Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Achmed Jones
Oct 16, 2004



CommieGIR posted:

I got my thing, so now to copy everyone's access cards:



if you get it to do anything interesting post about it, cause i set mine up to turn the tv on and then put it away v_v

i already have a proxmark from alibaba though so nfc stuff isn't as new

Adbot
ADBOT LOVES YOU

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Achmed Jones posted:

if you get it to do anything interesting post about it, cause i set mine up to turn the tv on and then put it away v_v

i already have a proxmark from alibaba though so nfc stuff isn't as new

Already cloned a couple of my access cards, I'm digging through the source code to do some Automotive dongle capture stuff, already used it to ID the frequencies for my audi key fob.

I'm really liking it so far. And yeah, this is replacing the little RFID cloner I made with an arduino previously that I'd use on engagements to grab keycards.

Midjack
Dec 24, 2007



mine came in last week too. i think the proxmark will always have more capability and flexibility for lf and hf rfid, but obviously the flipper can do ibuttons and the ism radio stuff that you won't get off of the proxmark. i'll be interested to see what kind of development community forms around the flipper.

Achmed Jones
Oct 16, 2004



it just needs to work with a chamberlain garage door opener dang it!

it'd be cool if it worked with my tv too instead of having to just replay signals but that's less important

Crime on a Dime
Nov 28, 2006
I missed the first run and I'm mad

Crime on a Dime
Nov 28, 2006

Achmed Jones posted:

if you get it to do anything interesting post about it, cause i set mine up to turn the tv on and then put it away v_v

i already have a proxmark from alibaba though so nfc stuff isn't as new

how much do you want for it

Sarah Problem
Sep 24, 2002

Because, if you confess with your mouth that Witten is Lord and believe in your heart that God raised him from the dead, you will be saved

Add another critical infrastructure RCE to the critical infrastructure RCE pile: https://www.bleepingcomputer.com/news/security/f5-warns-of-critical-big-ip-rce-bug-allowing-device-takeover/

No POC’s yet but it’s with iControl so I’m sure it’s very spicy

Achmed Jones
Oct 16, 2004



Crime on a Dime posted:

how much do you want for it

i don't wanna sell it, cause its still worth the purchase price to dick around with once a month to see if any improvements have been made. i guess i was one of the first people to get it or something, it showed up in like the second week of march

the update i put on today added a bunch of sub-ghz frequencies so i'm hopeful that it'll get more useful as the community does cool stuff

BlankSystemDaemon
Mar 13, 2009



Midjack posted:

mine came in last week too. i think the proxmark will always have more capability and flexibility for lf and hf rfid, but obviously the flipper can do ibuttons and the ism radio stuff that you won't get off of the proxmark. i'll be interested to see what kind of development community forms around the flipper.
It's a pity that they can't use the Rafael Micro R820T or R860, because it can't do LF RFID.
It's an absolutely tiny chip that can fit on even the smallest circuit board, and can tune between 13 and 1864 MHz at 2.5 million samples / second.

Crime on a Dime
Nov 28, 2006

Achmed Jones posted:

i don't wanna sell it, cause its still worth the purchase price to dick around with once a month to see if any improvements have been made. i guess i was one of the first people to get it or something, it showed up in like the second week of march

the update i put on today added a bunch of sub-ghz frequencies so i'm hopeful that it'll get more useful as the community does cool stuff

yeah they're sick, so it was worth an ask! the community stuff will be the good poo poo, but we will only use on devices we own etc :)

Crime on a Dime
Nov 28, 2006
looks like a bunch of people bought them to ᶠˡᶦᵖ on eBay for 400-1200 dollars and they can get flipped. I will wait.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Crime on a Dime posted:

looks like a bunch of people bought them to ᶠˡᶦᵖ on eBay for 400-1200 dollars and they can get flipped. I will wait.

Yeah this seems to be everything now days, getting sick of the flip economy.

ultrafilter
Aug 23, 2007

It's okay if you have any questions.


https://twitter.com/jacobian/status/1522068542157246465

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Yup, couple of my dev friends confirmed they got mandatory password and API key reset requests.

D34THROW
Jan 29, 2012

RETAIL RETAIL LISTEN TO ME BITCH ABOUT RETAIL
:rant:
Welp, good thing I hadn't deployed my project yet. PythonAnywhere is looking better and better.

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

CommieGIR posted:

I got my thing, so now to copy everyone's access cards:



I've been going ham with mine, especially collecting infrared stuff: https://github.com/RooneyMcNibNug/Flipper-nil/tree/main/Infrared

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."

Rooney McNibnug posted:

I've been going ham with mine, especially collecting infrared stuff: https://github.com/RooneyMcNibNug/Flipper-nil/tree/main/Infrared

My neighbor also keeps wondering why his Tesla's charger port keeps opening "out of nowhere" :ghost:

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Rooney McNibnug posted:

My neighbor also keeps wondering why his Tesla's charger port keeps opening "out of nowhere" :ghost:

Security Ghosts!

ynohtna
Feb 16, 2007

backwoods compatible
Illegal Hen

12-factor Ooops

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
good news everyone!
https://twitter.com/alex_a_simons/status/1522209148288606208

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

it's finally happening? neat

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

loving finally.

