![]() He then physically broke open a combination lock and noticed the resistance he observed was caused by two lock parts that touched in a way that revealed important clues about the combination. Kamkar told Ars his Master Lock exploit started with a well-known vulnerability that allows Master Lock combinations to be cracked in 100 or fewer tries. In 2005, he unleashed the Samy worm, a cross-site scripting exploit that knocked MySpace out of commission when it added more than one million MySpace friends to Kamkar's account. The technique was devised by Samy Kamkar, a serial hacker who has created everything from stealthy keystroke-pilfering USB chargers to DIY stalker apps that mined Google Streetview. The following video provides a simple tutorial. Now that the attacker knows the first and last digits and knows the second digit is one of eight possible numbers, the hack is a simple matter of trying each possible combination until the correct one opens the lock. By eliminating the false digit from the Web form, the page will automatically populate the eight possible numbers for the second digit of the combination. By testing which of the possible last digits has more 'give,' an attacker can quickly figure out which one is correct. The page responds with the first digit of the combination and two possible digits for the last digit. The two locked positions and the one resistance position are then recorded on a Web page that streamlines the exploit. (An attacker can still turn through it but will physically feel the resistance.) This location represents the resistance location. At some point before a full revolution is completed, the dial will resist being turned. Next, an attacker again lifts the locked shackle, this time with less force, while turning the dial clockwise. The remaining two locations represent locked positions. One of them will be ignored as it is exactly between two whole numbers on the dial. Before the dial reaches 11, there will be three points where the dial will resist being turned anymore. The exploit involves lifting up a locked shackle with one hand while turning the combination dial counterclockwise starting at the number 0 with the other. There's a vulnerability in Master Lock branded padlocks that allows anyone to learn the combination in eight or fewer tries, a process that requires less than two minutes and a minimal amount of skill to carry out. Reader comments with 96 posters participating
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |