Fun With HARDWARE HACKING!!! - UART ROOT SHELLS and Finding SECRETS!

  Рет қаралды 27,633

Daniel Lowrie

Daniel Lowrie

Күн бұрын

Пікірлер: 125
@309electronics5
@309electronics5 6 ай бұрын
Just proves everything runs linux pretty much. Such a cool thing. I love it when i get to see the boot process of a device for myself instead of waiting silently for the device to come online. Also uboot has some great tools and you can even set env variables so it will boot into the shell by setting init=/bin/sh or init=/bin/bash
@daniellowrie
@daniellowrie 6 ай бұрын
Spot on! Being able to watch the boot process has helped me bring a few devices back to working condish
@needausernameJesus
@needausernameJesus 11 ай бұрын
that was really cool! hope you have more of these. Take it easy Daniel. Merry Christmas
@daniellowrie
@daniellowrie 11 ай бұрын
Glad you enjoyed the video! I should definitely do another hardware episode. Hardware hacking is a lot of fun!👍
@brendoncurran6151
@brendoncurran6151 Ай бұрын
Hi Daniel, I really enjoyed this video. I've been building and tinkering with Raspberry Pi and other SBC's and Microcontrollers etc. You presented this little hack in a way that anyone can understand. Keep up the good work. You have a new subscriber sir. 👍
@daniellowrie
@daniellowrie Ай бұрын
Hey Brendon, thank you so much for the kind words! I'm really glad to hear that you enjoyed the video and thanks for the sub 😀💯
@waynesrealworld5801
@waynesrealworld5801 2 жыл бұрын
I am so excited to watch the new series and really want to do some of this. Thank-you for inspireing me to try something new
@daniellowrie
@daniellowrie 2 жыл бұрын
I'm really glad I could inspire you to branch out, Wayne! Gotta keep reaching just beyond our grasp so that we continue to grow 👍
@viktorkunz189
@viktorkunz189 Ай бұрын
The most quick method to detect GND and VCC is to probe pins against capacitor pins of the given voltage. Often there is a fixed voltage regulator and gives directly the right pins.
@daniellowrie
@daniellowrie Ай бұрын
Thanks for the great info!
@rajnikvlogs6027
@rajnikvlogs6027 Жыл бұрын
I have iot hacking in my course curriculum and I'm really - really excited to deep dive into some hardware hacking and do something different from traditional web/api hacking 🎉❤
@daniellowrie
@daniellowrie Жыл бұрын
I hope your ready to find a new level of passion for hacking, because hardware hacking is so much fun and fairly addictive!
@dabunnisher29
@dabunnisher29 5 ай бұрын
That was VERY useful. Thank you.
@daniellowrie
@daniellowrie 5 ай бұрын
You're very welcome! So glad to hear that this was helpful to you😀👍
@johnkatz5820
@johnkatz5820 2 жыл бұрын
Found your Channel on YT, video is great. You have cool ideas, thanks a lot. Great Job :-)
@daniellowrie
@daniellowrie 2 жыл бұрын
Thanks for watching, John and I'm glad you enjoyed it 😀👍
@TheElectronicDilettante
@TheElectronicDilettante 6 ай бұрын
Great video. You need an oscilloscope so you can have a visual representation of the voltage variations. They will be highs and lows; 1’s and 0’s. Have fun
@daniellowrie
@daniellowrie 6 ай бұрын
Funny you say that! I was just looking at oscilloscopes the other day because I want to do more with hardware and it seemed like a good tool to have in the kit. Thanks for the suggestion!
@brianbauer6361
@brianbauer6361 2 жыл бұрын
Woohoo hardware hacking… my absolute fav iT topic. Thanks Dan
@daniellowrie
@daniellowrie 2 жыл бұрын
I'm really diggin' your enthusiasm, Brian! 😀
@BlakeDynamoPelling
@BlakeDynamoPelling 11 ай бұрын
Dynanomite ma man exactly what i wanted to see to push this mush along
@daniellowrie
@daniellowrie 11 ай бұрын
Thanks! Glad you enjoyed the video. Hardware hacking is super fun 👍
@vasishtrahul18
@vasishtrahul18 2 жыл бұрын
Really solid stuff! I am pretty sure you are gonna show it in the IoT Pentesting series as well.
