GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Tuesday, 03-Sep-2024 07:59:33 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    in reply to
    • Richard "mtfnpy" Harman (he/him)
    • morb

    @xabean @morb is that descrypt?

    In conversation about 9 months ago from gnusocial.jp permalink
    • Embed this notice
      morb (morb@mastodon.social)'s status on Tuesday, 03-Sep-2024 07:59:34 JST morb morb
      in reply to
      • Richard "mtfnpy" Harman (he/him)

      @xabean don't have one on hand; just the latest firmware I could find for a rebranded Yealink that had the same shadow file -- will dig for that tho

      PasswdCopy.sh looks like it uses an unsafe subshell fwiw

      In conversation about 9 months ago permalink

      Attachments


      1. https://files.mastodon.social/media_attachments/files/113/068/335/135/342/660/original/d9aafc534ba7eca3.png

    • Embed this notice
      Richard "mtfnpy" Harman (he/him) (xabean@infosec.exchange)'s status on Tuesday, 03-Sep-2024 07:59:34 JST Richard "mtfnpy" Harman (he/him) Richard "mtfnpy" Harman (he/him)
      in reply to
      • morb

      @morb

      always fun when running strings on a piece of firmware and you find:

      user:s7C9Cx.rLsWFA
      var:jhl3iZAe./qXM
      admin:uoCbM.VEiKQto

      In conversation about 9 months ago permalink
    • Embed this notice
      morb (morb@mastodon.social)'s status on Tuesday, 03-Sep-2024 07:59:35 JST morb morb
      in reply to
      • Richard "mtfnpy" Harman (he/him)
      • Royce Williams

      @xabean @tychotithonus

      extracted latest fw for TIP200 (60.61.75.22) and...

      [Yealink Busybox Ver 1.0.0.1]
      BusyBox v1.10.3 (2013-08-06 13:53:41 CST) multi-call binary
      Copyright (C) 1998-2007 Erik Andersen, Rob Landley, Denys Vlasenko

      >_<

      In conversation about 9 months ago permalink
    • Embed this notice
      Richard "mtfnpy" Harman (he/him) (xabean@infosec.exchange)'s status on Tuesday, 03-Sep-2024 07:59:35 JST Richard "mtfnpy" Harman (he/him) Richard "mtfnpy" Harman (he/him)
      in reply to
      • Royce Williams
      • morb

      @morb @tychotithonus my head was in the same place - the "diagnosis" page that apparently had straight up shell injection isn't in the firmware I'm running on this phone, and now I'm digging into some of the MACADDRESS.cfg provisioning files and related XML translation on the phone checking what gets (ab)used by grep into shell variables, etc.

      In conversation about 9 months ago permalink
    • Embed this notice
      Richard "mtfnpy" Harman (he/him) (xabean@infosec.exchange)'s status on Tuesday, 03-Sep-2024 07:59:35 JST Richard "mtfnpy" Harman (he/him) Richard "mtfnpy" Harman (he/him)
      in reply to
      • morb

      @morb Oh neat, does this URL work on your phone? /servlet?p=hidden

      In conversation about 9 months ago permalink
    • Embed this notice
      morb (morb@mastodon.social)'s status on Tuesday, 03-Sep-2024 07:59:36 JST morb morb
      in reply to
      • Richard "mtfnpy" Harman (he/him)
      • Royce Williams

      @xabean @tychotithonus fwiw the Intelbras TIP 200 series shares the same shadow entries; dead end finding any working creds attributed though

      https://github.com/Ls4ss/CVE-2020-13886/blob/master/README.md

      In conversation about 9 months ago permalink
    • Embed this notice
      morb (morb@mastodon.social)'s status on Tuesday, 03-Sep-2024 07:59:36 JST morb morb
      in reply to
      • Richard "mtfnpy" Harman (he/him)
      • Royce Williams

      @xabean @tychotithonus running jtr against it and rockyou2024 right now for yucks

      In conversation about 9 months ago permalink
    • Embed this notice
      Richard "mtfnpy" Harman (he/him) (xabean@infosec.exchange)'s status on Tuesday, 03-Sep-2024 07:59:36 JST Richard "mtfnpy" Harman (he/him) Richard "mtfnpy" Harman (he/him)
      in reply to
      • Royce Williams
      • morb

      @morb @tychotithonus mmm whelp I bumped up the logging level through config, and I see when I try to telnet in with root/toor/admin/yealink any username all results in:

      login[480]: invalid password for 'UNKNOWN' on 'pts/0'

