ShellShock & Kernel Exploits - TryHackMe! 0day

  Рет қаралды 79,457

John Hammond

John Hammond

3 жыл бұрын

To help support me, check out Kite! Kite is a coding assistant that helps you faster, on any IDE offer smart completions and documentation. www.kite.com/get-kite/?... (disclaimer, affiliate link) Hang with our community on Discord! johnhammond.org/discord
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
E-mail: johnhammond010@gmail.com
PayPal: paypal.me/johnhammond010
GitHub: github.com/JohnHammond
Site: www.johnhammond.org
Twitter: / _johnhammond

Пікірлер: 106
@djmikeholmes6214
@djmikeholmes6214 3 жыл бұрын
Someone commented "Watching John makes me realize just how little i actually know about cyber-security". Thanks for giving me a reality check xDDD
@kaviyarasup5735
@kaviyarasup5735 3 жыл бұрын
true lol
@GajendraMahat
@GajendraMahat Жыл бұрын
realted lol🤣😂
@abisrug4898
@abisrug4898 3 жыл бұрын
0day was so good in the manner he prepared the box
@0dayCTF
@0dayCTF 3 жыл бұрын
Thank you!!
@abisrug4898
@abisrug4898 3 жыл бұрын
@@0dayCTF ur Story is grt and u deserve respect mate
@ronakjoshi5093
@ronakjoshi5093 3 жыл бұрын
Ryan is a fighter, he has an epic past♥️♥️ #respect
@anishagrawal7068
@anishagrawal7068 3 жыл бұрын
@@0dayCTF was the initial encrypted RSA key really a rabbit hole?
@0dayCTF
@0dayCTF 3 жыл бұрын
@@anishagrawal7068 Yes, that was a completely fake key. I had to do some things to distract from the real exploit!
@ympaquet
@ympaquet 3 жыл бұрын
I've been following you for a bit now and I love those "long and boring" parts! Your videos gave me the spark I needed to dive into InfoSec. Keep it going, i'm feeling a little less dumb each time you get a video out! Cheers!
@nizaabbie4403
@nizaabbie4403 2 жыл бұрын
Thanks for sharing real way of thinking instand of just showing off the answers eventhough you had already pawnd it. Supporting to you!
@ihatethesensors
@ihatethesensors 3 жыл бұрын
Great stuff man - very entertaining! One thing I'm glad for is that you didn't obsessively jot down every detail in a markdown file. It helps the video stay interesting. I suppose the documentation is the video itself. Otherwise documentation is purely for *personal* use. I like it.
@0__0retr0tg6
@0__0retr0tg6 2 жыл бұрын
man i love your videos about ctfs, it's really inspiring and motivates me to keep going i like your dynamic of explaining the videos. and you also demystify the idea that to be a good hacker you have to be an elliot alderson keep going all the love in the world
@samrudhkashyap2865
@samrudhkashyap2865 3 жыл бұрын
good content mate!! plz keep uploading such next level crazy stuff
@testu1testu294
@testu1testu294 6 ай бұрын
To sum up the things I've learned and needed to learn from this video: God bless you, John Hammond!!
@ElliyahuRosha
@ElliyahuRosha 3 жыл бұрын
Me: Satisfying yt algo. Also me: enjoying every minute watching JH.
@danielsalloum3006
@danielsalloum3006 3 жыл бұрын
Educational and entertaining. Excellent.
@XiSparks
@XiSparks 3 жыл бұрын
There's that beautiful pea-head!
@GuardianNative
@GuardianNative 4 ай бұрын
Okay. I do not understand all of this YET. but this makes me excited to go deeper into it. Lol I can follow along and it actually makes sense to me 😂. Wow this is awesome. Subbed!
@stevearivera
@stevearivera Жыл бұрын
Just wow, it was awesome seen this in action!
@mdsazzadhossainsajib1387
@mdsazzadhossainsajib1387 Жыл бұрын
Great job great tutorial so far i found about try hack mee series. Go ahead John
@serpasha
@serpasha 7 ай бұрын
Hi John, great job !
