How to Get Someone's Password — Transcript
Full transcript
- 0:00one two three four a question I get
- 0:05asked all the time is can you help me
- 0:08hack into something and probably the
- 0:10most easy way to hack into anything is
- 0:13just to get the password and log into it
- 0:15so I thought I'd give you 64 ways to get
- 0:18someone's password in 17 minutes oh and
- 0:21as a disclaimer don't do any of this
- 0:24unless you have permission
- 0:27probably the most effective way of
- 0:30getting someone's password is just to
- 0:32steal their computer or steal their
- 0:34phone or tablet this is sometimes called
- 0:37the evil maid attack because once you
- 0:39have physical access to their computer
- 0:40the chances of you being able to get
- 0:42into their accounts is much higher
- 0:44sometimes there's no password on their
- 0:46device and you could just get in and who
- 0:48knows maybe they're already logged into
- 0:49the account you want to access or their
- 0:51credentials are cached and you're in you
- 0:54could just ask for their password Jimmy
- 0:56Kimmel demonstrated how to do this on TV
- 0:58you mean to give my password right now
- 1:00no I cannot do that it is my dog's name
- 1:03and the year I graduated from high
- 1:05school like my cat's name and then just
- 1:07like a random number
- 1:09maybe the place you are in has already
- 1:11been breached before you can go on to
- 1:13breach forums and just buy the passwords
- 1:15you want if you can't find the database
- 1:17you're trying to get into a lot of
- 1:19people reuse passwords so maybe get into
- 1:21the contents of a different database see
- 1:24if their password is in that and then
- 1:26use it to try to get into the one you
- 1:28want to get into
- 1:29you can try to brute force your way in
- 1:31tools like burp Suite or Hydra can try
- 1:34to log into a website over and over with
- 1:36each time trying a different password
- 1:38starting with maybe AAA and then a a b
- 1:41and then AAC and then going down the
- 1:43line until it finds a match
- 1:48if you could somehow get the password
- 1:50hash uh like by grabbing the contents of
- 1:53Windows system32 config Sam where hashes
- 1:56are stored then you can try to Brute
- 1:58Force the hash tools like using John the
- 2:00Ripper or hashcat sometimes it's easier
- 2:03to get into a higher level account like
- 2:05if you can get root access to a Linux
- 2:08computer then you can reset the password
- 2:10for any user on that machine or see
- 2:12their private keys or if you can get
- 2:14admin access or help desk access you can
- 2:18then go in and reset any user's password
- 2:20in the whole ad database or if you can
- 2:22get in as the website admin you can
- 2:24reset any user's password that way or if
- 2:26you can get into the database directly
- 2:28you could reset someone's password using
- 2:30SQL commands or Heck if you can get in
- 2:32the database you might just be able to
- 2:33see the password itself there sometimes
- 2:35it's stored in plain text
- 2:37foreign
- 2:40and you might wonder how the hell am I
- 2:43going to get into a database of a
- 2:44company in the first place well you just
- 2:47need network access to it and then find
- 2:49a vulnerability on it or a password for
- 2:51it and then exploit it or get into it
- 2:53many times I've seen people go onto the
- 2:55website showdan and they find open
- 2:57mongodb databases and they're just open
- 3:00sitting on the internet for anyone to
- 3:02read the entire contents of or you could
- 3:05go into a website and try to do an SQL
- 3:07injection this is where the website and
- 3:09database servers just aren't secure and
- 3:12they allow too much user input from the
- 3:13website and yeah entire databases have
- 3:16been dumped through SQL injections
- 3:22another way to get into a database is to
- 3:24comb through any code that you might
- 3:26find on the website or app a lot of
- 3:28times credentials are hard-coded in
- 3:31programs or within the app somewhere you
- 3:33can also look to see if there's any open
- 3:34AWS instances that expose the code base
- 3:37and then dive in there looking for any
- 3:39sort of database credentials or you can
- 3:41look through GitHub repos searching for
- 3:43usernames and passwords in there
- 3:45unfortunately a lot of private API keys
