HackTheBox Zipping

Поделиться
HTML-код
  • Опубликовано: 27 авг 2024

Комментарии • 28

  • @AUBCodeII
    @AUBCodeII 7 месяцев назад +29

    You can't spell Zipping without Ipp

  • @user-js4wi8mp7m
    @user-js4wi8mp7m 7 месяцев назад +1

    Nice! I really like the second unintended method because it shows whoever discovered this, knew how the code works in deep depth and how to exploit it. That's something I need to get good at!

    • @ippsec
      @ippsec  7 месяцев назад +2

      Haha nope didn't really know the code in depth. Had looked in depth after finding it, null bytes is something I try a lot and when it didn't throw an error at upload, but the file never existed. Started debugging it and discovered what happened.

  • @xrunner55
    @xrunner55 7 месяцев назад

    I remember popping this box. Figuring out the proper formatting for the file extension bypass was a pain. Trying all of them and also figuring out how to format it was educational. Once I got a foothold with that, it was a lot easier.

  • @mohammadhosein6847
    @mohammadhosein6847 7 месяцев назад

    I always learn sth new by watching you videos.TY

  • @utkarshagrawal6060
    @utkarshagrawal6060 7 месяцев назад

    Amazing. Always great to see ippsec video

  • @anonymouspotato6017
    @anonymouspotato6017 7 месяцев назад +1

    Great video! I actually have a few questions about the machine. There're actually two files that we can perform SQLi : product.php as shown in the video and cart.php at product_id parameter. However, we cannot write files with cart.php and I couldn't figure out why.
    Also for the lfi part, we can't include the file if the php file was written to /tmp directory. I was able to perform it on my machine but the machine didn't like /tmp.

    • @ippsec
      @ippsec  7 месяцев назад +2

      /tmp is a dangerous directory because of SystemD PrivateTmp. MySQL and Apache have different tmp directories.

  • @0xmoriarty36
    @0xmoriarty36 7 месяцев назад +2

    Keep it up

  • @stefan.b7812
    @stefan.b7812 7 месяцев назад

    It is really hard to see urls and payloads on browser address bar. Can you zoom a little when working on address bar? Thanx in advance.

  • @Yoyo-qn4mv
    @Yoyo-qn4mv 7 месяцев назад

    Learned so much from this one :) Tnq sir

  • @HackerBabaOfficial
    @HackerBabaOfficial 7 месяцев назад

    Can you kindly tell which keyboard you are using ?

    • @ippsec
      @ippsec  7 месяцев назад

      Ducky Zero with cherry mx reds.

  • @y.vinitsky6452
    @y.vinitsky6452 7 месяцев назад

    Yay

  • @tg7943
    @tg7943 7 месяцев назад

    Push!

  • @perfectshow-bx1ov
    @perfectshow-bx1ov 7 месяцев назад +1

    Sir I have many issue's on bookworm machine please could you help me to solve it 😉

    • @trustedsecurity6039
      @trustedsecurity6039 7 месяцев назад +2

      There is tons of discord server where people do box together or help others people ;) That's also why i find the ranking a bit useless for most people, i interviewed a guy who was 48 or 58 on the ranking but didnt answer basic web question like what is a SSRF, didnt know what Magic bytes are...

    • @perfectshow-bx1ov
      @perfectshow-bx1ov 7 месяцев назад +1

      @@trustedsecurity6039 thanks for your suggestion thanks a lot 🫡

  • @riezzo1350
    @riezzo1350 7 месяцев назад

    i REALLY struggled with this one

  • @0x2e2e2f
    @0x2e2e2f 7 месяцев назад

    Hi guys, beginner quest here, I should avoid use Ubuntu as main operating system ? Ippsec uses windows ?

    • @younests.1824
      @younests.1824 7 месяцев назад +3

      Ippsec uses Parrot OS - HackTheBox Edition

    • @0x2e2e2f
      @0x2e2e2f 7 месяцев назад

      @@younests.1824 vm or main host ?

  • @sand3epyadav
    @sand3epyadav 7 месяцев назад

    Miss you sir , plz repying

  • @0xUnixy
    @0xUnixy 7 месяцев назад

    قولها تاني كدا يحب

  • @houssam3078
    @houssam3078 7 месяцев назад +2

    I hate watching your videos. I try hard to be on your level but I can't. You make things look easy, I'm thinking of staying away from this field

  • @felixkiprop48
    @felixkiprop48 7 месяцев назад

    peace