How to Proxy Command Execution: "Living Off The Land" Hacks

Поделиться
HTML-код
  • Опубликовано: 27 ноя 2024

Комментарии • 68

  • @Logan-vw8bg
    @Logan-vw8bg Год назад +22

    John! Thanks for everything you put into this community. I started my cyber career path last year and you've been a tremendous resource. Thanks again and cheers to the new year!

  • @Counterhackingsafe
    @Counterhackingsafe Год назад +3

    John, you are a master of the craft. Every time I watch one of your videos, I learn something new and valuable. The way you explain "Living off the Land" hacks is clear and easy to understand, making it accessible to all levels of cyber enthusiasts. Keep up the great work and thank you for all the knowledge you share with the community.

  • @netscout2451
    @netscout2451 Год назад +1

    Getting to see how you used procmon to investigate the scenario was awesome. Well done

  • @evilcorp3037
    @evilcorp3037 Год назад +4

    Wow, this is amazing. Thank you for your hard work, John!

  • @RealCyberCrime
    @RealCyberCrime Год назад +76

    Living off the land - a nightmare for script kiddies

    • @guitarware
      @guitarware Год назад +4

      lol

    • @whateverppl1229
      @whateverppl1229 Год назад +11

      just give me my botnet so I can press the funny button.
      Ion cannon go brr

    • @notme4526
      @notme4526 Год назад +1

      Ion cannon wasn't a botnet? It was just software that spammed request from your computer only to specified site that you started by running it there were no c2's, it was dependent on many people launching the tool at once following others. DDoS will probably go down in history as the method of attack from people with zero knowledge.

    • @goodnightmr5892
      @goodnightmr5892 Год назад

      Best Comment Ever!

    • @ytg6663
      @ytg6663 Год назад

      @@whateverppl1229 what is your botnet price

  • @DarkFaken
    @DarkFaken Год назад +4

    Your content is always top notch! Thanks for everything ❤️

  • @jorisschepers85
    @jorisschepers85 Год назад

    This content is gold. Thanks for explaining it in a calm and step by step way. Keep it going John.

  • @patrickslomian7423
    @patrickslomian7423 Год назад +1

    Happy New Year guys ! : )
    John, I love your content , please keep up the great work! :) !
    Btw. Grzegorz Tworek is a great teacher, his knowledge about Windows security is legendary .

  • @purplesprout5774
    @purplesprout5774 Год назад +4

    ok, off to test if the xdr detects this and if not rule creation and more testing! Thanks John, the red perspective is a great way to continue to build the blue fortress!

  • @centdemeern1
    @centdemeern1 Год назад

    6:32 - Tip: the windows equivalent to “which” is “where”, so you can do “where tpmtool”

  • @hamzarashid7579
    @hamzarashid7579 Год назад +2

    John your videos make me motivated, Thank you so much for these amazing videos.

  • @first-thoughtgiver-of-will2456
    @first-thoughtgiver-of-will2456 Год назад +1

    This shows how we really need to rework our operating systems.

  • @cybersploit7378
    @cybersploit7378 Год назад +2

    Interesting! We’d love more videos like this

  • @daiceman825
    @daiceman825 Год назад +11

    I wonder if this will be patched anytime soon...
    What level of privilege did calc.exe end up spawning with? Could this be a possible avenue for privesc, or is it meant only as a means of obfuscation?
    As always, love the content!

    • @0xbitbybit
      @0xbitbybit Год назад +3

      I just tried it, it runs as the user who ran tpmtool.exe, so no privesc.

  • @ThiagoSouza-oo6fj
    @ThiagoSouza-oo6fj Год назад

    OMG! Awesome Content John, as always!

  • @jcc6495
    @jcc6495 10 месяцев назад

    Great stuff as always John!!!

  • @eddiesalinas
    @eddiesalinas Год назад +2

    Thank you John for your content!

  • @sentinelaenow4576
    @sentinelaenow4576 Год назад +1

    Magnificent! Thanks a million! You rock Sir!

