Tried breaking into windows 10 yesterday and I'm impressed

Jason Voorhees

Jason Voorhees

Say cheese
Joined
May 15, 2020
Posts
79,912
Reputation
233,368
As you nighas know I’ve been dipping my feet into cybersec for a few days.


So yesterday I decided to set up an isolated test lab in Oracle VirtualBox and spun up a Windows 10 retail ISO image to do some authorized testing but even with aggressive scans and deep fingerprinting I couldn’t find shit. 0 vulnerabilities

1000114341
IMG 20251106 112631


Nmap TCP/UDP sweeps, vulnerability scanners and web fuzzing against services you name it and it all just returned noise.

I swapped the guest to a Windows 10 Insider (beta) build and things finally opened up but not in the easy CTF way I expected. The behavior I found was a mess. Fragile chains, timing sensitive race conditions, and misconfigurations that only show up under certain driver states. I used packet captures and found weird kernel mode driver failures also with noisy Windows Defender/IDS alerts and a thicket of mitigation technologies ASLR, DEP, UAC prompts, Credential Guard all fighting me at once and at the same time.


In plain English it wasn't like a simple hole in the wall that I could just punch through and bulldoze inside like I was used to. It was more like a fortress with tiny invisible cracks and trying to pick locks while the door and locks kept changing shape and location. Every time thought I had a weak spot. Windows moved the goalpost


IMG 20251106 112658
IMG 20251106 112710


The exploit paths weren’t one shot easy exploits. They required careful carefully crafted payloads. Every test run triggered alerts Windows Event Viewer spiked with Process Creation and AppLocker hits and the IDS flagged all the suspicious flows. I probably set off a hundred alarms across.At this point I was so deep I stopped noticing time.

My girlfriend walked in saw me clenching my fists over a frozen terminal, and laughed why are you so angry at random pixels? She told me come let's go out to have some ice cream and tried to drag me away I told her I wasn’t leaving the chair until I finished. She sighed and said ah so its one of those days where you turn into a lunatic satisfying your ego. All right good luck and left me to it.

IMG 20251106 112645


Every time I tried to do something even minor Windows Defender + Event Viewer + AppLocker would collectively come in to rape me and fuck everything up ruining all progress. Five hours of digging, iterating, and re imaging and scouring the internet to find known exploits and workarounds later replaying packet sequences individually and using logs from Procmon and Wireshark I finally saw the behavior I wanted and started dismantling it and finally managed to disable the windows defender firewall proof above and got elevated shell like response and a clean set of artifacts in the logs that proved the chain had worked. Literally hours of wrestling with the defenses, insane frustration, hundreds of alarms all for a small, fragile minor win. Nigga I finna cry. Fucking hell. I'm going to sleep and won't touch my computer for a few hours. Fuck this shit.

Sadness joker



What I learned: Modern Windows is a fortress of layered defenses that turns exploitation into a grueling marathon of plumbing logs correlating events.

As an amateur I came away humbled. Even after knowing about the exploits and Internet helping me all throughout it was nightmare to do it. Windows security and constant updates that it asks are isn't the pain in the ass they are designed to be extremely robust and resilient. It makes attackers fight tooth and nail for every inch. The real weakest link. Isn't the system security. Microsoft has built a beast of a setup it's your dumbass that clicks on random shit that makes it vulnerable not the Operating System.
 
Last edited:
  • +1
  • Woah
  • JFL
Reactions: avenox, Menas, 2022cel and 35 others
@BigBallsLarry @Swarthy Knight @JohnDoe @savage21
 
  • +1
Reactions: Menas, Deleted member 78797, Leo and 7 others
@DBDR @takethewhitepill @greycel @59H390
 
  • +1
Reactions: Menas, Deleted member 78797, greycel and 7 others
@Glorious King @Shahnamehgymmaxx @Mogsgymmaxx
 
  • +1
Reactions: Menas, Deleted member 78797, Leo and 6 others
Keep it up! I believe in you :geek:

 
  • +1
  • Love it
  • Woah
Reactions: Menas, Leo, Insomnia and 6 others
I aspire to become this knowledgeable
 
  • +1
Reactions: MiserableMan, Incelforeever, qxdr and 7 others
i bet 100$ @Mogsgymmaxx didn't understand shit
 
  • JFL
  • +1
Reactions: lmo1, MiserableMan, Incelforeever and 11 others
My girlfriend walked in saw me clenching my fists over a frozen terminal, and laughed why are you so angry at random pixels? She told me come let's go out to have some ice cream and tried to drag me away I told her I wasn’t leaving the chair until I finished. She sighed and said ah so its one of those days where you turn into a lunatic satisfying your ego.
:feelsahh::feelsahh::feelsahh::feelsahh::feelsahh:

Jokes aside, mirin the dedication to sit there for 5+ hours and hack away at this. Also yeah I kind of would’ve thought a multi billion dollar corporation would have insane security standards in place :feelskek:.
 
