Live data from Hacker News

Can you get root with only a cigarette lighter? (2024)

da.vidbuchanan.co.uk

11–20 of 42 posts

Re: Can you get root with only a cigarette lighter? (2024)

#11
post #8

my prediction before reading is that they're using the piezo sparker to beat the DUT over the head with a big EMF spike Edit: Nailed it!

I thought they were going to just heat a chip to increase the overall error rate

Be it eletric or thermal, i came here for fried hardware and left disappointed. Now i have to wrangle my curiosity to what happens when you lighter-spark a usb port for the rest of the day.

Re: Can you get root with only a cigarette lighter? (2024)

#15

Earlier quoted context omitted.

If it's intel, you can fry an egg for sure.

The ol' Black MacBook Cooktop...

In combination with a weighing scale (https://github.com/KrishKrosh/TrackWeight), you have everything you could ask for in a portable food processor.

Re: Can you get root with only a cigarette lighter? (2024)

#17
Answers to some of the questions at the end, from future me:

- It also works on LPDDR5, LPDDR4

- Yes, it works on ARM platforms (at least, the ones I tried).

- The simplest way to trigger similar faults electronically is via a high-speed mux IC, as described in https://stefan-gloor.ch/ddr5 (chipshouter also works, but is less elegant imho!)

- Yes, you can get webkit addrof/fakeobj primitives like this, although I didn't write an end-to-end exploit.

- You can pwn nintendo switch kernel with an adjusted exploit strategy, but the same adjusted strategy does not work on Switch 2, due to memory encryption (one bitflip corrupts a whole cache line). But other strategies may be possible? (notably, it is possible to block a whole write operation from happening at all - see also https://rdist.root.org/2010/01/27/how-the-ps3-hypervisor-was... )

Re: Can you get root with only a cigarette lighter? (2024)

#18

my prediction before reading is that they're using the piezo sparker to beat the DUT over the head with a big EMF spike Edit: Nailed it!

Yeah but the devil is in the details ;)

It's not like you can randomly spike stuff and achieve an exploit

Re: Can you get root with only a cigarette lighter? (2024)

#19
post #17

Answers to some of the questions at the end, from future me: - It also works on LPDDR5, LPDDR4 - Yes, it works on ARM platforms (at least, the ones I tried). - The simplest way to trigger similar faults electronically is via a high-speed mux IC, as described in https://stefan-gloor.ch/ddr5 (chipshouter also works, but is less elegant imho!) - Yes, you can get webkit addrof/fakeobj primitives like this, although I did…

I also spent a long time trying to do the glitching with a mosfet, but never got it to work. I couldn't get enough drive strength to actually glitch anything, without messing with the delicate capacitance+impedance tolerances of the bus.

Re: Can you get root with only a cigarette lighter? (2024)

#20
post #6

Yes. We do this in Australia, around the bars and pubs getting a root with only a cigarette lighter is a classic move.

I had an australian colleague who found it endlessly funny that we pronounced "router" as "rooter" instead of their "rowter". statements like "If that happens the system will root the packets via the rooter first" was met with much giggling
Post reply on HN