HNHacker News
TopNewBestAskShowJobs

antmldr

165 karma · joined April 14, 2013

Pentester
submissionscomments
antmldr··on One-Click RCE in Asus's Preinstalled Driver Software
>so I could see if anyone else had a domain with driverhub.asus.com.* registered. From looking at other websites certificate transparency logs, I could see that domains and subdomains would appear in the logs usually within a month. After a month of waiting I am happy to say that my test domain is the only website that fits the regex, meaning it is unlikely that this was being actively exploited prior to my reporting of it.

This only remains true in so far as no-one directly registered for a driverhub subdomain. Anyone with a wildcard could have exploited this, silent to certificate transparency?

antmldr··on iSponsorBlockTV v2: SponsorBlock for TVs and game consoles
Yeah, sponsor sections of content is usually done respectfully of the audience. There's no javascript being run on my machine, the sponsor is usually tangentially related to the content, and the creator has an incentive to deliver it in either a humorous or relevant manner.
antmldr··on Tesla is launching their developer APIs
https://bugcrowd.com/tesla :)
antmldr··on Kali Linux 2023.1 introduces 'Purple' distro for defensive security
Yeah, it's an unfortunate titling of the HN post. Defensive means something different in this context - it's meant for people working within the defensive roles of an organization's infosec department.

Kali are a little to blame here for that confusion as well - "We are making enterprise grade security accessible" - is open to misinterpretation of what they are presenting.

antmldr··on When eBPF meets TLS. Defeating TLS encryption with eBPF tricks [pdf]
Great presentation. Any thoughts on including these tricks directly into wireshark to allow fluid decryption at least on the Linux client where CAP_BPF is present?
antmldr··on When eBPF meets TLS. Defeating TLS encryption with eBPF tricks [pdf]
Being at the author's talk earlier today, that wasn't really the spirit that it was given in. The author isn't really talking about "defeating" TLS as a technical control more as he is talking about "defeating" it as an annoyance when reverse engineering.

It's meant more as a showcase of how eBPF can be applied to a technical challenge, as opposed to the author claiming they fundamentally broke TLS.

antmldr··on Passenger with “no idea how to fly” lands plane after pilot incapacitated
If you mean voice communication channel for emergencies, it's 121.5 MHz, 243.00 MHz for Military (double)
antmldr··on IBM's Asshole Test
Having been on the receiving end of this as a candidate (not at IBM), everyone was in on the test in the first 15 seconds, and it changed people's behavior instantly.

It's fairly obvious if you're on the receiving end what the purpose of the test is when you're being observed (as with most interview questions, it helps to ask yourself why the interviewer asking me / having me do this?)

antmldr··on Details emerge of Air France B777 landing incident
Agreed, but also given they initially thought the aircraft itself was deviating from a stable approach (or at least the ATC transcription appears to suggest that?), perhaps the pilots may have thought the feedback was due to autopilot and not the person sitting next to them.
antmldr··on Play Half-Life in the Browser
Make sure you're trying to get into the game mode you downloaded when prompted with "Select game data source" - if it was HLDM, only multiplayer is going to work.
antmldr··on NASA's Perseverance rover sends stunning images
Scott Manley recently did a pretty good ELI5 on the topic: https://www.youtube.com/watch?v=Wah1DbFVFiY
antmldr··on Facebook account banned after linking Oculus account
Wow, thought I'd be one of the few struggling with this.

Bought the device with the hope that I could register an account for the first time in years, but similar to others, my account was instantly banned with no explanation other than "violating community guidelines."

One of Facebook's arguments against anti-trust accusations has been to point to the lack of consumer harm. This is fairly obvious evidence of material harm to consumers who just bought $500 paperweights.

antmldr··on The CIA Is Sharing Declassified Maps
IIRC They're suppose to be protected under the Geneva Convention.
antmldr··on Powerwall 2 and Integrated Solar
Musk and JB got asked about this (I think at the 2016 AGM?). Their response was basically "yeah we get asked this a lot; No, because of the make up of the cells makes them inappropriate for the number of cycles."
antmldr··on Japan home to 541,000 young recluses
I think that's the 15-19 age group...
antmldr··on This JPEG is also a webpage
Saumil Shah released a framework for producing images using this technique to deploy browser exploits (but could potentially be used for anything).

Worth a look if you'd like to make your own! http://stegosploit.info/

antmldr··on I Just Drove Eight Hours on Tesla Autopilot
No, but granted we're getting into semantics. Feature 1 you describe is provided by the Flight Management System[0], and feature 2 is provided through Autoland[1]. [0]: https://en.wikipedia.org/wiki/Flight_management_system [1]: https://en.wikipedia.org/wiki/Autoland
antmldr··on Project Natick: Microsoft's Underwater Data Center
Data Sovereignty? Could this, for better or for worse, allow Microsoft to completely dictate the terms of how it stores and manages its data in international waters?
antmldr··on Hot Potato – Windows Privilege Escalation
My jaw kind of hit the floor after reading Google Security Research's issue 222; very glad someone has built a simplified PoC. With any luck this will get some kind of response out of MS.
antmldr··on Project: A Simple Operating System
Specifically, I've been to a few of the Functional Programming meetups- they've been good so far. UNSW and USYD are hubs for the CS community in general. As a UTS grad, there wasn't much but Business Analysis going on there.

Generally, recommendation would be to pick a few topics that you're interested and find related communities and meetups. You'll find interesting people through osmosis.

antmldr··on Number of legal 18x18 Go positions computed. One more to go
In a single round, perhaps not. In a best of 30 rounds on three different maps with asymmetrical teams and a team economy, you can see the elements of what the original comment was talking about, "interesting risk/reward and provoking you opponent to overextending type stuff."

If you haven't seen a Counter-Strike game played competitively, this weekend a "Major" tournament is being played in Katowice[0]. It's well worth watching a match to get a glimpse of the mechanics. It might also be fun.

[0] http://www.esl-one.com/csgo/katowice-2015/

antmldr··on Police Use Department Wish List When Deciding Which Assets to Seize
IANAL, but in Commonwealth countries this seems to be mitigated by the use of consolidated revenue funds[0].

It's explicit in s81[1] and 83[2] of the Australian Constitution that all revenues must be deposited into the CRF and you then need a law to appropriate the revenue elsewhere. Similarly, state law seems to point to revenue from civil seizure is paid into treasury.[3]

[0] https://en.wikipedia.org/wiki/Consolidated_Fund [1] http://www.austlii.edu.au/au/legis/cth/consol_act/coaca430/s... [2] http://www.austlii.edu.au/au/legis/cth/consol_act/coaca430/s... [3] http://www.austlii.edu.au/au/legis/nsw/consol_act/cara199027...

antmldr··on Apple – Privacy – Government Information Requests
http://images.apple.com/privacy/docs/legal-process-guideline...

Page 4 onwards provides a list of information they provide to law enforcement agencies. Probably prudent if you're an apple customer to simply assume all of this information is as good as public.

antmldr··on “End-to-End incompatible with Chrome Update functionality”
This isn't a bug / complaint / observation of a vulnerability of End-to-End per se, you could argue Microsoft could be NSL'd to do the same to a user's operating system.

To counter this you'd need a secure, distributed way to release updates in Chrome. I don't think that's quite in scope of what this project is trying to accomplish.

antmldr··on “A Windows 7 deployment image was accidently sent to all Windows machines”
>Frankly, I'm surprised things like this don't happen more often.

They do. This happened to the largest bank in Australia mid 2012[1]. Very similar circumstances. I've been told that SCCM's UI doesn't help here- something about the default action when nothing is selected to apply it to all devices managed by SCCM. Someone more familiar with SCCM may want to correct me here.

[1] http://delimiter.com.au/2012/07/30/disastrous-patch-cripples...

antmldr··on Video shows plane's moment of impact at SFO
Not sure how you'd warn a pilot about a crash simply using a camera? Either way, there is already a (practically P2P) collision avoidance system that's pretty reliable. https://en.wikipedia.org/wiki/TCAS
antmldr··on FAA: 'No, you can't hijack a plane with an Android app'
I think what you're describing is more a culture problem than an issue with the design of the FMS or pilots receiving incorrect information from instruments.

Any pilot will tell you the very last thing you want is to be at war with your own aircraft (or its instruments), but incorrect readings should not solely cause an incident. This is also the case with AF447. I'm more likely after reading the CVR to put the incident down to poor communication between the crew (in the industry known as CRM or Crew / Cockpit Resource Management) [1].

The crew failed to effectively communicate what each other were doing, to the extent where they were inputting opposite commands to the flight controls and had a misunderstanding of what conditions triggered certain flight control modes [2] of the Airbus' autopilot.

Coming back to the original point around culture and training, it was evident that the more junior pilots were relying on certain "protections" the autopilot has against conditions like a stall. It's this reliance upon a computer (commanding a full nose-up during a stall) and lack of understanding of how the aircraft's flight computer acts under certain conditions that ultimately ended 228 people's lives. The French investigation concluded that the inconsistency of speed measurements was only one of seven factors that caused the accident.

[1] http://en.wikipedia.org/wiki/Crew_Resource_Management [2] http://en.wikipedia.org/wiki/Flight_control_modes_%28electro...

EDIT: Having said that, I would not want to be the pilot flying an aircraft where I can't trust my own instruments, however there are numerous cases (QF72 [3] comes to mind) where pilots have had to disregard most if not all digital instrument readings and stick to the bare minimum to safely land.

[3] http://en.wikipedia.org/wiki/Qantas_Flight_72

antmldr··on FAA: 'No, you can't hijack a plane with an Android app'
Yep, hit the nail on the head.

Thing is, if you're able to inject un-authorised code into the FMS, chances are you have bigger concerns than a single aircraft getting hijacked.

It's the equivalent of saying "If I had access to a bank's mainframe and network infrastructure, I could steal millions of dollars with an Android App." Sure you could, but is the problem the fact you can do it with an Android App, or the fact you were able to inject the code in the first place?