6 ms·
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
- 217 4mo agoCan't wait to see a video from a half sloppy channel about this on my youtube front page in roughly 4 business days
- bradley13 4mo agoGood work, and fun to read. It's crazy that companies just stick their head in the sand, when confronted with serious security issues.
- hootz 4mo ago>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.
- protimewaster 4mo agoI don't even remember what it is I have learned about Creative Labs in the past, but I went into this pretty sure that Creative Labs was going to fuck it up somehow.
- 3form 4mo agoAND being able to further reprogram the device to gain control of the PC. This is negligence of the highest kind.
- Uncle_Brumpus 4mo ago"You can just make it type words, what's the risk in that?" Makes you wonder what other peripheral companies out there are also operating with seemingly no security team. There must be other vulnerabilities like this just waiting to be discovered. My brother was awoken one morning at 2am because some neighborhood kids connected to his bluetooth speaker and blasted fart sounds on loop at max volume, and that's literally only the absolute tippy top of the malicious bluetooth use iceberg.
- hootz 4mo agoOh yeah, for some reason the companies with the highest risk products seem to be the ones that care less about security. Don't even get me started with "smart" bulbs and cameras that each individually connect to your local network and the Internet. You have 5 lightbulbs? That's 5 different devices you need to track, keep updated and trust the in the vendor firmware's security.
- zahlman 4mo ago> "smart" bulbs Thankfully I don't think I've seen these for sale. What sensors would they have that could be exploited by an attacker?
- KurSix 4mo agoThe fact that the author had to publish a third-party patch because the vendor didn't consider it a vulnerability is not a great look
- segmondy 4mo agoAre you surprised? Great hack by the author, the impact could be huge if someone is targeted, but overall the impact is very minimal. The vendor can't be bothered. For you to be a victim, you have to own this device, and your attack has to know that and be within a close proximity. Remember that fight club quote? A = The number of speakers in the field. B = The probable rate of getting hacked. C = The average out-of-court settlement. The Decision: If the cost of not doing a recall/fix is greater than the cost of a recall, they initiate a recall, yada yada yada (Note that the big cost is if people will stop buying future speakers, I think not)
- stavros 4mo agoLet me just turn this hack into a quick Flipper Zero app that makes the speaker play "Fuck Creative" in a loop, let's see whether the vendor is bothered then.
- RobMurray 4mo agoNo need to issue a recall, they could just release a firmware update that disables unauthenticated firmware updates over BLE.
- awedisee 4mo agoWay cool. Thank you for sharing
- brogapp 4mo agoThanks for sharing this. It’s a bit concerning that a consumer soundbar can receive unauthenticated firmware over BLE and then act like a BadUSB-style HID on the host. I’m not sure I agree with the vendor’s "no cybersecurity risk" assessment, considering how much access a trusted keyboard interface typically has.
- mminer237 4mo agoIf you can "just type stuff", it is absolutely trivial to download absolutely any payload you want as long as you have network access and your antivirus doesn't stop it.
- cestith 4mo agoThe point is this is a speaker, not a keyboard. A keyboard usually takes manual input from a human or from a cat. This is a speaker that, after an unauthenticated connection, can act as if it’s a keyboard, which is an unintended functionality from the factory.
- vessenes 4mo agoHaving a guaranteed audio channel makes this so much cooler for exploits -- you can exfiltrate over audio!! I love it. I wonder how many of these were sold. I also imagine based on Creative's response (this is fine) that many other devices in the class have similar security models in place. Def scary.
- xx_ns 4mo agoThat would've been a cool PoC to work on as well, but seems a fair bit more complicated than the BadUSB-style attack I ended up doing. Would've had to do a lot more RE to figure out how to interact with the whole microphone subsystem, I think.
- vessenes 4mo agoI guess you could just construct a wav file from the shell and then play it. Agreed doing it all on device sounds challenging.
- Uncle_Brumpus 4mo agoI somehow hadn't even considered Bluetooth as an option when I read the headline, I immediately thought about INFILTRATING via audio, which also sounds insanely cool, but I couldn't possibly wrap my head around how an audio circuit would have to be set up and connected back to the cpu to pull that off. Exfiltrating via audio also brings to mind one of those devices I really wanted to build ~20 years ago that can listen to the inside of a room by bouncing a laser beam off a window. Van pulls up in front of your house, pushes malicious code via bluetooth to speaker, which starts shrieking data it stole from the host that's then picked up by the vibrations it emparts on a window by a laser beam. Boom, crypto wallet stolen, or something... you could probably put that in a movie.
