Your Win2k was infected from the get go.... man that brings me back. I can't believe that the Sasser is still active after over 20 years... this was also my first contact with Computer Security ^^ A freshly bought brand new computer from the local store, and as soon as the 56k modem finished, 20 seconds later I got the "System is shutting down" message. it is crazy how vulnerable Windows was (and partly still is)
Sasser was prolly the first time my PC got infected by something from the Net. It was also one of my early years of using the Net. Ig that's one way of learning the Net isn't safe.
@@Jesus.Christ106 hmm... not so sure about that. Supercomputers, servers, embedded/IOT devices, most smartphones, routers modern switches, some gaming consoles, microcontrollers all run on unixoid systems. Only the PC Desktop is dominated by Windows.
Lol not if you use a good firewall, if you use Windows on the public internet with only the Windows firewall without a hardware firewall such as a good modem or router or with wrong settings such as DMZ you WILL get hacked...
this is the same dude who farmed 320k views with the fake XP video before, putting it on the internet with NO firewall (which is not how the vast majority of people are connected to the internet) and because that STILL didn't work he googled for malware to infect the system with and accidentally left the browser window of him searching for it in the video
Most interesting is how it got hacked - anyone could suggest a path of infection ? Back in the day I recall servers got infected from one each other - so having pool of Win2k and one got infrected you had to deal with each separaterly before you got them back online. Its 2024 and I cant imagine anyone still having Win2k online that is infected and just waits for another Win2k to go online. Second thing which is bothering me is how does one get infected behind NAT at this point. Any comments welcome
4:30 Actually this happens when an attack fails. There is a similar video of exposing a real machine running Windows 2000, it kept rebooting and blue screening
Might be the WannaCry virus that went around back in 2017. If I remember correctly, if it tried to infect a Windows 2000 machine, it wouldn't be able to do anything else to it but crash it
7:22 If you wanted to revive Windows Update in earnest, you could install Legacy Update which redirects it to a community-hosted reverse-engineered server.
if you like people faking their way to clicks and views then sure lol. this is the same dude who farmed 320k views with the fake XP video before, putting it on the internet with NO firewall (which is not how the vast majority of people are connected to the internet) and because that STILL didn't work he googled for malware to infect the system with and accidentally left the browser window of him searching for it in the video lmao
super cozy nostalgia trip of giving all my early OS's literal aids when I was a child....but now its like we have a security wizard here to show and explain to us all about the aids we were giving our pc's back in the day :3
Neat to see. Everyone always talks about XP but Win2K was my daily driver untill xp sp2 was released. Win2k was always one of my favorite versions of windows.
Never switched to XP, never had a reason. Win2k could do anything XP could do, while not looking like a Kids toy. Kept Win2k until Win7 came out. Of course i was missing out on a additional taskbar icon, who's only purpose was to tell me whenever my antivirus was running or not, what a loss. :-D
@@timhartherz5652 I don't recall why I switched to XP. I did use to turn off the visual styling so it looked like W2K though, also used less resources.
I just found your channel because of a german article on a website. It's really interesting to see how the old systems "perform" in 2024. :) please go on with the series!
I saw somebody write an article about you showing what happens if you connect Windows XP to the internet, it bought me to your channel to see more interesting videos :)
@@yeahhhhhhhhhhhhhhhhhhhhhhhhhh Can't post links in YT comments, PCGamer have an article that specifically talks about Eric's video though, popped up on my phone's news feed last night so might be that one, but it's literally just a written summary of his video, they didn't add anything particularly interesting themselves, just reporting on the facts I guess
Back in 2015 Microsoft released an emergency update going as far back as windows 2000 bc 2000, XP, vista, etc had this exploit. It was released after wanna cry was spawned and had to do with the rdp of I remeber correctly. Anyways all I can say is to install that update and then trying this again. I was amazed that Ms not only quickly released that update but for Windows XP and especially 2000...
Wannacry was an SMB v1 exploit if I remember correctly. We were in the midst of a full scale company wide disaster recovery test when I was given the green light to disable SMB v1 across the board. Rolling out GPO’s at that scale are always fun. We had some heart sore Linux admins the next morning who couldn’t connect to shares anymore with their outdated Red Hat distros 😂.
EternalBlue (SMBv1 exploit) appeared in 2017, BlueKeep (RDP exploit) in 2019, for both beginning from WinXP patches has been issued. Never heard about any patches for 2000, guess its market share was extremely tiny to bother with even back then.
If I were to guess it's probably because WinXP and older are still in very regular use within industrial fields among other arguably more important ones, like nuclear facilities and Microsoft probably know how dumb people can be, after all this video is proof that all it would take is someone to connect it to the network with internet access for a couple of minutes lol Edit: Then again saying that, you'd hope if someone were stupid enough to connect it to the network that things like NAT or a firewall would save it, but I ain't gonna build a 2000 box to test that theory lmao
@3:40 i remember seeing that live back in the day via the Blaster worm, basically if you had your windows 2k system directly on the internet with no firewall, there was a good chance that the worm would eventually hit your IP causing this shutdown popup, and then it would start DDoSing windows update. Man viruses back in the day always were memorable, Nimda, Code Red, Blaster, ILOVEYOU, Melissa. Now days its all just generic trojans and cryptolockers
i hooked up a windows 2000 server machine direct to the internet back in 2003. it was just for a few minutes to download drivers before i moved it to an air gap net. I went to lunch. when i got back it was already fubar'd
It'd be interesting to see older versions of NT, like 4 or even 3.x, and whether they're still actively targeted (or vulnerable to the same exploits that target 2k and XP).
Hi Eric! a) the Win2k startup sound is absolutely the best one! b) the fact you keep closing the Tip of the Day window every time and not unclick the tickbox at the bottom of it is so funny :D Thanks for the vid.
So ... completely exposed host? All ports from router directly forwared to the VM? I´ve been using Retro systems online for years now. Behind NAT they don´t get hacked....
The video title describes exactly what has been done here. This is just how you connect a host to the internet. LAN is a different story and it requires a gateway to forward traffic to remote hosts. There are different applications involved, if you access the internet from inside a LAN. Its never been a good idea to connect Windows directly to the internet, lookup how old Norton Internet Security (just naming this popular example) is and you'll see...
@@Knaeckebrotsaege well, if he didn't do that, it's unlikely something interesting would happen unless he went to look for malware manually. Oh wait, he did that in the WinXP video.
@@Knaeckebrotsaege Why does this upset you exactly? He's not hiding this, it's made pretty obvious that you have to go out of your way to expose yourself this much. It's just a fun demonstration of what happens if you do
If not script kiddies, there's plenty of internet connected appliances out there running 2k/XP; ePOS machines, ATMs... Their chances of infection should have been reasonably low, but given they've been running for decades at this point, that's a lot of chances to roll those dice.
