conf.directory

DEF CON 30 - Jimi 'jimi2x" Allee - Chromebook Breakout - Escaping Jail Using a Pico Ducky

About this talk

Learn how we used our Pico Ducky to escape Chromebook jail, rescue our friends along the way, and have some fun Living Off the Land! Leveraging a discovered (but previously disclosed) Command Injection vulnerability in the ChromeOS crosh shell, we rabbithole into the internal ChromeOS Linux system, obtain persistence across reboots, and exfiltrate user data even before Developer Mode has been enabled. Learn how to provision and utilize local services in order to perform Privilege Escalations, and also create a 'Master Key' with the Pico Ducky and custom GTFO 1-liners, in order to perform a full Chromebook Breakout!

Stay Updated

Get notified about new features and conference additions.

DEF CON 30 - Jimi 'jimi2x" Allee - Chromebook Breakout - Escaping Jail Using a Pico Ducky by Jimi 'jimi2x" Allee | conf.directory | conf.directory