CJ Heres

660 posts

CJ Heres

CJ Heres

@cj_000

@exploiteers member

United States Katılım Mayıs 2012
123 Takip Edilen615 Takipçiler
CJ Heres retweetledi
Amir Etemadieh
Amir Etemadieh@Zenofex·
As of a little over 2 weeks ago, I've been laid off from my previous gig and am looking for new opportunities. DM me if you have a role you think I may be a good fit for. 👁️🔬🐛
English
0
7
9
7.1K
CJ Heres
CJ Heres@cj_000·
@David3141593 I've had more recent success with this one. Apologies on the Amazon link. However I can confirm that the one you've identified no longer seems to work. Manhattan USB 2.0 Card Reader / Writer – a.co/d/agxg92T
English
0
0
0
170
David Buchanan does not tweet anymore
Has anyone had success dumping emmc using a USB SD card reader? I bought the widely recommended TS-RDF5, however it enumerates as an TS-RDF5A, as opposed to TS-RDF5K. If I plug in an SD, it shows up under /dev/sdx as opposed to /dev/mmcblkx, which iiuc is the Wrong Thing
David Buchanan does not tweet anymore tweet media
English
8
8
75
20K
CJ Heres retweetledi
Exploitee.rs
Exploitee.rs@Exploiteers·
Great presentation from @LennertWo on hacking Starlink terminals with a surprise appearance of our Low Voltage Adapter!
Exploitee.rs tweet media
English
1
1
23
0
CJ Heres
CJ Heres@cj_000·
@jbit4n6 If you are monitoring this. Can you follow back / shoot a DM? Trying to figure out how to report something... Thanks!
English
0
0
0
0
CJ Heres retweetledi
Jay Freeman (saurik)
Jay Freeman (saurik)@saurik·
Last week, I discovered (and reported) a critical bug (which has been fully patched) in @optimismPBC (a "layer 2 scaling solution" for Ethereum) that would have allowed an attacker to print arbitrary quantity of tokens, for which I won a $2,000,042 bounty. saurik.com/optimism.html
English
201
834
5.5K
0
CJ Heres
CJ Heres@cj_000·
@Themariocrafter Unfortunately, no. Searched what I have, but it was 8 years and many hard drives ago...
English
2
0
0
0
CJ Heres
CJ Heres@cj_000·
Google TV v4, soon! Source from LG: goo.gl/uCEKvm Linux version 3.4.5 /home/work/inho.roh/gtv_platform/v4/ #GoogleTV
English
6
2
3
0
CJ Heres retweetledi
Miles in Transit
Miles in Transit@milesintransit1·
This is amazing
English
1
1
19
0
CJ Heres
CJ Heres@cj_000·
@cybergibbons @joernchen Yeah had a requirement for a box to be able to take an update at any point in its life, and date of 1970 / certs rolled. They opted to keep it in the clear vs over any type of TLS due to the multitude of problems it could cause. Meanwhile they refused to encrypt anything...
English
0
0
0
0
CJ Heres
CJ Heres@cj_000·
@cybergibbons @joernchen Once looked at a cheap thermostat that pinned certs, and encrypted comms via a proprietary means (inside the cert pinning). For $100, they checked the boxes of almost everything you could do right, which was awesome! Except the stupid shell with root/oemname for a logon.
English
0
0
0
0
CJ Heres
CJ Heres@cj_000·
@cybergibbons @joernchen Magic of course! To be honest I didn't look at the url, but intercept/dns alterations and strip/serve a bogus cert? Are they pinning certs?
English
1
0
0
0
CJ Heres
CJ Heres@cj_000·
@joernchen @cybergibbons That's my bet. See a .pgp in a packet sniffer. Dismiss as probably encrypted instead of digging deeper. Yet another example of security by obscurity. Not saying it's not effective at "preventing" something trivial, better than a zip, not as good as something actually encrypted.
English
1
0
2
0
CJ Heres
CJ Heres@cj_000·
@rmspeers @nolsen311 @mitch_berry Thanks - this isn't even the worst of the offenders (in terms of privilege), just the easiest to quickly find and hit over a network. Loads of silliness going on in here, but at least they encrypted the firmware updates...
English
0
0
0
0
Ryan Speers
Ryan Speers@rmspeers·
@cj_000 @nolsen311 @mitch_berry Nice work! Of course it’s fcgi leading to a binary for command injection... we keep seeing that common pattern all too often!
English
1
0
0
0
CJ Heres
CJ Heres@cj_000·
So, turns out that Vizio exploit... plan is to release it tonight, it affects multiple models and multiple chipsets and multiple software stacks. No longer as clean as I would have liked it, but have two POC's ready to go, may need some tweaks depending on model. #exploiteers
English
1
0
2
0