Bypassing Android MDM Using a $1.50 Electric Gas Lighter
payatu.com
payatu.com
I bypassed the payment procedure in a coke vending machine with a lighter.
Germany, around 2004 we had a coke vending machine at school, probably from the mid 90s. Someone told me you get free coke if you flick a (non-piezo) lighter in front of the display at the right time. I didn't believe it one bit, but when I tried it, it actually worked. It quickly spread around our school until months later the service guy fixed it.
Many years later I realized what has happened. The flick of the lighter emitted a strong IR impulse that triggered an infrared receiver (which was probably used for debugging, configuring etc).
This must have caused an interrupt, and if triggered at the same time the machine vended the bottle, it completed vending but never got back to actually decrementing the money you put into it. You could empty out the whole machine with nothing else but 1 Euro and a lighter and you even got your money back.
Lots of cokes were had.
And will provide a convenient excuse why I was unable to return that serve.
Look, it wasn't my fault, ok?
For my undergrad, we had a cross-major project to build a robot that shot pingpong balls at various targets that were tagged with IR lights. We used 2 wiimotes to calculate the 3D space.
What could go wrong!?
[1] https://payatu.com/static/images/remoteblogs/arun/emfi_blog/...
But... why?
If that's not the reason for trying to redact them, what is the reason? I can't think of anything else reasonable.
EDIT: I now realise that this was a very condescending comment to write to someone who, based on the submitted blog post, is considerably better at electronics than I am. Sorry about that!
[1] Yes, there are also 5.png, 6.png, and 8.png in between out of order, it is not a perfect pattern, but it is still close enough that one might notice the missing 4.png.
The attack relied on cosmic rays flipping bits of memory, but was accelerated by using a light bulb placed near the memory chips to induce heat based errors.
edit: found it! https://www.cs.princeton.edu/~appel/papers/memerr.pdf
I've often thought about these types of attacks, and wondered how advanced they've become.
Disclaimer: I'm extremely paranoid about computer security to the point where I almost don't care about it anymore and assume that any machine I use is compromised.
The big ones for gas stoves even work some feet away on some badly shielded products. Growing complexity, size/weight reduction and low power technology have made all these devices quite flimsy these days.
Can basically be a few pieces of carefully sized tinfoil, or some copper wire with copper clad soldered around it.
Also, the term "Jugaad" for Indian macgyverism is excellent!
Devices that implement any restrictions against the end user like DRM or MDM, on the other hand, are in possession of the said user. I heard a saying that getting root privileges on a device you physically possess is only a matter of time and effort.
In other words, you can totally take your phone apart as much as your tools and skills allow, but you'll get arrested if you try taking a slot machine apart.
The idea was not to take the machine apart but to try to glitch it by hitting metal parts that were not properly grounded. This would then allow the voltage spike to make it into the circuitry, either leading to breakage, no effect, or fault injection. The latter could sometimes be converted into a win on a subsequent spin.
This is 80's stuff, I'm pretty sure todays' slot machines are tamper proof to the point that trying this is totally pointless, and even back then hardening against this was common.
They are. Source: I own a modern-ish computer based slot machine and tried my fair share of tricks against it.
Given the absence of mechanical reels and the fact that the components likely to be susceptible to glitching aren’t remotely close to the outside of the machine this isn’t a viable attack method for machines in operation.
Source: NV Tech Standard 1 [1] also have zapped modern slot machines with an ESD gun.
[1]: https://gaming.nv.gov/modules/showdocument.aspx?documentid=2...
I remember swiping the piezo lighters out of the gas heaters at highschool, and using them to glitch free games in Asteroids and PacMan machines...
Disposable cameras had a little more umph though.
I ruined a screwdriver of my own that way once, discharging a photoflash cap in a flash head whose control circuit had died with the cap at full charge. Didn't do my hearing any good, either, I'm sure - it took fully half an hour for the ringing to go away.
Largely a disappeared skill.
I believe if you are really lucky if you discharge with a screwdriver, the cap can explode, not just melt the screwdriver. Same with batteries, like auto batteries, extra points there with boiling acid and hunks of thick plastic flying around.
Now I have to go look on youtube, to see if anyone's filmed themselves dropping a spanner across a Tesla's battery...
(I also had a friend wake up to about $500 worth of dead tropical fish, the morning after plugging a charger and car battery in on the shelf under his tank. Not entirely sure what the mechanism was, but the pH in the tank dropped enough to kill all the fish. )
It became a game between kids. The shock was more intense than harmful, although I saw two white dots on my nail that I assumed was due to the shock.
Today I rip microwave ovens, but I carry gloves and remove caps before anything else.
(The shocks I got were through carelessness; I used a kitchen knife to discharge the caps after ripping off the plastic shell of the camera, but sometimes I touched the wrong thing while disassembling. Roughly half the cameras I got had the caps charged to the point they'd spark brightly on discharge, and one of them damaged the knife.)
Context for those too young to remember: back before digital cameras were available and affordable, you could buy disposable cameras in kiosks and stores cheaply. These would come pre-loaded with a single roll of film, and after you used it up (~30 photos), you'd take the whole camera to a photo store. The photo store people would rip the roll out of the camera, develop your photos, and throw the camera away. Some models came with flash, so if you could get the used ones from the store (or their trash), you got a free source of high-voltage capacitors.)
I also discovered that accidentally holding a charged plate (thinking the supply was turned off) for a while could let you pick up tin foil just by holding your hand above it, which was pretty neat.
[1] IIRC we used a voltage divider to keep the maximum voltage around 500V, and the meters were rated for 1000VDC.
Sure you get a device that you can flash/root/reinstall - but will it be authenticated/allow login by Google/Your company?
> Here our objective was not to break the crypto or recover the data, it was to remove any MDM application and remove all restrictions on the device.
Yes you can remove - resell device. But MDM is not designed to prevent reinstall/selling/whatever.
Beyond Corp principles:
A particular network connection must not determine which services a user can access. Access to services is granted based on what we know about a user and the device. All access to services must be authenticated, authorized and encrypted.
Are you able to authorise device with your company/google? We are listening...