Convert .EXE to IMAGE!

Поділитися
Вставка
  • Опубліковано 13 січ 2025

КОМЕНТАРІ • 978

  • @ebolaman_
    @ebolaman_  Рік тому +1205

    webhook.exe is just a placeholder (so i dont get banned), you can use the methods in this video with a token logger, rat, etc

    • @Amitherabbit
      @Amitherabbit Рік тому +354

      very *Educational Purposes

    • @The_Wafool
      @The_Wafool Рік тому +67

      you do realize computer hacking is very illegal

    • @indio1452
      @indio1452 Рік тому

      have how send the code of the weehook.exe

    • @Andrew90046zero
      @Andrew90046zero Рік тому +1

      ​@@The_Wafool "hacking" is not the same as "stealing people's data and damaging property". So no, hacking is not illegal. What is illegal is using means of hacking to commit actual crimes like stealing, harassing, damaging property, etc. In the same way that teaching people how to pick locks is not illegal either.
      Though, in many situations, people may state that "hacking" IS "stealing data" as an over simplification of the word. This over simplification causes confusion and makes people think that Hacking is (and can only be) the act of breaking security for the purpose of stealing (and other crimes), but you can hack without causing damage to anyone. Hacking is simply the act of bypassing of security measures, or breaking some other system to gain access or priveledges. But if you have been given permission by the right people to have such access or priveledges, then it's not illegal.
      And spreading awareness of computer security flaws, like how @ebolaman_ has done here, helps everyone to know how to protect themselves against these exploits. If this was not shown here, it will still be shown in other places where actual criminals hang out. Showing these security flaws can even lead to an eventual patch of the flaws. So keeping this information secret can be more dangerous to everyone.

    • @InstantNameOfficial
      @InstantNameOfficial Рік тому

      ​@@The_Wafoolno way, its very much legal man what are you talking about?

  • @tenorton
    @tenorton Рік тому +3793

    Educational purposes is pretty much the universal dev excuse now

    • @F1L337
      @F1L337 Рік тому +165

      I guess it is the same for nudity counting as art.

    • @lembarkii8669
      @lembarkii8669 Рік тому

      ​@@F1L337t w i t c h

    • @0xF81
      @0xF81 Рік тому +93

      Not really, he showed us how is it made so now we're aware how to be careful in case of sus file

    • @BabyKnxckz
      @BabyKnxckz Рік тому +14

      it is educational init

    • @reality5783
      @reality5783 Рік тому +25

      I have soo many *educational purpose* ideas!!!🤣🤣

  • @Theooolone
    @Theooolone 10 місяців тому +836

    That right to left override character in the filename was absolutely devious

    • @Yazan_Majdalawi
      @Yazan_Majdalawi 7 місяців тому +9

      But I think the extension in the properties menu would still be the right one

    • @Archimedes.5000
      @Archimedes.5000 7 місяців тому +26

      @@Yazan_Majdalawiit will, but who looks at that
      In fact many scammers will just name it "pic.png.scr" and hope that the victim has the "hide known file extensions" option enabled, because it's still the default on Windows lmao

    • @twー
      @twー 6 місяців тому

      @@Archimedes.5000man.. Windows. I'd be on Linux still if devs supported their stuff on it more

  • @RealThornZ
    @RealThornZ 9 місяців тому +401

    the phrase educational purposes only is the one thing keeping this channel from not being cancalled

    • @MAGNETO-i1i
      @MAGNETO-i1i 8 місяців тому +6

      He hasnt done anything illegal.

    • @ziadidabde3662
      @ziadidabde3662 7 місяців тому

      Y can hide virus by this method ​@@MAGNETO-i1i

    • @farn1991
      @farn1991 7 місяців тому

      It's not like he is going to distribute any zero day exploit through youtube video.

    • @VideosViraisVirais-dc7nx
      @VideosViraisVirais-dc7nx Місяць тому

      ​@@MAGNETO-i1iyeah, nothing legal. It's like watching hentai knowing all characters are over 18

  • @cracktek_industries
    @cracktek_industries Рік тому +798

    The RLO trick is actually something I didn't know even as a CS student, thanks!

