1
submitted 1 month ago* (last edited 3 weeks ago) by to c/hacking@lemmy.ml
 
 

So, a while ago I left a raspberry pi at my parents house, with their permission, intending to use it as a VPN connection since they live in a different country.

Problem is, I didn't know I had to enable Sudo over SSH. So now I can SSH onto it, but can't run Sudo. So I can't install anything, like OpenVPN.

My parents are not literate enough to help. How can I do this?

Edit: PRETTY_NAME="Raspbian GNU/Linux 11 (bullseye)"

Linux raspberrypi 6.1.21-v7+ #1642 SMP Mon Apr 3 17:20:52 BST 2023 armv7l GNU/Linux

Raspberry Pi 2 Model B Rev 1.1

Installed is the raspian desktop, and Zerotier for the SSH login.

2
 
 

So this is just a question that popped into my mind the other day, sorry if it doesn't fit the community.

At the local pharmacy I noticed two USB ports on the back of the monitors they were using and I was thinking I could've easily gotten a RAT in there if I was more smart and malicious.

Similar places were banks or shops, sometimes ethernet ports as well.

Realistically, how dangerous is this? Thanks for any answers.

3
 
 

I am looking for a good USB card for pentesting.

Apparently, only those two are in stock and support Kali Linux (or at least that's what the website says)

https://alfa-network.eu/wi-fi/kali-linux-compatible/awus036acs

https://alfa-network.eu/wi-fi/kali-linux-compatible/awus036achm

Are they good enough for WiFi pentesting? I will be close to the router so I do not need a card with a great range.

4
The CLODO knew (archive.org)
submitted 5 months ago by to c/hacking@lemmy.ml
 
 

Committee for Liquidation or Subversion of Computers (French: Comité Liquidant ou Détournant les Ordinateurs; CLODO being a slang word for the homeless) was a French neo-Luddite anarchist organization that attacked computer and telecommunications companies in the early 1980s. The group was motivated by concerns over the growing ubiquity of telecommunications and potential misuse of computers by governments to strip freedoms from the general population. CLODO's targets were mainly located in Toulouse, France. CLODO carried out attacks in 1980 and 1983 with a two-year hiatus in-between; targets included: CII Honeywell Bull, International Computers Limited, and Sperry.

The group released a manifesto in 1983 and has been classified as inactive by the National Consortium for the Study of Terrorism and Responses to Terrorism since their final attack in December 1983. The 2022 experimental documentary Machines in Flames details CLODO's activities and ideologies. None of its members have been identified to date.

5
 
 

Whether it's hacking a neighbor's wifi or accessing a satellite network for free, I don't really care.

Does anyone know how to do this?

6
 
 
7
 
 

Hello fellow hackers and cyberpunk enthusiasts,

After 12 months of writing and research, I’m excited (and honestly a bit nervous) to share my first tech-thriller novella “Connection Timeout: The PingStarved Chronicles” with this community. This is my first time publishing fiction, so I’m both shy and thrilled to finally put it out there.

Set in 2030 Barcelona, it follows Andrés “PingStarved” Reyes, a 56-year-old. When mysterious forces target his old friend—a surveillance company CEO who sold out their shared ideals—and threaten to unleash chaos unless Andrés surrenders his greatest creation—a revolutionary mesh networking protocol that could free global communications—he faces an impossible choice.

What makes this different from typical cyberpunk:

Features real mesh networking protocols (Meshtastic, Reticulum) Based on actual security research and exploitation techniques Grounded in technologies currently in development Authentic hacker culture representation - written by someone who lives it NO DRM - All formats are DRM-free because information wants to be free This has been a labor of love, combining my passion for privacy tech and resistance against surveillance capitalism into a narrative that I hope resonates with our community. As someone who’s been hacking for years but never written fiction before, I poured everything I know and believe about our culture into these pages.

