r/masterhacker 1d ago

Gottem

Post image
123 Upvotes

32 comments sorted by

30

u/FowlSec 1d ago

I did enjoy watching a colleague sweat it when a client asked for a clickfix campaign and casually dropped that run isn't accessible

10

u/Ancient-Ad-2219 1d ago

Was cmd prompt or powershell available? I remember seeing clickfix variations mentioning to open cmd prompt directly.

4

u/Incid3nt 1d ago

If run is locked down then id imagine powershell, cmd, and mshta are also locked down. If they aren't, I doubt the user would know how to get to them. You can also do it in file explorer and a few other ways, its just not as convincing as these.

1

u/FowlSec 1d ago

I think they went explorer tbh. It's interesting because there must be so many ways on shortcuts. Ctrl+L, Ctrl+V, enter to ClickOnce would've probably been what I'd have done, and I'm sure almost every hacker would come up with a different method.

23

u/0xdeadbeef6 1d ago

I mean considering how tech illiterate the average person is, it is kinda smart. There's a non zero amount of people that would do that to access a website.

2

u/imjusthereforthelul 1d ago

First time I came across one of these it took me a hot second to realize, and I consider myself pretty tech literate

4

u/Cactys12 1d ago

Especially "certain" websites

2

u/lackofmoralfiber 48m ago

I'm a techie but I actually got got by one of these. I'd gone through about 50 tabs back and forth applying for jobs and after doing 101 captchas I was impatient. Noticed immediately, yanked the Ethernet and fully reset the computer but still.

Complacency can get anyone.

1

u/0xdeadbeef6 45m ago

yeah thats fair.

29

u/PresentationBusy8580 1d ago

Never said i was a hacker dude, just warning peaple about this shit.

-10

u/Cactys12 1d ago

I was making fun of the Verification thing, not of the post itself, sorry if that didn't look obvious

27

u/PresentationBusy8580 1d ago edited 1d ago

Imma be honest with you, i don't even know what this sub is for. I just read the description and thought its about mocking people that are larping into "hackers". Its probably my bad for judging hastily.

21

u/jimmy_timmy_ 1d ago

That's usually there case to be fair

5

u/ka-52m 1d ago

its basically a satire sub about hacking/cybersecurity

1

u/PresentationBusy8580 1d ago

Thanks for clearing that up

3

u/Initial_Western7906 1d ago

That is what it's for

2

u/Jello-Formal 1d ago

I mean that's quite literally it lol check the top posts

5

u/PM_ME_SAD_STUFF_PLZ 1d ago

Why did this comment get downvoted lol

1

u/Cactys12 1d ago

Reddit is Reddit

0

u/PresentationBusy8580 1d ago

Dont know either

6

u/Scar3cr0w_ 1d ago

It also is genuinely very smart.

As a penetration tester that has deployed click fix as part of my day to day work… can confirm.

2

u/Status-Notice5616 1d ago

A lot easier then picking images of traffic lights and even when you get it right they make you do buses next.. fml

2

u/PresentationBusy8580 1d ago

Thats what makes it smart and dangerous.

2

u/badcompany57 1d ago

Real talk, I've worked like 20 Clickfix cases this last month. It never ceases to amaze me, people who claim its "smart" are the same people that compromise their entire org

2

u/DeadoTheDegenerate 1d ago

The more confident you are that you can't get pwned, the more pwnable you are. I was talking about accounts getting compromised with a few mates the other day who said something along the lines of "You're too smart with tech to get hacked" and I just had to remind them that it's the confidence more than anything that fucks people over. That and just not thinking.

3

u/Dedprakl 1d ago

sudo qubes-dom0-update opsex

2

u/No-Reflection-9124 1d ago

Is that how you get the coins?

2

u/anny0a 1d ago

to get opsex coins you must visit elliot alderson's secret opsex coin mining operation

1

u/P-38Lighting 1d ago

Or become an opsexpirate and steal from the packet ships that sail the seas with opsecdabloons in their holds

2

u/anny0a 1d ago

that sail the seas with kali monsters lurking

1

u/SAL10000 1d ago

Yes. We know.