HSCTF - Obfuscated JavaScript (JSF**k) [Verbose]

  Рет қаралды 23,103

John Hammond

John Hammond

Күн бұрын

Пікірлер: 27
@Zwedgy
@Zwedgy 5 жыл бұрын
Cool to see my code in action!
@abdarafi
@abdarafi 5 жыл бұрын
Your sense of humor is quite interesting pal xD
@cravisbouyin4864
@cravisbouyin4864 3 жыл бұрын
Thanks John for the tip to win some of the challenges! Looks super easy when you use the discord server! However running the code on a debugger just to get the flag value looked tough enough, although you got a result in under 8 minutes! 🙂🙂❇👌
@jasonlough6640
@jasonlough6640 4 жыл бұрын
You could have just added debugger; to the end of the text file. Or, you could have looked at the network panel, checked preserve log, and looked at the request. By putting it in that (4th?) party tool, it ran in a node env, and thats why the error about window showed. My point is: theres too much reliance on unnecessary tools. Its like a gun. It gives you the illusion of security. Instead, learn the tools, in this case, javascript and its environment in the browser. That is so much more useful in more situations than always reaching for extensions / plugins / other tools like a script kiddie would.
@Zooiest
@Zooiest 2 жыл бұрын
You can just copy the text from the end to the matching bracket and execute that. It'll give you the original code.
@lxa1121
@lxa1121 5 жыл бұрын
Are you going to be doing any more from hsctf? That was a pretty fun ctf.
@_JohnHammond
@_JohnHammond 5 жыл бұрын
Absolutely, I have LOTS more ready and available to be released. Just a matter of spreading them out for the KZbin's sake. Thanks for watching! :D
@lxa1121
@lxa1121 5 жыл бұрын
@@_JohnHammond Cant' wait to see how you solved a few of them. And no problem. Your videos are very informative.
@yunusemrahdursun6317
@yunusemrahdursun6317 5 жыл бұрын
I learned new something about js thank you
@mrtommy9220
@mrtommy9220 5 жыл бұрын
Great stuff!!
@ashutoshpanda4336
@ashutoshpanda4336 5 жыл бұрын
Can You Please please walk through the procedure how did you get the zsh shell.... Please
@cyrilhancock3885
@cyrilhancock3885 3 жыл бұрын
chsh -s /bin/zsh
@JASDKA1
@JASDKA1 5 жыл бұрын
Was looking for something related. I see you uploaded it twice...?!
@ffork7803
@ffork7803 5 жыл бұрын
Can u show us what basic tools to use in ctf?
@sakisekiz
@sakisekiz 2 жыл бұрын
johnmohammed
@davidpanic
@davidpanic 5 жыл бұрын
There's also a tool called jsunfuck that you can use.
@csutka53
@csutka53 3 жыл бұрын
cool cli
@allanmarks2150
@allanmarks2150 5 жыл бұрын
Obfuscated JavaScript that is this easy to see can hardly be called Obfuscated. I have a complex pure client side JavaScript program and I am just waiting for somebody to find a way to truly obfuscate it without rewriting it, or have it run on a server without rewriting it. I know there are ways to write JS so that it can run on either a server or a desktop, but everything thing I have looked at so far requires a major rewrite of what I have already written.
@TheNewton
@TheNewton 5 жыл бұрын
Easy to see != easy to read or interpret without tools. Thus it's obfuscated by nature of being difficult for humans to parse.
@wardijien_official149
@wardijien_official149 3 жыл бұрын
tqqqqqqqq
@lifebarier
@lifebarier 5 жыл бұрын
First challenge to join discord... That is not easy. I would need to get my laptop, run virtual machine on it, go to public network, download discord, run it... They should be using jabber/irc instead of promoting that crap.
@cros108
@cros108 5 жыл бұрын
why would you need to use a virtual machine on a public network on a laptop lmao, scared the discord staff are gonna hack you by using their service?
@lifebarier
@lifebarier 5 жыл бұрын
@@cros108 I do not trust discord. And don't even try to change my mind mr glows in the dark.
@inx1819
@inx1819 5 жыл бұрын
@@lifebarier lmao you're weird af
@lifebarier
@lifebarier 5 жыл бұрын
@@inx1819 not wanting to use poorly codded, closed, tracking software is weird these days... Truly peak clown world. Go get some soycaf.
@inx1819
@inx1819 5 жыл бұрын
@@lifebarier discord is used by millions of people, it went through multiple security audits, it's trusted by many people and it never had any major hack or exploit. It's like not wanting to use google. Also, everything tracks you. Even if Discord would track you, other websites would as well. KZbin does it - and yet you're here Stop being so paranoid.
HSCTF - Hiding in ZIP Files (LockedUp)
4:23
John Hammond
Рет қаралды 6 М.
Nested JavaScript Obfuscation - GuidePoint Security CTF Challenge
33:33
MAGIC TIME ​⁠@Whoispelagheya
00:28
MasomkaMagic
Рет қаралды 38 МЛН
ЗНАЛИ? ТОЛЬКО ОАЭ 🤫
00:13
Сам себе сушист
Рет қаралды 4,1 МЛН
ROSÉ & Bruno Mars - APT. (Official Music Video)
02:54
ROSÉ
Рет қаралды 297 МЛН
JScript Deobfuscation - More WSHRAT (Malware Analysis)
1:02:01
John Hammond
Рет қаралды 59 М.
The Weird History of JavaScript
12:09
Fireship
Рет қаралды 1,2 МЛН
Reverse Engineering Obfuscated JavaScript
14:04
LiveOverflow
Рет қаралды 154 М.
How To Predict Random Numbers Generated By A Computer
13:54
PwnFunction
Рет қаралды 554 М.
IFrame Parent XSS - HackTheBox Cyber Apocalypse CTF
32:03
John Hammond
Рет қаралды 72 М.
The Vim Experience
45:19
Bog
Рет қаралды 155 М.
HSCTF -  XORing Data (Hidden Flag)
7:39
John Hammond
Рет қаралды 17 М.
I broke JavaScript (JSF**k)
3:31
A Byte of Code
Рет қаралды 92 М.
The Art of Code - Dylan Beattie
1:00:49
NDC Conferences
Рет қаралды 4,7 МЛН
MAGIC TIME ​⁠@Whoispelagheya
00:28
MasomkaMagic
Рет қаралды 38 МЛН