What other device should we try and research? Subscribe for more #cybernews
@Data_Rogue2 ай бұрын
Not exactly a device but Building Access Control systems would be interesting
@Kanonenwind2 ай бұрын
I mean, based on this, you really should investigate what other devices with mediatek chips are vulnerable. I didn't have any faith in a scam product being safe, but if this vulnerability still works on current TVs or phones, I'd rather it be reported on.
@ismayonnaiseaninstrument87002 ай бұрын
@@KanonenwindDunno if or why YT deleted my reply, but yeah, a lot of Android-related companies use Mediatek chips, from OnePlus, Huawei, Xiaomi, and Oppo to Lenovo, through their Chromebooks, and Samsung Galaxy's A13 and A14. In particular, the A14 uses the MediaTek MT6769 Helio G80 chip, and it's been around since 2023. It's a real shame, 'cause I was considering switching over to Samsung, but clearly I can't if I gotta worry about crap like this...
@a.a.panchev172 ай бұрын
Fliper zero
@RPG_Guy-fx8ns2 ай бұрын
KZbin deleted my reply.
@jaybrooks10982 ай бұрын
A physical hack through a debug port is not exactly the greatest heck of all times
@akostadinov2 ай бұрын
Also why shou;dn't consumer have access to the debugging port?? Right to repair anybody? Why shouldn't I be able to use my own device for whatever I want?
@JamesR624Ай бұрын
Also love how they put out this video like as if it's new. Dude, EVERYONE already knows it's a cheapo android phone running an app. You didn't "hack" anything. You plugged a cable into what was essentially the cheapo phone's USB port, and transferred data.
@foxonboard1Ай бұрын
@jaybrooks: The exploit they used works over USB not de debug ports, they are secured good enough and are within the device @akostadinov: Because, if they are, any security can be bypassed by anyone, including bad actors. Would be comparable with running around with a phone without passcode… @JamesR624: They had to wait with going puplic after informin rabbit, else rabbit could have and would have sued them. It is normal USB connection, but you can gain root right like this and bypass any password/encryption of any user on the device and thus you are able to install hidden stuff. They mentioned, that they use a bug already found for those chip. So what they did, is discovering that thi exploit is working as well on rabbit HW.
@GraniteFaunАй бұрын
@@JamesR624 If the site'S name is something with cyber in its name it's gonna be some cringe
@SimoneCangini2 ай бұрын
Looking at a serial port with a multimeter is like taking time at the Olympics with a sundial
@AUATUWVSHАй бұрын
you need to check for the correct voltage level (1.8v, 3.3v, 5v) but also the TX pin will fluctuate if its trying to speak to the outside world, so its a fast way of checking if anything is trying to say anything over the UART port before hooking it up to the adaptor
@SimoneCanginiАй бұрын
@@AUATUWVSHThe fast way is called oscilloscope
@ronnyspanneveld81102 ай бұрын
So you did not "hack" anything and found "nothing" :P Guy hypes up but its just another script kiddo :P
@Emayeah2 ай бұрын
imagine having to rewrite the entire exploit if there is already one
@sims234ify2 ай бұрын
basically sums up the whole concept of this channel. uninformative and superficial clickbait videos
@Emayeah2 ай бұрын
@@sims234ify tho I have to agree the video was extremely diluted
@shambles92 ай бұрын
my thoughts exactly, what is this garbage channel?!
@michaelgleason47912 ай бұрын
Yeah and then hyped themselves up for another incredibly boring 10 minutes. At least I used 2x.
@djksfhakhaks2 ай бұрын
I find it hilarious that anyone took this guy seriously after his nft pump and dump.
@R1L1.2 ай бұрын
on god bro, the moment is saw that shit i went form 99.99 to 1000% sure this guy is complete fraude. At least this time a product came out lol, cant say the same for the nfc or whatever he sold.
@djksfhakhaks2 ай бұрын
@@R1L1. At that point. If you get pownd, that's your fault.
@djksfhakhaks2 ай бұрын
@JohnathanDHill so you think that due to your lack of research we should all suffer.
@dafoex2 ай бұрын
I'd take him seriously. A crime they might be, but a pump and dump has worked in the past, so he's not an idiot in that regard.
@dafoex2 ай бұрын
@@djksfhakhaks I feel you're putting words in his mouth there. >so you think that due to your lack of research we should all suffer. What do you expect he do with his lack of knowledge? Warn people that it's a scam based on no evidence?
@jsalsman2 ай бұрын
This content is interesting but the delivery style is way too over the top. You don't have to act like you're doing an informercial.
@laxis962 ай бұрын
Yeah, it's also oversensationalizing the whole situation... They opened an embedded device and found the TX/RX pins of a debug UART which literally 95% of all embedded devices have. Then they found a 5 years old MediaTek exploit that requires physical access, and went on to spread fear against MediaTek... yeah MediaTek is not the best SoC company but that's all this video accomplishes? These guys have no idea what hardware hacking is...
@ciklop42062 ай бұрын
It's content for the unwashed masses lol
@Emelin-cr8nc2 ай бұрын
I totaly agree with you! This video was all over the top
@DaggaRage24 күн бұрын
agree.
@Lucas-wp1ju2 ай бұрын
10:30 to only say that the chip has got a vulnerability. C'mon..
@xipi45952 ай бұрын
10min video for a one liner
@rethardotv58742 ай бұрын
Breaking News: A device is exploitable, given unlimited physical Access.
@4bSix86f612 ай бұрын
The rabbit R1 ain't nothing but the spotify car thing on steroids. Wait until the day they end support for it.
@leonidas147752 ай бұрын
And like the Ouya, its still going to be overpriced on the secondhand market for what it is because it was such an infamous flop.
@NeedaNewAlias2 ай бұрын
You did not hack anything. People are running Linux in that R1.
@_OS_2 ай бұрын
But this vulnerability can be used before any operating system loaded. I have this vulnerability on my phone. I use it to modify firmware, because it is only way how to modify firmware on my device without memory desoldering. With this exploit I have full access to memory, everything can be replaced in firmware. Connecting off device through usb enougth to use this exploit.
@lbochtlerАй бұрын
access to the debug port is something that everyone should have, as well as the tools to debug any and everything. The entire schematics should be public so that it can be repaired.
@bearwolffish2 ай бұрын
Some devices that might be fun to explore: AI Friend, Any meshtastic, Anything using TEE like STM32MP1 ProvenCore, Steamdeck, CanBus/ECU automotive display.
@Sprinkles-r5y2 ай бұрын
Seconding Steam deck! Or anything claiming open source that shouldn't.
@ozzelot33492 ай бұрын
The Deck is open by design. It's just a PC running a Linux distro with an immutable rootfs. Not much to explore.
@donpalmera2 ай бұрын
You didn't hack anything. You found a serial port that wasn't enabled, then tried someone else's exploit and found it still works.
@MrTweetyhack2 ай бұрын
and he made a video out of it to make money scam
@EXEC_A2 ай бұрын
Well, if I break into a house by picking a lock, a > 200 year old trick, can I argue that I never broke into the house because it's already been repeated before?
@Ne-vc5pm2 ай бұрын
@@EXEC_A your analogy is flawed, here is a better one: someone shows you what tools are needed and exact movements to pick a lock, you pick a lock and then decide to brag the whole village that you lockpicked it yourself
@BadMemoryAccess2 ай бұрын
@@Ne-vc5pm But... in your example, you DID lockpick it yourself. I'm guessing you wanted to make an analogy for a script kiddy, but it did not work. It would have been better like this: "someone gives you a tools that you can just put on a lock, and it picks it for you. You use it, and then decide to brag the whole village that you lockpicked it yourself"
@TilmanBaumann2 ай бұрын
Should have listened to you
@ardent30702 ай бұрын
Important thing to note: This doesn't tangibly affect the security of the device, only the end-user's ability to modify it. If a device software were modified by a third-party, this would require the bootloader to be unlocked, which would then launch an error message regarding such upon every single startup, alerting users to potential modification. If the device is AVB (Android Verified Boot) 2.0 compliant and supports avb_custom_key, it can be re-signed with another key (something I have only seen in Pixels and select OnePlus and Motorola devices), however it will still notify the user that it is loading a separate operating system. Any Android 10+ device is also mandated to be encrypted for Play Services certification, which may not apply to this device anyway, but this means if the bootloader were unlocked, it would dump the encryption key and force a factory reset, rendering the data effectively useless. It's about as much of a danger as Qualcomm's EDL mode.
@Jeff-ss6qtАй бұрын
This exploit shouldn't even be able to be used to read or modify user data either, since that's often encrypted by default. The most they'd be able to do is get an encrypted blob to put on an emulator or other device, they'd still need the pin, pattern, or password as the other part.
