Linus Gabriel Sebastian & Linus Media Group / Linus Tech Tips - Narcissistic corporate shill YouTuber driving his media empire into the ground. KILL COUNT: 2

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.
Wait you can do that shit with a .pdf?
Depends. PDF's have support for embedded javascript (for some fucking reason, god knows why), and it's used sometimes to enable embedding of 3D models into PDF files, but the functionality is basically only available on Acrobat Reader, none of the other PDF viewers support it, I'm pretty sure it's not part of the PDF specification. Of course, basically any file format can be a vector, but it normally requires that the software reading the file is flawed in some way, and executes part of the file instead of just reading it.
 
Yes, but a business person doesn't need access to upload and delete videos. If Linus only gave people the permissions they need to do their jobs, this wouldn't have happened.
In my company a 'business person' doesn't need to run any .exe file that I didn't whitelist in AppLocker. That person doesn't even need any E-Mail attachments except maybe .pdf but even that is stretching it.
Those people are the worst retards and should be on their own zoned off VLAN using filtered kiddie-proof Internet.
 
2 pages and 9 hours yet no one archived, shame on you Kiwis.


It's kind of horrific to have the inside of your house covered in cameras like this. It's also horrific that he walks around naked even knowing those cameras are there.
Lemme 1up you with a compilation of Naked Linus clips and a full archive in a lower res.

 
Been noticing this happening more and more lately. Gotta wonder what's happening at YouTube that the exact same bad actors seem to breaching multiple accounts over the course of several months
It unlikely it's the "same actor". Given the scammer seems to be indian, it's probably the case that there's a bunch of pajeets siloed into an office somewhere as part of a front company, sending out as many phishing emails to targets as possible. Once they get in, they'll do the same thing, there'll be a list of instructions or something. There's no mastermind hacker behind these, just some pajeet with a checklist.
 
It unlikely it's the "same actor". Given the scammer seems to be indian, it's probably the case that there's a bunch of pajeets siloed into an office somewhere as part of a front company, sending out as many phishing emails to targets as possible. Once they get in, they'll do the same thing, there'll be a list of instructions or something. There's no mastermind hacker behind these, just some pajeet with a checklist.
Basically an Indian version of Linus’s company heh
 
It unlikely it's the "same actor". Given the scammer seems to be indian, it's probably the case that there's a bunch of pajeets siloed into an office somewhere as part of a front company, sending out as many phishing emails to targets as possible. Once they get in, they'll do the same thing, there'll be a list of instructions or something. There's no mastermind hacker behind these, just some pajeet with a checklist.
I would consider a business entity built around these actions to be "the exact same bad actors"
 
That's called caller ID you stupid zoomer.
Nope.
No, it's not:
Correct.

Trusted companies can send a text message with a name instead of a number attached to it. They are trusted on a telco basis. A shady or compromised telco can let someone else do the same thing. This means that someone can send a text message that goes straight into your text message chain from Paypal or UPS or Amazon or whatever. I actually got one of those the other day, shady link and all(think of something like www.service-paypal.com)
 
  • Informative
Reactions: Cowboy Kim
Yes, but a business person doesn't need access to upload and delete videos. If Linus only gave people the permissions they need to do their jobs, this wouldn't have happened.
I could see that when he was a small company he had it set up so everyone had total access and then just never bothered to change it as the channel grew. I ran a gaming discord that exploded from a few dozen to a few hundred people overnight and learned the hard way that with a small group you trust, roles and permissions don't really matter but when it expands to friends of friends and friends of their friends, someone will inevitably succumb to temptation and take advantage for the lulz.
 
  • Like
Reactions: Smar Mijou
:story:

Are you guys really surprised?
Those retards managed to fuck up a simple storage server until it became unusable despite having enterprise grade software designed to not fuck it up and start overwrite and corrupt old data, or the petabyte server that deleted everything because they couldn't do a simple RAID array?
I bet some retarded replied to a phishing email on a computer tied to their network, heck i'm sure despite their weekly sponsorship of some enteprise network router or crap, i don't doubt they got a single wifi network for everything they use.
 
None of this surprises me. LMG has had an incredibly laissez-faire attitude towards their own tech for a long time. The multiple data loss events, the previous hack(s?), Linus constantly dropping shit accidentally or as a meme, etc. Guess it's hard to give a damn about your stuff when the bulk of it is review units that get sent back after a month.

Linus:
I can hardly blame a sales rep, a video editor, or someone in accounting for not being up on the latest in cybercrime
A fair point, but is this really "the latest in cybercrime"? The PDF vector is semi-new, but I cannot agree that a document file executing malicious code is "the latest in cybercrime". The underlying age-old rule, "don't open email attachments from people you don't already know", is probably a decades-old concept at this point. IDK how it works at LMG, but if I was a Tuber who got a potential new sponsor deal I wouldn't open a PDF (or DOCX, or TXT, or anything) from the sender's initial message. I don't know who they are, and they're already sending me what? Contracts or some shit? Come the fuck on. I wouldn't even call this a "training issue" (as Linus did), I'd call it a "common sense issue".

