| 1 | 00:00:00.000-->00:00:05.005
|
|---|
| 2 | Alright, hey everybody, this is
|
|---|
| 3 | Ang Cui and Jaden Quitaria. They
|
|---|
| 4 | wanna talk to ya about a monitor
|
|---|
| 5 |
|
|---|
| 6 | 00:00:07.140-->00:00:12.145
|
|---|
| 7 | darkly. Give 'em a round, can
|
|---|
| 8 | we, come on congratulate them
|
|---|
| 9 | for getting up here. [laughter &
|
|---|
| 10 |
|
|---|
| 11 | 00:00:17.818-->00:00:21.488
|
|---|
| 12 | applause] >>Vegas! [applause]
|
|---|
| 13 | Thank you. Alright we're going
|
|---|
| 14 | to get stuff showing on the
|
|---|
| 15 |
|
|---|
| 16 | 00:00:21.488-->00:00:26.493
|
|---|
| 17 | monitors. And it's all going to
|
|---|
| 18 | work. Alright. [clears
|
|---|
| 19 | throat/sighs] Okay! So uh this
|
|---|
| 20 |
|
|---|
| 21 | 00:00:32.766-->00:00:37.771
|
|---|
| 22 | is work that we've done for the
|
|---|
| 23 | last two years in our spare
|
|---|
| 24 | time. So uh I wanted to tell you
|
|---|
| 25 |
|
|---|
| 26 | 00:00:37.771-->00:00:43.744
|
|---|
| 27 | this story of how we did it and
|
|---|
| 28 | uh what we found uh over that
|
|---|
| 29 | time. So we have a big cast of
|
|---|
| 30 |
|
|---|
| 31 | 00:00:43.744-->00:00:49.416
|
|---|
| 32 | characters okay. My name is Ang.
|
|---|
| 33 | Jaden is underneath this table
|
|---|
| 34 | he's will sometime reappear for
|
|---|
| 35 |
|
|---|
| 36 | 00:00:49.416-->00:00:55.455
|
|---|
| 37 | this talk. Uh we have a very
|
|---|
| 38 | strong Canadian in Francois uh
|
|---|
| 39 | the who we worked with but he
|
|---|
| 40 |
|
|---|
| 41 | 00:00:55.455-->00:01:01.261
|
|---|
| 42 | couldn't show up to this. Today
|
|---|
| 43 | we have uh person named Igor
|
|---|
| 44 | which we'll talk about. We have
|
|---|
| 45 |
|
|---|
| 46 | 00:01:01.261-->00:01:07.100
|
|---|
| 47 | a very uh concerned area man
|
|---|
| 48 | named Chris. And the last but
|
|---|
| 49 | definitely not least we have
|
|---|
| 50 |
|
|---|
| 51 | 00:01:07.100-->00:01:11.004
|
|---|
| 52 | area man of concern named
|
|---|
| 53 | Shakeve. And if you see his face
|
|---|
| 54 | in your monitor things are
|
|---|
| 55 |
|
|---|
| 56 | 00:01:11.004-->00:01:16.043
|
|---|
| 57 | really going to be bad and he's
|
|---|
| 58 | actually in the in the audience
|
|---|
| 59 | today. So watch out. Alright! So
|
|---|
| 60 |
|
|---|
| 61 | 00:01:16.043-->00:01:21.014
|
|---|
| 62 | today's primary main objective
|
|---|
| 63 | is to go after these little
|
|---|
| 64 | devices that you connect to your
|
|---|
| 65 |
|
|---|
| 66 | 00:01:21.014-->00:01:25.319
|
|---|
| 67 | computer that puts pixels up on
|
|---|
| 68 | your monitors. We all know what
|
|---|
| 69 | they are. Okay and uh and
|
|---|
| 70 |
|
|---|
| 71 | 00:01:25.319-->00:01:29.756
|
|---|
| 72 | motivation in why we are
|
|---|
| 73 | interested in monitors. You know
|
|---|
| 74 | a good hacker right is a lazy
|
|---|
| 75 |
|
|---|
| 76 | 00:01:29.756-->00:01:36.697
|
|---|
| 77 | hacker so if you think about
|
|---|
| 78 | this page right [clears throat]
|
|---|
| 79 | uh When you see this page you
|
|---|
| 80 |
|
|---|
| 81 | 00:01:36.697-->00:01:41.168
|
|---|
| 82 | think you're talking to your
|
|---|
| 83 | bank right? The little green
|
|---|
| 84 | pixels on the uh left side here
|
|---|
| 85 |
|
|---|
| 86 | 00:01:41.168-->00:01:46.506
|
|---|
| 87 | right makes you think this is an
|
|---|
| 88 | encrypted communication and your
|
|---|
| 89 | safe. Now think about all the
|
|---|
| 90 |
|
|---|
| 91 | 00:01:46.506-->00:01:51.878
|
|---|
| 92 | resources and the research and
|
|---|
| 93 | and the the money we spent to
|
|---|
| 94 | create this infrastructure uh so
|
|---|
| 95 |
|
|---|
| 96 | 00:01:51.878-->00:01:55.682
|
|---|
| 97 | that we can have this internet
|
|---|
| 98 | with you know with SSL right
|
|---|
| 99 | that will show you these green
|
|---|
| 100 |
|
|---|
| 101 | 00:01:55.682-->00:01:59.319
|
|---|
| 102 | pixels. You know you have to
|
|---|
| 103 | secure the browser you have to
|
|---|
| 104 | secure the kernel you have to
|
|---|
| 105 |
|
|---|
| 106 | 00:01:59.319-->00:02:02.689
|
|---|
| 107 | secure the you know the
|
|---|
| 108 | infrastructure for doing
|
|---|
| 109 | certificates and all this other
|
|---|
| 110 |
|
|---|
| 111 | 00:02:02.689-->00:02:07.194
|
|---|
| 112 | stuff. I would say we've
|
|---|
| 113 | probably cumulatively probably
|
|---|
| 114 | invested over a billion dollars
|
|---|
| 115 |
|
|---|
| 116 | 00:02:07.194-->00:02:11.431
|
|---|
| 117 | to make this infrastructure
|
|---|
| 118 | exist today the way it does.
|
|---|
| 119 | Okay, so let's look at the
|
|---|
| 120 |
|
|---|
| 121 | 00:02:11.431-->00:02:15.669
|
|---|
| 122 | content in which we see this
|
|---|
| 123 | website. Okay? So, we view it
|
|---|
| 124 | through this tiny little
|
|---|
| 125 |
|
|---|
| 126 | 00:02:15.669-->00:02:19.840
|
|---|
| 127 | computer with a big screen on it
|
|---|
| 128 | that we call the monitor.
|
|---|
| 129 | Alright so the lazy hacker would
|
|---|
| 130 |
|
|---|
| 131 | 00:02:19.840-->00:02:25.912
|
|---|
| 132 | say, you know if I wanted to
|
|---|
| 133 | break the pixels that show me
|
|---|
| 134 | green, I could either break the
|
|---|
| 135 |
|
|---|
| 136 | 00:02:25.912-->00:02:30.183
|
|---|
| 137 | security for the [indiscernible]
|
|---|
| 138 | you know built with a billion
|
|---|
| 139 | dollars of investment or
|
|---|
| 140 |
|
|---|
| 141 | 00:02:30.183-->00:02:34.588
|
|---|
| 142 | whatever the security is inside
|
|---|
| 143 | this little monitor right? And
|
|---|
| 144 | you know maybe it's not so great
|
|---|
| 145 |
|
|---|
| 146 | 00:02:34.588-->00:02:39.593
|
|---|
| 147 | and that's what we're here to
|
|---|
| 148 | talk about. Okay so this whole
|
|---|
| 149 | thing started bank in 2015 when
|
|---|
| 150 |
|
|---|
| 151 | 00:02:42.529-->00:02:48.735
|
|---|
| 152 | uh Jaden and I got really sweet
|
|---|
| 153 | new monitors and we bought these
|
|---|
| 154 | things and we said Wow! This is
|
|---|
| 155 |
|
|---|
| 156 | 00:02:48.735-->00:02:53.507
|
|---|
| 157 | beautiful and uh as soon as we
|
|---|
| 158 | plugged it in you know we
|
|---|
| 159 | noticed that this really curious
|
|---|
| 160 |
|
|---|
| 161 | 00:02:53.507-->00:02:59.579
|
|---|
| 162 | thing right the USB device on it
|
|---|
| 163 | said you know TUSB34 pin boot
|
|---|
| 164 | device right? And USB 23C
|
|---|
| 165 |
|
|---|
| 166 | 00:02:59.579-->00:03:03.750
|
|---|
| 167 | solution. So we looked at that
|
|---|
| 168 | and we said ah that's very
|
|---|
| 169 | interesting, right? So like a
|
|---|
| 170 |
|
|---|
| 171 | 00:03:03.750-->00:03:10.090
|
|---|
| 172 | minute of Googling later we
|
|---|
| 173 | found this really useful uh Dell
|
|---|
| 174 | forum uh response by Chris uh so
|
|---|
| 175 |
|
|---|
| 176 | 00:03:10.090-->00:03:14.761
|
|---|
| 177 | somebody asked, Hey you know I
|
|---|
| 178 | uh I don't have a driver for
|
|---|
| 179 | this you know T34 you know
|
|---|
| 180 |
|
|---|
| 181 | 00:03:14.761-->00:03:18.765
|
|---|
| 182 | [indiscernible] boot device you
|
|---|
| 183 | know what is it for? Is it a
|
|---|
| 184 | problem? And Chris from Dell
|
|---|
| 185 |
|
|---|
| 186 | 00:03:18.765-->00:03:22.135
|
|---|
| 187 | says, Eh don't worry about it.
|
|---|
| 188 | You know that driver is only
|
|---|
| 189 | there for firmware updates which
|
|---|
| 190 |
|
|---|
| 191 | 00:03:22.135-->00:03:26.306
|
|---|
| 192 | we'll probably never do. Right?
|
|---|
| 193 | But if you want the driver here
|
|---|
| 194 | it is. And I looked at that and
|
|---|
| 195 |
|
|---|
| 196 | 00:03:26.306-->00:03:32.279
|
|---|
| 197 | said how interesting. Right? So
|
|---|
| 198 | Jaden and I started thinking and
|
|---|
| 199 | I say, Hey Jaden let's tear down
|
|---|
| 200 |
|
|---|
| 201 | 00:03:32.279-->00:03:36.349
|
|---|
| 202 | this 34-inch monitor that we
|
|---|
| 203 | have laying around. >>Well we
|
|---|
| 204 | already have awesome monitors.
|
|---|
| 205 |
|
|---|
| 206 | 00:03:36.349-->00:03:40.454
|
|---|
| 207 | Uh why don't we take that uh
|
|---|
| 208 | that 3-quarter inch which is not
|
|---|
| 209 | doing anything? >>Yea and then
|
|---|
| 210 |
|
|---|
| 211 | 00:03:40.454-->00:03:44.491
|
|---|
| 212 | we're cool with this but then
|
|---|
| 213 | Chris hears this right you know
|
|---|
| 214 | nearby and he says like these
|
|---|
| 215 |
|
|---|
| 216 | 00:03:44.491-->00:03:48.495
|
|---|
| 217 | monsters have no heart. Like
|
|---|
| 218 | there's no end to their
|
|---|
| 219 | savagery. And I also have a
|
|---|
| 220 |
|
|---|
| 221 | 00:03:48.495-->00:03:54.167
|
|---|
| 222 | million VIM plug-ins and my life
|
|---|
| 223 | is sad. Right? [laughter] And
|
|---|
| 224 | and we said aww this is really
|
|---|
| 225 |
|
|---|
| 226 | 00:03:54.167-->00:03:57.804
|
|---|
| 227 | the saddest thing I've ever seen
|
|---|
| 228 | so what are we going to find
|
|---|
| 229 | these monitors? >>Why don't we
|
|---|
| 230 |
|
|---|
| 231 | 00:03:57.804-->00:04:01.241
|
|---|
| 232 | go to the interns? They don't
|
|---|
| 233 | need monitors. >>Yeah we can
|
|---|
| 234 | >>They have like 24 of them
|
|---|
| 235 |
|
|---|
| 236 | 00:04:01.241-->00:04:05.378
|
|---|
| 237 | sitting around doing nothing.
|
|---|
| 238 | >>Yeah we got a pit of interns
|
|---|
| 239 | they get 24-inch monitors. They
|
|---|
| 240 |
|
|---|
| 241 | 00:04:05.378-->00:04:10.183
|
|---|
| 242 | don't need them. Right? So we
|
|---|
| 243 | started looking at the 24 tens
|
|---|
| 244 | instead of the curved ones. And
|
|---|
| 245 |
|
|---|
| 246 | 00:04:10.183-->00:04:14.988
|
|---|
| 247 | uh like 15 minutes of Googling
|
|---|
| 248 | later we found this really nice
|
|---|
| 249 | document that described a USB
|
|---|
| 250 |
|
|---|
| 251 | 00:04:14.988-->00:04:20.427
|
|---|
| 252 | firmware upgrade instruction.
