Dillinger, the bastard behind MCP

For anyone not familiar with the film TRON (1982), the protagonist, Kevin Flynn, says this classic line after villain MCP (Master Control Program) decides to send all available tanks after Flynn after breaking out of the game grid. Intentional or not, this short quote introduced the ethical dilemma of creating…

Oh, the shit you'll see on Shodan

Preface: The internet is full of garbage. The founders of the internet envisioned computers around the world, interconnected, forming a mass network. What they didn't envision, however, is a network of millions of devices competing for IPv4 namespace. The reason why I bring this up is because war-dialing…

How a vendor's security negligence gave me root access to ticket vending machines across the US

This post details my experience with companyX, a popular vendor that sells ticket vending machines (referred to as TVMs) for bus agencies. This story is meant to educate others about the danger and risk associated with letting vendors run amuck without checking for security flaws. In my personal experience, most…

Intercepting Among Us traffic

So if you haven't heard of the recently popular game Among Us, it's a pretty simple game involving a group of crew members on a ship with a few unknown murderous "imposters" on board. Let's jump right into it - intercepting traffic…

Malicious QNAPs in the wild

Here's another observation of a weird in-the-wild attack on the blog. The IP address on Shodan shows a device located in Hong Kong based ISP network. At the time of writing, the IP address still responds to requests on ports 80/443/8081. The SSL cert shows QNAP…