{"id":8034,"date":"2015-09-06T10:42:16","date_gmt":"2015-09-06T17:42:16","guid":{"rendered":"http:\/\/crimeandtheforcesofevil.com\/blog\/?p=8034"},"modified":"2015-09-06T10:42:16","modified_gmt":"2015-09-06T17:42:16","slug":"i-dont-even-know-where-to-start","status":"publish","type":"post","link":"https:\/\/crimeandtheforcesofevil.com\/blog\/2015\/09\/06\/i-dont-even-know-where-to-start\/","title":{"rendered":"i don&#039;t even know where to start"},"content":{"rendered":"<p>Seagate and LaCie make wireless external hard drives for mobile use, so you can &#8216;expand your phone&#8217; and carry around whatever external data you&#8217;d like to carry around without blowing your phone&#8217;s storage. I guess that&#8217;s useful. I imagine people also use them as &#8216;personal cloud&#8217; devices, whatever the hell that&#8217;s supposed to mean, and other things.<\/p>\n<p>But I don&#8217;t care, really, because <a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/903500\">THEY SHIP WITH AN UNDOCUMENTED TELNET SERVER RUNNING WITH ROOT ACCESS<\/a>. You can read and write anything and everything.<\/p>\n<p>This is&#8230; <em>amazing<\/em>. How do you let this happen? It&#8217;s another case where I need an Industrial Espionage Inside! logo sticker. Here, have a first draft.<\/p>\n<p><center><img decoding=\"async\" src=\"http:\/\/solarbird.net\/Livejournal\/2015-09\/espionage-inside.gif\"><\/center><\/p>\n<p>On a related note, <a href=\"https:\/\/www.youtube.com\/watch?v=uL65zWrofvk\">this talk at Black Hat 2013 on hacking z\/OS mainframes<\/a> is pretty cool, and tells me that back in my <em>part of the problem<\/em> days that I could&#8217;ve been a goddamn rock star in this admittedly-small field at Black Hat, because the shit I was doing on IBM mainframes was <em>way<\/eM> more complicated and subtle than this.<\/p>\n<p>There are mainframe people in comments telling the presenter not to be so glib about mainframe security because they know exactly what you&#8217;re doing via their monitoring systems. I heard that shit then, too; it was bullshit at the time and I&#8217;m pretty sure it&#8217;s bullshit now given the sploits he&#8217;s outlining. Hell, I submitted some reports through trusted third parties because they were just too easy &#8211; easier than these, even, and some of this is pretty damn easy.<\/p>\n<p>I mean, seriously, ever seen a security patch for an unpublicised exploit released in <em>one day<\/eM>? I have. That was caused by one of my third-partied reports. (Arbitrary access to any account in 19 keystrokes, completely unlogged. It was <em>hilarious<\/em>. But also too easy, so, reported. I knew exactly what they were doing wrong and how to fix it, so it&#8217;s not like they had to work at it.)<\/p>\n<p>But enough of the past. Go play skeet shooting with your wireless Seagate and LaCie drives now. It&#8217;s probably more effective than trusting them.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Seagate and LaCie make wireless external hard drives for mobile use, so you can &#8216;expand your phone&#8217; and carry around whatever external data you&#8217;d like to carry around without blowing your phone&#8217;s storage. I guess that&#8217;s useful. I imagine people also use them as &#8216;personal cloud&#8217; devices, whatever the hell that&#8217;s supposed to mean, and [&#038;hellip<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-8034","post","type-post","status-publish","format-standard","hentry","category-random-coolness"],"_links":{"self":[{"href":"https:\/\/crimeandtheforcesofevil.com\/blog\/wp-json\/wp\/v2\/posts\/8034","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/crimeandtheforcesofevil.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crimeandtheforcesofevil.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crimeandtheforcesofevil.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/crimeandtheforcesofevil.com\/blog\/wp-json\/wp\/v2\/comments?post=8034"}],"version-history":[{"count":0,"href":"https:\/\/crimeandtheforcesofevil.com\/blog\/wp-json\/wp\/v2\/posts\/8034\/revisions"}],"wp:attachment":[{"href":"https:\/\/crimeandtheforcesofevil.com\/blog\/wp-json\/wp\/v2\/media?parent=8034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crimeandtheforcesofevil.com\/blog\/wp-json\/wp\/v2\/categories?post=8034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crimeandtheforcesofevil.com\/blog\/wp-json\/wp\/v2\/tags?post=8034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}