Stealing Computer Passwords on Login

Sdílet
Vložit
  • čas přidán 11. 06. 2024
  • jh.live/plextrac || Save time and effort on pentest reports with PlexTrac's premiere reporting & collaborative platform in a FREE one-month trial! jh.live/plextrac 😎
    / getting-windows-passwo...
    github.com/gtworek/PSBits/tre...
    Learn Cybersecurity - Name Your Price Training with John Hammond: nameyourpricetraining.com
    WATCH MORE:
    Dark Web & Cybercrime Investigations: • Tracking Cybercrime on...
    Malware & Hacker Tradecraft: • Malware Analysis & Thr...
    📧JOIN MY NEWSLETTER ➡ jh.live/email
    🙏SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware
    🔥CZcams ALGORITHM ➡ Like, Comment, & Subscribe!

Komentáře • 95

  • @Apple_Beshy
    @Apple_Beshy Před 15 dny +49

    The first "hack" I've ever did was in my middle school, one of my friend forgot to erase his password from facebook log in, and I literally just swap the password into text using inspect element and got his full password 😆

    • @fightme5543
      @fightme5543 Před 15 dny +2

      Corson Hardwick?

    • @wrathofainz
      @wrathofainz Před 15 dny

      ​@@fightme5543Corsair Vengeance ® RGB 32gb

    • @scorit-zq4yx
      @scorit-zq4yx Před 15 dny +5

      I started with Social Engineering in grade 8 back in the early 2000s when MSN was popular. Slowly get the answers to peoples secret questions to reset their passwords. The last day of school I had access to my entire classes MSN accounts. Good times.

    • @Sudowhoami-ni1td
      @Sudowhoami-ni1td Před 14 dny

      lol in Highschool I installed a keylogger on my own phone and convinced shitload of students to login into their fb accounts to show them some bs cool feature fb have on my phone which I completely made up

    • @flyers2000
      @flyers2000 Před hodinou

      @@scorit-zq4yx i beat you both. try ICQ on dial up built in search in ICQ and targetted gay predators, and also stole ISP dial info so tracing me would bounce all over
      pwn you both

  • @logiciananimal
    @logiciananimal Před 15 dny +15

    Microsoft does seem to not care about this sort of thing very much - they consider local administrator to be sufficiently powerful that abuse of other users or of SYSTEM to be always possible. (This was generally Raymond Chen's attitude for a while.)

    • @davidyoder5890
      @davidyoder5890 Před 15 dny +1

      How is this any different than the root user in Linux or MacOS?

    • @nou712
      @nou712 Před 15 dny

      @@davidyoder5890 In most desktop linux configurations the root account is locked by default and you have to use a live usb/dvd/cd environment to chroot and unlock the root account or edit your boot entry on startup in grub to use /usr/bin/bash. You have sudo which can do super user things, up to a limit though set by the distribution that packages sudo for you(unless you can do sudo su - root) and it depends again how your system is configured. You can remove your own sudo privileges meaning your system is very locked down however this also means you can't do even basic things such as installing new software unless you use something like flatpak or distrobox in userspace.

    • @chri-k
      @chri-k Před 15 dny

      @@davidyoder5890The difference is that administrator accounts are supposed to be (and if you configure sudo correctly, are) one level below root

  • @KeithGriffiths
    @KeithGriffiths Před 15 dny +2

    ...John, you provide so many links to really useful resources. I have built out most of the projects from videos you have created...and started running out of space, my 42u rack server is busting, I just keep on adding to it... 😂😂

  • @mkledits3679
    @mkledits3679 Před 13 dny +1

    John great video as always! Quick question; will this work also on Microsoft accounts? since winlogon process handles the authentication in both cases?

  • @akshaychoudhary3582
    @akshaychoudhary3582 Před 15 dny +6

    Hi john can you also add the link of the blog post that you refer. It'll be very helpful ❤

  • @poocyx
    @poocyx Před 15 dny

    great video john!

  • @debrainwasher
    @debrainwasher Před 13 dny +2

    This is really an insightful and heart warming contribution.

