<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>IppSec</title>
        <link>https://tube.ekaii.fr/c/ippsec/videos</link>
        <description></description>
        <lastBuildDate>Fri, 02 Oct 2026 23:36:27 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://tube.ekaii.fr</generator>
        <image>
            <title>IppSec</title>
            <url>https://tube.ekaii.fr/client/assets/images/icons/icon-1500x1500.png</url>
            <link>https://tube.ekaii.fr/c/ippsec/videos</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://tube.ekaii.fr/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://tube.ekaii.fr/feeds/videos.xml?videoChannelId=26" rel="self" type="application/rss+xml"/>
        <podcast:txt purpose="p20url">https://tube.ekaii.fr/feeds/podcast/videos.xml?videoChannelId=26</podcast:txt>
        <item>
            <title><![CDATA[HackTheBox   SmartHire]]></title>
            <link>https://tube.ekaii.fr/w/iC9hxbNZHffU7h1bswbHsc</link>
            <guid>https://tube.ekaii.fr/w/iC9hxbNZHffU7h1bswbHsc</guid>
            <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[00:00 - Introduction 00:50 - Start of nmap 03:55 - We can enumerate valid usernames based upon time 07:00 - Enumerating subdomains with ffuf finding models.smarthire.htb 10:00 - Discovering MLFlow has Python Pickles 13:00 - Sidequest, the copy to ...]]></description>
            <content:encoded><![CDATA[<p>00:00 - Introduction<br />
00:50 - Start of nmap<br />
03:55 - We can enumerate valid usernames based upon time<br />
07:00 - Enumerating subdomains with ffuf finding models.smarthire.htb<br />
10:00 - Discovering MLFlow has Python Pickles<br />
13:00 - Sidequest, the copy to clipboard doesn't work over http weakening our browser to allow clipboard access from HTTP<br />
17:40 - Uploading a Python Pickle, showing that the --data-binary flag is important<br />
25:40 - Got a HTTP Callback, getting a reverse shell<br />
27:16 - Shell returned<br />
29:50 - We can write to a plugins directory of a program we can run via sudo, begin of research to exploit<br />
37:50 - Turns out for PTH files we need to put everything on one line. Getting root</p>
]]></content:encoded>
            <dc:creator>IppSec</dc:creator>
            <category>Education</category>
            <enclosure length="183711404" type="video/mp4" url="https://tube.ekaii.fr/download/videos/generate/8eb73d24-3dc7-48aa-8922-4dbdc3b04ae3?videoFileIds=9744"/>
            <media:community>
                <media:statistics views="0"/>
            </media:community>
            <media:embed url="https://tube.ekaii.fr/videos/embed/iC9hxbNZHffU7h1bswbHsc"/>
            <media:player url="https://tube.ekaii.fr/w/iC9hxbNZHffU7h1bswbHsc"/>
            <media:group>
                <media:peerLink type="application/x-bittorrent" href="https://tube.ekaii.fr/lazy-static/torrents/b7aa4a43-a3f3-4c89-9454-5406fe2a7639-1440.torrent" isDefault="false"/>
                <media:content type="video/webm" medium="video" height="1440" fileSize="183711404" url="https://tube.ekaii.fr/static/web-videos/89c0c8d9-477a-48b4-8fcb-68895b89c2a5-1440.webm" framerate="30" duration="2417" isDefault="true"/>
            </media:group>
            <media:thumbnail url="https://tube.ekaii.fr/lazy-static/thumbnails/60a50384-b08f-4a2e-9531-63ff1524f18c.webp" height="1400" width="1400"/>
            <media:rating>nonadult</media:rating>
            <media:title type="plain">HackTheBox   SmartHire</media:title>
            <media:description type="plain">00:00 - Introduction 00:50 - Start of nmap 03:55 - We can enumerate valid usernames based upon time 07:00 - Enumerating subdomains with ffuf finding models.smarthire.htb 10:00 - Discovering MLFlow has Python Pickles 13:00 - Sidequest, the copy to ...</media:description>
        </item>
        <item>
            <title><![CDATA[HackTheBox - Silentium]]></title>
            <link>https://tube.ekaii.fr/w/av8tyf1637zNSGw7KMzQaZ</link>
            <guid>https://tube.ekaii.fr/w/av8tyf1637zNSGw7KMzQaZ</guid>
            <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[00:00 - Introduction 00:53 - Start of nmap 03:00 - Discovering the staging subdomain with ffuf 05:07 - The login has 3 different error messages allowing us to enumerate valid emails 06:50 - Forgot Password returns the entire user object, including...]]></description>
