Hackers Use Github For Malware

jh.live/keeper || Keeper Security offers a privileged access management solution to deliver enterprise grade protection all in one unified platform -- keep your users, your data, and your environment secure with Keeper! jh.live/keeper
Learn Cybersecurity - Name Your Price Training with John Hammond: nameyourpricetraining.com
Read The Hacker Mindset by Garret Gee: jh.live/hackermindset
📧JOIN MY NEWSLETTER ➡ jh.live/email
🙏SUPPORT THE CHANNEL ➡ jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
🌎FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
💥 SEND ME MALWARE ➡ jh.live/malware
🔥KZread ALGORITHM ➡ Like, Comment, & Subscribe!

Пікірлер: 67

  • @_JohnHammond
    @_JohnHammondАй бұрын

    To clarify, with the comments upload drag-and-drop trick, you can't upload any file extensions outside of this allowlist (i,e., executable files not allowed): GIF, JPEG, JPG, MOV, MP4, PNG, SVG, WEBM, CPUPROFILE, CSV, DMP, DOCX, FODG, FODP, FODS, FODT, GZ, JSON, JSONC, LOG, MD, ODF, ODG, ODP, ODS, ODT, PATCH, PDF, PPTX, TGZ, TXT, XLS, XLSX or ZIP. Nothing stopping you from putting things in a release asset, though 😜 That trick looks to be doable on Gitlab just as well.

  • @tomashublik5586

    @tomashublik5586

    Ай бұрын

    6hrs ago wtf

  • @blinking_dodo

    @blinking_dodo

    Ай бұрын

    I hope you have properly reset your GitHub session... 😅

  • @nordgaren2358

    @nordgaren2358

    Ай бұрын

    @@tomashublik5586 Video gets uploaded the day prior for scheduling. Can comment on it as much as you want, until then.

  • @xanderplayz3446

    @xanderplayz3446

    Ай бұрын

    Or just put an EXE in a password-protected zip and make a project with an issue, which you report on an alt, with logs in a zip, which has a password, and you fake a conversation between you and the alt, saying that it has a password, and then the alt sends real logs in a zip; There would be no evidence of malicious intent.

  • @us_f4rmer
    @us_f4rmerАй бұрын

    That´s an social engineer's wet dream. But the fact it works w/out even posting the issue is really the icing of the cake!

  • @discocat2500
    @discocat2500Ай бұрын

    The issues-based file hosting is wild. You would think a person would at least need to submit the issue to have their files stored on a server for any length of time. I wonder how long those links are valid.

  • @archlinuxsys
    @archlinuxsysАй бұрын

    this is why i love john. he's so passionate and eager to share!

  • @Jshicwhartz

    @Jshicwhartz

    Ай бұрын

    No, he technically has a 'business' to run, i.e., his KZread channel. He posts what he knows will generate clicks while also using his skills.

  • @BillAnt

    @BillAnt

    Ай бұрын

    @@Jshicwhartz - While providing clear info understandable by most folks.

  • @Creeperfun12

    @Creeperfun12

    Ай бұрын

    @@Jshicwhartz so your saying he doesnt enjoy his job

  • @Bluegeneral05
    @Bluegeneral05Ай бұрын

    Dude, this is awesome, great video!

  • @Leadshot
    @LeadshotАй бұрын

    So i am currently doing a cyber security course and theres a project coming up where we have to setup a metaspoiltable 2 box.. could anyone tell me some tools to use to pentest the box if i am on team red and or some tools to defend the box etc on team blue? Would i need to have python knowledge as i am very new to it and i am starting to dip my toes in it

  • @patrickslomian7423
    @patrickslomian7423Ай бұрын

    Python Selenium would be a simple solution. Imitate a web browser, "upload" your file, get the url and send it to the c2 server / client .

  • @funil6871

    @funil6871

    Ай бұрын

    Python selenium is pure love

  • @vaisakhkm783

    @vaisakhkm783

    Ай бұрын

    We can detect Hearless selenium's presence easly with cpu spike... 😂 but in windows it's doesn't make a dent, so it's fine but linux user would easly find it

  • @BluescreenSharp

    @BluescreenSharp

    Ай бұрын

    Would Not be. Its detected.

  • @patrickslomian7423

    @patrickslomian7423

    Ай бұрын

    @@BluescreenSharp Have you tried to run the script over a proxy ?

  • @wrathofainz

    @wrathofainz

    Ай бұрын

    That would be great if websites weren't able to detect things like selenium and chrome driver. Js and the dev tools are to blame. The people making browsers just aren't hardening them against developer tools being detected, so a site can refuse to work if you open it in selenium or even open the dev tools (like aniwave or 9anime)

  • @dothex
    @dothexАй бұрын

    I see you changed the title of the video and thumbnail with the quickness.. I'm guessing "How to use Github to hack" wasn't as viable as you thought :D

