Тёмный

I AUTOMATED a Penetration Test!? 

John Hammond
Подписаться 1,7 млн
Просмотров 70 тыс.
50% 1

jh.live/pentest-tools || For a limited time, you can use my code HAMMOND10 to get 10% off any ‪@PentestToolscom‬ plan!
Apply the code on the checkout page: jh.live/pentest-tools
Free Cybersecurity Education and Ethical Hacking with John Hammond
📧 JOIN MY NEWSLETTER ➡ jh.live/email
🙏 SUPPORT THE CHANNEL ➡ jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
🌎 FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
💥 SEND ME MALWARE ➡ jh.live/malware
🔥 RU-vid ALGORITHM ➡ Like, Comment, & Subscribe!

Опубликовано:

 

14 фев 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 86   
@bawalicoder1233
@bawalicoder1233 5 месяцев назад
I really miss those days when John used to show CTF walkthroughs. I never felt bored for even those long videos where he was banging his head, but sadly those days are over 😢
@_JohnHammond
@_JohnHammond 5 месяцев назад
What CTF would you like me to showcase?
@NahImPro
@NahImPro 5 месяцев назад
@@_JohnHammondyou know what’s funny is that your legit username looks to be fabricated at first glance lol. I had to go to the main channel to verify. You don’t need to do any CTF walkthroughs, but honestly I’d take a fair bet that it doesn’t matter what CTF/HTB/THM walkthrough you do, people will watch as your personality is just great and you “take us with you” seemingly with ease. We want to dive into those rabbit holes with you. I’ve seen it a lot on comments on your videos. These videos are excellent as well though for advertising a product you can stand behind (and get paid) so I get that.
@bawalicoder1233
@bawalicoder1233 5 месяцев назад
@@_JohnHammond thanks for replying John. I will be really pleased if you can showcase the hackthebox cyber apocalypse CTF 2024 🤩
@mak1674
@mak1674 5 месяцев назад
Seconding this, I do appreciate these advertising videos every now and then as we can easily see the product in use but I do miss the old >12mins vids of you running through challenges or situations and being brought through your troubleshooting process together
@jjann54321
@jjann54321 5 месяцев назад
@@_JohnHammond First I appreciate ALL of your videos and your success is long overdue. An idea for a video could be something like using an online XSS tool to find a website (that you own) vulnerability and then possibly showcase a super fundamental exploit technique using something open source like OWASP ZAP or Burp Suite. Maybe turn it into a TryHackMe! plug? I believe you did an "intro" to Burp Suite years ago, a follow up or "next steps" video could do well. Thank you again for all that you give the community.
@zack49
@zack49 5 месяцев назад
this is an ad with an ad in the ad
@lfcbpro
@lfcbpro 4 месяца назад
Ad-ception 😛 It's ads all the way down...........
@edrickreyes-melendez4215
@edrickreyes-melendez4215 5 месяцев назад
I felt betrayed at 6:36
@user-in2jf7tx1q
@user-in2jf7tx1q 5 месяцев назад
😂😂
@nonaligned293
@nonaligned293 5 месяцев назад
Some of the people are way too spoiled in comments. As a web dev I find this very informative as it's 1. quick overview of pentesting a flask app 2. showing how redundancy in testing can be automated with sponsored tool that has FREE TIER, that you DON'T HAVE TO use btw, but you will learn how these kinds of tools in general work and if you wanna be serious in this business you're gonna have to use them eventually for efficiency. I don't mind this "going straight to it" approach, but if John considers any changes, on longer videos especially, those quick previews at the beginning that list things that will be covered in the video are always cool (I think). For example if I started this video 2 min in and something have come up, I might just turn it off and forget to get back to it, whereas if I know what the structure will be and I find it interesting and potentially useful, I will bookmark it or send it to myself. And in that short overview, Jonh can mention ad so spoiled brats stop crying in comments.
