Fun With HARDWARE HACKING!!! - UART ROOT SHELLS and Finding SECRETS!

  Рет қаралды 17,452

Daniel Lowrie

Daniel Lowrie

Күн бұрын

Recently I've been learning about IoT and hardware hacking, so I thought it would be fun to crack open a wifi router that was so generously donated to me and see if I could find a UART and connect to it. From there I hope to see if I could find any sensitive data and use that to gain access to the router through the admin web-portal. So hold on to your multi-meter and let's hack a router!!! :)
Chapters
=================
00:00 Intro
01:00 The Plan of Attack
01:55 The Gear
06:02 Identifying UART Pins with Multi-meter
16:33 Connecting UART to TTL-to-USB
20:00 Terminal Emulator Settings
22:08 We Have SHELL!!!
24:58 Finding Secrets
29:45 Closing Thoughts
#iot #iotsecurity #hardwarehacking #iothacking #uart #jtag #jtagulator #redteam #redteaming #arduino #raspberrypi #cybersecurity #hacker #hacking #informationsecurity #infosec #penetrationtester #pentesting #ethicalhacker #ethicalhacking

Пікірлер: 88
@waynesrealworld5801
@waynesrealworld5801 Жыл бұрын
I am so excited to watch the new series and really want to do some of this. Thank-you for inspireing me to try something new
@daniellowrie
@daniellowrie Жыл бұрын
I'm really glad I could inspire you to branch out, Wayne! Gotta keep reaching just beyond our grasp so that we continue to grow 👍
@needausernameJesus
@needausernameJesus 4 ай бұрын
that was really cool! hope you have more of these. Take it easy Daniel. Merry Christmas
@daniellowrie
@daniellowrie 4 ай бұрын
Glad you enjoyed the video! I should definitely do another hardware episode. Hardware hacking is a lot of fun!👍
@johnkatz5820
@johnkatz5820 Жыл бұрын
Found your Channel on YT, video is great. You have cool ideas, thanks a lot. Great Job :-)
@daniellowrie
@daniellowrie Жыл бұрын
Thanks for watching, John and I'm glad you enjoyed it 😀👍
@vasishtrahul18
@vasishtrahul18 Жыл бұрын
Really solid stuff! I am pretty sure you are gonna show it in the IoT Pentesting series as well.
@daniellowrie
@daniellowrie Жыл бұрын
Thanks, Rahul! You will definitely see this and a whole lot more 😉👍
@Tech_kenya
@Tech_kenya Жыл бұрын
Great content. I always like what you bring to us
@daniellowrie
@daniellowrie Жыл бұрын
Thanks, Anthony! I'm glad to hear you enjoy the content 👍
@metalman5798
@metalman5798 4 ай бұрын
Appreciate you helping us with this topic
@daniellowrie
@daniellowrie 4 ай бұрын
No problem! I'm glad to do it 👍
@dnkdg
@dnkdg 3 ай бұрын
thank you Daniel for this video, easy and straight forward, good content :)
@daniellowrie
@daniellowrie 3 ай бұрын
Thanks for watching! So glad you enjoyed the content 😃
@brianbauer6361
@brianbauer6361 Жыл бұрын
Woohoo hardware hacking… my absolute fav iT topic. Thanks Dan
@daniellowrie
@daniellowrie Жыл бұрын
I'm really diggin' your enthusiasm, Brian! 😀
@laurendeal3336
@laurendeal3336 Жыл бұрын
This is great!!! You are a wealth of knowledge
@daniellowrie
@daniellowrie Жыл бұрын
You're great, Lauren! Thanks for the sub! 😃
@rajnikvlogs6027
@rajnikvlogs6027 9 ай бұрын
I have iot hacking in my course curriculum and I'm really - really excited to deep dive into some hardware hacking and do something different from traditional web/api hacking 🎉❤
@daniellowrie
@daniellowrie 9 ай бұрын
I hope your ready to find a new level of passion for hacking, because hardware hacking is so much fun and fairly addictive!
