Liste des Groupes | Revenir à e design |
On 4/8/2024 8:53 AM, Don Y wrote:Grrrr... s/chat/char/You also would be surprised at how much information "leaks" from naiveThis is my all-time favorite -- laughable -- take on "security":
encoding strategies. E.g., if you know (or suspect) the format of the
content, you can often deduce the coding algorithm.
<https://community.hpe.com/hpeb/attachments/hpeb/hpsc-46/6970/1/UserGuide.pdf>
This is (was) *sold* as "Secure Web Console".
By a "reputable" company with very deep pockets!
The product idea was excellent! Provide a means of accessing the
serial console on a remote computer over the internet. So, you could
troubleshoot boot problems and other issues in cases where the
server/host in question hadn't yet booted *or* had lost IP connectivity.
Essentially, you build a one-port terminal server and glue a web server
on the outfacing side. An administrator can then access the web server
(from any web client) and have his keystrokes passed through to the
attached serial console and the output from said console painted into
his web browser's display.
Easy peasy!
But, the data stream is naively "encrypted" with a simple substitution cipher.
The cipher is stateless so characters can be decoded without regard for where
in the data stream they are encountered. (i.e., a packet sniffer's paradise).
And, the decode operation is:
chat cleartext = crypttext ^ 0x37;
Seriously? What *idiot* thought to put "Secure" in the product's title???
("I locked my front door -- and put the key under the mat so I would
always know where I had left it...")
Les messages affichés proviennent d'usenet.