Telegram Has Been Hacked

  Рет қаралды 204,651

John Hammond

John Hammond

Ай бұрын

Learn Cybersecurity - Name Your Price Training with John Hammond: nameyourpricetraining.com
📧JOIN MY NEWSLETTER ➡ jh.live/email
🙏SUPPORT THE CHANNEL ➡ jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
🌎FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
💥 SEND ME MALWARE ➡ jh.live/malware
🔥KZbin ALGORITHM ➡ Like, Comment, & Subscribe!

Пікірлер: 341
@BhilBhil-tc8fy
@BhilBhil-tc8fy 25 күн бұрын
Yes please. I would love a video that does a deep dive on the *Metaspyclub* project
@ranjanekka85
@ranjanekka85 25 күн бұрын
Metaspyclub gang in the house! Thanks for the analysis!
@milanjamod7469
@milanjamod7469 25 күн бұрын
Metaspyclub anticipation is building to a fever pitch! 😥
@KvapuJanjalia
@KvapuJanjalia Ай бұрын
I'm not afraid of a calculator! Bring it on!
@cringemaki
@cringemaki Ай бұрын
Everybody gangsta till the calculator app starts to ask permissions for camera, microphone and location 💀
@yukiplaysFr
@yukiplaysFr Ай бұрын
💀
@TobbeOakleaf
@TobbeOakleaf Ай бұрын
Oh it will be problems! Count on it!
@BillAnt
@BillAnt Ай бұрын
At 8:14 that evil laughter Muaahhh!! lol
@Raymi20-
@Raymi20- Ай бұрын
​@@yukiplaysFr**salutes to the therian** Ma'am how can I help you ma'am
@Spiderfffun
@Spiderfffun Ай бұрын
RCE after RCE, I hope kids wont have to learn about the year of the vulnerabilities, 2024, in the future
@SLZeroArrow
@SLZeroArrow Ай бұрын
Thy Digital Apocalypse is drawing nearer by the day
@atomgutan8064
@atomgutan8064 Ай бұрын
This is literally cybersecurity history.
@TehPwnerer
@TehPwnerer Ай бұрын
No it will be certainly eclipsed by the number of them in 2025
@Ph34rNoB33r
@Ph34rNoB33r Ай бұрын
I wonder whether the whole AI hype will make even more RCEs show up. Either by improving exploit code or by reducing code quality in the attacked app because people trust AI code without questioning it.
@Shaggidelic69
@Shaggidelic69 Ай бұрын
​@@SLZeroArrow seriously. I dedicated my whole life to computers and now they looking like they wanna kill us (ai). Ai is phuggin everything up. Its kinda scary tbh
@DoorThief
@DoorThief Ай бұрын
I just got a SNYK sponsored ad by John Hammond before his own video
@NileGold
@NileGold Ай бұрын
Fr
@h5e
@h5e Ай бұрын
I did too
@alek002
@alek002 Ай бұрын
It's rigged!1!1!1!1!1
@thecrew8612
@thecrew8612 Ай бұрын
Saaame
@why1851
@why1851 Ай бұрын
too much rce exploits bro 💀💀💀💀💀💀💀
@sunbleachedangel
@sunbleachedangel Ай бұрын
What are others?
@amaankhan8436
@amaankhan8436 Ай бұрын
Xz utils, rust, palo alto
@sunbleachedangel
@sunbleachedangel Ай бұрын
@@amaankhan8436 Palo alto?? My company uses that lul
@why1851
@why1851 Ай бұрын
@@sunbleachedangel there was a rust rce CVE-2024-24576, aint that effective though
@yureimenkishi4291
@yureimenkishi4291 Ай бұрын
Rust already released a patch its java that said they ain't fixing it. Tbf .bat codes running aren't used anywhere so who really cares
@ghoulbuster1
@ghoulbuster1 Ай бұрын
TL;DR The exploit disguises as a fake video that when played executes python code, requires python to be installed for it to work.