@daniellowrie
@daniellowrie 2 жыл бұрын
Thanks, Rahul! You will definitely see this and a whole lot more 😉👍
@thebubblydreamz
@thebubblydreamz 2 жыл бұрын
And he is back lol. How are you Daniel? Its been a while
@daniellowrie
@daniellowrie 2 жыл бұрын
I'm good, Jake! Thanks for asking and it's good to be back. 😀👍
@sertralina100mg
@sertralina100mg 4 ай бұрын
10:47 I've done this. Connected VCC to 5V on my adapter and heard a literally frying sound. Fortunately my brand new Waveshare USB to TTL had some kind of protection and both my board and adapter still works lol.
@daniellowrie
@daniellowrie 4 ай бұрын
Thank goodness you didn't fry something! Letting out the magic smoke is definitely a hazard of the job 😆
@metalman5798
@metalman5798 11 ай бұрын
Appreciate you helping us with this topic
@daniellowrie
@daniellowrie 11 ай бұрын
No problem! I'm glad to do it 👍
@blackcats4980
@blackcats4980 4 ай бұрын
Thanks for your perfect video. I've got a question: What about if we don't get root shell access at first place ?
@daniellowrie
@daniellowrie 4 ай бұрын
Great question! If you don't get a root shell, then I would suggest dumping the firmware and then looking for useful secrets, or you could modify the firmware in a way that would allow remote access and then upload that modified firmware to the device. Just a few suggestions off the top of my head and I hope they help 👍 Cheers!
@wanderingmoon9772
@wanderingmoon9772 5 ай бұрын
You made this look so d@mn easy. This was some information I have been looking for. I'm glad I stumbled across this video and look forward to learning more.
@daniellowrie
@daniellowrie 4 ай бұрын
I'm glad you stumbled across this video too! Thanks for watching and I'm glad you enjoyed the content. 😀
@x0rZ15t
@x0rZ15t Жыл бұрын
Extra like for Arnie voice impression!
@daniellowrie
@daniellowrie Жыл бұрын
I like your extra like and raise you 2 likes 😁
@Mehpew
@Mehpew 6 ай бұрын
⌨️⌨️ That was pretty cool Daniel
@daniellowrie
@daniellowrie 6 ай бұрын
Thanks, Mehpew! It was a ton of fun to learn all that and doing the demo. I want to do more with hardware/IoT/embedded in the future 👍💯
@dnkdg
@dnkdg 10 ай бұрын
thank you Daniel for this video, easy and straight forward, good content :)
@daniellowrie
@daniellowrie 10 ай бұрын
Thanks for watching! So glad you enjoyed the content 😃
@laurendeal3336
@laurendeal3336 2 жыл бұрын
This is great!!! You are a wealth of knowledge
@daniellowrie
@daniellowrie 2 жыл бұрын
You're great, Lauren! Thanks for the sub! 😃
@karlkoch5417
@karlkoch5417 Жыл бұрын
Thanks for this video, helped a lot. I have to stay at home for some time, so I grabed an old modem from the early 2010 and found out, that there is a password for UART. Is there a good forum you can recommend for questions about this topic?
@daniellowrie
@daniellowrie Жыл бұрын
Glad to hear you enjoyed the video, Karl! I don't know of any forums off the top of my head, but you may be able to grab the password hash from the firmware using binwalk or firmware modkit and see if you can crack it with something like hashcat.
@Dumbc0mment
@Dumbc0mment 2 жыл бұрын
Thanks for sharing your knowledge. 🙂🖐💥🖐
@daniellowrie
@daniellowrie 2 жыл бұрын
You're welcome, zer0 and thanks for watching!
@jacermu
@jacermu 3 ай бұрын
Can you share the model and maker of your UART to TTL adapter?, thank you.
