TryHackMe! Skynet - Wildcard Injection

preview_player
Показать описание

Рекомендации по теме
Комментарии
Автор

That python bruteforcer is a lifesaver

jonny-mp
Автор

Nice vid John :)
Btw : The "balls have zero to me" stuff was from an experiment, letting 2 AIs talk to each other with a set alphabet but no actual grammatical rules.
After a while, they just came up with their own way of communicating :D

Urzgag
Автор

As a developer - very interesting to see your approach to finding weaknesses. I can sort of see the fun in this kind of activity, the lure of the dark side :)

Mosern
Автор

love the content and the way you explain everything so thoroughly! id also much rather see you walk through a script like that than if you didnt

stevenhernandez
Автор

wow... exploiting the tar wildcard to set the SUID bit on /bin/bash is so freaking smart and cool man, I was stunned by how amazing that was. I'm trying to better myself at pentesting and John, you are teaching me amazing things! Thank you so much!

christianmanalaysay
Автор

I wanted it for 1 time and will be watching it for a few more times to note all the things taught here. Thank you so much for your efforts. I do respect you and your talent. 😇

AhmedMohamed-knsf
Автор

Learnt a lot through this live walkthrough, well narrated and explained.
The best part is the way you put out your way of approaching the next possibility, that definitely helped me in knowing how to process my thoughts during a CTF

karangadhave
Автор

heretic, not confirming with ls after mkdir.

takeiteasyeh
Автор

Love this approach John. Its raw, honest and not contrived (i.e. doesnt come over as you've already completed it and are now just going back through the motions!). Its far more enjoyable to listen to your thought process this way, and you still seem to manage to keep things easy to understand. Nice work :-) Subbed.

mattstorr
Автор

Been loathing reading all those articles about wildcard injection....
Thanks for the video man :)

salimzavedkarim
Автор

Holyyyy that curl to python requests and the bruter you wrote just blew my mind. Good stuff John I really love your videos.

durzua
Автор

That tar exploit is INSANE, how have I *never* heard of "the * exploit"??

mikee.
Автор

Ah Skynet. One of the best loved THM rooms, I believe. Out of curiosity, I just looked at the conclusion in my own notes and it says "probably my favorite ctf to date." :)

bmbiz
Автор

john: makes a py script out of nothing in less than 2 minutes

me on google: "how to declare a variable"

nullpwn
Автор

John, I must say please do more of these vids are awesome and the talking through your process is exceptional

Deathfreeze
Автор

Amazing videos with great explanations to beginners instead of just cruising through all the answers without explaining the reasoning behind anything.

bryttontsai
Автор

This is probably the most educational video on the topic I've ever seen, and I've seen a lot. Amazing.

meeDamian
Автор

Thank you very much for each video you upload. I am a cybersecurity student and always I get upset, I put one of your video and get motivated to keep on.. thank you 🙏

RycnGaming
Автор

this video was awesome! i learned much! thank you so much john, your the man brother!

Childne
Автор

I was as excited as you are when you privilege escalated. This is simply amazing.

shiralihusan