Meta tags:
description= A technical blog by Sam Curry;
Headings (most frequently used words):
hacking, and, the, controlling, cars, samcurry, netblogabout, world, poker, tour, inside, clubwpt, gold, back, office, subaru, tracking, via, starlink, admin, panel, kia, remotely, with, just, license, plate, millions, of, modems, investigating, who, hacked, my, modem, leaked, secrets, unlimited, miles, largest, airline, hotel, rewards, platform,
Text of the page (most frequently used words):
and (12), the (9), min (5), read (5), #hacking (5), that (4), 2024 (4), 2023 (3), vulnerabilities (3), access (3), vulnerability (3), discovered (3), kia (3), 2025 (3), security (2), for (2), airline (2), hotel (2), rewards (2), these (2), would (2), have (2), attacker (2), customer (2), from (2), server (2), june (2), vehicles (2), allowed (2), license (2), plate (2), remotely (2), about (2), controlling (2), cars (2), shah (2), subaru (2), starlink (2), admin (2), panel (2), all (2), poker (2), clubwpt (2), gold (2), back (2), office (2), blog (2), older, newer, rss, zlz, samwcyo, between, march, may, identified, multiple, within, points, com, backend, provider, significant, portion, programs, enabled, sensitive, account, information, including, names, billing, addresses, redacted, credit, card, details, emails, phone, numbers, transaction, records, aug, leaked, secrets, unlimited, miles, largest, platform, two, years, ago, something, very, strange, happened, while, working, home, network, was, exploiting, blind, xxe, required, external, http, smuggle, out, files, spun, aws, box, ran, simple, python, webserver, receive, traffic, vulnerable, jun, millions, modems, investigating, who, hacked, modem, 11th, set, remote, control, over, key, functions, using, only, attacks, could, executed, any, hardware, equipped, vehicle, seconds, regardless, whether, had, active, connect, subscription, sep, with, just, november, shubham, gave, unrestricted, accounts, united, states, canada, japan, jan, tracking, via, shubs, online, website, which, fully, core, application, used, administrative, site, functionality, oct, world, tour, inside, samcurry, net, sam, curry,
Text of the page (random words):
blog sam curry samcurry net blog about hacking the world poker tour inside clubwpt gold s back office oct 12 2025 7 min read in june 2025 shubs shah and i discovered a vulnerability in the online poker website clubwpt gold which would have allowed an attacker to fully access the core back office application that is used for all administrative site functionality hacking subaru tracking and controlling cars via the starlink admin panel jan 23 2025 7 min read on november 20 2024 shubham shah and i discovered a security vulnerability in subaru s starlink admin panel that gave us unrestricted access to all vehicles and customer accounts in the united states canada and japan hacking kia remotely controlling cars with just a license plate sep 20 2024 8 min read on june 11th 2024 we discovered a set of vulnerabilities in kia vehicles that allowed remote control over key functions using only a license plate these attacks could be executed remotely on any hardware equipped vehicle in about 30 seconds regardless of whether it had an active kia connect subscription hacking millions of modems and investigating who hacked my modem jun 3 2024 21 min read two years ago something very strange happened to me while working from my home network i was exploiting a blind xxe vulnerability that required an external http server to smuggle out files so i spun up an aws box and ran a simple python webserver to receive the traffic from the vulnerable server leaked secrets and unlimited miles hacking the largest airline and hotel rewards platform aug 3 2023 21 min read between march 2023 and may 2023 we identified multiple security vulnerabilities within points com the backend provider for a significant portion of airline and hotel rewards programs these vulnerabilities would have enabled an attacker to access sensitive customer account information including names billing addresses redacted credit card details emails phone numbers and transaction records samwcyo zlz rss newer 1 5 older
|