HackTheBox "Business CTF" - Time - Command Injection

Поделиться
HTML-код
  • Опубликовано: 28 авг 2024
  • If you would like to support the channel and I, check out Kite! Kite is a coding assistant that helps you code faster, on any IDE offer smart completions and documentation. www.kite.com/g... (disclaimer, affiliate link)
    For more content, subscribe on Twitch! / johnhammond010
    If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
    PayPal: paypal.me/john...
    E-mail: johnhammond010@gmail.com
    Discord: johnhammond.or...
    Twitter: / _johnhammond
    GitHub: github.com/Joh...

Комментарии • 45

  • @markgentry8675
    @markgentry8675 3 года назад +5

    Really enjoyed the time you took to explain this one. it's pretty straight forward, but this format would be great for beginners. love your work

  • @SinusQuell_
    @SinusQuell_ 3 года назад +30

    this makes me want to try some of these myself

    • @FVT-tn8ji
      @FVT-tn8ji 3 года назад +1

      Yeah same, the problem is that Ive never done anything like that lol

  • @LlewdLloyd
    @LlewdLloyd 3 года назад +3

    Just wanted to say I'm new in the I.T. industry, read A+ and studying for my Network + cert while pursuing cyber security and watching these videos and having you explain things is really helpful for me despite how basic some of these are. Just wanted to say I appreciate the content this way.

  • @EmaCannella
    @EmaCannella 3 года назад +2

    Followed you up since start of the year and quality has evolved in the meantime. Keep It up📼

  • @viv_2489
    @viv_2489 3 года назад

    This little breadcrumbs are so essential, thanks for sharing 👌👍

  • @MovieWorldNow
    @MovieWorldNow 3 года назад

    I like the tune after the video ending

  • @ca7986
    @ca7986 3 года назад +1

    I love your work John! ❤️

  • @jocularich
    @jocularich 3 года назад +1

    Love your content John....learn more and more.....greeting from indonesia

  • @4lpina
    @4lpina 3 года назад

    absolutely love your videos John

  • @joeymelo2882
    @joeymelo2882 3 года назад

    Love the CTF videos! Keep that up man!

  • @highvisibilityraincoat
    @highvisibilityraincoat 3 года назад

    yay john is going back to his roots

  • @vivekchoudhary8745
    @vivekchoudhary8745 3 года назад

    I learned a lot from this ctf.

  • @safwanljd
    @safwanljd 3 года назад +3

    The reason it didn't work in the browser/curl was because you were using && instead of ;
    && runs the second command only if the first command ran successfully
    ; runs the second command regardless of the first command
    And since the first command is `date ''` which returns an error, the second command never ran!

    • @_JohnHammond
      @_JohnHammond  3 года назад +1

      ?format='; whoami # still fails in the browser.
      The command would run `date +''`, which doesn't error, and returns an error code of 0 indicating it succeeded. It just has an empty string for a format string :)

    • @AwesomeLazyNinja
      @AwesomeLazyNinja 2 года назад

      @@_JohnHammond I believe the reason it does not work in browser is because # is never sent to the server as it is the "fragment identifier". However, URL encoding it to %23 might have worked IMO :)
      Thank you for great video as always!

  • @ashishalex10
    @ashishalex10 3 года назад

    Awesome content, getting to learn some new stuff :)

  • @koukiadem
    @koukiadem 3 года назад +1

    Can you please tell us why it didn't work with curl or browser? And why it's working only python?

  • @andy-og7sv
    @andy-og7sv 2 года назад

    brilliant

  • @masfreitas
    @masfreitas 3 года назад

    love your videos man

  • @mmmdyarcavadl9004
    @mmmdyarcavadl9004 3 года назад

    Really helpful thank you

  • @faizaanilyas
    @faizaanilyas 3 года назад +3

    What happened to the dark web series?

  • @thischannelhad40subscriber51
    @thischannelhad40subscriber51 3 года назад

    Great video's mate.

  • @ikhmalfahmi9308
    @ikhmalfahmi9308 3 года назад

    Yayyyyy ctfs!!!!!!

  • @kiingjamesdagamer4738
    @kiingjamesdagamer4738 3 года назад

    Love ur vids

  • @sudosuraj
    @sudosuraj 3 года назад

    That was good

  • @evanhadi6395
    @evanhadi6395 3 года назад

    u are awsome

  • @comdeyoverflow2414
    @comdeyoverflow2414 3 года назад +6

    I am first command. Holy YES!

  • @prowlerL33T
    @prowlerL33T 5 месяцев назад

    Htb ca 2024 had same challenge again this year lol

    • @jobdekho-t6l
      @jobdekho-t6l День назад

      hey how did u crack the password? that time it was unprotected but now password is required. actually I am new here

  • @m4rt_
    @m4rt_ 3 года назад

    to the 8 people who disliked, Why?

  • @JitendraKumar-pi4bd
    @JitendraKumar-pi4bd 3 года назад

    Sir ... if possible ... please release a video on Pegasus spyware ...

  • @chillydickie
    @chillydickie 3 года назад

    shebang

  • @mrkaraly612
    @mrkaraly612 3 года назад

    Update your chrome

  • @neil7724
    @neil7724 3 года назад

    Nice try!

  • @wildmatt1205
    @wildmatt1205 3 года назад +2

    2nd comment because replies to comments don’t count.

  • @keroskyindonesia6477
    @keroskyindonesia6477 3 года назад +1

    3rd Comment Muahahaaaa

  • @deanvangreunen6457
    @deanvangreunen6457 3 года назад

    7th