TryHackMe! Skynet - Wildcard Injection

Sdílet
Vložit
  • čas přidán 28. 08. 2024
  • Come play the GuidePoint Security CTF! go.guidepoints...
    For more content, subscribe on Twitch! / johnhammond010
    If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
    PayPal: paypal.me/john...
    E-mail: johnhammond010@gmail.com
    Discord: johnhammond.or...
    Twitter: / _johnhammond
    GitHub: github.com/Joh...

Komentáře • 246

  • @jonny-mp3
    @jonny-mp3 Před 3 lety +130

    That python bruteforcer is a lifesaver

  • @Urzgag
    @Urzgag Před 3 lety +31

    Nice vid John :)
    Btw : The "balls have zero to me" stuff was from an experiment, letting 2 AIs talk to each other with a set alphabet but no actual grammatical rules.
    After a while, they just came up with their own way of communicating :D

  • @stevenhernandez3243
    @stevenhernandez3243 Před 3 lety +91

    love the content and the way you explain everything so thoroughly! id also much rather see you walk through a script like that than if you didnt

  • @Mosern1977
    @Mosern1977 Před 3 lety +43

    As a developer - very interesting to see your approach to finding weaknesses. I can sort of see the fun in this kind of activity, the lure of the dark side :)

  • @nullpwn
    @nullpwn Před 3 lety +261

    john: makes a py script out of nothing in less than 2 minutes
    me on google: "how to declare a variable"

  • @takeiteasyeh
    @takeiteasyeh Před 3 lety +214

    heretic, not confirming with ls after mkdir.

  • @compromyse
    @compromyse Před 3 lety +28

    RIP all terminator references.

  • @christianmanalaysay
    @christianmanalaysay Před 3 lety +2

    wow... exploiting the tar wildcard to set the SUID bit on /bin/bash is so freaking smart and cool man, I was stunned by how amazing that was. I'm trying to better myself at pentesting and John, you are teaching me amazing things! Thank you so much!

  • @sandipanmandal3830
    @sandipanmandal3830 Před 3 lety +28

    Sir u really are a very humble person ❤️❤️

  • @mikee.
    @mikee. Před 3 lety +14

    That tar exploit is INSANE, how have I *never* heard of "the * exploit"??

  • @karangadhave9002
    @karangadhave9002 Před 3 lety +1

    Learnt a lot through this live walkthrough, well narrated and explained.
    The best part is the way you put out your way of approaching the next possibility, that definitely helped me in knowing how to process my thoughts during a CTF

  • @tshidiflo2226
    @tshidiflo2226 Před 3 lety +6

    John please stop apologizing for doing exactly what we need (going into detail about how you as a pentester would approach this) Its exactly why I love this channel.. its not generic like the others. So please stop and carry on.

  • @mattstorr
    @mattstorr Před 3 lety +1

    Love this approach John. Its raw, honest and not contrived (i.e. doesnt come over as you've already completed it and are now just going back through the motions!). Its far more enjoyable to listen to your thought process this way, and you still seem to manage to keep things easy to understand. Nice work :-) Subbed.

    • @mattstorr
      @mattstorr Před 3 lety

      And thanks for introducing me to Terminator. Its my new favourite 'tmux' alternative :-) Now to work out what distro you are using...... ;)

  • @Child0ne
    @Child0ne Před 2 lety +1

    this video was awesome! i learned Sooooo much! thank you so much john, your the man brother!

  • @shiralihusan9344
    @shiralihusan9344 Před 3 lety +9

    I was as excited as you are when you privilege escalated. This is simply amazing.

  • @durzua07
    @durzua07 Před 3 lety +1

    Holyyyy that curl to python requests and the bruter you wrote just blew my mind. Good stuff John I really love your videos.

  • @bmbiz
    @bmbiz Před 2 lety +2

    Ah Skynet. One of the best loved THM rooms, I believe. Out of curiosity, I just looked at the conclusion in my own notes and it says "probably my favorite ctf to date." :)

  • @martyn158
    @martyn158 Před 2 lety +2

    please always go off on tangents like the python one in this video, if anything..... go on to do a video about the tangent and go off into a tangent in that video and then do a video of that tangent and so on and so on, your videos quite literally pushed me in the direction of doing my (now a year in) degree in cybersecurity and the tryhack me rooms, you sir are a legend , thank you for your work

  • @WafflesASAP
    @WafflesASAP Před 3 lety +2

    *John:* "Oh, we have a personal SMB share named milesdyson, that seems random."
    *Me:* Wait... does John not realize who Miles Dyson was in the Terminator universe?
    *John (5 mins later):* "I actually haven't seen the Terminator movies."
    *Me:* ...aha, well that explains that.

  • @salimzavedkarim230
    @salimzavedkarim230 Před 2 lety

    Been loathing reading all those articles about wildcard injection....
    Thanks for the video man :)

  • @Zachucks
    @Zachucks Před 3 lety +6

    curl to python... :O
    how did i not know about this, where has this been my whole life!?

    • @salatwurzel-4388
      @salatwurzel-4388 Před 3 lety

      I was literally sitting here and saying "bro ... that would helped me so many times" xD

  • @Deathfreeze14
    @Deathfreeze14 Před 3 lety +1

    John, I must say please do more of these vids are awesome and the talking through your process is exceptional

  • @gngn2973
    @gngn2973 Před 3 lety +1

    dude, you rock! This was awesome. when I saw the bash-4.3# i was like 😁😁😁

  • @AhmedMohamed-kn9sf
    @AhmedMohamed-kn9sf Před 7 měsíci

    I wanted it for 1 time and will be watching it for a few more times to note all the things taught here. Thank you so much for your efforts. I do respect you and your talent. 😇

  • @jonathangorelik7849
    @jonathangorelik7849 Před 7 měsíci

    super creative privelage escalation john! amazing content please keep it coming!

  • @lixanderguzman3305
    @lixanderguzman3305 Před 3 lety +36

    I don’t know what is going on but this seems interesting haha

    • @brian3947
      @brian3947 Před 3 lety

      You should learn python it’s fun

    • @lasergamer2869
      @lasergamer2869 Před 3 lety +1

      @@brian3947 I’ve learnt python but this is not just python haha. It’s also bout networking and managing file stuff

  • @cooliceman0001
    @cooliceman0001 Před 3 lety +4

    Had a great time watch you work your magic. Im still learning and watching your videos really helps! Thanks john

  • @bryttontsai6068
    @bryttontsai6068 Před 3 lety

    Amazing videos with great explanations to beginners instead of just cruising through all the answers without explaining the reasoning behind anything.

  • @meeDamian
    @meeDamian Před 3 lety

    This is probably the most educational video on the topic I've ever seen, and I've seen a lot. Amazing.

  • @armandsriekstins7646
    @armandsriekstins7646 Před 3 lety +2

    It seems like I've found my new favourite channel

  • @RycnGaming
    @RycnGaming Před 3 lety

    Thank you very much for each video you upload. I am a cybersecurity student and always I get upset, I put one of your video and get motivated to keep on.. thank you 🙏

  • @vojislavpavkovs9124
    @vojislavpavkovs9124 Před rokem

    Awesome! You are online person out there who cares to explain stuff! Love Your videos!

  • @alexclarke6839
    @alexclarke6839 Před 3 lety

    Hey John, been loving how much detail you go into when doing these videos. Keep up the great content!

  • @RedBlueLabs
    @RedBlueLabs Před rokem

    I liked how you used curl to trigger the call back. I will start bringing that into my process

  • @allesnikt
    @allesnikt Před rokem

    Just found your channel and subscribed. Awesome videos and explanations

  • @TheAyushbest1
    @TheAyushbest1 Před 3 lety +1

    Me sitting at home waiting for videos :- nothing happens for weeks.
    Me travels for 5 days :- 2 videos posted 😂

  • @uniquechannelnames
    @uniquechannelnames Před 2 lety

    Thanks for this I was having trouble with the tar wildcard portion!

  • @testingme7936
    @testingme7936 Před 2 lety +1

    i learned a lot from your videos thanks

  • @hayaanrizvi
    @hayaanrizvi Před 3 lety

    This was one of your best vids so far

  • @bbowling619
    @bbowling619 Před 3 lety

    Omg. More content! My brain cant keep up. Its literally regurgitating info at this point but im plugged back in . Leggo peeps and thank you once again Mr John !

