Jump to content
Security Installer Community

cybergibbons

Member
  • Posts

    498
  • Joined

  • Last visited

  • Days Won

    7

Posts posted by cybergibbons

  1. How about Alarming Company or Wakefield Security?

     

    Fareham and Worthing? Both there.

    CG

    what is pentested?

    and whats the report on?

     

    Pentested means penentration testing, i.e. you get someone who knows how to hack to have a crack at your systems. I'd argue that even ARCs should be having them done (I've done a few now, and found a lot of problems, most easily fixed), but signalling providers with centralised receiving, like CSL and WebWayOne, should definitely be pentested.

    The report is about the encryption and general security of the CSL CS2300 signalling units.

  2. I think there banning the browser id ? 

     

    I've not clicked a link to get the 403 page with IE (yet)

     

    attachicon.gifbanned.jpg

     

    chrome, opera & not yet banned with IE

     

    Ah, yes, sorry. The User-Agent is one of the factors they use, which is pretty stupid.

    I meant how come it was showing in search results?

  3. Should you wish to register...

     

    IIRC it asks you if your co is already registered, 

    I clicked yes & select postcode of a local co.

    & it shows you who at that co, is already signed up

     

    Yes - IMO it still leaks data that it shouldn't. The problem was before it used to send the client all of the data in the background. You couldn't see it in the plain, but it was sent.

    There's only a few options here:

    1. They haven't been pentested. You'd kind of think the biggest signalling provider in the UK would do it.

    2. They have been pentested by someone incompetent. If they gave money to the people who developed apprentices4fs.com, this is plausible.

    3. They have been pentested and ignored all of the findings.

    Who knows?

    FYI, on the 23rd November, the CSL Dualcom CS2300 report is being published.

  4. On 1st May this year, I found it was possible to dump the names, addresses, emails, usernames, and phone numbers of every single user of every single company who had registered on the CSL M2M SIM page. I did not push the investigation any further, but worse may have been visible.

     

    http://cybergibbons.com/alarms-2/customer-database-leak-on-csl-dualcoms-sim-registration-portal/

     

    If you would like to know if your company was one of the listed ones, I can check for you.

  5. they appear to have banned my IP by following your link?

    If I type "apprentice for security" into google 1st pags 1/2 down is london add,home IP bring up banned page

    **edit**

    must be cookie, as iphone on home IP displays page?

     

    Can you screenshot it and blank out the IP? Interested to work out why that happened.

    Surely it's pretty libellous leaving a page up listing someone's IP and saying they are some elite hacker.

  6. To be honest, if you are using common forum software, and anything custom was developed with a framework, or by a develop with any skill, you won't have these issues.

     

    It's actually like they have gone out of their way to make it bad.

     

    Happy to have a quick look over your stuff in the future, will need to send over a rules of engagement to legally cover us both. Much better to go into a touch more depth with some active attacks.

  7. is it the worst one you have seen generally or just in the 'security' world?

     

    It's the worst site I have seen that handles any more personal than email/password/forum posts. I've seen worse content management systems, but no one elses data has been put at risk.

     

    This has been purely observation of normal behaviour on the site. If it was taken to active attacks, god knows what would be found.

  8. should be careful giving them out as when employed by a company you sign a contract that would include some form of non disclosure. However any company that no longer maintains a system should be forced to default the engineers code or supply it to the new maintainer in my opinion.

     

    Problem with that is that there is not traceability or accountability on a 4 digit code.

  9. 9800 or 9800+ if showing 'LB'

     

    I wonder if the power cut has cooked the NVM chip itself, a common fault at this age on the panel.

     

    Try a complete power cycle, mains first then battery, and let us know. Beware of mains voltage if not a trained alarm technician or electrician.

     

    But I would recommend replacement with a 9651, although new NVM chips are still available (despite their obsolescence within the wider IC industry)

     

    Has someone stockpiled these? I can't remember the specific IC used, but it's not been made since 1996 or something.

  10. If you were the owner of a national company say and your code was being dished around publicly on a Facebook group, what would your response be??

     

    I might have a bit of a think and wonder why every single panel I installed had the same engineer's code, and how I have no response plan if it got leaked.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.