What SECRETS are in your Clipboard?

Sdílet
Vložit
  • čas přidán 6. 08. 2024
  • jh.live/snyk || Snyk loves CTF challenges just like this for forensics and application security -- you can use Snyk to find vulnerabilities in your own projects FOR FREE ➡ jh.live/snyk
    00:00 - Clipboard Forensics
    00:21 - The Setup
    02:52 - Getting started
    04:10 - Checking the data
    05:15 - What next?
    11:20 - Another way forward
    13:07 - Viewing the DB
    16:50 - Final Thoughts
    🔥 CZcams ALGORITHM ➡ Like, Comment, & Subscribe!
    🙏 SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎 FOLLOW ME EVERYWHERE ➡ jh.live/discord ↔ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware

Komentáře • 99

  • @samuelbruce8837
    @samuelbruce8837 Před rokem +64

    Don't know why I chuckled when John with all his automation and shortcuts typed out "yes" to the y/n prompt for sqlitebrowser install

  • @Quephara
    @Quephara Před rokem +133

    Finding this channel is the last thing everyone does before deciding against smart homes

    • @0_1_2
      @0_1_2 Před rokem

      Explain

    • @humanperson2325
      @humanperson2325 Před rokem

      @@0_1_2 security

    • @lightwxrk
      @lightwxrk Před rokem +6

      basic quality of life improvements is nice, but I would never trust smart home locks on your doors, which I have seen people do.

    • @UsernameXOXO
      @UsernameXOXO Před rokem +2

      ​@@lightwxrk finding LPL is the last thing everyone does before deciding against locked doors, there's literally no difference; it takes skill to open either and a smashed window will always work better.

    • @hannahsmith6095
      @hannahsmith6095 Před rokem

      @@0_1_2 That already defeats the purpose if needs explaining. If you are in this channel you already know it.

  • @CattopyTheWeb
    @CattopyTheWeb Před rokem +14

    Very cool CTF. I didn't know this was possible. Thanks John!

  • @AlucardNoir
    @AlucardNoir Před rokem +11

    I haven't used windows in around 5 years now, but when I did I spent so much time in the AppData directory I had actually forgotten it's supposed to be a hidden folder.

    • @itsawill9268
      @itsawill9268 Před rokem

      Linux?

    • @AlucardNoir
      @AlucardNoir Před rokem

      @@itsawill9268 yeah. Thought about going Mac, but around that time it came out Apple had given Uighur data to the CCP.

    • @teo2157
      @teo2157 Před rokem

      @@itsawill9268 TempleOS

  • @paulw3182
    @paulw3182 Před rokem +5

    The keyboard shortcuts trimming the data was great - excellent video!

  • @bot-hk
    @bot-hk Před rokem +1

    Amazing content quality, The video seemed way way more interactive since I last saw your video!!
    Kudossss!!!🎉

  • @userhandler0tten351
    @userhandler0tten351 Před rokem +2

    Thanks for the constant motivation John!

  • @adyp487
    @adyp487 Před rokem +1

    Awesome! Just awesome John! As always! 👏👏💜😎

  • @ATLuh
    @ATLuh Před rokem +2

    Thanks John! Always cool to see stuff from inversecos

  • @matthewwallace5682
    @matthewwallace5682 Před rokem

    Fantastic video. Thanks for sharing!

  • @CharlieG111
    @CharlieG111 Před rokem +5

    Thanks John bro. I learnt so much from you. Wish one day we will meet 🎉

  • @JSRJS
    @JSRJS Před rokem

    great video John. Learn something everytime I watch one of your vids

  • @andynn6691
    @andynn6691 Před rokem +15

    You can just paste the input into stdin of base64. No need to pipe it via echo. In bash you can also do

    • @BGM99
      @BGM99 Před rokem +4

      Average Man Page Enjoyer

    • @vikingthedude
      @vikingthedude Před rokem

      How do you paste to stdin?

  • @jmdefault
    @jmdefault Před rokem +24

    I'm impressed, Microsoft is actually thorough for once. If you deativate the clipboard history the clipboard folder is completely gone and all the ClipboardPayload values in the database are NULL. I fully expected them to half-ass this again.
    The Payload values are still there however so an attacker could still find out where you copied data from.

