samy kamkar Profile Banner
samy kamkar Profile
samy kamkar

@samykamkar

Followers
63,280
Following
3,535
Media
293
Statuses
3,944

think bad, do good. | | cofounder @openpathsec

los angeles
Joined June 2008
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@samykamkar
samy kamkar
4 years
I’m finally getting some decent results producing 100%-edible iridescent tempered chocolate. The colors are from the chocolate (not any ingredient or coating) diffracting light after being forcefully molded onto a diffraction grating in vacuum.
1K
8K
45K
@samykamkar
samy kamkar
4 years
I've released NAT Slipstreaming, a spooky new technique that allows an attacker to remotely access any TCP/UDP service bound to a victim machine, bypassing the victim’s NAT/firewall, just by the victim visiting a website. Happy Halloween!
Tweet media one
129
2K
5K
@samykamkar
samy kamkar
6 years
@elonmusk @MrNobre ☁ ☁ ☁ ⛅ ☁ ☁ 🚁 __🌳🌳_____🌲__🌳__ / 🚔 \ / | \ / 🚔 \ / 🚔 | \ / 🚔 🚔 \ / | \ / 🚘 \
34
271
3K
@samykamkar
samy kamkar
6 years
As a high school dropout, I often struggle comprehending mathematical formulas from academic papers (aka numbers combined with squiggly lines). This github just explained so much to me:
32
770
2K
@samykamkar
samy kamkar
4 years
I've developed a new technique for bypassing firewalls/NATs and producing full TCP/UDP session to targeted user. Anyone have RCE for a service that's typically only run behind NATs (eg desktop software like Sonos, Spotify, Dropbox, etc which bind to *) and want to merge projects?
84
412
2K
@samykamkar
samy kamkar
4 years
I've released webscan, a browser-based internal network scanner that detects victim's LAN IP (loops back via WebRTC) & other network hosts just by visiting a page. Can be chained w/NAT Slipstreaming+other attacks; works on mobile; no TURN/STUN/ICE needed.
35
342
1K
@samykamkar
samy kamkar
6 years
Sniff network traffic from your iOS device, no jailbreak necessary! Just plug into your mac and run: system_profiler SPUSBDataType|perl -0 -ne'/iP(?:hone|ad):.*?Serial Number: (\S+)/s?`rvictl -s $1`:0' ; sudo tcpdump -i rvi0 # standard tcpdump options/filters apply
10
359
1K
@samykamkar
samy kamkar
5 years
This is so deceptive. When you "disable" WiFi and Bluetooth in iOS Control Center and they gray out, they're technically still enabled. Even with Airplane Mode on, your device continues to transmit and your name can even be discovered nearby via AirDrop!
Tweet media one
Tweet media two
100
404
1K
@samykamkar
samy kamkar
5 years
Every time I attempt to code in a new language, "yeah, I totally got this"
22
136
924
@samykamkar
samy kamkar
4 years
Very cool, macOS now prevents (current) USBdriveby/Rubber Ducky attacks where USB device emulates keyboard to take control of system just by plugging in. I suspect this can be defeated by simulating a USB hub+mirrored monitor over USB, screen scraping to extract code, then typing
Tweet media one
@doctorow
Cory Doctorow NONCONSENSUAL BLUE TICK
9 years
Usbdriveby: horrifying proof-of-concept USB attack http://t.co/gpUhDY3BI3 http://t.co/EFWEn88Ebc
Tweet media one
4
47
45
41
258
885
@samykamkar
samy kamkar
6 years
Ahh, fresh meat! Diablo (1996 game) by @Blizzard_Ent reverse engineered and released as an open source project, compilable onto modern hardware.
Tweet media one
20
386
832
@samykamkar
samy kamkar
6 years
I've released frisky, a tiny collection of info, iOS tools for jailbreaking, examples of techniques to sniff/alter/reverse/inject code into closed-source mobile apps, etc, based off of the incredible work from @fridadotre and others.
8
369
826
@samykamkar
samy kamkar
4 years
@risknc Yup, hard sugar candies would work really well and is an easier process. Much more common to see neat optical properties in those; chocolate just seemed more unique and ultimately was a much more challenging process (for me :)
8
9
783
@samykamkar
samy kamkar
4 years
@Artist_HB I trade in hugs
8
4
761
@samykamkar
samy kamkar
4 years
I've drawn out the Contact Tracing spec (crypto/BLE/device/server) as it stands today from Apple & Google. Interesting way to anonymize+prevent tracking of users every 10mins until user opts-in to reveal themselves over past 14 days. Chart w/links avail @
Tweet media one
18
337
765
@samykamkar
samy kamkar
4 years
@StrangeAttract5 I rather release full details (sort of did in the tweet) so anyone can make it. It's all yours.
