Earlier quoted context omitted.
so the spoofer distributing these devices is going to all this trouble/expense/risk in the hope there is a http downloaded exe it can corrupt, then hopes the hashing doesn't fail on that corrupt exe, and hopes the user ignores the untrusted source warning so that it can install a trojan?
How many users do you know of who manually check hashes on downloaded executables? And of course the user is going to ignore the untrusted source warning on an executable they intentionally downloaded and are trying to run.
Found hooked up to my router
91–100 of 358 posts
Re: Found hooked up to my router
#92Earlier quoted context omitted.
Yeah, I have no idea how it could accomplish what is alleged. Just lots of very bad no good end of world comments. Have none of these people ever used public wifi?
Have none of these people ever used public wifi? This situation is totally totally unlike public wifi! When I connect to public wifi, the attack surface into my laptop is the external interface of the latest MacOS, with firewall on. Perhaps there are exploits against that, but they're not common. The Mac does have pf, but I'm sure it's a way out of date version! :) OTOH, "this thing" on the inside of a router/firewal…
To be honest, I found that easier than prudence and caution. New access point, stick all my IoT devices on there, then I don't have to particularly worry about what they are doing, they can't access anything interesting anyway (no outbound traffic, inbound traffic is only allowed from one device on my LAN).
Re: Found hooked up to my router
#93Interesting that it is "worth" $15/month. Maybe they were never going to pay up. But if they were, that seems expensive when they could just use compromised PCs and devices for ... whatever they are going to do? Plus they had to buy and supply the dongle.
Re: Found hooked up to my router
#94Earlier quoted context omitted.
The user can just be redirected to another similar looking site with a valid TLS certificate.
How?
This will seem like a valid website, especially if the phishing site is done well. Not just non-technical users, I'd wager some tech familiar users would be fooled too.
The focus always being on the lock icon might not always cover it.
Safari will prevent this though.
Re: Found hooked up to my router
#95Earlier quoted context omitted.
The spoofer can obtain a valid certificate for another, seemingly legitimate site. Any software that hasn't explicitly pinned the leaf TLS certificates will still accept the (valid) certificate it is redirected to. And sadly, a lot of software still doesn't perform certificate pinning.
How is this redirect performed?
Re: Found hooked up to my router
#96Earlier quoted context omitted.
The spoofer wouldn’t be able to obtain a valid certificate for the spoofed site, though.
The spoofer can obtain a valid certificate for another, seemingly legitimate site. Any software that hasn't explicitly pinned the leaf TLS certificates will still accept the (valid) certificate it is redirected to. And sadly, a lot of software still doesn't perform certificate pinning.
Re: Found hooked up to my router
#97Earlier quoted context omitted.
The spoofer can obtain a valid certificate for another, seemingly legitimate site. Any software that hasn't explicitly pinned the leaf TLS certificates will still accept the (valid) certificate it is redirected to. And sadly, a lot of software still doesn't perform certificate pinning.
How is this redirect performed?
Re: Found hooked up to my router
#98Re: Found hooked up to my router
#99Re: Found hooked up to my router
#100Earlier quoted context omitted.
My college used to do similar. If you did not register your MAC address, you would be DHCP assigned into a walled-garden IP block. We found we could run an IP scanner on the authorized subnet (from a computer with a whitelisted MAC), and find the unused IPs, and just set those statically for 'visitors'. No need to register any more MAC addresses.
I doubt they were very concerned with you or your friends. 80/20 solutions.
Oh, and all authorized IPs were in a public address space.