Skip to content

Download Subtitles: How To Learn Hacking – A Practical Demo

How To Learn Hacking - A Practical Demo

How To Learn Hacking - A Practical Demo

The Hacker Academy

702 segments EN
Save subtitles to LunaNotes

SRT - Most compatible format for video players (VLC, media players, video editors)

VTT - Web Video Text Tracks for HTML5 video and browsers

TXT - Plain text with timestamps for easy reading and editing

Subtitle preview

Scroll to view all subtitles

[00:00]

You clicked this because you want to

[00:01]

learn how to hack and you're tired of

[00:03]

videos that promise to teach you then

[00:05]

spend 20 minutes telling you to go learn

[00:07]

network or learn Linux first and never

[00:10]

actually show you anything. This is

[00:12]

different. In the next few minutes

[00:14]

you're going to break into a real

[00:15]

computer with your own hands and you'll

[00:18]

understand exactly how you did it. I'm

[00:20]

going to put my hands on the keyboard

[00:21]

with you. Every command, every click,

[00:23]

every line that shows up on your screen

[00:25]

explained. If you have never opened a

[00:27]

terminal in your life you are exactly

[00:30]

who I made this for. Here's what you'll

[00:32]

walk away knowing. The [music] actual

[00:33]

five-step process every professional

[00:36]

hacker uses. How to scan a target and

[00:38]

find its weak points. How to break in

[00:41]

and what to do once you're inside. Not

[00:43]

theory, the real skills, the ones

[00:45]

companies pay six-figures for and we're

[00:47]

not going to practice on anything

[00:49]

illegal. There's a free website that

[00:51]

gives you a real target machine built

[00:53]

specifically for this. You attack it in

[00:55]

your browser. Nothing to install,

[00:57]

completely legal. So open a second tab

[00:59]

right now because you're not going to

[01:01]

watch me hack. You're going to hack

[01:03]

right alongside me. Most people will

[01:04]

watch this whole thing and never type a

[01:06]

single command. They'll stay stuck

[01:08]

forever. Be the one who actually follows

[01:10]

along because 15 minutes from now you'll

[01:13]

have done the thing you've been wanting

[01:14]

to learn for real. Before we touch

[01:17]

anything, one rule and it matters more

[01:19]

than anything else in this video. You

[01:21]

only hack machines you own or machines

[01:24]

you have written permission to attack.

[01:26]

The target we're using today is built

[01:27]

[music] for this. It's legal. It's

[01:29]

designed to be hacked by beginners

[01:31]

learning exactly what you're learning.

[01:33]

That's allowed. What's not allowed?

[01:35]

Pointing these tools at a website, a

[01:37]

network or a device you don't own. Even

[01:40]

just scanning a stranger's system

[01:41]

without permission [music] is a crime in

[01:43]

most countries. Here's the first thing

[01:45]

that's going to change how you see

[01:47]

hacking forever. Hacking is not random

[01:49]

typing until you get in. That's a movie.

[01:52]

Real hacking is a process, a repeatable

[01:54]

step-by-step process. And once you know

[01:57]

it, every hack you ever attempt becomes

[01:59]

the same five steps in the same order.

[02:01]

Professional pen testers follow it.

[02:03]

Government red teams follow it. Bug

[02:05]

bounty hunters follow it. After today,

[02:08]

you'll follow it, too. Write these down.

[02:09]

[music]

[02:10]

Five phases. Phase one, reconnaissance.

[02:12]

You gather information about your

[02:14]

target. Who is it? What is it? What's it

[02:17]

running? Before you ever attack, you

[02:19]

learn. Phase two, scanning. You map the

[02:21]

target. You find its open doors, the

[02:24]

services running behind them. This is

[02:26]

where you find your way in. Phase three,

[02:28]

[music]

[02:28]

exploitation. You take a weakness you

[02:30]

found and you use it to break in. Phase

[02:33]

four, access. You're inside. Now you

[02:35]

take control. You see what you can reach

[02:38]

and you climb to the highest level of

[02:39]

power on the machine. Phase [music]

[02:41]

five, reporting. You document everything

[02:43]

you found because in the real world,

[02:45]

this is the part that pays. Companies

[02:47]

hire you to find the holes, then tell

[02:50]

them how to fix them. That's the entire

[02:51]

craft. Recon, scan, exploit, access,

[02:55]

report. Say it back in your head right

[02:57]

now. Here's why this matters so much for

[02:58]

you as a beginner. Most people drown

[03:01]

because they think they need to memorize

[03:02]

a thousand tricks.

