Тёмный

i hacked my son's baby monitor, for science. 

Low Level
Подписаться 692 тыс.
Просмотров 249 тыс.
50% 1

My wife and I are having a baby. I, being a security researcher, have been tasked with the fun job of buying all the gadgets. I wanted to make sure that my son's baby monitor wasn't able to be hacked. Baby monitors have been the topic of TONS of security research over the last ten years.
In this video, we explore the board breakdown of the DXR-8 Pro by Infant Optics, and see if we can get a root shell on the device. This is the first video in a series of videos where I audit the security of the device and see if it's safe for me to use when little homie arrives.
Thumbnail Credit: ‪@t3dotgg‬
Video Inspired by ‪@BenEater‬ ( • Hacking a weird TV cen... )
🛒 GREAT BOOKS FOR THE LOWEST LEVEL🛒
Blue Fox: Arm Assembly Internals and Reverse Engineering: amzn.to/4394t87
Practical Reverse Engineering: x86, x64, ARM, Windows Kernel, Reversing Tools, and Obfuscation : amzn.to/3C1z4sk
Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software : amzn.to/3C1daFy
The Ghidra Book: The Definitive Guide: amzn.to/3WC2Vkg
🏫 COURSES 🏫
www.udemy.com/...
🔥🔥🔥 SOCIALS 🔥🔥🔥
Low Level Merch!: www.linktr.ee/...
Follow me on Twitter: / lowleveltweets
Follow me on Twitch: / lowlevellearning
Join me on Discord!: / discord

Опубликовано:

 

26 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 306   
@LowLevel-TV
@LowLevel-TV Год назад
Leave a comment and let me know what you think is going on inside that baby monitor! 🧐
@aliph-null
@aliph-null Год назад
Really awesome, what other devices would you think this method would work on?
@alexandrohdez3982
@alexandrohdez3982 Год назад
Congratulation for your baby. Great video ... can t wait for next video 👏💪
@espero_dev
@espero_dev Год назад
hey i need help i have a pastebin on my account but i fregot the pin to it is their a way i can brute force my way into a pin the code i have to brute force my way is is broken so can you help me it has some passwords and usernames of mine but i want to brute force my way is so i can download then and delete the pastebin
@1mkhlv
@1mkhlv Год назад
As a catholic pope who studied electronics before I'm grateful for this kind of stuff, looking forward to see the second part
@RankyTev
@RankyTev Год назад
Fun fact: you don’t have a son (jk)
@alancce3179
@alancce3179 Год назад
As a embed system student this looks a pretty cool content! Nice video, can't wait for the next one
@LowLevel-TV
@LowLevel-TV Год назад
More to come!
@1ksubswithonevideochallenge745
What is that?
@_edit146_
@_edit146_ Год назад
@@1ksubswithonevideochallenge745 a comment 🤓🤓🤓🤓🤓🤓🤓
@LeonBentrup
@LeonBentrup Год назад
I'd be careful connecting the 5V Arduino UNO TX pin to connect to a 3.3V serial interface. Some devices can tolerate 5V on their input (at least for a short while) but others may break. Use a level shifter if in doubt.
@kikihun9726
@kikihun9726 Год назад
Just a simple resistor can do it too.
@leakimiW
@leakimiW Год назад
All raspberry pi models have 3.3V UARTS. Use that as it is also more likely what the viewers have at home.
@MohammadIbrahim-sq1xn
@MohammadIbrahim-sq1xn Год назад
most of the time it doesn't do anything, but as a cautionary a resistor of 2k ohm can be used
@NoorquackerInd
@NoorquackerInd Год назад
@@leakimiW In this economy????
@dieSpinnt
@dieSpinnt Год назад
@@NoorquackerInd Yeah, completely absurd suggestions which may lead to a dead RPI/Arduino ... including the "test candidate". Like there are no such things like the generic Ali-Express 1$ USB to USART bridge (Or $3 ... on Amazon) with actually matching logic levels, which do NOT introduce additional 10 points of uncertainties, a rabbit-hole of other complexity and pre-programmed frustration. Yeah, why not use a 10 or 50 times more expensive device for the problem. Even the hobbyist needs such an USB to Serial adapter. Sooner or later. Very smart!:)
@emmyw6587
@emmyw6587 Год назад
So at work we have an intercom system we never use, one day a few months ago it starts making noises suddenly and intermittently as if like possessed. We walk around the rooms but no one is using it, then one of my coworkers points out that it’s probably picking up interference from a baby monitor. That was kind of more freaky to me, i dont think people using baby monitors would like that people at the public library can hear through the other end. Now forever freaked out by baby monitors.
@LennyMiller739
@LennyMiller739 Месяц назад
Back in the day you used to be able to get interference when using a home land line. You could hear other conversations faintly in the background, creepy af
@Catalyst8487
@Catalyst8487 Год назад
First off, congrats on the baby! I'm super excited to see the rest of this series. Low level stuff like this has always been fascinating to me, but I've never made the jump to learn it.
@joelpww
@joelpww Год назад
Safe to say if you're goong to these lengths, even without a monitor i think your baby will be safe
@Root3264
@Root3264 Год назад
"...but sometimes they leave it open to give the user a root shell to the device." I don't think this is intended by the manufacturer:D
@LowLevel-TV
@LowLevel-TV Год назад
Then ground your pins wtf
@mskiptr
@mskiptr Год назад
What's the point of locking that down tho? You need to spend engineering time to make the device exactly the same for most of your customers and annoying for a tiny fraction. The only "real" reasons I've seen is some false sense of security, desperate attempts at protecting Imaginary Property or misguided regulations. Full verified boot would be way too complex for any such use case. (and if it's really needed, please let the actual owner control it!)
@jesseparrish1993
@jesseparrish1993 Год назад
I wish I had seen this before having to guess how to do it myself using an Arduino to diagnose a lab scale. I was on windows using the Arduino software to view the serial communications, so I didn't wire the reset as you did. But this is a lot more elegant for troubleshooting serial data than all of that.
@LowLevel-TV
@LowLevel-TV Год назад
Arduinos make a solid little USB-TTL
@jesseparrish1993
@jesseparrish1993 Год назад
@@LowLevel-TV Right! Awkward as my approach was, it worked for automating a material feed into a mixer using the scale output. Not bad for a few bucks.
@309electronics5
@309electronics5 Год назад
i use a esp wich has a cp2102 3 dollar on aliexpress
@Chris-on5bt
@Chris-on5bt Год назад
Love this, I remember the first time I found out about the UART solder trick with a old WiFi router I had. When I pulled it off with Raspberry PI, some jumpers, and a half decent solder job I felt so much like a hacker. Please keep up the great content.
@tejaswiramesh
@tejaswiramesh Год назад
i wonder what he would have done if he bought a Bluetooth controlled adult pleasure toy..
@LowLevel-TV
@LowLevel-TV Год назад
😏
@wtfdoiputhere
@wtfdoiputhere Год назад
And ddos someone ;)
@aeghohloechu5022
@aeghohloechu5022 Год назад
Straight to the chess competition
@TexasTimelapse
@TexasTimelapse Год назад
Good project for a future video!
@elllieeeeeeeeeeeeeeeeeeeeeeeee
@@aeghohloechu5022 I get this reference
@wknd3822
@wknd3822 Год назад
Crazy that you put out such videos with such high quality. I like a lot that you show the whole process of you looking at it for the first time. Keep it up. P.S. If you would start a patreon where you put out exclusive content or videos I would definetly like to support you and the channel.
@nitro5247
@nitro5247 Год назад
I really appreciate that you go for accessibility and approachability with these videos. I’m going into computer engineering and hoping to focus on low-level stuff like this, so the fact that this content is so readily available makes that a lot easier. Thank you man
@25hawkeye
@25hawkeye Год назад
If you can’t get it to work: In the Arduino IDE, put Serial.begin( * baud rate * ) to get communication, and press the upload button. Most importantly, if the ATMega chip is stuck in reset mode you HAVE to put tx to tx and Rx to rx, because the serial converter switches it around for unknown reasons.
@csbluechip
@csbluechip Год назад
Great video ...DP and DM are probably USB data pins: data plus, data minus. I wonder what your PC sees on those pins?
@stefan3816
@stefan3816 Год назад
You got me all excited now. Can't wait for the next video!
