Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rickostuff
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
rickostuff
4y ago
The station model doesn't matter. The version of Windows is important, though. WiFi and Ethernet are not involved at all here. The victim machine has a radio and KISS TNC hooked up to their PC running WinAPRS. The attacker crafts a mal
2.
▲
by
rickostuff
4y ago
I'm going to have to see what I can find about this incident. Sounds like the early days of phone phreaking. Awesome!
3.
▲
by
rickostuff
4y ago
I'm not a lawyer, but I used my real callsign when doing anything over the air. I used known protocols, no encryption, nothing commercial, etc. This was all against my own lab systems. I don't think I crossed any legal lines here.
4.
▲
by
rickostuff
4y ago
Thanks! I actually took three OffSec courses last year. The first one I did was the OSWP (wifi) as a sort of warm up because it's the easiest course they offer and I knew I could knock that out pretty quick. Then I took the OSEP course
5.
▲
by
rickostuff
4y ago
I'd like to spend some time digging into radio/tnc firmware for vulnerabilities but that's a bit over my head. I've managed to dump the firmware from my TNC but I haven't found a good way to get it disassembled yet.
6.
▲
by
rickostuff
4y ago
The resources that come to mind are actually all videos of Defcon talks by the same person (Major Malfunction aka Adam Laurie). They are pretty old now, but still interesting. Infrared Hacking: https://www.youtube.com/watch?
7.
▲
by
rickostuff
4y ago
I'm not sure if you are the same Cliff Stoll who wrote 'The Cuckoo's Egg', but if so I listened to the audio book in 2020 during the first part of the pandemic and I loved it. It was fascinating to see how a small billin
8.
▲
by
rickostuff
4y ago
I'm not familiar with DSD/mbelib but based on what I saw with a quick web search this sounds like a really interesting attack vector. I do want to perform some more research in this area, so thanks for the idea.
9.
▲
by
rickostuff
4y ago
I couldn't find where anyone else had done this before with ham radio. That was another motivating factor. It was an interesting new (but, actually old) attack vector. I've always been interested in weird attack vectors like this.
10.
▲
by
rickostuff
4y ago
I spent a lot of time last year researching packet radio software for vulnerabilities. I found a remote code execution (RCE) vulnerability in WinAPRS that let me hack into a system over the air. The result is a reverse shell obtained over h
11.
▲
RCE over ham radio – Reverse shell via WinAPRS memory corruption bug
(coalfire.com)
272 points
by
rickostuff
4y ago
|
47 comments