I Vulnerability Scanned The Entire Internet And Accidentally Made A Botnet

  Рет қаралды 101,293

Marcus Hutchins

Marcus Hutchins

Күн бұрын

Пікірлер: 286
@dooorrr
@dooorrr 2 ай бұрын
inb4 FBI on Marcus again
@archersterling4044
@archersterling4044 2 ай бұрын
Surely a lot of people in blue will think what he did here was illegal hurr hurr you made my computer send a request Is not an ideal situation to be in
@dooorrr
@dooorrr 2 ай бұрын
@@archersterling4044 Well, in this particular example it was done in more of a white hat manner but I guess if they really wanted they could make up some convoluted reasoning how it was illegal because muh exploit abuse and such
@sangeetguha51
@sangeetguha51 2 ай бұрын
Lol
@Jorn-sy6ho
@Jorn-sy6ho 2 ай бұрын
JA! Je hoopt dat de FBI meekijkt
@UNcommonSenseAUS
@UNcommonSenseAUS 2 ай бұрын
Bro too cool to just shodan
@graemepennell
@graemepennell 2 ай бұрын
News soon leaks "Kremlin printers suddenly start auto printing".....
@PvtAnonymous
@PvtAnonymous 2 ай бұрын
well, that's why Runet was created, so that this doesn't happen.
@w花b
@w花b Ай бұрын
​@@PvtAnonymouswhat's that
@PvtAnonymous
@PvtAnonymous Ай бұрын
@@w花b it's basically the "Great Firewall" Lite edition. A compilation of apps, services and websites that are supposed to create a sovereign Russian internet that doesn't rely on outside services. That even includes their own root certificates. Many government services or banks won't work outside of Russia even today. Or their access will be very limited (like streaming platforms). That also means, that outsiders can't really do as much anymore since CIDRs outside of Russia will be dropped by default.
@Ephicx
@Ephicx Ай бұрын
@@PvtAnonymous It also has the added "benefit" of russian government being able to decrypt any and all russian traffic using those certificates because they hold the keys. You know, for security reasons...
@PvtAnonymous
@PvtAnonymous Ай бұрын
@@Ephicx yup, that's part of the problem. It goes both ways: they can also take control of domestic services and harvest all the data they need since they don't need to ask foreign companies anymore. It's both a blessing and a curse.
@mad_mario_
@mad_mario_ 2 ай бұрын
Hope ppl in charge will hear your call, thanks for your service brother ❤
@DeviantOllam
@DeviantOllam 2 ай бұрын
Wow, this certainly is a leg up on the old "change the text string displayed on the HP printer" attack ☺️
@chilversc
@chilversc 2 ай бұрын
Ah, I do miss the number of times our college printers would declare themselves to be out of crayons or were having some form of existential crisis.
@shivkokroo6180
@shivkokroo6180 Ай бұрын
Link? Can't find a reference.
@chilversc
@chilversc Ай бұрын
@@shivkokroo6180 used to be (back 2000/2001 at least) there was a utility to change the status display on HP printers, no authentication required.
@bootha-qv4je
@bootha-qv4je Ай бұрын
​@@shivkokroo6180same question here, I wanna make my own printer says one fuckshit lmao
@CherryKayla
@CherryKayla Ай бұрын
Holy shit its the guy!!!!
@ehsnils
@ehsnils 2 ай бұрын
Next up: "I accidentally messed up the entire internet using fake BGP requests"
@alfonzo7822
@alfonzo7822 2 ай бұрын
That's something I'm trying to learn more about. So many rabbit holes so little time!
@warlordkeys
@warlordkeys Ай бұрын
you are a menace
@crissuper20
@crissuper20 Ай бұрын
Im sure, one day, a random Networking guy at a telecom would do that
@lotarion
@lotarion Ай бұрын
@@crissuper20 it has happened a couple times already, something tells me it can happen again
@michaelm1
@michaelm1 2 ай бұрын
My server has seen more than 50 recent attempts to connect to CUPS port. This is now being exploited. Anyone who has not secured their systems is probably compromised by now.
@MalwareTechBlog
@MalwareTechBlog 2 ай бұрын
So far I've only caught scanners in my honeypot, but I'm certain there is active exploitation happening. I'm not listed on Shodan, so I'm only seen attempts that scan the entire internet rather than targeting known CUPS servers.
