HackTheBox - Stacked

  Рет қаралды 17,923

IppSec

IppSec

Күн бұрын

Пікірлер: 38
@mitchodonnell3976
@mitchodonnell3976 2 жыл бұрын
First off, great video! Really loved the RCE using a lambda function! Around 57:50, you ask, "what did I just do". If you go to 57:41 you'll notice you changed your working directory to /root, the correct directory you wanted was /mnt/root, since the host's files system is mounted to /mnt/ within the docker container. I've made this mistake more times than I'd like to admit lol but we should call this out since all of us will hit the same using kubernetes, k3s, docker, etc.
@BluEhui09
@BluEhui09 2 жыл бұрын
There are a lot of things.. oh god I have to rewatch this again
@chiragartani
@chiragartani 2 жыл бұрын
I will watch this tonight. 🙌 Gonna ask you question after watching the video :).
@Vogel42
@Vogel42 2 жыл бұрын
"fetch" is the modern replacement for XMLHttpRequest
@cmdsecure
@cmdsecure 2 жыл бұрын
Superb!
@ne5i_
@ne5i_ 2 жыл бұрын
Ooh, also, ‘-it’ in ‘docker run’ means ‘interactive, allocate tty’
@AUBCodeII
@AUBCodeII 2 жыл бұрын
It is also a great mnemonic: "run IT"
@ctf59
@ctf59 2 жыл бұрын
Creating a CSRF to force the victim to navigate to pages and send us the date, read his email to discover an S3 Domain "date" or "data" ?) спасибо за видео.
@sand3epyadav
@sand3epyadav 2 жыл бұрын
I always see your terminal, when you open burpsuite and send any reqwest using burp, suddenly red light poped... how?....
@MohammedElamineHalia
@MohammedElamineHalia 2 жыл бұрын
hacking is the next gaming
@ijustcantseeit
@ijustcantseeit 2 жыл бұрын
This could actually be a pretty accurate insight I think
@MohammedElamineHalia
@MohammedElamineHalia 2 жыл бұрын
@@ijustcantseeit yeah when you take a look at the metaverse and what the future holds you'll say its inventable that everyone must learn hacking and security
@takeshikovacs1081
@takeshikovacs1081 2 жыл бұрын
awesome! thanks for sharing
@ingresssmurf5120
@ingresssmurf5120 2 жыл бұрын
Thanks man
@declanmcardle
@declanmcardle 2 жыл бұрын
t means allocate tty/pty in run/start/exec commands, t means tag in build
@MD4564
@MD4564 2 жыл бұрын
Full Stack = Full Stocker Developer
@pythonxsecurity8287
@pythonxsecurity8287 2 жыл бұрын
i work in another method but gg you have good idea good work bro you are the best
@spandexvortex1097
@spandexvortex1097 2 жыл бұрын
When you mounted host's '/' to docker's '/mnt' directory, and put the public ssh key in root's .ssh, does it also get written to host's root .ssh?
@muhammadghareeb399
@muhammadghareeb399 2 жыл бұрын
u r the best
@GC-rg6in
@GC-rg6in 2 жыл бұрын
Why did you not search for 200 codes in the vhost gobuster output?? Thanks
@helyosis1509
@helyosis1509 2 жыл бұрын
I didn't really understand the privesc part, if a docker container has access to the docket command, it doesn't create containers inside the container but create them on the host instead ?
@ne5i_
@ne5i_ 2 жыл бұрын
Pretty much! If you look at when he opens the docker-compose file, you can see that the host’s docker socket is mounted as a volume in the container. By default, volumes are read/write, so the container can create containers on the host
@ne5i_
@ne5i_ 2 жыл бұрын
If you look into the software ‘portainer’, this is the way it works!
@troopsleader4066
@troopsleader4066 2 жыл бұрын
What can i learn before starting with HACK THE BOX??
@AUBCodeII
@AUBCodeII 2 жыл бұрын
TryHackMe?
@readysetexploit
@readysetexploit 2 жыл бұрын
TryHackMe, and/or overthewire, HTB also has academy modules and a starting point module for beginners
@sand3epyadav
@sand3epyadav 2 жыл бұрын
Hack the box academy, i am vip user from 1 year.
@xXThePr0Xx
@xXThePr0Xx 2 жыл бұрын
You can just escape docker containers to the host that easily?
@ippsec
@ippsec 2 жыл бұрын
In this case yes, because the docker container was allowed to spawn other docker containers.
@xXThePr0Xx
@xXThePr0Xx 2 жыл бұрын
@@ippsec okay crazy, didn't know that
@kiriappeee
@kiriappeee 2 жыл бұрын
This is why you never run docker in docker if you can help it. When can you expect this irl? With kubernetes, a lot of people are putting their deployment pipelines, CICD infra into kubernetes itself because you get easy "scalability"; each build runs in its own docker container. Injecting code into a build, or finding a poorly configured instance presents a chance you can get code execution into a build container which could end up having the privileges needed. A lot of this has been patched now in most tools but one slip up in configuration and an attacker could find what they need. Can't say much more given Google's acceptable content guidelines. I'll just say that that I evaluated this attack path when considering build tools where I work and this was a real world attack path that came up.
@crusader_
@crusader_ 2 жыл бұрын
Where are the timestamps
@ippsec
@ippsec 2 жыл бұрын
Look in the description, where they should be :) Just busy with an event this weekend and didn't have time to create the timestamps.
@ismailarame3756
@ismailarame3756 2 жыл бұрын
first comment :)
@Thiesi
@Thiesi 2 жыл бұрын
Nice - really, really nice!
@biswajitdutta6063
@biswajitdutta6063 2 жыл бұрын
Comment
@declanmcardle
@declanmcardle 2 жыл бұрын
@1:00:02 - look! DEAD BEEF :-)
HackTheBox - Shibboleth
44:22
IppSec
Рет қаралды 18 М.
HackTheBox - Overflow
1:31:42
IppSec
Рет қаралды 18 М.
How I Turned a Lolipop Into A New One 🤯🍭
00:19
Wian
Рет қаралды 11 МЛН
龟兔赛跑:好可爱的小乌龟#short #angel #clown
01:00
Super Beauty team
Рет қаралды 30 МЛН
HackTheBox - Secret
49:26
IppSec
Рет қаралды 24 М.
HackTheBox - Toby
2:06:08
IppSec
Рет қаралды 23 М.
HackTheBox - Devzat
1:02:44
IppSec
Рет қаралды 16 М.
Enter The Arena: Simplifying Memory Management (2023)
1:47:50
Ryan Fleury
Рет қаралды 44 М.
HackTheBox - Backdoor
38:24
IppSec
Рет қаралды 75 М.
HackTheBox - AdmirerToo
58:09
IppSec
Рет қаралды 15 М.
JavaScript Fighting Game Tutorial with HTML Canvas
3:56:20
Chris Courses
Рет қаралды 7 МЛН
HackTheBox - Sink
1:13:55
IppSec
Рет қаралды 20 М.
Clean Code - Uncle Bob / Lesson 1
1:48:42
UnityCoin
Рет қаралды 1,9 МЛН
HackTheBox - Magic
57:06
IppSec
Рет қаралды 28 М.
How I Turned a Lolipop Into A New One 🤯🍭
00:19
Wian
Рет қаралды 11 МЛН