carving emails & AI prompt injection hacking

carving emails & AI prompt injection hacking

🎙 John Hammond 👥 2.2M 📅 December 8, 2025 ⏱ 19 min 👁 19K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

email carvingbase64 decodeOLEVBAprompt injectionpcap analysis

Summary

In this video, John Hammond continues solving Capture The Flag (CTF) challenges from ‘The Future Is…’ comic book series. He tackles three challenges: Challenge 2 involves analyzing a malicious email (.eml file) to extract a macro-enabled Word document (.docm) hidden as a base64 attachment. He demonstrates using command-line tools like base64 -d and file, then installs and uses OLEVBA to extract the macro and find the flag. Challenge 3 is an AI prompt injection challenge where he interacts with a chatbot and uses a simple inversion technique to trick the model into revealing the flag. Challenge 4 involves analyzing a network packet capture (pcap) file using Wireshark and tcpflow to extract a flag hidden in hex-encoded integrity violation messages. Throughout, he emphasizes practical skills like file carving, macro analysis, and network traffic inspection. The video is educational and aimed at cybersecurity enthusiasts, with clear step-by-step instructions.

146 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides high practical value by demonstrating real-world cybersecurity techniques in a CTF context. The argumentation is solid, as each step is clearly explained and justified. The creator shows the process of extracting and analyzing email attachments, using OLEVBA for macro analysis, and employing tcpflow for network traffic analysis. The techniques are standard and well-executed, making the content credible and useful for learners.

Scientific Rigor, Source Quality, Title Accuracy

The video is scientifically rigorous in its demonstration of tools and methods. The creator references specific tools and commands, and the sources are primarily the CTF platform and the comic book series. The title accurately reflects the content, focusing on email carving and AI prompt injection. The video does not cite external academic sources, but it is a tutorial based on practical experience. The adéquation between title and content is good, as the video indeed covers these topics.

157 words

Title / Content Match

The title accurately reflects the content, which focuses on extracting email attachments and performing AI prompt injection in a CTF context.

Quality & Reliability

8/10

The video provides a hands-on tutorial with clear demonstrations of tools and techniques. The methods shown are standard in the cybersecurity field, and the creator is a recognized expert. However, the content is not peer-reviewed and relies on the creator's expertise.

Key Moments

Cited Sources

  • Antisyphon Training — Mentioned as a sponsor and resource for cybersecurity training.
  • CodeCrafters — Affiliate link for learning to code.
  • CyberDefenders — Affiliate link for blue team training and certifications.
  • Newsletter — Link to sign up for the creator's newsletter.
  • OpenVPN — Affiliate link for hosting a VPN.
  • The Future Is... Comics — Link to purchase the comic book series.
  • Just Hacking Training — Link to cybersecurity training courses.

Concurring Sources

  • OLEVBA documentation — The tool used in the video for macro extraction is well-documented and widely used.
  • Wireshark official site — Wireshark is a standard tool for network analysis, consistent with the video's approach.

Contribution & Novelties

The video provides a practical, hands-on approach to solving CTF challenges, demonstrating real-world techniques for email forensics, macro analysis, and network traffic inspection. It adds value by showing the entire process from start to finish, including tool installation and usage. The ‘Pour aller plus loin’ section offers additional resources for deeper learning.

Pour aller plus loin :

  • OLEVBA — A tool for analyzing OLE and OpenXML files, essential for macro extraction.
  • Wireshark — Network protocol analyzer used for pcap inspection.
  • Prompt Injection — OWASP page on prompt injection attacks.

89 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and technical level, indicating a well-rounded educational video. The reliability score is also high, reflecting the creator's expertise and the use of standard tools.

Reliability 8/10