What certifications should I prioritize to be a security tester (hired by companies to test their defenses)? I tried college, but the learning environment was not a good fit for me.
@Lelende2 күн бұрын
Note to self. When social engineering/phishing hack to Low Level, use racoon meme
@LowLevelTV2 күн бұрын
Would work
@revenevan112 күн бұрын
Pls open attachedment [sic] *raccoonmemes.zip.exe*
@Ariccio123Күн бұрын
@@LowLevelTVdo you ever dip your code in water before you read it to read it more good
@UncleBroerКүн бұрын
@@LowLevelTV You really love those raccoon memes 🦝
@rigsofrodsmaster2 күн бұрын
Reminds me of the "don't trust no one not even yourself" meme but it's backdoors.
@VeptisКүн бұрын
In germany there is a court case where a security contractor disclosed a vulnerability (password in cleartext for a database connected to the open Internet)... And then got sued. And the judge ruled that using My PHP Admin consitutes hacking. Maybe by as much as entering a building you arent supposed to while the door is open.
@Waldemar_la_TendresseКүн бұрын
"These people" are obviously completely dumb concerning IT and programming. Rules for 1d1o75.
@jeblerКүн бұрын
I haven't done PHP for a decade, but I still remembered extract. All of the PHP standard lib is riddled with backdoors.
@CAGonRivКүн бұрын
Imagine explaining this to your PM that has no experience in anything STEM and worked in HR their entire career.
@Waldemar_la_TendresseКүн бұрын
@@CAGonRiv You should not have to because it just should not exist in that context.
@thecakeredux2 күн бұрын
Dude, raccoon memes are THE BEST. It's essentially all I laugh about these days and me and my buddy have HUNDREDS of them.
@_hi_pwr2 күн бұрын
The supreme Urban mammal
@Milan____2 күн бұрын
you should send me an .exe file with all your memes in a convenient self-extracting format!
@HalianTheProtogen2 күн бұрын
Need
@FlavorExperimentКүн бұрын
U have hundreds of raccoons? Bake a cake with them
@DevWolf312 күн бұрын
Backdoor your backdoors at the backdooring center of Backdoors Inc.
@Adam7ep2 күн бұрын
@@DevWolf31 😂😂
@javabeanz8549Күн бұрын
This message brought to the by : The redundant department of redundancy department of redundancy.
@cslearn30442 күн бұрын
Im not gay but 20 dollars is 20 dollars
@JessicaFEREM2 күн бұрын
mood
@joseeduardorussoperis46682 күн бұрын
Based comment
@du42bz2 күн бұрын
If you were gay it would be even better
@soupadoopafly2 күн бұрын
At that note this would also still hold with a reference to a certain type of masturbation for very flexible people
@wedgevic_protoКүн бұрын
I, however, am gay But $20 is $20
@dmitriyrasskazov88582 күн бұрын
State backed hacker sounds cool, but at the end of the day its still just government employee.
@javabeanz8549Күн бұрын
With lots of money and research backing the position.
@TriSept2 күн бұрын
The WHOIS certificate method was an old way of verifying the owner before GDPR and WHOIS redaction was a thing. They would send an email the address on the WHOIS registry for the domain to verify the owner. Clearly not the best solution and now the DNS TXT record is the favored option.
@brentsanerКүн бұрын
you still need populated WHOIS for EV IIRC, but this is still valid for any DV using ACME. 0. pop WHOIS 1. change authoritative nameservers 2. DNS-01 *OR* HTTP-01 ACME challenge with wide-trust CA 3. Profit
@Tabu11211Күн бұрын
Im only here for the article reads. Im dyslexic and adhd, so this helps me a ton!
@Jafus1Күн бұрын
20:00 My preferred example of this is actually the word "gift". For your birthday, you receives gifts, and not jifts. Since both has "gif", it better drives the point that "jif" just feels wrong.
@threeMetreJim22 сағат бұрын
I know of no system that does jiraphics either. Maybe something from a rural African fairy tale?
@Pasta_watcher19 сағат бұрын
@threeMetreJim did somebody say Jira???
@YaySyu2 күн бұрын
We need more of our own nation state actors lmao
@sharedcat2 күн бұрын
love these types of videos, keep it up
@j-wenning2 күн бұрын
19:59 Counterpoint: gin, gym, gist
@yanikb.13122 күн бұрын
Yeah 'kif' people have no point. Just ask them how they pronounce scuba or lazer.
