Pwnd Blaster: Hacking your PC using your speaker without ever touching it
21–30 of 133 posts
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#22Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#23Can't wait to see a video from a half sloppy channel about this on my youtube front page in roughly 4 business days
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#24Any script kiddie with an LLM could write a worm that would spread through the supply chain, possibly even hacking speakers right on the factory floor and blasting Rickroll music or something similar.
It would be interesting to see if Creative would still claim that it "does not present a cybersecurity risk".
Edit: Bonus points for closing the security hole and disabling the ability to flash the firmware normally, so that the manufacturer would have to jailbreak the speakers in order to repair them.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#25Having a guaranteed audio channel makes this so much cooler for exploits -- you can exfiltrate over audio!! I love it. I wonder how many of these were sold. I also imagine based on Creative's response (this is fine) that many other devices in the class have similar security models in place. Def scary.
That would've been a cool PoC to work on as well, but seems a fair bit more complicated than the BadUSB-style attack I ended up doing. Would've had to do a lot more RE to figure out how to interact with the whole microphone subsystem, I think.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#26Why think so small? Perhaps the speaker itself can be used as the attacker. Any script kiddie with an LLM could write a worm that would spread through the supply chain, possibly even hacking speakers right on the factory floor and blasting Rickroll music or something similar. It would be interesting to see if Creative would still claim that it "does not present a cybersecurity risk". Edit: Bonus points for closing th…
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#27Thanks for sharing this. It’s a bit concerning that a consumer soundbar can receive unauthenticated firmware over BLE and then act like a BadUSB-style HID on the host. I’m not sure I agree with the vendor’s "no cybersecurity risk" assessment, considering how much access a trusted keyboard interface typically has.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#28Earlier quoted context omitted.
"You can just make it type words, what's the risk in that?" Makes you wonder what other peripheral companies out there are also operating with seemingly no security team. There must be other vulnerabilities like this just waiting to be discovered. My brother was awoken one morning at 2am because some neighborhood kids connected to his bluetooth speaker and blasted fart sounds on loop at max volume, and that's literal…
Oh yeah, for some reason the companies with the highest risk products seem to be the ones that care less about security. Don't even get me started with "smart" bulbs and cameras that each individually connect to your local network and the Internet. You have 5 lightbulbs? That's 5 different devices you need to track, keep updated and trust the in the vendor firmware's security.
Thankfully I don't think I've seen these for sale.
What sensors would they have that could be exploited by an attacker?
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#29It doesn't have bluetooth so thankfully something like this wouldn't happen with mine. It's crazy that there's no auth at all for Bluetooth. I was reversing my e-scooter recently (still WIP) and there was a whole bunch of authentication required before its app could control any of it. I am still not confident in its security though
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#30Earlier quoted context omitted.
Oh yeah, for some reason the companies with the highest risk products seem to be the ones that care less about security. Don't even get me started with "smart" bulbs and cameras that each individually connect to your local network and the Internet. You have 5 lightbulbs? That's 5 different devices you need to track, keep updated and trust the in the vendor firmware's security.
> "smart" bulbs Thankfully I don't think I've seen these for sale. What sensors would they have that could be exploited by an attacker?
I run my home automation network entirely offline, so anything that needs the internet doesn't get added to my cart. I just do not trust the security of these IoT vendors at all, and refuse to have their nonsense cluttering up my limited network bandwidth and causing unknown problems.
(Edit: maybe not obvious, this is in the "smart bulbs" product category. Regular bulbs are still much more common on store shelves, because why fix what isn't broken? Most people don't need to automate their light bulbs.)