10 open source tools that feel illegal...

Fireship · Beginner ·🔐 Cybersecurity ·5mo ago

Key Takeaways

The video demonstrates the use of 10 free and open-source tools on Kali Linux for ethical hacking and penetration testing, including Wireshark, Metas-ploit, Air Crack, and Hashcat.

Full Transcript

There are three types of computer people in this world. Users, programmers, and hackers. The user just wants boring software to make boring spreadsheets to get boring stuff done at work. But in their naivity, users often get penetrated by hackers with high levels of RZ who employ social engineering to steal personal data, intimate photos, and crypto wallets. But then you've got programmers. They're the unsung heroes who make all the software in the world work. But they too get penetrated by hackers. If a programmer leaves the back door open to their mainframe, it could lead to catastrophic consequences that cost them, their job, and their employer billions of dollars. The lesson to be learned here is that you want to be the one doing the penetrating, not some stranger in a foreign country who doesn't even care about your feelings. In today's video, you'll learn the fundamentals of ethical hacking and penesting by looking at 10 free and open- source tools that you can use right now. All of which are available by default on Kali Linux, a DRO optimized for ethical hacking. By the end of this video, you'll be a legit wannabe hacker who can take down entire nations. But if you like to do bad things, you need to turn this video off right now. The tools in this video, if used non-consensually, it could break many international laws that land you in prison. So never do penetration testing on a website or network without permission. But now that all the bad guys have clicked off this video, let's learn how to use some of the most powerful and dangerous hacking tools. To follow along, I would highly recommend installing Kali Linux. And the desktop version is awesome. Although Microsofties can install it via WSL or if you don't want to use Cali, you can just install each one of these hacking tools individually. But the best way to get started is to spin up your own virtual private server on Hostinger, the sponsor of today's video. Their platform gives you the power and flexibility to run anything you want without locking you into a complicated and expensive cloud platform. You can run a basic Linux server like Arch with powerful hardware like NVMe SSD storage and AMD epic chips. You can easily manage containers with a dockervp and their free docker manager or self-host entire backends like superbase with a single click and zero config nightmares. But today I'm using hostinger to run kali linux. And after launching the VPS with just a few clicks, I can SSH into it with my password. And now our hacking journey begins. The first tool you need to know about is end mapap. It's like the peeping tom in your neighborhood who looks through all the windows in your house without actually breaking in. On a network like the one you're connected to right now to watch this video, there's likely multiple hosts connected to it like your computer, your PlayStation, and your smart lock. And the purpose of NAPAP is to map out a network. It does this by sending packets over an IP range. It then analyzes their responses to figure out which ports are open, which operating systems they use to help you find back doors to exploit. Like if grandpa misconfigured something on his network, you can hack his printer to send him a message. To use it, simply use the end mapap command followed by an IP address you have access to, like your local network or even a URL that you have permission to penetrate. If we do that on a website, you'll notice we get the IP address back. And it found that ports 80 and 443 were open. That's pretty cool. But we can also do a more aggressive scan with the A option. This will not only scan the network, but also try to detect the operating systems, and we'll use something called tracer route to track the path of the packets across the entire network, which can help detect misconfigurations that we can exploit. If you're interested in packets though, another tool you'll need to know about is Wireshark. It's like that guy at a party who tries to eavesdrop on every conversation. It allows you to inspect what's happening on the network at a microscopic level. You'll want to use the guey on this one because it collects tons of data from hundreds of different protocols which are all captured in real time and can be analyzed offline. For example, if you record the traffic on your network right now and notice all this weird traffic going to an IP address in North Korea, you can inspect the actual payload and might find out that they have access to those photos that were intended for only you and your future ex-wife to see. And now you might be radicalized and ready to fight back. Metas-ploit is perhaps the most powerful hacking framework out there. It's like a Swiss Army knife with an AK-47 attached to it that allows even the most unskilled script kitty to launch an attack. For example, we might be able to gain access to a Windows machine with a reverse shell. Thanks to the Eternal Blue vulnerability, open up the Metas-ploit console and search for Eternal Blue. That should bring up a list of potential Windows targets. We know that Grandpa is still on Windows 7. So, let's go ahead and use that exploit. From there, we can set a payload to use a reverse shell and configure the local host to our own IP address. And then finally, run the exploit command. Congratulations, you just made a successful penetration. You can now access all the files on this computer, change the desktop background, and install even more malware. But Metas-ploit is almost too powerful, and if you use it, you'll miss out on a lot of cyber security learning opportunities. The next tool you need to know about is Air Crack. Like the name implies, it's for hacking those magical invisible packets floating around in the air called Wi-Fi. When you're at Starbucks enjoying a soy latte coding a NodeJS app, there could be a guy behind the dumpster using air crack who just ran the Airmon command, but followed by air dump to find your network as the perfect target. He then proceeded to run air crack to crack the Wi-Fi protected access key and can now pull all the packets out