Mining Bitcoin on the Game Boystacksmashing2021-03-27 | In this video, we attempt to mine Bitcoin on the original Game Boy using the Raspberry Pi Pico as a link-cable to USB adapter!
Timestamps: 00:00 - Intro 01:13 - Bitcoin mining explained 02:27 - Hardware setup 03:13 - Game Boy firmware 04:18 - Link Cable Protocol 05:45 - Raspberry Pi Firmware 06:10 - Host computer 07:00 - Let's mine Bitcoin! 07:53 - TestchainFault injection vs Firmware hackingstacksmashing2024-04-18 | ...Sniffing Bitlocker keys with $10 of equipmentstacksmashing2024-02-06 | ...Breaking Bitlocker - Bypassing the Windows Disk Encryptionstacksmashing2024-02-03 | In this video we will use a hardware attack to bypass TPM-based Bitlocker encryption as used on most Microsoft Windows devices.
Errata: - PIN can also be enabled using manage-bde, not just using group policies
Original DEF CON recording: youtube.com/watch?v=8p3Oi4DL0eICan an AI drive Mario Kart 64?stacksmashing2021-11-14 | Can TensorFlow learn to control Mario Kart 64 running on a real, physical Nintendo 64? In this video we are going to find out! Starring the Raspberry Pi Pico as a USB to Nintendo 64 adapter!
Many many thanks again to Kevin Hughes for this awesome TensorKart project!
If you want to learn more about artificial intelligence, machine learning & co, checkout TensorFlow: tensorflow.org
00:00 Intro 00:37 The setup 01:32 TensorKart 02:28 Training the model 03:09 Lag :( 04:50 Training loss 05:20 Testing on hardware 06:20 More training 06:36 Results! 07:22 Does it generalize? 07:40 OutroHacking the Game Boy with a Silver Play Buttonstacksmashing2021-07-03 | Thank you all for supporting my channel! It's been awesome!
My links: - Twitter: twitter.com/ghidraninja - Patreon: patreon.com/stacksmashingHow the Apple AirTags were hackedstacksmashing2021-05-11 | On Saturday, I managed to dump the firmware of the newly released Apple AirTags - and in this video I'll show how I did it.
I won't share firmware dumps or so, so please don't ask :)
00:00 Intro 00:10 AirTags hardware 01:40 Debugging interface 02:35 Fault-Injection 04:30 Glitching the AirTags 05:50 Hardware Setup 07:10 Lets Glitch 07:56 Firmware modificationOnline Multiplayer on the Game Boystacksmashing2021-05-02 | In this video I will show you how I connected the Game Boy Tetris to the internet!
Timestamps: 00:00 - Intro 01:13 - The Link Cable Protocol 01:57 - Architecture 02:39 - Hardware setup 03:59 - WebUSB! 04:42 - The Frontend 05:27 - The Server 06:20 - A wild LiveOverflow appears! 07:19 - 3 Players!In-depth: Raspberry Pi Picos PIO - programmable I/O!stacksmashing2021-03-09 | In this video we take an in-depth look into the new Raspberry Pi Pico/RP2040 high-speed programmable I/O system: PIO!
I know this video is quite fast-paced and dense, but I'm trying to experiment with different formats for these in-depth videos :)
Errata: - 8:20 - the register is always decremented, not only if the condition is met - 9:01 - The pin will be OFF for one cycle and ON for 2 cycles - said it the other way around accidentally
Timestamps: 00:00:00 - Intro 00:01:15 - PIO architecture 00:02:30 - The state machine 00:05:30 - IO Mapping 00:06:56 - Set Instruction 00:07:47 - Jump Instruction 00:09:08 - Mov Instruction 00:10:23 - In/Out Instructions 00:10:53 - Push/Pull Instructions 00:11:43 - IRQ Instruction 00:12:47 - Wait Instruction 00:13:38 - Delay 00:14:45 - Side-Set 00:15:48 - Program WrappingWhy 111-1111111 is a valid Windows 95 keystacksmashing2021-01-29 | In this video, we take a look at why 111-1111111 is a valid Windows 95 key.
Errata: - In the beginning I say "while I was setting up Windows 98" - The 2 OEM digits are between 95 and 02Hacking the ████████® ████ & █████™stacksmashing2021-01-15 | The dispute was successful and the videos are back! Awesome!
The official recording, including Q&A can be found here: https://media.ccc.de/v/rc3-11527-hacking_the_nintendo_game_watch
Timestamps: 00:00:00 - Intro 00:06:00 - The hardware 00:08:30 - Debugging port 00:11:10 - RAM dump analysis 00:12:35 - Dumping the flash 00:19:48 - Dumping the original firmware 00:24:40 - Getting Homebrew and DOOM onto the device 00:30:05 - Emulators 00:32:54 - The community
Links: - Twitter: twitter.com/ghidraninjaGame & Watch: How we dumped the firmware & community-updatesstacksmashing2020-12-16 | In this video we first take a look at what the Game & Watch community has been up to, before then diving deep into how the original firmware was dumped!
