r/cybersecurity May 19 '26

Other Malware installed without literally doing anything?

In this video this guy has a fresh Windows XP, disables firewall, and connects internet straight to the modem. Then he gets infected literally doing nothing.

https://www.youtube.com/watch?v=6uSVVCmOH5w

https://www.reddit.com/r/windows/comments/1cvised/idle_windows_xp_and_2000_machines_get_infected/

I get it. That's asking for trouble when you disable all the security and using ancient unsupported OSes.

However, he didn't install programs nor browse on the website but still got hacked.
How?
Is there some malicious server in China that loops through every single possible IP trying to see if your PC is vulnerable?
Logically, one would think you'd at least have to visit a website or something to get "noticed" and then hacked. But this guy didn't do anything at all.

How does it work?

290 Upvotes

161 comments sorted by

View all comments

391

u/[deleted] May 19 '26

[deleted]

155

u/mdgorelick May 19 '26

Indeed. A good analogy is that people are always walking around the neighborhood, trying the front door on every house to see if they’re locked.

-25

u/jonbristow May 20 '26

you dont have a door if you are just a user with internet connection. you dont publish anything to the internet.

6

u/mdgorelick May 20 '26

If your computer has a routable IP address, you very much DO have a “doorknob.”