Matt Brown
Matt Brown
  • Видео 86
  • Просмотров 5 573 402
Hacking a Crowdfunded IoT Security Box - UART and Firmware Extraction
Hacking an IoT security box... aka pure snail oil!
Come join us on Discord for some device hacking!
discord.gg/GjVxUnrQKC
Need IoT pentesting or reverse engineering services?
Please consider Brown Fine Security:
brownfinesecurity.com/
🛠️ Stuff I Use 🛠️
🪛 Tools:
Raspberry PI Pico: amzn.to/3XVMS3K
XGecu Universal Programmer: amzn.to/4dIhNWy
Multimeter: amzn.to/4b9cUUG
Power Supply: amzn.to/3QBNSpb
Oscilloscope: amzn.to/3UzoAZM
Logic Analyzer: amzn.to/4a9IfFu
USB UART Adapter: amzn.to/4h4G7DD
iFixit Toolkit: amzn.to/44tTjMB
🫠 Soldering & Hot Air Rework Tools:
Soldering Station: amzn.to/4dygJEv
Microsoldering Pencil: amzn.to/4dxPHwY
Microsoldering Tips: amzn.to/3QyKhrT
Rework Station: amzn.to/3JOPV5x
Air Extracti...
Просмотров: 19 462

Видео

Open Source and Secure WiFi Router - OpenWrt One
Просмотров 62 тыс.21 час назад
OpenWrt One: amzn.to/4gh0608 OpenWrt Project: openwrt.org/start OpenWrt One Device Page: openwrt.org/toh/openwrt/one Come join us on Discord for some device hacking! discord.gg/GjVxUnrQKC Need IoT pentesting or reverse engineering services? Please consider Brown Fine Security: brownfinesecurity.com/ 🛠️ Stuff I Use 🛠️ 🪛 Tools: Raspberry PI Pico: amzn.to/3XVMS3K XGecu Universal Programmer: amzn.t...
Verizon ONT Firmware Analysis
Просмотров 17 тыс.День назад
Come join us on Discord for some device hacking! discord.gg/GjVxUnrQKC Need IoT pentesting or reverse engineering services? Please consider Brown Fine Security: brownfinesecurity.com/ 🛠️ Stuff I Use 🛠️ 🪛 Tools: Raspberry PI Pico: amzn.to/3XVMS3K XGecu Universal Programmer: amzn.to/4dIhNWy Multimeter: amzn.to/4b9cUUG Power Supply: amzn.to/3QBNSpb Oscilloscope: amzn.to/3UzoAZM Logic Analyzer: amz...
Chinese RedNote App Exposes Sensitive User Data
Просмотров 48 тыс.14 дней назад
Many TikTok users have flocked to the Chinese social media app RedNote. Are the risks worth it? News Article: www.forbes.com/sites/danidiplacido/2025/01/13/why-tiktok-users-are-turning-to-rednote-amid-the-ban-protest/ mitmrouter: github.com/nmatt0/mitmrouter certmitm: github.com/aapooksman/certmitm Need IoT pentesting or reverse engineering services? Please consider Brown Fine Security: brownfi...
100K Subs - Thank You!
Просмотров 7 тыс.21 день назад
Need IoT pentesting or reverse engineering services? Please consider Brown Fine Security: brownfinesecurity.com/ IoT Hackers Hangout Community Discord Invite: discord.gg/GjVxUnrQKC 🛠️ Stuff I Use 🛠️ 🪛 Tools: Raspberry PI Pico: amzn.to/3XVMS3K XGecu Universal Programmer: amzn.to/4dIhNWy Multimeter: amzn.to/4b9cUUG Power Supply: amzn.to/3QBNSpb Oscilloscope: amzn.to/3UzoAZM Logic Analyzer: amzn.t...
Verizon ONT Firmware Extraction
Просмотров 44 тыс.21 день назад
My Disappointment Is Immeasurable And My Day Is Ruined Need IoT pentesting or reverse engineering services? Please consider Brown Fine Security: brownfinesecurity.com/ IoT Hackers Hangout Community Discord Invite: discord.gg/GjVxUnrQKC 🛠️ Stuff I Use 🛠️ 🪛 Tools: Raspberry PI Pico: amzn.to/3XVMS3K XGecu Universal Programmer: amzn.to/4dIhNWy Multimeter: amzn.to/4b9cUUG Power Supply: amzn.to/3QBNS...
Public Video and Data Feeds of Highway License Plate Readers
Просмотров 705 тыс.28 дней назад
Do you think the government should be able to track license plates on this scale? Let me know in the comments! Pt 1: ruclips.net/video/yvINGzIa2fg/видео.html Pt 2: ruclips.net/video/BQTy9XVeSaE/видео.html EFF ALPR article: www.eff.org/deeplinks/2024/06/new-alpr-vulnerabilities-prove-mass-surveillance-public-safety-threat Need IoT pentesting or reverse engineering services? Please consider Brown...
Hacking a Motorola Automatic License Plate Reader - Unauthenticated Video Streams
Просмотров 49 тыс.Месяц назад
Previous ALPR vid: ruclips.net/video/yvINGzIa2fg/видео.html EFF ALPR article: www.eff.org/deeplinks/2024/06/new-alpr-vulnerabilities-prove-mass-surveillance-public-safety-threat Need IoT pentesting or reverse engineering services? Please consider Brown Fine Security: brownfinesecurity.com/ IoT Hackers Hangout Community Discord Invite: discord.gg/GjVxUnrQKC 🛠️ Stuff I Use 🛠️ 🪛 Tools: Raspberry P...
Hacking a Motorola Automatic License Plate Reader - Firmware Extraction and Password Cracking
Просмотров 167 тыс.Месяц назад
EFF ALPR article: www.eff.org/deeplinks/2024/06/new-alpr-vulnerabilities-prove-mass-surveillance-public-safety-threat RPI Compute Breakout Board: amzn.to/3PcUd9l Usbboot repo: github.com/raspberrypi/usbboot PCI Passthrough rabbit hole: wiki.archlinux.org/title/PCI_passthrough_via_OVMF Hashcat Examples Page: hashcat.net/wiki/doku.php?id=example_hashes Need IoT pentesting or reverse engineering s...
US Government to BanTP-Link Devices - Live Hacking of a Chinese WiFi Router
Просмотров 1,5 млнМесяц назад
Forbes TP-Link article: www.forbes.com/sites/larsdaniel/2024/12/18/us-considers-ban-on-chinese-made-tp-link-routers-heres-why/ Hacking Team Hack Writeup: gist.github.com/jaredsburrows/9e121d2e5f1147ab12a696cf548b90b0 Minipro Repo: gitlab.com/DavidGriffith/minipro Need IoT pentesting or reverse engineering services? Please consider Brown Fine Security: brownfinesecurity.com/ IoT Hackers Hangout ...
In-Circuit Firmware Extraction with the CH341A - The Poor Man’s Flash Programmer
Просмотров 28 тыс.Месяц назад
CH341A Flash Programmer: amzn.to/3VEJbxe Software: wiki.flashrom.org/Flashrom Need IoT pentesting or reverse engineering services? Please consider Brown Fine Security: brownfinesecurity.com/ IoT Hackers Hangout Community Discord Invite: discord.com/invite/vgAcxYdJ7A 🛠️ Stuff I Use 🛠️ 🪛 Tools: Raspberry PI Pico: amzn.to/3XVMS3K XGecu Universal Programmer: amzn.to/4dIhNWy Multimeter: amzn.to/4b9c...
Firmware Extraction and Hardcoded Password Discovery - Hacking the Mercusys MB110
Просмотров 34 тыс.Месяц назад
Minipro software: gitlab.com/DavidGriffith/minipro Need IoT pentesting or reverse engineering services? Please consider Brown Fine Security: brownfinesecurity.com/ IoT Hackers Hangout Community Discord Invite: discord.com/invite/vgAcxYdJ7A 🛠️ Stuff I Use 🛠️ 🪛 Tools: Raspberry PI Pico: amzn.to/3XVMS3K XGecu Universal Programmer: amzn.to/4dIhNWy Multimeter: amzn.to/4b9cUUG Power Supply: amzn.to/3...
Accessing UART Console on 4G LTE Router - Hacking the Mercusys MB110
Просмотров 22 тыс.Месяц назад
Previous glitching video: ruclips.net/video/F-G-7-qo7Xg/видео.html Need IoT pentesting or reverse engineering services? Please consider Brown Fine Security: brownfinesecurity.com/ IoT Hackers Hangout Community Discord Invite: discord.com/invite/vgAcxYdJ7A 🛠️ Stuff I Use 🛠️ 🪛 Tools: Raspberry PI Pico: amzn.to/3XVMS3K XGecu Universal Programmer: amzn.to/4dIhNWy Multimeter: amzn.to/4b9cUUG Power S...
Persistent Shells and SSL Decryption - Raw Look at TP-Link Camera Hacking
Просмотров 20 тыс.Месяц назад
Need IoT pentesting or reverse engineering services? Please consider Brown Fine Security: brownfinesecurity.com/ IoT Hackers Hangout Community Discord Invite: discord.com/invite/vgAcxYdJ7A 🛠️ Stuff I Use 🛠️ 🪛 Tools: Raspberry PI Pico: amzn.to/3XVMS3K XGecu Universal Programmer: amzn.to/4dIhNWy Multimeter: amzn.to/4b9cUUG Power Supply: amzn.to/3QBNSpb Oscilloscope: amzn.to/3UzoAZM Logic Analyzer...
Hardware Hacking Travel Loadout
Просмотров 13 тыс.2 месяца назад
Hardware Hacking Travel Loadout
Persistent Root Shell via IoT Firmware Modification - Rooting a TP-Link Security Camera
Просмотров 25 тыс.2 месяца назад
Persistent Root Shell via IoT Firmware Modification - Rooting a TP-Link Security Camera
Glitching Linux Bootloader for Shells and Freedom - Rooting a TP-Link Security Camera
Просмотров 42 тыс.2 месяца назад
Glitching Linux Bootloader for Shells and Freedom - Rooting a TP-Link Security Camera
Open Source Flash Programmer Software - minipro FTW
Просмотров 15 тыс.3 месяца назад
Open Source Flash Programmer Software - minipro FTW
Hacking Time - Discussing the Bug Class that Earned Me 5-Figures
Просмотров 11 тыс.3 месяца назад
Hacking Time - Discussing the Bug Class that Earned Me 5-Figures
Chip Off Firmware Extraction - Hacking the Totolink WiFi Router
Просмотров 47 тыс.3 месяца назад
Chip Off Firmware Extraction - Hacking the Totolink WiFi Router
Top 5 Tools for IoT Hacking Beginners
Просмотров 26 тыс.3 месяца назад
Top 5 Tools for IoT Hacking Beginners
Make Binwalk Fast Again - Rust Rewrite of Binwalk is in Beta
Просмотров 15 тыс.3 месяца назад
Make Binwalk Fast Again - Rust Rewrite of Binwalk is in Beta
Discovering Backdoor in Chinese Router Firmware Update Server - Hacking the Totolink WiFi Router
Просмотров 39 тыс.3 месяца назад
Discovering Backdoor in Chinese Router Firmware Update Server - Hacking the Totolink WiFi Router
UART Root Shell on Linux Router - Hacking the Totolink WiFi Router
Просмотров 22 тыс.4 месяца назад
UART Root Shell on Linux Router - Hacking the Totolink WiFi Router
Wireshark Basics for IoT Hacking
Просмотров 22 тыс.5 месяцев назад
Wireshark Basics for IoT Hacking
Using Linux to Intercept IoT Device Traffic
Просмотров 18 тыс.5 месяцев назад
Using Linux to Intercept IoT Device Traffic
Hacking a Chinese Medical Device via Bluetooth - iHealth Nexus Pro Scale
Просмотров 26 тыс.5 месяцев назад
Hacking a Chinese Medical Device via Bluetooth - iHealth Nexus Pro Scale
Intercepting Mobile Traffic with Caido and Frida - iHealth Nexus Pro Scale
Просмотров 15 тыс.5 месяцев назад
Intercepting Mobile Traffic with Caido and Frida - iHealth Nexus Pro Scale
Siglent SDM3045X Multimeter - with Custom OBS Overlay
Просмотров 7 тыс.5 месяцев назад
Siglent SDM3045X Multimeter - with Custom OBS Overlay
Statistical Attacks on Proprietary Encryption - Hacking the VStarcam CB73 Security Camera
Просмотров 19 тыс.5 месяцев назад
Statistical Attacks on Proprietary Encryption - Hacking the VStarcam CB73 Security Camera

