Skip to Content

Summer Budget Travel Tips from Gadling
AOL Tech

hacking posts

Homebrew apps come to the Palm Pre


According to Dieter over at PreCentral, real, honest-to-goodness usable apps are starting to "trickle out" for the Pre / webOS. Apparently utilizing a loophole in the operating system which allows unsigned apps to be sideloaded through email, homebrewers have taken to the interwebs with small utilities like the tip calculator (pictured above). This comes just a day after a group of DIY'ers figured out a workable solution for getting software onto the phone without rooting, so obviously Pre hacking is moving along at a healthy clip. These are -- of course -- very early applications, so don't expect perfection, and there seems to be some concern that Palm might want to patch up this hole, as it leaves the phone vulnerable to less altruistic endeavors. While the latter point is reasonable to consider, we do have a piece of advice for the folks at the front of this movement: don't wait and worry on how Palm will react to this stuff. It's important to push platforms like webOS, and the Pre needs all the love it can get on the development side right now.

Read - Right now: Install a Homebrew App without Hacking
Read - Homebrew Apps Tricking Out, but be careful

Pwnage Tool for iPhone OS 3.0 now live, ultrasn0w still on standby

That iPhone OS 3.0 jailbreak we saw the iPhone Dev-Team pull off earlier this week? It's out now, or at least, part of it is. Pwnage Tool is now flooding torrents, but there's lots of caveats here. Most importantly, this isn't Ultrasn0w, which means if you're wanting to use your toy on T-Mobile or another unofficial carrier, be patient -- it's also worth noting that the jailbreak doesn't jibe with yellowsn0w, so those who rely on it should stay away for the time being. No compatibility with the 3G S, or at least, it probably hasn't been tested... we wouldn't recommend anyone setting the precedent here. You'll need Mac OS X to run it, with QuickPwn for Mac and Windows coming further down the line. Ultrasn0w is also due out at some indeterminate future, so that all said, if you're just needing right now a jailbroken device with spotlight functionality, hit up the read link for all the pertinent details. It should goes without saying, but they're might a few negative side effects to it, and one of the big ones we heard is that YouTube might be fubar'd at the moment.

Read - trois, drei, три, három! (Pwnage Tool released)
Read - No YouTube On Jailbroken iPhone 3.0?

Palm Pre data tethering is a go, Sprint be damned


Well, that was fast. Just a couple hours after we noted Palm warning against hacking webOS to allow data tethering on the Pre, the first set of instructions has popped up. It's not the cleanest hack we've ever seen -- you need to root your phone, enable SSH, and then configure your browser to run through a SOCKS proxy -- but it'll certainly get the job done in a pinch. Just don't go crazy, alright? We've got a feeling Sprint's watching Pre accounts with an eagle eye.

Palm webOS system upgrades mandatory; hacking scene forbidden from tethering


We've seen a tremendous explosion in the webOS hacking scene ever since the Pre's firmware image leaked out -- between the easily-accessible restore more, Linux foundations and the directly-accessible HTML / CSS / Javascript application code, we've already seen everything from minor tweaks to full on NES emulation to Sprint activation hacks. In short, things are wide open at the moment, and people (including us) are excited by the possibilities -- but that doesn't mean Palm has to play along. In fact, two recent developments have us worried for the future of this happy little scene -- first, Palm's apparently forbidding the Pre Dev Wiki from posting any information about data tethering during the Sprint exclusivity period, and apparently threatening to have the site shut down if it happens:
We have been politely cautioned by Palm that any discussion of tethering during the Sprint exclusivity period (and perhaps beyond-we don't know yet) will probably cause Sprint to complain to Palm, and if that happened then Palm would be forced to react against the people running the IRC channel and this wiki.
Yeah, that's pretty aggro for a company that needs to court all the developer support it can. We're not sure what'll happen after Sprint's exclusivity runs out, but we can't imagine any other carriers are going to be thrilled about hacked tethering options either, so we'd say Palm's going to keep the pressure on until unlocked GSM webOS devices hit the scene -- and we can almost guarantee that tethering hacks are going to make it into the wild regardless of Palm's actions.