    • @catorlife
      @catorlife Рік тому +98

      this is old one, if you do this, even Window Defender can catch this, it automatically consider the file as a trojan even when it's not harmful (test file)

    • @KennyWlr
      @KennyWlr Рік тому +11

      ​@@catorlife can confirm, it's been like this for a while now

    • @Coxick
      @Coxick Рік тому +24

      The name will go back to it's original form once you upload it somewhere, so not useful even if the target has no antivirus

    • @RandomGeometryDashStuff
      @RandomGeometryDashStuff Рік тому +1

      there are file managers that separate extension from rest of name like double commander

    • @miner4236
      @miner4236 Рік тому +13

      Wow even as a CS student ? Xdd

  • @alibrahym
    @alibrahym Рік тому +167

    instructions unclear:
    Im in the prison cell and re-watching this video

  • @GRPYouTube
    @GRPYouTube Рік тому +599

    Bro you literally got the the info i was finding for 2 years

    • @nothink0945
      @nothink0945 Рік тому +23

      I was tryna find this for so long and this was here the whole time????

    • @x4dam
      @x4dam Рік тому +1

      frr

    • @TeeChemist
      @TeeChemist Рік тому +12

      The question is whether windows defender detects it as malicious? Or does it depends upton the the exe that is being executed.

    • @xodzphone
      @xodzphone Рік тому +6

      Shit I was doing 25 years ago

    • @dustindhansen
      @dustindhansen Рік тому +3

      @@xodzphone I was doing it 50 years ago

  • @ontop3543
    @ontop3543 Рік тому +60

    educational purpose only. Enjoy 💀

  • @olafcio
    @olafcio Рік тому +887

    .scr is an shortcut for screensaver executables. It's exactly the same as normal executables, but isn't .exe.
    EDIT: Also, it's better to change the shortcut executable to "cmd.exe /c .\image.png", because when you leave the full path (c:\users\boris\...), it only supports your location of the folder with your username. But still, good video.

    • @pizzazr
      @pizzazr Рік тому +5

      True but you're sending it to someone else anyways

    • @андрей_свиридов
      @андрей_свиридов Рік тому +8

      Wtf .scr is 'script' not 'screenshare'

    • @pizzazr
      @pizzazr Рік тому

      @@андрей_свиридов it's Screensaver

    • @Meletion1
      @Meletion1 Рік тому +108

      @@андрей_свиридовeveryone is wrong it’s screen saver😂

    • @андрей_свиридов
      @андрей_свиридов Рік тому +18

      @@Meletion1 yeah, that too. I have bubbles.scr installed as my Win11 screensaver :)

  • @antxnioo
    @antxnioo 8 місяців тому +36

    bro's channel is surviving with the educational purposes excuse

  • @Uthael_Kileanea
    @Uthael_Kileanea Рік тому +222

    Good video. Knowing how to do dangerous things helps in defending against them. For example, to defend yourself against this, use a custom system icon pack and disable thumbnails. No antivirus needed or keeping your eyes peeled for extensions. Also, your default icons look cooler.

    • @Cryptocurrency69
      @Cryptocurrency69 Рік тому +27

      Could you tell that how do you switch to a custom system pack and disable thumbnails

    • @blvdes
      @blvdes Рік тому +1

      ​@@Cryptocurrency69 ask Google

    • @Uthael_Kileanea
      @Uthael_Kileanea 11 місяців тому

      @@Cryptocurrency69 Both answers depend on your operating system. You'll have to ask mama Google.

    • @supercellex4D
      @supercellex4D 7 місяців тому +6

      Doesn't help if you're a high value target, the real trick is to know Windows screensavers are autoran executables, and to check the file type. Or use Unix because NT has one of the most comprehensive filesystem permission systems ever that doesn't have execute as an attribute.

    • @MightyDantheman
      @MightyDantheman 7 місяців тому +1

      You can also just have file extensions visible by default. But the more steps you take, the safer you'll be. The scary part is that these changes only help you if you know what you're looking for. Imagine the normal user...

  • @serbianspaceforce6873
    @serbianspaceforce6873 7 місяців тому +897

    malware tutorial 😭

    • @Wesd_YT
      @Wesd_YT 7 місяців тому +19

      thatts his whole channel

    • @Wilson-AM
      @Wilson-AM 7 місяців тому +3

      lol

    • @Wesd_YT
      @Wesd_YT 7 місяців тому

      @niikolehmainen Real.

