Fake CAPTCHA Runs Malware

Поділитися
Вставка
  • Опубліковано 18 вер 2024
  • jh.live/soc || Join me for the SOC Analyst Appreciation Day! A completely FREE event on October 16th by DEVO! jh.live/soc
    www.virustotal...
    x.com/aruhamm/...
    x.com/g0njxa/s...
    www.orangecybe...
    x.com/Unit42_I...
    github.com/Pal...
    • MALWARE on a BLOCKCHAI...
    denwp.com/anat...
    github.com/Joh...
    Learn Cybersecurity - Name Your Price Training with John Hammond: nameyourpricet...
    Learn Coding: jh.live/codecr...
    Don't listen to other "influencer" VPN crap -- host YOUR OWN: jh.live/openvpn
    WATCH MORE:
    Dark Web & Cybercrime Investigations: • Tracking Cybercrime on...
    Malware & Hacker Tradecraft: • Malware Analysis & Thr...
    📧JOIN MY NEWSLETTER ➡ jh.live/email
    🙏SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎FOLLOW ME EVERYWHERE ➡ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/discord ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware
    🔥UA-cam ALGORITHM ➡ Like, Comment, & Subscribe!

КОМЕНТАРІ • 166

  • @logoninternet
    @logoninternet 2 дні тому +212

    I could definitely see people falling for this. The fatigue among users encountering captchas is real. That's what this relies on.

    • @ardwetha
      @ardwetha 2 дні тому +15

      Let's be real. Elderly people or most of the boomer generation will fall for this and probably some of the younger people, without IT or security background would also.

    • @TessaBain
      @TessaBain День тому

      You're right, but you're technically also wrong. Yes, people are tired of it, but that would actually mean less people would likely fall for it.
      Apparently when you're tired of something, you go ahead and interact with it more for some reason, but normal people do not.
      They see the thing and they immediately disengage.
      I, for example, have closed thousands of pages when I saw a captcha and simply couldn't be bothered because it wasn't important enough.
      I am very fatigued of them and therefore stop interacting with not just pages but even whole sites that want me to do even one.
      Because I am tired of them, not only will I not do their captcha, I will never use their site again if I suspect I will be forced to do so to get what I wanted out of them in the first place.
      You've also clearly never dealt in much YGO if you think that people don't immediately forfeit when seeing their opponent slap down a card from decks they're tired of seeing.
      Something that happens because fatigue = disengagement.

    • @brbl415
      @brbl415 День тому +6

      @@ardwetha Yeah especially if you offer them free roblox

    • @balsalmalberto8086
      @balsalmalberto8086 День тому +2

      The crazy thing is this type social engineering attack bypasses browser sandboxing (browser can't launch executables on the host).. pretty ingenuous but scary stuff. All the more reason it's essential to use ad-blocking software.

    • @MichaelOfRohan
      @MichaelOfRohan День тому

      Yeah if youre based pirating shit at your grandmas house lol.
      Nobody who has a job is falling for that shit.

  • @siomek101
    @siomek101 2 дні тому +112

    its very clever if you think about it. "techy" people would not fall for it, but normal people, would probably fall for it

    • @MrNaesme
      @MrNaesme 2 дні тому +20

      Even a techy person could fall for it if they're just going through the motions. Never underestimate just how much you've been programmed to follow along with random bullshit processes.

    • @care-m7k
      @care-m7k 2 дні тому +9

      Linus tech tips falls for it

    • @truthboom
      @truthboom 2 дні тому +8

      @@MrNaesme hold alt f4 to check if there's malware

    • @WillyJL
      @WillyJL День тому

      people constantly fall for discord login scams and pollute servers with more bot scams, i could see a fake captcha being even more effective than those

    • @HenkGootjes66
      @HenkGootjes66 День тому +4

      Ty that worked ​@@truthboom

  • @surya_11
    @surya_11 2 дні тому +21

    John Hammond when he sees an Western name like Arnold Schwarzenegger: "That's too easy!"
    Also John Hammond when he sees basically a four-letter non-Western name: "I'm sorry, I quit."

  • @DS-sm3nu
    @DS-sm3nu День тому +27

    Any child offered vbucks, roblox, etc, playing on their parents/family computer would absolutely fall for this

  • @Yaimsputnik556
    @Yaimsputnik556 2 дні тому +77

    seems stupid but the sad part is it works very well for your average user

    • @DaweSMF
      @DaweSMF 2 дні тому +2

      Maybe because your average user isnt usualy computer enthusiast and have computer as "necessary evil". Usualy as workstation or machine for home use, to play movies and download porn. The technology goes forward so quick even professionals have "heads full" and often dont see the obvious. Lack of time is general issue and if you have deadlines and for example also staff shortage, you will fall for even more stupid things. Thats why there are ICT departments in companies.

