On hacking microSD cards

Remember when I wrote about how your mobile phone runs two operating systems, one of which is a black box we know and understand little about, ripe for vulnerabilities? As many rightfully pointed out in the comments – it’s not just mobile phones that have tiny processors for specific tasks embedded in them. As it turns out, memory cards have microprocessors though – and yes, they can be cracked for remote code execution too.

Today at the Chaos Computer Congress (30C3), xobs and I disclosed a finding that some SD cards contain vulnerabilities that allow arbitrary code execution – on the memory card itself. On the dark side, code execution on the memory card enables a class of MITM (man-in-the-middle) attacks, where the card seems to be behaving one way, but in fact it does something else. On the light side, it also enables the possibility for hardware enthusiasts to gain access to a very cheap and ubiquitous source of microcontrollers.

There’s so much computing power hidden in the dark.

37 Comments

  1. 2014-01-01 8:48 pm
  2. 2014-01-01 10:03 pm
    • 2014-01-01 11:13 pm
      • 2014-01-02 12:19 am
        • 2014-01-02 11:06 am
          • 2014-01-03 5:15 am
        • 2014-01-03 6:04 am
      • 2014-01-02 12:23 am
        • 2014-01-02 2:03 am
          • 2014-01-02 9:29 am
          • 2014-01-02 9:58 am
          • 2014-01-02 10:18 am
          • 2014-01-02 12:14 pm
          • 2014-01-02 12:59 pm
          • 2014-01-03 2:40 am
        • 2014-01-02 11:47 am
          • 2014-01-06 9:28 pm
    • 2014-01-02 1:02 am
  3. 2014-01-01 10:33 pm
  4. 2014-01-01 10:53 pm
    • 2014-01-02 1:09 am
      • 2014-01-02 10:55 am
        • 2014-01-02 11:26 am
          • 2014-01-02 1:23 pm
          • 2014-01-03 7:27 am
        • 2014-01-02 3:58 pm
          • 2014-01-02 5:35 pm
    • 2014-01-02 11:36 am
      • 2014-01-02 1:29 pm
        • 2014-01-03 7:29 am
          • 2014-01-03 10:33 am
          • 2014-01-03 10:59 am
          • 2014-01-03 11:34 am
          • 2014-01-03 11:38 am
  5. 2014-01-02 11:14 am
    • 2014-01-02 5:10 pm
  6. 2014-01-03 8:21 pm