RCE over ham radio – Reverse shell via WinAPRS memory corruption bug
coalfire.com
coalfire.com
Any particular source that you would recommend to start learning about these vectors?
Infrared Hacking: https://www.youtube.com/watch?v=61Fo-zg-DqI
Magstripe Hacking: https://www.youtube.com/watch?v=ITihB1c3dHw
Satellite Hacking: https://www.youtube.com/watch?v=PyXZX63etog
These all hit the sweet spot for me of technologies we use all the time but don't really consider the security implications.
By the way, did you catch yesterday's thread on the Hack-a-Sat(ellite) CTF?
>https://news.ycombinator.com/item?id=31559117
Also congratulations on passing the OSED. Reading your 5-part report it looks like you got your money's worth.
Did you study for the OSED full-time or did you manage to complete all studying and tasks after work?
Finding a bug in RDS would be pretty funny - https://en.wikipedia.org/wiki/Radio_Data_System
The local station had a UHF link from the studio to the TX site that was audio only, a very common setup in the mid-90s, and the RDS flag on the transmitter was switched "in band" by sending a burst of tones over the audio feed, right at the start of the traffic jingle. Slap the traffic announce jingle cart in, hit the button, tune starts with just three quick DTMF digits. Uh-huh, you're seeing where this is going, right?
So if you put those three DTMF digits at the start of your single... :-D
And public safety channels here are all encrypted so there's nothing to listen to, perhaps in the US that's not the case.
The vocal data on public safety channels being reported as encrypted does not necessarily say that there could be no vulnerability there. There's lots of control data that may or may not be encrypted, and encryption does not prevent all kinds of attacks here.
But nobody sells radio sets based on mbelib except the Chinese budget brands (e.g. baofeng) which have circumvented DVSI's patent by setting up a local company that sells the patent because they say they own it (even though they have no right to do it, but DVSI can't sue them in China). But all the public safety ones I've seen are brands like motorola and hytera that buy the real DVSI codecs.
But I'm not saying there are no other vulnerabilities. I'm just saying that there will not be many people using mbelib to listen to public safety frequencies because there is nothing to listen to as it's encrypted.
Possible I am missing something, but seems like at the very least they should add a warning to the download page found here:
The amateur radio community isn't enormous, and the overlap between operator and developer doesn't always exist.
That said some of the most popular ham software (like WSJT-X) are open source. I think the trend is starting to shift the other direction.
https://lwn.net/Articles/868309/ https://www.debian.org/blends/hamradio/
Private key disclosure seems catastrophic because of their scorched-earth security policy https://lotw.arrl.org/lotw-help/certificatesecurity/ where the server admins plan to invalidate all signed data, even if the same data had been sitting on the central server for years before the compromise happened. Yet, the docs don't recommend a password for the private key except on "shared or public computers." The adversary just looks for -----BEGIN PRIVATE KEY----- in a text file in a keys directory (the filename is the call letters).
In other words, although executing cmd.exe is a wonderful accomplishment, there's also the possibility of 1. wait for the PC and radio to be idle, 2. tune the radio to a clear frequency, 3. open the victim's private key file, 4. transmit the private key with Morse code.
I would like to echo your sentiment, that book was so good and has made me curious about the physical and digital world in so many different ways.
https://news.ycombinator.com/item?id=29387116
Here’s the wiki for those unfamiliar with it: