Plundering AWS S3 Buckets - HackTheBox

  Рет қаралды 73,420

John Hammond

John Hammond

3 жыл бұрын

For more content, subscribe on Twitch! / johnhammond010
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
PayPal: paypal.me/johnhammond010
E-mail: johnhammond010@gmail.com
Discord: johnhammond.org/discord
Twitter: / _johnhammond
GitHub: github.com/JohnHammond

Пікірлер: 107
@viv_2489
@viv_2489 3 жыл бұрын
Pwncat, linpeas juggling and then that auto deletion of files from files folder.. Entertainment with learning😂.. awesome video....thanks
@mindzhd
@mindzhd 3 жыл бұрын
When I found myself screaming "IT'S IN ADSERVER JOHN!!" I realised I learned something from watching this channel. Thanks John, stinkin love your content! You're one of the more vibrant pen-test people I know of and watching you wiggle your way through this and that is really entertaining and informative at the same time. You could probably teach this stuff professionally through those platforms like skillshare or brilliant!
@InsomniaFire
@InsomniaFire 3 жыл бұрын
He has a great Udemy course
@PalCan
@PalCan 2 жыл бұрын
@@InsomniaFire what is the course called? Thanks
@emporiove
@emporiove 2 жыл бұрын
@@InsomniaFire whats the name of the course?
@rudisrozitis
@rudisrozitis 3 жыл бұрын
1:00:24 got that Batman voice on point! :D
@Devinatron
@Devinatron 3 жыл бұрын
This is fantastic and I'm so happy I found your channel! I just participated in my first CTF (HTB Cyber Apocalypse) and it was so much fun! I didn't do too great, but learned a ton. Thanks for getting me into this fun 'hobby' to help build my skills as I work towards a career shift.
@sneezeman
@sneezeman 3 жыл бұрын
Love that everytime John tries to showcase Pwncat it just breaks in some way
@Cumander1
@Cumander1 10 ай бұрын
Beginner here. And i look up to the mountains and i see John Hammond😅...and my journey begins.
@wilcosec
@wilcosec 3 жыл бұрын
Fun walkthrough of a great box. Great job, John!
@jmoncadagutierrez
@jmoncadagutierrez 3 жыл бұрын
john this was genuinely one of your best videos!!
@Mslepe_8374
@Mslepe_8374 3 жыл бұрын
this video and your content in general is mind blowing. Truly awesome stuff!
@thatcreole9913
@thatcreole9913 3 жыл бұрын
Brilliant job John. Please keep them coming!
@morsi7842
@morsi7842 3 жыл бұрын
Awesome john, So much useful data in one video.Thanks appreciated
@fadhilsaheer8877
@fadhilsaheer8877 3 жыл бұрын
*Put a magnifying glass on your computer if you see red bugs you are in malware* - John Hammond 2021 😹
@xaxabogbart
@xaxabogbart 3 жыл бұрын
How random - I've met one of the guys who founded Hack The Box. He lives in my hometown. Glad to see it's launching into something really cool and getting attention - not surprised though, he was a very astute fellow.
@andymac7668
@andymac7668 3 жыл бұрын
I do not live in this coding/hacking world at all, but, this was very interesting to watch. Thank you for creating this content
@StevenIngram
@StevenIngram 2 жыл бұрын
It never ceases to amaze me how much of a security hole can be. LOL
@fennex79
@fennex79 Ай бұрын
I love your way of thinking!
@joshuajanssen5341
@joshuajanssen5341 3 жыл бұрын
Loving this type of content!!!!
@TheBrutaline
@TheBrutaline 3 жыл бұрын
I saw your name pop up on the activity feed for the box a couple of days ago. I was hoping you would make it into a video, very cool.
@Basieeee
@Basieeee 3 жыл бұрын
We are now on amazon's watchlist.
@hibdfghf2500
@hibdfghf2500 3 жыл бұрын
I loved this machine !! I learned di much about aws dynamodb
@XiSparks
@XiSparks 3 жыл бұрын
"aws get-buckets" - Uncle Drew
@f_u8264
@f_u8264 3 жыл бұрын
''Dang it'' part really got me!
