Defcon 21 - Defense by numbers: Making Problems for Script Kiddies and Scanner Monkeys

  Переглядів 295,133

HackersOnBoard

HackersOnBoard

День тому

Panel
August 1st--4th, 2013
Rio Hotel & Casino • Las Vegas, Nevada

КОМЕНТАРІ: 232
@mbunds
@mbunds 5 років тому
We deliver a 500 page instead of 403 after auto-black list to make the script kiddies believe they broke our website.
@creepychris420
@creepychris420 5 років тому
lool
@manishbhatt7653
@manishbhatt7653 5 років тому
lol
@AskJoeTaylor
@AskJoeTaylor 5 років тому
Lol smart
@AskJoeTaylor
@AskJoeTaylor 5 років тому
Hopefully they do not use VPN and find that the website is not broken and have professional hackers attacking your website.
@kleckson5489
@kleckson5489 5 років тому
@@AskJoeTaylor If you have professional hackers attacking your website you're not really worried about the script kiddies in the first place.
@mdo
@mdo 6 років тому
HellNet only returns 666 responses. Confuses the crap out of browsers.
@DMessham
@DMessham 4 роки тому
Wonder if I can do that on my ftp server
@Eo_Tunun
@Eo_Tunun 5 років тому
An IOT tea cooker that replies with 418 would be the only piece of IOT gear I might actually consider to buy. ^^)
@mayube9292
@mayube9292 5 років тому
418 was actually joke-proposed for the then-fictional "Coffee pot over IP" protocol. The idea being if you ask your coffee pot to make tea, but it's actually a teapot, it uses 418 to tell you it can't make coffee because it's a teapot.
@drumguy1384
@drumguy1384 4 роки тому
@@mayube9292 This would be a perfect example of using a joke error code to provide real security. I love it!
@untrust2033
@untrust2033 4 роки тому
Could be possible with a raspberry pi or something just set up to throw 418s and have some controls for the tea cooker :3
@overtheworl
@overtheworl Рік тому
@@drumguy1384 "real security"
@ChrisJohnRiley
@ChrisJohnRiley 10 років тому
Not sure why this was listed on the Def Con DVD as a panel… I'm big, but I'm no panel ;)
@z3r0f0xvideos
@z3r0f0xvideos 10 років тому
Really good talk, man. I'm somewhat new to infosec and your presentation was well laid out and made a lot of sense. Keep up the good work
@aporsuger
@aporsuger 10 років тому
Awesome stuff! Thanks for the entertainment.
@eX0Noah
@eX0Noah 10 років тому
Really enjoyed the talk! Funny and informative.
@Jango1989
@Jango1989 10 років тому
Great Talk!
@MAGACAT
@MAGACAT 6 років тому
WARGARBL
@aten747official
@aten747official 9 років тому
I should set my website up to only throw 7xx errors
@MegaZsolti
@MegaZsolti 7 років тому
Throw in the 418 as well :p
@AndreasDelleske
@AndreasDelleske 4 роки тому
401.0000000000001
@devikakrishna4464
@devikakrishna4464 3 роки тому
@@MegaZsolti iit should throw ouy 42069
@samiraperi467
@samiraperi467 7 років тому
500 is actually shamefully common even if you're not doing anything weird.
@kiraPh1234k
@kiraPh1234k 4 роки тому
Especially in an Enterprise application!
@l-l
@l-l 6 років тому
He's a fantastic first time speaker.
@JoshSweetvale
@JoshSweetvale 5 років тому
English Accent. +10 to Speech
@JayLim-bn9fh
@JayLim-bn9fh 4 роки тому
nice username
@amicloud_yt
@amicloud_yt 5 років тому
Lol, I actually made that "Loading... Please Wait" picture used at 16:10. You can pay me my royalties in the form of HTTP 7xx response codes
@ChillerDragon
@ChillerDragon 5 років тому
11:15 Even if you have 8gb of ram... when you suddenly realise the talk is from 2013 xd
@RyanLynch1
@RyanLynch1 4 роки тому
ChillerDragon that's almost enough for like 3 chrome tabs nowadays...
@Masterrunescapeer
@Masterrunescapeer 4 роки тому
8GB was the norm for dev laptops in 2013, or at least in my company, moved to 16GB in 2015, and half of us have shifted to 32GB this year, with next year having the other half swapped out. Mostly to help with caches on result queries when you're just testing small changes on test data. Normal dev machine I'd still stick with 16 nowadays.
@ukyoize
@ukyoize 4 роки тому
I stil have 8 gigs.
@Masterrunescapeer
@Masterrunescapeer 4 роки тому
@@ukyoize what do you do? If you don't need it, then no point in upgrading/wasting money, can spend it on e.g. a better screen, mouse, keyboard, etc. As I mentioned, for the work I do, it's one of the easiest performance improvements one can do, should be one of the main jobs of your manager to make sure you have the tools you need to be most productive.
@JasperJanssen
@JasperJanssen 4 роки тому
A UKpostsr my work laptop is supposed to run a browser and office. 8GB is fine. Not a coder though.
@AJMansfield1
@AJMansfield1 5 років тому
You could combine the "HTTP tarpit" idea with a full slow loris-style thing to _really_ extend those scan times.
@trevorthieme5157
@trevorthieme5157 5 років тому
Fun times fun times!
@whatever1502
@whatever1502 4 роки тому
Rly nice idea :'D
@JohnSmith-he5xg
@JohnSmith-he5xg 8 років тому
Great stuff. It's surprising how brittle so many implementations are and how simply you can muck things up by going slightly off the beaten path response wise.
@NatoBoram
@NatoBoram 4 роки тому
I mean, they are beaten paths for a reason. It's to ensure interoperability between services and tools. Malicious scripts are just using this interoperability to their advantage.
@chaseroberts2860
@chaseroberts2860 5 років тому
Proxy login User- Nice Pass- Try
@BenSherman42
@BenSherman42 10 років тому
@4:00 is actually 732 - Fucking Unic(U+1F4A9)de (turd symbol) haha
@abitofyourbrain
@abitofyourbrain 7 місяців тому
Oh, I forgot about this talk Absolutely pristine, well spoken wonderfully given talk on the subject Somehow, even as we reach DEFCON 31 somehow every part of this is still very very astute in regards to current affairs and Internet management Nothing changes really does it What a Time to be alive To this day, my absolute favorite lecture I do hope to find more by this man-he seems to be ahead of his time or conceptually people that make browsers don’t move with the times either way what a gem of a human So glad UKposts suggested it
@NekoYuki
@NekoYuki 6 років тому
That moment when you know most of the stuff is going over your head, but the gist is there, you can understand that much, and you're enjoying what you KNOW is about to follow.
@ablindgibsongirl
@ablindgibsongirl 9 років тому
i love watching these presentations. Thank you for uploading. Not a script kitty, interested in first principles. Learning linux via Vinux, reading up on Unix and other whys and hows of computing. This is the next best thing to going. Fully capable of admitting I know nothing. No one gives a shit about the geek blind lady any way. Happy to continue nibbling away at the bytes and bits of computing that are available to me.
@minihjalte
@minihjalte 9 років тому
Its not script kitty, its script kiddy. Script Kiddy.
@corymarsh
@corymarsh 9 років тому
minihjalte Now I want a Script Kitty.
@minihjalte
@minihjalte 9 років тому
Cory Marsh They are quite cheap actually, i think they go for 5 dollars right now.
@corymarsh
@corymarsh 9 років тому
minihjalte Do I need to buy a special keyboard for the script kitty or can they use a normal mac keyboard? I am assuming they come pre-trained.
@paulhendrix8599
@paulhendrix8599 7 років тому
Alex do consider that this could have been a joke. Check out AvE, man
@ehifnvhiebvzeruwdnivbvzbe5644
@ehifnvhiebvzeruwdnivbvzbe5644 4 роки тому
He has a real nice voice to listen to
@MazeFrame
@MazeFrame 4 роки тому
410, because this website is only available when all planets, including but not limited to the ones of our solar system, line up.
@Walter_
@Walter_ 4 роки тому
31:00 I know a way to counter the strategy of sending random or static status codes. Just run w3af like normal but use charles web debugging proxy ( or any other proxy ) and automatically replace every statuscode with a 200. You showed that 200 statuscodes takes the scanning software multiple hours longer to complete but at least the scan will be accurate.
@HritikV
@HritikV 3 роки тому
About fingerprinting, I guess you could do all of those with x-webkit-* CSS directives
@w0ttheh3ll
@w0ttheh3ll 4 роки тому
I like "737 - FuckThreadsing"
@marcosantimaria3879
@marcosantimaria3879 5 років тому
does anyone know where you can get the files from this talk?
@MLIOGJXNUYAT
@MLIOGJXNUYAT 5 років тому
One of my pet peeves is that a lot of 404 responses are more correctly 410 responses. 404: "Not here, try again later"; 410 "Not here, and won't ever be here so don't ask".
@kiraPh1234k
@kiraPh1234k 4 роки тому
It's a bold assumption that some request will be invalid forever.
@NineSun001
@NineSun001 3 роки тому
THis is wrong. 404 statest that the requested resopurce was never here to begin with. 410 states that an existing resource got deleted. Every 410 should become over time a 404.
@ConstantlyDamaged
@ConstantlyDamaged Рік тому
So you mean I should stop 301ing attackers to their own loopback? I might have to investigate that 1xx idea, though. That sounds like fun.
@XxxionxX
@XxxionxX 5 років тому
I use this talk as Ambien, it's perfect.
@yxngsixto.4401
@yxngsixto.4401 4 роки тому
ayeeee.
@danielbrunner829
@danielbrunner829 7 років тому
4:58 does he really say "Gesundheit!" ?
@averagegeek3957
@averagegeek3957 6 років тому
Ja, hat sich so angehört.
@talhatariqyuluqatdis
@talhatariqyuluqatdis 6 років тому
Daniel Brunner ich bin ein berliner
@mcMineoc
@mcMineoc 5 років тому
It’s a common word in some parts of the US
@boblewis5558
@boblewis5558 5 років тому
@@talhatariqyuluqatdis you're a hamburger?!
@Grimpmann
@Grimpmann 5 років тому
@@mcMineoc Only douches who want to seem cool.
@Mixer-he2wb
@Mixer-he2wb 5 місяців тому
Just thinking on the authentication error. Send bad ASCII. Bell tones?
@johnmckay1961
@johnmckay1961 9 років тому
Awesome :)
@MrRandsauce
@MrRandsauce 5 років тому
awesome talk man
@pgoeds7420
@pgoeds7420 4 роки тому
41:39 What web standard is he using from 1990?
@Shadow81989
@Shadow81989 5 років тому
About 23:00 when he talks about telling the website you're using a different browser than what you actually run... Opera had this fantastic feature to: a) "pretend to be browser x" b) "mask as browser x" with browser x being firefox or internet explorer - with chrome just appearing over 5 years later... That was a feature that I regularly used, when websites wouldn't load, because I wasn't using their preferred browser. When using the "wrong" browser, they would not even try to show the content, but just display a warning message... For most websites it was enough to use solution (a) to get it run, which I guess just changed what opera rightout TOLD the website about what browser it was. On SOME websites that would fail though, and you would have to "mask as...", which now I guess made Opera send the typical respond of [whichever browser it was masking as] for the most generally used "browser detection" status codes, when receiving them.
@alexbuhl1316
@alexbuhl1316 4 роки тому
I still use opera. on every front they actually innovate. I love it. >50% doesn't work out, yet they still try again and again. commendable.
@kiraPh1234k
@kiraPh1234k 4 роки тому
As an aside to this: Bypassing a browser check like that can result in using a broken web page. Often, if the site has a preferred browser, it's because they use some feature they know to be implemented on that browser that isn't implemented on others, or they use some specific browser extension (activeX, moz, webkit, etc). It's certainly bad programming on their part and an annoyance, but at least they're giving you the message that says "Hey, I know my garbage web page only works properly in Firefox" rather than letting you wonder why the site isn't working properly.
@johnfrancisdoe1563
@johnfrancisdoe1563 4 роки тому
Rue U There's also Goanna that is a complete Gecko fork.
@NineSun001
@NineSun001 3 роки тому
@@kiraPh1234k Mostly it is used to block out old and skimpy browser which don't comply witht he RFC. Of course I can use a ployfill, but honestly I don't want to serve an IE8 in 2021 and people should feel bad for using it.
