Live data from Hacker News

Pwnd Blaster: Hacking your PC using your speaker without ever touching it

blog.nns.ee

41–50 of 133 posts

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#41
post #28
post #8

Earlier quoted context omitted.

Oh yeah, for some reason the companies with the highest risk products seem to be the ones that care less about security. Don't even get me started with "smart" bulbs and cameras that each individually connect to your local network and the Internet. You have 5 lightbulbs? That's 5 different devices you need to track, keep updated and trust the in the vendor firmware's security.

> "smart" bulbs Thankfully I don't think I've seen these for sale. What sensors would they have that could be exploited by an attacker?

You don't need to exploit sensors. If a compromised device is connected to the internet (because the vendor app requires it to set up and control), you can use it as a part of botnet with a nice residential IP address.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#42
post #7

The fact that the author had to publish a third-party patch because the vendor didn't consider it a vulnerability is not a great look

Are you surprised? Great hack by the author, the impact could be huge if someone is targeted, but overall the impact is very minimal. The vendor can't be bothered. For you to be a victim, you have to own this device, and your attack has to know that and be within a close proximity. Remember that fight club quote?

A = The number of speakers in the field. B = The probable rate of getting hacked. C = The average out-of-court settlement.

The Decision: If the cost of not doing a recall/fix is greater than the cost of a recall, they initiate a recall, yada yada yada (Note that the big cost is if people will stop buying future speakers, I think not)

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#43
post #4

>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.

I don't even remember what it is I have learned about Creative Labs in the past, but I went into this pretty sure that Creative Labs was going to fuck it up somehow.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#44
post #34
post #4

>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.

> SingCERT dropped the case I expect some dodgy company to try to shirk out of it, I don't expect a country's cybersecurity agency to do so

Morons they are.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#45

Earlier quoted context omitted.

I somehow hadn't even considered Bluetooth as an option when I read the headline, I immediately thought about INFILTRATING via audio, which also sounds insanely cool, but I couldn't possibly wrap my head around how an audio circuit would have to be set up and connected back to the cpu to pull that off. Exfiltrating via audio also brings to mind one of those devices I really wanted to build ~20 years ago that can list…

Let's not. There's enough overcomplicated nonsense examples of cybersecurity in movies as it is. If you could compromise a device via bluetooth, then you could exfiltrate data via bluetooth just as easily.

you could but I think the inclusion of lasers would make for a better spy / cyberpunk movie. Most "hacking" in movies are not realistic and for show but it being plausible is just a bonus.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#46
post #14

Thanks for sharing this. It’s a bit concerning that a consumer soundbar can receive unauthenticated firmware over BLE and then act like a BadUSB-style HID on the host. I’m not sure I agree with the vendor’s "no cybersecurity risk" assessment, considering how much access a trusted keyboard interface typically has.

The point is this is a speaker, not a keyboard. A keyboard usually takes manual input from a human or from a cat. This is a speaker that, after an unauthenticated connection, can act as if it’s a keyboard, which is an unintended functionality from the factory.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#47
post #4

>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.

probably not high enough risk to consider one on their list. First you need someone to be physically in there, 2nd the person needs to have a USB speaker connected, which means is likely a home. 3rd if it's a restaurant or something you need the thing to not play anything first with a lot of restaurant noise

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#48
post #4

>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.

"You can just make it type words, what's the risk in that?" Makes you wonder what other peripheral companies out there are also operating with seemingly no security team. There must be other vulnerabilities like this just waiting to be discovered. My brother was awoken one morning at 2am because some neighborhood kids connected to his bluetooth speaker and blasted fart sounds on loop at max volume, and that's literal…

> "You can just make it type words, what's the risk in that?"

I don't know if it's a useful answer to people saying this kind of stuff, but here are some examples of other attacks arbitrary USB pwn allows.

A USB device can appear as a network adapter and most OS will happily route all your traffic there, so your speaker can know which porn you're looking at!

It can also appear as a DisplayLink dongle, so it can see what's on the screen (it does require those specific drivers installed, and uh yeah, no way in hell it's technically possible on that MCU).

It can also turn it into a mouse jiggler to prevent lock screen (yes it's technically the same thing as your first point, just HID, but different angle).

It can also appear as a USB-storage: You don't trust the cloud, so you're writing those super secret documents to give to your boss on the USB drive you just plugged in? Surprise, you actually sent it to the attacker.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#49

Earlier quoted context omitted.

I somehow hadn't even considered Bluetooth as an option when I read the headline, I immediately thought about INFILTRATING via audio, which also sounds insanely cool, but I couldn't possibly wrap my head around how an audio circuit would have to be set up and connected back to the cpu to pull that off. Exfiltrating via audio also brings to mind one of those devices I really wanted to build ~20 years ago that can list…

Let's not. There's enough overcomplicated nonsense examples of cybersecurity in movies as it is. If you could compromise a device via bluetooth, then you could exfiltrate data via bluetooth just as easily.

It's not completely unrealistic angle, you could pwn the speaker when someone is traveling with it in public and then exfiltrate data when it's plugged in a secure environment and you can't connect anymore

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#50

Earlier quoted context omitted.

Flash worm into device and RMA it. Boom.

Just flash it in a shop and someone will send it back.

Make sure the new firmware slightly corrupts the audio for guaranteed high return rate.

To be extra malicious, if you can infect a connected pc make it propagate the worm to any similar device plugged into the pc over usb in the future.

Post reply on HN