TryHackMe! PickleRick - BYPASSING Denylists

Sdílet
Vložit
  • čas přidán 27. 04. 2020
  • If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
    E-mail: johnhammond010@gmail.com
    PayPal: paypal.me/johnhammond010
    GitHub: github.com/JohnHammond
    Site: www.johnhammond.org
    Twitter: / _johnhammond

Komentáře • 326

  • @KoalaPlaying
    @KoalaPlaying Před 4 lety +581

    I wish to understand what is happening on my screen right now, but I love watching stuff like this

    • @Jib420
      @Jib420 Před 4 lety +9

      i dont know why im watching this... i just am

    • @tanyayadav15
      @tanyayadav15 Před 4 lety +2

      Same ..

    • @Nossody
      @Nossody Před 4 lety +5

      Lookup Red Hat courses if you want to learn linux :)

    • @senseifr0st819
      @senseifr0st819 Před 4 lety +3

      @@Nossody or just use linux and consume someones legg because that also helps

    • @panicswitch1271
      @panicswitch1271 Před 4 lety +6

      @@Jib420Half way through the video I asked myself, "how the hell did I get here?"

  • @ReySoMLB
    @ReySoMLB Před 10 měsíci +43

    John, I know you're a professional and im still a beginner .. but this was the first 'CTF' that i faced in THM and its labeled as easy. This was impressive but watching you fly through this was very discouraging lol. I've gone through the rooms up to this point in the "complete beginner" path, ive taken notes, studied, and re-read rooms... and i got to this and my brain just fried watching you do this. I couldn't follow what you were doing, you were running so many cmd pages and dropping commands left and right, it was hard to keep up. This is 100% educational and inspiring at least, but holy Christ. I'm subbing now... lol

    • @kutloano.mp4
      @kutloano.mp4 Před 6 měsíci +1

      I will come back to this video in the future and I vow to be able to understand this video

    • @laronthomas2006
      @laronthomas2006 Před 4 měsíci +1

      I just got lost. I was doing well with easy rooms but now im initimidated

    • @Alberto-ww7vb
      @Alberto-ww7vb Před 4 měsíci

      I'm pretty sure he mention that he did the room previously to making the video, but still It wouldn't surprise me if he flew through it. I just did the ctf after around 3 months of learning in the junior pentest path and got stuck in various places running around in circles hahaha. Still I think is a great way to learn to watch someone so experienced to things because we can learn so fu...ng much. Good luck on your learning journey

    • @onex_vu
      @onex_vu Před 2 měsíci

      yeh fr, I got lost when I see him doing things. I have learnt so many things like u but it's still not enough

    • @dreamkiller2693
      @dreamkiller2693 Před 28 dny

      ​@@kutloano.mp4 come back 😂

  • @davidthedreamer0
    @davidthedreamer0 Před 4 lety +148

    Me: Omg, Jon! How many command lines do you know???
    Jon: Yes.

  • @jacquescilliers4511
    @jacquescilliers4511 Před 2 lety +32

    To be honest as an absolute beginner in the cyber security space, watching videos like this makes me doubt myself, but excites and scares me all the same time

    • @angeatgr
      @angeatgr Před 2 lety +2

      Its like learning to code, I remember feeling like shit when learning OOP, today is a second nature and so is ethical hacking, there is a lot to learn, networking, pentesting tool, a bit of programming, linux, windows etc.. but you will get there !
      It takes time, lot of it and more with practice

    • @blazingfalcon7387
      @blazingfalcon7387 Před rokem +1

      I feel the same way lol

    • @iCyberVenom
      @iCyberVenom Před rokem +4

      Well he's absolutely ripping through the challenge at one million miles per hour, so....don't feel bad. He clearly posted this video to showcase his skills and speed, not to teach others. He couldn't possibly type, switch screens/apps, speak any faster than the pace he's moving in this video. Change the playback speed to 1/4 speed and you'll still see he's moving quickly.

    • @john_wick_catcher26
      @john_wick_catcher26 Před rokem +1

      how is it going after 9 months ?

    • @IGORDYES
      @IGORDYES Před rokem +1

      @@iCyberVenomhe clearly stated he spent a while in this before recording. The video is nearly 20 minutes and the box is just about as easy and beginner friendly as they come. He was not trying to show off his skill. It’s clear you need to practice alot. Good luck and cheer up.

  • @RossMitchell
    @RossMitchell Před 3 lety +15

    John - absolutely loving the videos dude. I'm an absolute level 0 n00b so some of this was over my head, but trying my best to work hard and grasp the basics! Appreciate the effort you put into your videos and the time you spend to explain things, you're a top dude. Peace!

  • @4ag2
    @4ag2 Před 4 lety +11

    Big fan ! I do learn a lot from you, I'll make sure to support whenever I'll be able to do that. GREAT JOB

  • @Laflamablanca969
    @Laflamablanca969 Před 4 lety +9

    What a great series. Please keep doing these! :)

  • @adriasanchez6633
    @adriasanchez6633 Před rokem

    Thanks John! That was my first ctf, i learned a lot trying stuff and your video gave me the tips i’m not aware of at the moment to run forward.

  • @Godmil
    @Godmil Před 3 měsíci

    Oh wow, that took me hours 😆 I'm going to write down everything you did here because that was just beautiful seeing how efficiently you got through it.

  • @Steefie70
    @Steefie70 Před 3 lety +3

    Thank you, every day I learn something new, also thanks to you John, you are very fast, but there is no limit to repeat the video (haha). All the best from Rotterdam.

  • @yankeesouth
    @yankeesouth Před 3 lety +2

    Your content has helped me learn so many things. My brain has one wrinkle in it now. Thank you

  • @giovanniromio2767
    @giovanniromio2767 Před 4 lety +10

    Loved the recap at the end. Also perfect editing of the video.

  • @jalajkumar9955
    @jalajkumar9955 Před 4 lety +39

    Hey John! Please create more THM videos, as they are very good for understanding new concepts and ways to exploit a box.
    Thank You !

  • @CleanCivilian
    @CleanCivilian Před 2 lety +2

    I really wanted to do this room without help, but man... there is just some things i do not know and the 'basic' room did not teach! Thanks for the walkthrough, took notes while following along and trying to figure out as you gave info.

  • @CybrJames
    @CybrJames Před 4 lety

    Kind of cool to see the Thumbnail work you did yesterday live today. Great video. Keep up the great work you're doing.

  • @kentharris7427
    @kentharris7427 Před rokem

    I like the way you take notes. I am going to implement it since I can use text files over different operating systems. I used Burp suite which didn't work for this room. Typically Burp suite will show the pages of a website which was not the case for this room. I joined THM about a week ago, with a background in IT hardware, so this has been a challenge. Thank you for your video.

  • @capivaradeprograma
    @capivaradeprograma Před 11 měsíci +2

    At first I was kind of afraid of not manage to complete this room.
    But watching your video makes me understand every concept tha I have been through in the path "Web fundamentals" and make this room way less scarier 🤣🤣🤣
    Great video

  • @jamaledineamarir6724
    @jamaledineamarir6724 Před 3 lety +13

    netcat is actually in there. You can redirect the STDERR output to STDOUT (as no result were shown in the portal.php page). Here's the command for that 10:50 :
    $ nc --version 2>&1
    $ nc -h 2>&1
    $ man nc
    That way, any error (stderr) will be prompted in the web page (stdout), instead of staying blank ^^.
    $ nc --version doesn't exist

    • @bcordone
      @bcordone Před 3 měsíci

      Yep. I found out netcat was on there via man nc, and then I used msfvenom to get the reverse shell. The part that had me stumped was how to get ROOT, ironically. "sudo -s" gave me some sort of error (forgot what it was exactly), su root prompted me for a password I couldn't figure out (I don't think ROOT even has a password in this one. I wonder if it works if you just hit enter without typing anything in) so I never would have thought of trying "sudo su root" which worked without asking for a password.
      When I saw "you can run all, nopasswd" I thought it meant you could run all commands that don't require a password (i.e. guest access) so I spent a while trying to dig around to see if there was some sort of local privilege escalation exploit but gave up and was asking for help on the discord, then I frustratedly tried sudo cat /etc/shadow after someone pointed out "Doesn't one thing stick out?" and it worked, then I tried sudo su root and got root.

