The fact that the author had to publish a third-party patch because the vendor didn't consider it a vulnerability is not a great look
Are you surprised? Great hack by the author, the impact could be huge if someone is targeted, but overall the impact is very minimal. The vendor can't be bothered. For you to be a victim, you have to own this device, and your attack has to know that and be within a close proximity. Remember that fight club quote? A = The number of speakers in the field. B = The probable rate of getting hacked. C = The average out-of-…
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
91–100 of 133 posts
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#92Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#93Having a guaranteed audio channel makes this so much cooler for exploits -- you can exfiltrate over audio!! I love it. I wonder how many of these were sold. I also imagine based on Creative's response (this is fine) that many other devices in the class have similar security models in place. Def scary.
I somehow hadn't even considered Bluetooth as an option when I read the headline, I immediately thought about INFILTRATING via audio, which also sounds insanely cool, but I couldn't possibly wrap my head around how an audio circuit would have to be set up and connected back to the cpu to pull that off. Exfiltrating via audio also brings to mind one of those devices I really wanted to build ~20 years ago that can list…
Yeah the headline isn't as interesting when truthful. I've never owned a "speaker" that plugs into USB. Only the good old analog audio jack, or a USB to toslink adapter that is purely a one-way stream.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#94Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#95Earlier quoted context omitted.
> "smart" bulbs Thankfully I don't think I've seen these for sale. What sensors would they have that could be exploited by an attacker?
Shopping in the US, these have entirely replaced zigbee and other sensible mesh-based options at hardware stores like Home Depot and Lowes. The only exception I can find is Phillips Hue, and those seem to be slowly getting phased out with (sigh) a new "hubless" (requires wifi) series. I run my home automation network entirely offline, so anything that needs the internet doesn't get added to my cart. I just do not tru…
TV manufacturers might want to differ.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#96>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.
In reality, even if they did recognize the severity of this problem, they likely view the cost to remediate it as prohibitive, as it would involve reworking their whole weird janky system. So better to pretend they don’t have to deal with security.
If this product continues to sell in EU after Dec 2027, they will have an obligation to update.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#97Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#98>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.
Yeah, but we already sold the device, so it's someone else's problem. Now if they were paying us a subscription fee..
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#99In summary he figured out how to reflash arbitrary firmware on a Creative Sound Blaster Katana V2X soundbar via Bluetooth, without requiring any effective authentication or user interaction.
The soundbar is plugged directly into its host computer via USB, so by adding a descriptor to its firmware he made it recognized as a keyboard. From there it was straightforward to have it send keystrokes to the PC. The soundbar is equipped with a mic, so an adversary could turn it into an eavesdropping device.
He reported it to Creative and SingCERT. Neither him or SingCERT got any meaningful response from the company until 2 months later, eventually saying "they do not consider this to be a vulnerability, as it does not present a cybersecurity risk".
He released a firmware patcher that disables the flawed transport protocol. It's a bit of a sledgehammer that likely also breaks functionality of the official Bluetooth app, but seems like the best he could do without cooperation from the manufacturer.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#100People who love tech buy superdupersmart loudspeaker that will connect to every computer in their house; and also somehow control their superdupersmart coffee maker so they can have a fresh coffee brewed when some Miles Davis play. People who understand tech keep an axe next to their toaster.