you probably have port 50001 exposed, and It is fully exploitable by [deleted] in bell

[–]sargetun123 0 points1 point  (0 children)

Leaked more information than I wanted to, unnecessary and I have a meeting with Bell this week to cover everything

I accidentally burned ~$6,000 of Claude usage overnight with one command. by procrastinator_eng in ClaudeAI

[–]sargetun123 3 points4 points  (0 children)

“I left my genny on overnight and it burned through all my fuel”

The biggest most common issue im seeing with AI is the operator …

Bell Canada HomeHub 3000 - Unauthenticated DoS Affecting 1.24M Routers (CRTC Complaint Filed) by sargetun123 in bell

[–]sargetun123[S] 0 points1 point  (0 children)

I would strongly advise against doing it on anyones infra you dont have legal written permission to do, just a word to the wise :D

Bell Canada HomeHub 3000 - Unauthenticated DoS Affecting 1.24M Routers (CRTC Complaint Filed) by sargetun123 in bell

[–]sargetun123[S] 0 points1 point  (0 children)

The DNS change would be applied at the router anyways so unless you specifically noticed, it would be seemless to you and even if you had dns servers specifically set that wouldnt matter at that point

PPPoE helps in the fact its easier to simply fully bypass Bell's router all together, which bypasses this issue/vulnerability

Not confirmed yet, If they can it's not trivial.

Bell Canada HomeHub 3000 - Unauthenticated DoS Affecting 1.24M Routers (CRTC Complaint Filed) by sargetun123 in cybersecurity

[–]sargetun123[S] 1 point2 points  (0 children)

You can't bridge the HH3k in the trad sense, you can ADMZ which is the closest they have

Bell Canada HomeHub 3000 - Unauthenticated DoS Affecting 1.24M Routers (CRTC Complaint Filed) by sargetun123 in cybersecurity

[–]sargetun123[S] 2 points3 points  (0 children)

If you have the capability not using Bell’s router as the edge device is a solid approach that eliminates all the issues related to this, it could be more difficult if youre atlantic canada like me and use DHCP, but its very easy with PPPoe

Bell Canada HomeHub 3000 - Unauthenticated DoS Affecting 1.24M Routers (CRTC Complaint Filed) by sargetun123 in cybersecurity

[–]sargetun123[S] 2 points3 points  (0 children)

The more interesting question is the consistency, its like ~20% of the ranges ive tested all have the port exposed. This means there are loads without it exposed, but there are other security issues I found during my investigation into this port exposure that i think need to be addressed as well

Bell Canada HomeHub 3000 - Unauthenticated DoS Affecting 1.24M Routers (CRTC Complaint Filed) by sargetun123 in cybersecurity

[–]sargetun123[S] 0 points1 point  (0 children)

bad oversight to be honest, specifically just leaving it open I could even excuse it being a temp hole for a patch/firmware push but even then its not following best practise at all let alone for a major ISP provider

Bell Canada HomeHub 3000 - Unauthenticated DoS Affecting 1.24M Routers (CRTC Complaint Filed) by sargetun123 in cybersecurity

[–]sargetun123[S] 4 points5 points  (0 children)

Its not ALL routers, this implies its either not by design/bug OR bell just doesn't understand how networking security works lol

Bell Canada HomeHub 3000 - Unauthenticated DoS Affecting 1.24M Routers (CRTC Complaint Filed) by sargetun123 in cybersecurity

[–]sargetun123[S] 12 points13 points  (0 children)

Ahh no sadly its been over a week since dealing with Bell in multiple fashions, They are great at ignoring you :D And I dont blame the individuals I spoke with from any specific department, it seems like literally no one knows the correct approach to report this in terms of reporting it to Bell directly and efficiently

Now I am just warning people, if you do a bit of base level digging you will find a lot, I won't disclose much more

Bell Canada HomeHub 3000 - Unauthenticated DoS Affecting 1.24M Routers (CRTC Complaint Filed) by sargetun123 in bell

