All-Army Cyberstakes! Ysoserial EXPLOIT - Java Deserialization

แชร์
ฝัง
  • เผยแพร่เมื่อ 8 ม.ค. 2025

ความคิดเห็น • 77

  • @novicetrader555
    @novicetrader555 4 ปีที่แล้ว +32

    One of the best channels on cybersec who actually teaches and explains some great stuff not just teaching how to run scripts like most other youtubers do..John is the one who motivated me to get into this field.Lets do our share and help him grow his channel.Thanks john for all the great content.Lots of love and respect man🙏

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว +2

      Thank you so much! I really appreciate all the kind words! I feel like some of explanations are a bit hit-or-miss, looking back they look like a big fail in some videos bahaha. Thanks so much for watching!

    • @DangerousPictures
      @DangerousPictures 3 ปีที่แล้ว

      @@_JohnHammond whats makes you so much better is showing the fails (expecially in the malware analysis Videos.)
      Other TH-camrs would wrap it up like
      Here is the sample, I unscrambled it to get stage 2, which downloads *insert RAT here*.
      Remember to like and subscribe and sub to my Patreon

  • @razzawazza
    @razzawazza 4 ปีที่แล้ว +4

    I hope to fully understand what you're doing in these videos one day- really cool stuff. Thanks for sharing.

  • @KhaosShield
    @KhaosShield 4 ปีที่แล้ว +2

    John I took part in ACI CTF and managed to rack up around a mere 1800 pts, Love your videos and everything always seem to easy to you (Just a representation of your hard work no doubt). Keep up the amazing work.

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว +4

      Hey that is still awesome! As long as you are playing and trying to learn, that is all that counts! Keep in mind I still struggle with these for hours, and the actual "writeup" or solution I showcase is often just me highlighting the things that work ahaha. So a 10 minute video could be really 2 hours of troubleshooting and debugging beforehand. :) Thank you so much for watching!

  • @checknate8820
    @checknate8820 4 ปีที่แล้ว +16

    Just discovered your channel this week, your content is amazing.I wish I would have discovered it earlier.

    • @XxLIVExX24
      @XxLIVExX24 4 ปีที่แล้ว

      This is literally me as well! I found him out this week tuned in to 3 vids in a row. Wish I knew of his channel before I graduated tho, I would be way sharper, by now.

    • @Ayahalom123
      @Ayahalom123 4 ปีที่แล้ว +1

      Same here, found out about this channel 3 weeks ago. Coolest stuff I've seen in a long time.

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว +2

      Very happy to hear that! Thank you so much!

    • @checknate8820
      @checknate8820 4 ปีที่แล้ว

      @@Ayahalom123 מה נשמה, אתה מארץ ישראל?

    • @checknate8820
      @checknate8820 4 ปีที่แล้ว

      @@XxLIVExX24 Lucky for me I'm not in school so his videos are my classes for pentesting.

  • @0xclayhax848
    @0xclayhax848 3 ปีที่แล้ว

    Thanks for this vid. Was just learning about insecure deserialization attacks and using ysoserial. Your video was the first video result in google.

  • @iulianichim7777
    @iulianichim7777 4 ปีที่แล้ว +2

    Just awesome content! Learning a lot from you. Thank you and keep it up!

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      Very happy to hear that! Thanks so much for watching!

  • @CybrJames
    @CybrJames 4 ปีที่แล้ว

    Video was awesome as always. Great job.

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      Thank you so much! I'll keep them coming!

  • @mariopetkovic915
    @mariopetkovic915 4 ปีที่แล้ว +1

    WE LOVE THE DAILY UPLOADS, DONT STOP

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      THANK YOU! I am set for the month of May, but need to do a bit more recording to keep getting more in the backlog! Thanks so much for watching!

  • @algerienizer
    @algerienizer 3 ปีที่แล้ว

    hey john this video didn't suck, please keep doing them

  • @padaloni
    @padaloni 4 ปีที่แล้ว

    Really good video, dude. Nice and easy to follow.

  • @linobossio6638
    @linobossio6638 3 ปีที่แล้ว

    thank you very much, you are the sun that monetizes the glow

  • @laststar7716
    @laststar7716 4 ปีที่แล้ว +1

    Thanks a lot for explaining this one! Much help :-)

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      Thanks so much for watching!

  • @realkiddshady
    @realkiddshady 4 ปีที่แล้ว

    Another great video. Thank you!

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      Thank you so much! And thanks for watching!

  • @bigbooduh
    @bigbooduh ปีที่แล้ว

    Loved this, will give this a try

  • @mi2has
    @mi2has 4 ปีที่แล้ว +2

    finally one on JAVA :-), Good one JOhn, btw i have joined your discord community ,it is great

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      Happy to hear that! Thank you so much for joining the party -- and thanks for watching!

  • @robertadamplant
    @robertadamplant 4 ปีที่แล้ว

    I admire your skill set.

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      Ah thank you! And thanks for watching!

  • @omeraljoboury6157
    @omeraljoboury6157 4 ปีที่แล้ว

    Nice videos i am leaning new skilles watching youe videos and i like them, continue.

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      Very happy to hear that! Thanks so much for watching!

  • @pythondoesstuff2969
    @pythondoesstuff2969 4 ปีที่แล้ว +1

    Please also explain how the exploit works after using it. It helps a lot. Pleaasseeeeeeee!

  • @ankitkumarjat9886
    @ankitkumarjat9886 4 ปีที่แล้ว +1

    Hey John tell us about your host os ( I know it is ubantu but but I want to know about how you customized that and what tools you use mostly)
    Please make a video.

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว +1

      A lot have been asking for that lately, I can certainly try and do that soon!

  • @sko_
    @sko_ 4 ปีที่แล้ว

    This one is much needed :)

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      Happy to hear that! Thanks so much for watching!

  • @berndeckenfels
    @berndeckenfels 3 ปีที่แล้ว

    Is there any writeup/video on the CTF(?) where you used ysoserial with RMI?

    • @_JohnHammond
      @_JohnHammond  3 ปีที่แล้ว +1

      I believe I have one with the All Army Cyberstakes, "Y So Serious" or something like that. There is a picture of Joker in the thumbnail :)

  • @AdamTheGuitarist
    @AdamTheGuitarist 4 ปีที่แล้ว +1

    so the hardest thing here was downloading whysoserial am I right?

  • @tamilxctf4075
    @tamilxctf4075 4 ปีที่แล้ว

    Y fearless music at the end..try hall of frame musiq

  • @MrPaddy35
    @MrPaddy35 4 ปีที่แล้ว

    can someone tell me why we using cat payload and then piping it to netcat , does cat payload suppose to do something ?

    • @padaloni
      @padaloni 4 ปีที่แล้ว

      it might work if you used < to redirect the file into the command, but piping seems to work fine. it's like a way to avoid typing the payload manually. apologies if I've misunderstood your question.

  • @lordtony8276
    @lordtony8276 4 ปีที่แล้ว

    Do you know of any tools to do this kind of thing if the backend server is running python with a pickle deserilization vulnerability? I wrote my own script called "evilPickle.py" to generate payloads like this but it is barely functional at the best of times.

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว +1

      Hmmm, there might be one out there but I do not know off the top of my head. That would be a very cool and certainly a fun project to build! Thanks so much for watching!

  • @oliviadrinkwine1411
    @oliviadrinkwine1411 4 ปีที่แล้ว

    I love the reference for why so serial?

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      Hahaha. Mixing in the Joker makes it fun! Thanks so much for watching!

  • @Laflamablanca969
    @Laflamablanca969 4 ปีที่แล้ว +1

    Who the hell keeps putting 1 dislike on your videos!?!?

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว +1

      Bahahah I've seen it for years and have never been able to track them down! I'm glad someone else sees it too!
      Thanks for watching!

  • @prafulaga
    @prafulaga 3 ปีที่แล้ว

    Nice one..

  • @aidencrilley730
    @aidencrilley730 4 ปีที่แล้ว

    Hey John how are you running LInux? I'm trying to run an Ubuntu VM on mac in virtual box and it's super laggy. I may go and pay for a subscription to parallels desktop

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว +1

      I run Ubuntu as my daily driver, it is installed as the host OS on my laptop. Whenever I can avoid VMs I try to ahaha. Thanks so much for watching!

    • @aidencrilley730
      @aidencrilley730 4 ปีที่แล้ว

      @@_JohnHammond Thanks for the reply! I love your content and I've learned quite a bit from your videos. At the moment, I'm in college as a computer science major and I'm looking to work in the cybersecurity field once I graduate. For now, I'm running Ubuntu in a vm because it makes the most sense for my situation. Maybe one day it will be my host OS!

  • @JuanBotes
    @JuanBotes 3 ปีที่แล้ว

    thanks

  • @kneesnap1041
    @kneesnap1041 4 ปีที่แล้ว

    Mmm I was just reading into ysoserial just the other day.

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      It's a super cool tool! Thanks so much for watching!

  • @vadhub
    @vadhub 4 ปีที่แล้ว +3

    did anyone see the 493 MB/s when he did wget damn

    • @nickrameau938
      @nickrameau938 4 ปีที่แล้ว

      I don't know where you saw that but to me, it seemed like it was between 4 and 6 MB/s

  • @madaniyousfiabdelwahed8553
    @madaniyousfiabdelwahed8553 4 ปีที่แล้ว

    Great

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      Thanks so much for watching!

  • @neilthomas5026
    @neilthomas5026 4 ปีที่แล้ว

    Didn't get a lot of what was happening tbh!! This one seems a bit more advanced than the other ones 😅😅😅

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว +1

      Yeeeah this one was tough, it didn't have as many solves. Thanks so much for watching!

  • @aakashgautam3851
    @aakashgautam3851 4 ปีที่แล้ว

    Hey John 🙂 nice video... I'm wondering about how can we train an AI to make more efficient payloads or maybe to find vulnerabilities.

  • @brendancurran9894
    @brendancurran9894 4 ปีที่แล้ว

    Could you do a video writeup for 'No Escape'? I got stuck on that one and really want to know how to complete it.

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว +1

      I have that one solved, I can certainly release a video for that one this week! Thanks so much for watching!

  • @eman3144
    @eman3144 4 ปีที่แล้ว

    Comment for the algo god

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      You're the man! (The "e" Man!) Thank you so much, and thank you for watching!

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 ปีที่แล้ว

    Git comments,canry 1 number work headel

  • @tomasgorda
    @tomasgorda 4 ปีที่แล้ว

    nice video again. It's not necessary to be so fast :)

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      Shoot, I always gotta work on that, slowing down a bit. :) Thanks so much for watching!

  • @beeeatantcheng6861
    @beeeatantcheng6861 4 ปีที่แล้ว

    Hi John Hammond! Can you cover Tryhackme Gamezone room without the use of burpsuite? I would love to see that!

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว

      Ooooh I have not seen that one yet -- I will have to take a look and see if I can get that one out for you! Thanks so much for watching!

  • @danielhemmati
    @danielhemmati 4 ปีที่แล้ว

    i just struggle with java 😂😂
    trying to solve one room in tryahackme and this video really help me
    thanks 🤗🤗

  • @tekken-pakistan2718
    @tekken-pakistan2718 4 ปีที่แล้ว

    Thanks this was helpful! Regarding the ping command not working initially, maybe it required to be encapsulated in double quotes? If we go with that, not sure why the other version worked xD
    Anyways, thanks!