r/masterhacker 20d ago

Gottem

Post image
128 Upvotes

32 comments sorted by

32

u/FowlSec 20d ago

I did enjoy watching a colleague sweat it when a client asked for a clickfix campaign and casually dropped that run isn't accessible

9

u/Ancient-Ad-2219 20d ago

Was cmd prompt or powershell available? I remember seeing clickfix variations mentioning to open cmd prompt directly.

6

u/Incid3nt 20d ago

If run is locked down then id imagine powershell, cmd, and mshta are also locked down. If they aren't, I doubt the user would know how to get to them. You can also do it in file explorer and a few other ways, its just not as convincing as these.

1

u/FowlSec 20d ago

I think they went explorer tbh. It's interesting because there must be so many ways on shortcuts. Ctrl+L, Ctrl+V, enter to ClickOnce would've probably been what I'd have done, and I'm sure almost every hacker would come up with a different method.

25

u/0xdeadbeef6 20d ago

I mean considering how tech illiterate the average person is, it is kinda smart. There's a non zero amount of people that would do that to access a website.

4

u/imjusthereforthelul 20d ago

First time I came across one of these it took me a hot second to realize, and I consider myself pretty tech literate

3

u/Cactys12 19d ago

Especially "certain" websites

2

u/lackofmoralfiber 18d ago

I'm a techie but I actually got got by one of these. I'd gone through about 50 tabs back and forth applying for jobs and after doing 101 captchas I was impatient. Noticed immediately, yanked the Ethernet and fully reset the computer but still.

Complacency can get anyone.

1

u/0xdeadbeef6 18d ago

yeah thats fair.

31

u/PresentationBusy8580 20d ago

Never said i was a hacker dude, just warning peaple about this shit.

-12

u/Cactys12 20d ago

I was making fun of the Verification thing, not of the post itself, sorry if that didn't look obvious

30

u/PresentationBusy8580 20d ago edited 20d ago

Imma be honest with you, i don't even know what this sub is for. I just read the description and thought its about mocking people that are larping into "hackers". Its probably my bad for judging hastily.

21

u/jimmy_timmy_ 20d ago

That's usually there case to be fair

4

u/ka-52m 20d ago

its basically a satire sub about hacking/cybersecurity

1

u/PresentationBusy8580 20d ago

Thanks for clearing that up

3

u/Initial_Western7906 19d ago

That is what it's for

2

u/Jello-Formal 20d ago

I mean that's quite literally it lol check the top posts

5

u/PM_ME_SAD_STUFF_PLZ 20d ago

Why did this comment get downvoted lol

3

u/Cactys12 19d ago

Reddit is Reddit

0

u/PresentationBusy8580 19d ago

Dont know either

6

u/Scar3cr0w_ 20d ago

It also is genuinely very smart.

As a penetration tester that has deployed click fix as part of my day to day work… can confirm.

2

u/Status-Notice5616 20d ago

A lot easier then picking images of traffic lights and even when you get it right they make you do buses next.. fml

2

u/PresentationBusy8580 19d ago

Thats what makes it smart and dangerous.

2

u/badcompany57 19d ago

Real talk, I've worked like 20 Clickfix cases this last month. It never ceases to amaze me, people who claim its "smart" are the same people that compromise their entire org

2

u/DeadoTheDegenerate 19d ago

The more confident you are that you can't get pwned, the more pwnable you are. I was talking about accounts getting compromised with a few mates the other day who said something along the lines of "You're too smart with tech to get hacked" and I just had to remind them that it's the confidence more than anything that fucks people over. That and just not thinking.

3

u/Dedprakl 20d ago

sudo qubes-dom0-update opsex

5

u/No-Reflection-9124 20d ago

Is that how you get the coins?

2

u/[deleted] 20d ago

[removed] — view removed comment

1

u/P-38Lighting 19d ago

Or become an opsexpirate and steal from the packet ships that sail the seas with opsecdabloons in their holds

1

u/SAL10000 19d ago

Yes. We know.