@D.von.N
@D.von.N Ай бұрын
Linux got CUPS patched up very soon after this came out, people just must not ignore the prompts for updates. On my MS system I print via a cable, the printer sitting next to me. I know what it is called so printing only there. And since keyboards and mouses (mice?) Can also be hacked wirelessly, considering going back to a wired mouse. Keyboard already is. Wireless one behaved strangely on Excel from time to time.
@kirill9064
@kirill9064 Ай бұрын
@@D.von.N You mean someone broadcasts signal, sends🪟+R, and sends malicious comand?
@shaggy6249
@shaggy6249 Ай бұрын
Can’t wait for the “I accidentally turned off the internet” video, keep up the good work Marcus!
@gehirndoper
@gehirndoper Ай бұрын
If it cameyou would have to wait anyway, given no internet.
@pidojaspdpaidipashdisao572
@pidojaspdpaidipashdisao572 Ай бұрын
I always knew that that bloody printer will be the end of me.
@sravanmathangi
@sravanmathangi Ай бұрын
😂😂
@Google_Does_Evil_Now
@Google_Does_Evil_Now 2 ай бұрын
You're a very good teacher. Easy to follow what you're saying. Wonder why the default isn't setup tighter. 0.0.0.0 is full open door. Amazing.
@patchshorts
@patchshorts Ай бұрын
that just means it listens on all network interfaces, he also didn't accidentally make a botnet either
@Griimnak
@Griimnak Ай бұрын
I learned something today because I always thought 0.0.0.0 isn't much different from 127.0.0.1. I just never thought into it much
@notmyrealname4340
@notmyrealname4340 Ай бұрын
Bro did not learn his lesson the first time
@MaddoeGgasvyw
@MaddoeGgasvyw Ай бұрын
No he aint he went from white to grey hat 🤣🤣🤣🤣
@Dygear
@Dygear 2 ай бұрын
Man, if I had a nickel for every time that happened to me ... I'd be flat broke.
@NeonVisual
@NeonVisual 2 ай бұрын
"Accidently"
@JimmyMatis-h9y
@JimmyMatis-h9y Ай бұрын
came for this comment. 😊 thx for not disappointing!
@JimmyMatis-h9y
@JimmyMatis-h9y Ай бұрын
lol. my first thought as well.
@wasefmahmud
@wasefmahmud 2 ай бұрын
A legend like u should be getting millions of views
@MaddoeGgasvyw
@MaddoeGgasvyw Ай бұрын
Faxx he bet white hat
@5nowChain5
@5nowChain5 Ай бұрын
Hes getting mllions of hits for sure😂😂😂😂
@MaddoeGgasvyw
@MaddoeGgasvyw Ай бұрын
@@5nowChain5 no cap them botnets spread faster den hiv
@patchshorts
@patchshorts Ай бұрын
that is not what 0.0.0.0 means, it means a listen is happening on every ip of the host on that port, the listen mask isn't a firewall
@m8_981
@m8_981 Ай бұрын
yea but he said "if the port is forwarded through the firewall".
@sablanex
@sablanex 24 күн бұрын
@@m8_981 which is the real problem here. If the server is behind a nat someone would have to explicitly add a rule to forward the packets to that ip and port. Unless they just plugged the server directly to the internet.
@terraflops
@terraflops 2 ай бұрын
someone posted your video on mastodon -> first time watching this channel. really enjoyed your calm and easy to follow along explanation on the CUPS vulnerability.
@GabrielSykes
@GabrielSykes Ай бұрын
Just wait til you see his Wikipedia page.
@behindYOUR6
@behindYOUR6 2 ай бұрын
Open the door 、its FBI
@MaddoeGgasvyw
@MaddoeGgasvyw Ай бұрын
Lmaooo
@gispry
@gispry Ай бұрын
an informative video explained calmly with no background music and with a soothing voice. Great production, love your work
@xCheddarB0b42x
@xCheddarB0b42x Ай бұрын
do not "scan the entire internet" kids unless you know, badged three letter indemnity
@FreeLovingAmerican
@FreeLovingAmerican Ай бұрын
Ya... guy's a quack really. You don't accidentally install malware to create a botnet either lol.
