GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    kajer (kajer@infosec.exchange)'s status on Thursday, 16-Nov-2023 03:34:58 JST kajer kajer

    Picked up some switches from an auction

    One wasn't wiped. Cisco type 5, say hello to hashcat.

    In conversation Thursday, 16-Nov-2023 03:34:58 JST from infosec.exchange permalink
    • Embed this notice
      kajer (kajer@infosec.exchange)'s status on Thursday, 16-Nov-2023 03:35:16 JST kajer kajer
      in reply to

      moar power

      In conversation Thursday, 16-Nov-2023 03:35:16 JST permalink

      Attachments


      1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/415/916/434/405/647/original/d3a681af1701a2a7.png
    • Embed this notice
      kajer (kajer@infosec.exchange)'s status on Thursday, 16-Nov-2023 03:35:16 JST kajer kajer
      in reply to
      • CrackMeIfYouCan

      🤔 I need more GPUs

      Did I learn nothing from @CrackMeIfYouCan at @defcon ???

      I have no metadata to make educated guesses as to what the passwords could be. Unless it's a cheesy variation of the school mascot?

      In conversation Thursday, 16-Nov-2023 03:35:16 JST permalink

      Attachments


      1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/415/963/115/263/014/original/b994c6cd30c97720.png

      2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/415/965/665/694/667/original/df09731710f07aa0.png
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 16-Nov-2023 03:35:16 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • CrackMeIfYouCan

      @kajer @CrackMeIfYouCan @defcon 🍿

      In conversation Thursday, 16-Nov-2023 03:35:16 JST permalink
    • Embed this notice
      kajer (kajer@infosec.exchange)'s status on Thursday, 16-Nov-2023 03:35:18 JST kajer kajer
      in reply to

      the network admin even left an emergency maintenance port

      This switch was probably in a locked closet, as this maintenance port has 0 controls for access.

      Red teams would probably note a 24 port access switch with port24 NOT patched in and hanging out...

      In conversation Thursday, 16-Nov-2023 03:35:18 JST permalink
    • Embed this notice
      kajer (kajer@infosec.exchange)'s status on Thursday, 16-Nov-2023 03:35:18 JST kajer kajer
      in reply to

      Here we go...

      In conversation Thursday, 16-Nov-2023 03:35:18 JST permalink

      Attachments


      1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/415/882/512/319/812/original/11177e25ceea8b4e.png
    • Embed this notice
      kajer (kajer@infosec.exchange)'s status on Thursday, 16-Nov-2023 03:35:18 JST kajer kajer
      in reply to

      Oh good, my CMIYC rig is still loading drivers... So many times the background processes destroy the nvidia drivers randomly....

      In conversation Thursday, 16-Nov-2023 03:35:18 JST permalink

      Attachments


      1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/415/895/585/604/646/original/e35dd4cfe6c34715.png
    • Embed this notice
      kajer (kajer@infosec.exchange)'s status on Thursday, 16-Nov-2023 03:35:19 JST kajer kajer
      in reply to

      I am reviewing the stored config. It's very nicely done for an access switch.

      proper ACLs on SNMP server / management SSH

      dhcp snooping and RA guard

      arp inspection with src and dst mac

      err-disable recovery for all common problems

      bpduguard, 802.1x

      I'm pretty jealous, this config is nice!

      In conversation Thursday, 16-Nov-2023 03:35:19 JST permalink
    • Embed this notice
      kajer (kajer@infosec.exchange)'s status on Thursday, 16-Nov-2023 03:46:45 JST kajer kajer
      in reply to
      • Ryan Castellucci :nonbinary_flag:
      • CrackMeIfYouCan

      @ryanc @CrackMeIfYouCan @defcon

      I did some RDP sessions to my other gaming rigs... Got the ETA down to 11days to process RockYou+OneRule

      This is brute force basically, as I have nothing to base a taylored wordlist on. Unless the Network Admins at this school like to use emojis in their passwords?

      Estimated time: 11d 09:01:44
      Speed: 3203.03 kH/s

      In conversation Thursday, 16-Nov-2023 03:46:45 JST permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 17-Nov-2023 03:53:45 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Francis 🏴‍☠️ Gulotta
      • CrackMeIfYouCan

      @kajer @reconbot @CrackMeIfYouCan @defcon

      :hacker_h: :hacker_a: :hacker_c: :hacker_k:

      :hacker_h: :hacker_a: :hacker_r: :hacker_d: :hacker_e: :hacker_r:

      In conversation Friday, 17-Nov-2023 03:53:45 JST permalink
    • Embed this notice
      kajer (kajer@infosec.exchange)'s status on Friday, 17-Nov-2023 03:53:46 JST kajer kajer
      in reply to
      • Francis 🏴‍☠️ Gulotta
      • Ryan Castellucci :nonbinary_flag:
      • CrackMeIfYouCan

      @reconbot @ryanc @CrackMeIfYouCan @defcon

      Sadly, overnight didnt make much progress. Still at 0 cracked hashes.

      Here are the quick stats of the operation.

      Keyspace dispatched: 1729129 (12.05%)
      Keyspace searched: 1689227 (11.78%)
      Time spent: 23:56:27
      Estimated time: 7d 11:21:26
      Speed: 4905.58 kH/s

      This is mode 500 on hashcat

      cisco type 5 is $1$salt$hash

      In conversation Friday, 17-Nov-2023 03:53:46 JST permalink
    • Embed this notice
      Francis 🏴‍☠️ Gulotta (reconbot@toot.cafe)'s status on Friday, 17-Nov-2023 03:53:48 JST Francis 🏴‍☠️ Gulotta Francis 🏴‍☠️ Gulotta
      in reply to
      • Ryan Castellucci :nonbinary_flag:
      • CrackMeIfYouCan

      @kajer @ryanc @CrackMeIfYouCan @defcon In 2002 my godfather owned one of the first 1ghz Pentiums on the market and my god it ran l0phtcrack faster than anything else. We've come a long way but the more things change...

      In conversation Friday, 17-Nov-2023 03:53:48 JST permalink
    • Embed this notice
      kajer (kajer@infosec.exchange)'s status on Friday, 17-Nov-2023 03:53:49 JST kajer kajer
      in reply to
      • Ryan Castellucci :nonbinary_flag:
      • CrackMeIfYouCan

      @ryanc @CrackMeIfYouCan @defcon

      At least my garage will be nice and cozy

      In conversation Friday, 17-Nov-2023 03:53:49 JST permalink

      Attachments


      1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/416/074/206/726/111/original/5a562c5f460da7f9.png

      2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/416/079/878/385/278/original/cb1059665a26cfe4.png
    • Embed this notice
      kajer (kajer@infosec.exchange)'s status on Friday, 17-Nov-2023 05:59:22 JST kajer kajer
      in reply to
      • Francis 🏴‍☠️ Gulotta
      • Ryan Castellucci :nonbinary_flag:
      • CrackMeIfYouCan

      @ryanc @reconbot @CrackMeIfYouCan @defcon

      Trying!!!

      In conversation Friday, 17-Nov-2023 05:59:22 JST permalink

      Attachments


      1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/422/228/512/800/687/original/9fc39b21793febb7.png

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.