У нас вы можете посмотреть бесплатно FluxCapacitor - Hackthebox.eu или скачать в максимальном доступном качестве, видео которое было загружено на ютуб. Для загрузки выберите вариант из формы ниже:
Если кнопки скачивания не
загрузились
НАЖМИТЕ ЗДЕСЬ или обновите страницу
Если возникают проблемы со скачиванием видео, пожалуйста напишите в поддержку по адресу внизу
страницы.
Спасибо за использование сервиса ClipSaver.ru
Can You Hack It Series - Flux Capacitor - www.hackthebox.eu. This is the second video in my "Can you hack it?" series that looks at various pen testing challenges online. This one takes a look at the hackthebox.eu system FluxCapacitor. Sorry about the reverb in the audio towards the end of the video. I didn't hear it in my headset while I was recording. HTB Profile: https://www.hackthebox.eu/home/users/... HTB Forum: https://forum.hackthebox.eu/profile/I... (feel free to drop me a line) 00:12 - Start 01:28 - Nmap Scan 04:44 - WAF Bypass with Burp 06:55 - Using wfuzz to fuzz for parameters 12:20 - Parameter found 15:55 - First remote command execution 17:30 - Fuzzing Linux command WAF filtering with gofuzz (source to be posted soon) 21:50 - Unfiltered Linux command list 23:00 - Using 'du' to enumerate directories and files 24:56 - Using 'od' command to read contents of files 26:45 - User flag owned 37:45 - Nginx configuration / WAF configuration 40:32 - List of commands WAF was configured to block 41:00 - Tool to build base64 encoded payloads that will pass the WAF's filter 45:45 - Root priv esc found, building payload for obtaining root.txt 47:05 - Root flag owned 47:15 - Box owned - End of normal video 47:16 - Extended video, showing how to get an interactive shell with full TTY as an alternative method for accessing the box.