RECOVERING FILES with Autopsy (PicoCTF 2022 #47 'operation-oni')

  Рет қаралды 29,357

John Hammond

John Hammond

Күн бұрын

Пікірлер: 44
@BarYamin
@BarYamin 2 жыл бұрын
If you want to understand the rwx permission set, it's better to interpret it as binary. Basically, we have 3 bits that each represent r, w, and x, respectively. so, let's say I want read & execute, this translates to r-x, which translates in binary to 101, which then in turn converts to 4+1=5 in base10 :)
@MrToast72
@MrToast72 2 жыл бұрын
Briefly talks about Chmod three digit codes "you can look up resources on how this exactly works" then proceeds to explain how it exactly works lol thank you John, I love when you do that!
@SESUAV
@SESUAV 2 жыл бұрын
I used binwalk too. It was quick and easy using that than autopsy because of command line
@testentry353
@testentry353 2 жыл бұрын
one easy way to remember the file permissions is to know that read is 4, write is 2, and execute is 1 so r-x will be 4+1=5 and rw- will be 4+2=6
@ericbarlow6772
@ericbarlow6772 2 жыл бұрын
It’s binary. RWX is a bit either on (1) or off (0). Read only is 100 in binary or 0*2^0 + 0*2^1 + 1*2^2 = 4.
@abiolasamuel9760
@abiolasamuel9760 Жыл бұрын
Hello 👋 My samsung a71 phone was factory reset remotely and I don't have any backup whatsoever, is it possible to recover the phone data
@TheNobleSavage612
@TheNobleSavage612 2 жыл бұрын
"i need to look for keys" hovers over the key folder and moves on
@rahimmahat0007
@rahimmahat0007 2 жыл бұрын
Exactly, I was like John you just passed right through it
@adinathrangnekar3064
@adinathrangnekar3064 Жыл бұрын
Same
@IAmCandal
@IAmCandal 2 жыл бұрын
HOLY SHIT BRO YOU DONT EVEN KNOW HOW HELPFUL THIS WAS FOR ME HOMIE
@wisemasterbuilder
@wisemasterbuilder 2 жыл бұрын
Love this Format Mighty Friend! You can lead a horse to water but ya can't always git'em to drink.
@fjr2go
@fjr2go 2 жыл бұрын
I like the 'short' informative videos like these. Thanks
@maxxinev.pennelope7179
@maxxinev.pennelope7179 2 жыл бұрын
Watching this on the TV cast with my father fingers crossed 🤞 it's not to over my or rather our head(s).
@viv_2489
@viv_2489 2 жыл бұрын
Really like the alternate solution / additional extra curricular activity that you mention as applicable....
@eavi4645
@eavi4645 2 жыл бұрын
Great video, love the content. Thank you!
@Zerback
@Zerback 2 жыл бұрын
Great content John! Keep it up!
@zer001
@zer001 2 жыл бұрын
Nice one as allways!
@omaralhalboosi2713
@omaralhalboosi2713 2 жыл бұрын
Great great video John, but dude you are like sonic speed lol barely catching up , which made this vid a 40 minutes show. But the point is this is great . May God bless you brother
@rationalbushcraft
@rationalbushcraft 2 жыл бұрын
I like using autopsy and we don't even do traditional forensics as my state requires you be a PI of all things to do that. But I do use it for data recovery and I even use a hardware write blocker. Probably seems like overkill but I never have to say that I may have changed something so if the end user wants to send it to Ontrack or some other place I can argue that we never changed anything.
@abiolasamuel9760
@abiolasamuel9760 Жыл бұрын
Hello 👋 My phone was factory reset remotely and I don't have any backup whatsoever, is it possible to recover my phone data
@jreamscape
@jreamscape 9 ай бұрын
thanks dude
@booruledie3052
@booruledie3052 2 жыл бұрын
cant wait for htb cyber apocalypse videos.
@debarghyamaitra
@debarghyamaitra 2 жыл бұрын
I did it with commands icat and fls....it was a lot hectic though!
@yaserbasaad7984
@yaserbasaad7984 2 жыл бұрын
You are Epic
@johnmcmanus6719
@johnmcmanus6719 2 жыл бұрын
The SSH key wasn't a deleted file though
@bech2342
@bech2342 2 жыл бұрын
uh, he saw for the first time a kernel source tree 🙊 binwalk FTW!
@Lacsap3366
@Lacsap3366 2 жыл бұрын
Lol I just mounted the root partition as a loop device with losetup
@hallgowrt
@hallgowrt 2 жыл бұрын
the audio seemed low at full volume was I able to hear anything as always great vid
@luthfisukma9787
@luthfisukma9787 2 жыл бұрын
are you use linux for daily driver ??
@Youtupe69
@Youtupe69 2 жыл бұрын
Whats this GUI, I've used autopsy on windows and it wasnt a web app, had a much nicer GUI... Is it not available on Linux?
@kiyu3229
@kiyu3229 Жыл бұрын
It is you can install it with apt
@ecjb1969
@ecjb1969 2 жыл бұрын
Couldn’t you just midair image; mount -t iso9660 -o loop disk.img image to mount the disk image and then use find to look for SSH keys and the like?
@CA-FE-C0-FF-EE-00
@CA-FE-C0-FF-EE-00 2 жыл бұрын
Watching this file failing the htb CTF xD only 8 challenges done, but I'm alone ^^
@guilherme5094
@guilherme5094 2 жыл бұрын
👍
@msasdc2087
@msasdc2087 2 жыл бұрын
Finnaly, I got your home address.
@re70-december32
@re70-december32 2 жыл бұрын
Hiiiii
@johny_dope8575
@johny_dope8575 2 жыл бұрын
1
@shocker9434
@shocker9434 2 жыл бұрын
13:40 whats that finish command 🤔🤔 can anyone explain?
@PR1NC3
@PR1NC3 2 жыл бұрын
he created bash script to rename the working folder with prifix _completed
@shocker9434
@shocker9434 2 жыл бұрын
@@PR1NC3 oh got it. thanks
@herrpez
@herrpez 2 жыл бұрын
I love your content, but calling things a "gimmick" when they're far from it... that's... grating. :(
@abiolasamuel9760
@abiolasamuel9760 Жыл бұрын
Hello 👋 My phone was factory reset remotely and I don't have any backup whatsoever, is it possible to recover my phone data
@abiolasamuel9760
@abiolasamuel9760 Жыл бұрын
Hello 👋 My phone was factory reset remotely and I don't have any backup whatsoever, is it possible to recover my phone data
Least Bit Steganography w/ zsteg (PicoCTF 2022 #50 'st3g0')
8:04
John Hammond
Рет қаралды 23 М.
Чистка воды совком от денег
00:32
FD Vasya
Рет қаралды 2,1 МЛН
FOREVER BUNNY
00:14
Natan por Aí
Рет қаралды 30 МЛН
Strange File in Downloads Folder? Gootloader Malware Analysis
30:20
John Hammond
Рет қаралды 827 М.
Hide your files like a hacker (5 Ways)
19:17
NetworkChuck
Рет қаралды 178 М.
WRITE BASH SCRIPTS for CTF Solutions (PicoCTF 08 'file-run1')
17:51
Obscure File Types & Compression (PicoCTF 2022 #10 'file-types')
17:06
GHIDRA for Reverse Engineering (PicoCTF 2022 #42 'bbbloat')
17:44
John Hammond
Рет қаралды 220 М.
Restructuring PCAP Network Packets (PicoCTF 2022 #45 'eavesdrop')
10:51
Hacking Bank from Hackthebox |  HTB Bank Walkthrough | Ethical Hacking
28:17
Is your PC hacked? RAM Forensics with Volatility
14:29
The PC Security Channel
Рет қаралды 919 М.