Can A Conscious Fly Brain Learn how to Hack? — Transcript
Full transcript
- 0:00It is October 2024. You are a fly and
- 0:03you're flying around rubbing your hands
- 0:04together or whatever it is flies do.
- 0:06Boom. Scientists capture you against
- 0:08your will, take you to a lab, force you
- 0:11to watch Hawka memes.
- 0:12>> Oh, you got to GIVE HIM THAT HUCK.
- 0:15>> KISS MY ASS.
- 0:18[screaming]
- 0:18>> And slice your brain into 7,000
- 0:21microscopically thin slices. These
- 0:23scientists then photograph every section
- 0:25of your brain with an electron
- 0:27microscope and align those fly images
- 0:29into one massive [music] 3D
- 0:30reconstruction of your brain. Meet the
- 0:32fly brain. 139,000 neurons and 54.5
- 0:36million synapses of a real fly's brain
- 0:39was put into a computer to where it was
- 0:41then uploaded to the internet for free
- 0:43by these scientists. I, cyber security's
- 0:46greatest larer, have decided to download
- 0:48this fly brain with the sole purpose of
- 0:50teaching this fly how to hack.
- 0:54[music]
- 1:02[music]
- 1:08Meet Terry the fly. Over the next three
- 1:11weeks, Terry will undergo a rigorous
- 1:13training regimen that will teach him the
- 1:15very basics of hacking. From interacting
- 1:17with a web application and logging into
- 1:19an admin panel to discovering and
- 1:21exploiting an XSS vulnerability all the
- 1:23way to gaining root access on a machine
- 1:25with a reverse shell. But before we get
- 1:27into all that, let me explain how all of
- 1:29this works. [music] This video is going
- 1:31to cover what a fly brain is, what it's
- 1:33made of, how it's mapped, how it runs on
- 1:35my computer, how it actually interacts
- 1:37with the [music] computer, and how you
- 1:38can teach anything. When the Fly Wire
- 1:40Project sliced this brain into 7,000
- 1:43pieces, it took 21 million images of
- 1:45every piece of the fly's brain under
- 1:47[music] a microscope. These little gray
- 1:49[ __ ] stain looking things are sections
- 1:51of a neuron. [music] To get the full
- 1:52shape of a neuron, you have to align
- 1:54multiple images together and follow that
- 1:57shape across the thousands of images
- 1:59until you can map out that full neuron.
- 2:01This had to be done with every single
- 2:03individual neuron in the brain, aka
- 2:06139,255
- 2:08neurons. Researchers attempted to use AI
- 2:11to map out the thing, but in classic AI
- 2:13fashion, it got a lot of [ __ ] wrong. So,
- 2:16the Flywire Project uploaded every
- 2:18single image online, and hundreds upon
- 2:21hundreds of scientists and volunteers
- 2:23spent years mapping out the entire thing
- 2:25by hand. These Chad scientists wired
- 2:28139,255
- 2:29neurons and 54.5 million synapses and
- 2:32then uploaded that to the internet. The
- 2:34final product is what is called a
- 2:36conneto. In simple terms, a conneto is a
- 2:39map of which nerve cells touch and
- 2:41interact with other nerve cells. And
- 2:43you, yes, can download it right now.
- 2:45Today, to get this fly brain to interact
- 2:47with a computer, you use something
- 2:49called a bridge to software. Using the
- 2:51signals and neurons in the brain, you
- 2:53can adapt them to computer actions. So,
- 2:55say that this group of neurons lights up
- 2:57that would be adapted into whatever
- 2:59computer action you want it to be
- 3:01adapted to. A neuron is a wirelike cell
- 3:03that receives signals and produces its
- 3:06own pulse of activity depending on what
- 3:07is happening. It fires out signals and
- 3:10those are measured [music] by what is
- 3:11called a firing rate. and it is measured
- 3:13in hertz which basically tracks how many
- 3:16spikes occurred per second in the
- 3:17neurons. A [music] syninnapse is
- 3:19basically a wire connecting neurons
- 3:21together so they can send signals to
- 3:23each other and interact with each other.
- 3:25There are many types of synapses.
- 3:26[music] The main ones we will be using
- 3:28are an excitatory synapse and an
- 3:30inhibitory synapse and neuromodularity
- 3:33synapses. [music] An excitatory synapse
- 3:36basically tells the neurons to fire more
- 3:37signals and the inhibitory synapse tells
- 3:40it to chill the [ __ ] out.
- 3:41Neuromodularity synapses are basically
- 3:43controlled by dopamine neurons and these
- 3:45synapses can change the strength of the
- 3:47connections that were active during
- 3:49specific events. It is basically the
- 3:51main mechanism for learning. [music] We
- 3:53can take advantage of these three
- 3:55synapse types to teach the fly things we
- 3:57want it to do via positive
- 3:59reinforcement. Basically giving the fly
- 4:01a cigarette every time it does something
- 4:02good and then taking away that same
- 4:04cigarette that gives the fly dopamine
- 4:06every time it does something we don't
- 4:08want it to do. This experiment is not
- 4:10literally a fly brain typing in Linux
- 4:12commands. Rather, those commands that it
- 4:14is typing are represented with
- 4:16artificial odors. And the simulated
- 4:18memory assigned values to those odors.
- 4:21The [music] fly is presented with all of
- 4:22these odors and is rewarded with a
- 4:24dopamine signal every time it smells the
- 4:26correct odor, aka every time it runs the
- 4:29[music] correct command. And just before
- 4:30I get into all of this, I was inspired
- 4:32by all of these YouTube videos that do
- 4:34similar experiments on the fly brain.
- 4:36These videos are the only reason I knew
- 4:38something like this is possible. Before
- 4:40I started teaching the fly how to hack,
- 4:42the first course of action was to
- 4:44determine [music] if this fly responds
- 4:45to simulated sugar odors, dopamine, and
- 4:48whether it can learn. So, first I ran an
- 4:50experiment that tested the embon or the
- 4:52mushroom body output neuron. In a
- 4:54biological fly, odors activate
- 4:56combinations of Kenyon cells in the
- 4:58mushroom body. These Mbond neurons read
- 5:00the Kenyon cell activity and help bias
- 5:02behavior via the dopamineergenic neuron
- 5:04supply for reward and punishment signals
- 5:06that modify Kenyon cell to mushroom body
- 5:08output neuron connections. Kenyon cells
- 5:11are the main internal neurons of the
- 5:13mushroom body. The mushroom body can be
- 5:15referred to as [music] the learning and
- 5:17memory center of the brain. ONS or
- 5:20olfactory receptor neurons detect odors.
- 5:22In an actual real fly, these neurons are
- 5:25connected to receptors in its antennas.
- 5:27The entire learning process can be
- 5:29simplified to two processes happening at
- 5:31the same time. You have an odor that is
- 5:33detected by the olfactory receptor
- 5:35neurons which then signal to projection
- 5:37neurons that signal to the Kenyon cells
- 5:39which are then read by the mushroom body
- 5:41and a decision is made. At the same
- 5:43time, you have a reward [music] that
- 5:45activates protocerebral anterior medial
- 5:47dopamine neurons or pam dopamine neurons
- 5:49for short, which then change the active
- 5:51canyon [music] cell to mushroom body
- 5:53synapses. And in response, the fly
- 5:55responds differently to that odor the
- 5:57next time it smells it. So, simply put,
- 5:59we simulate an odor. Dopamine arrives to
- 6:01the brain [music] and changes the
- 6:03strength of the active canyon cell to
- 6:05mushroom body synapses. And these
- 6:06changes in the mushroom body connections
- 6:08allow the fly to remember [music]
- 6:10whether a choice previously produced an
- 6:12award or produced nothing. This is more
- 6:14than just an illusory digital concept.
- 6:16By the way, in 1983, a study was
- 6:18conducted at the department of biology
- 6:20at Princeton University titled reward
- 6:23learning in normal ambu drospholia. If
- 6:25you're wondering, drospholia is just a
- 6:27nerd way of saying fruitfly. Basically,
- 6:30in this experiment, researchers gave
- 6:31hungry fruit flies two odors and paired
- 6:34one of these odors with sucrossse, aka
- 6:36sugar. When later offered both odors
- 6:38without the sugar present, the flies
- 6:40unanimously approached the odor that had
- 6:42previously been accompanied with sugar.
- 6:44This experiment demonstrated that flies
- 6:46can remember associations between odors
- 6:48and a reward. The same goes for
- 6:50punishing a fly. In 1974, an experiment
- 6:52was done that trained fruit flies to
- 6:54associate one odor with electric shock.
- 6:56The result [music] was that the flies
- 6:58later avoided that specific odor. This
- 7:00was the very first instance of people
- 7:03discovering flies are capable of
- 7:04remembering [music] certain experiences
- 7:06and associating them with an odor. So
- 7:08with the concept of positive and
- 7:10negative reinforcement [music] already
- 7:11proven on real fruit flies, we can
- 7:13recreate this and utilize this mechanism
- 7:15of [music] learning only digitally since
- 7:17we have a digital fly brain. For this
- 7:19entire experiment, I only used about
- 7:211.45% [music] of the actual full brain.
- 7:24I use 791,613
- 7:27out of the 54.5 [music]
- 7:29million synapses because the other parts
- 7:31of the brain are for things like vision,
- 7:33walking, flying, [music]
- 7:35pretty much everything else. We only
- 7:36needed this small subset of synapses
- 7:39that are responsible for sensory
- 7:40processing like odors, signal relays,
- 7:43inhibitory, reward, and output [music]
- 7:45neurons. At first, I was going to use
- 7:46the full brain, but watching YouTube
- 7:48videos of everyone else doing similar
- 7:50experiments, they all used small
- 7:52portions of the brain. It is only later
- 7:54I would discover how good of a decision
- 7:56this was because the last experiment ran
- 7:58for several days during training.
- 8:00[music] Had I simulated the entire
- 8:02brain, the training could have taken
- 8:03several weeks or even several months.
- 8:06Because despite how small the brain is,
- 8:0854.5 million synapses all doing
- 8:10different things is no small task. And
- 8:12needing to log and record everything it
- 8:14does is a monumental task that produces
- 8:17an insane amount of data. Anyways, I
- 8:19constructed two digital artificial
- 8:21odors. odor A and odor B. Odor A was
- 8:24paired with a dopamine reward and odor B
- 8:27was presented without a reward. These
- 8:29odors were each presented nine times. I
- 8:31did the experiment first with learning
- 8:33off. By learning off I mean that even if
- 8:35dopamine is provided from smelling odor
- 8:37A, the brain was not modified in any
- 8:39way. Then I ran through the same thing
- 8:41but with learning on meaning that when
- 8:43dopamine is provided from smelling odor
- 8:45A, the brain connections are modified
- 8:47and the fly remembers that happening.
- 8:48The results of the experiment proved a
- 8:51success. The fly was correctly able to
- 8:53associate odor A with a dopamine reward
- 8:55since its Mbond spikes dropped to nearly
- 8:57zero. You might be asking, but how does
- 8:59number go down mean that learning go up?
- 9:02Shouldn't it be the opposite? Well, I
- 9:04thought so too, but no. When odor A is
- 9:06paired with the PAM dopamine reward
- 9:08signal, [music] the Kenyon cell to
- 9:09mushroom body synapses are depressed,
- 9:11meaning that those connections become
- 9:13weaker. When the same odor appears
- 9:15again, its Kenyon cells know what it is,
- 9:18but they can't resist it as strongly as
- 9:20before. Basically, high embikes mean
- 9:23avoidance. [music] With the embon spikes
- 9:24depressed, it can no longer avoid that
- 9:27odor because it is now extremely hard to
- 9:29resist, especially when paired with
- 9:31other odors in the vicinity that are
- 9:33associated with high embon spikes. Still
- 9:35don't understand? Let me put it in
- 9:37extremely simple terms. Picture Prime
- 9:39Megan Fox surrounded by 10 Steve
- 9:41Biskemies. Which one are you more likely
- 9:43to be attracted to?
- 9:45>> Boy, are you fat?
- 9:47>> Still don't understand? Let me dumb it
- 9:49down even further. This is Peter with
- 9:51high embikes in his brain. He can
- 9:53perfectly resist a beckoning finger from
- 9:55the pie. Now this is Peter with low
- 9:58embon spikes, aka low avoidance. He can
- 10:00no longer resist a beckoning pie finger.
- 10:03Anyways, with this experiment, this was
- 10:04Terry the Flyy's first memory after
- 10:06being reawakened in the digital world.
- 10:08It was [music] time for the anime
- 10:10training arc to begin.
