbeancanman 3 жыл бұрын
its definitely worth while! more of this please :D
@TheDyscontinuum
@TheDyscontinuum 3 жыл бұрын
Much appreciated good sir
@asmedeus448
@asmedeus448 3 жыл бұрын
I learn something today. Thank you.
@petehinch3871
@petehinch3871 3 жыл бұрын
Love your Videos John
@atishkumarpradhan9759
@atishkumarpradhan9759 3 жыл бұрын
The thought process is really helpful brother :)
@_d47_
@_d47_ 3 жыл бұрын
Thanks bro, i really like watch your videos
@akay9030
@akay9030 3 жыл бұрын
Always wait for your videos...awesome work ..keep it up,plz upload ctf more often
@theITGuy-no3nt
@theITGuy-no3nt 3 жыл бұрын
@johnhammond Sorry for the second comment, but this is like the 10th time I have heard you apologize for being verbose in explanation, video length, or for "fumbling" through a challenge. I can not state strongly enough that those things are *precisely* why I watch your videos, and I feel that I am not alone. I do not give a fetid pair of dingo's kidneys about the a-b-c steps of solving any particular challenge; it is the thought process that leads to the solution that interests me. I enjoy watching you beat your head against walls, as would anyone who ever pounded a keyboard in fury whilst screaming "What the *actual* $%@# ?" Keep it up. What you are doing works.
@hayaanrizvi
@hayaanrizvi 3 жыл бұрын
Exactly, couldn't have said it better myself
@theITGuy-no3nt
@theITGuy-no3nt 3 жыл бұрын
@@hayaanrizvi Thanks
@THRE3KINGZStudios3kz
@THRE3KINGZStudios3kz 3 жыл бұрын
Ayo I seen you on a recommended vid by Joshua Fluke discussing Cyber Sec and I started off just like you mane I was into making video games and I started in unity and UE5, got my degree in CIS, and lately I’ve been sharpening my technical skills. I want to get the Cyber MOS in the Army and AF and since I recently graduated, like this week, I been putting together my resume and trying to soak in as much info as possible bc We really want this job you know! Well anyways it’s nice to find someone with some things in common and your vids are very informative!
@adnentrimech7958
@adnentrimech7958 3 жыл бұрын
THANKS
@talinross
@talinross 3 жыл бұрын
Best video ever !
@joehollon317
@joehollon317 3 жыл бұрын
Great vid
@ajaymandal2560
@ajaymandal2560 3 жыл бұрын
Worth while ❤️👌
@vellankiindeevar5530
@vellankiindeevar5530 3 жыл бұрын
Man your vids are so engaging
@devil874
@devil874 3 жыл бұрын
oh thats nice i used: -o argument to uplaod a .php file that printed the flag its great i kinda allways learn something watching you
@ilyesdhiaeddine6610
@ilyesdhiaeddine6610 3 жыл бұрын
yes please keep this format
@nothingreallymatters7530
@nothingreallymatters7530 3 жыл бұрын
it's super worth it just beginner like me.
@LinuxSploitOfficial
@LinuxSploitOfficial 3 жыл бұрын
Amazing Thumbnail ♥️
@_CryptoCat
@_CryptoCat 3 жыл бұрын
thats cool you got the -T flag to work! i was playing around with it for a while before eventually solving with file:/// 😀
@telnobynoyator_6183
@telnobynoyator_6183 2 жыл бұрын
I though of the same thing ! So file IS a solution...
@bhagyalakshmi1053
@bhagyalakshmi1053 Жыл бұрын
Nice 👍
@dedkeny
@dedkeny 3 жыл бұрын
Almighty Algo STUFF!!!!!!!!!
@bhagyalakshmi1053
@bhagyalakshmi1053 11 ай бұрын
Work full this one to track is a nice easy to work my headel jobs
@morsi7842
@morsi7842 3 жыл бұрын
Big fan from Egypt, I really appreciate your work. Thank you for sharing such knowledge
@CyberSecForce
@CyberSecForce Жыл бұрын
Great
@amine250
@amine250 3 жыл бұрын
That was a nice challenge
@andydietz7434
@andydietz7434 3 жыл бұрын
Love the explanation and please don't think you are being "Long Winded". I agree with the others, that this is great explanations for beginners or just to understand what you are thinking!! Please keep it up and yes, we want more CTF writeup videos. Also what is the song that is in the end of the video, it is stuck in my head and I want to go find it so I can listen to it while work on my hacker skilz!!
