Ancestors

Toot

Written by Mäh W. on 2024-12-30 at 15:15

My #FlippyRAM USB pen drive which was handed out during the Rowhammer talk at #38C3 has Vendor ID 0x346d=13421d and Product ID 0x5678. If https://usb.org/sites/default/files/vendor_ids051920_0.pdf is the most recent account then this doesn't look like an officially registered VID. My Linux displays a "USB Disk 2.0". It actually enumerates as "Mass Storage" device. PID of 0x5678 also really reads like a dummy value though 0x38c3 would have been even nicer. Probably really just some cheap-o pen drives from $somewhere?

=> More informations about this toot | More toots from maehw@chaos.social

Descendants

Written by Mäh W. on 2024-12-30 at 15:34

The device model is "VendorCo ProductCode". ¯_(ツ)_/¯

7.5 GiB in total. Two partitions (~1 GiB + ~10 MiB + ) with fat32 filesystems on them. A big part is unallocated. I wonder if some easter eggs have been hidden there? First partition is labeled "ARCH_202412".

=> More informations about this toot | More toots from maehw@chaos.social

Written by Mäh W. on 2024-12-30 at 16:50

"When the only tool you have is a hammer, everything looks like a nail." Turns out my laptop is a train grid power driven hammer now. All for science! 💻🔨 (Please note: minimum runtime is 3 hours just in case you are also on travel and dare to run this.)

=> View attached media

=> More informations about this toot | More toots from maehw@chaos.social

Written by Mäh W. on 2024-12-30 at 17:05

Oh nice, they updated the website with hints about their #38c3 talk. And details alt how to verify the USB pen drive firsthand. Well, I took a backup and a hash of the drive, but it's currently not accessible as my laptop is already hammering. 😅

=> View attached media | View attached media

=> More informations about this toot | More toots from maehw@chaos.social

Written by Mäh W. on 2024-12-30 at 18:57

The experiment has ended. No bits have been harmed in this experiment. Maybe in the next one... who knows. #FlippyRAM #38c3

=> View attached media | View attached media

=> More informations about this toot | More toots from maehw@chaos.social

Written by Mäh W. on 2024-12-30 at 19:11

BTW this has been run on Arch Linux with kernel 6.12.6.

=> More informations about this toot | More toots from maehw@chaos.social

Written by Mäh W. on 2024-12-30 at 19:33

Apparently, my sha256sum starts with 0a... 🥸 Let's see if this matches the other one, which is going to be uploaded to their web page. 😄

=> More informations about this toot | More toots from maehw@chaos.social

Written by Daniel Gruss on 2024-12-31 at 00:59

@maehw was this booted natively or in a vm?

=> More informations about this toot | More toots from lavados@infosec.exchange

Written by Mäh W. on 2024-12-31 at 09:33

@lavados It was booted natively.

=> More informations about this toot | More toots from maehw@chaos.social

Written by Daniel Gruss on 2024-12-31 at 00:58

@maehw the partition extends on first boot

=> More informations about this toot | More toots from lavados@infosec.exchange

Written by Daniel Gruss on 2024-12-31 at 00:57

@maehw basically cheapest offer (public funding project...)

=> More informations about this toot | More toots from lavados@infosec.exchange

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113742429750900957
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
290.455723 milliseconds
Gemini-to-HTML Time
5.003854 milliseconds

This content has been proxied by September (3851b).