What certifications should I prioritize to be a security tester (hired by companies to test their defenses)? I tried college, but the learning environment was not a good fit for me.
@Lelende10 күн бұрын
Note to self. When social engineering/phishing hack to Low Level, use racoon meme
@LowLevelTV10 күн бұрын
Would work
@revenevan1110 күн бұрын
Pls open attachedment [sic] *raccoonmemes.zip.exe*
@Ariccio1239 күн бұрын
@@LowLevelTVdo you ever dip your code in water before you read it to read it more good
@UncleBroer9 күн бұрын
@@LowLevelTV You really love those raccoon memes 🦝
@rigsofrodsmaster10 күн бұрын
Reminds me of the "don't trust no one not even yourself" meme but it's backdoors.
@dmitriyrasskazov885810 күн бұрын
State backed hacker sounds cool, but at the end of the day its still just government employee.
@javabeanz85499 күн бұрын
With lots of money and research backing the position.
@thecakeredux10 күн бұрын
Dude, raccoon memes are THE BEST. It's essentially all I laugh about these days and me and my buddy have HUNDREDS of them.
@_hi_pwr10 күн бұрын
The supreme Urban mammal
@Milan____10 күн бұрын
you should send me an .exe file with all your memes in a convenient self-extracting format!
@HalianTheProtogen10 күн бұрын
Need
@FlavorExperiment9 күн бұрын
U have hundreds of raccoons? Bake a cake with them
@Veptis9 күн бұрын
In germany there is a court case where a security contractor disclosed a vulnerability (password in cleartext for a database connected to the open Internet)... And then got sued. And the judge ruled that using My PHP Admin consitutes hacking. Maybe by as much as entering a building you arent supposed to while the door is open.
@Waldemar_la_Tendresse9 күн бұрын
"These people" are obviously completely dumb concerning IT and programming. Rules for 1d1o75.
@SALTINBANK3 күн бұрын
Germany and France mate they are seeking wrong targets : hacktivist and sec guys treating them like terrorists .
@sir_no_name1478Күн бұрын
@@Veptis you meant the most recent case right? Remember the CDU scandal with the CCC girl that found the vulnerability in their app ^^. Not quite the same and thankfully it backfired for the politicians :D
@DevWolf3110 күн бұрын
Backdoor your backdoors at the backdooring center of Backdoors Inc.
@Adam7ep10 күн бұрын
@@DevWolf31 😂😂
@javabeanz85499 күн бұрын
This message brought to the by : The redundant department of redundancy department of redundancy.
@jebler9 күн бұрын
I haven't done PHP for a decade, but I still remembered extract. All of the PHP standard lib is riddled with backdoors.
@CAGonRiv9 күн бұрын
Imagine explaining this to your PM that has no experience in anything STEM and worked in HR their entire career.
@Waldemar_la_Tendresse9 күн бұрын
@@CAGonRiv You should not have to because it just should not exist in that context.
@Tabu1121110 күн бұрын
Im only here for the article reads. Im dyslexic and adhd, so this helps me a ton!
@cslearn304410 күн бұрын
Im not gay but 20 dollars is 20 dollars
@JessicaFEREM10 күн бұрын
mood
@joseeduardorussoperis466810 күн бұрын
Based comment
@du42bz10 күн бұрын
If you were gay it would be even better
@soupadoopafly10 күн бұрын
At that note this would also still hold with a reference to a certain type of masturbation for very flexible people
@wedgevic_proto9 күн бұрын
I, however, am gay But $20 is $20
@TriSept10 күн бұрын
The WHOIS certificate method was an old way of verifying the owner before GDPR and WHOIS redaction was a thing. They would send an email the address on the WHOIS registry for the domain to verify the owner. Clearly not the best solution and now the DNS TXT record is the favored option.
@brentsaner9 күн бұрын
you still need populated WHOIS for EV IIRC, but this is still valid for any DV using ACME. 0. pop WHOIS 1. change authoritative nameservers 2. DNS-01 *OR* HTTP-01 ACME challenge with wide-trust CA 3. Profit
@kamiljanowski72369 күн бұрын
Lol. I once attended KPI Open - an international algorithmic competition held in Ukraine. On the first day the server that we were supposed to upload our solutions to just died because 1 of the teams from Russia just hacked it :P
@lotarion4 күн бұрын
@@kamiljanowski7236 average polytech uni infrastructure lol
@sharedcat10 күн бұрын
love these types of videos, keep it up
@Jafus19 күн бұрын
20:00 My preferred example of this is actually the word "gift". For your birthday, you receives gifts, and not jifts. Since both has "gif", it better drives the point that "jif" just feels wrong.
@threeMetreJim8 күн бұрын
I know of no system that does jiraphics either. Maybe something from a rural African fairy tale?
@Pasta_watcher8 күн бұрын
@threeMetreJim did somebody say Jira???
@eepicfailz6 күн бұрын
what about ginger ?
@YaySyu10 күн бұрын
We need more of our own nation state actors lmao
@DC-Nigma10 күн бұрын
reminds me of those belgium domains that where abbandon and they setup a email server and the emails with personal information just comes in...
@Mmouse_10 күн бұрын
Hah I remember using some of those... And I remember looking at that extract code when setting stuff up and wondering wtf it did... Shrugged and carried on. Being young was fun, thanks for allowing me to visit it here.
@Stratelier9 күн бұрын
I haven't scripted any PHP in years and I noticed the @extract() sooner than he did.
@Newb1eProgrammer10 күн бұрын
Next video: backdoor the backdoor to the backdoor
@marsovac3 күн бұрын
"You don't GIO to the bathroom" The giraffe disagrees.
@bennyswayofficial10 күн бұрын
Defunct and abandoned infrastructure? I'm gonna start going to abandoned warehouses, leave ip cams that stream to AM frequencies ('._.')
@dmitriyrasskazov885810 күн бұрын
Just never ever come back for them.
@Little-bird-told-me10 күн бұрын
Backdoor the backdoor
@enzopestana10 күн бұрын
Article reading videos are great pls keep it up Ed
@j-wenning10 күн бұрын
19:59 Counterpoint: gin, gym, gist
@yanikb.131210 күн бұрын
Yeah 'kif' people have no point. Just ask them how they pronounce scuba or lazer.
@Stratelier9 күн бұрын
"The correct pronunciation is--" _[end of video]_
@ankomcoper11839 күн бұрын
I do not care how you pronounce GIF, but I do find the bad arguments made by both sides hilarious.
@cattocs9 күн бұрын
There's no way you pronounce gin as djinn
@Ariccio1239 күн бұрын
This is the real content I'm here for
@thelanavishnuorchestra9 күн бұрын
I personally don't care whether you pronounce GIF with a hard or soft "g". I randomly say it both ways. As an old person who remembers the creator of the GIF format was making a pun about a certain brand of peanut butter, I do care if you have an exceptionally strong opinion and it's wrong. I reserve the right to point and laugh. And hey, I know sudo is pronounced "sue due" but f that, it sounds awful and I pronounce it "psuedo" like everyone else who has the word sudo in their vocabulary. So yes, Linux geeks. Pardon my french. Have a lovely day and keep making these videos. :)
@MattDog_2229 күн бұрын
jia tan is disappointed in how unobfuscated that data is
@shize9ine10 күн бұрын
19:58 - Thank you. Arguing with a co-worker: “ok fine. Let’s jo to my house and watch jaurdians of the jalaxy then.”
@GrahamLyon10 күн бұрын
my favourite animal to see at the zoo is the giraffes.
@grmpf9 күн бұрын
Would you offer them some gin?
@shize9ine9 күн бұрын
@@grmpf touché
@et44938 күн бұрын
This channel is amazing. I love your style man. Do you
@katana18557 күн бұрын
I love how simple the thumbnails are lol. I am also trying to learn IT. So I am here.
@m4rt_10 күн бұрын
It's Graphics Interchange Format, not Jraphics Interchange Format.
@MattHudsonAtx10 күн бұрын
It's actually jraffic
@mage369010 күн бұрын
Also, JIF is peanut butter, not some sort of moving picture.
@monkemode812810 күн бұрын
Ummmmmmm actually 👆 it's an acronym and the symbols in acronyms don't need to be pronounced by the word they represent. 🙅
@pianochess188210 күн бұрын
Hey that’s a good argument. How do pronounce the abbreviation of "Computer Science" (CS)
@barry510 күн бұрын
@pianochess1882 you pronounce each letter individually because that's an initialism and not an acronym
@threeMetreJim8 күн бұрын
Instead of buying domains, I've seen hackers using services where you can host your own php driven pages; at least until they get caught. Sometimes the temporary domains have a 'username' preceding the actual domain, so maybe finding those, and using the same username in future may give similar results (assuming no random characters are added to the usernames).
@TungstenCarbideProjectile9 күн бұрын
this guy is so 1337 he can read tech articles aloud like no other pen tester in the world
@randomgeocacher9 күн бұрын
Dropping webshells in pentests - an interesting ethical aspect, like how do you ensure a malicious web crawler does not find it? Maybe a randomized file name is a workaround. Aside from the fact that it darn better not be backdoored.
@musicaeclectica9 күн бұрын
Thank you for pronouncing it correctly and setting the record straight on GIF! A GIF is a gift
@Waldemar_la_Tendresse9 күн бұрын
Good sh1t, as always. After spending a few days watching various videos of yours, I am convinced that programming languages should be structured very differently. Rust is already taking the first steps so that memory access problems don't grow into even bigger problems. However, this can only be a start. I think we may have to introduce several levels for program execution in programming languages in which code and data have to live (analogous to userspace and kernel space, only with different levels). User input or much more in the level for user input, for example, or input from unknown sources in general, a defined and definable minimum of input should be possible. To take a closer look at the example: at the level at which what is discussed here works, "extract" should simply not exist. At other levels, however, it might. "Enforced security", so to speak, depending on the application level or area of the application.
@EonityLuna10 күн бұрын
We put backdoors in your backdoors so you can sneak in by the backdoor while sneaking in by the other backdoor.
@0x0michael8 күн бұрын
As a Nigerian, i can tell you the federal high court website is not worth the $20 used in getting the backdoor backdoor
@Lino12598 күн бұрын
can you take a look at the patient monitor backdoor? maybe even take a look at the code? cisa did provide some insights.
@smort1239 күн бұрын
14:57: The only difference between screwing around and Science is writing it down. - Adam Savage
@JosephDalrymple9 күн бұрын
Love these videos! Incredibly nostalgic. My 13 year old son enjoys listening to them with me on our daily drives, and asking about the good old days! 😂
@cachoraver8 күн бұрын
Racoon memes are indeed the best.
@TheVault199910 күн бұрын
Mobi domain was ment for mobile devices
@SimonSchick9 күн бұрын
Nice article, thanks for the read-up 😎🎉
@brentsaner9 күн бұрын
also if you comp a WHOIS, you wouldn't change the information about who owns a domain- you'd change the nameservers. preferably with ones that fallback to the real NS if they have queries open to non-root servers to avoid noise.
@r1konTheAutomator4 күн бұрын
1:28 - I don't think you meant to say DMARC here. DMARC is a dns entry that tells an email service provider what to do if an email from your domain fails SPF or DKIM mail checks. (You can tell it to do nothing, to quarantine the email, or reject it)
@Aplysia10 күн бұрын
Hey, we just collect usage analytics in order to improve your user experience with future releases! What's the problem?
@mattjohnson85859 күн бұрын
Jif. You don't gi-raffe, you ji-raff
@tertrih90788 күн бұрын
But the gi in gift is pronounced with a hard G. Anyways, the g in gif stands for graphics which has a hard g
@mattjohnson85858 күн бұрын
I tend to agree. I'm just being obnoxious lol
@cameramaker8 күн бұрын
So is there some list of sinkholed domains which I can put in the DNS resolver and get a poor man IDN solution, to get a notification if we catch some of that illness?
@viennois012310 күн бұрын
Backdooring backdoors sounds to me like shit squared.
@dev.sharif10 күн бұрын
It's funny, like you have a backdoor to a backdoor and you don't care to lose access to all of that, WTF! I'm so curious why these hackers didn't renew the hard coded domain. Am I missing something?!
@monkemode812810 күн бұрын
They probably got what they wanted and left. Maybe the guy with admin access got arrested or his hard drive crashed. Maybe there was an opsec mistake or vulnerability which puts them at risk.
@Vor10min.10 күн бұрын
I do not want to loose compromised infrastructure, because it can be used for further attacks for example as Webserver for Phishing.
@Tux.Penguin9 күн бұрын
@@dev.sharif Maybe they were lazy, careless, or forgetful.
@MiriamSlaffey9 күн бұрын
Ohh the nostalgia for the c99 and r57...
@SBPk38 күн бұрын
How does one try to help an organization and work with them when the organization wants to call you a liar and refuse to help. With that organization being my ISP. In which was compromised leading up to my issue.
@RoyalReptilePirates9 күн бұрын
Forgive me but you and John Hammond look like brothers? Am I wrong here guys???? Love both your guys content!
