THM File Inclusion

  Рет қаралды 4,611

stuffy24

stuffy24

Күн бұрын

Пікірлер: 44
@stuffy24
@stuffy24 2 жыл бұрын
Get 20% OFF @manscaped + Free Shipping with promo code STUFFY24 at MANSCAPED.com! #ad #manscapedpod
@alechernandez5506
@alechernandez5506 4 ай бұрын
Tricky Tricky, I always feel like I don't understand anything but I started my PJPT coursework and it turns out THM has been great at exposing things to me and I capable of more than I realized.. It gets easier with repetition. Thank You for all that you do to explain things in your own words. For anyone reading this, make sure to take good notes!
@PublishX
@PublishX 2 жыл бұрын
this was a really difficult section and i put it off for a day. i woke up with a fresh mind and watched this and stopped at 9:45. took my time to read it and truly understand it and do the labs and had a lot of fun knowing i was able to completely grasp it. it all finally clicked and made complete sense. i really appreciate the tutorial, finished all my answers right now and watching this video to squeeze anything else i can learn
@stuffy24
@stuffy24 2 жыл бұрын
That's awesome! Congrats! That's a big thing thats so hard to do!
@Jugg215
@Jugg215 2 жыл бұрын
Yo youre a lifesaver on this one. I literally would have had no clue how to get through this. Definitely the hardest room so far.
@stuffy24
@stuffy24 2 жыл бұрын
Glad you figured it out! The big thing is just to make sure you understand it! That's awesome to see people getting through these harder rooms!
@johnnyclejel7434
@johnnyclejel7434 3 жыл бұрын
Great Video! I would've liked a more in-depth into the 'why' behind the actions that were performed. Ex: Why are you changing the referer? I also don't mind a longer video if it's explaining all the technicality of what is going on. Awesome stuff though and keep it up!
@MeeroSom
@MeeroSom 2 жыл бұрын
Thank you so much, this is one of the best walkthroughs, quite similar to the legends of similar content! You definitely are talented to have fun and contribute at the same time. please go on, learn, do stuff, I give a follow.
@stuffy24
@stuffy24 2 жыл бұрын
Thank you so much! I'm glad you like it and hopefully we all keep learning! We are just getting started !
@frkangungor
@frkangungor 3 жыл бұрын
Keep going, you are doing it great
@stuffy24
@stuffy24 3 жыл бұрын
Thanks man! Really appreciate it!
@sugarskulllyfe5890
@sugarskulllyfe5890 3 жыл бұрын
i really appreciate your walkthroughs!
@stuffy24
@stuffy24 3 жыл бұрын
Thanks man I really appreciate that! I just want to get more people into cyber ! It can be so fun! Most people think it's impossible to be a hacker but today it's so much more accessible!
@radovanthestudent4268
@radovanthestudent4268 2 жыл бұрын
Cheers, I've been struggling a bit .. took me some time to google out the "file is actually body parameter. Can't recall, if we have covered this one in previous lessons (also checked HTML module on THM). The questions is; why do we have to use body parameter for "file" instead of query parameter. Cheers!
@stuffy24
@stuffy24 2 жыл бұрын
Can you throw the question in the discord so I can remember to answer this when I get a chance ? Thanks man
@funandweird5633
@funandweird5633 2 жыл бұрын
Thanks a lot mate!! I've been finding that the explanations on the thm to be difficult to understand. Sometimes it makes me want to give up. I think thm should have video walk throughs and tutorials in video format which beginners can easily understand. You make things so much clearer to understand. Please keep posting videos for thm, we NEED them. Any tips for resources that beginners could utilise?
@stuffy24
@stuffy24 2 жыл бұрын
It all depends what your trying to learn but I find that if your studying for certs then use the resources the cert recemmonds I know it sounds dumb but a lot of people look for pump and dump info and don't retain any! If your looking for hacking stuff and you learn best in video I recemmond network chuck, cyber mentor, professor messer, and Hammond. They have all great KZbin channels!
@jeremiahmbugua3312
@jeremiahmbugua3312 2 жыл бұрын
Thank you for this, I really appreciate the video. Am running into problems though, my rce doesn't work, might you know what the problem is? I have replicated exactly what you did but somehow it's not working.
@stuffy24
@stuffy24 2 жыл бұрын
You can join the discord or Patreon and use the chat there but I couldn't tell you the issue without getting more information. The discord and Patreon have chat features you can use to upload screenshots and things
@jeremiahmbugua3312
@jeremiahmbugua3312 2 жыл бұрын
@@stuffy24 I finally figured it out: I was using the wrong ip. I was using eth0 instead of tun0 for my vm🤦🏾. I wouldn't have made through the challenges without your walk-through. I will definitely join your discord.
@stuffy24
@stuffy24 2 жыл бұрын
@@jeremiahmbugua3312 glad u figured it out man! Wish I could a helped over comments just so hard without more context.
@jeremiahmbugua3312
@jeremiahmbugua3312 2 жыл бұрын
@@stuffy24 your video helped me alot. I was only able to complete the challenges because of your video bro. I really appreciate your effort. I was completely stuck. I was only to do the first challenge by myself, the rest I was clueless. I have one question but I will ask it on your discord.
@awecwec3720
@awecwec3720 9 ай бұрын
can't thank u enough
@stuffy24
@stuffy24 9 ай бұрын
Thank you
@cameronjenkins584
@cameronjenkins584 3 жыл бұрын
Yoo you mentioned discord... where is the link for this? :)
@stuffy24
@stuffy24 3 жыл бұрын
discord.gg/KzzGfnKjCS
@greyhat430
@greyhat430 10 ай бұрын
why thm doesnt have rooms for cURL , altest they need to warn us to learn cURL ,
@stuffy24
@stuffy24 10 ай бұрын
I think it's an expected thing to know since LFI isn't a beginner technique
@greyhat430
@greyhat430 10 ай бұрын
@@stuffy24 your content is amazing , helping many who stuck in these rooms , love you soo much sir : ) and pls suggest resources on how to learn curl , it became my nightmare , i cant understand headers also and modifying them
@stuffy24
@stuffy24 10 ай бұрын
@@greyhat430 feel free to hop into the discord and ask in the questions section and if I can't get to you someone for sure will! Thanks man!
@Epeymen
@Epeymen 3 жыл бұрын
merhaba vpn bağlanıyorum ama ip adresi değişmediği için 405 hatası alıyorum yardım edermisin
@moosematrix
@moosematrix 3 жыл бұрын
Subscribed buddy.!
@stuffy24
@stuffy24 3 жыл бұрын
Let's go!
@unnamed3533
@unnamed3533 Жыл бұрын
The last one, challange I got reverse shell, and typed hostname by myself right to the terminal)
@unnamed3533
@unnamed3533 Жыл бұрын
I've been trying to get my privilege escalated, but they have closed every single possibility :(
@stuffy24
@stuffy24 Жыл бұрын
@@unnamed3533 hop in the discord and let us know the issue ur having we can try and troubleshoot
@unnamed3533
@unnamed3533 Жыл бұрын
@@stuffy24 nuh, it is not a trouble, I just tried to root the machine that I was not supposed to root.
@stuffy24
@stuffy24 Жыл бұрын
@@unnamed3533 ohh gotcha I thought you were saying it wasn't giving you a shell I apologize! Lol
@ragtaghero84
@ragtaghero84 Жыл бұрын
awesome
@stuffy24
@stuffy24 Жыл бұрын
Thanks so much!
@unclehoop3554
@unclehoop3554 2 жыл бұрын
Why is my result from cyberchef is not the same as yours? My recipe is url encode. My input is ../../../../etc/flag1. My result doesn't contain ".." as yours. Also my result seems to be longer than yours. Here is my encoded result: file%3D%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2Fetc%2Fflag1 Any suggestions? Thank yo
@stuffy24
@stuffy24 2 жыл бұрын
Could you throw the screenshots into the discord ?
@unclehoop3554
@unclehoop3554 2 жыл бұрын
@@stuffy24 just posted it. Thanks
THM SSRF Server side request forgery
25:21
stuffy24
Рет қаралды 872
Remote File Inclusion Explained and Demonstrated!
9:54
Loi Liang Yang
Рет қаралды 40 М.
ЗНАЛИ? ТОЛЬКО ОАЭ 🤫
00:13
Сам себе сушист
Рет қаралды 4 МЛН
Wait… Maxim, did you just eat 8 BURGERS?!🍔😳| Free Fire Official
00:13
Garena Free Fire Global
Рет қаралды 7 МЛН
У вас там какие таланты ?😂
00:19
Карина Хафизова
Рет қаралды 18 МЛН
CAN YOU DO THIS ?
00:23
STORROR
Рет қаралды 47 МЛН
Try Hack Me : Cross-Site Scripting
29:08
stuffy24
Рет қаралды 1,9 М.
File Inclusion - TryHackMe Junior Penetration Tester 3.6
44:02
Brock Rosen
Рет қаралды 13 М.
Tryhackme | File Inclusion | Jr. Penetration Path
40:34
johnnyPentester
Рет қаралды 2,4 М.
Try Hack Me : What the Shell
45:08
stuffy24
Рет қаралды 13 М.
Why Are Open Source Alternatives So Bad?
13:06
Eric Murphy
Рет қаралды 665 М.
Advanced Local and Remote File Inclusion - PHP Wrappers
11:19
Netsec Explained
Рет қаралды 10 М.
NSURLProtocol: How I Stole an App For My Wedding
56:25
Bryce Bostwick
Рет қаралды 53 М.
My favorite browser is (kind of) dead
28:18
Theo - t3․gg
Рет қаралды 95 М.
THM IDOR!
18:14
stuffy24
Рет қаралды 548
ЗНАЛИ? ТОЛЬКО ОАЭ 🤫
00:13
Сам себе сушист
Рет қаралды 4 МЛН