@@papajohnscookie Surely, but only the LSASS issue is critical to the continued functioning of an infected machine, and it's quite possible to have a particular configuration of updates that eliminates this issue, whilst not resolving the infection itself and therefore allowing continued propogation. Consider this: If Sasser shut down every machine it infected, why then was it able to spread so virulently in the first place?
@@rossstewart9475 That's a fair point, my personal anecdotal experience was that Blaster would just constantly cause the lsass process to crash and shut the machine down. I do love the idea of a number of legacy systems being infected with a worm that is 20 odd years old and want it to be true! I intend to set up the same sort of lab environment that was in this video. I'll let you know the results.
This stuff is so interesting, it's amazing how fast you're pwned. Are there bots just nmapping the entire v4 address space 24/7 or something? Who's doing this for 20 year old OSes? Any chance you can get a packet capture for one of these experiments?
There literally are systems scanning the whole IP space; legitimate ones like Shodan for analytical and security purposes, botnets searching for new infection prospects, nation state actors looking for footholds and kids at colleges or universities learning about computer security who will probe you from their campus IP in another country so they don't get bothered by the cops. If you actually watch the traffic on an open port it's really quite interesting. I had a secure SSH host open to the internet and watched the traffic in real time as well as capturing the packets with Wireshark. It was really amazing to look into who was doing what and from where.
since it was intended for businesses, it probably is a high priority or something. a lot of businesses are probably still using windows 2k, but who knows.
It's possible to scan the entire public IPv4 address space in less than 15 minutes with modern tools like masscan, so there's definitely a lot of bots that are just scanning for open ports. There may also be old systems that are still infected with the worms, still spreading them all these years later.
What I dont understand is how did the exploit happen? I mean how did the "hacker" get the ip & port for the win 2000 machine? Do they just scan IP's? How does that work as everything is pretty much behind a NAT?
Yep, port scanning entire IP ranges. As far as I know this guy has the machine completely exposed, bypassing NAT and no firewall running. Also I think I remember him saying it's an Amazon AWS IP or something, a particularly spicy target IP range for anyone port scanning. That said it is still quite surprising that the worms (likely Sasser or Blaster) are still out there and still apparently infecting hosts given there has to be basically no new Windows 2000 hosts exposed to the internet.
@@BlueSheep777you act like he's misleading viewers. He repeatedly makes it very clear that he is exposing the system directly to the internet. And in his xp video he said it's to emulate how most users were hooked into the intent back in the day when security was significantly weaker.
@@BlueSheep777 did you... did you honestly think someone would make a video about Win2k security in 2024 for any reason other than idle entertainment? C'mon, now...
Windows 2000 is just too similar to XP RTM to assume anything other than almost immediately getting hacked. 2000 sp4 was released in 2003 meaning it will be vulnerable to anything fixed for xp after 2003. Anything fixed for XP means a public disclosure of what the vulnerability is, effectively zero daying Windows 2000 and is why you never use Windows after support ends it will have known unfixed public vulnerabilities.
No, it will not be vulnerable to anything fixed for XP after 2003. Mainstream support for 2000 ended on June 30, 2005, and extended support ended on July 13, 2010. Also, there were patches for 2000 published at least as late as 2015.
@@morsecypher Except in this video he is not using a version of Windows 2000 with all updates applied. As he is using sp4 anything fixed after that is a big problem
The chances that someone is still running 7 unmatched but deliberately running on the exposed internet is probably low, as those who are unaware about computer security are using home routers with built in protections
@justina1909 yeah, the average person needs to put in a considerable amount of effort and bypass a lot of intentional roadblocks to face the internet ass first and get the results seen in this video, which is a good thing. Run any competent modern firewall (built in to basically every router/switch/even service provider....) and you shouldn't be able to get the results seen in the video without going even more out of your way. It's very impressive how hardened computers are now.
Holy crap, sasser is *still* this fast? haha I remember this was about the time it took for any Win2k/XP machine to get hit by sasser back in the early 00's! You can halt the shutdown process after lsass.exe crashes if you really don't want it to reboot, the crash does indicate that it is being exploited though. I cannot quite remember what the payload/purpose of sasser was though. Windows 2000 had the event viewer didn't it? that would be where to look for more information on your bluescreen.
Old style malware was a lot more fun indeed. I remember getting myself infected when I was ~10yo (11 years ago) trying to activate windows 7 using shady links on Google. The malware that infected me did nothing but infect exes to make them say "File corrupted! This program has been manipulated and maybe it's infected by a Virus or cracked. This file won't work anymore." And over a day, every program said that. Didn't get any of my accounts stolen or anything, just made my system unusable in an amusing way haha
ah the times when people were in it for the love of being assholes, or industrial sabotage, or occasionally disrupting an entire country’s nuclear program
Ahh, Windows 2000. I have a real soft spot for Windows 2000--it was the OS of my very first computer. I was 5 years old, that thing was already yellowing with age and running with a CRT monitor, I kid you not. It was not connected to the internet, lol. My dad works in IT and always had loads of old computers and stuff around, and he gave it to us kids to let us play around and learn the basics of how computers worked without exposing us to the horrors of the worldwide web. I had loads of fun playing King's Quest and Charlie the Duck and screwing around in MS Paint. I really do think it was a great parenting decision on my parents' part, and I'm glad they did it. Small children do need to learn tech literacy in this day and age, but a 6-year-old absolutely should not be on TikTok or Instagram or whatever. It is more than possible, and in fact a very good idea, to let kids learn how to use computers and phones without rotting their brains on social media before they even know how to spell it.
I feel like this video is kind of false because I have been using Windows 2000 with Extended Kernel on my second machine connected to the internet, and nothing has happened.
This VM is connected directly with ports open, while yours is probably behind router. Thats like having your home front door open all the time. This is to show how weak the security is if exposed to a worst case scenario. Behind a router and functioning brain using old OS is mostly safe.
All these kinds of videos have been interesting to me, as long as I've believed that nothing could go wrong connecting an older version of Windows to the internet.
Attempted this myself. Kept it up for two hours. Nothing happened (other than a few attempts for port 21 and 80). Nothing hacked it. Gave up because I got bored, but I'm considering redoing it
New to your channel but I’ve enjoyed the windows to internet series. Can I make a request? :) Windows 7,8,10,11 Linux Mac All directly to the internet! I would genuinely love to know how safe newer consumer OS are.
Thing is I recently compiled an application and ran it on 2000, but I still haven't managed to get it running on ME (real hardware for both). Windows 2K needed a couple of XP only functions that are used by the modern Microsoft C runtimes. These were actually fairly trivial to implement as stubs if they're not implemented in kernel32 (runtime resolution), things like EncodePointer. But to target 9x is more complex, as you need Unicode support (there is a library for that), and substantially more functions. Plus you have to set the headers correctly, and I can't find any documentation about what 9x actually looks for here! If you don't actively target 9x your malware is unlikely to work on it these days. And who targets 9x!?
Interesting to see that old worms still plague the Internet, just waiting for an old OS to connect. Even if those worms aren't too dangerous if contained in a virtual machine, this confirms that it's better to keep a secure connection between the host and guest and browse the web with the host only.
