sʏɴғɪɴɴᴇʀ

28 Followers
57 Following
374 Posts

| Computer Network Operations | Exploit dev | Malware Reversing | I do other stuff too: reading, *nix stuff, traveling the globe, cooking | Be kind to everyone. |

Languages: English, русский

Bloghttps://vx128.ru/blog
Onion sitehttp://vz35c7werosf4orb.onion
Keybasehttps://keybase.io/synfinner
LocationWashington, D.C.

My package from UPS has successfully been out for deliver since Thursday.

Why. Why are you like this.

 

Being paid to break into stuff isn't always as glorious as people make it out to be.

I've been up entirely too long, coffee mugs are littering my desk, and I'm tired.

nmap even yelled at me.

Remember, it isn't always about how fast you break into a system.

Sometimes patience is truly key 🙏

Need coffee today.  
Critical RCE Bug Found Lurking in Avaya VoIP Phones

The vulnerability is a decade old with a public exploit, yet remained unpatched in one of the phone giant's most popular models.

Threatpost - English - Global - threatpost.com
Some fun #BlackHat shenanigans. Ruben Santamarta, a researcher at IOActive, gave a presentation about vulnerabilities he found in the Boeing 787 core network. Boeing has issued a strong denial, and has a PR rep here to boot. FAA has also chimed in, supporting Boeing.
I have been told (BUT HAVE NOT CONFIRMED) that there are Boeing engineers at the conference to refute the claims in person.
Santamarta and IOActive are emphatically standing behind their work.

Additionally, their vendor risk acceptance must be almost 0.

Some of these third-party connections their systems make are simply horrific.

At no point are they enforcing HSTS, one of their API keys for object storage is sitting right there in the source.

Their chat system is misconfigured and gives up its internal ip and the fact that backend comms are done plaintext.

Outdated JS libraries everywhere, not a single cookie is specified with HTTPOnly nor 'secure', no frame options headers/content security policy, urls of staging servers are disclosed.

So, I got bored and decided to open Burpsuite while going to my bank's site.

I didn't do anything active. Everything found was simply passive.