@munaz55
@munaz55 3 жыл бұрын
awesome content, thanks john
@talinross
@talinross 3 жыл бұрын
Awesome job love it !
@mgillanders
@mgillanders 3 жыл бұрын
Great video John!
@gp6723
@gp6723 2 жыл бұрын
Great, really liked this
@SinusQuell_
@SinusQuell_ 2 жыл бұрын
I learned so much today
@NothingPicksLocks
@NothingPicksLocks 2 жыл бұрын
That was friggin awesome John
@onlylikenerd
@onlylikenerd 3 жыл бұрын
You make it look too easy. I get inspired and try and realize quickly my experience is lacking haha!
@obeydabachir5975
@obeydabachir5975 3 жыл бұрын
You are the best Jonny
@andydwyer4285
@andydwyer4285 2 жыл бұрын
straight up cool
@mushenji
@mushenji 3 жыл бұрын
This is extremely cool
@Kurainu
@Kurainu 3 жыл бұрын
I must say I get some Ippsec Vibes with the Ip Adress and how your saying the nmap stuff :D. But Grreat Video
@mrbeancanman
@mrbeancanman 3 жыл бұрын
love your videos dude !
@ResonantFractal
@ResonantFractal 3 жыл бұрын
Fun stuff! Wonder what would have happened if you had tried sshing with the usernames in their correct case.
@playmaker1011
@playmaker1011 Жыл бұрын
More Cloud John! Thanks a lot, as always :)
@11anushkariya18
@11anushkariya18 3 жыл бұрын
Great music John Hammond xd
@crazyman7659
@crazyman7659 3 жыл бұрын
John is the best
@imranthoufeeque165
@imranthoufeeque165 3 жыл бұрын
Just to inform everyone who are doing OSCP... Linpeas has been banned by oscp because of auto-exploitation feature... Again Linpeas creator reached out to OSCP and confirmed that there is no auto-exploitation feature on linpeas.. So OSCP agrees for the new version of linpeas and banned older version of linpeas so be careful....
@H4cK3r5
@H4cK3r5 3 жыл бұрын
Awesome John !
@ARZ10198
@ARZ10198 3 жыл бұрын
Peculiar john
@secwriteups
@secwriteups Жыл бұрын
First person on yt who doesn't une neither Parrot nor Kali.
@DevashishGuptaOfficial
@DevashishGuptaOfficial 3 жыл бұрын
I wish the audio was a bit louder 🥺
@RccoGamer
@RccoGamer 3 жыл бұрын
+1
@TheYugurtiscrazy
@TheYugurtiscrazy 3 жыл бұрын
@@RccoGamer 1+
@rdktd.
@rdktd. 3 жыл бұрын
agreed
@leonardoorona
@leonardoorona 3 жыл бұрын
nice one John...
@ARIFF861
@ARIFF861 3 жыл бұрын
i wish for more htb content in the future
@pk10006
@pk10006 3 жыл бұрын
Epic skillz
@nmay231
@nmay231 3 жыл бұрын
It contains a bucket. Dear God... Scout, SEDUCE ME!
@JoeM370
@JoeM370 5 ай бұрын
This is top-of-the-line material. I read a similar book that was a huge turning point for me. "AWS Unleashed: Mastering Amazon Web Services for Software Engineers" by Harrison Quill
@PezaoShow
@PezaoShow 3 жыл бұрын
This video show that I know more about something John doesn't, hahah 😂
@jtucker87
@jtucker87 Жыл бұрын
John: How do I use this? Server: tutorial.start() John: Nope...
@luciferreficul1926
@luciferreficul1926 3 жыл бұрын
Nice!
@erosmlima5981
@erosmlima5981 3 жыл бұрын
AWS top! John
@AhrenBaderJarvis
@AhrenBaderJarvis 3 жыл бұрын
Stop saying you're bad at everything. You're learning. I get the temptation but think of everyone watching who likely is newer to this than you. They also are just learning.
