Found two vulnerabilities on my router thanks to this! Then I found out that xfinity doesn't allow users to update the hardware they provide. Guess who just ordered a new router? Thanks for this video.
@illuminatiilluminati98366 жыл бұрын
Please make a full course on ethical hacking...
@fredericchopin76396 жыл бұрын
@Richard Vaughn what you are talking about is illegal im pretty sure. If you really want to you should go to the deep web.
@joemccormick93486 жыл бұрын
@@fredericchopin7639 u crack me up
@fredericchopin76396 жыл бұрын
Joe McCormick can you explain why
@joemccormick93486 жыл бұрын
Your general lack of knowledge that its perfectly fine to put it on the internet and your general complete misconception of what the dark web is entirely
@fredericchopin76396 жыл бұрын
@@joemccormick9348 And why do you think so? There are many helpful forums for hackers on the dark web. He wont be able to find unethical hacking courses on youtube so i suggested him to check out the forums on the dark web. whats so wrong about that.
@maxpayne4385 жыл бұрын
I asked my router for concent, and it blinked...guess it is okay with this
@3rdvoidmen5945 жыл бұрын
Underrated comment
@luiscastillo66155 жыл бұрын
Hey how do I open routersploit I cant open it and I install it help
@NinjaHempKnight5 жыл бұрын
@@luiscastillo6615 make sure you are root: sudo routersploit [ENTER]
@brothersgta339-jb1ld3 ай бұрын
eat chickens 😂
@Drael10246 жыл бұрын
Just discovered your channel and I have to say, your content is amazing! Also thank you for this video.
@emtdavis6 жыл бұрын
I came here to say the same as Tibor - great stuff, man. Keep up the excellent work!
@enos51924 жыл бұрын
Hey I know U
@juanp53084 жыл бұрын
Bro u are the guy of linus tech tips!
@norsendo65324 жыл бұрын
Lil note (HE DOESNT BLINK!)
@roykibet60385 жыл бұрын
Imagine having this guy as your next door neighbor 😅😅
@mono92375 жыл бұрын
would be cool, i would ask him for teaching :D
@ajinkc10315 жыл бұрын
@Nguyen Dang Duy Khang i dont think he would do that
@mikemaschine225 жыл бұрын
i would only run wires no wifi xD
@J2897Tutorials5 жыл бұрын
A distant physical location wouldn't provide safety. He can attack from both the LAN and the WAN.
@dashdashdash_5 жыл бұрын
@@J2897Tutorials And he also might test your locks whilst you're out at work...
@platinumpython93126 жыл бұрын
Everybody makes errors, makes more sense to continue the video than to edit it. Great stuff, your way of explanation is super smooth. Would appreciate a video of you creating Persistence USB, without LUK. Thank you!
@mlgamer55474 жыл бұрын
I want to say that once i was a beginner i learned all from this channel. I wish this channel could reach 1 m subscribe before 2021
@trentcarr19394 жыл бұрын
teach me your ways
@Jackaldev5 жыл бұрын
2:46 I thought he was having a stroke for a second.
@capalert13015 жыл бұрын
Jackal cool to see you here...
@Jackaldev5 жыл бұрын
Wym?
@Jackaldev5 жыл бұрын
Yep
@colt81105 жыл бұрын
Jackaldev i saw you from the lanc vids
@5entience6264 жыл бұрын
Lmfaooo
@crimsontorso41266 жыл бұрын
Hawaiian routers are mostly unsecured, as a large amount of botnets (mostly mirais) use these routers by using a set list of 0days. Also, thanks for the
@rage76586 жыл бұрын
that introduction is one hell of a ride
@NullByteWHT6 жыл бұрын
We shot that and a commercial for a donut store in the same two hour period
@rage76586 жыл бұрын
Null Byte Oh my god 😂
@psknhegem0n5936 жыл бұрын
Thanks for your awsome job mate! It's clearly not rewarded enough!
@jeonghutamilim22596 жыл бұрын
ISP's like to implement TR-069 backdoor into things
@lennovo95255 жыл бұрын
Omg. It blinks at 1:20. He may be human after all. Great channel.
@tibielias6 жыл бұрын
Thanks for the video! I scanned all my devices at home. Routersploit has only found devices where the 6-9 vulnearbilities (on various ports) couldn't be verified. Is there a way to try to get a better picture whether these devices are really vulnearble or not? Can you group together these unverified exploits and run them individually using RouterSploit? Update: Never mind. I tinkered with it a bit and got it to work! Pretty powerful tool, I have to say. Many of the payloads might need some fine tuning since they crash the CLI with silly errors such as "unorderable types" when comparing tuples and such. Nothing that couldn't be fixed.
@C-j-m-2185 жыл бұрын
Well if they have the exploits see if you can hack it
@KayvonGz5 жыл бұрын
Charles Mills Shouldn’t have to, the scanners Routersploit uses is trash.
@hotwoodgaming57956 жыл бұрын
You need an online course for this stuff man great channel btw
@grimssouls38976 жыл бұрын
I managed to get into my own router. My creds weren't vulnerable, but rom0 and another thing like cmd was. I was able to run payloads/commands directly from my computer. My skill level doesn't know what to do with the vulnerabilities I got, but I do know that it could reak havoc on my router.
@christianhernandez45736 жыл бұрын
Awesome video man, I love your work. Thank you for putting this information out into the world. I can guarantee you will inspiring people to do great things by sparking their curiosity. Again Thank you
@dr--a6 жыл бұрын
Awesome stuff Bro, I agree you should make a course on ethical hacking 👍🏼
@shmehfleh31154 жыл бұрын
This RouterSploit program is cool and all, (and it's definitely good advice to keep your stuff patched), but if it requires you to be on the inside of the network anyway, then the damage is already done. At that point, having your IP cam hijacked is the least of your concerns.
@djnikx12 жыл бұрын
yup, he missed to mention that..
@techtweakstv6 жыл бұрын
Nice video! but if that cam was a sample, maybe you can create a dummy info or vulnerability so that we can see the information given on that exploit and how we can check the credentials and logged in. .:)
@rkan26 жыл бұрын
Yeah… I completely left hanging by what was pwned!
@squiggerzzzz4 жыл бұрын
Like a few others have mentioned, the “set port” command was giving me trouble too (on MacOS), but in the list of usable options it displayed it appears maybe routersploit got an update and now the command is set http_port 80 (or whatever port you want). Awesome vids btw NB, whenever my brain shifts into inquisitive mode during the day I try to come back to pick up another topic I’m unfamiliar with. Thank you for sharing the intel!
@thejestersrealm79653 жыл бұрын
*Says legal disclaimer* Black hats: “that is merely a suggestion”
@georgek44166 жыл бұрын
1:30 I was looking at this cute cat and not listening you. I had to rewatch this part.
@NullByteWHT6 жыл бұрын
if it was the fat angel behind me then I don't blame you
@georgek44166 жыл бұрын
@@NullByteWHT lol
@MirkWoot6 жыл бұрын
Right away when i heard "Easy python script", I thought.. "No, not simple or easy" haha.. then there are requirements, and commands :P. I can figure this out, and know there is target audience. I just thought it was a little fun anyway as it also takes a little more knowing things than the average person.
@TheAnalystradioprogram6 жыл бұрын
I burst out laughing the way you said “Definitely illegal” because you already know I’m gonna do it. Omg. You might have well have said “Yea fuck it, you people are on your own” Lol
@Kurkeyyy4 жыл бұрын
So you can use router split for your own good to see if your router is good?
@fawwazchiwne86116 жыл бұрын
Explanation man ♥️
@rafeinnit81145 жыл бұрын
I dont have a port setting in my target options?
@porlando126 жыл бұрын
Thanks for the vid. I was able to get this running on my Rpi!
@plutoboy88276 жыл бұрын
Awesome man!!! Going to hit 1 lakh subs soon...