|
|---|
| 253 | Okay? And this instruction is
|
|---|
| 254 | insultingly clear because the
|
|---|
| 255 |
|
|---|
| 256 | 00:04:20.427-->00:04:24.231
|
|---|
| 257 | first instruction that's that's
|
|---|
| 258 | the power goes into the power
|
|---|
| 259 | wall thing. Right? And then the
|
|---|
| 260 |
|
|---|
| 261 | 00:04:24.231-->00:04:30.403
|
|---|
| 262 | USB goes into the USB thing. But
|
|---|
| 263 | then you know it talks about
|
|---|
| 264 | this uh U24 ten ISP tool in
|
|---|
| 265 |
|
|---|
| 266 | 00:04:30.403-->00:04:36.009
|
|---|
| 267 | incir or in circuit programmer.
|
|---|
| 268 | Uh and then we get you know we
|
|---|
| 269 | started to get very interesting
|
|---|
| 270 |
|
|---|
| 271 | 00:04:36.009-->00:04:41.047
|
|---|
| 272 | results. Right? So we're seeing
|
|---|
| 273 | screen shots of this Dell
|
|---|
| 274 | utility that doesn't require any
|
|---|
| 275 |
|
|---|
| 276 | 00:04:41.047-->00:04:45.152
|
|---|
| 277 | administrative privilege. That
|
|---|
| 278 | you know starts up a bunch of
|
|---|
| 279 | stuff and at the end of the day
|
|---|
| 280 |
|
|---|
| 281 | 00:04:45.152-->00:04:51.091
|
|---|
| 282 | right? Runs you know things like
|
|---|
| 283 | app tests and a lot of other
|
|---|
| 284 | mystery. And uh just does the
|
|---|
| 285 |
|
|---|
| 286 | 00:04:51.091-->00:04:55.662
|
|---|
| 287 | firmware upgrade for you. So we
|
|---|
| 288 | looked at the the output of this
|
|---|
| 289 | program we say you know what is
|
|---|
| 290 |
|
|---|
| 291 | 00:04:55.662-->00:05:00.000
|
|---|
| 292 | an app test? Like what is this
|
|---|
| 293 | all about? We started Googling
|
|---|
| 294 | right? We found a lot of you
|
|---|
| 295 |
|
|---|
| 296 | 00:05:00.000-->00:05:04.704
|
|---|
| 297 | know documents mentioning
|
|---|
| 298 | genesis and g-probe and all this
|
|---|
| 299 | other stuff. And we also found
|
|---|
| 300 |
|
|---|
| 301 | 00:05:04.704-->00:05:09.709
|
|---|
| 302 | these documents from you know
|
|---|
| 303 | the late 90's and early 2000's
|
|---|
| 304 | that had this all these mystery
|
|---|
| 305 |
|
|---|
| 306 | 00:05:09.709-->00:05:13.580
|
|---|
| 307 | hardware that updates firmware
|
|---|
| 308 | from these really old monitors.
|
|---|
| 309 | So if you see the one on the
|
|---|
| 310 |
|
|---|
| 311 | 00:05:13.580-->00:05:18.552
|
|---|
| 312 | bottom there's a a parallel port
|
|---|
| 313 | with power supply going to VGA.
|
|---|
| 314 | Right? And somehow this hardware
|
|---|
| 315 |
|
|---|
| 316 | 00:05:18.552-->00:05:23.657
|
|---|
| 317 | changes firmware on on monitors.
|
|---|
| 318 | Uh so we start Googling more!
|
|---|
| 319 | Alright we find mention of SD
|
|---|
| 320 |
|
|---|
| 321 | 00:05:23.657-->00:05:29.196
|
|---|
| 322 | micro, analog, safina and Dell.
|
|---|
| 323 | So we're trying to figure out
|
|---|
| 324 | what this is all about! Okay? Uh
|
|---|
| 325 |
|
|---|
| 326 | 00:05:29.196-->00:05:33.266
|
|---|
| 327 | so like days n days of Googling
|
|---|
| 328 | later we figured out that
|
|---|
| 329 | roughly how this happens. So app
|
|---|
| 330 |
|
|---|
| 331 | 00:05:33.266-->00:05:39.806
|
|---|
| 332 | tests us is a thing that is used
|
|---|
| 333 | by g-probe which was created by
|
|---|
| 334 | a company named Genesis and they
|
|---|
| 335 |
|
|---|
| 336 | 00:05:39.806-->00:05:43.210
|
|---|
| 337 | were a big player in the on
|
|---|
| 338 | screen display controller
|
|---|
| 339 | market. You know in the early
|
|---|
| 340 |
|
|---|
| 341 | 00:05:43.210-->00:05:48.949
|
|---|
| 342 | 2000's. Right? From there we did
|
|---|
| 343 | a lot of Googling and here's
|
|---|
| 344 | what happened. Okay? So in 2002
|
|---|
| 345 |
|
|---|
| 346 | 00:05:48.949-->00:05:55.589
|
|---|
| 347 | Genesis created G-probe and
|
|---|
| 348 | G-probe were Genesis was in 2008
|
|---|
| 349 | later sold to SD micro. And then
|
|---|
| 350 |
|
|---|
| 351 | 00:05:55.589-->00:06:02.095
|
|---|
| 352 | SD Micro threw in some of their
|
|---|
| 353 | IP and created this called the
|
|---|
| 354 | ST DP 6000 something. Right?
|
|---|
| 355 |
|
|---|
| 356 | 00:06:02.095-->00:06:07.701
|
|---|
| 357 | That chip was then sourced to
|
|---|
| 358 | Intellucks which is partially
|
|---|
| 359 | owned by Foxconn which is then
|
|---|
| 360 |
|
|---|
| 361 | 00:06:07.701-->00:06:12.005
|
|---|
| 362 | what something that the analyst
|
|---|
| 363 | built a board that was
|
|---|
| 364 | eventually used in Dell
|
|---|
| 365 |
|
|---|
| 366 | 00:06:12.005-->00:06:18.078
|
|---|
| 367 | monitors. Alright? So this is
|
|---|
| 368 | how you know somebody wrote 2
|
|---|
| 369 | various and secret codes in 2002
|
|---|
| 370 |
|
|---|
| 371 | 00:06:18.078-->00:06:22.382
|
|---|
| 372 | that caused you know probably a
|
|---|
| 373 | few hundred million printer
|
|---|
| 374 | monitors in the world being
|
|---|
| 375 |
|
|---|
| 376 | 00:06:22.382-->00:06:26.586
|
|---|
| 377 | vulnerable today. So that's you
|
|---|
| 378 | know how it happened basically.
|
|---|
| 379 | And now we were able to get a
|
|---|
| 380 |
|
|---|
| 381 | 00:06:26.586-->00:06:30.590
|
|---|
| 382 | copy of g-probe. Alright? So
|
|---|
| 383 | this is a screen shot of what it
|
|---|
| 384 | looks like. You know the imp
|
|---|
| 385 |
|
|---|
| 386 | 00:06:30.590-->00:06:36.263
|
|---|
| 387 | interesting thing to look at
|
|---|
| 388 | here is it the software says we
|
|---|
| 389 | can connect to the monitor via
|
|---|
| 390 |
|
|---|
| 391 | 00:06:36.263-->00:06:42.168
|
|---|
| 392 | things like serial. Right? And
|
|---|
| 393 | also USB. And uh we're looking
|
|---|
| 394 | at things like the DDC 2 BI.
|
|---|
| 395 |
|
|---|
| 396 | 00:06:42.168-->00:06:47.340
|
|---|
| 397 | Right? So that's something
|
|---|
| 398 | that's important to look at come
|
|---|
| 399 | back to later. So we got a copy
|
|---|
| 400 |
|
|---|
| 401 | 00:06:47.340-->00:06:51.011
|
|---|
| 402 | of this from [indiscernible]
|
|---|
| 403 | tool. Right? We ran into the
|
|---|
| 404 | virtual machine. We dumped a lot
|
|---|
| 405 |
|
|---|
| 406 | 00:06:51.011-->00:06:56.349
|
|---|
| 407 | of USB traffic and we noticed
|
|---|
| 408 | that there are DDC packets
|
|---|
| 409 | imbedded inside USB packets.
|
|---|
| 410 |
|
|---|
| 411 | 00:06:56.349-->00:07:01.554
|
|---|
| 412 | Okay? So Jaden's going to talk a
|
|---|
| 413 | little bit about what DDC is.
|
|---|
| 414 | >>So uh DDC is like a display
|
|---|
| 415 |
|
|---|
| 416 | 00:07:01.554-->00:07:07.727
|
|---|
| 417 | data channel communications. Set
|
|---|
| 418 | up by uh b-cell. So this used by
|
|---|
| 419 | the host adapter to query the
|
|---|
| 420 |
|
|---|
| 421 | 00:07:07.727-->00:07:11.865
|
|---|
| 422 | monitor about uh hardware
|
|---|
| 423 | capabilities. What is the
|
|---|
| 424 | vendor? What resolution does it
|
|---|
| 425 |
|
|---|
| 426 | 00:07:11.865-->00:07:16.736
|
|---|
| 427 | support? And blah blah blah. And
|
|---|
| 428 | then if you go to the there's
|
|---|
| 429 | multiple versions of uh DDC
|
|---|
| 430 |
|
|---|
| 431 | 00:07:16.736-->00:07:21.741
|
|---|
| 432 | which exist. Uh there's DDC 2B,
|
|---|
| 433 | 2BI, AB, d 2B plus. And what
|
|---|
| 434 | we're working with here is 2BI.
|
|---|
| 435 |
|
|---|
| 436 | 00:07:24.010-->00:07:29.582
|
|---|
| 437 | And which is um a next version
|
|---|
| 438 | of 2B which works all that I can
|
|---|
| 439 | see and talks to the post
|
|---|
| 440 |
|
|---|
| 441 | 00:07:29.582-->00:07:35.655
|
|---|
| 442 | adapter. So here is what uh any
|
|---|
| 443 | [indiscernible] of communication
|
|---|
| 444 | started with uh host adapter to
|
|---|
| 445 |
|
|---|
| 446 | 00:07:35.655-->00:07:39.993
|
|---|
| 447 | the monitor happens. It sends a
|
|---|
| 448 | [indiscernible] with the code
|
|---|
| 449 | CF. Uh which is [indiscernible]
|
|---|
| 450 |
|
|---|
| 451 | 00:07:39.993-->00:07:46.266
|
|---|
| 452 | vendor code. Uh and it is
|
|---|
| 453 | wrapped over uh its wrapped in
|
|---|
| 454 | USB mass storage uh back end
|
|---|
| 455 |
|
|---|
| 456 | 00:07:46.266-->00:07:51.271
|
|---|
| 457 | which sent over to USB. Then uh
|
|---|
| 458 | the USB request log contains the
|
|---|
| 459 | DDC 2BI package which is
|
|---|
| 460 |
|
|---|
| 461 | 00:07:54.140-->00:07:59.546
|
|---|
| 462 | encapsulation over G-probe
|
|---|
| 463 | packet. Uh to do like different
|
|---|
| 464 | commands. So one of the command
|
|---|
| 465 |
|
|---|
| 466 | 00:07:59.546-->00:08:04.718
|
|---|
| 467 | if you look in here is run go
|
|---|
| 468 | command. Which allow us to put
|
|---|
| 469 | PC anywhere in the monitor.
|
|---|
| 470 |
|
|---|
| 471 | 00:08:04.718-->00:08:10.557
|
|---|
| 472 | >>How how convenient right? And
|
|---|
| 473 | uh if we look into the g-probe
|
|---|
| 474 | documentation right? Uh all the
|
|---|
| 475 |
|
|---|
| 476 | 00:08:10.557-->00:08:15.261
|
|---|
| 477 | trace algorithms are laid out
|
|---|
| 478 | here for you. They're very
|
|---|
| 479 | simple. So again we're taking
|
|---|
| 480 |
|
|---|
| 481 | 00:08:15.261-->00:08:19.566
|
|---|
| 482 | messages that are supposed to go
|
|---|
| 483 | into I2C packet into USB and
|
|---|
| 484 | sending it over to the monitor
|
|---|
| 485 |
|
|---|
| 486 | 00:08:19.566-->00:08:25.271
|
|---|
| 487 | via the USB interface. Okay so
|
|---|
| 488 | yeah let me show you a really
|
|---|
| 489 | simple uh communication between
|
|---|
| 490 |
|
|---|
| 491 | 00:08:25.271-->00:08:30.343
|
|---|
| 492 | the host and the the monitor. So
|
|---|
| 493 | I"ll play the monitor. Jade will
|
|---|
| 494 | play the host. Okay? >>Um
|
|---|
| 495 |
|
|---|
| 496 | 00:08:30.343-->00:08:36.182
|
|---|
| 497 | monitor initiate incoming
|
|---|
| 498 | communication. Give me registry.
|
|---|
| 499 | >>I as the monitor say I
|
|---|
| 500 |
|
|---|
| 501 | 00:08:36.182-->00:08:41.087
|
|---|
| 502 | acknowledge your request for
|
|---|
| 503 | initiation of communication. >>I
|
|---|
| 504 | acknowledge your acknowledgement
|
|---|
| 505 |
|
|---|
| 506 | 00:08:41.087-->00:08:47.360
|
|---|
| 507 | that you started that you want
|
|---|
| 508 | to initial communication. >>Okay
|
|---|
| 509 | I have uh acknowledge that you
|
|---|
| 510 |
|
|---|
| 511 | 00:08:47.360-->00:08:51.498
|
|---|
| 512 | have run the read registry
|
|---|
| 513 | command. End of acknowledgement.
|
|---|
| 514 | Okay, but we're not done yet.
|
|---|
| 515 |
|
|---|
| 516 | 00:08:51.498-->00:08:55.268
|
|---|
| 517 | Alright this is just the send
|
|---|
| 518 | the command. >>Okay this is like
|
|---|
| 519 | 6 packets to send the command.
|
|---|
| 520 |
|
|---|
| 521 | 00:08:55.268-->00:08:58.838
|
|---|
| 522 | Uh hey monitor let's do a
|
|---|
| 523 | communication again. Uh give me
|
|---|
| 524 | the response of my previous
|
|---|
| 525 |
|
|---|
| 526 | 00:08:58.838-->00:09:03.009
|
|---|
| 527 | command. >>I acknowledge your
|
|---|
| 528 | request for initiation of
|
|---|
| 529 | communication. >>I acknowledge
|
|---|
| 530 |
|
|---|
| 531 | 00:09:03.009-->00:09:06.279
|
|---|
| 532 | your acknowledgement that you
|
|---|
| 533 | want the communication.
|
|---|
| 534 | [laughter] >>Okay I have the
|
|---|
| 535 |
|
|---|
| 536 | 00:09:06.279-->00:09:11.985
|
|---|
| 537 | result for you from re-register.
|
|---|
| 538 | End of communication. Goodbye.
|
|---|
| 539 | >>So 12 packets to get 2 bytes
|
|---|
| 540 |
|
|---|
| 541 | 00:09:11.985-->00:09:17.090
|
|---|
| 542 | out of the monitor. [laugher] >>
|
|---|
| 543 | Great. But uh it works. You know
|
|---|
| 544 | that's how that's how the
|
|---|
| 545 |
|
|---|
| 546 | 00:09:17.090-->00:09:20.360
|
|---|
| 547 | monitors doing it. Right? And
|
|---|
| 548 | this is the mechanism that the
|
|---|
| 549 | monitor uses to updated the
|
|---|
| 550 |
|
|---|
| 551 | 00:09:20.360-->00:09:24.097
|
|---|
| 552 | firmware from USB into the
|
|---|
| 553 | onscreen display controller.
|
|---|
| 554 | Okay? So we read some
|
|---|
| 555 |
|
|---|
| 556 | 00:09:24.097-->00:09:28.535
|
|---|
| 557 | documentation let's void void
|
|---|
| 558 | the warranty let's figure out
|
|---|
| 559 | what the hardware looks like. So
|
|---|
| 560 |
|
|---|
| 561 | 00:09:28.535-->00:09:32.272
|
|---|
| 562 | we opened up the back of the
|
|---|
| 563 | monitor. This is pretty typical.
|
|---|
| 564 | Right? The top of the board is
|
|---|
| 565 |
|
|---|
| 566 | 00:09:32.272-->00:09:36.543
|
|---|
| 567 | where all the power stuff is and
|
|---|
| 568 | the digital stuff is on the
|
|---|
| 569 | bottom. Okay? And uh here is an
|
|---|
| 570 |
|
|---|
| 571 | 00:09:36.543-->00:09:40.013
|
|---|
| 572 | architectural diagram. Right? So
|
|---|
| 573 | you have main SD micro uh on the
|
|---|
| 574 | upper left hand corner. Notice
|
|---|
| 575 |
|
|---|
| 576 | 00:09:40.013-->00:09:42.015
|
|---|
| 577 | that that chip sits on an IC2
|
|---|
| 578 | bus which is connected to a
|
|---|
| 579 | multi-plexor chip and that's the
|
|---|
| 580 |
|
|---|
| 581 | 00:09:42.015-->00:09:44.951
|
|---|
| 582 | uh the 48 53. Right? And that
|
|---|
| 583 | multi-plexor again sits on a
|
|---|
| 584 | second IC2 bus which is
|
|---|
| 585 |
|
|---|
| 586 | 00:09:44.951-->00:09:49.956
|
|---|
| 587 | connected to a USB controller.
|
|---|
| 588 | Right? Which is the thing we are
|
|---|
| 589 | talking to. So traffic comes
|
|---|
| 590 |
|
|---|
| 591 | 00:09:57.931-->00:10:01.901
|
|---|
| 592 | into this USB controller. Goes
|
|---|
| 593 | into the I2C bus. Goes through
|
|---|
| 594 | this multi-plexor then
|
|---|
| 595 |
|
|---|
| 596 | 00:10:01.901-->00:10:06.473
|
|---|
| 597 | eventually ends up directly on
|
|---|
| 598 | the I2C bus for the uh onscreen
|
|---|
| 599 | display controller. So we're
|
|---|
| 600 |
|
|---|
| 601 | 00:10:06.473-->00:10:11.845
|
|---|
| 602 | able to able to send raw I2C
|
|---|
| 603 | packets through USB to this
|
|---|
| 604 | machine. There that's how things
|
|---|
| 605 |
|
|---|
| 606 | 00:10:11.845-->00:10:16.549
|
|---|
| 607 | work. And we flipped the board
|
|---|
| 608 | over. This is pretty typical. We
|
|---|
| 609 | found an SPI flash chip that we
|
|---|
| 610 |
|
|---|
| 611 | 00:10:16.549-->00:10:20.353
|
|---|
| 612 | were able to dump. So we dumped
|
|---|
| 613 | the code. And us this is
|
|---|
| 614 | something we like to do. We like
|
|---|
| 615 |
|
|---|
| 616 | 00:10:20.353-->00:10:25.859
|
|---|
| 617 | to do 2-D render you know
|
|---|
| 618 | visualization of entropy. Ah so
|
|---|
| 619 | you know off the top of er of
|
|---|
| 620 |
|
|---|
| 621 | 00:10:25.859-->00:10:29.362
|
|---|
| 622 | the top off with our heads we
|
|---|
| 623 | looked at this thing and we said
|
|---|
| 624 | I have no idea what that is.
|
|---|
| 625 |
|
|---|
| 626 | 00:10:29.362-->00:10:32.932
|
|---|
| 627 | That looks pretty sweet. Right?
|
|---|
| 628 | Uh it's high entropy followed by
|
|---|
| 629 | low entropy There's certainly a
|
|---|
| 630 |
|
|---|
| 631 | 00:10:32.932-->00:10:37.437
|
|---|
| 632 | pattern there. Uh this stuff you
|
|---|
| 633 | know somewhere in the middle
|
|---|
| 634 | probably looks like code. Uh
|
|---|
| 635 |
|
|---|
| 636 | 00:10:37.437-->00:10:42.609
|
|---|
| 637 | stuff over here maybe data.
|
|---|
| 638 | Right? It's high entropy. Right?
|
|---|
| 639 | I mean it's low entropy but it
|
|---|
| 640 |
|
|---|
| 641 | 00:10:42.609-->00:10:46.646
|
|---|
| 642 | looks like there some stuff in
|
|---|
| 643 | there that's interesting. And
|
|---|
| 644 | who knows? Maybe this is
|
|---|
| 645 |
|
|---|
| 646 | 00:10:46.646-->00:10:51.117
|
|---|
| 647 | compressed data. We don't really
|
|---|
| 648 | know. And then we took it and we
|
|---|
| 649 | just ran a string on this thing.
|
|---|
| 650 |
|
|---|
| 651 | 00:10:51.117-->00:10:54.787
|
|---|
| 652 | And you know we're seeing a lot
|
|---|
| 653 | of stuff that we're you know we
|
|---|
| 654 | saw in the documentation. So
|
|---|
| 655 |
|
|---|
| 656 | 00:10:54.787-->00:10:59.559
|
|---|
| 657 | there's app test. Right? I
|
|---|
| 658 | mentions of you know picture in
|
|---|
| 659 | picture. And things like OSD
|
|---|
| 660 |
|
|---|
| 661 | 00:10:59.559-->00:11:03.730
|
|---|
| 662 | high and OSD show right? So this
|
|---|
| 663 | looks like we're on the right
|
|---|
| 664 | track. We want to play with
|
|---|
| 665 |
|
|---|
| 666 | 00:11:03.730-->00:11:09.302
|
|---|
| 667 | these things. So, then I said
|
|---|
| 668 | obviously let's throw this in
|
|---|
| 669 | ida and see what happens. Right?
|
|---|
| 670 |
|
|---|
| 671 | 00:11:09.302-->00:11:13.573
|
|---|
| 672 | And this is what ida did. Right?
|
|---|
| 673 | And you know we looked and it
|
|---|
| 674 | and we said oh this is really
|
|---|
| 675 |
|
|---|
| 676 | 00:11:13.573-->00:11:18.845
|
|---|
| 677 | hard. We can't figure out how to
|
|---|
| 678 | to disassemble turbo 186. Which
|
|---|
| 679 | is the architecture here. So we
|
|---|
| 680 |
|
|---|
| 681 | 00:11:18.845-->00:11:23.917
|
|---|
| 682 | started Googling around and it
|
|---|
| 683 | seems like somebody on open
|
|---|
| 684 | universe in 2008 probably did
|
|---|
| 685 |
|
|---|
| 686 | 00:11:23.917-->00:11:28.354
|
|---|
| 687 | exactly this research but maybe
|
|---|
| 688 | didn't tell anybody. Because
|
|---|
| 689 | they're asking about exactly the
|
|---|
| 690 |
|
|---|
| 691 | 00:11:28.354-->00:11:31.991
|
|---|
| 692 | same architecture and exactly
|
|---|
| 693 | the same format. And I think the
|
|---|
| 694 | binary is actually from one of
|
|---|
| 695 |
|
|---|
| 696 | 00:11:31.991-->00:11:36.229
|
|---|
| 697 | these us former updates. So we
|
|---|
| 698 | looked at this. And we said oh
|
|---|
| 699 | we don't like [indiscernible] so
|
|---|
| 700 |
|
|---|
| 701 | 00:11:36.229-->00:11:39.832
|
|---|
| 702 | we're going to go do something
|
|---|
| 703 | more fun. Right? And we put it
|
|---|
| 704 | down. And we didn't work on it
|
|---|
| 705 |
|
|---|
| 706 | 00:11:39.832-->00:11:45.238
|
|---|
| 707 | for like 6 months. Ah and then
|
|---|
| 708 | 2016 comes along right? And
|
|---|
| 709 | Jaden and I are sitting around
|
|---|
| 710 |
|
|---|
| 711 | 00:11:45.238-->00:11:49.409
|
|---|
| 712 | and this is really bothering us.
|
|---|
| 713 | You know. I have no idea how
|
|---|
| 714 | this works. Like computers are
|
|---|
| 715 |
|
|---|
| 716 | 00:11:49.409-->00:11:55.815
|
|---|
| 717 | hard. So we just said write Igor
|
|---|
| 718 | an email. Right? And uh in 6
|
|---|
| 719 | hours or 8 hours Igor responds
|
|---|
| 720 |
|
|---|
| 721 | 00:11:55.815-->00:12:00.286
|
|---|
| 722 | and it says like here's a long
|
|---|
| 723 | in full explanation of how ida
|
|---|
| 724 | works and turbo 186. And also I
|
|---|
| 725 |
|
|---|
| 726 | 00:12:00.286-->00:12:03.723
|
|---|
| 727 | already disassembled this thing
|
|---|
| 728 | for you simple. >>So this
|
|---|
| 729 | [indiscernible] tag says
|
|---|
| 730 |
|
|---|
| 731 | 00:12:03.723-->00:12:05.725
|
|---|
| 732 | basically uh
|
|---|
| 733 | [indiscernible]......monitor to
|
|---|
| 734 | update the [indiscernible] on
|
|---|
| 735 |
|
|---|
| 736 | 00:12:05.725-->00:12:10.730
|
|---|
| 737 | the device. And he was it was
|
|---|
| 738 | like uh 200 kilobyte um I think?
|
|---|
| 739 | 2 megabyte. Uh and he had
|
|---|
| 740 |
|
|---|
| 741 | 00:12:14.200-->00:12:18.538
|
|---|
| 742 | reversed uh everything and uh it
|
|---|
| 743 | was perfectly uh disassembled.
|
|---|
| 744 | And he gave it back to us. So we
|
|---|
| 745 |
|
|---|
| 746 | 00:12:18.538-->00:12:22.041
|
|---|
| 747 | thought uh like we could do
|
|---|
| 748 | something like this with the
|
|---|
| 749 | formula monitor. >>Yeah so you
|
|---|
| 750 |
|
|---|
| 751 | 00:12:22.041-->00:12:25.111
|
|---|
| 752 | know I read his email and I said
|
|---|
| 753 | I'm just going to do exactly
|
|---|
| 754 | what you did. Right? I got
|
|---|
| 755 |
|
|---|
| 756 | 00:12:25.111-->00:12:29.916
|
|---|
| 757 | segment city everywhere. And
|
|---|
| 758 | nothing worked out. And I
|
|---|
| 759 | failed. And Jaden said let's now
|
|---|
| 760 |
|
|---|
| 761 | 00:12:29.916-->00:12:36.556
|
|---|
| 762 | do that. >>So let's be monkeys
|
|---|
| 763 | and press space. So we we added
|
|---|
| 764 | a hard key which uh if you add
|
|---|
| 765 |
|
|---|
| 766 | 00:12:36.556-->00:12:40.793
|
|---|
| 767 | like um space or like it jumps
|
|---|
| 768 | to different references you
|
|---|
| 769 | won't get a control for analysis
|
|---|
| 770 |
|
|---|
| 771 | 00:12:40.793-->00:12:46.366
|
|---|
| 772 | but likely [indiscernible]. So
|
|---|
| 773 | if [indiscernible] is looking at
|
|---|
| 774 | it please sorry. Um so while we
|
|---|
| 775 |
|
|---|
| 776 | 00:12:46.366-->00:12:51.371
|
|---|
| 777 | have now um we can run code but
|
|---|
| 778 | we want to do our um we want to
|
|---|
| 779 | run some sort of code on it.
|
|---|
| 780 |
|
|---|
| 781 | 00:12:53.539-->00:12:57.777
|
|---|
| 782 | Right? So we use uh we went
|
|---|
| 783 | through the g-probe um
|
|---|
| 784 | documentation and we found 3
|
|---|
| 785 |
|
|---|
| 786 | 00:12:57.777-->00:13:00.713
|
|---|
| 787 | commands. One is registry which
|
|---|
| 788 | uh [indiscernible].......One
|
|---|
| 789 | code uh placing PC anywhere we
|
|---|
| 790 |
|
|---|
| 791 | 00:13:00.713-->00:13:05.718
|
|---|
| 792 | want. And uh ram write which
|
|---|
| 793 | allow us to batch shell code uh
|
|---|
| 794 | into the memory. And uh there's
|
|---|
| 795 |
|
|---|
| 796 | 00:13:08.921-->00:13:13.926
|
|---|
| 797 | no MMU so this is
|
|---|
| 798 | [indiscernible]. So we want so
|
|---|
| 799 | there's a concept of app test uh
|
|---|
| 800 |
|
|---|
| 801 | 00:13:16.596-->00:13:21.768
|
|---|
| 802 | which is basically a unit test
|
|---|
| 803 | inside the monitor. Uh so it
|
|---|
| 804 | creates a context and it uh
|
|---|
| 805 |
|
|---|
| 806 | 00:13:21.768-->00:13:27.440
|
|---|
| 807 | tears down the context and does
|
|---|
| 808 | something inside it. >>Yeah so
|
|---|
| 809 | now that we have this ability to
|
|---|
| 810 |
|
|---|
| 811 | 00:13:27.440-->00:13:31.811
|
|---|
| 812 | write code into memory and then
|
|---|
| 813 | run code right? We want to
|
|---|
| 814 | highjack something that seems
|
|---|
| 815 |
|
|---|
| 816 | 00:13:31.811-->00:13:36.616
|
|---|
| 817 | like it might be useful. Uh to
|
|---|
| 818 | see if we can do a very simple
|
|---|
| 819 | hello world. So we found there's
|
|---|
| 820 |
|
|---|
| 821 | 00:13:36.616-->00:13:40.420
|
|---|
| 822 | one function that says you know
|
|---|
| 823 | always the fill rectangle you
|
|---|
| 824 | know that sounds like a good
|
|---|
| 825 |
|
|---|
| 826 | 00:13:40.420-->00:13:43.756
|
|---|
| 827 | idea. We want to just put a
|
|---|
| 828 | rectangle on the screen to see
|
|---|
| 829 | if we can actually do this.
|
|---|
| 830 |
|
|---|
| 831 | 00:13:43.756-->00:13:46.793
|
|---|
| 832 | >>That's batch it using
|
|---|
| 833 | [indiscernible] >>All right so
|
|---|
| 834 | Jaden wrote this thing and it
|
|---|
| 835 |
|
|---|
| 836 | 00:13:46.793-->00:13:50.963
|
|---|
| 837 | turn out to be the grossest code
|
|---|
| 838 | that we've seen to that point.
|
|---|
| 839 | It gets way worse than this.
|
|---|
| 840 |
|
|---|
| 841 | 00:13:50.963-->00:13:55.601
|
|---|
| 842 | Right? So this is what it looks
|
|---|
| 843 | like. Uh >>And I have I have
|
|---|
| 844 | looked at this for 3 weeks.
|
|---|
| 845 |
|
|---|
| 846 | 00:13:55.601-->00:13:59.272
|
|---|
| 847 | >>Yeah and if you stare at this
|
|---|
| 848 | for hours and hours it will make
|
|---|
| 849 | you want to puke. Um >>It will
|
|---|
| 850 |
|
|---|
| 851 | 00:13:59.272-->00:14:05.278
|
|---|
| 852 | get us close. >>And Jaden
|
|---|
| 853 | definitely did stare at this for
|
|---|
| 854 | hours and hours. And okay so now
|
|---|
| 855 |
|
|---|
| 856 | 00:14:05.278-->00:14:09.315
|
|---|
| 857 | okay now that we're able to dump
|
|---|
| 858 | some memory from the firmware.
|
|---|
| 859 | Right? We're looking at the code
|
|---|
| 860 |
|
|---|
| 861 | 00:14:09.315-->00:14:13.720
|
|---|
| 862 | with some most of it
|
|---|
| 863 | disassembled. Right? We notice
|
|---|
| 864 | that most the virtual memory
|
|---|
| 865 |
|
|---|
| 866 | 00:14:13.720-->00:14:18.257
|
|---|
| 867 | address map is between this and
|
|---|
| 868 | this. Okay. But there's all
|
|---|
| 869 | these far calls to this very
|
|---|
| 870 |
|
|---|
| 871 | 00:14:18.257-->00:14:20.259
|
|---|
| 872 | mysterious memory region. >>So
|
|---|
| 873 | we started uh we thought like um
|
|---|
| 874 | there's no reference to it and
|
|---|
| 875 |
|
|---|
| 876 | 00:14:20.259-->00:14:23.663
|
|---|
| 877 | we do not understand how to get
|
|---|
| 878 | this code. So we started dumping
|
|---|
| 879 | code. Um we um so we wrote a USB
|
|---|
| 880 |
|
|---|
| 881 | 00:14:23.663-->00:14:25.665
|
|---|
| 882 | dump and uh so we took there is
|
|---|
| 883 | there is a command which is
|
|---|
| 884 | listed called grand read. Uh be
|
|---|
| 885 |
|
|---|
| 886 | 00:14:25.665-->00:14:27.667
|
|---|
| 887 | we were not able to make it
|
|---|
| 888 | work. Although it works now. So
|
|---|
| 889 | we used uh a reg read uh which
|
|---|
| 890 |
|
|---|
| 891 | 00:14:27.667-->00:14:32.672
|
|---|
| 892 | allowed us dump 2 bytes at a
|
|---|
| 893 | time. So imagine like uh doing
|
|---|
| 894 | those 12 packet transfers to get
|
|---|
| 895 |
|
|---|
| 896 | 00:14:44.617-->00:14:51.457
|
|---|
| 897 | 2 bytes out. Uh so uh I wrote a
|
|---|
| 898 | memory dumper which allowed us
|
|---|
| 899 | to do uh 1 megabyte dump per 8
|
|---|
| 900 |
|
|---|
| 901 | 00:14:51.457-->00:14:55.094
|
|---|
| 902 | minutes. >>Per 8 minutes. So
|
|---|
| 903 | remember those tall commands
|
|---|
| 904 | that you had to do. Right? We're
|
|---|
| 905 |
|
|---|
| 906 | 00:14:55.094-->00:15:00.166
|
|---|
| 907 | doing those USB commands for
|
|---|
| 908 | what it is 100 bytes at a time
|
|---|
| 909 | right? So >>Yeah >>We this is
|
|---|
| 910 |
|
|---|
| 911 | 00:15:00.166-->00:15:05.171
|
|---|
| 912 | what we did it was dumb. Jaden
|
|---|
| 913 | writes the USB dumper. We dump
|
|---|
| 914 | and we wait and we dump and we
|
|---|
| 915 |
|
|---|
| 916 | 00:15:07.673-->00:15:11.410
|
|---|
| 917 | wait and we dump. And this is
|
|---|
| 918 | very slow. Right? And then
|
|---|
| 919 | Francois comes along says like
|
|---|
| 920 |
|
|---|
| 921 | 00:15:11.410-->00:15:15.381
|
|---|
| 922 | you guys dump too slow and
|
|---|
| 923 | totally do this differently. So
|
|---|
| 924 | he went off and he said I"m just
|
|---|
| 925 |
|
|---|
| 926 | 00:15:15.381-->00:15:20.453
|
|---|
| 927 | going to reimplement the UR of
|
|---|
| 928 | using GPIO pins in the sock uh
|
|---|
| 929 | that's going to be way faster.
|
|---|
| 930 |
|
|---|
| 931 | 00:15:20.453-->00:15:23.523
|
|---|
| 932 | And we're like no way that's
|
|---|
| 933 | going to work. You know. Two
|
|---|
| 934 | days later he comes back and he
|
|---|
| 935 |
|
|---|
| 936 | 00:15:23.523-->00:15:27.827
|
|---|
| 937 | says you are implemented. Okay?
|
|---|
| 938 | He has a highjacked standard in
|
|---|
| 939 | standard out. So all of a sudden
|
|---|
| 940 |
|
|---|
| 941 | 00:15:27.827-->00:15:32.932
|
|---|
| 942 | we had a u-art over GPIO pins on
|
|---|
| 943 | the monitor that not only
|
|---|
| 944 | allowed us dump arbitrary memory
|
|---|
| 945 |
|
|---|
| 946 | 00:15:32.932-->00:15:37.904
|
|---|
| 947 | it also allowed us to highjack
|
|---|
| 948 | all these these very important
|
|---|
| 949 | very useful debug messages. >>So
|
|---|
| 950 |
|
|---|
| 951 | 00:15:37.904-->00:15:41.874
|
|---|
| 952 | it is very important important
|
|---|
| 953 | to know that right now we're
|
|---|
| 954 | working with the assumption that
|
|---|
| 955 |
|
|---|
| 956 | 00:15:41.874-->00:15:47.413
|
|---|
| 957 | there is only one um micro
|
|---|
| 958 | controller and that suck. Ah but
|
|---|
| 959 | after dumping the F thousand
|
|---|
| 960 |
|
|---|
| 961 | 00:15:47.413-->00:15:51.884
|
|---|
| 962 | range we realized that it's
|
|---|
| 963 | actually a hardware obstruction
|
|---|
| 964 | there to talk to another chip.
|
|---|
| 965 |
|
|---|
| 966 | 00:15:51.884-->00:15:57.323
|
|---|
| 967 | Uh and the processor inside the
|
|---|
| 968 | sock which which uh it's called
|
|---|
| 969 | OSD now on screen display whose
|
|---|
| 970 |
|
|---|
| 971 | 00:15:57.323-->00:16:03.462
|
|---|
| 972 | main uh function is to display
|
|---|
| 973 | midges on the on the on the
|
|---|
| 974 | monitor. But the other OCM which
|
|---|
| 975 |
|
|---|
| 976 | 00:16:03.462-->00:16:08.000
|
|---|
| 977 | is on chip micro controller is
|
|---|
| 978 | actually talking to other device
|
|---|
| 979 | uh uh that are common place
|
|---|
| 980 |
|
|---|
| 981 | 00:16:08.000-->00:16:13.840
|
|---|
| 982 | inside the sock and other um
|
|---|
| 983 | external interfaces. So the
|
|---|
| 984 | which is uh is 8000
|
|---|
| 985 |
|
|---|
| 986 | 00:16:13.840-->00:16:20.346
|
|---|
| 987 | [indiscernible] is mapped to is
|
|---|
| 988 | uh OCM and F uh and OSD has its
|
|---|
| 989 | own code running inside s ram.
|
|---|
| 990 |
|
|---|
| 991 | 00:16:20.346-->00:16:25.251
|
|---|
| 992 | Um its own kind of processor.
|
|---|
| 993 | >>Yeah so at this point you know
|
|---|
| 994 | we now know that we're now
|
|---|
| 995 |
|
|---|
| 996 | 00:16:25.251-->00:16:28.955
|
|---|
| 997 | working with just one processor
|
|---|
| 998 | there's at least 2 different
|
|---|
| 999 | processors inside the sock.
|
|---|
| 1000 |
|
|---|
| 1001 | 00:16:28.955-->00:16:32.725
|
|---|
| 1002 | Right? And they communicate
|
|---|
| 1003 | using some memory map register
|
|---|
| 1004 | that we don't really understand
|
|---|
| 1005 |
|
|---|
| 1006 | 00:16:32.725-->00:16:37.530
|
|---|
| 1007 | yet. And uh we kind of hit a
|
|---|
| 1008 | wall. So we spent like a million
|
|---|
| 1009 | years Googling and clicking on
|
|---|
| 1010 |
|
|---|
| 1011 | 00:16:37.530-->00:16:40.900
|
|---|
| 1012 | pretty much everything that
|
|---|
| 1013 | we're not supposed to. Right?
