[# Systematic Destruction (Hacking the Scammers pt. 2)
Taking on the “Smishing Triad”](https://blog.smithsecurity.biz/systematic-destruction-hacking-the-scammers-pt.-2) g
His blog on the topic if you don’t want the wired summary.
[# Systematic Destruction (Hacking the Scammers pt. 2)
Taking on the “Smishing Triad”](https://blog.smithsecurity.biz/systematic-destruction-hacking-the-scammers-pt.-2) g
His blog on the topic if you don’t want the wired summary.
I’m all for the enthusiasm I’m seeing with Harris, but am happy to see someone like Axelrod pointing out the polling. He’s absolutely right in that it will take work to win, and mistakes to lose. Fortunately Harris seem to be working and Trump seems to be making mistakes for now. Let’s hope it doesn’t flip soon.
Alternative link
In 2021, Trump’s running mate, Sen. JD Vance of Ohio, denounced women for leaving abusive husbands. The same year, he also decried allowing rape victims to abort their pregnancies, claiming all pregnancies should be forced to term, “even though the circumstances of that child’s birth are somehow inconvenient.” Former Fox News host Tucker Carlson also spoke. In the past, he has argued that raping underage girls is less bad if the rapists marry them first, and complained about rape shield laws that protect the identity of victims.
This is part of the Trump campaign’s strategy of shoring up support among younger men by appealing directly to the Joe Rogan and Jordan Peterson fanboys. The tactic runs the risk of backfire. If female swing voters learn how much the GOP is built on apologia for sexual violence, focus group information suggests it will turn them away from Trump. With Biden as the nominee, there was a real chance this issue would stay on the back burner. Even though he was the author of the Violence Against Women Act in the 90s, Biden has proved incapable of making Trump’s sexual violence a defining issue. He’s tried, even using the word “rape” to describe Trump’s behavior. But Biden’s overall problems communicating got in the way of this message.
Harris, however, is not hobbled by the issues with talking that plagued Biden in the end. More than that, sexual violence is an issue that she can speak about with a level of authority that Biden — really, most male politicians — never could achieve. Her gender is only part of it. As she often discusses on the campaign trail, Harris got her start in criminal law by working in the sex crimes division of Alameda County. She spent years talking about these hard issues in a court setting, and it shows in the way she strikes a deft balance between sensitivity and frankness when speaking about sexual violence. I recommend watching this co-interview she did on MSNBC with Hadley Duvall, a child sex abuse survivor who has been speaking out about abortion rights. Harris tells the story of her high school friend who told her that her stepfather was molesting her. “I said to her: ‘you have to come live with us. I called my mother and my mother said, ‘of course she has to come stay with us.’”
It’s going to be a much better race.
Alternative link non paywalled
If this request worked, it meant that I could use an “encryptedValue” parameter in the API that didn’t have to have a matching account ID.
I sent the request and saw the exact same HTTP response as above! This confirmed that we didn’t need any extra parameters, we could just query any hardware device arbitrarily by just knowing the MAC address (something that we could retrieve by querying a customer by name, fetching their account UUID, then fetching all of their connected devices via their UUID). We now had essentially a full kill chain.
I formed the following HTTP request to update my own device MAC addresses SSID as a proof of concept to update my own hardware:
…
Did it work? It had only given me a blank 200 OK response. I tried re-sending the HTTP request, but the request timed out. My network was offline. The update request must’ve reset my device.
About 5 minutes later, my network rebooted. The SSID name had been updated to “Curry”. I could write and read from anyone’s device using this exploit.
This demonstrated that the API calls to update the device configuration worked. This meant that an attacker could’ve accessed this API to overwrite configuration settings, access the router, and execute commands on the device. At this point, we had a similar set of permissions as the ISP tech support and could’ve used this access to exploit any of the millions of Cox devices that were accessible through these APIs.
Blows me a away that an unauthenticated API with sensitive controls and data was publicly facing. Corporations these days want all your data but wonder why some customers are worry about how it is protected, it let alone if it’s being sold. Why should I allow you to control my hardware when you can’t protect yourself.
Yt-DLP and it’s variation (Seal, YTDLnis, etc.), newpipe and it’s variation (Tubular, Newpipe Sponsorblock, etc) already allow you to do this without having to get manual.