Finding WEIRD Phishing Websites

Sdílet
Vložit
  • čas přidán 16. 05. 2024
  • jh.live/censys || Get started with the leading Internet Intelligence Platform for threat hunting and attack surface management -- find what is exposed out on the open Internet with Censys! jh.live/censys
    Learn Cybersecurity - Name Your Price Training with John Hammond: nameyourpricetraining.com
    WATCH MORE:
    Dark Web & Cybercrime Investigations: • Tracking Cybercrime on...
    Malware & Hacker Tradecraft: • Malware Analysis & Thr...
    📧JOIN MY NEWSLETTER ➡ jh.live/email
    🙏SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware
    🔥CZcams ALGORITHM ➡ Like, Comment, & Subscribe!

Komentáře • 74

  • @pelijot
    @pelijot Před 16 dny +38

    yup, thats Dynmap, a web Minecraft map.

    • @BillAnt
      @BillAnt Před 16 dny +2

      Gotta love going down rabbit holes... hehe

    • @awesomekalin55
      @awesomekalin55 Před 15 dny +2

      And Railway System Map is from Minecraft Transit Railway

  • @PopperOfCorn
    @PopperOfCorn Před 16 dny +20

    You know, all the information you should never share with a stranger on the internet.

  • @SzaboB33
    @SzaboB33 Před 16 dny +75

    You constrained by the sponsorship: cannot use "screw you" as an email address
    Me, a free individual: deleting their databases with SQL injection

  • @blinking_dodo
    @blinking_dodo Před 16 dny +19

    I often get spam mails with links to those pages.
    One of the actors fails to protect their backdoor, so i can just walk in open the file manager they keep exposed.
    Then i rename the index files to break the landing pages.
    Really want to automate it, but *legal* is evil.

  • @shinris3n
    @shinris3n Před 16 dny +29

    How could you tease us like that with the exe file! Follow up vid?!

  • @coder_117
    @coder_117 Před 16 dny +5

    I've been getting spam texts for months telling me my USPS package has arrived at the warehouse but can't be delivered due to incomplete address information. It then asks me to confirm my address at an obviously fake link.

  • @tobixnator9314
    @tobixnator9314 Před 16 dny +18

    That's a real Minecraft server

    • @stavros222
      @stavros222 Před 16 dny +5

      Live overflow will absolutely love it 🤣

  • @s1lverposting
    @s1lverposting Před 16 dny +72

    hey, you found my Minecraft server!

  • @3N18AKPzmGOsBgWKH
    @3N18AKPzmGOsBgWKH Před 16 dny +6

    Truth be told, i just love you exploring the internet and see what happens :P Hope these will show up more in the future. Sure, phishing was in focus, but you ended up going in all other different directions and even cracking the password for the zipfile xD Love it!

  • @j_r_-
    @j_r_- Před 10 dny

    Green spotlight makes that background foam look good

  • @drabspirit
    @drabspirit Před 16 dny +5

    The Minecraft server looks interesting! That map view you opened seemed to be Dynmap, which is a mod/plugin to create a Google maps like view of your server, definitely someone with quite the world and those color blocks on the maps were likely player claims within the game using another mod/plugin!

  • @_tr11
    @_tr11 Před 15 dny +2

    it's so fun to write scripts to fill their databases with garbage bro

  • @nickadams2361
    @nickadams2361 Před 16 dny

    Never been so excited for front desk information

  • @exoexe1555
    @exoexe1555 Před 16 dny

    The Minecraft Map is a plugin called DynMap, which uses an open port to process and host that live map you were interacting with. It can be configured to show players, mobs, waypoints and more

  • @vectoralphaAI
    @vectoralphaAI Před 16 dny +5

    How much does Censys cost??

    • @deaddead698
      @deaddead698 Před 9 dny

      There’s a free version that gives you 250 searches a month with 10 pages worth of results. Tbh not bad for basic usage. To go up to 500 searches tho, you gotta pay $69 US. That right there’s a ripoff

  • @radscientist
    @radscientist Před 15 dny

    I've gotten a bunch of these as well as the "Thank you for your payment" with a transaction number that is a link and, of course, a downloadable file. They are usually sent from a Gmail address with a person's name and the sender's name is different.

  • @nickadams2361
    @nickadams2361 Před 16 dny +2

    I love how you said “hosted in Ohio apparently”

    • @BillAnt
      @BillAnt Před 16 dny

      Well it could be located on a server just about anywhere.

  • @AkiiiMatcha
    @AkiiiMatcha Před 14 dny

    Super fun video! Thanks for making this. :)

  • @luketurner314
    @luketurner314 Před 15 dny

    17:50 that colab would be so cool

  • @SperkSan
    @SperkSan Před 16 dny +3

    Hey John I was wondering when you send requests to these actual *bad* websites (not some CTF challenge), do you use a VPN? If no then if the guys behind the website check their logs and see your IP has made some weird requests to their server then won't they target you?

  • @luketurner314
    @luketurner314 Před 15 dny

    17:45 that almost sounds like Owen Wilson's "wow"

  • @kymtoobe
    @kymtoobe Před 16 dny +3

    censys not for usual user :P

  • @htjmartin
    @htjmartin Před 16 dny

    Today I learned that there is an open source phising tool... interesting.

  • @cat_fury
    @cat_fury Před 16 dny

    this work?

  • @maddyfromcartoon
    @maddyfromcartoon Před 16 dny +1

    is brave browser safer than chrome?

    • @arthur979
      @arthur979 Před 16 dny

      if you are smart, every browser is the same

    • @nicholas4839
      @nicholas4839 Před 16 dny

      Nos all the same

    • @linux_for_noobs
      @linux_for_noobs Před 14 dny

      Just don't use chrome, edge, opera or safari. Those are basically spyware.

    • @maddyfromcartoon
      @maddyfromcartoon Před 12 dny

      @@linux_for_noobs how? Can you pls explain? I am using chrome rn.

    • @maddyfromcartoon
      @maddyfromcartoon Před 10 dny

      @@linux_for_noobs Can you explain how? btw I am using Chrome

  • @kalidoom1674
    @kalidoom1674 Před 16 dny

    finds sites like this and writes code to send bogus info ;)~

  • @jon9509
    @jon9509 Před 16 dny +1

    11:27 xD

  • @cyber_space09
    @cyber_space09 Před 15 dny +1

    Hmm🫠 you found Minecraft server 😂

  • @CyberSecJourn
    @CyberSecJourn Před 6 dny

    Dude seriously, why are all your sponsors pretty expensive? If I'm to assume beginners, and people just learning Cybersecurity to gain information to pass a cert or get a job, are they really going to be interested in purchasing these tools, services, etc? I mean, I won't say scammy but it is SURE looking like you're here for the money if I'm to be honest.

  • @Milonsarkar-xn7db
    @Milonsarkar-xn7db Před 11 dny

    On eBay s3

  • @grudge290
    @grudge290 Před 16 dny

    I get this all the time lol

  • @GamerBekodie
    @GamerBekodie Před 16 dny

    Its a real dynamap lol

  • @n18y
    @n18y Před 16 dny +1

    first! i love ur videos

  • @floppa.flo88a
    @floppa.flo88a Před 15 dny

    Jesus loves you John

  • @Cubeocheez
    @Cubeocheez Před 16 dny

    Here before viral

  • @Smurfsmith-os5ip
    @Smurfsmith-os5ip Před 16 dny

    4th

  • @Olflix
    @Olflix Před 16 dny

    3rd

  • @eirik874
    @eirik874 Před 16 dny

    1st