@LowLevel-TV
@LowLevel-TV Год назад
Glad to hear it!
@typedef_
@typedef_ Год назад
2:53 it's not 3.3v because it's outputting stuff, but because a "logic 0" on UART is "high level". The signal gets inverted (and amplified) with a RS232 transceiver.
@minirop
@minirop Год назад
I was a tad worried when I saw the video length.... then "to be continued" hit. ☺
@jsaenzMusic
@jsaenzMusic Год назад
Congrats man! You are on a wonder, life long journey!
@hansformer9556
@hansformer9556 Год назад
UART TX being high doesn‘t mean it’s transmitting. The high voltage is the idle state for uart on the bus. But it is an indicator that it may not be disabled.
@PingPong-em5pg
@PingPong-em5pg Год назад
Lucky bastard. Arduino is 5V TTL and this device is 3.3V. You need a logic level converter otherwise you can break the chip in the device. Fortunately it looks like it worked (maybe because of breadboard cables resistance and chip not being susceptible) But one day you're not gonna be happy when the magic smoke comes out.
@dieSpinnt
@dieSpinnt Год назад
You are absolutely right with your concerns, but: RTFM! Resistor RN4a and RN4b (both 1k in serial to the ATMEGA8U2-MU USB to Serial Bridge, see Arduino Uno Reference Design) have saved Low Level Learnings precious cheeks:) LLL: ... just use the right tool for the job ... next time, or?:)
@blazed-space
@blazed-space Год назад
You put in more effort than most dads, good work! Much best wishes to you and your family!
@nicejs8194
@nicejs8194 Год назад
Did you try typing "sh" in that shell? My router has a similar command prompt (telnet is open for some reason) and typing sh on there just gave me a root shell
@abdox86
@abdox86 Год назад
Man every time you are blowing my mind, couple years ago I've seen two guys did the same trick using uart to root to a linux shell on TP-LINK router, and I've done it my self it's super exciting, but never seen RTOS kinda shell before, thanx man for the brilliant content you are making, cant wait for the next upload; Also Are you really married?? !!
@krassebewegtbilder
@krassebewegtbilder Год назад
I also recently found an old babycam which can't pair anymore, because there's no app for it. Maybe with this method, I can bring it to life again!
@jacobweiss1122
@jacobweiss1122 Год назад
This is awesome. I'm very excited for the next in the series.
@StudioGallifrey
@StudioGallifrey Год назад
Seriously this is the kind of content I subscribe for! More of this please!!
@yarpen26
@yarpen26 4 месяца назад
Hands down the one video of yours that's been hardest for me to follow, I just suck at embedded too much. With software, typically I can at least understand the purpose of a complex operation even if not entirely its workflow, here I'm just lost from the get-go. As embarrassing as it sounds, truth of the matter is, I just never learned about electricity. And without that, it's naturally hard to get anywhere beyond.
@kabelloseskabel7029
@kabelloseskabel7029 Год назад
3:56 there is a program in the Arduino forum to just set the uno to serial passthrough without the need for the reset line.
@someguy4915
@someguy4915 Год назад
That uses SoftSerial, which is usually 'good enough' for simple communication but doesn't work for higher speeds as the Arduino can't keep up. You use SoftSerial when you've chosen to use the wrong type of Arduino (one with only 1 UART) while for a project you need 2 UARTs, it's always a compromise. Here it would be much easier (and better) to just use a CP1202/CH340 USB UART with 3.3V logic levels. He's now using a 5V Arduino on a 3.3V device. This can damage both the Arduino and the baby monitor, only reason it didn't happen here is because there's a 2K resistor in series on the UART on the Arduino. Some cheaper Arduino clones might not have that. Basically this video shows how to use a much more expensive and not too suitable tool to do something that a $1 USB UART can do better...
@kabelloseskabel7029
@kabelloseskabel7029 Год назад
@@someguy4915 Yes thats also an option but i mean just to disable the Pullup/Pulldown resistors on D0, D1 so the microcontroller just ignores all serial sent to it.
@someguy4915
@someguy4915 Год назад
@@kabelloseskabel7029 I guess you could upload a program that sets D1 as an input, effectively disabling the TX from the Arduino and like you said putting it out of the way.
@ozdemirsalik
@ozdemirsalik Год назад
Asking the ultimate question: Can it run Doom though? 😊
@clehaxze
@clehaxze Год назад
I think SONIX is referring to the camera DSP manufacturer. My company also uses SONIX products for our camera. All I can legally say is. I hate their firmware. You probably can find UAF or data race bugs within a few hours.
@idontwantgoogletofindoutmy558
Congrats on your baby!!!
@CharlesVanNoland
@CharlesVanNoland Год назад
Root Amazon's new flying surveillance drone too! Congrats on the inbound fatherhood. Having kids was the best thing I ever did for my life.
@Ma1ne2
@Ma1ne2 Год назад
This was a lot of fun to watch m8! You did a lot of "basic" stuff lately, cool to see you dive deep into a much more advanced topic and share your more advanced knowledge with us, really appreciate it!
@Valery0p5
@Valery0p5 Год назад
On one hand, I'm sure you are going to find something vulnerable; on the other hand, it would be nice to see if they managed to do mitigate the risk enough for their treat model
@hikingpete
@hikingpete Год назад
DP/DN looks like USB. Don't know about CE, but I would guess E for enable.
@LowLevel-TV
@LowLevel-TV Год назад
I was thinking something SPI related for "chip enable"
@shimpleshequackutus
@shimpleshequackutus Год назад
the enrichment center reminds that altough fun and learning are the main purpose of this video, serious crimes may occur during the enrichment activities. please for the fun and safety of others, refrain from commiting such things made in this video. -alternate universe in some place
@MYNKS18
@MYNKS18 Год назад
I was planning to learn low level stuff for a very long time! This content is epic ❤️
@DaCaveman84
@DaCaveman84 Год назад
I’d love to see it be secured to a reasonable degree but as with most tech security it will likely have some holes. Curiously I wonder if manufacturers like this patch bugs and holes in the 3rd party software & libraries they use.
@MuhammadArshad
@MuhammadArshad Год назад
Wow, that was very informative and interesting. Cant find the second part???? Congratulations on becoming a parent 😊
@TimL_
@TimL_ Год назад
The most interesting video I have seen in a long time. It reminded me of the microcomputers and embedded systems courses I took in university. Please make more.
@TechSY730
@TechSY730 Год назад
Not going to lie, on the video intro I was looking for the "skip ad" button for a bit before I realized what was going on.
@TheGiba44
@TheGiba44 Год назад
Aren't UART pins usually high in idle state? In the first step when you measured the voltage on UART TX pin you said because it's 3v3 it's outputing data. I think the fact that it wasn't a stable 3v3 means there's some data on the line and if it was just 3v3 would mean there's no data on the line.
@k7iq
@k7iq 11 месяцев назад
Oh the connector... DP an DM should be the 2 USB date + and - lines. A UART will normally be high so that might be why you saw 3.3V. Just high. If data was being transmitted, I might expect a voltage between 0 and 3.3V and moving around some in voltage if the data being sent isn't too repetitive and too fast
@PawelKraszewski
@PawelKraszewski Год назад
The other 4 pins seem like USB... DP/DM lines (a.k.a D+ and D-) strongly suggests it.
@rileyparish5149
@rileyparish5149 Год назад
I'd be curious what kind of access you could get purely over a network connection (as malicious actors would likely not have physical access to the device).
@Tyler_0_
@Tyler_0_ Год назад
@4:00 Always connect the ground first!
@NathanEmmert
@NathanEmmert Год назад
Much better video title. I'm glad you changed it
@DanelonNicolas
@DanelonNicolas Год назад
it's super boring to be married with an expert, right? Look babe, I just bought this [whatever thing] Oh let me break down it so I can see what's inside 🤣
@thelateweeb2799
@thelateweeb2799 Год назад
Always good to check tbh
@packmandudefake
@packmandudefake Год назад
Exactly.
@xxslaysminecraftxx1094
@xxslaysminecraftxx1094 Год назад
more of this please, this is so interesting
@soapyboiman
@soapyboiman Год назад
DUDE THAT SHIRT LOOKS SICK!!!!!
