0:00 Music 0:07 What can be, you know, usually hacked, right? 0:13 So this is like, obviously not the full list. 0:16 This is just an example of what can be hacked and how. 0:22 So websites. 0:24 Websites are hacked daily. 0:26 How to hack website without even hacking it. 0:29 It's taking like five seconds to find some database in the internet. 0:36 I'm not talking about already compromised database. 0:39 I'm not talking about the forums where you can buy it or torrents where you can download. 0:46 Enormous amount of databases. 0:48 There are crazy amount of databases and leaks which you can buy, but you don't even need to do it because you can buy now services which are selling this stuff. 0:57 So index of. 1:01 So what is index of is if we are running usually Apache service, a server, 1:11 that Apache server by default, if you didn't input index.html page or index.php page, it will show that folder. 1:21 Or if you don't have access. 1:23 So there are only three criteria. 1:28 If folder 1:30 doesn't have index.html or you see it has header.php. 1:36 If it will be index.php or index.html or htaccess, which will not allow you to access here, by default, this server is showing everything what is in this directory by default. 1:52 So, 1:56 Yeah, it looks like this. 1:58 And so what can we do with this, right? 2:03 We can just go and write maybe like dump.zip. 2:09 And what we will see, it's even maybe SQL or backup, whatever. 2:18 So we can put a scale here just to make it stronger. 2:21 So here we can see that this is already known Google Dork. 2:27 No. 2:29 And in this website, you can also see some other Google dorks. 2:33 What means dork? 2:34 Dork is just exactly what I'm doing right now. 2:38 Is you are searching for something in the internet using the commands which are allowed to be used in the Google. 2:48 So let's see what is this. 2:51 Database. 2:53 This is database and this is website backup. 2:56 This is 100% sure. 2:58 So let's see, who is this guy? 3:03 No information. 3:04 Whatever. 3:05 What about this one? 3:08 Again, same stuff. 3:10 Some trading. 3:13 They just have the backup right there. 3:16 Why this happened? 3:17 Because they didn't put the index or HTML file. 3:23 And this one is running on the Lightspeed web server. 3:27 So Lightspeed web server is doing the same as Apache. 3:31 So we can just spend some time just navigating the internet. 3:35 And you see Google is trying to block me because of such activity. 3:40 So we can just keep going and going and collecting all those databases. 3:46 And this database is 10 megabyte. 3:53 This is 360 megabyte. 3:59 Some update. 3:59 I don't know. 4:00 So database, let's go check. 4:05 And what is this? 4:06 Yeah, database PHP. 4:08 So migrations, maybe migrations, tables. 4:16 So this is like some PHP websites. 4:18 And I'm more interested to find the zipper chive or a scale. 4:22 But I'm just showing you. 4:23 You can just navigate. 4:25 And basically, it is 2024. 4:30 And this is post-terminal or what? 4:32 This is also interesting. 4:34 What is this? 4:35 Look. 4:37 They just keep it open in their subdomain. 4:41 So if you will remove subdomain, let's see what is this company doing. 4:47 Whatever, they just selling something. 4:50 This is Arabic hospital, no, hospital street. 4:58 somewhere. 4:59 So it doesn't even matter, right? 5:04 They have the post dot something. 5:07 So this is subdomain. 5:08 And in that subdomain, you can just navigate and see so much of 5:14 data and you can just download it, right? 5:16 You can just click here and you will download. 5:18 We're not going to do it. 5:19 And I don't suggest you to do it as well because this is, and this is the POS database. 5:27 POS means 5:29 And the terminal. 5:31 What is POS? 5:34 I want to show you. 5:35 Now Google is going, you see. 5:38 To throttle me. 5:40 So what is post-terminal? 5:42 Point of sale. 5:44 I think most of you have seen it everywhere. 5:47 So maybe there are like tiny chances that this is post-terminal for those guys. 5:54 And 5:56 that PostTerminal has the database, and that database is just stored in the clear net in the unprotected hosting. 6:06 So I'm just giving you an example. 6:08 This is the post terminal. 6:09 I just showed you the web server, right? 6:12 Like website. 6:13 Let's talk a little bit more about Shodan. 6:18 And let's just go and put like elastic search. 6:25 So why am I even talking about Elasticsearch? 6:31 What is... 6:33 And look, we are talking about low-hanging fruits. 6:37 We are not talking about some crazy stuff. 6:41 And low-hanging fruits are something that hackers are just doing. 