TryHackMe! SweetRice Exploit & Stabilizing Shells

  Рет қаралды 55,331

John Hammond

John Hammond

Күн бұрын

Пікірлер: 69
@guineapigs2998
@guineapigs2998 4 жыл бұрын
Love how gobuster just chugged along in the background the entire video trying to find more directories/files xD It was on a quest, even if it was no longer needed xD
@_JohnHammond
@_JohnHammond 4 жыл бұрын
It's dangerous to go alone -- take this!
@danauri7186
@danauri7186 4 жыл бұрын
why is ginger Seth Rogan teaching me computer security?
@tswdev
@tswdev 4 жыл бұрын
Go for Gun Gamers if you want a buffed up Seth Rogan teaching you about guns and airsoft lol. They even have the same glasses: v=uZMMAXugI7E
@zartech-info
@zartech-info 4 жыл бұрын
The voice lol. I knew I recognized it.
@WRWhizard
@WRWhizard 2 жыл бұрын
Being a newbie I found the hash easy enough after discovering the directories and crawling around through them. Once I was logged in I did realize I'd have to look for exploits and did find several for SweetRice. At that point I had no idea how do do what I figured I needed to do. So, I read a walk through. Saw I needed to do RCE and get a shell. Bailed out. Later watching YTVids and saw this one. Chuckled a bit at how long it took you to find the SQL backup but then you took off like a rabbit and I had a real hard time following the rest. I kind of learned the script trick for stabilizing a shell a few nights ago but will need to do it a bunch to retain it. Well... at least I know I'm not gonna do this all by myself yet. Have to watch, read and learn some more.
@mi2has
@mi2has 4 жыл бұрын
use of searchsploit and script technique was slick, new tools to learn..cool
@sirw369
@sirw369 4 жыл бұрын
Thanks again for an awesome walkthrough! 💪🏼🙌🏼
@AJXD2
@AJXD2 2 жыл бұрын
Thanks for these videos. I’m learning programming Right Now and you give me motivation to keep going cause one day I might be like you.
@gin263
@gin263 4 жыл бұрын
I just practice My English listening
@mamtachahal1277
@mamtachahal1277 4 жыл бұрын
I love watching those videos, even though I don't understand much
@thecaretaker0007
@thecaretaker0007 4 жыл бұрын
I have been requesting for your stabilize shell script for a long time. Thanks John.
@gametimewitharyan6665
@gametimewitharyan6665 3 жыл бұрын
Brawl Stars
@thecaretaker0007
@thecaretaker0007 3 жыл бұрын
@@gametimewitharyan6665 old logo, I miss it
@gametimewitharyan6665
@gametimewitharyan6665 3 жыл бұрын
@@thecaretaker0007 Ahhh, Old Memories :)
@mattfowler6504
@mattfowler6504 4 жыл бұрын
Great video hope you're doing well don't over work yourself to much!!
@ARZ10198
@ARZ10198 4 жыл бұрын
Just did this box and found your walkthrough for this later xD
@Vogel42
@Vogel42 4 жыл бұрын
11:54 a short way to memorize it is TUNA please: ss -tunapl
@_JohnHammond
@_JohnHammond 4 жыл бұрын
AHAHAH that is awesome. Thanks so much!
@tunatuncer5639
@tunatuncer5639 4 жыл бұрын
wow thanks for that
@yankeesouth
@yankeesouth 3 жыл бұрын
I like this video and I am not just typing this to kick in the Al Go Rhythm
@WheYPrOTeiNProductions
@WheYPrOTeiNProductions 4 жыл бұрын
Your channel is the future man ,u rocks... Make a vídeo teaching us how to join in the rooms of TryHackMe without subscribe, the tools that you use most to do the test. And how we use python, because i se u always open 2 tabs, i want to learn how to do that, sorry but i am a newbie but a love to watch your videos and im learn a lot thanks.
@peterarbeitsloser7819
@peterarbeitsloser7819 4 жыл бұрын