@mushroommanny
@mushroommanny Ай бұрын
saved me about 10 mins bro ty
@lucplayed
@lucplayed 21 күн бұрын
Me, an it student, got "hacked" like that...🤣
@AstralArchivists
@AstralArchivists Ай бұрын
Bet the three later agencies are punching air rn. All their exploits getting found.
@BillAnt
@BillAnt Ай бұрын
While reading your comment. lol
@MrCobalt
@MrCobalt Ай бұрын
You think every exploit exists because of "three later agencies"? 😂
@ohmsohmsohms
@ohmsohmsohms Ай бұрын
@@MrCobaltgiven the past of their involvement with 0days, I wouldn’t be surprised if they were aware of maybe 1 of the RCE vulnerabilities discovered this year
@v-y
@v-y Ай бұрын
​@@MrCobalt theres no way this was an unintended oversight
@januzi2
@januzi2 Ай бұрын
Wait ... we can hack those spammers that are sending us the messages to text them?
@osiristeam6959
@osiristeam6959 Ай бұрын
They should have a list of trusted extensions instead of a list of untrusted ones.
@zeteya
@zeteya Ай бұрын
Very bad idea
@rafayahmed6259
@rafayahmed6259 Ай бұрын
​@@zeteyawhy?
@zeteya
@zeteya Ай бұрын
@@rafayahmed6259 Many reasons, one being a good extension can turn bad one day, but an extension that was bad to begin with will never turn good.
@ThisIsJustADrillBit
@ThisIsJustADrillBit Ай бұрын
The fuzzing begins ❤
@BillAnt
@BillAnt Ай бұрын
LPL has entered the chat, fuzzing locks are fun. hehe
@AuxiliaryPanther
@AuxiliaryPanther Ай бұрын
​@@BillAnt...we're getting an SQL injection on three, oh it's binding. A little malware on four, and we're set. Going back to three, gained root access to run our query, annd now we're in.
@BillAnt
@BillAnt Ай бұрын
​@@AuxiliaryPanther lol that took like 30 seconds.... not a very secure lock. :D
@cvl14
@cvl14 Ай бұрын
This just shows how blacklist are ineffective as a security tool
@kbabe3915
@kbabe3915 Ай бұрын
The scrum meeting: "Yeah, an approve list is too short, let's write out every single extension that could execute code instead of just choosing some image and video formats that we support."
@user-hp2dr5qc8p
@user-hp2dr5qc8p Ай бұрын
A whitelist can get annoying tbh.
@kbabe3915
@kbabe3915 Ай бұрын
@@user-hp2dr5qc8p Ah yeah, you're right, much more annoying than a 0 day. Also a blacklist had to have been annoying from the very start.
@milanvucetic1292
@milanvucetic1292 Ай бұрын
3:55 Not me watching the John Hammond video and getting an ad with John Hammond in it. Some may say it's a 2 for 1.
@BillAnt
@BillAnt Ай бұрын
Taking it up the a** without lube. lol
@acessor9899
@acessor9899 Ай бұрын
This one RCE was indeed fun to use, gotta find more ;)
@1hw3
@1hw3 Ай бұрын
hello vro
@Luzum
@Luzum Ай бұрын
im gonna touch u vro ♥
@jabrowski_
@jabrowski_ Ай бұрын
Interesting shiz John. Liked and subbed, stay safe
@te-weikaigai1836
@te-weikaigai1836 Ай бұрын
I'm glad that I migrated to Debian + KDE two months ago. I still have my Windows on my drive, but never want to boot it anymore. The KDE environment in Linux is just much better than Windows.
@HyBlock
@HyBlock Ай бұрын
who asked?
@KLR-3
@KLR-3 Ай бұрын
Welcome to the family.🐧
@te-weikaigai1836
@te-weikaigai1836 Ай бұрын
@@HyBlock the implication was that I'm not affected by windows RCE anymore.
@freerice9595
@freerice9595 Ай бұрын
I've tried making Ubuntu and Linux mint my daily driver many times. Can't do it. But for home labbing and running servers it's perfect.
