Exploring the wide open world of TikTok.

There’s not a lot of talk about TikTok between peers in the infosec community. The TikTok platform is somewhat of a joke to many in the security world due to many of it’s factors. The truth is that it’s gaining popularity and it may be here to stay, so from a security and privacy perspective we need to acknowledge it and give it the attention it deserves.

If your reading this blog, then it’s unlikely that you’ve never heard of TikTok. It made world news when Former President Donald Trump ordered China’s ByteDance (TikTok’s Parent company) to divest ownership of the application, and threatened to shut down its U.S. operations through executive action. As with most threats Trump made during those short nightmarish 4 years, there were likely hidden reasons that benefited himself or his close friends. Regardless of Trump’s rationale, TikTok was owned by a Chinese business, which is required by law to send it’s data to the Chinese government. Security researchers checked and saw “unusually large” amounts of data that TikTok was collecting on it’s users.

After some legal back and forth, and bids made by Oracle and Microsoft, Oracle ended up purchasing 12% of TikTok, because ByteDance was unwilling to give their algorithm to Microsoft as part of the deal. So a small chunk of TikTok stock belongs to US based company Oracle, and that was enough to make the politicians happy. Note that Oracle also owns small portions in Canada in other countries, but I couldn’t find the exact details on percentages or if the 12% is everything that isn’t China.

Read more at CNBC TikTok Deal Splits Control Between US and Chinese Owners

TikTok itself has grown at blazing speeds, and is catching up fast to the big boys of social media Facebook, Youtube, and Twitter. This was made possible by the isolation brought on by the Covid19 Pandemic ( due to our basic need for society), and the free publicity brought to you by our former US President.
PS. My favorite word for 2021 is “Former”

So what is TikTok exactly and how is it different?

If you remember Vine from the mid 2010s, then TikTok is a version of Vine with a few added features pulled from Twitch and other social media platforms. The TikTok app even works exactly like the Vine app with it’s quick 15 to 60 second videos, delivered to you in an endless scroll. The differences (from what I can tell) include the editing interface and the live streams. Live is a big part of TikTok, with the usual scrolling chat that allow viewers to interact with the creator and send gifts, similar to Twitch. Many popular creators have multiple moderators to assist with managing the live chats, and the chat has a filter to allow certain words not to be said. For example, creators who are showing how to make health foods or drinks might filter “poop” to prevent viewers from saying “that looks like poop.”

TikTok’s definition will depend greatly on you ask. The security world and those that reverse engineer the site say “TikTok is a data collection service that is thinly veiled as a social media networkGuy who Reverse Engineered TikTok on boredpanda.com. But if you ask the standard to heavy users, it’s a God-send. Social Media fundamentally provides social interaction to people you would normally not have social contact with. For people who are too busy for events in their community, who work from home, or just don’t feel like they fit in where they are, social media can be a lifesaver. It’s our need to belong to something and to have relationships. It’s probably something that I personally need to do more of. That’s why I believe it’s important to look at these platforms very closely and protect the users that make up the network.

What I’ve learned from TikTok:

If you are male, TikTok’s algorithm with send you mostly female videos. If you are female, you will be served mostly male videos. They’re algorithm also puts lower priority on videos from LGBTQ and creators with obesity among other things. Very little control is given on the web interface (as opposed to the mobile app). For instance, to change certain settings in your profile you must use the mobile app because no option is available when using a web browser. After all, mobile apps can pull more data off your device than a website, and can do so with more secrecy.

When I first joined TikTok, I immediately believed that it was almost entirely female creators, because female creators made up 80% of what TikTok served me. This would be preferable for someone in their 20s and not married, but I was suspicious. I learned that the results were the opposite when using a fake female account. My feed and search results as a female user were noticeably different, showing way more male created videos.

To test the male vs female claim, I did a very simple search using my male account. A search that is normally guaranteed to have high male to female ratio.. I searched “infosec”. The first few results were mostly female with a few thumbnails that didn’t show anyone. As I scrolled i slowly started to see more videos from male creators. To be fair, there isn’t a lot of infosec people on TikTok. Most of my results were copies of previous results.

Two guys in a row in my search for “inforsec”, and both have their face covered in the thumbnail..

These results are not expected on any platform. Hopefully there will one day be equal gender ratio in the information security world, but it’s widely recognized that there are more men in infosec.
Shout out to all the women in the security world! We need more of you and what your able to bring to the table.

The TikTok Culture

Those of us older millennials remember the internet in the late 90s early 2000s. In those days, you didn’t use your real name, you never posted a picture of yourself publicly, and never gave personal information or credit card numbers. It was a time when prime-time TV included catching online child predators (which we need now more than ever) and movies like “The Net”. But, the internet was unknown and scary back then. We had chats and tight communities and friendships without ever needing to know each other’s real name or appearance. You always wondered, and in time, people would share that info, but the magic of it was your friends like you for you, and not what you looked like, where you came from or who your friends and family were. a/s/l? Most people asked but few responses were honest.

On TikTok, this kind of thinking is taboo. If you set up an account pretending to be something you aren’t, people find that suspicious. It mirrors a larger paradigm shift in online culture that started with Facebook (which I wont get into here). On TikTok, you are expected to be everything you are in real life and more. It attempts to be more personal than YouTube, while it’s content remains very public. This is partly due to the platform preferring mobile phones over traditional PCs, but also because of the short video time. Your videos can be 15 seconds, or 60 seconds.