@panagiwthspetroulios2075
@panagiwthspetroulios2075 Ай бұрын
@@FreeLovingAmerican you didn't really understand the video
@javierarzon4853
@javierarzon4853 Ай бұрын
You are awesome Mr Marcus, have been looking at your videos for Manny years, and they are are absolutely awesome . My blessings to you 😊
@dvast4942
@dvast4942 Ай бұрын
You're a good person, I would have made a lot of money but you aren't me, you'e a good person indeed
@5nowChain5
@5nowChain5 Ай бұрын
You just created your own Orbitial Ion Cannon. Expect a knock on the door...
@Chris-cv1ll
@Chris-cv1ll Ай бұрын
And that is why it was given a high rating…
@stuffless
@stuffless Ай бұрын
Thank you for explaining every part of the process so clearly. It is thanks to people like you I develop an everdeepening interest in cyber security
@impulsiveDecider
@impulsiveDecider Ай бұрын
Glad someone at my university notified my of that issue. I don't know if I would have heard about it another way.
@brendanmcgullion9358
@brendanmcgullion9358 Ай бұрын
Jail Bait meant something different when I was growing up.
@MiroslavObrtel
@MiroslavObrtel 2 ай бұрын
Thanks Marcus for reigniting my desire to explore and curiosity ♥ This is sick!
@___aZa___
@___aZa___ Ай бұрын
4:23 320TB if my math is correct :D
@elhnston6589
@elhnston6589 Ай бұрын
"Accidentally" .. That's brave.
@Sellbob
@Sellbob 2 ай бұрын
Would love to see a video covering, how you contacted the respective parties and how someone like me could go about it.
@einname9986
@einname9986 2 ай бұрын
That would be really interesting + It'd be interesting how the situation develops. Do the respective governments react? Do these systems stop being vulnerable after some time?
@Sellbob
@Sellbob 2 ай бұрын
​@@einname9986 Could not agree more!
@Jimmy_Jones
@Jimmy_Jones Ай бұрын
Probably just an email form on their websites
@KG-id3hk
@KG-id3hk Ай бұрын
I LOVE THESE VIDEOS!!! Please keep making more
@Sam-y5o6j
@Sam-y5o6j 2 ай бұрын
Wrote a high performance C++ scanner.. presumably because it's about three decades quicker than understanding massscan configuration.
@MalwareTechBlog
@MalwareTechBlog 2 ай бұрын
Probably 4
@user2200-t5z
@user2200-t5z 2 ай бұрын
Nice, U not only great at performing but also great at presenting your work.
@MaddoeGgasvyw
@MaddoeGgasvyw Ай бұрын
Oh he great at performing alright he gunna need to perform new speech for usa after this 😂😂😂😂
@nanostar6138
@nanostar6138 2 ай бұрын
Wow, you better get a Nobel peace prize soon mate!
@nathanpendergrast6917
@nathanpendergrast6917 Ай бұрын
bros trying to go back to jail
@MaddoeGgasvyw
@MaddoeGgasvyw Ай бұрын
He cyber security genius
@runed0s86
@runed0s86 Ай бұрын
​@@MaddoeGgasvywNah, anyone can learn this stuff being ignorant doesn't make everyone else a genius.
@ExperimentalKana
@ExperimentalKana Ай бұрын
wait he was in jail?
@MaddoeGgasvyw
@MaddoeGgasvyw Ай бұрын
@@ExperimentalKana he was almost in jail he almost got 10 years back n 2017
@MaddoeGgasvyw
@MaddoeGgasvyw Ай бұрын
@@runed0s86 tbh ill say this hacking u kinda have to be genius not easy hack
@matinmrv4213
@matinmrv4213 2 ай бұрын
Wow. Learnt alot. Thank you Marcus.
@Shenepoy
@Shenepoy 13 күн бұрын
your ISP in knocking on the door for espionage concerns 🤣🤣
@ellehooq
@ellehooq Ай бұрын
Thanks for such high quality content.
@bliskenx7239
@bliskenx7239 2 ай бұрын
Great video mate. Legend!