|
|---|
| 1014 | Until we found this beautiful
|
|---|
| 1015 |
|
|---|
| 1016 | 00:16:40.900-->00:16:45.771
|
|---|
| 1017 | site Dot 88 which is a place
|
|---|
| 1018 | where people upload you know
|
|---|
| 1019 | awesome proprietary documents
|
|---|
| 1020 |
|
|---|
| 1021 | 00:16:45.771-->00:16:51.043
|
|---|
| 1022 | for the internet and stuff. And
|
|---|
| 1023 | uh you'll probably want to open
|
|---|
| 1024 | this in a VM but it did give us
|
|---|
| 1025 |
|
|---|
| 1026 | 00:16:51.043-->00:16:55.882
|
|---|
| 1027 | the exact data sheet for this
|
|---|
| 1028 | chip that we're working with and
|
|---|
| 1029 | from there we found pretty much
|
|---|
| 1030 |
|
|---|
| 1031 | 00:16:55.882-->00:16:59.752
|
|---|
| 1032 | everything we needed to know
|
|---|
| 1033 | about how this chip worked. Uh
|
|---|
| 1034 | and we were right about this
|
|---|
| 1035 |
|
|---|
| 1036 | 00:16:59.752-->00:17:03.456
|
|---|
| 1037 | assumption that there is an OCM
|
|---|
| 1038 | and an OSD chip and or OSD
|
|---|
| 1039 | processor and they are
|
|---|
| 1040 |
|
|---|
| 1041 | 00:17:03.456-->00:17:08.261
|
|---|
| 1042 | completely separate. And they
|
|---|
| 1043 | work more or less asynchornously
|
|---|
| 1044 | from each other. Okay? So now
|
|---|
| 1045 |
|
|---|
| 1046 | 00:17:08.261-->00:17:11.864
|
|---|
| 1047 | that we have the data sheet
|
|---|
| 1048 | we've done all the stuff you
|
|---|
| 1049 | know let's try to display a
|
|---|
| 1050 |
|
|---|
| 1051 | 00:17:11.864-->00:17:15.968
|
|---|
| 1052 | picture. Right? Let's get that
|
|---|
| 1053 | to work. First uh there are 3
|
|---|
| 1054 | things that we have to solve.
|
|---|
| 1055 |
|
|---|
| 1056 | 00:17:15.968-->00:17:19.939
|
|---|
| 1057 | And if we solve these things we
|
|---|
| 1058 | we got picture display. Okay?
|
|---|
| 1059 | We'll have to figure out where
|
|---|
| 1060 |
|
|---|
| 1061 | 00:17:19.939-->00:17:24.543
|
|---|
| 1062 | to transfer the image to the
|
|---|
| 1063 | monitor. Alright? We have to
|
|---|
| 1064 | figure out how to trigger the
|
|---|
| 1065 |
|
|---|
| 1066 | 00:17:24.543-->00:17:28.681
|
|---|
| 1067 | image display function to you
|
|---|
| 1068 | know display that image that we
|
|---|
| 1069 | transferred. And then we also
|
|---|
| 1070 |
|
|---|
| 1071 | 00:17:28.681-->00:17:32.952
|
|---|
| 1072 | have to figure out you know what
|
|---|
| 1073 | a color is. Right? How the
|
|---|
| 1074 | colors represented in this this
|
|---|
| 1075 |
|
|---|
| 1076 | 00:17:32.952-->00:17:38.424
|
|---|
| 1077 | monitor. >>So uh when you start
|
|---|
| 1078 | booting the monitor right? Like
|
|---|
| 1079 | if this image comes up. So the
|
|---|
| 1080 |
|
|---|
| 1081 | 00:17:38.424-->00:17:42.161
|
|---|
| 1082 | the theory was that it defined
|
|---|
| 1083 | this image we will be able to
|
|---|
| 1084 | find the code which loads this
|
|---|
| 1085 |
|
|---|
| 1086 | 00:17:42.161-->00:17:47.166
|
|---|
| 1087 | image and our quest will be
|
|---|
| 1088 | over. But uh I I we had drunk
|
|---|
| 1089 | sober and >>Very sober
|
|---|
| 1090 |
|
|---|
| 1091 | 00:17:49.835-->00:17:54.073
|
|---|
| 1092 | [indiscernible as they talk over
|
|---|
| 1093 | each other] >>And uh after a few
|
|---|
| 1094 | hours we came with our own
|
|---|
| 1095 |
|
|---|
| 1096 | 00:17:54.073-->00:17:59.045
|
|---|
| 1097 | analysis and uh we put said that
|
|---|
| 1098 | this is not a Dell image so what
|
|---|
| 1099 | is this? um >>Well uh I mean so
|
|---|
| 1100 |
|
|---|
| 1101 | 00:17:59.045-->00:18:02.581
|
|---|
| 1102 | we looked at some part of the
|
|---|
| 1103 | code. Right? This clearly
|
|---|
| 1104 | doesn't hold the Dell logo.
|
|---|
| 1105 |
|
|---|
| 1106 | 00:18:02.581-->00:18:05.551
|
|---|
| 1107 | Right? But you know what about
|
|---|
| 1108 | stuff like this on the on the
|
|---|
| 1109 | left side? Right? Like maybe
|
|---|
| 1110 |
|
|---|
| 1111 | 00:18:05.551-->00:18:08.955
|
|---|
| 1112 | that's you know some
|
|---|
| 1113 | representation of image. You
|
|---|
| 1114 | know what is the thing on the
|
|---|
| 1115 |
|
|---|
| 1116 | 00:18:08.955-->00:18:14.794
|
|---|
| 1117 | left? Right? And if you stare at
|
|---|
| 1118 | that too long it also does crazy
|
|---|
| 1119 | things to your brain. Um okay!
|
|---|
| 1120 |
|
|---|
| 1121 | 00:18:14.794-->00:18:21.400
|
|---|
| 1122 | So then you know Francois comes
|
|---|
| 1123 | along. Right? And uh we you know
|
|---|
| 1124 | >>Yeah after like after few days
|
|---|
| 1125 |
|
|---|
| 1126 | 00:18:21.400-->00:18:25.871
|
|---|
| 1127 | uh he came up with me like he
|
|---|
| 1128 | wanted to [indiscernible] to
|
|---|
| 1129 | stare at. And uh I looked at it
|
|---|
| 1130 |
|
|---|
| 1131 | 00:18:25.871-->00:18:32.578
|
|---|
| 1132 | for hours and uh Duh come on
|
|---|
| 1133 | that's obviously an OSD command
|
|---|
| 1134 | packet uh >>Great! I mean don't
|
|---|
| 1135 |
|
|---|
| 1136 | 00:18:32.578-->00:18:37.049
|
|---|
| 1137 | you see that? Obviously right?
|
|---|
| 1138 | This is just you know in memory
|
|---|
| 1139 | of run time. Right? Just a big
|
|---|
| 1140 |
|
|---|
| 1141 | 00:18:37.049-->00:18:41.988
|
|---|
| 1142 | ol' blob of binary and Jaden
|
|---|
| 1143 | stares at this thing and he says
|
|---|
| 1144 | obviously this is this
|
|---|
| 1145 |
|
|---|
| 1146 | 00:18:41.988-->00:18:48.127
|
|---|
| 1147 | structure. >>So uh this OSD
|
|---|
| 1148 | command packet allows the OSD to
|
|---|
| 1149 | display packet uh anywhere in
|
|---|
| 1150 |
|
|---|
| 1151 | 00:18:48.127-->00:18:52.231
|
|---|
| 1152 | the screen. You can specify the
|
|---|
| 1153 | coordinates. You can specify the
|
|---|
| 1154 | size. You can specify the color.
|
|---|
| 1155 |
|
|---|
| 1156 | 00:18:52.231-->00:18:57.303
|
|---|
| 1157 | How many bits per pixel have to
|
|---|
| 1158 | be used uh and uh what we
|
|---|
| 1159 | understood after a lot of
|
|---|
| 1160 |
|
|---|
| 1161 | 00:18:57.303-->00:19:02.241
|
|---|
| 1162 | reverse analysis uh of the um I
|
|---|
| 1163 | rom [indiscernible] This is how
|
|---|
| 1164 | it actually works. So you write
|
|---|
| 1165 |
|
|---|
| 1166 | 00:19:05.478-->00:19:10.850
|
|---|
| 1167 | the OSD packet inside the OCM
|
|---|
| 1168 | memory map. And then you engage
|
|---|
| 1169 | the main engine to map this
|
|---|
| 1170 |
|
|---|
| 1171 | 00:19:10.850-->00:19:15.855
|
|---|
| 1172 | memory over to s ram of OSD. And
|
|---|
| 1173 | uh as long like uh as OSD is
|
|---|
| 1174 | working asynchronously um it
|
|---|
| 1175 |
|
|---|
| 1176 | 00:19:17.890-->00:19:22.762
|
|---|
| 1177 | reads the packet and displays
|
|---|
| 1178 | image. And similarly you can
|
|---|
| 1179 | transfer the image to the OSD
|
|---|
| 1180 |
|
|---|
| 1181 | 00:19:22.762-->00:19:26.565
|
|---|
| 1182 | using the main memory mapping.
|
|---|
| 1183 | So this solved this first 2
|
|---|
| 1184 | questions which was transfer and
|
|---|
| 1185 |
|
|---|
| 1186 | 00:19:26.565-->00:19:32.505
|
|---|
| 1187 | display image. Right? And uh the
|
|---|
| 1188 | APS which were used to do this
|
|---|
| 1189 | was SD ram read uh to check
|
|---|
| 1190 |
|
|---|
| 1191 | 00:19:32.505-->00:19:38.177
|
|---|
| 1192 | verify our write. And the SD ram
|
|---|
| 1193 | write which showed us to do all
|
|---|
| 1194 | this. And this is what we came
|
|---|
| 1195 |
|
|---|
| 1196 | 00:19:38.177-->00:19:43.649
|
|---|
| 1197 | with. This is probably the most
|
|---|
| 1198 | gross blinking um box blinking
|
|---|
| 1199 | program I have ever and if you
|
|---|
| 1200 |
|
|---|
| 1201 | 00:19:43.649-->00:19:48.587
|
|---|
| 1202 | look at it for hours you I have
|
|---|
| 1203 | the [indiscernible] once. >>Uh
|
|---|
| 1204 | alright wait you gotta see it.
|
|---|
| 1205 |
|
|---|
| 1206 | 00:19:48.587-->00:19:55.361
|
|---|
| 1207 | You guys all have to watch this
|
|---|
| 1208 | with us now. Wait hold why did
|
|---|
| 1209 | that >>So you will see >>No it
|
|---|
| 1210 |
|
|---|
| 1211 | 00:19:55.361-->00:19:58.497
|
|---|
| 1212 | doesn't want to play. Hold on.
|
|---|
| 1213 | No No You're not gonna get
|
|---|
| 1214 | >>Doesn't want to come up >>Your
|
|---|
| 1215 |
|
|---|
| 1216 | 00:19:58.497-->00:20:03.502
|
|---|
| 1217 | not off the hook. You gotta
|
|---|
| 1218 | watch this video. [pause]
|
|---|
| 1219 | >>Okay. So as you will see that
|
|---|
| 1220 |
|
|---|
| 1221 | 00:20:05.704-->00:20:11.744
|
|---|
| 1222 | the blob [indiscernible] moved
|
|---|
| 1223 | the box around anywhere on the
|
|---|
| 1224 | screen. And uh >>That's so
|
|---|
| 1225 |
|
|---|
| 1226 | 00:20:11.744-->00:20:16.348
|
|---|
| 1227 | nauseating >>There is there was
|
|---|
| 1228 | a blinking blob which I figured
|
|---|
| 1229 | out after recon. >>Right but
|
|---|
| 1230 |
|
|---|
| 1231 | 00:20:16.348-->00:20:20.086
|
|---|
| 1232 | this is after days of looking at
|
|---|
| 1233 | this non-stop. So the last
|
|---|
| 1234 | question we have to figure out
|
|---|
| 1235 |
|
|---|
| 1236 | 00:20:20.086-->00:20:24.457
|
|---|
| 1237 | you know what is a color? Right?
