TryHackMe! Overpass - Authentication Bypass

แชร์
ฝัง
  • เผยแพร่เมื่อ 17 ต.ค. 2024

ความคิดเห็น • 120

  • @bhnjhbjhbkgkkvhnhmbm
    @bhnjhbjhbkgkkvhnhmbm 4 ปีที่แล้ว +185

    I watched so much John Hammond that my son was born a ginger, true story.

    • @ashmitadhikari891
      @ashmitadhikari891 4 ปีที่แล้ว +5

      damn😂

    • @goblinninja1234
      @goblinninja1234 4 ปีที่แล้ว +1

      STOP LYING IK U R

    • @avananana
      @avananana 3 ปีที่แล้ว +2

      Whether or not that's true, that's funny.

    • @Huskai666
      @Huskai666 3 ปีที่แล้ว +5

      Umm who’s gonna tell him

    • @hishamhaneefa7753
      @hishamhaneefa7753 3 ปีที่แล้ว

      maaan! dont make me sick😂

  • @andycascade
    @andycascade 4 ปีที่แล้ว +137

    It would be interesting to see your TryHackMe streams without preparations, just cracking tasks in real time with chat. BTW, I like your CTF streams.

  • @KapuzenSohn
    @KapuzenSohn 4 ปีที่แล้ว +61

    For Cookies:
    You can press F12 and then go to the "Application" tab and then in the left is another menu where you can access the Cookies and add / edit / delete them, no need for a chrome plugin :)

  • @zuk0273
    @zuk0273 4 ปีที่แล้ว +56

    John hammond is that guy with whom you can hangout and discuss all the geeky stuffs and still look damn cool. Awesome John

  • @0xGreed
    @0xGreed 4 ปีที่แล้ว +13

    I just finished that room, I can’t wait to see how you approched this one !

  • @oai9106
    @oai9106 4 ปีที่แล้ว +7

    He's such a kind respectful man, thank you very much for the walkthrough,Cheers

  • @satyamvirat3489
    @satyamvirat3489 4 ปีที่แล้ว +2

    I have been studying for the linux and it's tool since a month or over and ur video was the first video of a practical hand season for me.
    Thanks Man!
    Looking forward to more of ur such videos so that I can keep learning.

  • @strappedwithkrylon
    @strappedwithkrylon 4 ปีที่แล้ว +31

    I wonder if I'm the only one watching who doesn't have a clue what you're doing, I mean outside of the fairly obvious conceptual aspect of it. Still fun and interesting to watch despite the fact that I lack the technical knowledge that goes behind it.

  • @QQ-nd1gn
    @QQ-nd1gn 3 ปีที่แล้ว +1

    That privesc segment was absolutely splendid and educational, thank you so much John

  • @neffisback9729
    @neffisback9729 4 ปีที่แล้ว +2

    For anyone else having problems (or simply having no clue what to do) with setting up the http.server with python. It is possible you got several different python versions installed and the standard "python" command uses a version before the (i think python3...) module was implemented.
    Just check which versions you got installed with: ls -ls /usr/bin/python*
    If you got python 3.8 or 3.9 installed just use John's command including the python version: sudo python3.9 -m http.server 80
    That worked for me :)

  • @mathiasdesouza
    @mathiasdesouza 3 ปีที่แล้ว +1

    Great video John!!! It's always a class watching your approach, thanks for spreading knowledge.

  • @champagnepete3386
    @champagnepete3386 2 ปีที่แล้ว +1

    Great work, love how you walk us through it

  • @nhantran0
    @nhantran0 4 ปีที่แล้ว +3

    I didn't know about TryHackMe until TH-cam sends me a notification of this video which belongs to a channel I didn't subscribed to. The website immediately catches my attention. Fascinating how youtube recommendation system works. Thanks for making this video.

    • @djvincon
      @djvincon 4 ปีที่แล้ว

      100% same happened to me

  • @dropcake
    @dropcake 3 ปีที่แล้ว

    Damn, that's a cool box. I've got to try this and Overpass2 now. Thanks for your great video John!

  • @waldir3442
    @waldir3442 4 ปีที่แล้ว +2

    Hello John. A hug from Brazil. Your CTF videos are sensational. Explore more content in this theme. See you later!

  • @HundleBundle47
    @HundleBundle47 4 ปีที่แล้ว +2

    @John Hammond do you have a video where you discuss how you get set up to tackle these boxes? i.e. connecting to a VPN, setting up any proxies, spinning up a VM, etc? If not would you be able to give a brief overview here or create a video for that? Would love to see your process for getting setup

  • @descentintozachstrom
    @descentintozachstrom 3 ปีที่แล้ว

    Yo John! Sorry if you’ve answered this before. Are you running Ubuntu on a VM, or bare metal?

  • @bruh_5555
    @bruh_5555 4 ปีที่แล้ว

    Hello John is there any reason you use chrome and not Firefox, or it's just personal preference?? Love your videos!!!

  • @Tekionemission
    @Tekionemission 2 ปีที่แล้ว

    (20:41) - Using John to crack ssh key passhrase, NICE!

  • @imranmahmood493
    @imranmahmood493 9 วันที่ผ่านมา

    I am currently studying json exam quite in depth

  • @moebob24
    @moebob24 3 ปีที่แล้ว +16

    *almost types "/home/tryjackme"
    John: Woah! Careful there John
    I died!!!!!!

    • @DG-ej5nz
      @DG-ej5nz 2 ปีที่แล้ว

      Haha same here!

  • @peterharris7229
    @peterharris7229 3 ปีที่แล้ว

    Hey John, I started watching your videos yesterday and am really enjoying them. Just wanted to let you know that this video is not in your TryHackMe! playlist.

    • @_JohnHammond
      @_JohnHammond  3 ปีที่แล้ว

      Thanks for the heads up! Just added it in. :) Thanks again!

  • @MrDeatmatch
    @MrDeatmatch 4 ปีที่แล้ว

    Just out of curiosity, how long does it take to actually solve these boxes?

  • @8.O.8.
    @8.O.8. ปีที่แล้ว

    i decided that instead of plowing through the beginner materials in tryhack me and joining rooms that i can mostly not ssh into and getting frustrated over, i went straight into practice section and i'm so glad i did. i found this guide and i learned infinite and your passion and enjoyment really showed through this vid. i had a few laughs here and there, thank you!!!

  • @alph4byt3
    @alph4byt3 4 ปีที่แล้ว

    Ever considered ffuf? or is Gobuster just your go to preference?

  • @pipe4188
    @pipe4188 ปีที่แล้ว

    Hey just a question ! ,
    how did you know that the output of cat .overpass is a rot47 algorithm (at 22:37).
    Love your videos btw

    • @chaoskong2987
      @chaoskong2987 ปีที่แล้ว

      You find it out through by looking through the source code of overpass itself.

  • @felipesnet
    @felipesnet 4 ปีที่แล้ว

    when you VPN into the challenge box does that not mean all your network traffic from your local computer is going through that box?

  • @bruh_5555
    @bruh_5555 4 ปีที่แล้ว

    Hacking aside, John also makes a good suspense actor

  • @abdullatifnizamani6850
    @abdullatifnizamani6850 3 ปีที่แล้ว

    it was crazy how did you found flaw in log.js , i had no idea about it,, amazing

  • @gopalpatel2501
    @gopalpatel2501 4 ปีที่แล้ว +1

    Love from india @John Hammond
    We love your thm content..and also do more on hackthebox...

  • @mattsmelser
    @mattsmelser 4 ปีที่แล้ว +1

    Great video! Thanks for doing this!
    Do you have a link for the documentation of what the -p flag does with /bin/bash? I'm having trouble finding it on the man page.

    • @somebodystealsmyname
      @somebodystealsmyname 4 ปีที่แล้ว +1

      tl;dr: -p will tell bash not to drop privileges.
      ---
      Invocation
      [...]
      The following paragraphs describe how bash executes its startup files. If any of the files exist but cannot be read, bash reports an error. Tildes are expanded in file names as described below under Tilde Expansion in the EXPANSION section.
      [...]
      If the shell is started with the effective user (group) id not equal to the real user (group) id, and the -p option is not supplied, no startup files are read, shell functions are not inherited from the environment, the SHELLOPTS, BASHOPTS, CDPATH, and GLOBIGNORE variables, if they appear in the environment, are ignored, and the effective user id is set to the real user id. If the -p option is supplied at invocation, the startup behavior is the same, but the effective user id is not reset.
      ---
      linux.die.net/man/1/bash

  • @vijaykishorea3987
    @vijaykishorea3987 3 ปีที่แล้ว

    What are the pre-requisites to have known before solving this room?

  • @BlkManMountaineer
    @BlkManMountaineer 3 ปีที่แล้ว +1

    i get lost when you say convert the format to something that john can read.. so are you just changing it to a txt format?? are you copying the info then putting it into txt?

  • @mranonymous9355
    @mranonymous9355 2 ปีที่แล้ว

    Great video but HOW do I get linpeas onto the victim side WITHOUT your automated script/tool?

  • @aakashadhikari3752
    @aakashadhikari3752 3 ปีที่แล้ว

    obviously man ..this vid deserves a like :3

  • @ahmedtlili3006
    @ahmedtlili3006 4 ปีที่แล้ว

    Glad yr back again in it keep it up

  • @zacktzeng8569
    @zacktzeng8569 2 ปีที่แล้ว

    Awesome video John!! Thanks for sharing! Quick question, why do you run tee with nikto scan and not gobuster?

  • @vishal_ravanank
    @vishal_ravanank 4 ปีที่แล้ว

    I eagerly wait for your TryHackMe ctf videos. Please upload more. ❤️ Love to watch your videos and learn from you. Thank you 🙏

  • @cbug6581
    @cbug6581 4 ปีที่แล้ว

    thank you, John, I have always enjoyed watching your videos please make more.

  • @Klausi-uq4xq
    @Klausi-uq4xq 4 ปีที่แล้ว

    Great Job! Greets from Germany

  • @Pharm8alin
    @Pharm8alin 4 ปีที่แล้ว

    Well done !

  • @monicah3788
    @monicah3788 ปีที่แล้ว +1

    why do most of the "hackers on youtube" waste so much time trying to appear spontaneous when we all know that you prepare a lot in advance and besides that you also edit the material?
    Instead of wasting your neurons trying to appear smarter than you are, you'd better concentrate on transmitting as well as possible.
    The fact that you press Alt+f4 many times does not make you smarter.

  • @HabibsWorld96
    @HabibsWorld96 3 ปีที่แล้ว

    As a newbie, it's tough to understand for me, looks interesting

  • @Noremo83
    @Noremo83 3 ปีที่แล้ว +1

    Just a Question. What does "-p" in /bin/bash -p

  • @MrLEODUDE
    @MrLEODUDE 4 ปีที่แล้ว

    Love me some John "2 videos in 2 days" Hammond. Great Content!

  • @chittodihoc
    @chittodihoc 4 ปีที่แล้ว +1

    yeah yeah, keep making video, i just have completed the introduction room after watch your video.

  • @Nano-oi7yb
    @Nano-oi7yb 4 ปีที่แล้ว

    Good job

  • @BachPhotography
    @BachPhotography 4 ปีที่แล้ว

    Very interesting video, I learned a lot, cool way to get root privileges at the end, thanks for sharing!

  • @tranquility6358
    @tranquility6358 4 ปีที่แล้ว

    All the stars aligned, root cron that executes a shell script from an external source and a writeable /etc/hosts... Damn...

  • @eventhorizon8014
    @eventhorizon8014 4 ปีที่แล้ว +1

    Very enjoyable to watch :)

  • @sachalraja1054
    @sachalraja1054 ปีที่แล้ว

    waiting for john to write something in the readme file👀

  • @mortalstang6294
    @mortalstang6294 4 ปีที่แล้ว

    Could you share your "upload_files_nc.sh" and "upload_files_wget.sh" on your github? thanks!

  • @toinhnguyen7402
    @toinhnguyen7402 3 ปีที่แล้ว

    can anyone help me , what the tag -p of /bin/bash means ?

  • @Pasan34
    @Pasan34 4 ปีที่แล้ว

    I like your singing.

  • @jerfp8026
    @jerfp8026 ปีที่แล้ว

    Thanks!

  • @logiciananimal
    @logiciananimal 3 ปีที่แล้ว +1

    Admittedly it is a CTF, but I do find the cascading failures a bit weird - I mean, I wonder if it would be possible to make a slightly more "realistic" example that doesn't rely on /etc/hosts being modifiable? the fact the .thm site was original hosted on localhost suggests there might be something else ...

  • @mjtonyfire
    @mjtonyfire 3 ปีที่แล้ว

    This excites me

  • @Now2Sense
    @Now2Sense ปีที่แล้ว

    Grande

  • @0xnightfury
    @0xnightfury 10 หลายเดือนก่อน

    This is definatly not a easy box catogory

  • @presequel
    @presequel ปีที่แล้ว

    pfff im just starting but if this is easy than it will be a steep, very steep learning curve ... maybe this is easy for an expert, but I doubt if this is easy for a beginner..... but thanx for the vid, this will help a lot!

  • @controlaltdeleteninjas
    @controlaltdeleteninjas 3 ปีที่แล้ว

    Hi John, Great Videos Any chance you could walk us through setting up Cloudflare's Flan Scan?

  • @Luftbubblan
    @Luftbubblan 4 ปีที่แล้ว

    Ty

  • @q-bert558
    @q-bert558 3 ปีที่แล้ว

    Nice!

  • @ProjectSage
    @ProjectSage 4 ปีที่แล้ว

    Thast awesome brother ^^

  • @cooliceman0001
    @cooliceman0001 3 ปีที่แล้ว

    So cool

  • @nya0783
    @nya0783 4 ปีที่แล้ว

    Love from your discord server @John Hammond

  • @furkancosgun3943
    @furkancosgun3943 3 ปีที่แล้ว +1

    Güzel içerik

  • @peterarbeitsloser7819
    @peterarbeitsloser7819 4 ปีที่แล้ว

    Great video again. But could you use pwncat next time?

  • @CyberxploitHausa
    @CyberxploitHausa 2 ปีที่แล้ว

    Great

  • @theuniverse9456
    @theuniverse9456 4 ปีที่แล้ว

    Wow! That was cool😎!!

  • @0xb15h4l
    @0xb15h4l 3 ปีที่แล้ว

    this box was awesome..

  • @rashpt
    @rashpt 4 ปีที่แล้ว

    what was that system password for? Found any use for it?

  • @shubham_srt
    @shubham_srt 4 ปีที่แล้ว +1

    which terminal is that?

    • @ruslank-1
      @ruslank-1 3 ปีที่แล้ว

      Terminator

  • @opiniondiscarded6650
    @opiniondiscarded6650 3 ปีที่แล้ว

    That's brilliant, but I like this

  • @nareshg7292
    @nareshg7292 4 ปีที่แล้ว

    please tell me what terminal multiplexer you use

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว +1

      I am using Terminator. I love it!

    • @nareshg7292
      @nareshg7292 4 ปีที่แล้ว

      @@_JohnHammond thank you very much ... You've been my inspiration and effective immediately i will start using terminator

  • @ca7986
    @ca7986 4 ปีที่แล้ว

    ❤️

  • @surferbum618
    @surferbum618 4 ปีที่แล้ว

    Nice

  • @ajaykumark107
    @ajaykumark107 4 ปีที่แล้ว +1

    Whats the use of /bin/bash -p ??

    • @logicNreason2008
      @logicNreason2008 4 ปีที่แล้ว

      The -p option ensures that the effective user id is not reset.

  • @xguidosan
    @xguidosan 4 ปีที่แล้ว

    NICE ED SHEERAN

  • @goforit367
    @goforit367 4 ปีที่แล้ว

    Hi John I really do like your vids . Could you pls slow down a bit...You do things too quick for us the newbies... :)

  • @Ms.Robot.
    @Ms.Robot. 4 ปีที่แล้ว

    Nice. Ohhh💗

  • @geekbunny5844
    @geekbunny5844 4 ปีที่แล้ว

    tryjackme lol.
    careful john

  • @123gostly
    @123gostly 4 ปีที่แล้ว

    Doing the yt algorithm thing

  • @NexInfernis
    @NexInfernis 3 ปีที่แล้ว

    when i'm running python -m http.server command why it is coming command not found
    sudo pyhton3 -m http.server 80
    sudo: pyhton3: command not found

  • @space8028
    @space8028 4 ปีที่แล้ว

    8:00 is it python or js ?

  • @JohnDoe-by1xg
    @JohnDoe-by1xg 4 ปีที่แล้ว

    That -p would have helped me if i saw it yestersay for overpass 2...anyways alrdy done😅

  • @faiqzafran4383
    @faiqzafran4383 4 ปีที่แล้ว

    When did ed sheeran starts writing codes

  • @enessimsek4624
    @enessimsek4624 ปีที่แล้ว

    it was medium room

  • @shuvambarui7158
    @shuvambarui7158 4 ปีที่แล้ว

    33:45 tryhackme on the way to sue you for defamation

  • @LinuxJedi
    @LinuxJedi 3 ปีที่แล้ว

    TRY JACKME LMFAO

  • @hudson8207
    @hudson8207 4 ปีที่แล้ว

    This would be better if you didn't practice this before you did it

  • @Hackedpw
    @Hackedpw 4 ปีที่แล้ว

    K

  • @vcaalnu34
    @vcaalnu34 4 ปีที่แล้ว

    This looks like a clone of hackthebox.eu

  • @fordorth
    @fordorth 3 ปีที่แล้ว

    I keep trying to subscribe but the only option I get is unsubscribe I can't figure it out... maybe next time. =)

  • @anuradhalakruwan1918
    @anuradhalakruwan1918 4 ปีที่แล้ว

    John Hammond sar windows 10 OS use ethical hac**king course. Please🌹🌹🌹🌹🌹🌹🌹🌹🌹🌹

  • @asnibzayd7500
    @asnibzayd7500 4 ปีที่แล้ว

    #sudo apt hack 'John Hammond'
    #password:
    #access denied

  • @mecho771
    @mecho771 ปีที่แล้ว

    I like to do the follow along but when I enter the command " subl " on tryhackme it says command not found.

  • @icaronunes
    @icaronunes 2 ปีที่แล้ว

  • @danyrogers4220
    @danyrogers4220 4 ปีที่แล้ว

    nice