Тёмный

The Dangerous Flaw in Windows XP's 45 Million Lines of Code🎙Darknet Diaries Ep. 57: MS08-067 

Jack Rhysider
Подписаться 372 тыс.
Просмотров 117 тыс.
50% 1

Опубликовано:

 

26 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 219   
@sammcewan3834
@sammcewan3834 Год назад
I still can’t get over how great the name Brake Master Cylinder is. I always think of Curtis Blow as a mechanic.
@nazaxprime
@nazaxprime Год назад
Amen
@melok4081
@melok4081 Год назад
LOL
@nannesoar
@nannesoar Год назад
I actually named my son Cylinder after him
@Godwillsortyou
@Godwillsortyou Год назад
Clutch master cylinder is an alternative.
@stevengill1736
@stevengill1736 8 месяцев назад
Or spell it Break, like break dancing??
@Singularity24601
@Singularity24601 Год назад
Windows XP sent off a crash report only if the user clicked yes? How quaint that Microsoft once respected the concept of consent!
@DoubleUSlade
@DoubleUSlade Год назад
Your using their service. And it’s massively Important to have that data to understand crashes lol
@DoubleUSlade
@DoubleUSlade Год назад
I mean why wouldn’t you want them to know about a crash
@Singularity24601
@Singularity24601 Год назад
@@DoubleUSlade Heh, really? It's simply not for other people to force you to use your computer that you paid for in a certain way. If you were using your computer to present an important meeting or to treat a busy waiting room full of anxious patients, it's grossly inappropriate to sit there waiting for 10 minutes for something that won't help your situation.
@HippieInHeart
@HippieInHeart Год назад
True, lol. But it's not just Microsoft, pretty much across all software industries, companies are diligently working to erase the concept of ownership. They want you to pay for their products but at the same time they also want to keep total control over those products and reduce your ability to make decisions on your own down to an absolute minimum. Of course all while gathering every little scrap of data they can possibly get their hands on, stasi-like. (If you don't know what stasi is, it was basically the secret police/government agency in soviet occupied germany, which was tasked with, amongst other things, extensive surveillence and monitoring of the population)
@donovanswift5010
@donovanswift5010 Год назад
@@Singularity24601 Linux
@rosehacksyoutube
@rosehacksyoutube Год назад
Love these podcasts! Keep up the amazing work.
@generallowres4636
@generallowres4636 Год назад
@@sIXXIsDesigns when did he say that?
@fakename6310
@fakename6310 Год назад
Hi Jack! Huge fan of the show, I discovered you 6 months ago, and since then watched all episodes, you’ve made work a-lot more bearable :)
@egaxorz
@egaxorz 8 месяцев назад
one thing to note about jack's commentary, is that he is talking from the perspective of a "novice" character, not himself, then occasionally breaks character and shows a fraction of his true knowledge before returning to both the character and neutral recap. he obviously knows more than what he lets on but obfuscates that for storytelling purposes. that is what makes the podcast so engaging.
@amrozein8683
@amrozein8683 Год назад
Everyday, every single day i end my day listening to your podcast. These podcasts are music to my ears.
@snarevox
@snarevox Год назад
i am in love with these thumbnails. i also have a thing for courtroom art, but i think i like these thumbnails even better.
@noranoxica
@noranoxica Год назад
I love your podcast. You've taken the rabbit hole, shone a light down it and "See I told you it's not that deep and it's also pretty cool .And it's not a rabbit hole at all, but the foundation of our modern world" and I love that.
@royrush5374
@royrush5374 Год назад
New to this channel. Not computer savvy but mind blown none the less. I learn something new every few minutes watching these. I binge watched for a few hours last night. Subbed!
@FennecTECH
@FennecTECH Год назад
A facility i lived in had a system full of (my) PII vulnerable to ms08-067 in 2021 and they refused to update it. This thing was used exclusively for email and printing documents. I fired up wannacry in a VM to force their hand. they asked me what i did. I said “you left a your computer vulnerable to an exploit that was patched in 2008 and a worm infected one of my test machines. They replaced that anemic XP machine straight out of 2012 with something running windows 10.
