Slashdot Mirror


New 'Phlashing' Attack Sabotages Hardware

yahoi writes "A new type of denial-of-service attack, called permanent denial-of-service (PDOS), damages a system so badly that it requires replacement or reinstallation of hardware. A researcher has discovered how to abuse firmware update mechanisms with what he calls 'phlashing' — a type of remote PDOS attack."

21 of 242 comments (clear)

  1. Bricking by ThrudTheBarbarian · · Score: 5, Funny

    FINALLY! *This* is bricking

    1. Re:Bricking by hostyle · · Score: 3, Funny

      +1 Architectural

      --
      Caesar si viveret, ad remum dareris.
  2. That's the best they could come up with by Zerth · · Score: 5, Funny

    Phlashing? And he calls his demo code PhlashDance? Good way to make this seem completely silly. "Damn it, we've been phlashdanced!" That'll really get management to up your security budget, if they ever stop laughing.

    It figures that when "bricking" might be remotely appropriate, they pick something worse.

    It could have been remote bricking, BOIP(brick over IP), brick-and-run, packet bricking, warbricking.

    Even brick-o-gram(landshark).

    Sigh...

    1. Re:That's the best they could come up with by trongey · · Score: 4, Funny

      It could have been remote bricking, BOIP(brick over IP), brick-and-run, packet bricking, warbricking.

      Even brick-o-gram(landshark). I vote for Brick-rolling.
      --
      You never really know how close to the edge you can go until you fall off.
    2. Re:That's the best they could come up with by Orbijx · · Score: 3, Funny

      We're no strangers to v4. You know ipchains, and so do I. A full traceroute's what I'm thinking of. You wouldn't ping it with any other guy. :)

      --
      One of these days, I am going to flip out. When I flip out, I'll be back in five minutes.
  3. Re:thank you for another buzzword by aproposofwhat · · Score: 5, Funny

    nah - his tool's called PhlashDance, which made me go all warm and fuzzy at the thought of Jennifer Beals stamping on my fimware in her heels :P

    --
    One swallow does not a fellatrix make
  4. Re:Pharphetched naming by Thanshin · · Score: 4, Funny

    I pheel it phaitphully phollows the phirst uses oph it.

  5. Re:Pharphetched naming by Kamineko · · Score: 4, Funny

    It sure as hell beats phbricked.

  6. Proof of concept by Malevolent+Tester · · Score: 5, Funny

    Dear Sir, I am the former son of the Nigerian dictator Sonni Abacha. I would like to give you several million dollars. To receive this, please add a static IP to your D-Link router and reboot it.

    --
    If you haven't made a developer cry, you've wasted a day.
  7. Re:I had no clue people still upgraded firmwares. by maxume · · Score: 3, Funny

    No doubt all his equipment works exactly as he expects it to.

    He would probably be outright offended if he heard about Rockbox or other projects where people are *writing* their own firmware.

    --
    Nerd rage is the funniest rage.
  8. Re:New word overloading by smooth+wombat · · Score: 3, Funny
    Just another reason not to use Flash or even have it installed on your system.


    This is why, Flash must die!

    --
    We will bankrupt ourselves in the vain search for absolute security. -- Dwight D. Eisenhower
  9. Re:Pharphetched naming by davidpbrown · · Score: 5, Funny

    Reminds me of the European Commission

    The European Commission has announced an agreement whereby English will be the official language of the EU, rather than German, which was the other contender. Her Majesty's Government conceded that English spelling had room for improvement and has therefore accepted a five-year phasing in of "Euro-English".

    In the first year, "s" will replace the soft "c". Sertainly, this will make sivil servants jump for joy. The hard "c" will be dropped in favour of the "k", Which should klear up some konfusion and allow one key less on keyboards.

    There will be growing publik enthusiasm in the sekond year, when the troublesome "ph" will be replaced with "f", making words like "fotograf" 20% shorter.

    In the third year, publik akseptanse of the new spelling kan be expekted to reach the stage where more komplikated changes are possible. Governments will enkourage the removal of double letters which have always ben a deterent to akurate speling. Also, al wil agre that the horible mes of the silent "e" is disgrasful.

    By the fourth yer, peopl wil be reseptiv to steps such as replasing "th" with "z" and "w" with "v".

    During ze fifz yer, ze unesesary "o" kan be dropd from vords kontaining "ou" and similar changes vud of kors be aplid to ozer kombinations of leters. After zis fifz yer, ve vil hav a reli sensibl riten styl. Zer vil be no mor trubls or difikultis and everivun vil find it ezi to understand ech ozer. ZE DREM VIL FINALI COM TRU!

    Herr Schmidt

  10. Works in real life too ! by garett_spencley · · Score: 4, Funny

    The last time I "phlashed" someone in real-life I received a permanent injunction and restraining order from a very nice judge in court. I guess you can call that a permanent denial of service.

    1. Re:Works in real life too ! by hyperz69 · · Score: 3, Funny

      I guess your firmware didn't impress her.

  11. Re:Pharphetched naming by beadfulthings · · Score: 4, Funny

    I'm in a lot of trouble. By those rules, by Year 5 there won't be any letters left in my first name.

    Sincerely yours,

    *

    --
    "Here's what's happening. You're starting to drive like your Dad..." - Red Green
  12. Re:thank you for another buzzword by Anonymous Coward · · Score: 5, Funny

    nah - his tool's called PhlashDance, which made me go all warm and fuzzy at the thought of Jennifer Beals stamping on my fimware in her heels :P Hmmmm... What a pheeling.
  13. Re:Pharphetched naming by Anonymous Coward · · Score: 1, Funny

    Oh no. My machine is phukked.

  14. Re:Pharphetched naming by nmg196 · · Score: 2, Funny

    > I'm sick of this naming phad.

    Yeah it's phucking stupid. The stupid phuckwits should take some time to phink of a better name.

  15. Re:Pharphetched naming by Anonymous Coward · · Score: 5, Funny

    Cphethw, is that you!?

  16. Ouch by commodoresloat · · Score: 2, Funny

    This would have been in the mid '90s. I have been wracking my brain over finding it since then. Wow, man, you've been wracking your brain since the mid-90s?
  17. Re:source of the name by morgan_greywolf · · Score: 2, Funny

    PHLASH.EXE is the name of Phoenix's BIOS upgrade tool.
    N0 1tz FLASH.EXE, c3pt l45t w33k, i t0t411y h4x0r3d F33n1x's g1bs0n n i r4pl4c3d th31r upd4t3 @pp w/mj tr0j4n!!! H4! 1 t0t411y pwn3d j00!!!!!