6:47 Massively. 6:49 So you should understand that when you target somebody, you can use those techniques as well. 6:55 But the chances that they will work, 6:58 like 2, 7%, 2, 5%. 7:01 But if you're using like 50 techniques, it means that you have like good chances that you will find low hanging fruit in this company, right? 7:11 But you're focusing one company, you're not focusing like abroad. 7:15 But let me show you something else. 7:18 So just to maybe to finish the website, compromise, I will show you another low-hanging fruit. 7:26 So like .com, again, SQL error. 7:32 So what is SQL error? 7:37 Okay, let's make it easier. 7:39 Let's go to chat and say when we have, let me hide that stuff, how to use it. 7:52 When we have a SQL error in MySQL and in MS SQL, how does it look? 8:02 So I need exactly to understand how error looks like. 8:08 Nice. 8:09 Now I have... 8:11 Different errors from the database. 8:13 Why do I need to collect errors? 8:16 You'll ask me. 8:17 I will show you. 8:18 I'm just taking this one, going to the Google, which already doesn't like what we are doing for a long time. 8:26 And I will just input it here. 8:29 It is throttling me, obviously. 8:33 So, let's keep going. 8:41 It really trotted me. 8:44 Now, nice, nice, nice. 8:47 I already see it. 8:49 This website can be basically compromised within five minutes. 8:56 They are selling phones and, you know, they have online store. 9:01 And everything is okay with them. 9:03 And they just created the website in 2025. 9:05 So this is not something, you know, from 1992. 9:09 This is new website and looks like guys are in China and they are just selling stuff. 9:18 So when you find similar website on the Google, 9:22 I have nothing against this website or anything else, but I'm just saying, when you are just buying some stuff in the internet, just click buy now, whatever, they have it in Amazon, Japan, Canada, 9:37 I don't know. 9:39 And you can just follow what they are proposing here. 9:42 I think that this website does not even have the ability to buy here, right? 9:47 Do they have this ability? 9:53 Maybe, maybe. 9:54 But I think they're just like reselling on the marketplaces. 9:57 But it doesn't matter. 9:59 Doesn't matter. 9:59 This is just an example. 10:01 So in this example, I wanted to show you that this website has this type of 10:09 error. 10:10 And why does error occur? 10:13 Because we can see that it looks like they don't, for example, have the article number 95, or it was deleted, or something like this. 10:23 And we can see that, let's reconstruct it. 10:28 Can you reconstruct this query? 10:35 Reconstruct this query, right? 10:39 I know I don't need to change the grammar because chat is smart enough, but yes, let's reconstruct it. 10:47 So this is what is in the backend. 10:54 This is what's used in the backend. 10:57 So does it look like a SQL injection? 11:07 not automatically means. 11:08 Okay. 11:09 Maybe, maybe it's not automatically means. 11:13 I agree with this. 11:14 But the idea here is that this pattern, if I see such pattern, I automatically try to play around with the parameters here. 11:28 And after, I just run the SQL map, and the SQL map will tell me if this stuff is really vulnerable or not. 11:39 Why SQL map is better than me doing this manually? 11:44 I will tell you why. 11:47 In a second, using their facts. 11:51 So 10,500 commits done by a big amount of extremely smart guys, 139 people who are specializing in doing SQL injection. 12:06 They created this tool. 12:07 So that tool definitely can be a little bit smarter than the guy who is trying to understand blindly what is in the backend. 12:19 Even if you have the source code of that website, even with all the knowledges, that stuff has a lot of plugins. 12:33 you can try to run SQL map inside your Kali Linux sudo apt install SQL map. 12:45 If you've never seen it, it's time to install it maybe. 12:50 And again, I don't suggest you to run ever, ever, just ever any tools against any websites which are not authorizing you to do it. 13:05 Why? 13:06 Because accidentally you can cause this website to go down. 13:11 Accidentally, I will give you an example. 13:14 Accidentally, you're running the web scanner, which... 13:19 Accidentally accesses the admin panel because this happened to one of my colleagues and it was legitimate penetration testing, legitimate. 13:28 And he was scanning the website in production for penetration testing and he ran web scanner which accessed admin panel 13:38 And it was just clicking around that web scanner automatically and just deleted the full database of all clients and all the stuff which was on that website. 