Track a Target Using Canary Token Tracking Links [Tutorial]

Поделиться
HTML-код
  • Опубликовано: 24 авг 2024
  • How to Use Canary Tracking Token Links to Monitor Targets
    Full Tutorial: bit.ly/Ctoken
    Subscribe to Null Byte: goo.gl/J6wEnH
    Kody's Twitter: / kodykinzie
    For a hacker interested in phishing, being able to monitor whether the target took the bait is essential. On this episode of Cyber Weapons Lab, we'll show you how to use Canary token links to track how the links are interacted with and from where. You could mask these links using a URL shortener like Bitly or via a document such as a PDF. There are lots of avenues to explore.
    Follow Null Byte on:
    Twitter: / nullbytewht
    Flipboard: flip.it/3.Gf_0
    Weekly newsletter: eepurl.com/dE3Ovb

Комментарии • 213

  • @91stantheman
    @91stantheman 5 лет назад +85

    You should consider doing a video on inspecting links to see if there is anything malicious embedded.

    • @jaylils
      @jaylils 5 лет назад +10

      I concur!

  • @alberiton8966
    @alberiton8966 4 года назад +33

    Please never change bro, you just don’t know how these videos helped some of us get the knowledge which made us get employed. Thanks man

  • @kusum1179
    @kusum1179 5 лет назад +155

    You are SO UNDERRATED, bro.

    • @Yorsa
      @Yorsa 4 года назад +2

      no shit

    • @superdave5170
      @superdave5170 4 года назад +1

      2020-08-14T14:07:25Z

    • @big2neat586
      @big2neat586 3 года назад +3

      he likes it that way

    • @Shmancy_pants_69
      @Shmancy_pants_69 3 года назад +1

      Good that's why he hasn't been banned lol

    • @morozer62
      @morozer62 2 года назад

      Is it cuse eye contact is op

  • @SchoolforHackers
    @SchoolforHackers 5 лет назад +8

    Kudos to you Kody. Whatever they’re paying you, you deserve double.

  • @jeffstanley2972
    @jeffstanley2972 5 лет назад +5

    Null Byte Just wanted to say that all of your videos are very well done! You have an incredible knowledge of cyber operations! I have always been interested in cyber security and am taking some basic computer networking and programming and scripting courses at my university. Anyway, I just wanted to say that I enjoy watching your videos. Thank you for sharing your knowledge!

  • @Drakkofire
    @Drakkofire 5 лет назад +18

    That’s easy to make, I coded something similar to make a joke on my friends, but instead of being a blank page it redirected to google and my pasarell wasn’t registred on the browser’s history, also I mentioned that in a technicall level with wireshark captures and other tools how it is done to a private course and what information it uses from http headers.
    Cool video!

    • @Drakkofire
      @Drakkofire 5 лет назад

      Y3llowl4bs Hackers yeah but if you won’t learn how it works or have that satisfaction that you made it🙄😂

    • @whiskeyburns5230
      @whiskeyburns5230 4 года назад

      @@Drakkofire made my own text editor and now I want to kill myself

  • @raysy4500
    @raysy4500 5 лет назад

    Hi, just wanted to thank , Null Byte for all the great informative tutorials, just tested the pirate box in a raspberrypi 3 on one of your tutorials and it's working fine.

  • @MCHL_-jl2yx
    @MCHL_-jl2yx 4 года назад +1

    I thought i couldnt do anything in my life no more but i saw your video , thank you btw

  • @V4mpirella
    @V4mpirella 3 года назад

    Very interesting. Everyday I learn something new instead of watching music videos or movies.

  • @jlo4720
    @jlo4720 5 лет назад +9

    so every web apps that gives previews of links would work ? like Facebook messenger , whatsapp .....

    • @arielnaveh507
      @arielnaveh507 5 лет назад +3

      yeah but it will probably give you a location of one of thier proxies

    • @jlo4720
      @jlo4720 5 лет назад

      @@arielnaveh507 huh yeah interesting

    • @arielnaveh507
      @arielnaveh507 5 лет назад +2

      You can use it to log when they open or refresh the link

  • @edselarbasto766
    @edselarbasto766 5 лет назад +1

    Best educational channel. Please create more vids like this. Glad I found this channel.

