Plundering AWS S3 Buckets - HackTheBox

แชร์
ฝัง
  • เผยแพร่เมื่อ 23 เม.ย. 2021
  • For more content, subscribe on Twitch! / johnhammond010
    If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
    PayPal: paypal.me/johnhammond010
    E-mail: johnhammond010@gmail.com
    Discord: johnhammond.org/discord
    Twitter: / _johnhammond
    GitHub: github.com/JohnHammond

ความคิดเห็น • 109

  • @viv_2489
    @viv_2489 3 ปีที่แล้ว +48

    Pwncat, linpeas juggling and then that auto deletion of files from files folder.. Entertainment with learning😂.. awesome video....thanks

  • @mindzhd
    @mindzhd 3 ปีที่แล้ว +39

    When I found myself screaming "IT'S IN ADSERVER JOHN!!" I realised I learned something from watching this channel.
    Thanks John, stinkin love your content! You're one of the more vibrant pen-test people I know of and watching you wiggle your way through this and that is really entertaining and informative at the same time. You could probably teach this stuff professionally through those platforms like skillshare or brilliant!

    • @InsomniaFire
      @InsomniaFire 3 ปีที่แล้ว +2

      He has a great Udemy course

    • @PalCan
      @PalCan 2 ปีที่แล้ว +1

      @@InsomniaFire what is the course called? Thanks

    • @emporiove
      @emporiove 2 ปีที่แล้ว

      @@InsomniaFire whats the name of the course?

  • @Devinatron
    @Devinatron 3 ปีที่แล้ว +20

    This is fantastic and I'm so happy I found your channel! I just participated in my first CTF (HTB Cyber Apocalypse) and it was so much fun! I didn't do too great, but learned a ton. Thanks for getting me into this fun 'hobby' to help build my skills as I work towards a career shift.

  • @rudisrozitis
    @rudisrozitis 3 ปีที่แล้ว +16

    1:00:24 got that Batman voice on point! :D

  • @andymac7668
    @andymac7668 3 ปีที่แล้ว +6

    I do not live in this coding/hacking world at all, but, this was very interesting to watch. Thank you for creating this content

  • @wilcosec
    @wilcosec 3 ปีที่แล้ว +1

    Fun walkthrough of a great box. Great job, John!

  • @xaxabogbart
    @xaxabogbart 3 ปีที่แล้ว +3

    How random - I've met one of the guys who founded Hack The Box. He lives in my hometown. Glad to see it's launching into something really cool and getting attention - not surprised though, he was a very astute fellow.

  • @Mslepe_8374
    @Mslepe_8374 3 ปีที่แล้ว +4

    this video and your content in general is mind blowing. Truly awesome stuff!

  • @jmoncadagutierrez
    @jmoncadagutierrez 3 ปีที่แล้ว +8

    john this was genuinely one of your best videos!!

  • @morsi7842
    @morsi7842 3 ปีที่แล้ว +2

    Awesome john, So much useful data in one video.Thanks appreciated

  • @sneezeman
    @sneezeman 3 ปีที่แล้ว +18

    Love that everytime John tries to showcase Pwncat it just breaks in some way

  • @thatcreole9913
    @thatcreole9913 3 ปีที่แล้ว +4

    Brilliant job John. Please keep them coming!

  • @fadhilsaheer8877
    @fadhilsaheer8877 3 ปีที่แล้ว +11

    *Put a magnifying glass on your computer if you see red bugs you are in malware*
    - John Hammond 2021 😹

  • @TheBrutaline
    @TheBrutaline 3 ปีที่แล้ว +7

    I saw your name pop up on the activity feed for the box a couple of days ago. I was hoping you would make it into a video, very cool.

  • @StevenIngram
    @StevenIngram 3 ปีที่แล้ว +2

    It never ceases to amaze me how much of a security hole can be. LOL

  • @Cojo173
    @Cojo173 3 ปีที่แล้ว +3

    Loving this type of content!!!!

  • @fennex79
    @fennex79 4 หลายเดือนก่อน

    I love your way of thinking!

  • @Basieeee
    @Basieeee 3 ปีที่แล้ว +3

    We are now on amazon's watchlist.

  • @f_u8264
    @f_u8264 3 ปีที่แล้ว +1

    ''Dang it'' part really got me!

  • @hibdfghf2500
    @hibdfghf2500 3 ปีที่แล้ว

    I loved this machine !! I learned di much about aws dynamodb

  • @XiSparks
    @XiSparks 3 ปีที่แล้ว +1

    "aws get-buckets" - Uncle Drew

  • @talinross
    @talinross 3 ปีที่แล้ว +1

    Awesome job love it !

  • @wizzbitgxs
    @wizzbitgxs 3 ปีที่แล้ว +2

    This was a very cool action Movie! Maybe Mr. Robot season 5 with John Hammond? :D

  • @GilligansTravels
    @GilligansTravels 3 ปีที่แล้ว

    Great video John!

  • @munaz55
    @munaz55 3 ปีที่แล้ว

    awesome content, thanks john

  • @Kurainu
    @Kurainu 3 ปีที่แล้ว +1

    I must say I get some Ippsec Vibes with the Ip Adress and how your saying the nmap stuff :D. But Grreat Video

  • @DevashishGuptaOfficial
    @DevashishGuptaOfficial 3 ปีที่แล้ว +23

    I wish the audio was a bit louder 🥺

  • @gp6723
    @gp6723 2 ปีที่แล้ว

    Great, really liked this

  • @onlylikenerd
    @onlylikenerd 3 ปีที่แล้ว

    You make it look too easy. I get inspired and try and realize quickly my experience is lacking haha!

  • @NothingPicksLocks
    @NothingPicksLocks 2 ปีที่แล้ว

    That was friggin awesome John

  • @ResonantFractal
    @ResonantFractal 3 ปีที่แล้ว +4

    Fun stuff! Wonder what would have happened if you had tried sshing with the usernames in their correct case.

  • @SinusQuell_
    @SinusQuell_ 3 ปีที่แล้ว

    I learned so much today

  • @mrbeancanman
    @mrbeancanman 3 ปีที่แล้ว

    love your videos dude !

  • @secwriteups
    @secwriteups ปีที่แล้ว

    First person on yt who doesn't une neither Parrot nor Kali.

  • @mushenji
    @mushenji 3 ปีที่แล้ว +1

    This is extremely cool

  • @11anushkariya18
    @11anushkariya18 3 ปีที่แล้ว

    Great music John Hammond xd

  • @playmaker1011
    @playmaker1011 ปีที่แล้ว

    More Cloud John!
    Thanks a lot, as always :)

  • @obeydabachir5975
    @obeydabachir5975 3 ปีที่แล้ว

    You are the best Jonny

  • @H4cK3r5
    @H4cK3r5 3 ปีที่แล้ว +3

    Awesome John !

  • @JoeM370
    @JoeM370 8 หลายเดือนก่อน

    This is top-of-the-line material. I read a similar book that was a huge turning point for me. "AWS Unleashed: Mastering Amazon Web Services for Software Engineers" by Harrison Quill

  • @AttkBeast
    @AttkBeast 2 ปีที่แล้ว

    WWJD, What would John do? That's how I approach these challenges in HTB and THM. After watching these videos your voice and logic get stuck in my head!

  • @imranthoufeeque165
    @imranthoufeeque165 3 ปีที่แล้ว +18

    Just to inform everyone who are doing OSCP... Linpeas has been banned by oscp because of auto-exploitation feature... Again Linpeas creator reached out to OSCP and confirmed that there is no auto-exploitation feature on linpeas.. So OSCP agrees for the new version of linpeas and banned older version of linpeas so be careful....

  • @andydwyer4285
    @andydwyer4285 2 ปีที่แล้ว

    straight up cool

  • @crazyman7659
    @crazyman7659 3 ปีที่แล้ว +2

    John is the best

  • @AhrenBaderJarvis
    @AhrenBaderJarvis 3 ปีที่แล้ว +8

    Stop saying you're bad at everything. You're learning.
    I get the temptation but think of everyone watching who likely is newer to this than you. They also are just learning.

  • @jtucker87
    @jtucker87 ปีที่แล้ว

    John: How do I use this?
    Server: tutorial.start()
    John: Nope...

  • @ARIFF861
    @ARIFF861 3 ปีที่แล้ว +2

    i wish for more htb content in the future

  • @ARZ10198
    @ARZ10198 3 ปีที่แล้ว +1

    Peculiar john

  • @BrunoAraujo677
    @BrunoAraujo677 3 ปีที่แล้ว

    This video show that I know more about something John doesn't, hahah 😂

  • @leonardoorona
    @leonardoorona 3 ปีที่แล้ว

    nice one John...

  • @causeitis
    @causeitis 3 ปีที่แล้ว +2

    31:46 I think the fi you commented out at the bottom was a mistake

  • @John-shreds
    @John-shreds 3 ปีที่แล้ว

    Does the endpoint url take the place of access keys for the AWS cli? So because it's public you don't need any access & secret keys?

  • @nmay231
    @nmay231 3 ปีที่แล้ว

    It contains a bucket.
    Dear God...
    Scout, SEDUCE ME!

  • @freshios4873
    @freshios4873 3 ปีที่แล้ว +1

    Rick and morty creator knows coding??!? This dude can do it all

  • @luciferreficul1926
    @luciferreficul1926 3 ปีที่แล้ว

    Nice!

  • @pk10006
    @pk10006 3 ปีที่แล้ว

    Epic skillz

  • @sebastian33458
    @sebastian33458 3 ปีที่แล้ว

    🤯👌🏼💯

  • @cassandradawn780
    @cassandradawn780 3 ปีที่แล้ว +1

    nice

  • @RCJans
    @RCJans 3 ปีที่แล้ว +2

    fudge btw

  • @aaryanbhagat4852
    @aaryanbhagat4852 3 ปีที่แล้ว

    Content is awesome but i would suggest timestamping videos which have length greater then 30 min.
    Helps a lot!

  • @luciferreficul1926
    @luciferreficul1926 3 ปีที่แล้ว

    And i like your outro.

  • @christophmosimann9244
    @christophmosimann9244 3 ปีที่แล้ว

    Great video, but how did you know that pd4ml had this specific file inclusion vulnerability without researching?

  • @erosmlima5981
    @erosmlima5981 3 ปีที่แล้ว +4

    AWS top! John

  • @RickHenderson
    @RickHenderson หลายเดือนก่อน

    What's the importance of adding the entry to your etc/hosts file near 3:30?

  • @JeremiahShaferSimulacra
    @JeremiahShaferSimulacra 2 ปีที่แล้ว

    I know NMAP is kind of the go-to for port-scanning. Have you tried Rustscan? It's built on top of NMAP but runs port scans much faster with exactly the same scan options.

    • @_JohnHammond
      @_JohnHammond  2 ปีที่แล้ว

      Yes! I have showcased rustscan in other videos and I am definitely a fan, it is a super cool tool and very fast!

  • @berndeckenfels
    @berndeckenfels 3 ปีที่แล้ว

    It triggers me if you add options after arguments, but I like it that you stick to the IPpsec method

  • @entertainment4you852
    @entertainment4you852 3 ปีที่แล้ว

    Resources you have shared with us such as TH-cam videos and blogs are enough to crack OSCP exam or should we join any institutions to gain knowledge....?

  • @Cumander1
    @Cumander1 ปีที่แล้ว

    Beginner here. And i look up to the mountains and i see John Hammond😅...and my journey begins.

  • @kgmyatthu3171
    @kgmyatthu3171 3 ปีที่แล้ว

    more of this please?

  • @umut6093
    @umut6093 3 ปีที่แล้ว

    Maaan whyyyy whyy u did not shared this 2 days ago. I had a HW project about AWS pentesting. I had got only some old staf...

  • @btno222
    @btno222 3 ปีที่แล้ว

    Hey There Seth Rogan!

  • @whtiequillBj
    @whtiequillBj 3 ปีที่แล้ว

    it was not possible to see the flickering lights in the video.

  • @adityagupta3870
    @adityagupta3870 3 ปีที่แล้ว +3

    Hey. John... Please make a course for newbies to advanced 😭😭🙏🏿🙏🏿🙏🏿please

  • @vibiemood1079
    @vibiemood1079 3 ปีที่แล้ว +1

    Ooop...the voice is little down ...!!

