Download Subtitles: How To Learn Hacking – A Practical Demo
How To Learn Hacking - A Practical Demo
The Hacker Academy
SRT - Most compatible format for video players (VLC, media players, video editors)
VTT - Web Video Text Tracks for HTML5 video and browsers
TXT - Plain text with timestamps for easy reading and editing
Scroll to view all subtitles
You clicked this because you want to
learn how to hack and you're tired of
videos that promise to teach you then
spend 20 minutes telling you to go learn
network or learn Linux first and never
actually show you anything. This is
different. In the next few minutes
you're going to break into a real
computer with your own hands and you'll
understand exactly how you did it. I'm
going to put my hands on the keyboard
with you. Every command, every click,
every line that shows up on your screen
explained. If you have never opened a
terminal in your life you are exactly
who I made this for. Here's what you'll
walk away knowing. The [music] actual
five-step process every professional
hacker uses. How to scan a target and
find its weak points. How to break in
and what to do once you're inside. Not
theory, the real skills, the ones
companies pay six-figures for and we're
not going to practice on anything
illegal. There's a free website that
gives you a real target machine built
specifically for this. You attack it in
your browser. Nothing to install,
completely legal. So open a second tab
right now because you're not going to
watch me hack. You're going to hack
right alongside me. Most people will
watch this whole thing and never type a
single command. They'll stay stuck
forever. Be the one who actually follows
along because 15 minutes from now you'll
have done the thing you've been wanting
to learn for real. Before we touch
anything, one rule and it matters more
than anything else in this video. You
only hack machines you own or machines
you have written permission to attack.
The target we're using today is built
[music] for this. It's legal. It's
designed to be hacked by beginners
learning exactly what you're learning.
That's allowed. What's not allowed?
Pointing these tools at a website, a
network or a device you don't own. Even
just scanning a stranger's system
without permission [music] is a crime in
most countries. Here's the first thing
that's going to change how you see
hacking forever. Hacking is not random
typing until you get in. That's a movie.
Real hacking is a process, a repeatable
step-by-step process. And once you know
it, every hack you ever attempt becomes
the same five steps in the same order.
Professional pen testers follow it.
Government red teams follow it. Bug
bounty hunters follow it. After today,
you'll follow it, too. Write these down.
[music]
Five phases. Phase one, reconnaissance.
You gather information about your
target. Who is it? What is it? What's it
running? Before you ever attack, you
learn. Phase two, scanning. You map the
target. You find its open doors, the
services running behind them. This is
where you find your way in. Phase three,
[music]
exploitation. You take a weakness you
found and you use it to break in. Phase
four, access. You're inside. Now you
take control. You see what you can reach
and you climb to the highest level of
power on the machine. Phase [music]
five, reporting. You document everything
you found because in the real world,
this is the part that pays. Companies
hire you to find the holes, then tell
them how to fix them. That's the entire
craft. Recon, scan, exploit, access,
report. Say it back in your head right
now. Here's why this matters so much for
you as a beginner. Most people drown
because they think they need to memorize
a thousand tricks.
>> [music]
>> They don't. You need to learn one
process, then you just get better at
each phase over time. A beginner thinks
hacking is about secret knowledge. A
professional knows it's about working
the process patiently [music]
every time. And here's the best part.
We're not going to just talk about these
five phases. We're going to walk through
all five on a real machine together
[music] starting right now. So let's get
you set up. Okay, hands on keyboard.
Let's get you set up. Follow along
exactly. I'll wait for you at every
step. Open a new tab. Go to
tryhackme.com. This is the platform
we're using. It's free to start. It
gives you real machines to legally hack.
And the best part, you don't install
anything. Everything runs in your
browser. If you're on a laptop you
bought yesterday or a five-year-old
machine, it doesn't matter. It all
happens in the browser. Sign up for a
free account, email and password. Takes
30 seconds. I'll wait. Pause the video
if you need to. Got your account? Good.
Now, in the search bar at the top, type
the word blue. Just blue. You're looking
for a room called blue. A room is just
TryHackMe's word for a guided hacking
challenge. Click into the blue room.
Now, why this machine? I picked blue on
purpose. It's a Windows computer with a
famous weakness. The exact kind of
weakness that took down hospitals and
companies across the world a few years
ago. You're going to exploit that same
weakness today as your very first hack.
It's dramatic and it works every time.
Perfect for your first win. Here's your
first real action. On the room page,
you'll see a button that says start
machine. Click it.
>> [music]
>> This boots up your target, the actual
computer you're going to hack. It takes
about a minute to start. While it boots,
a box appears, usually at the top of the
page, and it shows you an IP address,
something like [music] 10 10 and then
two more numbers. IP address is your
target. That's the address of the
machine you're attacking. Write it down
or just keep that box visible. You're
going to need it constantly. Every tool
you use, you point at that IP. Quick
explanation, because I don't want you
just copying. I want you understanding.
IP address is just a location on a
network, like a street address for a
computer. When I say point your tool at
the target, I mean send it to that IP.
That's how your attacker machine finds
the target machine across the network.
Now, we need to use your attacker
machine, the computer you attack from.
On the room page, look for a button that
says start attack box. Click it. The
attack box is a ready-made hacking
computer. It runs in your browser. It
already has every tool we need
pre-installed. You don't set up
anything. It just appears on the right
side of your screen. Give it a minute to
load. When it loads, you'll see a
desktop. It looks like a normal computer
desktop, because it is one. It's just
running in your browser and it's loaded
with hacker tools. Now, [music]
the part that scares every single
beginner, the terminal on that attack
box desktop. Find the icon that looks
like a little black screen, usually in
the taskbar. It might be called
terminal. Click it. A black window opens
with some text and a blinking cursor.