  • @Chrysilla_QuantumHealing
    @Chrysilla_QuantumHealing Před 15 dny +7

    I am not very technical, but enjoy your videos and enthusiasm. 😊

  • @SpaceCadet4Jesus
    @SpaceCadet4Jesus Před 15 dny

    A couple security softwares do monitor login process and would make this technique null and void. But I gave you a thumbs up anyways.

  • @charleshines2142
    @charleshines2142 Před 13 dny +4

    Windows is just a security nightmare from the looks of this. First I find out about Recall the biggest security risk that NO ONE asked for and now this.

  • @shenetworks
    @shenetworks Před 15 dny +6

    JOHN WHY ARE YOU YELLING

    • @deanvangreunen6457
      @deanvangreunen6457 Před 12 dny

      It's for the blind people at the front of the room. 😂

    • @deanvangreunen6457
      @deanvangreunen6457 Před 12 dny

      He's FBI agent is a little "slow"

    • @deanvangreunen6457
      @deanvangreunen6457 Před 12 dny

      He's talking load so an Indian hacker can hear him cause he's mic is bugged by Indian government 😂

    • @abdalrahman0x80
      @abdalrahman0x80 Před 6 dny

      why are you watch this video?
      you: Any Comment

  • @DePhoegonIsle
    @DePhoegonIsle Před 15 dny

    I am more curious about how you would interact with this and an account that uses Windows Hello sign-in, or Pin Sign in.
    I must say it is interesting to see the password logins be ... taken apart, but I am almost more upset that there is some pathological avoidance of pushing against MS Logins with pins/Windows Hello auth.

  • @ricseeds4835
    @ricseeds4835 Před 15 dny

    I want to try this just to find out if it still works when the user is already logged in but locked. Also, how does it work if the user mistypes the password on the first try?

  • @lunaxyzi
    @lunaxyzi Před 14 dny

    Very important question: What KEYBOARD do you use?

  • @harrylumsdon6773
    @harrylumsdon6773 Před 15 dny

    Wont any xdr report any lsass acccess or calls?

  • @pidojaspdpaidipashdisao572

    Hey if the method is hot, it's always worth making a video on it. :)

  • @comosaycomosah
    @comosaycomosah Před 15 dny

    been trying to remember dudes last name for like 2 years lmao thanks

  • @LightningGamerZt
    @LightningGamerZt Před 4 dny

    Bro should have put in the description warning disclaimer for educational purposes only!!

  • @neilpatil7786
    @neilpatil7786 Před 15 dny +2

    Very informative sir .... 😊

    • @hollywoodhank591
      @hollywoodhank591 Před 15 dny +5

      His Video is 21 Minuten long... and 13 Minutes up. 3 minutes after its up, you commenting this 🤔

    • @Mohammad-zg4jd
      @Mohammad-zg4jd Před 10 dny

      ​@@hollywoodhank591❤😂😂⁰

  • @saimanish4374
    @saimanish4374 Před 13 dny

    Brilliant 🤩

  • @kongpanha1816
    @kongpanha1816 Před 15 dny

    Hi John 🎉

  • @johnnywilliams2641
    @johnnywilliams2641 Před 15 dny

    The legend with the golden hair.

  • @user-te9jy7hx7n
    @user-te9jy7hx7n Před 6 dny +1

    Jai Shree Radhe Radhe 🙏🙏

    • @user-te9jy7hx7n
      @user-te9jy7hx7n Před 6 dny +1

      Jai Shree Radhe Radhe 🙏🙏😍😍😍🇳🇵♥️👌👍💐🙏

  • @mastersingleton
    @mastersingleton Před 15 dny

    Thanks for another informative cyber security video for Windows 10/Windows 11 PC users.

  • @nathancoats6432
    @nathancoats6432 Před 15 dny

    OMG Ppl in IT are wizards! 😮

  • @gunnargu
    @gunnargu Před 2 dny

    linux can do this too, just put a PAM into PAM...

