Defcon 21 - How my Botnet Purchased Millions of Dollars in Cars and Defeated the Russian Hackers

แชร์
ฝัง
  • เผยแพร่เมื่อ 28 ก.ย. 2024

ความคิดเห็น • 378

  • @waffle911
    @waffle911 7 ปีที่แล้ว +236

    You know you've been in the automotive business long enough when you recognize the example VIN he uses as belonging to a Lexus.

  • @KX36
    @KX36 5 ปีที่แล้ว +36

    And this is why it's nearly impossible to buy concert tickets now.

    • @ShelliLoop
      @ShelliLoop 5 ปีที่แล้ว +1

      Naw, people are stupid. There are hawkers selling tickets at 10x the value only feet from the ticket booths.

  • @earlgrey2130
    @earlgrey2130 9 ปีที่แล้ว +295

    I feel like i should've learned IT stuff instead of arts. Then i'd maybe not be homeless and fucking unemployed -.-

    • @D4rkst4r235
      @D4rkst4r235 9 ปีที่แล้ว +13

      Правда

    • @RiDankulous
      @RiDankulous 9 ปีที่แล้ว +44

      I know IT people who majored in the arts. Not many, but they are out there. Nothing's stopping you from learning programming on your own or through certification training. The internet is full of good tutorials for every area.

    • @NightmareTV666
      @NightmareTV666 9 ปีที่แล้ว +5

      You should learning hacking to get your art out

    • @navy4341
      @navy4341 9 ปีที่แล้ว +9

      Go for Codecademy for a programming introduction. Latter on, go for C++ and hammer at emulators and collect some experience, and then go for industrial emulation projects.

    • @zombiemoat5
      @zombiemoat5 9 ปีที่แล้ว +3

      x3kesa3 This is true. learning it is free, the certification is all that matters.

  • @Minzkraut
    @Minzkraut 8 ปีที่แล้ว +166

    It might not have been the best talk, but I liked it as a story.

  • @arsalan2005
    @arsalan2005 10 ปีที่แล้ว +11

    Awesome! Enjoy watching these stories!

  • @cselph
    @cselph 9 ปีที่แล้ว +226

    I guess this was kinda interesting, but the title was completely misleading.

    • @jbGraphics_
      @jbGraphics_ 7 ปีที่แล้ว +13

      nah dog you're just dumb

    • @talhatariqyuluqatdis
      @talhatariqyuluqatdis 7 ปีที่แล้ว +3

      jb OHHHHHHHHHHHH

    • @bee_irl
      @bee_irl 5 ปีที่แล้ว

      @Joel P The fact that they may or may not have been hackers doesn't seem relevant to me.

    • @Freakazoid12345
      @Freakazoid12345 5 ปีที่แล้ว +7

      I haven't watched it yet, but might as well have thrown the word "quantum" in there for good measure.

    • @medularob7158
      @medularob7158 4 ปีที่แล้ว +1

      Exactly more of a scraper than a hack

  • @younglife88
    @younglife88 10 ปีที่แล้ว +9

    Enjoyed this talk. learned a few things, even though they are a bit of older legacy hack but still applicable.

  • @GonG108
    @GonG108 7 ปีที่แล้ว +4

    it took me 7 minutes to realize i would not even get a description of how to get me a burger by a bootnet

    • @ShelliLoop
      @ShelliLoop 5 ปีที่แล้ว

      Would you EAT a burger from a greasy dirty bot hacker????

    • @goiterlanternbase
      @goiterlanternbase 4 ปีที่แล้ว

      What ever brings me closer to a burger now, is reasonable.

  • @alexandernyberg8668
    @alexandernyberg8668 2 ปีที่แล้ว +1

    6:40 "It's important because the developer has to get payed" -The developer

  • @maverickstclare3756
    @maverickstclare3756 4 ปีที่แล้ว +8

    I use Burpsuite to MITM the browser to work out the flow to build bots. I have automated my work in my last two jobs. The last one from 8 hours per day to 20 mins. Then I got the sack when the next boss came because my jobs looked so easy. They assigned a cheaper colleague to take over and he went nuts finding out it was going to take him 8 hours.