Even worse for hackers, Palm's taking an unusually aggressive approach to webOS system updates -- they're mandatory. According to the support docs, webOS updates are automatically downloaded in the background within two days of being available, and they're required to be installed within a week of the download -- after seven days and four install prompts, the phone will give you a ten-minute countdown and then automatically begin installing the update. Sure, we can understand why Palm would want all of its devices to be updated, and we know that a lot of webOS system foundations are in flux while the Mojo SDK is being finalized, but forced updates seem extremely heavy-handed to us -- it's one thing to try and maintain control over a platform, it's another to keep it with an iron fist. Of course, it's probable that we'll see a hack to bypass all of this extremely soon, so maybe it'll all work itself out, but we'd really like to see Palm develop an official policy friendly towards hacking and homebrew and stick to it -- the Pre and webOS have attracted a lot of talent in the past two weeks, and it'd be a shame to lose it.

[Via PreThinking; thanks, Justin]

Read - Pre Dev Wiki tethering policy
Read - Palm webOS updates support doc

Defense Department developing portable hacking device for soldiers


It's not exactly news that the Department of Defense is looking at ways to make hacking a more practical weapon, but it looks to really be stepping up its game with its latest project, which promises to make complicated attacks as simple as a few button presses. That would apparently be possible thanks to a slightly mysterious device that'd be small enough to carry around in a backpack, but powerful enough to do everything from breaking into a wireless network to hacking into SCADA (or Supervisory Control and Data Acquisition) systems (used at power plants, nuclear facilities, and the like). While complete details are obviously a bit light, the system would apparently be able to, for instance, map out the nodes in a wireless network, cause them to disconnect, and watch them come back online to identify weak spots. It would then present the "hacker" with various attack attributes that could simply be adjusted using sliders on a touchscreen. No word if the soldiers will also be rewarded with Achievements.

[Via Softpedia]

VHS casette hacked into USB drive? Yes, please


Don't bother asking questions, just admit to yourself that you really might want one (if not several) of these. Using very few materials, you can make yourself a USB storage device which looks just like a VHS tape with a giant wire sticking out of it! It's not a terribly complicated affair -- connecting the USB cable to a thumb drive inside the tape, some simple circuit board wiring -- and presto! If you're willing to spend three or four hours and around $10-15 a pop, you could finally make use of your lonely, disused 227 collection. Check out an informative, educational video of the process after the break.

PlayStation 3 used to hack SSL, Xbox used to play Boogie Bunnies


Between the juvenile delinquent hordes of PlayStation Home and some lackluster holiday figures, the PlayStation has been sort of a bummer lately, for reasons that have nothing to do with its raison d'etre -- gaming. That doesn't mean that the machine is anything less than a powerhouse -- as was made clear today when a group of hackers announced that they'd beaten SSL, using a cluster of 200 PS3s. By exploiting a flaw in the MD5 cryptographic algorithm (used in certain digital signatures and certificates), the group managed to create a rogue Certification Authority (CA) which allows them to create their own SSL certificates -- meaning those authenticated web sites you're visiting could be counterfeit, and you'd have no way of knowing. Sure, this is all pretty obscure stuff, and the kids who managed the hack said it would take others at least six months to replicate the procedure, but eventually vendors are going to have to upgrade all their CAs to use a more robust algorithm. It is assumed that the Wii could perform the operation just as well, if the hackers had enough room to spread out all their Balance Boards.

[Via ZD Net]

Open source "Game Boy" has five awesome parts, zero games


The Arduino-based, DIY GamePack is sort of like the Mignon Game Kit we saw in 2005, but it definitely looks much, much radder. For a mere $249.93, all the necessary parts -- CPU, "Inputshield" customizable, vibrating controller / button component (say, for right or left-handed configurations), "TouchShield Stealth" OLED display unit, and "MeCap" lithium battery pack -- can be yours. Once you've cobbled it together, of course, the real fun begins -- it's pretty much a blank slate with little more than code for a color-changing dot to start with, so if you want to play any "games" on that new "Game Boy" of yours, you're going to have to write them yourself. See a video of the device in action after the break.

[Via technabob]

Princeton publishes how-to guide for hacking Sequoia e-voting machines

Princeton publishes how-to guide for hacking Sequoia e-voting machines
If you're American, it's nearly time to do your civic duty and pick the lesser of two evils for the greater good... and then to wonder if that vote actually got counted. With Diebold admitting its own machines are utterly insecure, competitor Sequoia is now under the microscope and, after a little quality time with the company's machines, Princeton researchers have filed a 158 page report on the ease of replacing their ROMs and winning yourself an election. Okay, we know what you're thinking: "Hacking hardware isn't exactly easy when the computer is in a locked box." Amazingly, it is. A researcher was able to bypass the physical security mechanisms in 13 seconds, despite never having picked a lock before. Now you're thinking: "But you'd need to do that on hundreds of them!" Not so; once infected that malicious code can spread itself to others, and, with no paper trail and an easily bypassed internal audit system, you're well on your way to whatever dark corner of Washington, D.C. you care to occupy!

