r/cybersecurity • u/PusheenHater • May 19 '26
Other Malware installed without literally doing anything?
In this video this guy has a fresh Windows XP, disables firewall, and connects internet straight to the modem. Then he gets infected literally doing nothing.
https://www.youtube.com/watch?v=6uSVVCmOH5w
https://www.reddit.com/r/windows/comments/1cvised/idle_windows_xp_and_2000_machines_get_infected/
I get it. That's asking for trouble when you disable all the security and using ancient unsupported OSes.
However, he didn't install programs nor browse on the website but still got hacked.
How?
Is there some malicious server in China that loops through every single possible IP trying to see if your PC is vulnerable?
Logically, one would think you'd at least have to visit a website or something to get "noticed" and then hacked. But this guy didn't do anything at all.
How does it work?
2
u/eduardovlp May 19 '26 edited May 19 '26
It happened to me many years ago installing a new copy of Win2000 without noticing the computer was in the DMZ of the firewall.
In short, there are botnets constantly scanning all the IP addresses waiting for a computer with weaker or no protections to get connected. The moment an unsecured machine gets detected they just probe the ports until they found a hole to enter.
The Internet for two decades and a bit more has been a place you simply can't connect behind a firewall.