@Dumbc0mment
@Dumbc0mment Жыл бұрын
Thanks for sharing your knowledge. 🙂🖐💥🖐
@daniellowrie
@daniellowrie Жыл бұрын
You're welcome, zer0 and thanks for watching!
@Vampirat3
@Vampirat3 10 ай бұрын
Thank you , great video , Totally going to try!
@daniellowrie
@daniellowrie 10 ай бұрын
So glad to hear that you enjoyed the video! 😀👍
@michi.m
@michi.m Жыл бұрын
Awesome stuff
@daniellowrie
@daniellowrie Жыл бұрын
Thanks, Michi! Glad you liked it 😃👍
@BlakeDynamoPelling
@BlakeDynamoPelling 4 ай бұрын
Dynanomite ma man exactly what i wanted to see to push this mush along
@daniellowrie
@daniellowrie 4 ай бұрын
Thanks! Glad you enjoyed the video. Hardware hacking is super fun 👍
@thors3c
@thors3c Жыл бұрын
Awesome Content sir
@daniellowrie
@daniellowrie Жыл бұрын
Thank you very much for the compliment, Mohd. I'm glad you enjoyed it and thanks for watching 👍
@karlkoch5417
@karlkoch5417 Жыл бұрын
Thanks for this video, helped a lot. I have to stay at home for some time, so I grabed an old modem from the early 2010 and found out, that there is a password for UART. Is there a good forum you can recommend for questions about this topic?
@daniellowrie
@daniellowrie Жыл бұрын
Glad to hear you enjoyed the video, Karl! I don't know of any forums off the top of my head, but you may be able to grab the password hash from the firmware using binwalk or firmware modkit and see if you can crack it with something like hashcat.
@lukeschmidt7872
@lukeschmidt7872 Жыл бұрын
Hey friend great videos. I'm trying something similar at home. I've identified the Ground port, and Im pretty sure VCC (it's steady 3.30, 3.29) but the other two ports are both reading 0 volts throughout the whole boot process. Any idea what is happening? I know you mentioned one could possibly read 0.00V being the Rx port, but im confused why both :(
@daniellowrie
@daniellowrie Жыл бұрын
This is such a great question, and honestly I'm surprised at myself for not addressing it in the video! My guess would be that the UART RX and/or TX ports are not connected. I've seen manufacturers do that before and when that happens you have to expose the lead wire and jump the pin to the wire. I hope that helps. Cheers!
@lukeschmidt7872
@lukeschmidt7872 Жыл бұрын
@Daniel Lowrie Heya thanks for the reply yep that's exactly right. I put it under a scope and I can see the traces have been disconnected. I'm trying to bridge them (theres two pins that can reconnect the traces) with solder but boy is it ever small.. the thinnest solder I have is still too big for it! It's like doing a surgery.
@daniellowrie
@daniellowrie Жыл бұрын
@@lukeschmidt7872 Oh yeah, those traces are soooo stinkin' small! At least you know what the issue is and can attempt to work around it. Even if you're unsuccessful, at least you've gained so much useful experience.
@CoderMaker
@CoderMaker 6 ай бұрын
tx pin will have oscillations when you turn on the device. So check voltage oscillation in tx and rx pins while powering on.
@x0rZ15t
@x0rZ15t Жыл бұрын
Extra like for Arnie voice impression!
@daniellowrie
@daniellowrie Жыл бұрын
I like your extra like and raise you 2 likes 😁
@ClickClack_Bam
@ClickClack_Bam 6 ай бұрын
Thank you for this.,, I'm super new to the whole electronics thing. In fact the Flipper Zero GPIO pins got me interested & then I came upon Arduino & GPIO & now I'm seeing hacking on this level. I'll bet you could sell this type of thing to people. Like ship them that hardware & have different things to try to accomplish. Things like: - don't tell them what to try to find & see what all they can find on their own. -then after they've tried to totally crack this thing, list the things & see if they've found everything & if not, go do those things -then whatever they couldn't do have a walkthrough video & explanation of the why & how to handle these things I think people would pay for this type of thing & as long as it's legit it'll be such a powerful tool.