  • @funil6871

    @funil6871

    Ай бұрын

    😂

  • @unknownlordd
    @unknownlorddАй бұрын

    who would've thought 😱

  • @ronaldosd
    @ronaldosdАй бұрын

    Lol, Microsoft is still using AWS for Github and not Azure 😂😂

  • @kcnl2522

    @kcnl2522

    Ай бұрын

    Migration is a pain on the ass even for msft

  • @cringesh1t427

    @cringesh1t427

    Ай бұрын

    @@kcnl2522so are Russian hackers

  • @exploittutorial8689
    @exploittutorial8689Ай бұрын

    I was once following your tutorial on burpsuite and I downloaded foxy-proxy extension on my Linux machine. Whenever I tried to use terminal as sudo the terminal freezed. I cannot recall the exact extension developer but clearly it was some variation of foxy-proxy. I uninstalled the extension and the terminal worked again. You should do a video on this

  • @mattd1957
    @mattd1957Ай бұрын

    Hay John, I hope you're doing well, so I'm trying to find a websites Directory with Linux like Ubuntu, but I'm not sure how, can you make a video on how to find a websites directory please Thanks. 😊

  • @emc2847
    @emc2847Ай бұрын

    Hi John, great video. How can I connect with you about learning more.

  • @user-jd3gf5xw1x
    @user-jd3gf5xw1xАй бұрын

    10:14 I love that that's the video, idk it's hilarious

  • @wrathofainz
    @wrathofainzАй бұрын

    I can imagine having a command of some sort in a file hosted on github and malware hosted on a device which occasionally checks that repo for a commit to that file, or perhaps a comment in a reply chain or something... I was specifically thinking that your command & control changes a file on the repo and at some point the malware will pull that file (during a poll :P) and do the command like taking a screenshot and uploading it back to the repo. Idk Very interesting video. I'm already using github to share memes, but now I'm getting ideas about how I can use other sites I'd otherwise never touch, like Truth Social.

  • @yalekthelembine0391
    @yalekthelembine0391Ай бұрын

    Why does the Linux community ignore this? Especially Linus Torvalds? Because they're also hackers. And by the way RMS, hacker is also ambiguous . Hacking is also dangerous because of its black hat definition.

  • @mentor_bajrami
    @mentor_bajramiАй бұрын

    I keep reporting github malwares on a daily basis

  • @smnomad9276

    @smnomad9276

    Ай бұрын

    Thanks for your service man. This is the essence of open source, we need more people like you.

  • @user-my2kp6js8o
    @user-my2kp6js8oАй бұрын

    love from nepal

  • @zanidd
    @zaniddАй бұрын

    You forgot my kind of hackers: the ugly

  • @VaibhavShewale
    @VaibhavShewaleАй бұрын

    well that was a fun until it lasted!

  • @anselmoarantes
    @anselmoarantesАй бұрын

    When I Saw the title, what came to my mind was "Who Doesn't?"....

  • @xpower7125
    @xpower7125Ай бұрын

    github is the new discord (kind of)

  • @funil6871

    @funil6871

    Ай бұрын

    True

  • @zanidd
    @zaniddАй бұрын

    Keep'er Security? I hardly know her!

  • @cyber_space09
    @cyber_space09Ай бұрын

    Okay Sir that's what i want to do 🤣📈🚩

  • @dademurphy6123
    @dademurphy6123Ай бұрын

    Are you Seth Rogens brother?

  • @zcavaleiro
    @zcavaleiroАй бұрын

    Looks like web 1.0

  • @pliusleft
    @pliusleftАй бұрын

    discord was so much easier before they made the fix

  • @kcnl2522

    @kcnl2522

    Ай бұрын

    You are talking about the cdn links ye?

  • @abdallamohamed5844
    @abdallamohamed5844Ай бұрын

    Wow

  • @c.n.crowther438
    @c.n.crowther438Ай бұрын

    Seth Rogan sounding breh

  • @arunprakash2426
    @arunprakash2426Ай бұрын

  • @user-jd3gf5xw1x
    @user-jd3gf5xw1xАй бұрын

    I thought it was gonna be the zoo

  • @carsonjamesiv2512
    @carsonjamesiv2512Ай бұрын

    😀👍

  • @endoxidev
    @endoxidevАй бұрын

    dang just 4 minutes and I'm already here

  • @wrathofainz
    @wrathofainzАй бұрын

    Lmao, this totally works 😂

  • @iamwitchergeraltofrivia9670
    @iamwitchergeraltofrivia9670Ай бұрын

    Hahahhhhhhahahh so many malware

  • @IlIIllIlIlIIlIlIlIlIIl
    @IlIIllIlIlIIlIlIlIlIIlАй бұрын

    .

  • @ChristmasTvGames
    @ChristmasTvGamesАй бұрын

    8th comment here

  • @hollywoodhank591
    @hollywoodhank591Ай бұрын

    First!!!

  • @tomashublik5586

    @tomashublik5586

    Ай бұрын

    nope

  • @uncleburu9464
    @uncleburu9464Ай бұрын

    First

  • @tomashublik5586

    @tomashublik5586

    Ай бұрын

    L, I am first

  • @zwanski.m
    @zwanski.mАй бұрын

    I've been a follower since 2018 but he never response to my comment 😂

  • @insomniac-afk

    @insomniac-afk

    Ай бұрын

    no one gives a fucking shit

  • @tomashublik5586
    @tomashublik5586Ай бұрын

    first