Тёмный

A Poor Man's Pentest: Automating the Manual - BsidesDE 2019 

John Hammond
Подписаться 1,7 млн
Просмотров 49 тыс.
50% 1

If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
E-mail: johnhammond010@gmail.com
PayPal: paypal.me/johnhammond010
GitHub: github.com/JohnHammond
Site: www.johnhammond.org
Twitter: / _johnhammond

Опубликовано:

 

9 ноя 2019

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 77   
@_JohnHammond
@_JohnHammond 4 года назад
View the original on BsidesDE's channel, and check out their other talks! ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-w5qNbmqBBbY.html
@sickthotsonmymind2299
@sickthotsonmymind2299 4 года назад
Whew, working your way up brother. You're a proper example for all the youngsters
@_JohnHammond
@_JohnHammond 4 года назад
@@sickthotsonmymind2299 Thanks so much! Doing the best I can!
@jobsphil9553
@jobsphil9553 4 года назад
I joined discord channel. but I can not load messages . help me
@_JohnHammond
@_JohnHammond 4 года назад
@@jobsphil9553 Have you done the verification CAPTCHA that the bot sent you in a DM?
@kumarniloy3893
@kumarniloy3893 3 года назад
Probably the first time John remembered his IP
@gtdt5666
@gtdt5666 3 года назад
:'D
@aidancollins1591
@aidancollins1591 4 года назад
That was a hard crowd lol
@deity6119
@deity6119 2 года назад
when you compare his talk to some of the actually talented talkers at defcon he just sounds stupid lol
@aidancollins1591
@aidancollins1591 2 года назад
@@deity6119 Defcon? My impression is that Defcon has turned into a huge advertising convention with the talks centered around showcasing hacking products. It's hard to find a good talk post-2015. You're better off checking out smaller conventions. This talk isn't groundbreaking or anything, it's not unveiling new research or a vulnerability, but it's perfectly fine for what it is. Showcasing what you're able to do with limited funds.
@deity6119
@deity6119 2 года назад
@@aidancollins1591 Old defcon was way better for sure. But I dunno I just don't think he's a very engaging speaker
@DT-hb3zu
@DT-hb3zu 3 года назад
I FOUND IT! Do you know how frustrating it is to search "John Hammon presentation", and get nothing but Jurassic Park clips?!
@sechvnnull1524
@sechvnnull1524 4 года назад
Can't thank you enough for these videos and the walk throughs you do. It literally is inspiring and motivating and gives me goals to shoot for! I started out really late in life and am working towards a degree but you really can't put a price on the content you continue to share. Its awesome stuff!!
@_JohnHammond
@_JohnHammond 4 года назад
Very happy to hear that, appreciate all the kind words! Thank you so much and thanks for watching!
@barakcobrama1703
@barakcobrama1703 2 года назад
i use kali linux is ubunto better?? does anyone know???
@mustafaismail5773
@mustafaismail5773 4 года назад
That was amazing ideas, you gave me a lot of information and Techniques to continue on this path
@sirw369
@sirw369 4 года назад
Just watching this now, but super informative and useful if you’re into pen-testing. As always John, great presentation. Hope to catch you at your next one!
@TheViranga
@TheViranga 4 года назад
Great stuff. Very helpful and informative. Thanks!
@_JohnHammond
@_JohnHammond 4 года назад
Thank you for watching!
@xfaraday2433
@xfaraday2433 4 года назад
Ayyy my boy John rising up and doing talks now! Nice
@ankitkumarjat9886
@ankitkumarjat9886 4 года назад
It's a very good automation resource.Thanks john
@123ezekiel456
@123ezekiel456 4 года назад
John, very cool talk. Enjoyed it so much!
@_JohnHammond
@_JohnHammond 4 года назад
Thank you! It was a lot of fun to do. On to the next one!
@minibit0103
@minibit0103 4 года назад
Totally could see you becoming a professor. Very cool presentation 👏
@picious
@picious 4 года назад
Once more, thank you !
@simonb8988
@simonb8988 2 года назад
Great video!
@bigtymer4862
@bigtymer4862 4 года назад
Great talk John! Brilliant!
@_JohnHammond
@_JohnHammond 4 года назад
It's a cheesy thing, but thank you so much!
@thecaretaker0007
@thecaretaker0007 3 года назад
