dawg, BobDaHacker compromised McDonalds by finding one of their endpoints and ... REGISTERING AN ACCOUNT. That's all it took. It then sent a plaintext password via email.
McDonalds did however apparently fix the problem when they reported it to them.
McDonalds did however apparently fix the problem when they reported it to them.
π48π€11π8β€2π’2π€2
vx-underground
dawg, BobDaHacker compromised McDonalds by finding one of their endpoints and ... REGISTERING AN ACCOUNT. That's all it took. It then sent a plaintext password via email. McDonalds did however apparently fix the problem when they reported it to them.
You can read the full write-up here. It's very silly. I recommend reading it.
https://bobdahacker.com/blog/mcdonalds-security-vulnerabilities
https://bobdahacker.com/blog/mcdonalds-security-vulnerabilities
Bobdahacker
How I Hacked McDonald's (Their Security Contact Was Harder to Find Than Their Secret Sauce Recipe)
How I found critical security vulnerabilities in McDonald's systems affecting millions of employees, and had to cold-call their HQ pretending to know security staff just to report them.
π35π7π€5β€2π’1
If you buy newer models of Volkswagen you can't use every feature in the vehicle unless you subscribe to a monthly service.
The subscription fee to unlock the additional features is $22/month.
https://www.autoexpress.co.uk/volkswagen/367566/forget-netflix-volkswagen-locks-horsepower-behind-paid-subscription
The subscription fee to unlock the additional features is $22/month.
https://www.autoexpress.co.uk/volkswagen/367566/forget-netflix-volkswagen-locks-horsepower-behind-paid-subscription
Auto Express
Forget Netflix, Volkswagen locks horsepower behind paid subscription
Owners can now subscribe to boost the power of their car⦠for a fee
π€£70π€―21π’8β€2π±2π1π1
vx-underground
If you buy newer models of Volkswagen you can't use every feature in the vehicle unless you subscribe to a monthly service. The subscription fee to unlock the additional features is $22/month. https://www.autoexpress.co.uk/volkswagen/367566/forget-netflixβ¦
Soon Volkswagen will encounter the final boss: hardware nerds.
They gotta try to stop mfers who play Doom on toasters and shit. Good luck
They gotta try to stop mfers who play Doom on toasters and shit. Good luck
π57π€£50π30β€4π―2β€βπ₯1π’1
This media is not supported in your browser
VIEW IN TELEGRAM
hello and good morning tiny people living inside my computer
β€79π₯°21π5π€2π±1π’1π1
vx-underground
hello and good morning tiny people living inside my computer
> be me
> be edgelord into death metal and satanic artwork
> make vxug
> fast forward 6 years
> mind broken from malware
> just want to watch silly cat videos
> be edgelord into death metal and satanic artwork
> make vxug
> fast forward 6 years
> mind broken from malware
> just want to watch silly cat videos
π€£73β€27π₯°10π€4π3π€3β€βπ₯2π1π₯1π’1π«‘1
HOW DID YOU PEOPLE GET INSIDE MY PHONE
π49β€9π8π3π±3π€2π2π₯1π’1π1
vx-underground
HOW DID YOU PEOPLE GET INSIDE MY PHONE
The people inside my phone exhausted of hearing the same KPop Demon Hunter song for the 38th time today
β€57π23π€―6π€3π₯°2π’1
That Israeli intelligence dude who got arrested in Las Vegas, while attending BLACKHAT, for (allegedly) trying to lure a minor, had the arrest documents unsealed and released online today.
The documents are so cooked, dude mentioned to the detective (and on the record) he has just met with the NSA and FBI.
It's a level 10 shit maelstrom online. Every comment section is internet street fights. You can scroll infinitely of people arguing about it.
It's got all the key ingredients to really rustle jimmies
- Israeli
- Russian
- Pedophilia
- NSA mentioned
- FBI mentioned
The documents are so cooked, dude mentioned to the detective (and on the record) he has just met with the NSA and FBI.
It's a level 10 shit maelstrom online. Every comment section is internet street fights. You can scroll infinitely of people arguing about it.
It's got all the key ingredients to really rustle jimmies
- Israeli
- Russian
- Pedophilia
- NSA mentioned
- FBI mentioned
π€£117π₯°10π10β€4π«‘2π’1π1π―1π€1
Crazy that the term bug and debug unironically comes from removing bugs (insects) from big ass computers
π―63π€11β€4π€―2π’2π1π1π1
vx-underground
Crazy that the term bug and debug unironically comes from removing bugs (insects) from big ass computers
This isn't even a meme lmfao this is true. This isnt just me schizo posting
π€51β€10π6π€3π2π1π’1π―1
vx-underground
Germanyβs Federal Supreme Court (BGH) is debating whether or not ad-blockers constitute COPYRIGHT INFRINGEMENT which would result in making ad-blockers illegal.
