YouTube2Text

How to Get Someone's Password — Transcript

by Jack Rhysider · 3,444 words · 494 segments · language en · Watch on YouTube

Full transcript

  1. 0:00one two three four a question I get
  2. 0:05asked all the time is can you help me
  3. 0:08hack into something and probably the
  4. 0:10most easy way to hack into anything is
  5. 0:13just to get the password and log into it
  6. 0:15so I thought I'd give you 64 ways to get
  7. 0:18someone's password in 17 minutes oh and
  8. 0:21as a disclaimer don't do any of this
  9. 0:24unless you have permission
  10. 0:27probably the most effective way of
  11. 0:30getting someone's password is just to
  12. 0:32steal their computer or steal their
  13. 0:34phone or tablet this is sometimes called
  14. 0:37the evil maid attack because once you
  15. 0:39have physical access to their computer
  16. 0:40the chances of you being able to get
  17. 0:42into their accounts is much higher
  18. 0:44sometimes there's no password on their
  19. 0:46device and you could just get in and who
  20. 0:48knows maybe they're already logged into
  21. 0:49the account you want to access or their
  22. 0:51credentials are cached and you're in you
  23. 0:54could just ask for their password Jimmy
  24. 0:56Kimmel demonstrated how to do this on TV
  25. 0:58you mean to give my password right now
  26. 1:00no I cannot do that it is my dog's name
  27. 1:03and the year I graduated from high
  28. 1:05school like my cat's name and then just
  29. 1:07like a random number
  30. 1:09maybe the place you are in has already
  31. 1:11been breached before you can go on to
  32. 1:13breach forums and just buy the passwords
  33. 1:15you want if you can't find the database
  34. 1:17you're trying to get into a lot of
  35. 1:19people reuse passwords so maybe get into
  36. 1:21the contents of a different database see
  37. 1:24if their password is in that and then
  38. 1:26use it to try to get into the one you
  39. 1:28want to get into
  40. 1:29you can try to brute force your way in
  41. 1:31tools like burp Suite or Hydra can try
  42. 1:34to log into a website over and over with
  43. 1:36each time trying a different password
  44. 1:38starting with maybe AAA and then a a b
  45. 1:41and then AAC and then going down the
  46. 1:43line until it finds a match
  47. 1:48if you could somehow get the password
  48. 1:50hash uh like by grabbing the contents of
  49. 1:53Windows system32 config Sam where hashes
  50. 1:56are stored then you can try to Brute
  51. 1:58Force the hash tools like using John the
  52. 2:00Ripper or hashcat sometimes it's easier
  53. 2:03to get into a higher level account like
  54. 2:05if you can get root access to a Linux
  55. 2:08computer then you can reset the password
  56. 2:10for any user on that machine or see
  57. 2:12their private keys or if you can get
  58. 2:14admin access or help desk access you can
  59. 2:18then go in and reset any user's password
  60. 2:20in the whole ad database or if you can
  61. 2:22get in as the website admin you can
  62. 2:24reset any user's password that way or if
  63. 2:26you can get into the database directly
  64. 2:28you could reset someone's password using
  65. 2:30SQL commands or Heck if you can get in
  66. 2:32the database you might just be able to
  67. 2:33see the password itself there sometimes
  68. 2:35it's stored in plain text
  69. 2:37foreign
  70. 2:40and you might wonder how the hell am I
  71. 2:43going to get into a database of a
  72. 2:44company in the first place well you just
  73. 2:47need network access to it and then find
  74. 2:49a vulnerability on it or a password for
  75. 2:51it and then exploit it or get into it
  76. 2:53many times I've seen people go onto the
  77. 2:55website showdan and they find open
  78. 2:57mongodb databases and they're just open
  79. 3:00sitting on the internet for anyone to
  80. 3:02read the entire contents of or you could
  81. 3:05go into a website and try to do an SQL
  82. 3:07injection this is where the website and
  83. 3:09database servers just aren't secure and
  84. 3:12they allow too much user input from the
  85. 3:13website and yeah entire databases have
  86. 3:16been dumped through SQL injections
  87. 3:22another way to get into a database is to
  88. 3:24comb through any code that you might
  89. 3:26find on the website or app a lot of
  90. 3:28times credentials are hard-coded in
  91. 3:31programs or within the app somewhere you
  92. 3:33can also look to see if there's any open
  93. 3:34AWS instances that expose the code base
  94. 3:37and then dive in there looking for any
  95. 3:39sort of database credentials or you can
  96. 3:41look through GitHub repos searching for
  97. 3:43usernames and passwords in there
  98. 3:45unfortunately a lot of private API keys