  • @ryanpongracz8051
    @ryanpongracz8051 8 ปีที่แล้ว +54

    sooooo, this is how all those scalpers, buy all the tickets from ticket master and keep us all from being able to buy them fairly. I need to learn how to do this stuff

    • @molomono9795
      @molomono9795 8 ปีที่แล้ว +13

      Actually Ticketmaster can stop scalpers but they would loose money in doing so. So i doubt it's a very prominent topic on their agenda.

    • @johnfrancisdoe1563
      @johnfrancisdoe1563 5 ปีที่แล้ว +1

      ryan pongracz I remember a concert house working with a journalist from the same corporation to bait those bots with an unannounced concert then publicly shaming the scalping site that instabought tickets and put them up for sale before the concert was announced. Didn't make a dent.

  • @jtc1947
    @jtc1947 4 ปีที่แล้ว +5

    I wonder why this project was only successful for about 40 weeks or so? Did it start failing? Were there changes that the project could not handle? Did the other people COMPENSATE for the improvements and start intruding on the business?

  • @thatguy1000001
    @thatguy1000001 10 ปีที่แล้ว +10

    "..It was like the gods handing me fire! Here you go Mike, you've been a good boy!"
    Hahahaha gold

  • @JordanShackelford
    @JordanShackelford 7 ปีที่แล้ว +58

    My mom and dad made a bot in 1995 too. His name was Jordan. :(

    • @DrFreezedUp
      @DrFreezedUp 7 ปีที่แล้ว +8

      Jordan Shackelford k

    • @pure_espress0393
      @pure_espress0393 7 ปีที่แล้ว +7

      Hey wait a second........

    • @talhatariqyuluqatdis
      @talhatariqyuluqatdis 7 ปีที่แล้ว

      Jordan Shackelford your profile pic perfectly portrays this plump emoji :(

    • @lawrencenoyman350
      @lawrencenoyman350 6 ปีที่แล้ว

      You think you are a bot?

  • @Gunbudder
    @Gunbudder 7 ปีที่แล้ว +8

    for any curious, the vin at 13:49 is for a salvage title lexus in michigan. i don't know why i looked that up

  • @Its__Good
    @Its__Good 5 ปีที่แล้ว +7

    It seems odd that the market is consistently under-valuing these cars to the point where people are designing bots just so they can click 'buy now' as quickly as possible. Why aren't prices rising as a result? Why aren't they being sold at auction?

  • @Samura1gamer
    @Samura1gamer 6 ปีที่แล้ว +45

    i was one of the russian hackers that was defeated by his bot back then, and yes i saw a giant red and blue eagle on my screen at the time of defeat

  • @DanielLopez-up6os
    @DanielLopez-up6os 5 ปีที่แล้ว +7

    Dang Myspace was old in 2013... And it's still there... Barely.

  • @IronFilmVR
    @IronFilmVR 7 ปีที่แล้ว +2

    Wow, how did the small dealership then handle buying over 800 cars in less than a year so as to then sell them on to customers?! Must have needed to massively increase his sales.

    • @Seth9809
      @Seth9809 7 ปีที่แล้ว

      He sold like 20 cars a week, that easy.
      That's like one every two working hours.

  • @NeoIsrafil
    @NeoIsrafil 9 ปีที่แล้ว +6

    I would imagine you could estimate the lag time and server load needed by pinging the server and basing your purchase timing on the response. Could be wrong though...

    • @ShelliLoop
      @ShelliLoop 5 ปีที่แล้ว

      exactly. but it would ruined his lengthy story.

  • @sellersgarner
    @sellersgarner 7 ปีที่แล้ว +1

    "RUSSIAN HACKERS?! MIKEY FORRESTER?! WHAT THE HELL ARE YOU GUYS ON ABOUT?!?!" - S. Williamson

  • @batlin
    @batlin 6 ปีที่แล้ว +2

    If you wanted to try just "re-enabling" the Buy button, you could just give the client a bookmarklet that alters the page content... probably still wouldn't work though, if they actually validate requests on the server side.

    • @ConstantlyDamaged
      @ConstantlyDamaged 2 ปีที่แล้ว +1

      As he stated repeatedly, this kind of action could lead to people buying cars before the sale time-in which case you get all your accounts deleted and are banned from the service. This is how not to have a Good Day™.

    • @batlin
      @batlin 2 ปีที่แล้ว

      @@ConstantlyDamaged I didn't say it was a good idea, just that it can be done, and therefore someone will do it.

  • @mkomovffdfewrwqwerqw
    @mkomovffdfewrwqwerqw 9 ปีที่แล้ว +47

    The GROUP of RUSSIAN HACKERS hired by competing USED CAR DEALERSHIP. They bring them here from the cold Siberia, to conduct their evil plan on constructing a CAR SALES BOT. But I single handely defeated them.

    • @kb3ngb
      @kb3ngb 7 ปีที่แล้ว

      was probably kids in secaucus using some open russian iot device running msh

    • @kb3ngb
      @kb3ngb 7 ปีที่แล้ว +1

      found signs of PAS web shell, immediately attributes russia
      (for the dense never mind PAS is ukrainian and available here github.com/wordfence/grizzly was until recently available at profexer.name but site changed and i don't speak the language to grok it any more)

    • @sliyarohmodus5749
      @sliyarohmodus5749 5 ปีที่แล้ว +2

      Exactly. If you replace "Russian Hacker" with any other racist stereotype you'll see that this is yet another attempt at pole pissing and chest thumping by a bigot.

  • @75PercentWater
    @75PercentWater 6 ปีที่แล้ว +3

    or is he the guy defeated by captcha?

  • @xorinzor
    @xorinzor 6 ปีที่แล้ว +8

    All you need to do is send a POST or GET request with the form data it'd expect and you're done xD

  • @swaaagquan3540
    @swaaagquan3540 5 ปีที่แล้ว +1

    You guys are aware he's a CIA/DIA contractor talking about work done a few years back. Hence the legality doesn't matter as he was operating above the law.

  • @phatrikk123
    @phatrikk123 7 ปีที่แล้ว +1

    Can someone explain to me how he determined the time from the server's clock? I''ll admit I'm not a web dev but it seems unlikely to me a server would voluntarily give away it's time to anyone who asks for it (who isn't already authenticated to the server with a user account). Did he possibly mean the sales website showed a clock?

    • @phatrikk123
      @phatrikk123 7 ปีที่แล้ว +1

      and yeah, I know what NTP is... Obviously, that's not what he's talking about here...

    • @ConstantlyDamaged
      @ConstantlyDamaged 2 ปีที่แล้ว +3

      I know this is late, and you might know the answer by now, but when a web server responds to a HTTP(S) request, they include a "Date" field in their reply header which has a lovely date/time value that is usually referenced to GMT. These are accurate to the second, of course, so that's why he repeatedly prods the server to obtain more precision.

  • @ericsbuds
    @ericsbuds 9 ปีที่แล้ว +1

    how did the bot know what time the buy button would show up? wasn't that the whole point? if you knew what time the buy button would appear, you wouldn't need people constantly clicking refresh in the first place.

    • @Ilikeyourgirl
      @Ilikeyourgirl 9 ปีที่แล้ว

      +ericsbuds Of course, even if you know that the car in on sale at, let's say 2pm, there are still 700-800 people wanting to press the buy button first. If you don't refresh, you won't be the first one to buy as it will not refresh automatically.

    • @ericsbuds
      @ericsbuds 9 ปีที่แล้ว +1

      Pianolicious i see I see, so you know what time the buy will happen before hand. thanks ;D

    • @Ilikeyourgirl
      @Ilikeyourgirl 9 ปีที่แล้ว +2

      +ericsbuds I might be completely wrong, but as far as I understood, the time the offer went live was actually known to everyone. just like an auction, it starts at a specific time.

  • @TheTigero
    @TheTigero 9 ปีที่แล้ว +103

    I had high hopes for this talk... In the end, all the guy really needed was Firebug to enable the buy button...

    • @teejaye110
      @teejaye110 9 ปีที่แล้ว +28

      +Kevin Klika he talks about that option near the end, and says while it probably would have worked, it wouldn't be the smartest choice for the same reason the VIN numbers were verified before trying to buy the car

    • @sebastienlauzon5655
      @sebastienlauzon5655 8 ปีที่แล้ว +4

      *Spoiler Alert??*

    • @TheTigero
      @TheTigero 8 ปีที่แล้ว +2

      Sébastien Lauzon not a spoiler alert, it's exactly NOT a spoiler because it's not what he did...

    • @IoanKatalinn
      @IoanKatalinn 8 ปีที่แล้ว +2

      Bullshit. Watch the video guys.

    • @Penissniffer
      @Penissniffer 7 ปีที่แล้ว +18

      Just cause u can enable the the buy button client side doesnt mean server side code will accept the request.

  • @ContagiousRepublic
    @ContagiousRepublic 5 ปีที่แล้ว +3

    Credit on you for not writing a buy-before-the-button-appears button using a greasemonkey script, which the russians hackers would not hesitate to. ALSO you might have wanted to try working for the sales sites and have them setup a proper bidding process and have customers enter reserve prices...

  • @ShelliLoop
    @ShelliLoop 5 ปีที่แล้ว +4

    Your whole talk is obfuscation Good job, you diverted the topic from down-right-evil-BOT-hacker, to do-kinda-good-sometimes-BOT-hacker.

  • @jonandbrooklynn6361
    @jonandbrooklynn6361 5 ปีที่แล้ว

    Really interesting. Thanks for sharing

  • @Anvilshock
    @Anvilshock 6 ปีที่แล้ว +35

    VIN number. Vehicle Identification Number number.

  • @ФеофанЭтополедолжнобытьзаполне

    I'm afraid to watch more recent defcons. Now they are probably discussing how to make a dark theme for your browser or how to "hack" youtube ads by editing DOM on the fly.

  • @kirdook
    @kirdook 10 ปีที่แล้ว +1

    To anyone trying to do this that isn't 40-50 years old and want to write readable and sane code, imacros sounds like such overkill. The python library mechanize is what you need. Look up how to spoof a browser it's 20 lines of code your can copy paste that works anywhere.
    I could do this guys job, easily. Just goes to show that business is 90% who you know.

    • @fission1110
      @fission1110 10 ปีที่แล้ว

      Probably, but this stuff isn't hard. The point of imacros though, is mechanize doesn't pull down ajax, and it's really easy to detect and block even with spoofed user agents.

    • @kirdook
      @kirdook 10 ปีที่แล้ว

      what you say is 100% true, trying to get JS to run in mechanize is not something you want to do, all I was saying is for this application where they're just refreshing a page and looking at a button property then it's most certainly overkill

    • @sciencoking
      @sciencoking 10 ปีที่แล้ว

      I can't say I have experience with automating processes that actually involve money (really in this context I'm just some script kid), but the validation mechanisms I've seen could be replicated by looking at the websites' code hard enough - is that not feasible for serious applications like this? Would it take too much time?

    • @fission1110
      @fission1110 10 ปีที่แล้ว

      Yea, I've been on both sides of this problem.
      That's probably fine if you're just crawling one site, but the problem comes when you're crawling 20 websites, and need specialized code for each site for getting around A/B testing, browser validation, template updates, etc. It's soooo much easier to just throw up some imacros stuff and not even worry about how the site renders, just let it do its thing and then send you back the completed html.

    • @sciencoking
      @sciencoking 10 ปีที่แล้ว

      ryan edge I see, so I'm just not thinking big enough :P

  • @Pleiodes
    @Pleiodes 7 ปีที่แล้ว +1

    is it possible to buy stocks with a bot network? Or is that illegal?

    • @mikecrapse5285
      @mikecrapse5285 7 ปีที่แล้ว +6

      Pleiodes it's called machine trading, and more than 75% of stock trades are done with this method

    • @grendelum
      @grendelum 5 ปีที่แล้ว +1

      There’s also a *_huge_* amount of work that goes into currency trading... bots that are scanning currency markets around the world for when currency A is just a fraction off in market B and tho it may be tenths of a percent it can add up quick !!

  • @eliluong
    @eliluong 7 ปีที่แล้ว

    how did he know when the buy button would appear? he is counting down time to make the purchase.

    • @ShelliLoop
      @ShelliLoop 5 ปีที่แล้ว

      yes. he said EXACTLY that.

  • @dzhiurgis
    @dzhiurgis 7 ปีที่แล้ว +1

    I guess no XSRF tokens back then?
    Also rental car is great if you need to something that looks brand new but is completely destroyed mechanically.

  • @knopjeh
    @knopjeh 8 ปีที่แล้ว

    What did that guy shout at the beginning?

  • @firefox5926
    @firefox5926 7 ปีที่แล้ว +1

    13:12 did no one think of just using a drinking bird ?

