Helsinki Darknet Market's Security Failures: IP Leak, Info. Disclosure, etc [Still Live]

  Рет қаралды 18,112

Sam Bent

Sam Bent

Күн бұрын

Пікірлер: 97
@Usmc913
@Usmc913 4 ай бұрын
Someone took a few coding classes and thought they could build a market. Any competent threat actor could destroy that market.
@Aaron-zu3xn
@Aaron-zu3xn 4 ай бұрын
they bought a script they don't even know how to run a tor exit node network they were just told they could operate it if they paid someone so this scammer got scammed lol
@nothingtoseehere449
@nothingtoseehere449 4 ай бұрын
you are 100% right 3 darknet market admins were caught this year and all of them are facing LIFE in federal prison they gave Ross Ulbrich the Silk Road founder a double life sentence this is not a game
@tonysolar284
@tonysolar284 4 ай бұрын
Hey. Have a great day.
@4lphao256
@4lphao256 4 ай бұрын
Ross was also meddling in Murder for Hire. These things are not the same.
@nothingtoseehere449
@nothingtoseehere449 4 ай бұрын
@@4lphao256 people like to throw in the murder for hire aspect but the prosecutor didn’t even do that nor was he charged with it
@amir3515
@amir3515 4 ай бұрын
@@4lphao256 innocent until proven guilty and he was not proven guilty for the charge
@ImperiumLibertas
@ImperiumLibertas 4 ай бұрын
​@@4lphao256 the evidence was so suspect that the prosecutors didn't even use it. It smelled heavily of planted evidence. Seems like the prosecutor didn't want to risk the case by including the imo obviously planted evidence by the feds. Isnt it interesting that every enemy of the state happens to have csam or other illegal digital untraceable content on their hard drives? Very interesting.
@Bullminator
@Bullminator 4 ай бұрын
A market with security so bad could also be a fed trap.
@veganlsd1577
@veganlsd1577 4 ай бұрын
i was thinking something similar, probs even with Java :D :D ... like Middle Earth Market enabled java just before they exit scammed ...
@projectsspecial9224
@projectsspecial9224 4 ай бұрын
Of course, when you think a few moves ahead like chess 😅
@dave7244
@dave7244 4 ай бұрын
2:55 Even for a regular clearnet site, I would avoid giving away any information on how the system is configured at all. I know sometimes you can tell by how the site works. or the HTML/Scripts that are sent to the browser. But I just wouldn't make it easy to find out what version of the OS, what language / interpreters are installed and what the system configuration is, because someone malicious could use this information when crafting an exploit.
@Sam_Bent
@Sam_Bent 4 ай бұрын
Absolutely great advice to give.
@JAIMOUStheFAMOUS
@JAIMOUStheFAMOUS 4 ай бұрын
Hey ya know what makes this channel unique? Besides being super informative regarding DW stuff, but even more so, is How genuine of a guy u are. And i bet your a great friend. It shows thru in most of your videos, weather u mean it to or not.. U mentioned trying to raise your videos production stuff, but dont worry too much about that, your videos current vibe is straight! I dont want to feel like im watching msm news or something. Lol but thats just my opinion. I e learned alot in the short time since i found your channel, keep em coming my guy!! Oh just to be clear im not a vendor or looking to be one, im more experienced in the costomer side of the DN markets, and these videos help me stay informed . Thanks man!
@Sam_Bent
@Sam_Bent 4 ай бұрын
Thank you for the positive reinforcement! I appreciate you taking the time to comment and give me your input as to the quality of the current production. I'm a perfectionist which definitely slows down my actual video production. It has really amazed me that the quick videos that I put out get so much traction. Some of the videos that I actually edit take weeks. When I hit 20000 subscribers I intend on starting up daily or by daily videos, these videos will definitely not have the ridiculous level of production value that I currently have but they will be current and about topics that are relevant or that I feel you guys would like.
@peterRobinson10101
@peterRobinson10101 4 ай бұрын
Further to the security concerns now... We dont know what tech will be available as more resources become devoted to blockchain and we speed toward more quantum like equip. Those who have evaded LE now with $ laundering and XMR etc all these transactions may one day be far more mapable than they are today... Now will it impact the little guy gettjng a dime bag sent to Nanas post box? probably not... but those big accounts with multi million dollar transactions will FOREVER be the target of LE mapping. So a Succesful 7figure DNV should never expect to retire in the USA or any country with a US extradition treaty.
