Microwave Modified for Disinfecting

We’re all hopefully a little more concerned about health these days, but with that concern comes a growing demand for products like hand sanitizer, disinfectant, and masks. Some masks are supposed to be single-use only, but with the shortage [Bob] thought it would be good if there were a way to sanitize things like masks without ruining them. He was able to modify a microwave oven to do just that.

His microwave doesn’t have a magnetron anymore, which is the part that actually produces the microwaves for cooking. In its place is an ultraviolet light which has been shown to be effective at neutralizing viruses. The mask is simply placed in the microwave and sterilized with the light. He did have to make some other modifications as well since the magnetron isn’t always powered up when cooking, so instead he wired the light into the circuit for the turntable so that it’s always powered on.

Since UV can be harmful, placing it in the microwave’s enclosure like this certainly limits risks. However, we’d like to point out that the mesh on the microwave door is specifically designed to block microwaves rather than light of any kind, and that you probably shouldn’t put your face up to the door while this thing is operating. Some other similar builds have addressed this issue. Still, it’s a great way to get some extra use out of your PPE.

source https://hackaday.com/2020/07/24/microwave-modified-for-disinfecting/

Laser Cutting Your Way to an RGB LED Table

You’ve got the RGB keyboard, maybe even the RGB mouse. But can you really call yourself master of the technicolor LED if you don’t have an RGB table to game on? We think you already know the answer. Luckily, as [ItKindaWorks] shows in his latest project, it’s easy to build your own. Assuming you’ve got a big enough laser cutter anyway…

The construction of the table is quite straightforward. Using an 80 watt laser cutter, he puts a channel into a sheet of MDF to accept RGB LED strips, a pocket to hold a Qi wireless charger, and a hole to run all the wires out through. This is then backed with a second, solid, sheet of MDF.

Next, a piece of thin wood veneer goes into the laser cutter. In the video after the break you can see its natural tendency to roll up gave [ItKindaWorks] a little bit of trouble, but when strategically weighted down, it eventually lays out flat. He then uses the laser to blast an array of tiny holes in the veneer, through which the light from the LEDs will shine when it’s been glued over the MDF. A few strips of plastic laid over the strips serve both to diffuse the light and support the top surface.

The end result is truly gorgeous and has a very futuristic feel. Assuming you’ve got the equipment, it’s also a relatively simple concept to experiment with. It’s yet another example of the unique construction techniques possible when you add a high-powered laser to your arsenal.

source https://hackaday.com/2020/07/24/laser-cutting-your-way-to-an-rgb-led-table/

HAPPY HOLIDAYS

CLOSED 23 Dec – 2 Jan.
THANK YOU 2018. It’s been a massive pleasure tattooing all of you. There would be no TRADE MARK without your continuous support. We hope you have a great & safe festive season. See all of you in 2019 

RGB Minecraft Sign isn’t Just For Looks

This laser cut and LED illuminated version of the Minecraft logo created by [Geeksmithing] looks good enough to occupy a place of honor on any gamer’s shelf. But it’s not just decoration: it can also notify you about your Minecraft’s server status and tell you when players are online by way of its addressable LEDs.

In the first half of the video after the break, [Geeksmithing] shows how the logo itself was built by cutting out pieces of white and black acrylic on his laser cutter. When stacked up together, it creates an impressive 3D effect but also isolates each letter. With carefully aligned rows of RGB LEDs behind the stack, each individual letter can be lit in its own color (or not at all) without the light bleeding into either side.

Once he had a way of lighting up each letter individually, it was just a matter of writing some code for the Raspberry Pi that can do something useful with them. Notifying him when the server goes down is easy enough, just blink them all red. But the code [Geeksmithing] came up with also associates each letter with one of the friends he plays with, and lights them up when they go online. So at a glance he can not only tell how many friends are already in the game, but which ones they are. Naturally this means the display can only show the status of nine friends…but hey, that’s more than we have anyway.