  • +1
Reactions: MiserableMan, Leo, Insomnia and 3 others
  • +1
  • JFL
Reactions: MiserableMan, Incelforeever, Leo and 7 others
I'm too retarded to know about this stuff. But are you saying Windows 10 is good or bad :feelsahh:
 
  • +1
Reactions: MiserableMan, Incelforeever, Leo and 8 others
  • JFL
  • +1
Reactions: MiserableMan, Incelforeever, Leo and 6 others
I'm too retarded to know about this stuff. But are you saying Windows 10 is good or bad :feelsahh:
Very very good. If you don't act retarded you are basically invincible and safe from all kinds of hackers
 
  • +1
  • Woah
  • JFL
Reactions: MiserableMan, Incelforeever, Leo and 5 others
  • +1
  • JFL
  • Love it
Reactions: Tigermoggerlol, Leo, Insomnia and 2 others
Very very good. If you don't act retarded you are basically invincible and safe from all kinds of hackers
Oh that's interesting. My mom was nagging me to upgrade her windows 10 to 11 because apparently she got a message saying it's gonna be discontinued or sumshit
 
  • +1
Reactions: Incelforeever, Leo, Chadeep and 3 others
As you nighas know I’ve been dipping my feet into cybersec for a few days.


So yesterday I decided to set up an isolated test lab in Oracle VirtualBox and spun up a Windows 10 retail ISO image to do some authorized testing but even with aggressive scans and deep fingerprinting I couldn’t find shit. 0 vulnerabilities

View attachment 4293873View attachment 4293890

Nmap TCP/UDP sweeps, vulnerability scanners and web fuzzing against services you name it and it all just returned noise.

I swapped the guest to a Windows 10 Insider (beta) build and things finally opened up but not in the easy CTF way I expected. The behavior I found was a mess. Fragile chains, timing sensitive race conditions, and misconfigurations that only show up under certain driver states. I used packet captures and found weird kernel mode driver failures also with noisy Windows Defender/IDS alerts and a thicket of mitigation technologies ASLR, DEP, UAC prompts, Credential Guard all fighting me at once and at the same time.


In plain English it wasn't like a simple hole in the wall that I could just punch through and bulldoze inside like I was used to. It was more like a fortress with tiny invisible cracks and trying to pick locks while the door and locks kept changing shape and location. Every time thought I had a weak spot. Windows moved the goalpost


View attachment 4293882View attachment 4293876

The exploit paths weren’t one shot easy exploits. They required careful carefully crafted payloads. Every test run triggered alerts Windows Event Viewer spiked with Process Creation and AppLocker hits and the IDS flagged all the suspicious flows. I probably set off a hundred alarms across.At this point I was so deep I stopped noticing time.

My girlfriend walked in saw me clenching my fists over a frozen terminal, and laughed why are you so angry at random pixels? She told me come let's go out to have some ice cream and tried to drag me away I told her I wasn’t leaving the chair until I finished. She sighed and said ah so its one of those days where you turn into a lunatic satisfying your ego. All right good luck and left me to it.

View attachment 4293884

Five hours of digging, iterating, and re imaging later replaying packet sequences individually and using logs from Procmon and Wireshark I finally saw the behavior I wanted and started dismantling it. I had bypassed the windows firewall proof above and got elevated shell like response and a clean set of artifacts in the logs that proved the chain had worked. Literally hours of wrestling with the defenses, insane frustration, hundreds of alarms all for a small, fragile minor win. Fucking hell. I'm going to sleep and won't touch my computer for a few hours. Fuck this shit.

View attachment 4293910


What I learned: Modern Windows is a fortress of layered defenses that turns exploitation into a grueling marathon of plumbing logs correlating events.

As an amateur I came away humbled. Windows security and constant updates that it asks are isn't the pain in the ass they are designed to be extremely robust and resilient. It makes attackers fight tooth and nail for every inch. The real weakest link. Isn't the system security. Microsoft has built a beast of a setup it's your dumbass that clicks on random shit that makes it vulnerable not the Operating System.
Dont call me oke?
 
