This weekend hackers had to solve remote timing attacks against the dragonfly PAKE for the @HackingForSoju midnight sun qualifier. This PAKE is the basis of WPA3's handshake. It's got a pretty silly history. Congrats to the solvers ✅ https://supernetworks.org/pages/blog/midnightsun-qualifiers-2024-dragonfly
22.4.2024 16:57This weekend hackers had to solve remote timing attacks against the dragonfly PAKE for the @HackingForSoju midnight sun qualifier. This PAKE...Last week, I lost a dear friend and ctf teammate, Quend. Every spring we all gather to compile together the best challenges we can for the Midnight Sun CTF qualifiers. The current HFS crew were all back together again this month getting things ready to launch
Years earlier, before we even met, I had started @rpisec with @rgov to find like minds to kick some butt at ctf. I was always very proud that we could inspire hackers like quend to join years later and seriously kick ass
Quend was an inspiration to me as well, between her resolve, her depth of knowledge, her funny jokes and memes, and always a joy to ctf with. It was good to brainstorm through challenge concepts too. She took the midnight sun ctf and helped organize it into a wonderful conference in stockholm and it's hard to understate how awesome she was
Between RPI, NYC, HFS, defcon, and all the little ctfs we played over the years, it was a great time and it's beyond an awful time right now to have lost one of the great ones
12.4.2024 00:58Last week, I lost a dear friend and ctf teammate, Quend. Every spring we all gather to compile together the best challenges we can for the...We've reported a double-free security bug with beacon/probe parsing in inet wireless daemon with potential for remote code execution. This was addressed with v2.16.
Details within
https://supernetworks.org/pages/blog/beacon-double-free-inet-wireless-daemon-CVE-2024-28084
Took some time this sunday afternoon chatting with DaveG and writing up some exploits and fixes for https://github.com/RaspAP/raspap-webgui/issues. I was able to confirm Julien's post https://dustri.org/b/carrot-disclosure.html for full preauth RCE. PHP is just not straightforward at all to write securely
https://github.com/RaspAP/raspap-webgui/pull/1546
11.3.2024 03:18Took some time this sunday afternoon chatting with DaveG and writing up some exploits and fixes for...I wrote up some speculative thoughts why memory safety could appear more urgent for the whitehouse than it does for an average tech developer working adjacent to or within infosec
https://www.supernetworks.org/pages/blog/federal-focus-memory-corruption-2024
1.3.2024 20:11I wrote up some speculative thoughts why memory safety could appear more urgent for the whitehouse than it does for an average tech...CVE-2023-52161: inet-wireless daemon (iwd) APs allowed clients to connect with a NULL key, bypassing the WiFi password
https://www.top10vpn.com/research/wifi-vulnerabilities/
26.2.2024 22:10CVE-2023-52161: inet-wireless daemon (iwd) APs allowed clients to connect with a NULL key, bypassing the WiFi...Anyone apply LLM's to their mastodon feed yet? please share your setup
18.2.2024 22:18Anyone apply LLM's to their mastodon feed yet? please share your setupFind a CVE starter pack
14.2.2024 13:33Find a CVE starter packAQ35 https://ionq.com/news/ionq-achieves-technical-milestone-one-year-ahead-of-schedule
1.2.2024 05:28AQ35 https://ionq.com/news/ionq-achieves-technical-milestone-one-year-ahead-of-schedulethe wifi war driving community has the messiest cars. y'all are gonna get targeted advertising by car detailing services running @nzyme
26.1.2024 19:04the wifi war driving community has the messiest cars. y'all are gonna get targeted advertising by car detailing services running @nzymehttps://www.supernetworks.org/pages/blog/spr-2023-in-review
28.12.2023 00:03https://www.supernetworks.org/pages/blog/spr-2023-in-reviewhappy monday
18.12.2023 15:06happy mondayHappy Friday, we put together some of our favorite links for WiFi Radio & Security
https://supernetworks.org/pages/docs/wireless
8.12.2023 19:21Happy Friday, we put together some of our favorite links for WiFi Radio & Security https://supernetworks.org/pages/docs/wirelessshoot your wifi questions at me
28.11.2023 21:38shoot your wifi questions at meJust published a post on making that built-in wifi a bit more useful on the raspberry pi 4, using Seemoo Lab's Nexmon
https://www.supernetworks.org/pages/blog/spr-nexmon
2.11.2023 00:49Just published a post on making that built-in wifi a bit more useful on the raspberry pi 4, using Seemoo Lab's...i just launched barely-ap on seemoo's patched raspberry pi 4 firmware/drivers for monitor mode -- and then connected an iOS device
28.10.2023 04:56i just launched barely-ap on seemoo's patched raspberry pi 4 firmware/drivers for monitor mode -- and then connected an iOS device@spr_networks is seeking an intern with Rust knowledge for wifi attack surface reduction
https://www.supernetworks.org/pages/blog/barely-ap-surfaces
24.10.2023 06:17@spr_networks is seeking an intern with Rust knowledge for wifi attack surface...Pushed a fix for barely-ap bug that was preventing iOS devices from connecting
https://github.com/spr-networks/barely-ap/
Recv/read return a partial payload? Try sending fragmented packets in reverse.
During this defcon's final round of livectf, the contestants ran into just this problem.
Here's my solution with a pwntools and scapy script
https://www.supernetworks.org/pages/blog/scapy-revfrag
😷 Defcon COVID surived, testing negative for 3 days now. Catching up on your DMs now! Was great seeing everyone in vegas
1.9.2023 03:40😷 Defcon COVID surived, testing negative for 3 days now. Catching up on your DMs now! Was great seeing everyone in vegas