All language subtitles for 034 Android Attack 3-subtitle-en

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified) Download
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

In the previous lecture we saw one of that work related to social engineer to get this lecture going

to see a more advanced tech which will allow us to get full access to the Android device.

So let's see how to do this.

Let's go to the chairman and then launch the social engineering tool kit kit

and choose number one.

Then we're going to choose Web site attack vector which is number two like previous one.

So the two but this time we can use meters play a browser exploit miswrote which is number two.

And this will allow us to create a payload associated to the browser.

So once the user click on the link We're going to get emitted retrocession on the victim machine.

And I believe we explained Zometa operative session in a previous election in the section.

So let's see how it will be done and we're going to type number two and here would you like this Web

sites that will include the payload which includes this malicious code that will allow us to access

Android to be from a web template or from a site cloner.

So I'm going to choose a template for simplicity I I'm going to choose any website.

Are you going to do that or port forwarding.

This will be done on a different letterer and this will be needed in case you do that remotely.

I mean you are compromising an Android device that are not on the same network you are doing that for

someone somewhere else in this attack.

This is a basic attack which we are doing this attack in someone on the same network.

So here are going to choose no.

But later on I'm going to create a remote attack and nothing will change only some network sitting need

to be done.

So we're going to do that in a separate lecture.

What is the IP address that will be receives a connection because this is a reverse connection so as

a victim would be connected to me.

I would not be the who can act as a victim and this is I try to bypass any security.

So in our case our IP of the Linux machine is 1 9 2 1 6 8 2 1 0 1 0 3

which template would you like to have Google of required.

Let me have Google one more time.

And here will be is the payload that will be added to the fake website so we can use the number 8 or

number 9 which is the java applet remote code execution.

This would be a message that will give us a full.

I'm going to use number 8 because it's more effective if not is that most of them are Microsoft and

Adobe so only 8 and 9 Araba.

And this just keep getting updated.

I mean maybe it will have a different number of neurons these tools because they keep updating this

list.

Then what do you need to have once you get the payload will be running.

I need to have emitter pressurisation which is number two reverse interpreter which means the clatters

a victim will be connected to my machine because the opposite of reverse is the bind connection which

is my computer connect to the victim and if the victim is behind the firewall or has any security software

this would be dropped.

But when the victim would be connected back to me.

Most probably this will be successful.

So I'm going to use an operator then which port you'll be using.

I mean you receive a connection on your IP which I just wrote one man to and succeeded to under-23.

But you should specify as reporters when and by default they are giving support for 4C which I suggest

you keep the same because this is HTP support and most people are familiar with using such force.

So it will not be suspicion anyway.

And as you can see it's going to take a few seconds and it will be ready what I need to send to the

victim will be the IP of my machine with the port.

So

with dequeue second

minute to pause for a few seconds until they finish and it's done.

Moser So yep this is the IP that you need to sends the victim 1 and 2 and 6 8 1 on screen which is your

local IP with the port number which is full 4C if you are doing that to attack a remote Android device

you need to change this private IP was a public IP.

I just explained in the previous letter.

But not to confuse you we're going to do that right now in a simple way.

And then later on I'm going to have to do that remotely.

So let's jump to our machine and I prepared in an e-mail that will be sent to the victim an email resumes

we're going to see how to manipulate this immensely strong and we're going to type IP 1 and 2 and 6

8 or 200 one seriously call on for four-CD

for Ford City and

I told you previously that we can change that we can choose any short website to change the link instead

of having close bunch of numbers it could be like you are in.

And now let's go to the device.

And then let me open my email

gay code to my email.

See you fresh Here we go and let's see what would happen if we comes.

You mean

see you as you can see we are getting a metropolitan session on the

victim mobile and we explain how to utilize this metal decision.

And by the way you may notice that it will keep closing and opening and another admitted later this

is normal.

After a few times you know it will be stable.

So it's quite easy to like keep trying that until you get a successful session but you're getting the

idea and then you know how using an interpreter session you can get full access to the machine.

This has been explained on a sort of forced transaction.

So once you get the Metropolitan session you've got a full access on the device.

So what we did we created a fake Web site and or web sites that include the payload the malicious payload

and once the victim opens the website we get a full access on the machine.

It's different than the previous lecture where we just capture the username and password.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.