Hacking (redacted) PUBLIC WiFi with a Raspberry Pi and Kali Linux

Поделиться
HTML-код
  • Опубликовано: 21 ноя 2024

Комментарии • 2,5 тыс.

  • @NetworkChuck
    @NetworkChuck  5 лет назад +216

    the Network Engineer tools I use:
    WAN Killer: bit.ly/WANkiller
    IP Address Scanner: bit.ly/ipscansw
    Network Device Scanner: bit.ly/netdevicescanner
    Wifi Heat Map: bit.ly/wifiheatmapsw
    Wifi Analyzer: bit.ly/wifianalyzersw
    SolarWinds NPM: bit.ly/netperfmon
    GET NORDVPN: nordvpn.org/networkchuck
    USE COUPON CODE: networkchuck
    USE THE CODE SO YOU CAN GET 75% off 3-year plan + 1 month free.
    🔥Become a 10x Engineer🔥
    Join NetworkChuck: bit.ly/2XPaF7u
    Need help? Join the community: bit.ly/nc-discord

    • @bm7752
      @bm7752 5 лет назад +5

      hey check are you at Cisco impact in Los Vegas this week?

    • @NetworkChuck
      @NetworkChuck  5 лет назад +8

      @@bm7752 Naw, chillin' with my new baby. Heard it's going to be fun though!

    • @salnaggar
      @salnaggar 5 лет назад

      we need the hostapd.conf data & i have no idea where the hell you found udhcpd tool??

    • @bm7752
      @bm7752 5 лет назад +1

      Man, I'm happy for you Chuck! Hopefully you'll come through next year! Cheers

    • @xeon8566
      @xeon8566 5 лет назад +7

      Hey don’t use nord It got hacked into 2 times

  • @Nico-wr6tz
    @Nico-wr6tz 5 лет назад +276

    I've spent so much time in coffeeshops working on uni work, and honestly only a year ago I started to understand how easy is to see what people are doing on their laptops... just stand behind them.

    • @NetworkChuck
      @NetworkChuck  5 лет назад +44

      too true.

    • @francinha
      @francinha 2 года назад +30

      That is called shoulder surfing.

    • @alaric5
      @alaric5 2 года назад +6

      @@francinha Hahahaha I was just gonna comment that when I saw their comment because I've been studying for my Security+

    • @sidmovich
      @sidmovich Год назад +1

      Damn this method sucks, i got arested

  • @benjaminmathew289
    @benjaminmathew289 5 лет назад +1476

    he protecc
    he atacc
    but most importantly
    he teach his daughter how to hacc

  • @doooouge1136
    @doooouge1136 5 лет назад +1945

    If you ever see someone with a Raspberry Pi at Starbucks turn off your Wi-Fi

    • @c1ph3rpunk
      @c1ph3rpunk 5 лет назад +130

      You won’t see mine.

    • @dvdcd
      @dvdcd 5 лет назад +86

      You can put kali linux on anything, not just pis

    • @doooouge1136
      @doooouge1136 5 лет назад +246

      ​@Dvdcd Well then if you ever see someone with an Anonymous mask turn off your Wi-Fi

    • @DataLog
      @DataLog 5 лет назад +50

      Rasberry Pi is unnecessary for this. You can setup fake network with your laptop or cellphone.

    • @MichaelLeichtML
      @MichaelLeichtML 5 лет назад +25

      If you ever see someone with that much gear showing up in a starbucks just call the cops on their asses and have them explain everything while trying to not get shot or beaten up. But seriously, I am amazed to see how little everyone cares, there are videos of people bringing most of their office (including desktop PCs)..

  • @harl3quinn
    @harl3quinn 3 года назад +46

    "I will get you, and my daughters will too." is probably the scariest thing you could hear from a hacker.

  • @iamjjohnny
    @iamjjohnny 5 лет назад +331

    The funniest thing is that NordVPN has been hacked

    • @Swede_4_More_Years
      @Swede_4_More_Years 5 лет назад +39

      And they didnt tell their customers...

    • @EvanOttinger
      @EvanOttinger 5 лет назад +17

      I'm more concerned with the lack of responsible disclosure to their customers after the breach was discovered.

    • @ExarchGaming
      @ExarchGaming 4 года назад +11

      The hack wasn't anything really noteworthy, what was noteworthy though is that they didn't disclose it to their customers and to the public for an entire year.
      The hack itself was done from the inside if I recall(from one of their server partners?), and nothing important such as user information or sensitive data was exposed.

    • @PineappleJamYT
      @PineappleJamYT 4 года назад

      @@Swede_4_More_Years ... oof

    • @srilankaghost5225
      @srilankaghost5225 4 года назад +1

      @@ExarchGaming do you know that so many nordvpn accounts are there to buy for cheap. All are hacked. Their security is the worst

  • @herald1953
    @herald1953 5 лет назад +410

    "i basically own her life now" hacking sounds like marriage at this point

    • @AngelCintiaRockgirl
      @AngelCintiaRockgirl 5 лет назад +7

      Herald Yes, any fun is always ruined by marriage.

    • @crowvizion9588
      @crowvizion9588 4 года назад

      Cintia I can definitely vouch for that

    • @bobbob1278
      @bobbob1278 4 года назад +3

      @@AngelCintiaRockgirl My wife and I have been married for about 11 years now but we still act like we got married a few months ago.

    • @Nadd684
      @Nadd684 4 года назад

      it was funny XD

  • @BitterValentines
    @BitterValentines 5 лет назад +825

    Even my toilet runs a VPN, trust no one

    • @NetworkChuck
      @NetworkChuck  5 лет назад +146

      Smart. Protection where you’re most vulnerable.

    • @juddlentz1115
      @juddlentz1115 5 лет назад +24

      @@NetworkChuck protect yer sh1t :)

    • @LittleJacob1985
      @LittleJacob1985 5 лет назад +16

      Go even further don't sh1t at all :] Don't give hackers a chance.

    • @rehoboth_farm
      @rehoboth_farm 5 лет назад +5

      That's not all that runs on your toilet.