@ardent3070Ай бұрын
@@Jeff-ss6qt Yup, hence why it doesn't really matter too much. One could argue it makes the process easier though, but no software is gonna stop someone from pulling the nandflash if they really wanted to lol. This vuln is a huge win for the consumer tbh
@exapod232 ай бұрын
They choose Mediatek because is the only logical and commercially viable option for this kind of devices.
@AtroposLeshesis2 ай бұрын
So uhh, whats an example of the vulnerability besides the debugging port?
@DirtyPlumbus2 ай бұрын
It's entirely hackable.
@Jeff-ss6qtАй бұрын
If you watch the video, they're just saying what they went through and tried before finding the actual vulnerability. The vulnerability is the MediaTec chip, which allows you to modify the firmware or replace it entirely without any issue.
@R1L1.2 ай бұрын
Ah yes mediatek, the most disgusting chip company ever. These people will literally make actual human shit if they could sell it to you.
@leonidas147752 ай бұрын
Why? not every cheap tech product that needs a cpu needs a good cpu. If anything, their insecure chips are a blessing if you want to root a budget phone
@nijamkaj2 ай бұрын
@@leonidas14775 True
@MrTweetyhack2 ай бұрын
@@leonidas14775 keep buying insecure everything because it's cheaper
@sebiai61612 ай бұрын
Just gonna mention that the Nintendo Switch originally shipped with a vulnerable chip on board which ultimately lead to custom code being executable.
@amateurprogrammer25Ай бұрын
Oh no. Root access on a device I own. What a nightmare.
@mattilindstrom2 ай бұрын
Many tech companies will obfuscate what key components they use by e.g. laser etching the markings away. Good luck guessing the part number by a standard package format.
@danielvest96022 ай бұрын
Do some more like this - deep dives into exploits are my favorite, even the old ones.
@rootshell101Ай бұрын
lol what a glazer
@strukmichal22352 ай бұрын
For thos wondering what vulnerability it is, its BROM mode
@aleksandertrubin48692 ай бұрын
The chip doesn't seem to be a rebaged old chip, from what I found it is Helio P35, which was designed before 2019. Mediatek probably just didn't bother with updating the design. I don't really think there was a malicious intent, and the Rabbit company simply cheaped out. The chip is/recently was very common in low budget devices (below 80$ on many brands). I guess the moral of the story is not to buy devices with pre-2019 chips designed by mediatek
@EwanMarshall2 ай бұрын
It might be the G35 which is the 2020 rebadge release of the 2018 CPU... but yeah, it is not a 2023 chip by any means.
@zAlaska2 ай бұрын
I'm dealing with an exploit with my toothbrush. There's no place to put the batteries and it doesn't run, proving I've become a victim of North Korean espionage or something Snowden did.
@atxcomputerservices2 ай бұрын
why does alot of this look edited and fake?
@YarosMallorca2 ай бұрын
Amazing video!! Please make more videos like this, as a programmer and cybersecurity enthusiast, I really enjoy this style of content, keep it up!!
@cybernews2 ай бұрын
Thank you!
@matasstrazdas84672 ай бұрын
How nice it is for a Lithuanian to see that your employee is from Lithuania
@mephistovonfaust2 ай бұрын
The way I understood it it's the other way around. He is employed by CyberNews, that is a Lithuanian company. I could be wrong though. Just what I understood.
@JelloPuddingMasterАй бұрын
3:00 it connects to _chinese_ servers but its encrypted so thats "additional points for privacy"? you have to be joking
@DoctorBiobrain2 ай бұрын
The key to security on this device is that it’s really expensive and doesn’t do anything. That’s a feature, not a bug.
@kizi862 ай бұрын
i think the only reason they went with that specific chip, was it was dirt cheap, because of said vulnerabilities, and the creators of the R1 didnt do their research beforehand, OR if they did, and knew of the vuln, that is treading dangerously close to criminal behaviour, willingly using a bad chip, for a device like that..
@grande19002 ай бұрын
LLL covered pretty much the same vulnerability, but with more information about the actual vulnerability
@mikeantr9 күн бұрын
Most people don't realize that this is such a dangerous layered issue. It starts with hardware, but the entire stack needs to move away from being closed or "hidden". We need open source for everything, to be auditable, secure, and transparent. Automation is going to shock the system in the coming years.
@JigmeDatseАй бұрын
"This was discovered in 2019. Some of you were not even born then." How many 6 year olds do you think watch your videos? Like *really* watch them?
