TryHackMe! SweetRice Exploit & Stabilizing Shells

Поделиться
HTML-код
  • Опубликовано: 27 ноя 2024

Комментарии • 69

  • @guineapigs2998
    @guineapigs2998 4 года назад +57

    Love how gobuster just chugged along in the background the entire video trying to find more directories/files xD It was on a quest, even if it was no longer needed xD

    • @_JohnHammond
      @_JohnHammond  4 года назад +19

      It's dangerous to go alone -- take this!

  • @danauri7186
    @danauri7186 4 года назад +55

    why is ginger Seth Rogan teaching me computer security?

    • @tswdev
      @tswdev 4 года назад

      Go for Gun Gamers if you want a buffed up Seth Rogan teaching you about guns and airsoft lol. They even have the same glasses: v=uZMMAXugI7E

    • @zartech-info
      @zartech-info 4 года назад

      The voice lol. I knew I recognized it.

  • @sirw369
    @sirw369 4 года назад +6

    Thanks again for an awesome walkthrough! 💪🏼🙌🏼

  • @AJXD2
    @AJXD2 2 года назад

    Thanks for these videos. I’m learning programming Right Now and you give me motivation to keep going cause one day I might be like you.

  • @mi2has
    @mi2has 4 года назад

    use of searchsploit and script technique was slick, new tools to learn..cool

  • @WRWhizard
    @WRWhizard 2 года назад +2

    Being a newbie I found the hash easy enough after discovering the directories and crawling around through them. Once I was logged in I did realize I'd have to look for exploits and did find several for SweetRice. At that point I had no idea how do do what I figured I needed to do. So, I read a walk through. Saw I needed to do RCE and get a shell. Bailed out. Later watching YTVids and saw this one. Chuckled a bit at how long it took you to find the SQL backup but then you took off like a rabbit and I had a real hard time following the rest. I kind of learned the script trick for stabilizing a shell a few nights ago but will need to do it a bunch to retain it. Well... at least I know I'm not gonna do this all by myself yet. Have to watch, read and learn some more.

  • @gin263
    @gin263 4 года назад +7

    I just practice My English listening

  • @mamtachahal1277
    @mamtachahal1277 4 года назад +2

    I love watching those videos, even though I don't understand much

  • @thecaretaker0007
    @thecaretaker0007 4 года назад +8

    I have been requesting for your stabilize shell script for a long time. Thanks John.

  • @Vogel42
    @Vogel42 4 года назад +16

    11:54 a short way to memorize it is TUNA please: ss -tunapl

  • @mattfowler6504
    @mattfowler6504 4 года назад +1

    Great video hope you're doing well don't over work yourself to much!!

  • @ARZ10198
    @ARZ10198 4 года назад +1

    Just did this box and found your walkthrough for this later xD

  • @yankeesouth
    @yankeesouth 3 года назад

    I like this video and I am not just typing this to kick in the Al Go Rhythm

  • @samfretus3394
    @samfretus3394 4 года назад +4

    Hey John, I appreciate all your hard work and the content you've been releasing as of late, I am new to the world of pentesting and am learning a great deal from your videos!
    May I ask what theme you're using for sublime text, I have the default but would love an explanation on how to colour coordinate certain symbols and the like, for a better viewing and typing exp.
    Cheers man, keep up the great work!

    • @_JohnHammond
      @_JohnHammond  4 года назад +12

      Very happy to hear that! Thanks so much for watching! I use the `monokai` theme in Sublime Text. If you don't have a file saved with a specific extension and it cannot auto-detect what syntax highlight to use, you can enter Ctrl+Shift+P to enter the Sublime Text prompt and then type in something like "bash" or "python" or "html" to find the option to "Set Syntax Hilighting To" and you can specify what it might highlight the code words with. Hope that helps a bit!

  • @WheYPrOTeiNProductions
    @WheYPrOTeiNProductions 4 года назад

    Your channel is the future man ,u rocks...
    Make a vídeo teaching us how to join in the rooms of TryHackMe without subscribe, the tools that you use most to do the test.
    And how we use python, because i se u always open 2 tabs, i want to learn how to do that, sorry but i am a newbie but a love to watch your videos and im learn a lot thanks.

    • @peterarbeitsloser7819
      @peterarbeitsloser7819 4 года назад +1

      You have to use a terminal emulator called TERMINATOR. Then search for shortcuts.

  • @kkhek
    @kkhek 4 года назад +1

    awesome highquality content. keep going like this 👍🏽

  • @ElGhadraouiTaha
    @ElGhadraouiTaha 4 года назад

    man i just love your videos !!!!

  • @WheYPrOTeiNProductions
    @WheYPrOTeiNProductions 4 года назад +1

    Where i can find these stabilize shell scripts?

  • @billgen7663
    @billgen7663 4 года назад

    Once again awesome content!

  • @gbravy
    @gbravy 4 года назад

    What's this setup that you use? Your main machine or something else? It's not a standard Kali vm. Also, it's a much nicer output when using linpeas

    • @_JohnHammond
      @_JohnHammond  4 года назад +1

      In this video I'm running Ubuntu installed on my laptop, with the Terminator terminal emulator. Thanks for watching!

