stacksmashing
stacksmashing
  • Видео 32
  • Просмотров 13 268 622
Breaking Bitlocker - Bypassing the Windows Disk Encryption
In this video we will use a hardware attack to bypass TPM-based Bitlocker encryption as used on most Microsoft Windows devices.
Errata:
- PIN can also be enabled using manage-bde, not just using group policies
Questions:
- Does this work on TPM2.0? Yes, at least on some: pulsesecurity.co.nz/articles/TPM-sniffing
Links:
- hextree.io/
- Pascal Gujer: pascal_gujer / hands-on-security.com
- Enabling Bitlocker PIN: www.howtogeek.com/262720/how-to-enable-a-pre-boot-bitlocker-pin-on-windows/
- Hardware & source-code: github.com/stacksmashing/pico-tpmsniffer
- LPC Clockless Analyzer for Saleae: github.com/stacksmashing/LPCClocklessAnalyzer
Me:
- Twitter: ghidraninja
- Patreon: patreon....
Просмотров: 882 064

Видео

Getting JTAG on the iPhone 15
Просмотров 332 тыс.9 месяцев назад
In this video we explore how to get access to the JTAG interface on the new iPhone 15! Special thanks to aunali1 & h0m3us3r, the Asahi Linux Project and Marc Zyngier! Sign-up to the hextree.io waiting list here: hextree.io/ Links: - Twitter: ghidraninja - Patreon: patreon.com/stacksmashing - Modified Chip Scrutinizer Firmware: github.com/stacksmashing/cs-sw-iphone15 - macvdmtool pat...
The secrets of Apple Lightning - Part 1
Просмотров 822 тыс.Год назад
Apple's proprietary Lightning connector is very well known. But do you know how it works? How is a cable authenticated? What can you do with Lightning? In this video we dive into the details of Apple's Lightning protocol - also known as SDQ and IDBUS! Links: - Twitter: ghidraninja - Patreon: patreon.com/stacksmashing - Nyan Satan's Lightning page: nyansatan.github.io/lightning/ - My...
The Hitchhacker’s Guide to iPhone Lightning and JTAG Hacking (DEF CON 30 Presentation)
Просмотров 62 тыс.Год назад
At DEF CON 30 I talked about a project I've been working on with a couple of friends for the past few month: The Tamarin Cable! An open-source Kanzi Cable. Thanks to DEF CON for having me! Links: - Tamarin Firmware: github.com/stacksmashing/tamarin-firmware - OpenOCD fork with Tamarin support: github.com/stacksmashing/openocd - Twitter: ghidraninja - Patreon: patreon.com/stacksmashi...
Can an AI drive Mario Kart 64?
Просмотров 88 тыс.2 года назад
Can TensorFlow learn to control Mario Kart 64 running on a real, physical Nintendo 64? In this video we are going to find out! Starring the Raspberry Pi Pico as a USB to Nintendo 64 adapter! Many many thanks again to Kevin Hughes for this awesome TensorKart project! If you want to learn more about artificial intelligence, machine learning & co, checkout TensorFlow: tensorflow.org/ Links: - Orig...
Hacking the Game Boy with a Silver Play Button
Просмотров 36 тыс.2 года назад
Thank you all for supporting my channel! It's been awesome! Links: - Gekkio's Disobey 2018 talk: ruclips.net/video/GBYwjch6oEE/видео.html - BennVenn's bootrom dump: web.archive.org/web/20150329083720/www.bennvenn.com/MGB.htm - SGB attack: www.its.caltech.edu/~costis/sgb_hack/ - Decapped ROM extraction: dot-matrix-game.blogspot.com/2014/01/boot-roms.html - My cartridge: github.com/stacksmashing/...
How the Apple AirTags were hacked
Просмотров 1,6 млн3 года назад
On Saturday, I managed to dump the firmware of the newly released Apple AirTags - and in this video I'll show how I did it. I won't share firmware dumps or so, so please don't ask :) Links: - Colin on Twitter: colinoflynn - Colin on RUclips: ruclips.net/channel/UCqc9MJwX_R1pQC6A353JmJg - Colin's company: www.newae.com - LimitedResults Appprotect bypass: limitedresults.com/2020/06/nr...
Online Multiplayer on the Game Boy
Просмотров 206 тыс.3 года назад
In this video I will show you how I connected the Game Boy Tetris to the internet! Links: - Buy the adapter kit: gum.co/gb-link - LiveOverflow: ruclips.net/channel/UClcE-kVhqyiHCcjYwcpfj9w - Patreon: patreon.com/stacksmashing - Twitter: ghidraninja - Discord: discord.gg/YASkVQY5Pr - Server: github.com/stacksmashing/gb-tetris-server - Frontend: github.com/stacksmashing/gb-tetris-web ...
Mining Bitcoin on the Game Boy