@StratelierКүн бұрын
"The correct pronunciation is--" _[end of video]_
@ankomcoper1183Күн бұрын
I do not care how you pronounce GIF, but I do find the bad arguments made by both sides hilarious.
@cattocsКүн бұрын
There's no way you pronounce gin as djinn
@Ariccio123Күн бұрын
This is the real content I'm here for
@DC-Nigma2 күн бұрын
reminds me of those belgium domains that where abbandon and they setup a email server and the emails with personal information just comes in...
@et449325 минут бұрын
This channel is amazing. I love your style man. Do you
@enzopestana2 күн бұрын
Article reading videos are great pls keep it up Ed
@Mmouse_2 күн бұрын
Hah I remember using some of those... And I remember looking at that extract code when setting stuff up and wondering wtf it did... Shrugged and carried on. Being young was fun, thanks for allowing me to visit it here.
@StratelierКүн бұрын
I haven't scripted any PHP in years and I noticed the @extract() sooner than he did.
@Newb1eProgrammer2 күн бұрын
Next video: backdoor the backdoor to the backdoor
@bennyswayofficial2 күн бұрын
Defunct and abandoned infrastructure? I'm gonna start going to abandoned warehouses, leave ip cams that stream to AM frequencies ('._.')
@dmitriyrasskazov88582 күн бұрын
Just never ever come back for them.
@kamiljanowski7236Күн бұрын
Lol. I once attended KPI Open - an international algorithmic competition held in Ukraine. On the first day the server that we were supposed to upload our solutions to just died because 1 of the teams from Russia just hacked it :P
@MattDog_222Күн бұрын
jia tan is disappointed in how unobfuscated that data is
@m4rt_2 күн бұрын
It's Graphics Interchange Format, not Jraphics Interchange Format.
@MattHudsonAtx2 күн бұрын
It's actually jraffic
@mage36902 күн бұрын
Also, JIF is peanut butter, not some sort of moving picture.
@monkemode81282 күн бұрын
Ummmmmmm actually 👆 it's an acronym and the symbols in acronyms don't need to be pronounced by the word they represent. 🙅
@pianochess18822 күн бұрын
Hey that’s a good argument. How do pronounce the abbreviation of "Computer Science" (CS)
@barry52 күн бұрын
@pianochess1882 you pronounce each letter individually because that's an initialism and not an acronym
@Little-bird-told-me2 күн бұрын
Backdoor the backdoor
@thelanavishnuorchestraКүн бұрын
I personally don't care whether you pronounce GIF with a hard or soft "g". I randomly say it both ways. As an old person who remembers the creator of the GIF format was making a pun about a certain brand of peanut butter, I do care if you have an exceptionally strong opinion and it's wrong. I reserve the right to point and laugh. And hey, I know sudo is pronounced "sue due" but f that, it sounds awful and I pronounce it "psuedo" like everyone else who has the word sudo in their vocabulary. So yes, Linux geeks. Pardon my french. Have a lovely day and keep making these videos. :)
@iExistOneКүн бұрын
Your timing is impeccable, 2 for ₪60 led. On the Triplebeam, 175 gram bred. Lock, Stock, and Two Smokin Barrels, It's twins Jed. Kookiel Ed, Tookie took my Kookie, Nuff Sed. Orbe Grinding at The Mill, up and down, Ram ban Ed. Those Cookies are making ME thirsty ked. Tail review your Auditd Logs head.
@shize9ine2 күн бұрын
19:58 - Thank you. Arguing with a co-worker: “ok fine. Let’s jo to my house and watch jaurdians of the jalaxy then.”
@GrahamLyonКүн бұрын
my favourite animal to see at the zoo is the giraffes.
@grmpfКүн бұрын
Would you offer them some gin?
@shize9ineКүн бұрын
@@grmpf touché
@randomgeocacherКүн бұрын
Dropping webshells in pentests - an interesting ethical aspect, like how do you ensure a malicious web crawler does not find it? Maybe a randomized file name is a workaround. Aside from the fact that it darn better not be backdoored.
@TungstenCarbideProjectileКүн бұрын
this guy is so 1337 he can read tech articles aloud like no other pen tester in the world
@threeMetreJim22 сағат бұрын
Instead of buying domains, I've seen hackers using services where you can host your own php driven pages; at least until they get caught. Sometimes the temporary domains have a 'username' preceding the actual domain, so maybe finding those, and using the same username in future may give similar results (assuming no random characters are added to the usernames).
@JosephDalrympleКүн бұрын
Love these videos! Incredibly nostalgic. My 13 year old son enjoys listening to them with me on our daily drives, and asking about the good old days! 😂
@0x0michael48 минут бұрын
As a Nigerian, i can tell you the federal high court website is not worth the $20 used in getting the backdoor backdoor
@Waldemar_la_TendresseКүн бұрын
Good sh1t, as always. After spending a few days watching various videos of yours, I am convinced that programming languages should be structured very differently. Rust is already taking the first steps so that memory access problems don't grow into even bigger problems. However, this can only be a start. I think we may have to introduce several levels for program execution in programming languages in which code and data have to live (analogous to userspace and kernel space, only with different levels). User input or much more in the level for user input, for example, or input from unknown sources in general, a defined and definable minimum of input should be possible. To take a closer look at the example: at the level at which what is discussed here works, "extract" should simply not exist. At other levels, however, it might. "Enforced security", so to speak, depending on the application level or area of the application.
@smort123Күн бұрын
14:57: The only difference between screwing around and Science is writing it down. - Adam Savage
@Lino12595 сағат бұрын
can you take a look at the patient monitor backdoor? maybe even take a look at the code? cisa did provide some insights.
@EonityLuna2 күн бұрын
We put backdoors in your backdoors so you can sneak in by the backdoor while sneaking in by the other backdoor.
@SimonSchick23 сағат бұрын
Nice article, thanks for the read-up 😎🎉
@viennois01232 күн бұрын
Backdooring backdoors sounds to me like shit squared.
@brentsanerКүн бұрын
also if you comp a WHOIS, you wouldn't change the information about who owns a domain- you'd change the nameservers. preferably with ones that fallback to the real NS if they have queries open to non-root servers to avoid noise.
@TheVault19992 күн бұрын
Mobi domain was ment for mobile devices
@mattjohnson858523 сағат бұрын
Jif. You don't gi-raffe, you ji-raff
@tertrih907833 минут бұрын
But the gi in gift is pronounced with a hard G. Anyways, the g in gif stands for graphics which has a hard g
@mattjohnson858522 минут бұрын
I tend to agree. I'm just being obnoxious lol
@nio804Күн бұрын
I like how the extract function uses the "@" operator too, which is probably my top candidate for the worst feature in a programming language ever. @ silences all errors, including syntax errors. I had to once debug a piece of steaming PHP that used it liberally and I now have a burning hatred in my soul for anyone who uses it.
@dev.sharif2 күн бұрын
It's funny, like you have a backdoor to a backdoor and you don't care to lose access to all of that, WTF! I'm so curious why these hackers didn't renew the hard coded domain. Am I missing something?!
@monkemode81282 күн бұрын
They probably got what they wanted and left. Maybe the guy with admin access got arrested or his hard drive crashed. Maybe there was an opsec mistake or vulnerability which puts them at risk.
@Vor10min.Күн бұрын
I do not want to loose compromised infrastructure, because it can be used for further attacks for example as Webserver for Phishing.
@Tux.PenguinКүн бұрын
@@dev.sharif Maybe they were lazy, careless, or forgetful.
@SBPk33 сағат бұрын
How does one try to help an organization and work with them when the organization wants to call you a liar and refuse to help. With that organization being my ISP. In which was compromised leading up to my issue.
@cachoraver10 сағат бұрын
Racoon memes are indeed the best.
@o0alessandro0o10 сағат бұрын
19:57 I mean, for those who prefer gif-like-giant to gif-like-git... There does exist a jif format, and I personally don't want to have to call them Golf India Foxtrot or Juliet India Foxtrot every time because somebody decided they should sound the same. That, however, is a different Foxtrot Uniform entirely, compared to the topic of the video.
@zalkiah9884Күн бұрын
Eat trash, be trash - Raccoons probably
@boomchaka14192 күн бұрын
the creator said jif like the peanut butter. For logic to be consistent you would have say JFeg instead of Jpeg
@mjmeans7983Күн бұрын
Only a fool spells photo with an F, when writing in English. Or are you implying JFEG should be Joint Foolish Experts Group?
