Internet Explorer Forced to Run Malware

  Рет қаралды 91,222

John Hammond

John Hammond

Күн бұрын

j-h.io/guardio || Guardio helps keep your business safe from online threats! Start a free 14-day trial with Guardio to get started: j-h.io/guardio
🔥 KZfaq ALGORITHM ➡ Like, Comment, & Subscribe!
🙏 SUPPORT THE CHANNEL ➡ jh.live/patreon
🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
🌎 FOLLOW ME EVERYWHERE ➡ jh.live/discord ↔ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/instagram ↔ jh.live/tiktok
💥 SEND ME MALWARE ➡ jh.live/malware

Пікірлер: 136
@januzi2
@januzi2 Жыл бұрын
Using Internet Explorer to run malicious code? I've never heard about such thing.
@seniorchonkza997
@seniorchonkza997 Жыл бұрын
Next they're gonna tell you they're in word documents. How silly!
@entelin
@entelin Жыл бұрын
I bet they had to really twist it's arm
@romanemul1
@romanemul1 Жыл бұрын
You mean you never heard about internet explorer right? Who uses IE anyway?
@januzi2
@januzi2 Жыл бұрын
@@romanemul1 Unfortunately, I've spent hundreds of hours trying to make the webpages look the same in the IE6, as in the Firefox or Chrome. For some reason corporations didn't want to upgrade their browsers, even when the IE8 went live. I guess they were using Flash and other old software to keep their business running. I have a feeling they all had been forced to upgrade their systems, because nobody wanted from me to make the changes to the webpages for over 15 years. Nowadays, it's more like "FF & Chrome are good, but you should do something about the webpage on the Iphones".
@roygalaasen
@roygalaasen Жыл бұрын
I remember IE 4. That was the bomb!
@peters.c.5541
@peters.c.5541 Жыл бұрын
"Malware forced to run Internet Explorer" I think is more accurate
@Gattancha
@Gattancha Жыл бұрын
I have a feeling the errors in Windows 11 and possibly now Windows 10 , may be in part due to Microsoft now retiring the IE Desktop application. It still, sort of, runs but only in a very stripped down way known as "IE Mode" which opens in Edge - so the chances are there are no accessible COM objects now.
@dakoderii4221
@dakoderii4221 Жыл бұрын
@@HypeXesk Don't forget the telemetry.
@ololh4xx
@ololh4xx Жыл бұрын
"Internet Explorer forced to run malware" is like saying "spyware forced to run malware"
@mossdem
@mossdem Жыл бұрын
So accurate 😂
@dragonloverlord
@dragonloverlord Жыл бұрын
It's more like "Windows Vista forced to be slow" when as anyone who used it during it's time would know that's actually more of a built in feature.
@nicholasbrooks7349
@nicholasbrooks7349 Жыл бұрын
Still I bet you use google chrome, which itself could be considered as much spyware as chrome is.
@dragonloverlord
@dragonloverlord Жыл бұрын
@@nicholasbrooks7349 I'd still take spyware without malware over spyware with malware assuming we're leaving other choices out of the equation and honestly sometimes you have to use chrome (I'm looking at you enterprise device's / internal use only websites). I still remember when employers actively wanted all their software for IE... What a nightmare those days were.
@NeptuneOnYouTube
@NeptuneOnYouTube Жыл бұрын
Internet Explorer is Spyware?
@zsi
@zsi Жыл бұрын
Reminds me of malware a couple of years ago for a red team engagement that would spawn IE as a background process as a means of communicating with our C&C server.
@fr8trainUS
@fr8trainUS Жыл бұрын
This reminded me of a "hack" we figured out in high school in the mid to late 90s. In windows 95 The security on the lab systems would lock down certain programs. They were gone from the start menu, and if you navigated to them directly, and tried to run them, nothing would happen. However, we could use MS Paint. In paint, file, open, navigate to the game's .exe and bingo, you could play solitaire.
@zoes17
@zoes17 Жыл бұрын
When I first saw this I wondered about S-mode but I mean that would make loading/installing your own executable non-trivial too so I suspect a malicious actor would try to disable that first, if that's even possible remotely.
@gPuma
@gPuma Жыл бұрын
Cool great video, stuff I would never thought about, but John, how come you never put the websites you visit in the description...
@derekciravola5374
@derekciravola5374 Жыл бұрын
"ahh I got some weird stuff in that directory. That's kinda sketch" "ANYWAY" LMFAOO subbed.