18
5
717
@samykamkar
samy kamkar
6 years
Oh, DEFCON, how you make me smile.
Tweet media one
10
138
680
@samykamkar
samy kamkar
6 years
This is crazy. Australia banned & censors The Anarchist Cookbook, a book I grew up learning electronic attacks, surveillance techniques, and methods of detecting surveillance tools. I've published it at . I will leave it up unless any legal copyright claim.
Tweet media one
27
210
641
@samykamkar
samy kamkar
4 years
@PlanetaryPiggy Absolutely. Tastes like...chocolate!
4
1
622
@samykamkar
samy kamkar
6 years
Awesome! Vim has a built-in spellchecker that only spellchecks *comments* when writing code. :setlocal spell
Tweet media one
17
133
593
@samykamkar
samy kamkar
6 years
Uber created a software upgrade (Android) using the signal to noise ratio of GNSS (including GPS) signals in conjunction with 3D maps to improve location accuracy in urban areas, like determining side of street from a weak, reflected signal off a building.
Tweet media one
6
254
570
@samykamkar
samy kamkar
5 months
Back to the lab again.
Tweet media one
23
13
511
@samykamkar
samy kamkar
6 years
New technique for cracking WPA PSK passwords on 802.11i/p/q/r networks
Tweet media one
4
233
494
@samykamkar
samy kamkar
4 years
@L_AGalloway I saw 3D printing on diffraction grating a while back, tried it, worked really well (very poor print, but the effect worked well - black PLA). Thought it would be cool to do with food!
Tweet media one
7
16
495
@samykamkar
samy kamkar
6 years
Decided to go to @defcon ; arriving tonight! Where will I find friends?
Tweet media one
33
35
487
@samykamkar
samy kamkar
3 years
Created insulated ice tray to make clear ice via directional freezing. Ice freezes clear until water has no where to go/expand so insulating allows it to freeze top down while reservoir below the silicone tray w/holes becomes the cloudy portion, vs normal tray freezing outside in
Tweet media one
Tweet media two
Tweet media three
Tweet media four
19
21
463
@samykamkar
samy kamkar
4 years
First attempt at magnetron sputtering
16
32
446
@samykamkar
samy kamkar
3 years
Had opportunity to collab w/ @gregoryvish & @BenSeri87 of @ArmisSecurity , releasing NAT Slipstreaming v2, an upgraded technique that allows attacker to remotely access any TCP port bound to *any system* behind victim's NAT just by victim visiting a website.
16
162
447
@samykamkar
samy kamkar
2 years
Old fashioned + maraschino cherry spheres that explode in your mouth! I've improved & sped up the reverse spherification process by using cryobath (dry ice + ethanol) to freeze the alcoholic shots, pull vacuum on alginate bath to remove bubbles in minutes & sweetened the alginate
Tweet media one
22
19
441
@samykamkar
samy kamkar
5 years
Okay, that's neat
7
71
401
@samykamkar
samy kamkar
6 years
Wow, stealing credit card numbers over Bluetooth, and full PoC from @mpeg4codec
Tweet media one
5
237
392
@samykamkar
samy kamkar
5 years
@cybergibbons Simple tool I wrote for comparing binary strings between each other, as well as against other groups of binary strings. Used primarily in proprietary protocol research
Tweet media one
7
68
383
@samykamkar
samy kamkar
6 years
Get your NAND game on. Build a 16-bit computer starting from just NAND gates (which in reality you can build from just two relays) in this online game:
Tweet media one
10
125
373
@samykamkar
samy kamkar
9 years
I've released http://t.co/OLldCUqn7i, a camouflaged USB charger+Arduino to sniff Microsoft wireless keyboards. SMSs & logs keystrokes online
30
410
362
@samykamkar
samy kamkar
6 years
Circuit Coder was an absolutely awesome iOS game that gamified and taught building circuits and logic components from scratch. It's no longer available. Does anyone know the author(s) from Tricycle Design HB? I'd like to help get it back up.
Tweet media one
14
97
354
@samykamkar
samy kamkar
6 years
My, how times have changed.
Tweet media one
6
76
341
@samykamkar
samy kamkar
10 months
First time successfully evaporating aluminum in home built vacuum chamber! Test coated acrylic disc as a mirror. Now to get reflectivity/transmission measurement going in vacuum to build controlled beamsplitters for single-photon experiment similar to Elitzur–Vaidman bomb tester
12
31
350
@samykamkar
samy kamkar
4 years
Quora, recently acquired by Yahoo! Answers.