    • @atanki5682
      @atanki5682 5 лет назад +2

      @@rehoboth_farm lolll

  • @craighames6282
    @craighames6282 5 лет назад +367

    "Hacking"...........The New Family Activity!

    • @codeplug756
      @codeplug756 5 лет назад +1

      Hacking is fuck with code just tryng 1 million times of click

    • @cyberpunisher8652
      @cyberpunisher8652 5 лет назад

      Nothing wrong with that

  • @sr.oskar_alhos
    @sr.oskar_alhos 3 года назад +10

    1:14 - the attacker is hiddenly right behind the target and and very well disguised ;)

  • @krizsan0596
    @krizsan0596 4 года назад +9

    That was the smoothest sponsor segment I have ever seen

  • @DarkbaseTTV
    @DarkbaseTTV 5 лет назад +891

    So essentially you were hacking wife-i

    • @Lil_mar00
      @Lil_mar00 5 лет назад +14

      niceeeeeeeeeeeeeeeeeeeeeeeeeeeee

    • @jeinnerabdel
      @jeinnerabdel 5 лет назад +18

      Let me show you the door, handsome person...

    • @sillybytes
      @sillybytes 5 лет назад +3

      FBI wants to know your location

    • @XanderPetty
      @XanderPetty 5 лет назад +3

      Every comment from here down is gold 😂

    • @adrienrozenbaum814
      @adrienrozenbaum814 5 лет назад +1

      No "essentially" he is showing you a commercial about NORDvpn!!!!!!

  • @Star88701
    @Star88701 5 лет назад +55

    I love the fact that your getting your daughters exposed to hobby electronics and even more so, Linux. I wish my parents had, imagine how much I would know today with almost 20 more years of experience. So props to you on that.
    Evil twin AP's are pretty nasty, you could even send deauth packets to attempt to force them to reconnect to the rogue AP.

  • @hiveintelligence5642
    @hiveintelligence5642 5 лет назад +166

    That is a bold statement:"The MAC Address will never change!". ;D

    • @NetworkChuck
      @NetworkChuck  5 лет назад +40

      I should have said the “burned in address” will never change. But ya know, gotta keep it simple.

    • @MrARM
      @MrARM 5 лет назад +3

      @@blisphul8084 Android 10 also supports random macs too, by default

    • @nickstrauser1228
      @nickstrauser1228 5 лет назад +11

      $ ifconfig eth0 down
      $ macchanger -r eth0
      $ ifconfig eth0 up

    • @baileyharrison1030
      @baileyharrison1030 5 лет назад +1

      Nick Strauser
      What sort of Linux distribution still uses eth0, eth1 etc? For years I’ve only seen random names like enp0s1 or ens33

    • @foty8679
      @foty8679 5 лет назад +2

      @@baileyharrison1030 Linux Kali does

  • @rhueoflandorin
    @rhueoflandorin 5 лет назад +70

    a VPN by its nature is a man in the middle. :P
    plot twist.

    • @ligmaballs3635
      @ligmaballs3635 3 года назад

      **hacker__virious* on IG is the best 💯✔️✔️🎗...

  • @qhouseproductions8423
    @qhouseproductions8423 4 года назад +95

    “I want you to be scared of public wifi”
    *laughs in cellular data*

    • @4kGambit
      @4kGambit 3 года назад +2

      😂😂

    • @ligmaballs3635
      @ligmaballs3635 3 года назад

      **hacker__virious* on IG is the best 💯✔️✔️🎗...

  • @GianlucaSegato
    @GianlucaSegato 5 лет назад +102

    The first attack doesn’t make any sense in the real world. TSL/SSL protects from DNS swapping, since it both encrypts the connection as well as guarantees the identity of the website you’re connecting to. Any browser checks that, you can actually see Safari doing the control in the video at 7:08. You don’t own anything, and a VPN is necessary only in the context of a HTTP transaction (which is more and more infrequent) instead of HTTPs

    • @albertocrescini2076
      @albertocrescini2076 5 лет назад +1

      Gianluca Segato puoi comunque vedere quali siti l’host visita. Se ci fai caso in tutti gli attacchi viene identificato il sito come “non sicuro” per via dello swap

    • @GianlucaSegato
      @GianlucaSegato 5 лет назад +2

      @@albertocrescini2076 fair point! credo tu possa vedere solamente l'host che il DNS ha risolto, e non il full path (mi sa, dovrei controllare), ma poco cambia: sicuramente puoi essere spiato quantomeno a livello di metadata (cosa visiti e per quanto).
      Però è impossibile fare full ownership come nel video, che francamente è misleading al limite del disonesto

    • @foobars3816
      @foobars3816 5 лет назад +8

      @@GianlucaSegato & Alberto Yeah you can only see the domain as the dns request isn't encrypted. You can clearly see in the video that the user is clicking through the obvious warnings in their browser and this isn't even mentioned which is quite shit.

    • @LtdJorge
      @LtdJorge 5 лет назад +5

      And if you are using DNS over HTTPS, DNS requests can't be intercepted.

    • @foobars3816
      @foobars3816 5 лет назад

      @@LtdJorge Heh Yeah I just learnt about that a few hours ago thanks to the UK government complaining about it being in Firefox.

  • @aitchpea6011
    @aitchpea6011 5 лет назад +149

    One minute in: "I wonder what VPN this is going to be an advert for?"
    Two minutes in: "Oh, it's nordVPN."

    • @cyberpunisher8652
      @cyberpunisher8652 5 лет назад +2

      Of course it’s nord

    • @StoneColdMalone
      @StoneColdMalone 5 лет назад +2

      @@cyberpunisher8652 Sounds like Nord advertises a lot, but are there any good?

    • @cyberpunisher8652
      @cyberpunisher8652 5 лет назад +1

      @@StoneColdMalone Not my personal favourite but i think it gets the job done. But its definitely over advertised. if I were you I would look for an alternative.

    • @Chris-B-Chicken
      @Chris-B-Chicken 5 лет назад +3

      @@cyberpunisher8652 Express VPN dont save logs - other than nord :)

    • @itstimeforafuckingcrusade
      @itstimeforafuckingcrusade 5 лет назад

      @@cyberpunisher8652 what's your favorite then?

  • @realchrishawkes
    @realchrishawkes 5 лет назад +103

    Nice one bro

    • @NetworkChuck
      @NetworkChuck  5 лет назад +12

      Thanks!

    • @scooptopus8150
      @scooptopus8150 4 года назад

      Thanks!

    • @scooptopus8150
      @scooptopus8150 4 года назад

      @Elizabeth da lezbo bro what’s ur problem?

    • @b07x
      @b07x 3 года назад +1

      airmon-ng
      airodump-ng
      aireplay-ng
      aircrack-ng
      So many WiFi hacking tools!!

    • @b07x
      @b07x 3 года назад

      @@daghanabi airmon-ng start wlan0

  • @trevorswartz1559
    @trevorswartz1559 4 года назад +30

    Just came across this channel and I absolutely love it. Extremely informative and entertaining. Also phenomenal job describing things very precisely with your diagrams. Thank you so much man. Absolutely subscribed and enjoyed your video.

  • @GetCTOwned
    @GetCTOwned 5 лет назад +11

    Great video highlighting network security awareness! No one is safe relying on public Wifi. Take care of your own security.

  • @DaPurpleJ
    @DaPurpleJ 5 лет назад +40

    watched 30 seconds and i got the feeling that this could be sponsored content...

    • @scooptopus8150
      @scooptopus8150 4 года назад

      DaPurple J stfu nerd

    • @DaPurpleJ
      @DaPurpleJ 4 года назад

      you should get a computer, then come @ me thanks.

    • @scooptopus8150
      @scooptopus8150 4 года назад

      DaPurple J I’m getting a kali Linux laptop soon dumb nerd

    • @0day490
      @0day490 3 года назад

      @@scooptopus8150 yo chill

  • @honkhonk165
    @honkhonk165 5 лет назад +701

    While I respect what you're doing, this video is super misleading for the sake of a commercial.
    In the video, your wife had to agree to use the website despite the fact the SSL certificate was invalid. Something you have to dig down into the error page to do, something the tech illiterate would never be able to do, and something the literate would never do in public.
    Additionally, you said you could get her passwords using additional tools, as if this is an effortless thing.
    Even aside from the error page, if the website the user is using, uses an SSL certificate, this is not trivial.
    That's not to say you won't get some people, but it's not even close to as easy as you are presenting in this video for the sake of a sales pitch.
    The real "hack" of this video is the unethical life hack of making people scared to use public WiFi in order to funnel money to your affiliate link.

    • @varx0484
      @varx0484 5 лет назад +70

      I agree with everything said here. The overall message of this video is false. I'd expect someone like chuck to not shove something so useless down our throats for money...

    • @honkhonk165
      @honkhonk165 5 лет назад +37

      @@H12-q7x I mean, I am a software engineer with 15 years in the field. I put myself through college with white hat and black hat tactics back in the day. I am the expert to learn from. I happened on this video because I'm a raspberry pi enthusiast, and seen a deceptive sales pitch.

    • @H12-q7x
      @H12-q7x 5 лет назад +9

      @@honkhonk165 I am aware of that. You've pointed out many flaws of the video which demonstrates your knowledge on the topic. I was about to comment about SSL encryption myself before I read your comment.
      I am sorry instead of _"you"_ I should have written _"the audience"_ , I edited my comment to make that clear. I believe these kind of crimes are performed in teams, this is why I wrote _join the mafia_ . I wasn't serious, though :P
      I still don't think there is a valid concern about being unethical. Yes, this content is overly simplified, incomplete and incorrect, but this is done intentionally for the sake of entertainment / commercial. These flaws *_are the reason why_* this video is so entertaining.

    • @afsdfsdfsdf4707
      @afsdfsdfsdf4707 5 лет назад +15

      Exactly. You must be incredibly stupid to be hacked - use unecnrypted websites, use the same password for all your accounts, accept all BIG RED ERRORS in your browser.

    • @8bitkame
      @8bitkame 5 лет назад +6

      @@honkhonk165 Can you be my mentor? Srsly

  • @DaveSomething
    @DaveSomething 5 лет назад +24

    I use my Pi as a VPN to help keep you out! That, and I rarely get on public networks...

  • @Non5ens
    @Non5ens 3 года назад +1

    This is probably the best way to advertise a vpn, Like THE BEST WAY

  • @saud4696
    @saud4696 Год назад

    My body got stiffer thinking is he going to ask people if he can hack them? But the way my body let loose and it was too adorable to process when he says it's his wife! This is why I keep watching these videos, so engaging and exciting. Keep up the work!

  • @alainrojas6191
    @alainrojas6191 5 лет назад +51

    Well Chuck to answer your question, they can actually use a simple firewall to avoid these kind of attacks, on the other side of the coin as end users we can and should use host level security solutions along with good security awareness (I'd say this last one is critical). There's a ton of open source/free security solutions you can implement @ your local device whether it is a laptop or mobile device you can use HIDS solutions like Snort, a good proxy solution like K9 software from Bluecoat, and a good firewall and anti-malware a quick Google for "free or open source security solutions" will get you going...ever heard about Sidejacking with ferret and hamster by Blackhat? That was a cool attack back in the days very much similar to what you did.
    P.S. Just got my brand new Network Chuck coffee mug!! It rocks!!! Just like you, man. Thanks!!!

    • @NetworkChuck
      @NetworkChuck  5 лет назад +3

      Excellent response!
      And thanks for reppin’ the mug!

