Тёмный

TryHackMe! Basic Penetration Testing 

John Hammond
Подписаться 1,9 млн
Просмотров 2,5 млн
50% 1

Опубликовано:

 

2 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 1,8 тыс.   
@scott_spawn1830
@scott_spawn1830 4 года назад
he never said "Im in" when hacking.... Very dissapointed
@frankolwenda5128
@frankolwenda5128 4 года назад
epic letdown
@yashp97
@yashp97 4 года назад
Looks like a amature hacker, no i'm in is a big no
@lucasliam8238
@lucasliam8238 4 года назад
Saying I’m in is the difference between a good and great hack. He will seriously need to work on this if he wants to improve.
@bobhrobor4654
@bobhrobor4654 4 года назад
Nice
@Diglo1
@Diglo1 4 года назад
To be real hacking is more like sex. Sometimes the other party just won't participate and there is nothing to gain, however once they do participate you will likely go in and out each time deeper and deeper multiple times until something brakes and you're done. Yes some times you can try brute forcing things, but it only works if the other party is weak. If you can't brute force things and well things don't go anywhere, you should try various other approaches and see if taking your time will make a difference.
@Envinite
@Envinite 4 года назад
This is not hacking. All the texts are not in bright green color and doesn't have that "pip" sound on every letter pressed
@natking1u1z99
@natking1u1z99 4 года назад
Agreed, no Mr.Robot here
@amp4105
@amp4105 3 года назад
@@natking1u1z99 mr robot is accurate tho
@umairsyd8054
@umairsyd8054 3 года назад
@@natking1u1z99 Sorry Mr Robot is too accurate for this
@adrianozuna2149
@adrianozuna2149 3 года назад
@@natking1u1z99 wdym, mr.robot is actually pretty accurate when it comes to hacking (so no green colors or pip sounds)
@PedroHenrique-kl3ww
@PedroHenrique-kl3ww 3 года назад
@@natking1u1z99 ?????? did you even watch mr robot?
@matibrizu1207
@matibrizu1207 4 года назад
i didn't understand a single shit of what was happening but i loved every single bit of it
@nemplayer1776
@nemplayer1776 4 года назад
You and me both lol
@bloodbound696
@bloodbound696 4 года назад
Haha same, hopefully one day most of this stuff doesn't fly over my head!
@elukok
@elukok 4 года назад
Start learning linux. That alone will make a lot of this stuff very clear.
@CoachGabe223
@CoachGabe223 4 года назад
"a single shit" I lold
@rexis91
@rexis91 4 года назад
i dont even know how to program and i find this very interesting even tho i dont understand whats going on :D
@Blizy
@Blizy 4 года назад
I am now in anonymous
@Blu-ray
@Blu-ray 4 года назад
hello Mr. Blizy i am big fan pls send me csgo knife please yes?
@mirai5268
@mirai5268 4 года назад
yes
@kulcavadog543
@kulcavadog543 4 года назад
Lol
@JoDotNet
@JoDotNet 4 года назад
elo blizy give naif yez
@mattstorm360
@mattstorm360 4 года назад
@@nahomgetiye2468 No you can't. Yes we can. Nope!
@bwubi5936
@bwubi5936 4 года назад
aw man they missed out on the chance to call it 'trypenetrateme!'
@xiampiii
@xiampiii 4 года назад
I was gonna like your comment but it's sitting at 69 likes... nice
@xiampiii
@xiampiii 4 года назад
update... someone already fucked it up :/
@darkdailo2987
@darkdailo2987 4 года назад
lets get it to 420 then
@NN-rt3gf
@NN-rt3gf 4 года назад
It's so akward when you have to explain what pentester means..
@mattman1864
@mattman1864 4 года назад
@@xiampiii It's at 420 likes now.
@garchafpv
@garchafpv 4 года назад
You: And boom! we just completed the basic room! Me: WTF was basic about that!?
@herminiocossa3475
@herminiocossa3475 4 года назад
Kkkkkkk mesma coisa irmão
@blackhatstudios5673
@blackhatstudios5673 4 года назад
Hermínio Cossa tf
@Babakinha
@Babakinha 4 года назад
Apenas Hackermans entendem Hackermans
@BiIIsTheGod
@BiIIsTheGod 4 года назад
@@herminiocossa3475 ne
@camarada1996
@camarada1996 4 года назад
It stops being basic when you have to develop your own tools and exploits lol
@ecoshade
@ecoshade 4 года назад
Man you really made me watch 30 min and I didn`t even get bored xD. Great video.
@lorenzopellegrino_
@lorenzopellegrino_ 3 года назад
same!
@anantsingh75
@anantsingh75 3 года назад
before reading this comment i didnt even think this video was 30 mins long well those 30 mins were well spent...
@blidge8282
@blidge8282 4 года назад
A real hacker would be wearing sunglasses in a dark room and listening to techno.
@hematogen50g
@hematogen50g 3 года назад
And big black hood
@fuzz992
@fuzz992 3 года назад
@@dermottobin9 I think you mean Doritos.