@JoPraveen
@JoPraveen 3 жыл бұрын
👏✨
@alexandrohdez3982
@alexandrohdez3982 Жыл бұрын
👏👏👏👏👏
@savoyblue777
@savoyblue777 3 жыл бұрын
If you don't mind John What terminal do use on your system? And thank you for all you do to help us all
@BRYDN_NATHAN
@BRYDN_NATHAN 3 жыл бұрын
Thank you. KZfaq
@THRE3KINGZStudios3kz
@THRE3KINGZStudios3kz 3 жыл бұрын
My twin and I are both in the military but not branched or have MOS yet and we were told we shouldn’t get our certs before going in just wait... I kinda wished I already gotten them trying to get at least our Sec+ first 😂😂😂
@viv_2489
@viv_2489 3 жыл бұрын
Waiting for this
@jeffersonding5898
@jeffersonding5898 3 жыл бұрын
A great resource to use instead of reading through thousands of lines of manuals is GTFOBins. Has may important exploits and examples implemented already
@avasonds
@avasonds 3 жыл бұрын
yo John your a beast I've been watching your videos, so when is the nsa hiring you?
@ayush_panwar1
@ayush_panwar1 3 жыл бұрын
Another awesome video 👏👏 But we r hungry we need more ctfs and there are new KOTH machines out there we want a new KOTH VIDEO ALSO!!! WANT TO SEE PEOPLE Lynched by you 😆😅
@jaopredoramires
@jaopredoramires 3 жыл бұрын
is this your `classic` ubuntu box? always wanted to know which version it is also, took me ages to figure out you were on XFCE
@cocosloan3748
@cocosloan3748 3 жыл бұрын
You are fucking amazing John !
@tanrrivtko1249
@tanrrivtko1249 3 жыл бұрын
My head hurts.
@mossdem
@mossdem 3 жыл бұрын
We know you wanna just release it now John…
@telnobynoyator_6183
@telnobynoyator_6183 2 жыл бұрын
I immediately though of (and saw) the FILE protocol I wonder if that's going to be the answer
@krish12180
@krish12180 3 жыл бұрын
Long form and verbose is the way to do this.
@holigan5392
@holigan5392 3 жыл бұрын
Make a tutorial for black box pen testing
@GodModeMaker
@GodModeMaker 3 жыл бұрын
I love Verbosity. Don't stop being Verbose. Ever. sudo johnhammond -vvvv
@Minecodes
@Minecodes 3 жыл бұрын
Well, this is a nice challange, bu i missed it too XDD
@rebootlinux608
@rebootlinux608 3 жыл бұрын
I have a question do you use ubuntu on your hardware or as a virtual machine?
@logiciananimal
@logiciananimal 3 жыл бұрын
I think it is interesting to name a CTF game an "apocalypse", as that literally means something like an unveiling or uncovering.
@FaZeInvite17
@FaZeInvite17 3 жыл бұрын
just for the yt algo :))
@learn_offsec
@learn_offsec 3 жыл бұрын
Can you please do videos for Cyber Security Germany challenge
@DHIRAL2908
@DHIRAL2908 3 жыл бұрын
Haha just when I saw the curl prompt, the first thing I would try will be file:///
@killerskincanoe
@killerskincanoe 3 жыл бұрын
Will there be a secret plz subscribe command? It's the main reason why I watch.
@dobermanelliot8129
@dobermanelliot8129 3 жыл бұрын
keep great job John, dont stop beeing verbose, we love it! if u just come and write "okay its ease lets file:///flag" we would not watch it! cya ;)
@tylersmith8245
@tylersmith8245 3 жыл бұрын
I love the deep dives. I'm a web application developer and have been watching your channel to get a better grasp on security, and by the end of each video my face is basically surprised_pikachu.gif
@worldaroundyou593
@worldaroundyou593 3 жыл бұрын
💻💣🛸
@karthika3357
@karthika3357 3 жыл бұрын
What song play in outro?