    • @MichaelOfRohan
      @MichaelOfRohan День тому

      Said an apple user....

  • @samuelbudzinak
    @samuelbudzinak 2 дні тому +37

    It's evil genius
    I know A LOT of people, who would fall for it

  • @SzaboB33
    @SzaboB33 День тому +11

    This is the biggest "facepalm" foothold I have seen in 2024

  • @TUXbeatDOWN
    @TUXbeatDOWN День тому +5

    The one John made, I feel, would trick so many people... Much more than the attacker's version shown before that.

  • @orderandchaos_at_work
    @orderandchaos_at_work 2 дні тому +19

    You'd have to be a robot to complete those steps.

    • @Krullfath
      @Krullfath 2 дні тому +3

      That's so funny

    • @ShortBusRejectz
      @ShortBusRejectz 2 дні тому +4

      Old people exist. Unfortunately, they are the most targeted

    • @Krullfath
      @Krullfath 2 дні тому +3

      @@ShortBusRejectz Calling old people robots now?

    • @tsuketsu9889
      @tsuketsu9889 День тому +5

      Tech illiterate people exist, and are more common than you think.

    • @reefhound9902
      @reefhound9902 День тому

      @@tsuketsu9889 You don't have to be tech literate to Just Say No. No to clicking any links or buttons in email. No to giving personal info over the phone (or even answering a call). No to running commands. No to doing anything asked that is unusual. In fact I would think being tech illiterate should make it easier. If you don't understand it, don't do it. If in doubt, don't do it.

  • @diobrando5334
    @diobrando5334 2 дні тому +18

    I DON'T BELIEVE IT ... I JUST SAW IT YESTERDAY AND ALMOST FELL FOR IT!!!

    • @MekelachiChijioke
      @MekelachiChijioke День тому

      me too but when they said Crtl + V i knew something was fishy so why not hack the hackers site

    • @iamyourgreatgreatgreatgrea6291
      @iamyourgreatgreatgreatgrea6291 День тому

      Thank god you didn't provide any info about where you saw it, truly helps people so they don't encounter it.

    • @diobrando5334
      @diobrando5334 День тому

      @@iamyourgreatgreatgreatgrea6291 it was on a pirating website so ... not risking that the website to go down + why tf do u want the website if you know how the hack work?

    • @TessaBain
      @TessaBain День тому

      Never seen this one but just opening something on the computer itself is fishy.
      Once you get to the fact that they want you to paste something, it immediately tells you they copied something to your clipboard when you pressed the button.
      I can see clicking it (they're constantly changing these systems around for no reason, so the fact that it looks a little different isn't necessarily weird) but the first is just an immediate red flag and the second is a giant rainbow kaleidescope flag unless you don't know copy and paste.

  • @mybachhertzbaud3074
    @mybachhertzbaud3074 День тому +7

    The more complex things get, the easier simple weapons seem to work.🤔

  • @AstralArchivists
    @AstralArchivists День тому +9

    I got a John Hammond ad ln this video haha

  • @jimkats1
    @jimkats1 День тому +2

    Unfortunately even the simplest and dumbest trick works for most of the average users, and that's why they keep appearing. Under circumstances, even the most careful may fall for it.
    Thank you for this video of analyzing the situation (and to everyone else of course who did the research and spread awareness about it).

  • @munshidomain
    @munshidomain День тому +1

    New fear unlocked.
    Guess I am declaring myself as ROBOT.

  • @andrewbarth8157
    @andrewbarth8157 День тому +5

    Sorry to be cynical, but really not an interesting attack vector. John admits this multiple times, and I waited for more to come out of it, but there really wasn't any more substance to it. The Twitter (and UA-cam) comments saying this would fool people are largely missing the point. It's a social engineering technique that has the same motivation that MFA fatigue attacks do, this is not anything new. Appreciate the attempt to give it some relevance by trying to make it more convincing. Also, kinda odd to review the .md file to us in the text editor.

  • @benediktussava
    @benediktussava День тому +3

    greetings from the Ethical Hacking Indonesia community John !