Not to mention the point that many people made already: Where were the security controls? ACLs? VLANs? AV? Linus basically admits to knowing access controls exist on their YT account, but failed to use them (~7:30 in the "My Channel Was Deleted" video). His excuse? "Hindsight is 20/20." Lmao. Security controls exist so you can prevent bad things from happening, not for you to flip them on in a rush after shit's hit the fan. Just like above, this boils down to one critical concept: never give your idiot users enough access to destroy mission-critical shit.

For people who claim to be "techy", they sure get roasted a lot for not using tech that would protect their "techy" channels. You can't sell ACLs, VLANS, etc. to consoomers though, so there's no content to be had and therefore no effort will be put into it.

It unlikely it's the "same actor". Given the scammer seems to be indian, it's probably the case that there's a bunch of pajeets siloed into an office somewhere as part of a front company, sending out as many phishing emails to targets as possible. Once they get in, they'll do the same thing, there'll be a list of instructions or something. There's no mastermind hacker behind these, just some pajeet with a checklist.
I'm curious if this is, at least partly, a response to people like Kitboga/Scambaiter/Jim Browning/etc. who have hurt many Indian scammers' chances of financially raping morons who believe their horse shit. "They take 'our' money and ridicule us online, so we'll take their channel" kind of thing. Probably not hard to pivot from phone scamming to email scamming, just need someone to proofread the fucked up English ("please do the needful") and make them sound American.

Also, this disclaimer lmfao. In case you didn't know, these kinds of disclaimers are always complete bullshit and you can ignore them. There's literally no legal basis to uphold this and you're wasting bytes on your email server if you use one.
1679697221905.png
 
Mental Outlaw put out a video on it. He pretty much covers the basics and things I've mentioned previously lately, but I'll add, if you trash a computer, always destroy the hard drives physically as it's super easy to pull the browser files and more off a drive when you have access to the physical drive. It's not even about your account on here or whatever, it's about all your banking information that any amateur dumpster diver can get.
You don't even have to go that far with the drive necessarily. Just 0 out the bits or use something like nwipe running off of ShredOS or gparted. Or encrypt the drive and lose the keys. There are so many ways to effectively ensure your drive's contents are wiped and are not going to pop up in a ddrescue attempt by the feds or a local dumpster diver.

But yeah if you don't have or aren't willing to learn how to do any of those other options, taking a hammer or a drill to the drive may work, though sometimes data can still be recovered from it if you don't destroy it well enough. At the very least, I'd expect a supposed tech channel to know the basics of how to protect their drives but this is Linus we're talking about.

Love or hate Linus, this has been an ongoing problem across YouTube. Your favorite creator could be next.
Good. I hope the hackers make lots of money scamming retards out of their crypto. e-celebs are gay, their fans are gayer, and anything that makes YT a shittier, unworkable platform is a bonus in my book.
 
Last edited:
I hate pajeets so much it's unreal. They stumbled upon the golden goose and squandered it by running a generic crypto scam that netted less money than they'd get from a demented grandma. They actually got some moron at LMG to run malware and all they do is steal sessions? Don't cryptolocker the petabyte server? Don't even attempt to harvest employee docs or company secrets? (I bet you the shares are open to guests with read/write, no way these morons could figure out Kerberos)

Respect to Russian hackers, they'd never let an opportunity like this slip and I bet LMG is going to get absolutely hammered with far more sophisticated scams going forward since incidents like these tend to have a "blood in the water" effect.
 
I'll take my clocks if this was mentioned earlier on the page with the video attachments because I had trouble loading that to scroll past it, but the T-shirt has landed.

20230324_231730.JPG

Adding since it's not really important enough to post a second time about but as per WAN Show Luke was also naked for the first hour of all of this which is just a hilarious if haram mental image. Unscripted simultaneous angry naked computer men.
 
Last edited:
You don't even have to go that far with the drive necessarily. Just 0 out the bits or use something like nwipe running off of ShredOS or gparted. Or encrypt the drive and lose the keys. There are so many ways to effectively ensure your drive's contents are wiped and are not going to pop up in a ddrescue attempt by the feds or a local dumpster diver.

But yeah if you don't have or aren't willing to learn how to do any of those other options, taking a hammer or a drill to the drive may work, though sometimes data can still be recovered from it if you don't destroy it well enough. At the very least, I'd expect a supposed tech channel to know the basics of how to protect their drives but this is Linus we're talking about.
Just get a good pair of pliers and crack the discs and leave them in some salt water for a day or two. If it's an SSD or M2 it's even easier to turn them to dust.

Any form of damage will usually deter amateurs which is what you have to worry about as usually you're not targeted. Though digitally formatting the discs can be an option I enjoy the physical aspect of the destruction.
 
Back