hacking: security in practice
VFD wifi back door
Im not a havker at all tho ive always had an interest in it. Im actually an electrician and cnc technician. Something i noticed in my 18 years is i think potentially scary as hell. I have done a lot of work in waste water treatment facilities which are more and more becoming automated and remote operable. That isnt necessarily the issue i found what the issue is is that every single VFD in these places has wifi capabilities and ive never found one where it had been disabled or had the factory password changed. Like i said im no expert on the matter but it seems to me that someone in close proximity could use this as a back door to the entire operation and even if thatvwerentvthe case you could still effect individual VFDs and create a cascade effect which would shit the operation down. Not a good thing. Am i wrong in thinking thatvthis is the case? It just seems like a rather large oversight in a very critical part of our infrastructure here in the usa.
If youre unaware a VFD is a variable frequency drive. They are used for controlling electric motors. One could very easily destroy a motor by changing one of more key parameters.
Not sure if this is the place to ask this question but it seems like the sort of thing a white hat would be interested in.
submitted by /u/Own_Mechanic_9805
[link] [comments]
VFD wifi back door
Im not a havker at all tho ive always had an interest in it. Im actually an electrician and cnc technician. Something i noticed in my 18 years is i think potentially scary as hell. I have done a lot of work in waste water treatment facilities which are more and more becoming automated and remote operable. That isnt necessarily the issue i found what the issue is is that every single VFD in these places has wifi capabilities and ive never found one where it had been disabled or had the factory password changed. Like i said im no expert on the matter but it seems to me that someone in close proximity could use this as a back door to the entire operation and even if thatvwerentvthe case you could still effect individual VFDs and create a cascade effect which would shit the operation down. Not a good thing. Am i wrong in thinking thatvthis is the case? It just seems like a rather large oversight in a very critical part of our infrastructure here in the usa.
If youre unaware a VFD is a variable frequency drive. They are used for controlling electric motors. One could very easily destroy a motor by changing one of more key parameters.
Not sure if this is the place to ask this question but it seems like the sort of thing a white hat would be interested in.
submitted by /u/Own_Mechanic_9805
[link] [comments]
Reddit
r/hacking on Reddit: VFD wifi back door
Posted by u/Own_Mechanic_9805 - No votes and no comments
hacking: security in practice
Top Hacking Podcasts, Series, or Content to actually learn something?
Hey guys,
Student here.
I was wondering, which hacking or cybersecurity content do you like or know that you *actually* learn from?
I've noticed there's a lot of trash content out there that is click-baiting or just opinions over opinions over opinions. YES, I get it. Professionals in this area of IT have their own opinions about stuff, but I don't get nurtured by other people's opinions only. I want to learn and SEE!
I'm looking to passively LEARN by entertaining myself at the same time when I'm not with the HARD stuff, actively studying.
Plus, we get to share cool resources with each other!
Share your favorite hacking content below.
submitted by /u/AmazingWear465
[link] [comments]
Top Hacking Podcasts, Series, or Content to actually learn something?
Hey guys,
Student here.
I was wondering, which hacking or cybersecurity content do you like or know that you *actually* learn from?
I've noticed there's a lot of trash content out there that is click-baiting or just opinions over opinions over opinions. YES, I get it. Professionals in this area of IT have their own opinions about stuff, but I don't get nurtured by other people's opinions only. I want to learn and SEE!
I'm looking to passively LEARN by entertaining myself at the same time when I'm not with the HARD stuff, actively studying.
Plus, we get to share cool resources with each other!
Share your favorite hacking content below.
submitted by /u/AmazingWear465
[link] [comments]
Reddit
r/hacking on Reddit: Top Hacking Podcasts, Series, or Content to actually learn something?
Posted by u/AmazingWear465 - 49 votes and 11 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Environmentalist hacker group “Guacamaya” releases DIY Guide to Digital Monkey-wrenching; showing in detail how they hacked Pronico mining, downloaded files and emails to leak, and then repeatedly sabotaged the company's computers over the course of 6 months.
https://external-preview.redd.it/JOOdREgwLuMQOiR1qlczR8-a3pCukmzQaTdwHy6PpBc.jpg?width=640&crop=smart&auto=webp&s=e3d766e91fb6d573d73734c7c64e85d002ca3214 submitted by /u/LickMyCockGoAway
[link] [comments]
Environmentalist hacker group “Guacamaya” releases DIY Guide to Digital Monkey-wrenching; showing in detail how they hacked Pronico mining, downloaded files and emails to leak, and then repeatedly sabotaged the company's computers over the course of 6 months.
https://external-preview.redd.it/JOOdREgwLuMQOiR1qlczR8-a3pCukmzQaTdwHy6PpBc.jpg?width=640&crop=smart&auto=webp&s=e3d766e91fb6d573d73734c7c64e85d002ca3214 submitted by /u/LickMyCockGoAway
[link] [comments]
hacking: security in practice
Why do people implement SPF without DMARC?