@daniellowrie
@daniellowrie 6 ай бұрын
Sounds like you're proposing a Hardware Hacking Scavenger Hunt. A very cool idea! 😀
@ClickClack_Bam
@ClickClack_Bam 6 ай бұрын
@@daniellowrie Yes. That's it. I've seen some KZbin crime channels have started selling these "See if you can solve the crime" kits. I could see this being a thing like that. I don't know a lot about this (yet) but it seems like finding hardware is cheap & the kits could be either left as is or tinkered with to add to the lesson.
@thebubblydreamz
@thebubblydreamz Жыл бұрын
And he is back lol. How are you Daniel? Its been a while
@daniellowrie
@daniellowrie Жыл бұрын
I'm good, Jake! Thanks for asking and it's good to be back. 😀👍
@jonasisaksson3885
@jonasisaksson3885 4 ай бұрын
Sorry for n00b question but when I plug it in to my computer I don’t get COM5, it just says ”serial port”. Did I mess something up?
@daniellowrie
@daniellowrie 4 ай бұрын
I assume you're using Windows as your OS, but if you're not getting assigned a COM port then there might be a driver issue. Verify that your device is being recognized by your system by checking under "Universal Serial Bus controllers" > "USB Serial Converter". You may just need to reinstall the driver for it. You might even try plugging into a different USB port. If none of that works then it may just be a bad device that you're plugging in and you'll need to exchange it for another. I hope that helps 👍
@tombutsik7389
@tombutsik7389 5 ай бұрын
Thanks
@daniellowrie
@daniellowrie 5 ай бұрын
Happy to oblige 👍
@PhilieBlunt666
@PhilieBlunt666 Жыл бұрын
We got arnie, I think I see hanz, I can be franz. And we are here to pump👏 you up!
@daniellowrie
@daniellowrie Жыл бұрын
Love the reference! LOL. Here's a clip of what I consider to be Arnie's best work. kzbin.info/www/bejne/g6G0f2Z-ga2lgKM Enjoy and thanks for commenting 😁
@PhilieBlunt666
@PhilieBlunt666 Жыл бұрын
@@daniellowrie he definitely sells the character in that scene
@PhilieBlunt666
@PhilieBlunt666 Жыл бұрын
@@daniellowrie love the video btw, I'm waiting for my uart connector now. So I got a long rabbit hole ahead of me
@daniellowrie
@daniellowrie Жыл бұрын
@@PhilieBlunt666 honestly I'm surprised he didn't win an Oscar for this performance. Shame on the Academy for this oversight. Shame, I say!
@daniellowrie
@daniellowrie Жыл бұрын
@@PhilieBlunt666 thanks, and I'm glad to hear it. There is something very satisfying about hardware and firmware hacking to me, so I for one really enjoyed the rabiit hole 😁👍
@severedconnections4821
@severedconnections4821 11 ай бұрын
Cool
@daniellowrie
@daniellowrie 11 ай бұрын
Thanks! I find hardware/IoT hacking is a VERY interesting and fun as well
@davegalaga1101
@davegalaga1101 Жыл бұрын
This video is good for the economy!
@daniellowrie
@daniellowrie Жыл бұрын
Thanks Dave! I'm just trying to do my part 😁👍
@firosiam7786
@firosiam7786 Жыл бұрын
Wow look who decided to pop up 😂. Man u just post some great content and be like gone for months . Anyways good to see some great hardware hacking
@daniellowrie
@daniellowrie Жыл бұрын
I'm like a hacking phantasm! 😝 I sure do appreciate your viewership, firos and I'm glad you feel it's worth the wait 😁👍
@firosiam7786
@firosiam7786 Жыл бұрын
@@daniellowrie ya I thnk its also the wait that does it . I see ur vedios and the phrase "quality over quantity" comes to my mind
@daniellowrie
@daniellowrie Жыл бұрын
Thanks, @@firosiam7786 , that's the highest praise I could hope to get 🙂
@hackwithprogramming7849
@hackwithprogramming7849 Жыл бұрын
i loved it make similar videos
@daniellowrie
@daniellowrie Жыл бұрын
I love that you loved it! 😁
@johnkatz5820
@johnkatz5820 Жыл бұрын
Is it possible to found UART Ports inside Smart Phones, like iphone?
