DEF CON 32 - Why are you still using my server for your internet access - Thomas Boejstrup Johansen

  Рет қаралды 45,747

DEFCONConference

DEFCONConference

Күн бұрын

Пікірлер: 83
@alzeheimersgaming
@alzeheimersgaming 28 күн бұрын
Most danish presenter ever, no context, no intro, just right into the presentation. Fun talk!
@robertbruce7686
@robertbruce7686 16 күн бұрын
His ancestors were also pretty straighforward too am sure 😂😂 (think longboats....). Great talk!!
@ChristianHaschek
@ChristianHaschek 13 күн бұрын
and spelling "w" as "v" :D
@fullfungo
@fullfungo 2 күн бұрын
And I still have no idea what the presentation was about 😅
@Jergling
@Jergling Ай бұрын
The web is a nightmare of 40 years of band-aids holding together spaghetti. My god, this is bleak.
@stansteez
@stansteez Ай бұрын
It's a miracle that it works at all :)
@quantumbacon
@quantumbacon Ай бұрын
So that's why it's called TCP.
@RonaldChmara
@RonaldChmara Ай бұрын
40 years ago it was band-aids holding together spaghetti from 40+ years before *then*.... that's all it's ever been, or will be, and yet we still manage to do amazing things.
@trudyandgeorge
@trudyandgeorge 28 күн бұрын
This is absolutely mind blowing. And the presentation was top notch. He totally foreplayed us all and when he bought the domain I knew it was gonna be a total show. Just. Amazing.
@ZedaZ80
@ZedaZ80 Ай бұрын
This is pretty funny, great work! It's wild this still works
@ZedaZ80
@ZedaZ80 Ай бұрын
Buddy, I cackled out loud about the crowd strike thing. A true hero!
@MiddlePath007
@MiddlePath007 Ай бұрын
He got me a few good times
@RedSntDK
@RedSntDK Ай бұрын
As a Dane it's hilarious how many times he uses "eller" instead of "or". Cute. 13:32 "Eller hvad hedder det.." 😅
@nirv
@nirv 29 күн бұрын
So man foreigns.
@7rich79
@7rich79 Ай бұрын
Great talk. I was in too much of a good mood with my weekend starting. Fixed.
@mibdev
@mibdev Ай бұрын
Completely unrelated, but I was watching this with my SO beside me, and then they went "He sounds danish", then four more seconds pass and there's a domain ending in ".dk". It's funny how you can just hear these things! :)
@RedSntDK
@RedSntDK Ай бұрын
To be fair, he has a quite thick accent and also uses "eller" several times. And the way he pronounces "data" is exactly like Danes do.
@Blommefeldt
@Blommefeldt 26 күн бұрын
@@RedSntDK The same with Java. In danish the J is more soft, and will sound like the english "yah" or "yea". So it would be kinda like "Yava".
@ehsnils
@ehsnils Ай бұрын
The ad-proxy thing could be that some ISPs are trying to inject their own ads into the web page.
@alfonzo7822
@alfonzo7822 Ай бұрын
Definitely!
@sb0373
@sb0373 23 күн бұрын
or just block all ads. thats how I do it. I hate ads.
@godnah
@godnah Ай бұрын
He speaks out of one side of his mouth. That's red team activity through and through.
@yescats3327
@yescats3327 Ай бұрын
If you are using the VeinMaster Iot 5ghz wifi butt plug, you have to twist the sac counter clockwise to access the proxy settings. Your welcome.
@gordslater
@gordslater Ай бұрын
I tried this but it just buzzes "404 not found" in morse code. Is there a root shell? Because there's always a root shell...
@andrewdunbar828
@andrewdunbar828 Ай бұрын
I was having a smaller Yaver script but the technical behind it was very technique.
@pete3897
@pete3897 Ай бұрын
I gotta get me some of that Yavascript for my Veepad :)
@storm4246
@storm4246 Ай бұрын
Great talk!
@5z436
@5z436 21 күн бұрын
lmao! this presentation is sooo funny~🤣🤣🤣 Also, he is a Master Troll! *bows*
@szaszm_
@szaszm_ 18 күн бұрын
The guy who only proxies ads is probably blocking ads.
@rabidpb
@rabidpb Ай бұрын
He implies in a few places that his proxy can intercept HTTPS traffic, which is not the case. There's a lot of useful data in the plaintext though.
@FuckYoutubeCensorshipCunts
@FuckYoutubeCensorshipCunts Ай бұрын
Anyone can intercept HTTPS traffic. Whether or not they can decrypt it is another question
@seansingh4421
@seansingh4421 Ай бұрын
It could be done if someone has access to certain TLS’s private pki information. Then there’s nothing stopping someone.
@alfonzo7822
@alfonzo7822 Ай бұрын
I'm guessing he's just used to saying Https instead of http.. just a little brain blip
@cmusgrave
@cmusgrave Ай бұрын
-I think he's redirecting https to a http connection- re-watching the video, at about 10 minutes, he's using the wpad proxy script to ensure that all connections to his proxy server are on port 80 / unencrypted connection
@rabidpb
@rabidpb Ай бұрын
@@cmusgrave only works if he can offer a trusted cert matching the request URL (in which case bigger things are broken)
@Jorn-sy6ho
@Jorn-sy6ho Ай бұрын
Very academic this approach! When will we see Hacking as a dedicated acedemic field?
@realdavidpain
@realdavidpain Ай бұрын
It is my friend, it is...
@MrMatthijsr
@MrMatthijsr Ай бұрын