@shiiy5131
@shiiy5131 Ай бұрын
it's just so much more superior, once you try it you never go back lol
@vladislavkaras491
@vladislavkaras491 Ай бұрын
Thanks for the news!
@cyber_space09
@cyber_space09 Ай бұрын
Wow good job I want more info ❤
@yessintaktak9200
@yessintaktak9200 Ай бұрын
Hello john . I am a big fan of your content can you make a roadmaps for us form when need to start 😅❤
@actng
@actng Ай бұрын
Thanks John you explained that very well
@SchooiYT
@SchooiYT Ай бұрын
Nice Video!
@ToniMorton
@ToniMorton Ай бұрын
calculator opens in my nightmares.
@wiertgo
@wiertgo Ай бұрын
I got an ad from you on this video
@anthonymcevans8191
@anthonymcevans8191 Ай бұрын
“It is not by default installed” **laughs in Linux**
@abandoninplace2751
@abandoninplace2751 Ай бұрын
They are identifying files by extension. Nice.
@user-fp7fs9xl2t
@user-fp7fs9xl2t Ай бұрын
Great Content ...
@TheMAZZTer
@TheMAZZTer Ай бұрын
Oof, this is why blacklists can be problematic, with a whitelist they would not have had this problem.
@BaggerPRO
@BaggerPRO Ай бұрын
Except perhaps for the problem of naming this list as "white" 😁
@joshallen128
@joshallen128 Ай бұрын
​@@BaggerPROblock allow lists?
@BaggerPRO
@BaggerPRO Ай бұрын
@@joshallen128 , Yeah, it looks like it's fashionable to call these lists that way now :)
@BillAnt
@BillAnt Ай бұрын
A block list is usually shorter than a white list, but it's just a matter of decision.
@joshallen128
@joshallen128 Ай бұрын
@@BillAnt Deny list because block sounds like black with an accent
@shadflur874
@shadflur874 Ай бұрын
How do u register for that forum?
@planktonfun1
@planktonfun1 Ай бұрын
every vulnerability whether or not its trivial, can and will be leveraged
@ShadowManceri
@ShadowManceri Ай бұрын
I find it very bizarre that you can execute a file in the first place. That seems like a bad idea in many ways.
@user-hp2dr5qc8p
@user-hp2dr5qc8p Ай бұрын
How do you suggest to open a .txt file?
@ShadowManceri
@ShadowManceri Ай бұрын
@@user-hp2dr5qc8p .txt file should be read, not executed.
@johndeaux8815
@johndeaux8815 Ай бұрын
Hate the red border on the thumbnails, I assume I've already watched and scroll past half the time
@sophisticatedserpent1512
@sophisticatedserpent1512 Ай бұрын
The red bars in the thumbnail made me think I already watched this video.
@ernestmugo1765
@ernestmugo1765 Ай бұрын
Right, I thought so too!
@sevuszeld5015
@sevuszeld5015 Ай бұрын
the title of the video is not that nice because i thought it would be a vulnerability that accurs right now. anyways. Thanks for sharing.
@mrhassell
@mrhassell Ай бұрын
Requires Python to be installed in the local path as a global environment variable.
@sa1t938
@sa1t938 16 күн бұрын
it requires the file extension to be registered to the python interpreter, not anything to do with environment variables
@PasqualItizzz
@PasqualItizzz Ай бұрын
Tis the season to find folly, tra la la la la, la la la lol
@Bromon655
@Bromon655 Ай бұрын
3:28 lol. They backed themselves into a corner with that statement.
@allxrise
@allxrise Ай бұрын
They might have been logging something like "There is no any program to open this file-type/mime-type" perhaps? Or they just RCE'd to everyone... Who knows?
@Bromon655
@Bromon655 Ай бұрын
@@allxrise I’m more inclined to believe they were just fabricating a number as an attempt at damage control
@runedust9875
@runedust9875 Ай бұрын
Having a whitelist instead of a blacklist would prob. be more secure and reliable. Basic security not?
@tablettablete186
@tablettablete186 Ай бұрын
I was thinking the same
@xion637
@xion637 Ай бұрын
@@tablettablete186 governed by implicit deny. Also agree.
