Tumblelog by Soup.io
Newer posts are loading.
You are at the newest post.
Click here to check if anything new just came in.

November 12 2016

digitaliban

November 05 2016

digitaliban
Reposted frompjoter pjoter viaevablis evablis
digitaliban

October 07 2016

digitaliban
5195 c15a 500
Reposted fromMatalisman Matalisman viaMissDeWorde MissDeWorde
digitaliban
8049 f34a 500
Reposted fromfungi fungi viawandi wandi

September 22 2016

digitaliban
Cat and dog headrest pillows
Cat headrest pillows
Dog headrest pillows
Dog headrest
Dog headrest pillow
Reposted fromoopsiak oopsiak viaevablis evablis
digitaliban
7503 52e5 500
Reposted fromelegy elegy

August 22 2016

digitaliban
NOT AUS
Reposted fromfightling fightling viawandi wandi

June 04 2016

digitaliban
Reposted fromFlau Flau viaEineFragevonStil EineFragevonStil

March 11 2016

digitaliban
1861 4a6a
Reposted fromsuper-hot super-hot viaevablis evablis
digitaliban
1787 b976
Reposted fromdoener doener viaevablis evablis
digitaliban

I stayed in a hotel with Android lightswitches and it was just as bad as you'd imagine

I'm in London for Kubecon right now, and the hotel I'm staying at has decided that light switches are unfashionable and replaced them with a series of Android tablets. A tablet displaying the text uk_bathroom isn't responding. do you want to close it? One was embedded in the wall, but the two next to the bed had convenient looking ethernet cables plugged into the wall. So.

I managed to borrow a couple of USB ethernet adapters, set up a transparent bridge (brctl addbr br0; brctl addif br0 enp0s20f0u1; brctl addif br0 enp0s20f0u2; ifconfig br0 up) and then stuck my laptop between the tablet and the wall. tcpdump -i br0 showed traffic, and wireshark revealed that it was Modbus over TCP. Modbus is a pretty trivial protocol, and notably has no authentication whatsoever. tcpdump showed that traffic was being sent to 172.16.207.14, and pymodbus let me start controlling my lights, turning the TV on and off and even making my curtains open and close. What fun!

And then I noticed something. My room number is 714. The IP address I was communicating with was 172.16.207.14. They wouldn't, would they?

I mean yes obviously they would.

It's not as bad as it could be - the only traffic I could see was from the 207 subnet, so it seems like there's a separate segment per floor. But I could query other rooms on my floor to figure out whether the lights were on or not, which strongly implies that I could control them as well. Jesus Molina talked about doing this kind of thing a couple of years ago, so it's not some kind of one-off - instead, hotels are happily deploying systems with no meaningful security, and the outcome of sending a constant stream of "Set room lights to full" and "Open curtain" commands at 3AM seems fairly predictable.

We're doomed.
mjg59 | I stayed in a hotel with Android lightswitches and it was just as bad as you'd imagine
Reposted fromnaich naich viaTechnofrikus Technofrikus

February 29 2016

digitaliban
Reposted fromFlau Flau viaEineFragevonStil EineFragevonStil

February 23 2016

4107 06a7

turbo-kitty:

fifty-shadesofgay:

seerofsarcasm:

I CAN’T

this is my favorite post on tumblr okay

THAT COST $7?! WTF AMAZON

Reposted fromtornfret tornfret viawandi wandi
digitaliban
Reposted fromiv-vi iv-vi viaEineFragevonStil EineFragevonStil

February 11 2016

digitaliban

January 27 2016

digitaliban
7168 fc44 500
Reposted fromswissfondue swissfondue viawandi wandi
digitaliban
The dorse
Reposted fromfabs3 fabs3 viawandi wandi

January 25 2016

digitaliban
8675 c2d0 500
Reposted fromneon neon viaTechnofrikus Technofrikus
digitaliban
5943 aaf3 500
Reposted fromRockYourMind RockYourMind viaevablis evablis
Older posts are this way If this message doesn't go away, click anywhere on the page to continue loading posts.
Could not load more posts
Maybe Soup is currently being updated? I'll try again automatically in a few seconds...
Just a second, loading more posts...
You've reached the end.

Don't be the product, buy the product!

Schweinderl