HackTheBox - Seventeen

แชร์
ฝัง
  • เผยแพร่เมื่อ 18 ธ.ค. 2024

ความคิดเห็น • 34

  • @kavishkagihan9495
    @kavishkagihan9495 2 ปีที่แล้ว +36

    The reason your reverse shell didn't work is because, if you look at the index.js, it is calling the log() function from the logger module, since the malicious logger module you made doesn't have such a function to be used, it crashes. Yet the command gets executes. Thats why you get a connection back to your netcat but doesn't respond to the commands. So to get a direct reverse shell, you would have to add a function called log() for to stop it from crashing.

    • @obscurus4103
      @obscurus4103 2 ปีที่แล้ว +1

      thanks

    • @securiti
      @securiti 2 ปีที่แล้ว +3

      That's correct.
      I spend hours on the reverse shell - didn't notice the "logger.log is not a function" error message.
      Great machine, kavi!

    • @oscargarin1740
      @oscargarin1740 2 ปีที่แล้ว +2

      You are the box creator. Static webpage links to a medium acc & github acc both of which have same username as you!

    • @kavishkagihan9495
      @kavishkagihan9495 2 ปีที่แล้ว +1

      @@oscargarin1740 exactly

    • @kavishkagihan9495
      @kavishkagihan9495 2 ปีที่แล้ว +1

      @@securiti Thanks man!

  • @saketsrv9068
    @saketsrv9068 2 ปีที่แล้ว +2

    Thanks for the consistency. Box quality could have been better,just old school things

  • @fer.guitar
    @fer.guitar 2 ปีที่แล้ว +1

    Amazing vid!

  • @mohamedgamal1163
    @mohamedgamal1163 2 ปีที่แล้ว +3

    thanks man

  • @harshitanamiwal8962
    @harshitanamiwal8962 2 ปีที่แล้ว

    OMG 🔥🔥🔥🔥

  • @lool7922
    @lool7922 2 ปีที่แล้ว +1

    awesome

  • @0xA98Net
    @0xA98Net 2 ปีที่แล้ว +2

    Nicee

  • @y.vinitsky6452
    @y.vinitsky6452 2 ปีที่แล้ว

    32:53 why not just use a GUID for the file name?

  • @madcane13
    @madcane13 2 ปีที่แล้ว +1

    what is shortcut key to be like this?
    ssh>

    • @ippsec
      @ippsec  2 ปีที่แล้ว +1

      www.sans.org/blog/using-the-ssh-konami-code-ssh-control-sequences/

  • @kavishkagihan9495
    @kavishkagihan9495 2 ปีที่แล้ว +1

    Always save files in a database!

    • @SakayaNagii
      @SakayaNagii ปีที่แล้ว +1

      Hey Man! Great Box. I appreciate your work. Can you tell more about your yourself. How you started and the journey.

  • @-bubby9633
    @-bubby9633 ปีที่แล้ว

    Just wondering but could it be possible to upload to escape the /files/ directory completely by doing "../" as the "stud_no"?

  • @Toniantonioo
    @Toniantonioo 2 ปีที่แล้ว

    THANK YOU A LOT

  • @user-ph1sh5qq4u
    @user-ph1sh5qq4u 2 ปีที่แล้ว +5

    that .htaccess trick is crazy shit

  • @adrianjimenezcarrion6692
    @adrianjimenezcarrion6692 2 ปีที่แล้ว

    realy useful

  • @boogieman97
    @boogieman97 2 ปีที่แล้ว +3

    Oh boy. I watch your videos every week, they're so well explained and touching the real core of the technique used. One remark is that I often see that you're making unnecessary mistakes, e.g. not copying the complete hash and later bump into a silly issue. Would really like to see that you take a bit more time to validate everything you did and not make those silly mistakes. You're still human after all, but a bit annoying to see these mistakes and have to skip forward in the video.

    • @wisdomovermoney3394
      @wisdomovermoney3394 2 ปีที่แล้ว

      Caught that mistake too while copying the hash, missing one char 😂

    • @WhatsSmackin
      @WhatsSmackin 2 ปีที่แล้ว +2

      He’s making “unnecessary mistakes” because he is actively thinking and working during the videos. If he scripted out every correct command and every perfect methodology the videos would lose so much value because you would lose getting to view his thought process. People make mistakes, and then have to back track sometimes. I caught the hash copy paste too, and I laughed. Curious if it would cause him problems and how he would catch it in his process. You’d probably get more value from the videos trying to learn how to work through mistakes than being frustrated and skipping the video. Anyone can point out mistakes when watching someone else do the work.

    • @boogieman97
      @boogieman97 2 ปีที่แล้ว +1

      @@WhatsSmackin these videos are totally not edited right? Me personally don't like to watch someone missing a character of a hash and later on struggling on an issue. I watch these videos to understand the technique and core essence of the box, not to see someone debugging.

    • @stefan.b7812
      @stefan.b7812 2 ปีที่แล้ว

      @@boogieman97 If you read comments on other videos, you will find out people like his debugging thing.
      That is why he does not remove those debugging parts.

    • @boogieman97
      @boogieman97 2 ปีที่แล้ว

      @Stefan .b haha oh man, I watch ippsec' videos already for a long long time. There is a big difference in debugging something that is actually explaining something uncommon or important to understand the core principle of a technique or debugging something silly. I mentioned very clearly that I don't like to see someone debugging something silly. Ippsec is a genius guy, everything he does is self taught. I do agree it adds a human factor in the video which is something others might relate to. Apart from that, it doesn't bring value to the video if the 'mistake' that you've made is something that you should have noticed, like not completely copying the full hash. It is fine by me if that is a part of the video. Although that feels like watching sqlmap to finish on a boolean blind / time based injection, in both situations you already know where it will head to.

  • @fahmimohamadramadhan3978
    @fahmimohamadramadhan3978 2 ปีที่แล้ว

    how

  • @AsadAli-ye8ns
    @AsadAli-ye8ns 2 ปีที่แล้ว

    Bro you doing fine, but if you just talk slowly and act some slow like John Hammond, you are shifting to directories and other things very fast, its ok for experienced peoples, but for beginners you have to explain some things a little bit, if you just consider my request and you can do alot better and we will learn very easy from you.... thanks for your kind

    • @ghostinc7
      @ghostinc7 2 ปีที่แล้ว

      set playback speed to .5 . slow it down.

    • @collapzcursed
      @collapzcursed 2 ปีที่แล้ว

      you just assume this is even intended for beginners... it is not.
      The pace at which he goes is rather perfect.
      If you lack understanding of what is going on you can always rewind or maybe even RTFM ;)

    • @agenericaccount3935
      @agenericaccount3935 2 ปีที่แล้ว

      Ok Asad

  • @JNET_Reloaded
    @JNET_Reloaded ปีที่แล้ว

    too much talking get on withit

  • @sotecluxan4221
    @sotecluxan4221 2 ปีที่แล้ว