RSS.Social

nns.ee

follow: @[email protected]

Posts

Bypassing dnsmasq dhcp-script limitations for command execution in config injection attacks

Retrospective on hosting my blog inside an LTE modem, 4 years later

When parameterization fails: SQL injection in Nim's db_postgres module using parameterized queries

Symlinks as mount portals: Abusing container mount points on MikroTik's RouterOS to gain code execution

Code execution as root via AT commands on the Quectel RG500Q-EA 5G modem

Don't trust comments

Code execution as root via AT commands on the Quectel EG25-G modem

This blog is now hosted on a GPS/LTE modem

Viewing and resetting the BIOS passwords on the RedmiBook 16

Patching ACPI tables to enable deep sleep on the RedmiBook 16

iopshell: A shell-like application for communicating with IOPSYS devices

chroot shenanigans 2: Running a full desktop environment on an Amazon Kindle

chroot shenanigans: Running Arch Linux on OpenWRT (LEDE) routers

Unsafe firewall includes allowing for remote code execution on Inteno's IOPSYS devices

Creating a key generator to reset a Hikvision IP camera's admin password

From writing to /tmp to a root shell on Inteno IOPSYS

pwn910nd - abusing OpenWRT's printer server to become root

Remote Code Execution vulnerability in Inteno's Iopsys

CVE-2017-11361 post-remedy: Is it fixed?

Inteno misconfigured ACLs leading to information disclosure and logging in as root

Installing custom OpenWRT on an Inteno (DG301) router

ksoft's Easy Auto Refresh extension is selling your data

Restoring stock BIOS on a Braswell Chromebook with a broken rom