TikTok turned it’s live feature into an achievement. How do you reach this achievement? Popularity. 1000 followers are required to achieve the “Live” option.

DigitalTrends.com writes:

“A TikTok user must have at least 1,000 followers to even see the live stream option on the platform, for example. Even after you hit 1,000 followers, it could still take several days before the live stream button appears.”

The Monetary benefits for creators:

Why is it important to go live? Two reasons, live streams can be longer than 60 seconds, and followers can send the streamer “Gifts” only on a live stream. Here’s how gifts work:
1. A User must purchase “Coins”. Coins are the only monetary purchase that can be made.
2. Once a user has Coins, they can then click the “Gift” icon in a live video.
3. This gift icon is then sent to the creator’s account, and are converted into “Diamonds”
4. Diamonds can then be cashed in, but the creator receives only 50% or less of the original coin’s value. TikTok keeps the other 50-60%

This information and much more can be found on this site: Alpha.com: How Much are TikTok Gift Points Worth?

Coins, Gifts, and Diamonds can be complicated by design, and depend on the nation’s currency and it’s exchange rates. Best estimates put Diamonds at around $0.05 USD. Coins purchased in bulk are around $0.015 or 1.5 cents, but Gifts start out at 5 Coins, and so multiple gifts are needed to attain diamonds. Like I said, complicated.

In my opinion, it would be very hard to make a living on TikTok without having a secondary source of income. That may range from music sales, to alternative advertising within videos, or using TikTok as a secondary platform to YouTube. However, there are creators that claim they can make a few thousand dollars each live stream, and a few are able to make a living on those earnings.

Friends versus Followers

This topic is honestly a little complicated too. To add a friend, you must follow that person, and they must follow you back. If you have content that only friend’s can see, then this agreement must take place. One can not see friends only content by being a follower alone.

With that said, the downside to this is that it will take longer to acquire enough friends to do a live video, and even longer to gain any gifts (or make profit)

The Privacy issues of TikTok on it’s surface

With what we already know about TikTok’s data collection, there’s no way I would use it without a VPN, and I wouldn’t recommend using it on a mobile device that wasn’t a burner phone or hasn’t been hardened before hand. Let’s put it this way, if you have information on your phone that you wouldn’t want other people to have, you shouldn’t use this app. Right off the bat, the app requests access to your contact list, other social media accounts, phone number, camera, microphone, local (home) network. As if that wasn’t bad enough, well.. don’t take my word for it.. Here’s some more from boredpanda.com from someone with 15 years experience and reverse engineered the app:



To be fair, this post was from almost a year ago. Lets add a few what I’ve seen recently. And I haven’t had a chance at attempting to reverse engineer the app, but maybe soon.

Uploading videos are public be default. You must specifically request for videos to be “friends only” or only viewable to you.

The gifts and monetary exchange is sketchy at best. There is little information provided by TikTok on actual numbers. The money that TikTok itself makes from these are not enough to support the platform, so it goes without saying that most of ByteDance’s profits come from selling some of that user data, and we can assume some nation state funding is involved.

The platform and it’s culture put a lot of emphasis on the individual and personal information. The vast majority of TikTok’s videos are self videos, and what people do in those videos will remain online indefinitely, possibly by one of the several archiving projects that collect TikTok videos and publish them publicly. See this reddit feed if you would like to look at the discussion on TikTok video archiving without the need of a TikTok account: https://www.reddit.com/r/Archiveteam/comments/hr3zsm/lets_archive_tiktok/
This is not a new concept, even Angelfire and Geocities pages have been resurrected recently, bringing back websites created up to 30 years ago. And there are bigger projects, such as the The WayBack Machine .
Point being, What you do online will always be there, in one form or another. It can be viewed by potential employers, schools, and future friend’s and in-laws. I predict there will be a lot of social media accounts pulled out of the void in future Presidential elections


https://tik.fail/browse Another TikTok video Archive that appears to be on hold due to API changes.
I will add more archive links as they become available.

To the TikTok community:

I can’t stress this enough, I’m not targeting TikTok users in this post. I know many and they are great people. A lot of great friendships have been made on this platform, and it’s giving potential stars a chance to shine. I love the people that make up TikTok.. Most of them anyways.. There are some blatant child predators I’ve come across and I have no respect for that kind of scum. Maybe that’s a blog post for another day, because I would love nothing more than to expose people who manipulate and hurt children. So stay tuned…
…But to the average users on TikTok, If you have to be there, please consider doing it this way:
Use a web browser on a PC in privacy/privacy mode, behind a VPN. Brave is a great privacy enriched browser built on chromium, that has built in adblockers and other features. It wouldn’t hurt to do it within a clean Virtual Machine, the same safeguards we use to reverse engineer malware, because that’s basically what your using.

If you must use it on a mobile phone, purchase a prepaid smart phone from Walmart, and add a VPN like Private Internet Access or PIA, but do not add your email address or any other accounts or apps to the phone. Set your normal phone up as a WiFi access point and connect the WiFi from the TikTok phone to your normal phone with the VPN enabled. This will allow you to use the same amount of data, but in a safe way.

I would have suggested using the Tor Browser, which does all that for you. However, when I tried to browse TikTok in Tor the screen became distorted and made it impossible to click anything. This occurred on the two highest security profile types. This is due partly to the restriction on scripts being run within TOR, but there also seems to be some safeguards TikTok has to prevent a hardened browser like Tor from working correctly.