When it comes to windows update. Microsoft stopped allowing OSes using SHA-1 hashing from updating. So patched windows 7 is the earliest OS that can use windows update. You can update 2000 with legacy update i think.
Parfom my ignorance. But what is the network config of the machine? Did you made it public to the Wan? Like, the web can basically initiate a "talk" to it? From my little knowledge, as long as a LAN network is safe - every computer in it is safe- connecting a fossil to it wouldnt be a problem.
I'm fairly certain you're referring to CIH as the "virus that destroyed motherboards", which was written to show just how ineffective AVs used to be. It unfortunately leaked out of the university that it was made as a project for and spread like a plague, spawning stuff such as Magistr, which was that but against people in legal professions, Kriz which changed the payload date from 4/16 (the author's birthday and infamously the date of the Chernobyl disaster) and was famously embedded into some screensavers for a Dreamcast game. The last notable one was Boomerang, which was just CIH across a network. Why he gave it such a destructive payload, maybe you are right in that he wanted some fun. But, that worm wasn't even intended to get out of the lab in the first place. Interesting to note that it would overwrite BIOSes with garbage data through an exploit, though. Made it worse when all the popular motherboards were using that exact vulnerable chipset, unless you were one of the rare few with that write protect jumper enabled.
I agree, win2000 startup really nostalgic and compared to XP (which Tbf is more nostalgic) win2k has some tinge of Internet but no mobile phone. Idk why but I think of the wtc, I guess pre-2001 vibes. You'd see movies and the airports were like bus terminals. I think 2000 was just nice in that it was still old enough to be the "good ol times" of developed world, but recent enough for most countries to be over with post-ww2 civil war / cold war tragedy
My favorite bug in Windows 95, 98, 2000 back in the day was the IP Fragment overlap bug. You could send a packet to a host with a specially crafted TCP ip packet with invalid ip fragments and when the kernel tried to reassemble the packets back together, kernel would blue screen. I used to run this code on a cron job and crash coworker machines, printers, and other stuff on the network.
In terms of stability, Windows 2000 Professional was a rock. XP came along making it more versatile. Therefore in terms of improvements on a previous product, Windows XP is king.
I'd love to see you do Windows 95. Yeah, if 98 is safe then 95 probably is too, but you never know. Also, 98 might have gotten some real nasties if you had given it enough time.
1:40 The CPUID instruction, when called to get the processor branding string will literally move an ASCII string literal into the registers EAX, EBX, EDX, and ECX.
From what I remember from 20+ years ago, playing around with Windows 2000 installs on my pc, at some point in time, the machine got infected like yours by simply pluging the ethernet cable. I remember that the service packs fixed it, back then. ca 2001-2002 :)
Win2K was also often nicknamed "Windows NT 5.0" and in some cases would show that when an asked to identify itself (in browsers and for web server statistics).
the system shutdown ui can be aborted with run -> shutdown -a, there are other syntax you can use other than -a for abort that generate it in different ways. It's how we used to make our friends fake viruses back in the day. It very much DOES shut down the PC. Whats likely happened here is that something wants to enable persistence and needs you to restart.
Back in the late 90s I was running NT4 without any sort of firewall on 56k and later cable, and never had any issues. The internet was such an innocent place when these OS were released, and for the time NT security was pretty good. A Linux or BSD system from the same time frame wouldn't last much longer. Solaris used to be the king of being owned out of the box, but I somehow doubt there are still Solaris malware crawling around the net now. If you want a laugh, when I first got cable (98-99?) I found that I could see all my neighbors on my local segment in "Network Neighborhood" - they didn't filter any NetBIOS or SMB traffic at the modem level at all on cable when it rolled out. You could browse shares and printers on their PCs if they had any - most had no idea. At this time almost nobody was using any sort of router or hardware firewall in a residential setting. I built a FreeBSD router out of an old 486 not long after.
i really dont understand how they do it so fast. Like you basically type in google, and youre hacked how do they know the ip range and stuff they should be looking for?
My question is do virtual machine software like virtual box or VMware allow open Internet connections that attack these older operating systems or is this something you'd have to manually configure to actually open yourself up to this because I like to fiddle with old operating systems and accessing the Internet on them.
In order to accomplish something like what was done in this video, you would need to manually hook one of your virtual machine host's network interfaces up to an internet connection with no network address translation or firewall in between the two. Then you would need to configure your virtual machine host to pass that physical interface through to your virtual machine, and then configure your virtual machine to either obtain a WAN IP address automatically from your internet service provider's DHCP server if they support that, or set the interface up with the static IP address that was assigned to you by your internet service provider when you initially signed up for their service. You can see him set this WAN IP address up manually on the virtual machine used in this video at 1:55. It is very unlikely that something like what happened in this video would happen to you while you are fiddling with a virtual machine running an old OS at your home. This is because your virtual machine is very likely sitting behind a router that is doing network address translation for all of the devices on your local area network and is also acting as a network firewall that is isolating all of the devices on your local area network from the internet at large. Your router's firewall will block the type of attacks that we saw compromise the system in this video automatically. You still should be very wary of browsing the internet using old, unsupported software though, as your router's network firewall likely will not be able to block all of the malicious scripts that can be embedded inside of websites or downloaded from the internet.
@@frequentfrenzied essentially as long as I leave settings as default my routers firewall should be able to prevent these attacks as if I were in my host machine? I know the basics of not to click the funny random link and download so I was just curious. Would hate to lose a nostalgic os to malware.
@@Chowder908 You should be safe behind your router's firewall. I'd stay off the internet which should be easy since you probably can't get a modern browser to run on the older Window OSs. Their old browsers can't display modern web sites.
@@frequentfrenziedIs there a photo or video explanation of how this is done? This sounds very complicated, so far I have never been attacked by a virus when I tried old systems in a VM. I want my virtual machine to be vulnerable to viruses, how can I ensure this?
@@capulcununteki The best approach is to use a real machine or a Linux system with VM since Linux has a good software firewall build-in. You need to configure your modem/router to set the IP-address of your PC to a DMZ-host, but warning, the maker of this video is wrong and ALL Windows systems are extremely vulnerable if you set them as a DMZ-host, so DO NOT do this if you are running a Windows host system otherwise you WILL get hacked, in Linux this is pretty safe unless you mess with the root and firewall settings.
I don't understand how random file can just suddenly appear like this and be executed. when you popped over to Virustotal and a lot of the malware was listed as a trojan but isn't a trojan something you have to download (pretending to be something else) and execute yourself?
that just shows you how vulnerable this old OS is, nowdays isnt that easy the thing is if you have a bug that allows you to execute code, you can allocate code to download and execute that dont need the user to do anything
I remember back in 2003 I had a 800mhz Pentium running Windows 2000 Professional. I connected my computer directly to my ADSL modem. The blaster worm was extremely annoying. I didnt know the tricks to stop the computer from shutting down. I cant remember exactly how long it would take to reinstall windows, but it took a long time. So you can imagine how aggravating it was to once again see the system shutdown because of a failed RPC Remote Procedure Call as soon as I connected my computer to the internet.