  • @WalleCarlos
    @WalleCarlos 9 ปีที่แล้ว +3

    Can anybody help?
    My PC is connected to the internet ant it shows "internet access" but whenever I open up a browser and try to access a website it says "Connection Unavailable" I running windows 8.1 64Bits. Help, please!!!

    • @JustChillF
      @JustChillF 7 ปีที่แล้ว +3

      try a different browser firstly, if that doesnt work, check your pc proxy settings or dns server, otherwise check your browser's proxy settings

  • @sebastianiuga3020
    @sebastianiuga3020 4 ปีที่แล้ว

    Why would you go against hackers i thought we were on the same side

  • @xxPEvexx
    @xxPEvexx 5 ปีที่แล้ว

    LOL they frantically refresh and DOS themselves. I work at a dealership and i knew salesmen were stupid but, wow this is stupid on another level.

  • @bradypatterson1891
    @bradypatterson1891 5 ปีที่แล้ว

    He almost got a sentence in between ads there for a bit.

  • @Vrani2110
    @Vrani2110 9 ปีที่แล้ว +5

    Well, glad to see that bots can actually be used for something "good" xp
    Much better than all the immensly hobby.lacking people making messenger-bots who wants "to have sex with you" >>;
    Though, they don't like being asked irrellevant questions it seems x3

    • @tizrmonky
      @tizrmonky 9 ปีที่แล้ว

      Vrani2110 hahahaha ahhhh good one

    • @johnfrancisdoe1563
      @johnfrancisdoe1563 5 ปีที่แล้ว

      Vrani2110 Not as bad as the bots that commercially messes with our lives out of their California headquarters.

  • @pinotfilmnoir
    @pinotfilmnoir 10 ปีที่แล้ว +1

    Awesome!

  • @HackersOnBoard
    @HackersOnBoard  4 ปีที่แล้ว +4

    Hello dear friends
    The 2nd December 2019 we get notified of the censorship of our channel by the new TH-cam Guidelines (who change every 6 months) because of "Content reusing without including substantial original commentary or educational value" so in consequence the Monetization of our channel was disabled.
    This is a little bit tricky because these Guidelines wasn't there in 2013, 2014, 2015 and so on...
    It is abnormal to change the rules during a game
    ...even more before Christmas!
    Since 2013 we are trying to share the best Security Conference on our channel and we need your help to keep it up.
    As you already know I was fighting the disease since the last 2 years and it's difficult and without resource and support I wouldn't be able to keep up on this way.
    You can support us on Patreon if you find our work valuable.
    You can also express your dissatisfaction regarding our situation to TH-cam on Twitter, Facebook, Instagram and wherever you can. to help us regain our rights.
    Your support in anyway will be truly appreciated
    Thanks guys for taking time reading me and stay tuned!
    Merry Christmas to you all and God bless you all!
    www.patreon.com/HackersOnBoard
    Bitcoin Wallet: 1NWM4upgKj8iF7zknzmnHG8Mm2pvAyTHqc

    • @Vykk_Draygo
      @Vykk_Draygo 4 ปีที่แล้ว +3

      So you want to be paid for re-uploading other people's content? Geez.

    • @HackersOnBoard
      @HackersOnBoard  4 ปีที่แล้ว +1

      @@Vykk_Draygo This is not "other people's content" because this is free to use...

  • @a29_
    @a29_ 7 ปีที่แล้ว

    0:45 sounds like the last fast and fiurious movies

  • @rekrn12345
    @rekrn12345 7 ปีที่แล้ว +2

    God damn russian hackers everywhere.

  • @nikolaos9175
    @nikolaos9175 7 ปีที่แล้ว

    Very informative. Thx

  • @metalfist54
    @metalfist54 10 ปีที่แล้ว +9

    "bot net" haha...

  • @thetrioffish
    @thetrioffish 7 ปีที่แล้ว

    what's wrong with your ads?

  • @niight2122
    @niight2122 7 ปีที่แล้ว

    I watched the whole video and I'm like a huge football meathead kind of guy but I think this stuff interests me...I think I might major in some kind of network or technology in a few years when I transfer from high-school to college

    • @kebman
      @kebman 6 ปีที่แล้ว

      Nxght yeah sorry, this guy is either full of shit, or he's purposefully misleading people about how forms can be spoofed. Or worse, he didn't even know it himself...

