badge Tech Siddhi: Hacking










Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Saturday, 25 April 2020

Apple iOS 13 has sever security flaws including zero click hack in its mail app - Researchers

A new potentially serious software vulnerability has been discovered in iOS 13 that works via the default Mail app on iPhone and iPad. Security researchers say the iPhone has a severe flaw in the native iOS Mail app that makes it vulnerable to hackers.
 
Representation image only


Commenting on this Satnam Narang, Principal Research Engineer at Tenable said, "The recent disclosure that multiple zero-days in the Apple iOS Mail application were exploited in the wild is significant and noteworthy. One of the flaws can be exploited without user interaction (also known as zero click) on iOS 13. The vulnerabilities also affect iOS 12, though interaction is required in most cases.

Exploitation of these flaws would allow an attacker to leak, modify or delete emails within the Mail application. However, the researchers note that combining these flaws with an unpatched kernel vulnerability would provide an attacker with full device access, though that information has not been identified as of yet.

While Apple has issued fixes for these flaws in the beta version of iOS 13.4.5, devices are still vulnerable until the final version of iOS 13.4.5 is readily available to all iOS device owners. In the interim, the only mitigation for these flaws is to disable any email accounts that are connected to the iOS Mail application, and use an alternative application, such as Microsoft Outlook or Google's GMail."

Wednesday, 23 September 2015

16 characters in Google's Chrome address bar and it's gone

An interesting bug is said to be present in one of the most used browsers , Google Chrome. The bug is found by security researcher Andris Atteka from Latvia. The blog post says 

"Recently I reported a crash bug in Google Chrome (issue #533361). This issue reminded me of the recent Skype vulnerability - both occur with simple URL strings. So how can you crash Google Chrome? By adding a NULL char in the URL string:

http://biome3d.com/%%30%30"

 Once you hit this URL in your chrome browser you , the browser will crash  immediately, even hovering your mouse over the link will cause the crash or atleast this particular tab will crash if not the whole browser.

Turns out to be that the crash can be reproduced by replacing "biome3d.com" with a single character like 'a' and the bug lies in parsing null present in the URL.

The vulnerability was reported as a security bug but the bounty was turned down as it is deemed as a DOS attack rather than a security issue, said Andris in his blog. Earlier the bug was thought to be only affecting desktop versions of Chrome Browser but some users have reported that this is reproducible on Android version of the browser as well.

Interesting aspect of the bug is that a user szhu created a maze game (pic below) wherein the maze comprises of trees and bears, you have to hover your mouse over bears to reach from one end to another but the moment you touch trees your tab will crash and now you know why. 

Maze Game

You can also try this game by heading on to Github page , though hovering over will only crash your current tab, but we recommend to close all your important tabs and then try the game in case you accidentally click on any of the trees it will lead in crashing of the browser itself.

Tuesday, 18 August 2015

How a simple hack turned $5 Amazon dash into multi purpose IOT device

Amazon recently launched its $5 dash buttons which allows you to order your house hold goods with just a click. These buttons are physical hardware buttons which can be set up to order a particular SKU on Amazon with just a click. The device makes it easier to order household goods like detergents, paper towels, diapers, personal care items etc. One device can be set up to order only one SKU, but CloudStitch CTO Ted Benson had other plans in his mind. He just hacked this petty device and found a way that can make these devices do pretty much everything he wants.

Ted, has detailed in a post on medium.com how he hacked the device to track his child's poops. He mentioned that impressive way to do this would have been to rip open the device  and reprogram it, however being a lazy dad he chose the other option of sniffing his wifi network whenever a device requested for a connection and then record a data point when it hears some.

By this time if you haven't clicked on the link above to see the detailed post, here is a summary of actions how this hack was done.

  • First step is to configure your Amazon dash button as per the instructions provided except the last step where in you are asked to give the SKU of product you want to order. This will ensure that your device connects to your network and is ready to trigger some action when you push the button.
  • Run a small python code written below to sniff your wifi network, to get details when the dash button is connected to wifi. 
from scapy.all import *
def arp_display(pkt):
if pkt[ARP].op == 1: #who-has (request)
if pkt[ARP].psrc == '0.0.0.0': # ARP Probe
print "ARP Probe from: " + pkt[ARP].hwsrc
print sniff(prn=arp_display, filter="arp", store=0, count=10)
  • Note down the mac address of devices you connected as shown in below pic.
  • Now modify the above code with the MAC addresses got from the above step.

    from scapy.all import * def arp_display(pkt):
    if pkt[ARP].op == 1: #who-has (request)
    if pkt[ARP].psrc == '0.0.0.0': # ARP Probe
    if pkt[ARP].hwsrc == '74:75:48:5f:99:30': # Huggies
    print "Pushed Huggies"
    elif pkt[ARP].hwsrc == '10:ae:60:00:4d:f3': # Elements
    print "Pushed Elements"
    else:
    print "ARP Probe from unknown device: " + pkt[ARP].hwsrc
    print sniff(prn=arp_display, filter="arp", store=0, count=10)
  • Finally modify your python script's code to do whatever you want. Below is the working demo video uploaded by Ted on Youtube.