@user-mk3zz8zn9b
@user-mk3zz8zn9b Ай бұрын
nah, its not think again
@rian0xFFF
@rian0xFFF Ай бұрын
depends on size
@oncetwice6366
@oncetwice6366 Ай бұрын
Who's idea it was to hardcode bunch of files there. They'll just keep updating it every timea new file type that can execute code comes? Sounds like horrible idea.
@higurashinerd
@higurashinerd Ай бұрын
Part of whyI never share diagnostic data with devs. It’s so nosey now
@dimike96
@dimike96 Ай бұрын
Surely some communities would have a very high hit rate for python being installed on a windows machine right?
@crism8868
@crism8868 Ай бұрын
Yup. All data science and AI nerds.
@Bromon655
@Bromon655 Ай бұрын
Anybody even slightly interested in programming has a decent chance of having it installed on their computer. I refuse to believe less than 0.01% of users were affected.
@paulwesley3862
@paulwesley3862 Ай бұрын
​@@Bromon655a) is the 6th most downloaded app - is your grandma programming? b) die this you must use it on your PC. how many people just have it on their phone?
@hackcode2240
@hackcode2240 Ай бұрын
Amo tus videos
@BreadGuy0
@BreadGuy0 Ай бұрын
Everybody be acting gangsta until calculator auto launches
@kipchickensout
@kipchickensout 27 күн бұрын
"Google Photos would like to make Phone calls"
@fokyewtoob8835
@fokyewtoob8835 Ай бұрын
Music to my ears
@kuperrr6776
@kuperrr6776 19 күн бұрын
Hey how can i get an xss is account? i tried and always the same when i create an account "Your account has been declined."
@commanderpaladin
@commanderpaladin Ай бұрын
I like cats. Btw we can all be farmers. No tech no rce problems 😎
@mrfoodarama
@mrfoodarama Ай бұрын
Oooff... thank you John... cant believe im one of those 0.01% .. slackin
@paul-olof
@paul-olof Ай бұрын
Haha so specific but I would've been at risk
@zheil9152
@zheil9152 Ай бұрын
1:48 macOS has it installed by default, last I checked at least
@dom1310df
@dom1310df Ай бұрын
Does mac have a similar concept of file extension associations as on windows, so a pyzw file will open with python by default?
@chiroyce
@chiroyce Ай бұрын
Not anymore, used to have Python 2.x
@momentum9319
@momentum9319 Ай бұрын
what is "flair"
@guilherme5094
@guilherme5094 Ай бұрын
👍Nice.
@benherbst3620
@benherbst3620 Ай бұрын
CRAZY
@manasmahanand732
@manasmahanand732 Ай бұрын
With a bit of social engineering this could have been pretty terrible
@kingoftheorient
@kingoftheorient Ай бұрын
A lot of noodles will be leaked for sure.
@Javv1721
@Javv1721 Ай бұрын
Me as python developer and windows user💀
@Mat2095
@Mat2095 Ай бұрын
But, isn't pyzw supposed to be a zip-archive? That contains a __main__.py? I'm actually surprised this runs at all.
@reijin999
@reijin999 Ай бұрын
yeah but it updates every hour so it's chill
@Pem7
@Pem7 Ай бұрын
2024 is on fire with RCEs🤞🏾
@BU5TER288
@BU5TER288 Ай бұрын
oh no.. now i feel so dirty i cant wash it off
@DoingFedTime
@DoingFedTime Ай бұрын
Bad stuff for many. One of the reasons I always tell people to NOT use this medium.
@aaronguerrero2003
@aaronguerrero2003 Ай бұрын
There is always a way in😉
@Axodus
@Axodus Ай бұрын
Good, they banned my account for no reason.