Stop. [music] Take a breath. This black
window is not scary. This is just where
you type commands instead of clicking
buttons. That's the only difference
between this and your normal computer.
Instead of clicking icons with the
mouse, you type instructions with words.
That's [music] it. That's all a terminal
is. You type a command. You press enter.
The computer does the thing. Then it
shows you the result. Type, enter, read.
[music] That's the entire rhythm of
everything we're about to do. Let's
prove it's not scary. In that black
window, type this exact word,
press enter. The terminal just told you
which user you are on the attacker
machine. You asked the computer a
question in plain words. It answered.
That's all a terminal is. A
conversation. You just had your first
one. So, let's recap where you are right
now. You have a target machine running
with an IP address. You have your
attacker machine, the attack box, loaded
with tools, and you have a terminal
open, ready for commands. That's a
complete professional hacking setup. You
built it in under 2 minutes. Now, let's
start the actual hack. Phase one,
reconnaissance. Recon means gathering
information before you attack. In the
real world, on a paid job, this phase is
huge. You'd research the company, find
employee names and emails, map out their
public websites, look at what technology
they use. You learn everything you can
before you touch anything. Why? Because
you can't attack what you don't
understand. The more you know about the
target, the more ways in you'll find.
Amateurs rush to attack. Professionals
spend most of their time here, learning.
But for our target today, recon is
[music] simple. We already have the one
thing we need, the target's IP address,
that box on your screen. So, our recon
question is short. What is this machine?
What's running on it? Where are the
doors? And to answer that, we move into
the most important skill you will learn
today, scanning. Phase two, scanning.
Pay close attention here because this is
the skill you will use in every single
hack you ever do. Master this one tool
and you're already ahead of most
beginners. The tool is called Nmap.
Nmap, short for network mapper, it's
free. It's already installed on your
attack box and it is the most important
reconnaissance tool in the world. Every
professional uses it every single day.
Here's what Nmap actually does. Remember
I said the target is like a building.
Nmap walks around that building and
checks every single door and window. It
tells you which ones are open, which are
locked, and what's [music] behind each
open one. In computer terms, those doors
are called ports. A port is just a
numbered entrance into a computer. Each
service running on a machine, a website,
a file share, a remote login, sits
behind a specific port. Find the open
ports and you found your possible ways
in. Let's run your first scan. Go to
your terminal, the black window, and
type this exactly, nmap, then a space,
then your target's IP address. Now you
wait. Nmap is knocking on every door. It
takes a few seconds, maybe a minute.
Don't touch anything. Let it work. And
there it is. Nmap just gave you a list.
Look at it. You'll see a column of
numbers. Each one followed by the word
open or closed. The open ones are what
matter. You'll probably see port 135,
port 139, and the important one, port
445, all open. Right now you know the
doors are open, but you don't know
what's behind them yet. A basic scan
only shows you the doors, not what's
inside. So, let's go deeper. This is
where you learn your first flag. A flag
is just an option you add to a command.
It changes what the tool does.
>> [music]
>> You add a flag by typing a space, then a
dash, then a letter. Type this, nmap
space {dash} capital S capital V space
your IP. That {dash} capital S capital V
means version detection. [music] Now,
Nmap doesn't just tell you a door is
open. It tells you exactly what service
is running behind it and which version
of that service. Press enter. Wait
again. [music]
This one takes a little longer. When it
comes back, look at port 445 next to it.
We'll now see a service name, something
about Microsoft and Windows. Nmap is
telling you this is a Windows machine
and port 445 is running something called
SMB, server message block. It's the
service Windows uses to share files.
This is the moment that matters. Write
down what you see, [music] the operating
system, Windows, the open port, 445, the
service, SMB, because here's the secret
at the center of all hacking. Those
details are your lead, a specific
service on a specific system. Old
software has known weaknesses and when
you know exactly what's running, you can
go find exactly how to break it. Let's
do one more scan, the smartest one.
{dash} capital S capital C runs Nmap's
built-in scripts. These are little
automated checks that look for common
problems. Sometimes, this single command
finds the weakness for you
automatically. Press enter, let it run.
Stop and realize what you just did. You
scanned a real machine. You found its
open ports. You identified the operating
system and you fingerprinted the exact
service running on the target. That is
professional reconnaissance. That's the
first thing I do on every real
engagement I get paid for. And you just
did it on your first date. Quick
question before we break in. Drop a
comment with how many open ports your
scan found. I want to see that you're
actually following along, not just
watching. Type your number, then keep
going. Now you have your lead, Windows
port 445 SMB. In the next phase, we turn
that lead into a way in. This is where
you find the weakness. Let's go. Look,
if this video makes you actually want to
learn hacking, not just watch it. I
built a place for that. Welcome to the
Hacker Academy. Here's some of the
things you get instant access to. The
OSINT Field Manual. Learn how to find
anyone online from a single photo,
username, or email. A full course on
hacking websites and Wi-Fi hacking.
Learn how to build your own AI hacking
agent that runs on your computer 24/7.
The full beginner to pro hacking guide.
And the pro hacking cheat sheets I
personally use every single day. For 9
bucks a month, you get lifetime access
locked at that price point. You can
check it out via the link in the
description. Phase three. Now we find
the weakness. Here is the single most
valuable skill in all of hacking, and
almost nobody teaches it to beginners
directly. So listen closely. Hacking is
not about inventing attacks from
scratch. It's about finding weaknesses
that already exist in software that's
out of date, and then using attacks that
already exist, that other people have
already built. Read that again in your
head. You are not inventing anything.
You are finding a known weakness and
applying a known solution. That's the
job. That realization alone puts you
ahead of 90% of beginners who think they
need to be a genius coder. You [music]
don't. You need to know how to research.