You have to use a terminal emulator called TERMINATOR. Then search for shortcuts.
@samfretus3394
@samfretus3394 4 жыл бұрын
Hey John, I appreciate all your hard work and the content you've been releasing as of late, I am new to the world of pentesting and am learning a great deal from your videos! May I ask what theme you're using for sublime text, I have the default but would love an explanation on how to colour coordinate certain symbols and the like, for a better viewing and typing exp. Cheers man, keep up the great work!
@_JohnHammond
@_JohnHammond 4 жыл бұрын
Very happy to hear that! Thanks so much for watching! I use the `monokai` theme in Sublime Text. If you don't have a file saved with a specific extension and it cannot auto-detect what syntax highlight to use, you can enter Ctrl+Shift+P to enter the Sublime Text prompt and then type in something like "bash" or "python" or "html" to find the option to "Set Syntax Hilighting To" and you can specify what it might highlight the code words with. Hope that helps a bit!
@kkhek
@kkhek 4 жыл бұрын
awesome highquality content. keep going like this 👍🏽
@ElGhadraouiTaha
@ElGhadraouiTaha 4 жыл бұрын
man i just love your videos !!!!
@WheYPrOTeiNProductions
@WheYPrOTeiNProductions 4 жыл бұрын
Where i can find these stabilize shell scripts?
@billgen7663
@billgen7663 4 жыл бұрын
Once again awesome content!
@R4yan-
@R4yan- 4 жыл бұрын
i love this kind of videos ! :)
@ugwsiliguri
@ugwsiliguri 4 жыл бұрын
Ur just awesome
@aiden6343
@aiden6343 4 жыл бұрын
no idea what he is talking about but still find it fum to watch
@bidfca5980
@bidfca5980 4 жыл бұрын
JOHN CAN YOU PLEASE MAKE VIDEOS ABOUT BINARY EXPLOITATION AND ASSEMBLY FOR BEGINNERS? I'VE BEEN STRUGGLING A LOT TO LEARN ABOUT IT. LOVE YOUR VIDS
@gibrael_
@gibrael_ 4 жыл бұрын
Dá uma olhadinha em um canal chamado LiveOverflow. Também tô aprendendo Binary Exploitation, lá encontrei um conteúdo excelente! Ele tem uma playlist só de Assembly pra Iniciantes!
@bidfca5980
@bidfca5980 4 жыл бұрын
@@gibrael_ Opa, vlw pela dica ;)
@solon7740
@solon7740 4 жыл бұрын
How are you running these stabilize shell scripts etc?
@ARZ10198
@ARZ10198 4 жыл бұрын
check out his poor man's pentest video
@chiragsharma6215
@chiragsharma6215 3 жыл бұрын
How do you bring on your own terminal back to tty (after stty raw -echo)?
@lawia8369
@lawia8369 Жыл бұрын
fg %1
@novicetrader555
@novicetrader555 4 жыл бұрын
🔥🔥
@gwnbw
@gwnbw 4 жыл бұрын
14:40 my terminal does weird shit when I try to foreground the session, and getting: "Error opening terminal: unknown. " when trying to modify /etc/copy.sh to get a shell for the root.
@bullybilly4105
@bullybilly4105 2 жыл бұрын
same issue
@gwnbw
@gwnbw 4 жыл бұрын
Amazing vid though 🚩
@gbravy
@gbravy 4 жыл бұрын
What's this setup that you use? Your main machine or something else? It's not a standard Kali vm. Also, it's a much nicer output when using linpeas
@_JohnHammond
@_JohnHammond 4 жыл бұрын
In this video I'm running Ubuntu installed on my laptop, with the Terminator terminal emulator. Thanks for watching!
@t.i.s.r.oofficial7142
@t.i.s.r.oofficial7142 4 жыл бұрын
Guys i want to learn all of this so quickly. How long does it take to learn/study this?
@arminharper510
@arminharper510 4 жыл бұрын
Anywhere between a year and 12 years :p
@nero2k619
@nero2k619 4 жыл бұрын
After 3 months you should be able to understand basic topics and after a year you should be comfortable with what you doing at decent level. Of course if you willing to spent 5 hours per day studying and practising.
