Customers thought they were privately chatting with an AI bot named "Samantha" to schedule appliance repairs. Instead, their names, home addresses, phone numbers, and hours-long call recordings were sitting exposed for anyone to find.
This is a great beginner-to-intermediate SQLi challenge showing how UNION-based injection works in a real (simulated) web app.
#CTF #SQLInjection #MetaCTF #CyberSecurity #EthicalHacking #WebSecurity #SQLi #CaptureTheFlagI Sat Down With John Hammond and Asked Him Everythingshenetworks2026-03-18 | I finally got to sit down with John Hammond — one of the most well-known names in cybersecurity on YouTube — for a real, unfiltered conversation about how he got to where he is today.
We get into everything: his journey and career at Huntress, his thoughts on AI and where it's taking the cybersecurity world, and the research he's been diving into. Whether you're just getting into the field or you've been in it for years, there's something in this one for you.
---
🎤 Guest: John Hammond 📍 Topics covered: - His career path and role at Huntress - AI's impact on cybersecurity - Cybersecurity research and what's on his radar
---
If you enjoyed this, drop a like and subscribe to shenetworks for more interviews, CTF walkthroughs, and cybersecurity content! 🙌
#CyberSecurity #JohnHammond #Huntress #AIHacking #EthicalHacking #shenetworks #CyberSecurityInterview #InfoSec #HackingCareer #CTF #CyberSecurityCareersBypassing Admin Auth with One Cookie Edit | MetaCTF Admin Portal Walkthroughshenetworks2026-03-16 | In this video, I walk through the MetaCTF Flash CTF challenge "Admin Portal" — a beginner-friendly web exploitation challenge where all you need to do is tweak one cookie to go from regular user to admin and grab the flag. 🍪 No fancy exploits, no code injection — just your browser's built-in DevTools and a little curiosity. Perfect if you're just getting into CTFs!
If you found this helpful, drop a like and subscribe to shenetworks for more CTF walkthroughs, cybersecurity tips, and hands-on hacking content! 🙌
#CTF #MetaCTF #WebExploitation #CyberSecurity #EthicalHacking #shenetworks #CaptureTheFlag #BugBounty #Hacking #DevTools #BeginnerHackingCan you crack this code? MetaCTF - Cracking Javashop Walkthroughshenetworks2026-03-09 | ...Why MCP Servers Can Become a Security Nightmareshenetworks2026-03-04 | MCP servers are becoming a common way to connect AI systems to real tools, APIs, and internal services—but they also introduce security risks that many teams aren’t prepared for.
In this video, I break down what MCP servers are, why they’re powerful, and the most common security issues I’m seeing in real-world environments. We’ll look at problems like over-privileged tool access, weak authentication, prompt-driven tool abuse, sensitive data exposure, and the lack of logging and monitoring—and how these issues can quietly turn MCP servers into high-impact security risks.
This isn’t a theoretical discussion. The focus is on how these problems show up in practice and what organizations should be thinking about as they integrate AI systems more deeply into production environments.
If you’re building, deploying, or securing AI systems—or you just want to understand where the real risks are—this video is for you.
🔐 Subscribe for more real-world security content 💬 Let me know if you’d like a deeper dive into MCP hardening or real attack paths in a future videoCan you solve this challenge? MetaCTF - Dot-Matrix Destruction Walkthroughshenetworks2026-03-02 | In this walkthrough, we solve the "Dot Matrix Destruction" challenge from MetaCTF's Flash CTF — a fun web exploitation challenge built around an XXE (XML External Entity) injection vulnerability.
We start by analyzing a retro-themed dot matrix printer store website, reverse-engineering how its search API works, and discovering that it accepts raw XML in its POST requests. From there, we craft a classic XXE payload that tricks the vulnerable XML parser into reading /flag.txt off the server's filesystem — and leaking it back to us through an error message.
