Default password lists

I’ve decided to centralize the default password lists for multiple vendors. I’m making this a sticky post and will update this list when as I find these types of sites:

* http://bit.ly/2S6SToW – NETGEAR Default Password List
* http://bit.ly/2S37j9u – Linksys Default Password List
* http://bit.ly/2S3gPJV – D-Link Default Password List
* http://bit.ly/2S8KWzJ – Cisco Default Password List
* http://bit.ly/2S37FwQ – Default Router Usernames and Passwords (multiple vendors)
* http://bit.ly/2HrgT3O – Telnet, MySQL and other Linux and Windows service passwords courtesy of n0tazombie.

Always available CTF Labs

I have identified the following CTF labs which are 24/7 and most if not all are free:

* CTF101: https://ctf101.org/
*
Shellter Hacking Express: https://shellterlabs.com/en/contests/
* Backdoor: https://backdoor.sdslabs.co/
* ShellWePlayAGame?: https://shellweplayagame.org/
* RootMe: https://www.root-me.org/?lang=en
* OverTheWire: https://overthewire.org/wargames/
* Virginia Cyber Range: https://portal.virginiacyberrange.net/
* Hack The Box: https://www.hackthebox.eu/
* FuzzyLand: https://fuzzy.land/
* Hacking Lab: https://www.hacking-lab.com/index.html
* 365 CSAW: https://365.csaw.io
* pwnable.xyz (good for people new to CTF): https://pwnable.xyz/

Article: Linux Kernel Prior to 5.0.8 Vulnerable to Remote Code Execution

If you are using any major Linux distribution you should patch now. There’s a remotely exploitable condition in any Linux Kernel (such as Fedora, Debian, Ubuntu, and others) that is prior to 5.0.8. It’s got the potential for being exploitable, but thankfully it’s fairly difficult the gain code execution but not impossible.

https://www.bleepingcomputer.com/news/security/linux-kernel-prior-to-508-vulnerable-to-remote-code-execution/

Vodaphone denies any backdoors found in Huawei devices

Looks like Vodaphone considered having a telnet server running as a backdoor in the initial reporting by Bloomberg. All the same though, using Huawei devices as infrastructure of a 5G cellular network gives another nation state access to some potentially sensitive data and they would have the ability to remotely tamper with it. As more and more people rely on high speed cellular networks this is still a bad idea!

https://bbc.in/2Y0rd85

 

Awesome video on how quantum computer can break current encryption

Someone posted this video on one of the Slack workspaces that I’m on. It was really informative on the techniques used and where the current state of the art quantum computers currently are. The good news is current quantum computers don’t have enough quantum memory to break large primes, however I wonder if there’s such a thing as Moore’s Law for quantum computing in which case the Internet will be in big trouble in just a few years.