@fss1704
@fss1704 Год назад
Full r/maliciouscompliance
@James-wi9mg
@James-wi9mg Год назад
This channel will be at 1m subs by the end of the year easily. Keep up the great work man!
@guens01
@guens01 Год назад
I'm not gonna lie, this was my favorite vulnerability to exploit when it was new. I'm happy to hear a story about it from the Microsoft's side. It was juicy!
@redacted629
@redacted629 Год назад
I'm sure many could wrip holes in this podcast regards Microsoft but I'll let Microsoft do that with the millions of lines of closed source code.
@omgemilyhd4500
@omgemilyhd4500 Год назад
Stolen too. China and Russia were able to download some or all of the source code for Windows OS. Don't trust Windows for a second with your valuables
@jcs0984
@jcs0984 Год назад
They're a multi -platform billion dollar company. Considering the billions of devices, making the source code open at this point would be akin to wreckless abandon. It sucks, but it is what it is
@carnivorebear6582
@carnivorebear6582 Год назад
Haven't there been a few decades old security vulnerabilities found in the Linux kernel in recent history? Not saying open source is useless but it doesn't make complex software immune to bugs
@reyzelcruz393
@reyzelcruz393 Год назад
jjjj
@k.graceross7177
@k.graceross7177 Год назад
@Carnivore Bear but it does make it possible for the community to fix bugs faster potentially. Obviously Microsoft has money to pay people to do for their code. But the argument remains.
@notsam498
@notsam498 Год назад
So nostalgic. Some of these podcast on old security bring back some find memories. Thanks Jack!
@akzorz9197
@akzorz9197 Год назад
Fun fact, back in the day, Dr. Watson was the reporting tool of windows. Thus where this got its' internal name.
@kenosabi
@kenosabi Год назад
Yeah. That's what they said in the podcast ... lmfao
@WhiteIceHawk
@WhiteIceHawk Год назад
Back then my dad recieved mails form our ISP that or network is sending malicious packages but he ignored it since it lkooked like spam. But when we got a letter from our ISP that we had to fix the issue our our internet contract would be terminated he bought virus scanners and they found conficker on our devices. I recently plugged in an old USB device and windows instantly warned me that conficker is on there.
@TDOLLA
@TDOLLA Год назад
you should get that usb framed and hang it on your wall and when someone in 20 years ask what it is you can be like “oh, thats pure vintage conficker”
@fss1704
@fss1704 Год назад
Nevermind goddamn sality. That shit gets everywhere.
@baked921
@baked921 Год назад
Hey bro I thought you were taking a vacation? I was really excited to listen to this last night but how come your not taking the break? It’s well deserved and we will still be here give yourself some you time. Love your work btw you have very quickly became my fav channel. I’m rewatching from the beginning now. Thanks for all your hard work!
@AshleyEhSMR
@AshleyEhSMR Год назад
I think he may still be taking a break, but has scheduled uploads of which he already made a podcast episode. It’s new to RU-vid, but he originally shared it January 21, 2020, on his podcast ☺️
@petritikkala8926
@petritikkala8926 Год назад
Anyother place to listen Jacks podcasts than apple service?
@droffii
@droffii Год назад
Its on most services, Spotify, stitcher etc
@sammay1540
@sammay1540 Год назад
You’re a fantastic storyteller. I’m hooked
@accesser
@accesser Год назад
Gret episode Jack As somebody who's team has to try and patch thousands of end point when this stuff happens, I can relate to much of it, great work by M$ behind the scenes to get patches out
@jamescollier3
@jamescollier3 Год назад
48:11 Because NS@ has good relationship with MS, and has it's own backdoor
@jchastain789
@jchastain789 Год назад
Awesome story man. Loved that you had an actual ms engineer on . Fantastic
@mjmeans7983
@mjmeans7983 Год назад
I love what he said about his job at MS, to improve public trust by hardening the operating system. Not a job so many companies now have in marketing, by spinning the bad news, or by deflecting the blame to some other company, or by blaming the right to repair movement.
@fss1704
@fss1704 Год назад
Don't you know, these techicians might install tiktok on your phone.
@rdragonsheridan
@rdragonsheridan Год назад
OMG 😱 I am getting addicted to these stories!!!