Details:

29,429 words (86 pages, 2-3 hour read) Available in PDF and EPUB formats Price: $4.99 USD / €4.99 EUR DRM-FREE on all platforms Available at:

Gumroad (DRM-FREE): https://rek2.gumroad.com/l/connection-timeout-cyberpunk Amazon Kindle US: https://www.amazon.com/dp/B0FPZ18STC Amazon Kindle Spain: https://www.amazon.es/dp/B0FPZ18STC Also available on Amazon in UK, Germany, France, Italy, Japan, Canada, Australia, and many other countries If you enjoyed Neuromancer, Little Brother, or Mr. Robot, this explores similar themes of surveillance capitalism, digital liberty, and technological resistance - but grounded in the real tech we’re building today.

Any feedback from the community would mean the world to me. Thanks for reading!

P.S. - For those who prefer open platforms, the Gumroad version comes with both PDF and EPUB, completely DRM-free. Support indie publishing and digital freedom!

8
 
 

So, I know this sounds a little stereotypical, but I'm terrible with people. I know that social engineering is an excellent tool and can speed up things like active recon, but I just can't figure it out. Does anyone know any resources for learning or just have general tips?

9
 
 

cross-posted from: https://sh.itjust.works/post/42358249

cross-posted from: https://sh.itjust.works/post/42358197

And if so, what are you most excited about?!

10
11
 
 

Hey everyone yesterday I was at a grocery store and I noticed suspicious WiFi networks and Bluetooth networks. I am quite tech savvy so I decided to investigate thinking it was probably just some skid. But when I opened Wireshark I saw the mac addressees for Cisco Merkari (A relatively advanced DPI program) , along with multiple other enterprise grade tools such as Fortinet and VMware. I have collected pcaps for both my Bluetooth and WiFi interfaces with Wireshark(available upon request). Does anyone have any idea could this be a government contractor? Or could it just be spoofed cause its relatively easy to spooph Mac addresses.

12
 
 

I really don't know how to explain but hacking is difficult to understand. Like I watched tutorials on Youtube, took courses and read many books but still I feel like I know nothing. Watching Mr Robot and other documentation made feel even worse, you might say Mr Robot doesn't portray the real world but the documentation do. Like this video I was completely baffled at how I didn't have a single clue how they did it what techniques they used.

After all that though, I don't want to give up on hacking, I want to learn more advanced stuff. If you have an recommendations please dm me or comment.

Sorry for my bad english learning to write too.

13
14
 
 

Hi as per above , Any1 have experience? Was given this bluray, it's still running old firmware, hesistant to upgrade, but was hoping for some kung fu firmware hack on the new firmware to be installed, to make this so 🤷. Have checked online and nada.

https://org.downloadcenter.samsung.com/downloadfile/ContentsFile.aspx?CDSite=UNI_AU&OriginYN=N&ModelType=N&ModelName=BD-D5300&CttFileID=3864250&CDCttType=FM&VPath=FM%2F201307%2F20130726182311156%2FB-BRCM53BSP.zip

Tx 4 reading

15
test (lemmy.one)
submitted 1 year ago by to c/hacking@lemmy.ml
 
 

Test

16
X is down (slrpnk.net)
submitted 1 year ago by to c/hacking@lemmy.ml
 
 
17
 
 
18
19
 
 

Hi folks, not sure if this is the right place but so please lmk if there is a better place to put this:

I'm currently attempting to reverse engineer yealink t41p IP phone firmware since the device is out of support for some years and but works very well imo. For security reasons and keeping the devices out of the trash, I would like to provide open source firmware for it. I recently learned how the process with clean room reversing works but I'm stumbling at the first step already. Here is what I attempted so far:

