PHP 8.1.0-dev BACKDOOR Hack (Easy RCE)

  Рет қаралды 143,710

John Hammond

John Hammond

Күн бұрын

Пікірлер: 137
@_JohnHammond
@_JohnHammond 2 жыл бұрын
Ps, HUGE THANKS to Snyk for sponsoring this video ! Snyk is putting together their next Capture the Flag 101 workshop! If you are new to CTF challenges and want some extra guidance on how to cut through binary exploitation or web security tasks, jump into their free online session on September 14th at 11am EDT! j-h.io/snyk-ctf101 click the link plz click it CLICK THE LINK j-h.io/snyk-ctf101 click click click
@nighthawk5305
@nighthawk5305 2 жыл бұрын
Click a posted link, enter "Name", "Company E-Mail", "Company Name" and "Job Title" to register..... Not comfortable with that.
@link_safe
@link_safe 2 жыл бұрын
@@nighthawk5305 It's designed for businesses and companies.
@Fl0kii_
@Fl0kii_ 2 жыл бұрын
I could watch John explaining Python code for the rest of my life!
@caiovinicius8448
@caiovinicius8448 2 жыл бұрын
It's a good idea.
@nikhilsuryanarayanan2133
@nikhilsuryanarayanan2133 2 жыл бұрын
😂nice
@Propertymagnet_boy
@Propertymagnet_boy 2 жыл бұрын
why?
@spiegelbestseller9853
@spiegelbestseller9853 2 жыл бұрын
Me too
@jasonb2221
@jasonb2221 2 жыл бұрын
Thanks John, your way of teaching, explaining while you're working on the fly is awesome! Really teaches us how to think and react while troubleshooting.
@zanidd
@zanidd 2 жыл бұрын
Thank you -John- Kevin!
@Scorpion_Yug
@Scorpion_Yug 6 ай бұрын
Zanidd ❤
@dayanjihuzefa1827
@dayanjihuzefa1827 2 жыл бұрын
Your channel is best source to learn Cybr security 👍
@michaelwerkov3438
@michaelwerkov3438 2 жыл бұрын
Its fun how i know nothing about hacking but when he explains things it makes perfect sense
@bs12wrblimitedsti38
@bs12wrblimitedsti38 2 жыл бұрын
I just got my A+, Net+, Sec+ and man there’s SOOO much more to learn haha maybe I’ll under more with time but 80% of the video I know. Just now I have to figure out how to implement everything I learned. Hands on is WAY better for me! Thank you for what you do hopefully one day I will be kind of close to on your level of knowledge.
@flaviomoreira01
@flaviomoreira01 2 жыл бұрын
The more you know the more there is to know. Do you think it is good idea to get CEH cert has my first cert?
@johnpathe
@johnpathe 2 жыл бұрын
@@flaviomoreira01 yes
@Smithy957
@Smithy957 2 жыл бұрын
@@flaviomoreira01 the OSCP is so much better than the CEH
@flaviomoreira01
@flaviomoreira01 2 жыл бұрын
@@Smithy957 I have heard that it is harder to get it, but what is the requirement?
@flaviomoreira01
@flaviomoreira01 2 жыл бұрын
@@zebbybobebby But in terms of reputation, would you agree that CEH is more advanced?
@jimo8486
@jimo8486 2 жыл бұрын
this is the only ad sponsor i would watch
@analyzec137
@analyzec137 2 жыл бұрын
Glad to hear about the snyk ctf webinar John.... can’t wait XD
@daleryanaldover6545
@daleryanaldover6545 2 жыл бұрын
I just remembered when I first CTF like experience with Kirshbaum. They have a challenge for job applicants and successfully doing the challenge grants them a chance for an interview. I failed the interview tho but it was a fun experience nonetheless.
@ponan0053
@ponan0053 2 жыл бұрын
Could you do a video on how you make these challenges? like the thought process and steps behind it? I think thatd be awesome
@cnfreitas
@cnfreitas 2 жыл бұрын
Look, I'm not into security but I could not pass this video. Very interesting and made easy to understand some Linux command lines and strategies to find problems. Thanks!
@mohammedbahamid8759
@mohammedbahamid8759 2 жыл бұрын
It would really be awesome if you could make a video on how to create a CTF challenge based on the vulnerabilities on Exploit DB. The way to navigate through exploit DB, the thinking process, etc...
@khaleedmayas
@khaleedmayas Жыл бұрын
+1
@cheeseIT1992
@cheeseIT1992 2 жыл бұрын
You never disappoint, thanks John!
@Zerback
@Zerback 2 жыл бұрын
Great content John! Thanks for all your shared knowledge as usual!