|
|---|
| 1238 | I mean is it a 32 bit color? How
|
|---|
| 1239 | is it represented? So we did the
|
|---|
| 1240 |
|
|---|
| 1241 | 00:20:24.457-->00:20:28.994
|
|---|
| 1242 | reasonable thing and filled a
|
|---|
| 1243 | rectangle with rows n rows of
|
|---|
| 1244 | you know of color and
|
|---|
| 1245 |
|
|---|
| 1246 | 00:20:28.994-->00:20:35.401
|
|---|
| 1247 | incremental values from 0 1 2 3
|
|---|
| 1248 | 4 etc. Uh so instead of getting
|
|---|
| 1249 | very similar colors we got these
|
|---|
| 1250 |
|
|---|
| 1251 | 00:20:35.401-->00:20:41.574
|
|---|
| 1252 | colors. Right? So you know why
|
|---|
| 1253 | is color 0 basically the same as
|
|---|
| 1254 | color 2? Why is 1 totally
|
|---|
| 1255 |
|
|---|
| 1256 | 00:20:41.574-->00:20:46.345
|
|---|
| 1257 | different? Okay? And uh we
|
|---|
| 1258 | didn't really know. Let's do
|
|---|
| 1259 | some science. We take a tiny
|
|---|
| 1260 |
|
|---|
| 1261 | 00:20:46.345-->00:20:52.017
|
|---|
| 1262 | little microscope and we point
|
|---|
| 1263 | it at specific pixels in order
|
|---|
| 1264 | for us to figure out you know
|
|---|
| 1265 |
|
|---|
| 1266 | 00:20:52.017-->00:20:58.090
|
|---|
| 1267 | what color gets rendered into
|
|---|
| 1268 | what um pixel value. So filled
|
|---|
| 1269 | every rectangle with um value oh
|
|---|
| 1270 |
|
|---|
| 1271 | 00:20:58.090-->00:21:04.130
|
|---|
| 1272 | it's 3 3. Okay? And this is what
|
|---|
| 1273 | we saw. So if you looked at it
|
|---|
| 1274 | right R is blank. G is 100%. And
|
|---|
| 1275 |
|
|---|
| 1276 | 00:21:04.130-->00:21:08.768
|
|---|
| 1277 | B is 100% Right? So this is you
|
|---|
| 1278 | know individual pixel cells that
|
|---|
| 1279 | we're looking at. And then we
|
|---|
| 1280 |
|
|---|
| 1281 | 00:21:08.768-->00:21:14.473
|
|---|
| 1282 | said okay. Let's do instead of
|
|---|
| 1283 | you know the same pattern we'd
|
|---|
| 1284 | do augs 3 3 augs 0 0 augs 3 3
|
|---|
| 1285 |
|
|---|
| 1286 | 00:21:14.473-->00:21:20.913
|
|---|
| 1287 | augs 0 0. So Jaden how many bits
|
|---|
| 1288 | does the monitor use to
|
|---|
| 1289 | represent each color?
|
|---|
| 1290 |
|
|---|
| 1291 | 00:21:20.913-->00:21:25.518
|
|---|
| 1292 | >>[indiscernible] So if 0
|
|---|
| 1293 | represents transparency and
|
|---|
| 1294 | there's 2 pixels missing so its
|
|---|
| 1295 |
|
|---|
| 1296 | 00:21:25.518-->00:21:31.290
|
|---|
| 1297 | 4 bits per pixel. >>Right and
|
|---|
| 1298 | then >>How do you encode colors
|
|---|
| 1299 | with 4 bits? Right? In normal
|
|---|
| 1300 |
|
|---|
| 1301 | 00:21:31.290-->00:21:35.060
|
|---|
| 1302 | RGB world each color each
|
|---|
| 1303 | [indiscernible] is presented
|
|---|
| 1304 | using 8 bit. And there
|
|---|
| 1305 |
|
|---|
| 1306 | 00:21:35.060-->00:21:40.966
|
|---|
| 1307 | [indiscernible] 32 bit color. So
|
|---|
| 1308 | how do you do this
|
|---|
| 1309 | [indiscernible]? >>Yeah so
|
|---|
| 1310 |
|
|---|
| 1311 | 00:21:40.966-->00:21:46.105
|
|---|
| 1312 | right? If you have 4 bits then
|
|---|
| 1313 | you can have 1 bit for our 1 bit
|
|---|
| 1314 | for B you know etc. And that's
|
|---|
| 1315 |
|
|---|
| 1316 | 00:21:46.105-->00:21:49.842
|
|---|
| 1317 | clearly not whats happening
|
|---|
| 1318 | here. So it turns out this
|
|---|
| 1319 | monitor uses a thing called
|
|---|
| 1320 |
|
|---|
| 1321 | 00:21:49.842-->00:21:54.380
|
|---|
| 1322 | color lookup table. Which is
|
|---|
| 1323 | basically this index structure
|
|---|
| 1324 | right? That uses 4 bits then can
|
|---|
| 1325 |
|
|---|
| 1326 | 00:21:54.380-->00:21:59.852
|
|---|
| 1327 | actually do 32 bit colors. So
|
|---|
| 1328 | this allows you to save space.
|
|---|
| 1329 | Right? You can have at most 16
|
|---|
| 1330 |
|
|---|
| 1331 | 00:21:59.852-->00:22:05.024
|
|---|
| 1332 | different colors. but you can
|
|---|
| 1333 | have colors that are 32 bit
|
|---|
| 1334 | deep. Um so now the big question
|
|---|
| 1335 |
|
|---|
| 1336 | 00:22:05.024-->00:22:11.664
|
|---|
| 1337 | is how where's the lookup table?
|
|---|
| 1338 | Can we change it? Can we modify
|
|---|
| 1339 | it? Uh and then we did a very
|
|---|
| 1340 |
|
|---|
| 1341 | 00:22:11.664-->00:22:16.702
|
|---|
| 1342 | you know again very sober very
|
|---|
| 1343 | collaborative work with
|
|---|
| 1344 | Francois. Right? And we did this
|
|---|
| 1345 |
|
|---|
| 1346 | 00:22:16.702-->00:22:21.707
|
|---|
| 1347 | for days n days to try and
|
|---|
| 1348 | figure this out. Where he dumped
|
|---|
| 1349 | lots of memory and we helped a
|
|---|
| 1350 |
|
|---|
| 1351 | 00:22:21.707-->00:22:26.612
|
|---|
| 1352 | lot. And uh like 2 days later
|
|---|
| 1353 | okay we finally find the
|
|---|
| 1354 | structure that we think is the
|
|---|
| 1355 |
|
|---|
| 1356 | 00:22:26.612-->00:22:30.649
|
|---|
| 1357 | lookup table. >>So it works in a
|
|---|
| 1358 | similar way how we were
|
|---|
| 1359 | transferring the images in the
|
|---|
| 1360 |
|
|---|
| 1361 | 00:22:30.649-->00:22:35.754
|
|---|
| 1362 | command packets. So you generate
|
|---|
| 1363 | specific color lookup table
|
|---|
| 1364 | structure. And you write OSM
|
|---|
| 1365 |
|
|---|
| 1366 | 00:22:35.754-->00:22:39.758
|
|---|
| 1367 | memory um memory map that
|
|---|
| 1368 | [indiscernible] displays the
|
|---|
| 1369 | color for that specific image.
|
|---|
| 1370 |
|
|---|
| 1371 | 00:22:39.758-->00:22:42.761
|
|---|
| 1372 | >>Okay so we have everything
|
|---|
| 1373 | that we need. Okay we gonna uh
|
|---|
| 1374 | display a photo. And we did.
|
|---|
| 1375 |
|
|---|
| 1376 | 00:22:42.761-->00:22:45.297
|
|---|
| 1377 | Okay? So look at that. We have
|
|---|
| 1378 | tiny little SSL locks. We have
|
|---|
| 1379 | as many as want wherever we want
|
|---|
| 1380 |
|
|---|
| 1381 | 00:22:45.297-->00:22:47.299
|
|---|
| 1382 | it. And that was sort of the
|
|---|
| 1383 | point of this. Right? Uh but I
|
|---|
| 1384 | looked at it and I said we still
|
|---|
| 1385 |
|
|---|
| 1386 | 00:22:47.299-->00:22:52.304
|
|---|
| 1387 | only have 16 colors. And that
|
|---|
| 1388 | SSL lock actually had something
|
|---|
| 1389 | like 20 >>26 >>26 colors! So
|
|---|
| 1390 |
|
|---|
| 1391 | 00:22:57.543-->00:23:02.481
|
|---|
| 1392 | that's not enough colors Jaden.
|
|---|
| 1393 | We need more colors. >>It's
|
|---|
| 1394 | really hard has been really hard
|
|---|
| 1395 |
|
|---|
| 1396 | 00:23:04.884-->00:23:09.488
|
|---|
| 1397 | now. >>Yeah. >>So we went
|
|---|
| 1398 | through some docs and uh we
|
|---|
| 1399 | figured out like uh the hardware
|
|---|
| 1400 |
|
|---|
| 1401 | 00:23:09.488-->00:23:15.527
|
|---|
| 1402 | does support at least a bit per
|
|---|
| 1403 | pixel. So uh and and until recon
|
|---|
| 1404 | we didn't have we had only 4 bit
|
|---|
| 1405 |
|
|---|
| 1406 | 00:23:15.527-->00:23:19.265
|
|---|
| 1407 | per pixel but now we have uh
|
|---|
| 1408 | fixed up to get 256 colors and
|
|---|
| 1409 | the code is [indiscernible]. Uh
|
|---|
| 1410 |
|
|---|
| 1411 | 00:23:19.265-->00:23:25.738
|
|---|
| 1412 | but after going over more
|
|---|
| 1413 | analysis of the documentation
|
|---|
| 1414 | there is the documentation that
|
|---|
| 1415 |
|
|---|
| 1416 | 00:23:25.738-->00:23:30.242
|
|---|
| 1417 | we found. We we found a break
|
|---|
| 1418 | point so which means that we can
|
|---|
| 1419 | hold the monitor figure out
|
|---|
| 1420 |
|
|---|
| 1421 | 00:23:30.242-->00:23:34.146
|
|---|
| 1422 | everything and this is like
|
|---|
| 1423 | after like 90% of the research
|
|---|
| 1424 | we have already done. We're
|
|---|
| 1425 |
|
|---|
| 1426 | 00:23:34.146-->00:23:40.085
|
|---|
| 1427 | spending like weeks on it. Um
|
|---|
| 1428 | even months and now if if we
|
|---|
| 1429 | were to have access to this
|
|---|
| 1430 |
|
|---|
| 1431 | 00:23:40.085-->00:23:44.056
|
|---|
| 1432 | break point we would have
|
|---|
| 1433 | finished it in probably like
|
|---|
| 1434 | half 1-n-half weeks or 2 weeks.
|
|---|
| 1435 |
|
|---|
| 1436 | 00:23:44.056-->00:23:47.126
|
|---|
| 1437 | >>Yeah so at this point Jaden
|
|---|
| 1438 | and I just kind of like put our
|
|---|
| 1439 | hands up in the air and was like
|
|---|
| 1440 |
|
|---|
| 1441 | 00:23:47.126-->00:23:51.997
|
|---|
| 1442 | argh I can't believe we missed
|
|---|
| 1443 | that one. Or that's terrible.
|
|---|
| 1444 | You know so we said like interns
|
|---|
| 1445 |
|
|---|
| 1446 | 00:23:51.997-->00:23:55.367
|
|---|
| 1447 | go do the rest of it. Right?
|
|---|
| 1448 | Break point everything reverse
|
|---|
| 1449 | it tell us what it is and
|
|---|
| 1450 |
|
|---|
| 1451 | 00:23:55.367-->00:23:59.204
|
|---|
| 1452 | Francois helped. The interns
|
|---|
| 1453 | went out uh dumped the static
|
|---|
| 1454 | dumped the heat you know found
|
|---|
| 1455 |
|
|---|
| 1456 | 00:23:59.204-->00:24:03.375
|
|---|
| 1457 | pretty much everything we needed
|
|---|
| 1458 | to do. All the demos that I'll
|
|---|
| 1459 | show you later. Uh and then we
|
|---|
| 1460 |
|
|---|
| 1461 | 00:24:03.375-->00:24:09.281
|
|---|
| 1462 | find the treasure. >>This was
|
|---|
| 1463 | very surprising because we the
|
|---|
| 1464 | OSD should be allowed to display
|
|---|
| 1465 |
|
|---|
| 1466 | 00:24:09.281-->00:24:13.452
|
|---|
| 1467 | a pixel on the image on the
|
|---|
| 1468 | screen but it should it is very
|
|---|
| 1469 | surprising that it has the
|
|---|
| 1470 |
|
|---|
| 1471 | 00:24:13.452-->00:24:18.324
|
|---|
| 1472 | capability to read pixels
|
|---|
| 1473 | anywhere on the screen. And what
|
|---|
| 1474 | can you do with that now? >>Yeah
|
|---|
| 1475 |
|
|---|
| 1476 | 00:24:18.324-->00:24:22.761
|
|---|
| 1477 | we'll talk about that in a
|
|---|
| 1478 | little bit. So we presented some
|
|---|
| 1479 | of the research uh at recon and
|
|---|
| 1480 |
|
|---|
| 1481 | 00:24:22.761-->00:24:26.598
|
|---|
| 1482 | after the presentation people
|
|---|
| 1483 | who actually knew how monitors
|
|---|
| 1484 | worked came up to us and said
|
|---|
| 1485 |
|
|---|
| 1486 | 00:24:26.598-->00:24:30.035
|
|---|
| 1487 | like hey stupid! You don't
|
|---|
| 1488 | actually even need the USB cable
|
|---|
| 1489 | because you know there
|
|---|
| 1490 |
|
|---|
| 1491 | 00:24:30.035-->00:24:37.009
|
|---|
| 1492 | [indiscernible] I 2 C channels
|
|---|
| 1493 | on uh DVI HDMI and VGA etc. So
|
|---|
| 1494 | we actually ported the code to
|
|---|
| 1495 |
|
|---|
| 1496 | 00:24:37.009-->00:24:42.848
|
|---|
| 1497 | run over the I 2 C interface.
