Mother's Secret - TryHackMe -

  Рет қаралды 3,495

Djalil Ayed

Djalil Ayed

Күн бұрын

Пікірлер: 13
@jjann54321
@jjann54321 11 ай бұрын
Thank you for taking the time to make this detailed analysis and walkthrough. While I do appreciate this room, having completed the modules leading up to this challenge DID NOT prepare me for this. Having a deep understanding of YAML, JS or using Burpsuite (as many people have in other write-ups) was not covered in the training and not mentioned as a "recommendation or prerequisite" for this challenge. Truthfully you didn't use any of the tools/techniques covered in the modules leading up this this challenge but your methodology certainly works well. I tried using OWASP ZAP but with limited success/results. I found this challenge quite frustrating and I can only assume many people feel the same way as I do as this is the lowest scoring (rated) room in the TryHackMe SecEng learning path. If someone would create a walkthrough/write-up using the tools/techniques covered in the training prior to this challenge that would be extremely helpful and appreciated. Thank you again and well done.
@djalilayed
@djalilayed 11 ай бұрын
Hi, the rooms on each TryHackMe path I think are just guidelines for general knowledge and tools you need on specific area, you need to practice more and learn more details, that is why each CTF room you try you will lean new things, in this room is more like manual code review, that is why I believe learning how to code is good if you planning to have career on hacking. So its combination of practice (doing rooms, ctf etc) and also learning (books, videos, online documentation) and here where most do the mistake, many they just do CTF rooms and do not spend more time on learning.
@akashps3899
@akashps3899 9 ай бұрын
I agree with you @jjann54321, I really got confused with this room! I was excited while starting but I felt like I didn't learn much with fun.
@ShahriyarRzayev
@ShahriyarRzayev Жыл бұрын
Cool room, cool explanation, probably next time better to zoom in the browser while sending a request or use burp with a bigger font size. Thanks for sharing :)
@djalilayed
@djalilayed Жыл бұрын
Thanks for the tip, glad you enjoyed the video.
@Hey-yk8pj
@Hey-yk8pj Жыл бұрын
Excellent explanation as always
@djalilayed
@djalilayed Жыл бұрын
Thanks again!
@yassinom2466
@yassinom2466 2 ай бұрын
thanks for the video, i have a question for ../../../../opt/m0ther, i don't understand this step, (how did you think about this)
@pinchesteve4431
@pinchesteve4431 Жыл бұрын
Thanks for the walkthrough; as always, it was clear and helpful. I tried using Burp to do the POSTs, and can get the flags/secrets correctly from the OS (doing things in the correct order). But even though I can make the all the calls, the Role/Interface doesn't change from Crew Member (so I couldn't read the "classified flag"). Of course, your method works like a charm, but I'm still curious if there is something that I could do with Burp.
@djalilayed
@djalilayed Жыл бұрын
Glad it helped!. I tried just now with burp, what I noticed is if you keep burp active on firefox using foxyproxy it will not update. So what I did is when I first captured the request using burp, I deactivated burp on firefox, refresh the page, then send request with burp as I did with firefox on my video, it will work
@mebessusn
@mebessusn Жыл бұрын
Thank you for the help!
@djalilayed
@djalilayed Жыл бұрын
Happy to help!
@djalilayed
@djalilayed Жыл бұрын
Please subscribe to get the latest videos www.youtube.com/@djalilayed
Mother's Secret  :  DevSecOps :  TryHackMe : Walk through 11
34:32
Taking over a website with JWT Tokens!
14:27
Tech Raj
Рет қаралды 36 М.
Fake watermelon by Secret Vlog
00:16
Secret Vlog
Рет қаралды 27 МЛН
Kluster Duo #настольныеигры #boardgames #игры #games #настолки #настольные_игры
00:47
Osman Kalyoncu Sonu Üzücü Saddest Videos Dream Engine 262 #shorts
00:20
🕊️Valera🕊️
00:34
DO$HIK
Рет қаралды 12 МЛН
Linux System Hardening TryHackMe
24:00
Djalil Ayed
Рет қаралды 3,9 М.
Traverse TryHackMe Walk Through
17:28
Djalil Ayed
Рет қаралды 1,8 М.
Got Logs? | TryHackMe - Intro to Logs
32:24
WireDogSec
Рет қаралды 636
How to Solve the TryHackMe Mother's Secret Challenge
33:47
Hank Hackerson
Рет қаралды 275
Next.js Authentication with Next Auth - Protected Routes & more
37:23
Coding With Abbas
Рет қаралды 31 М.
Try Hack Me: Weaponization
30:40
stuffy24
Рет қаралды 2,5 М.
Mother's Secret - CTF (TryHackMe) | detail explained
21:08
Osman Dağdelen
Рет қаралды 2,2 М.
When you Accidentally Compromise every CPU on Earth
15:59
Daniel Boctor
Рет қаралды 863 М.
Vulnerability Management TryHackMe
25:06
Djalil Ayed
Рет қаралды 2 М.
TryHackMe | Mother's Secret | Security Engineer
23:04
Hürşah
Рет қаралды 235
Fake watermelon by Secret Vlog
00:16
Secret Vlog
Рет қаралды 27 МЛН