  • @DJ369-Miami
    @DJ369-Miami 10 ปีที่แล้ว +2

    With the car buy program, how is that even a bot, it's just an application?

  • @RichMantaray
    @RichMantaray 7 ปีที่แล้ว

    it was a younger guy that actually did the botnet not him

  • @MusiciansReflib
    @MusiciansReflib 4 ปีที่แล้ว

    Auto Hot Key ftw

  • @kenichimori8533
    @kenichimori8533 4 ปีที่แล้ว

    Thanks purchased botnet.

  • @happyjohn1656
    @happyjohn1656 6 ปีที่แล้ว +5

    18:53 Awkward!
    6:02 PM
    9/16/2018

  • @hrnekbezucha
    @hrnekbezucha 6 ปีที่แล้ว

    Cute little story of a dude making a bot..

  • @foof811
    @foof811 6 ปีที่แล้ว +4

    at 6:15 he sounds like Kermit the frog

  • @brianaragon1641
    @brianaragon1641 5 ปีที่แล้ว

    Amazing

  • @padlockbeats151
    @padlockbeats151 7 ปีที่แล้ว +4

    damn thats a hustle. sounds illegal lol

  • @mcottingham
    @mcottingham 5 ปีที่แล้ว +1

    ...my client said we were attacked by russian hackers.. WHY THE F%!$ does Russia care about a few cars on a dealership network? Give your head a shake people.

    • @TripleBarrel06
      @TripleBarrel06 5 ปีที่แล้ว

      Where did he say that? Pretty sure he said his client found out that a competitor hired some Russian hackers to make a competing bot.

    • @mcottingham
      @mcottingham 5 ปีที่แล้ว

      Exactly. I'm pretty sure his client was exaggerating. Again, I doubt Russian hackers care about a few cars on a dealer network.

  • @shellybelly35
    @shellybelly35 9 ปีที่แล้ว +2

    i got well bored love zoz's presentations =)

  • @EduardoGonzalez-bm1mk
    @EduardoGonzalez-bm1mk 4 ปีที่แล้ว

    Now all bots are for stupid drops sites and you have to make a fucking Ai that generates a canvas and a bunch of random click so the antibot system thinks that you re human .
    I’m talking about all the Nike bots or the supreme ones.

  • @ShelliLoop
    @ShelliLoop 5 ปีที่แล้ว +2

    TOO BAD he didn't have "insider" --REAL INFORMATION. i.e. Dealers only pay HALF THE STICKER PRICE for a car. The "catch" was dealers had to buy ANY car sent to them--no choices--until their contract quota was met. But, half the sticker price is AWESOME!
    So, the MARKUP IS INSANELY HIGH! 100% !!! How can GM or Ford etc. do this? Because when the typical Sticker Price was $18,000 it only cost $2500 (including labor) a car to produce.
    Enough free info. Now, cars cost more but the percentages are closely the same.

  • @LexFromHell
    @LexFromHell 7 ปีที่แล้ว

    But... captchas ?

    • @ertpecsertpecs
      @ertpecsertpecs 4 ปีที่แล้ว

      How many captchas do you remember in 2007? Sorry about the necro

  • @evileyeden8024
    @evileyeden8024 8 ปีที่แล้ว +2

    what would happen if storm worm, mydoom and ILOVEYOU were all spread across the internet, AT THE SAME TIME?someone do it please.

    • @Wwisp
      @Wwisp 8 ปีที่แล้ว +5

      +Sonny Slaterling You massive, fucking skid.

    • @grren1782
      @grren1782 8 ปีที่แล้ว

      HIDE YOU DATA, HIDE YOU BYTES

    • @evileyeden8024
      @evileyeden8024 8 ปีที่แล้ว

      ALL YOUR BYTES ARE BELONG TO US.

    • @grren1782
      @grren1782 8 ปีที่แล้ว

      Sonny Slaterling perfect

  • @maxximuss
    @maxximuss 10 ปีที่แล้ว

    this should be a crime

  • @evileyeden8024
    @evileyeden8024 8 ปีที่แล้ว +1

    find ILOVEYOU script, copy, paste, run in vb. watch your files disappear infront of your very eyes.