|
|---|
| 1498 | And now our demos do not require
|
|---|
| 1499 | USB at all. Although it can be
|
|---|
| 1500 |
|
|---|
| 1501 | 00:24:42.848-->00:24:48.520
|
|---|
| 1502 | done over both channels. Um and
|
|---|
| 1503 | that stuff [indiscernible]. Now,
|
|---|
| 1504 | let's have some fun with it.
|
|---|
| 1505 |
|
|---|
| 1506 | 00:24:48.520-->00:24:53.192
|
|---|
| 1507 | Right? Let's make a monitor
|
|---|
| 1508 | implant. So let's assume that we
|
|---|
| 1509 | have a very simple base implant
|
|---|
| 1510 |
|
|---|
| 1511 | 00:24:53.192-->00:24:57.963
|
|---|
| 1512 | in the monitor. Okay? And let's
|
|---|
| 1513 | also assume that I'm a sneaky
|
|---|
| 1514 | guy and I have control over a
|
|---|
| 1515 |
|
|---|
| 1516 | 00:24:57.963-->00:25:03.736
|
|---|
| 1517 | pixel. Right? So if I blink the
|
|---|
| 1518 | pixel I should be able to
|
|---|
| 1519 | transmit data to my you know
|
|---|
| 1520 |
|
|---|
| 1521 | 00:25:03.736-->00:25:08.841
|
|---|
| 1522 | base monitor implant. And I can
|
|---|
| 1523 | do something very much similar
|
|---|
| 1524 | to command and control. Right?
|
|---|
| 1525 |
|
|---|
| 1526 | 00:25:08.841-->00:25:13.679
|
|---|
| 1527 | So every time I sample a pixel I
|
|---|
| 1528 | can change the data and I can do
|
|---|
| 1529 | something like the command type
|
|---|
| 1530 |
|
|---|
| 1531 | 00:25:13.679-->00:25:18.684
|
|---|
| 1532 | data data data which allows me
|
|---|
| 1533 | to load or return code or return
|
|---|
| 1534 | data X 2 code and do all sorts
|
|---|
| 1535 |
|
|---|
| 1536 | 00:25:18.684-->00:25:23.722
|
|---|
| 1537 | of other things. Now we take
|
|---|
| 1538 | this pixel. We put it on the
|
|---|
| 1539 | internet. Right? And as we know
|
|---|
| 1540 |
|
|---|
| 1541 | 00:25:23.722-->00:25:29.228
|
|---|
| 1542 | the internet is used for one
|
|---|
| 1543 | thing. Right? So we can put this
|
|---|
| 1544 | pixel on photos of cats. Right?
|
|---|
| 1545 |
|
|---|
| 1546 | 00:25:29.228-->00:25:34.266
|
|---|
| 1547 | We can do YouTube videos of
|
|---|
| 1548 | cats. We even do you know movies
|
|---|
| 1549 | about cats. And once we do this
|
|---|
| 1550 |
|
|---|
| 1551 | 00:25:34.266-->00:25:38.804
|
|---|
| 1552 | we can distribute this pixel
|
|---|
| 1553 | down to millions and millions of
|
|---|
| 1554 | monitors and we update them all
|
|---|
| 1555 |
|
|---|
| 1556 | 00:25:38.804-->00:25:43.041
|
|---|
| 1557 | at the same time. And we can
|
|---|
| 1558 | have direct command command and
|
|---|
| 1559 | control down to those exact
|
|---|
| 1560 |
|
|---|
| 1561 | 00:25:43.041-->00:25:47.980
|
|---|
| 1562 | monitors. Okay? And within our
|
|---|
| 1563 | organization this is commonly
|
|---|
| 1564 | known as cap base for domination
|
|---|
| 1565 |
|
|---|
| 1566 | 00:25:47.980-->00:25:54.953
|
|---|
| 1567 | plan #7. Okay? Uh now so in the
|
|---|
| 1568 | end what do we do? Okay? We
|
|---|
| 1569 | figured out that we can change
|
|---|
| 1570 |
|
|---|
| 1571 | 00:25:54.953-->00:25:59.625
|
|---|
| 1572 | whatever pixel on the screen
|
|---|
| 1573 | wherever we want. Uh we can also
|
|---|
| 1574 | see every pixel on the screen
|
|---|
| 1575 |
|
|---|
| 1576 | 00:25:59.625-->00:26:03.562
|
|---|
| 1577 | which is really cool. And uh for
|
|---|
| 1578 | those folks who have followed
|
|---|
| 1579 | our previous research we even
|
|---|
| 1580 |
|
|---|
| 1581 | 00:26:03.562-->00:26:07.866
|
|---|
| 1582 | got Funtana to work on the
|
|---|
| 1583 | monitors as well but that's its
|
|---|
| 1584 | own conversation that we'll have
|
|---|
| 1585 |
|
|---|
| 1586 | 00:26:07.866-->00:26:13.872
|
|---|
| 1587 | later. So you know I've talked
|
|---|
| 1588 | right we're going to do some
|
|---|
| 1589 | demos. Okay? Uh and then first I
|
|---|
| 1590 |
|
|---|
| 1591 | 00:26:13.872-->00:26:18.877
|
|---|
| 1592 | have to figure out how do this
|
|---|
| 1593 | work? [indiscernible] [long
|
|---|
| 1594 | pause] We swear there's an
|
|---|
| 1595 |
|
|---|
| 1596 | 00:26:36.495-->00:26:42.367
|
|---|
| 1597 | actual monitor underneath this
|
|---|
| 1598 | table and the demo is not
|
|---|
| 1599 | rigged. Uh but shooting a camera
|
|---|
| 1600 |
|
|---|
| 1601 | 00:26:42.367-->00:26:47.372
|
|---|
| 1602 | at the monitor is a little bit
|
|---|
| 1603 | difficult so does it work? >>I
|
|---|
| 1604 | think your >>No
|
|---|
| 1605 |
|
|---|
| 1606 | 00:26:55.247-->00:27:00.185
|
|---|
| 1607 | >>[indiscernible] >>Alright
|
|---|
| 1608 | [indiscernible] we go >>Okay so
|
|---|
| 1609 | I'm gonna talk from under the
|
|---|
| 1610 |
|
|---|
| 1611 | 00:27:07.626-->00:27:12.631
|
|---|
| 1612 | table >>Yeah >>So first I'm
|
|---|
| 1613 | going to show you how to put
|
|---|
| 1614 | brand new people pictures on the
|
|---|
| 1615 |
|
|---|
| 1616 | 00:27:15.667-->00:27:20.672
|
|---|
| 1617 | screen and you can uh not remove
|
|---|
| 1618 | it. So I'm so this is Shakib
|
|---|
| 1619 | that we talked about. And his
|
|---|
| 1620 |
|
|---|
| 1621 | 00:27:23.041-->00:27:27.312
|
|---|
| 1622 | picture is going to be on the
|
|---|
| 1623 | monitor. >>So this is a typical
|
|---|
| 1624 | you know you put new machine no
|
|---|
| 1625 |
|
|---|
| 1626 | 00:27:27.312-->00:27:33.151
|
|---|
| 1627 | uh administrative privilege and
|
|---|
| 1628 | where showing you know putting
|
|---|
| 1629 | an image on the screen. Now we
|
|---|
| 1630 |
|
|---|
| 1631 | 00:27:33.151-->00:27:36.955
|
|---|
| 1632 | didn't do this in genhub but we
|
|---|
| 1633 | can actually make this
|
|---|
| 1634 | permanent. So imagine if that
|
|---|
| 1635 |
|
|---|
| 1636 | 00:27:36.955-->00:27:41.226
|
|---|
| 1637 | happened to you. How terrible
|
|---|
| 1638 | your life would be? Alright?
|
|---|
| 1639 | >>So my second attack will be
|
|---|
| 1640 |
|
|---|
| 1641 | 00:27:41.226-->00:27:46.798
|
|---|
| 1642 | you all know about fortune
|
|---|
| 1643 | right? And it is not uh it
|
|---|
| 1644 | doesn't have any D list uh
|
|---|
| 1645 |
|
|---|
| 1646 | 00:27:46.798-->00:27:49.902
|
|---|
| 1647 | capabilities. But I'm going to
|
|---|
| 1648 | give it to you. >>We're going to
|
|---|
| 1649 | secure fortune for everybody.
|
|---|
| 1650 |
|
|---|
| 1651 | 00:27:49.902-->00:27:53.672
|
|---|
| 1652 | >>We did! >>So check it out.
|
|---|
| 1653 | Right? Can you like move it a
|
|---|
| 1654 | little bit? If you can see that
|
|---|
| 1655 |
|
|---|
| 1656 | 00:27:53.672-->00:27:58.043
|
|---|
| 1657 | closely. Right? So we get to put
|
|---|
| 1658 | SSL locks wherever we want. And
|
|---|
| 1659 | if we just line it up right
|
|---|
| 1660 |
|
|---|
| 1661 | 00:27:58.043-->00:28:03.482
|
|---|
| 1662 | it'll be right on the browser
|
|---|
| 1663 | where SSL lock ought to be. So
|
|---|
| 1664 | now fortune has SSL. So yay!
|
|---|
| 1665 |
|
|---|
| 1666 | 00:28:03.482-->00:28:10.422
|
|---|
| 1667 | >>Uh the next stack will be the
|
|---|
| 1668 | you if you guys know about
|
|---|
| 1669 | [indiscernible] faces uh where
|
|---|
| 1670 |
|
|---|
| 1671 | 00:28:10.422-->00:28:14.993
|
|---|
| 1672 | you know in power plants and uh
|
|---|
| 1673 | [indiscernible] operator
|
|---|
| 1674 | [indiscernible] what has gone
|
|---|
| 1675 |
|
|---|
| 1676 | 00:28:14.993-->00:28:19.932
|
|---|
| 1677 | wrong in a power plant system or
|
|---|
| 1678 | a nuclear fusion system. So if
|
|---|
| 1679 | you look at that green light it
|
|---|
| 1680 |
|
|---|
| 1681 | 00:28:19.932-->00:28:26.338
|
|---|
| 1682 | tells that uh that uh whatever
|
|---|
| 1683 | gun battle is perfectly working
|
|---|
| 1684 | fine but I'm going to change
|
|---|
| 1685 |
|
|---|
| 1686 | 00:28:26.338-->00:28:32.578
|
|---|
| 1687 | that to [pause] what >>Alright.
|
|---|
| 1688 | So what if we were able to right
|
|---|
| 1689 | show the different status of the
|
|---|
| 1690 |
|
|---|
| 1691 | 00:28:32.578-->00:28:36.949
|
|---|
| 1692 | uh industrial control system
|
|---|
| 1693 | just by changing the pixels that
|
|---|
| 1694 | said this pump is good this pump
|
|---|
| 1695 |
|
|---|
| 1696 | 00:28:36.949-->00:28:42.120
|
|---|
| 1697 | is bad. What if we're able to
|
|---|
| 1698 | change the operatives behavior
|
|---|
| 1699 | just by changing the pixels on
|
|---|
| 1700 |
|
|---|
| 1701 | 00:28:42.120-->00:28:46.291
|
|---|
| 1702 | the monitor? Right? We'd have a
|
|---|
| 1703 | fundamental trust of you know we
|
|---|
| 1704 | trust that whatever pixels are
|
|---|
| 1705 |
|
|---|
| 1706 | 00:28:46.291-->00:28:50.162
|
|---|
| 1707 | coming out of the computer will
|
|---|
| 1708 | be displayed on the monitor and
|
|---|
| 1709 | we're seeing that this is
|
|---|
| 1710 |
|
|---|
| 1711 | 00:28:50.162-->00:28:54.866
|
|---|
| 1712 | actually not even true. Okay? So
|
|---|
| 1713 | the last one we're going to do
|
|---|
| 1714 | is going to show the uh the
|
|---|
| 1715 |
|
|---|
| 1716 | 00:28:54.866-->00:28:58.537
|
|---|
| 1717 | blinking pixel command and
|
|---|
| 1718 | control. You know that we talked
|
|---|
| 1719 | about? So on the left side
|
|---|
| 1720 |
|
|---|
| 1721 | 00:28:58.537-->00:29:02.441
|
|---|
| 1722 | right? We have a paypal page or
|
|---|
| 1723 | paypal account. Uh I don't have
|
|---|
| 1724 | any money in this paypal account
|
|---|
| 1725 |
|
|---|
| 1726 | 00:29:02.441-->00:29:07.312
|
|---|
| 1727 | which is really sad. Uh Jaden's
|
|---|
| 1728 | going to change that for me.
|
|---|
| 1729 | Alright? >>I'm gonna put how
|
|---|
| 1730 |
|
|---|
| 1731 | 00:29:07.312-->00:29:09.314
|
|---|
| 1732 | much money do you want? >>Like a
|
|---|
| 1733 | mill million dollars. >>Okay
|
|---|
| 1734 | let's do it. >>One million
|
|---|
| 1735 |
|
|---|
| 1736 | 00:29:09.314-->00:29:11.316
|
|---|
| 1737 | dollars. [pause] >>Alright so I
|
|---|
| 1738 | also gave it uh SSL protection
|
|---|
| 1739 | that fishing page. >>Great.
