Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. This is a fun write-up.

This is a fun write-up.

Scheduled Pinned Locked Moved Uncategorized
9 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchange
    wrote last edited by
    #1

    This is a fun write-up. @da_667 it's not something you can write sigs for but you might find it interesting anyway.

    Link Preview Image
    A Route to Root in a 4G Industrial Router

    A journey into the USR-G806AU 4G LTE industrial router. From fake root accounts to real and undocumented root accounts, and the discovery of hardcoded credentials that expose devices to remote compromise.

    favicon

    Tanto Security (tantosec.com)

    H / T @buherator

    h2onolan@infosec.exchangeH fritzadalis@infosec.exchangeF 2 Replies Last reply
    0
    • cr0w@infosec.exchangeC cr0w@infosec.exchange

      This is a fun write-up. @da_667 it's not something you can write sigs for but you might find it interesting anyway.

      Link Preview Image
      A Route to Root in a 4G Industrial Router

      A journey into the USR-G806AU 4G LTE industrial router. From fake root accounts to real and undocumented root accounts, and the discovery of hardcoded credentials that expose devices to remote compromise.

      favicon

      Tanto Security (tantosec.com)

      H / T @buherator

      h2onolan@infosec.exchangeH This user is from outside of this forum
      h2onolan@infosec.exchangeH This user is from outside of this forum
      h2onolan@infosec.exchange
      wrote last edited by
      #2

      @cR0w @da_667 @buherator oh no not again

      cr0w@infosec.exchangeC 1 Reply Last reply
      0
      • h2onolan@infosec.exchangeH h2onolan@infosec.exchange

        @cR0w @da_667 @buherator oh no not again

        cr0w@infosec.exchangeC This user is from outside of this forum
        cr0w@infosec.exchangeC This user is from outside of this forum
        cr0w@infosec.exchange
        wrote last edited by
        #3

        @h2onolan @da_667 @buherator At least it's a well written tire fire.

        h2onolan@infosec.exchangeH 1 Reply Last reply
        0
        • cr0w@infosec.exchangeC cr0w@infosec.exchange

          @h2onolan @da_667 @buherator At least it's a well written tire fire.

          h2onolan@infosec.exchangeH This user is from outside of this forum
          h2onolan@infosec.exchangeH This user is from outside of this forum
          h2onolan@infosec.exchange
          wrote last edited by
          #4

          @cR0w i liked the ghidra asides.

          A while back, cradlepoint shipped some vulnerable sierra crap that allowed an attacker to do unauthed proxy, running up huge data bills on remote well installations. Fun times- thanks for the traumatic stress flashback

          cr0w@infosec.exchangeC 1 Reply Last reply
          0
          • h2onolan@infosec.exchangeH h2onolan@infosec.exchange

            @cR0w i liked the ghidra asides.

            A while back, cradlepoint shipped some vulnerable sierra crap that allowed an attacker to do unauthed proxy, running up huge data bills on remote well installations. Fun times- thanks for the traumatic stress flashback

            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchange
            wrote last edited by
            #5

            @h2onolan I swear I find a new Sierra device in our org like monthly. Undocumented but there's always one person who knows what it is so it's fine it's all fine. Or so I'm told.

            1 Reply Last reply
            0
            • cr0w@infosec.exchangeC cr0w@infosec.exchange

              This is a fun write-up. @da_667 it's not something you can write sigs for but you might find it interesting anyway.

              Link Preview Image
              A Route to Root in a 4G Industrial Router

              A journey into the USR-G806AU 4G LTE industrial router. From fake root accounts to real and undocumented root accounts, and the discovery of hardcoded credentials that expose devices to remote compromise.

              favicon

              Tanto Security (tantosec.com)

              H / T @buherator

              fritzadalis@infosec.exchangeF This user is from outside of this forum
              fritzadalis@infosec.exchangeF This user is from outside of this forum
              fritzadalis@infosec.exchange
              wrote last edited by
              #6

              @cR0w @da_667 @buherator
              > [The Pi] had been looking at me longingly, much like the Flipper Zero we all have in our bottom desk drawer, each hoping for something to do.

              DUDE.

              cr0w@infosec.exchangeC 1 Reply Last reply
              0
              • fritzadalis@infosec.exchangeF fritzadalis@infosec.exchange

                @cR0w @da_667 @buherator
                > [The Pi] had been looking at me longingly, much like the Flipper Zero we all have in our bottom desk drawer, each hoping for something to do.

                DUDE.

                cr0w@infosec.exchangeC This user is from outside of this forum
                cr0w@infosec.exchangeC This user is from outside of this forum
                cr0w@infosec.exchange
                wrote last edited by
                #7

                @FritzAdalis @da_667 @buherator Feeling a bit called out?

                da_667@infosec.exchangeD 1 Reply Last reply
                0
                • cr0w@infosec.exchangeC cr0w@infosec.exchange

                  @FritzAdalis @da_667 @buherator Feeling a bit called out?

                  da_667@infosec.exchangeD This user is from outside of this forum
                  da_667@infosec.exchangeD This user is from outside of this forum
                  da_667@infosec.exchange
                  wrote last edited by
                  #8

                  @cR0w @FritzAdalis @buherator I have an ancient 512mb pi sitting in one of my shelf cubbies, connected to an unplugged samsung wall wort just staring a hole into the back of my head right now.

                  da_667@infosec.exchangeD 1 Reply Last reply
                  0
                  • da_667@infosec.exchangeD da_667@infosec.exchange

                    @cR0w @FritzAdalis @buherator I have an ancient 512mb pi sitting in one of my shelf cubbies, connected to an unplugged samsung wall wort just staring a hole into the back of my head right now.

                    da_667@infosec.exchangeD This user is from outside of this forum
                    da_667@infosec.exchangeD This user is from outside of this forum
                    da_667@infosec.exchange
                    wrote last edited by
                    #9

                    @cR0w @FritzAdalis @buherator oh yeah, that doesn't include the one with 4gb of ram, sitting in a water-resistant otter-box knockoff case, that can't stare me down.

                    1 Reply Last reply
                    1
                    0
                    • R relay@relay.infosec.exchange shared this topic
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                    • Login

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • World
                    • Users
                    • Groups