hacc

Google and Apple take on BLE tracker abuse — that they pioneered

Google announced in a blog post today that it and Apple were leading an industry coalition (that includes smaller item-tracking players like Samsung, Tile, and others) to develop a specification for Bluetooth Low Energy (BLE) tracking devices. These devices, like Apple’s popular AirTag, are small BLE emitters that use public key cryptography and a network of “finding” devices to tell you where your tag is when you’re not around. Soon after AirTags were released, malicious…

Continue reading

hacc

The GL-iNet Mango Travel Router & CVE-2022-31898

I had an hour or two to kill before a dentist appointment last summer, so I pulled out the GL-iNet Mango v2 Travel Router I had bought to hack on in just this type of situation. At 30$ and about the size of a credit card, I figured I was bound to find something. And boy, did it not take long. After opening up the firmware in Ghidra and searching for calls to system() as a first shot, I…

Continue reading