GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 16:21:33 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️

    good lord. I pulled a microSD card out of a Raspi inside an IoT product and it appears they had some developer use a raspi to develop/test some software, and then they just yanked the SD card out of that machine and duped it on to all of their deployed products.

    it's got .bash_history of the development process! there's git checkouts of private repos! WHY WOULD YOU DO THIS?

    In conversation about 10 months ago from digipres.club permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      http://products.it/
    • Haelwenn /элвэн/ :triskell:, narcolepsy and alcoholism :flag: and clacke and 3 others like this.
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Saturday, 20-Jul-2024 16:21:26 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to

      @foone 🍿

      In conversation about 10 months ago permalink
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 16:21:27 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      this is deeply embarrassing. I have lists of their duckduckgo and google searches for the programming problems they were having building this product.

      no programmer should ever have that personal shame shared with the world. let alone included on every microSD card your company ships!

      In conversation about 10 months ago permalink
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 16:21:28 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      oh sweet jesus they logged into slack from this machine('s image)

      I have their chrome profile, with history and cookies and shit!

      In conversation about 10 months ago permalink
      Haelwenn /элвэн/ :triskell: and Polychrome :blabcat: like this.
      Paul Cantrell repeated this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 16:21:30 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      this might be UPS trucks. I should probably not query any of these GPS histories

      In conversation about 10 months ago permalink
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 16:21:30 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      also they're spamming 9 lines to syslog every minute.

      this is a microsd card in a raspi, guys! you are going to fry your fucking card by running out of write cycles. That's not a good idea in any raspi application, especially not an IoT one

      In conversation about 10 months ago permalink
      Haelwenn /элвэн/ :triskell: and Polychrome :blabcat: like this.
      Haelwenn /элвэн/ :triskell: and Polychrome :blabcat: repeated this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 16:21:31 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      also, you punks are writing python 2 code in 2021? come on, who does that?

      I mean, I do all the time, but I'm a known retrocomputerist. I run Windows 95 and MS-DOS regularly. of course I'm using a wildly outdated programming language. I'm not making a product I sell to customers!

      In conversation about 10 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
      GreenSkyOverMe (Monika) repeated this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 16:21:31 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      oh cool you can pull the GPS history of a truck from azure without any login, you just need to know the device ID.

      In conversation about 10 months ago permalink
      Polychrome :blabcat: likes this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 16:21:32 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      I've also been able to de-stealth a "stealth startup" on linked in.
      because this has commits from different users, and I can just look up on linkedin what stealth-startup all those people work/worked at and then look at the name on the IoT box I'm holding

      In conversation about 10 months ago permalink
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 16:41:11 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      oh sweet jesus

      they automatically scp up some logs to a server somewhere. Did they set up keys so that authorized devices could log in automatically without passwords?

      NOPE THEY USED SSHPASS

      In conversation about 10 months ago permalink
      Haelwenn /элвэн/ :triskell: and Polychrome :blabcat: like this.
      Ryan Castellucci :nonbinary_flag: and GreenSkyOverMe (Monika) repeated this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 16:41:27 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      well I'm putting this away so I don't accidentally hack them.

      In conversation about 10 months ago permalink
      Haelwenn /элвэн/ :triskell: and Pleroma-tan like this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 16:41:28 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      I have a file here with multiple lines like:

      sudo sshpass -p PASSWORDHERE scp /path/system/network.log USERNAME@IPADDRESS:/home/manufacturing/

      In conversation about 10 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
      Polychrome :blabcat:, Haelwenn /элвэн/ :triskell: and Pleroma-tan repeated this.
    • Embed this notice
      Polychrome :blabcat: (polychrome@poly.cybre.city)'s status on Saturday, 20-Jul-2024 16:42:09 JST Polychrome :blabcat: Polychrome :blabcat:
      in reply to
      @foone this thread just slowly became worse and worse as I was reading it :blobcatsweat:
      In conversation about 10 months ago permalink
      Haelwenn /элвэн/ :triskell: and GuySoft like this.
    • Embed this notice
      Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Saturday, 20-Jul-2024 16:53:31 JST Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
      in reply to
      @foone Kind of thing that is so bad I kind of wonder if it's a really weird attempt at an honeypot.
      In conversation about 10 months ago permalink
    • Embed this notice
      Pleroma-tan (kirby@lab.nyanide.com)'s status on Saturday, 20-Jul-2024 16:54:52 JST Pleroma-tan Pleroma-tan
      in reply to
      @foone LOG IN TO THEIR EMAIL AND START SENDING TONS OF SPAM YOU PUSSY
      In conversation about 10 months ago permalink
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 17:11:29 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to
      • Pleroma-tan

      @kirby their company is only two cities over it would be trivial for them to find and arrest me!

      In conversation about 10 months ago permalink
      Pleroma-tan likes this.
      Pleroma-tan repeated this.
    • Embed this notice
      Jens Finkhäuser (jens@social.finkhaeuser.de)'s status on Saturday, 20-Jul-2024 17:19:03 JST Jens Finkhäuser Jens Finkhäuser
      in reply to
      • Pleroma-tan

      @foone @kirby Share this info with someone and let them do the hack? No, no, that'd be a criminal conspiracy, I cannot recommend this.

      In conversation about 10 months ago permalink
      Pleroma-tan likes this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 17:22:45 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      Also I'm a reverse engineer. There's no reverse engineering here!
      I unscrewed the box, pulled out the raspi, pulled the SD card out, put it in my laptop, and it automounted. I then looked at some files while making a disgusted face.

      That's not reverse engineering! That's just lookin'

      In conversation about 10 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Saturday, 20-Jul-2024 17:22:46 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      this is one of the many reasons I'm not a security researcher.

      it's a target rich environment.

      In conversation about 10 months ago permalink

      Attachments


      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      :umu: :umu: (a1ba@suya.place)'s status on Sunday, 21-Jul-2024 09:40:59 JST :umu: :umu: :umu: :umu:
      in reply to
      @foone if it's not reverse engineering, it's zero velocity engineering.

      Also, LOL. I knew guys who did the same thing but it was like temporary solution and nothing was shipped in similar state.
      In conversation about 10 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      GuySoft (guysoft@hayu.sh)'s status on Wednesday, 24-Jul-2024 15:59:33 JST GuySoft GuySoft
      in reply to
      @foone
      I think its super common among even bigger companies.
      As the creator of CustomPiOS people keep saying they rather dup and don't know that the first boot generates the public keys.
      In conversation about 10 months ago permalink
    • Embed this notice
      Mx Amber Alex (she/it) (amberage@eldritch.cafe)'s status on Tuesday, 20-Aug-2024 21:57:17 JST Mx Amber Alex (she/it) Mx Amber Alex (she/it)
      in reply to

      @foone in Germany, which is infamously backwards and close-minded about i.e. disclosing 0days, you could go to prison for this.

      Germany recently sentenced a software engineer to huge fines for cybercrimes, in a years-long trial that destroyed his career, because he found a plaintext password in a file, told the company about that vulnerability, and went public with it when they bitched at him what business he had finding vulnerabilities in their product (a client of theirs had hired him to figure out why his servers were crashing or smth) (and ofc he waited with the going public until the vuln was closed).

      (German news article about it)

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      DeterioratedStucco (softwaretheron@mas.to)'s status on Wednesday, 21-Aug-2024 20:21:16 JST DeterioratedStucco DeterioratedStucco
      in reply to

      @foone
      Dev to grumbly tester: "Hey, it works on my machine :) "
      Overhearing PM: "Right, let's ship your machine then!"

      In conversation about 9 months ago permalink
      clacke likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.