- 3:48and passwords are discovered on GitHub
- 3:50just posted right there in the public
- 3:52for anyone to see and an API key if you
- 3:54can get that it's often just as good as
- 3:56a password or sometimes even an
- 3:58inspection of the app itself using like
- 4:01the strings command or looking through
- 4:02the plist files may just contain a
- 4:04password sitting right there in plain
- 4:06text for you to use actually you might
- 4:08just be able to right click and view
- 4:09source and look through the code right
- 4:11on the website and find something like a
- 4:13vulnerability or password or API key so
- 4:16an API key can get you data from a
- 4:19website such as a password or other user
- 4:21data get getting a private key is
- 4:23sometimes all you need but you could
- 4:25also try exploiting an API directly
- 4:27sometimes you can trick apis into
- 4:29sending you more data than what you
- 4:31should be allowed to see and we've seen
- 4:33some major breaches that were supposedly
- 4:35just data from insecure apis oh yeah and
- 4:38if you can get into it data center
- 4:39physically and steal a database server
- 4:42and bring it home you could probably get
- 4:44into it eventually it might be as simple
- 4:46as just pulling out the hard drive and
- 4:47putting it in your own computer and
- 4:48trying to read it that way
- 4:51thank you
- 4:53okay so what else oh yeah if you're on
- 4:57the scene Windows computer as a person
- 4:59that you want to steal their password
- 5:00you could try to run mimikats um this is
- 5:03a tool that can extract other users
- 5:05passwords out of memory and if you're on
- 5:07the same local subnet as another user
- 5:09you could run a tool called responder
- 5:11which will act like a shared drive on
- 5:13the network other computers will see it
- 5:15and try to connect but responder will
- 5:17first ask them to authenticate and this
- 5:18is where another computer will show you
- 5:20their password hash and you can just
- 5:22grab that and try to crack it sometimes
- 5:24just passing the hash is good enough to
- 5:26log into something and you don't
- 5:27actually need a password or maybe you
- 5:29run responder and get the password of
- 5:31another user not the one you're trying
- 5:33to get well if you have that you might
- 5:35want to try to log in as them see if
- 5:36they have some sort of extra privileges
- 5:38like maybe they're an admin and if they
- 5:40are then that would give you the ability
- 5:42to take over whoever's account you want
- 5:43and hey maybe the domain admin password
- 5:46wasn't what you wanted but if you had
- 5:49that this can get you access to other
- 5:51accounts that might help you get into
- 5:52what you do want or maybe this password
- 5:54is reused in other places or maybe it
- 5:57shows you a clue of what the passwords
- 6:00might look like
- 6:02if you want someone's Wi-Fi password and
- 6:04you're near their device you can get
- 6:06something that's called a Wi-Fi
- 6:07pineapple which will act like their
- 6:09Wi-Fi network and ask them for their
- 6:11Wi-Fi password and their devices might
- 6:14give it speaking of Wi-Fi passwords if
- 6:16you're in range you can get tools like
- 6:18aircrack NG to try to watch Wi-Fi
- 6:20traffic and try to crack the password on
- 6:22some Networks
- 6:24talk about 80s any is someone on the
- 6:27inside imagine if you knew someone who
- 6:30worked at Facebook who could reset any
- 6:32user's password for you and they might
- 6:34charge you a fee but that's one way to
- 6:36get a password right take a look at this
- 6:38this is a picture someone sent me of an
- 6:41innie who works at Taco Bell showing
- 6:43that for 30 bucks they'll reset any Taco
- 6:46Bell users account and this picture is
- 6:49of their terminal showing that they have
- 6:51access to do these things there's a lot
- 6:53of different kind of innies you just
- 6:55gotta know people nation-state actors do
- 6:58something similar with what's called a
- 7:00seating operation where they recruit
- 7:03someone who's about to go work for a
- 7:05company and they help them get hired
- 7:07there and then use their inside access
- 7:09to carry out tasks that will help the
- 7:11government like the CIA might seed
- 7:13someone into a company and then ask them
- 7:16for passwords or internal data or