@kiraPh1234k
@kiraPh1234k 3 роки тому
@@NineSun001 Uh, no. The situation i pointed out of a web developer using features that exist only in specific browsers is much more common than a situation where a web developer is just not supporting very old browsers. These situations will often happen because either the developer wants to utilize a web feature only implemented on one browser, or wants to implement a browser feature as part of their project. So usually these are browser specific extensions like moz, webkit or activeX controls (and even out of those it's mostly activeX and moz...). You will see this go side by side with supporting only Firefox or only Edge (Firefox so they can keep using moz, or Edge for activeX). This is actually why I used Firefox specifically in my first example. Since it's never a leader in implementation of RFC you'd almost never want to support just Firefox which has some of the worst web compliance of any available browser. So to be clear, in most situations and especially in situations where you see "Only works in IE" or "Only works in Firefox" - this is because the developer isn't following web standards/RFC. It's not because they're stopping RFC compliant browsers (Like say, Chrome, Brave or even Edge - all of which implement more of the RFCs for HTML5/CSS3 and such than Firefox. Next time you see a site supporting only Firefox, look at it's source. Most likely you'll see them using moz extensions for things which other browsers use normal HTML for. Edit: Remember, most humans have bad habits - even in their jobs. Programmers or web developers have never been an exception.
@sham69ohio
@sham69ohio 3 роки тому
How can I get the slides used in this video?
@firstnamelastname2298
@firstnamelastname2298 6 років тому
Thumbs up for numbers )
@elukok
@elukok 6 років тому
Probably not a good idea to use, i would be worried that browsers change the status code behavior in different versions. Firefox 30 could behave differently then Firefox 45. One displaying the content and one not displaying it.
@elukok
@elukok 6 років тому
Not everything. Most major functionality stays the same, at least trough the miner releases. The things mentioned here will probably be different every small release. It would be quite hard to keep up and test every new version of the browser. Automating it would be one solution though.
@MobCat_
@MobCat_ 4 роки тому
Error 200 - This is a nice message telling you to piss off nice, i am soo using that >__
@onyxtay7246
@onyxtay7246 6 років тому
411 Ouch. Really don't want to get that one huh.
@sticky170
@sticky170 6 років тому
411 that's what she said
@fartyperson
@fartyperson 5 років тому
Tongue slaps
@philswaim392
@philswaim392 5 років тому
Really cool info on http and how to bend rfc vs reality. However i dont think this type of obscurity is very sustainable through turnover in companies. I could see using honey headers or other kinds of trickery to get attackers to reveal themselves and their techniques more clearly, but you have to be able to manage these kinds of configurations. It would be better to hold to standard configuration for your production stuff and throw curiosities in the environment to distract ne'rdowells and make their presence and their movement more obvious. I can get behind obscurity helping security, but you cant confuse your developers and 3rd parties as to why your webserver is always showing 300 or 400 when everything is working just fine.
@benistingray6097
@benistingray6097 6 років тому
I would call myself a script "kiddi" but in a good way, let me explain. As i started to get interested in these things i was 28 years old and i tried my best to start with some python but honestly i just cant remember all that stuff lol. But im still interested in it and want to know how these things work and such scripts help me a lot to understand at least basicly whats going. Im just messing around in my home network and my biggest "achievment" was to crack my own wpa2 network. A lot didnt work but i didnt give up and researched a lot of things and at the end it worked. So yeah i think it isnt allways bad, i learned some things, i felt i achieved something and at the end it was also a lot fun. Anyway have a nice day folks ;)
@JoshSweetvale
@JoshSweetvale 5 років тому
The vernacular difference is the same as the one between difference between 'noob' and 'newbie'. Taking scriptcode apart isn't what 'Scriptkiddies'(vernacular) do. They find these programs and use them as blunt instruments of cyberwarfare, without much thought as to how. The 'lout with a brick' of hacking.
@adgasdggfg
@adgasdggfg 5 років тому
Give a man a wifi password and he has internet for a spot Learn a man how to hack a wifi password and he has internet forever
@luxzartheglorious
@luxzartheglorious 4 роки тому
@@JoshSweetvale skript kiddies will beat you with a stick, where a skript noob will learn to sharpen said stick
@broquestwarsneeder7617
@broquestwarsneeder7617 4 роки тому
i like this dude
@alexchristensen2651
@alexchristensen2651 4 роки тому
601: i like this guy
@TheKorrent
@TheKorrent 5 років тому
4:59 Gesundheit
@minnermin
@minnermin 5 років тому
"The wisest man is the man who knows he doesn't know jack shit" ~socrates
@SamJakob1
@SamJakob1 6 років тому
420! It is used by Twitter!
@Yuzuki1337
@Yuzuki1337 4 роки тому
Error 420 - the cache is too high
@nnslife
@nnslife 4 роки тому
Start watching at 19:50. First 20 minutes is a complete waste. This is talk about HTTP response codes, specifically about two things: 1) Different browsers behave differently when receiving rare HTTP codes. You might use it to detect the real browser person using. It's easy to fake request http header with browser info, but it's harder to fake browser behaviour and fewer people will do that 2) You can really confuse automated scanners by returning rare/wrong/random HTTP codes If these two things are not of your interest than you don't need to watch the talk. Otherwise start watching at 19:50. First 20 minutes is a complete waste.
@THEFRISKIESTDINGO
@THEFRISKIESTDINGO 10 років тому
42:50 - I want to go to Defcon
@Gredddfe
@Gredddfe 4 роки тому
I've been pronouncing nginx as "en-ginks" for years.
@kiraPh1234k
@kiraPh1234k 4 роки тому
Same, and now I can't get "N Gin X" put of my head
@SonOfNone
@SonOfNone 6 років тому
I worked for a company that used 503 - busy/try later response codes for all email not in a custom white list. Seems smart since spam never retries emails, but sometimes neither does legitimate email servers. Fucking nightmare
@ThoriumHeavyIndustries
@ThoriumHeavyIndustries 10 років тому
Nice talk unless the comment about loadbalancers. Loadbalancer like F5 or Cisco can help you a lot with fighting of skriptkiddies and DDoS. And If you host websites, you have loadbalancer, at least for redundance.
@larsfinlay7325
@larsfinlay7325 9 місяців тому
I'm something of an edge case myself
@AlaricScandoveski
@AlaricScandoveski 4 роки тому
... Why does he sound like 'Internet Historian'?
@Mmouse_
@Mmouse_ 4 роки тому
500 I see a lot because I like to miss punctuation in php
@Ratty2480
@Ratty2480 4 роки тому
Dude have a drink
@AssemblyWizard
@AssemblyWizard 5 років тому
39:21 the regex is wrong, it should've been parentheses instead of square brackets. This means there should be more than a 1000
@atorac
@atorac 5 років тому
() parentheses are for group matching, no use there.. res[p|ponse]? matches 3 options: res resp response Which is exactly what he meant to do. Not crazy complex and gets the job done.
@AssemblyWizard
@AssemblyWizard 5 років тому
Puffo Sciamano No, `res[p|ponse]?` matches: res resp res| reso resn ress rese While `res(p|ponse)?` matches res, resp, response Like he wanted. Or better - `res(p(onse)?)?` Know your regexs.
@atorac
@atorac 5 років тому
@@AssemblyWizard oh my.. uops :) I stand corrected, kids dont drink and regex
@opensourceftw3282
@opensourceftw3282 8 років тому
200 Hacking Appempt Detected...
@lonewanderer1776
@lonewanderer1776 8 років тому
699 - Deez nutz
@paulhendrix8599
@paulhendrix8599 7 років тому
Lone Wanderer is 666 a thing?
@pawpatrolnews
@pawpatrolnews 3 роки тому
You don't need to be mean to the people with spiders! They aren't hurting you.
@CrucesNomad1
@CrucesNomad1 4 роки тому
good primer
@CaboLabsHealthInformatics
@CaboLabsHealthInformatics 3 роки тому
why assume everyone scanning is a script kiddie?
@visvge4934
@visvge4934 2 роки тому
Anyone scanning without your permission might as well be considered potentially checking for weaknesses
@minnermin
@minnermin 5 років тому
Appachkey
@repairaholic4858
@repairaholic4858 4 роки тому
Why would you have to restart your android phone when you can go to app and force close it 🤔
@LiEnby
@LiEnby 4 роки тому
if you sent 404 on every request then most libaries would have *issues* GET-ing pages, like python requests would throw an exception lel though its worth mentioning the PS4 browser does check for status code 404 then display a generic "Not found" message^
@destiny_02
@destiny_02 Рік тому
And so does Chrome Mobile
@hosting_utilities
@hosting_utilities 5 років тому
Way too many problems with this: I believe this is bad for SEO. No research was done about how this affects screen-readers. This could negatively affect bots that a marketing department uses to do things like scanning a website for info about the internal link structure. I could see a caching mechanism or a caching preload bot failing to cache pages that do not return a 200 response. Programs that analyze the health of the network will fail to work properly. And some of these programs it would be interfering with could be third-party programs that would have to be replaced with in-house solutions.
@lerubikscubetherubikscube2813
@lerubikscubetherubikscube2813 4 роки тому
Could you not have this setup to change the return code rules dynamically depending if you want to use a tool to check the health of your website? Also, could you not whitelist certain bots while still avoiding malicious ones?
@kiraPh1234k
@kiraPh1234k 4 роки тому
Actually, this setup is easy to use with in house interference. When you have access to your own network, it's a different beast than the Internet coming in. The Internet traffic is restricted to whatever you exposed to them, but from inside you could for example, simply use your health checking tool on the server directly, ignoring the proxy that all the internet traffic is coming through, hence getting all the correct response codes into any needed tool. Edit: It likely won't actually impact SEO much either, mainly due to search engines using content and reference to judge rank, not response code. It could impact the spider's ability to crawl the site, but there are solutions to that as well.
@creepychris420
@creepychris420 5 років тому
Opera is awesome again dude, it's 2018 check that shit out
@isbestlizard
@isbestlizard 4 роки тому
i HATE that browsers don't respect 410 Gone for their stupid fucking favicon requests and keep DEMANDING more favicons even though every response is me saying NO it's NOT HERE and is NEVER GOING TO BE HERE
@isbestlizard
@isbestlizard 4 роки тому
how much net traffic could be saved if fucking edge and mozilla and chrome RESPECTED 410 Gone for crappy speculative requests and STOP ASKING on that domain/whatever
@isbestlizard
@isbestlizard 4 роки тому
i wish my wishes came true except typing them here as a reply to a random video about http status codes probably isn't going to make it happen :
@isbestlizard
@isbestlizard 11 місяців тому
I was right then and I stand by old me
@uimvbjhjzephhmfvyvjlhccabj3855
@uimvbjhjzephhmfvyvjlhccabj3855 8 років тому
i use lynx!!!!!!!!
@nullplan01
@nullplan01 5 років тому
For youtube?
@pteppig
@pteppig 5 років тому
Oh, that was you
@authorizedblock2373
@authorizedblock2373 5 років тому
WORLDSTAGE- be safe, have fun. But RESULTS AND irreconcilable RUIN Runs Randomly recurring risk.
@Skylarr
@Skylarr 7 років тому
I'm a little late here xD but I have my servers set up to try to attack the person who's attacking me back
@luxzartheglorious
@luxzartheglorious 4 роки тому
He's 13 now
@daydodog
@daydodog 5 років тому
this is *by far* the most lost i've been watching a defcon talk
@ukyoize
@ukyoize 4 роки тому
Why not just write code without wurnerabiblities?
@lort256c
@lort256c 8 років тому
GG first GG
@Shadowlogic420
@Shadowlogic420 4 роки тому
Am I the only one noticing Bitcoin miner scripts in the sources of websites these days? That's some shady shit.
@asbeltrion
@asbeltrion 4 роки тому
Wait, what?
@pinguimgutembergcarvalho7775
@pinguimgutembergcarvalho7775 4 роки тому
Eu só fiz isso pois não quero ser preso por hackers vcs. Simples assim.
@DeeWeext
@DeeWeext 8 років тому
"a 300 fold" .....
@casportflyers
@casportflyers 8 років тому
A 300 fold. wut
@alextilson9741
@alextilson9741 5 років тому
This has to be fucking terrible for SEO lol
@ShroudedWolf51
@ShroudedWolf51 5 років тому
....why is he using IE6 as the Internet Explorer example? IE has been decent enough since IE9 came out and IE10 released nearly a year before this talk.
@thedarkness125
@thedarkness125 4 роки тому
Internet explorer still isnt decent.
@johnfrancisdoe1563
@johnfrancisdoe1563 4 роки тому
ShroudedWolf51 He only mentions trying "all" IE versions and IE6 being the extra weird one.
