ShellShock & Kernel Exploits - TryHackMe! 0day

แชร์
ฝัง
  • เผยแพร่เมื่อ 19 ธ.ค. 2024

ความคิดเห็น • 106

  • @mikeholmesdj
    @mikeholmesdj 4 ปีที่แล้ว +129

    Someone commented "Watching John makes me realize just how little i actually know about cyber-security". Thanks for giving me a reality check xDDD

  • @abisrug4898
    @abisrug4898 4 ปีที่แล้ว +69

    0day was so good in the manner he prepared the box

    • @0dayCTF
      @0dayCTF 4 ปีที่แล้ว +23

      Thank you!!

    • @abisrug4898
      @abisrug4898 4 ปีที่แล้ว +2

      @@0dayCTF ur Story is grt and u deserve respect mate

    • @ronakjoshi5093
      @ronakjoshi5093 4 ปีที่แล้ว +3

      Ryan is a fighter, he has an epic past♥️♥️ #respect

    • @anishagrawal7068
      @anishagrawal7068 4 ปีที่แล้ว +1

      @@0dayCTF was the initial encrypted RSA key really a rabbit hole?

    • @0dayCTF
      @0dayCTF 4 ปีที่แล้ว +9

      @@anishagrawal7068 Yes, that was a completely fake key. I had to do some things to distract from the real exploit!

  • @ympaquet
    @ympaquet 4 ปีที่แล้ว +29

    I've been following you for a bit now and I love those "long and boring" parts!
    Your videos gave me the spark I needed to dive into InfoSec.
    Keep it going, i'm feeling a little less dumb each time you get a video out!
    Cheers!

  • @Tekionemission
    @Tekionemission 2 ปีที่แล้ว +2

    (18:57)-SHELL shock reference
    (20:00)-Need to be an absolute path, cmd using curl
    (23:41)-Using Metasploit console
    (26:03)-Upload linpeash via meterpreter
    (31:04)-searchsploit tack m to mirror the dot c file and upload the dot c file via meterpreter

  • @adicandra9940
    @adicandra9940 11 หลายเดือนก่อน +1

    I didn't know shit about hacking, and this video give me so many insight how to do offensive hacking (metasploit, cve, the cve poc, etc). This is literally goldmine.
    I recommend this channel to any software engineer trying to make sense the "hacking world".
    I tried to watch LifeOverflow channel and most of the time, the content just went over my head because he mostly doing low level stuff.
    This channel on the other hand, hits closer to home because I use linux daily, so I already familiar with it.

  • @testu1testu294
    @testu1testu294 ปีที่แล้ว

    To sum up the things I've learned and needed to learn from this video: God bless you, John Hammond!!

  • @nizaabbie4403
    @nizaabbie4403 3 ปีที่แล้ว +1

    Thanks for sharing real way of thinking instand of just showing off the answers eventhough you had already pawnd it. Supporting to you!

  • @0__0retr0tg6
    @0__0retr0tg6 2 ปีที่แล้ว +1

    man i love your videos about ctfs, it's really inspiring and motivates me to keep going i like your dynamic of explaining the videos. and you also demystify the idea that to be a good hacker you have to be an elliot alderson
    keep going
    all the love in the world

  • @GuardianNative
    @GuardianNative ปีที่แล้ว

    Okay. I do not understand all of this YET. but this makes me excited to go deeper into it. Lol I can follow along and it actually makes sense to me 😂. Wow this is awesome. Subbed!

  • @ElliyahuRosha
    @ElliyahuRosha 4 ปีที่แล้ว +7

    Me: Satisfying yt algo.
    Also me: enjoying every minute watching JH.

  • @osincipeu6412
    @osincipeu6412 2 ปีที่แล้ว

    The reaaaal realty hack! Awesome i love it ❤️‍🔥

  • @XiSparks
    @XiSparks 4 ปีที่แล้ว +11

    There's that beautiful pea-head!

  • @stevearivera
    @stevearivera 2 ปีที่แล้ว

    Just wow, it was awesome seen this in action!

  • @mdsazzadhossainsajib1387
    @mdsazzadhossainsajib1387 2 ปีที่แล้ว

    Great job great tutorial so far i found about try hack mee series. Go ahead John

  • @pushkarnandwalkar
    @pushkarnandwalkar 3 ปีที่แล้ว +1

    solving the machine was fun but infinite scrolling which i didn't knew and I now know was damn good

  • @abhhibirdawade9657
    @abhhibirdawade9657 4 ปีที่แล้ว +4

    I really enjoy with you and ippsec. You guys are amazing. Like your voice man... See you around

  • @serpasha
    @serpasha ปีที่แล้ว

    Hi John, great job !

  • @samrudhkashyap2865
    @samrudhkashyap2865 4 ปีที่แล้ว

    good content mate!! plz keep uploading such next level crazy stuff

  • @GuardianNative
    @GuardianNative ปีที่แล้ว

    No.. I understood a lot more than I thought I would ❤❤❤

  • @danielsalloum3006
    @danielsalloum3006 3 ปีที่แล้ว

    Educational and entertaining. Excellent.

  • @gouthamj7553
    @gouthamj7553 4 ปีที่แล้ว +2

    Oh yeah legend in action 😂😊 waiting John bro ☺️

  • @HomelessDeamon
    @HomelessDeamon 4 ปีที่แล้ว

    John Hammond .... +1 You ROCK!!!!!!!!!

  • @Fybir_
    @Fybir_ 3 ปีที่แล้ว +4

    that sad moment when he forgets that "export TERM=xterm" allows him to clear screen from the shell

  • @richarddalton4305
    @richarddalton4305 4 ปีที่แล้ว +1

    0days box was fun

  • @0dayCTF
    @0dayCTF 4 ปีที่แล้ว +4

    🙏🙏🙏

    • @_JohnHammond
      @_JohnHammond  4 ปีที่แล้ว +1

      I SEE YOU BOO

    • @0dayCTF
      @0dayCTF 4 ปีที่แล้ว

      Ayeeeeee 🙏🙏

  • @koomer2237
    @koomer2237 4 ปีที่แล้ว +2

    no idea what the fuck im watching but cool i want to do things now

  • @karstenroelofs9216
    @karstenroelofs9216 3 ปีที่แล้ว +1

    19:04 who else checked their discord?

  • @mattplaygamez
    @mattplaygamez 4 ปีที่แล้ว +1

    The next room is OWASP Juice Shop. It would by fun

  • @mrroobt4968
    @mrroobt4968 2 ปีที่แล้ว +1

    thx good joooooooobbb🐯🐯🐯

  • @user-us6qm2dr9u
    @user-us6qm2dr9u 4 ปีที่แล้ว +2

    29:55?
    Green screen?

  • @UmbraAtrox_
    @UmbraAtrox_ 3 ปีที่แล้ว

    MORE! THE MOB DEMANDS MORE

  • @ronakjoshi5093
    @ronakjoshi5093 4 ปีที่แล้ว +3

    Ryan and john big fan ♥️♥️

    • @0dayCTF
      @0dayCTF 4 ปีที่แล้ว +2

  • @mehammered
    @mehammered 4 ปีที่แล้ว

    I have looked to see if you did a rust scan set up. Could you show how to set up rust scan on kali?

  • @fastshovel7036
    @fastshovel7036 3 ปีที่แล้ว +1

    you were an inspiration to me to start a yt channel in my native language for OffSec and general comluter stuff

  • @bgokj1
    @bgokj1 4 ปีที่แล้ว +1

    I Really love your energies ngl.
    Big fan here haha could you maybe give me some tips on how to get better in cyber security? A beginner here haha.
    Again big fan

    • @HowToCyber
      @HowToCyber 4 ปีที่แล้ว

      Energy really comes from passion. Did you see his reaction when he got root ? That was a priceless expression that only comes out if you are passionate about what you are doing.

  • @abdullatifnizamani6850
    @abdullatifnizamani6850 3 ปีที่แล้ว

    amazing dude

  • @causeitis
    @causeitis 3 ปีที่แล้ว

    Why not use tab completion on files and folders in your terminal?

  • @Randy-nb6fw
    @Randy-nb6fw 8 หลายเดือนก่อน

    why does he prounounce room as rum or rim but not door as dur or dir

  • @vb6code
    @vb6code 4 ปีที่แล้ว

    I'm wondering what is the music name n the end!

  • @Insomniac_Insights
    @Insomniac_Insights 4 ปีที่แล้ว +2

    Fun fact: As you know linux sometimes dosen't let you to "do clear screen command".
    Clear your terminal screen anytime using this guide.
    Guide:
    (1)Open terminal and click on 3 dots, then click on preference
    (2)Then click on 'shortcuts' and then find option named 'reset and clear' option could be 'disabled'
    (3)Click on "disabled" and enter a special key that you don't use in terminal.
    (I suggest you use this key)"i am using ''END'' key".
    And whenever you press that key it will clear terminal screen anywhere.

    • @camarada1996
      @camarada1996 4 ปีที่แล้ว +1

      doesn't 'ctrl+L' work? always use it
      edit: nvm, probably about the meterperter

    • @Insomniac_Insights
      @Insomniac_Insights 4 ปีที่แล้ว

      @@camarada1996 Yes Exactly.
      When terminal is doing something While processing previously given command, for instance "exploit" in metasploit.
      You will first have to stop running "whatever" process with Ctrl + c and then you can use "Ctrl + L or clear" command to clear your screen.
      With method which I wrote, by simply adding a shortcut In terminal you can clear the screen anytime.

  • @AcezeroGame
    @AcezeroGame 4 ปีที่แล้ว +1

    Wow there's race to be 1st or 2nd didn't know that XD

  • @sand3epyadav
    @sand3epyadav 3 ปีที่แล้ว

    Lots of fun

  • @ChrisLeftBlank
    @ChrisLeftBlank 10 หลายเดือนก่อน

    wait so what if spoofed the dhcp instead of targeting the service

  • @fahimprotik3203
    @fahimprotik3203 2 ปีที่แล้ว

    Hi ,unfortunately my nikto is not showing any shellshock vulnerability, I could only know from your video ,so then in other cases /cgi-bin/test.cgi can be vulnerable then .If I see these somewhere I should try shellshock

    • @fahimprotik3203
      @fahimprotik3203 2 ปีที่แล้ว

      I was using parrot os in there nikto doesnt show this vulnerabiltry

  • @derrenmarcusturner408
    @derrenmarcusturner408 4 ปีที่แล้ว +1

    I had no idea Seth Rogan had this side to him

  • @chandramouleeswaranv5115
    @chandramouleeswaranv5115 3 ปีที่แล้ว

    Hi John, I want to know is there a way to take priv esc without using kernel exploit on this box?

    • @jeremyklein953
      @jeremyklein953 3 ปีที่แล้ว

      There was a recent bug in the sudo binary that was recently discovered that is supposed to be ~9 years old. That would probably work

  • @pjrox9458
    @pjrox9458 4 ปีที่แล้ว +2

    anybody saw the irony that john himself couldn't find ssh2john XP.

  • @ARZ10198
    @ARZ10198 4 ปีที่แล้ว

    John will you showcase HTB battlegrounds ?

  • @ih3xo.o433
    @ih3xo.o433 4 ปีที่แล้ว

    Which os you are using ?

    • @Bryan_Kay
      @Bryan_Kay ปีที่แล้ว

      Linux Kali

  • @alexpearce3083
    @alexpearce3083 4 ปีที่แล้ว

    31:24 nice nice thats why they pay me the big backs XD

  • @krlst.5977
    @krlst.5977 4 ปีที่แล้ว

    That was cool

  • @codekibaat
    @codekibaat 4 ปีที่แล้ว

    i love you so much sir

  • @NexInfernis
    @NexInfernis 3 ปีที่แล้ว +1

    hey john while I try to upload the .c file I'm getting an error
    "4: Operation failed: 1"
    and I am using metasploit 6 . Anyone who reads it if he has the solution for this can help me It will be a great pleasure from my side. Please help me with this situation.

  • @enadalotaibi8181
    @enadalotaibi8181 4 ปีที่แล้ว +1

    I hate when already solve it without us

    • @mikeholmesdj
      @mikeholmesdj 4 ปีที่แล้ว

      I think some of the rooms take hours to solve. Couldn't really stream live for that long. Maybe John can answer this a little better.

    • @enadalotaibi8181
      @enadalotaibi8181 4 ปีที่แล้ว +1

      @@mikeholmesdj maybe, but it would be awesome if he did

    • @mikeholmesdj
      @mikeholmesdj 4 ปีที่แล้ว +1

      @@enadalotaibi8181 It would be truly awesome. I'm hoping his 1000th video is going to be something special for us all. He has done 998 at mo.

  • @rahishnamikaze1516
    @rahishnamikaze1516 4 ปีที่แล้ว

    I'm a little late but I'm here

  • @ronnieaggarwal4745
    @ronnieaggarwal4745 4 ปีที่แล้ว

    love you
    love from India...........

  • @fedelecavaliere5249
    @fedelecavaliere5249 4 ปีที่แล้ว

    What does WAAAAAAAK mean LMAO

  • @Liquidhun
    @Liquidhun 4 ปีที่แล้ว

    Spoiler alert: 32:58

  • @nikolacekov9099
    @nikolacekov9099 2 ปีที่แล้ว

    Dope

  • @psychoSherlock
    @psychoSherlock 3 ปีที่แล้ว

    ssh2john is located on /usr/share/john/ssh2john ❤️

  • @allurbase
    @allurbase 4 ปีที่แล้ว

    Dud, try Turtles? as the password? maybe??

  • @jackcarter1897
    @jackcarter1897 4 ปีที่แล้ว

    I’m getting the ‘cc1’ error message you said you got before filming. Shame you wasn’t able to quickly show what you did to solve it. Made this challenge far too frustrating. I tried to watch your video as less as possible and do it on my own. I thought I was doing something wrong and you ended up using the same exact file as I did, so I knew I didn’t make a mistake. Clearly a bug. Just annoying :(

  • @ivanvalentini9345
    @ivanvalentini9345 4 ปีที่แล้ว

    ssh2john, just like other john scripts is located at /usr/share/john/ssh2john.py

  • @cuttlefishn.w.2705
    @cuttlefishn.w.2705 2 ปีที่แล้ว

    In spirit, metasploit is as much cheating as using google. If anything should be considered cheating or cheap, shouldn't it be linpeas? Because you should already know where to check for privesc vectors, whereas expecting you to know every exploit in every language is ridiculous.

  • @morganpg
    @morganpg 4 ปีที่แล้ว

    hi

  • @ca7986
    @ca7986 4 ปีที่แล้ว

    ❤️

  • @alexpearce3083
    @alexpearce3083 4 ปีที่แล้ว

    car . secret ahhahaaha

  • @whowins34
    @whowins34 4 ปีที่แล้ว

    Hello,
    my fifa21 Account got a transfermarket ban. Could you remove it with nmap or could you show me how i could remove it.
    Greetings from Germany

  • @all_c1ear
    @all_c1ear 4 ปีที่แล้ว

    msf5 1337

  • @4ag2
    @4ag2 4 ปีที่แล้ว +2

    1st 😎😁

  • @Daniel-so9rg
    @Daniel-so9rg 4 ปีที่แล้ว +1

    6th

  • @silamoolan5228
    @silamoolan5228 4 ปีที่แล้ว +2

    2st

  • @DarkSide3211
    @DarkSide3211 4 ปีที่แล้ว +1

    Im a 12th grade programming student and seeing this kinda overwhelms me lol

    • @Dpoint0
      @Dpoint0 4 ปีที่แล้ว

      dont worry broda he is on a very different level, just chill and learn slowly

    • @jeremyklein953
      @jeremyklein953 3 ปีที่แล้ว

      Sadly this has nearly nothing to do with programming. Just pen testing.

  • @rajith8973
    @rajith8973 4 ปีที่แล้ว

    0th

  • @JNET_Reloaded
    @JNET_Reloaded 4 ปีที่แล้ว

    USE TAB FFS typing filenames in full is anoying asf, type some of it then hit tab!!!! easy!!!!

    • @jclongy7886
      @jclongy7886 4 ปีที่แล้ว

      Doesn't always work in your shell. You can see that he tried that a few times and had to go back and type the full file name. I do agree with your sentiment though. You get used to the autocomplete.