We’ve been seeing people connect the real world to Minecraft in weird and wonderful ways for years now, and it doesn’t seem like there’s any sign of things slowing down. While we recognize the game isn’t for everyone, but you’ve got to respect the incredible creativity it’s inspired in young and old players alike.

source https://hackaday.com/2020/07/24/rgb-minecraft-sign-isnt-just-for-looks/

Hackaday Podcast 077: Secret Life of SD Cards, Mining Minecraft’s Secret Seed, BadPower is Bad, and Sailing a Sea of Neon

Hackaday editors Mike Szczys and Elliot Williams are deep in the hacks this week. What if making your own display matrix meant a microcontroller board for every pixel? That’s the gist of this incredible neon display. There’s a lot of dark art poured into the slivers of microSD cards and this week saw multiple hacks digging into the hidden test pads of these devices. You’ve heard of Folding@Home, but what about Minecraft@Home, the effort to find world seeds from screenshots. And when USB chargers have exposed and rewritable firmware, what could possibly go wrong?

Take a look at the links below if you want to follow along, and as always, tell us what you think about this episode in the comments!

Direct download (~65 MB)

Places to follow Hackaday podcasts:

Episode 077 Show Notes:

New This Week:

Interesting Hacks of the Week:

Quick Hacks:

Can’t-Miss Articles:

source https://hackaday.com/2020/07/24/hackaday-podcast-077-secret-life-of-sd-cards-mining-minecrafts-secret-seed-badpower-is-bad-and-sailing-a-sea-of-neon/

USB-C Where It Was Never Intended To Be

The USB-C revolution is well under way, as first your new phone, then your single-board computer, and now your laptop are likely so sport the familiar reversible round-cornered connector. We’re still in the crossover period of requiring to keep micro USB, proprietary laptop, and USB-C power supplies at hand, but the promise of a USB-C-only world is tantalisingly close. For [Purkkaviritys] that’s a little bit closer now, as he’s modified his Thinkpad T440s to take a USB charger instead of its proprietary Lenovo square-plug part. (Video, embedded below.)

At its heart is a USB-PD emulator module that does all the hard work of negotiation with the power supply, giving the laptop the DC voltage it needs. It’s not quite that simple though, because a resistor is required to reassure the laptop that it’s got a genuine power supply. The module is encased in a carefully-designed surround that neatly takes the space vacated by the original connector, and since this laptop has its internal power connector on a short cable it is made very straightforward to fit into the case. If you didn’t know it was a home-made upgrade, you could be forgiven for thinking that this laptop left the factory with a USB-C power socket.

The USB-C module used here is a versatile part. We’ve previously seen it in a soldering iron conversion.

source https://hackaday.com/2020/07/24/usb-c-where-it-was-never-intended-to-be/

This Week in Security: Iran’s ITG18, ProcMon for Linux, and Garbage Collection Fail

Even top-tier security professionals make catastrophic mistakes, and this time it was the operators at Iran’s ITG18. We’re once again talking about the strange shadowy world of state sponsored hacking. This story comes from the IBM X-Force Incident Response Intelligence Services (IRIS). I suspect a Deadpool fan must work at IBM, but that’s beside the point.

A server suspected to be used by ITG18 was incorrectly configured, and when data and training videos were stored there, that data was publicly accessible. Among the captured data was records of compromised accounts belonging to US and Greek military personnel.

The training videos also contained a few interesting tidbits. If a targeted account used two factor authentication, the attacker was to make a note and give up on gaining access to that account. If a Google account was breached, the practice was to start with Google Takeout, the service from Google that allows downloading all the data Google has collected related to that account. Yoiks.

To Make an Exploit From Scratch, You Must First Invent the Universe

We’ve covered many kernel level exploits in this column, but never have we covered a guide quite like the one just published by Secfault Security. They attempt to bridge the gap between being a developer and an exploit author, walking us through the process of building an actual working exploit PoC based on a Google Project Zero write-up.

ProcMon

ProcMon in action
Image by Microsoft, Licensed MIT

Microsoft is continuing to develop their Linux presence, this time by re-engineering Process Monitor as ProcMon for Linux. A bit of history, Process Monitor is part of the Sysenternals suite, originally developed by [Bryce Cogswell] and [Mark Russinovich], founders of Winternals. Incidentally, they also broke the Sony BMG rootkit story, using sysinternals tools. Less than a year after that story broke, Winternals was acquired by Microsoft, and while [Cogswell] has moved on, [Russonovich] has stayed with Microsoft, and is now the CTO of Azure.

