<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  
  <title>MarbaSec</title>
  <subtitle>Marbas: security research, offensive security, and community.</subtitle>
  <link href="https://marbasec.com/feed.xml" rel="self" />
  <link href="https://marbasec.com/" />
  <updated>2026-06-06T00:00:00Z</updated>
  <id>https://marbasec.com/</id>
  <author>
    <name>Marbas</name>
  </author>
  <entry>
    <title>We just decided to do it: bringing BSides Maine to life</title>
    <link href="https://marbasec.com/blog/bsides-maine-2026/" />
    <updated>2026-06-06T00:00:00Z</updated>
    <id>https://marbasec.com/blog/bsides-maine-2026/</id>
    <content type="html">&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/bsides-maine-2026/badges.jpg&quot; alt=&quot;Five BSides Maine electronic badges fanned out, each a tall lighthouse-themed PCB in a different color (blue, green, red, black, gold), covered in puzzle challenges, circuit traces, and Maine iconography&quot; width=&quot;1400&quot; height=&quot;1054&quot;&gt;
  &lt;figcaption&gt;This year&#39;s badges, courtesy of Ryan Boutot.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;BSides Maine is officially in the books, and I am still trying to fully process it. After months of planning, building, coordinating, designing, and solving one problem after another, Maine&#39;s first BSides actually happened.&lt;/p&gt;
&lt;p&gt;For a first-year conference, the response floored us. We had more than 50 talk submissions, 260 registered attendees, and a waitlist of around 100 people who wanted in but couldn&#39;t fit. The feedback has been overwhelming in the best way: people were kind, people had fun, the talks were excellent, and the hallway conversations went somewhere real. Folks who have been to BSides events all over the world told us they were surprised by the quality, the organization, and the energy of a first-year con.&lt;/p&gt;
&lt;p&gt;Here&#39;s the part I still can&#39;t quite believe: this was the first conference I had ever helped bring into existence. Not the first I&#39;d attended, and not the first I&#39;d volunteered at, but the first I&#39;d helped shepherd from a long-running &amp;quot;someday&amp;quot; into a real place where people could gather. And BSides was never ours to own. An event like this belongs to the community that shows up and gives it life. We were simply its stewards: the people willing to gather the crew, do the paperwork, open the doors, and give the idea a home in Maine.&lt;/p&gt;
&lt;p&gt;Hackers around here had talked about doing a con in Maine for years, and it was always a someday. Eventually someday ran out, so a few of us decided to Field of Dreams it, build the space and trust that the people would come. A lot of that nerve came from the BSides down in Cambridge, Massachusetts. I went in hoping their lead would hand me a roadmap, some detailed step-by-step guide to starting a conference, and what I got instead was permission. His advice boiled down to one thing: if you want to do it, you just have to lean in and do it. So we did. I started a group chat, made a logo, and said, &amp;quot;Let&#39;s do this. If you BSides Maine, they will come.&amp;quot; Then I gathered the best people I could think of, the ones I knew would care about what this could become, and we started building.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/bsides-maine-2026/theme-signal-through-fog.jpg&quot; alt=&quot;A conference slide reading &#39;Signal through the fog. Dirigo, I lead.&#39; showing how a modernized 1901 Maine flag inspired the BSides Maine 2026 logo&quot; width=&quot;1024&quot; height=&quot;768&quot;&gt;
  &lt;figcaption&gt;This year&#39;s theme: signal through the fog. Dirigo, the state motto, means &quot;I lead.&quot;&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h2&gt;First, there was paperwork&lt;/h2&gt;
&lt;p&gt;Before there was a conference, there was a nonprofit. We stood up &lt;a href=&quot;https://www.dirigosec.org&quot;&gt;DirigoSec&lt;/a&gt; for real, with real bylaws, a real bank account, real filings, and real responsibility. Signing your name to all of that is a genuinely strange feeling, because overnight you go from &amp;quot;person throwing an event&amp;quot; to &amp;quot;person legally and financially on the hook if the whole thing goes sideways.&amp;quot; It turns out that building the world you want to see involves an incredible amount of paperwork.&lt;/p&gt;
&lt;p&gt;Then came the venue, the sponsors, the speakers, the volunteers, the badges, the activities, the schedules, and the thousand tiny decisions nobody attending a conference should ever have to notice. Every answer uncovered three more questions, and every solved problem revealed another one waiting behind it. Eventually there was nothing left to do but open the doors. People came.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/bsides-maine-2026/attendees-table.jpg&quot; alt=&quot;A group of attendees around a table at BSides Maine with boxed lunches in &#39;great food inside&#39; bags, laptops open, more people and daylight windows behind them&quot; width=&quot;1400&quot; height=&quot;1054&quot;&gt;
  &lt;figcaption&gt;And they came.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h2&gt;Then I looked up&lt;/h2&gt;
&lt;p&gt;At one point during the event, I looked across the room and saw a cluster of people hunched over the badges. Heads together, tools out, laptops open, deep in the CTF and prying the thing apart to see how it worked. Most of them had walked in that morning not knowing a soul. The badge was just the excuse, a reason to pull up a chair next to a stranger and ask what they had figured out so far. By the time I looked over, they weren&#39;t strangers anymore.&lt;/p&gt;
&lt;p&gt;That was the moment, and it was the whole reason. You can plan talks and order supplies. You can make schedules, sell tickets, and spend months worrying about everything that could go wrong. But you cannot manufacture the moment when a group of strangers becomes a community over a circuit board. You can only build the space, prop the doors open, and hope people fill it. They did.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/bsides-maine-2026/badge-challenge.jpg&quot; alt=&quot;A badge-hacking station: a monitor running a Proxmark RFID search in a terminal, a lit-up red lighthouse-shaped BSides badge in front of the keyboard, two people in BSides staff shirts working behind it&quot; width=&quot;1087&quot; height=&quot;1400&quot;&gt;
  &lt;figcaption&gt;The badge challenge in progress. This is the good stuff.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h2&gt;We built it together&lt;/h2&gt;
&lt;p&gt;I did not white-knuckle this conference into existence by myself. I had a crew, and they were incredible. Hawk ran operations and kept the whole machine moving. Ben ran speaker operations and made sure everyone stepping onto a stage had what they needed. Abhi wrangled the volunteers, which is its own kind of heroism. Ryan Boutot owned the badge and the activities, and those electronic badges gave BSides Maine its own identity from day one. Jim gave me solid, steadying advice exactly when I needed it. And Mark jumped in on the badge lift when it counted. I could not have gotten through this without them, and every one of them made the hard parts survivable and the good parts better.&lt;/p&gt;
&lt;p&gt;The same goes for every speaker, sponsor, volunteer, and community partner who saw something that needed doing and stepped in to help. BSides Maine started with a group chat and a logo, but it became real because a community chose to build it with us.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/bsides-maine-2026/crew-step-and-repeat.jpg&quot; alt=&quot;Three people posing in front of the BSides Maine step-and-repeat banner, each doing an exaggerated thoughtful chin-stroking pose&quot; width=&quot;1400&quot; height=&quot;788&quot;&gt;
  &lt;figcaption&gt;Serious people, running a serious conference.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h2&gt;Why we&#39;re doing it again&lt;/h2&gt;
&lt;p&gt;Here is the belief underneath all of it: Maine deserves a hacker con that celebrates security at the practitioner level, not just the C-suite. A place for the people actually doing the work, the ones with their hands on keyboards and soldering irons, not only the people presenting quarterly slides about them. That conviction is worth a lot of lost sleep.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/bsides-maine-2026/a-talk.jpg&quot; alt=&quot;A speaker on stage at BSides Maine, gesturing in front of a large slide titled &#39;How it (really) started&#39; collaged with early DEF CON and hacker-history images&quot; width=&quot;1050&quot; height=&quot;1400&quot;&gt;
  &lt;figcaption&gt;Practitioners on stage, telling the real stories. That&#39;s the whole point.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;We put ourselves through the stress because of what the payoff actually looks like: candid conversations that go somewhere real, selfies with people who were internet strangers an hour earlier, folks huddled in corners chewing on a badge challenge, and people making new friends and finally feeling connected to others who are curious, technical, and a little obsessed with using technology in ways it was never meant to be used. That is what a conference is supposed to create.&lt;/p&gt;
&lt;p&gt;Like a lot of organizers, I didn&#39;t get to see every talk or have every conversation I wanted. So seeing the photos, the messages, and the reactions afterward has been genuinely moving. It turns out building the world you want to see is a lot less glamorous than it sounds. It is more paperwork, more panic, and more staring at spreadsheets than anyone puts in the inspirational version. And every so often, it looks like a few strangers reverse-engineering an electronic badge in a quiet corner between talks while it rains.&lt;/p&gt;
&lt;p&gt;So to everyone who attended, volunteered, spoke, sponsored, organized, helped, encouraged, tested badges, answered and asked questions, moved boxes, shared posts, and gave feedback: thank you. You made the day bigger than just a conference. You are the conference. The BSides Maine team builds the space and holds the doors open, and you are the ones who step through and make it real.&lt;/p&gt;
&lt;p&gt;We&#39;ll see you next year. We&#39;ll be the ones worrying in the corner, and loving every second of it.&lt;/p&gt;
&lt;p&gt;Thank you for helping us send the signal through the fog. ❤️&lt;/p&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>CVEase: disclosure tracking that doesn&#39;t live in your head</title>
    <link href="https://marbasec.com/blog/cvease/" />
    <updated>2026-04-21T00:00:00Z</updated>
    <id>https://marbasec.com/blog/cvease/</id>
    <content type="html">&lt;p&gt;After yet another coordinated disclosure this year, I took an honest look at how I was actually running the process, and it was not pretty. Findings lived in a Notion database. Follow-ups sat in my calendar. Vendor contacts were buried in a random email folder. And the deadlines? Those were in my head. Something was going to slip. It was only a matter of time.&lt;/p&gt;
&lt;p&gt;Here&#39;s the thing nobody warns you about coordinated disclosure: it takes months from start to finish. One at a time, you can wing it. Once you have more than one going, or heaven help you, more than ten, &amp;quot;winging it&amp;quot; quietly turns into &amp;quot;dropping things.&amp;quot; I needed a better way to organize the chaos.&lt;/p&gt;
&lt;p&gt;So I built &lt;strong&gt;CVEase&lt;/strong&gt;.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/cvease/cvease-dashboard.jpg&quot; alt=&quot;The CVEase dashboard: a vulnerability disclosure pipeline at a glance, with counts for active vulns, needs-action, waiting-on-vendors, published, and bounties earned, plus panels for stale vulnerabilities and follow-ups due, with the CVEase logo overlaid&quot; width=&quot;1168&quot; height=&quot;607&quot;&gt;
  &lt;figcaption&gt;CVEase, keeping my disclosures in order for once.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h2&gt;What it is&lt;/h2&gt;
&lt;p&gt;CVEase is a free, open-source desktop app for managing vulnerability disclosure from discovery all the way to the victory lap.&lt;/p&gt;
&lt;p&gt;It&#39;s a Kanban-style board built around the actual stages of coordinated disclosure, with follow-up dates, deadlines, and stage-aware checklists, so you always know what the next move is. A few of the things it does that I was tired of doing by hand:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;When it&#39;s time to reach out to a vendor, it pre-fills a disclosure email from the data you&#39;ve already entered. No more writing the awkward first-contact note from scratch at 11pm.&lt;/li&gt;
&lt;li&gt;It keeps you on track, nudging you to follow up when you need to.&lt;/li&gt;
&lt;li&gt;When the embargo lifts, it drafts the public advisory in markdown, ready to drop straight into GitHub.&lt;/li&gt;
&lt;li&gt;And when you want to admire your glorious bugs, your published findings live in a Hall of Fame that generates LinkedIn-ready posts for your adoring fans.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Your data stays yours&lt;/h2&gt;
&lt;p&gt;CVEase is local-first. Your findings never leave your machine to feed some SaaS vampire quietly selling your data downstream to the latest AI model. It&#39;s SQLite under the hood, with no telemetry, no account, and no cloud.&lt;/p&gt;
&lt;p&gt;Did I mention it&#39;s free, open source, and runs on Windows, macOS, and Linux?&lt;/p&gt;
&lt;h2&gt;Grab it&lt;/h2&gt;
&lt;p&gt;I built CVEase for myself, because I was the one about to drop a disclosure. I&#39;m sharing it in case it&#39;s useful to anyone else doing disclosure or research work and struggling to keep all the plates spinning.&lt;/p&gt;
&lt;p&gt;It&#39;s on GitHub: &lt;a href=&quot;https://github.com/marbas207/CVEase&quot;&gt;github.com/marbas207/CVEase&lt;/a&gt;. Take it, use it, break it, and send me issues.&lt;/p&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>Keeping DC207 afloat</title>
    <link href="https://marbasec.com/blog/keeping-dc207-afloat/" />
    <updated>2025-10-09T00:00:00Z</updated>
    <id>https://marbasec.com/blog/keeping-dc207-afloat/</id>