    • @Klenric
      @Klenric 5 лет назад +4

      Well, the solutions you have mentioned would not help in this scenario. Basically he is rerouting your DNS traffic, this is an outbound connection and having a firewall at a host level will allow outbound to 443/80 regardless to the IP address received by the DNS. You need tools with threat intel capabilities that can stop you at a phishing site, it could use HSTS (HTTP Strict transport) or general information of the web page to headers to a lot of factors to alert you. Besides K9 is outdated, SNORT is an IDS/ IPS .. not sure why Chuck has liked the comment, probably just cause of the coffee mug but the details within are inaccurate. A proxy would not help either cause this is a local address, which will likely bypass proxy config. Anti-malware/ Endpoint security/ EDR/ which intercepts web traffic and provides a layer of security is the only useful information here.

    • @MichaelLeichtML
      @MichaelLeichtML 5 лет назад +4

      The whole thing is very theoretical - you are going to get about 90% encrypted traffic nowadays or Cert Warnings in your Browser, Mail etc, everyone working from there will most likely use a VPN anyway. It's a nice demo for people without a clue but you are far away from "hacking" people in any meaningfull way.

    • @deividjesus10
      @deividjesus10 5 лет назад +1

      ​@@Klenric It seems like you're looking for some attention, take my like as relief. Besides we're talking about a single user taking a little care, you wanted to look pretty smart with your comment, but dude.. take it easy, it's just people trying to share knowledge

    • @Klenric
      @Klenric 5 лет назад +3

      @@deividjesus10 What a lame response, first of all why do I need attention from a tech channel that too using tech terminology? This is typical RUclips comment, use "attention" when replying to someone if you don't have any logical response. While it's important to share information but misinformation or outdated information when it comes to a dynamic industry like IT is even more dangerous.

  • @AfonsoMiranda22
    @AfonsoMiranda22 4 года назад +3

    This is the first video I've seen from you. I watched 1min52s and I already decided to subscribe. Amazing job, Keep up!

  • @CollabCrush
    @CollabCrush 5 лет назад +53

    It wold be great if you did a video showing how to set up you own VPN. You can set one up for free through AWS...

    • @The2468101214161
      @The2468101214161 5 лет назад +6

      AWS gives you only 15GB transfer per month. If you use beyond that, you will have pay for its (AWS) hourly rate. That's what happened to me.

    • @novadnebula451
      @novadnebula451 5 лет назад

      @@The2468101214161 that happened to me too. Got extremely costly for me.

    • @CollabCrush
      @CollabCrush 5 лет назад +6

      I mention AWS just because I know that Chuck is into Amazon Web Services. Either way, I just think it'd be cool to see how to set up your own VPN.

    • @NetworkChuck
      @NetworkChuck  5 лет назад +13

      I’ve been using my own VPN for a long time running off a Cisco router. My biggest problem is speed.
      But you’re right, would be a fun video :)

    • @don0ctavio
      @don0ctavio 5 лет назад

      @@NetworkChuck Hi, greetings from Mexico, I would love to see a video about setting your own vpn with rb pi or so, I mean not to like have free vpn but to fully understand how this works. Have a good one and keep doing videos like this.

  • @Matte9
    @Matte9 4 месяца назад +1

    He made a whole cafe connect to him using only 5% power

  • @C0LPAN1C
    @C0LPAN1C Месяц назад +1

    This is why I use my local cellular hotspot with VPN tethered.

  • @xanokothe
    @xanokothe 5 лет назад +18

    And this is why kids you do not press "Accept the Risk and Continue" when your browser say the HTTPS is NOT SAFE

    • @JimBob1937
      @JimBob1937 5 лет назад

      Exactly, these attacks are prevented if the site is https, but the cert doesn't match or isn't authoritative. I don't think a VPN is needed if you visit only https sites and don't accept bad certs in the process, unless you also don't like your DNS being leaked (I personally wouldn't care). These are the basic attacks that the transport encryption and trusted cert authority system was designed to prevent. And most major sites are whole site https these days.

  • @blakryptonite1
    @blakryptonite1 5 лет назад +5

    I liked this video just based on the fact that you taught your kids linux. Your kids are going to grow up to think for themselves as opposed to the Desktop GUI thinking for them.

  • @jonathantx
    @jonathantx 5 лет назад +65

    Hello my fellow Texan 👋👋. Passed my CCENT this past Friday👍👍 It was tougher than expected.🥵🥵 But worth it😎🍻

    • @CollabCrush
      @CollabCrush 5 лет назад +2

      Congrats!

    • @heavensno487
      @heavensno487 5 лет назад +1

      Congratulations Jonathan, Keep up the hard work and success will never be out of reach.

    • @ClanILikeTurtlez
      @ClanILikeTurtlez 5 лет назад +2

      Hopefully you expected it to be super easy, barely an inconvenience. I take it this Friday lol

    • @tripptt9
      @tripptt9 5 лет назад

      congrats stranger. :)

    • @christopherkrause9899
      @christopherkrause9899 5 лет назад

      Congrats!

  • @learnhacking1437
    @learnhacking1437 3 года назад +6

    The good thing to know is you could shut down your neighbors wifi without even knowing their password 😂🔑

  • @droningandgoing9286
    @droningandgoing9286 4 года назад

    Ima buy myself a Raspberry Pi now, your goal of getting people interested in hacking and security is a success!

  • @TRS-Tech
    @TRS-Tech 5 лет назад +30

    As a CCIE I had a big smile on my face when you performed what we know as simple and easy attacks but most users imagine as the domain (excuse the pun) of super internet hackers ..... Grrr.
    I don't know about you but when I try and explain the dangers I am branded as a "conspiracy theorist that wears a foil hat and watches for UFO's every night" . I find it hard to make anyone listen or implement any proper security. The only answers I get are that they have a super wow antivirus and firewall (usually Norton or Mcafee LOL) and that nothing can happen.
    Working in the security field you get used to this but its sad that users have to get pwned and have major issues or privacy loss before they actually listen. People are lazy and just want to click and go. They don't care how it works or what is happening to the traffic once it leaves the device.
    I have been running a cert based IPSEC vpn on my home network for years so I don't worry about this to much but I strongly believe that there should be more awareness and that schools should teach students actual computer science " Yes people running netstat from the windows command shell does not make you a security expert ". I wish they would just cover even the basics so when asked about packets they do not think of the morning post delivery.
    Thank you for highlighting just how easily this can be done and bringing awareness and knowledge to viewers. I swish more people would do this. Keep up the great work my friend and hopefully I may bump into you online some day.
    Keep up the good work my friend.
    Stu.