  • @masterbloon9812
    @masterbloon9812 Před 2 měsíci

    Ahhhhhhhhhhhh thanks for the tipp with the reverse shell, i was really stuck at that point XD

  • @BenKadel
    @BenKadel Před 4 lety

    Love your videos dude! This was awesome!!!

  • @patrickavognon2850
    @patrickavognon2850 Před 3 měsíci

    Thanks John, this is video is very helpful

  • @ggmaxx66
    @ggmaxx66 Před 2 lety

    excellent presentation John!

  • @real.xplo1t
    @real.xplo1t Před 3 lety

    strings also helps in the portal.php page. Good stuff

  • @nicolaslaborie5015
    @nicolaslaborie5015 Před 4 lety +2

    for the cat "file" that didn't work, less did :) Very nice walkthrough. It was a fun box :)

  • @sergiohernandez273
    @sergiohernandez273 Před 2 lety

    All this it's awesome, at the beginning, I didn't know how to upload rev' sh, but from now on I can see it's very easy. 'E= Congratulations!

  • @the_offsec_noob1120
    @the_offsec_noob1120 Před 4 lety

    You are an awesome mentor.. Thanx you helped a lot and know i started my own channel..

  • @andrevwebb
    @andrevwebb Před 9 měsíci

    Wow…..thank you. This is great

  • @Micahs0day
    @Micahs0day Před 2 lety

    Excellent video!

  • @rellsw02
    @rellsw02 Před 4 lety

    A great video that you made look very simple.

  • @CybrJames
    @CybrJames Před 4 lety +3

    Damn, you make it look so easy. Hard to follow as a beginner, as I don't always understand. But I will get there. NICE

  • @rodriquh
    @rodriquh Před 4 lety +1

    This was an excellent example of owning a box. Great job using the poor mans pentest, it’s really an awesome accomplishment.

    • @su8z3r03
      @su8z3r03 Před rokem

      What is the poor man pentest ?

  • @SeaDraGraphics
    @SeaDraGraphics Před 4 lety +9

    man i would love to see another king of the hill livestream

  • @silf6950
    @silf6950 Před 2 lety

    Thanks for the help!

  • @cooliceman0001
    @cooliceman0001 Před 3 lety

    Really enjoy your videos

  • @xorinzor
    @xorinzor Před 4 lety +28

    7:30 searching for incredibly difficult workarounds, while all he had to do was just add the filename to the base URL since they're located in the webroot, lol.

    • @imTyp0_
      @imTyp0_ Před 2 lety +2

      Commands: less and tac work to read the files. Also everything was doable from the website, aka without a shell

    • @iCyberVenom
      @iCyberVenom Před rokem

      I remember thinking, "It's impressive he knows multiple paths to get where he wants to go, but there's no way this is the easiest path"

  • @4rikkkk
    @4rikkkk Před 5 měsíci

    I'm beginner and this is my 3rd machine, I completed it without running a reverse shell, but the fact is I tried to :') I will keep this way to run a revershe shell, thanks!

  • @tizkit1
    @tizkit1 Před rokem

    Thank you for this helpful vid

  • @haXez_org
    @haXez_org Před 2 lety

    Cheers John

  • @dopy8418
    @dopy8418 Před 4 lety +32

    Hey i've see that thumbnail somewhere...

  • @CuteTransGirlxD
    @CuteTransGirlxD Před 4 lety

    I didnt know this was a thing. I wish my college classes was this cool when it came to doing this

  • @talio-5469
    @talio-5469 Před 4 lety +4

    Liked, already subscribed, and I'm typing things to then press enter.

  • @onlylikenerd
    @onlylikenerd Před 4 lety

    Fantastic video!

  • @TRD_Mike
    @TRD_Mike Před 2 lety

    Type things in and hit the enter button to submit a comment. Thanks for making this video my dude.

  • @justangryvideos47
    @justangryvideos47 Před 3 lety +2

    This is not even close to how I did this ctf. But thats the cool part, there are so many ways to tackle the same room

  • @robertoquinones785
    @robertoquinones785 Před 3 lety

    I tried using head, cat and less, and less was the only one who worked. But happy to learn the grep . approach. !