@daniellowrie
@daniellowrie Жыл бұрын
Good news. It is possible. You should check out Joe Grand's KZbin channel and watch him crack into smartphones and other hardware. He has excellent content! kzbin.info
@PlayerScave
@PlayerScave Ай бұрын
Is it possible to use Arduino as a usb to serial converter
@daniellowrie
@daniellowrie Ай бұрын
I'm not sure, but my guess would be "Yes" especially since they used to make this docs.arduino.cc/retired/boards/arduino-usb-2-serial-micro/. Edit: I just read through the info for the retired arduino usb-2-serial micro and it says that it has the same chip as the Arduino Uno. "It features an Atmega16U2 programmed as a USB-to-serial converter, the same chip found on the Arduino Uno." This makes me more confident that you could use an Arduino Uno as a usb to serial converter.
@klmmkl9397
@klmmkl9397 Жыл бұрын
Hallo, can you pleas make video about how to scan another network that security cameras connected to and how to break them or hack them for learning purpose 🙏thank you
@daniellowrie
@daniellowrie Жыл бұрын
That's not a bad idea. I just need to get my hands on a security camera.👍
@adriansony9762
@adriansony9762 Жыл бұрын
Hey Daniel can u give links of the stuff where to buy these pls
@daniellowrie
@daniellowrie Жыл бұрын
www.amazon.com/EDGELEC-Breadboard-Optional-Assorted-Multicolored/dp/B07GD2BWPY/ref=mp_s_a_1_3?crid=JR9MZIJISAG2&keywords=Pin+wires&qid=1671558358&sprefix=pin+wires%2Caps%2C126&sr=8-3 www.amazon.com/DSD-TECH-SH-U09C5-Converter-Support/dp/B07WX2DSVB/ref=mp_s_a_1_3?crid=2Q32JOBJJ29Y4&keywords=uart+to+usb&qid=1671558459&sprefix=Uart%2Caps%2C120&sr=8-3
@citronster
@citronster Жыл бұрын
Love to watch, but sound is not in sync with the video, not working with my ocd :( ... still listen with no video, only sound and it's perfect
@daniellowrie
@daniellowrie Жыл бұрын
Sorry about that, Jim. I've been working on getting the sound to sync up better, but it's been an odd issue. I'll keep at it though and thanks for watc...listening 😁👍
@MalongaModeste
@MalongaModeste Жыл бұрын
What the name of that strange USB Daniel?
@daniellowrie
@daniellowrie Жыл бұрын
TTL-to-USB 👍
@MalongaModeste
@MalongaModeste Жыл бұрын
@@daniellowrie thanks so much, really enjoying your videos, gonna recommend them
@daniellowrie
@daniellowrie Жыл бұрын
​@@MalongaModeste I really appreciate the support, thanks!
@NoName_silent
@NoName_silent 10 ай бұрын
How to dump firmware
@daniellowrie
@daniellowrie 10 ай бұрын
Thanks for the suggestion, No Name 👍
@napalm1101
@napalm1101 Жыл бұрын
Bruh, is that a Harbor Freight multimeter? 😅
@daniellowrie
@daniellowrie Жыл бұрын
I got it at Auto Zone thank you 😂😁
@mauricio1179
@mauricio1179 2 ай бұрын
Is this a copy of youtube.com/@mattbrwn?si=ZMHd7XM5hPeFCqUq Matt Brown video?
