HackTheBox - Paper

แชร์
ฝัง
  • เผยแพร่เมื่อ 19 ธ.ค. 2024

ความคิดเห็น • 33

  • @filipczuba
    @filipczuba 2 ปีที่แล้ว +3

    This has been my first box some months ago. Keep up the good work!

  • @AndreasHontzia
    @AndreasHontzia 2 ปีที่แล้ว +9

    The /proc/ keeps on giving. Once I got only a LFI, where this was mostly the only content I could load. I managed to get code execution on the server. This was a pentest of a shared cloud environment. So a big desaster. 😂

  • @HopliteSecurity
    @HopliteSecurity 2 ปีที่แล้ว +1

    So good! Keep it up IppSec, your content is greatly appreciated!

  • @thatskden8121
    @thatskden8121 2 ปีที่แล้ว +2

    If you read the code for the bot - there is a hidden command called run that gives you command execution, took me ages to realise there was SSH creds because of that

  • @AUBCodeII
    @AUBCodeII 2 ปีที่แล้ว +17

    What's going on IppSec, this is Paper and we're doing TH-cam

  • @sp3ct3r71
    @sp3ct3r71 2 ปีที่แล้ว +2

    as a office fan how could i miss this box:(

  • @lklkhvf
    @lklkhvf 2 ปีที่แล้ว +2

    Awesome explanation, as always! But I have one question... I ran linpeas 4 times and the vuln check doesn't show up... Am I doing something wrong??

    • @daniyalahmed7034
      @daniyalahmed7034 ปีที่แล้ว

      same... I don't know what's wrong.
      I even downloaded the updated LinPEAS

  • @LostInTheRush
    @LostInTheRush 2 ปีที่แล้ว +6

    I think this is the first time I have heard anyone pronounce CentOS. I've always assumed it's "Cent Oh Ess", not "Centoes". What do you peeps think?

    • @h4gg497
      @h4gg497 2 ปีที่แล้ว +3

      Cent Toss

    • @plushplush7635
      @plushplush7635 2 ปีที่แล้ว +1

      that question will change my life

  • @SaravanaKumar-qm7kj
    @SaravanaKumar-qm7kj 2 ปีที่แล้ว +2

    Hey ippsec, whenever I intercept hackthebox domain(.htb) with burp, it throws an error and automatically converts http to https. Any solution for this???

    • @ASoggySandal
      @ASoggySandal 2 ปีที่แล้ว

      it could potentially be a HSTS thing, maybe an old box set HSTS for the domain? Try clearing your HSTS settings in the browser see if it helps.

  • @pythonxsecurity8287
    @pythonxsecurity8287 2 ปีที่แล้ว +1

    ippsec can you tell me wath wrong with me on playing ctf i have a good level on ctf & programming if i start playing ctf i acctually stuck i dont know where i can start

  • @r_a_n_
    @r_a_n_ 2 ปีที่แล้ว

    running the most recent linpeas release against this box doesn't show that CVE...

  • @masamune5710
    @masamune5710 2 ปีที่แล้ว

    I wish there was a more consistent way to find subdomains with the cli tools, I cant tell how many times I been stuck bc my script aint find any subdomains istg

  • @nectius123
    @nectius123 2 ปีที่แล้ว

    Another great video!

  • @saketsrv9068
    @saketsrv9068 2 ปีที่แล้ว

    How this box is released this time ? its 6.27 AM IST

    • @ippsec
      @ippsec  2 ปีที่แล้ว +1

      Thought I released it but guess I didnt

    • @padaloni
      @padaloni 2 ปีที่แล้ว +2

      @@ippsec haha i was going to message you to see if you were ok. was thinking you must be unwell since you are so consistent with posting walkthrus

  • @plushplush7635
    @plushplush7635 2 ปีที่แล้ว +1

    sticky note: update linpeas

  • @mensahjoseph_8009
    @mensahjoseph_8009 2 ปีที่แล้ว +1

    please is there any hackthebox give away?

  • @sollybrown8217
    @sollybrown8217 2 ปีที่แล้ว

    Can you explain what makes you choose parrot OS? Thank you, I love ur vids

    • @AliaMorozova
      @AliaMorozova 2 ปีที่แล้ว

      Reason: www.hackthebox.com/newsroom/supporting-parrot-os

  • @aliabdullah9354
    @aliabdullah9354 2 ปีที่แล้ว

    17:00

  • @timrustle6114
    @timrustle6114 2 ปีที่แล้ว

    It took me fucking hours to just try the bot pw as dwights ssh password... 😢

  • @cybersecurity3523
    @cybersecurity3523 2 ปีที่แล้ว +2

    Second

  • @padaloni
    @padaloni 2 ปีที่แล้ว +1

    omg im first

  • @sand3epyadav
    @sand3epyadav 2 ปีที่แล้ว +1

    Sir i am from india, here is morning,

  • @GarthHumphreys
    @GarthHumphreys 2 ปีที่แล้ว

    /proc/ seems to be the way to go. So useful to escalate the lfi

  • @felixkiprop48
    @felixkiprop48 2 ปีที่แล้ว

    Yes I did enjoy.
    Pwnkit cve-2021-3560 dbus-send.... time base PE, need to learn how to develop an exploit that script worked superb 👏 👌. I always go the hardway timing Kill command by my own instinct in GUI poor me. 🤣😂😂