@user-in2jf7tx1q
@user-in2jf7tx1q 5 месяцев назад
bro we love this type of stuff, it keeps you up to date with very small effort
@veltgaist
@veltgaist Месяц назад
If you like to give all your data for free, sure
@kuczaq69
@kuczaq69 5 месяцев назад
I think you need some better guidelines on disclosing sponsored content... This was quite disappointing.
@_JohnHammond
@_JohnHammond 5 месяцев назад
This video shows a "Includes paid promotion" banner in the top-left every time you view it. What guidelines would you like?
@jesperwall839
@jesperwall839 5 месяцев назад
Yeah, that makes me expect a short ad for NordVPN or something. Not that the whole video is an ad… This is clickbait in its worst form…
@uncommoncharlie7
@uncommoncharlie7 5 месяцев назад
@@_JohnHammondI’m watching in mobile and that banner doesn’t get shown. My recommendation is just to make a clear title of what the video actually represents. You might not have as many views without clickbaiting but I don’t think the juice is worth the squeeze for how it comes off to people who enjoyed your videos
@kuczaq69
@kuczaq69 5 месяцев назад
@@_JohnHammond sir, I have a 42 inch screen and I sit 30cm from it. I don't see things in top-left, nor do I pay attention to them honestly. A verbal disclaimer would be very much appreciated, maybe big red banner like other channels do. When I watch your videos I treat them somewhat as university lectures, so I try to concentrate and listen, and when I found in the middle that I am in fact watching an ad, I felt led astray.
@NDDp9615
@NDDp9615 5 месяцев назад
​@@kuczaq69🤡
@Brateee1001
@Brateee1001 5 месяцев назад
Cool stuff dude!
@avihayl7911
@avihayl7911 5 месяцев назад
Why give John such a hard time for showcasing a pretty cool practical tool that will help you as professionals to shine at interviews and on the job? Free and open source is fine but sometimes having a real product at your fingertips can raeally make a difference! Also, he actually showed you at first a really long how to guide to do it yourselves. Dont be cheap and invest in yourselves instead of crying about "ads"...
@capability-snob
@capability-snob 5 месяцев назад
I have to know the justification for the deliberate eval 💀 also: werkzeug sites running in dev mode used to have a built-in shell on error, not sure if that still works
@unexplicitist-oy3eh
@unexplicitist-oy3eh 5 месяцев назад
Nice commercial buddy
@unexplicitist-oy3eh
@unexplicitist-oy3eh 5 месяцев назад
@@user-qd4xs8zb8s I love you
@ThisPageIntentionallyLeftBlank
@ThisPageIntentionallyLeftBlank 5 месяцев назад
😂
@LaxmanTamang-sx3ey
@LaxmanTamang-sx3ey 4 месяца назад
1:12 😅😂❤r😢😮😅
@Logan-vw8bg
@Logan-vw8bg 5 месяцев назад
Correct me if I'm wrong... Doesn't Legion do most of this already?
@RohanSharma-di3co
@RohanSharma-di3co 5 месяцев назад
Amazing stuff
@ibwthunder7059
@ibwthunder7059 5 месяцев назад
funny how my graduation project prof just agreed to a web pentest tool idea, and i am really worried on how i would do it
@PentestToolscom
@PentestToolscom 4 месяца назад
Best of luck with the project! 🤘
@jimmynoo
@jimmynoo 5 месяцев назад
I will volunteer using this for my OSCP attempt /s
@hrajrhakobjan5258
@hrajrhakobjan5258 5 месяцев назад
They don't allow automated tools like these
@jimmynoo
@jimmynoo 5 месяцев назад
@@hrajrhakobjan5258 the /s at the end of the sentence indicates sarcasm.
@NotToBeTooTakenSeriously
@NotToBeTooTakenSeriously 5 месяцев назад
does the free version come with limited uses?
@anonymousalexander6005
@anonymousalexander6005 5 месяцев назад
Probably corpo gated like intezer or whatever else he was promoting.
@darioriverajr4027
@darioriverajr4027 5 месяцев назад
Shoutout from Philippines
@YTBAlexis
@YTBAlexis 5 месяцев назад
This tool feels quite dangerous to use on a real test, how intrusive this web checks are ? Would it break something while testing ?
@TheHerisatry
@TheHerisatry 5 месяцев назад
could be great to run a webserver and see the logs after a scan from the tool
@PentestToolscom
@PentestToolscom 4 месяца назад
You can start by testing the more incisive tools on a staging/test/pentest environment. If you want to test on production, we recommend switching to passive-only options. And, for more advanced users there are options to limit requests/second and individual detectors, but it requires a bit of getting used to.
@Jamy-bl4ib
@Jamy-bl4ib 4 месяца назад
please make video on how to find lost bitcoin wallet and how to withdraw this amount into your wallet
@SohaibKhan-hp1oe
@SohaibKhan-hp1oe 5 месяцев назад
Make one video about ss7 attacks
@sophiophile
@sophiophile 5 месяцев назад
Do you know if anyone has built an LLM Agent with tool usage built around Kali? That could be a fun project I'd be willing to collab with people on. (I am proficient on the LLM side, and have basic pentesting capabilities). Anyone interested in collabing?
@user-mz1lx4ny3g
@user-mz1lx4ny3g 5 месяцев назад
i realy love osint challanges can you do that?
@TheSilentLearner786
@TheSilentLearner786 5 месяцев назад
Sir plz do videos for splunk soar
@lancemarchetti8673
@lancemarchetti8673 5 месяцев назад
Wow.. next level
@uncommoncharlie7
@uncommoncharlie7 5 месяцев назад
Watched 9 minutes in before realizing I’m ad revenue, sick 😂
@cybersamuraidk
@cybersamuraidk 4 месяца назад
Very cool tool! :) But very expensive!
@wardellcastles
@wardellcastles 4 месяца назад
I thought I paid for an ad free subscription to RU-vid
@HEXiT_
@HEXiT_ 5 месяцев назад
seems pretty cool. im guessing using these kinds of tools isnt allowed on bug bounty's?. shame though as it ripped through that really quick.
@_JohnHammond
@_JohnHammond 5 месяцев назад
I don't see why it wouldn't be allowed on bug bounties. Doesn't matter how you find a vulnerability, as long as you did find one 😜
@HEXiT_
@HEXiT_ 5 месяцев назад
@@ellerionsnow3340 depends on the scope. some briefs make no mention of automatic scanning.. while others defiantly do. i was thinking it would fall into the automation category so disallowed in the scope if mentioned. that being said johns piped up and basically confirmed what your sayin ;) ... so, cool.
@EE-hj7cm
@EE-hj7cm 5 месяцев назад
Yes, always look at the scope and then if your tools and methodology go outside of this scope for specific bug bounties
@almatsumalmaadi8103
@almatsumalmaadi8103 5 месяцев назад
Yeah i think such tools are not allowed because they flood their servers with request, imagine if couple of thousands running the same pentesting tool? They my break the network or stress their system. Once i read " find bugs but don't disturb our system".
@highfiveshighfives4980
@highfiveshighfives4980 5 месяцев назад
Did he say redis as read-is?. I’ve heard it pronounced red-is
@iakashx
@iakashx 5 месяцев назад
Cool. Not so cheap tool.
@ruinedbectorem2254
@ruinedbectorem2254 5 месяцев назад
Pay the bills All love
@zes7215
@zes7215 2 месяца назад
no such thing as nerdy detailsx etc, some tech s k, doesn't matter, no nerx etc nmw
@bathuudamdin
@bathuudamdin 5 месяцев назад
Another commercial?
@DRKSPAD3
@DRKSPAD3 5 месяцев назад
Really good video
@IntiArtDesigns
@IntiArtDesigns 5 месяцев назад
Only $400 a month if you want access to everything. *dies inside* I see why he failed to mention pricing in this ad. That's an awful lot of money just to save yourself some time. I think i'd rather invest the time into doing those basic preliminary scans myself and save myself that money. Even the cheapest personal plan is $860 for the year, with only 5 assets and limited access to functionality and tools. Sheesh. I don't think i could justify paying that even on a 6 figure income. You've spent a long time learning how to use those tools and do those scans, so you might as well just do them, as monotonous as they may be. IMHO.
