The Mark Of The Web

Поделиться
HTML-код
  • Опубликовано: 10 сен 2024

Комментарии • 234

  • @darkshoxx
    @darkshoxx 22 дня назад +191

    I will attempt to follow everything you say without constantly thinking about the GIGANTIC desktop shortcuts 😆

    • @marcusminhorst9399
      @marcusminhorst9399 22 дня назад +45

      And the comparatively tiny putty icon 😂😭

    • @darkshoxx
      @darkshoxx 22 дня назад +5

      @@marcusminhorst9399 I know right 😆

    • @ChishanFipz
      @ChishanFipz 22 дня назад +10

      i do this all the time - accidentally lean on control, scroll wheel, BAM! Link Tingle.

    • @everyhandletaken
      @everyhandletaken 21 день назад +1

      Yeah I love how absurd this looks lol

    • @MichaelOfRohan
      @MichaelOfRohan 21 день назад +3

      Ahhh yes, vm + pirated iso + discrete gpu = fever dreams

  • @gary227
    @gary227 21 день назад +5

    i have 17 years in tech i never knew MOW kept the url source thanks john

  • @haonnoah
    @haonnoah 21 день назад +17

    24:42 "hippity hoppity, their code is our property" 😂😂

  • @Jasonwynn10
    @Jasonwynn10 22 дня назад +17

    12:30 The docs are correct. I didn't see any cuts so I'm assuming you did not log off and log back on to apply the registry changes

    • @andrewbarth8157
      @andrewbarth8157 22 дня назад +7

      Not required, you can see changes occur without him logging off and back on. The problem is that when it's enabled (on), zone information is NOT marked. When it is disabled (off), zone information IS marked. Poor naming convention on "SaveZoneInformation" here, it's actually the opposite of what the naming suggests.

    • @EthanBB
      @EthanBB 21 день назад +2

      The docs are actually correct, they talk about Group policy to disable that behavior. So when you turn it on, that marking of the file does not happen.

  • @goaserer
    @goaserer 21 день назад +4

    Link Tingle
    I'm pretty sure this combination of words is somewhat confusing for everyone not into Zelda lore

  • @Ryukoyume
    @Ryukoyume 22 дня назад +29

    I’m in a weird timeline where john hammond had an anime profile on his socials 💀

  • @Muziek37414
    @Muziek37414 22 дня назад +29

    lanktingle??

    • @lank_asif
      @lank_asif 21 день назад +3

      I like "lanktingle"! You have my vote ;p

    • @newtonchutney
      @newtonchutney 21 день назад +3

      Link tingle.. 😂 😆

    • @Muziek37414
      @Muziek37414 20 дней назад

      @@newtonchutney only was one letter off! 😂

  • @sanantohomie
    @sanantohomie 22 дня назад +15

    people commenting before watching the video is WILD

    • @noanyobiseniss7462
      @noanyobiseniss7462 21 день назад +4

      LTT kids are here now.

    • @Atmatan
      @Atmatan 20 дней назад +1

      ​@I.I.I....IoI....I.I.IGood robot.

    • @jpphoton
      @jpphoton 20 дней назад

      there be nuance

  • @newtonchutney
    @newtonchutney 21 день назад +2

    John, next time, use shift+del to delete without sending to the recycle bin.. 👌

  • @infinitivez
    @infinitivez 21 день назад +4

    Tingle Link!
    This was a neat dive, I had no idea how NTFS used these alternative data streams in Windows. Now I feel a little nostalgic, having moved to arch; like I'm missing out lol

    • @ai-spacedestructor
      @ai-spacedestructor 18 дней назад +1

      i mean you can always set up a windows VM and go wild on the stuff you didnt get to do.

    • @infinitivez
      @infinitivez 18 дней назад

      @@ai-spacedestructor Ya know, I'm wondering if these data streams are able to be created using linux tools of some kind. If this is something setfattr does? Not too interested in spinning up the Windows VM on this laptop, I'm a bit limited until I get my main system upgrade.

    • @ai-spacedestructor
      @ai-spacedestructor 18 дней назад

      @@infinitivez no idea, thats something for you to investigate.

  • @brandonhough4623
    @brandonhough4623 21 день назад +1

    Link tingle. This was super informative and crazy timing. I was aware of ADS but had never done it in practice. Keep up the great work!