@toututu299320 күн бұрын
Including you yes
@JigmeDatse20 күн бұрын
@@toututu2993 Mi ne comprenas vin.
@nikos46772 ай бұрын
Nice my mum's phone is bricked and the boot loader is locked. I might try to use this exploit to finally fix it
@koto9x2 ай бұрын
most advanced ai newscaster i’ve seen from y’all yet ;)
@nofx714Ай бұрын
there goes 10:30 mins of my life i’ll never get back
@juandigАй бұрын
I could see Rabbit having cheaped out in their source for the CPU and having gotten an inofficial rebadged CPU which used old CPUs.
@null-nl5su2 ай бұрын
Looks like the "debugging port" is a UART. Note the RX and TX pins.
@jumpstartfpv2 ай бұрын
Good job bringing out the risk of buying a second hand Rabbit. But that applies to almost every device running these processors.
@Tiky.8192Ай бұрын
Omg!! we can read and write the firmware of a device we own, how craaZzzyyy. That just shows that there should be a foolproof way to do a factory reset on a device, not that we should lock down every piece of equipment...
@Centipede25772 ай бұрын
This device would be a practise tool for learning hacking. Or to practise modding devices.
@flickwtchr2 ай бұрын
Just the product design alone was a joke. Also, who would want to keep track of that and their smartphone. The day it came out my first thought was that I would be seeing them in thrift shops within a year.
@leonidas147752 ай бұрын
If they just made an AI app people could install on any phone, they'd have more success. I think the device was just investor bait.
@inv_djАй бұрын
Not the Monty Python Rabbit catching strays 😭😭🤣🤣🤣🤣
@pp3k072 ай бұрын
I'll even go as far as to say this channel is view farming. Too many views and likes, not enough comments.
@joemck85Ай бұрын
The obvious next step is to start connecting random phones, tablets, TVs, routers, smart speakers, robot vacuums, etc. to a laptop and run this exploit. If Mediatek is still selling vulnerable chips and Rabbit bought them, there's no way other random companies haven't also.
@j7ndominica05122 күн бұрын
If I own one of these, I'm more than a regular user, and should be allowed to access if fully without hacking it.
@ObservingBeauty2 ай бұрын
Fantastic video. Thanks
@flcamera2 ай бұрын
love to see more, thx for sharing
@xpower71252 ай бұрын
was **not** expecting this bro
@TrueBangers2 ай бұрын
YOOO POWER
@jimbosanderАй бұрын
Suggestion for research. Just bought the cheap TP-Link TAPO C220, and found that it requires internet AND inter-client (phone:app and camera) communication. A huge red-flag.
@djwikkid2 ай бұрын
Wow. This coupled with the fact that all your use is logged to the device, including past GPS history, and the fact that the rabbit hole uses VNC to have you enter your credentials to sites on computers you don't control instead of using oauth tokens client side is a huge liability for consumers. What were they thinking?!
@buhumon1232 ай бұрын
7:55 'where money?' wtf come on guys LOL
@artemi_sg2 ай бұрын
Hopefully, your researchers are not in Kaliningrad as the map suggests.😂
@DccToon2 ай бұрын
Summary: Mediatek chip in Rabbit r1 has a vunrability since 2019
@rubenyoungblood316716 күн бұрын
Props for the Monty Python reference.
@joeybruins2 ай бұрын
cant wair for the r1 to be used in ddos attakcs
@RaceCarLogic2 ай бұрын
good video, thanks!
@rubenrubnrbn2 ай бұрын
Happy for more of that!
@rettignickАй бұрын
I discovered all this in June. Along with everyone else in the Rabbitude discord.
@EliasFeverАй бұрын
This is a big, and I mean a BIG Security risk. If rabbit does not fix this bug soon. It would probably be discontinued. (Correct me if I am wrong.)
@keithgoh1232 ай бұрын
Never let someone else hookup a USB to your device lmao
@nathan222112 ай бұрын
so is it possible Rabbit bought the chips from anywhere but Meditak? The chip etching is scratched off pretty much. Also, I can't find anything on the Mediatek R1 that it showed up as. I would highly recommend going to Mediatek themselves and asking about the chip name it came up as. It's very possible that the chip isn't what Rabbit claimed it to be. My guess is that it's a custom chip and Rabbit went with the older architecture that MediaTek used with the vulnerability.
