HackTheBox Walkthrough // Three

Поделиться
HTML-код
  • Опубликовано: 21 окт 2024

Комментарии • 114

  • @lucmarrouche71
    @lucmarrouche71 6 месяцев назад +1

    I love this guy, great teacher, well spoken, knowledgeable and takes the time to explain things in details

  • @jhc1979
    @jhc1979 Год назад +33

    Your explanation made me understand this x10 better than the official HTB tutorial. Thank you!

    • @johnbuery687
      @johnbuery687 Год назад

      Couldn't agree more! Keep up the good work @FindingUrPasswd!!!

  • @pietrowy-pieriewod-i-subtitr
    @pietrowy-pieriewod-i-subtitr Год назад +43

    For 15:19, if ur gobuster version is 3.5, u'll need to add "--append-domain true" to the command for that the option is by default false. Otherwise, u won't get the subdomain name in the scan result.

    • @akotamaki3385
      @akotamaki3385 Год назад

      Thank you 🙏

    • @rogert144
      @rogert144 Год назад

      Thank you, and Yes for gobuster version above 3.1 we need to use the option --append-domain to view sub domain

    • @kourygg8738
      @kourygg8738 Год назад

      thanks you that wa the same issue l was having appreaciate your help

    • @defX0bite
      @defX0bite 10 месяцев назад

      great job! Thanks

    • @9gogox
      @9gogox 10 месяцев назад

      Merci

  • @KevinJohn556
    @KevinJohn556 6 месяцев назад

    Your awesome. Your guides are helping me understand so MUCH MORE! I am half way through my google classes and this is well past what I’m doing right now so I’m getting lost easily. It’s so much easier listening to you than following their write ups.

  • @jarvis32aj
    @jarvis32aj 5 месяцев назад

    Awesome walk through, thank you for this. You did a great job of breaking down the "why" that a lot of others might take for granted or skip over, it's greatly appreciated.

  • @gamingandtech5151
    @gamingandtech5151 Год назад +1

    Best! I understood everything,I had watched many tutorials but didn't understand a thing. Cheers

  • @itSinger
    @itSinger Год назад

    Great explanation. Finally understood this gobuster thing after I spent 2 hours of useless search. Thank u ♥️

  • @iannavarro138
    @iannavarro138 2 года назад +3

    Incredible video!! I was strugling with the parameters in the url and setting up the listener and this video really help me to understand everything, best of lucks. Hope to see you in the top channels one day!

  • @karthikbt7239
    @karthikbt7239 11 месяцев назад

    Hey thank you so much for this tutorial. This box was very challenging for me especially because I'm a complete beginner and have no experience with Amazon.
    But your explanation on the working of the things in the backend, setting up a reverse shell made things clear. It was challenging to understand all this but hopefully I get better. Your explanation helped me understand this box so much better

  • @papafhill9126
    @papafhill9126 Год назад

    This one was super confusing in the walk through, thank you for this video!

  • @dnk4eva
    @dnk4eva 11 месяцев назад

    This is great man . Thank you for the writeup.

  • @kavishkagihan9495
    @kavishkagihan9495 Год назад

    Nice walkthrough. Hope you enjoyed the box!

  • @tone_loc
    @tone_loc 6 месяцев назад

    Great walkthrough! thank you! subscribed!

  • @ditapeskova4
    @ditapeskova4 10 месяцев назад

    This is a great video. I finally got reverse shells!

  • @cazatesorosmurcia3832
    @cazatesorosmurcia3832 Год назад +3

    Me uno al resto de comentarios. Solo he visto un video y puedo decir que tu forma de explicar es una maravilla. Voy a repasar los walkthroughs que ya habia terminado con tus videos ya que añaden mucha informacion extra e incluso a veces de forma mas practica. Enhorabuena!

  • @shawnawan209
    @shawnawan209 Год назад

    You a G bro! Three days to figure this out and this vid was the one! Was literally 30 seconds from throwing my desktop out the window - appreciate you

  • @nightenamoured4798
    @nightenamoured4798 2 года назад

    A video that deserves million likes

  • @MarcA75
    @MarcA75 2 года назад +28

    For everyone that had the same problem as me that gobuster didn't showed the s3.thethoppers.htb subdomain.
    The problem comes from a change from gobuster 3.1.0 to 3.2.0. With the current version you have to include the flag --append-domain.
    So your command should now look like this:
    gobuster vhost --append-domain -u TARGET -w WORDLIST

    • @TheAbnormalDesigner
      @TheAbnormalDesigner 2 года назад +1

      There's 2 dashes before append-domain, for those that couldn't see the space :-)

    • @1amkdm
      @1amkdm Год назад

      you win the internet today :D

    • @JuanfeDV
      @JuanfeDV Год назад

      My respects sir

    • @AgungDimasIrawan
      @AgungDimasIrawan Год назад

      thank you sir

    • @macstar95
      @macstar95 Год назад

      Taz you a real one

  • @Ged325
    @Ged325 Год назад

    Thank you for actually showing the reverse shell. Tutorial was off and have a better understanding of what's going on.