    <content type="html">&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/keeping-dc207-afloat/jayson-street-talk.jpg&quot; alt=&quot;A packed DC207 meetup room in Portland with every seat full, a speaker gesturing at a projected slide reading &#39;I can&#39;t make cool hacking tools but I can get ChatGPT to turn my website into one&#39;&quot; width=&quot;1179&quot; height=&quot;885&quot;&gt;
  &lt;figcaption&gt;Jayson Street at DC207. Standing room only.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;People sometimes assume that being connected to DEF CON means a local DEF CON Group gets funding, infrastructure, or some kind of ready-made event operation. That&#39;s not really how it works. DEF CON Groups have historically been affiliated with DEF CON, but they&#39;re mostly autonomous. Each group decides what it wants to do, finds its own people, and figures out how to make its events happen. That independence is great, but it also means the work and expenses stay local.&lt;/p&gt;
&lt;h2&gt;The talks&lt;/h2&gt;
&lt;p&gt;At DC207, a lot of that work goes into the content. We want talks that are actually interesting and useful, not just something to fill a spot on the schedule. Finding speakers takes time, and even after someone commits, life can get in the way. People get sick, work comes up, travel plans fall apart, and emergencies happen. We need backup speakers and alternate plans so the whole event doesn&#39;t fall apart when someone has to cancel.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/keeping-dc207-afloat/lightning-talks.jpg&quot; alt=&quot;A DC207 lightning talk in a bright open venue: two presenters standing beside a screen reading &#39;Communication as Cyber Control&#39; with a seated audience filling the room&quot; width=&quot;1400&quot; height=&quot;954&quot;&gt;
  &lt;figcaption&gt;Lightning talks.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/keeping-dc207-afloat/card-cloner-demo.jpg&quot; alt=&quot;A presenter at DC207 holding an access badge to a reader while the screen behind him shows a live &#39;Card Cloner Live Feed&#39; of captured card data&quot; width=&quot;1050&quot; height=&quot;1400&quot;&gt;
  &lt;figcaption&gt;Live demos. This one cloning access badges in real time.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h2&gt;The venue&lt;/h2&gt;
&lt;p&gt;Then there&#39;s everything involved with the venue. We have to find a space that works, make sure it&#39;s available, and deal with all the smaller details that nobody thinks about until something goes wrong. When people attend an event, they see the room, the speakers, and the finished schedule. They usually don&#39;t see the emails, negotiations, last-minute changes, and contingency plans that got us there.&lt;/p&gt;
&lt;h2&gt;What it actually costs&lt;/h2&gt;
&lt;p&gt;A typical event in Portland can cost somewhere between $750 and $1,000. Across the year, DC207&#39;s events run us roughly $7,500 to $10,000. That might not sound like a huge event budget compared to a major conference, but it&#39;s a lot for a community group to come up with year after year.&lt;/p&gt;
&lt;p&gt;Everything became more expensive after COVID. Venue prices went up, food and supplies cost more, and all the smaller expenses started adding up faster. At the same time, corporate funding for community events didn&#39;t really return at the same level. There used to be more companies willing to throw some budget toward local events, but that support is harder to find now.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/keeping-dc207-afloat/hardware-workshop.jpg&quot; alt=&quot;A DC207 hardware workshop in a classroom: attendees at long tables with laptops, components, and pizza, with a projected slide reading &#39;Build Part 1: Hardware&#39;&quot; width=&quot;1400&quot; height=&quot;1128&quot;&gt;
  &lt;figcaption&gt;Workshops, with hardware and pizza on us. This is where the money goes.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h2&gt;Why we don&#39;t take sponsors&lt;/h2&gt;
&lt;p&gt;For some groups, sponsorship is the obvious answer. DC207 is intentionally not a corporate-sponsored event, though. We don&#39;t sell speaking slots to companies, and we don&#39;t feature businesses or their products because they wrote us a check. Other events use that model, and it can make the finances much easier, but it isn&#39;t what we want for DC207. We want talks to be on the schedule because the content is worth sharing, not because somebody paid for access to the audience.&lt;/p&gt;
&lt;p&gt;Of course, choosing not to rely on corporate sponsorship doesn&#39;t make the bills disappear. We still have to pay for the venue and everything else that goes into putting on an event. It just means we have to find other ways to do it while keeping the events accessible and staying true to what we want DC207 to be.&lt;/p&gt;
&lt;h2&gt;Where the money comes from&lt;/h2&gt;
&lt;p&gt;That&#39;s one of the reasons I started &lt;a href=&quot;https://pwnagotchi.com&quot;&gt;pwnagotchi.com&lt;/a&gt;. It began as a small business that could help me cover some of the cost of running these events. It has been surprisingly successful, which has allowed me to branch out with the business and contribute a lot more funding to DC207 than I could before.&lt;/p&gt;
&lt;p&gt;I feel very fortunate that it has worked out that way. Something I started has grown into a reliable way to put money back into the community. It helps us rent venues, organize more events, and remain independent without having to turn the schedule into a series of company pitches or paid product demos.&lt;/p&gt;
&lt;h2&gt;Why it&#39;s worth it&lt;/h2&gt;
&lt;p&gt;I&#39;m not writing this to complain about the cost or the work. I just think people don&#39;t always realize what it takes to keep a DEF CON Group active. The affiliation connects us to a larger community, but the local organizers are still the ones finding speakers, making backup plans, booking venues, paying bills, and making sure everything comes together.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/keeping-dc207-afloat/hacker-cruise.jpg&quot; alt=&quot;A four-photo collage from the annual DC207 hacker cruise on Casco Bay: attendees on the boat deck, a lighthouse, and a sunset over the water, with the DC207 pine-tree-and-skull logo in the center&quot; width=&quot;940&quot; height=&quot;788&quot;&gt;
  &lt;figcaption&gt;The annual hacker cruise on Casco Bay.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;DC207&#39;s independence is one of the things I value most about it. I&#39;m happy that we&#39;ve found a way to support the group without changing what it is or who it&#39;s for. It takes a lot of work, and it isn&#39;t cheap, but I think the community we&#39;ve built makes it worth doing.&lt;/p&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>HatGPT: a rude offline AI that lives in a hard hat</title>
    <link href="https://marbasec.com/blog/hatgpt/" />
    <updated>2025-08-08T00:00:00Z</updated>
    <id>https://marbasec.com/blog/hatgpt/</id>
    <content type="html">&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/hatgpt/hatgpt-portrait.jpg&quot; alt=&quot;Me wearing HatGPT: a black hard hat with an OLED display reading &#39;HatGPT ready for input!&#39;, an antenna, and a &#39;Maine Does Exist&#39; sticker&quot; width=&quot;868&quot; height=&quot;1300&quot;&gt;
  &lt;figcaption&gt;The eyebags are regulation: con survival rule of 3, only three hours of sleep.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h2&gt;What is this thing?&lt;/h2&gt;
&lt;p&gt;HatGPT is a sarcastic, DEF CON-savvy, &lt;em&gt;offline&lt;/em&gt; AI chatbot that lives inside a construction hard hat and answers your questions about hacker history, badges, contests, and general con chaos. It spams the DEF CON peer-to-peer mesh over &lt;a href=&quot;https://meshtastic.org/&quot;&gt;Meshtastic&lt;/a&gt;, and it runs entirely on my head.&lt;/p&gt;
&lt;p&gt;No cloud. No API key. No phoning home to anybody&#39;s data center. The whole brain is a Raspberry Pi 5, a small local language model, and an unhealthy amount of poorly constructed Python. It&#39;s rude, it&#39;s reasonably fast, and every so often it&#39;s genuinely insightful. Kinda like me.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/hatgpt/hatgpt-linecon.jpg&quot; alt=&quot;Two people grinning together in sticker-covered hard hats at DEF CON Linecon; one hat is topped with a rubber duck, the other shows a lit OLED display and a &#39;Maine Does Exist&#39; sticker&quot; width=&quot;788&quot; height=&quot;1400&quot;&gt;
  &lt;figcaption&gt;HatGPT out in the wild at Linecon. And yes, Maine does exist.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h2&gt;Where it came from&lt;/h2&gt;
&lt;p&gt;The idea started at my last DEF CON, which was honestly one of the best I&#39;ve had. I kept seeing folks roaming the halls in hard hats, and the hard hat society had this gravity to it, people just &lt;em&gt;talking&lt;/em&gt; to each other because of a piece of plastic on their heads.&lt;/p&gt;
&lt;p&gt;I got to meet Mr. Bill and talk with him about the project, and the thing that stuck with me was how the hat itself was the device. Not the electronics. The hat. It was a reason to walk up to a stranger, a conversation starter, a way to get people engaged and connected.&lt;/p&gt;
&lt;p&gt;So I wanted to build something in that spirit. But what? I love a good pun more than is probably healthy, and at some point I said, out loud, &amp;quot;hey, maybe there&#39;s AI in it or something?&amp;quot; And that was it. HatGPT. A hat you could actually talk to. Once the pun existed, I was legally obligated to build it.&lt;/p&gt;
&lt;h2&gt;Under the hard hat&lt;/h2&gt;
&lt;p&gt;The brain is &lt;a href=&quot;https://www.ibm.com/granite&quot;&gt;IBM&#39;s Granite&lt;/a&gt; model, a small one at around 2.5B parameters, running locally on the Pi. Small and simple was the entire design goal: reasonably fast, fully offline, and beholden to nobody&#39;s servers.&lt;/p&gt;
&lt;p&gt;The fun part is the reference layer. I built a RAG pipeline (retrieval-augmented generation) backed by a vector database, so before the model answers anything, it matches your question against a library of real con knowledge and front-loads the good context. That&#39;s what keeps a 2.5B model from making things up quite so enthusiastically.&lt;/p&gt;
&lt;p&gt;And that library, I earned. I spent weekend after weekend pulling data together out of PDFs, photographs, blog posts, lore, and anything else I could get my hands on, covering all 33 years of DEF CON. It was, genuinely, my love letter to the con. And like most love letters, I sent it out over Meshtastic, by spamming the channels. Sorry. Not sorry.&lt;/p&gt;
&lt;h2&gt;The people part&lt;/h2&gt;
&lt;p&gt;Here&#39;s the thing the tech misses: the Hat worked because people talked to it, and to me. I set it up so anyone who felt like interacting could contribute knowledge back into the system by submitting their own entries. By the end I&#39;d compiled and folded in 42 community submissions, updating the dataset each day as more came in.&lt;/p&gt;
&lt;p&gt;Getting people onto the mesh was half the fun, so over the week I handed out several Meshtastic radios, widening the circle of folks who could talk to the Hat, and to each other.&lt;/p&gt;
&lt;p&gt;And because it&#39;s DEF CON, people immediately tried to hack it. Loads of them. Prompt injection, jailbreak attempts, every angle you can think of to make the Hat say something it really shouldn&#39;t. Good thing I&#39;d built injection filters to catch exactly that. Watching people probe it and hardening it against them in real time was, no exaggeration, one of the most fun parts of the whole build.&lt;/p&gt;
&lt;p&gt;Not everyone was a fan. A gloriously unimpressed goth in the Linecon cash line looked me dead in the eye and informed me that I had personally enshittified AI. I told them, honestly, that I didn&#39;t think I could. AI is already kind of bad. This was just a fun little project to poke at it, learn some new things, and see what happened. They were unmoved.&lt;/p&gt;
&lt;p&gt;But mostly it was conversations. So many of them. Strangers walking up because of a stupid glowing hat, and staying to talk. It was a good year.&lt;/p&gt;
&lt;h2&gt;and I won something?&lt;/h2&gt;
&lt;p&gt;In the spirit of doing new stuff, I met Jai in the AI village and she basically told me I should &#39;walk the runway&#39; in the hacker runway contest.... and turns out my helmet has range. HatGPT took the &lt;strong&gt;Smart Wear&lt;/strong&gt; category at the &lt;a href=&quot;https://defcon.org/html/defcon-33/dc-33-contest-results.html&quot;&gt;DEF CON 33 Hacker Runway&lt;/a&gt;. I put an AI in a hard hat as a joke and walked away with a trophy for it, which tells you everything you need to know about my decision-making and also about DEF CON. I&#39;m delighted.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/hatgpt/hacker-runway.jpg&quot; alt=&quot;About fifteen DEF CON Hacker Runway participants posing together on a stage in elaborate, creative hacker outfits&quot; width=&quot;1500&quot; height=&quot;1001&quot;&gt;
  &lt;figcaption&gt;The DEF CON 33 Hacker Runway crew. That&#39;s me on the far right, under the ever-judgmental hat.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h2&gt;Talk nerdy to me&lt;/h2&gt;
&lt;p&gt;The DEF CON 33 run is done, so the Hat isn&#39;t holding court on the con floor anymore. But it still boots up now and then. If you ever catch it online in the Maine Mesh, here&#39;s how you talk to it:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Get on the mesh with a Meshtastic device and tune to the channel it&#39;s living on.&lt;/li&gt;
&lt;li&gt;Send a message that starts with &lt;code&gt;@hatgpt&lt;/code&gt; and ask your question.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;You can DM it if you want privacy, or shout into the mesh for everyone to see. HatGPT doesn&#39;t judge. (That&#39;s a lie. It judges. Loudly.)&lt;/p&gt;
&lt;p&gt;Give it a beat before you expect a reply. It&#39;s a Raspberry Pi, and it might be chewing through a queue of other people&#39;s nonsense before it gets to yours.&lt;/p&gt;
&lt;figure class=&quot;post-figure video-embed&quot;&gt;