@@EricParker But what kind of internet connection do you have because I cannot even remember the last time I had a service provider that allowed inbound connections? It must have been at least 15 years ago.
Windows XP on my university campus would be hacked in 10 seconds if left on the bare network. It was impossible to install XP unless you had at least a home router with NAT to create a private network. I’m surprised you got as far as you did with Win2k post-install.
I had nightmares thinking about WIndows XP getting exposed by hackers in a minute or so, but this happens when you use Windows 2000 and the BSOD shows up on crash while hackers try to catch you with malware or any other kinds of viruses that you don't expect to come. Same thing goes when you use use Windows NT 4.0. It is a nightmare to have such old Windows OS in 2024. I wish I didn't believe it.
How is it possible to get a virus by just connecting to the internet? I thought you have to enter to some web page and accept adds or install something
The BSOD's could be an exploit failing, but it could also be someone trying to protect/alert these ancient systems? no? Something similar happened with some IOT device exploits where someone, instead of abusing it for monetary gain, bricked the devices so they wouldn't be made a part of some botnet (which i guess is real "cause damage but greater good" kinda thing) feel free to look this up. there was also this "A mysterious grey-hat is patching people's outdated MikroTik routers "
This reminds me of Novell Netware 4, which was shipped with malware pre-installed. Caused a few problems, the least of which was the demise of Netware. They tried to recover,but Windows NT and Windows 2000 closed that door.
It would be interesting to see if windows 2000 gets hacked when it has a firewall installed. Like Zone Alarm or Tiny personal firewall. My dad had a windows 2000 computer around 2004-2005 and it was full of malware. If the ADSL modem was connected to the computer it started on the night by itself. And around 2010 i tried to use the computer when i was 13. Around 2006 it was put out of use. If i typed anything that had to do with antivirus in google, then the browser closed every time. Then i installed an old f-secure antivirus 5.40 from CD. It was hard to install because the viruses pushed cancel all the time but they didn't know to push yes after that :D. After i got it installed it started to show several infected files but the program was very unusable with all the malware. And the funniest thing was that one day there was a little window that said: F-secure antivirus has caused much harm to the computer and has to be closed.
I use mine with Tiny Personal Firewall as ZoneAlarm made a few bluescreens when using it with VPN. While most of the time it's behind a NAT, sometimes it gets internet directly. So far I haven't seen anything, especially that bad... but after this video I'll have a closer look. And your story is pretty interesting, haha~ Viruses were pretty crazy.
I doubt someone is actively trying to infect these OSs so that means there are Win2k or similar era machines out there on the internet spreading this around. That is mind blowing.
> connects to the internet
> immediately gets infected by a 20 year old worm
Where does the 20 yr old Worm lives? Is it cloud Based?
@@therealfoxprobably his IP is public or he is on public wifi example one dusty winxp computer infected with sasser scans wifi and finds this pc.
@@Mihot7 so probably its xp cloud from the past.
i connected it and nothing happened at all
@@NotThatEpic7492 turn your firewall and any network protection off and watch the sparks begin
Damn, Sasser is still active on the internet?
That's crazy.
Your Win2k was infected from the get go.... man that brings me back. I can't believe that the Sasser is still active after over 20 years... this was also my first contact with Computer Security ^^ A freshly bought brand new computer from the local store, and as soon as the 56k modem finished, 20 seconds later I got the "System is shutting down" message. it is crazy how vulnerable Windows was (and partly still is)
Yep, got blasted.
most commonly used OS in the world, actually not that crazy to constantly have found vulnerabilities in it.
Sasser was prolly the first time my PC got infected by something from the Net. It was also one of my early years of using the Net. Ig that's one way of learning the Net isn't safe.
@@Jesus.Christ106 hmm... not so sure about that. Supercomputers, servers, embedded/IOT devices, most smartphones, routers modern switches, some gaming consoles, microcontrollers all run on unixoid systems. Only the PC Desktop is dominated by Windows.
Lol not if you use a good firewall, if you use Windows on the public internet with only the Windows firewall without a hardware firewall such as a good modem or router or with wrong settings such as DMZ you WILL get hacked...
Wow. You get hacked and infected with the Sasser worm literally within two minutes even with SP4. I'm not sure what i expected.
More likely Blaster, due to all the crashes and only one lsass termination.
@@nullkid10also possible, but blaster gives a registry entry OP can check (if the VM isn't completely bricked)
this is the same dude who farmed 320k views with the fake XP video before, putting it on the internet with NO firewall (which is not how the vast majority of people are connected to the internet) and because that STILL didn't work he googled for malware to infect the system with and accidentally left the browser window of him searching for it in the video
@@Knaeckebrotsaege Got a timestamp?
EDIT: Nevermind, 2:50 on that video, oof.
Most interesting is how it got hacked - anyone could suggest a path of infection ?
Back in the day I recall servers got infected from one each other - so having pool of Win2k and one got infrected you had to deal with each separaterly before you got them back online.
Its 2024 and I cant imagine anyone still having Win2k online that is infected and just waits for another Win2k to go online. Second thing which is bothering me is how does one get infected behind NAT at this point.
Any comments welcome
4:30 Actually this happens when an attack fails. There is a similar video of exposing a real machine running Windows 2000, it kept rebooting and blue screening
Might be the WannaCry virus that went around back in 2017. If I remember correctly, if it tried to infect a Windows 2000 machine, it wouldn't be able to do anything else to it but crash it
@@RandomGuy37 Yeah, those things are bots
my guess is it wasMS17-010, aka the infamous EternalBlue vulnerability in SMB
He literally just connected to microsoft and google.
Not even a sketchy website, that says a lot.
@@JackSeries44 indeed. win2000 with default configuration is basically a glowing target
Next up: What happens if you expose Red Star OS to the internet
A pizza delivery van will be parked outside of your house for a couple months
I like where this is going, although it'd probably be more focused on trying to browse the internet than malware.
@@ozzie_goat Flowers by Irene*
@@Sectonidse Solid reference
You cant. They specifically made it so that if you connect it to the internet it will brick itself.
7:22 If you wanted to revive Windows Update in earnest, you could install Legacy Update which redirects it to a community-hosted reverse-engineered server.
Virus mentioned around 5:15 which destroyed motherboards was called CIH or more commonly "Chernobyl" it did override bios memory corrupting it.
4:00 sasser joined the game
Edit: wow I never got that many likes tysm!
This is such a good series
I agree
if you like people faking their way to clicks and views then sure lol. this is the same dude who farmed 320k views with the fake XP video before, putting it on the internet with NO firewall (which is not how the vast majority of people are connected to the internet) and because that STILL didn't work he googled for malware to infect the system with and accidentally left the browser window of him searching for it in the video lmao
super cozy nostalgia trip of giving all my early OS's literal aids when I was a child....but now its like we have a security wizard here to show and explain to us all about the aids we were giving our pc's back in the day :3
@@Shredddddy If only any of this were actually real. Good thing tech illiterate like you keep budget youtubers in business.
