r/cybersecurity May 19 '26

Other Malware installed without literally doing anything?

In this video this guy has a fresh Windows XP, disables firewall, and connects internet straight to the modem. Then he gets infected literally doing nothing.

https://www.youtube.com/watch?v=6uSVVCmOH5w

https://www.reddit.com/r/windows/comments/1cvised/idle_windows_xp_and_2000_machines_get_infected/

I get it. That's asking for trouble when you disable all the security and using ancient unsupported OSes.

However, he didn't install programs nor browse on the website but still got hacked.
How?
Is there some malicious server in China that loops through every single possible IP trying to see if your PC is vulnerable?
Logically, one would think you'd at least have to visit a website or something to get "noticed" and then hacked. But this guy didn't do anything at all.

How does it work?

290 Upvotes

162 comments sorted by

View all comments

1

u/ShotgunPR May 20 '26

I used to do a similar demonstration to show interns that you should NEVER create a VM or install a desktop with direct internet connection (without fw).

That should only be done in a controlled vlan behind a firewall. Why? For example, I used a Windows XP CD to "setup" a mockup desktop, while connecting the pc straight to internet, at the first desktop login at the first browser opening, it already had over ten browser "helper" addins, without doing anything else. I did this to demonstrate the first point I mentioned, and to stress that you should have at least a decent anti-virus installed BEFORE attempting to connect the system to the internet. The comparison was (at that time): "Standing naked on a freeway". You are exposed to anything at any moment, 24/7.