<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Michael Wheeler &#187; hack</title>
	<atom:link href="http://michael-wheeler.org/tag/hack/feed/" rel="self" type="application/rss+xml" />
	<link>http://michael-wheeler.org</link>
	<description>mmmm bacon.</description>
	<lastBuildDate>Fri, 27 Jan 2012 12:12:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Why using SSH won&#039;t secure your network</title>
		<link>http://michael-wheeler.org/2010/03/04/ssh/</link>
		<comments>http://michael-wheeler.org/2010/03/04/ssh/#comments</comments>
		<pubDate>Thu, 04 Mar 2010 10:11:29 +0000</pubDate>
		<dc:creator>mwheeler</dc:creator>
				<category><![CDATA[None]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[snmp]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://michael-wheeler.org/?p=459</guid>
		<description><![CDATA[SSH is a wonderful protocol / tool which I use every day. It allows a user secure communication between hosts. Amongst it&#8217;s many features it allows people to securely to execute commands, copy files and tunnel net traffic. Using SSH &#8230; <a href="http://michael-wheeler.org/2010/03/04/ssh/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>SSH is a wonderful protocol / tool which I use every day. It allows a user secure communication between hosts. Amongst  it&#8217;s many features it allows people to securely to execute commands, copy files and tunnel net traffic. Using SSH rather than telnet to configure and access devices is a great step up, and unlike telnet, passwords and secure information is encrypted.</p>
<p>But just because you&#8217;ve enabled SSH on all your devices doesn&#8217;t mean your network is any more secure. SSH is only one in many changes that need to be changed in order to have a secure network.</p>
<p><strong>Network Management</strong>, most network management software still access your devices using insecure techniques (some of which are listed below). What&#8217;s the use of using SSH, when you network management polls it every 5 minutes insecurely</p>
<p><strong>Keys</strong><br />
A simple think overlooked in most SSH setups, is that keys are never logged / saved, nor are private/public key authentication. So when you have 500 network devices, when you connect to one, people start getting into the habit of just accepting ssh keys without looking at them. A simple ARP man in the middle attack could allow a user to grab your password without any work.</p>
<p><strong>File Transfer</strong><br />
So you need to upload a config file. Simple I&#8217;ll just TFTP or FTP it. Maybe you might even HTTP it across. Well there you go, all the work of installing SSH on all your devices has been wasted. This can easily be fixed with either SCP, HTTPS or FTPS.</p>
<p><strong>SNMP</strong><br />
Commonly used SNMPv2 and v1 has no encryption support. It is common that most devices are setup with SNMPv2 and v1 rather than the SNMPv3 which support encryption. SNMP can be used to monitor, and set configuration options on most devices.</p>
<p><strong>Vulnerabilities in software</strong><br />
Sounds pretty stupid, but why would an attacker bother with SSH when they can just exploit a page. It&#8217;s annoying, but IOS and other software need to stay updated.</p>
<p><strong>Routing Protocols</strong><br />
Routing protocols really need to stay on routed links. Having OSPF running on general access VLANs is not a good idea. Very easy to make a man in the middle attack.</p>
<p><strong>Spanning Tree</strong><br />
Spanning Tree can easily be disturbed, and be used for malicious activities. BPDU GUARD really needs to be enabled on access ports, otherwise you&#8217;ll be in trouble.</p>
<p>Theses simple fixes will in fact make your network more secure than SSH would.</p>
]]></content:encoded>
			<wfw:commentRss>http://michael-wheeler.org/2010/03/04/ssh/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Iodine</title>
		<link>http://michael-wheeler.org/2009/10/25/iodine/</link>