  • @jonnyfatboy7563
    @jonnyfatboy7563 2 дні тому +1

    funnily enough my add before this video started was john Hammond talking about deadsec 😅 very cool

  • @xXstevilleXx
    @xXstevilleXx День тому

    John, thanks for this. I am doing a write up so to speak on captchas. Mainly because many people who are just users do not know the dangers. Besides the dangers, with AI, these are useless and verification is so much more complicated than I at first assumed. Heck as we speak those working on countering this and find better ways are still finding ways that are better than what they roll-out almost daily, doing a great job for sure but for this I have not quite seen as much research being done. Any rate long story short, much appreciated.

  • @erocme
    @erocme День тому +1

    This is great😂 I don’t want to be the analyst that has to work up a solution to prevent clients from using the clipboard to evade the browser sandbox. Seriously, always interesting. Also thanks for sharing some of the other examples and writeups showing how our users fall victim to these payloads 🔥🔥

    • @AntiAtheismIsUnstoppable
      @AntiAtheismIsUnstoppable День тому

      No, but, shouldn't there be a warning when you copy/paste into the terminal, it did that in my old linux system?
      Look, when you open web developer tools, there is warning because this is used by scammers to fool non tech people, so why is it not obvious, that anything else where the user is copy/pasting into a field which has connection to terminal, then there should be a warning, preferebly a confirmation via UAC?
      When you download a file from the internet, it has certain restricted rights, same should be the case with anything copied from a web site into a terminal or system form field.

  • @barronvonnoodle
    @barronvonnoodle День тому

    Watching a John Hammond and then i get an ad from John Hammond. Now that's marketing at work

  • @test-rj2vl
    @test-rj2vl 2 дні тому +2

    We need to make Win + R to require you to type "allow pasting" for first time like browser dev tools does. Normies would get stuck behind skill issue.

    • @AlfiesFuntime
      @AlfiesFuntime День тому +2

      They'll just add: Type "allow pasting"

  • @logiciananimal
    @logiciananimal День тому +1

    You're right about that use of copy - I encountered in a pentest I did a few months ago.

    • @AntiAtheismIsUnstoppable
      @AntiAtheismIsUnstoppable День тому

      I use the old fashioned copy style on my web site because the new is way too advanced, and the old one works, and I assume will also work for a very long time for backwards compatibility. But it's not the browsers fault and not javascripts fault either, it is a security flaw in the OS, that data from an unsafe area is not validated before execution. It's very clever, because it is not directly obvious that it is a security flaw, but it is.

  • @Zero11_ss
    @Zero11_ss День тому +3

    His hair is like a delicious croissant

  • @martinbaran7570
    @martinbaran7570 2 дні тому +1

    i'm starting to think the analyst they are referring to may be me !, I had responded to this exact looking incident with the same IOC'S but I knew the user manually ran this powershell as I could see it in the logs the question was why and how and where did they get the this encoded command. did some digging and came across unusual amounts of redirects and yep came across the download step domain with a fake captcha getting the user to open the run window and paste in the command. very simple but clearly effective.

  • @Splarkszter
    @Splarkszter 2 дні тому +17

    Why are encoded commands allowed in the first place?

    • @Entropy67
      @Entropy67 2 дні тому

      Probably because its useful depending on what you want your app to do

    • @muizzsiddique
      @muizzsiddique 2 дні тому +5

      Probably a way to deal with horrendously nested quote marks, so you don't have to add nested escape characters.

    • @H3cJP
      @H3cJP 2 дні тому +4

      because encoded commands are actually used
      i use it sometimes, a b64 encoded string, instead of dealing with the crazyness of quote marks
      but yeah would be better if that gets blocked from being runned by the "run" thing, it is useful but i think it should be limited to running from console or as a command runned by a program

    • @H3cJP
      @H3cJP 2 дні тому

      to be clear i used once b64 but it was just for something that i wasnt going to publish, bad idea for shared work imo

    • @Splarkszter
      @Splarkszter 2 дні тому

      But why on Normie computers that should never need to touch CMD?

  • @Capiosus
    @Capiosus День тому +2

    clipboard history should be a web permission denied by default.

  • @rozansanuraalbary2944
    @rozansanuraalbary2944 День тому

    that powershell bloked by EDR in my office. i dont expect that the cyber attack happens in many places

  • @zenginellc
    @zenginellc День тому

    It's better for people to know even the more simple methods so they don't get overlooked.

