Let's Hack: Extracting Firmware from Amazon Echo Dot and Recovering User Data

Let's Hack: Extracting Firmware from Amazon Echo Dot and Recovering User Data

Matt Brown

1 год назад

107,307 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

Matt Brown
Matt Brown - 05.01.2023 04:45

UPDATE: the storage partition also has API keys used for various amazon services that are associated with the previous user's account. (albeit probably expired)

Ответить
siosin V
siosin V - 12.10.2023 08:39

What sources or publications did you use?

Ответить
Furz
Furz - 04.10.2023 23:59

You know what amazon isnt prepared for atall an adversary applying for a job as a warehouse goon working there i got a shell on the sorting stations with just alt f2 the scanners all run incredebly old windows embedded with a configured telnet client open ports are all over the warehouse etc etc

Ответить
F H
F H - 26.09.2023 08:19

dd stands for copy and convert, but since cc (c compiler) was already in use, they went for dd

Ответить
Sean G
Sean G - 17.09.2023 01:02

damn my xgecu t48 wont read that emmc :( that reader you used is really expensive too. anyone else found another way to read these? i've tried soldering it onto an sd breakout board but they are really difficult to reball and fit

Ответить
imnutrak130
imnutrak130 - 12.08.2023 10:22

a bash script to make it automatically go from sdc1 to sdc16, because I am lazy, I know you are too!

#!/bin/bash

for ((i = 1; i <= 16; i++))
do
partition="/dev/sdc$i"
output="sdc$i.bin"
sudo dd if="$partition" of="$output"
done

Ответить
It's_Kepler.
It's_Kepler. - 10.08.2023 15:08

Bro my 2nd gen echo dot is not working.after connect to the powet it says download an update and after a hour it light ring become purple and not working plz help me bro what i need to now?
🥲

Ответить
OlMr Green
OlMr Green - 04.07.2023 15:05

Insane content. Its truly inspiring to see you in action.

Ответить
Bagas Electra
Bagas Electra - 26.06.2023 21:15

Interesting content i want more content about extracting firmware ,and i never know use linux os but very interesting ,maybe i will try linux os tomorrow thanks bro👍

Ответить
Erick Builds Stuff
Erick Builds Stuff - 09.06.2023 02:48

Matt, i stumbled upon your video after trying to solve the stuck red mute button and no ring light for my echo 4. I purchased as defective and unable to figure out the problem. Both do not reset and only light that turns on is red mute button at 2 different lighting levels. I'm guessing it's some type of firmware issue. Many others have the same problem and could you look at one in the used market? Follow up video would be awesome.

Ответить
ASKAI
ASKAI - 17.05.2023 18:02

Thanks for making this video. I would like to understand this information enough, to apply it to a 1st generation Echo Plus for the purpose of repurposing the hardware. I have always felt that the ~9" tall cylinder has impressive features: Microphones, lighted volume ring, top function buttons, and a pretty great sounding speaker setup. Do you think the main board could be repurposed, or that a newly designed board could be fitted while maintaining the functionality of the other components? I have a new 1st generation Echo Plus I'd be willing to send you. Also is that a Ravens hat your wearing? 👍Let me know.

Ответить
Marcos Scriven
Marcos Scriven - 12.05.2023 23:20

Incredibly well presented video. Thank you. I’ve been trying to understand how an IoT device that uses eMMC can be analysed, as I was only familiar with either simple 8-pin chips, or setups where the firmware could be downloaded without encryption.

Ответить
GCM
GCM - 14.04.2023 00:29

probably running FireOS which is a custom version of Android.

Ответить
浩 渠
浩 渠 - 03.04.2023 08:07

dude you look like Jim Carrey

Ответить
H8handles Security
H8handles Security - 11.03.2023 02:08

Love hacking but new to hardware on this scale. Learning a lot here thanks so much!

Ответить
Jason
Jason - 02.03.2023 21:48

Do you ever do in-system programming (ISP) extractions?

Ответить
Florian
Florian - 02.03.2023 02:27

That is REALLY great. Is there some way, we can exchange the extracted data, so people / others can work on Hacking the Bluetooth Firmware Update / Create alternative Firmware that does work without Amazon Stuff?

Ответить
The Legendary Gamers Of Awesomeness
The Legendary Gamers Of Awesomeness - 12.02.2023 17:35

These are the type of videos I was looking for, Keep up the good work!

