I Hacked & Exposed This Fake Website for Educational Purposes - CTF

  Рет қаралды 168,121

thehackerish

thehackerish

Күн бұрын

Пікірлер: 227
@5374seth
@5374seth Жыл бұрын
Takeaway: don’t upload your evil incriminating journal to your company’s public web server
@Artemyst
@Artemyst Жыл бұрын
Why upload it at all? Pen and paper would protect a lot of companies getting evil shit only 1 or 2 people at the top should know about from coming out
@vatsaljoshi5788
@vatsaljoshi5788 5 ай бұрын
M.x lostyckwi have smeeyny
@akatsukilevi
@akatsukilevi Жыл бұрын
Not bad! Just next time put a disclaimer at the start of the video saying that it is a actual CTF challenge Might help people who aren't knowledgeful into CTF's or platforms like root-me to get to know them!
@antonaparin
@antonaparin Жыл бұрын
=clickbait
@onidaaitsubasa4177
@onidaaitsubasa4177 Жыл бұрын
What's really disturbing is that there actually might actually be a real reasearch company that does questionable testing like this on people somewhere out there, it's good they have these simulation websites to test your hacking and programming skills.
@mikymuky1171
@mikymuky1171 Жыл бұрын
I was literally just binging a tv series called Fringe. What a great coincidence! Great series
@user-ge7ep5sc2d
@user-ge7ep5sc2d Жыл бұрын
​@trackme3621and you lack the ability to read
@mikymuky1171
@mikymuky1171 Жыл бұрын
@trackme3621 r/whoosh
@ok-tr1nw
@ok-tr1nw Жыл бұрын
Mkultra
@comstate
@comstate Жыл бұрын
Its a ctf examination its not a real website it's just a example of how hackers can show the truth and test your skills.
@jerrymartin7019
@jerrymartin7019 Жыл бұрын
Always love the little lore tidbits ctf makers include in their challenges
@victorstegmaier7572
@victorstegmaier7572 Жыл бұрын
You sure you haven't hacked accidentally the source code of Fallout 5? That sounds like some Vault-Tec horror story... 😂
@thehackerish
@thehackerish Жыл бұрын
😂😂😂
@filtztr
@filtztr Жыл бұрын
i had a stroke reading that and fucking died
@collectorXVIII
@collectorXVIII Жыл бұрын
The real question is how does he know its evil?
@shouvikkundu8289
@shouvikkundu8289 Жыл бұрын
It's a ctf challenge bro
@jrapp654
@jrapp654 Жыл бұрын
He’s joking bro
@pitpot2
@pitpot2 Жыл бұрын
its very clearly an evil website
@pegtade
@pegtade Жыл бұрын
Its not a real site, well it is but its made for hackers to hack.
@hidden_network
@hidden_network Жыл бұрын
The website was created by him .. just a demo
@MaxWis
@MaxWis Жыл бұрын
I wish they did this as security lesson on my uni. just one day of doing this just to get a feel for it and learn how to protect against these attacks
@Sparkette
@Sparkette Жыл бұрын
I think "might go to jail" is more accurate. It's not a guarantee; people do get away with it sometimes.
@thehackerish
@thehackerish Жыл бұрын
Better safe than sorry 😉
@aiexzs
@aiexzs Жыл бұрын
@@thehackerish 😉
@hermanbenstreng
@hermanbenstreng Жыл бұрын
most of the times xd
@vedantkanoujia
@vedantkanoujia Жыл бұрын
I love how you fool people's while playing ctf & adding *STORY* to it like cherry on cake
@flatiialt-kx4fo
@flatiialt-kx4fo Жыл бұрын
" " *
@chri-k
@chri-k Жыл бұрын
People seem to click before they read, so moving "CTF" closer to the front (or shortening the title in general, or putting it in the thumbnail) may help with the clickbait accusations. It may also be getting cut off in some places ( i don't know though )
@Mahatah
@Mahatah Жыл бұрын
This directory traversal, to log poisoning, to RCE revshell is very well presented. Also, there are clearly some really interesting command aliases used in this video. If we ask nicely, could we see a few that you have? I noticed "nmapq" and "revshell" in the video.
