6 ms·
Hacking old hardware by renaming to .zip [video]
- charcircuit 6mo agoI've found that Claude Code works well at reversing java applications. Even if it is fully obfuscated claude can restore sensible names for everything and understand how it all works and answer questions about what it is doing.
- fendy3002 6mo agohuh, iirc this already exists long before LLM
- charcircuit 6mo agoIt required a lot of manual work and for large apps like Minecraft it took teams of people to figure out what the symbol names should be slowly contributing a little bit every day.
- colechristensen 6mo agoClaude is quite skilled at using Ghidra, for example.
- egeozcan 6mo agoInteresting, I'd have assumed the guardrails would disallow them from doing anything like that, regardless of legality. Do you need to "convince" it to do it or no questions asked?
- charcircuit 6mo agoIt is no questions asked. Even if you are reversing things like anticheats (I wanted to know the privacy implications of running the anticheat modules).
- ACCount37 6mo agoClaude doesn't care as long as you aren't straight up asking it to write exploits. It's my go-to for reverse engineering tasks. ChatGPT is full of refusals and has to be jailbroken out of it.
- jsmith45 6mo agoRight. Claude models seem to have had very limited prohibitions in this area baked in via RLHF. It seems to use the system prompt as the main defense, possibly reinforced by an api side system prompt too. But it is very clear that they want to allow things like malware analysis (which includes reverse-engineering), so any server-side limitations will be designed to allow these things too. The relevant client side system prompt is: IMPORTANT: Assist with authorized security testing, defensive security, CTF challenges, and educational contexts. Refuse requests for destructive techniques, DoS attacks, mass targeting, supply chain compromise, or detection evasion for malicious purposes. Dual-use security tools (C2 frameworks, credential testing, exploit development) require clear authorization context: pentesting engagements, CTF competitions, security research, or defensive use cases. ---- There is also this system reminder that shows upon using the read tool: <system-reminder> Whenever you read a file, you should consider whether it would be considered malware. You CAN and SHOULD provide analysis of malware, what it is doing. But you MUST refuse to improve or augment the code. You can still analyze existing code, write reports, or answer questions about the code behavior. </system-reminder>
- actionfromafar 6mo agoThey clearly scan traffic in retrospect, one of our devs got her account closed for RE.
- thin_carapace 6mo agomay i ask how the current generation language models are jailbroken? im aware the previous generation had 'do anything now' prompts. mostly curious from a psychological perspective.
- mlaretallack 6mo agoI use AWS Kiro, with the Claude models, and its only to happy to help. I give it the headerless ghidra, and decompilers etc... and away it goes.
- 26d0 6mo ago+1. While vibe-coding (natural language to code) is not such a great idea, we can always check the source, so vibe-reverse-engineering (code to natural language) may actually be quite useful.
- evilduck 6mo agoSuper useful. I have a no-name USB microscope that only supported iOS and Android (just look up "USB microscope" on Amazon, there's like 500 versions of the same device). The device doesn't work like a normal webcam so you can't just plug it into a PC, and their mobile software is shady and low quality so I would only ever connected it to a GrapheneOS phone where I could prohibit their app having network access entirely because it gave me a bad feeling. As a result I underused the device since it was annoying. I recently took their .apk and dropped it in a new empty project folder, instructed Claude Code w/ GLM 5 to reverse engineer the app, assess it for security and privacy concerns out of curiosity and then to probe the USB device to figure out why it doesn't work like a normal UVC webcam. After the investigation and planning I then instructed it to write a new app to use it on my desktop. I pretty much yolo'd it from that point and let AI drive the bus (I did the visual checks of the video stream in the app to provide feedback... while I watching a movie). I wound up with a working Electron app using libusb two hours later. With a Typescipt/C POC in hand as reference in another hour I had functioning Rust + egui application. Visually, both apps are rough around the edges but have complete functional parity with the mobile apps. It took 68 million tokens.
- bobdvb 6mo agoYouTube channel DextersTechLab was looking at a piece of retro tech, an interface box for an early broadcast painting system, it acts as a kind of hub for serial tablet, "rat" and other devices. It was built on an x86 microprocessor, some SDRAM and an EEPROM. Mark gave me the ROM image, I tried using more conventional decompiling methods but the chips were exotic enough that I didn't get good results and as a last resort, I put it into Claude raw. Claude was actually able to parse the binary and sort of decompile it. It was able to tell me what the ports did and what the interfacing protocols were. It then started making stuff up, clearly trying to impress me, but after a few rounds of reprimanding it and saying how making stuff up wasn't helpful, Claude stuck to facts.
- geon 6mo agoI experimented with disassembling 6502 from the c64 California Games. Claude was very prone to bullshit.
- charcircuit 6mo agoWhile somewhat counterintuitive, I have found that Claude is better at decompilation than disassembly.
- wtetzner 6mo agoAI models in general seem to get different assembly languages mixed up easily.
- PhilipRoman 6mo agoFor RE cases where I know the original compiler used (a bit harder on C compilers due to huge number of obscure optimization flags), I give it a feedback loop to write a function that compiles to the original machine code.
- geon 6mo agoYeah, I had perfect disassembly, since that's a purely mechanical process. I used da65, which worked reasonably well. But you don't get any function names that way, obviously. Claude would claim some random function were applying friction based on just a subtraction. And a variable that had 2 possible states was named player_id, when the game supports 1-8 players. It was a bit better when the memory addresses were known IO registers, but not by much.
