[00:00.000 --> 00:06.860] It's time for Low-Level Firmware Analysis and Hacking with John Maushammer, number 67. [00:19.690 --> 00:20.170] Hello. [00:20.170 --> 00:21.330] It's a little early for me. [00:21.470 --> 00:24.430] I flew in from Denver, so it's two hours earlier. [00:27.050 --> 00:29.570] I'm going to need this... I'm sorry. [00:29.750 --> 00:31.330] I'm going to need this in front of me so I can see it. [00:43.710 --> 00:44.270] Okay. [00:44.670 --> 00:45.050] Now I'm sorry. [00:48.190 --> 00:49.050] Introduce myself. [00:49.190 --> 00:50.130] My name is John Maushammer. [00:50.370 --> 00:51.590] I'm also known as Morchiba. [00:53.970 --> 00:55.870] Like many of you, hacker. [00:56.610 --> 01:04.350] My specialty recently has been the CVS camcorder and the one-time-use disposable camcorders and still cameras. [01:04.610 --> 01:15.350] And I've gone and disassembled the firmware and then figured out how they work and then gone and kind of altered them so that I can just connect them up to a normal computer and then get my pictures. [01:16.370 --> 01:18.730] So, my background is electrical engineering. [01:20.070 --> 01:22.810] But the biggest part... biggest factors... [01:22.810 --> 01:25.970] I have too much time on my hands, so that's why I've been hacking so much recently. [01:28.250 --> 01:34.050] So, for those of you not familiar with the cameras that I've played with, here's a quick history of them. [01:35.650 --> 01:40.810] They're all made by a company named Pure Digital out in San Francisco. [01:42.970 --> 01:46.910] And they make three still cameras and one camcorder. [01:47.990 --> 01:50.530] They've gone through different variations, different models. [01:52.450 --> 01:53.590] They're still in business. [01:53.730 --> 01:55.010] They're still getting a lot of venture capital. [01:55.210 --> 01:58.910] So, I'm not sure if they're profitable yet, but we'll see how long they last. [02:00.970 --> 02:09.190] Their basic business model for all the cameras is that you buy the camera, you take your pictures or your video, and then you return it for development. [02:09.650 --> 02:14.170] And then you get back your prints or either a CD or DVD of your video. [02:15.450 --> 02:16.470] It's pretty simple. [02:16.750 --> 02:17.830] It's just kind of expensive. [02:23.400 --> 02:24.880] So, I have to take a break here. [02:25.340 --> 02:26.560] There's a little setup problem. [02:26.560 --> 02:31.990] I've got... my notes are not showing for some reason. [02:33.400 --> 02:34.320] Oh, I know. [02:35.740 --> 02:36.340] Sorry. [02:36.520 --> 02:38.550] Again, another display problem. [02:42.550 --> 02:43.330] There we go. [02:43.490 --> 02:43.590] Okay. [02:44.450 --> 02:45.710] This is the first camera. [02:47.490 --> 02:49.830] First generation was released in 2003. [02:50.670 --> 02:52.830] It has... it's a very basic camera. [02:52.970 --> 02:57.710] It's got just 25 pictures, 1.2 megapixels, not even cutting edge for 2003. [02:58.730 --> 02:59.890] But it's cheap. [03:00.210 --> 03:01.250] It's $18. [03:02.050 --> 03:04.650] And if you lose it, you drop it, you break it, it's all okay. [03:05.250 --> 03:06.230] You're not out of much money. [03:07.990 --> 03:11.230] The lock-in that they have is that the memory is not expandable. [03:11.330 --> 03:12.930] There's no slot, nothing. [03:13.110 --> 03:18.310] It's just a built-in memory chip soldered directly onto the PC board. [03:19.150 --> 03:22.950] So, to get to that memory chip, you have to go through their hardware and their firmware. [03:22.950 --> 03:24.650] And that's how they lock you in. [03:28.750 --> 03:31.930] The next version of the camera came out a couple years later. [03:32.530 --> 03:33.870] I guess maybe a year later. [03:35.010 --> 03:36.230] Much, much cheaper to produce. [03:36.350 --> 03:40.790] The first one was clearly a prototype that they... they pushed into production. [03:40.990 --> 03:42.970] This one has a much cheaper case. [03:43.170 --> 03:44.270] It's a lot easier to recycle. [03:45.170 --> 03:47.950] But basically, it's got the same specs. [03:48.190 --> 03:50.190] It's 25 pictures, 1.1 megapixels. [03:50.550 --> 03:53.230] Totally different processor, chipset, everything. [03:53.850 --> 03:57.050] Required a lot of reverse engineering, again, because we were starting from scratch. [03:57.310 --> 03:59.470] Because everything was different. [03:59.630 --> 04:00.270] I mean, everything. [04:02.570 --> 04:06.170] So, the big feature of this camera is that it has a picture preview. [04:06.710 --> 04:08.050] It has an LCD screen. [04:08.470 --> 04:09.770] And they bumped up the price a little bit. [04:09.890 --> 04:10.250] It's $18. [04:12.330 --> 04:13.490] Actually, the other one was $11. [04:14.330 --> 04:17.130] And you can see the pictures that you've taken. [04:17.270 --> 04:20.370] You can use the screen. [04:20.690 --> 04:22.810] Oh, actually, on this one, I'm not sure if you can. [04:23.050 --> 04:24.130] Use the screen as a preview. [04:26.290 --> 04:28.110] And then, if you don't like a picture, you can delete it. [04:28.210 --> 04:30.190] And there's a big old delete button at the bottom there. [04:33.600 --> 04:38.740] And then, most recently, last year, they came out with a third generation, which is their first camcorder. [04:39.660 --> 04:44.340] And it's basically a... not a camcorder in the traditional sense. [04:44.460 --> 04:47.700] It's more like a still camera that takes videos. [04:47.960 --> 04:50.280] It just has that video option enabled. [04:51.780 --> 04:55.120] So, it's got built-in memory, enough for 20 minutes. [04:55.500 --> 05:00.640] It takes the video at a quarter resolution, quarter VGA, 30 frames per second. [05:00.640 --> 05:02.680] It's got an MPEG-4 decoder. [05:02.900 --> 05:03.940] So, it's no lightweight. [05:04.300 --> 05:05.700] It's pretty nice. [05:07.680 --> 05:08.740] Just 20 minutes. [05:08.880 --> 05:12.820] And then, you've still got the whole pricing model that Pure Digital has. [05:14.760 --> 05:15.280] Until... [05:17.140 --> 05:22.740] And this is one of the features that they've got that kind of challenges people. [05:23.240 --> 05:29.140] There's a sticker on it, and it says, explicitly, cannot be connected to a TV or a computer. [05:29.580 --> 05:33.380] And so, that's just a challenge to me and others that it's got to happen. [05:36.040 --> 05:38.680] So, one of the questions is, why hack it? [05:38.980 --> 05:43.500] And I'm sure this audience would have no problem with that. [05:43.640 --> 05:44.880] No, it's there. [05:45.040 --> 05:45.800] That's a good enough reason. [05:46.800 --> 05:47.980] But other people ask that. [05:48.560 --> 05:51.120] And the first one, obviously, is cheaper pictures. [05:52.900 --> 05:55.820] Just, you bought a camera, you'd like to take full use of it. [05:57.140 --> 05:59.420] Another one is, use it in dangerous places. [05:59.680 --> 06:06.760] There's a lot of people that I've gotten feedback from that have bought these cameras and give them to preschoolers, kids that easily destroy them. [06:08.320 --> 06:09.020] Dangerous places. [06:10.440 --> 06:16.740] And then, another reason is, is that camcorder version that they sell is the lightest camera on the market that I've ever seen. [06:16.980 --> 06:19.600] I think it's 21 grams, the weight of a soul. [06:21.400 --> 06:23.080] It's just a tiny, tiny thing. [06:23.180 --> 06:24.460] It's a PC board and a lens. [06:24.640 --> 06:26.220] It's super tiny. [06:26.580 --> 06:27.660] Just nothing at all. [06:27.760 --> 06:28.060] No weight. [06:29.200 --> 06:32.120] So, you can put it in places where light weight is important. [06:32.380 --> 06:33.960] And I've got an example of that coming up. [06:35.900 --> 06:37.920] And then, of course, you can always make it do new things. [06:37.920 --> 06:40.580] And I've got some of those examples coming up later, too. [06:40.760 --> 06:47.640] Things that it was never meant to do, not just from being hacked, but it was originally a camera. [06:47.740 --> 06:49.680] You can make it do other things other than being a camera. [06:53.980 --> 