Тёмный

A New Kind of Phishing Attack - ThreatWire 

Hak5
Подписаться 940 тыс.
Просмотров 56 тыс.
50% 1

Опубликовано:

 

26 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 167   
@Jack-qj2pr
@Jack-qj2pr 5 месяцев назад
You've grown into your role really well. You certainly come across as much more confident compared to when you started Threatwire. You're doing great!
@JohnPeter-yf5jf
@JohnPeter-yf5jf 5 месяцев назад
Haven’t watched since she started, still a little tough but this one was important today.
@xxxxzzzzz5943
@xxxxzzzzz5943 5 месяцев назад
All women are QUEENS
@annnooon8455
@annnooon8455 5 месяцев назад
@@JohnPeter-yf5jfwhat happened to Shannon?
@HyperMakes
@HyperMakes 5 месяцев назад
​@@annnooon8455That's what i was wondering too. Looks like Shannon has parted away from Hak5.
@WhyOOWhenCanOOIIO
@WhyOOWhenCanOOIIO 5 месяцев назад
@@annnooon8455 Shannon left due to health issues. She still posts on her channel. You can find her final episode where she discusses her departure in the Nov 7 2023 ThreatWire.
@AQDuck
@AQDuck 5 месяцев назад
I think if your IOT product holds important customer data it should absolutely be patched regardless of how long it's been. Or at the very least, when support is ended it should be cut off from the manufacturer's cloud and only work locally.
@ishmaelmusgrave
@ishmaelmusgrave 5 месяцев назад
I agree.. like Fail Secure / Fail Closed
@billmiller4800
@billmiller4800 5 месяцев назад
Maybe open sourcing the software so someone else will fix it would make sense?
@AQDuck
@AQDuck 5 месяцев назад
@@billmiller4800 Open sourcing abandonware would be an absolute dream
@KDR911KO
@KDR911KO 5 месяцев назад
Data can be traced but can be removed from your iot devices, iasae devices. Etc he who can think like a hacker can prevent one from attack another person. 😮😅😉 Just remember that each motif can have a long term affect or effect or both? You be the judge of the that.
@JosephValentine-o5w
@JosephValentine-o5w 5 месяцев назад
When you're a one man NOC, sometimes you gotta play for both the teams. (No homo)
@zephyfoxy
@zephyfoxy 5 месяцев назад
Of course Micro$hit just marks a bug as resolved without actually taking action.
@KDR911KO
@KDR911KO 5 месяцев назад
Why? The only thing shitty is it's flaws like viruses it can get. Best option? Buy a client oem and ask network administrator with ISP to do that dual boot if you're phone is compatible with. Client OEM devices sound alot like Motorola or Verizon or metro would do
@secinject814
@secinject814 5 месяцев назад
Yeah that was the weirdest line like, okay that technique for a device compromise is "solved" as in we know how it works (yay microsoft wowee) but we ajn't doing anything. My rule is I never click anything in an email unless it's a password reset I know I just initiated.
@stevenpugh5412
@stevenpugh5412 5 месяцев назад
Thanks for all the work putting this together.
@BobCollins42
@BobCollins42 5 месяцев назад
D-Link says FU to its customers. I say FU to D-Link.
@SimonGreen85
@SimonGreen85 5 месяцев назад
Fu dlink are words to live by
@DinoNucci
@DinoNucci 5 месяцев назад
Who buys D Link?
@BobCollins42
@BobCollins42 5 месяцев назад
@@DinoNucci Obviously, many people do, as per Ali's report.
@DinoNucci
@DinoNucci 5 месяцев назад
@@BobCollins42 why
@Ottomanmint
@Ottomanmint 5 месяцев назад
D-Link & WD Security patches either don't work as claimed or don't manifest lately...
@ducodarling
@ducodarling 5 месяцев назад
Where's the rest of the info on the phishing attack? How does hiding elements result in a phishing attack anyway? Is there a CVE? Suggestions for the laymen?
