Hidden Comcast Modem User

by illwill

Monday, February 7th, 2011 at 3:18 pm

Seems Comcast has a hidden admin user account on their business class modems other than the usual user:cusadmin-pw:highspeed. You can log in locally using the username mso and password: D0nt4g3tme . Furthermore you can also use Cross Site Request Forgery in iframes to set the modem to open up its remote admin ports to all IP’s not just the ones Comcast has preconfigured. If you wanna test this out you can visit this URL http://illmob.org/comcast BEWARE, if you are on vulnerable Comcast modem it will open remote access to your modem on http port 80, https port 8181 and telnet 2323.

Props to the guys @ Trustwave for the iframe POC.

Stuxnet exploit code released

by illwill

Thursday, January 13th, 2011 at 11:54 am

Used by Stuxnet to escalate privs in win2k and XP Explanation of the code ::here:: and source code ::here::

Free at last! Free at last! Thank God Almighty, I am free at last.

by illwill

Tuesday, January 4th, 2011 at 8:53 pm

Thats right bitches, after 6 long retarded years being under the government’s thumb for some bullshit charges ,I am finally a free man!!!!

Your IP: 172.70.127.8
Hostname: 172.70.127.8

You are from the area.

We love our country, but fear our government.