All language subtitles for 005 Basic terminology including SQL injections_ VPN _ proxy_ VPS_ and key loggers_-subtitle-en

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

1

Hello everybody and welcome to this

tutorial.

2

Here, I'm just gonna continue from where I left off in the previous one.

3

If you have not seen the previous tutorial, I

strongly urge you to do so

4

as the two are closely interrelated, so to say.

5

Anyway, previously we discussed some of these things

6

such as DoS, RAT, fishing and so on and so forth.

7

But here, I wanna go a step further

8

and tell you about SQL injections, VPNs,

proxies, Tor, VPS, key loggers

9

and so on and so forth.

10

You will see how all these things will

play a role later on

11

throughout the course.

12

But for the time being

13

you have SQL injections, which are simply passing SQL queries to HTTP requests.

14

If they are not properly formatted by the PHP code on the server side

15

this can present a serious problem

16

and this is always one of the primary

considerations

17

of all the web developers out there.

18

Later on I will demonstrate how you can use these

19

formulate them

20

and there is a large amount of websites that are vulnerable out there

21

primarily because the frameworks on which they're based

22

are vulnerable as well.

23

Next up, you have Virtual Private Networks

24

so VPNs

25

These are ways of anonymizing yourselves.

26

Basically, if you have a VPN provider somewhere

27

and if you want you anonymize yourself

28

you will route all their traffic through this VPN provider

29

and all the traffic between you and the VPN provider will be heavily encrypted.

30

So any other server out there

31

if it is receiving requests from you

32

it is actually receiving them from VPN.

33

There is no real way of detecting you or fighting your physical location

34

unless the VPN provider actually gives it up.

35

which doesn't really happen if you pick the right one.

36

Down below you have proxies.

37

Now proxies are a less reliable way of staying anonymous

38

but you should always make it your common practice to use Socks5 proxies.

39

I will explain what these are

40

I will introduce them when we do proxy chains

41

and when I explain to you how you can

actually stay anonymous

42

while conducting these sort of activities.

43

You will realize that you can route your connection through several proxies

44

but very soon you will see as well, that doesn't always work.

45

In the movies or something like that you see people going through 10

46

or 20 different proxies.

47

In reality that would be very VERY difficult to implement

48

primarily because of internet speeds

49

because of the available bandwidth.

50

Most of the free proxies out there are not very fast

51

and routing your connection through several of them

52

will make it very difficult for you to do anything in a reasonable amount of time.

53

There are, of course, paid proxies

54

but when you pay a proxy, you leave digital footprints somewhere

55

so you can be traced.

56

Down below, you have Tor.

57

Now Tor is absolutely free open source

58

and it's much faster than proxies.

59

It's not faster than VPNs, but it is faster than proxies.

60

It gives you the ability to torify your applications

61

which in essence, means simply routing

traffic through certain routes

62

and using certain routers on the Internet to

actually

63

not just routers, but using certain devices

on the Internet for your packets

64

for your connection to go through.

65

It can be slow from time to time.

66

It is not a 100% guarantee

67

but you will be anonymous to a very large extent

68

if you are using Tor.

69

There are ways of detecting you

70

but they are HIGHLY unlikely to happen Nike night

71

Like 99.99% of time, you will be almost 100% anonymous

72

which is a very good way of functioning.

73

Also, you have the Tor browser

74

which allows you to access dark web, or hidden web

75

however you wish to call it.

76

Basically, those are ".onion" websites

77

and they are not indexed by any other search engines out there

78

and they cannot be accessed by a regular internet route...

79

from the regular internet browsing perspective.

80

You cannot...I mean if you open up Firefox

81

and if you had your internet connection

82

and if you don't have your internet connection configured in a proper way

83

to connect it to a network, or something of a kind

84

you will not be able to access any of the hidden webs, dark webs, website services

85

and so on and so forth.

86

Now I will also show you how to access dark web and how to use it

87

as it has a vast amount of resources that are at your disposal

88

most of them free

89

some of them paid, and so on and so forth.

90

Down below, you have VPS.

91

These are Virtual Private Servers.

92

It is a method of...

93

it is a security...

94

it can viewed as a security layer.

95

For example, if you have an Apache server

running on your physical machine

96

you can have a virtual machine within

that physical machine

97

which will serve as an SQL Server for that Apache server.

98

This is done so that the SQL server cannot be accessed from outside

99

and that you don't have an SQL port open

on your physical machine.

100

So only devices

101

only programs

102

and users from that particular machine

103

will be able to access to virtual machine where the SQL Server is.

104

A bit of back and forth action here.

105

It might sound unclear or something like that

106

but I don't want you to worry about it now.