So let's research. You have your lead
from the scan. Windows, [music] port
445, the SMB service. Here's the
process. You take that information and
you go looking for known weaknesses in
it. The simplest version, you literally
search the internet. You'd search the
service, the system, and the word
vulnerability or exploit. But there's a
faster way built right into your
attacker machine. A tool called
searchsploit. Searchsploit is a giant
offline database of known working
exploits, tens of thousands of them.
Pre-built attacks for known weaknesses.
It's already on your attack box. In your
terminal, type searchsploit, then a
space, then SMB Windows. Now simply
press the enter key on your keyboard to
continue. Look at what comes back. A
list of known attacks against Windows
SMB. These are real exploits. Each one
targets a specific weakness. You're
reading a menu of ways into Windows
machines. Now, for our specific target,
[music] there's one weakness that
matters, and it has a name you need to
know. It's officially called MS17-010,
but the world knows it by another name.
The infamous name you need to know is
EternalBlue. Let me tell you what you're
looking at because this is not just any
vulnerability. EternalBlue was developed
in secret by the National Security
Agency, the NSA, as a cyber weapon. It
was stolen, leaked to the public, and
then used to launch the largest
ransomware attack in history. It shut
down hospitals, banks, [music] shipping
companies across 150 countries in a
single weekend. And that exact weakness
is sitting on the machine in front of
you right now, waiting for you to use
it. That's why I picked this machine for
your first hack. You're not breaking
into some toy. You're about to run one
of the most infamous exploits in the
history of computing on your first day.
Let me break that down so you're not
just copying. -p 445 tells Nmap only
look at port 445. --script tells Nmap to
run one specific check, and
smb-vuln-ms17-010
is [music] the name of the check for
EternalBlue. Now, press enter again and
wait for the results to appear. And
there's your answer. Look for one word
in the output, vulnerable. If you see
it, the machine is wide open to
EternalBlue. You've confirmed your way
in. Stop and appreciate this for a
second. You scanned the target. You
identified what it was [music] running.
You researched a known weakness, and you
confirmed that weakness exists. That is
the complete vulnerability research
process, the same process a professional
follows on a real engagement. You just
did it. Now comes the part you've been
waiting for since you clicked this
video. We take this weakness, and we use
it to break in. Phase four,
exploitation. Let's get inside. We're
going to use the most famous hacking
tool in the world. It's called
Metasploit. Think of it as a massive
toolbox of ready-made exploits,
thousands of them, pre-built. All you do
is pick the right one, point it at your
target, and fire. It's already installed
on your attack box. Let's open it. In
your terminal, type this one word,
msfconsole. Now, wait. The first time it
opens, it takes a moment. You'll see
some artwork appear, maybe a logo made
of text. That's normal. That's
Metasploit starting up. When it's ready,
your prompt changes. Instead of the
normal terminal line, you'll now see
something that starts with msf and then
a number. [music]
That's how you know you're inside
Metasploit now. You're in a different
environment, a command center. First,
[music] we find our exploit. In that msf
prompt, type search space eternalblue.
Press enter. Metasploit searches its
database and shows you a list of modules
related to eternalblue. Look at the
list. You'll see entries with numbers
next to them, 0, [music] 1, 2, and so
on. We want the main exploit. It's the
one with ms17-010
in the name and the word eternalblue.
Here's the easy way to select it. Each
item has a number on the left. Find the
one that says exploit and has
eternalblue and ms17_010
in the path. Note its number. Usually,
it's 0. To select it, type use space and
that number. So, if it's 0, you type use
space 0, press enter. Watch your prompt
again. It just changed. It now shows the
name of the exploit in red. That's
Metasploit telling you this exploit is
now loaded and ready. You've picked your
weapon. Now, we have to tell it two
things, what to attack and where to send
the results. First, what to attack, the
target. In [music] Metasploit, the
target is called RHOSTS, remote host,
the machine you're attacking remotely.
[music] Type set space r h o s t s
space, and then your target's IP
address, the one from the top of your
screen. Second, where to send the
results. When you break into the target,
it It to call back to you, to your
attacker machine. That callback address
is called L-host, local host, it's you.
Now, this is the one spot beginners get
stuck. So, pay attention. You need your
attack boxes own IP address, not the
targets, yours. [music]
On the attack box, your IP is usually
shown somewhere on screen already. Often
labeled as your VPN or tun0 address. If
you can see it, use it. If you're not
sure, there's a simple way. Open a
second terminal and [music] type IP
space A, press enter. Look for the
address under something called tun0.
That's your attacker IP. Once you have
it, [music] back in Metasploit, type set
space Lhost space and your attack box
IP, press enter. Now, Metasploit knows
both things, what to attack and where to
send the shell when it gets in. Before
we fire, let's do what professionals do.
We confirm. Type check, press enter.
Metasploit reaches out to the target,
tests it and tells you. If you see the
words, the target is vulnerable, you're
about to succeed. That's the green
light. Now, the moment. Type one word,
exploit. Press enter. Watch the screen.
You'll see lines start to appear.
Metasploit is sending the attack. You'll
see it sending the exploit, making the
connection, and then, the line you're
waiting for.
>> [music]
>> Meterpreter session one opened. Stop.
Read that line. Meterpreter session
open. That means you are in. You just
broke into a Windows machine. The attack
worked. You are now inside the target.
If you see that line, take a breath
because you just did the thing. The
thing you clicked this video to learn.
You hacked a computer. Now, quick
reassurance because beginners panic
here. After [music] it breaks in, your
prompt changes again. It now says
meterpreter with an arrow. That is not
an error. That is the most beautiful
word in hacking. It means you have a
live connection into the machine you
just compromised. You're not looking at
your computer anymore. You're commanding
theirs. If the exploit didn't work the
first time, don't panic. It happens.