@barbdwyer45Күн бұрын
@@boomchaka1419 Penelope vs Antelope
@boomchaka1419Күн бұрын
@@barbdwyer45 Not sure what your point is. The P in Jpeg stands for Photographic.
@barbdwyer45Күн бұрын
@ hercules testicles
@cameramaker22 сағат бұрын
So is there some list of sinkholed domains which I can put in the DNS resolver and get a poor man IDN solution, to get a notification if we catch some of that illness?
@billhurt3644Күн бұрын
Geoffrey the gentle giraffe would would side eye you on his way to the gym if he heard you pronounce gif that way.
@brentsanerКүн бұрын
"Jraphics Interchange Format" yeah no you're totally right
@billhurt3644Күн бұрын
@ yes your right. The rule is you have to pronounce every letter of an acronym the same way the word is pronounced. I’m sure that’s why was say NASA like N-AE-S-AA instead of the linguistically easier NASA. Or I’m sure you pronounce HUD (housing and urban development) like Hood.
@brentsanerКүн бұрын
lol none of that was applicable. Good job. Oh, sorry, I mean "jood" job.
@RoyalReptilePiratesКүн бұрын
Forgive me but you and John Hammond look like brothers? Am I wrong here guys???? Love both your guys content!
@HalianTheProtogen2 күн бұрын
Incorrect. Per the inventor's word, choosy developers use `.gif`. :D
@KizulEmeraldfireКүн бұрын
19:56 - I opt always to spell it out: NO ONE can argue with the pronunciation of "G-I-F"! :D
@icefreezer7Күн бұрын
What's next ---- software update infrastructure and autoscaling cloud infrastructure for SSLVPN appliances? That would be a never-ending nightmare!
@gomo562819 сағат бұрын
article sounds like man google dorked his way into known exploits. Used to do same back in the 90s, with php shell backdoors. and many other stuff. Anyway bro, whats your lowlevel academy roadmap, like future courses, marketable skills based projects? etc...Really horny about diving deep into C, but cant really see how the current courses you have can potentially equip me with emplyable skillset...then again i might be little bit to dumb to comprehend the actual value of the course in terms of jobs and all that.I would honestly love to see projects that demostrate practical use of c ....even a a simple video promoting the applicable value of the course at the jobs market, ideally exaplaining like you would explain it to a racoon :)
@Aplysia2 күн бұрын
Hey, we just collect usage analytics in order to improve your user experience with future releases! What's the problem?
@Muhammed_Shameer_Quraish_KMКүн бұрын
so its a backdoor in your backdoor ? sounds like inception of backdoor.
@MiriamSlaffeyКүн бұрын
Ohh the nostalgia for the c99 and r57...
@brentsanerКүн бұрын
"imagine they're on their mobile phones" Nah, fam, that's probably just a UA rotator.
@duetwithme766Күн бұрын
Maybe this is general knowledge, but what's up with .MOBI? Seems a like a major event? Do you have a video on it?
@srsherman7Күн бұрын
Backdoors... those are the doors in the backrooms, right?....
@HorrorMakesUsHappyКүн бұрын
Don't be surprised when the people paid to find/create backdoors don't close them when the current project stops paying. It's like leaving a stolen vehicle somewhere with the keys behind the tire. Yeah, it might not be there when you come back, but if it is, great, because that just saved you some time.
@genuismensa2 күн бұрын
Most of them just require you to do a TXT record with a hash in it to prove that you are the owner of the domain. - Regarding WHOIS question he asked.
@oaklyfoundation22 сағат бұрын
What does dmarc have to do with ownership validation? I don’t think you are right on that part.
@send_loveКүн бұрын
20:00 small correction. It is indeed pronounced jiff
@Some-Guy-Күн бұрын
There's a prince who can help the Federal High Court of Nigeria find the hackers, but in order to keep his bank details out of the hacker's hands he needs your help moving some funds around.
@erikhicks07Күн бұрын
You would think these once-rogue domains would be DNS blacklisted worldwide.
@davidbronke5484Күн бұрын
100% on GIF pronunciation. I don't hear anyone saying "jraphics" 😹
@steveyh132 күн бұрын
19:58 you don't "jo" to the bathroom, but do you like watching "jiraffes" at the zoo?
