Newsletter
REAL HACKER NEWS
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO
No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO
No Result
View All Result
REAL HACKER NEWS
No Result
View All Result
Home REVIEWS

The long, solder-heavy way to get root access to a Starlink terminal

Real Hacker Staff by Real Hacker Staff
November 14, 2022
in REVIEWS
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Enlarge / Nobody said getting root access to space was going to be easy.

Getting root access inside one of Starlink’s dishes requires a few things that are hard to come by: a deep understanding of board circuitry, eMMC dumping hardware and skills, bootloader software understanding, and a custom PCB board. But researchers have proven it can be done.

In their talk “Glitched on Earth by Humans: A Black-Box Security Evaluation of the SpaceX Starlink User Terminal,” researchers at KU Leuven in Belgium detailed at Black Hat 2022 earlier this year how they were able to execute arbitrary code on a Starlink User Terminal (i.e., a dish board) using a custom-built modchip through a voltage fault injection. The talk took place in August, but the researchers’ slides and repository have recently made the rounds.

There’s no immediate threat, and the vulnerability is both disclosed and limited. While bypassing signature verification allowed the researchers to “further explore the Starlink User Terminal and networking side of the system,” slides from the Black Hat talk note that Starlink is “a well-designed product (from a security standpoint).” Getting a root shell was challenging, and doing so didn’t open up obvious lateral movement or escalation. But updating firmware and repurposing Starlink dishes for other purposes? Perhaps.

Still, satellite security is far from merely theoretical. Satellite provider Viasat saw thousands of modems knocked offline by AcidRain malware, pushed by what most assess to be Russian state actors. And while the KU Leuven researchers note how unwieldy and tricky it would be to attach their custom modchip to a Starlink terminal in the wild, many Starlink terminals are placed in the most remote locations. That gives you a bit more time to disassemble a unit and make the more than 20 fine-point soldering connections detailed in slide images.

  • Reading from eMMC test points to extract and patch Starlink’s firmware.

  • The basic design of the Starlink intruder modchip, with a Pi-designed processor at its core

  • Nobody said getting root access to space was going to be easy.

  • How to test your satellite security proof-of-concept when you work inside a university.

It’s not easy to summarize the numerous techniques and disciplines used in the researchers’ hardware hack, but here is an attempt. After some high-level board analysis, the researchers located test points for reading the board’s eMMC storage. Dumping the firmware for analysis, they found a place where introducing errant voltage into the core system on a chip (SoC) could modify an important variable during bootup: “development login enabled: yes.” It’s slow, it only works occasionally, and the voltage tampering can cause lots of other errors, but it worked.

Advertisement

The modchip used by the researchers is centered around a RaspberryPi RP2040 microcontroller. Unlike most Raspberry Pi hardware, you can still seemingly order and receive the core Pi chip, should you embark on such a journey. You can read more about the firmware dumping process in the researchers’ blog post.

Related articles

Twitter will kill ‘legacy’ blue checks on April 1

Twitter will kill ‘legacy’ blue checks on April 1

March 24, 2023
TikTok CEO fails to convince Congress that the app is not a “weapon” for China

TikTok CEO fails to convince Congress that the app is not a “weapon” for China

March 23, 2023



Source link

Tags: accesslongrootsolderheavyStarlinkterminal
Share76Tweet47

Related Posts

Twitter will kill ‘legacy’ blue checks on April 1

Twitter will kill ‘legacy’ blue checks on April 1

by Real Hacker Staff
March 24, 2023
0

Twitter has picked April Fool’s Day, otherwise known as April 1, to start removing legacy blue checkmarks from the platform....

TikTok CEO fails to convince Congress that the app is not a “weapon” for China

TikTok CEO fails to convince Congress that the app is not a “weapon” for China

by Real Hacker Staff
March 23, 2023
0

Enlarge / TikTok Chief Executive Officer Shou Zi Chew testifies before the House Energy and Commerce Committee. For nearly five...

Daily Crunch: In SEC filing, Accenture reveals plans to dismiss 19,000 workers over the next 18 months

Daily Crunch: In SEC filing, Accenture reveals plans to dismiss 19,000 workers over the next 18 months

by Real Hacker Staff
March 23, 2023
0

To get a roundup of TechCrunch’s biggest and most important stories delivered to your inbox every day at 3 p.m....

Coinbase SEC warning: What it means for future of crypto

Coinbase SEC warning: What it means for future of crypto

by Real Hacker Staff
March 23, 2023
0

Coinbase was issued a Wells notice from the U.S. Securities and Exchange Commission on Wednesday, and executives from the company...

Startup says the seaweed blobbing toward Florida has a silver lining

Startup says the seaweed blobbing toward Florida has a silver lining

by Real Hacker Staff
March 23, 2023
0

A brown macroalgae native to the Atlantic’s Sargasso Sea is increasingly a menace to coastal ecosystems and communities across the...

Load More
  • Trending
  • Comments
  • Latest

eSIMs Will Transform the Way You Think About Mobile Data and Security

March 7, 2023

XMOS Launches XVF3800 High-Performance Voice Processor for Enterprise and Consumer Voice Conferencing Platforms

March 7, 2023

Sennheiser Starts Shipping EW-DX Digital Wireless Microphone Series

November 22, 2022

Chinese Hackers Using Russo-Ukrainian War Decoys to Target APAC and European Entities

December 7, 2022

Hello world!

0
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Yellen, caught between markets and US Congress, tweaks message | Business and Economy News

Yellen, caught between markets and US Congress, tweaks message | Business and Economy News

March 24, 2023
A New Pokémon Distribution Event Has Been Announced For Japan

A New Pokémon Distribution Event Has Been Announced For Japan

March 24, 2023
Thieaudio Wraith review: Industrial design, unique sound

Thieaudio Wraith review: Industrial design, unique sound

March 24, 2023
Zelenskyy calls on EU to give jets, missiles or expect a long war | Russia-Ukraine war News

Zelenskyy calls on EU to give jets, missiles or expect a long war | Russia-Ukraine war News

March 24, 2023

Recent News

Yellen, caught between markets and US Congress, tweaks message | Business and Economy News

Yellen, caught between markets and US Congress, tweaks message | Business and Economy News

March 24, 2023
A New Pokémon Distribution Event Has Been Announced For Japan

A New Pokémon Distribution Event Has Been Announced For Japan

March 24, 2023

Categories

  • APPLICATIONS
  • AUDIO
  • CAMERA
  • COMPUTERS
  • GAMING
  • LAPTOP
  • REVIEWS
  • SECURITY
  • SMARTPHONES
  • Uncategorized
REAL HACKER NEWS

We bring you the best news on Internet new gadgets hacking and technology from around the world

  • Contact
  • Cookie Privacy Policy
  • Terms and Conditions
  • Privacy Policy
  • Disclaimer
  • DMCA

© 2003 Real Hacker News

No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO

© 2003 Real Hacker News

Go to mobile version