Defcon badge info

SO the Defcon Badge deep-dive was well-received during tonight’s Zoom, there were some interesting ideas thrown about. For now, we’re collecting everything we figure out about it in the bad decisions discord. If you’re not on that, ask yourself what you’re even doing with your life.

Defcon28 Badge

Anybody interested in collaborating to investigate the Defcon 28 tape badge to uncover its secrets? Hit me up if you’ve got ideas and cycles.

Hackerspace Bookshelf…

The DC540 hackerspace just got a bookshelf. It’d be pretty cool if it had more titles on it that are relevant to this thing of ours. If you’ve got infosec, hacking, telephony, o’reilly books, etc., you no longer need, please consider donating.

DC540 hackerspace network infrastructure…

I’ve been working on infrastructure quite a bit lately. As a means of allowing people to become more involved in DC540 projects as they arise, I’ve been working on an authentication and information management infrastructure within the hackerspace. For example, I have Atlassian’s Jira and Confluence for collaboration, project management, and knowledge management, Bitbucket for code storage, and shared NFS file storage. The idea was originally that I’d be able to find some people willing to collab on projects, and the infrastructure would be there and ready for them. Since the pandemic has basically put the kibosh on in-person gatherings, I’m now working on opening that up to members via VPN.

I realize that not everyone has time to collab on projects, or even the interest. But when we find those that have the passion and availability to get involved in that way, it will be ready. I have enough information and projects of my own that it needs to be done anyway.

Users will be able to pound on the CTF vulnerable boxes, review and add documentation, upload 3d-printer files and schematics. I will try to integrate everything I have into the environment so there’ll be much to play with. Perhaps I’ll move the citadel into this environment as well.

KiCAD/FreeCAD free course

Did y’all see this?

https://www.eventbrite.com/e/hackadayu-kicad-freecad-tickets-109682641734?utm_source=Tindie+Community&utm_campaign=2db292f858-Community-July2020-1&utm_medium=email&utm_term=0_bb799798bb-2db292f858-87037781&mc_cid=2db292f858&mc_eid=7ed4a54b79

Hackaday U is offering a free KiCAD/FreeCAD course. Full course is four sessions, I’m signed up for what I hope is the first session Tuesday evening at 7. I figure it will mesh very nicely with the electronics course, since that course is mostly taught on Labcenter Proteus ($$$).

Meeting Notice

Monday’s check-in meeting is on at 6:30 at the following link:

https://zoom.us/j/819063060?pwd=b0wwUWtpRENkMGFiNUJQQW5pdVVJZz09

It’ll be limited to an hour, for me anyway, I have a rescue group board meeting at 7:30.

I can’t wait till this stupid pandemic is over.

LED Marquee kits are still available

Some of you newer members missed out on this, we picked up a bunch of parts to assemble kits to build this LED Marquee:

https://www.thingiverse.com/thing:2867294

for the December meeting, and we still have a few left. Includes case, Wemos D1 Mini microcomputer and LED matrix panels. Assembly and programming instructions are at that link. The 3d-printed case I settled on was white, and I went with red LED panels. It looks good.

If you’re interested in getting into IOT devices, it’s a great intro project. Not much soldering, good Arduino experience/introduction, etc. If you’re already into IOT stuff, it makes a great gift.

Cost is $15 per kit. Not doing shipping to keep the cost down, but we could meet up in the area and do a handoff. HMU up on twitter @dc540baab or email [email protected] if you want one.

Here’s what our kit looks like:

Busy busy week.

I’ve always been kind of scattered in my approach and involvement in new things. I get hyper-focused on a new project, idea or gadget, at the expense of other things I might have going on, and I kind of meander back and forth between my pursuits, inching each forward a bit at a time. My internal guidance system tells me that one day they will all converge and Nirvana will happen.

With that being said, let me tell you about my week.

After last week’s meeting, I gave myself some internal mental grief for lack of follow-through and lack of motivation. I went downstairs to the lab that night, determined to make some forward momentum on my 3d printer, which is one of those things that had been a long-standing victim of my procrastination.

I bought the thing over 3 years ago, before my first Defcon and before my first Burn. I had gotten to the point of bed leveling, and then I was overcome by events. I went to several Burn events that year, and Defcon, and everything at home was just left in the state it was in. Then everything else piled on. I focused on home improvements for a year or two, changed jobs, went to Defcon a couple more times, and moved residences.

Fast forward to last year in the new house. I unpacked it, thought to myself, “I probably don’t have everything it takes to get this operational right here in front of me. I’m going to procrastinate further while I focus on organizing all of my parts, tools, small parts, cables, and everything else, and at the same time make tiny progress on many other little things.

Anyhow, back to last Monday night. Step 1: What the fuck printer do I even have? It’s been that long, and I felt like shit about that. I couldn’t even remember what I had bought. So I figured out how to find out, installed and launched pronterface, and issued the M115 code to get the firmware info. It’s an Anet A8. Alrighty. So I double-checked the bed-leveling, dug out a microSD card and threw a test cube gcode onto it. I fed in the filament (wondering the whole time if it was too old to even use) and started the job. The print came out kind of shitty and thin, but it worked. That’s because the slic3r I used to slice it had shitty default settings, and I didn’t even bother to customize them to what the print recommened.

The important thing is that I made progress.

So I tried to print something else, and it failed. I quickly realized I needed a glass bed and a build surface. SO I ordered those and moved on to the next project.

The next project was Hackerbox #0036, the JumboTron, a 64×32 RGB matrix run by an ESP32 devboard. I had abandoned that project when I realized it needed a power source I didn’t think I had at the time, or couldn’t find, or whatever buillshit excuse. So I ordered a power supply, one of those steel cage-encased hobbyist power supplies rated for 5V/4A.