@nio8049 күн бұрын
I like how the extract function uses the "@" operator too, which is probably my top candidate for the worst feature in a programming language ever. @ silences all errors, including syntax errors. I had to once debug a piece of steaming PHP that used it liberally and I now have a burning hatred in my soul for anyone who uses it.
@billhurt36449 күн бұрын
Geoffrey the gentle giraffe would would side eye you on his way to the gym if he heard you pronounce gif that way.
@brentsaner9 күн бұрын
"Jraphics Interchange Format" yeah no you're totally right
@billhurt36449 күн бұрын
@ yes your right. The rule is you have to pronounce every letter of an acronym the same way the word is pronounced. I’m sure that’s why was say NASA like N-AE-S-AA instead of the linguistically easier NASA. Or I’m sure you pronounce HUD (housing and urban development) like Hood.
@brentsaner9 күн бұрын
lol none of that was applicable. Good job. Oh, sorry, I mean "jood" job.
@HalianTheProtogen10 күн бұрын
Incorrect. Per the inventor's word, choosy developers use `.gif`. :D
@icefreezer79 күн бұрын
What's next ---- software update infrastructure and autoscaling cloud infrastructure for SSLVPN appliances? That would be a never-ending nightmare!
@duetwithme76610 күн бұрын
Maybe this is general knowledge, but what's up with .MOBI? Seems a like a major event? Do you have a video on it?
@zalkiah98849 күн бұрын
Eat trash, be trash - Raccoons probably
@oaklyfoundation8 күн бұрын
What does dmarc have to do with ownership validation? I don’t think you are right on that part.
@asdasdaee223210 күн бұрын
We did this in 2010; not new but a great write up! Another option I'm surprised they didn't pick up on is using public VPN services which allow for port forwarding :) Old school stuff being brought up is great! Source: I'm an ex-malware developer turned security researcher.
@tcc123410 күн бұрын
"Another option I'm surprised they didn't pick up on is using public VPN services which allow for port forwarding :)" Could you elaborate on this?
@send_love9 күн бұрын
20:00 small correction. It is indeed pronounced jiff
@salpertia6 күн бұрын
Next vid, hacking hackers that hack hackers that hack government backdoors
@HorrorMakesUsHappy9 күн бұрын
Don't be surprised when the people paid to find/create backdoors don't close them when the current project stops paying. It's like leaving a stolen vehicle somewhere with the keys behind the tire. Yeah, it might not be there when you come back, but if it is, great, because that just saved you some time.
@genuismensa10 күн бұрын
Most of them just require you to do a TXT record with a hash in it to prove that you are the owner of the domain. - Regarding WHOIS question he asked.
@CodyDBentley8 күн бұрын
17:47 begs to be GIF'ed
@Dank10 күн бұрын
i had no idea you could do this (twenty dollar dollars)
@sjoer7 күн бұрын
Bruh, BASE64 is like everywhere :D It made me chuckle so hard I need to see a doctor.
@sjoer7 күн бұрын
Also, not the first time one of my servers filled up with logs :D
@sjoer7 күн бұрын
I'll have you know that back in the good old WEP cracking days I had a target acquired that kept sending predictable data at predictable intervals! So I figured out what the data was, it was a password sent out in the clear that gave me access to his TV set top box :D From there I got into his e-mail, his PokerStars account... and then I realized I better ring his doorbell and tell him what is going on!
@Muhammed_Shameer_Quraish_KM9 күн бұрын
so its a backdoor in your backdoor ? sounds like inception of backdoor.
@o0alessandro0o8 күн бұрын
19:57 I mean, for those who prefer gif-like-giant to gif-like-git... There does exist a jif format, and I personally don't want to have to call them Golf India Foxtrot or Juliet India Foxtrot every time because somebody decided they should sound the same. That, however, is a different Foxtrot Uniform entirely, compared to the topic of the video.
@davidbronke54849 күн бұрын
100% on GIF pronunciation. I don't hear anyone saying "jraphics" 😹
@KizulEmeraldfire9 күн бұрын
19:56 - I opt always to spell it out: NO ONE can argue with the pronunciation of "G-I-F"! :D
@erikhicks079 күн бұрын
You would think these once-rogue domains would be DNS blacklisted worldwide.
@BennettBeach9 күн бұрын
Not saying Jiff is enough for me to
@brentsaner9 күн бұрын
"imagine they're on their mobile phones" Nah, fam, that's probably just a UA rotator.
@alexparker77912 күн бұрын
don't pretend your gif pronunciation is anything but preference. english has soft-g words like giraffe, giant, gin, ginger, gem, gel, gentle, gem, gym, gyroscope, gist, genesis, generous, etc
@Some-Guy-9 күн бұрын
There's a prince who can help the Federal High Court of Nigeria find the hackers, but in order to keep his bank details out of the hacker's hands he needs your help moving some funds around.
@johnsmith89819 күн бұрын
I got my backdoor hacked once. I kinda liked it .///.
@srsherman79 күн бұрын
Backdoors... those are the doors in the backrooms, right?....
@randomgeocacher9 күн бұрын
You speed-ran through the networking/IP comments, barely comprehensible, having the page on 192.168 up for like a second :) The block reservation size vs network size was way to quick for me to follow there, and I’ve been around since ancient times when we built networks with sticks and stones.
@kidmosey8 күн бұрын
JAG - Judge Advocate (J)eneral, or Judge Advocate (Gh)eneral?
@wurshraggwurshington22847 күн бұрын
If you don't Jo to the bathroom, and you go there instead, what do you look at in there? A Gif of a (Grrr)iraffe?
@eepicfailz6 күн бұрын
20:00 yeah but would you want some ginger ?
@mr.togrul--93839 күн бұрын
LMAO, were you able to learn what is SSRF?
@boomchaka141910 күн бұрын
the creator said jif like the peanut butter. For logic to be consistent you would have say JFeg instead of Jpeg
@mjmeans79839 күн бұрын
Only a fool spells photo with an F, when writing in English. Or are you implying JFEG should be Joint Foolish Experts Group?
@barbdwyer459 күн бұрын
@@boomchaka1419 Penelope vs Antelope
@boomchaka14199 күн бұрын
@@barbdwyer45 Not sure what your point is. The P in Jpeg stands for Photographic.
@barbdwyer459 күн бұрын
@ hercules testicles
@Brahvim6 күн бұрын
@@boomchaka1419 They're giving another example, is all.
@jeanbig9 күн бұрын
thumbs up for correct pronunciation of *.gif (also the video was good)
@cognitive-carpenter10 күн бұрын
Don't forget to like--wow, only 995 likes thus far! Great content LL
@randalthor179 күн бұрын
oooo my govt is vulnerable as we thought, woooo
@steveyh1310 күн бұрын
19:58 you don't "jo" to the bathroom, but do you like watching "jiraffes" at the zoo?
@qpc20106 күн бұрын
This video just reminded me I've been mispronouncing giraffe my whole life....
@elizhaZafr-s7k5 күн бұрын
I appreciate your post! My okx wallet holds USDT and other coins and I’ve got the seed phrase :(tag suit turtle raccoon orange fever main skull special hungry crystal mixture). Could you explain What's the best way to send them to Binance?
@avegamers10 күн бұрын
Oh Hello, a new Video 👋
@soulife83838 күн бұрын
Pfft if you thought 2010 was a fun time for the Internet you should have seen 2000. Almost no antivirus, or firewalls, DSL sucked but if you were patient you could get free dialup from a compromised library computer, or put a Trojan into an AOL install and put it on as many school computers as possible. I even remember compromising our towns email, sending emails from teachers using telnet, net send flooding classrooms with pop-up messages, bypassing DNS filters, ah good times. I don't miss walking around with 40 disks to bring home mp3s from the schools T1 connection
@JackShen10 күн бұрын
ah the days when you could put javascript tags in comments........
@HadTooMuchToDream10 күн бұрын
When ya done, why wipe off the victim? Sloppy practice, yet it leaves sloppy seconds.
@CrateSauce10 күн бұрын
low level tv?
@nR-kv7xo10 күн бұрын
haha I played with this as minir in the early 2000s. Funny this is still alive. With properly containers today with readonly fs, no root access, and ingress controllers this is useless for most systems... except these legacy ones. Very interesting
@Rx7man8 күн бұрын
Competing with Louis Rossmann for talking and 2x speed!
@TomAtkinson9 күн бұрын
Wow dude. Omg.
@pwood64468 күн бұрын
Sorry, No. ".gif "is "jif" according to the resposible parties ...think "jiffy". Give it a little thought, it's the only way any of it makes sense, no matter how many people try to twist it.
@bthemedia6 күн бұрын
What’s more annoying than watching someone read an article, and only provide low level of effort/low value commentary? I don’t know… that’s an honest question.