@rogersepeda
@rogersepeda 2 года назад
@@hematogen50g damn you beat me to this comment lol
@tomthetatman714
@tomthetatman714 4 года назад
Him: "obviously this is some kind of beginner room here" Me: Doesn't understand at all what he is doing and just sees random letters and numbers.
@evanwatling3897
@evanwatling3897 3 года назад
Its like a gamer trying to play dwarf fortress for the first time. Its completely gibberish to an untrained eye and it probably takes months or years to begin to understand. All in good practice though I assume.
@Baconator1368
@Baconator1368 3 года назад
Honestly the most important thing too understanding this video is becoming familiar with Linux. I'm not at all interested in pen-testing as a career, my only involvement is watching these videos. However, I'm able to keep up with the videos just with my existing knowledge of Linux. All the special tools he uses to brute force accounts are pretty self explanatory with a quick Google search.
@RELFIR
@RELFIR 4 года назад
no "I'm attacking the firewall" and visualization of tetris being played to break said wall....disappointed
@mickcaulton001
@mickcaulton001 4 года назад
Great to see a higher level pentest explanation type video which doesn't bore you to death with every tiny detail but still goes over each of your steps. If we see a tool or vector that's new to us we can follow up at a lower level later. For a 30 min video you kept up a speed and momentum that was so easy to follow and engaging it seemed like its was much shorter. To me the sign of good video making is when you realise what you thought was short 5 or 10 min of viewing was actually half an hour or more. Definitely leaving a deserved Thumbs Up on this Video and I'm now off to check out you other content. If this video is a typical I will be subscribing for sure.
@_JohnHammond
@_JohnHammond 4 года назад
Thanks so much! Appreciate all the kind words, I am happy to hear the video is well-received. Thanks for watching!!
@nander1988
@nander1988 4 года назад
I totally agree with this random stranger on the internet. I hope there's more videos on this try hack me stuff on your channel! Nice video and hope to be seeing more of those!
@goldenlee1932
@goldenlee1932 3 года назад
Hello
@wooshbait36
@wooshbait36 3 года назад
Ok boomer 🤣
@Tech_kenya
@Tech_kenya 2 года назад
Yeah yeah it was lit 👍
@adammcveigh
@adammcveigh 4 года назад
me - print("hello world") *I AM HACKER*
@brotherindeed992
@brotherindeed992 4 года назад
#Include Int main(); { std::cout
@TheKainzor
@TheKainzor 4 года назад
@@brotherindeed992 Weird flex but ok
@qstrafe8390
@qstrafe8390 4 года назад
@@brotherindeed992 const f = "H"; let u = "E"; let c = "L"; let k = "LO"; let y = "W"; let o = "O"; console.log(f + u +c + k); let u = "RLD"; console.log(y + o + u); This took me so long to type
@h-0058
@h-0058 3 года назад
@@brotherindeed992 Wait, how do you use std::cout with lol Either std::cout from or printf() from
@brotherindeed992
@brotherindeed992 3 года назад
@@h-0058 I learnt c++ on my own but my college demands I write all programs in c, hence the mindfuck.
@shreychandra2956
@shreychandra2956 4 года назад
Ed Sheeran when he isn't making music.
@CobraunieSC
@CobraunieSC 4 года назад
Ginger : *exists* People : eD sHeErAn
@gamerology1741
@gamerology1741 4 года назад
@@CobraunieSC true 😂
@quachhengtony7651
@quachhengtony7651 4 года назад
definitely fake because i neves saw the green "ACCESS GRANTED" text showing
@vexraill
@vexraill 4 года назад
I can't believe I haven't heard of tryhackme before but I'm so excited to go try it out! Great video, can't wit to learn some new stuff!
@_JohnHammond
@_JohnHammond 4 года назад
I hope you enjoy it, I think it is a blast! Thanks for watching!
@mohammedthajudheen.k974
@mohammedthajudheen.k974 4 года назад
And also hack the box ,just try that
@rileyhowarth9721
@rileyhowarth9721 4 года назад
Are u a experienced hacker ?
@zerosploit
@zerosploit 4 года назад
@@AkashwithUS google
@jondavis839
@jondavis839 4 года назад
This dude must be a legit hacker...stole Seth Rogen's identity AND his voice.
@xttechie2995
@xttechie2995 4 года назад
Wow seeing this walkthrough has really opened my eyes to what must be done to gain access. I'm definitely getting into cybersecurity now. Great video!
@_JohnHammond
@_JohnHammond 4 года назад
Excellent, I am very happy to hear that! Thanks so much for watching!
@squirlmy
@squirlmy 4 года назад
The phrase I expect to hear after "really opened my eyes to what must be done to gain access" is you DON'T want to do cybersecurity (or your own hacking). I have a hard time imagining what you mean. Is it: "cybersecurity sounds like a really easy job, because I can sit back and know there are so many defences already in place"? I can't imagine any other way you get from your first thought to the second. Are you just lazy, or really excited about learning how to invade the privacy of others? Nothing else makes sense here.