@abhhibirdawade9657
@abhhibirdawade9657 3 жыл бұрын
I really enjoy with you and ippsec. You guys are amazing. Like your voice man... See you around
@osincipeu6412
@osincipeu6412 Жыл бұрын
The reaaaal realty hack! Awesome i love it ❤️‍🔥
@pushkarnandwalkar
@pushkarnandwalkar 2 жыл бұрын
solving the machine was fun but infinite scrolling which i didn't knew and I now know was damn good
@adicandra9940
@adicandra9940 4 ай бұрын
I didn't know shit about hacking, and this video give me so many insight how to do offensive hacking (metasploit, cve, the cve poc, etc). This is literally goldmine. I recommend this channel to any software engineer trying to make sense the "hacking world". I tried to watch LifeOverflow channel and most of the time, the content just went over my head because he mostly doing low level stuff. This channel on the other hand, hits closer to home because I use linux daily, so I already familiar with it.
@gouthamj7553
@gouthamj7553 3 жыл бұрын
Oh yeah legend in action 😂😊 waiting John bro ☺️
@HomelessDeamon
@HomelessDeamon 3 жыл бұрын
John Hammond .... +1 You ROCK!!!!!!!!!
@GuardianNative
@GuardianNative 4 ай бұрын
No.. I understood a lot more than I thought I would ❤❤❤
@abdullatifnizamani6850
@abdullatifnizamani6850 2 жыл бұрын
amazing dude
@bgokj1
@bgokj1 3 жыл бұрын
I Really love your energies ngl. Big fan here haha could you maybe give me some tips on how to get better in cyber security? A beginner here haha. Again big fan
@HowToCyber
@HowToCyber 3 жыл бұрын
Energy really comes from passion. Did you see his reaction when he got root ? That was a priceless expression that only comes out if you are passionate about what you are doing.
@richarddalton4305
@richarddalton4305 3 жыл бұрын
0days box was fun
@mattplaygamez
@mattplaygamez 3 жыл бұрын
The next room is OWASP Juice Shop. It would by fun
@Tekionemission
@Tekionemission Жыл бұрын
(18:57)-SHELL shock reference (20:00)-Need to be an absolute path, cmd using curl (23:41)-Using Metasploit console (26:03)-Upload linpeash via meterpreter (31:04)-searchsploit tack m to mirror the dot c file and upload the dot c file via meterpreter
@mehammered
@mehammered 3 жыл бұрын
I have looked to see if you did a rust scan set up. Could you show how to set up rust scan on kali?
@AcezeroGame
@AcezeroGame 3 жыл бұрын
Wow there's race to be 1st or 2nd didn't know that XD
@Fybir_
@Fybir_ 2 жыл бұрын
that sad moment when he forgets that "export TERM=xterm" allows him to clear screen from the shell
@UmbraAtrox_
@UmbraAtrox_ 3 жыл бұрын
MORE! THE MOB DEMANDS MORE
@sand3epyadav
@sand3epyadav 3 жыл бұрын
Lots of fun
@fastshovel7036
@fastshovel7036 3 жыл бұрын
you were an inspiration to me to start a yt channel in my native language for OffSec and general comluter stuff
@nikolacekov9099
@nikolacekov9099 2 жыл бұрын
Dope
@vb6code
@vb6code 3 жыл бұрын
I'm wondering what is the music name n the end!
@krlst.5977
@krlst.5977 3 жыл бұрын
That was cool
@ARZ10198
@ARZ10198 3 жыл бұрын
John will you showcase HTB battlegrounds ?
@howtohack01
@howtohack01 3 жыл бұрын
i love you so much sir
@causeitis
@causeitis 3 жыл бұрын
Why not use tab completion on files and folders in your terminal?
@mrroobt4968
@mrroobt4968 2 жыл бұрын
thx good joooooooobbb🐯🐯🐯
@ronakjoshi5093
@ronakjoshi5093 3 жыл бұрын
Ryan and john big fan ♥️♥️
@0dayCTF
@0dayCTF 3 жыл бұрын
@chandramouleeswaranv5115
@chandramouleeswaranv5115 3 жыл бұрын
Hi John, I want to know is there a way to take priv esc without using kernel exploit on this box?
@jeremyklein953
@jeremyklein953 3 жыл бұрын
There was a recent bug in the sudo binary that was recently discovered that is supposed to be ~9 years old. That would probably work
@ronnieaggarwal4745
@ronnieaggarwal4745 3 жыл бұрын
love you love from India...........
