Vulnerable IoT Devices! (Using Publicly-available Information To Learn More About A Target pt. 2)

Three very cool search engines. Use them 1-2-3 bang all together.

IoT devices are horribly insecure nowadays. You can search for information in your passive footprinting.  Stuff like webcams by manufacturer or version. Continue reading “Vulnerable IoT Devices! (Using Publicly-available Information To Learn More About A Target pt. 2)”

Day at theZoo

No that is not a typo. The original theZoo is a github repo with commodity malware samples.  Everyone has access to malware that is off-the-shelf and it’s the most common type.  No Advanced Persistent Threats here. But your anti-malware software will probably flag you.

It’s neat because you can use it to study this code. Alternatively, you could do some things that are not recommended. You could create a phishing email that could be sent to a million users, not targeting anyone in particular like the APTs do.  The APTs and other lone hackers or groups create more sophisticated malware. Instead, these users–sometimes called script kiddies–can download say WannaCry ransomware and send it out through your phishing email (or through a “stager” email malware that will load other modules). No reconnaissance needed here.

Think about it, if only one percent of a million users open the email, you end up with 10,000 compromises. Not a bad pay day.

All hail, the Recovering Provocateur!

My day starts with my family member playing and reading all the Trump-related memes.
“Don’t you know what’s going on?”
“No, what?”
“They found massive fraud in the elections in Arizona and they’re going to find it in the other states…”
“O.K. let me know when that happens.”
I need proof, I say—a lot. When it comes to QAnon you must.
“It’s not QAnon,” she says.
“Maybe not in name. It’s just Qanon-lite.” Continue reading “All hail, the Recovering Provocateur!”

Dictionary.com Changes and Early Covid-era Mental Health Suggestions

ATTENTION: The discussion below includes talk of suicidal ideation. If you or someone you know is having any suicidal ideation, please contact the National Suicide Prevention Lifeline at 800-273-TALK (8255). People care about you.

Dictionary.com has removed the word “commit” in various references to suicide.
https://www.dictionary.com/e/mental-health-language/

And has the following recommendations for being aware of and helping those struggling with suicidal ideation:

  • Adopt a nonjudgmental and open-minded attitude
  • Show you care by listening actively, without interrupting or giving advice unless prompted
  • Ask open-ended questions instead of “yes”-or-“no” questions to keep the conversation going
  • Validate the feelings of the other person; it’s OK to not be OK, and sometimes just holding space for another to express themselves can be deeply comforting

Because I am so high functioning, it took me a long time to acknowledge having a mental illness. Talk it out. Below are some early Covid-era mental health suggestions (by early I mean under more stringent sheltering conditions), from Mental Health During Coronavirus (seizetheawkward.org):

  • Engage in live streams – from your favorite yoga studio to your favorite artists
  • Schedule virtual dinners or dance parties with friends
  • Start a virtual book club
  • Participate in online game nights
  • Plan to watch television shows or movies at the same time and video chat to share reactions
  • Enroll in remote learning classes or look up tutorials online
  • Go on virtual museum tours together
  • Share your favorite recipes or host a virtual cooking competition
  • Try a home workout together

“Whatever Gets You Talking” | Seize the Awkward | Ad Council – YouTube

Gadgets 10/12/2021: Holiday shopping; lower storage prices; M1 price returns; mixed reality headset; FHD projector

My new tech days are comprised of today’s deals and then upcoming tech that I think kewl.

Try shopping early this holiday season. As you may know, there is a shortage in a number of industries/supply chains. In fact, Amazon, Home Depot, Walmart and other big retailers will probably get their own planes to make up for the cargo ship problem.

This could be great. I just question the decision to not have the peripheral vision immersed.
https://www.kickstarter.com/projects/stanlarroque/lynx?ref=discovery&term=mixed%20reality%20headset

M1 Macbook at $850
https://www.amazon.com/Apple-MacBook-13-inch-256GB-Storage/dp/B08N5LNQCX/ref=sr_1_4?dchild=1&keywords=m1+macbook&qid=1634058025&sr=8-4

Cheaper micro sd cards
https://www.amazon.com/s?k=micro+sd+card&i=computers&rh=n%3A516866%2Cp_n_feature_two_browse-bin%3A13203835011&dc&crid=237NQWK1KJUNR&nav_sdd=aps&qid=1634058218&rnid=6518301011&sprefix=micro&ref=sr_nr_p_n_feature_two_browse-bin_1

This is not completely clear to me, but is it a rear projector?
Splay- Expandable Display & Ultra-Short-Throw Pico Projector by Arovia — Kickstarter

China’s Aggression and U.S. Debt

The incursions on Taiwanese airspace seems to have picked up. I don’t know how this will work out if there is conflict with the U.S. Will the debt we owe China be called in if there is a conflict? We know that it would have a horrible effect, but China would suffer as well. This piece I wrote a little while back talks about the debt and Chinese aggression before these events.

Thoughts on 100th Anniversary of the CCP

Skynet is Rebooting

What is everyone doing now? I kid, but no really.

