<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Thread Dump</title><link>https://threaddump.info/</link><description>Recent content on Thread Dump</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://threaddump.info/index.xml" rel="self" type="application/rss+xml"/><item><title>From an Unknown 433 MHz Signal to a Real-Time Meshtastic Security Research Pipeline</title><link>https://threaddump.info/notes/sdr/meshtastic-sdr-research/</link><pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate><guid>https://threaddump.info/notes/sdr/meshtastic-sdr-research/</guid><description>&lt;h2 id="summary"&gt;Summary&lt;/h2&gt;
&lt;p&gt;A wide burst near 433 MHz looked unusual in SDR++. It was too broad for a typical narrowband voice channel and displayed repeated slanted structures in the waterfall. That observation led to a passive research pipeline:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;BladeRF / SDR++ capture
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; -&amp;gt; LoRa PHY identification
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; -&amp;gt; GNU Radio demodulation
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; -&amp;gt; payload CRC gate
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; -&amp;gt; packet-preserving UDP
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; -&amp;gt; Meshtastic protobuf decoder
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; -&amp;gt; JSONL and SQLite persistence
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; -&amp;gt; public, privacy-aware reporting
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The goal of this note is to document the technical path from RF observation to structured Meshtastic packet analysis, while also showing that public RF telemetry can expose metadata, topology, and operational patterns.&lt;/p&gt;</description></item><item><title>H.323 Devices discovery scan via TPTK/Q.931/H.225.0.CS</title><link>https://threaddump.info/notes/threat-intel/m-000900-tptk-931/</link><pubDate>Sun, 10 Apr 2022 10:24:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000900-tptk-931/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
H.323 service detection technique based on the SETUP message type (0x05).&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;


&lt;figure&gt;&lt;img src="capture-detail.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;</description></item><item><title>SoftEther reflection DDoS amplification attack via OpenVPN P_CONTROL_HARD_RESET_CLIENT_2</title><link>https://threaddump.info/notes/threat-intel/m-000897-openvpn-reset/</link><pubDate>Sun, 10 Apr 2022 10:24:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000897-openvpn-reset/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
OpenVPN P_CONTROL_HARD_RESET_CLIENT_2 - initial key from client, forget previous state&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;According to &lt;a href="https://github.com/SoftEtherVPN/SoftEtherVPN/issues/1001" rel="noopener noreferrer"&gt;SoftEther issue #1001&lt;/a&gt;
 SoftEther is vulnerable
to DDoS amplification attack via OpenVPN&lt;/p&gt;

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;</description></item><item><title>IEC 60870-5-104 TESTFR</title><link>https://threaddump.info/notes/threat-intel/m-000896-iec-60870-5-104/</link><pubDate>Sun, 10 Apr 2022 01:31:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000896-iec-60870-5-104/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
IEC 60870-5-104 Transmission Protocols - Network access for IEC 60870-5-101 using standard transport profiles

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Apple File Service (AFS) DSI AFP</title><link>https://threaddump.info/notes/threat-intel/m-000881-afp-dsi/</link><pubDate>Sun, 20 Feb 2022 08:18:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000881-afp-dsi/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Apple File Service(AFS) DSI GetStatus(AFP) call

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>LDAP Search Request</title><link>https://threaddump.info/notes/threat-intel/m-000879-ldap-search/</link><pubDate>Sun, 20 Feb 2022 08:18:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000879-ldap-search/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
LDAP SearchRequest for objectclass=any

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Apache Cassandra CQL</title><link>https://threaddump.info/notes/threat-intel/m-000865-cassandra/</link><pubDate>Fri, 18 Feb 2022 22:29:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000865-cassandra/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Cassandra CQL Protocol Request

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>TPKT ISO 8073/X.224 COTP Connect Request</title><link>https://threaddump.info/notes/threat-intel/m-000864-tpkt-cotp/</link><pubDate>Fri, 18 Feb 2022 13:37:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000864-tpkt-cotp/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
TSAP ISO 8073/X.224 COTP Connect Request

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Android Debug Bridge(ADB) service</title><link>https://threaddump.info/notes/threat-intel/m-000846-adbd/</link><pubDate>Thu, 17 Feb 2022 18:55:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000846-adbd/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Android Debug Bridge(ADB) service remote shell access

