TryHackMe! Skynet - Wildcard Injection

  Рет қаралды 109,587

John Hammond

John Hammond

3 жыл бұрын

Come play the GuidePoint Security CTF! go.guidepointsecurity.com/202...
For more content, subscribe on Twitch! / johnhammond010
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
PayPal: paypal.me/johnhammond010
E-mail: johnhammond010@gmail.com
Discord: johnhammond.org/discord
Twitter: / _johnhammond
GitHub: github.com/JohnHammond

Пікірлер: 251
@jonny-mp3
@jonny-mp3 3 жыл бұрын
That python bruteforcer is a lifesaver
@eXfilPr4tik
@eXfilPr4tik 3 жыл бұрын
True
@PreetisKitchenltr
@PreetisKitchenltr 3 жыл бұрын
Not Working For Me... Another Room By The Way...
@nullpwn
@nullpwn 3 жыл бұрын
john: makes a py script out of nothing in less than 2 minutes me on google: "how to declare a variable"
@eXfilPr4tik
@eXfilPr4tik 3 жыл бұрын
True XD
@praisong7475
@praisong7475 3 жыл бұрын
Learn python. It'll be worth it and fun to play with
@raihanrabbani386
@raihanrabbani386 3 жыл бұрын
yeah its straight tho!
@jozef187
@jozef187 3 жыл бұрын
😂😂
@LuisAlberto-si9hn
@LuisAlberto-si9hn 3 жыл бұрын
True that AHAHHAHA
@Mosern1977
@Mosern1977 3 жыл бұрын
As a developer - very interesting to see your approach to finding weaknesses. I can sort of see the fun in this kind of activity, the lure of the dark side :)
@Urzgag
@Urzgag 3 жыл бұрын
Nice vid John :) Btw : The "balls have zero to me" stuff was from an experiment, letting 2 AIs talk to each other with a set alphabet but no actual grammatical rules. After a while, they just came up with their own way of communicating :D
@stevenhernandez3243
@stevenhernandez3243 3 жыл бұрын
love the content and the way you explain everything so thoroughly! id also much rather see you walk through a script like that than if you didnt
@oaklyfoundation
@oaklyfoundation 3 жыл бұрын
This is why i like John more then ipsec, this is more learning then walkthrough
@takeiteasyeh
@takeiteasyeh 3 жыл бұрын
heretic, not confirming with ls after mkdir.
@osamaamarneh5762
@osamaamarneh5762 3 жыл бұрын
Lmfao
@_caracalla_
@_caracalla_ 3 жыл бұрын
thats true lol
@meercat1880
@meercat1880 Жыл бұрын
i have never had an original experience huh
@jeffthechef69
@jeffthechef69 11 ай бұрын
Nope
@karangadhave9002
@karangadhave9002 3 жыл бұрын
Learnt a lot through this live walkthrough, well narrated and explained. The best part is the way you put out your way of approaching the next possibility, that definitely helped me in knowing how to process my thoughts during a CTF
@Deathfreeze14
@Deathfreeze14 3 жыл бұрын
John, I must say please do more of these vids are awesome and the talking through your process is exceptional
@alexclarke6839
@alexclarke6839 3 жыл бұрын
Hey John, been loving how much detail you go into when doing these videos. Keep up the great content!
@AhmedMohamed-kn9sf
@AhmedMohamed-kn9sf 4 ай бұрын
I wanted it for 1 time and will be watching it for a few more times to note all the things taught here. Thank you so much for your efforts. I do respect you and your talent. 😇
@christianmanalaysay
@christianmanalaysay 2 жыл бұрын
wow... exploiting the tar wildcard to set the SUID bit on /bin/bash is so freaking smart and cool man, I was stunned by how amazing that was. I'm trying to better myself at pentesting and John, you are teaching me amazing things! Thank you so much!
@aspxDEFINED
@aspxDEFINED 3 жыл бұрын
This was incredible. Thanks for the content John!
@meeDamian
@meeDamian 2 жыл бұрын
This is probably the most educational video on the topic I've ever seen, and I've seen a lot. Amazing.
@durzua05
@durzua05 2 жыл бұрын
Holyyyy that curl to python requests and the bruter you wrote just blew my mind. Good stuff John I really love your videos.
@bryttontsai6068
@bryttontsai6068 3 жыл бұрын
Amazing videos with great explanations to beginners instead of just cruising through all the answers without explaining the reasoning behind anything.
@mattstorr
@mattstorr 3 жыл бұрын
Love this approach John. Its raw, honest and not contrived (i.e. doesnt come over as you've already completed it and are now just going back through the motions!). Its far more enjoyable to listen to your thought process this way, and you still seem to manage to keep things easy to understand. Nice work :-) Subbed.