    • @terminator00709
      @terminator00709 5 лет назад +4

      Maybe because the attack doesn't work in the real world ?

    • @terminator00709
      @terminator00709 4 года назад

      @dd active Because tls and certificates exist, which make mitm useless.

    • @terminator00709
      @terminator00709 4 года назад

      @dd active Recently ? Hello from 2015-2016 my dude. Check up on your knowledge, it might be a little ... obsolete. Just like the presented video, also thank you for agreeing with me that even in 2015 you couldn't get away with just what this guy does in the video. Also, there is this CAA thing which lists which CAs can issue a cert for a certain domain. If you are so sure it's so easy to "hack" someone, please go in a starbucks, do what the guys says and come back with paypal info, have a good day and good luck to you!

  • @keaunwild300
    @keaunwild300 5 лет назад +23

    morale of the story
    Block dns servers for Nord VPN when your doing mim attacks

    • @Yufflez
      @Yufflez 5 лет назад +1

      Doesn't work that way

    • @coreyl3191
      @coreyl3191 5 лет назад +1

      Nord vpn encapsulates dns requests too.

    • @incredible_max
      @incredible_max 5 лет назад +3

      @@coreyl3191 I believe he means that when you can't get the nordvpn ip resolved before opening the Tunnel, you can't open the tunnel

    • @juri14111996
      @juri14111996 5 лет назад

      @@coreyl3191the vpn app itself need to get the ip of the vpn server.

    • @coreyl3191
      @coreyl3191 5 лет назад +1

      @@incredible_max just talked to the support desk about this. He assured me that blocking the DNS requests from the app would not effect the preference of the VPN service. I have my doubts as well, but I now see what the original commenter ment.

  • @lassehansen6583
    @lassehansen6583 5 лет назад +6

    This might have been the longest ad I have ever seen :D

  • @Jameshasconnected
    @Jameshasconnected 5 лет назад +2

    If you really want protection, always consider that TOR is way better than a vpn in most cases, and its free.

  • @DavinderEvolution
    @DavinderEvolution Год назад

    1st of all, you have really cute daughters and you taught them linux at such an early age, god damn! you're gonna be dad of the year. Anyway, love the content brother, more power to you

  • @njneer
    @njneer 5 лет назад +82

    Great video. I'm learning ethical hacking now from a Udemy course. It's crazy interesting. I'm retired so I have a lot of time to spend on it, and I am. LOL. Your girls are adorable and as one beard guy to another, nice beard. haha

    • @1990spiderman
      @1990spiderman 5 лет назад +1

      How is the course?

    • @crtvofficialchannel8833
      @crtvofficialchannel8833 5 лет назад +2

      @@1990spiderman I am doing the "Learn Ethical Hacking From Scratch" course on udemy, really insightfull, example orientated and cheap! for around 15 dollar you cant get anything more compact in my opinion

    • @swaroopchirayinkil
      @swaroopchirayinkil 5 лет назад

      @@crtvofficialchannel8833 could you please share the course url 😇🤗

    • @swaroopchirayinkil
      @swaroopchirayinkil 5 лет назад

      @@crtvofficialchannel8833 thanks bro 🙂

    • @terminator00709
      @terminator00709 5 лет назад +2

      Guess they didn't teach you about https, huh ?

  • @fortialex
    @fortialex 5 лет назад +19

    Good thing Starbucks runs on Cisco Meraki AP's and automatically stops and alerts of all those attacks!

    • @cmeza1985
      @cmeza1985 5 лет назад

      How do they do that? Do you get a message on your screen?

    • @macvspc
      @macvspc 5 лет назад +1

      The only reason i know about the Meraki AP's is because the company that my father works at (he's the Network admin) got a few of them (I think for free) from some cisco event that were trying to show them off when they first came out (I believe). They look really nice and are pretty cool.

    • @titotrees437
      @titotrees437 5 лет назад +1

      MERAKI, admin at my site watch that air marshall is tight

    • @SchoolforHackers
      @SchoolforHackers 5 лет назад +1

      Alex Pavlock - Meraki gear has proven to be near-bulletproof and golden, for sure.

  • @VigilanceTech
    @VigilanceTech 5 лет назад +6

    the problem is you're still having to trust the VPN company with all your data/passwords (unless you set up your *own* VPN at home) as you're creating your OWN "man in the middle"

    • @ligmaballs3635
      @ligmaballs3635 3 года назад

      **hacker__virious* on IG is the best 💯✔️✔️🎗...

    • @hooptierescue2540
      @hooptierescue2540 3 года назад

      @dd active or just get a cheap or free linux virtual server somewhere and run a socks-proxy

  • @ahaanhalwai6739
    @ahaanhalwai6739 3 года назад +1

    I wanted to learn Linux and when I found your channel I learnt it and I’m now a pro

  • @salg8502
    @salg8502 4 года назад

    I know it’s an old vid but I don’t see the more in depth blog/video mentioned linked anywhere. Thanks for this and please do more!

  • @sethinman7206
    @sethinman7206 5 лет назад +9

    This was one long but really great advertisement. I learned alot

  • @mnageh-bo1mm
    @mnageh-bo1mm 5 лет назад +32

    Ssl laughing at the background

    • @rohanmalik895
      @rohanmalik895 5 лет назад +4

      I was scrolling through the comments just to find someone talk of SSL...

    • @mnageh-bo1mm
      @mnageh-bo1mm 5 лет назад +2

      @@rohanmalik895 i know .. the video is pretty dump we are in 2K19 and he didn't mention ssl ... sites that use http aren't important.