@daniellowrie
@daniellowrie 3 ай бұрын
Sure thing! It's a DSD TECH SH-U09C5. Here's the Amazon link... www.amazon.com/DSD-TECH-SH-U09C5-Converter-Support/dp/B07WX2DSVB/ref=sr_1_4?crid=3VF1J1LQ61KP6&dib=eyJ2IjoiMSJ9.HxWzQmv0Xp_HK4a0l7Ql6PjstSh63QL-LDf7MULYDWulVtFEbgBu2oSHl_VItSoOjLGk6mfYiTJYqr50CsmaWjlDefnhuKBL_TEXkuPdleq5MP0zaokcUgbdyQuxB6McLPYBpjPnzgj8IqdETsT-uA63f4e46d2D7nz4o4idDvc63HVrIhjgcxWLoaQQlBg9qGpY939ZInBO7w6Dy3lw_AiV_VAYvb56YjTTb7tHkwI.aBg1o3KygLGZoAV-QhcOtSenEUkVwRKs1XhlbfHBMeE&dib_tag=se&keywords=uart+to+usb&qid=1724090207&sprefix=uart+to+usb%2Caps%2C155&sr=8-4
@davegalaga1101
@davegalaga1101 2 жыл бұрын
This video is good for the economy!
@daniellowrie
@daniellowrie 2 жыл бұрын
Thanks Dave! I'm just trying to do my part 😁👍
@picklerick6759
@picklerick6759 3 ай бұрын
Channel your inner Schwartzenager😅 lol rx and tx, Cisco world would be a cross over cable 😊
@daniellowrie
@daniellowrie 3 ай бұрын
It has been a WHILE since I've touched a cross-over cable! Nice 😁 Now GOOOOO! RUUUUNNNN! GET TO DA CHOPPA!
@Tech_kenya
@Tech_kenya 2 жыл бұрын
Great content. I always like what you bring to us
@daniellowrie
@daniellowrie 2 жыл бұрын
Thanks, Anthony! I'm glad to hear you enjoy the content 👍
@michi.m
@michi.m Жыл бұрын
Awesome stuff
@daniellowrie
@daniellowrie Жыл бұрын
Thanks, Michi! Glad you liked it 😃👍
@thors3c
@thors3c 2 жыл бұрын
Awesome Content sir
@daniellowrie
@daniellowrie 2 жыл бұрын
Thank you very much for the compliment, Mohd. I'm glad you enjoyed it and thanks for watching 👍
@jonasisaksson3885
@jonasisaksson3885 11 ай бұрын
Sorry for n00b question but when I plug it in to my computer I don’t get COM5, it just says ”serial port”. Did I mess something up?
@daniellowrie
@daniellowrie 10 ай бұрын
I assume you're using Windows as your OS, but if you're not getting assigned a COM port then there might be a driver issue. Verify that your device is being recognized by your system by checking under "Universal Serial Bus controllers" > "USB Serial Converter". You may just need to reinstall the driver for it. You might even try plugging into a different USB port. If none of that works then it may just be a bad device that you're plugging in and you'll need to exchange it for another. I hope that helps 👍
@PhilieBlunt666
@PhilieBlunt666 2 жыл бұрын
We got arnie, I think I see hanz, I can be franz. And we are here to pump👏 you up!
@daniellowrie
@daniellowrie 2 жыл бұрын
Love the reference! LOL. Here's a clip of what I consider to be Arnie's best work. kzbin.info/www/bejne/g6G0f2Z-ga2lgKM Enjoy and thanks for commenting 😁
@PhilieBlunt666
@PhilieBlunt666 2 жыл бұрын
@@daniellowrie he definitely sells the character in that scene
@PhilieBlunt666
@PhilieBlunt666 2 жыл бұрын
@@daniellowrie love the video btw, I'm waiting for my uart connector now. So I got a long rabbit hole ahead of me
@daniellowrie
@daniellowrie 2 жыл бұрын
@@PhilieBlunt666 honestly I'm surprised he didn't win an Oscar for this performance. Shame on the Academy for this oversight. Shame, I say!
@daniellowrie
@daniellowrie 2 жыл бұрын
@@PhilieBlunt666 thanks, and I'm glad to hear it. There is something very satisfying about hardware and firmware hacking to me, so I for one really enjoyed the rabiit hole 😁👍
@johnkatz5820
@johnkatz5820 2 жыл бұрын
Is it possible to found UART Ports inside Smart Phones, like iphone?