Just type exploit and run it again.
Sometimes Eternal Blue needs a second
attempt. Run it twice. It almost always
lands. So, take stock of what just
happened. You opened Metasploit. You
loaded the NSA's leaked exploit. You set
your [music] target. You confirmed it
was vulnerable, and you fired. And it
worked. You have a live shell inside a
Windows machine. That's not a simulation
of hacking. That is [music] hacking, the
real thing, and you're inside. Now,
let's find out exactly how much power
you have. Because what you're about to
see surprises every beginner. Phase four
continues. What to do once you're in.
You're inside, but right now you have
what's called a basic shell, a plain
command line on the target. It works,
but it's limited, and it can be
unstable. It can drop on you. So, the
first thing a professional does is
upgrade to something better, a
meterpreter shell. Meterpreter is a far
more powerful way to control the
machine. More commands, more stability,
more control. So, let's upgrade. First,
we set this shell aside without closing
it. In your terminal, press control and
Z at the same time. It'll ask if you
want to background the session.
>> [music]
>> Type Y and press enter. That just parked
your shell safely in the background.
It's still alive. You just stepped away
from it for a second. Now, we use a
built-in Metasploit tool that upgrades a
basic shell into a meterpreter shell.
Type [music] search space shell
{underscore} to {underscore} meterpreter
and press enter. You'll see a module
appear. Its path is post {slash} multi
{slash} manage {slash} shell
{underscore} to {underscore}
meterpreter. Select [music] it, type use
space, and the number next to it,
usually zero, and press enter. Now, this
tool needs to know which shell to
upgrade, the one you just parked. Type
set space session space one, and press
enter. That points it at your
backgrounded shell, session one. Now,
type run and press enter. Metasploit
takes your basic shell and upgrades it.
In a few seconds, you'll see a new
meterpreter session open. You just
leveled up your access.
>> [music]
>> To jump into it, type sessions. Then,
look at the list, find the one that says
meterpreter, note its number, then type
session space and that number. Press
enter. Now the question every hacker
asks, who am I? Type getuid and press
enter. [music]
Look at what it says, NT Authority
backslash system. Stop. System is the
single highest level of power on a
Windows machine, higher than the
administrator, higher than the owner.
System means total control, every file,
every password, every account, all of
it, yours. Here's why that's remarkable.
On most hacks, you break in as some weak
limited user, and then you have to grind
through a whole phase called privilege
escalation, climbing your way up to the
top. EternalBlue is so powerful it put
you near the very top immediately. But
here's a subtle thing the pros know.
Being system is not the same as your
process being stable as system. To lock
in rock solid control, we migrate into a
process that's already running as
system. Type PS and press enter. This
lists every running process on the
machine. Look down the list, find one
running as NT Authority system. A common
reliable one is a process that handles
Windows internals. Note the process ID,
>> [music]
>> then type migrate space and that process
ID. Press enter. Metasploit moves your
session into that stable process. Now
your foothold is solid, it won't drop on
you. This is exactly the move a real
operator makes. Now let's collect the
proof. The room wants you to find flags,
hidden pieces of text that prove you had
access. They're scattered in specific
locations, the system root, a user's
folder, the administrator's files. The
fastest professional way to find them,
drop into a shell on the target. Type
shell and press enter. You're now in a
Windows command line on their machine.
Then you search the entire drive for
anything named [music] flag. The flags
are sitting in those key locations. As
you find each one, you copy the text
inside.
>> [music]
>> Then back on the Blue Room page in your
browser, you paste each flag into its
answer box and submit. And when that
final answer turns green, that's it.
[music] The room is solved, officially.
You scanned the target, found its
weakness, exploited it, upgraded your
access,
>> [music]
>> migrated to a stable system process, and
you proved your control. You completed a
full, real-world attack chain. Take a
real moment with that, because most
people who say they want to learn
hacking never get this far. They watch,
they plan, they tell themselves someday.
You didn't plan. You did it today. But
owning the machine is only four of the
five phases. There's one more, and in
the real world, it's the phase that
actually pays your salary. Let me show
you the part that turns this from a
hobby into a career. Phase five,
reporting. And I know what you're
thinking. Writing a report sounds like
the most boring part of hacking. So let
me change your mind in about 60 seconds.
Here's the truth nobody tells beginners.
The hacking you just did, the scanning,
the exploiting, the breaking in, that's
not what companies pay you for. They pay
you for the report. Think about it. A
company hires an ethical hacker, a
penetration tester, to break into their
systems on purpose. Why? Because they
want to know where the holes are before
a real criminal finds them. The break-in
proves the hole exists, but the report
is what let them fix it. The report is
the product. It's literally the thing
you deliver. It's the thing they're
paying for. A hacker who can break in
but can't write it up doesn't get hired
twice. A hacker who can break in and
explain it clearly names their price.