    • @mralderson5627
      @mralderson5627 5 лет назад +3

      *TLS

    • @mnageh-bo1mm
      @mnageh-bo1mm 5 лет назад

      @@mralderson5627 whatever

    • @mnageh-bo1mm
      @mnageh-bo1mm 5 лет назад +1

      @TheRageMaker lol i can imagine this working in the year 2012 only ...
      This thang is dead and doesn't work on the most of the site anymore .. do a quick search and you will find out

  • @austinjsimas
    @austinjsimas 5 лет назад +14

    I'm so sick of hearing people hawk VPNs as a solution for protecting you on public wifi. All reputable sites use SSL. All major browsers do everything they can to keep users off of websites that have bad SSL certificates. You do not need a VPN when using public wifi. Chuck either doesn't know what he's talking about or is overstating the value of a VPN to make a buck.

  • @echologname
    @echologname 3 года назад

    Nice! I'm going to rickroll my family's LAN! You are going to make me SO prepared for the next April 1st!

  • @solarsthetic4047
    @solarsthetic4047 3 года назад +1

    I love how this is a video about hacking but is also educational and wholesome haha x) you're an awesome father chuck ! 👍

  • @FinaLBoSSv0iD
    @FinaLBoSSv0iD 5 лет назад +10

    DNSCRYPT also protects you - no need to have a VPN in order to bypass these DNS attack

  • @DeadDad1
    @DeadDad1 5 лет назад +4

    Do you have the walk through done yet? I am very interested in reading/watching it. Thank you for the awesome videos!

  • @footballhero9717
    @footballhero9717 5 лет назад +42

    Wow dude you have a very beautiful wife . WHAT A LUCKY MAN

    • @Trident7235
      @Trident7235 5 лет назад +2

      Wanna hack her? ;)

    • @byrussx
      @byrussx 3 года назад

      @Finlay Indeed

  • @Crroow
    @Crroow 2 года назад

    Very smooth way to lure people to use a vpn with scare tactic. Upfront, you will toss 22 min down the drain to an advert

  • @vipanchika5059
    @vipanchika5059 4 месяца назад

    Thank you for all your help and lovely support

  • @marfnl2
    @marfnl2 5 лет назад +54

    Drink coffie in a coffieshop?
    I never known that they do that...
    I'm dutch ;)

  • @okidave
    @okidave 5 лет назад +5

    This is exactly the reason I don't use free WiFi. I also setup a hotspot on my phone for my family to connect to if needed.

    • @NetworkChuck
      @NetworkChuck  5 лет назад +1

      Another fantastic way to protect yourself. As our speeds increase we won’t need WiFi.

  • @madzo0omadz
    @madzo0omadz 4 года назад +2

    Amazon video, Chuck. You come off as a genuine person which eases the discomfort of learning about this double-edged sword. I'm about to give you an unsolicited suggestion but I mean it with good intentions I promise. I believe you should get one of those routers that people can install specific security + ad-blocking ad ons on and offer to install it for them as a one-time thing.

  • @wilwilson8146
    @wilwilson8146 3 года назад

    Channel sponsors are a better YT timestamp then the YT time stamp.

  • @TheBuffNerd7539
    @TheBuffNerd7539 5 лет назад +1

    Watching this Video at 4am! So amazing and very well put together. Awesome Sauce!!!

  • @i-use-arch-btw3954
    @i-use-arch-btw3954 5 лет назад +7

    Damn
    We all started somewhere...
    brings me back to when i was a script kiddie

    • @davidpacak691
      @davidpacak691 5 лет назад

      I am in the *script/programming/whatever kiddie* phase now :D

  • @HayzieGaming
    @HayzieGaming 5 лет назад +6

    That coffee shop is down the street from my house 😯

    • @NetworkChuck
      @NetworkChuck  5 лет назад +2

      Great coffee. Insecure network ;)
      Go help them!

  • @8bit-meiko
    @8bit-meiko 5 лет назад +79

    > spreads awareness of internet security
    > sponsoring a vpn that has apparently more marketing budget than security budget.
    hmm..
    love the vid otherwise tho.

    • @KennethNicholasK9
      @KennethNicholasK9 4 года назад +2

      I just caught on *cough* sponsored *cough* but good info nonetheless

    • @teckcross3174
      @teckcross3174 3 года назад

      You need to elaborate on that. Last time I checked, NordVPN was right up there in terms of security features for the end users, and their cybersec, killswitch, double VPN etc. options are very effective. The only issue sometimes is with the connection speed, especially when using some of theses or all of them together. But again, no major flaws in their security, don't know what you're referring to really..

  • @LourdIschan
    @LourdIschan 3 года назад

    This the longest and most entertaining NordVPN ad yet

  • @bountyhunterj6822
    @bountyhunterj6822 5 лет назад +2

    You are by far the coolest person alive.

  • @Wise_Dragon
    @Wise_Dragon 5 лет назад +3

    hacking with permission
    it is like knocking the jail door before entering

  • @Flipvb
    @Flipvb 5 лет назад +5

    Haha its weird to hear the word coffeeshop because in the netherlands a coffeeshop is a shop where you can buy legal drugs like weed

    • @dnyce0013
      @dnyce0013 4 года назад

      Why not call it a street pharmacy?

  • @marco114
    @marco114 5 лет назад +7

    When you connect to a VPN, you have to Trust those VPN providers aren't doing anything nefarious too. It would be better if every company just used SSL.

    • @NetworkChuck
      @NetworkChuck  5 лет назад +1

      True.

    • @mrmotofy
      @mrmotofy 5 лет назад

      Or create your own vpn server at home. I have 3 at 2 locations depending on what I need access to

    • @musicalmercy5204
      @musicalmercy5204 5 лет назад

      What is the difference? (I'm trying to keep up with tech and would like to be educated pls)

    • @mrmotofy
      @mrmotofy 5 лет назад +1

      @@musicalmercy5204 A vpn server is just a computer on a network somewhere that is acting as a server which allows computers to connect to it. If you purchase NordVPN you get a username and login info and connect to their servers in whichever country you choose they operate in. If you do it at home you just run a vpn server on one of your own computers and connect to it from a Starbucks etc. Then websites see you as connected from your home not the starbucks. Or a Nordvpn server in Russia instead of the starbucks 4blocks away. It can mask your location and also secures it from the public wifi you're on for example. You can just watch a few vids of vpn setup to get a better idea.

