Defcon 20 - Dan Tentler - Drinking from the caffeine firehose we know as shodan

  Рет қаралды 180,414

vissago

vissago

Күн бұрын

Пікірлер: 96
@Pzoco
@Pzoco 11 жыл бұрын
Wow when I saw Gigantium, I almost spit out my coffee.. - I live in that town, and I drive by that building every single day.
@mygueldf1462
@mygueldf1462 6 жыл бұрын
what a fking dead crowd tho, this guy is hilarious and brilliant at the same time!
@wizardsbane
@wizardsbane 11 жыл бұрын
Kind of funny/scary how much damage he could have done if he really wanted to.
@vissago
@vissago 11 жыл бұрын
That, my friend, is the difference between blackhats and whitehats. Blackhats will just go nuts, and never tell a soul of the vulnerability. Or exploit it somehow for gain.
@sighwestberry5079
@sighwestberry5079 10 жыл бұрын
vissago freedom is a appealling idea, but most people in this country prefer locks. At some point we will find ourselves locked in a prison of our own making. In fact we are almost there!
@osterpenpen9379
@osterpenpen9379 6 жыл бұрын
What's scary is that the information he's using is published to the Internet.
@vissago
@vissago 12 жыл бұрын
In this particular case the issue is that the sysop would be *NOT* the IT or security group. The way to fix this is to include security when making decisions about putting technology into the business - not just computers, all technology.
@ashleybishton742
@ashleybishton742 4 жыл бұрын
So true, it's so easy to VNC into a thing and then control it with out any authentication. Still in 2020 it's unreal how many you can just stumble across. And you can literally set alarms destroy factory's do anything you want lol. Loads of windows PC's and loads of shells literally waiting for you to get into with a VNC viewer.
@halftome
@halftome 11 жыл бұрын
What would a pentest report look like in a few years? 3 vulnerable fridges, 0-day found for washing machine. garbage bin uses outdated firmware. Kitchen lights vulnerable to format string exploits :)
@cybercat1531
@cybercat1531 6 жыл бұрын
Tamási Benjamin here I am 4 years later.
@tepadno
@tepadno 10 жыл бұрын
2:05 "some German thing counting cubing meters of gas" :D
@EradWir
@EradWir 7 жыл бұрын
I like your humor bro
@philippfarag
@philippfarag 6 жыл бұрын
@@EradWir i do not
@Some_Beach
@Some_Beach 3 жыл бұрын
@@philippfarag good thing no one asked
@masnoy
@masnoy 10 жыл бұрын
THANKS YOU SHODAN CREATOR AND METASPLOIT TEAM !!! AM I ALONE FEEL POWER OF CYBER GOD?!? ;D WATCH DOGS IS RESTING =D
@bFix
@bFix 9 жыл бұрын
how can you dislike this video? This presentation is awesome :D
@SteefHartman
@SteefHartman 7 жыл бұрын
people get scared, and dislike the fact he scared them with the truth
@dannyphilipson2641
@dannyphilipson2641 4 жыл бұрын
there's only 26
@TravisTerrell
@TravisTerrell 24 күн бұрын
I used to live near an indoor mall and a large national department store provided public wifi. A quick network scan found unsecured* network printers. I made it a point to walk within wifi range and print out 1 meme image a day. I like to think that it was brightening somebody's day to have their printer randomly shoot out [relatively wholesome] memes, but of course I will never know. *_unsecured network printer_ is effectively an oxymoron, haha.
@vissago
@vissago 11 жыл бұрын
On and off since 2008. Freelanced for 5 years, then took several full time jobs. At the moment I'm working for a pentest firm doing %100 pentest.
@vissago
@vissago 11 жыл бұрын
Yep. And the more tech we get, the more people will connect everything together. If they don't stop to think for ten seconds about what could possibly go wrong, or even ask someone, expect more of this sort of stuff to crop up :D
@R_got_a_name_change
@R_got_a_name_change 6 жыл бұрын
I keep coming back to this. Classic
@zigitroll
@zigitroll 10 жыл бұрын
damn it i never should have watched this at 2am now i feel like i just smoked crack
@TC-ht9jv
@TC-ht9jv 5 жыл бұрын
I know
@mattmchenry6835
@mattmchenry6835 6 жыл бұрын
Viss I love these videos, I work with a lot of that equipment, mostly cameras (I def saw plenty of exacqvision servers) and intercoms but some of the control devices too and power stuff like lieberts and what not. It's super fun watching your videos and trying to see how many interfaces I recognize.