  • @Nickm-ns2jv
    @Nickm-ns2jv 2 года назад

    Amazing video, commenting for algo, keep it up. Its hard to find quality HTB videos and you are filling a void in the youtube market!!

  • @arthurbenavides465
    @arthurbenavides465 Год назад

    This is my first htb walkthrough vid i watched. Haven’t done any of my own labs on the site yet. Very informative and well put together. Subscribing!

  • @songyh4290
    @songyh4290 2 года назад +4

    Great explanation! However I think since we can put the php web shell to the bucket to run command on it, we can just pass the command "cat ../flag.txt" to get the flag without using reverse shell.

    • @FindingUrPasswd
      @FindingUrPasswd  2 года назад +5

      Yep you technically can! However it’s basically always best practice to escalate to a rev shell because it gives us an interactive session with the host and in a real world scenario you’d always want to try to take it a step further to see if you can fully compromise (privilege escalate) a server from an initial foothold! And you need an interactive session to do so! :)

  • @danielechiappa1046
    @danielechiappa1046 Год назад

    Best explanation ever. I really appreciate what you are doing bro

  • @mikuaster7087
    @mikuaster7087 2 года назад +2

    I really like your videos, it's very helpful for me as a noob,thx.

  • @flintl0ck79
    @flintl0ck79 2 года назад

    the --open tag for nmap is clutch, thanks for sharing!

  • @karlozf9278
    @karlozf9278 Год назад

    man, great explanation! it was extremely helpful and you’re very talented in teaching!

  • @haydenbruinsma5091
    @haydenbruinsma5091 Год назад

    Awesome video! I learned a few new methods such as your way of achieving a reverse shell :) love it!

  • @smar3tech343
    @smar3tech343 Год назад

    im glad i found this video this will help me understand everything for the oscp test preparing very well explain keep up the good work👍

  • @mariojules1814
    @mariojules1814 5 месяцев назад

    Thank you i was ready to give up untill i saw your tutorial.

  • @7311Kento
    @7311Kento Год назад +1

    Que forma tan clara de explicar. Muchas gracias!

  • @elamishne8982
    @elamishne8982 2 года назад

    Thank you! Please continue making more videos.

    • @FindingUrPasswd
      @FindingUrPasswd  2 года назад +1

      Absolutely! The next one is already in progress

  • @domydew
    @domydew Год назад

    you've earned my sub! please do more like this.

  • @patriciobriones2536
    @patriciobriones2536 Год назад

    i always think shell and reverse shell a little bit confuse, but you make me understad better this way

  • @carlosolvera5556
    @carlosolvera5556 Год назад

    you're amazing, man. Thank you for sharing your knowledge about the topic

  • @ArcamNight
    @ArcamNight 2 года назад +14

    it's difficult to do this machine without a walkthrough

  • @danielmoncayo3732
    @danielmoncayo3732 Год назад

    you are an outstanding explainer haha thanks so much for the walkthrough!

  • @monkeyparadise8767
    @monkeyparadise8767 2 года назад

    Hello from Russia, I love you and your videos. I watch with auto subtitles and even in this case understand your explaining. Waiting for new content 👍

  • @mohammedhijazi4603
    @mohammedhijazi4603 2 года назад +1

    Your really amazing at explaining things ❤️

  • @Secure_Play
    @Secure_Play Год назад

    🥳 Very good walkthrough my friend 🖖

  • @rodolfomoro2029
    @rodolfomoro2029 2 года назад +1

    Thank you so much for your videos. It's been really helpful

    • @FindingUrPasswd
      @FindingUrPasswd  2 года назад

      Absolutely! I’m glad they’ve been able to help out 😄

  • @Death_User666
    @Death_User666 11 месяцев назад

    you are a legend sir

  • @firefox.3496
    @firefox.3496 Год назад

    you are so underrated.

  • @jamesk400
    @jamesk400 7 месяцев назад

    the walkthrough that HTB provided didn't get me the answer, your explanation got me to the flag, thank you

  • @lukasjerabek2504
    @lukasjerabek2504 11 месяцев назад

    Hi could someone please explain to me, why couldnt execute directly the content of shell.sh in the url instead of that curl command? Id be very glad, because it seems like an unnecessary step.

  • @timeskipbeatz2990
    @timeskipbeatz2990 2 года назад

    thanks a lot man im doing all of them and dont know how to thank you man! i wish you everything you wish, god bless you big brother. also sorry for the bad english

    • @FindingUrPasswd
      @FindingUrPasswd  2 года назад

      no worries! The english is awesome! Glad you like the video :)

  • @starlox0
    @starlox0 Год назад

    That's too tough...but at last understood 😃

  • @derekberthiaume5367
    @derekberthiaume5367 8 месяцев назад

    My Firefox flat out refuses to get the s3 subdomain to show up. I've added it to the etc/hosts. I discovered it in my gobuster but I just read through the walkthrough and skipped the step where I check if it's running

  • @Vejinx
    @Vejinx 11 месяцев назад

    My linux installation doesn't have a Dev/TCP directory, is there another way for me to run the reverse shell?