@danielma2824
@danielma2824 3 жыл бұрын
hello i have a problem in hack the box (challenge/ hardware) can you help me ??the file open .sal (the challengs Debugging Interface) can you me a tip
@kraemrz
@kraemrz 3 жыл бұрын
For yt algorithm
@annankazi6628
@annankazi6628 3 жыл бұрын
HEY SIR HOPE YOU'LL REPLY SIR HOW CAN I KNOW THAT SOMEONE HAS HACKED MY ANDROID?? PLZ REPLY ME SIR!!
@theITGuy-no3nt
@theITGuy-no3nt 3 жыл бұрын
I think most of us watch for the verbosity, John.
@bbott-britishbroadcastingo535
@bbott-britishbroadcastingo535 3 жыл бұрын
I really think he should‘ve done „curl file:///flag“
@_JohnHammond
@_JohnHammond 3 жыл бұрын
I showcase that at the end of the video and explain that that is the best solution?
@debtlesspig7685
@debtlesspig7685 3 жыл бұрын
78mins tick tok
@sumedh1678
@sumedh1678 3 жыл бұрын
Doggo CTF Walkthrough, Please?
@Ca1vema
@Ca1vema 3 жыл бұрын
Can you actually put a video description in a description box? Not only ads? It’s there for a reason.
@joelpainchaud4887
@joelpainchaud4887 3 жыл бұрын
Algorithm token
@gauravbisht9622
@gauravbisht9622 3 жыл бұрын
ethical hacker ed sheeran lite 😂😂
@tamilxctf4075
@tamilxctf4075 3 жыл бұрын
Human doing ctf 🤔..
@b0b2600
@b0b2600 3 жыл бұрын
Verbose is good. - v
@alpacasecurity9915
@alpacasecurity9915 3 жыл бұрын
LOL I uploaded a webshell and then found the flag
@rajeshvayalar965
@rajeshvayalar965 3 жыл бұрын
മലയാളി ഇല്ല
@laurenzkaml3864
@laurenzkaml3864 3 жыл бұрын
I had a better solution. You can write a trace file of the request and then just access it like /trace.
@prabingurung4844
@prabingurung4844 3 жыл бұрын
hey John, what's going on ( ̄_, ̄ )
@methuso
@methuso 3 жыл бұрын
yes. long and verbose... please :)
@himanishmandal9556
@himanishmandal9556 3 жыл бұрын
Sir, we do know you want to start right away. Why wait after all the channel does belong to you, does it not? Kindest of Regards, Himanish Mandal one of your fans. P. S - Don't find mistakes in my statement I am from India.
XML Object Exfiltration - HackTheBox Cyber Apocalypse CTF "E. Tree"
28:13
HackTheBox - "Remote" - Umbraco & Windows
48:23
John Hammond
Рет қаралды 81 М.
Mini Jelly Cake 🎂
00:50
Mr. Clabik
Рет қаралды 15 МЛН
0% Respect Moments 😥
00:27
LE FOOT EN VIDÉO
Рет қаралды 39 МЛН
Request v4.12 firmware installation
3:35
岬チャンネル
Рет қаралды 31
SQLite Blind SQL Injection - HackTheBox Cyber Apocalypse CTF
35:25
John Hammond
Рет қаралды 70 М.
These Files Don't Show Their Extension
41:26
John Hammond
Рет қаралды 15 М.
WinUtil May Update #2
Titus Tech Talk
Рет қаралды 50
Cloudflare CDN CSP - XSS Bypass / HackTheBox Cyber Apocalypse CTF
40:49
HAFNIUM - Post-Exploitation Analysis from Microsoft Exchange
1:18:33
John Hammond
Рет қаралды 137 М.
Plundering AWS S3 Buckets - HackTheBox
1:04:04
John Hammond
Рет қаралды 73 М.
Has Generative AI Already Peaked? - Computerphile
12:48
Computerphile
Рет қаралды 141 М.
Mini Jelly Cake 🎂
00:50
Mr. Clabik
Рет қаралды 15 МЛН