@mattmchenry6835
@mattmchenry6835 6 жыл бұрын
Lol Daktronics and default creds. Signaltec signs are a lot of fun too, it's like the easiest interface ever.
@NedTheDread
@NedTheDread 11 жыл бұрын
You can alternatively right click on the input field, choose "Inspect Element" and change the type attribute of the input box from "password" to "text".
@vissago
@vissago 11 жыл бұрын
Sir - at some point - we all come from 4chan.
@twiztidbagz
@twiztidbagz 11 жыл бұрын
As a new user of shodan, I have been able to find tons of cameras and tons of home nas drives that have a TON of free space on them... I am wondering... When you decide to locate these other things, such as traffic cameras, etc etc How do you start? do you find a popular manufacturer? How does that process word? I would love to hear a talk about that.
@BrainSlugs83
@BrainSlugs83 12 жыл бұрын
IMHO the issue is that a lot of this gear defaults to require no security credentials at all -- the first time you power something up, like the integrated web server in a random piece of equipment for a 100 megawatt hydroelectric dam, it should force you to integrate it with your internal security, setup it's own security, or disable itself. Problem is, everyone wants it cheaper, which means the web servers and solutions are built/architected by junior developers.
@thatburneydude
@thatburneydude 11 жыл бұрын
awesome presentation
@vissago
@vissago 11 жыл бұрын
It's a matter of manual fingerprinting, basically. You have to find something you know about and see what kinds of tcp banners it has, then you can search for them. A lot of embedded devices all use the same (sometimes crappy) codebase. For example, search for "auther". You'll find both cameras and print servers. It's literally like feeling around in the dark, which is why I wrote my screenshotter tool.
@vissago
@vissago 11 жыл бұрын
You mean the one that deobfuscates passwords that are obfuscated by asterisks? Google for 'chrome extension html revealer and password revealer'. KZbin wont let me paste links.
@vissago
@vissago 12 жыл бұрын
Apples to oranges, my friend. The internet is one gigantic neighborhood. and there are people in other countries that ROUTINELY go around "trying peoples doors", as it were. If you leave your door unlocked on the internet, you're gonna have a bad time.
@realitynowassigned
@realitynowassigned 3 жыл бұрын
He is the kind of dude that would call it shodon
@twiztidbagz
@twiztidbagz 11 жыл бұрын
Understood. Thank you for the response. The Screenshotter tool, and other related things on your blog?
@vissago
@vissago 12 жыл бұрын
They could at least do a lot of things - the trouble is that generally speaking the people in charge of these systems ARENT computer people - they're the bar manager, or a warehouse manager, or the facilities group - they are unaware of the implications of these things.
@trickznmix
@trickznmix 11 жыл бұрын
Ahk cool. btw your 'who watches the watchers' joke was excellent. Keep up the good work and all the best.
@SurfKahuna2008
@SurfKahuna2008 12 жыл бұрын
IP convergence has only just begun... soon enough my shoes laces will each have their own IP address so that each one can remind me if its coming loose... (Nike+ is already close to assigning IPs to your dang shoe!)
@gFamWeb
@gFamWeb 8 жыл бұрын
Autoplate is now gone on Shodan. there is only one result and you cannot telnet into it.
@0100-s8t
@0100-s8t 11 жыл бұрын
This was a great and funny talk, thanks for posting it :D
@RobloxFun100
@RobloxFun100 11 жыл бұрын
You are a GENIUS. Can you show me the AC controller? Message me the link, please, if you still have it.
@brandonwood0
@brandonwood0 11 жыл бұрын
I just tried shodan....How do you use the search results to actually access the devices? Do you paste the IP in the browser bar...totally new to this...Is there a beginners guide somewhere?
@TahreyUK
@TahreyUK 11 жыл бұрын
So, it didn't take me too long just using google to work out what the Security Integrator company was ... shoulda blanked out the whole name :D Let's put it this way, they're located in a small business park deep in a forest in Massachusetts...