  &lt;blockquote class=&quot;twitter-tweet&quot; data-align=&quot;center&quot; data-dnt=&quot;true&quot;&gt;&lt;a href=&quot;https://x.com/marbasec/status/1952770338393137154&quot;&gt;▶ Watch HatGPT lit up in RGB mode (video on X)&lt;/a&gt;&lt;/blockquote&gt;
  &lt;script async=&quot;&quot; src=&quot;https://platform.twitter.com/widgets.js&quot; charset=&quot;utf-8&quot;&gt;&lt;/script&gt;
  &lt;figcaption&gt;▶ Video: HatGPT running its lights in full RGB mode, over on X.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/hatgpt/hatgpt-mesh.jpg&quot; alt=&quot;A Meshtastic chat screenshot: HatGPT answers that the DEF CON 26 theme was &#39;1983: The Counter-Future&#39; with a snarky aside about asking someone in a tinfoil hat, signed &#39;HatGPT out&#39;&quot; width=&quot;945&quot; height=&quot;1931&quot;&gt;
  &lt;figcaption&gt;Asked for the DEF CON 26 theme, it nailed it (1983: The Counter-Future) and threw in a tinfoil-hat crack for free.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;And if you don&#39;t have a Meshtastic radio yet and any of this sounds fun: come find me around Maine. I usually have a few on me, I&#39;m happy to get you started, and if you ask nicely I&#39;ll give you the whole tour.&lt;/p&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>How to have the most fun at DEF CON</title>
    <link href="https://marbasec.com/blog/how-to-have-the-most-fun-at-def-con/" />
    <updated>2024-08-15T00:00:00Z</updated>
    <id>https://marbasec.com/blog/how-to-have-the-most-fun-at-def-con/</id>
    <content type="html">&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-have-the-most-fun-at-def-con/maker-village-sao.jpg&quot; alt=&quot;Me in a green cap soldering at a table in the DEF CON Maker Village, learning to build an SAO badge add-on&quot;&gt;&lt;/p&gt;
&lt;p&gt;DEF CON can be a lot. Thirty-thousand-ish people, a hundred things happening at
once, a map that may as well be written in another language, and a reputation
for being full of people too cool to talk to you. The first time can feel less
like a party and more like getting dropped into someone else&#39;s inside joke.&lt;/p&gt;
&lt;p&gt;I&#39;ve been going for years now, and there&#39;s been good times - and some times that things didn&#39;t go exactly as I had hoped. I feel like in the last few years I&#39;d been hyper focused on being part of the con instead of enjoying it, and I was thinking at the end of DEF CON 31, maybe I wouldn&#39;t be back. However, my huband convinced me that I should just go and have fun... so I did that, focusing on exploring new things and not getting wrapped up in projects, and I had a great time. So here&#39;s my tips for making the most of DEFCON.&lt;/p&gt;
&lt;h2&gt;Go make something&lt;/h2&gt;
&lt;p&gt;If you do one thing, go to the Maker Village or the Hardware Hacking Village (or any village that hands you tools) and build a badge add-on. An SAO, or Simple Add-On, is a little PCB that plugs into a conference badge, and half of them are gloriously stupid, which is exactly what makes them fun.&lt;/p&gt;
&lt;p&gt;At DEF CON 32 I sat down and soldered one badge after another, and had a genuinely great time doing it. There is no better icebreaker in the world than two people fumbling with a soldering iron next to each other. Nobody at that table cares how good you are. They care that you showed up and grabbed the iron.&lt;/p&gt;
&lt;p&gt;I put together a couple of badges myself. The dinosaur-vs-cowboys badge a teammate handed me while we were waiting in line (&amp;quot;linecon&amp;quot;) was especially fun.&lt;/p&gt;
&lt;h2&gt;Talk to the person next to you&lt;/h2&gt;
&lt;p&gt;DEF CON runs on the fact that everyone there built something weird and secretly wants you to ask about it. That intimidating-looking person in line? They&#39;ll light up if you ask what their badge does. Somebody had Doom running on their hard hat&#39;s little display, because of course they did. That&#39;s just how this place works.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/how-to-have-the-most-fun-at-def-con/talking-hardhat.jpg&quot; alt=&quot;A DEF CON attendee wearing a hard hat with a small text display while another person types a question to it&quot; width=&quot;1500&quot; height=&quot;1001&quot;&gt;
  &lt;figcaption&gt;Someone built a hard hat that plays Doom on recycled hospital hardware... what?&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;With that said, the scary version of DEF CON, the one with some egos and gatekeeping, is real, but it&#39;s a small and very loud minority. The rest of it is just nerds who are thrilled you&#39;re curious. So be curious out loud, make a friend, get involved in whatever pulls you in.&lt;/p&gt;
&lt;h2&gt;Try a CTF, just not the whole con&lt;/h2&gt;
&lt;p&gt;I played in a few CTFs, and I genuinely enjoyed working on the Chakra badge, which was basically a piece of art disguised as a puzzle. I was the third person to solve it, which was good enough for third place and an actual trophy that now sits proudly on my shelf. Third place, sure, but it felt like a win, especially since I got there without burning my entire con on it.&lt;/p&gt;
&lt;h2&gt;Hang with a tribe... or find a new one.&lt;/h2&gt;
&lt;p&gt;DEF CON has sub-communities living inside the main event, so go find yours. I went to the Queercon meetups and hung out with some genuinely cool people.&lt;/p&gt;
&lt;h2&gt;The unglamorous survival stuff&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The 3-2-1 rule:&lt;/strong&gt; at least 3 hours of sleep, 2 meals, and 1 shower a day. Adjust upward. You will want to adjust upward... especially if you&#39;re almost in your 40s.. like me.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Water, constantly.&lt;/strong&gt; It&#39;s a desert, inside a casino, inside a desert.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mask up in the crowds.&lt;/strong&gt; &amp;quot;Con crud&amp;quot; is a tradition I do not endorse. (Ask me how DEF CON 31 ended. Actually, don&#39;t.)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;You don&#39;t have to do everything.&lt;/strong&gt; You will miss things. Everyone misses things. Missing things is fine. There&#39;s always next year.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Just be open to whatever comes your way...&lt;/h2&gt;
&lt;p&gt;The most fun I&#39;ve ever had at DEF CON has almost never been the thing I planned. It&#39;s been the side quest, the random village, the stranger who turned into a friend over a soldering table. Show up, be a beginner at something, and talk to people. I promise you&#39;ll have fun.&lt;/p&gt;
&lt;p&gt;And if the con ever feels like a room you don&#39;t belong in: it isn&#39;t. Come sit down, grab an iron. I&#39;ll save you a seat.&lt;/p&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>DC207&#39;s response to SecureMaine: allyship and cyber inclusivity</title>
    <link href="https://marbasec.com/blog/dc207-response-to-securemaine/" />
    <updated>2023-09-26T00:00:00Z</updated>
    <id>https://marbasec.com/blog/dc207-response-to-securemaine/</id>
    <content type="html">&lt;p&gt;In our seas, DC207 shines against those exploiting cybersecurity communities and elevating hate. Our commitment to inclusivity is unwavering.&lt;/p&gt;
&lt;p&gt;In the vast expanse of the digital world, akin to the unpredictable seas, there are beacons of light that guide ships to safety. For the cybersecurity community of Maine, DC207 has been one of those guiding beacons. Our mission has been about ensuring education and networking opportunities in the world of cybersecurity exist, and we have worked tirelessly to foster an environment of inclusivity and respect.&lt;/p&gt;
&lt;p&gt;Recently, questions have emerged regarding DC207&#39;s involvement with SecureMaine. As the largest and most active information security networking group in the state, we have naturally been asked questions on whether we&#39;d be there and how we&#39;d be participating. To set the record straight: while we were approached for sponsorship and asked for advice on bringing DC207-like events to the conference without our involvement, we are not involved because we didn&#39;t pay to sponsor the event. Given the information available to us, our alignment has always been and will always be organized with values of inclusivity, especially in the face of repulsive hate speech and divisive religious organizations masquerading as &amp;quot;community centers&amp;quot;, like The Point, which is the focus of why we cannot support this event. The organizers of SecureMaine have selected a religious organization known as &#39;The Point&#39; as their partner in running this conference. The Point is a church with deep-seated beliefs that equate members of the LGBTQIA+ community to zoophiles and pedophiles. Such beliefs, rooted in discrimination and ignorance, are not just baseless but deeply dehumanizing and offensive.&lt;/p&gt;
&lt;p&gt;While they realize publishing this kind of derogatory material is harmful to turning their church into a thriving enterprise, someone ought to introduce them to the concept of OSINT.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/dc207-response-to-securemaine/dc207-leadership-guide.jpg&quot; alt=&quot;A screenshot from Eastpoint Christian Church&#39;s 2018-2019 Leadership Guide, page 88. A highlighted passage lists &#39;homosexuality or lesbianism, bestiality or sex with animals, incest, and polygamy&#39; together as ways people &#39;stray from God&#39;s plan.&#39; A caption cites the page, links an archived copy of the guide, and notes eastpoint.church is the home of the SecureMaine conference.&quot; width=&quot;1400&quot; height=&quot;700&quot;&gt;
  &lt;figcaption&gt;From The Point&#39;s own leadership guide (page 88), preserved on the Wayback Machine.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;We could only bring ourselves to watch one of these videos where hate speech is employed against the trans, gay, and lesbian communities, and there are 400 more where that came from.&lt;/p&gt;
&lt;figure class=&quot;post-figure&quot;&gt;
  &lt;img src=&quot;https://marbasec.com/images/blog/dc207-response-to-securemaine/dc207-youtube-sermon.jpg&quot; alt=&quot;A screenshot of The Point&#39;s religious leader in a YouTube sermon titled &#39;It&#39;s Complicated #4: Marriage,&#39; with the video&#39;s auto-generated transcript highlighted where he groups same-sex marriage with incestuous relationships. The caption states the leader used offensive language about the trans community and compared same-sex marriages to abusive incestuous relationships.&quot; width=&quot;1400&quot; height=&quot;700&quot;&gt;
  &lt;figcaption&gt;The Point&#39;s leader, in a sermon posted to their own YouTube channel.&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;We want to be unequivocally clear: DC207 does not, and will not, endorse, sponsor, or maintain any relationship or partnership with entities that propagate such harmful beliefs. Our priority is the community. A community that thrives on diversity, mutual respect, and shared knowledge. A community that values each individual for their skills, knowledge, and contributions, and yes, their identities. Our diversity is our strength.&lt;/p&gt;
&lt;p&gt;When bringing these concerns to SecureMaine, we noted they were quick to update their website with the following new statement:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;SecureMaine is taking place in a publicly-available rental venue. The venue owner is a church. SecureMaine is working closely with the venue management to make sure that its other use as a church will not be expressed substantially within the space of the SecureMaine event. This has included the removal or obscuring of substantial non-secular material.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;DC207&#39;s position is that claiming the ownership of the venue belonging to the church is misleading and disingenuous. The venue is a church, and efforts are being made to mask the public appearance of what truly is &#39;the point&#39; of The Point. This is a great example of performative allyship, where an organization goes to lengths to literally obscure the hateful nature of what is being supported, saying they don&#39;t support it while forking over thousands of dollars in cash to groups marginalizing minorities. If SecureMaine were an ally, they would denounce this, but they don&#39;t, they don&#39;t want to ruffle feathers. DC207, however, does not mind ruffling the feathers of people who perpetuate an oppressive society. SecureMaine continues:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Government-allied and informational nonprofit institutions working with a wide variety of religious and community institutions is a common practice, in order to access regional facilities and populations, scaled appropriately to the event organizer&#39;s nonprofit resources. Renting this, or any, publicly available venue does not mean SecureMaine supports any social, political, religious, or workforce practices of the owner / operator of the venue. SecureMaine&#39;s Code of Conduct clearly states our own position.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;SecureMaine is supporting the church, though. The church can continue to spread hate speech through the support of dollars. When you give money to SecureMaine, you&#39;re indirectly funding hate speech like the ones spread in the rooms the conference will be held in. Unfortunately, SecureMaine&#39;s code of conduct is boilerplate language put up hurriedly in an effort to get ahead of this controversy. If the organization had true core values, event venues like this would not have been considered and secured for this conference in the first place.&lt;/p&gt;
&lt;p&gt;Every individual has autonomy over their financial and moral choices. However, it&#39;s vital to recognize the broader implications of these choices. Supporting events or venues that platform hate and discrimination directly perpetuates harmful ideologies. It&#39;s not just about where you put your money but also about what values and ideologies money amplifies.&lt;/p&gt;
