How to Hack Webcam, Microphone & get Mobile Location using a Link - YouTube

Channel: ehacking

[5]
in this tutorial you will learn to聽 access device information location聽聽
[9]
accessing webcam microphone and many other聽 things by just sending a url or a link聽聽
[21]
hello everyone this is irfan from ehacking.net聽 you know the drill like subscribe share and聽聽
[26]
comment anyway let's get started stormbreaker is聽 the utility that we will discuss in this tutorial聽聽
[33]
what it does well if you go down you can see聽 a lot of thing perfect so it grabs device聽聽
[41]
information and location without any permission聽 it can access mobile or even desktop or laptop聽聽
[47]
webcam and microphone as well exciting聽 utility now let's configure it聽聽
[54]
rule of thumb clone it using the good聽 clone command so open the terminal聽聽
[59]
let me zoom so that you can see properly all聽 right and there you can see what i will do now聽聽
[66]
i have to just clone it so go there copy open聽 your terminal again type get uh clone sorry
[79]
and enter it will take some time it will download聽 okay so once you are done you need to get into the聽聽
[84]
directory for example let me check so this is see聽 stormbreaker all right so cd stormbreaker perfect聽聽
[94]
now there you can see the installer which is a聽 bash script so since i'm logged in as root i'm聽聽
[101]
not using the sudo command however if you are聽 not logged in as you root you should use the聽聽
[105]
sudo command so bash and one more thing聽 i need to see the name linux installer聽聽
[114]
perfect so type bash linux聽 installer dot sh install it聽聽
[122]
okay it's done after installation you need to聽 check all the requirements in order to do this you聽聽
[128]
should execute uh the uh the python script to run聽 to check this requirement so the python you should聽聽
[136]
not be worried about all the commands you will get聽 all the commands in the description of this video聽聽
[141]
so so don't worry about uh you know looking here聽 and typing i will just paste all the command there聽聽
[148]
all right perfect and let's check the requirements聽 ops spell issue uh it's requirements without e聽聽
[160]
now let's see already satisfied is working perfect聽 done so let me just clear it all thing done we聽聽
[168]
have successfully installed and configured the聽 utility a few things to understand this excellent聽聽
[175]
utility generates a and grog url hence you can聽 access the target outside your lan environment聽聽
[183]
this means you can access anyone considering they聽 are connected to the internet this program is very聽聽
[190]
easy to use i will demonstrate few things the聽 rest you can do on your own now let's find out聽聽
[196]
what it can do so it's python 3 and just execute聽 this script and again if you are not logged in as聽聽
[204]
root you should use the sudo otherwise it will not聽 work so even i'm using the sudo as well so there聽聽
[212]
you can see that yeah perfect so these things can聽 be done uh now let's find out the device location聽聽
[220]
so for this i need to execute number four enter聽 number four there are two templates near you is聽聽
[228]
very interesting when a user opens the url it聽 displays a page that says find people around you聽聽
[236]
upon continue the targets device location聽 capture and send back to the attacker now聽聽
[241]
let's see the first option near you i'm testing聽 it on my android phone what you need to do is聽聽
[247]
to just copy this particular url and send it to聽 your target and once your target opens this url聽聽
[254]
the connection establishes to your local聽 host or local machine on this particular port聽聽
[259]
you you don't need to do anything else just聽 copy this url and send it to your target聽聽
[266]
so let me send it to my android phone and let's聽 see what will happen well so there you can see聽聽
[271]
that it's it has captured some information it聽 means that the target has opened this particular聽聽
[277]
url uh what i did i just i simply send this聽 url via whatsapp to the target and now the聽聽
[285]
uh the shell is waiting for the interaction the聽 user interaction and upon clicking on uh on the聽聽
[293]
continue it it will automatically automatically聽 captures the device device information so let's聽聽
[298]
just do this i'm clicking on the continue now聽 wow wow so there you can see the exact location聽聽
[305]
with google map this is interesting very very聽 interesting now let's move further and discuss the聽聽
[312]
second option that was the weather option so the聽 second option the it's called the weather option聽聽
[319]
is also very exciting it displays a random聽 location that excites users to click on the change聽聽
[327]
my location button upon clicking it asks for聽 permission hence it gathers the actual location聽聽
[335]
anyway so the working structure is similar now聽 let's move further and see the webcam option聽聽
[341]
as well so let's access the webcam number聽 one perfect it presents three templates聽聽
[349]
the default is handy to capture desktop or laptop聽 webcam however for mobile use the second option聽聽
[356]
rather than sending this ngrok url i suggest using聽 any link shortener such as bitly to shorten this聽聽
[364]
particular url and for a more sophisticated attack聽 buy a domain host a genuine website and either use聽聽
[372]
redirector or dns to land users on this url a聽 lot of things can be done you should use your聽聽
[380]
social engineering and technical skills as聽 well now let's quickly see this webcam feature聽聽
[386]
on a mobile device rather than testing it on the聽 desktop i have i've tested it on a desktop as well聽聽
[392]
it's working perfectly but now i'm demonstrating聽 this second option the mobile camera let's select聽聽
[399]
number two as discussed earlier you just need聽 to copy this particular url and send it to your聽聽
[405]
target and once you target open this url it聽 opens uh on a on a browser on a web browser聽聽
[411]
and it gives you the access to the particular聽 webcam now let's see this so i've sent this聽聽
[418]
particular url on a mobile now i'm opening聽 it wow perfect so we are getting images now聽聽
[424]
and the images uh it automatically plays聽 all the images all the capture images聽聽
[429]
in the images directory or folder which is inside聽 this particular tool so there you can see that聽聽
[435]
it is it captures the images in in after after a聽 certain interval or after a certain period of time聽聽
[442]
so it captures a lot of information as long as聽 the session is established so in order to check聽聽
[448]
the images what you can do you can just simply go聽 to this particular directory and cross check it聽聽
[453]
for for example let me do this so cd storm breaker聽 and then if you see open in the webcam directory聽聽
[467]
webcam directory if you see and let's get聽 into the images and there you can see that聽聽
[474]
it has it has captured all these image images聽 and it is continuously capturing the images聽聽
[481]
so there you can see that it has a captured one聽 two three four five six images so far and still聽聽
[488]
capturing the images and there you can see the聽 two two four and five and six images as well聽聽
[494]
well perfect so yep one more image captured聽 so if if i just cross check again so there聽聽
[501]
you can see that the image count increasing聽 i'm not opening it although i can open it聽聽
[507]
you can just go to the directory and you聽 can open it you can see the images as well聽聽
[512]
and it is it is you know continuously capturing聽 the images so let me just stop it at the moment聽聽
[518]
uh the purpose has been served we have discussed聽 it so i have demonstrated few things you can聽聽
[524]
grab windows password access microphone etc etc聽 anyway that is it see you next time take care bye