Bypassing SmartScreen on Web Browsers

แชร์
ฝัง
  • เผยแพร่เมื่อ 28 ก.ย. 2024
  • jh.live/keeper || Keeper Security offers a privileged access management solution to deliver enterprise grade protection all in one unified platform -- keep your users, your data, and your environment secure with Keeper! jh.live/keeper
    Learn Cybersecurity - Name Your Price Training with John Hammond: nameyourpricet...
    📧JOIN MY NEWSLETTER ➡ jh.live/email
    🙏SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware
    🔥TH-cam ALGORITHM ➡ Like, Comment, & Subscribe!

ความคิดเห็น • 126

  • @b3twiise853
    @b3twiise853 5 หลายเดือนก่อน +44

    “He was messing around with his piehole “ ohh joel tsk tsk tsk 😂😂😂

    • @5iddd
      @5iddd 5 หลายเดือนก่อน +1

      Thats crazy

    • @GustavoPinho89
      @GustavoPinho89 5 หลายเดือนก่อน +4

      Security researchers always be testing stuff with their pieholes.....

    • @vuufke4327
      @vuufke4327 5 หลายเดือนก่อน

      hope he wasn't doing it on company time

  • @mclarenf1gtr99
    @mclarenf1gtr99 5 หลายเดือนก่อน +29

    I don't mind having them put warnings when I try access a supposed "dangerous" link, but now they don't even present the option to advance anyway. This makes me worry about the future where you can't access something because someone of a higher power said No, not because it is dangerous, but because they don't want people to access.

    • @L2002
      @L2002 5 หลายเดือนก่อน +7

      you can literally just use any other browser that doesn't have safe browsing, nothing to worry.

    • @angeleeh
      @angeleeh 5 หลายเดือนก่อน

      on chrome, just type 'thisisunsafe' and will let you through

  • @RodrigoPhysicist
    @RodrigoPhysicist 5 หลายเดือนก่อน +92

    you could also set up a small tcp server that always returns true and add it on the hosts of your co-worker... now he's gonna have the red screen for every site he browses 😂

    • @CZghost
      @CZghost 5 หลายเดือนก่อน +6

      That's just evil, man! :D

    • @Spiderfffun
      @Spiderfffun 5 หลายเดือนก่อน +1

      oh dude I really want to do this now
      i would integrate this in my troll tool and it would be so funny

    • @L2002
      @L2002 5 หลายเดือนก่อน +1

      you need admin rights?

    • @SaintSaint
      @SaintSaint 5 หลายเดือนก่อน +1

      @@L2002 yes.

    • @strangegamer-si
      @strangegamer-si 5 หลายเดือนก่อน

      ​@@L2002 well yes, but it was proven, within the video, that you can use a python script on some breadboard, to do stuff that requires admin rights. So you basically connect the troll device and hide it. Run the python script to block every page, and finally, test. If it works just close the test and change desktop (if on windows). But if it doesn't work just unplug the troll device and adjust your device/script 'till it works.

  • @CZghost
    @CZghost 5 หลายเดือนก่อน +6

    One possible thing MS and/or Google could do is that if it can't reach the destination of the safe browsing/smart screen DNS, it flashes an error on the screen warning about this nefarious behaviour of your local network, before it lets you to interact with any page. If you didn't do this, you might want to investigate.

  • @SzaboB33
    @SzaboB33 5 หลายเดือนก่อน +11

    I always had a weird feeling AVs blocking Bloodhound and even maybe mimikatz. I always thought about AVs that protect me from being compromised but in those cases it limits my usage of the machine. Yea, they can be used to compromise OTHER accounts and machines but it's weird that they limit me doing it even in a non AD joined machine. I want AVs to protect me from compromise and then not to moralize about what I want to do with my life!