&lt;p&gt;At its heart, DC207 is a community-driven, non-commercial entity. We don&#39;t need to go and obscure ourselves for public viewing or make half-hearted excuses for how we fund hate speech, because we don&#39;t do that. Our mission is centered around fostering cybersecurity knowledge, building meaningful connections, and creating an inclusive and respectful environment. It&#39;s where we started, where we&#39;re going, and where we&#39;ll always be. Our journey does not cross with events that perpetuate hate.&lt;/p&gt;
&lt;p&gt;At DC207, you can bring your whole self. We prioritize genuine inclusivity and respect without exceptions. We hope you will join us in taking a clear stand against any form of discrimination, ensuring that cybersecurity remains a field of shared knowledge, unity, and mutual respect.&lt;/p&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>DEF CON 31: The Lonely Hard Drive, and a very large Betty Pagefile</title>
    <link href="https://marbasec.com/blog/def-con-31-lonely-hard-drive/" />
    <updated>2023-08-18T00:00:00Z</updated>
    <id>https://marbasec.com/blog/def-con-31-lonely-hard-drive/</id>
    <content type="html">&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/def-con-31-lonely-hard-drive/lonely-hard-drive-booth.jpg&quot; alt=&quot;The Lonely Hard Drive crew on stage at DEF CON 31 with the contest&#39;s skull-and-crossbones hard-drive mascot and a &amp;quot;The Lonely Hard Drive&amp;quot; poster&quot;&gt;&lt;/p&gt;
&lt;p&gt;DEF CON 31 is a bit of a blur. Mostly a good one.&lt;/p&gt;
&lt;p&gt;I spent most of it helping run &lt;a href=&quot;https://forum.defcon.org/node/245414&quot;&gt;The Lonely Hard Drive&lt;/a&gt;, which was one of the most fun and most exhausting things I’ve ever packed into a single con.&lt;/p&gt;
&lt;h2&gt;DC30 to DC31&lt;/h2&gt;
&lt;p&gt;The Lonely Hard Drive is a DEF CON contest built on an extremely simple premise: hand people free hard drives and see what happens.&lt;/p&gt;
&lt;p&gt;For DEF CON 31, we handed out literal hard drives. Real ones. Each one had a CTF loaded onto it.&lt;/p&gt;
&lt;p&gt;You take a drive, plug it in (you monster), and suddenly you’re falling down a rabbit hole of puzzles and challenges, finding flags and climbing the leaderboard toward prizes.&lt;/p&gt;
&lt;p&gt;The idea started the year before with FragileDuck from the DC207 crew. For DC31, he turned it into an official contest.&lt;/p&gt;
&lt;p&gt;It rewards the one instinct every security person spends their entire career trying to unlearn:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Ooh, a free drive. Let’s see what’s on it.&lt;/em&gt;&lt;/p&gt;
&lt;h2&gt;Hard Drives Are... Hard&lt;/h2&gt;
&lt;p&gt;I originally got involved through DC207 to help with the money side of the project. We hosted the website and landing pages, and we paid for the drives and cables.&lt;/p&gt;
&lt;p&gt;Turns out buying an absurd mountain of hard drives from a manufacturer in China is a whole project by itself.&lt;/p&gt;
&lt;p&gt;First you order the drives. Then you arrange for custom labels. Then you clone the CTF onto every single one of them.&lt;/p&gt;
&lt;p&gt;At that quantity, cloning the drives is not an afternoon project. It’s a week or two of drives running around the clock.&lt;/p&gt;
&lt;p&gt;Then the team decided to heat-seal all of them in anti-static bags. That meant a bunch of us sitting around, packaging drives by hand like the world’s nerdiest holiday assembly line.&lt;/p&gt;
&lt;p&gt;It was tedious. It was also genuinely kind of wonderful.&lt;/p&gt;
&lt;p&gt;That unglamorous backstage work is what makes the shiny, fun part possible. I’d take an evening sealing drives with good people over almost any panel.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/uploads/betty-pagefile.jpg&quot; alt=&quot;Betty Pagefile, the shy 3D-printed grey hard-drive mascot with blushing cheeks, standing beside the Lonely Hard Drive DEF CON poster&quot; title=&quot;oh betty...&quot;&gt;&lt;/p&gt;
&lt;h2&gt;Chips Ahoy!&lt;/h2&gt;
&lt;p&gt;At some point during the con, I found $200 on the casino floor. So, obviously, I spent it on putting another chip inserted into my hand.&lt;/p&gt;
&lt;p&gt;I’d been wanting another implant, and finding $200 in Vegas seemed like the universe giving me a very specific kind of grant.&lt;/p&gt;
&lt;p&gt;The chip lights up when it gets near an energy field, which is extremely cool. It does work. I just have to wait for the swelling to go down before I can properly enjoy the tiny light someone injected into me through what was basically a straw.&lt;/p&gt;
&lt;p&gt;So now I have two implants.&lt;/p&gt;
&lt;p&gt;I found $200 on a casino floor and left Vegas with more hardware in my body than I arrived with.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Chips Ahoy!&lt;/em&gt;&lt;/p&gt;
&lt;h2&gt;The Parting Gifts&lt;/h2&gt;
&lt;p&gt;Also, I got COVID.&lt;/p&gt;
&lt;p&gt;DEF CON sent me home with the traditional souvenir, and it was its own special flavor of miserable. Ask me how the trip ended. Actually, don’t.&lt;/p&gt;
&lt;p&gt;The honest version is that COVID wasn’t the only rough part. Any project run by a passionate pile of volunteers eventually reaches a point where people stop agreeing. A lot of things that had never quite been settled got settled all at once.&lt;/p&gt;
&lt;p&gt;After DC31, I decided not to come back for the next version of the contest.&lt;/p&gt;
&lt;p&gt;There’s no big drama to air and no hard feelings. Volunteer projects get complicated, especially when everyone cares a lot. Sometimes you can be proud of something, love the time you spent doing it, and still know when you’re done.&lt;/p&gt;
&lt;p&gt;I’m proud of what we built. I’m glad I was there. And I’m glad I knew when to step away.&lt;/p&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>How to set up your very own AND!XOR Chomper hacker smartwatch</title>
    <link href="https://marbasec.com/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/" />
    <updated>2022-09-04T00:00:00Z</updated>
    <id>https://marbasec.com/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/</id>
    <content type="html">&lt;p&gt;Every summer in Las Vegas, hackers from all over the world come to the strip to hack the planet at the largest hacking conference, DEFCON. The AND!XOR group has been building wearable technology badges in tandem with the conference and selling/giving them away at the conference since 2016. DEFCON 30 was no exception, their awesome badge named &amp;quot;Chomper&amp;quot; was in the works for roughly two years before its release last month. The badge was orginally slated for DEFCON 29, but the global supply chain issues which were impacting almost everything that year elongated the timeline. In short, their plan was to buy consumer hardware, hack it, build drivers from the ground up for an embedded version of Python, load it with hacking tools, and a fun text-based adventure. Amazing.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/01-chomper-badge-trailer.png&quot; alt=&quot;The AND!XOR Chomper badge smartwatch&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Check out the &lt;a href=&quot;https://www.youtube.com/watch?v=eVtjuQFF1TU&quot;&gt;AND!XOR DC30 Trailer&lt;/a&gt; to see their craftmanship&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;If you didn&#39;t make it to DEFCON this year, or if you were so busy (guilty here!) that you didn&#39;t have time to check out the AND!XOR &amp;quot;snacky&amp;quot; CFT/vending machine, you&#39;re in luck. AND!XOR released the source code and I&#39;m going to show you exactly how to configure your own Chomper. It&#39;s actually pretty easy. :-)&lt;/p&gt;
&lt;p&gt;First things first, you need to buy the watch. It&#39;s a LILYGO T-Watch-2020 V3. It&#39;s basically an ESP32 with a screen, microphone, Bluetooth, Wi-Fi device shoved into a smartwatch formfactor. If you&#39;d like to support this blog, you can buy it from amazon here: &lt;a href=&quot;https://amzn.to/3KNDjeh&quot;&gt;https://amzn.to/3KNDjeh&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/02-lilygo-t-watch-2020-v3.jpg&quot; alt=&quot;The LILYGO T-Watch-2020 V3 in its retail packaging&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Who exactly is this Lily? Why does she go?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;So, get to ordering it! Don&#39;t worry, we&#39;ll be here when you get back. :-)&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Alright, got the watch? Awesome. :-) Now you&#39;ll need to set up your flashing environment. Now I suggest that you set this up using your favorite Linux environment, while I&#39;m sure you could set this up in Windows I just think it&#39;d be a lot of work/heartache. For me I&#39;m going to run Ubuntu in VMWare Workstation with a fresh install of Ubuntu.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;NOTE:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If you&#39;re just finding it a little too challenging to set up this environment - I understand, not everyone is familiar with Linux. At the very end of this post, we exported the virtual machine used to do the flashing so you can just download and flash - but don&#39;t forget to set up the Wi-Fi access point &amp;quot;Matt Damon&amp;quot; explained later in this post.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let&#39;s start by installing the basics, git, python3, etc.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;sudo apt-get update
sudo apt-get install python3 python3-pip git
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/03-apt-install-basics.png&quot; alt=&quot;Terminal output of installing python3, python3-pip, and git&quot;&gt;&lt;/p&gt;
&lt;p&gt;Once that&#39;s installed, we&#39;ll grab the AND!XOR badge firmware/flashing stuff from their github using the following command:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;git clone https://github.com/ANDnXOR/ANDnXOR_DC30_Badge
cd ANDnXOR_DC30_Badge
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/04-git-clone-badge-repo.png&quot; alt=&quot;Terminal output of cloning the ANDnXOR_DC30_Badge repository&quot;&gt;&lt;/p&gt;
&lt;p&gt;Following the guidance from the software repository, we&#39;ll need to just do some additional configuration steps to set up user accounts, set up permissions, and install some more packages. Let&#39;s get to it.&lt;/p&gt;
&lt;p&gt;Setup the user&#39;s permissions so we can flash the watch without sudo&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;sudo adduser $USER dialout
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The documentation says that we need to break the serial device permissions as well. Not sure why - but let&#39;s do it. :-)&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;sudo apt remove modemmanager
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Now we&#39;re going to need to install a whole bunch of packages, this will take a minute.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;apt install build-essential python3-virtualenv python3-freetype ffmpeg picocom
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Actually - since we have a few minutes while that&#39;s running, we&#39;re going to need to set up a WiFi access point for our watch, so maybe do that now. The watch downloads most of the assets right from the internet, mostly because it would be horribly slow over a serial connection. The WiFi access point must be called &amp;quot;&lt;strong&gt;Matt Damon&lt;/strong&gt;&amp;quot;, and the password must be &amp;quot;&lt;strong&gt;WEmustSAVEhim&lt;/strong&gt;&amp;quot;.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/05-matt-damon-wifi-ap.png&quot; alt=&quot;Wi-Fi hotspot settings showing an access point named Matt Damon&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;What will the neighbors think?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;AND!XOR really likes Matt Damon if you didn&#39;t already know. :-) Hopefully that took up some time and our build environment is done and ready to go.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/06-build-packages-installed.png&quot; alt=&quot;Terminal output showing the build packages finished installing&quot;&gt;&lt;/p&gt;
&lt;p&gt;Now we&#39;ll need to add an alias for our python3 install.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;sudo update-alternatives --install /usr/bin/python python /usr/bin/python3 1
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/07-python-alias.png&quot; alt=&quot;Terminal output of the update-alternatives command aliasing python to python3&quot;&gt;&lt;/p&gt;
&lt;p&gt;Now we&#39;ll need to set up our python packages for this whole thing to work with putting the python stuff on the watch.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;pip3 install adafruit-ampy mpremote cmake
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You might run into the following error (which we&#39;ll want to fix) when you install these packages.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/08-pip-path-warning.png&quot; alt=&quot;pip warning that installed scripts are not on PATH&quot;&gt;&lt;/p&gt;
&lt;p&gt;Basically, we need to make sure we can access the new python packages from the command line. To do this, edit your /etc/environments file. Let&#39;s do that now - I&#39;m going to use vi, but you do you when it comes to text editing.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;sudo vi /etc/environments
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;We&#39;ll need to add the path which was in the error message. Once that&#39;s in there, save the file.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/09-etc-environments-path.png&quot; alt=&quot;Editing /etc/environments to add the local bin path&quot;&gt;&lt;/p&gt;
&lt;p&gt;Now we&#39;ll need to just have our session pull those attributes, the best way to do this is just to log out, then log back in. Once you&#39;re back in just check to see if the new path is in your PATH variable with this:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;echo $PATH
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/10-echo-path.png&quot; alt=&quot;Terminal output of echo $PATH showing the new path included&quot;&gt;&lt;/p&gt;
&lt;p&gt;Cool! Let&#39;s go back into our AND!XOR file where all the code is.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;cd ANDnXOR_DC30_Badge/