  • @Ian-se5qe
    @Ian-se5qe 5 лет назад +1

    Got to say, you explain things so well. I really do enjoy watching your videos :-)

  • @pedroassuncao10
    @pedroassuncao10 5 лет назад +2

    I saw that we can edit the name of the word document ... the document is clean .. can we change the content inside?
    Great vid Kody ;)
    greetings from portugal

  • @danielnilsson5302
    @danielnilsson5302 5 лет назад +2

    is there a way to know if someone tracking you with canary tokens?

  • @dxlultra1020
    @dxlultra1020 5 лет назад +2

    I'm wondering how we would modify the response when Skype, Instagram, Messenger, etc request the preview for the website (change it to whatever we want for phishing, etc). Shoot that's some backend server stuff..time to fire up Python

  • @lewisrichardson6456
    @lewisrichardson6456 5 лет назад

    my best teacher ever

  • @netbin
    @netbin 5 лет назад +2

    what about youtube? My friend youtuber WPEagle having problem with some botnet, as soon as he upload something to the youtube, bot immediately dislikes his videos, is there a way to exfiltrate that bot via canary token API and shut down that DLbotnet?

  • @Nerzhina
    @Nerzhina 5 лет назад +1

    Interesting video. Great info for finding website vulnerabilities.

  • @CodeXND
    @CodeXND 5 лет назад +1

    what's the reason of blurring the time?

  • @bitchleepringles2214
    @bitchleepringles2214 4 года назад +1

    ipod and ipad are read as mac

  • @francescopresta9570
    @francescopresta9570 5 лет назад +1

    Great job Kody!

  • @kingslayer9097
    @kingslayer9097 5 лет назад +1

    Can we just change the browser resolution to change device info leak, instead of using addon?

  • @michalmikulasi5193
    @michalmikulasi5193 5 лет назад +1

    is there a way to track someones complete address? not just city or country, but possibly even street name? or at least smaller area? Thank you for the knowledge

    • @julius8441
      @julius8441 5 лет назад

      Nope

    • @julius8441
      @julius8441 5 лет назад

      But you can get close, but it's not possible to get the exact location of an IP.

  • @randomrandom7878
    @randomrandom7878 5 лет назад +1

    Sir can you make a video about a mobile versions of your tutorials using android applications

  • @AkalixYasuo
    @AkalixYasuo 5 лет назад +3

    Like if he’s the best RUclips teacher

  • @deusvult4678
    @deusvult4678 5 лет назад +1

    So how is that different from a php code uploaded to a host web ?

  • @majdps995
    @majdps995 5 лет назад

    Basically the an IP logger but with a fancy name.
    * WhatsApp used to show users IP instead of the server's because thumbnail processing is/was (idk if it still) client-side

  • @redpilledpatriot6868
    @redpilledpatriot6868 4 года назад

    I get this error "This page didn't load Google Maps correctly. See the JavaScript console for technical details." after clicking History. To get to the JavaScript console in Microsoft Edge, click on the three black dots in the top right hand corner just below the exit button for the web browser, hover your cursor over the "More Tools" option, then click "Developer Tools". There's also keyboard shortcuts if you don't want to take the long way, Microsoft Edges keyboard shortcut is F12 and Google chromes keyboard shortcut is Ctrl+Shift+I.

  • @feiwoza
    @feiwoza 5 лет назад +1

    Awesome tutorial !!

  • @jaimecabrera3242
    @jaimecabrera3242 4 года назад

    I tied to run it on my iPad and it says that google maps didn’t load correctly. See javaScrip ? Great tool hope you help to solve my problem

  • @khue6377
    @khue6377 5 лет назад +1

    I love this channel ! Thank you for the great videos ...it would be really nice if you help us to get the right environment for our system ...( mac off course) I am usually try to follow but quite often unsuccessful because don’t have the right software.... thank you ....

  • @NicholasMaietta
    @NicholasMaietta 5 лет назад +2

    I've been doing this since the early 2000's.

    • @raulalejandromunozaraya3878
      @raulalejandromunozaraya3878 5 лет назад

      Good for you

    • @NullByteWHT
      @NullByteWHT  5 лет назад +7

      Okay! Here is a tiny trumpet just for you.
      🎺
      I am assuming that is what you were requesting with your comment.