ProcMon is written in C++, and released under the MIT license. It keeps track of the system calls happening on machine in real time, giving a detailed look at the activity of the system. It’s useful for security, debugging, and troubleshooting performance issues. All in all, it’s a really handy tool, and should be a useful part of the sysadmin’s toolbox. The source is available under an OSI approved license, so the various distros should pick up and package ProcMon before long.

Windows Server Containers

Windows Server supports a couple of ways to run processes in containers: HyperV containers, and Windows Server Containers. It’s fairly widely accepted that virtualization based containerization provides a more secure isolation. That is, if a virtualized container is compromised, is far more difficult for an attacker to migrate out and attack the host machine, as compared to a kernel based containerization.

The news is a new way to escape a Windows Server Container. While not encountered as often as on a Linux machine, Windows does support symbolic links. Reading through the deep dive also makes it clear how much modern Windows machines are becoming POSIX machines with a Windows compatibility layer on top. For example, the “C:” directory is actually a global symlink to “\Device\HarddiskVolumeX\”.

If a containerized process could create a global symlink, AKA one that pointed to the root directory, then the container escape would be trivial. As expected, the container security controls don’t allow the isolated processes to create such a symlink during runtime. That said, there is a particular function that can be abused to create the global symlink. The specific function parameters have yet to be disclosed, in order to make in-the-wild exploitation just a bit more difficult.

Password Reset Gone Wrong

The story of a security audit on a website caught my eye this week, put together by [Maxwell “ꓘ” Dulin]. The password reset form is the focus here, and it has a few problems. The first one is a common flaw: the password reset form verifies whether a given email address is in the system. It’s not the worst flaw, but it does give an attacker information — he can guess email addresses, and gets confirmation when there is an account with that address.

The next flaw is a subtle one, the contents of the password reset email are generated using the host sent in the HTTP request. That normally works as expected: A user goes to ourwebsite.com/reset, inputs their email address, and submits the form to generate a password reset request. They get an email with a link back to ourwebsite.com that allows the password reset. An attacker, however, can send a malicious HTTP request to the password reset form, using someone else’s address, and manipulate the Host value. The reset email now points to the injected host. If the user clicks the link in the email, the magic value is sent to host specified by the attacker, who can then go reset the user’s password.

The last flaw [Maxwell] found was the worst of the bunch. The reset token is confirmed when the user first clicks the link sent via email, but it isn’t confirmed when the password is actually updated. You could create your own account, go through the password reset process, and then change the password reset form to point at another user’s account. Because the back-end sees you as already authenticated, it dutifully sets the new password, even if the account specified isn’t yours.

None of us will likely use the little website that this audit was performed on, but the steps described and problems to look for are a good guide for anyone needing doing the same.

Garbage Collection Use After Free

CVE-2019–1367 is an older bug at this point, found being exploited in the wild in 2019, and given a full write-up by Confiant. It’s yet another vulnerability in Internet Explorer’s jscript engine. For a very brief review, jscript.dll is the deprecated IE implementation of Javascript. It’s no longer the default implementation, but can be requested by a web page for compatibility purposes. It appears that jscript.dll is only accessible in Internet Explorer, and neither iteration of Edge support the legacy implementation at all.

This vuln was being actively used by state actors and was a watering hole style attack, where simply visiting the malicious site was enough to compromise. The next page of the write-up goes into the technical details. This is a class of vulnerability that we haven’t covered before. It’s a use-after-free in a garbage collected language.

Garbage collection is the alternative to manually freeing memory when finished with it. One of the advantages is that it is supposed to make use-after-free bugs a thing of the past, so what’s going on here? The garbage collection code in jscript.dll doesn’t properly track the reference count in certain situations. This bug specifically deals with the Array.sort() callback function. Arguments to that function aren’t properly tracked, so the JS instance can be manipulated such that a GC sweep frees an object that will be later accessed.