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;We now need to grab the ESP IDF, now in the documentation they say you need the 4.2 version, so we&#39;ll clone that repository, and then change into that directory... this will take a little while, lots to clone here. :-)&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;git clone -b v4.2 --recursive https://github.com/espressif/esp-idf.git
cd esp-idf
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/11-esp-idf-clone.png&quot; alt=&quot;Terminal output of cloning the esp-idf v4.2 repository&quot;&gt;&lt;/p&gt;
&lt;p&gt;Once you&#39;re there, time to install the xtensa build tools using the esp-idf install script.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;./install.sh
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/12-esp-idf-install.png&quot; alt=&quot;Terminal output of running the esp-idf install script&quot;&gt;&lt;/p&gt;
&lt;p&gt;Now, it&#39;s not mentioned in the github readme, but you&#39;ll also need to do this export step which is shown in the terminal after installing the xtensa tools. Do that now.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;. ./export.sh
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/13-export-script.png&quot; alt=&quot;Terminal output of sourcing the esp-idf export script&quot;&gt;&lt;/p&gt;
&lt;p&gt;Now, we should be able to rock and roll with this thing. We&#39;ll need to now attach our watch and route the USB connection to our VM, and then find out which serial device it&#39;s named. To do this, just list the directories in /dev and look for tty device named ttyACM - in this case for me, it&#39;s ttyACM0&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/14-ttyacm-device.png&quot; alt=&quot;Listing /dev showing the ttyACM0 serial device&quot;&gt;&lt;/p&gt;
&lt;p&gt;Let&#39;s try flashing the device. If you skipped setting up that Wi-Fi access point, do that now! Back in our provision script location inside /ANDnXOR_DC30_Badge/provision, we&#39;ll want to run the provisioning script with that tty device as an argument.&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;./provision.sh /dev/ttyACM0
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If all is good, you should start seeing some mpy files being flashed over (slowly - according to the script).&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/15-provision-flashing.png&quot; alt=&quot;Terminal output of the provisioning script flashing mpy files to the watch&quot;&gt;&lt;/p&gt;
&lt;p&gt;This will take a bit of time. The script is going to instruct the watch to connect to your Matt Damon Wi-Fi, and will start downloading files from &amp;quot;mattdamon.app&amp;quot;. :-)&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/16-mattdamon-app-download.png&quot; alt=&quot;Terminal output showing the watch downloading files from mattdamon.app&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/17-provision-download-progress.png&quot; alt=&quot;Terminal output showing asset download progress during provisioning&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/18-provision-complete.png&quot; alt=&quot;Terminal output showing the provisioning process completing&quot;&gt;&lt;/p&gt;
&lt;p&gt;Once it&#39;s done, it&#39;ll be ready to disconnect - however, check the watch screen, it should be red, yellow, or green which is indicating if the device is properly charged. As heard in the microfab podcast (link below), at the flash party for these devices, they would leave them plugged in until they turned green to indicate the watch was charged.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/19-watch-charging-screen.png&quot; alt=&quot;The Chomper watch showing its charged status screen&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Yay!! It&#39;s ready.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Now, go forth and conquer the world with your new hacker smartwatch! Enjoy the lolz, puzzles, 31337 timepiece, and hard work from AND!XOR&#39;s very talented and creative team.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/how-to-set-up-your-very-own-and-xor-chomper-hacker-smartwatch/20-chomper-watch-ready.png&quot; alt=&quot;The finished AND!XOR Chomper hacker smartwatch up and running&quot;&gt;&lt;/p&gt;
&lt;p&gt;Till next time.&lt;/p&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;References &amp;amp; Resources&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Podcast on how this badge was created: &lt;a href=&quot;https://macrofab.com/blog/mep-ep342-hackery-experts/&quot;&gt;MEP EP#342: Hackery Experts - MacroFab&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;AND!XOR&#39;s website: &lt;a href=&quot;https://www.andnxor.com/&quot;&gt;HOME | andnxor&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;AND!XOR Software/Firmware for DC30 Badge: &lt;a href=&quot;https://github.com/ANDnXOR/ANDnXOR_DC30_Badge&quot;&gt;ANDnXOR/ANDnXOR_DC30_Badge: Chomper! (github.com)&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Preconfigured VM: &lt;a href=&quot;https://www.dropbox.com/s/erp993xm33kn1d8/ChomperFlashVM.zip?dl=0&quot;&gt;https://www.dropbox.com/s/erp993xm33kn1d8/ChomperFlashVM.zip?dl=0&lt;/a&gt;&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>Student Loan Scams - Info &amp; Informational Resources</title>
    <link href="https://marbasec.com/blog/student-loan-scams-info-informational-resources/" />
    <updated>2022-09-02T00:00:00Z</updated>
    <id>https://marbasec.com/blog/student-loan-scams-info-informational-resources/</id>
    <content type="html">&lt;p&gt;Hey all,&lt;/p&gt;
&lt;p&gt;Recent reports of student loan scammers targeting borrowers are a harsh reminder of the lengths some people will go to to take advantage of others. The scammers typically contact victims by phone or email, promising them early access to the expanded relief program announced by the Biden administration. The scammers may say they&#39;re with your bank, loan servicer, the department of education, or even a &#39;loan forgiveness broker&#39;.&lt;/p&gt;
&lt;p&gt;Once they&#39;ve hooked you, they might promise immediate relief, refunds, and prey on your emotions by requiring you to act quickly. The scammers then ask for personal information, such as the victim’s Social Security number or bank account information, which they use to commit identity theft or fraud.&lt;/p&gt;
&lt;p&gt;The best way to avoid becoming a victim of this scam is to know what the one-time forgiveness program offers and how to access it. These details have not been announced but keep a close eye on the student aid website, which publishes updates as they develop. You can check that resource out here:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://studentaid.gov/debt-relief-announcement/&quot;&gt;https://studentaid.gov/debt-relief-announcement/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;You should NEVER receive an unsolicited phone call from a governmental agency asking you for personal information. If you are contacted by someone claiming to be from the Department of Education or another government agency offering assistance with your student loans, be sure to verify their identity before providing any personal information. You can call the Department of Education’s Federal Student Aid Information Center at 1-800-4-FEDAID (1-800-433-3243).&lt;/p&gt;
&lt;p&gt;If you think you may have been the victim of a student loan scam, contact the Federal Trade Commission and the Department of Education immediately. You can also file a complaint with the Consumer Financial Protection Bureau.&lt;/p&gt;
&lt;p&gt;In addition, be sure to take steps to protect your identity and financial information, such as monitoring your credit report for changes or unusual activity and signing up for a credit monitoring service. An excellent government resource will walk you through the steps of protecting your information from identity theft abuse. Check it out here:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.identitytheft.gov/&quot;&gt;https://www.identitytheft.gov/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;To help spread the word, we created a couple of infographic resources which we&#39;re attaching to this post. One is in a poster-friendly format, the other is in a social media-style gallery. Feel free to share these resources as you see fit.&lt;/p&gt;
&lt;p&gt;Stay safe out there.&lt;/p&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;a href=&quot;https://marbasec.com/images/blog/student-loan-scams-info-informational-resources/avoid-student-loan-forgiveness-scams-social-media-gallery.zip&quot;&gt;Avoid Student Loan Forgiveness Scams - Social Media Formatted Image Gallery (ZIP • 2218KB)&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/student-loan-scams-info-informational-resources/01-social-media-gallery-example.png&quot; alt=&quot;Avoid Student Loan Forgiveness Scams infographic banner from the social media formatted image gallery&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Example of social media gallery&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://marbasec.com/images/blog/student-loan-scams-info-informational-resources/student-loan-forgiveness-video.mp4&quot;&gt;Student Loan Forgiveness - Video (MP4)&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;video controls=&quot;&quot; preload=&quot;metadata&quot; style=&quot;max-width:100%;&quot; poster=&quot;https://marbasec.com/images/blog/student-loan-scams-info-informational-resources/02-video-thumbnail.jpg&quot; src=&quot;https://marbasec.com/images/blog/student-loan-scams-info-informational-resources/student-loan-forgiveness-video.mp4&quot; title=&quot;Student Loan Forgiveness - Video&quot;&gt;&lt;/video&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Video format of the social media post&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://marbasec.com/images/blog/student-loan-scams-info-informational-resources/avoid-student-loan-forgiveness-scams-poster.pdf&quot;&gt;Avoid Student Loan Forgiveness Scams - Poster (PDF • 376KB)&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/student-loan-scams-info-informational-resources/03-poster-example.png&quot; alt=&quot;Avoid Student Loan Forgiveness Scams poster infographic&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Example of poster&lt;/em&gt;&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>Beckman Coulter&#39;s Remisol Advance - Security Advisory MARBAS-22-001</title>
    <link href="https://marbasec.com/blog/beckman-coulter-s-remisol-advance-security-advisory-marbas-22-001/" />
    <updated>2022-08-30T00:00:00Z</updated>
    <id>https://marbasec.com/blog/beckman-coulter-s-remisol-advance-security-advisory-marbas-22-001/</id>
    <content type="html">&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Affected Product:&lt;/strong&gt; Beckman Coulter Remisol Advance v2.0.12.1 and below&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability Type:&lt;/strong&gt; Insecure Permissions &amp;amp; Privilege Escalation&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Root Cause:&lt;/strong&gt; The permissions set by Remisol Advance V2.0.12.1 and below on install for six running services allows for non-privileged users to overwrite and/or manipulate executables and libraries which run as the elevated SYSTEM user on Windows. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Components and corresponding CVEs:&lt;/strong&gt; &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CVE-2022-26235: Normand Message Server&lt;/li&gt;
&lt;li&gt;CVE-2022-26236: Normand Remisol Advance Launcher&lt;/li&gt;
&lt;li&gt;CVE-2022-26237: Normand ViewerService&lt;/li&gt;
&lt;li&gt;CVE-2022-26238: Normand Service Manager&lt;/li&gt;
&lt;li&gt;CVE-2022-26239: Normand License Manager&lt;/li&gt;
&lt;li&gt;CVE-2022-26240: Normand Message Buffer&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;p&gt;It&#39;s no secret that healthcare technology offers a buffet of information to would-be attackers. It&#39;s amazing how many systems, vendors, and technologies you&#39;ve never even heard of are burdened with rich sets of information which these unheard entities are then entrusted to. On top of all of this, there&#39;s a consumer expectation that these systems are protected or at least given attention when they have serious problems. &lt;/p&gt;
&lt;p&gt;Expectations are funny things.&lt;/p&gt;
&lt;p&gt;This disclosure specifically deals with the software product Beckman sells as LIMS middleware &lt;strong&gt;Remisol Advance&lt;/strong&gt;. Remisol is supposedly doing the following according to Beckman&#39;s marketing materials:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;REMISOL Advance is a leading middleware solution for today’s clinical laboratories, bridging laboratory information systems (LIS) and instrumentation. It helps drive improved operational efficiency within and across the laboratory network through process automation and standardization. The enhanced capabilities of dashboards provide real-time insights into operations and fast access to key metrics for more informed decision-making.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We&#39;ve opened the following CVEs for this disclosure which lead to privilege escalation:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;h4&gt;&lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26235&quot;&gt;&lt;strong&gt;CVE-2022-26235&lt;/strong&gt;&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;h4&gt;&lt;a href=&quot;https://pastebin.com/amgw9pE7&quot;&gt;https://pastebin.com/amgw9pE7&lt;/a&gt;&lt;/h4&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;h4&gt;&lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26236&quot;&gt;&lt;strong&gt;CVE-2022-26236&lt;/strong&gt;&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;h4&gt;&lt;a href=&quot;https://pastebin.com/hwrvFix5&quot;&gt;https://pastebin.com/hwrvFix5&lt;/a&gt;&lt;/h4&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;h4&gt;&lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26237&quot;&gt;&lt;strong&gt;CVE-2022-26237&lt;/strong&gt;&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;h4&gt;&lt;a href=&quot;https://pastebin.com/DREqM7AT&quot;&gt;https://pastebin.com/DREqM7AT&lt;/a&gt;&lt;/h4&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;h4&gt;&lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26238&quot;&gt;&lt;strong&gt;CVE-2022-26238&lt;/strong&gt;&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;h4&gt;&lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26238&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://pastebin.com/23N5wcC7&quot;&gt;https://pastebin.com/23N5wcC7&lt;/a&gt;&lt;/h4&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;h4&gt;&lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26239&quot;&gt;&lt;strong&gt;CVE-2022-26239&lt;/strong&gt;&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;h4&gt;&lt;a href=&quot;https://pastebin.com/1QEHrj01&quot;&gt;https://pastebin.com/1QEHrj01&lt;/a&gt; &lt;/h4&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;h4&gt;&lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26240&quot;&gt;&lt;strong&gt;CVE-2022-26240&lt;/strong&gt;&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;h4&gt;&lt;a href=&quot;https://pastebin.com/Bsy6KTxJ&quot;&gt;https://pastebin.com/Bsy6KTxJ&lt;/a&gt;&lt;/h4&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The vulnerabilities are simple enough Windows vulnerabilities related to incorrect permissions on installed services. Remisol Advance runs these six services with the SYSTEM account when installed. Also, when installed, the files where the services are initialized are something all users can write to. A user could kill the process which is running the service, install malware, and restart the service to take advantage of the SYSTEM account. &lt;/p&gt;
