0:06 There are cyber weapons and you can use the fake color software. 0:13 You can use the voice changing software now with AI deep fakes are getting to the picture. 0:20 And you can deploy malicious captive portal. 0:23 What is malicious captive portal? 0:25 That is great stuff. 0:29 Let me show you what is malicious captive portal. 0:34 I think when you've been in airport, you've seen such stuff. 0:39 So you connect to Wi-Fi and without any question, it is dropping you this stuff. 0:47 It is called... 0:49 Captive portal. 0:50 So that captive portal is very crazy stuff. 0:54 Because let's imagine that we all sit at McDonald's with you. 0:59 And I'm thinking, okay, I want to hug those guys. 1:02 So what I will do? 1:03 I will just create the same 1:07 you know, name SSID for the Wi-Fi, I will call it McDonald's. 1:14 And basically, as long as my signal will be stronger than McDonald's signal, you will connect to me. 1:22 Because your phone works like this. 1:24 It is just, okay, if you have like, for example, big house, and in that big house, 1:30 You have like one router and you want to make sure that that signal is getting around all your big house. 1:38 You buy repeater. 1:41 That repeater is basically repeating that signal. 1:44 So when the guy is just moving around house, he is changing constantly all those devices. 1:53 He's not sitting on that device. 1:54 He's just using SSID of that device. 1:57 So what that means, that malicious guy, he can just create the McDonald's SSID and you will connect to him because, I mean, he will connect to you because your signal is stronger than McDonald's one. 2:12 Additionally, if that attacker is super cool, he can kick you all from McDonald's. 2:19 This is one thing. 2:21 If he's super cool, he can do the DHCP starvation, which means that McDonald's will not be able to assign more IPs. 2:31 I will show you what this means. 2:36 He would just put down the McDonald's network, I can say. 2:42 So what is this? 2:46 What is the HTTP starvation? 2:48 So this router, which we can see here, it has maybe two or three subnets. 2:58 Usually your home router has like one subnet, 192.0.0.0.1. 3:06 From 0.0 to 0.256. 3:11 So here the attack is that you just create big amount of 3:20 MAC addresses, which go there and say, I'm new client, I'm new client, give me IP, give me IP. 3:25 And IP is giving for lease for 24 hours. 3:30 So by sending 256 MAC addresses, you will make sure that you will reserve all IP addresses. 3:38 And when new guy will come, he will try to connect to that router, and that router will say, man, 3:45 I don't have anything for you. 3:47 Lease is full. 3:50 My lease is full. 3:51 You know, I have only 256 IPs. 3:56 I cannot give you more. 3:58 My software is not allowing me to do it. 4:00 So it's not about like hardware. 4:02 It is about software, which is... 4:04 not allowing to provide more IP addresses than specific one. 4:08 So in McDonald's, you can do DHCP starvation. 4:12 So it will not be able to provide you with that ability. 4:18 So people will not be even able to connect there. 4:21 Or you can get those itself. 4:23 You can connect to it. 4:25 Right? 4:25 Like this. 4:26 You can find the router by scanning the local network. 4:31 You will detect the router. 4:33 It will be your gateway. 4:35 Right? 4:35 So we can check it right now. 4:38 So IP config, right? 4:41 So this is our default gateway. 4:45 Right? 4:46 You see, it's asking. 4:47 Login and password. 4:50 So, router password reset. 4:56 So this is already some my discussion with the router. 5:01 Now, if I will start, I just don't want to do it because we will go down. 5:08 But I will show you. 5:11 I will show you. 5:13 So, stress tester. 5:16 So. 5:20 I will add it as a target. 5:23 So, and I will start monitoring. 5:26 So, let's wait a little bit and we will see if it's online or offline. 5:33 Now, we see uptime is good. 5:36 So, our router... 5:37 Which is working for all of you, is giving us the internet. 5:42 Now, what I'm going to do, I'm going to little bit, little bit, for 60 seconds only, attack the router. 5:54 So now I'm attacking it. 5:57 So response time is increasing. 6:00 It means that when I'm attacking it, it is getting the traffic which makes other requests stuck. 6:09 You see? 6:11 It's going like this, like this, like this. 6:12 And after it will be just down. 6:14 I just don't want to put it down. 6:16 So response time is increasing. 6:19 When response time will be five seconds? 6:20 It means it is thinking five seconds. 6:23 between it is replying to me. 6:25 So it is already getting some fails. 6:30 You see? 6:32 Total request. 6:34 So some fails are there already. 6:39 Let's just... 6:42 Yeah, I stopped that attack because in reality, there is a big list of attacks which I can do. 6:50 And that router, it will die. 6:52 That is good router. 6:54 But it will die because it will not be able. 6:57 To get that big amount of threads. 7:03 Let's do 100 just for testing. 7:09 What will happen? 7:10 You see? 7:14 This guy is not happy with us. 7:16 I am sending 100 threads. 7:19 In parallel, I'm connecting 100 times per second to this guy. 7:26 In parallel. 7:27 So you see the response time went like 50 times. 7:33 So if I continue doing this, 7:37 It already got 190 timeouts. 7:42 It means that 200 packages it already lost. 7:48 So I am attacking it. 7:50 I send like 16,000 packages, 212. 7:53 It should be zero. 7:55 Lost. 7:55 Lost should be zero. 7:57 If I put here 1,000, this guy is dead. 8:01 You understand? 8:01 This is like me, me against him. 8:04 My computer against him. 8:06 My computer is stronger than this device. 8:09 It's not going to, you know, to play around for a long time. 8:13 And I have different methods. 8:16 For example, slow lorries. 8:18 We will start with this guy. 8:22 Slow lorries is not connecting back and forth. 8:25 It is connecting and waiting. 8:27 It is like sitting there and saying like, so what? 8:30 So I'm not going to stop. 8:32 So I'm just waiting for your reply. 8:35 I'm sending you little by little data. 8:37 I'm very slow. 8:39 I'm sorry. 8:40 You got the point. 8:40 And it will just collect all the RAM because that stuff has RAM. 8:46 The stuff has, you know, all the... 8:50 We can try slow lorries. 8:56 So you see, our attack was crazy, but now it's getting even more crazier. 9:03 Because low lorries is just, you know, 9:09 Trying to put this guy down. 9:16 My internet is still working. 9:18 I think maybe because I'm on cable. 9:21 But the idea here is that if I will continue doing such a tip, you see it's already red. 9:27 You see red. 9:29 Router was down. 9:31 So it was down for like five seconds. 9:34 Most of the routers, they are using default open VRT or similar firmware, which is not having any protection. 9:46 So most of the home routers, they are not protected. 9:52 Because this is not possible for them to protect such a cheap device and provide additional 10:03 security layers which can consume additional processor time in such a cheap device. 10:11 So this one... 10:12 This one is not cheap stuff. 10:15 Potentially, you can read documentation and understand. 10:18 Maybe it has something. 10:20 90% no. 10:23 The idea here is that I wanted to just to show you that you can play around with that stuff. 10:30 And this can be any website. 10:35 This can be anything. 10:36 Now imagine if you just went to distributed agents, you created like 20 distributed agents. 10:44 With your friends, with hosting, and you're just attacking like some website. 10:50 That website will be dead. 10:52 So you got the point. 10:56 Using technical advantage, you can destroy the router and create your own router. 11:03 And when you create your own router, guys will come to you. 11:08 And basically, you will be able to see their traffic. 11:12 Basically, you will be able to drop them down that captive portal. 11:17 And on that captive portal, malicious captive portal, GitHub. 11:25 So. 11:29 Fake sign-in. 11:31 This is what I wanted to show you. 11:33 So, this is firmware, which you can download. 11:42 You see, this is firmware, which you install on your router. 11:46 For example. 11:48 You can do it on your computer. 11:50 But you can just buy some cheap router, put down some other router, and just download this bin file. 11:59 Bin is basically firmware. 12:03 And people will be just getting that type of, you know, that stuff. 12:09 So when first time they will connect to your Wi-Fi, even unintentionally, they will be connecting to your Wi-Fi unintentionally. 12:18 Do you know that your Wi-Fi is constantly, that your phone is constantly, think about this. 12:25 I'm sure. 12:27 Like you don't even think about this. 12:29 Your phone is constantly sending search signal. 12:36 Your phone is searching for Wi-Fi and exposing the list of Wi-Fi from its list. 12:45 It's not connecting to Wi-Fi. 12:48 It is searching that Wi-Fi and asking, where is this Wi-Fi? 12:52 Where is this Wi-Fi? 12:53 And the most important part from this one. 12:56 If you are a attacker, you can see that this phone is searching for McDonald's. 13:02 And you will automatically redeploy your Wi-Fi name to McDonald's or to McDonald's free or to home free or to something like this. 13:16 So you got the point that with Wi-Fi, there are a big amount of crazy tricks and they are connected to social engineering as well.