  • @lugasiyt899
    @lugasiyt899 3 ปีที่แล้ว

    Yo how do u Zoom In in the terminal Lol

  • @Pr4547h
    @Pr4547h 3 ปีที่แล้ว

    Audio volume little bit low compared with other videos

  • @TheHappyXD
    @TheHappyXD 3 ปีที่แล้ว

    how come he was able to use aws cli on the bucket despite using random secrets?

  • @80sixd
    @80sixd 2 ปีที่แล้ว

    i8ts areally awkward watching you pretend to not know this stuff and or have not read these exact pages. Still love the channel

  • @fbmello
    @fbmello 3 ปีที่แล้ว +1

    Man you are awesome 🤘🤘🤘......There was only one part that I didn't really understand. How did you run the .php in the S3 bucket??? because S3 only works with static webpage. It was not supposed to run .PHP 🤷‍♂️🤷‍♂️🤷‍♂️

    • @tomvandencorput1408
      @tomvandencorput1408 3 ปีที่แล้ว +2

      You can use the s3 bucket stuff to upload the script. When you then visit the script via port 80, your request will be handled by Apache which will run PHP. If you finish the machine you can see that s3.bucket.htb will be forwarded to a docker container running local stack

    • @fbmello
      @fbmello 3 ปีที่แล้ว +1

      @@tomvandencorput1408 OHHHHHHHHHH that makes sense. Thank you for the explanation.

  • @alimohammadi1148
    @alimohammadi1148 3 ปีที่แล้ว +2

    You getting more views than ippsec now 🤨

  • @blackmrx6319
    @blackmrx6319 ปีที่แล้ว

    Nice HTML LFI xD

  • @kraemrz
    @kraemrz 3 ปีที่แล้ว +1

    For yt algorithm

  • @aryanmajumder1090
    @aryanmajumder1090 3 ปีที่แล้ว

    Showing Root_id_rsa : invalid format . Why?

  • @tanishsaxena545
    @tanishsaxena545 3 ปีที่แล้ว

    Hello sir I have been watch TH-cam for awhile now i saw your using ubuntu as your primary os soo my question is why u don't use kali or parrot os or any other Linux distribution????????????

    • @takipsizad
      @takipsizad 3 ปีที่แล้ว +1

      ubuntu is for desktop which how he uses

    • @tanishsaxena545
      @tanishsaxena545 3 ปีที่แล้ว

      @@takipsizad okkay 😁👍👍

  • @0xbinHex
    @0xbinHex 3 ปีที่แล้ว

    What a handsome whitehead

  • @ajualex3503
    @ajualex3503 3 ปีที่แล้ว

    Can we hope for htb contents

  • @djcb4190
    @djcb4190 ปีที่แล้ว

    You plunder

  • @d3spis3m3
    @d3spis3m3 ปีที่แล้ว

    etc/ is pronounced etsy. not etcetera, is it not? Semantics, but, I love your content. I am aware this video is a year old.

  • @kitajskijmost
    @kitajskijmost 3 ปีที่แล้ว +3

    Где subtitles?

  • @mmelt
    @mmelt 3 ปีที่แล้ว

    Please fix the audio - it's too quiet

  • @jorides_official
    @jorides_official 3 ปีที่แล้ว

    where is the flag

  • @nogoodhacker6944
    @nogoodhacker6944 3 ปีที่แล้ว

    Hey John, Your content is awesome man, but it is not recommended for script kiddies to learn real hacking because your content requires some level of knowledge on hacking/programming, 'coz to be honest, i have been trying to understand your videos where i am now solving ctf challenges and still find it a bit confusing to understand your videos sometimes, anyways
    it's still a rich content!

  • @sefterm-zade9744
    @sefterm-zade9744 3 ปีที่แล้ว

    I said fug guysss😂😂😂😂

  • @tamilxctf4075
    @tamilxctf4075 3 ปีที่แล้ว

    Like first 10 comments; else:unsubscribe ("Mv to liveoverpellow");