I continued to document progress, organize shit, find shit, clean shit, etc., until the bed and build surface came. YAY.

Only my first print failed. No flow. Turns out the nozzle got clogged. Cut me some slack, I’m new at this. So I ordered 30 replacement nozzles for $6.

Meanwhile the power supply showed up. I spent a few hours yesterday making that happen, and researching other cool things to do with it (build a 3d case for it, make the wiring more permanent and less fragile, make it able to update OTA via wifi, etc).

My nozzles may or may not be here tomorrow. But I feel like I’ve had a fantastic week as far as tech stuff goes.

See y’all tomorrow nighht.

BSidesLV Cancelled

So I’m sure you’ve seen the alert that BSides Las Vegas is cancelled this year, you know, due to that thing that’s going around.

I have zero inside information, but I can’t imagine a scenario where this doesn’t play into the decision process for DEFCON and BlackHat, since it’s the same location during the same week. While I haven’t cancelled my hotel booking yet, it’s looking more and more likely.

I’m sad about this.

Fun with Payphones, part 1

So I scored an old payphone. My “vintage replica” just wasn’t cutting it anymore.

It appears to be a Western Electric single-slot 1C from May of 1977.

Decent cosmetic condition, but looks aren’t the reason I bought it. I bought it to learn, play, restore, and maybe even modify it.

It didn’t come with keys — this is problem .

There’s a reason these things stayed in service so long, and it’s not just because cellphones were invented and eventually became ubiquitous and disposable. It’s also because they were seriously armored and indestructable. Picking these locks when they’re in good shape is no joke. In fact, I found the restricted Bell document that shows what to do when you no longer have the key to the vault door (the shiny square door at the bottom) — basically you use a circle template and drill through the door so that you have direct access to the latch bolts internally. Then you replace the door and the lock assembly with one which has keys.

The problem is, step one in that process is “remove the cover assembly.” Which is also locked. So what if I ALSO don’t have keys to the cover assembly? Well, I guess I could maybe drill that lock out — BUT I found another tutorial that indicates that with 8-15 minutes of tapping with a dowel and hammer, you basically nudge the four screws securing that lock assembly out from the inside.

It looks like that would have to happen anyway, because these locks looks like shit, and might not be pickable even by a TOOOL expert on a good day.

Fortunately, replacement vault doors, coin vaults and lock assemblies with keys are available on eBay, so eventually this project may find itself nudged further along. I’ll update you.

Another successful meeting on the books.

Only a couple members could make tonight’s meeting, but it was a positive meeting anyway. I was working on my Vic-20 recovery when Kevin arrived, and we pretty quickly ended up in a conversation about Zeek. He needs to master it for work, and I need to master it just because. I found a lab from FAU that might be helpful. Here’s the link:

http://ce.sc.edu/cyberinfra/docs/workshop/Zeek_Lab_Series.pdf

We did a bit of research on network taps, and settled on Great Scott Gadgets’ Lan Tap Pro (or, if you’re cheap and handy like me, the Throwing Star Lan Tap Kit). both are passive LAN taps, and will pipe all traffic that passes through them into your Zeek, Snort or other IDS box.

We’re looking forward into the new year and planning some exciting talks and presentations. Maybe we’ll talk about Zeek in February if we’re ready, and Dan wants to talk about social engineering research tools, possibly in March.

Next meeting is Monday February 24. I hope you can make it.

Site move

Today I migrated the DC540 website to an overseas VPS. Somehow an overseas VPS, with just 2GB of RAM, responds faster by multitudes than shared hosting at Hostgator. I guess Hostgator has reached maximum oversubscription. Please let me know how YOU experience the website, and let me know if I missed any bugs. Took me longer than I should have to get the events plugin working, for stupid configuration reasons that I am too proud to admit.

Holy Crap, It’s 2020!

Several people indicated being unavailable on the fourth Monday in January. Options: 4th Monday anyway, 3rd Monday (MLK day), some other day. I’ll pencil in 4th Monday anyway until we achieve consensus.

Apache, filebeat and Graylog – Oh My

I’ve been getting notices from one of my more popular WordPress sites of an increasing number of attempts to login lately. Compared to my other sites, this one feels like it’s being targeted for some reason. Normally I don’t pay a whole lot of attention to Apache logs unless I’m troubleshooting something, but I felt like ignoring this would be a missed opportunity.

The site is hosted on a shared site out in the wild. I don’t have full access to the server, but the vendor is kind enough to deposit apache logs into a known location on a regular basis.

So I spun up a Graylog instance at home, setup an automated rsync to suck down the logs, and then used filebeat with a logstash output to pipe them into Graylog for me. At some point I might set up a real SIEM (maybe SIEMonster’s community edition?) to do a bit of threat intel for me, but for now it’s a good pull this morning to have the logs for 20-30 websites sucked into my Graylog VM as a starter.

It’s a two-pot coffee day today.

The exercise ended up pulling in about 3 million log lines, and now I can easily visualize a history of what these ass-monkeys did on my hosting server.

FOLLOWUP: Yeah, turns out they were attracted to the WordPress by the unsecured Wiki hiding underneath. On 11/6, I upgraded mediawiki, and apparently missed turning off registrations. Since then, I’ve had 55,000 new users on the Wiki, and over 60,000 page edits (new pages, spam vandalism, etc). It was relatively easy to clean up after, but they were really having their way with that site.

I suspect the brute-forcing is going on especially hard today because they think nobody’s watching on a holiday weekend. BITCH I’M ALWAYS WATCHING.