4 ms·
Can you get root with only a cigarette lighter? (2024)
- rkagerer 6mo ago> Finally, I'd like to thank JEDEC for paywalling all of the specification documents that were relevant to conducting this research.
- b00ty4breakfast 6mo agomy prediction before reading is that they're using the piezo sparker to beat the DUT over the head with a big EMF spike Edit: Nailed it!
- grufkork 6mo agoI thought they were going to just heat a chip to increase the overall error rate
- throwawayqqq11 6mo agoBe it eletric or thermal, i came here for fried hardware and left disappointed. Now i have to wrangle my curiosity to what happens when you lighter-spark a usb port for the rest of the day.
- b00ty4breakfast 6mo agoif you've got an old disposable flash camera lying around, you can give it a big zap (I felt myself instantly aging like Dorian Gray looking at his portrait as I typed that sentence.)
- 4gotunameagain 6mo agoYeah but the devil is in the details ;) It's not like you can randomly spike stuff and achieve an exploit
- b00ty4breakfast 6mo agobut of course
- ted_dunning 6mo agoUh... yeah. Just hold the sysadmins hand over the lighter until they tell you the password. Never forget the easy way in ... the humans.
- quietbritishjim 6mo agoLike the classic xkcd on security https://xkcd.com/538/ https://xkcd.com/538/
- debugnik 6mo agoGood luck hacking a Switch using that method and getting away with it.
- haunter 6mo agoYeah but can you light a cigarette with only a laptop? Checkmate atheists! /s
- mirekrusin 6mo agoIf it's intel, you can fry an egg for sure.
- LoganDark 6mo agoThe ol' Black MacBook Cooktop...
- hi-im-buggy 6mo agoIn combination with a weighing scale (https://github.com/KrishKrosh/TrackWeight https://github.com/KrishKrosh/TrackWeight), you have everything you could ask for in a portable food processor.
- LoganDark 6mo agoI would love a black MacBook with Force Touch.
- thenthenthen 6mo agoShort the battery!
- Babkock 6mo agoDownvoted on Hacker News
- slj 6mo agoYes. We do this in Australia, around the bars and pubs getting a root with only a cigarette lighter is a classic move.
- karmakurtisaani 6mo agoI feel like getting root privileges means something else in Australia.
- defrost 6mo agoStill only a third of the full wombat trifecta.
- CTOSian 6mo agoalso free arcade credits :}
- RugnirViking 6mo agoI had an australian colleague who found it endlessly funny that we pronounced "router" as "rooter" instead of their "rowter". statements like "If that happens the system will root the packets via the rooter first" was met with much giggling
- kjkjadksj 6mo agoWe americans call it rowter too. Well, really raoter.
- Retr0id 6mo agoAnswers to some of the questions at the end, from future me: - It also works on LPDDR5, LPDDR4 - Yes, it works on ARM platforms (at least, the ones I tried). - The simplest way to trigger similar faults electronically is via a high-speed mux IC, as described in https://stefan-gloor.ch/ddr5 https://stefan-gloor.ch/ddr5 (chipshouter also works, but is less elegant imho!) - Yes, you can get webkit addrof/fakeobj primitives like this, although I didn't write an end-to-end exploit. - You can pwn nintendo switch kernel with an adjusted exploit strategy, but the same adjusted strategy does not work on Switch 2, due to memory encryption (one bitflip corrupts a whole cache line). But other strategies may be possible? (notably, it is possible to block a whole write operation from happening at all - see also https://rdist.root.org/2010/01/27/how-the-ps3-hypervisor-was-hacked/ https://rdist.root.org/2010/01/27/how-the-ps3-hypervisor-was... )
- Retr0id 6mo agoI also spent a long time trying to do the glitching with a mosfet, but never got it to work. I couldn't get enough drive strength to actually glitch anything, without messing with the delicate capacitance+impedance tolerances of the bus.
- nom 6mo agopfff, root, back in my day we hacked a vending machine with a lighter and got free coke. No idea who discovered it, but the machine back at my school had an infrared interface for servicing, and you could trigger an interrupt with the flash of the flintstone of a lighter. Because it's just some 90s microcontroller, it would simply reset after failing to receive a valid command and forget what it was doing previously. All you had to do was order a coke, and right when it drops out, before it subtracts the amount, you flash the lighter in front of the IR port like a magician, say the magic words and bam - free coke!
- limit35 6mo agoI used a saline glitch trick in the 90s. I cannot remember the exact sequence of events, but one injected saline into the coin or bill receptacle, which made the sensor believe money was being continuously inserted into the machine. This method had the benefit of clearing the machine of change after purchase since it registered the candy bar was bought with a substantial amount of money.
- thatguy0900 6mo agoClearing the machine of money it already had sounds way more likely to get you into trouble than getting a free coke, I'm not so sure that's a benifit
- chrisBob 6mo agoWe just unplugged our vending machine with similar timing.
- kjkjadksj 6mo agoWow. We were like cave men in comparison shaking the machine with 2-3 people to knock a can out of the racking.
- bdjdjdndndb 6mo agoBrave ... Those things can kill