This excellent content from the Hackaday writing crew highlights recurring topics and popular series like Linux-Fu, 3D-Printering, Hackaday Links, This Week in Security, Inputs of Interest, Profiles in Science, Retrotechtacular, Ask Hackaday, Teardowns, Reviews, and many more.
Join Hackaday Editor-in-Chief Elliot Williams and Assignments Editor Kristina Panos for a free-as-in-beer showcase of the week’s most gnarly but palatable hacks. But first, a reminder! Round 2 of the 2022 Hackaday Prize comes to an end in the early hours of Sunday, June 12th, so there’s still enough time to put a project together and get it entered.
This week, we discuss the utility of those squishy foam balls in projects and issue the PSA that it is in fact pool noodle season, so go get ’em. We drool over if-you-have-to-ask-you-can’t-afford-it 3D printers with staircases and such, and wonder why breadboard game controls didn’t already exist. Later on we laugh about lasers, shake the bottle of LTSpice tips from [fesz], and ponder under-door attacks. Finally, we’re back to frickin’ laser beams again, and we discover that there’s a fruity demoscene in Kristina’s backyard.
If you roll way back through the history of open source webmail projects, you’ll find Horde, a groupware web application. First released in 1998 on Freshmeat, it gained some notoriety in early 2012 when it was discovered that the 3.0 release had been tampered with, and packages containing a backdoor had been shipped for three months. While this time around it isn’t an intentional backdoor, there is a very serious problem in the Horde webmail interface. Or more accurately, a pair of problems. The most serious is CVE-2022-30287, an RCE bug allowing an authenticated user to trigger code execution on the connected server.
The vulnerable element is the Turba address book module, which uses a PHP factory method to access a specific address book. The create() method has an interesting bit of code, that first checks the initialization value. If it’s a string, that value is understood as the name of the local address book to access. However, if the factory is initialized with an array, any of the address book drivers can be used, including the IMSP driver. IMSP fetches serialized data from remote servers, and deserializes it. And yes, PHP can have deserialization bugs, and this one runs code on the host.
But it’s not that bad, it’s only authenticated users, right? That would be bad enough, but that second bug is a Cross-site Request Forgery, CSRF, triggered by viewing an email. So on a vulnerable Horde server, any user viewing a malicious message would trigger RCE on the server. Oof. So let’s talk fixes. There is a new version of the Turba module that seems to fix the bugs, but it’s not clear that the actual Horde suite has pushed an update that includes it. So you may be on your own. As is pointed out on the Sonar Blog where the vulnerability was discovered, Horde itself seems to be essentially unmaintained at this point. Maybe time to consider migrating to a newer platform. Continue reading “This Week In Security: For The Horde, Feature Not A Bug, And Confluence”→
In any era, the story of electronics has very much been about figuring out how to make something happen with what’s available at the time. And as is often the case, the most interesting developments come from occasions when needs exceed what’s available. That’s when real innovation takes place, even if circumstances conspire to keep the innovation from ever taking hold in the marketplace.
This gem of a video from the Antique Wireless Association has a perfect example of this: the long-lost analog-to-digital converter vacuum tube. Like almost every mid-20th-century innovation in electronics, this one traces its roots back to the Bell Laboratories, which was keenly interested in improving bandwidth on its massive network of copper lines and microwave links. As early as 1947, one Dr. Frank Gray, a physicist at Bell Labs, had been working on a vacuum tube that could directly convert an analog signal into a digital representation. His solution was a cathode ray tube similar to the CRT in an oscilloscope. A beam of electrons would shine down the length of the tube onto a shadow mask containing holes arranged in a “reflected binary code,” which would later be known as a Gray code. The analog signal to be digitized was applied to a pair of vertical deflector plates, which moved the beam into a position along the plate corresponding to the voltage. A pair of horizontal deflector plates would then scan the beam across the shadow mask; where electrons fell on a hole, they would pass through to an output plate to be registered as a bit to be set.
Where has the year gone? It’s already summer in the Northern Hemisphere, and the second Challenge of the 2022 Hackaday Prize ends this weekend, along with your chance at one of ten $500 prizes. If you thrive on last-minute challenges, consider the eleventh hour upon you. But don’t panic; there’s still a decent amount of time left to start a new project over on Hackaday.io and get it entered into the contest.