- 7:17something another thing I've heard
- 7:19nation state actors do is set up
- 7:21surveillance systems on certain targets
- 7:23and spy on them such as planting
- 7:25microphones and listening to
- 7:26conversations or using long-range
- 7:28photography to see what they're doing on
- 7:30a computer
- 7:32take a look through nsa's ant catalog
- 7:34for an example to see some wild and
- 7:36crazy tools that could absolutely be
- 7:38used to steal a password and I saw this
- 7:40article the other day supposedly you
- 7:42could just turn the mic on on your phone
- 7:44and record when somebody types in their
- 7:47password and that might be enough
- 7:49information to decode what buttons were
- 7:51pressed
- 7:52here's another crazy article about
- 7:54someone using thermal cameras to watch
- 7:56what keys got warmer when someone was
- 7:58typing on there let's talk about
- 8:00tricking your target
- 8:03um this is sometimes called phishing or
- 8:04social engineering or just scamming them
- 8:06there are hundreds of ways to trick the
- 8:09user to give you their password like one
- 8:12method is to install a key logger on
- 8:14your computer and then get them to use
- 8:16your computer to log into something of
- 8:18theirs with a key logger on your
- 8:20computer you can then go back and see
- 8:21what keys they typed when they typed in
- 8:23their password to a website you can try
- 8:26shoulder surfing watching their fingers
- 8:28hit the keys as they type their password
- 8:30you should probably practice this before
- 8:32doing it as it takes a bit to learn I
- 8:34mean some reason and others like watch
- 8:36this video and try to guess what Kanye's
- 8:38password is
- 8:39[Music]
- 8:42um
- 8:44you could set up a fake look-alike
- 8:47website using a tool like uh the social
- 8:49engineering toolkit and with this you
- 8:51can set like a totally fake website and
- 8:54then give them the link to make it look
- 8:55like they're logging into their account
- 8:57but it's a fake website and then when
- 8:59they try to log in it captures that
- 9:02password that they typed in and sends it
- 9:03to you you can try to call the person up
- 9:06and just try to trick them into telling
- 9:08you their password like hello I'm
- 9:11calling from Microsoft customer support
- 9:12we see some suspicious activity on your
- 9:15account I can fix it but first I need
- 9:18you to verify your password this kind of
- 9:20trickery can work very well it might be
- 9:23the most easy way to get someone's
- 9:24password you could also call up the
- 9:26place that you're trying to access and
- 9:28act like you're the target you're trying
- 9:31to access and ask the company to reset
- 9:34your password you're acting like you're
- 9:36them and now if you can get them to do
- 9:39that you can access their account
- 9:42you can also try looking on their desk
- 9:44under their keyboard or in their wallet
- 9:46password just might be written down
- 9:48somewhere if you're the CEO of a company
- 9:51and you're dumb enough to leave your
- 9:52login info on a Post-It note on your
- 9:55desks it's not a hack
- 9:57it's barely social engineering if they
- 9:59don't physically write it down you could
- 10:01try looking through their files Dropbox
- 10:03Google Drive local storage network
- 10:05storage people sometimes think it's a
- 10:07safe place to store their passwords in
- 10:10some file somewhere and you could also
- 10:12try to get a victim to install a key
- 10:14logger on their machine maybe you trick
- 10:16them into installing something like a
- 10:18chat program or game that they want to
- 10:21play but really it's a key larger which
- 10:23captures all their keystrokes and then
- 10:25sends them to you and you can eventually
- 10:27see what passwords they type when they
- 10:29finally do speaking of keyloggers there
- 10:32are USB keyloggers too if you could just
- 10:34walk by someone's computer and plug it
- 10:36in it'll capture all the keystrokes that
- 10:38person types and stores it on the USB
- 10:40drive and then you just need to walk by
- 10:42later and pull it out there are also
- 10:44other tools such as the rubber ducky and
- 10:46the OMG cable that looks like ordinary
- 10:49cables and USB drives when you plug it
- 10:51in it injects keystrokes into the
