Friday, August 2, 2024
Arctic Code Vault Contributor: ✓
Sunday, June 30, 2024
Hack3r Achievement Obtained!
You may have seen on my X feed by now, but if not. I am proud to say my IPMIPWN tool was added to not only Kali Linux, but to BlackArch Linux as well!! This happened earlier, but I haven't bragged on the blog yet :) It's so amazing it was so well liked and used! I hope it has helped many hackers in their education and professional careers.
If you somehow don't know about these projects, welcome skiddy and go here and here and RTFM :P
I loving giving back to the scene that has helped me so much and I am always trying to do more. Now I can say I honestly have in a "I hope" meaningful way! Thanks to whoever found my tool worthy and all the people at the Kali and BackArch organizations. You are all awesome! Thank you!!
Enjoy the 1's and 0's :)
Wednesday, June 12, 2024
Go Tell That Spammer, The Scammer, The Crypto Jacker. Tell'em That God's Gonna Cut'em Down.
I will start with a Facebook/Zelle scan that was tried against my wife. So Cmoney was posting stuff on FB to sell, she was asking around $200 for the item and she got a hit that same night at around 4AM. He wanted to pay and come get it ASAP, but said he wanted to use Zelle to buy it then come get it later that day. as he was at work. We didn't use Zelle so we asked if he could use any other service, which he said no and said he will pass. Well Cmoney wanted to sell this thing so we got a Zelle account to accommodate this guy. We gave him our Zelle info to send money, which he then says he sent the payment, but nothing showed up on our end, then an email came saying this BS:
For your account to be credited fully with the sum of $230.00 USD You are required to send the sum of
$100.00 USD (FIRST) to the buyer’s Zelle information for your buyer’s safety
We of course were all, yeah f that. Thats when I took a deeper look at the email from "Zelle" and noticed the from address was zellepay.customerservices024975@gmail.com which is obviously not a Zelle email, but you dont see that URL until you go into header details, just a hover over the form/to area in gmail shows the below:
So the email is so long that google cuts off the TLD and all you see is the zelle portion. Here is a look at the expanded headers view:
Friday, April 26, 2024
Getting GSMEvil2 working on Debian.
So MOST of the instructions on GSMEvil2's github work fine with the exception of the pip guidance. Here is what I had to use to get it working:
pip3 install pyshark flask flask_socketio==4.3.2 pysqlite3
Yeah its a short post, Deal with it :P
Saturday, February 10, 2024
Heating control system meinETA open to attack with Hax11
meinETA is a heating control system that can be accessed remotely via a password protected portal, however since it uses X11 to expose the GUI to the user, if you can get the IP of the meinETA system this portal can be bypassed and you can manipulate the system directly with Hax11 as seen below.
The ETA site says this about meinETA:
meinETA: the free internet platform
If your heating boiler is connected to the internet, you can see and change all heating settings on your mobile, tablet or PC. So you always have a handle on your heating, wherever you are! When you login to www.meinETA.at, you see the touchscreen as if you were standing right in front of the boiler!
This means that with Hax11 you have full control of the system, without the need for the portal, just needing the systems IP. This would seem to be a big hurdal, but a few minutes on shodan and you can track systems down and be in full control with just a few keystrokes and clicks of the mouse. There doesn't seem to be any sort of authentication on the GUI, not even a pin code so there is nothing stopping you once you locate one.
More on ETA
Get Hax11 HERE
Thursday, October 5, 2023
Update to Hax11 allows connect to more display ports for larger attack surface
I have updated Hax11 to connect to non-default display ports. The previous version only allowed connecting to display 0 "port 6000", but now you can connect to any a system has available.
Example:
If you want to connect to display 1 "port 6001" use this command:
python hax11.py ip.addr.here 1
If you want to connect to display 0 use the old command style:
python hax11.py ip.addr.here
You can connect to display 1, 2, 3, and so on. I know it seems like a small change, but it doubles or more your attack surface. So while the change is small, the impact is big.
Get it HERE
Enjoy!
Saturday, April 1, 2023
smilePOS RCE via MS .NET Remoting
While searching the internets for MS .NET Remoting deployments to test my service name brute force script, I stumbled on a gem.





