CSW2017 Mickey+maggie low cost radio attacks on modern platforms

23
Low cost radio wave attacks on modern platforms Mickey Shkatov Maggie Jauregui

Transcript of CSW2017 Mickey+maggie low cost radio attacks on modern platforms

Lowcostradiowaveattacksonmodernplatforms

MickeyShkatovMaggieJauregui

Intros

>MaggieJauregui@MagsJauregui>MickeyShkatov@HackingThings

Backstory–DC22

“Itworks,Idon’tknowwhy”

-Hackerseverywhere

EMIPreviouswork

>Mainlypassive...

>Sniffingcryptokeysacrosswallsorperformingside channelattacks

https://motherboard.vice.com/en_us/article/how-white-hat-hackers-stole-crypto-keys-from-an-offline-laptop-in-another-room

>FMSignalsandCellPhonesCanbeUsedtoSteal Data https://aabgu.org/fm-signals-cell-phones-can-used-steal-data/>LunchboxGlitchingforfun&noprofit https://depletionmode.com/2015/11/05/lunchbox-glitching-for-fun-non-profit/

Demos

i.PowerSurge

PowerSurge

>ASUSDIGI+VRMEPU>ASUSTPU

PowerSurge

>Tmpsensors[OSvsBIOS]>CPU>System

>Fanspeed>CPUcorevoltage

ii.Sensorcorruption/fanspeed

Incaseyoumissedit…

Sensorcorruption/fanspeed

Sensorcorruption/fanspeed

>Back-upvideo

Sensorcorruption

iii.Poweringmotherboardcomponents

Potentialimpact</punintended>

>RNG?>FireHazard>Memorycorruption>PDOS:FryCPU/components>Targetedglitchingattacks>Controlovercapacitanceinputsystems<wip>>RemoteattacksviaKVM>HWImplants

Mitigations

>FCallthethings!>Non-windowedchassis

>EMshielding.Don’tcheapouton...>Powersupplies>Motherboards-Voltageregulators

>Built-infaulttolerance

Backup…

iv.Bonusdemo:BSOD