A thread on the Tasmota TLS MitM attack I found a few months ago since getting a proper blog post about it is taking me forever.
Tasmota is an open source firmware that runs on a number of ESP8266-based IoT home automation devices, which talks to an MQTT broker for management.
string "ssh-rsa"
mpint e
mpint n
where e is the public exponent (usually 65537) and n is the modulus.
Slight problem. RFC4253 doesn't explain what an mpint is.
Tasmota's implementation missed this.

GNFS's difficulty depends on the size of the number, and these are too big.
ECM, however, depends on the size of the second largest factor.
So, then, to attack the key, the family of RSA keys that match the fingerprint are all generated, and then ECM is used to try to factor them.
https://t.co/1AITBNXWIv
The attack also worked just fine on my LAN and I was able to pull off a MitM attack.
https://t.co/quyAT5uzw4
I am the sort of person who thinks that running transport mode IPSec at home is a good time.
More from Trading
As this year comes to an end, here are the 11 most powerful threads on Subasish Pani exclusively compiled for you all.
Collborated with @AdityaTodmal
1/ Important concepts from Power of Stocks - Subasish
Important Concepts from Power of Stocks\u2014 Subhasish Pani
— Aditya Todmal (@AdityaTodmal) August 12, 2022
7+ years of trading experience in 14 tweets\U0001f9f5
Collaborated with @niki_poojary
2/ Important concepts with video links of Subasish
There are plenty of videos of Subhasish Pani from Power of Stocks.
— Aditya Todmal (@AdityaTodmal) April 17, 2022
You already know those.
Instead, here are 12 concepts from his videos that will make you a better trader\u2013\u2013not worse:\U0001f9f5
Collaborated with @niki_poojary
3/ The 5 EMA
Subasish Pani revealed the most simple, yet successful strategy: 5EMA set up!
— Nikita Poojary (@niki_poojary) July 3, 2022
Here is a thread of 23 video clips on the 5EMA set-up that will save you hundreds of hours and available to you for no cost!
5EMA set-up: \U0001f9f5!
Collaborated with @AdityaTodmal
4/ The Bollinger Band set-
A set up which has a minimum Risk/Reward (R/R) of 1:4
— Nikita Poojary (@niki_poojary) October 2, 2022
This set up can be used for intraday, option selling, option buying, as well as investing.
Maximum profit strategy by Subasish Pani.
Bollinger band set-up: \U0001f9f5!
Collaborated with @AdityaTodmal pic.twitter.com/aEIUVQF2XY