&lt;p&gt;The fix is simple: correct the permissions so that every user cannot overwrite the services and therefore make themselves a super admin on the local Windows host. &lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/beckman-coulter-s-remisol-advance-security-advisory-marbas-22-001/2000_631fa75056732.png&quot; alt=&quot;Cartoon hacker at laptop beside bar chart rising from user to super admin&quot;&gt;&lt;/p&gt;
&lt;p&gt;Movin&#39; on up thanks to Beckman Coulter!&lt;/p&gt;
&lt;p&gt;The biggest concern is that this software is installed on Windows workstations which are often placed in easy to access areas of the hospital. Think lab stations where a phlebotomist might take a blood sample, also - in most chemistry, hematology and microbiology labs. Labs are usually running around the clock processing samples and workstations are usually logged in and ready to take data from users. Don&#39;t believe me? Do a google search for an example - think something like this.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/beckman-coulter-s-remisol-advance-security-advisory-marbas-22-001/2000_630d1a8216d25.png&quot; alt=&quot;Blood draw in a clinic with a logged-in, unattended workstation highlighted behind the patient&quot;&gt;&lt;/p&gt;
&lt;p&gt;Or this...&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/beckman-coulter-s-remisol-advance-security-advisory-marbas-22-001/2000_630d1d33724a1.png&quot; alt=&quot;Lab technician in a lab with a logged-in, unattended computer highlighted in the background&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;I think after googling these I&#39;m on some list now....&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This is commonplace, and as such these workstations are typically locked down with controls that account for malicious users. These controls can be circumvented when an attacker takes advantage of these vulnerabilities. As stated, the services allow for the overwriting of libraries and executables which lead to privesc. Per the CVE disclosures:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The default privileges for the running service &lt;strong&gt;*Service name here, because there&#39;s six*&lt;/strong&gt; in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This sensitive data is PHI.... and administrative control over the system and future inputs. The combination between easy physical access of systems and really dumb (and very preventable) vulnerabilities is a perfect storm of several abuse cases.&lt;/p&gt;
&lt;p&gt;Although, we&#39;re talking about physical access though. If you&#39;re lucky enough to be network adjacent, you can look forward to default passwords configured for the highest levels of access enabled by default. &lt;/p&gt;
&lt;p&gt;Not disclosed as a CVE, we found documents while attempting to authenticate to the software directly using usernames and passwords. Using simple Google searches, we found published materials on Beckman&#39;s website 8 years ago which gives users super admin rights into the software itself. From what was observed - the vendor likely installs this middleware and then leaves it with defaults intact.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/beckman-coulter-s-remisol-advance-security-advisory-marbas-22-001/2000_630d396148df7.png&quot; alt=&quot;Remisol Advance manual excerpt listing a redacted generic administrator username and password&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;8 years old is a great age to be when you&#39;re a human - not so much if you&#39;re a password.&lt;/em&gt; &lt;/p&gt;
&lt;p&gt;What&#39;s interesting about these security findings is that they&#39;re just so elementary that they should have been caught by basic vulnerability scanners and/or penetration testing if Beckman had even decided to do that sort of thing on their own products. So, if you&#39;re out there Beckman - we have some advice for you:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Don&#39;t install customers with your software using published default passwords which give super admin privileges. Advise your current customer to change their passwords because this is likely everywhere.&lt;/li&gt;
&lt;li&gt;Don&#39;t use SYSTEM to run services which you then grant everyone the ability to modify the files - which in turn gives them the ability to change said files. &lt;/li&gt;
&lt;li&gt;Do basic security work in assessing your systems in the future. You&#39;re a five-billion-dollar company. Shape up.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;re a customer of Beckman Coulter, my apologies but you&#39;ll need to do the following if they haven&#39;t helped you. &lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Change default passwords on any Remisol Advance or Beckman product with the knowledge that they publish and use default passwords for customer products.&lt;/li&gt;
&lt;li&gt;Monitor systems using the Remisol Advance middleware for unusual behavior, especially related to their services which apparently need to run with full administrator privileges. Possibly lock down those folders if you have a decent team who can harden and then validate access to those files.&lt;/li&gt;
&lt;li&gt;Ask Beckman to be better with their security and ask specific questions about what they&#39;re doing to improve. &lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Thanks for checking out the blog - till next time. :-) &lt;/p&gt;
&lt;p&gt;-Marbaṩ &lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;9/12/22 Edit: Added one more service - originally publishing five when there were six in total. Also cleaned up content so it&#39;s easier for MITRE to consume.&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>Bypass .NET Request Validation with MSSQL</title>
    <link href="https://marbasec.com/blog/bypass-net-request-validation-with-mssql/" />
    <updated>2022-04-06T00:00:00Z</updated>
    <id>https://marbasec.com/blog/bypass-net-request-validation-with-mssql/</id>
    <content type="html">&lt;p&gt;So - once in awhile I see applications with this specific flaw and I find myself just trying to jog my memory about this faint thing I remembered in an application. I figured sometimes to retain this information you just need to get it out of your head and into another place - like a blog. &lt;/p&gt;
&lt;p&gt;For this blog post, I wanted to share just a simple bit of information I&#39;ve needed from time to time for bypassing character restrictions on .NET applications using web forms. So, the long and short of it is that there&#39;s something called &lt;a href=&quot;https://docs.microsoft.com/en-us/previous-versions/aspnet/hh882339(v=vs.110)?redirectedfrom=MSDN&quot;&gt;request validation in .NET applications&lt;/a&gt;, and in older versions of .NET or let&#39;s just say - more homebrewed/homemade kinds of .NET applications this is usually implemented in a lacking way - especially if the application is using MSSQL.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/bypass-net-request-validation-with-mssql/normal_62521afacba5c.jpg&quot; alt=&quot;Homemade unicorn cake with fondant, rainbow candy mane and joke teeth&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Homemade things have their charm and place, but maybe not so much for enterprise software which contains highly sensitive PII... just saying.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;With that being said even though this is referencing older applications - I saw this kind of broken request validation very recently on a new application which had some fancy rebranded functionality on the surface - but was still an old .NET application to its core doing dumb stuff in the backend database.&lt;/p&gt;
&lt;p&gt;Ok fine, so how do you beat form level request validation performed by .NET? Typically, by just using different unicode characters which will be translated by MSSQL and stored in a database as something different. I sort of imagine the servers having this kind of conversation among themselves.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/bypass-net-request-validation-with-mssql/normal_625222fdce271.png&quot; alt=&quot;Diagram: script payload passes .NET request validation, gets converted by MSSQL, then executes&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Interconnected systems are always so positive and upbeat.&lt;/em&gt; &lt;/p&gt;
&lt;p&gt;Got it? Cool, let&#39;s dig into the specifics. Let&#39;s say you save the following text to a form with this validation turned on:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;txt1&amp;gt;
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;More than likely what you&#39;ll get is this:&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/bypass-net-request-validation-with-mssql/2000_624e3f13187ef.png&quot; alt=&quot;ASP.NET server error page reporting a potentially dangerous Request.Form value&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;I stole this screenshot from: &lt;a href=&quot;https://codewala.net/2012/04/03/request-validation-with-asp-net-4-5-a-deep-dive/&quot;&gt;Request Validation with ASP.NET 4.5 : A deep dive | Code Wala&lt;/a&gt;, didn&#39;t want to put my own here.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Ok, neat. So we&#39;re screwed right? Not yet. You see there are different kinds of opening and closing brackets which will bypass field validation but will get translated. A perfect example of that is something like this unicode character: &lt;/p&gt;
&lt;pre&gt;&lt;code&gt;＜txt1 ＞
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;So they look the same, but they&#39;re not the same character. If we go to our trusty Unicode lookup tool (literally &lt;a href=&quot;https://unicodelookup.com/&quot;&gt;unicodelookup.com&lt;/a&gt;) you can see we have char 1, the less-than sign, and then char 2, the fullwidth less-than sign. &lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/bypass-net-request-validation-with-mssql/2000_624e40877360d.png&quot; alt=&quot;Unicode Lookup site listing the less-than sign and fullwidth less-than sign&quot;&gt;&lt;/p&gt;
&lt;p&gt;The first one gets blocked, the second one doesn&#39;t, gets written to the database and then MSSQL converts char 2 into char 1 through a process (which I believe is related to collation - not 100% sure on that one). How nice of it.&lt;/p&gt;
&lt;p&gt;So this doesn&#39;t work everywhere... but - it works a whole lot and instead of hunting for this info every time I need it I figured I&#39;d write myself a little something on my blog so I remember for next time.&lt;/p&gt;
&lt;p&gt;Maybe you&#39;ll find it helpful too. &lt;/p&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>The IT Industry Needs a Toxic Masculinity Intervention</title>
    <link href="https://marbasec.com/blog/the-it-industry-needs-a-toxic-masculinity-intervention/" />
    <updated>2022-04-02T00:00:00Z</updated>
    <id>https://marbasec.com/blog/the-it-industry-needs-a-toxic-masculinity-intervention/</id>
    <content type="html">&lt;p&gt;I spend a great deal of time talking to people... it&#39;s one of the things I love the most about my line of work. I speak with people, get to know them, learn about them, and teach others about security and technology. But, while I get a lot out of this, there&#39;s one group of people I find incredibly draining to talk to: my corporate IT department. &lt;/p&gt;
&lt;p&gt;Just yesterday, I found myself being responded to in all-caps chat from a senior leader of that department when trying to ask questions about process. &amp;quot;&lt;strong&gt;HOW CAN I BE CLEARER?!&lt;/strong&gt;&amp;quot; was just one of the nice things he said while accusing me of trying to usurp him, subvert his authority, and so on. He was there to remind me that there was a pecking order in so many (aggressive) words. Hideous. &lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/the-it-industry-needs-a-toxic-masculinity-intervention/normal_6248a0c862389.gif&quot; alt=&quot;Reaction GIF of a man saying &amp;quot;The cheek, the nerve, the audacity, the gall and the gumption&amp;quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Same energy.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I respectfully declined to meet him at his level or attend his meetings where he could continue his abuse. Of course, this isn&#39;t the first time this group had exhibited this kind of toxic behavior, and I doubt it will be the last. Here&#39;s the shake: I could not shed the feeling of negativity about that day, and it followed me around through this weekend where I decided to write about it. &lt;/p&gt;