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Rsyncd service enumeration</title><link>https://threaddump.info/notes/threat-intel/m-000845-rsyncd/</link><pubDate>Thu, 17 Feb 2022 18:55:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000845-rsyncd/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Rsync daemon service enumeration

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Dahua DVR protocol - Remote access</title><link>https://threaddump.info/notes/threat-intel/m-000826-dahua-dvr/</link><pubDate>Tue, 15 Feb 2022 11:02:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000826-dahua-dvr/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Dahua DVR protocol remote access using common credentials

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>TPLINK Archer C20i CVE-2017-8220</title><link>https://threaddump.info/notes/threat-intel/m-000825-archer-c20i/</link><pubDate>Tue, 15 Feb 2022 10:40:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000825-archer-c20i/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
TPLINK Archer C20i CVE-2017-8220

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Java Debug Wire Protocol(JDWP) Handshake</title><link>https://threaddump.info/notes/threat-intel/m-000820-jdwp/</link><pubDate>Mon, 14 Feb 2022 11:25:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000820-jdwp/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Java Debug Wire Protocol(JDWP) Handshake

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>LibreOffice Impress Remote Server</title><link>https://threaddump.info/notes/threat-intel/m-000778-libre-impress/</link><pubDate>Sun, 13 Feb 2022 20:22:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000778-libre-impress/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
LibreOffice Impress Remote Server access. Slideshow remote control.

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Asterisk Manager</title><link>https://threaddump.info/notes/threat-intel/m-000777-asterisk/</link><pubDate>Sun, 13 Feb 2022 19:36:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000777-asterisk/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Asterisk Manager remote access

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>IBM DB2 Administration Server</title><link>https://threaddump.info/notes/threat-intel/m-000753-db2das/</link><pubDate>Fri, 11 Feb 2022 18:38:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000753-db2das/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
IBM DB2DAS Administration Server

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>XMPP Jabber Client request</title><link>https://threaddump.info/notes/threat-intel/m-000717-jabber/</link><pubDate>Thu, 10 Feb 2022 23:36:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000717-jabber/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
XMPP Jabber Client initiation

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>AppSocket/JetDirect/PDL Printer PJL INFO</title><link>https://threaddump.info/notes/threat-intel/m-000715-hp-pjl/</link><pubDate>Wed, 09 Feb 2022 22:26:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000715-hp-pjl/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
HP Printer job language(PJL) status query over PDL

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Redis INFO enumeration</title><link>https://threaddump.info/notes/threat-intel/m-000714-redis-info/</link><pubDate>Wed, 09 Feb 2022 22:00:00 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000714-redis-info/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Redis in-memory database enumeration via info command

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Telnet root/root automated exploitation</title><link>https://threaddump.info/notes/threat-intel/m-000693-telnet-root-root/</link><pubDate>Tue, 08 Feb 2022 11:16:02 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000693-telnet-root-root/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Telnet root/root credentials automated exploitation with malware deployment

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Log4j CVE-2021-44228 HTTP Headers</title><link>https://threaddump.info/notes/threat-intel/m-000692-log4j-tomcatbypass/</link><pubDate>Mon, 07 Feb 2022 21:07:02 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000692-log4j-tomcatbypass/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Log4j CVE-2021-44228 using various HTTP Headers

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Unitronics PLC GetID</title><link>https://threaddump.info/notes/threat-intel/m-000691-plc-ided/</link><pubDate>Mon, 07 Feb 2022 20:30:02 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000691-plc-ided/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Model and OS Version /00IDED query. 00 enables any controller to respond.

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Babylon RAT C2 Client Request</title><link>https://threaddump.info/notes/threat-intel/m-000689-babylon-rat-c2/</link><pubDate>Sun, 06 Feb 2022 19:51:21 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000689-babylon-rat-c2/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Babylon RAT C2 Client Request

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>KUKA.WorkVisual DeviceInfo</title><link>https://threaddump.info/notes/threat-intel/m-000688-kuka-robotics/</link><pubDate>Sat, 05 Feb 2022 11:57:21 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000688-kuka-robotics/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
KUKA.WorkVisual configuration software for KUKA KR C4 (Robotics) DeviceInfo call

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>IBM-3279-4-E Telnet</title><link>https://threaddump.info/notes/threat-intel/m-000687-ibm-3279-4-e/</link><pubDate>Thu, 03 Feb 2022 23:12:21 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000687-ibm-3279-4-e/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
IBM-3279-4-E Telnet host access

&lt;figure&gt;&lt;img src="terminal.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>LDAP Search request</title><link>https://threaddump.info/notes/threat-intel/m-000686-ldap-searchreq/</link><pubDate>Thu, 03 Feb 2022 22:40:21 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000686-ldap-searchreq/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
LDAP wire search request

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Microsoft Windows SMB</title><link>https://threaddump.info/notes/threat-intel/m-000685-microsoft-smb/</link><pubDate>Thu, 03 Feb 2022 15:45:21 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000685-microsoft-smb/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Microsoft Windows 2000 2195 5.0 SMB

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>AWS Credentials GET</title><link>https://threaddump.info/notes/threat-intel/m-000684-aws-config/</link><pubDate>Thu, 03 Feb 2022 10:59:53 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000684-aws-config/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
AWS Credential file HTTP GET

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Siemens Logo! 0BA7 PLC</title><link>https://threaddump.info/notes/threat-intel/m-000679-siemens-logo-0ba7/</link><pubDate>Wed, 02 Feb 2022 21:25:56 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000679-siemens-logo-0ba7/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Siemens Logo! 0BA7 PLC init

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>DVRIP-Web</title><link>https://threaddump.info/notes/threat-intel/m-000681-dvrip-web/</link><pubDate>Wed, 02 Feb 2022 18:26:56 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000681-dvrip-web/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
DVRIP-Web Protocol request

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Weblogic Server 12.1.2 T3</title><link>https://threaddump.info/notes/threat-intel/m-000683-weblogic-t3/</link><pubDate>Wed, 02 Feb 2022 18:26:56 +0100</pubDate><guid>https://threaddump.info/notes/threat-intel/m-000683-weblogic-t3/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Archive note:&lt;/strong&gt; This observation was migrated from the former threatdump project. It is retained as historical packet research and is not a live threat feed.
Weblogic T3 RMI protocol

&lt;figure&gt;&lt;img src="capture.png" alt="" loading="lazy" style="width:100%;"&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;/blockquote&gt;</description></item><item><title>Cisco 2960 WS-C2960G-24TC-L</title><link>https://threaddump.info/notes/hardware/cisco2960g-24-tcl/</link><pubDate>Sat, 24 Oct 2020 00:00:00 +0000</pubDate><guid>https://threaddump.info/notes/hardware/cisco2960g-24-tcl/</guid><description>&lt;p&gt;Quite unusual, not listed on the &lt;a href="https://www.cisco.com/c/en/us/support/switches/index.html" rel="noopener noreferrer"&gt;Cisco&lt;/a&gt;
 website 2960 &amp;ldquo;G&amp;rdquo; series WS-C2960G-24TC-L with 20 Ethernet 10/100/1000 ports and 4 dual-purpose uplinks&lt;/p&gt;

 &lt;figure&gt;&lt;img src="sasqua8g.jpg" alt="" loading="lazy" width="200" height="200"&gt;&lt;/figure&gt;</description></item><item><title>Cisco 2960 WS-C2960-24TC-S</title><link>https://threaddump.info/notes/hardware/cisco2960-24-tcs/</link><pubDate>Sat, 03 Oct 2020 00:00:00 +0000</pubDate><guid>https://threaddump.info/notes/hardware/cisco2960-24-tcs/</guid><description>&lt;p&gt;&lt;a href="https://www.cisco.com/c/en/us/support/switches/catalyst-2960-24tc-s-switch/model.html" rel="noopener noreferrer"&gt;Cisco Catalyst 2960-24TC-S&lt;/a&gt;
 with 24 Ethernet 10/100 and 2 dual-purpose ports (10/100/1000 or SFP) from &lt;a href="https://www.cisco.com/c/en/us/support/switches/catalyst-2960-series-switches/series.html" rel="noopener noreferrer"&gt;Cisco 2960&lt;/a&gt;
 series.&lt;/p&gt;
&lt;p&gt;
&lt;figure&gt;&lt;img src="2960-24tc-s.jpg" alt="" loading="lazy" width="300" height="300"&gt;&lt;/figure&gt;