107

When I show the examples when you get into it

108

you will understand it.

109

I guarantee it to you.

110

So no problems there.

111

Here I'm just introducing you to the terminology

112

and giving you an idea of what's to come.

113

Excellent

114

So we also have "Key Loggers"

115

which are tools that are used to steal credentials

116

and not only credentials

117

but also used to extract information.

118

If you manage to deploy a key logger on a machine

119

you can configure it to send

120

to record all keystrokes and send them to a mail address

121

to an FTP server.

122

Today, key loggers are advanced to the extent

123

that they have

124

they have like a hundred options or so

125

configurable to the fullest of extents

126

and you can do pretty much whatever you want with them

127

I mean, they have their basic functionalities

128

the basic functionalities are still there

129

to record the keystrokes

130

but not only do they record keystrokes

131

for example

132

they can extract existing information as well.

133

You can configure their behavior

134

how is the stealth level of the key logger?

135

How will it hide?

136

Where will it go?

137

Where will it be installed?

138

What sort of information do you want to extract?

139

Do you want monitor particular folders for activity

140

and you want to record it?

141

You can configure them take screenshots.

142

You can configure them to use the camera on the device

143

on which you had deployed a key logger to take a picture every five minutes

144

or something like that

145

That wouldn't be the of brightest ideas

146

because obviously somebody would that you are taking a picture

147

but those are just examples of what you

can do with them

148

and later on we will actually download the genuine keylogger

149

Install it

150

Deploy it

151

and show methods of deployment and how you can configure it as well

152

although you should be very careful from where you download your tools

153

such as key loggers, remote demonstration tools, rootkits

154

and so on and so forth.

155

Primarily because you never ever want to download

156

an uncompiled binary file that is not open source

157

because you have no way of knowing what's in it

158

and you absolutely NEVER want to run it on your computer

159

You might get what you want

160

you know, a key logger or something of a kind

161

but your computer might get infected with exactly the same key logger

162

that you planned to deploy somewhere

163

or with exactly the same wrath that you intended to deploy somewhere.

164

So that's a very bright idea.

165

You should use verified sources of such tools.

166

I will show a few of them later on

167

as I go over to the internet and download them

168

but I'm just making it very clear here

169

that you should be very careful with these things

170

and one of the full proof methods of doing this

171

is actually configuring a virtual machine

172

and doing this sort of activity on that virtual machine.

173

So even if you get infected or something of a kind

174

it doesn't matter.

175

It's a virtual machine.

176

You can reinstall it anytime you want.

177

Very fast

178

Pretty much no information will be lost there.

179

More importantly, the primary file system on your main physical machine

180

will not be accessed from the virtual machine

181

Anyway, down below you have the terminal

182

So terminal is basically an interface for you

183

that allows you to control your operating system.

184

Now, Linux terminal is VERY powerful.

185

We will be using it extensively.

186

You will need to familiarize yourselves with it.

187

I will familiarize you with it.

188

I will teach how to use it.

189

To some people, it might seem a bit difficult

190

or a bit tricky at first sight.

191

You know, there are a lot of commands to type in --

192

How to memorize them all

193

What to use where, and so on and so forth

194

but believe me, there is a certain logic to it

195

and once you figure it out, everything

just flies.

196

I know by heart about 30% of possible commands out there.

197

regarding Linux terminals

198

and the rest I simply figure out with dash H or dash dash help.

199

The system pretty much tells you everything you need to know.

200

It helps you out to a great extent

201

and you are able to figure out a lot of

things

202

from just understanding the basic logic

of how it works

203

and so on.

204

Now, there will always of course be arguments

205

I don't know, maybe people saying "Why would you use terminals?"

206

"Why won't you just use GUI tools or something like that?"

207

The simple answer is because they are not as nearly as powerful

208

as the terminal tools are.

209

Plus, terminal tools have far less dependencies

210

and most the hacking tools are basically designed for the terminals.

211

They're not...they don't have GUIs.

212

A lot of do have them these days

213

but I might go over them briefly at a certain point of time

214

because it is not...

215

the GUI interfaces are not that relevant

216

When you figure out how to do it in the terminal

217

you will automatically, by default

218

know how to do it with the Graphical

User Interface

219

for that particular program.

220

Anyway, down below you have firewalls.

221

Now, firewall in Linux is configured through IP table commands

222

You keep on passing arguments and configuring these firewalls

223

and this is one of the main reasons

224

why you should not be using any distribution of windows

225

for this particular tutorial --

226

to follow this tutorial.

227

You will need to install

228

as I said previously

229

will need to install either a Linux virtual machine or create a duel boot

230

or something of a kind.

231

I will, of course, show how to do this and demonstrate it in great detail what are the main

232

but one of the main reasons --

233

the firewalls are one of the main reasons

234

why we can't use windows for these sort of purposes.

235

Linux firewall is open source

236

and it has a ridiculous amount of options

237

a ridiculous amount.

238

Enough getting here...

239

You can do with it pretty much whatever you want.

240

You can configure.

241

You can close and open ports.

242

Forward connections via ports or via IP addresses.

243

You can close...

244

you can just forbid certain protocols on certain ports

245

or forbid certain protocols for certain IP addresses.

246

Do all manner of forwarding and redirection

247

and so on and so forth.

248

This all available for free with a Linux

firewall

249

While in Windows, you will have some of these options

250

but most of them you won't unless you, for example

251

buy a certain package or something like that

252

which is not something that we really want to do here.

253

We want to keep this budget-friendly

254

and we want to have a powerful firewall

255

which can do pretty much whatever we want it to do.

256

Now, there will be two ways of configuring this firewall

257

and if you are afraid of messing it up, don't worry about it

258

because most configurations that we will do will be short-lived configurations

259

so to say

260

primarily because all the configurations made to the firewall

261

from iptables command

262

unless specified otherwise

263

will be temporary, and they will hold until the next system reset.

264

There is a way to circumvent this, of course

265

and to configure the firewall rules in the configuration file directly

266

and thereby making the changes permanent

267

which is also one of the ways of doing it

268

but I don't generally prefer it

269

I prefer it to have a script somewhere which you can run at anytime

270

and it will configure firewall by default.

271

This is primarily because you want to

have your tools set in a USB stick

272

or somewhere in the line

273

or something of a kind.

274

and you have these quick scripts, which you generate

275

and then they perform these tasks for

you in an automated fashion.

276

It's really simple.

277

I will show you how to make these scripts.

278

You don't need...

279

You do not necessarily need some advanced programming knowledge

280

or anything of a kind.

281

Basically what these scripts are

282

are lists of Linux terminal commands

283

which we will do anyway.

284

So basically, the script would consist out of a list of those commands

285

then you just change the mod of the script to be an executable file

286

run it

287

and all those commands are past the system

288

and those tasks are finished in an automated fashion, by default.

289

Anyway, one of the final things that I wish to address here

290

are "Reverse-shells"

291

There are hundreds, if not thousands of reverse-shells out there

292

that you can use.

293

I will pick a few that we will use, depending on the framework

294

depending on the environment, of course, that we want to infect.

295

But in essence, what reverse-shells are

296

as the name itself says

297

you have a program, which you infect in another device

298

and then that program opens up a reverse connection from that device

299

back to you.

300

So you can keep on passing commands.

301

You can keep on controlling the system

302

even though you are nowhere near it. there are

different types of course today

303

There are different types, of course, today with routers

304

and so on and so forth.

305

With such firewalls, you need to do a lot of extra configuration

306

and there are problems that need to be solved and addressed.

307

You'll see how when you're trying to break into a single computer

308

sometimes you need to break into the

router first.

309

Usually you need to break into the router first

310

unless you're performing these fishing sort of attacks

311

or there's a web server, or something of a kind, running in the background

312

But attacking a private device --

313

private computer, which is usually what

people do

314

as preludes to bigger hacks

315

because they want to extract some sort of information

316

or something of a kind

317

from let's say, a company's employee that's a network administrator

318

or somebody like that.

319

They will...

320

One of the basic factors would be to attack a home router

321

change the DNS settings there

322

and try to steal credentials in such a way

323

or put the computer in the DMZ of the router

324

demilitarized zone

325

so that the router is no longer effective for the device.

326

Rather instead, it just forwards all traffic to that device regardless

327

So that can be...

328

Those are some of the types of attacks you can do

329

but reverse-shells will depend on the choice of the environment

330

that you are trying to infect

331

and will depend on the choice of your attack route, as well.

332

In any case, I hope that you got some basic introduction to these terms

333

and I again repeat, if you didn't figure it out all immediately

334

don't worry about it.

335

We will do all of this in great details with a lot of examples

336

and you will understand it.

337

It is not complicated.

338

Do not allow fear to dissuade or stop you.

339

Just keep on going in spite of it

340

and if you can just stick in to the end of this course

341

I guarantee it to you, you will understand it

342

with just a bit a focus and a bit of curiosity

343

you will be able to obtain the necessary skills needed

344

in order to become a pen tester or an ethical hacker.

345

I bid you all farewell and I hope to see you in the next tutorial.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.