Tryhackme, Advent of Cyber 4 - Day 13!

Поделиться
HTML-код
  • Опубликовано: 2 дек 2024

Комментарии • 31

  • @ryanl.4296
    @ryanl.4296 2 года назад +3

    Wireshark is such a useful tool, glad to see a day in the AoC dedicated to it. Thanks for the video, subscribed.

  • @knightjack
    @knightjack Год назад +1

    Thank you very much for the help!

  • @andrewsboateng6845
    @andrewsboateng6845 Год назад +4

    Thanks for the walk-through. As I am attempting this room right now the malicious file has now been flagged for 22 more times on virustotal compared to when you were doing it and the connected IP addresses are more. So I got frustrated there for a second. Thanks again for the walk-through.

    • @wow_parzival5036
      @wow_parzival5036 Год назад

      Bandit Yeti has been busy associating more IP addresses! That infuriating Bandit Yeti APT.

    • @andrewsboateng6845
      @andrewsboateng6845 Год назад +1

      @@wow_parzival5036 it is up to us to save the world this Christmas🎅

    • @srirajtata9052
      @srirajtata9052 Год назад

      I am now doing this challenge, the virus total I copy pasted but no used I think it did not updated or so .

  • @DJSubstyla
    @DJSubstyla Год назад

    great walkthrough! Thanks 👍

  • @Sam-uy7et
    @Sam-uy7et 2 года назад

    Thanks for the walk through Security Ninja! :)

  • @jacksonhue381
    @jacksonhue381 Год назад

    Fun one solving this task, thanks!

  • @WestleyRamey
    @WestleyRamey 2 года назад

    Very easy to follow. Thank you! I also appreciate you doing the work with us. My learning style errors out briefly when I'm looking at the information already gathered.

  • @wow_parzival5036
    @wow_parzival5036 Год назад

    I'm not sure if it's just my situation, but once I push Ctrl+C on my VM attackbox, I don't need to open the "clipboard" on the side. I think that clipboard just shows what is copying over, but I don't have to copy a 2nd time from it to paste on THM site for answers (or other sites like CyberChef). Hope this helps others :)

  • @howtocyberwar
    @howtocyberwar 2 года назад

    Another very good room! Thank you!

  • @capivaradeprograma
    @capivaradeprograma Год назад

    Awesome challange and nice video 🙂

  • @MAX-nv6yj
    @MAX-nv6yj Год назад

    I love your videos keep going my friend + u guys are the best (THM)

  • @orionblu3
    @orionblu3 Год назад +4

    Honestly if THM doesn't have an OpenVPN option for the room I'm not even attempting it. The constant disconnection issue is a huge problem

  • @pablomartinezone
    @pablomartinezone 2 года назад

    Love your videos brother! Very concise and to easy to follow.

  • @whitedwarf33
    @whitedwarf33 2 года назад

    Hey there - thanks for the video -
    i finished the challange before watching, except for one thing - where could i see that the "used protocol" was RDP?
    checked out whole wireshark but couldn't figure that out on my own...

    • @vinr
      @vinr 2 года назад +1

      Just use the found port 3389 and search on the internet

    • @majorxen6390
      @majorxen6390 2 года назад +1

      Certain ports you will become familiar with through experience, but if you arent familiar Google is your friend and this wikipedia site should be part of your reference tools - en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers

  • @Adyisekk
    @Adyisekk Год назад

    So we worked with the file from the very beginning of the challenge. But how do you extract the network traffic into the file in the first place? Thanks!

    • @SecurityNinja
      @SecurityNinja  Год назад +1

      There are tools out there you can capture network traffic. Wireshark itself can also do this. confluence.atlassian.com/kb/how-to-capture-http-traffic-using-wireshark-fiddler-or-tcpdump-779164332.html

    • @Adyisekk
      @Adyisekk Год назад

      @@SecurityNinja thanks!

  • @mentaripagi__
    @mentaripagi__ Год назад

    Thanks :D

  • @dilshan_ketakumbura_666
    @dilshan_ketakumbura_666 2 года назад

    Thanks

  • @Trick_E_Lemonz
    @Trick_E_Lemonz 2 года назад

    In real world. How often would you be using pcap files/ wireshark

    • @SecurityNinja
      @SecurityNinja  Год назад

      I think that really depends on the company. Some companies use it, others are not. My current role allows me to play Wireshark quite a bit.

  • @WhisperFire26
    @WhisperFire26 2 года назад +5

    Your mumbling made it hard to understand and the lack of a noise gate meant that we heard every keystroke and mouseclick... You need to calibrate your audio.

  • @manthanghasadiya
    @manthanghasadiya 2 года назад +1

    Great