@NullByteWHT6 жыл бұрын
pluto boy thank you!
@DormirnaodaXP6 жыл бұрын
Hello null byte team am I again, congratulations for your good work on youtube, I would like to ask a video teaching how to capture information on smartphones and laptops on the same wi-fi network as us!
@ricarprieto5 жыл бұрын
You're awesome! I just discovered your channel... how many wasted minutes on youtube before you! Thank you for your videos
@ne12bot946 жыл бұрын
Great video , keep up the excellent work.
@joincryptouk6 жыл бұрын
Great video on a very nice tool to play with on your own network.
@jamesnduati70834 жыл бұрын
I would like to see this channel get 1m subscribers very soon.
@MrCipek12216 жыл бұрын
It's awesome to see tool made in poland in your video :)) greetings from pl :)
@j.rumbleseed6 жыл бұрын
got it finally. thanx much for this tutorial.
@wesleyvaleran3946 жыл бұрын
Great video kody like always😁 ive been playing with routersploit since last year but recently got some error(python 3) but i guess it will be fixed with a pip upgrade anyways i hope to see more videos like this that are not based on hardware or anything of a kind(tried your wireless attack videos unfortunately my wifi card only supports monitor mode not packet injections)😅 could you do a video on how these attack/exploits are automated, like vpnfilter/botnet ? Keep up the good work😁
@NullByteWHT6 жыл бұрын
Wesley Valeran glad you enjoy them! I'll be trying some basic python exploits soon.
@Steven-wo9bm4 жыл бұрын
You......are......amazing bro. You are my teacher.
@ulim86 жыл бұрын
Great video, thanks for contributing it! One thing that gets me though, that black book in the background with the yellow font, what is it? It seems so familiar to me....
@NullByteWHT6 жыл бұрын
It's called "the code book"
@NullByteWHT6 жыл бұрын
I got that wrong, it's "codes, ciphers, secrets and cryptic communication"
@ulim86 жыл бұрын
Thanks muchly! I knew i recognised it! Choice!
@ericimi Жыл бұрын
Love this series.
@_crys_6 жыл бұрын
The only thing I don't get: you're doing the scan and exploitation on the internal network. How does the vpnfilter malware or anyone malicious access these ports that are only open internally? If you type in someone's IP address into your browser, you won't see their router's web configuration panel...
@geminivegan65874 жыл бұрын
Where can i find a full length of you teaching cyber security ?????
@benjaminallread46565 жыл бұрын
thank you so much I love your channel I just tested this out on my own router and I actually got in this is my first real life hack I AM SO EXCITED THANK YOU SO MUCH I LOVE YOU
@mrj29044 жыл бұрын
Just to wrap my head around things. It makes sense to do this on your own network that you are connected to. But can you do this to other routers remotely? If you use a public ip address ? Is this possible ? Or do you need to be connected to the router you are trying to exploit ? Any help and advice would be appreciated. To clarify I’m learning / have consent from others 😂
@5wholepizzas2842 жыл бұрын
I think u have to be in the routers network before u can exploit it
@outlaw83794 жыл бұрын
I've been learning these types of things for a while and always wondered is it possible to find out a WiFi BSSID and Channel even if the router is in another country? I can perform the basic DoS on any network im within range for, however my friend who lives in Scotland volunteered that I can pentest his Router, is there anyway of doing so? Sorry, im a newbie to ethical hacking and cyber security
@DeanoboiROTMG6 жыл бұрын
very informative just goes to show how vulnerable everyone truly is and they dont even know it
@nobeltnium4 жыл бұрын
my router look at me watching this video and scream
@zephyr10186 жыл бұрын
Your voice is like an angel nice video 😇
@PaulBadman6 жыл бұрын
Would OEM ISP routers be at a greater risk than a store bought router?