@AttkBeast
@AttkBeast 2 жыл бұрын
WWJD, What would John do? That's how I approach these challenges in HTB and THM. After watching these videos your voice and logic get stuck in my head!
@causeitis
@causeitis 3 жыл бұрын
31:46 I think the fi you commented out at the bottom was a mistake
@luciferreficul1926
@luciferreficul1926 3 жыл бұрын
And i like your outro.
@JeremiahShaferSimulacra
@JeremiahShaferSimulacra 2 жыл бұрын
I know NMAP is kind of the go-to for port-scanning. Have you tried Rustscan? It's built on top of NMAP but runs port scans much faster with exactly the same scan options.
@_JohnHammond
@_JohnHammond 2 жыл бұрын
Yes! I have showcased rustscan in other videos and I am definitely a fan, it is a super cool tool and very fast!
@aaryanbhagat4852
@aaryanbhagat4852 2 жыл бұрын
Content is awesome but i would suggest timestamping videos which have length greater then 30 min. Helps a lot!
@cassandradawn780
@cassandradawn780 3 жыл бұрын
nice
@freshios4873
@freshios4873 3 жыл бұрын
Rick and morty creator knows coding??!? This dude can do it all
@sebastian33458
@sebastian33458 3 жыл бұрын
🤯👌🏼💯
@christophmosimann9244
@christophmosimann9244 2 жыл бұрын
Great video, but how did you know that pd4ml had this specific file inclusion vulnerability without researching?
@RCJans
@RCJans 3 жыл бұрын
fudge btw
@John-shreds
@John-shreds 3 жыл бұрын
Does the endpoint url take the place of access keys for the AWS cli? So because it's public you don't need any access & secret keys?
@berndeckenfels
@berndeckenfels 3 жыл бұрын
It triggers me if you add options after arguments, but I like it that you stick to the IPpsec method
@entertainment4you852
@entertainment4you852 3 жыл бұрын
Resources you have shared with us such as KZfaq videos and blogs are enough to crack OSCP exam or should we join any institutions to gain knowledge....?
@kgmyatthu3171
@kgmyatthu3171 3 жыл бұрын
more of this please?
@umutunal6093
@umutunal6093 3 жыл бұрын
Maaan whyyyy whyy u did not shared this 2 days ago. I had a HW project about AWS pentesting. I had got only some old staf...
@whtiequillBj
@whtiequillBj 3 жыл бұрын
it was not possible to see the flickering lights in the video.
@Pr4547h
@Pr4547h 3 жыл бұрын
Audio volume little bit low compared with other videos
@kraemrz
@kraemrz 3 жыл бұрын
For yt algorithm
@btno222
@btno222 2 жыл бұрын
Hey There Seth Rogan!
@vibiemood1079
@vibiemood1079 3 жыл бұрын
Ooop...the voice is little down ...!!
@aryanmajumder1090
@aryanmajumder1090 3 жыл бұрын
Showing Root_id_rsa : invalid format . Why?
@blackmrx6319
@blackmrx6319 Жыл бұрын
Nice HTML LFI xD
@lugasiyt899
@lugasiyt899 2 жыл бұрын
Yo how do u Zoom In in the terminal Lol
@0xbinHex
@0xbinHex 3 жыл бұрын
What a handsome whitehead
@djcb4190
@djcb4190 Жыл бұрын
You plunder
@adityagupta3870
@adityagupta3870 3 жыл бұрын
Hey. John... Please make a course for newbies to advanced 😭😭🙏🏿🙏🏿🙏🏿please
@alimohammadi1148
@alimohammadi1148 3 жыл бұрын
You getting more views than ippsec now 🤨
@TheHappyXD
@TheHappyXD 2 жыл бұрын
how come he was able to use aws cli on the bucket despite using random secrets?
