Skip to main content

Put this in your threat model! Crashing machines with… music?


MicoolPaul
Forum|alt.badge.img+23

Saw this article today and I’m just astounded.

 

https://devblogs.microsoft.com/oldnewthing/20220816-00/?p=106994

 

In summary, Janet Jackson’s song “Rhythm Nation” could cause specific machines with 5.4k RPM hard drives to crash. The best part? The machine that crashed could be a nearby machine, not necessarily the one playing the music.

 

The reason behind this was specific frequencies that were being played in the track that were “resonant” frequencies for the hard drives, meaning they caused the disks to increase their “wobbling” until they made contact with the drive head, and then crashed!

 

One of the more interesting ways I’ve seen to crash a system so far… and the fix? Filter out those frequencies digitally in the audio pipeline

5 comments

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8494 comments
  • August 18, 2022
MicoolPaul wrote:

Saw this article today and I’m just astounded.

 

https://devblogs.microsoft.com/oldnewthing/20220816-00/?p=106994

 

In summary, Janet Jackson’s song “Rhythm Nation” could cause specific machines with 5.4k RPM hard drives to crash. The best part? The machine that crashed could be a nearby machine, not necessarily the one playing the music.

 

The reason behind this was specific frequencies that were being played in the track that were “resonant” frequencies for the hard drives, meaning they caused the disks to increase their “wobbling” until they made contact with the drive head, and then crashed!

 

One of the more interesting ways I’ve seen to crash a system so far… and the fix? Filter out those frequencies digitally in the audio pipeline

😮what will they think of next.  Wow!


JMeixner
Forum|alt.badge.img+17
  • On the path to Greatness
  • 2650 comments
  • August 18, 2022

😱😱😱

So, no music in the DC 😂😂😂


MicoolPaul
Forum|alt.badge.img+23
  • Author
  • 2361 comments
  • August 18, 2022
JMeixner wrote:

😱😱😱

So, no music in the DC 😂😂😂

I’m wondering how long before some PoC virus starts messing with fans or built in speakers to trigger similar frequencies for all those 10/15k SAS drives in the DCs.


Geoff Burke
Forum|alt.badge.img+22
  • Veeam Legend, Veeam Vanguard
  • 1318 comments
  • August 18, 2022

Man!!! my super electronic fridge broke down last week after listening to this song. Thanks @MicoolPaul I know will expand my treat factor detection ;) 

 

 


dips
Forum|alt.badge.img+7
  • Veeam Legend
  • 808 comments
  • August 19, 2022

There is an actual CVE too: CVE - CVE-2022-38392 (mitre.org)