@knightscape
@knightscape Год назад
Your question at 39 minutes is valid in more scopes. A user who finds and discloses to a company that doesn’t respond raises those same concerns… but the person disclosing has no control over the outcome… so if the vendor decides not to fix… or doesn’t fix it well. That decision to disclose can impact the user disclosing their findings
@spharion7988
@spharion7988 Год назад
I have a question for the experts: Is it possible for 4 guys with no electronics devices but sheets of papers and pencils to analyze a 17 million lines code, in 5 days, that runs a multiple choice machine?..Would they be able to find something in the code that favors one choice more than the others?.... this scenario happened in real life about 2 months ago.
@fss1704
@fss1704 Год назад
Search "god mode unlocked", this is what you're looking for. Of course these people didn't care for a disclosure.
@jakevinton2075
@jakevinton2075 Год назад
What can I look up to find this story
@spharion7988
@spharion7988 Год назад
@Jake Vinton ...It was the presidential election in Brazil.
@fss1704
@fss1704 Год назад
@@spharion7988 search _eSAF_qT_FY
@Really658
@Really658 Год назад
Nice modulation. No annoying music or screaming nor shouting. The content is great.
@DEtchells
@DEtchells Год назад
These stories are so fascinating! Keep up the great work!
@KenSherman
@KenSherman Год назад
5:50 AH HA! The good ole days. Heard people are still using even older OSes. I still remember the upgraded R2 version of XP. 9:00 And oh yes, I remember Dr. Watson. We went all the way back to the 2006. 😃 Not going 2 tell you about that obvious ad banner🚫 that was running back then.🤫 58:07-58:13 L🖤🤍ve that outro.😆
@AuxiliaryPanther
@AuxiliaryPanther Год назад
I hate podcasts generally, but your stuff is so good! How do you make your editing decisions, like the random percussive sounds during the intense parts?
@Counterhackingsafe
@Counterhackingsafe Год назад
Wow, this episode of Darknet Diaries is mind-blowing! The story of how Microsoft discovered and dealt with the Conficker Worm is incredibly interesting, and I couldn't stop listening. Keep up the great work, Jack! Highly recommended to anyone interested in computer security.
@rogerramjet6429
@rogerramjet6429 Год назад
Windows has been compromised ever since 98SE. Permanently opened ports giving access whenever there is an internet connection. Remote connections are not needed to be enabled internally, and there's no extra install necessary. The specific routines cannot be discovered via manually searching due to the exposure being given an exemption from being displayed.
@rpm10k.
@rpm10k. Год назад
Um, citation needed. Run your own firewall eg opnsense and you can decide exactly what traffic you allow
@xandernoel4592
@xandernoel4592 10 месяцев назад
I totally agree with holding the individual accountable for most of their safety practices. However, it is this absurdity of marketing on behalf of Big Technology that leads to people paying an inordinate amount of money to protect themselves. It's also simple enough to justify that the individual and not the collective corporations are left to figure out what is the best solution for their online security. This makes sense up to the point that most people don't have even novice level understanding of what they need. If you aren't using TOR with a VPN and browser tracking blocking. Then you are under surveillance. Sometimes at every level of the TCP/IP model. Just saying... Great job, great channel and great work! Thank you.
@drakehasbula5557
@drakehasbula5557 Год назад
Best podcast in the game🤝
@borregoayudando1481
@borregoayudando1481 11 месяцев назад
yay, an episode of my favorite mainstream OS ever
@ImadZeryouh
@ImadZeryouh Год назад
During windows XP I had always a linux USB bootable or CD-rom. Malware and hostage software were easy to remove when u booted system on linux.
@arduinoguru7233
@arduinoguru7233 Год назад
I used WinRAR to remove viruses manually after they disabled show hidden files option.
@ImadZeryouh
@ImadZeryouh Год назад
@@arduinoguru7233 Thats some creative thinking. Never knew winrar could do that. Learned something new, Thank You.
@arduinoguru7233
@arduinoguru7233 Год назад
@@ImadZeryouh Yep, both WinRAR and 7zip still can show hidden files even if the system is infected, Last, you are first one to say about my methods creative. Because (Almost 20 yrs ago) I applied for IT jobs on ( _Europeans companies_ ) and the only company replied, told me we don't need your methods, I should learn more hacking methods instead when I was still young, and make my living of it, I know now why these hackers developed all that nasty tools, simply because nobody actually cares.