@brandodelatorre
@brandodelatorre 4 жыл бұрын
Can anyone explain what stabilizing shell can do? I didn't follow it was so fast HAHAHA
@ARZ10198
@ARZ10198 4 жыл бұрын
It allows you use auto tab , like if you got a shell and when you try to use up and down arrow key it would show just random character like "[^A" so to avoid it we stabilize shell for our ease of use it is not necessary
@floatingblaze8405
@floatingblaze8405 4 жыл бұрын
My question isn't why is there a reverse shell, but why the hell does it point to a class C IP address? I thought THM uses class A networks.
@ingokrispin3482
@ingokrispin3482 3 жыл бұрын
Guess the person who built this box had tested in their own network before they pushed it to THM. There are many more boxes with references to internal IPs other than class A ones.
@vira7912
@vira7912 4 жыл бұрын
Hi Brother , in my terminal ever stunk when I input "stty raw -echo " and then ctrl +z ,fg %1 It don't respond back nc -lvnp 9001. how to solve please explain me
@ARZ10198
@ARZ10198 4 жыл бұрын
when you get a non stabilize shell press ctrl+z on that terminal then on the same terminal "stty raw -echo" then "fg "press enter also if you want clear command to work "export TERM=xterm"
@dannyv12
@dannyv12 4 жыл бұрын
Can someone explain me why my terminal crashes in tmux and zsh when i do the CTRL+Z; stty raw -echo fg ?
@_JohnHammond
@_JohnHammond 4 жыл бұрын
In zsh, you will need to combine the two stty raw command and the fg command into just one line, with a semi-colon. So it looks like: stty raw -echo; fg
@dannyv12
@dannyv12 4 жыл бұрын
@@_JohnHammond damn your fast :-) thanks for you quick answer. love your vids !
@dannyv12
@dannyv12 4 жыл бұрын
@@_JohnHammond I've tested it on the root me box on tryhackme the crash is gone but the shell is not stable I can't copy and I can't see what I'm typing and it doesn't create enters. Even the export XTERM didn't word when I execute reset it worked somehow 😎
@biswajitdutta6063
@biswajitdutta6063 2 жыл бұрын
My comment
@szymex73
@szymex73 4 жыл бұрын
.
@leventgul7690
@leventgul7690 4 жыл бұрын
cevaplara bakanlar +1
@djebbaranon5892
@djebbaranon5892 4 жыл бұрын
I have never found suid binary exploit in real life the only way to esculate your privlege is with Kernel's exploit 😂😂
@moonshadow6224
@moonshadow6224 3 жыл бұрын
where do I find the script John used to stable the shell "stabilize_shell.sh"
TryHackMe! Buffer Overflow & Penetration Testing
30:33
John Hammond
Рет қаралды 78 М.
Best 10 Items I Tested in 2024!
20:12
Project Farm
Рет қаралды 567 М.
The IMPOSSIBLE Puzzle..
00:55
Stokes Twins
Рет қаралды 177 МЛН
Players push long pins through a cardboard box attempting to pop the balloon!
00:31
За кого болели?😂
00:18
МЯТНАЯ ФАНТА
Рет қаралды 3,1 МЛН
He tried to hack me...
34:15
John Hammond
Рет қаралды 384 М.
TryHackMe! Abusing SETUID Binaries - Vulnversity
29:35
John Hammond
Рет қаралды 145 М.
The Best Way to Learn Linux
9:45
Mental Outlaw
Рет қаралды 124 М.
TryHackMe! Sudo - CVE-2019-14287
26:46
John Hammond
Рет қаралды 52 М.
this BASH script will make you a MILLIONAIRE
19:20
NetworkChuck
Рет қаралды 728 М.
New divisibility rule! (30,000 of them)
26:51
Stand-up Maths
Рет қаралды 347 М.
How to Get a Private Phone, Number, and Cellular Data
10:00
Mental Outlaw
Рет қаралды 1,1 МЛН
TryHackMe! Wonderland - Python Module Manipulation & Capabilities
24:04
HTB Cyber Apocalypse - cURL As a Service
26:07
John Hammond
Рет қаралды 38 М.
Have we lost control of METHANE gas?
13:41
Just Have a Think
Рет қаралды 88 М.