@sim00ps
@sim00ps Ай бұрын
That amplification is incredible. Nice job chief
@BryanEnsign
@BryanEnsign Ай бұрын
This needs more views. Great work. The world is in trouble 🤦‍♂️
@evilmortyofficial
@evilmortyofficial 25 күн бұрын
NSA field day
@budgetarms
@budgetarms Ай бұрын
Isn't this the guy that stopped one of the most infamous virusses of all time, ...
@zhornz
@zhornz Ай бұрын
as an c2 owner (botnet but more powerfull). whould say this is not "accidental"
@stevenstark-com
@stevenstark-com Ай бұрын
it seems to me that you likely just stumbled onto an existing botnet
@DaneSchell
@DaneSchell 2 ай бұрын
Bro just gave the government back door access to those systems (if they didn't already have it) lol
@exodeus7959
@exodeus7959 Ай бұрын
I would bet you they already know. He just stumbled onto this thinking it is some unknown exploit. Meanwhile our government’s probably have been using this exploit on their own citizens for years.
@ilyasessar7267
@ilyasessar7267 Ай бұрын
🤣🤣🤣
@tonycarter8440
@tonycarter8440 2 ай бұрын
Great breakdown Marcus! Now do ipv6 :-)
@anonuser2640
@anonuser2640 Ай бұрын
10/10 video I watched it without skipping a second
@computerpastiche
@computerpastiche Ай бұрын
amazing video and discovery! you're a natural for deftly presenting complex ideas in a digestible manner; this is endlessly interesting, thanks for sharing :·)
@Synflood-dot-txt
@Synflood-dot-txt Ай бұрын
Love your videos dude, thanks!
@rogerkell4964
@rogerkell4964 Ай бұрын
As a hearing impaired user, this was a really fun video to attempt to listen to.
@bdm1019
@bdm1019 Ай бұрын
There are captions but you need to turn them on.
@ryanpaaz
@ryanpaaz 2 ай бұрын
Marcus, any thoughts on the frustration of the vulnerability disclosure process and how responsible disclosure was dismissed the the researcher had to prove their technical prowess? It looked like a no-win. From the story I heard he told the Devs and they dismissed it as something that wasn't a concern to them and had a less than productive discourse. Researcher posts results and a proof of concept and the Dev's are all bent out of shape that this happened. It didn't appear there was much way for the researcher to win, except let 'security through obscurity' reign.
@tagKnife
@tagKnife Ай бұрын
Wait... This wouldnt happen to be the 3.8Tbps "ddos" cloudflare detected?
@brandonb5394
@brandonb5394 Ай бұрын
student here: so does this mean that this vulnerability for network-printer discovery gave access to these peoples networks or no? If so could someone explain how so.
@NiklasTerhorst
@NiklasTerhorst Ай бұрын
"Obviously i not do this" Not sure how many ppl will create a botnet with some chatgpt knowledge just from your video about the cups exploit
@FragileMaleEggo
@FragileMaleEggo 2 ай бұрын
Was IPv4 or IPv6 blast
@guilherme5094
@guilherme5094 2 ай бұрын
Marcus's lawyer now: 👀! I feel a slight tingling in my arm.
@OGB2
@OGB2 Ай бұрын
"Hey guys look what I figured out how to do! Pretty cool huh? Guys?..."
@NotSure416
@NotSure416 Ай бұрын
You should have posted notice to these systems by sending a message to their printer.
@nagi603
@nagi603 2 ай бұрын
A subset could be some distributed/microservice pdf/etc printers that were open to all instead of just the service/users they are supposed to provide capability for. Like an open bucket. e.g.: "hey, we need to have our xls export also output pdf, and I don't where to start, so I spun up a pdf printer docker and as networking is also not my cup of tea, opened the firewall. Task done, next ticket please!"
@starnumber_alt
@starnumber_alt Ай бұрын
Now you gotta destroy another ransomware
@lfcbpro
@lfcbpro Ай бұрын
Total noob here, but why would the systems have this port open in the first place? Is it for network printing or something along those lines? I wouldn't even know how to contact all of the authorities you had to, that is going above and beyond, well done sir.
@jacobcourtney5778
@jacobcourtney5778 Ай бұрын
Yeah FBI, he is at it again
@shadowlord0162
@shadowlord0162 Ай бұрын
is it already time to create the blackwall?
@sunsaktayho
@sunsaktayho Ай бұрын
so unfortunate to know you just have 100k subscriber while I just came to know you as a WannaCry Hero.