    • @serbianspaceforce6873
      @serbianspaceforce6873 7 місяців тому +3

      @koolehmainen sure but I'm on Linux so idk if it'll work the same

    • @threeMetreJim
      @threeMetreJim 5 місяців тому +1

      It's useful to know how they work. You can learn some interesting code too, help to defend people against malware and learn how to remove the persistent back doors. Just don't get hit by a crypto locker.

  • @MarilynCol7
    @MarilynCol7 Рік тому +17

    Damn its very rare that i find interesting channels ln UA-cam

  • @sanchogodinho
    @sanchogodinho Рік тому +15

    Its just wow 🤯
    So nicely explained straight to the point!

  • @zirtaontop
    @zirtaontop Рік тому +8

    this is very improtant not for scamming but for being aware so its very important also this teaches u that the best antivirus is you

  • @kingnightmarevin
    @kingnightmarevin 11 днів тому +1

    What a hero, protecting video game creepypasta protagonists from demonic hedgehogs

  • @Bin2Hex
    @Bin2Hex Рік тому +89

    RLO is already detected by most AV's
    .scr is also detected by most AV's now and will be stopped by WD smart screen.
    the .lnk method works but will be caught by behavior dynamic analysis which most AV's have.
    double masquerade extensions will also be caught and stopped by smartscreen.

    • @phir9255
      @phir9255 Рік тому +32

      Is Windows Defender included in "most AV's"?

    • @MrGenius2
      @MrGenius2 Рік тому

      ​@@phir9255probably yeah wd is the most annoying av because it just does to much I don't have it because it even blocks my work

    • @whocares4444
      @whocares4444 Рік тому

      @@phir9255windows defender is an AV (anti-virus software) preloaded with the windows OS

    • @miner4236
      @miner4236 Рік тому

      ​@@phir9255likely

    • @Bin2Hex
      @Bin2Hex Рік тому

      @@phir9255 considering windows defender is default installed on all windows operating system, then yes it would be considered part of “Most AV’s”

  • @TSF-nexus2
    @TSF-nexus2 8 місяців тому +4

    mixing this with being able to view other desktops and holy hell you're goated

  • @chillappreciator885
    @chillappreciator885 Рік тому +4

    Slick demonstration man! It was fun to finally know how do they do this

  • @cwypto4488
    @cwypto4488 Рік тому +28

    that's really cool! im not interested in doing this but i like the style of your videos and your explanation. Subbed.

  • @AussieCricketOnTop
    @AussieCricketOnTop Рік тому +15

    Cant wait to use this for educational perpousus only!

  • @ancestrall794
    @ancestrall794 7 місяців тому +2

    First video I see of your channel and you definitely earned a sub. Tbh I don't really see how the "standard users" could not fall for this

  • @btarg1
    @btarg1 Рік тому +22

    You can embed code inside an LNK file, and have the link file run it, so you could also fit an image inside an LNK and do it that way!

  • @firebolt3626
    @firebolt3626 4 місяці тому

    yo man, idk from how many days I've been looking for something like this. thanks a lot for this buddy.

    • @KalkiKrivaDNA
      @KalkiKrivaDNA 4 місяці тому

      So have u been bleto tech virus to Gmail ?

    • @guili-p7m
      @guili-p7m 3 місяці тому

      I'll give a huge reward to anyone who can make it

    • @firebolt3626
      @firebolt3626 3 місяці тому

      @@guili-p7m i was able to do it. so what u gonna give me?

  • @avocadoricardo6957
    @avocadoricardo6957 Рік тому +45

    The amount of people who think that clicking the image sent on discord will execute it is hilarious

    • @pinguluk1
      @pinguluk1 Рік тому +5

      Wasn't there an exploit that basically did that?

    • @freen1364
      @freen1364 Рік тому +2

      They just send the embed from a other device once they click the image it’s all a scam

    • @avocadoricardo6957
      @avocadoricardo6957 Рік тому +11

      @@pinguluk1 no that’s not possible because of how discord works. When you send an image, discord harvests that information and displays the image, more or less like a middleman, in other words it’s literally just an image, you can’t hide executables in it.

