HackTheBox - Forge

  Рет қаралды 24,441

IppSec

IppSec

Күн бұрын

00:00 - Intro
01:00 - Running nmap finding a filtered port with some open ones
03:30 - Running GoBuster to always have something running in the background
05:00 - Playing with the Upload Form
07:20 - Playing with the Upload from URL to see what library connects back to us (SSRF)
09:30 - The Upload From URL has a blacklisted address, playing with it to discover what is blacklisted
10:55 - Bypassing the URL Blacklist in the SSRF by changing the case of words
11:45 - Running a virtualhost bruteforce within gobuster to discover vhost
13:10 - Bypassing the URL Blacklist in the SSRF by creating a webserver that will send a redirect
16:50 - Using the SSRF to download admin.forge.htb and discovering ftp creds and another SSRF
18:20 - Using the SSRF to use FTP
19:20 - Encoding the IP Address as hex to bypass a blacklist
22:10 - When specifying a directory in the FTP with SSRF need a trailing slash explaining why
23:10 - Downloading id_rsa and then logging into the machine
24:10 - The user can sudo run a python script, which stands up a debugger on a random port
26:13 - Doing a nested tmux so we can run the python script and then use netcat to connect
28:50 - Getting root
30:55 - Explaining how to harden the blacklist to prevent the easy bypassing
34:30 - Looking at how admin.forge.htb added FTP Support
36:50 - Thinking there's an RCE but there isn't, shlex is a good filter
44:30 - Getting frusterated, lets break this down and see whats stopping our RCE
45:40 - Playing with Shlex to discover it is what prevents the RCE