[03:04]

>> [music]

[03:04]

>> They don't. You need to learn one

[03:05]

process, then you just get better at

[03:07]

each phase over time. A beginner thinks

[03:09]

hacking is about secret knowledge. A

[03:11]

professional knows it's about working

[03:13]

the process patiently [music]

[03:15]

every time. And here's the best part.

[03:17]

We're not going to just talk about these

[03:18]

five phases. We're going to walk through

[03:20]

all five on a real machine together

[03:22]

[music] starting right now. So let's get

[03:24]

you set up. Okay, hands on keyboard.

[03:26]

Let's get you set up. Follow along

[03:28]

exactly. I'll wait for you at every

[03:30]

step. Open a new tab. Go to

[03:32]

tryhackme.com. This is the platform

[03:34]

we're using. It's free to start. It

[03:37]

gives you real machines to legally hack.

[03:39]

And the best part, you don't install

[03:41]

anything. Everything runs in your

[03:43]

browser. If you're on a laptop you

[03:44]

bought yesterday or a five-year-old

[03:46]

machine, it doesn't matter. It all

[03:48]

happens in the browser. Sign up for a

[03:50]

free account, email and password. Takes

[03:53]

30 seconds. I'll wait. Pause the video

[03:55]

if you need to. Got your account? Good.

[03:57]

Now, in the search bar at the top, type

[03:59]

the word blue. Just blue. You're looking

[04:02]

for a room called blue. A room is just

[04:04]

TryHackMe's word for a guided hacking

[04:06]

challenge. Click into the blue room.

[04:08]

Now, why this machine? I picked blue on

[04:11]

purpose. It's a Windows computer with a

[04:13]

famous weakness. The exact kind of

[04:16]

weakness that took down hospitals and

[04:18]

companies across the world a few years

[04:19]

ago. You're going to exploit that same

[04:22]

weakness today as your very first hack.

[04:25]

It's dramatic and it works every time.

[04:27]

Perfect for your first win. Here's your

[04:29]

first real action. On the room page,

[04:31]

you'll see a button that says start

[04:33]

machine. Click it.

[04:35]

>> [music]

[04:35]

>> This boots up your target, the actual

[04:37]

computer you're going to hack. It takes

[04:38]

about a minute to start. While it boots,

[04:41]

a box appears, usually at the top of the

[04:43]

page, and it shows you an IP address,

[04:46]

something like [music] 10 10 and then

[04:48]

two more numbers. IP address is your

[04:51]

target. That's the address of the

[04:52]

machine you're attacking. Write it down

[04:55]

or just keep that box visible. You're

[04:57]

going to need it constantly. Every tool

[04:59]

you use, you point at that IP. Quick

[05:02]

explanation, because I don't want you

[05:04]

just copying. I want you understanding.

[05:06]

IP address is just a location on a

[05:08]

network, like a street address for a

[05:10]

computer. When I say point your tool at

[05:12]

the target, I mean send it to that IP.

[05:15]

That's how your attacker machine finds

[05:17]

the target machine across the network.

[05:19]

Now, we need to use your attacker

[05:20]

machine, the computer you attack from.

[05:22]

On the room page, look for a button that

[05:24]

says start attack box. Click it. The

[05:27]

attack box is a ready-made hacking

[05:28]

computer. It runs in your browser. It

[05:31]

already has every tool we need

[05:32]

pre-installed. You don't set up

[05:34]

anything. It just appears on the right

[05:36]

side of your screen. Give it a minute to

[05:38]

load. When it loads, you'll see a

[05:40]

desktop. It looks like a normal computer

[05:42]

desktop, because it is one. It's just

[05:44]

running in your browser and it's loaded

[05:46]

with hacker tools. Now, [music]

[05:49]

the part that scares every single

[05:50]

beginner, the terminal on that attack

[05:52]

box desktop. Find the icon that looks

[05:55]

like a little black screen, usually in

[05:57]

the taskbar. It might be called

[05:59]

terminal. Click it. A black window opens

[06:01]

with some text and a blinking cursor.

[06:03]

Stop. [music] Take a breath. This black

[06:05]

window is not scary. This is just where

[06:08]

you type commands instead of clicking

[06:09]

buttons. That's the only difference

[06:11]

between this and your normal computer.

[06:13]

Instead of clicking icons with the

[06:15]

mouse, you type instructions with words.

[06:17]

That's [music] it. That's all a terminal

[06:19]

is. You type a command. You press enter.

[06:22]

The computer does the thing. Then it

[06:23]

shows you the result. Type, enter, read.

[06:26]

[music] That's the entire rhythm of

[06:28]

everything we're about to do. Let's

[06:30]

prove it's not scary. In that black

[06:32]

window, type this exact word,

[06:35]

press enter. The terminal just told you

[06:37]

which user you are on the attacker

[06:39]

machine. You asked the computer a

[06:40]

question in plain words. It answered.

[06:43]

That's all a terminal is. A

[06:44]

conversation. You just had your first

[06:46]

one. So, let's recap where you are right

[06:48]

now. You have a target machine running

[06:50]

with an IP address. You have your

[06:52]

attacker machine, the attack box, loaded

[06:55]

with tools, and you have a terminal

[06:57]

open, ready for commands. That's a

[06:59]

complete professional hacking setup. You

[07:01]

built it in under 2 minutes. Now, let's

[07:03]

start the actual hack. Phase one,

[07:05]

reconnaissance. Recon means gathering

[07:08]

information before you attack. In the

[07:09]

real world, on a paid job, this phase is

[07:12]

huge. You'd research the company, find

[07:15]

employee names and emails, map out their

[07:17]

public websites, look at what technology

[07:19]

they use. You learn everything you can

[07:22]

before you touch anything. Why? Because

[07:24]

you can't attack what you don't

[07:25]

understand. The more you know about the

[07:27]

target, the more ways in you'll find.

[07:29]

Amateurs rush to attack. Professionals

[07:31]

spend most of their time here, learning.

[07:33]

But for our target today, recon is

[07:35]

[music] simple. We already have the one

[07:37]

thing we need, the target's IP address,

[07:40]

that box on your screen. So, our recon

[07:42]

question is short. What is this machine?

[07:44]

What's running on it? Where are the

[07:46]

doors? And to answer that, we move into

[07:48]

the most important skill you will learn

[07:50]

today, scanning. Phase two, scanning.

[07:53]

Pay close attention here because this is

[07:55]

the skill you will use in every single

[07:57]

hack you ever do. Master this one tool

[08:00]

and you're already ahead of most

[08:01]

beginners. The tool is called Nmap.

[08:04]

Nmap, short for network mapper, it's

[08:06]

free. It's already installed on your

[08:08]

attack box and it is the most important

[08:10]

reconnaissance tool in the world. Every

[08:12]

professional uses it every single day.

[08:15]

Here's what Nmap actually does. Remember

[08:16]

I said the target is like a building.

[08:18]

Nmap walks around that building and

[08:20]

checks every single door and window. It

[08:23]

tells you which ones are open, which are

[08:25]

locked, and what's [music] behind each

[08:27]

open one. In computer terms, those doors

[08:29]

are called ports. A port is just a

[08:32]

numbered entrance into a computer. Each

[08:34]

service running on a machine, a website,

[08:36]

a file share, a remote login, sits

[08:38]

behind a specific port. Find the open

[08:41]

ports and you found your possible ways

[08:43]

in. Let's run your first scan. Go to

[08:45]

your terminal, the black window, and

[08:47]

type this exactly, nmap, then a space,

[08:51]

then your target's IP address. Now you

[08:53]

wait. Nmap is knocking on every door. It

[08:55]

takes a few seconds, maybe a minute.

[08:57]

Don't touch anything. Let it work. And

[08:59]

there it is. Nmap just gave you a list.

[09:02]

Look at it. You'll see a column of

[09:04]

numbers. Each one followed by the word

[09:06]

open or closed. The open ones are what

[09:09]

matter. You'll probably see port 135,

[09:11]

port 139, and the important one, port

[09:13]

445, all open. Right now you know the

[09:16]

doors are open, but you don't know

[09:18]

what's behind them yet. A basic scan

[09:20]

only shows you the doors, not what's

[09:22]

inside. So, let's go deeper. This is

[09:24]

where you learn your first flag. A flag

[09:26]

is just an option you add to a command.

[09:28]

It changes what the tool does.

[09:29]

>> [music]

[09:30]

>> You add a flag by typing a space, then a

[09:31]

dash, then a letter. Type this, nmap

[09:34]

space {dash} capital S capital V space

[09:38]

your IP. That {dash} capital S capital V

[09:41]

means version detection. [music] Now,

[09:43]

Nmap doesn't just tell you a door is

[09:45]

open. It tells you exactly what service

[09:47]

is running behind it and which version

[09:49]

of that service. Press enter. Wait

[09:52]

again. [music]

[09:52]

This one takes a little longer. When it

[09:54]

comes back, look at port 445 next to it.

[09:58]

We'll now see a service name, something

[10:00]

about Microsoft and Windows. Nmap is

[10:03]

telling you this is a Windows machine

[10:05]

and port 445 is running something called

[10:07]

SMB, server message block. It's the

[10:10]

service Windows uses to share files.

[10:12]

This is the moment that matters. Write

[10:14]

down what you see, [music] the operating

[10:16]

system, Windows, the open port, 445, the

[10:19]

service, SMB, because here's the secret

[10:22]

at the center of all hacking. Those

[10:24]

details are your lead, a specific

[10:26]

service on a specific system. Old

[10:29]

software has known weaknesses and when

[10:31]

you know exactly what's running, you can

[10:33]

go find exactly how to break it. Let's

[10:35]

do one more scan, the smartest one.

[10:38]

{dash} capital S capital C runs Nmap's

[10:40]

built-in scripts. These are little

[10:42]

automated checks that look for common

[10:44]

problems. Sometimes, this single command

[10:46]

finds the weakness for you

[10:48]

automatically. Press enter, let it run.

[10:51]

Stop and realize what you just did. You

[10:53]

scanned a real machine. You found its

[10:55]

open ports. You identified the operating

[10:58]

system and you fingerprinted the exact

[11:00]

service running on the target. That is

[11:02]

professional reconnaissance. That's the

[11:04]

first thing I do on every real

[11:05]

engagement I get paid for. And you just

[11:08]

did it on your first date. Quick

[11:09]

question before we break in. Drop a

[11:11]

comment with how many open ports your

[11:13]

scan found. I want to see that you're

[11:15]

actually following along, not just

[11:17]

watching. Type your number, then keep

[11:18]

going. Now you have your lead, Windows

[11:20]

port 445 SMB. In the next phase, we turn

[11:24]

that lead into a way in. This is where

[11:26]

you find the weakness. Let's go. Look,

[11:29]

if this video makes you actually want to

[11:31]

learn hacking, not just watch it. I

[11:33]

built a place for that. Welcome to the

[11:35]

Hacker Academy. Here's some of the

[11:37]

things you get instant access to. The

[11:39]

OSINT Field Manual. Learn how to find

[11:41]

anyone online from a single photo,

[11:43]

username, or email. A full course on

[11:46]

hacking websites and Wi-Fi hacking.

[11:48]

Learn how to build your own AI hacking

[11:50]

agent that runs on your computer 24/7.

[11:52]

The full beginner to pro hacking guide.

[11:55]

And the pro hacking cheat sheets I

[11:56]

personally use every single day. For 9

[11:58]

bucks a month, you get lifetime access

[12:00]

locked at that price point. You can

[12:02]

check it out via the link in the

[12:03]

description. Phase three. Now we find

[12:06]

the weakness. Here is the single most

[12:08]

valuable skill in all of hacking, and

[12:10]

almost nobody teaches it to beginners

[12:12]

directly. So listen closely. Hacking is

[12:14]

not about inventing attacks from

[12:16]

scratch. It's about finding weaknesses

[12:18]

that already exist in software that's

[12:20]

out of date, and then using attacks that

[12:23]

already exist, that other people have

[12:25]

already built. Read that again in your

[12:26]

head. You are not inventing anything.

[12:29]

You are finding a known weakness and

[12:31]

applying a known solution. That's the

[12:33]

job. That realization alone puts you

[12:35]

ahead of 90% of beginners who think they

[12:38]

need to be a genius coder. You [music]

[12:39]

don't. You need to know how to research.

[12:42]

So let's research. You have your lead

[12:44]

from the scan. Windows, [music] port

[12:46]

445, the SMB service. Here's the

[12:49]

process. You take that information and

[12:52]

you go looking for known weaknesses in

[12:54]

it. The simplest version, you literally

[12:56]

search the internet. You'd search the

[12:58]

service, the system, and the word

[13:00]

vulnerability or exploit. But there's a

[13:02]

faster way built right into your

[13:04]

attacker machine. A tool called

[13:06]

searchsploit. Searchsploit is a giant

[13:08]

offline database of known working

[13:10]

exploits, tens of thousands of them.

[13:13]

Pre-built attacks for known weaknesses.

[13:14]

It's already on your attack box. In your

[13:16]

terminal, type searchsploit, then a

[13:19]

space, then SMB Windows. Now simply

[13:23]

press the enter key on your keyboard to

[13:24]

continue. Look at what comes back. A

[13:27]

list of known attacks against Windows

[13:29]

SMB. These are real exploits. Each one

[13:32]

targets a specific weakness. You're

[13:33]

reading a menu of ways into Windows

[13:35]

machines. Now, for our specific target,

[13:38]

[music] there's one weakness that

[13:40]

matters, and it has a name you need to

[13:42]

know. It's officially called MS17-010,

[13:46]

but the world knows it by another name.

