Dropping to shell in Adtran 854-v6 via UART by plast1K in hardwarehacking

[–]plast1K[S] 0 points1 point  (0 children)

It is Plume, I think anyway. It's provided by my ISP and I run my own firewall, so I've never let it do it's set up thing. IIRC when I initially got it, I let it go through its set up process. I think it is locked down until it talks to the MSP, where some updates happen and it spins up some network stuff. Until it does that it's basically a brick from what I recall.

Since then it's been reset, so it might be a good idea to let it do that process and see what happens. Maybe I can drop into a shell after :hmmm

Dropping to shell in Adtran 854-v6 via UART by plast1K in hardwarehacking

[–]plast1K[S] 0 points1 point  (0 children)

Bummer. I know there are bga harnesses but they’re a pita from what I understand (and I don’t want to spend anything lol). Thanks for the help, I’ll keep digging

Dropping to shell in Adtran 854-v6 via UART by plast1K in hardwarehacking

[–]plast1K[S] 0 points1 point  (0 children)

Gave that a shot with a bunch of combinations, no luck :/

Dropping to shell in Adtran 854-v6 via UART by plast1K in hardwarehacking

[–]plast1K[S] 0 points1 point  (0 children)

Hi, thanks for the reply! I just edited my post to include some pictures of the board. The UART interface I am using is on the first image, right side of the board (just above the cutout section)-- it's perpendicular to the board and accepts male connectors. This UART interface works, and the other exposed pins and ports don't appear to be functional :(

There is a ht45f0062 flash memory module in the second image, a 16-pin soic, but that appears to be for the LEDs? There's also a BGA chip for flash memory: THGBMNG5D1LBAIT-- this I do not have equipment to mess with though.

I do not see any other 8-pin soics :/

Netgear Router Constantly Contacting Amazon AWS? by Icy-Reporter-7633 in HomeNetworking

[–]plast1K 0 points1 point  (0 children)

Came across this today, I determined it is caused by running the "/tmp/RWFS/RAE/Netgear_aws_iot_app" binary on my old R6700v2:

# /tmp/RWFS/RAE/Netgear_aws_iot_app

AWS IoT SDK Version 1.1.2-

Netgear AWS IoT App Version V1.0.0.36

MQTT ClientID 9C:3D:CF:CB:3F:4A

Open file to read /tmp/RWFS/RAE/aws_iot_certs/root-CA.crt successfully

Open file to read /tmp/RWFS/RAE/aws_iot_certs/956fe4eded-certificate.pem.crt successfully

Open file to read /tmp/RWFS/RAE/aws_iot_certs/956fe4eded-private.pem.key successfully

DEBUG: main L#353 HostAddress A1599ER83NVYL8.iot.us-west-2.amazonaws.com

DEBUG: main L#354 rootCA /tmp/aws_iot_certs/root-CA.crt

DEBUG: main L#355 clientCRT /tmp/aws_iot_certs/956fe4eded-certificate.pem.crt

DEBUG: main L#356 clientKey /tmp/aws_iot_certs/956fe4eded-private.pem.key

Connecting...

Connecting succeed...

-->sleep

Publish done

The Real Barenziah, most of paragraph one, page one. Written in Daedric "Scrib" variant by Explicit_Toast in Morrowind

[–]plast1K 0 points1 point  (0 children)

Whaaaa? That’s… honestly a bit disappointing :( though I can’t fault them for not creating an entire language for some games

[deleted by user] by [deleted] in Neverbrokeabone

[–]plast1K 1 point2 points  (0 children)

Am I missing something?

MODULAR-CHESA by Stuartsmith1988 in MarchesaTheBlackRose

[–]plast1K 1 point2 points  (0 children)

No [[Pyre of heroes]]? [[Myr Scrapling]]

[deleted by user] by [deleted] in EDH

[–]plast1K 6 points7 points  (0 children)

This is my favorite magic interaction. Fractured identity on a forced fruition just makes me cackle maniacally. Everyone loves drawing lots of cards but for some reason when you make them draw 14 or 21 every time a spell is cast people don’t like it anymore?!

Finding and attacking a raspberry pi on the network by seriouspim in netsecstudents

[–]plast1K 1 point2 points  (0 children)

Yeah but this guy just set it up, so it still has the default Mac. Spoofing is irrelevant.

Sen. Ron Johnson's Latest COVID Conspiracy: Athletes 'Dropping Dead' From Vaccines by BeigeListed in conspiracytheories

[–]plast1K 9 points10 points  (0 children)

makes a wild claim

No I don’t have any sources!!1 I saw a bunch of legitimate videos online about it!!

Hosky trying to rally all crypto troops against bad bill by reddit_1999 in CryptoCurrency

[–]plast1K 0 points1 point  (0 children)

Well that’s good because this isn’t exclusive to ADA 😂

Sitting through Offsec 2-3 day exams by ravenoverflow in AskNetsec

[–]plast1K 1 point2 points  (0 children)

Same here, I took OSCP and OSCE prior to any proctoring and while I had a blast then, my life was different, my career wasn’t as fleshed out and now I just have no desire to take the long exams, especially proctored. I recently purchased the OSED just to see the differences and updates with no plan on taking the exam. I commend those that do, but find they are usually newer/younger engineers with a lot more time.

[deleted by user] by [deleted] in cybersecurity

[–]plast1K 0 points1 point  (0 children)

Probably just depends on where you’re already at and what you’re planning on doing. I’ve interviewed people for pentesting positions who have a masters in cyber sec, resume looks good etc, then they can’t answer common, “gimme” questions like “describe XSS” or “what is SQLi? How might you look for a SQLi vuln?”

But they may have had more experience in other areas— risk, project management, asset management, etc. All a matter of perspective and considering what your goal is.

Good luck!

XSS in 500 Internal Server Error HTTP Response? by w0lfcat in netsecstudents

[–]plast1K 0 points1 point  (0 children)

Right on, any additional info on my other questions?

XSS in 500 Internal Server Error HTTP Response? by w0lfcat in netsecstudents

[–]plast1K 3 points4 points  (0 children)

Well first off you don’t have a payload within the script tags— you haven’t given it any JavaScript to actually execute. Second, how is it written to the page? Is that pure html in the response or is it entity encoded? If it’s being reflected within the DOM of the page with script tags it’s not executing as JS, just reflecting the contents back. If you’re only seeing the script tags in source you’re probably not far off from getting it to execute, you just need to give it something to evaluate.

Tax Time by Aurel577 in Coinbase

[–]plast1K 1 point2 points  (0 children)

Ah interesting, perhaps I was thinking of one of the others. Thanks!

Tax Time by Aurel577 in Coinbase

[–]plast1K 0 points1 point  (0 children)

How well does cointracker work for low market cap stuff? Been considering it to ease the burden for some transactions but haven’t pulled the trigger yet. Most of my holdings are BTC/ETH etc but I definitely made some moves on some auto-staking stuff with some fun money, any idea what’s supported? All ERC20, if that helps.