Tweet media one
9
37
315
@samykamkar
samy kamkar
4 years
Your devices' components reveal your passwords through sound.
7
56
311
@samykamkar
samy kamkar
9 years
I’ve released USBdriveby: device to weaponize mouse clicks, evade firewall, install backdoor & reroute DNS in seconds http://t.co/Bg8q4hrkXD
22
290
286
@samykamkar
samy kamkar
5 months
Built a Raman spectrometer for chemical analysis based on the awesome @openraman project; new optical breadboard design w/performant components to augment more + quick alignment. Exciting to "see" light change color via Raman scattering! Example acetone spectra vs public db's
Tweet media one
Tweet media two
Tweet media three
11
45
274
@samykamkar
samy kamkar
7 years
Aww yiss! A gift from youtube for
Tweet media one
22
14
270
@samykamkar
samy kamkar
11 months
Got an NFC continuous glucose monitor out of curiosity to see how food (read: pints of Ben & Jerry's Half Baked) affects my glucose & if linked to mood/energy/hangry. Swapped the sensor, Abbott Freestyle Libre CGM, last night and did a quick teardown and X-ray. IC: RF430TAL152H
Tweet media one
Tweet media two
Tweet media three
Tweet media four
13
30
270
@samykamkar
samy kamkar
8 years
Want to actually *see* the data on your credit card or magstripe? You can with the naked eye
10
250
259
@samykamkar
samy kamkar
9 years
Current Bluetooth research using the latest in Faraday cage technology. From Ikea. http://t.co/QAcpcVp74M
Tweet media one
18
156
252
@samykamkar
samy kamkar
2 years
Tweet media one
0
11
239
@samykamkar
samy kamkar
5 years
This was released 20 years ago. Unfortunately no one can be told what the Matrix is. You have to see it for yourself.
9
47
233
@samykamkar
samy kamkar
3 years
v1 of my design of a mechanical Wimshurst high voltage electrostatic generator. No magnets. Instead of Leyden jars, a single aluminum sheet in the base acts as a capacitor plate to 2 plates in the sides. Sides detach to move the 10s of kilovolts of charge to other HV projects.
10
16
226
@samykamkar
samy kamkar
9 years
I've released OpenSesame, a new vulnerability that can open fixed code garages in under 10 seconds with a Mattel toy
15
249
222
@samykamkar
samy kamkar
5 years
@matthew_d_green In addition to phones tracking routers! When I first reverse engineered iOS, Android & Windows (RIP) in 2011, they all sent wifi MACs+RSSI strength of all nearby routers+GPS to parent companies correlating routers to location. iOS sent cell tower+MACs even w/Location Services off
Tweet media one
10
66
216
@samykamkar
samy kamkar
4 years
@mikko
@mikko
4 years
Take a look at this IP address. http://31.10.590 Before you tell me that it's invalid and won't work, try it.
110
407
1K
11
37
212
@samykamkar
samy kamkar
4 years
@engineers_feed Why do my math homework when a computer can do it for me?
6
12
203
@samykamkar
samy kamkar
10 years
I've released SkyJack, a RasPi drone that seeks out and hacks drones, turns them into zombie drones that you control. http://t.co/o3VVtKpLZp
45
400
207
@samykamkar
samy kamkar
4 years
Had a lot of fun on @WIRED 's "5 Levels" discussing hacking, its various techniques, and some underlying principles, with increasing levels of complexity from a child (Level 1) to an expert (Boss Level, @colinoflynn )
5
35
203
@samykamkar
samy kamkar
6 years
Blow out an LED! @hackaday just ran article on blowing out an LED with a resistor & microcontroller. You can get rid of the resistor and just use internal pullup! Temperature affects diode (LED) voltage drop, thus measurable by the MCU's ADC across pullup.
5
28
200
@samykamkar
samy kamkar
4 years
@LoialOtter I didn't get as much optical vibrance without the vacuum chamber. My guess is that air was being trapped in the rulings between the grating and chocolate, but this is just a guess. Yup, tempered with 2/3rds at 41-45°C, mixed other 1/3rd in till reached 30°C, then cast
3
8
200
@samykamkar
samy kamkar
5 years
For UI nerds
13
64
200
@samykamkar
samy kamkar
6 years
Life tip. When waiting for your flight and watching your phone to see if departure time is close, make sure you’re not staring at a screenshot from an hour ago.