[Via Ars Technica]

PS3 backup hack kinda clarified, still kinda sketchy

There was (and still is) plenty of buzz surrounding StreetskaterFU's recent hack that enabled Blu-ray games to be played back from the PlayStation 3's internal hard drive, and now it seems like details are beginning to seep out. Fellow hacker ATOC has released an admittedly sketchy step-by-step guide for getting a number of backups to boot from the PS3, though it has only been thoroughly tested on Warhawk and Call of Duty 3. Hit up the links below for instructions, but think long and hard before you make any irreversible decisions and come dangerously close to destroying the universe.

[Thanks, Bob]

Unloved e-voting machines cluttering warehouses, losing value fast

Just as the world's landfills could soon see an influx of unwanted televisions, many American warehouses are packed with e-voting machines that once held promise for a better way to vote. Instead, they turned into a multi-year fiasco, with hackers figuring out how to do everything save for their income taxes on 'em and states reverting back to less vulnerable methods. Now, many states are scrambling for ways to recoup costs, even for outlets that will take them in for recycling. Oddly, Ohio cannot ditch the systems it purchased until a couple of related lawsuits get dealt with. The result? Buckeyes will probably still be using e-voting machines come November.

[Via Slashdot, image courtesy of BradBlog]

Nintendo files suit against five DS hacking firms


"Touching is good," but hacking? Not so much. Nintendo has gone on the war path against five Japanese companies that make their living helping users rip off DS games. Of course, a primary use for such hardware -- such as the R4 Revolution, pictured -- is homebrew and emulation, but good luck convincing Nintendo (or any large console manufacturer) of that. Details of the actual lawsuit are slim, but Nintendo has brought along with it 54 Japanese software makers to lend a bit of gravitas to the suit. If you haven't managed to hack your DS yet, now might be a good time to score the requisite hardware -- we might be facing a scarcity before too long.

[Thanks, Michael]

How to reveal blocked caller ID info: a video guide to risky behavior

Revealing caller ID
Let's say for some reason someone has his or her caller ID blocked and is calling you all the time. Let's then say you really want to know who that person is for, you know, whatever reason -- not that we'd know anything about that. Some crafty phreaker types have come up with a way to do this using an enterprise-spec asterisk box and a SIP trunk provider. In a demonstration video, a hacker tweaks said asterisk box with some new configurations to strip out privacy flags, forward the call to another number, and ultimately reveal caller ID information which, surprisingly, is still available. This isn't meant to be easy, but if the terms "prepend," "SIP trunk," and "asterisk box" don't scare you away, go ahead and watch the video after the break. Big disclaimer: we're not responsible for your broken gear, jail time, or restraining orders.

UK court rules that modchips do not circumvent copyright protection


Here in the US, we've heard some pretty terrifying experiences about selling modchips, but it seems as if higher-ups in the UK are being a bit more reasonable about the whole thing. Reportedly, UK-based MrModchips was cleared of all 26 counts against him for his role in importing and selling console modchips, as the Court of Appeal Criminal Division (Judge Justice Jacobs, in particular) ruled that said chips do not circumvent copyright protection. Better still, the defendant was "awarded full costs as a result of his successful appeal," and we can only assume he was smiling all the way out of the crowded courtroom. Chalk one up for the little guy.

[Via Slashdot]

aTV Flash voluntarily pulled until further notice


Ah, bugger. Just days after Apple Core began offering its aTV Flash on a foolproof USB stick, the outfit has officially pulled the software. Apparently there have been a few "questions arising regarding the fair use of a particular file present on the aTV Flash, and conflicting opinions as to whether or not it falls under the fair use category." In order to keep itself off of the hot seat, it has "proactively" (and voluntarily) discontinued offering the product "until further notice." Not all hope is lost, however, as Apple Core is currently working with the party in question to resolve the dilemma, and it should be keeping us all in the loop as discussions progress. Oh, and in case you're curious -- all current orders were canceled and refunded.

[Thanks to everyone who sent this in]
Follow us on Twitter
Engadget Video


AOL News

Joystiq

Download Squad

TUAW

BloggingStocks

Asylum

Autoblog

Switched.com

FanHouse

Autoblog Green