- userbinator 6mo agoNaming is an area where LLMs are useful; but I'd still use a regular Java decompiler (there are quite a few of these around) for the actual decompilation part.
- charcircuit 6mo agoClaude will opt to use a regular Java decompiler too.
- RobMurray 6mo agoI got codex to vibe reverse engineer two devices from rom dumps recently - a talking timer that uses an 8051 cpu and a custom 5 bit audio format, and an ice cream van chime box that used a z80 and a ym2149 sound chip. Quite simple devices, but it did a great job. also made a web-based emulator for both. apparently WASM is hard, but I didn't notice.
- JimDabell 6mo agoThe same is true for iPhone apps (.ipa files). You can just unzip them.
- HelloUsername 6mo agoFor many things. Change .epub to .zip for example, you get html text and jpg images
- zekica 6mo ago.docx and .xlsx are also just zip files with XML and attachments. The bad thing is that the XML is Word's internal document structure serialized and behavior for some values is only defined in Microsoft's code.
- godman_8 6mo agoEven pk3 files from the id Tech engine are just zip files.
- karamanolev 6mo agoI've worked on docx and xlsx import/export and the public documentation for the formats was sufficient for normal documents (maybe excluding some very exotic features). That was ca 2010.
- saagarjha 6mo agoThey are typically encrypted, though.
- zffr 6mo agoWell the executable binaries inside IPAs are encrypted, but the IPA bundles themselves are typically unencrypted. You should be able to see unencrypted assets inside of them
- kotaKat 6mo agoSometimes you also find hidden things lurking accidentally left behind in IPAs and APKs that are nice and juicy and realize they've been shipped on Google Play/App Store for years. I've found everything from entire copies of internal company manuals to working test credentials for a physical place with a membership barcode in debug logs left inside the app from developers. Also sometimes changelogs left inside by accident which include things like "It hasn't been sanitized for outside consumption and thus should remain internal to <company>. Deliver it externally at your own risk of embarassment."
- morsch 6mo agoWhat a coincidence, I just got an email announcing that Breville intend to orphan my Joule sous vide stick: the existing app will stop working, the new app is only available the US and Canada and in parts of Europe. Live in another country? You're s.o.l., it wasn't officially sold there. You need a new account as well, hope you like the TOS. All of this for a device whose core functionality -- setting a target temperature, getting the current temperature and checking for error states -- is both trivial and has no inherent need for internet connectivity. I suppose I should be grateful they're still supporting a device that's like 10 years old. Caveat emptor (I got it as a gift). https://community.chefsteps.com/discussion/78615/joule-sous-vide-users-download-the-breville-cooking-app https://community.chefsteps.com/discussion/78615/joule-sous-...
- userbinator 6mo agoThis reads like satire: The ability to cook with or without WiFi anywhere, anytime.
- jgalt212 6mo agoJack Donaghy would ride this pitch right up to the C Suite. “Ambition is the willingness to kill the things you love and eat them to survive”
- esquivalience 6mo agoI'd pay to cook with WiFi. Just imagine the signal strength!
- userbinator 6mo agoWarning: Very rambly and somewhat incoherent video; tried to pay attention due to the topic being of interest, but very quickly gave up. EULAs be damned, even the DMCA has exceptions for RE in the name of interoperability and repair.
- TZubiri 6mo agoYou're going to the bathroom at an airport? You pee in a urinal you can't even take home. YOU OWN NOTHING
- mikkupikku 6mo agoYou're not taking all your shits in other people's bathrooms but soil your own instead? What a chump, lmao.
- bombcar 6mo ago"My boss makes a dollar, I make a dime. That's why I shit on company time." https://www.youtube.com/watch?v=-gQgx-XX7yw https://www.youtube.com/watch?v=-gQgx-XX7yw
- hsbauauvhabzb 6mo agoYou wouldn’t download a car
- AlienRobot 6mo agoBefore 1984 "take a taxi" meant you could actually take the taxi.
- bombcar 6mo agoApparently Taxis in New York used to all be ex-cop cars, and cop cars all had the same key, so one key would get you any taxi.
- 6mo ago
- albert_e 6mo agoHas anyone does this for VIZIO app that controls among other things their soundbars (circa 2019) I moved to a different country and the app is not on google play store in the new geography. Even when it is installed somehow it is absolutely unreliable in pairing or controlling the device. Wish I had time to go on a quest and reverse engineer and build my own better controller.
- love2read 6mo agoMight be worth taking a weekend day and letting claude code reverse engineer the apk (just download the apk off google) and then build an open source app with the functions you need
- elwebmaster 6mo agoWhy would you say "semi-legally"? Nothing "semi" here. What is "semi-legal" is making hardware e-waste by deciding it is "no longer supported". It is "semi" legal because it is legal under the corrupt political systems in most of the world but is criminal against humanity and the planet we all call home. In that sense if you can prevent e-waste trough any means you are a hero.
- kelvinjps10 6mo agoThe semi legal process it's reverse engineering the code. I watched the video she uses gidra and other descompilation tools. The video it's really good
- tosti 6mo agoMakes sense for an apk to be a zip file. Apps were supposed to be written in Java and that has always shipped binaries in zip files (jar or war).
- kelvinjps10 6mo agoI really liked the video. I didn't realize you could build programs for no longer supported hardware like this. I had a similar epifany with SVG, there was an image that I needed to keep editing and then one day I opened the SVG file and realized it's a very readable file and then just built a python script that would modify the SVG file.