Ответить
J
J - 07.02.2023 17:21

This content is so useful. I'm a software engineer but I'm trying to learn more on the hardware side. Thank you so much for posting this content!

Ответить
S Soll
S Soll - 29.01.2023 16:01

Matt you are a genius 👏💯

Ответить
J W
J W - 19.01.2023 22:10

when using the "dd" command; if you specify an appropriate blocksize (i.e. 'bs=4M' is reasonable for most flash storage), the "dd" command can finish much, much faster than if a less optimal blocksize (i.e. the default) was chosen

Also amazon products use a derivation of 'FireOS' which is a fork of android from a while back, kinda like how linux-mint is a fork of ubuntu

Ответить
Zack Mitkin
Zack Mitkin - 13.01.2023 04:13

Could you chroot into it? 🤔

Ответить
Jake Hemmerle
Jake Hemmerle - 12.01.2023 04:02

dd means data destroyer ;)

Ответить
Shane Brady
Shane Brady - 07.01.2023 09:39

Not sure if you've covered this already but what microscope are you using? Could you go over the tools you have in a future video. Thank you!!!

Ответить
Neon_nomad
Neon_nomad - 07.01.2023 06:19

Block a or block b gotta flash both or itl wreck your day

Ответить
Neon_nomad
Neon_nomad - 07.01.2023 06:14

In the vehicle industry the us uses android, Europe uses android built on linux and russia uses linux

Ответить
Neon_nomad
Neon_nomad - 07.01.2023 06:03

Disk destroyer aka. "The dd cmd" that will wreck your day.....

Ответить
Neon_nomad
Neon_nomad - 07.01.2023 05:41

You're not missing much without it ;p better off used for training purposes.
Heres to that hotplate reflow station though

Ответить
Vincent Janelle
Vincent Janelle - 07.01.2023 05:30

The SSID or password could also be in some other flash/nvram storage that operates more like a k/v store, this is pretty common with some other devices, although this one has a lot of storage.

Likely that keychain apk would lead to more details.

Ответить
Vincent Janelle
Vincent Janelle - 07.01.2023 05:24

".dump" in sqlite3 is useful sometimes

Ответить
Vincent Janelle
Vincent Janelle - 07.01.2023 05:18

You're very brave just doing `cat` on files instead of xxd :)

Ответить
Vincent Janelle
Vincent Janelle - 07.01.2023 05:07

There's multiple root filesystems because that's how they do OS updates - they update one root filesystem, then the bootloader switches to it - if it fails to boot, it reverts back to the last known working state.

Typically any user data would be in its own partition - and you're right, it's an android based system. Amazon's fire products are android based.

Ответить
Eduardo Anonimo
Eduardo Anonimo - 05.01.2023 12:36

Dude! I thought you have learned the leasson... sunshade hats are for gardening or for harvesting berries in the fields...

Still repairing the roof?

Ответить
Walter Green
Walter Green - 05.01.2023 06:58

apk files are generally use in android???

Ответить
Nathan Walker
Nathan Walker - 05.01.2023 06:44

This was fantastic! Thanks for the great walkthrough. Let us know how it continues :)

Ответить
Harjoat
Harjoat - 05.01.2023 06:16

Excited to see more :)

Ответить
Adric Me
Adric Me - 05.01.2023 05:03

id love to see more analysis of the google home mini.

Ответить
Trevor Boultwood
Trevor Boultwood - 05.01.2023 01:49

Cool video, please keep it up.

Ответить
frank378
frank378 - 05.01.2023 01:04

Really nice work Matt!

Ответить
Tanjiro
Tanjiro - 04.01.2023 21:54

I'm trying to learn about writing firmware to cheap apple clone smartwatches and smartbands but I don't know where to look for tutorials on firmware development for mediatek chips and nrf chips.please guide 🙏

Ответить
Анатолий П
Анатолий П - 04.01.2023 18:14

Грубые загрязнения хорошо счищается мягкой зубной щеткой.
Чип от флюса хорошо чистить обычной салфеткой смоченной изопропиловым спиртом.

Ответить
Matt Brown
Matt Brown - 04.01.2023 17:20

What devices should I look at in the future?

Ответить
Mark Ayala
Mark Ayala - 04.01.2023 17:09

i have learned a lot hope you post more :) .

Ответить