Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
bolind
Jun 19, 2005



Pillbug
Uhm, hi. I'm in no way a security professional, but I do dabble in it as part of my job, and I have a fascination with it in sort of a spectator kind of way.

Last night I happened upon this video:

https://www.youtube.com/watch?v=_eSAF_qT_FY

Which is WELL worth a watch, IMO.

Adbot
ADBOT LOVES YOU

bolind
Jun 19, 2005



Pillbug
Here's another one from a while ago. Not quite as impressive as the previous one, but I really dig the fact this was all done with QEMU and publicly available firmware images. Anyone with a computer made in the last decade and an internet connection could theoretically pull this off.

https://www.youtube.com/watch?v=B8DjTcANBx0

bolind
Jun 19, 2005



Pillbug

HTTP Basic authentication in TYOOL 2021? smdh...

bolind
Jun 19, 2005



Pillbug
I'm being told that the support you receive, once you've coughed up the money, to get your files back, is second to none.

bolind
Jun 19, 2005



Pillbug
So you're telling me that a five year old GitLab install running on a public IP got compromised and used for mining crypto?

bolind
Jun 19, 2005



Pillbug
I, a dude whose electronics knowledge barely includes which end of a soldering iron is hot, managed to extract the bios password from an old thinkpad using a similar technique, in, like, 2013.

bolind
Jun 19, 2005



Pillbug

:stare: indeed.

bolind
Jun 19, 2005



Pillbug

Oh yeah, there’s an exploit on GitHub which is like 23 LoC and it works beautifully. Ask me how I know.

Patched a couple of dozen servers today. Yay.

bolind
Jun 19, 2005



Pillbug
If I want to dip my feet into RFID card/fob cloning, where do I go? 300EUR for a Proxmark v3 is a little out of my snack bracket.

bolind
Jun 19, 2005



Pillbug

Or 75 eurobux: https://www.digitalkey.it/en/sensor-readers-rfid/144-proxmark3-v3-easy-512m-kit-nfc-rfid-5-tag-di-test-793596617942.html

Thanks!

bolind
Jun 19, 2005



Pillbug

Quite some time back I asked about RFID cloning tools and the Proxmark3 v3 came up. I finally decided to pull the trigger, and lo and behold it's sold out and appears to be discontinued.

What's the recommendation these days? Budget is around USD100.

bolind
Jun 19, 2005



Pillbug
What's the deal with 1PassWord? My app version (100% locally stored) just works and doesn't cost me anything, but for new users it's paid only?

Adbot
ADBOT LOVES YOU

bolind
Jun 19, 2005



Pillbug
Is there a dumb free password manager for iOS? I just need like an encrypted notepad. No sync to PC or autofill or anything.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply