People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!
bashrunner simply runs shell scripts on behalf of our applications. By writing to the directory content_acquisition, a restart of the device will whitelist the file as valid and allow it to be executed in future runs. Initially, this required a hardwire connection to the Robot.0xFFE2 is the generalized inbox for commands to be executed; this could be hit without pairing, but some of the commands are protected by an AES-GCM layer. For instance, the WiFi opcodes remain locked behind a valid incoming user.wpa_supplicant.conf configuration file. By using weirdly formatted data in the packet, it's possible to modify the configuration to force the Robot to join any WiFi network we choose. This requires a classic string-injection attack to change data that was not meant to be changed.system(), you can get command execution on the device pretty trivially. Although the system has PIE enabled, so they used the first bug to get the base address. It slightly feels like cheating to get the PIE address needed for RCE from another RCE bug?