@yellowklayman
@yellowklayman 11 жыл бұрын
Can you imagine a day when someone finds an exploit for a fridge and turns a whole brand into a bot network?
@powerjbn9283
@powerjbn9283 6 жыл бұрын
*camera
@sonofnone116
@sonofnone116 2 жыл бұрын
2022 says Russia might just pull that type of nonsense.
@undercop5567
@undercop5567 11 жыл бұрын
This is how the NSA must feel... I sure as hell wouldn't want to lose the ability to monitor cool shit like this, though it doesn't seem to have much of a legal practical purpose
@vissago
@vissago 12 жыл бұрын
Agreed - people are being lazy and silly and not taking security into consideration when putting webservers on stuff. By design, scada is NOT SUPPOSED TO BE ON THE INTERNET. I went to a handful of talks. Zfasels talk was rad, Rendermans talk was rad - I missed a BUNCH I wanted to go to, so I need the CDs.
@tomnesheim8817
@tomnesheim8817 10 жыл бұрын
ok, so you can go in and "look" at some of these traffic cams and other systems. But can the administrator of these devices see that you were in there after the fact and then send the cops after you for spying or industrial espionage? Or do you have to take measures to hide yourself?
@thelemonking3288
@thelemonking3288 9 жыл бұрын
***** tor. tor is always the answer
@dwerg1
@dwerg1 10 жыл бұрын
Holy shit, I've been to Skallerup Klit.
@Krissam2k
@Krissam2k 11 жыл бұрын
in before someone assassinates someone important by disabling his cars breaks over the internet with no credentials.
@Krissam2k
@Krissam2k 11 жыл бұрын
He didn't hack anything, all the things he showed were open to everyone, that's the point.
@brandonwood0
@brandonwood0 11 жыл бұрын
What do you think?
@VaraAccountti
@VaraAccountti 11 жыл бұрын
What you do if you get access for them?
@AayVy
@AayVy 11 жыл бұрын
kind of scared i have been in that place in demark.!!!!!! i live in denmark btw
@XRatedPoetry
@XRatedPoetry 11 жыл бұрын
Some guy in Germanys car is going to be really clean
@vissago
@vissago 11 жыл бұрын
youtube wont let me link it. Check out my toorcon talk (next vid?) it's got the links to the github repos.
@Skydmig
@Skydmig 12 жыл бұрын
Haha yeah I've been to that building. So random
@vissago
@vissago 11 жыл бұрын
Thanks! :D
@EnygmaHD
@EnygmaHD 10 жыл бұрын
Awesome
@VaraAccountti
@VaraAccountti 11 жыл бұрын
What is meaning of shodan?
@tax_evad3r
@tax_evad3r 11 жыл бұрын
I came from 4chan :D
@trickznmix
@trickznmix 11 жыл бұрын
Sir, how long have you been pentesting?
@nuvaintereseaza
@nuvaintereseaza 10 жыл бұрын
I died at 1:40 xD
@jayynecobb
@jayynecobb 11 жыл бұрын
Whered you get the name from? Thats my nickname, been my name for 30 years
@vissago
@vissago 11 жыл бұрын
Heh, thanks!
@VaraAccountti
@VaraAccountti 11 жыл бұрын
How i can find passwords?
@fraserbc
@fraserbc 6 жыл бұрын
You're obviously a script kiddie so why would anyone tell you?
@Speedy.V
@Speedy.V 10 жыл бұрын
This is REALLY NOT FUNNY...its actually HORRIFYING to see how many of these "connected" devices are so unsecured.
@njblair143
@njblair143 10 жыл бұрын
Seems pretty fuckin funny to me. And probably to anyone that grew up in, and embraced the i Generation.
@pfelon
@pfelon 11 жыл бұрын
Cactus
@5m4rt6uy
@5m4rt6uy 11 жыл бұрын
there is a hack to post links on youtube just remove the htp... and w3 . and change forward slash to back slash and you're good to go
@vissago
@vissago 12 жыл бұрын
Rendermans talk was badass - he found out the system that commercial aircraft use to keep track of planes flying around has little to no security and permits the injection of phantom aircraft. youtube com/watch?v=NSLqRXyxiBo (put the dots in) this is one of the presenters injecting a fake aircraft into the system - locally, so it doesnt make people shit their pants - and demonstrating that the system recognizes the aircraft.