    • @ThatBlueFalcon
      @ThatBlueFalcon 5 หลายเดือนก่อน +1

      It's within a security tool's interest to block downloads of attacker tools, including Bloodhound and Mimikatz. If an attacker gained user priveleges on a host and Microsoft allowed users to freely download hacking tools from Github, that'd be a very convenient loophole to onboard tools.
      It's much better to download and use those tools using a sandbox environment without Defender/security features enabled, or even better just stick to a Kali distro where this wouldn't be an issue

  • @chrisjinks5414
    @chrisjinks5414 5 หลายเดือนก่อน +2

    Thank you, i have just built a Defender hunting query to notify us if the hosts file is modified and or if a request to a Microsoft or google domains returns an IP that's not publically routable (as its then been hijacked or sinkholes), many thanks.

  • @86ajmn
    @86ajmn 5 หลายเดือนก่อน

    It's def a neat trick to stick in the tool belt and also as a mental exercise to possible defeat other security look up based measures.
    I think a good question here is why doesn't Microsoft and other big tech companies bypass DNS for these type of things?

  • @Sourpusscandy
    @Sourpusscandy 5 หลายเดือนก่อน +5

    Eeww dude what are you using? Edge?

  • @heeshsusnwo666qsbwsjsjeuhwsns
    @heeshsusnwo666qsbwsjsjeuhwsns 5 หลายเดือนก่อน +2

    Yeah man another great video 🎉

  • @Crysal
    @Crysal 5 หลายเดือนก่อน

    You can also block the call to their connection test server and you device will have internet access but the Network Icon will change to "No internet access"

  • @ramseyibe2844
    @ramseyibe2844 5 หลายเดือนก่อน +1

    Thank you for this😃 i leant something new today

  • @cmarines7
    @cmarines7 5 หลายเดือนก่อน

    I have definitely learned a lot from you and Ryan Montgomery. As well as from David Bombal and Network Chuck. Thanks for all you do and keep them coming.

  • @younjesus4087
    @younjesus4087 5 หลายเดือนก่อน +1

    You should always update windows John...

    • @nordgaren2358
      @nordgaren2358 5 หลายเดือนก่อน

      It's a VM used for demos...

  • @logiciananimal
    @logiciananimal 5 หลายเดือนก่อน +1

    Microsoft traditionally says that local administrator access being required for anything nullifies any merit to it as a vulnerability.

  • @cyber_space09
    @cyber_space09 5 หลายเดือนก่อน +1

    Thanks for more formation ⚡🐦‍🔥❤️‍🔥

  • @ToniMorton
    @ToniMorton 5 หลายเดือนก่อน

    you think the browser would notify you "hey some wierd stuff is going on with your dns settings we cant access smartscreen/url screening but your connected.. 🤔
    it could just check another dns name for internet check and use those domains its checking as a sanity check for tampering

    • @ToniMorton
      @ToniMorton 5 หลายเดือนก่อน

      i think a solution would be a notification explaining your dns settings may have been altered or something just in the case of malware but i guess av is kinda the limit here? hmmm i feel like the browser could totally help notify the user of tampering here tho

  • @ankanroy2
    @ankanroy2 5 หลายเดือนก่อน

    doesn't need to go and investigate every url just sinkhole the whole smartscreen and its subdomains with wildcard thats just saves time, unless someone wants fine grain control

  • @icebice
    @icebice 4 หลายเดือนก่อน

    It does render the feature totally useless but it would require an attacker to have access in the first place. Even then, what would be the point of modifying a victim's host file if you already got access to the victim and smart screen doesn't even check for example, file transfers over ALL TCP sessions.
    I can't really see a hacker root a victim and change their host file so that the victim can download "malware" freely. It wouldn't serve the hacker any real purpose unless they are terribly bad and try to use browsers for downloading their files.
    It's a cool thing to break features in browsers but nothing more than that in my opinion.
    Good find though!

  • @Spiderfffun
    @Spiderfffun 5 หลายเดือนก่อน

    This is a little bit of an issue, and good to know, but it takes a lot more in a real world scenario, and if you can do this, you can probably do something much more meaningful.