      In conversation about 9 months ago permalink
    • Embed this notice
      morb (morb@mastodon.social)'s status on Tuesday, 03-Sep-2024 07:59:36 JST morb morb
      in reply to
      • Richard "mtfnpy" Harman (he/him)
      • Royce Williams

      @xabean @tychotithonus have you tried shell injection in any of the provisioning file fields yet

      In conversation about 9 months ago permalink
    • Embed this notice
      Richard "mtfnpy" Harman (he/him) (xabean@infosec.exchange)'s status on Tuesday, 03-Sep-2024 07:59:37 JST Richard "mtfnpy" Harman (he/him) Richard "mtfnpy" Harman (he/him)
      in reply to
      • Royce Williams

      @tychotithonus cool, thank you. I appreciate it, this is an area I'm not well versed in :)

      In conversation about 9 months ago permalink
    • Embed this notice
      Royce Williams (tychotithonus@infosec.exchange)'s status on Tuesday, 03-Sep-2024 07:59:37 JST Royce Williams Royce Williams
      in reply to
      • Richard "mtfnpy" Harman (he/him)

      @xabean What's in the other /etc/shadow?

      In conversation about 9 months ago permalink
    • Embed this notice
      Richard "mtfnpy" Harman (he/him) (xabean@infosec.exchange)'s status on Tuesday, 03-Sep-2024 07:59:37 JST Richard "mtfnpy" Harman (he/him) Richard "mtfnpy" Harman (he/him)
      in reply to
      • Royce Williams

      @tychotithonus dunno what is in the /yealink/config filesystem yet. Haven't found a way into the device yet. I *did* manage to figure out how to enable telnet, through config it fetches via provisioning.

      In conversation about 9 months ago permalink
    • Embed this notice
      Royce Williams (tychotithonus@infosec.exchange)'s status on Tuesday, 03-Sep-2024 07:59:38 JST Royce Williams Royce Williams
      in reply to
      • Richard "mtfnpy" Harman (he/him)

      @xabean Depending on sensitivity, Hashes.com has a bounty / escrow system (free). Or you could upload it as a 'user list' to HashMob. Or you could let me take a ... crack at it (2x 4090s). :D

      Edit: a third option, if you know hashcat and Docker, is to just rent a chunk of GPUs through vast.ai or similar.

      In conversation about 9 months ago permalink

      Attachments

      1. Decrypt MD5, SHA1, MySQL, NTLM, SHA256, MD5 Email, SHA256 Email, SHA512, Wordpress, Bcrypt hashes for free online
        Decrypt and crack your MD5, SHA1, SHA256, MySQL, MD5 Email, SHA256 Email, and NTLM hashes for free online. We also support Bcrypt, SHA512, Wordpress and many more.
      2. Domain not in remote thumbnail source whitelist: vast.ai
        Rent GPUs | Vast.ai
        from @vast_ai
        Reduce your cloud compute costs by 3-5X with the best cloud GPU rentals. Vast.ai's simple search interface allows fair comparison of GPU rentals from all providers.
    • Embed this notice
      Richard "mtfnpy" Harman (he/him) (xabean@infosec.exchange)'s status on Tuesday, 03-Sep-2024 07:59:38 JST Richard "mtfnpy" Harman (he/him) Richard "mtfnpy" Harman (he/him)
      in reply to
      • Royce Williams

      @tychotithonus if you want to poke at it, here you go -- this is for a Yealink SIP phone. Strings in the firmware nearby suggest the password is YealinkPhone1106 but it doesn't seem to work on my hardware; which might be due to the fact that there's a config partition that overlay mounts a shadow file overtop of /etc/shadow from the ROM:

      root:$1$.jKlhz0B$/Nmgj0klrsZk0nYc1BLUR/:11876:0:99999:7:::

      In conversation about 9 months ago permalink
    • Embed this notice
      Royce Williams (tychotithonus@infosec.exchange)'s status on Tuesday, 03-Sep-2024 07:59:38 JST Royce Williams Royce Williams
      in reply to
      • Richard "mtfnpy" Harman (he/him)

      @xabean No immediate hits - permuted case and leet for both 'Yealink' and 'YealinkPhone', and appended and prepended all sorts of stuff (all possible 4-char suffixes, etc.) ... nothing so far

      In conversation about 9 months ago permalink
    • Embed this notice
      Richard "mtfnpy" Harman (he/him) (xabean@infosec.exchange)'s status on Tuesday, 03-Sep-2024 07:59:39 JST Richard "mtfnpy" Harman (he/him) Richard "mtfnpy" Harman (he/him)

      Is there a cloud "throw money at the problem" service that cracks md5crypt passwords with GPUs?

      In conversation about 9 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.