PhatHack
May 30, 2012, 11:09:17 am *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Registration only by approval.  You probably want to send one of the admins an email asking them to approve you if you just created an account.
 
   Home   Help Search Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Man in the middle attack  (Read 1132 times)
0 Members and 2 Guests are viewing this topic.
para
Senior Member
Veteran.
*****
Offline Offline

Posts: 181



WWW
« on: March 28, 2005, 12:01:58 am »

Hi,
yet another approach...

What about having something like a mod chip (in this case a microcontroller) which is plugged between the HDD and the IDE interface of the PB. If hdparm requests the drive's information like ID, serial no. etc. it just intercepts that transfer and returns a pre-defined (programmable) value. Voila!

Para
Logged

judb
Administrator
Veteran.
*****
Offline Offline

Posts: 1329


ph4t l3wtz


WWW
« Reply #1 on: March 28, 2005, 12:21:51 am »

I think an IDE analyzer might get us all the info we need to figure it out which is a lot like a man in the middle attack.. only we shouldnt have to mod the box to do it.. just crack the protection scheme by getting at the private key somehow (if its stored on the drive we can get it.)
Logged
judb
Administrator
Veteran.
*****
Offline Offline

Posts: 1329


ph4t l3wtz


WWW
« Reply #2 on: March 28, 2005, 12:23:27 am »

Although I think the private key would be more likley placed in the boot5.pac or someplace that like that, loaded into flash memory and used during start up. Sad

thats still not impossible to get at.. we just need someone whos good at removing surface mount chips and getting them into a chip reader so we can grab the decrypted boot flash.
Logged
para
Senior Member
Veteran.
*****
Offline Offline

Posts: 181



WWW
« Reply #3 on: March 28, 2005, 08:38:30 am »

The assumption for this has been that there's no way of getting the private key. That would mean to let the DMS lock as it is but fool the system with faked data... Of course this is only meant as a last resort but if someone in here has some capabilities in that field of exertise why not explore it...

Para
« Last Edit: March 28, 2005, 08:39:44 am by para » Logged

judb
Administrator
Veteran.
*****
Offline Offline

Posts: 1329


ph4t l3wtz


WWW
« Reply #4 on: March 28, 2005, 02:32:52 pm »

after last night I THINK we might be able to download the flash without taking chips off the board...  
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.14 | SMF © 2006-2011, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 0.021 seconds with 16 queries.