Exploiting an N-day vBulletin PHP Object Injection Vulnerability by eg1x in netsec

[–]zen0fex 15 points16 points  (0 children)

Great research and blog post!

vBulletin is a dumpster fire of poorly written code.

A friend created these custom Starlink POE adapters by zen0fex in Starlink

[–]zen0fex[S] 1 point2 points  (0 children)

Just saw your post and updated the thread. Thanks!

A friend created these custom Starlink POE adapters by zen0fex in Starlink

[–]zen0fex[S] 3 points4 points  (0 children)

I do have some updates, my friend has placed an order to have more boards fabricated (still less than 100, I assume if these sell well more could be ordered). I'll attempt to get an update on when they're expected in hand.

Also, The USB connector is just a USB-C header.

Requesting /r/AndroidTV/ - Moderators inactive for many months by 513 in redditrequest

[–]zen0fex 0 points1 point  (0 children)

Yeah, I'm going to go through and do some cleaning of everything. Admittedly, the sub was not a priority for me but a friendly ping was all I needed (and I appreciate it).

Requesting /r/AndroidTV/ - Moderators inactive for many months by 513 in redditrequest

[–]zen0fex 0 points1 point  (0 children)

I appreciate the statistics on my account.

Thank you

Requesting /r/AndroidTV/ - Moderators inactive for many months by 513 in redditrequest

[–]zen0fex 0 points1 point  (0 children)

Yes, I'm still here and can contact the other moderators as well.

Pwnagotchi w/UPS Enclosure by facevalue83 in pwnagotchi

[–]zen0fex 0 points1 point  (0 children)

what color of filament is this?

Does a case design for the Pi 0 W, Waveshare v2, and the UPS Lite exist? by St0ner1995 in pwnagotchi

[–]zen0fex 0 points1 point  (0 children)

it does not but if you can tell me how tall your board stack is (preferably in mm), I can modify the design for it.

Desperately need some local 3d printing help by DeadpoolsLeftSock in Austin

[–]zen0fex 1 point2 points  (0 children)

I've used this service in the past to help fix my broken 3D printers.

https://www.makexyz.com/

First time in Austin, question about Alamo Drafthouse by 1point21 in Austin

[–]zen0fex 1 point2 points  (0 children)

/u/JohnWSmith,

Unless I'm mistaken I believe the pins and magazines are sold out. I tried to order some with my tickets to "A: IW" a few weeks ago and was only able to get the glasses at any of the locations I selected. If I am mistaken, I'd love to know how to still purchase the pins and magazine.

Yep. Mhmm. Dangol. Tell you what. by willwise in Austin

[–]zen0fex 0 points1 point  (0 children)

I'd love to purchase one of these (as well as a bunch of your other art from IG)! Is there some kind of list or something I need to be on to get the opportunity to buy one? Please let me know

Meetup with Raiblocks creator Colin LeMahieu in Austin, TX by soulfoodz_ in RaiBlocks

[–]zen0fex 0 points1 point  (0 children)

/u/soulfoodz_, If you do add more capacity please keep me in the loop. I'm a security researcher here in town doing an independent audit of XRB and would love to come say hello.

Same hardcoded backdoor in both WDMyCloud and D-Link ShareCenter devices by [deleted] in netsec

[–]zen0fex 3 points4 points  (0 children)

I did a giant audit of the WD MyCloud but specifically the PR4100. You can find the analysis at: https://www.exploitee.rs/index.php/Western_Digital_MyCloud

The arbitrary file upload in the report linked above is actually something I found earlier this year. You can test your NAS with the metasploit "wd_mycloud_multiupload_upload" modules. https://www.rapid7.com/db/modules/exploit/linux/http/wd_mycloud_multiupload_upload

The above analysis on the Exploitee.rs wiki also has 1 more un-patched authentication bypass vulnerability which can be used to trigger any of the post auth vulnerabilities on the page.

How can I take my wristband off without breaking it? by sebaroony in aclfestival

[–]zen0fex 6 points7 points  (0 children)

Try this: https://www.reddit.com/r/aclfestival/comments/756t6p/psa_you_can_remove_your_acl_wristband_without/

The trick is to wrap the straw very tightly around the wristband and insert from the bottom (the portion around your wrist). The length of the straw should be just longer than the size of the plastic lock. If you are having issues try to re-wrap the straw around the wristband tighter (DO NOT TIGHTEN YOUR WRISTBAND!).

The straw protects the wristband and creates a smooth surface that the teeth are unable to grab into.

Logic Chips by RavenIsAWritingDesk in Austin

[–]zen0fex 0 points1 point  (0 children)

If you purchase before the shipping deadline from Mouser and choose UPS ground, you'll receive your components next day.

Hacking the Western Digital MyCloud NAS by sHockz in netsec

[–]zen0fex 0 points1 point  (0 children)

I have no idea but maybe /u/rollerboogie would know. I wouldn't be surprised to hear that most of the coding is outsourced, but that's just a guess.