Комментарии

  • @lucasliamshop
    @lucasliamshop 5 часов назад

    One way to do it in failsafe mode to have root shell is mount _root passwd -d root reboot You can change root to any username.

  • @AMG749
    @AMG749 5 часов назад

    Us market so suck it's own 🍆

  • @humai771
    @humai771 7 часов назад

    Woohoo found a license plate number on a camera 🎉🎉🎉 notify me when you have owner registration status and addresses otherwise waste of time.

  • @BazNo-e6i
    @BazNo-e6i 7 часов назад

    If you’re driving a newer vehicle, your vehicle is sending data back to the manufacturer on the car company about every move you make, and knows how fast you’re going. When you slow down where you slow down at it’s got GPS on it. Remember the murder trial they had him slowing down at the river, and that’s where her phone disappeared, that was the last place they had a tag on it. I don’t know what happened to it after he slowed down right there by the river they assume it’s somewhere in the river

  • @BazNo-e6i
    @BazNo-e6i 7 часов назад

    What’s really shocking is how many of you who watch this video have no clue of the rights that you have or don’t have in public and lotta you don’t even realize that they’re being violated every single day and no one‘s being held accountable for it but when you get pulled over, you see those red blue lights you just apply you do whatever they tell you and that’s just ridiculous. Don’t comply when you go into a public building and they want you to leave your phone in your gun in the car then the only people in the government building who have guns are the government who’s the hostage now?

  • @BazNo-e6i
    @BazNo-e6i 7 часов назад

    They use them for Geo fencing, which is illegal rule, but they still use them

  • @abuibraham005
    @abuibraham005 8 часов назад

    Could you make tutorial on one of the 5G CPE devices

  • @crawford323
    @crawford323 9 часов назад

    Ir illumination even when there is no light. Then why on earth do we get busted for a license plate bulb not working? Probable cause maybe?

  • @brent57
    @brent57 9 часов назад

    You'd think they'd be behind some layer of filtration simply to prevent malicious attacks to disable them. I assume if you can connect on all those ports, that management access isn't filtered or restricted by IP address.

  • @ChristopherBond-j2h
    @ChristopherBond-j2h 9 часов назад

    It's not the public I worry about it's the government that's got to set up in the first place.That's the problem

  • @Jesus_Muslim
    @Jesus_Muslim 10 часов назад

    simply because TP-Link is FAR BETTER than US products...

  • @skeggjoldgunnr3167
    @skeggjoldgunnr3167 15 часов назад

    I got the Hakko FM2023 mini hot tweezers years ago. Waste of money without preheat of board + components. The old FX951 sits beside my FM203 running those tweezers, FM2032 and FM2027 and desoldering stuff. All Hakko. I bought all-in. it's served my business well, paid for themselves. Except for the mini hot tweezers. For the most part it's a joke: One tip is hot and the other tip isn't.

  • @skeggjoldgunnr3167
    @skeggjoldgunnr3167 16 часов назад

    Do those chinese power supplies perform reliably?

  • @concernedcitizen2031
    @concernedcitizen2031 19 часов назад

    I would love to see a video on extracting firmware from an eero router. My fiber provider tries to push the eero onto customers because they have a custom firmware for it that gives them a backdoor to customers networks and I think like most things isp related it likely isn’t the most secure .

  • @jweber1792
    @jweber1792 20 часов назад

    What was the password

  • @Walkercool-j5x
    @Walkercool-j5x 20 часов назад

    The login info is username:superadmin Password Y_qKrIrTQyp_

  • @RichSad45
    @RichSad45 21 час назад

    It's absolutely a big deal that they are leaking this data. Thank you for exposing this. Great video

  • @brianczuhai8909
    @brianczuhai8909 День назад

    Banned from what? How would ANYONE know what I have or USE in this thing called the privacy OF MY HOME? What if I just put a network device between the TP-Link router and the cable internet modem? I can then disable/control the host log-in address from ever appearing on MY NETWORK. I can change the SSID names. How could "a ban" ever be enforced?

