Sometimes, what you know is not enough to get noticed above the crowd when trying to get a position; it is who you know who can open that door.
@madara556552 сағат бұрын
amazing walkthrough
@Tib3rius2 сағат бұрын
Thank you!
@TheRealVegapunk5 сағат бұрын
I'll start doing this soon, I'm in need of a career change 😄
@Ox8jOrn4r8Or9310 сағат бұрын
Great walkthrough Tib3rius. Keep up the good work!
@Tib3rius5 сағат бұрын
Thank you!
@alienboy68910 сағат бұрын
First time I've really had Burp explained so well 🐥
@Tib3rius10 сағат бұрын
Thank you! 🙏
@salmakhaled50012 сағат бұрын
amazing explanation appreciate it
@Tib3rius5 сағат бұрын
Thanks!
@orbitxyz786720 сағат бұрын
What is twitch
@Tib3rius20 сағат бұрын
It's a streaming platform I use: www.twitch.tv/0xTib3rius
@_NET_Күн бұрын
🔥🍿 Premium Popcorn !!
@dzabdo8017Күн бұрын
Great looking forward to it 😊.
@vipinsharma1984Күн бұрын
😊
@gamehacks5814Күн бұрын
you are better than these other plebs, best walktrough!
@santhoshurs82132 күн бұрын
No other youtuber had explained any task like u did.. understood every small details.. very well explained.
@Tib3rius2 күн бұрын
Thanks! Always enjoy doing these walkthroughs!
@Jussi-s5n2 күн бұрын
Incredible clarity and simplicity in your teaching, yet packed with detailed information on all the essentials. Thank you for this. I'll definitely check out what other content you've created!
@Tib3rius2 күн бұрын
Thanks, hope you enjoy!
@Lahmikhara4 күн бұрын
Great video so far, it's really giving me a lot of insight I'm not getting from simply going through the rooms on THM. I did manage to figure out a different (although much more boring) way of finding the flag on 38:39. I edited the python code to: import os; print(os.popen("cat app.py").read()) The flag was in the result Must honestly admit that in the last task even after trying to follow along I have no clue how you got the extra flag. I get the basic idea but what are the %3*? codes for when adjusting the url, and how did they get there?
@faheema46024 күн бұрын
Sort of up, above & around then scroll down 😂 Last-Byte Syn Attack Explanation 👌
@Tib3rius4 күн бұрын
If there's a feature which temporarily disables the changing highlighting, I wanna know about it. 😅
@MannerStyles5 күн бұрын
yoyo 1st~
@MannerStyles5 күн бұрын
liked/subbed/followed/incredible
@Tib3rius5 күн бұрын
Thank you!
@Jayden_Sewall5 күн бұрын
What is the name of the lock set
@mohammadhosein775 күн бұрын
Thank you so much for amazing contenet!
@Tib3rius5 күн бұрын
Glad you enjoy it!
@JosiahAyogu6 күн бұрын
Wow😮
@narsimharao85656 күн бұрын
last one is SQLI /page/edit/1'1+1'
@lukerzonca57547 күн бұрын
How would you go about getting code to determine if a race condition is possible on a real web app? I know it's provided here to help learn, but is it just a guess and hope it works in a real world scenario, or are there more effective ways to see what the code is doing?
@Tib3rius7 күн бұрын
Great question! Yeah, on a real engagement you are unlikely to have access. It's more about noticing the potential for race conditions in functionality and setting up the conditions where an attack might work, then testing to see if it does.
@T-Rex07117 күн бұрын
I'm so glad I watched this video in addition to reading the room. Your explanation of last byre sync with wireshark was great
@Tib3rius7 күн бұрын
Glad it helped!
@JohsonClint7 күн бұрын
this a lots of information
@imrcrabs35287 күн бұрын
just add in end '1'='1
@shivamnaik78577 күн бұрын
Hi what does:Where balances shift and numbers soar, look for an entry - an open door! mean? what should we look for?
@JosephBrady-u8c8 күн бұрын
For the past 2 AoCs, your videos have been the best. You add a ton of value to the lessons they provide, thanks for going in depth and thanks for making these walkthroughs.
@Tib3rius8 күн бұрын
Thanks! Appreciate the kind words.
@Dr4hcir8 күн бұрын
Very informative video. Great work, thanks!
@Tib3rius8 күн бұрын
Thank you!
@KaungKhant-yz8nd8 күн бұрын
OMG the more I participate in advent of cyber 2024, the more gold I dig. Another great resource you tube channel for me.
@KaungKhant-yz8nd8 күн бұрын
This walkthrough is special.... I couldn't help to close my mouth wondering every details your are explaining.. Thank you
@Tib3rius8 күн бұрын
Thank you!
@mecyber63168 күн бұрын
in the task is says send OVER 2000$. and i did as told to do and me end up not getting the flag. how to refund glitch account?
@Tib3rius3 күн бұрын
You can't refund the account as far as I'm aware. You need to reset the machine. I believe to trigger the flag you need to use the exploit like I did in the video. You probably need to make the end balance -$2000 or something.
@ramakrishnant77848 күн бұрын
I totally agree with you on this!
@psycho_iffe88288 күн бұрын
Savage 😂
@wassimmariamable8 күн бұрын
Thank you for that. I just learnt something very new to me. Well done Tib3rius. Do you have any videos on Burpe Suite?
@Tib3rius3 күн бұрын
I have a web app hacking playlist that contains a few videos on Burp! kzbin.info/www/bejne/g5OUmayciruSorc But also check out my live streams, we use Burp a lot. I stream most Mondays and Wednesdays, and you can find the recorded streams on the Live tab of my channel!
@atharvavlogs14468 күн бұрын
Awesome video.
@Tib3rius8 күн бұрын
Thank you!
@camerawman8 күн бұрын
Saved some time by going through this walkthrough . Thanks for this
@Tib3rius8 күн бұрын
You're welcome!
@DaniSpeh9 күн бұрын
And again Tib3rius explained the topic exceptionally well, going above and beyond by not just covering the basics but also diving into the 'why' and 'how' behind it. His videos are always so informative, and the streams are especially great for learning. Keep up the amazing work!
@Tib3rius9 күн бұрын
Thank you!
@c0ri9 күн бұрын
Nice to see you doing one of these Tib3rius! I've been following your walkthroughs for a few years now. You always go the extra mile and explain all the details.
@Tib3rius9 күн бұрын
Thank you!
@Zelousfear9 күн бұрын
Thoughts
@Tib3rius9 күн бұрын
Thank you for following instructions. 👍
@heybevis019 күн бұрын
Aww you gotta give him that TOCTOU
@Tib3rius5 күн бұрын
Can I steal this for a sticker? 🙏🥹
@newfaith9129 күн бұрын
Great it does not work for me. Luckly devs that made code dont check if i transfer 1000 than 2000 so it goes to negative anyway. Cheese way to get flag but i just cant replicate attack. It does 10 requests i get 10 response and only first gets processed. Did same with attackbox and it worked. Now i have even less clue why it didnt work on my personal vm.
@Tib3rius9 күн бұрын
Weird! Yeah not sure why it won't work on your personal VM. Interesting cheese, I thought the code did prevent that, but maybe I misread it. 🤔
@lynettestevenson64069 күн бұрын
Thanks! I loved the additional information, like showing us Wireshark as well.🙂
@Tib3rius9 күн бұрын
Thanks! Glad you enjoyed!
@ACatttttt9 күн бұрын
thanks for to me. for you see i have no eyes
@zigaudi9 күн бұрын
Great video and explaination.
@Tib3rius9 күн бұрын
Thanks!
@Zdenon1339 күн бұрын
There is an issue with last task (glitch account). When I duplicated the tab from the previous task and swapped the cookie session, account number and amount for proper values, the Balance went to 0, but no flag was provided.
@Tib3rius9 күн бұрын
I would go join the TryHackMe discord where someone from support should be able to help. Alternatively try resetting the box and trying the attack again with the actual request instead of swapping out values etc.
@Zdenon1339 күн бұрын
@@Tib3rius Thanks! I wanted to check if it was actually possible. If I were to provide a higher value than 2000 and go below 0, the flag might appear. Unfortunately, in this scenario, I'm also unable to duplicate requests, as the balance cannot process more transactions when it is 0. :D
@Tib3rius9 күн бұрын
Ah I understand what you mean now. Yes, if the balance is at $0 before you start the last-byte-sync attack, it won't work. This is due to a check in the code (see the code review section in the video). If the balance is > $0 however, the attack should be successful!
@Zdenon1339 күн бұрын
@@Tib3rius Ohhh... I think i should get a new pair of glasses :D "over" 2000 :D well nvm then :D Thanks !
@digvijaynetke98059 күн бұрын
turbo intruder not installing
@Tib3rius9 күн бұрын
Can you access the Internet from the Attack Box? If you aren't subscribed to TryHackMe I think the Attack Box is limited. Not sure if the same is true for AoC though.
@eliyartursun9 күн бұрын
Try "Last-Byte Sync in Action!" It is fast and better with the grouping, and it will help you find the flag.
@Tib3rius9 күн бұрын
@@eliyartursun in the video I compare last byte sync to Turbo Intruder. I think they are trying to replicate that.
@Lahmikhara9 күн бұрын
While the challenge was pretty easy, even for a beginner like me. This video really added a lot of value. I loved how you went into detail explaining how this attack works. Thank you
@Tib3rius9 күн бұрын
Thanks!
@vixytech_cybersecurity9 күн бұрын
I enjoyed every byte of this video. Well-done and Thank you. Well explained.
@Tib3rius9 күн бұрын
Thank you!
@sridharjayadavan79799 күн бұрын
Hi, Your explanation is awesome and i could able to understand the last byte syn. Thank you.
@Tib3rius9 күн бұрын
Glad to hear it!
@KumManish9 күн бұрын
Ah thanks Man ! Your videos are always with a superb quality 🐳