@NullByteWHT6 жыл бұрын
Paul Badman ISP routers are worse
@PaulBadman6 жыл бұрын
Thought that would be the case,However thought I would ask anyway
@PaulBadman6 жыл бұрын
DD-WRT is down at the moment and my router isn't supported by open-WRT (I changed provider and old router broke),However I'm looking for a new router mainly because this one is bullshit for streaming files from NAS to over devices I would really like one with a 4G back up on it but I doubt I would ever use the 4G function lol
@PaulBadman6 жыл бұрын
what do you need to hack? Most people have their profile public and the answer to their email security question on their profile. as long as you get their email thats tied to their account you could just reset the P/w and jump in,It's been a while since I done anything like this so I wouldn't know if that still works
@JohnTheRipper1436 жыл бұрын
hello,I love your videos,but I'm curious about what classes I should take in order to become a professional pentester. what type of books should I read? please help
@HeadlampMafia6 жыл бұрын
I also am curious. This sort of thing has always fascinated me, but I never allowed myself the time to dig into it
@Subjagator6 жыл бұрын
@@HeadlampMafia My suggestion would be to find a company that specialises in penetration testing and ask them what they typically look for when they are hiring people. That will give you a decent idea for what is required and you can go from there.
@cexeodus Жыл бұрын
Its wild that you can literally render your wifi network invisible to most wifi scans by adding one specific character and never really need to worry. Cant even detect other devices over ADB wireless debug when on the same network. NSA gonna love that, when they have to pay me to reveal one literal key press and then realize how stupidly simple it is 😂
@dududjddjehdhdud-ui3yc Жыл бұрын
You believe that?
@cexeodus Жыл бұрын
@@dududjddjehdhdud-ui3yc Its not a belief in that I would rely on it, but also I do have a bit of awareness of the fact anything can be hacked. Just a metter of time with any service, protocol, etc Its good until it isnt like the whole rest of the tech world.
@mrtgsy6 жыл бұрын
Thanks... spent the night beasting my network looking for issues. None found, which is good. Potentially stupid question time though: are these vulnerabilities only 'real' if the device in question is exposed to the internet / port forwarding to internal? i.e., if a 'bad' device is behind a firewall, it will only pose a threat if someone can actually gain physical access to the network?
@tin20016 жыл бұрын
matt's debates Pretty much.... But remember you've got web browsers capable of running JavaScript that you use all day. One clever bit of JS, and your bad devices may suddenly be bots in a massive router botnet.
@henryward83114 жыл бұрын
...you use mac too!? I thought I was the only mac hacker - WHAT THE HAACCKK
@slaxblake6 жыл бұрын
a question, when setting the ip can it be a public ip instead of a private ip that u put doing the video? because the way you do it you should already be in the wifi you are trying to pwn
@mihirshah10566 жыл бұрын
The ping only can be done if the firewall allows the icmp echo request and responses to the same, so even if the router if vulnerable with a good firewall, chances are you would never know about the vulnerability
@tin20016 жыл бұрын
Mihir Shah Blocking ICMP echo (and most other ICMP) is a bad idea. It breaks more than it solves... No hacker actually believes a lack of ping means he IP is down these days.
@mihirshah10566 жыл бұрын
tin2001 True...but can u list the disavantages of blocking icmp echo requests...thanx btw
@kshitijkathuria94736 жыл бұрын
Yeah that's an intuitive question...good work bro...keep it up
@mihirshah10566 жыл бұрын
Kshitij Kathuria thanx...
@mrshoes10026 жыл бұрын
What is the thing scanner you mentioned on your phone to do a similar nmap scan?
@NullByteWHT6 жыл бұрын
Fing www.fing.io/
@TemperedWambat6 жыл бұрын
My router is two years old and i havnt been able to update my firmware because there is no patch from the devolpers wtf =[
@NullByteWHT6 жыл бұрын
supersonic118 Alex you should really get a new one, that's the worst case scenario.
@ithraldharzul68876 жыл бұрын
does openwrt, ddwrt, or tomato support it? those open source router opperating systems support a wide range of devices and often offer more features than the manufacturer defaults
@blakel956 жыл бұрын
Just do a factory reset and make strong passwords for router and wifi login.
