Why the reddit tracking link?
𞋴𝛂𝛋𝛆
- 6 Posts
- 12 Comments
The easiest way I know of to check any machine is to put another router or machine in front of it with a white list firewall or way of logging DNS traffic. You just need to spot the address in the list.
DNS filtering usually only filters on incoming packets, but for bot stuff that should catch issues.
In general, most routers run everything from a serial flash chip on the board. These are usually 8, 16, or 32 megabytes. They have a simple bootloader like U-Boot. This is what loads the operating system. These devices have a UART serial port on the PCB. You can use a USB to serial UART adaptor to see what is happening in the device. With a proprietary OS, you are still likely to see the pre-init boot sequence that the bootloader prints to terminal. Most operating systems also print information to this interface, at least of the couple dozen junk devices I have been given and messed around with. I make a little mount for a USB to serial adaptor and add it to all of my routers when new, so I only need to plug in USB to get to the internal bootloader and tty terminal interface of OpenWRT. You will need to know the default baud rate of the device, although it is probably listed somewhere online or can be guessed as one of the common high values at or above 9600.
Getting into this further gets complicated. It is probably better to look for any CVE that is relevant to the device or software and work backwards. Look for any software updates that have obfuscated the risk for each CVE. If the issue was not fixed, that is where to look to see if someone has exploited the device. Ultimately, they need clock cycles from the CPU scheduler. So it must be a process or some way of executing code from unregistered memory.
This is getting to the edge of what I have messed around with and understand. There may be a way to get a memory map that includes unused pages, and compare that with a hex dump of the flash memory. This is outside of your scope of a proprietary OS, but hopefully frames the abstract scope of what is possible on this class of device when you have an open source stack. The main advantage of this kind of device and issue is that you can physically remove the flash chip and then see and manipulate every page and memory location. The device likely doesn’t have microcode loaded into the CPU(s) that make it challenging to determine what is going on.
There is probably an easier way, but a hex dump of the current system can be hashed against the factory updated version to see if any differences are present. It is likely that any exploit will include a string with the address to connect to somewhere in flash memory. It could be obfuscated through encryption or a cypher, but a simple check for strings in the hex dump and a grep for “http” is a simple way to looks for issues.
The OpenWRT forum is a good general source. The people behind the bootloaders for these devices are also Linux kernel developers and on the OpenWRT forum.
𞋴𝛂𝛋𝛆@lemmy.worldto
Showerthoughts@lemmy.world•Expecting a LLM to become conscious, is like expecting a painting to become aliveEnglish
2·6 days agoThe first life did not possess a sentient consciousness. Yet here you are reading this now. No one even tried to direct that. Quite the opposite, everything has been trying to kill you from the very start.
𞋴𝛂𝛋𝛆@lemmy.worldto
Linux@lemmy.ml•An update on the move from one motherboard to another.English
6·10 days agoAny UEFI secure boot enabled distro will remove all boot entries without a valid package key or a shim to a valid key.
Glad you got it working.
𞋴𝛂𝛋𝛆@lemmy.worldto
politics @lemmy.world•Internet erupts as MAGA influencers exposed for being based in other countriesEnglish
7·16 days agoBillionaires. Governments are small pawns.
𞋴𝛂𝛋𝛆@lemmy.worldto
politics @lemmy.world•Internet erupts as MAGA influencers exposed for being based in other countriesEnglish
1·16 days agoThought he bubba babyin Bill?
𞋴𝛂𝛋𝛆@lemmy.worldto
politics @lemmy.world•Rep. Marjorie Taylor Greene says she's received threats amid deepening feud with TrumpEnglish
3·23 days agoIf the redneck psycho of Rome was not getting death threats at any point in her political asylum jaunt, I would be very surprised.
HONK (smoke pours out of beak)
🐉≝🔥🪿
𞋴𝛂𝛋𝛆@lemmy.worldtoUnited States | News & Politics@midwest.social•Michael Burry is sounding an alarm on AI stocks that's similar to what Jim Chanos saidEnglish
2·26 days agoAfter hearing about his gamble, hearing any more without results is irrelevant poisoning the pot.
𞋴𝛂𝛋𝛆@lemmy.worldto
Lemmy Shitpost@lemmy.world•When they call you "worthless" - just remember THISEnglish
1·1 month agoYou really are worth less, as you are older than you were yesterday, and young organs sell for more.
𞋴𝛂𝛋𝛆@lemmy.worldto
Technology@lemmy.world•Is this the end of Bootloader Unlocking in the EU?English
1·4 months agoFuck smart phones and neo feudalism. This is theft of ownership with a criminal complicit government. I applaud all Luigi’s these people deserve it. These are the killers of democracy. If your device only runs factory filtered stalkerware garbage, all democracy is dead. All information is easily filtered by this proprietary shit. Freedom of the press is a bullshit tiny niche of the broader requirement for a fully informed public. The fucking “press” is bullshit to highlight. You must have fully informed citizens and you may not choose how that information is shared or disseminated between citizens. This is not democracy. People are so fucking stupid.





It is the tiny URL link that has a unique identifier. The normal website links are just the regular website address root for reddit.com. Tiny URL links stand out more to me because I use a DNS whitelist firewall and will never approve any of these forwarding connections.