@ocsanik502
@ocsanik502 Ай бұрын
Why are people not firewalling the cups port?!
@flavio6179
@flavio6179 2 ай бұрын
Good video Marcus , thanks for sharing
@kevinnyawakira4600
@kevinnyawakira4600 2 ай бұрын
I want to be like you when i grow up. I like how you do amazing things accidently😂
@0xphk
@0xphk 2 ай бұрын
Still searching for the printer to finally pickup my printouts :D well done
@obtFusi
@obtFusi Ай бұрын
Which ISP allows so many connections from one source?
@ilex8015
@ilex8015 Ай бұрын
Dude just accidently showed anyone how to ddos
@RandoWisLuL
@RandoWisLuL Ай бұрын
id love to set up 2 servers on different network connections and see what the 30,000+ servers would do to a setup.
@GoldenOni.
@GoldenOni. 22 күн бұрын
You Are my Hero!
@ThisisFerrariKhan
@ThisisFerrariKhan 2 ай бұрын
Bro must like them awkward conversations with the alphabets boys 🤣
@polymathx_
@polymathx_ Ай бұрын
bro is building his own case file edit : his
@cracisn
@cracisn Ай бұрын
yoo arnt u that geezer who stopped that one ransomware or smng
@_GhostMiner
@_GhostMiner Ай бұрын
*4:34** Rookie mistake of not using a real language.*
@RobertElliotPahel-Short
@RobertElliotPahel-Short Ай бұрын
Love your content, commenting for more
@Hexachroma
@Hexachroma Ай бұрын
This might be the reason behind IA DDOS attack :(
@blackmennewstyle
@blackmennewstyle 2 ай бұрын
The map with all the potential victims is definitely quite worrisome... Definitely something other malicious actors have definitely taken advantage of...
@MrPyro91
@MrPyro91 2 ай бұрын
FBI warrant round 2
@SY1Mella
@SY1Mella Ай бұрын
Mad how much of a ballache it is to connect to my OWN printer sometimes
@morgan_bowe
@morgan_bowe Ай бұрын
Was that cloudflare mitigating your botnet last week? PC Per podcast said it was something like 8 gigabits per second.
@hew34
@hew34 Ай бұрын
I thought binding to 0.0.0.0 didn’t mean any address could connect but any local IP could service that port.
@yzz__
@yzz__ 2 ай бұрын
i’m just commenting to annoy the guy who got pissed at me for saying first
@2fated
@2fated 2 ай бұрын
First
@kkuriboh
@kkuriboh Ай бұрын
easiest botnet tutorial I've found, thanks for the information. now I must collect my billion dollars from the russian gobberment.
@scrapycholo2659
@scrapycholo2659 2 ай бұрын
When will you make skynet?
@Lebensgott
@Lebensgott 2 ай бұрын
thanks for that informative video. i really have to check if anything is port forwarded, which shouldnt be forwarded... ^^
@defeatSpace
@defeatSpace Ай бұрын
Oh god I see myself on the map
@bluemajestic9580
@bluemajestic9580 2 ай бұрын
Dam Africa is pretty secure
@hashfors
@hashfors Ай бұрын
Yeah it’s ridiculous how good at network security these ppl are..
@potatocrispychip
@potatocrispychip Ай бұрын
Did he just abuse a CVE 9.9 bug that was technically safe outside the local network?
@BFG_10G
@BFG_10G 2 ай бұрын
Don't let the FBI see this video.😆
@chrisridings9544
@chrisridings9544 2 ай бұрын
It's interesting. But I think there's a problem that another title for this video could be "How to DDoS without a botnet".
@janfkarel92
@janfkarel92 Ай бұрын
I’m not tech wavy how Di I check my own printer or wifi iv this vulnerability is patch able ?
@cli
@cli Ай бұрын
if you don’t have more or less a newer “dumb” printer and not a complex configuration on it and just have a regular one then you are _probably_ going to be fine, CUPS requires a more or less custom setup
@janfkarel92
@janfkarel92 Ай бұрын
@@cli ah thanks
@mrhassell
@mrhassell Ай бұрын
Making the Case for Elixir, in the least practical way.
