TryShadowing
Shadow YouTube. Nói tiếng Anh.
Trang chủ
Khám phá
Chép chính tả
NEW
Thư viện
vi
0
ngày
Đăng nhập
10 open source tools that feel… — Fireship luyện shadowing | TryShadowing
TryShadowing
Shadow YouTube. Nói tiếng Anh.
Trang chủ
Khám phá
Chép chính tả
NEW
Thư viện
vi
0
ngày
Đăng nhập
Trang chủ
Khám phá
Fireship
10 open source tools that feel illegal...
10 open source tools that feel illegal...
Fireship
·
10:03 · 5 thg 2, 2026
Bắt đầu học
0:00
0:00
Ghi âm
×1
1x
VI
EN
JA
KO
ZH
FR
PT
TH
IT
DE
IPA
Chấm điểm phát âm chưa hỗ trợ trên trình duyệt này — bạn vẫn ghi âm & nghe lại được.
There
are
three
types
of
computer
people
in
this
world.
Đang dịch…
Bật Ghi âm để được thu giọng và chấm điểm
Thông minh
Karaoke
Câu
1
/251
0:00
There are three types of computer people in this world.
0:02
Users, programmers, and hackers.
0:04
The user just wants boring software to make boring spreadsheets to get boring stuff
0:08
done at work.
0:09
But in their naivity,
0:11
users often get penetrated by hackers with high levels of RZ who employ social
0:15
engineering to steal personal data,
0:17
intimate photos, and crypto wallets.
0:19
But then you've got programmers.
0:21
They're the unsung heroes who make all the software in the world work.
0:24
But they too get penetrated by hackers.
0:26
If a programmer leaves the back door open to their mainframe,
0:29
it could lead to catastrophic consequences that cost them, their job,
0:32
and their employer billions of dollars.
0:34
The lesson to be learned here is
0:36
that you want to be the one doing the penetrating,
0:38
not some stranger in a foreign country who doesn't even care about your feelings.
0:41
In today's video, you'll learn the fundamentals of ethical hacking
0:44
and penesting by looking at 10 free
0:46
and open- source tools
0:47
that you can use right now.
0:49
All of which are available by default on Kali Linux,
0:52
a DRO optimized for ethical hacking.
0:54
By the end of this video,
0:55
you'll be a legit wannabe hacker who can take down entire nations.
0:59
But if you like to do bad things,
1:00
you need to turn this video off right now.
1:02
The tools in this video, if used non-consensually,
1:04
it could break many international laws that land you in prison.
1:07
So never do penetration testing on a website or network without permission.
1:11
But now that all the bad guys have clicked off this video,
1:13
let's learn how to use some of the most powerful and dangerous hacking tools.
1:17
To follow along, I would highly recommend installing Kali Linux.
1:20
And the desktop version is awesome.
1:22
Although Microsofties can install it via WSL
1:24
or if you don't want to use Cali,
1:26
you can just install each one of these hacking tools individually.
1:29
But the best way to get started is to spin up your own virtual
1:31
private server on Hostinger,
1:33
the sponsor of today's video.
1:35
Their platform gives you the power
1:36
and flexibility to run anything you want without locking you into a complicated
1:40
and expensive cloud platform.
1:42
You can run a basic Linux server like Arch with powerful hardware like NVMe
1:46
SSD storage and AMD epic chips.
1:49
You can easily manage containers with a dockervp
1:51
and their free docker manager
1:53
or self-host entire backends like superbase with a single click
1:57
and zero config nightmares.
1:58
But today I'm using hostinger to run kali linux.
2:01
And after launching the VPS with just a few clicks,
2:04
I can SSH into it with my password.
2:06
And now our hacking journey begins.
2:08
The first tool you need to know about is end mapap.
2:10
It's like the peeping tom in your neighborhood who looks through all the windows
2:13
in your house without actually breaking in.