More things to consider: The US military does not allow TikTok on it’s networks, nor does many Federal agencies, large enterprises, and defense networks. Supposedly, the parent company ByteDance are also not allowed to use TikTok on they’re own network, although this isn’t verified and I assume there are some details left out of that claim.

If this blog post doesn’t scare you, then check back. I’m going to be making a blog post that will explain to people why privacy matters, and why businesses want you to believe privacy is dead.

If you are the victim of an internet stalker, then visit this link, or call the number below:
National Center for Victims of Crime
1-855-4-VICTIM (1-855-484-2846)

For information on how to report Child Sex Trafficking, Pornography, Sexual Abuse or kidnapping, visit this page on the Department of Justice’s website:
https://www.justice.gov/criminal-ceos/report-violations

Or call your local law enforcement.

Why we love Mr. Robot

I’m a big Mr. Robot fan. I have two t-shirts, an Fsociety mask, two patches, and a copy of Elliot’s journal from prison. This doesn’t sound like much, but it’s major for me because I’m not the type to collect Funko Pop, or wear tshirts of my favorite show, band, etc. So it’s funny to think back to when a coworker first recommended the show to me, and I rolled my eyes and ignored him.

Mr. Robot was a series that aired on USA beginning in 2015 about a Security Engineer by day, vigilante hacker by night, named Elliot Alderson (played by Rami Malick) who “wanted to change the world.” He meets up with a group of hackers called “F Society” to erase the world’s debt, and take on the “people who secretly run the world… top 1% of the top 1% who play God without permission…”

As stated above, I first heard about Mr. Robot from a co worker. I was discussing “Halt and Catch Fire”, which is another great show that aired on AMC. After I explained the story line, he asked if I was also watching Mr. Robot. “What’s that?” I asked. “I’m surprised you haven’t heard of it. It’s about a hacker…” I can’t recall anything he said after that line because I tuned out the rest. It wasn’t until he asked 2 more times that I finally decided to give it a chance. The first episode I watched was season 1 episode 5, where Elliot infiltrates Steel Mountain, and halfway into the episode I was hooked. I stopped the episode and decided I needed to watch it from the beginning. I was caught up the following day.

Why did I ignore it? Before Mr. Robot, no movie or TV show had ever accurately portrayed a hacker, or the act of hacking. Many had the right mindset and good ideas, but it was always overshadowed by a lack of realism. There was even a new term created for this epidemic called “HollywoodOS”. Even within the movies I liked, I could never fully enjoy them out of frustration and a little embarrassment. If you don’t understand what I mean, try watching the live action Mario Bros. Movie that was released in the early 90s. If you know anything about Super Mario Bros, you will quickly understand what I’m talking about.

I’ve mentioned before that the 1995 movie “Hackers” is what started me down the path of becoming a hacker, but that happened when I was in 7th grade. It didn’t take long for me to realize that the hacker community was not a big fan of the movie, and as I learned the trade I too realized how fake and silly the footage really was. Flying through a virtual world where directory trees are on large boxes? Where worms visually resemble a long twisted umm… worm? with tentacles? Viruses speaking ransoms and singing until they execute? There’s no logical rationale for any of it. Even the keyboard the network security team uses with it’s flat inverted keys, would make typing extremely difficult.

Inverted keyboard in the movie Hackers

All that aside, the story line portrayed hackers as the good guys for once, and there were some legit hacks and good ideas mentioned, and even a few Easter eggs. “Hackers” fell victim to the same mistakes of every other Hollywood attempt at portraying hacking, and little has changed over the years.

Mr. Robot was the first to get it right (and hopefully not the last). Wargames was close, but most other films portrayed hacking as multiple, big screens with a lot of graphics, or speed typist writing hundreds of lines of perfect code on the spot. My favorite Hollywood hacker fail is the CSI scene where two agents are typing on the same keyboard at an attempt to fend off an intrusion.

WarGames 1983

Sam Esmail had a team of security professionals work with production to make the hacks as accurate as possible. He actually put forth the effort needed to get it right, and it shows that he cared. Wikipedia states:

“Aside from the pilot episode, Esmail hired Kor Adana (former network security analyst and forensics manager for Toyota Motor Sales), Michael Bazzell (security consultant and former FBI Cyber Crimes Task Force agent and investigator) and James Plouffe (lead solutions architect at MobileIron) as his advisors to oversee the technical accuracy of the show. By the second season, Adana assembled a team of hackers and cybersecurity experts including Jeff Moss (founder and director of Black Hat and DEF CON computer security conferences),[77] Marc Rogers (principal security researcher for Cloudflare and head of security for DEF CON),[78] Ryan Kazanciyan (chief security architect for Tanium) and Andre McGregor (director of security for Tanium and former FBI Cyber Special agent) to assist him with the authenticity of the hacks and the technology being used.[79

The show’s team of experts answering questions in the Mr Robot Panel at Defcon

Sam Esmail was fascinated by hacker culture and stated that he had wanted to make a film about it for around 15 years. He was also inspired by the Arab Spring. This all came on the heels of the NSA leaks by Edward Snowden, which occurred in 2013, two years before Mr. Robot aired. This show was legit, and the timing was perfect. For the first time ever, the hacker and security community as a whole had nothing bad to say about what they were seeing.

Mr. Robot even took a few jabs at the past Hollywood attempts at hacker films. In season 1, before the Steel Mountain hack, Romero and Mobley are watching the movie “Hackers” in a hotel room, and Romero (being the older, seasoned hacker/phreaker) says “Hollywood hacker bullshit! I’ve been in this game 27 years. Not once have I come across an animated singing virus.” This is exactly what most hackers in the 90s would have said about the movie “Hackers”

In addition to the authenticity of the hacks, I think Sam Esmail also realized something in production that Hollywood had never considered. We get excited when you show software, or a pen-test tool being used accurately, that we ourselves have experience using, or helped develop. When I saw the HackRF being used in the last few episodes of the 4th season, I tapped my wife’s shoulder and said “Look! It’s a hackRF like you got me for our anniversary! You wanted to know what it does? There’s your answer.”

OpenWRT Interface and USB Rubber Ducky

Another reason we love Mr. Robot is that it gives examples of use cases, usually being the worse case scenario. I’ve found myself showing clips to family and friends to help push the idea of why security and privacy is important. Anytime someone is loose on privacy, especially in a business setting, I tend to ask if they’ve seen Mr. Robot.

All that aside, you don’t have to be a hacker to love the show and understand the story line. This wasn’t really a show about hacking, it was a show about a hacker with serious personal issues, suffering from mental illness, creating a revolution, and questioning his reality. This all makes for a great show, but believe it or not, it goes even deeper..

Like most people, I had never heard of ARGs (Alternate Reality Games). Mr Robot introduced me that world when I decided to check the QR Code drawn in pencil in Elliot’s journal in Season 2 Episode 2. The day the show aired, I found myself seeking a copy online that I could pause and take screen shot of the QR Code. Once that was accomplished, I opened Paintbrush and drew over the blocks in black so that my phone could pick up the possible message or URL. As a result, I landed on Confictura Industries, which then looked like a 1990’s style home page for the notebook’s brand. Confused and curious, I Googled what I was seeing. I quickly found a group on Reddit called ARG Society. https://www.reddit.com/r/ARGsociety/

whoismrrobot.com part of the Mr. Robot ARG

With the ARG, the first few findings offered prizes to the few people who found them and solved the puzzles. Season 2 offered an e-coin signup with prizes (ringtones, clues, wallpaper). As the show progressed and became more popular, the ARG became bigger, with more sites to find, clues that spanned across multiple social media sites, and increasingly more complex. Click the link above to see how complex season 4 became. With this, I found out there were many other ARGs and it became a new hobby. Some good one’s to check are “This House has People In it”, Cloverfield, Petscop, Dad, and the infamous Cicada 3301 (Whether or not this was an ARG is debatable) https://en.wikipedia.org/wiki/Cicada_3301

Many of us love it because Elliot’s problems mirrored a lot of our own. It’s no secret that there’s an epidemic of depression and social anxiety within the hacking and security community. Elliot’s mental health issues included all of that to an extreme, as well as drug abuse and Dissociated Identity Disorder. Elaborating on this subject could require spoilers, so I’ll end it with this…
Those of us that know that pain and shared those struggles with Elliot, now feel a little less alone in the world.

Modified Electric Flyswatter for more bug zapping Power!

This is an electric flyswatter that has been modified to be more powerful. Your likely to find these in hardware stores, probably on end caps. It’s shaped like a small, plastic tennis racket with a trigger button, and a compartment for two AA batteries. To use it, you swat at flies or insects while holding the button, which shocks the bug as it’s being hit. They’re good to have when camping in areas with a lot of mosquitoes. You can purchase an Electric Fly Swatter by clicking the link below.

HOMEVAGE Electric Fly Swatter (2 AA Batteries Included) $14.99

Due to safety reasons, the shock is not that impressive. The only way a bug can be “zapped” is if it’s touching the inner and outer metal screen. Even then, it’s hard to know for sure if it’s being zapped because the voltage is very low. I wanted more power…

The electric fly swatter you see at the top is one that I modified a couple years ago. It has a much higher voltage output than the stock fly swatter, and I will show you everything you need to modify one for yourself. The modification consists of replacing the stock transformer inside with a Step Up Power Module, aka “Voltage Multiplier” to increase the voltage to as much as 700kV and create an arc (or spark) without anything touching the screens. The nice thing about these voltage multipliers is that they fit easily inside the handle of the fly swatter, and work off of two AA batteries.

DC Step Up Module / Voltage Generator / Voltage Multiplier
The Red and Green wires connect to the + and – sides of the batteries. The other two wires connect to the mesh screen .
The original stock transformer

You can purchase a one for yourself from Amazon $6.99 by visiting this link:
DC Boost Step Up Power Module High Voltage Generator DC 3V-6V,700KV

The reason I’m revisiting this project now is because I’ve been afraid to leave the batteries inside when its not in use. The button is easy to press, and doing so will cause a small arc. It’s possible for a child to grab it and shock themselves, or worse case, dropped onto the button and potentially cause a fire. So I revisited this project to add a safety switch onto the bottom.

This is the inside of the flyswatter prior to installing the safety switch. The black trigger button was originally a programming switch for an aftermarket remote start system for a car. Most installers remove this button during the install to prevent the system from being reprogrammed by accident. It’s soldered in-line with the + wire coming from the batteries to the Voltage Multiplier. I replaced the stock button because it was broken during disassembly, but it would have worked as well and required less work.

Here is a rough schematic I spent 5 minutes drawling in MS Paint. The bottom shows the safety switch that we are adding, which is going in-line with the negative wire from the batteries.
There are 3 wires coming from the mesh screen at the top, one wire for a center mesh (positive charge), and two wires for each of the outer mesh (negative charge). Both outer mesh wires will connect to a single wire from the module, and the other wire is connected to the inner mesh. It doesn’t matter which wire is which from the module, as long as the two outer mesh screens are connected to the same wire. This is honestly a simple circuit and great for beginners.

This is the switch I will add to be used as a safety switch. It has a small washer that reads “On Off” so that anyone can easily see whether the power is turned off or on. The current trigger switch will make the connection to the + side wire from the batteries, while the safety switch makes the connection to the – side. Both switches will have to be “ON” to allow the zapper to function.

There is limited room inside the handle, and since we’re working with high voltage we don’t want any wires to come loose or short out, so I’ll be soldering my connections and using heat shrink tubing.

This is my Hakko soldering iron. I’ve used many soldering irons over the years, and this is my favorite. The base is heavy enough to prevent itself from tipping over, and includes a wet sponge and wire mesh thing to quickly clean the tip. The iron itself heats up within 10 seconds, and shows a readout of the temperature. Hakko is a well known brand, so finding new tips is easy. You can purchase this Hakko Soldering Iron at this link:
Hakko FX888D-23BY Digital Soldering Station FX-888D FX-888 (blue & yellow)

This is standard 2:1 heat shrink tubing that I’m using for this application. You can purchase a similar assorted box of heat shrink tubing here:
650pcs Heat Shrink Tubing Black innhom Heat Shrink Tube Wire Shrink Wrap UL Approved Ratio 2:1 Electrical Cable Wire Kit Set Long Lasting Insulation Protection, Safe and Easy, Eco-Friendly Material

Always tin wires and contacts with solder before soldering them together. It’s makes soldering them together easier and creates a stronger weld. I also use flux when I have it nearby. Do not inhale the fumes from the solder, and use a fume filter if one is available.

.

After soldering the wires to the switch, I slide some small pieces of heat shrink tubing over the wires and contacts. Normally I use a heat gun, or my solder reflow gun set at a low temperature, but I decided to use a torch because the tubing was so small. You have to be careful with a lighter or torch because it can quickly melt the material, which is why I’m leaving an inch between the end of the flame and the tube, and constantly moving the torch up and down. Always keep in mind that heat rises.

Heat shrink is better than electric tape at staying adhered to the wires. I normally do not use electric tape in cars or anything that requires movement and sudden temperature changes. Electric tape has a tendency to dry out and unravel over time, which would expose the wires that it’s supposed to protect.

I added a larger piece of heat shrink tubing around both wires to keep them together. I could have used tape for this, but since I already had the torch and heat shrink tube out, it was easier to use another tube. That section of wires will run along the side of the batteries, so keeping them snug will help prevent an accident when replacing batteries in the future.

I decided to mount the safety switch on bottom of the handle. Mounting it on the side would feel awkward with the toggle switch sticking up between your fingers, or poking the palm of your hand. There was no place higher that provided enough space inside, so the bottom was really my only choice.

I desoldered the original green wire from the negative battery terminal and replaced it with one wire from my switch. Then I soldered the other switch wire the the original green wire I just just desoldered.

To mount this safety switch, I had to drill a hole into the bottom of the handle large enough for the threaded area part of the switch to fit through, but small enough to keep the nuts from falling through.
This is what the safety switch looks like after everything was reassembled.

Here’s a video of this electric flyswatter in use, so you can see the outcome and the arc created by the Voltage Generator Module thingy.
The arc will always occur where the inner and outer screens are closest. Unless a bug is on it, this flyswatter tends to always arc in that top area.

After I was finished, I tested to make sure all switches were working as expected. I hope you found this informative. Note that the links within this blog post are affiliated links, which means I get paid when they are used to purchase parts from Amazon.

My First Hack

I have a few posts in the works, but personal matters have kept me too busy to invest the time they deserve. So I wanted to add a quick story for the few people that follow my blog.

My first hack happened in 8th grade, back in the late 90s. The computer lab at the school had just switched from a mainframe networked to workstations, to a LAN with Gateway 2000 PCs Windows 95. It was the school’s first computer lab with internet access, and the teachers were given email addresses. A few teachers proudly tacked them to the bulletin board on the wall at the front of the lab for everyone to see.

We had a new computer lab teacher, fresh out of college. She was genuinely nice and seemed very excited to be there.

The teacher explained that these machines had a program called “Deep Freeze” which prevented access to anything other than the shortcuts on the desktop, by locking out the Start Menu and prevented right clicking on the desktop icons and taskbar. The teachers were confident that the only abuse these computers could suffer was physical, such as gum in the keyboard.

Put yourself in my shoes for a moment. Imagine being a middle schooler in the 90’s who had watched the movie “Hackers” way too many times. The internet was like magic, and hackers were wizards wielding that magic. This middleschool wannabe hacker got excited by the restrictions the teacher was describing, and saw it as a challenge.

