HackTheBox - Backdoor

แชร์
ฝัง
  • เผยแพร่เมื่อ 18 ธ.ค. 2024

ความคิดเห็น • 46

  • @fabiorj2008
    @fabiorj2008 2 ปีที่แล้ว +29

    I'm impressed how much I can learn new things even on easy machines in ippsec videos. There is always a valuable tip that helps me a lot in my daily work.

  • @emtrexsecurity5882
    @emtrexsecurity5882 2 ปีที่แล้ว +6

    Ippsec and John Hammond get me through my day

  • @yttos7358
    @yttos7358 2 ปีที่แล้ว +2

    In the mood for quality YT content and look who just uploaded ⛱️😎

  • @argon603
    @argon603 ปีที่แล้ว

    Great video, as usual! Learned a ton, thanks. Just a quick note, the wpscan aggressive plugins enumation can be sped up a lot by using more threads (-t flag). I've used -t 200 and got the result in less than 3 minutes. YMMV.

  • @drd2852
    @drd2852 2 ปีที่แล้ว +8

    You can use "show advanced" or just "advanced" to see the advanced options in Metasploit. Use "set DisablePayloadHandler true" to disable Metasploit's payload handler and use your own (like nc).

  • @ghsinfosec
    @ghsinfosec 2 ปีที่แล้ว +1

    I really wish I could have spent more time on this box. This was awesome

  • @VoidBiscuit
    @VoidBiscuit 2 ปีที่แล้ว +12

    32:53 - This should be in the timestamps 😂

  • @ohmyavax
    @ohmyavax 2 ปีที่แล้ว

    Really good video, thank you for the effort for showing us how privesc worked and for waiting 30+ minutes to show wpscan is not useless :P

    • @Dooom7
      @Dooom7 2 ปีที่แล้ว

      videonun olayı ney

  • @jaylal4899
    @jaylal4899 ปีที่แล้ว

    The trick to stealing the process information to identify what was listening on port 1337 was a great technique.

  • @Ruiditos80
    @Ruiditos80 2 ปีที่แล้ว +9

    29:04 🐶

  • @6Sambora
    @6Sambora 2 ปีที่แล้ว +5

    Hi Ippsec, which do you prefer as your daily laptop? Windows or Mac? 🤔

  • @blackmine57
    @blackmine57 2 ปีที่แล้ว +3

    29:05 Was that a dog ? Do you have a dog ?!

  • @tlouik
    @tlouik 2 ปีที่แล้ว +2

    great work :D

  • @mathisabbaszadeh2433
    @mathisabbaszadeh2433 2 ปีที่แล้ว

    great as always

  • @Itayc3578
    @Itayc3578 2 ปีที่แล้ว +4

    Another way to find the cmdline behind the open 1337 port instead of brute forcing could be looking in the /proc/sched_debug file
    (By the way I would appreciate if someone can explain more about that file to me. This file did not seem to exist on my machine and I don't understand it to a degree I'm comfortable with.)

    • @ippsec
      @ippsec  2 ปีที่แล้ว +2

      The sched_debug won't display the port afaik. It may say GDB is running but not the arguments that started it.

    • @Itayc3578
      @Itayc3578 2 ปีที่แล้ว

      @@ippsec Yeah, I don't think it will, but it may help with intuition about interesting processes to get the cmdline of. If I recall correctly, what I did was using it and my intuition to get the cmdline of some processes, and it was a bash process so it was one of the first ones I checked, and then (in the cmdline) I found the port and connected the dots

  • @kavishkagihan9495
    @kavishkagihan9495 2 ปีที่แล้ว +1

    You can also use `screen -x root/root` to attach to a detached session. Format of -x is `username/session_name` I guess.

  • @Error-rz9re
    @Error-rz9re 2 ปีที่แล้ว

    🔥🔥🔥🔥

  • @samsepi0l227
    @samsepi0l227 2 ปีที่แล้ว

    keep going man!

  • @mikes_.5_cent
    @mikes_.5_cent 2 ปีที่แล้ว

    @ippsec can you share your bash prompt ?

  • @sezarstarscourge7368
    @sezarstarscourge7368 2 ปีที่แล้ว

    i wanna learn more request stuff what box you suggest

  • @i_sometimes_leave_comments
    @i_sometimes_leave_comments 2 ปีที่แล้ว

    Why do you run `sudo msfdb run` instead of just `msfconsole`?

    • @padaloni
      @padaloni 2 ปีที่แล้ว

      its starts the database if needed and opens the console. i always do the same thing. probably just habbit

  • @taiwolateef2981
    @taiwolateef2981 2 ปีที่แล้ว

    Please can you give me a nudge on how to get root access on meta machine.. I have been on it for some days now. Thanks in anticipation of your response.

  • @informatik4lehrplan216
    @informatik4lehrplan216 4 หลายเดือนก่อน

    Hey thank you for your guide. But in the Part of 44:17 i get this message after command: user@Backdoor:/home/user$ screen -r root
    screen -r root
    Must be connected to a terminal.
    user@Backdoor:/home/user$ screen -S root
    screen -S root
    Must be connected to a terminal.
    I did follow your guide step by step. Do you have an idea, what the problem is?

  • @AndreaTosk
    @AndreaTosk 2 ปีที่แล้ว

    why not using xmlrpc?

  • @CheaterPeter0
    @CheaterPeter0 2 ปีที่แล้ว +1

    Ippsec Rocks

    • @AUBCodeII
      @AUBCodeII 2 ปีที่แล้ว +3

      Ipprock 'n roll

    • @AUBCodeII
      @AUBCodeII 2 ปีที่แล้ว +1

      @Voldemort however he's never gonna let me down

  • @leafaravlis9705
    @leafaravlis9705 2 ปีที่แล้ว

    Is there a tool to test API zend

  • @TAYYABKHAN-fm6wx
    @TAYYABKHAN-fm6wx 2 ปีที่แล้ว

    Please sir tell me the format of fullname of hackthebox i want to create new account m new user

  • @cy_wareye7395
    @cy_wareye7395 2 ปีที่แล้ว +1

    How did you know '/self/' to add there on URL (/proc/self/cmdline)? I dont get it.
    Edit:
    8:30

    • @AUBCodeII
      @AUBCodeII 2 ปีที่แล้ว +4

      It's part of the default Linux directory structure: man7.org/linux/man-pages/man5/proc.5.html

    • @cy_wareye7395
      @cy_wareye7395 2 ปีที่แล้ว +1

      @@AUBCodeII Ah, Ty! Good to know!

  • @saidjonasrorov1721
    @saidjonasrorov1721 2 ปีที่แล้ว

    can anyone explain how hack so easy box(i try but never could it) plz?

  • @vonniehudson
    @vonniehudson 2 ปีที่แล้ว

    Yes!

  • @sparrowgamingl6200
    @sparrowgamingl6200 2 ปีที่แล้ว

    cannot find port 1337

  • @gabrielsantos19
    @gabrielsantos19 2 ปีที่แล้ว

    👍👏👏

  • @Geniyah_is_crazy
    @Geniyah_is_crazy 2 ปีที่แล้ว

    is that MacBook? cuz I see three button it have yellow green and red we have that MacBook😮😮😮😮

  • @sand3epyadav
    @sand3epyadav 2 ปีที่แล้ว

    Rockstar of hacking

  • @declanmcardle
    @declanmcardle 2 ปีที่แล้ว

    @22:30 $MANPAGER

  • @TAYYABKHAN-fm6wx
    @TAYYABKHAN-fm6wx 2 ปีที่แล้ว

    Please sir tell me the format of fullname of hackthebox i want to create new account m new user