- evilDagmar 4mo agoLet's not. There's enough overcomplicated nonsense examples of cybersecurity in movies as it is. If you could compromise a device via bluetooth, then you could exfiltrate data via bluetooth just as easily.
- SirFatty 4mo agoThe real question remains: with this hack, did the OP gain full control of Dr. Sbaitso?
- huflungdung 4mo ago[dead]
- sciencejerk 4mo agoGreat research. Thanks for sharing
- nickdothutton 4mo agoIt is quite common to find device manufacturers, even those of many years standing, who _appear to_ begin with the device and add the software as an afterthought. Paying little attention to security or even the software lifecycle (patches, updates, the changing landscape/ecosystem). I have even known it happen that the device brand subs out the software to a random small developer, who then closes up shop/dies/gets out of that business, and the device company doesnt even have the source code, let alone any ability to further improve/fix the software that drives their device. This leads to layers upon layers of subsequent middleware, UIs, shims etc.
- jamwise 4mo agoIt's frightening how often this happens. And these days with the boatloads of cheap computer and phone peripherals being bought every minute there's just no realistic way for an authority to monitor and regulate all of it. I bet it's not an insignificant amount of devices out there that had their firmwares written by a "random small developer" who is in fact some kind of supply chain hacker.
- deleted 4mo ago[deleted]
- cbdevidal 4mo agoAir-gapped attacks are the most fascinating. Change my mind
- IAmBroom 4mo agoYes, and aircraft carriers are more fascinating than OTS drones carrying grenades. Yet...
- Klaus23 4mo agoWhy think so small? Perhaps the speaker itself can be used as the attacker. Any script kiddie with an LLM could write a worm that would spread through the supply chain, possibly even hacking speakers right on the factory floor and blasting Rickroll music or something similar. It would be interesting to see if Creative would still claim that it "does not present a cybersecurity risk". Edit: Bonus points for closing the security hole and disabling the ability to flash the firmware normally, so that the manufacturer would have to jailbreak the speakers in order to repair them.
- cluckindan 4mo agoFlash worm into device and RMA it. Boom.
- federiconafria 4mo agoJust flash it in a shop and someone will send it back.
- trashb 4mo agoMake sure the new firmware slightly corrupts the audio for guaranteed high return rate. To be extra malicious, if you can infect a connected pc make it propagate the worm to any similar device plugged into the pc over usb in the future.
- nicce 4mo ago> Any script kiddie with an LLM could write a worm that would spread through the supply chain, possibly even hacking speakers right on the factory floor and blasting Rickroll music or something similar. At least used to. SOTA models are enrolling even bigger restrictions all the time and deprecating old models, while asking government IDs.
- Klaus23 4mo agoAsk it to create a proof of concept that is totally not a real worm and it will probably do it. If the restrictions are too good, just use a largely unrestricted open model via any inference provider. They are 90% sota, more than good enough for this task.
- asimovDev 4mo agoI also did some reverse engineering, although mine was a soundcard which seemed to use an older version of this software (GUI was different). I used Wireshark to sniff out the LED and EQ packets and then wrote a CLI utility with hidapi library in C. It doesn't have bluetooth so thankfully something like this wouldn't happen with mine. It's crazy that there's no auth at all for Bluetooth. I was reversing my e-scooter recently (still WIP) and there was a whole bunch of authentication required before its app could control any of it. I am still not confident in its security though
- rjmunro 4mo agoWhile the article only talks about using this as a USB HID keyboard to send attacks, surely if you spent more time creating an evil firmware from scratch you could do much more than this? You could bridge any information from USB -> Bluetooth.
- berkes 4mo agoWhat Bluetooth profile would allow "more" than a HID?