@mattstorr
@mattstorr 3 жыл бұрын
And thanks for introducing me to Terminator. Its my new favourite 'tmux' alternative :-) Now to work out what distro you are using...... ;)
@salimzavedkarim230
@salimzavedkarim230 Жыл бұрын
Been loathing reading all those articles about wildcard injection.... Thanks for the video man :)
@Child0ne
@Child0ne 2 жыл бұрын
this video was awesome! i learned Sooooo much! thank you so much john, your the man brother!
@cooliceman0001
@cooliceman0001 3 жыл бұрын
Had a great time watch you work your magic. Im still learning and watching your videos really helps! Thanks john
@RycnGaming
@RycnGaming 3 жыл бұрын
Thank you very much for each video you upload. I am a cybersecurity student and always I get upset, I put one of your video and get motivated to keep on.. thank you 🙏
@compromyse
@compromyse 3 жыл бұрын
RIP all terminator references.
@mikee.
@mikee. 3 жыл бұрын
That tar exploit is INSANE, how have I *never* heard of "the * exploit"??
@allesnikt
@allesnikt Жыл бұрын
Just found your channel and subscribed. Awesome videos and explanations
@uniquechannelnames
@uniquechannelnames 2 жыл бұрын
Thanks for this I was having trouble with the tar wildcard portion!
@johnmcconnell4030
@johnmcconnell4030 2 жыл бұрын
You are amazing! Thanks for the walk through!
@shawn8163
@shawn8163 3 жыл бұрын
Great video like walk throughs to see your process.
@RedBlueLabs
@RedBlueLabs Жыл бұрын
I liked how you used curl to trigger the call back. I will start bringing that into my process
@jeprox718
@jeprox718 3 жыл бұрын
CTFs are so fascinating ..enjoyable content! keep it coming!
@hayaanrizvi
@hayaanrizvi 2 жыл бұрын
This was one of your best vids so far
@gngn2973
@gngn2973 3 жыл бұрын
dude, you rock! This was awesome. when I saw the bash-4.3# i was like 😁😁😁
@jonathangorelik7849
@jonathangorelik7849 4 ай бұрын
super creative privelage escalation john! amazing content please keep it coming!
@bmbiz
@bmbiz 2 жыл бұрын
Ah Skynet. One of the best loved THM rooms, I believe. Out of curiosity, I just looked at the conclusion in my own notes and it says "probably my favorite ctf to date." :)
@sandipanmandal3830
@sandipanmandal3830 3 жыл бұрын
Sir u really are a very humble person ❤️❤️
@shiralihusan9344
@shiralihusan9344 3 жыл бұрын
I was as excited as you are when you privilege escalated. This is simply amazing.
@TntTnt-oz7iv
@TntTnt-oz7iv 2 жыл бұрын
That was incredible thanks for your work
@bbowling619
@bbowling619 3 жыл бұрын
Omg. More content! My brain cant keep up. Its literally regurgitating info at this point but im plugged back in . Leggo peeps and thank you once again Mr John !
@jocularich
@jocularich 2 жыл бұрын
this video inspired me more...thanks John
@fangUwU
@fangUwU 3 жыл бұрын
you explain everything so simply ❤️ thanks bruhhh 😘😘
@sylvesterrac3792
@sylvesterrac3792 3 жыл бұрын
Thanks John, I always learn something new
@vojislavpavkovs9124
@vojislavpavkovs9124 Жыл бұрын
Awesome! You are online person out there who cares to explain stuff! Love Your videos!
@KevinMsyah
@KevinMsyah 3 жыл бұрын
Please keep making contents like this, we really enjoy watching your vids ,thankss
@tshidiflo2226
@tshidiflo2226 2 жыл бұрын
John please stop apologizing for doing exactly what we need (going into detail about how you as a pentester would approach this) Its exactly why I love this channel.. its not generic like the others. So please stop and carry on.
@SamerAlhasweh
@SamerAlhasweh Жыл бұрын
i enjoyed every single moment of this
@tobiasgerber3546
@tobiasgerber3546 3 жыл бұрын
Good work. Well done. Learned a lot!
@testingme7936
@testingme7936 2 жыл бұрын
i learned a lot from your videos thanks
@osamaamarneh5762
@osamaamarneh5762 3 жыл бұрын
Thank you for an amazing informative educational video ❤️
@randompicks1328
@randompicks1328 3 жыл бұрын
Buddy you are the best I ever seen so far 😍😍😍
@giuliano6535
@giuliano6535 3 жыл бұрын
Thanks for another fun and educational video boss!