@kodytrinnier3192
@kodytrinnier3192 2 жыл бұрын
My guess is the bucket was public
@fbmello
@fbmello 3 жыл бұрын
Man you are awesome 🤘🤘🤘......There was only one part that I didn't really understand. How did you run the .php in the S3 bucket??? because S3 only works with static webpage. It was not supposed to run .PHP 🤷‍♂️🤷‍♂️🤷‍♂️
@tomvandencorput1408
@tomvandencorput1408 3 жыл бұрын
You can use the s3 bucket stuff to upload the script. When you then visit the script via port 80, your request will be handled by Apache which will run PHP. If you finish the machine you can see that s3.bucket.htb will be forwarded to a docker container running local stack
@fbmello
@fbmello 3 жыл бұрын
@@tomvandencorput1408 OHHHHHHHHHH that makes sense. Thank you for the explanation.
@80sixd
@80sixd 2 жыл бұрын
i8ts areally awkward watching you pretend to not know this stuff and or have not read these exact pages. Still love the channel
@tanishsaxena545
@tanishsaxena545 3 жыл бұрын
Hello sir I have been watch KZfaq for awhile now i saw your using ubuntu as your primary os soo my question is why u don't use kali or parrot os or any other Linux distribution????????????
@takipsizad
@takipsizad 3 жыл бұрын
ubuntu is for desktop which how he uses
@tanishsaxena545
@tanishsaxena545 3 жыл бұрын
@@takipsizad okkay 😁👍👍
@ajualex3503
@ajualex3503 3 жыл бұрын
Can we hope for htb contents
@kitajskijmost
@kitajskijmost 3 жыл бұрын
Где subtitles?
@d3spis3m3
@d3spis3m3 Жыл бұрын
etc/ is pronounced etsy. not etcetera, is it not? Semantics, but, I love your content. I am aware this video is a year old.
@mmelt
@mmelt 3 жыл бұрын
Please fix the audio - it's too quiet
@nogoodhacker6944
@nogoodhacker6944 3 жыл бұрын
Hey John, Your content is awesome man, but it is not recommended for script kiddies to learn real hacking because your content requires some level of knowledge on hacking/programming, 'coz to be honest, i have been trying to understand your videos where i am now solving ctf challenges and still find it a bit confusing to understand your videos sometimes, anyways it's still a rich content!
@jorides_official
@jorides_official 3 жыл бұрын
where is the flag
@sefterm-zade9744
@sefterm-zade9744 3 жыл бұрын
I said fug guysss😂😂😂😂
@tamilxctf4075
@tamilxctf4075 3 жыл бұрын
Like first 10 comments; else:unsubscribe ("Mv to liveoverpellow");
TryHackMe! Bypassing Upload Filters & DirtySock
53:38
John Hammond
Рет қаралды 67 М.
Mozi Malware - Finding Breadcrumbs...
50:16
John Hammond
Рет қаралды 196 М.
КАКАЯ ХИТРАЯ КОШКА! #cat #funny #pets
00:50
SOFIADELMONSTRO
Рет қаралды 16 МЛН
АВДА КЕДАВРАААААА😂
00:11
Romanov BY
Рет қаралды 4,5 МЛН
LA FINE 😂😂😂 @arnaldomangini
00:26
Giuseppe Barbuto
Рет қаралды 14 МЛН
Bruteforcing MFA & Fail2ban Manipulation - TryHackMe! (Biteme)
44:38
XML Object Exfiltration - HackTheBox Cyber Apocalypse CTF "E. Tree"
28:13
I Tried a Disney Secret Project!
11:33
Marques Brownlee
Рет қаралды 3,4 МЛН
Coding a Web Server in 25 Lines - Computerphile
17:49
Computerphile
Рет қаралды 311 М.
I Bought a Recording Jammer. It’s Legal.
14:00
Linus Tech Tips
Рет қаралды 687 М.
intro to cloud hacking (leaky buckets)
26:02
NetworkChuck
Рет қаралды 119 М.
HackTheBox - "Remote" - Umbraco & Windows
48:23
John Hammond
Рет қаралды 81 М.
HTA JScript to PowerShell - Novter Malware Analysis
1:24:19
John Hammond
Рет қаралды 93 М.
Uncovering NETWIRE Malware - Discovery & Deobfuscation
59:46
John Hammond
Рет қаралды 90 М.