  • @R4yan-
    @R4yan- 4 года назад

    i love this kind of videos ! :)

  • @aiden6343
    @aiden6343 4 года назад

    no idea what he is talking about but still find it fum to watch

  • @bidfca5980
    @bidfca5980 4 года назад +1

    JOHN CAN YOU PLEASE MAKE VIDEOS ABOUT BINARY EXPLOITATION AND ASSEMBLY FOR BEGINNERS? I'VE BEEN STRUGGLING A LOT TO LEARN ABOUT IT. LOVE YOUR VIDS

    • @gibrael_
      @gibrael_ 4 года назад +1

      Dá uma olhadinha em um canal chamado LiveOverflow. Também tô aprendendo Binary Exploitation, lá encontrei um conteúdo excelente! Ele tem uma playlist só de Assembly pra Iniciantes!

    • @bidfca5980
      @bidfca5980 4 года назад

      @@gibrael_ Opa, vlw pela dica ;)

  • @ugwsiliguri
    @ugwsiliguri 4 года назад

    Ur just awesome

  • @solon7740
    @solon7740 4 года назад +1

    How are you running these stabilize shell scripts etc?

    • @ARZ10198
      @ARZ10198 4 года назад

      check out his poor man's pentest video

  • @t.i.s.r.oofficial7142
    @t.i.s.r.oofficial7142 4 года назад

    Guys i want to learn all of this so quickly. How long does it take to learn/study this?

    • @arminharper510
      @arminharper510 4 года назад

      Anywhere between a year and 12 years :p

    • @nero2k619
      @nero2k619 4 года назад

      After 3 months you should be able to understand basic topics and after a year you should be comfortable with what you doing at decent level. Of course if you willing to spent 5 hours per day studying and practising.

  • @novicetrader555
    @novicetrader555 4 года назад

    🔥🔥

  • @chiragsharma6215
    @chiragsharma6215 3 года назад +1

    How do you bring on your own terminal back to tty (after stty raw -echo)?

  • @gwnbw
    @gwnbw 4 года назад

    Amazing vid though 🚩

  • @brandodelatorre
    @brandodelatorre 4 года назад +1

    Can anyone explain what stabilizing shell can do? I didn't follow it was so fast HAHAHA

    • @ARZ10198
      @ARZ10198 4 года назад

      It allows you use auto tab , like if you got a shell and when you try to use up and down arrow key it would show just random character like "[^A" so to avoid it we stabilize shell for our ease of use it is not necessary

  • @vira7912
    @vira7912 4 года назад

    Hi Brother ,
    in my terminal ever stunk when I input "stty raw -echo " and then ctrl +z ,fg %1
    It don't respond back nc -lvnp 9001.
    how to solve please explain me

    • @ARZ10198
      @ARZ10198 4 года назад +1

      when you get a non stabilize shell press ctrl+z on that terminal then on the same terminal "stty raw -echo" then "fg "press enter also if you want clear command to work "export TERM=xterm"

  • @floatingblaze8405
    @floatingblaze8405 4 года назад +4

    My question isn't why is there a reverse shell, but why the hell does it point to a class C IP address? I thought THM uses class A networks.

    • @ingokrispin3482
      @ingokrispin3482 3 года назад +1

      Guess the person who built this box had tested in their own network before they pushed it to THM.
      There are many more boxes with references to internal IPs other than class A ones.

  • @gwnbw
    @gwnbw 4 года назад +4

    14:40 my terminal does weird shit when I try to foreground the session, and getting: "Error opening terminal: unknown.
    " when trying to modify /etc/copy.sh to get a shell for the root.

  • @dannyv12
    @dannyv12 4 года назад

    Can someone explain me why my terminal crashes in tmux and zsh when i do the CTRL+Z; stty raw -echo fg ?

    • @_JohnHammond
      @_JohnHammond  4 года назад +3

      In zsh, you will need to combine the two stty raw command and the fg command into just one line, with a semi-colon. So it looks like:
      stty raw -echo; fg

    • @dannyv12
      @dannyv12 4 года назад +1

      @@_JohnHammond damn your fast :-) thanks for you quick answer. love your vids !

    • @dannyv12
      @dannyv12 4 года назад

      @@_JohnHammond I've tested it on the root me box on tryhackme the crash is gone but the shell is not stable I can't copy and I can't see what I'm typing and it doesn't create enters. Even the export XTERM didn't word when I execute reset it worked somehow 😎

  • @biswajitdutta6063
    @biswajitdutta6063 2 года назад

    My comment

  • @szymex73
    @szymex73 4 года назад +1

    .

  • @leventgul7690
    @leventgul7690 4 года назад

    cevaplara bakanlar +1

  • @djebbaranon5892
    @djebbaranon5892 4 года назад

    I have never found suid binary exploit in real life the only way to esculate your privlege is with Kernel's exploit 😂😂

  • @moonshadow6224
    @moonshadow6224 3 года назад

    where do I find the script John used to stable the shell "stabilize_shell.sh"