LED Marquee kits are still available

Some of you newer members missed out on this, we picked up a bunch of parts to assemble kits to build this LED Marquee:

https://www.thingiverse.com/thing:2867294

for the December meeting, and we still have a few left. Includes case, Wemos D1 Mini microcomputer and LED matrix panels. Assembly and programming instructions are at that link. The 3d-printed case I settled on was white, and I went with red LED panels. It looks good.

If you’re interested in getting into IOT devices, it’s a great intro project. Not much soldering, good Arduino experience/introduction, etc. If you’re already into IOT stuff, it makes a great gift.

Cost is $15 per kit. Not doing shipping to keep the cost down, but we could meet up in the area and do a handoff. HMU up on twitter @dc540baab or email [email protected] if you want one.

Here’s what our kit looks like:

Busy busy week.

I’ve always been kind of scattered in my approach and involvement in new things. I get hyper-focused on a new project, idea or gadget, at the expense of other things I might have going on, and I kind of meander back and forth between my pursuits, inching each forward a bit at a time. My internal guidance system tells me that one day they will all converge and Nirvana will happen.

With that being said, let me tell you about my week.

After last week’s meeting, I gave myself some internal mental grief for lack of follow-through and lack of motivation. I went downstairs to the lab that night, determined to make some forward momentum on my 3d printer, which is one of those things that had been a long-standing victim of my procrastination.

I bought the thing over 3 years ago, before my first Defcon and before my first Burn. I had gotten to the point of bed leveling, and then I was overcome by events. I went to several Burn events that year, and Defcon, and everything at home was just left in the state it was in. Then everything else piled on. I focused on home improvements for a year or two, changed jobs, went to Defcon a couple more times, and moved residences.

Fast forward to last year in the new house. I unpacked it, thought to myself, “I probably don’t have everything it takes to get this operational right here in front of me. I’m going to procrastinate further while I focus on organizing all of my parts, tools, small parts, cables, and everything else, and at the same time make tiny progress on many other little things.

Anyhow, back to last Monday night. Step 1: What the fuck printer do I even have? It’s been that long, and I felt like shit about that. I couldn’t even remember what I had bought. So I figured out how to find out, installed and launched pronterface, and issued the M115 code to get the firmware info. It’s an Anet A8. Alrighty. So I double-checked the bed-leveling, dug out a microSD card and threw a test cube gcode onto it. I fed in the filament (wondering the whole time if it was too old to even use) and started the job. The print came out kind of shitty and thin, but it worked. That’s because the slic3r I used to slice it had shitty default settings, and I didn’t even bother to customize them to what the print recommened.

The important thing is that I made progress.

So I tried to print something else, and it failed. I quickly realized I needed a glass bed and a build surface. SO I ordered those and moved on to the next project.

The next project was Hackerbox #0036, the JumboTron, a 64×32 RGB matrix run by an ESP32 devboard. I had abandoned that project when I realized it needed a power source I didn’t think I had at the time, or couldn’t find, or whatever buillshit excuse. So I ordered a power supply, one of those steel cage-encased hobbyist power supplies rated for 5V/4A.

I continued to document progress, organize shit, find shit, clean shit, etc., until the bed and build surface came. YAY.

Only my first print failed. No flow. Turns out the nozzle got clogged. Cut me some slack, I’m new at this. So I ordered 30 replacement nozzles for $6.

Meanwhile the power supply showed up. I spent a few hours yesterday making that happen, and researching other cool things to do with it (build a 3d case for it, make the wiring more permanent and less fragile, make it able to update OTA via wifi, etc).

My nozzles may or may not be here tomorrow. But I feel like I’ve had a fantastic week as far as tech stuff goes.

See y’all tomorrow nighht.

BSidesLV Cancelled

So I’m sure you’ve seen the alert that BSides Las Vegas is cancelled this year, you know, due to that thing that’s going around.

I have zero inside information, but I can’t imagine a scenario where this doesn’t play into the decision process for DEFCON and BlackHat, since it’s the same location during the same week. While I haven’t cancelled my hotel booking yet, it’s looking more and more likely.

I’m sad about this.

March Meeting Cancelled

It’s not even an abundance of caution. After reading the latest from WHO and CDC, it’s just common sense. Stay safe, y’all. We’ll get together when thing settles down.

Fun with Payphones, part 1

So I scored an old payphone. My “vintage replica” just wasn’t cutting it anymore.

It appears to be a Western Electric single-slot 1C from May of 1977.

Decent cosmetic condition, but looks aren’t the reason I bought it. I bought it to learn, play, restore, and maybe even modify it.

It didn’t come with keys — this is problem .