Imagine if legislation passes that makes blocking ads illegal. Imagine you're at home, browsing the internet, then the fuckin' internet Schutzstaffel bust through your door and drag you into the street for visiting a website with uBlock enabled
π€£104β€13π’12π€2π1
Axel Springer says ad blockers threaten their revenue generation model and that using an ad-blocker illegally manipulates the HTML / CSS (and other web components) thus it is infringement of their intellectual property
INSPECT ELEMENT IS ILLEGAL AND FOR NERDS
INSPECT ELEMENT IS ILLEGAL AND FOR NERDS
π86π€£39π€20π―5β€4π’1
vx-underground
Wtf why is Tulsi Gabbard doing something we all agree is good
Mfw a politician does something that makes sense
π€£60π12π₯4β€2π1π’1
Saw some report on a information stealer named MaksStealer, or MaksRat, or something.
Written in Java, multi-staged, delivered from some Minecraft place. The dude makes it pretty clear he's just a kid, probably around 17 years old. He seems pretty happy Threat Intelligence and Malware Analysts have looked at his work.
Proud of you, kid. You shouldn't facilitate crime and steal peoples identities and/or credentials, or operate a Malware-as-a-Service campaign, but the code looks pretty solid. You get a cat for being a clever kid.
Written in Java, multi-staged, delivered from some Minecraft place. The dude makes it pretty clear he's just a kid, probably around 17 years old. He seems pretty happy Threat Intelligence and Malware Analysts have looked at his work.
Proud of you, kid. You shouldn't facilitate crime and steal peoples identities and/or credentials, or operate a Malware-as-a-Service campaign, but the code looks pretty solid. You get a cat for being a clever kid.
β€92π26π₯12π4π’1π1
Yesterday Seamus Hughes shared with us the recent court records on RapperBot which was operated (in an undefined capacity) by a United States citizen named Ethan Foltz.
Foltz was successfully identified by the United States Federal Bureau of Investigation when they discovered Mr. Foltz has purchased (rented) infrastructure in the United States (in the state of Arizona) under the moniker "Seth Rogan".
However, Mr. Foltz paid for the infrastructure using his PayPal. Upon this discovery, the FBI subpoenaed PayPal which unveiled his name, as well as personal Gmail accounts. The FBI then subpoenaed Google as well as the ISP they believed Mr. Foltz to be using.
Upon receiving data from Google regarding Mr. Foltz they discovered some interesting things.
- The source code to RapperBot in his Google Drive
- Search history including: "x86 x priv escalation linux", "poplin router firmwar", "poplin firmware reverse", and other incriminating searches
- Search history indicated Mr. Foltz frequently searched "RapperBot" to monitor discussions of the RapperBot operation
- Search history of Google Dorks on the RapperBot panel, looking for potential misconfigurations
When the FBI made contact with Mr. Foltz court records indicate he complied with every request they made. This includes allowing the FBI to perform test DDoS attacks against FBI controlled infrastructure to review botnet bandwidth capabilities.
Despite Mr. Foltz being an adult, having an estimated 300,000 IoT devices infected from his RapperBot botnet, conducting DDoS attacks against an approx. 370,000 targets (18,000 unique targets), making an undisclosed amount of money, and (basically) admitting guilt by allowing the FBI to use his botnet for testing, Mr. Foltz has RECEIVED ONLY ONE CHARGE.
He has received 1 count of aiding and betting computer intrusions which carries a maximum of 10 years in prison. However, as noted by the Department of Justice, "a federal judge will determine any sentence after considering U.S. sentencing guidelines and other statutory factors"
Foltz was successfully identified by the United States Federal Bureau of Investigation when they discovered Mr. Foltz has purchased (rented) infrastructure in the United States (in the state of Arizona) under the moniker "Seth Rogan".
However, Mr. Foltz paid for the infrastructure using his PayPal. Upon this discovery, the FBI subpoenaed PayPal which unveiled his name, as well as personal Gmail accounts. The FBI then subpoenaed Google as well as the ISP they believed Mr. Foltz to be using.
Upon receiving data from Google regarding Mr. Foltz they discovered some interesting things.
- The source code to RapperBot in his Google Drive
- Search history including: "x86 x priv escalation linux", "poplin router firmwar", "poplin firmware reverse", and other incriminating searches
- Search history indicated Mr. Foltz frequently searched "RapperBot" to monitor discussions of the RapperBot operation
- Search history of Google Dorks on the RapperBot panel, looking for potential misconfigurations
When the FBI made contact with Mr. Foltz court records indicate he complied with every request they made. This includes allowing the FBI to perform test DDoS attacks against FBI controlled infrastructure to review botnet bandwidth capabilities.
Despite Mr. Foltz being an adult, having an estimated 300,000 IoT devices infected from his RapperBot botnet, conducting DDoS attacks against an approx. 370,000 targets (18,000 unique targets), making an undisclosed amount of money, and (basically) admitting guilt by allowing the FBI to use his botnet for testing, Mr. Foltz has RECEIVED ONLY ONE CHARGE.
He has received 1 count of aiding and betting computer intrusions which carries a maximum of 10 years in prison. However, as noted by the Department of Justice, "a federal judge will determine any sentence after considering U.S. sentencing guidelines and other statutory factors"
π€£56β€7π5π€1π’1