@nordgaren2358
@nordgaren2358 5 месяцев назад
All of the tools are $85 a month...
@PentestToolscom
@PentestToolscom 4 месяца назад
​@@nordgaren2358 has the facts here. The Basic plan gets you access to all the tools (without authenticated and internal scans). Whether it's a fit for you or not really depends on your m.o. and goals. We all need different things to get the job done. Always good to get honest feedback!
@JustinJ.
@JustinJ. 5 месяцев назад
This channel is turning in to a NetworkChuck type channel, much ado about nothing, too much sponsored content, bring back the old John who used to teach us stuff, not show tools that cost 100's of USD a month
@Rafael-oq9vu
@Rafael-oq9vu 4 месяца назад
wow what a big fucking ad
@amirmohamed8748
@amirmohamed8748 5 месяцев назад
Hi there
@getr
@getr 4 месяца назад
John is trying to make his money but at least let us know it's a paid ad.
@0oNoiseo0
@0oNoiseo0 5 месяцев назад
Betrayed was a bit harsh as it was an easy spot.... But damn promoting that pentest site is actual cringe! sorry but... xD BTW how many ad's in this video now by total?!?!?!?!?!?!?!?!
@SatyamPatel-jc6gy
@SatyamPatel-jc6gy 5 месяцев назад
This is the video most will unfollow you
@user-in2jf7tx1q
@user-in2jf7tx1q 5 месяцев назад
Imaging that at the time when Snowden was with the USA government they got this type of technology at their hands, controlling the world with one click for an air model to do all the hard work, just amazing to imagine
@margarita8442
@margarita8442 5 месяцев назад
script kiddie stuff
@claudeorigi8764
@claudeorigi8764 5 месяцев назад
two
@jesperwall839
@jesperwall839 5 месяцев назад
No. You didn’t automate anything….
@user-ls9cw6hh5q
@user-ls9cw6hh5q 5 месяцев назад
🤣
@wb5191
@wb5191 5 месяцев назад
3 :P
@pangjinghui7842
@pangjinghui7842 5 месяцев назад
Second!
@tomdotsh
@tomdotsh 5 месяцев назад
First
@IlIIIl
@IlIIIl 5 месяцев назад
Unsubscribed because you’re literally just an ad channel now. It’s beyond ridiculous now how many ads this vid has. I understand the need to make money however this is borderline unethical. All the best.
@juliojti
@juliojti 5 месяцев назад
hello, translate your videos into Brazilian Portuguese, we love your videos.
@liamtwine2267
@liamtwine2267 5 месяцев назад
Problem is, the site costs a fortune to use.
@GG-qo4qo
@GG-qo4qo 5 месяцев назад
TF is this John, Stop now, do not sell out.
@SeniorCitizen-fp8jd
@SeniorCitizen-fp8jd 4 месяца назад
RIP This channel, full of paid promotion. You should have to declare that at the beginning. Unsubbed.
@MD4564
@MD4564 5 месяцев назад
Half of the video was sponsership........... Just as bad as LSS.
@ertaku1870
@ertaku1870 5 месяцев назад
Pls stop posting videos too often. I can’t catch up 🙏🏻
Далее
Can a PDF File be Malware?
22:26
Просмотров 83 тыс.
Introduction to Hacking | How to Start Hacking
6:55
Просмотров 1,1 млн
How Hackers Move Through Networks (with Ligolo)
20:01
Просмотров 258 тыс.
Watch hackers break into the US power grid
15:51
Просмотров 9 млн
i BACKDOORED a Desktop Shortcut (to run malware)
13:58
How to get validation proof with Sniper Auto-exploiter
4:21
Is AI The Future Of Penetration Testing?
35:38
Tracking Cybercrime on Telegram
23:26
Просмотров 300 тыс.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
Просмотров 98 тыс.
Tactics of Physical Pen Testers
44:17
Просмотров 891 тыс.
The Weirdest Hoax on the Internet
9:46
Просмотров 666 тыс.