@furrygem5176
@furrygem5176 Ай бұрын
"Certified rce moment" 💀
@r35p3ct00
@r35p3ct00 Ай бұрын
Такое чувство, что на безопасность всем насрать, только ты можешь себя обезопасить, не кликая на всякое говно
@RebziSquad
@RebziSquad Ай бұрын
Если человек наивный, то его никакая защита не спасет) Однажды мой знакомый запустил подозрительный tampermonkey скрипт в дискорде, говорит "2FA стоит же, чего бояться?". В конечном итоге украли его токен и смогли получить доступ к аккаунту.
@EnitinEnitin
@EnitinEnitin 14 күн бұрын
This is why you should use whitelists instead of blacklists.
@legendarycuber9205
@legendarycuber9205 Ай бұрын
I got a SYNK ad with John right before the video and was confused why there was a skip button 😂
@user-mc8xt1iq7c
@user-mc8xt1iq7c Ай бұрын
bro, youtube just showed me your ad, on your own video. theyre wasting your ad money
@SimplyGamer605
@SimplyGamer605 Ай бұрын
Hey, nice video, but just one thing. Your audio and video dosent seem to be perfectly in sync and its getting on my nerves
@ZaberfangX
@ZaberfangX Ай бұрын
Is it safer just makes a user that is not admin user? So if code ran its needs admin user right as default user windows always user are admin?
@lunaxquinn
@lunaxquinn Ай бұрын
Linux users are way more likely to have python installed out of the box so i wouldn't call this a "very specific" exploit.
@maktiki
@maktiki Ай бұрын
I think the problem is Windows. It runs everything too fast without permission.
@StealthSec-BugBounty
@StealthSec-BugBounty Ай бұрын
Ohh no
@rigsshiver823
@rigsshiver823 Ай бұрын
tf is going on .. rce 💀
@IlIlIIlIlIlIlIlIl
@IlIlIIlIlIlIlIlIl Ай бұрын
Good thing I run it in a vm on a vps
@Luzum
@Luzum Ай бұрын
vm escape + pyzw = your vps gets owned
@luizzeroxis
@luizzeroxis Ай бұрын
How is this RCE? It's just running the code that someone sent to you. There's no difference between that and opening an exe.
@definitelyno
@definitelyno Ай бұрын
You can add an extra dot at the end. Windows -> Run -> 'calc.exe.' -> Enter opens calc. Does that work to bypass.
@LibraryOFSounds
@LibraryOFSounds Ай бұрын
Yeah uae does not like private messaging.
@rafayahmed6259
@rafayahmed6259 Ай бұрын
😅😅
@LibraryOFSounds
@LibraryOFSounds Ай бұрын
@@rafayahmed6259 Do you know uae connection with then twitter ? Or the documentary about state hackers of usa training uae agents. That documentary is so interesting
@impostorsyndrome1350
@impostorsyndrome1350 Ай бұрын
I have Python installed on Windows computer... It helps with learning Python programming, idk why people are so against it.
@zombi1034
@zombi1034 Ай бұрын
Yea, not sure why he made it seem like something extremely unusual. I think most people that do any kind of programming and use Windows will have python installed.
@Slada1
@Slada1 Ай бұрын
Why would you learn python if you could not use it? :D
@impostorsyndrome1350
@impostorsyndrome1350 Ай бұрын
@@Slada1 wdym not use it? You can use it to create various programs.
@robotron1236
@robotron1236 Ай бұрын
You should watch Telegrams owners interview with Tucker Carlson. They have like 30 employees and have never spent a dime on advertising. 😂
@entertain8648
@entertain8648 Ай бұрын
Why are you laughing though?
@couldntgivafuk
@couldntgivafuk Ай бұрын
I've never liked the idea of "allow" and "deny" list... just deny all and allow the user to specify.
@FRITTY12348546
@FRITTY12348546 Ай бұрын
But was it a typo :D
@user-fe5mz9mq5o
@user-fe5mz9mq5o Ай бұрын
i found this exploit 2 years ago... never posted anything about it
@rodricbr
@rodricbr Ай бұрын
this is such an interesting rce tho... lol
@kipchickensout
@kipchickensout 27 күн бұрын
python on windows, not that unnatural
@Reelix
@Reelix Ай бұрын
"Windows that has python installed" you claim is extremely odd. That... Is an extremely odd statement.
@jamesciastko8861
@jamesciastko8861 Ай бұрын
What is happening lately? 💀💀
@Aghnanster
@Aghnanster Ай бұрын
Ive heard this is on discord also
@Luzum
@Luzum Ай бұрын
it is not
@adenosinetp10
@adenosinetp10 Ай бұрын
can you stop using the word "stupid" so frequently and often?
@christoferrian
@christoferrian Ай бұрын
hello world
@TheAwillz
@TheAwillz Ай бұрын
Sometimes you guys are very clever with tech but not so clever with people…
@dkizilkaya6839
@dkizilkaya6839 Ай бұрын
This was surely done by purpose. Believe me not.
@YouTubeName-hw1uk
@YouTubeName-hw1uk Ай бұрын
Anf i thought wiiu wansthe only thing that has rce 😂
@oracuda
@oracuda Ай бұрын
how do RCEs still exist in 2024 bro 😭😭😭😭😭
@crlfff
@crlfff Ай бұрын
They are found in everything
@KLR-3
@KLR-3 Ай бұрын
Why do they blacklist file types they believe are unsafe. They should be whitelisting filetypes that are safe. If some new software comes along that belongs in the unsafe catagory they have to know about the related filetype and then add it to the blacklist...
@wafinashwan8242
@wafinashwan8242 Ай бұрын
whitelist would take too long.
@erroroliver
@erroroliver Ай бұрын
​@@wafinashwan8242got any quote from a developer?
@johnsmith34
@johnsmith34 Ай бұрын
"Reimplemeent file open confirmations" has a noWarning list, so I think that's done now.
@KLR-3
@KLR-3 Ай бұрын
​@@wafinashwan8242how so?
@johndoublew3060
@johndoublew3060 Ай бұрын
@@wafinashwan8242 how come
@BouleyMusic
@BouleyMusic Ай бұрын
wonder if you could just do the same with .bat file that puts itself in the shell:startup folder upon clicking the "video"
@TheRealJohnJokes
@TheRealJohnJokes Ай бұрын
I edited my comment so no one knows what I said!
@DavidFrankland
@DavidFrankland Ай бұрын
echo y | format c:
@imranapervez1886
@imranapervez1886 Ай бұрын
😊
Fileless Malware Analysis & PowerShell Deobfuscation
26:42
John Hammond
Рет қаралды 7 М.
Tracking Cybercrime on Telegram
23:26
John Hammond
Рет қаралды 261 М.
ПООСТЕРЕГИСЬ🙊🙊🙊
00:39
Chapitosiki
Рет қаралды 20 МЛН
1 класс vs 11 класс (неаккуратность)
01:00
어른의 힘으로만 할 수 있는 버블티 마시는법
00:15
진영민yeongmin
Рет қаралды 13 МЛН
98% Cloud Cost Saved By Writing Our Own Database
21:45
ThePrimeTime
Рет қаралды 287 М.
Where People Go When They Want to Hack You
34:40
CyberNews
Рет қаралды 966 М.
Genisys : Telegram Information Gathering Tool
3:22
KISEC
Рет қаралды 13 М.
The Apex Legends Hacker: Destroyer2009
21:47
John Hammond
Рет қаралды 115 М.
Finding WEIRD Typosquatting Websites
24:26
John Hammond
Рет қаралды 320 М.
All PHP Applications are Vulnerable
8:37
Mental Outlaw
Рет қаралды 126 М.
Access Location, Camera  & Mic of any Device 🌎🎤📍📷
15:48
zSecurity
Рет қаралды 2,1 МЛН
Finding WEIRD Devices on the Public Internet
27:48
John Hammond
Рет қаралды 223 М.
Bypassing SmartScreen on Web Browsers
17:31
John Hammond
Рет қаралды 57 М.
3 Levels of WiFi Hacking
22:12
NetworkChuck
Рет қаралды 1,5 МЛН
ПООСТЕРЕГИСЬ🙊🙊🙊
00:39
Chapitosiki
Рет қаралды 20 МЛН