Hed
Mar 31, 2004

Fun Shoe
interesting. I’m pretty familiar with the Secure Enclave on the Apple side but I need to check out how Windows is doing it and the whole hello thing. also curious what this does for Yubikeys used as a simple FIDO/2 token.

mystes
May 31, 2006

For a second I thought this was saying there was another NEW standard which would have sucked a lot.

Zamujasa
Oct 27, 2010



Bread Liar

Rooney McNibnug posted:

I've been going ham with mine, especially collecting infrared stuff: https://github.com/RooneyMcNibNug/Flipper-nil/tree/main/Infrared

but can it interact with a game boy color? asking for a friend :v:

Achmed Jones
Oct 16, 2004



Crime on a Dime posted:

looks like a bunch of people bought them to ᶠˡᶦᵖ on eBay for 400-1200 dollars and they can get flipped. I will wait.

wtf

who would even spend that much on one? people looking to flip for even more?

like i'd expect anyone who has $600 to drop on the hacker toy to know they're worth $80 or so and that it's not really worth it, and for anybody who thinks they're oh-my-god-magic-hacking-tool to not have that kind of money because they're 16

then again dumbasses buy nfts so maybe im expexting too much

flakeloaf
Feb 26, 2003

Still better than android clock

like many stupid ideas, it only has to work once to be worth it

spankmeister
Jun 15, 2008






only a matter of time for chinese clones to hit the market o suppose

Dr_0ctag0n
Apr 25, 2015
Probation
Can't post for 4 hours!

Submarine Sandpaper posted:

When I did the MSP stint our enterprise shared admin PWs were [company initial][company initial][year]**!!

Yes, a ransomware occurred before my tour.

Our newest MSP has a lead security expert who had an entire onboarding conversation with me while a [presumably shared] generic password was written on the dry-erase board behind him.

:shepicide:

sb hermit
Dec 13, 2016





Hed posted:

interesting. I’m pretty familiar with the Secure Enclave on the Apple side but I need to check out how Windows is doing it and the whole hello thing. also curious what this does for Yubikeys used as a simple FIDO/2 token.

Yubikeys would still be useful as an alternative to carrying around an entire smartphone. Like as an emergency "break glass" second factor or login token.

Yubikeys can also be used as a mechanism to encrypt FDE passwords, or at other times when it's not really feasible to connect to a computer to fetch the password.

Midjack
Dec 24, 2007



Achmed Jones posted:

wtf

who would even spend that much on one? people looking to flip for even more?

like i'd expect anyone who has $600 to drop on the hacker toy to know they're worth $80 or so and that it's not really worth it, and for anybody who thinks they're oh-my-god-magic-hacking-tool to not have that kind of money because they're 16

then again dumbasses buy nfts so maybe im expexting too much

paging through sold items on ebay they seem to be going more for 4-500. there are a couple on offer with buy it now prices that are way higher but no takers so far. markups still suck though.

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock

Dr_0ctag0n posted:

Our newest MSP has a lead security expert who had an entire onboarding conversation with me while a [presumably shared] generic password was written on the dry-erase board behind him.

:shepicide:

it's a trap



question, though: if you put a fake login on the whiteboard when interviewing someone for a red team role, would seeing that login being attempted count as positive or negative?

post hole digger
Mar 21, 2011

Dr_0ctag0n posted:

Our newest MSP has a lead security expert who had an entire onboarding conversation with me while a [presumably shared] generic password was written on the dry-erase board behind him.

:shepicide:

you dont say... :allears:

Midjack
Dec 24, 2007



ymgve posted:

it's a trap



question, though: if you put a fake login on the whiteboard when interviewing someone for a red team role, would seeing that login being attempted count as positive or negative?

slight negative. good observation and initiative but didn't clarify the roes before beginning the test which is how you end up getting sued.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Dr_0ctag0n posted:

Our newest MSP has a lead security expert who had an entire onboarding conversation with me while a [presumably shared] generic password was written on the dry-erase board behind him.

:shepicide:

Favorite past time: Screenshotting support members desktops when they are presenting and forget to leave all their plaintext passwords in notepad on their desktop.

flakeloaf
Feb 26, 2003

Still better than android clock

emailing clients to tell them "passwords.txt" is not a password safe that should be published in the clear on a network where 100,000 people could read it

it's called "system high" cause you'd have to be fuckin high to put anything you want to keep private on the system

MrQueasy
Nov 15, 2005

Probiot-ICK

CommieGIR posted:

Favorite past time: Screenshotting support members desktops when they are presenting and forget to leave all their plaintext passwords in notepad on their desktop.

Someone flashed their MFA QR code in a demo and a couple of us snapped pictures with our cameras because we couldn't believe what we were seeing.

mystes
May 31, 2006

MrQueasy posted:

Someone flashed their MFA QR code in a demo and a couple of us snapped pictures with our cameras because we couldn't believe what we were seeing.
Were they creating a new account for the demo? Otherwise how did they even have the qr code lying around?

MrQueasy
Nov 15, 2005

Probiot-ICK

mystes posted:

Were they creating a new account for the demo? Otherwise how did they even have the qr code lying around?

It was worse... it was a shared mfa.

Adbot
ADBOT LOVES YOU

mystes
May 31, 2006

MrQueasy posted:

It was worse... it was a shared mfa.
They're sharing it by passing the qr code around?!!!!!!!

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply