HackTheBox - Headless

Поделиться
HTML-код
  • Опубликовано: 5 сен 2024

Комментарии • 40

  • @mf-11111
    @mf-11111 Месяц назад +1

    Every video of Ippsec is epic, thanks you ippsec for all your writeups of HTB!
    All of those are really exciting, and also I learn a lot with them.
    Like

  • @ClemensGooooo
    @ClemensGooooo Месяц назад +1

    Even though I already did the box, it was like always amazing and informative!

  • @PatrickHener
    @PatrickHener Месяц назад +1

    Really nice beyond root part. I like how you did all that total OSWE style. You could have concluded with that part and let the bot send you a root shell by using the command injection to do all the privesc part as well. Would have been fun having a one shot root reverse shell. Also look into goshs. It will give you a nice parsed view of the returned POST request with all the data when using -V in verbose mode.

    • @AUBCodeII
      @AUBCodeII Месяц назад

      Compromising an HttpOnly cookie definitely seems like something you would see on an OSWE lab or on the exam.

  • @HopliteSecurity
    @HopliteSecurity Месяц назад +1

    Great video, love your content. Keep it up 🙏☺️

  • @AUBCodeII
    @AUBCodeII Месяц назад +1

    Ipp, we need to get OSPP right now. No excuses. No mercy

  • @candyyyq
    @candyyyq Месяц назад +1

    I just did this box today in the morning 😂

    • @AUBCodeII
      @AUBCodeII Месяц назад

      I didn't know Kim Jong Un watched IppSec

  • @activ3Port
    @activ3Port Месяц назад +1

    THE GOAT

  • @drwombat
    @drwombat Месяц назад

    Excellent demo. What was the trick you at 16:05 to include the URL encoded spaces in your highlighted string? That seems very handy and something i often find myself wasting time having to go back and change

    • @AUBCodeII
      @AUBCodeII Месяц назад

      He pressed Ctrl+U to URL-encode the highlighted string. Conversely, you can press Ctrl+Shift+U to URL-decode the highlighted string

  • @hannahprobably5765
    @hannahprobably5765 Месяц назад

    Thanks awesome as usual

  • @user-up2rz4oo7v
    @user-up2rz4oo7v Месяц назад +7

    I don't know why no youtuber i watch, seem to use the mouse middle button, to paste whatever previously was highlighted. Super fast, no ctrl c \ v. If you get more used to this, it is like a second clipboard. Highlite text => Ctrl+c for a different clipboard. Then push middle button somewhere else to paste from that other clipboard. It can take some time to get more used to it. In tmux to paste hold shift+middle Button. Oh and only Linux 😅

    • @hoholebaguette7298
      @hoholebaguette7298 Месяц назад +1

      stop yapping

    • @AmanuelHaileGiyorgis
      @AmanuelHaileGiyorgis Месяц назад

      Oh my God. I owe you my energy, my guy!
      It works on my arch😂

    • @ancestrall794
      @ancestrall794 Месяц назад

      Thanks for the tip ;) i'll definitely give it a try next time

    • @AgresBoi
      @AgresBoi Месяц назад

      I use mouse with 6 buttons I use side 2 buttons for ctrl c and ctrl v
      It make life easy

    • @ippsec
      @ippsec  Месяц назад +6

      Simply because I dislike touching the mouse

  • @tg7943
    @tg7943 20 дней назад

    Push!

  • @candyyyq
    @candyyyq Месяц назад

    Hey I would love if you could make a video about Editorial box, there are a couple things that I don't fully understand and your videos are amazing so that would be awsome!

  • @mohamudmohamedbarre3459
    @mohamudmohamedbarre3459 Месяц назад

    Thank you sir learn’t lots of things from 🙏

  • @aymanelamsouguer613
    @aymanelamsouguer613 Месяц назад

    Hello, I am completely new here, so please I dont know why after i try to steal the cookie when pasting the cookie command and forwarding the post request i dont get anything on my local machine server

  • @NitrogenXP
    @NitrogenXP Месяц назад +1

    This might be dumb question but can someone explain why in post exploitation he got the shell with this /dev/tcp/10.10.14.8/9001 why wasn't the port specified like this /dev/tcp/10.10.14.8:9001? I am sorry I am still learning and I don't understand this.

    • @ippsec
      @ippsec  Месяц назад +5

      So /dev/tcp/ is a weird directory created by bash (not all shells have this). The IP is treated as a folder and port as a file.

    • @manikandann9796
      @manikandann9796 6 дней назад

      Hey @ippsec a dumb question how did you bring the IP address in CLI as default is it from your OS or HTB’s virtual machine?

  • @timgreen5281
    @timgreen5281 4 дня назад

    I don't understand how this one is a beginner box.. I feel like if you can solve this box, you can get any entry level job in cyber.. Just how I suppose to know all this stuff, if it is for beginner..

  • @LaviArzi
    @LaviArzi Месяц назад +1

    17:54 Dvir is a hebrew name, pronounced as is (dvir/dveer/dvear whatever)

  • @androiddoctor4897
    @androiddoctor4897 Месяц назад +1

    Can anyone tell me why we find the ttl value here ? Using -vv

    • @boogieman97
      @boogieman97 Месяц назад +3

      The v-flag is for verbose, so more details/information. Double verbose, shows the time to live. Triple verbose I think is showing actual ports it tries almost realtime

    • @de_pack_
      @de_pack_ Месяц назад +1

      ttl value can be used to determine the OS. For Linux, it's 64, for windows it's 128. He was trying to determine the OS. I would assume that was his intent.

    • @ippsec
      @ippsec  Месяц назад +6

      I find the TTL Handy as it can reveal [Port/Network] Address Translation, since the TTL Decrements everytime it hits a router. So when you scan a single IP and have different TTL's you know there are multiple hosts. It is one of those things that is rarely useful, but in the past, I have wasted a lot of time ruling out an attack because I didn't realize there were multiple hosts.

  • @dollarboysushil
    @dollarboysushil Месяц назад +3

    25:21 But we are hackers, we don't do this proper 🤣🤣

  • @h4gg497
    @h4gg497 Месяц назад +1

    Loled at NO AND THEN

  • @AUBCodeII
    @AUBCodeII Месяц назад +1

    IppStrike