  • +1
Reactions: Leo, Insomnia and Jason Voorhees
  • +1
  • JFL
Reactions: Leo, Insomnia, Jason Voorhees and 2 others
Yeah, this is why I always am stupified when I see people paying for shitty defence services like norton when windows itself is the steongest thing you can use. Watching people bring me a laptop that runs shit because maxed out memory from norton and ask me to fix it is crazy cagefuel. But what is this talk of your girlfriend? Not so sure on that one, its either software or foids and you made your bed
 
  • +1
Reactions: Incelforeever, Leo, Chadeep and 3 others
You should record it an post a Timelapse. It would be interesting to see a part of the process
 
  • +1
Reactions: Incelforeever, Leo, Chadeep and 2 others
Screenshot 2025 11 05 223524

mirin tho ngl

I thought it was 100% over for every user with thousands of posts
 
Last edited:
  • +1
Reactions: 2022cel, Incelforeever, Leo and 1 other person
Yeah, this is why I always am stupified when I see people paying for shitty defence services like norton when windows itself is the steongest thing you can use. Watching people bring me a laptop that runs shit because maxed out memory from norton and ask me to fix it is crazy cagefuel. But what is this talk of your girlfriend? Not so sure on that one, its either software or foids and you made your bed
Sometimes when I get into something I become completely obsessed I don’t quit halfway If I start a task I either give it everything I’ve got or I don’t do it at all. My family always jokes and worries that that kind of intensity will make me burn out or even fall ill. I've pulled off all nighters to finish my work sometimes.
 
  • +1
Reactions: takethewhitepill, Incelforeever and Leo
  • +1
  • Woah
Reactions: takethewhitepill, Incelforeever, Leo and 1 other person
@Nodesbitch @wishIwasSalludon @Imaloser7754
 
  • +1
Reactions: Nodesbitch
@Leo @4ever @Debetro @LXR
 
  • +1
Reactions: 4ever, Leo and LXR
As you nighas know I’ve been dipping my feet into cybersec for a few days.


So yesterday I decided to set up an isolated test lab in Oracle VirtualBox and spun up a Windows 10 retail ISO image to do some authorized testing but even with aggressive scans and deep fingerprinting I couldn’t find shit. 0 vulnerabilities

View attachment 4293873View attachment 4293890

Nmap TCP/UDP sweeps, vulnerability scanners and web fuzzing against services you name it and it all just returned noise.

I swapped the guest to a Windows 10 Insider (beta) build and things finally opened up but not in the easy CTF way I expected. The behavior I found was a mess. Fragile chains, timing sensitive race conditions, and misconfigurations that only show up under certain driver states. I used packet captures and found weird kernel mode driver failures also with noisy Windows Defender/IDS alerts and a thicket of mitigation technologies ASLR, DEP, UAC prompts, Credential Guard all fighting me at once and at the same time.


In plain English it wasn't like a simple hole in the wall that I could just punch through and bulldoze inside like I was used to. It was more like a fortress with tiny invisible cracks and trying to pick locks while the door and locks kept changing shape and location. Every time thought I had a weak spot. Windows moved the goalpost


View attachment 4293882View attachment 4293876

The exploit paths weren’t one shot easy exploits. They required careful carefully crafted payloads. Every test run triggered alerts Windows Event Viewer spiked with Process Creation and AppLocker hits and the IDS flagged all the suspicious flows. I probably set off a hundred alarms across.At this point I was so deep I stopped noticing time.

My girlfriend walked in saw me clenching my fists over a frozen terminal, and laughed why are you so angry at random pixels? She told me come let's go out to have some ice cream and tried to drag me away I told her I wasn’t leaving the chair until I finished. She sighed and said ah so its one of those days where you turn into a lunatic satisfying your ego. All right good luck and left me to it.

View attachment 4293884

Five hours of digging, iterating, and re imaging later replaying packet sequences individually and using logs from Procmon and Wireshark I finally saw the behavior I wanted and started dismantling it. I had bypassed the windows firewall proof above and got elevated shell like response and a clean set of artifacts in the logs that proved the chain had worked. Literally hours of wrestling with the defenses, insane frustration, hundreds of alarms all for a small, fragile minor win. Nigga I finna cry. Fucking hell. I'm going to sleep and won't touch my computer for a few hours. Fuck this shit.

View attachment 4293910


What I learned: Modern Windows is a fortress of layered defenses that turns exploitation into a grueling marathon of plumbing logs correlating events.

As an amateur I came away humbled. Windows security and constant updates that it asks are isn't the pain in the ass they are designed to be extremely robust and resilient. It makes attackers fight tooth and nail for every inch. The real weakest link. Isn't the system security. Microsoft has built a beast of a setup it's your dumbass that clicks on random shit that makes it vulnerable not the Operating System.
Don't fret, you'll get better once you go deeper. Luckily for you, Windows has a ton of exploits even today compared to BSD so you can look them up
 
  • +1
Reactions: Jason Voorhees
Linus tech tips was hacked because of a pdf sent to them. Hackers use exploits like these days.
 
