GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Stephen Brooks 🦆 (sjb@mstdn.io)'s status on Sunday, 09-Mar-2025 16:19:41 JST Stephen Brooks 🦆 Stephen Brooks 🦆

    #ESP32 backdoor. #security
    https://www.bleepingcomputer.com/news/security/undocumented-backdoor-found-in-bluetooth-chip-used-by-a-billion-devices/

    In conversation about 3 months ago from mstdn.io permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.bleepstatic.com
      Undocumented backdoor found in Bluetooth chip used by a billion devices
      from @BleepinComputer
      The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains an undocumented backdoor that could be leveraged for attacks.
    • Embed this notice
      翠星石 (suiseiseki@freesoftwareextremist.com)'s status on Sunday, 09-Mar-2025 16:19:39 JST 翠星石 翠星石
      in reply to
      • Wolf480pl
      @wolf480pl @sjb It doesn't strictly require already having root on the device - if the bluetooth implementation generates bluetooth commands in some way, that would allow for easy remote exploitation (if an attacker can get the bluetooth library to generate the backdoor opcodes, the attacker can trivially write to memory or flash and get persistent exploitation).
      In conversation about 3 months ago permalink
    • Embed this notice
      Wolf480pl (wolf480pl@mstdn.io)'s status on Sunday, 09-Mar-2025 16:19:40 JST Wolf480pl Wolf480pl
      in reply to

      @sjb AFAIU it requires already having root on the chip, so it's not really a backdoor

      In conversation about 3 months ago permalink
    • Embed this notice
      Wolf480pl (wolf480pl@mstdn.io)'s status on Sunday, 09-Mar-2025 16:30:11 JST Wolf480pl Wolf480pl
      in reply to
      • 翠星石

      @Suiseiseki @sjb by remote you mean wirelessly over bluetooth?

      In conversation about 3 months ago permalink
    • Embed this notice
      翠星石 (suiseiseki@freesoftwareextremist.com)'s status on Sunday, 09-Mar-2025 16:30:11 JST 翠星石 翠星石
      in reply to
      • Wolf480pl
      @wolf480pl @sjb Yes.
      In conversation about 3 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.