I was under the impression that SPF records are useless without actually having a policy that actions failed verification?
But the more I look the more I see SPF records without anything else.
Am I missing something here? That would mean people can just spoof all they want?
submitted by /u/thehunter699
[link] [comments]
Why do people implement SPF without DMARC?
I was under the impression that SPF records are useless without actually having a policy that actions failed verification?
But the more I look the more I see SPF records without anything else.
Am I missing something here? That would mean people can just spoof all they want?
submitted by /u/thehunter699
[link] [comments]
Reddit
r/hacking on Reddit: Why do people implement SPF without DMARC?
Posted by u/thehunter699 - No votes and no comments
5 common Vulnerabilities in smart contracts
Smart contracts are self-executing contracts with the terms of the agreement between buyer and seller being directly written into code…Continue reading on Medium »
Read more...
Smart contracts are self-executing contracts with the terms of the agreement between buyer and seller being directly written into code…Continue reading on Medium »
Read more...
What is a reentrancy attack?
Reentrancy attacks are a type of exploit that can be used to drain funds from smart contracts. They work by taking advantage of the fact…Continue reading on Medium »
Read more...
Reentrancy attacks are a type of exploit that can be used to drain funds from smart contracts. They work by taking advantage of the fact…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top 5 Benefits of Hacking Your WhatsApp Account
https://cdn-images-1.medium.com/max/1080/1*lfCLjF1wh8Lq5cjYv6nAew.png
WhatsApp is one of the most popular messaging apps in the world, used by millions of people every day. It’s an excellent platform for…
Continue reading on Medium »
Top 5 Benefits of Hacking Your WhatsApp Account
https://cdn-images-1.medium.com/max/1080/1*lfCLjF1wh8Lq5cjYv6nAew.png
WhatsApp is one of the most popular messaging apps in the world, used by millions of people every day. It’s an excellent platform for…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
My Review of Hire a Hacker Pro
https://cdn-images-1.medium.com/max/620/1*i4dF3VLdIyaiSHNxgC1ceA.jpeg
Review of Tony Capo and Hire a Hacker Pro
Continue reading on Medium »
My Review of Hire a Hacker Pro
https://cdn-images-1.medium.com/max/620/1*i4dF3VLdIyaiSHNxgC1ceA.jpeg
Review of Tony Capo and Hire a Hacker Pro
Continue reading on Medium »
The Key to Successful Bug Bountying
Bug bounties are a way for ethical hackers to earn money by finding and reporting security vulnerabilities in websites, apps, and other…Continue reading on Medium »
Read more...
Bug bounties are a way for ethical hackers to earn money by finding and reporting security vulnerabilities in websites, apps, and other…Continue reading on Medium »
Read more...
Bypassing the 2FA /MFA — An Easy win
Hello Readers, Today I am going to tell how was I was to bypass the 2FA protection for a product based company main login page. I hope…Continue reading on Medium »
Read more...
Hello Readers, Today I am going to tell how was I was to bypass the 2FA protection for a product based company main login page. I hope…Continue reading on Medium »
Read more...
hacking: security in practice
Tesla Spotify Account
I’m looking for a way to capture network traffic from my Tesla when on wifi at home. Specifically I need to find out the log in credentials the car uses when connecting to Spotify. I want to be able to use this account outside the car but Tesla does not release the login details.
submitted by /u/KathryneMarville
[link] [comments]
Tesla Spotify Account
I’m looking for a way to capture network traffic from my Tesla when on wifi at home. Specifically I need to find out the log in credentials the car uses when connecting to Spotify. I want to be able to use this account outside the car but Tesla does not release the login details.
submitted by /u/KathryneMarville
[link] [comments]
Reddit
r/hacking on Reddit: Tesla Spotify Account
Posted by u/KathryneMarville - No votes and no comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Identifying a phishing link in an email
Phishing emails are a common form of cyber attack in which an attacker tries to trick you into revealing personal information such as your…
Continue reading on Medium »
Identifying a phishing link in an email
Phishing emails are a common form of cyber attack in which an attacker tries to trick you into revealing personal information such as your…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CSTI vulnerabilities will get you $$$ and this is why
https://cdn-images-1.medium.com/max/893/1*KNDj1x1EFDEqDZBNmXFdcA.png
Hi everyone, today I want to talk about CSTI (Client-Side Template Injection) Vulnerabilities and how you can exploit those to execute…
Continue reading on Medium »
CSTI vulnerabilities will get you $$$ and this is why
https://cdn-images-1.medium.com/max/893/1*KNDj1x1EFDEqDZBNmXFdcA.png
Hi everyone, today I want to talk about CSTI (Client-Side Template Injection) Vulnerabilities and how you can exploit those to execute…
Continue reading on Medium »