HackTheBox - WhiteRabbit
00:00 - Introduction 01:00 - Start of nmap 05:10 - Playing with a JavaScript Client app (Vue) to get information to do recon and finding public /status/ page 12:00 - Looking at the N8N Workflow with GoPhish 14:30 - Looking at the JSON Schema File that leaks a secret key and shows possible SQL Injection 18:00 - Using CyberChef to test the HMAC Key and confirm we can sign payloads 21:50 - Switching to Caido to show we can create WorkFlows on the Replay (repeater) functionality 25:20 - Creating a convert workflow to HMAC Sign all our requests 35:40 - Using the MITM Python Library to quickly write a proxy that would sign our requests that makes it easier for tools to test this endpoint 45:20 - SQLMap found the injection, dumping tables discovering a restic password 48:50 - Using the restic CLI to download a backup, then cracking the 7z file. Cracking fails the first time due to a weird collision. 57:00 - On the box, we can run restic with sudo, use password-command to give us a root shell 1:05:50 - Finding the neo password generator, discovering it uses random insecurely to set the seed and generate password. 1:18:45 - Adding milliseconds to our timestamp and then bruteforcing the password to get root

Web Scraping Using Python For Beginners and File Handling in Python | Python Web Scraping

How to Lose a Pentester in 10 Days | By Ippsec
![HackTheBox | Eighteen [Easy] Full Walkthrough (Retired 2026)](https://i.ytimg.com/vi/IL75kx71fYE/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLAKwncrLPKBJyd1InKdcOE1S_FDDQ)
HackTheBox | Eighteen [Easy] Full Walkthrough (Retired 2026)

Learn From Proficiency: Here’s How Today’s Market Wizards Made Their Fortunes | Investing With IBD

Real-Life Infrastructure Pentest: From Network Scan to Root (TryHackMe)

LIVE: Belgian Grand Prix Post-Race Show

HackTheBox - Office

HackTheBox - Hacknet

Kto jest gadem, a kto ptakiem? O systematyce paleontologicznej / Dr Daniel Tyborowski

F1 LIVE: Belgian Grand Prix Post Sprint Show

Life in the Carboniferous Forest / Dr. Daniel Tyborowski

Trump Preps for 80th Birthday, Threatens to Hit Iran, Knicks Historic Win & Elon Musk Trillionaire!?

What is SonarQube | Introduction SonarQube | SonarQube Tutorial | SonarQube Basics | Intellipaat

HackTheBox - Resource

Super Pogchamps | Semis vs Andrea Botez and Finals vs Sardoche

Let’s Handle 1 Million Requests per Second, It’s Scarier Than You Think!

Something is jamming GPS over Europe. Here's what we found

LIVE: Belgian Grand Prix Post-Race Show

Inside Anthropic, the $965 Billion AI Juggernaut | The Circuit