@daniellowrie
@daniellowrie 2 ай бұрын
Hey Mauricio, Great question! 🤔 I don't know that "copy" would best describe the situation as it may lead someone to think that something negative or nefarious is happening. I think "similar" would be a better descriptor. We are exploring the same topic, so you've got to expect that we're going to cover some, if not all of the same materials (concepts, tools, techniques, procedures). I would say that this video is only a "copy" of Matt's video insofar as Matt's video is a "copy" of... Tony Gambacorta's video ( kzbin.info/www/bejne/kJ69pn53YremqpIsi=JBBk2jAO9b78CnFW ) Valerio Di Giampietro's video ( kzbin.info/www/bejne/bJC0Z2lpjtCsjqcsi=CxMHJV1OnCWmpXdu ) The Flashback Team's video ( kzbin.info/www/bejne/ZmLQqGOlia2qrsksi=fL0fHQqyKQPu4qJ8 ) ...all of which helped me greatly when learning about this topic. So, like I said, not a copy but definitely similar. That said, I'd not seen Matt's channel before, so a big thanks to you for bringing his content to my attention as it's a really great channel with content! Everyone that watches this video should absolutely jump over to Matt's channel ( www.youtube.com/@mattbrwn ) and subscribe. 👍 I would also recommend Joe Grand's channel ( www.youtube.com/@JoeGrand ) if you're looking for some amazing hardware hacking content. 😃
@nikscha
@nikscha 4 ай бұрын
This video could have been 5 minutes long lol
@daniellowrie
@daniellowrie 4 ай бұрын
I do have a tendency to be loquacious, for sure! But hey, that's who God made me and I totally understand if my content isn't your "cup of tea". If you're looking for cyber security channels that focus on hardware, might I suggest... Joe Grand - www.youtube.com/@JoeGrand Make Me Hack - www.youtube.com/@MakeMeHack Flashback Team - www.youtube.com/@FlashbackTeam They all have great content and you won't have to listen to me drone on and on. 😅 Cheers!
Real Hardware Hacking for S$30 or Less - Presented by Joe FitzPatrick
45:01
Infosec In the City
Рет қаралды 14 М.
Finding UART and Getting a Root Shell on a Linux Router
20:11
Matt Brown
Рет қаралды 26 М.
Суд над Бишимбаевым. 24 апреля | ОНЛАЙН
7:26:50
АВДА КЕДАВРАААААА😂
00:11
Romanov BY
Рет қаралды 8 МЛН
skibidi toilet 73 (part 1)
04:46
DaFuq!?Boom!
Рет қаралды 34 МЛН
Philippe Laulheret - Intro to Hardware Hacking - DEF CON 27 Conference
46:07
Unlocking the Secrets of Firmware with QEMU and Binwalk
25:00
Ian Trimble
Рет қаралды 9 М.
Hacker's Guide to UART Root Shells
17:40
Flashback Team
Рет қаралды 449 М.
How We Hacked a TP-Link Router and Took Home $55,000 in Pwn2Own
17:44
Flashback Team
Рет қаралды 366 М.
Watch these hackers crack an ATM in seconds
5:42
CNET
Рет қаралды 6 МЛН
How I hacked a hardware crypto wallet and recovered $2 million
32:18
Samy Kamkar's Crash Course in How to Be a Hardware Hacker
28:07
EEVblog #977 - Keysight 1000X Hacking - Part 1
30:45
EEVblog
Рет қаралды 92 М.
Extracting Firmware from Embedded Devices (SPI NOR Flash) ⚡
18:41
Flashback Team
Рет қаралды 483 М.
Which Phone Unlock Code Will You Choose? 🤔️
0:12
Game9bit
Рет қаралды 6 МЛН
Секретная функция ютуба 😱🐍 #shorts
0:14
Владислав Шудейко
Рет қаралды 2,1 МЛН
Phone charger explosion
0:43
_vector_
Рет қаралды 32 МЛН
КУПИЛ SAMSUNG GALAXY S24 ULTRA ЗА 88000 РУБЛЕЙ!
27:29