We are so dependent on Facebook and this could be time for reflection. What do we do at home, out and about–God forbid, at work? I know that FB is a kind of drug for some people and I have found that I need a timeout sometimes myself. But when 2.89 billion people on the planet are on this infernal thing, the question is what would happen in a long term outage? People may get back to life.

Avoiding the Crush

Part 2 of Considering the Crush

So what should we do being in Europe amid the crush? I thought, “how can we make this work? How to sleep well, get around relatively cheaply and easily, and to just enjoy ourselves?” We could have made a frantic travel plan, to see all the big attractions, run to and fro, and try to get photos of everything. You may encounter someone in your party like Ellen Griswold (National Lampoon’s “Vacation”): Continue reading “Avoiding the Crush”

Active Reconnaissance – There’s no place like 127.0.0.1

Before I continue, I should mention that scanning any other system than yours could get you in big trouble. To be safe, you need written permission to do so on systems other than your own. The IP number for the computer you are on is 127.0.0.1, also called “localhost” or just home. If you run nmap against that IP you should be OK. Continue reading “Active Reconnaissance – There’s no place like 127.0.0.1”

Debt Limit – Non-stop

If we keep borrowing money and only repay the interest, aren’t we saying that we don’t intend on paying it back? I don’t see a way out of this and we’re just kicking the can down the road. Fiscal responsibility used to be part of conservative ideology.

Yellen wrote “This uncertainty underscores the critical importance of not waiting to raise or suspend the debt limit. The full faith and credit of the United States should put at risk.”

I think the full faith and credit are already at risk. As long as we can’t touch entitlements, we are not pursuing a responsible solution. Someone is going to have to break the news, someone preferably in their last term of their job and not concerned with being re-elected.

Gadgets 09/25/2021: Fold 3, Galaxy S22/22+ advance view, $150 off 2020 Macbook M1 13″, Noku Canvas wall planter, Nest Everyday Adventure Backpack

My new tech days are comprised of today’s deals and then upcoming tech that I think kewl.

The Fold 3 doesn’t seem to have the same problems as the prior versions (the Fold 1 in particular broke upon much folding). I really like the pinned taskbar for multi-tasking. I think that further adds to a Windows/Mac taskbar experience. But the crease issue could be reason for waiting for maturity of the tech. (My friend j0mb13 said he’ll wait for it to become more durable/less trendy.) This is a very popular review.

Look forward to Samsung Galaxy 22/22+ – The Ultra model will have a S-Pen!
https://www.engadget.com/samsung-galaxy-s22-plus-ultra-design-leaks-144617511.html

2020 Apple MacBook Air Laptop: Apple M1 Chip, 13” – rare deal with $150 off, costing just $850
https://www.amazon.com/Apple-MacBook-13-inch-256GB-Storage/dp/B08N5LNQCX/

The Noku Canvas: bring your walls to life. This would add to Zen ambiance, or future city night soundtrack.
https://www.kickstarter.com/projects/shirinoku/the-noku-canvas-bring-your-walls-to-life

Nest: The Everyday Adventure Backpack
This backpack has some great organization/modular ecosystem for your gadgets. I still prefer my leather laptop case, which is made for a 17″er.
https://www.kickstarter.com/projects/tropicfeel/nest-the-everyday-adventure-backpack

 

Considering the Crush

PUBLISHED 
Travel restrictions are still in place in a number of countries around the world. But I am taking time to consider what I am really missing out on.

My last international trip was to Italy, which currently has curbs on any non-essential travel, and when I was in Rome, I realized that I can no longer be on vacation in Europe without realizing I am vacationing. Turning the corner with my smartphone map, we ran into the crush to shoot photos at the Trevi Fountain. Everyone shooting the same photo and posting it instantly. Look where I am!

Who really is “winning” this one? Continue reading “Considering the Crush”

Ransomware: best practices

Still the preferred attack against businesses, education, and governments. As a home user, the cyber policies below still go a long way to securing your computers against attacks:

“The FBI and CISA’s recommendations echo best practices for most cybersecurity situations: Don’t click on suspicious links. Make an offline backup of your data. Use strong passwords. Make sure your software is up to date. Use two-factor authentication. If you use Remote Desktop Protocol—a Microsoft product that has historically proven a popular entry point for attackers—proceed with caution.”

Out of Order

So typing with one hand is not impossible, but the flow of words is slower.

Anyway, I’ve still been making notes while I read. That’s what I always do. I go through old articles or books and see notes for which I don’t remember the context. I also have the stack of papers wherein I have a lot of my ideas for articles.

Some of these are not good either, but sounded good at the time. I think it coincides with those “great ideas at night.” Though I have tried, through writing them down, to stop forgetting those, that still happens.

But my activities being a little more sequestered, I am thinking more long-term. I hope to bring some of those projects online soon.

I have my first doctor’s follow-up this afternoon.

How to Write White Papers #6

In regard to writing, closing bit on White Papers for Dummies:

  • See how you can rearrange your writing environment/conditions
  • Try mind mapping or brainstorming
  • Trick yourself to get started
  • Ease off the self-criticism until after you write
  • Try positive affirmations

I’ll add: don’t think the ocean side, forests, deserts are automatically great places to write. If they help you then that’s fine, but some people think they must have a special environment.

It’s been a great read.