Full transcript without timestamps
You clicked this because you want to learn how to hack and you're tired of videos that promise to teach you then spend 20 minutes telling you to go learn network or learn Linux first and never actually show you anything. This is different. In the next few minutes you're going to break into a real computer with your own hands and you'll understand exactly how you did it. I'm going to put my hands on the keyboard with you. Every command, every click, every line that shows up on your screen explained. If you have never opened a terminal in your life you are exactly who I made this for. Here's what you'll walk away knowing. The [music] actual five-step process every professional hacker uses. How to scan a target and find its weak points. How to break in and what to do once you're inside. Not theory, the real skills, the ones companies pay six-figures for and we're not going to practice on anything illegal. There's a free website that gives you a real target machine built specifically for this. You attack it in your browser. Nothing to install, completely legal. So open a second tab right now because you're not going to watch me hack. You're going to hack right alongside me. Most people will watch this whole thing and never type a single command. They'll stay stuck forever. Be the one who actually follows along because 15 minutes from now you'll have done the thing you've been wanting to learn for real. Before we touch anything, one rule and it matters more than anything else in this video. You only hack machines you own or machines you have written permission to attack. The target we're using today is built [music] for this. It's legal. It's designed to be hacked by beginners learning exactly what you're learning. That's allowed. What's not allowed? Pointing these tools at a website, a network or a device you don't own. Even just scanning a stranger's system without permission [music] is a crime in most countries. Here's the first thing that's going to change how you see hacking forever. Hacking is not random typing until you get in. That's a movie. Real hacking is a process, a repeatable step-by-step process. And once you know it, every hack you ever attempt becomes the same five steps in the same order. Professional pen testers follow it. Government red teams follow it. Bug bounty hunters follow it. After today, you'll follow it, too. Write these down. [music] Five phases. Phase one, reconnaissance. You gather information about your target. Who is it? What is it? What's it running? Before you ever attack, you learn. Phase two, scanning. You map the target. You find its open doors, the services running behind them. This is where you find your way in. Phase three, [music] exploitation. You take a weakness you found and you use it to break in. Phase four, access. You're inside. Now you take control. You see what you can reach and you climb to the highest level of power on the machine. Phase [music] five, reporting. You document everything you found because in the real world, this is the part that pays. Companies hire you to find the holes, then tell them how to fix them. That's the entire craft. Recon, scan, exploit, access, report. Say it back in your head right now. Here's why this matters so much for you as a beginner. Most people drown because they think they need to memorize a thousand tricks. >> [music] >> They don't. You need to learn one process, then you just get better at each phase over time. A beginner thinks hacking is about secret knowledge. A professional knows it's about working the process patiently [music] every time. And here's the best part. We're not going to just talk about these five phases. We're going to walk through all five on a real machine together [music] starting right now. So let's get you set up. Okay, hands on keyboard. Let's get you set up. Follow along exactly. I'll wait for you at every step. Open a new tab. Go to tryhackme.com. This is the platform we're using. It's free to start. It gives you real machines to legally hack. And the best part, you don't install anything. Everything runs in your browser. If you're on a laptop you bought yesterday or a five-year-old machine, it doesn't matter. It all happens in the browser. Sign up for a free account, email and password. Takes 30 seconds. I'll wait. Pause the video if you need to. Got your account? Good. Now, in the search bar at the top, type the word blue. Just blue. You're looking for a room called blue. A room is just TryHackMe's word for a guided hacking challenge. Click into the blue room. Now, why this machine? I picked blue on purpose. It's a Windows computer with a famous weakness. The exact kind of weakness that took down hospitals and companies across the world a few years ago. You're going to exploit that same weakness today as your very first hack. It's dramatic and it works every time. Perfect for your first win. Here's your first real action. On the room page, you'll see a button that says start machine. Click it. >> [music] >> This boots up your target, the actual computer you're going to hack. It takes about a minute to start. While it boots, a box appears, usually at the top of the page, and it shows you an IP address, something like [music] 10 10 and then two more numbers. IP address is your target. That's the address of the machine you're attacking. Write it down or just keep that box visible. You're going to need it constantly. Every tool you use, you point at that IP. Quick explanation, because I don't want you just copying. I want you understanding. IP address is just a location on a network, like a street address for a computer. When I say point your tool at the target, I mean send it to that IP. That's how your attacker machine finds the target machine across the network. Now, we need to use your attacker machine, the computer you attack from. On the room page, look for a button that says start attack box. Click it. The attack box is a ready-made hacking computer. It runs in your browser. It already has every tool we need pre-installed. You don't set up anything. It just appears on the right side of your screen. Give it a minute to load. When it loads, you'll see a desktop. It looks like a normal computer desktop, because it is one. It's just running in your browser and it's loaded with hacker tools. Now, [music] the part that scares every single beginner, the terminal on that attack box desktop. Find the icon that looks like a little black screen, usually in the taskbar. It might be called terminal. Click it. A black window opens with some text and a blinking cursor. Stop. [music] Take a breath. This black window is not scary. This is just where you type commands instead of clicking buttons. That's the only difference between this and your normal computer. Instead of clicking icons with the mouse, you type instructions with words. That's [music] it. That's all a terminal is. You type a command. You press enter. The computer does the thing. Then it shows you the result. Type, enter, read. [music] That's the entire rhythm of everything we're about to do. Let's prove it's not scary. In that black window, type this exact word, press enter. The terminal just told you which user you are on the attacker machine. You asked the computer a question in plain words. It answered. That's all a terminal is. A