06:59.660] So, and then, of course, the biggest reason is that they said it couldn't be connected to computers. [07:02.640 --> 07:03.420] So, let's start. [07:06.060 --> 07:10.620] The first, before I even disassembled it, the first thing I played was the buttons. [07:11.640 --> 07:14.000] The three-finger salute is what we kind of named it. [07:14.200 --> 07:20.420] It's holding the record button and the delete button while turning it on. [07:21.360 --> 07:23.900] And when you do that, it'll come up in a special mode. [07:24.520 --> 07:27.940] And it'll tell you some more information about it that you normally wouldn't see. [07:28.200 --> 07:35.020] It's the firmware version, the serial number of the camera, and for some reason it's got the revision of the PC board, which... [07:35.020 --> 07:35.980] Okay, fine. [07:37.100 --> 07:43.740] I guess there's some versions of firmware that don't work on certain versions of the PC board, but we haven't really figured out what the differences are. [07:44.240 --> 07:44.600] Meh. [07:46.560 --> 07:48.420] So, opening the cover is pretty straightforward. [07:50.240 --> 07:56.000] Cleverly hidden underneath the big sticker on the back are four screws, and just a normal screwdriver, a little prying. [07:57.460 --> 07:59.940] And underneath you'll see the main PC board. [08:00.380 --> 08:06.280] That's the screen in the middle layer, LCD screen, and the buttons are those four metal things down the bottom. [08:06.700 --> 08:13.660] And there's a microphone on the other side, but at the bottom is a speaker for playback of your videos. [08:19.160 --> 08:24.940] And so, let's see, up at the top here, we've got the special secret connector that they've got. [08:24.940 --> 08:26.040] It's a really cheap connector. [08:26.260 --> 08:27.660] It's not made to be used that often. [08:29.880 --> 08:32.860] It's built into the PC board, so it costs them nothing to make. [08:33.240 --> 08:36.280] All the cost is in their reader, so it just minimizes cost for them. [08:39.650 --> 08:41.990] The lens and the sensor is on another little board. [08:42.110 --> 08:43.770] It connects with a little connector in the back. [08:45.290 --> 08:46.070] Fairly standard. [08:47.050 --> 08:48.170] There's the main processor. [08:48.450 --> 08:50.130] It's a BGA package. [08:50.130 --> 08:51.490] It's a MIPS processor. [08:53.150 --> 08:56.110] You can tell because it's the big package on the board. [08:57.790 --> 09:02.370] And then we've got some graphic SD RAM memory, which is a special type of SD RAM memory. [09:02.670 --> 09:07.990] And it's got some extra modes so that it's used better for streaming. [09:08.610 --> 09:10.150] And you can look up that part number. [09:11.150 --> 09:12.930] Same with the memory chip down here. [09:13.090 --> 09:15.310] It's a flash memory chip, 128 megabytes. [09:15.850 --> 09:16.690] Pretty standard. [09:27.120 --> 09:30.080] So the secret 10 pin connector is up there at the top. [09:31.640 --> 09:33.280] How do we know what each pin does? [09:33.560 --> 09:35.440] It's 10 pins are unlabeled. [09:35.560 --> 09:37.180] They're supposed to be secret. [09:37.620 --> 09:40.540] So it sounds kind of like a first stumbling block. [09:41.640 --> 09:43.280] And there's a couple tricks to the trade. [09:45.700 --> 09:55.420] One trick is that for determining which pin is the ground pin, if you see the metal around the outside of the edge of the board, it's all gold there. [09:56.360 --> 09:57.880] That's usually an indication of ground. [09:58.100 --> 10:02.140] And if it connects to a screw hole, that's an even better indication of ground. [10:06.040 --> 10:08.320] So right there is the ground. [10:14.320 --> 10:16.060] And then also we can use a multimeter. [10:17.200 --> 10:18.260] Doesn't have to be this fancy. [10:18.480 --> 10:21.280] To go and test to see which pins actually physically connect to them. [10:21.400 --> 10:23.660] Because they can connect through the board, through the backside. [10:24.540 --> 10:26.840] So once you identify a ground, you can figure out all the ground pins. [10:27.080 --> 10:28.300] And same with the power pins too. [10:28.480 --> 10:34.960] If you have a chip that you've identified, and the documentation labels which pins the power pin, you can connect it and see if it buzzes. [10:35.720 --> 10:37.480] And then you'll need the power pin. [10:40.060 --> 10:41.160] There's another way too. [10:41.940 --> 10:43.380] Just by looking at the connector. [10:43.680 --> 10:47.360] They see if some of the pins, three of those pins there are taller than the others. [10:47.840 --> 10:50.140] That's an indication that it's a power ground. [10:51.080 --> 10:55.960] When the connectors connect, those are the first pins to touch the connector. [10:57.140 --> 10:58.660] The first pins to mate. [11:00.000 --> 11:01.800] And that's usually done for static. [11:02.800 --> 11:03.920] The grounds are connected. [11:03.920 --> 11:07.320] That way you don't get a high voltage static spike on the data lines. [11:07.440 --> 11:07.920] It protects them. [11:15.320 --> 11:16.280] See there, yeah. [11:17.620 --> 11:20.940] Another indication is that there's extra metal on those pins. [11:21.280 --> 11:24.620] And PC board designers think that there's going to be tons of current. [11:24.820 --> 11:26.260] In truth, it's all overkill. [11:26.260 --> 11:28.600] You could get away with the thinnest piece of wire. [11:28.920 --> 11:38.180] But it's like this pin furthest on your right has got a whole bunch of metal at the left and right of it. [11:38.920 --> 11:42.240] And those traces not only are on the sides of the connector, they continue through the board. [11:42.240 --> 11:43.780] You can trace those. [11:46.140 --> 11:47.300] Oh, also... sorry. [11:51.210 --> 11:52.130] Go back a little bit. [11:52.530 --> 11:54.270] Also, um... [11:55.890 --> 11:58.610] Vias are the little holes that you see drilled in the middle. [11:59.270 --> 12:01.070] Kind of by the C40 over there. [12:01.870 --> 12:02.830] To slightly to the right. [12:03.470 --> 12:04.470] Fourth pin from the right. [12:04.930 --> 12:10.210] Those vias are holes that go and connect through to inner layers of the PC board or the other side of the PC board. [12:10.210 --> 12:12.590] They're holes drilled and then they're plated with copper. [12:13.470 --> 12:17.030] And if you see a lot of those on a pin, usually there's only one per wire. [12:17.230 --> 12:20.510] But if you see a lot, it's designed to carry more current. [12:20.970 --> 12:24.070] Still overkill, but people do it so you can figure out what it is. [12:25.590 --> 12:27.210] The data pins are a little trickier. [12:27.870 --> 12:29.390] We got pretty lucky with this camera. [12:31.630 --> 12:34.030] They connect last, so they're a little further down. [12:34.850 --> 12:36.230] They're often thinner traces. [12:37.790 --> 12:43.070] You can't see it on this board, but there's two vias at the bottom and the wiring on the backside is just thinner. [12:43.690 --> 12:44.870] It's just normal width. [12:46.510 --> 12:48.230] And then often the data pins are symmetric. [12:48.430 --> 12:54.870] They'll either be in pairs or if it's a bus, you'll see them all routed in a kind of a lanes. [12:56.130 --> 12:57.370] So it's just a visual clue. [12:59.470 --> 13:05.090] There's the vias that I was talking about and you can see how that whole connector is totally symmetric. [13:05.090 --> 13:07.230] It's just... [13:08.800 --> 13:15.620] And then since this is the third generation of the camera, we've got some unused pins. [13:15.800 --> 13:18.560] And these pins used to be used on previous generations of the camera. [13:18.680 --> 13:21.140] But if you look carefully, you can just see they don't go anywhere. [13:21.280 --> 13:22.440] They're just there. [13:26.610 --> 13:30.150] So actually, I didn't do the reverse engineering of this connector. [13:30.450 --> 13:32.850] Someone else did before I got started in the project. [13:33.390 --> 13:35.310] But they guessed a USB connection. [13:35.870 --> 13:36.950] And it makes sense. [13:37.150 --> 13:38.330] It's a