[13:48]

The infamous name you need to know is

[13:50]

EternalBlue. Let me tell you what you're

[13:51]

looking at because this is not just any

[13:53]

vulnerability. EternalBlue was developed

[13:55]

in secret by the National Security

[13:57]

Agency, the NSA, as a cyber weapon. It

[14:00]

was stolen, leaked to the public, and

[14:03]

then used to launch the largest

[14:04]

ransomware attack in history. It shut

[14:06]

down hospitals, banks, [music] shipping

[14:08]

companies across 150 countries in a

[14:11]

single weekend. And that exact weakness

[14:14]

is sitting on the machine in front of

[14:15]

you right now, waiting for you to use

[14:17]

it. That's why I picked this machine for

[14:19]

your first hack. You're not breaking

[14:21]

into some toy. You're about to run one

[14:23]

of the most infamous exploits in the

[14:25]

history of computing on your first day.

[14:27]

Let me break that down so you're not

[14:28]

just copying. -p 445 tells Nmap only

[14:32]

look at port 445. --script tells Nmap to

[14:36]

run one specific check, and

[14:37]

smb-vuln-ms17-010

[14:41]

is [music] the name of the check for

[14:42]

EternalBlue. Now, press enter again and

[14:45]

wait for the results to appear. And

[14:46]

there's your answer. Look for one word

[14:48]

in the output, vulnerable. If you see

[14:50]

it, the machine is wide open to

[14:52]

EternalBlue. You've confirmed your way

[14:54]

in. Stop and appreciate this for a

[14:56]

second. You scanned the target. You

[14:58]

identified what it was [music] running.

[14:59]

You researched a known weakness, and you

[15:01]

confirmed that weakness exists. That is

[15:04]

the complete vulnerability research

[15:06]

process, the same process a professional

[15:08]

follows on a real engagement. You just

[15:10]

did it. Now comes the part you've been

[15:12]

waiting for since you clicked this

[15:14]

video. We take this weakness, and we use

[15:16]

it to break in. Phase four,

[15:18]

exploitation. Let's get inside. We're

[15:20]

going to use the most famous hacking

[15:22]

tool in the world. It's called

[15:24]

Metasploit. Think of it as a massive

[15:26]

toolbox of ready-made exploits,

[15:28]

thousands of them, pre-built. All you do

[15:30]

is pick the right one, point it at your

[15:32]

target, and fire. It's already installed

[15:34]

on your attack box. Let's open it. In

[15:36]

your terminal, type this one word,

[15:38]

msfconsole. Now, wait. The first time it

[15:40]

opens, it takes a moment. You'll see

[15:42]

some artwork appear, maybe a logo made

[15:44]

of text. That's normal. That's

[15:46]

Metasploit starting up. When it's ready,

[15:48]

your prompt changes. Instead of the

[15:50]

normal terminal line, you'll now see

[15:53]

something that starts with msf and then

[15:55]

a number. [music]

[15:56]

That's how you know you're inside

[15:57]

Metasploit now. You're in a different

[15:59]

environment, a command center. First,

[16:01]

[music] we find our exploit. In that msf

[16:03]

prompt, type search space eternalblue.

[16:07]

Press enter. Metasploit searches its

[16:09]

database and shows you a list of modules

[16:11]

related to eternalblue. Look at the

[16:13]

list. You'll see entries with numbers

[16:15]

next to them, 0, [music] 1, 2, and so

[16:18]

on. We want the main exploit. It's the

[16:20]

one with ms17-010

[16:22]

in the name and the word eternalblue.

[16:24]

Here's the easy way to select it. Each

[16:26]

item has a number on the left. Find the

[16:28]

one that says exploit and has

[16:30]

eternalblue and ms17_010

[16:33]

in the path. Note its number. Usually,

[16:35]

it's 0. To select it, type use space and

[16:38]

that number. So, if it's 0, you type use

[16:41]

space 0, press enter. Watch your prompt

[16:43]

again. It just changed. It now shows the

[16:45]

name of the exploit in red. That's

[16:47]

Metasploit telling you this exploit is

[16:49]

now loaded and ready. You've picked your

[16:51]

weapon. Now, we have to tell it two

[16:53]

things, what to attack and where to send

[16:55]

the results. First, what to attack, the

[16:57]

target. In [music] Metasploit, the

[16:59]

target is called RHOSTS, remote host,

[17:01]

the machine you're attacking remotely.

[17:03]

[music] Type set space r h o s t s

[17:07]

space, and then your target's IP

[17:09]

address, the one from the top of your

[17:11]

screen. Second, where to send the

[17:13]

results. When you break into the target,

[17:14]

it It to call back to you, to your

[17:16]

attacker machine. That callback address

[17:18]

is called L-host, local host, it's you.