of thin air floating on this network. If you're connected to a regular unencrypted HTTP website, your sensitive data could be intercepted. That's why you always want to make sure to use HTTPS when submitting forms with personal data because even if a hacker intercepts those packets, they'll be encrypted. Luckily though, the cops just arrested this guy because using air crack on a network without permission is highly illegal. But now it's time to talk about passwords. normies who watch Hollywood movies think that hackers get access to the mainframe by running some program that cracks their password. >> I could launch a cyber nuke, but [music] it'll completely fry your system. >> And believe it or not, Hollywood movies about hacking are 100% accurate. Kali Linux has multiple password cracking tools like John the Ripper and Hydra. But the easiest tool to learn in my opinion is Hashcat. First though, it's crucial to understand that nobody in their right mind stores a plain text password in a database. Instead, passwords get hashed with a one-way algorithm like Shaw or BCrypt to then salt them with another random string to make them even more difficult to crack. Now, even if somebody steals the database, it's still almost impossible to reverse engineer the hash back to the original password. The key word here, though, is almost. Let's imagine I found this hash for the president's login credentials to access the nuclear Armageddon launch button website. Hashcat allows us to run a variety of different strategies to figure out the original text value of this hash. like we could try to brute force every possible string combination. But a more common technique is to use a file like rocku.txt which contains over 14 million common passwords. Once we have that, we can then use hashcat and specify a hashing algorithm which in this example is MD5 because it can be cracked in just a few seconds. But in real life with a hashing algorithm like brypt, it might take multiple days to go through the rocky file. In any case, it looks like President Kamacho used a weak password and forgot to enable 2FA, which means it's finally time to kick off Armageddon. But you might be wondering how I even found this top secret website. The skipfish is a tool for finding vulnerabilities on websites. It will recursively crawl an entire website and in the process scan for vulnerabilities like cross-sight scripting, SQL injection, and other web application screw-ups. It provides this nice HTML report. And what's awesome about it is that if you've already hacked a username and password, you can provide those credentials to also crawl the deep web beyond what's available to the public. Then when you find vulnerabilities, you can use tools like Cross-Side Scriptor to install Worms, just like my hero Sammy did to MySpace back in 2005. Now, in order to be a successful cyber criminal, you need to think like law enforcement and use their tools like Foremost, a forensic data recovery tool built on a process called file carving. Imagine you got access to a hard drive in Area 51 somehow, but all the data is gone. Well, if they did a quick format and didn't overwrite the data, it can likely be recovered with foremost. It doesn't even need a file system and will scan the entire disc image bite by bite looking for unique patterns like the bites at the beginning of a header to identify a JPEG. When it finds the corresponding footer, it can then reconstruct an image that you were never supposed to see. And that's why when you end up with two shots to the back of the head, it'll be ruled a suicide. At this point, we know how to map networks, websites, and hard drives. But the golden goose for any hacker is a database which can be sold for Monero on the dark web. The SQL map allows you to scan a website or server to find all the databases and map out their schemas with all the tables and columns. Once you have that information, you can start launching SQL injection attacks where you submit forms with raw SQL statements in them to try to trick their server into running that code. Or better yet, print that code out and paste it on the front of your car and blow through a bunch of speed cameras. But a more common attack nowadays is denial of service. You probably know how to ping a website in Linux, but in Kali Linux, you can use hping 3 along with the flood option to send packets as fast as possible to an IP address without waiting for replies. This can flood a server with traffic and grind it to a halt or cost the developer millions of dollars if they host on a serverless platform. When used on one machine, it's just a basic DOSs attack, but if you distribute it across a botnet of all the machines that you've hacked already, it then becomes a DDoS attack. Yet another great way to embark on a magical journey to prison. But the sad reality of hacking is that most people are victimized by those they trust. Like I trusted Prince Hyman Cholo to transfer my inheritance after I gave him my checking account password, but he took all my money and went to a fish concert. The social engineering toolkit in Kali Linux allows you to create your own sophisticated fishing attacks using a variety of attack vectors like email, QR codes, SMS text messages, Arduino IoT devices, and of course websites. In fact, the tool can even clone a website, which you can then host on your server, and when someone finds it and enters their email and password, it goes directly to you instead of PayPal. But that entire attack was accomplished without writing any JavaScript code. And with that, we've looked at 10 dangerously powerful tools for hackers in Kali Linux. But we've barely scratched the surface. And you'll also want to learn about John the Ripper, Nikto, Burpuite, just to name a few. Actually, you know what? Forget I ever said anything. Nobody should know about any of these tools. So, go ahead and look into this device real quick. I am just a figment of your imagination. >> All right, guys. You just watched a tutorial about Enterprise Oracle forms with Microsoft Silver Light, but make sure to smash that like button and subscribe for more benign and totally not illegal programming content. Huge thanks to Hostinger for sponsoring and make sure to check out their platform to get the best deal on your own virtual private server in the industry. Thanks for watching and I will see you in the next