@daniellowrie
@daniellowrie 2 жыл бұрын
Good news. It is possible. You should check out Joe Grand's KZbin channel and watch him crack into smartphones and other hardware. He has excellent content! kzbin.info
@lukeschmidt7872
@lukeschmidt7872 Жыл бұрын
Hey friend great videos. I'm trying something similar at home. I've identified the Ground port, and Im pretty sure VCC (it's steady 3.30, 3.29) but the other two ports are both reading 0 volts throughout the whole boot process. Any idea what is happening? I know you mentioned one could possibly read 0.00V being the Rx port, but im confused why both :(
@daniellowrie
@daniellowrie Жыл бұрын
This is such a great question, and honestly I'm surprised at myself for not addressing it in the video! My guess would be that the UART RX and/or TX ports are not connected. I've seen manufacturers do that before and when that happens you have to expose the lead wire and jump the pin to the wire. I hope that helps. Cheers!
@lukeschmidt7872
@lukeschmidt7872 Жыл бұрын
@Daniel Lowrie Heya thanks for the reply yep that's exactly right. I put it under a scope and I can see the traces have been disconnected. I'm trying to bridge them (theres two pins that can reconnect the traces) with solder but boy is it ever small.. the thinnest solder I have is still too big for it! It's like doing a surgery.
@daniellowrie
@daniellowrie Жыл бұрын
@@lukeschmidt7872 Oh yeah, those traces are soooo stinkin' small! At least you know what the issue is and can attempt to work around it. Even if you're unsuccessful, at least you've gained so much useful experience.
@CoderMaker
@CoderMaker Жыл бұрын
tx pin will have oscillations when you turn on the device. So check voltage oscillation in tx and rx pins while powering on.
@klmmkl9397
@klmmkl9397 Жыл бұрын
Hallo, can you pleas make video about how to scan another network that security cameras connected to and how to break them or hack them for learning purpose 🙏thank you
@daniellowrie
@daniellowrie Жыл бұрын
That's not a bad idea. I just need to get my hands on a security camera.👍
@firosiam7786
@firosiam7786 2 жыл бұрын
Wow look who decided to pop up 😂. Man u just post some great content and be like gone for months . Anyways good to see some great hardware hacking
@daniellowrie
@daniellowrie 2 жыл бұрын
I'm like a hacking phantasm! 😝 I sure do appreciate your viewership, firos and I'm glad you feel it's worth the wait 😁👍
@firosiam7786
@firosiam7786 2 жыл бұрын
@@daniellowrie ya I thnk its also the wait that does it . I see ur vedios and the phrase "quality over quantity" comes to my mind
@daniellowrie
@daniellowrie 2 жыл бұрын
Thanks, @@firosiam7786 , that's the highest praise I could hope to get 🙂
@severedconnections4821
@severedconnections4821 Жыл бұрын
Cool
@daniellowrie
@daniellowrie Жыл бұрын
Thanks! I find hardware/IoT hacking is a VERY interesting and fun as well
@St3amPunk
@St3amPunk 6 ай бұрын
what is the name of the usb device?
@daniellowrie
@daniellowrie 6 ай бұрын
That device is called uart-to-usb. Hope that helps
@hackwithprogramming7849
@hackwithprogramming7849 2 жыл бұрын
i loved it make similar videos
@daniellowrie
@daniellowrie 2 жыл бұрын
I love that you loved it! 😁
@adriansony9762
@adriansony9762 Жыл бұрын
Hey Daniel can u give links of the stuff where to buy these pls
@daniellowrie
@daniellowrie Жыл бұрын
www.amazon.com/EDGELEC-Breadboard-Optional-Assorted-Multicolored/dp/B07GD2BWPY/ref=mp_s_a_1_3?crid=JR9MZIJISAG2&keywords=Pin+wires&qid=1671558358&sprefix=pin+wires%2Caps%2C126&sr=8-3 www.amazon.com/DSD-TECH-SH-U09C5-Converter-Support/dp/B07WX2DSVB/ref=mp_s_a_1_3?crid=2Q32JOBJJ29Y4&keywords=uart+to+usb&qid=1671558459&sprefix=Uart%2Caps%2C120&sr=8-3
@speedeespeedboi9527
@speedeespeedboi9527 6 ай бұрын
mine is looking for password after starting putty. i have a archer mr200 router. what should i enter?
@daniellowrie
@daniellowrie 6 ай бұрын
I would try all the common passwords and even no password at all. If that doesn't work then you can try extracting the shadow file from the firmware and brute-forcing it with hashcat or using an online password cracker like crackstation.net. You might be able to grab a copy of the firmware from the device's support page. Then try extracting with binwalk. I hope that helps and best of luck!