@Subjagator6 жыл бұрын
@@blakel95 Strong passwords don't help if there is an exploit vulnerability. As shown here when he connected to the device normally it asked for username/password but that didn't stop him dumping the config info using an exploit. I have no idea what was dumped but he said it was pretty bad so you really need to be able to update firmware when vulnerabilities are found.
@TheAnalystradioprogram6 жыл бұрын
Hide your ESSID/BSSID (Network broadcast) to start with.
@mc.doncardervisa72796 жыл бұрын
Would this allow you to attack an IoT camera that allows connections from anywhere. Or would you have to be on the same network to target devices and only works with local IP addresses?
@Brasuasd6 жыл бұрын
tyvm for teaching us, started a small project of security with some friends and well Im the only one that doesn`t know all this things...
@tomnoyb83016 жыл бұрын
Noob here. Are we saying someone can penetrate our firewall router to reach a port on our printer or other device, then leapfrog back into other devices on our network? Or worse, monitor all network traffic?
@misbahuddin18976 жыл бұрын
best as always_ bro make video on protocol downgrade attack,,,,,
@johnconnor38296 жыл бұрын
What is the title of the book behind and to the right of the guy talking? The big green book.
@NullByteWHT6 жыл бұрын
Hi! I'm the guy talking. It's a book I grew up with: www.amazon.com/Codes-Ciphers-Secrets-Cryptic-Communication/dp/1579124852
@johnconnor38296 жыл бұрын
Null Byte Thanks, I'll grab a copy. I will have to try routersploit in future pentesting.
@NullByteWHT6 жыл бұрын
I hope it serves you well in the war against the machines.
@sihamkarbous99725 жыл бұрын
How on earth u only have 150k subs
@chrisberger92866 жыл бұрын
So.. incredibly stupid question - trying to get a general understanding of this topic, but just started and frankly don't even know where to find the answer to this or how to ask it.... So, if one were to be using Routersploit to look for vulnerabilities, would one ever use a public IP address for a target? Or is it usually used with 192.168.1.1 ect (not sure what these IPs are called, intranetwork?). If it's usually used with 192.168.1.1, how does one target an outside location, as opposed to just looking at their own router constantly? An answer, or the above condensed to a searchable google question, is greatly appreciated
@NullByteWHT6 жыл бұрын
You generally cannot log into a router from an external IP address
@chrisberger92866 жыл бұрын
@@NullByteWHT I'm fascinated by the subject.. but a little confused on this point of it specifically. If you don't mind answering another question or two, or if there's a better forum you'd suggest (strictly for white hat questions), I'd appreciate it.. So there is no way I could, hypothetically, from California target a Missouri router, find an open port with a vulnerability of some type, enter the network and upload a RAT to a computer? Or would router vulns typically be exploited for information leaks of some kind?
@rohankumarshah5679 Жыл бұрын
amazing work dude!!
@htown46526 жыл бұрын
I have a pau05 and when I search for networks I cant find anything. Suggestions?
@leontalkdaliy58945 жыл бұрын
You are amazing super explanation and everything are clear that’s why I follow your channel thankx for information
@NullByteWHT5 жыл бұрын
leon vita thanks for watching! Tell all of your friends about us! 😃
@ffs43025 жыл бұрын
Could you please suggest any setup (router, firewall, etc.) to secure our small company network? thanks
@rasajacobin71055 жыл бұрын
What terminal did you use? Itern is that for mac only what about window can you provide some link on description? correct me if im wrong
@holybigpp17854 жыл бұрын
music name "Xtract - Audiotool Day 2016"
@MmDipro4 жыл бұрын
Can you do this over WAN?
@deusvult46786 жыл бұрын
very nice tut thanks ,but what about routers to which we are not connected ?
@harry09_089 ай бұрын
Is routersploit is used to test switches also?