@tiscojack
@tiscojack 4 года назад
@@squirlmy He probably just thinks that this was cool ^^
@cdev-kz3lj
@cdev-kz3lj 4 года назад
@@squirlmy you're great at parties I bet
@squirlmy
@squirlmy 4 года назад
@@cdev-kz3lj yeah, I don't get invited to parties anymore since all the fatalities at the last one. But you can hardly blame me, the axe was right there, just begging to be used!
@MrMasteryder
@MrMasteryder 3 года назад
I took a class in Cyber Security during my Bachelor's some years ago. This was a cool way of seeing some of those concepts actually applied. I found your way of solving the problem very informational, and it was definitely very entertaining
@BeesUSA
@BeesUSA 3 года назад
I've been thinking of pursuing cyber security in uni, what's it like?
@Lv1Magikarp
@Lv1Magikarp 3 года назад
Starting my degree in Cyber Security this year, can't wait.
@dinnerwithjayz
@dinnerwithjayz 11 месяцев назад
How did that turn out? 😁
@Abor-Abor
@Abor-Abor 2 месяца назад
😂😂​@@dinnerwithjayz
@thetruetom9104
@thetruetom9104 4 года назад
U sound like Seth rogan 😂😂
@azulamazigh2789
@azulamazigh2789 4 года назад
he looks like Seth rogan
@turomd2852
@turomd2852 4 года назад
@@azulamazigh2789 he is seth rogan
@NorthernHarker
@NorthernHarker 4 года назад
You're actually mentally crooked if you seriously think that
@RobertTiger942
@RobertTiger942 4 года назад
Scrolled down to find this. Not disappointed
@sadface
@sadface 4 года назад
@@azulamazigh2789 glasses and a beard, yeah sure he does....
@Boemenno
@Boemenno 3 года назад
I found that, using vim (instead of cat), I could read files that were restricted while logged in as jan. /etc/shadow (giving access to hashed passwords), but also kay/pass.bak (skipping the ssh private key step). Would you know why the system allowed me doing this? Some configuration flaw?
@shubhamsoin2429
@shubhamsoin2429 4 года назад
Thanks a lot for giving the overview. Really helpful for n00bs like me.
@_JohnHammond
@_JohnHammond 4 года назад
Happy to hear that! Thanks so much for watching!
@charleshennings5134
@charleshennings5134 3 года назад
my machine had port 8009 open so i spent most of the hour researching apache tomcat "ghostcat" vulnerability and was completely lost. humbled once again..
@jordananderson2728
@jordananderson2728 4 года назад
I knew cybersec/pentesting was a challenge and a puzzle, but I never knew it was like this! Thank you for confirming that it's something I'd like to do with my life!
@zik435
@zik435 2 года назад
i made my life a bit harder with this one... didnt noticed the ssh key part, so i exploited the vim.basic SUID to become root, and read the file
@3arabs4
@3arabs4 4 года назад
I watched this the first time and got motivated (Had no idea what was going on though). So I went over to overthewire bandit and after reading TONS of articles I was able to finish all the levels(I had zero experience in this field, also had to see 4 solutions). Now I'm in picoCTF checking out different fields(Whilst reading TONS of articles). I came back here and surprisingly I understood most of the things that you did (Not that I know the tools you used or anything but I can relate to the concept itself). The only thing that I have to read about to understand more is the ssh2john part. Anyways Just letting you know that your videos are an inspiration. I have been training since 1st October and I will be joining a capture-the-flag competition which is for middle east. I'll keep you updated with the results (I am not expecting to get a good rank but want to see how well I can do).
@v380riMz
@v380riMz 3 года назад
ssh2john is just a command for John the Ripper for bruteforcing ssh2 passwords
@Richard-wi5eb
@Richard-wi5eb 2 года назад
someone read the thumbnail and took it seriously
@zixr
@zixr 4 года назад
"Basic"
@denislavkaragiozov5876
@denislavkaragiozov5876 4 года назад
that is basic, thhe users had weak passwords like 'armando' no capitals no numbers no special chars and a short password. It's just asking to get broke into :D
@muath1125
@muath1125 4 года назад
@@denislavkaragiozov5876 Why would capital letters or special chars make it difficult i don't get it?
@florianprau8723
@florianprau8723 4 года назад
@@muath1125 If you use in a 7 char length passwort only lowercase letters, the password can easy brutforced. (26)^7 = 8,031,810,176 password combinations. Lower and uppercase letters (26+26)^7 = (52)^7 = 1,028,071,702,528 password combinations. Lower & upper & numbers (52+10)^7 = (62)^7 = 3,521,614,606,208 combinations. Lower & upper & numbers & special chars (62+26)^7 = (88)^7 = 40,867,559,636,992 combinations. With those kind of combinations, its extremly hard to brutforce. I recommend a password length of minimum 18 chars with lower & upper & numbers & special chars: 88^18 = 100,158,566,165,017,531,560,835,501,527,138,304 possible password combinations.
@highvisibilityraincoat
@highvisibilityraincoat 3 года назад
do you think hacking is just clicking buttons and done?