Bro got infected with blaster/sasser in under a minute 💀
This series is really fun, I don’t know how much more content you can make with it because there aren’t many more versions of Windows but great work!
Neat to see. Everyone always talks about XP but Win2K was my daily driver untill xp sp2 was released. Win2k was always one of my favorite versions of windows.
windows 2000 is pre windows xp not 98 or 95🤣🤣
Never switched to XP, never had a reason. Win2k could do anything XP could do, while not looking like a Kids toy.
Kept Win2k until Win7 came out.
Of course i was missing out on a additional taskbar icon, who's only purpose was to tell me whenever my antivirus was running or not, what a loss. :-D
@@timhartherz5652 I don't recall why I switched to XP. I did use to turn off the visual styling so it looked like W2K though, also used less resources.
Hacked% Speedrun world record
I just found your channel because of a german article on a website. It's really interesting to see how the old systems "perform" in 2024. :) please go on with the series!
I saw somebody write an article about you showing what happens if you connect Windows XP to the internet, it bought me to your channel to see more interesting videos :)
do you have a link to it?
@@yeahhhhhhhhhhhhhhhhhhhhhhhhhh Can't post links in YT comments, PCGamer have an article that specifically talks about Eric's video though, popped up on my phone's news feed last night so might be that one, but it's literally just a written summary of his video, they didn't add anything particularly interesting themselves, just reporting on the facts I guess
Yes and it's a total crock. These videos are pure trash, crazy how uninformed people are.
I've seen the same article!! I like that person wrote about Parker so now I can watch his videos
@@Sophix_37 well your both very dumb. the misinformation in this video and the extreme deception of that crap article is beyond anything with a brain.
Back in 2015 Microsoft released an emergency update going as far back as windows 2000 bc 2000, XP, vista, etc had this exploit. It was released after wanna cry was spawned and had to do with the rdp of I remeber correctly.
Anyways all I can say is to install that update and then trying this again.
I was amazed that Ms not only quickly released that update but for Windows XP and especially 2000...
Wannacry was an SMB v1 exploit if I remember correctly. We were in the midst of a full scale company wide disaster recovery test when I was given the green light to disable SMB v1 across the board. Rolling out GPO’s at that scale are always fun. We had some heart sore Linux admins the next morning who couldn’t connect to shares anymore with their outdated Red Hat distros 😂.
EternalBlue (SMBv1 exploit) appeared in 2017, BlueKeep (RDP exploit) in 2019, for both beginning from WinXP patches has been issued.
Never heard about any patches for 2000, guess its market share was extremely tiny to bother with even back then.
@@xTh1eFx yea they even issued the patch for 2000 too
If I were to guess it's probably because WinXP and older are still in very regular use within industrial fields among other arguably more important ones, like nuclear facilities and Microsoft probably know how dumb people can be, after all this video is proof that all it would take is someone to connect it to the network with internet access for a couple of minutes lol
Edit: Then again saying that, you'd hope if someone were stupid enough to connect it to the network that things like NAT or a firewall would save it, but I ain't gonna build a 2000 box to test that theory lmao
@@PhantomWorksStudios hm, I failed to locate that one, only some unofficial patch from MSFN forums based on backported library from XP...
boy I miss that old school right click menu animation at 5:28. They don't do that anymore.
there is a command for registry to get it back for newer version of windows ...
@3:40 i remember seeing that live back in the day via the Blaster worm, basically if you had your windows 2k system directly on the internet with no firewall, there was a good chance that the worm would eventually hit your IP causing this shutdown popup, and then it would start DDoSing windows update.
Man viruses back in the day always were memorable, Nimda, Code Red, Blaster, ILOVEYOU, Melissa. Now days its all just generic trojans and cryptolockers
suggestion: what happens if you connect windows vista to the internet in 2024
No one knows, because even people who would run ME for 'fun' would turn their nose up at running the Vista binfire 😬😆🤣
Chaos😂
I tried it using Supermium and it runs well
@@mor4y i like vista, take that
You wouldn't know if it was Vista that crashed or because of a hacker attack. Same same.
i hooked up a windows 2000 server machine direct to the internet back in 2003. it was just for a few minutes to download drivers before i moved it to an air gap net. I went to lunch. when i got back it was already fubar'd
It'd be interesting to see older versions of NT, like 4 or even 3.x, and whether they're still actively targeted (or vulnerable to the same exploits that target 2k and XP).
Hi Eric!
a) the Win2k startup sound is absolutely the best one!
b) the fact you keep closing the Tip of the Day window every time and not unclick the tickbox at the bottom of it is so funny :D
Thanks for the vid.
7:18 Updates can be downloaded with Legacy Update
That's exactly what i did on my Windows XP Professional guest VM in VMware Workstation Pro, which is now free for personal use.
So ... completely exposed host?
All ports from router directly forwared to the VM?
I´ve been using Retro systems online for years now.
Behind NAT they don´t get hacked....
Correct
The video title describes exactly what has been done here. This is just how you connect a host to the internet. LAN is a different story and it requires a gateway to forward traffic to remote hosts. There are different applications involved, if you access the internet from inside a LAN. Its never been a good idea to connect Windows directly to the internet, lookup how old Norton Internet Security (just naming this popular example) is and you'll see...
@@Knaeckebrotsaege well, if he didn't do that, it's unlikely something interesting would happen unless he went to look for malware manually.
Oh wait, he did that in the WinXP video.
@@Knaeckebrotsaege Why does this upset you exactly? He's not hiding this, it's made pretty obvious that you have to go out of your way to expose yourself this much. It's just a fun demonstration of what happens if you do
@@Knaeckebrotsaege He explicitly explained this fact in an earlier video in the series.
So is the sasser worm just still running somewhere in the wild looking for machines to infect? Or is somebody hosting it and doing it that way
some script kiddies probably hosting it somewhere
If not script kiddies, there's plenty of internet connected appliances out there running 2k/XP; ePOS machines, ATMs...
Their chances of infection should have been reasonably low, but given they've been running for decades at this point, that's a lot of chances to roll those dice.
@@rossstewart9475but surely they would be suffering the symptoms of it?
@@papajohnscookie Surely, but only the LSASS issue is critical to the continued functioning of an infected machine, and it's quite possible to have a particular configuration of updates that eliminates this issue, whilst not resolving the infection itself and therefore allowing continued propogation.
Consider this: If Sasser shut down every machine it infected, why then was it able to spread so virulently in the first place?
@@rossstewart9475 That's a fair point, my personal anecdotal experience was that Blaster would just constantly cause the lsass process to crash and shut the machine down. I do love the idea of a number of legacy systems being infected with a worm that is 20 odd years old and want it to be true! I intend to set up the same sort of lab environment that was in this video. I'll let you know the results.