  • @omerahmed463
    @omerahmed463 Před rokem

    You are awesome
    Love you John

  • @oussamanbou1090
    @oussamanbou1090 Před 4 lety

    i love what you are doing

  • @lance_lot2866
    @lance_lot2866 Před 3 lety +2

    Hello, when I walked through this room, I googled commands to output the file contents and one of them was "nl". It is not forbidden and is on the system. And file "second ingredients" I read with the command: "nl /home/rick/second\ ingredients". It's great that you can go through it in different ways.

  • @mr.meatbeat9894
    @mr.meatbeat9894 Před 3 měsíci

    Thanks dude

  • @osmanisiktas
    @osmanisiktas Před 2 lety

    He is in another dimension!

  • @sfxElrick
    @sfxElrick Před 3 lety +2

    @John Hammond you can also use wildcards to evade that type of blacklist: /bin/ca? *.txt will work

  • @keithreynolds4108
    @keithreynolds4108 Před 4 lety

    Gotta say, it's impossible for me to follow that without pausing this but bravo!

  • @cyberdevil657
    @cyberdevil657 Před 2 lety

    Holuy shit John you are a ninja at this!
    Ive seen the intervieuws with networkchuck & David Bombal. And what u do is amazing!

  • @felipecg6587
    @felipecg6587 Před 3 lety

    gracias amigo, you rock!

  • @kylemagness5172
    @kylemagness5172 Před 4 lety

    nice stuff! ive gotten into linux a little, have it running on my laptop and RasPI but nothing as cool as this!

  • @phoenixbird09
    @phoenixbird09 Před 3 lety

    Thank you!!!

  • @pascalkasparian1316
    @pascalkasparian1316 Před 2 lety

    It's seems so easy for you.. i'am a beginner and it was a little hard for me to understand all stuff ;) Love your vidéo Thx

  • @comedytime9010
    @comedytime9010 Před 2 lety

    Superb sir ❤️❤️

  • @RicondaRacing
    @RicondaRacing Před 2 lety

    I started getting lost after you popped the reverse shell...lol

  • @skinhoe
    @skinhoe Před 4 lety

    Are you on the Redteam at VZ? I loved this video, can't wait for more; subed and all notifications on

  • @shubhamsoin2429
    @shubhamsoin2429 Před 4 lety

    Thanks for the super neat walkthrough John.
    Could you please share the link to the video on setting up a stable reverse shell?

    • @UsamaAli-kr2cw
      @UsamaAli-kr2cw Před 4 lety +3

      python -c 'import pty;pty.spawn("/bin/bash")'
      Ctrlz
      stty raw -echo
      fg
      Enter key 2 times
      export TERM=xterm

  • @lugasiyt899
    @lugasiyt899 Před 3 lety

    love ur videosss keep up the good work btw i just did less clue.txt its worked well :)

  • @Noeth
    @Noeth Před 3 lety

    Very nice. I actually used strings to cat out.

  • @zacktzeng8569
    @zacktzeng8569 Před 2 lety

    Hi John thanks for the awesome video! Out of curiosity, how do you split the terminal? Is that the native Ubuntu terminal or did you use something else?

  • @Sami-xv8ve
    @Sami-xv8ve Před 4 lety

    great video man.

  • @nothingreallymatters7530

    i love watching this

  • @Jsfun
    @Jsfun Před rokem

    Rough seeing LastPass knowing what we now know.

  • @TheTubejunky
    @TheTubejunky Před rokem

    Well made video!

  • @DrRedrum
    @DrRedrum Před 2 lety +2

    that... was.. TOTALLY AWESOME!!! I wanna do stuff like this too! By the way your typing speed is insane!

  • @nestorvillafane7737
    @nestorvillafane7737 Před rokem

    What a ninja.

  • @natking1u1z99
    @natking1u1z99 Před rokem

    The first two flags were simple. But the third was stuck on because i couldn't figure out how review the source code for the php page, even though we didn't need it.
    Python3 didn't work for me so i had to see if the perl and php commands work which they did. A php shell wouldnt connect but perl reverse shell worked.
    I going to revisit this room once i really all fet a hold of what im learning . Been working on the support side of IT for 9 years so this is a new realm for me.

  • @Zeeshan220dtsi
    @Zeeshan220dtsi Před 4 lety

    Helped me alot !!

  • @ashelift
    @ashelift Před rokem

    Great video! By the way you can solve the entire thing from the website command panel (without any reverse shell)

  • @ryzein8450
    @ryzein8450 Před 4 lety

    i don't understand what is he doing, but it's so fun to watch.