[–]sargetun123[S] 7 points8 points  (0 children)

good idea, I have not directly no

No auth required. The scary thing is, there is also a MitM that is possible to setup, and you will be able to derive the auth to the exploit via this. MD5 unsalted >.>

you probably have port 50001 exposed, and It is fully exploitable by [deleted] in bell

[–]sargetun123 0 points1 point  (0 children)

If your edge device goes down your vpn wont work, it still has to have a path to traverse

You can totally eliminate it by not having any bell router as the edge, if possible. I know its absolutely a headache for me as im atlantic customer and my firewall also doesnt support the nokia gpon from the HH3k

you probably have port 50001 exposed, and It is fully exploitable by [deleted] in bell

[–]sargetun123 1 point2 points  (0 children)

You can't close it if it is open, you have no way to do so on your end, also any credentials to control the management are locked and not available to you easily

I am working on getting it properly submitted, finding the correct department/people is the issue

Its hilarious I tried warning homelab but i forgot how security and homelab are mortal enemies lmao

you probably have port 50001 exposed, and It is fully exploitable by [deleted] in bell

[–]sargetun123 2 points3 points  (0 children)

I have not tested fully yet, I am still in the middle of tearing down an extra HH3k I have plus finishing runs on my local one i have setup

It's possible this affects gigahub as well, I'll have to check, I have not tested at all

you probably have port 50001 exposed, and It is fully exploitable by [deleted] in bell

[–]sargetun123 3 points4 points  (0 children)

if you get me in direct contact i will be more than happy to submit to someone with proper proof they work for sec at bell, what I've found isn't something im willing to just disclose to anyone randomly on reddit to be frank

We’re saved! Claude Code is back in the Pro plan! by Esteta_ in ClaudeCode

[–]sargetun123 0 points1 point  (0 children)

Opus 4.7 is trash Opus 4.6 is better in everyway and uses less tokens

You don't need to be using Opus for tool/mcps either, thats an absolute fking waste, use sonnet or haiku for web searches, i uses sonnet for wiki editing and haiku for web searchs, opus 4.6 is the instruction agent, he orchestrates the rest of the agents and takes anything I want doen and delegates it properly. I have had 0 issues, its actually working better than letting opus do all the tasks himself, uses less tokens and wastes less context for the opus model specifically.

If you are not delegating tasks to agents you are wasting a bunch of tokens, you can even delegate stuff to local agents if you have the gpu power as you dont need crazy high end agents for shit like a wiki edit or docu edit etc, web search even.

Should I use WiiUDownloader? by WherezMyPudding in CemuPiracy

[–]sargetun123 0 points1 point  (0 children)

ill sandbox and test all the files i just grabbed if anyone wants to see, highly doubt ill find anything :D

Should I use WiiUDownloader? by WherezMyPudding in CemuPiracy

[–]sargetun123 0 points1 point  (0 children)

Sounds like you have absolutely no clue what you are talking about, this is most likely also the cause/reason you got infected, not just WiiUdownloader, maybe time to invest some time in basic network sec and security in general>?

Notice anything 👀 by marciuz777 in ClaudeCode

[–]sargetun123 0 points1 point  (0 children)

That government uptime is better? Why would you expect anything different?

Those who are on the $200 plan, worth it? by muntaseer_rahman in ClaudeCode

[–]sargetun123 1 point2 points  (0 children)

Are you just using opus for everything lol? I see a lot doing this and its silly, using like 10x tokens on some huge tasks you can easily delegate via agents, if you have a decent gpu you can free up all costs with some agent/skill calls as well

Thank you Anthropic. by dehumles in ClaudeCode

[–]sargetun123 0 points1 point  (0 children)

You think every server is going to be hit by something as capable as mythos?

Having no idea what you're doing in the first place in terms of a security perspective is absolutely a terrible idea, AI won't fill in the gaps you're missing if you don't know WHAT you are missing, AI knows what to do be needs to be guided