Post B4ObtV1hfIQFr95H4y by wolf480pl@mstdn.io
 (DIR) More posts by wolf480pl@mstdn.io
 (DIR) Post #B4OZJ9jv8EQhVFJChk by algernon@come-from.mad-scientist.club
       0 likes, 0 repeats
       
       Heh. Hehehe. Oh dear.algernon wipes a tearOh dear, what do we have here. Vulnerability hunting the crawlers is surprisingly fun. Lets plant a nice little surprise here.Tehehehehe.
       
 (DIR) Post #B4OZJ9wgMmdc8pHOb2 by algernon@come-from.mad-scientist.club
       0 likes, 0 repeats
       
       Casual reminder to the crawlers: do not fuck with the mouse. He's not a nice person. He's especially not nice when in a foul mood1.I am in a foul mood. ↩︎
       
 (DIR) Post #B4OZJA7fhvQcguQAj2 by algernon@come-from.mad-scientist.club
       0 likes, 0 repeats
       
       Before anyone asks: no crimes are being committed, no exploit will be shared. It's all just... :sparkles_light: fantasy :sparkles_light:.algernon nods sagely(But PS: Still, don't fuck with the mouse. It's not nice.)
       
 (DIR) Post #B4OZJAIJ4Nw3DtOfIm by algernon@come-from.mad-scientist.club
       0 likes, 0 repeats
       
       Purely for a thought experiment, lets imagine a crawler that's running off a remote controlled, possibly malware infected device. Lets also suppose that the crawler software itself is not vulnerable - but the device it infected, is.What if we could access that device? What if we could... I dunno... disable the crawler, and patch the hole it came through?What if we could disable the applications that host the crawler "service"? Or if not disable outright, guide them into a state where they don't start, and need to be not only reinstalled, but their data wiped first?Imagine the possibilities! What if this would allow us to alert the - probably unsuspecting - owner of the device that their device is being abused?That's an interesting thought experiment, I think.
       
 (DIR) Post #B4OZJASaSA9tjmCsKG by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @algernon sounds like a nice sequel to the Mirai vs Brickerbot story
       
 (DIR) Post #B4OZh98T1sc8ZzEIue by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @algernon though you know what would be even better in that hypothetical scenario?finding the C&C server that commands these botsfinding out how the botnet spreadsfinding the website that sells the proxy services that run on them
       
 (DIR) Post #B4ObtUcBCC0QZz8tIO by algernon@come-from.mad-scientist.club
       0 likes, 0 repeats
       
       @wolf480plinnocent whistles
       
 (DIR) Post #B4ObtUrQHWCPLGH43U by starchturrets@mastodon.social
       0 likes, 0 repeats
       
       @algernon @wolf480pl https://lobste.rs/s/pmfuza/bro_ban_me_at_ip_level_if_you_don_t_like_me#c_hzq0yphttps://lobste.rs/s/rvsica/you_should_feed_bots#c_erbjsv
       
 (DIR) Post #B4ObtV1hfIQFr95H4y by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @starchturrets @algernon I think it's quite possible there VPN apps are not the only way these botnets are made.