@pwntwtf
@pwntwtf 3 года назад
I didn't get smarter by watching this, but I did get stupid faster.
@Anatol_SG
@Anatol_SG 3 года назад
Is there a pre-pre- beginner level??? Something like fidget spinner’s level??
@highvisibilityraincoat
@highvisibilityraincoat 3 года назад
learn the linux command line
@Anatol_SG
@Anatol_SG 3 года назад
@@highvisibilityraincoat yes sir! Honestly, thank you. I am working towards a CCNA now, obviously non IT background, this every little helps.
@Anatol_SG
@Anatol_SG 3 года назад
@@highvisibilityraincoat русский что-ли?
@AlejandraCotrina
@AlejandraCotrina 2 года назад
Como cuando lo único que entiendes son los comandos iniciales, ya a la mitad del vídeo estaba como Homero Simpson xDD
@nathanmorningstar5254
@nathanmorningstar5254 4 года назад
Seems like a more organized version of Hack The Box. Definitely giving this a spin.
@_JohnHammond
@_JohnHammond 4 года назад
I tend to agree -- I'm sure you will love it if you try it out, there is a lot of great activities in there!
@arjunsharma3248
@arjunsharma3248 4 года назад
Yeah, I visited the site today and it does feel more organized and also If we subscribe we can get paths which is amazing for newbies like myself.
@bobguy6542
@bobguy6542 4 года назад
More focused on learning
@fredflintstoner596
@fredflintstoner596 3 года назад
Mrs Richards: " I paid for a room with a view!" Basil: (pointing to the lovely view) "That is Torquay, Madam. " Mrs Richards: "It's not good enough!" Basil: "May I ask what you were expecting to see out of a Torquay hotel bedroom window? Sydney Opera House, perhaps? the Hanging Gardens of Babylon? Herds of wildebeest sweeping majestically past?..." Mrs Richards: "Don't be silly! I expect to be able to see the sea!" Basil: "You can see the sea, it's over there between the land and the sky." Mrs Richards: "I'm not satisfied. But I shall stay. But I expect a reduction." Basil: "Why?! Because Krakatoa's not erupting at the moment?
@morphman86
@morphman86 4 года назад
I love how free from shame TryHackMe is. I tried to get into pentesting very early on, I think this was the early 00's, with a similar service. But back then, there was so much snobbery. The site was meant to be used to learn, but you got no hints, no instructions. You just loaded up the first page and was supposed to know what to do already. This was when search engines were still in their very early versions, so trying to look up writeups wasn't an option either. Going on forums would give you one of two responses: Why are you hacking? and You don't even know the basics? So yeah, it was hard getting into pentesting 15-20 years ago, unless you shelled out a few thousand on courses. You couldn't really go for the books, since nobody would tell you what you needed to research. But today, with services like TryHackMe, it's much more open. Free, or close to free education for the masses. And Internet has become a much more secure place thanks to it.
@RonboZ
@RonboZ 2 года назад
Great Stuff John! you are helping a bunch by making this fun and understandable....Kinda...lol
@sygyzy
@sygyzy 4 года назад
I've been using computers my whole life and my entire career is in software but I have never really dabbled in pen testing or "hacking" even though I am familiar with the concepts. I am so glad I came across your video because it really inspired me to learn more about it and it seems like TryHackMe! is the exact type of platform that I do best on when trying to learn new concepts. You gave a very brief explanation each time you used a new utility in your toolkit but to save us time scrubbing your video and searching for everything, would mind updating the description and listing out and/or linking to what was used? Thanks for posting this video - I love your style.
@marty19771210
@marty19771210 2 года назад
John, thanks for making this video. Was really great to VPN in and use my own kali box as the attack box. Learned a lot of cool stuff.
@NTDARK13
@NTDARK13 4 года назад
It would be great if you made a catalog of all the tools you have ready in opt. Although I know most of them I never actually install them in my Linux machine and would be great to have a place where everything is kept for a rainy day :)
@sent4dc
@sent4dc 4 года назад
John, it would probably help by saying that it is NOT OK to do this kinda stuff to real websites/servers. Unless you want to lose your internet privilege, or get something way worse. (And yes, provided you live in a Western country.) PS. I see so many of these brute-forcing attempts against the websites that I help administer. They are so annoying too by taking a lot of valuable bandwidth. So trust me any single one of those annoying script kiddies gets reported to their ISP.
@alexgoranov5049
@alexgoranov5049 4 года назад
Hi John, thanks for the great tutorials! I have an issue. After running john2ssh and saving it into hash.txt, I run john with the hash.txt. It gives me 'No password hashes loaded (see FAQ)'. Furthermore, I tried providing it with the rockyou.txt wordlist but it keeps giving me the same error.
@samuelmathieson249
@samuelmathieson249 4 года назад
hey I have never attempted Penetration testing but I would love to start because it fascinates me I just cant understand anything, I was wondering how you got started and if you have any help for me.
@Juliana-mo7ef
@Juliana-mo7ef 3 года назад
And? Did you start learning?
