ACCESS what you WERE NEVER SUPPOSED TO

Поделиться
HTML-код
  • Опубликовано: 11 окт 2022
  • j-h.io/guidepoint-security-ctf GuidePoint Security is hosting a Capture The Flag competition on October 27th, FREE for everyone! These are always a ton of fun -- jump in and play!! j-h.io/guidepoint-security-ctf
    Help the channel grow with a Like, Comment, & Subscribe!
    ❤️ Support ➡ j-h.io/patreon ↔ j-h.io/paypal ↔ j-h.io/buymeacoffee
    Check out the affiliates below for more free or discounted learning!
    🖥️ Zero-Point Security ➡ Certified Red Team Operator j-h.io/crto
    💻Zero-Point Security ➡ C2 Development with C# j-h.io/c2dev
    🐜Zero2Automated ➡ Ultimate Malware Reverse Engineering j-h.io/zero2auto
    🐜Zero2Automated ➡ MISP & Malware Sandbox j-h.io/zero2auto-sandbox
    ⛳Point3 ESCALATE ➡ Top-Notch Capture the Flag Training j-h.io/escalate
    👨🏻‍💻7aSecurity ➡ Hacking Courses & Pentesting j-h.io/7asecurity
    📗Humble Bundle ➡ j-h.io/humblebundle
    🐶Snyk ➡ j-h.io/snyk
    🤹‍♀️SkillShare ➡ j-h.io/skillshare
    🌎Follow me! ➡ j-h.io/discord ↔ j-h.io/twitter ↔ j-h.io/linkedin ↔ j-h.io/instagram ↔ j-h.io/tiktok
    📧Contact me! (I may be very slow to respond or completely unable to)
    🤝Sponsorship Inquiries ➡ j-h.io/sponsorship
    🚩 CTF Hosting Requests ➡ j-h.io/ctf
    🎤 Speaking Requests ➡ j-h.io/speaking
    💥 Malware Submission ➡ j-h.io/malware
    ❓ Everything Else ➡ j-h.io/etc

Комментарии • 61

  • @pmcforever9686
    @pmcforever9686 Год назад +58

    hey john I have been looking through your malware analysis series and was wondering if you are going to start streaming those again?

  • @alh4zr3d3
    @alh4zr3d3 Год назад +19

    I just did this box on stream yesterday and found it very interesting and cute! I took the opportunity to practice my BASH skills and wrote a for-loop one-liner that would iterate through the numbers 1-100, hash the number, and then curl the endpoint. Was cool and satisfying when it worked....shame it didn't solve the box though! Should have just tried "0" at the outset.

  • @nicholasdacri
    @nicholasdacri Год назад +2

    John has become my ASMR :)

  • @ghsinfosec
    @ghsinfosec Год назад +21

    Your explanations are always so thorough, thanks for all you do. I'm also looking forward to your WWHF talk!

  • @MorebitsUK
    @MorebitsUK Год назад +4

    Hi John, the corridor also references the beginning of the hacking series that was on British TV a month or two ago called: The Undeclared War.

  • @logiciananimal
    @logiciananimal Год назад +4

    Neat; and good to see some old school HTML approaches rather than some unnecessary framework. I always use the idea of the bus stop information numbers one can use in some places when explaining IDOR, but I'll have to remember this idea too. (All: Feel free to borrow mine!)

  • @fredb5626
    @fredb5626 Год назад

    Ngl the new line thing didn't even cross my mind - I appreciate you John, even on the "cheesy" ones lol ❤️

  • @bijoy_26
    @bijoy_26 Год назад

    Precise and informative as always, John!

  • @softsolute8653
    @softsolute8653 Год назад

    I really enjoy your explainers John. Thanks for this Channel.

  • @jorisschepers85
    @jorisschepers85 Год назад

    Keep these vids coming. Useful stuff

  • @dedkeny
    @dedkeny Год назад

    Bippity boppity your idea is now my property LOL

  • @lambo_drives
    @lambo_drives Год назад

    John. I truly wish the Al-Gore-Rhythm would have hooked us up 4 years ago... your content is what I wish I would have known as I rediscovered my next phase... alas, you may be phase 3 because your Information is EXACTLY what i've hungered for since being introduced to Fortran 77 in 1994... i've missed soooo many years but can feel and understand what you're throwing down...
    LOVE what you do, awesome, interesting, informative, inspirational...
    Namaste

  • @DexieTheSheep
    @DexieTheSheep Год назад

    Never really knew what an IDOR was, and never really bothered to look it up, but this explains it really well in simple terms. Thanks!

  • @clement1446
    @clement1446 Год назад

    IT WORKED, THANKS I'VE BEEN LOOKING FOR THIS FOREVER, BUT NO TUTORIAL COULD EXPLAIN IT AS YOU DID

  • @Fl0kii_
    @Fl0kii_ Год назад +7

    Loved this challenge John, just a little tip if you don't mind my friend, when you use the .encode() method, the default encoding is UTF-8 so you don't necessarily need to specify it, hope this can be useful to you 🙏

    • @uwu-zl6tq
      @uwu-zl6tq Год назад +1

      its good practice to include it anyway

  • @aymaneelhadi2954
    @aymaneelhadi2954 Год назад

    Thank you so much you really help me :)

  • @JackBond1234
    @JackBond1234 Год назад

    Nice, I figured out what to do before you explained it. I feel smart.