Before this, I had read a collection of text files called “The Happy Hackers Guide to Mostly Harmless Hacking.” It can now be found on textfiles.com. I knew becoming a hacker didn’t happen over night, and that I needed to crawl before I could run. From those texts I learned to use Telnet, and had a habit of scanning for ports on a server and using telnet on each port to see what would happen.

I sat in the computer lab with the rest of my class, opened Word, and rushed through our assignment. It was a tutorial on how to use Copy, Cut, and Paste, and how to open and save a Word document. The final instructions said to save the document when we were finished. I click “Save As” which opened to root directory (or C:\ Folder) and had an interesting thought…

I quickly saved my document to the Desktop, and clicked “Save As” again. I had never heard of Deep Freeze before that day, but I was already noticing a potential vulnerability. I changed the file type from “Documents” to “All Files” and started exploring directories within the Save As window. I made it to C:\Windows and decided to test it. I right clicked on mspaint.exe and selected “Open”. To my surprise, the Paint application opened on my screen. I closed it and grinned.

I found and opened Telnet.exe. “What should I do now?“ I thought, with no real plan in mind. The classmate beside me had taken notice and asked, “How did you open that?” While giving him the quick run down, I noticed the teacher’s email addresses on the bulletin board at the front of the room.

I already knew that nearby Virginia Tech had an SMTP server that would allow anonymous emails to be sent, and the address was easy to remember, smtp.vt.edu port 25. I decided to play a little prank. I opened a connection in telnet to VT and did the usual HELO commands with a fake sender address, and started composing an email to one of my teachers.

Before I could finish typing the message, I felt a hand in my shoulder. I turned to the guy beside me, who was frantically trying to close Nike.com in Netscape Navigator, and then looked up to see the computer lab teacher staring straight at me with a panicked look. She said “close everything and come with me…”

I followed her out of the classroom into the hall, and she closed the door behind us. In a panicked voice she said “(My name).. I’m getting calls from the school board telling me something is up. I don’t know what your doing, but you need to stop right this minute, or you will face suspension! Do you understand!?” I looked down and nodded, and we walked back into the lab.

I entered the classroom and realized the room had turned silent and my classmates were all staring at me, some were trying not to laugh. The lab teacher darted back to her desk and grabbed the phone that had been left on hold. Apparently the teacher had talked loud enough in the hallway for everyone inside to hear. I wasn’t the type of person to show off to everyone, and rarely got in trouble. I didn’t know whether to be proud or embarrassed.

Rumors spread fast in middle school, and despite my attempt so far to keep a low profile, many people were already calling me a hacker. Explaining what actually happened didn’t help things, and for a few days I was known as the kid that hacked Virginia Tech from the Middle School’s computer lab.

Blind upgrade to macOS 11

What do I mean by blind upgrade? I’m going to upgrade to Big Sur without any prior knowledge, or reading any reviews.

If you didn’t already know, I was an ACMT (Apple Certified Macintosh Technician) for 6 years. I mostly performed repairs on Mac laptops (MacBook Pro, MacBook Air, MacBook) due to an overwhelming amount of college students in the area that used Mac. I also worked on iMacs and MacMini, performed data recovery, and fixed OS and filesystem related issue. I had never owned a Mac computer, and briefly used one at school, before I was asked to take on that role, but I grew very fond of them in time.

A few things I specifically like about Macs:
macOS is free
You can install macOS on an external hard drive and boot it on any compatible Mac
You can clone your HDD to an external, and boot it off any compatible Mac
You can connect a Thunderbolt/Thunderbolt 3 to another mac and boot off it’s internal HDD
You can dual boot (bootcamp) to Windows or Linux.
HDD encrypted by default

When I started seeing some of the buzz words being used about macOS 11, I became concerned. This is the first major macOS update that has occurred since I was a technician, so I had an idea…

I’m going to install and review a major OS update, without reading any of the reviews or opinions in advance.

This will result in a true review, going in blind with very few expectations. Expectations, be they good or bad, from other blogs, vlogs, and news sites. This is the first major OS version update released since I was a technician, and in the past, I was always very prepared for the issues I would see, and ready with fixes.

My 13″ MacBook Pro 2016

I’m going to be using my newest MacBook Pro (I have a few). Here are the specs/details
MacBook Pro 13″ 2016, four Thunderbolt 3 Ports (has touch ID)
Processor: 2.9 GHz Dual Core i5
Memory: 8GB 2133MHz LPDDR3
Graphics: Intel Iris 550 1536MB
250GB SSD
Model: MacBookPro13,2

Here is a list that worry me about this update:
Still UNIX based?
App updates (require repurchase?)
Dualboot (bootcamp) work?
Disk Utility still work?
Is it worth the effort?

Like any responsible computer user does, I created a backup. (sarcasm)
And now we’re ready to upgrade…

The upgrade itself happened much quicker than I expected. I make sure all the analytics stuff is unchecked.

^ Proof

The first and most obvious thing I noticed is that the visuals are a little different. Icons and Menus have a cleaner look and seem a little more spaced apart. So far, I prefer the new look. Back around macOS 10.8, Icons had become to detailed that it was sometimes hard to tell them apart.

Btw, This is dark mode.

The two icons I’ve found with a prohibitory sign (circle with a slash through it, like a no parking sign) are shown above. One was the iPhoto Library Upgrader, which is only for upgrading a library from iPhoto to Photos, and is no longer needed, as well as a Bluetooth Firmware update. I honestly don’t remember what that was for.

