Dan 🔓, powered by sarcasm

@sycophantic@infosec.exchange
621 Followers
791 Following
20 Posts

senior product security engineer / pentester, hacker, retro computers / consoles, amateur radio, SDR, cybersecurity researcher, breaking things, dad, ewr, ally

Other accounts:
@sycophantic
@sycophantic
@w2grk

websitehttps://grink.com
websitehttps://8086.org
githubhttps://github.com/sycophantic
xss<script>alert('Tiananmen Square');</script>
10% off! Use code: betterbmp on checkout, expires 11:59PM ET! https://www.adafruit.com
Adafruit Industries, Unique & fun DIY electronics and kits

Adafruit Industries, Unique & fun DIY electronics and kits : - Tools Gift Certificates Arduino Cables Sensors LEDs Books Breakout Boards Power EL Wire/Tape/Panel Components & Parts LCDs & Displays Wearables Prototyping Raspberry Pi Wireless Young Engineers 3D printing NeoPixels Kits & Projects Robotics & CNC Accessories Cosplay/Costuming Halloween Reseller and School Packs Internet of Things - IoT Development Boards Batteries Feather CircuitPython Circuit Playground Crickit - Creative Robotics Particle STEMMA Machine Learning micro:bit Add-ons & Accessories Bluetooth PPE Microchip Mechanical Keyboards Clearance Sale ecommerce, open source, shop, online shopping

VDLM2 Message From: N685UA / UA0134

Message: FLIGHT CONTROL ISSUE RETURNING TO EWR

Track Aircraft

Area: New York City, NY, USA

#acars #vdlm2 #N685UA #UA0134

Congratulations to our K0HRV operators @hopeconf this weekend for getting the "Worked All Toilets" and "Ceramic Hunter - 5" TOTA awards!
#HamRadio #AmateurRadio

Getting the posters ready for TOTA @ @hopeconf !

#TOTA #hope_16 #AmateurRadio #HamRadio

$5 Membership sale is live: https://account.shodan.io/billing/member
Watched the latest Jurassic Park and it was terrible.

Time for an updated #introduction #readme

I don't know where to start. I started out in the electric utility industry then moved onto cyber security research. Currently I'm responsible for product security for a smart building company.

If you follow me you'll be signing up for #shitposts, #cybersecurity, #electronics, #SDR, #retrogaming, #retrocomputing, #3dprinting, #dronephotography, #drones, #homegardening, and #diy. Probably some other random tech stuff too!

Almost to 10000 accounts on Infosec.exchange. Y’all have chewed through 120GB of disk in 2 weeks.
×

QR code for #EICAR (antivirus test file)

ROT13 decode command to make EICAR test file on demand... Enjoy 😺

printf "%s" 'K5B!C%@nc[4\CMK54(C^)7PP)7}$RVPNE-FGNAQNEQ-NAGVIVEHF-GRFG-SVYR!$U+U*' | tr '[A-Za-z]' '[N-ZA-Mn-za-m]' >EICAR
@catsalad @nc it is velcro-ed to the sleeve of my jacket. 😊
@egeltje @nc That's awesome! Helps "test" those pesky automated image recognition systems. ✅
@catsalad @egeltje @nc I doubt these systems do a virus scan of the scanning results. If they're made for facial recognition, they won't have a qr code interpreter implemented. But we should definitely try some SQL injection.
@Datterich @catsalad @nc in my dream, the scanner records the string and some AV thinks "VIRUS" and destroys the db file. 😊
I know it doesn't work like that anymore, but one can dream...
@egeltje @Datterich @nc Quarantine entire production database... 

@egeltje @Datterich @catsalad @nc For those who don’t:

“According to EICAR's specification the antivirus detects the test file only if it starts with the 68-byte test string and is not more than 128 bytes long. As a result, antiviruses are not expected to raise an alarm on some other document containing the test string.”
https://en.wikipedia.org/wiki/EICAR_test_file#Adoption

EICAR test file - Wikipedia

@Datterich @egeltje @nc Okay! Now #SQLi in a QR code sounds like it has potential...  

BEGIN:VCARD
VERSION:3.0
N:;1';waitfor delay '0:0:10'--
FN:1';waitfor delay '0:0:10'--
TEL;CELL:
TEL;HOME;VOICE:
TEL;WORK;VOICE:
TEL;FAX:
EMAIL;INTERNET:1' AND ISNULL(ASCII(SUBSTRING((SELECT TOP 1 name FROM sysObjects WHERE xtYpe=0x55 AND name NOT IN(SELECT TOP 0 name FROM sysObjects WHERE xtYpe=0x55)),1,1)),0)>78--
ORG:
TITLE:
ADR:;;;;;;
URL:
GENDER:O
END:VCARD

@Datterich @catsalad @egeltje @nc Some systems will store whatever data they decode, and antivirus may quarantine that file.

A few years ago you could break the WiFi stack in Windows by connecting to a network named Invoke-Mimikatz – Windows would connect and store the network in its settings, then Windows Defender would notice the bad string and nuke the whole thing. (sadly WiFi network names are limited to 32 bytes, so EICAR doesn't fit).

@jernej__s EICAR (68 bytes) may be too big as a WiFi name (max 32 bytes), but it's not too big for Bluetooth (max 248 bytes). 👀

@Datterich @egeltje @nc

@catsalad @Datterich @egeltje @nc You're right. Sadly, it doesn't seem to trigger anything on my Windows.

It's 19 bytes for wifi because the name should end in "_optout_nomap"... :-D

@catsalad @jernej__s @Datterich @egeltje @nc

@catsalad
@egeltje @nc

I couldn't resist.   

(Content in ALT text.)

@Datterich and I still don’t know how to read the alt text with the mastodon-glitch web ui
HyperFace

False-face decoy camouflage concept for NeuroSpeculative AfroFeminism (2017)

Adam Harvey Studio
@catsalad brb loading this on my work laptop, wanna see what those endpoint systems can do
I'm thinking I should put this in my email signature
@catsalad YAY!
I have a QR sticker of that on my luggage. I was working on a cross stitch of it to put on my bag (I started it before a Vegas trip since I figure that's the most surveillance-heavy place I go), but apparently "actually going to the fucking craft store and remembering to buy more fucking embroidery floss" is an impossible task for me.
@catsalad
Oh i've been looking for this for decades! Thank you so much!
@catsalad @nc ugh I could tell that was eciar just from the symbols
@catsalad @nc
Gonna print some stickers.