Тёмный

HTB Cyber Apocalypse - cURL As a Service 

John Hammond
Подписаться 1,9 млн
Просмотров 38 тыс.
50% 1

Moving your first steps into hacking? Start from HTB Academy: bit.ly/3vuWp08
Hungry for more hacking training? Join Hack The Box now: bit.ly/331nQCl
For more content, subscribe on Twitch! / johnhammond010
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
PayPal: paypal.me/john...
E-mail: johnhammond010@gmail.com
Discord: johnhammond.or...
Twitter: / _johnhammond
GitHub: github.com/Joh...

Опубликовано:

 

1 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 103   
@NateRoberts
@NateRoberts 3 года назад
You say “you talked too much” but for a beginner your deep dives/verbosity definitely help someone like me. So it’s greatly appreciated, thanks so much for the content.
@jwoo13
@jwoo13 3 года назад
I really appreciate you "thinking out loud" as to what you're doing at each step; it helps a lot of us learn as that fits our learning style.
@vanshajdhar9223
@vanshajdhar9223 3 года назад
Yes I agree
@mjtonyfire
@mjtonyfire 3 года назад
John, man... Do NOT stop being verbose. Your train of thought whilst solving a problem is INVALUABLE. I don't think there's another youtuber out there that gives us this fine grain critical thinking regards hacking/CTF/stuff. I'll watch one of your vids from start to finish the first time, then I'll be going slower through the next play through, taking notes, following along... This is the best way to learn. Keep going. You've just earned another patreon. Thanks man.
@Zygorg
@Zygorg 3 года назад
Yes
@lepsycho3691
@lepsycho3691 3 года назад
I really like to hear your thought process, it gives me a lot of insights on how to approach a challenge like this!
@YeffRamos
@YeffRamos 3 года назад
love how descriptive and verbose these are actually... even if we use curl every day it's nice to see somebody go in-depth with it.
@theITGuy-no3nt
@theITGuy-no3nt 3 года назад
@johnhammond Sorry for the second comment, but this is like the 10th time I have heard you apologize for being verbose in explanation, video length, or for "fumbling" through a challenge. I can not state strongly enough that those things are *precisely* why I watch your videos, and I feel that I am not alone. I do not give a fetid pair of dingo's kidneys about the a-b-c steps of solving any particular challenge; it is the thought process that leads to the solution that interests me. I enjoy watching you beat your head against walls, as would anyone who ever pounded a keyboard in fury whilst screaming "What the *actual* $%@# ?" Keep it up. What you are doing works.
@hayaanrizvi
@hayaanrizvi 3 года назад
Exactly, couldn't have said it better myself
@theITGuy-no3nt
@theITGuy-no3nt 3 года назад
@@hayaanrizvi Thanks
@tsustyle6263
@tsustyle6263 3 года назад
I've said this before and I'm going to say it again. I learn more in 30 minutes watching John's videos than I do in 3 hours with any other teaching medium. Incredible job as always. Thank you.
@_CryptoCat
@_CryptoCat 3 года назад
thats cool you got the -T flag to work! i was playing around with it for a while before eventually solving with file:/// 😀
@telnobynoyator_6183
@telnobynoyator_6183 3 года назад
I though of the same thing ! So file IS a solution...
@theITGuy-no3nt
@theITGuy-no3nt 3 года назад
I think most of us watch for the verbosity, John.
@mossdem
@mossdem 3 года назад
We know you wanna just release it now John…
@rajeshvayalar965
@rajeshvayalar965 3 года назад
മലയാളി ഇല്ല
@holigan5392
@holigan5392 3 года назад
Make a tutorial for black box pen testing
@GodModeMaker
@GodModeMaker 3 года назад
I love Verbosity. Don't stop being Verbose. Ever. sudo johnhammond -vvvv
@peterchari3839
@peterchari3839 3 года назад
Great walk through video. Clear explanation. Its very easy to follow.
@dobermanelliot8129
@dobermanelliot8129 3 года назад
keep great job John, dont stop beeing verbose, we love it! if u just come and write "okay its ease lets file:///flag" we would not watch it! cya ;)
@jeffersonding5898
@jeffersonding5898 3 года назад
A great resource to use instead of reading through thousands of lines of manuals is GTFOBins. Has may important exploits and examples implemented already
@THRE3KINGZStudios3kz
@THRE3KINGZStudios3kz 3 года назад
Ayo I seen you on a recommended vid by Joshua Fluke discussing Cyber Sec and I started off just like you mane I was into making video games and I started in unity and UE5, got my degree in CIS, and lately I’ve been sharpening my technical skills. I want to get the Cyber MOS in the Army and AF and since I recently graduated, like this week, I been putting together my resume and trying to soak in as much info as possible bc We really want this job you know! Well anyways it’s nice to find someone with some things in common and your vids are very informative!
@danielma2824
@danielma2824 3 года назад
hello i have a problem in hack the box (challenge/ hardware) can you help me ??the file open .sal (the challengs Debugging Interface) can you me a tip
@telnobynoyator_6183
@telnobynoyator_6183 3 года назад
I immediately though of (and saw) the FILE protocol I wonder if that's going to be the answer
@jaopredoramires
@jaopredoramires 3 года назад
is this your `classic` ubuntu box? always wanted to know which version it is also, took me ages to figure out you were on XFCE
@AustinReed1
@AustinReed1 Год назад
John I had to hop on here and leave a comment, you are great man keep up the good work, I just saw one of the CTF's you were in and it was obvious they were being assholes, muting you on purpose, being snide then dismissing you at the end was shitty and inexcusable. Good for you for taking the high road and being tactful during the whole event and never uttering a negative word about that guy. Keep up the awesome work, the world needs more people like you!
@Ca1vema
@Ca1vema 3 года назад
Can you actually put a video description in a description box? Not only ads? It’s there for a reason.
@annankazi6628
@annankazi6628 3 года назад
HEY SIR HOPE YOU'LL REPLY SIR HOW CAN I KNOW THAT SOMEONE HAS HACKED MY ANDROID?? PLZ REPLY ME SIR!!
@killerskincanoe
@killerskincanoe 3 года назад
Will there be a secret plz subscribe command? It's the main reason why I watch.
@THRE3KINGZStudios3kz
@THRE3KINGZStudios3kz 3 года назад
My twin and I are both in the military but not branched or have MOS yet and we were told we shouldn’t get our certs before going in just wait... I kinda wished I already gotten them trying to get at least our Sec+ first 😂😂😂
@devil874
@devil874 3 года назад
oh thats nice i used: -o argument to uplaod a .php file that printed the flag its great i kinda allways learn something watching you
@_d47_
@_d47_ 3 года назад
Thanks bro, i really like watch your videos
@Devinatron
@Devinatron 3 года назад
I feel dumb now seeing how simple it was. I got too far in the weeds during the event on this one, but I really appreciate the thinking out-loud! I'll get better at these, thanks for the awesome vid!
@savoyblue777
@savoyblue777 3 года назад
If you don't mind John What terminal do use on your system? And thank you for all you do to help us all
@bhagyalakshmi1053
@bhagyalakshmi1053 Год назад
Work full this one to track is a nice easy to work my headel jobs
@xBrownnyx
@xBrownnyx 3 года назад
It is worthwhile, thanks. Great video!
@laurenzkaml3864
@laurenzkaml3864 3 года назад
I had a better solution. You can write a trace file of the request and then just access it like /trace.
@prabingurung4844
@prabingurung4844 3 года назад
hey John, what's going on ( ̄_, ̄ )
@nicolaspanu7448
@nicolaspanu7448 2 месяца назад
Thank you, excellent explanation!
@JimmyGeschwind
@JimmyGeschwind 3 года назад
I like that you go through and show the whole process and not just jump on the solution. I feel that I learn more from that approach. Keep it up!
@alpacasecurity9915
@alpacasecurity9915 3 года назад
LOL I uploaded a webshell and then found the flag
@nothingreallymatters7530
@nothingreallymatters7530 3 года назад
it's super worth it just beginner like me.
@JoPraveen
@JoPraveen 3 года назад
👏✨
@bbott-britishbroadcastingo535
@bbott-britishbroadcastingo535 3 года назад
I really think he should‘ve done „curl file:///flag“
@_JohnHammond
@_JohnHammond 3 года назад
I showcase that at the end of the video and explain that that is the best solution?
@gauravbisht9622
@gauravbisht9622 3 года назад
ethical hacker ed sheeran lite 😂😂
@shauncollins1280
@shauncollins1280 3 года назад
Love you man... Thank you so much 🙏
@ilyesdhiaeddine6610
@ilyesdhiaeddine6610 3 года назад
yes please keep this format
@karthika3357
@karthika3357 3 года назад
What song play in outro?
@ayush_panwar1
@ayush_panwar1 3 года назад
Another awesome video 👏👏 But we r hungry we need more ctfs and there are new KOTH machines out there we want a new KOTH VIDEO ALSO!!! WANT TO SEE PEOPLE Lynched by you 😆😅
@petehinch3871
@petehinch3871 3 года назад
Love your Videos John
@FaZeInvite17
@FaZeInvite17 3 года назад
just for the yt algo :))
@andydietz7434
@andydietz7434 3 года назад
Love the explanation and please don't think you are being "Long Winded". I agree with the others, that this is great explanations for beginners or just to understand what you are thinking!! Please keep it up and yes, we want more CTF writeup videos. Also what is the song that is in the end of the video, it is stuck in my head and I want to go find it so I can listen to it while work on my hacker skilz!!
@joelpainchaud4887
@joelpainchaud4887 3 года назад
Algorithm token
@alexandrohdez3982
@alexandrohdez3982 Год назад
👏👏👏👏👏
@akay9030
@akay9030 3 года назад
Always wait for your videos...awesome work ..keep it up,plz upload ctf more often
@amine250
@amine250 3 года назад
That was a nice challenge
@ez-it-solutions9128
@ez-it-solutions9128 3 года назад
It's very difficult to hit every audience and talent level but these are the kind of video's worth paying for! A shorter, summed up version that skips specific steps or lacks the long-winded explanations is what most video's provide - but you provide the most thorough and absolute content! Keep it coming - What you call long-form or verbose is what makes it easy for everyone to follow.
@ajaymandal2560
@ajaymandal2560 3 года назад
Worth while ❤️👌
@steps0x029a
@steps0x029a 3 года назад
Love the talking-to-yourself and thinking-out-load approach, it really helps with understanding the process!
@DHIRAL2908
@DHIRAL2908 3 года назад
Haha just when I saw the curl prompt, the first thing I would try will be file:///
@kylejessup5740
@kylejessup5740 3 года назад
Happy to see some Cyber Apocalypse videos, I'm a beginner at this stuff and only found a few flags in this CTF. I will definitely watch more.
@kraemrz
@kraemrz 3 года назад
For yt algorithm
@eklypzn
@eklypzn 3 года назад
Solid video. I was like yelling at the screen early about the methods. I definitely had a few questions about source code answered for me and I'll probably end up referring to this video again.
@nouriyacine8823
@nouriyacine8823 3 года назад
I loved CTF games because of you dear . Can't stop learning more abd more all thee day. Thanks so much for everything you share with us.
@tanrrivtko1249
@tanrrivtko1249 3 года назад
My head hurts.
@b0b2600
@b0b2600 3 года назад
Verbose is good. - v
@yoshi5113
@yoshi5113 3 года назад
I love how the way you explain the tricks, thanks a lot John, Love from Indonesia.
@Minecodes
@Minecodes 3 года назад
Well, this is a nice challange, bu i missed it too XDD
@logiciananimal
@logiciananimal 3 года назад
I think it is interesting to name a CTF game an "apocalypse", as that literally means something like an unveiling or uncovering.
@hjorturpalmipalsson4521
@hjorturpalmipalsson4521 3 года назад
Always fun to see different take on those challenges. I used the -o flag in curl, it allows us to output the content of the curl into a file. With that in mind, I just curled a webshell file and outputted it into the static js folder and then executed it via the browser.
@tylerlwsmith
@tylerlwsmith 3 года назад
I love the deep dives. I'm a web application developer and have been watching your channel to get a better grasp on security, and by the end of each video my face is basically surprised_pikachu.gif
@nikkittb
@nikkittb 3 года назад
I really like how you took the time to explain all the steps you took here John! Even explaining the little things, like what ngrok does and how you spin it up! Loving the content man!
@adnentrimech7958
@adnentrimech7958 3 года назад
THANKS
@ThushyCyber
@ThushyCyber Год назад
Great
@bhagyalakshmi1053
@bhagyalakshmi1053 Год назад
Nice 👍
@avasonds
@avasonds 3 года назад
yo John your a beast I've been watching your videos, so when is the nsa hiring you?
@learn_offsec
@learn_offsec 3 года назад
Can you please do videos for Cyber Security Germany challenge
@sumedh1678
@sumedh1678 3 года назад
Doggo CTF Walkthrough, Please?
@LinuxSploitOfficial
@LinuxSploitOfficial 3 года назад
Amazing Thumbnail ♥️
@saidjuma1433
@saidjuma1433 3 года назад
I always learn something new when i see a upload from you. Keep up the good work my mans
@asmedeus448
@asmedeus448 3 года назад
I learn something today. Thank you.
@jimpowers4463
@jimpowers4463 3 года назад
Great video, so awesome that HTB spun up the game for you to make these videos for us.
@rebootlinux608
@rebootlinux608 3 года назад
I have a question do you use ubuntu on your hardware or as a virtual machine?
@BRYDN_NATHAN
@BRYDN_NATHAN 3 года назад
Thank you. RU-vid
@cocosloan3748
@cocosloan3748 3 года назад
You are fucking amazing John !
@mrbeancanman
@mrbeancanman 3 года назад
its definitely worth while! more of this please :D
@krishanuchhabra
@krishanuchhabra 3 года назад
Long form and verbose is the way to do this.
@dedkeny
@dedkeny 3 года назад
Almighty Algo STUFF!!!!!!!!!
@tamilxctf4075
@tamilxctf4075 3 года назад
Human doing ctf 🤔..
@methuso
@methuso 3 года назад
yes. long and verbose... please :)
@TheDyscontinuum
@TheDyscontinuum 3 года назад
Much appreciated good sir
@vellankiindeevar5530
@vellankiindeevar5530 3 года назад
Man your vids are so engaging
@joehollon317
@joehollon317 3 года назад
Great vid
@talinross
@talinross 3 года назад
Best video ever !
@debtlesspig7685
@debtlesspig7685 3 года назад
78mins tick tok
@wilcosec
@wilcosec 3 года назад
This was a fun one! Thanks John!
@morsi7842
@morsi7842 3 года назад
Big fan from Egypt, I really appreciate your work. Thank you for sharing such knowledge
@worldaroundyou593
@worldaroundyou593 3 года назад
💻💣🛸
@viv_2489
@viv_2489 3 года назад
Waiting for this
@himanishmandal9556
@himanishmandal9556 3 года назад
Sir, we do know you want to start right away. Why wait after all the channel does belong to you, does it not? Kindest of Regards, Himanish Mandal one of your fans. P. S - Don't find mistakes in my statement I am from India.
Далее
Дикий Бармалей разозлил всех!
01:00
IFrame Parent XSS - HackTheBox Cyber Apocalypse CTF
32:03
HackTheBox - "Remote" - Umbraco & Windows
48:23
Просмотров 82 тыс.
Finding WEIRD Devices on the Public Internet
27:48
Просмотров 290 тыс.
Gitlab LFI to RCE - HackTheBox "Laboratory"
1:13:44
Просмотров 117 тыс.
HackTheBox - Late
26:05
Просмотров 22 тыс.
Дикий Бармалей разозлил всех!
01:00