  • @Nycto97
    @Nycto97 День тому

    Oh God, as soon as I saw the "Verification Steps"... Like others are saying in the comments, most of us know immediately something fishy is going on, but my mom, dad, grandmother etc would all just follow those steps blindly, not knowing what Win+R does or opens, not knowing they're about to paste something that's been set on their clipboard,... It's so scummy from these bad actors, they know exactly that most people have no clue what all of this means. It's so sad, and I feel sorry for every victim. They're paying the price just for not being familiar enough with these things.

  • @vitaliwilhelm7654
    @vitaliwilhelm7654 День тому

    Wow, had a John Hammond Ad on a John Hammond Video 🤣🤣🤣

  • @Illogical.
    @Illogical. 17 годин тому

    I got an ad while watching this. You were in the ad.

  • @BrickTamlandOfficial
    @BrickTamlandOfficial 2 дні тому +3

    is there any way to disable the base64 decoding in powershell commands?

  • @LeeZhiWei8219
    @LeeZhiWei8219 2 дні тому

    I got a John Hammond snyk ad, on a John Hammond video 😂

  • @vadiks20032
    @vadiks20032 2 дні тому +7

    i appreciate your videos, but judging by video title, i thought its some brand new 0 day drive-by on a click exploit, but all it is, is yet another social engineering hack where you have to do stupid things to win stupid prizes. have you ever showcased drive by exploits though? if there are any, in 2024

    • @ronpaul9172
      @ronpaul9172 День тому

      There are plenty. I have quite a few.

    • @balsalmalberto8086
      @balsalmalberto8086 День тому

      @@ronpaul9172 "I was busy hoarding computer virus samples while you were out honing your social skills and living a normy life"

    • @vadiks20032
      @vadiks20032 День тому

      @@ronpaul9172 a video with showcasing one would be fun

  • @theepicslayer7sss101
    @theepicslayer7sss101 День тому +1

    glad there is a barrier between for it to work... if it were the exact same looking captcha AND only need to click, that would be a nightmare! also, i got your DevSecCon 2024 ad on your video around the 9 minutes mark lol, not sure if you pay your self and have 0 gains or a net loss... still was funny seeing your ad playing over your ad!

  • @technikschaf1574
    @technikschaf1574 22 години тому

    Oh the irony of hitting Enter being the action that allows the malware to enter your PC.

  • @HolyAdilokGames
    @HolyAdilokGames 2 дні тому

    First.. i remember when this video was posted 10 mins ago.. I'm at 12:10. Love the begining and the sponsor of this very video.

  • @kev2020-z9s
    @kev2020-z9s 2 дні тому +1

    Thank you for this I run linux (not trying to sound better just use linux as I am on an old pc)still interesting to see what people are trying.

  • @an3ssh
    @an3ssh День тому

    that JS code looks like something that I'd write. Plain SIMPLE!!!

  • @jrnvnjk
    @jrnvnjk 14 годин тому

    Fun fact: The user click on the capcha is required for some browser fearures like going to fullscreen or using clipboard. When it's done in the "contructor" it just throws an error.

  • @Bashiroo
    @Bashiroo 2 дні тому

    Getting into this video, I was genuinely wondering "are we really talking about the fake captcha that asks for notifications and spam you with ads?"

  • @vaibhav3852
    @vaibhav3852 2 дні тому

    i love clever dynamic testing, but dont like dynamic testing to avoid or get a head start in static testing of malware

  • @Pointless-Point
    @Pointless-Point День тому +1

    And another power-user feature about to be removed...

  • @raihanrafi3665
    @raihanrafi3665 2 дні тому

    11:34 jai minton with JH low quality face. Lol😅😅

  • @Iron_Condorr
    @Iron_Condorr День тому +1

    I posted about the potential for this on Reddit years ago, and no joke was met with so much toxic/know it all replies that i deleted the post. "I told you so" is never a response i want to give in relation to malware.

  • @cameronrich2536
    @cameronrich2536 День тому +1

    Neofetch im looking at you

  • @asf130thecompany7
    @asf130thecompany7 День тому

    These longer videos for me are ok due to somewhat intresting topics you cover but that's just me ^^

  • @iuhere
    @iuhere 16 годин тому

    Dumber is more effective. I sniff convenience winning over.

  • @Sourpusscandy
    @Sourpusscandy 2 дні тому +5

    Just another reason I HATE CAPTCHA BS!

    • @AntiAtheismIsUnstoppable
      @AntiAtheismIsUnstoppable День тому

      It's not the CAPTHAs fault, actually, it is a security flaw in the OS, not an obvious flaw I admit, but it is a violation of good security practice, when data which is coming from an unsafe area and then moved into the system area for execution is not verified by the user. The same is true when you download an executable from the internet, which is unsafe by defasult, again when you run that executable the user should be asked for verification by UAC.