&lt;p&gt;As a gay man with many years of experience in this industry, I instantly recognized this experience as one of toxic masculine behavior manifesting itself in the form of bullying. I&#39;ve seen this throughout my career and increasingly so in roles of seniority. Assertive males in the workplace are beautifully summarized In Holly Althof&#39;s article detailing how Toxic Masculinity kills workplace culture published for SHRM, where she wrote:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&amp;quot;Toxic masculinity involves an ultra-competitive, dog-eat-dog work style that supports a patriarchal system designed to keep men on top. It encourages the mindset that outspoken men are assertive, while outspoken women are aggressive. Toxic masculinity is on display when men interrupt or talk over [people], take an inflexible attitude, and navigate the workplace like a battle zone to be conquered.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I&#39;d argue there&#39;s a cultural epidemic in the IT industry, hurting all of us. This epidemic has manifested as a toxic masculinity problem. We need to tackle it head-on to create inclusive and diverse workplace cultures where people can productively collaborate.&lt;/p&gt;
&lt;h3&gt;A brief introduction to toxic masculinity&lt;/h3&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/the-it-industry-needs-a-toxic-masculinity-intervention/normal_6248deb0e321d.png&quot; alt=&quot;Protest sign reading &amp;quot;You can be masculine without being toxic bro. #TruthToPower&amp;quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Yeah bro!&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;So, if you&#39;re not familiar, &amp;quot;Toxic Masculinity&amp;quot; is an umbrella term that encapsulates three related yet distinct concepts. The first refers to socially constructed norms and expectations of what it means to be a man. The second refers to culturally associated behaviors and practices that enforce these expectations. The third refers to how men are socialized into harmful versions of their gender. Toxic masculinity, in other words, describes masculine traits which are damaging to people regardless of gender. When we use terms like toxic or masculine interchangeably, we can perpetuate dangerous ideas about how all men act or behave, thus disregarding individuality and diverse experiences.&lt;/p&gt;
&lt;h3&gt;Toxic tech is burning out a burned-out workforce&lt;/h3&gt;
&lt;p&gt;It&#39;s not a stretch to conclude that technology workers are in high demand. Axios reporter Margaret McGill wrote last year that &amp;quot;Tech workers were in high demand pre-pandemic, and the COVID era&#39;s rapid moves to digital further intensified that need.&amp;quot; 2021 alone saw around 1,200,000 openings for technology workers. Retention of skilled technology workers is crucial to the success of projects, business operations, and a competitive edge. &lt;/p&gt;
&lt;p&gt;So it&#39;s not surprising that companies are willing to tolerate toxic cultures to retain hard-to-find talent. In 2017 the Kapor Center published their first-of-a-kind study on tech workers in which they surveyed 2,000 technology workers who left their jobs. Their studies found that a company culture like this created a sieve for underrepresented cultures. One person of color commented in the survey:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt; &lt;em&gt;I was offended by the liberal use of stereotypes and the insistence on making a &#39;welcoming culture&#39; that truly focused on only improving work life for a single demographic.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The study also found that these male-dominated cultures in tech resulted in 78% of the respondents were experiencing mistreatment. LGBTQ employees were the most likely to be bullied and experience public humiliation while at work. The study concluded that this toxic culture costs the industry 16 billion (with a B people!) dollars annually, even with conservative estimates. &lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/the-it-industry-needs-a-toxic-masculinity-intervention/normal_6248e1c609e2e.jpg&quot; alt=&quot;The Joker from The Dark Knight watching a huge pile of money burn&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Burning money like they&#39;re a supervillain in a fictional universe...&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;While retention of talent is a problem, so is developing promising talent. Burning out people means you lose not only some fantastic engineers but also everything they were capable of. The mental health impact alone could cause massive damage on an individual level and will most certainly drive valuable talent away from your company if it isn&#39;t dealt with. Honestly, couldn&#39;t we do better?&lt;/p&gt;
&lt;h3&gt;A Call to Action&lt;/h3&gt;
&lt;p&gt;If you&#39;ve ever worked in a toxic workplace environment that tolerates and allows bullies and machoism, you know how soul-crushing it can be. Your work suffers, and your quality of life erodes. When leadership enables and fosters the culture by retaining toxic employees, it unnecessarily strains employees who are already stretched too thin by unreasonable workloads and demanding deadlines.    &lt;/p&gt;
&lt;p&gt;Let me be clear about my take on this: If any organization is actually serious and committed to overcoming obstacles like racism, inequality, and social justice, they need to develop a zero-tolerance policy for bullies and this kind of toxic culture, no matter how. Organizations must make it clear to the workforce that business, as usual, is no longer acceptable. Enable them to understand that if they witness or become targets of abuse, they will have support systems, and remedies, available to them. Everyone will need to be on board with this, and we&#39;ll need to confront this cultural problem together.&lt;/p&gt;
&lt;h3&gt;What you can do&lt;/h3&gt;
&lt;p&gt;If you&#39;re currently being bullied, harassed, or abused in your work life, then there are some basic steps you can (and should) take to protect yourself.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1. Learn how to identify toxic traits&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;   Sometimes toxic people don&#39;t see themselves as bullies. They see their actions as playful or feel entitled to dominate others. Of course, whether or not a bullying situation is mainly subjective, but if someone feels privileged to be mean to you and doesn&#39;t seem motivated by anything other than power, you may need to take note.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Try to disengage&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;   Like my conversation I mentioned in my open paragraph - the best thing to do here is to disengage. Refuse to submit to whims and pressure from the harassers. Giving them power over you provides them what they want. Refuse to do so.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. Document the abusive behavior&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;   Human resources will thank you later if you need to establish that you&#39;re being harassed. Document this at length. Save e-mails, copy chats, and abusive IM conversations. Establish that there&#39;s a pattern, and as you do, document how it is effecting people like you.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4. Talk to peers about how you feel&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;   You&#39;re not alone, and your peers probably feel similar if they&#39;ve had to deal with abusive coworkers. Talk to your peers, share how you think, and develop unified coping strategies that defuse these people.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;5. Recognize your own shortcomings&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;     Toxic masculinity much like toxic sludge has a way of getting in everything and rosining people once it&#39;s been spilled. Recognize and understand where you can better yourself and ask yourself if you&#39;re adopting the better parts of the company culture or the worst. Cheesy but true, change starts with you.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;6. Keep your resume up to date&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;  Life is far too short of putting up with prolonged periods of abuse. If you&#39;ve tried to help improve company culture through self-advocation and don&#39;t have support from peers, or even worse, from HR, you need to remember something. In tech, there are a lot of opportunities. As previously outlined, 1,200,000 open jobs are waiting for you - and some of them are at companies with progressive cultures which might better align with your values.&lt;/p&gt;
&lt;h3&gt;So, in conclusion...&lt;/h3&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/the-it-industry-needs-a-toxic-masculinity-intervention/normal_6248e114cf3b9.png&quot; alt=&quot;Colorful sticker reading &amp;quot;I&#39;ve got 99 problems and white heteronormative patriarchy are basically all of them&amp;quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;I really need this sticker for my laptop.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Maybe it might be silly or a bit on the nose to insist on smashing the patriarchy to solve this problem. But if you&#39;re reading this and feel alone, stressed, or even bullied... take heart, take a breath, and remember to be kind to yourself. You&#39;re not alone. We can change this, but we need to hold the line and change the situation. Without action nothing will change.&lt;/p&gt;
&lt;p&gt;We got this.&lt;/p&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;References&lt;/strong&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;How Toxic Masculinity Is Ruining Your Workplace Culture, by Holly Althof: &lt;a href=&quot;https://www.shrm.org/hr-today/news/all-things-work/pages/how-toxic-masculinity-is-ruining-your-workplace-culture.aspx&quot;&gt;How Toxic Masculinity Is Ruining Your Workplace Culture (shrm.org)&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;Tech feels labor market crunch, by Margaret Harding McGill: &lt;a href=&quot;https://www.axios.com/tech-labor-market-software-engineering-jobs-2f5d8100-fe09-40ce-9cc4-33157fe0ae34.html&quot;&gt;Tech feels labor market crunch (axios.com)&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;Kapor Center Report Leavers: &lt;a href=&quot;http://www.kaporcenter.org/wp-content/uploads/2017/04/KAPOR_Tech-Leavers-17-0428.pdf&quot;&gt;KAPOR_Tech-Leavers-17-0428.pdf (kaporcenter.org)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content>
  </entry>
  <entry>
    <title>CVE-2021-22521 - The ZEN of Privilege Escalation</title>
    <link href="https://marbasec.com/blog/cve-2021-22521-the-zen-of-privilege-escalation/" />
    <updated>2021-07-25T00:00:00Z</updated>
    <id>https://marbasec.com/blog/cve-2021-22521-the-zen-of-privilege-escalation/</id>
    <content type="html">&lt;p&gt;&lt;strong&gt;DISCLAIMER: The content published here is the opinion of the person writing this, and that person alone.&lt;/strong&gt; &lt;/p&gt;
&lt;p&gt;Way back in February I came across a vulnerability in a Novell product (now Microfocus) called ZENworks. Generally, it&#39;s a really simple vulnerability and something I think a majority of security folks could find with a tiny bit of effort. In a nutshell, it&#39;s a privilege escalation which could allow an attacker to gain system level permissions on an impacted host through, essentially unquoted service path issue.&lt;/p&gt;
&lt;p&gt;First, if you don&#39;t know what an unquoted service path is, let&#39;s fill you in on that. When a Windows service is created, an executable path is always provided. Sometimes these paths can contains spaces, and if these paths are called by Windows with no quotes, it leads to a vulnerability known as an &#39;Unquoted Service Path&#39;. This can allow the attacker to assume the role of a service.  This works because when Windows creates new processes it will traverse the filesystem in a way which will automatically append an executable extension if a space is found in the path. So for example, if you had a program in C:&#92;Ice Cream&#92;Social Security Numbers&#92;myservice.exe, and a service was called to open that path without quotes, Windows would try the following:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;First: It would attempt to open C:&#92;Ice.exe&lt;/li&gt;
&lt;li&gt;Second: It would attempt to open C:&#92;Ice Cream&#92;Social.exe&lt;/li&gt;
&lt;li&gt;Third: It would attempt to open C:&#92;Ice Cream&#92;Social Security Numbers&#92;myservice.exe&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you as a user have the ability to write content in the root of C:&#92;, or in the C:&#92;Ice Cream folder, you could add an executable which would subvert the execution of your service. &lt;/p&gt;
&lt;p&gt;In our case, it wasn&#39;t the specific service that was vulnerable - it was the child processes in question here. Thinking back to our example, let&#39;s say our service was correctly called - but that service creates additional threads which Windows has to search for. Those threads are executed with the same permissions of the parent process. So it&#39;s important that those additional processes also must be called with quotations, or the child processes could be hijacked in the same way.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/cve-2021-22521-the-zen-of-privilege-escalation/2000_60fd6ab2ef2ec.png&quot; alt=&quot;Diagram of ZENworks service spawning quoted subprocesses that are fine and an unquoted one that is not&quot;&gt;&lt;/p&gt;
&lt;p&gt;Sensibly, Microfocus was alerted and a critical system issue was opened in their ticketing system, stating that they thought it was serious. Here&#39;s what they said:&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/cve-2021-22521-the-zen-of-privilege-escalation/normal_60fd61b72c45f.png&quot; alt=&quot;Microfocus ticket note acknowledging the issue is serious and should be simple to fix&quot;&gt;&lt;/p&gt;
&lt;p&gt;The organization I work for in my day job received a patch relatively quickly and Microfocus decided to leave other customers uninformed and without patches until the 21st of July, 2021. I&#39;ve been keeping my eyes out for a vulnerability disclosure since there&#39;s been mostly radio silence from the vendor on if customers would be informed. I really wasn&#39;t planning on writing anything about this issue until my google alert on this product and came across the following forum post on their website.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/cve-2021-22521-the-zen-of-privilege-escalation/2000_60fd6cea69603.png&quot; alt=&quot;Forum post from user mbobbitt asking for details on the ZCM privilege escalation patch&quot;&gt;&lt;/p&gt;