@SNSISNSJISEJSJS
@SNSISNSJISEJSJS Ай бұрын
Does anyone know where can i find that ui that worked in the browser I saw it was soo cool Does anyone have idea or i fo where can i get that dashboard glob very cool ui ? I searched a while but didn't find anything yet ..
@SimonZerafa
@SimonZerafa 2 ай бұрын
Oh No! Not again?! 😉🤷‍♂️
@LordOdin
@LordOdin Ай бұрын
Pretty decent video other than the python statement being complete bullshit. I’ve made many pythons web servers that are capable of over 10GB/s on a single thread.
@MalwareTechBlog
@MalwareTechBlog Ай бұрын
It's basic common sense that the less time spent per system call, the higher the throughput. I don't necessarily doubt that someone could create a 10gb/s web server in Python, but based on your response to the discussion at hand, I do doubt that you could.
@LordOdin
@LordOdin Ай бұрын
🤷‍♂️ I’ll take that as a complement I guess I wasn’t saying that python isn’t slow. I was saying that it’s not a bad tool for this specific task. You said your self it took 40 minutes for the c code to run.. 1.8 million requests per second is 100% achievable with python if you are halfway decent at python. At least on the hardware you mentioned. We can make this a bit more constructive instead of an argument, I’ll write some code to do it when I get back from my trip to Europe.
@MalwareTechBlog
@MalwareTechBlog Ай бұрын
It's nothing about "being decent with python" it's an interpreted language, there is a massive overhead with each call. It's not going to even come close to C in terms of requests per second given identical hardware. If the hardware is maxing out at 1.8 million RPS, how are you going to increase that by adding more CPU cycles?
@LordOdin
@LordOdin Ай бұрын
@@MalwareTechBlog it is possible to write bad c code… Language is irrelevant if you write a pile of unoptimized slop. Good logic is more important than the speed of the language most of the time, especially in networking. The metrics you mention are fairly within reach from python based on my past experience. You are only doing 37,500 requests per second per thread on that system. If you are correct you would let me write the code and prove my self wrong.
@MalwareTechBlog
@MalwareTechBlog Ай бұрын
You're free to prove yourself as wrong as you want. I already know my C code will be faster.
@nsacyber
@nsacyber Ай бұрын
Ah, so it was YOU. FBI will be there shortly. ;)
@BruxoCp13
@BruxoCp13 Ай бұрын
A laughed my arse off all the way through this lol
@Interminableable
@Interminableable 2 ай бұрын
Hi Marcus, love your content and your in-depth explanations. Your description how the binding IP address varies stuff is somewhat inaccurate/misleading. Was this deliberate comment bait for network nerds?
@farhanrejwan
@farhanrejwan 2 ай бұрын
thanks for your comment, it really helps the channel grow.
@Google_Does_Evil_Now
@Google_Does_Evil_Now 2 ай бұрын
It looked accurate to me, but I'm just average user. What did you see inaccurate about it? 0.0.0.0 means no restrictions on the IP. Is that not right?
this is what happens when you let the intern write code.
12:50
Low Level
Рет қаралды 376 М.
Why Microsoft Is To Blame For The Crowdstrike Outage (Not The EU)
17:37
Что-что Мурсдей говорит? 💭 #симбочка #симба #мурсдей
00:19
Creative Justice at the Checkout: Bananas and Eggs Showdown #shorts
00:18
Fabiosa Best Lifehacks
Рет қаралды 35 МЛН
Why no RONALDO?! 🤔⚽️
00:28
Celine Dept
Рет қаралды 119 МЛН
She made herself an ear of corn from his marmalade candies🌽🌽🌽
00:38
Valja & Maxim Family
Рет қаралды 16 МЛН
They tried to hack me with UNDETECTED Malware
20:19
Eric Parker
Рет қаралды 55 М.
Making Minecraft 100x faster (by rewriting it in Rust)
17:02
Theo - t3․gg
Рет қаралды 154 М.
When a CIA Hacker Goes Rogue
23:09
TyFrom99
Рет қаралды 2,5 МЛН
Somebody emailed me a trojan virus
14:06
Bog
Рет қаралды 1,1 МЛН
The Shocking Ease of Cracking Windows 11 Passwords
14:27
Enderman
Рет қаралды 112 М.
Что-что Мурсдей говорит? 💭 #симбочка #симба #мурсдей
00:19