  • @skitties_the_folf6969
    @skitties_the_folf6969 Před 15 dny

    thanks for more than enough info to add securities to my computer

  • @ravenhoodcat9421
    @ravenhoodcat9421 Před 15 dny

    Soooo basically, you need to already have the keys to the kingdom in order to get the keys to the kingdom.

    • @snowysysadmin59
      @snowysysadmin59 Před 15 dny

      This is more of a pentest thing. Wouldnt be practical in a real blackhat scenario

    • @0xgordo350
      @0xgordo350 Před 14 dny

      @@snowysysadmin59 I think you can go from local admin to domain admin with this technique

  • @mirozo
    @mirozo Před 15 dny

    does it work with login on domain users?

    • @mirozo
      @mirozo Před 15 dny

      like if i wanna grub domain admins2 password but only have domain admin1 and local admin1

    • @rochdiferjani6778
      @rochdiferjani6778 Před 7 dny

      @@mirozo it s working fine, enjoy !!!

  • @carsonjamesiv2512
    @carsonjamesiv2512 Před 15 dny

    COOL!

  • @abenezerkassa111
    @abenezerkassa111 Před 15 dny

    big fan bro

  • @balloney2175
    @balloney2175 Před 15 dny +2

    Yesss! I'm gonna ask my g.f. to login to my laptop and then I'll be able to discover secrets she'd been keeping.

    • @kaiosama1237
      @kaiosama1237 Před 15 dny +1

      Maybe don’t say it here? Lol 😂

    • @balloney2175
      @balloney2175 Před 15 dny

      @@kaiosama1237 She didn't know my alias on CZcams.

    • @SpaceCadet4Jesus
      @SpaceCadet4Jesus Před 15 dny

      You mean you'll get your girlfriend's secret passwords when she uses the browser? You think.

  • @JonahNDavis
    @JonahNDavis Před 15 dny +2

    lol just use the ctrl + alt + delete thing on login. it kills all other processes. and encrypt your SSD with veracrypt, so you dont have access to an alternate live boot

  • @anonymous-65732
    @anonymous-65732 Před 15 dny

    nice sir

  • @BG5850
    @BG5850 Před 12 dny

    Hey I followed along your video from 4 years ago with the Rick and Morty ctf. I had a few questions toward the very end. Is there away we can connect?

  • @mountp1391
    @mountp1391 Před 4 dny

    good

  • @mahiwells819
    @mahiwells819 Před 19 hodinami

    I need your help it's urgent sos

  • @rusnuker
    @rusnuker Před 15 dny

    hi

  • @CRSolarice
    @CRSolarice Před 15 dny

    Wow, what an amazing thumbnail! It makes you look like the handsome red headed man that you really are. Be careful about accepting too many date requests online because you may run out of time to make videos!!! I have the thought that you are much more intelligent than you are leading people to believe! Nevertheless I am really amazed! Is this just a fluke?? Best regards.

  • @user-vz7tx8tl3n
    @user-vz7tx8tl3n Před 8 dny

    Hey bro can you give me help to recover my account Gmail pleaseeee

  • @atikhossaindip
    @atikhossaindip Před 13 dny

    --comment

  • @sammycy5016
    @sammycy5016 Před 9 dny

    Sir can you hack clash of clans account? I can't access my account even though I have my Gmail but need a unlock code please help

  • @limhanliang
    @limhanliang Před 15 dny

    😮😮

  • @chmod_
    @chmod_ Před 15 dny

    Use middle finger on keyboard 😅

  • @iamwitchergeraltofrivia9670

    Hahahahahjajahajajajajjajaja linux permissins are the best

  • @abenezerkassa111
    @abenezerkassa111 Před 15 dny +1

    first lol

  • @KCKingcollin
    @KCKingcollin Před 15 dny

    The title should be "stealing windows passwords" Linux doesn't have these issues unless you somehow get root, and you'd need a 0 day or social engineering attack for that

    • @0xgordo350
      @0xgordo350 Před 14 dny +1

      Yeah it does, it's called PAM Backdoor

  • @CapnCrunk
    @CapnCrunk Před 15 dny +75

    Stop filming your hands/keyboard while talking. I hope the pin you logged in with isn't used anywhere else.