@HackersOnBoard
@HackersOnBoard 4 роки тому
Hello dear friends Today we get notified of the censorship of our channel by the new UKposts Guidelines (who change every 6 months) because of "Content reusing without including substantial original commentary or educational value" This is a little bit tricky because these Guidelines wasn't there in 2013, 2014, 2015 and so on... It is abnormal to change the rules during a game ...even more before Christmas! Since 2013 we are trying to share the best Security Conference on our channel and we need your help to keep it up. As you already know I was fighting the disease since the last 2 years and it's difficult and without resource and support I wouldn't be able to keep up on this way. You can support us on Patreon if you find our work valuable. You can also express your dissatisfaction regarding our situation to UKposts on Twitter, Facebook, Instagram and wherever you can. to help us regain our rights. Your support in anyway will be truly appreciated Thanks guys for taking time reading me and stay tuned! Merry Christmas to you all and God bless you all! www.patreon.com/HackersOnBoard Bitcoin Wallet: 1NWM4upgKj8iF7zknzmnHG8Mm2pvAyTHqc
@m.h.8729
@m.h.8729 9 років тому
i dont understand anything
@talhatariqyuluqatdis
@talhatariqyuluqatdis 6 років тому
Angry addict lol
@jonharson
@jonharson 5 років тому
Found the script kiddy.
@m00str
@m00str 6 років тому
it freaks me out every time a English speaker says "Gesundheit". since it's German for health
@RnBandCrunk
@RnBandCrunk 6 років тому
Rou Lor it's the equivalent of "bless you" in english.
@ERIK31351
@ERIK31351 5 років тому
Why would that freak you out?
@nopenope7184
@nopenope7184 5 років тому
@@ERIK31351 Because "bless you" at least somewhat makes sense and just saying "health" is weird.
@alex190291
@alex190291 5 років тому
the german set phrase "Gesundheit" has its origin in the idea, that you wish health ("Gesundheit" in german) for yourself when somebody sneezed around you. But nowadays it means you wish "Gesundheit" for the sick person, even if the origin is, that you wish health for yourself :D
@berndlauer2894
@berndlauer2894 5 років тому
I hate it that they disrupt talks for drug usage.
@alex190291
@alex190291 5 років тому
@Bobby Fisher i also hate, when someone disrupts my drug usage for talking...
@robpatershuk
@robpatershuk 5 років тому
I much prefer when a talk incorporates drug usage. Far more interesting than the alternative.
@thedarkness125
@thedarkness125 4 роки тому
Man that alcohol is so evil. I wish the devil would burn them down with his fury...shut the fuck up.
@OEFarredondo
@OEFarredondo 5 років тому
Haters lol lazy hackers is all a skittie is
@kiraPh1234k
@kiraPh1234k 4 роки тому
Nah, that's too much credit. A hacker actually creates solutions to problems and makes tech do what they want. A script kiddie is generally not a hacker, they have less interest in engineering any solutions and more interest in commiting crime.
@carcolgeo
@carcolgeo 5 років тому
"No one cares about edge case stuff" says someone who knew nothing about ai as late as 2013.
@zeroskill.
@zeroskill. Рік тому
im going to save you 49 minutes, common scanning tools are poorly crafted when it comes to out of the ordinary http response codes, you can (as of 9 years ago) fingerprint which browser a client is connecting with with php using response codes. sending random response codes to suspicious ips can cause scanners to behave strangely. in the end more of a deterrent than any real solution
@blackneos940
@blackneos940 4 роки тому
What if you speak at Defcon and don't drink because of Bipolar and Autism?
@undefined879
@undefined879 4 роки тому
blackneos940 what
@blackneos940
@blackneos940 4 роки тому
@@undefined879 I asked exactly that. :)
@thesuperpunmaster6369
@thesuperpunmaster6369 4 роки тому
@@blackneos940 do it pussy
@HelloKittyFanMan.
@HelloKittyFanMan. 5 років тому
So... what if some "script kiddies" are watching this and will now learn how to circumvent this kind of defense?
@Roxor128
@Roxor128 5 років тому
Script kiddies are called that because running scripts is about as far as their computing knowledge goes. They don't have the experience to modify their tools to circumvent these measures yet. If they're interested enough to try, they'll probably develop a more-productive interest and end up writing code for a living or end up becoming security researchers themselves a decade down the line.
@Tridd666
@Tridd666 4 роки тому
"the big three" "Firefox" This video did not age well
@HelloKittyFanMan.
@HelloKittyFanMan. 5 років тому
Wow, you tested IE from the current one for this part of 2013 clear down to 1.0, eh?