Просмотров 1,3 млн3 года назад
In this video, we attempt to mine Bitcoin on the original Game Boy using the Raspberry Pi Pico as a link-cable to USB adapter! Links: - Breakout and ROM cart: gumroad.com/stacksmashing#wKdGY - Patreon: www.patreon.com/stacksmashing - Twitter: ghidraninja Code: - Game Boy code: github.com/ghidraninja/game-boy-bitcoin-miner - ntgbtminer for Game Boy: github.com/ghidraninja/game-boy-nt...
In-depth: Raspberry Pi Pico's PIO - programmable I/O!
Просмотров 130 тыс.3 года назад
In this video we take an in-depth look into the new Raspberry Pi Pico/RP2040 high-speed programmable I/O system: PIO! For a high level video check ruclips.net/video/o-tRJPCv0GA/видео.html! I know this video is quite fast-paced and dense, but I'm trying to experiment with different formats for these in-depth videos :) Errata: - 8:20 - the register is always decremented, not only if the condition...
Why 111-1111111 is a valid Windows 95 key
Просмотров 2 млн3 года назад
In this video, we take a look at why 111-1111111 is a valid Windows 95 key. Links: - Ghidra quickstart: ruclips.net/video/fTGTnrgjuGA/видео.html - Jon Sawyer on Twitter: jcase - Patreon: patreon.com/stacksmashing - Twitter: ghidraninja - OEM Key Check: gist.github.com/nezza/a25bee13f25a1733a4c7a1d3d1cf5882 Errata: - In the beginning I say "while I was setting up Windows ...
Hacking the ████████® ████ & █████™
Просмотров 181 тыс.3 года назад
The dispute was successful and the videos are back! Awesome! - gizmodo.com/nintendo-is-making-copyright-claims-on-videos-of-game-1846040532 - www.eff.org/wp/unfiltered-how-youtubes-content-id-discourages-fair-use-and-dictates-what-we-see-online - ruclips.net/video/AKtaFU2ky9E/видео.html
rC3 Talk: Hacking the Game & Watch
Просмотров 73 тыс.3 года назад
rC3 Talk: Hacking the Game & Watch
Game & Watch: How we dumped the firmware & community-updates
Просмотров 95 тыс.3 года назад
Game & Watch: How we dumped the firmware & community-updates
Bringing homebrew to the Game & Watch
Просмотров 271 тыс.3 года назад
Bringing homebrew to the Game & Watch
DOOM on the Game and Watch
Просмотров 405 тыс.3 года назад
DOOM on the Game and Watch
Hacking the Nintendo Game and Watch
Просмотров 682 тыс.3 года назад
Hacking the Nintendo Game and Watch
In-depth: ELF - The Extensible & Linkable Format
Просмотров 189 тыс.3 года назад
In-depth: ELF - The Extensible & Linkable Format
Exploring the Mew Glitch
Просмотров 186 тыс.4 года назад
Exploring the Mew Glitch
How to reverse engineer & patch a Game Boy ROM
Просмотров 142 тыс.4 года назад
How to reverse engineer & patch a Game Boy ROM
Reversing WannaCry Part 3 - The encryption component
Просмотров 116 тыс.4 года назад
Reversing WannaCry Part 3 - The encryption component
Hacking the Game Boy cartridge protection
Просмотров 552 тыс.4 года назад
Hacking the Game Boy cartridge protection
Bare-metal ARM firmware reverse engineering with Ghidra and SVD-Loader
Просмотров 138 тыс.4 года назад
Bare-metal ARM firmware reverse engineering with Ghidra and SVD-Loader
Reversing WannaCry Part 2 - Diving into the malware with #Ghidra
Просмотров 236 тыс.4 года назад
Reversing WannaCry Part 2 - Diving into the malware with #Ghidra
CVE-2020-0601 aka Curveball: A technical look inside the critical Microsoft CryptoAPI vulnerability
Просмотров 41 тыс.4 года назад
CVE-2020-0601 aka Curveball: A technical look inside the critical Microsoft CryptoAPI vulnerability
IoT Security: Backdooring a smart camera by creating a malicious firmware upgrade
Просмотров 272 тыс.4 года назад
IoT Security: Backdooring a smart camera by creating a malicious firmware upgrade
Reversing WannaCry Part 1 - Finding the killswitch and unpacking the malware in #Ghidra
Просмотров 1,4 млн5 лет назад
Reversing WannaCry Part 1 - Finding the killswitch and unpacking the malware in #Ghidra
Reverse engineering with #Ghidra: Breaking an embedded firmware encryption scheme
Просмотров 111 тыс.5 лет назад
Reverse engineering with #Ghidra: Breaking an embedded firmware encryption scheme
Ghidra quickstart & tutorial: Solving a simple crackme
Просмотров 327 тыс.5 лет назад
Ghidra quickstart & tutorial: Solving a simple crackme

