HackTheBox "Business CTF" - Time - Command Injection

Sdílet
Vložit
  • čas přidán 26. 07. 2021
  • If you would like to support the channel and I, check out Kite! Kite is a coding assistant that helps you code faster, on any IDE offer smart completions and documentation. www.kite.com/get-kite/?... (disclaimer, affiliate link)
    For more content, subscribe on Twitch! / johnhammond010
    If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
    PayPal: paypal.me/johnhammond010
    E-mail: johnhammond010@gmail.com
    Discord: johnhammond.org/discord
    Twitter: / _johnhammond
    GitHub: github.com/JohnHammond

Komentáře • 44

  • @markgentry8675
    @markgentry8675 Před 3 lety +5

    Really enjoyed the time you took to explain this one. it's pretty straight forward, but this format would be great for beginners. love your work

  • @EmaCannella
    @EmaCannella Před 3 lety +2

    Followed you up since start of the year and quality has evolved in the meantime. Keep It up📼

  • @SinusQuell_
    @SinusQuell_ Před 3 lety +30

    this makes me want to try some of these myself

    • @FVT-tn8ji
      @FVT-tn8ji Před 2 lety +1

      Yeah same, the problem is that Ive never done anything like that lol

  • @LlewdLloyd
    @LlewdLloyd Před 3 lety +3

    Just wanted to say I'm new in the I.T. industry, read A+ and studying for my Network + cert while pursuing cyber security and watching these videos and having you explain things is really helpful for me despite how basic some of these are. Just wanted to say I appreciate the content this way.

  • @viv_2489
    @viv_2489 Před 3 lety

    This little breadcrumbs are so essential, thanks for sharing 👌👍

  • @joeymelo2882
    @joeymelo2882 Před 3 lety

    Love the CTF videos! Keep that up man!

  • @ca7986
    @ca7986 Před 3 lety +1

    I love your work John! ❤️

  • @4lpina
    @4lpina Před 3 lety

    absolutely love your videos John

  • @jocularich
    @jocularich Před 3 lety +1

    Love your content John....learn more and more.....greeting from indonesia

  • @MovieWorldNow
    @MovieWorldNow Před 3 lety

    I like the tune after the video ending

  • @ashishalex10
    @ashishalex10 Před 3 lety

    Awesome content, getting to learn some new stuff :)

  • @vivekchoudhary8745
    @vivekchoudhary8745 Před 3 lety

    I learned a lot from this ctf.

  • @highvisibilityraincoat

    yay john is going back to his roots

  • @koukiadem
    @koukiadem Před 2 lety +1

    Can you please tell us why it didn't work with curl or browser? And why it's working only python?

  • @thischannelhad40subscriber51

    Great video's mate.

  • @mmmdyarcavadl9004
    @mmmdyarcavadl9004 Před 3 lety

    Really helpful thank you

  • @andy-og7sv
    @andy-og7sv Před 2 lety

    brilliant

  • @BaraGraff
    @BaraGraff Před 3 lety

    love your videos man

  • @sudosuraj
    @sudosuraj Před 3 lety

    That was good

  • @faizaanilyas
    @faizaanilyas Před 3 lety +3

    What happened to the dark web series?

  • @kiingjamesdagamer4738
    @kiingjamesdagamer4738 Před 3 lety

    Love ur vids

  • @ikhmalfahmi9308
    @ikhmalfahmi9308 Před 3 lety

    Yayyyyy ctfs!!!!!!

  • @evanhadi6395
    @evanhadi6395 Před 3 lety

    u are awsome

  • @safwanljd
    @safwanljd Před 3 lety +3

    The reason it didn't work in the browser/curl was because you were using && instead of ;
    && runs the second command only if the first command ran successfully
    ; runs the second command regardless of the first command
    And since the first command is `date ''` which returns an error, the second command never ran!

    • @_JohnHammond
      @_JohnHammond  Před 3 lety +1

      ?format='; whoami # still fails in the browser.
      The command would run `date +''`, which doesn't error, and returns an error code of 0 indicating it succeeded. It just has an empty string for a format string :)

    • @AwesomeLazyNinja
      @AwesomeLazyNinja Před 2 lety

      @@_JohnHammond I believe the reason it does not work in browser is because # is never sent to the server as it is the "fragment identifier". However, URL encoding it to %23 might have worked IMO :)
      Thank you for great video as always!

  • @JitendraKumar-pi4bd
    @JitendraKumar-pi4bd Před 3 lety

    Sir ... if possible ... please release a video on Pegasus spyware ...

  • @prowlerL33T
    @prowlerL33T Před 4 měsíci

    Htb ca 2024 had same challenge again this year lol

  • @comdeyoverflow2414
    @comdeyoverflow2414 Před 3 lety +6

    I am first command. Holy YES!

  • @m4rt_
    @m4rt_ Před 3 lety

    to the 8 people who disliked, Why?

  • @chillydickie
    @chillydickie Před 3 lety

    shebang

  • @mrkaraly612
    @mrkaraly612 Před 3 lety

    Update your chrome

  • @neil7724
    @neil7724 Před 3 lety

    Nice try!

  • @keroskyindonesia6477
    @keroskyindonesia6477 Před 3 lety +1

    3rd Comment Muahahaaaa

  • @wildmatt1205
    @wildmatt1205 Před 3 lety +2

    2nd comment because replies to comments don’t count.

  • @deanvangreunen6457
    @deanvangreunen6457 Před 3 lety

    7th