Plundering AWS S3 Buckets - HackTheBox

Поделиться
HTML-код
  • Опубликовано: 23 апр 2021
  • For more content, subscribe on Twitch! / johnhammond010
    If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
    PayPal: paypal.me/johnhammond010
    E-mail: johnhammond010@gmail.com
    Discord: johnhammond.org/discord
    Twitter: / _johnhammond
    GitHub: github.com/JohnHammond

Комментарии • 109

  • @viv_2489
    @viv_2489 3 года назад +48

    Pwncat, linpeas juggling and then that auto deletion of files from files folder.. Entertainment with learning😂.. awesome video....thanks

  • @mindzhd
    @mindzhd 3 года назад +39

    When I found myself screaming "IT'S IN ADSERVER JOHN!!" I realised I learned something from watching this channel.
    Thanks John, stinkin love your content! You're one of the more vibrant pen-test people I know of and watching you wiggle your way through this and that is really entertaining and informative at the same time. You could probably teach this stuff professionally through those platforms like skillshare or brilliant!

    • @InsomniaFire
      @InsomniaFire 3 года назад +2

      He has a great Udemy course

    • @PalCan
      @PalCan 2 года назад +1

      @@InsomniaFire what is the course called? Thanks

    • @emporiove
      @emporiove 2 года назад

      @@InsomniaFire whats the name of the course?

  • @Devinatron
    @Devinatron 3 года назад +20

    This is fantastic and I'm so happy I found your channel! I just participated in my first CTF (HTB Cyber Apocalypse) and it was so much fun! I didn't do too great, but learned a ton. Thanks for getting me into this fun 'hobby' to help build my skills as I work towards a career shift.

  • @Mslepe_8374
    @Mslepe_8374 3 года назад +4

    this video and your content in general is mind blowing. Truly awesome stuff!

  • @rudisrozitis
    @rudisrozitis 3 года назад +16

    1:00:24 got that Batman voice on point! :D

  • @morsi7842
    @morsi7842 3 года назад +2

    Awesome john, So much useful data in one video.Thanks appreciated

  • @jmoncadagutierrez
    @jmoncadagutierrez 3 года назад +8

    john this was genuinely one of your best videos!!

  • @wilcosec
    @wilcosec 3 года назад +1

    Fun walkthrough of a great box. Great job, John!

  • @xaxabogbart
    @xaxabogbart 3 года назад +3

    How random - I've met one of the guys who founded Hack The Box. He lives in my hometown. Glad to see it's launching into something really cool and getting attention - not surprised though, he was a very astute fellow.

  • @thatcreole9913
    @thatcreole9913 3 года назад +4

    Brilliant job John. Please keep them coming!

  • @andymac7668
    @andymac7668 3 года назад +6

    I do not live in this coding/hacking world at all, but, this was very interesting to watch. Thank you for creating this content

  • @fadhilsaheer8877
    @fadhilsaheer8877 3 года назад +11

    *Put a magnifying glass on your computer if you see red bugs you are in malware*
    - John Hammond 2021 😹

  • @sneezeman
    @sneezeman 3 года назад +18

    Love that everytime John tries to showcase Pwncat it just breaks in some way

  • @TheBrutaline
    @TheBrutaline 3 года назад +7

    I saw your name pop up on the activity feed for the box a couple of days ago. I was hoping you would make it into a video, very cool.

  • @Cojo173
    @Cojo173 3 года назад +3

    Loving this type of content!!!!

  • @Basieeee
    @Basieeee 3 года назад +3

    We are now on amazon's watchlist.

  • @fennex79
    @fennex79 4 месяца назад

    I love your way of thinking!

  • @StevenIngram
    @StevenIngram 3 года назад +2

    It never ceases to amaze me how much of a security hole can be. LOL

  • @talinross
    @talinross 3 года назад +1

    Awesome job love it !

  • @hibdfghf2500
    @hibdfghf2500 3 года назад

    I loved this machine !! I learned di much about aws dynamodb

  • @munaz55
    @munaz55 3 года назад

    awesome content, thanks john

  • @gp6723
    @gp6723 2 года назад

    Great, really liked this

  • @GilligansTravels
    @GilligansTravels 3 года назад

    Great video John!

  • @f_u8264
    @f_u8264 3 года назад +1

    ''Dang it'' part really got me!

  • @onlylikenerd
    @onlylikenerd 3 года назад

    You make it look too easy. I get inspired and try and realize quickly my experience is lacking haha!