@rrd_webmania
@rrd_webmania Жыл бұрын
This video is my favorite so far
@DanielPizarro184
@DanielPizarro184 3 жыл бұрын
so happy that ur channel exists
@martyn158
@martyn158 2 жыл бұрын
please always go off on tangents like the python one in this video, if anything..... go on to do a video about the tangent and go off into a tangent in that video and then do a video of that tangent and so on and so on, your videos quite literally pushed me in the direction of doing my (now a year in) degree in cybersecurity and the tryhack me rooms, you sir are a legend , thank you for your work
@playmaker1011
@playmaker1011 3 жыл бұрын
Simply a huge thanks ✊
@marco.garofalo
@marco.garofalo 3 жыл бұрын
This was so much fun!
@johannespain7855
@johannespain7855 3 жыл бұрын
really great live premiere and overall video!
@lixanderguzman3305
@lixanderguzman3305 3 жыл бұрын
I don’t know what is going on but this seems interesting haha
@brian3947
@brian3947 3 жыл бұрын
You should learn python it’s fun
@lasergamer2869
@lasergamer2869 3 жыл бұрын
@@brian3947 I’ve learnt python but this is not just python haha. It’s also bout networking and managing file stuff
@stefan.krause
@stefan.krause 2 жыл бұрын
Very nice, thanks for showcasing your way of solving this room. I tried it this morning before I looked at your video. Since I cannot code in python I had a similar script as bash script, but never made it working because I forgot sending the hidden fields .. I don't know if the room is an easy one, I was lost after finding the user.txt Still a lot to learn I guess :)
@anonymoushackeromega6376
@anonymoushackeromega6376 2 жыл бұрын
nothing better then this..john...explnation is wonderfull :)
@armandsriekstins7646
@armandsriekstins7646 3 жыл бұрын
It seems like I've found my new favourite channel
@iAshenBlade
@iAshenBlade 2 жыл бұрын
Can't tell how much I appreciate this was so confused at root privilege escalation lol
@leblanc666666
@leblanc666666 2 жыл бұрын
loved your bin bash suid. My lazy version is simply doing that to the /etc/passwd and login as root. Have all the info I need in a file that I just copy paste everytime! Nice and quick
@WafflesASAP
@WafflesASAP 2 жыл бұрын
*John:* "Oh, we have a personal SMB share named milesdyson, that seems random." *Me:* Wait... does John not realize who Miles Dyson was in the Terminator universe? *John (5 mins later):* "I actually haven't seen the Terminator movies." *Me:* ...aha, well that explains that.
@squeelyinc
@squeelyinc 3 жыл бұрын
Great content John, could tell you hadn’t watched the terminator movies once you seem to overlook the miles dyson reference. :-) What sort of hardware and software setup would you recommend for a beginner?
@user-ii2hp9tp1z
@user-ii2hp9tp1z 3 жыл бұрын
that wildcard priv-esc is just super nice
@Zachucks
@Zachucks 3 жыл бұрын
curl to python... :O how did i not know about this, where has this been my whole life!?
@salatwurzel-4388
@salatwurzel-4388 3 жыл бұрын
I was literally sitting here and saying "bro ... that would helped me so many times" xD
@spoonkrisp8776
@spoonkrisp8776 2 жыл бұрын
I can’t believe that I have seen a 1 hour video on KZfaq and want more
@gabrielex
@gabrielex 3 жыл бұрын
So clear, so good!
@master_of_bytes
@master_of_bytes 3 жыл бұрын
Nice video. Learned a lot from that.
@werskantti
@werskantti 3 жыл бұрын
When you got to that Miles Dyson Personal Page i was sure that the picture had steganography in it.. :D But where it continued were so much better
@demonview6075
@demonview6075 12 сағат бұрын
yo awesome vid, crystal clear thanks
@yusufbilalbatir5221
@yusufbilalbatir5221 3 жыл бұрын
Extremly funny, thank you.
@MrPOWER6000
@MrPOWER6000 3 жыл бұрын
I love it! thank you.
@dxnxz53
@dxnxz53 2 жыл бұрын
dude this is awesome!
@0xsudip892
@0xsudip892 3 жыл бұрын
Awesome as always
@John-hq9kx
@John-hq9kx 3 жыл бұрын
That was a very Interesting video, thank you for this amazing content ! 😁👍
@av9401
@av9401 2 жыл бұрын
Thank you!
@robertron5303
@robertron5303 3 жыл бұрын
Big ups! Great content 👍👍
@dannelson2590
@dannelson2590 3 жыл бұрын
Awesome video!