Пікірлер: 37
@randomguy3784
@randomguy3784 2 жыл бұрын
The 'Beyond Root' portion was extremely enjoyable! 😇👌
@damnmayneunfiltered
@damnmayneunfiltered 2 жыл бұрын
yep. kept me watching the whole 48 minutes
@mertfromhell
@mertfromhell 2 жыл бұрын
you are an absolute legend bruh no matter how much time passes you still doing this stuff even now
@swapnilbhosale2230
@swapnilbhosale2230 2 жыл бұрын
Amazing. We as a community owe you my man.
@atefbouallegue605
@atefbouallegue605 2 жыл бұрын
Today i learned that you can do SSRF inside of an SSRF 🥳 Thanks Ipp 🙏
@damnmayneunfiltered
@damnmayneunfiltered 2 жыл бұрын
2:26 MVC is both a methodology for software engineering and a mindset. model is thought of as the brains of the application, view is though of as what the end user sees, and controller makes the model and the view work together. This way, you can change something in the logic of the app without changing the view or the other way around. its handy when your application is going to be very large.
@abdirahmann
@abdirahmann 2 жыл бұрын
This was beautiful to watch :)
@sand3epyadav
@sand3epyadav 2 жыл бұрын
Nice Video sir, you are my best teacher....
@morphein
@morphein 2 жыл бұрын
the last part was super cool, I like that you try things and they don't work, it's even better than success LOL
@pampipipi8254
@pampipipi8254 2 жыл бұрын
Love you man
@MrMeLaX
@MrMeLaX 2 жыл бұрын
Thanks a lot for your work
@techtutorials7026
@techtutorials7026 2 жыл бұрын
Thanks for video
@tomasofficial.
@tomasofficial. 2 жыл бұрын
I had to say goodbye to my main linux machine.. storage error. So sad, I had everything set-up. Damn. But, new machine = better knowledge so kinda gg : ) nice video, wow.
@PrinceHigu
@PrinceHigu 2 жыл бұрын
Would you mind sharing your Machine Specifications? For the physical machines (kraken and others) you use and the hardware allocation of VMs as well?
@SaadiBabar
@SaadiBabar 2 жыл бұрын
Great video and got new things to learn , Thank you.
@saurabhshinde1855
@saurabhshinde1855 2 жыл бұрын
Netcat redirect request crafting stuff was awesome.. So much to learn from you Ippsec.. Please keep it up
@extravenger9137
@extravenger9137 2 жыл бұрын
Great as always. Ippsec is there any chance we could have a new video on AV Evasion? it would be really cool to learn more about this subject, ik there are so many around the internet, but the way you describe things, i got used to it xD
@ippsec
@ippsec 2 жыл бұрын
If you use ippsec.rocks, I'm sure you can find a method that still works.
@defyteryt2452
@defyteryt2452 2 жыл бұрын
Nice
@flipponator
@flipponator 2 жыл бұрын
Just wondering: Is the time in your VM off, or do you just like to record the videos at night time?
@mathiasensimon
@mathiasensimon 2 жыл бұрын
It might be an am/pm clock
@ippsec
@ippsec 2 жыл бұрын
Time is correct in my VM. This video I was recording at 1am as it was just a busy week and couldn’t squeeze it in anywhere unless I just sacrificed sleep. I’m normally in bed by 10 or 11.
@innerfire369
@innerfire369 2 жыл бұрын
Hello IppSec, I watch almost all of your videos and can I ask you to make more about Active Directory attacks. Thanks!
@theebanb5183
@theebanb5183 2 жыл бұрын
what is the keyboard shortcut to send requests to server from burp repeater tab?
@ippsec
@ippsec 2 жыл бұрын
Go to ippsec.rocks and type in "burp repeater"
@sreyanchakravarty7694
@sreyanchakravarty7694 2 жыл бұрын
Thanks for the video
@israelrabi5016
@israelrabi5016 2 жыл бұрын
what distro you use?
@velomeister
@velomeister 2 жыл бұрын
He uses Parrot OS.
@israelrabi5016
@israelrabi5016 2 жыл бұрын
@@velomeister thanks
@souleymaneadellah1176
@souleymaneadellah1176 2 жыл бұрын
An Ipssec vid? Thats my afternoon sorted
@MoeJama5454
@MoeJama5454 2 жыл бұрын
Long videos but worth it
@prakasakatheilluminator6904
@prakasakatheilluminator6904 2 жыл бұрын
Why i like ippsec's videos more than any other youtube cuz ippsec show every single method which is available in Box...
@damnmayneunfiltered
@damnmayneunfiltered 2 жыл бұрын
I didnt like this box.
@AUBCodeII
@AUBCodeII 2 жыл бұрын
What's going on KZbin, this is ippsec and I'm gonna pin this comment for no reason.
@skinnyelephant7351
@skinnyelephant7351 2 жыл бұрын
shlex.quote was the most fun part, when we (myself and you) could have just googled/stackoverflow it more, but spent time fuzzing it too much and then finally realizing its for input sanitization. lolllllllllllllllll anyways, like always, this was great to learn.
@ippsec
@ippsec 2 жыл бұрын
Yeah Google returned a lot of fancy words at first and scared me away. Just goes to show ho much more you can learn after getting the root flag
@skinnyelephant7351
@skinnyelephant7351 2 жыл бұрын
@@ippsec 💝💝💝
HackTheBox - Pikaboo
42:27
IppSec
Рет қаралды 21 М.
HackTheBox - OpenAdmin
1:20:41
IppSec
Рет қаралды 43 М.
Женская драка в Кызылорде
00:53
AIRAN
Рет қаралды 470 М.
Double Stacked Pizza @Lionfield @ChefRush
00:33
albert_cancook
Рет қаралды 85 МЛН
A clash of kindness and indifference #shorts
00:17
Fabiosa Best Lifehacks
Рет қаралды 125 МЛН
50 YouTubers Fight For $1,000,000
41:27
MrBeast
Рет қаралды 199 МЛН
HackTheBox - Backdoor
38:24
IppSec
Рет қаралды 75 М.
HackTheBox - AdmirerToo
58:09
IppSec
Рет қаралды 15 М.
HackTheBox - Secret
49:26
IppSec
Рет қаралды 23 М.
AES: How to Design Secure Encryption
15:37
Spanning Tree
Рет қаралды 154 М.
AMD's Macbook Moment.
15:30
Hardware Canucks
Рет қаралды 41 М.
Beginner's Guide to the Bash Terminal
1:14:37
Joe Collins
Рет қаралды 2,3 МЛН
HackTheBox - Napper
1:24:46
IppSec
Рет қаралды 10 М.
The moment we stopped understanding AI [AlexNet]
17:38
Welch Labs
Рет қаралды 789 М.
HackTheBox - Anubis
1:42:25
IppSec
Рет қаралды 95 М.
HackTheBox - Stacked
1:00:05
IppSec
Рет қаралды 17 М.
Женская драка в Кызылорде
00:53
AIRAN
Рет қаралды 470 М.