Tweet media one
12
4
187
@samykamkar
samy kamkar
9 years
I've released http://t.co/AyMPUMFeMr, an open, more advanced #ProxyHam device. Proxies wifi2radio 10km+&serializes a shell GLOBALLY over GSM
10
220
189
@samykamkar
samy kamkar
4 years
Cool to see Lenz's law in action w/o enveloping the magnet. I cut away part of a copper tube for full view of Neo the magnet on its journey as it induces current in the conductive partial-tube (Henry/Faraday) which in turn generates a magnetic field (Oersted), opposing Neo here
5
21
187
@samykamkar
samy kamkar
6 years
Well this is neat!
10
20
184
@samykamkar
samy kamkar
5 years
Amazing work from @axi0mX with first iPhone bootrom exploit since 2010. Sets stage for permanent and *unpatchable* jailbreak, affects iPhone 4S through X (A5-11).
3
30
185
@samykamkar
samy kamkar
6 years
Amazing YouTube channel from Michel van Biezen with playlists teaching various areas of math, physics, mechanical engineering, chemistry, astronomy, and more! It's so good.
2
34
190
@samykamkar
samy kamkar
5 years
@mikko I now exchange leftover currency onto my Starbucks gift card. Holds value, internationally accepted, and no fees!
8
13
189
@samykamkar
samy kamkar
4 years
You enter password to decrypt email (PGP w/RSA). CPU instructions executed based on the key, diff instructions = diff power. Power delivered to capacitors+inductors produce electro+magnetostrictive+piezoelectric effects, Lorentz force, others. Components vibrate the key under EM!
7
23
181
@samykamkar
samy kamkar
9 months
Hello ⁦ @defcon ⁩, I am impetuously venturing towards you.
5
11
182
@samykamkar
samy kamkar
2 years
Making liquid nitrogen @ home by extracting nitrogen from air (adsorbing O2) & pumping into cryocooler (~77K!) extracted from superconducting RF filter. Next up, liquid cooling the cryocooler to remove (loud) fan and producing pressure swing adsorption system to run indefinitely
7
16
178
@samykamkar
samy kamkar
5 years
Amazing. Created by @redpepper using @Raspberry_Pi , @GCPcloud 's AutoML, and @UFACTORY_UF 's uArm Swift Pro & uArm Vision Camera Kit
3
31
174
@samykamkar
samy kamkar
7 years
GPU Accelerated JavaScript (perform massively parallel GPGPU computations using WebGL):
Tweet media one
7
75
174
@samykamkar
samy kamkar
4 years
@Viss @gsuberland After failures attempting lasing gratings, finally designed mold in @adskFusion360 , laser cut acrylic plates (variable thickness) w/ @glowforge , turned rods w/Grizzly G0765, CNCd diffraction grating w/ @Inventables Carvey, tempered+pressure injected chocolate, pulled vacuum @ 4torr
Tweet media one
Tweet media two
Tweet media three
Tweet media four
10
24
173
@samykamkar
samy kamkar
2 years
Press F12 to pay respects.
@TheRegister
The Register
2 years
Journalist won't be prosecuted for pressing 'view source'
11
72
214
5
21
167
@samykamkar
samy kamkar
4 years
@gsuberland If refrigerated, it persists. I'm guessing it will melt away at room temp somewhat quick, but longer now that I'm tempering it. That image is from chocolate that was in the fridge for a few days.
3
1
164
@samykamkar
samy kamkar
5 years
tty tip: if your terminal is out of whack after accidentally cat'ing binary, run `reset` to fix the crazy characters
9
30
165
@samykamkar
samy kamkar
6 years
Hacked by @Snubs
8
15
164
@samykamkar
samy kamkar
5 years
@femtoduino I actually think that's a great question...not everyone will like it, but that may be a good filter to find a place where respectful debate/challenge is accepted despite hierarchy (though I would answer their question first)
5
3
158
@samykamkar
samy kamkar
5 years
Uberducky from @mpeg4codec ! A wireless USB Rubber Ducky triggered via BLE
Tweet media one
5
50
151
@samykamkar
samy kamkar
8 years
Cool idea, an anti-forensic tool that shuts down your computer if USB is tampered with (eg w/a mouse jiggler)
11
84
152
@samykamkar
samy kamkar
4 years
@atomicthumbs Do you know which is the most common device going into this recycle mode? I'd like to purchase a non-recycled one and investigate liberation from recycle mode.
13
6
148
@samykamkar
samy kamkar
6 years
Older versions of iOS are (accidentally?) currently signed by Apple, meaning you can *downgrade* for the first time! if you want to jailbreak, downgrade to a jailbreakable version right now!
Tweet media one
7
107
146
@samykamkar
samy kamkar
6 years
Woot! Excited to launch our product today and work with such an amazing team at @OpenpathSec on fun hardware, software & research!
Tweet media one
23
26
147
@samykamkar
samy kamkar
4 years
Is anyone familiar with tools to perform out-of-band snooping+modification of AV signals for HDMI? Seems like it would be an effective game cheat tactic, eg adding improved/assisted zoom on weapons, improved contrast, HUD locating surround-sound sonic signatures of footsteps, etc
Tweet media one
14
15
142
@samykamkar
samy kamkar
4 years
I want a book-reading vid-chat group where you jump in/out @ any time to read quietly near others. Host always playing lofi hip hop, can be muted/unmuted, and you'd just hear people flipping through pages/(dry)coughing. Take a break in the text chat to share your book/chit-chat.
Tweet media one
15
7
141
@samykamkar
samy kamkar
8 years
Wow. 3D printed, 30-watt hand cranked power generator by Even Erichsen -- so cool!
Tweet media one
1
100
134
@samykamkar
samy kamkar
6 years
I want a `DT` (Do Track) HTTP header. If I'm using the browser where I *do* want cookies, I don't want to click 'Accept cookies' from the legit sites I visit. I'm really over those popups as "malicious" trackers will track you regardless via fingerprinting, evercookie, etc
9
30
130
@samykamkar
samy kamkar
4 years
Ah, so that’s what those mean.
@scienceshitpost
Science Diagrams that Look Like Shitposts
4 years
Tweet media one
104
8K
48K
3
18
133
@samykamkar
samy kamkar
4 years
Cool to see how simple the mechanism of a rotary vane vacuum pump is & that there’s no such thing as “sucking”. As rotor+spring loaded vanes turn, one side volume increases/pressure lowers. Inlet wants to equalize pressure so air rushes in then gets compressed/pushed out exhaust.
3
9
132
@samykamkar
samy kamkar
2 years
Love it! Half-duplex version: perl -ne'$,=":44"x5;map{`sudo packit -minject -tarp -e44$, -E$_ 2>&1`}join":",map{unpack"H2",chr(ord()<<1|1)}split//,$&.$/."\0"x4,6while+s/.{1,6}//' sudo tcpdump -le ether host 444444444444|perl -ne'/> (\S+)/;print+map+chr(hex()>>1),split/:/,$1'
@netspooky
Battle Programmer Yuu
2 years
dst2dst, a multicast chat protocol tunneled over any ethernet frame and bounced off the router
10
66
393
2
15
129
@samykamkar
samy kamkar
4 years
@annewils0n @PlanetaryPiggy I couldn't tell it was any different on my tongue. I licked the grating just now & also can't tell it's any diff from non-ruled side. Only way I can tell which side is which is by rubbing finger to produce squeak sound. Gratings are ~2µm. Wonder how the freq of sound is related?
Tweet media one
2
4
130
@samykamkar
samy kamkar
7 months
Whoa, nondestructive detection of single photons (QND)! Can this break BB84 quantum crypto protocol? Polarizing beamsplitter->45˚ PBS @ outputs->QND (det|refl)ectors @ outputs; recover *both* basis states based on detector! Going to need a bigger kitchen.
Tweet media one
12
17
126
@samykamkar
samy kamkar
4 years
@elonmusk Would love to join and contribute. Happy to demonstrate some potential attacks and solutions!
8
2
125
@samykamkar
samy kamkar
2 years
Best starting word for Wordle is "ALTER", tested by getting most used letters in its dictionary, finding word w/each unique letter & most letters in most likely positions: curl |perl -ne'/=\[".*?\]/;$.{$_}++for$&=~/\w/g;print+(sort{$.{$b}-$.{$a}}%.)[0..5]'
10
16
126
@samykamkar
samy kamkar
6 years
Very cool, Arduino has a yield() function built into delay -- if you overload yield() with your own function, it will run *during* delay()s without need for interrupts or any other code changes!
Tweet media one
1
19
122
@samykamkar
samy kamkar
6 years
There was a petition to make "hella" an official SI unit prefix for 10^27. The International Bureau of Weights and Measures were not impressed, but Google and Wolfram Alpha adopted this useful multiple.
6
40
113
@samykamkar
samy kamkar
6 years
Whoa, I just created a free @ComedyCentral account with a never-before-used email in a private browser window, and it showed me a CNC milling machine advertisement (I have two CNCs) which they'd never show a generic audience. Thoughts on how? Only IP address seems reasonable...
37
24
115