@jacobfurnish7450
@jacobfurnish7450 Жыл бұрын
"I was playing with some moth balls...i dunno can you say that???" - John Hammond
@jkobain
@jkobain Жыл бұрын
I don't think Guardio is really *that* helpful, but I like the fact that they paid you and I can hear your pleasant voice.
@sourabhpurohit8575
@sourabhpurohit8575 Жыл бұрын
I just have a question. Can this be used to invoke a malicious exe without triggering windows defender ?
@romanburczymorda4313
@romanburczymorda4313 Жыл бұрын
"It's a feature, not a bug" :D
@pepemunic3661
@pepemunic3661 Жыл бұрын
like always, great content
@JuanBotes
@JuanBotes Жыл бұрын
I really appreciate your content and great ability to explain material, I think my skills at beginner and struggle with reading studies slow due to my challenges and searching for advanced skills training to level up my skills, I am frustrated with my slow learning curve ,if you would please make advance content
@imzesok
@imzesok Жыл бұрын
4:44 - right it works this way because it's technically an extension of windows explorer. which is partly why it's trash. it's the Konquerer(for the youngsters it was the original file manager that doubled as a web browser of the KDE desktop environment under linux/BSD) of the Windows Desktop. dumb little things like this is why it's getting retired. I don't think it'll get completely removed from Win10, because IE is still so tightly baked into the file explorer. Pretty sure they rewrote explorer without the IE integration for 11, but I could be wrong on that.
@tabbydacat9506
@tabbydacat9506 Жыл бұрын
Woke up too see a upload from hammond today will be a good day
@mossdem
@mossdem Жыл бұрын
I listen to a podcast called Darknet Diaries. I’m sure you must’ve come across a few scenarios you could discuss but would love to hear you on one of these podcasts
@Thedude897
@Thedude897 Жыл бұрын
Best podcast around!
@weiSane
@weiSane Жыл бұрын
What a great podcast...Jack did us a solid starting that podcast
@franciscolucarini8761
@franciscolucarini8761 Жыл бұрын
Hey John when the next Windows Kernel exploitation video? Really like them
@justwiredme
@justwiredme Жыл бұрын
Thank you for your video I enjoyed your presentation and how you show with code also thank you for sponsoring the item you do very helpful
@jagdtigger
@jagdtigger Жыл бұрын
4:20 Not only that but when lets say you try to open google in IE edge pops up instead, one more indicator that MS SW is basically malware.....
@logiciananimal
@logiciananimal Жыл бұрын
Does changing %SYSTEMROOT% require elevated permissions?
@noobergober
@noobergober Жыл бұрын
it could not find any of the names in the hex editor
@forxstsombodi3043
@forxstsombodi3043 Жыл бұрын
"wow i have some random stuff in that directory, that's kinda sketch" lmao
@TomTom-gx1sm
@TomTom-gx1sm Жыл бұрын
IE is finally useful for me !
@nanopi
@nanopi Жыл бұрын
Remember when IE could just embed the contents of C:\ as an on a web page?
@_AN203
@_AN203 Жыл бұрын
0:40 When a redteamer want to flex some skills.... 😂😂😂
@sandeepsinghsethi15
@sandeepsinghsethi15 Жыл бұрын
Last video you talked about guardio and now this one is sponsored by guardio 😅✌️
@superproxocz
@superproxocz Жыл бұрын
7:40 you can overwrite sethc.exe (sticky keys) and that also gives u advantage to run it with 5x shift like normal sticky keys
@GalaxinTM
@GalaxinTM Жыл бұрын
but that'd require administrator privileges to do.
@TomTom-gx1sm
@TomTom-gx1sm Жыл бұрын
Similar to environment variable (order) hijacking on Linux, but exploiting a software that is there on default install. Great gift from Windows ! Windows > Linux!!1
@skystoyhunts7225
@skystoyhunts7225 Жыл бұрын
I've been using the updated version of Internet explorer for a while. Is it not safe to use? I think the update is called Microsoft edge.
@jkobain
@jkobain Жыл бұрын
04:04 - And this is because they wanted FAT12-compatible names, yes.
@jkobain
@jkobain Жыл бұрын
John, report these scammers as channels impersonating you. Please.
