0:00 Music 0:07 Let's talk a little bit more about servers. 0:10 So in the websites, I just show you two quick, super quick items, how guys are hacking the websites with zero effort. 0:21 Zero effort. 0:22 SQL injection plus SQL map. 0:27 And I want to show you something funny. 0:30 That is Katusha. 0:33 Katusha. 0:34 It is already deprecated. 0:38 Credit card. 0:40 So let me show you. 0:43 That is really funny stuff. 0:48 SQL injection. 0:52 That was kind of like private software. 0:55 Not that easy even to find. 0:58 Katusha. 0:59 So let me show you this one. 1:03 That, first of all, I was at house of the guy who created that stuff. 1:09 And he was arrested, I can say. 1:14 And what he was doing, this guy. 1:21 This guy was part of the group who created the hacking tool in 2017. 1:29 And what he was doing, basically, he was using the door king, which I showed you. 1:34 Using Bing, using Google, using Yahoo, he was finding a big amount of websites which are potentially vulnerable to a scale injection. 1:42 After that one, he was running this software, Arachne Web Scanner. 1:55 So this web scanner, he was running it. 2:01 It was, and until now it's open source and it can detect SQL injection. 2:07 So. 2:09 Again, the script was to find potentially vulnerable websites. 2:15 after to run Arachne to verify the type of SQL injection, because there are like plenty of them, right? 2:27 And after, when it was verified, he was sending it to SQL map. 2:32 And after, it was downloading full database. 2:36 And extracting credit cards and storing it in other database. 2:42 So when you buy Katusha, all you need to do is pay like $5,000 to the developer, maybe like for a year, lifetime, I don't exactly remember, from $3,000 to like $10,000 or $9,000. 2:56 So they were like, you know, having the different prices. 3:00 And you can buy Katusha and run in your computer, or you can buy it and run in their servers. 3:08 So the idea there that you just pay money and you start to get automatic database update with the credit cards of people. 3:19 And you don't even know which websites, whatever, you don't care. 3:22 You just run it. 3:24 It goes to internet, finds all the potentially vulnerable websites, run web scanner. 3:30 After it runs the expectation tool and just parses for the credit card using regular expressions. 3:36 And that's it. 3:37 Because usually hackers need credit cards, right? 3:40 Especially in 2015, 12, 17, it's already like, you know, 3:45 Not the best time, but I'm just saying that it was the last, you know, the last stuff which was around that credit cards automatic obtaining. 3:58 And we can check the news and see how they were selling it. 4:03 So like this. 4:06 Arachne scanner system, but it was Katusha in reality. 4:12 And this is the website. 4:14 So it's written here the amount of, think about this, amount of websites is more than 100,000. 4:25 200 websites are now 4:28 under scanning. 4:30 So it was like just going crazy. 4:34 $500. 4:37 Pretty cheap. 4:38 I thought it was like more expensive. 4:41 I don't think like 500 is true. 4:45 I don't think this is true because they don't have any proof for this. 4:49 Because I remember it was like expensive. 4:51 You cannot just buy it, the chip. 4:55 Yeah, and it will send you in the Telegram notification that a SQL map dump started. 5:01 And after it will just automatically extract the credit cards. 5:07 So yeah, this is what I wanted just to show you. 5:12 So it took some time from release. 5:16 06. 5:17 They have a pro version and a lot of stuff. 5:22 So those guys were basically doing such automation. 5:29 So you can understand that if that website, 5:36 was used by you, you will be automatically compromised. 5:40 Automatically. 5:41 So you've seen the amount of the websites which were scanned automatically and the credit cards extracted, whatever, phones and stuff. 5:52 So two days ago, 5:55 I deployed the website on the internet two days ago. 5:58 And the first request which I got was not from the guy whom I sent this link because I was on the phone and I said, I just deployed the website. 6:09 Here is the website. 6:11 And I went to check, you know, like debug data. 6:16 Because I access the website, he access the website. 6:18 So the first guy who access the website was Chinese bot. 6:22 And he tried to find .nth file format. 6:28 So what is .nth file? 6:33 Let me show you. 6:35 Google just doesn't want to work. 6:38 Example. 6:40 Example. 6:42 Let me go to GitHub. 