[17:21]

Now, this is the one spot beginners get

[17:23]

stuck. So, pay attention. You need your

[17:25]

attack boxes own IP address, not the

[17:28]

targets, yours. [music]

[17:29]

On the attack box, your IP is usually

[17:31]

shown somewhere on screen already. Often

[17:33]

labeled as your VPN or tun0 address. If

[17:36]

you can see it, use it. If you're not

[17:38]

sure, there's a simple way. Open a

[17:40]

second terminal and [music] type IP

[17:42]

space A, press enter. Look for the

[17:45]

address under something called tun0.

[17:47]

That's your attacker IP. Once you have

[17:49]

it, [music] back in Metasploit, type set

[17:52]

space Lhost space and your attack box

[17:55]

IP, press enter. Now, Metasploit knows

[17:58]

both things, what to attack and where to

[18:00]

send the shell when it gets in. Before

[18:02]

we fire, let's do what professionals do.

[18:04]

We confirm. Type check, press enter.

[18:07]

Metasploit reaches out to the target,

[18:09]

tests it and tells you. If you see the

[18:11]

words, the target is vulnerable, you're

[18:14]

about to succeed. That's the green

[18:15]

light. Now, the moment. Type one word,

[18:18]

exploit. Press enter. Watch the screen.

[18:21]

You'll see lines start to appear.

[18:22]

Metasploit is sending the attack. You'll

[18:24]

see it sending the exploit, making the

[18:26]

connection, and then, the line you're

[18:28]

waiting for.

[18:29]

>> [music]

[18:29]

>> Meterpreter session one opened. Stop.

[18:32]

Read that line. Meterpreter session

[18:34]

open. That means you are in. You just

[18:36]

broke into a Windows machine. The attack

[18:38]

worked. You are now inside the target.

[18:40]

If you see that line, take a breath

[18:42]

because you just did the thing. The

[18:43]

thing you clicked this video to learn.

[18:45]

You hacked a computer. Now, quick

[18:47]

reassurance because beginners panic

[18:49]

here. After [music] it breaks in, your

[18:51]

prompt changes again. It now says

[18:53]

meterpreter with an arrow. That is not

[18:56]

an error. That is the most beautiful

[18:58]

word in hacking. It means you have a

[18:59]

live connection into the machine you

[19:01]

just compromised. You're not looking at

[19:03]

your computer anymore. You're commanding

[19:05]

theirs. If the exploit didn't work the

[19:07]

first time, don't panic. It happens.

[19:09]

Just type exploit and run it again.

[19:11]

Sometimes Eternal Blue needs a second

[19:13]

attempt. Run it twice. It almost always

[19:15]

lands. So, take stock of what just

[19:17]

happened. You opened Metasploit. You

[19:19]

loaded the NSA's leaked exploit. You set

[19:22]

your [music] target. You confirmed it

[19:24]

was vulnerable, and you fired. And it

[19:26]

worked. You have a live shell inside a

[19:28]

Windows machine. That's not a simulation

[19:30]

of hacking. That is [music] hacking, the

[19:31]

real thing, and you're inside. Now,

[19:33]

let's find out exactly how much power

[19:35]

you have. Because what you're about to

[19:37]

see surprises every beginner. Phase four

[19:40]

continues. What to do once you're in.

[19:42]

You're inside, but right now you have

[19:44]

what's called a basic shell, a plain

[19:46]

command line on the target. It works,

[19:48]

but it's limited, and it can be

[19:50]

unstable. It can drop on you. So, the

[19:52]

first thing a professional does is

[19:54]

upgrade to something better, a

[19:55]

meterpreter shell. Meterpreter is a far

[19:58]

more powerful way to control the

[19:59]

machine. More commands, more stability,

[20:02]

more control. So, let's upgrade. First,

[20:05]

we set this shell aside without closing

[20:07]

it. In your terminal, press control and

[20:09]

Z at the same time. It'll ask if you

[20:11]

want to background the session.

[20:13]

>> [music]

[20:13]

>> Type Y and press enter. That just parked

[20:16]

your shell safely in the background.

[20:17]

It's still alive. You just stepped away

[20:19]

from it for a second. Now, we use a

[20:21]

built-in Metasploit tool that upgrades a

[20:23]

basic shell into a meterpreter shell.

[20:25]

Type [music] search space shell

[20:27]

{underscore} to {underscore} meterpreter

[20:29]

and press enter. You'll see a module

[20:31]

appear. Its path is post {slash} multi

[20:33]

{slash} manage {slash} shell

[20:35]

{underscore} to {underscore}

[20:36]

meterpreter. Select [music] it, type use

[20:39]

space, and the number next to it,

[20:41]

usually zero, and press enter. Now, this

[20:43]

tool needs to know which shell to

[20:44]

upgrade, the one you just parked. Type

[20:47]

set space session space one, and press

[20:50]

enter. That points it at your

[20:51]

backgrounded shell, session one. Now,

[20:54]

type run and press enter. Metasploit

[20:57]

takes your basic shell and upgrades it.

