"Please Hack My Computer"

"Please Hack My Computer"

Source: YouTube · John Hammond · published Jul 20, 2023 · 17:50

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The creator set up a honeypot server called cybersec.fail using Cowrie to monitor hacker activities and gather threat intelligence, revealing what attackers actually do when they think they've compromised a system. 2:21-2:32

Key Takeaways:
• The server was intentionally configured with weak credentials (John/"I love you" and root/"toor") to attract hackers and observe their behavior. 1:34-2:05
• Approximately 2,000 unique IP addresses attacked the server, making about 255,000 login attempts total. 6:15-8:39
• Successful hackers ran various commands including privilege escalation attempts, crypto miner searches, and even leaving humorous messages in the system. 11:10-14:19
• The experiment demonstrated the value of cyber deception and active defense techniques for gathering intelligence on attacker methods. 3:38-3:48

This honeypot experiment provides valuable insights into real attacker behavior and tradecraft that defenders can use to better protect their systems.

Sources:

  • 2:21-2:32 Explanation of the honeypot setup using Cowrie
  • 1:34-2:05 Details about the weak credentials configuration
  • 6:15-8:39 Statistics on unique IP addresses and login attempts
  • 11:10-14:19 Examples of commands run by successful attackers
  • 3:38-3:48 Discussion on cyber deception and active defense

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

over the Fourth of July I asked you to hack into my server that I hosted at cybersec.fail now I thought this would be kind of a fun challenge I'd be interested in how many people would want to do it who would actually just take the permission and scope offered in a tweet or LinkedIn post and then just go on their merry way to try and beat up the server how many people would do it and then what would they do so if you are one of those hackers who tried the task maybe the first thing that you did was run nmap the network mapper utility on the command line trying to get a little bit more Intel and detail on what is the open attack surface what ports are open and accessible on that server maybe you ran the who is command maybe you draw a little bit more detail on the domain could have been any…