  • @Manavetri
    @Manavetri Před rokem

    Brilliant as always !!!

  • @thomyhr
    @thomyhr Před rokem

    This was really interesting. Thanks!

  • @robertofolikwei23
    @robertofolikwei23 Před rokem

    Thank you John.

  • @andrecinelli
    @andrecinelli Před rokem

    Thanks for the video.

  • @Bchicken2
    @Bchicken2 Před rokem +1

    Ayyy great to see chompie be credited!! 11:40

  • @victorsolhof3576
    @victorsolhof3576 Před rokem

    “Running strings on these things” 😂 i love your videos!

  • @local-admin
    @local-admin Před rokem +3

    1:43
    Not parentheses but “%” or percent signs

  • @byteafterlife
    @byteafterlife Před rokem

    Love the vid❤

  • @johnathondupuis1301
    @johnathondupuis1301 Před rokem

    Awesome content in this video.

  • @Pixailz
    @Pixailz Před rokem +5

    Hey john great video as always, i have learn so many tips in bash thanks to you, now it's my turn :)
    In bash, you can specify the depth of dir that are display with this variable PROMPT_DIRTRIM
    like PROMPT_DIRTRIM=2 will trim your prompt from
    ~/Documents/dir1/dir2 to ~/.../dir1/dir2

  • @kal_dev
    @kal_dev Před rokem

    😊😊thanks

  • @noi7160
    @noi7160 Před rokem

    good video!

  • @TAPCybersec
    @TAPCybersec Před rokem +8

    Nice work! I came across a similar challenge not too long ago where the answer lied within the activities cache.

  • @shinrafahell
    @shinrafahell Před rokem

    Awesome 😎

  • @burpsploit741
    @burpsploit741 Před rokem +4

    We need more forensics videos

  • @mohammedissam3651
    @mohammedissam3651 Před rokem

    Yeah this is really good topic

  • @Junk-Junky
    @Junk-Junky Před rokem

    bro makes it look so easy

  • @animalkillerable
    @animalkillerable Před rokem

    Nice

  • @briansciretti-informatica6721

    Will we be able to try these challenges or the files aren't going to be released?

  • @Dahlah.FightMe
    @Dahlah.FightMe Před rokem +1

    Nice :D

  • @chri-k
    @chri-k Před rokem

    It’s interesting that even though MacOS keeps clipboard history ( only in RAM though, i think ), and provides an API to access it, no built-in software actually uses it.

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Před rokem

    Going bad boys.

  • @ExCyberino
    @ExCyberino Před rokem +1

    Your VM is so fast, what hypervisor are you using on windows?
    I always experience so much lag even if a allocate almost all my host resources.

    • @arjix8738
      @arjix8738 Před rokem +1

      Allocating all your host resources to a VM is bad.

    • @ExCyberino
      @ExCyberino Před rokem +1

      @@arjix8738 sure

  • @DancePants2012b
    @DancePants2012b Před rokem +1

    my Clipboard is in my Clipboard

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Před rokem

    What is dpapi

  • @PeterAdiSaputro
    @PeterAdiSaputro Před rokem

    I don't find Clipboard folder on my Windows system

  • @monthoramemi1937
    @monthoramemi1937 Před rokem

    ❤❤

  • @EricSchmeling
    @EricSchmeling Před rokem +3

    Clippy is ‘cheesy’? How dare you sir?!?! 😂

    • @Fidumo
      @Fidumo Před rokem

      yeah, Clippy is Clippy, not Cheesy!

  • @motbus3
    @motbus3 Před rokem +3

    It seems Mr hammand has been playing some diablo 4

    • @nordgaren2358
      @nordgaren2358 Před rokem +1

      Where do you see that?

    • @9rye
      @9rye Před rokem +3

      @@nordgaren2358 Most likely when he showcases his %APPDATA%/Local folder. 1:57

    • @nordgaren2358
      @nordgaren2358 Před rokem +1

      @@9rye I don't see Battle.net or Diablo 4 in there, though.

