Hacking Philips Hue Lights To Hack Whole Networks - ThreatWire

preview_player
Показать описание
Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005:
____________________________________________
Four hackers have been charged for the equifax data breach, Philips Hues could be used to hack your network, and changing screen brightness to steal data! All that coming up now on ThreatWire. #threatwire #hak5

Links:

USE CODE MOVING2020 FOR 25% OFF ALL ORDERS! VALID 2-11-20 THROUGH 3-4-2020

Links:

Photo credit:

-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆

-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
____________________________________________
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Рекомендации по теме
Комментарии
Автор

When you're providing information like version numbers, etc, PLEASE display them on the screen. It's easier for people to pause and copy/verify once than to have to rewind a couple times as they listen and copy it down and then verify what they heard with what they just wrote down. If you can visually post links to Patreon on the screen for your own benefit, you can most certainly post other equally important information for the user's benefit.

NorthernKitty
Автор

ThreatWire! Have been missing this in my feed lately!

StefanRows
Автор

Stay Tuned for Next Week: Reading Brainwaves to steal data....

DaHaiZhu
Автор

Ah, the old light pulse data transfer trick! It's a classic Agent 99! I still have a wrist-watch from the 'way back'. It's an early 90's model of the Timex Ironman (Datalink)) that you could hold up to your computer screen to transfer data back and forth. (Alarms, reminders, calendar events, things like that). Software installed on the computer would convert your data into light patterns and flash/pulse them very quickly on the screen. A photo sensor on the watch would receive and convert the light patterns back into your data. As long as you and your monitor both survived the transfer process, you would end up with data from your PC being on your watch. The hack mentioned in the video appears to be just an updated version of a hack that was used back then where a camera within line-of-sight and having appropriate lighting, could capture the patterns and decode the data. Interesting that instead of somebody implementing a simple 1-time encryption key generation method for transferring/accepting 'light-based' data, that a problem from the '90s still has the same basic vulnerabilities, and the same basic solutions today.

CopalFreak
Автор

the only sucky thing about automatic updates is if they lose power at the wrong time you get bricked

matthewpepperl
Автор

The screen brightness hack is pretty interesting. The basic idea is nothing special at all and the use case feels like zero to none. But if it where to happen that the stars align and it actually was useful and you didn't know about it, it would feel like a 200iq moment :D

Luftbubblan
Автор

Real air-gapped devices are equipped with cloaks of invisibility.

Ok.. it's a blanket you hide under, but still works.

R_C
Автор

Can second hand / used bulbs be hacked and it attack your system when you add them? Or must they be hacked when already on the system?

captainted
Автор

Not a concept for the exfiltration of airgapped machines. Was used many years ago by someone handcoding a script to parse a file and exfiltrate it by modulating the hard drive led.

FLGuru
Автор

Integrating the new IETF MUD security profiles into next gen firewalls like PfSense would make a lot of this go away.

lohphat
Автор

I thought story 3 was going to be more clever. Why not try turning the backlight voltage or ground lead into a funtenna? That way, you don't need a camera and can potentially extend the range.

chizukichan
Автор

On the stealing data with screen brightness.
Wouldn't the data rate also be crazy low?

TDG
Автор

Brb, gonna go update the firmware on my Phillips Hue™️ Lightbulb

Rick-jfig
Автор

How would i connect or bridge multiple vps servers together?

prxy_phnx
Автор

There's to be some kind of most key card with some kind of module\ serial numbers but need to use NFC or some close range communication.

OFFRoadWheels
Автор

Politely asked a family member if they had updated their Hue system recently... Yes, in December! Wonderful! But, Pi-hole says something you've been visiting for the last few days is doing something that gets blocked, EVERY 5 SECONDS. You might want to factor that in as part of the overall value of that website? Closed that tab, and whaddya know, blocked count drops... (And I was thanked for making my requests/suggestions politely. I don't mind you visiting possibly skeevy sites, just want you to know they're possibly quite skeevy...)

artiem
Автор

Woah, the web agency I work for just took over the ZigBee website. What a small world! Definitely weird to hear the name ZigBee in this after having worked on the site. LOL

JustinWelenofsky
Автор

Info transfer by lights like Stargate SG1 episode lol

Merlinherk
Автор

Where there's a Hue... There's a way! 🤣

Zodliness
Автор

Why does everything have to connect to the internet are people to lazy to turn off lights sad

benjaminfranklinhawkeyepie