@SJWBach
@SJWBach 6 років тому
you could rediredt attackers to childporn so the police breaks thair doorin the next 30 minutes xD
@SJWBach
@SJWBach 6 років тому
maybe even government honeypods and not real childporn so they arrive even faster xD
@ownageDan
@ownageDan 5 років тому
@@SJWBach ecksdee
@luxzartheglorious
@luxzartheglorious 4 роки тому
@@SJWBach yer
@HelloKittyFanMan.
@HelloKittyFanMan. 5 років тому
Oops, there's no such thing as a "PHP page"! Why? Let's see if you can figure that out! ;-) Opes, didn't figure it out? Because "PHP" already _stands_ for "__________ _page_ "!
@HelloKittyFanMan.
@HelloKittyFanMan. 5 років тому
"Each to their own"? Oops! What did you think that means? The common phrase that's reminiscent of that is actually " _to each_ their own" (or "to each his/her own").
@kamigo
@kamigo 4 роки тому
It would have been better if he was a little bit more polite.
@HelloKittyFanMan.
@HelloKittyFanMan. 5 років тому
"Respond back"? So you're saying... like... "say something back _back_ "? Oops!
@HelloKittyFanMan.
@HelloKittyFanMan. 5 років тому
"No one really cares who the speaker is"? um... do you think you're a mind reader? I have news for you: you're not one!
@butteredtoast8666
@butteredtoast8666 4 роки тому
The speaker is pretty melancholy. He's pretty negative. Depressing. He needs some counseling and encouragement or something.
@sebastians3773
@sebastians3773 4 роки тому
He's British. That's racist.
@HelloKittyFanMan.
@HelloKittyFanMan. 5 років тому
Guess what: there's and _easier way_ to say names of years like 2013 instead of "two thousand [and] thirteen": Remember from last and previous centuries when you said "NINETEEN-thirteen," etc.? Well, that method works in this century too; it's less syllables just like before! Try it today!
@HelloKittyFanMan.
@HelloKittyFanMan. 5 років тому
"TL;DR"? Nope, this is a speech with visuals, so more like... TL;DW! ("Watch"!)
@HelloKittyFanMan.
@HelloKittyFanMan. 5 років тому
"I know... nothing." Yeah, like... where to use commas or _not_ use them! Case in point: "The wisest man,"... (oops) ...."is he who knows,"... (oops again) ..."that he knows nothing." Well, not _absolutely_ nothing.
@HelloKittyFanMan.
@HelloKittyFanMan. 5 років тому
Oops, there is no such character as "Miss Pac-Man." Why? Because the closest thing we have to that is Ms. Pac-Man ("Ms." refers to either married or single; "Miss" is for single only.) But good attempt at a joke with that, still!
@jwadaow
@jwadaow 4 роки тому
Hello Kitty Lover Man! Ms. Being a fake artificial article
@HelloKittyFanMan.
@HelloKittyFanMan. 5 років тому
OR... why not just scan your sites yourselves and then _fix your vulnerabilities?_
Defcon 21 - Forensic Fails - Shift + Delete Won't Help You Here
47:10
HackersOnBoard
Переглядів 635 тис.
Defcon 21 - Stalking a City for Fun and Frivolity
45:20
HackersOnBoard
Переглядів 246 тис.
Угадайте концовку😂
00:11
Poopigirl
Переглядів 3,9 млн
DEFCON 16: Toying with Barcodes
44:26
Christiaan008
Переглядів 370 тис.
Defcon 21 - Social Engineering: The Gentleman Thief
41:55
HackersOnBoard
Переглядів 370 тис.
Ochko123 - How the Feds Caught Russian Mega-Carder Roman Seleznev
49:06
DEFCON 17: That Awesome Time I Was Sued For Two Billion Dollars
31:28
Christiaan008
Переглядів 1,6 млн
DEF CON 31 - Terminally Owned - 60 Years of Escaping - David Leadbeater
47:34
СКОЛЬКО ЕЩЕ БУДЕТ АКТУАЛЕН IPHONE 13?
14:10
DimaViper Live
Переглядів 31 тис.
МОЙ ПЕРВЫЙ ТЕЛЕФОН - Sony Erricson T280i
18:02
ЗЕ МАККЕРС
Переглядів 49 тис.