@bladesvlogs4965
@bladesvlogs4965 3 жыл бұрын
Sweet Video! Didn't understand 95%, but it looked cool :)
@Z0nd4
@Z0nd4 2 жыл бұрын
Thank you very much.
@AA-fy7kn
@AA-fy7kn 3 жыл бұрын
Hello John, could you do the Daily Bugle room on T.H.M.? I love the way you approach things and explain them.
@williamsys1504
@williamsys1504 3 жыл бұрын
Love the video!
@lioralalouf61
@lioralalouf61 Жыл бұрын
awsome work i love u so much
@holabola9064
@holabola9064 2 жыл бұрын
Awesome video
@assassino689
@assassino689 2 жыл бұрын
thanks man!
@mr.holmes4149
@mr.holmes4149 3 жыл бұрын
Awesome vid! 👌
@stefank2387
@stefank2387 2 жыл бұрын
Great content
@benfelts70
@benfelts70 3 жыл бұрын
So awesome!
@siddheshghag5889
@siddheshghag5889 3 жыл бұрын
Nice execution.
@NimbleSF
@NimbleSF Жыл бұрын
I'm not gonna lie, I was super annoyed once I realized how much work had to be put in at the end lol. I thought I was a rockstar until it got to the cuppa part. Then getting that stable shell and actually figuring out what to do? Infuriating. Thank you for your time an mentorship doing rooms like this for us. I wish this was something I could do on my own, but maybe THM is designed just for walkthroughs just like this so we can learn.
@adminservice9459
@adminservice9459 3 жыл бұрын
John Hammond for president everyone!
@Omar-gw8lt
@Omar-gw8lt 3 жыл бұрын
Awesome John Hammond but you let me down by not watching the terminator movie just kidding, if you do get the chance only watch 1 & 2 don't bother with the rest. lol
@nuridincersaygili
@nuridincersaygili Жыл бұрын
Excellent
@wanishoaib_
@wanishoaib_ 3 жыл бұрын
Love ur vids
@codermomo1792
@codermomo1792 4 ай бұрын
thank you very mush. this was helpfull
@yossig7316
@yossig7316 3 жыл бұрын
thank you, thank you, thank you!
@toolbgtools
@toolbgtools Жыл бұрын
that SUID trick was cool
@JustSomeAussie1
@JustSomeAussie1 3 жыл бұрын
On the part where you used python to check for logins i'm pretty sure you could use a session to make it a lot faster. s = requests.Session() s.post(url)
@zig0to
@zig0to 3 жыл бұрын
The problem seems to be SquirrelMail taking time to process requests, setting up a session won't help with it
@jonasbadstubner2905
@jonasbadstubner2905 3 жыл бұрын
LastPass better sponsor you now. Nice placement right there.
@lollo0296
@lollo0296 3 жыл бұрын
That was nice, John
@JavierPerez-me2se
@JavierPerez-me2se 3 жыл бұрын
You are great!
Bruteforcing MFA & Fail2ban Manipulation - TryHackMe! (Biteme)
44:38
TryHackMe! Bypassing Upload Filters & DirtySock
53:38
John Hammond
Рет қаралды 67 М.
Monster dropped gummy bear 👻🤣 #shorts
00:45
Yoeslan
Рет қаралды 12 МЛН
ОДИН ДОМА #shorts
00:34
Паша Осадчий
Рет қаралды 5 МЛН
ISSEI funny story😂😂😂Strange World | Pink with inoCat
00:36
ISSEI / いっせい
Рет қаралды 18 МЛН
The Flaws that Allow Hackers to Remotely Access Cars
22:18
VICE News
Рет қаралды 225 М.
TryHackMe! Looking Glass... with PWNCAT
59:28
John Hammond
Рет қаралды 66 М.
TryHackMe GAMING SERVER - LXD Privilege Escalation
34:50
John Hammond
Рет қаралды 162 М.
FREE STUFF? TryHackMe - "The Great Escape"
1:46:38
John Hammond
Рет қаралды 77 М.
Finding WEIRD Devices on the Public Internet
27:48
John Hammond
Рет қаралды 160 М.
Create Studio Ghibli Art in Cinema4D & Blender (with Peter France)
3:49:35
The Apex Legends Hacker: Destroyer2009
21:47
John Hammond
Рет қаралды 113 М.
ShellShock & Kernel Exploits - TryHackMe! 0day
35:10
John Hammond
Рет қаралды 79 М.
I Challenged 3 Hackers for 1 Hour in TryHackMe's King of the Hill.
8:30
Monster dropped gummy bear 👻🤣 #shorts
00:45
Yoeslan
Рет қаралды 12 МЛН