"Blue note" which causes a blue screen by physically destroying a hard disk by sounding a sound that is not heard by a person



By sending ultrasonic waves through speakers, physically destroying nearby hard disks "Blue NoteSecurity researchers announced an attack method called " The sound that is sent from the speaker is OK with no sound to humans, so it is possible that the hard disk will be broken and the PC will become a blue screen unnoticed.

Attackers Can Use Sonic and Ultrasonic Signals to Crash Hard Drives
https://thehackernews.com/2018/05/hard-drive-failure-hack.html

The modern hard disk is based on a physical phenomenon called "acoustic resonance"Head crashIn order to prevent movement, a shock sensor driven feedforward controller that detects movement and improves positioning accuracy of the head during data read / write is carried. However, research teams at the University of Michigan and Zhejiang announcedNew research paper, It is possible to stop the head unnecessarily by causing false detection of the shock sensor of the hard disk by using sound and ultrasonic signal.


"Blue note" is a method of exploiting the vulnerability on this hard disk and attacking the hard disk mounted on the surveillance camera or PC. The research team says, "Attackers use the hard disk's vulnerability to crash laptop PCs by sounding sounds from built-in speakers of the PC, or to hinder shooting of movies by crashing surveillance cameras, affecting the system level It is possible to do it. "

Blue Note uses the speaker near the target hard disk or the built-in speaker of the target system to fool the user to play malicious sound attached to e-mail or web page, so that the attack is completed Then it is. Seagate · Toshiba · Western Digital and other manufacturer's hard disks have investigated the influence of Blue Note, it seems necessary to reproduce the sound for 5 to 8 seconds to cause an error. Also, by playing the sound for more than 105 seconds, the Western Digital hard disk installed in the surveillance camera starts to vibrate and has successfully stopped shooting the movie until the system is restarted.

byNathaniel dahan

Also, since there are no signs of attacks on the images of surveillance cameras and other devices on which attacks have been laid, we can not even notice attacks when there are no people in the vicinity.

Researchers have succeeded in destroying the hard disk in a system running Windows and Linux operating systems, and when executing a blue note on the speaker of "Dell's high-end laptop" XPS 15 9550 " The operation freezes in 45 seconds, it seems that it got blue screen in 125 seconds.

The following list shows the frequency of ultrasonic waves that "Frequency (Freq)" has flowed from the speaker, "Volume (Amp)" is the sound volume from the speaker, "Time (Time) "indicates the time it took to physically destroy the hard disk.


As for the research team on Blue NoteIEEE Symposium on Security and Privacy 2018We are doing a presentation with the following movie. In the movie, you can see how to make a Windows 10 PC on a blue screen or cause the system to generate an error by playing the sound in front of the surveillance camera.

Blue Note: How Intentional Acoustic Interference Damages Availablity and Integrity - - YouTube


According to the research team, the influence of intentional acoustic resonance can be improved by firmware update of the hard disk.

As with Blue Note, the method of attacking a hard disk by using acoustic resonance is a research group of Princeton University and Purdue University in 2017Demonstrationdoing.

in Hardware,   Video,   Security, Posted by logu_ii