
I Stole My Own Reddit Account. Here's How.
Source: YouTube · John Hammond · published Dec 12, 2024 · 22:58
Session hijacking allows attackers to steal and take over accounts using stolen cookies, bypassing strong passwords and two-factor authentication. 0:41
Key Takeaways:
• Cookies stored in Netscape format contain session keys that can be used to authenticate to any website, including Reddit, even without passwords or 2FA 1:44.
• Info stealer malware collects user data, including cookies, browser autofill, IP address, and device information, which attackers use to impersonate legitimate users 5:13.
• Attackers use antidetect browsers to mimic real user behavior—such as timezone, screen resolution, and geolocation—making session hijacking more realistic and harder to detect 14:55.
• Flare’s new API proactively monitors and invalidates stolen session cookies from malware logs, offering a defense against account takeovers 18:40.
Even with strong passwords and 2FA, session hijacking remains a serious threat due to the ease of stealing and reusing cookies. Proactive monitoring and threat intelligence are essential to defending against such attacks.
Sources:
- 0:41 Discussion of session hijacking as a threat bypassing password and 2FA.
- 1:44 Explanation of cookies as authentication keys in Netscape format.
- 5:13 Info stealer malware data collection including cookies and device info.
- 14:55 Use of antidetect browsers to mimic user profiles.
- 18:40 Flare’s API for detecting and invalidating stolen session c
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
I stole my own Reddit account now I know that sounds weird but I'm going to show you in fact in this video I'm going to show you how hackers and thread actors can practically steal and take over any account on any website on the internet but I'm going to do this in a safe controlled demo environment so I'll be hacking myself first let me show you my Reddit account anytime I'm here on the Windows desktop that is me acting as the victim the one getting hacked now I'm using Firefox and I'll open that up to log to my Reddit account this is all for our learning so I am going to be working with a demo account but let me go ahead and log in now my username here is Le haor 1337 and I even have a super strong password that's over 128 characters it's all super secure randomly generated set up with m…