    • @aidaonYT
      @aidaonYT Рік тому

      thats why you only look at the embed

    • @Hackedpw
      @Hackedpw Рік тому +1

      @@pinguluk1 yeah there somewhat was. for others in the replies: .WebP (note; webp wasn't the only thing that was exploited nor was it only discord related but its the one with most information.)

  • @BytePix_
    @BytePix_ Рік тому +23

    This is scary simple. I don't know if I am suppose to be scared or surprised.

    • @kamimatsuyama
      @kamimatsuyama Рік тому +5

      you can check the file extension and size when downloading files

    • @AresEverett
      @AresEverett Рік тому +1

      both

    • @BytePix_
      @BytePix_ Рік тому

      Have you watched the entire video? because it can look like a png or whatever file and still run as a cmd. @@kamimatsuyama

    • @Ransomwave2
      @Ransomwave2 Рік тому +8

      the RLO method doesn't work after uploading a file to 99.9% of file hosts online. you shouldn't be scared. if you're skeptical, you can always just right click and check the properties

  • @potthegrunt
    @potthegrunt 5 місяців тому +4

    bro is helping the scammers😭

  • @macpclinux1
    @macpclinux1 9 місяців тому +2

    i admit. i have been pwned by this in the past. it's such a good method

    • @Vapixed
      @Vapixed 27 днів тому

      how did it work

  • @muuqii
    @muuqii Рік тому +28

    appreciate it man
    keep up the good work

  • @makar4ik_cat
    @makar4ik_cat 6 місяців тому +1

    Thanks to you, now malware creators will make the fake pngs

  • @lowHP_
    @lowHP_ Рік тому +4

    what a legendary mic stand

  • @alvinrahmanwafi
    @alvinrahmanwafi Рік тому +1

    My man earned a subscriber

  • @unknown-yo2tx
    @unknown-yo2tx Рік тому +8

    cool old techniques you covered

  • @touyaakira1866
    @touyaakira1866 Рік тому

    I'm like a lot of people here I'm like a lot of people here who are really scared if youtube bans you. Your knowledge is amazingwho are really scared if youtube bans you.

  • @orren6999
    @orren6999 Рік тому +41

    I remember this video

  • @shinydewott
    @shinydewott 7 місяців тому

    Now I am immensely paranoid of all of those background remover and image downloading websites I have visited in the past! Wonderful!

  • @vasilis23456
    @vasilis23456 Рік тому +25

    The fact that Windows lets you use the RLO in filenames and it actually works is crazy. They didn't think at all about how this could be used, or they did but didn't care. There should be some kind of indication of every type of character in a filename, be that a color change on reversed text or whatever.

    • @Lagger625
      @Lagger625 Рік тому +6

      What about Arabs and Asians, millions would be pissed about having to type their filenames in reverse

  • @idk-verynice
    @idk-verynice 28 днів тому

    Bro's channel description is the nerdiest shit ever to save him from getting sued

  • @lamborghinigamer
    @lamborghinigamer Рік тому +25

    Now I'm scared for images. Luckily I'm on linux so no exe's, but still scary to think how easy it is to hide the real file extension

    • @infectieon
      @infectieon Рік тому

      So ANY image on discord could be laced like this??? Wtf how do you even stay safe from this? Idk how to work linux

    • @Phobos001_youtube
      @Phobos001_youtube Рік тому +21

      ​@@infectieonUploaded images with machine code execution will get rejected because they're not REALLY images; The headers and offsets are wildly different and be considered corrupt or invalid. You only need to worry about fake 'images' stored directly on your file system, and make sure not to run them.

    • @dnchplay-archive
      @dnchplay-archive Рік тому +8

      Also the reversed text trick used to spoof the file format works only on explorer and a gew other programs, in the most of apps this trick won't work and the original file format will be shown

    • @CluelessGeek
      @CluelessGeek 10 місяців тому +5

      "linux is free if your time is worthless" proceeds to get hacked by an image

    • @yashi0412
      @yashi0412 10 місяців тому

      ​@@CluelessGeekthis was the cause by my change to dual boot windows/linux to just linux 😅

  • @hoangat7188
    @hoangat7188 11 місяців тому +1

    Keep it up man! That's awesome

  • @catorlife
    @catorlife Рік тому +35

    the RLO trick is not gonna work since even Window Defender can catch this, it automatically consider the file as a trojan even when it's not harmful (test file)

    • @ILoveTinfoilHats
      @ILoveTinfoilHats Рік тому +8

      Yeah this isn't actually a danger to anyone. The only reason windows isn't freaking out about the file is because it was made on his computer. If you were to upload that to the Internet and try running it on another computer it'd get instantly sent to the shadow realm by even the worst of anti viruses

    • @Lar_me
      @Lar_me Рік тому

      @@ILoveTinfoilHats I tried making my own, and Windows Defender successfully stopped it from executing. Maybe the video uploader disabled Defender for the sake of the demonstration?