  • @RyderCragie
    @RyderCragie 5 หลายเดือนก่อน

    Just disable it in Edge settings.

  • @aabdulr
    @aabdulr 5 หลายเดือนก่อน

    This is exactly how I get all my streaming and other things to work on ✈️ Internet. Try it out next time you're flying

  • @andrejs.smirnovs
    @andrejs.smirnovs 5 หลายเดือนก่อน

    Thanks for the video! But is there a way to bypass the verification of phishing site that was made, for example, by security team of a company to educate the personnel? It is possible of course to distribute those changes to hosts file to all assets, but this can be dangerous, since no verification will be made for real malicious sites.

    • @mollthecoder
      @mollthecoder 5 หลายเดือนก่อน

      If the company makes the phishing site for personnel only then it really shouldn't end up on a SmartScreen or Safe Browsing list.

  • @L2002
    @L2002 5 หลายเดือนก่อน +5

    Did they really contact Microsoft? 😂it's really a basic attack. I also wouldn't call it a security bug. What do you want them to do? Prevent you from downloading any file until you fix your network? Yeah, doesn't make sense.

    • @xdestino
      @xdestino 5 หลายเดือนก่อน

      yea. i agree. still cool to see

  • @rohit.vikram
    @rohit.vikram 5 หลายเดือนก่อน

    Algorithm boost go!!!

  • @lfcbpro
    @lfcbpro 5 หลายเดือนก่อน

    I'm curious about the CRDOWNLOAD file.
    While it is a temp file, I am guessing to check there is enough space to complete the download, in this instance, does it download the whole file? Or does it check with google/microsoft before completing the download and then flag it?
    If it does, can the extension be changed to give the original file?

    • @mollthecoder
      @mollthecoder 5 หลายเดือนก่อน +1

      It's the browser temporarily saving info about the file, which can be used to start off where you left off if, for example, you lose internet for a moment. It can also be used for pausing/unpausing file downloads. That's what I know about CRDOWNLOAD, although I must admit I don't know a ton about it.

  • @BunnyKhatri-pd8zm
    @BunnyKhatri-pd8zm 5 หลายเดือนก่อน +1

    I am still waiting for xz video

  • @Serpensin
    @Serpensin 5 หลายเดือนก่อน

    If I need to download blocked files, I simply wget, or curl them.

  • @Peccavi75
    @Peccavi75 5 หลายเดือนก่อน

    Invoke-webrequest?

  • @mattjohnson6276
    @mattjohnson6276 5 หลายเดือนก่อน

    Anyone know where I can get that hacker/hunter shirt he is wearing?

  • @gregisbroke
    @gregisbroke 5 หลายเดือนก่อน

    please do a pihole video

  • @crunchied8
    @crunchied8 5 หลายเดือนก่อน

    John thought on youtube was being hacked

  • @carsonjamesiv2512
    @carsonjamesiv2512 5 หลายเดือนก่อน

    Interesting.

  • @m4rt_
    @m4rt_ 5 หลายเดือนก่อน

    Maybe you could use this for a man in the middle attack, though if you already have a man in the middle thing going, I think there might be worse things you can do.

  • @harze6818
    @harze6818 5 หลายเดือนก่อน

    great video ! , 10 hours later its patched XD

  • @timecop1983Two
    @timecop1983Two 5 หลายเดือนก่อน

    OTW

  • @DavidAlvesWeb
    @DavidAlvesWeb 5 หลายเดือนก่อน

    Hey don't be mad at google, bloodhounds are good boyyyys! 🐶

  • @cybersecadventures01123
    @cybersecadventures01123 5 หลายเดือนก่อน

    Bloodhound😂

  • @wardrich
    @wardrich 5 หลายเดือนก่อน

    Smartscreen blocking downloaded files from opening is dead simple to get around with some DIR /R shenanigans too. Just modify the zone datastream to a 1, or delete it altogether and problem solved 🤣

  • @thesoftone
    @thesoftone 5 หลายเดือนก่อน

    microsoft try to not mess with their users challenge (impossible)

  • @robottwrecks5236
    @robottwrecks5236 5 หลายเดือนก่อน

    Doing a MITM or honey pot would allow you to block those as well.

