A Poor Man's Pentest: Automating the Manual - BsidesDE 2019

  Рет қаралды 49,059

John Hammond

John Hammond

4 жыл бұрын

If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
E-mail: johnhammond010@gmail.com
PayPal: paypal.me/johnhammond010
GitHub: github.com/JohnHammond
Site: www.johnhammond.org
Twitter: / _johnhammond

Пікірлер: 78
@_JohnHammond
@_JohnHammond 4 жыл бұрын
View the original on BsidesDE's channel, and check out their other talks! kzbin.info/www/bejne/rWbUf5Wjpqd1mLs
@sickthotsonmymind2299
@sickthotsonmymind2299 4 жыл бұрын
Whew, working your way up brother. You're a proper example for all the youngsters
@_JohnHammond
@_JohnHammond 4 жыл бұрын
@@sickthotsonmymind2299 Thanks so much! Doing the best I can!
@jobsphil9553
@jobsphil9553 4 жыл бұрын
I joined discord channel. but I can not load messages . help me
@_JohnHammond
@_JohnHammond 4 жыл бұрын
@@jobsphil9553 Have you done the verification CAPTCHA that the bot sent you in a DM?
@kumarniloy3893
@kumarniloy3893 3 жыл бұрын
Probably the first time John remembered his IP
@gtdt5666
@gtdt5666 3 жыл бұрын
:'D
@aidancollins1591
@aidancollins1591 4 жыл бұрын
That was a hard crowd lol
@deity6119
@deity6119 2 жыл бұрын
when you compare his talk to some of the actually talented talkers at defcon he just sounds stupid lol
@aidancollins1591
@aidancollins1591 2 жыл бұрын
@@deity6119 Defcon? My impression is that Defcon has turned into a huge advertising convention with the talks centered around showcasing hacking products. It's hard to find a good talk post-2015. You're better off checking out smaller conventions. This talk isn't groundbreaking or anything, it's not unveiling new research or a vulnerability, but it's perfectly fine for what it is. Showcasing what you're able to do with limited funds.
@deity6119
@deity6119 2 жыл бұрын
@@aidancollins1591 Old defcon was way better for sure. But I dunno I just don't think he's a very engaging speaker
@DT-hb3zu
@DT-hb3zu 3 жыл бұрын
I FOUND IT! Do you know how frustrating it is to search "John Hammon presentation", and get nothing but Jurassic Park clips?!
@sechvnnull1524
@sechvnnull1524 4 жыл бұрын
Can't thank you enough for these videos and the walk throughs you do. It literally is inspiring and motivating and gives me goals to shoot for! I started out really late in life and am working towards a degree but you really can't put a price on the content you continue to share. Its awesome stuff!!
@_JohnHammond
@_JohnHammond 4 жыл бұрын
Very happy to hear that, appreciate all the kind words! Thank you so much and thanks for watching!
@barakcobrama1703
@barakcobrama1703 2 жыл бұрын
i use kali linux is ubunto better?? does anyone know???
@mustafaismail5773
@mustafaismail5773 4 жыл бұрын
That was amazing ideas, you gave me a lot of information and Techniques to continue on this path
@sirw369
@sirw369 4 жыл бұрын
Just watching this now, but super informative and useful if you’re into pen-testing. As always John, great presentation. Hope to catch you at your next one!
@ankitkumarjat9886
@ankitkumarjat9886 4 жыл бұрын
It's a very good automation resource.Thanks john
@picious
@picious 4 жыл бұрын
Once more, thank you !
@TheViranga
@TheViranga 4 жыл бұрын
Great stuff. Very helpful and informative. Thanks!
@_JohnHammond
@_JohnHammond 4 жыл бұрын
Thank you for watching!
@xfaraday2433
@xfaraday2433 4 жыл бұрын
Ayyy my boy John rising up and doing talks now! Nice
@123ezekiel456
@123ezekiel456 4 жыл бұрын
John, very cool talk. Enjoyed it so much!
@_JohnHammond
@_JohnHammond 4 жыл бұрын
Thank you! It was a lot of fun to do. On to the next one!
@simonb8988
@simonb8988 2 жыл бұрын
Great video!
@bigtymer4862
@bigtymer4862 4 жыл бұрын
Great talk John! Brilliant!
@_JohnHammond
@_JohnHammond 4 жыл бұрын
It's a cheesy thing, but thank you so much!
@minibit0103
@minibit0103 4 жыл бұрын
Totally could see you becoming a professor. Very cool presentation 👏
@runnerc
@runnerc 3 жыл бұрын
Great job man! Very helpfull!
@glennbloemhof3194
@glennbloemhof3194 4 жыл бұрын
@John Hammond do you have any idea how to make the stabilize_shell.sh work inside reverse shell using something like tmux? Nice Video btw! love your content!
@thecaretaker0007
@thecaretaker0007 3 жыл бұрын
Such a great video, now i wanna make this on my own!
@Waarzown
@Waarzown 2 жыл бұрын
Usually I designate a specific terminal for callbacks. If you use something similar, you can set "stty raw -echo" in that window ahead of time, and not need to background the callback in order to set it.
@anujkumarpatel2686
@anujkumarpatel2686 4 жыл бұрын
you have inspire me alot
@rodriquh
@rodriquh 4 жыл бұрын
Great talk John! They definitely needed a mic for the crowd for their questions. You’re a top notch instructor, you can tell by the way you throw in questions to keep engagement up. It seems like these guys either weren’t tracking or the concepts were way over their heads. I love the thought you put into this, but don’t you worry about creating script kiddies? Just curious. Again, great talk John, I love following your channel and seeing all the good stuff you put out there to allow people to hack their brains and change the way people look at things. Thanks for all you do brother!
@_JohnHammond
@_JohnHammond 4 жыл бұрын
Hey Henry, thanks for all the kind words! Haha, it has been a few months since I have on podium instructing, but it's fun, I miss it a bit :) I am not too concerned with script kiddies -- they'll do their thing, but they won't improve :P Thanks so much, and thanks for watching!
@RohanOnBike
@RohanOnBike 4 жыл бұрын
Cool stuff as always🤘
@_JohnHammond
@_JohnHammond 4 жыл бұрын
Thank you for watching!
@Joshua1_7sc
@Joshua1_7sc 3 жыл бұрын
That was awesome
@brandanderstine677
@brandanderstine677 4 жыл бұрын
Great job dude
@_JohnHammond
@_JohnHammond 4 жыл бұрын
Thank you so much!
@mrjamesprince
@mrjamesprince 4 жыл бұрын
wow, how did i miss this
@lordtony8276
@lordtony8276 3 жыл бұрын
Any idea how to stabilize a shell when you are attacking from a windows machine? Powershell and CMD don't like it when you CTRL + Z. It makes the system lock up or something. Even when I use a kali linux docker instance, I am still running through Powershell so I can't seem to background the revshell.
@NickBouwhuis
@NickBouwhuis 4 жыл бұрын
Great talk! Love it! Too bad they added a rather aggressive noise gate.
@_JohnHammond
@_JohnHammond 4 жыл бұрын
Thanks so much! Yeah it's a little spotty when I am speaking versus not speaking, ah well. Thanks for watching!
@koloxd3
@koloxd3 3 жыл бұрын
Love IT
@DDBAA24
@DDBAA24 4 жыл бұрын
This was a revealing video. Only been watching you a few months , you know you love your "cheezy" 🧀KZbin channel lol. Respect though, had a feeling you had military background .
@S1lenc31991
@S1lenc31991 3 жыл бұрын
As an addition to your "missing characters" problem - you could iterate over an string doing a very short delay after each keystroke to make sure you get all chars right :)
@S1lenc31991
@S1lenc31991 3 жыл бұрын
Oh, and maybe look up DBUS messages, Guake is scriptable by that
@v01dspac38
@v01dspac38 4 жыл бұрын
volume = volume++
@puppe1977
@puppe1977 4 жыл бұрын
48:34 shouldn't the keyup/keydown for Tab be in the reverse order? Great talk! It's in the correct order in your git repo (in functions.sh) so maybe just update your slides.
@Dontfkwithme69
@Dontfkwithme69 4 жыл бұрын
I hope one day i get a chance to attend your workshop :(
@ajaykumark107
@ajaykumark107 4 жыл бұрын
what is the use of xterm command ? Why do we use it here in the context?
@damienkali
@damienkali 4 жыл бұрын
great demo, would be good if you shared your final functions.sh somewhere ;) - was a tough crowd to work with, only feedback I can suggest, is have someone with a spare mic to pass to people when asking questions, (or if you can repeat their question back so we can hear what is going on)
@_JohnHammond
@_JohnHammond 4 жыл бұрын
Thanks so much! Is the final function.sh not in the GitHub repo? I can see it there. I should definitely get in the habit of repeating questions. Thanks for all the kind words and thanks for watching!
@damienkali
@damienkali 4 жыл бұрын
@@_JohnHammond Pleasure to give feedback, I found your channel 2 days ago & literally going through each video now non stop. I completed (with your help) all on overthewire, have you started Krypton yet? if not, I would love to see your way of doing the challenges. I forgot to check the github repo & my bad I didnt even know you had a link, can you post it here? tks (feel free to check out some of my videos) :)
@_JohnHammond
@_JohnHammond 4 жыл бұрын
@@damienkali Oh that is excellent, thank you! I have gone through a bit of Krypton, but you are right that I have not shared any videos on it! I will add it my list for sure and can hopefully get that out within the month. Github repo is here: github.com/JohnHammond/poor-mans-pentest And I took a look at your channel -- subscribed! :D
@arinugraha635
@arinugraha635 2 жыл бұрын
when i enter stty raw -echo my terminal like freeze cann't response. what's wrong ?
@highvisibilityraincoat
@highvisibilityraincoat 3 жыл бұрын
Miffed I wasn’t into security when this happened bc i’m like 30 minutes away.
@nabinsademba
@nabinsademba 4 жыл бұрын
is ctf challenge over?
@_JohnHammond
@_JohnHammond 4 жыл бұрын
Yes, sorry -- I am hoping to bring the event to more conferences, so I am waiting until the next one to bring it back up again.
@p4nz9r60
@p4nz9r60 4 жыл бұрын
Hi, have you thought about using the tmux instead of xte/terminator/guake?
@_JohnHammond
@_JohnHammond 4 жыл бұрын
I have, yes, I used tmux for some time-- especially when I was tinkering with Arch. Admittedly I have gone back to Ubuntu -- too many idiosyncrasies added up haha.
@tsurumaruwordpress
@tsurumaruwordpress 4 жыл бұрын
I was wondering if this would be possible, substituting tmux for guake. Should be, right?
@p4nz9r60
@p4nz9r60 4 жыл бұрын
@@tsurumaruwordpress 'tmux send-keys -t paneID -l some text \; send-keys -t paneID Enter' will send 'some text ' to the pane 'paneID', so you probably won't need xte at all, plus it could be used on macOS as well.
@dnperfors
@dnperfors 4 жыл бұрын
P4nz9R mostly that should work, except for the script to start the reverse shell where you want to switch to your browser... but yeah, it would be worth a try :)
@_JohnHammond
@_JohnHammond 4 жыл бұрын
@@tsurumaruwordpress I think that's a fine idea. Admittedly, with the "Alt Tab" functionality, we really don't even need Guake. We can automate shifting the focus as needed. Tmux might need some other key strokes to close a current pane, or switch a new one -- however you would like to implement it.
@jeszczewiecejmichala
@jeszczewiecejmichala 4 жыл бұрын
You record it with a terrible hair dryer (calculator;)) Super presentation - From Poland
@nabinsademba
@nabinsademba 4 жыл бұрын
why cant i join the discord?
@_JohnHammond
@_JohnHammond 4 жыл бұрын
What is preventing you?
@pauloelienay1662
@pauloelienay1662 4 жыл бұрын
Why use Ubuntu (who sells your data) if you can use Debian (if you like stability and the Ubuntu package manager), Fedora (what I used for a long time, really good IMO) or Arch (rolling release, full control over your machine etc)
@thegripmaster666
@thegripmaster666 4 жыл бұрын
Do give us some reference for your claim that Ubuntu sells your data.
@bhagyalakshmi1053
@bhagyalakshmi1053 Жыл бұрын
Kail linux ram
@bhagyalakshmi1053
@bhagyalakshmi1053 Жыл бұрын
Chg pt explain
@ctrlcapsswap966
@ctrlcapsswap966 3 жыл бұрын
someone show this man at least i3
KOVTER Malware Analysis - Fileless Persistence in Registry
1:28:14
John Hammond
Рет қаралды 332 М.
Binary Exploitation Deep Dive: Return to LIBC (with Matt)
2:12:41
John Hammond
Рет қаралды 185 М.
ПАРАЗИТОВ МНОГО, НО ОН ОДИН!❤❤❤
01:00
Chapitosiki
Рет қаралды 2,6 МЛН
WHY DOES SHE HAVE A REWARD? #youtubecreatorawards
00:41
Levsob
Рет қаралды 39 МЛН
1🥺🎉 #thankyou
00:29
はじめしゃちょー(hajime)
Рет қаралды 79 МЛН
1 класс vs 11 класс (неаккуратность)
01:00
Basic Buffer Overflow - VulnServer TRUN
1:03:04
John Hammond
Рет қаралды 194 М.
This Illegal Car Mod Just Changed the Game
10:21
Scotty Kilmer
Рет қаралды 4,5 МЛН
HackTheBox - "Remote" - Umbraco & Windows
48:23
John Hammond
Рет қаралды 82 М.
The biggest fails from Driving Test | Driving Test 2020
10:40
Channel 9
Рет қаралды 4,9 МЛН
This might be the best watercooling case I've EVER seen!
13:36
JayzTwoCents
Рет қаралды 789 М.
How to Do 90% of What Plugins Do (With Just Vim)
1:14:03
thoughtbot
Рет қаралды 866 М.
415 Hack Yourself Building A Pentesting Lab David Boyd
43:43
Adrian Crenshaw
Рет қаралды 51 М.
Exploiting Tomcat with LFI & Container Privesc - "Tabby" HackTheBox
45:54
ПАРАЗИТОВ МНОГО, НО ОН ОДИН!❤❤❤
01:00
Chapitosiki
Рет қаралды 2,6 МЛН