I’m impressed by how quickly apps open. The only exception is Firefox, which is unchanged in how quickly it opens. By the way, I’ve switched to the same MacBook Pro to complete the remainder of this post.

I have not yet found any third party app that doesn’t work. Several needed to be updated, but updates were very quick. Again, I’m very impressed with how quick everything is. So far I’m seeing no problems with Brew, Tor, iHex, What’s Your Sign (adds hex values to right click menu), and so on.

I will need to do a separate section for the last part of this review, which is booting to Windows and Linux. Neither was installed on this Mac, due to the SSD being only 250GB. In the passed, I used a loader like rEFIt or equivalent.

For now, macOS has exceeded my expectations and, for the first time ever, I’m not disappointed with anything in this upgrade… so far.

UPDATE
I wanted to include that Docker works on this ver of macOS, and UNIX shells still appear to be available, however I have no been able to find a version of Wine that works on macOS Catalina or later.

Filtering Honeypots in Shodan

I used Shodan a lot when it was first introduced, and I’ve learned a lot about banners and services by using it. A few months ago I noticed a lot of searches were returning honeypots, which end up being false positives for my search. Shodan now labels honeypot results in the search, but previously I identified them as having 10-20 ports open and a long list of vulnerabilities associated with the results.

Honeypot tag in shodan Search

Below is a tag I’ve started adding to my searches if I begin seeing honeypots

-"792/71644"

On the other hand, it can also be used to search specifically for honeypots by removing the “-“

A search of “792/1644” in Shodan

The search returned 5.036 results. Not all results are Honeypots, because this number was added to help lure attackers. I haven’t taken the time to find out what technology this part of the banner came from, but I will update this post as that information comes to light. It’s also likely that Shodan has a search tag that will allow you to filter out anything tagged as a honeypot, but I haven’t yet explored that possibility.

Software Defined Radio SDR

SDR, or Software Defined Radio is the use of software instead of hardware in the radio world. Believe it or not, radio is still a common communications medium. It’s still used by Police, Fire, and Rescue on a regular basis. There are still amateur radio enthusiast communicating over long distances, CB radios over shorter distances, and signals continue to be sent from satellites in space. Our computers and cell phones continue to use it for wireless connections over WIFI, Bluetooth, Zigbee, LTE, and many other protocols. A lot of the older technology is still in use, and newer types of technology get added regularly. There is a huge spectrum of SDR to explore, but this post will focus mostly on the basics, and act as an introduction to the subject.

Before you start exploring SDR, you need to know a little about radio frequencies. Most people understand the basics, like FM radio between 87Mhz-108Mhz. FM is a good starting point in SDR because you can use a local radio station to verify that your SDR device and antenna are working. When you turn on the FM Radio in your car, the numbers on the screen are literally the frequency of the station. If you listen to Hot97 in NYC, your turning to 97.1MHz. The nice thing about SDR is that we can listen way above or below that range of frequencies. Moving up passed 108MHz puts you into a range that Aircraft use to communicate.

Interesting fact, many old home radios from the WW2 era had a knob to switch between AM, FM, and aircraft.

VHF and UHF bands

The image above is outdated, but gives a good overview of what’s what on different frequencies. Two ranges you might notice are missing from this diagram are WiFi and AM radio. AM is found on much lower frequencies, around 1Mhz. WiFi is on the opposite side of the spectrum at 2.4Ghz (2400Mhz) and 5Ghz (5000Mhz)

Antennas.

This is where it really gets tricky. Wavelengths of frequencies determine the size of the antenna. Most people make the mistake of thinking bigger antennas are better. This is not true, and can hurt in certain cases. The lower the frequency, the longer the wavelength. Longer wavelength means bigger antenna. 100Mhz is requires roughly a total of 4ft antenna, while 3MHz would require a combined 156Ft. antenna. Most antenna can operate at half the size, called a half wave-length antenna. There are several good antenna calculators online, such as at Dipole Antenna Calculator

Consider this, how much longer is your car radio antenna, than your cell phone antenna? Most people don’t even realize their cellphone has an antenna because it’s so small that it fits inside the phone. Most modern smartphones have the WiFi, Bluetooth, and Cellular Antennas literally in a circuit board as shown below.

https://www.taoglas.com/

Sometimes you will see much larger directional antennas, such as WiFi antennas, that claim to receive better reception or more WiFi networks. This is true, but only in the direction they are pointing. These yagi antennas have “directors” and “reflectors” which help to broadcast and receive radio frequencies from further distances, but the part of the antenna that is doing all the work is very small.

I could do an entire blog just on antennas and antenna theory, but for the purpose of this blog we’ll only talk about the basic antenna, a dipole. Dipole antennas have a positive and negative side, one for the wave going up, and one for the wave going down. Think old rabbit ear TV antennas. Most antennas are this same type, but turned sideways.

Dipole antenna picture from wikipedia

If you remove the rubber from a basic WiFi antenna, you will notice they do this by taking coax cable and exposing the inside of the wire. The inner part acts as one pole and the outer shielding acts as the other pole. It’s literally a stripped wire inside hard plastic to keep it upright.

The metal thing in the center of the wire is to keep it in place inside the plastic cover.