2:15
On a network like the one you're connected to right now to watch this
2:18
video,
2:18
there's likely multiple hosts connected to it like your computer, your PlayStation,
2:22
and your smart lock.
2:23
And the purpose of NAPAP is to map out a network.
2:25
It does this by sending packets over an IP range.
2:28
It then analyzes their responses to figure out which ports are open,
2:31
which operating systems they use to help you find back doors to exploit.
2:35
Like if grandpa misconfigured something on his network,
2:37
you can hack his printer to send him a message.
2:39
To use it, simply use the end mapap command followed by an IP address
2:42
you have access to,
2:43
like your local network or even a URL that you have permission to penetrate.
2:47
If we do that on a website,
2:48
you'll notice we get the IP address back.
2:50
And it found that ports 80 and 443 were open.
2:53
That's pretty cool.
2:53
But we can also do a more aggressive scan with the A option.
2:57
This will not only scan the network,
2:58
but also try to detect the operating systems,
3:01
and we'll use something called tracer route to track the path of the packets
3:04
across the entire network,
3:05
which can help detect misconfigurations that we can exploit.
3:08
If you're interested in packets though,
3:10
another tool you'll need to know about is Wireshark.
3:12
It's like that guy at a party who tries to eavesdrop on every conversation.
3:16
It allows you to inspect what's happening on the network at a microscopic level.
3:19
You'll want to use the guey on this one
3:21
because it collects tons of data from hundreds of different protocols
3:24
which are all captured in real time
3:25
and can be analyzed offline.
3:27
For example, if you record the traffic on your network right now
3:30
and notice all this weird traffic going to an IP address in North Korea,
3:33
you can inspect the actual payload
3:35
and might find out
3:35
that they have access to those photos
3:37
that were intended for only you
3:39
and your future ex-wife to see.
3:40
And now you might be radicalized and ready to fight back.
3:43
Metas-ploit is perhaps the most powerful hacking framework out there.
3:46
It's like a Swiss Army knife with an AK-47 attached to it
3:48
that allows even the most unskilled script kitty to launch an attack.
3:52
For example, we might be able to gain access to a Windows machine with
3:55
a reverse shell.
3:56
Thanks to the Eternal Blue vulnerability,
3:58
open up the Metas-ploit console and search for Eternal Blue.
4:01
That should bring up a list of potential Windows targets.
4:03
We know that Grandpa is still on Windows 7.
4:05
So, let's go ahead and use that exploit.
4:07
From there, we can set a payload to use a reverse shell
4:09
and configure the local host to our own IP address.
4:12
And then finally, run the exploit command.
4:14
Congratulations, you just made a successful penetration.
4:17
You can now access all the files on this computer, change the desktop background,
4:20
and install even more malware.
4:22
But Metas-ploit is almost too powerful, and if you use it,
4:25
you'll miss out on a lot of cyber security learning opportunities.
4:28
The next tool you need to know about is Air Crack.
4:30
Like the name implies,
4:31
it's for hacking those magical invisible packets floating around in the air called Wi-Fi.
4:35
When you're at Starbucks enjoying a soy latte coding a NodeJS app,
4:39
there could be a guy behind the dumpster using air crack who just ran
4:41
the Airmon command,
4:43
but followed by air dump to find your network as the perfect target.
4:46
He then proceeded to run air crack to crack the Wi-Fi protected access key
4:50
and can now pull all the packets out of thin air floating on this
4:53
network.
4:53
If you're connected to a regular unencrypted HTTP website,
4:56
your sensitive data could be intercepted.
4:58
That's why you always want to make sure to use HTTPS
5:01
when submitting forms with personal data
5:03
because even if a hacker intercepts those packets,
5:05
they'll be encrypted.
5:06
Luckily though, the cops just arrested this guy
5:08
because using air crack on a network without permission is highly illegal.
5:11
But now it's time to talk about passwords. normies who watch Hollywood movies think
5:15
that hackers get access to the mainframe by running some program
5:18
that cracks their password.
