If you solder a ~10cm long "antenna" wire to a laptop's DRAM data bus, it makes it extra sensitive to electromagnetic interference.

So much so that clicking a piezo-electric arc lighter nearby can induce bit-flips.

I wrote an exploit to turn those bitflips into a shell:
dram_emfi/ddr3_dq7.py at 348bd15c9e767bff5968a4fcc80a97b81dc63bda · DavidBuchanan314/dram_emfi

playing with DDR DRAM bus fault injection. Contribute to DavidBuchanan314/dram_emfi development by creating an account on GitHub.

GitHub
I'm exploring this because I think it might be useful for console hacking - where you have physical access, and the ability to execute sandboxed code (say, inside a web browser)
now with 100% more root. prototype-quality exploit source: https://github.com/DavidBuchanan314/dram_emfi/blob/main/linux_x86_64_lpe.c
dram_emfi/linux_x86_64_lpe.c at main · DavidBuchanan314/dram_emfi

playing with DDR DRAM bus fault injection. Contribute to DavidBuchanan314/dram_emfi development by creating an account on GitHub.

GitHub
@retr0id thanks for sharing this, this is another level of physical attack I did not know about
@retr0id the energy from your fingers flipped those bits
@retr0id That's impressive.
@retr0id gotta buy some bulk piezo clickers, when the next jailbreak hits prices are going to skyrocket
@retr0id especially with pcie maybe. Try to use m.2 to exploit the cpu.
@retr0id don't consoles tend to have some form of hardware ram encryption?
@Rairii possibly, I'll be finding out how the nintendo switch reacts to it shortly
@retr0id @Rairii Yeah I think all of the AMD SOCs have transparent RAM encryption
@retr0id @Rairii We’re kicking grandpa over here are we
@Rairii @retr0id I’d still expect a bit flip to be reflected in decrypted data — I’m assuming the way blocks of data are encrypted is some sort of xor against another pseudo random block of data, without any kind of authentication or serial dependency on previous blocks

@retr0id jesus

i‘ve seen glitching exploits but with a lighter is just hilarious

@retr0id 🔥 Don't let the DEF CON hotels look at this video.
@retr0id CVE (Critical Vulnerability Entertainment) Score: 10/10.

@retr0id

When I was a kid we would use piezo electric ciggy lighters to get credits on some of the arcade game machines

#oldschoolcool

@n_dimension @retr0id semi fun fact, Nevada technical standards for casino gaming devices specify "electrical interference immunity" as the first standard. I like to think the hackers back in '89 inspired that one.
@retr0id why bit 7?
@evilchili it's convenient because it either adds or subtracts 128 when flipped, which I use to "misalign" a pointer into an object
@retr0id good for ghost huntin
@[email protected] do you have source code / a WU?
@retr0id #ALT4you video of a laptop console that reacts to lighter clicks

@retr0id @catsalad

Won‘t work with Rust, right? Right?😬

@retr0id cc @bean might be of interest to you
@retr0id I've got one of those light arc lighters. What would that do to the RAM?
@retr0id yeah... don't let anybody have physical access to your computers

@a1ba @retr0id

The manufacturer has physical access.

@Professor_Stevens @retr0id your family members probably too.

@a1ba @retr0id

True, though I trust them not to be for sale to hostile governments.

@Professor_Stevens @a1ba @retr0id eh, some of my family members killed my pets because they didn't like cats. I am fairly sure they would sell me for 50 bucks despite being rich as fuck

@Archivist @a1ba @retr0id

I believe you are on the verge of insight as to just why it is that they are rich as fuck.

@Professor_Stevens @a1ba @retr0id I did not reject that part of my family telling them they are assholes and that I will not go to their funeral without a reason
@a1ba @Professor_Stevens @retr0id they grabbed the occasion while I was doing a business trip to, while my brotherhad his husky outside, to let her out with her kitten. Then they said that it was my fault for going to work and not taking her with me. Note that the cat was at my apartment, and I had someone come regularly to care for them

@retr0id

"If you solder a ~10cm long "antenna" wire to a laptop's DRAM data bus, it makes it extra sensitive to electromagnetic interference."

Everybody should do this.

It's happened again that this is not publicly linkable
@retr0id
@p intended
Ok fair, I recall it happened previously unintentionally with your dragon hashquine
@retr0id
@retr0id unrelated, but is that a Samsung RV 509/511?
@retr0id is this the principle why the rpi2 was sensitive to photoflashes nearby?
@retr0id The archetypical fediverse post.