This stuff is so interesting, it's amazing how fast you're pwned. Are there bots just nmapping the entire v4 address space 24/7 or something? Who's doing this for 20 year old OSes? Any chance you can get a packet capture for one of these experiments?
There literally are systems scanning the whole IP space; legitimate ones like Shodan for analytical and security purposes, botnets searching for new infection prospects, nation state actors looking for footholds and kids at colleges or universities learning about computer security who will probe you from their campus IP in another country so they don't get bothered by the cops. If you actually watch the traffic on an open port it's really quite interesting. I had a secure SSH host open to the internet and watched the traffic in real time as well as capturing the packets with Wireshark. It was really amazing to look into who was doing what and from where.
since it was intended for businesses, it probably is a high priority or something. a lot of businesses are probably still using windows 2k, but who knows.
@@egg_addictI know there's a Windows NT4 PC hanging around the HVAC lab at my college for sure, but I doubt it's networked
@bouncypear_net it's crazy to think you're one ethernet cable away from malware city
It's possible to scan the entire public IPv4 address space in less than 15 minutes with modern tools like masscan, so there's definitely a lot of bots that are just scanning for open ports.
There may also be old systems that are still infected with the worms, still spreading them all these years later.
What I dont understand is how did the exploit happen? I mean how did the "hacker" get the ip & port for the win 2000 machine? Do they just scan IP's? How does that work as everything is pretty much behind a NAT?
Yep, port scanning entire IP ranges.
As far as I know this guy has the machine completely exposed, bypassing NAT and no firewall running. Also I think I remember him saying it's an Amazon AWS IP or something, a particularly spicy target IP range for anyone port scanning.
That said it is still quite surprising that the worms (likely Sasser or Blaster) are still out there and still apparently infecting hosts given there has to be basically no new Windows 2000 hosts exposed to the internet.
except this isn't behind a NAT, it's a view farm.
@@BlueSheep777you act like he's misleading viewers. He repeatedly makes it very clear that he is exposing the system directly to the internet. And in his xp video he said it's to emulate how most users were hooked into the intent back in the day when security was significantly weaker.
@@BlueSheep777 did you... did you honestly think someone would make a video about Win2k security in 2024 for any reason other than idle entertainment?
C'mon, now...
@@rossstewart9475 to check if servers running on that version of Windows aren't safe anymore
Windows 2000 is just too similar to XP RTM to assume anything other than almost immediately getting hacked. 2000 sp4 was released in 2003 meaning it will be vulnerable to anything fixed for xp after 2003. Anything fixed for XP means a public disclosure of what the vulnerability is, effectively zero daying Windows 2000 and is why you never use Windows after support ends it will have known unfixed public vulnerabilities.
No, it will not be vulnerable to anything fixed for XP after 2003. Mainstream support for 2000 ended on June 30, 2005, and extended support ended on July 13, 2010. Also, there were patches for 2000 published at least as late as 2015.
@@morsecypher Except in this video he is not using a version of Windows 2000 with all updates applied. As he is using sp4 anything fixed after that is a big problem
Do Windows 7 RTM. I wonder how vulnerable is it in 2024 since some pc's probably still run a retail unpatched windows 7.
The chances that someone is still running 7 unmatched but deliberately running on the exposed internet is probably low, as those who are unaware about computer security are using home routers with built in protections
I done this and it worked fine I guess but outdated :(
@justina1909 yeah, the average person needs to put in a considerable amount of effort and bypass a lot of intentional roadblocks to face the internet ass first and get the results seen in this video, which is a good thing. Run any competent modern firewall (built in to basically every router/switch/even service provider....) and you shouldn't be able to get the results seen in the video without going even more out of your way. It's very impressive how hardened computers are now.
I'm still on win7. Works perfectly fine. I even play brand new steam games on it. The system requirements appear to be a suggestion lmao.
@@GabrielFurryPhone you didn't pass through the ports to net
Holy crap, sasser is *still* this fast? haha
I remember this was about the time it took for any Win2k/XP machine to get hit by sasser back in the early 00's! You can halt the shutdown process after lsass.exe crashes if you really don't want it to reboot, the crash does indicate that it is being exploited though. I cannot quite remember what the payload/purpose of sasser was though.
Windows 2000 had the event viewer didn't it? that would be where to look for more information on your bluescreen.
Id like to see some older/unsecure linux distros & malware/viruses that can effect linux servers
Finally an Eric Parker video that I can watch on a mobile device without squinting.
Old style malware was a lot more fun indeed. I remember getting myself infected when I was ~10yo (11 years ago) trying to activate windows 7 using shady links on Google.
The malware that infected me did nothing but infect exes to make them say "File corrupted! This program has been manipulated and maybe it's infected by a Virus or cracked. This file won't work anymore." And over a day, every program said that. Didn't get any of my accounts stolen or anything, just made my system unusable in an amusing way haha
ah the times when people were in it for the love of being assholes, or industrial sabotage, or occasionally disrupting an entire country’s nuclear program
i dont know what i expected but it was not getting infected with sasser literally 30 seconds after connecting to the internet
Eric Parker on a generational run rn, been here since a couple hundred subs keep it up man
Windows 2000 has an Active Desktop! I miss that. It disappeared too early.
this is the type of channel where it answers questions before we ask them and then it makes you feel smarter after the video ends
Who tf builds random virus bots for specifically Windows 2000 machines connected to the open internet?
Microsoft did
Man, this is awesome content. Saw your "What happens if you connect Windows XP to the Internet In 2024." Intriguing!
Perhaps you might wanna use Legacy Update, newer replacement for the good ol Windows Updates. Then patch the system to it's latest.
Ahh, Windows 2000. I have a real soft spot for Windows 2000--it was the OS of my very first computer. I was 5 years old, that thing was already yellowing with age and running with a CRT monitor, I kid you not. It was not connected to the internet, lol. My dad works in IT and always had loads of old computers and stuff around, and he gave it to us kids to let us play around and learn the basics of how computers worked without exposing us to the horrors of the worldwide web. I had loads of fun playing King's Quest and Charlie the Duck and screwing around in MS Paint. I really do think it was a great parenting decision on my parents' part, and I'm glad they did it. Small children do need to learn tech literacy in this day and age, but a 6-year-old absolutely should not be on TikTok or Instagram or whatever. It is more than possible, and in fact a very good idea, to let kids learn how to use computers and phones without rotting their brains on social media before they even know how to spell it.
you made my day with this video! the trivia was a nice touch
I feel like this video is kind of false because I have been using Windows 2000 with Extended Kernel on my second machine connected to the internet, and nothing has happened.
This VM is connected directly with ports open, while yours is probably behind router. Thats like having your home front door open all the time. This is to show how weak the security is if exposed to a worst case scenario. Behind a router and functioning brain using old OS is mostly safe.
Same here
All these kinds of videos have been interesting to me, as long as I've believed that nothing could go wrong connecting an older version of Windows to the internet.