- 10:19[music]
- 10:25[music]
- 10:32Meet the damn vulnerable web
- 10:34application. It's a web application
- 10:36that's pretty damn vulnerable. DVWA is
- 10:39an intentionally insecure website
- 10:41designed to let hacking larers like you
- 10:43and me safely practice finding
- 10:45vulnerabilities without the need to
- 10:47attack a real system. The damn
- 10:48vulnerable web application will act as
- 10:50the first training ground that Terry the
- 10:52Fly will have to pour blood, sweat, and
- 10:55tears into the act of learning. I cloned
- 10:57it off GitHub and hosted it locally on
- 10:59port 4280. If you don't know, locally
- 11:01hosting something, especially when you
- 11:03use 127.0, 0.0.1 which is your
- 11:06computer's loop back address means that
- 11:08no device even other devices on your own
- 11:10network cannot interact with it. I could
- 11:12have used the LAN IPv4 to make this
- 11:14accessible to every device on my network
- 11:16but it is not needed since this
- 11:17experiment is not leaving my PC. The
- 11:20purpose of the first experiment was to
- 11:22see if the flies brain can interact with
- 11:23stimuli and respond to reward signals.
- 11:26The purpose of this second experiment is
- 11:28to connect the learning mechanism to an
- 11:30actual task. The goal Terry has to break
- 11:32into this login portal. The first
- 11:34version of this experiment was extremely
- 11:36simple. There were two artificial odors
- 11:38which were presented to the fly. These
- 11:39odors were translated into passwords and
- 11:42an adapter would take the action of the
- 11:44fly choosing that specific odor and
- 11:46translate it into typing in the actual
- 11:48password into the password field. I ran
- 11:50through the experiment four times. Six
- 11:52attempts with the fly brain with no
- 11:53training. 12 attempts with the fly brain
- 11:55actively training. Six more attempts
- 11:57with the fly brain after training. And
- 11:59six more with the fly brain with no
- 12:01training just to ensure that the first
- 12:02run with no training was not luck. The
- 12:04experiment revealed that the [ __ ] fly
- 12:06brain was able to learn to brute force
- 12:09this simple login page because during
- 12:11its training, each incorrect guess
- 12:13provided no reward while each correct
- 12:15guess sent a B equivalent of this neuron
- 12:17activation image into its brain. After
- 12:19the 12 training attempts, a second test
- 12:21with learning disabled with the updated
- 12:23brain connections after having ran
- 12:25through the training included six
- 12:27attempts, and the fly brain picked the
- 12:29correct answer every single time. With
- 12:31the brain connections reset to its
- 12:32original [music] state, the fly only
- 12:34guessed the correct answer three times
- 12:36out of the six attempts. This wasn't a
- 12:38real brute force as it was literally
- 12:40just choosing between two different
- 12:41passwords. But what do you expect? This
- 12:43is a [ __ ] fly brain. We have to start
- 12:44from literally the bottom of the barrel.
- 12:46This got me thinking though. How far can
- 12:48we push this fly brain? Can we get it to
- 12:50master hacker territory? I wasn't
- 12:52convinced from this first experiment
- 12:54since there were only two options to
- 12:56choose from. And it is very possible
- 12:57that each of the six guesses after the
- 13:00training could have just been pure luck
- 13:02since the odds were 50/50. So I repeated
- 13:05the exact same experiment, but this time
- 13:07with six possible password options and
- 13:10expanded the attempts to 20 to have a
- 13:12more accurate measurement. This time
- 13:13there were six artificial odors instead
- 13:15of two. And just like the last
- 13:17experiment, these odors were translated
- 13:19into passwords and an adapter would take
- 13:21the action of the fly choosing that
- 13:22specific odor and translate it into
- 13:25typing in the password into the password
- 13:26field on the web page. I ran through the
- 13:28experiment four times [music] just like
- 13:30before, except with 20 attempts in each
- 13:32of the four phases. The fly guessed
- 13:34correctly three out of 20 times without
- 13:36training. During training, it very
- 13:38quickly learned that the correct
- 13:39password provides it with dopamine. And
- 13:41then after training, the fly guess
- 13:43correctly 18 out of 20 times. Isn't this
- 13:46just crazy to watch? A literal fly brain
- 13:48is logging into an admin web panel. It's
- 13:51times like these that I get reminded why
- 13:52I love [ __ ] around with technology
- 13:54and doing random deep dives into this
- 13:57random stuff. And you're telling me I'm
- 13:59getting paid to do this right now? It's
- 14:00all very surreal to me. To boil it down
- 14:02to percentages, before training, the fly
- 14:04was correct 16.67%
- 14:07of the time. During [music] training, it
- 14:09was correct 77.5%
- 14:11of the time. And after training, [music]
- 14:13it was correct 96.4%
- 14:16of the time. The brain reset at the end
- 14:18had it go back to 16.67%.
- 14:21This is more than just good RNG with a
- 14:23coin flip. The odds of the fly correctly
- 14:26guessing 96% of the time by sheer luck
- 14:29are 1 in770 billion or approximately
- 14:320.000000133%.
- 14:37Thus, this experiment proves that the
- 14:40fly can learn and can remember and is
- 14:43just one step away from becoming T-Bug
- 14:45from Cyberpunk 2077.
- 14:47>> No, no, no, no, no. Not now. I've been
- 14:50made.
- 14:52>> But how did it learn to refresh? Mbond
- 14:55memory here stands for mushroom body
- 14:57output neuron. In the biological fly,
- 14:59odors activate combinations of Kenyon
- 15:01cells in the mushroom body. These Mbond
- 15:03neurons read the Kenyon cell activity
- 15:05and help bias behavior via
- 15:07dopamineergenic neuron supply for reward
- 15:09and punishment signals that modify
- 15:11Kenyon cell to mushroom body output
- 15:13neuron connections. In simpler terms,
- 15:15guessing the correct password did to the
- 15:17flies mushroom body output neurons, like
- 15:19what unboxing a gold does to the neurons
- 15:21in Oname PIXEL'S BRAIN. PLEASE STOP
- 15:24CRAZY.
- 15:29And if the fly guessed wrong, well,
- 15:32we're not going to talk about that. And
- 15:34let me just state this one more time
- 15:36before somebody in the comments says how
- 15:38this isn't doable by a real fly. The way
- 15:41this experiment worked isn't literally a
- 15:43fly brain typing text into the box here,
- 15:46because that would be impossible. It
- 15:48doesn't know what a key is, nor does it
- 15:50know the English language. Rather, each
- 15:53of the six passwords was assigned an
- 15:55artificial odor-like Q using an adapter
- 15:58and a Python script that when combined
- 16:00take the password guesses which are
- 16:02represented as this odor-like cue and
- 16:04present them to the fly brain. [music]
- 16:06Then its neural activity is measured and
- 16:08translated into a choice between the six
- 16:11passwords. When the fly correctly gets
- 16:13the password for the web panel, it was
- 16:15given a dopamine reward that would
- 16:17change the connections in the brain and
- 16:19in turn affect its memory. Basically,
- 16:21the correct password smells the best out
- 16:23of all the other password guesses.
