HackTheBox - CozyHosting

  Рет қаралды 13,386

IppSec

IppSec

Күн бұрын

Пікірлер: 27
@clarb027
@clarb027 7 ай бұрын
Have you ever considered using a base32 encoded bash shell instead of base64? It can have = for padding of course but no + because of the chars used.
@thepracticesquad2716
@thepracticesquad2716 7 ай бұрын
Hey IPpsec have u thought about doing a series on getting started ? Like how to llearn from square one.
@lool7922
@lool7922 7 ай бұрын
always the best to explain things very clearly. Thanks 👍👍👍
@lonelyorphan9788
@lonelyorphan9788 7 ай бұрын
Ippsec rocks!!! 🙂
@dollarboysushil
@dollarboysushil 7 ай бұрын
what is that kracken used for hash cracking?
@GajendraMahat
@GajendraMahat 7 ай бұрын
I think, it's a ippsec host machine. He ran Linux in VM and ssh to the host machine for cracking hashes ❤
@nournote
@nournote 7 ай бұрын
A machine of his equipped with a GPU so he can crack passwords
@monKeman495
@monKeman495 7 ай бұрын
@@GajendraMahat may be he setup 10 parallel rtx 4090 rig on cloud
@0xPr3d4T0r
@0xPr3d4T0r 3 ай бұрын
@@monKeman495 it says 1080 tho
@james_nt
@james_nt 5 ай бұрын
i actually learn lots of tip & trick from you. thanks !!!
@AUBCodeII
@AUBCodeII 6 ай бұрын
Sorry Ipp, but aren't you mistakenly calling "/..;/manager" off-by-slash at 4:55? I think you called this technique URL confusion during RegistryTwo. I think off-by-slash is when you do "/assets../flag.txt" or something, like you explained in Cybermonday. Unless "/..;/manager" is also considered off-by-slash. Please do not take offense as I just want to figure out which technique is which. My broken English doesn't help as well, lol. Thanks!
@ippsec
@ippsec 6 ай бұрын
I'm not positive but I think I made the mistake in RegistryTwo just because I didn't know the term "Off By Slash". The Off By Slash is when the location in NGINX doesn't have a trailing slash. I am 80% sure that for /..;/ to work, nginx has to have this vulnerability. The difference between ../ and ..;/ is just the nginx setup you are exploiting.
@AUBCodeII
@AUBCodeII 6 ай бұрын
@@ippsec I see. Thank you very much for the response! You rock! :)
@monKeman495
@monKeman495 7 ай бұрын
proper fingerprinting wins the race every time like we saw springboot enumeration
@anonymousvevo8697
@anonymousvevo8697 7 ай бұрын
Unbelievably good
@Macj707
@Macj707 6 ай бұрын
CHEF CRISP WUZ HERE! Thanks for all you do!
@GajendraMahat
@GajendraMahat 7 ай бұрын
i was waiting for your video 🥰
@AUBCodeII
@AUBCodeII 7 ай бұрын
Hey Ipp, what's 9 + 10?
@tg7943
@tg7943 7 ай бұрын
Push!
@garrag8421
@garrag8421 7 ай бұрын
Oh i had tried it)))) just yesterday
@ruycr4ft
@ruycr4ft 7 ай бұрын
First :P
@highlights973
@highlights973 7 ай бұрын
ippsec i need to start a channel like yours any tip so i dont make mistake
@perfectshow-bx1ov
@perfectshow-bx1ov 7 ай бұрын
Sir also solve the active machines instead of retired 😁😁😁
@ippsec
@ippsec 7 ай бұрын
That’s against the terms of HTB
@sleepymarauder4178
@sleepymarauder4178 7 ай бұрын
Where's the challenge if you get the answers. Retired are great for learning and having some aid
HackTheBox - AppSanity
1:27:34
IppSec
Рет қаралды 14 М.
HackTheBox - Codify
35:00
IppSec
Рет қаралды 12 М.
An Unknown Ending💪
00:49
ISSEI / いっせい
Рет қаралды 57 МЛН
How To Get Married:   #short
00:22
Jin and Hattie
Рет қаралды 23 МЛН
Amazing Parenting Hacks! 👶✨ #ParentingTips #LifeHacks
00:18
Snack Chat
Рет қаралды 23 МЛН
HackTheBox - Crafty
26:17
IppSec
Рет қаралды 12 М.
HackTheBox - Devvortex
41:00
IppSec
Рет қаралды 13 М.
HackTheBox - Rebound
1:25:08
IppSec
Рет қаралды 13 М.
HackTheBox - Backdoor
38:24
IppSec
Рет қаралды 75 М.
Solving distributed systems challenges in Rust
3:15:52
Jon Gjengset
Рет қаралды 243 М.
HackTheBox - Blackfield
1:13:14
IppSec
Рет қаралды 37 М.
HackTheBox - Awkward
2:01:09
IppSec
Рет қаралды 17 М.
HackTheBox - FormulaX
1:24:02
IppSec
Рет қаралды 10 М.
HackTheBox - Builder
1:12:42
IppSec
Рет қаралды 12 М.
An Unknown Ending💪
00:49
ISSEI / いっせい
Рет қаралды 57 МЛН