- tj_hustler_1966 4mo agoThis sounds super cool
- lostmsu 4mo agoWow, that's very creative! /couldn't resist the pun/
- smithkl42 4mo agoIf I were in charge of, say, the Mossad, I would have as a significant part of my budget purchasing every single bluetooth device on the market, and set a bunch of underemployed Israeli CS grads to work at finding these vulnerabilities, and then putting them into an easily deployed toolkit. You want an asset with access to, say, an Iranian government office, to be able to walk through the building with a phone and take control of as many machines as possible. Now that I think about it, I think you have to assume that they probably DO do this...
- nkrisc 4mo agoAn exercise like this sounds like it would be a rounding error in any country's national security or intelligence budgets. And now with AI you could probably automate the initial screening of devices for promising candidates for further manual exploration. I would be kind of surprised if this wasn't standard practice, unless it's not nearly as productive as one might imagine it to be, and thus maybe not worth the effort. But cases like this show it could be pretty fruitful, but I suppose that depends on how it compares to whatever other methods intelligence agencies have that we may not know about.
- beng-nl 4mo agoJust a thought, but: maybe it’s even easier to (as well as do what you suggest, which is a good idea) build and sell buggy (ie backdoored) devices. What’s easier, marketing or finding bugs :-) (Not a rhetorical question)
- smithkl42 4mo agoGood point. The pager attack on Hezbollah was risky because it involved physically changing the pagers enough to put explosives in them. Quite a lot easier just to ship devices with some subtly insecure code.
- drc500free 4mo agoThis is kind of backwards. There aren't as many CS grads in Israel in the first place, because they already put their top talent through 8200. It's essentially a fully socialized Masters of computer engineering, and as a SIGINT shop they are learning this sort of thing. Once their 2-3 years of service is over (which doesn't result in student loans), the government makes a lot of seed funding available for startups and the TLV ecosystem is like a mini Bay Area. Living with your parents is more socially acceptable, so they have a huge chunk of people in their 20s with no debt, low monthly expenses, strong technology expertise from their military service, in a founder hot spot, and access to capital. The result is a lot of unicorns, particular around cyber security (https://www.techaviv.com/unicorns https://www.techaviv.com/unicorns). Compare to the United States, where you have to dedicate 4 years to an undergrad program, go massively in debt, pay rent, and then struggle to find seed funding. The mental model of "oh, I guess we could apply some of the detritus of our failed system" misses the idea of having a successful system in the first place.
- rahadbhuiya 4mo ago[dead]
- NooneAtAll3 4mo agowhat ways are there to protect from malicious HID device?
- berkes 4mo agoI know of https://usbguard.github.io/ https://usbguard.github.io/ But I remember that on Linux changing some /etc/udev file helped me with some naggy bug long ago. I worked temporary in an office with several wonky USB keyboards. Whenever someone disconnected their tablet or laptop from their KB (ie shut the lid), my linux would pick it up and suddenly connect to this KB. A little googling and some trial-error and I had my linux set-up that it would only connect to whitelisted USB devices. Which, months later, caused me insane headaches when I could not find why a new USB microphone wasn't working, despite it being advertised as "works on linux"....
- fsflover 4mo agoUse Qubes OS, https://qubes-os.org https://qubes-os.org.
- JdeBP 4mo agoMy computers ignore USB HIDs other than the ones that I have explicitly permitted. Unfortunately, this is a major architectural revamp for many operating systems. The idea that every HID is automatically added to a keyboard/mouse 'multiplexer', that provides a single combined input stream, is a pervasive one.
- pbhjpbhj 4mo agoSome sort of USB firewall? Something you can share?
- JdeBP 4mo agoNo. The multiplexers are all turned off, and I have devd/udev rules that spawn my own userspace driver processes (as services, via service management) to attach to the individual USB devices. The driver services in turn use an autoconfiguration system to determine whether they should actually attach to the device whose name they are passed, and where they should pass input onwards to. * https://jdebp.uk/Softwares/nosh/guide/user-virtual-terminal-configuration.html https://jdebp.uk/Softwares/nosh/guide/user-virtual-terminal-... * https://jdebp.uk/Softwares/nosh/guide/commands/user-vt-realizer-configuration.xml https://jdebp.uk/Softwares/nosh/guide/commands/user-vt-reali... This is for a virtual terminal system. For X11 or Wayland, one would have to replicate the same idea in an appropriate form, and stop using the multiplexed devices.