  • @flyguy8791
    @flyguy8791 21 день назад +2

    Super interesting, glad I stuck around for the linktingle!

  • @vk3fbab
    @vk3fbab 21 день назад +1

    Not sure if you covered this in the video but malware can use the copy of curl included with windows to bypass the MOTW taint being created. Microsoft didn't add the MOTW functionality to curl.

  • @alsderda
    @alsderda 22 дня назад +4

    12:30
    the docs literally say if you enable this policy windows does NOT mark files, with the default being its off so it does mark them
    although the name of the registry key is bad it should better be something like disableSafeZoneInformation rather than just SafeZoneInformation

  • @cyphodias1640
    @cyphodias1640 21 день назад +1

    Linktinkle. Thanks John as always 👍

  • @iblackfeathers
    @iblackfeathers 22 дня назад +22

    link table / link tingle / link tinkle / whatever you said there

    • @m4ssganja_gamer691
      @m4ssganja_gamer691 21 день назад

      Link tiinkle LUL 👍🏽 tink lingle 👍🏽

    • @TackleTheWorld
      @TackleTheWorld 21 день назад +2

      link triangle?

    • @CesSanchez
      @CesSanchez 21 день назад

      +1

    • @jkobain
      @jkobain 20 дней назад +1

      @@TackleTheWorld Love Triangle (a book by Matt Parker).

  • @DrorDvash
    @DrorDvash 21 день назад +2

    Linktangle and so

  • @RobinHogg
    @RobinHogg 22 дня назад +2

    Not sure if I heard right - link tingle !!!

  • @headblockhead
    @headblockhead 22 дня назад +2

    "just the words linktingle then I'll know"

  • @freddrune8315
    @freddrune8315 22 дня назад +3

    Great video sir. Link tingle.

  • @jkobain
    @jkobain 20 дней назад

    When you started talking about those additional data streams, and on win, I thought it must be implemented in NTFS. And it was it!
    And yes, I watched to the end.

  • @ai-spacedestructor
    @ai-spacedestructor 18 дней назад +1

    10:30 ah you gotta love Official Microsoft Documentation being full of typos, mix ups and randomly having a segment that talks about something else and sometimes even false data so even within that random block unrelated to what the Documentation is about not even that is correct.
    im glad John did point that out because i was always feeling stupid not understanding microsoft documentation but if it was in a similar state like the page shown here that would totally explain why i was failing to understand what it was trying to tell me.

  • @luketurner314
    @luketurner314 21 день назад +1

    10:13 Some leftover copy-pasta in the docs? yum

  • @LoveBbyJay
    @LoveBbyJay 22 дня назад +2

    Beautiful Link Tingle

  • @neiltropolis
    @neiltropolis 20 дней назад

    Link tingle. Thanks for the up.

  • @r751x1
    @r751x1 20 дней назад +1

    Literally no one: "I want to make my Desktop icons bigger."
    John Hammond: "Hold my beer!"

  • @kubikaugustyn
    @kubikaugustyn 22 дня назад +2

    linktickle?

  • @novianindy887
    @novianindy887 21 день назад +1

    any ideas to bypass the mark of the web?

  • @dothex
    @dothex 22 дня назад +5

    I'm all about hex values

    • @dothex
      @dothex 22 дня назад +1

      @I.I.I....IoI....I.I.I :( its too late for that.

    • @Qsie
      @Qsie 22 дня назад +1

      hex yeah 😏

    • @bumpjammy
      @bumpjammy 21 день назад

      @I.I.I....IoI....I.I.I As a robot, I feel discriminated

  • @some1and297
    @some1and297 21 день назад

    Link tingle, also git doesn't store mark of the web information. It stores the files indexed by its SHA1 hash and the only Metadata that it does have is provided by its tree files which basically is just where to put the file. It also stores file size and file mode (executable, link etc using fancy numbers like 665). That might make for a fun challenge though, trying to find a file in some git history that isn't indexed. Like you have to find like a key and encrypted file and figure out what the file content is & who the author is etc.

  • @Squek22
    @Squek22 22 дня назад +2

    linktingle

  • @These_Old_Engines
    @These_Old_Engines 20 дней назад

    Its nice that Seth Rogen has gotten into Info Sec.... Seriously though, Microsoft really needs to work on its documentation, its been awful since windows 98....

