Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Apple keyboard with evil firmware can root any computer

Loading...

Sign in or sign up now!
90,252
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Jul 31, 2009

DEFCON and BlackHat 2009. Hacker K. Chen showed off his latest hack where he was able to replace the firmware on an Apple keyboard. This firmware can sniff keystrokes to obtain your password and it can launch a bash shell connected to any remote IP address on any port.

Read the rest of this report on:
http://www.digitalsociety.org/apple-keyboards-hacked-and-possessed/

Category:

Science & Technology

Tags:

License:

Standard YouTube License

  • likes, 16 dislikes

Link to this comment:

Share to:

Uploader Comments (DigitalSocietyOrg)

  • This video, if its legit, proves a concept. If the micro-controller firmware can be further modefied, its lethality can be simply awesome.

    But improve the footage quality so that we can figure out better whats happening !!!

  • Or, you can look at the link I provide in the description which details the exploit and links to the 900 page presentation released by K. Chen that details how to replicate this exploit.

  • This is a poorly done video.

    1. it doesn't really explain well enough to the everyday person what is going on. I'm a power user of computers (not a hacker) and I barely understand what's going on

    2. you need to increase the font size to say at least 36 points so that we can actually see both screen and keyboard at the same time. The video shots of the screen is blurry and often illegible.

  • If you follow the link in the description, it puts everything in proper context. The video was never meant to stand on its own, but about 50K more people saw the video without reading the article.

    As for the quality of the video, it was an improvised setting lacking tripod and dedicated microphone. Font size could have been much bigger, but hind sight is 20/20. These problems will be fixed for future videos.

  • you type asdf and it's asdf, okay.. then now what.. :D

  • Read the article in the description.

    If the keyboard can log your typing, it can capture your password. If the keyboard can insert commands into the host computer, it can tell the computer to open a connect back bash shell or it can get rootkit via command line.

    If you don't know what this means, it basically means you've been owned remotely by someone anywhere on the Internet.

Top Comments

  • The OS doesn't matter. He manipulated the firmware of the keyboard, and the firmware is a part of the keyboard itself. So even if you would re-install your OS the hack will still work.

    This works on every OS.

  • Windows and PC aren't interchangeable terms.

    Regardless, it's a firmware exploit. The keys are logged on the keyboard's firmware and are then repeated back (in reverse order) when pressing a certain series of keys).

see all

All Comments (46)

Sign In or Sign Up now to post a comment!
  • Hi, I know this is really old. But I REALLY REALLY would love to get that presentation he's written. Somehow the link's broken. I would really love to know how this works, and the applications that it could be used for.

  • @DigitalSocietyOrg I can't understand what's going on, From my understanding they turned the keyboard into a keylogger?

    PS. Link in description = Error 404 not found.

  • @DigitalSocietyOrg I know it your own post and all, but you comment is misleading and don't deserve the thumb up. If anyone can flash the firmware of any usb device over the fucking intertubes you are already rooted. Installing a keyloger will only allow to grab password and gain access on more computer system.

    Also, APPLs are ass holes. Simple device usb like mouse and keyboard should be on rom. They probably use the wireless keyboard platform and just add a usb cable to save money. Fuck 'em.

  • @thibaulthalpern Fake. The title is misleading.

    This won't root the computer. It is merely a key loger. There is noting to fear about this. Physical access is require to install the firmware. With physical access he could have install a loger on the OS or as a usb dongle.

  • @Gameboygenius

    Except it is a keyboard keylogger rather than a software keylogger. So he could replace someone's keyboard alone and steal their passwords. Pretty genius.

  • Well this is interesting. THX for sharing.

  • So it's basically just a keylogger?

  • @thibaulthalpern fuck off loser

Loading...

0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more