@madmax4042 ай бұрын
I was waiting for you to have a point. You didn't. This video is so pointless, of course if you have physical access to a device you can reprogram it and have access to it. That's why the mediatek "vulnerability" isn't considered really notable either. You trying to somehow gas yourself up as if this was some big revelation makes your whole channel look bad
@adityaray203Ай бұрын
I am curious about how secure are gaming consoles. That could be an interesting device to hack into
@timelordtardis32912 ай бұрын
Can someone tell me what is the stuff that we shouldn't be allowed to do on R1 that the debugging makes possible?
@sjoervanderploeg43402 ай бұрын
Never trusted a MediaTek chipset in my life :D
@barderino5673Ай бұрын
Its insane that we still give views to a company that is legit a scam ........
@Gildermesh2 ай бұрын
You couldn't find a lump of coal in a coal sack, but hey you can say you did if you were handed one.
@Twoshoes22Jason2 ай бұрын
Great video and awesome explanation on the larger issue
@tigerscott29662 ай бұрын
It's ORANGE! Orange for: FREEMASON! That says it all right there. 2 billion colors and they chose the big O.
@attribute-46772 ай бұрын
Did you expect anything less for a Chinese product?
@UltimatePerfection2 ай бұрын
6:16 They could use a CPU from a different manufacturer like Qualcomm.
@vidal97472 ай бұрын
I think a serious vulnerability is cause enough to break a contract. It should be law that you can do it if it is serious enough and not up for the contract to decide.
@leonidas147752 ай бұрын
They should make a tool available to flash the stock firmware. Mediatek already has one called SP flash tool, that they could distribute with instructions and the stock rom.
@brlin2 ай бұрын
Not gonna happen as you don't have the sale quantity to reduce the price of the chip from them.
@0xlol642 ай бұрын
yes please make more like this
@IlllIlllIlllIlll2 ай бұрын
Good thing I never purchased one
@ZaryanUrRehman2 ай бұрын
Alternative video title: a rabbit hole of cyber exploits
@frodev7282 ай бұрын
I didn’t realise Christian Bale was a tech head
@KomodoSoup2 ай бұрын
I have no idea why I feel so relieved and satisfied for watching this video 😂 Maybe because of the bit of exposing a vulnerability
@Zenless2602 ай бұрын
IS ANY1 REALLY USING THAT TRASH? LMAO
@jumpstartfpv2 ай бұрын
I'm sure this is a cliffhanger for all the people watching who were born after 2019.
@4N07H3R_12 ай бұрын
you make good explanations more than AI generated one
@doingtime202 ай бұрын
I don't need to open rabbit to know it's crap, all you need to know is the founder previously had a get rich quick scheme involving a videogame and nfts.
@greenhacker0com2 ай бұрын
"We" = your research team..
@meh11235Ай бұрын
Grace period allows the Zero day Market...
@ROLEXLOVER1232 ай бұрын
They could just remove the debug points.
@5speedfattyАй бұрын
ooh nice Leon reference
@j2klegendАй бұрын
2:48 And the amount of bot activity in comment section indicates that it is what the Rabbit is meant for.. and you should not buy it to serve CCP 😂 Message to the channel: Guys you explained everything in detail but, please be aware of bots when you are touching some countries!
@coldham7711 күн бұрын
I'm kinda shocked Rabbit is still in business. Horrible product.
@rselvarajanMBA2 ай бұрын
That's a good vulnerability for developers 😅 They can use Rabbit for various projects, instead of fiddling with microchips and trying to solder tiny cameras and mics. I guess R1 is the best development board out there!
@diynevalaАй бұрын
5:09 Gary Oldman in Leon
@cinchstik2 ай бұрын
you cracked the fortune cookie and found the following message" "Clarity is better than cleverness"
@Grid212 ай бұрын
You know what, 1. I don't care, and 2. So what? Most major "hacks" and "leaks" are not the end users fault, it's the corporate companies fault, and the end user is left holding the bag. Everything is hackable, Just accept that and move on.
@MCHarperYTАй бұрын
Can you please make a video a install Minecraft to it for the Rabbit r1
@zenmoto369Ай бұрын
It's alright no one even bought that physical android app :D
@kiriannapatrick724314 күн бұрын
That's all interesting and all but can Rabbit run Doom???
@Ym-oi2we2 ай бұрын
Working as intended
@vibertoo2 ай бұрын
what have to say Nothing brand?
@gamereditor59ner222 ай бұрын
Interesting...🤔
@Earth-To-Zan2 ай бұрын
FitMC is that you?
@rayzz133762 ай бұрын
This device is not worth any attention, why give it more coverage?