popular interface. [13:38.710 --> 13:41.710] It's supported by tons of consumer electronics. [13:41.850 --> 13:42.610] Why change it? [13:42.730 --> 13:43.650] I mean, it's already in there. [13:45.130 --> 13:46.870] If they were to change it, it would cost them money. [13:46.990 --> 13:49.270] And the whole point of this camera is to be cheap. [13:50.810 --> 13:55.550] This is also, just for people keeping track, this is the lamest slide in the whole presentation. [13:55.550 --> 13:58.090] So, everything else would be more exciting. [13:59.470 --> 14:00.310] Couldn't jazz it up. [14:01.670 --> 14:04.150] So, a USB connector has four pins. [14:05.330 --> 14:06.710] Ground, a five-volt supply. [14:06.850 --> 14:09.490] So, when you plug in your keyboard, that's where the power is coming from. [14:10.650 --> 14:12.650] And then a data plus and a data minus. [14:12.970 --> 14:17.850] It's complicated, but they're a differential line. [14:18.150 --> 14:19.110] They work in a pair. [14:19.830 --> 14:24.210] And as you can see here, the ground and the power are pins that stick out a little further. [14:24.210 --> 14:28.870] So, they connect first so that they don't cause damage with the ESD. [14:29.890 --> 14:32.070] Same principle as on the secret connector. [14:33.670 --> 14:37.230] So, the final pinout that we figured out was that there's a couple grounds. [14:38.290 --> 14:39.410] Data plus, data minus. [14:39.690 --> 14:45.810] You can wire it up and if you get it backwards and you try and hook it up to a Windows machine, it'll say there's a communication error. [14:46.070 --> 14:47.130] It doesn't do any damage. [14:47.370 --> 14:48.950] It just says communication error. [14:49.090 --> 14:53.230] You can change it back and you know you had it backwards and now you've got the right answer. [14:54.970 --> 14:57.290] And then there's a battery connection. [14:57.490 --> 14:59.990] We traced with a multimeter back to the battery. [15:00.530 --> 15:01.970] And that way they can check the state of the battery. [15:04.070 --> 15:05.810] I think they'd be able to recharge the battery. [15:05.950 --> 15:06.830] Some people have done that. [15:07.110 --> 15:14.590] But they basically check it to make sure it's a good battery so that before they recycle it, they can replace it if they need to, if it's going to die. [15:17.310 --> 15:19.510] So we've got the cable, it's hacked, right? [15:19.870 --> 15:21.690] It doesn't sound too complicated. [15:23.370 --> 15:27.110] Well, it's recognized by the computer, but there still needs drivers. [15:27.510 --> 15:28.830] This is all my computer said. [15:28.970 --> 15:33.450] It just said Saturn, which is our code name for the whole camera, the camcorder. [15:35.410 --> 15:54.550] One of the hacks, one of the easier hacks was that you could go through and find a known driver by doing the research on the chips inside the camera and see if you can take that known driver, change the vendor ID and the product ID that it has to the number that the camera gives you. [15:54.550 --> 15:58.470] And then that driver should automatically work with that camera. [15:58.830 --> 16:01.750] And in this case, we tried that, it didn't work. [16:01.890 --> 16:04.970] There's a locking mechanism in there that prevents it working with normal drivers. [16:06.610 --> 16:08.510] So we're back to square one. [16:09.310 --> 16:10.010] Not quite. [16:11.170 --> 16:13.670] We have to do another level of analysis. [16:16.470 --> 16:17.930] So we're going to go back to the hardware. [16:18.390 --> 16:20.370] And if you notice, there's a lot of chips. [16:20.550 --> 16:27.330] And one of the points of this whole project was for the pure digital domain, manufacturers, was to minimize the cost. [16:27.550 --> 16:31.510] And there's so many components on this, you wonder how it can be so cheap. [16:34.010 --> 16:34.490] $30. [16:35.630 --> 16:39.710] The key is that each chip on there is produced with a different technology. [16:39.950 --> 16:43.610] There's flash chips, memory chips, processor chips. [16:43.830 --> 16:52.530] They're all so dense that they tweak the parameters when they're making the chips so that they'll work the best for that type of thing. [16:52.530 --> 16:58.710] So for a flash memory, it's got a grid of transistors and stuff. [16:59.050 --> 17:02.010] And they optimize it so it works with that grid. [17:02.090 --> 17:06.490] But it would be really lousy if the shape that you were trying to make was not a grid. [17:07.630 --> 17:12.910] So it's actually cheaper to make different chips in different packages, different die. [17:13.810 --> 17:20.330] That helps us a whole lot because, as you can see, the memory chips have part numbers on them. [17:20.490 --> 17:31.210] And it also helps the camera manufacturer because they can buy it in bulk, compete on the market with the other memory chip manufacturers. [17:43.280 --> 17:47.000] So if we go to the websites and look up these parts, we get the whole data sheet. [17:47.140 --> 17:50.620] It tells us everything you could possibly want to know about the chip. [17:50.760 --> 17:55.540] I mean, there's tons of users of these chips and they need to know this information. [17:55.540 --> 17:56.400] So it's all out there. [17:56.520 --> 17:58.740] And there's a standards organization that has the same stuff. [17:59.080 --> 17:59.960] So they're all interoperable. [18:00.980 --> 18:04.120] It's all the best documented part of the whole camera. [18:07.730 --> 18:11.930] But then when you get to the processor, it's kind of secretive. [18:14.750 --> 18:18.510] This is a company called Zoran in, I think it's San Diego. [18:20.050 --> 18:28.070] And they make processor chips for a whole bunch of cameras, just sold under a ton of different brand names, Fuji, a bunch of them. [18:29.070 --> 18:34.010] They're very high volume, but interestingly enough, they have very few customers. [18:34.390 --> 18:36.450] And those customers are the people who make the cameras. [18:36.830 --> 18:39.950] So they prefer to deal with those people only. [18:41.110 --> 18:47.030] Another thing is that this camera has... part of it's the microprocessor, part of it's the software. [18:47.290 --> 18:49.330] And they're very tightly interleaved. [18:49.510 --> 18:56.670] There's functions you could do in the processor or in the software, and they've partitioned that mix of how and where things get done. [18:56.670 --> 18:59.690] So their software is an integral component. [19:00.890 --> 19:03.590] And they're fairly protective of it. [19:03.850 --> 19:07.070] So they've got non-disclosure agreements. [19:07.810 --> 19:12.810] They're not going to let normal people really get into the software or the data sheets. [19:16.710 --> 19:18.930] So translation is we're boned. [19:18.930 --> 19:20.830] It's going to be hard still. [19:23.490 --> 19:24.510] But carry on. [19:24.810 --> 19:25.950] We've got the flash memory chips. [19:26.470 --> 19:30.910] If you look up in the flash memory data sheet, it shows you the pin out. [19:31.050 --> 19:34.890] It shows you what every single one of those 48 pins does on that package. [19:36.810 --> 19:39.910] And if you look closely, you can see about half of them are no connects. [19:40.870 --> 19:42.270] That helps us with soldering. [19:42.690 --> 19:44.050] We don't have to solder those. [19:45.150 --> 19:50.990] It's such a big chip that they have to put it in a big package even if it doesn't have a lot of wires going to it. [19:54.210 --> 19:57.190] So if you go and look in the data sheet, it tells us which pins are there. [19:57.990 --> 20:05.490] It tells us what the exact order is that we have to go in and what commands to give it. [20:05.490 --> 20:06.970] So we'll start on the left there. [20:07.730 --> 20:12.150] We'll lower the chip enabled to tell it we want to start talking to it. [20:12.730 --> 20:13.410] Toggle the rights. [20:13.970 --> 20:16.190] Give it a command to start reading. [20:16.470 --> 20:18.550] Give it an address we want to read and we'll get our data back. [20:20.090 --> 20:22.830] And you could do that actually with wires and