  • @minnermin
    @minnermin 5 лет назад +3

    Everything being so easily manipulated via anything with a cpu gives me an ever intensifying paranoia of being watched

  • @3N18AKPzmGOsBgWKH
    @3N18AKPzmGOsBgWKH 5 лет назад +4

    I just LOVE your videos. Keep up the super awesome work.
    However... Let's say you wanted to track someone you were suspicious of. How could one do this?
    I've for example used these kinds of tricks. A website I've used a lot is grabbify which you might be aware of.
    But once i might have their IP, it's also possible to geo-locate them to see which country and hopefully city they might be from. IF i want to expand myself even more, how would i do this?
    I know like... Talking to someone who might know this person might give off a name and such which will help out with the search, especially as most people seem to have social medias such as facebook, BUT what if you don't have someone close to the person you want to find. How does one search someone up even further? Would be super cool if you know any neat and fun tricks.
    Have an awesome day, Null Byte! Your videos actually helps me a lot in school and with my studies (IT-Security and might continue studying towards IT-Forensics)

  • @Fury1757
    @Fury1757 5 лет назад +1

    A canary token is kind of like an IP logger, right?

  • @themonkeyminds7252
    @themonkeyminds7252 5 лет назад +1

    Respected sir ,
    I want to send screen shots of public WiFi Registration page
    To use public WiFi we need to authenticate email I'd as well as mobile phone number (Indian) so that they will send us otp .
    After verifying we get 100 mb for 30 minutes . After the data has been used we can't use more data.
    Is there any way to get data more than the limits (time &data)?
    Hope u will give some solution.
    Awaiting for your response.
    Thankyou
    Peace:)

  • @al8479
    @al8479 5 лет назад

    Any more channels like this?

  • @circuitmasters5258
    @circuitmasters5258 5 лет назад +1

    Nb already knew about it brother.....late....i use it daily....

  • @jonathanvelazquez7176
    @jonathanvelazquez7176 5 лет назад +1

    You can also use grabbify which dose the same and you can edit the link to not make it suspicious . However using a VPN will block these types of things

    • @adnjordan
      @adnjordan 5 лет назад +1

      So if the attacker scan the IP adress generated by the VPN to find vulnerabilities on my system I have nothing to worry about ? Because it dosn't dislpay my real IP adress am i right ?

    • @jonathanvelazquez7176
      @jonathanvelazquez7176 5 лет назад +1

      Jordan correct but a skilled hacker can reverse engineer the VPN IP adress but unless its a script kitty or somone who knows nothing then there's nothing to worry about

    • @michalmikulasi5193
      @michalmikulasi5193 5 лет назад

      @@jonathanvelazquez7176 how do you reverse engineer proxy like VPN? I believe its not really possible unless you are somewhere inside server

  • @Hyde-Jahf
    @Hyde-Jahf 5 лет назад

    What information can this provide that standard web logs can't?

  • @adens4665
    @adens4665 5 лет назад

    I am from indonesia . I like your videos.. all you videoss😊

  • @pratheeshm400
    @pratheeshm400 Год назад

    Is this exact GPS location?

  • @staidd
    @staidd 4 года назад

    There should be a chrome exstension which blocks you from visiting ip loggers.

  • @sebastiancioek5970
    @sebastiancioek5970 4 года назад

    Thanks, Great tutorials!

  • @nematsaadati4934
    @nematsaadati4934 5 лет назад

    hello
    can you make a video about fixing the apt-get on kali 2018.4

  • @ne12bot94
    @ne12bot94 5 лет назад

    Can you still be tracked if you used ip address change or location changer

  • @grahamelliott9506
    @grahamelliott9506 3 года назад

    'known tor exit node'
    so, i'm guessing that if we can keep cycling the tor circuits , when we find not-known and are using tor we may have a rogue tor exit node? just an outside the box idea :)

  • @JonTheDeveloper
    @JonTheDeveloper 3 года назад

    Excellent video! Question: Will this work if it is no longer in the view of the user opening the chat? Ex. It is an older message in the chat so the user doesn't technically view the link but it's still in the chat

  • @thelebbies
    @thelebbies 5 лет назад +1

    This was awesome!!!

  • @rajasekharreddy7977
    @rajasekharreddy7977 3 года назад

    Great video bro.

  • @TOn-fx2gr
    @TOn-fx2gr 5 лет назад +1

    It doesnt give the ip ?

  • @bhaveshjain2402
    @bhaveshjain2402 5 лет назад

    I am not able to see the incident map on canary tokens please help.