haui@TowerPC:~/Downloads/t41p-firmware$ binwalk T41-36.83.0.160.rom 

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------

haui@TowerPC:~/Downloads/t41p-firmware$ binwalk --signature T41-36.83.0.160.rom 

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------

haui@TowerPC:~/Downloads/t41p-firmware$ binwalk -E T41-36.83.0.160.rom 

DECIMAL       HEXADECIMAL     ENTROPY
--------------------------------------------------------------------------------
16384         0x4000          Rising entropy edge (0.984980)
20480         0x5000          Falling entropy edge (0.783278)
32768         0x8000          Rising entropy edge (0.992664)
45056         0xB000          Falling entropy edge (0.601562)
65536         0x10000         Rising entropy edge (0.991434)
815104        0xC7000         Rising entropy edge (0.992069)
2945024       0x2CF000        Falling entropy edge (0.668870)
2949120       0x2D0000        Rising entropy edge (0.993514)
8155136       0x7C7000        Falling entropy edge (0.843171)

haui@TowerPC:~/Downloads/t41p-firmware$ binwalk -BE T41-36.83.0.160.rom 

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------


DECIMAL       HEXADECIMAL     ENTROPY
--------------------------------------------------------------------------------
16384         0x4000          Rising entropy edge (0.984980)
20480         0x5000          Falling entropy edge (0.783278)
32768         0x8000          Rising entropy edge (0.992664)
45056         0xB000          Falling entropy edge (0.601562)
65536         0x10000         Rising entropy edge (0.991434)
815104        0xC7000         Rising entropy edge (0.992069)
2945024       0x2CF000        Falling entropy edge (0.668870)
2949120       0x2D0000        Rising entropy edge (0.993514)
8155136       0x7C7000        Falling entropy edge (0.843171)

haui@TowerPC:~/Downloads/t41p-firmware$ binwalk -y T41-36.83.0.160.rom 
haui@TowerPC:~/Downloads/t41p-firmware$ binwalk -e T41-36.83.0.160.rom 

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------

haui@TowerPC:~/Downloads/t41p-firmware$ binwalk -I T41-36.83.0.160.rom 

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------
12622         0x314E          BFF volume entry, AIXv3, file name: "iX2jÅ

haui@TowerPC:~/Downloads/t41p-firmware$ binw^C

haui@TowerPC:~/Downloads/t41p-firmware$ binwalk -G T41-36.83.0.160.rom 

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------
20
21
 
 

https://inscaptions.com/how-to-see-private-accounts-on-instagram-using-inspect/

https://techcult.com/how-to-access-private-instagram-inspect-element/

I don’t know anything about programming, and sadly I can’t differentiate between rubbish webpages and the real deal when it comes to stuff like that..

I also read about a couple of ios shortcuts that claim to be able to download private Instagram posts if you have the link to it.. is it true?

22
23
 
 

Apologies is this seems somewhat weird, I was using the reddit app on my iphone when I clicked on a tag in my search history and at the same time I noticed my flash go off on my phone. I suppose this could have been some strange hardware issue in my phone, but I suspected it took a photo. I checked my photo stream and there was nothing new. There is no log of events on my phone I know of, but I wondered if it was intentional. Curious if anyone here has any idea if it could have been something intentional (it taking a photo), or maybe some log info source I could check to see if it was legitimate hack.

24
Best fuzzing tool (programming.dev)
 
 

I'm trying to find a good fuzzing tool for testing my web applications and was wondering what people would recommend. I'm trying to find one that is open source, free, and doesn't use proprietary stuff. It seems like Google's OSSFuzz is the closest option to what I'm looking for, but it uses Google cloud :/

25
 
 

Security researchers have discovered new Bluetooth security flaws that allow hackers to impersonate devices and perform man-in-the-middle attacks.

The vulnerabilities impact all devices with Bluetooth 4.2 through Bluetooth 5.4, including laptops, PCs, smartphones, tablets, and others.

Users can do nothing at the moment to fix the vulnerabilities, and the solution requires device manufacturers to make changes to the security mechanisms used by the technology.

Research paper: https://dl.acm.org/doi/pdf/10.1145/3576915.3623066

Github: https://github.com/francozappa/bluffs

CVE: https://nvd.nist.gov/vuln/detail/CVE-2023-24023

view more: next ›