@thehackerish
@thehackerish Жыл бұрын
Sure, I will share them in future videos
@leafofyume7838
@leafofyume7838 Жыл бұрын
wow rly didint think it would be so easy to hack a website that has close to none security implementations. scary
@rodricbr
@rodricbr Жыл бұрын
very nice little easy ctf. I think I'ma go back into doing them, you've inspired me
@thehackerish
@thehackerish Жыл бұрын
Have fun!
@hartpa
@hartpa Жыл бұрын
I don't understand a second of this but respect that you share it.
@Owl69699
@Owl69699 Жыл бұрын
Bro made this video like im watching a horror movie and i absolutely love it!! \
@thehackerish
@thehackerish Жыл бұрын
Glad you liked it!
@NatureSoulHarmony
@NatureSoulHarmony Жыл бұрын
This series is awesome keep up
@ultralaggerREV1
@ultralaggerREV1 Жыл бұрын
The FBI is definitely watching us
@itsmmdoha
@itsmmdoha Жыл бұрын
I love these videos, please keep making these!
@ClashWithHuzefa
@ClashWithHuzefa Жыл бұрын
Man, this hacking looks so difficult. I want to learn like you 😭😭
@noobidubi8137
@noobidubi8137 Жыл бұрын
If you wanna learn try "hack the box academy"
@justincase5228
@justincase5228 Жыл бұрын
I had a friend working in I.T. at a college in Wales and we were talking on the phone. I asked if he thought his system was secure and of course, he's talking shit. So while we were talking I was hacking their website in real time and then email'd him the contents of one of the server's logs. :evil laugh:
@muneeburrehman547
@muneeburrehman547 Жыл бұрын
😂😂😂
@justinmorales4635
@justinmorales4635 4 ай бұрын
Can you check a website and see what you can see on it. It’s a scammers fake website that he uses to scam people
@TheOverkillSociety
@TheOverkillSociety Жыл бұрын
Damn, this sounds like something straight out of Resident Evil.
@happyboom-
@happyboom- Жыл бұрын
great video. I would fully prepare for youtube to take it down though. So please let us know about any community resources you host :) subscribed!
@MayorMcBluntz
@MayorMcBluntz Жыл бұрын
its a CTF would probably be considered to be educational and not malicious since the site is for this purpose.
@Gray3ther
@Gray3ther Жыл бұрын
Very instructive, as always. Thanx hackerish! ❤
@thehackerish
@thehackerish Жыл бұрын
My pleasure!
@pitpot2
@pitpot2 Жыл бұрын
love your videos! hope you get more traction soon because your channel is very underrated :)
@thehackerish
@thehackerish Жыл бұрын
Thank you so much! Share it with your peers
@md.mahadi1
@md.mahadi1 Жыл бұрын
Very nice. Please make a video with java/nodejs website
@glaszn
@glaszn Жыл бұрын
amazing act m8 ... really good and very educational
@BomMeldingYT
@BomMeldingYT Жыл бұрын
I keep on learning stuff, thanks
@ButterflyAdminOfAuth
@ButterflyAdminOfAuth Жыл бұрын
Btw Your CTF was Great I learned A lotcz I used same payload on HTB clicker machine but I faile now I know what to do
@amin7581
@amin7581 Жыл бұрын
Oh my. This is definitely scary. I can't believe there are company hidden in the world would do this. As a professional website clicker, I can tell you, this is definitely and totally not a dummy site. Very scary indeed.
@harryhack91
@harryhack91 Жыл бұрын
That journal at the end looked like an SCP
@Tommi-C
@Tommi-C Жыл бұрын
You had me there for 11 min and 15 seconds 😉😉
@franceconi
@franceconi Жыл бұрын
Excellent work!! Thanks for sharing.
@thehackerish
@thehackerish Жыл бұрын
Thank you! Cheers!
@SSS333-AAA
@SSS333-AAA Жыл бұрын
i'm so damn confused. enchantment table is something i never learned.
@thetechdudemc
@thetechdudemc Жыл бұрын
The etc/sudoers file properly set up would have prevented the escalation to root right?