@CodyDBentley18 сағат бұрын
17:47 begs to be GIF'ed
@randomgeocacherКүн бұрын
You speed-ran through the networking/IP comments, barely comprehensible, having the page on 192.168 up for like a second :) The block reservation size vs network size was way to quick for me to follow there, and I’ve been around since ancient times when we built networks with sticks and stones.
@BennettBeachКүн бұрын
Not saying Jiff is enough for me to
@johnsmith8981Күн бұрын
I got my backdoor hacked once. I kinda liked it .///.
@Dank2 күн бұрын
i had no idea you could do this (twenty dollar dollars)
@kidmosey17 сағат бұрын
JAG - Judge Advocate (J)eneral, or Judge Advocate (Gh)eneral?
@mr.togrul--9383Күн бұрын
LMAO, were you able to learn what is SSRF?
@soulife83837 сағат бұрын
Pfft if you thought 2010 was a fun time for the Internet you should have seen 2000. Almost no antivirus, or firewalls, DSL sucked but if you were patient you could get free dialup from a compromised library computer, or put a Trojan into an AOL install and put it on as many school computers as possible. I even remember compromising our towns email, sending emails from teachers using telnet, net send flooding classrooms with pop-up messages, bypassing DNS filters, ah good times. I don't miss walking around with 40 disks to bring home mp3s from the schools T1 connection
@randalthor17Күн бұрын
oooo my govt is vulnerable as we thought, woooo
@HadTooMuchToDreamКүн бұрын
When ya done, why wipe off the victim? Sloppy practice, yet it leaves sloppy seconds.
@cognitive-carpenter2 күн бұрын
Don't forget to like--wow, only 995 likes thus far! Great content LL
@Bill_BaconКүн бұрын
The description sounds like a "one flew over the cuckoo's nest" ideology. Effective at being non-suspicious, I guess.
@CrateSauce2 күн бұрын
low level tv?
@pwood644612 сағат бұрын
Sorry, No. ".gif "is "jif" according to the resposible parties ...think "jiffy". Give it a little thought, it's the only way any of it makes sense, no matter how many people try to twist it.
@gurbanliye2 күн бұрын
Is this like writing an antivirus to antivirus ?
@jeanbigКүн бұрын
thumbs up for correct pronunciation of *.gif (also the video was good)
@nR-kv7xo2 күн бұрын
haha I played with this as minir in the early 2000s. Funny this is still alive. With properly containers today with readonly fs, no root access, and ingress controllers this is useless for most systems... except these legacy ones. Very interesting
@asdasdaee22322 күн бұрын
We did this in 2010; not new but a great write up! Another option I'm surprised they didn't pick up on is using public VPN services which allow for port forwarding :) Old school stuff being brought up is great! Source: I'm an ex-malware developer turned security researcher.
@tcc12342 күн бұрын
"Another option I'm surprised they didn't pick up on is using public VPN services which allow for port forwarding :)" Could you elaborate on this?
@JackShenКүн бұрын
ah the days when you could put javascript tags in comments........
@avegamers2 күн бұрын
Oh Hello, a new Video 👋
@mcgrewgsКүн бұрын
19:59 Joe mama goes to the bathroom
@GilesBathgate2 күн бұрын
Having the name Giles, I can tell you hat I don't "go" to the bathroom either. I Gi to the Bathgate.
@user-ju5wk3iu1kКүн бұрын
I'm not into security but I'm here for you sweet, beautiful face. Thanks.
@Rx7man11 сағат бұрын
Competing with Louis Rossmann for talking and 2x speed!
@lMINERlКүн бұрын
but but , LL i always Jo to the bathroom XD
@alphaomega1542 күн бұрын
those what i call as "rebel without a cause". looking for trouble against the authority for thrills. i dont see the point of why they do what they do. just causing nuisance to the state actors without actual mission or purposes. they arent trying to help anybody. i dont respect those type of factions. well, one of the "animal guided" humans. no wonder. the sufferings are still sufferings. and those group you talk about just in it for thrill. they exists or not make no difference.
@Mudflap11102 күн бұрын
Hahaha 😊 Love it! Raccoons for the win🎉
@sheis5358Күн бұрын
and you don't call a jpeg a "j-pheg," Ed
@supermariomistickgames4700Күн бұрын
Backdoor of a program if it was a person: "Haha! I've got all your data and I'm going to share them to the author of this backdor!!...... which.... is... you..........😳😳"