There’s a reason these things stayed in service so long, and it’s not just because cellphones were invented and eventually became ubiquitous and disposable. It’s also because they were seriously armored and indestructable. Picking these locks when they’re in good shape is no joke. In fact, I found the restricted Bell document that shows what to do when you no longer have the key to the vault door (the shiny square door at the bottom) — basically you use a circle template and drill through the door so that you have direct access to the latch bolts internally. Then you replace the door and the lock assembly with one which has keys.

The problem is, step one in that process is “remove the cover assembly.” Which is also locked. So what if I ALSO don’t have keys to the cover assembly? Well, I guess I could maybe drill that lock out — BUT I found another tutorial that indicates that with 8-15 minutes of tapping with a dowel and hammer, you basically nudge the four screws securing that lock assembly out from the inside.

It looks like that would have to happen anyway, because these locks looks like shit, and might not be pickable even by a TOOOL expert on a good day.

Fortunately, replacement vault doors, coin vaults and lock assemblies with keys are available on eBay, so eventually this project may find itself nudged further along. I’ll update you.

February Meeting cancelled!

Sorry folks, I had to cancel hosting the February meetup. Heading out to Vegas (I know, not even Defcon season!) to help my mom recover from cancer surgery. You’re welcome to meetup on your own at Glory Days or wherever if you like. Please talk amongst yourselves. 🙂

$15 Lan Tap? You’re joking, right?

During the last meeting, we were discussing Zeek (formerly Bro) and narrowing down choices for sniffing accessories (tap vs span port). We settled on the Great Scott Gadgets lan taps. The pro version is enclosed and complete for $40, and the Throwing Star version is in kit form and just $15. Because I’m (a) cheap, (b) addicted to flux fumes, and (c) a ninja, I opted for the throwing star. I just slapped it together in about ten minutes, and it seems to be working just fine.

Another successful meeting on the books.

Only a couple members could make tonight’s meeting, but it was a positive meeting anyway. I was working on my Vic-20 recovery when Kevin arrived, and we pretty quickly ended up in a conversation about Zeek. He needs to master it for work, and I need to master it just because. I found a lab from FAU that might be helpful. Here’s the link:

http://ce.sc.edu/cyberinfra/docs/workshop/Zeek_Lab_Series.pdf

We did a bit of research on network taps, and settled on Great Scott Gadgets’ Lan Tap Pro (or, if you’re cheap and handy like me, the Throwing Star Lan Tap Kit). both are passive LAN taps, and will pipe all traffic that passes through them into your Zeek, Snort or other IDS box.

We’re looking forward into the new year and planning some exciting talks and presentations. Maybe we’ll talk about Zeek in February if we’re ready, and Dan wants to talk about social engineering research tools, possibly in March.

Next meeting is Monday February 24. I hope you can make it.

Site move

Today I migrated the DC540 website to an overseas VPS. Somehow an overseas VPS, with just 2GB of RAM, responds faster by multitudes than shared hosting at Hostgator. I guess Hostgator has reached maximum oversubscription. Please let me know how YOU experience the website, and let me know if I missed any bugs. Took me longer than I should have to get the events plugin working, for stupid configuration reasons that I am too proud to admit.

TIL about john the ripper and trigraph frequencies.

I have an assignment to crack an Office password for a document. I have tried using john and hashcat with several large wordlists, and had no luck, so I decided to go all-in and just leave a Kali instance running john in incremental (brute force) mode for “as long as it takes.” It’s been two days so far.

I have it running within ‘screen’ so that I can occasionally login to the system remotely to check progress without risk of losing it. I was excited at one point yesterday seeing that it was in the middle of checking seven-character passwords, but then I checked back later and it was checking six-character passwords. This morning, five. I wanted to understand — I assumed (without doing a deep dive on the mechanics) that it would just go literally incrementally. aaaaa, aaaab, aaaac, etc. That was an incorrect assumption.

John’s incremental mode actually operates on “trigraph frequencies.” While I understand the concept of trigraph frequencies (certain sets of three characters occur more frequently than others, and this can help with decryption efforts, I have my doubts as to whether this helps in cracking passwords. Passwords aren’t always natural speech, after all.

Anyhow, it’s been running for two days now, and I’ll post about it again when it’s done just to give an idea of whether it’s successful, and if so, how long it took vs the complexity of the password.

If anyone else wants to try using similar or other methods, let me know, and I’ll send you the hash (generated by office2john). No, I can’t send you the actual document. That would be unethical.

Holy Crap, It’s 2020!

Several people indicated being unavailable on the fourth Monday in January. Options: 4th Monday anyway, 3rd Monday (MLK day), some other day. I’ll pencil in 4th Monday anyway until we achieve consensus.

It’s been a few days now, so…

I can safely say that I believe this show will be recognized, when the rest of the world catches up and watches it, as right up there with Breaking Bad as some of the best television ever written.

Someone on Reddit posted this, and I’m really glad I didn’t have a mouthful of coffee when I saw it. Laugh with me, fellow devotees!

Apache, filebeat and Graylog – Oh My

I’ve been getting notices from one of my more popular WordPress sites of an increasing number of attempts to login lately. Compared to my other sites, this one feels like it’s being targeted for some reason. Normally I don’t pay a whole lot of attention to Apache logs unless I’m troubleshooting something, but I felt like ignoring this would be a missed opportunity.

The site is hosted on a shared site out in the wild. I don’t have full access to the server, but the vendor is kind enough to deposit apache logs into a known location on a regular basis.

So I spun up a Graylog instance at home, setup an automated rsync to suck down the logs, and then used filebeat with a logstash output to pipe them into Graylog for me. At some point I might set up a real SIEM (maybe SIEMonster’s community edition?) to do a bit of threat intel for me, but for now it’s a good pull this morning to have the logs for 20-30 websites sucked into my Graylog VM as a starter.

It’s a two-pot coffee day today.

The exercise ended up pulling in about 3 million log lines, and now I can easily visualize a history of what these ass-monkeys did on my hosting server.

FOLLOWUP: Yeah, turns out they were attracted to the WordPress by the unsecured Wiki hiding underneath. On 11/6, I upgraded mediawiki, and apparently missed turning off registrations. Since then, I’ve had 55,000 new users on the Wiki, and over 60,000 page edits (new pages, spam vandalism, etc). It was relatively easy to clean up after, but they were really having their way with that site.

I suspect the brute-forcing is going on especially hard today because they think nobody’s watching on a holiday weekend. BITCH I’M ALWAYS WATCHING.

December Meeting update…

Things are rolling right along for December’s meeting. I hope to see a bunch of you on the 16th.

  • I’ve got a healthy smattering of Kali and ParrotOS workstations on the long table ready for anyone who wants to do actual pentesting against the CTF server. (These were the HP All-In-Ones I picked up at the auction.)
  • The CDC book will be one door prize/raffle for one lucky winner, and I will also have a few decks of “Backdoors and Breaches,” a tabletop card-based game for simulating incident response using a D20 for other winners.
  • As I mentioned before, the LED Marquee parts kits are all here ($15 a set), and I built and tested one. It’s been up and running in my family room for a couple of weeks now. If you want to assemble one at the meeting, it’s super-easy, and if you want it programmed as well, I’ll leave the choice up to you whether you want me to push the programming from my Arduino IDE on my laptop, or if you’d rather go through the process of setting up Arduino yourself, for the learning experiences. There are a number of dependencies and modifications that need to be made, more than I’ve had to do in any other Arduino project. Most of them are well-documented, and some are just common-sense fixes, I trust all of you are capable of figuring it out. It’s just a matter of do you want to go home with a working device or a challenge. 🙂

I mentioned this on Twitter, but not all of you follow Twitter — I picked up the “Crash Course Electronics & PCB Design” course on Udemy over Black Friday weekend for just $10. I can’t say enough good things about it. I have a reasonable enough basic understanding of electronics to get by on mimicry and duplication with minor troubleshooting, but I’ve always wanted a deeper understanding and more foundational knowledge. This 100-hour course, taught patiently by Andre Lamothe, is really hitting the mark.

I guess the best way to characterize it is, come for the PCB design, stay for the best approach to electronics foundational knowledge I’ve seen yet. I was going to skip ahead to the PCB design part, but I’m learning and enjoying the electronics portion so much that I haven’t been able to pull myself away. Already I’ve added a few more things to my wishlist (a signal generator, a set of thru-hole diodes, etc.) and acquired a renewed sense of vigor and enthusiasm for my portable payphone project, which fell by the wayside in the old house when I ran into issues trying to power it properly. Exciting times indeed. It’s one thing being able to troubleshoot a circuit by trial and error. It’s another thing to understand the math and theory behind it and be able to make it right — or even make it better.

Be sure to register for the meeting so that I can be sure to have enough beer chairs for everyone.

Fascinating — The Drone Databook, by Dan Gettinger

From the Preface:

Once a novelty, drones have become standard military equipment, spawning a global network of units, bases, and test sites. Battlefields in Ukraine, Syria, and Yemen, as well as zones of geopolitical conflict such as the Persian Gulf and the East China Sea, are increasingly crowded with drones of varying size and sophistication. Whether they are used for intelligence gathering, aerial strikes, artillery spotting, or electronic warfare, drones are a leading contributor to the changing character of modern war.

The Drone Databook is a study of military drone capabilities. It is comprised of profiles of 101 countries in seven regions – Asia and Oceania, Eurasia, Europe, Latin America, the Middle East and North Africa, North America, and Sub-Saharan Africa – as well as two appendixes that address military drone infrastructure around the globe and the technical specifications of more than 170 drones currently in use by these countries. The Databook evaluates the military drone capabilities of each country in terms of six categories: inventory and active acquisition programs, personnel and training programs, infrastructure, operational experience, aircraft research and development programs, and exports.