  • @maxxthecoder5974
    @maxxthecoder5974 Год назад

    Great video John!!!!!

  • @MygenteTV
    @MygenteTV Год назад

    I wanted something like this weeks ago the problem is Windows will stop any weird exec you try to save into the machine

  • @kyputer
    @kyputer Год назад

    Great video! Love it :D

  • @utensilapparatus8692
    @utensilapparatus8692 Год назад

    Buying time - gr8 tutorial

  • @NoportOfbot
    @NoportOfbot Год назад

    good content as always

  • @dmadden999
    @dmadden999 Год назад +1

    Intel, now PlexTrac. Do you feel dirty, reading off these scripted ads?

  • @samuelirungu5324
    @samuelirungu5324 Год назад

    Actually, tried this and loved it. kudos John...

  • @petermayagibson
    @petermayagibson Год назад

    Wow!

  • @SumanRoy.official
    @SumanRoy.official Год назад +1

    They patched it, it now uses full path of cmd.exe 😂

    • @_JohnHammond
      @_JohnHammond  Год назад +3

      Which version/patch of Windows are you seeing this on? On a fully updated Windows 11 box it still seems to work just fine for me.

    • @emmetgwilliam6527
      @emmetgwilliam6527 Год назад

      @@_JohnHammond windows 11 my old computer had a lot of problems with my linux terminals on there never working like Ubuntu and Debian do u use windows 11?

  • @mikeuk1927
    @mikeuk1927 Год назад +3

    You could pronounce his name more less like this: Ghsheghosh Tvorek ;)

  • @LindomarkBiohazardYTB
    @LindomarkBiohazardYTB Год назад +1

    hum uma boa falha execution remote do windowns genial

  • @guilherme5094
    @guilherme5094 Год назад

    👏👍

  • @asdfasddfs5484
    @asdfasddfs5484 Год назад

    Sweet

  • @AP-rv6kk
    @AP-rv6kk Год назад

    Wonder if this can work as another applocker bypass

  • @ChiefYOUtuber
    @ChiefYOUtuber Год назад

    👌

  • @SzymekCRX
    @SzymekCRX Год назад

    Polska!

  • @oinatzgarciagorrotxategi7120
    @oinatzgarciagorrotxategi7120 5 месяцев назад

    Sinapsis

  • @ftechnologies1
    @ftechnologies1 Год назад

    Nice one

  • @CharlesManch
    @CharlesManch Год назад

    😳😲

  • @codrindumitrescu
    @codrindumitrescu Год назад +1

    hey john, could you please make a video on uninstalling microsoft edge via your windows emulator?

  • @slavik1513
    @slavik1513 10 месяцев назад

    same as ark game

  • @Shintowel
    @Shintowel Год назад

    Mantap

  • @vanillafromnekopara
    @vanillafromnekopara Год назад

    Damn

  • @demon1058
    @demon1058 Год назад +1

    Can you teach how to make malware persistent

    • @corruption781
      @corruption781 Год назад +4

      bro do it your self dont be a *SKID*

    • @demon1058
      @demon1058 Год назад

      @@corruption781i can't find anything related to that

    • @watchmehope6560
      @watchmehope6560 Год назад

      @@demon1058 i highly doubt that lol.

    • @JoakimBB
      @JoakimBB Год назад

      Sektor7

    • @0xbitbybit
      @0xbitbybit Год назад

      @@demon1058 If you can't Google and find information or education resources, then don't bother going any further to be a hacker, it's probably THE most important skill, to be able to find things out.

  • @ashishkhanduri1327
    @ashishkhanduri1327 Год назад

    U always want to be politicaly correct...or I can watch ur words more than hacking community person does...hahah

  • @murderbunnies
    @murderbunnies Год назад

    do you make more money from youtube or from pentesting?

  • @johngreco7987
    @johngreco7987 Год назад

    hi john, i have a problum you might be able to help me with , i think somone is rooted in my system,if interested email me ASAP