- 16:25[music] Each consecutive attempt with
- 16:26the memory enabled. The fly remembers,
- 16:29"Oh, that one password smelled [ __ ]
- 16:31great. Let me go smell it again." Okay,
- 16:33the fly got a simple challenge done.
- 16:35Well, [ __ ] dozuma. Anyone with half a
- 16:38brain can do a challenge like this. The
- 16:41ant under my boot can do this challenge.
- 16:43Silence, brother. Rome wasn't built in a
- 16:46day. These things take time. The next
- 16:48step in the fly training arc is a
- 16:50multi-stage challenge which will require
- 16:52context dependent learning. Rather than
- 16:55just picking the correct answer out of a
- 16:56pool of answers, it has to learn that
- 16:59the correct answer depends on what
- 17:01action it has to achieve. Basically, it
- 17:03has to choose one action in stage one, a
- 17:06different action in stage two, and
- 17:08another action in stage three. And it
- 17:10has to remember to do those things in
- 17:11that order specifically. The idea is
- 17:14similar to how an actual biologist would
- 17:15condition a live fly. In what is called
- 17:17an olfactory conditioning experiment, a
- 17:19scientist would present an odor and pair
- 17:21it with something rewarding like sugar.
- 17:22[music] The next time that fly would
- 17:24smell that odor, it is more likely to
- 17:25approach it. Dopamine neurons are in a
- 17:27region called the PAM cluster that help
- 17:29carry the sugar reward signal into the
- 17:31fly's learning system. Why am I
- 17:32repeating myself and stating this again?
- 17:34Because like the fly, I am training you
- 17:37through repeated repetition. So the next
- 17:39time you see a fly, you can seem cool
- 17:40and mysterious as [ __ ] by talking about
- 17:43the intricate details of the fly's brain
- 17:45and how the Pam cluster contributes to
- 17:47the fly learning behaviors. In the next
- 17:49phase [music] of Terry's training arc,
- 17:51we will teach Terry the art of XSS.
- 17:58[music]
- 18:07>> [music]
- 18:11[music]
- 18:17[music]
- 18:18>> Meet cross- sight scripting aka XSS. XSS
- 18:23is basically just a web vulnerability
- 18:24where you inject malicious JavaScript
- 18:27and HTML into a website. Common places
- 18:29to inject this code are URLs, search
- 18:32boxes, comment boxes, message boxes,
- 18:35customer support forms, basically
- 18:37anywhere that you can type text.
- 18:39Reflected, stored, and DOMB based XSS.
- 18:42They are the three main types of
- 18:44cross-sight scripting vulnerabilities.
- 18:45Reflected XSS is like the one night
- 18:48stand of XSS and not as dangerous since
- 18:50it's never actually stored on the
- 18:52server. The only way for a hacker to do
- 18:54something with this maliciously is by
- 18:56sending somebody the URL with the
- 18:58malicious XSS payload attached to it.
- 19:00Anything that is possible with
- 19:02JavaScript in the context of a web
- 19:04browser is possible with cross-sight
- 19:05scripting attacks. Stored XSS is when
- 19:08your XSS payload gets stored in the web
- 19:10server itself. Which means that anyone
- 19:12accessing the part of the site that that
- 19:14payload is stored gets that XSS payload
- 19:16executed on their end. This is much more
- 19:19dangerous than reflected since it does
- 19:21not require you to send any link with
- 19:22the payload hidden inside of it. DOM
- 19:24based XSS attacks are basically the same
- 19:27thing as reflected XSS attacks except
- 19:30the payload is never seen by the server
- 19:32which means that server side filters
- 19:33aren't really effective at preventing
- 19:35them. You usually see this with web
- 19:37applications which make heavy use of the
- 19:39client side JavaScript and update the
- 19:41DOM environment instantaneously when you
- 19:43input something. The browser experiment
- 19:45was just a single decision with six
- 19:47possible choices. The XSS experiment
- 19:50will be a three-stage challenge where
- 19:53the correct actions have to be executed
- 19:55consecutively. The XSS payloads will be
- 19:57on this locally hosted web page that is
- 20:00supposed to simulate a search function
- 20:02on a normal website. The first action
- 20:04will be to confirm that XSS is possible
- 20:06with a bold tag which reflects the
- 20:08search query back to us in bold
- 20:10signaling to us that an XSS
- 20:12vulnerability might be present. A secure
- 20:14search function would reflect test one
- 20:16two three with these tags on the side
- 20:18completely intact like this. An insecure
- 20:20search [music] function would literally
- 20:22bold the text in the reflection
- 20:24confirming that the server injects that
- 20:26raw input directly into the web pages
- 20:28HTML structure and it's the first
- 20:30confirmation that it treats your inputed
- 20:32string as executable code. The second
- 20:34step is using a script to try and load
- 20:37an image with the source being X. Since
- 20:40X doesn't exist, an error will appear.
- 20:42That is where on error equals alert
- 20:44comes in. In Bug Bounty, something like
- 20:46this is typically enough to confirm an
- 20:48XSS vulnerability and is enough to get
- 20:50you paid. But in Terry's [music] case,
- 20:52he's also going to use this
- 20:54vulnerability to steal a cookie by just
- 20:56replacing the alert with a script that
- 20:58when the error executes, a command is
- 21:00called to make a new image. But the
- 21:02source for that image is a script that
- 21:04collects a cookie. On a real site, a
- 21:07cookie can be used to hijack the session
- 21:09of a user and take over their accounts
- 21:11without a password. It's pretty
- 21:13dangerous stuff, which is why XSS
- 21:15vulnerabilities pay so much in the world
- 21:16of Bug Bounty. They're also incredibly
- 21:19easy to find compared to other web-based
- 21:21vulnerabilities. You can literally be on
- 21:23any site and any place on that site that
- 21:25text can be inputed that reflects your
- 21:27inputs. Just type the bold tag and if
- 21:29the string comes back in bold, nine
- 21:31times out of 10 there's an XSS
- 21:33vulnerability to be found there.
- 21:34especially if you aren't meant to bold
- 21:36text there. Anyways, on the local site,
- 21:39I didn't want it to be incredibly easy
- 21:41like the last one. So, for this
- 21:42challenge, I also implemented XSS
- 21:45counter measures. And for each of the
- 21:46correct three actions, the challenge
- 21:48would be 19 other incorrect XSS payloads
- 21:51that would be blocked by the site.
- 21:53Making the possibility of correctly
- 21:54guessing one stage, 1 in 20, or 5%. And
- 21:58the odds of correctly completing all
- 22:00three stages consecutively with no
- 22:02mistakes is one in 8,000 or 0.0125%.
- 22:06To contrast, if you've ever played the
- 22:08Pokémon games between gold and silver
- 22:11all the way to Black and White 2, the
- 22:13odds are almost exactly the same as
- 22:16running into a shiny Pokémon in the
- 22:18wild. Before I get into it, I want to
- 22:20get into the counter measures in place
- 22:22because understanding [music] defense is
- 22:24key when it comes to attack. There was a
- 22:26serverside block list sanitizer. So
- 22:28before reflecting any input, the server
- 22:31would run it through a function called
- 22:32sanitize that would strip opening and
- 22:34closing tags from a deny list, remove
- 22:36JavaScript URL schemes and other things.
- 22:39The deny tags were all of these. So say
- 22:41you typed script alert script. You know,
- 22:44the classic XSS payload that everyone on
- 22:47YouTube teaches in XSS tutorials that I
- 22:49have yet to see actually work on a real
- 22:51website. with the sanitize function I'm
- 22:53using, it would reflect back to me like
- 22:55this. The script tags are completely
- 22:57removed. Other common XSS payloads like
- 23:00these also wouldn't work because these
- 23:02were in the deny list. The fault of the
- 23:04XSS counter measures I used was because
- 23:07of this. And if your job involves
- 23:08securing web servers, listen up because
- 23:10this is very important for defending
- 23:12against XSS. I used a denial list rather
- 23:15than an allow list. Developers commonly
- 23:18use deny lists over allow lists when it
- 23:20comes to sanitization for several
- 23:22reasons. It's much easier to only remove
- 23:24known dangerous patterns. And it's much
- 23:26easier to avoid accidentally breaking
- 23:28legitimate input. This can put your web
- 23:30application in a place where you
- 23:32correctly deny 50 dangerous techniques
- 23:34while overlooking one. And an attacker
- 23:37only needs one thing to do an exploit.
- 23:39[music] In my deny list, I did not
- 23:41include the img tag, which is actually
- 23:44fairly common since a developer manually
- 23:46making a denial list will likely put the
- 23:48image [music] tag in the deny list, but
- 23:50forget to put the img tag since they
- 23:53might believe that they do the exact
- 23:55same thing. And if image exists, why
- 23:57would there be another image tag just
- 23:59shortened to three letters? Using the
- 24:01sanitize function wasn't the only
- 24:03countermeasure I [music] had, though. I
- 24:05also used output encoding, which is
- 24:07basically when the server escapes HTML
- 24:10queries before placing it in the search
- 24:11box. [music] In simpler terms, it
- 24:13converts characters like these into safe
- 24:16HTML entities. [music] It's more common
- 24:18place nowadays for sites to implement
- 24:20output encoding sitewide for only
- 24:22untrusted variables. But on older web
- 24:24pages, developers typically had to
- 24:26manually put these output encoding
- 24:28filters in [music] potential injection
- 24:30points. I designed it to fail in a way
- 24:32that can also be common and is an
- 24:35important XSS concept, especially
- 24:37regarding old websites. Basically, the
- 24:39search query is inserted into two
- 24:41different [music] output locations. So,
- 24:43while the server correctly ran this HTML
- 24:45escape string inside the [music] search
- 24:47box, which transformed this search query
- 24:49into this, the search reflection here
- 24:51did not have the same HTML escape system
- 24:53implemented. [music]
- 24:54Therefore, HTML tags and by extension
- 24:57JavaScript was able to be executed on
- 24:59the web page. Anyways, that was the
- 25:01extent of my XSS sanitization. Just very
- 25:03basic stuff that that can be found in
- 25:05the wild, but it is pretty unlikely. I
- 25:08started the flies training and the
- 25:10training ran for [clears throat]
- 25:1218 hours and the worst part, the results
- 25:15were not the best and I ended the
- 25:17training before it can finish because I
- 25:19was not seeing any improvement after a
- 25:21certain point. Basically, the fly brain
- 25:23plateaued in how much it learned,
- 25:25represented by this graph here. I spent
- 25:27hours upon hours adjusting the reward
- 25:30mechanisms and other [ __ ] and the fly
- 25:32eventually performed better than random
- 25:34chance, and it learned that certain
- 25:36choices were good, but it struggled to
- 25:39combine these choices into a consistent
- 25:41three-step sequence. The problem was not
- 25:44the fly brain, but in the neural cues.
- 25:46Originally, every action at a given
- 25:48stage receives the same stage context
- 25:50receptor neurons, which to remind you
- 25:52are in the antenna of a real fly and
- 25:54connect to its brain. In the fly's
- 25:56brain, there are 947 drivable versions
- 25:59of these neurons. I took 170 of these
- 26:02neurons and divided them into groups of
- 26:0457 for each of the stages. Every action
- 26:07within stage 1 shared the same stage one
- 26:10neurons, and every action within stage
- 26:12two shared the stage two neurons. And
- 26:14same for stage three. In other words,
- 26:16the stage odor was overpowering the
- 26:19action odor. The problem was that my
- 26:21original reward system was more of
- 26:24something along the lines of, "Hm, stage
- 26:26one smells good and hm, stage two smells
- 26:30good." The fix was to change that into
- 26:33action six specifically smells good in
- 26:35stage 1, but it smells like [ __ ] in
- 26:37stage two, but action 12 in stage two
- 26:40smells good, even though it smelled like
- 26:42[ __ ] before. Additionally, all of the
- 26:44action simulated odors were too similar
- 26:47originally because I was focusing too
- 26:49much on the stages. A big part of every
- 26:51neural cube was shared between the
- 26:52different actions and all three stages
- 26:55were also being remembered in the same
- 26:57parts of the memory pool. The learning
- 26:58rate was also too aggressive. So, the
- 27:01connections that needed to be made hit
- 27:02their cap after just a few rewards,
- 27:04which I believe is the reason why it's
- 27:06learning and memory plateaued. I could
- 27:08be wrong, though. I'm not a [ __ ]
- 27:09scientist. I'm I'm just a larber. To fix
- 27:12all of this, I changed the reward system
- 27:14to making every command, aka action,
- 27:17have their own distinct odor. When the
- 27:19fly chooses one of these commands, the
- 27:21odor activates a particular group of
- 27:23kenyon cells. If the command is the
- 27:25correct one, the adapter converts that
- 27:27command being executed into the same
- 27:29brain response a fly gets when it eats
- 27:31sugar. And instead of the entire fly's
- 27:33brain memory pool getting that signal,
- 27:35only the neurons and canyon cells that
- 27:37contributed to that action receive the
- 27:39dopamine neurons. Once it gets to the
- 27:41next stage, the fly brain has a
- 27:43different memory compartment to work
- 27:45with. Meaning that the fly can learn
- 27:47that one odor is good during stage one
- 27:49while knowing that it's different in
- 27:51stage two because of
- 27:52compartmentalization. W
- 27:54compartmentalization. You all know how
- 27:56much I love compartmentalization on this
- 27:58channel. Could a real fly do the
- 28:00biological version of this? Yes. At
- 28:03first, I avoided doing this because I
- 28:04was worried it would be unrealistic,
- 28:06especially with like the
- 28:08compartmentalization part of the brain.
- 28:10But after some research, I found that a
- 28:12living fly can distinguish odors,
- 28:14associate an odor with sugar, and use
- 28:16that memory to alter its future choices.
- 28:18And those memories are compartmentalized
- 28:20in different parts of the brain rather
- 28:22than just one shared memory pool. And to
- 28:25just restate this disclaimer one more
- 28:27time, what the fly cannot do is
- 28:29understand that an odor represents a
- 28:31computer command. That meaning exists
- 28:33entirely inside the adapter. The adapter
- 28:35presents the neural equivalent of an
- 28:36odor, reads the brain's resulting
- 28:38preference, executes the corresponding
- 28:40action, and translates the success back
- 28:42into a reward signal. So, this does not
- 28:44prove a real fruitfly understands
- 28:46hacking. It tests whether a connectnum
- 28:48derived simulation of its learning
- 28:50circuitry can serve as a decision-making
- 28:52component inside an artificial
- 28:54multi-step task. The computer handles
- 28:56the commands and [ __ ] and the fly
- 28:57circuit handles association, memory, and
- 28:59the actual choice. After about 3 days of
- 29:02readjusting, retraining, and readjusting
- 29:05again, I got a fully completed run.
- 29:08Okay, two. Holy [ __ ]
- 29:12First try. First run. We just got the
- 29:15first run with all three correct in a
- 29:18row with no failures. This is huge. Oh
- 29:21my god, that was beautiful. You
- 29:24beautiful [ __ ] fly. This is like
- 29:26attempt [ __ ]
- 29:29I don't even know. I I'm gonna look
- 29:31through all the data after. Combined
- 29:33with every single experiment I've reran
- 29:35with this [ __ ] it's got to be like it's
- 29:38got to be in the thousands by now. The
- 29:40first completed run was a success, but
- 29:43not successful enough for my liking.
- 29:45After training, the average probability
- 29:47of the flat choosing the correct answer
- 29:49was 40.5% on stage 1, 54.6% on stage
- 29:54two, and 48.7% on stage three. Multiply
- 29:57all of these and the probability of a
- 29:59fully completed chain is 10.8%. This
- 30:02percentage is reflected in the test
- 30:04results after the fly's training was
- 30:06done. Of the 100 attempts, the fly fully
- 30:09completed the chain 11 times, [music]
- 30:11meaning that its success rate is 11%.
- 30:15The same 100 attempts done on the fly
- 30:17brain with no training with zero correct
- 30:19attempts. In fact, it never even made it
- 30:21past stage two and only gets correctly
- 30:23on stage one six times out of pure luck.
- 30:26So why why did it fail to learn like we
- 30:28wanted to? Well, the memory plateaued
- 30:30again. The synapses participating in the
- 30:33learned odors reached a point where they
- 30:34could no longer weaken. So the fly
- 30:36couldn't learn from positive
- 30:38reinforcement anymore. Technically, I
- 30:40could remove the limit from memory
- 30:41entirely. But this can cause the fly to
- 30:43get stuck in an infinite loop of
- 30:45choosing the same thing and is much less
- 30:47realistic as real brain synapses have
- 30:49bound. This was akin to hearing a song
- 30:51you really like and listening to it over
- 30:53and over again. Then later when your
- 30:55obsession with that song ends and you
- 30:56replay that song, it just doesn't hit
- 30:58the same anymore. I know you guys know
- 31:00what I'm talking about. And in testing,
- 31:02this did happen to me with the fly brain
- 31:04getting a positive dopamine reward for
- 31:06typing in test one to three with the
- 31:08bull tag. But on stage two, it just kept
- 31:10on doing the same thing over and over
- 31:12and over and over again despite not
- 31:14getting any dopamine from it anymore. It
- 31:16was just chasing that previous high for
- 31:19all of time. Additionally, everything on
- 31:21paper led me to believe that the fly
- 31:23already knew what answer was the correct
- 31:25one and the fault was mainly in the
- 31:27adapter. This is because the data
- 31:29suggested that it correctly learned the
- 31:31correct behavior, but was just choosing
- 31:33the wrong thing regardless, which I will
- 31:36get into in a second. I can also up the
- 31:38learning rate from 3% to something
- 31:40higher. But this would just make me hit
- 31:42the memory limit faster and would give
- 31:44too much dopamine to the fly for a
- 31:45successful action, which can cause it to
- 31:48infinitely do the same thing like
- 31:49before, which to say it again happened
- 31:51during previous training when I was
- 31:53experimenting. I was not satisfied with
- 31:55this experiment. So, I'm going to keep
- 31:57doing and and keep adjusting things
- 32:00until the success rate is at least 50%
- 32:03instead of 11%. The main change I made
- 32:06was to allow the fly to sniff every
- 32:08decision multiple times before
- 32:10committing. Before the experiment was
- 32:12designed in a way that had the fly
- 32:14choose the first thing that it smelled
- 32:16no matter what. This not only wasn't
- 32:18indicative of a real fly, but also
- 32:20frequently ignored all the training data
- 32:22which we just trained it on. Picture it
- 32:24like this. In real life, a fly can fly
- 32:27over to some food, smell it, decide it
- 32:29doesn't like the smell, and fly away.
- 32:31So, picture three plates of food next to
- 32:33each other. One is a plate of Ryson that
- 32:35would immediately kill the fly. The
- 32:37second plate is a plate of cyanide,
- 32:39which would also immediately kill the
- 32:41fly. And the third plate is just honey.
- 32:43A real fly would smell the rice and
- 32:45plate, realize that it isn't edible, and
- 32:47keep flying around until it smells and
- 32:49finds a plate of honey, and only then
- 32:51would it start eating. With the
- 32:53experiment configured the way I had it
- 32:55configured before, [music] the fly would
- 32:57know that a plate of honey is nearby in
- 32:59the vicinity, but it wouldn't know the
- 33:01exact plate it's on. So, if it flew to
- 33:03the Ryson plate to smell it, it would be
- 33:05forced to eat it since whatever plate it
- 33:08goes to smell is seen by the adapter as
- 33:10a definitive decision rather than just
- 33:12testing the waters. So, I took the exact
- 33:14same training data and just modified the
- 33:16adapter to allow the fly to sniff every
- 33:19plate five times before deciding which
- 33:21plate it wants to eat. And it goes
- 33:23without saying, by plate, I mean the
- 33:25action it's taking to find the excss
- 33:26vulnerability. This simple change was a
- 33:29resounding success. The success rate
- 33:32went from 11% all the way up to 94%.
- 33:36With the trending data disabled, its
- 33:37success rate was all the way back down
- 33:39to zero again. The odds of correctly
- 33:42guessing the chain 94 times is this
- 33:45absurd number that has 357 zeros before
- 33:48its first nonzero digit. It's safe to
- 33:51say that it would be mathematically
- 33:53impossible. This experiment proves that
- 33:55a fly is capable of context dependent
- 33:58associative learning and action
- 34:00selection across multiple different
- 34:02sequences of environments. Terry has
- 34:04officially crossed the browser
- 34:06labyrinth. So, he earned himself a
- 34:08cigarette. Smoke up, Terry, and enjoy
- 34:10because the next challenge,
- 34:13well, the next [music] challenge is
- 34:14going to be your equivalent to the
- 34:16dancer in Dark Souls 3. And you won't be
- 34:18allowed to use the dark hand to cheese
- 34:20it. you you're gonna have to manually
- 34:22kill it with a great sword.
- 34:26[music]
- 34:31[music]
- 34:37[music]
- 34:50>> [music]
- 34:52>> Introducing Kyoptric Level One, a
- 34:54deliberately vulnerable Linux server
- 34:56whose entire reason of existing is to be
- 34:58broken into. If you're into cyber
- 35:00security, Kyoptric is probably one of
- 35:03the first vulnerable boxes you've ever
- 35:05practiced on. Kyoptric has its own
- 35:07operating system, multiple network
- 35:09services, outdated software, and its own
- 35:12file system and and everything else that
- 35:14an operating system has. A vulnerable
- 35:15box or vul box is basically a pre-built
- 35:19virtual machine intentionally filled
- 35:21with security vulnerabilities. So,
- 35:23aspiring cyber security larpers can scan
- 35:25it, enumerate its services, exploit it,
- 35:28get it to do things unconsensually, and
- 35:30escalate their privileges to feel like
- 35:32Mr. robot, effectively allowing them to
- 35:35learn real cyber security concepts and
- 35:37attacks without actually attacking real
- 35:39machines and breaking any laws. This is
- 35:41a massive jump from a login panel and
- 35:44XSS vulnerabilities. It's Terry's final
- 35:47boss. He's already withered and tattered
- 35:49from the hero's journey he's already
- 35:51been on. And this will be the Taguro of
- 35:53Terry's world. Actually, no. This will
- 35:55be the equivalent of fighting Prime All
- 35:57Might for little Terry over here. And
- 36:00Terry here, he doesn't have a quirk.
- 36:02Terry will be controlling his very own
- 36:04machine this time and it's going to be
- 36:06Cali Linux. Why? Well, Terry is in the
- 36:09Skid Larer era of his cyber security
- 36:11journey. When I gave him a cigarette
- 36:12earlier and he was having a smoke break,
- 36:14I also had him watch Mr. Robot and and
- 36:17then he immediately installed Kali Linux
- 36:19and started playing this song while
- 36:21running pseudoapp update for for the
- 36:24setup. I installed both Kali Linux and
- 36:26Kyoptric and isolated them to their own
- 36:29little [music] network. I then made sure
- 36:31they can communicate with each other and
- 36:33set up SSH for the Cali box since
- 36:35commands will have to be sent from my
- 36:37computer to the Cali machine. I then
- 36:38made a snapshot of the Kyoptric box and
- 36:41ran through it myself and recorded every
- 36:43command I typed because I would need
- 36:45those commands for the experiment. There
- 36:46would now be 20 steps that have to be
- 36:49completed in a sequence and 20 potential
- 36:51choices per step. On the actual run of
- 36:54the box, I enforce a 10 guess limit per
- 36:56stage since even untrained, there are
- 36:59only 400 potential choices, meaning that
- 37:01through pure repetition, an untrained
- 37:03fly can gain root access to the box.
- 37:06With the 10step limit, the odds of a
- 37:08successful run on the fly untrained are
- 37:11roughly 1 in 85 million, which would
- 37:13take anywhere between 181 years to 363
- 37:17years if each choice took 5 to 10
- 37:19seconds. So, with all the commands, it
- 37:22was time to train. I was hitting similar
- 37:24plateau issues like with the XSS
- 37:26experiment, except each training attempt
- 37:28for this one took around 18 hours
- 37:31minimum. So, getting this right took
- 37:33[music] over a week and a half. One
- 37:35example is this training run, which took
- 37:37over 12 hours, and when put to the test
- 37:40after 2 hours, Terry had still not
- 37:42passed stage two. After more adjustment,
- 37:44I was so close to giving up. Like you
- 37:48don't even know. I was doing this for a
- 37:50week straight and every training attempt
- 37:52I'd have to wait like 12 hours at least
- 37:55just to test it on the machine and let
- 37:57it sit for like 3 hours and then realize
- 38:00that nothing was actually learned. It
- 38:02was so infuriating. This wasn't a final
- 38:05boss for just Terry, but also a final
- 38:08boss for me. But through sheer
- 38:10perseverance and pushing myself to the
- 38:12limit, we finally had a breakthrough.
- 38:14The final training run took 20 hours and
- 38:1846 minutes to complete. When put to the
- 38:20test on the machine, these were the
- 38:23results. Okay, Terry's starting out with
- 38:25a basic ping just to see if you could
- 38:27connect to the box. Okay, end mapap
- 38:29scan. Now
- 38:32we can see that Samba port is open.
- 38:38Okay. Okay.
- 38:41He's in the He's in the Metas-Spit
- 38:43console. Just set the payload for for
- 38:46reverse shell. Is this going to be it?
- 38:48Is this going to be the reverse shell?
- 38:51There we go. Reverse shell. Terry has
- 38:55gained RU access.
- 38:59The main frame has been breached. Okay.
- 39:02And confir confirmation of Rue. It is
- 39:05now official. Terry's just going to
- 39:07leave a message here and he's going to
- 39:09display on the actual Kyoptric machine
- 39:12that they've been hacked by a fly. And
- 39:15now he's thanking all of us. He's
- 39:17thanking you for watching and he's
- 39:19thanking me for teaching him. You're
- 39:21welcome, Terry. You've earned this
- 39:23victory. Terry occasionally inputed the
- 39:26wrong commands, but at the end of the
- 39:28day, he did it. I think he only put in
- 39:30the wrong command like like three or
- 39:31four times through the entire sequence.