lights. [20:23.390 --> 20:26.250] It would be very painful, but it's possible. [20:27.730 --> 20:34.130] But a much better way is either you work at a company that has one of these readers, which I don't, or you build your own. [20:34.130 --> 20:36.390] And it's not that difficult to build your own. [20:37.630 --> 20:39.830] This is a product that I got a while ago. [20:40.290 --> 20:43.890] It's really handy ever since the parallel port disappeared on computers. [20:44.190 --> 20:45.570] It's a USB I/O. [20:46.230 --> 20:49.930] And basically it gives you 24 pins to play with under computer control. [20:50.130 --> 20:52.030] You can set them high, set them low. [20:52.130 --> 20:52.750] You can read them. [20:52.990 --> 20:55.710] You can talk to all sorts of things with this. [21:00.590 --> 21:03.510] So the main board is in the background there. [21:03.510 --> 21:08.150] And I got an adapter board and made a little wiring harness to connect up the two. [21:08.810 --> 21:12.630] And desoldered the chip from the camcorder and soldered it on the top there. [21:15.470 --> 21:17.690] And the reader program is fairly simple. [21:19.430 --> 21:22.650] The instructions for the board tell you how to raise and lower the pins. [21:24.050 --> 21:25.630] And basically I just go through it. [21:28.710 --> 21:32.910] Each command goes through, corresponds to something on the data sheet. [21:33.070 --> 21:34.850] So just follow the data sheet as a guide. [21:35.690 --> 21:37.470] And of course I got my software on the web too. [21:37.630 --> 21:40.210] So if anyone wants to look at that, it's pretty simple. [21:43.570 --> 21:47.350] Another interface that people have used is the smart media interface. [21:47.570 --> 21:59.170] Turns out that that chip, just for reasons of homogenization, just to make it compatible. [21:59.170 --> 22:03.630] So they have fewer versions of flash, high density flash memory chips out there. [22:03.630 --> 22:08.450] It's the same exact electrical interface as a smart media card. [22:08.610 --> 22:10.150] Even though the package is obviously really different. [22:11.010 --> 22:14.250] So people have figured out what the wiring correspondence is between those two. [22:14.910 --> 22:21.510] And they've gotten just a generic smart media reader from RadioShack and rewired it. [22:21.770 --> 22:23.570] And been able to read out all the data in the chip. [22:26.470 --> 22:30.710] So once we do that, we've got 128 megabytes of just numbers. [22:30.710 --> 22:32.150] And it's kind of intimidating. [22:32.410 --> 22:33.830] It doesn't look at it. [22:33.930 --> 22:35.350] It's just this huge data file. [22:35.590 --> 22:38.330] There's no, like, no way to edit it. [22:40.590 --> 22:44.170] So the first thing to do is just to start searching for interesting stuff. [22:45.630 --> 22:53.690] And I found ELF, which people might recognize as a executable format, which is kind of interesting. [22:53.890 --> 22:54.430] That's nice. [22:54.610 --> 22:55.270] That's a good signal. [22:57.290 --> 22:59.210] Also, FAT12 we found in there. [23:01.730 --> 23:02.210] FAT16. [23:03.750 --> 23:04.730] A bunch of stuff. [23:07.730 --> 23:13.310] So some of those markers, the FAT12, FAT16, and ELF, I figured out where they were in memory. [23:14.090 --> 23:19.510] And luckily for each of those formats, the FAT or the ELF is at the beginning of the file. [23:19.990 --> 23:28.270] And so that kind of allowed us to divvy up the whole memory so we know which area of memory is used for what purpose. [23:28.770 --> 23:30.370] And it's pretty much like a hard drive. [23:30.510 --> 23:31.370] It's just partitioned. [23:31.970 --> 23:34.750] And there's a special area in the beginning that's the firmware. [23:36.990 --> 23:42.830] And since it's just like a hard drive and it's partitioned, you can go in and use DD, which is a UNIX file. [23:43.250 --> 23:54.150] UNIX program that will go and split up the file into sections and get ISO files and just mount them on a Mac or Linux or whatever. [23:56.050 --> 23:59.230] Any guesses what's in that big no name section there? [24:02.610 --> 24:04.010] We got video files. [24:05.990 --> 24:08.170] So that was a very painful hack. [24:09.150 --> 24:10.510] Had to take off the memory chip. [24:11.110 --> 24:16.490] But it also allowed us to figure out that the AVI files were standard AVI files. [24:17.550 --> 24:18.290] No encryption. [24:18.650 --> 24:22.690] Just plain old sitting there exactly like on a regular digital camcorder. [24:24.350 --> 24:30.430] So it's kind of a proof of concept, but it's still not a good hack because it's just painful. [24:31.090 --> 24:36.050] But while we're in there, we can go and start exploring the other sections of memory, other partitions. [24:37.090 --> 24:38.990] And there's a bunch of resource folders. [24:40.410 --> 24:51.870] They have different things like all the video images that are used at different processes in the operation of the camera, like turning on and turning off, different messages that just encoded as bitmaps. [24:54.170 --> 25:01.770] We also found some production line test software in there, which is kind of interesting because I have no idea how it's... [25:02.390 --> 25:06.150] If there's a special key sequence you use to bring it up, but it's in there. [25:06.310 --> 25:07.650] So it's still available. [25:07.850 --> 25:10.870] It's an avenue that we can eventually hack later if anyone's interested in it. [25:11.950 --> 25:17.310] They've got the color chart and they've got a gray chart, which is complicated. [25:18.710 --> 25:20.550] It's obviously used for some calibration. [25:21.810 --> 25:27.790] Interestingly, if you zoom in, it's the Macbeth color chart and copyrighted. [25:28.070 --> 25:31.130] And I'm sure they've paid for that license, but yeah. [25:33.790 --> 25:45.610] Also, if you noticed when we brought up with the three-finger salute to bring up the firmware version and the serial number, it kind of looked like MS Comics, that font. [25:48.890 --> 25:52.330] And so there's a file named comic.bin in there. [25:53.150 --> 25:55.350] And we want to see if it's the real thing. [25:55.550 --> 26:02.250] If you look at the beginning of it, it says Comic Sans MS, which is a pretty good indication that it's a derivative of the Microsoft version. [26:04.110 --> 26:11.930] Interestingly, the Microsoft version doesn't allow you to use it in commercial products or modify the format from the true type. [26:12.230 --> 26:14.390] So I'm sure they license that too. [26:18.510 --> 26:23.610] And then also there's another file in here called stat file. [26:23.830 --> 26:27.370] And this is kind of a feature that surprised me. [26:28.230 --> 26:33.570] Every video that's recorded, every time you turn on and off the power, it records that in this file. [26:33.890 --> 26:41.210] So there's a date and time, video length, frames per second, a number of bytes of the file, a mystery number 42. [26:44.630 --> 26:47.510] And so the date and time, there's no clock. [26:48.030 --> 26:50.350] Just by using it, you can't tell that there's a clock in there. [26:50.470 --> 26:53.690] But my clock was set correctly for some time zone. [26:53.690 --> 26:58.850] And just kind of a hidden feature that's Georgia Orwell. [27:03.510 --> 27:05.350] And then there's a bunch of other files too. [27:05.590 --> 27:12.950] They've got one resource, one partition that they use for all their customization, individual customization. [27:13.390 --> 27:15.210] So it's got the serial number of the camera. [27:15.570 --> 27:17.810] Each camera has a custom unlock code. [27:17.810 --> 27:21.790] And there's also a default unlock code. [27:22.250 --> 27:26.150] And it also has the parameters like the recording resolution and the time limit. [27:26.390 --> 27:27.770] There's a 20 minute time limit. [27:28.110 --> 27:37.650] Even if you record a video that's a really low bit rate, because it's just a wall that's not moving, they'll still time you out at 20 minutes or 25 minutes or so. [27:38.570 --> 27:39.850] Even though the memory is not full. [27:42.430 --> 27:45.410] So