    • @balsalmalberto8086
      @balsalmalberto8086 День тому

      I hate the internet. I wish I never got into computers lol.

  • @vaibhav3852
    @vaibhav3852 2 дні тому +1

    Please make more complex reverse enginnering malware videos. maybe show how to do analysis on exe files

  • @ThatLinuxDude
    @ThatLinuxDude День тому

    Kinda off topic, but now you point out the Run command order key, it makes me wonder why Microsoft didn't just store the command history as a MULTI_SZ - worried about size limit maybe?

  • @LivvieLynn
    @LivvieLynn День тому

    They'd do better to automatically fail the captcha and provide instructions for alternate verification along with a phone number since anyone who calls is likely to fall for call center scams.

  • @NirabShrestha-Nirab
    @NirabShrestha-Nirab 5 годин тому

    Your answer is my mom would fall for that

  • @jamrar_wh
    @jamrar_wh День тому +3

    If this doesn't get resolved soon on browser protections, we could see this as a wide spread method of account stealing. Hoping that it isn't the case.

    • @AntiAtheismIsUnstoppable
      @AntiAtheismIsUnstoppable День тому

      No, this is not the problem it is not the browser, the problem is two fold, 1. User informakion is trusted without validation and 2. Moving data from an unsafe areae into the system area which should be safe, without any verification.
      Solution is logcial, when you take data from anywhere unsafe and paste it into a system form field for execution, then the UAC needs to ask for verification, preferebly the user pass word, and, give a warning.

    • @Sierra410
      @Sierra410 День тому +1

      @@AntiAtheismIsUnstoppable the problem is between the chair and the keyboard, as usual. The only way to truly "solve" it, is to prohibit running unsigned code of any kind. Anything else the user will end up just mindlessly clicking through.
      That, however, would be "literally 1984".

  • @MikaelaExtra
    @MikaelaExtra День тому

    MY EYES!

  • @Bubblessss420
    @Bubblessss420 День тому

    I just met this today… one of our user ran that code… luckily the file instantly got erased by av.

  • @KLEOPATTRAA999
    @KLEOPATTRAA999 День тому

    Generall you are getting the BAG 🏦🏦🏦😤🙏♥️

  • @rtdev8512
    @rtdev8512 День тому

    if the malware run automaticaly when you click captcha, then it will be a serious problem, BUT if it runs AFTER you copying some nosense code to your runtime, then, what kind of person would do that?

  • @Vulcan-t2m
    @Vulcan-t2m День тому

    This happened to me a few days ago. I would probably have laughed if you told me I would fall for this cheap of a trick, but even still I fell for it and did it while tired. My main concern now is should I wipe my whole C drive, or can i trust antiviruses to detect and delete it. What should i do?

  • @Nqe-m6h
    @Nqe-m6h День тому

    Sir can you give us roadmap for beginner to advance and also the courses that contain things bcz I am also new and faced difficulties about roadmap

  • @balsalmalberto8086
    @balsalmalberto8086 День тому

    Why does shell support base64 on the command line? hell... why does Microsoft still hide file extensions by default? ohhh I see they implemented bash piping in windows and it's enabled by default ... The security team at micrsoft is doing wonders.

  • @iamwitchergeraltofrivia9670
    @iamwitchergeraltofrivia9670 2 дні тому +2

    Hahhhha fucking windows

  • @TessaBain
    @TessaBain День тому

    This mostly seems pretty pointless. Anyone who doesn't at least have the basics of tech are probably not going to want to do "whatever that means" as far as they're concerned and anyone who is online even a moderate amount in general are probably too tired of seeing these things to bother.
    You don't need any amount of tech savvy to be tired of seeing captchas at which point you just close the page.
    In an ironic twist of security events, the vast majority of people who might see these, are probably going to be protected by, essentially, simple laziness, lol.

  • @TheTubejunky
    @TheTubejunky День тому

    Be careful of those MINECRAFT VOTER LINKS

  • @subarutendou
    @subarutendou День тому

    I will click 10 times or verify 10 times because the CAPTCHA loop infinitely then I will block the website from my search engine results. And for me recently some website will jump to a separate page that just have CAPTCHA in the page so if it happens I will not able to tell if that is a fake site or not because the website is show in the search result.

