They also missed ERIPP, which does something similar. This is all old news though, these things are constantly mentioned in other security reports. Even the government knows these things exist, which means that CNN is not scouping anyone :)
Shodan: The scariest search engine on the Internet
121–130 of 152 posts
Re: Shodan: The scariest search engine on the Internet
#122Earlier quoted context omitted.
Shoot me an email.
Would be interesting to offer this script as "ptaas" penetration testing as a service. That way instead of having the script and having the potential to abuse the script (or temptation) someone would be forced to allow tracking of the IP (presumably their own or their companies) that they are doing the testing on (and you could compile statistics for use elsewhere as a condition if they got the script for free). I kn…
Re: Shodan: The scariest search engine on the Internet
#123Earlier quoted context omitted.
My Netgear Router N600 does exactly that. There's a nice laminated sticker on the bottom with the admin password.
Most of those types are some sort of hash of the MAC which are quickly reversed. A quick search will contain many fruitful examples. How else do you think the default password ends up the same on a system reset?
Re: Shodan: The scariest search engine on the Internet
#124Earlier quoted context omitted.
Assuming they didn't, you know, disconnect you while you were doing it. There are actual people up there; presumably they have manual overrides.
Right. I was assuming/implying a lot by saying, "if you had the controls." In the hypothetical where you have complete control of the ISS (despite manual overrides, et al), you'd still have a very hard time hitting a specific target on Earth. You could crash the thing fairly easily though. That's all I meant to say; I understand that this isn't a practical reality.
Re: Shodan: The scariest search engine on the Internet
#125Re: Shodan: The scariest search engine on the Internet
#126Eagerly awaiting the moment someone at CNN finds out about Metasploit. I'd like to think of it as a kind of "Dark Firefox".
Love this: http://www.metasploit.com/about/penetration-testing-basics/ "You can become a penetration tester at home by testing your own server and later make a career out of it." Sounds like the old style correspondence school ads - a bit hokey. http://www.thefreedictionary.com/correspondence+school I would have rewritten that as: "Many people have actually made a career out of being a penetration tester by first tes…
"By and large, Management agrees that there is but one adequate solution to the problem ... a solution that can be applied only by Management itself."
Re: Shodan: The scariest search engine on the Internet
#127I've been playing with the data from the Carna botnet output[1]. Basically someone scanned a massive portion of the Internet using broken routers as bots. There's some interesting finds in the data but analysing it is quite awkward given the size. Shodan is interesting but unless you take up a subscription is pretty limited. [1] - http://internetcensus2012.bitbucket.org/paper.html
Oh, and I've seen this in a few locations now but: NO SUBSCRIPTION REQUIRED. All of the stuff that's sold on the website is a one-time charge. There are no subscriptions on the website :)
Re: Shodan: The scariest search engine on the Internet
#128+1 for the System Shock reference :) http://en.wikipedia.org/wiki/System_Shock
Apparently it works well under wine, too.
Re: Shodan: The scariest search engine on the Internet
#129Earlier quoted context omitted.
Love this: http://www.metasploit.com/about/penetration-testing-basics/ "You can become a penetration tester at home by testing your own server and later make a career out of it." Sounds like the old style correspondence school ads - a bit hokey. http://www.thefreedictionary.com/correspondence+school I would have rewritten that as: "Many people have actually made a career out of being a penetration tester by first tes…
You can absolutely learn to do penetration testing on your own time with your own servers. We have a script we give people to do the same thing. If you feel like you have a knack for systems programming, being a good systems programmer is 1/2 the hard part of appsec; the other 1/2 is literally "taking pleasure in finding creative ways to break things", and you can find out if you have that personality streak in just…
Re: Shodan: The scariest search engine on the Internet
#130Earlier quoted context omitted.
Crazy idea, if you don't know what you're talking about, shut the hell up.
I used to be able to tell people like you to go back to Reddit. Unfortunately the quality of HN has declined far enough that your content-free insulting of a decent question is not immediately recognizable as something with no place here. I consider that fact a sad commentary on how far HN has fallen.
Also saying reddit doesn't have quality discussion is a bit unfair to the minority of subreddits that do.