All language subtitles for 029 Stagefright Attack-subtitle-en

ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

Next attack is that we can talk about this.

It's a very famous exploit in most of the Android device.

It's a the ability to call this thread stage fright and stage fright was found in 2015.

In a lot of devices and we're going to see how to exploit this vulnerability and to gain access to the

device as well.

But the objective of this lecture and the other lectures it's not just to follow the steps or to execute

some vulnerability and some exploit it.

It's more into to know how to search for a weakness and then know how to get advantage and compromise

device using this weakness.

So we did some search we know that there is a vulnerability called Stage fright and then we the image

or framework which is a meta Sprite to get access to the device.

So let's see how to do this.

I already have my device on the recall and in we'll go to

we'll go to our Kelly Linux machine

and

we're going to open a terminal and open MSF concern so it opens a terminal and type m s f concern and

wait until it's done.

Now I believe by now you start becoming familiar with meter's plate split a free framework because you

know that there is a free one and a paid one still.

Now we don't need to pay anything.

You can utilize the free it's an excellent tool.

And we're going to search once it's START we're going to search for stage fright.

And I have to say that stagefright allow you to do different kinds of attack including creating an MP

five that if the user opens fire and you'll get access to his device.

But we will not be using this part because this stage fright that allows you to create an MP for it's

a very exhausting process you need to download the file and change your site code and so on.

I'm going to show you how to use this exploit in a very easy way.

So we already found one.

So we're going to type Pew's and I'm going to put the pass for this one use exploit Android browser.

This is the end of it copy and in the east then we're going to type show option to see what option is

needed to execute this exploit.

So show option and as you can see I just need to change one value which is the r s or.

It should be a local IP from whereas the victim would be connected and you pass which is the access

you are I-PASS what access you can have for this device some type set as are the host.

And we're going to put our IP Zakarian next machine IP on 9:26 it upon 1 0 3.

I'm going to keep the port the same way it is and then I'm going to type set.

Sorry

set

you are on the bus.

And you put this the road sign and that's it.

And we type exploit

going to start the handler to wait for the connection.

And what you need to do you need to send the victims this IP.

Now let's send it through an email and open it and see what will happen.

So I'm going to copy that.

And let me open the browser.

We're going to see that you don't have to send it the same way it is right that you can change it using

those Web sites that change this IP to a short in your brain.

So you don't have to worry about you know how I'm going to send him the link because this requires some

social engineering and some website and some tools so it shouldn't be an issue.

Right now I want us to focus on that tech.

And as I keep saying later on you're going to know how to use this set.

But now we are proofing the concept so let me open my main and click on send.

And

let's see.

Please check.

You can do that by sending an S M S or

an email and later during the course when you take some tools and some application that allows you to

spoof Decimus and then go right to my e-mail here that this thing is that I'm trying I am often

and

now getting back to our mobile phone before opening this file or this link.

We're going to check here is status of the.

Nothing is working.

So let me

also go to

here and let's

open my e-mail and refresh

and we can open the e-mail here.

And assumes that I did click on the link.

So let's see what will happen on our machine.

As you can see the open emitter perturbation is actually more on that too is a victim machine.

And if we type on Sishen

minus I believe the stations

really go.

You have to station you can log to any one of source and you have full access on that device.

This is how easy it is.

The effort will be how to convince someone to click on the link and this is actually it's quite easy

because the tools that exist right now will allow you to fake an email or fake an SS or fake immobile

call so it's quite easy to do that.

So most of the Android devices are affected with this vulnerability.

Next election we're going to take some different framework and we're going to see how to compromise

it using this force later on during this course.

I'm going to show you some our how to tune this is zorse attack and how to use them remotely how to

compromise systems that does not exist on the same network and zantac will still the same except we

need to change some network settings specially inside the router.

So we're going to see that later on.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.