MOVEit Transfer Exploitation (my API presentation recording)

  Рет қаралды 16,214

John Hammond

John Hammond

Күн бұрын

🔥 KZbin ALGORITHM ➡ Like, Comment, & Subscribe!
🙏 SUPPORT THE CHANNEL ➡ jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
🌎 FOLLOW ME EVERYWHERE ➡ jh.live/discord ↔ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/instagram ↔ jh.live/tiktok
💥 SEND ME MALWARE ➡ jh.live/malware

Пікірлер: 23
@jjann54321
@jjann54321 Жыл бұрын
It's so rare to find someone that's technical, experienced, well spoken and entertaining in this industry. Watching John's channel will make you spoiled quickly. Many channels of this "genre" have a host and a team of graphic artists and editors working in hopes of keeping their audience engaged and they are fighting for 2nd place at best. Thank you Mr. Hammond for all that you do for community. I can't imagine what your sleep schedule looks like.
@RRahulRajput798
@RRahulRajput798 Жыл бұрын
1st as indexing starts with 0 ❤
@DarkFaken
@DarkFaken Жыл бұрын
Mate, thank you once again for your amazing lesson! You really are a pillar of this community
@b3nx0
@b3nx0 Жыл бұрын
John, you're KZbin content is absolutely fantastic! The depth of knowledge and the engaging way you present complex topics is truly impressive. I'm constantly learning something new and exciting from your videos. Keep up the amazing work!
@Innocuils
@Innocuils Жыл бұрын
Watching now, clearly not through the video....but I seriously appreciate how you are going over this. Keep up the great work John!
@accrevoke
@accrevoke Жыл бұрын
Progress / MOVEit has been using ancient designs and absolutely horrific security practices waiting to be exploited. Their MFT (managed file transfer) hasn't changed much since 2008, it's practically suicide to permit unauthenticated external access. Second runner up is Stonebench and JSCAPE, at least JSCAPE got some updates and is rarely "directly" open to external / public. For GoAnywhere, it's unfortunate, they are supposed to be a security first company, but I guess the team dropped the ball in their SaaS environment. And again, SaaS, just contracting out the liability to someone else :)
@beng9145
@beng9145 Жыл бұрын
this is a BIG deal, always on top of John
@0xMoha
@0xMoha Жыл бұрын
thank you john
@katendemusa5747
@katendemusa5747 Жыл бұрын
Do more on APIs please
@sophiophile
@sophiophile Жыл бұрын
I mean, there isn't much to them, tbh. REST is very simple/limited. It all comes down to whether there is something about how data is handled on the backend of the API that allows an attack using the exposed endpoints.
@4CHUX
@4CHUX Жыл бұрын
1
@deadbeef2482
@deadbeef2482 Жыл бұрын
dope!
@HarvestHaven09
@HarvestHaven09 Жыл бұрын
🎉🎉🎉🎉
@hackwithprogramming7849
@hackwithprogramming7849 Жыл бұрын
Give me ❤️
@emoneymd5
@emoneymd5 Жыл бұрын
Move it was a file transfer vulnerability
@JeffFranchetti
@JeffFranchetti Жыл бұрын
Were the victim organizations using moveit “on premise” or in the cloud?
@RJZN5Gaming
@RJZN5Gaming Жыл бұрын
How to i learn to use a new cve?
@JeffFranchetti
@JeffFranchetti Жыл бұрын
How did you get the IIS logs?
@Kabodanki
@Kabodanki Жыл бұрын
21min talk, 4min intro
@Thebloggermustdie
@Thebloggermustdie Жыл бұрын
You're getting lazy man
@emoneymd5
@emoneymd5 Жыл бұрын
What
Top 10 FREE OSINT tools (with demos) for 2024 - And FREE OSINT course!
1:08:19
Gauravzone Deserves His FAILURE 😨!?
8:04
Reconic
Рет қаралды 287 М.
1ОШБ Да Вінчі навчання
00:14
AIRSOFT BALAN
Рет қаралды 5 МЛН
Matching Picture Challenge with Alfredo Larin's family! 👍
00:37
BigSchool
Рет қаралды 53 МЛН
Where People Go When They Want to Hack You
34:40
CyberNews
Рет қаралды 1,7 МЛН
The MOVEit Hack In Retrospect
43:05
John Hammond
Рет қаралды 12 М.
Why You NEED To Learn FastAPI | Hands On Project
21:15
Travis Media
Рет қаралды 160 М.
How To Pivot Through a Network with Chisel
33:45
John Hammond
Рет қаралды 125 М.
Finding Your First API Bug (NahamCon 2023)
22:10
InsiderPhD
Рет қаралды 10 М.
The AI Cybersecurity future is here
26:42
David Bombal
Рет қаралды 157 М.
How Hackers Hide From Memory Scanners
21:11
John Hammond
Рет қаралды 58 М.
Log4J Vulnerability (Log4Shell)  Explained - for Java developers
20:50
How Hackers Move Through Networks (with Ligolo)
20:01
John Hammond
Рет қаралды 268 М.
1ОШБ Да Вінчі навчання
00:14
AIRSOFT BALAN
Рет қаралды 5 МЛН