HackTheBox - MonitorsThree

แชร์
ฝัง
  • เผยแพร่เมื่อ 30 ม.ค. 2025

ความคิดเห็น • 41

  • @Foiliagegaming
    @Foiliagegaming 11 วันที่ผ่านมา +1

    Thank you for doing this. I am going through HTBA and just watching and taking notes on this is priceless for me.

  • @RISE_BEFORE_YOU_GREECE
    @RISE_BEFORE_YOU_GREECE 12 วันที่ผ่านมา +6

    Yeaaa,,, Boyz
    Ippsec Upload 🎉

  • @dairrow8550
    @dairrow8550 วันที่ผ่านมา

    Why exactly after you execute the "date" command does the connection to the machine occur? How is this related, I can't figure it out

  • @mozzamileltayeeb2948
    @mozzamileltayeeb2948 12 วันที่ผ่านมา +1

    35:53 what you click on keyboard when you login throw ssh to do port forwarding?

  • @addliam
    @addliam 9 วันที่ผ่านมา

    Thanks Ipp
    I learn from u every video. 🎉

  • @dopy8418
    @dopy8418 12 วันที่ผ่านมา +7

    If you are into netsec, this is so rich. I watch those just like a hockey player watches hockey games. Rewind every 10 seconds, pause understand his moves. Replicate his moves on my won workstation. I should donate some money to you, how can we do this ? I mean i'm benefiting so much from this.

    • @ippsec
      @ippsec  12 วันที่ผ่านมา +4

      @@dopy8418 I have YT memberships open, I don’t accept donations any other way

  • @blackhacker9393
    @blackhacker9393 12 วันที่ผ่านมา +1

    What type of terminal you're using?

  • @juniper1312x
    @juniper1312x 11 วันที่ผ่านมา

    how did you just get root through duplicati i though it was running inside Docker? where does the “source” directory come from?

  • @matheusespindola4971
    @matheusespindola4971 12 วันที่ผ่านมา

    Ipp, which monitor do you use? I got a 28 inches monitor and is awful to use vms, everything is small and selecting it to strectch in Vmware makes things bigger, but with a very low image quality.

  • @haidarkaraali
    @haidarkaraali 12 วันที่ผ่านมา +1

    how did you know that duplicati was running as root or had the necessary privileges?

    • @ippsec
      @ippsec  12 วันที่ผ่านมา +3

      Educated guess - backup software generally will have full disk access because it needs it companies want a full backup

  • @shenetworks
    @shenetworks 8 วันที่ผ่านมา

    awesome video!

  • @MohanedBakrihamad
    @MohanedBakrihamad 12 วันที่ผ่านมา

    The TikTok generation need to know that this is the real entertainment🙏🏼

  • @enhboldotgonbaatar248
    @enhboldotgonbaatar248 12 วันที่ผ่านมา

    absolute cinema

  • @user-up2rz4oo7v
    @user-up2rz4oo7v 11 วันที่ผ่านมา

    I was thinking, i have never seen you using scp / sftp not even for kraken. Is there a security risk i am not aware of or are you just more used netcat and c/p? I guess for the boxes you don't want always to setup ssh_config. Thanks.

    • @ippsec
      @ippsec  11 วันที่ผ่านมา

      No security risk - Just easier for me to copy and paste

  • @ДмитрийКузнецов-я4д
    @ДмитрийКузнецов-я4д 12 วันที่ผ่านมา +1

    20:00 (password 21,20) should be password(21,40) keep watching, thank you very much in advance! (or am i mistaken)))

    • @ippsec
      @ippsec  12 วันที่ผ่านมา +4

      @@ДмитрийКузнецов-я4д the second number is length. Not start/end.

    • @GajendraMahat
      @GajendraMahat 12 วันที่ผ่านมา +2

      ​@@ippsecoh, thanks a lot.
      i had the same doubt.

  • @anonymousvevo8697
    @anonymousvevo8697 11 วันที่ผ่านมา

    Bravo

  • @sotecluxan4221
    @sotecluxan4221 11 วันที่ผ่านมา

    What a breeze!

  • @mohammadhosein77
    @mohammadhosein77 11 วันที่ผ่านมา

    great

  • @jwouter
    @jwouter 11 วันที่ผ่านมา

    Nice but I am missing a lot of enumeration steps making it look so easy.

  • @tg7943
    @tg7943 12 วันที่ผ่านมา

    Push!

  • @MR-Gh0st_0day
    @MR-Gh0st_0day 12 วันที่ผ่านมา +1

    Thank IppSec

  • @2187nobody
    @2187nobody 12 วันที่ผ่านมา +1

    fuck yea

  • @Hope-kf1nl
    @Hope-kf1nl 12 วันที่ผ่านมา +1

    @IppSec Blind Boolean-based SQL injection isn't nearly as time-consuming as you suggest-at least, not if you're using the right approach. By implementing a binary search tree in your enumeration script, you can drastically cut down the time it takes to retrieve characters. This technique allows for rapid data extraction, even in a blind scenario. With a bit of scripting finesse, you can efficiently enumerate the target and save yourself a lot of headaches.

    • @ippsec
      @ippsec  12 วันที่ผ่านมา +1

      @@Hope-kf1nl I do show speeding up Boolean SQL injection here: m.th-cam.com/video/mF8Q1FhnU70/w-d-xo.html, which probably is the same method you are talking about. You’re still likely making 4-6 requests per character, when this can do 32 characters in a single request.
      For an md5sum, I believe every character would be 4 requests (maybe 3). So you’re talking about making 64 or 128 requests per password hash versus the 2 requests this way.
      It’s exponentially faster to go with error injection when you can.

    • @Hope-kf1nl
      @Hope-kf1nl 12 วันที่ผ่านมา

      @@ippsec Yes, this was what I was talking about. Also, yes, no arguing it. You're correct that the error-based strategy is best here.

  • @bhag47
    @bhag47 41 นาทีที่ผ่านมา

    hey ipp is there any auto clearing happening in there? in cacti when try to access that shell.php file i get 404 after a 3-4 seconds and no shell triggering🥲

  • @AUBCodeII
    @AUBCodeII 12 วันที่ผ่านมา +8

    Hey Ipp, let's assume, hypothetically, you have 426.8 billion USD. Would you buy an OSCP/OSWE/OSEP/OSED/OSEE voucher pack for all your subscribers and Discord Nitro for all the homies?

    • @ippsec
      @ippsec  12 วันที่ผ่านมา +13

      @@AUBCodeII id buy everyone HTB vouchers, I don’t like the way offsec has gone in the last couple of years. Laying off a lot of their content team left a bad taste in my mouth

    • @AUBCodeII
      @AUBCodeII 12 วันที่ผ่านมา +2

      @ippsec fair enough. I didn't know they laid off their staff

    • @ippsec
      @ippsec  12 วันที่ผ่านมา +8

      @AUBCodeII yup, they got rid of the community team (falconspy/tjnull) ~2 years ago. Then a lot of the content creators (ex: Siren) and such a year ago. To my knowledge a lot of their content is just created by contractors nowadays, which isn’t a recipe for long term success

    • @AUBCodeII
      @AUBCodeII 12 วันที่ผ่านมา +2

      @@ippsec that sucks :(

    • @GajendraMahat
      @GajendraMahat 12 วันที่ผ่านมา +1

      ​​@@ippsec lol, HTB voucher will be more interesting to be honest 🥰