Page 1 of 1

PSA - I'm trying to give you clown porn, how to stop me

Posted: Wed Mar 26, 2025 7:53 pm
by cumlord
I've been messing around with crawling the netdb with snex to see whats out there. Found 2 destinations this way that gave us access to add torrents through a web panel. If this can be done, be prepared to receive clown porn, maybe a podcast or show for good measure

The second case also gave us access to the router console, torrents were added through snark. A message was sent and they seemed to have fixed it now. I don't think any "real" damage was done (we did try to get access to filesystem) besides changing the router console language to spanish. Also, susimail will leave the username available this way, very dangerous obviously, as this allowed us to link the ident with an ip address obtained from the router console as well as see any services they were hosting.

http://git.simp.i2p/simp/clowning

please use auth / encrypted leasesets

Re: PSA - I'm trying to give you clown porn, how to stop me

Posted: Mon Mar 31, 2025 3:44 am
by cumlord
about the webui for bigly....in my opinion it's safest to just turn it off entirely, but auth is fine too.

This has allowed us to get the ip address of some bigly users now. If we can force your torrent client to download a torrent, we can give you one with a clearnet tracker url and get the ip that way.

Bigly also can make other http tunnels for tracker and rss feed exposed over i2p, haven't found anything dangerous in those, but the rss feed one may display device names like the biglybt client shows.