  • @cleitongbr
    @cleitongbr 5 หลายเดือนก่อน

    1

  • @JoeHellethemayor
    @JoeHellethemayor 5 หลายเดือนก่อน +59

    Thanks for the shout!
    And you got it right - Hell - E

    • @sussteve226
      @sussteve226 5 หลายเดือนก่อน +1

      hi

    • @sigitas909
      @sigitas909 5 หลายเดือนก่อน +2

      As of this comment, JH didn't share the link for that article. Can you link a brother up?

    • @onemoreguyonline7878
      @onemoreguyonline7878 5 หลายเดือนก่อน +1

      Hi Joe!

    • @MaysaAhmed-jz7sp
      @MaysaAhmed-jz7sp 5 หลายเดือนก่อน

      @@sussteve226 ٢

  • @ThisIsJustADrillBit
    @ThisIsJustADrillBit 5 หลายเดือนก่อน +17

    This man is relentless ❤🔥

  • @claudiafischering901
    @claudiafischering901 5 หลายเดือนก่อน +6

    Cool, but is it not more easier to turn it of the SmartScreen ? Maybe by registry or in edge itself? Or is it to avoid the message pops up you turn off SmartScreen ?

  • @usaidkbf
    @usaidkbf 5 หลายเดือนก่อน +4

    how ur that smart ❤

  • @arjunraghunadhan3611
    @arjunraghunadhan3611 5 หลายเดือนก่อน +3

    After watching his videos i learnt many things including how to be daring and crazy because this gave me inspiration 🤣
    I love his content

  • @brbl415
    @brbl415 5 หลายเดือนก่อน +1

    this is not an issue, it's a feature

  • @patrickreuvekamp
    @patrickreuvekamp 5 หลายเดือนก่อน +1

    Am I correct in thinking that this could be a risk in public networks as well?

  • @Boxersteavee
    @Boxersteavee 5 หลายเดือนก่อน

    what if a new malware turned off smartscreen using this to then download other malware.

  • @SocialIPO
    @SocialIPO 5 หลายเดือนก่อน

    You might want to change thumbnail It looks like the video is banned

  • @DevilsVendettas
    @DevilsVendettas 5 หลายเดือนก่อน

    can you call the download in terminal to avoid the download via browser? or does it still flag it?

  • @KyleRice
    @KyleRice 5 หลายเดือนก่อน +1

    great Video

  • @grimsquirrels
    @grimsquirrels 5 หลายเดือนก่อน

    Brave browser ftw.

  • @Pem7
    @Pem7 5 หลายเดือนก่อน

    🤞🏾

  • @themirrazz
    @themirrazz 5 หลายเดือนก่อน

    The fact that Microsoft blocked their own website is beyond me

    • @paillat
      @paillat 5 หลายเดือนก่อน

      Wdym

  • @djrobSMV
    @djrobSMV 5 หลายเดือนก่อน

    " yES"

  • @draugr7693
    @draugr7693 5 หลายเดือนก่อน +1

    This is just yet another example of why i only use Windows exclusively for gaming and Linux for everything else cos with Linux i get much better privacy and security and complete control of almost everything on my computer without having to jump through hoops.

    • @L2002
      @L2002 5 หลายเดือนก่อน

      you know that the security of SmartScreen/Safe Browsering in Windows and Linux are same?!