    • @op-cq7hw
      @op-cq7hw 8 ปีที่แล้ว +14

      are you stupid?

  • @music9170
    @music9170 7 ปีที่แล้ว

    I used to make things like this when I was a kid to mess with chat sites ahahahaha

    • @mrpumperknuckles1631
      @mrpumperknuckles1631 7 ปีที่แล้ว +1

      Joe can you make webpage servers with its own domain with no need to pay for a host?

    • @music9170
      @music9170 7 ปีที่แล้ว

      I used to put them on free hosting servers like angelfire (not sure they even exist anymore) the only problem was the add-on style domain name. From what I remember reading it was possible as long as you have your own server with enough bandwidth?

  • @numbah12time
    @numbah12time 10 ปีที่แล้ว +4

    Man, Where do I go to find people that are great at stuff like this?? Reddit?? :>

    • @IdoruFalls
      @IdoruFalls 9 ปีที่แล้ว +1

      IRC

    • @numbah12time
      @numbah12time 9 ปีที่แล้ว

      But then they'll just hack me! :(

    • @IdoruFalls
      @IdoruFalls 9 ปีที่แล้ว

      ***** Inland Revenue Chat. It's an old messaging system that was created to allow fast communication betwen IRS agents in the 80s. When it fell out of use [they now use headsets and VoIP services like Ventrilo] the US government didn't bother to delete the digital infrastructure, so hackers commandeered it and have been using it to plan e-heists and cybercapers ever since.

    • @jasengibson6619
      @jasengibson6619 9 ปีที่แล้ว +1

      Mr Wednesday bahahaha.... I could hear the whooshing sound as that flew by someone's head all the way over here.

    • @stormcloaksoldier4676
      @stormcloaksoldier4676 9 ปีที่แล้ว

      Mr Wednesday Pretty sure it just means Internet related chat

  • @75PercentWater
    @75PercentWater 6 ปีที่แล้ว

    is he one of the people invented spam mails?

  • @alekseevstepan
    @alekseevstepan 4 ปีที่แล้ว

    still sometime do same things)

  • @deadeyenation1
    @deadeyenation1 5 ปีที่แล้ว +2

    people do this shit with concert ticket sales now :(

  • @boxbox6290
    @boxbox6290 9 ปีที่แล้ว

    Im 2 mins in this guy seems sound n funny

  • @Seernadroj
    @Seernadroj 10 ปีที่แล้ว

    18:15? What did he say/

    • @Xeldafied
      @Xeldafied 9 ปีที่แล้ว

      He started to say the persons name so he stopped himself.

    • @JonathanCr0ss
      @JonathanCr0ss 5 ปีที่แล้ว

      @@Xeldafied "Mike would call..."

  • @JohnSmith-ii8pp
    @JohnSmith-ii8pp 7 ปีที่แล้ว

    The whole thing seemed pointless. The first few seconds into the description of the problem, I thought, "why not just enable the submit button?", Seems like a no-brainer. If timed right, you could have submitted a second before sale time, and nobody would have ever noticed. There would have been no need for version 2.0.

  • @marianoarganaraz
    @marianoarganaraz 8 ปีที่แล้ว

    Damn I almost fell asleep

    • @ShelliLoop
      @ShelliLoop 5 ปีที่แล้ว

      if you are a "couple" its your own fault you fell asleep. Take a shower.

  • @markintoit8260
    @markintoit8260 10 ปีที่แล้ว

    Russian Hackers? seriously...what is this Cyber berlin wall

  • @Cmcmillen77
    @Cmcmillen77 5 ปีที่แล้ว

    What the fuck is a bot? How the fuck do I do this?

  • @JohnSmith-bx4gf
    @JohnSmith-bx4gf 7 ปีที่แล้ว +1

    bliet

  • @mikeholloway6302
    @mikeholloway6302 9 ปีที่แล้ว +1

    hacking? you can only hack some of the people some of the time but not all the people all the time...lol

  • @DigitalicaEG
    @DigitalicaEG 6 ปีที่แล้ว +1

    "Now the Russian hackers screw you" -Putin 2017

  • @rixsta1256
    @rixsta1256 9 ปีที่แล้ว +1

    More like he started selling the bots to other people and fkd the guy over.

  • @daneisu6885
    @daneisu6885 9 ปีที่แล้ว +16

    What a waste of time....