@xmodalloy
@xmodalloy 3 жыл бұрын
Anyone else here after the east coast pipeline hack scare?
@njblair143
@njblair143 10 жыл бұрын
Game theorists 13:30
@MVrockersPS3
@MVrockersPS3 11 жыл бұрын
lol
@neliscph
@neliscph 12 жыл бұрын
Denmark got owned by iLon
@SurfKahuna2008
@SurfKahuna2008 12 жыл бұрын
Are you trolling? Do you not see the purpose of IP convergence? The purpose is to streamline the devices and products that we normally track using archaic means using a unified network, which can use targeted and/or unified interfaces for asset tracking. Knowledge is power, right? Rubbish bins being trackable can help the collection service know which bins are out, which can help determine routes, collection times, staffing, etc., which results in direct cost savings to the end users.
@aaronhamilton6872
@aaronhamilton6872 12 жыл бұрын
they could at least use ssh...
@OK2BCK
@OK2BCK 11 жыл бұрын
running web servers on various things, he makes it sound like a bad thing but it's not true. lack of security and common sense is a bad thing.
@valaha
@valaha 11 жыл бұрын
Welcome to Anonymous
@AayVy
@AayVy 11 жыл бұрын
holy shit he has hacked alot of placed i have been!!!!
@HassanSelim0
@HassanSelim0 11 жыл бұрын
is this what I think it is? the web server throwing at you: <input type="password" value="password123" /> because if that's the case, I can't even start to describe how stupid these people are! also, you wouldn't need a plugin for that, just plain old view source :D
@RAGHAVENDRASINGH17
@RAGHAVENDRASINGH17 4 жыл бұрын
this video DOESNT mention HOW he found this, video looks like bragging
@edbo10
@edbo10 3 жыл бұрын
the video description literally says that it was found via shodan, why can't people read the damn description it's not so much bragging so much as it is highlighting how people never change the default password on wifi-enabled devices
@RAGHAVENDRASINGH17
@RAGHAVENDRASINGH17 3 жыл бұрын
@@edbo10 i can see that he used shodan, i was asking about specific commands
@bencze1
@bencze1 11 жыл бұрын
I found the presentation style really annoying, not sure if it was the author or it was intended for a different audience. Looks like you were trying too hard to 'sell' it. The content was entertaining, some funny stuff, I guess this facebook world will continue for some while until some really, really bad incidents happen (ey, no i'm not promoting anything just some realistic thinking).
@morrisova2
@morrisova2 11 жыл бұрын
VIPmsg- I know ur probably a hack but what if your Jewish? ...
Here's What Happens When an 18 Year Old Buys a Mainframe
45:12
SHARE Association
Рет қаралды 3,2 МЛН
DEFCON 17: Failure
55:03
Christiaan008
Рет қаралды 344 М.
Não sabe esconder Comida
00:20
DUDU e CAROL
Рет қаралды 61 МЛН
Perfect Pitch Challenge? Easy! 🎤😎| Free Fire Official
00:13
Garena Free Fire Global
Рет қаралды 34 МЛН
"It's Fine," They Said. "Just Ship It," They Said.
1:13:28
Dartmouth
Рет қаралды 58 М.
How the Best Hackers Learn Their Craft
42:46
RSA Conference
Рет қаралды 2,6 МЛН
The Expert (Short Comedy Sketch)
7:35
Lauris Beinerts
Рет қаралды 31 МЛН
Is Skynet watching you already?
1:04:00
David Bombal
Рет қаралды 1,1 МЛН
Hacking Windows TrustedInstaller (GOD MODE)
31:07
John Hammond
Рет қаралды 702 М.
Hacktivity 2012 - Joe McCray - Big Bang Theory - Pentesting high security environments
50:53
Hacktivity - IT Security Festival
Рет қаралды 194 М.
AT&T Archives: The UNIX Operating System
27:27
AT&T Tech Channel
Рет қаралды 2 МЛН
Não sabe esconder Comida
00:20
DUDU e CAROL
Рет қаралды 61 МЛН