    • @ILoveTinfoilHats
      @ILoveTinfoilHats Рік тому

      @@Lar_me yes exactly my point, even the crappiest of antivirus programs would catch this low-level bug

  • @RoachJr695
    @RoachJr695 Рік тому +1

    underrated content creator

  • @notarctxc
    @notarctxc 8 місяців тому +7

    One day bro is gonna hack the NASA and say that it was only for educational purpose

  • @BellaTheUnicorn-ko5yt
    @BellaTheUnicorn-ko5yt 3 місяці тому +1

    def gonna use this for educational purposes

  • @arshamshayan
    @arshamshayan Рік тому +4

    thank you for this tutorial ebola man

  • @aigg_
    @aigg_ Рік тому +3

    i'm torn over liking this for the educational purpose but also not liking so less people use this maliciously. nice explanation tho, kinda scary

  • @mgtgamer6029
    @mgtgamer6029 6 місяців тому +1

    The best Explanation❤

  • @wallaguest1
    @wallaguest1 Рік тому +14

    damn it, the RLO trick is quite surprising, for things like this you just better drag the file to the image editor

  • @mapg519
    @mapg519 10 місяців тому +1

    WE ARE MAKING A RAMSOM WARE WITH THIS ONE 🗣️🔥🔥🗣️🗣️🔥🔥🔥🔗🔗🔗

  • @Islandpulledfromthesea
    @Islandpulledfromthesea Рік тому +6

    This is getting out of hands
    Thank you tho

  • @Pr0toPoTaT0
    @Pr0toPoTaT0 Рік тому +2

    I subscribed right at.... you know. The one nobody buys. I totally never bought this program but damn if it doesnt seem to always be activated. Crazy.

  • @MiguelWilson0
    @MiguelWilson0 Рік тому +102

    fun fact: there is no educational use for thst

    • @jasii7206
      @jasii7206 8 місяців тому +10

      I am taking Cybersecurity as a trade, this is educational to me.
      :D

    • @tomasprochazka6198
      @tomasprochazka6198 7 місяців тому +1

      how come? I learnt that Win is still a mess in these days.

    • @Noahitis
      @Noahitis 7 місяців тому +3

      ? It doesnt have to have an educational use, he's educating on a subject, which makes the video educational.
      Whether that be if you were educated on how to infect other peoples machines or to better protect against having your own machine infected, this video was by definition educational as it taught something

    • @MiguelWilson0
      @MiguelWilson0 7 місяців тому

      @@Noahitis that comment was from 5 months ago...

    • @Noahitis
      @Noahitis 7 місяців тому +2

      @@MiguelWilson0 people comment on my stuff from 6 years ago, it doesn't change the validity of what I just said

  • @blu3m0nkey
    @blu3m0nkey Годину тому

    "Freak truck"
    I can't even download images off Google without a virus now

  • @svenrawandreloaded
    @svenrawandreloaded Рік тому +4

    you should show people how to detect these files

  • @thereaper3796
    @thereaper3796 Рік тому +2

    Esto podría ser bastante útil algún dia en el sentido "educativo"

  • @xodzphone
    @xodzphone Рік тому +4

    Man i remember doing this in like 2001

    • @LeZylox
      @LeZylox Рік тому +1

      Old person.

    • @Will_of_Iron
      @Will_of_Iron Рік тому +1

      I wasn't even born yet lmao. You're awesome 😎💯

    • @HhVhji
      @HhVhji 8 місяців тому

      Yes thats what i says its too old 😂😂

  • @Calamite-n3p
    @Calamite-n3p 7 місяців тому

    Bro that's insane i really didn't know those techniques before holy shit that's scary

  • @artiflefy1371
    @artiflefy1371 Рік тому +3

    Now I'm scared of discord img

  • @user-tc9uz7zy8d
    @user-tc9uz7zy8d Рік тому +2

    Fantastic video

  • @htgg9006
    @htgg9006 Рік тому +6

    Skid material
    We don't need more 15 year olds roaming around discord sending malicious files to other kids

    • @ebolaman_
      @ebolaman_  Рік тому +3

      i’m literally a professional skid

    • @htgg9006
      @htgg9006 Рік тому +1

      @@ebolaman_ lol, why not progress deeper tho?