I got lucky and received my Game and Watch Super Mario Bros. one day early - and immediately started hacking it! In this video we will teardown the device, take a look inside, and find how we can put our own, customized ROM onto it!
Also many thanks to SciresM ( twitter.com/SciresM ) on Twitter from telling me that ... basically exclusively uses AES-CTR!In-depth: ELF - The Extensible & Linkable Formatstacksmashing2020-10-27 | ELF files are everywhere: From your PS4, to the Wii, to any Linux device out there. In this video we explore the Extensible & Linkable Format, and understand how it works - on the byte level!
Errata: - At the beginning I say extensible while displaying executable and linkable file format - Extensible is the old name, nowadays ist called Executable. Must’ve gotten confused :)
Timestamps: 0:00 Intro 0:47 segment and section differentiation 2:05 ELF structure 3:39 ELF header data structure 9:34 Program header data structure 13:54 Section header data structureExploring the Mew Glitchstacksmashing2020-05-03 | In this video we explore the long range trainer glitch, or, as it's more widely known, the Mew glitch! This glitch allows us to catch mew on the original Pokemon Generation 1 games for the Game Boy.
Fyi, this is not the quickest way to catch mew - the trainer to the west of the nugget bridge can be access much earlier in the game and is the easiest & quickest way! I used this specific trainer because it was (as far as I can tell) the "first" version of this glitch that was discovered :)
To clarify the engaged trainer class, as there were some comments about it: During the fight against Youngster, the byte "engaged trainer class" is used as the second byte of Slowpokes special stat. It's a 16 bit value, so at 7:55 you can see that it's 0x0015. As we go back to route 8, DisplayEnemyTrainerTextAndStartBattle however uses this value as "engaged trainer class". So the second byte of the special stat of Slowpoke sets what Pokemon/Trainer we will see when we go back to i.e. route 8. If it's over 200, it will engage a trainer, if it's under 200, it will engage a Pokemon. And the Pokemon we are encountering is the one with the ID in "Engaged Trainer Class" at that moment - Mew.
You can also find me on Twitter: twitter.com/ghidraninjaHow to reverse engineer & patch a Game Boy ROMstacksmashing2020-04-19 | In this video, we patch a Game Boy ROM using Ghidra!
You can also find me on Twitter: twitter.com/ghidraninjaReversing WannaCry Part 3 - The encryption componentstacksmashing2020-04-11 | In this video we take a quick look at the encryption component of WannaCry! We also check out how the 'decrypt' functionality of the WannaDecryptor probably is implemented.
Twitter: twitter.com/ghidraninjaHacking the Game Boy cartridge protectionstacksmashing2020-03-28 | In this video we hack the GameBoy cartridge protection by building our own GameBoy cartridge using an FPGA!
- ModernVintageGame on the CIC chips: youtube.com/watch?v=x8PYE8A-WEw - The Gbdev wiki: https://gbdev.gg8.se/wiki/articles/Main_Page
Equipment used in the video: - FPGA Board: Digilent Arty 7 - Level shifters: TXS0108E - A GameBoy...
Errata: - I messed up the resolution - the logo is 48px by 8px, not 96px by 16px!
You can also find me on Twitter: twitter.com/ghidraninjaBare-metal ARM firmware reverse engineering with Ghidra and SVD-Loaderstacksmashing2020-02-27 | In this video we look at reverse engineering a bare metal ARM firmware using Ghidra and SVD-Loader!
More resources: - Pull-Ups & Pull-Downs: youtube.com/watch?v=BxA7qwmY9mg - STM32 GPIOs: youtube.com/watch?v=jZ6J8oITgK8Reversing WannaCry Part 2 - Diving into the malware with #Ghidrastacksmashing2020-02-02 | In the second video of the "Reversing WannaCry" series we continue to dive into the malware and find some encrypted components and the first traces of the decryption & encryption functionality of the ransomware. We also learn how to use OOAnalyzer to easily reverse engineer C++ code in Ghidra!
Links: - OOAnalyzer: https://insights.sei.cmu.edu/sei_blog/2019/07/using-ooanalyzer-to-reverse-engineer-object-oriented-code-with-ghidra.html - My Ghidra Scripts: github.com/ghidraninja/ghidra_scriptsCVE-2020-0601 aka Curveball: A technical look inside the critical Microsoft CryptoAPI vulnerabilitystacksmashing2020-01-17 | On Tueday, a critical vulnerability in Microsoft's CryptoAPI was patched - it can allow an attacker to generate a CA that is considered trusted by the system, allowing attacks on TLS, code signing and co.
In this video, we look at how exactly that vulnerably works, and how we can attack it using Oliver Lyak's proof-of-concept!
In this first video of the "Reversing WannaCry" series we will look at the infamous killswitch and the installation and unpacking procedure of WannaCry.