@ilias5185
@ilias5185 3 года назад
@@Juliana-mo7ef Probably not, get real lol
@Juliana-mo7ef
@Juliana-mo7ef 3 года назад
@@ilias5185 wdym with get real
@JD-qo7hm
@JD-qo7hm 4 года назад
"basic" and im over here like, "Okay, so Cali isn't referring to the state... *scribbles notes*"
@Shadowsphere1
@Shadowsphere1 3 года назад
Little sad that my university's IT program didn't have a pen testing course or introduction aside from mentioning it as a side topic. I took some Linux security courses focused on policies and configuration but I never really got exposed to tools such as these. However, I did take some digital forensics courses, so this was very similar to that with respect to data investigation. Also decent hint for threat modelers and network admins to pay attention to their policies considering how easily these tools can slip through.
@tomhgriff1
@tomhgriff1 2 года назад
This is basic?? I'm a total newbie and understood about 0.001%. VPN is about the only thing i understood.
@pizzakid135
@pizzakid135 4 года назад
How did you learn all this and understand it so easily? I've been interested and im a computer science major, but I feel like theres so much to learn but dont know where to start.
@MrJay4170
@MrJay4170 4 года назад
i have been learning from a facebook ad i saw and its really helped me heres the website. There are loads of small courses you get that build up your knowledge and even some courses that get you ready for CEH, CCSP AND CISSP Hacking seems to be very different to what you would learn in Comp Sci but some skills you may have from that could be useful
@rishabseshadri3691
@rishabseshadri3691 4 года назад
There's a 15 hour tutorial on basic pentesting information and strategies on yt, go check it out
@traida111
@traida111 3 года назад
no offence but sometimes I feel you speak too much, i mean like, the detail is sometimes a bit slow and overly long and I feel like im waiting too long to hear the important stuff. I watched another of your video on speed 2x which worked, but this video it didnt work. Just some constructive critism, im sure there are many people who dont mind and its most likely my issue. but feedback is feedback
@RGT.
@RGT. 4 года назад
was expecting "i'm in" but i still love ya xd
@twizz420
@twizz420 3 года назад
I learned how to open powershell last week, so I'm basically a hacker now. Time to corrupt the bitcoin system with my epic powershell hax0rz
@TRAVESIAA
@TRAVESIAA 4 года назад
Amazing. Thank you. Awesome. Do you know if "linPEAS is allowed in the OSCP exam?
@_JohnHammond
@_JohnHammond 4 года назад
As far as I know, no -- it is not in their Exam Restrictions. support.offensive-security.com/oscp-exam-guide/ I had used LinEnum without an issue. Thanks for watching!
@BJ-fu4zy
@BJ-fu4zy 2 года назад
Any resources on how to use linpeas?? Thats where I get stuck. How do you use Linpeas since it's pre-installed on Kali Linux?
@nate6268
@nate6268 4 года назад
Thanks for showing this site off, I'm about a month out from OSCP exam and I am going to run through the OSCP prep path.
@_JohnHammond
@_JohnHammond 4 года назад
Heck yeah! That's a solid plan! Hopefully I can get some videos out for the OSCP path soon. Thanks for watching!
@aqeebhussain9032
@aqeebhussain9032 4 года назад
Nate Golick good luck on OSCP exam Nate!
@nate6268
@nate6268 4 года назад
@@aqeebhussain9032 Thank you 🙏
@shutterbugsid1467
@shutterbugsid1467 4 года назад
All the best!
@KunalSaini97
@KunalSaini97 4 года назад
How did it gooo? :D
@codeinstein3286
@codeinstein3286 3 года назад
i just got a basic knowledge on priv esc but this video just got me know much more that i learned in my whole life before
@kenny11111video
@kenny11111video 4 года назад
so, seems the most essential tools for hacking is that "rockyou.txt"
@ldiegosousa
@ldiegosousa 4 года назад
Lol , for sure. I was watching this video on TV and I came up here to see if he uploaded the rockyou.txt . Nothing here 😅
@PanasTvP
@PanasTvP 4 года назад
@@ldiegosousa its available everywhere
@cynerboy1650
@cynerboy1650 4 года назад
@@PanasTvP what's could i search for get rockyou.txt file? please help
@PanasTvP
@PanasTvP 4 года назад
@@cynerboy1650 if you google rockyou text file, the first result will probably be a github link where you can get it
@cynerboy1650
@cynerboy1650 4 года назад
@@PanasTvP Thank you
@differntname2807
@differntname2807 Год назад
I feel like eventually some nation-state threat-actor is going to set up one one of these websites. Except while you're learning to exploit telnet, the VM is searching you for exploits.
@ml2929
@ml2929 3 года назад
After taking a linux course and Redhat, you will think this is a basic room xD
@kr36820
@kr36820 3 года назад
Where from?!
@bruhmoment490
@bruhmoment490 4 года назад
I didn't understand a single thing of what you were doing over there and I don't like programming/ hacking/whatever at all but I somehow still watched it entirely. That's a big like from me :)
@tb0nestk
@tb0nestk 4 года назад
Great vid! Should do a series of these lessons, showing the tools and the capabilities and tryhackme is a perfect site to test them with.