  • @HackSyndicate
    @HackSyndicate Před rokem

    less works better than cat for me, in most situations. Great video, thank you!

  • @Nixamina
    @Nixamina Před 4 lety +2

    I didn't understand anything but i still watched the whole video.

    • @Melvin420x12
      @Melvin420x12 Před 4 lety

      It’s worthy to do the basic rooms in TryHackMe. OpenVPN, Linux Basics and Vulnversity. Just those three are enough to understand everything. Personal experience haha

  • @nullpwn
    @nullpwn Před 4 lety

    thanks man, now i know where i suck at..

  • @rafaelpedroso7002
    @rafaelpedroso7002 Před rokem

    that was nice to do with John

  • @starcloister4651
    @starcloister4651 Před rokem +1

    I still haven't learned all the stuff he did in the last few minutes. I did the web app hacking path and it taught me a lot but I still feel like it didn't prepare me for this exercise.

  • @VectorGameStudio
    @VectorGameStudio Před 2 lety

    Wow so many techniques 😬

  • @danielclv97
    @danielclv97 Před 4 měsíci

    the 2nd command I used after the cat failed was less, and it just worked! haha, weird they blocked head but not less

  • @sean_reyes
    @sean_reyes Před 4 lety +1

    Loved it.. it inspires me do to some CTF.. question.. do you really recommend using linux OS for doing stuffs likes this? if so.. what distribution?

  • @theITGuy-no3nt
    @theITGuy-no3nt Před 3 lety

    🎥🎬🍿 Its like SecDork movie night! 🍿🎬🎥

  • @1joaods
    @1joaods Před 4 lety

    i have no fucking idea of anything i´ve just watched lol. liked it

  • @RicondaRacing
    @RicondaRacing Před 2 lety

    Woah, this is a really advanced room...

    • @iCyberVenom
      @iCyberVenom Před rokem +1

      It's actually not - he made it more complex than it had to be

  • @carnifex17
    @carnifex17 Před 2 lety +1

    To bypass blacklist in command panel we could just use "less" command

  • @francoramirezcastillo8075

    doing it I only got to the part where the command can be executed, where the reverse shell was done, but then I had to watch this video and even so it took me about 2 hours in total to complete this CTF, and that was an easy level...

  • @nayeemislam574
    @nayeemislam574 Před 2 lety

    Love the way he teaches these stuff.

  • @notkorean1224
    @notkorean1224 Před 4 lety

    I don't understand anything that is going on but its super entertaining

  • @unknwonyes3345
    @unknwonyes3345 Před 2 lety

    WTF the voice of this guy is deep af

  • @cannae187
    @cannae187 Před rokem

    The guy is blazing fast

  • @gilbertobarron
    @gilbertobarron Před 3 lety

    Nice room!

  • @davidthedreamer0
    @davidthedreamer0 Před 4 lety

    Damn... it looks powerful to use commands like that

  • @fongjon
    @fongjon Před 3 lety +1

    A question, at 13:45 ish when quake is used the commands in the script (stablize_shell.sh) are echoed on the other netcat shell, how is this happening? If I do the same on my system the script writes out the commands on the guake shell. What am I missing? Thanks to anyone who can help

  • @edgarchan5251
    @edgarchan5251 Před 4 lety

    I appreciate you fully prepared before you start recording.
    but... its better to clear your browser caches on those text boxes, which shows your submission histories~

  • @chrisshevlin7771
    @chrisshevlin7771 Před rokem

    I've been trying for ages to use gtfo bins for privilege escalation in the command line, I'm assuming now having watched this video that it won't work and I'm looking in the wrong place and only a reverse shell is the answer?

  • @SDavies2010
    @SDavies2010 Před 3 lety +1

    Oh man as a noob, I tired to follow getting the stable shell and can't get it to work.. Went to the poor mans pentest video and still didn't know what was going on 😂

  • @thesuperpunmaster6369
    @thesuperpunmaster6369 Před 4 lety +1

    Funniest CTF I've ever seen

  • @reign6139
    @reign6139 Před 4 lety +1

    Aaaaaand now I’m taking emptying my bank accounts for cash

  • @EpiDot52
    @EpiDot52 Před 4 lety

    Super cool!