@garicrewsen1128
@garicrewsen1128 5 месяцев назад
Definitely the last request! TIA😊
@gabethedog4043
@gabethedog4043 5 месяцев назад
The CSS can change what the email says after it detects that it has been forwarded because an email that has been forwarded has been offset. It could be programmed to notice that, then change what the text says based on that. The scheme was to trick the first recipient to forward the email. Next, the email changes the text to something "malicious" like sending money as the article used as an example. In the long run, it appears that the email was forwarded from your boss (because it was) and says to send money. You ask your boss to confirm he sent you an email, and he says that he has indeed sent an email. He did not know you meant an email to send money. He thought you meant the innocent email which may have only said "forward this to (person 2) because I do not know his email address" but the text was changed by the CSS after detecting the format change due to being forwarded. Hopefully you understand now, and this isn't too long.
@OneWildTurkey
@OneWildTurkey 5 месяцев назад
@@gabethedog4043 Thanks!
@squarefpvsmind
@squarefpvsmind 5 месяцев назад
00ppLl. DQzpq v
@MyEyeOnAi
@MyEyeOnAi 5 месяцев назад
Thank you
@wilgarcia1
@wilgarcia1 5 месяцев назад
ooff. If I ever have hardware bricked by an update. I will never buy that brand again.
@spirit.canada
@spirit.canada 5 месяцев назад
You and your team are doing great! Thank you for this valuable info
@dunce_cap
@dunce_cap 5 месяцев назад
Informative as always, thanks!
@RidinWithMyLocsOn
@RidinWithMyLocsOn 5 месяцев назад
Always interesting and informative, thank you! Stay safe!
@mrmiyagi5
@mrmiyagi5 5 месяцев назад
HTML in EMAIL was a mistake bros.
@MrPir84free
@MrPir84free 5 месяцев назад
Imagine a car company telling their customers that their vehicles are designed to last 5 years, because that's when the warranty expires; at the end of 5 years, customers should take their vehicles to the junkyard and sell it as scrap. Then the customer should return to buy the next round of vehicles, also with a 5 year lifespan. This is what D-Link is telling their customers. Worse, the manufacturer created the issue by including default logins and passwords, which is an industry norm to AVOID at all costs. Yet, D-Link says to their customer base - toss it in the trash, and come buy something new instead. Folks, it's time to NEVER buy a D-Link device, even to include a unmanaged switch, or a cable ; vote with your money and send it anywhere but D-Link.
@jamescarroll6954
@jamescarroll6954 5 месяцев назад
Interesting name. Latrodectus is a genus of spiders, including Black Widow. (L. Mactans)
@Stephanie3XL
@Stephanie3XL 5 месяцев назад
heavy going with lots of big words. simple layman's terms with what to do/not to do would help my seriously cluttered mind. happy saturday
@secinject814
@secinject814 5 месяцев назад
It's a balance because there's technical folk who want some details and more layman level of knowledge who just want to know what to do for protection.
@justforyounl7388
@justforyounl7388 5 месяцев назад
For the nas exploit they could just release there firmware to the public, so the open source community can do something about it!
@niallflynn1833
@niallflynn1833 5 месяцев назад
After eol/eos, release the source code and schematics....
@MrPir84free
@MrPir84free 5 месяцев назад
In D-Link's case, it would have meant that hackers would have gained access to the devices much earlier; default logins and passwords are always a bad thing; usually a sign of a company that does not give a crap about security, just selling product, abandoning it when it stops making money, then selling more new product just as long as they can make a dime. People should steer clear of D-Link products. Their approach to security and how it sees its customer base is abhorrent.
@pehden
@pehden 5 месяцев назад
Okay, so this is my favorite video so far, 100% at every point of it. Ready for the next one.
@briianhebert
@briianhebert 5 месяцев назад
Thanks for the video
@infinitivez
@infinitivez 5 месяцев назад
Grow with you, no problemo. Occasionally late, we'll eagerly wait for you all. But no PUPPY?!?! HOW COULD YOU DO THIS TO US?!?! 😜
@KDR911KO
@KDR911KO 5 месяцев назад
The puppy thing is a great attachment like a call of duty attachment lol 😂 anywho she should hired by metro
@KDR911KO
@KDR911KO 5 месяцев назад
I'm not sorry but Will be a better pet next time 😂
@DinoNucci
@DinoNucci 5 месяцев назад
WAT!?
@Dav1d_999
@Dav1d_999 5 месяцев назад
Love the smile and dimples 😊 thanks for the info
@zainuddinbrahim4625
@zainuddinbrahim4625 5 месяцев назад
Appreciate the info
@VincentGroenewold
@VincentGroenewold 5 месяцев назад
Great work! Ignore bad comments, embrace useful criticism and focus on the positive ones, tough for us humans to do but it helped me quite a bit. Keep on rocking!
@garicrewsen1128
@garicrewsen1128 5 месяцев назад
Many creators suggest not reading the comments. Kinda defeats the purpose of commenting, though. Maybe hire someone to proof the comments, remove the negative, overly critical and childish ones? Although you've no need to worry about them. You're doing great. Thx and keep it up! 😊
@MatthewCallier
@MatthewCallier 5 месяцев назад
Another great episode.
@zer0r00t
@zer0r00t 5 месяцев назад
Wait Sonos never did that iirc. They simply split the systems into v1 and v2 so newer devices could only be grouped with newer devices and vice versa
@oxoboo
@oxoboo 5 месяцев назад
I believe she was referring to Sonos's "Recycle Mode" that bricked old speakers and was required to enable for Sonos's trade-up program to get a discount. Edit: clarification
@zer0r00t
@zer0r00t 5 месяцев назад
@@oxoboo hmm yea. True that. But that was opt-in. It was basically a trade-in, but without actually sending the hardware to them. So essentially it's the same thing. You 'trade-in' aka disable your old hardware and get the discount
@DinoNucci
@DinoNucci 5 месяцев назад
Wrong
@jordanyoung1836
@jordanyoung1836 4 месяца назад
Always keep your emails safe
@innerfire369
@innerfire369 5 месяцев назад
I just have one question about the oldest episodes of the threatwire. Where are they?
@robotron1236
@robotron1236 5 месяцев назад
Why would people make fun of the name Ally Diamond? That's not even a weird name...
@FunkCakes
@FunkCakes 5 месяцев назад
Its very annoying these situations exist. Although the public can't top this we can more careful in the selection of products we choose to use. We need to strive to not choose products that are D-Link to a bad experience. 😅
@gaptastic
@gaptastic 5 месяцев назад
You're kicking ass. I'm glad Hak5 is continuing with Threatwire and I'm glad you're taking it over. Wish you the best in this role. Ignore the haters, for haters will only hate.
@adonaiblackwood
@adonaiblackwood 5 месяцев назад
This is interesting! Stay aware!
@KDR911KO
@KDR911KO 5 месяцев назад
Just remember that awareness of these things matter so you can prevent another attack.
@stuxed
@stuxed 5 месяцев назад
Shared! Thank you!
@SloppyPastrami
@SloppyPastrami 5 месяцев назад
if a company is going to EOL/EOS a hardware product, then they should release the software and firmware so owners at least have the option to maintain them on their own.
@KDR911KO
@KDR911KO 5 месяцев назад
Kingphisher is a compaign awareness like what a ciso does
@Rochester92G
@Rochester92G 5 месяцев назад
Smart company. Gets attractive women to present technical information.
@debugin1227
@debugin1227 5 месяцев назад
dlink attitude to security is the reason I won't buy any more of their products. hard coded reds warrants and update if out of support because of the stupidity of the vendor to include one Mr Potato Head... Mr Potato Head back doors are not secret and they should know it
@xXDarthBagginsXx
@xXDarthBagginsXx 5 месяцев назад
In the end, just build your own NAS.
@CanadaHasFallen
@CanadaHasFallen 5 месяцев назад
Dlink has had a horrible reputation since....forever? at least 2005?
@hak5
@hak5 5 месяцев назад
2 points for the War Games quote ~Darren
@secinject814
@secinject814 5 месяцев назад
Yeah hardcoded creds are an invite for compromise. And they're usually unbelievably easy, short and predictable. Probably didnt even need to bruteforce it with a program lol
@hcfdewet1
@hcfdewet1 5 месяцев назад
Why does D-Link not make the EOL/EOS firmware available to the Open Source community?
@user-lg4le8xr4s
@user-lg4le8xr4s 5 месяцев назад
Honestly, even if D-link released a patch, the type of person who is exposing an EoL device's management interface (or ANY device really) directly to the internet isn't going to update it anyways, and probably will never even hear about this CVE.
@sandsquid
@sandsquid 5 месяцев назад
You go grrl!
@vectoralphaSec
@vectoralphaSec 5 месяцев назад
Its always hard when doing something new so its ok. You will get more comfortable with news delivery as time goes by.
@marks0117
@marks0117 5 месяцев назад
Keep up the good work, guys.
@ZeNex74
@ZeNex74 4 месяца назад
Noob now subbed and hit the bell
@electricsushi
@electricsushi 5 месяцев назад
Something is off with the transcoding. Not complaining about the 720P choice, but should not have this may artifacts.
@redslashed
@redslashed 5 месяцев назад
No Ali Diamond sound so cool
@ch1pnd413
@ch1pnd413 5 месяцев назад
❤ excellent content 👍🏻
@qkb3128
@qkb3128 5 месяцев назад
That’s ridiculous that forces people to upgrade all their hardware. Sounds like you don’t want to buy D-link…lol just Dlink there product.
@KDR911KO
@KDR911KO 5 месяцев назад
I'm cool with threatwire
@ScriptureFirst
@ScriptureFirst 5 месяцев назад
🙋🏻‍♂️ startup 💎 2 man team 1️⃣ customer 😏 but he’s paying all the bills 🙌🏼
@UNcommonSenseAUS
@UNcommonSenseAUS 5 месяцев назад
6:21 please validate me
@userou-ig1ze
@userou-ig1ze 5 месяцев назад
2:00 have them install JavaScript?
@RCBMW
@RCBMW 4 месяца назад
What is she even talking about? I'm lost!!
@astrogatorjones
@astrogatorjones 5 месяцев назад
You’re doing fine.
@woritsez
@woritsez 5 месяцев назад
never trust ppl that forward email
@yanasitta
@yanasitta 5 месяцев назад
Burberry, how decadent.
@agritech802
@agritech802 5 месяцев назад
4 years is a joke for eol, it should be 15 years at least
@nicolasferrari7146
@nicolasferrari7146 5 месяцев назад
It's kind of scary nearly 1 mil people subscribe to hak5.
@blookolla
@blookolla 5 месяцев назад
It started off well.
@miproduction6196
@miproduction6196 5 месяцев назад
@@blookollawhat what is she declining or something
@blckwaterpark
@blckwaterpark 5 месяцев назад
Lesson to learn here, never buying any D-Link devices knowing how insecure they are just after a few years..
@scentilatingone2148
@scentilatingone2148 5 месяцев назад
Those dimples
@imca_b_5517
@imca_b_5517 5 месяцев назад
It was major issue in the world 🌍 "email attack"
@AnonMedic
@AnonMedic 5 месяцев назад
The fact D-Link won't just release a patch makes me never want to buy another D-Link product again. Also I just noticed you got the cutest dimples ever.
@Videos_Marco_Multicanal
@Videos_Marco_Multicanal 3 месяца назад
😮
@ShinitaiKokii
@ShinitaiKokii 5 месяцев назад
🔗 Story 1: New Kind of Phishing Attack link does not work!
@hak5
@hak5 5 месяцев назад
fixed - ali
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked 5 месяцев назад
Shalom.
@KDR911KO
@KDR911KO 5 месяцев назад
Still permission denied because of passkeys
@gravelguitar9443
@gravelguitar9443 5 месяцев назад
HTTP, OR HTTPS?
@lossless4129
@lossless4129 5 месяцев назад
You’re great! Keep it up
@Starfire42
@Starfire42 5 месяцев назад
Dlink is horrible as usual. Great work Ali!
@Human_Shrek
@Human_Shrek 5 месяцев назад
she's so adorable and informative. thank you, threat-wire as always.
@secinject814
@secinject814 5 месяцев назад
I think you're a good presenter, no complaints!
@sigmamale6143
@sigmamale6143 5 месяцев назад
I'm not even in cyber security stuff but I'm here for her cute dimples God made so beautiful people
@blookolla
@blookolla 5 месяцев назад
Where's Shannon?
@DiegoGueterez
@DiegoGueterez 5 месяцев назад
thumbs up on that dress thumbs up! like the beerrrrrrr beerrry
@Kyus2001
@Kyus2001 5 месяцев назад
Cicada3301 good actors
@KDR911KO
@KDR911KO 5 месяцев назад
Try and catch and patch your services
@IndyAdvant
@IndyAdvant 5 месяцев назад
Lutra link is broken
@ultranadax6852
@ultranadax6852 5 месяцев назад
Sub’d- great info and delivery!
@russell28533
@russell28533 5 месяцев назад
Good work Ali
@canlelola
@canlelola 5 месяцев назад
Why on earth do people forget or have never come across w3c or w3school?
@secinject814
@secinject814 5 месяцев назад
While im still looking for a job atm, throughout my learning on Tryhackme, Hackthebox, portswigger(so far), some books and studying for my Sec+ exam I don't think it has ever been mentioned. Perhaps once but not in enough detail to remember. Ive heard of the IEEE and IANA, but not w3c, there's sooooo much info in learning the fundamentals of the web/software/different OS'/networking/Active Dir/cloud/back-end & front-end, cyber- security, coding... Obvs I know you don't need to be proficient in all these areas, but the amount of information is mind boggling. It's so easy to miss stuff that more experienced people assume you would run across.
@tommyboy3164
@tommyboy3164 5 месяцев назад
…..I can’t….
@cesar3422
@cesar3422 5 месяцев назад
Nice tablecloth
@juriendejong5201
@juriendejong5201 5 месяцев назад
You cool, please continue
@MajesticBlueFalcon
@MajesticBlueFalcon 5 месяцев назад
I miss Snubs 😢
@DJMerck
@DJMerck 5 месяцев назад
We all do a lil. What happened? I quit paying attention for a lil over a year, maybe 2 and now everyone is gone.
@bigboldsale
@bigboldsale 5 месяцев назад
What happened to Shanon?
@w3w3w3
@w3w3w3 5 месяцев назад
im interested to know myself, just out of curiosity
@0Buddhaspot0
@0Buddhaspot0 5 месяцев назад
👽☠️👾
@DinoNucci
@DinoNucci 5 месяцев назад
PizzA
@RCBMW
@RCBMW 4 месяца назад
Hey, looking good, love your golf vids
@adrift4days
@adrift4days 5 месяцев назад
RIP SOPHIE
@asishreddy7729
@asishreddy7729 5 месяцев назад
Nothing ruins a beautiful girl like fake body parts. That lip filler….
@JoeyFun
@JoeyFun 5 месяцев назад
Ignore the haters, idk why anyone would make fun of your name. My driving instructor's last name was Diamond and it was pretty kewl! Anywho, keep up the great work.
@Chris558576
@Chris558576 5 месяцев назад
I'm done with D-Link. Clearly they are not on the side of consumers.
@kjetilhvalstrand1009
@kjetilhvalstrand1009 5 месяцев назад
they always done this crap, they used type words with mispelling as well.
@bfrancis9898
@bfrancis9898 5 месяцев назад
D-fective link
@thewelder3538
@thewelder3538 5 месяцев назад
I came to this video with an open mind, but your delivery of pertinent information is REALLY bad. This I think, is down to some terrible writing. Now I'm not entirely sure what you're aiming for, but it sounds like some like some sort of badly written news segment with various quotes from whatever sources you can find. There's nothing here about what people should look for in detail, or how they can avoid these threats. This video is actually hard to watch because of the way things are delivered, to the point I couldn't make it all the way through. If I feel this way and I'm trying to be as constructive as I can, I'm sure others will have a similar opinion. However, the worst thing here are the comments. All the supportive ones with no real reason for the support other than the "you go girl" perspective. Sure, there's are trolls, but a lot of the comments are bad because of the reasons I mentioned above. With other commenters saying "ignore the haters" and other moronic things without trying to understand why the haters are saying what they're saying. As someone who works in this field, I found this incredibly difficult to watch and I think you have a lot of work to do in order to maintain engagement.
@jasonybarra8277
@jasonybarra8277 5 месяцев назад
Your cool new snubs remember the old phrase "trust your techno lust" and my favorite " drink all the booze hack all the things"🖖🖖🤘🤘🤘🤟
@endingwithali
@endingwithali 5 месяцев назад
new snubs LMAOOOOO
@KDR911KO
@KDR911KO 5 месяцев назад
Cloud C2 rem fix eol nas server cve
@SHAZAMYOUNGORDER
@SHAZAMYOUNGORDER 5 месяцев назад
🪥
@Hat_Uncle
@Hat_Uncle 5 месяцев назад
takeaway, once again, Don't Install Java on your machine. LOL
@JohnPeter-yf5jf
@JohnPeter-yf5jf 5 месяцев назад
lol 4yr out of date while windows xp still running on a network somewhere
@michael5743
@michael5743 3 месяца назад
Hey Ali. You're cute. We're going to have to figure out a means to cryptographically send each other our numbers here soon.
@Akshun82
@Akshun82 5 месяцев назад
_No dog with me this week_ *Unsubscribes*
@RonPhillips420
@RonPhillips420 5 месяцев назад
OMG I am sooooooo interested but you are soooooooo painful to watch
@FiscalRangersFlorida
@FiscalRangersFlorida 5 месяцев назад
I have a hard time thinking this young gal has any technical credibility. She talks WAY too fast with too many unexplained jargon terms for my ears, so I am out of here.
Далее
It’s Been a Good Run, Phone Providers.
26:31
Просмотров 4,6 млн
DEF CON was actually cancelled?! - ThreatWire
5:47
Просмотров 27 тыс.
Brilliant Budget-Friendly Tips for Car Painting!
00:28
17 Hacker Tools in 7 Minutes - ALL Hak5 Gear
6:54
Просмотров 426 тыс.
Internet Archive Lost The Fight - ThreatWire
7:19
Просмотров 92 тыс.
NEVER install these programs on your PC... EVER!!!
19:26
Kaspersky is the New Tiktok - ThreatWire
9:55
Просмотров 18 тыс.
I-S00N China File Drop - ThreatWire
6:40
Просмотров 26 тыс.
The Home Server I've Been Wanting
18:14
Просмотров 15 тыс.
Microsoft Recall got Recalled - ThreatWire
9:24
Просмотров 18 тыс.
12 Privacy & Security Tools I Use EVERY DAY
6:14
Просмотров 115 тыс.
New PuTTY Vulnerability - ThreatWire
8:52
Просмотров 29 тыс.