5:20
>> I could launch a cyber nuke, but it'll completely fry your system.
5:23
>> And believe it or not, Hollywood movies about hacking are 100% accurate.
5:27
Kali Linux has multiple password cracking tools like John the Ripper and Hydra.
5:31
But the easiest tool to learn in my opinion is Hashcat.
5:34
First though, it's crucial to understand
5:36
that nobody in their right mind stores a plain text password in a database.
5:40
Instead, passwords get hashed with a one-way algorithm like Shaw
5:43
or BCrypt to then salt them with another random string to make them even
5:47
more difficult to crack.
5:48
Now, even if somebody steals the database,
5:50
it's still almost impossible to reverse engineer the hash back to the original password.
5:54
The key word here, though, is almost.
5:56
Let's imagine I found this hash for the president's login credentials to access the
6:00
nuclear Armageddon launch button website.
6:02
Hashcat allows us to run a variety of different strategies to figure out the
6:06
original text value of this hash. like we could try to brute force every
6:09
possible string combination.
6:11
But a more common technique is to use a file like rocku.txt
6:15
which contains over 14 million common passwords.
6:18
Once we have that,
6:18
we can then use hashcat
6:20
and specify a hashing algorithm
6:22
which in this example is MD5
6:24
because it can be cracked in just a few seconds.
6:26
But in real life with a hashing algorithm like brypt,
6:29
it might take multiple days to go through the rocky file.
6:31
In any case, it looks like President Kamacho used a weak password
6:34
and forgot to enable 2FA,
6:36
which means it's finally time to kick off Armageddon.
6:38
But you might be wondering how I even found this top secret website.
6:41
The skipfish is a tool for finding vulnerabilities on websites.
6:45
It will recursively crawl an entire website
6:47
and in the process scan for vulnerabilities like cross-sight scripting,
6:50
SQL injection, and other web application screw-ups.
6:53
It provides this nice HTML report.
6:55
And what's awesome about it is
6:57
that if you've already hacked a username
6:58
and password,
6:59
you can provide those credentials to also crawl the deep web beyond what's available
7:03
to the public.
7:03
Then when you find vulnerabilities,
7:05
you can use tools like Cross-Side Scriptor to install Worms,
7:08
just like my hero Sammy did to MySpace back in 2005.
7:11
Now, in order to be a successful cyber criminal,
7:14
you need to think like law enforcement and use their tools like Foremost,
7:17
a forensic data recovery tool built on a process called file carving.
7:21
Imagine you got access to a hard drive in Area 51 somehow,
7:24
but all the data is gone.
7:25
Well, if they did a quick format and didn't overwrite the data,
7:28
it can likely be recovered with foremost.
7:30
It doesn't even need a file system
7:31
and will scan the entire disc image bite by bite looking for unique patterns
7:35
like the bites at the beginning of a header to identify a JPEG.
7:38
When it finds the corresponding footer,
7:40
it can then reconstruct an image that you were never supposed to see.
7:43
And that's why when you end up with two shots to the back of
7:45
the head,
7:45
it'll be ruled a suicide.
7:46
At this point, we know how to map networks, websites, and hard drives.
7:50
But the golden goose for any hacker is a database
7:52
which can be sold for Monero on the dark web.
7:54
The SQL map allows you to scan a website
7:56
or server to find all the databases
7:58
and map out their schemas with all the tables
8:00
and columns.
8:01
Once you have that information,
8:02
you can start launching SQL injection attacks where you submit forms with raw SQL
8:06
statements in them to try to trick their server into running
8:09
that code.
8:09
Or better yet, print
8:10
that code out and paste it on the front of your car
8:12
and blow through a bunch of speed cameras.
8:14
But a more common attack nowadays is denial of service.
8:17
You probably know how to ping a website in Linux, but in Kali Linux,
8:20
you can use hping 3 along with the flood option to send packets
8:24
as fast as possible to an IP address without waiting for replies.