[20:59]

In a few seconds, you'll see a new

[21:00]

meterpreter session open. You just

[21:02]

leveled up your access.

[21:04]

>> [music]

[21:04]

>> To jump into it, type sessions. Then,

[21:06]

look at the list, find the one that says

[21:08]

meterpreter, note its number, then type

[21:11]

session space and that number. Press

[21:13]

enter. Now the question every hacker

[21:15]

asks, who am I? Type getuid and press

[21:19]

enter. [music]

[21:19]

Look at what it says, NT Authority

[21:22]

backslash system. Stop. System is the

[21:25]

single highest level of power on a

[21:27]

Windows machine, higher than the

[21:29]

administrator, higher than the owner.

[21:31]

System means total control, every file,

[21:34]

every password, every account, all of

[21:37]

it, yours. Here's why that's remarkable.

[21:39]

On most hacks, you break in as some weak

[21:43]

limited user, and then you have to grind

[21:45]

through a whole phase called privilege

[21:48]

escalation, climbing your way up to the

[21:50]

top. EternalBlue is so powerful it put

[21:53]

you near the very top immediately. But

[21:55]

here's a subtle thing the pros know.

[21:57]

Being system is not the same as your

[21:58]

process being stable as system. To lock

[22:01]

in rock solid control, we migrate into a

[22:03]

process that's already running as

[22:05]

system. Type PS and press enter. This

[22:08]

lists every running process on the

[22:09]

machine. Look down the list, find one

[22:11]

running as NT Authority system. A common

[22:15]

reliable one is a process that handles

[22:17]

Windows internals. Note the process ID,

[22:20]

>> [music]

[22:20]

>> then type migrate space and that process

[22:22]

ID. Press enter. Metasploit moves your

[22:25]

session into that stable process. Now

[22:27]

your foothold is solid, it won't drop on

[22:29]

you. This is exactly the move a real

[22:31]

operator makes. Now let's collect the

[22:33]

proof. The room wants you to find flags,

[22:36]

hidden pieces of text that prove you had

[22:37]

access. They're scattered in specific

[22:40]

locations, the system root, a user's

[22:42]

folder, the administrator's files. The

[22:44]

fastest professional way to find them,

[22:47]

drop into a shell on the target. Type

[22:49]

shell and press enter. You're now in a

[22:52]

Windows command line on their machine.

[22:54]

Then you search the entire drive for

[22:55]

anything named [music] flag. The flags

[22:57]

are sitting in those key locations. As

[22:59]

you find each one, you copy the text

[23:02]

inside.

[23:02]

>> [music]

[23:02]

>> Then back on the Blue Room page in your

[23:04]

browser, you paste each flag into its

[23:06]

answer box and submit. And when that

[23:08]

final answer turns green, that's it.

[23:10]

[music] The room is solved, officially.

[23:12]

You scanned the target, found its

[23:14]

weakness, exploited it, upgraded your

[23:17]

access,

[23:17]

>> [music]

[23:17]

>> migrated to a stable system process, and

[23:20]

you proved your control. You completed a

[23:22]

full, real-world attack chain. Take a

[23:25]

real moment with that, because most

[23:27]

people who say they want to learn

[23:28]

hacking never get this far. They watch,

[23:31]

they plan, they tell themselves someday.

[23:34]

You didn't plan. You did it today. But

[23:37]

owning the machine is only four of the

[23:39]

five phases. There's one more, and in

[23:42]

the real world, it's the phase that

[23:43]

actually pays your salary. Let me show

[23:45]

you the part that turns this from a

[23:47]

hobby into a career. Phase five,

[23:50]

reporting. And I know what you're

[23:51]

thinking. Writing a report sounds like

[23:53]

the most boring part of hacking. So let

[23:56]

me change your mind in about 60 seconds.

[23:58]

Here's the truth nobody tells beginners.

[24:00]

The hacking you just did, the scanning,

[24:03]

the exploiting, the breaking in, that's

[24:05]

not what companies pay you for. They pay

[24:07]

you for the report. Think about it. A

[24:09]

company hires an ethical hacker, a

[24:12]

penetration tester, to break into their

[24:14]

systems on purpose. Why? Because they

[24:17]

want to know where the holes are before

[24:19]

a real criminal finds them. The break-in

[24:21]

proves the hole exists, but the report

[24:24]

is what let them fix it. The report is

[24:26]

the product. It's literally the thing

[24:28]

you deliver. It's the thing they're

[24:30]

paying for. A hacker who can break in

[24:32]

but can't write it up doesn't get hired

[24:34]

twice. A hacker who can break in and

[24:36]

explain it clearly names their price.

Keep this transcript

Save it to LunaNotes and it becomes a real note in your library — editable, searchable, and ready to turn into flashcards or a diagram. Free to start.

Save to LunaNotes

Or download subtitles for another video.

These subtitles were extracted using the Free YouTube Subtitle Downloader by LunaNotes.

Related videos

Download Cyber Security Full Course Subtitles (11-Hour Edureka Training for Beginners)

Download Cyber Security Full Course Subtitles (11-Hour Edureka Training for Beginners)

Enhance your learning experience by downloading subtitles for this comprehensive 11-hour Cyber Security Full Course by Edureka. Perfect for beginners, these captions allow you to follow complex training topics, improve comprehension, and easily reference key security concepts offline.

Download Subtitles for Harvard CS50 2026 Computer Science Course

Download Subtitles for Harvard CS50 2026 Computer Science Course

Enhance your learning experience with downloadable subtitles for the Harvard CS50 2026 full computer science course. Easily follow along with lectures, improve comprehension, and access the content offline anytime. Perfect for students and enthusiasts aiming to master computer science concepts.

Download Subtitles for How to Setup an SSH Server on Windows

Download Subtitles for How to Setup an SSH Server on Windows

Easily follow along with our step-by-step guide by downloading accurate subtitles for the 'How to Setup an SSH Server on Windows' video. Enhance your learning experience, understand every detail clearly, and access the content anytime.

Download Subtitles for XLMRat Lab - Cyberdefenders Video

Download Subtitles for XLMRat Lab - Cyberdefenders Video

Enhance your understanding of cybersecurity with downloadable subtitles for the XLMRat Lab - Cyberdefenders video. Access accurate captions to follow complex concepts easily and improve learning efficiency.

Download Subtitles for 'How Transistors Run Code' Video

Download Subtitles for 'How Transistors Run Code' Video

Enhance your understanding of computing with downloadable subtitles for the "How Transistors Run Code" video. Access clear, accurate captions to follow along easily and reinforce your learning experience.

Most viewed

Untertitel für 'Nicos Weg' Deutsch lernen A1 Film herunterladen

Untertitel für 'Nicos Weg' Deutsch lernen A1 Film herunterladen

Laden Sie die Untertitel für den gesamten Film 'Nicos Weg' herunter, um Ihr Deutschlernen auf A1 Niveau zu unterstützen. Untertitel helfen Ihnen, Wortschatz und Aussprache besser zu verstehen und verbessern das Hörverständnis effektiv.

ดาวน์โหลดซับไตเติ้ล DMD LAND 3 The Final Land Day 1

ดาวน์โหลดซับไตเติ้ล DMD LAND 3 The Final Land Day 1

ดาวน์โหลดซับไตเติ้ลสำหรับวิดีโอ DMD LAND 3 The Final Land Day 1 เพื่อช่วยให้เข้าใจเนื้อหาได้ง่ายขึ้น และเพิ่มความสะดวกในการติดตามทุกช่วงเวลา เหมาะสำหรับผู้ชมที่ต้องการความชัดเจนและเข้าถึงข้อมูลอย่างครบถ้วน

Subtítulos para TIPOS DE APEGO | 6 DE COPAS Episodio 56

Subtítulos para TIPOS DE APEGO | 6 DE COPAS Episodio 56

Descarga los subtítulos para el episodio 56 de la tercera temporada de 6 DE COPAS, centrado en los tipos de apego. Mejora tu comprensión y disfruta del contenido en detalle con nuestros subtítulos precisos y accesibles.

Descarga Subtítulos para NARCISISMO | 6 DE COPAS - Episodio 63

Descarga Subtítulos para NARCISISMO | 6 DE COPAS - Episodio 63

Accede fácilmente a los subtítulos del episodio 63 de '6 DE COPAS', centrado en el narcisismo. Descargar estos subtítulos te ayudará a entender mejor el contenido y mejorar la experiencia de visualización.

Download Subtitles for Inside Out 2 Extended Preview 2024

Download Subtitles for Inside Out 2 Extended Preview 2024

Get accurate and easy-to-follow subtitles for the Inside Out 2 extended preview (2024) featured on Fandango at Home. Enhance your viewing experience and ensure you catch every detail of this exciting preview with our downloadable captions.

Found this transcript useful?

Take it with you. One click puts it in your own LunaNotes library.

Save to LunaNotes

Start taking better notes today with LunaNotes