Attempted this myself. Kept it up for two hours. Nothing happened (other than a few attempts for port 21 and 80). Nothing hacked it.
Gave up because I got bored, but I'm considering redoing it
New to your channel but I’ve enjoyed the windows to internet series. Can I make a request? :)
Windows 7,8,10,11
Linux
Mac
All directly to the internet! I would genuinely love to know how safe newer consumer OS are.
You were at like 5k subs just a week ago, loveee your content man!
NAT behind routers stopped this. since people do not use dail up connections and instead have broadband routers this stopped
3:05 This smile was personal 😅
You CAN connect Win 2000, 98, 95 to the internet...but you have to be careful WHERE you surf, or you'll get some fun.
Thing is I recently compiled an application and ran it on 2000, but I still haven't managed to get it running on ME (real hardware for both).
Windows 2K needed a couple of XP only functions that are used by the modern Microsoft C runtimes. These were actually fairly trivial to implement as stubs if they're not implemented in kernel32 (runtime resolution), things like EncodePointer.
But to target 9x is more complex, as you need Unicode support (there is a library for that), and substantially more functions. Plus you have to set the headers correctly, and I can't find any documentation about what 9x actually looks for here!
If you don't actively target 9x your malware is unlikely to work on it these days. And who targets 9x!?
No. They exposed all ports to the nat so they got hacked fast
i just discovered your channel, its great, keep it up!
6:07 that's system properties, because it says rundll target is sysdm.cpl, which if you put into a run dialog, opens system properties
It’s so funny that worms are still circulating from decades ago
I just dont understand how. Who found you that fast and how did they see you? Just by simply going to Google?
Interesting to see that old worms still plague the Internet, just waiting for an old OS to connect.
Even if those worms aren't too dangerous if contained in a virtual machine, this confirms that it's better to keep a secure connection between the host and guest and browse the web with the host only.
Sasser still lives, probably due to some kids running it to this very day, there's no other reason why it would be still running :p
i mean, maybe those kids are like dannoct, but instead of just seeing what it does, they want it to still live
When it comes to windows update. Microsoft stopped allowing OSes using SHA-1 hashing from updating. So patched windows 7 is the earliest OS that can use windows update. You can update 2000 with legacy update i think.
Windows ME living up to expectations and crashing whenever anyone wants to run some software on it... even the hackers.
Parfom my ignorance. But what is the network config of the machine? Did you made it public to the Wan? Like, the web can basically initiate a "talk" to it? From my little knowledge, as long as a LAN network is safe - every computer in it is safe- connecting a fossil to it wouldnt be a problem.
he's directly connecting it to the internet, no router, no NAT, no firewall, his ip is his computer, not the router just routing ports
I'm fairly certain you're referring to CIH as the "virus that destroyed motherboards", which was written to show just how ineffective AVs used to be. It unfortunately leaked out of the university that it was made as a project for and spread like a plague, spawning stuff such as Magistr, which was that but against people in legal professions, Kriz which changed the payload date from 4/16 (the author's birthday and infamously the date of the Chernobyl disaster) and was famously embedded into some screensavers for a Dreamcast game. The last notable one was Boomerang, which was just CIH across a network.
Why he gave it such a destructive payload, maybe you are right in that he wanted some fun. But, that worm wasn't even intended to get out of the lab in the first place. Interesting to note that it would overwrite BIOSes with garbage data through an exploit, though. Made it worse when all the popular motherboards were using that exact vulnerable chipset, unless you were one of the rare few with that write protect jumper enabled.
bro you literally turned off all the protections
I agree, win2000 startup really nostalgic and compared to XP (which Tbf is more nostalgic) win2k has some tinge of Internet but no mobile phone.
Idk why but I think of the wtc, I guess pre-2001 vibes. You'd see movies and the airports were like bus terminals.
I think 2000 was just nice in that it was still old enough to be the "good ol times" of developed world, but recent enough for most countries to be over with post-ww2 civil war / cold war tragedy
My favorite bug in Windows 95, 98, 2000 back in the day was the IP Fragment overlap bug. You could send a packet to a host with a specially crafted TCP ip packet with invalid ip fragments and when the kernel tried to reassemble the packets back together, kernel would blue screen. I used to run this code on a cron job and crash coworker machines, printers, and other stuff on the network.
found your channel, and immediately subscribed after seeing what your content is like
In terms of stability, Windows 2000 Professional was a rock. XP came along making it more versatile. Therefore in terms of improvements on a previous product, Windows XP is king.
You were just featured on some ordinary gamers channel, came racing back to check your sub count to see if it’s risen and it has quite a bit
nowadays virus : It's all about money.
20 years old virus: It's about sending a message.
I'd love to see you do Windows 95. Yeah, if 98 is safe then 95 probably is too, but you never know. Also, 98 might have gotten some real nasties if you had given it enough time.
1:40 The CPUID instruction, when called to get the processor branding string will literally move an ASCII string literal into the registers EAX, EBX, EDX, and ECX.
From what I remember from 20+ years ago, playing around with Windows 2000 installs on my pc, at some point in time, the machine got infected like yours by simply pluging the ethernet cable. I remember that the service packs fixed it, back then. ca 2001-2002 :)
Win2K was also often nicknamed "Windows NT 5.0" and in some cases would show that when an asked to identify itself (in browsers and for web server statistics).
I don’t get these videos. Who’s looking for and attacking your open ports? Am I missing something?
bots scanning the entire IPv4 address space 24/7, mostly from Russia and China.
the system shutdown ui can be aborted with run -> shutdown -a, there are other syntax you can use other than -a for abort that generate it in different ways. It's how we used to make our friends fake viruses back in the day. It very much DOES shut down the PC. Whats likely happened here is that something wants to enable persistence and needs you to restart.
Sasser and Blaster both cause the computer to shutdown like that. The machine was infected by one of those immediately.
I tried with windows 98, and NO mainstream browser would install. The default made a total mess of websites
Back in the late 90s I was running NT4 without any sort of firewall on 56k and later cable, and never had any issues. The internet was such an innocent place when these OS were released, and for the time NT security was pretty good.
A Linux or BSD system from the same time frame wouldn't last much longer. Solaris used to be the king of being owned out of the box, but I somehow doubt there are still Solaris malware crawling around the net now.
If you want a laugh, when I first got cable (98-99?) I found that I could see all my neighbors on my local segment in "Network Neighborhood" - they didn't filter any NetBIOS or SMB traffic at the modem level at all on cable when it rolled out. You could browse shares and printers on their PCs if they had any - most had no idea. At this time almost nobody was using any sort of router or hardware firewall in a residential setting. I built a FreeBSD router out of an old 486 not long after.
i really dont understand how they do it so fast. Like you basically type in google, and youre hacked how do they know the ip range and stuff they should be looking for?
mass nmaps
Well, that was quite fast! :D
Thanks for the video!
My question is do virtual machine software like virtual box or VMware allow open Internet connections that attack these older operating systems or is this something you'd have to manually configure to actually open yourself up to this because I like to fiddle with old operating systems and accessing the Internet on them.