Комментарии

  • @sneauxburrow
    @sneauxburrow День назад

    Great video, thank you 🙏

  • @themrunknown850
    @themrunknown850 День назад

    There are several way to protect your computer from attack like this. For example, some Lenovo laptop have tamper protection settings in BIOS, opening the laptop will trigger the lock and force the user to connect to AC and type in three supervisor password. Or just make it so that you have to type the drive password with TPM check in order to decrypt

  • @subbastionbastion2167
    @subbastionbastion2167 3 дня назад

    A universal way is to literally do a gpu attack on software sure it may take a lot more time but it will work against any device

    • @stacksmashing
      @stacksmashing 2 дня назад

      "a gpu attack on software", what's that supposed to mean?

    • @subbastionbastion2167
      @subbastionbastion2167 День назад

      @@stacksmashing literally cracking the code by brute force

    • @stacksmashing
      @stacksmashing День назад

      @subbastionbastion2167 “take a lot more time” - you mean until the heat death of the universe?😂

    • @subbastionbastion2167
      @subbastionbastion2167 День назад

      @@stacksmashing more like days but ok

    • @stacksmashing
      @stacksmashing День назад

      @subbastionbastion2167 completely false.

  • @Adarsh-wg6xq
    @Adarsh-wg6xq 3 дня назад

    If i deleted the OS in the HDD thus locking the other drives inside it and installed SDD and OS in it. Will this work then.

  • @_nobody_of_consequence_
    @_nobody_of_consequence_ 4 дня назад

    So the TPM has to used for it to be 'sniffed'... Does this mean external drives that do not open automatically when connected can't be sniffed out. A user request would have to be made to open the drive from the PC with the TPM chip?

  • @horsethi3f
    @horsethi3f 6 дней назад

    Why cant the tpm module by part of the CPU itself.

  • @LetsPlayKeldeo
    @LetsPlayKeldeo 8 дней назад

    Okay but the rom cartrdige itself cant do the swapping right ? I would still need a micro controller

  • @joshuaott2800
    @joshuaott2800 9 дней назад

    I would totally buy one from you! sell them!

