RSSAmplifier

Blog

Valtteri Lehtinen

Recent content on Valtteri Lehtinen

shufflingbytes.comRSS feed ↗11 posts

Latest posts

Harjus v4 adds kernel bypass and more

After releasing the triangular arbitrage trading bot Harjus under MIT license and publishing a write-up on my journey last year, I took a brief stint of working on other stuff. However, I was constantly feeling that I had given up too early, when there were still major optimizations that could be enough to turn a profit. My previous write-up had caught the eye of multiple aspirational arbitrageurs…

Harjus: Triangular Arbitrage Bot for Binance

Note Read also the writeup on latest Harjus release. The idea of turning on a program and just letting it rip while collecting (riskless) money is compelling. No sales or marketing, or other things I, as an engineer, like to shy away from doing - just enjoyable tinkering with models and infra. That’s printing money. To have a go at money printing, I built a trading bot. The bot is called…

How to Make Nmap Recognize New Services

Nmap has been my favorite hacking tool for years. Its accuracy is unchallenged and it boasts hundreds of scripts that make it vital in every pentest engagement. Lately, I’ve been working more on the ICS space, developing a OPC UA vulnerability scanner. To my dismay, I noticed that Nmap does not recognize OPC UA services. This makes black box security testing of this dominating ICS protocol…

InmateBridge: Voice Bridge for Prank Calling

I don’t know what it tells about me, but I have a soft spot for prank calls. My guilty pleasure is listening to the prank call show Phone Losers of America. In the show, the host Brad calls up unsuspecting people with bizarre stories to get a reaction out of them. He’s done it for decades, which you can tell from his ability of giving his victims a hard time on the phone while…

Ripping Off Professional Criminals by Fermenting Onions

DALL-E’s take on “A scary person holding rotten onion” In 2018, I read about the perfect crime of stealing the money of credit card fraudsters by making fake carding sites. At the time, this felt genius to me; the attackers were apparently making a decent living while nobody was presumably coming after them. (Except maybe now someone will, as they got Krebs’d by Brian).…

UPnProxyChain: a Tool to Exploit Devices Vulnerable to UPnProxy

Remember UPnProxy? Flawed implementations of UPnP allow external attackers to use devices as proxies without any authentication. Such devices are vulnerable to UPnProxy. Various malicious actors have been using this vulnerability to commit crimes. During penetration tests, I have multiple times encountered such devices on the public IP address space of the clients. No suitable tooling exists to…

GoIP-1 GSM gateway could be harnessed for phone fraud by hackers

While listening to Risky Business ep. 642, I learned about a botnet that has been abusing a vulnerability in TP-Link routers to provide SMS messaging as a service for years. The exploited vulnerability allowed the botnet operator to send SMS messages on someone else’s bill and the operator sold this capability for others, including other criminals. Similar services are no doubt used when you…

DNS records of 1% .fi domains exposed through Zone Transfers

DNS Zone Transfer is a mechanism for administrators to replicate DNS datasets across DNS servers. If it is enabled for a DNS nameserver, the nameserver will gladly give all DNS data regarding a domain to anyone who asks. Enabling Zone Transfers will cause an information disclosure and can thus be considered misconfiguration. I decided to investigate how common this nameserver misconfiguration is…

I made 56874 calls to explore the telephone network. Here's what I found

What kind of systems are there in the Finnish telephone network today? This question appeared to me a while ago when leafing through an old telephone directory from the early 2000s. There are at least ordinary subscribers, business customer support lines, voice mails, and fax machines. Subscribers and customer support lines are not of special interest to me. I am more interested in automated…

What I learned of the VOIP hacker scene by setting up a SIP Honeypot

I got interested in telephones and the Voice Over IP (VOIP) scene soon after reading Phil Lapsley’s Exploding the phone (2013). According to the book, there is a whole underground of VOIP hackers. I had not come across them while lurking in the information security scene. After my interest sparked, I started paying more attention to telephone-related security research. The podcast Darknet…

About

Me Hi! My name is Valtteri. I’m a hacker. I love to apply knowledge across domains and spend much of my limited freetime trying novel things on a computer. Some of those experiments end up here as writeups. Beyond my love for computers and security, I enjoy books, board games, trekking, and fishing. I work as a Senior Security Engineer at Konecranes. Previously, I worked as a freelancer and…