7 comments

  • Retr0id4 hours ago
    Answers to some of the questions at the end, from future me:<p>- It also works on LPDDR5, LPDDR4<p>- Yes, it works on ARM platforms (at least, the ones I tried).<p>- The simplest way to trigger similar faults electronically is via a high-speed mux IC, as described in <a href="https:&#x2F;&#x2F;stefan-gloor.ch&#x2F;ddr5" rel="nofollow">https:&#x2F;&#x2F;stefan-gloor.ch&#x2F;ddr5</a> (chipshouter also works, but is less elegant imho!)<p>- Yes, you can get webkit addrof&#x2F;fakeobj primitives like this, although I didn&#x27;t write an end-to-end exploit.<p>- You can pwn nintendo switch kernel with an adjusted exploit strategy, but the same adjusted strategy does not work on Switch 2, due to memory encryption (one bitflip corrupts a whole cache line). But other strategies may be possible? (notably, it is possible to block a whole write operation from happening at all - see also <a href="https:&#x2F;&#x2F;rdist.root.org&#x2F;2010&#x2F;01&#x2F;27&#x2F;how-the-ps3-hypervisor-was-hacked&#x2F;" rel="nofollow">https:&#x2F;&#x2F;rdist.root.org&#x2F;2010&#x2F;01&#x2F;27&#x2F;how-the-ps3-hypervisor-was...</a> )
    • Retr0id3 hours ago
      I also spent a long time trying to do the glitching with a mosfet, but never got it to work. I couldn&#x27;t get enough drive strength to actually glitch anything, without messing with the delicate capacitance+impedance tolerances of the bus.
  • nom2 hours ago
    pfff, root, back in my day we hacked a vending machine with a lighter and got free coke.<p>No idea who discovered it, but the machine back at my school had an infrared interface for servicing, and you could trigger an interrupt with the flash of the flintstone of a lighter. Because it&#x27;s just some 90s microcontroller, it would simply reset after failing to receive a valid command and forget what it was doing previously.<p>All you had to do was order a coke, and right when it drops out, before it subtracts the amount, you flash the lighter in front of the IR port like a magician, say the magic words and bam - free coke!
  • b00ty4breakfast8 hours ago
    my prediction before reading is that they&#x27;re using the piezo sparker to beat the DUT over the head with a big EMF spike<p>Edit: Nailed it!
    • grufkork7 hours ago
      I thought they were going to just heat a chip to increase the overall error rate
      • throwawayqqq117 hours ago
        Be it eletric or thermal, i came here for fried hardware and left disappointed. Now i have to wrangle my curiosity to what happens when you lighter-spark a usb port for the rest of the day.
    • 4gotunameagain3 hours ago
      Yeah but the devil is in the details ;)<p>It&#x27;s not like you can randomly spike stuff and achieve an exploit
  • ted_dunning8 hours ago
    Uh... yeah.<p>Just hold the sysadmins hand over the lighter until they tell you the password.<p>Never forget the easy way in ... the humans.
    • quietbritishjim5 hours ago
      Like the classic xkcd on security<p><a href="https:&#x2F;&#x2F;xkcd.com&#x2F;538&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;538&#x2F;</a>
    • debugnik4 hours ago
      Good luck hacking a Switch using that method and getting away with it.
  • rkagerer8 hours ago
    &gt; Finally, I&#x27;d like to thank JEDEC for paywalling all of the specification documents that were relevant to conducting this research.
  • slj7 hours ago
    Yes. We do this in Australia, around the bars and pubs getting a root with only a cigarette lighter is a classic move.
    • RugnirViking2 hours ago
      I had an australian colleague who found it endlessly funny that we pronounced &quot;router&quot; as &quot;rooter&quot; instead of their &quot;rowter&quot;. statements like &quot;If that happens the system will root the packets via the rooter first&quot; was met with much giggling
    • karmakurtisaani7 hours ago
      I feel like getting root privileges means something else in Australia.
      • defrost7 hours ago
        Still only a third of the full wombat trifecta.
    • CTOSian6 hours ago
      also free arcade credits :}
  • haunter7 hours ago
    Yeah but can you light a cigarette with only a laptop? Checkmate atheists! &#x2F;s
    • mirekrusin7 hours ago
      If it&#x27;s intel, you can fry an egg for sure.
      • LoganDark5 hours ago
        The ol&#x27; Black MacBook Cooktop...
        • hi-im-buggy4 hours ago
          In combination with a weighing scale (<a href="https:&#x2F;&#x2F;github.com&#x2F;KrishKrosh&#x2F;TrackWeight" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;KrishKrosh&#x2F;TrackWeight</a>), you have everything you could ask for in a portable food processor.