    • @thesoftone
      @thesoftone 5 หลายเดือนก่อน

      i use linux for everything because proton is awesome :3
      the only instance of windows i will allow on my laptop is the stripped-down edition of win11, locked down in ~300gb of storage space to make sure i can have both D2 and fl studio alongside it

  • @6pfk
    @6pfk 5 หลายเดือนก่อน

    useful technique could be used to find malware, but I would use wget or curl for download bit? sorry Linux convert 80)

    • @6pfk
      @6pfk 5 หลายเดือนก่อน

      Oh! could block Microsoft spyware?????

  • @TechnicalHeavenSM
    @TechnicalHeavenSM 5 หลายเดือนก่อน

    very interesting analysis..loved the video

  • @Hybrid_Netowrks
    @Hybrid_Netowrks 5 หลายเดือนก่อน

    John just in case if you don't have admin rights on a laptop like your office laptop in that case that Joe solution is more scalable than that of yours. But, still you are the King.

  • @onemoreguyonline7878
    @onemoreguyonline7878 5 หลายเดือนก่อน

    Isn't the hosts file a bad option nowadays, because Windows regularly reset hosts files?

  • @FusionDeveloper
    @FusionDeveloper 5 หลายเดือนก่อน

    Not recommended, but good to know.

  • @torsec6048
    @torsec6048 5 หลายเดือนก่อน

    nice work john

  • @msalih
    @msalih 5 หลายเดือนก่อน

    I wish to see what data browser sends to these addresses

  • @ancestrall794
    @ancestrall794 5 หลายเดือนก่อน

    Very interesting, great video bro 👍

  • @luketurner314
    @luketurner314 5 หลายเดือนก่อน

    Pi-hole can also be ran in a Docker container

  • @sussteve226
    @sussteve226 5 หลายเดือนก่อน

    Nice no more Meet circle crap.

  • @rainbowdoesinfosec
    @rainbowdoesinfosec 5 หลายเดือนก่อน

    Classic host file trick

  • @paritoshbhatt
    @paritoshbhatt 5 หลายเดือนก่อน

    informative

  • @unknownentity5354
    @unknownentity5354 5 หลายเดือนก่อน

    I could see a scammer using this. If they get the local user to run a script or command to modify the host file, they can then have them download malicious files.

    • @mollthecoder
      @mollthecoder 5 หลายเดือนก่อน

      If they get the user to run a malicious script with administrator privileges then there's no need to convince the user to download more files from their browser - the script itself could download any necessary files.

  • @amaurisrodriguez9914
    @amaurisrodriguez9914 5 หลายเดือนก่อน

    Hi John, are you planning to do a live demo about the most recent Palo Alto CVE related to Globalprotect RCE?

    • @xYarbx
      @xYarbx 5 หลายเดือนก่อน

      If you would know the licensing costs to Palo Alto you would not be asking this. It's pretty much among the lines if you need to ask how much it is you can't afford it. When I was in Uni that does co-operation with their development team we had discounted licensing to PA-220 and even price for that was eye watering.

  • @sameul.basheerr.0Xpc
    @sameul.basheerr.0Xpc 5 หลายเดือนก่อน

    please tell how to bypass verify browser from Cloudflare

    • @Sammysapphira
      @Sammysapphira 5 หลายเดือนก่อน

      You don't

    • @mollthecoder
      @mollthecoder 5 หลายเดือนก่อน

      You won't see it up here as a TH-cam tutorial, because Cloudflare is way more serious. If you're able to bypass Cloudflare, then they would likely pay a good amount of money for you to tell them how. Or it might get sold to a government for even more money than Cloudflare would pay, in which case it would be even better kept under wraps.

  • @JNET_Reloaded
    @JNET_Reloaded 5 หลายเดือนก่อน

    starts @5:00 mins boring bs needs to be cut out!

  • @JNET_Reloaded
    @JNET_Reloaded 5 หลายเดือนก่อน

    no1 would need to do this esp a victum pointless video!

    • @nordgaren2358
      @nordgaren2358 5 หลายเดือนก่อน

      Maybe if you watched the first five minutes of the video, you'd know what use cases it's for?