@TheHaircutFish
@TheHaircutFish 2 жыл бұрын
Awesome vid John!!!
@huzifaahmed1426
@huzifaahmed1426 2 жыл бұрын
I learn alot from you man 💚
@NicolaCalore
@NicolaCalore 2 жыл бұрын
Thanks John for teaching me 👾
@GeorgeWulfers_88
@GeorgeWulfers_88 2 жыл бұрын
Awesome! :) Great video as always.
@joaoverde7742
@joaoverde7742 2 жыл бұрын
I loved the office reference :D
@anthonylamoreaux1282
@anthonylamoreaux1282 2 жыл бұрын
Love your videos! Thank you for all that you do.
@JoakimKanon
@JoakimKanon 2 жыл бұрын
May I suggest backing off from the mic, or getting a pop filter? Your P’s are pretty brutal on headphones. Great video, anyways. 😍
@moustafakashen3610
@moustafakashen3610 2 жыл бұрын
Love your content Mr. Hammond
@mrobvious6112
@mrobvious6112 2 жыл бұрын
Its crazy how simple it is to understand python ven though I barely learned python Not really as simple but getting use to how it works makes it simple enough to understand...
@huzifaahmed1426
@huzifaahmed1426 2 жыл бұрын
The Greatest man in this feild ❤❤❤
@renatofreirefilho
@renatofreirefilho 2 жыл бұрын
Obrigado, sempre ótimos conteúdos!
@danielghani3903
@danielghani3903 2 жыл бұрын
Thank you for the video suggestions .I will go through one by one
@DEADCODE_
@DEADCODE_ 2 жыл бұрын
you know what john i love you
@Freeak6
@Freeak6 2 жыл бұрын
One thing I don't understand is why root user in container has root privileges in host filesystem? These shouldn't be treated as different users? To me, users in containers shouldn't 'communicate' with users in host. Why is it the case? Thanks :)
@sdafasfF
@sdafasfF 2 жыл бұрын
Real cool man! Although I completed the box within 3 minutes X3
@0xmkay
@0xmkay 2 жыл бұрын
Pls was the workshop session recorded cos I missed it
@christophermarshall8712
@christophermarshall8712 Жыл бұрын
This is why I never upgrade to a version of PHP when it first comes out. I always stay one or two behind if I can to make sure if any severe vulnerabilities like this come out they are fixed before they can affect me.
@frosecold
@frosecold 2 жыл бұрын
Hey John, I've been using rustscan lately and i really like it, is. Slot faster and can be complemented with nmap for full scans but is much faster. I wonder why you don't use it?
@djones0105
@djones0105 2 жыл бұрын
thanks, John!
@branisgreat
@branisgreat 2 жыл бұрын
The hair in front of his face the entire time man lmao
@aquaforgegames6207
@aquaforgegames6207 2 жыл бұрын
I've always wanted to get into whitehat hacking and this is the best video I've seen so far about it. You're amazing
@badbgp
@badbgp 2 жыл бұрын
Zerodium ~ Zero Diem ~ Zero Day
@vipanchika5059
@vipanchika5059 5 ай бұрын
Thank you sir you would have been intresting to me to become a good business man
@CageTheTurtle
@CageTheTurtle 2 жыл бұрын
what up KEVIN!!
@georgehammond867
@georgehammond867 2 жыл бұрын
what is proc in Linux directories? and why does its size be 140 TB ,, which system uses that huge amount of memory in the tera bytes?
@caiovinicius8448
@caiovinicius8448 2 жыл бұрын
Very interesting.
@0xm3m
@0xm3m 2 жыл бұрын
Can you make a video on Creating vulnerable machines for hacking platforms in depth, and that can be in series?
@michaelwerkov3438
@michaelwerkov3438 2 жыл бұрын
What is verbosity in this context?
@learnfirst-1
@learnfirst-1 2 жыл бұрын
Apache tomcat 8.5.58 vuln ??
@kekeke7815
@kekeke7815 2 жыл бұрын
Hey, I just wanted to check briesofty if there is a way for to import a new soft into the program, for example softs or sotNice tutorialng that
@ALD7MI2011
@ALD7MI2011 2 жыл бұрын
I learned alot thanks
@Terszel
@Terszel 2 жыл бұрын
Think I remember when this backdoor went up, wasn't it a big thing?
@elisansabimana6200
@elisansabimana6200 2 жыл бұрын
Thanks for the video.
@nelaina
@nelaina 2 жыл бұрын
Thank you John. Do you think the snyk ctf webinar is good for an absolute beginner? No ctf experience (aside from your channel), and just starting to learn python, cybersec, etc...thanks.
@cartoonchannel5584
@cartoonchannel5584 2 жыл бұрын
You are best ;) Thank You !!!!!!!!!!!!!!!!
@themasterofdisastr1226
@themasterofdisastr1226 2 жыл бұрын
Last year, this exploit was featured in HackTheBox when it was quite new. You had to understand a chinese Blog post to get the shell back then
@ihsankurniawan3591
@ihsankurniawan3591 2 жыл бұрын
how do you know what to search? what if i cannot tell if PHP 8.1.0-dev is the keyword?
@judylyons177
@judylyons177 2 жыл бұрын
Sorry, not on this subject. Any advice of how to get rid of Instant Memo? It is messing my tablet up. Tried numerous ways to uninstall, can't. Force stop, clear cache doesn't even slow it down. I can't find any info on it.
@MrsCyImsofly
@MrsCyImsofly 2 жыл бұрын
Thank you John
@onen0zednine753
@onen0zednine753 2 жыл бұрын
so who caught the 'Kevin/ Office' refence at the beginning?
@Alisson-Faoli
@Alisson-Faoli 2 жыл бұрын
yeah!!! "Why use more words when less do trick?" 🤣🤣🤣🤣🤣🤣
@onen0zednine753
@onen0zednine753 2 жыл бұрын
@@Alisson-Faoli
@soniablanche5672
@soniablanche5672 2 жыл бұрын
I don't get it, why would you intentionally add a backdoor to php.
@Freeak6
@Freeak6 2 жыл бұрын
It was made by an attacker who compromised git php's servers. So the attacker will have a backdoor on all servers that run this version of php (so possibly millions of servers if the attack had not been detected).
@mathesonstep
@mathesonstep 2 жыл бұрын
Can you do a video on setting up a VM for doing these challenges, I have wanted to do these challenges for a while but want to ensure I am being as safe as possible as I have heard you are all connecting to the same VPN network I want to ensure my vm is as isolated as possible, I was thinking putting my vm behind a virtualized pfSense and blocking access to my network from that pfSense firewall. Am I overthinking this or should I really dedicate one vm and virtual network setup to just CTF challenges?
@eandudley8415
@eandudley8415 2 жыл бұрын
Just throw up a kali machine on VMware.
@dopy8418
@dopy8418 2 жыл бұрын
What's with the marvin villain thumbnail ?
@sdafasfF
@sdafasfF 2 жыл бұрын
Every happened to the Ubuntu install?
@WanderlustVisual5
@WanderlustVisual5 2 жыл бұрын
Good stuff
@aqsajimmy2803
@aqsajimmy2803 2 жыл бұрын
did u already create an exploite sir ?
@brian.-_393i3.-_
@brian.-_393i3.-_ 2 жыл бұрын
Thanks!
@khaleedmayas
@khaleedmayas Жыл бұрын
anyone tried to get rev shell on the machine or could ?
2 жыл бұрын
What I'm really struck by is that it was _planted_, by a security firm that sells exploits no less... wow
@animesubber7136
@animesubber7136 2 жыл бұрын
Whats with the thumbnail lol John Hammond Breaking bad XD
@gauthamgamer1214
@gauthamgamer1214 2 жыл бұрын
nice one
@wcrb15
@wcrb15 2 жыл бұрын
Whoa that seems really bad. Gonna have to go do some more research on that user agentt situation
@guilherme5094
@guilherme5094 2 жыл бұрын
Thanks.
@12346798Mann
@12346798Mann 2 жыл бұрын
The webpage looks like an appseed template
@FidelEmilioSusanaJimenez
@FidelEmilioSusanaJimenez 2 жыл бұрын
👽😍😍😍
@plooshdev
@plooshdev 2 жыл бұрын
nice
@Rantofthings.
@Rantofthings. 4 ай бұрын
I’m guessing I need to know PHP.
@kevinwong_2016
@kevinwong_2016 2 жыл бұрын
Look for mobile malware please
@fdgmedd
@fdgmedd 2 жыл бұрын
Gj :)
@diegocracker
@diegocracker 2 жыл бұрын
Show thanks obrigado
@juneilquilana5159
@juneilquilana5159 2 жыл бұрын
❤️❤️❤️👏👏👍
@jaume748
@jaume748 2 жыл бұрын
Why I got rickrolled ?¿? I only wanted to do the workshop
@LiEnby
@LiEnby 2 жыл бұрын
LOL'd at this ahaha if you dont provide the "zerodium" at the start of the string it just says "REMOVETHIS: Sold to zerodium in 2017"
@abhishek24506
@abhishek24506 2 жыл бұрын
Php is still important??
@sipintarpatrick
@sipintarpatrick 2 жыл бұрын
why not
@HTWwpzIuqaObMt
@HTWwpzIuqaObMt 2 жыл бұрын
Trying to be funny?
@JustinMylo
@JustinMylo 2 жыл бұрын
@@HTWwpzIuqaObMt it is funny
@henrym5034
@henrym5034 2 жыл бұрын
Wordpress.
@_Omni
@_Omni 2 жыл бұрын
Yes it is
@chris7010_1
@chris7010_1 8 ай бұрын
Astra Linux users can take the hack me challenge.
@azatecas
@azatecas 2 жыл бұрын
to all php devs, jump ship while you still can
@SB-qm5wg
@SB-qm5wg 2 жыл бұрын
php had a backdoor built in. WTF!?
@Freeak6
@Freeak6 2 жыл бұрын
It was a dev version, and from what they showed, it has been caught before going into production.
@InsaneRecords997
@InsaneRecords997 2 жыл бұрын
Watching on sep 27 lol
@pathfinder750
@pathfinder750 2 жыл бұрын
Agent-T
@rebelsdeveloper367
@rebelsdeveloper367 2 жыл бұрын
hmm..
@omari4m
@omari4m 2 жыл бұрын
as a php programmer , feeling so sad
@masdadmin
@masdadmin 2 жыл бұрын
Please laugh a bit so I can see if you sound like Seth Rogen.
@unknown_3293
@unknown_3293 2 жыл бұрын
mp4 mp3 files backdoor
@thispacifist9004
@thispacifist9004 2 жыл бұрын
John your having a laugh arent you with this? I like watching your videos because you are informative. You said at the beginning this was an easy challenge, yet you copy and pasted someone else's code.
@hanomedia
@hanomedia 2 жыл бұрын
*I feel pity for Php Evangelists*
@MrGeekGamer
@MrGeekGamer 2 жыл бұрын
I dropped PHP 19 years ago, because I was awful then and it's still awful now. Stop using PHP.
@tutorialsacc7314
@tutorialsacc7314 2 жыл бұрын
no its not
@MrGeekGamer
@MrGeekGamer 2 жыл бұрын
@@tutorialsacc7314 I won't argue with you, because you're clearly an idiot if you're simping for PHP in 2022.
@cirklare
@cirklare 2 жыл бұрын
I told you PHP is very vulnerable language Also php 5.3 has RCE exploit Another php vulnerability PHP CGI argument injection
@toifel
@toifel 2 жыл бұрын
PHP 5.3 is older than KZbin and this backdoor is using a "-dev" build which no sane person would ever use in production. I'm not even using PHP, but you obviously don't have any clue what you're even talking about.
@whetfaartz6685
@whetfaartz6685 2 жыл бұрын
@@toifel lol you didn't have to do him like that
@tagKnife
@tagKnife 2 жыл бұрын
still using nmap rather then zmap. 2000 called they want their shell script kiddies back.
@alezad57121
@alezad57121 2 жыл бұрын
this is good, enjoyment.exe 😊
@Jax_Malren
@Jax_Malren 2 жыл бұрын
Ah man tryhackme is so fun. Thanks you for developing some fun challenges for us.
catch EVERY reverse shell while hacking! (VILLAIN)
19:03
John Hammond
Рет қаралды 226 М.
Google Ad Promotes Fake Homebrew Malware
24:47
John Hammond
Рет қаралды 37 М.
Непосредственно Каха: сумка
0:53
К-Media
Рет қаралды 12 МЛН
Война Семей - ВСЕ СЕРИИ, 1 сезон (серии 1-20)
7:40:31
Семейные Сериалы
Рет қаралды 1,6 МЛН
this vulnerability shouldn’t even exist
14:33
Low Level
Рет қаралды 241 М.
How Hackers Hide
20:55
John Hammond
Рет қаралды 241 М.
how is this hacking tool legal?
11:42
Low Level
Рет қаралды 465 М.
a Hacker's Backdoor: Service Control Manager
17:49
John Hammond
Рет қаралды 93 М.
Scammers PANIC After I Hack Their Live CCTV Cameras!
23:20
NanoBaiter
Рет қаралды 26 МЛН
Fake ChatGPT Browser Extension Malware Analysis (CyberDefenders)
17:48
Password Cracker with Notepad!
11:41
ebola man
Рет қаралды 812 М.
How Microsoft Accidentally Backdoored 270 MILLION Users
14:45
Daniel Boctor
Рет қаралды 254 М.
ACCESS what you WERE NEVER SUPPOSED TO
14:33
John Hammond
Рет қаралды 66 М.
Making Smallest Possible Linux Distro (x64)
27:43
Nir Lichtman
Рет қаралды 81 М.
Непосредственно Каха: сумка
0:53
К-Media
Рет қаралды 12 МЛН