Skip to content

Instantly share code, notes, and snippets.

@rot256
Created February 28, 2020 20:38
Show Gist options
  • Save rot256/9571e9853880e16de2300fce4e9cee56 to your computer and use it in GitHub Desktop.
Save rot256/9571e9853880e16de2300fce4e9cee56 to your computer and use it in GitHub Desktop.
Glitching attack on Atmega328
#include <avr/io.h>
#include <stdio.h>
#include <stdint.h>
#include <string.h>
#include <util/delay.h>
#include "aes.h"
#define UART_BAUD 9600
char HEX[] = {
'0', '1', '2', '3',
'4', '5', '6', '7',
'8', '9', 'A', 'B',
'C', 'D', 'E', 'F'
};
uint8_t secret[] = {
0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f,
0xd6, 0xaa, 0x74, 0xfd, 0xd2, 0xaf, 0x72, 0xfa, 0xda, 0xa6, 0x78, 0xf1, 0xd6, 0xab, 0x76, 0xfe,
0xb6, 0x92, 0xcf, 0x0b, 0x64, 0x3d, 0xbd, 0xf1, 0xbe, 0x9b, 0xc5, 0x00, 0x68, 0x30, 0xb3, 0xfe,
0xb6, 0xff, 0x74, 0x4e, 0xd2, 0xc2, 0xc9, 0xbf, 0x6c, 0x59, 0x0c, 0xbf, 0x04, 0x69, 0xbf, 0x41,
0x47, 0xf7, 0xf7, 0xbc, 0x95, 0x35, 0x3e, 0x03, 0xf9, 0x6c, 0x32, 0xbc, 0xfd, 0x05, 0x8d, 0xfd,
0x3c, 0xaa, 0xa3, 0xe8, 0xa9, 0x9f, 0x9d, 0xeb, 0x50, 0xf3, 0xaf, 0x57, 0xad, 0xf6, 0x22, 0xaa,
0x5e, 0x39, 0x0f, 0x7d, 0xf7, 0xa6, 0x92, 0x96, 0xa7, 0x55, 0x3d, 0xc1, 0x0a, 0xa3, 0x1f, 0x6b,
0x14, 0xf9, 0x70, 0x1a, 0xe3, 0x5f, 0xe2, 0x8c, 0x44, 0x0a, 0xdf, 0x4d, 0x4e, 0xa9, 0xc0, 0x26,
0x47, 0x43, 0x87, 0x35, 0xa4, 0x1c, 0x65, 0xb9, 0xe0, 0x16, 0xba, 0xf4, 0xae, 0xbf, 0x7a, 0xd2,
0x54, 0x99, 0x32, 0xd1, 0xf0, 0x85, 0x57, 0x68, 0x10, 0x93, 0xed, 0x9c, 0xbe, 0x2c, 0x97, 0x4e,
0x13, 0x11, 0x1d, 0x7f, 0xe3, 0x94, 0x4a, 0x17, 0xf3, 0x07, 0xa7, 0x8b, 0x4d, 0x2b, 0x30, 0xc5
};
void uart_init(void) {
UBRR0 = (F_CPU / (16UL * UART_BAUD)) - 1;
UCSR0B = _BV(TXEN0) | _BV(RXEN0);
}
void uart_putchar(char c) {
loop_until_bit_is_set(UCSR0A, UDRE0);
UDR0 = c;
}
void uart_putstr(char *s) {
while (*s) {
uart_putchar(*s);
s++;
}
}
void uart_hex(uint8_t c) {
uart_putchar(HEX[c >> 4]);
uart_putchar(HEX[c & 0xf]);
}
int main (void) {
uart_init();
aes_expanded_key_t key;
uint8_t pt[AES_BLOCKSIZE];
uart_putstr("hi\n\r");
while(1) {
PORTB |= _BV(PORTB5);
memcpy(key.bytes, secret, sizeof secret);
memset(pt, 0, sizeof pt);
encrypt(pt, &key);
PORTB |= ~_BV(PORTB5);
for (uint8_t i = 0; i < sizeof pt; i++)
uart_hex(pt[i]);
uart_putchar('\n');
uart_putchar('\r');
}
}
/* Serial Output:
hi
E4A54AE83F9C11FA165582BF28B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E7380A92A4FE4FD993115F474FB94F93
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A5A3D23FE1A3FA3BFE82BFB0B0C8D3
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
F422B2610F2BBFC273E3B5E2F000FF80
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
961EE601FC1E9C327CE9EB8A2E581E4A
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
8B73F1D50B80719A697C1A3759F33616
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
A92F091C1FF076898255619ACB83BB95
E4CCA61521D4183972383505E8A57974
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4AA4AD25A9CA3FA16FE82E1B0B005AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
34B71708FF7890AFA395124F69B0FE8B
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC
E4A54AD23F9CA3FA16FE82BFB0B0C8AC

*/
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment