HackTheBox - Analytics

  Рет қаралды 11,501

IppSec

IppSec

Күн бұрын

0:00 - Introduction
01:00 - Start of nmap
03:20 - Discovering Metabase, noticing the HTTP Headers are different. Checking TTL just to see if it decrements from the main web page.
07:00 - Searching for an exploit for metabase, then enumerating version
09:30 - Manually exploiting Metabase by pulling the setup-token, then getting injection on the /setup/validate endpoint through the JDBC Driver
15:50 - Reverse shell returned
18:30 - Discovering credentials in the environment variables, then ssh into the box
20:12 - Googling the kernel to discover its vulnerable to GameOverlay
24:00 - Explaining the gameoverlay exploit (CVE-2023-23640, CVE-2023-32629)
25:50 - Stepping through the exploit manually to understand how the overlay fs works, and what the exploit did to abuse it
28:10 - Looking into the permissions of the binaries that were created

Пікірлер: 16
@steve0ro
@steve0ro 3 ай бұрын
"womp womp" 😂😂 Great video, I appreciate the breakdown of the gameoverlay exploit
@antoniob.6515
@antoniob.6515 3 ай бұрын
Amazing as usual😊
@7ner.
@7ner. 3 ай бұрын
Great as always
@ruycr4ft
@ruycr4ft 3 ай бұрын
Nice video!
@tg7943
@tg7943 3 ай бұрын
Push!
@dadamnmayne
@dadamnmayne 3 ай бұрын
"and its banner tells us its an Ubuntu server"
@3xpl0i79
@3xpl0i79 3 ай бұрын
This can take some time to run so I have already ran it, looking at the results, we just two ports open, the first one being SSH on port 22 ...
@TheKnox159
@TheKnox159 3 ай бұрын
Its pretty iconic at this point lol
@ujsimrananees
@ujsimrananees 3 ай бұрын
Great vid. Hey Ipp, could you do the walkthrough for P.O.O Endgame. I would appreciate it.
@AUBCodeII
@AUBCodeII 3 ай бұрын
Hey Ipp, are you friends with Little Bobby Tables?
@gespoL-
@gespoL- 3 ай бұрын
!!!
@highlights973
@highlights973 3 ай бұрын
Sir how can i make videos like you without being demonetized or getting a channel strike
@denic6861
@denic6861 3 ай бұрын
As long as you’re not copyrighting, teaching people to do things for nefarious purposes, or breaking common TOS rules, you should be fine. This falls under educational content
@highlights973
@highlights973 3 ай бұрын
@@denic6861 Thank you
@sotecluxan4221
@sotecluxan4221 3 ай бұрын
HackTheBox - CozyHosting
37:18
IppSec
Рет қаралды 12 М.
HackTheBox - Devvortex
41:00
IppSec
Рет қаралды 11 М.
孩子多的烦恼?#火影忍者 #家庭 #佐助
00:31
火影忍者一家
Рет қаралды 36 МЛН
MEU IRMÃO FICOU FAMOSO
00:52
Matheus Kriwat
Рет қаралды 41 МЛН
THEY made a RAINBOW M&M 🤩😳 LeoNata family #shorts
00:49
LeoNata Family
Рет қаралды 8 МЛН
HackTheBox - PC
29:32
IppSec
Рет қаралды 13 М.
HackTheBox - Napper
1:24:46
IppSec
Рет қаралды 10 М.
Linux Terminal Tweaks | Tmux + Aliases + Shortcuts
34:09
A Vulnerability to Hack The World - CVE-2023-4863
18:00
LiveOverflow
Рет қаралды 105 М.
HackTheBox - AppSanity
1:27:34
IppSec
Рет қаралды 13 М.
HackTheBox - Monitored
1:02:07
IppSec
Рет қаралды 10 М.
HackTheBox - Bookworm
2:05:30
IppSec
Рет қаралды 13 М.
Incredible Dangers in Browsers (Affects all of them)
21:02
Rob Braxman Tech
Рет қаралды 283 М.
HackTheBox - Broker
29:03
IppSec
Рет қаралды 25 М.
I legally defaced this website.
25:48
thehackerish
Рет қаралды 503 М.
孩子多的烦恼?#火影忍者 #家庭 #佐助
00:31
火影忍者一家
Рет қаралды 36 МЛН