  • @danielniedzwiecki638
    @danielniedzwiecki638 Год назад

    works, keep up the good work man

  • @robottwrecks5236
    @robottwrecks5236 Год назад

    I love it! :D

  • @champagnepete3386
    @champagnepete3386 Год назад

    great work as always

  • @zer001
    @zer001 Год назад

    Wow that was fun!

  • @Dimlutube
    @Dimlutube Год назад

    Alh4zr3d busted this one on his stream last night; it was wicked fun. Thanks John!

  • @brymstoner
    @brymstoner Год назад

    this is really cool, john. thanks for sharing it. i created a similar ctf a few months ago, just without the image map. it was well received by the small userbase i demo'ed it to, but i quickly ran out of ideas of where and how to hide clues for the proceeding flags. i accept that most of it is imagination, but do you know of any good sources for hiding place ideas? i'd love to build my ctf out into a learning tool.

  • @lonixlon
    @lonixlon Год назад

    You could have piped into xxd to prove the point, hindsight is always good

  • @alainherreman3685
    @alainherreman3685 Год назад

    Rich and original as usual!

  • @Microsoftie
    @Microsoftie Год назад +1

    It was the quickest room I’ve ever managed to do. I felt like a god lol.

  • @mukundpawar9066
    @mukundpawar9066 Год назад

    It's just yesterday I solved it and loved it...

  • @lancemarchetti8673
    @lancemarchetti8673 Год назад

    😎 very cool

  • @faruq3507
    @faruq3507 Год назад

    i was lost for around 40 mins trying to understand your clues , However . thank you for doing the effort and creating the room

  • @adamn777
    @adamn777 Год назад

    I posted this walkthrough and referenced this link on THM room write up section

  • @xBZZZZyt
    @xBZZZZyt Год назад

    09:16 not important but why is there no door in this room?

  • @muzec-sec
    @muzec-sec Год назад

    Guidepoint is a cool platform I always play the CTF every year

  • @x32gx
    @x32gx Год назад +2

    This was a great box! I really liked it!

  • @arenaesports2580
    @arenaesports2580 Год назад

    Yeah i have done it

  • @dom1310df
    @dom1310df Год назад

    Is this the cause of Moonpig's leak from a few years ago, where you could change your user ID in the address bar and view someone else's account details?

  • @кардер
    @кардер Год назад

    i so was scared when i saw this preview, it looks like backrooms.

  • @djosearth3618
    @djosearth3618 Год назад

    Ssoo obscurity is kinda zero
    sexurity??
    ps: thx for some _BEHIND (you)_ the scenes content too .;]

  • @didntmeantokillemtwasaaccident
    @didntmeantokillemtwasaaccident Год назад +1

    hi.

  • @emilybond7556
    @emilybond7556 Год назад

    First lesson, don't sign up - it's a bait.

  • @Diorden119
    @Diorden119 Год назад

    when's the next asdfmovie

  • @DaniSpeh
    @DaniSpeh Год назад +2

    Neither dumb not stupid. I found it pretty creative, beautiful and smart made. Ok, the challenge is not that hard. Also, I watched a couple of streamers solving it. Every single on said it's very creative how it's made. Congrats to you and the team who built it.

  • @abhimusic9178
    @abhimusic9178 Год назад +1

    🇮🇳love from india

  • @mgabriel650
    @mgabriel650 Год назад

    Early on here, hi John

  • @Nightscreener
    @Nightscreener Год назад

    Old comment

  • @user-cj1dq4gf5d
    @user-cj1dq4gf5d Год назад

    2nd here!

  • @frkcdjfjdjjg3226
    @frkcdjfjdjjg3226 Год назад

    i commented first.

  • @aliencatmeow
    @aliencatmeow Год назад

    Lmao 4 first comments. Y'all cant all be first

  • @rishabhrana3773
    @rishabhrana3773 Год назад

    First comment!!!

  • @BubkisLord
    @BubkisLord Год назад

    1st here!

  • @aakashadhikari3752
    @aakashadhikari3752 Год назад

    Hii, I just saw the ZeroPoints Certified Red Team Ops certification link ...is there anyway to get discount from your side 💖, I would love to get ! 💖🔥

  • @V3racious3
    @V3racious3 Год назад

    The sad realization that he actually puts time into that hair.

    • @V3racious3
      @V3racious3 Год назад

      @@MaxPower-ig7kh that time could be better spent, for example: with your mum.

  • @mr.unforgettable
    @mr.unforgettable Год назад +1

    It was really a cool and creative idea for a CTF challenge. I will try to implement this idea when i will capable like @JohnHammond 😅😅

  • @Unbreaded452
    @Unbreaded452 Год назад

    This is where I lose interest in capture the flag. There is no practical purpose for this. Why not just teach people how to examinen MD5. Websites don’t use MD5 like this.

  • @blackhathacking9103
    @blackhathacking9103 Год назад +1

    I really appreciate your video really helpful

  • @y.vinitsky6452
    @y.vinitsky6452 Год назад

    Cool. I was doing another IDOR room earlier today. Could you do a video of your process making these for tryhackme (or a different one if you prefer) there aren't a lot of videos like that out there with good English

  • @arenaesports2580
    @arenaesports2580 Год назад

    Corridor in tryhackme with IDOR vulnerability 😀

  • @py_world
    @py_world Год назад

    This is the only CTF on tryhackme I could do in an hour. Thanks for the teaching about IDOR Vulnerabilities.