@murasaki-dayo
@murasaki-dayo 4 ай бұрын
type shi bruh noone wan take a risk like that
@ifrozenphoenix-real
@ifrozenphoenix-real 4 ай бұрын
Yeah I remember when he blocked u.The reason was u posted a screenshot of someones post that later added "DarkWebInformer can't read" 😂😂😂.
@dohboi6987
@dohboi6987 4 ай бұрын
Found your channel a couple months ago. Really enjoy your calm, strait-on reporting style. No Hype. I have a question about something in this video: @ the 5 mins mark, some text appeared on the screen. Name, Register number, etc.... Is this info related to the channel name? Did you get released from a federal bit in the past? Just curious if these things are all related. Also, does the gvt. force you to add that stuff b/c of release conditions or some sh!t? _Peace
@murasaki-dayo
@murasaki-dayo 4 ай бұрын
bruh what nah that's the Silk Road creator's info lol
@dohboi6987
@dohboi6987 4 ай бұрын
@@murasaki-dayo ahhhh kk got it =/
@Sam_Bent
@Sam_Bent 4 ай бұрын
kzbin.info/www/bejne/hHjMhpugqqdlaLs
@dohboi6987
@dohboi6987 4 ай бұрын
@@Sam_Bent Thx 4 the link. Great talk & bio. _Peace
@terbospeed
@terbospeed 4 ай бұрын
When the OP in opsec means Optional
@blinking_dodo
@blinking_dodo 4 ай бұрын
I saw the post earlier today. That was some terribly bad security! I personally hosted darknet sites *more* secure than this... (nothing illegal)
@ChrisHaefner
@ChrisHaefner 4 ай бұрын
Thanks for the news sam!
@Sam_Bent
@Sam_Bent 4 ай бұрын
Hi chris, it's great to see you in the comments section again! I hope all has been well with you and yours.
@davegebbings7632
@davegebbings7632 4 ай бұрын
Another interesting episode. Thanks Sam. We have been getting a lot of shorts lately I like them.
@joshuagold809
@joshuagold809 4 ай бұрын
You make the best content. Excellent, informative video
@Sam_Bent
@Sam_Bent 4 ай бұрын
Thank you! I appreciate you taking the time to comment.
@rysiekzradomia
@rysiekzradomia 4 ай бұрын
Great video as always, greetings from Poland
@gta6traileroutbutwaitto2025...
@gta6traileroutbutwaitto2025... 4 ай бұрын
greetings from the 4th dimension Poland
@InMoneroWeTrust
@InMoneroWeTrust 4 ай бұрын
@@gta6traileroutbutwaitto2025... Greeting from Latveria
@BladeMaster69420
@BladeMaster69420 4 ай бұрын
These people make my opsec look godlike by comparison.
@InMoneroWeTrust
@InMoneroWeTrust 4 ай бұрын
Thats what i call “dollar store OpSec” lol
@umutzd
@umutzd 4 ай бұрын
So is this a US hosting provider? That ip address seem to be from US
@Sam_Bent
@Sam_Bent 4 ай бұрын
Appears to be so.
@peterRobinson10101
@peterRobinson10101 4 ай бұрын
Such a good video! Im glad I dont know how to make a DNM.. kinda thing I would do while drunk and then be messing my pants the rest of my life. Pretty sure you could find a prefab DIY DNM kit somewhere😂 Mmm safe! (BlackMarket PRELoaded!) Actually I am surprised the LE dont package one up for drunk kiddies to instal... would help keep them in a job.
@NeverGiveUpYo
@NeverGiveUpYo 4 ай бұрын
Maybe it's a bait gone wrong.
@ret2libc0x90
@ret2libc0x90 4 ай бұрын
It's probably some dude in a desert some place that nobody is going to go to to arrest them lol.
@MorningStarChrist
@MorningStarChrist 4 ай бұрын
the ip should be secure even if the machine is compromised.
@Sam_Bent
@Sam_Bent 4 ай бұрын
It's been awhile! It's great to see you in the comments section again!
@MorningStarChrist
@MorningStarChrist 4 ай бұрын
@@Sam_Bent I disappear every so often
@inkybz
@inkybz 4 ай бұрын
ah yes preamp with the sm7b, is it the sm7db? even with that one you have to really mouth it, and you've got great audio at a distance, great room sound its totally dead sorry i just love great sounding audio
@inkybz
@inkybz 4 ай бұрын
i've got an akg c214 with a focusrite isa one preamp connected to an SSL2+ audio interface, i'm using a balanced line cable from my isa one to my ssl and i get 0 noise, I just use it in a living room and it only sounds great when the ac is off, and springs over lol
@inkybz
@inkybz 4 ай бұрын
and a dialed in gate is awesome, i have a whole voicemeeter potato set up that gives me a 0db limiter and a gate, there's a compressor in there (its shitty so i dont use it, and i have it set up for going on discord most of the time anyways), but for live audio recording i would patch it through ableton and use my vsts for that (fabfilter, waves, de-esser, parallel comp, etc..)
@Sam_Bent
@Sam_Bent 4 ай бұрын
I totally cheated. I have teh Shure MVX2u XLR - TO - USB adapter (has a integrated preamp with 16 decibel gain control, 0 latency monitoring, and 48 volt phantom power. To my sm7db. I have the input feeding into nvidia broadcast, which has noise removal built into it which is kind of like in my novice mind like a smart noise gate. From there it goes to my MOTIV Mix app. I am an absolute neophyte at audio. I still do a lot of post production with the audio things like breath sounds and whatnot.
@Sam_Bent
@Sam_Bent 4 ай бұрын
This is like chinese to me. I'm a complete neophyte when it comes to audio engineering.
@jordanskidmore6337
@jordanskidmore6337 4 ай бұрын
Is there a way to spoof this info? Maybe they don’t run on what it says, maybe it’s a double bluff and the opsec is better than average? 🙈 wishful thinking maybe 😂✌️
@mx338
@mx338 4 ай бұрын
There's no reason why you would spoof this header information, instead of just hiding it. It is most certainly automatically generated, even though it could easily be overwritten.
@Usmc913
@Usmc913 4 ай бұрын
Yes it's possible but there's no reason to do it. You would want it completely hidden. I guess they could do it just for shits and giggles but that's giving them too much credit.
@murasaki-dayo
@murasaki-dayo 4 ай бұрын
too much work bruh why make it spoof it and make it public? i aint tryna be on my desk for 1 week straight tf
@MinePossu
@MinePossu 4 ай бұрын
​@@mx338 Something like this lol HTTP/1.1 200 OK Server: TempleOS 5.03 X-Powered-By: HolyC
@kuukeli
@kuukeli 4 ай бұрын
thank you for video
@dvsur
@dvsur 4 ай бұрын
Empire Market, Incognito Market
@bigpanda6787
@bigpanda6787 4 ай бұрын
Are u a cop? No seriously. Lol. I’m glad these guys keep on choochin and not conforming. These guys are champs. Anything is possible
@tonysolar284
@tonysolar284 4 ай бұрын
I'm going to build a darknet market for my Army of AI Furbys. The government wont like me when my Army hacks their network. 😏
@omarjokr1153
@omarjokr1153 4 ай бұрын
what is the mistake that this guy take to expose the server ip address ? ( technicaly )
@Aera223
@Aera223 4 ай бұрын
Likely port forwarding the IP or directly connected to the wider network (not using a modem, or having a modem set to DMZ mode)
@omarjokr1153
@omarjokr1153 4 ай бұрын
the ip address is leaked through the response heders or what ? , or the person who set up this hidden service makes it available on the internet ( via port forwarding or somthing ) and someone accedently find it on the clear net . is that right ?
@topcatcoast2coast579
@topcatcoast2coast579 4 ай бұрын
I love how he has a still right behind him. 12 cents an hour!!! Even a table whisper, literally just runs a towel over tables at chow, would get 40 cents in Pennsylvania State Prison. Library or tutor, that's where the money is 1.40 an hour wooooo.
@williamcullen4035
@williamcullen4035 4 ай бұрын
tyvm
@Sam_Bent
@Sam_Bent 4 ай бұрын
Thank you for supporting the channel by taking the time to comment!
@EvansEkene
@EvansEkene 4 ай бұрын
What's the best private browser and VPN or Suckz to you for maximum security?
@koba2160
@koba2160 4 ай бұрын
Vpn provides no security, but mullvad is best Tor for security, byt for every day use ff
@DarknetDiscussions
@DarknetDiscussions 4 ай бұрын
DANG .....
@veganlsd1577
@veganlsd1577 4 ай бұрын
you need more than a few evening classes to make a DNM ... lol
@Sephsa
@Sephsa 4 ай бұрын
Seems like a honey pot
@Waldo-Manfred
@Waldo-Manfred 4 ай бұрын
you really calling twitter X bro?
