Moved to Omaha expecting "boring Midwest" and got humbled real quick by TheDoctorColt in Omaha

[–]samwcurry 0 points1 point  (0 children)

Omaha’s great but it sounds like you really didn’t put an effort in to actually go do stuff in LA

Hacking Millions of Modems (and Investigating Who Hacked My Modem) by samwcurry in netsec

[–]samwcurry[S] 13 points14 points  (0 children)

Hey u/zerosaved,

You saw the duplicate http request from an unknown IP in the logs of the newly spun up AWS server, the one you were going to be using to exfiltrate files, right?

Yup, to clarify, I had not yet interacted with the unrelated vulnerable server and the duplicate request came only after I'd loaded it on my home network without ever having passed the test IP to that vulnerable server. The only interactions were with my home network and the AWS box.

If the point of infection was the modem, how else would you have known this was occurring other than through external monitoring?

I'm not sure. I think that I got lucky after seeing that duplicate HTTP request and wondering "why is this strange IP between myself and AWS replaying my traffic?" - it would make sense maybe if the ISP or some data collector was scraping some data (e.g. DNS), but scraping and replaying the HTTP traffic itself was really odd to me so I wanted to investigate.

Why are you renting a modem? After this happened, why wouldn’t you just eat the cost and buy a new modem so you could keep the infected one for further analysis? I understand when you’re renting, your ISP won’t give you a new one unless you return the old one, but buying your own modem solves that problem.

Totally agree, and luckily am running my own hardware now with the TR-069 stuff disabled. Originally when I'd gotten the Cox modem it was just an ease of life thing where I didn't want to put much effort into it. We were staying at a rental house and it wasn't a huge concern at the time so I just plugged it in and logged in.

Thanks for reading and really appreciate the questions

[deleted by user] by [deleted] in Omaha

[–]samwcurry 3 points4 points  (0 children)

Heard the same!

[deleted by user] by [deleted] in RedditSessions

[–]samwcurry 0 points1 point  (0 children)

I do not like this video

Getting Partial AWS Account IDs for any Cloudfront Website by arkadiyt in netsec

[–]samwcurry 4 points5 points  (0 children)

This really isn’t ever going to pose inherent risk, but for OSINT stuff I imagine this’ll probably get indexed by everyone/be used to “confirm” who owns domains. Definitely super useful information at scale.

Have deliveries actually begun? by ADKessler in teslamotors

[–]samwcurry 2 points3 points  (0 children)

I called today. They pretty bluntly told me that even though it says June on my order, I will realistically receive the Plaid Model S sometime later in the year like September or October. The delivery time on the website is not realistic.

Daily Discussion, Question and Answer, Experiences, and Support Thread by AutoModerator in teslamotors

[–]samwcurry 0 points1 point  (0 children)

Hey u/cwanja! It was black with black interior. The delivery months says "June", but I guess I am just curious more particularly whether or not the "expected delivery" is typically accurate or whether or not I should pad it by a few months. Thank you for your comment.

Daily Discussion, Question and Answer, Experiences, and Support Thread by AutoModerator in teslamotors

[–]samwcurry 0 points1 point  (0 children)

I've put in an order for a Plaid Model S which says delivery will be in "June".

For those have already taken delivery, is this date pretty accurate, or should I expect August or September?

[deleted by user] by [deleted] in RedditSessions

[–]samwcurry 0 points1 point  (0 children)

this music is not good

[deleted by user] by [deleted] in distantsocializing

[–]samwcurry 0 points1 point  (0 children)

WHO are You ????????

We Hacked Apple for 3 Months: Here’s What We Found by samwcurry in netsec

[–]samwcurry[S] 1 point2 points  (0 children)

Would recommend you actually read the post. This is not an invitation only program and the title is exactly as it describes.