  • @aaronhenderson571
    @aaronhenderson571 Год назад +1

    Hi!
    im having a issues with AWS, when I put the commanded in I get a error that reads "could not connect to the endpoint URL" would you know anything about this? Thanks!

    • @infiniteformless
      @infiniteformless Год назад +1

      did you figure this out im experiencing this same issue

    • @aaronhenderson571
      @aaronhenderson571 Год назад

      @@infiniteformless hey! I did. I had to reboot the box and that seemed to fix it. Hope you figure it out!

  • @Angel-dq1mo
    @Angel-dq1mo Год назад

    Bien explicado, se agradece.

  • @mcjthemcj521
    @mcjthemcj521 Год назад

    Thank you for this walkthrough! The one in pdf on hack the box must have some errors because the python script refused to work. But I've followed your approach for the final step and everything works finally... gosh, what a tiresome machine for a "very easy" instance

  • @deliciousdestiny450
    @deliciousdestiny450 Год назад

    After getting the listening command ID is not coming which is shown on the http window showing var/www/html $ then nothing can you help

  • @jamesdaniels2094
    @jamesdaniels2094 Год назад

    I had a few issues along the way, and worked through them on my own with just the papwerwork from HTB and then at the very last step couldnt figure out what I was doing incorrectly at the stage of getting the reverse shell established. - Because i have a VM with kali, and the VPN established on the host, I sort of crashed through this, and have had a hard time wrapping my head around setting up my vm to perform all this - and actually get this all done from the VM

  • @sebangel9182
    @sebangel9182 Год назад

    14:46 where you get a download the list seclists/ Discovery/DNS/... ?

  • @matheusblimblien8978
    @matheusblimblien8978 9 месяцев назад

    Hi Dude, could explain for me, why we necessary web server on python? Sorry if u explain in the video, but I'm Brazil and my listening is trash. Thx for that Bro, thx for the content!

  • @amineboumosbah2126
    @amineboumosbah2126 2 года назад

    you are the best thank you

  • @haydengiles402
    @haydengiles402 Год назад +1

    when i tried running that gobuster command i do not get the s3 sub domain and i have tried using different lists from the seclist repository

    • @dbuckner54
      @dbuckner54 Год назад

      I am having the same issue. Have you found a resolution

    • @dbuckner54
      @dbuckner54 Год назад

      I figured it out use the - - append-domain hope this helps

    • @nickparisie8741
      @nickparisie8741 Год назад

      Try adding -append-domain

  • @Hunter-em3dr
    @Hunter-em3dr Год назад

    I can't find ifconfig tun0, do you know why?

  • @AsrorOdilov-bk5xc
    @AsrorOdilov-bk5xc Год назад

    the best

  • @hichamouabellla9836
    @hichamouabellla9836 Год назад +1

    i don't know why netcat Don't catch up the connection

  • @gregO00O
    @gregO00O Год назад

    love you

  • @waipak7378
    @waipak7378 2 года назад

    very nice video. :)

  • @jonphinguyen
    @jonphinguyen 2 года назад +1

    Great videos! Any chance you'll be joining Odysee?

  • @elyjahmusee3733
    @elyjahmusee3733 10 месяцев назад

    Broooo..Thankyou

  • @GajendraMahat
    @GajendraMahat 2 года назад

    Big Fan bro

  • @codewithraiju1424
    @codewithraiju1424 2 года назад

    Hello sir great video.. Can you make a video on htb red panda lab?

  • @dylancardenas
    @dylancardenas Год назад

    my kali has no seclists =(

  • @Kevindavegan
    @Kevindavegan 5 месяцев назад

    I didn't get the flag.

  • @joseluisramirezpolanco5310
    @joseluisramirezpolanco5310 2 года назад

    i cant use comands in the url, i think its because the shell.php dont work it to me, maybe i have to write it of other way, please tell me how i can do it

  • @ovejanegra6351
    @ovejanegra6351 Год назад

    este comando subl no me sale

  • @zayya9362
    @zayya9362 2 года назад

    Waiting for so long . Why dont you upload regularly ?

    • @FindingUrPasswd
      @FindingUrPasswd  2 года назад +2

      Sorry for such a long wait! I was moving into a new apartment and it took me a while to get everything sorted out. I’m going to try to upload a lot more regularly now!

  • @ayushprajapati9486
    @ayushprajapati9486 Год назад

    leaving my mark at subs:4.48K

  • @ademakinemmanuel2809
    @ademakinemmanuel2809 2 года назад

    aws cli isn't installing

  • @priyachhatwani4370
    @priyachhatwani4370 Год назад

    i have used gobuster to find the s3 domain but i tried everything using ffuf can you tell me how to find the subdomain using fuff thanks :)

  • @dheerajrp4685
    @dheerajrp4685 10 месяцев назад

    Please give us more videos like this 🥲 Your explanations are just great

  • @therabbit5702
    @therabbit5702 2 года назад +1

    great stuff man i was stuck on this one an was waiting for you to do this video thanks again man From Aus... FollowThewhiteRabbit

  • @ovejanegra6351
    @ovejanegra6351 Год назад +1

    Found: 1 Status: 400 [Size: 306] I only get this because it should come out 03 thetoppers.htb