  • @ziadlemeurs4483
    @ziadlemeurs4483 5 лет назад

    You are the best, keep going

  • @Xero-oz1tp
    @Xero-oz1tp Год назад

    it works

  • @hybrid3684
    @hybrid3684 Год назад

    wait what do i have to write in the gmail thing ?
    my email bc i wont

  • @audit2901
    @audit2901 5 лет назад +1

    I can't see the map, why?

  • @Elliott2001
    @Elliott2001 5 лет назад

    I dont get the map when looking at the alert any suggestions?

  • @GDubs13
    @GDubs13 5 лет назад

    What is the name of the user agent that you use? Awesome channel!

  • @def5100
    @def5100 5 лет назад

    If you paste the link in FB Messenger you will also see how many different bots click on the link and 1 "Non-Bot" to make a preview

  • @MrChrisskilton
    @MrChrisskilton 4 года назад

    Looks like Slack is making a request to retrieve the content-length header.

  • @harrydamour7564
    @harrydamour7564 5 лет назад +2

    My friend 🙋‍♂️

  • @BootyClaimer
    @BootyClaimer 4 года назад

    I bet 10 bill nobody can beat you in a staring contest

  • @JNET_Reloaded
    @JNET_Reloaded 3 года назад

    where do i signup on there site im trying to login but dont have an account?

  • @TOn-fx2gr
    @TOn-fx2gr 5 лет назад +1

    I want to know. How this tool work how its capable of doing this
    Where i should look ??

    • @kingslayer9097
      @kingslayer9097 5 лет назад

      The webpage code inside the link you create, if you mean Canary tokens tool :)

    • @TOn-fx2gr
      @TOn-fx2gr 5 лет назад

      I mean to try write the code my self or at least read it may be its on githube

    • @kingslayer9097
      @kingslayer9097 5 лет назад

      @@TOn-fx2gr I think there was a post on this how to do it on the website - wonderhowto.com

    • @derekroberts1693
      @derekroberts1693 5 лет назад

      If you have your own server just create a link to your server and then use PHP to look at the user agent string and other $_SERVER vars whenever someone visits the link you created.

  • @L.Parisi
    @L.Parisi 5 лет назад

    well, pdf, word and folder browsing ones don't work for me, maybe i have to wait half an hour? let's see...

  • @youtubeguy1141
    @youtubeguy1141 5 лет назад +1

    i liked before i watch :)

  • @sinsofyourpast
    @sinsofyourpast 4 года назад

    I would love a video on how to back up or clone your kali linux install so you can move it to another computer without going through the hassle of reinstalling EVERYTHING. please and thank you.

    • @NullByteWHT
      @NullByteWHT  4 года назад

      Good idea Jason Malone, I've added it to the list of video ideas.

  • @themineofmind2431
    @themineofmind2431 5 лет назад +1

    Hello again friend as always tugh stuff u shoot that from the hip bro

  • @habibizerak9567
    @habibizerak9567 5 лет назад

    ins this token works in facebook messanger to send it and tack him him without clicking on it?

  • @joemckibbin2062
    @joemckibbin2062 4 года назад

    When he says track dose he mean location or cyber activity

  • @arbindhidang4198
    @arbindhidang4198 4 года назад +1

    Gps locaton is not accurate, it shows 1000km difference

    • @Theinatoriinator
      @Theinatoriinator 4 года назад

      its not gps its ip and true ipv6 is a location tracking downgrade from ipv4

  • @ninadshetty5702
    @ninadshetty5702 2 года назад

    why am i not getting the map......someone plss help mee😭😭

  • @SMAKIEVISUALMEDIA
    @SMAKIEVISUALMEDIA 5 лет назад

    Mine don't give me accurate resultant
    Am using Firefox

  • @Shmancy_pants_69
    @Shmancy_pants_69 3 года назад

    So how do we take it down....

  • @sgv-1613
    @sgv-1613 2 года назад

    yo i need help i clicked a discord link for nitro and my friend saying it’s probably a token logger but i don’t know what to do in scared i did it on my phone idk what to do

  • @gadigehemanthkumar8510
    @gadigehemanthkumar8510 3 года назад

    sir i tried this but google map is not loading what can i do

  • @saurrav3801
    @saurrav3801 5 лет назад

    Bro please help me......I want to learn python for ethical hacking and tool making......Is they any video or books u know about....then pls reply

  • @jonathanharvey1900
    @jonathanharvey1900 4 года назад

    Just stumbled upon Canary Tokens today and tested it out. I have a question though. When the link is clicked, it shows my public PAT IP. Does anyone know how to set this up so it will report on the internal IP, assuming someone on my network is accessing the file?

