Most danish presenter ever, no context, no intro, just right into the presentation. Fun talk!
@robertbruce768616 күн бұрын
His ancestors were also pretty straighforward too am sure 😂😂 (think longboats....). Great talk!!
@ChristianHaschek13 күн бұрын
and spelling "w" as "v" :D
@fullfungo2 күн бұрын
And I still have no idea what the presentation was about 😅
@JerglingАй бұрын
The web is a nightmare of 40 years of band-aids holding together spaghetti. My god, this is bleak.
@stansteezАй бұрын
It's a miracle that it works at all :)
@quantumbaconАй бұрын
So that's why it's called TCP.
@RonaldChmaraАй бұрын
40 years ago it was band-aids holding together spaghetti from 40+ years before *then*.... that's all it's ever been, or will be, and yet we still manage to do amazing things.
@trudyandgeorge28 күн бұрын
This is absolutely mind blowing. And the presentation was top notch. He totally foreplayed us all and when he bought the domain I knew it was gonna be a total show. Just. Amazing.
@ZedaZ80Ай бұрын
This is pretty funny, great work! It's wild this still works
@ZedaZ80Ай бұрын
Buddy, I cackled out loud about the crowd strike thing. A true hero!
@MiddlePath007Ай бұрын
He got me a few good times
@RedSntDKАй бұрын
As a Dane it's hilarious how many times he uses "eller" instead of "or". Cute. 13:32 "Eller hvad hedder det.." 😅
@nirv29 күн бұрын
So man foreigns.
@7rich79Ай бұрын
Great talk. I was in too much of a good mood with my weekend starting. Fixed.
@mibdevАй бұрын
Completely unrelated, but I was watching this with my SO beside me, and then they went "He sounds danish", then four more seconds pass and there's a domain ending in ".dk". It's funny how you can just hear these things! :)
@RedSntDKАй бұрын
To be fair, he has a quite thick accent and also uses "eller" several times. And the way he pronounces "data" is exactly like Danes do.
@Blommefeldt26 күн бұрын
@@RedSntDK The same with Java. In danish the J is more soft, and will sound like the english "yah" or "yea". So it would be kinda like "Yava".
@ehsnilsАй бұрын
The ad-proxy thing could be that some ISPs are trying to inject their own ads into the web page.
@alfonzo7822Ай бұрын
Definitely!
@sb037323 күн бұрын
or just block all ads. thats how I do it. I hate ads.
@godnahАй бұрын
He speaks out of one side of his mouth. That's red team activity through and through.
@yescats3327Ай бұрын
If you are using the VeinMaster Iot 5ghz wifi butt plug, you have to twist the sac counter clockwise to access the proxy settings. Your welcome.
@gordslaterАй бұрын
I tried this but it just buzzes "404 not found" in morse code. Is there a root shell? Because there's always a root shell...
@andrewdunbar828Ай бұрын
I was having a smaller Yaver script but the technical behind it was very technique.
@pete3897Ай бұрын
I gotta get me some of that Yavascript for my Veepad :)
@storm4246Ай бұрын
Great talk!
@5z43621 күн бұрын
lmao! this presentation is sooo funny~🤣🤣🤣 Also, he is a Master Troll! *bows*
@szaszm_18 күн бұрын
The guy who only proxies ads is probably blocking ads.
@rabidpbАй бұрын
He implies in a few places that his proxy can intercept HTTPS traffic, which is not the case. There's a lot of useful data in the plaintext though.
@FuckYoutubeCensorshipCuntsАй бұрын
Anyone can intercept HTTPS traffic. Whether or not they can decrypt it is another question
@seansingh4421Ай бұрын
It could be done if someone has access to certain TLS’s private pki information. Then there’s nothing stopping someone.
@alfonzo7822Ай бұрын
I'm guessing he's just used to saying Https instead of http.. just a little brain blip
@cmusgraveАй бұрын
-I think he's redirecting https to a http connection- re-watching the video, at about 10 minutes, he's using the wpad proxy script to ensure that all connections to his proxy server are on port 80 / unencrypted connection
@rabidpbАй бұрын
@@cmusgrave only works if he can offer a trusted cert matching the request URL (in which case bigger things are broken)
@Jorn-sy6hoАй бұрын
Very academic this approach! When will we see Hacking as a dedicated acedemic field?