@speedeespeedboi9527
@speedeespeedboi9527 6 ай бұрын
@@daniellowrie i have it opened with binwalk but the shadow file is not in it
@citronster
@citronster 2 жыл бұрын
Love to watch, but sound is not in sync with the video, not working with my ocd :( ... still listen with no video, only sound and it's perfect
@daniellowrie
@daniellowrie 2 жыл бұрын
Sorry about that, Jim. I've been working on getting the sound to sync up better, but it's been an odd issue. I'll keep at it though and thanks for watc...listening 😁👍
@Vampirat3
@Vampirat3 Жыл бұрын
Thank you , great video , Totally going to try!
@daniellowrie
@daniellowrie Жыл бұрын
So glad to hear that you enjoyed the video! 😀👍
@MalongaModeste
@MalongaModeste Жыл бұрын
What the name of that strange USB Daniel?
@daniellowrie
@daniellowrie Жыл бұрын
TTL-to-USB 👍
@MalongaModeste
@MalongaModeste Жыл бұрын
@@daniellowrie thanks so much, really enjoying your videos, gonna recommend them
@daniellowrie
@daniellowrie Жыл бұрын
​@@MalongaModeste I really appreciate the support, thanks!
@tombutsik7389
@tombutsik7389 Жыл бұрын
Thanks
@daniellowrie
@daniellowrie Жыл бұрын
Happy to oblige 👍
@tolkienfan1972
@tolkienfan1972 5 ай бұрын
Cool stuff. My son might be interested in trying this with me: he's been studying cybersecurity.
@daniellowrie
@daniellowrie 4 ай бұрын
Thanks for watching! Glad you enjoyed the content and I hope you and your son have a lot of fun connecting to UARTs 😀
@PlayerScave
@PlayerScave 8 ай бұрын
Is it possible to use Arduino as a usb to serial converter
@daniellowrie
@daniellowrie 8 ай бұрын
I'm not sure, but my guess would be "Yes" especially since they used to make this docs.arduino.cc/retired/boards/arduino-usb-2-serial-micro/. Edit: I just read through the info for the retired arduino usb-2-serial micro and it says that it has the same chip as the Arduino Uno. "It features an Atmega16U2 programmed as a USB-to-serial converter, the same chip found on the Arduino Uno." This makes me more confident that you could use an Arduino Uno as a usb to serial converter.
@309electronics5
@309electronics5 6 ай бұрын
​@@daniellowriebe warned, some arduinos use 5volt and can absolutely break your target if its 3.3volt. some serial ports cant tolerate 5volt for long. I learned it the hard way and lost my test router
@daniellowrie
@daniellowrie 6 ай бұрын
@@309electronics5 Great advice! Thanks for the heads-up 👍
@NoName_silent
@NoName_silent Жыл бұрын
How to dump firmware
@daniellowrie
@daniellowrie Жыл бұрын
Thanks for the suggestion, No Name 👍
@napalm1101
@napalm1101 2 жыл бұрын
Bruh, is that a Harbor Freight multimeter? 😅
@daniellowrie
@daniellowrie 2 жыл бұрын
I got it at Auto Zone thank you 😂😁
@mauricio1179
@mauricio1179 8 ай бұрын
Is this a copy of youtube.com/@mattbrwn?si=ZMHd7XM5hPeFCqUq Matt Brown video?
@daniellowrie
@daniellowrie 8 ай бұрын
Hey Mauricio, Great question! 🤔 I don't know that "copy" would best describe the situation as it may lead someone to think that something negative or nefarious is happening. I think "similar" would be a better descriptor. We are exploring the same topic, so you've got to expect that we're going to cover some, if not all of the same materials (concepts, tools, techniques, procedures). I would say that this video is only a "copy" of Matt's video insofar as Matt's video is a "copy" of... Tony Gambacorta's video ( kzbin.info/www/bejne/kJ69pn53YremqpIsi=JBBk2jAO9b78CnFW ) Valerio Di Giampietro's video ( kzbin.info/www/bejne/bJC0Z2lpjtCsjqcsi=CxMHJV1OnCWmpXdu ) The Flashback Team's video ( kzbin.info/www/bejne/ZmLQqGOlia2qrsksi=fL0fHQqyKQPu4qJ8 ) ...all of which helped me greatly when learning about this topic. So, like I said, not a copy but definitely similar. That said, I'd not seen Matt's channel before, so a big thanks to you for bringing his content to my attention as it's a really great channel with content! Everyone that watches this video should absolutely jump over to Matt's channel ( www.youtube.com/@mattbrwn ) and subscribe. 👍 I would also recommend Joe Grand's channel ( www.youtube.com/@JoeGrand ) if you're looking for some amazing hardware hacking content. 😃
@KingErasmos
@KingErasmos 4 ай бұрын
Hardly hardware “hacking”. All you did was connect to the UART on a device that stupidly drops to the root shell without any authentication.
