Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Know before we dive into the course content I'd like to give you a teaser or a taste of what you'll
be able to do by the end of the course.
So this is going to be one example.
That's based on one topic that's covered in one subsection of the course.
So by the end of the Course you'll be able to do so much more.
But I chose to make a teaser on this topic because first of all it's the last topic explained in the
course.
To have to go through the whole course to know how to do this.
Also I think this topic can be used to make a really nice teaser now because this is a teaser lecture.
I'm not going to explain the technical aspect of how am I doing this because I'm going to teach you
how to do this as you go through the course for now just sit back and enjoy this lecture.
And after this lecture we're going to dive into the course content where you learn how to do things
like this and much much more.
So we're going to try to hark into this Windows machine from this candy machine.
Now this Windows machine is connected to the same network as this Callimachi And so this attack will
work whether the windows and the Callimachi are connected to the same Wi-Fi network or if they're connected
to the same ethernet or wired network.
Now as you can see the Callimachi is full of weird text.
That's because I've already executed all of the attack.
So I'm listening for incoming connections here.
I'm a piece spoofing the Windows machine here.
I'm running the script that's doing all the magic in here.
Basically the script that's running and this terminal tab in here can be used to convert any file that
any person downloads to a trojan made out of that file.
As long as the person is connected to the same network as us.
Now this script is not something that we're just going to download and install.
You're going to learn how to actually think and write scripts like this one.
So throughout the course we're going to implement the script ourselves use in Python and man in the
middle proxy so the script is already running.
And let's go and see it in action.
So let's say the target person wants to download Firefox.
So we're just going to go to Firefox dot com
we get Firefox Web site.
Now keep in mind Firefox Web sites use TTP.
So it's supposed to be secure against attacks like this one.
Now the user is just going to go and download Firefox from the bottom that the Web site offers.
And then the Firefox installer is going to get downloaded.
As you can see here then I'm just going to go to my downloads to show you.
You can see we have a file with an installer icon.
It's called Firefox installer.
If we double click this it's an X..
So it's asking me if I want to run this DXi I'm going to say yes I want to install Firefox.
And as you can see we have the publisher Firefox which is all good.
We're going to say yes please install this for me and then we're going to get the Firefox installer.
So everything looks perfect.
Nothing suspicious at all.
If we go to the candy machine you'll see that we actually gained access to this computer.
And now we actually have full control over this computer and I can do whatever I want with it so I can
download upload files at the files install programs install viruses log.
The key is or do anything I want I can even access the computer resources such as the mike or the webcam.
So as you know I like to run the webcam in my teaser lectures just to convey the idea that I have full
control over the computer.
So I'm just going to do webcams Trium to open the web cam of the hacked computer.
And as you can see you'll see me through the webcam of the windows computer.
Now I'm going to close this and this is not all that I want to show you.
Know this script will also work with other file types because they're going to understand how this works
and how to implement it yourself.
You're going to be able to adapt it to get it to work with any file type.
So let me close this so I'm going to do Control-C exploit or sorry exit first to close this connection.
So right now I close my connection with the hacked machine.
I don't have control over it anymore.
And I'm going to do exploit again.
And now I'm going to go to the Windows machine and I'm going to close this and I'm going to try to download
a PDA if I'm just going to try to open a normal PDA or file.
So let's say the target wants to learn about network security.
So they're going to look for network security PBF that's go to the first result in here I'm going to
click on that.
Now as you can see this got downloaded as a zip file.
So if I go to my downloads you'll see I have a zip file called security I'm going to extract this here.
And as you can see I have a PDA a book called security has a PDA icon.
If we double click this we will get our book about network security or we can learn about the different
aspects of network security.
But if we go to the Callimachi And again you can see that we have full control over the machine we got
an interpreter connection.
Again just as an example I'm going to run the Web stream to show you that I got full control and I can
access the webcam.
And here we go access and the webcam through the hacked Windows machine.
Now as I said this is just a taste of what you'll be able to do.
This is not everything that's going to be covered in the course.
This is only covered in one subsection of the course and you're going to understand exactly how to do
this and how to write the tool that's used to run this attack.
So you're going to be able to use the same knowledge to implement other man in the middle tools that
run your own attack ideas.
Throughout the course we're going to learn a lot more than just this.
And with everything that you're going to learn you're going to learn it in details.
And we're going to break it down into small components so that you understand how they work and you
can combine them together to run your own attack ideas.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.