    • @draxler.a
      @draxler.a 8 ปีที่แล้ว +2

      +danei su Very stupid talk

  • @freem4nn129
    @freem4nn129 5 ปีที่แล้ว

    hahahaha no comprendo legend

  • @jagerbombs2006
    @jagerbombs2006 8 ปีที่แล้ว +31

    Very stupid talk... not what I expected from defcon...

    • @talhatariqyuluqatdis
      @talhatariqyuluqatdis 7 ปีที่แล้ว

      Jager Bombs Very stupid profile pic... not what I expected from the bomb...

    • @pmAdministrator
      @pmAdministrator 6 ปีที่แล้ว +1

      And still you watched it. You fail man.

  • @jackflash9123
    @jackflash9123 4 ปีที่แล้ว

    TOY

  • @bass9454
    @bass9454 7 ปีที่แล้ว

    thnx for upload

  • @18Svea
    @18Svea 6 ปีที่แล้ว

    to much publicity in 20 min video

  • @RaviBhojwani
    @RaviBhojwani 6 ปีที่แล้ว

    #htmlcoin

  • @markintoit8260
    @markintoit8260 10 ปีที่แล้ว

    He made something that he can't even own...and he calls himself hacker...lol

    • @Xeldafied
      @Xeldafied 9 ปีที่แล้ว +3

      He wrote the bot and owns the hardware that runs the clients so what?

    • @isurujn
      @isurujn 5 ปีที่แล้ว +1

      You really don't know how broad hacking is, do you?

  • @memres217
    @memres217 5 ปีที่แล้ว +1

    Honestly expected some next level bots, his system sounded like something you could whip up in about 2 hours =/

  • @weir-t7y
    @weir-t7y 7 ปีที่แล้ว

    "Acquiring good used cars"
    Bullshit, I work on cars. The used cars given to dealers are shitboxes that were about to become too expensive or leases that were never maintained.

  • @draxler.a
    @draxler.a 8 ปีที่แล้ว +1

    Very stupid talk ....waste of time

  • @pauleluard8854
    @pauleluard8854 7 ปีที่แล้ว +1

    Client side scripting and used cars at Defcon 21! Please guys we are at the age of API and self driving cars, wtf was this 90's survivor loonie doin on stage??

  • @martinzember8721
    @martinzember8721 5 ปีที่แล้ว +48

    This is about automation for a customer (something we also love to do). But calling it a botnet at defcon, in the context of security? And russian hackers?

    • @Galactipod
      @Galactipod 8 หลายเดือนก่อน +1

      A botnet is a group of Internet-connected devices, each of which runs one or more bots. The bots don't have to be across the world on random people's PCs. And this is outside the context of security, it's in the context of online retail.

    • @martinzember8721
      @martinzember8721 8 หลายเดือนก่อน

      ​@@Galactipodit's not outside of context of security if it was presented at DEFCON.
      "DEF CON is a hacker convention ...since 1993 and today many attendees at DEF CON include computer security professionals, journalists, ..." Wikipedia
      According to the number of upvotes, I was not alone wondering.

  • @eustatianwings
    @eustatianwings 8 ปีที่แล้ว +6

    "Trespass to chattels" "very illegal" - before we get all FUDdy on that, the term actually means "you messed with and broke my shit, now I shall sue you." In the real world you'll be blocked and/or asked to stop before you're sued.

    • @ryannorthup3148
      @ryannorthup3148 2 ปีที่แล้ว +1

      Cease and desists usually come before big lawsuits. Intimidation is cheaper than a lawyer.

  • @Jay-Niner
    @Jay-Niner 7 ปีที่แล้ว +46

    Love the amount of mid-stream ads you injected into this freebooted video...

    • @Seth9809
      @Seth9809 7 ปีที่แล้ว +7

      Fuck the uploader.

    • @KeenJT
      @KeenJT 5 ปีที่แล้ว +1

      It doesn't matter, the video would be auto detected by youtube's copyright claims and all the ad money would go to the copyright owner

    • @MasterMindWC
      @MasterMindWC 5 ปีที่แล้ว

      Brave browser.

    • @lolcatwill
      @lolcatwill 4 ปีที่แล้ว +6

      @@MasterMindWC ublock. brave is spyware.