conversation. You just had your first one. So, let's recap where you are right now. You have a target machine running with an IP address. You have your attacker machine, the attack box, loaded with tools, and you have a terminal open, ready for commands. That's a complete professional hacking setup. You built it in under 2 minutes. Now, let's start the actual hack. Phase one, reconnaissance. Recon means gathering information before you attack. In the real world, on a paid job, this phase is huge. You'd research the company, find employee names and emails, map out their public websites, look at what technology they use. You learn everything you can before you touch anything. Why? Because you can't attack what you don't understand. The more you know about the target, the more ways in you'll find. Amateurs rush to attack. Professionals spend most of their time here, learning. But for our target today, recon is [music] simple. We already have the one thing we need, the target's IP address, that box on your screen. So, our recon question is short. What is this machine? What's running on it? Where are the doors? And to answer that, we move into the most important skill you will learn today, scanning. Phase two, scanning. Pay close attention here because this is the skill you will use in every single hack you ever do. Master this one tool and you're already ahead of most beginners. The tool is called Nmap. Nmap, short for network mapper, it's free. It's already installed on your attack box and it is the most important reconnaissance tool in the world. Every professional uses it every single day. Here's what Nmap actually does. Remember I said the target is like a building. Nmap walks around that building and checks every single door and window. It tells you which ones are open, which are locked, and what's [music] behind each open one. In computer terms, those doors are called ports. A port is just a numbered entrance into a computer. Each service running on a machine, a website, a file share, a remote login, sits behind a specific port. Find the open ports and you found your possible ways in. Let's run your first scan. Go to your terminal, the black window, and type this exactly, nmap, then a space, then your target's IP address. Now you wait. Nmap is knocking on every door. It takes a few seconds, maybe a minute. Don't touch anything. Let it work. And there it is. Nmap just gave you a list. Look at it. You'll see a column of numbers. Each one followed by the word open or closed. The open ones are what matter. You'll probably see port 135, port 139, and the important one, port 445, all open. Right now you know the doors are open, but you don't know what's behind them yet. A basic scan only shows you the doors, not what's inside. So, let's go deeper. This is where you learn your first flag. A flag is just an option you add to a command. It changes what the tool does. >> [music] >> You add a flag by typing a space, then a dash, then a letter. Type this, nmap space {dash} capital S capital V space your IP. That {dash} capital S capital V means version detection. [music] Now, Nmap doesn't just tell you a door is open. It tells you exactly what service is running behind it and which version of that service. Press enter. Wait again. [music] This one takes a little longer. When it comes back, look at port 445 next to it. We'll now see a service name, something about Microsoft and Windows. Nmap is telling you this is a Windows machine and port 445 is running something called SMB, server message block. It's the service Windows uses to share files. This is the moment that matters. Write down what you see, [music] the operating system, Windows, the open port, 445, the service, SMB, because here's the secret at the center of all hacking. Those details are your lead, a specific service on a specific system. Old software has known weaknesses and when you know exactly what's running, you can go find exactly how to break it. Let's do one more scan, the smartest one. {dash} capital S capital C runs Nmap's built-in scripts. These are little automated checks that look for common problems. Sometimes, this single command finds the weakness for you automatically. Press enter, let it run. Stop and realize what you just did. You scanned a real machine. You found its open ports. You identified the operating system and you fingerprinted the exact service running on the target. That is professional reconnaissance. That's the first thing I do on every real engagement I get paid for. And you just did it on your first date. Quick question before we break in. Drop a comment with how many open ports your scan found. I want to see that you're actually following along, not just watching. Type your number, then keep going. Now you have your lead, Windows port 445 SMB. In the next phase, we turn that lead into a way in. This is where you find the weakness. Let's go. Look, if this video makes you actually want to learn hacking, not just watch it. I built a place for that. Welcome to the Hacker Academy. Here's some of the things you get instant access to. The OSINT Field Manual. Learn how to find anyone online from a single photo, username, or email. A full course on hacking websites and Wi-Fi hacking. Learn how to build your own AI hacking agent that runs on your computer 24/7. The full beginner to pro hacking guide. And the pro hacking cheat sheets I personally use every single day. For 9 bucks a month, you get lifetime access locked at that price point. You can check it out via the link in the description. Phase three. Now we find the weakness. Here is the single most valuable skill in all of hacking, and almost nobody teaches it to beginners directly. So listen closely. Hacking is not about inventing attacks from scratch. It's about finding weaknesses that already exist in software that's out of date, and then using attacks that already exist, that other people have already built. Read that again in your head. You are not inventing anything. You are finding a known weakness and applying a known solution. That's the job. That realization alone puts you ahead of 90% of beginners who think they need to be a genius coder. You [music] don't. You need to know how to research. So let's research. You have your lead from the scan. Windows, [music] port 445, the SMB service. Here's the process. You take that information and you go looking for known weaknesses in it. The simplest version, you literally search the internet. You'd search the service, the system, and the word vulnerability or exploit. But there's a faster way built right into your attacker machine. A tool called searchsploit. Searchsploit is a giant offline database of known working exploits, tens of thousands of them. Pre-built attacks for known weaknesses. It's already on your attack box. In your terminal, type searchsploit, then a space, then SMB Windows. Now simply press the enter key on your keyboard to continue. Look at what comes back. A list of known attacks against Windows SMB. These are real exploits. Each one targets a specific weakness. You're reading a menu of ways into Windows machines. Now, for our specific target, [music] there's one weakness that matters, and it has a name you need to know. It's officially called MS17-010, but the world knows it by another name. The infamous name you need to know is EternalBlue. Let me