Flole

321 posts

Flole

Flole

@flole998

Katılım Ağustos 2014
69 Takip Edilen14 Takipçiler
Flole
Flole@flole998·
@WaLeedALzamil @0xB4x Unfortunately I can't DM you. Yes the 1765 uses the same mechanism, I've dumped and verified that. Others failed on the 1765 aswell, also glitching a loop. Brownout on this CPU just seems to be too good. Disabling it makes a glitch work, but in the bootloader it's always active
English
0
0
0
871
Waleed
Waleed@WaLeedALzamil·
@flole998 @0xB4x We tried it with 3 different types of LPCs and worked but we didn’t tried it on the 1765. Here is some tips: -Have you dumped the BootROM and found the same CRP mechanism? -Have you tried glitching a infinite loop with variables? For more help please DM us.
English
1
0
0
47
Waleed
Waleed@WaLeedALzamil·
Happy to share my first talk and @0xB4x ! It’s a continuous of @akacastor brilliant work. I would like to thank him for sharing. Also a special thank you to these guys who we mentioned in the talk @jcldf @ghidraninja @joegrand @colinoflynn and @walletfail group.
hardwear.io@hardwear_io

Attack on 📟NXP LPC family #microcontrollers 💡Waleed & Bandar presented their research on attacking NXP LPC family microcontrollers using voltage #faultinjection to enable the #debug interface 🍿Enjoy the talk ▶️youtu.be/RlV9t0gXTLI #hw_ioNL2022 #embedded #Conference #NXP

English
3
3
17
0
Flole
Flole@flole998·
@WaLeedALzamil @0xB4x Thanks for your response and the writeup. Unfortunately when I tried it on the LPC1765 it seems to be resistant to glitches for some reason. Have you tried your attack against that one aswell or only against a single cpu type?
English
1
0
0
672
Flole
Flole@flole998·
@khaxan I need your whatsapp aswell to ask you regex questions! 😉😂
English
1
0
0
8
Flole
Flole@flole998·
@Laughing_Mantis Sometimes you might think that you've done something wrong during your process and don't want to discourage others from doing the same thing as they might be successful.
English
0
0
1
39
Flole
Flole@flole998·
@travisgoodspeed @NXP Additionally I just tried to use multiple short glitches after each other, in that case I can do 8 glitches without a reset, but the CPU appears to operate normally, so no success either
English
0
0
0
17
Flole
Flole@flole998·
@travisgoodspeed @NXP I've used the chipwhisperer's "enable only" mode, so I've tried a single glitch with a varying length. At 30nS there's nothing, at 40nS there's a reset. Usually such protections should be mentioned in the datasheet though, after all they make the CPU more secure/"better".
English
1
0
0
40
Flole
Flole@flole998·
@travisgoodspeed @NXP Also apparently that CPU seems to be resistant against voltage fault injection attacks. I wasn't able to glitch a simple loop and also wasn't able to replicate the bootloader CRP glitches that exist on other LPC CPUs, I either see a reset or no effect at all.
English
1
0
0
73
Flole
Flole@flole998·
@travisgoodspeed @NXP Awesome! Thanks a lot! I'm especially curious why it has two VDD(Reg) inputs on opposite sides, they should power an internal voltage regulator.
English
1
0
0
28
Flole
Flole@flole998·
@pinguinii_ Oh wow, das sieht ja völlig anders aus
Deutsch
0
0
0
132
Flole
Flole@flole998·
@LisaForteUK Post the database credentials so they can take care of it themselves
English
0
0
0
2
Lisa Forte
Lisa Forte@LisaForteUK·
Your org has a breach. You have to reset 30k customer accounts. How do you do it? (Wrong answers only)
English
422
16
177
98.7K
Flole
Flole@flole998·
@khaxan PUT THERE, GET WHERE?, API will answer HERE 😂 Did I get that right?
English
1
0
0
13
Flole
Flole@flole998·
@pinguinii_ Heute bei mir genau dasselbe! 😂😂 Danke für die "Vorwarnung", sonst hätte ich das Ding wirklich abgeholt und die 85 Cent bezahlt 😂 Aber so....
Deutsch
0
0
0
34
Flole
Flole@flole998·
@khaxan I didn't even know there are other colors than green available until a few minutes ago
English
1
0
1
0
Flole
Flole@flole998·
@khaxan *tightens screws on VGA connector*..... Wait a second, those aren't green?
English
1
0
1
0
Flole retweetledi
Dadman Walking
Dadman Walking@dadmann_walking·
dog: [brings sticks inside] me: no that belongs outside me, at Christmas time: [brings entire tree inside] dog: what the actual shit is this
English
116
9.4K
104.5K
0
Flole
Flole@flole998·
@khaxan Oh, apparently I'm not the only one who experienced that today 😂
English
1
0
1
0
Flole retweetledi
Almor Tech
Almor Tech@AlmorTech·
When your code works, but you have no idea how
English
1.9K
38.3K
285.6K
0