- 10:54computer so you could plug it in and it
- 10:56might do something like grab a dump of
- 10:58the memory or hash table and then you
- 11:01can unplug it and try to look through
- 11:03that data for a password or maybe you
- 11:06could just attack their device over the
- 11:07network because maybe it's insecure
- 11:10somehow so if you can identify a
- 11:12vulnerability and use that exploit to
- 11:15get yourself access to their device once
- 11:17you get on their device you can do
- 11:18things like install your own keylogger
- 11:20or sift through their files looking for
- 11:22the password
- 11:25a lot of people use password managers
- 11:28now which I recommend I think it's a
- 11:30good idea but what this is is it's a
- 11:32secure database where all your passwords
- 11:34are in one place and it's protected by a
- 11:36single password so if you can get their
- 11:38password manager's master password
- 11:41and you can have access to everything
- 11:43another thing that would give you tons
- 11:44of data is their email if you can't get
- 11:47into where you need to get but you can
- 11:49get into their email inbox then you can
- 11:51just reset their password which will
- 11:53typically send them a link to their
- 11:55email and then you can just click the
- 11:57link and reset it to whatever you want
- 11:59and this is so effective that what some
- 12:01people do is go right for attacking the
- 12:04email when they need to get into someone
- 12:05else's account like they'll call up
- 12:07Google or Microsoft and pretend to be
- 12:09that person that they want access to and
- 12:11trick Google into resetting the Gmail
- 12:13password
- 12:15[Music]
- 12:19a lot of times the password is just
- 12:21something you can guess a lot of people
- 12:22use their dog's name or grandma's name
- 12:25or something close to them here's
- 12:27guildfoyle doing it on the show of
- 12:28Silicon Valley I was social engineering
- 12:30them then that information is entered
- 12:33into a word list generator pop it with
- 12:36their hash into John the Ripper and
- 12:39within minutes you have their passwords
- 12:42and you don't have to social engineer
- 12:44them you can sometimes just look at what
- 12:46they publish online and build a word
- 12:48list that way they might talk a lot on
- 12:50social media about the things they love
- 12:52or their private life which can all be
- 12:54gathered for someone to try to guess
- 12:56what their password might be in there to
- 12:58give you a clearer idea when pen testers
- 13:00are tasked to seeing if a company's
- 13:02users have weak passwords they'll try to
- 13:05crack the hashes of all the users in the
- 13:07whole company but what they've learned
- 13:08that helps them find weak passwords is
- 13:11to throw a whole bunch of cultural
- 13:13relevant words into the word list that
- 13:15they'll be guessing from such as local
- 13:18school names local sports teams local
- 13:21street names local restaurants city
- 13:23names or things that are related to the
- 13:25company like the name of the company or
- 13:27it's mascot or address it's sick how
- 13:31many employees use their own company
- 13:33name as their password also take a look
- 13:36at the most common passwords seen today
- 13:37there's a high chance it might be just
- 13:40one of those people will often use the
- 13:42simplest password they can
- 13:43[Music]
- 13:47thank you
- 13:49sometimes websites have weak reset or
- 13:51password policies I've seen a website
- 13:52once reset the password to a new four
- 13:55character password that the website
- 13:57chose for me and if you can reset a
- 13:59user's password to B4 characters it'll
- 14:02be pretty easy to brute force that
- 14:03afterwards
- 14:04if you know where the person works that
- 14:06you're trying to hack into you could
- 14:08call up their help desk and pretend to
- 14:10be that person that you want to access
- 14:12and ask for a password reset and you
- 14:15might be able to trick them into
- 14:16changing it for you to whatever you
- 14:18choose
- 14:18sometimes you don't need their passwords
- 14:21sometimes you can just steal a session
- 14:22cookie which will make it seem like
- 14:24you're already logged in without even
- 14:26providing a password recently I had
- 14:28someone try to trick me into sending
