Hacker News with Generative AI: Hacking

Can Injection: keyless car theft (2023) (kentindell.github.io)
This is a detective story about how a car was stolen - and how it uncovered an epidemic of high-tech car theft. It begins with a tweet. In April 2022, my friend Ian Tabor tweeted that vandals had been at his car, pulling apart the headlight and unplugging the cables.
Guys Hacked AirPods to Give Their Grandmas Hearing Aids (wired.com)
Three technologists in India used a homemade Faraday cage and a microwave oven to get around Apple’s location blocks.
Airlines Hate 'Skiplagging.' Meet the Man Who Helps Travelers Pull It Off (nytimes.com)
Aktarer Zaman is the founder of a controversial website that unearths airfare hacks, most notably skipping the last leg of a flight for a cheaper price.
Bypassing regulatory locks, hacking AirPods and Faraday cages (lagrangepoint.substack.com)
Last week, right after Apple dropped the iOS 18.1 update, my dad and I set out to go buy a pair of AirPods Pro 2 for my grandma who is hard of hearing. Fifteen minutes after buying them, I found out that the device was for all intents and purposes useless, because Apple has region locked the Hearing Aids feature to the US and some other countries1.
Amazon confirms employee data breach after vendor hack (bleepingcomputer.com)
Amazon confirmed a data breach involving employee information after data allegedly stolen during the May 2023 MOVEit attacks was leaked on a hacking forum.
Tamagotchi Hacking, in Depth (hackaday.com)
In this strangely fascinating talk, you can follow along as [Natalie Silvanovich] reverse engineers some Tamagotchi. Even if you have no interest whatsoever in digital pets, you’ll probably pick up a trick or two by listening to how she went about taking over the toy. She can now push her own images to the screen, and evolve her Tamagotchi at will.
Hackers are stealing tickets from Ticketmaster customers' accounts (businessinsider.com)
Hackers are breaking into some Ticketmaster users' accounts and transferring tickets to themselves.
FBI Warns Gmail, Outlook, AOL, Yahoo Users–Hackers Gain Access to Accounts (forbes.com)
“Cybercriminals are gaining access to email accounts,” the FBI warned this week, even when accounts are protected by multifactor authentication (MFA).
Hacking cars in JavaScript (Replay attacks in the browser with the HackRF) (charliegerard.dev)
A couple of years ago, I built a project using the RTL-SDR to get live raw data from passing airplanes, in the browser.
Sophos' 5-Year War with the Chinese Hackers Hijacking Its Devices (wired.com)
For years, it's been an inconvenient truth within the cybersecurity industry that the network security devices sold to protect customers from spies and cybercriminals are, themselves, often the machines those intruders hack to gain access to their targets.
Sophos' 5-Year War with the Chinese Hackers Hijacking Its Devices (wired.com)
For years, it's been an inconvenient truth within the cybersecurity industry that the network security devices sold to protect customers from spies and cybercriminals are, themselves, often the machines those intruders hack to gain access to their targets.
Ask HN: Is there a good hackable smart watch? (ycombinator.com)
How to get the whole planet to send abuse complaints to your best friends (delroth.net)
It all begins with one scary email late at night just before I had to go to sleep:
Insiders Stealing Instagram Usernames? (javier.computer)
Alright, let me share the full story of how my 14-year-old Instagram account, @javier, was stolen and ended up in the hands of a hip-hop producer—and why I believe it was an inside job.
Skyscraper-high sewage plume erupts in Moscow (theregister.com)
There's a literal shitshow erupting in Moscow, where a skyscraper-high plume of sewage has erupted in the Russian capital, just months after Ukrainian hackers hit related systems.
My 14-year-old Instagram account, "javier," was stolen (twitter.com)
I discovered mysterious hidden signals on a public radio channel (2013) [video] (media.ccc.de)
How I discovered mysterious hidden signals on a public radio channel and eventually found out their meaning through hardware hacking, reverse engineering and little cryptanalysis.
ZombAIs: From Prompt Injection to C2 with Claude Computer Use (embracethered.com)
A few days ago, Anthropic released Claude Computer Use, which is a model + code that allows Claude to control a computer. It takes screenshots to make decisions, can run bash commands and so forth.
Freeing Glucose Data from Freestyle (frdmtoplay.com)
The Abbott Freestyle Libre 3 v3.4.2 iOS and Android apps do not provide a way to export blood glucose data without syncing to a cloud account. The data is stored on device in an encrypted RealmDB with a wrapped encryption key also stored on the device. Frida is used to hook the Android APK and unwrap the key to decrypt the RealmDB.
Ask HN: Who is hacking Internet Archive? (ycombinator.com)
apparently a "pro-Palestinian" group SN_BlackMeta claimed responsibility for the attack.
Practical Introduction to BLE GATT Reverse Engineering: Hacking the Domyos EL500 (2023) (jcjc-dev.com)
My goal for this project was quite specific, leaving many details unexplored (for now). This post aims to be a quick reference for my future self, and to hopefully help anyone else who might be interested in doing something similar.
Hackers the History of Hacking – Phone Phreaking, Cap.Crunch, Wozniak, Mitnick [video] (youtube.com)
Brazil Arrests 'USDoD' Hacker in FBI Infragard Breach (krebsonsecurity.com)
Brazilian authorities reportedly have arrested a 33-year-old man on suspicion of being “USDoD,” a prolific cybercriminal who rose to infamy in 2022 after infiltrating the FBI’s InfraGard program and leaking contact information for 80,000 members.
Firefox-Passwords-Decryptor: Extracts and decrypts passwords saved in Firefox (github.com/Sohimaster)
This tool is primarily designed for decrypting and extracting passwords stored in Firefox, offering an in-depth look into the security of saved credentials. It provides additional reconnaissance capabilities such as system info, open ports info, devices info, and Firefox browsing history extraction.
Over 6k WordPress hacked to install plugins pushing infostealers (bleepingcomputer.com)
WordPress sites are being hacked to install malicious plugins that display fake software updates and errors to push information-stealing malware.
Robot vacuum cleaners hacked to spy on, insult owners (malwarebytes.com)
Multiple robot vacuum cleaners in the US were hacked to yell obscenities and insults through the onboard speakers.
FBI Shuts Down Botnet Run by Beijing-Backed Hackers That Hijacked 200k+ Devices (gizmodo.com)
U.S. authorities have dismantled a massive botnet run by hackers backed by the Chinese government, according to a speech given by FBI director Christopher Wray on Wednesday.
From getting JTAG on the iPhone 15 to hacking Apple's USB-C Controller [video] (youtube.com)
Hacker sends email blast to Internet Archive Zendesk support ticket submitters (ycombinator.com)
I received the following email as a response to a long closed support email. I don’t see anything to indicate it isn’t from Internet Archive’s actual Zendesk instance.
Brazil Arrests 'USDoD,' Hacker in FBI Infragard Breach (krebsonsecurity.com)
Brazilian authorities reportedly have arrested a 33-year-old man on suspicion of being “USDoD,” a prolific cybercriminal who rose to infamy in 2022 after infiltrating the FBI’s InfraGard program and leaking contact information for 80,000 members.