Video summary

7 websites that feel illegal...

Main summary

Key takeaways

Technology

Summary of technological concepts & key features (7 “possibly illegal” but actually legal sites)

The video argues that these services aren’t inherently illegal; instead, they make already-public exposure on the internet easy to search, aggregate, and visualize.


7) Wigle (Wireless geographic logging)

  • A global map of Wi‑Fi networks collected over ~20 years by volunteers using a phone app (wardriving).
  • Visual layout
    • Yellow pixels = dense/saturated Wi‑Fi areas
    • Purple fringes = less dense rural/suburban coverage
    • Blue dots over oceans = often ships/ferries captured during travel
  • Search/filter capabilities
    • Search by SSID (network name) and BSSID (unique router hardware/MAC address)
    • Filter by date range
    • Filter by likelihood/type (e.g., public/free vs commercial-looking access points)
  • Scale/coverage
    • Claims 1.5B+ indexed networks and data growth since 2001
  • Security/privacy implication highlighted
    • Typing a home SSID may reveal it on the public map, implying someone walking by could have recorded approximate location data.

6) VirusTotal (file/URL scanning across many engines)

  • Lets users upload files or paste URLs for instant scanning.
  • Runs analysis against:
    • 70+ antivirus engines
    • multiple sandbox analyzers
  • Example described
    • Uploading a suspicious Windows executable leads to many vendors flagging it as malicious (including references to reverse shell/malware family style detections).
  • How results are interpreted
    • Shows community score, file hash (unique fingerprint), and vendor-specific verdicts
    • Emphasizes multi-engine scanning because no single AV catches everything
  • Product positioning
    • Owned by Google; described as free

5) Wayback Machine (internet archiving)

  • Archived web pages: 1 trillion+ pages.
  • Focuses on “deleted content isn’t always gone”:
    • captures pages people believed removed
    • archives political statements/old posts and historical web states
  • Example: Myspace
    • Shows over 1,052,843 snapshots from 1996 to present
    • Uses charts:
      • histogram by year (capture frequency)
      • daily dots where clicks show multiple timestamps
  • Tutorial-like takeaway
    • Demonstrates restoring the exact page state at a specific timestamp.

4) Have I Been Pwned (breach lookup by email)

  • A site by Troy Hunt to check whether an email appears in known data breaches.
  • Index scale
    • nearly 17B accounts
    • adds new breaches within hours of leaks appearing
    • handles 18B+ password lookups per month
  • What the user sees
    • breach count and a chronological timeline with breach details
  • Example described
    • An email shows 161 breaches, including a loyalty-program leak (ShinyHunters/cruise operator example)
  • Key concept
    • Bulk breach aggregation makes exposure visible across many incidents.

3) OSINT Industries (account discovery from identifiers)

  • Accepts email addresses, phone numbers, or usernames.
  • Returns a mapping of every online account associated with those identifiers—not just mainstream services.
    • Example platforms mentioned: Instagram, Facebook, LinkedIn, Strava, Cash App, Airbnb, Adobe, Spotify, plus older forgotten profiles/apps.
  • Intended audience
    • used by 5,000+ law enforcement agencies worldwide
    • no free tier; subscription-based for professionals
  • Main concept
    • OSINT aggregation correlates identifiers to account footprints.

2) Insecam (public IP camera indexing)

  • Aggregates publicly accessible IP cameras whose owners supposedly left them unsecured (no password).
  • Live/stream emphasis
    • site shows a grid of thumbnails, refreshing every few seconds
    • timestamps are presented as real-time (not stored recordings)
  • Search functionality
    • filter by manufacturer (e.g., Bosch) → shows cameras using a default/unchanged credential across multiple countries
    • filter by country (e.g., Germany) → shows multiple camera sources in the same region
  • Highlighted risk
    • It’s framed as legal to list feeds if broadcast openly without authentication, but the existence/visibility is “deeply wrong” and acts as a reminder to secure devices.

1) Shodan (search engine for internet-connected devices)

  • A search engine for internet-connected devices (routers, servers, webcams, IoT, industrial control systems, etc.).
  • Core mechanism
    • crawls the IPv4 address space port-by-port
    • records device “banner” messages (greeting strings) and makes them searchable
  • Example: SSH scanning
    • query for port 22 (SSH)
    • results show device counts by country (US/China/Germany) and individual machines with:
      • IP, location, software banner/version, cryptographic key fingerprints
    • notes “exceeded max startups” indicating scanners hitting connection limits
  • Broader capabilities
    • searches other protocols: Telnet, FTP, RTSP, industrial protocols like Modbus, MongoDB, etc.
    • supports complex filtering (city, org, OS), with references to filters/explore pages
  • Key idea
    • Makes exposed services and version information quickly discoverable—useful for defenders and also for attackers if misused.

Safety/ethics rules mentioned by the video

  • Don’t log into anything you find (even with default credentials).
  • Don’t access systems that aren’t yours (viewing banners is framed as legal; interacting is not).
  • “Just look, learn, then patch your own stuff.”

Main speakers / sources (from the subtitles)

  • Troy Hunt (founder/creator of Have I Been Pwned)
  • Google (ownership mentioned for VirusTotal)

Original video