Earlier quoted context omitted.
I don't think you could crash the ISS into New York. I don't even think that's possible. It doesn't have the engines necessary to get back to the surface.
Getting down is way easier than getting up. ISS has some engines, crashing on earth is very simple, you can just thrust in the opposite direction that you are going (thus falling into the planet, although slowly and probably astronauts can find the attacker and put it back into orbit before anything serious happens) or you can trust in a diagonal of sorts, to slow your speed AND toward the planet (if you just acceler…
Shodan: The scariest search engine on the Internet
71–80 of 152 posts
Re: Shodan: The scariest search engine on the Internet
#72Earlier quoted context omitted.
Most of those types are some sort of hash of the MAC which are quickly reversed. A quick search will contain many fruitful examples. How else do you think the default password ends up the same on a system reset?
The MAC has to be stored in flash so why not a password?
Re: Shodan: The scariest search engine on the Internet
#73Earlier quoted context omitted.
Love this: http://www.metasploit.com/about/penetration-testing-basics/ "You can become a penetration tester at home by testing your own server and later make a career out of it." Sounds like the old style correspondence school ads - a bit hokey. http://www.thefreedictionary.com/correspondence+school I would have rewritten that as: "Many people have actually made a career out of being a penetration tester by first tes…
You can absolutely learn to do penetration testing on your own time with your own servers. We have a script we give people to do the same thing. If you feel like you have a knack for systems programming, being a good systems programmer is 1/2 the hard part of appsec; the other 1/2 is literally "taking pleasure in finding creative ways to break things", and you can find out if you have that personality streak in just…
My comment strictly related to the style of what they were saying (and how I might rewrite that) I think it's a great idea.
Re: Shodan: The scariest search engine on the Internet
#74Earlier quoted context omitted.
No because the ISS would burn up way before it hit the ground.
There would be debris hitting the Earth. It's too big to completely burn I think.
Re: Shodan: The scariest search engine on the Internet
#75This is awesome, I never knew such a thing existed! But it's also quite alarming that so many devices are connected to the internet/computers that probably shouldn't be. So my big question is: Is there a way to solve this 'security failure'? And if so, what is it/is it feasible? For someone with malintentions, Shodan seems to be golden.
It used to be fairly costless to ship products without security. It still is but the more attacks there are the more incentive there is to fix stuff. But there are so many more online devices shipping...
As an example, take WordPress. I talk to people all the time who say "oh, WordPress isn't secure" even though the reasons most WordPress sites get hacked are due to practices that would make you vulnerable no matter what CMS you run -- not keeping up with security patches, running unneeded services on the server, not putting the admin area behind SSL, etc. But there's lots of people who move from WP to, say, Drupal and think that's made them secure, even as they continue doing all those same practices.
Re: Shodan: The scariest search engine on the Internet
#76+1 for the System Shock reference :) http://en.wikipedia.org/wiki/System_Shock
http://www.youtube.com/watch?v=MXPn6wcsUmk
Let's hope this Shodan isn't as intelligent and psycho as System Shock 2 Shodan! Oh, and no zombies.
Re: Shodan: The scariest search engine on the Internet
#77Re: Shodan: The scariest search engine on the Internet
#78Earlier quoted context omitted.
At least over here, traffic lights fail and turn off on their own, no need for hackers :) . Now, fixing them (for example setting up a "green wave"... hmm that could be a more interesting use :) http://en.wikipedia.org/wiki/Green_wave
I'd like to see the local lights reprogrammed to follow the legal guidelines instead of short yellows to maximize traffic ticket revenues.
Re: Shodan: The scariest search engine on the Internet
#79Earlier quoted context omitted.
Sounds like they also attempt to authenticate using default user/pass combos.
Is that legal? I've seen all kinds of analogies like "if your neighbor leaves the front door unlocked..." or "but if you go down the street testing each lock..." but never anyone who really knew what actual criminal law says.
Re: Shodan: The scariest search engine on the Internet
#80Earlier quoted context omitted.
You can absolutely learn to do penetration testing on your own time with your own servers. We have a script we give people to do the same thing. If you feel like you have a knack for systems programming, being a good systems programmer is 1/2 the hard part of appsec; the other 1/2 is literally "taking pleasure in finding creative ways to break things", and you can find out if you have that personality streak in just…
Agree. Fully understand the ability to self learn (and have done that with almost everything I've ever made a dollar on despite going to one of those good business schools which is why people think I make money rather than other qualities). My comment strictly related to the style of what they were saying (and how I might rewrite that) I think it's a great idea.