6:43 I want to go to GitHub because... 6:45 This will be much faster. 6:48 So I'm going to GitHub. 6:51 To show you. 6:52 GitHub also has the docs. 6:54 Just to be clear, in the GitHub, you can find as much stuff as in the Google or anywhere. 7:00 So I'm going here, .env. 7:05 So let's look this .env. 7:10 This .env doesn't have a lot of stuff. 7:18 If we go here, password, password. 7:25 Now we are in the way of getting the password, right? 7:31 Now we see it's empty. 7:34 But if we will keep scrolling or we will write some script, 7:39 Obviously, we will find some passwords. 7:42 So now, as an example, this database username is root and the password is empty. 7:51 So this is just an example. 7:53 I don't even want to find the password, to be honest, database name. 7:57 So this .n file can be exposed. 8:03 So website.com. 8:08 It can be like this. 8:10 Why this happened? 8:11 Because developer can just commit it in the server. 8:18 And when you will just try to access it, 8:21 You will see the database login, database password. 8:25 It can be anything. 8:26 Inside environment, it can be anything stored like this. 8:31 Look, this is real password. 8:35 They call it example, but, you know, sometimes it can be even environment example, which will have the password or whatever. 8:46 So if you will spend some time here, you will find not only password, you will find like secret 8:56 key, you can find Amazon key, you can find anything, right? 9:03 So be sure that this is another low hanging fruit, which is... 9:11 Look, I'm not sure what is the service. 9:17 But I don't think that it should be exposed. 9:26 So let me hide this panel again. 9:33 Does this item, no, is this public item? 9:42 It is public item. 9:43 No. 9:47 What can I do? 9:48 What can I do with this key? 9:57 Full authentication access. 9:59 Nice. 10:01 I don't even know what is the service, but I already like it. 10:05 So let's go and check it. 10:10 Yeah. 10:11 So basically, some guy just committed his key to this platform. 10:16 I think this is something like no-code platform. 10:20 No code platform, backup your own S3 bucket. 10:23 So that is hosting. 10:25 Clearly, this is the same as I will have the key from Amazon. 10:30 Yes, so this is just one of many, many examples of the low-hanging fruits and how hackers can just compromise. 10:40 Your data, you know, like crazy. 10:45 So let's go to Shodan and let's continue. 10:49 We discussed the servers, right? 10:51 So Shodan. 10:55 Sodan.io Elasticsearch. 11:02 Elasticsearch. 11:03 So currently we can see that there are some Elasticsearch in the internet, right? 11:11 And we can keep going, especially if we have here some commercial account. 11:18 And we can see that this port is 11:22 9200. 11:25 Port 9200. 11:27 Let's see. 11:28 Login. 11:29 Okay. 11:30 Let's use ZoomEye, for example, for this one. 11:37 Elasticsearch. 11:44 So Elasticsearch 9200, port 9200. 11:56 Yeah. 11:58 I think there are some websites. 11:59 If we will scan them, they have this port open, most likely. 12:06 So there are some websites. 12:10 This one is Elasticsearch. 12:14 Is it website or is it Elasticsearch? 12:18 I think this is website which is hosted in the Elasticsearch just port. 12:25 So sometimes it can be, I think this one was Elasticsearch, but they removed it, I think. 12:31 So why do I even talk about Elasticsearch? 12:37 And by default, Elasticsearch has AWS or not. 12:47 So think about this. 12:51 You are using one of the fastest database globally. 12:59 To store your data and there is no out. 13:04 Only they start to use it in version number eight. 13:09 So just 13:11 Imagine that for like maybe 10 years or how many years Elasticsearch was open. 13:20 So if you find port 9200, that's it. 13:26 You hacked the website. 13:28 You don't even need to do anything. 13:29 You just download the Elasticsearch. 13:32 Because it doesn't have any authorization or authentication. 13:38 You just go and download the database. 13:42 What about CoachDB and similar ones? 13:48 Create list. 13:51 What do we have here? 13:53 CoachDB, Elasticsearch, MongoDB, Redis, Memcached, Cassandra, and InfluxDB. 14:02 didn't have the authentication. 14:05 So Redis, Memcached, and Cassandra, they keep not having it. 14:11 Just think about this. 14:12 And you can understand that GitHub, CodeDB, 14:20 Cassandra Elasticsearch GitHub. 14:26 I know what it will find. 14:31 Okay, it's not finding fine. 14:34 Google doesn't like me anymore. 