  • @schern6737
    @schern6737 9 дней назад

    Anyone knows how it works, I purchased a SSD and have been using as a secondary drive for ages, It realize now it might have been used. because I recently reinstalled windows 10, now that secondary drive is requesting for a bitkey that isn't tied to my account. It never requested before.

  • @shoop9274
    @shoop9274 10 дней назад

    so what does this mean, bitlocker is useless? what should I use as an alternative?

  • @Shvraz
    @Shvraz 11 дней назад

    wont work on modern pcs with tpm in the cpu

  • @nikbl4k
    @nikbl4k 14 дней назад

    Great video. Very informative, i would love more videos that share relation to C, GCC or linux. Anyway, thx! yvrycool

  • @oh6881
    @oh6881 15 дней назад

    Have you ever tried to break FireVault? Just curious

  • @JamieTheCreator157
    @JamieTheCreator157 15 дней назад

    I’m setting up a windows 95 virtual machine while I’m watching this

  • @b213videoz
    @b213videoz 15 дней назад

    If only you could click around SLOWER

  • @Berzeger
    @Berzeger 15 дней назад

    Holy smokes, after the first part I must say - what a ride! I've got back to reverse engineering after a 2 year long hiatus and your WannaCry analysis blows my mind. Immediate subscribe.

  • @kitsune-chan6897
    @kitsune-chan6897 16 дней назад

    Now play DOOM on it.

  • @alrikrr
    @alrikrr 17 дней назад

    Thanks for this amazing video ! I ordered some PCB and started soldering the PICO, thou the pogo pins are a pain to solder, any tips ?

  • @halvarmc671
    @halvarmc671 20 дней назад

    The best practice is to always 0 your drive before recycling or 0 and reinstall the OS if you're selling the laptop. In the case of externals, I always 0 or reformat.

    • @Turco949
      @Turco949 20 дней назад

      A single pass zero-write is hardly that guaranteed that the data can never be recovered. Best is to wipe/zero write the drive then physically destroy it. At the very least, a 3-pass DOD level wipe or something equivalent is needed.

  • @Mani-kt5iw
    @Mani-kt5iw 21 день назад

    Would it also work if us a esp32 instead of the Raspberri pi pico

  • @cat-win98
    @cat-win98 21 день назад

    STOP CENSORING THE SCREEN!!!!!!! 🤬🤬🤬🤬🤬😡😡😡😡

  • @cat-win98
    @cat-win98 21 день назад

    WHY DO YOU CENSOR THE SCREEN???????? 😡😡🤬🤬🤬🤬🤬

    • @stacksmashing
      @stacksmashing 21 день назад

      Because Nintendo sent a take down.

  • @Rayan-Singh
    @Rayan-Singh 23 дня назад

    So this won't work on newer CPU's that use TPM which is inbuilt on the CPU like Newer Gen Ryzen and Intel ?

  • @literallydoing4425
    @literallydoing4425 26 дней назад

    well, linux *is* in fact better IG

  • @pcguy5491-the-modern-retro-man
    @pcguy5491-the-modern-retro-man 27 дней назад

    Next video should be why 222222222222222 is a valid quake 3 arena cd key

  • @pcguy5491-the-modern-retro-man
    @pcguy5491-the-modern-retro-man 27 дней назад

    Monster truck madness, office 95/97, microsoft hellbender and any microsoft product before 1998 except plus 98 also works with this same key too.

  • @walsterdoomit
    @walsterdoomit 28 дней назад

    Above my pay grade but pretty cool video.

  • @Vadermods
    @Vadermods 29 дней назад

    now as a cherry on top, make a multiplayer game besides Tetris, something open world would be groundbreaking if you built it it on top of the wifi cart we have avalible to us now.

  • @marcoc.6022
    @marcoc.6022 29 дней назад

    Is it also possible to remove the linked apple id?