For the exploit and further analysis of how this flaw was used in the wild, check out part 2 and part 3 of the full write-up.

source https://hackaday.com/2020/07/24/this-week-in-security-irans-itg18-procmon-for-linux-and-garbage-collection-fail/

A Complete Raspberry Pi Power Monitoring System

As the world has become more environmentally conscious, we’ve seen an uptick in projects that monitor or control home energy use. At a minimum one of these setups involves a microcontroller and some kind of clamp-on current sensor, but if you’re looking for resources to take things a bit farther, this Raspberry Pi energy monitoring system created by [David00] would be a great place to start.

This project includes provides software and hardware to be used in conjunction with the Raspberry Pi to keep tabs on not just home energy consumption, but also production if your home has a solar array or other method of generating its own power. Data is pulled every 0.5 seconds from a MCP3008 ADC connected to up to five current sensors to provide real-time utilization statistics, and visualized with Grafana so you can see all of the information at a glance.

While [David00] has already done the community a great service by releasing the hardware and software under an open source license, he’s also produced some absolutely phenomenal documentation for the project that’s really a valuable resource for anyone who wants to roll their own monitoring system. He’s even offering hardware kits for anyone who’s more interested in experimenting with the software side of things than building the PCB.

Home energy monitoring projects are certainly nothing new, but the incredible advances we’ve seen in the type of hardware and software available for DIY projects over the last decade has really pushed the state-of-the-art forward. With so many fantastic resources available now, the only thing standing between you and your own home energy monitoring dashboard is desire and a long weekend.

source https://hackaday.com/2020/07/24/a-complete-raspberry-pi-power-monitoring-system/

TinyPilot Provides KVM-over-IP, With Low Cost and Even Lower Latency

Remote access is great, but if the machine stops booting, ceases to connect to the network, or needs low-level interaction like BIOS settings or boot management, remote access is worthless because it’s only available once the host computer is up and running. The usual solution is to drag a keyboard and monitor to the machine in question for physical access.

Ubuntu laptop (right) being accessed over IP, via web browser on the left.

For most people, swapping cables in this way is an infrequent task at best. But for those who work more closely with managing hardware or developing software, the need to plug and unplug a keyboard and monitor into machines that otherwise run headless can get tiresome. The modern solution is KVM (keyboard, video, mouse) over IP, but commercial options are expensive. [Michael Lynch]’s TinyPilot on the other hand clocks in at roughly $100 of parts, including a Raspberry Pi and USB HDMI capture device. It does have to drop the ‘M’ from KVM (meaning it does not support a mouse yet) but the rest of it hits all the bases, and does it all from a web browser.

What exactly does TinyPilot do? It provides remote access via web browser, but the device is an independent piece of hardware that — from the host computer’s point of view — is no different from a physical keyboard and monitor. That means keyboard and video access works before the host machine even boots, so even changing something like BIOS settings is no problem.

[Michael] demonstrates his design in the video embedded below, but we encourage you to check out the project page for a fascinating exploration of all the challenges that were part of TinyPilot’s development.

Interested? Make one yourself, or as an alternative [Michael] has made a parts kit available. TinyPilot doesn’t provide an interface to the host machine’s power switch, but if you need to add that you can use this other KVM project’s method of integrating a relay module with some DIY of your own.

source https://hackaday.com/2020/07/24/tinypilot-provides-kvm-over-ip-with-low-cost-and-even-lower-latency/

TinyPilot Provides KVM-over-IP, With Low Cost and Even Lower Latency

Remote access is great, but if the machine stops booting, ceases to connect to the network, or needs low-level interaction like BIOS settings or boot management, remote access is worthless because it’s only available once the host computer is up and running. The usual solution is to drag a keyboard and monitor to the machine in question for physical access.

Ubuntu laptop (right) being accessed over IP, via web browser on the left.

For most people, swapping cables in this way is an infrequent task at best. But for those who work more closely with managing hardware or developing software, the need to plug and unplug a keyboard and monitor into machines that otherwise run headless can get tiresome. The modern solution is KVM (keyboard, video, mouse) over IP, but commercial options are expensive. [Michael Lynch]’s TinyPilot on the other hand clocks in at roughly $100 of parts, including a Raspberry Pi and USB HDMI capture device. It does have to drop the ‘M’ from KVM (meaning it does not support a mouse yet) but the rest of it hits all the bases, and does it all from a web browser.