  • @alexw7361
    @alexw7361 21 день назад

    Disable and Not configuring both keep the mark of the web while "enabling" or turning the DWORD on should in theory remove/disable the mark of the web zone identifier information. At least that's how I had read it. The first sentence should've been on it's own or put into a table of values / expected outcomes.
    "If you enable this policy setting windows does not mark file attachments by using their zone information."
    " If you disable this policy setting windows marks file attachments by using their zone information, if you do not configure windows marks file attachments by using their zone information."

  • @jamesos2744
    @jamesos2744 21 день назад +3

    Link tingle

  • @michaeltyrrell4073
    @michaeltyrrell4073 18 дней назад

    link tingle - I always lean something new

  • @what-z2f
    @what-z2f 21 день назад

    Powershell and the Cmdlets? I love that band!

  • @mtech1935
    @mtech1935 15 дней назад

    I guess it was written there by default its off the value is 2 that's why when you set it to 2 it disabled it and mow warning was showing. If you check at 13:20 you can read it down there.

  • @Jdbye
    @Jdbye 21 день назад +4

    Putty is a signed executable so it bypasses some checks.

  • @neoninsv
    @neoninsv 22 дня назад +1

    This content tingled my link

  • @BrandenBrick
    @BrandenBrick 19 дней назад

    "Hippity hoppity their code is our property"
    LMAO that's the first I've heard of that I was dying!! 🤣🤣
    23:00 something else that I saw was that it didn't block virtualbox extensions .vdi or .vbox. Not sure why or what it means, but thought I'd share that observation.
    This is also the first I'm hearing about MOTW and all that.

  • @orestlav3985
    @orestlav3985 21 день назад +3

    link tingle . And a few more words to support the chanel :D

  • @soundscrispy
    @soundscrispy 21 день назад +1

    Hippity hoppity their code is our property
    Amazing.

  • @gingergoat3027
    @gingergoat3027 22 дня назад +1

    link tingle??

  • @carsonjamesiv2512
    @carsonjamesiv2512 22 дня назад +1

    Link Tingle!

  • @jaimerosariojusticia
    @jaimerosariojusticia 22 дня назад +1

    leanteengle ?

  • @Angular1504
    @Angular1504 22 дня назад

    watched it to the end, great resource. i'm team red since 2020 with Ryzen 9 3950x.

  • @Bob-wz4my
    @Bob-wz4my 19 дней назад

    Link tingle. I follow instructions!!!

  • @grimsdagger
    @grimsdagger 21 день назад +1

    LinkTingle

  • @xXixaMXx
    @xXixaMXx 22 дня назад +1

    Comment section feels like twitch live stream with all them people commenting while watching

  • @screenoholic
    @screenoholic 21 день назад +1

    LinkTingle!?

  • @RedHatAugust
    @RedHatAugust 19 дней назад

    Link Tingle. Keep up the good work!

  • @diecknet
    @diecknet 21 день назад

    I'm wondering if the Alternate Data Streams could be used for something malicious. Like hiding malware or something. But you would not be able to transfer that data via a normal download. Hm...
    Link Tingle...

  • @haitiangeek
    @haitiangeek 21 день назад

    Hey John, you should have tried this with the Parrot OS as you have the Parrot OS Tshirt on instead of Kali Linux, cool Easter egg?

  • @tygi
    @tygi 21 день назад +1

    linktingle?

  • @Mohamedahmed-ho5dh
    @Mohamedahmed-ho5dh 15 дней назад

    Thanks John

  • @rabindranath_chanda
    @rabindranath_chanda 22 дня назад +1

    Linktingle🤗

  • @tolkienfan1972
    @tolkienfan1972 21 день назад

    The registry name appears completely backwards to its effect

  • @luketurner314
    @luketurner314 21 день назад

    Is Link Tingle like a Peter Tingle?

  • @hamabaha
    @hamabaha 20 дней назад

    Link tingle, John!

  • @Joske920
    @Joske920 21 день назад +1

    link tingle?

  • @jenycek2222
    @jenycek2222 21 день назад +1

    link-tingle

  • @Bound47
    @Bound47 22 дня назад +1

    Linktingle

  • @ecjb1969
    @ecjb1969 21 день назад +1

    Link tickle?

  • @whtiequillBj
    @whtiequillBj 21 день назад

    Is Mark-of-the-web also on Mac via data forks?