tell you what you're looking at because this is not just any vulnerability. EternalBlue was developed in secret by the National Security Agency, the NSA, as a cyber weapon. It was stolen, leaked to the public, and then used to launch the largest ransomware attack in history. It shut down hospitals, banks, [music] shipping companies across 150 countries in a single weekend. And that exact weakness is sitting on the machine in front of you right now, waiting for you to use it. That's why I picked this machine for your first hack. You're not breaking into some toy. You're about to run one of the most infamous exploits in the history of computing on your first day. Let me break that down so you're not just copying. -p 445 tells Nmap only look at port 445. --script tells Nmap to run one specific check, and smb-vuln-ms17-010 is [music] the name of the check for EternalBlue. Now, press enter again and wait for the results to appear. And there's your answer. Look for one word in the output, vulnerable. If you see it, the machine is wide open to EternalBlue. You've confirmed your way in. Stop and appreciate this for a second. You scanned the target. You identified what it was [music] running. You researched a known weakness, and you confirmed that weakness exists. That is the complete vulnerability research process, the same process a professional follows on a real engagement. You just did it. Now comes the part you've been waiting for since you clicked this video. We take this weakness, and we use it to break in. Phase four, exploitation. Let's get inside. We're going to use the most famous hacking tool in the world. It's called Metasploit. Think of it as a massive toolbox of ready-made exploits, thousands of them, pre-built. All you do is pick the right one, point it at your target, and fire. It's already installed on your attack box. Let's open it. In your terminal, type this one word, msfconsole. Now, wait. The first time it opens, it takes a moment. You'll see some artwork appear, maybe a logo made of text. That's normal. That's Metasploit starting up. When it's ready, your prompt changes. Instead of the normal terminal line, you'll now see something that starts with msf and then a number. [music] That's how you know you're inside Metasploit now. You're in a different environment, a command center. First, [music] we find our exploit. In that msf prompt, type search space eternalblue. Press enter. Metasploit searches its database and shows you a list of modules related to eternalblue. Look at the list. You'll see entries with numbers next to them, 0, [music] 1, 2, and so on. We want the main exploit. It's the one with ms17-010 in the name and the word eternalblue. Here's the easy way to select it. Each item has a number on the left. Find the one that says exploit and has eternalblue and ms17_010 in the path. Note its number. Usually, it's 0. To select it, type use space and that number. So, if it's 0, you type use space 0, press enter. Watch your prompt again. It just changed. It now shows the name of the exploit in red. That's Metasploit telling you this exploit is now loaded and ready. You've picked your weapon. Now, we have to tell it two things, what to attack and where to send the results. First, what to attack, the target. In [music] Metasploit, the target is called RHOSTS, remote host, the machine you're attacking remotely. [music] Type set space r h o s t s space, and then your target's IP address, the one from the top of your screen. Second, where to send the results. When you break into the target, it It to call back to you, to your attacker machine. That callback address is called L-host, local host, it's you. Now, this is the one spot beginners get stuck. So, pay attention. You need your attack boxes own IP address, not the targets, yours. [music] On the attack box, your IP is usually shown somewhere on screen already. Often labeled as your VPN or tun0 address. If you can see it, use it. If you're not sure, there's a simple way. Open a second terminal and [music] type IP space A, press enter. Look for the address under something called tun0. That's your attacker IP. Once you have it, [music] back in Metasploit, type set space Lhost space and your attack box IP, press enter. Now, Metasploit knows both things, what to attack and where to send the shell when it gets in. Before we fire, let's do what professionals do. We confirm. Type check, press enter. Metasploit reaches out to the target, tests it and tells you. If you see the words, the target is vulnerable, you're about to succeed. That's the green light. Now, the moment. Type one word, exploit. Press enter. Watch the screen. You'll see lines start to appear. Metasploit is sending the attack. You'll see it sending the exploit, making the connection, and then, the line you're waiting for. >> [music] >> Meterpreter session one opened. Stop. Read that line. Meterpreter session open. That means you are in. You just broke into a Windows machine. The attack worked. You are now inside the target. If you see that line, take a breath because you just did the thing. The thing you clicked this video to learn. You hacked a computer. Now, quick reassurance because beginners panic here. After [music] it breaks in, your prompt changes again. It now says meterpreter with an arrow. That is not an error. That is the most beautiful word in hacking. It means you have a live connection into the machine you just compromised. You're not looking at your computer anymore. You're commanding theirs. If the exploit didn't work the first time, don't panic. It happens. Just type exploit and run it again. Sometimes Eternal Blue needs a second attempt. Run it twice. It almost always lands. So, take stock of what just happened. You opened Metasploit. You loaded the NSA's leaked exploit. You set your [music] target. You confirmed it was vulnerable, and you fired. And it worked. You have a live shell inside a Windows machine. That's not a simulation of hacking. That is [music] hacking, the real thing, and you're inside. Now, let's find out exactly how much power you have. Because what you're about to see surprises every beginner. Phase four continues. What to do once you're in. You're inside, but right now you have what's called a basic shell, a plain command line on the target. It works, but it's limited, and it can be unstable. It can drop on you. So, the first thing a professional does is upgrade to something better, a meterpreter shell. Meterpreter is a far more powerful way to control the machine. More commands, more stability, more control. So, let's upgrade. First, we set this shell aside without closing it. In your terminal, press control and Z at the same time. It'll ask if you want to background the session. >> [music] >> Type Y and press enter. That just parked your shell safely in the background. It's still alive. You just stepped away from it for a second. Now, we use a built-in Metasploit tool that upgrades a basic shell into a meterpreter shell. Type [music] search space shell {underscore} to {underscore} meterpreter and press enter. You'll see a module appear. Its path is post {slash} multi {slash} manage {slash} shell {underscore} to {underscore} meterpreter. Select [music] it, type use space, and the number next to it, usually zero, and press enter. Now, this tool needs to know which shell to upgrade, the