@ad633f5
@ad633f5 Год назад
2:55, UART is active low, so 3.3V means it's not transmitting. *IrDA is active high
@gigachad8810
@gigachad8810 Год назад
6:14 "pls check uasge!" hahaha
@amongsusman
@amongsusman Год назад
Part 2 pleaseeee
@aaron-bieber
@aaron-bieber Год назад
I learned more about UART in the last 7 minutes than I ever thought I'd know.
@ΝίκοςΙστοσελίδα
Wait, isn't the Arduino Tx/Rx on 5V? Wouldn't that be a risk to the device? Also, is it possible that tying RST to GND damage the arduino by constantly resetting it?
@rikxianvanhoutenvanhouten1384
constantly tying rst to gnd is no problem if it would be people could kill their arduino by holding the reset button ofcourse its made idiot proof so noproblem
@ΝίκοςΙστοσελίδα
@@rikxianvanhoutenvanhouten1384 OK, that makes sense. Any idea about the other question?
@someguy4915
@someguy4915 Год назад
@@ΝίκοςΙστοσελίδα Tying RESET LOW won't damage the Arduino, though 5V UART on a 3.3V UART is never a good idea...
@ΝίκοςΙστοσελίδα
@@someguy4915 i find plausible that while the Arduino is resetting it keeps the UART at 3.3V. Though not likely, it isn't impossible
@someguy4915
@someguy4915 Год назад
@@ΝίκοςΙστοσελίδα Good point, hadn't thought about that so I just tested it and surprisingly, the Arduino does keep pulling TX to 5VDC even whilst the Arduino is held in RESET. This can both damage the 3.3VDC device but also can corrupt messages over the UART so in both cases terrible advice to use an Arduino like this as a USB-UART.
@KalamShellaby
@KalamShellaby Год назад
Good ol' baby stuff. I still have a Leapad from my childhood... now it's a PS1 emulator... I played FFIX for the first time on that thing, yes really!
@Cain532.
@Cain532. Год назад
Have you ever used a UART USB cable? I had someone show me how to use that on a PS4 and used the Arduino programmer to read output
@309electronics5
@309electronics5 Год назад
i think sonix reffers to the main processor chip (big chip) on the board often baby monitors use sonix media chips and the chip has a sonix logo on it so its not only the board. Often the serial console mentions the processor and not the board manufacturer because you comminucate with the main processor and not the board
@jm-alan
@jm-alan Год назад
This is exactly the kind of thing that makes me want to get out of backend engineering and into systems and platforms shit
@rawexploiterp6951
@rawexploiterp6951 Год назад
i think you could use ESP32/STM32 for this, Arduino UNO operates *5V* logic, which might damage the boards 3.3V logic. ESP32/STM32 have 3.3V logic and are much faster than UNO.
@chasefournier
@chasefournier Год назад
This is so awesome, thanks for sharing!!
@rafaelgcpp
@rafaelgcpp Год назад
I'd suggest DP and DM to be an USB port
@Gin-toki
@Gin-toki Год назад
Hardware hacking is something I find really interresting, I would love to see more of this type of content. Also what would you do in case the debug/serial port has been locked/closed? Also, have you heard about power analysis sidechannel attacks? suck as what the chipwhisperer tool can do?
@mikeuk1927
@mikeuk1927 Год назад
The Arduino trick is awesome. I'm currently in need for a USB UART and I've been delaying my project, because I own a USB UART interface, but I have it at the bottom on some box :p But now I can use an Arduino which I have ready and just use it's builtin interface. Now it sounds obvious, but this idea didn't occur to me. Thanks for the tip!
@LowLevel-TV
@LowLevel-TV Год назад
Glad I could help!
@vaisakhkm783
@vaisakhkm783 Год назад
yes for years i had Arduino and doing hardware stuff, even though i am just a soft. engg, I completely unaware about this.... really thanks for this... can use tx rx pin of raspberrypi to arudino to do the same 😅
@someguy4915
@someguy4915 Год назад
@@vaisakhkm783 Never connect an Arduino Uno and Raspberry Pi's UARTs like shown in this video though, you risk destroying your Raspberry Pi and Arduino... Use a newer 3.3V Arduino ('Arduino DUE' for example) or use a logic level shifter in between to prevent damage...