@thehackerish
@thehackerish Жыл бұрын
Yep, correct
@Mr.Equinox
@Mr.Equinox Жыл бұрын
Finally! Log poisoning 😁
@beast-chan
@beast-chan Жыл бұрын
i robbed a bank and stole 2M$ for educational purposes 🤣
@amongusboi2032
@amongusboi2032 Жыл бұрын
Sounds like chaos insurgency hacker hacking into one of scp foundations websites. Welcome to the splinter group, cyber security dude. 😂😂😂
@sifuhotman8595
@sifuhotman8595 Жыл бұрын
Clickbait Successful. 😂
@deadman746
@deadman746 Жыл бұрын
I know someone who hacked into a rape ring. He got more prison time than the rapists.
@turbo_marc
@turbo_marc Жыл бұрын
The hacker shouldn't have gotten any prison time. Absolutely ridiculous.
@Bartyron
@Bartyron Жыл бұрын
very entertaining!
@davin2002
@davin2002 Жыл бұрын
so there was no ssl key, so what was the use of the private key ? , then why post stuff on a webserver, i don't understand the security of this site
@dreamaker2107
@dreamaker2107 Жыл бұрын
What program are you using at the digging part?
@thehackerish
@thehackerish Жыл бұрын
Web proxy: burpsuite, terminal: Ubuntu
@Patel_jishan
@Patel_jishan Жыл бұрын
Hii sir please please give a fuxsocy details video
@silkroad780
@silkroad780 10 ай бұрын
Thank you , but if the website outside you Lan network , you do the same ?
@thehackerish
@thehackerish 9 ай бұрын
if it's accessible through internet, yes
@michaeltaylor8835
@michaeltaylor8835 Жыл бұрын
Good job
@Faeest
@Faeest Жыл бұрын
what app you use to digging in? some kinda postman but it's not postman. what was that?
@thehackerish
@thehackerish Жыл бұрын
Burpsuite, or zaproxy works as well
@paolomontelbano
@paolomontelbano Жыл бұрын
This is just a ctf.. why are you making it sound as if this is a real site in the title?
@taronnersisyan9612
@taronnersisyan9612 Жыл бұрын
Dude noone is gonna post something unethical in KZbin
@artificialviews
@artificialviews 8 күн бұрын
what proxy inspector dashboard is that?
@dereklee2590
@dereklee2590 Жыл бұрын
How do hack website that is doing illegal activity also the users doing illegal activity
@RenderBenderProductions
@RenderBenderProductions Жыл бұрын
What is the rpogram hat you use in this video?
@thehackerish
@thehackerish 11 ай бұрын
Just aliases around Nmap and wfuzz
@justarandomcat7
@justarandomcat7 Жыл бұрын
🔵 The Hackerish is the best 👏
@mebmeamarketing7094
@mebmeamarketing7094 Жыл бұрын
Not understand fully but I enjoy every time. With seen of earning. But I not understand every time. What is money. Why people always money only. Why they do not work for reality. Why they don't need simple ways. Why people going in trouble trouble and troublings..... 🎉 Enjoy your money. But Please take care yourself and poors. You you all. ALLAH BLESS US AAMEEN ❤
@shareb1t
@shareb1t Жыл бұрын
Disclaimer: Never put click bait such as video without permission from your viewers otherwise you might go actually you will be banned and forgotten
@thehackerish
@thehackerish Жыл бұрын
Well heard, what do you suggest as a title?
@AliAbbasi-j5i
@AliAbbasi-j5i 11 ай бұрын
can you hack a scammer website who take money from people's by fraud .. reply if you can i will share you link.
@SujjtaLopchan
@SujjtaLopchan 7 ай бұрын
Brother i am in huge trouble i need your help plz help me
@rgtechyt9267
@rgtechyt9267 Жыл бұрын
Which operation system are you using bro please reply
@W_Rizz.
@W_Rizz. Жыл бұрын
Kali Linux I assume
@thehackerish
@thehackerish Жыл бұрын
Ubuntu running on windows wsl
@thekillercrum
@thekillercrum Жыл бұрын
sick project
@nolannono31
@nolannono31 Жыл бұрын
what happen if someone go to the url of the website
@lel0uchfr199
@lel0uchfr199 Жыл бұрын
what's the name of the tool to fetch data (with GET etc...) ?