    • @NullByteWHT
      @NullByteWHT  4 года назад

      I don't know how to set that up. You might also want to checkout Grabify: nulb.app/x4jjq

  • @tech-n-moe3248
    @tech-n-moe3248 5 лет назад +1

    What if I share it on WhatsApp , and your videos are the best!

    • @austinwolfe7295
      @austinwolfe7295 5 лет назад

      Its owned by Facebook. That should answer your question

  • @thepracticalhowtohomebrewman
    @thepracticalhowtohomebrewman 3 года назад

    So this just shows local city or town not gps location of phone.

  • @rujin_x9842
    @rujin_x9842 2 года назад

    he got my adrease

  • @yunokawaii1772
    @yunokawaii1772 5 лет назад +1

    Sweet Video Bro :D Give Tut on how to create an image of this canarytokens pls :3

  • @barresoft
    @barresoft 5 лет назад

    faaaa que rico tip! el servicio VPN tiene servidor uruguayo?

  • @mohammadahmed4659
    @mohammadahmed4659 5 лет назад

    it is work with me but i can't see the map !!

  • @NarutoUzumaki-vm8ko
    @NarutoUzumaki-vm8ko 2 года назад

    If i use vpn!can it track my location & ip also???

  • @marvinbrooks7050
    @marvinbrooks7050 4 года назад

    Facts

  • @stanislavsmetanin1307
    @stanislavsmetanin1307 3 года назад

    Very useful)) thanks 👍

  • @outlow84
    @outlow84 5 лет назад +1

    Good amico mio

  • @nsjsjdjsbcncmfmfm9830
    @nsjsjdjsbcncmfmfm9830 3 года назад

    yo so does anyone have a idea of how to trace someone’s exact location over snap chat or just how I can get info on them

  • @potatoeguy3571
    @potatoeguy3571 7 месяцев назад

    bro doxxed himself

  • @carleparwa6481
    @carleparwa6481 5 лет назад +1

    Bro can you do tuturials in UserLAnd -Kali linux? I'm a newbie pls

  • @vinayk3839
    @vinayk3839 5 лет назад +1

    Hii Bro....
    Make a video on how to be fully anonymous on internet please

    • @adnjordan
      @adnjordan 5 лет назад

      Don't think its possible. You can be 99.99% but never fully anonymous in my opinion . There's always a risk to get caught

    • @vinayk3839
      @vinayk3839 5 лет назад

      @@adnjordan So what max we can do from our side to do so

    • @michalmikulasi5193
      @michalmikulasi5193 5 лет назад

      @@vinayk3839 well, linux things like anonsurf, proxychains should be the absolute best one can do. Then vpn is very helpful if you are torrenting, and tor + duckduckgo.com is a good, free combination if you want to find something without your isp knowing. and never use Tor to download torrents

  • @riseagain4973
    @riseagain4973 3 года назад

    it tracks the location of the service provider not you. But anyway, at least it get the right country and city

  • @SandeshKarumuri
    @SandeshKarumuri 5 лет назад

    I'm not getting map there

  • @carlosleon8026
    @carlosleon8026 3 года назад

    How can I get an exact address?

  • @sarundayo
    @sarundayo 5 лет назад

    Great vid!
    VPN provider?

  • @spetsnazrussia2446
    @spetsnazrussia2446 5 лет назад

    Mixed with grabify.

  • @baboballi2159
    @baboballi2159 5 лет назад

    thanks bro :D

  • @Shorts_creator9511
    @Shorts_creator9511 4 года назад

    Hlo sir,
    It shows victims public ip.... If we want private ip of victim then what we have to do??
    Reply pls sir...

    • @NullByteWHT
      @NullByteWHT  4 года назад

      I don't quite understand the question. By private IP you mean the local IP? You would need to gain access through the public IP to the network then scan the local network.

    • @Shorts_creator9511
      @Shorts_creator9511 4 года назад

      @@NullByteWHT sir my question is... It is possible to grab the local ip address of any victim..

  • @zardos7016
    @zardos7016 5 лет назад

    do a video on how to get into CCTV cameras please

    • @CrypticConsole
      @CrypticConsole 5 лет назад

      Most cameras use http to transmit the requests so use a man in the middle attack to capture the frames of the feed