@swapnilshinde9868
@swapnilshinde9868 3 жыл бұрын
Fun fact: As you know linux sometimes dosen't let you to "do clear screen command". Clear your terminal screen anytime using this guide. Guide: (1)Open terminal and click on 3 dots, then click on preference (2)Then click on 'shortcuts' and then find option named 'reset and clear' option could be 'disabled' (3)Click on "disabled" and enter a special key that you don't use in terminal. (I suggest you use this key)"i am using ''END'' key". And whenever you press that key it will clear terminal screen anywhere.
@camarada1996
@camarada1996 3 жыл бұрын
doesn't 'ctrl+L' work? always use it edit: nvm, probably about the meterperter
@swapnilshinde9868
@swapnilshinde9868 3 жыл бұрын
@@camarada1996 Yes Exactly. When terminal is doing something While processing previously given command, for instance "exploit" in metasploit. You will first have to stop running "whatever" process with Ctrl + c and then you can use "Ctrl + L or clear" command to clear your screen. With method which I wrote, by simply adding a shortcut In terminal you can clear the screen anytime.
@0dayCTF
@0dayCTF 3 жыл бұрын
🙏🙏🙏
@_JohnHammond
@_JohnHammond 3 жыл бұрын
I SEE YOU BOO
@0dayCTF
@0dayCTF 3 жыл бұрын
Ayeeeeee 🙏🙏
@user-be2bs1hy8e
@user-be2bs1hy8e 2 ай бұрын
wait so what if spoofed the dhcp instead of targeting the service
@fahimprotik3203
@fahimprotik3203 Жыл бұрын
Hi ,unfortunately my nikto is not showing any shellshock vulnerability, I could only know from your video ,so then in other cases /cgi-bin/test.cgi can be vulnerable then .If I see these somewhere I should try shellshock
@fahimprotik3203
@fahimprotik3203 Жыл бұрын
I was using parrot os in there nikto doesnt show this vulnerabiltry
@user-us6qm2dr9u
@user-us6qm2dr9u 3 жыл бұрын
29:55? Green screen?
@pjrox9458
@pjrox9458 3 жыл бұрын
anybody saw the irony that john himself couldn't find ssh2john XP.
@ca7986
@ca7986 3 жыл бұрын
❤️
@Randy-nb6fw
@Randy-nb6fw Ай бұрын
why does he prounounce room as rum or rim but not door as dur or dir
@karstenroelofs9216
@karstenroelofs9216 3 жыл бұрын
19:04 who else checked their discord?
@derrenmarcusturner408
@derrenmarcusturner408 3 жыл бұрын
I had no idea Seth Rogan had this side to him
@ih3xo.o433
@ih3xo.o433 3 жыл бұрын
Which os you are using ?
@Bryan_Kay
@Bryan_Kay Жыл бұрын
Linux Kali
@rahishnamikaze1516
@rahishnamikaze1516 3 жыл бұрын
I'm a little late but I'm here
@koomer2237
@koomer2237 3 жыл бұрын
no idea what the fuck im watching but cool i want to do things now
@fedelecavaliere5249
@fedelecavaliere5249 3 жыл бұрын
What does WAAAAAAAK mean LMAO
@alexpearce3083
@alexpearce3083 3 жыл бұрын
31:24 nice nice thats why they pay me the big backs XD
@psychoSherlock
@psychoSherlock 2 жыл бұрын
ssh2john is located on /usr/share/john/ssh2john ❤️
@ivanvalentini9345
@ivanvalentini9345 3 жыл бұрын
ssh2john, just like other john scripts is located at /usr/share/john/ssh2john.py
@enadalotaibi8181
@enadalotaibi8181 3 жыл бұрын
I hate when already solve it without us
@djmikeholmes6214
@djmikeholmes6214 3 жыл бұрын
I think some of the rooms take hours to solve. Couldn't really stream live for that long. Maybe John can answer this a little better.
@enadalotaibi8181
@enadalotaibi8181 3 жыл бұрын
@@djmikeholmes6214 maybe, but it would be awesome if he did
@djmikeholmes6214
@djmikeholmes6214 3 жыл бұрын
@@enadalotaibi8181 It would be truly awesome. I'm hoping his 1000th video is going to be something special for us all. He has done 998 at mo.
@allurbase
@allurbase 3 жыл бұрын
Dud, try Turtles? as the password? maybe??
