Hacker News
Can you get root with only a cigarette lighter? (2024)
Retr0id
|next
[-]
- It also works on LPDDR5, LPDDR4
- Yes, it works on ARM platforms (at least, the ones I tried).
- The simplest way to trigger similar faults electronically is via a high-speed mux IC, as described in https://stefan-gloor.ch/ddr5 (chipshouter also works, but is less elegant imho!)
- Yes, you can get webkit addrof/fakeobj primitives like this, although I didn't write an end-to-end exploit.
- You can pwn nintendo switch kernel with an adjusted exploit strategy, but the same adjusted strategy does not work on Switch 2, due to memory encryption (one bitflip corrupts a whole cache line). But other strategies may be possible? (notably, it is possible to block a whole write operation from happening at all - see also https://rdist.root.org/2010/01/27/how-the-ps3-hypervisor-was... )
nom
|next
|previous
[-]
No idea who discovered it, but the machine back at my school had an infrared interface for servicing, and you could trigger an interrupt with the flash of the flintstone of a lighter. Because it's just some 90s microcontroller, it would simply reset after failing to receive a valid command and forget what it was doing previously.
All you had to do was order a coke, and right when it drops out, before it subtracts the amount, you flash the lighter in front of the IR port like a magician, say the magic words and bam - free coke!
limit35
|root
|parent
|next
[-]
chrisBob
|root
|parent
|next
|previous
[-]
charcircuit
|root
|parent
|next
|previous
[-]
kjkjadksj
|root
|parent
|next
|previous
[-]
b00ty4breakfast
|next
|previous
[-]
Edit: Nailed it!
ted_dunning
|next
|previous
[-]
Just hold the sysadmins hand over the lighter until they tell you the password.
Never forget the easy way in ... the humans.