Scanning the internet with Lucas Lundgren

05/07/2022 58 min Temporada 1 Episodio 9

Listen "Scanning the internet with Lucas Lundgren"

Episode Synopsis

In this episode of Hacker Talk, we are joined by
Lucas Lundgren, is an impressive penetration tester, security researcher, and our Hacker of honor today.
Lucas is known for going out on the internet and finding interesting internet-facing protocols, he has found several internet-facing critical infrastructures, prison door systems, medical x-ray file storage servers(Pacs), earthquake systems, and a lot more! 


In this episode we cover the following topics: 
Journey into hacking, radio, commodore64, Amiga 500, cracking games
Time bomb viruses for Amiga 500 games
Finding vulnerabilities, getting invited to conferences to speak at 13
War dialing Amiga 500, phone phreaking with modern
Learning lock picking 
building your own port scanner
Scanning the entire internet with Masscan from home with a 10gigabit connection 
Parsing scan results with elastic search, grep, kibana
Mqtt - embedded protocol, finding and opening prison doors with MQTT, 
Malware with MQTT brokers
Opening and closing doors in prisons in the UK
Atm's with MQTT
Changing oil pipelines pressure with
Finding protocols to scan the internet for 
iscsi
Hacking x-ray machines
Finding hospitals x-ray records in Pax servers  dating back to 1985
Problems with hospitals' x-ray storage servers 

Reporting security vulnerabilities
Editing x-ray pictures, 
Malware that adds black spots on the pictures and reuploads it.
Malware in metadata of the x-ray pictures 
X-ray malware in the wild
Image recognition 
Making fictional earthquakes
Remote code execution on doorbells
Hack-rf, software-defined radio
Wardriving
Hacking radio
Iridium
Weather satellites 
Hacking satellites 
Breaking into a gas pump with wooden straws
Physical penetration testing


Links: 
https://github.com/robertdavidgraham/masscan 
https://en.wikipedia.org/wiki/MQTT
https://www.elastic.co/kibana
https://en.wikipedia.org/wiki/Picture_archiving_and_communication_system 
https://www.youtube.com/watch?v=o7qDVZr0t2c
https://en.wikipedia.org/wiki/Barnaby_Jack
https://www.iridium.com/
https://hack.cysat.eu/
Skullkeysecurity.com 
https://twitter.com/Acidgen