@TheMAZZTer
@TheMAZZTer Жыл бұрын
Hey John I dug deeper into this using Sysinternals' Process Monitor tool. It looks like Windows 11 requires the %SYSTEMROOT%\Registration folder and the absence causes this error. Copying it over resolves it but then you get another weird problem where the original rstrui app won't run and even requests elevation (?!?). However if you copy over the last file it is failing to load (c:\windows\System32\en-US strui.exe.mui) then it loads and runs properly in Windows 11. Of course that file doesn't apply if you're replacing the app with a different one; you will need to use a tool like Process Monitor to investigate failed file loads yourself (I set Result filter to is PATH NOT FOUND (or alternatively is not SUCCESS but that resulted in a bunch of junk messages) and Path filter to begins with my temporary folder path). One other thing I had to do was pass the shell: url directly to windows and not through IExplore for it to work; if I try using the original form with iexplore nothing happens after fixing the Registration issue. So: start shell:::3f6bc534-dfa1-4ab4-ae54-ef25a74e0107} This is just a case of setting up a test environment and leaving too many files out... just the DLL files from the single folder is not enough! Windows is more complex than that. I'm surprised Windows 10 shell objects work with that minimal setup. It is possible this error is due to more components are relying on the environment variable than in Windows 10, though that would be odd, as Microsoft's recommended best practice is to NOT use them as a reference for paths but to use SHGetKnownFolderPath API, IIRC. But clearly overriding the variable is working, so MS is using it here. This is because the paths for shell objects are stored in the registry, so there are no options except to use environment variables in the paths. You can open up HKEY_CLASSES_ROOT\CLSID\{3f6bc534-dfa1-4ab4-ae54-ef25a74e0107} yourself and take a peek at the definition for this shell object to see it does indeed use SYSTEMROOT. It's a very simple object that just runs the rstrui.exe app when invoked. If you're familiar with file type data in the registry the format is nearly identical. It's also worth noting IExplore has nothing to do with this. You can omit it entirely and just pass the shell: url directly to Windows for the same effect. In fact it reveals the original error was just given the title of the command line you were trying to launch... it was not coming from IE but from Windows. Though oddly enough if I add it back into my start command on Windows 11 rstrui won't launch. I think I'm done investigating this for now though.
@crinob1
@crinob1 Жыл бұрын
Awesome!!!
@Anilkushwah7201
@Anilkushwah7201 Жыл бұрын
Nice video 👍
@ellerionsnow3340
@ellerionsnow3340 Жыл бұрын
When you CD on windows, what is the % used for. Always been confused on that. Can you also CD directly to the path without that?
@ellerionsnow3340
@ellerionsnow3340 Жыл бұрын
@@Joomluh12 Ah thanks so much, so these are similar to Environment Variables on Linux.
@IamKyuTee
@IamKyuTee Жыл бұрын
Questions: Do you do giveaways of channel branded stickers? I am collecting all the channels I am subscribed to so that I can make a collage and frame it to put on my livingroom wall. If not do you have a store where I can buy it?
@fluidmind3629
@fluidmind3629 Жыл бұрын
can we make this attack via link ?
@ramseycharlie
@ramseycharlie Жыл бұрын
John how about a video on using "ChatGP" AI to write malware? I just saw a post about that.
@DiamondBroPlayz
@DiamondBroPlayz Жыл бұрын
You might wanna contact him directly, there’s a link to contact him in his description
@tombalvin6344
@tombalvin6344 Жыл бұрын
hey man can you hepp me with this audio file i have. i am being acousticly harrassed.
@surkewrasoul4711
@surkewrasoul4711 Жыл бұрын
A completely Irrelevant question, Anyone knows if John hammond managed to get his Windows Exploit from Offsec? Haven't been following he's videos in a long time.
@ElectricoGamez
@ElectricoGamez Жыл бұрын
Thank God IE went unsupported 6 months ago...
@dominicskywalker
@dominicskywalker Жыл бұрын
So essentially disable Internet Explorer on my Windows server?
@Stopinvadingmyhardware
@Stopinvadingmyhardware Жыл бұрын
Fix it Group
@Izzythemaker127
@Izzythemaker127 Жыл бұрын
Level of surprise when internet explorer is bad: -50
@moviezbuzz77
@moviezbuzz77 Жыл бұрын
Waiting for your new video
@CartoonPhreak
@CartoonPhreak Жыл бұрын
I use Google Chrome for Windows to download some music, games, software and videos
@CartoonPhreak
@CartoonPhreak Жыл бұрын
@@DaxyGamer Google Chrome is way more popular than Firefox because it protects your identity, personal information and brain while downloading torrents, music and KZfaq videos
@CesSanchez
@CesSanchez Жыл бұрын
Hi, mate, are you OK?