|
|---|
| 1740 |
|
|---|
| 1741 | 00:29:11.316-->00:29:17.889
|
|---|
| 1742 | [laughter/clapping] There ya go!
|
|---|
| 1743 | >>I put a million dollars! >>And
|
|---|
| 1744 | the way this is working is
|
|---|
| 1745 |
|
|---|
| 1746 | 00:29:17.889-->00:29:22.894
|
|---|
| 1747 | there's a tiny little blinking
|
|---|
| 1748 | pixel on the right screen that's
|
|---|
| 1749 | communicating to the monitor.
|
|---|
| 1750 |
|
|---|
| 1751 | 00:29:28.867-->00:29:34.072
|
|---|
| 1752 | Telling the monitor to put this
|
|---|
| 1753 | image at this specific value.
|
|---|
| 1754 | And uh we can do this of course
|
|---|
| 1755 |
|
|---|
| 1756 | 00:29:34.072-->00:29:38.110
|
|---|
| 1757 | in real time. >>But Ang I don't
|
|---|
| 1758 | want to give you a million
|
|---|
| 1759 | dollar. I want to change it now.
|
|---|
| 1760 |
|
|---|
| 1761 | 00:29:38.110-->00:29:44.483
|
|---|
| 1762 | I'm >>Noooo >>No let me let me
|
|---|
| 1763 | >>[giggle] >>So what we're doing
|
|---|
| 1764 | is uh we gonna so let's suppose
|
|---|
| 1765 |
|
|---|
| 1766 | 00:29:44.483-->00:29:49.488
|
|---|
| 1767 | we're going we gonna send a
|
|---|
| 1768 | command and control packet our
|
|---|
| 1769 | from our server. oops
|
|---|
| 1770 |
|
|---|
| 1771 | 00:29:57.996-->00:30:03.001
|
|---|
| 1772 | [indiscernible] [long pause] my
|
|---|
| 1773 | server has gone down. [long
|
|---|
| 1774 | pause] [laughter] [talking off
|
|---|
| 1775 |
|
|---|
| 1776 | 00:30:11.143-->00:30:15.213
|
|---|
| 1777 | mic] >>Okay so anyway that's a
|
|---|
| 1778 | demo. Right? And all the all the
|
|---|
| 1779 | code that went into this demo is
|
|---|
| 1780 |
|
|---|
| 1781 | 00:30:15.213-->00:30:20.218
|
|---|
| 1782 | up on our [indiscernible] Is it
|
|---|
| 1783 | working? Is it working? >>Okay
|
|---|
| 1784 | yep. >>Yeah? Okay. [long pause]
|
|---|
| 1785 |
|
|---|
| 1786 | 00:30:41.506-->00:30:46.511
|
|---|
| 1787 | [off mic noises] >>Okay so I'm
|
|---|
| 1788 | going to give you how much you
|
|---|
| 1789 | want to [long pause] >>No yeah I
|
|---|
| 1790 |
|
|---|
| 1791 | 00:30:50.415-->00:30:55.087
|
|---|
| 1792 | mean. Okay so anyway. All the
|
|---|
| 1793 | code that went into this demo is
|
|---|
| 1794 | in [indiscernible] ready. Uh the
|
|---|
| 1795 |
|
|---|
| 1796 | 00:30:55.087-->00:31:00.025
|
|---|
| 1797 | link is on [loud mic drop] [long
|
|---|
| 1798 | pause] Okay so let's talk about
|
|---|
| 1799 | what this means. Okay?
|
|---|
| 1800 |
|
|---|
| 1801 | 00:31:10.168-->00:31:13.872
|
|---|
| 1802 | Implication wise. You know the
|
|---|
| 1803 | first question is you know how
|
|---|
| 1804 | big is this problem really?
|
|---|
| 1805 |
|
|---|
| 1806 | 00:31:13.872-->00:31:18.043
|
|---|
| 1807 | Right? We looked at a single
|
|---|
| 1808 | onscreen display implementation
|
|---|
| 1809 | for one type of monitor. Uh you
|
|---|
| 1810 |
|
|---|
| 1811 | 00:31:18.043-->00:31:21.780
|
|---|
| 1812 | know we certainly found some
|
|---|
| 1813 | vulnerabilities in it but you
|
|---|
| 1814 | know is this a pervasive thing?
|
|---|
| 1815 |
|
|---|
| 1816 | 00:31:21.780-->00:31:26.118
|
|---|
| 1817 | So to answer that question we
|
|---|
| 1818 | bought 4 other types of monitors
|
|---|
| 1819 | that are very common. You know
|
|---|
| 1820 |
|
|---|
| 1821 | 00:31:26.118-->00:31:30.255
|
|---|
| 1822 | there on the budget end of
|
|---|
| 1823 | things 24 monitors inch monitors
|
|---|
| 1824 | that are approximately between
|
|---|
| 1825 |
|
|---|
| 1826 | 00:31:30.255-->00:31:36.828
|
|---|
| 1827 | $100 to $200. That we we looked
|
|---|
| 1828 | at Samsung, Dell,Acer, HP. And
|
|---|
| 1829 | uh what's inside these guys uh
|
|---|
| 1830 |
|
|---|
| 1831 | 00:31:36.828-->00:31:42.901
|
|---|
| 1832 | these chips these boards. Uh the
|
|---|
| 1833 | bad news is they're not uh SD
|
|---|
| 1834 | micro. They don't run g-code or
|
|---|
| 1835 |
|
|---|
| 1836 | 00:31:42.901-->00:31:47.773
|
|---|
| 1837 | g-probe. Uh the good news is
|
|---|
| 1838 | this one is Amstar. That one is
|
|---|
| 1839 | Amstar. And this one is also
|
|---|
| 1840 |
|
|---|
| 1841 | 00:31:47.773-->00:31:52.677
|
|---|
| 1842 | Amstar. And so is this one.
|
|---|
| 1843 | Right? So is seems like Amstar
|
|---|
| 1844 | is uh you know very pervasive
|
|---|
| 1845 |
|
|---|
| 1846 | 00:31:52.677-->00:31:57.449
|
|---|
| 1847 | right? A popular OSD controller
|
|---|
| 1848 | that's used in the lower uh the
|
|---|
| 1849 | cheaper segment of the market.
|
|---|
| 1850 |
|
|---|
| 1851 | 00:31:57.449-->00:32:01.620
|
|---|
| 1852 | And it turns out that this
|
|---|
| 1853 | really cool dude named Alex
|
|---|
| 1854 | Bohlen already did all the work
|
|---|
| 1855 |
|
|---|
| 1856 | 00:32:01.620-->00:32:07.225
|
|---|
| 1857 | for us. So he figured out the
|
|---|
| 1858 | way to uh do firmware updates to
|
|---|
| 1859 | all Amstar uh micr onscreen
|
|---|
| 1860 |
|
|---|
| 1861 | 00:32:07.225-->00:32:12.764
|
|---|
| 1862 | controllers. And uh this is
|
|---|
| 1863 | actually like a featured inside
|
|---|
| 1864 | the limits kernel now. Right? So
|
|---|
| 1865 |
|
|---|
| 1866 | 00:32:12.764-->00:32:17.636
|
|---|
| 1867 | that's the link. This work has
|
|---|
| 1868 | already been done. Um so it
|
|---|
| 1869 | looks like the same type of
|
|---|
| 1870 |
|
|---|
| 1871 | 00:32:17.636-->00:32:21.973
|
|---|
| 1872 | vulnerability that is
|
|---|
| 1873 | fundamental to the Dell monitor
|
|---|
| 1874 | is also within it's also within
|
|---|
| 1875 |
|
|---|
| 1876 | 00:32:21.973-->00:32:26.044
|
|---|
| 1877 | these other Amstar monitors
|
|---|
| 1878 | which means you know it probably
|
|---|
| 1879 | would have made more than a
|
|---|
| 1880 |
|
|---|
| 1881 | 00:32:26.044-->00:32:30.115
|
|---|
| 1882 | billion monitors. Right? So in
|
|---|
| 1883 | the last 10 years and most of
|
|---|
| 1884 | those it looks like will be
|
|---|
| 1885 |
|
|---|
| 1886 | 00:32:30.115-->00:32:34.619
|
|---|
| 1887 | vulnerable to some type of
|
|---|
| 1888 | attack like this. Okay and uh
|
|---|
| 1889 | the next question is you know
|
|---|
| 1890 |
|
|---|
| 1891 | 00:32:34.619-->00:32:39.391
|
|---|
| 1892 | how practical is this attack? I
|
|---|
| 1893 | mean you guys have to make up
|
|---|
| 1894 | your own mind about. Right? But
|
|---|
| 1895 |
|
|---|
| 1896 | 00:32:39.391-->00:32:44.529
|
|---|
| 1897 | keep in mind that we don't have
|
|---|
| 1898 | to have any privilege uh on the
|
|---|
| 1899 | on the computer in order to
|
|---|
| 1900 |
|
|---|
| 1901 | 00:32:44.529-->00:32:50.335
|
|---|
| 1902 | launch this type of thing. So
|
|---|
| 1903 | any unprivileged code execution
|
|---|
| 1904 | will allow permanent persistent
|
|---|
| 1905 |
|
|---|
| 1906 | 00:32:50.335-->00:32:55.040
|
|---|
| 1907 | firmware modification inside the
|
|---|
| 1908 | monitor. Right? And uh last big
|
|---|
| 1909 | question is you know how
|
|---|
| 1910 |
|
|---|
| 1911 | 00:32:55.040-->00:33:00.979
|
|---|
| 1912 | realistic is this fix? You know
|
|---|
| 1913 | because I the way to fix this
|
|---|
| 1914 | now right without a physical
|
|---|
| 1915 |
|
|---|
| 1916 | 00:33:00.979-->00:33:05.183
|
|---|
| 1917 | recall would be to have the
|
|---|
| 1918 | vendor distribute a firmware
|
|---|
| 1919 | update tool that patches some of
|
|---|
| 1920 |
|
|---|
| 1921 | 00:33:05.183-->00:33:10.522
|
|---|
| 1922 | these you know insecurities
|
|---|
| 1923 | about firmware updates and code
|
|---|
| 1924 | execution. Okay? But if they did
|
|---|
| 1925 |
|
|---|
| 1926 | 00:33:10.522-->00:33:14.659
|
|---|
| 1927 | that they would also release
|
|---|
| 1928 | exactly the algorithm and the
|
|---|
| 1929 | protocol for updating all the
|
|---|
| 1930 |
|
|---|
| 1931 | 00:33:14.659-->00:33:20.732
|
|---|
| 1932 | firmware all the monitors. So
|
|---|
| 1933 | this is not exactly a simple
|
|---|
| 1934 | thing to do. Um and uh you know
|
|---|
| 1935 |
|
|---|
| 1936 | 00:33:20.732-->00:33:24.603
|
|---|
| 1937 | this is um something that I
|
|---|
| 1938 | would like the community to talk
|
|---|
| 1939 | about. You know is monitor
|
|---|
| 1940 |
|
|---|
| 1941 | 00:33:24.603-->00:33:30.709
|
|---|
| 1942 | security important? I think it
|
|---|
| 1943 | is. How do we actually uh secure
|
|---|
| 1944 | the monitors that we have now?
|
|---|
| 1945 |
|
|---|
| 1946 | 00:33:30.709-->00:33:35.513
|
|---|
| 1947 | Right? And how do we build more
|
|---|
| 1948 | secure monitors in the future.
|
|---|
| 1949 | So uh that's pretty much my
|
|---|
| 1950 |
|
|---|
| 1951 | 00:33:35.513-->00:33:41.386
|
|---|
| 1952 | presentation and uh I have to
|
|---|
| 1953 | say this, you know we're we're
|
|---|
| 1954 | from Rebleware Security. We do
|
|---|
| 1955 |
|
|---|
| 1956 | 00:33:41.386-->00:33:45.523
|
|---|
| 1957 | imbedded security stuff when
|
|---|
| 1958 | we're hired. So if you want to
|
|---|
| 1959 | do this type of research, uh get
|
|---|
| 1960 |
|
|---|
| 1961 | 00:33:45.523-->00:33:50.595
|
|---|
| 1962 | in touch with us. And also big
|
|---|
| 1963 | thanks to [indiscernible] Abbot
|
|---|
| 1964 | who did a lot of the demo code.
|
|---|
| 1965 |
|
|---|
| 1966 | 00:33:50.595-->00:33:55.533
|
|---|
| 1967 | Um Bob drew all this stuff that
|
|---|
| 1968 | wasn't terrible. And Brian who
|
|---|
| 1969 | also helped a lot and he's in
|
|---|
| 1970 |
|
|---|
| 1971 | 00:33:55.533-->00:34:00.538
|
|---|
| 1972 | the front row. So thank you very
|
|---|
| 1973 | much. This is where the code is
|
|---|
| 1974 | Uh for all this work. Uh check
|
|---|
| 1975 |
|
|---|
| 1976 | 00:34:00.538-->00:34:05.543
|
|---|
| 1977 | it out. [applause]
|
|---|
| 1978 |
|
|---|