    • @b4rlvnna
      @b4rlvnna Рік тому

      @@htgg9006 what makes you think he hasnt

    • @beamsandshits
      @beamsandshits Рік тому +3

      the only thing skid here is the skidmarks in ur underwear bro

    • @htgg9006
      @htgg9006 Рік тому

      @@beamsandshits your channel is literally roblox exploits, why you bein a kid instead of doing real sh*t? No need to get mad but if you're into cyber do it all the way and not like a clown

  • @brunio167761
    @brunio167761 Рік тому +1

    nice dude, next turorial: how to empty someone bank account (just educational)

  • @pinguluk1
    @pinguluk1 Рік тому +11

    this is insane, I better be careful with downloaded images from now on 💀

    • @OrganicYetiBS
      @OrganicYetiBS Рік тому +2

      Same here

    • @Otherwise_1
      @Otherwise_1 Рік тому +1

      Same here

    • @Ransomwave2
      @Ransomwave2 Рік тому +1

      the RLO method doesn't work after uploading a file to 99.9% of file hosts online. you shouldn't be scared. if you're skeptical, you can always just right click and check the properties

  • @sab_33fr
    @sab_33fr 10 місяців тому +1

    This is very interesting. Might use it against scammers

  • @HTDMAS
    @HTDMAS Рік тому +5

    but wont Windows diffender block that file if someone trys to download it

    • @enty-3035
      @enty-3035 Рік тому +1

      Its depends.
      If has a malwer blocks it if dont it not

  • @EvanVR1987
    @EvanVR1987 7 місяців тому +1

    thanks, now i "educationally" know how to give someone a virus.

  • @AdrianLee
    @AdrianLee Рік тому +18

    Why not just make the shortcut point to the hidden webhook.exe file instead? If they're looking at the properties in any case, they'll see that it points to an .exe and not an image 😅

    • @guili-p7m
      @guili-p7m 3 місяці тому

      I'll give a huge reward to anyone who can make it

  • @Aurora.Astralis
    @Aurora.Astralis 10 місяців тому +2

    Love some good bass boosted Xenogenesis by TheFatRat

  • @zmudzin4493
    @zmudzin4493 7 місяців тому +9

    ok how to avoid it now

    • @ZeroEight
      @ZeroEight 7 місяців тому +2

      don't download anything

    • @JohnyLilMoney
      @JohnyLilMoney 20 днів тому

      Stop using the internet and go outside

  • @user-CosmoGT
    @user-CosmoGT Рік тому +2

    i love this man

  • @Xaredion
    @Xaredion Рік тому +22

    what app did you use to 'short cut' the unicode rlo character?

    • @ebolaman_
      @ebolaman_  Рік тому +14

      right click>insert unicode character

    • @Dino-zg2vx
      @Dino-zg2vx Рік тому +1

      @@ebolaman_ he wants to know how youre able to see that unicode thing

    • @nuggetvb
      @nuggetvb Рік тому +5

      @@Dino-zg2vx when youre renaming the file just right click on the file name and it should give you those options. he literally told you to pay attention

    • @joedartonthefenderbass
      @joedartonthefenderbass Рік тому +2

      @@Dino-zg2vx it's just built into windows

  • @li_B4shar_il
    @li_B4shar_il Рік тому +1

    thanks ebola man, very cool 👍

  • @Darkbeamer01
    @Darkbeamer01 Рік тому +4

    can you make a slightly less complicated version?