@_JohnHammond
@_JohnHammond 4 года назад
Absolutely plan to-- just gotta make the time for it! Thanks so much for watching!
@bibigabuyo1654
@bibigabuyo1654 4 года назад
John Hammond yes please do more video like these. Really like your approach and note taking. Hoping to learn more best practices
@ianberdahl108
@ianberdahl108 4 года назад
Just realized how much I've got to learn.
@ascetahedonista7161
@ascetahedonista7161 3 года назад
Uh... If you can excuse me, I have to go to change some chmod privileges in my server right now...
@user-yd7ug3jb4t
@user-yd7ug3jb4t 4 года назад
Oh man. John coming at us AGAIN with the great info! This is exactly what I was looking for. I've done a few HTB challenges. But I usually need help during them, because there are basic fundamentals I don't understand. And there are tools I didn't know exist. I can fumble my way through some boxes, but I'm usually pulling out my hair. This is a wonderful service. And will hopefully solve exactly that issue for me. Thank you!
@UnknownSend3r
@UnknownSend3r 4 года назад
I was looking forward to starting HTB, what fundamentals would you say you were missing so that I may check if I'm on the same boat as you.
@user-yd7ug3jb4t
@user-yd7ug3jb4t 4 года назад
@@UnknownSend3r HTB is still great, and I highly advise it. It's super fun. I'm still quite unfamiliar with the Linux system as a whole. The syntax of many of the tools. And which tools to use, why, and when. Sometimes I simply don't know where to look. But. The more practice I do, the more I learn. Hack The Box is great, but it just kinda throws you in and you just like - do it. I like that. Try Hack Me has stepping stones. Give them both a shot. DuckDuckGo and RU-vid have been extremely helpful though! xD
@UnknownSend3r
@UnknownSend3r 4 года назад
@@user-yd7ug3jb4t thanks, really appreciate the advice. Il definitely give HTB a go along with THM. Before I start any of them I plan to complete overthewire (along with my RHCSA studies) to get me familiar with the Linux command line. I also think since you're unfamiliar with the Linux system OTW would be a great place to start. It's geared towards those with little Linux experience who are interested in cybersec/hacking, and provides you with what commands you might need to complete each task. Goodluck on your journey.
@user-yd7ug3jb4t
@user-yd7ug3jb4t 4 года назад
@@UnknownSend3r I'll check it out! Good luck on your endeavours!
@tomheyde4172
@tomheyde4172 2 года назад
Very interesting video. Have never seen how someone goes about hacking. Defiently has peaked my interest to learn more.
@alexsherzhukov6747
@alexsherzhukov6747 4 года назад
Russian phrase says, "if a video doen't have ads, the whole video is an ad" haha
@ajax333221
@ajax333221 3 года назад
also, "If something is free, you are the product"
@youdonotknowmyname9663
@youdonotknowmyname9663 3 года назад
In Soviet Russia, video advertises you!
@xipity
@xipity 3 года назад
I myself work as a dev on mostly web stuff and I think I should be more worried about this kind of stuff. **anxiety kicks in**
@nickswink7983
@nickswink7983 3 года назад
Its crazy to think this was the exact video that got me into cybersecurity a little over 1 year ago and this week i just landed a job in the industry. Much love to the RU-vid algorithm!
@halzoun6195
@halzoun6195 3 года назад
Do you have relative backgrounds of computer science before that? bc it sounds incredible to pick up cybersecurity within a year
@nickswink7983
@nickswink7983 3 года назад
@@halzoun6195 yeah I was in University studying information systems. So i already had a background in web development and some other programming. Also I wouldn't say i picked it up in a year because i am still trying to learn every day.
@seeker296
@seeker296 3 года назад
10 minutes in before he even starts coding. Comp science had way too much downtime and inertia for me
@ianm-cmd_rav1448
@ianm-cmd_rav1448 3 года назад
I'm in IT administration for 20 years but never went in-dept in that stuff. Now you left me speechless.
@3styleat
@3styleat 3 года назад
if youre an admin for 20 years chances are really high that you never even properly learned about cyber security at all
@bass_rhino
@bass_rhino 2 года назад
Great video. I followed along and learnt a lot but would never be able to do it on my own. Yet
@Helkewen
@Helkewen 3 года назад
I've just discovered your channel. I'm super super new at learning coding, hacking and all this, but your videos are really enjoyables! and you help a lot to familiarize with all the technical words and stuff (yeah, I'm not that technical for now XD). Thanks for explaining what you do and what you see, I've already subscribed.
@mertcankayamc
@mertcankayamc 3 года назад
i can't realy understand what is happening but it seems cool
@h2sectaylor
@h2sectaylor 4 года назад
You’re like a more intelligent, ginger Seth Rogan. Love the video man. I’ll have to *start using tryhackme too!
@_JohnHammond
@_JohnHammond 4 года назад
Ha, thanks for the kind words! I definitely recommend it!
@shaneboltz5648
@shaneboltz5648 4 года назад
I was thinking the EXACT same thing lol.
@xXking2000Xx
@xXking2000Xx Год назад
I like it because it is like a puzzle game so you can have fun while you training.
@sechvnnull1524
@sechvnnull1524 4 года назад
Currently a cybersecurity student and just recently finished a class on pentesting and will be participating in pentesting tournaments soon with my school. Amazing job and what a great resource that you have shared hopefully we will be using this site to practice! Thank you!
@_JohnHammond
@_JohnHammond 4 года назад
That is excellent, awesome to hear that!! Thanks so much for the kind words, I do hope you use TryHackMe to learn more and more!
@RiemannThumbs
@RiemannThumbs 3 года назад
Does anyone know where I can learn what he typing and how to read the shell output? I would like to start doing this. It looks amazingly fun
@Tech_kenya
@Tech_kenya 2 года назад
🙂make more awesome videos especially on the basics ... It's was even challenging for such a beginner like me to understand most of the magic you did 👍
@nakedwildman9479
@nakedwildman9479 4 года назад
Yesterday i changed my Wifi Name to:: "Hack if you can". When i checked today it was "Challenge accepted".
@MisterL2_yt
@MisterL2_yt 4 года назад
hahahahahahahha ;D
@thrasherskater5131
@thrasherskater5131 4 года назад
dam is it really that easy
@nakedwildman9479
@nakedwildman9479 4 года назад
@@thrasherskater5131 Its not hard, yes. But If you think anyone could do it, ur wrong.
@thrasherskater5131
@thrasherskater5131 4 года назад
Nakedwildman it’s just scary knowing someone can really hack your wifi and monitor what you do... maybe do some bad things you know bro ?
@nakedwildman9479
@nakedwildman9479 4 года назад
@@thrasherskater5131 it was a joke ...
@michelrussell2014
@michelrussell2014 2 года назад
im very new to pen testing but I am learning. Even though I can barely follow what your doing, seeing how you actually go about the process is incredibly enlightening.
@mattplaygamez
@mattplaygamez 3 года назад
Can you pls make a video over the OWASP Juice Shop
@mrwilson.1
@mrwilson.1 3 года назад
I have no clue what just happened, but it was very entertaining!
@michalroth3684
@michalroth3684 2 года назад
Thank you very much for this video sober Seth Rogan!
@umer1712
@umer1712 4 года назад
Hi John. Amazing videos. Hardly had any clue what was going on but found it fascinating nonetheless. Just out of curiosity, do you know or would recommend any resources to learn absolute basics from?
@kobart1101
@kobart1101 3 года назад
question from a newbie, do you need Kali or should I be okay with Mint for this?
@_JohnHammond
@_JohnHammond 3 года назад
You can certainly use Linux Mint, or any other distro or OS you would like! You can install the tools as you need them. I'm running Ubuntu Linux in this video :)
@benneboii8117
@benneboii8117 4 года назад
Just started pen-testing in school whilst learning network security. Learned more during this than I did during 1 month of lectures+labs. Thank you!
@CLIPFILM888
@CLIPFILM888 Год назад
I AM OLD BUT I LIKE HACKING... WHAT MUST I LEARN IT FIRST ? PLEASE ADVISE ME.. THANK YOU
@omonoiafan
@omonoiafan Год назад
There is no such a thing as old.. its just passion and problem solving.
@CLIPFILM888
@CLIPFILM888 Год назад
but i feel that i can not learn fast dan memorize longer than before like in my youth...@@omonoiafan
@Obiwayne
@Obiwayne 3 года назад
Hey John, I've recently been made redundant and I was in two minds of a career change at age of 41. I started looking into cybersecurity your channel popped up in the search results. I watched this video to the very end, I sat back in my chair, I took a sip of my tea thinking, that was f@£king cool!! I want to do that for a career. I'm now on the long path to become an expert in cybersecurity just because of your video, thank you.
@IkkeBareAnders
@IkkeBareAnders 2 года назад
Rock on! I had the same experience when corona hit. Got hired four months ago. Employees market for sure.
@IkkeBareAnders
@IkkeBareAnders 2 года назад
Just noticed you posted 11m ago. How is it going?
@Obiwayne
@Obiwayne 2 года назад
@@IkkeBareAnders Hi Anders, tbh at the beginning information overload to pick theough. The path I decided to go down is Hack the box learning path. Ive come to grips with the tool about 2 months ago I'm doing bug bounties hacker1 im still along way off my goal one hack at a time.
@brandinmcclune
@brandinmcclune 4 года назад
Im flirting with the idea of switching careers to cyber security, understood nothing but loved this video xD. Does this mean cybersec is my new career path??
@dannyd806
@dannyd806 4 года назад
I’m 15:00 in and I’ve come to realize that being able to build a PC, overclock it’s hardware, instal an OS and other hardware monitoring programs is not very impressive in the world of PCs. I understood a very minimal amount of what you were doing. Looking at the source code of a website, and using the program similar to a command prompt. What you were telling the program to search for - no idea. The significance of those 4 numbers you noted down is - no idea. I imagine it would take years of practise to actual be able to hack something. My 34 year old brain isn’t a sharp as it used to be and is only going to get worse. The ship may have sailed for me regarding the ability to hack. I have enjoyed what I’ve watched so far! Well done!
