Sign in

Corben Leo

@hacking.bsky.social
1.9K followers 17 following 18 posts

I hack stuff (legally). | co-founder boring.co Twitter: twitter.com/hacker_

PostsRepliesMedia
Corben Leo @hacking.bsky.social · 27/11/2024
this app still exists in 2024
020
Corben Leo @hacking.bsky.social · 04/07/2023
yeah….😬
000
Corben Leo @hacking.bsky.social · 02/07/2023
Can see why there haven’t been any sticky Twitter competitors
000
Corben Leo @hacking.bsky.social · 29/06/2023
this app does in fact still exist
020
Corben Leo @hacking.bsky.social · 25/04/2023
Super insane. Kinda scary, curious about the ramifications of violent games that look so realistic
000
Corben Leo @hacking.bsky.social · 09/04/2023
It’d be an interesting read! Why not? Bootstrapped businesses can’t play the same game that venture-backed businesses play
000
Corben Leo @hacking.bsky.social · 08/04/2023
TLDR; - In a bug bounty program (telecommunications company) - Scanned their IPV4 Ranges - Found a webserver that said "███ Cable System" - Directory brute-force found /admin/accounts/ - The endpoint set a valid admin JSESSIONID bsky.app/profile/hacking.bsky.socia…
010
Corben Leo @hacking.bsky.social · 08/04/2023
10/ I reported it immediately and started pinging their program manager. It was the best response I've ever gotten. And will ever get
100
Corben Leo @hacking.bsky.social · 08/04/2023
9/ I clicked through the menus to see if I was actually authenticated. I was. FULLY. AUTHENTICATED. On that same IP range, They had ANOTHER system for ANOTHER cable. I tried the same attack. IT WORKED! I had admin access to TWO. Different. Cables. I was in disbelief. So,
100
Corben Leo @hacking.bsky.social · 08/04/2023
8/ Redirected to the home page. Second visit: > HTTP/1.1 200 OK > --- snip --- > <title>Account Administration</title> HOLY **** IT WORKED. This is a HIGHLY redacted version of what I saw: So,
100
Corben Leo @hacking.bsky.social · 08/04/2023
7/ It's probably worthless. Right? I was intrigued enough. So I decided to visit the endpoint in my browser. Twice. 1st - To set the JSESSIONID cookie in my browser. 2nd - To see if the cookie was valid & used for authentication. 1st visit: <IP>/admin/accounts and
100
Corben Leo @hacking.bsky.social · 08/04/2023
6/ Let's see if there are more directories down /admin/ Directory-Bruteforcing found /accounts/. This redirected to the login page. I was about to brute-force JSP files when I realized something unique in the response. A header. > Set-Cookie: JSESSIONID=<id>; That's weird.
110
Corben Leo @hacking.bsky.social · 08/04/2023
5/ The directory /admin/ Remember, it's running Apache Tomcat. I built a wordlist for .jsp files using BigQuery. (Learned from @assetnote's commonspeak) Bruteforcing found a few JSP files, but they all redirected to the login page. Gah. Well,
110
Corben Leo @hacking.bsky.social · 08/04/2023
4/ "login.jsp" Ok! It was a Tomcat webserver I didn't have credentials. Obviously. I started with directory brute-forcing. Used @joohoi's ffuf & filtered by the number of response words on the 404 page. It found several directories. One that stuck out was
110
Corben Leo @hacking.bsky.social · 08/04/2023
3/ "███ Cable System" (I have to redact this) So, I visited the server in my browser. The home page said > "Welcome to the ███ Management System" No way. This isn't really online is it? Underneath was a link: "Log in to ███" Clicked it and it brought me to
110
Corben Leo @hacking.bsky.social · 08/04/2023
2/ I searched the company's name on bgp.he\.net Saved their IP ranges. I ran masscan, probed for HTTP(s) servers, and grabbed the HTTP titles. Looked something like: $ masscan -p 80,443 -iL ranges -oL out.txt $ cat out.txt | httpx -title One title stuck out:
110
Corben Leo @hacking.bsky.social · 08/04/2023
1/ It began with a bug bounty program. Of a telecommunications company (that I can't name publicly). As some of you may know, I love recon. I had already done subdomain enumeration. The next step was to scan their IP ranges. So,
110
Corben Leo @hacking.bsky.social · 08/04/2023
In 2010, WikiLeaks released a classified document. A list of infrastructure critical to U.S national security. The government listed a Trans-Atlantic cable. 3 years ago, 19-year-old me gained ADMIN access to that cable (and another; shared codebase). Here's how I did it:
2123