After releasing the triangular arbitrage trading bot Harjus under MIT license and publishing a write-up on my journey last year, I took a brief stint of working on other stuff. However, I was constantly feeling that I had given up too early, when there were still major optimizations that could be enough to turn a profit. My previous write-up had caught the eye of multiple aspirational arbitrageurs…
Note Read also the writeup on latest Harjus release. The idea of turning on a program and just letting it rip while collecting (riskless) money is compelling. No sales or marketing, or other things I, as an engineer, like to shy away from doing - just enjoyable tinkering with models and infra. That’s printing money. To have a go at money printing, I built a trading bot. The bot is called…
Nmap has been my favorite hacking tool for years. Its accuracy is unchallenged and it boasts hundreds of scripts that make it vital in every pentest engagement. Lately, I’ve been working more on the ICS space, developing a OPC UA vulnerability scanner. To my dismay, I noticed that Nmap does not recognize OPC UA services. This makes black box security testing of this dominating ICS protocol…
I don’t know what it tells about me, but I have a soft spot for prank calls. My guilty pleasure is listening to the prank call show Phone Losers of America. In the show, the host Brad calls up unsuspecting people with bizarre stories to get a reaction out of them. He’s done it for decades, which you can tell from his ability of giving his victims a hard time on the phone while…
DALL-E’s take on “A scary person holding rotten onion” In 2018, I read about the perfect crime of stealing the money of credit card fraudsters by making fake carding sites. At the time, this felt genius to me; the attackers were apparently making a decent living while nobody was presumably coming after them. (Except maybe now someone will, as they got Krebs’d by Brian).…
Remember UPnProxy? Flawed implementations of UPnP allow external attackers to use devices as proxies without any authentication. Such devices are vulnerable to UPnProxy. Various malicious actors have been using this vulnerability to commit crimes. During penetration tests, I have multiple times encountered such devices on the public IP address space of the clients. No suitable tooling exists to…
While listening to Risky Business ep. 642, I learned about a botnet that has been abusing a vulnerability in TP-Link routers to provide SMS messaging as a service for years. The exploited vulnerability allowed the botnet operator to send SMS messages on someone else’s bill and the operator sold this capability for others, including other criminals. Similar services are no doubt used when you…
DNS Zone Transfer is a mechanism for administrators to replicate DNS datasets across DNS servers. If it is enabled for a DNS nameserver, the nameserver will gladly give all DNS data regarding a domain to anyone who asks. Enabling Zone Transfers will cause an information disclosure and can thus be considered misconfiguration. I decided to investigate how common this nameserver misconfiguration is…
What kind of systems are there in the Finnish telephone network today? This question appeared to me a while ago when leafing through an old telephone directory from the early 2000s. There are at least ordinary subscribers, business customer support lines, voice mails, and fax machines. Subscribers and customer support lines are not of special interest to me. I am more interested in automated…
I got interested in telephones and the Voice Over IP (VOIP) scene soon after reading Phil Lapsley’s Exploding the phone (2013). According to the book, there is a whole underground of VOIP hackers. I had not come across them while lurking in the information security scene. After my interest sparked, I started paying more attention to telephone-related security research. The podcast Darknet…
Me Hi! My name is Valtteri. I’m a hacker. I love to apply knowledge across domains and spend much of my limited freetime trying novel things on a computer. Some of those experiments end up here as writeups. Beyond my love for computers and security, I enjoy books, board games, trekking, and fishing. I work as a Senior Security Engineer at Konecranes. Previously, I worked as a freelancer and…