            <content:encoded><![CDATA[<p>00:00 - Introduction<br />
00:53 - Start of nmap<br />
03:00 - Discovering the staging subdomain with ffuf<br />
05:07 - The login has 3 different error messages allowing us to enumerate valid emails<br />
06:50 - Forgot Password returns the entire user object, including reset token, taking over ben's account<br />
10:30 - Finding an public RCE in Flowise, but this docker doesn't have bash that makes it a little tricky to get the reverse shell<br />
16:35 - Shell returned getting a password from the environment then SSH into the box<br />
20:55 - Accessing GOGS by creating a SSH Port Forward, then looking at the version to find a RCE (CVE-2025-8110)<br />
25:40 - Creating a Git Repo so we can trigger the File Write uploading our SSH key to the root directory<br />
27:50 - Sending the File Write command to GOGS</p>
]]></content:encoded>
            <dc:creator>IppSec</dc:creator>
            <category>Education</category>
            <enclosure length="166361867" type="video/mp4" url="https://tube.ekaii.fr/download/videos/generate/4cf36c88-f62c-4a00-9d21-3963abcd825b?videoFileIds=9543"/>
            <media:community>
                <media:statistics views="0"/>
            </media:community>
            <media:embed url="https://tube.ekaii.fr/videos/embed/av8tyf1637zNSGw7KMzQaZ"/>
            <media:player url="https://tube.ekaii.fr/w/av8tyf1637zNSGw7KMzQaZ"/>
            <media:group>
                <media:peerLink type="application/x-bittorrent" href="https://tube.ekaii.fr/lazy-static/torrents/1e34fb6d-4ca0-4ae6-a44b-0a86fb39351e-1440.torrent" isDefault="false"/>
                <media:content type="video/mp4" medium="video" height="1440" fileSize="166361867" url="https://tube.ekaii.fr/static/web-videos/0a9b3327-2883-4aa8-a571-9bc7b7071536-1440.mp4" framerate="30" duration="1880" isDefault="true"/>
            </media:group>
            <media:thumbnail url="https://tube.ekaii.fr/lazy-static/thumbnails/23447923-21ee-43b3-b157-84b39bdbae7a.webp" height="1400" width="1400"/>
            <media:rating>nonadult</media:rating>
            <media:title type="plain">HackTheBox - Silentium</media:title>
            <media:description type="plain">00:00 - Introduction 00:53 - Start of nmap 03:00 - Discovering the staging subdomain with ffuf 05:07 - The login has 3 different error messages allowing us to enumerate valid emails 06:50 - Forgot Password returns the entire user object, including...</media:description>
        </item>
        <item>
            <title><![CDATA[HackTheBox - Pirate]]></title>
            <link>https://tube.ekaii.fr/w/k1v7PKh52i3K83ZjWTT6fM</link>
            <guid>https://tube.ekaii.fr/w/k1v7PKh52i3K83ZjWTT6fM</guid>
            <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[00:00 - Introduction 01:05 - Start of nmap 04:00 - Running a lot of NXC Enumeration (users, computers, groups, delegation) 07:00 - Running Rusthound and looking over Bloodhound data, discovering delegation, pre-2k compatibility group, etc 14:30 - ...]]></description>
            <content:encoded><![CDATA[<p>00:00 - Introduction<br />
01:05 - Start of nmap<br />
04:00 - Running a lot of NXC Enumeration (users, computers, groups, delegation)<br />
07:00 - Running Rusthound and looking over Bloodhound data, discovering delegation, pre-2k compatibility group, etc<br />
14:30 - Abusing the Pre-2k Compatibility group to login as MS01 and dump GMSA Passwords<br />
17:00 - WinRM to DC01, pivoting to Web01 via chisel<br />
31:00 - Stealing the NTLM Hash, discovering NTLMv1 and attempting to crack it<br />
34:30 - Using KrbRelayX to add the ippsec DNS record<br />
48:20 - Unable to crack, doing NTLMRelay and coercer to trick the machine account to authenticate from HTTP to DC LDAP and then using set_rbcd to add a privilege that lets us impersonate users on this box<br />
01:00:00 - Running SecretsDump with our impersonated account to dump the SAM, get A.White's password which can reset their ADM account password whom has a path to DA<br />
01:07:00 - Updating the SPN's to point to the DC instead of WEB01 which lets us impersonate users to the domain and getting root<br />