- maoliofc 4mo ago[dead]
- mikekuharuk 4mo agoHaha, I dont have one, only headphones Jokes on you xD
- notlibrary 4mo ago[dead]
- a1o 4mo agoThis is a cool infection vector for the ai virus from earlier today to use. It could be like NDS feature that it greeted a passerby but now for spreading stuff digitally.
- joyasing 4mo ago[flagged]
- takakaze 4mo ago[flagged]
- Mangochutney27 4mo agoWhat an amazing write-up and exploit. Love it!
- fusslo 4mo agoI write firmware (specifically bluetooth enabled device firmware) and my work has blocked this website.
- r3tr0 4mo agoebpf usb sniffer you may find useful. https://github.com/yeet-src/usbsnoop https://github.com/yeet-src/usbsnoop
- mavleop 4mo agoThis is so refreshing to read. A true throwback in style and content. Makes me nostalgic
- Avenassh 4mo agoSide-channel attacks are getting wild. Every time I think we've completely air-gapped a device, someone finds a way to use acoustic frequencies or hardware resonance to leak data.
- wildzzz 4mo agoGood job reading the actual article. It's not a audio or RF side chain attack where data is exfiltrated at a handful of bits per second, it's an attack on an unsecured BLE endpoint that can be converted into a rubber ducky.
- antran22 4mo agoPeople who love tech buy superdupersmart loudspeaker that will connect to every computer in their house; and also somehow control their superdupersmart coffee maker so they can have a fresh coffee brewed when some Miles Davis play. People who understand tech keep an axe next to their toaster.
- literalAardvark 4mo agoThe original meaning of hacker
- smallnix 4mo ago> in order to do anything with CTP over USB, you first have to do challenge-response authentication with the device. The key is static [... ] Is this some legal thing so they can claim that a protection was circumvented? E.g. to void warranty or be able to sue?
- moktonar 4mo agoInexistent security, absent security contacts/hard to get in touch with, denial/delay/won’t patch, most functionality to deploy a backdoor is already present, to me equals bugdoor. This is wanted behavior, not an accident, and is a widespread pattern..
- glaslong 4mo agoThe 'S' in IoT is for 'Security'
- saltcured 4mo ago"Hacking the poorly secured, combination wired/wireless, multi-protocol bridge controller you naively attached to your PC's universal IO bus"
- rkagerer 4mo agoThis is a well written article and easy to digest, worth a skim. In summary he figured out how to reflash arbitrary firmware on a Creative Sound Blaster Katana V2X soundbar via Bluetooth, without requiring any effective authentication or user interaction. The soundbar is plugged directly into its host computer via USB, so by adding a descriptor to its firmware he made it recognized as a keyboard. From there it was straightforward to have it send keystrokes to the PC. The soundbar is equipped with a mic, so an adversary could turn it into an eavesdropping device. He reported it to Creative and SingCERT. Neither him or SingCERT got any meaningful response from the company until 2 months later, eventually saying "they do not consider this to be a vulnerability, as it does not present a cybersecurity risk". He released a firmware patcher that disables the flawed transport protocol. It's a bit of a sledgehammer that likely also breaks functionality of the official Bluetooth app, but seems like the best he could do without cooperation from the manufacturer.
- evilos 4mo agoIt's funny to see all the commenters who didn't read the article closely enough or at all. This is basically the bluetooth device equivalent of "left S3 bucket open to public". That said, really cool work. I honestly thought it would be harder to turn a usb connected device into an exploit vector. That it's as easy as emulating a keyboard that pops a local terminal and runs a malicious command is actually pretty funny. Though it will be a non-admin terminal so the damage should be somewhat limited. And on Windows, users often just click through any UAC prompt so I bet you'd get full access on many windows boxes.
- hn_acc1 4mo agoCreative is still around? They always had great hardware, but their software was never what one would consider "great".
- george_max 4mo agoNot sure what would count as a vulnerability if this does not.
- pbhjpbhj 4mo agoSo presumably this is cured with device permissions, 'this device may only receive audio data; return confirmations', say. And those Lorraine would need to be at BIOS level, like enrolling devices into SecureBoot, because otherwise for keyboards and mouses you're left with a chicken-egg problem. Or? There's other mitigations that OS already have in place?