@antimatter2376
@antimatter2376 4 года назад
​@@ekonomija8718 Very good but most machines have private ip addresses within a single network space, that has its own public ip address. This is because with IPv4, around 4 billion addresses are possible, and yet we have billions of IoT devices, so we use the public one as the "gateway" into the network, usually a router, and each individual device has its own private ip address within the network
@grim789
@grim789 4 года назад
Not true if you can read you can learn it.
@HartzUS
@HartzUS 2 года назад
pretty cool this site gives you a platform to hone in your skills and continue to learn
@Clemens42776
@Clemens42776 3 года назад
"there is no shame" that goes right through my heart xd
@Chiken1
@Chiken1 4 года назад
hey i know another website that shows you penetration testing, but it's a "little" different 😬
@italianfunplay
@italianfunplay 4 года назад
The best channel that RU-vid has recommended to me in a long time
@synctic
@synctic 4 года назад
Wait Im in uae but vpn is illegal in uae so what can I do I liked the we so much
@SirRyuk92
@SirRyuk92 4 года назад
would love a series going through some of these machines.
@_JohnHammond
@_JohnHammond 4 года назад
I'll see what I can do! Thanks for watching!
@helpmefriendandsuscribemyc7038
@helpmefriendandsuscribemyc7038 4 года назад
@@_JohnHammond how to made bugs cyber
@SunDevilThor
@SunDevilThor 2 года назад
I ended up exploiting the vim.basic SUID bit set file to gain access to the pass.bak file. But, this SSH route was fantastic to learn, so thanks for pointing it out!
@CsTrGaming
@CsTrGaming 3 года назад
this is the level of badass I want to achieve
@JoolsParker
@JoolsParker 4 года назад
I'm tight, and so am using the OpenVPN route and my own machine (a Mac) - struggling to find something like enum4linux on the Mac - I've downloaded the actual perl script, but it relies on the relevant client tools being installed, and I can't seem to find them - any other options you know of to enumerate users on Samba shares on a Mac?
@rmmr8513
@rmmr8513 4 года назад
man, this was fascinating!!!!!!!!!!!!!
@rannyarcher29
@rannyarcher29 4 года назад
i didnt done it like that :) but i like ur way also . when i log in into ssh of jan i put the command : sudo -l and linux say i cant use sudo :) so i put this command to find some thing to escalate my previleges : find / -perm -4000 2> /dev/null then i see something interesting ! u know what i found vim.basic 😐 then i use it to read the files which i dont have permissions to do read it 😂 actually previously i try toget shell using vim.basic by this commands : :!sh :!sh :!bash :!bash -i ... and i try also to do this command : :!whoami 😂😂😂 but nothing 's happened :( but its fiiiine i need just one thing to complete this its just the password of kay 😐 i go to /home/kay/ ohhh there is file leys read it ! cat pass.. permission denied ! 😐😐😐 hey linux did u challenge me ! so i put nano pass... and the nano is open but there is nothing but i am sure there is something useful 😐 i put vim.basic pass... then i found the pass of kay 😐 hahaha thank u for reading this stupid thing 😊 and thank u for the like 😁
@awoltv6499
@awoltv6499 2 года назад
Thank you brother your funny as heck. Man, I appreciate your openness throughout this walk-through. Also your willingness to help others who may not be as far along as you are in this Field. What are your Goals after this, and have you reached them, or are you still going to make Quality Content for us Viewers to enjoy? I want to say thank you for your time and the Passion that you have for this.
@brunomenezes9011
@brunomenezes9011 2 года назад
First time I watched this video I didn't understand a single thing. After less than a month of hard study, now I get 100% of it! That's so satisfying, even though it's considered an easy challenge.
@sai63
@sai63 4 года назад
This video randomly came up while i left my phone aside while playing a video .. great content on this page 🙌🏻
@hotjesus666
@hotjesus666 4 года назад
This guy sounds and looks like Snowden's cousin.
Далее
Дикий Бармалей разозлил всех!
01:00
OYUNCAK DİREKSİYON İLE ARABAYI SÜRDÜ 😱
00:16
TryHackMe! EternalBlue/MS17-010 in Metasploit
28:15
Просмотров 269 тыс.
Finding WEIRD Devices on the Public Internet
27:48
Просмотров 290 тыс.
Where People Go When They Want to Hack You
34:40
Просмотров 1,9 млн
TryHackMe! KENOBI - Linux Pentest: Samba Shares
34:11
TryHackMe! Skynet - Wildcard Injection
47:18
Просмотров 111 тыс.
Windows Privilege Escalation for Beginners
3:11:45
Просмотров 102 тыс.
Linux for Ethical Hackers (Kali Linux Tutorial)
2:01:00
TryHackMe! Buffer Overflow & Penetration Testing
30:33