HackTheBox "Business CTF" - Time - Command Injection

Поделиться
HTML-код
  • Опубликовано: 12 ноя 2024

Комментарии • 45

  • @padaloni
    @padaloni 3 года назад +6

    Really enjoyed the time you took to explain this one. it's pretty straight forward, but this format would be great for beginners. love your work

  • @SinusQuell_
    @SinusQuell_ 3 года назад +32

    this makes me want to try some of these myself

    • @FVT-tn8ji
      @FVT-tn8ji 3 года назад +1

      Yeah same, the problem is that Ive never done anything like that lol

  • @LlewdLloyd
    @LlewdLloyd 3 года назад +6

    Just wanted to say I'm new in the I.T. industry, read A+ and studying for my Network + cert while pursuing cyber security and watching these videos and having you explain things is really helpful for me despite how basic some of these are. Just wanted to say I appreciate the content this way.

  • @EmaCannella
    @EmaCannella 3 года назад +3

    Followed you up since start of the year and quality has evolved in the meantime. Keep It up📼

  • @MovieWorldNow
    @MovieWorldNow 3 года назад

    I like the tune after the video ending

  • @viv_2489
    @viv_2489 3 года назад

    This little breadcrumbs are so essential, thanks for sharing 👌👍

  • @highvisibilityraincoat
    @highvisibilityraincoat 3 года назад

    yay john is going back to his roots

  • @4lpina
    @4lpina 3 года назад

    absolutely love your videos John

  • @jocularich
    @jocularich 3 года назад +1

    Love your content John....learn more and more.....greeting from indonesia

  • @ca7986
    @ca7986 3 года назад +1

    I love your work John! ❤️

  • @vivekchoudhary8745
    @vivekchoudhary8745 3 года назад

    I learned a lot from this ctf.

  • @mrjoeymelo
    @mrjoeymelo 3 года назад

    Love the CTF videos! Keep that up man!

  • @ashishalex10
    @ashishalex10 3 года назад

    Awesome content, getting to learn some new stuff :)

  • @koukiadem
    @koukiadem 3 года назад +1

    Can you please tell us why it didn't work with curl or browser? And why it's working only python?

  • @andy-og7sv
    @andy-og7sv 2 года назад

    brilliant

  • @safwanljd
    @safwanljd 3 года назад +4

    The reason it didn't work in the browser/curl was because you were using && instead of ;
    && runs the second command only if the first command ran successfully
    ; runs the second command regardless of the first command
    And since the first command is `date ''` which returns an error, the second command never ran!

    • @_JohnHammond
      @_JohnHammond  3 года назад +1

      ?format='; whoami # still fails in the browser.
      The command would run `date +''`, which doesn't error, and returns an error code of 0 indicating it succeeded. It just has an empty string for a format string :)

    • @AwesomeLazyNinja
      @AwesomeLazyNinja 2 года назад +1

      @@_JohnHammond I believe the reason it does not work in browser is because # is never sent to the server as it is the "fragment identifier". However, URL encoding it to %23 might have worked IMO :)
      Thank you for great video as always!

  • @mmmdyarcavadl9004
    @mmmdyarcavadl9004 3 года назад

    Really helpful thank you

  • @masfreitas
    @masfreitas 3 года назад

    love your videos man

  • @faizaanilyas
    @faizaanilyas 3 года назад +4

    What happened to the dark web series?

  • @thischannelhad40subscriber51
    @thischannelhad40subscriber51 3 года назад

    Great video's mate.

  • @ikhmalfahmi9308
    @ikhmalfahmi9308 3 года назад

    Yayyyyy ctfs!!!!!!

  • @kiingjamesdagamer4738
    @kiingjamesdagamer4738 3 года назад

    Love ur vids

  • @evanhadi6395
    @evanhadi6395 3 года назад

    u are awsome

  • @sudosuraj
    @sudosuraj 3 года назад

    That was good

  • @comdeyoverflow2414
    @comdeyoverflow2414 3 года назад +7

    I am first command. Holy YES!

  • @JitendraKumar-pi4bd
    @JitendraKumar-pi4bd 3 года назад

    Sir ... if possible ... please release a video on Pegasus spyware ...

  • @m4rt_
    @m4rt_ 3 года назад

    to the 8 people who disliked, Why?

  • @barisck-1337
    @barisck-1337 7 месяцев назад

    Htb ca 2024 had same challenge again this year lol

    • @jobdekho-t6l
      @jobdekho-t6l 2 месяца назад

      hey how did u crack the password? that time it was unprotected but now password is required. actually I am new here

  • @mrkaraly612
    @mrkaraly612 3 года назад

    Update your chrome

  • @neil7724
    @neil7724 3 года назад

    Nice try!

  • @wildmatt1205
    @wildmatt1205 3 года назад +2

    2nd comment because replies to comments don’t count.

  • @keroskyindonesia6477
    @keroskyindonesia6477 3 года назад +1

    3rd Comment Muahahaaaa

  • @deanvangreunen6457
    @deanvangreunen6457 3 года назад

    7th