this post was submitted on 06 Nov 2025
382 points (99.7% liked)

World News

50674 readers
3174 users here now

A community for discussing events around the World

Rules:

Similarly, if you see posts along these lines, do not engage. Report them, block them, and live a happier life than they do. We see too many slapfights that boil down to "Mom! He's bugging me!" and "I'm not touching you!" Going forward, slapfights will result in removed comments and temp bans to cool off.

We ask that the users report any comment or post that violate the rules, to use critical thinking when reading, posting or commenting. Users that post off-topic spam, advocate violence, have multiple comments or posts removed, weaponize reports or violate the code of conduct will be banned.

All posts and comments will be reviewed on a case-by-case basis. This means that some content that violates the rules may be allowed, while other content that does not violate the rules may be removed. The moderators retain the right to remove any content and ban users.


Lemmy World Partners

News !news@lemmy.world

Politics !politics@lemmy.world

World Politics !globalpolitics@lemmy.world


Recommendations

For Firefox users, there is media bias / propaganda / fact check plugin.

https://addons.mozilla.org/en-US/firefox/addon/media-bias-fact-check/

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Mikina@programming.dev 7 points 16 hours ago (2 children)

It depends on how well segmented is their network, but all you might need for that is a Raspbery PI with ethernet and GSM.

I've done some engagements where we sent someone into the company to get in as an air conditioning tech, and when they got in he planted that device between a printer and the network. It was set up to forward all traffic, but also allowed us to connect through GSM and get into the network.

It takes like a few seconds to plant it.

Or if it's really bad, then you might be able to reach it from the WiFi.

[–] uniquethrowagay@feddit.org 1 points 9 hours ago (1 children)

If your network does not have NAC and just lets unknown devices plugged into a random wall outlet inside, you might as well get rid of passwords alltogether.

[–] Mikina@programming.dev 1 points 6 hours ago

There are some ways how to get around NAC. If it's older 802.1x, you can use https://github.com/s0lst1c3/silentbridge, but what usually works for us is simply cloning the printer MAC, because older printers can't do authentication and rely on MAC whitelisting.

Making a MITM device that just clones the MAC when you plug it between the printer and the network isn't that difficult.

But I agree, NAC is important!

[–] kent_eh@lemmy.ca 1 points 12 hours ago

Or if it's really bad, then you might be able to reach it from the WiFi.

Or some employee might have dropped their own wifi access point onto the Lan for their own convenience.

I found 2 of those on the same floor during one sweep...