Topics covered: Web recon & reading page source / JavaScript Intercepting and replaying API requests with Burp (and browser DevTools) XML External Entity (XXE) injection fundamentals Using error-based output to exfiltrate data
If you're learning web security or CTF techniques, XXE is a must-know vulnerability — hope this helps! #CTF #XXE #WebSecurity #MetaCTF #EthicalHacking #PenTesting #CyberSecurity5 Active Directory Misconfigurations Hackers Exploit Firstshenetworks2026-02-25 | Active Directory is one of the most critical—and most commonly misconfigured—parts of enterprise environments.
In this video, I break down five Active Directory misconfigurations that attackers routinely exploit during real penetration tests. These issues don’t require zero-days or advanced malware—just default settings, legacy configurations, and missing hardening.
Topics covered: - SMB signing not required - Vulnerable ADCS web enrollment - Default machine account quota - Domain Controllers running Print Spooler - Privileged accounts missing from Protected Users
If you manage or secure Active Directory, this video will help you understand where real risk comes from—and what to fix first.
🔐 Subscribe for more offensive security and real-world pentesting insights.This JWT Misconfiguration Breaks Authentication (MetaCTF)shenetworks2026-02-23 | ...WiFi Pineapple Enterprise Penetration Testing Workflowshenetworks2026-02-18 | ...TryHackMe Relevant Walkthroughshenetworks2026-02-11 | Tryhackme Relevant WalkthroughLookup Walkthrough TryHackMeshenetworks2026-02-04 | Lookup walkthrough TryHackMeTryHackMe Bugged: What You Missedshenetworks2026-01-28 | TryHackMe Bugged WalkthroughTryHackMe Exposed Walkthroughshenetworks2026-01-21 | Tryhackme Exposed WalkthroughThe HPE Networking Instant On AP 27shenetworks2024-12-02 | The HPE Networking Instant On AP 27 can withstand being dropped in a bucket of water for up to 30 minutes! Follow HPE Networking Instant On @HPENetworkingInstantOn and click the link to purchase or learn more! #HPENetworkingInstantOn #HPENetworkingInstanOnAP27 #InstantOn #ITInstall #SMB #SmallBusinessOwner #SmallBusiness #WiFi #Network #AccessPoints or #switch LINK: amzn.to/49jS44VTesting Out the HPE Networking Instant On Access Point AP27shenetworks2024-12-02 | LINK: amzn.to/49jS44V
Can this HPE Instant On Access Point AP27 stand being fully submerged in water? How will it hold up outdoors? In this video we test the HPE Instant On Access Point AP27's durability, and see how it fairs after being fully submerged in water. This video will also contain the initial set up and mounting. #InstantOn #ITInstall #SMB #SmallBusinessOwner #SmallBusiness #WiFi #Network #AccessPointsTryHackMe - Agent Sudo - Privilege Escalationshenetworks2024-10-25 | ...Mastering Microsoft 365 Security: Post-Exploitation with Graph Runner | Part 3shenetworks2024-04-16 | //GraphRunner// Github: github.com/dafthack/GraphRunner Blog: blackhillsinfosec.com/introducing-graphrunner Overview: youtube.com/watch?v=o29jzC3deS0&t=1695s
Conclude your learning on Microsoft 365 post-exploitation with our final video, which focuses on pillaging techniques using Graph Runner. Discover how to use various modules to extract valuable information and exploit data across Microsoft 365 services effectively. This tutorial will equip you with advanced skills to assess and enhance your organization’s security posture.Unlocking Microsoft 365: Post-Exploitation Tactics with Graph Runner | Part 2shenetworks2024-04-16 | //GraphRunner// Github: github.com/dafthack/GraphRunner Blog: blackhillsinfosec.com/introducing-graphrunner Overview: youtube.com/watch?v=o29jzC3deS0&t=1695s
Elevate your Microsoft 365 security strategies with Part 2 of our series, where we delve into persistence techniques using Graph Runner. This video explores how to maintain access within Microsoft 365 environments discreetly. Learn to implement sophisticated persistence modules that allow you to stay under the radar while securing footholds. Ideal for security professionals looking to enhance their defensive and offensive capabilities.Unlocking Microsoft 365: Post-Exploitation Tactics with Graph Runner | Part 1shenetworks2024-04-16 | //GraphRunner// Github: github.com/dafthack/GraphRunner Blog: blackhillsinfosec.com/introducing-graphrunner Overview: youtube.com/watch?v=o29jzC3deS0&t=1695s
Kickstart your journey into Microsoft 365 post-exploitation with this introductory tutorial on Graph Runner. In this first video, we cover the essentials: how to download Graph Runner, import it into PowerShell, and authenticate to Microsoft 365 securely. This step-by-step guide ensures you have the foundational skills needed to move onto more advanced techniques.Reading Mean Comments Tech Edition Part 2 #infosec #comedy #tech #infosecshenetworks2024-02-27 | ...Reading Mean Comments Tech Edition Part 1 #comedy #tech #infosecshenetworks2024-02-22 | ...Scattered Spider? Back Cat? Lockbit? #cybersecurity #hacking #ransomware #lasvegasshenetworks2023-09-14 | ...MGM & Scattered Spider #cybersecurity #hacking #technology #vegas #ransomwareshenetworks2023-09-13 | ...MGM Casinos is dealing with a cyber attack #cybersecurity #networking #infosec #hackingshenetworks2023-09-12 | ...Fact or Fiction? Technical Dive into Zero Daysshenetworks2023-09-07 | This video contains some spoilers. Fact or Fiction? This is a technical deep dive into the book Zero Days authored by Ruth Ware. This is not a review of the book itself, just a look at the technical/hacking components.
No hate towards the author! Negativity will be removed. Don't mind the audio, I sped the video up and removed quite a bit.Ransomware down, extorsion upshenetworks2023-07-31 | Over the last few years, unencrypted data extorsion has become more common.Guide to Landing Your First Tech Jobshenetworks2023-07-18 | Answering my most asked question
Keywords: Support, Lead, Facilitate, Ensure, Maintain, Initiate, Implement, Manage, Coordinate, Improve, Evaluate, Performance, Monitor, Identify, Participate, Deliver, Resolve, Design, Analyze, Increase, Adapt, Review, Develop, Produce, Provide, Revise, Apply, Adhere, Configure, Recommend, Enhance, Execute, Upgrade, Install, Test, Assist, Educate, Efficient, Guide, Approve, Assign, Solve, CreateNetwork Content missing from YouTubeshenetworks2023-01-16 | Tech content creators have shifted from networking content to security. I try to explain why in this video.Exploiting File Upload with MetaCTFshenetworks2023-01-06 | check out the full video on my channelCan Hackers Track Your IP Address?shenetworks2023-01-05 | Full video on my channel Check out the full explanationAsking ChatGPT About Hackingshenetworks2022-12-15 | Trying out ChatGPT, testing its knowledge about hacking and cyber securityInsecure networking protocols: LLMNRshenetworks2022-12-12 | Check and see if youre running this protocol in your environmentLazy Admin Walkthrough - TryHackMeshenetworks2022-11-30 | Join me on twitch for live solving on Twitch twitch.tv/shenetworksBounty Hacker Walkthrough -TryHackMeshenetworks2022-11-17 | Bounty Hacker Walkthrough on TryHackMe
Follow on TwitchCan Hackers Track Your IP Address?shenetworks2022-10-21 | Discussing if hackers can track your IP and a little history of the internet
github.com/shenetworksTracking Down Hackers Through a Packet Capture - MetaCTFshenetworks2022-09-16 | Second video in the MiniCTF series. We analyze a packet capture to find out how the hackers defaced out website.
Follow me - beacons.page/shenetworks
This challenge was apart of a Black Hills Information Security miniCTF
Backdoor - gist.github.com/sente/4dbb2b7bdda2647ba80bHack with this O.MG Cable - Setupshenetworks2022-09-14 | *reupload to fix audio issues* Welcome to the O.MG Multipart series. This video is to talk you through the setup of the O.MG cable