Such a great video, now i wanna make this on my own!
@runnerc
@runnerc 3 года назад
Great job man! Very helpfull!
@RohanOnBike
@RohanOnBike 4 года назад
Cool stuff as always🤘
@_JohnHammond
@_JohnHammond 4 года назад
Thank you for watching!
@Waarzown
@Waarzown 2 года назад
Usually I designate a specific terminal for callbacks. If you use something similar, you can set "stty raw -echo" in that window ahead of time, and not need to background the callback in order to set it.
@rodriquh
@rodriquh 4 года назад
Great talk John! They definitely needed a mic for the crowd for their questions. You’re a top notch instructor, you can tell by the way you throw in questions to keep engagement up. It seems like these guys either weren’t tracking or the concepts were way over their heads. I love the thought you put into this, but don’t you worry about creating script kiddies? Just curious. Again, great talk John, I love following your channel and seeing all the good stuff you put out there to allow people to hack their brains and change the way people look at things. Thanks for all you do brother!
@_JohnHammond
@_JohnHammond 4 года назад
Hey Henry, thanks for all the kind words! Haha, it has been a few months since I have on podium instructing, but it's fun, I miss it a bit :) I am not too concerned with script kiddies -- they'll do their thing, but they won't improve :P Thanks so much, and thanks for watching!
@anujkumarpatel2686
@anujkumarpatel2686 4 года назад
you have inspire me alot
@glennbloemhof3194
@glennbloemhof3194 4 года назад
@John Hammond do you have any idea how to make the stabilize_shell.sh work inside reverse shell using something like tmux? Nice Video btw! love your content!
@brandanderstine677
@brandanderstine677 4 года назад
Great job dude
@_JohnHammond
@_JohnHammond 4 года назад
Thank you so much!
@mrjamesprince
@mrjamesprince 4 года назад
wow, how did i miss this
@Joshua1_7sc
@Joshua1_7sc 4 года назад
That was awesome
@puppe1977
@puppe1977 4 года назад
48:34 shouldn't the keyup/keydown for Tab be in the reverse order? Great talk! It's in the correct order in your git repo (in functions.sh) so maybe just update your slides.
@DDBAA24
@DDBAA24 4 года назад
This was a revealing video. Only been watching you a few months , you know you love your "cheezy" 🧀RU-vid channel lol. Respect though, had a feeling you had military background .
@koloxd3
@koloxd3 3 года назад
Love IT
@NickBouwhuis
@NickBouwhuis 4 года назад
Great talk! Love it! Too bad they added a rather aggressive noise gate.
@_JohnHammond
@_JohnHammond 4 года назад
Thanks so much! Yeah it's a little spotty when I am speaking versus not speaking, ah well. Thanks for watching!
@lordtony8276
@lordtony8276 3 года назад
Any idea how to stabilize a shell when you are attacking from a windows machine? Powershell and CMD don't like it when you CTRL + Z. It makes the system lock up or something. Even when I use a kali linux docker instance, I am still running through Powershell so I can't seem to background the revshell.
@S1lenc31991
@S1lenc31991 3 года назад
As an addition to your "missing characters" problem - you could iterate over an string doing a very short delay after each keystroke to make sure you get all chars right :)
@S1lenc31991
@S1lenc31991 3 года назад
Oh, and maybe look up DBUS messages, Guake is scriptable by that
@Dontfkwithme69
@Dontfkwithme69 4 года назад
I hope one day i get a chance to attend your workshop :(
@ajaykumark107
@ajaykumark107 4 года назад
what is the use of xterm command ? Why do we use it here in the context?
@arinugraha635
@arinugraha635 2 года назад
when i enter stty raw -echo my terminal like freeze cann't response. what's wrong ?
@damienkali
@damienkali 4 года назад
great demo, would be good if you shared your final functions.sh somewhere ;) - was a tough crowd to work with, only feedback I can suggest, is have someone with a spare mic to pass to people when asking questions, (or if you can repeat their question back so we can hear what is going on)
@_JohnHammond
@_JohnHammond 4 года назад