@daniellowrie
@daniellowrie 4 ай бұрын
Hey KingErasmos, I'm so sorry to hear that you didn't enjoy my content. The intended audience I was aiming for was for those new to concepts and practices such as connecting to UARTs on devices that, as you say, "stupidly drops to the root shell without any authentication", looking for sensitive information, and possibly discovering weaknesses that could allow for exploitation. I was under the impression that this was something that falls under the rubric of "hardware hacking" as I learned how to do it from books and sites that described this process as an essential "hardware hacking" skill to master. If I'm mistaken in that understanding, then many thanks for the correction. When I made this video, I was new to this type of cybersecurity and was just excited to share what I'd learned with others new to it as well. I'm sure you're already aware of great hardware hacking channels like Joe Grand, The Flashback Team, and Matt Brown, but just in case you haven't here are the links to their channels. I hope they are more aligned with the type of content you're looking for. - Joe Grand kzbin.info - The Flashback Team www.youtube.com/@FlashbackTeam - Matt Brown www.youtube.com/@mattbrwn All the best, Daniel
@nikscha
@nikscha 11 ай бұрын
This video could have been 5 minutes long lol
@daniellowrie
@daniellowrie 10 ай бұрын
I do have a tendency to be loquacious, for sure! But hey, that's who God made me and I totally understand if my content isn't your "cup of tea". If you're looking for cyber security channels that focus on hardware, might I suggest... Joe Grand - www.youtube.com/@JoeGrand Make Me Hack - www.youtube.com/@MakeMeHack Flashback Team - www.youtube.com/@FlashbackTeam They all have great content and you won't have to listen to me drone on and on. 😅 Cheers!
@Huppat
@Huppat 6 ай бұрын
blablabla and the you got 2 receive pins, nice. u svck
@daniellowrie
@daniellowrie 6 ай бұрын
Oh man, I can be a bit verbose for sure 😅 I'm sorry to hear that it bothered you so much. I totally get that my content isn't for everyone, but maybe you'd enjoy Matt Brown or Joe Grand. They are both very skilled at hardware and great presenters too. Cheers 😀👍
Hardware Hacking - UART Shell with FlipperZero & Buspirate !
23:08
AlrikRr - Ethical Hacking
Рет қаралды 1,7 М.
Chip Off Firmware Extraction - Hacking the Totolink WiFi Router
31:15
FOREVER BUNNY
00:14
Natan por Aí
Рет қаралды 22 МЛН
This Game Is Wild...
00:19
MrBeast
Рет қаралды 133 МЛН
Is T-POT The ULTIMATE HONEYPOT Platform?
19:58
Daniel Lowrie
Рет қаралды 3,5 М.
Real Hardware Hacking for S$30 or Less - Presented by Joe FitzPatrick
45:01
Infosec In the City
Рет қаралды 18 М.
Accessing U-Boot through UART KS0 ultra
7:49
Crypto440
Рет қаралды 3,1 М.
I Created a Custom Exploit for a CRITICAL VULN in GeoServer
27:09
DNS Remote Code Execution: Finding the Vulnerability 👾 (Part 1)
29:31
CyberCast IRL - 11/22/2024 - Ep.4
1:00:02
Daniel Lowrie
Рет қаралды 188
#02 - How To Find The UART Interface - Hardware Hacking Tutorial
23:47
DEF CON 24 - Hardware Hacking Village - Matt DuHarte - Basic Firmware Extraction
45:50
DEF CON Hardware Hacking Village
Рет қаралды 99 М.
Hacking an AT&T 4G Router For Fun and User Freedom
34:38
Matt Brown
Рет қаралды 578 М.