@thehackerish
@thehackerish Жыл бұрын
Curl and Burpsuite
@ewancadmore3592
@ewancadmore3592 Жыл бұрын
what are the names of those windows he's using to execute code?
@W_Rizz.
@W_Rizz. Жыл бұрын
Terminal
@legend7066
@legend7066 7 ай бұрын
what is nmapq?
@khalnayakgamer6607
@khalnayakgamer6607 Жыл бұрын
1st yr 😌
@MasterHacker...
@MasterHacker... Жыл бұрын
1דא
@itwasntme947
@itwasntme947 Жыл бұрын
I am root
@naptimusnapolyus1227
@naptimusnapolyus1227 Жыл бұрын
Delightful. 🎩 ☕🗿
@MikeRegan-z3v
@MikeRegan-z3v Жыл бұрын
Sir good day to you l was watching your videos but l should like to ask about a certain app which l don't know if it's real or fake app
@MikeRegan-z3v
@MikeRegan-z3v Жыл бұрын
He research l made almost people are saying that it's working but honestly speaking according to you hackers you can tell us the truth
@MikeRegan-z3v
@MikeRegan-z3v Жыл бұрын
So how can l reach on you or how can l contact you and l give you full details sir, l will be glad to hear from you
@thehackerish
@thehackerish Жыл бұрын
You can dm me on Twitter
@MikeRegan-z3v
@MikeRegan-z3v Жыл бұрын
But guy why do you always send us to contact you through Twitter, Instagram, Telegram why do you give us direct numbers or contacts to reach up on you
@PythVR2
@PythVR2 Жыл бұрын
when you put educational purposes at the end of the law the just ignore what your doing.
@thehackerish
@thehackerish Жыл бұрын
Not just that, the website itself is for educational purposes only 😉
@0RIPPER0
@0RIPPER0 Жыл бұрын
Dyaumn man !
@stormgaminggg
@stormgaminggg Жыл бұрын
so you can basicaly install a virus and run it using this to destroy the server?
@thehackerish
@thehackerish Жыл бұрын
Yeah, once root, you can do pretty much all you want. But in penetration tests, you always take your customer's data and availability into account
@SomeDudeCauseYes
@SomeDudeCauseYes Жыл бұрын
twist: he hacked a evil site, create but remove security, then do a educational vid on it. (Joke btw)
@ghost_ship_supreme
@ghost_ship_supreme Жыл бұрын
5:40 wait… what did he do here?
@e.v.a.l.s
@e.v.a.l.s Жыл бұрын
i dnot get it
@Vurkman
@Vurkman Жыл бұрын
can u do it on a virtual box?
@thehackerish
@thehackerish Жыл бұрын
Yes, from vulnhub.com
@OligoST
@OligoST Жыл бұрын
Spooky story
@deatheternal720
@deatheternal720 Жыл бұрын
why are you recording in 2 fps
@holl7w
@holl7w Жыл бұрын
The video is not in 2 fps
@gocciolabtw
@gocciolabtw Жыл бұрын
0:13 then why are you doing it 💀
@0xdt0x
@0xdt0x Жыл бұрын
Is this genuine data of them... or you just crafted iy yourself, i mean the experiment sounds russian
@thehackerish
@thehackerish Жыл бұрын
No, this is a capture the flag designed to test hacking skills, and has a story behind
@harrymakongwa1147
@harrymakongwa1147 Жыл бұрын
How do you know what you know ..
@thehackerish
@thehackerish Жыл бұрын
Everything is available online to self-learn
@yusufermanto1540
@yusufermanto1540 Жыл бұрын
is the life expectancy gonna be Pay To Win? i prefer Free To Play
@GrumpyGillsFishing
@GrumpyGillsFishing Жыл бұрын
Beautiful lab 😂 I love it
@jimschips254
@jimschips254 Жыл бұрын
Pro tip: this vid smacks in 1.25x speed
@alexjames1575
@alexjames1575 Ай бұрын
Hey 👋 I want to talk with you in private conversation
@Steve-xb7dn
@Steve-xb7dn Жыл бұрын
this stuff is years old.....