Original Description

Get up to 67% off Kali Linux VPS hosting with Hostinger’s one-click template. Use code FIRESHIP for an extra discount - https://hostinger.com/fireship Let's learn the fundamentals of penetration testing and ethical hacking tools by running 10 free and open source tools on Kali Linux. If some of these tools feel illegal, that's because they could be if used without consent. Never use these tools on a website or network without permission. #coding #programming #hacking #ethicalhacking 🔗 Resources - https://www.kali.org/tools/ 🔥 Brain food for developers - https://fireship.dev 🎨 My Editor Settings - Atom One Dark - vscode-icons - Fira Code Font 🔖 Topics Covered - Ethical hacking - Penetration Testing - Kali Linux - NMAP - Wireshark - Metasploit - Aircrack-ng - HashCat - Skip Fish - SQL Map - hPing3 - Social Engineering Toolkit
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from Fireship · Fireship · 0 of 60

← Previous Next →
1 Angular 4 Development and Production Environments with Firebase
Angular 4 Development and Production Environments with Firebase
Fireship
2 OAuth with Angular and Firebase Tutorial
OAuth with Angular and Firebase Tutorial
Fireship
3 Anonymous Authentication with Angular and Firebase - Lazy Registration
Anonymous Authentication with Angular and Firebase - Lazy Registration
Fireship
4 Angular Router Guards for Firebase Users
Angular Router Guards for Firebase Users
Fireship
5 Angular Firebase CRUD App with NoSQL Database Tutorial
Angular Firebase CRUD App with NoSQL Database Tutorial
Fireship
6 Upload Files from Angular to Firebase Storage
Upload Files from Angular to Firebase Storage
Fireship
7 How to Deploy an Angular App to Firebase Hosting
How to Deploy an Angular App to Firebase Hosting
Fireship
8 Sharing Data between Components in Angular
Sharing Data between Components in Angular
Fireship
9 Loading Spinners for Asynchronous Firebase Data
Loading Spinners for Asynchronous Firebase Data
Fireship
10 Angular 4 Transactional Email with Google Firebase Cloud Functions
Angular 4 Transactional Email with Google Firebase Cloud Functions
Fireship
11 Firebase Database Rules Tutorial
Firebase Database Rules Tutorial
Fireship
12 Autocomplete Search with Angular4 and Firebase
Autocomplete Search with Angular4 and Firebase
Fireship
13 Reddit Inspired Upvoting System with Angular and Firebase NoSQL
Reddit Inspired Upvoting System with Angular and Firebase NoSQL
Fireship
14 Angular Drag-and-Drop File Uploads to Firebase Storage
Angular Drag-and-Drop File Uploads to Firebase Storage
Fireship
15 Text Translation with Firebase Cloud Functions onWrite and Angular 4
Text Translation with Firebase Cloud Functions onWrite and Angular 4
Fireship
16 Custom Usernames with Firebase Authentication
Custom Usernames with Firebase Authentication
Fireship
17 Twitter-Inspired Follow Unfollow Feature with Firebase and Angular 4
Twitter-Inspired Follow Unfollow Feature with Firebase and Angular 4
Fireship
18 Simple Pagination with Firebase and Angular 4
Simple Pagination with Firebase and Angular 4
Fireship
19 How to Connect Firebase Users to their Data - 3 Methods
How to Connect Firebase Users to their Data - 3 Methods
Fireship
20 Add Toast Message Notifications to your Angular App
Add Toast Message Notifications to your Angular App
Fireship
21 Facebook-Inspired Reactions System with Angular and Firebase
Facebook-Inspired Reactions System with Angular and Firebase
Fireship
22 Learn NgModule in Angular with Examples
Learn NgModule in Angular with Examples
Fireship
23 Lazy Loading Components in Angular 4
Lazy Loading Components in Angular 4
Fireship
24 Stripe Checkout Payments with Angular and Firebase - Part 1
Stripe Checkout Payments with Angular and Firebase - Part 1
Fireship
25 Process Stripe Payments with Firebase Cloud Functions - Part 2