@AjayKumar-fd9mv Жыл бұрын
Hi, 1)Does Routersploit instalation has any malware or executable binaries as part of its payload which inturn can infect the computer on which Routersploit is run ? 2)Can Routersploit payload infect target router and make it vulnerable to further attack if I forgot to factory reset the router after test is run ?
@cs777x4 жыл бұрын
Most malware payloads are jus botnets. For example ssh into routers with default user and pass and wgetting your payload to install your malicious bins onto that router to add to your botnet. Most routers use the mips bin.
@NullByteWHT4 жыл бұрын
Too true!
@smudgepost6 жыл бұрын
As this isn't open scanning/monitoring wireless networks, I don;t think a AWUS036ACH chipset wireless adapter is required, please confirm?
@Synthetic-Chicken6 жыл бұрын
How does this work against ISP switches and routers? I had a play and I think I got right through to my internet providers main credentials.
@D3rMesaa6 жыл бұрын
And how Do I get to know the IP Adress of a foreign Router to test it?
@kutchve81984 жыл бұрын
Same issue brother ], if u had find out than let me know.
@alibaker87605 жыл бұрын
Thank you very much for your hard work. We appreciate that.
@catlover89676 жыл бұрын
I like the pics of the cat in the background
@grissgray6 жыл бұрын
If a device is Vulnerable on my network.. Dose that mean you'd have too be on my network too do take advantage of that vulnerability
@BizcochitosNeko5 жыл бұрын
Very good Talk, informative!
@tamaboy624 жыл бұрын
help sir...why my routersploit any notification bellow TypeError: '>=' not supported between instances of 'tuple' and 'int'
@npenope76365 жыл бұрын
In the distance you see a potato. Like if you saw a potato after reading this.
@Ash_Pirate6 жыл бұрын
i'm getting error when i run this command: python3 -m pip install -r requirements.txt error: /usr/local/bin/python3: No module named pip but i've installed it using command : apt-get install python3-pip so what should i do now to work it?
@Sam-gd4xp6 жыл бұрын
What is the name of second suggested port scanner. First was nmap, second one souded like 'thin' or 'thing' !?
@NullByteWHT6 жыл бұрын
Fing network scanner
@flex63985 жыл бұрын
Nullbyte please help me out will this also work on someones else router i mean you can het there information or Just your own router 🤷🏻♂️🤷🏻♂️
@CristiVladZ6 жыл бұрын
do antivirus or malwarebytes detect infection with this?
@MarsAsmr2.0 Жыл бұрын
I know this video is from along time ago but how do you fix the issue exploit failed could not extract credentials?
@Alm1r5 жыл бұрын
if i keep watching ur videos i may end up in the big brother
@mrdiamond645 жыл бұрын
6:09 What command did you use to scan the network for ports? Does the command work on kali Linux? I’m trying it but it’s not working
@Artook5 жыл бұрын
he used nmap to look for open ports. The prompt is : nmap -p 80,8080,8081,81 /24
@bilalmazhar1006 жыл бұрын
which router and version of router you use ?
@listerofsmeg99324 жыл бұрын
Is this as straightforward in user land?
@ashtondarrengoh20014 жыл бұрын
Hi if I put a clock to monitor the time in the background if someone freezes my IP camera is it accurate to say the date and time stamp on the IP camera would not coincide with the actual clock in the background of the camera footage?
@iteachcyber5713 Жыл бұрын
Do you have to be connected to a network to use routersploit?
@pxdb80283 ай бұрын
Yes you have to be connect to the network you want to use it on
@novax62126 жыл бұрын
Hi dude what wireless adapter should i buy for my parrot sec os virtual machine ?
@xp0z5 жыл бұрын
You should be able to use your computer's standard adapter
@русскийдруг-е2х4 жыл бұрын
Thanks you brother i like you presentations !!!
@ferzeliy3v3 жыл бұрын
Hello, I have a term, how can I do it, because I have ipv4 or ipv6 writes because I don't write ip address, help me