It already is? There are dedicated conferences and journals focused on cyber security..
@Jorn-sy6ho
@Jorn-sy6ho Ай бұрын
@@MrMatthijsr cool! I probably had a very specific idea in my head ;)
@Sonyboj
@Sonyboj 28 күн бұрын
You mean computer science ? To hack something you must understand it.
@bonsairobo
@bonsairobo Ай бұрын
GET THIS ERROR MESSAGE WHEN TRYING TO USE NETBANK
@trudyandgeorge
@trudyandgeorge 24 күн бұрын
Dude really? 😂🤯 Adjust your hosts file my friend. And if it's not a personal machine then 1000% tell your IT / networking people.
@dangerfox1776
@dangerfox1776 22 күн бұрын
@@trudyandgeorge he is quoting the presentation... also yeah just tell grandma to adjust her host file... This needs to be fixed on an OS level.
@gijsyo
@gijsyo Ай бұрын
Haha this guy. Great and sad at the same time.
@Sonyboj
@Sonyboj 28 күн бұрын
How are they getting a wpad proxy on their machines in the first place? Just using the browser or they set it in settings?
@trudyandgeorge
@trudyandgeorge 24 күн бұрын
+1. I wanted to know this too. At first I figured it's set at the OS level, maybe in some proxy discover daemon as part of the networking daemon ...but the more I think about it the more I reckon it's at the application-level. It must be the browser runtime reaches out, or the antivirus reaches out, or the Steam client itself reaches out, etc (he does mention to set a rule in /etc/hosts to resolve it locally 127.0.0.1). I wonder if my machine does it too? I'm going to setup a rule in my /etc/hosts then setup an nginx server to capture any requests. I'm on Ubuntu. (This is really blowing my mind. Best talk so far imo)
@_mr_andersson
@_mr_andersson 18 күн бұрын
All Microsoft software, and many third party applications, use the IE/Edge proxy settings and they have WPAD enabled by default.
@Sonyboj
@Sonyboj 18 күн бұрын
@@_mr_andersson But then EVERY PC would be connected to this?
@_mr_andersson
@_mr_andersson 17 күн бұрын
@@Sonyboj Not every pc, but many. You have to have automatic proxy discovery enabled, you can't have a DHCP server that sets a custom WPAD address, your FQDN has to be under a top level domain where he controls the wpad domain, and there can't be any higher level wpad domain existing.
@trudyandgeorge
@trudyandgeorge 17 күн бұрын
@@_mr_andersson They also need the implementation to be wrong; I believe he mentioned the spec said to recursively fetch, but not all the way to the top level domain. (perhaps I am misremembering as I saw this video a week ago)
@jacksonfive5180
@jacksonfive5180 29 күн бұрын
besically it should be criminal to inform you close a bug and its still there.
@rwz
@rwz 29 күн бұрын
The definition of "bug" is very loose.
@jacksonfive5180
@jacksonfive5180 28 күн бұрын
​@@rwz​@rwz Once you talk about closing it you do have opportunity to explain what are you closing and how.
@howwitty
@howwitty Ай бұрын
38:45
@paxdriver
@paxdriver 16 күн бұрын
So, so soooo funny
@NinaMcmunn
@NinaMcmunn Ай бұрын
I thought the audio would be better at a computer nerd convention
@Algoinde
@Algoinde Ай бұрын
Sadly audio is provided by the venue. Or so I've heard. And the venue audio is usually the worst and the most rundown thing you can have. I'm a bit surprised defcon doesn't just run their own audio at the venue... could be achieved by using digital runs and one flight case worth of stuff nowadays.
@zwapz
@zwapz Ай бұрын
Nerds type, radio dj's talk. ;)
@NinaMcmunn
@NinaMcmunn Ай бұрын
@@zwapz this is a talk 👀
@NinaMcmunn
@NinaMcmunn Ай бұрын
@@Algoinde that makes a lot of sense, if they streamed the event the issues would probably solve themselves with the stream implementation and would actually be worthwhile to do.
@smartyhall
@smartyhall Ай бұрын
Unfortunately, A/V nerds are security nerds are rarely the same. What makes it more painful for the someone like myself who is into both is that fact that most of the A/V problems they have could be solved by the audio equivalent of a couple of Raspberry Pis and a bit of creative thinking for almost nothing in either monetary or time investment. (I speak as someone who has decades of experience with the cheapest of clients - charities and churches.)
@TESTA-CC
@TESTA-CC 6 күн бұрын
MINIX.
@Sonyboj
@Sonyboj 28 күн бұрын
.local and .ad... yesssss
DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix
32:30
DEFCONConference
Рет қаралды 44 М.
Amazing remote control#devil  #lilith #funny #shorts
00:30
Devil Lilith
Рет қаралды 16 МЛН
Linux Sucks 2024
1:14:16
Bryan Lunduke
Рет қаралды 107 М.
DEF CON 31 - Private Keys in Public Places - Tom Pohl
40:06
DEFCONConference
Рет қаралды 57 М.
New Computing Breakthrough achieves 100 Million Times GPU Performance
18:45
TCP/IP for Programmers
3:03:31
Eli the Computer Guy
Рет қаралды 226 М.
Sqlite Is Getting So Good
28:52
ThePrimeTime
Рет қаралды 203 М.
Whatever Happened to Millimeter-Wave 5G?
21:29
Asianometry
Рет қаралды 294 М.