  • +1
  • JFL
Reactions: LXR and Jason Voorhees
Humbled me and made me feel retarded, this sound super hard:dafuckfeels:
 
  • +1
Reactions: Incelforeever and Jason Voorhees
Humbled me and made me feel retarded, this sound super hard:dafuckfeels:
What I did is hard and quite frustrating but finding exploits and taking advantage of them to gain access using legacy(older) software is easy. Just download old Mozilla Firefox or VLC. Run scans and exploit. It is a lot of fun but ofc in the real world. You'll get something like what I did in OP and not have all it handed to you like a game
 
  • +1
Reactions: Leo
1762412691420
 
  • +1
Reactions: GoErOnFoids and Jason Voorhees
My girlfriend walked in saw me clenching my fists over a frozen terminal, and laughed why are you so angry at random pixels? She told me come let's go out to have some ice cream and tried to drag me away I told her I wasn’t leaving the chair until I finished. She sighed and said ah so its one of those days where you turn into a lunatic satisfying your ego. All right good luck and left me to it.
this was very cute :Comfy: read every particle, I'm glad you had your fun jason.

you should try something like this with MacOS
 
  • +1
Reactions: GoErOnFoids, Incelforeever and Jason Voorhees
how are we sending messages in the future
1762412727175
 
  • +1
Reactions: GoErOnFoids and Jason Voorhees


@Leo if you are interested I'd start from this video
 
  • +1
Reactions: Leo
@Leo

 
  • +1
Reactions: Leo
As you nighas know I’ve been dipping my feet into cybersec for a few days.


So yesterday I decided to set up an isolated test lab in Oracle VirtualBox and spun up a Windows 10 retail ISO image to do some authorized testing but even with aggressive scans and deep fingerprinting I couldn’t find shit. 0 vulnerabilities

View attachment 4293873View attachment 4293890

Nmap TCP/UDP sweeps, vulnerability scanners and web fuzzing against services you name it and it all just returned noise.

I swapped the guest to a Windows 10 Insider (beta) build and things finally opened up but not in the easy CTF way I expected. The behavior I found was a mess. Fragile chains, timing sensitive race conditions, and misconfigurations that only show up under certain driver states. I used packet captures and found weird kernel mode driver failures also with noisy Windows Defender/IDS alerts and a thicket of mitigation technologies ASLR, DEP, UAC prompts, Credential Guard all fighting me at once and at the same time.


In plain English it wasn't like a simple hole in the wall that I could just punch through and bulldoze inside like I was used to. It was more like a fortress with tiny invisible cracks and trying to pick locks while the door and locks kept changing shape and location. Every time thought I had a weak spot. Windows moved the goalpost


View attachment 4293882View attachment 4293876

The exploit paths weren’t one shot easy exploits. They required careful carefully crafted payloads. Every test run triggered alerts Windows Event Viewer spiked with Process Creation and AppLocker hits and the IDS flagged all the suspicious flows. I probably set off a hundred alarms across.At this point I was so deep I stopped noticing time.

My girlfriend walked in saw me clenching my fists over a frozen terminal, and laughed why are you so angry at random pixels? She told me come let's go out to have some ice cream and tried to drag me away I told her I wasn’t leaving the chair until I finished. She sighed and said ah so its one of those days where you turn into a lunatic satisfying your ego. All right good luck and left me to it.

View attachment 4293884

Five hours of digging, iterating, and re imaging later replaying packet sequences individually and using logs from Procmon and Wireshark I finally saw the behavior I wanted and started dismantling it. I had bypassed the windows firewall proof above and got elevated shell like response and a clean set of artifacts in the logs that proved the chain had worked. Literally hours of wrestling with the defenses, insane frustration, hundreds of alarms all for a small, fragile minor win. Nigga I finna cry. Fucking hell. I'm going to sleep and won't touch my computer for a few hours. Fuck this shit.

View attachment 4293910


What I learned: Modern Windows is a fortress of layered defenses that turns exploitation into a grueling marathon of plumbing logs correlating events.

