Video summary
7 websites that feel illegal...
Main summary
Key takeaways
Summary of technological concepts & key features (7 “possibly illegal” but actually legal sites)
The video argues that these services aren’t inherently illegal; instead, they make already-public exposure on the internet easy to search, aggregate, and visualize.
7) Wigle (Wireless geographic logging)
- A global map of Wi‑Fi networks collected over ~20 years by volunteers using a phone app (wardriving).
- Visual layout
- Yellow pixels = dense/saturated Wi‑Fi areas
- Purple fringes = less dense rural/suburban coverage
- Blue dots over oceans = often ships/ferries captured during travel
- Search/filter capabilities
- Search by SSID (network name) and BSSID (unique router hardware/MAC address)
- Filter by date range
- Filter by likelihood/type (e.g., public/free vs commercial-looking access points)
- Scale/coverage
- Claims 1.5B+ indexed networks and data growth since 2001
- Security/privacy implication highlighted
- Typing a home SSID may reveal it on the public map, implying someone walking by could have recorded approximate location data.
6) VirusTotal (file/URL scanning across many engines)
- Lets users upload files or paste URLs for instant scanning.
- Runs analysis against:
- 70+ antivirus engines
- multiple sandbox analyzers
- Example described
- Uploading a suspicious Windows executable leads to many vendors flagging it as malicious (including references to reverse shell/malware family style detections).
- How results are interpreted
- Shows community score, file hash (unique fingerprint), and vendor-specific verdicts
- Emphasizes multi-engine scanning because no single AV catches everything
- Product positioning
- Owned by Google; described as free
5) Wayback Machine (internet archiving)
- Archived web pages: 1 trillion+ pages.
- Focuses on “deleted content isn’t always gone”:
- captures pages people believed removed
- archives political statements/old posts and historical web states
- Example: Myspace
- Shows over 1,052,843 snapshots from 1996 to present
- Uses charts:
- histogram by year (capture frequency)
- daily dots where clicks show multiple timestamps
- Tutorial-like takeaway
- Demonstrates restoring the exact page state at a specific timestamp.
4) Have I Been Pwned (breach lookup by email)
- A site by Troy Hunt to check whether an email appears in known data breaches.
- Index scale
- nearly 17B accounts
- adds new breaches within hours of leaks appearing
- handles 18B+ password lookups per month
- What the user sees
- breach count and a chronological timeline with breach details
- Example described
- An email shows 161 breaches, including a loyalty-program leak (ShinyHunters/cruise operator example)
- Key concept
- Bulk breach aggregation makes exposure visible across many incidents.
3) OSINT Industries (account discovery from identifiers)
- Accepts email addresses, phone numbers, or usernames.
- Returns a mapping of every online account associated with those identifiers—not just mainstream services.
- Example platforms mentioned: Instagram, Facebook, LinkedIn, Strava, Cash App, Airbnb, Adobe, Spotify, plus older forgotten profiles/apps.
- Intended audience
- used by 5,000+ law enforcement agencies worldwide
- no free tier; subscription-based for professionals
- Main concept
- OSINT aggregation correlates identifiers to account footprints.
2) Insecam (public IP camera indexing)
- Aggregates publicly accessible IP cameras whose owners supposedly left them unsecured (no password).
- Live/stream emphasis
- site shows a grid of thumbnails, refreshing every few seconds
- timestamps are presented as real-time (not stored recordings)
- Search functionality
- filter by manufacturer (e.g., Bosch) → shows cameras using a default/unchanged credential across multiple countries
- filter by country (e.g., Germany) → shows multiple camera sources in the same region
- Highlighted risk
- It’s framed as legal to list feeds if broadcast openly without authentication, but the existence/visibility is “deeply wrong” and acts as a reminder to secure devices.
1) Shodan (search engine for internet-connected devices)
- A search engine for internet-connected devices (routers, servers, webcams, IoT, industrial control systems, etc.).
- Core mechanism
- crawls the IPv4 address space port-by-port
- records device “banner” messages (greeting strings) and makes them searchable
- Example: SSH scanning
- query for port 22 (SSH)
- results show device counts by country (US/China/Germany) and individual machines with:
- IP, location, software banner/version, cryptographic key fingerprints
- notes “exceeded max startups” indicating scanners hitting connection limits
- Broader capabilities
- searches other protocols: Telnet, FTP, RTSP, industrial protocols like Modbus, MongoDB, etc.
- supports complex filtering (city, org, OS), with references to filters/explore pages
- Key idea
- Makes exposed services and version information quickly discoverable—useful for defenders and also for attackers if misused.
Safety/ethics rules mentioned by the video
- Don’t log into anything you find (even with default credentials).
- Don’t access systems that aren’t yours (viewing banners is framed as legal; interacting is not).
- “Just look, learn, then patch your own stuff.”
Main speakers / sources (from the subtitles)
- Troy Hunt (founder/creator of Have I Been Pwned)
- Google (ownership mentioned for VirusTotal)