@realdavidpainАй бұрын
It is my friend, it is...
@MrMatthijsrАй бұрын
It already is? There are dedicated conferences and journals focused on cyber security..
@Jorn-sy6hoАй бұрын
@@MrMatthijsr cool! I probably had a very specific idea in my head ;)
@Sonyboj28 күн бұрын
You mean computer science ? To hack something you must understand it.
@bonsairoboАй бұрын
GET THIS ERROR MESSAGE WHEN TRYING TO USE NETBANK
@trudyandgeorge24 күн бұрын
Dude really? 😂🤯 Adjust your hosts file my friend. And if it's not a personal machine then 1000% tell your IT / networking people.
@dangerfox177622 күн бұрын
@@trudyandgeorge he is quoting the presentation... also yeah just tell grandma to adjust her host file... This needs to be fixed on an OS level.
@gijsyoАй бұрын
Haha this guy. Great and sad at the same time.
@Sonyboj28 күн бұрын
How are they getting a wpad proxy on their machines in the first place? Just using the browser or they set it in settings?
@trudyandgeorge24 күн бұрын
+1. I wanted to know this too. At first I figured it's set at the OS level, maybe in some proxy discover daemon as part of the networking daemon ...but the more I think about it the more I reckon it's at the application-level. It must be the browser runtime reaches out, or the antivirus reaches out, or the Steam client itself reaches out, etc (he does mention to set a rule in /etc/hosts to resolve it locally 127.0.0.1). I wonder if my machine does it too? I'm going to setup a rule in my /etc/hosts then setup an nginx server to capture any requests. I'm on Ubuntu. (This is really blowing my mind. Best talk so far imo)
@_mr_andersson18 күн бұрын
All Microsoft software, and many third party applications, use the IE/Edge proxy settings and they have WPAD enabled by default.
@Sonyboj18 күн бұрын
@@_mr_andersson But then EVERY PC would be connected to this?
@_mr_andersson17 күн бұрын
@@Sonyboj Not every pc, but many. You have to have automatic proxy discovery enabled, you can't have a DHCP server that sets a custom WPAD address, your FQDN has to be under a top level domain where he controls the wpad domain, and there can't be any higher level wpad domain existing.
@trudyandgeorge17 күн бұрын
@@_mr_andersson They also need the implementation to be wrong; I believe he mentioned the spec said to recursively fetch, but not all the way to the top level domain. (perhaps I am misremembering as I saw this video a week ago)
@jacksonfive518029 күн бұрын
besically it should be criminal to inform you close a bug and its still there.
@rwz29 күн бұрын
The definition of "bug" is very loose.
@jacksonfive518028 күн бұрын
@@rwz@rwz Once you talk about closing it you do have opportunity to explain what are you closing and how.
@howwittyАй бұрын
38:45
@paxdriver16 күн бұрын
So, so soooo funny
@NinaMcmunnАй бұрын
I thought the audio would be better at a computer nerd convention
@AlgoindeАй бұрын
Sadly audio is provided by the venue. Or so I've heard. And the venue audio is usually the worst and the most rundown thing you can have. I'm a bit surprised defcon doesn't just run their own audio at the venue... could be achieved by using digital runs and one flight case worth of stuff nowadays.
@zwapzАй бұрын
Nerds type, radio dj's talk. ;)
@NinaMcmunnАй бұрын
@@zwapz this is a talk 👀
@NinaMcmunnАй бұрын
@@Algoinde that makes a lot of sense, if they streamed the event the issues would probably solve themselves with the stream implementation and would actually be worthwhile to do.
@smartyhallАй бұрын
Unfortunately, A/V nerds are security nerds are rarely the same. What makes it more painful for the someone like myself who is into both is that fact that most of the A/V problems they have could be solved by the audio equivalent of a couple of Raspberry Pis and a bit of creative thinking for almost nothing in either monetary or time investment. (I speak as someone who has decades of experience with the cheapest of clients - charities and churches.)