  99. 3:48and passwords are discovered on GitHub
  100. 3:50just posted right there in the public
  101. 3:52for anyone to see and an API key if you
  102. 3:54can get that it's often just as good as
  103. 3:56a password or sometimes even an
  104. 3:58inspection of the app itself using like
  105. 4:01the strings command or looking through
  106. 4:02the plist files may just contain a
  107. 4:04password sitting right there in plain
  108. 4:06text for you to use actually you might
  109. 4:08just be able to right click and view
  110. 4:09source and look through the code right
  111. 4:11on the website and find something like a
  112. 4:13vulnerability or password or API key so
  113. 4:16an API key can get you data from a
  114. 4:19website such as a password or other user
  115. 4:21data get getting a private key is
  116. 4:23sometimes all you need but you could
  117. 4:25also try exploiting an API directly
  118. 4:27sometimes you can trick apis into
  119. 4:29sending you more data than what you
  120. 4:31should be allowed to see and we've seen
  121. 4:33some major breaches that were supposedly
  122. 4:35just data from insecure apis oh yeah and
  123. 4:38if you can get into it data center
  124. 4:39physically and steal a database server
  125. 4:42and bring it home you could probably get
  126. 4:44into it eventually it might be as simple
  127. 4:46as just pulling out the hard drive and
  128. 4:47putting it in your own computer and
  129. 4:48trying to read it that way
  130. 4:51thank you
  131. 4:53okay so what else oh yeah if you're on
  132. 4:57the scene Windows computer as a person
  133. 4:59that you want to steal their password
  134. 5:00you could try to run mimikats um this is
  135. 5:03a tool that can extract other users
  136. 5:05passwords out of memory and if you're on
  137. 5:07the same local subnet as another user
  138. 5:09you could run a tool called responder
  139. 5:11which will act like a shared drive on
  140. 5:13the network other computers will see it
  141. 5:15and try to connect but responder will
  142. 5:17first ask them to authenticate and this
  143. 5:18is where another computer will show you
  144. 5:20their password hash and you can just
  145. 5:22grab that and try to crack it sometimes
  146. 5:24just passing the hash is good enough to
  147. 5:26log into something and you don't
  148. 5:27actually need a password or maybe you
  149. 5:29run responder and get the password of
  150. 5:31another user not the one you're trying
  151. 5:33to get well if you have that you might
  152. 5:35want to try to log in as them see if
  153. 5:36they have some sort of extra privileges
  154. 5:38like maybe they're an admin and if they
  155. 5:40are then that would give you the ability
  156. 5:42to take over whoever's account you want
  157. 5:43and hey maybe the domain admin password
  158. 5:46wasn't what you wanted but if you had
  159. 5:49that this can get you access to other
  160. 5:51accounts that might help you get into
  161. 5:52what you do want or maybe this password
  162. 5:54is reused in other places or maybe it
  163. 5:57shows you a clue of what the passwords
  164. 6:00might look like
  165. 6:02if you want someone's Wi-Fi password and
  166. 6:04you're near their device you can get
  167. 6:06something that's called a Wi-Fi
  168. 6:07pineapple which will act like their
  169. 6:09Wi-Fi network and ask them for their
  170. 6:11Wi-Fi password and their devices might
  171. 6:14give it speaking of Wi-Fi passwords if
  172. 6:16you're in range you can get tools like
  173. 6:18aircrack NG to try to watch Wi-Fi
  174. 6:20traffic and try to crack the password on
  175. 6:22some Networks
  176. 6:24talk about 80s any is someone on the
  177. 6:27inside imagine if you knew someone who
  178. 6:30worked at Facebook who could reset any
  179. 6:32user's password for you and they might
  180. 6:34charge you a fee but that's one way to
  181. 6:36get a password right take a look at this
  182. 6:38this is a picture someone sent me of an
  183. 6:41innie who works at Taco Bell showing
  184. 6:43that for 30 bucks they'll reset any Taco
  185. 6:46Bell users account and this picture is
  186. 6:49of their terminal showing that they have
  187. 6:51access to do these things there's a lot
  188. 6:53of different kind of innies you just
  189. 6:55gotta know people nation-state actors do
  190. 6:58something similar with what's called a
  191. 7:00seating operation where they recruit
  192. 7:03someone who's about to go work for a
  193. 7:05company and they help them get hired
  194. 7:07there and then use their inside access
  195. 7:09to carry out tasks that will help the
  196. 7:11government like the CIA might seed
  197. 7:13someone into a company and then ask them
  198. 7:16for passwords or internal data or
