3 ms·
Don’t forget, also very few of those people want to be blackhat.
by bluesign 4y ago
Don’t forget, also very few of those people want to be blackhat.
- w1nst0nsm1th 4y agoI read once blackhat and whitehat are just buzz words and most of real hackers (not script kiddies or pentesters) are more like greyhats. That being said, I uncovered once a security hole (in reality it should be called an open door) in the admin password of the now disappeared bbox2, the official router for the belgian company called Proximus. How did I discovered it ? I wanted to watch ip addresses going through the router because I knew the owner of the box was up to something about me... But almost immediatelly I discovered the admin password field was like an 'universal lock', meaning any key could open it... in other word word, any string entered in the password field allowed to access admin pages of the box. After a few google searches, I discovered the software (the OS) was the last version, dating a few years back, and the box producer didn't pushed anymore update, not even security update. (Look at synology NAS scandal where Synology dropped software update for one of its older hardware to have an idea of the kind of thing it means for hardware facing internet access). I immediatly reported the security hole to the federal cybersecurity unit, and after that, kept my mouth shut because there wasn't any way to fix this security issue except replacing the hardware itself. At that time, between 1/6 to 1/4 of routers in belgium were bbox2. I never heard anything from the federal cybersecurity unit (except a mere thank you by mail) or Proximus, but 1 year and a half later, bbox2 where nowhere to be found anymore in belgium. The only thing I have left from that is the mail I sent to the cybersecurity unit with screenshots of the bbox2 admin pages. Why did I report it and shut my mouth without taking credentials for it (that's the kind of things which can launch a career in security field) ? Because it's one thing to try to snoop on an accointance browsing activity, it's another to let a security hole of this magnitude in the open, and a far worse thing to disclose it to the public while there is no fix for it. And that's another level to sell it on dark market or to the chinese or russian ambassy (I'm not in the hacking business but I'm pretty sure they would have dropped a big pile of cash for that). Just to say, Bruxelles is also home of numerous european institutions... Maybe that's why the european parlement voted for mandotary code review for everything facing the internet in EU ?