one you just parked. Type set space session space one, and press enter. That points it at your backgrounded shell, session one. Now, type run and press enter. Metasploit takes your basic shell and upgrades it. In a few seconds, you'll see a new meterpreter session open. You just leveled up your access. >> [music] >> To jump into it, type sessions. Then, look at the list, find the one that says meterpreter, note its number, then type session space and that number. Press enter. Now the question every hacker asks, who am I? Type getuid and press enter. [music] Look at what it says, NT Authority backslash system. Stop. System is the single highest level of power on a Windows machine, higher than the administrator, higher than the owner. System means total control, every file, every password, every account, all of it, yours. Here's why that's remarkable. On most hacks, you break in as some weak limited user, and then you have to grind through a whole phase called privilege escalation, climbing your way up to the top. EternalBlue is so powerful it put you near the very top immediately. But here's a subtle thing the pros know. Being system is not the same as your process being stable as system. To lock in rock solid control, we migrate into a process that's already running as system. Type PS and press enter. This lists every running process on the machine. Look down the list, find one running as NT Authority system. A common reliable one is a process that handles Windows internals. Note the process ID, >> [music] >> then type migrate space and that process ID. Press enter. Metasploit moves your session into that stable process. Now your foothold is solid, it won't drop on you. This is exactly the move a real operator makes. Now let's collect the proof. The room wants you to find flags, hidden pieces of text that prove you had access. They're scattered in specific locations, the system root, a user's folder, the administrator's files. The fastest professional way to find them, drop into a shell on the target. Type shell and press enter. You're now in a Windows command line on their machine. Then you search the entire drive for anything named [music] flag. The flags are sitting in those key locations. As you find each one, you copy the text inside. >> [music] >> Then back on the Blue Room page in your browser, you paste each flag into its answer box and submit. And when that final answer turns green, that's it. [music] The room is solved, officially. You scanned the target, found its weakness, exploited it, upgraded your access, >> [music] >> migrated to a stable system process, and you proved your control. You completed a full, real-world attack chain. Take a real moment with that, because most people who say they want to learn hacking never get this far. They watch, they plan, they tell themselves someday. You didn't plan. You did it today. But owning the machine is only four of the five phases. There's one more, and in the real world, it's the phase that actually pays your salary. Let me show you the part that turns this from a hobby into a career. Phase five, reporting. And I know what you're thinking. Writing a report sounds like the most boring part of hacking. So let me change your mind in about 60 seconds. Here's the truth nobody tells beginners. The hacking you just did, the scanning, the exploiting, the breaking in, that's not what companies pay you for. They pay you for the report. Think about it. A company hires an ethical hacker, a penetration tester, to break into their systems on purpose. Why? Because they want to know where the holes are before a real criminal finds them. The break-in proves the hole exists, but the report is what let them fix it. The report is the product. It's literally the thing you deliver. It's the thing they're paying for. A hacker who can break in but can't write it up doesn't get hired twice. A hacker who can break in and explain it clearly names their price.
Keep this transcript
Save it to LunaNotes and it becomes a real note in your library — editable, searchable, and ready to turn into flashcards or a diagram. Free to start.
Save to LunaNotesOr download subtitles for another video.
These subtitles were extracted using the Free YouTube Subtitle Downloader by LunaNotes.
Related videos
Download Cyber Security Full Course Subtitles (11-Hour Edureka Training for Beginners)
Enhance your learning experience by downloading subtitles for this comprehensive 11-hour Cyber Security Full Course by Edureka. Perfect for beginners, these captions allow you to follow complex training topics, improve comprehension, and easily reference key security concepts offline.
Download Subtitles for Harvard CS50 2026 Computer Science Course
Enhance your learning experience with downloadable subtitles for the Harvard CS50 2026 full computer science course. Easily follow along with lectures, improve comprehension, and access the content offline anytime. Perfect for students and enthusiasts aiming to master computer science concepts.
Download Subtitles for How to Setup an SSH Server on Windows
Easily follow along with our step-by-step guide by downloading accurate subtitles for the 'How to Setup an SSH Server on Windows' video. Enhance your learning experience, understand every detail clearly, and access the content anytime.
Download Subtitles for XLMRat Lab - Cyberdefenders Video
Enhance your understanding of cybersecurity with downloadable subtitles for the XLMRat Lab - Cyberdefenders video. Access accurate captions to follow complex concepts easily and improve learning efficiency.
Download Subtitles for 'How Transistors Run Code' Video
Enhance your understanding of computing with downloadable subtitles for the "How Transistors Run Code" video. Access clear, accurate captions to follow along easily and reinforce your learning experience.
Most viewed
Untertitel für 'Nicos Weg' Deutsch lernen A1 Film herunterladen
Laden Sie die Untertitel für den gesamten Film 'Nicos Weg' herunter, um Ihr Deutschlernen auf A1 Niveau zu unterstützen. Untertitel helfen Ihnen, Wortschatz und Aussprache besser zu verstehen und verbessern das Hörverständnis effektiv.
ดาวน์โหลดซับไตเติ้ล DMD LAND 3 The Final Land Day 1
ดาวน์โหลดซับไตเติ้ลสำหรับวิดีโอ DMD LAND 3 The Final Land Day 1 เพื่อช่วยให้เข้าใจเนื้อหาได้ง่ายขึ้น และเพิ่มความสะดวกในการติดตามทุกช่วงเวลา เหมาะสำหรับผู้ชมที่ต้องการความชัดเจนและเข้าถึงข้อมูลอย่างครบถ้วน
Subtítulos para TIPOS DE APEGO | 6 DE COPAS Episodio 56
Descarga los subtítulos para el episodio 56 de la tercera temporada de 6 DE COPAS, centrado en los tipos de apego. Mejora tu comprensión y disfruta del contenido en detalle con nuestros subtítulos precisos y accesibles.
Descarga Subtítulos para NARCISISMO | 6 DE COPAS - Episodio 63
Accede fácilmente a los subtítulos del episodio 63 de '6 DE COPAS', centrado en el narcisismo. Descargar estos subtítulos te ayudará a entender mejor el contenido y mejorar la experiencia de visualización.
Download Subtitles for Inside Out 2 Extended Preview 2024
Get accurate and easy-to-follow subtitles for the Inside Out 2 extended preview (2024) featured on Fandango at Home. Enhance your viewing experience and ensure you catch every detail of this exciting preview with our downloadable captions.
Found this transcript useful?
Take it with you. One click puts it in your own LunaNotes library.
Save to LunaNotes