that kind of leaves that first partition, the firmware. [27:46.410 --> 27:47.770] Which is the most fun for me. [27:49.090 --> 27:51.730] My specialty is embedded in engineering. [27:52.010 --> 27:54.150] So I deal with this professionally a lot. [27:54.370 --> 27:56.950] But I also dealt with it in high school and college. [27:57.190 --> 27:59.350] So it's not that complicated. [27:59.710 --> 28:01.070] It just takes a lot of diligence. [28:02.950 --> 28:05.030] So the three cameras are all very different. [28:06.770 --> 28:11.230] The first one, the simplest one without the display, 60 KB of code. [28:11.750 --> 28:15.510] The one with the still camera with the display, 124. [28:15.790 --> 28:18.730] And then the camcorder just blows it out massively. [28:19.030 --> 28:20.730] It's 1.2 megs. [28:22.810 --> 28:24.090] It has to do more. [28:24.270 --> 28:28.290] It also has the MPEG 4 compression and MPEG 4 playback in there. [28:28.510 --> 28:30.250] So it's doing more. [28:30.250 --> 28:31.770] The other ones do more stuff in hardware. [28:32.030 --> 28:33.410] So it doesn't have to do it in the software. [28:35.830 --> 28:38.470] So we can start looking through that file. [28:38.810 --> 28:39.570] The firmware file. [28:40.630 --> 28:42.510] And strings is a popular UNIX utility. [28:43.710 --> 28:45.530] And you can find a whole bunch of junk. [28:46.950 --> 28:49.990] But if you keep looking through it, there's some interesting stuff in there. [28:50.970 --> 28:51.810] Defective pixels. [28:52.090 --> 28:54.390] Apparently they're doing some mapping of defective pixels. [28:55.290 --> 28:58.730] Masking those out so that you don't see a little bright spot every time you record something. [28:59.950 --> 29:01.170] Tons of other stuff in there. [29:02.330 --> 29:05.610] And some of this stuff is some very useful stuff. [29:07.510 --> 29:14.830] Even though the Zorian chipset on the website didn't say too much about what was actually what kind of processor was in there. [29:15.050 --> 29:16.210] It just said it was a blah, blah, blah. [29:17.050 --> 29:18.670] We can find out how... [29:20.130 --> 29:23.510] This is some text left over from the compiler. [29:23.770 --> 29:29.390] And it tells exactly what the compiler was and the operating system. [29:29.630 --> 29:34.610] And it also says that it is the LX4180, which is a MIPS processor. [29:34.890 --> 29:37.190] If you go look up that, then it's obviously... [29:37.190 --> 29:44.110] If it was good enough for the compiler to assume that the Zorian chip was a LX4180, then it's good enough for us to decompile with. [29:45.630 --> 29:48.570] So ThreadX is the embedded operating system in there. [29:49.150 --> 29:50.750] And then Green Hills makes their own compiler. [29:52.270 --> 29:54.390] Or they use GCC, something like that. [29:55.310 --> 29:56.910] But lots of information there. [29:59.190 --> 30:00.910] Strings also gets us some more information. [30:02.570 --> 30:03.090] UART monitor. [30:03.270 --> 30:04.990] UART is a fancy name for a serial port. [30:05.930 --> 30:12.210] And even though we don't see a serial port, and even testing out the secret 10 pin connector, I think it's on the chip. [30:12.390 --> 30:14.730] It's just not connected in a way that we can connect to. [30:14.810 --> 30:18.410] It's probably underneath the chip on a pin that we can't get to. [30:20.010 --> 30:24.430] But it kind of gives a hint that there's some secret debug features in there that's accessible some way. [30:27.890 --> 30:33.190] And then also, just a little part, I have no idea how they use this, but they had these things in there. [30:34.390 --> 30:39.970] It tells us the model number of the sensor and the model number of the LCD. [30:40.190 --> 30:42.010] Both of those are kind of information that was hard to get. [30:42.250 --> 30:44.770] The sensor wasn't marked because it was in a clear package. [30:45.190 --> 30:51.530] And the LCD was just, I think it was a Taiwanese manufacturer that didn't have good documentation. [30:55.190 --> 30:57.470] So just strings, very simple utility. [30:57.770 --> 31:00.790] We can get lots of data pretty easily. [31:03.390 --> 31:08.230] And then I know this is a pretty much technical audience, but I have a quick overview of how programs are made. [31:08.290 --> 31:14.890] And this is essential to figure out how to take that raw data, convert it back into something that's meaningful. [31:20.380 --> 31:26.580] So we start off with most of the stuff is written in C for embedded systems. [31:28.320 --> 31:31.280] Here's an example code that averages a whole bunch of numbers. [31:32.420 --> 31:34.580] And that's run through a compiler. [31:34.980 --> 31:37.880] It gives us the assembly language, and that looks something like this. [31:38.660 --> 31:44.120] And you can kind of tell maybe if you looked at the file closely, you could tell it was an averaging algorithm. [31:44.380 --> 31:45.920] You can see there's some addition in there. [31:46.220 --> 31:47.020] There's a loop. [31:47.440 --> 31:49.560] And then at the end, it's divided by ten. [31:51.160 --> 31:53.560] So there's an indication, but it's not obvious. [31:55.720 --> 32:06.840] And then after it's in the assembly language, it goes into an object file, which takes the functions and just kind of says that they're here. [32:06.840 --> 32:11.120] Here's the parameters that they use, but it doesn't give... [32:11.120 --> 32:12.720] It's reduced the raw numbers. [32:14.860 --> 32:16.640] So it's a little less information. [32:17.200 --> 32:21.540] And then finally, that information is stripped out, and we get into the object file. [32:21.720 --> 32:28.760] And in this case, it's a stripped ELF file, which means that they took out all the extra data, the strings that are useful in debugging, which also makes it smaller. [32:30.640 --> 32:35.620] And that's how we get the raw data that we find in the flash memory chip. [32:37.360 --> 32:40.780] So to disassemble it, we do the reverse process of this chart. [32:43.320 --> 32:45.920] I just picked these bytes totally at random. [32:48.480 --> 32:49.000] The... [32:50.500 --> 32:51.680] They're three hex... [32:51.680 --> 32:55.200] I'm sorry, four hex bytes makes up a 32-bit word for the MIPS instruction set. [32:55.720 --> 33:06.660] And with that instruction set, if you convert it to binary, and then look it up in their book, it tells you exactly what that instruction does. [33:07.720 --> 33:13.200] The binary is used because different fields will indicate which instruction is being done. [33:13.540 --> 33:16.820] Other ones are different values, like the immediate data value over there. [33:17.220 --> 33:20.660] And then the page in the MIPS manual is very descriptive. [33:20.820 --> 33:21.580] It tells you everything. [33:22.220 --> 33:22.740] It's... [33:22.740 --> 33:23.980] Even if... [33:23.980 --> 33:30.600] And this is a big step to learn assembly, but once you learn one assembly language, the other ones are... [33:30.600 --> 33:32.020] come easier and easier. [33:32.240 --> 33:37.580] It's still a challenge, but this documentation is so good for the MIPS. [33:38.540 --> 33:41.660] And most of the other things, you'll get through it eventually. [33:41.900 --> 33:42.420] It's just... [33:42.420 --> 33:43.420] It's kind of slow. [33:46.500 --> 33:47.880] So that's one instruction. [33:48.240 --> 33:51.200] And there's 300,000 more instructions like that in the camera. [33:52.980 --> 33:54.620] So we can automate the process. [33:56.000 --> 33:58.740] There's a number of disassemblers that you can use. [34:00.180 --> 34:04.420] There's a free one from GNU called OBJTools. [34:04.800 --> 34:09.300] It's the default installation on a lot of Linux and... [34:09.300 --> 34:10.530] Linux machines... [34:10.940 --> 34:11.400] Linux... [34:11.400 --> 34:12.840] I'm sorry, my pronunciation is not too good. [34:14.280 --> 34:14.800] The... [34:15.960 --> 34:19.860] And then there's also a commercial one that's used a lot in virus analysis. [34:21.020 --> 34:22.260] The commercial one... [34:22.260 --> 34:23.640] I have never used. [34:23.880 --> 34:25.000] It's apparently really good. [34:25.640 --> 34:30.840] It's $450 to $875, depending on what options you get. [34:31.640 --> 34:37.220] And then the support is $10,000 a year, which is kind of out of my budget for this project. [34:40.200 --> 34:42.180] And then there's a third option. [34:42.180 --> 34:44.080] You can always write your own. [34:44.320 --> 34:46.220] And that sounds pretty intimidating. [34:46.660 --> 34:49.560] But the disassembler is just a translator. [34:49.860 --> 34:50.920] It takes four bytes. [34:51.700 --> 34:52.980] It figures out some text. [34:53.760 --> 34:57.140] It's not as complicated as a lot of the programs. [34:57.820 --> 34:59.300] It could be written in a weekend. [35:00.740 --> 35:02.300] It's just a basic input output. [35:02.500 --> 35:05.980] There's not a lot of sophistication to it. [35:07.300 --> 35:12.460] You can also base your disassembler on other people's disassemblers. [35:13.160 --> 35:15.060] I did that for all my projects. [35:16.080 --> 35:20.580] And the cool thing about writing your own is that you can support any processor. [35:20.860 --> 35:27.400] And the digital camera with the viewfinder used a custom processor that had never been documented. [35:27.800 --> 35:29.240] And I'll show some more on that. [35:30.580 --> 35:32.960] But as a result, there were no disassemblers for it. [35:33.680 --> 35:35.700] So writing my own helped out. [35:35.860 --> 35:36.840] I mean, it was the only way to do it. [35:38.580 --> 35:42.300] And then the last thing is you can make the disassembler as smart as you need it to be. [35:42.300 --> 35:55.860] And if you go and you find a situation where you're looking at some code and you want to make it automatically comment, you can add that comment or make it do some thinking for you where it's repetitive. [35:57.140 --> 35:58.600] So I'll give an example here. [36:01.240 --> 36:04.440] Here's the initial output from OBJDump. [36:05.220 --> 36:08.120] And it's just text, numbers, stuff. [36:11.560 --> 36:17.940] One of the things I added onto it was to load a 32-bit number into a register, it takes two instructions. [36:18.260 --> 36:20.280] And one instruction loads half 16 bits. [36:20.400 --> 36:22.040] The other one loads the other 16 bits. [36:23.860 --> 36:26.320] And it's kind of non-intuitive when you look at it. [36:26.420 --> 36:28.620] You've got negative 31812. [36:28.680 --> 36:29.840] What's that number mean? [36:30.220 --> 36:38.000] So I made the disassembler kind of put those two instructions together and figure out what address it was. [36:39.260 --> 36:42.300] There's the math, the instructions that's taking place. [36:42.460 --> 36:47.940] And the address that those two instructions load is at the bottom, 801183BC. [36:49.460 --> 36:50.640] So we can put that in. [36:52.480 --> 36:56.560] Red's probably not the best color for this slide here, but it's in the middle there. [36:58.820 --> 37:01.380] And so we've got more information that wasn't there. [37:02.960 --> 37:07.680] Another step onto that is we don't know what that number means. [37:07.900 --> 37:09.360] It's just there. [37:10.500 --> 37:13.660] We can automatically look up in memory where that piece is. [37:13.840 --> 37:16.080] And in this case, we got lucky. [37:16.220 --> 37:18.800] It was part of the flash memory, which we had already taken out. [37:21.080 --> 37:23.300] And you can see that that points to the string. [37:23.520 --> 37:27.120] It's a C style string with a zero terminating at the end. [37:27.260 --> 37:28.460] And it says camera ID. [37:29.100 --> 37:31.320] And so we can make the disassembler smarter again. [37:31.960 --> 37:37.960] Have it automatically indicate when it finds a number whether it points to some interesting string. [37:39.360 --> 37:41.960] So that's what my disassembler now does. [37:42.900 --> 37:45.960] Show you camera ID whenever something's using that variable. [37:47.560 --> 37:50.080] And kind of think, where did we see that before? [37:50.800 --> 37:52.840] And that was in that three-finger salute. [37:53.260 --> 37:59.940] So right now we know that that code is using... is being used to generate this output. [38:00.360 --> 38:01.680] So that's pretty powerful. [38:01.840 --> 38:02.960] It was just a bunch of numbers. [38:03.420 --> 38:06.660] Now we've got... we can actually know when it's being called, what it does. [38:08.960 --> 38:11.900] And that's a specific example I kind of cherry picked. [38:12.120 --> 38:17.020] But it's... you start with that and then you can build on to finding out where... what it calls. [38:21.280 --> 38:21.860] Let's see. [38:22.060 --> 38:22.300] Yeah. [38:23.660 --> 38:27.980] Since we know that it draws text to the screen, we can put a comment in there that says draw text to the screen. [38:28.400 --> 38:30.120] For that sub-routine that it calls. [38:30.360 --> 38:34.380] And then make the disassembler automatically whenever anyone calls that routine. [38:35.700 --> 38:37.520] Put that comment in, draw text to the screen. [38:37.720 --> 38:39.500] So we can find other things that draw text to the screen. [38:40.920 --> 38:42.740] So it's all an incremental process. [38:43.220 --> 38:45.260] Just building this disassembler so that it's smarter. [38:45.540 --> 38:48.380] So that I don't have to do the work because there's way too much code to look at. [38:51.200 --> 38:52.760] And then you can kind of get lucky. [38:53.920 --> 38:57.880] I found some strings in there that were really interesting that looked like path names. [38:58.620 --> 39:01.960] Dev, camera, zcam, agents, comment, on command. [39:03.320 --> 39:05.440] And those are used as parameters. [39:05.800 --> 39:08.760] And typically this is used as a debug parameter. [39:10.420 --> 39:12.300] In this case, the function malloc. [39:12.500 --> 39:17.800] If it were to fail, it would print out this debug message on some debug console that we don't have access to. [39:18.540 --> 39:24.080] And it would tell you that line number 72 of function on command.c had a failure. [39:24.620 --> 39:28.900] And that way the person could go back to the source code, trace it, figure out what the problem is and fix it. [39:29.660 --> 39:30.800] But they left this in. [39:31.220 --> 39:35.460] And since it's kind of built into the library, it's not as easy for them to remove. [39:35.460 --> 39:37.420] And they could have removed it. [39:37.520 --> 39:38.380] It's just kind of an oversight. [39:38.580 --> 39:39.520] But it's lucky for us. [39:40.020 --> 39:48.200] And so looking at all those path names, we can find out that the firmware is made up from over 200 files, which is kind of neat. [39:48.440 --> 39:52.620] We've got some insight into how they build their whole program. [39:53.500 --> 39:55.960] And actually, I got all this from strings. [39:56.260 --> 40:01.820] I just did a search on C colon slash dev and got this list. [40:05.040 --> 40:13.140] Oh, and more importantly, that ties some code to a file, which kind of gives us an idea of what it's doing. [40:16.870 --> 40:24.370] So taking the analysis to another level, which is a lot, since it's using an operating system [40:27.470 --> 40:36.750] objects, like cues, memory buffers, all sorts of things like that. [40:37.070 --> 40:38.590] And some of them are labeled with text. [40:38.950 --> 40:46.510] And for example, this function here, USB cam command, is a parameter calling a function. [40:46.510 --> 40:55.510] And if we look up in the ThreadX manual, you can see it described in great detail again. [40:56.270 --> 40:59.070] The name of the command... let me bring it back down. [40:59.550 --> 41:03.430] The name of the command and what all the other parameters are. [41:04.750 --> 41:14.210] So that you can... you can see USB cam command is now associated with that variable 80143FB4 at the top. [41:15.050 --> 41:23.210] So whenever we use that variable, we can put a comment in again, automatically with the disassembler, that we're using that queue. [41:26.750 --> 41:29.230] So... turns out there's a lot of system objects. [41:30.690 --> 41:34.450] And some of them are named very obviously, so that you can tell what they are. [41:35.430 --> 41:41.330] These not so much, but there's a seven system level threads, just different things they can do. [41:41.910 --> 41:45.190] Browse server, which I assume is for looking at pictures. [41:45.710 --> 41:47.190] Agent server, I think, is a USB. [41:48.210 --> 41:50.250] Monitor could be a secret debug command. [41:52.910 --> 41:54.250] There were 11 timers. [41:54.910 --> 41:59.210] So when you press a button, there's probably a timer in there to see if you hold it down. [41:59.210 --> 42:02.130] For more than three seconds or different things. [42:02.430 --> 42:04.490] Video time or probably just the frame rates. [42:07.730 --> 42:09.150] There's 22 mutexes. [42:10.830 --> 42:14.710] And these are things that... and you can see one of them is FCU mutex. [42:14.810 --> 42:16.250] So that's how I knew that these were mutexes. [42:16.930 --> 42:18.910] They all call the same function with this text. [42:22.650 --> 42:25.850] And then beyond that, there were 34 cues. [42:26.810 --> 42:28.270] Still lots more information. [42:29.410 --> 42:30.430] Empty frames. [42:30.950 --> 42:32.390] Free buffer for display. [42:33.150 --> 42:34.970] All sorts of stuff that can... [42:34.970 --> 42:40.030] Not only is it just interesting to see how it's built, but again, it's tied back to pieces in the software. [42:40.370 --> 42:41.830] So we can see what it's doing. [42:43.310 --> 42:48.670] Then there were 64 transient threads, which just keeps getting bigger and bigger. [42:50.750 --> 42:54.530] Different things like a lot of these are features that aren't enabled in this camera. [42:54.690 --> 42:56.210] Like there's an open lens in there somewhere. [42:57.210 --> 43:03.470] Zoom commands that are... you say zoom in and it'll turn the motor on, wait a little bit of time, turn it off. [43:06.350 --> 43:13.390] And then lastly, there were 180 monitor commands, which if anyone remembers the old Apple II, you could type in things. [43:13.830 --> 43:14.730] It's kind of like a DOS prompt. [43:15.850 --> 43:16.970] Very low level though. [43:17.350 --> 43:19.430] It's common in a lot of embedded operating systems. [43:20.030 --> 43:24.190] And the cool thing about this is that not only were these commands in there, they had their parameters. [43:24.490 --> 43:27.690] They also had a help portion. [43:28.330 --> 43:30.290] And it described what each command did. [43:30.290 --> 43:35.850] So there's 180 commands, 180 places in the software where we know what it's going to do. [43:36.470 --> 43:40.330] So it's a lot of information to help us out. [43:41.910 --> 43:45.170] So again, going back to the disassembler, improving it. [43:45.730 --> 43:55.490] We can go through and figure out a lot of these threads and the monitor commands have entry points. [43:55.610 --> 43:57.590] So we know where they start. [43:58.690 --> 44:03.790] And we can automatically add that into the disassembler so that it will keep track of... [44:03.790 --> 44:10.330] If one function calls another function, calls another function, you know that that function, that third function, is used by the first function. [44:10.590 --> 44:11.850] So it keeps track of that. [44:12.010 --> 44:14.030] And this is a function... [44:16.470 --> 44:23.890] You can see it's called by the shutter command, the motor shutter, the motor iris, zoom motor, LED blink, focus temp. [44:23.890 --> 44:29.190] It's also called by GPIO set, which is general purpose IO. [44:29.850 --> 44:38.010] And so this is probably a low level function that goes through and sets some bits, controls some physical outputs to the outside world. [44:38.410 --> 44:44.170] So that's just through seeing who calls it, we can figure out what it does without even looking at the code. [44:47.150 --> 44:49.610] So there's lots of work, many months. [44:51.990 --> 44:52.430] It's... [44:53.570 --> 44:55.130] For me, it's kind of relaxing. [44:55.370 --> 45:00.770] I go through, I can take it on my laptop once it's in the firmware, take it to a coffee shop, just work on it. [45:00.950 --> 45:02.110] It's kind of like a crossword puzzle. [45:04.630 --> 45:06.590] Figure out if something works. [45:07.850 --> 45:09.250] Put all the pieces together. [45:09.550 --> 45:11.430] It's just a relaxing hobby for me. [45:12.330 --> 45:14.030] And then the CVS camera. [45:15.610 --> 45:20.230] Eventually, after doing that enough, you'll get pieces of code that start to fit together. [45:20.670 --> 45:23.510] And I found a USB cam command queue. [45:24.230 --> 45:26.190] Also a USB agent task. [45:26.530 --> 45:26.850] And... [45:28.650 --> 45:29.390] Let's see. [45:29.550 --> 45:31.570] And the command dispatcher task. [45:32.190 --> 45:39.210] And I kind of took these disparate elements and put it together in a model of how I thought the camera worked internally. [45:40.330 --> 45:58.530] And my initial idea was that the USB comes in, talks to the USB agent, which puts a command in the USB cam command queue, which goes to the command dispatcher, which goes and figures out the commands that it needs to do, and then calls the various low-level commands in order. [46:01.890 --> 46:02.410] So... [46:03.090 --> 46:06.010] This is a pretty looking picture, but it didn't help me. [46:06.150 --> 46:06.590] It didn't work. [46:06.950 --> 46:08.730] There was something that was preventing me from... [46:09.290 --> 46:13.210] And the drivers from talking to the commands to go get your pictures out. [46:13.570 --> 46:16.510] So, obviously, there's a flaw in that model there. [46:18.670 --> 46:22.610] And then the CVS camcorder actually came together pretty quickly. [46:23.030 --> 46:24.610] It had been going slow for months. [46:24.610 --> 46:29.210] And then within a couple days, people were trying different commands. [46:29.410 --> 46:35.590] And they were just trying every single possible USB command that could go out. [46:35.890 --> 46:40.830] And they found that one command, number FE, would sometimes return a number. [46:41.310 --> 46:43.570] And all the other commands just didn't do anything. [46:43.730 --> 46:46.030] They just didn't return anything, just no feedback. [46:46.370 --> 46:47.650] But this one returned a number once. [46:48.690 --> 46:49.090] So... [46:50.830 --> 46:51.230] Yeah. [46:51.570 --> 46:51.790] So... [46:51.790 --> 46:51.870] Yeah. [46:52.670 --> 46:53.070] So... [46:53.070 --> 46:56.570] So, at the same time, I was looking through the code, and I found this neat piece of code. [46:59.170 --> 47:00.270] It looks like this. [47:00.670 --> 47:04.730] And it's a piece of code that goes through and checks for a number that's passed to it. [47:04.870 --> 47:07.390] And sees if it's one of five numbers. [47:07.530 --> 47:10.230] 92, 9D, FA, FE, or FF. [47:11.350 --> 47:12.910] And that's kind of... [47:12.910 --> 47:13.990] Why would you check that? [47:14.370 --> 47:17.790] Those are kind of some specific numbers. [47:18.550 --> 47:21.730] And luckily, one of those was the FE command that we had seen. [47:22.850 --> 47:24.970] So, I kind of put that back into my model. [47:25.750 --> 47:31.330] And the idea was that most of the commands I thought were locked until something had unlocked them. [47:31.410 --> 47:35.430] And there's one command or a couple commands that would go serve to unlock it. [47:36.230 --> 47:37.750] So, that's what happened. [47:38.970 --> 47:41.810] I followed that program where it was doing that comparison. [47:42.210 --> 47:46.230] Checked out where the FA, FE, and FF commands were and figured out how they worked. [47:48.370 --> 47:50.310] And here's how they worked, basically. [47:51.650 --> 47:53.610] The camera has a... [47:54.390 --> 47:55.190] Has a... [47:55.190 --> 47:56.890] It's a challenge in response. [47:57.190 --> 47:59.230] It has a secret password, which is your challenge. [47:59.470 --> 48:00.770] And that's unique to every camera. [48:03.170 --> 48:05.750] And then there's the response, which you have to... [48:05.750 --> 48:08.730] You have to tell the camera the correct response