		<comments>http://michael-wheeler.org/2009/10/25/iodine/#comments</comments>
		<pubDate>Sun, 25 Oct 2009 05:56:10 +0000</pubDate>
		<dc:creator>mwheeler</dc:creator>
				<category><![CDATA[None]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[iodine]]></category>
		<category><![CDATA[networking]]></category>

		<guid isPermaLink="false">http://michael-wheeler.org/?p=375</guid>
		<description><![CDATA[realred_draco &#8211; Iodine, Disinfecting Our Wounds Since I didn&#8217;t want to get charged $27.50 for 100MB of data on ReiverNet at the Oaks Auroa hotel (amazing place), I looked for some ways around the system. Before leaving I read up &#8230; <a href="http://michael-wheeler.org/2009/10/25/iodine/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="flickr"><a title="photo sharing" href="http://www.flickr.com/photos/10941454@N08/986195983/"><img class="flickr-photo" src="http://p.michael-wheeler.org/flickr/986195983_d00c51c398.jpg" alt="freebsd-logo" width="200" /></a><br />
<span class="flickr-caption"><a href="http://www.flickr.com/photos/10941454@N08/">realred_draco</a> &#8211; <a href="http://www.flickr.com/photos/10941454@N08/986195983/">Iodine, Disinfecting Our Wounds</a></span></div>
<p class="flickr-yourcomment">
Since I didn&#8217;t want to get charged $27.50 for 100MB of data on <a href="http://www.reivernet.com/">ReiverNet</a> at the Oaks Auroa hotel (amazing place), I looked for some ways around the system. Before leaving I read up about <a href="http://thomer.com/icmptx/">ICMPTX</a>( IP over ICMP, e.g. ping packets ) and <a href="http://thomer.com/howtos/nstx.html">NSTX</a>(IP over DNS). ICMP didn&#8217;t seem to work, but hostnames were resolvable, so I done some more reading on NSTX.</p>
<p>Turns out that some software called <a href="http://code.kryo.se/iodine/">iodine</a> has taken over the roll of NSTX. I was able to convince another user to compile iodine for snow leopard because I forgot to install xtools before I left, and followed <a href="http://www.spoofedpacket.net/index.php/2007/10/31/everyone-needs-a-little-iodine/"> this</a> tutorial on installing on FreeBSD and <a href="http://www.brool.com/index.php/dns-tunneling-on-mac-os-x">this</a>. In no time I had free internet at the cost of their name server. If they charged a decent rate, I wouldn&#8217;t have worried.</p>
<p>The tunnel is ok for low bandwidth uses, like HTML, but other content slows the pipe down quickly.</p>
]]></content:encoded>
			<wfw:commentRss>http://michael-wheeler.org/2009/10/25/iodine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hazard Perception Test hacking</title>
		<link>http://michael-wheeler.org/2009/06/01/hazard-perception-test-hacking/</link>
		<comments>http://michael-wheeler.org/2009/06/01/hazard-perception-test-hacking/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 03:01:02 +0000</pubDate>
		<dc:creator>mwheeler</dc:creator>
				<category><![CDATA[None]]></category>
		<category><![CDATA[driving]]></category>
		<category><![CDATA[gov]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacks]]></category>

		<guid isPermaLink="false">http://michael-wheeler.org/2009/06/01/hazard-perception-test-hacking</guid>
		<description><![CDATA[TheSkorm &#8211; Hazard perception test hacking HPT (Hazard Perception Test) is a test to test your reaction time for hazards when driving. It is required for Queensland drivers to take the test to move from a P1 to P2 licence. &#8230; <a href="http://michael-wheeler.org/2009/06/01/hazard-perception-test-hacking/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="flickr"><a title="photo sharing" href="http://www.flickr.com/photos/theskorm/3583362825/"><img class="flickr-photo" src="http://p.michael-wheeler.org/flickr/3583362825_24fd8442cf_m.jpg" alt="Hazard perception test hacking" width="200" /></a><br />
<span class="flickr-caption"><a href="http://www.flickr.com/people/theskorm/">TheSkorm</a> &#8211; <a href="http://www.flickr.com/photos/theskorm/3583362825/">Hazard perception test hacking</a></span></div>