  • @SamerAlhasweh
    @SamerAlhasweh Před rokem

    i enjoyed every single moment of this

  • @anonymoushackeromega6376

    nothing better then this..john...explnation is wonderfull :)

  • @aspxDEFINED
    @aspxDEFINED Před 3 lety

    This was incredible. Thanks for the content John!

  • @marco.garofalo
    @marco.garofalo Před 3 lety +7

    This was so much fun!

  • @jocularich
    @jocularich Před 3 lety

    this video inspired me more...thanks John

  • @rrd_webmania
    @rrd_webmania Před rokem

    This video is my favorite so far

  • @jeprox718
    @jeprox718 Před 3 lety

    CTFs are so fascinating ..enjoyable content! keep it coming!

  • @KevinMsyah
    @KevinMsyah Před 3 lety

    Please keep making contents like this, we really enjoy watching your vids ,thankss

  • @NimbleSF
    @NimbleSF Před rokem

    I'm not gonna lie, I was super annoyed once I realized how much work had to be put in at the end lol. I thought I was a rockstar until it got to the cuppa part. Then getting that stable shell and actually figuring out what to do? Infuriating. Thank you for your time an mentorship doing rooms like this for us. I wish this was something I could do on my own, but maybe THM is designed just for walkthroughs just like this so we can learn.

  • @jonasbadstubner2905
    @jonasbadstubner2905 Před 3 lety +2

    LastPass better sponsor you now. Nice placement right there.

  • @iAshenBlade
    @iAshenBlade Před 3 lety

    Can't tell how much I appreciate this was so confused at root privilege escalation lol

  • @spoonkrisp8776
    @spoonkrisp8776 Před 3 lety

    I can’t believe that I have seen a 1 hour video on CZcams and want more

  • @DanielPizarro184
    @DanielPizarro184 Před 3 lety

    so happy that ur channel exists

  • @johnmcconnell4030
    @johnmcconnell4030 Před 2 lety

    You are amazing! Thanks for the walk through!

  • @ransomhades
    @ransomhades Před 3 lety +5

    Miles Dyson is the father of Skynet

  • @shawn8163
    @shawn8163 Před 3 lety

    Great video like walk throughs to see your process.

  • @JustSomeAussie1
    @JustSomeAussie1 Před 3 lety +12

    On the part where you used python to check for logins i'm pretty sure you could use a session to make it a lot faster. s = requests.Session() s.post(url)

    • @zig0to
      @zig0to Před 3 lety

      The problem seems to be SquirrelMail taking time to process requests, setting up a session won't help with it

  • @InfoSecDojo
    @InfoSecDojo Před 3 lety

    you explain everything so simply ❤️ thanks bruhhh 😘😘

  • @oliverer3
    @oliverer3 Před 3 lety +1

    The gibberish email was a reference to a Facebook research project where two AI supposed to talk to each other essentially descended into madness.

    • @PietSahadd
      @PietSahadd Před 3 lety

      Creepy shit, did recognize it instantly :)

  • @sylvesterrac3792
    @sylvesterrac3792 Před 3 lety

    Thanks John, I always learn something new

  • @thatquietkid8610
    @thatquietkid8610 Před 3 lety

    that "what" at 18.30 has a separate fan base

  • @TntTnt-oz7iv
    @TntTnt-oz7iv Před 2 lety

    That was incredible thanks for your work

  • @johannespain7855
    @johannespain7855 Před 3 lety +1

    really great live premiere and overall video!

  • @demonview6075
    @demonview6075 Před 3 měsíci

    yo awesome vid, crystal clear thanks

  • @giuliano6535
    @giuliano6535 Před 3 lety

    Thanks for another fun and educational video boss!

  • @user-ii2hp9tp1z
    @user-ii2hp9tp1z Před 3 lety

    that wildcard priv-esc is just super nice

  • @randompicks1328
    @randompicks1328 Před 3 lety

    Buddy you are the best I ever seen so far 😍😍😍

  • @Omar-gw8lt
    @Omar-gw8lt Před 3 lety +2

    Awesome John Hammond but you let me down by not watching the terminator movie just kidding, if you do get the chance only watch 1 & 2 don't bother with the rest. lol

  • @tobiasgerber3546
    @tobiasgerber3546 Před 3 lety

    Good work. Well done. Learned a lot!