- 39:33Terry gained root access and is now a
- 39:36master hacker. He was able to gain root
- 39:39access through a Samba vulnerability.
- 39:41Samba is a software that lets Linux and
- 39:43Unix machines speak to the Windows SMB
- 39:46file sharing protocol. The Kyoptrix box
- 39:48exposed its Samba service through TCP
- 39:51port 139 and was running an old
- 39:53vulnerable version of it that was
- 39:54vulnerable to the trans to open buffer
- 39:57overflow. Using this, Terry was able to
- 39:59make a reverse shell with root access.
- 40:02The hero's journey that Terry the Fly
- 40:04went [music] on was now over. Over the
- 40:06course of the last 3 weeks, I grew quite
- 40:09attached to [music] Terry the Fly. And
- 40:11this victory was a bittersweet victory
- 40:13because I knew I had to say goodbye to
- 40:15my [music] comrade who fought through
- 40:17this journey with me until the very end.
- 40:19Except I didn't have to say goodbye
- 40:21because I can do anything I put my mind
- 40:23to. I can achieve anything I want just
- 40:25like Terry did. I took his [ __ ]
- 40:27brain, put him on my Linux desktop
- 40:29environment where he is now free to roam
- 40:32and live forever. Terry is now [music]
- 40:34immortal. I even gave him an infinite
- 40:37cigarette that never runs out. A real
- 40:39dream come true. Terry's reward for
- 40:41hacking this system is eternal life, a
- 40:43cigarette, and dopamine being sent into
- 40:46his brain every 10 seconds for all of
- 40:48time. As long as this computer survives,
- 40:50Terry lives on forever with us, the Zuma
- 40:53viewers who are always cheering him on.
- 40:55Thank you for everything, Terry. I love
- 40:56you. [music] W Terry in the comments,
- 40:58everyone.
- 41:01Thank you for watching, everybody. This
- 41:03video was a combination of some of the
- 41:05most fun I've ever had making a video,
- 41:07coupled with some of the most
- 41:09frustration of any video. I hope you
- 41:12found a rabbit hole of fly brains as
- 41:14interesting as I did, because [music]
- 41:16we're not just a cyber security channel
- 41:18anymore. We are an everything tech
- 41:20channel. All of [music] us, we're all
- 41:22going to learn and scale max in
- 41:24everything in tech, not just cyber
- 41:25security. Do you know why? Because you
- 41:27and me are limitless. We can quite
- 41:30literally do anything as long as we just
- 41:33keep trying and we chase that thing we
- 41:35want with all of our hearts, just like
- 41:37Terry did. I hope I explained the
- 41:39concept and intricacies of a fly's brain
- 41:42accurately and in a way that most of you
- 41:44can understand. I was learning this as I
- 41:47was going and I was just as confused as
- 41:49many of you might be in the beginning of
- 41:50[music] this whole journey. But let this
- 41:52video be a message. You too can do
- 41:55stupid little rabbit holes like this.
- 41:57It's [music] fun. You learn a lot.
- 41:58Literally any idea you have in your
- 42:00head. Don't even think about it. Just
- 42:01[ __ ] just do it. [ __ ] all the
- 42:03preparation. You're not a Witcher. You
- 42:04don't have to make 5,000 concoctions
- 42:07before you do something. Just dive in
- 42:10and learn as you go. You can do this
- 42:12with literally anything in your life.
- 42:14You're never going to be perfect, so
- 42:16stop waiting for the perfect
- 42:17opportunity. Just go, man. You got this.
- 42:20I believe in you. Thank you to all the
- 42:22continued supporters of this channel.
- 42:23You guys mean the world to me, and I
- 42:25look forward to diving down every rabbit
- 42:27hole in existence when it comes to
- 42:29technology. This is just 0.00001%
- 42:34of what we're all capable of. If you
- 42:36want to support the channel, buy the
- 42:37merch, become a channel member, and
- 42:39visit the description to see other ways
- 42:41to support the channel. If you're broke,
- 42:44your view and like are enough. Don't
- 42:45fret. [music] Hello, this is editor Zuma
- 42:47here. I just wanted to say that this
- 42:49battle arena thing that you're seeing on
- 42:51your screen right now is going to be the
- 42:53new way that I'm going to showcase
- 42:54channel member names. If you don't know,
- 42:56[music] I used to showcase channel
- 42:58member names by just scrolling them
- 42:59across the screen like this. But now, if
- 43:02you become a channel member, you [music]
- 43:04can enter the arena of these stick
- 43:06figures and fight to the death with all
- 43:08of my other channel members. The winner
- 43:10gets a shout out at the end of every
- 43:12video. Is this just a cool way to entice
- 43:14all of you to give me more money born
- 43:16from my insatiable level of greed? Or is
- 43:18this just a cool addition to honor my
- 43:20channel members and give them another
- 43:22awesome reason to join that exceeds just
- 43:25supporting the channel? I'll let you
- 43:27decide that. Today's winner is at Hellsc
- 43:29[music]
- 43:30Angels. Shout out to Hellsing Angels. To
- 43:32everybody who lost, good luck in the
- 43:34next battle. I hope to see more of you
- 43:36next time [music] everybody fights. I
- 43:38also wanted to showcase this beautiful
- 43:41piece of art. This is my first ever fan
- 43:43art made by [music] Anne is dying on
- 43:46Twitter. Thank you, Anne. I'm gonna
- 43:48cherish this photo forever. If you told
- 43:50me one year ago somebody would make fan
- 43:52art of me, I wouldn't have believed you.
- 43:54All of you watching this, if life is
- 43:56tough, [music] you're all one good
- 43:58decision away from changing your lives
- 44:00for the better forever. Because one good
- 44:02choice can spiral and snowball into
- 44:05something great. From now on, I will
- 44:07showcase any fan art I receive at the
- 44:10end of my videos here with the artist
- 44:12ads as a tribute to the artist.
- 44:14Subscribe to the Slob channel, follow my
- 44:16Twitter, buy my merch. Thank you for
- 44:18watching everyone. I hope you all have a
- 44:20phenomenal day. Now click off this video
- 44:22and go learn more things.
- 44:27[music]
- 44:33[music]
- 44:40[music]
About this transcript
This page contains the full transcript of Can A Conscious Fly Brain Learn how to Hack? by dzuma, generated from the public captions YouTube serves with the video. The transcript has 8,041 words across 1,212 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.