What exactly does TinyPilot do? It provides remote access via web browser, but the device is an independent piece of hardware that — from the host computer’s point of view — is no different from a physical keyboard and monitor. That means keyboard and video access works before the host machine even boots, so even changing something like BIOS settings is no problem.

[Michael] demonstrates his design in the video embedded below, but we encourage you to check out the project page for a fascinating exploration of all the challenges that were part of TinyPilot’s development.

Interested? Make one yourself, or as an alternative [Michael] has made a parts kit available. TinyPilot doesn’t provide an interface to the host machine’s power switch, but if you need to add that you can use this other KVM project’s method of integrating a relay module with some DIY of your own.

source https://hackaday.com/2020/07/24/tinypilot-provides-kvm-over-ip-with-low-cost-and-even-lower-latency/

TinyPilot Provides KVM-over-IP, With Low Cost and Even Lower Latency

Remote access is great, but if the machine stops booting, ceases to connect to the network, or needs low-level interaction like BIOS settings or boot management, remote access is worthless because it’s only available once the host computer is up and running. The usual solution is to drag a keyboard and monitor to the machine in question for physical access.

Ubuntu laptop (right) being accessed over IP, via web browser on the left.

For most people, swapping cables in this way is an infrequent task at best. But for those who work more closely with managing hardware or developing software, the need to plug and unplug a keyboard and monitor into machines that otherwise run headless can get tiresome. The modern solution is KVM (keyboard, video, mouse) over IP, but commercial options are expensive. [Michael Lynch]’s TinyPilot on the other hand clocks in at roughly $100 of parts, including a Raspberry Pi and USB HDMI capture device. It does have to drop the ‘M’ from KVM (meaning it does not support a mouse yet) but the rest of it hits all the bases, and does it all from a web browser.

What exactly does TinyPilot do? It provides remote access via web browser, but the device is an independent piece of hardware that — from the host computer’s point of view — is no different from a physical keyboard and monitor. That means keyboard and video access works before the host machine even boots, so even changing something like BIOS settings is no problem.

[Michael] demonstrates his design in the video embedded below, but we encourage you to check out the project page for a fascinating exploration of all the challenges that were part of TinyPilot’s development.

Interested? Make one yourself, or as an alternative [Michael] has made a parts kit available. TinyPilot doesn’t provide an interface to the host machine’s power switch, but if you need to add that you can use this other KVM project’s method of integrating a relay module with some DIY of your own.

source https://hackaday.com/2020/07/24/tinypilot-provides-kvm-over-ip-with-low-cost-and-even-lower-latency/

Portable CP/M Runs the Classics Anywhere

If you want to run an old CP/M program — maybe you want to run WordStar or play StarTrek — you have several options. One is to acquire some classic hardware. You can also build a new computer using a Z80 or some other processor that will emulate a Z80. Finally, you can emulate old hardware on your current computer. The iz-cpm project from [ivanizag] takes this last approach. Unlike some emulators, iz-cpm doesn’t try to emulate everything in one simulated environment. Instead, it directly accesses your file system so it allows CP/M executables to run more as though they were a native program.

You can think of it as Wine for CP/M. The code is portable to Linux, Windows, or MacOS. The author mentions, though, that it won’t run on CP/M itself! The program can run an executable standalone which means you could set .COM files up to execute automatically if you wanted to.

The machine looks like a Kaypro and emulates an ADM-3A. There is a script to download interesting CP/M software, for instance WordStar, Basic, and Zork. You can trace calls and even CPU instructions if you want to debug things. Speaking of debugging, though, you might actually need to do that.

When trying out the program, we noticed that WordStar had some odd behavior. Saving files to drive A works, but if you save anywhere else, the file winds up on drive A, anyway. This confuses WordStar because it tries to reread the file from the other disk so it blanks out the text you were working on. We reported the problem on GitHub and in a couple of hours the author had it fixed. You have to love the open source community.

The program is written in Rust which seems to be gaining traction lately. The program is a great way to get into CP/M hacking, especially if you are interested in Rust programming.

If you want real hardware, it is hard to beat the price for this Z80 computer. However, pick up the PCB and check out our updates to it, as well.

source https://hackaday.com/2020/07/23/portable-cp-m-runs-the-classics-anywhere/