- 14:29them my Discord logs which contained my
- 14:32session data if I would have sent this
- 14:34to them they would have been able to log
- 14:35in as me on Discord even though I have
- 14:38two-factor authentication turned on and
- 14:40you know when I talked with this person
- 14:42and they told me about another trick
- 14:43that they use which is to send people
- 14:45fake Dino links on Discord which looks
- 14:47like you're authenticating to a Discord
- 14:49Dyno but in reality you just gave them
- 14:51access to your account which works even
- 14:53if you have two fa turned on or I've
- 14:56seen people get into someone else's
- 14:57account simply by telling the website
- 14:58that they are a different user and since
- 15:01the website saw that they have already
- 15:02authenticated that it just lets them
- 15:04switch users to someone else and this
- 15:07obviously relies on the website being
- 15:08poorly coded and insecure for it to work
- 15:13private keys are a whole nother thing if
- 15:16you can get a private key it's often
- 15:17just as good as a password and private
- 15:20keys are typically too hard to memorize
- 15:22and they've got to be stored somewhere
- 15:25so where are they stored you can look
- 15:27around for them and try to find them
- 15:29when someone types their password in
- 15:31it's usually shown in All Stars on the
- 15:33screen right but in some situations you
- 15:36can right click and do inspect element
- 15:38to see what the password looks like in
- 15:40clear text
- 15:42you can also try looking through cached
- 15:43data to see if a password is saved
- 15:45somewhere on their device a lot of times
- 15:47the password is left as default to so
- 15:50always try default passwords like um
- 15:52maybe admin admin or root root or admin
- 15:56password
- 15:57if you're on the same network as them
- 15:58you might be able to act as a proxy I
- 16:00started intercepting all the traffic on
- 16:02your network and inspect all their
- 16:04traffic that they're sending or
- 16:05receiving or intercept their traffic
- 16:07with something like a land tap somewhere
- 16:09in the traffic is their password or
- 16:11session cookie and it's just a matter of
- 16:13finding it
- 16:15instead of getting the password for the
- 16:16Target that you want it might be
- 16:18possible to attack a third party like
- 16:20maybe if you can get into their Apple
- 16:22account that might get you into their
- 16:24phone and then once you're in their
- 16:25phone then you can get into the other
- 16:27account you want or you could just
- 16:30extort them threaten them attack them
- 16:33there's something called a wrench attack
- 16:34where it doesn't matter how much
- 16:36security you have if somebody is banging
- 16:38you in the head with a wrench over and
- 16:40over that might be enough for you to
- 16:42give up your password
- 16:42[Music]
- 16:45I've got it all right here with a bow on
- 16:47it now I want to emphasize don't go
- 16:49stealing people's passwords and logging
- 16:51into their accounts accessing their data
- 16:53you could get in a lot of trouble for
- 16:55doing that the point I'm trying to make
- 16:57here is that there are a lot of ways
- 16:59that someone can get into your accounts
- 17:02and it should be clear at this point
- 17:04that your password is a weak link when
- 17:07it comes to securing your stuff I just
- 17:09mentioned 64 ways of getting into your
- 17:11accounts but with enough creativity time
- 17:14and resources this list can grow really
- 17:17long it's important to take your own
- 17:20security seriously so use long complex
- 17:24passwords use a different password on
- 17:25every website you have an account on and
- 17:27I recommend using a password manager and
- 17:29use two-factor authentication where
- 17:31available and always be extremely
- 17:33careful of where you're logging in or
- 17:35who you're giving your password to so
- 17:37that you don't accidentally hand your
- 17:39password to the wrong person or site
- 17:41good luck and stay safe
- 17:47[Music]
About this transcript
This page contains the full transcript of How to Get Someone's Password by Jack Rhysider, generated from the public captions YouTube serves with the video. The transcript has 3,444 words across 494 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.