  • @wizzbitgxs
    @wizzbitgxs 3 года назад +2

    This was a very cool action Movie! Maybe Mr. Robot season 5 with John Hammond? :D

  • @Kurainu
    @Kurainu 3 года назад +1

    I must say I get some Ippsec Vibes with the Ip Adress and how your saying the nmap stuff :D. But Grreat Video

  • @XiSparks
    @XiSparks 3 года назад +1

    "aws get-buckets" - Uncle Drew

  • @NothingPicksLocks
    @NothingPicksLocks 2 года назад

    That was friggin awesome John

  • @SinusQuell_
    @SinusQuell_ 3 года назад

    I learned so much today

  • @imranthoufeeque165
    @imranthoufeeque165 3 года назад +18

    Just to inform everyone who are doing OSCP... Linpeas has been banned by oscp because of auto-exploitation feature... Again Linpeas creator reached out to OSCP and confirmed that there is no auto-exploitation feature on linpeas.. So OSCP agrees for the new version of linpeas and banned older version of linpeas so be careful....

  • @mrbeancanman
    @mrbeancanman 3 года назад

    love your videos dude !

  • @DevashishGuptaOfficial
    @DevashishGuptaOfficial 3 года назад +23

    I wish the audio was a bit louder 🥺

  • @obeydabachir5975
    @obeydabachir5975 3 года назад

    You are the best Jonny

  • @playmaker1011
    @playmaker1011 Год назад

    More Cloud John!
    Thanks a lot, as always :)

  • @ResonantFractal
    @ResonantFractal 3 года назад +4

    Fun stuff! Wonder what would have happened if you had tried sshing with the usernames in their correct case.

  • @mushenji
    @mushenji 3 года назад +1

    This is extremely cool

  • @H4cK3r5
    @H4cK3r5 3 года назад +3

    Awesome John !

  • @andydwyer4285
    @andydwyer4285 2 года назад

    straight up cool

  • @crazyman7659
    @crazyman7659 3 года назад +2

    John is the best

  • @11anushkariya18
    @11anushkariya18 3 года назад

    Great music John Hammond xd

  • @secwriteups
    @secwriteups Год назад

    First person on yt who doesn't une neither Parrot nor Kali.

  • @AttkBeast
    @AttkBeast 2 года назад

    WWJD, What would John do? That's how I approach these challenges in HTB and THM. After watching these videos your voice and logic get stuck in my head!

  • @John-shreds
    @John-shreds 3 года назад

    Does the endpoint url take the place of access keys for the AWS cli? So because it's public you don't need any access & secret keys?

  • @ARIFF861
    @ARIFF861 3 года назад +2

    i wish for more htb content in the future

  • @ARZ10198
    @ARZ10198 3 года назад +1

    Peculiar john

  • @JoeM370
    @JoeM370 8 месяцев назад

    This is top-of-the-line material. I read a similar book that was a huge turning point for me. "AWS Unleashed: Mastering Amazon Web Services for Software Engineers" by Harrison Quill

  • @BrunoAraujo677
    @BrunoAraujo677 3 года назад

    This video show that I know more about something John doesn't, hahah 😂

  • @Cumander1
    @Cumander1 Год назад

    Beginner here. And i look up to the mountains and i see John Hammond😅...and my journey begins.

  • @jtucker87
    @jtucker87 Год назад

    John: How do I use this?
    Server: tutorial.start()
    John: Nope...

  • @aaryanbhagat4852
    @aaryanbhagat4852 3 года назад

    Content is awesome but i would suggest timestamping videos which have length greater then 30 min.
    Helps a lot!

  • @AhrenBaderJarvis
    @AhrenBaderJarvis 3 года назад +8

    Stop saying you're bad at everything. You're learning.
    I get the temptation but think of everyone watching who likely is newer to this than you. They also are just learning.

  • @leonardoorona
    @leonardoorona 3 года назад

    nice one John...

  • @luciferreficul1926
    @luciferreficul1926 3 года назад

    Nice!

  • @causeitis
    @causeitis 3 года назад +2

    31:46 I think the fi you commented out at the bottom was a mistake

  • @erosmlima5981
    @erosmlima5981 3 года назад +4

    AWS top! John

  • @luciferreficul1926
    @luciferreficul1926 3 года назад

    And i like your outro.

  • @pk10006
    @pk10006 3 года назад

    Epic skillz

  • @freshios4873
    @freshios4873 3 года назад +1

    Rick and morty creator knows coding??!? This dude can do it all

  • @JeremiahShaferSimulacra
    @JeremiahShaferSimulacra 2 года назад

    I know NMAP is kind of the go-to for port-scanning. Have you tried Rustscan? It's built on top of NMAP but runs port scans much faster with exactly the same scan options.

    • @_JohnHammond
      @_JohnHammond  2 года назад

      Yes! I have showcased rustscan in other videos and I am definitely a fan, it is a super cool tool and very fast!

  • @christophmosimann9244
    @christophmosimann9244 3 года назад

    Great video, but how did you know that pd4ml had this specific file inclusion vulnerability without researching?

  • @berndeckenfels
    @berndeckenfels 3 года назад

    It triggers me if you add options after arguments, but I like it that you stick to the IPpsec method

  • @cassandradawn780
    @cassandradawn780 3 года назад +1

    nice

  • @sebastian33458
    @sebastian33458 3 года назад

    🤯👌🏼💯

  • @nmay231
    @nmay231 3 года назад

    It contains a bucket.
    Dear God...
    Scout, SEDUCE ME!