  • @dogewow8999
    @dogewow8999 День назад

    Most TP-Link routers have an emergency TFTP flash mode, you can flash OpenWRT or whatever you like without JTAG, UART, EEPROM programmers...

  • @VirtualBSHere
    @VirtualBSHere День назад

    Before we even get into the weeds about what BS this device is, can we take a moment to cringe at all the wasted space in that enclosure. It's much larger than it needs to be. Then we can take a moment to appreciate that the OpenWrt banner used to have cocktail recipes while also noting that this version is more than 10 years old.

  • @adammoss5284
    @adammoss5284 День назад

    Awesome tip for googling the hash Matt. That just went woosh plain over the top till you mentioned that. Thanks 👍

  • @maxwellcastro339
    @maxwellcastro339 День назад

    American lies American lies inventions

  • @ostrov11
    @ostrov11 День назад

    ... хоспадеблять, классика пустой суеты ради создания мусора для ютуб.

  • @davegalaga1101
    @davegalaga1101 День назад

    You should make a video on how to keep these devices from reaching out to the internet

  • @davegalaga1101
    @davegalaga1101 День назад

    Matt, this was super interesting! Hardware hacking is a topic which doesn't get much attention

  • @vibrolax
    @vibrolax День назад

    I was an OpenWRT on cheap TP-Link router guy. Unfortunately, the lack of open source drivers for modern broadcom and realtek radios made that approach a dead end. Thankfully, MediaTek stepped up with modern radios with mainline linux support. I like the banana pi router boards, including the openwrt one. I ended up getting a new asus ax6000 tuf gaming router with mainline openwrt support for a great price. it's great to see openwrt going strong.

  • @pablopoo
    @pablopoo День назад

    liked the way is edited, is more natural to see doubts and thinking moments, is the real way of working behind the camera.

  • @LEBATO
    @LEBATO День назад

    Is the firmware analysis in the room with us right now?

  • @Aaronarnold92
    @Aaronarnold92 День назад

    I wonder if that domain is up for grabs free back door

  • @johanngambolputty5351
    @johanngambolputty5351 2 дня назад

    Why did you have to unsquash, didn't binwalk already extract?

  • @Alex-uh8lv
    @Alex-uh8lv 2 дня назад

    Yeah all law enforcement should have since people don't want to give any information not even I'd let alone insurance...stop all the hasel they only stop you if there is a red flag on your plate

  • @SYNner2u
    @SYNner2u 2 дня назад

    Hmm... so an attacker is going to gain entry into my house, gain physical access to my tp-link router that is operating in bridge mode that sits my crappy cisco asa firewall, take out the board, de-soldered the flash chip on it, plug it into a reader so they can get access to my password while staring down my cane corso. Okay, ban the device.

  • @wiley0714
    @wiley0714 2 дня назад

    Sometimes you have to realize that when you've come up with the same information that everybody else could see with their own two eyes, that you're a nerd. I've seen this kid at his real job. He works at Walmart as a security guard.

  • @kb45382
    @kb45382 2 дня назад

    I feel bad for the guy in Taiwan...

  • @jahblohnsteron
    @jahblohnsteron 2 дня назад

    you are covered. lv your passion and analysis

  • @ferencgaborsimon245
    @ferencgaborsimon245 2 дня назад

    I will buy OpenWRT Ten. By than they will make the product mature.

  • @MaximusDecimus-h2z
    @MaximusDecimus-h2z 2 дня назад

    38:32 could the daemon.bak be the same file that the device downloads from the servers

  • @6LordMortus9
    @6LordMortus9 2 дня назад

    I'm going to have to try that drink that it lists on boot :)

  • @davidtomlinson9621
    @davidtomlinson9621 2 дня назад

    The tools to put that chip back on the board or like $5 more dollars from what you already have. All you need is the reball stencil and solder paste, then just hit it with the hot air.

  • @johnsakrekov3874
    @johnsakrekov3874 2 дня назад

    Hey Matt I just bought a ryoko router do I have to worry about it looking into my bank account.??