    • @ebolaman_
      @ebolaman_  Рік тому +2

      alr

    • @Darkbeamer01
      @Darkbeamer01 Рік тому

      thanks alot first time a youtuber actually responds to their viewer good job@@ebolaman_

    • @pyro4888
      @pyro4888 Рік тому +5

      i mean its already simplified enough its not that hard to follow

    • @Darkbeamer01
      @Darkbeamer01 Рік тому

      for me it is@@pyro4888

  • @SimplyAtset
    @SimplyAtset Місяць тому +1

    First time watching this dude and what is that mic stand, anyway the video was amazing

  • @Ali-wf9ef
    @Ali-wf9ef Рік тому +3

    so if you open an image and it opens it doesn't necessarily mean that it is not a virus.. great job microsoft

  • @pilgrim_gaming
    @pilgrim_gaming 3 місяці тому +1

    Do you still see a shortcut thing? Yes. It’s not perfect, but that’s pretty good.

  • @anony-mousex
    @anony-mousex Рік тому +7

    Insane most of this stuff is just baked into the OS.. Windows really has no regard for user safety

  • @Georgian_guy-1
    @Georgian_guy-1 9 місяців тому +1

    This can be both life saver and life ruiner💀

  • @PhantomZaya
    @PhantomZaya Рік тому +3

    when i do extention spoof #3 the output file is (img name).png.lnk why?

    • @ebolaman_
      @ebolaman_  Рік тому +1

      .lnk is the shortcut extension

  • @thelibyandxer
    @thelibyandxer 8 місяців тому +2

    Imagine doing this in school 😭💀

  • @natoplly
    @natoplly Рік тому +5

    Hi I noticed that there is no multi-tool video at your place. Could you please share this video on e.g. Google Drive or something else.

    • @ebolaman_
      @ebolaman_  Рік тому +1

      github.com/EbolaMan-YT/Multi-Tool

    • @natoplly
      @natoplly Рік тому +1

      @@ebolaman_ thank you good person!!

    • @AsterLight
      @AsterLight Рік тому

      Ngl downloading a file from this guy is the last thing I would do

  • @letsqooo
    @letsqooo 4 місяці тому +2

    why is the hardest part to find the ico image😭

    • @keremustax
      @keremustax 25 днів тому +1

      i can send you an troll ico that everyone will click if you want but after you watched this video it will hard to believe me i think xD

  • @fredo13377
    @fredo13377 Рік тому +8

    Release the code that sends the message to the webhook as well as to the logger.

    • @ebolaman_
      @ebolaman_  Рік тому +9

      the code that sends the message to the webhook is an placeholder for a token logger

    • @KyuDoesCode
      @KyuDoesCode Рік тому

      C# ? C++ ? Python ?

    • @Maxx23
      @Maxx23 Рік тому

      c#@@KyuDoesCode

    • @freen1364
      @freen1364 Рік тому

      Look for it on google

  • @tryingtonot3369
    @tryingtonot3369 Рік тому

    casualy doing gods work

  • @OfficialSwazzzy
    @OfficialSwazzzy Рік тому +5

    hello do you know how to make a hwid spoofer? been watching these videos and tryna make one using the multi tool method as well.

  • @ninjaxboy
    @ninjaxboy 7 місяців тому

    Educational purposes only is the special key to not getting banned

  • @phsycdelic
    @phsycdelic Рік тому +4

    When uploading it on discord, does it act like an actual png. Also what stubs do you recommend for roblox

    • @ebolaman_
      @ebolaman_  Рік тому +3

      idk abt roblox stubs but yeah it only works w discord if u zip it

    • @phsycdelic
      @phsycdelic Рік тому

      @@ebolaman_ damn, are there any stubs you'd recommend

    • @omggggggggg-jkyss
      @omggggggggg-jkyss Рік тому +7

      @@phsycdelicjs learn c stop being a skid >w

    • @Sown.
      @Sown. Рік тому

      ​​@@omggggggggg-jkyssmalware in C is very annoying to make

    • @pyro4888
      @pyro4888 Рік тому +1

      @@phsycdelicwhy u wanna beam so bad😂😂😂

  • @nonstoppe9
    @nonstoppe9 8 місяців тому +1

    Educational purposes=educating hacksers

  • @WukCR中文
    @WukCR中文 8 місяців тому +3

    how does the webhook exe work

    • @_neins
      @_neins 8 місяців тому

      Discord bot

    • @luimu
      @luimu 7 місяців тому

      it sends post request to an url

  • @Dont-Refer-to-me
    @Dont-Refer-to-me 9 місяців тому +1

    Thank you! I just hacked tens of thousands of poor souls who thought i sent them a picture of a puppy! 😃

  • @HeyVSauce
    @HeyVSauce Рік тому +4

    this is why i avoid windows at all costs; over here on linux, you need the executable permission/flag set if you want a file opening to result in it running code

    • @Bo0mber
      @Bo0mber Рік тому +2

      Don't pretend that linux doesn't have a shit ton of other vulnerabilities. And I'm not even talking about how painful it is to use

    • @HeyVSauce
      @HeyVSauce Рік тому +3

      @@Bo0mber
      "painful to use" clearly you havent used windows with it's painful constant crashes & all around instability
      "vulnerabilities" true, however let's not pretend windows doesnt have the same ones + a bunch of phishing ones - this video essentially describes a text-rendering bug allowing you to perform a phishing attack, something that i would like to see happen on linux
      tricking users into opening an "image" is way easier than any phishing attack that relies on literally anything on a modern, up-to-date linux system ever will be
      also, since we're now comparing actual vulnerabilities, i can still load genshin's kernel mode driver for free kernelspace privilege escalation on a system which never had genshin installed - it's still trusted by windows :)
      microsoft doesn't give too much of a fuck about fixing legitimate vulnerabilities, linux kernel & other critical-inifra developers usually do.

    • @HeyVSauce
      @HeyVSauce Рік тому +1

      to clarify: the text-rendering bug is only a bug due to it's possible use-cases; I get the use for an RLO, it's just considered a bug due to it being abusable in this specific context.

    • @Bo0mber
      @Bo0mber Рік тому +6

      @@HeyVSauce saying I haven't used windows is so ridiculous I don't think you believe it either. As far as stability goes, from my quite limited experience with ubuntu, I can say it is way less stable and usually when you try to make something work in linux it takes several hours of recearch, whereas in windows it just works right away. I also don't remember the last time I've seen something crash, maybe it is because my computer isn't 20 years old?
      As for vulnerabilities, I'm not arguing about how many there are in each os, I'm just saying it's quite dumb to pick an os based on this factor when "preffered" os isn't even free from them

    • @HeyVSauce
      @HeyVSauce Рік тому +1

      ​@@Bo0mber ubuntu is maintained by canonical, a company not known for anything except being idiotic amongst the linux community.
      when I run windows for testing shit, I'm running on like 2-3 year old hardware, and the amount of random crashes I get when doing the simplest of things is insane - sure, it won't just crash when opening notepad, but it is a very unstable operating system.
      even just the APIs it provides to usermode applications cannot stay stable for 0.3ms

  • @jannes5293
    @jannes5293 Рік тому

    i appriciate youre videos i love all of them

  • @boing7679
    @boing7679 Рік тому +7

    what about doing it by adding the executable to the shortcut as an alternate data stream so you only need to download one file

    • @deeeeeeeeeep88
      @deeeeeeeeeep88 Рік тому

      You will have to go into the registry to show the file extension but since the file extension for a shortcut is .lnk, it would seem really suspicious

  • @NolenFelten
    @NolenFelten Рік тому

    That grassy hill image was taken in Sonoma County, California, where I grew up.

  • @imauser301
    @imauser301 Рік тому +4

    you can literally teach people how to obtain interesting substances and add "educational purposes only" and completely pass off youtube

  • @spartv1537
    @spartv1537 9 місяців тому

    technically, you can go deeper with shortcut method without spoiling hidden file but it's gonna be multi-task command for cmd

  • @zerayde
    @zerayde Рік тому +3

    what is ur patreon

    • @ebolaman_
      @ebolaman_  Рік тому +2

      www.patreon.com/EbolaMan

  • @boraj
    @boraj 7 місяців тому

    Teaching things that used without authorization could lead you straight to jail.

  • @IamOsvy
    @IamOsvy Рік тому +4

    it's very obvious that no one is going to use it in an educational way and they will use it for doxing.

    • @CramePus
      @CramePus Рік тому +2

      hahahah really? main point you donkey, have a good xmas tho and stay safe

    • @mrhonkhonk6116
      @mrhonkhonk6116 Рік тому

      no shit sherlock

  • @entic207
    @entic207 Рік тому +1

    Thats why I always use the “show file extension names” option

  • @guedaigegedeon2042
    @guedaigegedeon2042 Рік тому +3

    THANK YOOU