HackTheBox - Unobtainium

แชร์
ฝัง
  • เผยแพร่เมื่อ 17 ธ.ค. 2024

ความคิดเห็น • 35

  • @MADhatter_AIM
    @MADhatter_AIM 3 ปีที่แล้ว +13

    Unobtainium is a fictional element created for the movie "The Core" from 2003, a scientist named this material for his earth-crust-drilling machine, because it's so rare, it's almost unobtainable :) - btw love your chan ! keep up the good work.

    • @KlaypexDelusion
      @KlaypexDelusion 3 ปีที่แล้ว +2

      True. Better story than twilight. The credit card scene is top =)

    • @padaloni
      @padaloni 3 ปีที่แล้ว

      It's also the material they were after in Avatar

  • @Deaple
    @Deaple 3 ปีที่แล้ว +4

    One simple way to simulate a pod creation and print the yaml to stdout/file is:
    kubectl run my-pod --image=busybox --dry-run=client --output=yaml > my-pod.yaml
    Really nice explanation as always!

  • @Jake-nh4ek
    @Jake-nh4ek 3 ปีที่แล้ว +9

    At 12:17, the reason you couldn’t grab the route.js file is because that is a file part of the express router framework, not the user’s codebase. The index.js at the bottom of the error is the same, part of express router framework. The reason you can grab index.js is because that specific index.js is part of the the user’s codebase (app/index.js).

  • @socat9311
    @socat9311 3 ปีที่แล้ว +26

    Just failed oscp for one flag. Freaking sucks, but if I managed to get this far it's almost exclusively thanks to your videos and knowledge sharing. Thanks man

    • @acidopcodes
      @acidopcodes 3 ปีที่แล้ว +6

      Better luck next time! All the best!

    • @socat9311
      @socat9311 3 ปีที่แล้ว +4

      @@acidopcodes cheers my friend :) great learning step!

    • @thev01d12
      @thev01d12 3 ปีที่แล้ว

      Is it harder now? I remember it was hella easy back then

    • @dojoku88
      @dojoku88 3 ปีที่แล้ว

      Comparing tO The lab, How much The gap.??

    • @chiraqsoulja
      @chiraqsoulja 3 ปีที่แล้ว

      @@thev01d12 a lot harder now a days

  • @user-fp6dt1os1l
    @user-fp6dt1os1l 3 ปีที่แล้ว +47

    "There's 24 letters in the alphabet" - Ippsec, 2021

    • @user-fp6dt1os1l
      @user-fp6dt1os1l 3 ปีที่แล้ว +6

      (also, it tells you .toString(32), so you should know immediately it's 32**11)

    • @ippsec
      @ippsec  3 ปีที่แล้ว +29

      I would not do good on a game show lol... Guess the number is bigger, even more reason to not bruteforce!

    • @boogieman97
      @boogieman97 3 ปีที่แล้ว +1

      @@ippsec Ah it happens to anyone and with the fact that tons of people will comment on you, like yourself, @C. The way this guy is able to transform knowledge to others and the way he taught knowledge himself is insane. He is killing every box, every week with a little extra most of the times. A little mistake now and then is acceptable.

  • @overgrowncarrot1
    @overgrowncarrot1 3 ปีที่แล้ว

    Unobtainium is what they want to find in the movie avatar, and yes you said it right

  • @randomnickname00
    @randomnickname00 3 ปีที่แล้ว +2

    Hey thank you very much for all your videos, it motivates me a lot to learn and of course your videos are really helpful, it is very entertaining

  • @zgredfryd
    @zgredfryd 3 ปีที่แล้ว +1

    At last, I will get to know how to hack this machine. I was trying for few days but with no luck!
    EDIT: I watched the whole video. Personally, I got to creds to unobtainium app and js files but didn't know what to do next. as always great content man!

  • @averytan
    @averytan 3 ปีที่แล้ว

    Ippsec, I'd love to wine and dine you one day to thank you for all the resources and work you contribute to the community! You truly rock!

  • @krosec
    @krosec 3 ปีที่แล้ว +1

    The creds I got from the PHAR file, that is basically a compressed JS of the electron app, and to move from the webapp to the dev node I used Chisel, I wrote a Python script to exploit the credential, so was kinda fast. The last part that made me lost a bunch of hours to figure out lol, but my way was the Bad Pod exploit with yaml... But was a ton of learning

  • @DeadAksRab
    @DeadAksRab 3 ปีที่แล้ว

    Awesome, thank you

  • @younesmohssen8158
    @younesmohssen8158 3 ปีที่แล้ว

    Why did you decide to examine the traffic with wireshark instead of burpsuite for example? Anything specific at all?

  • @mssblogs
    @mssblogs 3 ปีที่แล้ว +2

    Hey ippsec do you have any courses related to cyber security?? If yes where I mean udemy plural sight??

    • @ippsec
      @ippsec  3 ปีที่แล้ว +5

      Not really, I help out with some courses on HackTheBox Academy but mainly just what you see on my YT.

    • @mindtropy
      @mindtropy 3 ปีที่แล้ว

      @@ippsec Is joining channel on YT available? or just patreon?

  • @Ms.Robot.
    @Ms.Robot. 3 ปีที่แล้ว

    Sweet box! ❤️

  • @thatcrockpot1530
    @thatcrockpot1530 3 ปีที่แล้ว

    superb

  • @jeffersongeorgewill9567
    @jeffersongeorgewill9567 2 ปีที่แล้ว

    Wow. How does someone go from zero knowledge of hacking to this?

  • @Free.Education786
    @Free.Education786 3 ปีที่แล้ว +1

    Please make tutorial how to install Python 2.7 Python3.10 with pip pip2 pip3 and all other important python repositories in debian Linux smoothly without errors. Also make tutorial how to install Docker in debian Linux and install Docker tools script programs like Jok3r web framework in it smoothly without errors. 🤝💯✌🥰💚💙💜❤😘🤩😍🤝

  • @bernasevinc5259
    @bernasevinc5259 3 ปีที่แล้ว +1

    Can you add Turkish subtitles to ippsec videos please don't offend me

    • @WithoutRemorce
      @WithoutRemorce 3 ปีที่แล้ว +6

      Better to learn English, technical isn't so hard.
      P.s. There are watchers from all world, really think that Turkish is the most preferable?😁

    • @bernasevinc5259
      @bernasevinc5259 3 ปีที่แล้ว

      Evgeniy Lenc yes but I don't understand the techniques in the video so I asked for Turkish subtitles

    • @mindtropy
      @mindtropy 3 ปีที่แล้ว

      @@bernasevinc5259 otomatik çeviri iş görebilir, değilse anlamadığın kısmı sorarsan cevaplayan olacaktır. Ayrıca zorluk derecesine göre oynatma listeleri oluşturmuş, sıra ile gidersen tekniklere aşina olursun.