Rickrolling a Google Chromecast at Black Hat

Share

Away from the big show floor where vendors exhibit their wares at the Black Hat USA conference is a smaller room called Black Hat Arsenal, where researchers demonstrate their tools and innovations. Among those demonstrating at Black Hat Arsenal was Dan Petro, a security researcher for BishopFox.

rickmote-660x495

 

Petro demonstrated how, with a small customized Raspberry Pi Linux mini-computer, he could take over a Google Chromecast dongle. The Chromecast is a USB device that enables streaming video for consumer TVs. Petro called his customized Raspberry Pi a Rickmote controller, after the attack payload he delivers to the Chromecast. As part of the Chromecast takeover, Petro’s device streams Rick Astley’s “Never Going to Give You Up” in an attack known as Rickrolling.

The Rickmote is able to Rickroll a Chromecast by abusing functionality on the Chromecast that is intended to make it easier for users to set up the device and get it configured. Petro said that he has informed Google of the issue, but a fix isn’t likely since any additional checks or security measures would make the device more difficult for users to set up and configure.

Sukhraj Singh
Sukhraj Singh
I Live in Chandigarh, India. Having a Great interest in gadgets and writes on my blog about updates on gadgets. Now I'm working with GoAndroid and The Gadget Square. I also love to listening Music.

Read more

Local News

HP Launches Omen 32x Gaming Monitor with Google TV for $749.99

HP is set to make waves in the smart monitor realm with its OMEN 32x, a gaming montior that seamlessly transforms into a Google...

First Chromecast with Google TV update is rolling out in 2025

Last year saw Google unveil eight updates for its streaming dongles, and as we step into 2025, the first Chromecast with Google TV update...

Disney and Fubo Join Forces to Challenge YouTube TV and Settle Venu Lawsuit

Fubo has struck a lucrative deal worth $220 million with Disney, Fox, and Warner Bros. Discovery to resolve an antitrust lawsuit. The agreement aims...

YouTube Music Glitch Inflates Top Listener Badges

In an unexpected twist, YouTube Music users are now witnessing their existing "badges" double, rather than receiving their anticipated December Top Listener badge that...