• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

POWER-SUPPLaY Cyberattack Steals Data From Air-Gapped PC via Power Supply

Joined
Mar 31, 2020
Messages
1,519 (1.02/day)
It was only a few weeks ago when we reported that Dr. Mordechai Guri and his team had devised a new cyberattack known as Air-ViBeR which could use the vibrations of a PC's fans to steal data by regulating fan speed and recording the sounds on a nearby smartphone. This time Dr. Mordechai and his team have discovered a way to silently transmit data from the ultrasonic frequencies put out by a PC power supply they have dubbed this new attack POWER-SUPPLaY. The cyberattack involves a piece of malware that can alter system load by changing the CPU workload, this causes the PC power supply to change its ultrasonic frequencies which can be detected by a smartphone at a maximum distance of 5 m.

While this cyberattack is certainly technologically impressive, it is unlikely to ever be used out of anything but a Hollywood movie due to some fatal limitations. The attack requires the computer to be compromised and for a mobile device to be within listening distance for a prolonged time, the transmission rate of the attack is only 50 bits per second, or equivalent to about 22.5 kB per hour. With such a low transmission rate the only data that could be feasibly transmitted would be plain text at a rate of 10,000 words an hour.





Dr. Mordechai Guri and his team have posted a demonstration video of the cyberattack in action.


View at TechPowerUp Main Site
 
Joined
Jun 26, 2015
Messages
68 (0.02/day)
Who the heck pays for these so called studies ? I mean, seriously..
And these people call themselves "scientists", what a joke. "Dr. Mordechai Guri and his team"...just wow, impressive work indeed.

Between these and the vulnerabilities of mainstream desktop CPUs, that affect pretty much nobody ever using a PC for mainstream purposes, like media consumption, gaming, editing and such, the entire field oif people finding "vulnerabilities" in modern PCs is becoming a joke.
 
Joined
Mar 10, 2015
Messages
3,984 (1.19/day)
System Name Wut?
Processor 3900X
Motherboard ASRock Taichi X570
Cooling Water
Memory 32GB GSkill CL16 3600mhz
Video Card(s) Vega 56
Storage 2 x AData XPG 8200 Pro 1TB
Display(s) 3440 x 1440
Case Thermaltake Tower 900
Power Supply Seasonic Prime Ultra Platinum
Who the heck pays for these so called studies ? I mean, seriously..
And these people call themselves "scientists", what a joke. "Dr. Mordechai Guri and his team"...just wow, impressive work indeed.

Between these and the vulnerabilities of mainstream desktop CPUs, that affect pretty much nobody ever using a PC for mainstream purposes, like media consumption, gaming, editing and such, the entire field oif people finding "vulnerabilities" in modern PCs is becoming a joke.

It may not be feasible but it is still fundamentally interesting. It's ok that these things aren't for you, the Legos are over there.

PS: I like Legos too.
 
Joined
Sep 17, 2014
Messages
20,961 (5.96/day)
Location
The Washing Machine
Processor i7 8700k 4.6Ghz @ 1.24V
Motherboard AsRock Fatal1ty K6 Z370
Cooling beQuiet! Dark Rock Pro 3
Memory 16GB Corsair Vengeance LPX 3200/C16
Video Card(s) ASRock RX7900XT Phantom Gaming
Storage Samsung 850 EVO 1TB + Samsung 830 256GB + Crucial BX100 250GB + Toshiba 1TB HDD
Display(s) Gigabyte G34QWC (3440x1440)
Case Fractal Design Define R5
Audio Device(s) Harman Kardon AVR137 + 2.1
Power Supply EVGA Supernova G2 750W
Mouse XTRFY M42
Keyboard Lenovo Thinkpad Trackpoint II
Software W10 x64
Imagine if you're English language and you see it constantly mangled like this.

Air Supplay? Viber? :twitch:
 
Joined
Jul 16, 2014
Messages
8,124 (2.27/day)
Location
SE Michigan
System Name Dumbass
Processor AMD Ryzen 7800X3D
Motherboard ASUS TUF gaming B650
Cooling Artic Liquid Freezer 2 - 420mm
Memory G.Skill Sniper 32gb DDR5 6000
Video Card(s) GreenTeam 4070 ti super 16gb
Storage Samsung EVO 500gb & 1Tb, 2tb HDD, 500gb WD Black
Display(s) 1x Nixeus NX_EDG27, 2x Dell S2440L (16:9)
Case Phanteks Enthoo Primo w/8 140mm SP Fans
Audio Device(s) onboard (realtek?) - SPKRS:Logitech Z623 200w 2.1
Power Supply Corsair HX1000i
Mouse Steeseries Esports Wireless
Keyboard Corsair K100
Software windows 10 H
Benchmark Scores https://i.imgur.com/aoz3vWY.jpg?2
Imagine if you're English language and you see it constantly mangled like this.

Air Supplay? Viber? :twitch:

IT could be worse...
 
Joined
Oct 22, 2014
Messages
13,213 (3.80/day)
Location
Sunshine Coast
System Name Black Box
Processor Intel Xeon E3-1260L v5
Motherboard MSI E3 KRAIT Gaming v5
Cooling Tt tower + 120mm Tt fan
Memory G.Skill 16GB 3600 C18
Video Card(s) Asus GTX 970 Mini
Storage Kingston A2000 512Gb NVME
Display(s) AOC 24" Freesync 1m.s. 75Hz
Case Corsair 450D High Air Flow.
Audio Device(s) No need.
Power Supply FSP Aurum 650W
Mouse Yes
Keyboard Of course
Software W10 Pro 64 bit
Secure your air gapped PC, fill it with expanding foam. :p :roll:
 
Joined
May 8, 2019
Messages
132 (0.07/day)
There's ongoing patch from all major CPU vendors that will run a 100% busy task in the background all the time to render this vulnerability useless. Researchers expect that it might affect performance of our systems significantly.
 
Joined
Dec 30, 2010
Messages
2,101 (0.43/day)
Everything in a way is based on RF signals inside a PC. This was already obvious with the 70's and the 27mc thing. If you can find a way to 'listen' to those signals it's pretty much easy to obfuscate on what a PC is doing. I mean coilwhine in a way is a RF based signal too. You could extract the data a GPU is processing if you knew how to build the tools for it. As far as i know, a AMD cpu encrypts the stuff that it's doing.

But in order to fully protect a PC from this stuff; or any device, just shield it out. That simple. This demonstration however could lead to future devices that could listen to a PC in general, and pretty much all it's doing. We're not far from this really.
 
Joined
Aug 20, 2007
Messages
20,794 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Who the heck pays for these so called studies ? I mean, seriously..

If you are in the USA, most likely your tax dollars. Thank the Military Industrial complex...

Seriously, while these aren't vulnerabilities in the traditional sense, that does not mean they are useless. Those who need them, pay for them.

We're not far from this really.

Sensitivity wise... we kinda are.
 
Top