Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Rogan Dawes

@RoganDawes@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Infosec researcher @ OrangeCyberDefense.
ALL people have the right to exist.

281 Followers
342 Following
35 Posts
Joined November 04, 2022
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 2mo ago
Replying to
@thedarktangent@defcon.social @dcuthbert@defcon.social sounds like they need to replace the antenna with an attenuator, rather than just leaving it disconnected.
2
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 2mo ago
Replying to
@sborrill@justfollow.me.uk @eickefrohwein@social.cologne same, South Africa 🇿🇦
2
1
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 3mo ago
Replying to on bertha.social
@eltonfc@bertha.social ssh with password auth is a bad idea. But if you use key auth, and disable password auth entirely, I don’t imagine they should have a problem.
2
3
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 3mo ago
Replying to
@n8dmt@mastodon.radio @forty2@oldbytes.space I suggest researching “degloving injuries”, to understand some of the possible downsides of using gloves around power tools. Skin is (fortunately!) relatively weak. If the glove gets caught by the power tool, it can get very ugly!
1
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 3mo ago
Replying to
@suriq@infosec.exchange my point is, won’t the scanner read the same (tampered) bytes from the page cache when it tries to calculate the checksum after the exploit? Assuming the cached page has not been evicted, of course.
1
1
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 3mo ago
Replying to
@mkj@social.mkj.earth @eltonfc@bertha.social the advantage is that your IT/security department can audit the security of the ssh configuration externally, without even having to have login access. If you connect to the ssh server and it doesn’t even offer password auth, then you don’t have to worry about how strong any passwords are.
1
1
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 6mo ago
Replying to
@dougmerritt @feld @spaf seems like the original videos were made in the 80/90’s, so maybe that was the quality available at the time. And never redigitised.
2
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 6mo ago
Replying to
@LaF0rge I’m in South Africa, work for @sensepost, mostly into #hardwarehacking and making electronic things.
2
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 11mo ago
Replying to
@IvanDSM@mastodon.social @f4grx@chaos.social he’s not outside the realm of possibility claiming adb. Just because the rest of user space is not Android, doesn’t mean that you cannot run adbd. It offers some very useful services, that are not Android-specific. In fact, my LTE modem runs adbd (with no other Android bits).
5
3
1
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 7mo ago
Replying to
@baloo @mica @rebane2001 it’s a good security default. Imagine a bastion host or other program that allows you to ssh to a target host. The expectation is that all you can do is interact with the terminal on the target, or exit. However, the ssh escape allows you to create and delete tunnels, amongst other things, which might not have been anticipated. Disabling by default removes the surprise.
2
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 6mo ago
Replying to
@old_angry_queer pretty sure my dad used to cut two longitudinal slits into the middle of the end end, and just bend the the resulting tab up/down as needed.
1
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 5mo ago
Replying to
@aparcar@chaos.social @T_X@chaos.social yeah, second the appreciation. It’s a game changer, as long as you remember to add any customisations to the save file. Possibly silly suggestion: while scanning installed packages, also look for any files on flash that are not part of the packages, or explicitly listed to keep that would otherwise be discarded, and prompt? I realise that it could be quite resource intensive - basically a diff between “find / -xdev -type f” and “for all installed packages: list installed files”
0
4
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 2mo ago
Replying to
@cynicalsecurity@bsd.network @mischa@exquisite.social @dartov@hachyderm.io I mean, this is a simple hardware error that only manifests when in a non-manufacturer-blessed state, but it otherwise IS a serial console design from the 80’s! (TTL serial vs RS-232, if you want to be picky! 😎)
0
2
1
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 4w ago
Replying to
@TheRealPomax@mastodon.social @misty@digipres.club out of curiosity, were you able to find any details about the chip inside? Could it be easily reflashed with your own firmware? Eg esphome
0
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 2mo ago
Replying to
@psh@infosec.exchange curious where you see that report in openwrt?
0
1
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 3mo ago
Replying to
@Junicast@chaos.social it’s really funny. Tasmota started as the project that you didn’t have to compile yourself, while esphome you did. But then Tasmota split into this mage and that image, with different drivers compiled in each. And now ….
0
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 3mo ago
Replying to
@asakiyume@wandering.shop @jondresner@spore.social ohwah, tanaah, siam 🤪
0
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 5mo ago
Replying to
@Natasha_Jay without wanting to downplay the importance of this, in such a small study, this is really a case of “50% of the time, it works all the time”. Those who responded survived! How many responded? “Only” 50%. But of course, 50% is much better than 0%! Super exciting to even get to that point!
0
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 2mo ago
Replying to
@cynicalsecurity@bsd.network @mischa@exquisite.social @dartov@hachyderm.io my Wink hub fails to boot with no serial console attached. Reason is that I have jailbroken it and allowed a keypress to interrupt u-boot. Underlying reason is that there is no pull-up resistor on the rx line, and so it picks up interference, simulating a keypress. Added a pull-up/pulldown resistor and the problem went away.
0
3
1
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 3mo ago
Replying to
@awfulwoman@indieweb.social I don’t believe they interfere with the readings, but they may interfere size-wise, especially if you choose split-core CT’s - they appear to be a little bigger than solid core, but then installation is more complicated.
0
1
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 3mo ago
Replying to
@whitequark@social.treehouse.systems @haroonmeer@infosec.exchange @ThinkstCanary@mastodon.sdf.org the results of the corruption, presumably?
0
1
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 3mo ago
Replying to on blog.rozman.info

@tomi there’s an easier way. Just use esphome run updated.yaml —device old.add.re.ss when flashing the new config. #esphome

0
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 2mo ago
Replying to
@shermozle@aus.social @km@aus.social you don’t power them from mains while reprogramming them. That would be likely to let the smoke out of you and your computer.
0
2
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 2mo ago
Replying to
@jpm@aus.social @hacks4pancakes@infosec.exchange drove a Crumpler for about 20 years until the zip finally gave in. Now got a Goruck GR1 I’m happy enough with.
0
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 3mo ago
Replying to
@suriq@infosec.exchange would it really stay green? Surely checksumming the file reads it in exactly the same way that the kernel does to load it into memory. In which case, I would expect it to sum differently to expected.
0
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 5mo ago
Replying to
@gregdavill@chaos.social aren’t they light sensitive, though? Cf Pi’s rebooting under flash photography…
0
1
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 6mo ago
Replying to
@html5test @hackaday
0
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 6mo ago
Replying to
@feld @spaf the videos are out there. “George Gobel liquid oxygen bbq” should track them down.
0
5
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 5mo ago
Replying to
@faebudo@ioc.exchange @ifrauding@don.linxx.net @goncalor@infosec.exchange @campuscodi@mastodon.social literally nothing uses the hdmi Ethernet channel, other than the marketing teams selling cables. Seems like a handy thing to have, but I think routing complexities (and cost) killed it.
0
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 5mo ago
Replying to
@ifrauding@don.linxx.net @goncalor@infosec.exchange @faebudo@ioc.exchange @campuscodi@mastodon.social afaik, the only bidirectional data channels in a display cable are hdmi-cec, and DDI (basically i2c). I’d be interested to see the threat model that they are targeting with this device, that can’t be circumvented by just unplugging it. Seems like a very particular setup, where eg the computer itself is physically secure, but the display is not.
0
2
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 6mo ago
Replying to
@ryanc @AMS @chaos this is excellent, thank you! I wanted to run ssh over Bluetooth Serial Port Profile (I have a JDY-31 dongle wired to the serial console of my device), and couldn’t figure out how to bodge it together. This looks like it should do the trick!
0
1
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 2mo ago
Replying to
@shermozle@aus.social @km@aus.social fair point!
0
1
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 3mo ago
#caturday Three foster kittens settled for a nap within 10 minutes of arriving.
0
0
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 2w ago
Replying to on chaos.social
@jaseg@chaos.social @gsuberland@chaos.social @azonenberg@ioc.exchange @aleksorsist@mastodon.social reminded me of this hack from 10 years ago: https://hackaday.com/2016/03/15/sdram-logic-analyzer-uses-an-avr-and-a-dirty-trick/ Wonder if it might be possible to do something similar with a high speed ADC and DDR5 DRAM?
SDRAM Logic Analyzer Uses An AVR And A Dirty Trick
Hackaday

SDRAM Logic Analyzer Uses An AVR And A Dirty Trick

We often see “logic analyzer” projects which are little more than microcontrollers reading data as fast as they can, sending it to a PC, and then plotting the results. Depending on how …

0
1
0
0
Open post
Rogan Dawes @RoganDawes@infosec.exchange
· 5mo ago
Replying to
@aparcar@chaos.social @T_X@chaos.social will check that out! Thanks for the pointer. 🙏🏻
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:13:21 UTC