  199. 7:17something another thing I've heard
  200. 7:19nation state actors do is set up
  201. 7:21surveillance systems on certain targets
  202. 7:23and spy on them such as planting
  203. 7:25microphones and listening to
  204. 7:26conversations or using long-range
  205. 7:28photography to see what they're doing on
  206. 7:30a computer
  207. 7:32take a look through nsa's ant catalog
  208. 7:34for an example to see some wild and
  209. 7:36crazy tools that could absolutely be
  210. 7:38used to steal a password and I saw this
  211. 7:40article the other day supposedly you
  212. 7:42could just turn the mic on on your phone
  213. 7:44and record when somebody types in their
  214. 7:47password and that might be enough
  215. 7:49information to decode what buttons were
  216. 7:51pressed
  217. 7:52here's another crazy article about
  218. 7:54someone using thermal cameras to watch
  219. 7:56what keys got warmer when someone was
  220. 7:58typing on there let's talk about
  221. 8:00tricking your target
  222. 8:03um this is sometimes called phishing or
  223. 8:04social engineering or just scamming them
  224. 8:06there are hundreds of ways to trick the
  225. 8:09user to give you their password like one
  226. 8:12method is to install a key logger on
  227. 8:14your computer and then get them to use
  228. 8:16your computer to log into something of
  229. 8:18theirs with a key logger on your
  230. 8:20computer you can then go back and see
  231. 8:21what keys they typed when they typed in
  232. 8:23their password to a website you can try
  233. 8:26shoulder surfing watching their fingers
  234. 8:28hit the keys as they type their password
  235. 8:30you should probably practice this before
  236. 8:32doing it as it takes a bit to learn I
  237. 8:34mean some reason and others like watch
  238. 8:36this video and try to guess what Kanye's
  239. 8:38password is
  240. 8:39[Music]
  241. 8:42um
  242. 8:44you could set up a fake look-alike
  243. 8:47website using a tool like uh the social
  244. 8:49engineering toolkit and with this you
  245. 8:51can set like a totally fake website and
  246. 8:54then give them the link to make it look
  247. 8:55like they're logging into their account
  248. 8:57but it's a fake website and then when
  249. 8:59they try to log in it captures that
  250. 9:02password that they typed in and sends it
  251. 9:03to you you can try to call the person up
  252. 9:06and just try to trick them into telling
  253. 9:08you their password like hello I'm
  254. 9:11calling from Microsoft customer support
  255. 9:12we see some suspicious activity on your
  256. 9:15account I can fix it but first I need
  257. 9:18you to verify your password this kind of
  258. 9:20trickery can work very well it might be
  259. 9:23the most easy way to get someone's
  260. 9:24password you could also call up the
  261. 9:26place that you're trying to access and
  262. 9:28act like you're the target you're trying
  263. 9:31to access and ask the company to reset
  264. 9:34your password you're acting like you're
  265. 9:36them and now if you can get them to do
  266. 9:39that you can access their account
  267. 9:42you can also try looking on their desk
  268. 9:44under their keyboard or in their wallet
  269. 9:46password just might be written down
  270. 9:48somewhere if you're the CEO of a company
  271. 9:51and you're dumb enough to leave your
  272. 9:52login info on a Post-It note on your
  273. 9:55desks it's not a hack
  274. 9:57it's barely social engineering if they
  275. 9:59don't physically write it down you could
  276. 10:01try looking through their files Dropbox
  277. 10:03Google Drive local storage network
  278. 10:05storage people sometimes think it's a
  279. 10:07safe place to store their passwords in
  280. 10:10some file somewhere and you could also
  281. 10:12try to get a victim to install a key
  282. 10:14logger on their machine maybe you trick
  283. 10:16them into installing something like a
  284. 10:18chat program or game that they want to
  285. 10:21play but really it's a key larger which
  286. 10:23captures all their keystrokes and then
  287. 10:25sends them to you and you can eventually
  288. 10:27see what passwords they type when they
  289. 10:29finally do speaking of keyloggers there
  290. 10:32are USB keyloggers too if you could just
  291. 10:34walk by someone's computer and plug it
  292. 10:36in it'll capture all the keystrokes that
  293. 10:38person types and stores it on the USB
  294. 10:40drive and then you just need to walk by
  295. 10:42later and pull it out there are also
  296. 10:44other tools such as the rubber ducky and
  297. 10:46the OMG cable that looks like ordinary
  298. 10:49cables and USB drives when you plug it
  299. 10:51in it injects keystrokes into the
  300. 10:54computer so you could plug it in and it
  301. 10:56might do something like grab a dump of
  302. 10:58the memory or hash table and then you
  303. 11:01can unplug it and try to look through
  304. 11:03that data for a password or maybe you
  305. 11:06could just attack their device over the
  306. 11:07network because maybe it's insecure
  307. 11:10somehow so if you can identify a
  308. 11:12vulnerability and use that exploit to
  309. 11:15get yourself access to their device once
  310. 11:17you get on their device you can do
  311. 11:18things like install your own keylogger
  312. 11:20or sift through their files looking for
  313. 11:22the password
  314. 11:25a lot of people use password managers
  315. 11:28now which I recommend I think it's a
  316. 11:30good idea but what this is is it's a
  317. 11:32secure database where all your passwords
  318. 11:34are in one place and it's protected by a
  319. 11:36single password so if you can get their
  320. 11:38password manager's master password
  321. 11:41and you can have access to everything
  322. 11:43another thing that would give you tons
  323. 11:44of data is their email if you can't get
  324. 11:47into where you need to get but you can
  325. 11:49get into their email inbox then you can
  326. 11:51just reset their password which will
  327. 11:53typically send them a link to their
  328. 11:55email and then you can just click the
  329. 11:57link and reset it to whatever you want
  330. 11:59and this is so effective that what some
  331. 12:01people do is go right for attacking the
  332. 12:04email when they need to get into someone
  333. 12:05else's account like they'll call up
  334. 12:07Google or Microsoft and pretend to be
  335. 12:09that person that they want access to and
  336. 12:11trick Google into resetting the Gmail
  337. 12:13password
  338. 12:15[Music]
  339. 12:19a lot of times the password is just
  340. 12:21something you can guess a lot of people
  341. 12:22use their dog's name or grandma's name
  342. 12:25or something close to them here's
  343. 12:27guildfoyle doing it on the show of
  344. 12:28Silicon Valley I was social engineering
  345. 12:30them then that information is entered
  346. 12:33into a word list generator pop it with
  347. 12:36their hash into John the Ripper and
  348. 12:39within minutes you have their passwords
  349. 12:42and you don't have to social engineer
  350. 12:44them you can sometimes just look at what
  351. 12:46they publish online and build a word
  352. 12:48list that way they might talk a lot on
  353. 12:50social media about the things they love
  354. 12:52or their private life which can all be
  355. 12:54gathered for someone to try to guess
  356. 12:56what their password might be in there to
  357. 12:58give you a clearer idea when pen testers
  358. 13:00are tasked to seeing if a company's
  359. 13:02users have weak passwords they'll try to
  360. 13:05crack the hashes of all the users in the
  361. 13:07whole company but what they've learned
  362. 13:08that helps them find weak passwords is
  363. 13:11to throw a whole bunch of cultural
  364. 13:13relevant words into the word list that
  365. 13:15they'll be guessing from such as local
  366. 13:18school names local sports teams local
  367. 13:21street names local restaurants city
  368. 13:23names or things that are related to the
  369. 13:25company like the name of the company or
  370. 13:27it's mascot or address it's sick how
  371. 13:31many employees use their own company
  372. 13:33name as their password also take a look
  373. 13:36at the most common passwords seen today
  374. 13:37there's a high chance it might be just
  375. 13:40one of those people will often use the
  376. 13:42simplest password they can
  377. 13:43[Music]
  378. 13:47thank you
  379. 13:49sometimes websites have weak reset or
  380. 13:51password policies I've seen a website
  381. 13:52once reset the password to a new four
  382. 13:55character password that the website
  383. 13:57chose for me and if you can reset a
  384. 13:59user's password to B4 characters it'll
  385. 14:02be pretty easy to brute force that
  386. 14:03afterwards
  387. 14:04if you know where the person works that
  388. 14:06you're trying to hack into you could
  389. 14:08call up their help desk and pretend to
  390. 14:10be that person that you want to access
  391. 14:12and ask for a password reset and you
  392. 14:15might be able to trick them into
  393. 14:16changing it for you to whatever you
  394. 14:18choose
  395. 14:18sometimes you don't need their passwords
  396. 14:21sometimes you can just steal a session
  397. 14:22cookie which will make it seem like
  398. 14:24you're already logged in without even
  399. 14:26providing a password recently I had
  400. 14:28someone try to trick me into sending
  401. 14:29them my Discord logs which contained my
  402. 14:32session data if I would have sent this
  403. 14:34to them they would have been able to log
  404. 14:35in as me on Discord even though I have
  405. 14:38two-factor authentication turned on and
  406. 14:40you know when I talked with this person
  407. 14:42and they told me about another trick
  408. 14:43that they use which is to send people
  409. 14:45fake Dino links on Discord which looks
  410. 14:47like you're authenticating to a Discord
  411. 14:49Dyno but in reality you just gave them
  412. 14:51access to your account which works even
  413. 14:53if you have two fa turned on or I've
  414. 14:56seen people get into someone else's
  415. 14:57account simply by telling the website
  416. 14:58that they are a different user and since
  417. 15:01the website saw that they have already
  418. 15:02authenticated that it just lets them
  419. 15:04switch users to someone else and this
  420. 15:07obviously relies on the website being
  421. 15:08poorly coded and insecure for it to work
  422. 15:13private keys are a whole nother thing if
  423. 15:16you can get a private key it's often
  424. 15:17just as good as a password and private
  425. 15:20keys are typically too hard to memorize
  426. 15:22and they've got to be stored somewhere
  427. 15:25so where are they stored you can look
  428. 15:27around for them and try to find them
  429. 15:29when someone types their password in
  430. 15:31it's usually shown in All Stars on the
  431. 15:33screen right but in some situations you
  432. 15:36can right click and do inspect element
  433. 15:38to see what the password looks like in
  434. 15:40clear text
  435. 15:42you can also try looking through cached
  436. 15:43data to see if a password is saved
  437. 15:45somewhere on their device a lot of times
  438. 15:47the password is left as default to so
  439. 15:50always try default passwords like um
  440. 15:52maybe admin admin or root root or admin
  441. 15:56password
  442. 15:57if you're on the same network as them
  443. 15:58you might be able to act as a proxy I
  444. 16:00started intercepting all the traffic on
  445. 16:02your network and inspect all their
  446. 16:04traffic that they're sending or
  447. 16:05receiving or intercept their traffic
  448. 16:07with something like a land tap somewhere
  449. 16:09in the traffic is their password or
  450. 16:11session cookie and it's just a matter of
  451. 16:13finding it
  452. 16:15instead of getting the password for the
  453. 16:16Target that you want it might be
  454. 16:18possible to attack a third party like
  455. 16:20maybe if you can get into their Apple
  456. 16:22account that might get you into their
  457. 16:24phone and then once you're in their
  458. 16:25phone then you can get into the other
  459. 16:27account you want or you could just
  460. 16:30extort them threaten them attack them
  461. 16:33there's something called a wrench attack
  462. 16:34where it doesn't matter how much
  463. 16:36security you have if somebody is banging
  464. 16:38you in the head with a wrench over and
  465. 16:40over that might be enough for you to
  466. 16:42give up your password
  467. 16:42[Music]
  468. 16:45I've got it all right here with a bow on
  469. 16:47it now I want to emphasize don't go
  470. 16:49stealing people's passwords and logging
  471. 16:51into their accounts accessing their data
  472. 16:53you could get in a lot of trouble for
  473. 16:55doing that the point I'm trying to make
  474. 16:57here is that there are a lot of ways
  475. 16:59that someone can get into your accounts
  476. 17:02and it should be clear at this point
  477. 17:04that your password is a weak link when
  478. 17:07it comes to securing your stuff I just
  479. 17:09mentioned 64 ways of getting into your
  480. 17:11accounts but with enough creativity time
  481. 17:14and resources this list can grow really
  482. 17:17long it's important to take your own
  483. 17:20security seriously so use long complex
  484. 17:24passwords use a different password on
  485. 17:25every website you have an account on and
  486. 17:27I recommend using a password manager and
  487. 17:29use two-factor authentication where
  488. 17:31available and always be extremely
  489. 17:33careful of where you're logging in or
  490. 17:35who you're giving your password to so
  491. 17:37that you don't accidentally hand your
  492. 17:39password to the wrong person or site
  493. 17:41good luck and stay safe
  494. 17:47[Music]

About this transcript

This page contains the full transcript of How to Get Someone's Password by Jack Rhysider, generated from the public captions YouTube serves with the video. The transcript has 3,444 words across 494 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.