  • @MrMaguuuuuuuuu
    @MrMaguuuuuuuuu 2 дня назад

    I used to love open source projects. But now they’re all being scraped into training AI to replace programmers and I’m tired of being my own tech support. Just buy from a reliable US based company run by real Americans ( or whatever country you live in).

  • @Joe-o7j4o
    @Joe-o7j4o 3 дня назад

    problem is you are not a true hacker; only a true hacker unbound by rules and restriction can hack and is a master of UNIX.....

  • @danielh.8836
    @danielh.8836 3 дня назад

    Could you please show how to get the XGecu software running in wine? Or maybe point out to some documentation? I own a T48 and it really sucks always having to dual boot Windows or start a VM to use it. I tried to get it working in Wine a while ago but did not have any success.

  • @zippythechicken
    @zippythechicken 3 дня назад

    Is this User Error? Can Setup Prevent user error by requiring the admin pass be changed before data can pass from the Wan to the Lan? OR as we have seen in some devices are hidden/diagnostic Backdoors being opened to allow access and the user can not close them. What you have shown is not dramatic or proof of evil doing by the manufacturer but it might be dangerous. But is it any different than the normal operation of Windows that exposes your device, logs data, transfers data which you can not prevent. There needs to be privacy standards and security standards for the future... but what you have shown isn't as malicious as what we have seen from some manufacturers intentionally opening doors that can't be closed... .. Just like we are fighting for the freedom to Repair our own devices like iPhones or even Caterpillar Tractors we should fight for the ability to completely shut any door or phone home or memory dump sent to manufacturers for their "testing" or Tracking of our use of our local devices or the connections they make to remote devices like browsing on the web.. AND THEN a subject no one talks about... YOUR ISP IS TRACKING EVERY CLICK YOU MAKE AND CACHING IT... Squid Servers, DNS Caching and so many ways... AND even if you Air Gap your computer there is the possibility to run exploits across that air gap... ....... Its more than I care to know.. but its all real... they can even get you across an Air Gap so you're basically fucked.... HOWEVER IT ALL COMES DOWN TO ... is this User Error? that maybe can be prevented with better setups.. Is this 100% intentionally Malicious? is this incompetence? or is it the fact that every device can be exploited if enough effort is put forth... ........... What you showed was cute.. and you can write ip range scanners to find systems that go beyond some website lookup.. but ... also please don't expose system IPs you find on those searches even if everyone else can.. you showed an IP supposedly in Taiwan that was open .. this video has been seen by 1.4 million people... not a good thing to do .. its like opening Google Maps showing a home and saying... They leave their doors unlocked .. maybe they do but maybe 1.4 Million people didn't know that who now do.

  • @billf.2960
    @billf.2960 3 дня назад

    I feel stupidier each time i see a video.. Just when i think i figured something out. I watch a new video and go.. nope.. back to basic.. looking at back doors in my own routers and cameres..

  • @zoiks6631
    @zoiks6631 3 дня назад

    It only has dual band WiFi 6? That’s a no from me.

  • @tupapa7230
    @tupapa7230 3 дня назад

    I have no idea what language you just spoke 😁 im 💯 confused, but even I can see how vulnerable people are as well as how bad these units are. Its almost like they are designed to be utilized in this manner. Crazy stuff just subbed 👊🏻💯

  • @noccy80
    @noccy80 3 дня назад

    Hmm, I commented on this video a few days ago, but that comment seem to have been removed as it doesn't even show up in my comment history. I included a link to FCC documents then, may be why. Anyway, Matt, you should dig deeper into what the firmware actually is up to. The more I look into it, the weirder it gets. TrustPilot is full of 1-star reviews, with some people claiming to have been hacked multiple times after installing the device on their network, and the internals and details on how it is supposed to work are classified. The device has direct links to Russia, China and Israel, so this may have been a trojan horse of sorts, rather than simply snake-oil. Either for spying and exfiltration, or as an egress point for tunneling traffic.

  • @jayirishful
    @jayirishful 3 дня назад

    What kind of devices can be used to counter the technology on a daily basis for the reasonable citizen

  • @hectorvido
    @hectorvido 3 дня назад

    Nice video! I hope this project can grow much more. Do you know what is the range of the wireless connection?