Process Stripe Payments with Firebase Cloud Functions - Part 2
Fireship
26 Selling Digital Content in Angular with Stripe Payments - Part 3
Selling Digital Content in Angular with Stripe Payments - Part 3
Fireship
27 Angular 4 Full Text Search with Algolia - Part 1
Angular 4 Full Text Search with Algolia - Part 1
Fireship
28 Algolia with Firebase Cloud Functions - Part 2
Algolia with Firebase Cloud Functions - Part 2
Fireship
29 Firebase Phone Authentication in Angular 4
Firebase Phone Authentication in Angular 4
Fireship
30 Top 7 RxJS Concepts for Angular Developers
Top 7 RxJS Concepts for Angular Developers
Fireship
31 Learn Angular Animations with 5 Examples
Learn Angular Animations with 5 Examples
Fireship
32 Advanced Firebase Data Filtering (Multi-Property)
Advanced Firebase Data Filtering (Multi-Property)
Fireship
33 Realtime Maps with Mapbox + Firebase + Angular
Realtime Maps with Mapbox + Firebase + Angular
Fireship
34 Angular Reactive Forms with Firebase Database Backend
Angular Reactive Forms with Firebase Database Backend
Fireship
35 Send Push Notifications in Angular with Firebase Cloud Messaging
Send Push Notifications in Angular with Firebase Cloud Messaging
Fireship
36 Top 7 Ways to Debug Angular 4 Apps
Top 7 Ways to Debug Angular 4 Apps
Fireship
37 Infinite Scroll with Angular and Firebase
Infinite Scroll with Angular and Firebase
Fireship
38 Use TypeScript with Firebase Cloud Functions
Use TypeScript with Firebase Cloud Functions
Fireship
39 Realtime Graphs and Charts with Plotly and Firebase
Realtime Graphs and Charts with Plotly and Firebase
Fireship
40 Role-Based User Permissions in Firebase
Role-Based User Permissions in Firebase
Fireship
41 User Presence System in Realtime - Online, Offline, Away
User Presence System in Realtime - Online, Offline, Away
Fireship
42 Location-based Queries with GeoFire and Angular Google Maps
Location-based Queries with GeoFire and Angular Google Maps
Fireship
43 Angular ngrx Redux Quick Start Tutorial
Angular ngrx Redux Quick Start Tutorial
Fireship
44 Angular Ngrx Effects with Firebase Database
Angular Ngrx Effects with Firebase Database
Fireship
45 Progressive Web Apps with Angular
Progressive Web Apps with Angular
Fireship
46 Angular Ngrx with Firebase Google OAuth User Authentication
Angular Ngrx with Firebase Google OAuth User Authentication
Fireship
47 RxJS Quick Start with Practical Examples
RxJS Quick Start with Practical Examples
Fireship
48 Send SMS Text Messages with Twilio and Firebase
Send SMS Text Messages with Twilio and Firebase
Fireship
49 Firebase Database Performance Profiling
Firebase Database Performance Profiling
Fireship
50 Native Desktop Apps with Angular and Electron
Native Desktop Apps with Angular and Electron
Fireship
51 Subscription Payments with Stripe, Angular, and Firebase
Subscription Payments with Stripe, Angular, and Firebase
Fireship
52 Firestore with AngularFire5 Quick Start Tutorial
Firestore with AngularFire5 Quick Start Tutorial
Fireship
53 Angular HTTP Client Quick Start Tutorial
Angular HTTP Client Quick Start Tutorial
Fireship
54 Google Sign-In with Firestore Custom User Data
Google Sign-In with Firestore Custom User Data
Fireship
55 Star Review System from Scratch with Firestore + Angular
Star Review System from Scratch with Firestore + Angular
Fireship
56 Angular Chatbot with Dialogflow (API.ai)
Angular Chatbot with Dialogflow (API.ai)
Fireship
57 Learn @ngrx/entity and Feature Modules
Learn @ngrx/entity and Feature Modules
Fireship
58 Infinite Scroll Pagination with Firestore
Infinite Scroll Pagination with Firestore
Fireship
59 Faster Firestore via Data Aggregation
Faster Firestore via Data Aggregation
Fireship
60 Contentful - CMS for Angular Progressive Web Apps
Contentful - CMS for Angular Progressive Web Apps
Fireship