@tigerscott2966
@tigerscott2966 Год назад
I have a laptop that's over 15 years old and it has Windows XP on it...that machine is still useful - away from the internet...
@phalkhan9076
@phalkhan9076 Год назад
Thanks for more amazing content.
@dailyscarystories4
@dailyscarystories4 Год назад
kids, this is why you use linux
@EvilMmM
@EvilMmM Год назад
dude i'm hooked on your videos... keep the good work up!!
@JohnDlugosz
@JohnDlugosz Год назад
But you never explained how the vulnerability worked, or how it was in an area that's already been fixed (and reviewed for other problems).
@countvonthizzle9623
@countvonthizzle9623 6 месяцев назад
John Lambert just confirmed what I've always said : "You are a beta tester for M$FT if you use their new OS in it's first 3 years." Let the sheep test it......
@anti-popfpv4638
@anti-popfpv4638 27 дней назад
I try not to break the law in order to help people with their own property. Not sure how I haven't been "talked to" but any real hacker could see I'm just trying to help people.
@malectric
@malectric Год назад
One thing's quickly become evident around 14 minutes in: sidelining, trivializing, discounting bugs because "they aren't security problems" shows scant disregard for their paying customers. Yes, it's a complex coddled-together chunk of software with millions of moving parts but it suggests to me that there are systemic problems with the design and that a really hard re-evaluation of how such projects are built would have been in order. I think that Millenium or whatever it was called should never have hit the shelves. I spent a morning at a friend's place manually having to get bootloading-bits sorted (I forget the exact details) just to get the thing to boot. And it was lucky I knew which files were involved. Having said all that, a pox on the hacker/s who do their best to ruin the lives of people including the company that is trying to put a piece of software out there to make lives easier for people who want to use what amounts to a pile of transistors.
@SajjadsLife19
@SajjadsLife19 6 месяцев назад
The intro explains perfectly the concept behind hijap in Islam, that women and men should wear modestly and cover their "attractive" parts. Just like men should lower their gaze
@penttest-jw6ff
@penttest-jw6ff Год назад
thank you, great viewing
@terryhayward7905
@terryhayward7905 Год назад
This why I have been using Linux for years. I wonder, has anyone hacked the windows crash reporting system to send data to their remote server. ?
@misst004
@misst004 Год назад
Thank you Jack I have learned so much for watching just a couple of your videos and they totally make sense I was hacked a couple months ago they tried to take out money out of my account but it didn't work cuz I'm broke but thank you
@cexeodus
@cexeodus 10 месяцев назад
Hey I remember conficker. Haven't heard that word in forever. Man that damn worm took out three of my pc's in 2008.
@americanswan
@americanswan Год назад
If a researcher discloses a vulnerability and Microsoft spends more than a year not fixing it, we might know why. Fixing the bug may cause more harm to more computers and more companies. So just let the bug live for a while with more likely minimal damage. Microsoft then can sell the exploit to the NSA.
@tommyhuffman7499
@tommyhuffman7499 Год назад
Glad you didn't really take a break👍
@Hershizzle
@Hershizzle Год назад
They get a billion error reports a week.. remember the first time you got one and submitted it like they were going to reach back out to you and help? 😂
@FlyinRaptorJesus
@FlyinRaptorJesus Год назад
I have a work computer that still runs windows 95 lol.. Its just hooked up to a lable printer, but I guarantee this dinosaur has not been updated. I don't know if it's ever been hooked up to the internet.
@kc62301
@kc62301 Год назад
This was a great episode. I really enjoyed it.
@damonsisk4270
@damonsisk4270 Год назад
So... unless the exploit causes a crash, the vulnerability will not be noticed or fixed... M$ makes sense now.
@JohnDlugosz
@JohnDlugosz Год назад
How can patching this vulnerability cause applications to stop working? Presumably the fix affects that service's code only and adds error checking for RPC packets, and would not affect anything _other_ than what happens when malformed packets are received. So why does installing that patch make other code stop working, such that you have to wait for each vendor to update their code first?