  • @Nexalian_Gamer
    @Nexalian_Gamer 2 года назад

    Woah, this looks cool. Imma buy one
    * sees $100 price *
    Aw hell nah

  • @Phychologik
    @Phychologik 5 лет назад +19

    Q: Why is the girl wearing that mask?
    A: Because she wanted to be anonymous.

  • @notholdini2740
    @notholdini2740 4 года назад +2

    I like how this is for “learning” purposes

    • @ahmadzainul1144
      @ahmadzainul1144 3 года назад

      he teach us to use vpn in public network stupid..

  • @abdurahman3896
    @abdurahman3896 4 года назад +2

    Amazing channel! Family based, and education/ hacking... truly a unique take!

  • @chrisoakleyfx
    @chrisoakleyfx 2 года назад

    With so many people now working remotely/WFH this is more crucial knowledge than ever to protect yourself and stores operating public hotspots need to be clued up on even just the very basics. Every store offering public WiFi should have a note/sticker next to the WiFi information saying USE A VPN!! But then that would be a sad day for would-be hackers ;) Love the content!

  • @AndrewEtmus
    @AndrewEtmus 4 года назад +2

    My wife and I got engaged at Conversations! I'd love to meet you there! Haha

  • @karlbooklover
    @karlbooklover 5 лет назад +6

    I used to use a 5Watt chinese Wifi amplifier for deauth attacks with Linset to making the evil twin. I think you should have mentioned that nowadays basically all traffic is protected by TLS with downgrade attacks not being supported with current protocol versions in most cases. So basically peoples passwords and user data is safe without an VPN, what a VPN does is hide the metadata, the DNS requests.

    • @alainrojas6191
      @alainrojas6191 5 лет назад

      I'd clarify SSL is obsolete. You may have wanted to say TLS...

    • @NetworkChuck
      @NetworkChuck  5 лет назад

      BUT, if i had some beefy hardware doing some SSL/TLS decryption, it would be a different story.
      I think the scariest attack is an evil twin with DNS spoofing. I can make a website that looks just like target that will fool any average user into logging in.

    • @wolfie3098
      @wolfie3098 5 лет назад

      NetworkChuck if you have the means to crack tls traffic then nord vpn doesnt really have any benefits. But maybe #NSA can give some insight

  • @criticalmoorhen
    @criticalmoorhen 5 лет назад +4

    Well, thanks for covering Linux :) Linux is a platform that completelly replaced Windows to me.

  • @weshuiz1325
    @weshuiz1325 5 лет назад +10

    jokes on you there is no starbucks where i live

    • @goodmorning77777
      @goodmorning77777 4 года назад

      weshuiz13 do you live in the ocean

    • @Caroleeeh
      @Caroleeeh 4 года назад

      @@goodmorning77777 probably in a village somewhere in the Congo

  • @SugarRay69420
    @SugarRay69420 2 года назад

    I remember when my friend across the states was able to turn off my wifi! shit was impressive

  • @mavjerm
    @mavjerm 2 года назад

    i wish chuck was my dad,that would’ve been so much more fun.

  • @ko-Daegu
    @ko-Daegu 5 лет назад +10

    If you are not using the same SSID and deauthing the original Network then this is not an evil twin attack
    Am I right ????

    • @NetworkChuck
      @NetworkChuck  5 лет назад +4

      I had the same thoughts, just depends on how loose your definitions are. Mine was more of a fraternal evil twin attack because I didn’t want to be flagged as a rogue AP.

    • @BastienVide
      @BastienVide 5 лет назад

      @@NetworkChuck You could easily put the SSID. As long as you emit stronger and deauth every other clients, it should work!
      But sure, you should have the permission from Starbucks then, not to violate laws.
      That's more a phishing AP haha!

  • @chilldudie242
    @chilldudie242 5 лет назад +4

    00:31 coffee really is dangerous, over 500 people die annually from caffeine overdose.

  • @asandax6
    @asandax6 5 лет назад +15

    Chuck: your MAC address will never change
    Me: roots phone changes MAC than use Kali Linux to change my PCs MAC
    😎😎Yup it will never change

    • @NetworkChuck
      @NetworkChuck  5 лет назад +4

      *For most people
      ;)

    • @nickstrauser1228
      @nickstrauser1228 5 лет назад +1

      What does rooting a phone have to do with anything? And what does Kali Linux have anything to do with changing your Mac address? You can change your mac address on any flavor of Linux.

    • @asandax6
      @asandax6 5 лет назад +1

      @@nickstrauser1228 yeah I know every Linux or Unix based System you can change the MAC. You can even do it on a Windows system but on Android you have you have to root it first atleast that's the easy way to do it.

    • @legitscoper1409
      @legitscoper1409 5 лет назад +1

      @@nickstrauser1228 on Android I think you need a rooted phone to change MAC. But i'm not 100% sure

    • @DePhoegonIsle
      @DePhoegonIsle 5 лет назад

      kek, the MAC address didn't change.. it's called Spoofing for a reason. X] Just because it didn't change doesn't mean it can't be spoofed else where or ignored it from the hw itself.

  • @viczking8520
    @viczking8520 5 лет назад

    I have ever done all those attacks but I really enjoyed the video, I actually laughed in the evil twin part! Good Job!

  • @katkat4272
    @katkat4272 4 года назад +2

    i love your content mister😅 im inspired bcoz when my daughter grows up i'll keep watching her 😂😂 and protect her , im running GNU linux on android i keep practicing 😄 someday i can afford to buy a desktop for more powerfull features to use ..bcoz in android there's alot of limits

  • @maroonhaykal9836
    @maroonhaykal9836 5 лет назад +12

    How could nerds like us get such a pretty wife :P no offense great vid keep it up !!

