User Controls
Posts by Laserbeams
-
2017-06-30 at 8:37 AM UTC in TV will break your mind like it did to mineI was sitting there minding my own business
and it took form as special effects. bright
red glowing eyes flashing like that one
simpsons episode.
I broke down and ripped apart all my
electronics except for this old laptop.
Internal Combustion engines are starting to
give me headaches.... -
2017-06-27 at 10:31 PM UTC in Deleted posts for: LaserbeamsQUIT SHOOTING ME WITH LASER BEAMS RIGHT NOW!!!!!! THEY MELLT THE FILLINGS IN YOUR TEEETH!!!!
-
2017-06-27 at 9:46 PM UTC in Deleted posts for: Laserbeamsthey killed my dog with laserbeams :(
-
2017-06-27 at 9:45 PM UTC in Deleted posts for: Laserbeams
-
2017-06-27 at 9:44 PM UTC in Deleted posts for: Laserbeams
-
2017-06-27 at 7:26 AM UTC in Deleted posts for: Laserbeams
-
2017-06-27 at 7:23 AM UTC in Deleted posts for: LaserbeamsIs this about LASERS?
-
2017-06-27 at 7:18 AM UTC in Deleted posts for: Laserbeams
Originally posted by -SpectraL https://www.theregister.co.uk/2017/05/05/intel_amt_remote_exploit/
Code dive You can remotely commandeer and control computers that use vulnerable Intel chipsets by sending them empty authentication strings.
You read that right. When you're expected to send a password hash, you send zero bytes. Nothing. Nada. And you'll be rewarded with powerful low-level access to a vulnerable box's hardware from across the network – or across the internet if the management interface faces the public web.
Remember that the next time Intel, a $180bn international semiconductor giant, talks about how important it treats security.
To recap: Intel provides a remote management toolkit called AMT for its business and enterprise-friendly processors; this software is part of Chipzilla's vPro suite and runs at the firmware level, below and out of sight of Windows, Linux, or whatever operating system you're using. The code runs on Intel's Management Engine, a tiny secret computer within your computer that has full control of the hardware and talks directly to the network port, allowing a device to be remotely controlled regardless of whatever OS and applications are running, or not, above it.
Thus, AMT is designed to allow IT admins to remotely log into the guts of computers so they can reboot a knackered machine, repair and tweak the operating system, install a new OS, access a virtual serial console, or gain full-blown remote desktop access via VNC. It is, essentially, god mode.
Normally, AMT is password protected. This week it emerged this authentication can be bypassed, potentially allowing miscreants to take over systems from afar or once inside a corporate network. This critical security bug was designated CVE-2017-5689. While Intel has patched its code, people have to pester their hardware suppliers for the necessary updates before they can be installed.
Today we've learned it is trivial to exploit this flaw, allowing anyone to gain control of vulnerable systems without a password.
AMT is accessed over the network via a bog-standard web interface: the service listens on ports 16992 and 16993. Visiting this with a browser brings up a prompt for a password, and this passphrase is sent using standard HTTP Digest authentication: the username and password are hashed using a nonce from the AMT firmware plus a few other bits of metadata. This scrambled response is checked by the AMT software to be valid, and if so, access is granted to the management interface.
But if you send an empty response, the firmware is fooled into thinking this is correct and lets you through. This means if you use a proxy to change the response to an empty string, or otherwise set up your browser to send empty HTTP Digest authentication responses, you can bypass the password checks.
Essentially, behind the scenes, your browser would normally send something like this to the AMT service, which includes the hashed response string containing the username, password and server nonce:
GET /index.htm HTTP/1.1
Host: 192.168.1.2:16992
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101
Firefox/45.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://192.168.1.2:16992/logon.htm
Connection: keep-alive
Authorization: Digest username=»admin»,
realm=»Digest:048A0000000000000000000000000000»,
nonce=»Q0UGAAQEAAAV4M4iGF4+Ni5ZafuMWy9J», uri=»/index.htm»,
response=»d3d4914a43454b159a3fa6f5a91d801d», qop=auth, nc=00000001,
cnonce=»9c5beca4011eea5c»
WHO TOLD YOU ABOUT THE LASER BEAMS!!!!!!????? YOUR NAME KEEPS COMING UP :"SPECTRAL" -
2017-06-27 at 7:03 AM UTC in Deleted posts for: Laserbeams
-
2017-06-27 at 7:01 AM UTC in Deleted posts for: Laserbeams
-
2017-06-27 at 7 AM UTC in Deleted posts for: Laserbeams
-
2017-06-27 at 6:58 AM UTC in Deleted posts for: LaserbeamsIt'S THE LASERS IM TELLING YOU!!! THEY WILL GET YOU WHEN YOU LEASSSRTTTT HEXPECT UT!!
-
2017-06-24 at 6:59 PM UTC in Deleted posts for: Laserbeamsfather son and holy ghost i would not spread that on my toast for the kiazer would be wizer ill wack a mizer.
LASER BEAM VERSE!!!! SENT SOME FROM SPACEW!!!!! -
2017-06-24 at 6:55 PM UTC in Deleted posts for: LaserbeamsWATCH OUT FOR THE LASER BEAASAAAAMMMSS@!@@@@@ !!! THEY WILL MAKE YOU NOT WANT TO DIE BUT TO KILL ALL LIVING LIFE IN THE UNIVERSE. THE LASERS CHOSE ME TO END IT ALL!!!!!! I WANT TO KILL YOU NEXT!!!! AHHSHHSHHHHH THE LASERS!@!!! AMHH MAKE ITY STOP PLEASEEEEE
-
2017-06-24 at 6:54 PM UTC in Deleted posts for: LaserbeamsAll sexual deviations and rapists, murderers, MKultra CIA are caused by the MALICIOUS Laserbeams! they wrecked every aspect of my life. I cant eat.
Haven't slept in days... CONSTANT HEADACHE CANT BE NEAR LIGHT
CANT LEAVE HOUSE
Sometimes I think its all in my head.. then I realize THATS EXACTLY WHERE THEY AIM THE WHERE (what are they doing?)
LASER BEAMING ME IN THE FUCKING HEAD!!! -
2017-06-22 at 8:53 PM UTC in Deleted posts for: LaserbeamsIf you stay out in the open they can hit you with the laser beam emitter easier.
-
2017-06-22 at 8:52 PM UTC in Deleted posts for: LaserbeamsiTS BECAUSE OF THE FUCKING LASER BEAMS!!!!
Thanks to THEM they can shoot me in the head and project all my thoughts onto the minds of those arrouund me.
One time at a public gathering I was struck and everyone turned their heads and stared at me. THey knew all the things I had done ever since childhood. I could just feel the hate and then I collapsed from being laser beamed too much and people thought I was one drugs. -
2017-06-22 at 8:49 PM UTC in Deleted posts for: LaserbeamsWHAT THE FUCK I HAVE THE EXACT SAME THING LODGED IN MY EYE SOCKET AND IT WILLLLL NOOTTT COME OUT!!!!!
IT FUCKING HURTS BRO.
I HAVE BEEN SCREAMING IN PAIN AND BEGGING THEM TO JUST FUCKING KILL ME BUT THEY WONT
THEY JUST TURNED THE LASER BEAMS UP I CAN BARELY THINK AHHHHHHHHH!!!!! -
2017-06-19 at 2:21 PM UTC in Ow my head
-
2017-06-19 at 2:21 PM UTC in Deleted posts for: LaserbeamsI wonder when these women will stop SHOOTING LASERBEAMS IN MY FUCKING HEAD ZZZZZZZZAzzaaaapp OUCH!!