This video teaches the fundamentals of penetration testing and ethical hacking using 10 free and open-source tools on Kali Linux. It covers various topics, including network mapping, password cracking, and vulnerability scanning. By watching this video, viewers can learn how to use these tools to conduct penetration testing and improve their cybersecurity skills.

Key Takeaways
  1. Install Kali Linux using the desktop version or WSL
  2. Use End mapap to map networks
  3. Use Wireshark to capture and analyze network traffic
  4. Use Traceroute to detect misconfigurations
  5. Exploit Eternal Blue vulnerability with Metas-ploit
  6. Crack Wi-Fi protected access key with Air Crack
  7. Use Hashcat to crack passwords
  8. Use BCrypt with salting to secure passwords
  9. Use Skipfish to find vulnerabilities on websites
  10. Use Foremost for forensic data recovery
💡 The video highlights the importance of cybersecurity and the need for individuals to be aware of the various tools and techniques used by hackers. It also emphasizes the importance of using these tools for ethical purposes, such as penetration testing and vulnerability scanning.

Related Reads

📰
CVE-2026-6875: ServiceNow AI Platform Sandbox Escape Under Active Exploitation
Actively exploited CVE-2026-6875 allows threat actors to escape ServiceNow AI Platform sandbox with CVSS 9.5 severity
Dev.to · Etairos.ai
📰
Securing SaaS Signup Forms: Stop Bot Attacks With CAPTCHA
Learn how to secure SaaS signup forms from bot attacks using CAPTCHA and prevent infrastructure exploitation
Dev.to · Silverwing
📰
How to Configure a WinCollect Agent on a Windows Client for IBM QRadar
Configure a WinCollect agent on a Windows client to integrate with IBM QRadar and enhance security monitoring
Medium · Cybersecurity
📰
Support Bot — LetsDefend Walkthrought — UnderTheBit #07
Learn to create a secure support bot using AI, understanding the importance of security controls in chatbot development
Medium · Cybersecurity
Up next
Cerebras CISO Naor Penso on AI Security & The CrowdStrike Partnership
Cerebras
Watch →