  • @woofelator
    @woofelator 5 лет назад +26

    "I want you to hack your friends, your family"
    ~NetworkChuck

    • @danielmiller8004
      @danielmiller8004 5 лет назад +1

      Me: *Hacks sisters phone, sends sms message to sisters phone making it look like her phone sent the message* We are the borg your phone has been assimilated Resistance is futile.
      My Sister: What the hell is this?
      ( I would love to actually do something like this to my sister some time just to mess with her)

  • @DXTR420
    @DXTR420 5 лет назад +14

    BRO your music is SO LOUD compared to your voice in the volume mix...

  • @lol-inc
    @lol-inc 2 года назад

    Do you know anything about the Evil twin's attack? "Wooow, I asked you the question before watching the video and the first thing you come up" 😁👌🏻

  • @sav4426
    @sav4426 5 лет назад

    i've never seen someone being so honest

  • @NicolaiWeitkemper
    @NicolaiWeitkemper 5 лет назад +12

    So why were there no Problems with HTTPS? Did you use a self-signed certificate?
    And the DNS attacks would stop working when browsers implement DNS-over-HTTPS, right?

  • @MrARM
    @MrARM 5 лет назад +4

    The trick is to just block VPN on the attacker network.

  • @Jorgeramirez-uf3xc
    @Jorgeramirez-uf3xc 5 лет назад +5

    Damn I should have waited to get Nord lol

  • @kevinheckart
    @kevinheckart 5 лет назад

    Thankful for browsers being able to detect spoofing. VPN is good too obviously.

  • @redgamestream
    @redgamestream Год назад +1

    Good vid! Can u make an updated version? like a bit more in depth how to do it (for educational purposes only ofc)

    • @gtgt8564
      @gtgt8564 Год назад

      Good luck doing that with one antenna only

  • @protu7908
    @protu7908 5 лет назад +5

    "come play with us daddy" cmon bruh im here trying to sleep lol

    • @byrussx
      @byrussx 3 года назад

      danny* lol

  • @princeyashu
    @princeyashu 5 лет назад +7

    by da way why need raspberry pi if you can install kali linux on laptop :p it will do more good

    • @NetworkChuck
      @NetworkChuck  5 лет назад +2

      Good point. I just love the versatility and price of a raspberry pi. In theory, I could configure one and leave it in a coffee show to access remotely.

    • @GX2re
      @GX2re 5 лет назад +1

      I bought a cheap laptop for $35 and I'm currently learning Linux with it

    • @princeyashu
      @princeyashu 5 лет назад

      @@NetworkChuck yeah i agree with dat and with a good powerbank or anythin usb it can stay longer den laptop. `can do many things with kali, mitmf, BEef etc etc :D

    • @cyberpunisher8652
      @cyberpunisher8652 5 лет назад +1

      You can hide a pi much easier than a laptops but for everything you don’t need to hid it for a laptop is better

  • @vim_usr2753
    @vim_usr2753 5 лет назад +4

    In general, is tethering to a cell phone's LTE connection over WiFi secure? Or does it suffer from the same possible hacks?

    • @xxcr4ckzzxx840
      @xxcr4ckzzxx840 5 лет назад +1

      Think LeBron James got smth mixed up. No its not if its "open". With WPA2 its another story, but if its Open, u can get hacked the same way cuz your Phone does nothing else than being a Router for others and forward the packets to another connection. If u want so, the Phone is the man in the middle, but in a good way. If u use USB tethering, its safe.

    • @michaelmichael8406
      @michaelmichael8406 5 лет назад +2

      The LTE is pretty secure - it's possible to attack it, but it isn't common.
      The WiFi connection between the phone and your computer is another matter. Pick an SSID that doesn't stand out (do not taunt happy fun hacker) and a good, complex password (don't use a dictionary word, but make it a nonsense sentence or a complex mix of upper, lower, numbers, and symbols) and you should be ok. Don't do your banking in public where people can look over your shoulder anyway.

    • @vim_usr2753
      @vim_usr2753 5 лет назад

      @@michaelmichael8406 this is what I was getting at--tethering to your phone over WiFi. Thanks for the info.

  • @minecraft-wz5fd
    @minecraft-wz5fd 3 года назад +1

    Me: uses a vpn
    Also me: Somehow still gets haxed
    Again me: disconnects from WiFi
    The universe: THE FINAL SOLUTION HAS BEEN FOUND

  • @0v_x0
    @0v_x0 5 лет назад

    I got to attend the RSA conference in 2013 courtesy of my high school buddies who helped start up the pen testing company Pwnie Express. my friend developed the pwnpad which was basically debian shoehorned into android on a nexus tablet in order to run Kali Linux. it also had an external wifi antenna with more power and things like packet injection. some tech blogs were showcasing a demo, in which (in a conference hall with over 3000 people, many of them security professionals) he set up a spoofed router with a generic name likely to be in people's remembered networks (at the time attwifi worked great). this was being video recorded by a few people. within seconds, dozens if not hundreds of connections flooded in, and all the saved automatic login data for Google, facebook etc that it's automatically sent out started streaming down the console in plain text. "you guys might want to blur that part out," lol. it was quite impressive and surprisingly effective in a room full of supposed experts. ofc this was before mobile VPNs were much easier, but I always turn off wifi when I leave the house and run my VPN even over my LTE network. it has an internet kill switch if it loses connection so I am protected instantly even if I join a wifi network somewhere. just found your channel, looking forward to learning more. I really want a pwnpad or a pwnphone (the latter was featured on the show Mr Robot in the second season). distant family (step sister in law) showed me how to use netbus and sub7 back in middle school too, had a lot of fun with friends using
    exe trojans (with permission ofc, they had to give be their IP address, this was back in the day of aol instant messenger and dial-up). I'm no proficient hacker at all, I was at best a script kiddie in middle school lol, but between that and my friends I definitely got the bug. I've got a live boot usb stick for Kali on hand just on principle, for my laptop. I should know how to use it better though.
    cheers :)