@iamwitchergeraltofrivia9670
@iamwitchergeraltofrivia9670 4 ай бұрын
Hahahahh trash Security windows
@Sam_Bent
@Sam_Bent 4 ай бұрын
Agreed!
@Deductive
@Deductive 4 ай бұрын
You said you posted it on dread and pitch, but the explanation you followed after that, the "why" doesn't make much sense. I don't care nor is it in my interest, but it sounds to me more like you were after clout chasing than you wanting to help either individuals or the law inforcement.
@Sam_Bent
@Sam_Bent 4 ай бұрын
Is it really that hard to grasp that warning people about insecure markets is beneficial? Would you prefer these vulnerabilities go unnoticed, putting users at risk? Labeling my efforts as 'clout chasing' ignores the years I've spent educating on OpSec. According to your logic, any informational video would be clout chasing. The information I shared was already public knowledge. If you don't understand, perhaps you need to look deeper into the topic.
@Deductive
@Deductive 4 ай бұрын
​@@Sam_Bent, Perhaps, I wouldn't know your past history nor have any context, maybe it was never about clout chasing, but that section of the video to me seemed reasonably weak, but perhaps it was just explained poorly (as it seemed to me). (I am referring to the part of the video at 5:30 where you proceed to explain *why* you publicisized this information in these forums upon finding out)
@Sam_Bent
@Sam_Bent 4 ай бұрын
@@Deductive And that's the issue. It's telling that you admit to not knowing my past work or the context, yet feel confident critiquing a section of the video. This lack of understanding is exactly why your judgment is flawed. My channel has a long history of covering OpSec and darknet vulnerabilities, and this isn't the first time I've exposed such issues for the community's safety. At 5:30, I explained the necessity of sharing this information on Dread and Pitch to alert those directly affected. This isn't about clout but about preventing serious risks for users and admins. Your inability to grasp this due to your admitted lack of context shows a fundamental misunderstanding of the landscape we're discussing. If you're genuinely interested in understanding, I'd suggest watching my previous videos or even doing a simple search to get up to speed. Criticizing without context is not just unhelpful; it's frankly shortsighted. Thank you for clarifying and for being honest, about your full understanding. My history and background are probably best presented in my Defcon 30 talk on Darknet OpSec.
@Deductive
@Deductive 4 ай бұрын
@@Sam_Bent thank you for your response. It wasn't in my interest to critisize, rather wonder or highlight the poor justification given in that section. Hey, it would be the last of my interests to misinterpret or diminish your work and efforts in your said goals and youtube career. Rather, I meant to point out that without given any further context (say a new viewer like me) those few justification sentences came out off. Is this a nitpick? Probably, I just watched the video and had the typical reaction "What is lad trying to say here?" in that part and left the appropriate comment. Cheers.
@cody_raves
@cody_raves 4 ай бұрын
Don’t make dark net markets. I understand the point but you shouldn’t out right tell people to make markets lol
@murasaki-dayo
@murasaki-dayo 4 ай бұрын
when he say that bruh
@RT-.
@RT-. 4 ай бұрын
He said that if you have the skill to make something like this, then you should do it for legitimate, clear net, markets
@Sam_Bent
@Sam_Bent 4 ай бұрын
With that! In the video I said that people shouldn't create darknet markets because of the inherent risk associated with them. Also it's great to see you in the comments section cody! Been doing well, I haven't seen you in the comment section lately.
Archetyp - Darknet Drugmarket Analysis
1:00:58
Sam Bent
Рет қаралды 52 М.
When u fight over the armrest
00:41
Adam W
Рет қаралды 31 МЛН
Twin Telepathy Challenge!
00:23
Stokes Twins
Рет қаралды 98 МЛН
Empire Darknet Drug Market Admin Gets Busted
16:23
Sam Bent
Рет қаралды 16 М.
How Hackers Bypass Kernel Anti Cheat
19:38
Ryscu
Рет қаралды 779 М.
STOP Making These 10 CRUCIAL Mistakes On The Dark Web
16:01
I Downloaded Games Off The Dark Web.. (actually)
14:29
Tranium
Рет қаралды 505 М.
SSH IP Spoofing Attack on Tor
13:37
Sam Bent
Рет қаралды 10 М.
The Darknet Market OPSEC Bible 2023 Edition
29:58
Mental Outlaw
Рет қаралды 372 М.
WE EXPLORED THE DARK WEB [INSTANT REGRET]
1:01:30
Trilogy Media
Рет қаралды 2 МЛН
When u fight over the armrest
00:41
Adam W
Рет қаралды 31 МЛН