  • @entertainment4you852
    @entertainment4you852 3 года назад

    Resources you have shared with us such as RUclips videos and blogs are enough to crack OSCP exam or should we join any institutions to gain knowledge....?

  • @RickHenderson
    @RickHenderson Месяц назад

    What's the importance of adding the entry to your etc/hosts file near 3:30?

  • @RCJans
    @RCJans 3 года назад +2

    fudge btw

  • @aryanmajumder1090
    @aryanmajumder1090 3 года назад

    Showing Root_id_rsa : invalid format . Why?

  • @Pr4547h
    @Pr4547h 3 года назад

    Audio volume little bit low compared with other videos

  • @kgmyatthu3171
    @kgmyatthu3171 3 года назад

    more of this please?

  • @umut6093
    @umut6093 3 года назад

    Maaan whyyyy whyy u did not shared this 2 days ago. I had a HW project about AWS pentesting. I had got only some old staf...

  • @whtiequillBj
    @whtiequillBj 3 года назад

    it was not possible to see the flickering lights in the video.

  • @kraemrz
    @kraemrz 3 года назад +1

    For yt algorithm

  • @btno222
    @btno222 3 года назад

    Hey There Seth Rogan!

  • @vibiemood1079
    @vibiemood1079 3 года назад +1

    Ooop...the voice is little down ...!!

  • @lugasiyt899
    @lugasiyt899 3 года назад

    Yo how do u Zoom In in the terminal Lol

  • @adityagupta3870
    @adityagupta3870 3 года назад +3

    Hey. John... Please make a course for newbies to advanced 😭😭🙏🏿🙏🏿🙏🏿please

  • @TheHappyXD
    @TheHappyXD 3 года назад

    how come he was able to use aws cli on the bucket despite using random secrets?

  • @fbmello
    @fbmello 3 года назад +1

    Man you are awesome 🤘🤘🤘......There was only one part that I didn't really understand. How did you run the .php in the S3 bucket??? because S3 only works with static webpage. It was not supposed to run .PHP 🤷‍♂️🤷‍♂️🤷‍♂️

    • @tomvandencorput1408
      @tomvandencorput1408 3 года назад +2

      You can use the s3 bucket stuff to upload the script. When you then visit the script via port 80, your request will be handled by Apache which will run PHP. If you finish the machine you can see that s3.bucket.htb will be forwarded to a docker container running local stack

    • @fbmello
      @fbmello 3 года назад +1

      @@tomvandencorput1408 OHHHHHHHHHH that makes sense. Thank you for the explanation.

  • @0xbinHex
    @0xbinHex 3 года назад

    What a handsome whitehead

  • @tanishsaxena545
    @tanishsaxena545 3 года назад

    Hello sir I have been watch RUclips for awhile now i saw your using ubuntu as your primary os soo my question is why u don't use kali or parrot os or any other Linux distribution????????????

    • @takipsizad
      @takipsizad 3 года назад +1

      ubuntu is for desktop which how he uses

    • @tanishsaxena545
      @tanishsaxena545 3 года назад

      @@takipsizad okkay 😁👍👍

  • @blackmrx6319
    @blackmrx6319 Год назад

    Nice HTML LFI xD

  • @80sixd
    @80sixd 2 года назад

    i8ts areally awkward watching you pretend to not know this stuff and or have not read these exact pages. Still love the channel

  • @djcb4190
    @djcb4190 Год назад

    You plunder

  • @kitajskijmost
    @kitajskijmost 3 года назад +3

    Где subtitles?

  • @ajualex3503
    @ajualex3503 3 года назад

    Can we hope for htb contents

  • @alimohammadi1148
    @alimohammadi1148 3 года назад +2

    You getting more views than ippsec now 🤨

  • @d3spis3m3
    @d3spis3m3 Год назад

    etc/ is pronounced etsy. not etcetera, is it not? Semantics, but, I love your content. I am aware this video is a year old.

  • @mmelt
    @mmelt 3 года назад

    Please fix the audio - it's too quiet

  • @jorides_official
    @jorides_official 3 года назад

    where is the flag

  • @nogoodhacker6944
    @nogoodhacker6944 3 года назад

    Hey John, Your content is awesome man, but it is not recommended for script kiddies to learn real hacking because your content requires some level of knowledge on hacking/programming, 'coz to be honest, i have been trying to understand your videos where i am now solving ctf challenges and still find it a bit confusing to understand your videos sometimes, anyways
    it's still a rich content!

  • @sefterm-zade9744
    @sefterm-zade9744 3 года назад

    I said fug guysss😂😂😂😂

  • @tamilxctf4075
    @tamilxctf4075 3 года назад

    Like first 10 comments; else:unsubscribe ("Mv to liveoverpellow");