14:36 So, our frog. 14:40 So. 14:48 You can check on this tool. 14:52 It can do a lot of interesting activities around finding low-hanging fruits for you. 15:03 It can find CVEs. 15:06 CVEs are basically the web vulnerabilities. 15:12 Also, it can even find Elasticsearch and similar stuff. 15:17 But this tool is not specializing only on this. 15:21 Let me show you a frog. 15:27 Oh. 15:33 So this is the command which you can run. 15:38 And it will find you only high and critical. 15:40 So you can input here like 55 websites, and it will analyze you all the 55 websites real quick. 15:48 Now, this is the list of the database which we just discussed. 15:52 And you should understand that this list was created before ChatGPT or anything like this. 15:58 It was manually analyzed. 16:01 And you can use this tool, Frog House, it's called. 16:08 And you can be amazed that also Docker registry API and Spark and Jenkins 16:17 and Spring Boot and Zabbix and Solr, all those guys are not having authentication by default usually. 16:27 Or it's like default or super easy one. 16:32 Think that in your network, there is already intruder. 16:38 in your computer can be already intruder. 16:41 So whatever you are doing, you should understand that the guy can be in your computer, the guy can be in your network, the malicious guy can be the guy who is sitting near you. 16:53 Maybe he wants to sniff the traffic or to do some crazy activities. 17:00 So the idea here is that you need to always use all the possible techniques to secure the protocol. 17:11 So if you are deploying MySQL, do not use default password. 17:16 Do not use like root, root, root, empty. 17:19 Because I had like a big amount of experience where, for example, 17:25 I was able to scan the server and I found the website. 17:34 And that website basically, I mean, the server had only open website. 17:41 I know that it had the database, but I never seen the database. 17:46 And I was able to find PHPMyAdmin. 17:49 Like an example, what is PHPMyAdmin? 17:53 Let me show you. 17:59 We can even try to find some in Google. 18:06 HP, my admin. 18:09 I think in title. 18:15 I think like this. 18:19 So what is PHPMyAdmin? 18:22 Try demo. 18:24 Okay, we already found the demo. 18:26 So this stuff allows you to connect to your database using the website. 18:36 So let's log out. 18:39 I will show you. 18:40 It's not telling me to look out. 18:41 So basically, just to be clear, this stuff allows you to export database in one minute. 18:48 You just click export. 18:50 Done. 18:52 You just export it. 18:53 It is just demo stuff. 18:55 You can export it and you can even execute the commands here. 18:59 So when you click here, you can execute the commands. 19:04 So the idea here is that you see there is no database port open, but somebody is using the software to manage database. 19:14 And there are a big amount of software which is allowing you to manage database. 19:18 And for some reason, you can think that if you named it like PHP, 19:25 my, my, my admin, nobody will find it, only you, it doesn't mean that nobody will find it. 19:32 Because if somebody will find it and your login and password to database is root empty, the guy will download your database. 19:39 And I had a lot of experience where I was like scanning like local networks and I was finding 19:45 Like, you know, PHP my admin or externally I was finding or whatever. 19:51 And just default login and password were used there. 19:57 So let's see. 19:59 Let me see that stuff. 20:01 So what is the title here? 20:02 Title. 20:04 PHP my admin. 20:05 This is the title. 20:07 So let's try like this. 20:12 Okay. 20:14 Because Google also doesn't like when people are doing the twerking. 20:18 So we are trying to find PHPMyAdmin. 20:22 I don't see a lot of luck of finding it, to be honest. 20:27 But I think you've spent some time. 20:32 Maybe it will be possible to. 20:37 Oh. 20:41 HP my admin. 20:43 Usually it is just in the default pass. 20:55 Let's see. 20:58 No, it's not here. 21:00 So I think you got the point that if you will just spend time to find it, you will find it. 21:11 And if somebody is using 21:15 This is router, router default passwords. 21:19 So if somebody is using PHP, my admin or similar stuff, you will be able to access his database and just download it. 21:27 So this is just, 21:32 some example of hacking the servers and hacking the websites. 21:43 There is another stuff, DB scanner. 21:48 So how it works, we can just open the source code real quick. 21:54 And check. 21:56 So it is allowing you to check the MySQL, the Postgres, the Redis, the MongoDB, and Memcache based on the port. 22:08 And after it is just trying to connect to it. 22:12 That's it. 22:13 This is like only, you know, 100 lines of code and exploit itself. 22:22 So the exploit itself is just usage of default credentials or something. 22:30 You see, so it's trying just to connect to the database using default credentials or empty credentials or like admin or whatever. 22:42 So if this is like only, you know, 100 lines of code and exploit itself. 22:52 So the exploit itself is just usage of default credentials or something. 23:00 You see, so it's trying just to connect to the database using default credentials or empty credentials or like admin or whatever. 23:12 So if this is like only, you know, 100 lines of code and exploit itself. 23:20 So the exploit itself is just usage of default credentials or something. 23:28 You see, so it's trying just to connect to the database using default credentials or empty credentials or like admin or whatever. 22:43 example of elastic search. 22:45 He, nothing. 22:48 Zero. 22:51 If we are taking this source code, maybe we want to have some clarification. 22:58 Let me know exactly what is doing and which payload it is using. 23:17 Default credential login, big password, brute force, authentication service. 23:21 Basically what I told you. 23:24 So it is trying the root password for MySQL or SA, this is super admin, trying to connect to using super admin to MS SQL or for Oracle, 23:39 it is using Oracle user and Oracle pass default. 23:43 SIS, it uses SIS system. 23:46 The same for Postgres. 23:49 It is using the user called Postgres. 23:54 And for Redis, it is just... 23:59 To authenticate using the info. 24:03 So if Redis will reply to info, it is like getting the Redis version. 24:09 It means it's, you know, you can just connect to it. 24:13 The same goes for MongoDB, Memcache, and Elasticsearch, just like this. 24:19 So when you go to Elasticsearch to get categories and master, you see all the data. 24:26 This is just to answer your question. 24:27 How do you do it? 24:28 Just through browser. 24:31 Like this. 24:33 In Elasticsearch.
0:00 Music 0:07 Let's talk a little bit more about servers. 0:10 So in the websites, I just show you two quick, super quick items, how guys are hacking the websites with zero effort. 0:21 Zero effort. 0:22 SQL injection plus SQL map. 0:27 And I want to show you something funny. 0:30 That is Katusha. 0:33 Katusha. 0:34 It is already deprecated. 0:38 Credit card. 0:40 So let me show you. 0:43 That is really funny stuff. 0:48 SQL injection. 0:52 That was kind of like private software. 0:55 Not that easy even to find. 0:58 Katusha. 0:59 So let me show you this one. 1:03 That, first of all, I was at house of the guy who created that stuff. 1:09 And he was arrested, I can say. 1:14 And what he was doing, this guy. 1:21 This guy was part of the group who created the hacking tool in 2017. 1:29 And what he was doing, basically, he was using the door king, which I showed you. 1:34 Using Bing, using Google, using Yahoo, he was finding a big amount of websites which are potentially vulnerable to a scale injection. 1:42 After that one, he was running this software, Arachne Web Scanner. 1:55 So this web scanner, he was running it. 2:01 It was, and until now it's open source and it can detect SQL injection. 2:07 So. 2:09 Again, the script was to find potentially vulnerable websites. 2:15 after to run Arachne to verify the type of SQL injection, because there are like plenty of them, right? 2:27 And after, when it was verified, he was sending it to SQL map. 2:32 And after, it was downloading full database. 2:36 And extracting credit cards and storing it in other database. 2:42 So when you buy Katusha, all you need to do is pay like $5,000 to the developer, maybe like for a year, lifetime, I don't exactly remember, from $3,000 to like $10,000 or $9,000. 2:56 So they were like, you know, having the different prices. 3:00 And you can buy Katusha and run in your computer, or you can buy it and run in their servers. 3:08 So the idea there that you just pay money and you start to get automatic database update with the credit cards of people. 3:19 And you don't even know which websites, whatever, you don't care. 3:22 You just run it. 3:24 It goes to internet, finds all the potentially vulnerable websites, run web scanner. 3:30 After it runs the expectation tool and just parses for the credit card using regular expressions. 3:36 And that's it. 3:37 Because usually hackers need credit cards, right? 3:40 Especially in 2015, 12, 17, it's already like, you know, 3:45 Not the best time, but I'm just saying that it was the last, you know, the last stuff which was around that credit cards automatic obtaining. 3:58 And we can check the news and see how they were selling it. 4:03 So like this. 4:06 Arachne scanner system, but it was Katusha in reality. 4:12 And this is the website. 4:14 So it's written here the amount of, think about this, amount of websites is more than 100,000. 4:25 200 websites are now 4:28 under scanning. 4:30 So it was like just going crazy. 4:34 $500. 4:37 Pretty cheap. 4:38 I thought it was like more expensive. 4:41 I don't think like 500 is true. 4:45 I don't think this is true because they don't have any proof for this. 4:49 Because I remember it was like expensive. 4:51 You cannot just buy it, the chip. 4:55 Yeah, and it will send you in the Telegram notification that a SQL map dump started. 5:01 And after it will just automatically extract the credit cards. 5:07 So yeah, this is what I wanted just to show you. 5:12 So it took some time from release. 5:16 06. 5:17 They have a pro version and a lot of stuff. 5:22 So those guys were basically doing such automation. 5:29 So you can understand that if that website, 5:36 was used by you, you will be automatically compromised. 5:40 Automatically. 5:41 So you've seen the amount of the websites which were scanned automatically and the credit cards extracted, whatever, phones and stuff. 5:52 So two days ago, 5:55 I deployed the website on the internet two days ago. 5:58 And the first request which I got was not from the guy whom I sent this link because I was on the phone and I said, I just deployed the website. 6:09 Here is the website. 6:11 And I went to check, you know, like debug data. 6:16 Because I access the website, he access the website. 6:18 So the first guy who access the website was Chinese bot. 6:22 And he tried to find .nth file format. 6:28 So what is .nth file? 6:33 Let me show you. 6:35 Google just doesn't want to work. 6:38 Example. 6:40 Example. 6:42 Let me go to GitHub. 6:43 I want to go to GitHub because... 6:45 This will be much faster. 6:48 So I'm going to GitHub. 6:51 To show you. 6:52 GitHub also has the docs. 6:54 Just to be clear, in the GitHub, you can find as much stuff as in the Google or anywhere. 7:00 So I'm going here, .env. 7:05 So let's look this .env. 7:10 This .env doesn't have a lot of stuff. 7:18 If we go here, password, password. 7:25 Now we are in the way of getting the password, right? 7:31 Now we see it's empty. 7:34 But if we will keep scrolling or we will write some script, 7:39 Obviously, we will find some passwords. 7:42 So now, as an example, this database username is root and the password is empty. 7:51 So this is just an example. 7:53 I don't even want to find the password, to be honest, database name. 7:57 So this .n file can be exposed. 8:03 So website.com. 8:08 It can be like this. 8:10 Why this happened? 8:11 Because developer can just commit it in the server. 8:18 And when you will just try to access it, 8:21 You will see the database login, database password. 8:25 It can be anything. 8:26 Inside environment, it can be anything stored like this. 8:31 Look, this is real password. 8:35 They call it example, but, you know, sometimes it can be even environment example, which will have the password or whatever. 8:46 So if you will spend some time here, you will find not only password, you will find like secret 8:56 key, you can find Amazon key, you can find anything, right? 9:03 So be sure that this is another low hanging fruit, which is... 9:11 Look, I'm not sure what is the service. 9:17 But I don't think that it should be exposed. 9:26 So let me hide this panel again. 9:33 Does this item, no, is this public item? 9:42 It is public item. 9:43 No. 9:47 What can I do? 9:48 What can I do with this key? 9:57 Full authentication access. 9:59 Nice. 10:01 I don't even know what is the service, but I already like it. 10:05 So let's go and check it. 10:10 Yeah. 10:11 So basically, some guy just committed his key to this platform. 10:16 I think this is something like no-code platform. 10:20 No code platform, backup your own S3 bucket. 10:23 So that is hosting. 10:25 Clearly, this is the same as I will have the key from Amazon. 10:30 Yes, so this is just one of many, many examples of the low-hanging fruits and how hackers can just compromise. 10:40 Your data, you know, like crazy. 10:45 So let's go to Shodan and let's continue. 10:49 We discussed the servers, right? 10:51 So Shodan. 10:55 Sodan.io Elasticsearch. 11:02 Elasticsearch. 11:03 So currently we can see that there are some Elasticsearch in the internet, right? 11:11 And we can keep going, especially if we have here some commercial account. 11:18 And we can see that this port is 11:22 9200. 11:25 Port 9200. 11:27 Let's see. 11:28 Login. 11:29 Okay. 11:30 Let's use ZoomEye, for example, for this one. 11:37 Elasticsearch. 11:44 So Elasticsearch 9200, port 9200. 11:56 Yeah. 11:58 I think there are some websites. 11:59 If we will scan them, they have this port open, most likely. 12:06 So there are some websites. 12:10 This one is Elasticsearch. 12:14 Is it website or is it Elasticsearch? 12:18 I think this is website which is hosted in the Elasticsearch just port. 12:25 So sometimes it can be, I think this one was Elasticsearch, but they removed it, I think. 12:31 So why do I even talk about Elasticsearch? 12:37 And by default, Elasticsearch has AWS or not. 12:47 So think about this. 12:51 You are using one of the fastest database globally. 12:59 To store your data and there is no out. 13:04 Only they start to use it in version number eight. 13:09 So just 13:11 Imagine that for like maybe 10 years or how many years Elasticsearch was open. 13:20 So if you find port 9200, that's it. 13:26 You hacked the website. 13:28 You don't even need to do anything. 13:29 You just download the Elasticsearch. 13:32 Because it doesn't have any authorization or authentication. 13:38 You just go and download the database. 13:42 What about CoachDB and similar ones? 13:48 Create list. 13:51 What do we have here? 13:53 CoachDB, Elasticsearch, MongoDB, Redis, Memcached, Cassandra, and InfluxDB. 14:02 didn't have the authentication. 14:05 So Redis, Memcached, and Cassandra, they keep not having it. 14:11 Just think about this. 14:12 And you can understand that GitHub, CodeDB, 14:20 Cassandra Elasticsearch GitHub. 14:26 I know what it will find. 14:31 Okay, it's not finding fine. 14:34 Google doesn't like me anymore. 14:36 So, our frog. 14:40 So. 14:48 You can check on this tool. 14:52 It can do a lot of interesting activities around finding low-hanging fruits for you. 15:03 It can find CVEs. 15:06 CVEs are basically the web vulnerabilities. 15:12 Also, it can even find Elasticsearch and similar stuff. 15:17 But this tool is not specializing only on this. 15:21 Let me show you a frog. 15:27 Oh. 15:33 So this is the command which you can run. 15:38 And it will find you only high and critical. 15:40 So you can input here like 55 websites, and it will analyze you all the 55 websites real quick. 15:48 Now, this is the list of the database which we just discussed. 15:52 And you should understand that this list was created before ChatGPT or anything like this. 15:58 It was manually analyzed. 16:01 And you can use this tool, Frog House, it's called. 16:08 And you can be amazed that also Docker registry API and Spark and Jenkins 16:17 and Spring Boot and Zabbix and Solr, all those guys are not having authentication by default usually. 16:27 Or it's like default or super easy one. 16:32 Think that in your network, there is already intruder. 16:38 in your computer can be already intruder. 16:41 So whatever you are doing, you should understand that the guy can be in your computer, the guy can be in your network, the malicious guy can be the guy who is sitting near you. 16:53 Maybe he wants to sniff the traffic or to do some crazy activities. 17:00 So the idea here is that you need to always use all the possible techniques to secure the protocol. 17:11 So if you are deploying MySQL, do not use default password. 17:16 Do not use like root, root, root, empty. 17:19 Because I had like a big amount of experience where, for example, 17:25 I was able to scan the server and I found the website. 17:34 And that website basically, I mean, the server had only open website. 17:41 I know that it had the database, but I never seen the database. 17:46 And I was able to find PHPMyAdmin. 17:49 Like an example, what is PHPMyAdmin? 17:53 Let me show you. 17:59 We can even try to find some in Google. 18:06 HP, my admin. 18:09 I think in title. 18:15 I think like this. 18:19 So what is PHPMyAdmin? 18:22 Try demo. 18:24 Okay, we already found the demo. 18:26 So this stuff allows you to connect to your database using the website. 18:36 So let's log out. 18:39 I will show you. 18:40 It's not telling me to look out. 18:41 So basically, just to be clear, this stuff allows you to export database in one minute. 18:48 You just click export. 18:50 Done. 18:52 You just export it. 18:53 It is just demo stuff. 18:55 You can export it and you can even execute the commands here. 18:59 So when you click here, you can execute the commands. 19:04 So the idea here is that you see there is no database port open, but somebody is using the software to manage database. 19:14 And there are a big amount of software which is allowing you to manage database. 19:18 And for some reason, you can think that if you named it like PHP, 19:25 my, my, my admin, nobody will find it, only you, it doesn't mean that nobody will find it. 19:32 Because if somebody will find it and your login and password to database is root empty, the guy will download your database. 19:39 And I had a lot of experience where I was like scanning like local networks and I was finding 19:45 Like, you know, PHP my admin or externally I was finding or whatever. 19:51 And just default login and password were used there. 19:57 So let's see. 19:59 Let me see that stuff. 20:01 So what is the title here? 20:02 Title. 20:04 PHP my admin. 20:05 This is the title. 20:07 So let's try like this. 20:12 Okay. 20:14 Because Google also doesn't like when people are doing the twerking. 20:18 So we are trying to find PHPMyAdmin. 20:22 I don't see a lot of luck of finding it, to be honest. 20:27 But I think you've spent some time. 20:32 Maybe it will be possible to. 20:37 Oh. 20:41 HP my admin. 20:43 Usually it is just in the default pass. 20:55 Let's see. 20:58 No, it's not here. 21:00 So I think you got the point that if you will just spend time to find it, you will find it. 21:11 And if somebody is using 21:15 This is router, router default passwords. 21:19 So if somebody is using PHP, my admin or similar stuff, you will be able to access his database and just download it. 21:27 So this is just, 21:32 some example of hacking the servers and hacking the websites. 21:43 There is another stuff, DB scanner. 21:48 So how it works, we can just open the source code real quick. 21:54 And check. 21:56 So it is allowing you to check the MySQL, the Postgres, the Redis, the MongoDB, and Memcache based on the port. 22:08 And after it is just trying to connect to it. 22:12 That's it. 22:13 This is like only, you know, 100 lines of code and exploit itself. 22:22 So the exploit itself is just usage of default credentials or something. 22:30 You see, so it's trying just to connect to the database using default credentials or empty credentials or like admin or whatever. 22:42 So if this is like only, you know, 100 lines of code and exploit itself. 22:52 So the exploit itself is just usage of default credentials or something. 23:00 You see, so it's trying just to connect to the database using default credentials or empty credentials or like admin or whatever. 23:12 So if this is like only, you know, 100 lines of code and exploit itself. 23:20 So the exploit itself is just usage of default credentials or something. 23:28 You see, so it's trying just to connect to the database using default credentials or empty credentials or like admin or whatever. 22:43 example of elastic search. 22:45 He, nothing. 22:48 Zero. 22:51 If we are taking this source code, maybe we want to have some clarification. 22:58 Let me know exactly what is doing and which payload it is using. 23:17 Default credential login, big password, brute force, authentication service. 23:21 Basically what I told you. 23:24 So it is trying the root password for MySQL or SA, this is super admin, trying to connect to using super admin to MS SQL or for Oracle, 23:39 it is using Oracle user and Oracle pass default. 23:43 SIS, it uses SIS system. 23:46 The same for Postgres. 23:49 It is using the user called Postgres. 23:54 And for Redis, it is just... 23:59 To authenticate using the info. 24:03 So if Redis will reply to info, it is like getting the Redis version. 24:09 It means it's, you know, you can just connect to it. 24:13 The same goes for MongoDB, Memcache, and Elasticsearch, just like this. 24:19 So when you go to Elasticsearch to get categories and master, you see all the data. 24:26 This is just to answer your question. 24:27 How do you do it? 24:28 Just through browser. 24:31 Like this. 24:33 In Elasticsearch.