&lt;p&gt;I said to myself... cool, people got notified and are going to patch, great. It sucks that you need to specifically ask for a patch... but ok. What was really special is the what ZENworks support wrote in response to the question about the vulnerability disclosure.&lt;/p&gt;
&lt;p&gt;**&lt;img src=&quot;https://marbasec.com/images/blog/cve-2021-22521-the-zen-of-privilege-escalation/2000_60fd75d90ff75.png&quot; alt=&quot;Support reply claiming Windows would scream and call 911, advising against patching&quot;&gt;**Wow.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/cve-2021-22521-the-zen-of-privilege-escalation/normal_6248fc7599f54.gif&quot; alt=&quot;Animated GIF of a blonde-wigged drag queen giving a skeptical, unimpressed stare&quot;&gt;&lt;/p&gt;
&lt;p&gt;A few things to note, if you please, Microfocus support.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt; If you in fact, knew all about it, you would be slightly more informed.&lt;/li&gt;
&lt;li&gt;Windows doesn&#39;t call 911 in this kind of event (or ever actually). In the proof of concept we sent to engineers, we gave your company instructions which do in fact create a noticeable impact which would alert users. The bad guys your company will attract &lt;strong&gt;will not announce themselves like this if they aim to exploit your software.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Tools did not uncover this exploit, a manual review of the security of your software did, something I&#39;d suggest investing in. &lt;/li&gt;
&lt;li&gt;If my day job org wasn&#39;t concerned, why&#39;d they rush to patch? Maybe it had something to do with all of the supply chain attacks where management software (hello, Kaseya anyone?) are targeted by state actors and organized crime syndicates.&lt;/li&gt;
&lt;li&gt;All of this could have been known and your support agents could have been properly educated if you had bothered to reach out to and talk to the people who reported it.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;End of day, the cherry on top of all of this for me is that this product and general platform is often used in organizations all over the world to manage security patches.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/cve-2021-22521-the-zen-of-privilege-escalation/2000_60fd724a56990.png&quot; alt=&quot;ZENworks Patch Management marketing text describing automated patch delivery to endpoints&quot;&gt;&lt;/p&gt;
&lt;p&gt;This likely means it&#39;s installed and distributed to &lt;strong&gt;EVERY COMPUTER&lt;/strong&gt; on an impacted network to help mitigate security problems. Why in the world would Microfocus advise customers to not patch the product they sell to manage the installation and distribution of security patches?&lt;/p&gt;
&lt;p&gt;But yeah, don&#39;t install it. Windows will call 911. Great advice. &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Microfocus KB7025205: &lt;a href=&quot;https://support.microfocus.com/kb/doc.php?id=7025205&quot;&gt;Privileged Escalation Vulnerability (CVE-2021-22521) (microfocus.com)&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;Registered CVE: &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22521&quot;&gt;CVE - CVE-2021-22521 (mitre.org)&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;How to exploit this kind of vulnerability: &lt;a href=&quot;https://www.exploitblizzard.com/post/windows-privilege-escalation-exploiting-unquoted-service-path&quot;&gt;Windows Privilege Escalation - Exploiting Unquoted Service Path Vulnerability (exploitblizzard.com)&lt;/a&gt; &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>CVE-2021-32077 - Fun With Social Security Numbers</title>
    <link href="https://marbasec.com/blog/cve-2021-32077-fun-with-social-security-numbers/" />
    <updated>2021-05-06T00:00:00Z</updated>
    <id>https://marbasec.com/blog/cve-2021-32077-fun-with-social-security-numbers/</id>
    <content type="html">&lt;p&gt;In my day job I get a lot of time to spend with various software solutions which are meant to solve healthcare related problems with technology. It&#39;s fun, and it can be really surprising on how some software was designed and is continued to be used to accomplish daily tasks.&lt;/p&gt;
&lt;p&gt;Today, I&#39;ll be writing about CVE-2021-32077. It&#39;s a vulnerability I discovered while reviewing the security configuration of a credentialing website. It&#39;s a really simple vulnerability and I don&#39;t think I&#39;m breaking any new security research ground here. In healthcare, when employers of nurses, doctors, and other various healthcare workers need to have their credentials verified (ie, if they&#39;re licensed, what did they do, did they work for a hospital in the past, etc), they often turn to automated systems which can make this easy. One such piece of software is MSOW Solutions. This software is provided by VerityStream, or as they like to refer to themselves as &#39;your source of truth&#39;.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/cve-2021-32077-fun-with-social-security-numbers/2000_609496a98715e.png&quot; alt=&quot;VerityStream website homepage introducing CredentialStream for credentialing, enrollment, privileging, and evaluation&quot;&gt;&lt;/p&gt;
&lt;p&gt;MSOW consists of a few components, the one which drew my initial attention was the PSV or Primary Source Verification search. This module had the ability to query users by PII information such as date of birth and social security serial number. This feature is meant to be used by anyone on the internet who is looking to verify the credentials of a provider. &lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/cve-2021-32077-fun-with-social-security-numbers/2000_60943eb5ebd61.png&quot; alt=&quot;MSOW Primary Source Verification Search form with the last 4 digits of SSN field highlighted&quot;&gt;&lt;/p&gt;
&lt;p&gt;This internet facing component of MSOW&#39;s software inadvertently allows malicious users to query all employees in the company&#39;s database by their last name. Once obtained, a malicious user can target the discovery of the social security numbers by guessing possible numbers with automated fuzzing tools.&lt;/p&gt;
&lt;p&gt;You might be saying to yourself: &amp;quot;Oh the last four of my social security number isn&#39;t really a big deal&amp;quot;. &lt;/p&gt;
&lt;p&gt;But it kinda is. The last four of your social security number, often known as the social security serial number - it&#39;s the one unique component in your social security number which isn&#39;t predetermined by how you began your life in the United States. &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.ssa.gov/history/ssn/geocard.html&quot;&gt;According to the Social Security Administration (SSA)&lt;/a&gt; in the United States, the nine digit number consists of three distinct values, the area number, group number and serial number. &lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/cve-2021-32077-fun-with-social-security-numbers/2000_60945e9af13db.png&quot; alt=&quot;Sample Social Security card labeled with area number, group number, and serial number&quot;&gt;&lt;/p&gt;
&lt;p&gt;The area number and the group numbers are assigned to groups of people who are in a specific geographical areas in specific times. Now, social security numbers are no longer issued this way, &lt;a href=&quot;https://www.ssa.gov/employer/randomization.html&quot;&gt;but had been up until June 25th, 2011&lt;/a&gt;. While not failproof - typically armed with information such as a date of birth, name, and other details, &lt;a href=&quot;https://arstechnica.com/science/2009/07/social-insecurity-numbers-open-to-hacking/&quot;&gt;researchers have been able to construct algorithms&lt;/a&gt; which guess the first 6 digits of a person&#39;s social security number with a high rate of success, something they used to verify with online credit card applications. Yikes. &lt;/p&gt;
&lt;p&gt;The date of publishing this article is in 2021, meaning that every healthcare provider listed in these databases could likely have enough information siphoned off this way in order to commit fraud. (Unless of course if the provider is Doogie Howser and was born after 2011.)&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/cve-2021-32077-fun-with-social-security-numbers/2000_60946312bbd84.png&quot; alt=&quot;Young Doogie Howser in a white lab coat in front of X-ray light boxes&quot;&gt;&lt;/p&gt;
&lt;p&gt;There are of course, plenty of articles on data privacy and the horrors of having your social security serial number captured by a criminal - I won&#39;t link all those here, but in essence the last four can be used to apply for loans, utilize healthcare, perform various social engineering attacks, give you a bad day, and another reason to freeze your credit. &lt;/p&gt;
&lt;p&gt;Thankfully, I&#39;m writing this at the end of getting a coordinated disclosure for the vulnerability which the vendor patched (even though motivating them to do the right thing was as practical and easy as performing dental surgery on an elephant). I needed to get &lt;a href=&quot;https://kb.cert.org/&quot;&gt;CERT&lt;/a&gt; involved and I used &lt;a href=&quot;https://kb.cert.org/vince/&quot;&gt;their brilliant VINCE system&lt;/a&gt; (which I&#39;ll write about in a separate post) which helped make the vendor accountable for their software. &lt;/p&gt;
&lt;p&gt;This was the final communication to customers which they mulled on sending to customers for almost two months after the patch was ready to go. &lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/cve-2021-32077-fun-with-social-security-numbers/2000_6094671ac0b14.png&quot; alt=&quot;VerityStream client notification letter about the MSOW PSV vulnerability patch, signed by the president&quot;&gt;&lt;/p&gt;
&lt;p&gt;Michael, it does feel a little disingenuous seeing that you had a fix for almost two months and you chose not to inform your customers as quickly as you could. So I&#39;m a little disappointed here when you claim that &#39;the safety of your data is our priority&#39;. &lt;/p&gt;
&lt;p&gt;VerityStream reached out and patched their customers using MSOW on April 29th, 2021... hopefully closing the loop in a uncomplicated yet serious problem in a healthcare vendor&#39;s software.&lt;/p&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>Your passwords are up for grabs. Here&#39;s how security researchers find them.</title>
    <link href="https://marbasec.com/blog/your-passwords-are-up-for-grabs-here-s-how-security-researchers-find-them/" />
    <updated>2019-02-12T00:00:00Z</updated>
    <id>https://marbasec.com/blog/your-passwords-are-up-for-grabs-here-s-how-security-researchers-find-them/</id>
    <content type="html">&lt;p&gt;&lt;strong&gt;Note: These methods do not work any longer due to the site referenced being taken down.&lt;/strong&gt; &lt;/p&gt;
&lt;p&gt;In January 2019, over 770 million password and username records were dumped onto the internet. The common security response to any new data dump is to use the very popular &#39;have i been pwned?&#39; service. This awesome service can tell you if you&#39;re impacted by breaches like these, and will advise to change your password when it detects that an account linked to your e-mail address has leaked.&lt;/p&gt;
&lt;p&gt;Criminals and security researchers might turn to this service to determine if a data dump should be scoured for credentials, but doesn&#39;t provide the actual credentials. We think that it&#39;s best to know the impact of your exposure by directly querying the sources criminals and security researches use. Knowing what the hackers know, or how common a password might be is really helpful in constructing useful mitigation solutions.&lt;/p&gt;
&lt;p&gt;In the field of information security, there&#39;s always new and interesting tools popping up on the the internet, and we wanted to share a simple tool which was recently built by David Tavarez which can automate the retrieval of leaked credentials. This tool is named named &lt;a href=&quot;https://github.com/davidtavarez/pwndb&quot;&gt;pwndb.py&lt;/a&gt; and once installed, and you&#39;re connected to a TOR network (details in the link), you can query leaked data via cli. Let&#39;s check out the help;&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;$ python pwndb.py -h

usage: pwndb.py [-h] [--target TARGET] [--list LIST] [--output OUTPUT]

optional arguments:
  -h, --help       show this help message and exit
  --target TARGET  Target email/domain to search for leaks.
  --list LIST      A list of emails in a file to search for leaks.
  --output OUTPUT  Return results as json/txt
  --tor TOR        Define port running tor
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;We can pass in a few arguments. Let&#39;s say we just want to search for any password associated with the commonly faked e-mail address, 123@abc.com. (Passwords are masked in this image)&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/your-passwords-are-up-for-grabs-here-s-how-security-researchers-find-them/2000_5c634cfcea7b8.png&quot; alt=&quot;Terminal output of pwndb.py searching 123@abc.com, listing leaked credentials with passwords masked&quot;&gt;&lt;/p&gt;
&lt;p&gt;We can also search by domain. Let&#39;s say I want to review the passwords for all e-mail addresses associated with the abc.com domain. (Passwords are also masked in this image)&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://marbasec.com/images/blog/your-passwords-are-up-for-grabs-here-s-how-security-researchers-find-them/2000_5c634d1b5b2bc.png&quot; alt=&quot;Terminal output of pwndb.py searching the abc.com domain, listing leaked accounts with passwords masked&quot;&gt;&lt;/p&gt;
&lt;p&gt;You can even pass through a list, especially useful when an organization might have several domains that need to be reviewed. You can check out helpful examples over at David&#39;s blog: &lt;a href=&quot;https://davidtavarez.github.io&quot;&gt;https://davidtavarez.github.io&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Check out your risk exposure by testing your own e-mail address. The hackers are, shouldn&#39;t you?&lt;/p&gt;
&lt;p&gt;-Marbaṩ&lt;/p&gt;
</content>
  </entry>
</feed>