13:50 Yeah, the good thing that it was resolved normally. 13:53 But I'm just saying that guy on the real penetration testing with a real client who didn't really complain because he 14:02 He signed all the documents and he understood that it can be damaged. 14:06 And he provided the production. 14:07 He didn't provide the staging. 14:09 And he had the backups because it was part of the checklist that you should have the backup. 14:15 And he said he had the backup and he had to spend time to put it back up again. 14:20 So what I'm just saying, when you are trying to attack any website, which you found using the dorks, which I showed or whatever, guys, it can be jail time. 14:32 I'm not kidding about that one. 14:35 This can be jail time. 14:36 And I'm saying this because I worked in cyber police. 14:40 And I was doing jail time for other guys. 14:42 I didn't want to do it, but this is the law which they were breaking, unfortunately for them. 14:52 I will just show you. 14:54 Yes. 14:55 So it looks like this. 14:59 So you don't want to be that guy who's standing near the wall and telling, oh, blah, blah, blah, blah. 15:05 So, yeah. 15:09 This, yeah. 15:13 And the guy will come and just start to sniff your computer and he will definitely find all what is needed. 15:21 So, yeah, you don't want such guys to come and ask. 15:25 All those questions. 15:26 So that stuff is not from movies. 15:29 That stuff is real. 15:32 So if you are doing the criminal activities, don't think that it's not going to be mentioned by special forces, because if you are causing the damage, 15:47 People just go report after it becomes official request. 15:53 And that official request can even become global. 15:56 So don't play around with that stuff. 16:01 Don't try to collect databases. 16:03 Don't try to sell them. 16:04 Don't try to do any legal activities because there are plenty of room in cybersecurity where you can do it legally. 16:12 So I'm just telling you right away. 16:15 Obviously, if you will go to the news, you will see that the guys are hacking databases. 16:21 Crypto, blackmailing, and it's like 50, 100 millions. 16:24 Okay, this is up to them, and they're taking those risks. 16:28 That's it. 16:29 So this is what they chose.
0:00 Music 0:07 What can be, you know, usually hacked, right? 0:13 So this is like, obviously not the full list. 0:16 This is just an example of what can be hacked and how. 0:22 So websites. 0:24 Websites are hacked daily. 0:26 How to hack website without even hacking it. 0:29 It's taking like five seconds to find some database in the internet. 0:36 I'm not talking about already compromised database. 0:39 I'm not talking about the forums where you can buy it or torrents where you can download. 0:46 Enormous amount of databases. 0:48 There are crazy amount of databases and leaks which you can buy, but you don't even need to do it because you can buy now services which are selling this stuff. 0:57 So index of. 1:01 So what is index of is if we are running usually Apache service, a server, 1:11 that Apache server by default, if you didn't input index.html page or index.php page, it will show that folder. 1:21 Or if you don't have access. 1:23 So there are only three criteria. 1:28 If folder 1:30 doesn't have index.html or you see it has header.php. 1:36 If it will be index.php or index.html or htaccess, which will not allow you to access here, by default, this server is showing everything what is in this directory by default. 1:52 So, 1:56 Yeah, it looks like this. 1:58 And so what can we do with this, right? 2:03 We can just go and write maybe like dump.zip. 2:09 And what we will see, it's even maybe SQL or backup, whatever. 2:18 So we can put a scale here just to make it stronger. 2:21 So here we can see that this is already known Google Dork. 2:27 No. 2:29 And in this website, you can also see some other Google dorks. 2:33 What means dork? 2:34 Dork is just exactly what I'm doing right now. 2:38 Is you are searching for something in the internet using the commands which are allowed to be used in the Google. 2:48 So let's see what is this. 2:51 Database. 2:53 This is database and this is website backup. 2:56 This is 100% sure. 2:58 So let's see, who is this guy? 3:03 No information. 3:04 Whatever. 3:05 What about this one? 3:08 Again, same stuff. 3:10 Some trading. 3:13 They just have the backup right there. 3:16 Why this happened? 3:17 Because they didn't put the index or HTML file. 3:23 And this one is running on the Lightspeed web server. 3:27 So Lightspeed web server is doing the same as Apache. 