@mikehunthunt8269
@mikehunthunt8269 Жыл бұрын
You have your own ip 😔
@devviz
@devviz Жыл бұрын
who tf encode experiment logs in a flag.png file?! ridiculous, unrealistic
@thehackerish
@thehackerish Жыл бұрын
It's a ctf
@IBadAtEditing
@IBadAtEditing Жыл бұрын
POV you don’t understand that even in unrealistic CTF’s, you can learn a thing or two to apply to real world scenarios 🤯🤯🤯🤯
@traida111
@traida111 Жыл бұрын
I believe you already hacked it, then repeated the steps again while recording. I mean, in this type of thing its how to make good content. well done
@johndavemontalvo7236
@johndavemontalvo7236 7 ай бұрын
naay kahibaw mu hack dri cebu? willing to pay
@codename_ghost1676
@codename_ghost1676 Жыл бұрын
PLEASE TELL ME THIS IS SATIRE
@lpsfairylightz6468
@lpsfairylightz6468 Жыл бұрын
LOLL IM STUPJD IDK ANYTHING ABOUT CODE AND I WAS LIKE ILL WATCH GHIS IT LOOKS COOL I THOUGHT IT WAS REAL AND THEN THE REVEAL STARTED AND I WAS LIKE 💔💔💔
@purple-47
@purple-47 Жыл бұрын
5:23 is that your IP?
@thehackerish
@thehackerish Жыл бұрын
Nice catch, vpn
@purple-47
@purple-47 Жыл бұрын
thanks.@@thehackerish
@alexgamingyt-cj1bf
@alexgamingyt-cj1bf Жыл бұрын
hello fbi watchlist!
@iskrassupercoolchannel
@iskrassupercoolchannel Жыл бұрын
hi
@bepisenjoyer
@bepisenjoyer Жыл бұрын
omething has gone wron
@z3r0c00l2
@z3r0c00l2 Жыл бұрын
Fake
@tilde00
@tilde00 8 ай бұрын
its a ctf walkthrough LMAOOOOO
@Biejoy666
@Biejoy666 Жыл бұрын
And don't be evil again okay😊
@ImDuck42
@ImDuck42 Жыл бұрын
can you hack discord servers and give everyone free Nitro ? (for educational purposes of course)
@thehackerish
@thehackerish Жыл бұрын
Haha, unfortunately no. It's unethical
@Lynixity
@Lynixity Жыл бұрын
it is lel >:)))))@@thehackerish
@realPikachu1p
@realPikachu1p Жыл бұрын
Ngl a link name like that already screams scam lol
@alvaromoe
@alvaromoe Жыл бұрын
Discalimer
@vitorstreetboys
@vitorstreetboys Жыл бұрын
hahahaha
@wereisaly
@wereisaly Жыл бұрын
Lmao just hack any website and say its for “educational purposes“ problem solved
@thehackerish
@thehackerish Жыл бұрын
It's not just any website, I don't hack things I am not authorized to
@Kwijtamine
@Kwijtamine Жыл бұрын
bruh
1, 2, 3, 4, 5, 6, 7, 8, 9 🙈⚽️
00:46
Celine Dept
Рет қаралды 114 МЛН
風船をキャッチしろ!🎈 Balloon catch Challenges
00:57
はじめしゃちょー(hajime)
Рет қаралды 97 МЛН
МЕНЯ УКУСИЛ ПАУК #shorts
00:23
Паша Осадчий
Рет қаралды 5 МЛН
How to Crack Software (Reverse Engineering)
16:16
Eric Parker
Рет қаралды 716 М.
I legally defaced this website.
25:48
thehackerish
Рет қаралды 527 М.
Using My Python Skills To Punish Credit Card Scammers
7:13
Engineer Man
Рет қаралды 4,9 МЛН
I used AI to hack this website...
23:23
Tech Raj
Рет қаралды 132 М.
How to not get hacked: real example
13:55
The PC Security Channel
Рет қаралды 420 М.
Can I Hack This? InfluxDB Hacking and Docker Escape
14:26
thehackerish
Рет қаралды 3,7 М.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
John Hammond
Рет қаралды 741 М.
1, 2, 3, 4, 5, 6, 7, 8, 9 🙈⚽️
00:46
Celine Dept
Рет қаралды 114 МЛН