  • @imTyp0_
    @imTyp0_ Před rokem

    Please do more challenges that you don’t do beforehand

  • @PancakeByte
    @PancakeByte Před rokem

    After the video, I realize that skills takes time. well it really is. its time to practice lol

  • @Bafflementation
    @Bafflementation Před rokem

    Hmm, I'm pretty sure most SIFT VMs I've seen came with SQLite.

  • @tyrojames9937
    @tyrojames9937 Před rokem

    Que The Decrypting Tools.

  • @saucymoon7134
    @saucymoon7134 Před rokem

    how do you get your hair to bounce like that. cute

  • @geodebreaker
    @geodebreaker Před rokem

    1:41 do you mean percent symbols?

  • @stevelp
    @stevelp Před rokem

    @1:39, 2 percentage signs, not parentheses.

  • @ciaobello1261
    @ciaobello1261 Před rokem

    ❤❤💪💪

  • @kipchickensout
    @kipchickensout Před rokem +2

    1:40 those aren't parentheses and you can just as well type that into the start menu :D

  • @JamesTDG
    @JamesTDG Před rokem

    If someone did this to me, they'd regret looking at how many times I do Ctrl c, Ctrl v in my art...

  • @xxlarrytfvwxx9531
    @xxlarrytfvwxx9531 Před rokem

    I always run `type nul | clip` when I'm in public.

  • @CharlieG111
    @CharlieG111 Před rokem

    First comment for you ☝️

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Před rokem

    Main detecting persons also here other mind attack other mind to for controlling brain to attack print to work brain attack analysing for you brain to process cutting

  • @RunicSigils
    @RunicSigils Před rokem +1

    Considering everything I copy and paste are comments (especially if I'm leaving a long one I prefer to see it all written out before actually posting), links, and screenshots of things online, there would be nothing secret there.

  • @JohnPaulBuce
    @JohnPaulBuce Před rokem

    seeing a popup that says "allow access to clipboard" scares me now

  • @LocaLGh0sT
    @LocaLGh0sT Před rokem +1

    Man, Windows is so flimsy.

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Před rokem

    Saving work real get go language in get command for you object work headel application and tools, skills lod balance attending.

  • @tomr6955
    @tomr6955 Před rokem +2

    These are NOT parentheses:
    %

  • @tilakmadichettitheappdeveloper

    Why ask "uncle Google" instead of chat gpt ?

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Před rokem

    Not andsting

  • @officialchrisii
    @officialchrisii Před rokem +2

    SOON I WILL BE AN EXPECT IN ETHICAL HACKING

  • @MrBledi
    @MrBledi Před rokem

    i hope this is patched already

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Před rokem

    Concurrent?
    What is rust,git comments skills tools elements server files lod comments balance attending hacking.

  • @RandomGeometryDashStuff

    05:47 you don't need to export PS1

  • @xikes
    @xikes Před rokem

    As a GUI user, watching someone navigating folders via command line and then alt-tab to some other normal GUI app just seems stupid.
    Unless you have a valid reason for not using a GUI, this is just pretentious and stupid.
    You are not appearing more smart or clever just by typing bunch of cd and ls.

    • @MuigiTheModder
      @MuigiTheModder Před rokem

      Linux does not have ALT+TAB than windows does, and his type he can navigate folders terminal if he wants.

    • @DamienWillis-pu9bm
      @DamienWillis-pu9bm Před rokem

      Dude he is just using Linux a very common way. You saying that you must do your way or the high way is clearly a sign that you hardly care about the community.

  • @MangoMousse888
    @MangoMousse888 Před rokem +1

    Seems easier to just ring the NSA and ask if you could get some your unconstitutionally aquired data back if the form of your clipboard history, in this case. 😂😂😂

  • @cougar-town
    @cougar-town Před rokem

    the cloud_id means the clipboard data is being stored by some government that collects all the meta data is my assumption.

    • @1stAshaMan
      @1stAshaMan Před rokem +4

      Probably referring to OneDrive

    • @impoppy9145
      @impoppy9145 Před rokem +2

      Clipboard can be synced across devices in Windows. The option is called Clipboard Cloud Sync i think

  • @V4mpirella
    @V4mpirella Před rokem

    I've been looking for a video like this

  • @bhagyalakshmi1053
    @bhagyalakshmi1053 Před rokem

    Assembly code file's get comment,biycod ujeing alrebm