  • @bax_upx
    @bax_upx Месяц назад

    cool

  • @IIIIIIIIIIIllllllIIIIIIIIIII
    @IIIIIIIIIIIllllllIIIIIIIIIII Месяц назад

    Awesome

  • @lashlarue7924
    @lashlarue7924 Месяц назад

    I am a lowly sweet potato 🍠 and do not comprehend such things. Serve me piping hot with a pinch of cinnamon and a dollop of bytecode.

  • @TheTarkovSh00ter
    @TheTarkovSh00ter Месяц назад

    Add a pin, dont store stuff that you need on main drive. This only gets you into windows it doesnt decrypt other drives.

  • @joelstolarski2244
    @joelstolarski2244 Месяц назад

    Amazing and so well explained. Have a dell micro 3080 that belonged to a company, recovered from an unpaid storage unit. Have bought several laptops the same way. This is first one, that had a bitlocker encrypted drive. I'm new to using kali, and have done an 8266 nodmcu deauth chip, but this is a little more involved. Don't have a raspberry pi yet. Thanks for the tutorial !

  • @DeweckPewez
    @DeweckPewez Месяц назад

    PS2 Slim

  • @DeweckPewez
    @DeweckPewez Месяц назад

    GAME BOY COLOR ONLINE MULTIPLAYER

  • @michaelknight4041
    @michaelknight4041 Месяц назад

    I don't know about this guy. The Indian dude hacking and splicing a standard USB to a Lightning cable with a resistor and a capacitor in between while horrible Indian music looped over and over seemed more trustworthy. Im gonna go see what hes up to.

  • @nataliegrn17
    @nataliegrn17 Месяц назад

    Thanks!

  • @Smiley_Frown
    @Smiley_Frown Месяц назад

    Who are you

  • @silvereagleranch7352
    @silvereagleranch7352 Месяц назад

    what hardware do u need to buy... for my machine?

  • @CoachMikeyStudios
    @CoachMikeyStudios Месяц назад

    I used to encrypt hard drives all the time in the windows XP days. It would take days. I always wanted to know why bitlocker works so quickly. Great video. Thanks for sharing.

  • @mbican
    @mbican Месяц назад

    Well, of course TPM without PIN is useless, you just turn on the laptop and it is decrypted, you can also do cold boot attack and read memory, there is many ways how to bypass TPM without PIN, it's a lock without a key 🤷‍♂️

  • @Muhammad-re4wk
    @Muhammad-re4wk Месяц назад

    The way he says Ghidra drives me crazy

    • @stacksmashing
      @stacksmashing Месяц назад

      yep, completely wrong 😀 sorry about that

  • @damny0utoobe
    @damny0utoobe Месяц назад

    Excellent tutorial

  • @NeverSuspects
    @NeverSuspects Месяц назад

    Anyone who would care to steal encrypted data would come prepared or have taken the whole laptop to gain access to it with no time limit.. Anyone who really really want to get access will find information like this video and read a bit and carry out the process.. so what dies this whole thing really provide to the user outside of possibly difficult recovery process?? Microsoft gets a new word to use in marketing the os "Secured with BitLocker!"

  • @jackkirby5287
    @jackkirby5287 Месяц назад

    How do I identify which chip is the TPM? And how do I identify the LPC bus? I've been looking over an HP for hours and I cannot seem to find either one.

  • @nnibxx
    @nnibxx Месяц назад

    Awesome, do you know how is wired (color coded) in the terminal?

  • @aurelienlevra3782
    @aurelienlevra3782 Месяц назад

    Most pedagogic content about a presentation of how the ELF format work. Top tier quality content

  • @SuperSonicWind
    @SuperSonicWind Месяц назад

    Companies should still throw the harddrive when they sell laptops separately. This is for the sole purpose of stopping african criminals from recovering loose hard drives found in garbage dumps and selling their data. This whole bitlocker thing is for promoting shipping deceased hardware to 3rd wirld countries garbage dumps. Which is a very bad act in my opinion

  • @censoredeveryday3320
    @censoredeveryday3320 Месяц назад

    Or voltage and current glitching. An art that few have experience with.