hobune Channels Contact About Donate

Your Windows 11 Password is NOT safe... #endermanch #windows #microsoft

Back to video page | Download comments jsonl

Comments (archived 2024-12-23 08:31; 31 top, 67 total comments)

@ٴٴٴٴۥۥٴٴ 2024-11-04 14:08:50

Damn, it's crazy that a big company like Microsoft can't use a newer, better hash function

25 likes
@Lofote 2024-11-04 14:54:15 (edited 2024-11-04 14:54:45 )

You are aware that you need local admin access to access that? There is no security in Windows when you are logged in as an admin (the book of Windows NT 3.1 already says this). So where exactly is the security risk now? It's like saying a safe is insecure for a person that already has the key or the code.

79 likes
Replies (18)
@hyperkiko 2024-12-10 20:24:01

​@@Lofotewhile it is saved as a hash, it is an unsalted md4 hash which means you can just run it through a rainbow table (aka a hash database as he calls it) to get the original password

0 likes
@Lofote 2024-12-10 19:56:40

@@mortn_yt and have the same full acces if you login as root. Exactly same thing

0 likes
@Lofote 2024-12-10 19:56:04

@@hyperkiko good point, but to my understanding, this is about the security questions, not getting the original passwordd, which should be saved as a hash only. Or do you mean something else?

0 likes
@Lofote 2024-12-10 19:53:27

@TheRealMangoDev you see, if you leave your safe open, you cant blame the manufacturer when stuff is stolen from it.

0 likes
@Lofote 2024-12-10 17:09:21

@TheRealMangoDev  everything is vulnerable when you login as admin. If someone has root access there is no protection barrier anymote, it is vulnerable to everything

0 likes
@TheRealMangoDev 2024-12-10 17:03:15

And..? Its still vulnerable.

0 likes
@mortn_yt 2024-11-10 06:52:58

Or you can use linux

0 likes
@gmddolbaeb2191 2024-11-05 17:19:40

@@Lofote you can change C:/system32 sethc to cmd.exe

0 likes
@Lofote 2024-11-04 23:47:23 (edited 2024-11-04 23:48:37 )

@@SketchyB_YT How? (Just to clarify: I am talking about a well configured system, with user having no admin rights, a good admin password and BitLocker against offline attacks for example via USB stick (which requires physical access however).

0 likes
@drtibbs693 2024-11-04 20:36:10

@@gmddolbaeb2191 yep! Can even automate it by creating your own WinPE bootable environment with a custom program that runs the cracker. The entire registry is stored as reg.dat so it really is as simple as finding that file.

0 likes
@SketchyB_YT 2024-11-04 19:40:15

No, but he doesn’t have to be a local admin for that to happen. Hackers can do that easily.

0 likes
@Chief-CO 2024-11-04 19:02:35

@Lofote Lookup the Dunning Kruger effect

0 likes
@Lofote 2024-11-04 16:07:27

@@gmddolbaeb2191 Thats why on a secure system BitLocker (or similar) is required, if you also want to block people that have physical access to the machine. If you can hinder people from physically access (or access via IPMI), e.g. servers in a locked down room, you can skip that.

0 likes
@gmddolbaeb2191 2024-11-04 15:56:46

USB from bootable media command prompt

2 likes
@hyperkiko 2024-11-04 15:55:21

​@@Lofote this is if you already have access but want to know the users password, most people use the same password for a lot of services so it would be helpful to know their password so you can try it on other services

3 likes
@SOTP. 2024-11-04 15:54:48

thats not the point, the point is you can get the original password, setting it to something else never gives you the original password. Also you could just boot on a usb drive instead to get the sam file or use the recovery bug if its windows 10 1907 or earlier​@@Lofote

43 likes
@Lofote 2024-11-04 15:51:16

@@guilhermemestre4 Yes, I understand that, but the security flaw is already there then. The thing is (the major rule, how Microsoft security is implemented): if someone or something has admin rights, it can do whatever it want. There is no security anymore then. This is the same on Linux: if you run something as root, you are "inside", there is nothing the operating system will prevent then. :)

7 likes
@guilhermemestre4 2024-11-04 15:29:18

@Lofote in the last enderman video, he explained how to access these reg files. you need a specific account in addition to the administrator one. but some third-party services have these privileges, that's the problem. if I'm not mistaken, he explains this in the previous video

28 likes
@thegrishplays3356 2024-11-05 02:42:45 (edited 2024-11-05 02:45:16 )

When windows is running, only the NT AUTHORITY\SYSTEM internal user has read access to the SAM hive by default. (so the login stuff can read the hash data) Unless someone has offline access to the drive (or the system was tampered with), this is not a serious security risk.

13 likes
Replies (3)
@paulstelian97 2024-11-11 17:23:05

@@txicatedbeast386The problem is you need some bug in Windows (which security updates patch out) or admin access for this.

0 likes
@sendevia 2024-11-07 23:54:47

​@@txicatedbeast386still need admin

0 likes
@txicatedbeast386 2024-11-06 12:15:43

I guess you'll are the ones who don't know the risk getting NT Authority elevated CMD is as easy pancakes.😅

Once you have a CMD with full power, aka NT authority system power, then you can easily get access to these keys (in theory).