0:06 There are cyber weapons and you can use the fake color software. 0:13 You can use the voice changing software now with AI deep fakes are getting to the picture. 0:20 And you can deploy malicious captive portal. 0:23 What is malicious captive portal? 0:25 That is great stuff. 0:29 Let me show you what is malicious captive portal. 0:34 I think when you've been in airport, you've seen such stuff. 0:39 So you connect to Wi-Fi and without any question, it is dropping you this stuff. 0:47 It is called... 0:49 Captive portal. 0:50 So that captive portal is very crazy stuff. 0:54 Because let's imagine that we all sit at McDonald's with you. 0:59 And I'm thinking, okay, I want to hug those guys. 1:02 So what I will do? 1:03 I will just create the same 1:07 you know, name SSID for the Wi-Fi, I will call it McDonald's. 1:14 And basically, as long as my signal will be stronger than McDonald's signal, you will connect to me. 1:22 Because your phone works like this. 1:24 It is just, okay, if you have like, for example, big house, and in that big house, 1:30 You have like one router and you want to make sure that that signal is getting around all your big house. 1:38 You buy repeater. 1:41 That repeater is basically repeating that signal. 1:44 So when the guy is just moving around house, he is changing constantly all those devices. 1:53 He's not sitting on that device. 1:54 He's just using SSID of that device. 1:57 So what that means, that malicious guy, he can just create the McDonald's SSID and you will connect to him because, I mean, he will connect to you because your signal is stronger than McDonald's one. 2:12 Additionally, if that attacker is super cool, he can kick you all from McDonald's. 2:19 This is one thing. 2:21 If he's super cool, he can do the DHCP starvation, which means that McDonald's will not be able to assign more IPs. 2:31 I will show you what this means. 2:36 He would just put down the McDonald's network, I can say. 2:42 So what is this? 2:46 What is the HTTP starvation? 2:48 So this router, which we can see here, it has maybe two or three subnets. 2:58 Usually your home router has like one subnet, 192.0.0.0.1. 3:06 From 0.0 to 0.256. 3:11 So here the attack is that you just create big amount of 3:20 MAC addresses, which go there and say, I'm new client, I'm new client, give me IP, give me IP. 3:25 And IP is giving for lease for 24 hours. 3:30 So by sending 256 MAC addresses, you will make sure that you will reserve all IP addresses. 3:38 And when new guy will come, he will try to connect to that router, and that router will say, man, 3:45 I don't have anything for you. 3:47 Lease is full. 3:50 My lease is full. 3:51 You know, I have only 256 IPs. 3:56 I cannot give you more. 3:58 My software is not allowing me to do it. 4:00 So it's not about like hardware. 4:02 It is about software, which is... 4:04 not allowing to provide more IP addresses than specific one. 4:08 So in McDonald's, you can do DHCP starvation. 4:12 So it will not be able to provide you with that ability. 4:18 So people will not be even able to connect there. 4:21 Or you can get those itself. 4:23 You can connect to it. 4:25 Right? 4:25 Like this. 4:26 You can find the router by scanning the local network. 4:31 You will detect the router. 4:33 It will be your gateway. 4:35 Right? 4:35 So we can check it right now. 4:38 So IP config, right? 4:41 So this is our default gateway. 4:45 Right? 4:46 You see, it's asking. 4:47 Login and password. 4:50 So, router password reset. 4:56 So this is already some my discussion with the router. 5:01 Now, if I will start, I just don't want to do it because we will go down. 5:08 But I will show you. 5:11 I will show you. 5:13 So, stress tester. 5:16 So. 5:20 I will add it as a target. 5:23 So, and I will start monitoring. 5:26 So, let's wait a little bit and we will see if it's online or offline. 5:33 Now, we see uptime is good. 5:36 So, our router... 5:37 Which is working for all of you, is giving us the internet. 5:42 Now, what I'm going to do, I'm going to little bit, little bit, for 60 seconds only, attack the router. 5:54 So now I'm attacking it. 5:57 So response time is increasing. 6:00 It means that when I'm attacking it, it is getting the traffic which makes other requests stuck. 6:09 You see? 6:11 It's going like this, like this, like this. 6:12 And after it will be just down. 6:14 I just don't want to put it down. 6:16 So response time is increasing. 6:19 When response time will be five seconds? 6:20 It means it is thinking five seconds. 6:23 between it is replying to me. 6:25 So it is already getting some fails. 6:30 You see? 6:32 Total request. 6:34 So some fails are there already. 6:39 Let's just... 6:42 Yeah, I stopped that attack because in reality, there is a big list of attacks which I can do. 6:50 And that router, it will die. 6:52 That is good router. 6:54 But it will die because it will not be able. 6:57 To get that big amount of threads. 7:03 Let's do 100 just for testing. 7:09 What will happen? 7:10 You see? 7:14 This guy is not happy with us. 7:16 I am sending 100 threads. 7:19 In parallel, I'm connecting 100 times per second to this guy. 7:26 In parallel. 7:27 So you see the response time went like 50 times. 7:33 So if I continue doing this, 7:37 It already got 190 timeouts. 7:42 It means that 200 packages it already lost. 7:48 So I am attacking it. 7:50 I send like 16,000 packages, 212. 7:53 It should be zero. 7:55 Lost. 7:55 Lost should be zero. 7:57 If I put here 1,000, this guy is dead. 8:01 You understand? 8:01 This is like me, me against him. 8:04 My computer against him. 8:06 My computer is stronger than this device. 8:09 It's not going to, you know, to play around for a long time. 8:13 And I have different methods. 8:16 For example, slow lorries. 8:18 We will start with this guy. 8:22 Slow lorries is not connecting back and forth. 8:25 It is connecting and waiting. 8:27 It is like sitting there and saying like, so what? 8:30 So I'm not going to stop. 8:32 So I'm just waiting for your reply. 8:35 I'm sending you little by little data. 8:37 I'm very slow. 8:39 I'm sorry. 8:40 You got the point. 8:40 And it will just collect all the RAM because that stuff has RAM. 8:46 The stuff has, you know, all the... 8:50 We can try slow lorries. 8:56 So you see, our attack was crazy, but now it's getting even more crazier. 9:03 Because low lorries is just, you know, 9:09 Trying to put this guy down. 9:16 My internet is still working. 9:18 I think maybe because I'm on cable. 9:21 But the idea here is that if I will continue doing such a tip, you see it's already red. 9:27 You see red. 9:29 Router was down. 9:31 So it was down for like five seconds. 9:34 Most of the routers, they are using default open VRT or similar firmware, which is not having any protection. 9:46 So most of the home routers, they are not protected. 9:52 Because this is not possible for them to protect such a cheap device and provide additional 10:03 security layers which can consume additional processor time in such a cheap device. 10:11 So this one... 10:12 This one is not cheap stuff. 10:15 Potentially, you can read documentation and understand. 10:18 Maybe it has something. 10:20 90% no. 10:23 The idea here is that I wanted to just to show you that you can play around with that stuff. 10:30 And this can be any website. 10:35 This can be anything. 10:36 Now imagine if you just went to distributed agents, you created like 20 distributed agents. 10:44 With your friends, with hosting, and you're just attacking like some website. 10:50 That website will be dead. 10:52 So you got the point. 10:56 Using technical advantage, you can destroy the router and create your own router. 11:03 And when you create your own router, guys will come to you. 11:08 And basically, you will be able to see their traffic. 11:12 Basically, you will be able to drop them down that captive portal. 11:17 And on that captive portal, malicious captive portal, GitHub. 11:25 So. 11:29 Fake sign-in. 11:31 This is what I wanted to show you. 11:33 So, this is firmware, which you can download. 11:42 You see, this is firmware, which you install on your router. 11:46 For example. 11:48 You can do it on your computer. 11:50 But you can just buy some cheap router, put down some other router, and just download this bin file. 11:59 Bin is basically firmware. 12:03 And people will be just getting that type of, you know, that stuff. 12:09 So when first time they will connect to your Wi-Fi, even unintentionally, they will be connecting to your Wi-Fi unintentionally. 12:18 Do you know that your Wi-Fi is constantly, that your phone is constantly, think about this. 12:25 I'm sure. 12:27 Like you don't even think about this. 12:29 Your phone is constantly sending search signal. 12:36 Your phone is searching for Wi-Fi and exposing the list of Wi-Fi from its list. 12:45 It's not connecting to Wi-Fi. 12:48 It is searching that Wi-Fi and asking, where is this Wi-Fi? 12:52 Where is this Wi-Fi? 12:53 And the most important part from this one. 12:56 If you are a attacker, you can see that this phone is searching for McDonald's. 13:02 And you will automatically redeploy your Wi-Fi name to McDonald's or to McDonald's free or to home free or to something like this. 13:16 So you got the point that with Wi-Fi, there are a big amount of crazy tricks and they are connected to social engineering as well.