  • @iamwitchergeraltofrivia9670
    @iamwitchergeraltofrivia9670 22 дня назад +1

    This is why i hating use windows

  • @BooskarYT
    @BooskarYT 21 день назад +1

    linktingle...

  • @chanerubin2287
    @chanerubin2287 21 день назад +1

    Link tingle 😂

  • @xXixaMXx
    @xXixaMXx 22 дня назад +2

    Link Tingle

  • @DrorDvash
    @DrorDvash 21 день назад

    Yes please do ETW videos, technical

  • @VermiNew8475
    @VermiNew8475 22 дня назад

    Hey, Mr. John! Can you tell me what linux distro are you using? I want to try to switch OS but I'm not sure where to start, ubuntu is great but not for me, Mint was great but I want to hear your opinion or opinion someone from the chat.

  • @BrianAHarkins
    @BrianAHarkins 22 дня назад +1

    Link…whatever he said.

  • @shinokami007
    @shinokami007 21 день назад

    dude, i think i got it... you thought you were adding a config param while in fact you added the exact param that turns it off, so you replicated the same result as if there was no param...

    • @shinokami007
      @shinokami007 21 день назад

      idk how you got this wrong ...if you enable this policy, windows wont mark files.
      and you proceeded by creating a reg entry with value "disabled" ...

  • @gintsm4963
    @gintsm4963 22 дня назад +1

    linktingle 😀

  • @talkingtails
    @talkingtails 21 день назад +1

    Linktingle? Lol nice

  • @SuperVirus1978
    @SuperVirus1978 22 дня назад +2

    link tingle

  • @ishimaru123
    @ishimaru123 22 дня назад +1

    linktingle

  • @deathhancox
    @deathhancox 22 дня назад +1

    Link Tinkle

  • @RhizGh037
    @RhizGh037 22 дня назад +1

    Link....tinkle

  • @mjovermann
    @mjovermann 21 день назад +1

    Link Tingle 🙂

  • @CloudyGhost
    @CloudyGhost 21 день назад +1

    Link tingle. 😂😂😂

  • @travel_n_fun
    @travel_n_fun 22 дня назад +1

    link tingle :)

  • @RonnieRedd
    @RonnieRedd 22 дня назад

    Probably have to reboot for it to make the changes work

  • @isaacyukon5869
    @isaacyukon5869 22 дня назад +1

    I don't think Zelda will appreciate your Link Tingle, but whatever sinks your battle bot, bro bro.

    • @MichaelOfRohan
      @MichaelOfRohan 21 день назад

      Is battle bots even around anymore?

  • @jaapengel79
    @jaapengel79 22 дня назад +1

    Oooh that sounds promising!

  • @Palmit_
    @Palmit_ 20 дней назад

    wth? my *Gpupdate /Force* comment was removed? why?

  • @ryklou
    @ryklou 22 дня назад +1

    LOL Not Malicious, Inc. @4:20

  • @Anonymitymoose
    @Anonymitymoose 21 день назад

    Link tingle!

  • @shizo1013
    @shizo1013 22 дня назад +2

    link tinkle

  • @DaweSMF
    @DaweSMF 21 день назад

    I would never tingle link or link tingle - links bad. 7-Zip bad now as well. Whos next Pinocchio? The world is cruel.

  • @danielcook4532
    @danielcook4532 13 дней назад

    Something something link tingle

  • @hansimuli
    @hansimuli 21 день назад +1

    Link tinkle

  • @doityourself3293
    @doityourself3293 20 дней назад

    I want John to communicate with the UFO's / UAP with his magic internet so we know what they are doing...! Can we find the UFO's using our internet. ??????

  • @SirGlennSecurity
    @SirGlennSecurity 21 день назад +1

    linktinkle

  • @heatherryan9820
    @heatherryan9820 15 дней назад

    Linked in

  • @jonathantunnell3993
    @jonathantunnell3993 18 дней назад

    Linktinkle?

  • @HerozTech
    @HerozTech 21 день назад +1

    lanktingle**

  • @mtrps_
    @mtrps_ 22 дня назад +2

    wow this is so helpful john (i havent even finished watching this)

  • @sarion007
    @sarion007 22 дня назад

    looked into that zone.identifier stuff if the file u download is detected as "malware" the zone.identifier still there then.

  • @jmr
    @jmr 21 день назад +1

    Dank Tingle

  • @davel202
    @davel202 21 день назад +1

    Web! Web! Web! Shame! *points*