8:27
This can flood a server with traffic
8:29
and grind it to a halt
8:30
or cost the developer millions of dollars
8:32
if they host on a serverless platform.
8:34
When used on one machine, it's just a basic DOSs attack,
8:36
but if you distribute it across a botnet of all the machines
8:39
that you've hacked already,
8:40
it then becomes a DDoS attack.
8:42
Yet another great way to embark on a magical journey to prison.
8:45
But the sad reality of hacking is
8:47
that most people are victimized by those they trust.
8:49
Like I trusted Prince Hyman Cholo to transfer my inheritance after I gave him
8:53
my checking account password,
8:54
but he took all my money and went to a fish concert.
8:56
The social engineering toolkit in Kali Linux allows you to create your own sophisticated
9:00
fishing attacks using a variety of attack vectors like email,
9:04
QR codes, SMS text messages, Arduino IoT devices, and of course websites.
9:09
In fact, the tool can even clone a website,
9:11
which you can then host on your server,
9:12
and when someone finds it and enters their email and password,
9:15
it goes directly to you instead of PayPal.
9:17
But that entire attack was accomplished without writing any JavaScript code.
9:21
And with that, we've looked at 10 dangerously powerful tools for hackers in Kali
9:24
Linux.
9:25
But we've barely scratched the surface.
9:26
And you'll also want to learn about John the Ripper, Nikto, Burpuite,
9:30
just to name a few.
9:31
Actually, you know what?
9:31
Forget I ever said anything.
9:33
Nobody should know about any of these tools.
9:34
So, go ahead and look into this device real quick.
9:36
I am just a figment of your imagination.
9:43
>> All right, guys.
9:44
You just watched a tutorial about Enterprise Oracle forms with Microsoft Silver Light,
9:48
but make sure to smash
9:49
that like button and subscribe for more benign
9:51
and totally not illegal programming content.
9:53
Huge thanks to Hostinger for sponsoring
9:55
and make sure to check out their platform to get the best deal on
9:58
your own virtual private server in the industry.
10:00
Thanks for watching and I will see you in the next
Thích
Chia sẻ
Fireship
Xem tất cả →
C1
Công nghệ
Karaoke
7:22
Tragic mistake... Anthropic leaks Claude’s source code
Fireship
1
C1
Công nghệ
Karaoke
5:18
The wild rise of OpenClaw
Fireship
C1
Công nghệ
Karaoke
4:50
Google just changed the future of UI/UX design...
Fireship
C1
Công nghệ
Karaoke
9:10
The unhinged world of tech in 2026...
Fireship
C1
Công nghệ
Karaoke
5:15
Google just casually disrupted the open-source AI narrative…
Fireship
C1
Công nghệ
Karaoke
5:36
He just crawled through hell to fix the browser…
Fireship
C1
Công nghệ
Karaoke
5:36
Claude Mythos is too dangerous for public consumption...
Fireship
C1
Công nghệ
Karaoke
5:00
Anthropic just released the real Claude Bot...
Fireship
Video gợi ý
B2
Công nghệ
Karaoke
17:24
Driving Xiaomi's Electric Car: Are we Cooked?
Marques Brownlee
B2
Công nghệ
Karaoke
8:47
Macbook Neo Impressions: Reincarnated!
Marques Brownlee
B2
Công nghệ
Karaoke
11:51
Xiaomi 17 Pro Max: An iPhone... But Better!
Marques Brownlee
B2
Công nghệ
Karaoke
16:11
The Problem with this Humanoid Robot
Marques Brownlee
B2
Công nghệ
Karaoke
10:47
So This is Peak Foldable
Marques Brownlee
B2
Công nghệ
Karaoke
12:52
OnePlus 15 Review: This is Not Normal!
Marques Brownlee
B2
Công nghệ
Karaoke
32:38
Smartphone Awards 2025!
Marques Brownlee
B2
Công nghệ
Karaoke
12:53
Macbook Neo Review: Better than you Think!
Marques Brownlee