@B.a.r.c.o.d.e....
@B.a.r.c.o.d.e.... Год назад
I woke up to another gem!! Thanks bro 🙏
@Daniel-le3gl
@Daniel-le3gl Год назад
Love this - awesome work!!!
@jono_horry
@jono_horry Год назад
Great work!
@bet
@bet Год назад
What if the way people get zero days is a Microsoft insider letting them know private
@colbyhartman9467
@colbyhartman9467 Год назад
I like your storys and I'm sure that these are true so keep them going I'm watching the new ones and the older ones as well
@carly09et
@carly09et Год назад
The NSA wants the patch of a known exploit to develop a new long life exploit -
@gregrodgers3350
@gregrodgers3350 Год назад
I've been beta testing Windows in the wild for decades. Tracking hours on a spreadsheet. Hoping for a check. /s
@LMB222
@LMB222 Год назад
Microsoft has a security team? Yeah, a token one, to be able to say they have one.
@Bullminator
@Bullminator Год назад
I guess Jack didnt take the vacation.
@ParisLawLess
@ParisLawLess Год назад
It's old
@oglothenerd
@oglothenerd Год назад
Windows, Mac... nah dude, I use Linux!
@TadiclsOperator
@TadiclsOperator Год назад
I have two computers one is my gaming rig and the other is a gaming rig I haven't done anything with it just has a fresh copy of windows. Is it legal to hack my own computer to teach my self the trade? My goal is to get into infosec
@TadiclsOperator
@TadiclsOperator Год назад
@Ricardo where can I get hacking tools without getting malware from a sketchy site
@jonnyfatboy7563
@jonnyfatboy7563 Год назад
yes running on virtual machines might be worth considering.. also not sure if ur isp would be too happy.. good hunting to ya kali linux has a plethora of tools for just what ur after
@brena3582
@brena3582 Год назад
@tadwaller3281 Kali Linux maybe 🤔
@rpm10k.
@rpm10k. Год назад
@@TadiclsOperator look up Kali Linux. There's tons of tools included, it's a pen test learning industry standard.
@s0r03
@s0r03 Год назад
My computer was infected with this or something similar when I was young I was able to fix it by stopping svchost and then doing a fresh install of windows I was pretty young at the time brought the memory back to me as I listened to this
@SubvertTheState
@SubvertTheState Год назад
If NSA and Microsoft not having fully aligned interests confuses you, you need to reevaluate your worldview lol.
@code-inc
@code-inc Год назад
Which one is the best, windows 7 , 10 or 11??
@bartandrew
@bartandrew Год назад
42:37 could you send the patch out via the worm itself?
@colinsphoneemail
@colinsphoneemail Год назад
You should do an episode with Dave Plummer. Dave’s Garage.
@AdvidsStudio1337
@AdvidsStudio1337 Год назад
I miss my doggy, Now i cant eat food without thinkin about how i used to give him a little share every time >w
@qntkka
@qntkka Год назад
Great stuff! 👊
@jcs0984
@jcs0984 Год назад
I enjoyed the story bro, thanks
@ja5onp
@ja5onp Год назад
Why play music when your talking ?
@madbruv
@madbruv Год назад
For background music? Whats ur issue
@sujitkumarsingh3200
@sujitkumarsingh3200 Год назад
Great quality content 👍
@Abuzwebstar
@Abuzwebstar Год назад
Excellent content 👍
@rochr4
@rochr4 Год назад
I ditched proprietary trash long ago, I am not a zealot but still listening to this gives me bad vibes, mesianic saviors from M$ and their struggle to save our souls, where are we now, apple, android, ppl are terrible and do not deserve nice things, let it all burn.
@richarddevenezia8186
@richarddevenezia8186 Год назад
I wonder how may WER deliveries were counterfeit, false, or misdirections from exploiters.
@SM-vo5gj
@SM-vo5gj Год назад
Sup Jack, you gonna be at Defcon this year?
@KittenKatja
@KittenKatja Год назад
Civil engineers don't make the speed limit on roads, it's the city.
@nge400
@nge400 Год назад
The city- who hires civil engineers to determine what speed limit to set.