to make it unlock. [48:11.990 --> 48:14.130] So, there's the three functions that support that. [48:16.510 --> 48:19.370] Yeah, there's two for the challenge. [48:19.630 --> 48:21.730] One to tell it which number you want. [48:21.870 --> 48:23.250] And then another number to get it back. [48:24.190 --> 48:26.550] And the way it works is that you... [48:26.550 --> 48:27.670] First, you... [48:28.690 --> 48:29.250] Let's see. [48:29.330 --> 48:31.450] You ask it what challenge number zero is. [48:31.450 --> 48:33.330] You get the number back. [48:33.610 --> 48:35.570] It's one, two, three, four from the table in memory. [48:35.770 --> 48:36.430] That's how... [48:36.430 --> 48:38.510] That's actually how the memory looks... [48:38.510 --> 48:39.610] How those two... [48:41.050 --> 48:41.450] Two... [48:41.450 --> 48:43.190] The challenge response are located in memory. [48:46.970 --> 48:47.370] Um... [48:47.970 --> 48:49.330] You send response zero. [48:50.330 --> 48:51.610] You tell it what the response is. [48:51.690 --> 48:52.630] It looks it up in the table. [48:52.950 --> 48:54.810] Sees that it's four, three, two, one that you... [48:54.810 --> 48:55.390] You sent it. [48:55.550 --> 48:56.530] Matches it with the table. [48:56.930 --> 48:57.850] Puts the little check mark. [48:57.850 --> 48:58.050] Yep. [48:58.830 --> 48:59.230] This... [48:59.910 --> 49:01.030] This response has been answered correctly. [49:01.190 --> 49:03.130] And it will tell you back whether... [49:03.130 --> 49:04.690] If all the responses have been answered correctly. [49:04.850 --> 49:05.330] Or if... [49:05.330 --> 49:06.610] If you still have more work to go. [49:08.310 --> 49:09.110] And so... [49:09.110 --> 49:10.010] I'm sure this is... [49:10.590 --> 49:11.850] A lot of hackers know this. [49:12.090 --> 49:13.970] Part of it is asking the wrong question. [49:15.350 --> 49:15.750] Uh... [49:15.750 --> 49:16.210] To... [49:16.210 --> 49:17.910] Hacking is asking the wrong questions. [49:19.170 --> 49:19.630] So... [49:19.630 --> 49:21.370] I asked it what was... [49:21.370 --> 49:22.010] Challenge number four. [49:23.330 --> 49:23.790] And... [49:23.790 --> 49:25.310] As you can see there's only zero through four. [49:25.570 --> 49:27.290] But that was a... [49:27.290 --> 49:29.370] Overflow error that they had in our code. [49:31.150 --> 49:31.610] So... [49:31.610 --> 49:33.370] We got back the number zero, the response. [49:39.250 --> 49:40.950] Kind of imagine where it goes from here. [49:46.150 --> 49:46.870] Go through... [49:46.870 --> 49:47.210] Get zero. [49:48.670 --> 49:49.030] Oh. [49:49.810 --> 49:50.630] Get all four of them. [49:51.190 --> 49:52.050] Give it back at the numbers. [49:52.190 --> 49:53.310] The same numbers it just gave you. [49:54.070 --> 49:54.770] And it's unlocked. [49:57.830 --> 49:58.190] So... [49:58.190 --> 49:58.810] So... [50:06.150 --> 50:06.770] There's more. [50:09.510 --> 50:12.050] You still need to figure out how to get the pictures out of the command... [50:14.590 --> 50:15.910] And it took a lot of work. [50:16.110 --> 50:18.590] Some of the drivers we looked at for Windows or Linux. [50:18.830 --> 50:23.750] We saw how those worked and emulated the same functionality once we had unlocked the camera. [50:24.850 --> 50:27.570] And you might say that this is all too easy. [50:27.710 --> 50:32.970] You saw how many text pieces that I found that describe portions of the camera. [50:34.010 --> 50:36.210] And the question is, what if you're not so lucky? [50:36.610 --> 50:37.050] So... [50:37.050 --> 50:39.410] I'm kind of running out of time here, but... [50:39.410 --> 50:40.230] And... [50:40.230 --> 50:42.130] So I'll go through this a little quicker. [50:42.950 --> 50:44.290] The second camera... [50:44.830 --> 50:46.390] Didn't have a documented processor. [50:46.670 --> 50:48.010] No documented OS. [50:48.410 --> 50:49.330] And no... [50:49.330 --> 50:51.510] No thread name or text to be lucky with. [50:52.250 --> 50:53.590] So we did a lot of research. [50:54.690 --> 50:59.850] Found out that the company that made it bought the V8 micro-risk processor from another company. [51:00.190 --> 51:03.110] And that's why it was so hard to find how it worked. [51:03.270 --> 51:06.730] Was that they bought it, kept it internally, and didn't release the documentation. [51:07.470 --> 51:09.890] Luckily, the Wayback Machine had some... [51:09.890 --> 51:12.730] One page from 1992 or something like that. [51:12.970 --> 51:13.490] But... [51:13.490 --> 51:14.630] Had one... [51:14.630 --> 51:16.450] Just a little bit of information on how it worked. [51:19.370 --> 51:21.390] So I have to kind of skip through these a little quicker. [51:22.050 --> 51:22.570] But... [51:22.570 --> 51:24.750] The first problem was that they... [51:24.750 --> 51:26.910] Too much code for a 64K processor. [51:28.070 --> 51:31.170] And so I made a little utility that went through and looked at... [51:31.170 --> 51:33.530] This is the actual code that I found in that camera. [51:34.390 --> 51:34.750] And... [51:34.750 --> 51:37.830] Color-coded it by how often that block had been seen. [51:38.610 --> 51:39.370] And so the... [51:39.370 --> 51:41.250] You can see some purple stuff. [51:41.390 --> 51:42.990] And that's the free space in between the blocks. [51:43.150 --> 51:45.250] The banks of memory that it switches in and out. [51:47.830 --> 51:49.430] And so you can tell how many banks there are. [51:49.530 --> 51:50.090] There are about 10. [51:50.870 --> 51:53.590] And then looking at this area over here. [51:54.790 --> 51:58.730] You can see that same pattern at the start of every bank. [51:59.650 --> 52:04.050] And that's the library routines that tell the bank how to initialize. [52:04.210 --> 52:05.320] It's got the math operations. [52:06.190 --> 52:08.030] That way it's always in memory. [52:08.250 --> 52:09.730] These are the most frequently used stuff. [52:17.250 --> 52:19.370] So just using that graphic image. [52:19.670 --> 52:20.910] We figured out how... [52:20.910 --> 52:21.950] How did... [52:21.950 --> 52:23.170] How the bank switching worked. [52:23.350 --> 52:24.070] Where they were. [52:25.110 --> 52:27.230] And I added bank switching to the disassembler. [52:27.470 --> 52:28.570] Which was fairly complicated. [52:29.370 --> 52:30.870] And it took the bulk of the time. [52:31.210 --> 52:32.610] And we figured out how... [52:33.210 --> 52:34.330] How to do it. [52:34.830 --> 52:34.970] Oh! [52:35.290 --> 52:35.530] Oh! [52:35.590 --> 52:36.230] I'm getting to stop. [52:39.870 --> 52:40.550] Let's see. [52:43.960 --> 52:46.800] So we found the letters in there. [52:47.140 --> 52:48.320] I figured out how it worked. [52:48.460 --> 52:49.220] Many months again. [52:50.440 --> 52:52.240] And the short story is... [52:52.240 --> 52:53.460] The second camera was hacked. [52:55.360 --> 52:56.660] I've got a security analysis. [52:56.840 --> 52:58.660] I can probably give that in a... [53:00.200 --> 53:03.240] The third track presentation if anyone's interested. [53:04.340 --> 53:06.260] The main news is that... [53:06.260 --> 53:08.020] And this is a first that I'm going to announce. [53:08.200 --> 53:10.740] That some other people have figured out how the encryption works. [53:10.740 --> 53:12.500] In the base encryption. [53:12.780 --> 53:15.220] Without using the tricks that I've used. [53:15.900 --> 53:17.040] And we're working on it. [53:17.940 --> 53:19.600] We're doing a brute force attack. [53:20.400 --> 53:23.100] Hopefully we'll find the key for the new camera. [53:23.440 --> 53:25.760] So the CBS cameras may be hacked again. [53:26.580 --> 53:28.060] And that's really big news. [53:28.240 --> 53:29.100] I'm excited about it. [53:30.140 --> 53:31.180] So that's it. [53:31.180 --> 53:32.480] My name's John Massimo. [53:38.660 --> 53:39.360] Thanks. [53:40.100 --> 53:40.560] Thank you. [53:40.760 --> 53:40.920] Thanks. [53:41.400 --> 53:41.860] Thank you. [53:41.860 --> 53:41.900] I want you to watch me on the next day. [53:41.900 --> 53:42.100] I'm talking about the new viper concept of.. as a Maxima,