Totally Pwning the Tapplock Smart Lock (the API way)tl:dr: Tapplocks api endpoints had no security checks other than a valid token to access any data.This results in anyone with a valid login…Jun 15, 20181Jun 15, 20181
Remote smart car hacking with just a phone.tl;dr: Calamp which provides the backend for a lot of really well known car alarm systems had a misconfigured reporting server that gave…May 12, 2018May 12, 2018
I spy with my little eye... #hakvisiontl;dr: Hikvisions cloud services (hik-connect.com) rely on a cookie value to determine with what user you are logged in.Changing the user…Apr 24, 20182Apr 24, 20182
Row, row, row your boat: Pwning ship’s VSAT for fun and profit.Some background:Feb 15, 2018Feb 15, 2018