3:31 So we can just spend some time just navigating the internet. 3:35 And you see Google is trying to block me because of such activity. 3:40 So we can just keep going and going and collecting all those databases. 3:46 And this database is 10 megabyte. 3:53 This is 360 megabyte. 3:59 Some update. 3:59 I don't know. 4:00 So database, let's go check. 4:05 And what is this? 4:06 Yeah, database PHP. 4:08 So migrations, maybe migrations, tables. 4:16 So this is like some PHP websites. 4:18 And I'm more interested to find the zipper chive or a scale. 4:22 But I'm just showing you. 4:23 You can just navigate. 4:25 And basically, it is 2024. 4:30 And this is post-terminal or what? 4:32 This is also interesting. 4:34 What is this? 4:35 Look. 4:37 They just keep it open in their subdomain. 4:41 So if you will remove subdomain, let's see what is this company doing. 4:47 Whatever, they just selling something. 4:50 This is Arabic hospital, no, hospital street. 4:58 somewhere. 4:59 So it doesn't even matter, right? 5:04 They have the post dot something. 5:07 So this is subdomain. 5:08 And in that subdomain, you can just navigate and see so much of 5:14 data and you can just download it, right? 5:16 You can just click here and you will download. 5:18 We're not going to do it. 5:19 And I don't suggest you to do it as well because this is, and this is the POS database. 5:27 POS means 5:29 And the terminal. 5:31 What is POS? 5:34 I want to show you. 5:35 Now Google is going, you see. 5:38 To throttle me. 5:40 So what is post-terminal? 5:42 Point of sale. 5:44 I think most of you have seen it everywhere. 5:47 So maybe there are like tiny chances that this is post-terminal for those guys. 5:54 And 5:56 that PostTerminal has the database, and that database is just stored in the clear net in the unprotected hosting. 6:06 So I'm just giving you an example. 6:08 This is the post terminal. 6:09 I just showed you the web server, right? 6:12 Like website. 6:13 Let's talk a little bit more about Shodan. 6:18 And let's just go and put like elastic search. 6:25 So why am I even talking about Elasticsearch? 6:31 What is... 6:33 And look, we are talking about low-hanging fruits. 6:37 We are not talking about some crazy stuff. 6:41 And low-hanging fruits are something that hackers are just doing. 6:47 Massively. 6:49 So you should understand that when you target somebody, you can use those techniques as well. 6:55 But the chances that they will work, 6:58 like 2, 7%, 2, 5%. 7:01 But if you're using like 50 techniques, it means that you have like good chances that you will find low hanging fruit in this company, right? 7:11 But you're focusing one company, you're not focusing like abroad. 7:15 But let me show you something else. 7:18 So just to maybe to finish the website, compromise, I will show you another low-hanging fruit. 7:26 So like .com, again, SQL error. 7:32 So what is SQL error? 7:37 Okay, let's make it easier. 7:39 Let's go to chat and say when we have, let me hide that stuff, how to use it. 7:52 When we have a SQL error in MySQL and in MS SQL, how does it look? 8:02 So I need exactly to understand how error looks like. 8:08 Nice. 8:09 Now I have... 8:11 Different errors from the database. 8:13 Why do I need to collect errors? 8:16 You'll ask me. 8:17 I will show you. 8:18 I'm just taking this one, going to the Google, which already doesn't like what we are doing for a long time. 8:26 And I will just input it here. 8:29 It is throttling me, obviously. 8:33 So, let's keep going. 8:41 It really trotted me. 8:44 Now, nice, nice, nice. 8:47 I already see it. 8:49 This website can be basically compromised within five minutes. 8:56 They are selling phones and, you know, they have online store. 9:01 And everything is okay with them. 9:03 And they just created the website in 2025. 9:05 So this is not something, you know, from 1992. 9:09 This is new website and looks like guys are in China and they are just selling stuff. 9:18 So when you find similar website on the Google, 9:22 I have nothing against this website or anything else, but I'm just saying, when you are just buying some stuff in the internet, just click buy now, whatever, they have it in Amazon, Japan, Canada, 9:37 I don't know. 9:39 And you can just follow what they are proposing here. 9:42 I think that this website does not even have the ability to buy here, right? 9:47 Do they have this ability? 9:53 Maybe, maybe. 9:54 But I think they're just like reselling on the marketplaces. 9:57 But it doesn't matter. 9:59 Doesn't matter. 9:59 This is just an example. 10:01 So in this example, I wanted to show you that this website has this type of 10:09 error. 10:10 And why does error occur? 10:13 Because we can see that it looks like they don't, for example, have the article number 95, or it was deleted, or something like this. 10:23 And we can see that, let's reconstruct it. 10:28 Can you reconstruct this query? 10:35 Reconstruct this query, right? 10:39 I know I don't need to change the grammar because chat is smart enough, but yes, let's reconstruct it. 10:47 So this is what is in the backend. 10:54 This is what's used in the backend. 10:57 So does it look like a SQL injection? 11:07 not automatically means. 11:08 Okay. 11:09 Maybe, maybe it's not automatically means. 11:13 I agree with this. 11:14 But the idea here is that this pattern, if I see such pattern, I automatically try to play around with the parameters here. 11:28 And after, I just run the SQL map, and the SQL map will tell me if this stuff is really vulnerable or not. 11:39 Why SQL map is better than me doing this manually? 11:44 I will tell you why. 11:47 In a second, using their facts. 11:51 So 10,500 commits done by a big amount of extremely smart guys, 139 people who are specializing in doing SQL injection. 12:06 They created this tool. 12:07 So that tool definitely can be a little bit smarter than the guy who is trying to understand blindly what is in the backend. 12:19 Even if you have the source code of that website, even with all the knowledges, that stuff has a lot of plugins. 12:33 you can try to run SQL map inside your Kali Linux sudo apt install SQL map. 12:45 If you've never seen it, it's time to install it maybe. 12:50 And again, I don't suggest you to run ever, ever, just ever any tools against any websites which are not authorizing you to do it. 13:05 Why? 13:06 Because accidentally you can cause this website to go down. 13:11 Accidentally, I will give you an example. 13:14 Accidentally, you're running the web scanner, which... 13:19 Accidentally accesses the admin panel because this happened to one of my colleagues and it was legitimate penetration testing, legitimate. 13:28 And he was scanning the website in production for penetration testing and he ran web scanner which accessed admin panel 13:38 And it was just clicking around that web scanner automatically and just deleted the full database of all clients and all the stuff which was on that website. 13:50 Yeah, the good thing that it was resolved normally. 13:53 But I'm just saying that guy on the real penetration testing with a real client who didn't really complain because he 14:02 He signed all the documents and he understood that it can be damaged. 14:06 And he provided the production. 14:07 He didn't provide the staging. 14:09 And he had the backups because it was part of the checklist that you should have the backup. 14:15 And he said he had the backup and he had to spend time to put it back up again. 14:20 So what I'm just saying, when you are trying to attack any website, which you found using the dorks, which I showed or whatever, guys, it can be jail time. 14:32 I'm not kidding about that one. 14:35 This can be jail time. 14:36 And I'm saying this because I worked in cyber police. 14:40 And I was doing jail time for other guys. 14:42 I didn't want to do it, but this is the law which they were breaking, unfortunately for them. 14:52 I will just show you. 14:54 Yes. 14:55 So it looks like this. 14:59 So you don't want to be that guy who's standing near the wall and telling, oh, blah, blah, blah, blah. 15:05 So, yeah. 15:09 This, yeah. 15:13 And the guy will come and just start to sniff your computer and he will definitely find all what is needed. 15:21 So, yeah, you don't want such guys to come and ask. 15:25 All those questions. 15:26 So that stuff is not from movies. 15:29 That stuff is real. 15:32 So if you are doing the criminal activities, don't think that it's not going to be mentioned by special forces, because if you are causing the damage, 15:47 People just go report after it becomes official request. 15:53 And that official request can even become global. 15:56 So don't play around with that stuff. 16:01 Don't try to collect databases. 16:03 Don't try to sell them. 16:04 Don't try to do any legal activities because there are plenty of room in cybersecurity where you can do it legally. 16:12 So I'm just telling you right away. 16:15 Obviously, if you will go to the news, you will see that the guys are hacking databases. 16:21 Crypto, blackmailing, and it's like 50, 100 millions. 16:24 Okay, this is up to them, and they're taking those risks. 16:28 That's it. 16:29 So this is what they chose.