@jackcarter1897
@jackcarter1897 3 жыл бұрын
I’m getting the ‘cc1’ error message you said you got before filming. Shame you wasn’t able to quickly show what you did to solve it. Made this challenge far too frustrating. I tried to watch your video as less as possible and do it on my own. I thought I was doing something wrong and you ended up using the same exact file as I did, so I knew I didn’t make a mistake. Clearly a bug. Just annoying :(
@morganpg
@morganpg 3 жыл бұрын
hi
@vibhavtiwari7260
@vibhavtiwari7260 3 жыл бұрын
hey john while I try to upload the .c file I'm getting an error "4: Operation failed: 1" and I am using metasploit 6 . Anyone who reads it if he has the solution for this can help me It will be a great pleasure from my side. Please help me with this situation.
@alexpearce3083
@alexpearce3083 3 жыл бұрын
car . secret ahhahaaha
@Liquidhun
@Liquidhun 3 жыл бұрын
Spoiler alert: 32:58
@DarkSide3211
@DarkSide3211 3 жыл бұрын
Im a 12th grade programming student and seeing this kinda overwhelms me lol
@Dpoint0
@Dpoint0 3 жыл бұрын
dont worry broda he is on a very different level, just chill and learn slowly
@jeremyklein953
@jeremyklein953 3 жыл бұрын
Sadly this has nearly nothing to do with programming. Just pen testing.
@cuttlefishn.w.2705
@cuttlefishn.w.2705 2 жыл бұрын
In spirit, metasploit is as much cheating as using google. If anything should be considered cheating or cheap, shouldn't it be linpeas? Because you should already know where to check for privesc vectors, whereas expecting you to know every exploit in every language is ridiculous.
@all_c1ear
@all_c1ear 3 жыл бұрын
msf5 1337
@kirofamin443
@kirofamin443 3 жыл бұрын
Hello, my fifa21 Account got a transfermarket ban. Could you remove it with nmap or could you show me how i could remove it. Greetings from Germany
@Daniel-so9rg
@Daniel-so9rg 3 жыл бұрын
6th
@4ag2
@4ag2 3 жыл бұрын
1st 😎😁
@rajith8973
@rajith8973 3 жыл бұрын
0th
@silamoolan5228
@silamoolan5228 3 жыл бұрын
2st
@JNET_Reloaded
@JNET_Reloaded 3 жыл бұрын
USE TAB FFS typing filenames in full is anoying asf, type some of it then hit tab!!!! easy!!!!
@jclongy7886
@jclongy7886 3 жыл бұрын
Doesn't always work in your shell. You can see that he tried that a few times and had to go back and type the full file name. I do agree with your sentiment though. You get used to the autocomplete.
TryHackMe! Looking Glass... with PWNCAT
59:28
John Hammond
Рет қаралды 66 М.
Bruteforcing MFA & Fail2ban Manipulation - TryHackMe! (Biteme)
44:38
顔面水槽がブサイク過ぎるwwwww
00:58
はじめしゃちょー(hajime)
Рет қаралды 22 МЛН
Which one will take more 😉
00:27
Polar
Рет қаралды 68 МЛН
Exploiting Tomcat with LFI & Container Privesc - "Tabby" HackTheBox
45:54
TryHackMe! Buffer Overflow & Penetration Testing
30:33
John Hammond
Рет қаралды 77 М.
TryHackMe! KENOBI - Linux Pentest: Samba Shares
34:11
John Hammond
Рет қаралды 91 М.
TryHackMe! Bypassing Upload Filters & DirtySock
53:38
John Hammond
Рет қаралды 67 М.
TryHackMe GAMING SERVER - LXD Privilege Escalation
34:50
John Hammond
Рет қаралды 162 М.
Scraping Dark Web Sites with Python
19:29
John Hammond
Рет қаралды 116 М.
Plundering AWS S3 Buckets - HackTheBox
1:04:04
John Hammond
Рет қаралды 73 М.
KING OF THE HILL - TryHackMe! Community Stream
1:19:29
John Hammond
Рет қаралды 60 М.
TryHackMe! Tartarus - Website Password Bruteforcing
31:59
John Hammond
Рет қаралды 94 М.
Finding WEIRD Devices on the Public Internet
27:48
John Hammond
Рет қаралды 157 М.
顔面水槽がブサイク過ぎるwwwww
00:58
はじめしゃちょー(hajime)
Рет қаралды 22 МЛН