The second Challenge focuses on creating new ways of recycling materials. What does this look like? That’s a pretty broad topic, but it could be anything from a better method of chip harvesting to an inexpensive and/or low-energy process for shredding used plastic and forming it into millable blocks.
Don’t just think big on a commercial scale — imagine what people can do at home with the stuff in their recycle bin or their neighbor’s trash. If everyone had access to one of [Jerzeek]’s plastic scanners for identifying the type of plastic that mystery bucket or old watering can was made of, just think what could be done. As long as your project focuses on reusing, recycling, or revamping, we want to see it!
[jude_pullen] is vacu-forming plastic milk jugs ’til the cows come home.
[Guillermo Perez Guillen]’s cornstarch mini pottery machine spins us right round.
So basically, we have a bunch of awesome entries right now, but we don’t have yours! Remember: it doesn’t have to be a new project, just a new project page. Did you revolutionize recycling during lockdown? Make a new project and tell us about it! Just don’t forget to actually enter the thing by using the drop-down on the left before 7AM PDT on Sunday, June 12th. Need a time converting countdown thingy? We’ve got you.
After the recycle bin is empty, we’ll be moving on immediately to the Hack It Back challenge. This time, we’ll be asking you to teach old tech new tricks, or to bring a piece of gear back from the dead. Turn a blender into a Dremel-like tool, or give an old ‘scope a screen upgrade. You know what to do!
When it comes to robots, especially ones that need to achieve some degree of autonomy, the more constrained the environment they work in, the easier it is for them to deal with the world. An industrial arm tethered next to a production line, for example, only has to worry about positioning its tool within its work envelope. The problems mount up for something like an autonomous car, though, which needs to deal with the world in two — or perhaps two and a half — dimensions.
But what about adding a third dimension? That’s the realm that aerial robots have to live and work in, and it’s where the problems get really interesting. Not only are there hardly any constraints to movement, but you’ve also got to deal with the problems of aerodynamic forces, navigation in space, and control systems that need to respond to the slightest of perturbations without overcompensating.
The atmosphere is a tough place to make a living, and dealing with the problems of aerial robotics has kept Nick Rehm occupied for many years as a hobbyist, and more recently as an aerospace engineer at Johns Hopkins Applied Physics Laboratory. Nick has spent his time away from the office solving the problems of autonomous flight, including detection and avoidance of mid-air collisions, development of vertical take-off and landing (VTOL) and fixed-wing aircraft, and even ground-effect aircraft. He’ll drop by the Hack Chat to discuss the problems of aerial robots and the challenges of unconventional aviation, and help us figure out how to deal with the third dimension.
The big news this week comes from the world of medicine, where a woman has received a 3D-printed ear transplant. The 20-year-old woman suffered from microtia, a rare congenital deformity that left her without a pinna, the external structure of the ear. Using scans of the normal ear, doctors were able to make a 3D model of what the missing pinna should look like. Raw material for the print was taken from the vestigial ear of the patient in the form of cartilage cells, or chondrocytes. The ear was printed using a bioprinter, which is a bit like an inkjet printer. The newly printed ear was placed into a protective structure and transplanted. The operation was done in March, and the results are pretty dramatic. With a little squinting, it does look a bit like there are some printing artifacts in the ear, but we’d imagine that’s more from the protective cage that was over the ear as it healed.
Join Hackaday Editor-in-Chief Elliot Williams and Staff Writer Dan Maloney for a tour of the week’s best and brightest hacks. We begin with a call for point-of-sale diversity, because who wants to carry cash? We move on to discussing glass as a building material, which isn’t really easy, but at least it can be sintered with a DIY-grade laser. Want to make a call on a pay phone in New York City? Too late — the last one is gone, and we offer a qualified “good riddance.” We look at socially engineering birds to get them away from what they should be really afraid of, discuss Apple’s potential malicious compliance with right-to-repair, and get the skinny on an absolute unit of a CNC machine. Watching TV? That’s so 2000s, but streaming doesn’t feel quite right either. Then again, anything you watch on a mechanical color TV is pretty cool by definition.