@nazstreamsini4870
@nazstreamsini4870 Год назад
excited for the next video!
@element4element4
@element4element4 Год назад
Had the "next video" come out? I see several videos after this one, but none seem related.
@thomasprovitt1806
@thomasprovitt1806 Год назад
Okay, I think you're taking this "Full-Stack" dev thing a bit to seriously. 😜 Really tho, cool video man!
@brecoldyls
@brecoldyls Год назад
Congratulations to your wife and you!
@FoxWolfWorld
@FoxWolfWorld Год назад
Criminal: “I’ve hacked your baby monitor and I’m watching your baby” Parent: “Cool, in that case imma get some sleep then. Lmk if the little shit wakes up.”
@LetsPlay-7D5
@LetsPlay-7D5 Год назад
New video idea: I played doom on a baby monitor
@meire62644
@meire62644 Год назад
Awesome video! One of my favourite RU-vidrs.
@VicGreenBitcoin
@VicGreenBitcoin Год назад
Bro can you still remember the analogue camera baby monitors, they where totally unsecured, everybody could watch it.
@GhostDancer-u8h
@GhostDancer-u8h 9 месяцев назад
Bravo!!! Behind the iron sights doing the lords work you are inspirational Thanks to you I'm able to educate myself on things I desire to invent Your simple accessible approaches and absolutely crystal clear and eloquent communication skills Lastly the confidence to go on camera I applaud you keep up the good work if I can ever make you art or do anything for you let me know with peace and love God bless
@LunaWuna
@LunaWuna Год назад
There are loads of 920mhz ISM analogue FM baby monitors where I live and it's possible to listen to with a $40 SDR. it's pretty impressive that people don't know they are bugging their own homes.
@GreenCrystalVR
@GreenCrystalVR Год назад
I love this chanel and wish he could post more content. I dont know much about electronics but I still see this as interesting ❤ 👍😄
@nothappyz
@nothappyz Год назад
Congrats for the baby ✨
@realtraphotography
@realtraphotography Год назад
Those Infant Optics ones pretty simple. Point to point with manually paired cameras (which is a bit wazoo, but we get to that later) and no connectivity. The open UART (or JTAG, SWD less so) is super common in those devices because they either dont care to close em, want it for debug, or they use it for some EOL manufacturing process. There is only one risk from having a reversible monitor for the user that I can think of off the cuff, it's gotta pair. Depending on where you live that may be a concern and it may not -- apartments/condos, maybe yeah, single family home - range isnt that great. That said, there's some hoops they'd need to jump through and that's where you should be looking. Is the pairing seed material when you push the button from the camera fairly unique? Does it broadcast its ID in some way that you could identify a camera you want to link a monitor to after the fact? If it's only during the initial handshake, cool, but how does it reconnect when it starts up? If the RF is in the clear (e.g. not just encoded or plain) you can patch in whatever auth material you want. What does that get you though? Cred online for showing it, but in reality, meh. People research baby monitors and safes and stuff for the emotional factor attached to it. Any malicious behavior where you have to be that close to the target is a really personal thing. I know it's a non-cool kid opinion, but patching a piece of firmware on a baby monitor to see inside a single room in your house would do...what exactly? Yeah, can see inside your house and that's a bit creepy, but if you live in an apartment, that person is your neighbor. Good bit of OSINT, RF analysis, and then firmware patching for your neighbor or someone that lives nearby to see in your kid's room? They know if you're home already. Live in a single family home? Not so much range wise. At that point any RF system unless you want to spend a bunch more for a legit security system (and even then they will have similar problems) isn't in the cards for you if you're concerned. BTW, the h264 is video encoding. Have fun!
@Sh4quille0atmeal
@Sh4quille0atmeal Год назад
- "I'm gonna try to hack into the US Government's database" ° "Hey, that's illegal!" - "...for science" ° "Oh, then it's okay"
@raevod6361
@raevod6361 Год назад
Please part two!
@MatthewSmithx
@MatthewSmithx Год назад
Dude! I’ve been futzing around with arduinos for over a decade and had no idea that you could boot loop loop it to use it as a ttl to usb. I’ve been using FT232RLs like a sucker
@LowLevel-TV
@LowLevel-TV Год назад
As the comments point out, just be careful with your TTL levels lol. Thanks for watching!
