Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
thehustler
Apr 17, 2004

I am very curious about this little crescendo
after asking two separate mods about this but getting no reply I figured I'd post it anyway and if it breaks the rules I'll take whatever punishment it deserves

i've been learning a fair amount of infosec stuff lately, mostly about unpacking and looking into firmware for all sorts of devices. I want to look at their underlying OS, some web app testing, and maybe even learn to do some decompiling and binary emulation. It's going well but I want to try and learn as I go and pick up some tips along the way. So I thought about making a let's play kinda thing. Why don't we get some POS Chinese firmware for a camera or something and all look at it and see if we can't teach us some infosec skills?

we need some ground rules though:

* don't touch the poop: that means no shodan or networks you don't own. Download the firmware or use your own device
* we have to follow responsible disclosure. I'm not an expert on that so maybe someone should take responsibility for it
* explain everything as you go and don't keep everything to yourself. This is supposed to be an educational experience

Is this a good idea or a monumentally poo poo idea?

Adbot
ADBOT LOVES YOU

pram
Jun 10, 2001
autism

thehustler
Apr 17, 2004

I am very curious about this little crescendo
probably. but that's how poo poo gets found and fixed.

guess no takers for this then? anyone dabbling in this kinda thing but not getting anywhere?

hifi
Jul 25, 2012

you should have made a thread where you did something cool instead of making a thread to ask if it's ok to make a thread

GameCube
Nov 21, 2006

:justpost:

thehustler
Apr 17, 2004

I am very curious about this little crescendo
in a sense I sort of have. I'll look for some things to download. cameras or dvrs?

anyone got any suggestions for good IoT things to hack? is the thought that Chinese stuff will be more lovely a good one? or have I been playing too much Shenzhen I/O?

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

thehustler posted:

* we have to follow responsible disclosure.

lol pussy

im not sure how you expect this to work on a public forum

thehustler
Apr 17, 2004

I am very curious about this little crescendo

Rufus Ping posted:

lol pussy

im not sure how you expect this to work on a public forum

well to be fair there's the paywall? maybe we can get the thread moved to private game servers

or it's loving stupid

(it's that)

hifi
Jul 25, 2012

thehustler posted:

in a sense I sort of have. I'll look for some things to download. cameras or dvrs?

anyone got any suggestions for good IoT things to hack? is the thought that Chinese stuff will be more lovely a good one? or have I been playing too much Shenzhen I/O?

a nuclear power plant or a bank

The Management
Jan 2, 2010

sup, bitch?
op is an ideas guy, if someone could just do the work that would be great

akadajet
Sep 14, 2003

i've cracked ur mom's internet of things dildo

Stymie
Jan 9, 2001

by LITERALLY AN ADMIN
let's not

The Management
Jan 2, 2010

sup, bitch?
good (?) effort op. maybe you can post some critical disassembled code for us and we can poke at it, but I don't see you getting any traction by asking us to do work

Chumbawumba4ever97
Dec 31, 2000

by Fluffdaddy
can someone work on the PS4 firmware for me so i can get free gamez, thanks!

Bloody
Mar 3, 2013

ill start the wiki

Bloody
Mar 3, 2013

I assume you've played through microcorruption

if not, play through microcorruption

"play"

thehustler
Apr 17, 2004

I am very curious about this little crescendo
I really wasn't expecting someone to do the work, I expected us to all chip in with different bits and maybe different folk had different skills and we could do tutorials and things but maybe this isn't a good medium for it

akadajet
Sep 14, 2003

Uncle at Nintendo posted:

can someone work on the PS4 firmware for me so i can get free gamez, thanks!

there's nothing on the ps4 worth playing, so you're fine as is

thehustler
Apr 17, 2004

I am very curious about this little crescendo

akadajet posted:

there's nothing on the ps4 worth playing, so you're fine as is

best post in what is a lovely thread

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
assuming you know how to use binwalk, just pick something and get started. probs gonna be pretty boring though, at best you'll find a ton of poo poo with hardcoded passwords or shell access that's left open

ipcams are interesting because their firmware is usually poo poo, and people tend to have them connected directly to the internet.

thehustler
Apr 17, 2004

I am very curious about this little crescendo
that was something I'd considered for the reason you stated. or cameras, I'd already got some of those.

hardcoded creds can't be that popular still, surely? I found some in some wireless presentation gateways at work but unfortunately someone had beaten me to it a few years ago

did allow me to tell our security guy that he sucks for not keeping the firmware up to date though, it's patched now

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
it's still pretty common. also in those home gateway/modem combos isps hand out. it's harder to find firmware for those though

thehustler
Apr 17, 2004

I am very curious about this little crescendo

infernal machines posted:

it's still pretty common. also in those home gateway/modem combos isps hand out. it's harder to find firmware for those though

well some are rebadged from a manufacturer so some of the firmware can be shared. but no, I can't get any for mine. JTAG well beyond my skills right now, sadly. not good at electronics

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
isps usually do custom badged distributions of the generic firmware. all the interesting stuff is in the isp specific versions though, because they tend to be horrific hackjobs

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

binwalkin' right into the garbage

Breakfast All Day
Oct 21, 2004

why isnt finding vulnerabilities in firmware called sounding

modern infosec missing some easy layups smdh

akadajet
Sep 14, 2003

Captain Foo posted:

binwalkin' right into the garbage

:tbear:

Bloody
Mar 3, 2013

seriously go play microcorruption its cool and good https://microcorruption.com/login

thehustler
Apr 17, 2004

I am very curious about this little crescendo

Bloody posted:

seriously go play microcorruption its cool and good https://microcorruption.com/login

this does actually look p cool thanks

vodkat
Jun 30, 2012



cannot legally be sold as vodka

Breakfast All Day posted:

why isnt finding vulnerabilities in firmware called sounding

:ironicat:

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
responsible disclosure is loving stupid

fart simpson
Jul 2, 2005

DEATH TO AMERICA
:xickos:

hack the bank, op

emoji
Jun 4, 2004
Once when working for some poo poo startup I changed some SuperMicro firmware to display our company's logos on boot and it was really easy to modify, just needed to change a checksum somewhere in the binary and their firmware dl site was FTP also I had no experience doing that kind of thing before and the ease with which I could modify it concerned me hth op

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE
is firmware with DES encryption securing the root password or pre-generated SSH private keys still a rampant thing?

Axel Rhodes Scholar
May 12, 2001

Courage Reactor

i figured out i can bruteforce the 4-digit pin for my fuji instax printer, which was pretty fun

other options for bypassing this security involve holding the power button down for 5 seconds or so

Adbot
ADBOT LOVES YOU

thehustler
Apr 17, 2004

I am very curious about this little crescendo

Jimmy Carter posted:

is firmware with DES encryption securing the root password or pre-generated SSH private keys still a rampant thing?

a bunch of stuff I downloaded was encrypted and I was annoyed. people are learning I guess.

ps microcorruption loving rocks

  • Locked thread