BLOODHOUND Domain Enumeration (Active Directory #06)

แชร์
ฝัง
  • เผยแพร่เมื่อ 29 ธ.ค. 2024

ความคิดเห็น •

  • @mossdem
    @mossdem 2 ปีที่แล้ว +54

    The errors you make show us that we are all human, even you John. Thanks for the great content as always!

    • @Lacsap3366
      @Lacsap3366 2 ปีที่แล้ว +1

      the thing is, I really appreciate that John is not cutting out the tinkering and error solving parts of this video series, because in that way we can learn from his errors and gain more insight on how he solves them.

  • @GC-rg6in
    @GC-rg6in 2 ปีที่แล้ว +5

    You don't need to change /etc/resolve. You can just pass the option -ns

  • @kilarosul
    @kilarosul 2 ปีที่แล้ว +3

    I've been watching videos from your channel like crazy... The fun part is that they are very educational... I've started with THM cuz of you and I've done the begginer path in just under a week. You've managed to inspire me to learn something new and right now I'm just having loads of fun with it. Thank you

  • @stefanfredin7120
    @stefanfredin7120 2 ปีที่แล้ว +2

    I love watching your videos. I used to be in to network security and such, got a job in a completely different direction and never touched it again after school. Now I have trouble even installing software on linux.. It's really relaxing watching people with knowledge doing what you do.

  • @TheCede555
    @TheCede555 8 หลายเดือนก่อน +1

    I died seeing the bloodhound doggo pictures, i think we've all had that moment :'D great videos!

  • @cyberbrain232001
    @cyberbrain232001 2 ปีที่แล้ว +1

    Excellent content and amazing knowledge. I will say your enthusiasm has truly reignited my love of IT. I want to learn and explore and expand my knowledge because of your videos.

  • @theMadhatter817
    @theMadhatter817 ปีที่แล้ว

    the mistakes are awesome, it helps us learn and shows everyone that its not perfect every time. troubleshooting is something that isnt shown in these types of videos. Thanks!

  • @SP800.69
    @SP800.69 ปีที่แล้ว +1

    This is awesome. Thanks John.
    The install instructions are a bit messed up now (July 2023).
    Following the install instructions on the site leads to a broken install. At least for me
    My install needed :
    The latest Bloodhound GUI binaries need neo4j 5+
    And neo4j 5 needs Java 17 whereas the instructions install 4.2 with Java 11.

  • @fastforward3695
    @fastforward3695 2 ปีที่แล้ว +6

    I feel like this will be a must have during the PNPT.

  • @jacobhulbert2976
    @jacobhulbert2976 ปีที่แล้ว

    Thanks for all you do John. I have learned so much from you. I just wanted to share with you; when running a command that should use sudo you can just type "sudo !!" and i will append sudo to the last command. It helped my efficiency so I wanted to pass it on. Again blessings :)

  • @alaahaider
    @alaahaider 2 ปีที่แล้ว +3

    John.. you are absolutely awesome. Great tool, great video and most of all great presentation. Very well done 👍

  • @piotrstasinskij2929
    @piotrstasinskij2929 ปีที่แล้ว

    Thank You John for video. Bloodhound is amazing tool for discovering ms ad

  • @Stellar_AI_History
    @Stellar_AI_History 2 ปีที่แล้ว +1

    Good video man. I hate it when people have a host already "compromised" and run sharphound (even though they probably never compromised it and just ran a vw with sharhound on it). I like how you changed it up and are being real! This will help me!

  • @jimpowers4463
    @jimpowers4463 2 ปีที่แล้ว +2

    Really enjoying this series, can't wait to see what's next.

  • @jeanaimarre8605
    @jeanaimarre8605 2 ปีที่แล้ว

    Useful and fun presentation. Please do more. I like the format, the way you explain. Regards

  • @AuctorisVideo
    @AuctorisVideo 2 ปีที่แล้ว

    Loving this series John. Very interesting. Thankyou.

  • @jonathanheadley2729
    @jonathanheadley2729 2 ปีที่แล้ว

    Loving the content, John. Thank you!

  • @Tekionemission
    @Tekionemission ปีที่แล้ว

    (25:00) - Edit resolv.conf since DNS is not resolving the Domain.
    (25:17) - Bloodhound extractor syntax

  • @lumin0l161
    @lumin0l161 ปีที่แล้ว

    Epic series, John. Thank you mate.

  • @dunkov1
    @dunkov1 2 ปีที่แล้ว +1

    John, you are amazing! Keep doing this stuff and maybe you know it but you can execute the previous commands with sudo permissions by just typing "sudo !!" 😅 Greetings and respect from Bulgaria!

  • @naomibenz5664
    @naomibenz5664 2 ปีที่แล้ว

    Awesome, Bloodhound name looks like those really scary thing like in horror movies really amazed by the creators, they are frictional stuffs, but I really love John your tutorials on point👌

  • @yazeedalotaibi4587
    @yazeedalotaibi4587 2 ปีที่แล้ว

    Love the content John. Keep on the grind.

  • @natemaiorana3936
    @natemaiorana3936 2 ปีที่แล้ว

    Great Vid Again John

  • @cedricvillani8502
    @cedricvillani8502 2 ปีที่แล้ว

    Maltego Enterprise makes sweet face love to this. ❤😂

  • @Semtx552
    @Semtx552 2 ปีที่แล้ว

    incredibly valuable John, thanks so much for this.

  • @TheTricro
    @TheTricro 2 ปีที่แล้ว

    Great content as always, keep up the good work!

  • @TheH2OWeb
    @TheH2OWeb 2 ปีที่แล้ว

    Thank you John !

  • @swyerdon
    @swyerdon 2 ปีที่แล้ว

    Very cool content. Thanks!

  • @johnatan5313
    @johnatan5313 ปีที่แล้ว

    Hello John, I have a dump question, Bloodhound ingestor scrap more informations with a high privileve account or its the same result with a low privilege account ?

  • @Aerogamer158
    @Aerogamer158 2 ปีที่แล้ว

    Question. Why do you not use sudo su for all that terminal install stuff in your videos?

  • @msaeed5228
    @msaeed5228 2 ปีที่แล้ว

    Thanks Hammond, u r amazing

  • @nullneekhil
    @nullneekhil 2 ปีที่แล้ว

    Love from india 💖 , love your vedio buddy great work 💖

  • @eatbreakfasts7993
    @eatbreakfasts7993 ปีที่แล้ว

    So mention being able to "see and access" the domain controller... If I'm unable to ping the domain controller does that mean I can't see it? I'm trying to run this in my lab and I can ping the Kali machine from the DC machine but not vice versa.

  • @chanceleram
    @chanceleram 2 ปีที่แล้ว

    thank you so much for sharing even when you commit a mistake !!!

  • @jimo8486
    @jimo8486 2 ปีที่แล้ว

    did i hear a police siren in the background at 29:26

  • @dwightschrute08
    @dwightschrute08 2 ปีที่แล้ว +1

    In case anyone else wants to do this, you'll need to add the stable 4.4 repo to your apt sources, not 4.0 per the Bloodhound instructions. Also, might have to uncomment "dbms.allow_upgrade=true" in the neo4j config file (/etc/neo4j/neo4j.conf) in order for the database to run properly.

    • @Pyroteq
      @Pyroteq 2 ปีที่แล้ว

      Yeah, I screwed around for ages trying to get this working. Bloodhound-Python wants you to have version 4.2 of Bloodhound and Bloodhound 4.2 wants you to have version 4.4 of Neo4j. I had to nuke Neo4j and ensure I cleaned up all the old database files and config files and then reboot before I could get Neo4j working again when I finally managed to find the latest version of it. Far out, what a headache.

    • @Eggsec
      @Eggsec 2 ปีที่แล้ว

      it's this why my update data isn't uploading anything? currently in 4.2.0 v bloodhound

  • @Lei_Wong
    @Lei_Wong 2 ปีที่แล้ว

    Amazing tool, great tutorial

  • @a1hun7
    @a1hun7 2 ปีที่แล้ว

    good good good...

  • @a1hun7
    @a1hun7 2 ปีที่แล้ว

    Oh god, is not fox-it is fox IT as in Information Technology. Is one of the biggest security firms in Europe.

  • @ifoam
    @ifoam 2 ปีที่แล้ว +2

    It's always DNS. I've seen that error too many times. That's what is happening when you try to join a computer to a domain without being able to resolve domain service records.

    • @lordmummie
      @lordmummie 2 ปีที่แล้ว +1

      I was looking for this 😂

    • @Stopinvadingmyhardware
      @Stopinvadingmyhardware 2 ปีที่แล้ว

      When you don’t own the DNS and it’s some private server yanking your chain.

  • @itssoEC
    @itssoEC ปีที่แล้ว

    I have tried setting up on 3 different machines and only one gave me the new temporary password. I'm not sure what happened, but I haven't found a solution yet. Is there a link to a solution available. I will keep looking, but my google-fu hasn't worked yet.

  • @yamangoyal405
    @yamangoyal405 2 ปีที่แล้ว

    Can anyone give me the link of this humble bundle link... Plz

  • @aspeakgaming3564
    @aspeakgaming3564 2 ปีที่แล้ว

    be carefull your add can be interpreted as 1$ the all bundle....but not true to get the all bundle it is 24.06 for the all bundle (worth anyway)

  • @logiciananimal
    @logiciananimal 2 ปีที่แล้ว

    Has anyone ever tried to get a *print* copy via the humble bundle idea? I'd be willing to pay fair value but I really don't want ebooks ...

  • @non2614
    @non2614 17 วันที่ผ่านมา

    but on the real system how we can get username and password. if you one of the users domain could you set your userame password

  • @Stopinvadingmyhardware
    @Stopinvadingmyhardware 2 ปีที่แล้ว

    I’m the guy that enters funny jokes for commits on GitHub

  • @martx0013
    @martx0013 ปีที่แล้ว

    👽

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 ปีที่แล้ว

    This is eroo mark domnam password missing sind elements

  • @slonkazoid
    @slonkazoid 2 ปีที่แล้ว

    tip: run `exec $0` to restart your shell without starting a new terminal

    • @slonkazoid
      @slonkazoid 2 ปีที่แล้ว

      sourcing /etc/profile is another option but this method replaces the current process image a with a new one, doesn't just reload the shell

  • @nekoda9379
    @nekoda9379 2 ปีที่แล้ว

    Ahh yess, BloodHound > Gibby

  • @devilveyron6762
    @devilveyron6762 2 ปีที่แล้ว +1

    Hi

  • @P2Pyt
    @P2Pyt 2 ปีที่แล้ว

    Can u beat anonymous

  • @kraemrz
    @kraemrz 2 ปีที่แล้ว

    YT algorytm

  • @edbolton
    @edbolton 2 ปีที่แล้ว +1

    …it’s always DNS

  • @erikalee5796
    @erikalee5796 2 ปีที่แล้ว

    p͓̽r͓̽o͓̽m͓̽o͓̽s͓̽m͓̽ 💖

  • @msasdc2087
    @msasdc2087 2 ปีที่แล้ว

    Hahaha, still a zero.

  • @zer0-skill893
    @zer0-skill893 2 ปีที่แล้ว +4

    John, there's a cool CTF I've been playing and I think you'd be interested in it, maybe check it out, it's being run by Deloitte. It's called "hacky holidays 2022"

  • @i_am_christoph1537
    @i_am_christoph1537 2 ปีที่แล้ว

    Hey John, I sent you a message on Discord and tried to email. How does one get in contact with you?

  • @ratchetbear5916
    @ratchetbear5916 ปีที่แล้ว

    Wasn't able to get the command @ 25:22 working, but i found a work around.
    command is: bloodhound-python -u [USER]-p [PASS] -ns [IP of DC] -d [Domain.local] -c All
    Wonder if my command will survive?..