HackTheBox - Overflow

แชร์
ฝัง
  • เผยแพร่เมื่อ 19 ธ.ค. 2024

ความคิดเห็น • 40

  • @chengtop2183
    @chengtop2183 2 ปีที่แล้ว +5

    damn,this time is so hard,First is web pentest then went into binary overflow and reverse.good video!

  • @levansadunashvili499
    @levansadunashvili499 2 ปีที่แล้ว +2

    When u watch his video and know solution on problem he have, you have feeling like he have rised you well. ❤️
    Thanks ippsec.

  • @declanmcardle
    @declanmcardle 2 ปีที่แล้ว

    This is the third time "Too many authentication failures" has popped up in as many videos :-)

  • @terraminator5441
    @terraminator5441 2 ปีที่แล้ว +2

    I guess you could have run the encrypter again to decrypt, because the reverse function of xor is xor. Cool Video :)

  • @AvinashKumar-fe8xb
    @AvinashKumar-fe8xb 2 ปีที่แล้ว

    at 1:16:40 why did we put 4 B's after 44 bytes. I tried with one B, 2 Bs ,3Bs also but only 4Bs reflected at eip address. I guess it is some kind of minimum byte of data that is needed to reflect?

    • @ippsec
      @ippsec  2 ปีที่แล้ว +2

      No, it’s probably just gdb not showing it to you, if you did like x/4x $eip to manually show 4 bytes of eip, it probably would show. It may be x/4s or something, im horrible with those commands in gdb

  • @rmlmax
    @rmlmax 2 ปีที่แล้ว

    Nice video! Thank you!
    Qq - would you recommend a practical approach to buffer overflow with heap randomization enabled (excluding env variable injection)?
    Also, what would you call the most bulletproof modern approach to binary protection (os level or not)?

  • @hm-jr4ok
    @hm-jr4ok 2 ปีที่แล้ว +1

    You're AWESOME !! ❤❤❤

  • @Heyhey_1792
    @Heyhey_1792 2 ปีที่แล้ว +2

    44:37 the dog is as annoyed as ipp :)

  • @Stain3610
    @Stain3610 2 ปีที่แล้ว

    Hiya, this is the first video of yours I've seen and ... wow - really impressive.
    How do you segment your console windows like that? looks very handy / slick how to switch around

    • @ippsec
      @ippsec  2 ปีที่แล้ว +1

      Check the tmux video out on my channel.

  • @BroodPitt
    @BroodPitt 2 ปีที่แล้ว

    @1:26:11 you did not link the symlink right....... it was going nowhere... . maybe thats why it didnt work?
    ah nevermind, still doesnt work in tmp :(
    Great video tho!

    • @ippsec
      @ippsec  2 ปีที่แล้ว

      yeah in the troubleshooting i cut out. I figured that out... tried it in /dev/shm (which it also doesn't work oddly).

    • @zx_gio
      @zx_gio 2 ปีที่แล้ว

      @@ippsec YT removed my previous comment with the link (grrr!), search for symlinks and sticky bit. It's a security mitigation feature.

    • @nibba7614
      @nibba7614 2 ปีที่แล้ว

      @@zx_gio thank you! But it's still weird it works inside folders of /tmp

  • @souleymaneadellah1176
    @souleymaneadellah1176 2 ปีที่แล้ว

    Love how Ippssec said it f-ck it to taking notes this time

  • @fabiorj2008
    @fabiorj2008 2 ปีที่แล้ว

    Amazing explanation

  • @prateekthakur2039
    @prateekthakur2039 2 ปีที่แล้ว +2

    Let's gooooo

  • @plushplush7635
    @plushplush7635 2 ปีที่แล้ว

    fix Perspective please, that box breaks all the time and cannot render anything completely, that makes it impossible to play. of course mods are always here to blame spoils but no-one is there to fix things correctly

    • @ippsec
      @ippsec  2 ปีที่แล้ว

      You should use the HTB Ticketing system to report it. I haven't played perspective, so no way to know what is wrong to report it.

    • @plushplush7635
      @plushplush7635 2 ปีที่แล้ว

      Customer Support link doesnt work on the site

  • @funnyfail9800
    @funnyfail9800 2 ปีที่แล้ว

    can you please tell me the path to become hacker like you please

    • @nibba7614
      @nibba7614 2 ปีที่แล้ว

      Sure its simple:
      1) Start reading a lot of documentation and writeups, also watch videos like this
      2) ....
      3) You are a trainee hacker in 3-5 years!

  • @ARZ10198
    @ARZ10198 2 ปีที่แล้ว +1

    Ipp OP

  • @letterc8247
    @letterc8247 2 ปีที่แล้ว

    its strange whenever i sent the send message request i do not get the "auth cookie"

    • @ippsec
      @ippsec  2 ปีที่แล้ว

      Probably a typo in cookie, I send cookies pretty often

    • @letterc8247
      @letterc8247 2 ปีที่แล้ว

      @@ippsec I shall try it soon thank you

  • @oy9804
    @oy9804 2 ปีที่แล้ว

    Subtitles are not enabled in this video

  • @notacarnivore6019
    @notacarnivore6019 2 ปีที่แล้ว

    wow thats insane

  • @almokhtar1844
    @almokhtar1844 2 ปีที่แล้ว

    Thanks

  • @0xtz_
    @0xtz_ 2 ปีที่แล้ว

    First comment 👍 great video

  • @skyfire100
    @skyfire100 2 ปีที่แล้ว +1

    First :D

  • @sand3epyadav
    @sand3epyadav 2 ปีที่แล้ว

    Download and watchcare, i notice your all words, want to say some words.
    Common ippsec learn how to type, i am idiot, etc.