@KittenKatja
@KittenKatja Год назад
@@nge400 Wow, sounds so great that the civil engineers can make that happen. One city in Germany has a road with a speed limit of 80, then 50, then 130 for 100m, and then 50, and the guy that pushed for those 130km/h speed limit, which was that whole street's formed speed limit, isn't even driving on it to work. How many civil engineers were needed to make that happen?
@gawdat3859
@gawdat3859 Год назад
DistriBUTED FentaNOL 😅
@OverSimplifiedHQ
@OverSimplifiedHQ Год назад
Yeaaaaaa RxBot IRC Golden age of sit back and relax.
@Wreckz_Tea
@Wreckz_Tea Год назад
What's with that weird loud annoying music at around 30:00
@ScottCalvinsClause
@ScottCalvinsClause Год назад
What are the most accurate "hacking" movies out there? Been searching around a bit and I just realized that this is probably one of the best communities for this question.
@SupremeLeaderSahil
@SupremeLeaderSahil Год назад
Movie on Edward Snowden i don't remember the actual name of the movie but search Edward Snowden movie and documentry
@SupremeLeaderSahil
@SupremeLeaderSahil Год назад
It talks about real Hacking related terms and softwars
@trevorhopkins2327
@trevorhopkins2327 Год назад
Watch Mr. Robot, it’s a tv show and a lot of the hacks they do on their are similar to hacks that have been used in the real world!
@schwingedeshaehers
@schwingedeshaehers Год назад
@@SupremeLeaderSahil citizens four?
@ALCRAN2010
@ALCRAN2010 Год назад
There's an older documentary called something like: Freakers. The original hackers were phone landline hacking . Really interesting.
@via45
@via45 Год назад
I thought u taking a hiatus 😂😂
@baked921
@baked921 Год назад
It would be well deserved. But that being said I was very pleasantly surprised to see this episode pop up! He should take a bit of time for himself tho at least a couple weeks. We will still be here waiting his content is worth it.
@thejoe4975
@thejoe4975 Год назад
@@baked921 I'm pretty sure this is an older episode.
@danialdunson
@danialdunson Год назад
Great episode
@iloveallthepeople
@iloveallthepeople Год назад
Keeping your apps and system updated is a very good way to stay protected on the internet, but let's be honest here, not the best. If you want to have a safe browsing experience, make sure to get finger cots.
@shibbidydoowop
@shibbidydoowop 6 месяцев назад
😂
@pyrusmasterdan1
@pyrusmasterdan1 7 месяцев назад
did you get paid the same if i skip the ads?
@MrZigzter
@MrZigzter Год назад
Might it be possible, that the vulnerabilities are intentional. Without transparency there is potential for nefarious behaviour behind the veils of secrecy.
@lawrencejneuser8801
@lawrencejneuser8801 Год назад
Be careful, My computer got hacked by going on to Pinterest. One of the companies that regularly uses Pinterest Is that fault.
@SportSync_official
@SportSync_official Год назад
LETS GOOOO NEW VIDEOOO!!!
@CodeCorruptor
@CodeCorruptor Год назад
You should interview DoingFedTime.
@phoenixmistertwo8815
@phoenixmistertwo8815 Год назад
But I was told to NEVER send the error report! ;)
@landrew3847
@landrew3847 Год назад
I wonder if some white hat went and created a worm using the vulnerability to force the vulnerable computers to update 😂
@xSaintxSmithx
@xSaintxSmithx Год назад
You lost me at "we need cops"
@justletmesigninokthx
@justletmesigninokthx Год назад
Nice backdrop !
@jodyranie5489
@jodyranie5489 Год назад
Music guy is usually pretty good, the click track choice was a bit distracting
@eyephpmyadmin6988
@eyephpmyadmin6988 Год назад
Absolute banger
@eddieweaver7570
@eddieweaver7570 Год назад
PLEASE DO A RU-vid PODCAST OF - THE COMPUTER,KGB AND ME... YOU WILL LOVE IT, PLEASE!!!!
Далее
this can't be real.
10:16
Просмотров 197 тыс.
Windows "Activators" are SKETCHY
27:55
Просмотров 162 тыс.
Windows XP for Net Cafés (SteadyState Demo)
23:54
Просмотров 141 тыс.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
Просмотров 646 тыс.