Why does this matter? Choosing an antenna can make a big difference depending on what your trying to do, but they are not as complicated as they appear. For beginners, I suggest using a set of rabbit ears. The last rabbit ear antenna I found at a yard-sale for $1. If nothing else, you can use a bare copper wire around 6” long, connected to the inner conductor of antenna output. but most cheap SDR devices come with a small antenna. Which brings us to the next section.

SDR USB Devices

Feb 17 2009 was the date that all over-the-air TV broadcasting (aka local TV stations) were required to switch from analog to digital. People who relied on local TV using an antenna would need a new TV with a digital tuner built in, or a separate digital tuner set-top-box to hook to their older TV. Manufacturers decided to also offer USB digital tuners which allowed digital TV to be received on a PC, because they were cheap to make. They were called DVB-T TV Tuner Dongles and generally use the RTL2832U chipset.

Hackers realized that by changing the drivers in Windows, the RTL2832U could be accessed directly with Software Defined Radio software, and were able to recieve way beyond the range of UHF TV frequencies. DVB-T dongles then became known as RTL-SDR within the hacker world and became somewhat popular because they be purchased for as little as $7. History on the subject can be found at https://www.rtl-sdr.com/about-rtl-sdr/

My first SDR Dongle. $8.99 on Newegg

Above is my first RTL-SDR Dongle. It’s a standard DVB-T USB dongle, and has a type-F coax connector. This is the standard connector for Cable TV and UHF TV antennas. It can pick up between 20Mhz-950Mhz. Newer RTL-SDR Dongles have a wider range, but are usually around $25.

What can it do? If you have ever used a police scanner, it’s like that on steroids. It can pick up FM radio, police, EMS, Fire, pagers, older baby monitors, taxis, some satellites, aircraft (positions and communication), weather radio, some CB stations and a lot more.

The next step up in devices would be a Yardstick One or HackRF. These get a are a bit more expensive but the HackRF has the ability to transmit. Be careful because this can be illegal depending on the frequency and range.

Yardstick One $129 at https://shop.hak5.org/collections/wireless-testing/products/yard-stick-one
HackRF One approx $329 https://shop.hak5.org/products/hackrf

Other types of hardware to consider are Up-converters and down-converters. These devices can extend the frequency range of your SDR receiver, by taking lower or higher frequencies, and inputting them as a UHF frequency into the RTL-SDR. Below is a picture of my “Ham It Up” by NooElec. This is a USB powered up-converter that connects in line with your SDR dongle and drops the frequency range down to below 1Mhz and inputs it as 120Mhz

Ham It Up up-converter

Software

The software that I recommend starting out with is SDR# or SDRSharp for Windows. Look for the Download link beside Windows SDR Software Package at https://airspy.com

SDRSharp comes packaged with Zadig, a small app that changes the driver associated with your SDR dongle so that it will work with RTL-SDR software. If this doesn’t come with the package, or you find that your SDR doesn’t work in SDRSharp, then check the lower part of the same website for “WinUSB Compatibility Driver”.

SDRSharp GUI

The nice thing about SDRSharp is that it gives a clean visual of the frequencies your looking at. It’s great for exploring what is going through the air in your area. Select RTL-SDR/USB from the drop down menu in the top left and click Start. Click Configure to tune the power on your SDR if desired. You can then drag the top right window right or left to select the frequency to monitor. The right also has a selection for NFM (narrow FM), WFM (Wide FM), AM, and others. Play with the section and try all three when you notice activity on a certain frequency. Your standard FM radio stations are going to be WFM, while other signals will usually be either NFM or AM. Most other options will be more useful on HF, which would require and up-converter. I highly suggest checking youtube for videos on how to use SDRSharp if your not familiar with SDR software. It can seem overwhelming at first, but only takes a few minutes to learn.

SDRSharp also has an option for up and down-converters, to show the actual frequency being searched, rather than the one it’s being converted to. It supports plugins for recording, noise control, and receiving and decoding digital voice.

You can find a big list of software at https://www.rtl-sdr.com/big-list-rtl-sdr-supported-software/

They also include other SDR receivers for Linux, macOS, Rasbpian, Android, and web-apps

At the bottom of that site there is a section called “Programs Compatible Through Piping” . Many of these were created for other radio devices to decode digital signals using the microphone input on a PC. Search the web for “Virtual Audio Cable” (Windows only). This app creates virtual audio inputs and audio outputs, so that SDRSharp can be assigned to a virtual audio output, which will show up in other apps as an audio input, mimicking a microphone

Interesting apps to check are DSD+ which can decode digital police and other digital audio and data communications, and PDW which can decode data being sent to pagers.

Security

Much of what is broadcasted on RF is not encrypted. Encryption and Security are things that aren’t typically considered in the RF world, except for WiFi and LTE. Otherwise, little has changed with these communications since they were created.

Things that should consider better RF security includes garage door openers, keyfobs, cordless phones (yeah, they’re still around), baby monitors, and much more. You might be surprised at what you will find.

My purpose for writing this is to get people interested. I may add more specific posts on the subject at a later date. Below are some links to useful websites on the subject.

Signal ID Wiki – https://www.sigidwiki.com/wiki/Signal_Identification_Guide
The BIG list of RTL-SDR Software https://www.rtl-sdr.com/big-list-rtl-sdr-supported-software/
Great Scott Gadgets – home of HackRF https://greatscottgadgets.com/
Attify Shop – IoT, SDR, and Embedded security tools https://www.attify-store.com/collections/frontpage