  • @mikeaxel6552
    @mikeaxel6552 Před měsícem

    great video and awesome explanation

  • @adminservice9459
    @adminservice9459 Před 3 lety

    John Hammond for president everyone!

  • @squeelyinc
    @squeelyinc Před 3 lety

    Great content John, could tell you hadn’t watched the terminator movies once you seem to overlook the miles dyson reference. :-)
    What sort of hardware and software setup would you recommend for a beginner?

  • @bladesvlogs4965
    @bladesvlogs4965 Před 3 lety

    Sweet Video! Didn't understand 95%, but it looked cool :)

  • @osamaamarneh5762
    @osamaamarneh5762 Před 3 lety

    Thank you for an amazing informative educational video ❤️

  • @toolbgtools
    @toolbgtools Před rokem

    that SUID trick was cool

  • @meetn2veg
    @meetn2veg Před 3 lety

    OMG!!! Skynet! Don't they eventually take over the world and cause its destruction that ends up with Arnold coming back from the future???
    Oh. Got to the SquirrelMail bit and then realised :-( Doh!!

  • @leblanc666666
    @leblanc666666 Před 2 lety

    loved your bin bash suid. My lazy version is simply doing that to the /etc/passwd and login as root. Have all the info I need in a file that I just copy paste everytime! Nice and quick

  • @John-hq9kx
    @John-hq9kx Před 3 lety

    That was a very Interesting video, thank you for this amazing content ! 😁👍

  • @playmaker1011
    @playmaker1011 Před 3 lety

    Simply a huge thanks ✊

  • @master_of_bytes
    @master_of_bytes Před 3 lety

    Nice video. Learned a lot from that.

  • @Bobtb
    @Bobtb Před 3 lety

    I wanted to scream at the screen: the CMS password was in that mail! :-D
    But damn, what actually happened was much better.

  • @holabola9064
    @holabola9064 Před 2 lety +1

    Awesome video

  • @gabrielex
    @gabrielex Před 3 lety

    So clear, so good!

  • @Z0nd4
    @Z0nd4 Před 2 lety

    Thank you very much.

  • @stefan.krause
    @stefan.krause Před 3 lety

    Very nice, thanks for showcasing your way of solving this room. I tried it this morning before I looked at your video. Since I cannot code in python I had a similar script as bash script, but never made it working because I forgot sending the hidden fields ..
    I don't know if the room is an easy one, I was lost after finding the user.txt
    Still a lot to learn I guess :)

  • @NerveClasp
    @NerveClasp Před 3 lety

    To the five people (by the time of posting) who disliked it, what is wrong with you?)) Great video, man!

  • @FirePower1985
    @FirePower1985 Před 3 lety

    I love it! thank you.

  • @dxnxz53
    @dxnxz53 Před 3 lety

    dude this is awesome!

  • @cmdrleeloocatfish7619
    @cmdrleeloocatfish7619 Před 3 lety

    12:50 Very cool !

  • @AA-fy7kn
    @AA-fy7kn Před 3 lety +1

    Hello John, could you do the Daily Bugle room on T.H.M.? I love the way you approach things and explain them.

  • @monkfoobar
    @monkfoobar Před 3 lety

    4:13 suddenly I have a strange urge to hit the subscribe button

  • @yusufbilalbatir5221
    @yusufbilalbatir5221 Před 3 lety

    Extremly funny, thank you.

  • @werskantti
    @werskantti Před 3 lety

    When you got to that Miles Dyson Personal Page i was sure that the picture had steganography in it.. :D But where it continued were so much better

  • @codermomo1792
    @codermomo1792 Před 7 měsíci

    thank you very mush. this was helpfull

  • @0xsudip892
    @0xsudip892 Před 3 lety

    Awesome as always

  • @siddheshghag5889
    @siddheshghag5889 Před 3 lety

    Nice execution.

  • @av9401
    @av9401 Před 2 lety

    Thank you!

  • @durzua07
    @durzua07 Před 3 lety +1

    Man I always get lost when you stabilize the reverse shell, I've tried it by myself but I get stuck on the second nc listener. I wish I could see all the steps to get a nice reverse shell.

  • @RichBeaden
    @RichBeaden Před 3 lety +4

    The John Hammond having his geek card removed due to a failure to watch terminator, I’m not angry, just disappointed

  • @dannelson2590
    @dannelson2590 Před 3 lety

    Awesome video!