As an amateur I came away humbled. Windows security and constant updates that it asks are isn't the pain in the ass they are designed to be extremely robust and resilient. It makes attackers fight tooth and nail for every inch. The real weakest link. Isn't the system security. Microsoft has built a beast of a setup it's your dumbass that clicks on random shit that makes it vulnerable not the Operating System.
crack denuvo
 
  • +1
Reactions: Jason Voorhees


@Leo if you are interested I'd start from this video

Bookmarked, if i have extra time in the weekend then i will 100% look into it! Thanks for sharing:feelsautistic:
 
  • +1
Reactions: Jason Voorhees
@JohnDoe @CorinthianLOX @sub5outsider @browncurrycel @aladdinmaxxer
 
  • +1
Reactions: browncurrycel and CorinthianLOX
JSON Voorhees
 
  • Love it
Reactions: Jason Voorhees
That's why all these "firewalls" that boomers pay to this day "annual promo, only 39$", expensive anti-viruses are freaking bullshit, when windows itself (macOS even better) is hard to infiltrate
matrix cinematography GIF
 
  • +1
Reactions: Jason Voorhees
As you nighas know I’ve been dipping my feet into cybersec for a few days.


So yesterday I decided to set up an isolated test lab in Oracle VirtualBox and spun up a Windows 10 retail ISO image to do some authorized testing but even with aggressive scans and deep fingerprinting I couldn’t find shit. 0 vulnerabilities

View attachment 4293873View attachment 4293890

Nmap TCP/UDP sweeps, vulnerability scanners and web fuzzing against services you name it and it all just returned noise.

I swapped the guest to a Windows 10 Insider (beta) build and things finally opened up but not in the easy CTF way I expected. The behavior I found was a mess. Fragile chains, timing sensitive race conditions, and misconfigurations that only show up under certain driver states. I used packet captures and found weird kernel mode driver failures also with noisy Windows Defender/IDS alerts and a thicket of mitigation technologies ASLR, DEP, UAC prompts, Credential Guard all fighting me at once and at the same time.


In plain English it wasn't like a simple hole in the wall that I could just punch through and bulldoze inside like I was used to. It was more like a fortress with tiny invisible cracks and trying to pick locks while the door and locks kept changing shape and location. Every time thought I had a weak spot. Windows moved the goalpost


View attachment 4293882View attachment 4293876

The exploit paths weren’t one shot easy exploits. They required careful carefully crafted payloads. Every test run triggered alerts Windows Event Viewer spiked with Process Creation and AppLocker hits and the IDS flagged all the suspicious flows. I probably set off a hundred alarms across.At this point I was so deep I stopped noticing time.

My girlfriend walked in saw me clenching my fists over a frozen terminal, and laughed why are you so angry at random pixels? She told me come let's go out to have some ice cream and tried to drag me away I told her I wasn’t leaving the chair until I finished. She sighed and said ah so its one of those days where you turn into a lunatic satisfying your ego. All right good luck and left me to it.

View attachment 4293884

Every time I tried to do something even minor Windows Defender + Event Viewer + AppLocker would collectively come in to rape me and fuck everything up ruining all progress. Five hours of digging, iterating, and re imaging and scouring the internet to find known exploits and workarounds later replaying packet sequences individually and using logs from Procmon and Wireshark I finally saw the behavior I wanted and started dismantling it and finally managed to disable the windows defender firewall proof above and got elevated shell like response and a clean set of artifacts in the logs that proved the chain had worked. Literally hours of wrestling with the defenses, insane frustration, hundreds of alarms all for a small, fragile minor win. Nigga I finna cry. Fucking hell. I'm going to sleep and won't touch my computer for a few hours. Fuck this shit.

View attachment 4293910


What I learned: Modern Windows is a fortress of layered defenses that turns exploitation into a grueling marathon of plumbing logs correlating events.

As an amateur I came away humbled. Even after knowing about the exploits and Internet helping me all throughout it was nightmare to do it. Windows security and constant updates that it asks are isn't the pain in the ass they are designed to be extremely robust and resilient. It makes attackers fight tooth and nail for every inch. The real weakest link. Isn't the system security. Microsoft has built a beast of a setup it's your dumbass that clicks on random shit that makes it vulnerable not the Operating System.
Isn't this water? Is the most used operation system in the world :forcedsmile:
 
  • +1
Reactions: Jason Voorhees
Isn't this water? Is the most used operation system in the world :forcedsmile:
It should be. I feel you don't even need an anti virus or whatever. Wimdows defender is already s tier
 
  • +1
Reactions: childishkillah

Similar threads

frentanyl
Replies
14
Views
1K
Bölþorn.Anabolic
Bölþorn.Anabolic
ltn dreams
Replies
5
Views
394
thekey
thekey
brownboy2006
Replies
48
Views
1K
Galvatron
Galvatron
Nodesbitch
Replies
30
Views
2K
aabb123
aabb123

Users who are viewing this thread

Back
Top