<p class="flickr-yourcomment">
HPT (Hazard Perception Test) is a test to test your reaction time for hazards when driving. It is required for Queensland drivers to take the test to move from a P1 to P2 licence. The test is taken online where you are shown several one minutes videos, and you must click on the hazard as soon as you spot it. I always like to play around with online systems testing security so I gave this setup a shot. I used the practice tests to see how the system worked, and it was pretty easy to work out a way to cheat the system (like most online exams).</p>
<p>Since it was encrypted using HTTPS Wireshark was out of the question, however this doesn&#8217;t mean you can&#8217;t still see what&#8217;s happening. I found a nice tool called &#8220;Live HTTP headers&#8221; which shows you all the requests. The first thing I noticed is that the videos are preloaded. You can see all the requested URLs in Live HTTP headers.</p>
<p>To watch one of the videos before taking the test, all you have to do is grab the URL for it (see the screenshot above) and paste that into a new tab. The videos seem to be able to be downloaded at least twice. You can then watch the videos, and then take the exam, and know exactly what&#8217;s in the exam / video.</p>
<p>It&#8217;s not overly hard to do, and actually quite fun.</p>
]]></content:encoded>
			<wfw:commentRss>http://michael-wheeler.org/2009/06/01/hazard-perception-test-hacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iBigMac</title>
		<link>http://michael-wheeler.org/2009/04/25/ibigmac/</link>
		<comments>http://michael-wheeler.org/2009/04/25/ibigmac/#comments</comments>
		<pubDate>Sat, 25 Apr 2009 03:23:30 +0000</pubDate>
		<dc:creator>mwheeler</dc:creator>
				<category><![CDATA[None]]></category>
		<category><![CDATA[gentoo]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[ibigmac]]></category>
		<category><![CDATA[imac]]></category>
		<category><![CDATA[pxe]]></category>
		<category><![CDATA[ugly]]></category>

		<guid isPermaLink="false">http://theskorm.net/2009/04/25/ibigmac</guid>
		<description><![CDATA[TheSkorm &#8211; IMG_3438 Had some old hardware laying around at home, so I thought I would make my own iMac, or more namely, iBigMac. Started with a Dell 15&#8243; LCD, an a7v8x-x with a AMD 450mhz CPU, and a nVidia &#8230; <a href="http://michael-wheeler.org/2009/04/25/ibigmac/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="flickr"><a title="photo sharing" href="http://www.flickr.com/photos/theskorm/3471778597/"><img class="flickr-photo" src="http://p.michael-wheeler.org/flickr/3471778597_dea07c2864_m.jpg" alt="IMG_3438" width="200" /></a><br />
<span class="flickr-caption"><a href="http://www.flickr.com/people/theskorm/">TheSkorm</a> &#8211; <a href="http://www.flickr.com/photos/theskorm/3471778597/">IMG_3438</a></span></div>
<p class="flickr-yourcomment">
Had some old hardware laying around at home, so I thought I would make my own iMac, or more namely, iBigMac. Started with a Dell 15&#8243; LCD, an a7v8x-x with a AMD 450mhz CPU, and a nVidia Geforce graphics card and an unknown amount of RAM. It wasn&#8217;t much of a build. Make some holes in the LCD plastic, screw everything down and the hardware part was done.</p>
<p>I planned on using a USB stick to boot it, but he motherboard doesn&#8217;t support it so it&#8217;s network booting using PXE to my server, which is pretty cool. It&#8217;s BIOS is really quick, and since everything is loaded in RAM it&#8217;s quite speedy. It&#8217;s perfect for quickly looking at a website, and requires a lot less power. 100% recycled parts.</p>
<p>Oh, the red tape is to hold the motherboard on the screen at the top half. None of the holes lined up.</p>
]]></content:encoded>
			<wfw:commentRss>http://michael-wheeler.org/2009/04/25/ibigmac/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

