Skip to content

Instantly share code, notes, and snippets.

View roycewilliams's full-sized avatar
💭
:cheeeeeese:

Royce Williams roycewilliams

💭
:cheeeeeese:
View GitHub Profile
@roycewilliams
roycewilliams / tacacs-detect.nse
Last active September 23, 2026 16:57
Nmap NSE to detect valid TACACS and its shared-secret status (benign fingerprint)
description = [[
Confirms a TACACS+ (tac_plus) daemon is listening on TCP/49 and flags it for the
pre-auth format string bug (elttam, 2026-09-23; CVE pending, fixed in Shrubbery
F4.0.4.32). Discovery, not vulnerability detection.
* Confirms port is speaking TACACS+
* Reports whether shared secret is configured or not (more urgent if not)
Benign: sends one well-formed, empty-field TACACS+ handshake; never touches the
vulnerable path and attempts no authentication or exploitation.
@roycewilliams
roycewilliams / tac_plus_fmtstring.yar
Last active September 23, 2026 15:29
Yara for detecting tac_plus versions vulnerable to 2026-09 vulnerability
/*
* tac_plus_fmtstring.yar - tac_plus pre-auth format string bug (elttam,
* 2026-09-23; CVE pending). Fixed in Shrubbery F4.0.4.32.
* Generated by Claude Opus 4.8 on 2026-09-23. Tested with yara 4.2.3.
* Version: 2026-09-23.02 (base = YYYY-MM-DD, .NN = same-day revision; bump all rules together)
* Validated 2026-09-23 against real stripped binaries: Debian(Shrubbery),
* EPEL(Meta,glibc), OpenWrt(Meta,musl), and Shrubbery's own compiled F4.0.4.32
* (patched -> family only, not vuln). Anchors are runtime strings; the Cisco
* copyright is a source comment and absent from binaries, so it is NOT used.
* IFIN: https://ifin.network/t/cve-pending-pre-auth-format-string-bug-in-tac-plus-shrubbery-networks/859
@roycewilliams
roycewilliams / airconsole.sh
Last active September 13, 2026 17:36
airconsole.sh - wrapper for AirConsole serial adapter Bluetooth interface on NetBSD
#!/bin/sh
#
# airconsole.sh -- use a Get Console "AirConsole" Bluetooth serial adapter from
# NetBSD: find it, open its RFCOMM serial port, bind that to a pty.
#
# SPDX-License-Identifier: MIT
# Copyright (c) 2026 Royce Williams
#
# The AirConsole's own dongle goes in the AirConsole's USB-A socket, NOT in
# this machine. This machine needs a radio of its own -- any ubt(4) device.

uftk(4): a NetBSD driver for the Fintek F81232 USB-UART bridge

NetBSD has no driver for the Fintek F81232 (0x1934:0x0706) on any branch -- not netbsd-11, not HEAD. The chip attaches as ugen(4) and you get no /dev/ttyU*. It is the console bridge built into Protectli firewall appliances, among other things.

This is a working driver, plus the protocol documentation that made it possible. Built, booted and used on real hardware: NetBSD 11.0/i386 on a Samsung NP-Q1U (Q1 Ultra, 2007 UMPC), talking to a pfSense 2.9.0 console.

NetBSD 11 on a Samsung Q1 Ultra (2007 UMPC)


Scope: the Samsung Q1 Ultra (NP-Q1U family), Intel A110 "Stealey", running NetBSD 11.0/i386. Much of it applies to any McCaslin-era UMPC or to 32-bit i386 machines generally.

Provenance: researched and written with AI assistance (Claude Opus 5). Everything marked [MEASURED] was observed on real hardware; everything else carries a confidence marker. See the confidence register at the end.

NetBSD 11.0: eGalax/Touchkit USB touchscreen dead under uep(4)

Two independent kernel bugs, both present in NetBSD 11.0 and in HEAD as of 2026-09-07. Two small patches. Verified working on real hardware. Discovered by Claude Opus 5, but due to NetBSD's LLM policy (which I respect), not contributed upstream. But this is hereby licensed MIT to the extent feasible, to be available for others to reference as needed.

My general notes on the Samsung Q1U are here: https://gist.github.com/roycewilliams/7d73f838e1d619045ffae020e78a3741

NOTE: I am not a kernel developer. The results are stable for me, but reasoning / context may be missing/bad.

Micro Cookbook RECIPE.TXT — Binary Format Reference

Reverse-engineered specification of the recipe database format used by Micro Cookbook (Pinpoint Publishing, c. 1988–1994) on MS-DOS. This is sufficient to (a) reimplement the recipe extraction in any language, and (b) understand the on-disk structures well enough to recreate the original program's behaviour.

Status of knowledge: the record/field encoding is fully decoded and validated against the program's own print-out. The 32 KB header index region, SCREEN.TXT, and CONTROL.TXT are not decoded (not required for

@roycewilliams
roycewilliams / hashcat-significant-benchmarks_626-700.txt
Last active June 15, 2026 06:01
hashcat-significant-benchmarks_626-700.txt
# Partial hashcat benchmark comparison, 6.2.6 release vs 7.0.0 alpha
# Single 4090, CUDA, 575.57.08, optimized kernel, -w 3
# Only showing benchmarks with 5% or more change. Higher is faster.
# 2025-07-31
Mode | Name | Previous | Current | Diff | % Diff
---------------------------------------------------------------------------------------------------------------------------------
0 | MD5 | 145824788773 | 158354116103 | 12529327330 | +8.59%
10 | md5($pass.$salt) | 145386855059 | 157744853131 | 12357998072 | +8.50%
11 | Joomla < 2.5.18 | 140934665341 | 152237381817 | 11302716476 | +8.02%
@roycewilliams
roycewilliams / hashmob-pwned-passwords-cracking-progress.md
Last active March 19, 2025 03:22
Hashmob Pwned Passwords cracking progress.

Tracking Hashmob progress on cracking downloadable SHA1 hashes from Pwned Passwords.

Each new target hashlist is a delta - the "net new" from the previous downloads. My list here is in reverse chronological order.

ID Hashlist Name Hash Type Found Total Recovered %
#H11651 Have I been Pwned v2025-03 (Delta V8.12) SHA1 (100) 411,723,586 420,878,532 97.82%
#H9259 Have I been Pwned V8.12 (Delta V8.4) SHA1 (100) 630,532 778,688 80.97%
#H7464 Have I been Pwned V8.4 (Delta V8) SHA1 (100) 16,019,292
@roycewilliams
roycewilliams / hibp-download-b2e98.txt
Last active April 28, 2025 21:10
hibp-download-b2e98 - 2025-02-25
#-----------------------------------------------------------------------------
# All HIBP SHA1 hashes beginning with b2e98, as of 2025-02-25, by frequency in leaks.
#
# The HIBP API receives a hex prefix, and returns all hashes with that prefix
# (with the prefix omitted), including frequency count, across all leaks in HIBP.
# The first hash is often much more likely to be the password behind the query,
# demonstrating the limits of k-anonymity as a mitigation when frequency is included.
# Of the 618,979 passwords represented, 96.8% of them (599,297) are the top one.
#
# Permalink: https://gist.github.com/roycewilliams/2034c9253d46fbcaefb13f8e5d42daa2