Apple keyboard with evil firmware can root any computer
Uploader Comments (DigitalSocietyOrg)
Top Comments
-
The OS doesn't matter. He manipulated the firmware of the keyboard, and the firmware is a part of the keyboard itself. So even if you would re-install your OS the hack will still work.
This works on every OS.
-
Windows and PC aren't interchangeable terms.
Regardless, it's a firmware exploit. The keys are logged on the keyboard's firmware and are then repeated back (in reverse order) when pressing a certain series of keys).
All Comments (46)
-
Hi, I know this is really old. But I REALLY REALLY would love to get that presentation he's written. Somehow the link's broken. I would really love to know how this works, and the applications that it could be used for.
-
@DigitalSocietyOrg I can't understand what's going on, From my understanding they turned the keyboard into a keylogger?
PS. Link in description = Error 404 not found.
-
@DigitalSocietyOrg I know it your own post and all, but you comment is misleading and don't deserve the thumb up. If anyone can flash the firmware of any usb device over the fucking intertubes you are already rooted. Installing a keyloger will only allow to grab password and gain access on more computer system.
Also, APPLs are ass holes. Simple device usb like mouse and keyboard should be on rom. They probably use the wireless keyboard platform and just add a usb cable to save money. Fuck 'em.
-
@thibaulthalpern Fake. The title is misleading.
This won't root the computer. It is merely a key loger. There is noting to fear about this. Physical access is require to install the firmware. With physical access he could have install a loger on the OS or as a usb dongle.
-
Except it is a keyboard keylogger rather than a software keylogger. So he could replace someone's keyboard alone and steal their passwords. Pretty genius.
-
Well this is interesting. THX for sharing.
-
So it's basically just a keylogger?
-
@thibaulthalpern fuck off loser
This video, if its legit, proves a concept. If the micro-controller firmware can be further modefied, its lethality can be simply awesome.
But improve the footage quality so that we can figure out better whats happening !!!
TheMrArvind 2 years ago 2
Or, you can look at the link I provide in the description which details the exploit and links to the 900 page presentation released by K. Chen that details how to replicate this exploit.
DigitalSocietyOrg 2 years ago 2
This is a poorly done video.
1. it doesn't really explain well enough to the everyday person what is going on. I'm a power user of computers (not a hacker) and I barely understand what's going on
2. you need to increase the font size to say at least 36 points so that we can actually see both screen and keyboard at the same time. The video shots of the screen is blurry and often illegible.
thibaulthalpern 2 years ago
If you follow the link in the description, it puts everything in proper context. The video was never meant to stand on its own, but about 50K more people saw the video without reading the article.
As for the quality of the video, it was an improvised setting lacking tripod and dedicated microphone. Font size could have been much bigger, but hind sight is 20/20. These problems will be fixed for future videos.
DigitalSocietyOrg 2 years ago
you type asdf and it's asdf, okay.. then now what.. :D
isti82 2 years ago 4
Read the article in the description.
If the keyboard can log your typing, it can capture your password. If the keyboard can insert commands into the host computer, it can tell the computer to open a connect back bash shell or it can get rootkit via command line.
If you don't know what this means, it basically means you've been owned remotely by someone anywhere on the Internet.
DigitalSocietyOrg 2 years ago 3