@MatthewSmithx
@MatthewSmithx Год назад
@@LowLevel-TV totally. I think the algorithm started serving me your content when I was trying to recover the firmware on a ASPEED2500 BMC that decided to corrupt itself. Once I managed to reflash it with an absurd DOS-over-serial setup, I got curious about what was in the firmware and needed to RU-vid learn some binwalk to see what was going on. Totally was able to get a root shell and turn on a bunch of other fun things because the shadow file revealed they used a woefully insecure password. Fun stuff.
@viperjay1
@viperjay1 Год назад
Cant wait until the next video!!!!
@ExpertOfNil
@ExpertOfNil Год назад
Congrats!
@n_kliesow
@n_kliesow Год назад
A rule is, EVERYTHING what has a processor (or a brain) in it can be hacked. This includes all computers and most humans.
@Stopinvadingmyhardware
@Stopinvadingmyhardware Год назад
You’d think designing one as a security auditor would be more effective
@donotprikel
@donotprikel Год назад
Is all the libraries the files on the chip? like the 6:14 libraries.
@WhyNotKevin
@WhyNotKevin Год назад
You left us on a cliffhanger as the video was getting really interesting... 😞
@lt3lt3lt3
@lt3lt3lt3 Год назад
More!!!
@MarcellJjr
@MarcellJjr Год назад
with a flipper you can utalize uart :)
@daniellim1212
@daniellim1212 Год назад
I mean the hardware layer is always assumed to be secure compared to the OS and application layer.. not a practical attack
@someguy4915
@someguy4915 Год назад
And yet the memory dump can expose software vulnerabilities that do pose a practical attack... Security is a case of layers, secure all layers or none of the layers are secure.
@vili3898
@vili3898 Год назад
Now, only one thing is missing, run doom on it
@mtalhakhalid1679
@mtalhakhalid1679 Год назад
Reading camera data and transmit it over similar to gow we setup epa01 or rsp32 with cli or flash formware to it using uart but witg embedded system awosm work i am fi.ilar with
@HTWwpzIuqaObMt
@HTWwpzIuqaObMt Год назад
Instead of an arduino, couldnt we use a usb to ttl devicd
@chancegriffin7398
@chancegriffin7398 Год назад
Hey, I have to take a X 86 assembly language class for my cs degree. Are there any courses you can recommend to help me learn better?
@luxdown7965
@luxdown7965 Год назад
Awesome, want to see more about hardware hacking
@WistrelChianti
@WistrelChianti Год назад
Interesting to know that an uno with a wire is an alternative to the FTDI jimmy I have
@WistrelChianti
@WistrelChianti Год назад
at least for 5v (although resistors are available)
@primosoma
@primosoma Год назад
What does your child think about living inside big brother? Anyway, great video. I look forward to the sequel.
@NonsensicalSpudz
@NonsensicalSpudz Год назад
wait so its a closed system, yet is also required to be completely torn down and photographed
@LucasHartmann
@LucasHartmann Год назад
Loving it but... An exposed serial console is NOT a security flaw. It is FREEDOM for the owner do do what he wants with the device. Supply chain attack is s thing, but that should be fixed im the supply chain, not by removing owner freedoms. That would make you sound like Apple...
@Tsukay.
@Tsukay. Год назад
Best youtube channel ever
Далее
i extracted the secrets of my son's baby monitor
8:01
Просмотров 452 тыс.
we need to talk about the new Linux exploit (9.9 CVSS)
13:50
Avaz Oxun - Yangisidan bor
14:29
Просмотров 285 тыс.
how do hackers exploit buffers that are too small?
8:25
Getting JTAG on the iPhone 15
9:10
Просмотров 334 тыс.
comparing GPUs to CPUs isn't fair
6:30
Просмотров 289 тыс.
Unlocking the Secrets of my Favorite Childhood Game.
8:10
Hacking a weird TV censoring device
20:59
Просмотров 3,1 млн
why do header files even exist?
10:53
Просмотров 408 тыс.
why are switch statements so HECKIN fast?
11:03
Просмотров 410 тыс.
Can ChatGPT Write an Exploit?
10:14
Просмотров 94 тыс.