@dbanopsec4255
@dbanopsec4255 Жыл бұрын
good stuffs
@adamn777
@adamn777 Жыл бұрын
John, try calling out this CLSID ::{ED7BA470-8E54-465E-825C-99712043E01C}, BTW which energy drink is your favorite? Have you tried Alanis--Cosmic Stardust?
@abandonedaccount435
@abandonedaccount435 Жыл бұрын
Windows 7 user here Internet Explorer is still in my computer and Microsoft Stoped supporting it
@rsvv6828
@rsvv6828 Жыл бұрын
Huge thanks for guardio For sponsoring this video 😂😂😂😂😂😂😂😂😂 New poem from john
@amethystdene
@amethystdene Жыл бұрын
you can run it without using internet explorer, just remove iexplore from the start command, i tried it in my win11 main pc and it opened sys restore
@amethystdene
@amethystdene Жыл бұрын
@@CalebHammer608 No
@amethystdene
@amethystdene Жыл бұрын
@@CalebHammer608 you go tell him
@danielbri9665
@danielbri9665 Жыл бұрын
Man just ended his pc
@RiderOfMooses
@RiderOfMooses Жыл бұрын
Anyone else getting access denied?
@stupidoldgamer
@stupidoldgamer Жыл бұрын
If you haven't already uninstalld IE and cut ties from IE in windows since you should be using Edge now then this won't work.. Won't work for me anyway because IE is dead the only thing this will do is load edge and possibly brosw your local file system. 😛 You can't download things either so off you trot with your shenanigans.
@Dig_Duke_SFM
@Dig_Duke_SFM Жыл бұрын
"Internet explorer is the best to use for windows." Me: *uses firefox on linux*
@TechGamer64960
@TechGamer64960 Жыл бұрын
internet explorer more like internet exploiter aM I RIgHt?
@nvs-different-ideas
@nvs-different-ideas Жыл бұрын
in : echo %windir% echo %SYSTEMROOT% _________________________ out : C:\Windows C:\Windows
@prabingurung4844
@prabingurung4844 Жыл бұрын
Hey John, you on break ): ?
@ygjt76v0-----
@ygjt76v0----- Жыл бұрын
Windolsw
@bertramdollas7409
@bertramdollas7409 Жыл бұрын
i uninstall all games dosent work i re install everyting works btw i use internet explorer 11 and i basicly trust everything saying stuff about malware since my pc has survived 32 malwares at once
@fastcode8664
@fastcode8664 Жыл бұрын
So a bash script could be written to execute these commands and download a malware that could steal stored passwords into that custom system32 directory created by the bash script itself. The script could be timed in a manner that allows enough duration for the importion of dll files to the new system32 directory and the execution of malware using the iexplorer. However, undetectable malware could be downloaded and executed using a bash script only without the need for iexplorer.
@EmperorCheed
@EmperorCheed Жыл бұрын
Does anyone actually use Guardio? Is it worth it?
@nordgaren2358
@nordgaren2358 Жыл бұрын
Guardio actually detected the OBS Malware from a few videos ago, and defender did not.
@EmperorCheed
@EmperorCheed Жыл бұрын
@@nordgaren2358 Wow that's interesting thanks
@storymationpresents6106
@storymationpresents6106 Жыл бұрын
so hes the guy who runs jurassic park
@guilherme5094
@guilherme5094 Жыл бұрын
👍
@lukedavis436
@lukedavis436 Жыл бұрын
"stop stop!!.. He's allready dead!!! Z
@xemon5811
@xemon5811 Жыл бұрын
With this new scandal about TLauncher can you maybe chek how bad is that ?
@iskrassupercoolchannel
@iskrassupercoolchannel Жыл бұрын
hi
@janmbaez
@janmbaez Жыл бұрын
Thanks god i though i was going crazy looking at my logs
@LV6LV
@LV6LV Жыл бұрын
Or just open calc.exe shell:::{74E23A81-AFA8-4bbe-8EC0-B345EAEF5D1C}
@richardbest9287
@richardbest9287 Жыл бұрын
I have been getting hacked with this method since august 30+ computers, routers , cameras, all smart home devices from some group from China. They have me connected to a server as a client I cannot disconnect from. They are using winpe, winre, windows resume, efi memory tester and fwbootmgr for persistence. I can’t rewrite the bcdbackup or read it since it is written in another language and a partition of my hard drive will not show up since it is written in an older version of windows fat 16 format that allows the characters to go to 260 places. All of my hard drives, thumb drives, cd drives, efi and nvram have boot backup to keep it persistent. Dlls and other programs blocking all antivirus to show clean. If I do manage to fix a section there is a watchdog that will catch it and instantly reboot the computer. I’m working through recovery command prompt trying to get it all fixed.
@baeg1689
@baeg1689 Жыл бұрын
🗽♨
@sammo7877
@sammo7877 Жыл бұрын
mof balls 😅
@Guzguz28
@Guzguz28 Жыл бұрын
❤❤❤
@RealCyberCrime
@RealCyberCrime Жыл бұрын
Seriously, who is still using internet explorer?
@HK-sw3vi
@HK-sw3vi Жыл бұрын
every accounting firm
@RadioactiveBlueberry
@RadioactiveBlueberry Жыл бұрын
Most windows servers established a decade ago
@KaptanUfuk
@KaptanUfuk Жыл бұрын
internet explorer mı kaldı lao
@breadmachine_official
@breadmachine_official Жыл бұрын
hey!
@SumherShankal
@SumherShankal Жыл бұрын
Commented 🥰
@deepikayadav7023
@deepikayadav7023 Жыл бұрын
I'm interested in ethical hacking 🤗😍
@zeatoz
@zeatoz Жыл бұрын
the waffle house has found its newest host.
@DrannaMTaltMa
@DrannaMTaltMa Жыл бұрын
toothmarks YVFSNUFAannoxVbcYnvaandakxs PLEASE STOP
@aaryankumar7395
@aaryankumar7395 Жыл бұрын
16 th comment
@brighthades5968
@brighthades5968 Жыл бұрын
Comments: 4: ‬
@xBZZZZyt
@xBZZZZyt Жыл бұрын
:
@lolsyoff
@lolsyoff Жыл бұрын
The Waffle house has found its new host.
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked Жыл бұрын
First. :3
@vocus7634
@vocus7634 Жыл бұрын
First
@DGModdersxNoScOPe
@DGModdersxNoScOPe Жыл бұрын
do you smoke weed?
@Indians_are_p00p
@Indians_are_p00p Жыл бұрын
please stop using soy facial expressions on the covers
@johngoodbrake7056
@johngoodbrake7056 Жыл бұрын
Gawd dmmmtttt back to work I guess 🥲
Finding WEIRD Devices on the Public Internet
27:48
John Hammond
Рет қаралды 168 М.
PowerShell CRYPTOSTEALER through DNS
24:28
John Hammond
Рет қаралды 54 М.
路飞关冰箱怎么关不上#海贼王 #路飞
00:12
路飞与唐舞桐
Рет қаралды 4,1 МЛН
The World's Fastest Cleaners
00:35
MrBeast
Рет қаралды 132 МЛН
How To Choose Ramen Date Night 🍜
00:58
Jojo Sim
Рет қаралды 51 МЛН
Она Постояла За Себя! ❤️
00:25
Глеб Рандалайнен
Рет қаралды 4,8 МЛН
Where People Go When They Want to Hack You
34:40
CyberNews
Рет қаралды 121 М.
3 Things You Didn't Know about Windows Command Prompt
25:56
John Hammond
Рет қаралды 95 М.
Exploring Ransomware Builders
50:00
Cyber from the Frontlines
Рет қаралды 926
Filter Evasion in a REVERSE SHELL (no spaces!!)
29:11
John Hammond
Рет қаралды 39 М.
Yet Another Cybercrime Hacking Forum...
22:10
John Hammond
Рет қаралды 20 М.
Certified Penetration Testing Specialist! Chat with HackTheBox
28:14
Beware Malicious Chrome Extensions!
17:26
ThioJoe
Рет қаралды 127 М.
OpenAI’s GPT-4o: The Best AI Is Now Free!
9:14
Two Minute Papers
Рет қаралды 172 М.
you should be using PODMAN
10:39
John Hammond
Рет қаралды 83 М.
Malware Analysis & Threat Intel: UAC Bypasses
33:00
John Hammond
Рет қаралды 63 М.
路飞关冰箱怎么关不上#海贼王 #路飞
00:12
路飞与唐舞桐
Рет қаралды 4,1 МЛН