A team comprised of Sean "xobs" Cross and Xbox hacker Andrew "bunnie" Huang has demonstrated an exploit that allows SD memory cards to be used for man-in-the-middle attacks. Rather than relying on software residing in the SD card's regular pool of user-accessible flash memory, the exploit allows malicious code to be injected directly into the device's firmware. That firmware governs how SD cards and other NAND-based devices manage their flash memory, giving it access to the onboard microcontroller in addition to all incoming and outgoing data.
The exploit was demonstrated with SD cards based on a flash controller from Appotech, but Huang says all "managed NAND" devices could be vulnerable, including SSDs and USB thumb drives. The problem seems to be a lack of security surrounding the firmware update process for flash controllers. More details are available in an hour-long presentation given during the Chaos Computer Congress:
Huang has already seen Chinese vendors loading custom firmware onto SD cards that misrepresents the amount of onboard storage. Now, it's apparently possible to load much more nefarious code.
The vulnerability doesn't have to be used for evil, though. According to Huang, the exploit allows SD cards to be used as a cheap source of microcontrollers for DIY projects. The processors inside common SD cards offer "several times the performance" of an Arduino CPU at "a fraction of the price," Huang says.
|1. Ryszard - $603||2. Hdfisise - $600||3. Andrew Lauritzen - $502|
|4. the - $306||5. SomeOtherGeek - $300||6. Ryu Connor - $250|
|7. Anonymous Gerbil - $150||8. dashbarron - $150||9. webkido13 - $135|
|10. cygnus1 - $126|
|Run with PowerColor's Devil 13 Dual Core R9 390 graphics card||46|
|The gaping maw of Lian Li's PC-V33 is ready to swallow ATX mobos||7|
|Huawei leapfrogs Apple with pressure-sensitive Mate S phone||21|
|Tune in for our Skylake live stream tonight with David Kanter||11|
|Get the speed you need with Toshiba Q300 SSDs||8|
|ZenWatch 2 runs Android Wear Asus-style||13|
|Asus previews ROG Swift PG348Q and PG279Q G-Sync monitors||26|
|Wanted for review: AMD's Radeon R9 Nano||168|
|MSI's Z170A Gaming M5 motherboard reviewed||7|