&lt;figure&gt;&lt;img src="front.jpg" alt="" loading="lazy" width="300" height="300"&gt;&lt;/figure&gt;
&lt;/p&gt;</description></item><item><title>Cisco 2960 WS-C2960-48TC-L</title><link>https://threaddump.info/notes/hardware/cisco2960-48-tcl/</link><pubDate>Sat, 03 Oct 2020 00:00:00 +0000</pubDate><guid>https://threaddump.info/notes/hardware/cisco2960-48-tcl/</guid><description>&lt;p&gt;WS-C2960-48TC-L is a &lt;a href="https://www.cisco.com/c/en/us/support/switches/catalyst-2960-48tc-l-switch/model.html" rel="noopener noreferrer"&gt;Cisco 2960&lt;/a&gt;
 layer 2 switch with 48 Ethernet 10/100 and 2 dual-purpose ports (10/100/1000 or SFP)&lt;/p&gt;

&lt;figure&gt;&lt;img src="boardview.jpg" alt="" loading="lazy" width="300" height="300"&gt;&lt;/figure&gt;


&lt;figure&gt;&lt;img src="frontview.jpg" alt="" loading="lazy" width="300" height="300"&gt;&lt;/figure&gt;</description></item><item><title>Cisco 2960 WS-C2960-48TT-L</title><link>https://threaddump.info/notes/hardware/cisco2960/</link><pubDate>Thu, 24 Sep 2020 00:00:00 +0000</pubDate><guid>https://threaddump.info/notes/hardware/cisco2960/</guid><description>&lt;p&gt;WS-C2960-48TT-L Cisco 2960 Series switch. Writing down remarks, findings about under the hood components.

&lt;figure&gt;&lt;img src="board.jpg" alt="" loading="lazy" width="300" height="300"&gt;&lt;/figure&gt;


&lt;figure&gt;&lt;img src="2960_front.jpg" alt="" loading="lazy" width="300" height="300"&gt;&lt;/figure&gt;
&lt;/p&gt;</description></item><item><title>Complaint tablet to Ea-nasir</title><link>https://threaddump.info/notes/essays/complaint-tablet/</link><pubDate>Sun, 07 Jun 2020 00:00:00 +0000</pubDate><guid>https://threaddump.info/notes/essays/complaint-tablet/</guid><description>&lt;p&gt;Around 1750 BC. Deal between Nani and Ea-Nasir goes wrong. First formal complaint ?

&lt;figure&gt;&lt;a href="https://en.wikipedia.org/wiki/Complaint_tablet_to_Ea-nasir#/media/File:Complaint_tablet_to_Ea-Nasir.jpg" rel="noopener noreferrer"&gt;&lt;img src="ea-nasir-complaint.png" alt="" loading="lazy" width="200" height="200"&gt;&lt;/a&gt;&lt;/figure&gt;
&lt;/p&gt;</description></item><item><title>Sortition &amp; democracy</title><link>https://threaddump.info/notes/essays/sortition-democracy/</link><pubDate>Sun, 07 Jun 2020 00:00:00 +0000</pubDate><guid>https://threaddump.info/notes/essays/sortition-democracy/</guid><description>&lt;p&gt;Do we have enough of social platform influence on our elections ? How about election by lot ?

&lt;figure&gt;&lt;a href="https://en.wikipedia.org/wiki/Sortition#/media/File:AGMA_Kleroterion.jpg" rel="noopener noreferrer"&gt;&lt;img src="kleroterion.png" alt="Kleroterion. Lot selection device from Athenes" loading="lazy" width="200" height="200"&gt;&lt;/a&gt;&lt;figcaption&gt;Kleroterion. Lot selection device from Athenes&lt;/figcaption&gt;&lt;/figure&gt;
&lt;/p&gt;</description></item><item><title>About</title><link>https://threaddump.info/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://threaddump.info/about/</guid><description>&lt;p&gt;Curiosity drives this notebook. It is a place to retain technical experiments, observations, failures, and conclusions instead of leaving them scattered across terminals and old repositories.&lt;/p&gt;
&lt;p&gt;The site combines material previously published through &lt;strong&gt;threaddump&lt;/strong&gt; and &lt;strong&gt;threatdump&lt;/strong&gt; with new research on SDR signals, security, FreeBSD and OpenBSD, networking, and hardware.&lt;/p&gt;</description></item><item><title>Search</title><link>https://threaddump.info/search/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://threaddump.info/search/</guid><description>&lt;p&gt;Search titles, summaries, categories, tags, and article text.&lt;/p&gt;</description></item></channel></rss>