  • @richardd9634
    @richardd9634 2 дні тому +1

    Oi! Leave ifconfig alone!

  • @יובלהרמן-ח2ד
    @יובלהרמן-ח2ד 2 дні тому

    Will anyone fall for that? Well... for my mom to use the computer, I had to make shortcuts to all the sites she uses on her desktop.
    It took her like a week to understand that when she clicks another link it opens a new tab and not closes the other site. When one time by mistake she opened a new tab and it launched a Google search page, she couldn't understand what happend and just wasn't able to use the computer until I came and "fixed it".
    She is "just" 50.
    Yeah. I'd say she would fall for that if she could figure out what the windows key is.

  • @axtadventures
    @axtadventures День тому

    i can see even people that have decent knowledge on how to avoid malware and all that stuff falling for this since you have to have alot more knowledge about malware and all that stuff to know instantly what this does somewhat so you know its malware

  • @rikschaaf
    @rikschaaf 2 дні тому

    Can't a hacker just delete that registry key to not leave any trace?

  • @Ash_G
    @Ash_G День тому

    I pasted it in Notepad instead of "Run Command." 😭😭😭

  • @tntomega
    @tntomega 2 дні тому

    can you please show how to find "pishing" email location? every Sunday, i got to my mail "paypal" post service" mastercard" re connection . i need to know from where the email came from tnx p.s love your channel

  • @lborate3543
    @lborate3543 День тому

    Software dev here... how do you report a website?

  • @MichaelOfRohan
    @MichaelOfRohan День тому

    Why is a web based sctipt even allowed to push to your clipboard?

  • @benisapp155
    @benisapp155 2 дні тому

    Good stuff, i recently had the same attack. My only thought at that time was this really old obvious. This was on a porn site.

  • @john_doe1st
    @john_doe1st День тому

    This happened to me, it asked me to paste some code, I just closed the page.

  • @g0njxa
    @g0njxa День тому

    who said whaaaaaat

  • @AstonishedByTheLackOfCake
    @AstonishedByTheLackOfCake День тому

    this is so dumb, I can't imagine anyone would fall for this bs, it's so obviously fake on so many levels

  • @shrek1435
    @shrek1435 День тому

    i have actualy seen this like 1 month ago, the same page but it was sketchy so i closed it

  • @DefconUnicorn
    @DefconUnicorn День тому

    If it works its not dumb.

  • @Mionwang
    @Mionwang 2 дні тому +1

    I don't mean to brag but I'm the one million eight hundred twelve thousand four hundred and thirty second subscriber.

  • @Ruhgtfo
    @Ruhgtfo День тому

    What tools is that 15:49 ?

  • @fabcara1
    @fabcara1 2 дні тому

    Apple users are safe, for a while 😅

  • @antonioveloy9107
    @antonioveloy9107 День тому

    *plock* nnnnice

  • @FireworkPlayz
    @FireworkPlayz 2 дні тому

    cool

  • @trump1678
    @trump1678 День тому

    Cool

  • @heyitsnemo
    @heyitsnemo День тому

    @ about 15:40 - I like to use windows 11.
    *click off*

  • @omarjokr1153
    @omarjokr1153 День тому

    so cool

  • @RandomytchannelGD
    @RandomytchannelGD День тому

    hi

  • @tried2178
    @tried2178 2 дні тому

    ooouuuu shit

  • @Melanittanigra
    @Melanittanigra День тому +1

    If you fall for this you should be banned from using a computer.

  • @WiissttaaLive
    @WiissttaaLive 2 дні тому +2

    First

  • @Hackanhacker
    @Hackanhacker День тому

    XD

  • @nicehairs1639
    @nicehairs1639 2 дні тому

    first? cool

  • @reporter9698
    @reporter9698 2 дні тому +4

    Free palestine

  • @dsfs17987
    @dsfs17987 День тому

    clear case of - hey, use this on your Mac to make it faster - "rm -rf" 🤣🤣🤣

  • @sakhawathossen2104
    @sakhawathossen2104 День тому

    This code was written by AI, that's why it's directly using document.body, and those depricated things.

  • @alkimos55
    @alkimos55 5 годин тому

    That moment the verification steps were revealed, lmao
    Sure, I sure as hell wouldn't fall for it - but those are such easy steps, anyone can just mindlessly execute them without knowing what it does. Pretty smart

  • @barbapapas-left-nut
    @barbapapas-left-nut 2 дні тому

    Anyone else getting chicken little vibes from john's haircut? the way it flaps when he turns his head lmao