Get a reverse shell with ngrok and netcat - Gemini Pentest v2 Ep5
#pentesting #ctf #hacking #metasploit #kalilinux #ssrf
Part 1: • H.A.C.K.E.R ALWAYS fin...
Part 2: • How to Hunt for Bugs -...
Part 3: • Trust your Gut Instinc...
Part 4: • Will RCE in cookie giv...
Part 5: • Get a reverse shell wi...
Part 6: • Redis privilege escala...
Part 7: • Redis privilege escala...
Hey what’s up? In this video series, I will h4ck the Gemini Pentest v2 CTF challenge. This episode will be dedicated to performing port scanning with nmap, then performing a directory bruteforce to find a registration feature. then creating a new user account that has to be activated. Then, I will bypass the activation feature, login, and explore the application features to hunt for bugs. We will then follow our gut instinct to turn a potential vulnerability into a promising lead. Then we will try to access the server using SSH by uploading our public key to the authorized_keys file. Since we can't achieve that, we will get a revere shell using ngrok and netcat.
🚀 🔥 Become a pentester
academy.thehackerish.com/p/fr...
📙 Learn the technical skills:
thehackerish.com/best-hacking...
📙 Become a successful bug bounty hunter: thehackerish.com/a-bug-bounty...
🆓 Download your FREE Web hacking LAB and starting hacking NOW: thehackerish.com/owasp-top-10...
🌐 Read more on the blog: thehackerish.com
💪🏻 Support this work: thehackerish.com/how-to-support
- Facebook Page: / thehackerish
- Follow us on Twitter: / thehackerish
- Listen on Anchor: anchor.fm/thehackerish
- Listen on Spotify: open.spotify.com/show/4Ht8jEb...
- Listen on Google Podcasts: podcasts.google.com/?feed=aHR...
Пікірлер: 10
Hello appreciate the video. How/What are you using for encoding ?
@thehackerish
Жыл бұрын
Burp has a shortcut ctrl+u to encode as url, and ctrl+shift+u to decode
you use powershell(windows) and Linux terminal ist not block by firewall? Thankyou for video looking for this so long..
@thehackerish
Жыл бұрын
I am using WSL in windows, so I have no issues.
For some unknown reason ngrok doesn’t work on my pc. But when I start VPN the. Run ngrok, it gives me a "ngrok"-link to work with.
@thehackerish
Жыл бұрын
hmmm...what OS? version of ngrok? how did you install it? Better use the version from the official website. The one that came with my ubuntu did not work
@random_guy1024
Жыл бұрын
@@thehackerish Well, I tried many versions (recent) on kali 2022.1 but same sh!t. On wifi, it needs vpn. But then I used my Android hotspot and it was perfectly fine.
is posible to use burp colab as alternative ngrok?
@thehackerish
Жыл бұрын
I am not sure that's possible. My understanding is that collaborator is more for callbacks
@oooimnvacation645
2 ай бұрын
@@thehackerish Is it nessesary to define a listener while using ngrok in case you're exploiting some vulnerability (instead of posting your payload on a webserver or sending it somewhere)?