1 like
@Fauxed 2024-11-04 14:27:26

I don't know that Google captha use an image of a Gojek driver in other country 😂

23 likes
Replies (4)
@Fauxed 2024-12-15 06:45:30

@@276- 😁

0 likes
@276- 2024-12-15 02:38:37

change the profile picture. NOW!! ⚡️🌩️

0 likes
@Arz-ytx 2024-11-05 11:31:08

wow never thought anyone would see the gojek driver 😂

0 likes
@CEKIKOFGAMERS 2024-11-05 04:44:50

@@Fauxed nah, i though i was mistake when saw the gojek driver

0 likes
@itzgametimevip1111 2024-11-05 01:35:22

I think they are doing this to save your password. I use a txt file to save my reminder batch file data

3 likes
Replies (1)
@MiteBlueRuby 2024-11-07 06:40:26

The way passwords work in recent years is it goes through an irreversible algorithm, then the result is stored. Anytime a password needs to be compared, it gets put through the same algorithm and the result is compared, so only you know your password. The problem is when that algorithm isnt one way, then people can get your original password from the hash.

0 likes
@nishweb 2024-11-04 14:03:38

Yeah it begged the question

4 likes
@Nathanseditzz 2024-11-30 21:41:22

always when i get a virus or some shit i always get redirected to your youtube channel

0 likes
@SYSTEM-Image-WIM 2024-11-25 05:51:42

My latest video makes Windows in the Recycle Bin use UWP normally. I don't know how.

0 likes
@TheYouTubeJosh13 2024-12-04 20:39:51

Big man and that HEY IS GREAT MATE❤❤❤❤❤

0 likes
@gigalar1248 2024-11-05 14:03:17

Hold on, can you make a longer video about this? Or can you at least explain better how you extract the hash from the dword?

0 likes
@dzinymasterpl7363 2024-11-05 13:56:09

Enderman different languages

[EN] Enderman
[PL] Kresostwór
[ES] Criatura
[FR] Créature
[RU] Существо
[TR] Yaratık

1 like
Replies (1)
@artcas2 2024-11-05 15:35:33

it's not true in all languages it's Enderman (becaus it's a minecraft mob)

2 likes
@Zinedine-Rhythm 2024-12-20 22:45:57

What's the website

0 likes
@tuchbootlol 2024-11-08 04:52:05 (edited 2024-11-24 18:31:23 )

Windows "security":

0 likes
Replies (2)
@tuchbootlol 2024-11-24 18:31:42

@@pronounjow Oh my bad lol I fixed it

1 like
@pronounjow 2024-11-23 19:17:05

At least spell "security" correctly...

0 likes
@Nieczytelny_official 2024-11-05 18:43:48

yeah, for me pretty safe
so would many people with laptops say



guys please buy me a thinkpad t480

0 likes
@TechOS. 2024-11-04 13:57:47

Useful

1 like
@opywndow 2024-11-29 10:22:09

who's ashley

0 likes
@userbin9011 2024-11-04 16:56:51

Or is it…?

0 likes
@AadiLMughal 2024-11-06 02:02:24

Brilliant

0 likes
@techgaming-on4wg 2024-11-04 14:37:03

Aleast i use Linux mint, so i am safe?

1 like
Replies (5)
@techgaming-on4wg 2024-11-05 03:42:19

@@256odeon well Linux user is so lows that hacker don't wasted their time for small fish

1 like
@CookieXD1998 2024-11-05 03:32:56 (edited 2024-11-05 03:34:31 )

@@256odeon in Linux mint the passwords are salted. So it's way more different to get them.

1 like
@256odeon 2024-11-05 02:11:21

@@CookieXD1998 so he is safer from a windows exploit in linux? 😂😂

2 likes
@CookieXD1998 2024-11-04 17:21:38 (edited 2024-11-04 17:24:26 )

Obviously not (being completely safe is impossible, you are safer.)

4 likes
@256odeon 2024-11-04 17:06:28

??????? obviously yeah

0 likes
@TheOriginalMacOS 2024-11-04 16:41:21

is it the same in windows 10?

0 likes
Replies (2)
@TheOriginalMacOS 2024-11-04 17:22:27

@@stysan i am disaapoimted in the microsft

0 likes
@stysan 2024-11-04 17:14:35

yes

1 like
@Jacobthe3rd_2 2024-11-04 20:03:16

Therr us a tornado RN in a lot of stated

0 likes
@ThierryKeoni 2024-11-04 13:50:43

First and nice🎉🎉

0 likes
@Daniel70002 2024-11-04 15:02:58

Hello

0 likes
@Lucianoelxdd 2024-11-05 03:27:23

nice now i know that microaodt will know that my favorite move was 1#*! And my frist child was ahsjsk

0 likes
@manan67891 2024-11-04 14:35:18

yeah wth Microsoft

0 likes
@MrAnimGuy 2024-11-04 13:52:58

a

0 likes
@TylerzillaPC 2024-11-04 13:57:26

Ok

1 like
@XIeepy1 2024-11-05 05:26:13

Windows is not safe

0 likes
@noonebullysme867 2024-11-09 21:25:44

bro telled us how to get admin passwords

0 likes
@sionchou5167 2024-11-05 09:52:23

someone password: ==-#djj121*

1 like
@ItzFlowerGMD 2024-11-04 14:09:13

what the fuck microsoft

0 likes