Live data from Hacker News

Security Researcher Assaulted Following Vulnerability Disclosure

secjuice.com

81–90 of 118 posts

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#81

Earlier quoted context omitted.

In the off chance that you're serious, this sounds like a great way to land yourself in federal prison.

> a great way to land yourself in federal prison. For what? Checking shodan and seeing that people don't know how to write secure code.

Ask Weev how it worked out for him.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#82
post #38

To assault a programmer on the floor of a conference and expect to get away with says a lot about what this person has likely gotten away in their past.

Yeah, especially a tech conference. Everyone has phones with cameras, vloggers and journalists covering things.

I know there are stories of casinos in Vegas breaking people's legs for cheating, but I guess that doesn't happen anymore since big corporations run them now with too much to lose. Plus if that ever happened and went viral, it would hurt their business.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#84

Earlier quoted context omitted.

That still doesn't make any sense to me in the context of the rest of the sentence.

Possibly, existing kiosks are registered by MAC address in the API. By querying the API for registered kiosks, you can pretend to be one by spoofing the MAC

I wonder if Casino's run their machines, etc on the same network as guests are on at the hotel, etc...

I'd think they'd at least isolate the networks to at least make things a bit harder... Maybe you could be sneaky and unplug an ethernet cable and plug in a device but apparently, the eye in the sky would catch you, and end up in serious trouble.

I know some probably have apps to check your rewards, etc but that probably would run on the public internet with some sort of proxy into their private databases.

I'm not really into gambling, the family took me once when I turned 21 and was kinda boring. I just waited around while everyone else played video pocket. Free Mt. Dew though...

Also, all the woman seem to wear something to show off their breasts more, I guess more tips... So stereotypical like you'd see on television.

At least they banned smoking in casinos, I guess in the old day's people would be smoking right next to you. Oh, Google'd it and it seems like they allow it in Vegas at the casino and bar, just not restaurants. Wow. I believe in my state it's a standard ban inside completely of any public building.

Also, reports of Atlantic City dying now since more and more states have allowed Casino's to open. I seem to associate gambling with Vegas though over any other city.

I wouldn't mind going to just play the slots someday again, but really not into wasting money right now.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#85

Earlier quoted context omitted.

> Sometimes I think the terrible web sites they have for hotel reservations are just a smokescreen. Captain Obvious says he'd imagine that the amount of money brought in from room reservations is a drop in the bucket to what is made on the casino floor, hence the comping of rooms for players. The money spent on reservations vs protecting the gaming would be in proportion to that. Maybe Captain Obvious is being a bit…

Everything about the hotel is geared to get you to lose your money in the casino. That's last century thinking. Gambling's influence on the bottom line domestically is waning. These days it's all about entertainment, clubs, and restaurants. That's why every casino in Las Vegas is falling all over itself to build new sports and entertainment arenas, and paying huge bucks to put celebrity chef names on their restaurant…

That sounds like the mindset they must have used when they had the Vegas is family friendly ad campaign. That failed, and the What happens in Vegas campaign took over. I would have a hard time believing concerts, magic shows, celeb chefs generate the same kind of money that the casinos and sports betting brings in. However, if you have something that backs that up, I'd definitely be willing to read it and change my view.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#86

Earlier quoted context omitted.

In the off chance that you're serious, this sounds like a great way to land yourself in federal prison.

> a great way to land yourself in federal prison. For what? Checking shodan and seeing that people don't know how to write secure code.

Dude, just don't.

I get the excitement of knowing how easy it is to do this stuff. But US Federal Laws can be interpreted in creative ways to throw you in Federal Prison. And I think that will continue to be the case until American society (the Jury, in US) learns more about how these things work.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#87
post #73

Earlier quoted context omitted.

Not in the UK the police only really get involved if blood is drawn aka GBH.

So you're saying that in the UK I can legally walk around shoving and slapping people at random?

No, thats not what he said.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#88

Earlier quoted context omitted.

That still doesn't make any sense to me in the context of the rest of the sentence.

Possibly, existing kiosks are registered by MAC address in the API. By querying the API for registered kiosks, you can pretend to be one by spoofing the MAC

I still don't understand it, TCP/IP doesn't transmit MAC addresses. Your knowledge of it ends at the next router... Therefore you definitely can't authenticate/authorize by MAC address.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#89
post #88

Earlier quoted context omitted.

Possibly, existing kiosks are registered by MAC address in the API. By querying the API for registered kiosks, you can pretend to be one by spoofing the MAC

I still don't understand it, TCP/IP doesn't transmit MAC addresses. Your knowledge of it ends at the next router... Therefore you definitely can't authenticate/authorize by MAC address.

> Therefore you definitely can't authenticate/authorize by MAC address.

I would be entirely unsurprised to see that the device is calling out to the API with it's MAC address as some kind of authenticator.

eg: http://foo.example.com/api/prizes?id=xx:xx:xx:xx:xx

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#90
post #2

If you (like me) didn't know what a Shodan safari is, you're in for a fun ride: https://techcrunch.com/2019/01/21/shodan-safari/

Without Oath's abusive GDPR wall: https://outline.com/JF28AH

It's quite ironic that I can view the techcrunch.com link without JS just fine, but the outline.com link requires me to allow JS on at least 2 domains before viewing the content.
Post reply on HN