Wikileaks, Vault 7: CIA hacking Samsung TVs

Posted: Thu Mar 09, 2017 9:39 pm
by erdem_ua
There are multiple Wikileaks articles mention from our site and our tools about recent leak about CIA penetrating user TVs,

At a meeting years ago (in Istanbul, Turkey), I told to three Samsung managers about similar "Weeping Angel" hack possibility and they need to make something to avoid it but they said "that can not be done".
And also say that they do NOT care about already sold TVs software but just busy with next series TVs software development.
That fact simply explains Samsung TV's software

After years, It looks like CIA and MI6 has something to learn from us BUT Samsung.

Wikileaks Vault 7:

Documents about "Weeping Angel":

And this is plus that shows about how Samsung's Security modal and concerning about SamyGO
(at last header, Samsung’s Countermeasure Fixing Security Holes ) ... 202010.pdf

Posted: Fri Mar 10, 2017 12:37 am
by bugficks
old stuff to us:)
good they didnt find :P

Posted: Sat Mar 11, 2017 4:00 am
by hudd0
If you read the Weeping Angel carefully. Try to compare every step described there, with the basic samygo rooting procedure...

Example: They kill the UEP.b by their own script. Samygo is using Haha!

And keep in mind that they "hacked" the F-Series around 2013/14... Long after the first samygo rooting methods were published here.

My opinion is, that they copied the procedure from samygo, modifyed it a little to their own needs (faking timestamps, remove traces, etc..)

Until now i had the opinion, that those guys are more professional. Hey, its the big fat USA... Professional Hackers, which do nothing other the whole day...

The second thing, i laugh about, is that the press/media realeases articles, which say: "CIA is listening to microphones and watching the camera of samsung TV's"... but audio/video Streaming from the Camera is definetly on their "To do List"...

But the third thing... is the reaction of Samsung: Woah! In the press statements from samsung They seem to be very suprised and shocked... About the practises... And they promise to react.. and fix the vulns...

WTF??? So this reaction means that they never heard/read about samygo?


Posted: Sun Mar 12, 2017 5:38 am
by bugficks
maybe we should add a legal disclaimer that forbids information, source and binaries provided by this site or related to samygo from gov use and their contractors :)

Posted: Sun Mar 12, 2017 11:47 pm
by hudd0
Good idea... Really. Although that we cannot do anything if they do not respect the disclsaimer ;-)

But on the other side:

It seems that govs and their contractors use the Information provided here for their own purposes.

I do not like that.
But Im not a sgo developer. Im just a stupid user in this case.
But if i would get knowledge that other govs, companies, etc. use my public code, projects, Apps for their benefits without asking me... I would do something to stop this.

Just my opinion...