01:12:10 - Unintended: Showing a direct path from Web01 to A.White with RemotePotato0 and NTLMRelay</p>
]]></content:encoded>
            <dc:creator>IppSec</dc:creator>
            <category>Education</category>
            <enclosure length="107889729" type="video/mp4" url="https://tube.ekaii.fr/download/videos/generate/99ef9434-5c8a-4377-865b-7c781c2baff5?videoFileIds=9470"/>
            <media:community>
                <media:statistics views="0"/>
            </media:community>
            <media:embed url="https://tube.ekaii.fr/videos/embed/k1v7PKh52i3K83ZjWTT6fM"/>
            <media:player url="https://tube.ekaii.fr/w/k1v7PKh52i3K83ZjWTT6fM"/>
            <media:group>
                <media:peerLink type="application/x-bittorrent" href="https://tube.ekaii.fr/lazy-static/torrents/6693d988-698d-40f1-9513-5de544f3b117-360.torrent" isDefault="false"/>
                <media:content type="video/mp4" medium="video" height="360" fileSize="107889729" url="https://tube.ekaii.fr/static/web-videos/8c23f280-7fa6-43e0-9611-10968b3017a5-360.mp4" framerate="30" duration="4816" isDefault="true"/>
            </media:group>
            <media:thumbnail url="https://tube.ekaii.fr/lazy-static/thumbnails/0fbcde00-055d-48cc-894f-1ad7eae3ce99.webp" height="1400" width="1400"/>
            <media:rating>nonadult</media:rating>
            <media:title type="plain">HackTheBox - Pirate</media:title>
            <media:description type="plain">00:00 - Introduction 01:05 - Start of nmap 04:00 - Running a lot of NXC Enumeration (users, computers, groups, delegation) 07:00 - Running Rusthound and looking over Bloodhound data, discovering delegation, pre-2k compatibility group, etc 14:30 - ...</media:description>
        </item>
        <item>
            <title><![CDATA[HackTheBox - Cobblestone]]></title>
            <link>https://tube.ekaii.fr/w/6KHiE2NXuqymFxBe2jkH26</link>
            <guid>https://tube.ekaii.fr/w/6KHiE2NXuqymFxBe2jkH26</guid>
            <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[00:00 - Introduction 01:00 - Start of nmap 03:00 - Creating an account on the main domain and discovering it doesn't create one on vote 05:30 - Discovering a SQL Injection when suggesting URL's on the vote application, converting it to Union Injec...]]></description>
            <content:encoded><![CDATA[<p>00:00 - Introduction<br />
01:00 - Start of nmap<br />
03:00 - Creating an account on the main domain and discovering it doesn't create one on vote<br />
05:30 - Discovering a SQL Injection when suggesting URL's on the vote application, converting it to Union Injection and showing SQLMap<br />
10:15 - Union injection working, getting the payload over to SQLMAP so we can have it dump the database while we look at other things<br />
15:30 - Going back to the Skin Suggestor, discovering XSS<br />
17:50 - Having the XSS Send us back the page the victim is on, discovering a debug page is linked which contains PHPINFO<br />
23:15 - The PHPINFO output reflects the PHP Cookie, creating a CSRF Payload to have the victim navigate to the PHPINFO page and send us the output to steal their cookies even thoe they are marked HTTPONLY<br />
28:15 - Discovering SSTI, this is PHP so using a PHP TWIG Payload to get RCE, some commands fail discovering it is apparmor<br />
35:15 - Failing to get a reverse shell for a while<br />
41:08 - Using MySQL Dump to dump the database, the SQL injection didn't get this because its a different DB<br />
45:50 - Shell returned as Cobblestone<br />
51:00 - Discovering Cobbler is running, forward the post back to us, use XMLRPC to get RCE (a 2014 GitHub issue)<br />
54:20 - Having Claude look at the issue and try to make a POC while we poke at it manually<br />
58:48 - Proving we can bypass auth with -1 as the password, and getting shell</p>
]]></content:encoded>
            <dc:creator>IppSec</dc:creator>
            <category>Education</category>
            <enclosure length="425722864" type="video/mp4" url="https://tube.ekaii.fr/download/videos/generate/2e982151-ec19-4043-a1a1-71ab839df27b?videoFileIds=9223"/>
            <media:community>
                <media:statistics views="0"/>
            </media:community>
            <media:embed url="https://tube.ekaii.fr/videos/embed/6KHiE2NXuqymFxBe2jkH26"/>
            <media:player url="https://tube.ekaii.fr/w/6KHiE2NXuqymFxBe2jkH26"/>
            <media:group>
                <media:peerLink type="application/x-bittorrent" href="https://tube.ekaii.fr/lazy-static/torrents/c0aa394b-3425-4f8e-adc7-113e0e4bc0ef-1440.torrent" isDefault="false"/>
                <media:content type="video/mp4" medium="video" height="1440" fileSize="425722864" url="https://tube.ekaii.fr/static/web-videos/0137f16d-4970-4508-ab20-a97aa67aa144-1440.mp4" framerate="30" duration="3796" isDefault="true"/>
            </media:group>
            <media:thumbnail url="https://tube.ekaii.fr/lazy-static/thumbnails/f5255c6f-e05a-4238-a802-fb51fe23138c.jpg" height="1400" width="1400"/>
            <media:rating>nonadult</media:rating>
            <media:title type="plain">HackTheBox - Cobblestone</media:title>
            <media:description type="plain">00:00 - Introduction 01:00 - Start of nmap 03:00 - Creating an account on the main domain and discovering it doesn't create one on vote 05:30 - Discovering a SQL Injection when suggesting URL's on the vote application, converting it to Union Injec...</media:description>
        </item>
        <item>
            <title><![CDATA[HackTheBox - Helix]]></title>
            <link>https://tube.ekaii.fr/w/nTHc1wmS2iAbzTSkesNydD</link>
            <guid>https://tube.ekaii.fr/w/nTHc1wmS2iAbzTSkesNydD</guid>
            <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[00:00 - Introduction 00:45 - Start of nmap 03:20 - Using FFUF to VHOST Bruteforce and finding flow.helix.htb 05:30 - Looking into H2 Database RCE's, finding the Alias Command allows us the ability to run Java 07:10 - RCE #1: Using H2 Syntax to cre...]]></description>
            <content:encoded><![CDATA[<p>00:00 - Introduction<br />
00:45 - Start of nmap<br />
03:20 - Using FFUF to VHOST Bruteforce and finding flow.helix.htb<br />
05:30 - Looking into H2 Database RCE's, finding the Alias Command allows us the ability to run Java<br />
07:10 - RCE #1: Using H2 Syntax to create an alias to run a shell command<br />
15:10 - RCE #2: Adding a Processor to run Groovy<br />
18:00 - RCE #3: Adding a Command Processor to run a bash command<br />
19:40 - RCE #4: Is it easier to just use Metasploit?<br />
26:00 - Shell on the box, using Find to show the types of all the files in our CWD and finding an SSH Key<br />
30:15 - Shell as Operator, cracking a PDF<br />
38:00 - Running OPCUA-Client-GUI and editing the registers to put the device in maintenance mode</p>
]]></content:encoded>
            <dc:creator>IppSec</dc:creator>
            <category>Education</category>
            <enclosure length="138668339" type="video/mp4" url="https://tube.ekaii.fr/download/videos/generate/b1483a6e-c2a3-4352-9f19-afc5c2b3c00d?videoFileIds=9157"/>
            <media:community>
                <media:statistics views="0"/>
            </media:community>
            <media:embed url="https://tube.ekaii.fr/videos/embed/nTHc1wmS2iAbzTSkesNydD"/>
            <media:player url="https://tube.ekaii.fr/w/nTHc1wmS2iAbzTSkesNydD"/>
            <media:group>
                <media:peerLink type="application/x-bittorrent" href="https://tube.ekaii.fr/lazy-static/torrents/a29e2e00-a977-4d75-8300-c14323999c37-1080.torrent" isDefault="false"/>
                <media:content type="video/mp4" medium="video" height="1080" fileSize="138668339" url="https://tube.ekaii.fr/static/web-videos/4a0c797c-e57b-4eb3-ab02-f91336439a32-1080.mp4" framerate="30" duration="2781" isDefault="true"/>
            </media:group>
            <media:thumbnail url="https://tube.ekaii.fr/lazy-static/thumbnails/e9965e20-b655-446c-99d1-7f7a06cdf5e4.jpg" height="1400" width="1400"/>
            <media:rating>nonadult</media:rating>
            <media:title type="plain">HackTheBox - Helix</media:title>
            <media:description type="plain">00:00 - Introduction 00:45 - Start of nmap 03:20 - Using FFUF to VHOST Bruteforce and finding flow.helix.htb 05:30 - Looking into H2 Database RCE's, finding the Alias Command allows us the ability to run Java 07:10 - RCE #1: Using H2 Syntax to cre...</media:description>
        </item>
    </channel>
</rss>