Comments on: Rescue Your Amazon Dash Buttons https://blog.christophermullins.com/2019/12/20/rescue-your-amazon-dash-buttons/ I occasionally write about things. Usually these things are about computers. Fri, 24 Nov 2023 17:27:00 +0000 hourly 1 https://wordpress.org/?v=5.7.11 By: chris https://blog.christophermullins.com/2019/12/20/rescue-your-amazon-dash-buttons/comment-page-1/#comment-16845 Fri, 24 Nov 2023 17:27:00 +0000 https://blog.christophermullins.com/?p=614#comment-16845 Hi Jean-Claude,

Yes, wav file is audible to me but only barely as it’s very high-pitched. I needed to play it through earbuds for it to work. The link to the wav file still works.

Chris

]]>
By: Jean-Claude DuBois https://blog.christophermullins.com/2019/12/20/rescue-your-amazon-dash-buttons/comment-page-1/#comment-16844 Fri, 24 Nov 2023 12:26:23 +0000 https://blog.christophermullins.com/?p=614#comment-16844 Should the wave file be within the human hearing range?  When I play it, I hear nothing in headphones.  Is the wave file audio_exploit_write_customer_secret.s.wav on this page still a valid file?

]]>
By: Bob https://blog.christophermullins.com/2019/12/20/rescue-your-amazon-dash-buttons/comment-page-1/#comment-14014 Tue, 18 Oct 2022 14:47:18 +0000 https://blog.christophermullins.com/?p=614#comment-14014 Thanks a lot for your info.
I can use all Dash Button with firmware 3xx, 4xx, 5xx and 6xx, although they were not activated through Amazon at the time.
I had a handful of buttons lying around unactivated that I had bought cheaply years ago. For testing I had activated one of the buttons via Amazon, i.e. it goes off 5 seconds after sending the probe request.
Now I’ve noticed that Amazon has discontinued Dash Button service for quite some time.
I only own the JK29LP model, but with four different versions of the firmware. Version 3xx and 4xx could be activated according to the instructions, but it takes 55 seconds for the white LED to go out.
With firmware 6xx, the MAC address is sent directly in all probe requests, even without audio hack and activation.
Since all devices also send probe requests at the beginning in setup mode, the firmware 5xx can also be detected. Here, however, you have to press for a long time until the blue LED is displayed.
For testing purposes I use the sketch for the ESP8266 at https://github.com/iotool/esp8266-AmazonDashButton/

]]>
By: Jim Gridley https://blog.christophermullins.com/2019/12/20/rescue-your-amazon-dash-buttons/comment-page-1/#comment-11806 Mon, 09 May 2022 03:55:18 +0000 https://blog.christophermullins.com/?p=614#comment-11806 Wait, why does the Dash button even have audio processing?!

]]>
By: Jose https://blog.christophermullins.com/2019/12/20/rescue-your-amazon-dash-buttons/comment-page-1/#comment-11490 Sun, 20 Mar 2022 04:00:36 +0000 https://blog.christophermullins.com/?p=614#comment-11490 If the firmware can be dumped from an older device cant it be written into a device that’s been bricked?
Using this method?
https://learn.adafruit.com/dash-hacking-bare-metal-stm32-programming

]]>
By: Daniel https://blog.christophermullins.com/2019/12/20/rescue-your-amazon-dash-buttons/comment-page-1/#comment-11374 Mon, 03 Jan 2022 08:41:29 +0000 https://blog.christophermullins.com/?p=614#comment-11374 Chris: I have one of these older style buttons too. I’m willing to do some leg work, to try and find the offsets in memory, if you’d be willing to help guide me a bit on how to pull the flash memory, and import it into ghidra.

]]>
By: chris https://blog.christophermullins.com/2019/12/20/rescue-your-amazon-dash-buttons/comment-page-1/#comment-10924 Tue, 14 Sep 2021 21:14:09 +0000 https://blog.christophermullins.com/?p=614#comment-10924 Hey Michael,

I think I’ve noticed this before too. It’s been a long time and my memory’s a little fuzzy, but I seem to remember visiting anything other than the root page winding up with a timeout. After visiting the root (just http://192.168.0.1, other stuff would work). Maybe give that a try?

]]>
By: Michael https://blog.christophermullins.com/2019/12/20/rescue-your-amazon-dash-buttons/comment-page-1/#comment-10897 Sat, 11 Sep 2021 22:48:22 +0000 https://blog.christophermullins.com/?p=614#comment-10897 So I have gone through about 15 buttons and only have managed to get 1 to work.  Most were obviously already bricked or new and patched, but I got a few that did blink green after playing the file.  Unfortunately though when I go to set the wireless config via the URL noted above, I get a connection refused error and the wireless info does not get set.  I have had this happen on about 4 unites and one was from the exact same, never configured batch.  I am not sure what is going on.  I have verified the URL string is correct and I am connected to the unit directly.  Anyone seen this or have any idea if there is any way to get these going.  The fact that I got one going was exciting but I have yet to have a second success. Any ideas would be helpful. Thanks.

]]>
By: chris https://blog.christophermullins.com/2019/12/20/rescue-your-amazon-dash-buttons/comment-page-1/#comment-10255 Wed, 23 Jun 2021 00:36:21 +0000 https://blog.christophermullins.com/?p=614#comment-10255 Hi Rob,

This hack allows the user to complete the setup process for a Dash Button. This is necessary for new buttons fresh out of the box, and for buttons that have had their memory wiped after a battery runs low (dash buttons do this automatically when the battery reaches a certain threshold).

The setup process is twofold:

1. Configure a WiFi network to connect to
2. Get a “customer secret,” which used to be served by Amazon

The problem this hack solves is (2). Since Amazon is no longer supporting the buttons, there’s no way for them to get the secret from Amazon. The hack basically tricks the button into writing a value for the customer secret.

The hack is specific to the setup process — no need for it after the button is configured.

]]>
By: Security Week 25: уязвимость в Apple ID | YandexNews Беларусь https://blog.christophermullins.com/2019/12/20/rescue-your-amazon-dash-buttons/comment-page-1/#comment-10246 Tue, 22 Jun 2021 08:23:59 +0000 https://blog.christophermullins.com/?p=614#comment-10246 […] описывает взлом кнопок Amazon Dash. Эти […]

]]>