Thanks so much! Is the final function.sh not in the GitHub repo? I can see it there. I should definitely get in the habit of repeating questions. Thanks for all the kind words and thanks for watching!
@damienkali
@damienkali 4 года назад
@@_JohnHammond Pleasure to give feedback, I found your channel 2 days ago & literally going through each video now non stop. I completed (with your help) all on overthewire, have you started Krypton yet? if not, I would love to see your way of doing the challenges. I forgot to check the github repo & my bad I didnt even know you had a link, can you post it here? tks (feel free to check out some of my videos) :)
@_JohnHammond
@_JohnHammond 4 года назад
@@damienkali Oh that is excellent, thank you! I have gone through a bit of Krypton, but you are right that I have not shared any videos on it! I will add it my list for sure and can hopefully get that out within the month. Github repo is here: github.com/JohnHammond/poor-mans-pentest And I took a look at your channel -- subscribed! :D
@highvisibilityraincoat
@highvisibilityraincoat 3 года назад
Miffed I wasn’t into security when this happened bc i’m like 30 minutes away.
@nabinsademba
@nabinsademba 4 года назад
is ctf challenge over?
@_JohnHammond
@_JohnHammond 4 года назад
Yes, sorry -- I am hoping to bring the event to more conferences, so I am waiting until the next one to bring it back up again.
@jeszczewiecejmichala
@jeszczewiecejmichala 4 года назад
You record it with a terrible hair dryer (calculator;)) Super presentation - From Poland
@nabinsademba
@nabinsademba 4 года назад
why cant i join the discord?
@_JohnHammond
@_JohnHammond 4 года назад
What is preventing you?
@p4nz9r60
@p4nz9r60 4 года назад
Hi, have you thought about using the tmux instead of xte/terminator/guake?
@_JohnHammond
@_JohnHammond 4 года назад
I have, yes, I used tmux for some time-- especially when I was tinkering with Arch. Admittedly I have gone back to Ubuntu -- too many idiosyncrasies added up haha.
@tsurumaruwordpress
@tsurumaruwordpress 4 года назад
I was wondering if this would be possible, substituting tmux for guake. Should be, right?
@p4nz9r60
@p4nz9r60 4 года назад
@@tsurumaruwordpress 'tmux send-keys -t paneID -l some text \; send-keys -t paneID Enter' will send 'some text ' to the pane 'paneID', so you probably won't need xte at all, plus it could be used on macOS as well.
@dnperfors
@dnperfors 4 года назад
P4nz9R mostly that should work, except for the script to start the reverse shell where you want to switch to your browser... but yeah, it would be worth a try :)
@_JohnHammond
@_JohnHammond 4 года назад
@@tsurumaruwordpress I think that's a fine idea. Admittedly, with the "Alt Tab" functionality, we really don't even need Guake. We can automate shifting the focus as needed. Tmux might need some other key strokes to close a current pane, or switch a new one -- however you would like to implement it.
@bhagyalakshmi1053
@bhagyalakshmi1053 Год назад
Chg pt explain
@bhagyalakshmi1053
@bhagyalakshmi1053 Год назад
Kail linux ram
@pauloelienay1662
@pauloelienay1662 4 года назад
Why use Ubuntu (who sells your data) if you can use Debian (if you like stability and the Ubuntu package manager), Fedora (what I used for a long time, really good IMO) or Arch (rolling release, full control over your machine etc)
@thegripmaster666
@thegripmaster666 4 года назад
Do give us some reference for your claim that Ubuntu sells your data.
@ctrlcapsswap966
@ctrlcapsswap966 3 года назад
someone show this man at least i3
Далее
Hacking Windows TrustedInstaller (GOD MODE)
31:07
Просмотров 309 тыс.
Копия iPhone с WildBerries
01:00
Просмотров 2,4 млн
OSCP - Taking Notes & Resources
14:45
Просмотров 97 тыс.
Exploring the Latest Dark Web Onion Sites
13:15
Просмотров 656 тыс.
Are CTFs even real? Featuring John Hammond.
25:16
Просмотров 71 тыс.
TryHackMe! Looking Glass... with PWNCAT
59:28
Просмотров 67 тыс.
He Sent Me Minecraft Malware (Java Deobfuscation)
28:40
How Bugatti's New Electric Motor Bends Physics
9:25
Просмотров 71 тыс.
Bad Robots - Driving Test Theory (Episode 1)
2:01
Просмотров 123 тыс.
TryHackMe! Abusing SETUID Binaries - Vulnversity
29:35
Просмотров 142 тыс.