In order to accomplish something like what was done in this video, you would need to manually hook one of your virtual machine host's network interfaces up to an internet connection with no network address translation or firewall in between the two. Then you would need to configure your virtual machine host to pass that physical interface through to your virtual machine, and then configure your virtual machine to either obtain a WAN IP address automatically from your internet service provider's DHCP server if they support that, or set the interface up with the static IP address that was assigned to you by your internet service provider when you initially signed up for their service. You can see him set this WAN IP address up manually on the virtual machine used in this video at 1:55. It is very unlikely that something like what happened in this video would happen to you while you are fiddling with a virtual machine running an old OS at your home. This is because your virtual machine is very likely sitting behind a router that is doing network address translation for all of the devices on your local area network and is also acting as a network firewall that is isolating all of the devices on your local area network from the internet at large. Your router's firewall will block the type of attacks that we saw compromise the system in this video automatically. You still should be very wary of browsing the internet using old, unsupported software though, as your router's network firewall likely will not be able to block all of the malicious scripts that can be embedded inside of websites or downloaded from the internet.
@@frequentfrenzied essentially as long as I leave settings as default my routers firewall should be able to prevent these attacks as if I were in my host machine? I know the basics of not to click the funny random link and download so I was just curious. Would hate to lose a nostalgic os to malware.
@@Chowder908 You should be safe behind your router's firewall. I'd stay off the internet which should be easy since you probably can't get a modern browser to run on the older Window OSs. Their old browsers can't display modern web sites.
@@frequentfrenziedIs there a photo or video explanation of how this is done? This sounds very complicated, so far I have never been attacked by a virus when I tried old systems in a VM. I want my virtual machine to be vulnerable to viruses, how can I ensure this?
@@capulcununteki The best approach is to use a real machine or a Linux system with VM since Linux has a good software firewall build-in. You need to configure your modem/router to set the IP-address of your PC to a DMZ-host, but warning, the maker of this video is wrong and ALL Windows systems are extremely vulnerable if you set them as a DMZ-host, so DO NOT do this if you are running a Windows host system otherwise you WILL get hacked, in Linux this is pretty safe unless you mess with the root and firewall settings.
So the 2000 internet and 2007 internet is different from each other
I don't understand how random file can just suddenly appear like this and be executed. when you popped over to Virustotal and a lot of the malware was listed as a trojan but isn't a trojan something you have to download (pretending to be something else) and execute yourself?
that just shows you how vulnerable this old OS is, nowdays isnt that easy
the thing is if you have a bug that allows you to execute code, you can allocate code to download and execute that dont need the user to do anything
@@lPlanetarizadothis wasn't even behind a NAT...
thats true....but even then you could get hacked, just not this quickly
you are correct!!
I remember back in 2003 I had a 800mhz Pentium running Windows 2000 Professional. I connected my computer directly to my ADSL modem. The blaster worm was extremely annoying. I didnt know the tricks to stop the computer from shutting down. I cant remember exactly how long it would take to reinstall windows, but it took a long time. So you can imagine how aggravating it was to once again see the system shutdown because of a failed RPC Remote Procedure Call as soon as I connected my computer to the internet.
And with a firewall like zone ⏰ alarm????
The introduction of the video reminded me Windows XP. Ah, I missed that legend too much.
Would be interesting to see how older versions of MacOS hold up vs windows versions of the same era
no harm - older macos'es hold 1 percent market share - so no profit developing malware
Wait so you can get a malware just by connecting to the Internet? but how, like you aren't downloading or visiting malicious websites.
Because if it's exposed to the internet you can just scan for vulnerable ports.
@@EricParker But what kind of internet connection do you have because I cannot even remember the last time I had a service provider that allowed inbound connections? It must have been at least 15 years ago.
@@satunnainenkatselija4478 Set your modem to bridge mode and connect a PC with an old OS to it and maybe you can have fun, too.
Should i be worried about getting infected even though my Windows 2000 machine is connected through a firewall?
No
Windows XP on my university campus would be hacked in 10 seconds if left on the bare network. It was impossible to install XP unless you had at least a home router with NAT to create a private network. I’m surprised you got as far as you did with Win2k post-install.
I had nightmares thinking about WIndows XP getting exposed by hackers in a minute or so, but this happens when you use Windows 2000 and the BSOD shows up on crash while hackers try to catch you with malware or any other kinds of viruses that you don't expect to come. Same thing goes when you use use Windows NT 4.0. It is a nightmare to have such old Windows OS in 2024. I wish I didn't believe it.
Lsass crashing and causing a restart dialog is very common as it was well known to be very vulnerable
I like how they still attempt to sent the 20 years old worm that only works on the ancient windows
windows 2000... the start of the home and pro era
It also can be Microsoft's own doing to eliminate the usage of older Windows Os.
How is it possible to get a virus by just connecting to the internet? I thought you have to enter to some web page and accept adds or install something
The BSOD's could be an exploit failing, but it could also be someone trying to protect/alert these ancient systems? no?
Something similar happened with some IOT device exploits where someone, instead of abusing it for monetary gain, bricked the devices so they wouldn't be made a part of some botnet (which i guess is real "cause damage but greater good" kinda thing) feel free to look this up.
there was also this "A mysterious grey-hat is patching people's outdated MikroTik routers "
The moment I seen that shutdown prompt and the name Sass I just knew it was done for immediately
This reminds me of Novell Netware 4, which was shipped with malware pre-installed.
Caused a few problems, the least of which was the demise of Netware.
They tried to recover,but Windows NT and Windows 2000 closed that door.
It would be interesting to see if windows 2000 gets hacked when it has a firewall installed. Like Zone Alarm or Tiny personal firewall. My dad had a windows 2000 computer around 2004-2005 and it was full of malware. If the ADSL modem was connected to the computer it started on the night by itself. And around 2010 i tried to use the computer when i was 13. Around 2006 it was put out of use. If i typed anything that had to do with antivirus in google, then the browser closed every time. Then i installed an old f-secure antivirus 5.40 from CD. It was hard to install because the viruses pushed cancel all the time but they didn't know to push yes after that :D. After i got it installed it started to show several infected files but the program was very unusable with all the malware. And the funniest thing was that one day there was a little window that said: F-secure antivirus has caused much harm to the computer and has to be closed.
I use mine with Tiny Personal Firewall as ZoneAlarm made a few bluescreens when using it with VPN. While most of the time it's behind a NAT, sometimes it gets internet directly. So far I haven't seen anything, especially that bad... but after this video I'll have a closer look.
And your story is pretty interesting, haha~ Viruses were pretty crazy.
I doubt someone is actively trying to infect these OSs so that means there are Win2k or similar era machines out there on the internet spreading this around. That is mind blowing.
If Windows Vista’s internet side effects would be less affective than XP’s, I would be impressed.
Love your vids man keep it up and you'll get big one day 👍