Lol, I was picking up medication at the chemist and they asked me "what is your relationship with them" after I showed ID... because I don't look as old as I am, apparently.
Winning.
Lol, I was picking up medication at the chemist and they asked me "what is your relationship with them" after I showed ID... because I don't look as old as I am, apparently.
Winning.
@c0dec0dec0de @enkiusz I think that detail was only in the book
@arrjay @drsbaitso @saraislet Vegan cheese, Canadian bacon, pineapple, and mandarin oranges, yum.
@c0dec0dec0de @enkiusz Nedry was recording that conversation so he could blackmail the guy.
The United States SS must have their hands full with all those time travelers who keep showing up.
@mkj nope
Apparently the serial console password on basically all EnGenius devices that I have firmware dumps for is "hom18".
Anyway, I like EnGenius's products and will probably buy more of them in the future.
I haven't found any vulns that can be exploited without either physical access, admin access, or non-default configuration, and I like being able to get a root shell on my equipment.
Anyone have Mikrotik 0-day?
This is from a bundle of code I got when I repeatedly complained to their legal department about GPL compliance.
el oh el
ryanc@airtop3:~/code/GPL_EAP1300$ fgrep -lr 'TRADESECRET INFORMATION OF SENAO' | wc -l
74
The funniest thing is that these access points have a patch to dropbear (an embedded SSH server, which is disabled by default) that ALWAYS enables blank passwords for the root account, though it'll drop you into a config tool, not a shell.
The default root password is, of course, blank...
The first backdoor password I found was "hom18" which drops you right into a root shell.
@arichtman
It also has commands like ifconfig:
Oh, neat, I found a second backdoor account on the EnGenius serial console that wasn't picked up by strings because it's too short.
Password "pe" (the serial console doesn't ask for a username) drops you into a manufacturer test tool. You can get a root shell from there with "cmd sh".
@drsbaitso @saraislet They can do amazing things vegan cheese these days.
IT DOESN'T COUNT AS A TWO PIZZA TEAM OF IT'S TWO TEAMS EATING TWO PIZZAS AND HALF OF THEM DON'T EAT PIZZA
@astraluma a good approximation for "simple" is "could a form submit this?"
@astraluma "simple" requests do not require a CORS preflight
Ryan Castellucci :nonbinary_flag:
Hacker. Cryptography geek. Bureaucramancer. Ex-sysadmin. Expat (US⮕UK).I'm suing the UK for more gender, please help with my legal bills: https://enby.org.ukMy continuing mission:To explore strange new platforms.To seek out new bugs and new software.To boldly shitpost where no one has shitposted before!https://justmytoots.com/@ryanc@infosec.exchange#hacker #nonbinary
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.