Live data from Hacker News

Shodan: The scariest search engine on the Internet

money.cnn.com

71–80 of 152 posts

Re: Shodan: The scariest search engine on the Internet

#71
post #35

Earlier quoted context omitted.

I don't think you could crash the ISS into New York. I don't even think that's possible. It doesn't have the engines necessary to get back to the surface.

Getting down is way easier than getting up. ISS has some engines, crashing on earth is very simple, you can just thrust in the opposite direction that you are going (thus falling into the planet, although slowly and probably astronauts can find the attacker and put it back into orbit before anything serious happens) or you can trust in a diagonal of sorts, to slow your speed AND toward the planet (if you just acceler…

It seems like the harder part would be hitting New York. You could crash the ISS somewhere on Earth pretty trivially, if you had the controls.

Re: Shodan: The scariest search engine on the Internet

#72

Earlier quoted context omitted.

Most of those types are some sort of hash of the MAC which are quickly reversed. A quick search will contain many fruitful examples. How else do you think the default password ends up the same on a system reset?

The MAC has to be stored in flash so why not a password?

Usually the MAC is stored in the network card's flash while the system image is stored in a different flash altogether, which is often cheaper if you can find a way to get away with making them all exactly the same.

Re: Shodan: The scariest search engine on the Internet

#73
post #58
post #55

Earlier quoted context omitted.

Love this: http://www.metasploit.com/about/penetration-testing-basics/ "You can become a penetration tester at home by testing your own server and later make a career out of it." Sounds like the old style correspondence school ads - a bit hokey. http://www.thefreedictionary.com/correspondence+school I would have rewritten that as: "Many people have actually made a career out of being a penetration tester by first tes…

You can absolutely learn to do penetration testing on your own time with your own servers. We have a script we give people to do the same thing. If you feel like you have a knack for systems programming, being a good systems programmer is 1/2 the hard part of appsec; the other 1/2 is literally "taking pleasure in finding creative ways to break things", and you can find out if you have that personality streak in just…

Agree. Fully understand the ability to self learn (and have done that with almost everything I've ever made a dollar on despite going to one of those good business schools which is why people think I make money rather than other qualities).

My comment strictly related to the style of what they were saying (and how I might rewrite that) I think it's a great idea.

Re: Shodan: The scariest search engine on the Internet

#74
post #10

Earlier quoted context omitted.

No because the ISS would burn up way before it hit the ground.

There would be debris hitting the Earth. It's too big to completely burn I think.

Perhaps, but ~70% of the Earth is empty ocean, and lots of the remainder is relatively empty landmass (huge deserts, unpopulated areas like Siberia, etc.), so just from a statistical perspective the odds of something that survives re-entry hitting a populated area without remote guidance are pretty slim.

Re: Shodan: The scariest search engine on the Internet

#75

This is awesome, I never knew such a thing existed! But it's also quite alarming that so many devices are connected to the internet/computers that probably shouldn't be. So my big question is: Is there a way to solve this 'security failure'? And if so, what is it/is it feasible? For someone with malintentions, Shodan seems to be golden.

It used to be fairly costless to ship products without security. It still is but the more attacks there are the more incentive there is to fix stuff. But there are so many more online devices shipping...

Part of the problem too is that when a particular product is compromised, most people stop at "Product X sucks" and don't ask themselves if the same vulnerabilities are present in products they themselves use.

As an example, take WordPress. I talk to people all the time who say "oh, WordPress isn't secure" even though the reasons most WordPress sites get hacked are due to practices that would make you vulnerable no matter what CMS you run -- not keeping up with security patches, running unneeded services on the server, not putting the admin area behind SSL, etc. But there's lots of people who move from WP to, say, Drupal and think that's made them secure, even as they continue doing all those same practices.

Re: Shodan: The scariest search engine on the Internet

#76

+1 for the System Shock reference :) http://en.wikipedia.org/wiki/System_Shock

Gah, still get creeped out watching the System Shock 2 intro.

http://www.youtube.com/watch?v=MXPn6wcsUmk

Let's hope this Shodan isn't as intelligent and psycho as System Shock 2 Shodan! Oh, and no zombies.

Re: Shodan: The scariest search engine on the Internet

#77
post #14

+1 for the System Shock reference :) http://en.wikipedia.org/wiki/System_Shock

Man, I found that game to be _very_ bad for my nerves in the 90s.

Me too. Scary game. Nothing else has come near to it.

As a tribute, my workstation and laptop are names xerxes and shodan.

Re: Shodan: The scariest search engine on the Internet

#78
post #62

Earlier quoted context omitted.

At least over here, traffic lights fail and turn off on their own, no need for hackers :) . Now, fixing them (for example setting up a "green wave"... hmm that could be a more interesting use :) http://en.wikipedia.org/wiki/Green_wave

I'd like to see the local lights reprogrammed to follow the legal guidelines instead of short yellows to maximize traffic ticket revenues.

Consider yellow to mean "stop", and the length of it becomes irrelevant and the roads become a little bit safer.

Re: Shodan: The scariest search engine on the Internet

#79
post #44

Earlier quoted context omitted.

Sounds like they also attempt to authenticate using default user/pass combos.

Is that legal? I've seen all kinds of analogies like "if your neighbor leaves the front door unlocked..." or "but if you go down the street testing each lock..." but never anyone who really knew what actual criminal law says.

It is a grey area, at least in the US. The main federal law for computer crimes is the ancient Computer Fraud and Abuse Act. The provisions of the act state all work off the concept of "exceeding authorized access" - but the law never defines what authorized access actually is. Logging in with a default username and password has never been tested in court, as far as I know, and I think there are arguments to be made for both sides about whether that counts as authorized access.

Re: Shodan: The scariest search engine on the Internet

#80
post #73
post #58

Earlier quoted context omitted.

You can absolutely learn to do penetration testing on your own time with your own servers. We have a script we give people to do the same thing. If you feel like you have a knack for systems programming, being a good systems programmer is 1/2 the hard part of appsec; the other 1/2 is literally "taking pleasure in finding creative ways to break things", and you can find out if you have that personality streak in just…

Agree. Fully understand the ability to self learn (and have done that with almost everything I've ever made a dollar on despite going to one of those good business schools which is why people think I make money rather than other qualities). My comment strictly related to the style of what they were saying (and how I might rewrite that) I think it's a great idea.

I would also like to get in on this circle jerk. You should totally start up a business where you claim to know stuff about security because you port scanned your Linux box. YOu can take their money and then they can get hacked then who cares? You have money. It's great that we can provide so much to the community here!
Post reply on HN